2016-03-07 01:32:40 +01:00
|
|
|
#
|
|
|
|
# The Qubes OS Project, https://www.qubes-os.org/
|
|
|
|
#
|
|
|
|
# Copyright (C) 2010 Joanna Rutkowska <joanna@invisiblethingslab.com>
|
|
|
|
# Copyright (C) 2013-2016 Marek Marczykowski-Górecki
|
|
|
|
# <marmarek@invisiblethingslab.com>
|
|
|
|
#
|
2017-10-12 00:11:50 +02:00
|
|
|
# This library is free software; you can redistribute it and/or
|
|
|
|
# modify it under the terms of the GNU Lesser General Public
|
|
|
|
# License as published by the Free Software Foundation; either
|
|
|
|
# version 2.1 of the License, or (at your option) any later version.
|
2016-03-07 01:32:40 +01:00
|
|
|
#
|
2017-10-12 00:11:50 +02:00
|
|
|
# This library is distributed in the hope that it will be useful,
|
2016-03-07 01:32:40 +01:00
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
2017-10-12 00:11:50 +02:00
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
|
|
# Lesser General Public License for more details.
|
2016-03-07 01:32:40 +01:00
|
|
|
#
|
2017-10-12 00:11:50 +02:00
|
|
|
# You should have received a copy of the GNU Lesser General Public
|
|
|
|
# License along with this library; if not, see <https://www.gnu.org/licenses/>.
|
2016-03-07 01:32:40 +01:00
|
|
|
#
|
2017-01-18 22:16:46 +01:00
|
|
|
|
2016-03-07 01:32:40 +01:00
|
|
|
import datetime
|
|
|
|
import qubes.ext
|
2016-09-12 06:03:15 +02:00
|
|
|
import qubes.firewall
|
2016-03-07 01:32:40 +01:00
|
|
|
import qubes.vm.qubesvm
|
|
|
|
import qubes.vm.appvm
|
|
|
|
import qubes.vm.templatevm
|
|
|
|
import qubes.utils
|
|
|
|
|
|
|
|
yum_proxy_ip = '10.137.255.254'
|
|
|
|
yum_proxy_port = '8082'
|
|
|
|
|
|
|
|
|
|
|
|
class R3Compatibility(qubes.ext.Extension):
|
|
|
|
'''Maintain VM interface compatibility with R3.0 and R3.1.
|
2017-12-03 03:19:06 +01:00
|
|
|
At least where possible.
|
2016-03-07 01:32:40 +01:00
|
|
|
'''
|
2016-03-07 03:22:59 +01:00
|
|
|
|
|
|
|
features_to_services = {
|
2017-07-05 04:16:16 +02:00
|
|
|
'service.ntpd': 'ntpd',
|
2016-03-07 03:22:59 +01:00
|
|
|
'check-updates': 'qubes-update-check',
|
|
|
|
'dvm': 'qubes-dvm',
|
|
|
|
|
|
|
|
}
|
|
|
|
|
2016-03-07 01:32:40 +01:00
|
|
|
# noinspection PyUnusedLocal
|
2016-03-14 22:16:52 +01:00
|
|
|
@qubes.ext.handler('domain-qdb-create')
|
|
|
|
def on_domain_qdb_create(self, vm, event):
|
2016-06-02 22:02:06 +02:00
|
|
|
'''
|
|
|
|
:param qubes.vm.qubesvm.QubesVM vm: \
|
|
|
|
VM on which QubesDB entries were just created
|
|
|
|
''' # pylint: disable=unused-argument
|
2016-03-07 01:32:40 +01:00
|
|
|
# /qubes-vm-type: AppVM, NetVM, ProxyVM, TemplateVM
|
|
|
|
if isinstance(vm, qubes.vm.templatevm.TemplateVM):
|
|
|
|
vmtype = 'TemplateVM'
|
|
|
|
elif vm.netvm is not None and vm.provides_network:
|
|
|
|
vmtype = 'ProxyVM'
|
|
|
|
elif vm.netvm is None and vm.provides_network:
|
|
|
|
vmtype = 'NetVM'
|
|
|
|
else:
|
|
|
|
vmtype = 'AppVM'
|
2017-07-21 23:11:24 +02:00
|
|
|
vm.untrusted_qdb.write('/qubes-vm-type', vmtype)
|
2016-03-07 01:32:40 +01:00
|
|
|
|
2017-07-21 23:11:24 +02:00
|
|
|
vm.untrusted_qdb.write("/qubes-iptables-error", '')
|
2016-03-07 01:36:57 +01:00
|
|
|
self.write_iptables_qubesdb_entry(vm)
|
|
|
|
|
2016-03-07 03:22:59 +01:00
|
|
|
self.write_services(vm)
|
|
|
|
|
2016-06-16 16:57:44 +02:00
|
|
|
@qubes.ext.handler('domain-spawn')
|
2016-03-07 01:36:57 +01:00
|
|
|
def on_domain_started(self, vm, event, **kwargs):
|
2016-06-02 22:02:06 +02:00
|
|
|
# pylint: disable=unused-argument
|
2016-03-07 01:36:57 +01:00
|
|
|
if vm.netvm:
|
|
|
|
self.write_iptables_qubesdb_entry(vm.netvm)
|
|
|
|
|
|
|
|
@qubes.ext.handler('firewall-changed')
|
|
|
|
def on_firewall_changed(self, vm, event):
|
2016-06-02 22:02:06 +02:00
|
|
|
# pylint: disable=unused-argument
|
2016-03-07 01:36:57 +01:00
|
|
|
if vm.is_running() and vm.netvm:
|
|
|
|
self.write_iptables_qubesdb_entry(vm.netvm)
|
|
|
|
|
|
|
|
def write_iptables_qubesdb_entry(self, firewallvm):
|
2016-06-02 22:02:06 +02:00
|
|
|
# pylint: disable=no-self-use
|
2018-10-15 06:05:05 +02:00
|
|
|
# skip compatibility rules if new format support is advertised
|
|
|
|
if firewallvm.features.check_with_template('qubes-firewall', False):
|
|
|
|
return
|
2017-07-21 23:11:24 +02:00
|
|
|
firewallvm.untrusted_qdb.rm("/qubes-iptables-domainrules/")
|
2016-03-07 01:36:57 +01:00
|
|
|
iptables = "# Generated by Qubes Core on {0}\n".format(
|
|
|
|
datetime.datetime.now().ctime())
|
|
|
|
iptables += "*filter\n"
|
|
|
|
iptables += ":INPUT DROP [0:0]\n"
|
|
|
|
iptables += ":FORWARD DROP [0:0]\n"
|
|
|
|
iptables += ":OUTPUT ACCEPT [0:0]\n"
|
|
|
|
|
|
|
|
# Strict INPUT rules
|
|
|
|
iptables += "-A INPUT -i vif+ -p udp -m udp --dport 68 -j DROP\n"
|
|
|
|
iptables += "-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED " \
|
|
|
|
"-j ACCEPT\n"
|
|
|
|
iptables += "-A INPUT -p icmp -j ACCEPT\n"
|
|
|
|
iptables += "-A INPUT -i lo -j ACCEPT\n"
|
|
|
|
iptables += "-A INPUT -j REJECT --reject-with icmp-host-prohibited\n"
|
|
|
|
|
|
|
|
iptables += "-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED " \
|
|
|
|
"-j ACCEPT\n"
|
|
|
|
# Deny inter-VMs networking
|
|
|
|
iptables += "-A FORWARD -i vif+ -o vif+ -j DROP\n"
|
|
|
|
iptables += "COMMIT\n"
|
2017-07-21 23:11:24 +02:00
|
|
|
firewallvm.untrusted_qdb.write("/qubes-iptables-header", iptables)
|
2016-03-07 01:36:57 +01:00
|
|
|
|
|
|
|
for vm in firewallvm.connected_vms:
|
|
|
|
iptables = "*filter\n"
|
2016-09-12 06:03:15 +02:00
|
|
|
conf = vm.firewall
|
2016-03-07 01:36:57 +01:00
|
|
|
|
|
|
|
xid = vm.xid
|
|
|
|
if xid < 0: # VM not active ATM
|
|
|
|
continue
|
|
|
|
|
|
|
|
ip = vm.ip
|
|
|
|
if ip is None:
|
|
|
|
continue
|
|
|
|
|
|
|
|
# Anti-spoof rules are added by vif-script (vif-route-qubes),
|
|
|
|
# here we trust IP address
|
|
|
|
|
2016-09-12 06:03:15 +02:00
|
|
|
for rule in conf.rules:
|
|
|
|
if rule.specialtarget == 'dns':
|
|
|
|
if rule.dstports not in ('53', None):
|
|
|
|
continue
|
|
|
|
if rule.proto:
|
|
|
|
protos = {'tcp', 'udp'}.intersection(str(rule.proto))
|
|
|
|
else:
|
|
|
|
protos = {'tcp', 'udp'}
|
|
|
|
for proto in protos:
|
|
|
|
if rule.dsthost:
|
|
|
|
dsthosts = set(vm.dns).intersection(
|
|
|
|
[str(rule.dsthost).replace('/24', '')])
|
|
|
|
else:
|
|
|
|
dsthosts = vm.dns
|
|
|
|
for dsthost in dsthosts:
|
|
|
|
iptables += '-A FORWARD -s {}'.format(ip)
|
|
|
|
iptables += ' -d {!s}'.format(dsthost)
|
|
|
|
iptables += ' -p {!s}'.format(proto)
|
|
|
|
iptables += ' --dport 53'
|
|
|
|
iptables += ' -j {}\n'.format(
|
|
|
|
str(rule.action).upper())
|
|
|
|
else:
|
|
|
|
iptables += '-A FORWARD -s {}'.format(ip)
|
|
|
|
if rule.dsthost:
|
|
|
|
iptables += ' -d {!s}'.format(rule.dsthost)
|
|
|
|
if rule.proto:
|
|
|
|
iptables += ' -p {!s}'.format(rule.proto)
|
|
|
|
if rule.dstports:
|
|
|
|
iptables += ' --dport {}'.format(
|
|
|
|
str(rule.dstports).replace('-', ':'))
|
|
|
|
iptables += ' -j {0}\n'.format(str(rule.action).upper())
|
|
|
|
|
|
|
|
iptables += '-A FORWARD -s {0} -j {1}\n'.format(ip,
|
|
|
|
str(conf.policy).upper())
|
|
|
|
iptables += 'COMMIT\n'
|
2017-07-21 23:11:24 +02:00
|
|
|
firewallvm.untrusted_qdb.write(
|
|
|
|
'/qubes-iptables-domainrules/' + str(xid),
|
2016-03-07 01:36:57 +01:00
|
|
|
iptables)
|
|
|
|
# no need for ending -A FORWARD -j DROP, cause default action is DROP
|
|
|
|
|
2017-07-21 23:11:24 +02:00
|
|
|
firewallvm.untrusted_qdb.write('/qubes-iptables', 'reload')
|
2016-03-07 03:22:59 +01:00
|
|
|
|
|
|
|
def write_services(self, vm):
|
|
|
|
for feature, value in vm.features.items():
|
2017-05-26 05:28:07 +02:00
|
|
|
service = self.features_to_services.get(feature, None)
|
|
|
|
if service is None:
|
|
|
|
continue
|
2016-03-07 03:22:59 +01:00
|
|
|
# forcefully convert to '0' or '1'
|
2017-07-21 23:11:24 +02:00
|
|
|
vm.untrusted_qdb.write('/qubes-service/{}'.format(service),
|
2016-03-07 03:22:59 +01:00
|
|
|
str(int(bool(value))))
|
2016-03-07 03:26:59 +01:00
|
|
|
if 'updates-proxy-setup' in vm.features.keys():
|
2017-07-21 23:11:24 +02:00
|
|
|
vm.untrusted_qdb.write(
|
|
|
|
'/qubes-service/{}'.format('yum-proxy-setup'),
|
2016-03-07 03:26:59 +01:00
|
|
|
str(int(bool(vm.features['updates-proxy-setup']))))
|