U
    &Ÿˆcý*  ã                   @   sˆ  d Z ddlmZ zddlmZ W n ek
r4   Y nX ddlZddlZddlZddl	Z	ddl
Z
ddlZddlZddlZddlmZ ejjdkr’eZz$ddlmZmZmZ e e e W n ek
rÊ   Y nX G dd	„ d	eƒZG d
d„ deƒZG dd„ deƒZdd„ Zdd„ Zdd„ Zdd„ Zdd„ Z dd„ Z!dd„ Z"dd„ Z#dd„ Z$d d!„ Z%e&d"k�r„d#d$„  d%d$„  e '¡  e%ƒ D ]Z(e)e(ƒ �qtdS )&z4Handle GnuPG keys used to trust signed repositories.é    )Úprint_function)ÚOptionalN)Úgettexté   )ÚListÚTupleÚUnionc                   @   s   e Zd ZdS )ÚAptKeyErrorN)Ú__name__Ú
__module__Ú__qualname__© r   r   ú*/usr/lib/python3/dist-packages/apt/auth.pyr	   :   s   r	   c                   @   s   e Zd ZdZdS )ÚAptKeyIDTooShortErrorz!Internal class do not rely on it.N)r
   r   r   Ú__doc__r   r   r   r   r   >   s   r   c                   @   s    e Zd ZdZdd„ Zdd„ ZdS )Ú
TrustedKeyzRepresents a trusted key.c                 C   s    || _ t|ƒ| _|| _|| _d S )N)Zraw_nameÚ_ÚnameÚkeyidÚdate)Úselfr   r   r   r   r   r   Ú__init__F   s    
zTrustedKey.__init__c                 C   s   d| j | j| jf S )Nz%s
%s %s)r   r   r   )r   r   r   r   Ú__str__N   s    zTrustedKey.__str__N)r
   r   r   r   r   r   r   r   r   r   r   B   s   r   c            	      O   s0  d}t j dd¡g}| | ¡ tj ¡ }d|d< d|d< zÞt j d¡d	kr€t	j
d
dd�}| t j ¡  d¡¡ | ¡  |j|d< tj||dtjtjtjd�}| dd¡}tjjdk rÈt|tƒrÈ| d¡}| |¡\}}|jrútd|jd |¡||f ƒ‚n|�rtj |¡ | ¡ W ¢S |dk	�r*| ¡  X dS )z0Run the apt-key script with the given arguments.NzDir::Bin::Apt-Keyz/usr/bin/apt-keyÚCZLANGÚ1Z$APT_KEY_DONT_WARN_ON_DANGEROUS_USAGEZDirú/zapt-keyz.conf)ÚprefixÚsuffixzUTF-8Z
APT_CONFIGT)ÚenvÚuniversal_newlinesÚstdinÚstdoutÚstderrr    é   zutf-8zGThe apt-key script failed with return code %s:
%s
stdout: %s
stderr: %sú )Úapt_pkgZconfigZ	find_fileÚextendÚosÚenvironÚcopyÚcloseZfind_dirÚtempfileZNamedTemporaryFileÚwriteÚdumpÚencodeÚflushr   Ú
subprocessÚPopenÚPIPEÚgetÚsysÚversion_infoÚmajorÚ
isinstanceÚunicodeÚcommunicateÚ
returncoder	   Újoinr"   Ústrip)	ÚargsÚkwargsÚconfÚcmdr   Úprocr    Úoutputr"   r   r   r   Ú_call_apt_key_scriptS   sN    

 ÿ

ý
   ÿýÿ
rC   c                 C   s@   t j | ¡std|  ƒ‚t  | t j¡s2td|  ƒ‚td| ƒ dS )z–Import a GnuPG key file to trust repositores signed by it.

    Keyword arguments:
    filename -- the absolute path to the public GnuPG key file
    z An absolute path is required: %szKey file cannot be accessed: %sÚaddN)r'   ÚpathÚabspathr	   ÚaccessÚR_OKrC   )Úfilenamer   r   r   Úadd_key_from_fileƒ   s
    rJ   c              
   C   sR   t  ¡ }z,zt| ||ƒ W n tk
r0   ‚ Y nX W 5 dd„ }tj||d� X dS )zÿImport a GnuPG key file to trust repositores signed by it.

    Keyword arguments:
    keyid -- the long keyid (fingerprint) of the key, e.g.
             A1BD8E9D78F7FE5C3E65D8AF8B48AD6246925553
    keyserver -- the URL or hostname of the key server
    c                 S   s(   t |d tƒr"|d jtjkr"d S ‚ d S )Né   )r7   ÚOSErrorÚerrnoZENOENT)ÚfuncrE   Úexc_infor   r   r   Úonerror¢   s
    ÿz'add_key_from_keyserver.<locals>.onerror)rP   N)r+   ZmkdtempÚshutilZrmtreeÚ_add_key_from_keyserverÚ	Exception)r   Ú	keyserverÚtmp_keyring_dirrP   r   r   r   Úadd_key_from_keyserver‘   s    	rV   c                 C   sN  t |  dd¡ dd¡ƒdk r$tdƒ‚tj |d¡}tj |d¡}dd	d
d|g}t |d|d|d|d| g ¡}|dkr„td|| f ƒ‚tj |d¡}t |d|d|d| g ¡}|dkr¾td| ƒ‚tj	|d|ddddg tj
dd� ¡ d }d }	| ¡ D ]"}
|
 d¡rô|
 d¡d }	 �qqô|  dd¡ ¡ }|	|k�rBtd||f ƒ‚t|ƒ d S )Nr$   Ú Z0xg      D@z,Only fingerprints (v4, 160bit) are supportedzsecring.gpgzpubring.gpgZgpgz--no-default-keyringz--no-optionsz	--homedirz--secret-keyringz	--keyringz--keyserverz--recvr   zrecv from '%s' failed for '%s'zexport-keyring.gpgz--outputz--exportzexport of '%s' failedz--fingerprintú--batchú--fixed-list-modeú--with-colonsT)r!   r   zfpr:ú:é	   )ÚlenÚreplacer   r'   rE   r;   r0   Úcallr	   r1   r2   r9   Ú
splitlinesÚ
startswithÚsplitÚupperrJ   )r   rT   rU   Ztmp_secret_keyringZtmp_keyringZgpg_default_optionsÚresZtmp_export_keyringrB   Zgot_fingerprintÚlineZsigning_key_fingerprintr   r   r   rR   ¬   s„    ÿ  ý    ü ÿ
   ý
 û÷	÷


 ÿÿrR   c                 C   s   t ddddd| d� dS )z…Import a GnuPG key to trust repositores signed by it.

    Keyword arguments:
    content -- the content of the GnuPG public key
    Úadvz--quietrX   z--importú-)r    N©rC   )Zcontentr   r   r   Úadd_keyô   s
      ÿri   c                 C   s   t d| ƒ dS )z“Remove a GnuPG key to no longer trust repositores signed by it.

    Keyword arguments:
    fingerprint -- the fingerprint identifying the key
    ZrmNrh   ©Zfingerprintr   r   r   Ú
remove_keyÿ   s    rk   c                 C   s
   t d| ƒS )zxReturn the GnuPG key in text format.

    Keyword arguments:
    fingerprint -- the fingerprint identifying the key
    Zexportrh   rj   r   r   r   Ú
export_key	  s    rl   c                   C   s   t dƒS )a  Update the local keyring with the archive keyring and remove from
    the local keyring the archive keys which are no longer valid. The
    archive keyring is shipped in the archive-keyring package of your
    distribution, e.g. the debian-archive-keyring package in Debian.
    Úupdaterh   r   r   r   r   rm     s    rm   c                   C   s   t dƒS )ay  Work similar to the update command above, but get the archive
    keyring from an URI instead and validate it against a master key.
    This requires an installed wget(1) and an APT build configured to
    have a server to fetch from and a master keyring to validate. APT
    in Debian does not support this command and relies on update
    instead, but Ubuntu's APT does.
    z
net-updaterh   r   r   r   r   Ú
net_update  s    	rn   c                  C   sx   t dddddƒ} g }|  d¡D ]T}| d¡}|d d	kr@|d
 }|d dkr|d }|d }t|||ƒ}| |¡ q|S )zaReturns a list of TrustedKey instances for each key which is
    used to trust repositories.
    rf   rZ   rX   rY   z--list-keysÚ
r[   r   Zpubé   Úuidr\   é   )rC   rb   r   Úappend)rB   rd   re   Zfieldsr   rq   Zcreation_dateÚkeyr   r   r   Ú	list_keys)  s     ÿ
ru   Ú__main__c                   C   s   t dƒS )Nz;Ubuntu Archive Automatic Signing Key <ftpmaster@ubuntu.com>©r   r   r   r   r   Ú<lambda>B  ó    rx   c                   C   s   t dƒS )Nz:Ubuntu CD Image Automatic Signing Key <cdimage@ubuntu.com>rw   r   r   r   r   rx   C  ry   )*r   Z
__future__r   Útypingr   ÚImportErrorrM   r'   Úos.pathrQ   r0   r4   r+   r%   r   r   r5   r6   Ústrr8   r   r   r   rS   r	   r   Úobjectr   rC   rJ   rV   rR   ri   rk   rl   rm   rn   ru   r
   ZinitZtrusted_keyÚprintr   r   r   r   Ú<module>   sT   0H




