2013-01-20 21:44:13 +01:00
|
|
|
#!/usr/bin/python2
|
2010-09-21 13:36:46 +02:00
|
|
|
#
|
|
|
|
# The Qubes OS Project, http://www.qubes-os.org
|
|
|
|
#
|
|
|
|
# Copyright (C) 2010 Rafal Wojtczuk <rafal@invisiblethingslab.com>
|
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or
|
|
|
|
# modify it under the terms of the GNU General Public License
|
|
|
|
# as published by the Free Software Foundation; either version 2
|
|
|
|
# of the License, or (at your option) any later version.
|
|
|
|
#
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program; if not, write to the Free Software
|
|
|
|
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
|
|
#
|
|
|
|
#
|
|
|
|
|
|
|
|
from qubes.qubes import QubesVmCollection
|
|
|
|
import os.path
|
|
|
|
import os
|
|
|
|
import sys
|
|
|
|
|
2011-09-03 16:07:10 +02:00
|
|
|
qvm_collection = None
|
|
|
|
|
2010-09-21 13:36:46 +02:00
|
|
|
def get_netvm():
|
2011-09-03 16:07:10 +02:00
|
|
|
global qvm_collection
|
2010-09-21 13:36:46 +02:00
|
|
|
qvm_collection = QubesVmCollection()
|
|
|
|
qvm_collection.lock_db_for_reading()
|
|
|
|
qvm_collection.load()
|
|
|
|
qvm_collection.unlock_db()
|
2012-03-04 21:59:02 +01:00
|
|
|
netvm = qvm_collection.get_default_netvm()
|
|
|
|
while netvm.netvm is not None:
|
|
|
|
netvm = netvm.netvm
|
2010-09-21 13:36:46 +02:00
|
|
|
if netvm is None or netvm.name == 'dom0':
|
2011-10-07 21:56:58 +02:00
|
|
|
print >> sys.stderr, 'There seems to be no dedicated default netvm, aborting.'
|
2010-09-21 13:36:46 +02:00
|
|
|
sys.exit(1)
|
|
|
|
return netvm
|
|
|
|
|
|
|
|
def vif_eth0_exists():
|
|
|
|
if not os.path.islink('/sys/class/net/eth0'):
|
|
|
|
return False
|
2013-03-03 20:05:53 +01:00
|
|
|
if not os.path.isdir('/sys/devices/vif-0/net/eth0'):
|
2011-10-07 21:56:58 +02:00
|
|
|
print >> sys.stderr, 'There is a dedicated netvm, but device eth0 is present'
|
|
|
|
print >> sys.stderr, 'and it is not a Xen interface. Refusing to continue.'
|
2010-09-21 13:36:46 +02:00
|
|
|
sys.exit(1)
|
|
|
|
return True
|
|
|
|
|
|
|
|
def bringup_eth0(netvm):
|
|
|
|
resolv_conf = open('/etc/resolv.conf', "w")
|
|
|
|
resolv_conf.write('nameserver ' + netvm.gateway + '\n')
|
|
|
|
resolv_conf.write('nameserver ' + netvm.secondary_dns + '\n')
|
|
|
|
resolv_conf.close()
|
2012-10-19 02:05:46 +02:00
|
|
|
return os.system('ifconfig eth0 10.137.0.2 netmask 255.255.255.255 && route add default dev eth0') == 0
|
2010-09-21 13:36:46 +02:00
|
|
|
|
|
|
|
def netup():
|
|
|
|
netvm = get_netvm()
|
|
|
|
if os.path.isfile('/var/lock/subsys/NetworkManager'):
|
|
|
|
os.system('/etc/init.d/NetworkManager stop')
|
|
|
|
if not vif_eth0_exists():
|
2013-03-03 20:05:53 +01:00
|
|
|
cmd = 'modprobe xen-netfront'
|
2010-09-21 13:36:46 +02:00
|
|
|
if os.system(cmd) != 0:
|
2011-10-07 21:56:58 +02:00
|
|
|
print >> sys.stderr, 'Error creating network device'
|
2010-09-21 13:36:46 +02:00
|
|
|
sys.exit(1)
|
2011-09-03 16:07:10 +02:00
|
|
|
qvm_collection[0].attach_network(verbose=True, netvm=netvm, wait=True)
|
2010-09-21 13:36:46 +02:00
|
|
|
if not bringup_eth0(netvm):
|
|
|
|
sys.exit(1)
|
|
|
|
|
|
|
|
def netdown():
|
|
|
|
netvm = get_netvm()
|
|
|
|
if not vif_eth0_exists():
|
2011-10-07 21:56:58 +02:00
|
|
|
print >> sys.stderr, 'There is no eth0 that is a Xen vif device, aborting.'
|
2010-09-21 13:36:46 +02:00
|
|
|
sys.exit(1)
|
2012-10-18 06:30:47 +02:00
|
|
|
resolv_conf = open('/etc/resolv.conf', "w")
|
|
|
|
resolv_conf.close()
|
2010-09-21 13:36:46 +02:00
|
|
|
os.system('ifconfig eth0 down')
|
2011-09-03 16:14:12 +02:00
|
|
|
os.system('xl network-detach 0 0')
|
2010-09-21 13:36:46 +02:00
|
|
|
|
|
|
|
def usage():
|
2012-02-07 12:57:29 +01:00
|
|
|
print >> sys.stderr, 'Usage: {0} [up|down]'.format(sys.argv[0])
|
2010-09-21 13:36:46 +02:00
|
|
|
sys.exit(1)
|
|
|
|
|
|
|
|
def main():
|
|
|
|
if len(sys.argv) != 2:
|
|
|
|
usage()
|
|
|
|
if os.getuid() != 0:
|
2011-10-07 21:56:58 +02:00
|
|
|
print >> sys.stderr, 'This script must be run as root'
|
2010-09-21 13:36:46 +02:00
|
|
|
sys.exit(1)
|
|
|
|
if sys.argv[1] == 'up':
|
|
|
|
netup()
|
|
|
|
sys.exit(0)
|
|
|
|
if sys.argv[1] == 'down':
|
|
|
|
netdown()
|
|
|
|
sys.exit(0)
|
|
|
|
usage()
|
|
|
|
|
|
|
|
main()
|
2011-03-14 20:44:17 +01:00
|
|
|
|