]> git.lizzy.rs Git - torbrowser-launcher.git/blob - torbrowser-launcher
removed bash script for verifying, and started checking gnupg exit codes instead...
[torbrowser-launcher.git] / torbrowser-launcher
1 #!/usr/bin/env python
2 from twisted.internet import gtk2reactor
3 gtk2reactor.install()
4 from twisted.internet import reactor
5
6 import pygtk
7 pygtk.require('2.0')
8 import gtk
9
10 import os, sys, subprocess, locale, urllib2, gobject, time, pickle, json
11
12 from twisted.web.client import Agent, ResponseDone
13 from twisted.web.http_headers import Headers
14 from twisted.internet.protocol import Protocol
15 from twisted.internet.ssl import ClientContextFactory
16
17 from OpenSSL.SSL import Context, VERIFY_PEER, VERIFY_FAIL_IF_NO_PEER_CERT
18 from OpenSSL.crypto import load_certificate, FILETYPE_PEM
19
20 class VerifyTorProjectCert(ClientContextFactory):
21
22     def __init__(self, torproject_pem):
23         self.torproject_ca = load_certificate(FILETYPE_PEM, open(torproject_pem, 'r').read())
24
25     def getContext(self, host, port):
26         ctx = ClientContextFactory.getContext(self)
27         ctx.set_verify_depth(0)
28         ctx.set_verify(VERIFY_PEER | VERIFY_FAIL_IF_NO_PEER_CERT, self.verifyHostname)
29         return ctx
30
31     def verifyHostname(self, connection, cert, errno, depth, preverifyOK):
32         return cert.digest('sha256') == self.torproject_ca.digest('sha256')
33
34
35 class TorBrowserLauncher:
36     def __init__(self):
37         # initialize the app
38         self.set_gui(None, '', [])
39         self.discover_arch_lang()
40         self.build_paths()
41         self.mkdir(self.paths['dir']['download'])
42         self.mkdir(self.paths['dir']['tbb'])
43         self.init_gnupg()
44
45         # allow buttons to have icons
46         try:
47             settings = gtk.settings_get_default()
48             settings.props.gtk_button_images = True
49         except:
50             pass
51
52         self.launch_gui = True
53
54         # if we haven't already hit an error
55         if self.gui != 'error':
56             # load settings
57             if self.load_settings():
58                 self.build_paths(self.settings['latest_version'])
59
60                 # how long was it since the last update check?
61                 # 86400 seconds = 24 hours
62                 current_timestamp = int(time.time())
63                 if current_timestamp - self.settings['last_update_check_timestamp'] >= 86400:
64                     # check for update
65                     print 'Checking for update'
66                     self.set_gui('task', "Checking for Tor Browser update.", 
67                         ['download_update_check', 
68                          'attempt_update'])
69
70                 else:
71                     # no need to check for update
72                     print 'Checked for update within 24 hours, skipping'
73                     self.start_launcher()
74
75             else:
76                 self.set_gui('error', "Error loading settings. Delete ~/.torbrowser and try again.", [])
77
78         if self.launch_gui:
79             # set up the window
80             self.window = gtk.Window(gtk.WINDOW_TOPLEVEL)
81             self.window.set_title("Tor Browser")
82             self.window.set_position(gtk.WIN_POS_CENTER)
83             self.window.set_border_width(10)
84             self.window.connect("delete_event", self.delete_event)
85             self.window.connect("destroy", self.destroy)
86
87             # build the rest of the UI
88             self.build_ui()
89
90     # download or run TBB
91     def start_launcher(self):
92       # is TBB already installed?
93       if os.path.isfile(self.paths['file']['start']) and os.access(self.paths['file']['start'], os.X_OK):
94         if self.settings['installed_version'] == self.settings['latest_version']:
95           # current version of tbb is installed, launch it
96           self.run(False)
97           self.launch_gui = False
98         elif self.settings['installed_version'] < self.settings['latest_version']:
99           # there is a tbb upgrade available
100           self.set_gui('task', "Your Tor Browser is out of date.", 
101             ['download_tarball', 
102              'download_tarball_sig', 
103              'verify', 
104              'extract', 
105              'run'])
106         else:
107           # for some reason the installed tbb is newer than the current version?
108           self.set_gui('error', "Something is wrong. The version of Tor Browser Bundle you have installed is newer than the current version?", [])
109
110       # not installed
111       else:
112           # are the tarball and sig already downloaded?
113           if os.path.isfile(self.paths['file']['tarball']) and os.path.isfile(self.paths['file']['tarball_sig']):
114               # start the gui with verify
115               self.set_gui('task', "Installing Tor Browser.", 
116                   ['verify', 
117                    'extract', 
118                    'run'])
119
120           # first run
121           else:
122               self.set_gui('task', "Downloading and installing Tor Browser.", 
123                   ['download_tarball', 
124                    'download_tarball_sig', 
125                    'verify', 
126                    'extract', 
127                    'run'])
128    
129     # discover the architecture and language
130     def discover_arch_lang(self):
131         # figure out the architecture
132         (sysname, nodename, release, version, machine) = os.uname()
133         self.architecture = machine
134
135         # figure out the language
136         available_languages = ['en-US', 'ar', 'de', 'es-ES', 'fa', 'fr', 'it', 'ko', 'nl', 'pl', 'pt-PT', 'ru', 'vi', 'zh-CN']
137         default_locale = locale.getdefaultlocale()[0]
138         if default_locale == None:
139             self.language = 'en-US'
140         else:
141             self.language = default_locale.replace('_', '-')
142             if self.language not in available_languages:
143                 self.language = self.language.split('-')[0]
144                 if self.language not in available_languages:
145                     for l in available_languages:
146                         if l[0:2] == self.language:
147                             self.language = l
148             # if language isn't available, default to english
149             if self.language not in available_languages:
150                 self.language = 'en-US'
151
152     # build all relevant paths
153     def build_paths(self, tbb_version = None):
154         homedir = os.getenv('HOME')
155         if not homedir:
156             homedir = '/tmp/.torbrowser-'+os.getenv('USER')
157             if os.path.exists(homedir) == False:
158                 try:
159                     os.mkdir(homedir, 0700)
160                 except:
161                     self.set_gui('error', "Error creating %s" % homedir, [], False)
162         if not os.access(homedir, os.W_OK):
163             self.set_gui('error', "%s is not writable" % homedir, [], False)
164
165         tbb_data = '%s/.torbrowser' % homedir
166
167         if tbb_version:
168             tarball_filename = 'tor-browser-gnu-linux-'+self.architecture+'-'+tbb_version+'-dev-'+self.language+'.tar.gz'
169             self.paths['file']['tarball'] = tbb_data+'/download/'+tarball_filename
170             self.paths['file']['tarball_sig'] = tbb_data+'/download/'+tarball_filename+'.asc'
171             self.paths['url']['tarball'] = 'https://www.torproject.org/dist/torbrowser/linux/'+tarball_filename
172             self.paths['url']['tarball_sig'] = 'https://www.torproject.org/dist/torbrowser/linux/'+tarball_filename+'.asc'
173             self.paths['filename']['tarball'] = tarball_filename
174             self.paths['filename']['tarball_sig'] = tarball_filename+'.asc'
175
176         else:
177             self.paths = {
178                 'dir': {
179                     'data': tbb_data,
180                     'download': tbb_data+'/download',
181                     'tbb': tbb_data+'/tbb/'+self.architecture,
182                     'gnupg_homedir': tbb_data+'/gnupg_homedir'
183                 },
184                 'file': {
185                     'settings': tbb_data+'/settings',
186                     'version': tbb_data+'/version',
187                     'start': tbb_data+'/tbb/'+self.architecture+'/tor-browser_'+self.language+'/start-tor-browser',
188                     'update_check': tbb_data+'/download/RecommendedTBBVersions',
189                     'torproject_pem': '/usr/share/torbrowser-launcher/torproject.pem',
190                     'erinn_key': '/usr/share/torbrowser-launcher/erinn.asc',
191                     'sebastian_key': '/usr/share/torbrowser-launcher/sebastian.asc'
192                 },
193                 'url': {
194                     'update_check': 'https://check.torproject.org/RecommendedTBBVersions'
195                 },
196                 'filename': {}
197             }
198
199     # create a directory
200     def mkdir(self, path):
201         try:
202             if os.path.exists(path) == False:
203                 os.makedirs(path, 0700)
204                 return True
205         except:
206             self.set_gui('error', "Cannot create directory %s" % path, [], False)
207             return False
208         if not os.access(path, os.W_OK):
209             self.set_gui('error', "%s is not writable" % path, [], False)
210             return False
211         return True
212
213     # if gnupg_homedir isn't set up, set it up
214     def init_gnupg(self):
215         if not os.path.exists(self.paths['dir']['gnupg_homedir']):
216             print 'Creating GnuPG homedir', self.paths['dir']['gnupg_homedir']
217             if self.mkdir(self.paths['dir']['gnupg_homedir']):
218                 # import keys
219                 print 'Importing keys'
220                 p1 = subprocess.Popen(['/usr/bin/gpg', '--homedir', self.paths['dir']['gnupg_homedir'], '--import', self.paths['file']['erinn_key']])
221                 p2 = subprocess.Popen(['/usr/bin/gpg', '--homedir', self.paths['dir']['gnupg_homedir'], '--import', self.paths['file']['sebastian_key']])
222                 # wait for keys to import before moving on
223                 p1.wait()
224                 p2.wait()
225
226     # there are different GUIs that might appear, this sets which one we want
227     def set_gui(self, gui, message, tasks, autostart=True):
228         self.gui = gui
229         self.gui_message = message
230         self.gui_tasks = tasks
231         self.gui_task_i = 0
232         self.gui_autostart = autostart
233
234     # set all gtk variables to False
235     def clear_ui(self):
236         if hasattr(self, 'box'):
237             self.box.destroy()
238         self.box = False
239
240         self.label = False
241         self.progressbar = False
242         self.button_box = False
243         self.start_button = False
244         self.exit_button = False
245
246     # build the application's UI
247     def build_ui(self):
248         self.box = gtk.VBox(False, 20)
249         self.window.add(self.box)
250
251         if self.gui == 'error':
252             # labels
253             self.label = gtk.Label( self.gui_message ) 
254             self.label.set_line_wrap(True)
255             self.box.pack_start(self.label, True, True, 0)
256             self.label.show()
257
258             #self.label2 = gtk.Label("You can fix the problem by deleting:\n"+self.paths['dir']['data']+"\n\nHowever, you will lose all your bookmarks and other Tor Browser preferences.") 
259             #self.label2.set_line_wrap(True)
260             #self.box.pack_start(self.label2, True, True, 0)
261             #self.label2.show()
262
263             # exit button
264             exit_image = gtk.Image()
265             exit_image.set_from_stock(gtk.STOCK_CANCEL, gtk.ICON_SIZE_BUTTON)
266             self.exit_button = gtk.Button("Exit")
267             self.exit_button.set_image(exit_image)
268             self.exit_button.connect("clicked", self.destroy, None)
269             self.box.add(self.exit_button)
270             self.exit_button.show()
271
272         elif self.gui == 'task':
273             # label
274             self.label = gtk.Label( self.gui_message ) 
275             self.label.set_line_wrap(True)
276             self.box.pack_start(self.label, True, True, 0)
277             self.label.show()
278             
279             # progress bar
280             self.progressbar = gtk.ProgressBar(adjustment=None)
281             self.progressbar.set_orientation(gtk.PROGRESS_LEFT_TO_RIGHT)
282             self.progressbar.set_pulse_step(0.01)
283             self.box.pack_start(self.progressbar, True, True, 0)
284
285             # button box
286             self.button_box = gtk.HButtonBox()
287             self.button_box.set_layout(gtk.BUTTONBOX_SPREAD)
288             self.box.pack_start(self.button_box, True, True, 0)
289             self.button_box.show()
290
291             # start button
292             start_image = gtk.Image()
293             start_image.set_from_stock(gtk.STOCK_APPLY, gtk.ICON_SIZE_BUTTON)
294             self.start_button = gtk.Button("Start")
295             self.start_button.set_image(start_image)
296             self.start_button.connect("clicked", self.start, None)
297             self.button_box.add(self.start_button)
298             if not self.gui_autostart:
299               self.start_button.show()
300
301             # exit button
302             exit_image = gtk.Image()
303             exit_image.set_from_stock(gtk.STOCK_CANCEL, gtk.ICON_SIZE_BUTTON)
304             self.exit_button = gtk.Button("Exit")
305             self.exit_button.set_image(exit_image)
306             self.exit_button.connect("clicked", self.destroy, None)
307             self.button_box.add(self.exit_button)
308             self.exit_button.show()
309
310         self.box.show()
311         self.window.show()
312
313         if self.gui_autostart:
314             self.start(None)
315
316     # start button clicked, begin tasks
317     def start(self, widget, data=None):
318         # disable the start button
319         if self.start_button:
320             self.start_button.set_sensitive(False)
321
322         # start running tasks
323         self.run_task()
324       
325     # run the next task in the task list
326     def run_task(self):
327         self.refresh_gtk()
328
329         if self.gui_task_i >= len(self.gui_tasks):
330             self.destroy(False)
331             return
332
333         task = self.gui_tasks[self.gui_task_i]
334         
335         # get ready for the next task
336         self.gui_task_i += 1
337
338         if task == 'download_update_check':
339             print 'Downloading '+self.paths['url']['update_check']
340             self.download('update check', self.paths['url']['update_check'], self.paths['file']['update_check'])
341         
342         if task == 'attempt_update':
343             print 'Checking to see if update it needed'
344             self.attempt_update()
345
346         elif task == 'download_tarball':
347             print 'Downloading '+self.paths['url']['tarball']
348             self.download('tarball', self.paths['url']['tarball'], self.paths['file']['tarball'])
349
350         elif task == 'download_tarball_sig':
351             print 'Downloading '+self.paths['url']['tarball_sig']
352             self.download('signature', self.paths['url']['tarball_sig'], self.paths['file']['tarball_sig'])
353
354         elif task == 'verify':
355             print 'Verifying signature'
356             self.verify()
357
358         elif task == 'extract':
359             print 'Extracting '+self.paths['filename']['tarball']
360             self.extract()
361
362         elif task == 'run':
363             print 'Running '+self.paths['file']['start']
364             self.run()
365         
366         elif task == 'start_over':
367             print 'Starting download over again'
368             self.start_over()
369
370     def response_received(self, response):
371         class FileDownloader(Protocol):
372             def __init__(self, file, total, progress, done_cb):
373                 self.file = file
374                 self.total = total
375                 self.so_far = 0
376                 self.progress = progress
377                 self.all_done = done_cb
378
379             def dataReceived(self, bytes):
380                 self.file.write(bytes)
381                 self.so_far += len(bytes)
382                 percent = float(self.so_far) / float(self.total)
383                 self.progress.set_fraction(percent)
384                 amount = float(self.so_far)
385                 units = "bytes"
386                 for (size, unit) in [(1024 * 1024, "MiB"), (1024, "KiB")]:
387                     if amount > size:
388                         units = unit
389                         amount = amount / float(size)
390                         break
391
392                 self.progress.set_text('Downloaded %2.1f%% (%2.1f %s)' % ((percent * 100.0), amount, units))
393
394             def connectionLost(self, reason):
395                 print 'Finished receiving body:', reason.getErrorMessage()
396                 self.all_done(reason)
397
398         dl = FileDownloader(self.file_download, response.length, self.progressbar, self.response_finished)
399         response.deliverBody(dl)
400
401     def response_finished(self, msg):
402         if msg.check(ResponseDone):
403             self.file_download.close()
404             # next task!
405             self.run_task()
406
407         else:
408             print "FINISHED", msg
409             ## FIXME handle errors
410
411     def download_error(self, f):
412         print "Download error", f
413         self.set_gui('error', "Error starting download:\n\n%s\n\nAre you connected to the internet?" % f.value, [], False)
414         self.clear_ui()
415         self.build_ui()
416
417     def download(self, name, url, path):
418         # initialize the progress bar
419         self.progressbar.set_fraction(0) 
420         self.progressbar.set_text('Downloading '+name)
421         self.progressbar.show()
422         self.refresh_gtk()
423
424         agent = Agent(reactor, VerifyTorProjectCert(self.paths['file']['torproject_pem']))
425         d = agent.request('GET', url,
426                           Headers({'User-Agent': ['torbrowser-launcher']}),
427                           None)
428
429         self.file_download = open(path, 'w')
430         d.addCallback(self.response_received).addErrback(self.download_error)
431         
432         if not reactor.running:
433             reactor.run()
434
435     def attempt_update(self):
436         # load the update check file
437         try:
438             versions = json.load(open(self.paths['file']['update_check']))
439             latest_version = None
440
441             end = '-Linux'
442             for version in versions:
443                 if str(version).find(end) != -1:
444                     latest_version = str(version)
445
446             if latest_version:
447                 self.settings['latest_version'] = latest_version[:-len(end)]
448                 self.settings['last_update_check_timestamp'] = int(time.time())
449                 self.save_settings()
450                 self.build_paths(self.settings['latest_version'])
451                 self.start_launcher()
452
453             else:
454                 # failed to find the latest version
455                 self.set_gui('error', "Error checking for updates.", [], False)
456         
457         except:
458             # not a valid JSON object
459             self.set_gui('error', "Error checking for updates.", [], False)
460
461         # now start over
462         self.clear_ui()
463         self.build_ui()
464
465     def verify(self):
466         # initialize the progress bar
467         self.progressbar.set_fraction(0) 
468         self.progressbar.set_text('Verifying Signature')
469         self.progressbar.show()
470
471         p = subprocess.Popen(['/usr/bin/gpg', '--homedir', self.paths['dir']['gnupg_homedir'], '--verify', self.paths['file']['tarball_sig']])
472         self.pulse_until_process_exits(p)
473         
474         if p.returncode == 0:
475             self.run_task()
476         else:
477             self.set_gui('task', "SIGNATURE VERIFICATION FAILED!\n\nYou might be under attack, or there might just be a networking problem. Click Start try the download again.", ['start_over'], False)
478             self.clear_ui()
479             self.build_ui()
480
481             if not reactor.running:
482                 reactor.run()
483
484     def extract(self):
485         # initialize the progress bar
486         self.progressbar.set_fraction(0) 
487         self.progressbar.set_text('Installing')
488         self.progressbar.show()
489
490         p = subprocess.Popen(['tar', '-xf', self.paths['file']['tarball'], '-C', self.paths['dir']['tbb']], stdout=subprocess.PIPE, stderr=subprocess.STDOUT)
491         self.pulse_until_process_exits(p)
492
493         # installation is finished, so save installed_version
494         self.settings['installed_version'] = self.settings['latest_version']
495         self.save_settings()
496
497         self.run_task()
498
499     def run(self, run_next_task = True):
500         subprocess.Popen([self.paths['file']['start']])
501         if run_next_task:
502             self.run_task()
503
504     # make the progress bar pulse until process p (a Popen object) finishes
505     def pulse_until_process_exits(self, p):
506         while p.poll() == None:
507             time.sleep(0.01)
508             self.progressbar.pulse()
509             self.refresh_gtk()
510
511     # start over and download TBB again
512     def start_over(self):
513         self.label.set_text("Downloading Tor Browser Bundle over again.")
514         self.gui_tasks = ['download_tarball', 'download_tarball_sig', 'verify', 'extract', 'run']
515         self.gui_task_i = 0
516         self.start(None)
517
518     # load settings
519     def load_settings(self):
520         if os.path.isfile(self.paths['file']['settings']):
521             self.settings = pickle.load(open(self.paths['file']['settings']))
522             # sanity checks
523             if not 'installed_version' in self.settings:
524                 return False
525             if not 'latest_version' in self.settings:
526                 return False
527             if not 'last_update_check_timestamp' in self.settings:
528                 return False
529         else:
530             self.settings = {
531                 'installed_version': False,
532                 'latest_version': '0',
533                 'last_update_check_timestamp': 0
534             }
535             self.save_settings()
536         return True
537
538     # save settings
539     def save_settings(self):
540         pickle.dump(self.settings, open(self.paths['file']['settings'], 'w'))
541         return True
542     
543     # refresh gtk
544     def refresh_gtk(self):
545         while gtk.events_pending():
546             gtk.main_iteration(False)
547
548     # exit
549     def delete_event(self, widget, event, data=None):
550         return False
551     def destroy(self, widget, data=None):
552         if hasattr(self, 'file_download'):
553             self.file_download.close()
554         if reactor.running:
555             reactor.stop()
556
557 if __name__ == "__main__":
558     tor_browser_launcher_version = '0.1'
559
560     print 'Tor Browser Launcher'
561     print 'version %s' % (tor_browser_launcher_version)
562     print 'https://github.com/micahflee/torbrowser-launcher'
563
564     app = TorBrowserLauncher()
565