ext.py 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458
  1. # -*- encoding: utf-8 -*-
  2. #
  3. # The Qubes OS Project, http://www.qubes-os.org
  4. #
  5. # Copyright (C) 2017 Marek Marczykowski-Górecki
  6. # <marmarek@invisiblethingslab.com>
  7. #
  8. # This library is free software; you can redistribute it and/or
  9. # modify it under the terms of the GNU Lesser General Public
  10. # License as published by the Free Software Foundation; either
  11. # version 2.1 of the License, or (at your option) any later version.
  12. #
  13. # This library is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  16. # Lesser General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU Lesser General Public
  19. # License along with this library; if not, see <https://www.gnu.org/licenses/>.
  20. import os
  21. import qubes.ext.core_features
  22. import qubes.ext.services
  23. import qubes.ext.windows
  24. import qubes.tests
  25. from unittest import mock
  26. class TC_00_CoreFeatures(qubes.tests.QubesTestCase):
  27. def setUp(self):
  28. super().setUp()
  29. self.ext = qubes.ext.core_features.CoreFeatures()
  30. self.vm = mock.MagicMock()
  31. self.features = {}
  32. self.vm.configure_mock(**{
  33. 'features.get.side_effect': self.features.get,
  34. 'features.items.side_effect': self.features.items,
  35. 'features.__iter__.side_effect': self.features.__iter__,
  36. 'features.__contains__.side_effect': self.features.__contains__,
  37. 'features.__setitem__.side_effect': self.features.__setitem__,
  38. 'features.__delitem__.side_effect': self.features.__delitem__,
  39. })
  40. def test_010_notify_tools(self):
  41. del self.vm.template
  42. self.loop.run_until_complete(
  43. self.ext.qubes_features_request(self.vm, 'features-request',
  44. untrusted_features={
  45. 'gui': '1',
  46. 'version': '1',
  47. 'default-user': 'user',
  48. 'qrexec': '1',
  49. 'vmexec': '1'}))
  50. self.assertListEqual(self.vm.mock_calls, [
  51. ('features.get', ('qrexec', False), {}),
  52. ('features.__contains__', ('qrexec',), {}),
  53. ('features.__setitem__', ('qrexec', True), {}),
  54. ('features.__contains__', ('gui',), {}),
  55. ('features.__setitem__', ('gui', True), {}),
  56. ('features.__setitem__', ('vmexec', True), {}),
  57. ('features.get', ('qrexec', False), {}),
  58. ('fire_event_async', ('template-postinstall',), {}),
  59. ('fire_event_async().__iter__', (), {}),
  60. ])
  61. def test_011_notify_tools_uninstall(self):
  62. del self.vm.template
  63. self.loop.run_until_complete(
  64. self.ext.qubes_features_request(self.vm, 'features-request',
  65. untrusted_features={
  66. 'gui': '0',
  67. 'version': '1',
  68. 'default-user': 'user',
  69. 'qrexec': '0',
  70. 'vmexec': '0'}))
  71. self.assertListEqual(self.vm.mock_calls, [
  72. ('features.get', ('qrexec', False), {}),
  73. ('features.__contains__', ('qrexec',), {}),
  74. ('features.__setitem__', ('qrexec', False), {}),
  75. ('features.__contains__', ('gui',), {}),
  76. ('features.__setitem__', ('gui', False), {}),
  77. ('features.__setitem__', ('vmexec', False), {}),
  78. ('features.get', ('qrexec', False), {}),
  79. ])
  80. def test_012_notify_tools_uninstall2(self):
  81. del self.vm.template
  82. self.loop.run_until_complete(
  83. self.ext.qubes_features_request(self.vm, 'features-request',
  84. untrusted_features={
  85. 'version': '1',
  86. 'default-user': 'user',
  87. }))
  88. self.assertListEqual(self.vm.mock_calls, [
  89. ('features.get', ('qrexec', False), {}),
  90. ('features.get', ('qrexec', False), {}),
  91. ])
  92. def test_013_notify_tools_no_version(self):
  93. del self.vm.template
  94. self.loop.run_until_complete(
  95. self.ext.qubes_features_request(self.vm, 'features-request',
  96. untrusted_features={
  97. 'qrexec': '1',
  98. 'gui': '1',
  99. 'default-user': 'user',
  100. }))
  101. self.assertListEqual(self.vm.mock_calls, [
  102. ('features.get', ('qrexec', False), {}),
  103. ('features.__contains__', ('qrexec',), {}),
  104. ('features.__setitem__', ('qrexec', True), {}),
  105. ('features.__contains__', ('gui',), {}),
  106. ('features.__setitem__', ('gui', True), {}),
  107. ('features.get', ('qrexec', False), {}),
  108. ('fire_event_async', ('template-postinstall',), {}),
  109. ('fire_event_async().__iter__', (), {}),
  110. ])
  111. def test_015_notify_tools_invalid_value_qrexec(self):
  112. del self.vm.template
  113. self.loop.run_until_complete(
  114. self.ext.qubes_features_request(self.vm, 'features-request',
  115. untrusted_features={
  116. 'version': '1',
  117. 'qrexec': 'invalid',
  118. 'gui': '1',
  119. 'default-user': 'user',
  120. }))
  121. self.assertEqual(self.vm.mock_calls, [
  122. ('features.get', ('qrexec', False), {}),
  123. ('features.__contains__', ('gui',), {}),
  124. ('features.__setitem__', ('gui', True), {}),
  125. ('features.get', ('qrexec', False), {}),
  126. ])
  127. def test_016_notify_tools_invalid_value_gui(self):
  128. del self.vm.template
  129. self.loop.run_until_complete(
  130. self.ext.qubes_features_request(self.vm, 'features-request',
  131. untrusted_features={
  132. 'version': '1',
  133. 'qrexec': '1',
  134. 'gui': 'invalid',
  135. 'default-user': 'user',
  136. }))
  137. self.assertListEqual(self.vm.mock_calls, [
  138. ('features.get', ('qrexec', False), {}),
  139. ('features.__contains__', ('qrexec',), {}),
  140. ('features.__setitem__', ('qrexec', True), {}),
  141. ('features.get', ('qrexec', False), {}),
  142. ('fire_event_async', ('template-postinstall',), {}),
  143. ('fire_event_async().__iter__', (), {}),
  144. ])
  145. def test_017_notify_tools_template_based(self):
  146. self.loop.run_until_complete(
  147. self.ext.qubes_features_request(self.vm, 'features-request',
  148. untrusted_features={
  149. 'version': '1',
  150. 'qrexec': '1',
  151. 'gui': '1',
  152. 'default-user': 'user',
  153. }))
  154. self.assertEqual(self.vm.mock_calls, [
  155. ('template.__bool__', (), {}),
  156. ('log.warning', ('Ignoring qubes.NotifyTools for template-based '
  157. 'VM',), {})
  158. ])
  159. def test_018_notify_tools_already_installed(self):
  160. self.features['qrexec'] = True
  161. self.features['gui'] = True
  162. del self.vm.template
  163. self.loop.run_until_complete(
  164. self.ext.qubes_features_request(self.vm, 'features-request',
  165. untrusted_features={
  166. 'gui': '1',
  167. 'version': '1',
  168. 'default-user': 'user',
  169. 'qrexec': '1'}))
  170. self.assertListEqual(self.vm.mock_calls, [
  171. ('features.get', ('qrexec', False), {}),
  172. ('features.__contains__', ('qrexec',), {}),
  173. ('features.__contains__', ('gui',), {}),
  174. ])
  175. def test_100_servicevm_feature(self):
  176. self.vm.provides_network = True
  177. self.ext.set_servicevm_feature(self.vm)
  178. self.assertEqual(self.features['servicevm'], 1)
  179. self.vm.provides_network = False
  180. self.ext.set_servicevm_feature(self.vm)
  181. self.assertNotIn('servicevm', self.features)
  182. class TC_10_WindowsFeatures(qubes.tests.QubesTestCase):
  183. def setUp(self):
  184. super().setUp()
  185. self.ext = qubes.ext.windows.WindowsFeatures()
  186. self.vm = mock.MagicMock()
  187. self.features = {}
  188. self.vm.configure_mock(**{
  189. 'features.get.side_effect': self.features.get,
  190. 'features.__contains__.side_effect': self.features.__contains__,
  191. 'features.__setitem__.side_effect': self.features.__setitem__,
  192. })
  193. def test_000_notify_tools_full(self):
  194. del self.vm.template
  195. self.ext.qubes_features_request(self.vm, 'features-request',
  196. untrusted_features={
  197. 'gui': '1',
  198. 'version': '1',
  199. 'default-user': 'user',
  200. 'qrexec': '1',
  201. 'os': 'Windows'})
  202. self.assertEqual(self.vm.mock_calls, [
  203. ('features.__setitem__', ('os', 'Windows'), {}),
  204. ('features.__setitem__', ('rpc-clipboard', True), {}),
  205. ])
  206. def test_001_notify_tools_no_qrexec(self):
  207. del self.vm.template
  208. self.ext.qubes_features_request(self.vm, 'features-request',
  209. untrusted_features={
  210. 'gui': '1',
  211. 'version': '1',
  212. 'default-user': 'user',
  213. 'qrexec': '0',
  214. 'os': 'Windows'})
  215. self.assertEqual(self.vm.mock_calls, [
  216. ('features.__setitem__', ('os', 'Windows'), {}),
  217. ])
  218. def test_002_notify_tools_other_os(self):
  219. del self.vm.template
  220. self.ext.qubes_features_request(self.vm, 'features-request',
  221. untrusted_features={
  222. 'gui': '1',
  223. 'version': '1',
  224. 'default-user': 'user',
  225. 'qrexec': '1',
  226. 'os': 'other'})
  227. self.assertEqual(self.vm.mock_calls, [])
  228. class TC_20_Services(qubes.tests.QubesTestCase):
  229. def setUp(self):
  230. super().setUp()
  231. self.ext = qubes.ext.services.ServicesExtension()
  232. self.features = {}
  233. specs = {
  234. 'features.get.side_effect': self.features.get,
  235. 'features.items.side_effect': self.features.items,
  236. 'features.__iter__.side_effect': self.features.__iter__,
  237. 'features.__contains__.side_effect': self.features.__contains__,
  238. 'features.__setitem__.side_effect': self.features.__setitem__,
  239. 'features.__delitem__.side_effect': self.features.__delitem__,
  240. }
  241. vmspecs = {**specs, **{
  242. 'template': None,
  243. 'maxmem': 1024,
  244. 'is_running.return_value': True,
  245. }}
  246. dom0specs = {**specs, **{
  247. 'name': "dom0",
  248. }}
  249. self.vm = mock.MagicMock()
  250. self.vm.configure_mock(**vmspecs)
  251. self.dom0 = mock.MagicMock()
  252. self.dom0.configure_mock(**dom0specs)
  253. def test_000_write_to_qdb(self):
  254. self.features['service.test1'] = '1'
  255. self.features['service.test2'] = ''
  256. self.ext.on_domain_qdb_create(self.vm, 'domain-qdb-create')
  257. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), [
  258. ('write', ('/qubes-service/meminfo-writer', '1'), {}),
  259. ('write', ('/qubes-service/test1', '1'), {}),
  260. ('write', ('/qubes-service/test2', '0'), {}),
  261. ])
  262. def test_001_feature_set(self):
  263. self.ext.on_domain_feature_set(self.vm,
  264. 'feature-set:service.test_no_oldvalue',
  265. 'service.test_no_oldvalue', '1')
  266. self.ext.on_domain_feature_set(self.vm,
  267. 'feature-set:service.test_oldvalue',
  268. 'service.test_oldvalue', '1', '')
  269. self.ext.on_domain_feature_set(self.vm,
  270. 'feature-set:service.test_disable',
  271. 'service.test_disable', '', '1')
  272. self.ext.on_domain_feature_set(self.vm,
  273. 'feature-set:service.test_disable_no_oldvalue',
  274. 'service.test_disable_no_oldvalue', '')
  275. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), sorted([
  276. ('write', ('/qubes-service/test_no_oldvalue', '1'), {}),
  277. ('write', ('/qubes-service/test_oldvalue', '1'), {}),
  278. ('write', ('/qubes-service/test_disable', '0'), {}),
  279. ('write', ('/qubes-service/test_disable_no_oldvalue', '0'), {}),
  280. ]))
  281. def test_002_feature_delete(self):
  282. self.ext.on_domain_feature_delete(self.vm,
  283. 'feature-delete:service.test3', 'service.test3')
  284. self.assertEqual(sorted(self.vm.untrusted_qdb.mock_calls), [
  285. ('rm', ('/qubes-service/test3',), {}),
  286. ])
  287. def test_010_supported_services(self):
  288. self.ext.supported_services(self.vm, 'features-request',
  289. untrusted_features={
  290. 'supported-service.test1': '1', # ok
  291. 'supported-service.test2': '0', # ignored
  292. 'supported-service.test3': 'some text', # ignored
  293. 'no-service': '1', # ignored
  294. })
  295. self.assertEqual(self.features, {
  296. 'supported-service.test1': True,
  297. })
  298. def test_011_supported_services_add(self):
  299. self.features['supported-service.test1'] = '1'
  300. self.ext.supported_services(self.vm, 'features-request',
  301. untrusted_features={
  302. 'supported-service.test1': '1', # ok
  303. 'supported-service.test2': '1', # ok
  304. })
  305. # also check if existing one is untouched
  306. self.assertEqual(self.features, {
  307. 'supported-service.test1': '1',
  308. 'supported-service.test2': True,
  309. })
  310. def test_012_supported_services_remove(self):
  311. self.features['supported-service.test1'] = '1'
  312. self.ext.supported_services(self.vm, 'features-request',
  313. untrusted_features={
  314. 'supported-service.test2': '1', # ok
  315. })
  316. self.assertEqual(self.features, {
  317. 'supported-service.test2': True,
  318. })
  319. def test_013_feature_set_dom0(self):
  320. self.test_base_dir = '/tmp/qubes-test-dir'
  321. self.base_dir_patch = mock.patch.dict(
  322. qubes.config.system_path, {'dom0_services_dir': self.test_base_dir})
  323. self.base_dir_patch.start()
  324. self.addCleanup(self.base_dir_patch.stop)
  325. service = 'guivm-gui-agent'
  326. service_path = self.test_base_dir + '/' + service
  327. self.ext.on_domain_feature_set(
  328. self.dom0,
  329. 'feature-set:service.service.guivm-gui-agent',
  330. 'service.guivm-gui-agent', '1')
  331. self.assertEqual(os.path.exists(service_path), True)
  332. def test_014_feature_delete_dom0(self):
  333. self.test_base_dir = '/tmp/qubes-test-dir'
  334. self.base_dir_patch = mock.patch.dict(
  335. qubes.config.system_path, {'dom0_services_dir': self.test_base_dir})
  336. self.base_dir_patch.start()
  337. self.addCleanup(self.base_dir_patch.stop)
  338. service = 'guivm-gui-agent'
  339. service_path = self.test_base_dir + '/' + service
  340. self.ext.on_domain_feature_set(
  341. self.dom0,
  342. 'feature-set:service.service.guivm-gui-agent',
  343. 'service.guivm-gui-agent', '1')
  344. self.ext.on_domain_feature_delete(
  345. self.dom0,
  346. 'feature-delete:service.service.guivm-gui-agent',
  347. 'service.guivm-gui-agent')
  348. self.assertEqual(os.path.exists(service_path), False)
  349. def test_014_feature_set_empty_value_dom0(self):
  350. self.test_base_dir = '/tmp/qubes-test-dir'
  351. self.base_dir_patch = mock.patch.dict(
  352. qubes.config.system_path, {'dom0_services_dir': self.test_base_dir})
  353. self.base_dir_patch.start()
  354. self.addCleanup(self.base_dir_patch.stop)
  355. service = 'guivm-gui-agent'
  356. service_path = self.test_base_dir + '/' + service
  357. self.ext.on_domain_feature_set(
  358. self.dom0,
  359. 'feature-set:service.service.guivm-gui-agent',
  360. 'service.guivm-gui-agent', '')
  361. self.assertEqual(os.path.exists(service_path), False)
  362. class TC_30_SupportedFeatures(qubes.tests.QubesTestCase):
  363. def setUp(self):
  364. super().setUp()
  365. self.ext = qubes.ext.supported_features.SupportedFeaturesExtension()
  366. self.features = {}
  367. specs = {
  368. 'features.get.side_effect': self.features.get,
  369. 'features.items.side_effect': self.features.items,
  370. 'features.__iter__.side_effect': self.features.__iter__,
  371. 'features.__contains__.side_effect': self.features.__contains__,
  372. 'features.__setitem__.side_effect': self.features.__setitem__,
  373. 'features.__delitem__.side_effect': self.features.__delitem__,
  374. }
  375. vmspecs = {**specs, **{
  376. 'template': None,
  377. 'maxmem': 1024,
  378. 'is_running.return_value': True,
  379. }}
  380. dom0specs = {**specs, **{
  381. 'name': "dom0",
  382. }}
  383. self.vm = mock.MagicMock()
  384. self.vm.configure_mock(**vmspecs)
  385. self.dom0 = mock.MagicMock()
  386. self.dom0.configure_mock(**dom0specs)
  387. def test_010_supported_features(self):
  388. self.ext.supported_features(self.vm, 'features-request',
  389. untrusted_features={
  390. 'supported-feature.test1': '1', # ok
  391. 'supported-feature.test2': '0', # ignored
  392. 'supported-feature.test3': 'some text', # ignored
  393. 'no-feature': '1', # ignored
  394. })
  395. self.assertEqual(self.features, {
  396. 'supported-feature.test1': True,
  397. })
  398. def test_011_supported_features_add(self):
  399. self.features['supported-feature.test1'] = '1'
  400. self.ext.supported_features(self.vm, 'features-request',
  401. untrusted_features={
  402. 'supported-feature.test1': '1', # ok
  403. 'supported-feature.test2': '1', # ok
  404. })
  405. # also check if existing one is untouched
  406. self.assertEqual(self.features, {
  407. 'supported-feature.test1': '1',
  408. 'supported-feature.test2': True,
  409. })
  410. def test_012_supported_features_remove(self):
  411. self.features['supported-feature.test1'] = '1'
  412. self.ext.supported_features(self.vm, 'features-request',
  413. untrusted_features={
  414. 'supported-feature.test2': '1', # ok
  415. })
  416. self.assertEqual(self.features, {
  417. 'supported-feature.test2': True,
  418. })