api_admin.py 82 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908
  1. # -*- encoding: utf8 -*-
  2. #
  3. # The Qubes OS Project, http://www.qubes-os.org
  4. #
  5. # Copyright (C) 2017 Marek Marczykowski-Górecki
  6. # <marmarek@invisiblethingslab.com>
  7. #
  8. # This program is free software; you can redistribute it and/or modify
  9. # it under the terms of the GNU General Public License as published by
  10. # the Free Software Foundation; either version 2 of the License, or
  11. # (at your option) any later version.
  12. #
  13. # This program is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. # GNU General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU General Public License along
  19. # with this program; if not, see <http://www.gnu.org/licenses/>.
  20. ''' Tests for management calls endpoints '''
  21. import asyncio
  22. import os
  23. import shutil
  24. import unittest.mock
  25. import libvirt
  26. import qubes
  27. import qubes.devices
  28. import qubes.api.admin
  29. import qubes.tests
  30. # properties defined in API
  31. volume_properties = [
  32. 'pool', 'vid', 'size', 'usage', 'rw', 'internal', 'source',
  33. 'save_on_stop', 'snap_on_start']
  34. class AdminAPITestCase(qubes.tests.QubesTestCase):
  35. def setUp(self):
  36. super().setUp()
  37. app = qubes.Qubes('/tmp/qubes-test.xml', load=False)
  38. app.vmm = unittest.mock.Mock(spec=qubes.app.VMMConnection)
  39. app.load_initial_values()
  40. app.default_kernel = '1.0'
  41. app.default_netvm = None
  42. self.template = app.add_new_vm('TemplateVM', label='black',
  43. name='test-template')
  44. app.default_template = 'test-template'
  45. with qubes.tests.substitute_entry_points('qubes.storage',
  46. 'qubes.tests.storage'):
  47. app.add_pool('test', driver='test')
  48. app.save = unittest.mock.Mock()
  49. self.vm = app.add_new_vm('AppVM', label='red', name='test-vm1',
  50. template='test-template')
  51. self.app = app
  52. libvirt_attrs = {
  53. 'libvirt_conn.lookupByUUID.return_value.isActive.return_value':
  54. False,
  55. 'libvirt_conn.lookupByUUID.return_value.state.return_value':
  56. [libvirt.VIR_DOMAIN_SHUTOFF],
  57. }
  58. app.vmm.configure_mock(**libvirt_attrs)
  59. self.emitter = qubes.tests.TestEmitter()
  60. self.app.domains[0].fire_event = self.emitter.fire_event
  61. self.app.domains[0].fire_event_pre = self.emitter.fire_event_pre
  62. self.test_base_dir = '/tmp/qubes-test-dir'
  63. self.base_dir_patch = unittest.mock.patch.dict(qubes.config.system_path,
  64. {'qubes_base_dir': self.test_base_dir})
  65. self.base_dir_patch.start()
  66. def tearDown(self):
  67. self.base_dir_patch.stop()
  68. if os.path.exists(self.test_base_dir):
  69. shutil.rmtree(self.test_base_dir)
  70. super(AdminAPITestCase, self).tearDown()
  71. def call_mgmt_func(self, method, dest, arg=b'', payload=b''):
  72. mgmt_obj = qubes.api.admin.QubesAdminAPI(self.app, b'dom0', method, dest, arg)
  73. loop = asyncio.get_event_loop()
  74. response = loop.run_until_complete(
  75. mgmt_obj.execute(untrusted_payload=payload))
  76. self.assertEventFired(self.emitter,
  77. 'mgmt-permission:' + method.decode('ascii'))
  78. return response
  79. class TC_00_VMs(AdminAPITestCase):
  80. def test_000_vm_list(self):
  81. value = self.call_mgmt_func(b'admin.vm.List', b'dom0')
  82. self.assertEqual(value,
  83. 'dom0 class=AdminVM state=Running\n'
  84. 'test-template class=TemplateVM state=Halted\n'
  85. 'test-vm1 class=AppVM state=Halted\n')
  86. def test_001_vm_list_single(self):
  87. value = self.call_mgmt_func(b'admin.vm.List', b'test-vm1')
  88. self.assertEqual(value,
  89. 'test-vm1 class=AppVM state=Halted\n')
  90. def test_010_vm_property_list(self):
  91. # this test is kind of stupid, but at least check if appropriate
  92. # mgmt-permission event is fired
  93. value = self.call_mgmt_func(b'admin.vm.property.List', b'test-vm1')
  94. properties = self.app.domains['test-vm1'].property_list()
  95. self.assertEqual(value,
  96. ''.join('{}\n'.format(prop.__name__) for prop in properties))
  97. def test_020_vm_property_get_str(self):
  98. value = self.call_mgmt_func(b'admin.vm.property.Get', b'test-vm1',
  99. b'name')
  100. self.assertEqual(value, 'default=False type=str test-vm1')
  101. def test_021_vm_property_get_int(self):
  102. value = self.call_mgmt_func(b'admin.vm.property.Get', b'test-vm1',
  103. b'vcpus')
  104. self.assertEqual(value, 'default=True type=int 42')
  105. def test_022_vm_property_get_bool(self):
  106. value = self.call_mgmt_func(b'admin.vm.property.Get', b'test-vm1',
  107. b'provides_network')
  108. self.assertEqual(value, 'default=True type=bool False')
  109. def test_023_vm_property_get_label(self):
  110. value = self.call_mgmt_func(b'admin.vm.property.Get', b'test-vm1',
  111. b'label')
  112. self.assertEqual(value, 'default=False type=label red')
  113. def test_024_vm_property_get_vm(self):
  114. value = self.call_mgmt_func(b'admin.vm.property.Get', b'test-vm1',
  115. b'template')
  116. self.assertEqual(value, 'default=False type=vm test-template')
  117. def test_025_vm_property_get_vm_none(self):
  118. value = self.call_mgmt_func(b'admin.vm.property.Get', b'test-vm1',
  119. b'netvm')
  120. self.assertEqual(value, 'default=True type=vm ')
  121. def test_030_vm_property_set_vm(self):
  122. netvm = self.app.add_new_vm('AppVM', label='red', name='test-net',
  123. template='test-template', provides_network=True)
  124. with unittest.mock.patch('qubes.vm.VMProperty.__set__') as mock:
  125. value = self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  126. b'netvm', b'test-net')
  127. self.assertIsNone(value)
  128. mock.assert_called_once_with(self.vm, 'test-net')
  129. self.app.save.assert_called_once_with()
  130. def test_032_vm_property_set_vm_invalid1(self):
  131. with unittest.mock.patch('qubes.vm.VMProperty.__set__') as mock:
  132. with self.assertRaises(qubes.exc.QubesValueError):
  133. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  134. b'netvm', b'forbidden-chars/../!')
  135. self.assertFalse(mock.called)
  136. self.assertFalse(self.app.save.called)
  137. def test_033_vm_property_set_vm_invalid2(self):
  138. with unittest.mock.patch('qubes.vm.VMProperty.__set__') as mock:
  139. with self.assertRaises(qubes.exc.QubesValueError):
  140. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  141. b'netvm', b'\x80\x90\xa0')
  142. self.assertFalse(mock.called)
  143. self.assertFalse(self.app.save.called)
  144. def test_034_vm_propert_set_bool_true(self):
  145. with unittest.mock.patch('qubes.property.__set__') as mock:
  146. value = self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  147. b'autostart', b'True')
  148. self.assertIsNone(value)
  149. mock.assert_called_once_with(self.vm, True)
  150. self.app.save.assert_called_once_with()
  151. def test_035_vm_propert_set_bool_false(self):
  152. with unittest.mock.patch('qubes.property.__set__') as mock:
  153. value = self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  154. b'autostart', b'False')
  155. self.assertIsNone(value)
  156. mock.assert_called_once_with(self.vm, False)
  157. self.app.save.assert_called_once_with()
  158. def test_036_vm_propert_set_bool_invalid1(self):
  159. with unittest.mock.patch('qubes.property.__set__') as mock:
  160. with self.assertRaises(qubes.exc.QubesValueError):
  161. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  162. b'autostart', b'some string')
  163. self.assertFalse(mock.called)
  164. self.assertFalse(self.app.save.called)
  165. def test_037_vm_propert_set_bool_invalid2(self):
  166. with unittest.mock.patch('qubes.property.__set__') as mock:
  167. with self.assertRaises(qubes.exc.QubesValueError):
  168. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  169. b'autostart', b'\x80\x90@#$%^&*(')
  170. self.assertFalse(mock.called)
  171. self.assertFalse(self.app.save.called)
  172. def test_038_vm_propert_set_str(self):
  173. with unittest.mock.patch('qubes.property.__set__') as mock:
  174. value = self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  175. b'kernel', b'1.0')
  176. self.assertIsNone(value)
  177. mock.assert_called_once_with(self.vm, '1.0')
  178. self.app.save.assert_called_once_with()
  179. def test_039_vm_propert_set_str_invalid1(self):
  180. with unittest.mock.patch('qubes.property.__set__') as mock:
  181. with self.assertRaises(qubes.exc.QubesValueError):
  182. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  183. b'kernel', b'some, non-ASCII: \x80\xd2')
  184. self.assertFalse(mock.called)
  185. self.assertFalse(self.app.save.called)
  186. def test_040_vm_propert_set_int(self):
  187. with unittest.mock.patch('qubes.property.__set__') as mock:
  188. value = self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  189. b'maxmem', b'1024000')
  190. self.assertIsNone(value)
  191. mock.assert_called_once_with(self.vm, 1024000)
  192. self.app.save.assert_called_once_with()
  193. def test_041_vm_propert_set_int_invalid1(self):
  194. with unittest.mock.patch('qubes.property.__set__') as mock:
  195. with self.assertRaises(qubes.exc.QubesValueError):
  196. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  197. b'maxmem', b'fourty two')
  198. self.assertFalse(mock.called)
  199. self.assertFalse(self.app.save.called)
  200. def test_042_vm_propert_set_label(self):
  201. with unittest.mock.patch('qubes.property.__set__') as mock:
  202. value = self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  203. b'label', b'green')
  204. self.assertIsNone(value)
  205. mock.assert_called_once_with(self.vm, 'green')
  206. self.app.save.assert_called_once_with()
  207. def test_043_vm_propert_set_label_invalid1(self):
  208. with unittest.mock.patch('qubes.property.__set__') as mock:
  209. with self.assertRaises(qubes.exc.QubesValueError):
  210. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  211. b'maxmem', b'some, non-ASCII: \x80\xd2')
  212. self.assertFalse(mock.called)
  213. self.assertFalse(self.app.save.called)
  214. @unittest.skip('label existence not checked before actual setter yet')
  215. def test_044_vm_propert_set_label_invalid2(self):
  216. with unittest.mock.patch('qubes.property.__set__') as mock:
  217. with self.assertRaises(qubes.exc.QubesValueError):
  218. self.call_mgmt_func(b'admin.vm.property.Set', b'test-vm1',
  219. b'maxmem', b'non-existing-color')
  220. self.assertFalse(mock.called)
  221. self.assertFalse(self.app.save.called)
  222. def test_050_vm_property_help(self):
  223. value = self.call_mgmt_func(b'admin.vm.property.Help', b'test-vm1',
  224. b'label')
  225. self.assertEqual(value,
  226. 'Colourful label assigned to VM. This is where the colour of the '
  227. 'padlock is set.')
  228. self.assertFalse(self.app.save.called)
  229. def test_052_vm_property_help_invalid_property(self):
  230. with self.assertRaises(AssertionError):
  231. self.call_mgmt_func(b'admin.vm.property.Help', b'test-vm1',
  232. b'no-such-property')
  233. self.assertFalse(self.app.save.called)
  234. def test_060_vm_property_reset(self):
  235. with unittest.mock.patch('qubes.property.__delete__') as mock:
  236. value = self.call_mgmt_func(b'admin.vm.property.Reset', b'test-vm1',
  237. b'default_user')
  238. mock.assert_called_with(self.vm)
  239. self.assertIsNone(value)
  240. self.app.save.assert_called_once_with()
  241. def test_062_vm_property_reset_invalid_property(self):
  242. with unittest.mock.patch('qubes.property.__delete__') as mock:
  243. with self.assertRaises(AssertionError):
  244. self.call_mgmt_func(b'admin.vm.property.Help', b'test-vm1',
  245. b'no-such-property')
  246. self.assertFalse(mock.called)
  247. self.assertFalse(self.app.save.called)
  248. def test_070_vm_volume_list(self):
  249. self.vm.volumes = unittest.mock.Mock()
  250. volumes_conf = {
  251. 'keys.return_value': ['root', 'private', 'volatile', 'kernel']
  252. }
  253. self.vm.volumes.configure_mock(**volumes_conf)
  254. value = self.call_mgmt_func(b'admin.vm.volume.List', b'test-vm1')
  255. self.assertEqual(value, 'root\nprivate\nvolatile\nkernel\n')
  256. # check if _only_ keys were accessed
  257. self.assertEqual(self.vm.volumes.mock_calls,
  258. [unittest.mock.call.keys()])
  259. def test_080_vm_volume_info(self):
  260. self.vm.volumes = unittest.mock.MagicMock()
  261. volumes_conf = {
  262. 'keys.return_value': ['root', 'private', 'volatile', 'kernel']
  263. }
  264. for prop in volume_properties:
  265. volumes_conf[
  266. '__getitem__.return_value.{}'.format(prop)] = prop +'-value'
  267. self.vm.volumes.configure_mock(**volumes_conf)
  268. value = self.call_mgmt_func(b'admin.vm.volume.Info', b'test-vm1',
  269. b'private')
  270. self.assertEqual(value,
  271. ''.join('{p}={p}-value\n'.format(p=p) for p in volume_properties))
  272. self.assertEqual(self.vm.volumes.mock_calls,
  273. [unittest.mock.call.keys(),
  274. unittest.mock.call.__getattr__('__getitem__')('private')])
  275. def test_080_vm_volume_info_invalid_volume(self):
  276. self.vm.volumes = unittest.mock.MagicMock()
  277. volumes_conf = {
  278. 'keys.return_value': ['root', 'private', 'volatile', 'kernel']
  279. }
  280. self.vm.volumes.configure_mock(**volumes_conf)
  281. with self.assertRaises(AssertionError):
  282. self.call_mgmt_func(b'admin.vm.volume.Info', b'test-vm1',
  283. b'no-such-volume')
  284. self.assertEqual(self.vm.volumes.mock_calls,
  285. [unittest.mock.call.keys()])
  286. def test_090_vm_volume_listsnapshots(self):
  287. self.vm.volumes = unittest.mock.MagicMock()
  288. volumes_conf = {
  289. 'keys.return_value': ['root', 'private', 'volatile', 'kernel'],
  290. '__getitem__.return_value.revisions': ['rev1', 'rev2'],
  291. }
  292. self.vm.volumes.configure_mock(**volumes_conf)
  293. value = self.call_mgmt_func(b'admin.vm.volume.ListSnapshots',
  294. b'test-vm1', b'private')
  295. self.assertEqual(value,
  296. 'rev1\nrev2\n')
  297. self.assertEqual(self.vm.volumes.mock_calls,
  298. [unittest.mock.call.keys(),
  299. unittest.mock.call.__getattr__('__getitem__')('private')])
  300. def test_090_vm_volume_listsnapshots_invalid_volume(self):
  301. self.vm.volumes = unittest.mock.MagicMock()
  302. volumes_conf = {
  303. 'keys.return_value': ['root', 'private', 'volatile', 'kernel']
  304. }
  305. self.vm.volumes.configure_mock(**volumes_conf)
  306. with self.assertRaises(AssertionError):
  307. self.call_mgmt_func(b'admin.vm.volume.ListSnapshots', b'test-vm1',
  308. b'no-such-volume')
  309. self.assertEqual(self.vm.volumes.mock_calls,
  310. [unittest.mock.call.keys()])
  311. @unittest.skip('method not implemented yet')
  312. def test_100_vm_volume_snapshot(self):
  313. pass
  314. @unittest.skip('method not implemented yet')
  315. def test_100_vm_volume_snapshot_invlid_volume(self):
  316. self.vm.volumes = unittest.mock.MagicMock()
  317. volumes_conf = {
  318. 'keys.return_value': ['root', 'private', 'volatile', 'kernel'],
  319. '__getitem__.return_value.revisions': ['rev1', 'rev2'],
  320. }
  321. self.vm.volumes.configure_mock(**volumes_conf)
  322. with self.assertRaises(AssertionError):
  323. self.call_mgmt_func(b'admin.vm.volume.Snapshots',
  324. b'test-vm1', b'no-such-volume')
  325. self.assertEqual(self.vm.volumes.mock_calls,
  326. [unittest.mock.call.keys()])
  327. @unittest.skip('method not implemented yet')
  328. def test_100_vm_volume_snapshot_invalid_revision(self):
  329. self.vm.volumes = unittest.mock.MagicMock()
  330. volumes_conf = {
  331. 'keys.return_value': ['root', 'private', 'volatile', 'kernel']
  332. }
  333. self.vm.volumes.configure_mock(**volumes_conf)
  334. with self.assertRaises(AssertionError):
  335. self.call_mgmt_func(b'admin.vm.volume.Snapshots',
  336. b'test-vm1', b'private', b'no-such-rev')
  337. self.assertEqual(self.vm.volumes.mock_calls,
  338. [unittest.mock.call.keys(),
  339. unittest.mock.call.__getattr__('__getitem__')('private')])
  340. def test_110_vm_volume_revert(self):
  341. self.vm.volumes = unittest.mock.MagicMock()
  342. volumes_conf = {
  343. 'keys.return_value': ['root', 'private', 'volatile', 'kernel'],
  344. '__getitem__.return_value.revisions': ['rev1', 'rev2'],
  345. }
  346. self.vm.volumes.configure_mock(**volumes_conf)
  347. self.vm.storage = unittest.mock.Mock()
  348. value = self.call_mgmt_func(b'admin.vm.volume.Revert',
  349. b'test-vm1', b'private', b'rev1')
  350. self.assertIsNone(value)
  351. self.assertEqual(self.vm.volumes.mock_calls,
  352. [unittest.mock.call.keys(),
  353. unittest.mock.call.__getattr__('__getitem__')('private')])
  354. self.assertEqual(self.vm.storage.mock_calls,
  355. [unittest.mock.call.get_pool(self.vm.volumes['private']),
  356. unittest.mock.call.get_pool().revert('rev1')])
  357. def test_110_vm_volume_revert_invalid_rev(self):
  358. self.vm.volumes = unittest.mock.MagicMock()
  359. volumes_conf = {
  360. 'keys.return_value': ['root', 'private', 'volatile', 'kernel'],
  361. '__getitem__.return_value.revisions': ['rev1', 'rev2'],
  362. }
  363. self.vm.volumes.configure_mock(**volumes_conf)
  364. self.vm.storage = unittest.mock.Mock()
  365. with self.assertRaises(AssertionError):
  366. self.call_mgmt_func(b'admin.vm.volume.Revert',
  367. b'test-vm1', b'private', b'no-such-rev')
  368. self.assertEqual(self.vm.volumes.mock_calls,
  369. [unittest.mock.call.keys(),
  370. unittest.mock.call.__getattr__('__getitem__')('private')])
  371. self.assertFalse(self.vm.storage.called)
  372. def test_120_vm_volume_resize(self):
  373. self.vm.volumes = unittest.mock.MagicMock()
  374. volumes_conf = {
  375. 'keys.return_value': ['root', 'private', 'volatile', 'kernel'],
  376. }
  377. self.vm.volumes.configure_mock(**volumes_conf)
  378. self.vm.storage = unittest.mock.Mock()
  379. value = self.call_mgmt_func(b'admin.vm.volume.Resize',
  380. b'test-vm1', b'private', b'1024000000')
  381. self.assertIsNone(value)
  382. self.assertEqual(self.vm.volumes.mock_calls,
  383. [unittest.mock.call.keys()])
  384. self.assertEqual(self.vm.storage.mock_calls,
  385. [unittest.mock.call.resize('private', 1024000000)])
  386. def test_120_vm_volume_resize_invalid_size1(self):
  387. self.vm.volumes = unittest.mock.MagicMock()
  388. volumes_conf = {
  389. 'keys.return_value': ['root', 'private', 'volatile', 'kernel'],
  390. }
  391. self.vm.volumes.configure_mock(**volumes_conf)
  392. self.vm.storage = unittest.mock.Mock()
  393. with self.assertRaises(AssertionError):
  394. self.call_mgmt_func(b'admin.vm.volume.Resize',
  395. b'test-vm1', b'private', b'no-int-size')
  396. self.assertEqual(self.vm.volumes.mock_calls,
  397. [unittest.mock.call.keys()])
  398. self.assertFalse(self.vm.storage.called)
  399. def test_120_vm_volume_resize_invalid_size2(self):
  400. self.vm.volumes = unittest.mock.MagicMock()
  401. volumes_conf = {
  402. 'keys.return_value': ['root', 'private', 'volatile', 'kernel'],
  403. }
  404. self.vm.volumes.configure_mock(**volumes_conf)
  405. self.vm.storage = unittest.mock.Mock()
  406. with self.assertRaises(AssertionError):
  407. self.call_mgmt_func(b'admin.vm.volume.Resize',
  408. b'test-vm1', b'private', b'-1')
  409. self.assertEqual(self.vm.volumes.mock_calls,
  410. [unittest.mock.call.keys()])
  411. self.assertFalse(self.vm.storage.called)
  412. def test_130_pool_list(self):
  413. self.app.pools = ['file', 'lvm']
  414. value = self.call_mgmt_func(b'admin.pool.List', b'dom0')
  415. self.assertEqual(value, 'file\nlvm\n')
  416. self.assertFalse(self.app.save.called)
  417. @unittest.mock.patch('qubes.storage.pool_drivers')
  418. @unittest.mock.patch('qubes.storage.driver_parameters')
  419. def test_140_pool_listdrivers(self, mock_parameters, mock_drivers):
  420. self.app.pools = ['file', 'lvm']
  421. mock_drivers.return_value = ['driver1', 'driver2']
  422. mock_parameters.side_effect = \
  423. lambda driver: {
  424. 'driver1': ['param1', 'param2'],
  425. 'driver2': ['param3', 'param4']
  426. }[driver]
  427. value = self.call_mgmt_func(b'admin.pool.ListDrivers', b'dom0')
  428. self.assertEqual(value,
  429. 'driver1 param1 param2\ndriver2 param3 param4\n')
  430. self.assertEqual(mock_drivers.mock_calls, [unittest.mock.call()])
  431. self.assertEqual(mock_parameters.mock_calls,
  432. [unittest.mock.call('driver1'), unittest.mock.call('driver2')])
  433. self.assertFalse(self.app.save.called)
  434. def test_150_pool_info(self):
  435. self.app.pools = {
  436. 'pool1': unittest.mock.Mock(config={
  437. 'param1': 'value1', 'param2': 'value2'})
  438. }
  439. value = self.call_mgmt_func(b'admin.pool.Info', b'dom0', b'pool1')
  440. self.assertEqual(value, 'param1=value1\nparam2=value2\n')
  441. self.assertFalse(self.app.save.called)
  442. @unittest.mock.patch('qubes.storage.pool_drivers')
  443. @unittest.mock.patch('qubes.storage.driver_parameters')
  444. def test_160_pool_add(self, mock_parameters, mock_drivers):
  445. self.app.pools = {
  446. 'file': unittest.mock.Mock(),
  447. 'lvm': unittest.mock.Mock()
  448. }
  449. mock_drivers.return_value = ['driver1', 'driver2']
  450. mock_parameters.side_effect = \
  451. lambda driver: {
  452. 'driver1': ['param1', 'param2'],
  453. 'driver2': ['param3', 'param4']
  454. }[driver]
  455. self.app.add_pool = unittest.mock.Mock()
  456. value = self.call_mgmt_func(b'admin.pool.Add', b'dom0', b'driver1',
  457. b'name=test-pool\nparam1=some-value\n')
  458. self.assertIsNone(value)
  459. self.assertEqual(mock_drivers.mock_calls, [unittest.mock.call()])
  460. self.assertEqual(mock_parameters.mock_calls,
  461. [unittest.mock.call('driver1')])
  462. self.assertEqual(self.app.add_pool.mock_calls,
  463. [unittest.mock.call(name='test-pool', driver='driver1',
  464. param1='some-value')])
  465. self.assertTrue(self.app.save.called)
  466. @unittest.mock.patch('qubes.storage.pool_drivers')
  467. @unittest.mock.patch('qubes.storage.driver_parameters')
  468. def test_160_pool_add_invalid_driver(self, mock_parameters, mock_drivers):
  469. self.app.pools = {
  470. 'file': unittest.mock.Mock(),
  471. 'lvm': unittest.mock.Mock()
  472. }
  473. mock_drivers.return_value = ['driver1', 'driver2']
  474. mock_parameters.side_effect = \
  475. lambda driver: {
  476. 'driver1': ['param1', 'param2'],
  477. 'driver2': ['param3', 'param4']
  478. }[driver]
  479. self.app.add_pool = unittest.mock.Mock()
  480. with self.assertRaises(AssertionError):
  481. self.call_mgmt_func(b'admin.pool.Add', b'dom0',
  482. b'no-such-driver', b'name=test-pool\nparam1=some-value\n')
  483. self.assertEqual(mock_drivers.mock_calls, [unittest.mock.call()])
  484. self.assertEqual(mock_parameters.mock_calls, [])
  485. self.assertEqual(self.app.add_pool.mock_calls, [])
  486. self.assertFalse(self.app.save.called)
  487. @unittest.mock.patch('qubes.storage.pool_drivers')
  488. @unittest.mock.patch('qubes.storage.driver_parameters')
  489. def test_160_pool_add_invalid_param(self, mock_parameters, mock_drivers):
  490. self.app.pools = {
  491. 'file': unittest.mock.Mock(),
  492. 'lvm': unittest.mock.Mock()
  493. }
  494. mock_drivers.return_value = ['driver1', 'driver2']
  495. mock_parameters.side_effect = \
  496. lambda driver: {
  497. 'driver1': ['param1', 'param2'],
  498. 'driver2': ['param3', 'param4']
  499. }[driver]
  500. self.app.add_pool = unittest.mock.Mock()
  501. with self.assertRaises(AssertionError):
  502. self.call_mgmt_func(b'admin.pool.Add', b'dom0',
  503. b'driver1', b'name=test-pool\nparam3=some-value\n')
  504. self.assertEqual(mock_drivers.mock_calls, [unittest.mock.call()])
  505. self.assertEqual(mock_parameters.mock_calls,
  506. [unittest.mock.call('driver1')])
  507. self.assertEqual(self.app.add_pool.mock_calls, [])
  508. self.assertFalse(self.app.save.called)
  509. @unittest.mock.patch('qubes.storage.pool_drivers')
  510. @unittest.mock.patch('qubes.storage.driver_parameters')
  511. def test_160_pool_add_missing_name(self, mock_parameters, mock_drivers):
  512. self.app.pools = {
  513. 'file': unittest.mock.Mock(),
  514. 'lvm': unittest.mock.Mock()
  515. }
  516. mock_drivers.return_value = ['driver1', 'driver2']
  517. mock_parameters.side_effect = \
  518. lambda driver: {
  519. 'driver1': ['param1', 'param2'],
  520. 'driver2': ['param3', 'param4']
  521. }[driver]
  522. self.app.add_pool = unittest.mock.Mock()
  523. with self.assertRaises(AssertionError):
  524. self.call_mgmt_func(b'admin.pool.Add', b'dom0',
  525. b'driver1', b'param1=value\nparam2=some-value\n')
  526. self.assertEqual(mock_drivers.mock_calls, [unittest.mock.call()])
  527. self.assertEqual(mock_parameters.mock_calls, [])
  528. self.assertEqual(self.app.add_pool.mock_calls, [])
  529. self.assertFalse(self.app.save.called)
  530. @unittest.mock.patch('qubes.storage.pool_drivers')
  531. @unittest.mock.patch('qubes.storage.driver_parameters')
  532. def test_160_pool_add_existing_pool(self, mock_parameters, mock_drivers):
  533. self.app.pools = {
  534. 'file': unittest.mock.Mock(),
  535. 'lvm': unittest.mock.Mock()
  536. }
  537. mock_drivers.return_value = ['driver1', 'driver2']
  538. mock_parameters.side_effect = \
  539. lambda driver: {
  540. 'driver1': ['param1', 'param2'],
  541. 'driver2': ['param3', 'param4']
  542. }[driver]
  543. self.app.add_pool = unittest.mock.Mock()
  544. with self.assertRaises(AssertionError):
  545. self.call_mgmt_func(b'admin.pool.Add', b'dom0',
  546. b'driver1', b'name=file\nparam1=value\nparam2=some-value\n')
  547. self.assertEqual(mock_drivers.mock_calls, [unittest.mock.call()])
  548. self.assertEqual(mock_parameters.mock_calls, [])
  549. self.assertEqual(self.app.add_pool.mock_calls, [])
  550. self.assertFalse(self.app.save.called)
  551. @unittest.mock.patch('qubes.storage.pool_drivers')
  552. @unittest.mock.patch('qubes.storage.driver_parameters')
  553. def test_160_pool_add_invalid_config_format(self, mock_parameters,
  554. mock_drivers):
  555. self.app.pools = {
  556. 'file': unittest.mock.Mock(),
  557. 'lvm': unittest.mock.Mock()
  558. }
  559. mock_drivers.return_value = ['driver1', 'driver2']
  560. mock_parameters.side_effect = \
  561. lambda driver: {
  562. 'driver1': ['param1', 'param2'],
  563. 'driver2': ['param3', 'param4']
  564. }[driver]
  565. self.app.add_pool = unittest.mock.Mock()
  566. with self.assertRaises(AssertionError):
  567. self.call_mgmt_func(b'admin.pool.Add', b'dom0',
  568. b'driver1', b'name=test-pool\nparam 1=value\n_param2\n')
  569. self.assertEqual(mock_drivers.mock_calls, [unittest.mock.call()])
  570. self.assertEqual(mock_parameters.mock_calls, [])
  571. self.assertEqual(self.app.add_pool.mock_calls, [])
  572. self.assertFalse(self.app.save.called)
  573. def test_170_pool_remove(self):
  574. self.app.pools = {
  575. 'file': unittest.mock.Mock(),
  576. 'lvm': unittest.mock.Mock(),
  577. 'test-pool': unittest.mock.Mock(),
  578. }
  579. self.app.remove_pool = unittest.mock.Mock()
  580. value = self.call_mgmt_func(b'admin.pool.Remove', b'dom0', b'test-pool')
  581. self.assertIsNone(value)
  582. self.assertEqual(self.app.remove_pool.mock_calls,
  583. [unittest.mock.call('test-pool')])
  584. self.assertTrue(self.app.save.called)
  585. def test_170_pool_remove_invalid_pool(self):
  586. self.app.pools = {
  587. 'file': unittest.mock.Mock(),
  588. 'lvm': unittest.mock.Mock(),
  589. 'test-pool': unittest.mock.Mock(),
  590. }
  591. self.app.remove_pool = unittest.mock.Mock()
  592. with self.assertRaises(AssertionError):
  593. self.call_mgmt_func(b'admin.pool.Remove', b'dom0',
  594. b'no-such-pool')
  595. self.assertEqual(self.app.remove_pool.mock_calls, [])
  596. self.assertFalse(self.app.save.called)
  597. def test_180_label_list(self):
  598. value = self.call_mgmt_func(b'admin.label.List', b'dom0')
  599. self.assertEqual(value,
  600. ''.join('{}\n'.format(l.name) for l in self.app.labels.values()))
  601. self.assertFalse(self.app.save.called)
  602. def test_190_label_get(self):
  603. self.app.get_label = unittest.mock.Mock()
  604. self.app.get_label.configure_mock(**{'return_value.color': '0xff0000'})
  605. value = self.call_mgmt_func(b'admin.label.Get', b'dom0', b'red')
  606. self.assertEqual(value, '0xff0000')
  607. self.assertEqual(self.app.get_label.mock_calls,
  608. [unittest.mock.call('red')])
  609. self.assertFalse(self.app.save.called)
  610. def test_195_label_index(self):
  611. self.app.get_label = unittest.mock.Mock()
  612. self.app.get_label.configure_mock(**{'return_value.index': 1})
  613. value = self.call_mgmt_func(b'admin.label.Index', b'dom0', b'red')
  614. self.assertEqual(value, '1')
  615. self.assertEqual(self.app.get_label.mock_calls,
  616. [unittest.mock.call('red')])
  617. self.assertFalse(self.app.save.called)
  618. def test_200_label_create(self):
  619. self.app.get_label = unittest.mock.Mock()
  620. self.app.get_label.side_effect=KeyError
  621. self.app.labels = unittest.mock.MagicMock()
  622. labels_config = {
  623. 'keys.return_value': range(1, 9),
  624. }
  625. self.app.labels.configure_mock(**labels_config)
  626. value = self.call_mgmt_func(b'admin.label.Create', b'dom0', b'cyan',
  627. b'0x00ffff')
  628. self.assertIsNone(value)
  629. self.assertEqual(self.app.get_label.mock_calls,
  630. [unittest.mock.call('cyan')])
  631. self.assertEqual(self.app.labels.mock_calls,
  632. [unittest.mock.call.keys(),
  633. unittest.mock.call.__getattr__('__setitem__')(9,
  634. qubes.Label(9, '0x00ffff', 'cyan'))])
  635. self.assertTrue(self.app.save.called)
  636. def test_200_label_create_invalid_color(self):
  637. self.app.get_label = unittest.mock.Mock()
  638. self.app.get_label.side_effect=KeyError
  639. self.app.labels = unittest.mock.MagicMock()
  640. labels_config = {
  641. 'keys.return_value': range(1, 9),
  642. }
  643. self.app.labels.configure_mock(**labels_config)
  644. with self.assertRaises(AssertionError):
  645. self.call_mgmt_func(b'admin.label.Create', b'dom0', b'cyan',
  646. b'abcd')
  647. self.assertEqual(self.app.get_label.mock_calls,
  648. [unittest.mock.call('cyan')])
  649. self.assertEqual(self.app.labels.mock_calls, [])
  650. self.assertFalse(self.app.save.called)
  651. def test_200_label_create_invalid_name(self):
  652. self.app.get_label = unittest.mock.Mock()
  653. self.app.get_label.side_effect=KeyError
  654. self.app.labels = unittest.mock.MagicMock()
  655. labels_config = {
  656. 'keys.return_value': range(1, 9),
  657. }
  658. self.app.labels.configure_mock(**labels_config)
  659. with self.assertRaises(AssertionError):
  660. self.call_mgmt_func(b'admin.label.Create', b'dom0', b'01',
  661. b'0xff0000')
  662. with self.assertRaises(AssertionError):
  663. self.call_mgmt_func(b'admin.label.Create', b'dom0', b'../xxx',
  664. b'0xff0000')
  665. with self.assertRaises(AssertionError):
  666. self.call_mgmt_func(b'admin.label.Create', b'dom0',
  667. b'strange-name!@#$',
  668. b'0xff0000')
  669. self.assertEqual(self.app.get_label.mock_calls, [])
  670. self.assertEqual(self.app.labels.mock_calls, [])
  671. self.assertFalse(self.app.save.called)
  672. def test_200_label_create_already_exists(self):
  673. self.app.get_label = unittest.mock.Mock(wraps=self.app.get_label)
  674. with self.assertRaises(qubes.exc.QubesValueError):
  675. self.call_mgmt_func(b'admin.label.Create', b'dom0', b'red',
  676. b'abcd')
  677. self.assertEqual(self.app.get_label.mock_calls,
  678. [unittest.mock.call('red')])
  679. self.assertFalse(self.app.save.called)
  680. def test_210_label_remove(self):
  681. label = qubes.Label(9, '0x00ffff', 'cyan')
  682. self.app.labels[9] = label
  683. self.app.get_label = unittest.mock.Mock(wraps=self.app.get_label,
  684. **{'return_value.index': 9})
  685. self.app.labels = unittest.mock.MagicMock(wraps=self.app.labels)
  686. value = self.call_mgmt_func(b'admin.label.Remove', b'dom0', b'cyan')
  687. self.assertIsNone(value)
  688. self.assertEqual(self.app.get_label.mock_calls,
  689. [unittest.mock.call('cyan')])
  690. self.assertEqual(self.app.labels.mock_calls,
  691. [unittest.mock.call.__delitem__(9)])
  692. self.assertTrue(self.app.save.called)
  693. def test_210_label_remove_invalid_label(self):
  694. with self.assertRaises(qubes.exc.QubesValueError):
  695. self.call_mgmt_func(b'admin.label.Remove', b'dom0',
  696. b'no-such-label')
  697. self.assertFalse(self.app.save.called)
  698. def test_210_label_remove_default_label(self):
  699. self.app.labels = unittest.mock.MagicMock(wraps=self.app.labels)
  700. self.app.get_label = unittest.mock.Mock(wraps=self.app.get_label,
  701. **{'return_value.index': 6})
  702. with self.assertRaises(AssertionError):
  703. self.call_mgmt_func(b'admin.label.Remove', b'dom0',
  704. b'blue')
  705. self.assertEqual(self.app.labels.mock_calls, [])
  706. self.assertFalse(self.app.save.called)
  707. def test_210_label_remove_in_use(self):
  708. self.app.labels = unittest.mock.MagicMock(wraps=self.app.labels)
  709. self.app.get_label = unittest.mock.Mock(wraps=self.app.get_label,
  710. **{'return_value.index': 1})
  711. with self.assertRaises(AssertionError):
  712. self.call_mgmt_func(b'admin.label.Remove', b'dom0',
  713. b'red')
  714. self.assertEqual(self.app.labels.mock_calls, [])
  715. self.assertFalse(self.app.save.called)
  716. def test_220_start(self):
  717. func_mock = unittest.mock.Mock()
  718. @asyncio.coroutine
  719. def coroutine_mock(*args, **kwargs):
  720. return func_mock(*args, **kwargs)
  721. self.vm.start = coroutine_mock
  722. value = self.call_mgmt_func(b'admin.vm.Start', b'test-vm1')
  723. self.assertIsNone(value)
  724. func_mock.assert_called_once_with()
  725. def test_230_shutdown(self):
  726. func_mock = unittest.mock.Mock()
  727. @asyncio.coroutine
  728. def coroutine_mock(*args, **kwargs):
  729. return func_mock(*args, **kwargs)
  730. self.vm.shutdown = coroutine_mock
  731. value = self.call_mgmt_func(b'admin.vm.Shutdown', b'test-vm1')
  732. self.assertIsNone(value)
  733. func_mock.assert_called_once_with()
  734. def test_240_pause(self):
  735. func_mock = unittest.mock.Mock()
  736. @asyncio.coroutine
  737. def coroutine_mock(*args, **kwargs):
  738. return func_mock(*args, **kwargs)
  739. self.vm.pause = coroutine_mock
  740. value = self.call_mgmt_func(b'admin.vm.Pause', b'test-vm1')
  741. self.assertIsNone(value)
  742. func_mock.assert_called_once_with()
  743. def test_250_unpause(self):
  744. func_mock = unittest.mock.Mock()
  745. @asyncio.coroutine
  746. def coroutine_mock(*args, **kwargs):
  747. return func_mock(*args, **kwargs)
  748. self.vm.unpause = coroutine_mock
  749. value = self.call_mgmt_func(b'admin.vm.Unpause', b'test-vm1')
  750. self.assertIsNone(value)
  751. func_mock.assert_called_once_with()
  752. def test_260_kill(self):
  753. func_mock = unittest.mock.Mock()
  754. @asyncio.coroutine
  755. def coroutine_mock(*args, **kwargs):
  756. return func_mock(*args, **kwargs)
  757. self.vm.kill = coroutine_mock
  758. value = self.call_mgmt_func(b'admin.vm.Kill', b'test-vm1')
  759. self.assertIsNone(value)
  760. func_mock.assert_called_once_with()
  761. def test_270_events(self):
  762. send_event = unittest.mock.Mock(spec=[])
  763. mgmt_obj = qubes.api.admin.QubesAdminAPI(self.app, b'dom0', b'admin.Events',
  764. b'dom0', b'', send_event=send_event)
  765. @asyncio.coroutine
  766. def fire_event():
  767. self.vm.fire_event('test-event', arg1='abc')
  768. mgmt_obj.cancel()
  769. loop = asyncio.get_event_loop()
  770. execute_task = asyncio.ensure_future(
  771. mgmt_obj.execute(untrusted_payload=b''))
  772. asyncio.ensure_future(fire_event())
  773. loop.run_until_complete(execute_task)
  774. self.assertIsNone(execute_task.result())
  775. self.assertEventFired(self.emitter,
  776. 'mgmt-permission:' + 'admin.Events')
  777. self.assertEqual(send_event.mock_calls,
  778. [
  779. unittest.mock.call(self.app, 'connection-established'),
  780. unittest.mock.call(self.vm, 'test-event', arg1='abc')
  781. ])
  782. def test_271_events_add_vm(self):
  783. send_event = unittest.mock.Mock(spec=[])
  784. mgmt_obj = qubes.api.admin.QubesAdminAPI(self.app, b'dom0', b'admin.Events',
  785. b'dom0', b'', send_event=send_event)
  786. @asyncio.coroutine
  787. def fire_event():
  788. self.vm.fire_event('test-event', arg1='abc')
  789. # add VM _after_ starting admin.Events call
  790. vm = self.app.add_new_vm('AppVM', label='red', name='test-vm2',
  791. template='test-template')
  792. vm.fire_event('test-event2', arg1='abc')
  793. mgmt_obj.cancel()
  794. return vm
  795. loop = asyncio.get_event_loop()
  796. execute_task = asyncio.ensure_future(
  797. mgmt_obj.execute(untrusted_payload=b''))
  798. event_task = asyncio.ensure_future(fire_event())
  799. loop.run_until_complete(execute_task)
  800. vm2 = event_task.result()
  801. self.assertIsNone(execute_task.result())
  802. self.assertEventFired(self.emitter,
  803. 'mgmt-permission:' + 'admin.Events')
  804. self.assertEqual(send_event.mock_calls,
  805. [
  806. unittest.mock.call(self.app, 'connection-established'),
  807. unittest.mock.call(self.vm, 'test-event', arg1='abc'),
  808. unittest.mock.call(self.app, 'domain-add', vm=vm2),
  809. unittest.mock.call(vm2, 'test-event2', arg1='abc'),
  810. ])
  811. def test_280_feature_list(self):
  812. self.vm.features['test-feature'] = 'some-value'
  813. value = self.call_mgmt_func(b'admin.vm.feature.List', b'test-vm1')
  814. self.assertEqual(value, 'test-feature\n')
  815. self.assertFalse(self.app.save.called)
  816. def test_290_feature_get(self):
  817. self.vm.features['test-feature'] = 'some-value'
  818. value = self.call_mgmt_func(b'admin.vm.feature.Get', b'test-vm1',
  819. b'test-feature')
  820. self.assertEqual(value, 'some-value')
  821. self.assertFalse(self.app.save.called)
  822. def test_291_feature_get_none(self):
  823. with self.assertRaises(qubes.exc.QubesFeatureNotFoundError):
  824. self.call_mgmt_func(b'admin.vm.feature.Get',
  825. b'test-vm1', b'test-feature')
  826. self.assertFalse(self.app.save.called)
  827. def test_300_feature_remove(self):
  828. self.vm.features['test-feature'] = 'some-value'
  829. value = self.call_mgmt_func(b'admin.vm.feature.Remove', b'test-vm1',
  830. b'test-feature')
  831. self.assertIsNone(value, None)
  832. self.assertNotIn('test-feature', self.vm.features)
  833. self.assertTrue(self.app.save.called)
  834. def test_301_feature_remove_none(self):
  835. with self.assertRaises(qubes.exc.QubesFeatureNotFoundError):
  836. self.call_mgmt_func(b'admin.vm.feature.Remove',
  837. b'test-vm1', b'test-feature')
  838. self.assertFalse(self.app.save.called)
  839. def test_310_feature_checkwithtemplate(self):
  840. self.vm.features['test-feature'] = 'some-value'
  841. value = self.call_mgmt_func(b'admin.vm.feature.CheckWithTemplate',
  842. b'test-vm1', b'test-feature')
  843. self.assertEqual(value, 'some-value')
  844. self.assertFalse(self.app.save.called)
  845. def test_311_feature_checkwithtemplate_tpl(self):
  846. self.template.features['test-feature'] = 'some-value'
  847. value = self.call_mgmt_func(b'admin.vm.feature.CheckWithTemplate',
  848. b'test-vm1', b'test-feature')
  849. self.assertEqual(value, 'some-value')
  850. self.assertFalse(self.app.save.called)
  851. def test_312_feature_checkwithtemplate_none(self):
  852. with self.assertRaises(qubes.exc.QubesFeatureNotFoundError):
  853. self.call_mgmt_func(b'admin.vm.feature.CheckWithTemplate',
  854. b'test-vm1', b'test-feature')
  855. self.assertFalse(self.app.save.called)
  856. def test_320_feature_set(self):
  857. value = self.call_mgmt_func(b'admin.vm.feature.Set',
  858. b'test-vm1', b'test-feature', b'some-value')
  859. self.assertIsNone(value)
  860. self.assertEqual(self.vm.features['test-feature'], 'some-value')
  861. self.assertTrue(self.app.save.called)
  862. def test_321_feature_set_empty(self):
  863. value = self.call_mgmt_func(b'admin.vm.feature.Set',
  864. b'test-vm1', b'test-feature', b'')
  865. self.assertIsNone(value)
  866. self.assertEqual(self.vm.features['test-feature'], '')
  867. self.assertTrue(self.app.save.called)
  868. def test_320_feature_set_invalid(self):
  869. with self.assertRaises(UnicodeDecodeError):
  870. self.call_mgmt_func(b'admin.vm.feature.Set',
  871. b'test-vm1', b'test-feature', b'\x02\x03\xffsome-value')
  872. self.assertNotIn('test-feature', self.vm.features)
  873. self.assertFalse(self.app.save.called)
  874. @asyncio.coroutine
  875. def dummy_coro(self, *args, **kwargs):
  876. pass
  877. @unittest.mock.patch('qubes.storage.Storage.create')
  878. def test_330_vm_create_standalone(self, storage_mock):
  879. storage_mock.side_effect = self.dummy_coro
  880. self.call_mgmt_func(b'admin.vm.Create.StandaloneVM',
  881. b'dom0', b'', b'name=test-vm2 label=red')
  882. self.assertIn('test-vm2', self.app.domains)
  883. vm = self.app.domains['test-vm2']
  884. self.assertIsInstance(vm, qubes.vm.standalonevm.StandaloneVM)
  885. self.assertEqual(vm.label, self.app.get_label('red'))
  886. self.assertEqual(storage_mock.mock_calls,
  887. [unittest.mock.call(self.app.domains['test-vm2']).create()])
  888. self.assertTrue(os.path.exists(os.path.join(
  889. self.test_base_dir, 'appvms', 'test-vm2')))
  890. self.assertTrue(self.app.save.called)
  891. @unittest.mock.patch('qubes.storage.Storage.create')
  892. def test_331_vm_create_standalone_spurious_template(self, storage_mock):
  893. storage_mock.side_effect = self.dummy_coro
  894. with self.assertRaises(AssertionError):
  895. self.call_mgmt_func(b'admin.vm.Create.StandaloneVM',
  896. b'dom0', b'test-template', b'name=test-vm2 label=red')
  897. self.assertNotIn('test-vm2', self.app.domains)
  898. self.assertEqual(storage_mock.mock_calls, [])
  899. self.assertFalse(os.path.exists(os.path.join(
  900. self.test_base_dir, 'appvms', 'test-vm2')))
  901. self.assertNotIn('test-vm2', self.app.domains)
  902. self.assertFalse(self.app.save.called)
  903. @unittest.mock.patch('qubes.storage.Storage.create')
  904. def test_332_vm_create_app(self, storage_mock):
  905. storage_mock.side_effect = self.dummy_coro
  906. self.call_mgmt_func(b'admin.vm.Create.AppVM',
  907. b'dom0', b'test-template', b'name=test-vm2 label=red')
  908. self.assertIn('test-vm2', self.app.domains)
  909. vm = self.app.domains['test-vm2']
  910. self.assertEqual(vm.label, self.app.get_label('red'))
  911. self.assertEqual(vm.template, self.app.domains['test-template'])
  912. self.assertEqual(storage_mock.mock_calls,
  913. [unittest.mock.call(self.app.domains['test-vm2']).create()])
  914. self.assertTrue(os.path.exists(os.path.join(
  915. self.test_base_dir, 'appvms', 'test-vm2')))
  916. self.assertTrue(self.app.save.called)
  917. @unittest.mock.patch('qubes.storage.Storage.create')
  918. def test_333_vm_create_app_default_template(self, storage_mock):
  919. storage_mock.side_effect = self.dummy_coro
  920. self.call_mgmt_func(b'admin.vm.Create.AppVM',
  921. b'dom0', b'', b'name=test-vm2 label=red')
  922. self.assertEqual(storage_mock.mock_calls,
  923. [unittest.mock.call(self.app.domains['test-vm2']).create()])
  924. self.assertIn('test-vm2', self.app.domains)
  925. self.assertEqual(self.app.domains['test-vm2'].template,
  926. self.app.default_template)
  927. self.assertTrue(self.app.save.called)
  928. @unittest.mock.patch('qubes.storage.Storage.create')
  929. def test_334_vm_create_invalid_name(self, storage_mock):
  930. storage_mock.side_effect = self.dummy_coro
  931. with self.assertRaises(qubes.exc.QubesValueError):
  932. self.call_mgmt_func(b'admin.vm.Create.AppVM',
  933. b'dom0', b'test-template', b'name=test-###')
  934. self.assertNotIn('test-###', self.app.domains)
  935. self.assertFalse(self.app.save.called)
  936. @unittest.mock.patch('qubes.storage.Storage.create')
  937. def test_335_vm_create_missing_name(self, storage_mock):
  938. storage_mock.side_effect = self.dummy_coro
  939. with self.assertRaises(AssertionError):
  940. self.call_mgmt_func(b'admin.vm.Create.AppVM',
  941. b'dom0', b'test-template', b'label=red')
  942. self.assertFalse(self.app.save.called)
  943. @unittest.mock.patch('qubes.storage.Storage.create')
  944. def test_336_vm_create_spurious_pool(self, storage_mock):
  945. storage_mock.side_effect = self.dummy_coro
  946. with self.assertRaises(AssertionError):
  947. self.call_mgmt_func(b'admin.vm.Create.AppVM',
  948. b'dom0', b'test-template',
  949. b'name=test-vm2 label=red pool=default')
  950. self.assertNotIn('test-vm2', self.app.domains)
  951. self.assertFalse(self.app.save.called)
  952. @unittest.mock.patch('qubes.storage.Storage.create')
  953. def test_337_vm_create_duplicate_name(self, storage_mock):
  954. storage_mock.side_effect = self.dummy_coro
  955. with self.assertRaises(qubes.exc.QubesException):
  956. self.call_mgmt_func(b'admin.vm.Create.AppVM',
  957. b'dom0', b'test-template',
  958. b'name=test-vm1 label=red')
  959. self.assertFalse(self.app.save.called)
  960. @unittest.mock.patch('qubes.storage.Storage.create')
  961. def test_338_vm_create_name_twice(self, storage_mock):
  962. storage_mock.side_effect = self.dummy_coro
  963. with self.assertRaises(AssertionError):
  964. self.call_mgmt_func(b'admin.vm.Create.AppVM',
  965. b'dom0', b'test-template',
  966. b'name=test-vm2 name=test-vm3 label=red')
  967. self.assertNotIn('test-vm2', self.app.domains)
  968. self.assertNotIn('test-vm3', self.app.domains)
  969. self.assertFalse(self.app.save.called)
  970. @unittest.mock.patch('qubes.storage.Storage.create')
  971. def test_340_vm_create_in_pool_app(self, storage_mock):
  972. storage_mock.side_effect = self.dummy_coro
  973. self.call_mgmt_func(b'admin.vm.CreateInPool.AppVM',
  974. b'dom0', b'test-template', b'name=test-vm2 label=red '
  975. b'pool=test')
  976. self.assertIn('test-vm2', self.app.domains)
  977. vm = self.app.domains['test-vm2']
  978. self.assertEqual(vm.label, self.app.get_label('red'))
  979. self.assertEqual(vm.template, self.app.domains['test-template'])
  980. # setting pool= affect only volumes actually created for this VM,
  981. # not used from a template or so
  982. self.assertEqual(vm.volume_config['root']['pool'], 'default')
  983. self.assertEqual(vm.volume_config['private']['pool'], 'test')
  984. self.assertEqual(vm.volume_config['volatile']['pool'], 'test')
  985. self.assertEqual(vm.volume_config['kernel']['pool'], 'linux-kernel')
  986. self.assertEqual(storage_mock.mock_calls,
  987. [unittest.mock.call(self.app.domains['test-vm2']).create()])
  988. self.assertTrue(os.path.exists(os.path.join(
  989. self.test_base_dir, 'appvms', 'test-vm2')))
  990. self.assertTrue(self.app.save.called)
  991. @unittest.mock.patch('qubes.storage.Storage.create')
  992. def test_341_vm_create_in_pool_private(self, storage_mock):
  993. storage_mock.side_effect = self.dummy_coro
  994. self.call_mgmt_func(b'admin.vm.CreateInPool.AppVM',
  995. b'dom0', b'test-template', b'name=test-vm2 label=red '
  996. b'pool:private=test')
  997. self.assertIn('test-vm2', self.app.domains)
  998. vm = self.app.domains['test-vm2']
  999. self.assertEqual(vm.label, self.app.get_label('red'))
  1000. self.assertEqual(vm.template, self.app.domains['test-template'])
  1001. self.assertEqual(vm.volume_config['root']['pool'], 'default')
  1002. self.assertEqual(vm.volume_config['private']['pool'], 'test')
  1003. self.assertEqual(vm.volume_config['volatile']['pool'], 'default')
  1004. self.assertEqual(vm.volume_config['kernel']['pool'], 'linux-kernel')
  1005. self.assertEqual(storage_mock.mock_calls,
  1006. [unittest.mock.call(self.app.domains['test-vm2']).create()])
  1007. self.assertTrue(os.path.exists(os.path.join(
  1008. self.test_base_dir, 'appvms', 'test-vm2')))
  1009. self.assertTrue(self.app.save.called)
  1010. @unittest.mock.patch('qubes.storage.Storage.create')
  1011. def test_342_vm_create_in_pool_invalid_pool(self, storage_mock):
  1012. storage_mock.side_effect = self.dummy_coro
  1013. with self.assertRaises(qubes.exc.QubesException):
  1014. self.call_mgmt_func(b'admin.vm.CreateInPool.AppVM',
  1015. b'dom0', b'test-template', b'name=test-vm2 label=red '
  1016. b'pool=no-such-pool')
  1017. self.assertFalse(self.app.save.called)
  1018. @unittest.mock.patch('qubes.storage.Storage.create')
  1019. def test_343_vm_create_in_pool_invalid_pool2(self, storage_mock):
  1020. storage_mock.side_effect = self.dummy_coro
  1021. with self.assertRaises(qubes.exc.QubesException):
  1022. self.call_mgmt_func(b'admin.vm.CreateInPool.AppVM',
  1023. b'dom0', b'test-template', b'name=test-vm2 label=red '
  1024. b'pool:private=no-such-pool')
  1025. self.assertNotIn('test-vm2', self.app.domains)
  1026. self.assertFalse(self.app.save.called)
  1027. @unittest.mock.patch('qubes.storage.Storage.create')
  1028. def test_344_vm_create_in_pool_invalid_volume(self, storage_mock):
  1029. storage_mock.side_effect = self.dummy_coro
  1030. with self.assertRaises(AssertionError):
  1031. self.call_mgmt_func(b'admin.vm.CreateInPool.AppVM',
  1032. b'dom0', b'test-template', b'name=test-vm2 label=red '
  1033. b'pool:invalid=test')
  1034. self.assertNotIn('test-vm2', self.app.domains)
  1035. self.assertFalse(self.app.save.called)
  1036. @unittest.mock.patch('qubes.storage.Storage.create')
  1037. def test_345_vm_create_in_pool_app_root(self, storage_mock):
  1038. # setting custom pool for 'root' volume of AppVM should not be
  1039. # allowed - this volume belongs to the template
  1040. storage_mock.side_effect = self.dummy_coro
  1041. with self.assertRaises(qubes.exc.QubesException):
  1042. self.call_mgmt_func(b'admin.vm.CreateInPool.AppVM',
  1043. b'dom0', b'test-template', b'name=test-vm2 label=red '
  1044. b'pool:root=test')
  1045. self.assertNotIn('test-vm2', self.app.domains)
  1046. self.assertFalse(self.app.save.called)
  1047. @unittest.mock.patch('qubes.storage.Storage.create')
  1048. def test_346_vm_create_in_pool_duplicate_pool(self, storage_mock):
  1049. # setting custom pool for 'root' volume of AppVM should not be
  1050. # allowed - this volume belongs to the template
  1051. storage_mock.side_effect = self.dummy_coro
  1052. with self.assertRaises(AssertionError):
  1053. self.call_mgmt_func(b'admin.vm.CreateInPool.AppVM',
  1054. b'dom0', b'test-template', b'name=test-vm2 label=red '
  1055. b'pool=test pool:root=test')
  1056. self.assertNotIn('test-vm2', self.app.domains)
  1057. self.assertFalse(self.app.save.called)
  1058. @unittest.mock.patch('qubes.storage.Storage.clone')
  1059. @unittest.mock.patch('qubes.storage.Storage.verify')
  1060. def test_350_vm_clone(self, mock_verify, mock_clone):
  1061. mock_clone.side_effect = self.dummy_coro
  1062. mock_verify.side_effect = self.dummy_coro
  1063. self.call_mgmt_func(b'admin.vm.Clone',
  1064. b'test-vm1', b'', b'name=test-vm2')
  1065. self.assertIn('test-vm2', self.app.domains)
  1066. vm = self.app.domains['test-vm2']
  1067. self.assertEqual(vm.label, self.app.get_label('red'))
  1068. self.assertEqual(vm.template, self.app.domains['test-template'])
  1069. self.assertEqual(vm.tags, self.vm.tags)
  1070. self.assertEqual(vm.features, self.vm.features)
  1071. self.assertEqual(vm.firewall, self.vm.firewall)
  1072. self.assertEqual(mock_clone.mock_calls,
  1073. [unittest.mock.call(self.app.domains['test-vm2']).clone(
  1074. self.app.domains['test-vm1'])])
  1075. self.assertTrue(os.path.exists(os.path.join(
  1076. self.test_base_dir, 'appvms', 'test-vm2')))
  1077. self.assertTrue(self.app.save.called)
  1078. @unittest.mock.patch('qubes.storage.Storage.clone')
  1079. @unittest.mock.patch('qubes.storage.Storage.verify')
  1080. def test_351_vm_clone_extra_params(self, mock_verify, mock_clone):
  1081. mock_clone.side_effect = self.dummy_coro
  1082. mock_verify.side_effect = self.dummy_coro
  1083. with self.assertRaises(qubes.exc.QubesException):
  1084. self.call_mgmt_func(b'admin.vm.Clone',
  1085. b'test-vm1', b'', b'name=test-vm2 label=red')
  1086. self.assertNotIn('test-vm2', self.app.domains)
  1087. self.assertEqual(mock_clone.mock_calls, [])
  1088. self.assertFalse(os.path.exists(os.path.join(
  1089. self.test_base_dir, 'appvms', 'test-vm2')))
  1090. self.assertFalse(self.app.save.called)
  1091. @unittest.mock.patch('qubes.storage.Storage.clone')
  1092. @unittest.mock.patch('qubes.storage.Storage.verify')
  1093. def test_352_vm_clone_duplicate_name(self, mock_verify, mock_clone):
  1094. mock_clone.side_effect = self.dummy_coro
  1095. mock_verify.side_effect = self.dummy_coro
  1096. with self.assertRaises(qubes.exc.QubesException):
  1097. self.call_mgmt_func(b'admin.vm.Clone',
  1098. b'test-vm1', b'', b'name=test-vm1')
  1099. self.assertFalse(self.app.save.called)
  1100. @unittest.mock.patch('qubes.storage.Storage.clone')
  1101. @unittest.mock.patch('qubes.storage.Storage.verify')
  1102. def test_353_vm_clone_invalid_name(self, mock_verify, mock_clone):
  1103. mock_clone.side_effect = self.dummy_coro
  1104. mock_verify.side_effect = self.dummy_coro
  1105. with self.assertRaises(qubes.exc.QubesException):
  1106. self.call_mgmt_func(b'admin.vm.Clone',
  1107. b'test-vm1', b'', b'name=test-vm2/..')
  1108. self.assertNotIn('test-vm2/..', self.app.domains)
  1109. self.assertEqual(mock_clone.mock_calls, [])
  1110. self.assertFalse(os.path.exists(os.path.join(
  1111. self.test_base_dir, 'appvms', 'test-vm2/..')))
  1112. self.assertFalse(self.app.save.called)
  1113. def test_400_property_list(self):
  1114. # actual function tested for admin.vm.property.* already
  1115. # this test is kind of stupid, but at least check if appropriate
  1116. # mgmt-permission event is fired
  1117. value = self.call_mgmt_func(b'admin.property.List', b'dom0')
  1118. properties = self.app.property_list()
  1119. self.assertEqual(value,
  1120. ''.join('{}\n'.format(prop.__name__) for prop in properties))
  1121. def test_410_property_get_str(self):
  1122. # actual function tested for admin.vm.property.* already
  1123. value = self.call_mgmt_func(b'admin.property.Get', b'dom0',
  1124. b'default_kernel')
  1125. self.assertEqual(value, 'default=False type=str 1.0')
  1126. def test_420_propert_set_str(self):
  1127. # actual function tested for admin.vm.property.* already
  1128. with unittest.mock.patch('qubes.property.__set__') as mock:
  1129. value = self.call_mgmt_func(b'admin.property.Set', b'dom0',
  1130. b'default_kernel', b'1.0')
  1131. self.assertIsNone(value)
  1132. mock.assert_called_once_with(self.app, '1.0')
  1133. self.app.save.assert_called_once_with()
  1134. def test_440_property_help(self):
  1135. # actual function tested for admin.vm.property.* already
  1136. value = self.call_mgmt_func(b'admin.property.Help', b'dom0',
  1137. b'clockvm')
  1138. self.assertEqual(value,
  1139. 'Which VM to use as NTP proxy for updating AdminVM')
  1140. self.assertFalse(self.app.save.called)
  1141. def test_450_property_reset(self):
  1142. # actual function tested for admin.vm.property.* already
  1143. with unittest.mock.patch('qubes.property.__delete__') as mock:
  1144. value = self.call_mgmt_func(b'admin.property.Reset', b'dom0',
  1145. b'clockvm')
  1146. mock.assert_called_with(self.app)
  1147. self.assertIsNone(value)
  1148. self.app.save.assert_called_once_with()
  1149. def device_list_testclass(self, vm, event):
  1150. if vm is not self.vm:
  1151. return
  1152. dev = qubes.devices.DeviceInfo(self.vm, '1234')
  1153. dev.description = 'Some device'
  1154. dev.data = {'other_property': 'property-value'}
  1155. dev.extra_prop = 'xx'
  1156. yield dev
  1157. dev = qubes.devices.DeviceInfo(self.vm, '4321')
  1158. dev.description = 'Some other device'
  1159. yield dev
  1160. def test_460_vm_device_available(self):
  1161. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1162. value = self.call_mgmt_func(b'admin.vm.device.testclass.Available',
  1163. b'test-vm1')
  1164. self.assertEqual(value,
  1165. '1234 extra_prop=xx other_property=property-value description=Some '
  1166. 'device\n'
  1167. '4321 description=Some other device\n')
  1168. self.assertFalse(self.app.save.called)
  1169. def test_461_vm_device_available_specific(self):
  1170. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1171. value = self.call_mgmt_func(b'admin.vm.device.testclass.Available',
  1172. b'test-vm1', b'4321')
  1173. self.assertEqual(value,
  1174. '4321 description=Some other device\n')
  1175. self.assertFalse(self.app.save.called)
  1176. def test_462_vm_device_available_invalid(self):
  1177. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1178. value = self.call_mgmt_func(b'admin.vm.device.testclass.Available',
  1179. b'test-vm1', b'no-such-device')
  1180. self.assertEqual(value, '')
  1181. self.assertFalse(self.app.save.called)
  1182. def test_470_vm_device_list_persistent(self):
  1183. assignment = qubes.devices.DeviceAssignment(self.vm, '1234',
  1184. persistent=True)
  1185. self.vm.devices['testclass'].attach(assignment)
  1186. value = self.call_mgmt_func(b'admin.vm.device.testclass.List',
  1187. b'test-vm1')
  1188. self.assertEqual(value,
  1189. 'test-vm1+1234 persistent=yes\n')
  1190. self.assertFalse(self.app.save.called)
  1191. def test_471_vm_device_list_persistent_options(self):
  1192. assignment = qubes.devices.DeviceAssignment(self.vm, '1234',
  1193. persistent=True, options={'opt1': 'value'})
  1194. self.vm.devices['testclass'].attach(assignment)
  1195. assignment = qubes.devices.DeviceAssignment(self.vm, '4321',
  1196. persistent=True)
  1197. self.vm.devices['testclass'].attach(assignment)
  1198. value = self.call_mgmt_func(b'admin.vm.device.testclass.List',
  1199. b'test-vm1')
  1200. self.assertEqual(value,
  1201. 'test-vm1+1234 opt1=value persistent=yes\n'
  1202. 'test-vm1+4321 persistent=yes\n')
  1203. self.assertFalse(self.app.save.called)
  1204. def device_list_attached_testclass(self, vm, event, **kwargs):
  1205. if vm is not self.vm:
  1206. return
  1207. dev = qubes.devices.DeviceInfo(self.vm, '1234')
  1208. yield (dev, {'attach_opt': 'value'})
  1209. def test_472_vm_device_list_temporary(self):
  1210. self.vm.add_handler('device-list-attached:testclass',
  1211. self.device_list_attached_testclass)
  1212. value = self.call_mgmt_func(b'admin.vm.device.testclass.List',
  1213. b'test-vm1')
  1214. self.assertEqual(value,
  1215. 'test-vm1+1234 attach_opt=value persistent=no\n')
  1216. self.assertFalse(self.app.save.called)
  1217. def test_473_vm_device_list_mixed(self):
  1218. self.vm.add_handler('device-list-attached:testclass',
  1219. self.device_list_attached_testclass)
  1220. assignment = qubes.devices.DeviceAssignment(self.vm, '4321',
  1221. persistent=True)
  1222. self.vm.devices['testclass'].attach(assignment)
  1223. value = self.call_mgmt_func(b'admin.vm.device.testclass.List',
  1224. b'test-vm1')
  1225. self.assertEqual(value,
  1226. 'test-vm1+1234 attach_opt=value persistent=no\n'
  1227. 'test-vm1+4321 persistent=yes\n')
  1228. self.assertFalse(self.app.save.called)
  1229. def test_474_vm_device_list_specific(self):
  1230. self.vm.add_handler('device-list-attached:testclass',
  1231. self.device_list_attached_testclass)
  1232. assignment = qubes.devices.DeviceAssignment(self.vm, '4321',
  1233. persistent=True)
  1234. self.vm.devices['testclass'].attach(assignment)
  1235. value = self.call_mgmt_func(b'admin.vm.device.testclass.List',
  1236. b'test-vm1', b'test-vm1+1234')
  1237. self.assertEqual(value,
  1238. 'test-vm1+1234 attach_opt=value persistent=no\n')
  1239. self.assertFalse(self.app.save.called)
  1240. def test_480_vm_device_attach(self):
  1241. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1242. mock_attach = unittest.mock.Mock()
  1243. mock_attach.return_value = None
  1244. self.vm.add_handler('device-attach:testclass', mock_attach)
  1245. with unittest.mock.patch.object(qubes.vm.qubesvm.QubesVM,
  1246. 'is_halted', lambda _: False):
  1247. value = self.call_mgmt_func(b'admin.vm.device.testclass.Attach',
  1248. b'test-vm1', b'test-vm1+1234')
  1249. self.assertIsNone(value)
  1250. mock_attach.assert_called_once_with(self.vm, 'device-attach:testclass',
  1251. device=self.vm.devices['testclass']['1234'],
  1252. options={})
  1253. self.assertEqual(len(self.vm.devices['testclass'].persistent()), 0)
  1254. self.app.save.assert_called_once_with()
  1255. def test_481_vm_device_attach(self):
  1256. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1257. mock_attach = unittest.mock.Mock()
  1258. mock_attach.return_value = None
  1259. self.vm.add_handler('device-attach:testclass', mock_attach)
  1260. with unittest.mock.patch.object(qubes.vm.qubesvm.QubesVM,
  1261. 'is_halted', lambda _: False):
  1262. value = self.call_mgmt_func(b'admin.vm.device.testclass.Attach',
  1263. b'test-vm1', b'test-vm1+1234', b'persistent=no')
  1264. self.assertIsNone(value)
  1265. mock_attach.assert_called_once_with(self.vm, 'device-attach:testclass',
  1266. device=self.vm.devices['testclass']['1234'],
  1267. options={})
  1268. self.assertEqual(len(self.vm.devices['testclass'].persistent()), 0)
  1269. self.app.save.assert_called_once_with()
  1270. def test_482_vm_device_attach_not_running(self):
  1271. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1272. mock_attach = unittest.mock.Mock()
  1273. self.vm.add_handler('device-attach:testclass', mock_attach)
  1274. with self.assertRaises(qubes.exc.QubesVMNotRunningError):
  1275. self.call_mgmt_func(b'admin.vm.device.testclass.Attach',
  1276. b'test-vm1', b'test-vm1+1234')
  1277. self.assertFalse(mock_attach.called)
  1278. self.assertEqual(len(self.vm.devices['testclass'].persistent()), 0)
  1279. self.assertFalse(self.app.save.called)
  1280. def test_483_vm_device_attach_persistent(self):
  1281. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1282. mock_attach = unittest.mock.Mock()
  1283. mock_attach.return_value = None
  1284. self.vm.add_handler('device-attach:testclass', mock_attach)
  1285. with unittest.mock.patch.object(qubes.vm.qubesvm.QubesVM,
  1286. 'is_halted', lambda _: False):
  1287. value = self.call_mgmt_func(b'admin.vm.device.testclass.Attach',
  1288. b'test-vm1', b'test-vm1+1234', b'persistent=yes')
  1289. self.assertIsNone(value)
  1290. dev = self.vm.devices['testclass']['1234']
  1291. mock_attach.assert_called_once_with(self.vm, 'device-attach:testclass',
  1292. device=dev,
  1293. options={})
  1294. self.assertIn(dev, self.vm.devices['testclass'].persistent())
  1295. self.app.save.assert_called_once_with()
  1296. def test_484_vm_device_attach_persistent_not_running(self):
  1297. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1298. mock_attach = unittest.mock.Mock()
  1299. mock_attach.return_value = None
  1300. self.vm.add_handler('device-attach:testclass', mock_attach)
  1301. value = self.call_mgmt_func(b'admin.vm.device.testclass.Attach',
  1302. b'test-vm1', b'test-vm1+1234', b'persistent=yes')
  1303. self.assertIsNone(value)
  1304. dev = self.vm.devices['testclass']['1234']
  1305. mock_attach.assert_called_once_with(self.vm, 'device-attach:testclass',
  1306. device=dev,
  1307. options={})
  1308. self.assertIn(dev, self.vm.devices['testclass'].persistent())
  1309. self.app.save.assert_called_once_with()
  1310. def test_485_vm_device_attach_options(self):
  1311. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1312. mock_attach = unittest.mock.Mock()
  1313. mock_attach.return_value = None
  1314. self.vm.add_handler('device-attach:testclass', mock_attach)
  1315. with unittest.mock.patch.object(qubes.vm.qubesvm.QubesVM,
  1316. 'is_halted', lambda _: False):
  1317. value = self.call_mgmt_func(b'admin.vm.device.testclass.Attach',
  1318. b'test-vm1', b'test-vm1+1234', b'option1=value2')
  1319. self.assertIsNone(value)
  1320. dev = self.vm.devices['testclass']['1234']
  1321. mock_attach.assert_called_once_with(self.vm, 'device-attach:testclass',
  1322. device=dev,
  1323. options={'option1': 'value2'})
  1324. self.app.save.assert_called_once_with()
  1325. def test_490_vm_device_detach(self):
  1326. self.vm.add_handler('device-list:testclass', self.device_list_testclass)
  1327. self.vm.add_handler('device-list-attached:testclass',
  1328. self.device_list_attached_testclass)
  1329. mock_detach = unittest.mock.Mock()
  1330. mock_detach.return_value = None
  1331. self.vm.add_handler('device-detach:testclass', mock_detach)
  1332. with unittest.mock.patch.object(qubes.vm.qubesvm.QubesVM,
  1333. 'is_halted', lambda _: False):
  1334. value = self.call_mgmt_func(b'admin.vm.device.testclass.Detach',
  1335. b'test-vm1', b'test-vm1+1234')
  1336. self.assertIsNone(value)
  1337. mock_detach.assert_called_once_with(self.vm, 'device-detach:testclass',
  1338. device=self.vm.devices['testclass']['1234'])
  1339. self.app.save.assert_called_once_with()
  1340. def test_491_vm_device_detach_not_attached(self):
  1341. mock_detach = unittest.mock.Mock()
  1342. mock_detach.return_value = None
  1343. self.vm.add_handler('device-detach:testclass', mock_detach)
  1344. with unittest.mock.patch.object(qubes.vm.qubesvm.QubesVM,
  1345. 'is_halted', lambda _: False):
  1346. with self.assertRaises(qubes.devices.DeviceNotAttached):
  1347. self.call_mgmt_func(b'admin.vm.device.testclass.Detach',
  1348. b'test-vm1', b'test-vm1+1234')
  1349. self.assertFalse(mock_detach.called)
  1350. self.assertFalse(self.app.save.called)
  1351. @unittest.mock.patch('qubes.storage.Storage.remove')
  1352. @unittest.mock.patch('shutil.rmtree')
  1353. def test_500_vm_remove(self, mock_rmtree, mock_remove):
  1354. value = self.call_mgmt_func(b'admin.vm.Remove', b'test-vm1')
  1355. self.assertIsNone(value)
  1356. mock_rmtree.assert_called_once_with(
  1357. '/tmp/qubes-test-dir/appvms/test-vm1')
  1358. mock_remove.assert_called_once_with()
  1359. self.app.save.assert_called_once_with()
  1360. @unittest.mock.patch('qubes.storage.Storage.remove')
  1361. @unittest.mock.patch('shutil.rmtree')
  1362. def test_501_vm_remove_running(self, mock_rmtree, mock_remove):
  1363. with unittest.mock.patch.object(
  1364. self.vm, 'get_power_state', lambda: 'Running'):
  1365. with self.assertRaises(qubes.exc.QubesVMNotHaltedError):
  1366. self.call_mgmt_func(b'admin.vm.Remove', b'test-vm1')
  1367. self.assertFalse(mock_rmtree.called)
  1368. self.assertFalse(mock_remove.called)
  1369. self.assertFalse(self.app.save.called)
  1370. def test_990_vm_unexpected_payload(self):
  1371. methods_with_no_payload = [
  1372. b'admin.vm.List',
  1373. b'admin.vm.Remove',
  1374. b'admin.vm.property.List',
  1375. b'admin.vm.property.Get',
  1376. b'admin.vm.property.Help',
  1377. b'admin.vm.property.HelpRst',
  1378. b'admin.vm.property.Reset',
  1379. b'admin.vm.feature.List',
  1380. b'admin.vm.feature.Get',
  1381. b'admin.vm.feature.CheckWithTemplate',
  1382. b'admin.vm.feature.Remove',
  1383. b'admin.vm.tag.List',
  1384. b'admin.vm.tag.Get',
  1385. b'admin.vm.tag.Remove',
  1386. b'admin.vm.tag.Set',
  1387. b'admin.vm.firewall.Get',
  1388. b'admin.vm.firewall.RemoveRule',
  1389. b'admin.vm.firewall.Flush',
  1390. b'admin.vm.device.pci.Attach',
  1391. b'admin.vm.device.pci.Detach',
  1392. b'admin.vm.device.pci.List',
  1393. b'admin.vm.device.pci.Available',
  1394. b'admin.vm.microphone.Attach',
  1395. b'admin.vm.microphone.Detach',
  1396. b'admin.vm.microphone.Status',
  1397. b'admin.vm.volume.ListSnapshots',
  1398. b'admin.vm.volume.List',
  1399. b'admin.vm.volume.Info',
  1400. b'admin.vm.Start',
  1401. b'admin.vm.Shutdown',
  1402. b'admin.vm.Pause',
  1403. b'admin.vm.Unpause',
  1404. b'admin.vm.Kill',
  1405. b'admin.Events',
  1406. b'admin.vm.feature.List',
  1407. b'admin.vm.feature.Get',
  1408. b'admin.vm.feature.Remove',
  1409. b'admin.vm.feature.CheckWithTemplate',
  1410. ]
  1411. # make sure also no methods on actual VM gets called
  1412. vm_mock = unittest.mock.MagicMock()
  1413. vm_mock.name = self.vm.name
  1414. vm_mock.qid = self.vm.qid
  1415. vm_mock.__lt__ = (lambda x, y: x.qid < y.qid)
  1416. self.app.domains._dict[self.vm.qid] = vm_mock
  1417. for method in methods_with_no_payload:
  1418. # should reject payload regardless of having argument or not
  1419. with self.subTest(method.decode('ascii')):
  1420. with self.assertRaises(AssertionError):
  1421. self.call_mgmt_func(method, b'test-vm1', b'',
  1422. b'unexpected-payload')
  1423. self.assertFalse(vm_mock.called)
  1424. self.assertFalse(self.app.save.called)
  1425. with self.subTest(method.decode('ascii') + '+arg'):
  1426. with self.assertRaises(AssertionError):
  1427. self.call_mgmt_func(method, b'test-vm1', b'some-arg',
  1428. b'unexpected-payload')
  1429. self.assertFalse(vm_mock.called)
  1430. self.assertFalse(self.app.save.called)
  1431. def test_991_vm_unexpected_argument(self):
  1432. methods_with_no_argument = [
  1433. b'admin.vm.List',
  1434. b'admin.vm.Clone',
  1435. b'admin.vm.Remove',
  1436. b'admin.vm.property.List',
  1437. b'admin.vm.feature.List',
  1438. b'admin.vm.tag.List',
  1439. b'admin.vm.firewall.List',
  1440. b'admin.vm.firewall.Flush',
  1441. b'admin.vm.microphone.Attach',
  1442. b'admin.vm.microphone.Detach',
  1443. b'admin.vm.microphone.Status',
  1444. b'admin.vm.volume.List',
  1445. b'admin.vm.Start',
  1446. b'admin.vm.Shutdown',
  1447. b'admin.vm.Pause',
  1448. b'admin.vm.Unpause',
  1449. b'admin.vm.Kill',
  1450. b'admin.Events',
  1451. b'admin.vm.feature.List',
  1452. ]
  1453. # make sure also no methods on actual VM gets called
  1454. vm_mock = unittest.mock.MagicMock()
  1455. vm_mock.name = self.vm.name
  1456. vm_mock.qid = self.vm.qid
  1457. vm_mock.__lt__ = (lambda x, y: x.qid < y.qid)
  1458. self.app.domains._dict[self.vm.qid] = vm_mock
  1459. for method in methods_with_no_argument:
  1460. # should reject argument regardless of having payload or not
  1461. with self.subTest(method.decode('ascii')):
  1462. with self.assertRaises(AssertionError):
  1463. self.call_mgmt_func(method, b'test-vm1', b'some-arg',
  1464. b'')
  1465. self.assertFalse(vm_mock.called)
  1466. self.assertFalse(self.app.save.called)
  1467. with self.subTest(method.decode('ascii') + '+payload'):
  1468. with self.assertRaises(AssertionError):
  1469. self.call_mgmt_func(method, b'test-vm1', b'unexpected-arg',
  1470. b'some-payload')
  1471. self.assertFalse(vm_mock.called)
  1472. self.assertFalse(self.app.save.called)
  1473. def test_992_dom0_unexpected_payload(self):
  1474. methods_with_no_payload = [
  1475. b'admin.vmclass.List',
  1476. b'admin.vm.List',
  1477. b'admin.label.List',
  1478. b'admin.label.Get',
  1479. b'admin.label.Remove',
  1480. b'admin.property.List',
  1481. b'admin.property.Get',
  1482. b'admin.property.Help',
  1483. b'admin.property.HelpRst',
  1484. b'admin.property.Reset',
  1485. b'admin.pool.List',
  1486. b'admin.pool.ListDrivers',
  1487. b'admin.pool.Info',
  1488. b'admin.pool.Remove',
  1489. b'admin.backup.Execute',
  1490. b'admin.Events',
  1491. ]
  1492. # make sure also no methods on actual VM gets called
  1493. vm_mock = unittest.mock.MagicMock()
  1494. vm_mock.name = self.vm.name
  1495. vm_mock.qid = self.vm.qid
  1496. vm_mock.__lt__ = (lambda x, y: x.qid < y.qid)
  1497. self.app.domains._dict[self.vm.qid] = vm_mock
  1498. for method in methods_with_no_payload:
  1499. # should reject payload regardless of having argument or not
  1500. with self.subTest(method.decode('ascii')):
  1501. with self.assertRaises(AssertionError):
  1502. self.call_mgmt_func(method, b'dom0', b'',
  1503. b'unexpected-payload')
  1504. self.assertFalse(vm_mock.called)
  1505. self.assertFalse(self.app.save.called)
  1506. with self.subTest(method.decode('ascii') + '+arg'):
  1507. with self.assertRaises(AssertionError):
  1508. self.call_mgmt_func(method, b'dom0', b'some-arg',
  1509. b'unexpected-payload')
  1510. self.assertFalse(vm_mock.called)
  1511. self.assertFalse(self.app.save.called)
  1512. def test_993_dom0_unexpected_argument(self):
  1513. methods_with_no_argument = [
  1514. b'admin.vmclass.List',
  1515. b'admin.vm.List',
  1516. b'admin.label.List',
  1517. b'admin.property.List',
  1518. b'admin.pool.List',
  1519. b'admin.pool.ListDrivers',
  1520. b'admin.Events',
  1521. ]
  1522. # make sure also no methods on actual VM gets called
  1523. vm_mock = unittest.mock.MagicMock()
  1524. vm_mock.name = self.vm.name
  1525. vm_mock.qid = self.vm.qid
  1526. vm_mock.__lt__ = (lambda x, y: x.qid < y.qid)
  1527. self.app.domains._dict[self.vm.qid] = vm_mock
  1528. for method in methods_with_no_argument:
  1529. # should reject argument regardless of having payload or not
  1530. with self.subTest(method.decode('ascii')):
  1531. with self.assertRaises(AssertionError):
  1532. self.call_mgmt_func(method, b'dom0', b'some-arg',
  1533. b'')
  1534. self.assertFalse(vm_mock.called)
  1535. self.assertFalse(self.app.save.called)
  1536. with self.subTest(method.decode('ascii') + '+payload'):
  1537. with self.assertRaises(AssertionError):
  1538. self.call_mgmt_func(method, b'dom0', b'unexpected-arg',
  1539. b'some-payload')
  1540. self.assertFalse(vm_mock.called)
  1541. self.assertFalse(self.app.save.called)
  1542. def test_994_dom0_only_calls(self):
  1543. # TODO set some better arguments, to make sure the call was rejected
  1544. # because of invalid destination, not invalid arguments
  1545. methods_for_dom0_only = [
  1546. b'admin.vmclass.List',
  1547. b'admin.vm.Create.AppVM',
  1548. b'admin.vm.CreateInPool.AppVM',
  1549. b'admin.vm.CreateTemplate',
  1550. b'admin.label.List',
  1551. b'admin.label.Create',
  1552. b'admin.label.Get',
  1553. b'admin.label.Remove',
  1554. b'admin.property.List',
  1555. b'admin.property.Get',
  1556. b'admin.property.Set',
  1557. b'admin.property.Help',
  1558. b'admin.property.HelpRst',
  1559. b'admin.property.Reset',
  1560. b'admin.pool.List',
  1561. b'admin.pool.ListDrivers',
  1562. b'admin.pool.Info',
  1563. b'admin.pool.Add',
  1564. b'admin.pool.Remove',
  1565. b'admin.pool.volume.List',
  1566. b'admin.pool.volume.Info',
  1567. b'admin.pool.volume.ListSnapshots',
  1568. b'admin.pool.volume.Snapshot',
  1569. b'admin.pool.volume.Revert',
  1570. b'admin.pool.volume.Resize',
  1571. b'admin.backup.Execute',
  1572. b'admin.backup.Info',
  1573. b'admin.backup.Restore',
  1574. ]
  1575. # make sure also no methods on actual VM gets called
  1576. vm_mock = unittest.mock.MagicMock()
  1577. vm_mock.name = self.vm.name
  1578. vm_mock.qid = self.vm.qid
  1579. vm_mock.__lt__ = (lambda x, y: x.qid < y.qid)
  1580. self.app.domains._dict[self.vm.qid] = vm_mock
  1581. for method in methods_for_dom0_only:
  1582. # should reject call regardless of having payload or not
  1583. with self.subTest(method.decode('ascii')):
  1584. with self.assertRaises(AssertionError):
  1585. self.call_mgmt_func(method, b'test-vm1', b'',
  1586. b'')
  1587. self.assertFalse(vm_mock.called)
  1588. self.assertFalse(self.app.save.called)
  1589. with self.subTest(method.decode('ascii') + '+arg'):
  1590. with self.assertRaises(AssertionError):
  1591. self.call_mgmt_func(method, b'test-vm1', b'some-arg',
  1592. b'')
  1593. self.assertFalse(vm_mock.called)
  1594. self.assertFalse(self.app.save.called)
  1595. with self.subTest(method.decode('ascii') + '+payload'):
  1596. with self.assertRaises(AssertionError):
  1597. self.call_mgmt_func(method, b'test-vm1', b'',
  1598. b'payload')
  1599. self.assertFalse(vm_mock.called)
  1600. self.assertFalse(self.app.save.called)
  1601. with self.subTest(method.decode('ascii') + '+arg+payload'):
  1602. with self.assertRaises(AssertionError):
  1603. self.call_mgmt_func(method, b'test-vm1', b'some-arg',
  1604. b'some-payload')
  1605. self.assertFalse(vm_mock.called)
  1606. self.assertFalse(self.app.save.called)
  1607. @unittest.skip('undecided')
  1608. def test_995_vm_only_calls(self):
  1609. # XXX is it really a good idea to prevent those calls this early?
  1610. # TODO set some better arguments, to make sure the call was rejected
  1611. # because of invalid destination, not invalid arguments
  1612. methods_for_vm_only = [
  1613. b'admin.vm.Clone',
  1614. b'admin.vm.Remove',
  1615. b'admin.vm.property.List',
  1616. b'admin.vm.property.Get',
  1617. b'admin.vm.property.Set',
  1618. b'admin.vm.property.Help',
  1619. b'admin.vm.property.HelpRst',
  1620. b'admin.vm.property.Reset',
  1621. b'admin.vm.feature.List',
  1622. b'admin.vm.feature.Get',
  1623. b'admin.vm.feature.Set',
  1624. b'admin.vm.feature.CheckWithTemplate',
  1625. b'admin.vm.feature.Remove',
  1626. b'admin.vm.tag.List',
  1627. b'admin.vm.tag.Get',
  1628. b'admin.vm.tag.Remove',
  1629. b'admin.vm.tag.Set',
  1630. b'admin.vm.firewall.Get',
  1631. b'admin.vm.firewall.RemoveRule',
  1632. b'admin.vm.firewall.InsertRule',
  1633. b'admin.vm.firewall.Flush',
  1634. b'admin.vm.device.pci.Attach',
  1635. b'admin.vm.device.pci.Detach',
  1636. b'admin.vm.device.pci.List',
  1637. b'admin.vm.device.pci.Available',
  1638. b'admin.vm.microphone.Attach',
  1639. b'admin.vm.microphone.Detach',
  1640. b'admin.vm.microphone.Status',
  1641. b'admin.vm.volume.ListSnapshots',
  1642. b'admin.vm.volume.List',
  1643. b'admin.vm.volume.Info',
  1644. b'admin.vm.volume.Revert',
  1645. b'admin.vm.volume.Resize',
  1646. b'admin.vm.Start',
  1647. b'admin.vm.Shutdown',
  1648. b'admin.vm.Pause',
  1649. b'admin.vm.Unpause',
  1650. b'admin.vm.Kill',
  1651. b'admin.vm.feature.List',
  1652. b'admin.vm.feature.Get',
  1653. b'admin.vm.feature.Set',
  1654. b'admin.vm.feature.Remove',
  1655. b'admin.vm.feature.CheckWithTemplate',
  1656. ]
  1657. # make sure also no methods on actual VM gets called
  1658. vm_mock = unittest.mock.MagicMock()
  1659. vm_mock.name = self.vm.name
  1660. vm_mock.qid = self.vm.qid
  1661. vm_mock.__lt__ = (lambda x, y: x.qid < y.qid)
  1662. self.app.domains._dict[self.vm.qid] = vm_mock
  1663. for method in methods_for_vm_only:
  1664. # should reject payload regardless of having argument or not
  1665. # should reject call regardless of having payload or not
  1666. with self.subTest(method.decode('ascii')):
  1667. with self.assertRaises(AssertionError):
  1668. self.call_mgmt_func(method, b'dom0', b'',
  1669. b'')
  1670. self.assertFalse(vm_mock.called)
  1671. self.assertFalse(self.app.save.called)
  1672. with self.subTest(method.decode('ascii') + '+arg'):
  1673. with self.assertRaises(AssertionError):
  1674. self.call_mgmt_func(method, b'dom0', b'some-arg',
  1675. b'')
  1676. self.assertFalse(vm_mock.called)
  1677. self.assertFalse(self.app.save.called)
  1678. with self.subTest(method.decode('ascii') + '+payload'):
  1679. with self.assertRaises(AssertionError):
  1680. self.call_mgmt_func(method, b'dom0', b'',
  1681. b'payload')
  1682. self.assertFalse(vm_mock.called)
  1683. self.assertFalse(self.app.save.called)
  1684. with self.subTest(method.decode('ascii') + '+arg+payload'):
  1685. with self.assertRaises(AssertionError):
  1686. self.call_mgmt_func(method, b'dom0', b'some-arg',
  1687. b'some-payload')
  1688. self.assertFalse(vm_mock.called)
  1689. self.assertFalse(self.app.save.called)