o
    O6uf€  ã                   @   sb   d dl Z d dlmZ d dlmZ d dlmZ d dlmZ d dl	m
Z
mZmZ G dd„ de
eƒZdS )	é    N)ÚHTTPResponse)ÚAny)Úrequest)ÚURLError)ÚPluginÚIndependentPluginÚ	PluginOptc                   @   s–   e Zd ZdZdZdZedddd�gZdZd	Z	d
Z
dZdZdd„ Zdd„ Zdd„ Zdefdd„Zededefdd„ƒZdd„ Zededefdd„ƒZdS )ÚGCPzGoogle Cloud PlatformÚgcp)Úvirtúkeep-piiFzyStop the plugin from removing PIIs like project name or organization ID from the metadata retrieved from Metadata server.)ÚdefaultÚdescz3http://metadata.google.internal/computeMetadata/v1/zBhttp://metadata.google.internal/computeMetadata/v1/?recursive=truez[--REDACTED--]NzDDMI: Google Google Compute Engine/Google Compute Engine, BIOS Googlec                 C   s(   |   d¡}|d dkrdS | j|d v S )zÍ
        Checks if this plugin should be executed at all. In this case, it
        will check the `dmesg` command output to see if the system is
        running on a Google Cloud Compute instance.
        ÚdmesgÚstatusr   FÚoutput)Úexec_cmdÚ
GOOGLE_DMI)Úselfr   © r   ú8/usr/lib/python3/dist-packages/sos/report/plugins/gcp.pyÚcheck_enabled)   s   
zGCP.check_enabledc                 C   s$   | j ddgd� | jddgd� dS )z²
        Collect the following info:
         * Metadata from the Metadata server
         * `gcloud auth list` output
         * Any google services output from journal
        zgcloud auth listr
   ©Útagszgoogle*)Úunitsr   N)Úadd_cmd_outputÚadd_journal©r   r   r   r   Úsetup4   s   	z	GCP.setupc                 C   s¦   | j ddgd��A}z|  ¡ | _|  ¡  | tj| jdd�¡ W n ty8 } z| t|ƒ¡ W Y d }~nd }~ww W d   ƒ d S W d   ƒ d S 1 sLw   Y  d S )Nzmetadata.jsonr
   r   é   )Úindent)	Úcollection_fileÚget_metadataÚmetadataÚscrub_metadataÚwriteÚjsonÚdumpsÚRuntimeErrorÚstr)r   ÚmfileÚerrr   r   r   ÚcollectB   s   
€ÿÿü"úzGCP.collectÚreturnc                 C   s"   |   | j¡}| ¡  ¡ }t |¡S )zq
        Retrieves metadata from the Metadata Server and transforms it into a
        dictionary object.
        )Ú_query_addressÚMETADATA_QUERYÚreadÚdecoder&   Úloads)r   ÚresponseÚresponse_bodyr   r   r   r"   L   s   
zGCP.get_metadataÚurlc              
   C   sœ   z8t j| ddid�}t  |¡�}|jdkr$td|j› d�| ¡  ¡  ƒ‚|W  d  ƒ W S 1 s1w   Y  W dS  tyM } z	tdt|ƒ ƒ|‚d}~ww )	zf
        Query the given url address with headers required by Google Metadata
        Server.
        zMetadata-FlavorÚGoogle)ÚheaderséÈ   z2Failed to communicate with Metadata Server (code: z): Nz,Failed to communicate with Metadata Server: )	r   ÚRequestÚurlopenÚcoder(   r0   r1   r   r)   )r5   Úreqr3   r+   r   r   r   r.   U   s*   
ÿ
þÿ(ú
ÿþ€ÿzGCP._query_addressc                    sŒ   ˆ  d¡rdS ˆjd d ‰ ˆjd d ‰tˆƒ‰dtdtf‡ ‡‡‡‡fdd	„‰ˆˆjƒˆ_ˆ ˆjd d
 d¡ ˆ ˆjd d
 d¡ dS )a"  
        Remove all PII information from metadata, unless a keep-pii option
        is specified.

        Note: PII information collected by this plugin, like
        project number, account names etc. might be required by Google
        Cloud Support for faster issue resolution.
        r   NÚprojectÚ	projectIdÚnumericProjectIdÚdatar-   c                    s�   t | tƒrd| v rˆj| d< ‡fdd„|  ¡ D ƒS t | tƒr'‡fdd„| D ƒS t | tƒr8|  ˆˆj¡ ˆ ˆj¡S t | tƒrF| ˆkrDˆjS | S | S )NÚtokenc                    s   i | ]\}}ˆ |ƒˆ |ƒ“qS r   r   )Ú.0ÚkÚv©Úscrubr   r   Ú
<dictcomp>   s    z5GCP.scrub_metadata.<locals>.scrub.<locals>.<dictcomp>c                    s   g | ]}ˆ |ƒ‘qS r   r   )rB   ÚvaluerE   r   r   Ú
<listcomp>�   s    z5GCP.scrub_metadata.<locals>.scrub.<locals>.<listcomp>)Ú
isinstanceÚdictÚREDACTEDÚitemsÚlistr)   ÚreplaceÚint)r@   ©Ú
project_idÚproject_numberÚproject_number_intrF   r   r   r   rF   y   s   




ÿ
z!GCP.scrub_metadata.<locals>.scrubÚ
attributeszssh-keysÚsshKeys)Ú
get_optionr#   r)   r   Úsafe_redact_keyr   r   rQ   r   r$   i   s   
	ÿÿzGCP.scrub_metadataÚdict_objÚkeyc                 C   s   ||v r| j ||< dS dS )z Redact keys N)rL   )ÚclsrY   rZ   r   r   r   rX   �   s   ÿzGCP.safe_redact_key)Ú__name__Ú
__module__Ú__qualname__Ú
short_descÚplugin_nameÚprofilesr   Úoption_listÚMETADATA_ROOTr/   rL   r#   r   r   r   r,   rK   r"   Ústaticmethodr)   r   r.   r$   ÚclassmethodrX   r   r   r   r   r	      s,    ÿÿ
	'r	   )r&   Úhttp.clientr   Útypingr   Úurllibr   Úurllib.errorr   Úsos.report.pluginsr   r   r   r	   r   r   r   r   Ú<module>   s   