test_firewall.py 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681
  1. import logging
  2. import operator
  3. from unittest import TestCase
  4. from unittest.mock import patch
  5. import qubesagent.firewall
  6. class DummyIptablesRestore(object):
  7. # pylint: disable=too-few-public-methods
  8. def __init__(self, worker_mock, family):
  9. self._worker_mock = worker_mock
  10. self._family = family
  11. self.returncode = 0
  12. def communicate(self, stdin=None):
  13. self._worker_mock.loaded_iptables[self._family] = stdin.decode()
  14. return ("", None)
  15. class DummyQubesDB(object):
  16. def __init__(self, worker_mock):
  17. self._worker_mock = worker_mock
  18. self.entries = {}
  19. self.pending_watches = []
  20. def read(self, key):
  21. try:
  22. return self.entries[key]
  23. except KeyError:
  24. return None
  25. def multiread(self, prefix):
  26. result = {}
  27. for key, value in self.entries.items():
  28. if key.startswith(prefix):
  29. result[key] = value
  30. return result
  31. def list(self, prefix):
  32. result = []
  33. for key in self.entries.keys():
  34. if key.startswith(prefix):
  35. result.append(key)
  36. return result
  37. def watch(self, path):
  38. pass
  39. def read_watch(self):
  40. try:
  41. return self.pending_watches.pop(0)
  42. except IndexError:
  43. return None
  44. class FirewallWorker(qubesagent.firewall.FirewallWorker):
  45. def __init__(self):
  46. # pylint: disable=super-init-not-called
  47. # don't call super on purpose - avoid connecting to QubesDB
  48. # super(FirewallWorker, self).__init__()
  49. self.qdb = DummyQubesDB(self)
  50. self.log = logging.getLogger('qubes.tests')
  51. self.init_called = False
  52. self.cleanup_called = False
  53. self.user_script_called = False
  54. self.update_connected_ips_called_with = []
  55. self.rules = {}
  56. def apply_rules(self, source_addr, rules):
  57. self.rules[source_addr] = rules
  58. def cleanup(self):
  59. self.init_called = True
  60. def init(self):
  61. self.cleanup_called = True
  62. def run_user_script(self):
  63. self.user_script_called = True
  64. def update_connected_ips(self, family):
  65. self.update_connected_ips_called_with.append(family)
  66. class IptablesWorker(qubesagent.firewall.IptablesWorker):
  67. '''Override methods actually modifying system state to only log what
  68. would be done'''
  69. def __init__(self):
  70. # pylint: disable=super-init-not-called
  71. # don't call super on purpose - avoid connecting to QubesDB
  72. # super(IptablesWorker, self).__init__()
  73. # copied __init__:
  74. self.qdb = DummyQubesDB(self)
  75. self.log = logging.getLogger('qubes.tests')
  76. self.chains = {
  77. 4: set(),
  78. 6: set(),
  79. }
  80. #: instead of really running `iptables`, log what would be called
  81. self.called_commands = {
  82. 4: [],
  83. 6: [],
  84. }
  85. #: rules that would be loaded with `iptables-restore`
  86. self.loaded_iptables = {
  87. 4: None,
  88. 6: None,
  89. }
  90. def run_ipt(self, family, args, **kwargs):
  91. self.called_commands[family].append(args)
  92. def run_ipt_restore(self, family, args):
  93. return DummyIptablesRestore(self, family)
  94. @staticmethod
  95. def dns_addresses(family=None):
  96. if family == 4:
  97. return ['1.1.1.1', '2.2.2.2']
  98. else:
  99. return ['2001::1', '2001::2']
  100. class NftablesWorker(qubesagent.firewall.NftablesWorker):
  101. '''Override methods actually modifying system state to only log what
  102. would be done'''
  103. def __init__(self):
  104. # pylint: disable=super-init-not-called
  105. # don't call super on purpose - avoid connecting to QubesDB
  106. # super(IptablesWorker, self).__init__()
  107. # copied __init__:
  108. self.qdb = DummyQubesDB(self)
  109. self.log = logging.getLogger('qubes.tests')
  110. self.chains = {
  111. 4: set(),
  112. 6: set(),
  113. }
  114. #: instead of really running `nft`, log what would be loaded
  115. #: rules that would be loaded with `nft`
  116. self.loaded_rules = []
  117. def run_nft(self, nft_input):
  118. self.loaded_rules.append(nft_input)
  119. @staticmethod
  120. def dns_addresses(family=None):
  121. if family == 4:
  122. return ['1.1.1.1', '2.2.2.2']
  123. else:
  124. return ['2001::1', '2001::2']
  125. class TestIptablesWorker(TestCase):
  126. def setUp(self):
  127. super(TestIptablesWorker, self).setUp()
  128. self.obj = IptablesWorker()
  129. self.subprocess_patch = patch('subprocess.call')
  130. self.subprocess_mock = self.subprocess_patch.start()
  131. def tearDown(self):
  132. self.subprocess_patch.stop()
  133. def test_000_chain_for_addr(self):
  134. self.assertEqual(
  135. self.obj.chain_for_addr('10.137.0.1'), 'qbs-10-137-0-1')
  136. self.assertEqual(
  137. self.obj.chain_for_addr('fd09:24ef:4179:0000::3'),
  138. 'qbs-09-24ef-4179-0000--3')
  139. def test_001_create_chain(self):
  140. testdata = [
  141. (4, '10.137.0.1', 'qbs-10-137-0-1'),
  142. (6, 'fd09:24ef:4179:0000::3', 'qbs-fd09-24ef-4179-0000--3')
  143. ]
  144. for family, addr, chain in testdata:
  145. self.obj.create_chain(addr, chain, family)
  146. self.assertEqual(self.obj.called_commands[family],
  147. [['-N', chain],
  148. ['-I', 'QBS-FORWARD', '-s', addr, '-j', chain]])
  149. def test_002_prepare_rules4(self):
  150. rules = [
  151. {'action': 'accept', 'proto': 'tcp',
  152. 'dstports': '80-80', 'dst4': '1.2.3.0/24'},
  153. {'action': 'accept', 'proto': 'udp',
  154. 'dstports': '443-1024', 'dsthost': 'yum.qubes-os.org'},
  155. {'action': 'accept', 'specialtarget': 'dns'},
  156. {'action': 'drop', 'proto': 'udp', 'specialtarget': 'dns'},
  157. {'action': 'drop', 'proto': 'icmp'},
  158. {'action': 'drop'},
  159. ]
  160. expected_iptables = (
  161. "*filter\n"
  162. "-A chain -d 1.2.3.0/24 -p tcp --dport 80:80 -j ACCEPT\n"
  163. "-A chain -d 147.75.32.69/32 -p udp --dport 443:1024 -j ACCEPT\n"
  164. "-A chain -d 1.1.1.1/32 -p tcp --dport 53:53 -j ACCEPT\n"
  165. "-A chain -d 2.2.2.2/32 -p tcp --dport 53:53 -j ACCEPT\n"
  166. "-A chain -d 1.1.1.1/32 -p udp --dport 53:53 -j ACCEPT\n"
  167. "-A chain -d 2.2.2.2/32 -p udp --dport 53:53 -j ACCEPT\n"
  168. "-A chain -d 1.1.1.1/32 -p udp --dport 53:53 -j REJECT "
  169. "--reject-with icmp-admin-prohibited\n"
  170. "-A chain -d 2.2.2.2/32 -p udp --dport 53:53 -j REJECT "
  171. "--reject-with icmp-admin-prohibited\n"
  172. "-A chain -p icmp -j REJECT "
  173. "--reject-with icmp-admin-prohibited\n"
  174. "-A chain -j REJECT "
  175. "--reject-with icmp-admin-prohibited\n"
  176. "COMMIT\n"
  177. )
  178. self.assertEqual(self.obj.prepare_rules('chain', rules, 4),
  179. expected_iptables)
  180. with self.assertRaises(qubesagent.firewall.RuleParseError):
  181. self.obj.prepare_rules('chain', [{'unknown': 'xxx'}], 4)
  182. with self.assertRaises(qubesagent.firewall.RuleParseError):
  183. self.obj.prepare_rules('chain', [{'dst6': 'a::b'}], 4)
  184. with self.assertRaises(qubesagent.firewall.RuleParseError):
  185. self.obj.prepare_rules('chain', [{'dst4': '3.3.3.3'}], 6)
  186. def test_003_prepare_rules6(self):
  187. rules = [
  188. {'action': 'accept', 'proto': 'tcp',
  189. 'dstports': '80-80', 'dst6': 'a::b/128'},
  190. {'action': 'accept', 'proto': 'tcp',
  191. 'dsthost': 'ripe.net'},
  192. {'action': 'accept', 'specialtarget': 'dns'},
  193. {'action': 'drop', 'proto': 'udp', 'specialtarget': 'dns'},
  194. {'action': 'drop', 'proto': 'icmp'},
  195. {'action': 'drop'},
  196. ]
  197. expected_iptables = (
  198. "*filter\n"
  199. "-A chain -d a::b/128 -p tcp --dport 80:80 -j ACCEPT\n"
  200. "-A chain -d 2001:67c:2e8:22::c100:68b/128 -p tcp -j ACCEPT\n"
  201. "-A chain -d 2001::1/128 -p tcp --dport 53:53 -j ACCEPT\n"
  202. "-A chain -d 2001::2/128 -p tcp --dport 53:53 -j ACCEPT\n"
  203. "-A chain -d 2001::1/128 -p udp --dport 53:53 -j ACCEPT\n"
  204. "-A chain -d 2001::2/128 -p udp --dport 53:53 -j ACCEPT\n"
  205. "-A chain -d 2001::1/128 -p udp --dport 53:53 -j REJECT "
  206. "--reject-with icmp6-adm-prohibited\n"
  207. "-A chain -d 2001::2/128 -p udp --dport 53:53 -j REJECT "
  208. "--reject-with icmp6-adm-prohibited\n"
  209. "-A chain -p icmpv6 -j REJECT "
  210. "--reject-with icmp6-adm-prohibited\n"
  211. "-A chain -j REJECT "
  212. "--reject-with icmp6-adm-prohibited\n"
  213. "COMMIT\n"
  214. )
  215. self.assertEqual(self.obj.prepare_rules('chain', rules, 6),
  216. expected_iptables)
  217. def test_004_apply_rules4(self):
  218. rules = [{'action': 'accept'}]
  219. chain = 'qbs-10-137-0-1'
  220. self.obj.apply_rules('10.137.0.1', rules)
  221. self.assertEqual(self.obj.called_commands[4],
  222. [
  223. ['-N', chain],
  224. ['-I', 'QBS-FORWARD', '-s', '10.137.0.1', '-j', chain],
  225. ['-F', chain]])
  226. self.assertEqual(self.obj.loaded_iptables[4],
  227. self.obj.prepare_rules(chain, rules, 4))
  228. self.assertEqual(self.obj.called_commands[6], [])
  229. self.assertIsNone(self.obj.loaded_iptables[6])
  230. def test_005_apply_rules6(self):
  231. rules = [{'action': 'accept'}]
  232. chain = 'qbs-2000--a'
  233. self.obj.apply_rules('2000::a', rules)
  234. self.assertEqual(self.obj.called_commands[6],
  235. [
  236. ['-N', chain],
  237. ['-I', 'QBS-FORWARD', '-s', '2000::a', '-j', chain],
  238. ['-F', chain]])
  239. self.assertEqual(self.obj.loaded_iptables[6],
  240. self.obj.prepare_rules(chain, rules, 6))
  241. self.assertEqual(self.obj.called_commands[4], [])
  242. self.assertIsNone(self.obj.loaded_iptables[4])
  243. def test_006_init(self):
  244. self.obj.init()
  245. self.assertEqual(self.obj.called_commands[4], [
  246. ['-F', 'QBS-FORWARD'],
  247. ['-A', 'QBS-FORWARD', '!', '-i', 'vif+', '-j', 'RETURN'],
  248. ['-A', 'QBS-FORWARD', '-j', 'DROP'],
  249. ['-t', 'raw', '-F', 'QBS-PREROUTING'],
  250. ['-t', 'mangle', '-F', 'QBS-POSTROUTING'],
  251. ])
  252. self.assertEqual(self.obj.called_commands[6], [
  253. ['-F', 'QBS-FORWARD'],
  254. ['-A', 'QBS-FORWARD', '!', '-i', 'vif+', '-j', 'RETURN'],
  255. ['-A', 'QBS-FORWARD', '-j', 'DROP'],
  256. ['-t', 'raw', '-F', 'QBS-PREROUTING'],
  257. ['-t', 'mangle', '-F', 'QBS-POSTROUTING'],
  258. ])
  259. def test_007_cleanup(self):
  260. self.obj.init()
  261. self.obj.create_chain('1.2.3.4', 'chain-ip4-1', 4)
  262. self.obj.create_chain('1.2.3.6', 'chain-ip4-2', 4)
  263. self.obj.create_chain('2000::1', 'chain-ip6-1', 6)
  264. self.obj.create_chain('2000::2', 'chain-ip6-2', 6)
  265. # forget about commands called earlier
  266. self.obj.called_commands[4] = []
  267. self.obj.called_commands[6] = []
  268. self.obj.cleanup()
  269. self.assertEqual([self.obj.called_commands[4][0]] +
  270. sorted(self.obj.called_commands[4][1:], key=operator.itemgetter(1)),
  271. [
  272. ['-F', 'QBS-FORWARD'],
  273. ['-F', 'chain-ip4-1'],
  274. ['-X', 'chain-ip4-1'],
  275. ['-F', 'chain-ip4-2'],
  276. ['-X', 'chain-ip4-2'],
  277. ['-t', 'mangle', '-F', 'QBS-POSTROUTING'],
  278. ['-t', 'raw', '-F', 'QBS-PREROUTING'],
  279. ])
  280. self.assertEqual([self.obj.called_commands[6][0]] +
  281. sorted(self.obj.called_commands[6][1:], key=operator.itemgetter(1)),
  282. [
  283. ['-F', 'QBS-FORWARD'],
  284. ['-F', 'chain-ip6-1'],
  285. ['-X', 'chain-ip6-1'],
  286. ['-F', 'chain-ip6-2'],
  287. ['-X', 'chain-ip6-2'],
  288. ['-t', 'mangle', '-F', 'QBS-POSTROUTING'],
  289. ['-t', 'raw', '-F', 'QBS-PREROUTING'],
  290. ])
  291. def test_008_update_connected_ips(self):
  292. self.obj.qdb.entries['/connected-ips'] = b'10.137.0.1 10.137.0.2'
  293. self.obj.called_commands[4] = []
  294. self.obj.update_connected_ips(4)
  295. self.assertEqual(self.obj.called_commands[4], [
  296. ['-t', 'raw', '-F', 'QBS-PREROUTING'],
  297. ['-t', 'mangle', '-F', 'QBS-POSTROUTING'],
  298. ['-t', 'raw', '-A', 'QBS-PREROUTING',
  299. '!', '-i', 'vif+', '-s', '10.137.0.1', '-j', 'DROP'],
  300. ['-t', 'mangle', '-A', 'QBS-POSTROUTING',
  301. '!', '-o', 'vif+', '-d', '10.137.0.1', '-j', 'DROP'],
  302. ['-t', 'raw', '-A', 'QBS-PREROUTING',
  303. '!', '-i', 'vif+', '-s', '10.137.0.2', '-j', 'DROP'],
  304. ['-t', 'mangle', '-A', 'QBS-POSTROUTING',
  305. '!', '-o', 'vif+', '-d', '10.137.0.2', '-j', 'DROP']
  306. ])
  307. def test_009_update_connected_ips_empty(self):
  308. self.obj.qdb.entries['/connected-ips'] = b''
  309. self.obj.called_commands[4] = []
  310. self.obj.update_connected_ips(4)
  311. self.assertEqual(self.obj.called_commands[4], [
  312. ['-t', 'raw', '-F', 'QBS-PREROUTING'],
  313. ['-t', 'mangle', '-F', 'QBS-POSTROUTING'],
  314. ])
  315. def test_010_update_connected_ips_missing(self):
  316. self.obj.called_commands[4] = []
  317. self.obj.update_connected_ips(4)
  318. self.assertEqual(self.obj.called_commands[4], [
  319. ['-t', 'raw', '-F', 'QBS-PREROUTING'],
  320. ['-t', 'mangle', '-F', 'QBS-POSTROUTING'],
  321. ])
  322. class TestNftablesWorker(TestCase):
  323. def setUp(self):
  324. super(TestNftablesWorker, self).setUp()
  325. self.obj = NftablesWorker()
  326. self.subprocess_patch = patch('subprocess.call')
  327. self.subprocess_mock = self.subprocess_patch.start()
  328. def tearDown(self):
  329. self.subprocess_patch.stop()
  330. def test_000_chain_for_addr(self):
  331. self.assertEqual(
  332. self.obj.chain_for_addr('10.137.0.1'), 'qbs-10-137-0-1')
  333. self.assertEqual(
  334. self.obj.chain_for_addr('fd09:24ef:4179:0000::3'),
  335. 'qbs-fd09-24ef-4179-0000--3')
  336. def expected_create_chain(self, family, addr, chain):
  337. return (
  338. 'table {family} qubes-firewall {{\n'
  339. ' chain {chain} {{\n'
  340. ' }}\n'
  341. ' chain forward {{\n'
  342. ' {family} saddr {addr} jump {chain}\n'
  343. ' }}\n'
  344. '}}\n'.format(family=family, addr=addr, chain=chain))
  345. def test_001_create_chain(self):
  346. testdata = [
  347. (4, '10.137.0.1', 'qbs-10-137-0-1'),
  348. (6, 'fd09:24ef:4179:0000::3', 'qbs-fd09-24ef-4179-0000--3')
  349. ]
  350. for family, addr, chain in testdata:
  351. self.obj.create_chain(addr, chain, family)
  352. self.assertEqual(self.obj.loaded_rules,
  353. [self.expected_create_chain('ip', '10.137.0.1', 'qbs-10-137-0-1'),
  354. self.expected_create_chain(
  355. 'ip6', 'fd09:24ef:4179:0000::3', 'qbs-fd09-24ef-4179-0000--3'),
  356. ])
  357. def test_002_prepare_rules4(self):
  358. rules = [
  359. {'action': 'accept', 'proto': 'tcp',
  360. 'dstports': '80-80', 'dst4': '1.2.3.0/24'},
  361. {'action': 'accept', 'proto': 'udp',
  362. 'dstports': '443-1024', 'dsthost': 'yum.qubes-os.org'},
  363. {'action': 'accept', 'specialtarget': 'dns'},
  364. {'action': 'drop', 'proto': 'udp', 'specialtarget': 'dns'},
  365. {'action': 'drop', 'proto': 'icmp'},
  366. {'action': 'drop'},
  367. ]
  368. expected_nft = (
  369. 'flush chain ip qubes-firewall chain\n'
  370. 'table ip qubes-firewall {\n'
  371. ' chain chain {\n'
  372. ' ip protocol tcp ip daddr 1.2.3.0/24 tcp dport 80 accept\n'
  373. ' ip protocol udp ip daddr { 147.75.32.69/32 } '
  374. 'udp dport 443-1024 accept\n'
  375. ' ip daddr { 1.1.1.1/32, 2.2.2.2/32 } tcp dport 53 accept\n'
  376. ' ip daddr { 1.1.1.1/32, 2.2.2.2/32 } udp dport 53 accept\n'
  377. ' ip protocol udp ip daddr { 1.1.1.1/32, 2.2.2.2/32 } udp dport '
  378. '53 reject with icmp type admin-prohibited\n'
  379. ' ip protocol icmp reject with icmp type admin-prohibited\n'
  380. ' reject with icmp type admin-prohibited\n'
  381. ' }\n'
  382. '}\n'
  383. )
  384. self.assertEqual(self.obj.prepare_rules('chain', rules, 4),
  385. expected_nft)
  386. with self.assertRaises(qubesagent.firewall.RuleParseError):
  387. self.obj.prepare_rules('chain', [{'unknown': 'xxx'}], 4)
  388. with self.assertRaises(qubesagent.firewall.RuleParseError):
  389. self.obj.prepare_rules('chain', [{'dst6': 'a::b'}], 4)
  390. with self.assertRaises(qubesagent.firewall.RuleParseError):
  391. self.obj.prepare_rules('chain', [{'dst4': '3.3.3.3'}], 6)
  392. def test_003_prepare_rules6(self):
  393. rules = [
  394. {'action': 'accept', 'proto': 'tcp',
  395. 'dstports': '80-80', 'dst6': 'a::b/128'},
  396. {'action': 'accept', 'proto': 'tcp',
  397. 'dsthost': 'ripe.net'},
  398. {'action': 'accept', 'specialtarget': 'dns'},
  399. {'action': 'drop', 'proto': 'udp', 'specialtarget': 'dns'},
  400. {'action': 'drop', 'proto': 'icmp', 'icmptype': '128'},
  401. {'action': 'drop'},
  402. ]
  403. expected_nft = (
  404. 'flush chain ip6 qubes-firewall chain\n'
  405. 'table ip6 qubes-firewall {\n'
  406. ' chain chain {\n'
  407. ' ip6 nexthdr tcp ip6 daddr a::b/128 tcp dport 80 accept\n'
  408. ' ip6 nexthdr tcp ip6 daddr { 2001:67c:2e8:22::c100:68b/128 } '
  409. 'accept\n'
  410. ' ip6 daddr { 2001::1/128, 2001::2/128 } tcp dport 53 accept\n'
  411. ' ip6 daddr { 2001::1/128, 2001::2/128 } udp dport 53 accept\n'
  412. ' ip6 nexthdr udp ip6 daddr { 2001::1/128, 2001::2/128 } '
  413. 'udp dport 53 reject with icmpv6 type admin-prohibited\n'
  414. ' ip6 nexthdr icmpv6 icmpv6 type 128 reject with icmpv6 type '
  415. 'admin-prohibited\n'
  416. ' reject with icmpv6 type admin-prohibited\n'
  417. ' }\n'
  418. '}\n'
  419. )
  420. self.assertEqual(self.obj.prepare_rules('chain', rules, 6),
  421. expected_nft)
  422. def test_004_apply_rules4(self):
  423. rules = [{'action': 'accept'}]
  424. chain = 'qbs-10-137-0-1'
  425. self.obj.apply_rules('10.137.0.1', rules)
  426. self.assertEqual(self.obj.loaded_rules,
  427. [self.expected_create_chain('ip', '10.137.0.1', chain),
  428. self.obj.prepare_rules(chain, rules, 4),
  429. ])
  430. def test_005_apply_rules6(self):
  431. rules = [{'action': 'accept'}]
  432. chain = 'qbs-2000--a'
  433. self.obj.apply_rules('2000::a', rules)
  434. self.assertEqual(self.obj.loaded_rules,
  435. [self.expected_create_chain('ip6', '2000::a', chain),
  436. self.obj.prepare_rules(chain, rules, 6),
  437. ])
  438. def test_006_init(self):
  439. self.obj.init()
  440. self.assertEqual(self.obj.loaded_rules,
  441. [
  442. 'table ip qubes-firewall {\n'
  443. ' chain forward {\n'
  444. ' type filter hook forward priority 0;\n'
  445. ' policy drop;\n'
  446. ' ct state established,related accept\n'
  447. ' meta iifname != "vif*" accept\n'
  448. ' }\n'
  449. ' chain prerouting {\n'
  450. ' type filter hook prerouting priority -300;\n'
  451. ' policy accept;\n'
  452. ' }\n'
  453. ' chain postrouting {\n'
  454. ' type filter hook postrouting priority -300;\n'
  455. ' policy accept;\n'
  456. ' }\n'
  457. '}\n'
  458. 'table ip6 qubes-firewall {\n'
  459. ' chain forward {\n'
  460. ' type filter hook forward priority 0;\n'
  461. ' policy drop;\n'
  462. ' ct state established,related accept\n'
  463. ' meta iifname != "vif*" accept\n'
  464. ' }\n'
  465. ' chain prerouting {\n'
  466. ' type filter hook prerouting priority -300;\n'
  467. ' policy accept;\n'
  468. ' }\n'
  469. ' chain postrouting {\n'
  470. ' type filter hook postrouting priority -300;\n'
  471. ' policy accept;\n'
  472. ' }\n'
  473. '}\n'
  474. ])
  475. def test_007_cleanup(self):
  476. self.obj.init()
  477. self.obj.create_chain('1.2.3.4', 'chain-ip4-1', 4)
  478. self.obj.create_chain('1.2.3.6', 'chain-ip4-2', 4)
  479. self.obj.create_chain('2000::1', 'chain-ip6-1', 6)
  480. self.obj.create_chain('2000::2', 'chain-ip6-2', 6)
  481. # forget about commands called earlier
  482. self.obj.loaded_rules = []
  483. self.obj.cleanup()
  484. self.assertEqual(self.obj.loaded_rules,
  485. ['delete table ip qubes-firewall\n'
  486. 'delete table ip6 qubes-firewall\n',
  487. ])
  488. def test_008_update_connected_ips(self):
  489. self.obj.qdb.entries['/connected-ips'] = b'10.137.0.1 10.137.0.2'
  490. self.obj.loaded_rules = []
  491. self.obj.update_connected_ips(4)
  492. self.assertEqual(self.obj.loaded_rules, [
  493. 'flush chain ip qubes-firewall prerouting\n'
  494. 'flush chain ip qubes-firewall postrouting\n',
  495. 'table ip qubes-firewall {\n'
  496. ' chain prerouting {\n'
  497. ' iifname != "vif*" ip saddr {10.137.0.1, 10.137.0.2} drop\n'
  498. ' }\n'
  499. ' chain postrouting {\n'
  500. ' oifname != "vif*" ip daddr {10.137.0.1, 10.137.0.2} drop\n'
  501. ' }\n'
  502. '}\n'
  503. ])
  504. def test_009_update_connected_ips_empty(self):
  505. self.obj.qdb.entries['/connected-ips'] = b''
  506. self.obj.loaded_rules = []
  507. self.obj.update_connected_ips(4)
  508. self.assertEqual(self.obj.loaded_rules, [
  509. 'flush chain ip qubes-firewall prerouting\n'
  510. 'flush chain ip qubes-firewall postrouting\n'
  511. ])
  512. def test_010_update_connected_ips_missing(self):
  513. self.obj.loaded_rules = []
  514. self.obj.update_connected_ips(4)
  515. self.assertEqual(self.obj.loaded_rules, [
  516. 'flush chain ip qubes-firewall prerouting\n'
  517. 'flush chain ip qubes-firewall postrouting\n'
  518. ])
  519. class TestFirewallWorker(TestCase):
  520. def setUp(self):
  521. self.obj = FirewallWorker()
  522. rules = {
  523. '10.137.0.1': {
  524. 'policy': b'accept',
  525. '0000': b'proto=tcp dstports=80-80 action=drop',
  526. '0001': b'proto=udp specialtarget=dns action=accept',
  527. '0002': b'proto=udp action=drop',
  528. },
  529. '10.137.0.2': {'policy': b'accept'},
  530. # no policy
  531. '10.137.0.3': {'0000': b'proto=tcp action=accept'},
  532. # no action
  533. '10.137.0.4': {
  534. 'policy': b'drop',
  535. '0000': b'proto=tcp'
  536. },
  537. }
  538. for addr, entries in rules.items():
  539. for key, value in entries.items():
  540. self.obj.qdb.entries[
  541. '/qubes-firewall/{}/{}'.format(addr, key)] = value
  542. self.subprocess_patch = patch('subprocess.call')
  543. self.subprocess_mock = self.subprocess_patch.start()
  544. def tearDown(self):
  545. self.subprocess_patch.stop()
  546. def test_read_rules(self):
  547. expected_rules1 = [
  548. {'proto': 'tcp', 'dstports': '80-80', 'action': 'drop'},
  549. {'proto': 'udp', 'specialtarget': 'dns', 'action': 'accept'},
  550. {'proto': 'udp', 'action': 'drop'},
  551. {'action': 'accept'},
  552. ]
  553. expected_rules2 = [
  554. {'action': 'accept'},
  555. ]
  556. self.assertEqual(self.obj.read_rules('10.137.0.1'), expected_rules1)
  557. self.assertEqual(self.obj.read_rules('10.137.0.2'), expected_rules2)
  558. with self.assertRaises(qubesagent.firewall.RuleParseError):
  559. self.obj.read_rules('10.137.0.3')
  560. with self.assertRaises(qubesagent.firewall.RuleParseError):
  561. self.obj.read_rules('10.137.0.4')
  562. def test_list_targets(self):
  563. self.assertEqual(self.obj.list_targets(), set(['10.137.0.{}'.format(x)
  564. for x in range(1, 5)]))
  565. def test_is_ip6(self):
  566. self.assertTrue(self.obj.is_ip6('2000::abcd'))
  567. self.assertTrue(self.obj.is_ip6('2000:1:2:3:4:5:6:abcd'))
  568. self.assertFalse(self.obj.is_ip6('10.137.0.1'))
  569. def test_handle_addr(self):
  570. self.obj.handle_addr('10.137.0.2')
  571. self.assertEqual(self.obj.rules['10.137.0.2'], [{'action': 'accept'}])
  572. # fallback to block all
  573. self.obj.handle_addr('10.137.0.3')
  574. self.assertEqual(self.obj.rules['10.137.0.3'], [{'action': 'drop'}])
  575. self.obj.handle_addr('10.137.0.4')
  576. self.assertEqual(self.obj.rules['10.137.0.4'], [{'action': 'drop'}])
  577. @patch('os.path.isfile')
  578. @patch('os.access')
  579. @patch('subprocess.call')
  580. def test_run_user_script(self, mock_subprocess, mock_os_access,
  581. mock_os_path_isfile):
  582. mock_os_path_isfile.return_value = False
  583. mock_os_access.return_value = False
  584. super(FirewallWorker, self.obj).run_user_script()
  585. self.assertFalse(mock_subprocess.called)
  586. mock_os_path_isfile.return_value = True
  587. mock_os_access.return_value = False
  588. super(FirewallWorker, self.obj).run_user_script()
  589. self.assertFalse(mock_subprocess.called)
  590. mock_os_path_isfile.return_value = True
  591. mock_os_access.return_value = True
  592. super(FirewallWorker, self.obj).run_user_script()
  593. mock_subprocess.assert_called_once_with(
  594. ['/rw/config/qubes-firewall-user-script'])
  595. def test_main(self):
  596. self.obj.main()
  597. self.assertTrue(self.obj.init_called)
  598. self.assertTrue(self.obj.cleanup_called)
  599. self.assertTrue(self.obj.user_script_called)
  600. self.assertEqual(self.obj.update_connected_ips_called_with, [4, 6])
  601. self.assertEqual(set(self.obj.rules.keys()), self.obj.list_targets())
  602. # rules content were already tested