
Virtual machines manipulation framework
Mofos is a tool designed to create, run, and manage virtual machines. It leverages Libvirt/QEMU/KVM, and Python, making it compatible with any Linux distribution. Heavily inspired by Qubes OS (https://www.qubes-os.org/), Mofos aims to replicate many of its features.
The tool has been extensively tested on Debian with Debian-based virtual machines. While other Linux distributions are expected to work, some additional configuration may be necessary. More details to be added.
Mofos provides a range of features focused on securely managing virtual machines, including:
A mofos machine consists of two disks combined using overlayfs. The first disk, known as the lower layer, is a read-only template disk, while the second disk stores all the changes made by the virtual machine. This template disk is shared across multiple virtual machines. As a result, creating a new virtual machine only requires cloning an empty disk that’s already partitioned to hold the modified data. This approach ensures that new virtual machines can be created quickly, while allowing the template to be updated independently. Any updates to the template will take effect for dependent virtual machines upon their next reboot.
Depending on the Linux distribution, the Makefile can be utilized to either generate a deb package or install the files directly.
make deb
apt install ./mofos-VERSION.deb
During the apt installation, various settings will be prompted. The default options can generally be accepted. The only setting that requires attention is the subnet address used by the mofos libvirt network (default: 192.168.90.0/24).
OR
Install the following dependancies:
make install_files
Depending on the distribution, the Python files copied to /usr/lib/python3/dist-packages may not be detected by the Python interpreter and should be placed elsewhere. For example, on Fedora, the Python files must be copied to /usr/lib/python3.11/site-packages.
[!WARNING] Attention, since Debian trixie,
xprais not packaged anymore, you have to install it manually from its custom repositories. See https://github.com/Xpra-org/xpra/wiki/Download#-for-debian-based-distributions for detailed instructions.
Mofos uses the QEMU/KVM system session, so to allow the virsh command to access virtual machines and related resources, set the environment variable LIBVIRT_DEFAULT_URI to qemu:///system:
export LIBVIRT_DEFAULT_URI=qemu:///system
Using QEMU/KVM system sessions improves isolation between the host and guest virtual machines by running qemu instances under a dedicated user (libvirt-qemu) and applying specific security profiles to each instance.
However, by default, regular users cannot interact with the libvirtd system socket to manage machines, networks, and other resources. To gain access, users must either be members of the libvirt Unix group or use sudo. Historically, local privilege escalation vulnerabilities have exploited membership in the libvirt group to obtain root privileges.
To mitigate these risks, this repository provides a strengthened AppArmor profile for the libvirtd process on systems using AppArmor. This profile significantly restricts where libvirtd can write files and which programs it can execute.
Additionally, polkit rules are included to further control the actions permitted for members of the libvirt group.
Note that the AppArmor profiles are packaged in the deb package but are not installed by the Makefile’s install_files target and therefore must be installed separately.
Mofos requires a configuration file located at $HOME/.config/mofos/config.toml with minimal settings to function correctly. A minimal example configuration can be found at /usr/share/mofos/config.minimal.toml, while a more comprehensive configuration is documented in /usr/share/mofos/config.sample.toml.
The following error indicates that the configuration file was not found:
[-] Copy the sample configuration file from /usr/share/mofos/config.minimal.toml to ~/.config/mofos/config.toml
The following error indicates that the current user is not a member of the libvirt group:
[-] libvirtError("authentication unavailable: no polkit agent available to authenticate action 'org.libvirt.unix.manage'")
The key configuration settings to customize in the configuration files are as follows:
Additionally, the following parameters must be configured for template installation:
Since the installation process relies on PXE netboot, an active internet connection is required. The following firewall rules should be configured:
sysctl net.ipv4.ip_forward=1
iptables -t nat -I POSTROUTING -s 192.168.90.0/24 -j MASQUERADE
iptables -t nat -I POSTROUTING -s 192.168.91.0/24 -j MASQUERADE
Or with nftables:
sysctl net.ipv4.ip_forward=1
nft insert inet nat postrouting iifname "install-*" masquerade
nft insert inet nat postrouting iifname "mof0" masquerade
When the ip_forward parameter is set to 1, the FORWARD chain should be configured to prevent other devices on the network from using the host as a router.