a ‚oelDã@s\dZddlmZddlmZddlZddlZddlZddlZddlZddl Z ddl m Z ddl m Z ddl m Z ddl mZdd l mZdd l mZdd l mZdd l mZdd l mZddlmZddlmZddlmZddlmZddlmZddlmZddlmZddlmZddlm Z ddlm!Z!ddl"m#Z$ddl"m%Z&ddl'm(Z(ej)dk�rnddl*m+Z,nddl,Z,e -e.¡Z/e0e0dœdd„Z1e0e0dœdd „Z2e 3d!¡Z4e 3d"ej5¡Z6Gd#d$„d$e&ed%�Z%Gd&d'„d'e$e%ed%�Z#Gd(d)„d)e#ej7ed%�Z8ed*d+d,�Z9Gd-d+„d+ƒZ:Gd.d/„d/ƒZ;e0e0e0e e0dd0œd1d2„ZszPlugin.__init__).N)ÚaddrcCsdS)zéAdd plugin arguments to the CLI argument parser. :param callable add: Function that proxies calls to `argparse.ArgumentParser.add_argument` prepending options with unique plugin name prefix. Nr!)Úclsr0r!r!r#Úadd_parser_argumentsCszPlugin.add_parser_arguments)Úparserrrcs$tttddœ‡‡fdd„ }| |¡S)zkInject parser options. See `~.certbot.interfaces.Plugin.inject_parser_options` for docs. N)Úarg_name_no_prefixÚargsÚkwargsrcs(ˆjd tˆƒ|¡g|¢Ri|¤ŽdS)Nz--{0}{1})Ú add_argumentÚformatr$)r4r5r6©rr3r!r#r0Vsÿþþz)Plugin.inject_parser_options..add)Ústrrr2)r1r3rr0r!r9r#Úinject_parser_optionsNszPlugin.inject_parser_options©rcCs t|jƒS)r)r$r©r-r!r!r#r$\szPlugin.option_namespacercCs |j|S)z'Option name (include plugin namespace).)r$)r-rr!r!r#Ú option_nameaszPlugin.option_namecCs t|jƒS)r%)r(rr=r!r!r#r(eszPlugin.dest_namespace)ÚvarrcCs|j| dd¡S)z.Find a destination for given variable ``var``.r r&)r(r'©r-r?r!r!r#Údestjsz Plugin.destcCst|j| |¡ƒS)z0Find a configuration value for variable ``var``.)Úgetattrr)rAr@r!r!r#Úconfpsz Plugin.conf)Úfailed_achallsrcCs(d tdd„|Dƒƒ¡}dj|j|d�S)a9Human-readable string to help the user troubleshoot the authenticator. Shown to the user if one or more of the attempted challenges were not a success. Should describe, in simple language, what the authenticator tried to do, what went wrong and what the user should try as their "next steps". TODO: auth_hint belongs in Authenticator but can't be added until the next major version of Certbot. For now, it lives in .Plugin and auth_handler will only call it on authenticators that subclass .Plugin. For now, inherit from `.Plugin` to implement and/or override the method. :param list failed_achalls: List of one or more failed challenges (:class:`achallenges.AnnotatedChallenge` subclasses). :rtype str: z and cSsh|] }|j’qSr!)Útyp)Ú.0Úachallr!r!r#Ú ˆóz#Plugin.auth_hint..záThe Certificate Authority couldn't externally verify that the {name} plugin completed the required {challs} challenges. Ensure the plugin is configured correctly and that the changes it makes are accessible from the internet.)rÚchalls)ÚjoinÚsortedr8r)r-rDrJr!r!r#Ú auth_hinttsýzPlugin.auth_hint)Ú__name__Ú __module__Ú __qualname__Ú__doc__rZNamespaceConfigr:r,Ú classmethodrrr2ÚargparseÚArgumentParserr;Úpropertyr$r>r(rArrCrrZAnnotatedChallengerMÚ __classcell__r!r!r.r#r;s  r)Ú metaclasscs´eZdZdZeeddœ‡fdd„ Zdeeeeddœdd „Z edd œd d „Z dd œdd„Z dd œdd„Z de ddœdd„Zeed œdd„ƒZeed œdd„ƒZdd œdd„Z‡ZS)rz‹An installer base class with reverter and ssl_dhparam methods defined. Installer plugins do not have to inherit from this class. N)r5r6rcs4tƒj|i|¤Žt|j|jƒ|_t |j¡|_dSr*)r+r,rr)rZstoragerZReverter)r-r5r6r.r!r#r,•szInstaller.__init__F)Ú save_filesÚ save_notesÚ temporaryrc Cs^|r|jj}n|jj}z|||ƒWn4tjyX}zt t|ƒ¡‚WYd}~n d}~00dS)a´Add files to a checkpoint. :param set save_files: set of filepaths to save :param str save_notes: notes about changes during the save :param bool temporary: True if the files should be added to a temporary checkpoint rather than a permanent one. This is usually used for changes that will soon be reverted. :raises .errors.PluginError: when unable to add to checkpoint N)rZadd_to_temp_checkpointÚadd_to_checkpointrÚ ReverterErrorÚ PluginErrorr:)r-rXrYrZZcheckpoint_funcÚerrr!r!r#r[šs  zInstaller.add_to_checkpoint)Útitlerc CsJz|j |¡Wn4tjyD}zt t|ƒ¡‚WYd}~n d}~00dS)z±Timestamp and save changes made through the reverter. :param str title: Title describing checkpoint :raises .errors.PluginError: when an error occurs N)rÚfinalize_checkpointrr\r]r:)r-r_r^r!r!r#r`±szInstaller.finalize_checkpointr<c CsHz|j ¡Wn4tjyB}zt t|ƒ¡‚WYd}~n d}~00dS)zÉRevert all previously modified files. Reverts all modified files that have not been saved as a checkpoint :raises .errors.PluginError: If unable to recover the configuration N)rÚrecovery_routinerr\r]r:©r-r^r!r!r#ra¾szInstaller.recovery_routinec CsHz|j ¡Wn4tjyB}zt t|ƒ¡‚WYd}~n d}~00dS)zkRollback temporary checkpoint. :raises .errors.PluginError: when unable to revert config N)rÚrevert_temporary_configrr\r]r:rbr!r!r#rcËsz!Installer.revert_temporary_configé)Úrollbackrc CsJz|j |¡Wn4tjyD}zt t|ƒ¡‚WYd}~n d}~00dS)zúRollback saved checkpoints. :param int rollback: Number of checkpoints to revert :raises .errors.PluginError: If there is a problem with the input or the function is unable to correctly revert the configuration N)rÚrollback_checkpointsrr\r]r:)r-rer^r!r!r#rfÖs zInstaller.rollback_checkpointscCstj |jjtj¡S)z(Full absolute path to ssl_dhparams file.)rÚpathrKr)Ú config_dirrZSSL_DHPARAMS_DESTr=r!r!r#Ú ssl_dhparamsäszInstaller.ssl_dhparamscCstj |jjtj¡S)z:Full absolute path to digest of updated ssl_dhparams file.)rrgrKr)rhrZUPDATED_SSL_DHPARAMS_DIGESTr=r!r!r#Úupdated_ssl_dhparams_digestész%Installer.updated_ssl_dhparams_digestcCst|j|jtjtjƒdS)zJCopy Certbot's ssl_dhparams file into the system's config dir if required.N)Úinstall_version_controlled_filerirjrZSSL_DHPARAMS_SRCZALL_SSL_DHPARAMS_HASHESr=r!r!r#Úinstall_ssl_dhparamsîs üzInstaller.install_ssl_dhparams)F)rd)rNrOrPrQrr,r r:Úboolr[r`rarcÚintrfrUrirjrlrVr!r!r.r#r�sÿ ÿ    rc@seZdZdZdS)Ú Configuratorzt A plugin that extends certbot.plugins.common.Installer and implements certbot.interfaces.Authenticator N)rNrOrPrQr!r!r!r#ro÷sroÚ GenericAddrÚAddr)Úboundc@sîeZdZdZd"eeefedœdd„Zee e ee e dœdd„ƒZ ed œd d „Z eeefd œd d „Zeedœdd„Zed œdd„Zed œdd„Zed œdd„Ze ee dœdd„Zeeedœdd„Zed œdd„Zeeedœdd „Zd!S)#rqzˆRepresents an virtual host address. :param str addr: addr part of vhost address :param str port: port number or \*, or "" F©ÚtupÚipv6cCs||_||_dSr*rs)r-rtrur!r!r#r,sz Addr.__init__)r1Ústr_addrrcCsŠ| d¡rh| d¡}|d|d…}d}t|ƒ|dkrX||ddkrX||dd…}|||fdd �S| d¡}||d |dfƒSdS) zInitialize Addr from string.ú[ú]NrdÚéú:T)rur)Ú startswithÚrfindÚlenÚ partition)r1rvZendIndexÚhostÚportrtr!r!r#Ú fromstring s    zAddr.fromstringr<cCs|jdrd|jS|jdS)Nrdz%s:%sr©rtr=r!r!r#Ú__str__s  z Addr.__str__cCs|jr| ¡|jdfS|jS)z5Normalized representation of addr/port tuple rd)ruÚget_ipv6_explodedrtr=r!r!r#Únormalized_tuple szAddr.normalized_tuple)ÚotherrcCs t||jƒr| ¡| ¡kSdS)NF)Ú isinstancer/r†)r-r‡r!r!r#Ú__eq__'s z Addr.__eq__cCs t|jƒSr*)Úhashrtr=r!r!r#Ú__hash__/sz Addr.__hash__cCs |jdS)z Return addr part of Addr object.rrƒr=r!r!r#Úget_addr2sz Addr.get_addrcCs |jdS)z Return port.rdrƒr=r!r!r#Úget_port6sz Addr.get_port)r-r�rcCs| |jd|f|j¡S)z6Return new address object with same addr and new port.r)r/rtru)r-r�r!r!r#Ú get_addr_obj:szAddr.get_addr_obj)ÚaddrrcCs| d¡}| d¡}| |¡S)z7Return IPv6 address in normalized form, helper functionrwrx)ÚlstripÚrstripÚ _explode_ipv6)r-r�r!r!r#Ú_normalize_ipv6>s  zAddr._normalize_ipv6cCs |jrd | |jd¡¡SdS)zReturn IPv6 in normalized formr{rry)rurKr“rtr=r!r!r#r…DszAddr.get_ipv6_explodedcCs’gd¢}| d¡}t|ƒt|ƒkr2|dt|ƒ…}d}t|ƒD]N\}}|sPd}q>t|ƒdkrf| d¡}|sxt|ƒ||<q>t|ƒ||t|ƒ<q>|S)z#Explode IPv6 address for comparison)Ú0r”r”r”r”r”r”r”r{rFTrdr”)Úsplitr~Ú enumerater�r:)r-r�ÚresultZ addr_listZ append_to_endÚiÚblockr!r!r#r’Js   zAddr._explode_ipv6N)F)rNrOrPrQr r:rmr,rRr rprr‚r„r†rr‰rnr‹rŒr�rŽrr“r…r’r!r!r!r#rqsc@sLeZdZdZedœdd„Zd ejee ddœdd„Z e e j d œd d „ZdS) ÚChallengePerformeravAbstract base for challenge performers. :ivar configurator: Authenticator and installer plugin :ivar achalls: Annotated challenges :vartype achalls: `list` of `.KeyAuthorizationAnnotatedChallenge` :ivar indices: Holds the indices of challenges from a larger array so the user of the class doesn't have to. :vartype indices: `list` of `int` )Ú configuratorcCs||_g|_g|_dSr*)r›ÚachallsÚindices)r-r›r!r!r#r,oszChallengePerformer.__init__N)rGÚidxrcCs$|j |¡|dur |j |¡dS)zÝStore challenge to be performed when perform() is called. :param .KeyAuthorizationAnnotatedChallenge achall: Annotated challenge. :param int idx: index to challenge in a larger array N)rœÚappendr�)r-rGržr!r!r#Ú add_challts zChallengePerformer.add_challr<cCs tƒ‚dS)z�Perform all added challenges. :returns: challenge responses :rtype: `list` of `acme.challenges.KeyAuthorizationChallengeResponse` N)ÚNotImplementedErrorr=r!r!r#Úperform�szChallengePerformer.perform)N)rNrOrPrQror,rZ"KeyAuthorizationAnnotatedChallengerrnr rr Z!KeyAuthorizationChallengeResponser¢r!r!r!r#ršcs ÿÿ rš)Ú dest_pathÚ digest_pathÚsrc_pathÚ all_hashesrcsÔt ˆ¡‰ddœ‡‡fdd„ ‰ddœ‡‡‡fdd„ }tj ˆ¡sJ|ƒdSt ˆ¡}|ˆkr`dS||vrp|ƒn`tj ˆ¡rºtˆdƒ�}| ¡}Wdƒn1s¤0Y|ˆkrºdSˆƒt dˆˆˆ¡dS) aƒCopy a file into an active location (likely the system's config dir) if required. :param str dest_path: destination path for version controlled file :param str digest_path: path to save a digest of the file in :param str src_path: path to version controlled file found in distribution :param list all_hashes: hashes of every released version of the file Nr<cs8tˆdƒ�}| ˆ¡Wdƒn1s*0YdS)NÚw)ÚopenÚwrite)Zfile_h)Ú current_hashr¤r!r#Ú_write_current_hash—s z._write_current_hashcst ˆˆ¡ˆƒdSr*)ÚshutilÚcopyfiler!)r«r£r¥r!r#Ú_install_current_file›s z>install_version_controlled_file.._install_current_fileÚrzh%s has been manually modified; updated file saved to %s. We recommend updating %s for security purposes.) rZ sha256sumrrgÚisfiler¨ÚreadÚloggerZwarning)r£r¤r¥r¦r®Zactive_file_digestÚfZ saved_digestr!)r«rªr£r¤r¥r#rkŒs(     &þrk)Útest_dirÚpkgrcCs²ttdœdd„}|dƒ}|dƒ}|dƒ}t |tj¡t |tj¡t |tj¡t |¡ d|¡}t |¡�*}t j |t j   ||¡dd �Wd ƒn1sž0Y|||fS) z5Setup the directories necessary for the configurator.)ÚprefixrcSst t |¡¡S)a�Return the real path of a temp directory with the specified prefix Some plugins rely on real paths of symlinks for working correctly. For example, certbot-apache uses real paths of configuration files to tell a virtual host from another. On systems where TMP itself is a symbolic link, (ex: OS X) such plugins will be confused. This function prevents such a case. )rÚrealpathÚtempfileZmkdtemp)r¶r!r!r#Úexpanded_tempdirÁs z#dir_setup..expanded_tempdirZtempr)ZworkZtestdataT)ÚsymlinksN)r:rÚchmodrZCONFIG_DIRS_MODEÚimportlib_resourcesÚfilesÚjoinpathZas_filer¬ÚcopytreerrgrK)r´rµr¹Ztemp_dirrhZwork_dirZ test_dir_refrgr!r!r#Ú dir_setup¿s  ÿ$rÀ)>rQÚabcrrrSZloggingÚrer¬Úsysr¸Útypingrrrrrr r r r Zacmer ZcertbotrrrrrrZcertbot._internalrZcertbot.compatrrZcertbot.interfacesrZAbstractInstallerrZAbstractPluginZcertbot.plugins.storagerÚ version_infoZimportlib.resourcesZ resourcesr¼Z getLoggerrNr²r:r$r(ÚcompileZprivate_ips_regexÚ IGNORECASEZhostname_regexZ AuthenticatorrorprqršrkrÀr!r!r!r#Úsh                          ÿÿTh b)ÿ 3