settings.py 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481
  1. #!/usr/bin/python2.6
  2. #
  3. # The Qubes OS Project, http://www.qubes-os.org
  4. #
  5. # Copyright (C) 2012 Agnieszka Kostrzewa <agnieszka.kostrzewa@gmail.com>
  6. # Copyright (C) 2012 Marek Marczykowski <marmarek@mimuw.edu.pl>
  7. #
  8. # This program is free software; you can redistribute it and/or
  9. # modify it under the terms of the GNU General Public License
  10. # as published by the Free Software Foundation; either version 2
  11. # of the License, or (at your option) any later version.
  12. #
  13. # This program is distributed in the hope that it will be useful,
  14. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. # GNU General Public License for more details.
  17. #
  18. # You should have received a copy of the GNU General Public License
  19. # along with this program; if not, write to the Free Software
  20. # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  21. #
  22. #
  23. import sys
  24. import os
  25. from PyQt4.QtCore import *
  26. from PyQt4.QtGui import *
  27. from qubes.qubes import QubesVmCollection
  28. from qubes.qubes import QubesVmLabels
  29. from qubes.qubes import QubesException
  30. from qubes.qubes import qubes_appmenu_create_cmd
  31. from qubes.qubes import qubes_appmenu_remove_cmd
  32. from qubes.qubes import QubesDaemonPidfile
  33. from qubes.qubes import QubesHost
  34. from qubes.qubes import qrexec_client_path
  35. import qubesmanager.resources_rc
  36. from pyinotify import WatchManager, Notifier, ThreadedNotifier, EventsCodes, ProcessEvent
  37. import subprocess
  38. import time
  39. import threading
  40. from operator import itemgetter
  41. from ui_settingsdlg import *
  42. from multiselectwidget import *
  43. from appmenu_select import *
  44. from firewall import *
  45. class VMSettingsWindow(Ui_SettingsDialog, QDialog):
  46. tabs_indices = {"basic": 0,
  47. "advanced": 1,
  48. "firewall": 2,
  49. "devices": 3,
  50. "applications": 4,
  51. "services": 5,}
  52. def __init__(self, vm, app, qvm_collection, init_page="basic", parent=None):
  53. super(VMSettingsWindow, self).__init__(parent)
  54. self.app = app
  55. self.qvm_collection = qvm_collection
  56. self.vm = vm
  57. if self.vm.template_vm:
  58. self.source_vm = self.vm.template_vm
  59. else:
  60. self.source_vm = self.vm
  61. self.setupUi(self)
  62. if init_page in self.tabs_indices:
  63. idx = self.tabs_indices[init_page]
  64. assert (idx in range(self.tabWidget.count()))
  65. self.tabWidget.setCurrentIndex(idx)
  66. self.connect(self.buttonBox, SIGNAL("accepted()"), self.save_and_apply)
  67. self.connect(self.buttonBox, SIGNAL("rejected()"), self.reject)
  68. self.tabWidget.currentChanged.connect(self.current_tab_changed)
  69. self.tabWidget.setTabEnabled(self.tabs_indices["applications"], not vm.is_netvm())
  70. self.tabWidget.setTabEnabled(self.tabs_indices["firewall"], vm.is_networked() and not (vm.is_netvm() and not vm.is_proxyvm()))
  71. ###### basic tab
  72. self.__init_basic_tab__()
  73. ###### firewall tab
  74. if self.tabWidget.isTabEnabled(self.tabs_indices["firewall"]):
  75. model = QubesFirewallRulesModel()
  76. model.set_vm(vm)
  77. self.set_fw_model(model)
  78. self.newRuleButton.clicked.connect(self.new_rule_button_pressed)
  79. self.editRuleButton.clicked.connect(self.edit_rule_button_pressed)
  80. self.deleteRuleButton.clicked.connect(self.delete_rule_button_pressed)
  81. self.policyAllowRadioButton.toggled.connect(self.policy_radio_toggled)
  82. self.dnsCheckBox.toggled.connect(self.dns_checkbox_toggled)
  83. self.icmpCheckBox.toggled.connect(self.icmp_checkbox_toggled)
  84. ####### devices tab
  85. self.dev_list = MultiSelectWidget(self)
  86. self.devices_layout.addWidget(self.dev_list)
  87. ####### apps tab
  88. if self.tabWidget.isTabEnabled(self.tabs_indices["applications"]):
  89. self.app_list = MultiSelectWidget(self)
  90. self.apps_layout.addWidget(self.app_list)
  91. self.AppListManager = AppmenuSelectManager(self.vm, self.app_list)
  92. def reject(self):
  93. self.done(0)
  94. #needed not to close the dialog before applying changes
  95. def accept(self):
  96. pass
  97. def save_and_apply(self):
  98. thread_monitor = ThreadMonitor()
  99. thread = threading.Thread (target=self.__save_changes__, args=(thread_monitor,))
  100. thread.daemon = True
  101. thread.start()
  102. progress = QProgressDialog ("Applying settings to <b>{0}</b>...".format(self.vm.name), "", 0, 0)
  103. progress.setCancelButton(None)
  104. progress.setModal(True)
  105. progress.show()
  106. while not thread_monitor.is_finished():
  107. self.app.processEvents()
  108. time.sleep (0.1)
  109. progress.hide()
  110. if not thread_monitor.success:
  111. QMessageBox.warning (None, "Error while changing settings for {0}!", "ERROR: {1}".format(self.vm.name, thread_monitor.error_msg))
  112. self.done(0)
  113. def __save_changes__(self, thread_monitor):
  114. if self.tabWidget.isTabEnabled(self.tabs_indices["firewall"]):
  115. self.fw_model.apply_rules()
  116. if self.tabWidget.isTabEnabled(self.tabs_indices["applications"]):
  117. self.AppListManager.save_appmenu_select_changes()
  118. ret = self.__apply_basic_tab__()
  119. if len(ret) > 0 :
  120. thread_monitor.set_error_msg('\n'.join(ret))
  121. thread_monitor.set_finished()
  122. def current_tab_changed(self, idx):
  123. if idx == self.tabs_indices["firewall"]:
  124. if self.vm.netvm is not None and not self.vm.netvm.is_proxyvm():
  125. QMessageBox.warning (None, "VM configuration problem!", "The '{0}' AppVM is not network connected to a FirewallVM!<p>".format(self.vm.name) +\
  126. "You may edit the '{0}' VM firewall rules, but these will not take any effect until you connect it to a working Firewall VM.".format(self.vm.name))
  127. ######### basic tab
  128. def __init_basic_tab__(self):
  129. self.vmname.setText(self.vm.name)
  130. #self.qvm_collection.lock_db_for_reading()
  131. #self.qvm_collection.load()
  132. #self.qvm_collection.unlock_db()
  133. self.label_list = QubesVmLabels.values()
  134. self.label_list.sort(key=lambda l: l.index)
  135. self.label_idx = 0
  136. for (i, label) in enumerate(self.label_list):
  137. if label == self.vm.label:
  138. self.label_idx = i
  139. self.vmlabel.insertItem(i, label.name)
  140. self.vmlabel.setItemIcon (i, QIcon(label.icon_path))
  141. self.vmlabel.setCurrentIndex(self.label_idx)
  142. if not self.vm.is_template() and self.vm.template_vm is not None:
  143. template_vm_list = [vm for vm in self.qvm_collection.values() if not vm.internal and vm.is_template()]
  144. self.template_idx = 0
  145. for (i, vm) in enumerate(template_vm_list):
  146. text = vm.name
  147. if vm is self.qvm_collection.get_default_template_vm():
  148. text += " (default)"
  149. if vm.qid == self.vm.template_vm.qid:
  150. self.template_idx = i
  151. text += " (current)"
  152. self.template_name.insertItem(i, text)
  153. self.template_name.setCurrentIndex(self.template_idx)
  154. else:
  155. self.template_name.setEnabled(False)
  156. if (not self.vm.is_netvm() or self.vm.is_proxyvm()):
  157. netvm_list = [vm for vm in self.qvm_collection.values() if not vm.internal and vm.is_netvm()]
  158. self.netvm_idx = -1
  159. for (i, vm) in enumerate(netvm_list):
  160. text = vm.name
  161. if vm is self.qvm_collection.get_default_netvm():
  162. text += " (default)"
  163. if self.vm.netvm is not None and vm.qid == self.vm.netvm.qid:
  164. self.netvm_idx = i
  165. text += " (current)"
  166. self.netVM.insertItem(i, text)
  167. none_text = "none"
  168. if self.vm.netvm is None:
  169. none_text += " (current)"
  170. self.netvm_idx = len(netvm_list)
  171. self.netVM.insertItem(len(netvm_list), none_text)
  172. self.netVM.setCurrentIndex(self.netvm_idx)
  173. else:
  174. self.netVM.setEnabled(False)
  175. self.include_in_backups.setChecked(self.vm.include_in_backups)
  176. #type
  177. self.type_label.setText(self.vm.type)
  178. #installed by rpm
  179. text = "Yes" if self.vm.installed_by_rpm == True else "No"
  180. self.rpm_label.setText(text)
  181. #maxmem
  182. self.priv_size.setValue(int(self.vm.maxmem)/1024)
  183. self.priv_size.setMinimum(0)
  184. self.priv_size.setMaximum(QubesHost().memory_total/1024/1024)
  185. #self.vmname.selectAll()
  186. #self.vmname.setFocus()
  187. def __apply_basic_tab__(self):
  188. msg = []
  189. # vmname changed
  190. vmname = str(self.vmname.text())
  191. if self.vm.name != vmname:
  192. if self.vm.is_running():
  193. msg.append("Can't change name of a running VM.")
  194. elif self.qvm_collection.get_vm_by_name(vmname) is not None:
  195. msg.append("A VM named <b>{0}</b> already exists in the system!".format(vmname))
  196. else:
  197. oldname = self.vm.name
  198. try:
  199. self.qvm_collection.lock_db_for_writing()
  200. self.vm.pre_rename(vmname)
  201. self.vm.set_name(vmname)
  202. self.vm.post_rename(oldname)
  203. self.qvm_collection.save()
  204. except Exception as ex:
  205. msg.append(str(ex))
  206. finally:
  207. self.qvm_collection.unlock_db()
  208. #vm label changed
  209. if self.vmlabel.currentIndex() != self.label_idx:
  210. if self.vm.is_running():
  211. msg.append("Can't change label of a running VM.")
  212. else:
  213. label = self.label_list[self.vmlabel.currentIndex()]
  214. self.qvm_collection.lock_db_for_writing()
  215. self.vm.label = label
  216. self.qvm_collection.save()
  217. self.qvm_collection.unlock_db()
  218. #vm template changed
  219. if self.template_name.currentIndex() != self.template_idx:
  220. new_template_name = self.template_name.currentText()
  221. new_template_name = new_template_name.split(' ')[0]
  222. template_vm = self.qvm_collection.get_vm_by_name(new_template_name)
  223. assert (template_vm is not None and template_vm.qid in self.qvm_collection)
  224. assert template_vm.is_template()
  225. self.qvm_collection.lock_db_for_writing()
  226. self.vm.template_vm = template_vm
  227. self.qvm_collection.save()
  228. self.qvm_collection.unlock_db()
  229. #vm netvm changed
  230. if self.netVM.currentIndex() != self.netvm_idx:
  231. new_netvm_name = self.netVM.currentText()
  232. new_netvm_name = new_netvm_name.split(' ')[0]
  233. cmd = ["qvm-prefs", "-s", self.vm.name, "netvm", new_netvm_name]
  234. res = subprocess.check_call(cmd, stderr=subprocess.PIPE)
  235. if res != 0:
  236. msg.append("Error while setting netVM!")
  237. #include in backups
  238. self.vm.include_in_backups = self.include_in_backups.isChecked()
  239. #maxmem
  240. maxmem = self.priv_size.value()*1024
  241. if maxmem == 0:
  242. maxmem = 256
  243. self.vm.maxmem = maxmem
  244. return msg
  245. # template_vm = template_vm_list[dialog.template_name.currentIndex()]
  246. # allow_networking = dialog.allow_networking.isChecked()
  247. ######### firewall tab related
  248. def set_fw_model(self, model):
  249. self.fw_model = model
  250. self.rulesTreeView.setModel(model)
  251. self.rulesTreeView.header().setResizeMode(QHeaderView.ResizeToContents)
  252. self.rulesTreeView.header().setResizeMode(0, QHeaderView.Stretch)
  253. self.set_allow(model.allow)
  254. self.dnsCheckBox.setChecked(model.allowDns)
  255. self.icmpCheckBox.setChecked(model.allowIcmp)
  256. def set_allow(self, allow):
  257. self.policyAllowRadioButton.setChecked(allow)
  258. self.policyDenyRadioButton.setChecked(not allow)
  259. def policy_radio_toggled(self, on):
  260. self.fw_model.allow = self.policyAllowRadioButton.isChecked()
  261. def dns_checkbox_toggled(self, on):
  262. self.fw_model.allowDns = on
  263. def icmp_checkbox_toggled(self, on):
  264. self.fw_model.allowIcmp = on
  265. def new_rule_button_pressed(self):
  266. dialog = NewFwRuleDlg()
  267. self.run_rule_dialog(dialog)
  268. def edit_rule_button_pressed(self):
  269. dialog = NewFwRuleDlg()
  270. dialog.set_ok_enabled(True)
  271. selected = self.rulesTreeView.selectedIndexes()
  272. if len(selected) > 0:
  273. row = self.rulesTreeView.selectedIndexes().pop().row()
  274. address = self.fw_model.get_column_string(0, row).replace(' ', '')
  275. dialog.addressComboBox.setItemText(0, address)
  276. dialog.addressComboBox.setCurrentIndex(0)
  277. service = self.fw_model.get_column_string(1, row)
  278. if service == "any":
  279. service = ""
  280. dialog.serviceComboBox.setItemText(0, service)
  281. dialog.serviceComboBox.setCurrentIndex(0)
  282. protocol = self.fw_model.get_column_string(2, row)
  283. if protocol == "tcp":
  284. dialog.tcp_radio.setChecked(True)
  285. elif protocol == "udp":
  286. dialog.udp_radio.setChecked(True)
  287. else:
  288. dialog.any_radio.setChecked(True)
  289. self.run_rule_dialog(dialog, row)
  290. def delete_rule_button_pressed(self):
  291. for i in set([index.row() for index in self.rulesTreeView.selectedIndexes()]):
  292. self.fw_model.removeChild(i)
  293. def run_rule_dialog(self, dialog, row = None):
  294. if dialog.exec_():
  295. address = str(dialog.addressComboBox.currentText())
  296. service = str(dialog.serviceComboBox.currentText())
  297. port = None
  298. port2 = None
  299. unmask = address.split("/", 1)
  300. if len(unmask) == 2:
  301. address = unmask[0]
  302. netmask = int(unmask[1])
  303. else:
  304. netmask = 32
  305. if address == "*":
  306. address = "0.0.0.0"
  307. netmask = 0
  308. if dialog.any_radio.isChecked():
  309. protocol = "any"
  310. port = 0
  311. else:
  312. if dialog.tcp_radio.isChecked():
  313. protocol = "tcp"
  314. elif dialog.udp_radio.isChecked():
  315. protocol = "udp"
  316. try:
  317. range = service.split("-", 1)
  318. if len(range) == 2:
  319. port = int(range[0])
  320. port2 = int(range[1])
  321. else:
  322. port = int(service)
  323. except (TypeError, ValueError) as ex:
  324. port = self.fw_model.get_service_port(service)
  325. if port is not None:
  326. if port2 is not None and port2 <= port:
  327. QMessageBox.warning(None, "Invalid service ports range", "Port {0} is lower than port {1}.".format(port2, port))
  328. else:
  329. item = QubesFirewallRuleItem(address, netmask, port, port2, protocol)
  330. if row is not None:
  331. self.fw_model.setChild(row, item)
  332. else:
  333. self.fw_model.appendChild(item)
  334. else:
  335. QMessageBox.warning(None, "Invalid service name", "Service '{0} is unknown.".format(service))
  336. # Bases on the original code by:
  337. # Copyright (c) 2002-2007 Pascal Varet <p.varet@gmail.com>
  338. def handle_exception( exc_type, exc_value, exc_traceback ):
  339. import sys
  340. import os.path
  341. import traceback
  342. filename, line, dummy, dummy = traceback.extract_tb( exc_traceback ).pop()
  343. filename = os.path.basename( filename )
  344. error = "%s: %s" % ( exc_type.__name__, exc_value )
  345. QMessageBox.critical(None, "Houston, we have a problem...",
  346. "Whoops. A critical error has occured. This is most likely a bug "
  347. "in Qubes VM Settings application.<br><br>"
  348. "<b><i>%s</i></b>" % error +
  349. "at <b>line %d</b> of file <b>%s</b>.<br/><br/>"
  350. % ( line, filename ))
  351. def main():
  352. global qubes_host
  353. qubes_host = QubesHost()
  354. global app
  355. app = QApplication(sys.argv)
  356. app.setOrganizationName("The Qubes Project")
  357. app.setOrganizationDomain("http://qubes-os.org")
  358. app.setApplicationName("Qubes VM Settings")
  359. sys.excepthook = handle_exception
  360. qvm_collection = QubesVmCollection()
  361. qvm_collection.lock_db_for_reading()
  362. qvm_collection.load()
  363. qvm_collection.unlock_db()
  364. vm = None
  365. if len(sys.argv) > 1:
  366. vm = qvm_collection.get_vm_by_name(sys.argv[1])
  367. if vm is None or vm.qid not in qvm_collection:
  368. QMessageBox.critical(None, "Qubes VM Settings Error",
  369. "A VM with the name '{0}' does not exist in the system.".format(sys.argv[1]))
  370. sys.exit(1)
  371. else:
  372. vms_list = [vm.name for vm in qvm_collection.values() if (vm.is_appvm() or vm.is_template())]
  373. vmname = QInputDialog.getItem(None, "Select VM", "Select VM:", vms_list, editable = False)
  374. if not vmname[1]:
  375. sys.exit(1)
  376. vm = qvm_collection.get_vm_by_name(vmname[0])
  377. global settings_window
  378. settings_window = VMSettingsWindow(vm, app, qvm_collection, "basic")
  379. settings_window.show()
  380. app.exec_()
  381. app.exit()
  382. if __name__ == "__main__":
  383. main()