 be7c079705
			
		
	
	
		be7c079705
		
	
	
	
	
		
			
			Actually looks like this solve problem, don't know why (cleaning as user didn't returned any error).
		
			
				
	
	
		
			100 lines
		
	
	
		
			3.6 KiB
		
	
	
	
		
			Python
		
	
	
		
			Executable File
		
	
	
	
	
			
		
		
	
	
			100 lines
		
	
	
		
			3.6 KiB
		
	
	
	
		
			Python
		
	
	
		
			Executable File
		
	
	
	
	
| #!/usr/bin/python2.6
 | |
| #
 | |
| # The Qubes OS Project, http://www.qubes-os.org
 | |
| #
 | |
| # Copyright (C) 2010  Rafal Wojtczuk  <rafal@invisiblethingslab.com>
 | |
| #
 | |
| # This program is free software; you can redistribute it and/or
 | |
| # modify it under the terms of the GNU General Public License
 | |
| # as published by the Free Software Foundation; either version 2
 | |
| # of the License, or (at your option) any later version.
 | |
| #
 | |
| # This program is distributed in the hope that it will be useful,
 | |
| # but WITHOUT ANY WARRANTY; without even the implied warranty of
 | |
| # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | |
| # GNU General Public License for more details.
 | |
| #
 | |
| # You should have received a copy of the GNU General Public License
 | |
| # along with this program; if not, write to the Free Software
 | |
| # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.
 | |
| #
 | |
| #
 | |
| import os
 | |
| import os.path
 | |
| import re
 | |
| import sys
 | |
| import subprocess
 | |
| import shutil
 | |
| import glob
 | |
| import grp
 | |
| from qubes.qubes import QubesVmCollection
 | |
| 
 | |
| updates_dir = "/var/lib/qubes/updates"
 | |
| updates_rpm_dir = updates_dir + "/rpm"
 | |
| updates_repodata_dir = updates_dir + "/repodata"
 | |
| 
 | |
| package_regex = re.compile(r"^[abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789._+-]{1,128}.rpm$")
 | |
| gpg_ok_regex = re.compile(r"pgp md5 OK$")
 | |
| 
 | |
| def dom0updates_fatal(msg):
 | |
|     print >> sys.stderr, msg
 | |
|     shutil.rmtree(updates_rpm_dir)
 | |
|     exit(1)
 | |
| 
 | |
| def handle_dom0updates(updatevm):
 | |
|     source=os.getenv("QREXEC_REMOTE_DOMAIN")
 | |
|     if source != updatevm.name:
 | |
|         print >> sys.stderr, 'Domain ' + source + ' not allowed to send dom0 updates'
 | |
|         exit(1)
 | |
|     # Clean old packages
 | |
|     if os.path.exists(updates_rpm_dir):
 | |
|         shutil.rmtree(updates_rpm_dir)
 | |
|     if os.path.exists(updates_repodata_dir):
 | |
|         shutil.rmtree(updates_repodata_dir)
 | |
|     qubes_gid = grp.getgrnam('qubes').gr_gid
 | |
|     os.mkdir(updates_rpm_dir)
 | |
|     os.chown(updates_rpm_dir, -1, qubes_gid)
 | |
|     os.chmod(updates_rpm_dir, 0775)
 | |
|     subprocess.check_call(["/usr/lib/qubes/qfile-dom0-unpacker", str(os.getuid()), updates_rpm_dir])
 | |
|     # Verify received files
 | |
|     for f in os.listdir(updates_rpm_dir):
 | |
|         full_path = updates_rpm_dir + "/" + f
 | |
|         if package_regex.match(f):
 | |
|             if os.path.islink(full_path) or not os.path.isfile(full_path):
 | |
|                 dom0updates_fatal('Domain ' + source + ' sent not regular file')
 | |
|             p = subprocess.Popen (["/bin/rpm", "-K", full_path],
 | |
|                     stdout=subprocess.PIPE)
 | |
|             output = p.communicate()[0]
 | |
|             if p.returncode != 0:
 | |
|                 dom0updates_fatal('Error while verifing %s signature: %s' % (f, output))
 | |
|             if not gpg_ok_regex.search(output.strip()):
 | |
|                 dom0updates_fatal('Domain ' + source + ' sent not signed rpm: ' + f)
 | |
|         else:
 | |
|             dom0updates_fatal('Domain ' + source + ' sent unexpected file: ' + f)
 | |
|     # After updates received - create repo metadata
 | |
|     subprocess.check_call(["/usr/bin/createrepo", "-q", updates_dir])
 | |
|     os.chown(updates_repodata_dir, -1, qubes_gid)
 | |
|     os.chmod(updates_repodata_dir, 0775)
 | |
|     # Clean old cache
 | |
|     subprocess.call(["sudo", "/usr/bin/yum", "-q", "clean", "all"], stdout=sys.stderr)
 | |
|     # This will fail because of "smart" detection of no-network, but it will invalidate the cache
 | |
|     try:
 | |
|         null = open('/dev/null','w')
 | |
|         subprocess.call(["/usr/bin/pkcon", "refresh"], stdout=null)
 | |
|         null.close()
 | |
|     except:
 | |
|         pass
 | |
|     exit(0)
 | |
| 
 | |
| def main():
 | |
| 
 | |
|     qvm_collection = QubesVmCollection()
 | |
|     qvm_collection.lock_db_for_reading()
 | |
|     qvm_collection.load()
 | |
|     qvm_collection.unlock_db()
 | |
|     
 | |
|     updatevm = qvm_collection.get_updatevm_vm()
 | |
|     handle_dom0updates(updatevm)
 | |
| 
 | |
| main()
 |