__init__.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279
  1. # -*- encoding: utf8 -*-
  2. #
  3. # The Qubes OS Project, http://www.qubes-os.org
  4. #
  5. # Copyright (C) 2017 Marek Marczykowski-Górecki
  6. # <marmarek@invisiblethingslab.com>
  7. #
  8. # This program is free software; you can redistribute it and/or modify
  9. # it under the terms of the GNU Lesser General Public License as published by
  10. # the Free Software Foundation; either version 2.1 of the License, or
  11. # (at your option) any later version.
  12. #
  13. # This program is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. # GNU Lesser General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU Lesser General Public License along
  19. # with this program; if not, see <http://www.gnu.org/licenses/>.
  20. import hashlib
  21. import logging
  22. import multiprocessing
  23. import os
  24. import shutil
  25. import qubesadmin.backup.restore
  26. import qubesadmin.exc
  27. import qubesadmin.tests
  28. SIGNATURE_LEN = 512
  29. class BackupTestCase(qubesadmin.tests.QubesTestCase):
  30. class BackupErrorHandler(logging.Handler):
  31. def __init__(self, errors_queue, level=logging.NOTSET):
  32. super(BackupTestCase.BackupErrorHandler, self).__init__(level)
  33. self.errors_queue = errors_queue
  34. def emit(self, record):
  35. self.errors_queue.put(record.getMessage())
  36. def make_vm_name(self, name):
  37. try:
  38. return super(BackupTestCase, self).make_vm_name(name)
  39. except AttributeError:
  40. return 'test-' + name
  41. def setUp(self):
  42. super(BackupTestCase, self).setUp()
  43. self.error_detected = multiprocessing.Queue()
  44. self.log = logging.getLogger('qubesadmin.tests.backup')
  45. self.log.debug("Creating backupvm")
  46. self.backupdir = os.path.join(os.environ["HOME"], "test-backup")
  47. if os.path.exists(self.backupdir):
  48. shutil.rmtree(self.backupdir)
  49. os.mkdir(self.backupdir)
  50. self.error_handler = self.BackupErrorHandler(self.error_detected,
  51. level=logging.WARNING)
  52. backup_log = logging.getLogger('qubesadmin.backup')
  53. backup_log.addHandler(self.error_handler)
  54. def tearDown(self):
  55. super(BackupTestCase, self).tearDown()
  56. shutil.rmtree(self.backupdir)
  57. backup_log = logging.getLogger('qubes.backup')
  58. backup_log.removeHandler(self.error_handler)
  59. def fill_image(self, path, size=None, sparse=False, signature=b''):
  60. block_size = 4096
  61. self.log.debug("Filling %s" % path)
  62. f = open(path, 'wb+')
  63. if size is None:
  64. f.seek(0, 2)
  65. size = f.tell()
  66. f.seek(0)
  67. f.write(signature)
  68. f.write(b'\0' * (SIGNATURE_LEN - len(signature)))
  69. for block_num in range(int(size/block_size)):
  70. if sparse:
  71. f.seek(block_size, 1)
  72. f.write(b'a' * block_size)
  73. f.close()
  74. # NOTE: this was create_basic_vms
  75. def create_backup_vms(self, pool=None):
  76. template = self.app.default_template
  77. vms = []
  78. vmname = self.make_vm_name('test-net')
  79. self.log.debug("Creating %s" % vmname)
  80. testnet = self.app.add_new_vm('AppVM',
  81. name=vmname,
  82. label='red')
  83. testnet.provides_network = True
  84. testnet.create_on_disk(pool=pool)
  85. testnet.features['services/ntpd'] = True
  86. vms.append(testnet)
  87. self.fill_image(testnet.storage.export('private'), 20*1024*1024)
  88. vmname = self.make_vm_name('test1')
  89. self.log.debug("Creating %s" % vmname)
  90. testvm1 = self.app.add_new_vm('AppVM',
  91. name=vmname, template=template, label='red')
  92. testvm1.uses_default_netvm = False
  93. testvm1.netvm = testnet
  94. testvm1.create_on_disk(pool=pool)
  95. vms.append(testvm1)
  96. self.fill_image(testvm1.storage.export('private'), 100 * 1024 * 1024)
  97. vmname = self.make_vm_name('testhvm1')
  98. self.log.debug("Creating %s" % vmname)
  99. testvm2 = self.app.add_new_vm('StandaloneVM',
  100. name=vmname,
  101. label='red')
  102. testvm2.virt_mode = 'hvm'
  103. testvm2.create_on_disk(pool=pool)
  104. self.fill_image(testvm2.storage.export('root'), 1024 * 1024 * 1024, \
  105. True)
  106. vms.append(testvm2)
  107. vmname = self.make_vm_name('template')
  108. self.log.debug("Creating %s" % vmname)
  109. testvm3 = self.app.add_new_vm('TemplateVM',
  110. name=vmname, label='red')
  111. testvm3.create_on_disk(pool=pool)
  112. self.fill_image(testvm3.storage.export('root'), 100 * 1024 * 1024, True)
  113. vms.append(testvm3)
  114. vmname = self.make_vm_name('custom')
  115. self.log.debug("Creating %s" % vmname)
  116. testvm4 = self.app.add_new_vm('AppVM',
  117. name=vmname, template=testvm3, label='red')
  118. testvm4.create_on_disk(pool=pool)
  119. vms.append(testvm4)
  120. self.app.save()
  121. return vms
  122. def make_backup(self, vms, target=None, expect_failure=False, **kwargs):
  123. if target is None:
  124. target = self.backupdir
  125. try:
  126. backup = qubesadmin.backup.Backup(self.app, vms, **kwargs)
  127. except qubesadmin.exc.QubesException as e:
  128. if not expect_failure:
  129. self.fail("QubesException during backup_prepare: %s" % str(e))
  130. else:
  131. raise
  132. if 'passphrase' not in kwargs:
  133. backup.passphrase = 'qubes'
  134. backup.target_dir = target
  135. try:
  136. backup.backup_do()
  137. except qubesadmin.exc.QubesException as e:
  138. if not expect_failure:
  139. self.fail("QubesException during backup_do: %s" % str(e))
  140. else:
  141. raise
  142. def restore_backup(self, source=None, appvm=None, options=None,
  143. expect_errors=None, manipulate_restore_info=None,
  144. passphrase='qubes'):
  145. if source is None:
  146. backupfile = os.path.join(self.backupdir,
  147. sorted(os.listdir(self.backupdir))[-1])
  148. else:
  149. backupfile = source
  150. with self.assertNotRaises(qubesadmin.exc.QubesException):
  151. restore_op = qubesadmin.backup.restore.BackupRestore(
  152. self.app, backupfile, appvm, passphrase)
  153. if options:
  154. for key, value in options.items():
  155. setattr(restore_op.options, key, value)
  156. restore_info = restore_op.get_restore_info()
  157. if callable(manipulate_restore_info):
  158. restore_info = manipulate_restore_info(restore_info)
  159. self.log.debug(restore_op.get_restore_summary(restore_info))
  160. with self.assertNotRaises(qubesadmin.exc.QubesException):
  161. restore_op.restore_do(restore_info)
  162. errors = []
  163. if expect_errors is None:
  164. expect_errors = []
  165. else:
  166. self.assertFalse(self.error_detected.empty(),
  167. "Restore errors expected, but none detected")
  168. while not self.error_detected.empty():
  169. current_error = self.error_detected.get()
  170. if any(map(current_error.startswith, expect_errors)):
  171. continue
  172. errors.append(current_error)
  173. self.assertTrue(len(errors) == 0,
  174. "Error(s) detected during backup_restore_do: %s" %
  175. '\n'.join(errors))
  176. if not appvm and not os.path.isdir(backupfile):
  177. os.unlink(backupfile)
  178. def create_sparse(self, path, size, signature=b''):
  179. f = open(path, "wb")
  180. f.write(signature)
  181. f.write(b'\0' * (SIGNATURE_LEN - len(signature)))
  182. f.truncate(size)
  183. f.close()
  184. def vm_checksum(self, vms):
  185. hashes = {}
  186. for vm in vms:
  187. assert isinstance(vm, qubesadmin.vm.QubesVM)
  188. hashes[vm.name] = {}
  189. for name, volume in vm.volumes.items():
  190. if not volume.rw or not volume.save_on_stop:
  191. continue
  192. vol_path = vm.storage.get_pool(volume).export(volume)
  193. hasher = hashlib.sha1()
  194. with open(vol_path, 'rb') as afile:
  195. for buf in iter(lambda: afile.read(4096000), b''):
  196. hasher.update(buf)
  197. hashes[vm.name][name] = hasher.hexdigest()
  198. return hashes
  199. def assertCorrectlyRestored(self, orig_vms, orig_hashes):
  200. ''' Verify if restored VMs are identical to those before backup.
  201. :param orig_vms: collection of original QubesVM objects
  202. :param orig_hashes: result of :py:meth:`vm_checksum` on original VMs,
  203. before backup
  204. :return:
  205. '''
  206. for vm in orig_vms:
  207. self.assertIn(vm.name, self.app.domains)
  208. restored_vm = self.app.domains[vm.name]
  209. for prop in ('name', 'kernel',
  210. 'memory', 'maxmem', 'kernelopts',
  211. 'services', 'vcpus', 'features'
  212. 'include_in_backups', 'default_user', 'qrexec_timeout',
  213. 'autostart', 'pci_strictreset', 'debug',
  214. 'internal'):
  215. if not hasattr(vm, prop):
  216. continue
  217. self.assertEqual(
  218. getattr(vm, prop), getattr(restored_vm, prop),
  219. "VM {} - property {} not properly restored".format(
  220. vm.name, prop))
  221. for prop in ('netvm', 'template', 'label'):
  222. if not hasattr(vm, prop):
  223. continue
  224. orig_value = getattr(vm, prop)
  225. restored_value = getattr(restored_vm, prop)
  226. if orig_value and restored_value:
  227. self.assertEqual(orig_value.name, restored_value.name,
  228. "VM {} - property {} not properly restored".format(
  229. vm.name, prop))
  230. else:
  231. self.assertEqual(orig_value, restored_value,
  232. "VM {} - property {} not properly restored".format(
  233. vm.name, prop))
  234. for dev_class in vm.devices.keys():
  235. for dev in vm.devices[dev_class]:
  236. self.assertIn(dev, restored_vm.devices[dev_class],
  237. "VM {} - {} device not restored".format(
  238. vm.name, dev_class))
  239. if orig_hashes:
  240. hashes = self.vm_checksum([restored_vm])[restored_vm.name]
  241. self.assertEqual(orig_hashes[vm.name], hashes,
  242. "VM {} - disk images are not properly restored".format(
  243. vm.name))