OpenSecurity/bin/vmmanager.pyw
author mb
Tue, 18 Mar 2014 16:31:47 +0100
changeset 96 630b62946c9e
parent 95 cdebb7e0ba10
parent 91 a26757850ea9
child 97 f274426bdbb4
permissions -rwxr-xr-x
merge
mb@96
     1
<<<<<<< local
mb@90
     2
'''
mb@90
     3
Created on Nov 19, 2013
mb@90
     4
mb@90
     5
@author: BarthaM
mb@90
     6
'''
mb@90
     7
import os
mb@90
     8
import os.path
mb@90
     9
from subprocess import Popen, PIPE, call, STARTUPINFO, _subprocess
mb@90
    10
import sys
mb@90
    11
import re
mb@90
    12
mb@90
    13
from cygwin import Cygwin
mb@90
    14
from environment import Environment
mb@90
    15
import threading
mb@90
    16
import time
mb@90
    17
import string
mb@90
    18
mb@90
    19
import shutil
mb@90
    20
import stat
mb@90
    21
import tempfile
mb@90
    22
from opensecurity_util import logger, setupLogger, OpenSecurityException
mb@90
    23
import ctypes
mb@90
    24
import itertools
mb@90
    25
import _winreg
mb@90
    26
DEBUG = True
mb@90
    27
mb@90
    28
class VMManagerException(Exception):
mb@90
    29
    def __init__(self, value):
mb@90
    30
        self.value = value
mb@90
    31
    def __str__(self):
mb@90
    32
        return repr(self.value)
mb@90
    33
mb@90
    34
class USBFilter:
mb@90
    35
    vendorid = ""
mb@90
    36
    productid = ""
mb@90
    37
    revision = ""
mb@90
    38
    
mb@90
    39
    def __init__(self, vendorid, productid, revision):
mb@90
    40
        self.vendorid = vendorid.lower()
mb@90
    41
        self.productid = productid.lower()
mb@90
    42
        self.revision = revision.lower()
mb@90
    43
        return
mb@90
    44
    
mb@90
    45
    def __eq__(self, other):
mb@90
    46
        return self.vendorid == other.vendorid and self.productid == other.productid and self.revision == other.revision
mb@90
    47
    
mb@90
    48
    def __hash__(self):
mb@90
    49
        return hash(self.vendorid) ^ hash(self.productid) ^ hash(self.revision)
mb@90
    50
    
mb@90
    51
    def __repr__(self):
mb@90
    52
        return "VendorId = \'" + str(self.vendorid) + "\' ProductId = \'" + str(self.productid) + "\' Revision = \'" + str(self.revision) + "\'"
mb@90
    53
    
mb@90
    54
    #def __getitem__(self, item):
mb@90
    55
    #    return self.coords[item]
mb@90
    56
 
mb@90
    57
class VMManager(object):
mb@90
    58
    vmRootName = "SecurityDVM"
mb@90
    59
    systemProperties = None
mb@90
    60
    _instance = None
mb@90
    61
    machineFolder = ''
mb@90
    62
    rsdHandler = None
mb@90
    63
    
mb@90
    64
    def __init__(self):
mb@90
    65
        self.systemProperties = self.getSystemProperties()
mb@90
    66
        self.machineFolder = self.systemProperties["Default machine folder"]
mb@90
    67
        self.cleanup()
mb@90
    68
        self.rsdHandler = DeviceHandler(self)
mb@90
    69
        self.rsdHandler.start()
mb@90
    70
        return
mb@90
    71
    
mb@90
    72
    @staticmethod
mb@90
    73
    def getInstance():
mb@90
    74
        if VMManager._instance == None:
mb@90
    75
            VMManager._instance = VMManager()
mb@90
    76
        return VMManager._instance
mb@90
    77
    
mb@90
    78
    def cleanup(self):
mb@90
    79
        if self.rsdHandler != None:
mb@90
    80
            self.rsdHandler.stop()
mb@90
    81
            self.rsdHandler.join()
mb@90
    82
        drives = self.getNetworkDrives()
mb@90
    83
        for drive in drives.keys():
mb@90
    84
            self.unmapNetworkDrive(drive)
mb@90
    85
        for vm in self.listSDVM():
mb@90
    86
            self.poweroffVM(vm)
mb@90
    87
            self.removeVM(vm)
mb@90
    88
        
mb@90
    89
    # return hosty system properties
mb@90
    90
    def getSystemProperties(self):
mb@90
    91
        result = checkResult(Cygwin.vboxExecute('list systemproperties'))
mb@90
    92
        if result[1]=='':
mb@90
    93
            return None
mb@90
    94
        props = dict((k.strip(),v.strip().strip('"')) for k,v in (line.split(':', 1) for line in result[1].strip().splitlines()))
mb@90
    95
        return props
mb@90
    96
    
mb@90
    97
    # return the folder containing the guest VMs     
mb@90
    98
    def getMachineFolder(self):
mb@90
    99
        return self.machineFolder
mb@90
   100
mb@90
   101
    # list all existing VMs registered with VBox
mb@90
   102
    def listVM(self):
mb@90
   103
        result = checkResult(Cygwin.vboxExecute('list vms'))[1]
mb@90
   104
        vms = list(k.strip().strip('"') for k,_ in (line.split(' ') for line in result.splitlines()))
mb@90
   105
        return vms
mb@90
   106
    
mb@90
   107
    # list running VMs
mb@90
   108
    def listRunningVMS(self):
mb@90
   109
        result = checkResult(Cygwin.vboxExecute('list runningvms'))[1]
mb@90
   110
        vms = list(k.strip().strip('"') for k,_ in (line.split(' ') for line in result.splitlines()))
mb@90
   111
        return vms
mb@90
   112
    
mb@90
   113
    # list existing SDVMs
mb@90
   114
    def listSDVM(self):
mb@90
   115
        vms = self.listVM()
mb@90
   116
        svdms = []
mb@90
   117
        for vm in vms:
mb@90
   118
            if vm.startswith(self.vmRootName) and vm != self.vmRootName:
mb@90
   119
                svdms.append(vm)
mb@90
   120
        return svdms
mb@90
   121
    
mb@90
   122
    # generate valid (not already existing SDVM name). necessary for creating a new VM
mb@90
   123
    def generateSDVMName(self):
mb@90
   124
        vms = self.listVM()
mb@90
   125
        for i in range(0,999):
mb@90
   126
            if(not self.vmRootName+str(i) in vms):
mb@90
   127
                return self.vmRootName+str(i)
mb@90
   128
        return ''
mb@90
   129
    
mb@90
   130
    # check if the device is mass storage type
mb@90
   131
    @staticmethod
mb@90
   132
    def isMassStorageDevice(device):
mb@90
   133
        keyname = 'SYSTEM\CurrentControlSet\Enum\USB' + '\VID_' + device.vendorid+'&'+'PID_'+ device.productid
mb@90
   134
        key = _winreg.OpenKey(_winreg.HKEY_LOCAL_MACHINE, keyname)
mb@90
   135
        #subkeys = _winreg.QueryInfoKey(key)[0]
mb@90
   136
        #for i in range(0, subkeys):
mb@90
   137
        #    print _winreg.EnumKey(key, i)     
mb@90
   138
        devinfokeyname = _winreg.EnumKey(key, 0)
mb@90
   139
        _winreg.CloseKey(key)
mb@90
   140
mb@90
   141
        devinfokey = _winreg.OpenKey(_winreg.HKEY_LOCAL_MACHINE, keyname+'\\'+devinfokeyname)
mb@90
   142
        value = _winreg.QueryValueEx(devinfokey, 'SERVICE')[0]
mb@90
   143
        _winreg.CloseKey(devinfokey)
mb@90
   144
        
mb@90
   145
        return 'USBSTOR' in value
mb@90
   146
    
mb@90
   147
    # return the RSDs connected to the host
mb@90
   148
    @staticmethod
mb@90
   149
    def getConnectedRSDS():
mb@90
   150
        results = checkResult(Cygwin.vboxExecute('list usbhost'))[1]
mb@90
   151
        results = results.split('Host USB Devices:')[1].strip()
mb@90
   152
        
mb@90
   153
        items = list( "UUID:"+result for result in results.split('UUID:') if result != '')
mb@90
   154
        rsds = dict()   
mb@90
   155
        for item in items:
mb@90
   156
            props = dict()
mb@90
   157
            for line in item.splitlines():
mb@90
   158
                if line != "":         
mb@90
   159
                    k,v = line[:line.index(':')].strip(), line[line.index(':')+1:].strip()
mb@90
   160
                    props[k] = v
mb@90
   161
            
mb@90
   162
            #if 'Product' in props.keys() and props['Product'] == 'Mass Storage':
mb@90
   163
            
mb@90
   164
            usb_filter = USBFilter( re.search(r"\((?P<vid>[0-9A-Fa-f]+)\)", props['VendorId']).groupdict()['vid'], 
mb@90
   165
                                    re.search(r"\((?P<pid>[0-9A-Fa-f]+)\)", props['ProductId']).groupdict()['pid'],
mb@90
   166
                                    re.search(r"\((?P<rev>[0-9A-Fa-f]+)\)", props['Revision']).groupdict()['rev'] )
mb@90
   167
            if VMManager.isMassStorageDevice(usb_filter):
mb@90
   168
                rsds[props['UUID']] = usb_filter;
mb@90
   169
                logger.debug(usb_filter)
mb@90
   170
        return rsds
mb@90
   171
    
mb@90
   172
    # return the RSDs attached to all existing SDVMs
mb@90
   173
    def getAttachedRSDs(self):
mb@90
   174
        vms = self.listSDVM()
mb@90
   175
        attached_devices = dict()
mb@90
   176
        for vm in vms:
mb@90
   177
            rsd_filter = self.getUSBFilter(vm)
mb@90
   178
            if rsd_filter != None:
mb@90
   179
                attached_devices[vm] = rsd_filter
mb@90
   180
        return attached_devices
mb@90
   181
    
mb@90
   182
    # configures hostonly networking and DHCP server. requires admin rights
mb@90
   183
    def configureHostNetworking(self):
mb@90
   184
        #cmd = 'vboxmanage list hostonlyifs'
mb@90
   185
        #Cygwin.vboxExecute(cmd)
mb@90
   186
        #cmd = 'vboxmanage hostonlyif remove \"VirtualBox Host-Only Ethernet Adapter\"'
mb@90
   187
        #Cygwin.vboxExecute(cmd)
mb@90
   188
        #cmd = 'vboxmanage hostonlyif create'
mb@90
   189
        #Cygwin.vboxExecute(cmd)
mb@90
   190
        checkResult(Cygwin.vboxExecute('hostonlyif ipconfig \"VirtualBox Host-Only Ethernet Adapter\" --ip 192.168.56.1 --netmask 255.255.255.0'))
mb@90
   191
        #cmd = 'vboxmanage dhcpserver add'
mb@90
   192
        #Cygwin.vboxExecute(cmd)
mb@90
   193
        checkResult(Cygwin.vboxExecute('dhcpserver modify --ifname \"VirtualBox Host-Only Ethernet Adapter\" --ip 192.168.56.100 --netmask 255.255.255.0 --lowerip 192.168.56.101 --upperip 192.168.56.200'))
mb@90
   194
    
mb@90
   195
    #create new virtual machine instance based on template vm named SecurityDVM (\SecurityDVM\SecurityDVM.vmdk)
mb@90
   196
    def createVM(self, vm_name):
mb@90
   197
        hostonly_if = self.getHostOnlyIFs()
mb@90
   198
        checkResult(Cygwin.vboxExecute('createvm --name ' + vm_name + ' --ostype Debian --register'))
mb@90
   199
        checkResult(Cygwin.vboxExecute('modifyvm ' + vm_name + ' --memory 512 --vram 10 --cpus 1 --usb on --usbehci on --nic1 hostonly --hostonlyadapter1 \"' + hostonly_if['Name'] + '\" --nic2 nat'))
mb@90
   200
        checkResult(Cygwin.vboxExecute('storagectl ' + vm_name + ' --name SATA --add sata --portcount 2'))
mb@90
   201
        return
mb@90
   202
    
mb@90
   203
    # attach storage image to controller
mb@90
   204
    def storageAttach(self, vm_name):
mb@90
   205
        if self.isStorageAttached(vm_name):
mb@90
   206
            self.storageDetach(vm_name)
mb@90
   207
        checkResult(Cygwin.vboxExecute('storageattach ' + vm_name + ' --storagectl SATA --port 0 --device 0 --type hdd --medium \"'+ self.machineFolder + '\SecurityDVM\SecurityDVM.vmdk\"'))
mb@90
   208
    
mb@90
   209
    # return true if storage is attached 
mb@90
   210
    def isStorageAttached(self, vm_name):
mb@90
   211
        info = self.getVMInfo(vm_name)
mb@90
   212
        return (info['SATA-0-0']!='none')
mb@90
   213
    
mb@90
   214
    # detach storage from controller
mb@90
   215
    def storageDetach(self, vm_name):
mb@90
   216
        if self.isStorageAttached(vm_name):
mb@90
   217
            checkResult(Cygwin.vboxExecute('storageattach ' + vm_name + ' --storagectl SATA --port 0 --device 0 --type hdd --medium none'))
mb@90
   218
    
mb@90
   219
    def changeStorageType(self, filename, storage_type):
mb@90
   220
        checkResult(Cygwin.vboxExecute('modifyhd \"' + filename + '\" --type ' + storage_type))
mb@90
   221
    
mb@90
   222
    # list storage snaphots for VM
mb@90
   223
    def updateTemplate(self):
mb@95
   224
mb@90
   225
        self.cleanup()
mb@90
   226
        self.poweroffVM('SecurityDVM')
mb@90
   227
        self.waitShutdown('SecurityDVM')
mb@90
   228
        
mb@90
   229
        # check for updates
mb@90
   230
        self.genCertificateISO('SecurityDVM')
mb@90
   231
        self.attachCertificateISO('SecurityDVM')
mb@90
   232
        
mb@90
   233
        self.storageDetach('SecurityDVM')
mb@90
   234
        results = checkResult(Cygwin.vboxExecute('list hdds'))[1]
mb@90
   235
        results = results.replace('Parent UUID', 'Parent')
mb@90
   236
        items = list( "UUID:"+result for result in results.split('UUID:') if result != '')
mb@90
   237
        
mb@90
   238
        snaps = dict()   
mb@90
   239
        for item in items:
mb@90
   240
            props = dict()
mb@90
   241
            for line in item.splitlines():
mb@90
   242
                if line != "":         
mb@90
   243
                    k,v = line[:line.index(':')].strip(), line[line.index(':')+1:].strip()
mb@90
   244
                    props[k] = v;
mb@90
   245
            snaps[props['UUID']] = props
mb@90
   246
        
mb@90
   247
        
mb@90
   248
        template_storage = self.machineFolder + '\SecurityDVM\SecurityDVM.vmdk'
mb@90
   249
        
mb@90
   250
        # find template uuid
mb@90
   251
        template_uuid = ''
mb@90
   252
        for hdd in snaps.values():
mb@90
   253
            if hdd['Location'] == template_storage:
mb@90
   254
                template_uuid = hdd['UUID']
mb@90
   255
        logger.debug('found parent uuid ' + template_uuid)
mb@90
   256
        
mb@90
   257
        # remove snapshots 
mb@90
   258
        for hdd in snaps.values():
mb@90
   259
            if hdd['Parent'] == template_uuid:
mb@90
   260
                #template_uuid = hdd['UUID']
mb@90
   261
                logger.debug('removing snapshot ' + hdd['UUID'])
mb@90
   262
                checkResult(Cygwin.vboxExecute('closemedium disk {' + hdd['UUID'] + '} --delete'))#[1]
mb@90
   263
                # parse result 0%...10%...20%...30%...40%...50%...60%...70%...80%...90%...100%
mb@90
   264
        
mb@90
   265
        self.changeStorageType(template_storage,'normal')
mb@90
   266
        self.storageAttach('SecurityDVM')
mb@90
   267
        self.startVM('SecurityDVM')
mb@90
   268
        self.waitStartup('SecurityDVM')
mb@90
   269
        checkResult(Cygwin.sshExecute('"sudo apt-get -y update"', VMManager.getHostOnlyIP('SecurityDVM'), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + 'SecurityDVM' + '/dvm_key'))
mb@90
   270
        checkResult(Cygwin.sshExecute('"sudo apt-get -y upgrade"', VMManager.getHostOnlyIP('SecurityDVM'), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + 'SecurityDVM' + '/dvm_key'))
mb@90
   271
        #self.stopVM('SecurityDVM')
mb@90
   272
        self.hibernateVM('SecurityDVM')
mb@90
   273
        self.waitShutdown('SecurityDVM')
mb@90
   274
        self.storageDetach('SecurityDVM')
mb@90
   275
        self.changeStorageType(template_storage,'immutable')
mb@90
   276
        self.storageAttach('SecurityDVM')
mb@90
   277
        self.rsdHandler = DeviceHandler(self)
mb@90
   278
        self.rsdHandler.start()
mb@90
   279
    
mb@90
   280
    #remove VM from the system. should be used on VMs returned by listSDVMs    
mb@90
   281
    def removeVM(self, vm_name):
mb@90
   282
        logger.info('Removing ' + vm_name)
mb@90
   283
        checkResult(Cygwin.vboxExecute('unregistervm ' + vm_name + ' --delete'))
mb@90
   284
        machineFolder = Cygwin.cygPath(self.machineFolder)
mb@90
   285
        checkResult(Cygwin.bashExecute('"/usr/bin/rm -rf ' + machineFolder + '/' + vm_name + '"'))
mb@90
   286
    
mb@90
   287
    # start VM
mb@90
   288
    def startVM(self, vm_name):
mb@90
   289
        logger.info('Starting ' +  vm_name)
mb@90
   290
        result = checkResult(Cygwin.vboxExecute('startvm ' + vm_name + ' --type headless' ))
mb@90
   291
        while 'successfully started' not in result[1]:
mb@90
   292
            logger.error("Failed to start SDVM: " + vm_name + " retrying")
mb@90
   293
            time.sleep(1)
mb@90
   294
            result = checkResult(Cygwin.vboxExecute('startvm ' + vm_name + ' --type headless'))
mb@90
   295
        return result[0]
mb@90
   296
    
mb@90
   297
    # return wether VM is running or not
mb@90
   298
    def isVMRunning(self, vm_name):
mb@90
   299
        return vm_name in self.listRunningVMS()    
mb@90
   300
    
mb@90
   301
    # stop VM
mb@90
   302
    def stopVM(self, vm_name):
mb@90
   303
        logger.info('Sending shutdown signal to ' + vm_name)
mb@90
   304
        checkResult(Cygwin.sshExecute( '"sudo shutdown -h now"', VMManager.getHostOnlyIP(vm_name), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + vm_name + '/dvm_key' ))
mb@90
   305
    
mb@90
   306
    # stop VM
mb@90
   307
    def hibernateVM(self, vm_name):
mb@95
   308
        logger.info('Sending hibernate-disk signal to ' + vm_name)
mb@90
   309
        checkResult(Cygwin.sshExecute( '"sudo hibernate-disk&"', VMManager.getHostOnlyIP(vm_name), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + vm_name + '/dvm_key', wait_return=False))
mb@90
   310
            
mb@90
   311
    # poweroff VM
mb@90
   312
    def poweroffVM(self, vm_name):
mb@90
   313
        if not self.isVMRunning(vm_name):
mb@90
   314
            return
mb@90
   315
        logger.info('Powering off ' + vm_name)
mb@90
   316
        return checkResult(Cygwin.vboxExecute('controlvm ' + vm_name + ' poweroff'))
mb@90
   317
    
mb@90
   318
    #list the hostonly IFs exposed by the VBox host
mb@90
   319
    @staticmethod    
mb@90
   320
    def getHostOnlyIFs():
mb@90
   321
        result = Cygwin.vboxExecute('list hostonlyifs')[1]
mb@90
   322
        if result=='':
mb@90
   323
            return None
mb@90
   324
        props = dict((k.strip(),v.strip().strip('"')) for k,v in (line.split(':', 1) for line in result.strip().splitlines()))
mb@90
   325
        return props
mb@90
   326
    
mb@90
   327
    # return the hostOnly IP for a running guest or the host
mb@90
   328
    @staticmethod    
mb@90
   329
    def getHostOnlyIP(vm_name):
mb@90
   330
        if vm_name == None:
mb@90
   331
            logger.info('Gettting hostOnly IP address for Host')
mb@90
   332
            return VMManager.getHostOnlyIFs()['IPAddress']
mb@90
   333
        else:
mb@90
   334
            logger.info('Gettting hostOnly IP address ' + vm_name)
mb@90
   335
            result = checkResult(Cygwin.vboxExecute('guestproperty get ' + vm_name + ' /VirtualBox/GuestInfo/Net/0/V4/IP'))
mb@90
   336
            if result=='':
mb@90
   337
                return None
mb@90
   338
            result = result[1]
mb@90
   339
            if result.startswith('No value set!'):
mb@90
   340
                return None
mb@90
   341
            return result[result.index(':')+1:].strip()
mb@90
   342
            
mb@90
   343
    # attach removable storage device to VM by provision of filter
mb@90
   344
    def attachRSD(self, vm_name, rsd_filter):
mb@90
   345
        return checkResult(Cygwin.vboxExecute('usbfilter add 0 --target ' + vm_name + ' --name OpenSecurityRSD --vendorid ' + rsd_filter.vendorid + ' --productid ' + rsd_filter.productid + ' --revision ' + rsd_filter.revision))
mb@90
   346
    
mb@90
   347
    # detach removable storage from VM by 
mb@90
   348
    def detachRSD(self, vm_name):
mb@90
   349
        return checkResult(Cygwin.vboxExecute('usbfilter remove 0 --target ' + vm_name))
mb@90
   350
        
mb@90
   351
    # return the description set for an existing VM
mb@90
   352
    def getVMInfo(self, vm_name):
mb@90
   353
        results = checkResult(Cygwin.vboxExecute('showvminfo ' + vm_name + ' --machinereadable'))[1]
mb@90
   354
        props = dict((k.strip().strip('"'),v.strip().strip('"')) for k,v in (line.split('=', 1) for line in results.splitlines()))
mb@90
   355
        return props
mb@90
   356
    
mb@90
   357
    # return the configured USB filter for an existing VM 
mb@90
   358
    def getUSBFilter(self, vm_name):
mb@90
   359
        props = self.getVMInfo(vm_name)
mb@90
   360
        keys = set(['USBFilterVendorId1', 'USBFilterProductId1', 'USBFilterRevision1'])
mb@90
   361
        keyset = set(props.keys())
mb@90
   362
        usb_filter = None
mb@90
   363
        if keyset.issuperset(keys):
mb@90
   364
            usb_filter = USBFilter(props['USBFilterVendorId1'], props['USBFilterProductId1'], props['USBFilterRevision1'])
mb@90
   365
        return usb_filter
mb@90
   366
    
mb@90
   367
    #generates ISO containing authorized_keys for use with guest VM
mb@90
   368
    def genCertificateISO(self, vm_name):
mb@90
   369
        machineFolder = Cygwin.cygPath(self.machineFolder)
mb@90
   370
        # remove .ssh folder if exists
mb@90
   371
        checkResult(Cygwin.bashExecute('\"/usr/bin/rm -rf \\\"' + machineFolder + '/' + vm_name + '/.ssh\\\"\"'))
mb@90
   372
        # remove .ssh folder if exists
mb@90
   373
        checkResult(Cygwin.bashExecute('\"/usr/bin/rm -rf \\\"' + machineFolder + '/' + vm_name + '/dvm_key\\\"\"'))
mb@90
   374
        # create .ssh folder in vm_name
mb@90
   375
        checkResult(Cygwin.bashExecute('\"/usr/bin/mkdir -p \\\"' + machineFolder + '/' + vm_name + '/.ssh\\\"\"'))
mb@90
   376
        # generate dvm_key pair in vm_name / .ssh     
mb@90
   377
        checkResult(Cygwin.bashExecute('\"/usr/bin/ssh-keygen -q -t rsa -N \\"\\" -C \\\"' + vm_name + '\\\" -f \\\"' + machineFolder + '/' + vm_name + '/.ssh/dvm_key\\\"\"'))
mb@90
   378
        # move out private key
mb@90
   379
        checkResult(Cygwin.bashExecute('\"/usr/bin/mv \\\"' + machineFolder + '/' + vm_name + '/.ssh/dvm_key\\\" \\\"' + machineFolder + '/' + vm_name + '\\\"'))
mb@90
   380
        # set permissions for private key
mb@90
   381
        checkResult(Cygwin.bashExecute('\"/usr/bin/chmod 500 \\\"' + machineFolder + '/' + vm_name + '/dvm_key\\\"\"'))
mb@90
   382
        # rename public key to authorized_keys
mb@90
   383
        checkResult(Cygwin.bashExecute('\"/usr/bin/mv \\\"' + machineFolder + '/' + vm_name + '/.ssh/dvm_key.pub\\\" \\\"' + machineFolder + '/' + vm_name + '/.ssh/authorized_keys\\\"'))
mb@90
   384
        # set permissions for authorized_keys
mb@90
   385
        checkResult(Cygwin.bashExecute('\"/usr/bin/chmod 500 \\\"' + machineFolder + '/' + vm_name + '/.ssh/authorized_keys\\\"\"'))
mb@90
   386
        # generate iso image with .ssh/authorized keys
mb@90
   387
        checkResult(Cygwin.bashExecute('\"/usr/bin/genisoimage -J -R -o \\\"' + machineFolder + '/' + vm_name + '/'+ vm_name + '.iso\\\" \\\"' + machineFolder + '/' + vm_name + '/.ssh\\\"\"'))
mb@90
   388
    
mb@90
   389
    # attaches generated ssh public cert to guest vm
mb@90
   390
    def attachCertificateISO(self, vm_name):
mb@90
   391
        result = checkResult(Cygwin.vboxExecute('storageattach ' + vm_name + ' --storagectl SATA --port 1 --device 0 --type dvddrive --mtype readonly --medium \"' + self.machineFolder + '\\' + vm_name + '\\'+ vm_name + '.iso\"'))
mb@90
   392
        return result
mb@90
   393
    
mb@90
   394
    # wait for machine to come up
mb@90
   395
    def waitStartup(self, vm_name, timeout_ms = 30000):
mb@90
   396
        checkResult(Cygwin.vboxExecute('guestproperty wait ' + vm_name + ' SDVMStarted --timeout ' + str(timeout_ms) + ' --fail-on-timeout'))
mb@90
   397
        return VMManager.getHostOnlyIP(vm_name)
mb@90
   398
    
mb@90
   399
    # wait for machine to shutdown
mb@90
   400
    def waitShutdown(self, vm_name):
mb@90
   401
        while vm_name in self.listRunningVMS():
mb@90
   402
            time.sleep(1)
mb@90
   403
        return
mb@90
   404
        
mb@90
   405
    # handles browsing request    
mb@90
   406
    def handleBrowsingRequest(self):
mb@90
   407
        handler = BrowsingHandler(self)
mb@90
   408
        handler.start()
mb@90
   409
        return 'ok'
mb@90
   410
    
mb@90
   411
    #Small function to check the availability of network resource.
mb@90
   412
    #def isAvailable(self, path):
mb@90
   413
        #return os.path.exists(path)
mb@90
   414
        #result = Cygwin.cmdExecute('IF EXIST "' + path + '" echo YES')
mb@90
   415
        #return string.find(result[1], 'YES',)
mb@90
   416
    
mb@90
   417
    #Small function to check if the mention location is a directory
mb@90
   418
    def isDirectory(self, path):
mb@90
   419
        result = checkResult(Cygwin.cmdExecute('dir ' + path + ' | FIND ".."'))
mb@90
   420
        return string.find(result[1], 'DIR',)
mb@90
   421
mb@90
   422
    def mapNetworkDrive(self, drive, networkPath, user, password):
mb@90
   423
        self.unmapNetworkDrive(drive)
mb@90
   424
        #Check for drive availability
mb@90
   425
        if os.path.exists(drive):
mb@90
   426
            logger.error("Drive letter is already in use: " + drive)
mb@90
   427
            return -1
mb@90
   428
        #Check for network resource availability
mb@90
   429
        retry = 5
mb@90
   430
        while not os.path.exists(networkPath):
mb@90
   431
            time.sleep(1)
mb@90
   432
            if retry == 0:
mb@90
   433
                return -1
mb@90
   434
            logger.info("Path not accessible: " + networkPath + " retrying")
mb@90
   435
            retry-=1
mb@90
   436
            #return -1
mb@90
   437
    
mb@90
   438
        command = 'USE ' + drive + ' ' + networkPath + ' /PERSISTENT:NO'
mb@90
   439
        if user != None:
mb@90
   440
            command += ' ' + password + ' /User' + user
mb@90
   441
    
mb@90
   442
        #TODO: Execute 'NET USE' command with authentication
mb@90
   443
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', command))
mb@90
   444
        if string.find(result[1], 'successfully',) == -1:
mb@90
   445
            logger.error("Failed: NET " + command)
mb@90
   446
            return -1
mb@90
   447
        return 1
mb@90
   448
    
mb@90
   449
    def unmapNetworkDrive(self, drive):
mb@90
   450
        drives = self.getNetworkDrives()
mb@90
   451
        if drive not in drives.keys():
mb@90
   452
            return 1 
mb@90
   453
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', 'USE ' + drive + ' /DELETE /YES'))
mb@90
   454
        if string.find(str(result[1]), 'successfully',) == -1:
mb@90
   455
            logger.error(result[2])
mb@90
   456
            return -1
mb@90
   457
        return 1
mb@90
   458
    
mb@90
   459
    def getNetworkDrives(self):
mb@90
   460
        ip = VMManager.getHostOnlyIP(None)
mb@90
   461
        ip = ip[:ip.rindex('.')]
mb@90
   462
        drives = dict()    
mb@90
   463
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', 'USE'))
mb@90
   464
        for line in result[1].splitlines():
mb@90
   465
            if ip in line:
mb@90
   466
                parts = line.split()
mb@90
   467
                drives[parts[1]] = parts[2]
mb@90
   468
        return drives
mb@90
   469
            
mb@90
   470
    def genNetworkDrive(self):
mb@90
   471
        network_drives = self.getNetworkDrives()
mb@90
   472
        logical_drives = VMManager.getLogicalDrives()
mb@90
   473
        drives = list(map(chr, range(68, 91)))  
mb@90
   474
        for drive in drives:
mb@90
   475
            if drive+':' not in network_drives and drive not in logical_drives:
mb@90
   476
                return drive+':'
mb@90
   477
mb@90
   478
    def getNetworkDrive(self, vm_name):
mb@90
   479
        ip = self.getHostOnlyIP(vm_name)
mb@90
   480
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', 'USE'))
mb@90
   481
        for line in result[1].splitlines():
mb@90
   482
            if line != None and ip in line:
mb@90
   483
                parts = line.split()
mb@90
   484
                return parts[0]
mb@90
   485
    @staticmethod
mb@90
   486
    def getLogicalDrives():
mb@90
   487
        drive_bitmask = ctypes.cdll.kernel32.GetLogicalDrives()
mb@90
   488
        return list(itertools.compress(string.ascii_uppercase,  map(lambda x:ord(x) - ord('0'), bin(drive_bitmask)[:1:-1])))
mb@90
   489
    
mb@90
   490
    @staticmethod
mb@90
   491
    def getDriveType(drive):
mb@90
   492
        return ctypes.cdll.kernel32.GetDriveTypeW(u"%s:\\"%drive)
mb@90
   493
    
mb@90
   494
    @staticmethod
mb@90
   495
    def getVolumeInfo(drive):
mb@90
   496
        volumeNameBuffer = ctypes.create_unicode_buffer(1024)
mb@90
   497
        fileSystemNameBuffer = ctypes.create_unicode_buffer(1024)
mb@90
   498
        serial_number = None
mb@90
   499
        max_component_length = None
mb@90
   500
        file_system_flags = None
mb@90
   501
        
mb@90
   502
        rc = ctypes.cdll.kernel32.GetVolumeInformationW(
mb@90
   503
            #ctypes.c_wchar_p("F:\\"),
mb@90
   504
            u"%s:\\"%drive,
mb@90
   505
            volumeNameBuffer,
mb@90
   506
            ctypes.sizeof(volumeNameBuffer),
mb@90
   507
            serial_number,
mb@90
   508
            max_component_length,
mb@90
   509
            file_system_flags,
mb@90
   510
            fileSystemNameBuffer,
mb@90
   511
            ctypes.sizeof(fileSystemNameBuffer)
mb@90
   512
        )
mb@90
   513
        
mb@90
   514
        return volumeNameBuffer.value, fileSystemNameBuffer.value
mb@90
   515
mb@90
   516
def checkResult(result):
mb@90
   517
    if result[0] != 0:
mb@90
   518
        logger.error('Command failed:' + ''.join(result[2]))
mb@90
   519
        raise OpenSecurityException('Command failed:' + ''.join(result[2]))
mb@90
   520
    return result
mb@90
   521
mb@90
   522
# handles browsing request                    
mb@95
   523
class BrowsingHandler(threading.Thread):   
mb@90
   524
    vmm = None
mb@90
   525
    def __init__(self, vmmanager):
mb@90
   526
        threading.Thread.__init__(self)
mb@90
   527
        self.vmm = vmmanager
mb@90
   528
     
mb@90
   529
    def run(self):
mb@90
   530
        try:
mb@95
   531
            Cygwin.start_X11()
mb@90
   532
            new_sdvm = self.vmm.generateSDVMName()
mb@90
   533
            self.vmm.createVM(new_sdvm)
mb@90
   534
            self.vmm.storageAttach(new_sdvm)
mb@90
   535
            self.vmm.genCertificateISO(new_sdvm)
mb@90
   536
            self.vmm.attachCertificateISO(new_sdvm)
mb@90
   537
            self.vmm.startVM(new_sdvm)
mb@90
   538
            new_ip = self.vmm.waitStartup(new_sdvm)
mb@90
   539
            drive = self.vmm.genNetworkDrive()
mb@90
   540
            if new_ip != None:
mb@90
   541
                self.vmm.mapNetworkDrive(drive, '\\\\' + new_ip + '\\Download', None, None)
mb@95
   542
            #browser = '/usr/bin/iceweasel'
mb@95
   543
            #browser = '/usr/bin/midori'
mb@95
   544
            browser = '/usr/bin/chromium'
mb@95
   545
            result = checkResult(Cygwin.sshExecuteX11(browser, new_ip, 'osecuser', Cygwin.cygPath(self.vmm.getMachineFolder()) + '/' + new_sdvm + '/dvm_key'))
mb@90
   546
        except:
mb@90
   547
            logger.error("BrowsingHandler failed. Cleaning up")
mb@90
   548
            
mb@90
   549
        self.vmm.unmapNetworkDrive(drive)
mb@90
   550
        self.vmm.poweroffVM(new_sdvm)
mb@90
   551
        self.vmm.removeVM(new_sdvm)
mb@90
   552
                
mb@90
   553
class DeviceHandler(threading.Thread): 
mb@90
   554
    vmm = None
mb@90
   555
    attachedRSDs = None  
mb@90
   556
    connectedRSDs = None
mb@90
   557
    running = True
mb@90
   558
    def __init__(self, vmmanger): 
mb@90
   559
        threading.Thread.__init__(self)
mb@90
   560
        self.vmm = vmmanger
mb@90
   561
 
mb@90
   562
    def stop(self):
mb@90
   563
        self.running = False
mb@90
   564
        
mb@90
   565
    def run(self):
mb@90
   566
        self.connectedRSDs = dict()
mb@90
   567
        while self.running:
mb@90
   568
            tmp_rsds = self.vmm.getConnectedRSDS()
mb@95
   569
            
mb@95
   570
            self.attachedRSDs = self.vmm.getAttachedRSDs()
mb@95
   571
            for vm_name in self.attachedRSDs.keys():
mb@95
   572
                if self.attachedRSDs[vm_name] not in tmp_rsds.values():
mb@95
   573
                    drive = self.vmm.getNetworkDrive(vm_name)
mb@95
   574
                    self.vmm.unmapNetworkDrive(drive)
mb@95
   575
                    #self.stopVM(vm_name)
mb@95
   576
                    self.vmm.detachRSD(vm_name)
mb@95
   577
                    self.vmm.poweroffVM(vm_name)
mb@95
   578
                    self.vmm.removeVM(vm_name)
mb@95
   579
                    break
mb@95
   580
                    
mb@95
   581
                    
mb@90
   582
            if tmp_rsds.keys() == self.connectedRSDs.keys():
mb@90
   583
                logger.debug("Nothing's changed. sleep(3)")
mb@90
   584
                time.sleep(3)
mb@90
   585
                continue
mb@90
   586
            
mb@90
   587
            logger.info("Something's changed")          
mb@90
   588
            self.connectedRSDs = tmp_rsds
mb@90
   589
            
mb@95
   590
            
mb@95
   591
            
mb@90
   592
            #create new vm for attached device if any
mb@90
   593
            self.attachedRSDs = self.vmm.getAttachedRSDs()
mb@90
   594
            self.connectedRSDs = self.vmm.getConnectedRSDS()
mb@90
   595
            
mb@90
   596
            new_ip = None
mb@90
   597
            for connected_device in self.connectedRSDs.values():
mb@90
   598
                if (self.attachedRSDs and False) or (connected_device not in self.attachedRSDs.values()):
mb@90
   599
                    new_sdvm = self.vmm.generateSDVMName()
mb@90
   600
                    self.vmm.createVM(new_sdvm)
mb@90
   601
                    self.vmm.storageAttach(new_sdvm)
mb@90
   602
                    self.vmm.attachRSD(new_sdvm, connected_device)
mb@90
   603
                    self.vmm.startVM(new_sdvm)
mb@90
   604
                    new_ip = self.vmm.waitStartup(new_sdvm)
mb@90
   605
                    drive = self.vmm.genNetworkDrive()
mb@90
   606
                    if new_ip != None:
mb@90
   607
                        self.vmm.mapNetworkDrive(drive, '\\\\' + new_ip + '\\USB', None, None)
mb@90
   608
mb@90
   609
if __name__ == '__main__':
mb@90
   610
    #man = VMManager.getInstance()
mb@90
   611
    #man.listVM()
mb@90
   612
    #print man.getConnectedRSDs()
mb@90
   613
    #print man.getNetworkDrives()
mb@90
   614
    #man.genNetworkDrive()
mb@90
   615
    #drive_bitmask = ctypes.cdll.kernel32.GetLogicalDrives()
mb@90
   616
    #print list(itertools.compress(string.ascii_uppercase,  map(lambda x:ord(x) - ord('0'), bin(drive_bitmask)[:1:-1])))
mb@90
   617
    #print list(map(chr, range(68, 91))) 
mb@90
   618
    #print Cygwin.getRegEntry('SYSTEM\CurrentControlSet\Enum\USB', 'VID_1058&PID_0704')[0]
mb@90
   619
    #devices = VMManager.getConnectedRSDS()
mb@90
   620
    #print devices
mb@90
   621
    
mb@90
   622
    drives = VMManager.getLogicalDrives()
mb@90
   623
    print drives
mb@90
   624
    print VMManager.getDriveType("E")
mb@90
   625
    print VMManager.getVolumeInfo("E")
mb@90
   626
    #for device in devices.values():
mb@90
   627
    #    #print device
mb@90
   628
    #    if VMManager.isMassStorageDevice(device):
mb@90
   629
    #        print device
mb@90
   630
        
mb@90
   631
    
mb@90
   632
    
mb@90
   633
    #time.sleep(-1)
mb@90
   634
    #man.listVM()
mb@90
   635
    #man.listVM()
mb@90
   636
    #man.listVM()
mb@90
   637
    #man.listVM()
mb@90
   638
    #man.genCertificateISO('SecurityDVM0')
mb@90
   639
    #man.guestExecute('SecurityDVM0', '/bin/ls -la')
mb@90
   640
    #logger = setupLogger('VMManager')
mb@90
   641
    #c = Cygwin()
mb@90
   642
    
mb@90
   643
    #man.sshExecute('/bin/ls -la', 'SecurityDVM0')
mb@90
   644
    #man.sshExecuteX11('/usr/bin/iceweasel', 'SecurityDVM0')
mb@90
   645
    #man.removeVM('SecurityDVM0')
mb@90
   646
    #man.netUse('192.168.56.134', 'USB\\')
mb@90
   647
    #ip = '192.168.56.139'
mb@90
   648
    
mb@90
   649
    #man.cygwin_path = 'c:\\cygwin64\\bin\\'
mb@90
   650
    #man.handleDeviceChange()
mb@90
   651
    #print man.listSDVM()
mb@90
   652
    #man.configureHostNetworking()
mb@90
   653
    #new_vm = man.generateSDVMName()
mb@90
   654
    #man.createVM(new_vm)
mb@90
   655
    
mb@90
   656
    #print Cygwin.cmd()
mb@90
   657
    #man.isAvailable('c:')
mb@90
   658
    #ip = man.getHostOnlyIP('SecurityDVM0')
mb@90
   659
    #man.mapNetworkDrive('h:', '\\\\' + ip + '\Download', None, None)
mb@90
   660
    
mb@90
   661
    #man.genCertificateISO(new_vm)
mb@90
   662
    #man.attachCertificateISO(new_vm)
mb@90
   663
    
mb@90
   664
    #man.attachCertificateISO(vm_name)
mb@90
   665
    #man.guestExecute(vm_name, "ls")
mb@90
   666
    #man.sshGuestX11Execute('SecurityDVM1', '/usr/bin/iceweasel')
mb@90
   667
    #time.sleep(60)
mb@90
   668
    #print man.cygwinPath("C:\Users\BarthaM\VirtualBox VMs\SecurityDVM\.ssh\*")
mb@90
   669
    #man.genCertificateISO('SecurityDVM')
mb@90
   670
    #man.attachCertificateISO('SecurityDVM')
mb@90
   671
    #man.isStorageAttached('SecurityDVM')
mb@90
   672
    #man.guestExecute('SecurityDVM', 'sudo apt-get -y update')
mb@90
   673
    #man.guestExecute('SecurityDVM', 'sudo apt-get -y upgrade' )
mb@90
   674
    
mb@90
   675
    #man.stopVM('SecurityDVM')
mb@90
   676
    #man.storageDetach('SecurityDVM')
mb@90
   677
    #man.changeStorageType('C:\Users\BarthaM\VirtualBox VMs\SecurityDVM\SecurityDVM.vmdk','immutable')
mb@90
   678
    #man.storageAttach('SecurityDVM')
mb@90
   679
    
mb@90
   680
    
mb@90
   681
    #cmd = "c:\\cygwin64\\bin\\bash.exe --login -c \"/bin/ls\""
mb@90
   682
    #man.execute(cmd)
mb@96
   683
=======
oliver@91
   684
'''
oliver@91
   685
Created on Nov 19, 2013
oliver@91
   686
oliver@91
   687
@author: BarthaM
oliver@91
   688
'''
oliver@91
   689
import os
oliver@91
   690
import os.path
oliver@91
   691
from subprocess import Popen, PIPE, call, STARTUPINFO, _subprocess
oliver@91
   692
import sys
oliver@91
   693
import re
oliver@91
   694
oliver@91
   695
from cygwin import Cygwin
oliver@91
   696
from environment import Environment
oliver@91
   697
import threading
oliver@91
   698
import time
oliver@91
   699
import string
oliver@91
   700
oliver@91
   701
import shutil
oliver@91
   702
import stat
oliver@91
   703
import tempfile
oliver@91
   704
from opensecurity_util import logger, setupLogger, OpenSecurityException
oliver@91
   705
import ctypes
oliver@91
   706
import itertools
oliver@91
   707
import _winreg
oliver@91
   708
DEBUG = True
oliver@91
   709
oliver@91
   710
class VMManagerException(Exception):
oliver@91
   711
    def __init__(self, value):
oliver@91
   712
        self.value = value
oliver@91
   713
    def __str__(self):
oliver@91
   714
        return repr(self.value)
oliver@91
   715
oliver@91
   716
class USBFilter:
oliver@91
   717
    vendorid = ""
oliver@91
   718
    productid = ""
oliver@91
   719
    revision = ""
oliver@91
   720
    
oliver@91
   721
    def __init__(self, vendorid, productid, revision):
oliver@91
   722
        self.vendorid = vendorid.lower()
oliver@91
   723
        self.productid = productid.lower()
oliver@91
   724
        self.revision = revision.lower()
oliver@91
   725
        return
oliver@91
   726
    
oliver@91
   727
    def __eq__(self, other):
oliver@91
   728
        return self.vendorid == other.vendorid and self.productid == other.productid and self.revision == other.revision
oliver@91
   729
    
oliver@91
   730
    def __hash__(self):
oliver@91
   731
        return hash(self.vendorid) ^ hash(self.productid) ^ hash(self.revision)
oliver@91
   732
    
oliver@91
   733
    def __repr__(self):
oliver@91
   734
        return "VendorId = \'" + str(self.vendorid) + "\' ProductId = \'" + str(self.productid) + "\' Revision = \'" + str(self.revision) + "\'"
oliver@91
   735
    
oliver@91
   736
    #def __getitem__(self, item):
oliver@91
   737
    #    return self.coords[item]
oliver@91
   738
 
oliver@91
   739
class VMManager(object):
oliver@91
   740
    vmRootName = "SecurityDVM"
oliver@91
   741
    systemProperties = None
oliver@91
   742
    _instance = None
oliver@91
   743
    machineFolder = ''
oliver@91
   744
    rsdHandler = None
oliver@91
   745
    _running = True
oliver@91
   746
    
oliver@91
   747
    def __init__(self):
oliver@91
   748
        self._running = True
oliver@91
   749
        self.systemProperties = self.getSystemProperties()
oliver@91
   750
        self.machineFolder = self.systemProperties["Default machine folder"]
oliver@91
   751
        self.cleanup()
oliver@91
   752
        self.rsdHandler = DeviceHandler(self)
oliver@91
   753
        self.rsdHandler.start()
oliver@91
   754
        return
oliver@91
   755
    
oliver@91
   756
    @staticmethod
oliver@91
   757
    def getInstance():
oliver@91
   758
        if VMManager._instance == None:
oliver@91
   759
            VMManager._instance = VMManager()
oliver@91
   760
        return VMManager._instance
oliver@91
   761
    
oliver@91
   762
    def cleanup(self):
oliver@91
   763
        if self.rsdHandler != None:
oliver@91
   764
            self.rsdHandler.stop()
oliver@91
   765
            self.rsdHandler.join()
oliver@91
   766
        drives = self.getNetworkDrives()
oliver@91
   767
        for drive in drives.keys():
oliver@91
   768
            self.unmapNetworkDrive(drive)
oliver@91
   769
        for vm in self.listSDVM():
oliver@91
   770
            self.poweroffVM(vm)
oliver@91
   771
            self.removeVM(vm)
oliver@91
   772
        
oliver@91
   773
    # return hosty system properties
oliver@91
   774
    def getSystemProperties(self):
oliver@91
   775
        result = checkResult(Cygwin.vboxExecute('list systemproperties'))
oliver@91
   776
        if result[1]=='':
oliver@91
   777
            return None
oliver@91
   778
        props = dict((k.strip(),v.strip().strip('"')) for k,v in (line.split(':', 1) for line in result[1].strip().splitlines()))
oliver@91
   779
        return props
oliver@91
   780
    
oliver@91
   781
    # return the folder containing the guest VMs     
oliver@91
   782
    def getMachineFolder(self):
oliver@91
   783
        return self.machineFolder
oliver@91
   784
oliver@91
   785
    # list all existing VMs registered with VBox
oliver@91
   786
    def listVM(self):
oliver@91
   787
        result = checkResult(Cygwin.vboxExecute('list vms'))[1]
oliver@91
   788
        vms = list(k.strip().strip('"') for k,_ in (line.split(' ') for line in result.splitlines()))
oliver@91
   789
        return vms
oliver@91
   790
    
oliver@91
   791
    # list running VMs
oliver@91
   792
    def listRunningVMS(self):
oliver@91
   793
        result = checkResult(Cygwin.vboxExecute('list runningvms'))[1]
oliver@91
   794
        vms = list(k.strip().strip('"') for k,_ in (line.split(' ') for line in result.splitlines()))
oliver@91
   795
        return vms
oliver@91
   796
    
oliver@91
   797
    # list existing SDVMs
oliver@91
   798
    def listSDVM(self):
oliver@91
   799
        vms = self.listVM()
oliver@91
   800
        svdms = []
oliver@91
   801
        for vm in vms:
oliver@91
   802
            if vm.startswith(self.vmRootName) and vm != self.vmRootName:
oliver@91
   803
                svdms.append(vm)
oliver@91
   804
        return svdms
oliver@91
   805
    
oliver@91
   806
    # generate valid (not already existing SDVM name). necessary for creating a new VM
oliver@91
   807
    def generateSDVMName(self):
oliver@91
   808
        vms = self.listVM()
oliver@91
   809
        for i in range(0,999):
oliver@91
   810
            if(not self.vmRootName+str(i) in vms):
oliver@91
   811
                return self.vmRootName+str(i)
oliver@91
   812
        return ''
oliver@91
   813
    
oliver@91
   814
    # check if the device is mass storage type
oliver@91
   815
    @staticmethod
oliver@91
   816
    def isMassStorageDevice(device):
oliver@91
   817
        keyname = 'SYSTEM\CurrentControlSet\Enum\USB' + '\VID_' + device.vendorid+'&'+'PID_'+ device.productid
oliver@91
   818
        key = _winreg.OpenKey(_winreg.HKEY_LOCAL_MACHINE, keyname)
oliver@91
   819
        #subkeys = _winreg.QueryInfoKey(key)[0]
oliver@91
   820
        #for i in range(0, subkeys):
oliver@91
   821
        #    print _winreg.EnumKey(key, i)     
oliver@91
   822
        devinfokeyname = _winreg.EnumKey(key, 0)
oliver@91
   823
        _winreg.CloseKey(key)
oliver@91
   824
oliver@91
   825
        devinfokey = _winreg.OpenKey(_winreg.HKEY_LOCAL_MACHINE, keyname+'\\'+devinfokeyname)
oliver@91
   826
        value = _winreg.QueryValueEx(devinfokey, 'SERVICE')[0]
oliver@91
   827
        _winreg.CloseKey(devinfokey)
oliver@91
   828
        
oliver@91
   829
        return 'USBSTOR' in value
oliver@91
   830
    
oliver@91
   831
    # return the RSDs connected to the host
oliver@91
   832
    @staticmethod
oliver@91
   833
    def getConnectedRSDS():
oliver@91
   834
        results = checkResult(Cygwin.vboxExecute('list usbhost'))[1]
oliver@91
   835
        results = results.split('Host USB Devices:')[1].strip()
oliver@91
   836
        
oliver@91
   837
        items = list( "UUID:"+result for result in results.split('UUID:') if result != '')
oliver@91
   838
        rsds = dict()   
oliver@91
   839
        for item in items:
oliver@91
   840
            props = dict()
oliver@91
   841
            for line in item.splitlines():
oliver@91
   842
                if line != "":         
oliver@91
   843
                    k,v = line[:line.index(':')].strip(), line[line.index(':')+1:].strip()
oliver@91
   844
                    props[k] = v
oliver@91
   845
            
oliver@91
   846
            #if 'Product' in props.keys() and props['Product'] == 'Mass Storage':
oliver@91
   847
            
oliver@91
   848
            usb_filter = USBFilter( re.search(r"\((?P<vid>[0-9A-Fa-f]+)\)", props['VendorId']).groupdict()['vid'], 
oliver@91
   849
                                    re.search(r"\((?P<pid>[0-9A-Fa-f]+)\)", props['ProductId']).groupdict()['pid'],
oliver@91
   850
                                    re.search(r"\((?P<rev>[0-9A-Fa-f]+)\)", props['Revision']).groupdict()['rev'] )
oliver@91
   851
            if VMManager.isMassStorageDevice(usb_filter):
oliver@91
   852
                rsds[props['UUID']] = usb_filter;
oliver@91
   853
                logger.debug(usb_filter)
oliver@91
   854
        return rsds
oliver@91
   855
    
oliver@91
   856
    # return the RSDs attached to all existing SDVMs
oliver@91
   857
    def getAttachedRSDs(self):
oliver@91
   858
        vms = self.listSDVM()
oliver@91
   859
        attached_devices = dict()
oliver@91
   860
        for vm in vms:
oliver@91
   861
            rsd_filter = self.getUSBFilter(vm)
oliver@91
   862
            if rsd_filter != None:
oliver@91
   863
                attached_devices[vm] = rsd_filter
oliver@91
   864
        return attached_devices
oliver@91
   865
    
oliver@91
   866
    # configures hostonly networking and DHCP server. requires admin rights
oliver@91
   867
    def configureHostNetworking(self):
oliver@91
   868
        #cmd = 'vboxmanage list hostonlyifs'
oliver@91
   869
        #Cygwin.vboxExecute(cmd)
oliver@91
   870
        #cmd = 'vboxmanage hostonlyif remove \"VirtualBox Host-Only Ethernet Adapter\"'
oliver@91
   871
        #Cygwin.vboxExecute(cmd)
oliver@91
   872
        #cmd = 'vboxmanage hostonlyif create'
oliver@91
   873
        #Cygwin.vboxExecute(cmd)
oliver@91
   874
        checkResult(Cygwin.vboxExecute('hostonlyif ipconfig \"VirtualBox Host-Only Ethernet Adapter\" --ip 192.168.56.1 --netmask 255.255.255.0'))
oliver@91
   875
        #cmd = 'vboxmanage dhcpserver add'
oliver@91
   876
        #Cygwin.vboxExecute(cmd)
oliver@91
   877
        checkResult(Cygwin.vboxExecute('dhcpserver modify --ifname \"VirtualBox Host-Only Ethernet Adapter\" --ip 192.168.56.100 --netmask 255.255.255.0 --lowerip 192.168.56.101 --upperip 192.168.56.200'))
oliver@91
   878
    
oliver@91
   879
    #create new virtual machine instance based on template vm named SecurityDVM (\SecurityDVM\SecurityDVM.vmdk)
oliver@91
   880
    def createVM(self, vm_name):
oliver@91
   881
        hostonly_if = self.getHostOnlyIFs()
oliver@91
   882
        checkResult(Cygwin.vboxExecute('createvm --name ' + vm_name + ' --ostype Debian --register'))
oliver@91
   883
        checkResult(Cygwin.vboxExecute('modifyvm ' + vm_name + ' --memory 512 --vram 10 --cpus 1 --usb on --usbehci on --nic1 hostonly --hostonlyadapter1 \"' + hostonly_if['Name'] + '\" --nic2 nat'))
oliver@91
   884
        checkResult(Cygwin.vboxExecute('storagectl ' + vm_name + ' --name SATA --add sata --portcount 2'))
oliver@91
   885
        return
oliver@91
   886
    
oliver@91
   887
    # attach storage image to controller
oliver@91
   888
    def storageAttach(self, vm_name):
oliver@91
   889
        if self.isStorageAttached(vm_name):
oliver@91
   890
            self.storageDetach(vm_name)
oliver@91
   891
        checkResult(Cygwin.vboxExecute('storageattach ' + vm_name + ' --storagectl SATA --port 0 --device 0 --type hdd --medium \"'+ self.machineFolder + '\SecurityDVM\SecurityDVM.vmdk\"'))
oliver@91
   892
    
oliver@91
   893
    # return true if storage is attached 
oliver@91
   894
    def isStorageAttached(self, vm_name):
oliver@91
   895
        info = self.getVMInfo(vm_name)
oliver@91
   896
        return (info['SATA-0-0']!='none')
oliver@91
   897
    
oliver@91
   898
    # detach storage from controller
oliver@91
   899
    def storageDetach(self, vm_name):
oliver@91
   900
        if self.isStorageAttached(vm_name):
oliver@91
   901
            checkResult(Cygwin.vboxExecute('storageattach ' + vm_name + ' --storagectl SATA --port 0 --device 0 --type hdd --medium none'))
oliver@91
   902
    
oliver@91
   903
    def changeStorageType(self, filename, storage_type):
oliver@91
   904
        checkResult(Cygwin.vboxExecute('modifyhd \"' + filename + '\" --type ' + storage_type))
oliver@91
   905
    
oliver@91
   906
    # list storage snaphots for VM
oliver@91
   907
    def updateTemplate(self):
oliver@91
   908
        self.cleanup()
oliver@91
   909
        self.poweroffVM('SecurityDVM')
oliver@91
   910
        self.waitShutdown('SecurityDVM')
oliver@91
   911
        
oliver@91
   912
        # check for updates
oliver@91
   913
        self.genCertificateISO('SecurityDVM')
oliver@91
   914
        self.attachCertificateISO('SecurityDVM')
oliver@91
   915
        
oliver@91
   916
        self.storageDetach('SecurityDVM')
oliver@91
   917
        results = checkResult(Cygwin.vboxExecute('list hdds'))[1]
oliver@91
   918
        results = results.replace('Parent UUID', 'Parent')
oliver@91
   919
        items = list( "UUID:"+result for result in results.split('UUID:') if result != '')
oliver@91
   920
        
oliver@91
   921
        snaps = dict()   
oliver@91
   922
        for item in items:
oliver@91
   923
            props = dict()
oliver@91
   924
            for line in item.splitlines():
oliver@91
   925
                if line != "":         
oliver@91
   926
                    k,v = line[:line.index(':')].strip(), line[line.index(':')+1:].strip()
oliver@91
   927
                    props[k] = v;
oliver@91
   928
            snaps[props['UUID']] = props
oliver@91
   929
        
oliver@91
   930
        
oliver@91
   931
        template_storage = self.machineFolder + '\SecurityDVM\SecurityDVM.vmdk'
oliver@91
   932
        
oliver@91
   933
        # find template uuid
oliver@91
   934
        template_uuid = ''
oliver@91
   935
        for hdd in snaps.values():
oliver@91
   936
            if hdd['Location'] == template_storage:
oliver@91
   937
                template_uuid = hdd['UUID']
oliver@91
   938
        logger.debug('found parent uuid ' + template_uuid)
oliver@91
   939
        
oliver@91
   940
        # remove snapshots 
oliver@91
   941
        for hdd in snaps.values():
oliver@91
   942
            if hdd['Parent'] == template_uuid:
oliver@91
   943
                #template_uuid = hdd['UUID']
oliver@91
   944
                logger.debug('removing snapshot ' + hdd['UUID'])
oliver@91
   945
                checkResult(Cygwin.vboxExecute('closemedium disk {' + hdd['UUID'] + '} --delete'))#[1]
oliver@91
   946
                # parse result 0%...10%...20%...30%...40%...50%...60%...70%...80%...90%...100%
oliver@91
   947
        
oliver@91
   948
        self.changeStorageType(template_storage,'normal')
oliver@91
   949
        self.storageAttach('SecurityDVM')
oliver@91
   950
        self.startVM('SecurityDVM')
oliver@91
   951
        self.waitStartup('SecurityDVM')
oliver@91
   952
        checkResult(Cygwin.sshExecute('"sudo apt-get -y update"', VMManager.getHostOnlyIP('SecurityDVM'), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + 'SecurityDVM' + '/dvm_key'))
oliver@91
   953
        checkResult(Cygwin.sshExecute('"sudo apt-get -y upgrade"', VMManager.getHostOnlyIP('SecurityDVM'), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + 'SecurityDVM' + '/dvm_key'))
oliver@91
   954
        #self.stopVM('SecurityDVM')
oliver@91
   955
        self.hibernateVM('SecurityDVM')
oliver@91
   956
        self.waitShutdown('SecurityDVM')
oliver@91
   957
        self.storageDetach('SecurityDVM')
oliver@91
   958
        self.changeStorageType(template_storage,'immutable')
oliver@91
   959
        self.storageAttach('SecurityDVM')
oliver@91
   960
        self.rsdHandler = DeviceHandler(self)
oliver@91
   961
        self.rsdHandler.start()
oliver@91
   962
    
oliver@91
   963
    #remove VM from the system. should be used on VMs returned by listSDVMs    
oliver@91
   964
    def removeVM(self, vm_name):
oliver@91
   965
        logger.info('Removing ' + vm_name)
oliver@91
   966
        checkResult(Cygwin.vboxExecute('unregistervm ' + vm_name + ' --delete'))
oliver@91
   967
        vm_file = Cygwin.cygPath(self.machineFolder + '\\' + vm_name)
oliver@91
   968
        checkResult(Cygwin.bashExecute('rm -rf \'' + vm_file + '\''))
oliver@91
   969
    
oliver@91
   970
    # start VM
oliver@91
   971
    def startVM(self, vm_name):
oliver@91
   972
        logger.info('Starting ' +  vm_name)
oliver@91
   973
        result = checkResult(Cygwin.vboxExecute('startvm ' + vm_name + ' --type headless' ))
oliver@91
   974
        while 'successfully started' not in result[1] and _running:
oliver@91
   975
            logger.error("Failed to start SDVM: " + vm_name + " retrying")
oliver@91
   976
            time.sleep(1)
oliver@91
   977
            result = checkResult(Cygwin.vboxExecute('startvm ' + vm_name + ' --type headless'))
oliver@91
   978
        return result[0]
oliver@91
   979
    
oliver@91
   980
    # return wether VM is running or not
oliver@91
   981
    def isVMRunning(self, vm_name):
oliver@91
   982
        return vm_name in self.listRunningVMS()    
oliver@91
   983
    
oliver@91
   984
    # stop VM
oliver@91
   985
    def stopVM(self, vm_name):
oliver@91
   986
        logger.info('Sending shutdown signal to ' + vm_name)
oliver@91
   987
        checkResult(Cygwin.sshExecute( '"sudo shutdown -h now"', VMManager.getHostOnlyIP(vm_name), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + vm_name + '/dvm_key' ))
oliver@91
   988
    
oliver@91
   989
    # stop VM
oliver@91
   990
    def hibernateVM(self, vm_name):
oliver@91
   991
        logger.info('Sending shutdown signal to ' + vm_name)
oliver@91
   992
        checkResult(Cygwin.sshExecute( '"sudo hibernate-disk&"', VMManager.getHostOnlyIP(vm_name), 'osecuser', Cygwin.cygPath(self.machineFolder) + '/' + vm_name + '/dvm_key', wait_return=False))
oliver@91
   993
            
oliver@91
   994
    # poweroff VM
oliver@91
   995
    def poweroffVM(self, vm_name):
oliver@91
   996
        if not self.isVMRunning(vm_name):
oliver@91
   997
            return
oliver@91
   998
        logger.info('Powering off ' + vm_name)
oliver@91
   999
        return checkResult(Cygwin.vboxExecute('controlvm ' + vm_name + ' poweroff'))
oliver@91
  1000
    
oliver@91
  1001
    #list the hostonly IFs exposed by the VBox host
oliver@91
  1002
    @staticmethod    
oliver@91
  1003
    def getHostOnlyIFs():
oliver@91
  1004
        result = Cygwin.vboxExecute('list hostonlyifs')[1]
oliver@91
  1005
        if result=='':
oliver@91
  1006
            return None
oliver@91
  1007
        props = dict((k.strip(),v.strip().strip('"')) for k,v in (line.split(':', 1) for line in result.strip().splitlines()))
oliver@91
  1008
        return props
oliver@91
  1009
    
oliver@91
  1010
    # return the hostOnly IP for a running guest or the host
oliver@91
  1011
    @staticmethod    
oliver@91
  1012
    def getHostOnlyIP(vm_name):
oliver@91
  1013
        if vm_name == None:
oliver@91
  1014
            logger.info('Gettting hostOnly IP address for Host')
oliver@91
  1015
            return VMManager.getHostOnlyIFs()['IPAddress']
oliver@91
  1016
        else:
oliver@91
  1017
            logger.info('Gettting hostOnly IP address ' + vm_name)
oliver@91
  1018
            result = checkResult(Cygwin.vboxExecute('guestproperty get ' + vm_name + ' /VirtualBox/GuestInfo/Net/0/V4/IP'))
oliver@91
  1019
            if result=='':
oliver@91
  1020
                return None
oliver@91
  1021
            result = result[1]
oliver@91
  1022
            if result.startswith('No value set!'):
oliver@91
  1023
                return None
oliver@91
  1024
            return result[result.index(':')+1:].strip()
oliver@91
  1025
            
oliver@91
  1026
    # attach removable storage device to VM by provision of filter
oliver@91
  1027
    def attachRSD(self, vm_name, rsd_filter):
oliver@91
  1028
        return checkResult(Cygwin.vboxExecute('usbfilter add 0 --target ' + vm_name + ' --name OpenSecurityRSD --vendorid ' + rsd_filter.vendorid + ' --productid ' + rsd_filter.productid + ' --revision ' + rsd_filter.revision))
oliver@91
  1029
    
oliver@91
  1030
    # detach removable storage from VM by 
oliver@91
  1031
    def detachRSD(self, vm_name):
oliver@91
  1032
        return checkResult(Cygwin.vboxExecute('usbfilter remove 0 --target ' + vm_name))
oliver@91
  1033
        
oliver@91
  1034
    # return the description set for an existing VM
oliver@91
  1035
    def getVMInfo(self, vm_name):
oliver@91
  1036
        results = checkResult(Cygwin.vboxExecute('showvminfo ' + vm_name + ' --machinereadable'))[1]
oliver@91
  1037
        props = dict((k.strip().strip('"'),v.strip().strip('"')) for k,v in (line.split('=', 1) for line in results.splitlines()))
oliver@91
  1038
        return props
oliver@91
  1039
    
oliver@91
  1040
    # return the configured USB filter for an existing VM 
oliver@91
  1041
    def getUSBFilter(self, vm_name):
oliver@91
  1042
        props = self.getVMInfo(vm_name)
oliver@91
  1043
        keys = set(['USBFilterVendorId1', 'USBFilterProductId1', 'USBFilterRevision1'])
oliver@91
  1044
        keyset = set(props.keys())
oliver@91
  1045
        usb_filter = None
oliver@91
  1046
        if keyset.issuperset(keys):
oliver@91
  1047
            usb_filter = USBFilter(props['USBFilterVendorId1'], props['USBFilterProductId1'], props['USBFilterRevision1'])
oliver@91
  1048
        return usb_filter
oliver@91
  1049
    
oliver@91
  1050
    #generates ISO containing authorized_keys for use with guest VM
oliver@91
  1051
    def genCertificateISO(self, vm_name):
oliver@91
  1052
        machineFolder = Cygwin.cygPath(self.machineFolder)
oliver@91
  1053
        # remove .ssh folder if exists
oliver@91
  1054
        checkResult(Cygwin.bashExecute('\"/usr/bin/rm -rf \\\"' + machineFolder + '/' + vm_name + '/.ssh\\\"\"'))
oliver@91
  1055
        # remove .ssh folder if exists
oliver@91
  1056
        checkResult(Cygwin.bashExecute('\"/usr/bin/rm -rf \\\"' + machineFolder + '/' + vm_name + '/dvm_key\\\"\"'))
oliver@91
  1057
        # create .ssh folder in vm_name
oliver@91
  1058
        checkResult(Cygwin.bashExecute('\"/usr/bin/mkdir -p \\\"' + machineFolder + '/' + vm_name + '/.ssh\\\"\"'))
oliver@91
  1059
        # generate dvm_key pair in vm_name / .ssh     
oliver@91
  1060
        checkResult(Cygwin.bashExecute('\"/usr/bin/ssh-keygen -q -t rsa -N \\"\\" -C \\\"' + vm_name + '\\\" -f \\\"' + machineFolder + '/' + vm_name + '/.ssh/dvm_key\\\"\"'))
oliver@91
  1061
        # move out private key
oliver@91
  1062
        checkResult(Cygwin.bashExecute('\"/usr/bin/mv \\\"' + machineFolder + '/' + vm_name + '/.ssh/dvm_key\\\" \\\"' + machineFolder + '/' + vm_name + '\\\"'))
oliver@91
  1063
        # set permissions for private key
oliver@91
  1064
        checkResult(Cygwin.bashExecute('\"/usr/bin/chmod 500 \\\"' + machineFolder + '/' + vm_name + '/dvm_key\\\"\"'))
oliver@91
  1065
        # rename public key to authorized_keys
oliver@91
  1066
        checkResult(Cygwin.bashExecute('\"/usr/bin/mv \\\"' + machineFolder + '/' + vm_name + '/.ssh/dvm_key.pub\\\" \\\"' + machineFolder + '/' + vm_name + '/.ssh/authorized_keys\\\"'))
oliver@91
  1067
        # set permissions for authorized_keys
oliver@91
  1068
        checkResult(Cygwin.bashExecute('\"/usr/bin/chmod 500 \\\"' + machineFolder + '/' + vm_name + '/.ssh/authorized_keys\\\"\"'))
oliver@91
  1069
        # generate iso image with .ssh/authorized keys
oliver@91
  1070
        checkResult(Cygwin.bashExecute('\"/usr/bin/genisoimage -J -R -o \\\"' + machineFolder + '/' + vm_name + '/'+ vm_name + '.iso\\\" \\\"' + machineFolder + '/' + vm_name + '/.ssh\\\"\"'))
oliver@91
  1071
    
oliver@91
  1072
    # attaches generated ssh public cert to guest vm
oliver@91
  1073
    def attachCertificateISO(self, vm_name):
oliver@91
  1074
        result = checkResult(Cygwin.vboxExecute('storageattach ' + vm_name + ' --storagectl SATA --port 1 --device 0 --type dvddrive --mtype readonly --medium \"' + self.machineFolder + '\\' + vm_name + '\\'+ vm_name + '.iso\"'))
oliver@91
  1075
        return result
oliver@91
  1076
    
oliver@91
  1077
    # wait for machine to come up
oliver@91
  1078
    def waitStartup(self, vm_name, timeout_ms = 30000):
oliver@91
  1079
        checkResult(Cygwin.vboxExecute('guestproperty wait ' + vm_name + ' SDVMStarted --timeout ' + str(timeout_ms) + ' --fail-on-timeout'))
oliver@91
  1080
        return VMManager.getHostOnlyIP(vm_name)
oliver@91
  1081
    
oliver@91
  1082
    # wait for machine to shutdown
oliver@91
  1083
    def waitShutdown(self, vm_name):
oliver@91
  1084
        while vm_name in self.listRunningVMS() and _running:
oliver@91
  1085
            time.sleep(1)
oliver@91
  1086
        return
oliver@91
  1087
        
oliver@91
  1088
    # handles browsing request    
oliver@91
  1089
    def handleBrowsingRequest(self):
oliver@91
  1090
        handler = BrowsingHandler(self)
oliver@91
  1091
        handler.start()
oliver@91
  1092
        return 'ok'
oliver@91
  1093
    
oliver@91
  1094
    #Small function to check the availability of network resource.
oliver@91
  1095
    #def isAvailable(self, path):
oliver@91
  1096
        #return os.path.exists(path)
oliver@91
  1097
        #result = Cygwin.cmdExecute('IF EXIST "' + path + '" echo YES')
oliver@91
  1098
        #return string.find(result[1], 'YES',)
oliver@91
  1099
    
oliver@91
  1100
    #Small function to check if the mention location is a directory
oliver@91
  1101
    def isDirectory(self, path):
oliver@91
  1102
        result = checkResult(Cygwin.cmdExecute('dir ' + path + ' | FIND ".."'))
oliver@91
  1103
        return string.find(result[1], 'DIR',)
oliver@91
  1104
oliver@91
  1105
    def mapNetworkDrive(self, drive, networkPath, user, password):
oliver@91
  1106
        self.unmapNetworkDrive(drive)
oliver@91
  1107
        #Check for drive availability
oliver@91
  1108
        if os.path.exists(drive):
oliver@91
  1109
            logger.error("Drive letter is already in use: " + drive)
oliver@91
  1110
            return -1
oliver@91
  1111
        #Check for network resource availability
oliver@91
  1112
        retry = 5
oliver@91
  1113
        while not os.path.exists(networkPath):
oliver@91
  1114
            time.sleep(1)
oliver@91
  1115
            if retry == 0:
oliver@91
  1116
                return -1
oliver@91
  1117
            logger.info("Path not accessible: " + networkPath + " retrying")
oliver@91
  1118
            retry-=1
oliver@91
  1119
            #return -1
oliver@91
  1120
    
oliver@91
  1121
        command = 'USE ' + drive + ' ' + networkPath + ' /PERSISTENT:NO'
oliver@91
  1122
        if user != None:
oliver@91
  1123
            command += ' ' + password + ' /User' + user
oliver@91
  1124
    
oliver@91
  1125
        #TODO: Execute 'NET USE' command with authentication
oliver@91
  1126
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', command))
oliver@91
  1127
        if string.find(result[1], 'successfully',) == -1:
oliver@91
  1128
            logger.error("Failed: NET " + command)
oliver@91
  1129
            return -1
oliver@91
  1130
        return 1
oliver@91
  1131
    
oliver@91
  1132
    def unmapNetworkDrive(self, drive):
oliver@91
  1133
        drives = self.getNetworkDrives()
oliver@91
  1134
        if drive not in drives.keys():
oliver@91
  1135
            return 1 
oliver@91
  1136
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', 'USE ' + drive + ' /DELETE /YES'))
oliver@91
  1137
        if string.find(str(result[1]), 'successfully',) == -1:
oliver@91
  1138
            logger.error(result[2])
oliver@91
  1139
            return -1
oliver@91
  1140
        return 1
oliver@91
  1141
    
oliver@91
  1142
    def getNetworkDrives(self):
oliver@91
  1143
        ip = VMManager.getHostOnlyIP(None)
oliver@91
  1144
        ip = ip[:ip.rindex('.')]
oliver@91
  1145
        drives = dict()    
oliver@91
  1146
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', 'USE'))
oliver@91
  1147
        for line in result[1].splitlines():
oliver@91
  1148
            if ip in line:
oliver@91
  1149
                parts = line.split()
oliver@91
  1150
                drives[parts[1]] = parts[2]
oliver@91
  1151
        return drives
oliver@91
  1152
            
oliver@91
  1153
    def genNetworkDrive(self):
oliver@91
  1154
        network_drives = self.getNetworkDrives()
oliver@91
  1155
        logical_drives = VMManager.getLogicalDrives()
oliver@91
  1156
        drives = list(map(chr, range(68, 91)))  
oliver@91
  1157
        for drive in drives:
oliver@91
  1158
            if drive+':' not in network_drives and drive not in logical_drives:
oliver@91
  1159
                return drive+':'
oliver@91
  1160
oliver@91
  1161
    def getNetworkDrive(self, vm_name):
oliver@91
  1162
        ip = self.getHostOnlyIP(vm_name)
oliver@91
  1163
        result = checkResult(Cygwin.execute('C:\\Windows\\system32\\net.exe', 'USE'))
oliver@91
  1164
        for line in result[1].splitlines():
oliver@91
  1165
            if line != None and ip in line:
oliver@91
  1166
                parts = line.split()
oliver@91
  1167
                return parts[0]
oliver@91
  1168
    @staticmethod
oliver@91
  1169
    def getLogicalDrives():
oliver@91
  1170
        drive_bitmask = ctypes.cdll.kernel32.GetLogicalDrives()
oliver@91
  1171
        return list(itertools.compress(string.ascii_uppercase,  map(lambda x:ord(x) - ord('0'), bin(drive_bitmask)[:1:-1])))
oliver@91
  1172
    
oliver@91
  1173
    @staticmethod
oliver@91
  1174
    def getDriveType(drive):
oliver@91
  1175
        return ctypes.cdll.kernel32.GetDriveTypeW(u"%s:\\"%drive)
oliver@91
  1176
    
oliver@91
  1177
    @staticmethod
oliver@91
  1178
    def getVolumeInfo(drive):
oliver@91
  1179
        volumeNameBuffer = ctypes.create_unicode_buffer(1024)
oliver@91
  1180
        fileSystemNameBuffer = ctypes.create_unicode_buffer(1024)
oliver@91
  1181
        serial_number = None
oliver@91
  1182
        max_component_length = None
oliver@91
  1183
        file_system_flags = None
oliver@91
  1184
        
oliver@91
  1185
        rc = ctypes.cdll.kernel32.GetVolumeInformationW(
oliver@91
  1186
            #ctypes.c_wchar_p("F:\\"),
oliver@91
  1187
            u"%s:\\"%drive,
oliver@91
  1188
            volumeNameBuffer,
oliver@91
  1189
            ctypes.sizeof(volumeNameBuffer),
oliver@91
  1190
            serial_number,
oliver@91
  1191
            max_component_length,
oliver@91
  1192
            file_system_flags,
oliver@91
  1193
            fileSystemNameBuffer,
oliver@91
  1194
            ctypes.sizeof(fileSystemNameBuffer)
oliver@91
  1195
        )
oliver@91
  1196
        
oliver@91
  1197
        return volumeNameBuffer.value, fileSystemNameBuffer.value
oliver@91
  1198
oliver@91
  1199
    @staticmethod
oliver@91
  1200
    def stop():
oliver@91
  1201
        """stop all running infinite loops now --> needed for gracefull shutdown"""
oliver@91
  1202
        _running = False
oliver@91
  1203
oliver@91
  1204
oliver@91
  1205
oliver@91
  1206
def checkResult(result):
oliver@91
  1207
    if result[0] != 0:
oliver@91
  1208
        logger.error('Command failed:' + ''.join(result[2]))
oliver@91
  1209
        raise OpenSecurityException('Command failed:' + ''.join(result[2]))
oliver@91
  1210
    return result
oliver@91
  1211
oliver@91
  1212
# handles browsing request                    
oliver@91
  1213
class BrowsingHandler(threading.Thread):
oliver@91
  1214
    vmm = None
oliver@91
  1215
    def __init__(self, vmmanager):
oliver@91
  1216
        threading.Thread.__init__(self)
oliver@91
  1217
        self.vmm = vmmanager
oliver@91
  1218
     
oliver@91
  1219
    def run(self):
oliver@91
  1220
        try:
oliver@91
  1221
            new_sdvm = self.vmm.generateSDVMName()
oliver@91
  1222
            self.vmm.createVM(new_sdvm)
oliver@91
  1223
            self.vmm.storageAttach(new_sdvm)
oliver@91
  1224
            self.vmm.genCertificateISO(new_sdvm)
oliver@91
  1225
            self.vmm.attachCertificateISO(new_sdvm)
oliver@91
  1226
            self.vmm.startVM(new_sdvm)
oliver@91
  1227
            new_ip = self.vmm.waitStartup(new_sdvm)
oliver@91
  1228
            drive = self.vmm.genNetworkDrive()
oliver@91
  1229
            if new_ip != None:
oliver@91
  1230
                self.vmm.mapNetworkDrive(drive, '\\\\' + new_ip + '\\Download', None, None)
oliver@91
  1231
            result = checkResult(Cygwin.sshExecuteX11('/usr/bin/iceweasel', new_ip, 'osecuser', Cygwin.cygPath(self.vmm.getMachineFolder()) + '/' + new_sdvm + '/dvm_key'))
oliver@91
  1232
        except:
oliver@91
  1233
            logger.error("BrowsingHandler failed. Cleaning up")
oliver@91
  1234
            
oliver@91
  1235
        self.vmm.unmapNetworkDrive(drive)
oliver@91
  1236
        self.vmm.poweroffVM(new_sdvm)
oliver@91
  1237
        self.vmm.removeVM(new_sdvm)
oliver@91
  1238
                
oliver@91
  1239
class DeviceHandler(threading.Thread): 
oliver@91
  1240
    vmm = None
oliver@91
  1241
    #handleDeviceChangeLock = threading.Lock()
oliver@91
  1242
    attachedRSDs = None  
oliver@91
  1243
    connectedRSDs = None
oliver@91
  1244
    running = True
oliver@91
  1245
    def __init__(self, vmmanger): 
oliver@91
  1246
        threading.Thread.__init__(self)
oliver@91
  1247
        self.vmm = vmmanger
oliver@91
  1248
 
oliver@91
  1249
    def stop(self):
oliver@91
  1250
        self.running = False
oliver@91
  1251
        
oliver@91
  1252
    def run(self):
oliver@91
  1253
        self.connectedRSDs = dict()
oliver@91
  1254
        self.attachedRSDs = self.vmm.getAttachedRSDs()
oliver@91
  1255
        while self.running:
oliver@91
  1256
            tmp_rsds = self.vmm.getConnectedRSDS()
oliver@91
  1257
            if tmp_rsds.keys() == self.connectedRSDs.keys():
oliver@91
  1258
                logger.debug("Nothing's changed. sleep(3)")
oliver@91
  1259
                time.sleep(3)
oliver@91
  1260
                continue
oliver@91
  1261
            
oliver@91
  1262
            logger.info("Something's changed")          
oliver@91
  1263
            self.connectedRSDs = tmp_rsds
oliver@91
  1264
            self.attachedRSDs = self.vmm.getAttachedRSDs()
oliver@91
  1265
            
oliver@91
  1266
            for vm_name in self.attachedRSDs.keys():
oliver@91
  1267
                if self.attachedRSDs[vm_name] not in self.connectedRSDs.values():
oliver@91
  1268
                    drive = self.vmm.getNetworkDrive(vm_name)
oliver@91
  1269
                    self.vmm.unmapNetworkDrive(drive)
oliver@91
  1270
                    #self.stopVM(vm_name)
oliver@91
  1271
                    self.vmm.detachRSD(vm_name)
oliver@91
  1272
                    self.vmm.poweroffVM(vm_name)
oliver@91
  1273
                    self.vmm.removeVM(vm_name)
oliver@91
  1274
            #create new vm for attached device if any
oliver@91
  1275
            self.attachedRSDs = self.vmm.getAttachedRSDs()
oliver@91
  1276
            self.connectedRSDs = self.vmm.getConnectedRSDS()
oliver@91
  1277
            
oliver@91
  1278
            new_ip = None
oliver@91
  1279
            for connected_device in self.connectedRSDs.values():
oliver@91
  1280
                if (self.attachedRSDs and False) or (connected_device not in self.attachedRSDs.values()):
oliver@91
  1281
                    new_sdvm = self.vmm.generateSDVMName()
oliver@91
  1282
                    self.vmm.createVM(new_sdvm)
oliver@91
  1283
                    self.vmm.storageAttach(new_sdvm)
oliver@91
  1284
                    self.vmm.attachRSD(new_sdvm, connected_device)
oliver@91
  1285
                    self.vmm.startVM(new_sdvm)
oliver@91
  1286
                    new_ip = self.vmm.waitStartup(new_sdvm)
oliver@91
  1287
                    drive = self.vmm.genNetworkDrive()
oliver@91
  1288
                    if new_ip != None:
oliver@91
  1289
                        self.vmm.mapNetworkDrive(drive, '\\\\' + new_ip + '\\USB', None, None)
oliver@91
  1290
oliver@91
  1291
if __name__ == '__main__':
oliver@91
  1292
    #man = VMManager.getInstance()
oliver@91
  1293
    #man.listVM()
oliver@91
  1294
    #print man.getConnectedRSDs()
oliver@91
  1295
    #print man.getNetworkDrives()
oliver@91
  1296
    #man.genNetworkDrive()
oliver@91
  1297
    #drive_bitmask = ctypes.cdll.kernel32.GetLogicalDrives()
oliver@91
  1298
    #print list(itertools.compress(string.ascii_uppercase,  map(lambda x:ord(x) - ord('0'), bin(drive_bitmask)[:1:-1])))
oliver@91
  1299
    #print list(map(chr, range(68, 91))) 
oliver@91
  1300
    #print Cygwin.getRegEntry('SYSTEM\CurrentControlSet\Enum\USB', 'VID_1058&PID_0704')[0]
oliver@91
  1301
    #devices = VMManager.getConnectedRSDS()
oliver@91
  1302
    #print devices
oliver@91
  1303
    
oliver@91
  1304
    drives = VMManager.getLogicalDrives()
oliver@91
  1305
    print drives
oliver@91
  1306
    print VMManager.getDriveType("E")
oliver@91
  1307
    print VMManager.getVolumeInfo("E")
oliver@91
  1308
    #for device in devices.values():
oliver@91
  1309
    #    #print device
oliver@91
  1310
    #    if VMManager.isMassStorageDevice(device):
oliver@91
  1311
    #        print device
oliver@91
  1312
        
oliver@91
  1313
    
oliver@91
  1314
    
oliver@91
  1315
    #time.sleep(-1)
oliver@91
  1316
    #man.listVM()
oliver@91
  1317
    #man.listVM()
oliver@91
  1318
    #man.listVM()
oliver@91
  1319
    #man.listVM()
oliver@91
  1320
    #man.genCertificateISO('SecurityDVM0')
oliver@91
  1321
    #man.guestExecute('SecurityDVM0', '/bin/ls -la')
oliver@91
  1322
    #logger = setupLogger('VMManager')
oliver@91
  1323
    #c = Cygwin()
oliver@91
  1324
    
oliver@91
  1325
    #man.sshExecute('/bin/ls -la', 'SecurityDVM0')
oliver@91
  1326
    #man.sshExecuteX11('/usr/bin/iceweasel', 'SecurityDVM0')
oliver@91
  1327
    #man.removeVM('SecurityDVM0')
oliver@91
  1328
    #man.netUse('192.168.56.134', 'USB\\')
oliver@91
  1329
    #ip = '192.168.56.139'
oliver@91
  1330
    
oliver@91
  1331
    #man.cygwin_path = 'c:\\cygwin64\\bin\\'
oliver@91
  1332
    #man.handleDeviceChange()
oliver@91
  1333
    #print man.listSDVM()
oliver@91
  1334
    #man.configureHostNetworking()
oliver@91
  1335
    #new_vm = man.generateSDVMName()
oliver@91
  1336
    #man.createVM(new_vm)
oliver@91
  1337
    
oliver@91
  1338
    #print Cygwin.cmd()
oliver@91
  1339
    #man.isAvailable('c:')
oliver@91
  1340
    #ip = man.getHostOnlyIP('SecurityDVM0')
oliver@91
  1341
    #man.mapNetworkDrive('h:', '\\\\' + ip + '\Download', None, None)
oliver@91
  1342
    
oliver@91
  1343
    #man.genCertificateISO(new_vm)
oliver@91
  1344
    #man.attachCertificateISO(new_vm)
oliver@91
  1345
    
oliver@91
  1346
    #man.attachCertificateISO(vm_name)
oliver@91
  1347
    #man.guestExecute(vm_name, "ls")
oliver@91
  1348
    #man.sshGuestX11Execute('SecurityDVM1', '/usr/bin/iceweasel')
oliver@91
  1349
    #time.sleep(60)
oliver@91
  1350
    #print man.cygwinPath("C:\Users\BarthaM\VirtualBox VMs\SecurityDVM\.ssh\*")
oliver@91
  1351
    #man.genCertificateISO('SecurityDVM')
oliver@91
  1352
    #man.attachCertificateISO('SecurityDVM')
oliver@91
  1353
    #man.isStorageAttached('SecurityDVM')
oliver@91
  1354
    #man.guestExecute('SecurityDVM', 'sudo apt-get -y update')
oliver@91
  1355
    #man.guestExecute('SecurityDVM', 'sudo apt-get -y upgrade' )
oliver@91
  1356
    
oliver@91
  1357
    #man.stopVM('SecurityDVM')
oliver@91
  1358
    #man.storageDetach('SecurityDVM')
oliver@91
  1359
    #man.changeStorageType('C:\Users\BarthaM\VirtualBox VMs\SecurityDVM\SecurityDVM.vmdk','immutable')
oliver@91
  1360
    #man.storageAttach('SecurityDVM')
oliver@91
  1361
    
oliver@91
  1362
    
oliver@91
  1363
    #cmd = "c:\\cygwin64\\bin\\bash.exe --login -c \"/bin/ls\""
oliver@91
  1364
    #man.execute(cmd)
mb@96
  1365
>>>>>>> other