
Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­
<!DOCTYPE html>
<html>
3
ôn»j®> ã               @   s  d dl mZ d dlZd dlZd dlZd dlZd dlZd dlZd dlZd dl	Z	d dl
Z
d dlZd dlZd dlZd dlZd dlZd dlZd dlmZ d dlmZ d dlmZ ddlmZmZmZmZmZmZmZmZmZm Z m!Z!m"Z"m#Z#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+ ddlm,Z,m-Z-m.Z. dd	l/m0Z0m1Z1m2Z2m3Z3m4Z4 d
Z5dZ6dÁZ7dZ8dZ9dÂZ:dZ;dZ<ej=dej>ƒZ?ej=dƒZ@ejAjBdƒ�rˆejAjCd dƒ ejDdeEd� e$jFjGejHƒ dd„ ZIdd„ ZJdd „ ZKd!d"„ ZLd#d$„ ZMdÃd%d&„ZNd'd(„ ZOd)d*„ ZPd+d,„ ZQd-d.„ ZRd/d0„ ZSd1d2„ ZTG d3d4„ d4eUƒZVG d5d6„ d6e,ƒZWG d7d8„ d8e,ƒZXG d9d:„ d:e,ƒZYd;d<„ ZZed=d>„ ƒZ[dÄd?d@„Z\dAdB„ Z]dCdD„ Z^i Z_dEdF„ Z`e`e2ja_becedGdƒ�sy8d dldZed dlfZgeejhjiegjjƒeejhjidHƒk �rÌekdIƒ‚W n ekk
�rä   Y n8X dJdK„ Zle2jmZnG dLdM„ dMeoƒZpG dNdO„ dOe2jmƒZqeqe2_mdPdQ„ ZrejsfdRdS„ZtdTdU„ ZudVdW„ ZvG dXdY„ dYeoƒZwdZd[„ Zxd\d]„ ZydÅd_d`„Zzdadb„ Z{dcdd„ Z|dÆdedf„Z}dgdh„ Z~didj„ Zdkdl„ Z€dmdn„ Z�dodp„ Z‚dqdr„ Zƒdsdt„ Z„dudv„ Z…dwdx„ Z†dydz„ Z‡d{d|„ Zˆd}d~„ Z‰dd€„ ZŠd�d‚„ Z‹dƒd„„ ZŒd…d†„ Z�dÇd‡dˆ„ZŽd‰dŠ„ Z�d‹dŒ„ Z�d�dŽ„ Z‘d�d�„ Z’dÈd’d“„Z“d”d•„ Z”d–d—„ Z•d˜d™„ Z–dšd›„ Z—dœd�„ Z˜e&j™dÉdždŸ„ƒZšd d¡„ Z›d¢d£„ ZœG d¤d¥„ d¥ƒZ�d¦d§„ Zžd¨d©„ ZŸdªd«„ Z d¬d­„ Z¡ej¢ejsfd®d¯„Z£d°d±„ Z¤e&j™e*j¥d²ƒej¢fd³d´„ƒƒZ¦dµd¶„ Z§d·d¸„ Z¨d¹dº„ Z©dÊd»d¼„Zªd½d¾„ Z«d¿dÀ„ Z¬dS )Ëé    )Úprint_functionN)ÚArgumentParser)Úcontextmanager)Údatetimeé   )ÚanomalyÚauthÚcapabilitiesÚconfigÚconfig_handlersÚ	constantsÚdoctorÚerrorsÚfetchÚ
http_utilsÚipv6_supportÚkcareÚlibcareÚ	log_utilsÚplatform_utilsÚprocess_utilsÚselinuxÚserver_infoÚserveridÚupdate_utilsÚutils)Ú
KcareErrorÚNotFoundÚSafeExceptionWrapper)Ú	HTTPErrorÚURLErrorÚhttplibÚjson_loads_nstrÚ	urlencodeéc   Zv3Ú12hÚ24hÚ48hÚtestz./etc/sysconfig/kcare/freezer.modules.blacklistz/usr/libexec/kcare/kcdoctor.shú	latest.v3ú	latest.v2z /etc/sysconfig/kcare/sysctl.confé
   z$==BLACKLIST==
(.*)==END BLACKLIST==
z'(kpatch.*|ksplice.*|kpatch_livepatch.*)z/usr/libexec/kcare/pythonÚignore)Úcategoryc              C   sD   t ƒ } tjjtƒr@ttdƒ}x|D ]}| j|jƒ ƒ q"W |jƒ  | S )NÚr)	ÚsetÚosÚpathÚisfileÚFREEZER_BLACKLISTÚopenÚaddÚrstripÚclose)ÚresultÚfÚline© r;   ú./usr/libexec/kcare/python/kcarectl/__init__.pyÚget_freezer_blacklistS   s    

r=   c             C   sB   |j dƒ}| r(dj|d | |d gƒ}ndj|d |d gƒ}|S )NÚ.r   r   éÿÿÿÿr?   )ÚsplitÚjoin)ÚptypeÚfilenameZ
name_partsr;   r;   r<   Ú_apply_ptype]   s
    
rD   c             C   sJ   t | tjƒt_t | tjƒt_t | tjƒt_t | tjƒt_t | tjƒt_d S )N)rD   r
   Ú	PATCH_BINÚ
PATCH_INFOÚBLACKLIST_FILEÚFIXUPS_FILEÚ
PATCH_DONE)rB   r;   r;   r<   Úapply_ptypef   s
    rJ   c              C   s   t jƒ \} }}d}t|tƒrbt|tƒ rbyd|jtj|jƒ|jf }W q² t	t
fk
r^   Y q²X nPt|tt
tfƒrˆt|tƒ rˆd| }n*t|tƒr²|jp t|jƒ} |jp°d|j }tjƒ }tjtjƒ |d |d t| dt| ƒƒ|djtj|dƒƒt|ddƒd	œS )
NÚ z[Errno %i] %s: '%s'z%sr   r   Ú__name__éd   Úattempts)Zagent_versionZpython_versionÚdistroZdistro_versionÚerrorÚdetailsÚ	tracebackrN   )ÚsysÚexc_infoÚ
isinstanceÚOSErrorr    Úerrnor0   ÚstrerrorrC   ÚAttributeErrorÚ	TypeErrorÚKeyErrorÚIOErrorr   ÚetypeÚtypeÚinnerrQ   r   Ú
get_distror   ÚVERSIONÚget_python_versionÚgetattrÚstrrA   rR   Z	format_tb)r]   ÚvalueÚtbZdetails_sanitizedrO   r;   r;   r<   Ú format_exception_without_detailsn   s*    

rg   c              C   sv   t jr
d S tjtƒ ƒ} tjtjtj	| ƒƒƒ}tj
dƒd | }tj|tjƒ ƒ}ytj|ƒ W n tk
rp   Y nX d S )Nz/api/kcarectl-tracez?trace=)r
   ÚUPDATE_FROM_LOCALÚjsonÚdumpsrg   r   ÚnstrÚbase64Zurlsafe_b64encodeZbstrÚget_patch_server_urlr   Zhttp_requestr   Zget_http_auth_stringZurlopen_baseÚ	Exception)ZtraceZencoded_traceÚurlZrequestr;   r;   r<   Úsend_excŠ   s    rp   c             C   sÖ   t jƒ }|dkr t j|dƒ dS t jƒ  t jƒ }|dkrBt jdƒ t jdƒ ttjdƒ�&}t j	|j
ƒ dƒ t j	|j
ƒ dƒ W dQ R X |r’tj|ƒ y
| ƒ  W n* tk
rÆ   tjjdƒ t jdƒ Y nX t jdƒ dS )zš
    Run func in a fork in an own process group
    (will stay alive after kcarectl process death).
    :param func: function to execute
    :return:
    r   NÚar   é   zWait exception)r0   ÚforkÚwaitpidÚsetsidÚ_exitr7   r4   r   ZLOG_FILEÚdup2ÚfilenoÚtimeÚsleeprn   r   ÚkcarelogÚ	exception)Úfuncrz   ÚpidÚfdr;   r;   r<   Ú
nohup_forkœ   s(    



r€   c              C   sˆ   t jjtjdƒ} t jj| ƒrtt| dƒ�H}y,t|jƒ ƒ}|t	j
 tjƒ krRt|| ƒ‚W n tk
rh   Y nX W dQ R X tj| tjƒ ƒ dS )a  Check the fact that there was a failed patching attempt.
    If anchor file not exists we should create an anchor with
    timestamp and schedule its deletion at $timeout.

    If anchor exists and its timestamp more than $timeout from now
    we should raise an error.
    z.kcareprev.lockr.   N)r0   r1   rA   r   ÚPATCH_CACHEr2   r4   ÚintÚreadr
   ÚSUCCESS_TIMEOUTry   ÚPreviousPatchFailedExceptionÚ
ValueErrorr   Úatomic_writeÚtimestamp_str)Zanchor_filepathZafileÚ	timestampr;   r;   r<   Útouch_anchorÂ   s    rŠ   c             C   sx   yt jt jjtjdƒƒ W n tk
r.   Y nX td| ƒ tj	j
ƒ  ytdd� W n  tk
rr   tjjdƒ Y nX dS )zÀ
    See touch_anchor() for detailed explanation of anchor mechanics.
    See KPT-730 for details about action registration.
    :param state_data: dict with current level, kernel_id etc.
    z.kcareprev.lockÚdone)ÚreasonzCannot send update info!N)r0   Úremover1   rA   r   r�   rV   Úregister_actionr   Úget_loaded_modulesÚclearÚget_latest_patch_levelrn   r   r{   r|   )Ú
state_datar;   r;   r<   Úcommit_updateÙ   s    

r“   c             C   s(   t jtjjtjdƒtj| |dƒd� d S )NÚpatchesrK   )Zexclude_path)	r   Úclean_directoryr0   r1   rA   r   r�   r   Úget_cache_path)ÚkhashZplevelr;   r;   r<   Úclear_cacheî   s    r˜   c             C   s>   t jpd}dj|| gƒ}tjd|f}|r2||f7 }tjj|Ž S )NÚnoneú-Úmodules)r
   ÚPREFIXrA   r   r�   r0   r1   )r—   ÚfnameÚprefixZ
module_dirr8   r;   r;   r<   Úget_current_level_pathò   s    

rŸ   c             C   s   t jt| dƒt|ƒdd� d S )NÚlatestT)Z
ensure_dir)r   r‡   rŸ   rd   )r—   Úpatch_levelr;   r;   r<   Úsave_cache_latestû   s    r¢   c             C   sV   t | dƒ}tjj|ƒrRy"tt|dƒjƒ jƒ ƒ}tj	| |ƒS  t
tfk
rP   Y nX d S )Nr    r.   )rŸ   r0   r1   r2   r‚   r4   rƒ   Ústripr   ÚLegacyKernelPatchLevelr†   rZ   )r—   Zpath_with_latestÚplr;   r;   r<   Úget_cache_latestÿ   s    
r¦   c               @   s   e Zd ZdS )ÚCertificateErrorN)rL   Ú
__module__Ú__qualname__r;   r;   r;   r<   r§     s   r§   c                   s    e Zd ZdZ‡ fdd„Z‡  ZS )ÚUnknownKernelExceptionzunknown kernelc                s6   dj tjƒ d tjƒ tjƒ ƒ}tt| ƒj	|f|Ž d S )NzLNew kernel detected ({0} {1} {2}).
There are no updates for this kernel yet.r   )
Úformatr   r`   ÚplatformÚreleaser   Úget_kernel_hashÚsuperrª   Ú__init__)ÚselfÚkwargsÚmsg)Ú	__class__r;   r<   r°     s    zUnknownKernelException.__init__)rL   r¨   r©   Ústatusr°   Ú__classcell__r;   r;   )r´   r<   rª     s   rª   c                   s(   e Zd ZdZ‡ fdd„Zdd„ Z‡  ZS )ÚApplyPatchErrorzpatch apply errorc                sF   t t| ƒj||Ž || _|| _|| _|| _tjƒ d | _	t
jƒ | _d S )Nr   )r¯   r·   r°   ÚcodeÚfreezer_styleÚlevelÚ
patch_filer   r`   rO   r¬   r­   )r±   r¸   r¹   rº   r»   Úargsr²   )r´   r;   r<   r°     s    zApplyPatchError.__init__c          	   C   s0   dj | j| j| j| j| jdjdd„ | jD ƒƒƒS )Nz0Unable to apply patch ({0} {1} {2} {3} {4}, {5})z, c             S   s   g | ]}t |ƒ‘qS r;   )rd   )Ú.0Úir;   r;   r<   ú
<listcomp>-  s    z+ApplyPatchError.__str__.<locals>.<listcomp>)r«   r»   rº   r¸   rO   r­   rA   r¹   )r±   r;   r;   r<   Ú__str__&  s    zApplyPatchError.__str__)rL   r¨   r©   rµ   r°   rÀ   r¶   r;   r;   )r´   r<   r·     s   	r·   c                   s(   e Zd ZdZ‡ fdd„Zdd„ Z‡  ZS )r…   zprevious patch failedc                s"   t t| ƒj||Ž || _|| _d S )N)r¯   r…   r°   r‰   Úanchor)r±   r‰   rÁ   r¼   r²   )r´   r;   r<   r°   5  s    z%PreviousPatchFailedException.__init__c             C   s   d}|j | j| jƒS )NzˆIt seems, the latest patch, applying at {0}, crashed, and further attempts will be suspended. To force patch applying, remove `{1}` file)r«   r‰   rÁ   )r±   Úmessager;   r;   r<   rÀ   :  s    z$PreviousPatchFailedException.__str__)rL   r¨   r©   rµ   r°   rÀ   r¶   r;   r;   )r´   r<   r…   2  s   r…   c             C   sÀ   t jƒ dj| ƒ }yztj|ƒ}tjtj|jƒ ƒƒ}t	|d ƒ}|dkrRtj
dƒ n8|dkrftj
dƒ n$|dkrztj
dƒ ntj
d	j|ƒƒ |S  tk
rº } ztj||ƒ W Y d d }~X nX d
S )Nz"/nagios/register_key.plain?key={0}r¸   r   zKey successfully registeredr   zWrong key format or sizerr   z!No KernelCare license for that IPzUnknown error {0}r?   )r   Úget_registration_urlr«   r   Úurlopenr   Údata_as_dictrk   rƒ   r‚   Úprint_wrapperr   r   Úprint_cln_http_error)Úkeyro   ÚresponseÚresr¸   Úer;   r;   r<   Ú!set_monitoring_key_for_ip_licenseC  s     
rÌ   c               c   s>   t jrtjt jdd� z
d V  W d t jr8tjt jdd� X d S )NT)Úshell)r
   ZBEFORE_UPDATE_COMMANDr   Úrun_commandZAFTER_UPDATE_COMMANDr;   r;   r;   r<   Úexecute_hooksW  s    
rÏ   c             C   sÖ   t ƒ }|j}|j}tjƒ }| dkrht|ƒtjtj	ƒ t
jƒ |ttjƒ ƒ|dœ}tjdƒ tjtj|ƒƒ njtjdƒ tjt|ƒƒ tjdt|ƒ ƒ tjtjƒ tjtj	ƒ ƒ tjt
jƒ ƒ tj|ƒ tjtjƒ ƒ dS )a1  
    The output will consist of:
    Ignore output up to the line with "--START--"
    Line 1: show if update is needed:
        0 - updated to latest,
        1 - update available,
        2 - unknown kernel
        3 - kernel doesn't need patches
        4 - no license, cannot determine
    Line 2: licensing message (can be skipped, can be more then one line)
    Line 3: LICENSE: CODE: 1: license present, 2: trial license present, 0: no license
    Line 4: Update mode (True - auto-update, False, no auto update)
    Line 5: Effective kernel version
    Line 6: Real kernel version
    Line 7: Patchset Installed # --> If None, no patchset installed
    Line 8: Uptime (in seconds)

    If *format* is 'json' return the results in JSON format.

    Any other output means error retrieving info
    :return:
    ri   )Z
updateCodeZ
autoUpdateZeffectiveKernelZ
realKernelZloadedPatchLevelZuptimeÚlicensez	--START--z	LICENSE: N)Ú_patch_level_infor¸   Úapplied_lvlr   Úlicense_inford   r
   ÚAUTO_UPDATEr   Úkcare_unamer¬   r­   r‚   r   Z
get_uptimer   rÆ   ri   rj   )ÚfmtÚpliZupdate_codeZ	loaded_plZlicense_info_resultZresultsr;   r;   r<   Úplugin_infoc  s,    



rØ   c              C   s^   t jƒ } ytdd�}W n tk
r4   tjr0dS dS X | d krBdS | |krNdS tjƒ rZdS dS )NÚinfo)rŒ   r   é   r   rr   )r   Úloaded_patch_levelr‘   rª   r
   ÚIGNORE_UNKNOWN_KERNELr   Zstatus_gap_passed)Úcurrent_levelZlatest_patch_levelr;   r;   r<   Úget_update_status—  s    rÞ   c              C   s2   t jƒ d d… \} }| dkr*|jdƒr*dS dS d S )Nrr   Z
CloudLinuxz7.ÚextrarK   )r   r`   Ú
startswith)rO   Úversionr;   r;   r<   Úedf_fallback_ptype§  s    râ   c             C   sl   | j | jf}tj||ƒ}tj|| jƒ| _| jjtj	tj
dƒ |tkrZ| jjƒ dd… t|< | jrh| jƒ  dS )z�Function remembers IP address of host connected to
    and uses it for later connections.

    Replaces stdlib version of httplib.HTTPConnection.connect
    r   Nrr   )ÚhostZportÚCONNECTION_STICKY_MAPÚgetÚsocketZcreate_connectionZtimeoutÚsockZ
setsockoptZIPPROTO_TCPZTCP_NODELAYZgetpeernameÚ_tunnel_hostZ_tunnel)r±   ZaddrZresolved_addrr;   r;   r<   Ústicky_connect´  s    ré   ZHAS_SNIz0.13z%No pyOpenSSL module with SNI ability.c              G   s   dS )NTr;   )r¼   r;   r;   r<   Údummy_verify_callbackØ  s    rê   c               @   s,   e Zd Zdd„ Zdd„ Zdd„ Zdd„ Zd	S )
ÚSSLSockc             C   s   || _ d| _d S )Nr   )Ú	_ssl_connÚ_makefile_refs)r±   rç   r;   r;   r<   r°   â  s    zSSLSock.__init__c             G   s&   |  j d7  _ tj| jf|žddiŽS )Nr   r7   T)rí   ræ   Z_fileobjectrì   )r±   r¼   r;   r;   r<   Úmakefileæ  s    zSSLSock.makefilec             C   s"   | j  r| jr| jjƒ  d | _d S )N)rí   rì   r7   )r±   r;   r;   r<   r7   ê  s    
zSSLSock.closec             G   s   | j j|Ž S )N)rì   Úsendall)r±   r¼   r;   r;   r<   rï   ï  s    zSSLSock.sendallN)rL   r¨   r©   r°   rî   r7   rï   r;   r;   r;   r<   rë   á  s   rë   c               @   s   e Zd Zdd„ ZdS )ÚPyOpenSSLHTTPSConnectionc             C   s¾   t jj| ƒ tjjtjjƒ}|jtjjtjj	B ƒ t
jrJ|jtjjtƒ n|jtjjtƒ |jƒ  tjj|| jƒ}|jƒ  | jp„| j}|j|jƒ ƒ |jƒ  t
jr°t|jƒ |ƒ t|ƒ| _d S )N)r!   ÚHTTPConnectionÚconnectÚOpenSSLZSSLZContextZSSLv23_METHODZset_optionsZOP_NO_SSLv2ZOP_NO_SSLv3r
   ÚCHECK_SSL_CERTSZ
set_verifyZVERIFY_PEERrê   ZVERIFY_NONEZset_default_verify_pathsZ
Connectionrç   Zset_connect_staterè   rã   Zset_tlsext_host_nameÚencodeZdo_handshakeÚmatch_hostnameZget_peer_certificaterë   )r±   ZctxZconnZserver_hostr;   r;   r<   rò   ó  s    z PyOpenSSLHTTPSConnection.connectN)rL   r¨   r©   rò   r;   r;   r;   r<   rð   ò  s   rð   c             C   s²  t jr&tj| |ƒ}tjtjƒ|dd�S |dk}t jo6|}�xrd|fd|fdgD �]Z\}}t	j	|||d�}	t	j
|	|d�}
|r„dj|
ƒ}
tj| t||ƒƒd	 |
 }d
}|sª|rÔt|ƒ|krÔ|r¾dnd}tjdj|ƒƒ qNyxtjtjƒ|dd�}t j�rJtj|	ƒ�rJtj|	ƒ}tj|ƒ}|�r.tjdj|ƒdd� ntjddd� |�rJ|jƒ  |S  tk
�r¨ } z>|�sl|�r–|jdk�s„|jdk�r–tjdj|ƒƒ wN‚ W Y d d }~X qNX qNW d S )NF)Úcheck_licenseú	latest.v1ú	latest.v2T)Úsecure_boot_infoÚperf_metrics)Úb64_encodingzinfo={0}ú?iX  zsecure boot infozperf metricsz/Check-in URL param is too large, discarding {0}z:Automatic kernel anomaly report uploaded successfully: {0})Ú	print_msgz$Failed to send kernel anomaly reporté�  éž  iô  zCCheck-in request failed with error: {0}, retrying with reduced info)rø   rù   )FF)rÿ   r   )r
   rh   r   Zget_kernel_prefixed_urlr   Zwrap_with_cache_keyr   Úurlopen_authZSEND_PERF_METRICSr   Zencode_checkin_payloadr«   ÚstickyfyÚlenr   ÚlogwarnZKERNEL_ANOMALY_REPORT_ENABLEr   Zdetect_anomalyÚprepare_kernel_anomaly_reportÚsend_data_packageÚloginfoÚremove_archiver   r¸   )r—   r    rŒ   Úmodero   rü   Zperf_enabledrú   rû   ZsinfoZrequest_paramZmax_url_lengthZdiscard_infor8   Údata_packageÚupload_nameÚexr;   r;   r<   Ú_fetch_patch_level_request  sB    
 


$r  c       	      C   s8  t jƒ }tjd k	r$t j|ttjƒƒS �xtD � ]ü}yªt||| |ƒ}tj	|j
ƒ tƒ  tj|jƒ ƒjƒ }tjdj| |ƒdd� |rÎ|jdƒrÎt|ƒ}|jdg ƒ}tj|ƒs²tjdƒ‚t j||d |d |d	 ƒS t j|t|ƒƒS  tk
rð   Y q, tk
�r( } z|jdk�rtdƒ‚‚ W Y d d }~X q,X q,W tƒ ‚d S )Nz;fetch patch level, reason: {0}, kernel latest response: {1}F)rþ   ú{r	   zeLatest KernelCare patchset is incompatible with the current kernecare package version, please upgraderº   Úbaseurlr­   é“  é‘  zKC licence is required)r  r  ) r   r®   r
   ÚPATCH_LEVELr¤   r‚   ÚPATCH_LATESTr  r   Zset_feature_flags_from_headersÚheadersÚupdate_all_kmod_paramsr   rk   rƒ   r£   r   r  r«   rà   r"   rå   r	   Zhas_kc_capabilitiesr   ÚCapabilitiesMismatchZKernelPatchLevelr   r   r¸   r   rª   )	rŒ   r	  r—   r    rÉ   r¥   Zlatest_infoZrequired_capabilitiesr  r;   r;   r<   Úfetch_patch_level;  s2    

r  c             C   s<  | j t|tjƒƒ}tjjdj|ƒƒ ytj	|ddd� dS  t
k
r^   tjjdj|ƒƒ dS  tk
r– } ztjjdj|t|ƒƒƒ W Y d d }~X nX | j t|tjƒtj ƒ}tjjdj|ƒƒ ytj	|dd� W nb t
k
� rü   tjjdj|ƒƒ dS  tk
�r6 } ztjjd	j|t|ƒƒƒ W Y d d }~X nX dS )
NzProbing patch URL: {0}FÚHEAD)r÷   ÚmethodTz{0} is not available: 404zFHEAD request for {0} raised an error, fallback to the GET request: {1})r÷   z{0} is not available: {1})Úfile_urlrD   r
   rE   r   r{   rÙ   r«   r   r  r   rn   Údebugrd   r   ZSIGr    )rº   rB   Zbin_urlr  ro   r;   r;   r<   Úprobe_patch\  s(    **r  c             C   sF   |t jkr| jt jƒ}n
| j|ƒ}| j|ƒ}tj||tjtj	| ƒd�S )N)Zhash_checker)
r   ÚKMOD_BINZkmod_urlr  Ú
cache_pathr   Z	fetch_urlr
   ÚUSE_SIGNATUREZget_hash_checker)rº   Únamero   Zdstr;   r;   r<   Úfetch_and_verify_kernel_fileu  s
    


r!  c               @   s>   e Zd Zddd„Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ ZdS )ÚPatchFetcherNc             C   s
   || _ d S )N)r¡   )r±   r¡   r;   r;   r<   r°   €  s    zPatchFetcher.__init__c             C   s   t | j|ƒS )N)r!  r¡   )r±   r   r;   r;   r<   Ú_fetchƒ  s    zPatchFetcher._fetchc             C   sr   | j jtjƒ}| j jtjƒ}| j jtjƒ}| j jtjƒ}tdd„ ||||fD ƒƒopt	j
j|ƒdkopt	j
j|ƒdkS )Nc             s   s   | ]}t jj|ƒV  qd S )N)r0   r1   r2   )r½   r1   r;   r;   r<   ú	<genexpr>�  s    z0PatchFetcher.is_patch_fetched.<locals>.<genexpr>r   )r¡   r  r
   rI   rE   rF   r   r  Úallr0   r1   Úgetsize)r±   Zpatch_done_pathZpatch_bin_pathZpatch_info_pathZkmod_bin_pathr;   r;   r<   Úis_patch_fetched†  s    zPatchFetcher.is_patch_fetchedc             C   s4  | j d krtdƒ‚| j s| j S | jƒ r6tjdƒ | j S tjdƒ t| j tjƒr¦ytj	| j j
tjƒdd�}W n tk
r~   Y n(X |jjdd ƒ}|r¦| j jtj|ƒƒ| _ y| jtjƒ W n0 tk
ræ   tdj| j tjpØdƒd	d
�‚Y nX | jtjƒ | jtjƒ | jƒ  tj| j jtjƒddd� tjtj ƒ | j S )Nz+Cannot fetch patch as no patch level is setzUpdates already downloadedzDownloading updatesr  )r  zKC-Base-UrlzfThe `{0}` patch level is not found for `{1}` patch type. Please select valid patch type or patch levelÚdefaultzpatch level not found)rµ   ó    Úwb)r	  )!r¡   r†   r'  r   r  rU   r   r¤   r   r  r  r
   rE   r   r  rå   Úupgrader   rk   r#  r   r«   Ú
PATCH_TYPErF   r   r  Úextract_blacklistr‡   r  rI   r   Úrestore_selinux_contextr�   )r±   Úrespr  r;   r;   r<   Úfetch_patch’  s:    


zPatchFetcher.fetch_patchc             C   sF   t j| jjtjƒƒ}|rBtj|ƒ}|rBt j| jjtj	ƒ|j
dƒƒ d S )Nr   )r   Úread_text_filer¡   r  r
   rF   ÚBLACKLIST_REÚsearchr‡   rG   Úgroup)r±   ZbufZmor;   r;   r<   r-  »  s
    
zPatchFetcher.extract_blacklistc             C   s´   |dkrdS yt |tjƒ}W n tk
r0   dS X |jjddƒ}|rT|jtj|ƒƒ}|j	tjƒ}t
|dƒ�}tdd„ |jƒ D ƒƒ}W dQ R X x|D ]}t ||ƒ q’W tjtjƒ dS )z¶
        Download fixup files for defined patch level
        :param level: download fixups for this patch level (usually it's a level of loaded patch)
        :return: None
        NzKC-Base-Urlr.   c             S   s   g | ]}|j ƒ ‘qS r;   )r£   )r½   Úfixupr;   r;   r<   r¿   Ø  s    z-PatchFetcher.fetch_fixups.<locals>.<listcomp>)r!  r
   rH   r   r  rå   r+  r   rk   r  r4   r/   Ú	readlinesr   r.  r   r�   )r±   rº   r/  r  Zfixups_fnamer9   Úfixupsr5  r;   r;   r<   Úfetch_fixupsÂ  s     
zPatchFetcher.fetch_fixups)N)	rL   r¨   r©   r°   r#  r'  r0  r-  r8  r;   r;   r;   r<   r"  ~  s   
)r"  c              C   s8   t ƒ } tj| jƒ | jtjkr*tjdƒ n
tjdƒ d S )Nr   r   )	rÑ   r   rÆ   r³   r¸   ÚPLIÚPATCH_NEED_UPDATErS   Úexit)r×   r;   r;   r<   Úkcare_checkà  s
    r<  c              C   s\  t ƒ } t| ƒ}ytjƒ }W n tk
r2   i }Y nX tjƒ }d}|d k	r\tj|d ƒj	dƒ}tj
ƒ }|jdg ƒ}ttj|dd�ƒ}t|ƒ}dd„ |D ƒ}	ttj|	d	d�ƒ}
td
d„ |D ƒƒ}|| }tjƒ }|sÜtjdƒ n
tjdƒ tjdj|ƒƒ tjdj|ƒƒ |dk�r tjdj|ƒƒ |
dk�r:tjdj|
ƒƒ |dk�rNtjdƒ tjdƒ d S )NZUnknownÚtsz%Y-%m-%dr”   z
kpatch-cve)Z	cve_fieldc             S   s"   g | ]}|j d g ƒD ]}|‘qqS )r”   )rå   )r½   ÚrecÚpatchr;   r;   r<   r¿   ý  s    z%show_generic_info.<locals>.<listcomp>Zcvec             s   s   | ]}t |jd g ƒƒV  qdS )r”   N)r  rå   )r½   r>  r;   r;   r<   r$  ÿ  s    z$show_generic_info.<locals>.<genexpr>z$KernelCare live patching is disabledz"KernelCare live patching is activez - Last updated on {0}z - Effective kernel version {0}r   z* - {0} kernel vulnerabilities live patchedz- - {0} userspace vulnerabilities live patchedz% - This system has no applied patchesz(Type kcarectl --patch-info to learn more)rÑ   Ú_kcare_patch_info_jsonr   Zlibcare_patch_info_basicr   r   Z	get_stater   ZfromtimestampZstrftimerÕ   rå   r  r   Zextract_unique_cvesÚsumrÛ   rÆ   r«   )r×   Ú
kcare_infoÚlibcare_infoÚstateZlatest_updateZeffective_versionZkernel_patchesZkernel_vulnerabilitiesZkernel_patches_countZuserspace_patchesZuserspace_vulnerabilitiesZuserspace_patches_countZtotal_patches_countr¡   r;   r;   r<   Úshow_generic_infoé  s>    





rE  Fc       	      C   sô   y¤t dtjd�}|st‚|jtjƒ}tjt	j
|ƒjƒ ƒ}| r˜g i  }}x>|jdƒD ]0}tj|ƒ}|rxd|krx|j|ƒ qR|j|ƒ qRW ||d< tj|ƒ}tj|ƒ W nJ tk
rÒ } ztj||jƒ dS d}~X n tk
rî   tjdƒ Y nX d	S )
z½
    Retrieve and output to STDOUT latest patch info, so it is easy to get
    list of CVEs in use. More info at
    https://cloudlinux.atlassian.net/browse/KCARE-952
    :return: None
    rÙ   )rŒ   Úpolicyz

zkpatch-namer”   r   NzNo patches availabler   )r‘   r   ÚPOLICY_REMOTErª   r  r
   rF   r   rk   r   r  rƒ   r@   rÅ   ÚappendÚupdateri   rj   rÆ   r   r   rÇ   ro   )	Úis_jsonr    ro   Ú
patch_infor”   r8   ÚchunkÚdatarË   r;   r;   r<   Úkcare_latest_patch_info  s,    


rN  c             C   sˆ   d| j i}| jd k	r„t| ƒ}g }x>|jdƒD ]0}tj|ƒ}|rRd|krR|j|ƒ q,|j|ƒ q,W ||d< tj	ƒ }|r||d nd|d< |S )NrÂ   z

zkpatch-namer”   r­   Úunknown)
r³   rÒ   Ú_kcare_patch_infor@   r   rÅ   rH  rI  r   Zread_dumped_kernel_patch_level)r×   r8   rK  r”   rL  rM  Zsaved_patch_levelr;   r;   r<   r@  4  s    


r@  c             C   sP   t jƒ }t j|| jtjƒ}tjj|ƒs2t	ddd�‚t
j|ƒ}|rLtjd|ƒ}|S )NzvCan't find information due to the absent patch information file. Please, run /usr/bin/kcarectl --update and try again.zpatch info not found)rµ   rK   )r   r®   r–   rÒ   r
   rF   r0   r1   r2   r   r   r1  r2  Úsub)r×   r—   r  rÙ   r;   r;   r<   rP  H  s    
rP  c             C   sZ   t ƒ }| s>|jdkr tj|jƒ |jd kr.d S tjt|ƒƒ ntjtjt	|ƒdd�ƒ d S )Nr   T)Z	sort_keys)
rÑ   r¸   r   rÆ   r³   rÒ   rP  ri   rj   r@  )rJ  r×   r;   r;   r<   rK  W  s    

rK  c             C   s:   t jd| g}tj|ƒ}tjƒ }d}tj||ƒtj||ƒkS )Nz	file-infozkpatch-build-time)r   Ú
KPATCH_CTLr   Úcheck_outputr   Ú_patch_infoZget_patch_value)Únew_patch_filer¼   Znew_patch_infoZcurrent_patch_infoZbuild_time_labelr;   r;   r<   Úis_same_patchc  s
    
rV  c             C   sL   |dkrdS | r|| k rdS | |kr(dS t jt jƒ |tjƒ}t|ƒsHdS dS )Nr   FT)r   r–   r®   r
   rE   rV  )Úapplied_levelÚ	new_levelrU  r;   r;   r<   Úkcare_need_updatek  s    rY  c              C   sp   t jrltjjtƒotjttjƒs6tj	j
djtƒƒ d S tjdddtgdd�\} }}| dkrltj	j
dj| ƒƒ d S )	Nz-File {0} does not exist or has no read accessz/sbin/sysctlz-qz-pT)Úcatch_stdoutr   z%Unable to load kcare sysctl.conf: {0})r
   ZUPDATE_SYSCTL_CONFIGr0   r1   r2   ÚSYSCTL_CONFIGÚaccessÚR_OKr   r{   Úwarningr«   r   rÎ   )r¸   Ú_r;   r;   r<   Úupdate_sysctl}  s    r`  c                s¼   t jjtƒsttdƒjƒ  t jtt jƒs>tj	j
djtƒƒ dS ttdƒ�j}|jƒ }|jdƒ x,|D ]$‰ t‡ fdd„| D ƒƒsb|jˆ ƒ qbW x|D ]}|j|d ƒ q�W |jƒ  W dQ R X dS )	z*Update SYSCTL_CONFIG accordingly the editsrq   zFile {0} has no read accessNzr+r   c             3   s   | ]}ˆ j |ƒV  qd S )N)rà   )r½   r.   )r:   r;   r<   r$  ™  s    z#edit_sysctl_conf.<locals>.<genexpr>Ú
)r0   r1   r2   r[  r4   r7   r\  r]  r   r{   r^  r«   r6  ÚseekÚanyÚwriteÚtruncate)r�   rH  ZsysctlÚlinesrq   r;   )r:   r<   Úedit_sysctl_confˆ  s    


rg  c             C   s.   x(| D ] }t j|ƒrtdj|ƒdd�‚qW d S )NzDDetected '{0}' kernel module loaded. Please unload that module firstzconflicting kernel module)rµ   )ÚCONFLICTING_MODULES_REÚmatchr   r«   )r›   Úmoduler;   r;   r<   Údetect_conflicting_modules¡  s
    

rk  c               C   s   dj tjƒ ƒS )Nz/lib/modules/{0}/extra/kcare.ko)r«   r   Zget_system_unamer;   r;   r;   r<   Úget_kcare_kmod_linkª  s    rl  c           
   C   sX   t dd�} tjtjƒ | tjƒ}tjj|ƒs.d S t	|dƒ�}|j
ƒ dd … dkS Q R X d S )NrÙ   )rŒ   Úrbé   s   ~Module signature appended~
iäÿÿÿ)r‘   r   r–   r®   r   r  r0   r1   r2   r4   rƒ   )rº   Z	kmod_fileZvfdr;   r;   r<   Úkmod_is_signed®  s    
ro  c                 s4   t jdƒ‰ ˆ d krd S ddg} t‡ fdd„| D ƒƒS )Nz
/proc/keysZ(12ff0613c0f80cfba3b2f8eba71ebc27c5a76170Z(69a6d9eed3f620d5c2e13a1d211c46510a5ad9f5c             3   s   | ]}|ˆ kV  qd S )Nr;   )r½   rÈ   )Úsystem_keysr;   r<   r$  ¿  s    z'kcare_certs_enrolled.<locals>.<genexpr>)r   Ztry_to_readrc  )Z
kcare_keysr;   )rp  r<   Úkcare_certs_enrolled·  s    
rq  c             K   sd   d| g}x&|j ƒ D ]\}}|jdj||ƒƒ qW tj|dd�\}}}|dkr`tdj| |ƒdd�‚d S )	Nz/sbin/insmodz{0}={1}T)rZ  r   zLUnable to load kmod ({0} {1}). Try to run with `--check-compatibility` flag.zkmod load error)rµ   )ÚitemsrH  r«   r   rÎ   r   )Zkmodr²   ÚcmdrÈ   re   r¸   r_  r;   r;   r<   Ú	load_kmodÂ  s    
rt  c               C   sT   t jƒ r,tƒ dkrtdƒ‚tƒ dkr,tdƒ‚t jƒ sDt jƒ sDt jƒ rPtddd�‚d S )NFz4Secure boot is enabled. Not supported by KernelCare.z<Secure boot is enabled. No KernelCare certificates enrolled.zWYou are running inside a container. Kernelcare should be executed on host side instead.zrunning in container)rµ   )r   Zis_secure_bootro  r   rq  Zinside_vz_containerZinside_lxc_containerZinside_docker_containerr;   r;   r;   r<   Úcheck_compatibilityÎ  s    

ru  c             C   sP   t jdƒ}t j|dgddd�d dk}|rL| d
krLtjdj| ƒƒ tjd	ƒ d S )NZmodinfoZkmodlveT)rZ  Úcatch_stderrr   Úfreerß   z3{0} patch type conflicts with kmodlve kernel moduler   )rw  rß   )r   Zfind_cmdrÎ   r   Úlogerrorr«   rS   r;  )rB   rs  Zhas_kmodlver;   r;   r<   Úcheck_patch_type_compatibilityÛ  s
    
ry  c             C   sP   t jddd| gƒ}g }x4|jdƒD ]&}|jƒ r"|jdƒ\}}}|j|ƒ q"W |S )Nz/sbin/modinfoz-FZparmra  ú:)r   rS  r@   r£   Ú	partitionrH  )Ú
kcare_linkÚstdoutZavailable_paramsr:   Z
param_namer_  r;   r;   r<   Úget_kmod_available_paramsç  s    r~  c               C   sL   t jr
dndt jrdndt jr$t jndtt jtƒr8t jndt jrDdnddœS )Nr   r   rK   )Úkpatch_debugZkmsg_outputZkcore_outputZ
kdumps_dirZenable_crashreporter)	r
   ÚKPATCH_DEBUGZKMSG_OUTPUTZKCORE_OUTPUTZKCORE_OUTPUT_SIZErU   Ú
KDUMPS_DIRrd   ZENABLE_CRASHREPORTERr;   r;   r;   r<   Úmake_kmod_new_paramsñ  s
    r‚  c              C   sH   t jr"tjjt jƒ r"tjt jƒ x tƒ jƒ D ]\} }t| |ƒ q.W d S )N)	r
   r�  r0   r1   ÚexistsÚmakedirsr‚  rr  Úupdate_kmod_param)ZparamÚvalr;   r;   r<   r  û  s    r  c             C   st   d}t jj|| ƒ}t jj|ƒs"d S y(t|dƒ�}|jt|ƒƒ W d Q R X W n$ tk
rn   tj	j
d| |ƒ Y nX d S )Nz/sys/module/kcare/parametersÚwz!failed to set %s kmod param to %s)r0   r1   rA   rƒ  r4   rd  rd   rn   r   r{   rP   )Zkmod_param_nameZparam_valueZparams_rootZ
param_pathr9   r;   r;   r<   r…    s    r…  c                s    t ƒ }tj| |tjƒ}ytj||ƒ W n tk
r>   |}Y nX tj	rbt
jjtj	ƒ rbt
jtj	ƒ tƒ }t|ƒ‰ t‡ fdd„|jƒ D ƒƒ}t|f|Ž tƒ  d S )Nc             3   s"   | ]\}}|ˆ kr||fV  qd S )Nr;   )r½   ÚkÚv)Úavailable_kmod_paramsr;   r<   r$  !  s    z"load_kcare_kmod.<locals>.<genexpr>)rl  r   r–   r   r  ÚshutilÚcopyrn   r
   r�  r0   r1   rƒ  r„  r‚  r~  Údictrr  rt  Úupdate_depmod)r—   rº   r|  Z
kcare_fileZkmod_paramsr;   )rŠ  r<   Úload_kcare_kmod  s    
r�  c             C   sX   dg}| d k	r|j d| gƒ tj|ddd�\}}}|rTtjdjdj|ƒ||ƒdd� d S )	Nz/sbin/depmodz-aT)rZ  rv  z%Running of `{0}` failed with {1}: {2}ú F)rþ   )Úextendr   rÎ   r   rx  r«   rA   )Úunamers  r¸   r_  Ústderrr;   r;   r<   rŽ  '  s    rŽ  c             C   s8   t jd| gdd�\}}}|dkr4tdj| |ƒdd�‚d S )Nz/sbin/rmmodT)rZ  r   zUnable to unload {0} kmod {1}zkmod unload error)rµ   )r   rÎ   r   r«   )Úmodnamer¸   r_  r;   r;   r<   Úunload_kmod3  s    r•  c             C   sT   g }xJdg| D ]<}t j| |dj|ƒƒ}tjj|ƒrt|ƒ |jdj|ƒƒ qW |S )NZvmlinuxzfixup_{0}.koz	fixup_{0})r   r–   r«   r0   r1   rƒ  rt  rH  )r—   rÝ   r›   ZloadedÚmodZmodpathr;   r;   r<   Úapply_fixups9  s    r—  c             C   sD   x>| D ]6}yt |ƒ W q tk
r:   tjjd| ƒ Y qX qW d S )Nz$Exception while unloading module %s.)r•  rn   r   r{   r|   )r7  r–  r;   r;   r<   Úremove_fixupsC  s
    
r˜  c             C   s’   | r
| }n6t jrt j}n(tƒ j|ƒr2d| t jdfS d| t jdfS ddddddœ}|jƒ }||krj|| }ntdj|| t jdƒd	d
�‚|| t jdfS )NZfreeze_conflictTr(  FZfreeze_noneZ
freeze_all)ZNONEZNOFREEZEZFULLZFREEZEZSMARTz3Unable to detect freezer style ({0}, {1}, {2}, {3})zfreezer style detection error)rµ   )r
   ZPATCH_METHODr=   ÚintersectionÚupperr   r«   )Úfreezerr›   r  Zpatch_method_mapr;   r;   r<   Úget_freezer_styleK  s&    
rœ  rK   c                sª  | ||dœ‰ t dˆ ƒ tjƒ }tjƒ }t|ƒ t||ƒ}tj| |tjƒ}t	| |ƒ dj
|tjtjƒ tj|ƒƒ}	d|k}
|
o„tj| |ƒ}|d k	}|o¢t|ƒo¢tj|	ƒ}ˆ j||dœƒ |rÆt dˆ ƒ d S |�rt dˆ ƒ t| ||ƒ}t dˆ ƒ t|ƒ t d	ˆ ƒ t|ƒ |�r"t d
ˆ ƒ tdƒ d}
|
�s<t dˆ ƒ t| |ƒ |�rHtƒ  t dˆ ƒ t|| ||	|ƒ tƒ  tjdj
|tjƒ ƒƒ tjƒ  t dˆ ƒ t ‡ fdd„tj!d� d S )N)r—   Zfuturer	  Ústartz{0}-{1}:{2};{3}r   )ZcurrentÚkmod_changedr‹   ZfxpÚunpatchZunfxpÚunloadFÚloadr?  z5Patch level {0} applied. Effective kernel version {1}Úwaitc                  s   t ˆ ƒS )N)r“   r;   )r’   r;   r<   Ú<lambda>©  s    zkcare_load.<locals>.<lambda>)rz   )"rŽ   r   rÛ   r�   rk  rœ  r–   r
   rE   r¢   r«   r,  r   rˆ   Zparse_unameZis_kmod_version_changedrV  Zkcare_update_effective_versionrI  r—  Úkpatch_ctl_unpatchr˜  r•  r�  rŠ   Úkpatch_ctl_patchr`  r   r  rÕ   r   Ztouch_status_gap_filer€   r„   )r—   rº   r	  r›  Ú
use_anchorrÝ   r›   r¹   r»   ÚdescriptionZkmod_loadedrž  Zpatch_loadedZ
same_patchr7  r;   )r’   r<   Ú
kcare_loadm  sR    











r¨  c              C   sD   g } t jd k	r"| jdtt jƒgƒ t jd k	r@| jdtt jƒgƒ | S )Nz-rz-t)r
   ZKPATCH_RETRIESr‘  rd   ZKPATCH_TIMEOUT_SEC)r¼   r;   r;   r<   Úkpatch_ctl_tuning_args¬  s    

r©  c       	      C   s˜   t jg}tj||tjƒ}tjj|ƒr2|j	d|gƒ |j	dd|gƒ |j	d|d gƒ |j	t
ƒ ƒ |j| ƒ tj|dd�\}}}|dkr”t|||| ƒ‚d S )Nz-br?  z-dz-mr   T)rZ  )r   rR  r   r–   r
   rG   r0   r1   rƒ  r‘  r©  rH  r   rÎ   r·   )	r»   r—   rº   r§  r¹   r¼   Zblacklist_filer¸   r_  r;   r;   r<   r¥  µ  s    
r¥  c             C   sd   t jtjdd| d gtƒ  ddd�\}}}|dkr`tjdj||ƒdd� td	j|t	| ƒƒd
d�‚d S )NrŸ  z-mr   T)rZ  rv  z4Error unpatching, kpatch_ctl stdout:
{0}
stderr:
{1}F)rþ   zError unpatching [{0}] {1}zunpatch error)rµ   )
r   rÎ   r   rR  r©  r   rx  r«   r   rd   )r¹   r¸   r}  r“  r;   r;   r<   r¤  Ã  s    r¤  c             C   s8   | |d< t tjƒ ƒ|d< tjtjjtjdƒt	|ƒƒ d S )NÚactionr=  zkcare.state)
r‚   ry   r   r‡   r0   r1   rA   r   r�   rd   )rª  r’   r;   r;   r<   rŽ   Ï  s    rŽ   c             C   sp   d}t jj|ƒsd S xVt j|ƒD ]H}t jj||ddƒ}t jj|ƒsDq t j|ƒ}|| kr t j|ƒ t|ƒ q W d S )Nz/usr/lib/modules/zweak-updateszkcare.ko)	r0   r1   ÚisdirÚlistdirrA   ÚislinkÚreadlinkÚunlinkrŽ  )Ú	kmod_linkZmodules_pathÚentryZsym_link_pathZtarget_pathr;   r;   r<   Úupdate_weak_modulesÕ  s    

r²  c       
   "   C   sü   t jƒ }tƒ }y|j|ƒ W n8 tk
rT } z|sDtdj|ƒdd�‚W Y d d }~X nX t jƒ }t| |ƒ}t	ƒ �„ d|krÊ|d k	}|r¬t
t jƒ ||ƒ}zt|ƒ W d t|ƒ X tjtjtƒdtd�tƒdƒ tƒ }	tjj|	ƒrætj|	ƒ t|	ƒ W d Q R X d S )Nz�Unable to retrieve fixups: '{0}'. The unloading of patches has been interrupted. To proceed without fixups, use the --force flag.zfixups retrieval error)rµ   r   r   )ÚcountÚdelay)r   rÛ   r"  r8  rn   r   r«   r�   rœ  rÏ   r—  r®   r¤  r˜  r   Zretryr   Z	check_excÚUNLOAD_RETRY_DELAYr•  rl  r0   r1   r2   r¯  r²  )
r›  ÚforcerÝ   ÚpfÚerrr›   r¹   Zneed_unpatchr7  r°  r;   r;   r<   Úkcare_unloadå  s2    


r¹  c             C   s8   t ƒ }| rt|ƒS |jdkr"|jS |jd k	r4tjƒ S d S )Nr   )rÑ   Ú_kcare_info_jsonr¸   r³   rÒ   r   rT  )rJ  r×   r;   r;   r<   rB    s    

rB  c             C   sR   d| j i}| jd k	r>|jtjtjƒ ƒƒ |jtj|jdƒƒƒ | j	|d< t
j|ƒS )NrÂ   zkpatch-descriptionzkpatch-state)r³   rÒ   rI  r   rÅ   r   rT  Zparse_patch_descriptionrå   rD  ri   rj   )r×   r8   r;   r;   r<   rº    s    


rº  c               @   s$   e Zd ZdZdZdZdZdd„ ZdS )r9  r   r   rr   rÚ   c             C   s"   || _ || _|| _|| _|| _d S )N)r¸   r³   Ú
remote_lvlrÒ   rD  )r±   r¸   r³   r»  rÒ   rD  r;   r;   r<   r°   ,  s
    zPLI.__init__N)rL   r¨   r©   r  r:  ÚPATCH_UNAVALIABLEÚPATCH_NOT_NEEDEDr°   r;   r;   r;   r<   r9  &  s
   r9  c              C   sü   t jƒ } y‚tdd�}| rJt| |ƒr6tjdd  }}}qxtjdd  }}}n.|dkrftjdd  }}}ntjd	d  }}}t|||| |ƒ}W nl tk
rö   tj	}t
jrÄd
jt
jtjƒ d tjƒ ƒ}ndjtjƒ d tjƒ t jƒ ƒ}t||d d dƒ}Y nX |S )NrÙ   )rŒ   z*Update available, run 'kcarectl --update'.ZappliedzThe latest patch is applied.r   z(This kernel doesn't require any patches.ZunsetzDNo patches applied, but some are available, run 'kcarectl --update'.zuInvalid sticky patch tag {0} for kernel ({1} {2}). Please check /etc/sysconfig/kcare/kcare.conf STICKY_PATCH settingszLNew kernel detected ({0} {1} {2}).
There are no updates for this kernel yet.Zunavailable)r   rÛ   r‘   rY  r9  r:  r  r½  rª   r¼  r
   ÚSTICKY_PATCHr«   r   r`   r¬   r­   r®   )Zcurrent_patch_levelZnew_patch_levelr¸   r³   rD  rÙ   r;   r;   r<   rÑ   4  s8    

rÑ   c       	      C   sæ   d}yXt jƒ }td|fd| fgƒ}tjƒ dj|ƒ }tj|ƒ}tj	tj
|jƒ ƒƒ}t|d ƒS  tk
rˆ } ztj||ƒ d
S d}~X nZ tk
r² } ztj||ƒ dS d}~X n0 tk
rà } ztjdj|ƒƒ dS d}~X nX dS )zÁ
    Request to tag server from ePortal. See KCARE-947 for more info

    :param tag: String used to tag the server
    :return: 0 on success, -1 on wrong server id, other values otherwise
    NÚ	server_idÚtagz/tag_server.plain?{0}r¸   rÚ   é   zInternal Error {0}é   éýÿÿÿéüÿÿÿéûÿÿÿ)r   Úget_serveridr#   r   rÃ   r«   r   rÄ   r   rÅ   rk   rƒ   r‚   r   r   rÇ   r    rn   rx  )	rÀ  ro   r¿  ZqueryrÉ   rÊ   rË   ZueZeer;   r;   r<   Ú
tag_serverf  s"    
rÇ  c              C   sÚ   t jdƒ} tjdj| ƒƒ t}tjƒ �ª}y:tj	| |j
ƒ}t jtj| ƒ|j
ƒ tj|j
|ƒ |j
}W n2 tk
r” } ztjdj|ƒƒ W Y d d }~X nX tjd|tjƒ gdd�\}}}|rÌtdj||ƒdd	�‚W d Q R X d S )
Nz	doctor.shz#Requesting doctor script from `{0}`z3Kcare doctor error: {0}. Fallback to the local one.ZbashT)rv  zScript failed with '{0}' {1}zdoctor script failed)rµ   )r   rm   r   Zlogdebugr«   ÚKCDOCTORÚtempfileZNamedTemporaryFiler   Zfetch_signaturer   Zsave_to_filer   rÄ   Zcheck_gpg_signaturern   rx  r   rÎ   r   Zget_patch_serverr   )Z
doctor_urlZdoctor_filenameZ
doctor_dstZ	signaturer¸  r¸   r_  r“  r;   r;   r<   Úkcdoctor�  s    


"rÊ  c              C   sB   t jdjtƒƒ} ytj| ƒ W n tk
r2   dS X tjdƒ dS )Nz{0}-new-versionFzwA new version of the KernelCare package is available. To continue to get kernel updates, please install the new versionT)	r   rm   r«   ÚEFFECTIVE_LATESTr   rÄ   r    r   r  )ro   r;   r;   r<   Úcheck_new_kc_version’  s    rÌ  c       
      C   s  t jƒ }t|ƒ}|tjkp*|tjko*|dk}yt| |ƒ}W n† tjk
r† } z.|dkrX‚ t	j
t|ƒƒ t	j
dƒ tj}W Y dd}~X n< tk
rÀ } z |rž‚ nt	jjdj|ƒƒ W Y dd}~X nX |tjkrÒ|}	n@|}	|dk�r|tjkrøt j|dƒ}	n|tjk�r
|}	ntdƒ‚|	S )aÒ  
    Get patch level to apply.
    :param reason: what was the source of request (update, info etc.)
    :param policy: REMOTE -- get latest patch_level from patchserver,
                   LOCAL -- use cached latest,
                   LOCAL_FIRST -- if cached level is None get latest from patchserver, use cache otherwise
    :param mode: constants.UPDATE_MODE_MANUAL, constants.UPDATE_MODE_AUTO or constants.UPDATE_MODE_SMART
    :return: patch_level string
    Nz#Using previously downloaded patcheszUnable to send data: {0}r   z9Unknown policy, choose one of: REMOTE, LOCAL, LOCAL_FIRST)r   r®   r¦   r   rG  ZPOLICY_LOCAL_FIRSTr  r   r  r   r  rd   ZPOLICY_LOCALrn   r{   r^  r«   r¤   r   )
rŒ   rF  r	  r—   Zcached_levelZconsider_remote_exZremote_levelrË   r  rº   r;   r;   r<   r‘   Ÿ  s2    
$


r‘   c             C   s–   | dkrd S | dkrdn| t _ttdd�t jƒr€tjt jd� t jdkrntjƒ rnt jpXt	}t
dddj|ƒfƒ tjdj| ƒƒ ntdj| ƒdd�‚d S )NÚedfr(  rK   Zprobe)rŒ   )r,  rw  rß   úfs.enforce_symlinksifownerúfs.symlinkown_gidzfs.enforce_symlinksifowner=1zfs.symlinkown_gid={0}z'{0}' patch type selectedz/'{0}' patch type is unavailable for your kernelzpatch type unavailable)rµ   )rw  rß   )rÎ  rÏ  )r
   r,  r  r  r   Úupdate_configr   Z	is_cpanelZ	FORCE_GIDÚ
CPANEL_GIDrg  r«   r   r  r   )rB   Zgidr;   r;   r<   Úupdate_patch_typeÍ  s    
rÒ  Zkernelc       	   $   C   sh  t tjƒ |tjkrtƒ  ytd||d�}W nR tk
r~ } z6|tjtj	fkrltj
rlt|ƒ}tjj|ƒ dS ‚ W Y dd}~X nX tjƒ }|tjkržtj rždS t|ƒ}|jƒ  t||d�sÈtjdƒ |S y(tjtjddd� tjtjdd	d� W n" tk
�r   tjjd
ƒ Y nX tjƒ }tƒ �( |j|ƒ t|||| |tj	kd� W dQ R X tj|ƒ t ||ƒ |S )aU  
    :param mode: constants.UPDATE_MODE_MANUAL, constants.UPDATE_MODE_AUTO or constants.UPDATE_MODE_SMART
    :param policy: REMOTE -- download latest and patches from patchserver,
                   LOCAL -- use cached files,
                   LOCAL_FIRST -- download latest and patches if cached level is None, use cache in other cases
    :param freezer: freezer mode
    :return: patch level in effect for the running kernel or None if the update
             was not performed at all. Zero level means the patchserver has no
             patches for this kernel, so nothing was applied.
    rI  )rŒ   rF  r	  N)rW  rX  z%No updates are needed for this kernelrÚ   zkcore*.dump)Zkeep_nZpatternz	kmsg*.logz#Error during crash reporter cleanup)r¦  )!ry  r
   r,  r   rG  rÌ  r‘   rª   ÚUPDATE_MODE_AUTOÚUPDATE_MODE_SMARTrÜ   rd   r   r{   r^  r   rÛ   rÔ   r"  r0  rY  r  r   r•   r�  rn   r|   r®   rÏ   r8  r¨  Zdump_kernel_patch_levelr˜   )	r›  r	  rF  rº   rË   r³   rÝ   r·  r—   r;   r;   r<   Ú	do_updateä  s>    



"

rÕ  c             C   s”   t ttjƒttjptjƒttjp$tjƒfƒ}|dkr@tddd�‚tjrLtjS | t	j
krptjp`tj}tjpltj}ntj}tj}|r„|S |r�d| S d S )Nr   z‰Invalid configuration: conflicting settings STICKY_PATCH, [AUTO_]UPDATE_DELAY or [AUTO_]STICKY_PATCHSET. There should be only one of themzconflicting sticky settings)rµ   zrelease-)rA  Úboolr
   r¾  ZUPDATE_DELAYZAUTO_UPDATE_DELAYZSTICKY_PATCHSETZAUTO_STICKY_PATCHSETr   r   ÚUPDATE_MODE_MANUAL)r	  r³  r´  Zpatchsetr;   r;   r<   Ú
get_sticky(  s&    
rØ  c             C   s   | d | S )Nr>   r;   )rž   r�   r;   r;   r<   Ú	_stickyfyH  s    rÙ  c             C   s   t |ƒ}|s| S |dkr"t|| ƒS tjƒ }|sDtjjdƒ tjdƒ yt	j
tjƒ dj|ƒ ƒ}W n: tk
rš } ztj||jƒ tjdƒ W Y dd}~X nX tjtj|jƒ ƒƒ}t|d ƒ}|dkrÒt|d	 | ƒS |d
krÞ| S |dk� rþtjjdƒ tjdƒ tjjd|d  ƒ tjdƒ dS )z„
    Used to add sticky prefix to satisfy KCARE-953
    :param file: name of the file to stickify
    :return: stickified file.
    ÚKEYzHPatch set to STICKY_PATCH=KEY, but server is not registered with the keyrÁ  z!/sticky_patch.plain?server_id={0}rÂ  Nr¸   r   rž   r   rr   zEServer ID is not recognized. Please check if the server is registeredzError: rÂ   rÚ   rÄ  rÅ  r?   rÃ  )rØ  rÙ  r   rÆ  r   r{   rÙ   rS   r;  r   rÄ   r   rÃ   r«   r   rÇ   ro   r   rÅ   rk   rƒ   r‚   )Úfiler	  Úsr¿  rÉ   rË   rÊ   r¸   r;   r;   r<   r  L  s2    



r  c       
      C   sö   g }| sdS | j dƒ}|d }|dd… }|jdƒ}||krLtdt| ƒ ƒ‚|s`| jƒ |jƒ kS |dkrt|jdƒ n>|jd	ƒsˆ|jd	ƒrš|jtj|ƒƒ n|jtj|ƒj	d
dƒƒ x|D ]}|jtj|ƒƒ q¸W tj
ddj|ƒ d tjƒ}	|	j|ƒS )zhMatching according to RFC 6125, section 6.4.3

    http://tools.ietf.org/html/rfc6125#section-6.4.3
    Fr>   r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)r@   r³  r§   ÚreprÚlowerrH  rà   ÚreÚescapeÚreplaceÚcompilerA   Z
IGNORECASEri  )
ZdnÚhostnameZmax_wildcardsZpatsÚpiecesZleftmostZ	remainderZ	wildcardsZfragZpatr;   r;   r<   Ú_dnsname_matchx  s(    


ræ  c       	      C   s
  g }xBt | jƒ ƒD ]2}| j|ƒ}|jƒ dkrdd„ t|ƒjdƒD ƒ}qW | sTtdƒ‚g }x0|D ](\}}|dkr^t||ƒr|d S |j|ƒ q^W |s°| j	ƒ j
}t||ƒr¦d S |j|ƒ t|ƒdkrÚtdj|d	jtt|ƒƒƒƒ‚n,t|ƒdk� rþtd
j||d ƒƒ‚ntdƒ‚d S )NZsubjectAltNamec             S   s   g | ]}|j ƒ jd dƒ‘qS )rz  r   )r£   r@   )r½   Úitr;   r;   r<   r¿   °  s    z"match_hostname.<locals>.<listcomp>ú,ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDZDNSr   z(hostname {0} doesn't match either of {1}z, zhostname {0} doesn't match {1}r   z=no appropriate commonName or subjectAltName fields were found)ÚrangeZget_extension_countZget_extensionZget_short_namerd   r@   r†   ræ  rH  Zget_subjectZ
commonNamer  r§   r«   rA   ÚmaprÞ  )	Zcerträ  Zsanr¾   rË   ZdnsnamesrÈ   re   Zcnr;   r;   r<   rö   «  s0    




rö   c           	   C   s@  t ddd�} | jdddd� | jdd	d
dd� | jdddd� | jddddd� | jdddd� | jdddd� | jdddd� | jdddd� | jdddd� | jdddd� | jdd dd� | jd!d"dd� | jd#d$dd� | jd%d&dd� | jd'd(d)d� | jd*d+dd� | jd,d-dd� | jd.d/dd� | jd0d1dd� | jd2d3dd� | jd4d5d6d� | jd7d8d9d� | jd:d;dd� | jd<d=d)d� | jd>d?dd� | jd@dAdd� | jdBdCdd� | jdDdEddFdG� | jdHdIdd� | jdJdKdd� | jdLdMdd� | jdNdOdd� | jdPdQdd� | jdRdSdd� | jdTdUdd� | jdVdWdd� | jdXdYdd� | jdZd[d\td d]d^� | jd_d`dd� | jdadbdd� | jƒ }|jdcddd\d� |jdedfdd� |jdgdhdd� | jdidjd\d d]dk� | jdldmdndd]do� | jdpdqdr� | jdsdtdd� | jdudvdwdxdy� tj�s| jdzd{d|d}d]d~� | jdd€d|d}d�d~� | jd‚dƒdd� | jd„d…d†dd� | jd‡dˆd‰dd� | jdŠddd� | jd‹dŒd�dd� | jdŽd�d�dd� | jd‘d’d“d”d� | jd•d–d—dd˜d™� | jdšd˜dd� | jd›dœdd� | jd�džd6dŸd\d d]d � | jƒ }tjƒ  tj�sFt j	d¡g7  _	|j
d k	�rzttd |j
jd¢ƒƒƒjtj	ƒ�rvd£S d¤S |j�sŠ|j�r¦tj�rœtjt_ntjt_n|j�r¶tjt_|j�sÞtjƒ d£k�rÞtd¥tjd¦� d¤S tj}|j�rôtj }n|j�rtj!}t"j#|ƒ tj$�stj%ƒ  tj&�r�|j'�p0|j �r�x2t(tj&j)ƒ ƒD ] \}}t"j*d§j+|tj,|ƒƒ �qFW t"j*d¨ƒ |j-�rŒt-j.t/|j0d©� d¤S |j1�r t2j3ƒ  |j4�râ|j4d£k�rÐt5|j4ƒt_6tj7tj6dª� nd t_6tj7ddª� |j8d k	�rtj7|j8d«� |j8t_9|j:�rd]t_;|j<�r d]t_=|j>�r.d�t_?|j@�r<t@ƒ  |jA�rRtBjCd¬tDƒ n8|jE�rŠtjFd­k�rŠtjGd­k�rvdntjG�p€d®|_Hd�|_I|jJ�rš|jJt_K|jL�r´tBjCd¯tDƒ d°t_KtjKjMd±ƒt_KtjK�ròtjKtNk�ròt"jOjPd²j+tjKd³jQtNƒƒƒ |jR�rd�t_Sd´|jR t_T|jH�rtU|jHƒ tjFd­k�rLtVƒ t_FtBjCdµj+tjF�pDd®ƒtDƒ |jW�rlt2jXtYjW|jZd¶�ƒ d S |j[�r˜t[j[d·d�d�d¸�}t2jXtZj\|ƒƒ d S t]tjFƒ |j-�r¾t-j.t/|j0d©� d S |j^�rNt_j`t[j[d·d�d�d¸�ƒ}d¹j+|jaƒ}|jb�rüt2jX|ƒ nRt_jc|ƒ}	|	�rt"jddºj+|	ƒƒ nt"jed»d�d¼� |jf�r@t2jX|ƒ n|�rN|jgƒ  |jh�rt|jZ�rjthd½d¾� nthƒ  d S |ji�rŒtj7d¿dÀ� d S |jj�r¤tj7dÁdÀ� d S |j'�r¼tjk|j'ƒ d S |jl�rÎtm|jlƒS |jn�rÞtojnƒ  |jp�	rtjFdÂk�rþtj7dÃdÄ� tojp|jp|jqƒS |jr�	r,tojrƒ d£k�	r(d£S d¤S |jsd k	�	rBtt|jsƒS |ju�	rVt2jXtjvƒ tw|d|d ƒd k	�	rxtxjy|jzƒ d£S tj�
sþ|j{�	r’dÅ|j{ini }
|j|�	r¦txj}ƒ S |j~�	rÊtxjf |
Žd k	�	rÊt"jddÆƒ |j€�	rêtxjf dÇtj�i|
—Ž n|j‚�
rtxjƒƒ  t"jddÈƒ |j„�
rtxj…ƒ  t"jddÉƒ |j†�
r4t2jXtxj‡ƒ ƒ |jˆ�
rJt2jXtxj‰ƒ ƒ |jŠ�
rntxj‹ƒ �
rnt2jXtxjŒ|jŠƒƒ |j�d k	�
rÞ|j�dk�
r tjŽ�
pœt�txj�ƒ j‘ƒ ƒ}ndÊdË„ |j�jd¢ƒD ƒ}txjf dÌt(|ƒi|
—Žd k	�
rÞt"jddÆƒ |j’�
rþtxjf tj�d dÍœ|
—Ž |j“�rt2jXt”|jZd¶�ƒ d}|j•�r4tBjCdÎtDƒ dÏ}|j–�rB|j–}|j—�r\t˜|tj™tjšdÐ� |jI�r~t˜|tj›dÑ��r~t"jddÒƒ |j�r”t2jXtœj�ƒ ƒ |jž�r´tŸ||j dÓ� t"jddÔƒ |j�râd]t_¡t¢j£t¤j¥d£dÕƒƒ t˜|tj�dÑ� |j¦�röt¦|jZd¶� |j§�rt¨ƒ S |j©�rtª|jZd¶� |j«�r&t¬ƒ  t­tj®ƒd¤k�r<t¯ƒ  d S )ÖNZkcarectlz)Manage KernelCare patches for your kernel)Zprogr§  z--debugrK   Z
store_true)Úhelprª  z-iz--infoz]Display information about KernelCare. Use with --json parameter to get result in JSON format.z
--app-infozcDisplay information about KernelCare agent. Use with --json parameter to get result in JSON format.z-uz--updatez<Download latest patches and apply them to the current kernelz--unloadzUnload patchesz--smart-updatez,Patch kernel based on UPDATE POLICY settingsz--auto-updatez-Check if update is available, if so -- updatez--localzNUpdate from a server local directory; accepts a path where patches are locatedÚPATH)rë  Úmetavarz--patch-infoz"Return the list of applied patchesz	--freezerz)Freezer type: full (default), smart, noner›  z
--nofreezez/[deprecated] Don't freeze tasks before patchingz--unamezReturn safe kernel versionz--license-infozReturn current license infoz--statuszReturn status of updatesz
--registerzRegister using KernelCare KeyrÚ  z--register-autoretryz=Retry registering indefinitely if failed on the first attemptz--unregisterz7Unregister from KernelCare (for key-based servers only)z--checkzCheck if new update availablez--latest-patch-infoziReturn patch info for the latest available patch. Use with --json parameter to get result in JSON format.z--testz&[deprecated] Use --prefix=test insteadz--tagz7Tag server with custom metadata, for ePortal users onlyZTAGz--prefixzpPatch source prefix used to test different builds by downloading builds from different locations based on prefixrœ   z--nosignaturezDo not check signaturez--set-monitoring-keyzPSet monitoring key for IP based licenses. 16 to 32 characters, alphanumeric onlyz--doctorz=Submits a vitals report to TuxCare for analysis and bug-fixesz
--fallbackzNWith --doctor, force the legacy kcdoctor.sh flow instead of the v2 upload pathz--kernel-anomaly-reportzESubmits a kernel anomaly report to TuxCare for analysis and bug-fixesz	--no-sendzSkip sending artifactsÚ	save_only)rë  rª  Údestz--keep-localz:Don't delete generated kernel anomaly report after sendingz--enable-auto-updatezEnable auto updatesz--disable-auto-updatezDisable auto updatesz--plugin-infozProvides the information shown in control panel plugins for KernelCare. Use with --json parameter to get result in JSON format.z--server-infoz3Provides information about the host in JSON format.z--jsonzoReturn '--plugin-info', '--latest-patch-info', '--patch-info', '--app-info' and '--info' results in JSON formatz	--versionz(Return the current version of KernelCarez--kpatch-debugzEnable the debug modez--no-check-certz2Disable the patch server SSL certificates checkingz--set-patch-levelzBSet patch level to be applied. To select latest patch level set -1ZstoreF)rë  rª  r^   r(  Úrequiredz--check-compatibilityzCheck compatibility.z--clear-cachezClear all cached filesz--set-patch-typez@Set patch type feed. To select default feed use 'default' optionz--edf-enabledz"Enable exploit detection frameworkz--edf-disabledz#Disable exploit detection frameworkz--set-sticky-patchzjSet patch to stick to date in DDMMYY format, or retrieve it from KEY if set to KEY. Leave empty to unstick)rë  rª  r(  rð  z-qz--quietz=Suppress messages, provide only errors and warnings to stderr)rë  rª  rð  z--has-flagszCheck agent features)rë  z--forcez-Force action and ignore several restristions.z--set-configzChange configuration optionrH  z	KEY=VALUE)rë  rª  rí  z--disable-libcarezDisable libcare servicesÚenable_libcareZstore_const)rë  rï  rª  Úconstz--enable-libcarezEnable libcare servicesTz--lib-updatezIDownload latest patches and apply them to the current userspace librariesz--lib-unloadz--userspace-unloadzUnload userspace patchesz--lib-repluginz--userspace-repluginzReload libcare-server pluginz--lib-auto-updatez
--lib-infoz--userspace-infoz&Display information about KernelCare+.z--lib-patch-infoz--userspace-patch-infoz,Return the list of applied userspace patchesz--lib-versionz--userspace-versionzReturn safe package versionZPACKAGENAMEz--userspace-updateÚUSERSPACE_PATCHESrý   zODownload latest patches and apply them to the corresponding userspace processes)rí  Znargsrò  rë  z--userspace-auto-updatez--userspace-statusz"Return status of userspace updatesz	--lib-tagz--userspace-tagzÌApply userspace patches for a specific tag (DDMMYY, YYYY-MM-DD, Nd, Nh, release-<NAME>) into an isolated cache, leaving the default storage untouched. Use together with --lib-update or --userspace-update.)rí  rë  rª  r(  rð  zlibcare-enabledrè  r   r   zPlease run as root)rÛ  z{0}: unusable value in {1}: {2}zVSet a valid value with `kcarectl --set-config OPTION=VALUE`, or `OPTION=` to unset it.)Zforce_fallback)r  )r¾  zTFlag --edf-enabled has been deprecated and will be not available in future releases.rÍ  r(  zMFlag --test has been deprecated and will be not available in future releases.r(   ú/z(Prefix `{0}` is not in expected one {1}.r�  zfile:z+edf patches are deprecated. Fallback to {0})rJ  r  )rŒ   rú   rû   z)Kernel anomaly report file generated: {0}z0Kernel anomaly report uploaded successfully: {0}z$Failed to send kernel anomaly report)rþ   ri   )rÖ   ZYES)rÔ   ZNOrw  rß   )r,  rÀ  zUserspace patches are applied.r	  zUserspace patches are unloaded.zLibcare plugin reloaded.c             S   s   g | ]}|j ƒ jƒ ‘qS r;   )r£   rß  )r½   Zptchr;   r;   r<   r¿   L  s    zmain.<locals>.<listcomp>Úlimit)r	  rõ  zQFlag --nofreeze has been deprecated and will be not available in future releases.r™   )r	  rF  )r	  zKernel is safe)r¶  z=KernelCare protection disabled. Your kernel might not be safeé<   )°r   Zadd_argumentr‚   Zadd_mutually_exclusive_groupr
   ZLIBCARE_DISABLEDZ
parse_argsr   Zset_settings_from_config_fileZFLAGSZ	has_flagsr/   Úfilterr@   ÚissubsetÚquietZauto_updateZSILENCE_ERRORSr   ZPRINT_CRITICALZPRINT_LEVELZPRINT_ERRORr  ZPRINT_DEBUGr’  r0   ÚgetuidÚprintrS   r“  ÚloggingZINFOZWARNINGÚDEBUGr   Zinitialize_loggingZIGNORE_FEATURE_FLAGSZset_feature_flags_from_cacheZINVALID_CONFIG_OPTIONSZ
set_configÚsortedrr  rx  r«   ZCONFIGr   Zsend_doctor_reportrÊ  Zfallbackr˜   r   Zclear_all_cacheZset_patch_levelrd   r  rÐ  Zset_sticky_patchr¾  Znosignaturer  Zno_check_certrô   r  r€  ru  Zedf_enabledÚwarningsÚwarnÚDeprecationWarningZedf_disabledr,  ZPREV_PATCH_TYPEZset_patch_typerI  rž   rœ   r(   r£   ÚEXPECTED_PREFIXr{   r^  rA   Zlocalrh   ZPATCH_SERVERrÒ  râ   Zapp_inforÆ   r   ri   r   rj   rJ   Zkernel_anomaly_reportr   r  Zarchive_pathrî  r  r  r  Z
keep_localr  rØ   Zenable_auto_updateZdisable_auto_updateZupdate_config_from_argsZset_monitoring_keyrÌ   Z
unregisterr   ÚregisterZregister_autoretryrÓ   rÀ  rÇ  rá   ra   rc   r   Zset_libcare_statusrñ  Zlib_tagZuserspace_statusZget_userspace_update_statusZ
lib_updateZdo_userspace_updateZlib_auto_updaterÓ  Z
lib_unloadZlibcare_unloadZlib_repluginZlibcare_repluginZlib_inforC  Zlib_patch_infoZlibcare_patch_infoZlib_versionZlibcare_server_startedZlibcare_versionZuserspace_updateró  ÚlistZget_userspace_mapÚkeysZuserspace_auto_updaterÙ   rB  Znofreezer›  Zsmart_updaterÕ  rÔ  ZUPDATE_POLICYr×  r   rÕ   r   r¹  r¶  ZCHECK_CLN_LICENSE_STATUSry   rz   ÚrandomZuniformrK  rµ   rÞ   Zlatest_patch_inforN  Zcheckr<  r  ÚargvrE  )ZparserZexclusive_groupr¼   rº   r   re   rÙ   r
  Zlocal_path_messager  Z
lib_tag_kwrõ  r›  r;   r;   r<   ÚmainÔ  s€    














r  )r%   r&   r'   r(   )r)   r*   )N)N)F)F)N)rK   F)rK   F)r   )­Z
__future__r   rl   ri   rü  r0   r¬   r  rà  r‹  ræ   ZsslrS   rÉ  ry   rR   rÿ  Zargparser   Ú
contextlibr   r   rK   r   r   r	   r
   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   Zpy23r   r    r!   r"   r#   rÑ  rË  r  r3   rÈ  r  r[  rµ  rã  ZDOTALLr2  rh  r1   r«  ÚinsertÚfilterwarningsr  r{   ZsetLevelrý  r=   rD   rJ   rg   rp   r€   rŠ   r“   r˜   rŸ   r¢   r¦   r†   r§   rª   r·   r…   rÌ   rÏ   rØ   rÞ   râ   rä   ré   rñ   rò   rc   Zdistutils.versionZ	distutilsZOpenSSL.SSLró   rá   ZStrictVersionZ__version__ÚImportErrorrê   ZHTTPSConnectionZPureHTTPSConnectionÚobjectrë   rð   r  r×  r  r  r!  r"  r<  rE  rN  r@  rP  rK  rV  rY  r`  rg  rk  rl  ro  rq  rt  ru  ry  r~  r‚  r  r…  r�  rŽ  r•  r—  r˜  rœ  r¨  r©  r¥  r¤  rŽ   r²  Zlog_all_parent_processesr¹  rB  rº  r9  rÑ   rÇ  rÊ  rÌ  rG  r‘   rÒ  Ztrack_update_statusrÕ  rØ  rÙ  r  ræ  rö   r  r;   r;   r;   r<   Ú<module>   s  \ 

	
&	

4
-!	b	+
 
		



"
?	(2.B ,
3)