ext.py 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320
  1. # -*- encoding: utf8 -*-
  2. #
  3. # The Qubes OS Project, http://www.qubes-os.org
  4. #
  5. # Copyright (C) 2017 Marek Marczykowski-Górecki
  6. # <marmarek@invisiblethingslab.com>
  7. #
  8. # This library is free software; you can redistribute it and/or
  9. # modify it under the terms of the GNU Lesser General Public
  10. # License as published by the Free Software Foundation; either
  11. # version 2.1 of the License, or (at your option) any later version.
  12. #
  13. # This library is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  16. # Lesser General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU Lesser General Public
  19. # License along with this library; if not, see <https://www.gnu.org/licenses/>.
  20. from unittest import mock
  21. import qubes.ext.core_features
  22. import qubes.ext.services
  23. import qubes.ext.windows
  24. import qubes.tests
  25. class TC_00_CoreFeatures(qubes.tests.QubesTestCase):
  26. def setUp(self):
  27. super().setUp()
  28. self.ext = qubes.ext.core_features.CoreFeatures()
  29. self.vm = mock.MagicMock()
  30. self.features = {}
  31. self.vm.configure_mock(**{
  32. 'features.get.side_effect': self.features.get,
  33. 'features.__contains__.side_effect': self.features.__contains__,
  34. 'features.__setitem__.side_effect': self.features.__setitem__,
  35. })
  36. def test_010_notify_tools(self):
  37. del self.vm.template
  38. self.loop.run_until_complete(
  39. self.ext.qubes_features_request(self.vm, 'features-request',
  40. untrusted_features={
  41. 'gui': '1',
  42. 'version': '1',
  43. 'default-user': 'user',
  44. 'qrexec': '1'}))
  45. self.assertEqual(self.vm.mock_calls, [
  46. ('features.get', ('qrexec', False), {}),
  47. ('features.__contains__', ('qrexec',), {}),
  48. ('features.__setitem__', ('qrexec', True), {}),
  49. ('features.__contains__', ('gui',), {}),
  50. ('features.__setitem__', ('gui', True), {}),
  51. ('features.get', ('qrexec', False), {}),
  52. ('fire_event_async', ('template-postinstall',), {}),
  53. ('fire_event_async().__iter__', (), {}),
  54. ])
  55. def test_011_notify_tools_uninstall(self):
  56. del self.vm.template
  57. self.loop.run_until_complete(
  58. self.ext.qubes_features_request(self.vm, 'features-request',
  59. untrusted_features={
  60. 'gui': '0',
  61. 'version': '1',
  62. 'default-user': 'user',
  63. 'qrexec': '0'}))
  64. self.assertEqual(self.vm.mock_calls, [
  65. ('features.get', ('qrexec', False), {}),
  66. ('features.__contains__', ('qrexec',), {}),
  67. ('features.__setitem__', ('qrexec', False), {}),
  68. ('features.__contains__', ('gui',), {}),
  69. ('features.__setitem__', ('gui', False), {}),
  70. ('features.get', ('qrexec', False), {}),
  71. ])
  72. def test_012_notify_tools_uninstall2(self):
  73. del self.vm.template
  74. self.loop.run_until_complete(
  75. self.ext.qubes_features_request(self.vm, 'features-request',
  76. untrusted_features={
  77. 'version': '1',
  78. 'default-user': 'user',
  79. }))
  80. self.assertEqual(self.vm.mock_calls, [
  81. ('features.get', ('qrexec', False), {}),
  82. ('features.get', ('qrexec', False), {}),
  83. ])
  84. def test_013_notify_tools_no_version(self):
  85. del self.vm.template
  86. self.loop.run_until_complete(
  87. self.ext.qubes_features_request(self.vm, 'features-request',
  88. untrusted_features={
  89. 'qrexec': '1',
  90. 'gui': '1',
  91. 'default-user': 'user',
  92. }))
  93. self.assertEqual(self.vm.mock_calls, [
  94. ('features.get', ('qrexec', False), {}),
  95. ('features.__contains__', ('qrexec',), {}),
  96. ('features.__setitem__', ('qrexec', True), {}),
  97. ('features.__contains__', ('gui',), {}),
  98. ('features.__setitem__', ('gui', True), {}),
  99. ('features.get', ('qrexec', False), {}),
  100. ('fire_event_async', ('template-postinstall',), {}),
  101. ('fire_event_async().__iter__', (), {}),
  102. ])
  103. def test_015_notify_tools_invalid_value_qrexec(self):
  104. del self.vm.template
  105. self.loop.run_until_complete(
  106. self.ext.qubes_features_request(self.vm, 'features-request',
  107. untrusted_features={
  108. 'version': '1',
  109. 'qrexec': 'invalid',
  110. 'gui': '1',
  111. 'default-user': 'user',
  112. }))
  113. self.assertEqual(self.vm.mock_calls, [
  114. ('features.get', ('qrexec', False), {}),
  115. ('features.__contains__', ('gui',), {}),
  116. ('features.__setitem__', ('gui', True), {}),
  117. ('features.get', ('qrexec', False), {}),
  118. ])
  119. def test_016_notify_tools_invalid_value_gui(self):
  120. del self.vm.template
  121. self.loop.run_until_complete(
  122. self.ext.qubes_features_request(self.vm, 'features-request',
  123. untrusted_features={
  124. 'version': '1',
  125. 'qrexec': '1',
  126. 'gui': 'invalid',
  127. 'default-user': 'user',
  128. }))
  129. self.assertEqual(self.vm.mock_calls, [
  130. ('features.get', ('qrexec', False), {}),
  131. ('features.__contains__', ('qrexec',), {}),
  132. ('features.__setitem__', ('qrexec', True), {}),
  133. ('features.get', ('qrexec', False), {}),
  134. ('fire_event_async', ('template-postinstall',), {}),
  135. ('fire_event_async().__iter__', (), {}),
  136. ])
  137. def test_017_notify_tools_template_based(self):
  138. self.loop.run_until_complete(
  139. self.ext.qubes_features_request(self.vm, 'features-request',
  140. untrusted_features={
  141. 'version': '1',
  142. 'qrexec': '1',
  143. 'gui': '1',
  144. 'default-user': 'user',
  145. }))
  146. self.assertEqual(self.vm.mock_calls, [
  147. ('template.__bool__', (), {}),
  148. ('log.warning', ('Ignoring qubes.NotifyTools for template-based '
  149. 'VM',), {})
  150. ])
  151. def test_018_notify_tools_already_installed(self):
  152. self.features['qrexec'] = True
  153. self.features['gui'] = True
  154. del self.vm.template
  155. self.loop.run_until_complete(
  156. self.ext.qubes_features_request(self.vm, 'features-request',
  157. untrusted_features={
  158. 'gui': '1',
  159. 'version': '1',
  160. 'default-user': 'user',
  161. 'qrexec': '1'}))
  162. self.assertEqual(self.vm.mock_calls, [
  163. ('features.get', ('qrexec', False), {}),
  164. ('features.__contains__', ('qrexec',), {}),
  165. ('features.__contains__', ('gui',), {}),
  166. ])
  167. class TC_10_WindowsFeatures(qubes.tests.QubesTestCase):
  168. def setUp(self):
  169. super().setUp()
  170. self.ext = qubes.ext.windows.WindowsFeatures()
  171. self.vm = mock.MagicMock()
  172. self.features = {}
  173. self.vm.configure_mock(**{
  174. 'features.get.side_effect': self.features.get,
  175. 'features.__contains__.side_effect': self.features.__contains__,
  176. 'features.__setitem__.side_effect': self.features.__setitem__,
  177. })
  178. def test_000_notify_tools_full(self):
  179. del self.vm.template
  180. self.ext.qubes_features_request(self.vm, 'features-request',
  181. untrusted_features={
  182. 'gui': '1',
  183. 'version': '1',
  184. 'default-user': 'user',
  185. 'qrexec': '1',
  186. 'os': 'Windows'})
  187. self.assertEqual(self.vm.mock_calls, [
  188. ('features.__setitem__', ('os', 'Windows'), {}),
  189. ('features.__setitem__', ('rpc-clipboard', True), {}),
  190. ])
  191. def test_001_notify_tools_no_qrexec(self):
  192. del self.vm.template
  193. self.ext.qubes_features_request(self.vm, 'features-request',
  194. untrusted_features={
  195. 'gui': '1',
  196. 'version': '1',
  197. 'default-user': 'user',
  198. 'qrexec': '0',
  199. 'os': 'Windows'})
  200. self.assertEqual(self.vm.mock_calls, [
  201. ('features.__setitem__', ('os', 'Windows'), {}),
  202. ])
  203. def test_002_notify_tools_other_os(self):
  204. del self.vm.template
  205. self.ext.qubes_features_request(self.vm, 'features-request',
  206. untrusted_features={
  207. 'gui': '1',
  208. 'version': '1',
  209. 'default-user': 'user',
  210. 'qrexec': '1',
  211. 'os': 'other'})
  212. self.assertEqual(self.vm.mock_calls, [])
  213. class TC_20_Services(qubes.tests.QubesTestCase):
  214. def setUp(self):
  215. super().setUp()
  216. self.ext = qubes.ext.services.ServicesExtension()
  217. self.vm = mock.MagicMock()
  218. self.features = {}
  219. self.vm.configure_mock(**{
  220. 'template': None,
  221. 'maxmem': 1024,
  222. 'is_running.return_value': True,
  223. 'features.get.side_effect': self.features.get,
  224. 'features.items.side_effect': self.features.items,
  225. 'features.__iter__.side_effect': self.features.__iter__,
  226. 'features.__contains__.side_effect': self.features.__contains__,
  227. 'features.__setitem__.side_effect': self.features.__setitem__,
  228. 'features.__delitem__.side_effect': self.features.__delitem__,
  229. })
  230. def test_000_write_to_qdb(self):
  231. self.features['service.test1'] = '1'
  232. self.features['service.test2'] = ''
  233. self.ext.on_domain_qdb_create(self.vm, 'domain-qdb-create')
  234. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), [
  235. ('write', ('/qubes-service/meminfo-writer', '1'), {}),
  236. ('write', ('/qubes-service/test1', '1'), {}),
  237. ('write', ('/qubes-service/test2', '0'), {}),
  238. ])
  239. def test_001_feature_set(self):
  240. self.ext.on_domain_feature_set(self.vm,
  241. 'feature-set:service.test_no_oldvalue',
  242. 'service.test_no_oldvalue', '1')
  243. self.ext.on_domain_feature_set(self.vm,
  244. 'feature-set:service.test_oldvalue',
  245. 'service.test_oldvalue', '1', '')
  246. self.ext.on_domain_feature_set(self.vm,
  247. 'feature-set:service.test_disable',
  248. 'service.test_disable', '', '1')
  249. self.ext.on_domain_feature_set(self.vm,
  250. 'feature-set:service.test_disable_no_oldvalue',
  251. 'service.test_disable_no_oldvalue', '')
  252. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), sorted([
  253. ('write', ('/qubes-service/test_no_oldvalue', '1'), {}),
  254. ('write', ('/qubes-service/test_oldvalue', '1'), {}),
  255. ('write', ('/qubes-service/test_disable', '0'), {}),
  256. ('write', ('/qubes-service/test_disable_no_oldvalue', '0'), {}),
  257. ]))
  258. def test_002_feature_delete(self):
  259. self.ext.on_domain_feature_delete(self.vm,
  260. 'feature-delete:service.test3', 'service.test3')
  261. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), [
  262. ('rm', ('/qubes-service/test3',), {}),
  263. ])
  264. def test_010_supported_services(self):
  265. self.ext.supported_services(self.vm, 'features-request',
  266. untrusted_features={
  267. 'supported-service.test1': '1', # ok
  268. 'supported-service.test2': '0', # ignored
  269. 'supported-service.test3': 'some text', # ignored
  270. 'no-service': '1', # ignored
  271. })
  272. self.assertEqual(self.features, {
  273. 'supported-service.test1': True,
  274. })
  275. def test_011_supported_services_add(self):
  276. self.features['supported-service.test1'] = '1'
  277. self.ext.supported_services(self.vm, 'features-request',
  278. untrusted_features={
  279. 'supported-service.test1': '1', # ok
  280. 'supported-service.test2': '1', # ok
  281. })
  282. # also check if existing one is untouched
  283. self.assertEqual(self.features, {
  284. 'supported-service.test1': '1',
  285. 'supported-service.test2': True,
  286. })
  287. def test_012_supported_services_remove(self):
  288. self.features['supported-service.test1'] = '1'
  289. self.ext.supported_services(self.vm, 'features-request',
  290. untrusted_features={
  291. 'supported-service.test2': '1', # ok
  292. })
  293. self.assertEqual(self.features, {
  294. 'supported-service.test2': True,
  295. })