/usr/lib/python3/dist-packages/uaclient/__pycache__
NameSizeModeActions
actions.cpython-310.pyc113810644editdlrm
apt.cpython-310.pyc283670644editdlrm
apt_news.cpython-310.pyc73460644editdlrm
config.cpython-310.pyc137600644editdlrm
contract.cpython-310.pyc248990644editdlrm
contract_data_types.cpython-310.pyc80680644editdlrm
data_types.cpython-310.pyc147880644editdlrm
defaults.cpython-310.pyc29130644editdlrm
event_logger.cpython-310.pyc78400644editdlrm
exceptions.cpython-310.pyc250390644editdlrm
gpg.cpython-310.pyc10250644editdlrm
livepatch.cpython-310.pyc106950644editdlrm
lock.cpython-310.pyc46350644editdlrm
log.cpython-310.pyc46330644editdlrm
secret_manager.cpython-310.pyc12560644editdlrm
security_status.cpython-310.pyc165980644editdlrm
snap.cpython-310.pyc64710644editdlrm
status.cpython-310.pyc183610644editdlrm
system.cpython-310.pyc227620644editdlrm
types.cpython-310.pyc4720644editdlrm
update_contract_info.cpython-310.pyc13320644editdlrm
upgrade_lts_contract.cpython-310.pyc29920644editdlrm
util.cpython-310.pyc135250644editdlrm
version.cpython-310.pyc24990644editdlrm
yaml.cpython-310.pyc11780644editdlrm
__init__.cpython-310.pyc1440644editdlrm
Edit: /usr/lib/python3/dist-packages/uaclient/__pycache__/contract.cpython-310.pyc (24899B)
o Ki@sddlZddlZddlZddlmZddlmZmZmZm Z m Z ddl m m ZddlmZmZmZmZmZmZmZmZmZddlmZddlmZddlmZddlm Z dd l!m"Z"m#Z#dd l$m%Z%dd l&m'Z'd Z(d Z)d Z*dZ+dZ,dZ-dZ.dZ/dZ0dZ1dZ2dZ3dddddZ4e5Z6e7e8e9Z:edddgZ;Gdddej<Z=Gdd d e%j>Z?d!e@fd"d#ZA $ $dLd%ed&eeBefd'eeBefd(eCd)eCd*eCd+dfd,d-ZD . $ $dMd%ed/eeBefd0eeBefd(eCd)eCd*eCd+e eeCffd1d2ZEd3ejFd+ejGfd4d5ZHdNd%efd6d7ZId%ed+eefd8d9ZJd%ed:eBd+eeBeffd;d<ZKd=eeBeBfd>eeBeBfd+eLfd?d@ZM dOdAeeBefdBeBdCeBde eBd+eeLeeBefff dDdEZN  dPd/eeBefdFe eBde eBd+dfdGdHZOd%edIeeBefd+ee;fdJdKZPdS)QN) namedtuple)AnyDictListOptionalTuple) data_types event_logger exceptionshttpmessagessecret_managersystemutilversion)_enabled_services) _is_attached)UAConfig)ATTACH_FAIL_DATE_FORMAT)attachment_data_filemachine_id_file) serviceclient)get_user_or_root_log_file_pathz/v1/context/machines/tokenz3/v1/contracts/{contract}/context/machines/{machine}z /v1/resourcesz3/v1/resources/{resource}/context/machines/{machine}z/v1/clouds/{cloud_type}/tokenz3/v1/contracts/{contract}/machine-activity/{machine}z /v1/contractz/v1/magic-attachz?/v1/contracts/{contract}/context/machines/{machine}/guest-token)series_overridesseriescloudvariantEnableByDefaultServicenamer c@seZdZejdejddejdejddejdejddejdejddejdejddejdejddejd ejddejd ejddejd ejddejd ejddejd ejddejdejddejdejddejdejddgZ              ddeedeedeedeedeedeed eed eed eed eed eedeedeedeefddZ dS) CPUTypeData cpuinfo_cpuF)requiredcpuinfo_cpu_architecturecpuinfo_cpu_familycpuinfo_cpu_implementercpuinfo_cpu_partcpuinfo_cpu_revisioncpuinfo_cpu_variant cpuinfo_modelcpuinfo_model_namecpuinfo_steppingcpuinfo_vendor_id"sys_firmware_devicetree_base_model sysinfo_model sysinfo_typeNcCsX||_||_||_||_||_||_||_||_| |_| |_ | |_ | |_ | |_ ||_ dSNr$r&r'r(r)r*r+r,r-r.r/r0r1r2)selfr$r&r'r(r)r*r+r,r-r.r/r0r1r2r63/usr/lib/python3/dist-packages/uaclient/contract.py__init__zs zCPUTypeData.__init__)NNNNNNNNNNNNNN) __name__ __module__ __qualname__rFieldStringDataValuefieldsrstrr8r6r6r6r7r#Fs5     r#c seZdZdZ d+deeddffdd Zeje j gdd d+d d Z de e effd d Zd e de e effddZeje j gddde de e effddZ d+de de dee de e effddZddZde de e effddZde e effddZde fd d!Z d+de d"e dee de e effd#d$Z d+de d"e dee de fd%d&Zde d"e de de fd'd(Zd)d*ZZS),UAContractClient contract_urlNcfgreturncstj|dt|_dS)NrB)superr8mtfget_machine_token_filemachine_token_file)r5rB __class__r6r7r8szUAContractClient.__init__)rrr) retry_sleepsc Cs|st|j}|}|dd|i|}||d<||d}t|}|j t ||d}|j dkr:t |j dkrCt||j dkrRt jt |j |jd |j} tj| d d | d gD] } tj| d d qe| S)a}Requests machine attach to the provided machine_id. @param contract_token: Token string providing authentication to ContractBearer service endpoint. @param machine_id: Optional unique system machine id. When absent, contents of /etc/machine-id will be used. @return: Dict of the JSON response containing the machine-token. Authorization Bearer {}lastAttachment machineId activityInfo)dataheadersiurlcodebody machineTokenresourceTokenstoken)rget_machine_idrBrSupdateformat_get_activity_info isoformat_support_old_machine_info request_urlAPI_V1_ADD_CONTRACT_MACHINErXr AttachInvalidTokenError_raise_attach_forbidden_messageContractAPIErrorrY json_dictr secrets add_secretget) r5contract_token attachment_dt machine_idrS activity_inforRbackcompat_dataresponse response_jsonr]r6r6r7add_contract_machines8       z%UAContractClient.add_contract_machinecCsT|}|jt|d|d|d|ddd}|jdkr'tjt|j|jd|jS) z=Requests list of entitlements available to this machine type. architecturerkernelvirtrurrvrw) query_paramsrUrV)rardAPI_V1_AVAILABLE_RESOURCESrXr rhrYri)r5rprrr6r6r7available_resourcess  z$UAContractClient.available_resourcesrmcCsN|}|dd|i|jt|d}|jdkr$tjt|j|jd|j S)NrLrMrSrUrV) rSr_r`rdAPI_V1_GET_CONTRACT_USING_TOKENrXr rhrYri)r5rmrSrrr6r6r7get_contract_using_tokens z)UAContractClient.get_contract_using_token cloud_typerRcCsz|jtj|d|d}|jdkr.|jdd}|r$t|tj |dtj t|j|j d|j}t j |dd|S) zRequests contract token for auto-attach images for Pro clouds. @param instance: AutoAttachCloudInstance for the cloud. @return: Dict of the JSON response containing the contract-token. )r)rRrUmessager[) error_msgrV contractToken)rd,API_V1_GET_CONTRACT_TOKEN_FOR_CLOUD_INSTANCEr`rXrirlLOGdebugr InvalidProImagerhrYr rjrk)r5rrRrrmsgrsr6r6r7%get_contract_token_for_cloud_instances*     z6UAContractClient.get_contract_token_for_cloud_instance machine_tokenresourceroc Cs|st|j}|}|dd|itj||d}|j||d}|jdkr3t j t|j|j d|j drA|jd|j d<|j }| dgD] }tj| d d qJ|S) aRequests machine access context for a given resource @param machine_token: The authentication token needed to talk to this contract service endpoint. @param resource: Entitlement name. @param machine_id: Optional unique system machine id. When absent, contents of /etc/machine-id will be used. @return: Dict of the JSON response containing entitlement accessInfo. rLrM)rmachiner|rUrVexpiresr\r]r[)rr^rBrSr_r`"API_V1_GET_RESOURCE_MACHINE_ACCESSrdrXr rhrYrlrir rjrk) r5rrrorSrWrrrsr]r6r6r7get_resource_machine_accesss(   z,UAContractClient.get_resource_machine_accesscCs|jj}|jjd}t|j}|}tj ||d}| }| dd |i|j |||d}|j dkrAtj||j |jd|jrU|jj}|j|d<|j|d Sd S) zReport current activity token and enabled services. This will report to the contracts backend all the current enabled services in the system. rZcontractrrLrM)rSrRrUrVrQN)rH contract_idrrlrr^rBraAPI_V1_UPDATE_ACTIVITY_TOKENr`rSr_rdrXr rhrYriwrite)r5rrro request_datarWrSrrr6r6r7update_activity_token;s*    z&UAContractClient.update_activity_token magic_tokencCs|}|dd|i|jt|d}|jdkrt|jdkr't|jdkr6tj t|j|j d|j }gd}|D] }t j ||d q?|S) zRequest magic attach token info. When the magic token is registered, it will contain new fields that will allow us to know that the attach process can proceed rLrMr|rTrUrVr]userCoderr[)rSr_r`rd"API_V1_GET_MAGIC_ATTACH_TOKEN_INFOrXr MagicAttachTokenErrorMagicAttachUnavailablerhrYrir rjrkrl)r5rrSrrrs secret_fieldsfieldr6r6r7get_magic_attach_token_infocs(   z,UAContractClient.get_magic_attach_token_infocCsx|}|jt|dd}|jdkrt|jdkr$tjt|j|jd|j}gd}|D] }t j | |dq-|S)z)Create a magic attach token for the user.POSTrSmethodrrUrVrr[) rSrdAPI_V1_NEW_MAGIC_ATTACHrXr rrhrYrir rjrkrl)r5rSrrrsrrr6r6r7new_magic_attach_tokens&  z'UAContractClient.new_magic_attach_tokencCs|}|dd|i|jt|dd}|jdkrt|jdkr(t|jdkr1t |jdkr@tj t|j|j d d S) z)Revoke a magic attach token for the user.rLrMDELETErrTrrUrVN) rSr_r`rdAPI_V1_REVOKE_MAGIC_ATTACHrXr MagicAttachTokenAlreadyActivatedrrrhrY)r5rrSrrr6r6r7revoke_magic_attach_tokens(    z*UAContractClient.revoke_magic_attach_tokenrc Cs|st|j}|}|dd|itj||d}|}|j|d||d|d|d|dd d }|j d krFt j ||j |j d |j d rT|jd |jd <|jS)a|Get the updated machine token from the contract server. @param machine_token: The machine token needed to talk to this contract service endpoint. @param contract_id: Unique contract id provided by contract service @param machine_id: Optional unique system machine id. When absent, contents of /etc/machine-id will be used. rLrMrGETrurrvrwrx)rrSryrUrVr)rr^rBrSr_r`API_V1_GET_CONTRACT_MACHINErardrXr rhrYrlri)r5rrrorSrWrprrr6r6r7get_contract_machines4    z%UAContractClient.get_contract_machinec Cs|st|j}|}|dd|i||d}t|}tj||d}|j ||d|d}|j dkr@t j ||j |j d|jd rN|jd |jd <|jS) aRequest machine token refresh from contract server. @param machine_token: The machine token needed to talk to this contract service endpoint. @param contract_id: Unique contract id provided by contract service. @param machine_id: Optional unique system machine id. When absent, contents of /etc/machine-id will be used. @return: Dict of the JSON response containing refreshed machine-token rLrMrOrr)rSrrRrUrVr)rr^rBrSr_r`rarcAPI_V1_UPDATE_CONTRACT_MACHINErdrXr rhrYrlri) r5rrrorSrRrqrWrrr6r6r7update_contract_machines*    z(UAContractClient.update_contract_machinecCst|}|dd|itj||d}|j||dd}|jdkr(tjdd|jd kr7tj||j|j d |j S) aRequest guest token associated with this machine's contract @param machine_token: The machine token needed to talk to this contract service endpoint. @param contract_id: Unique contract id provided by contract service @param machine_id: Unique machine id that was registered with the pro backend on attach. @return: Dict of the JSON response containing the guest token rLrMrrrrget_guest_token) feature_namerUrV) rSr_r`API_V1_GET_GUEST_TOKENrdrXr FeatureNotSupportedOldTokenErrorrhrYri)r5rrrorSrWrrr6r6r7rs$  z UAContractClient.get_guest_tokencCst}tjtjtjttt t t |j |j|j|j|j|j|j|j|j|j|j|j|j|jdjddd}t|jjrvt|jj }t!"}|j#j$p[t%|j|j#j&dd|Ddd|D|rq|j'(nd d }ni}i||S) z9Return a dict of activity info data for contract requestsr4F) keep_none) distributionrvrrudesktoprw clientVersioncpu_typecSsg|]}|jqSr6)r".0servicer6r6r7 Hsz7UAContractClient._get_activity_info..cSsi|] }|jr|j|jqSr6)variant_enabledr" variant_namerr6r6r7 Is z7UAContractClient._get_activity_info..N) activityID activityToken resourcesresourceVariantsrN))r get_cpu_infoget_release_inforget_kernel_info uname_releaser get_dpkg_arch is_desktop get_virt_typer get_versionr#r$r&r'r(r)r*r+r,r-r.r/r0r1r2to_dictrrB is_attachedrenabled_servicesrreadrH activity_idr^activity_token attached_atrb)r5cpuinfo machine_inforattachment_datarpr6r6r7ra#s^     z#UAContractClient._get_activity_infor3)r9r:r;cfg_url_base_attrrrr8rretrysockettimeoutrtrr?rr{r~rrrrrrrrrra __classcell__r6r6rIr7r@s~ *  $  &(  / ( #r@ request_bodyc CsJ|di}|d||d|d|d|ddtjdd S) a? Transforms a request_body that has the new activity_info into a body that includes both old and new forms of machineInfo/activityInfo This is necessary because there may be old ua-airgapped contract servers deployed that we need to support. This function is used for attach and refresh calls. rQrPrurrvrLinux)rrvrtyperelease)rPrQruos)rlrrr)rrpr6r6r7rc]s rcTrBpast_entitlementsnew_entitlements allow_enablerverboserCc Cslddlm}d}g}g} ||D]}} z|| } Wn ty!Yqwg} zt||| i| |||d\} } WnMtjy\}zt|d}| | t d| | WYd}~qd}~wt y}zt|| || | td| | WYd}~qd}~ww| r| rt | qt | t|dkrtjd d t| |Dd |rtjd d | Dd dS) aIterate over all entitlements in new_entitlement and apply any delta found according to past_entitlements. :param cfg: UAConfig instance :param past_entitlements: dict containing the last valid information regarding service entitlements. :param new_entitlements: dict containing the current information regarding service entitlements. :param allow_enable: Boolean set True if allowed to perform the enable operation. When False, a message will be logged to inform the user about the recommended enabled service. :param series_overrides: Boolean set True if series overrides should be applied to the new_access dict. :param verbose: If True, display output to stdout r)entitlements_enable_orderF)rB orig_access new_accessrrrTz+Failed to process contract delta for %s: %rNz5Unexpected error processing contract delta for %s: %rcSs*g|]\}}|tjjt|tdfqS))rlog_path)r UNEXPECTED_ERRORr`r?r)rr" exceptionr6r6r7rsz.process_entitlements_delta..)failed_servicescSsg|]}|tjfqSr6)r !E_ATTACH_FAILURE_DEFAULT_SERVICES)rr"r6r6r7rs)uaclient.entitlementsrKeyErrorprocess_entitlement_deltarlr UbuntuProErrorrrappenderror Exceptioneventservice_processedservices_failedlenAttachFailureUnknownErrorzipAttachFailureDefaultServices)rBrrrrrr delta_errorunexpected_errorsrr"new_entitlementdeltasservice_enableder6r6r7process_entitlements_deltaxst              rFrrc Csddlm}|r t|t||}d}|ri|did} | s*|did} | s3tj||d|didid d } z ||| | d } Wntjy_} zt d | | d } ~ ww| j ||||d}||fS)abProcess a entitlement access dictionary deltas if they exist. :param cfg: UAConfig instance :param orig_access: Dict with original entitlement access details before contract refresh deltas :param new_access: Dict with updated entitlement access details after contract refresh :param allow_enable: Boolean set True if allowed to perform the enable operation. When False, a message will be logged to inform the user about the recommended enabled service. :param series_overrides: Boolean set True if series overrides should be applied to the new_access dict. :param verbose: If True, display output to stdout :raise UbuntuProError: on failure to process deltas. :return: A tuple containing a dict of processed deltas and a boolean indicating if the service was fully processed rentitlement_factoryF entitlementr)orignew entitlements obligations use_selectorr[rBr"r z3Skipping entitlement deltas for "%s". No such classNrr) rrapply_contract_overridesrget_dict_deltasrlr InvalidContractDeltasServiceTypeEntitlementNotFoundErrorrrprocess_contract_deltas) rBrrrrrrrretr"r rexcr6r6r7rsD    rrrcCs|jd}|rJ|d}|d}|dkr(|dt}tj|||ddd|dkr@|dt}tj|||ddd |d krJtj|d t) Ninfo contractIdreasonzno-longer-effectivetimez%m-%d-%Y)rdatecontract_expiry_dateznot-effective-yet)rrcontract_effective_dateznever-effective)r) rirlstrftimerr AttachForbiddenExpiredAttachForbiddenNotYetAttachForbiddenNeverAttachExpiredToken)rrrrrrr6r6r7rgs*    rgc Cst|}|}|j}|d}|ddd}t|d}|j||d}||tj | di dt|} t | t |||d|d d S) aRequest contract refresh from ua-contracts service. :param verbose: If True, display output to stdout :raise UbuntuProError: on failure to update contract or error processing contract deltas :raise ConnectivityError: On failure during a connection rZmachineTokenInfo contractInfoidrD)rrrPFr N) rFrGrrr@rrrr^ cache_clearrlrr) rBrrHorig_entitlements orig_tokenrrcontract_clientrespror6r6r7refresh3s,        r%cCst|}|}|dgS)zDQuery available resources from the contract server for this machine.r)r@r{rl)rBclientrr6r6r7get_available_resourcesWs r'r]cCst|}||S)z/Query contract information for a specific token)r@r~)rBr]r&r6r6r7get_contract_information^s r(override_selectorselector_valuescCs<d}|D]\}}||f|vrdS|t|7}q|S)Nr)itemsOVERRIDE_SELECTOR_WEIGHTS)r)r*override_weightselectorvaluer6r6r7_get_override_weightds r0r series_namerc Cszi}||d}|r ||d<|di|i}|r||td<t|dg}|D]}t|d|} | r:||| <q*|S)N)rrr rr overridesr.)popr,copydeepcopyrlr0) rr1rr r2r*rgeneral_overridesoverrideweightr6r6r7_select_overridesps"   r9rcCsddlm}tt|td|vgstd||dur!tj n|}|\}}| di}t ||||}t | D]%\} } | D]\} } |d | } t| trY| | qC| |d| <qCq;dS)aApply series-specific overrides to an entitlement dict. This function mutates orig_access dict by applying any series-overrides to the top-level keys under 'entitlement'. The series-overrides are sparse and intended to supplement existing top-level dict values. So, sub-keys under the top-level directives, obligations and affordance sub-key values will be preserved if unspecified in series-overrides. To more clearly indicate that orig_access in memory has already had the overrides applied, the 'series' key is also removed from the orig_access dict. :param orig_access: Dict with original entitlement access details r)get_cloud_typerz?Expected entitlement access dict. Missing "entitlement" key: {}N)uaclient.clouds.identityr:all isinstancedict RuntimeErrorr`rrrrlr9sortedr+r_)rrr r:r1r_orig_entitlementr2_weightoverrides_to_applykeyr/currentr6r6r7r s*     r rc Csddlm}g}|D]H\}}|didd}z ||||d}Wn tjy-Yq w|didi}|d} ||| rT|\} } | rT|t ||d q |S) Nrrrrr[rr resourceToken)r"r ) rrr+rlr r _should_enable_by_default can_enablerr!) rBrrenable_by_default_servicesent_name ent_valuer entrrGrIrAr6r6r7get_enabled_by_default_servicess,    rN)TT)FTT)Tr3)NN)Qr4loggingr collectionsrtypingrrrrruaclient.files.machine_tokenfilesrrFuaclientrr r r r r rrr-uaclient.api.u.pro.status.enabled_services.v1r(uaclient.api.u.pro.status.is_attached.v1ruaclient.configruaclient.defaultsruaclient.files.state_filesrr uaclient.httpr uaclient.logrrerrrzrrrr}rrrrr,get_event_loggerr getLoggerreplace_top_level_logger_namer9rr! DataObjectr#UAServiceClientr@r>rcr?boolrr HTTPResponse NamedMessagergr%r'r(intr0r9r rNr6r6r6r7s ,     WC    a    A $       1