ext.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384
  1. # -*- encoding: utf-8 -*-
  2. #
  3. # The Qubes OS Project, http://www.qubes-os.org
  4. #
  5. # Copyright (C) 2017 Marek Marczykowski-Górecki
  6. # <marmarek@invisiblethingslab.com>
  7. #
  8. # This library is free software; you can redistribute it and/or
  9. # modify it under the terms of the GNU Lesser General Public
  10. # License as published by the Free Software Foundation; either
  11. # version 2.1 of the License, or (at your option) any later version.
  12. #
  13. # This library is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  16. # Lesser General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU Lesser General Public
  19. # License along with this library; if not, see <https://www.gnu.org/licenses/>.
  20. import os
  21. import qubes.ext.core_features
  22. import qubes.ext.services
  23. import qubes.ext.windows
  24. import qubes.tests
  25. from unittest import mock
  26. class TC_00_CoreFeatures(qubes.tests.QubesTestCase):
  27. def setUp(self):
  28. super().setUp()
  29. self.ext = qubes.ext.core_features.CoreFeatures()
  30. self.vm = mock.MagicMock()
  31. self.features = {}
  32. self.vm.configure_mock(**{
  33. 'features.get.side_effect': self.features.get,
  34. 'features.__contains__.side_effect': self.features.__contains__,
  35. 'features.__setitem__.side_effect': self.features.__setitem__,
  36. })
  37. def test_010_notify_tools(self):
  38. del self.vm.template
  39. self.loop.run_until_complete(
  40. self.ext.qubes_features_request(self.vm, 'features-request',
  41. untrusted_features={
  42. 'gui': '1',
  43. 'version': '1',
  44. 'default-user': 'user',
  45. 'qrexec': '1',
  46. 'vmexec': '1'}))
  47. self.assertListEqual(self.vm.mock_calls, [
  48. ('features.get', ('qrexec', False), {}),
  49. ('features.__contains__', ('qrexec',), {}),
  50. ('features.__setitem__', ('qrexec', True), {}),
  51. ('features.__contains__', ('gui',), {}),
  52. ('features.__setitem__', ('gui', True), {}),
  53. ('features.__setitem__', ('vmexec', True), {}),
  54. ('features.get', ('qrexec', False), {}),
  55. ('fire_event_async', ('template-postinstall',), {}),
  56. ('fire_event_async().__iter__', (), {}),
  57. ])
  58. def test_011_notify_tools_uninstall(self):
  59. del self.vm.template
  60. self.loop.run_until_complete(
  61. self.ext.qubes_features_request(self.vm, 'features-request',
  62. untrusted_features={
  63. 'gui': '0',
  64. 'version': '1',
  65. 'default-user': 'user',
  66. 'qrexec': '0',
  67. 'vmexec': '0'}))
  68. self.assertListEqual(self.vm.mock_calls, [
  69. ('features.get', ('qrexec', False), {}),
  70. ('features.__contains__', ('qrexec',), {}),
  71. ('features.__setitem__', ('qrexec', False), {}),
  72. ('features.__contains__', ('gui',), {}),
  73. ('features.__setitem__', ('gui', False), {}),
  74. ('features.__setitem__', ('vmexec', False), {}),
  75. ('features.get', ('qrexec', False), {}),
  76. ])
  77. def test_012_notify_tools_uninstall2(self):
  78. del self.vm.template
  79. self.loop.run_until_complete(
  80. self.ext.qubes_features_request(self.vm, 'features-request',
  81. untrusted_features={
  82. 'version': '1',
  83. 'default-user': 'user',
  84. }))
  85. self.assertListEqual(self.vm.mock_calls, [
  86. ('features.get', ('qrexec', False), {}),
  87. ('features.get', ('qrexec', False), {}),
  88. ])
  89. def test_013_notify_tools_no_version(self):
  90. del self.vm.template
  91. self.loop.run_until_complete(
  92. self.ext.qubes_features_request(self.vm, 'features-request',
  93. untrusted_features={
  94. 'qrexec': '1',
  95. 'gui': '1',
  96. 'default-user': 'user',
  97. }))
  98. self.assertListEqual(self.vm.mock_calls, [
  99. ('features.get', ('qrexec', False), {}),
  100. ('features.__contains__', ('qrexec',), {}),
  101. ('features.__setitem__', ('qrexec', True), {}),
  102. ('features.__contains__', ('gui',), {}),
  103. ('features.__setitem__', ('gui', True), {}),
  104. ('features.get', ('qrexec', False), {}),
  105. ('fire_event_async', ('template-postinstall',), {}),
  106. ('fire_event_async().__iter__', (), {}),
  107. ])
  108. def test_015_notify_tools_invalid_value_qrexec(self):
  109. del self.vm.template
  110. self.loop.run_until_complete(
  111. self.ext.qubes_features_request(self.vm, 'features-request',
  112. untrusted_features={
  113. 'version': '1',
  114. 'qrexec': 'invalid',
  115. 'gui': '1',
  116. 'default-user': 'user',
  117. }))
  118. self.assertEqual(self.vm.mock_calls, [
  119. ('features.get', ('qrexec', False), {}),
  120. ('features.__contains__', ('gui',), {}),
  121. ('features.__setitem__', ('gui', True), {}),
  122. ('features.get', ('qrexec', False), {}),
  123. ])
  124. def test_016_notify_tools_invalid_value_gui(self):
  125. del self.vm.template
  126. self.loop.run_until_complete(
  127. self.ext.qubes_features_request(self.vm, 'features-request',
  128. untrusted_features={
  129. 'version': '1',
  130. 'qrexec': '1',
  131. 'gui': 'invalid',
  132. 'default-user': 'user',
  133. }))
  134. self.assertListEqual(self.vm.mock_calls, [
  135. ('features.get', ('qrexec', False), {}),
  136. ('features.__contains__', ('qrexec',), {}),
  137. ('features.__setitem__', ('qrexec', True), {}),
  138. ('features.get', ('qrexec', False), {}),
  139. ('fire_event_async', ('template-postinstall',), {}),
  140. ('fire_event_async().__iter__', (), {}),
  141. ])
  142. def test_017_notify_tools_template_based(self):
  143. self.loop.run_until_complete(
  144. self.ext.qubes_features_request(self.vm, 'features-request',
  145. untrusted_features={
  146. 'version': '1',
  147. 'qrexec': '1',
  148. 'gui': '1',
  149. 'default-user': 'user',
  150. }))
  151. self.assertEqual(self.vm.mock_calls, [
  152. ('template.__bool__', (), {}),
  153. ('log.warning', ('Ignoring qubes.NotifyTools for template-based '
  154. 'VM',), {})
  155. ])
  156. def test_018_notify_tools_already_installed(self):
  157. self.features['qrexec'] = True
  158. self.features['gui'] = True
  159. del self.vm.template
  160. self.loop.run_until_complete(
  161. self.ext.qubes_features_request(self.vm, 'features-request',
  162. untrusted_features={
  163. 'gui': '1',
  164. 'version': '1',
  165. 'default-user': 'user',
  166. 'qrexec': '1'}))
  167. self.assertListEqual(self.vm.mock_calls, [
  168. ('features.get', ('qrexec', False), {}),
  169. ('features.__contains__', ('qrexec',), {}),
  170. ('features.__contains__', ('gui',), {}),
  171. ])
  172. class TC_10_WindowsFeatures(qubes.tests.QubesTestCase):
  173. def setUp(self):
  174. super().setUp()
  175. self.ext = qubes.ext.windows.WindowsFeatures()
  176. self.vm = mock.MagicMock()
  177. self.features = {}
  178. self.vm.configure_mock(**{
  179. 'features.get.side_effect': self.features.get,
  180. 'features.__contains__.side_effect': self.features.__contains__,
  181. 'features.__setitem__.side_effect': self.features.__setitem__,
  182. })
  183. def test_000_notify_tools_full(self):
  184. del self.vm.template
  185. self.ext.qubes_features_request(self.vm, 'features-request',
  186. untrusted_features={
  187. 'gui': '1',
  188. 'version': '1',
  189. 'default-user': 'user',
  190. 'qrexec': '1',
  191. 'os': 'Windows'})
  192. self.assertEqual(self.vm.mock_calls, [
  193. ('features.__setitem__', ('os', 'Windows'), {}),
  194. ('features.__setitem__', ('rpc-clipboard', True), {}),
  195. ])
  196. def test_001_notify_tools_no_qrexec(self):
  197. del self.vm.template
  198. self.ext.qubes_features_request(self.vm, 'features-request',
  199. untrusted_features={
  200. 'gui': '1',
  201. 'version': '1',
  202. 'default-user': 'user',
  203. 'qrexec': '0',
  204. 'os': 'Windows'})
  205. self.assertEqual(self.vm.mock_calls, [
  206. ('features.__setitem__', ('os', 'Windows'), {}),
  207. ])
  208. def test_002_notify_tools_other_os(self):
  209. del self.vm.template
  210. self.ext.qubes_features_request(self.vm, 'features-request',
  211. untrusted_features={
  212. 'gui': '1',
  213. 'version': '1',
  214. 'default-user': 'user',
  215. 'qrexec': '1',
  216. 'os': 'other'})
  217. self.assertEqual(self.vm.mock_calls, [])
  218. class TC_20_Services(qubes.tests.QubesTestCase):
  219. def setUp(self):
  220. super().setUp()
  221. self.ext = qubes.ext.services.ServicesExtension()
  222. self.features = {}
  223. specs = {
  224. 'features.get.side_effect': self.features.get,
  225. 'features.items.side_effect': self.features.items,
  226. 'features.__iter__.side_effect': self.features.__iter__,
  227. 'features.__contains__.side_effect': self.features.__contains__,
  228. 'features.__setitem__.side_effect': self.features.__setitem__,
  229. 'features.__delitem__.side_effect': self.features.__delitem__,
  230. }
  231. vmspecs = {**specs, **{
  232. 'template': None,
  233. 'maxmem': 1024,
  234. 'is_running.return_value': True,
  235. }}
  236. dom0specs = {**specs, **{
  237. 'name': "dom0",
  238. }}
  239. self.vm = mock.MagicMock()
  240. self.vm.configure_mock(**vmspecs)
  241. self.dom0 = mock.MagicMock()
  242. self.dom0.configure_mock(**dom0specs)
  243. def test_000_write_to_qdb(self):
  244. self.features['service.test1'] = '1'
  245. self.features['service.test2'] = ''
  246. self.ext.on_domain_qdb_create(self.vm, 'domain-qdb-create')
  247. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), [
  248. ('write', ('/qubes-service/meminfo-writer', '1'), {}),
  249. ('write', ('/qubes-service/test1', '1'), {}),
  250. ('write', ('/qubes-service/test2', '0'), {}),
  251. ])
  252. def test_001_feature_set(self):
  253. self.ext.on_domain_feature_set(self.vm,
  254. 'feature-set:service.test_no_oldvalue',
  255. 'service.test_no_oldvalue', '1')
  256. self.ext.on_domain_feature_set(self.vm,
  257. 'feature-set:service.test_oldvalue',
  258. 'service.test_oldvalue', '1', '')
  259. self.ext.on_domain_feature_set(self.vm,
  260. 'feature-set:service.test_disable',
  261. 'service.test_disable', '', '1')
  262. self.ext.on_domain_feature_set(self.vm,
  263. 'feature-set:service.test_disable_no_oldvalue',
  264. 'service.test_disable_no_oldvalue', '')
  265. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), sorted([
  266. ('write', ('/qubes-service/test_no_oldvalue', '1'), {}),
  267. ('write', ('/qubes-service/test_oldvalue', '1'), {}),
  268. ('write', ('/qubes-service/test_disable', '0'), {}),
  269. ('write', ('/qubes-service/test_disable_no_oldvalue', '0'), {}),
  270. ]))
  271. def test_002_feature_delete(self):
  272. self.ext.on_domain_feature_delete(self.vm,
  273. 'feature-delete:service.test3', 'service.test3')
  274. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), [
  275. ('rm', ('/qubes-service/test3',), {}),
  276. ])
  277. def test_010_supported_services(self):
  278. self.ext.supported_services(self.vm, 'features-request',
  279. untrusted_features={
  280. 'supported-service.test1': '1', # ok
  281. 'supported-service.test2': '0', # ignored
  282. 'supported-service.test3': 'some text', # ignored
  283. 'no-service': '1', # ignored
  284. })
  285. self.assertEqual(self.features, {
  286. 'supported-service.test1': True,
  287. })
  288. def test_011_supported_services_add(self):
  289. self.features['supported-service.test1'] = '1'
  290. self.ext.supported_services(self.vm, 'features-request',
  291. untrusted_features={
  292. 'supported-service.test1': '1', # ok
  293. 'supported-service.test2': '1', # ok
  294. })
  295. # also check if existing one is untouched
  296. self.assertEqual(self.features, {
  297. 'supported-service.test1': '1',
  298. 'supported-service.test2': True,
  299. })
  300. def test_012_supported_services_remove(self):
  301. self.features['supported-service.test1'] = '1'
  302. self.ext.supported_services(self.vm, 'features-request',
  303. untrusted_features={
  304. 'supported-service.test2': '1', # ok
  305. })
  306. self.assertEqual(self.features, {
  307. 'supported-service.test2': True,
  308. })
  309. def test_013_feature_set_dom0(self):
  310. self.test_base_dir = '/tmp/qubes-test-dir'
  311. self.base_dir_patch = mock.patch.dict(
  312. qubes.config.system_path, {'dom0_services_dir': self.test_base_dir})
  313. self.base_dir_patch.start()
  314. self.addCleanup(self.base_dir_patch.stop)
  315. service = 'guivm-gui-agent'
  316. service_path = self.test_base_dir + '/' + service
  317. self.ext.on_domain_feature_set(
  318. self.dom0,
  319. 'feature-set:service.service.guivm-gui-agent',
  320. 'service.guivm-gui-agent', '1')
  321. self.assertEqual(os.path.exists(service_path), True)
  322. def test_014_feature_delete_dom0(self):
  323. self.test_base_dir = '/tmp/qubes-test-dir'
  324. self.base_dir_patch = mock.patch.dict(
  325. qubes.config.system_path, {'dom0_services_dir': self.test_base_dir})
  326. self.base_dir_patch.start()
  327. self.addCleanup(self.base_dir_patch.stop)
  328. service = 'guivm-gui-agent'
  329. service_path = self.test_base_dir + '/' + service
  330. self.ext.on_domain_feature_set(
  331. self.dom0,
  332. 'feature-set:service.service.guivm-gui-agent',
  333. 'service.guivm-gui-agent', '1')
  334. self.ext.on_domain_feature_delete(
  335. self.dom0,
  336. 'feature-delete:service.service.guivm-gui-agent',
  337. 'service.guivm-gui-agent')
  338. self.assertEqual(os.path.exists(service_path), False)
  339. def test_014_feature_set_empty_value_dom0(self):
  340. self.test_base_dir = '/tmp/qubes-test-dir'
  341. self.base_dir_patch = mock.patch.dict(
  342. qubes.config.system_path, {'dom0_services_dir': self.test_base_dir})
  343. self.base_dir_patch.start()
  344. self.addCleanup(self.base_dir_patch.stop)
  345. service = 'guivm-gui-agent'
  346. service_path = self.test_base_dir + '/' + service
  347. self.ext.on_domain_feature_set(
  348. self.dom0,
  349. 'feature-set:service.service.guivm-gui-agent',
  350. 'service.guivm-gui-agent', '')
  351. self.assertEqual(os.path.exists(service_path), False)