Your IP : 216.73.216.52


Current Path : /usr/lib/python3/dist-packages/uaclient/entitlements/__pycache__/
Upload File :
Current File : //usr/lib/python3/dist-packages/uaclient/entitlements/__pycache__/base.cpython-38.pyc

U

8�-d��@s�ddlZddlZddlZddlZddlmZddlmZmZmZm	Z	m
Z
mZmZddl
mZmZmZmZmZmZddlmZddlmZmZmZmZmZmZmZmZddlm Z m!Z!ddl"m#Z#dd	l$m%Z%e�&�Z'Gd
d�d�Z(Gdd
�d
ej)d�Z*dS)�N)�datetime)�Any�Dict�List�Optional�Tuple�Type�Union)�config�contract�event_logger�messages�system�util)�DEFAULT_HELP_FILE)�ApplicabilityStatus�ApplicationStatus�CanDisableFailure�CanDisableFailureReason�CanEnableFailure�CanEnableFailureReason�ContractStatus�UserFacingStatus)�MessagingOperationsDict�StaticAffordance)�is_config_value_true)�	safe_loadc@s"eZdZedejd�dd�ZdS)�IncompatibleService�
UAEntitlement��entitlement�	named_msgcCs||_||_dS�Nr)�selfr r!�r$�</usr/lib/python3/dist-packages/uaclient/entitlements/base.py�__init__szIncompatibleService.__init__N)�__name__�
__module__�__qualname__rr
�NamedMessager&r$r$r$r%rs�rc@s�eZdZdZdZdZdZdZdZdZ	dZ
dZdZdZ
dZeejed�dd���Zeeed�dd	��Zeejed�d
d���Zeejed�dd
���Zeed�dd��Zeed�dd��Zeeedfd�dd��Zeeedfd�dd��Zeeeddfd�dd��Z eeeddfd�dd��Z!ee"d�dd��Z#dWe$e%j&e'e'ee'dd�dd �Z(ed!d"��Z)ee'e$e*fd�d#d$�Z+dXe'ee'e,de*ffd%�d&d'�Z-ejdYe'e'd%�d(d)��Z.e'd�d*d+�Z/d,d-�Z0eed�d.d/�Z1e'd�d0d1�Z2ee'e$e3j4fd�d2d3�Z5ee'e$e3j4fd�d4d5�Z6dZe'ee'e$e7fd6�d7d8�Z8d[e'ee'e$e7fd%�d9d:�Z9ejd\e'e'd%�d;d<��Z:e'ee'e$e3j4fd%�d=d>�Z;e'd�d?d@�Z<d]ee'ddA�dBdC�Z=ee>e$e3j4fd�dDdE�Z?e@d�dFdG�ZAeeBe$e3j4fd�dHdI�ZCejeeDe$e3j4fd�dJdK��ZEee'e$e3j4fd�dLdM�ZFe$ed�dNdO�ZGe'd�dPdQ�ZHeDd�dRdS�ZId^eJeeKfeJeeKfe'e'dT�dUdV�ZLdS)_rNFr$T)�returncCsdS)z&The lowercase name of this entitlementNr$�r#r$r$r%�nameDszUAEntitlement.namecCs$|jg}|j|jkr |�|j�|S)z1The list of names this entitlement may be called.)r-�presentation_name�append)r#�valid_namesr$r$r%r0JszUAEntitlement.valid_namescCsdS)z,The human readable title of this entitlementNr$r,r$r$r%�titleRszUAEntitlement.titlecCsdS)z&A sentence describing this entitlementNr$r,r$r$r%�descriptionXszUAEntitlement.descriptioncCsB|jjjr8|jjj�|ji��di��di��d|j�S|jSdS)z/The user-facing name shown for this entitlementr �affordancesZpresentedAsN)�cfg�machine_token_fileZ
is_present�entitlements�getr-r,r$r$r%r.^s
����zUAEntitlement.presentation_namec	CsV|jdkrPi}tj�t�r8ttd��}t|�}W5QRX|�|ji��dd�|_|jS)z$Help information for the entitlementN�r�help�)	�
_help_info�os�path�existsr�openrr7r-)r#Z	help_dict�fr$r$r%�	help_infoks
zUAEntitlement.help_info.cCsdS)Nr$r$r,r$r$r%�static_affordances|sz UAEntitlement.static_affordancescCs|jS)a
        Return a list of packages that aren't compatible with the entitlement.
        When we are enabling the entitlement we can directly ask the user
        if those entitlements can be disabled before proceding.
        Overridden in livepatch and fips
        )�_incompatible_servicesr,r$r$r%�incompatible_services�sz#UAEntitlement.incompatible_servicescCs|jS)a
        Return a list of packages that must be active before enabling this
        service. When we are enabling the entitlement we can directly ask
        the user if those entitlements can be enabled before proceding.
        Overridden in ros and ros-updates.
        )�_required_servicesr,r$r$r%�required_services�szUAEntitlement.required_servicescCs|jS)a
        Return a list of packages that depend on this service.
        We will use that list during disable operations, where
        a disable operation will also disable all of the services
        required by the original service
        Overriden in esm-apps and esm-infra
        )�_dependent_servicesr,r$r$r%�dependent_services�s	z UAEntitlement.dependent_servicescCsiSr"r$r,r$r$r%�	messaging�szUAEntitlement.messagingr:)r4�
assume_yes�
allow_beta�called_name�access_onlyr+cCs4|st��}||_||_||_||_||_d|_dS)z]Setup UAEntitlement instance

        @param config: Parsed configuration dictionary
        N)r
�UAConfigr4rJrKrMZ_called_name�_valid_service)r#r4rJrKrLrMr$r$r%r&�szUAEntitlement.__init__cCs.|jdkr(|jp$|jp$t|jjd�|_|jS)z2Check if the service is marked as valid (non-beta)Nzfeatures.allow_beta)rO�is_betarKrr4r,r$r$r%�
valid_service�s
��zUAEntitlement.valid_servicecCs&|��r"t�d|j�t�|j�|��tj	ksNdt
tjt
jj|jd�d�fS|��\}}|tjkr�dt
tjt
jj|jd�d�fS|js�dt
tj�fS|��\}}|tjkr�dt
tj|d�fS|jr�|��r�dt
tj�fS|jr�|��s�dt
tj�fS|j �s"|j!�r"dt
tj"t
j#j|jd��fSdS)z�
        Report whether or not enabling is possible for the entitlement.

        :return:
            (True, None) if can enable
            (False, CanEnableFailure) if can't enable
        z(Updating contract on service '%s' expiryF�r1��message�TN)$�is_access_expired�logging�debugr-rZrequest_updated_contractr4�contract_statusr�ENTITLEDrrZNOT_ENTITLEDr
�
UNENTITLED�formatr1�application_statusr�DISABLEDZALREADY_ENABLEDrQZIS_BETA�applicability_statusr�INAPPLICABLErD�detect_incompatible_services�INCOMPATIBLE_SERVICErF�check_required_services_active�INACTIVE_REQUIRED_SERVICES�supports_access_onlyrMZACCESS_ONLY_NOT_SUPPORTEDZ ENABLE_ACCESS_ONLY_NOT_SUPPORTED)r#r]�_r_�detailsr$r$r%�
can_enable�sn	���
��
���������
zUAEntitlement.can_enable)�silentr+c	Cs�|j�dg�}t�|�sdS|��\}}|s�|dkr8dS|jtjkrd|��\}}|s�||_	d|fSn4|jtj
kr�|��\}}|s�||_	d|fSnd|fS|j�dg�}t�|�s�dS|j|d�}|s�dS|j�dg�}t�|�s�dSdS)	aNEnable specific entitlement.

        @return: tuple of (success, optional reason)
            (True, None) on success.
            (False, reason) otherwise. reason is only non-None if it is a
                populated CanEnableFailure reason. This may expand to
                include other types of reasons in the future.
        Zpre_can_enable�FNNFZ
pre_enable�riZpost_enablerU)
rIr7r�handle_message_operationsrh�reasonrrb�handle_incompatible_servicesrTrd�_enable_required_services�_perform_enable)	r#ri�msg_opsrh�failZincompat_ret�errorZreq_ret�retr$r$r%�enables>


��


zUAEntitlement.enablecCsdS)a
        Enable specific entitlement. This should be implemented by subclasses.
        This method does the actual enablement, and does not check can_enable
        or handle pre_enable or post_enable messaging.

        @return: True on success, False otherwise.
        Nr$�r#rir$r$r%rpLs	zUAEntitlement._perform_enablecCs2|jD]&}||j���\}}|tjkrdSqdS)z�
        Check for depedent services.

        :return:
            True if there are dependent services enabled
            False if there are no dependent services enabled
        TF)rHr4r]r�ENABLED)r#�dependent_service_cls�
ent_statusrfr$r$r%�detect_dependent_servicesWs
�
z'UAEntitlement.detect_dependent_servicescCs2|jD]&}||j���\}}|tjkrdSqdS)z�
        Check if all required services are active

        :return:
            True if all required services are active
            False is at least one of the required services is disabled
        FT)rFr4r]rrw)r#�required_service_clsryrfr$r$r%rchs


z,UAEntitlement.check_required_services_activecCs<g}|jD],}|�|j���\}}|tjkr
|�|�q
|S)zI
        :return: List of incompatible services that are enabled
        )rDr r4r]rrwr/)r#rt�serviceryrfr$r$r%�blocking_incompatible_servicesws

z,UAEntitlement.blocking_incompatible_servicescCst|���dkS)z�
        Check for incompatible services.

        :return:
            True if there are incompatible services enabled
            False if there are no incompatible services enabled
        r)�lenr}r,r$r$r%ra�sz*UAEntitlement.detect_incompatible_servicescCs�tj|jjdd�}|��D]�}|j|jdd�}tjj|j|jd�}tj	j|j|jd�}|rfd|fStj
||jd�s�d|fSd�|j�}t�
|�|jdd	�}|s|d
fSqdS)a)
        Prompt user when incompatible services are found during enable.

        When enabling a service, we may find that there is an incompatible
        service already enable. In that situation, we can ask the user
        if the incompatible service should be disabled before proceeding.
        There are also different ways to configure that behavior:

        We can disable removing incompatible service during enable by
        adding the following lines into uaclient.conf:

        features:
          block_disable_on_enable: true
        z features.block_disable_on_enable)r
Z
path_to_valueT)rJ)�service_being_enabledZincompatible_serviceF��msgrJz"Disabling incompatible service: {}rkNrU)rrr4r}r r
rbr\r1Z!INCOMPATIBLE_SERVICE_STOPS_ENABLE�prompt_for_confirmationrJ�event�info�disable)r#Zcfg_block_disable_on_enabler|�ent�user_msg�e_msgZdisable_msgrtr$r$r%rn�s:�����
z*UAEntitlement.handle_incompatible_servicesc
Cs�|jD]�}||jdd�}|��dtjk}|rtjj|j|jd�}tj	j|j|jd�}t
j||jd�srd|fSt
�d�|j��|jdd�\}}|sd	}|r�|jr�|jjr�d
|jj}tjj||jd�}	||	fSqdS)
a,
        Prompt user when required services are found during enable.

        When enabling a service, we may find that there are required services
        that must be enabled first. In that situation, we can ask the user
        if the required service should be enabled before proceeding.
        T)rKr)r�required_servicer�FzEnabling required service: {}rkr:�
)rsr|rU)rFr4r]rr^r
ZREQUIRED_SERVICEr\r1ZREQUIRED_SERVICE_STOPS_ENABLErr�rJr�r�rurTr�ZERROR_ENABLING_REQUIRED_SERVICE)
r#r{r�Zis_service_disabledr�r�rtrr�	error_msgr�r$r$r%ro�s<

�����z'UAEntitlement._enable_required_services)�ignore_dependent_servicesr+cCsX|��\}}|tjkr4dttjtjj|jd�d�fS|j	rT|sT|�
�rTdttj�fSdS)z�Report whether or not disabling is possible for the entitlement.

        :return:
            (True, None) if can disable
            (False, CanDisableFailure) if can't disable
        FrRrSrU)r]rr^rrZALREADY_DISABLEDr
r\r1rHrz�ACTIVE_DEPENDENT_SERVICES)r#r�r]rfr$r$r%�can_disable�s 	
��
��zUAEntitlement.can_disablecCs�|j�dg�}t�|�sdS|��\}}|sp|dkr8dS|jtjkrh|j|d�\}}|sp||_	d|fSnd|fS|j
|d�s�dS|j�dg�}t�|�s�dS|jd|d�d	S)
a�Disable specific entitlement

        @param silent: Boolean set True to silence print/log of messages

        @return: tuple of (success, optional reason)
            (True, None) on success.
            (False, reason) otherwise. reason is only non-None if it is a
                populated CanDisableFailure reason. This may expand to
                include other types of reasons in the future.
        Zpre_disablerjNrkFZpost_disablezdisable operation)�	operationrirU)rIr7rrlr�rmrr��_disable_dependent_servicesrT�_perform_disable�_check_for_reboot_msg)r#rirqr�rrrtr�r$r$r%r�s4

��

�zUAEntitlement.disablecCsdS)a\
        Disable specific entitlement. This should be implemented by subclasses.
        This method does the actual disable, and does not check can_disable
        or handle pre_disable or post_disable messaging.

        @param silent: Boolean set True to silence print/log of messages

        @return: True on success, False otherwise.
        Nr$rvr$r$r%r�>szUAEntitlement._perform_disablecCs�|jD]�}||jdd�}|��dtjk}|rtjj|j|jd�}tj	j|j|jd�}t
j||jd�srd|fS|s�t
�tjj|jd��|jdd	�\}}|sd
}	|r�|jr�|jjr�d|jj}	tjj|	|jd�}
d|
fSqd
S)ay
        Disable dependent services

        When performing a disable operation, we might have
        other services that depend on the original services.
        If that is true, we will alert the user about this
        and prompt for confirmation to disable these services
        as well.

        @param silent: Boolean set True to silence print/log of messages
        T)r4rJr)�dependent_service�service_being_disabled)r�r�r�F)r�rkr:r�)rsr�rU)rHr4r]rrwr
ZDEPENDENT_SERVICEr\r1ZDEPENDENT_SERVICE_STOPS_DISABLErr�rJr�r�ZDISABLING_DEPENDENT_SERVICEr�rTr�Z"FAILED_DISABLING_DEPENDENT_SERVICE)r#rirxr�Zis_service_enabledr�r�rtrrr�r�r$r$r%r�KsF
�������z)UAEntitlement._disable_dependent_servicescCst��S)z%Check if system needs to be rebooted.)rZ
should_rebootr,r$r$r%�_check_for_reboot�szUAEntitlement._check_for_reboot)r�rir+cCs$|��r |s t�tjj|d��dS)z�Check if user should be alerted that a reboot must be performed.

        @param operation: The operation being executed.
        @param silent: Boolean set True to silence print/log of messages
        )r�N)r�r�r�r
ZENABLE_REBOOT_REQUIRED_TMPLr\)r#r�rir$r$r%r��s��z#UAEntitlement._check_for_reboot_msgcCs(|jjj�|j�}|s"tjtjfS|j	D]"\}}}|�|kr(tj
|fSq(|d�di�}t��}|�dd�}|j
r�|dk	r�|d|kr�t�|�}tj
tjj|j|dd�|�d�fS|�dd�}	|jr�|	dk	r�|d|	kr�tj
tjj|j|d	d
�fSt��}
|�dd�}|�dd�}|j�rZ|dk	�rZ|
j|k�rZtj
tjj|j|
jd�|�d
�fS|j�r|�r|
jdk	�r|
jdk	�rtjj|j|
j|d�}
z"|�d�\}}t |�}t |�}Wn,t!k
�r�t"�#d|�tj
|
fYSX|
j|k�r�tj
|
fS|
j|k�r|
j|k�rtj
|
fStjdfS)a�Check all contract affordances to vet current platform

        Affordances are a list of support constraints for the entitlement.
        Examples include a list of supported series, architectures for kernel
        revisions.

        :return:
            tuple of (ApplicabilityStatus, NamedMessage). APPLICABLE if
            platform passes all defined affordances, INAPPLICABLE if it doesn't
            meet all of the provided constraints.
        r r3Z
architecturesN�archz, )r1r�Zsupported_arches�series�version)r1r�Z
kernelFlavorsZminKernelVersion)r1�kernelZsupported_kernels)r1r�Z
min_kernel�.z$Could not parse minKernelVersion: %s)$r4r5r6r7r-r�
APPLICABLEr
Z"NO_ENTITLEMENT_AFFORDANCES_CHECKEDrBr`rZget_platform_info�affordance_check_archrZdeduplicate_archesZINAPPLICABLE_ARCHr\r1�join�affordance_check_seriesZINAPPLICABLE_SERIESZget_kernel_info�affordance_check_kernel_flavorZflavorZINAPPLICABLE_KERNELZ
uname_release�#affordance_check_kernel_min_version�major�minorZINAPPLICABLE_KERNEL_VER�split�int�
ValueErrorrW�warning)r#�entitlement_cfgZ
error_messageZfunctorZexpected_resultr3�platformZaffordance_archesZdeduplicated_archesZaffordance_seriesZkernel_infoZaffordance_kernelsZaffordance_min_kernelZinvalid_msgZkernel_majorZkernel_minorZmin_kern_majorZmin_kern_minorr$r$r%r_�s�
��
��
�
����
�������	������
��
z"UAEntitlement.applicability_statuscCs@|jjstjS|jjj�|ji�}|r:|d�d�r:tjStjS)z=Return whether the user is entitled to the entitlement or notr �entitled)	r4Zis_attachedrr[r5r6r7r-rZ)r#r�r$r$r%rY�s
�zUAEntitlement.contract_statuscCs�|��\}}|tjkr tj|fS|jjj�|j	�}|sLtj
tjj
|jd�fS|d�dd�dkrvtj
tjj
|jd�fS|��\}}|tjkr�tj|fS|��\}}|r�tj|fStj|fS)z4Return (user-facing status, details) for entitlementrRr r�F)r_rr�rr`r4r5r6r7r-ZUNAVAILABLEr
ZSERVICE_NOT_ENTITLEDr\r1r]rr^ZINACTIVE�enabled_warning_statusZWARNINGZACTIVE)r#Z
applicabilityrgr�r]Zexplanationr�Zwarn_msgr$r$r%�user_facing_statuss*


���


z UAEntitlement.user_facing_statuscCsdS)z�
        The current status of application of this entitlement

        :return:
            A tuple of (ApplicationStatus, human-friendly reason)
        Nr$r,r$r$r%r](s
z UAEntitlement.application_statuscCsdS)z�
        If the entitlment is enabled, are there any warnings?
        The message is displayed as a Warning Notice in status output

        :return:
            A tuple of (warning bool, human-friendly reason)
        rjr$r,r$r$r%r�4s
z$UAEntitlement.enabled_warning_statuscCsdSr"r$r,r$r$r%�status_description_override@sz)UAEntitlement.status_description_overridecCsF|jjj�|ji�}|�d�}|s&dSt�|d�}|t��krBdSdS)z<Return entitlement access info as stale and needing refresh.ZexpiresFz%Y-%m-%dT%H:%M:%S.%fZT)r4r5r6r7r-r�strptimeZutcnow)r#Zentitlement_contractZ
expire_strZexpiryr$r$r%rVEs
�
zUAEntitlement.is_access_expiredcCsl|j�d�}|dkrtjS|�dg�}|D]:}|�d�|jkr*|�d�}|dkrZtjStjSq*tjS)z6Check on the state of application on the status cache.�status-cacheN�servicesr-Zstatus�enabled)r4�
read_cacherr^r7r-rw)r#�status_cacheZservices_status_listr|Zservice_statusr$r$r%�"_check_application_status_on_cacheSs

z0UAEntitlement._check_application_status_on_cache)�orig_access�deltas�allow_enabler+cCs�|sdS|�di�}|�di�}|j�d�}t|tjk�}|sr|rTt�|�|d}|rrd|krr|ddtjfk}|r�|r�|r�|��}n|�	�\}}	|t
jkr�|��r�|�
�t�d|j�nt�d|j�|j�d	�|j��dS|�d
�}
|
s�|�d
�}
|�di�}t|�d��o|
�}|�r(d|_|��\}
}	|
�r�|�r�|�rptjj|jd
�}tj|tjd�|��n tjj|jd
�}tj|tjd�dSdS)avProcess any contract access deltas for this entitlement.

        :param orig_access: Dictionary containing the original
            resourceEntitlement access details.
        :param deltas: Dictionary which contains only the changed access keys
        and values.
        :param allow_enable: Boolean set True if allowed to perform the enable
            operation. When False, a message will be logged to inform the user
            about the recommended enabled service.

        :return: True when delta operations are processed; False when noop.
        :raise: UserFacingError when auto-enable fails unexpectedly.
        Tr Z
directivesr�r�Fz.Due to contract refresh, '%s' is now disabled.zhUnable to disable '%s' as recommended during contract refresh. Service is still active. See `pro status`zmachine-access-{}�
resourceTokenZobligationsZenableByDefault)r-)Z	file_type)r7r4r��boolrZDROPPED_KEYrZapply_contract_overridesr�r]rr^r�r�rWr�r-r�Zdelete_cache_keyr\rKrhr
ZENABLE_BY_DEFAULT_TMPLr��sys�stderrruZENABLE_BY_DEFAULT_MANUAL_TMPL)r#r�r�r�Zdelta_entitlementZdelta_directivesr�Ztransition_to_unentitledr]rfr�Zdelta_obligationsZenable_by_defaultrhr�r$r$r%�process_contract_deltasgsj
�

��	

�
�z%UAEntitlement.process_contract_deltas)NFFr:F)F)F)F)F)F)F)F)Mr'r(r)Zhelp_doc_urlrJrPrer;rCrErGr�r�r�r��property�abc�abstractmethod�strr-rr0r1r2r.rArrrBrrDrrFrHrrIrr
rNr�r&rQrrhr	rurprzrcr}rar
r*rnrorr�r�r�r�r�r�rr_rrYrr�rr]r�r�rVr�rrr�r$r$r$r%r%s�		��
Q��7
�7�0�� ��.
�9���e
�!�
���

�r)�	metaclass)+r�rWr<r�r�typingrrrrrrr	Zuaclientr
rrr
rrZuaclient.defaultsrZ(uaclient.entitlements.entitlement_statusrrrrrrrrZuaclient.typesrrZ
uaclient.utilrZ
uaclient.yamlrZget_event_loggerr�r�ABCMetarr$r$r$r%�<module>s$ (