o
    4ñÕfg)  ã                   @   s,  d Z ddlmZ ddlZddlZddlZddlZddlZddlZddl	Z	ddl
Z
ddl
mZ ddlmZmZmZ G dd„ deƒZG dd	„ d	eƒZG d
d„ deƒZdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Ze d kr’d!d"„  d#d"„  e
 !¡  eƒ D ]Z"e#e"ƒ q‹dS dS )$z4Handle GnuPG keys used to trust signed repositories.é    )Úprint_functionN)Úgettext)ÚListÚOptionalÚTuplec                   @   s   e Zd ZdS )ÚAptKeyErrorN)Ú__name__Ú
__module__Ú__qualname__© r   r   ú*/usr/lib/python3/dist-packages/apt/auth.pyr   +   s    r   c                   @   s   e Zd ZdZdS )ÚAptKeyIDTooShortErrorz!Internal class do not rely on it.N)r   r	   r
   Ú__doc__r   r   r   r   r   /   s    r   c                   @   s    e Zd ZdZdd„ Zdd„ ZdS )Ú
TrustedKeyzRepresents a trusted key.c                 C   s    || _ t|ƒ| _|| _|| _d S )N)Úraw_nameÚ_ÚnameÚkeyidÚdate)Úselfr   r   r   r   r   r   Ú__init__7   s   

zTrustedKey.__init__c                 C   s   d| j | j| jf S )Nz%s
%s %s)r   r   r   )r   r   r   r   Ú__str__?   s   zTrustedKey.__str__N)r   r	   r
   r   r   r   r   r   r   r   r   3   s    r   c            	      O   s  d}t j dd¡g}| | ¡ tj ¡ }d|d< d|d< zet j d¡d	kr@tj	d
dd�}| 
t j ¡  d¡¡ | ¡  |j|d< tj||dtjtjtjd�}| dd¡}| |¡\}}|jrltd|jd |¡||f ƒ‚|rttj 
|¡ | ¡ W |dur�| ¡  S S |dur‹| ¡  w w )z0Run the apt-key script with the given arguments.NzDir::Bin::Apt-Keyz/usr/bin/apt-keyÚCÚLANGÚ1Ú$APT_KEY_DONT_WARN_ON_DANGEROUS_USAGEÚDirú/zapt-keyz.conf)ÚprefixÚsuffixzUTF-8Ú
APT_CONFIGT)ÚenvÚuniversal_newlinesÚstdinÚstdoutÚstderrr#   zGThe apt-key script failed with return code %s:
%s
stdout: %s
stderr: %sú )Úapt_pkgÚconfigÚ	find_fileÚextendÚosÚenvironÚcopyÚfind_dirÚtempfileÚNamedTemporaryFileÚwriteÚdumpÚencodeÚflushr   Ú
subprocessÚPopenÚPIPEÚgetÚcommunicateÚ
returncoder   ÚjoinÚsysr%   ÚstripÚclose)	ÚargsÚkwargsÚconfÚcmdr!   Úprocr#   Úoutputr%   r   r   r   Ú_call_apt_key_scriptD   sH   

ÿ

ýÿýÿ

ÿ
ÿrE   c                 C   s@   t j | ¡std|  ƒ‚t  | t j¡std|  ƒ‚td| ƒ dS )z–Import a GnuPG key file to trust repositores signed by it.

    Keyword arguments:
    filename -- the absolute path to the public GnuPG key file
    z An absolute path is required: %szKey file cannot be accessed: %sÚaddN)r+   ÚpathÚabspathr   ÚaccessÚR_OKrE   )Úfilenamer   r   r   Úadd_key_from_fileq   s
   rL   c              
   C   s`   t  ¡ }zzt| ||ƒ W n ty   ‚ w W dd„ }tj||d� dS dd„ }tj||d� w )zÿImport a GnuPG key file to trust repositores signed by it.

    Keyword arguments:
    keyid -- the long keyid (fingerprint) of the key, e.g.
             A1BD8E9D78F7FE5C3E65D8AF8B48AD6246925553
    keyserver -- the URL or hostname of the key server
    c                 S   s$   t |d tƒr|d jtjkrd S ‚ )Né   )Ú
isinstanceÚOSErrorÚerrnoÚENOENT)ÚfuncrG   Úexc_infor   r   r   Úonerror�   s   z'add_key_from_keyserver.<locals>.onerror)rT   N)r/   ÚmkdtempÚ_add_key_from_keyserverÚ	ExceptionÚshutilÚrmtree)r   Ú	keyserverÚtmp_keyring_dirrT   r   r   r   Úadd_key_from_keyserver   s   	ÿÿùr\   c                 C   sJ  t |  dd¡ dd¡ƒdk rtdƒ‚tj |d¡}tj |d¡}dd	d
d|g}t |d|d|d|d| g ¡}|dkrBtd|| f ƒ‚tj |d¡}t |d|d|d| g ¡}|dkr_td| ƒ‚tj	|d|ddddg tj
dd� ¡ d }d }	| ¡ D ]}
|
 d¡rŠ|
 d¡d }	 nqz|  dd¡ ¡ }|	|krŸtd||f ƒ‚t|ƒ d S )Nr&   Ú Ú0xg      D@z,Only fingerprints (v4, 160bit) are supportedzsecring.gpgzpubring.gpgÚgpgz--no-default-keyringz--no-optionsz	--homedirz--secret-keyringz	--keyringz--keyserverz--recvr   zrecv from '%s' failed for '%s'zexport-keyring.gpgz--outputz--exportzexport of '%s' failedz--fingerprintú--batchú--fixed-list-modeú--with-colonsT)r$   r"   zfpr:ú:é	   )ÚlenÚreplacer   r+   rG   r;   r5   Úcallr   r6   r7   r9   Ú
splitlinesÚ
startswithÚsplitÚupperrL   )r   rZ   r[   Útmp_secret_keyringÚtmp_keyringÚgpg_default_optionsÚresÚtmp_export_keyringrD   Úgot_fingerprintÚlineÚsigning_key_fingerprintr   r   r   rV   š   sn   ÿýüÿ
ý
û÷	÷

ýÿÿrV   c                 C   s   t ddddd| d� dS )z…Import a GnuPG key to trust repositores signed by it.

    Keyword arguments:
    content -- the content of the GnuPG public key
    Úadvz--quietr`   z--importú-)r#   N©rE   )Úcontentr   r   r   Úadd_keyâ   s   
ÿrx   c                 C   s   t d| ƒ dS )z“Remove a GnuPG key to no longer trust repositores signed by it.

    Keyword arguments:
    fingerprint -- the fingerprint identifying the key
    ÚrmNrv   ©Úfingerprintr   r   r   Ú
remove_keyí   s   r|   c                 C   s
   t d| ƒS )zxReturn the GnuPG key in text format.

    Keyword arguments:
    fingerprint -- the fingerprint identifying the key
    Úexportrv   rz   r   r   r   Ú
export_key÷   s   
r~   c                   C   ó   t dƒS )a  Update the local keyring with the archive keyring and remove from
    the local keyring the archive keys which are no longer valid. The
    archive keyring is shipped in the archive-keyring package of your
    distribution, e.g. the debian-archive-keyring package in Debian.
    Úupdaterv   r   r   r   r   r€     s   r€   c                   C   r   )ay  Work similar to the update command above, but get the archive
    keyring from an URI instead and validate it against a master key.
    This requires an installed wget(1) and an APT build configured to
    have a server to fetch from and a master keyring to validate. APT
    in Debian does not support this command and relies on update
    instead, but Ubuntu's APT does.
    z
net-updaterv   r   r   r   r   Ú
net_update  s   	r�   c                  C   sx   t dddddƒ} g }|  d¡D ]*}| d¡}|d d	kr |d
 }|d dkr9|d }|d }t|||ƒ}| |¡ q|S )zaReturns a list of TrustedKey instances for each key which is
    used to trust repositories.
    rt   rb   r`   ra   z--list-keysÚ
rc   r   Úpubé   Úuidrd   é   )rE   rj   r   Úappend)rD   ro   rr   Úfieldsr   r…   Úcreation_dateÚkeyr   r   r   Ú	list_keys  s   ÿ

€r‹   Ú__main__c                   C   r   )Nz;Ubuntu Archive Automatic Signing Key <ftpmaster@ubuntu.com>©r   r   r   r   r   Ú<lambda>0  ó    rŽ   c                   C   r   )Nz:Ubuntu CD Image Automatic Signing Key <cdimage@ubuntu.com>r�   r   r   r   r   rŽ   1  r�   )$r   Ú
__future__r   rP   r+   Úos.pathrX   r5   r<   r/   r'   r   r   Útypingr   r   r   rW   r   r   Úobjectr   rE   rL   r\   rV   rx   r|   r~   r€   r�   r‹   r   ÚinitÚtrusted_keyÚprintr   r   r   r   Ú<module>   sB   -H




ø