
Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­
<!DOCTYPE html>
<html>
3
Ö;j*: ã               @   s  d dl mZ d dlZd dlZd dlZd dlZd dlZd dlZd dlZd dl	Z	d dl
Z
d dlZd dlZd dlZd dlZd dlZd dlZd dlmZ d dlmZ d dlmZ ddlmZmZmZmZmZmZmZmZmZm Z m!Z!m"Z"m#Z#m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+ ddlm,Z,m-Z-m.Z. dd	l/m0Z0m1Z1m2Z2m3Z3m4Z4 d
Z5dZ6d¿Z7dZ8dZ9dÀZ:dZ;dZ<ej=dej>ƒZ?ej=dƒZ@ejAjBdƒ�rˆejAjCd dƒ ejDdeEd� e$jFjGejHƒ dd„ ZIdd„ ZJdd „ ZKd!d"„ ZLd#d$„ ZMdÁd%d&„ZNd'd(„ ZOd)d*„ ZPd+d,„ ZQd-d.„ ZRd/d0„ ZSd1d2„ ZTG d3d4„ d4eUƒZVG d5d6„ d6e,ƒZWG d7d8„ d8e,ƒZXG d9d:„ d:e,ƒZYd;d<„ ZZed=d>„ ƒZ[dÂd?d@„Z\dAdB„ Z]dCdD„ Z^i Z_dEdF„ Z`e`e2ja_becedGdƒ�sy8d dldZed dlfZgeejhjiegjjƒeejhjidHƒk �rÌekdIƒ‚W n ekk
�rä   Y n8X dJdK„ Zle2jmZnG dLdM„ dMeoƒZpG dNdO„ dOe2jmƒZqeqe2_mdPdQ„ ZrejsfdRdS„ZtdTdU„ ZudVdW„ ZvG dXdY„ dYeoƒZwdZd[„ Zxd\d]„ ZydÃd_d`„Zzdadb„ Z{dcdd„ Z|dÄdedf„Z}dgdh„ Z~didj„ Zdkdl„ Z€dmdn„ Z�dodp„ Z‚dqdr„ Zƒdsdt„ Z„dudv„ Z…dwdx„ Z†dydz„ Z‡d{d|„ Zˆd}d~„ Z‰dd€„ ZŠd�d‚„ Z‹dƒd„„ ZŒd…d†„ Z�dÅd‡dˆ„ZŽd‰dŠ„ Z�d‹dŒ„ Z�d�dŽ„ Z‘d�d�„ Z’dÆd’d“„Z“d”d•„ Z”d–d—„ Z•d˜d™„ Z–dšd›„ Z—e&j˜dÇdœd�„ƒZ™dždŸ„ Zšd d¡„ Z›G d¢d£„ d£ƒZœd¤d¥„ Z�d¦d§„ Zžd¨d©„ ZŸdªd«„ Z ej¡ejsfd¬d­„Z¢d®d¯„ Z£e&j˜e*j¤d°ƒej¡fd±d²„ƒƒZ¥d³d´„ Z¦dµd¶„ Z§d·d¸„ Z¨dÈd¹dº„Z©d»d¼„ Zªd½d¾„ Z«dS )Éé    )Úprint_functionN)ÚArgumentParser)Úcontextmanager)Údatetimeé   )ÚanomalyÚauthÚcapabilitiesÚconfigÚconfig_handlersÚ	constantsÚdoctorÚerrorsÚfetchÚ
http_utilsÚipv6_supportÚkcareÚlibcareÚ	log_utilsÚplatform_utilsÚprocess_utilsÚselinuxÚserver_infoÚserveridÚupdate_utilsÚutils)Ú
KcareErrorÚNotFoundÚSafeExceptionWrapper)Ú	HTTPErrorÚURLErrorÚhttplibÚjson_loads_nstrÚ	urlencodeéc   Zv3Ú12hÚ24hÚ48hÚtestz./etc/sysconfig/kcare/freezer.modules.blacklistz/usr/libexec/kcare/kcdoctor.shú	latest.v3ú	latest.v2z /etc/sysconfig/kcare/sysctl.confé
   z$==BLACKLIST==
(.*)==END BLACKLIST==
z'(kpatch.*|ksplice.*|kpatch_livepatch.*)z/usr/libexec/kcare/pythonÚignore)Úcategoryc              C   sD   t ƒ } tjjtƒr@ttdƒ}x|D ]}| j|jƒ ƒ q"W |jƒ  | S )NÚr)	ÚsetÚosÚpathÚisfileÚFREEZER_BLACKLISTÚopenÚaddÚrstripÚclose)ÚresultÚfÚline© r;   ú./usr/libexec/kcare/python/kcarectl/__init__.pyÚget_freezer_blacklistS   s    

r=   c             C   sB   |j dƒ}| r(dj|d | |d gƒ}ndj|d |d gƒ}|S )NÚ.r   r   éÿÿÿÿr?   )ÚsplitÚjoin)ÚptypeÚfilenameZ
name_partsr;   r;   r<   Ú_apply_ptype]   s
    
rD   c             C   sJ   t | tjƒt_t | tjƒt_t | tjƒt_t | tjƒt_t | tjƒt_d S )N)rD   r
   Ú	PATCH_BINÚ
PATCH_INFOÚBLACKLIST_FILEÚFIXUPS_FILEÚ
PATCH_DONE)rB   r;   r;   r<   Úapply_ptypef   s
    rJ   c              C   s   t jƒ \} }}d}t|tƒrbt|tƒ rbyd|jtj|jƒ|jf }W q² t	t
fk
r^   Y q²X nPt|tt
tfƒrˆt|tƒ rˆd| }n*t|tƒr²|jp t|jƒ} |jp°d|j }tjƒ }tjtjƒ |d |d t| dt| ƒƒ|djtj|dƒƒt|ddƒd	œS )
NÚ z[Errno %i] %s: '%s'z%sr   r   Ú__name__éd   Úattempts)Zagent_versionZpython_versionÚdistroZdistro_versionÚerrorÚdetailsÚ	tracebackrN   )ÚsysÚexc_infoÚ
isinstanceÚOSErrorr    Úerrnor0   ÚstrerrorrC   ÚAttributeErrorÚ	TypeErrorÚKeyErrorÚIOErrorr   ÚetypeÚtypeÚinnerrQ   r   Ú
get_distror   ÚVERSIONÚget_python_versionÚgetattrÚstrrA   rR   Z	format_tb)r]   ÚvalueÚtbZdetails_sanitizedrO   r;   r;   r<   Ú format_exception_without_detailsn   s*    

rg   c              C   sv   t jr
d S tjtƒ ƒ} tjtjtj	| ƒƒƒ}tj
dƒd | }tj|tjƒ ƒ}ytj|ƒ W n tk
rp   Y nX d S )Nz/api/kcarectl-tracez?trace=)r
   ÚUPDATE_FROM_LOCALÚjsonÚdumpsrg   r   ÚnstrÚbase64Zurlsafe_b64encodeZbstrÚget_patch_server_urlr   Zhttp_requestr   Zget_http_auth_stringZurlopen_baseÚ	Exception)ZtraceZencoded_traceÚurlZrequestr;   r;   r<   Úsend_excŠ   s    rp   c             C   sÖ   t jƒ }|dkr t j|dƒ dS t jƒ  t jƒ }|dkrBt jdƒ t jdƒ ttjdƒ�&}t j	|j
ƒ dƒ t j	|j
ƒ dƒ W dQ R X |r’tj|ƒ y
| ƒ  W n* tk
rÆ   tjjdƒ t jdƒ Y nX t jdƒ dS )zš
    Run func in a fork in an own process group
    (will stay alive after kcarectl process death).
    :param func: function to execute
    :return:
    r   NÚar   é   zWait exception)r0   ÚforkÚwaitpidÚsetsidÚ_exitr7   r4   r   ZLOG_FILEÚdup2ÚfilenoÚtimeÚsleeprn   r   ÚkcarelogÚ	exception)Úfuncrz   ÚpidÚfdr;   r;   r<   Ú
nohup_forkœ   s(    



r€   c              C   sˆ   t jjtjdƒ} t jj| ƒrtt| dƒ�H}y,t|jƒ ƒ}|t	j
 tjƒ krRt|| ƒ‚W n tk
rh   Y nX W dQ R X tj| tjƒ ƒ dS )a  Check the fact that there was a failed patching attempt.
    If anchor file not exists we should create an anchor with
    timestamp and schedule its deletion at $timeout.

    If anchor exists and its timestamp more than $timeout from now
    we should raise an error.
    z.kcareprev.lockr.   N)r0   r1   rA   r   ÚPATCH_CACHEr2   r4   ÚintÚreadr
   ÚSUCCESS_TIMEOUTry   ÚPreviousPatchFailedExceptionÚ
ValueErrorr   Úatomic_writeÚtimestamp_str)Zanchor_filepathZafileÚ	timestampr;   r;   r<   Útouch_anchorÂ   s    rŠ   c             C   sx   yt jt jjtjdƒƒ W n tk
r.   Y nX td| ƒ tj	j
ƒ  ytdd� W n  tk
rr   tjjdƒ Y nX dS )zÀ
    See touch_anchor() for detailed explanation of anchor mechanics.
    See KPT-730 for details about action registration.
    :param state_data: dict with current level, kernel_id etc.
    z.kcareprev.lockÚdone)ÚreasonzCannot send update info!N)r0   Úremover1   rA   r   r�   rV   Úregister_actionr   Úget_loaded_modulesÚclearÚget_latest_patch_levelrn   r   r{   r|   )Ú
state_datar;   r;   r<   Úcommit_updateÙ   s    

r“   c             C   s(   t jtjjtjdƒtj| |dƒd� d S )NÚpatchesrK   )Zexclude_path)	r   Úclean_directoryr0   r1   rA   r   r�   r   Úget_cache_path)ÚkhashZplevelr;   r;   r<   Úclear_cacheî   s    r˜   c             C   s>   t jpd}dj|| gƒ}tjd|f}|r2||f7 }tjj|Ž S )NÚnoneú-Úmodules)r
   ÚPREFIXrA   r   r�   r0   r1   )r—   ÚfnameÚprefixZ
module_dirr8   r;   r;   r<   Úget_current_level_pathò   s    

rŸ   c             C   s   t jt| dƒt|ƒdd� d S )NÚlatestT)Z
ensure_dir)r   r‡   rŸ   rd   )r—   Úpatch_levelr;   r;   r<   Úsave_cache_latestû   s    r¢   c             C   sV   t | dƒ}tjj|ƒrRy"tt|dƒjƒ jƒ ƒ}tj	| |ƒS  t
tfk
rP   Y nX d S )Nr    r.   )rŸ   r0   r1   r2   r‚   r4   rƒ   Ústripr   ÚLegacyKernelPatchLevelr†   rZ   )r—   Zpath_with_latestÚplr;   r;   r<   Úget_cache_latestÿ   s    
r¦   c               @   s   e Zd ZdS )ÚCertificateErrorN)rL   Ú
__module__Ú__qualname__r;   r;   r;   r<   r§     s   r§   c                   s    e Zd ZdZ‡ fdd„Z‡  ZS )ÚUnknownKernelExceptionzunknown kernelc                s6   dj tjƒ d tjƒ tjƒ ƒ}tt| ƒj	|f|Ž d S )NzLNew kernel detected ({0} {1} {2}).
There are no updates for this kernel yet.r   )
Úformatr   r`   ÚplatformÚreleaser   Úget_kernel_hashÚsuperrª   Ú__init__)ÚselfÚkwargsÚmsg)Ú	__class__r;   r<   r°     s    zUnknownKernelException.__init__)rL   r¨   r©   Ústatusr°   Ú__classcell__r;   r;   )r´   r<   rª     s   rª   c                   s(   e Zd ZdZ‡ fdd„Zdd„ Z‡  ZS )ÚApplyPatchErrorzpatch apply errorc                sF   t t| ƒj||Ž || _|| _|| _|| _tjƒ d | _	t
jƒ | _d S )Nr   )r¯   r·   r°   ÚcodeÚfreezer_styleÚlevelÚ
patch_filer   r`   rO   r¬   r­   )r±   r¸   r¹   rº   r»   Úargsr²   )r´   r;   r<   r°     s    zApplyPatchError.__init__c          	   C   s0   dj | j| j| j| j| jdjdd„ | jD ƒƒƒS )Nz0Unable to apply patch ({0} {1} {2} {3} {4}, {5})z, c             S   s   g | ]}t |ƒ‘qS r;   )rd   )Ú.0Úir;   r;   r<   ú
<listcomp>-  s    z+ApplyPatchError.__str__.<locals>.<listcomp>)r«   r»   rº   r¸   rO   r­   rA   r¹   )r±   r;   r;   r<   Ú__str__&  s    zApplyPatchError.__str__)rL   r¨   r©   rµ   r°   rÀ   r¶   r;   r;   )r´   r<   r·     s   	r·   c                   s(   e Zd ZdZ‡ fdd„Zdd„ Z‡  ZS )r…   zprevious patch failedc                s"   t t| ƒj||Ž || _|| _d S )N)r¯   r…   r°   r‰   Úanchor)r±   r‰   rÁ   r¼   r²   )r´   r;   r<   r°   5  s    z%PreviousPatchFailedException.__init__c             C   s   d}|j | j| jƒS )NzˆIt seems, the latest patch, applying at {0}, crashed, and further attempts will be suspended. To force patch applying, remove `{1}` file)r«   r‰   rÁ   )r±   Úmessager;   r;   r<   rÀ   :  s    z$PreviousPatchFailedException.__str__)rL   r¨   r©   rµ   r°   rÀ   r¶   r;   r;   )r´   r<   r…   2  s   r…   c             C   sÀ   t jƒ dj| ƒ }yztj|ƒ}tjtj|jƒ ƒƒ}t	|d ƒ}|dkrRtj
dƒ n8|dkrftj
dƒ n$|dkrztj
dƒ ntj
d	j|ƒƒ |S  tk
rº } ztj||ƒ W Y d d }~X nX d
S )Nz"/nagios/register_key.plain?key={0}r¸   r   zKey successfully registeredr   zWrong key format or sizerr   z!No KernelCare license for that IPzUnknown error {0}r?   )r   Úget_registration_urlr«   r   Úurlopenr   Údata_as_dictrk   rƒ   r‚   Úprint_wrapperr   r   Úprint_cln_http_error)Úkeyro   ÚresponseÚresr¸   Úer;   r;   r<   Ú!set_monitoring_key_for_ip_licenseC  s     
rÌ   c               c   s>   t jrtjt jdd� z
d V  W d t jr8tjt jdd� X d S )NT)Úshell)r
   ZBEFORE_UPDATE_COMMANDr   Úrun_commandZAFTER_UPDATE_COMMANDr;   r;   r;   r<   Úexecute_hooksW  s    
rÏ   c             C   sÖ   t ƒ }|j}|j}tjƒ }| dkrht|ƒtjtj	ƒ t
jƒ |ttjƒ ƒ|dœ}tjdƒ tjtj|ƒƒ njtjdƒ tjt|ƒƒ tjdt|ƒ ƒ tjtjƒ tjtj	ƒ ƒ tjt
jƒ ƒ tj|ƒ tjtjƒ ƒ dS )a1  
    The output will consist of:
    Ignore output up to the line with "--START--"
    Line 1: show if update is needed:
        0 - updated to latest,
        1 - update available,
        2 - unknown kernel
        3 - kernel doesn't need patches
        4 - no license, cannot determine
    Line 2: licensing message (can be skipped, can be more then one line)
    Line 3: LICENSE: CODE: 1: license present, 2: trial license present, 0: no license
    Line 4: Update mode (True - auto-update, False, no auto update)
    Line 5: Effective kernel version
    Line 6: Real kernel version
    Line 7: Patchset Installed # --> If None, no patchset installed
    Line 8: Uptime (in seconds)

    If *format* is 'json' return the results in JSON format.

    Any other output means error retrieving info
    :return:
    ri   )Z
updateCodeZ
autoUpdateZeffectiveKernelZ
realKernelZloadedPatchLevelZuptimeÚlicensez	--START--z	LICENSE: N)Ú_patch_level_infor¸   Úapplied_lvlr   Úlicense_inford   r
   ÚAUTO_UPDATEr   Úkcare_unamer¬   r­   r‚   r   Z
get_uptimer   rÆ   ri   rj   )ÚfmtÚpliZupdate_codeZ	loaded_plZlicense_info_resultZresultsr;   r;   r<   Úplugin_infoc  s,    



rØ   c              C   s^   t jƒ } ytdd�}W n tk
r4   tjr0dS dS X | d krBdS | |krNdS tjƒ rZdS dS )NÚinfo)rŒ   r   é   r   rr   )r   Úloaded_patch_levelr‘   rª   r
   ÚIGNORE_UNKNOWN_KERNELr   Zstatus_gap_passed)Úcurrent_levelZlatest_patch_levelr;   r;   r<   Úget_update_status—  s    rÞ   c              C   s2   t jƒ d d… \} }| dkr*|jdƒr*dS dS d S )Nrr   Z
CloudLinuxz7.ÚextrarK   )r   r`   Ú
startswith)rO   Úversionr;   r;   r<   Úedf_fallback_ptype§  s    râ   c             C   sl   | j | jf}tj||ƒ}tj|| jƒ| _| jjtj	tj
dƒ |tkrZ| jjƒ dd… t|< | jrh| jƒ  dS )z�Function remembers IP address of host connected to
    and uses it for later connections.

    Replaces stdlib version of httplib.HTTPConnection.connect
    r   Nrr   )ÚhostZportÚCONNECTION_STICKY_MAPÚgetÚsocketZcreate_connectionZtimeoutÚsockZ
setsockoptZIPPROTO_TCPZTCP_NODELAYZgetpeernameÚ_tunnel_hostZ_tunnel)r±   ZaddrZresolved_addrr;   r;   r<   Ústicky_connect´  s    ré   ZHAS_SNIz0.13z%No pyOpenSSL module with SNI ability.c              G   s   dS )NTr;   )r¼   r;   r;   r<   Údummy_verify_callbackØ  s    rê   c               @   s,   e Zd Zdd„ Zdd„ Zdd„ Zdd„ Zd	S )
ÚSSLSockc             C   s   || _ d| _d S )Nr   )Ú	_ssl_connÚ_makefile_refs)r±   rç   r;   r;   r<   r°   â  s    zSSLSock.__init__c             G   s&   |  j d7  _ tj| jf|žddiŽS )Nr   r7   T)rí   ræ   Z_fileobjectrì   )r±   r¼   r;   r;   r<   Úmakefileæ  s    zSSLSock.makefilec             C   s"   | j  r| jr| jjƒ  d | _d S )N)rí   rì   r7   )r±   r;   r;   r<   r7   ê  s    
zSSLSock.closec             G   s   | j j|Ž S )N)rì   Úsendall)r±   r¼   r;   r;   r<   rï   ï  s    zSSLSock.sendallN)rL   r¨   r©   r°   rî   r7   rï   r;   r;   r;   r<   rë   á  s   rë   c               @   s   e Zd Zdd„ ZdS )ÚPyOpenSSLHTTPSConnectionc             C   s¾   t jj| ƒ tjjtjjƒ}|jtjjtjj	B ƒ t
jrJ|jtjjtƒ n|jtjjtƒ |jƒ  tjj|| jƒ}|jƒ  | jp„| j}|j|jƒ ƒ |jƒ  t
jr°t|jƒ |ƒ t|ƒ| _d S )N)r!   ÚHTTPConnectionÚconnectÚOpenSSLZSSLZContextZSSLv23_METHODZset_optionsZOP_NO_SSLv2ZOP_NO_SSLv3r
   ÚCHECK_SSL_CERTSZ
set_verifyZVERIFY_PEERrê   ZVERIFY_NONEZset_default_verify_pathsZ
Connectionrç   Zset_connect_staterè   rã   Zset_tlsext_host_nameÚencodeZdo_handshakeÚmatch_hostnameZget_peer_certificaterë   )r±   ZctxZconnZserver_hostr;   r;   r<   rò   ó  s    z PyOpenSSLHTTPSConnection.connectN)rL   r¨   r©   rò   r;   r;   r;   r<   rð   ò  s   rð   c             C   s²  t jr&tj| |ƒ}tjtjƒ|dd�S |dk}t jo6|}�xrd|fd|fdgD �]Z\}}t	j	|||d�}	t	j
|	|d�}
|r„dj|
ƒ}
tj| t||ƒƒd	 |
 }d
}|sª|rÔt|ƒ|krÔ|r¾dnd}tjdj|ƒƒ qNyxtjtjƒ|dd�}t j�rJtj|	ƒ�rJtj|	ƒ}tj|ƒ}|�r.tjdj|ƒdd� ntjddd� |�rJ|jƒ  |S  tk
�r¨ } z>|�sl|�r–|jdk�s„|jdk�r–tjdj|ƒƒ wN‚ W Y d d }~X qNX qNW d S )NF)Úcheck_licenseú	latest.v1ú	latest.v2T)Úsecure_boot_infoÚperf_metrics)Úb64_encodingzinfo={0}ú?iX  zsecure boot infozperf metricsz/Check-in URL param is too large, discarding {0}z:Automatic kernel anomaly report uploaded successfully: {0})Ú	print_msgz$Failed to send kernel anomaly reporté�  éž  iô  zCCheck-in request failed with error: {0}, retrying with reduced info)rø   rù   )FF)rÿ   r   )r
   rh   r   Zget_kernel_prefixed_urlr   Zwrap_with_cache_keyr   Úurlopen_authZSEND_PERF_METRICSr   Zencode_checkin_payloadr«   ÚstickyfyÚlenr   ÚlogwarnZKERNEL_ANOMALY_REPORT_ENABLEr   Zdetect_anomalyÚprepare_kernel_anomaly_reportÚsend_data_packageÚloginfoÚremove_archiver   r¸   )r—   r    rŒ   Úmodero   rü   Zperf_enabledrú   rû   ZsinfoZrequest_paramZmax_url_lengthZdiscard_infor8   Údata_packageÚupload_nameÚexr;   r;   r<   Ú_fetch_patch_level_request  sB    
 


$r  c       	      C   s8  t jƒ }tjd k	r$t j|ttjƒƒS �xtD � ]ü}yªt||| |ƒ}tj	|j
ƒ tƒ  tj|jƒ ƒjƒ }tjdj| |ƒdd� |rÎ|jdƒrÎt|ƒ}|jdg ƒ}tj|ƒs²tjdƒ‚t j||d |d |d	 ƒS t j|t|ƒƒS  tk
rð   Y q, tk
�r( } z|jdk�rtdƒ‚‚ W Y d d }~X q,X q,W tƒ ‚d S )Nz;fetch patch level, reason: {0}, kernel latest response: {1}F)rþ   ú{r	   zeLatest KernelCare patchset is incompatible with the current kernecare package version, please upgraderº   Úbaseurlr­   é“  é‘  zKC licence is required)r  r  ) r   r®   r
   ÚPATCH_LEVELr¤   r‚   ÚPATCH_LATESTr  r   Zset_feature_flags_from_headersÚheadersÚupdate_all_kmod_paramsr   rk   rƒ   r£   r   r  r«   rà   r"   rå   r	   Zhas_kc_capabilitiesr   ÚCapabilitiesMismatchZKernelPatchLevelr   r   r¸   r   rª   )	rŒ   r	  r—   r    rÉ   r¥   Zlatest_infoZrequired_capabilitiesr  r;   r;   r<   Úfetch_patch_level;  s2    

r  c             C   s<  | j t|tjƒƒ}tjjdj|ƒƒ ytj	|ddd� dS  t
k
r^   tjjdj|ƒƒ dS  tk
r– } ztjjdj|t|ƒƒƒ W Y d d }~X nX | j t|tjƒtj ƒ}tjjdj|ƒƒ ytj	|dd� W nb t
k
� rü   tjjdj|ƒƒ dS  tk
�r6 } ztjjd	j|t|ƒƒƒ W Y d d }~X nX dS )
NzProbing patch URL: {0}FÚHEAD)r÷   ÚmethodTz{0} is not available: 404zFHEAD request for {0} raised an error, fallback to the GET request: {1})r÷   z{0} is not available: {1})Úfile_urlrD   r
   rE   r   r{   rÙ   r«   r   r  r   rn   Údebugrd   r   ZSIGr    )rº   rB   Zbin_urlr  ro   r;   r;   r<   Úprobe_patch\  s(    **r  c             C   sF   |t jkr| jt jƒ}n
| j|ƒ}| j|ƒ}tj||tjtj	| ƒd�S )N)Zhash_checker)
r   ÚKMOD_BINZkmod_urlr  Ú
cache_pathr   Z	fetch_urlr
   ÚUSE_SIGNATUREZget_hash_checker)rº   Únamero   Zdstr;   r;   r<   Úfetch_and_verify_kernel_fileu  s
    


r!  c               @   s>   e Zd Zddd„Zdd„ Zdd„ Zdd	„ Zd
d„ Zdd„ ZdS )ÚPatchFetcherNc             C   s
   || _ d S )N)r¡   )r±   r¡   r;   r;   r<   r°   €  s    zPatchFetcher.__init__c             C   s   t | j|ƒS )N)r!  r¡   )r±   r   r;   r;   r<   Ú_fetchƒ  s    zPatchFetcher._fetchc             C   sr   | j jtjƒ}| j jtjƒ}| j jtjƒ}| j jtjƒ}tdd„ ||||fD ƒƒopt	j
j|ƒdkopt	j
j|ƒdkS )Nc             s   s   | ]}t jj|ƒV  qd S )N)r0   r1   r2   )r½   r1   r;   r;   r<   ú	<genexpr>�  s    z0PatchFetcher.is_patch_fetched.<locals>.<genexpr>r   )r¡   r  r
   rI   rE   rF   r   r  Úallr0   r1   Úgetsize)r±   Zpatch_done_pathZpatch_bin_pathZpatch_info_pathZkmod_bin_pathr;   r;   r<   Úis_patch_fetched†  s    zPatchFetcher.is_patch_fetchedc             C   s4  | j d krtdƒ‚| j s| j S | jƒ r6tjdƒ | j S tjdƒ t| j tjƒr¦ytj	| j j
tjƒdd�}W n tk
r~   Y n(X |jjdd ƒ}|r¦| j jtj|ƒƒ| _ y| jtjƒ W n0 tk
ræ   tdj| j tjpØdƒd	d
�‚Y nX | jtjƒ | jtjƒ | jƒ  tj| j jtjƒddd� tjtj ƒ | j S )Nz+Cannot fetch patch as no patch level is setzUpdates already downloadedzDownloading updatesr  )r  zKC-Base-UrlzfThe `{0}` patch level is not found for `{1}` patch type. Please select valid patch type or patch levelÚdefaultzpatch level not found)rµ   ó    Úwb)r	  )!r¡   r†   r'  r   r  rU   r   r¤   r   r  r  r
   rE   r   r  rå   Úupgrader   rk   r#  r   r«   Ú
PATCH_TYPErF   r   r  Úextract_blacklistr‡   r  rI   r   Úrestore_selinux_contextr�   )r±   Úrespr  r;   r;   r<   Úfetch_patch’  s:    


zPatchFetcher.fetch_patchc             C   sJ   t | jjtjƒdƒjƒ }|rFtj|ƒ}|rFtj	| jjtj
ƒ|jdƒƒ d S )Nr.   r   )r4   r¡   r  r
   rF   rƒ   ÚBLACKLIST_REÚsearchr   r‡   rG   Úgroup)r±   ZbufZmor;   r;   r<   r-  »  s
    
zPatchFetcher.extract_blacklistc             C   s´   |dkrdS yt |tjƒ}W n tk
r0   dS X |jjddƒ}|rT|jtj|ƒƒ}|j	tjƒ}t
|dƒ�}tdd„ |jƒ D ƒƒ}W dQ R X x|D ]}t ||ƒ q’W tjtjƒ dS )z¶
        Download fixup files for defined patch level
        :param level: download fixups for this patch level (usually it's a level of loaded patch)
        :return: None
        NzKC-Base-Urlr.   c             S   s   g | ]}|j ƒ ‘qS r;   )r£   )r½   Úfixupr;   r;   r<   r¿   Ø  s    z-PatchFetcher.fetch_fixups.<locals>.<listcomp>)r!  r
   rH   r   r  rå   r+  r   rk   r  r4   r/   Ú	readlinesr   r.  r   r�   )r±   rº   r/  r  Zfixups_fnamer9   Úfixupsr4  r;   r;   r<   Úfetch_fixupsÂ  s     
zPatchFetcher.fetch_fixups)N)	rL   r¨   r©   r°   r#  r'  r0  r-  r7  r;   r;   r;   r<   r"  ~  s   
)r"  c              C   s8   t ƒ } tj| jƒ | jtjkr*tjdƒ n
tjdƒ d S )Nr   r   )	rÑ   r   rÆ   r³   r¸   ÚPLIÚPATCH_NEED_UPDATErS   Úexit)r×   r;   r;   r<   Úkcare_checkà  s
    r;  c              C   s\  t ƒ } t| ƒ}ytjƒ }W n tk
r2   i }Y nX tjƒ }d}|d k	r\tj|d ƒj	dƒ}tj
ƒ }|jdg ƒ}ttj|dd�ƒ}t|ƒ}dd„ |D ƒ}	ttj|	d	d�ƒ}
td
d„ |D ƒƒ}|| }tjƒ }|sÜtjdƒ n
tjdƒ tjdj|ƒƒ tjdj|ƒƒ |dk�r tjdj|ƒƒ |
dk�r:tjdj|
ƒƒ |dk�rNtjdƒ tjdƒ d S )NZUnknownÚtsz%Y-%m-%dr”   z
kpatch-cve)Z	cve_fieldc             S   s"   g | ]}|j d g ƒD ]}|‘qqS )r”   )rå   )r½   ÚrecÚpatchr;   r;   r<   r¿   ý  s    z%show_generic_info.<locals>.<listcomp>Zcvec             s   s   | ]}t |jd g ƒƒV  qdS )r”   N)r  rå   )r½   r=  r;   r;   r<   r$  ÿ  s    z$show_generic_info.<locals>.<genexpr>z$KernelCare live patching is disabledz"KernelCare live patching is activez - Last updated on {0}z - Effective kernel version {0}r   z* - {0} kernel vulnerabilities live patchedz- - {0} userspace vulnerabilities live patchedz% - This system has no applied patchesz(Type kcarectl --patch-info to learn more)rÑ   Ú_kcare_patch_info_jsonr   Zlibcare_patch_info_basicr   r   Z	get_stater   ZfromtimestampZstrftimerÕ   rå   r  r   Zextract_unique_cvesÚsumrÛ   rÆ   r«   )r×   Ú
kcare_infoÚlibcare_infoÚstateZlatest_updateZeffective_versionZkernel_patchesZkernel_vulnerabilitiesZkernel_patches_countZuserspace_patchesZuserspace_vulnerabilitiesZuserspace_patches_countZtotal_patches_countr¡   r;   r;   r<   Úshow_generic_infoé  s>    





rD  Fc       	      C   sô   y¤t dtjd�}|st‚|jtjƒ}tjt	j
|ƒjƒ ƒ}| r˜g i  }}x>|jdƒD ]0}tj|ƒ}|rxd|krx|j|ƒ qR|j|ƒ qRW ||d< tj|ƒ}tj|ƒ W nJ tk
rÒ } ztj||jƒ dS d}~X n tk
rî   tjdƒ Y nX d	S )
z½
    Retrieve and output to STDOUT latest patch info, so it is easy to get
    list of CVEs in use. More info at
    https://cloudlinux.atlassian.net/browse/KCARE-952
    :return: None
    rÙ   )rŒ   Úpolicyz

zkpatch-namer”   r   NzNo patches availabler   )r‘   r   ÚPOLICY_REMOTErª   r  r
   rF   r   rk   r   r  rƒ   r@   rÅ   ÚappendÚupdateri   rj   rÆ   r   r   rÇ   ro   )	Úis_jsonr    ro   Ú
patch_infor”   r8   ÚchunkÚdatarË   r;   r;   r<   Úkcare_latest_patch_info  s,    


rM  c             C   sˆ   d| j i}| jd k	r„t| ƒ}g }x>|jdƒD ]0}tj|ƒ}|rRd|krR|j|ƒ q,|j|ƒ q,W ||d< tj	ƒ }|r||d nd|d< |S )NrÂ   z

zkpatch-namer”   r­   Úunknown)
r³   rÒ   Ú_kcare_patch_infor@   r   rÅ   rG  rH  r   Zread_dumped_kernel_patch_level)r×   r8   rJ  r”   rK  rL  Zsaved_patch_levelr;   r;   r<   r?  4  s    


r?  c             C   sT   t jƒ }t j|| jtjƒ}tjj|ƒs2t	ddd�‚t
|dƒjƒ }|rPtjd|ƒ}|S )NzvCan't find information due to the absent patch information file. Please, run /usr/bin/kcarectl --update and try again.zpatch info not found)rµ   r.   rK   )r   r®   r–   rÒ   r
   rF   r0   r1   r2   r   r4   rƒ   r1  Úsub)r×   r—   r  rÙ   r;   r;   r<   rO  H  s    rO  c             C   sZ   t ƒ }| s>|jdkr tj|jƒ |jd kr.d S tjt|ƒƒ ntjtjt	|ƒdd�ƒ d S )Nr   T)Z	sort_keys)
rÑ   r¸   r   rÆ   r³   rÒ   rO  ri   rj   r?  )rI  r×   r;   r;   r<   rJ  W  s    

rJ  c             C   s:   t jd| g}tj|ƒ}tjƒ }d}tj||ƒtj||ƒkS )Nz	file-infozkpatch-build-time)r   Ú
KPATCH_CTLr   Úcheck_outputr   Ú_patch_infoZget_patch_value)Únew_patch_filer¼   Znew_patch_infoZcurrent_patch_infoZbuild_time_labelr;   r;   r<   Úis_same_patchc  s
    
rU  c             C   sL   |dkrdS | r|| k rdS | |kr(dS t jt jƒ |tjƒ}t|ƒsHdS dS )Nr   FT)r   r–   r®   r
   rE   rU  )Úapplied_levelÚ	new_levelrT  r;   r;   r<   Úkcare_need_updatek  s    rX  c              C   sp   t jrltjjtƒotjttjƒs6tj	j
djtƒƒ d S tjdddtgdd�\} }}| dkrltj	j
dj| ƒƒ d S )	Nz-File {0} does not exist or has no read accessz/sbin/sysctlz-qz-pT)Úcatch_stdoutr   z%Unable to load kcare sysctl.conf: {0})r
   ZUPDATE_SYSCTL_CONFIGr0   r1   r2   ÚSYSCTL_CONFIGÚaccessÚR_OKr   r{   Úwarningr«   r   rÎ   )r¸   Ú_r;   r;   r<   Úupdate_sysctl}  s    r_  c                s¼   t jjtƒsttdƒjƒ  t jtt jƒs>tj	j
djtƒƒ dS ttdƒ�j}|jƒ }|jdƒ x,|D ]$‰ t‡ fdd„| D ƒƒsb|jˆ ƒ qbW x|D ]}|j|d ƒ q�W |jƒ  W dQ R X dS )	z*Update SYSCTL_CONFIG accordingly the editsrq   zFile {0} has no read accessNzr+r   c             3   s   | ]}ˆ j |ƒV  qd S )N)rà   )r½   r.   )r:   r;   r<   r$  ™  s    z#edit_sysctl_conf.<locals>.<genexpr>Ú
)r0   r1   r2   rZ  r4   r7   r[  r\  r   r{   r]  r«   r5  ÚseekÚanyÚwriteÚtruncate)r�   rG  ZsysctlÚlinesrq   r;   )r:   r<   Úedit_sysctl_confˆ  s    


rf  c             C   s.   x(| D ] }t j|ƒrtdj|ƒdd�‚qW d S )NzDDetected '{0}' kernel module loaded. Please unload that module firstzconflicting kernel module)rµ   )ÚCONFLICTING_MODULES_REÚmatchr   r«   )r›   Úmoduler;   r;   r<   Údetect_conflicting_modules¡  s
    

rj  c               C   s   dj tjƒ ƒS )Nz/lib/modules/{0}/extra/kcare.ko)r«   r   Zget_system_unamer;   r;   r;   r<   Úget_kcare_kmod_linkª  s    rk  c           
   C   sX   t dd�} tjtjƒ | tjƒ}tjj|ƒs.d S t	|dƒ�}|j
ƒ dd … dkS Q R X d S )NrÙ   )rŒ   Úrbé   s   ~Module signature appended~
iäÿÿÿ)r‘   r   r–   r®   r   r  r0   r1   r2   r4   rƒ   )rº   Z	kmod_fileZvfdr;   r;   r<   Úkmod_is_signed®  s    
rn  c                 s4   t jdƒ‰ ˆ d krd S ddg} t‡ fdd„| D ƒƒS )Nz
/proc/keysZ(12ff0613c0f80cfba3b2f8eba71ebc27c5a76170Z(69a6d9eed3f620d5c2e13a1d211c46510a5ad9f5c             3   s   | ]}|ˆ kV  qd S )Nr;   )r½   rÈ   )Úsystem_keysr;   r<   r$  ¿  s    z'kcare_certs_enrolled.<locals>.<genexpr>)r   Ztry_to_readrb  )Z
kcare_keysr;   )ro  r<   Úkcare_certs_enrolled·  s    
rp  c             K   sd   d| g}x&|j ƒ D ]\}}|jdj||ƒƒ qW tj|dd�\}}}|dkr`tdj| |ƒdd�‚d S )	Nz/sbin/insmodz{0}={1}T)rY  r   zLUnable to load kmod ({0} {1}). Try to run with `--check-compatibility` flag.zkmod load error)rµ   )ÚitemsrG  r«   r   rÎ   r   )Zkmodr²   ÚcmdrÈ   re   r¸   r^  r;   r;   r<   Ú	load_kmodÂ  s    
rs  c               C   sT   t jƒ r,tƒ dkrtdƒ‚tƒ dkr,tdƒ‚t jƒ sDt jƒ sDt jƒ rPtddd�‚d S )NFz4Secure boot is enabled. Not supported by KernelCare.z<Secure boot is enabled. No KernelCare certificates enrolled.zWYou are running inside a container. Kernelcare should be executed on host side instead.zrunning in container)rµ   )r   Zis_secure_bootrn  r   rp  Zinside_vz_containerZinside_lxc_containerZinside_docker_containerr;   r;   r;   r<   Úcheck_compatibilityÎ  s    

rt  c             C   sP   t jdƒ}t j|dgddd�d dk}|rL| d
krLtjdj| ƒƒ tjd	ƒ d S )NZmodinfoZkmodlveT)rY  Úcatch_stderrr   Úfreerß   z3{0} patch type conflicts with kmodlve kernel moduler   )rv  rß   )r   Zfind_cmdrÎ   r   Úlogerrorr«   rS   r:  )rB   rr  Zhas_kmodlver;   r;   r<   Úcheck_patch_type_compatibilityÛ  s
    
rx  c             C   sP   t jddd| gƒ}g }x4|jdƒD ]&}|jƒ r"|jdƒ\}}}|j|ƒ q"W |S )Nz/sbin/modinfoz-FZparmr`  ú:)r   rR  r@   r£   Ú	partitionrG  )Ú
kcare_linkÚstdoutZavailable_paramsr:   Z
param_namer^  r;   r;   r<   Úget_kmod_available_paramsç  s    r}  c               C   sL   t jr
dndt jrdndt jr$t jndtt jtƒr8t jndt jrDdnddœS )Nr   r   rK   )Úkpatch_debugZkmsg_outputZkcore_outputZ
kdumps_dirZenable_crashreporter)	r
   ÚKPATCH_DEBUGZKMSG_OUTPUTZKCORE_OUTPUTZKCORE_OUTPUT_SIZErU   Ú
KDUMPS_DIRrd   ZENABLE_CRASHREPORTERr;   r;   r;   r<   Úmake_kmod_new_paramsñ  s
    r�  c              C   sH   t jr"tjjt jƒ r"tjt jƒ x tƒ jƒ D ]\} }t| |ƒ q.W d S )N)	r
   r€  r0   r1   ÚexistsÚmakedirsr�  rq  Úupdate_kmod_param)ZparamÚvalr;   r;   r<   r  û  s    r  c             C   st   d}t jj|| ƒ}t jj|ƒs"d S y(t|dƒ�}|jt|ƒƒ W d Q R X W n$ tk
rn   tj	j
d| |ƒ Y nX d S )Nz/sys/module/kcare/parametersÚwz!failed to set %s kmod param to %s)r0   r1   rA   r‚  r4   rc  rd   rn   r   r{   rP   )Zkmod_param_nameZparam_valueZparams_rootZ
param_pathr9   r;   r;   r<   r„    s    r„  c                s    t ƒ }tj| |tjƒ}ytj||ƒ W n tk
r>   |}Y nX tj	rbt
jjtj	ƒ rbt
jtj	ƒ tƒ }t|ƒ‰ t‡ fdd„|jƒ D ƒƒ}t|f|Ž tƒ  d S )Nc             3   s"   | ]\}}|ˆ kr||fV  qd S )Nr;   )r½   ÚkÚv)Úavailable_kmod_paramsr;   r<   r$  !  s    z"load_kcare_kmod.<locals>.<genexpr>)rk  r   r–   r   r  ÚshutilÚcopyrn   r
   r€  r0   r1   r‚  rƒ  r�  r}  Údictrq  rs  Úupdate_depmod)r—   rº   r{  Z
kcare_fileZkmod_paramsr;   )r‰  r<   Úload_kcare_kmod  s    
rŽ  c             C   sX   dg}| d k	r|j d| gƒ tj|ddd�\}}}|rTtjdjdj|ƒ||ƒdd� d S )	Nz/sbin/depmodz-aT)rY  ru  z%Running of `{0}` failed with {1}: {2}ú F)rþ   )Úextendr   rÎ   r   rw  r«   rA   )Úunamerr  r¸   r^  Ústderrr;   r;   r<   r�  '  s    r�  c             C   s8   t jd| gdd�\}}}|dkr4tdj| |ƒdd�‚d S )Nz/sbin/rmmodT)rY  r   zUnable to unload {0} kmod {1}zkmod unload error)rµ   )r   rÎ   r   r«   )Úmodnamer¸   r^  r;   r;   r<   Úunload_kmod3  s    r”  c             C   sT   g }xJdg| D ]<}t j| |dj|ƒƒ}tjj|ƒrt|ƒ |jdj|ƒƒ qW |S )NZvmlinuxzfixup_{0}.koz	fixup_{0})r   r–   r«   r0   r1   r‚  rs  rG  )r—   rÝ   r›   ZloadedÚmodZmodpathr;   r;   r<   Úapply_fixups9  s    r–  c             C   sD   x>| D ]6}yt |ƒ W q tk
r:   tjjd| ƒ Y qX qW d S )Nz$Exception while unloading module %s.)r”  rn   r   r{   r|   )r6  r•  r;   r;   r<   Úremove_fixupsC  s
    
r—  c             C   s’   | r
| }n6t jrt j}n(tƒ j|ƒr2d| t jdfS d| t jdfS ddddddœ}|jƒ }||krj|| }ntdj|| t jdƒd	d
�‚|| t jdfS )NZfreeze_conflictTr(  FZfreeze_noneZ
freeze_all)ZNONEZNOFREEZEZFULLZFREEZEZSMARTz3Unable to detect freezer style ({0}, {1}, {2}, {3})zfreezer style detection error)rµ   )r
   ZPATCH_METHODr=   ÚintersectionÚupperr   r«   )Úfreezerr›   r  Zpatch_method_mapr;   r;   r<   Úget_freezer_styleK  s&    
r›  rK   c                sª  | ||dœ‰ t dˆ ƒ tjƒ }tjƒ }t|ƒ t||ƒ}tj| |tjƒ}t	| |ƒ dj
|tjtjƒ tj|ƒƒ}	d|k}
|
o„tj| |ƒ}|d k	}|o¢t|ƒo¢tj|	ƒ}ˆ j||dœƒ |rÆt dˆ ƒ d S |�rt dˆ ƒ t| ||ƒ}t dˆ ƒ t|ƒ t d	ˆ ƒ t|ƒ |�r"t d
ˆ ƒ tdƒ d}
|
�s<t dˆ ƒ t| |ƒ |�rHtƒ  t dˆ ƒ t|| ||	|ƒ tƒ  tjdj
|tjƒ ƒƒ tjƒ  t dˆ ƒ t ‡ fdd„tj!d� d S )N)r—   Zfuturer	  Ústartz{0}-{1}:{2};{3}r   )ZcurrentÚkmod_changedr‹   ZfxpÚunpatchZunfxpÚunloadFÚloadr>  z5Patch level {0} applied. Effective kernel version {1}Úwaitc                  s   t ˆ ƒS )N)r“   r;   )r’   r;   r<   Ú<lambda>©  s    zkcare_load.<locals>.<lambda>)rz   )"rŽ   r   rÛ   r�   rj  r›  r–   r
   rE   r¢   r«   r,  r   rˆ   Zparse_unameZis_kmod_version_changedrU  Zkcare_update_effective_versionrH  r–  Úkpatch_ctl_unpatchr—  r”  rŽ  rŠ   Úkpatch_ctl_patchr_  r   r  rÕ   r   Ztouch_status_gap_filer€   r„   )r—   rº   r	  rš  Ú
use_anchorrÝ   r›   r¹   r»   ÚdescriptionZkmod_loadedr�  Zpatch_loadedZ
same_patchr6  r;   )r’   r<   Ú
kcare_loadm  sR    











r§  c       	      C   sŒ   t jg}tj||tjƒ}tjj|ƒr2|j	d|gƒ |j	dd|gƒ |j	d|d gƒ |j
| ƒ tj|dd�\}}}|dkrˆt|||| ƒ‚d S )Nz-br>  z-dz-mr   T)rY  )r   rQ  r   r–   r
   rG   r0   r1   r‚  r�  rG  r   rÎ   r·   )	r»   r—   rº   r¦  r¹   r¼   Zblacklist_filer¸   r^  r;   r;   r<   r¤  ¬  s    
r¤  c             C   s^   t jtjdd| d gddd�\}}}|dkrZtjdj||ƒdd� td	j|t| ƒƒd
d�‚d S )Nrž  z-mr   T)rY  ru  z4Error unpatching, kpatch_ctl stdout:
{0}
stderr:
{1}F)rþ   zError unpatching [{0}] {1}zunpatch error)rµ   )	r   rÎ   r   rQ  r   rw  r«   r   rd   )r¹   r¸   r|  r’  r;   r;   r<   r£  ¹  s
     r£  c             C   s8   | |d< t tjƒ ƒ|d< tjtjjtjdƒt	|ƒƒ d S )NÚactionr<  zkcare.state)
r‚   ry   r   r‡   r0   r1   rA   r   r�   rd   )r¨  r’   r;   r;   r<   rŽ   Ã  s    rŽ   c             C   sp   d}t jj|ƒsd S xVt j|ƒD ]H}t jj||ddƒ}t jj|ƒsDq t j|ƒ}|| kr t j|ƒ t|ƒ q W d S )Nz/usr/lib/modules/zweak-updateszkcare.ko)	r0   r1   ÚisdirÚlistdirrA   ÚislinkÚreadlinkÚunlinkr�  )Ú	kmod_linkZmodules_pathÚentryZsym_link_pathZtarget_pathr;   r;   r<   Úupdate_weak_modulesÉ  s    

r°  c             C   sJ  t jƒ }tƒ }y|j|ƒ W n8 tk
rT } z|sDtdj|ƒdd�‚W Y d d }~X nX t jƒ }t| |ƒ}t	ƒ �Ò d|k�r|d k	}|røt
t jƒ ||ƒ}tjtjdd|d gddd	�\}	}
}t|ƒ |	dkrøtjd
j|
|ƒdd� tdj|	t|ƒƒdd�‚tjtjtƒdtd�tƒdƒ tƒ }tjj|ƒ�r4tj|ƒ t|ƒ W d Q R X d S )Nz�Unable to retrieve fixups: '{0}'. The unloading of patches has been interrupted. To proceed without fixups, use the --force flag.zfixups retrieval error)rµ   r   rž  z-mr   T)rY  ru  z4Error unpatching, kpatch_ctl stdout:
{0}
stderr:
{1}F)rþ   zError unpatching [{0}] {1}zunpatch errorr   )ÚcountÚdelay) r   rÛ   r"  r7  rn   r   r«   r�   r›  rÏ   r–  r®   r   rÎ   r   rQ  r—  r   rw  rd   r   Zretryr   Z	check_excÚUNLOAD_RETRY_DELAYr”  rk  r0   r1   r2   r­  r°  )rš  ÚforcerÝ   ÚpfÚerrr›   r¹   Zneed_unpatchr6  r¸   r|  r’  r®  r;   r;   r<   Úkcare_unloadÙ  s:    

 
r·  c             C   s8   t ƒ }| rt|ƒS |jdkr"|jS |jd k	r4tjƒ S d S )Nr   )rÑ   Ú_kcare_info_jsonr¸   r³   rÒ   r   rS  )rI  r×   r;   r;   r<   rA    s    

rA  c             C   sR   d| j i}| jd k	r>|jtjtjƒ ƒƒ |jtj|jdƒƒƒ | j	|d< t
j|ƒS )NrÂ   zkpatch-descriptionzkpatch-state)r³   rÒ   rH  r   rÅ   r   rS  Zparse_patch_descriptionrå   rC  ri   rj   )r×   r8   r;   r;   r<   r¸    s    


r¸  c               @   s$   e Zd ZdZdZdZdZdd„ ZdS )r8  r   r   rr   rÚ   c             C   s"   || _ || _|| _|| _|| _d S )N)r¸   r³   Ú
remote_lvlrÒ   rC  )r±   r¸   r³   r¹  rÒ   rC  r;   r;   r<   r°   %  s
    zPLI.__init__N)rL   r¨   r©   r  r9  ÚPATCH_UNAVALIABLEÚPATCH_NOT_NEEDEDr°   r;   r;   r;   r<   r8    s
   r8  c              C   sü   t jƒ } y‚tdd�}| rJt| |ƒr6tjdd  }}}qxtjdd  }}}n.|dkrftjdd  }}}ntjd	d  }}}t|||| |ƒ}W nl tk
rö   tj	}t
jrÄd
jt
jtjƒ d tjƒ ƒ}ndjtjƒ d tjƒ t jƒ ƒ}t||d d dƒ}Y nX |S )NrÙ   )rŒ   z*Update available, run 'kcarectl --update'.ZappliedzThe latest patch is applied.r   z(This kernel doesn't require any patches.ZunsetzDNo patches applied, but some are available, run 'kcarectl --update'.zuInvalid sticky patch tag {0} for kernel ({1} {2}). Please check /etc/sysconfig/kcare/kcare.conf STICKY_PATCH settingszLNew kernel detected ({0} {1} {2}).
There are no updates for this kernel yet.Zunavailable)r   rÛ   r‘   rX  r8  r9  r  r»  rª   rº  r
   ÚSTICKY_PATCHr«   r   r`   r¬   r­   r®   )Zcurrent_patch_levelZnew_patch_levelr¸   r³   rC  rÙ   r;   r;   r<   rÑ   -  s8    

rÑ   c       	      C   sæ   d}yXt jƒ }td|fd| fgƒ}tjƒ dj|ƒ }tj|ƒ}tj	tj
|jƒ ƒƒ}t|d ƒS  tk
rˆ } ztj||ƒ d
S d}~X nZ tk
r² } ztj||ƒ dS d}~X n0 tk
rà } ztjdj|ƒƒ dS d}~X nX dS )zÁ
    Request to tag server from ePortal. See KCARE-947 for more info

    :param tag: String used to tag the server
    :return: 0 on success, -1 on wrong server id, other values otherwise
    NÚ	server_idÚtagz/tag_server.plain?{0}r¸   rÚ   é   zInternal Error {0}é   éýÿÿÿéüÿÿÿéûÿÿÿ)r   Úget_serveridr#   r   rÃ   r«   r   rÄ   r   rÅ   rk   rƒ   r‚   r   r   rÇ   r    rn   rw  )	r¾  ro   r½  ZqueryrÉ   rÊ   rË   ZueZeer;   r;   r<   Ú
tag_server_  s"    
rÅ  c              C   sÚ   t jdƒ} tjdj| ƒƒ t}tjƒ �ª}y:tj	| |j
ƒ}t jtj| ƒ|j
ƒ tj|j
|ƒ |j
}W n2 tk
r” } ztjdj|ƒƒ W Y d d }~X nX tjd|tjƒ gdd�\}}}|rÌtdj||ƒdd	�‚W d Q R X d S )
Nz	doctor.shz#Requesting doctor script from `{0}`z3Kcare doctor error: {0}. Fallback to the local one.ZbashT)ru  zScript failed with '{0}' {1}zdoctor script failed)rµ   )r   rm   r   Zlogdebugr«   ÚKCDOCTORÚtempfileZNamedTemporaryFiler   Zfetch_signaturer   Zsave_to_filer   rÄ   Zcheck_gpg_signaturern   rw  r   rÎ   r   Zget_patch_serverr   )Z
doctor_urlZdoctor_filenameZ
doctor_dstZ	signaturer¶  r¸   r^  r’  r;   r;   r<   Úkcdoctorz  s    


"rÈ  c              C   sB   t jdjtƒƒ} ytj| ƒ W n tk
r2   dS X tjdƒ dS )Nz{0}-new-versionFzwA new version of the KernelCare package is available. To continue to get kernel updates, please install the new versionT)	r   rm   r«   ÚEFFECTIVE_LATESTr   rÄ   r    r   r  )ro   r;   r;   r<   Úcheck_new_kc_version‹  s    rÊ  c       
      C   s  t jƒ }t|ƒ}|tjkp*|tjko*|dk}yt| |ƒ}W n† tjk
r† } z.|dkrX‚ t	j
t|ƒƒ t	j
dƒ tj}W Y dd}~X n< tk
rÀ } z |rž‚ nt	jjdj|ƒƒ W Y dd}~X nX |tjkrÒ|}	n@|}	|dk�r|tjkrøt j|dƒ}	n|tjk�r
|}	ntdƒ‚|	S )aÒ  
    Get patch level to apply.
    :param reason: what was the source of request (update, info etc.)
    :param policy: REMOTE -- get latest patch_level from patchserver,
                   LOCAL -- use cached latest,
                   LOCAL_FIRST -- if cached level is None get latest from patchserver, use cache otherwise
    :param mode: constants.UPDATE_MODE_MANUAL, constants.UPDATE_MODE_AUTO or constants.UPDATE_MODE_SMART
    :return: patch_level string
    Nz#Using previously downloaded patcheszUnable to send data: {0}r   z9Unknown policy, choose one of: REMOTE, LOCAL, LOCAL_FIRST)r   r®   r¦   r   rF  ZPOLICY_LOCAL_FIRSTr  r   r  r   r  rd   ZPOLICY_LOCALrn   r{   r]  r«   r¤   r   )
rŒ   rE  r	  r—   Zcached_levelZconsider_remote_exZremote_levelrË   r  rº   r;   r;   r<   r‘   ˜  s2    
$


r‘   c             C   s–   | dkrd S | dkrdn| t _ttdd�t jƒr€tjt jd� t jdkrntjƒ rnt jpXt	}t
dddj|ƒfƒ tjdj| ƒƒ ntdj| ƒdd�‚d S )NÚedfr(  rK   Zprobe)rŒ   )r,  rv  rß   úfs.enforce_symlinksifownerúfs.symlinkown_gidzfs.enforce_symlinksifowner=1zfs.symlinkown_gid={0}z'{0}' patch type selectedz/'{0}' patch type is unavailable for your kernelzpatch type unavailable)rµ   )rv  rß   )rÌ  rÍ  )r
   r,  r  r  r   Úupdate_configr   Z	is_cpanelZ	FORCE_GIDÚ
CPANEL_GIDrf  r«   r   r  r   )rB   Zgidr;   r;   r<   Úupdate_patch_typeÆ  s    
rÐ  Zkernelc       	   $   C   sh  t tjƒ |tjkrtƒ  ytd||d�}W nR tk
r~ } z6|tjtj	fkrltj
rlt|ƒ}tjj|ƒ dS ‚ W Y dd}~X nX tjƒ }|tjkržtj rždS t|ƒ}|jƒ  t||d�sÈtjdƒ dS y(tjtjddd� tjtjdd	d� W n" tk
�r   tjjd
ƒ Y nX tjƒ }tƒ �( |j|ƒ t|||| |tj	kd� W dQ R X tj|ƒ t ||ƒ dS )ax  
    :param mode: constants.UPDATE_MODE_MANUAL, constants.UPDATE_MODE_AUTO or constants.UPDATE_MODE_SMART
    :param policy: REMOTE -- download latest and patches from patchserver,
                   LOCAL -- use cached files,
                   LOCAL_FIRST -- download latest and patches if cached level is None, use cache in other cases
    :param freezer: freezer mode
    rH  )rŒ   rE  r	  N)rV  rW  z%No updates are needed for this kernelrÚ   zkcore*.dump)Zkeep_nZpatternz	kmsg*.logz#Error during crash reporter cleanup)r¥  )!rx  r
   r,  r   rF  rÊ  r‘   rª   ÚUPDATE_MODE_AUTOÚUPDATE_MODE_SMARTrÜ   rd   r   r{   r]  r   rÛ   rÔ   r"  r0  rX  r  r   r•   r€  rn   r|   r®   rÏ   r7  r§  Zdump_kernel_patch_levelr˜   )	rš  r	  rE  rº   rË   r³   rÝ   rµ  r—   r;   r;   r<   Ú	do_updateÝ  s<    




"
rÓ  c             C   s”   t ttjƒttjptjƒttjp$tjƒfƒ}|dkr@tddd�‚tjrLtjS | t	j
krptjp`tj}tjpltj}ntj}tj}|r„|S |r�d| S d S )Nr   z‰Invalid configuration: conflicting settings STICKY_PATCH, [AUTO_]UPDATE_DELAY or [AUTO_]STICKY_PATCHSET. There should be only one of themzconflicting sticky settings)rµ   zrelease-)r@  Úboolr
   r¼  ZUPDATE_DELAYZAUTO_UPDATE_DELAYZSTICKY_PATCHSETZAUTO_STICKY_PATCHSETr   r   ÚUPDATE_MODE_MANUAL)r	  r±  r²  Zpatchsetr;   r;   r<   Ú
get_sticky  s&    
rÖ  c             C   s   | d | S )Nr>   r;   )rž   r�   r;   r;   r<   Ú	_stickyfy<  s    r×  c             C   s   t |ƒ}|s| S |dkr"t|| ƒS tjƒ }|sDtjjdƒ tjdƒ yt	j
tjƒ dj|ƒ ƒ}W n: tk
rš } ztj||jƒ tjdƒ W Y dd}~X nX tjtj|jƒ ƒƒ}t|d ƒ}|dkrÒt|d	 | ƒS |d
krÞ| S |dk� rþtjjdƒ tjdƒ tjjd|d  ƒ tjdƒ dS )z„
    Used to add sticky prefix to satisfy KCARE-953
    :param file: name of the file to stickify
    :return: stickified file.
    ÚKEYzHPatch set to STICKY_PATCH=KEY, but server is not registered with the keyr¿  z!/sticky_patch.plain?server_id={0}rÀ  Nr¸   r   rž   r   rr   zEServer ID is not recognized. Please check if the server is registeredzError: rÂ   rÚ   rÂ  rÃ  r?   rÁ  )rÖ  r×  r   rÄ  r   r{   rÙ   rS   r:  r   rÄ   r   rÃ   r«   r   rÇ   ro   r   rÅ   rk   rƒ   r‚   )Úfiler	  Úsr½  rÉ   rË   rÊ   r¸   r;   r;   r<   r  @  s2    



r  c       
      C   sö   g }| sdS | j dƒ}|d }|dd… }|jdƒ}||krLtdt| ƒ ƒ‚|s`| jƒ |jƒ kS |dkrt|jdƒ n>|jd	ƒsˆ|jd	ƒrš|jtj|ƒƒ n|jtj|ƒj	d
dƒƒ x|D ]}|jtj|ƒƒ q¸W tj
ddj|ƒ d tjƒ}	|	j|ƒS )zhMatching according to RFC 6125, section 6.4.3

    http://tools.ietf.org/html/rfc6125#section-6.4.3
    Fr>   r   r   NÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)r@   r±  r§   ÚreprÚlowerrG  rà   ÚreÚescapeÚreplaceÚcompilerA   Z
IGNORECASErh  )
ZdnÚhostnameZmax_wildcardsZpatsÚpiecesZleftmostZ	remainderZ	wildcardsZfragZpatr;   r;   r<   Ú_dnsname_matchl  s(    


rä  c       	      C   s
  g }xBt | jƒ ƒD ]2}| j|ƒ}|jƒ dkrdd„ t|ƒjdƒD ƒ}qW | sTtdƒ‚g }x0|D ](\}}|dkr^t||ƒr|d S |j|ƒ q^W |s°| j	ƒ j
}t||ƒr¦d S |j|ƒ t|ƒdkrÚtdj|d	jtt|ƒƒƒƒ‚n,t|ƒdk� rþtd
j||d ƒƒ‚ntdƒ‚d S )NZsubjectAltNamec             S   s   g | ]}|j ƒ jd dƒ‘qS )ry  r   )r£   r@   )r½   Úitr;   r;   r<   r¿   ¤  s    z"match_hostname.<locals>.<listcomp>ú,ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDZDNSr   z(hostname {0} doesn't match either of {1}z, zhostname {0} doesn't match {1}r   z=no appropriate commonName or subjectAltName fields were found)ÚrangeZget_extension_countZget_extensionZget_short_namerd   r@   r†   rä  rG  Zget_subjectZ
commonNamer  r§   r«   rA   ÚmaprÜ  )	Zcertrâ  Zsanr¾   rË   ZdnsnamesrÈ   re   Zcnr;   r;   r<   rö   Ÿ  s0    




rö   c           	   C   sÊ  t ddd�} | jdddd� | jdd	d
dd� | jdddd� | jddddd� | jdddd� | jdddd� | jdddd� | jdddd� | jdddd� | jdddd� | jdd dd� | jd!d"dd� | jd#d$dd� | jd%d&dd� | jd'd(d)d� | jd*d+dd� | jd,d-dd� | jd.d/dd� | jd0d1dd� | jd2d3dd� | jd4d5d6d� | jd7d8d9d� | jd:d;dd� | jd<d=d)d� | jd>d?dd� | jd@dAdd� | jdBdCdd� | jdDdEddFdG� | jdHdIdd� | jdJdKdd� | jdLdMdd� | jdNdOdd� | jdPdQdd� | jdRdSdd� | jdTdUdd� | jdVdWdd� | jdXdYdd� | jdZd[d\td d]d^� | jd_d`dd� | jdadbdd� | jƒ }|jdcddd\d� |jdedfdd� |jdgdhdd� | jdidjd\d d]dk� | jdldmdndd]do� | jdpdqdr� | jdsdtdd� | jdudvdwdxdy� tj�s| jdzd{d|d}d]d~� | jdd€d|d}d�d~� | jd‚dƒdd� | jd„d…d†dd� | jd‡dˆd‰dd� | jdŠddd� | jd‹dŒd�dd� | jdŽd�d�dd� | jd‘d’d“d”d� | jd•d–d—dd˜d™� | jdšd˜dd� | jd›dœdd� | jd�džd6dŸd\d d]d � | jƒ }tjƒ  tj�sFt j	d¡g7  _	|j
d k	�rzttd |j
jd¢ƒƒƒjtj	ƒ�rvd£S d¤S |j�sŠ|j�r¦tj�rœtjt_ntjt_n|j�r¶tjt_|j�sÞtjƒ d£k�rÞtd¥tjd¦� d¤S tj}|j�rôtj }n|j�rtj!}t"j#|ƒ tj$�stj%ƒ  |j&�r,t'j(ƒ  |j)�rn|j)d£k�r\t*|j)ƒt_+tj,tj+d§� nd t_+tj,dd§� |j-d k	�r�tj,|j-d¨� |j-t_.|j/�ržd]t_0|j1�r¬d]t_2|j3�rºd�t_4|j5�rÈt5ƒ  |j6�rÞt7j8d©t9ƒ n8|j:�rtj;dªk�rtj<dªk�rdntj<�pd«|_=d�|_>|j?�r&|j?t_@|jA�r@t7j8d¬t9ƒ d­t_@tj@jBd®ƒt_@tj@�r~tj@tCk�r~t"jDjEd¯jFtj@d°jGtCƒƒƒ |jH�r˜d�t_Id±|jH t_J|j=�rªtK|j=ƒ tj;dªk�rØtLƒ t_;t7j8d²jFtj;�pÐd«ƒt9ƒ |jM�røt'jNtOjM|jPd³�ƒ d S |jQ�r$tQjQd´d�d�dµ�}t'jNtPjR|ƒƒ d S tStj;ƒ |jT�rJtTjUtV|jWd¶� d S |jX�rÚtYjZtQjQd´d�d�dµ�ƒ}d·jF|j[ƒ}|j\�rˆt'jN|ƒ nRtYj]|ƒ}|�rªt"j^d¸jF|ƒƒ nt"j_d¹d�dº� |j`�rÌt'jN|ƒ n|�rÚ|jaƒ  |jb�r |jP�rötbd»d¼� ntbƒ  d S |jc�rtj,d½d¾� d S |jd�r0tj,d¿d¾� d S |je�rHtjf|jeƒ d S |jg�rZth|jgƒS |ji�rjtjjiƒ  |jk�rštj;dÀk�rŠtj,dÁdÂ� tjjk|jk|jlƒS |jm�r¸tjjmƒ d£k�r´d£S d¤S |jnd k	�rÎto|jnƒS |jp�rât'jNtjqƒ tr|d|d ƒd k	�	rtsjt|juƒ d£S tj�
sŠ|jv�	rdÃ|jvini }|jw�	r2tsjxƒ S |jy�	rVtsjzf |Žd k	�	rVt"j^dÄƒ |j{�	rvtsjzf dÅtj|i|—Ž n|j}�	r�tsj~ƒ  t"j^dÆƒ |j�	rªtsj€ƒ  t"j^dÇƒ |j��	rÀt'jNtsj‚ƒ ƒ |jƒ�	rÖt'jNtsj„ƒ ƒ |j…�	rútsj†ƒ �	rút'jNtsj‡|j…ƒƒ |jˆd k	�
rj|jˆdk�
r,tj‰�
p(tŠtsj‹ƒ jŒƒ ƒ}	ndÈdÉ„ |jˆjd¢ƒD ƒ}	tsjzf dÊt�|	ƒi|—Žd k	�
rjt"j^dÄƒ |jŽ�
rŠtsjzf tj|d dËœ|—Ž |j��
r¤t'jNt�|jPd³�ƒ d}
|j‘�
rÀt7j8dÌt9ƒ dÍ}
|j’�
rÎ|j’}
|j“�
rèt”|
tj•tj–dÎ� |j>�rt”|
tj—dÏ� t"j^dÐƒ |j�rt'jNt˜j™ƒ ƒ |jš�r>t›|
|jœdÑ� t"j^dÒƒ |j�rld]t_�tžjŸt j¡d£dÓƒƒ t”|
tj|dÏ� |j¢�r€t¢|jPd³� |j£�rŽt¤ƒ S |j¥�r¢t¦|jPd³� |j§�r°t¨ƒ  t©tjªƒd¤k�rÆt«ƒ  d S )ÔNZkcarectlz)Manage KernelCare patches for your kernel)Zprogr¦  z--debugrK   Z
store_true)Úhelpr¨  z-iz--infoz]Display information about KernelCare. Use with --json parameter to get result in JSON format.z
--app-infozcDisplay information about KernelCare agent. Use with --json parameter to get result in JSON format.z-uz--updatez<Download latest patches and apply them to the current kernelz--unloadzUnload patchesz--smart-updatez,Patch kernel based on UPDATE POLICY settingsz--auto-updatez-Check if update is available, if so -- updatez--localzNUpdate from a server local directory; accepts a path where patches are locatedÚPATH)ré  Úmetavarz--patch-infoz"Return the list of applied patchesz	--freezerz)Freezer type: full (default), smart, nonerš  z
--nofreezez/[deprecated] Don't freeze tasks before patchingz--unamezReturn safe kernel versionz--license-infozReturn current license infoz--statuszReturn status of updatesz
--registerzRegister using KernelCare KeyrØ  z--register-autoretryz=Retry registering indefinitely if failed on the first attemptz--unregisterz7Unregister from KernelCare (for key-based servers only)z--checkzCheck if new update availablez--latest-patch-infoziReturn patch info for the latest available patch. Use with --json parameter to get result in JSON format.z--testz&[deprecated] Use --prefix=test insteadz--tagz7Tag server with custom metadata, for ePortal users onlyZTAGz--prefixzpPatch source prefix used to test different builds by downloading builds from different locations based on prefixrœ   z--nosignaturezDo not check signaturez--set-monitoring-keyzPSet monitoring key for IP based licenses. 16 to 32 characters, alphanumeric onlyz--doctorz@Submits a vitals report to CloudLinux for analysis and bug-fixesz
--fallbackzNWith --doctor, force the legacy kcdoctor.sh flow instead of the v2 upload pathz--kernel-anomaly-reportzHSubmits a kernel anomaly report to CloudLinux for analysis and bug-fixesz	--no-sendzSkip sending artifactsÚ	save_only)ré  r¨  Údestz--keep-localz:Don't delete generated kernel anomaly report after sendingz--enable-auto-updatezEnable auto updatesz--disable-auto-updatezDisable auto updatesz--plugin-infozProvides the information shown in control panel plugins for KernelCare. Use with --json parameter to get result in JSON format.z--server-infoz3Provides information about the host in JSON format.z--jsonzoReturn '--plugin-info', '--latest-patch-info', '--patch-info', '--app-info' and '--info' results in JSON formatz	--versionz(Return the current version of KernelCarez--kpatch-debugzEnable the debug modez--no-check-certz2Disable the patch server SSL certificates checkingz--set-patch-levelzBSet patch level to be applied. To select latest patch level set -1ZstoreF)ré  r¨  r^   r(  Úrequiredz--check-compatibilityzCheck compatibility.z--clear-cachezClear all cached filesz--set-patch-typez@Set patch type feed. To select default feed use 'default' optionz--edf-enabledz"Enable exploit detection frameworkz--edf-disabledz#Disable exploit detection frameworkz--set-sticky-patchzjSet patch to stick to date in DDMMYY format, or retrieve it from KEY if set to KEY. Leave empty to unstick)ré  r¨  r(  rî  z-qz--quietz=Suppress messages, provide only errors and warnings to stderr)ré  r¨  rî  z--has-flagszCheck agent features)ré  z--forcez-Force action and ignore several restristions.z--set-configzChange configuration optionrG  z	KEY=VALUE)ré  r¨  rë  z--disable-libcarezDisable libcare servicesÚenable_libcareZstore_const)ré  rí  r¨  Úconstz--enable-libcarezEnable libcare servicesTz--lib-updatezIDownload latest patches and apply them to the current userspace librariesz--lib-unloadz--userspace-unloadzUnload userspace patchesz--lib-repluginz--userspace-repluginzReload libcare-server pluginz--lib-auto-updatez
--lib-infoz--userspace-infoz&Display information about KernelCare+.z--lib-patch-infoz--userspace-patch-infoz,Return the list of applied userspace patchesz--lib-versionz--userspace-versionzReturn safe package versionZPACKAGENAMEz--userspace-updateÚUSERSPACE_PATCHESrý   zODownload latest patches and apply them to the corresponding userspace processes)rë  Znargsrð  ré  z--userspace-auto-updatez--userspace-statusz"Return status of userspace updatesz	--lib-tagz--userspace-tagzÌApply userspace patches for a specific tag (DDMMYY, YYYY-MM-DD, Nd, Nh, release-<NAME>) into an isolated cache, leaving the default storage untouched. Use together with --lib-update or --userspace-update.)rë  ré  r¨  r(  rî  zlibcare-enabledræ  r   r   zPlease run as root)rÙ  )r  )r¼  zTFlag --edf-enabled has been deprecated and will be not available in future releases.rË  r(  zMFlag --test has been deprecated and will be not available in future releases.r(   ú/z(Prefix `{0}` is not in expected one {1}.r�  zfile:z+edf patches are deprecated. Fallback to {0})rI  r  )rŒ   rú   rû   )Zforce_fallbackz)Kernel anomaly report file generated: {0}z0Kernel anomaly report uploaded successfully: {0}z$Failed to send kernel anomaly report)rþ   ri   )rÖ   ZYES)rÔ   ZNOrv  rß   )r,  r¾  zUserspace patches are applied.r	  zUserspace patches are unloaded.zLibcare plugin reloaded.c             S   s   g | ]}|j ƒ jƒ ‘qS r;   )r£   rÝ  )r½   Zptchr;   r;   r<   r¿   5  s    zmain.<locals>.<listcomp>Úlimit)r	  ró  zQFlag --nofreeze has been deprecated and will be not available in future releases.r™   )r	  rE  )r	  zKernel is safe)r´  z=KernelCare protection disabled. Your kernel might not be safeé<   )¬r   Zadd_argumentr‚   Zadd_mutually_exclusive_groupr
   ZLIBCARE_DISABLEDZ
parse_argsr   Zset_settings_from_config_fileZFLAGSZ	has_flagsr/   Úfilterr@   ÚissubsetÚquietZauto_updateZSILENCE_ERRORSr   ZPRINT_CRITICALZPRINT_LEVELZPRINT_ERRORr  ZPRINT_DEBUGr‘  r0   ÚgetuidÚprintrS   r’  ÚloggingZINFOZWARNINGÚDEBUGr   Zinitialize_loggingZIGNORE_FEATURE_FLAGSZset_feature_flags_from_cacher˜   r   Zclear_all_cacheZset_patch_levelrd   r  rÎ  Zset_sticky_patchr¼  Znosignaturer  Zno_check_certrô   r~  r  rt  Zedf_enabledÚwarningsÚwarnÚDeprecationWarningZedf_disabledr,  ZPREV_PATCH_TYPEZset_patch_typerH  rž   rœ   r(   r£   ÚEXPECTED_PREFIXr{   r]  r«   rA   Zlocalrh   ZPATCH_SERVERrÐ  râ   Zapp_inforÆ   r   ri   r   rj   rJ   r   Zsend_doctor_reportrÈ  ZfallbackZkernel_anomaly_reportr   r  Zarchive_pathrì  r  r  r  Z
keep_localr  rØ   Zenable_auto_updateZdisable_auto_updateZ
set_configZupdate_config_from_argsZset_monitoring_keyrÌ   Z
unregisterr   ÚregisterZregister_autoretryrÓ   r¾  rÅ  rá   ra   rc   r   Zset_libcare_statusrï  Zlib_tagZuserspace_statusZget_userspace_update_statusZ
lib_updateZdo_userspace_updateZlib_auto_updaterÑ  Z
lib_unloadZlibcare_unloadZlib_repluginZlibcare_repluginZlib_inforB  Zlib_patch_infoZlibcare_patch_infoZlib_versionZlibcare_server_startedZlibcare_versionZuserspace_updaterñ  ÚlistZget_userspace_mapÚkeysÚsortedZuserspace_auto_updaterÙ   rA  Znofreezerš  Zsmart_updaterÓ  rÒ  ZUPDATE_POLICYrÕ  r   rÕ   rŸ  r·  r´  ZCHECK_CLN_LICENSE_STATUSry   rz   ÚrandomZuniformrJ  rµ   rÞ   Zlatest_patch_inforM  Zcheckr;  r  ÚargvrD  )ZparserZexclusive_groupr¼   rº   rÙ   r
  Zlocal_path_messager  Z
lib_tag_kwró  rš  r;   r;   r<   ÚmainÈ  sr    













r  )r%   r&   r'   r(   )r)   r*   )N)N)F)F)N)rK   F)rK   F)r   )¬Z
__future__r   rl   ri   rú  r0   r¬   r  rÞ  rŠ  ræ   ZsslrS   rÇ  ry   rR   rü  Zargparser   Ú
contextlibr   r   rK   r   r   r	   r
   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   Zpy23r   r    r!   r"   r#   rÏ  rÉ  rÿ  r3   rÆ  r  rZ  r³  rá  ZDOTALLr1  rg  r1   r©  ÚinsertÚfilterwarningsrþ  r{   ZsetLevelrû  r=   rD   rJ   rg   rp   r€   rŠ   r“   r˜   rŸ   r¢   r¦   r†   r§   rª   r·   r…   rÌ   rÏ   rØ   rÞ   râ   rä   ré   rñ   rò   rc   Zdistutils.versionZ	distutilsZOpenSSL.SSLró   rá   ZStrictVersionZ__version__ÚImportErrorrê   ZHTTPSConnectionZPureHTTPSConnectionÚobjectrë   rð   r  rÕ  r  r  r!  r"  r;  rD  rM  r?  rO  rJ  rU  rX  r_  rf  rj  rk  rn  rp  rs  rt  rx  r}  r�  r  r„  rŽ  r�  r”  r–  r—  r›  r§  r¤  r£  rŽ   r°  Zlog_all_parent_processesr·  rA  r¸  r8  rÑ   rÅ  rÈ  rÊ  rF  r‘   rÐ  Ztrack_update_statusrÓ  rÖ  r×  r  rä  rö   r  r;   r;   r;   r<   Ú<module>   s  \ 

	
&	

4
-!	b	+
 
		



"
?
-2.= ,
3)