+
    mi                        ^ RI t ^ RIt^ RIt^ RIHt ^ RIHtHtHtH	t	H
t
 ^ RIHu Ht ^ RIHtHtHtHtHtHtHtHtHt ^ RIHt ^ RIHt ^ RIHt ^ RIH t  ^ R	I!H"t"H#t# ^ R
I$H%t% ^ RI&H't' Rt(Rt)Rt*Rt+Rt,Rt-Rt.Rt/Rt0Rt1Rt2Rt3R^R^R^R^/t4]Pj                  ! 4       t6]Pn                  ! ]Pp                  ! ]94      4      t:]! RRR.4      t; ! R R]Px                  4      t= ! R R]%P|                  4      t?R R  lt@R5R! R" lltAR6R# R$ lltBR% R& ltCR7R' R( lltDR) R* ltER+ R, ltFR- R. ltGR8R/ R0 lltHR9R1 R2 lltIR3 R4 ltJR# ):    N)
namedtuple)AnyDictListOptionalTuple)	
data_typesevent_logger
exceptionshttpmessagessecret_managersystemutilversion)_enabled_services)_is_attachedUAConfig)ATTACH_FAIL_DATE_FORMAT)attachment_data_filemachine_id_file)serviceclient)get_user_or_root_log_file_pathz/v1/context/machines/tokenz3/v1/contracts/{contract}/context/machines/{machine}z/v1/resourcesz3/v1/resources/{resource}/context/machines/{machine}z/v1/clouds/{cloud_type}/tokenz3/v1/contracts/{contract}/machine-activity/{machine}z/v1/contractz/v1/magic-attachz?/v1/contracts/{contract}/context/machines/{machine}/guest-tokenseries_overridesseriescloudvariantEnableByDefaultServicenamec                     a  ] tR t^Ft o ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R	]P                  RR7      ]P
                  ! R
]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      ]P
                  ! R]P                  RR7      .tRV 3R lR lltRt	V t
R# )CPUTypeDatacpuinfo_cpuF)requiredcpuinfo_cpu_architecturecpuinfo_cpu_familycpuinfo_cpu_implementercpuinfo_cpu_partcpuinfo_cpu_revisioncpuinfo_cpu_variantcpuinfo_modelcpuinfo_model_namecpuinfo_steppingcpuinfo_vendor_id"sys_firmware_devicetree_base_modelsysinfo_modelsysinfo_typeNc                N  < V ^8  d   QhRS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          R	S[ S[,          R
S[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          /# )   r#   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   r0   r1   )r   str)format__classdict__s   "3/usr/lib/python3/dist-packages/uaclient/contract.py__annotate__CPUTypeData.__annotate__z   s      )  )c] ) #+3- ) %SM	 )
 "*# ) #3- ) 'sm ) &c] )  } ) %SM ) #3- ) $C= ) -5SM )  } ) sm )    c                    Wn         W n        W0n        W@n        WPn        W`n        Wpn        Wn        Wn        Wn	        Wn
        VV n        Wn        Wn        R # Nr#   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   r0   r1   )selfr#   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   r0   r1   s   &&&&&&&&&&&&&&&r7   __init__CPUTypeData.__init__z   s_    " '(@%"4'>$ 0$8!#6 *"4 0!2. 	/ +(r:   r=   )NNNNNNNNNNNNNN)__name__
__module____qualname____firstlineno__r	   FieldStringDataValuefieldsr?   __static_attributes____classdictcell__)r6   s   @r7   r"   r"   F   s    :55	
 	&&&	

 	 *"<"<u	
 	%&&	

 	
 : :U	
 	"J$>$>	
 	!:#=#=	
 	Z77%	
 	 *"<"<u	
 	
 : :U	
 	!;!;e	
 	0&&	

 	Z77%	
 	J66	
]1Ff )  )  )r:   r"   c                     a a ] tR t^t oRtRV3R lV 3R lllt]P                  ! ]P                  . ROR7      RR l4       t
V3R lR ltV3R lR	 lt]P                  ! ]P                  . ROR7      V3R
 lR l4       tRV3R lR lltR tV3R lR ltV3R lR ltV3R lR ltRV3R lR lltRV3R lR lltV3R lR ltR tRtVtV ;t# )UAContractClientcontract_urlc                4   < V ^8  d   QhRS[ S[,          RR/# )r3   cfgreturnN)r   r   )r5   r6   s   "r7   r8   UAContractClient.__annotate__   s$     ? ?h? 
?r:   c                \   < \         SV `  VR 7       \        P                  ! 4       V n        R# )rN   N)superr?   mtfget_machine_token_filemachine_token_file)r>   rN   	__class__s   &&r7   r?   UAContractClient.__init__   s&     	S!"%"<"<">r:   )retry_sleepsc                ^   V'       g!   \         P                  ! V P                  4      pV P                  4       pVP	                  RRP                  V4      /4       V P                  4       pVP                  4       VR&   RVRV/p\        V4      pV P                  \        WtR7      pVP                  R8X  d   \        P                  ! 4       hVP                  R8X  d   \        V4       VP                  ^8w  d2   \        P                  ! \        VP                  VP                   R	7      hVP"                  p	\$        P&                  P)                  V	P+                  R
R4      4       V	P+                  R. 4       F2  p
\$        P&                  P)                  V
P+                  RR4      4       K4  	  V	# )aM  Requests machine attach to the provided machine_id.

@param contract_token: Token string providing authentication to
    ContractBearer service endpoint.
@param machine_id: Optional unique system machine id. When absent,
    contents of /etc/machine-id will be used.

@return: Dict of the JSON response containing the machine-token.
Authorization	Bearer {}lastAttachment	machineIdactivityInfo)dataheaders  i  urlcodebodymachineToken resourceTokenstoken)r   get_machine_idrN   ra   updater5   _get_activity_info	isoformat_support_old_machine_inforequest_urlAPI_V1_ADD_CONTRACT_MACHINEre   r   AttachInvalidTokenError_raise_attach_forbidden_messageContractAPIErrorrf   	json_dictr   secrets
add_secretget)r>   contract_tokenattachment_dt
machine_idra   activity_infor`   backcompat_dataresponseresponse_jsonrj   s   &&&&       r7   add_contract_machine%UAContractClient.add_contract_machine   sg    ..txx8J,,.););N)KLM//1*7*A*A*C&'ZG3D9##'o $ 
 ==C4466]]c!+H5==C--/]]]] 
 !**))nb1	
 #&&'7<E""--eii.DE =r:   c                6   < V ^8  d   QhRS[ S[S[3,          /# r3   rO   r   r4   r   )r5   r6   s   "r7   r8   rP      s     " "T#s(^ "r:   c                4   V P                  4       pV P                  \        RVR,          RVR,          RVR,          RVR,          /R7      pVP                  ^8w  d2   \        P
                  ! \        VP                  VP                  R7      hVP                  # )z=Requests list of entitlements available to this machine type.architecturer   kernelvirt)query_paramsrc   )rm   rp   API_V1_AVAILABLE_RESOURCESre   r   rt   rf   ru   )r>   r|   r~   s   &  r7   available_resources$UAContractClient.available_resources   s    //1##&n =-1-1f-	 $ 
 ==C--.]]]] 
 !!!r:   c                <   < V ^8  d   QhRS[ RS[S[ S[3,          /# )r3   ry   rO   r4   r   r   )r5   r6   s   "r7   r8   rP      s#     " "s "tCH~ "r:   c                0   V P                  4       pVP                  R RP                  V4      /4       V P                  \        VR7      pVP
                  ^8w  d2   \        P                  ! \        VP
                  VP                  R7      hVP                  # )r[   r\   ra   rc   )
ra   rl   r5   rp   API_V1_GET_CONTRACT_USING_TOKENre   r   rt   rf   ru   )r>   ry   ra   r~   s   &&  r7   get_contract_using_token)UAContractClient.get_contract_using_token   s    ,,.););N)KLM##+W $ 
 ==C--3]]]] 
 !!!r:   c                <   < V ^8  d   QhRS[ RS[S[ S[3,          /# )r3   
cloud_typer`   r   )r5   r6   s   "r7   r8   rP      s%       (,S#Xr:   c                  V P                  \        P                  VR7      VR7      pVP                  ^8w  d   VP                  P                  RR4      pV'       d-   \        P                  V4       \        P                  ! VR7      h\        P                  ! \        VP                  VP                  R7      hVP                  p\        P                  P                  VP                  RR4      4       V# )zRequests contract token for auto-attach images for Pro clouds.

@param instance: AutoAttachCloudInstance for the cloud.

@return: Dict of the JSON response containing the contract-token.
)r   )r`   messagerh   )	error_msgrc   contractToken)rp   ,API_V1_GET_CONTRACT_TOKEN_FOR_CLOUD_INSTANCEr5   re   ru   rx   LOGdebugr   InvalidProImagert   rf   r   rv   rw   )r>   r   r`   r~   msgr   s   &$$   r7   %get_contract_token_for_cloud_instance6UAContractClient.get_contract_token_for_cloud_instance   s     ##8??% @  	 $ 
 ==C$$((B7C		# 003??--@]]]]  !**))or2	
 r:   c          
      X   < V ^8  d   QhRS[ RS[ RS[S[ ,          RS[S[ S[3,          /# )r3   machine_tokenresourcer{   rO   r4   r   r   r   )r5   r6   s   "r7   r8   rP     s?     $ $$ $ SM	$
 
c3h$r:   c                   V'       g!   \         P                  ! V P                  4      pV P                  4       pVP	                  RRP                  V4      /4       \        P                  W#R7      pV P                  WTR7      pVP                  ^8w  d2   \        P                  ! \        VP                  VP                  R7      hVP                  P                  R4      '       d!   VP                  R,          VP                  R&   VP                  pVP                  R. 4       F2  p\        P                  P!                  VP                  RR	4      4       K4  	  V# )
av  Requests machine access context for a given resource

@param machine_token: The authentication token needed to talk to
    this contract service endpoint.
@param resource: Entitlement name.
@param machine_id: Optional unique system machine id. When absent,
    contents of /etc/machine-id will be used.

@return: Dict of the JSON response containing entitlement accessInfo.
r[   r\   )r   machiner   rc   expiresri   rj   rh   )r   rk   rN   ra   rl   r5   "API_V1_GET_RESOURCE_MACHINE_ACCESSrp   re   r   rt   rf   rx   ru   r   rv   rw   )	r>   r   r   r{   ra   rd   r~   r   rj   s	   &&&&     r7   get_resource_machine_access,UAContractClient.get_resource_machine_access  s     ..txx8J,,.););M)JKL077 8 
 ##C#9==C--6]]]] 
 	**,4,<,<Y,GHy) **"&&'7<E""--eii.DE =r:   c                   V P                   P                  pV P                   P                  P                  R4      p\        P
                  ! V P                  4      pV P                  4       p\        P                  WR7      pV P                  4       pVP                  RRP                  V4      /4       V P                  WVVR7      pVP                  ^8w  d-   \        P                  ! WWP                  VP                   R7      hVP"                  '       dC   V P                   P                  pVP"                  VR&   V P                   P%                  V4       R# R# )	zReport current activity token and enabled services.

This will report to the contracts backend all the current
enabled services in the system.
rg   contractr   r[   r\   )ra   r`   rc   r_   N)rV   contract_idr   rx   r   rk   rN   rm   API_V1_UPDATE_ACTIVITY_TOKENr5   ra   rl   rp   re   r   rt   rf   ru   write)r>   r   r   r{   request_datard   ra   r~   s   &       r7   update_activity_token&UAContractClient.update_activity_token;  s$    --99//==AA
 **4884
..0*11  2 
 ,,.););M)JKL##C|#L==C--mm(--   33AAM -5,>,>M.)##))-8 r:   c                <   < V ^8  d   QhRS[ RS[S[ S[3,          /# )r3   magic_tokenrO   r   )r5   r6   s   "r7   r8   rP   c  s#      s tCH~ r:   c                D   V P                  4       pVP                  RRP                  V4      /4       V P                  \        VR7      pVP
                  R8X  d   \        P                  ! 4       hVP
                  R8X  d   \        P                  ! 4       hVP
                  ^8w  d2   \        P                  ! \        VP
                  VP                  R7      hVP                  p. ROpV F2  p\        P                  P                  VP                  VR4      4       K4  	  V# )	zRequest magic attach token info.

When the magic token is registered, it will contain new fields
that will allow us to know that the attach process can proceed
r[   r\   r   rb     rc   rh   rj   userCoder   )ra   rl   r5   rp   "API_V1_GET_MAGIC_ATTACH_TOKEN_INFOre   r   MagicAttachTokenErrorMagicAttachUnavailablert   rf   ru   r   rv   rw   rx   )r>   r   ra   r~   r   secret_fieldsfields   &&     r7   get_magic_attach_token_info,UAContractClient.get_magic_attach_token_infoc  s     ,,.););K)HIJ##. $ 
 ==C2244==C3355==C--6]]]] 
 !**>"E""--m.?.?r.JK #r:   c                6   < V ^8  d   QhRS[ S[S[3,          /# r   r   )r5   r6   s   "r7   r8   rP     s      S#X r:   c                   V P                  4       pV P                  \        VRR7      pVP                  R8X  d   \        P
                  ! 4       hVP                  ^8w  d2   \        P                  ! \        VP                  VP                  R7      hVP                  p. ROpV F2  p\        P                  P                  VP                  VR4      4       K4  	  V# )z)Create a magic attach token for the user.POSTra   methodr   rc   rh   r   )ra   rp   API_V1_NEW_MAGIC_ATTACHre   r   r   rt   rf   ru   r   rv   rw   rx   )r>   ra   r~   r   r   r   s   &     r7   new_magic_attach_token'UAContractClient.new_magic_attach_token  s    ,,.### $ 
 ==C3355==C--+]]]] 
 !**>"E""--m.?.?r.JK #r:   c                    < V ^8  d   QhRS[ /# )r3   r   )r4   )r5   r6   s   "r7   r8   rP     s      S r:   c                   V P                  4       pVP                  RRP                  V4      /4       V P                  \        VRR7      pVP
                  R8X  d   \        P                  ! 4       hVP
                  R8X  d   \        P                  ! 4       hVP
                  R8X  d   \        P                  ! 4       hVP
                  ^8w  d2   \        P                  ! \        VP
                  VP                  R7      hR	# )
z)Revoke a magic attach token for the user.r[   r\   DELETEr     rb   r   rc   N)ra   rl   r5   rp   API_V1_REVOKE_MAGIC_ATTACHre   r    MagicAttachTokenAlreadyActivatedr   r   rt   rf   )r>   r   ra   r~   s   &&  r7   revoke_magic_attach_token*UAContractClient.revoke_magic_attach_token  s    ,,.););K)HIJ##& $ 
 ==C==??==C2244==C3355==C--.]]]]   r:   c          
      X   < V ^8  d   QhRS[ RS[ RS[S[ ,          RS[S[ S[3,          /# r3   r   r   r{   rO   r   )r5   r6   s   "r7   r8   rP     s?     )" )")" )" SM	)"
 
c3h)"r:   c                   V'       g!   \         P                  ! V P                  4      pV P                  4       pVP	                  RRP                  V4      /4       \        P                  VVR7      pV P                  4       pV P                  VRVRVR,          RVR,          RVR,          RVR,          /R	7      pVP                  ^8w  d-   \        P                  ! WWP                  VP                  R
7      hVP                  P                  R4      '       d!   VP                  R,          VP                  R&   VP                  # )aL  Get the updated machine token from the contract server.

@param machine_token: The machine token needed to talk to
    this contract service endpoint.
@param contract_id: Unique contract id provided by contract service
@param machine_id: Optional unique system machine id. When absent,
    contents of /etc/machine-id will be used.
r[   r\   r   GETr   r   r   r   )r   ra   r   rc   r   )r   rk   rN   ra   rl   r5   API_V1_GET_CONTRACT_MACHINErm   rp   re   r   rt   rf   rx   ru   )r>   r   r   r{   ra   rd   r|   r~   s   &&&&    r7   get_contract_machine%UAContractClient.get_contract_machine  s&    ..txx8J,,.););M)JKL)00  1 
 //1##n =-1-1f-		 $ 

 ==C--mm(--  	**,4,<,<Y,GHy)!!!r:   c                B   < V ^8  d   QhRS[ RS[ RS[S[ ,          RS[/# r   )r4   r   r   )r5   r6   s   "r7   r8   rP     s7     &" &"&" &" SM	&"
 
&"r:   c                \   V'       g!   \         P                  ! V P                  4      pV P                  4       pVP	                  RRP                  V4      /4       RVRV P                  4       /p\        V4      p\        P                  W#R7      pV P                  WtRVR7      pVP                  ^8w  d-   \        P                  ! WxP                  VP                  R7      hVP                  P                  R	4      '       d!   VP                  R	,          VP                  R	&   VP                  # )
a  Request machine token refresh from contract server.

@param machine_token: The machine token needed to talk to
    this contract service endpoint.
@param contract_id: Unique contract id provided by contract service.
@param machine_id: Optional unique system machine id. When absent,
    contents of /etc/machine-id will be used.

@return: Dict of the JSON response containing refreshed machine-token
r[   r\   r^   r_   r   r   )ra   r   r`   rc   r   )r   rk   rN   ra   rl   r5   rm   ro   API_V1_UPDATE_CONTRACT_MACHINErp   re   r   rt   rf   rx   ru   )	r>   r   r   r{   ra   r`   r}   rd   r~   s	   &&&&     r7   update_contract_machine(UAContractClient.update_contract_machine  s     ..txx8J,,.););M)JKLD335
 4D9,33  4 
 ##o $ 
 ==C--mm(--  	**,4,<,<Y,GHy)!!!r:   c                2   < V ^8  d   QhRS[ RS[ RS[ RS[/# r   )r4   r   )r5   r6   s   "r7   r8   rP      s3     !" !"!" !" 	!"
 
!"r:   c                   V P                  4       pVP                  RRP                  V4      /4       \        P                  VVR7      pV P	                  WTRR7      pVP
                  R8X  d   \        P                  ! RR7      hVP
                  ^8w  d.   \        P                  ! VVP
                  VP                  R	7      hVP                  # )
ay  Request guest token associated with this machine's contract
@param machine_token: The machine token needed to talk to
    this contract service endpoint.
@param contract_id: Unique contract id provided by contract service
@param machine_id: Unique machine id that was registered with the pro
    backend on attach.
@return: Dict of the JSON response containing the guest token
r[   r\   r   r   r   r   get_guest_token)feature_namerc   )ra   rl   r5   API_V1_GET_GUEST_TOKENrp   re   r    FeatureNotSupportedOldTokenErrorrt   rf   ru   )r>   r   r   r{   ra   rd   r~   s   &&&&   r7   r    UAContractClient.get_guest_token   s     ,,.););M)JKL$++  , 
 ##C#G==C ==.  ]]c!--]]]] 
 !!!r:   c                 v   \         P                  ! 4       pR\         P                  ! 4       P                  R\         P                  ! 4       P
                  R\         P                  ! 4       P                  R\         P                  ! 4       R\         P                  ! 4       R\         P                  ! 4       R\        P                  ! 4       R\        VP                  VP                  VP                  VP                   VP"                  VP$                  VP&                  VP(                  VP*                  VP,                  VP.                  VP0                  VP2                  VP4                  R	7      P7                  R
R7      /p\9        V P:                  4      P<                  '       Ed   \?        V P:                  4      P@                  p\B        PD                  ! 4       pRV PF                  PH                  ;'       g!    \         PJ                  ! V P:                  4      RV PF                  PL                  RV Uu. uF  qUPN                  NK  	  upRV Uu/ uF.  pVPP                  '       g   K  VPN                  VPR                  bK0  	  upRV'       d   VPT                  PW                  4       MR/pM/ p/ VCVC# u upi u upi )z9Return a dict of activity info data for contract requestsdistributionr   r   r   desktopr   clientVersioncpu_typer=   F)	keep_none
activityIDactivityToken	resourcesresourceVariantsr]   N),r   get_cpu_infoget_release_infor   get_kernel_infouname_releaser   get_dpkg_arch
is_desktopget_virt_typer   get_versionr"   r#   r%   r&   r'   r(   r)   r*   r+   r,   r-   r.   r/   r0   r1   to_dictr   rN   is_attachedr   enabled_servicesr   readrV   activity_idrk   activity_tokenr    variant_enabledvariant_nameattached_atrn   )r>   cpuinfomachine_infor   attachment_dataservicer|   s   &      r7   rm   #UAContractClient._get_activity_info#  s>    %%'F335BBf,,.<<f--/66F002v((*F((*W002#//)0)I)I#*#=#=(/(G(G!(!9!9%,%A%A$+$?$?%33#*#=#=!(!9!9")";";3:3]3]%33$11 gg&/
4 !---0:KK2779Od55AA 3 3((2!8!8!G!G:JK:Jwll:JK"#3%#3.. 7GLL'"6"66#3%
 !& $//99;M" M


 	
 L%s   1J1J6%J6)rV   r<   )   r3   r3   )rA   rB   rC   rD   cfg_url_base_attrr?   r   retrysockettimeoutr   r   r   r   r   r   r   r   r   r   r   r   rm   rH   rI   __classcell__)rW   r6   s   @@r7   rK   rK      s     &? ? 
ZZY7( 8(T" "(" " 
ZZY7 8@$ $L&9P 8 . .)" )"V&" &"P!" !"F7
 7
r:   rK   c                $    V ^8  d   QhR\         /# )r3   request_body)dict)r5   s   "r7   r8   r8   ]  s      D r:   c                   V P                  R/ 4      pRV P                  R4      RVRVP                  R4      RRVP                  R4      RVP                  R4      RVP                  R4      RR	R
\        P                  ! 4       P                  //# )a'  
Transforms a request_body that has the new activity_info into a body that
includes both old and new forms of machineInfo/activityInfo

This is necessary because there may be old ua-airgapped contract
servers deployed that we need to support.
This function is used for attach and refresh calls.
r_   r^   r   osr   r   r   typeLinuxrelease)rx   r   r   r  )r  r|   s   & r7   ro   ro   ]  s     !$$^R8M 	\%%k2)).9M--n=m''1m''1 Gv..088
	 r:   c                    V ^8  d   QhR\         R\        \        \        3,          R\        \        \        3,          R\        R\        R\        RR/# )	r3   rN   past_entitlementsnew_entitlementsallow_enabler   verboserO   N)r   r   r4   r   bool)r5   s   "r7   r8   r8   x  sg     Z
 Z
	Z
CH~Z
 38nZ
 	Z

 Z
 Z
 
Z
r:   c                H   ^ RI Hp Rp. p. p	V! V 4       F[  p
 W*,          p. p	 \        T TP	                  T
/ 4      TTTTR7      w  rT'       d"   T'       d   \
        P                  T
4       KY  K[  K]  	  \
        P                  V	4       \        V4      ^ 8  dg   \        P                   ! \#        W4       U
Uu. uF9  w  rV
\$        P&                  P)                  \+        V4      \-        4       R7      3NK;  	  upp
R	7      hV'       d8   \        P.                  ! V	 U
u. uF  p
V
\$        P0                  3NK  	  up
R	7      hR#   \         d     EK:  i ; i  \        P                   dL   p\        P                  T4       RpT	P                  T
4       \        P                  RT
T4        Rp?EK  Rp?i\         d[   p\        P                  T4       TP                  T4       T	P                  T
4       \        P                  RT
T4        Rp?EK  Rp?ii ; iu upp
i u up
i )
a  Iterate over all entitlements in new_entitlement and apply any delta
found according to past_entitlements.

:param cfg: UAConfig instance
:param past_entitlements: dict containing the last valid information
    regarding service entitlements.
:param new_entitlements: dict containing the current information regarding
    service entitlements.
:param allow_enable: Boolean set True if allowed to perform the enable
    operation. When False, a message will be logged to inform the user
    about the recommended enabled service.
:param series_overrides: Boolean set True if series overrides should be
    applied to the new_access dict.
:param verbose: If True, display output to stdout
)entitlements_enable_orderF)rN   orig_access
new_accessr  r   r  Tz+Failed to process contract delta for %s: %rNz5Unexpected error processing contract delta for %s: %r)r   log_path)failed_services)uaclient.entitlementsr  KeyErrorprocess_entitlement_deltarx   eventservice_processedr   UbuntuProErrorr   	exceptionappenderror	Exceptionservices_failedlenAttachFailureUnknownErrorzipr   UNEXPECTED_ERRORr5   r4   r   AttachFailureDefaultServices!E_ATTACH_FAILURE_DEFAULT_SERVICES)rN   r  r  r  r   r  r  delta_errorunexpected_errorsr  r    new_entitlementdeltasservice_enableder$  s   &&&&&&          r7   process_entitlements_deltar5  x  s   . @K O)#.	.4O 	.&?-11$;*)!1'#F: 6''- $*K /N 
/*
!22 (+?'N	 (OOD --44"%i.!?!A 5  (O	
 	
 
55 ,+D xAAB+
 	
 
e  		 (( 	MM!K""4(II= 
  	MM!$$Q'""4(MMG 		"	sG   E #E7?H
H EEH(?F..H;H<AHHc                    V ^8  d   QhR\         R\        \        \        3,          R\        \        \        3,          R\        R\        R\        R\
        \        \        3,          /# )r3   rN   r  r  r  r   r  rO   )r   r   r4   r   r  r   )r5   s   "r7   r8   r8     sg     > >	>c3h> S#X> 	>
 > > 4:>r:   c                X   ^ RI Hp V'       d   \        V4       \        P                  ! W4      pRpV'       d   VP                  R/ 4      P                  R4      p	V	'       g"   VP                  R/ 4      P                  R4      p	V	'       g   \        P                  ! WR7      hVP                  R/ 4      P                  R/ 4      P                  RR	4      p
 V! V V	V
R
7      pTP                  YY5R7      pWx3#   \        P                   d   p\        P                  RT	4       ThRp?ii ; i)a&  Process a entitlement access dictionary deltas if they exist.

:param cfg: UAConfig instance
:param orig_access: Dict with original entitlement access details before
    contract refresh deltas
:param new_access: Dict with updated entitlement access details after
    contract refresh
:param allow_enable: Boolean set True if allowed to perform the enable
    operation. When False, a message will be logged to inform the user
    about the recommended enabled service.
:param series_overrides: Boolean set True if series overrides should be
    applied to the new_access dict.
:param verbose: If True, display output to stdout

:raise UbuntuProError: on failure to process deltas.
:return: A tuple containing a dict of processed deltas and a
         boolean indicating if the service was fully processed
entitlement_factoryFentitlementr  )orignewentitlementsobligationsuse_selectorrh   rN   r    r   z3Skipping entitlement deltas for "%s". No such classNr  r  )r  r9  apply_contract_overridesr   get_dict_deltasrx   r    InvalidContractDeltasServiceTypeEntitlementNotFoundErrorr   r   process_contract_deltas)rN   r  r  r  r   r  r9  r2  retr    r   r:  excs   &&&&&&       r7   r   r     s   4 : ,!!+:F
C}b155f=::mR044V<D==  
 NN>2.S#S$ 	

	-K 11l 2 
 ; 22 	IIEt I		s   C7 7D)D$$D)c                X    V ^8  d   QhR\         P                  R\        P                  /# )r3   r~   rO   )r   HTTPResponser   NamedMessage)r5   s   "r7   r8   r8     s(     * ***r:   c                    V P                   P                  R 4      pV'       d   VR,          pVR,          pVR8X  dL   VR,          P                  \        4      p\        P
                  ! VVVR,          P                  R4      R7      hVR8X  dL   VR,          P                  \        4      p\        P                  ! VVVR,          P                  R4      R7      hVR	8X  d   \        P                  ! VR
7      h\        P                  ! 4       h)info
contractIdreasonzno-longer-effectivetimez%m-%d-%Y)r   datecontract_expiry_dateznot-effective-yet)r   rQ  contract_effective_dateznever-effective)r   )	ru   rx   strftimer   r   AttachForbiddenExpiredAttachForbiddenNotYetAttachForbiddenNeverAttachExpiredToken)r~   rM  r   rO  rQ  s   &    r7   rs   rs     s     !!&)D<(h**<(()@AD33'%)&\%:%::%F	  **<(()@AD22'(,V(=(=j(I	  ((11kJJ

'
'
))r:   c                $    V ^8  d   QhR\         /# )r3   rN   r   )r5   s   "r7   r8   r8   3  s     ! ! !r:   c                   \         P                  ! V 4      pVP                  4       pVP                  pVR,          pVR,          R,          R,          p\	        V R7      pVP                  WVR7      pVP                  V4       \        P                  P                  4        VP                  R/ 4      P                  R\        P                  ! V 4      4      p	\        P                  ! V	4       \        V VVP                  4       RVR	7       R
# )zRequest contract refresh from ua-contracts service.

:param verbose: If True, display output to stdout

:raise UbuntuProError: on failure to update contract or error processing
    contract deltas
:raise ConnectivityError: On failure during a connection
rg   machineTokenInfocontractInfoidrR   )r   r   r^   FrA  N)rT   rU   r=  r   rK   r   r   r   rk   cache_clearrx   r   r5  )
rN   r  rV   orig_entitlements
orig_tokenr   r   contract_clientrespr{   s
   &&        r7   refreshrc  3  s     33C8*779#11J~.M/0@FK&3/O22# 3 D T"
%%',b155V**3/J *%'')r:   c                F    V ^8  d   QhR\         R\        \        ,          /# )r3   rN   rO   )r   r   r   )r5   s   "r7   r8   r8   W  s     * * *d4j *r:   c                \    \        V 4      pVP                  4       pVP                  R. 4      # )zDQuery available resources from the contract server for this machine.r   )rK   r   rx   )rN   clientr   s   &  r7   get_available_resourcesrg  W  s+    c"F**,I==b))r:   c                ^    V ^8  d   QhR\         R\        R\        \        \        3,          /# )r3   rN   rj   rO   )r   r4   r   r   )r5   s   "r7   r8   r8   ^  s)     2 2( 23 24S> 2r:   c                :    \        V 4      pVP                  V4      # )z/Query contract information for a specific token)rK   r   )rN   rj   rf  s   && r7   get_contract_informationrj  ^  s    c"F**511r:   c                    V ^8  d   QhR\         \        \        3,          R\         \        \        3,          R\        /# )r3   override_selectorselector_valuesrO   )r   r4   int)r5   s   "r7   r8   r8   d  s4     	 	CH~	8<S#X		r:   c                     ^ pV P                  4        F2  w  r4W43VP                  4       9  d    ^ # V\        V,          ,          pK4  	  V# )r   )itemsOVERRIDE_SELECTOR_WEIGHTS)rl  rm  override_weightselectorvalues   &&   r7   _get_override_weightru  d  sM     O,224O$9$9$;;4X>> 5
 r:   c                    V ^8  d   QhR\         \        \        3,          R\        R\        R\        \        ,          R\         \        \         \        \        3,          3,          /# )r3   r:  series_namer   r   rO   )r   r4   r   r   rn  )r5   s   "r7   r8   r8   p  sX      c3h  c]	
 
#tCH~
r:   c                 R   / pR VRV/pV'       d   W5R&   V P                  R / 4      P                  V/ 4      pV'       d   VV\        R,          &   \        P                  ! V P	                  R. 4      4      pV F,  p\        VP                  R4      V4      p	V	'       g   K(  WV	&   K.  	  V# )r   r   r   r   	overridesrs  )poprq  copydeepcopyrx   ru  )
r:  rw  r   r   ry  rm  r   general_overridesoverrideweights
   &&&&      r7   _select_overridesr  p  s     IgzBO%,	""x488bI 	+,>?@ kook2&FG%%LL$o
 6 (f & r:   c                    V ^8  d   QhR\         \        \        3,          R\        \        ,          R\        \        ,          RR/# )r3   r  r   r   rO   N)r   r4   r   r   )r5   s   "r7   r8   r8     s@     .8 .8c3h.8SM.8 c].8 
	.8r:   c                4   ^ RI Hp \        \        V \        4      RV 9   .4      '       g   \        RP                  V 4      4      hVf    \        P                  ! 4       P                  MTpV! 4       w  rVV P                  R/ 4      p\        WtWR4      p\        VP                  4       4       Fj  w  rV
P                  4        FQ  w  rV R,          P                  V4      p\        V\        4      '       d   VP                  V4       KF  WR,          V&   KS  	  Kl  	  R# )ao  Apply series-specific overrides to an entitlement dict.

This function mutates orig_access dict by applying any series-overrides to
the top-level keys under 'entitlement'. The series-overrides are sparse
and intended to supplement existing top-level dict values. So, sub-keys
under the top-level directives, obligations and affordance sub-key values
will be preserved if unspecified in series-overrides.

To more clearly indicate that orig_access in memory has already had
the overrides applied, the 'series' key is also removed from the
orig_access dict.

:param orig_access: Dict with original entitlement access details
)get_cloud_typer:  z?Expected entitlement access dict. Missing "entitlement" key: {}N)uaclient.clouds.identityr  all
isinstancer  RuntimeErrorr5   r   r   r   rx   r  sortedrp  rl   )r  r   r   r  rw  r   _orig_entitlementry  _weightoverrides_to_applykeyrt  currents   &&&           r7   rB  rB    s    & 8
;-}/KLMM&%
 	
 -3N!((  #$MJ"}b9!zI (.ioo.?'@#,224JC!-044S9G'4(( u% 38M*3/ 5 (Ar:   c                t    V ^8  d   QhR\         R\        \        \        3,          R\        \
        ,          /# )r3   rN   r=  rO   )r   r   r4   r   r   r   )r5   s   "r7   r8   r8     s2     & &	&!%c3h&	
 !&r:   c                    ^ RI Hp . pVP                  4        F  w  rEVP                  R/ 4      P                  RR4      p V! WVR7      pTP                  R/ 4      P                  R/ 4      pTP                  R4      p	TP                  Y4      '       g   K~  TP                  4       w  rT
'       g   K  TP                  \        TTR7      4       K  	  V#   \        P
                   d     K  i ; i)	r   r8  r>  r?  rh   r@  r:  resourceToken)r    r   )
r  r9  rp  rx   r   rE  _should_enable_by_default
can_enabler%  r   )rN   r=  r9  enable_by_default_servicesent_name	ent_valuer   entr>  r  r  r  s   &&          r7   get_enabled_by_default_servicesr    s     :!#+113--r266~rJ	%#gNC  mmM26::="M!o6((DDNN,MJz*11*% '  4* &%! 22 		s   
CC.-C.)TT)FTT)Tr<   )NN)Kr{  loggingr  collectionsr   typingr   r   r   r   r   uaclient.files.machine_tokenfilesr   rT   uaclientr	   r
   r   r   r   r   r   r   r   -uaclient.api.u.pro.status.enabled_services.v1r   (uaclient.api.u.pro.status.is_attached.v1r   uaclient.configr   uaclient.defaultsr   uaclient.files.state_filesr   r   uaclient.httpr   uaclient.logr   rq   r   r   r   r   r   r   r   r   r   r   r   rq  get_event_loggerr!  	getLoggerreplace_top_level_logger_namerA   r   r   
DataObjectr"   UAServiceClientrK   ro   r5  r   rs   rc  rg  rj  ru  r  rB  r   r:   r7   <module>r     sj      " 3 3 * *
 
 
 L A $ 5 L ' 7 ; 9  :  - 9 # 0O ,9  #1 %7 ", /  F 
 aQq	  	%%'::8DE $vy1 
T)*'' T)n}
}44 }
@6Z
z>B*:!H*2	:.8b&r:   