+
    iɢ                        ^ RI t ^ RIt^ RIt^ RIt^ RIt^ RIt^ RIt^ RIHt ^ RI	H	t	H
t
 ^ RIHtHt ^ RIHtHtHtHtHt ^ RIHt ^ RIHt ^ RIHtHtHtHtHtHt ^ R	IH t  ^ R
I!H"t" ]PF                  ! ]$4      t%Rt&Rt'Rt(Rt)Rt*] PV                  ! RRRR7      t,]! R4      t-R R lt.].R 4       t/].R 4       t0RR/R R llt1R t2].R 4       t3]R 4       t4].RRR ^R!^/R" R# ll4       t5R$ R% lt6 ! R& R'4      t7 ! R( R)]84      t9 ! R* R+4      t: ! R, R-4      t; ! R. R/4      t< ! R0 R14      t=].R<R2 R3 ll4       t>].R4 R5 l4       t?R6 R7 lt@ ! R8 R9]84      tA ! R: R;4      tBR# )=    N)contextmanager)datetimetimezone)sleeptime)CallableListOptionalTypeVarUnion)ElementTree)escape)distrossubp
temp_utils
url_helperutilversion)events)errorsz168.63.129.16boot-telemetryzsystem-info
diagnostic
compressedzazure-dsz initialize reporter for azure dsT)namedescriptionreporting_enabledTc                d    V ^8  d   QhR\         R\        3,          R\         R\        3,          /# )   func.return)r   r   )formats   "A/usr/lib/python3/dist-packages/cloudinit/sources/helpers/azure.py__annotate__r$   )   s,     	 	hsAv&6 	8CF;K 	    c                    a  V 3R  lpV# )c                     < \         P                  ! SP                  SP                  \        R 7      ;_uu_ 4        S! V / VB uuRRR4       #   + '       g   i     R# ; i)r   r   parentN)r   ReportEventStack__name__azure_ds_reporter)argskwargsr    s   *,r#   impl)azure_ds_telemetry_reporter.<locals>.impl*   sK    $$$
 

 ((
 
 
 
s   AA	 )r    r/   s   f r#   azure_ds_telemetry_reporterr2   )   s    ) Kr%   c                    \         P                  ! 4       '       g   \        R4      h\        P	                  R4        \        \        4       4      \        \        P                  ! 4       4      ,
          p  \        P                  ! . RORR7      w  r#RpT'       d    RT9   d   TP                  R4      ^,          pT'       g   \        R4      hT \        T4      R	,          ,           p \        P                  ! . RORR7      w  r#RpT'       d    RT9   d   TP                  R4      ^,          pT'       g   \        R4      hT \        T4      R	,          ,           p\        P                  ! \        RR\         P"                  ! T \$        P&                  4      P)                  4       : R\         P"                  ! T\$        P&                  4      P)                  4       : R\         P"                  ! T\$        P&                  4      P)                  4       : 2\        P*                  4      p\        P,                  ! T4       T#   \         d   p\        R4      ThRp?ii ; i  \        P                   d   p\        R
T,          4      ThRp?i\         d   p\        RT,          4      ThRp?ii ; i  \        P                   d   p\        RT,          4      ThRp?i\         d   p\        RT,          4      ThRp?ii ; i)zWReport timestamps related to kernel initialization and systemd
activation of cloud-initz1distro not using systemd, skipping boot telemetryzCollecting boot telemetryz*Failed to determine kernel start timestampNT)capture=z8Failed to parse UserspaceTimestampMonotonic from systemdi@B z-Failed to get UserspaceTimestampMonotonic: %sz<Failed to parse UserspaceTimestampMonotonic from systemd: %sz;Failed to parse InactiveExitTimestampMonotonic from systemdz0Failed to get InactiveExitTimestampMonotonic: %sz?Failed to parse InactiveExitTimestampMonotonic from systemd: %sr   zkernel_start=z user_start=z cloudinit_activation=)	systemctlshow-pUserspaceTimestampMonotonic)r6   r7   zcloud-init-localr8   InactiveExitTimestampMonotonic)r   uses_systemdRuntimeErrorLOGdebugfloatr   r   uptime
ValueErrorr   splitProcessExecutionErrorr   ReportingEventBOOT_EVENT_TYPEr   fromtimestampr   utc	isoformatDEFAULT_EVENT_ORIGINreport_event)kernel_starteout_tsm
user_startcloudinit_activationevts           r#   get_boot_telemetryrS   5   s    !!NOOII)*PTV}uT[[]';;F
 3#:))C.#CJ  "U3Z'%9:
 	
 3#:))C.#CM   ,uSzG/CD 

 ""<>HHJ"":x||<FFH""$hllik		
 	##C  JS  PGHaOP$ %% ;a?
	  JQN
	2 %% >B
	  M
 	sy   6H9 4AI $I &AJ) 3$J) 9IIIJ&-J  J&J&J!!J&)K7>KK7K7K22K7c                    \         P                  ! 4       p \        P                  ! \        RR\
        P                  ! 4       : RV R,          : RV R,          : RV R,          ^ ,          : R	V R,          ^,          : R
V R,          ^,          : RV R,          : 2\        P                  4      p\        P                  ! V4       V# )z%Collect and report system informationzsystem informationzcloudinit_version=z, kernel_version=releasez
, variant=variantz, distro_name=distz, distro_version=z	, flavor=z, python_version=python)	r   system_infor   rD   SYSTEMINFO_EVENT_TYPEr   version_stringrI   rJ   )inforR   s     r#   get_system_infor]      s     D



 ""$OOOOLOOLOOLOON	
 	##C"  Jr%   logger_funcc                D    V ^8  d   QhR\         R\        P                  /# )r   msgr!   )strr   rD   )r"   s   "r#   r$   r$      s"      	r%   c                   \        V4      '       d	   V! V 4       \        P                  ! \        RV \        P                  4      p\        P
                  ! VR0R7       V# )zReport a diagnostic eventzdiagnostic messagelogexcluded_handler_types)callabler   rD   DIAGNOSTIC_EVENT_TYPErI   rJ   )r`   r^   rR   s   &$ r#   report_diagnostic_eventrh      sT     C


##	C UG< Jr%   c                6   \         P                  ! \        P                  ! V4      4      pRRRVP	                  R4      /p\
        P                  ! \        V \        P                  ! V4      \
        P                  4      p\
        P                  ! V0 RmR7       V# )zReport a compressed eventencodingzgz+b64dataasciird   >   rc   printwebhook)base64encodebyteszlibcompressdecoder   rD   COMPRESSED_EVENT_TYPEjsondumpsrI   rJ   )
event_nameevent_contentcompressed_data
event_datarR   s   &&   r#   report_compressed_eventr{      s    ((})EFOH&&w/J 



:##	C $?
 Jr%   c                 
   \         P                  R4        \        P                  ! R.RRR7      w  r\        RV 4       R#   \         d7   p\        R\        T4      ,          \         P                  R7        Rp?R# Rp?ii ; i)	zReport dmesg to KVP.zDumping dmesg log to KVPdmesgFT)rs   r4   z$Exception when dumping dmesg log: %sr^   N)r=   r>   r   r{   	Exceptionrh   reprwarning)rM   rN   exs      r#   report_dmesg_to_kvpr      sf     II()
G9UDA- 
2T"X=	
 	

s   (A B+A==Bc              #   
  "   \         P                  ! 4       p\         P                  ! \         P                  P	                  V 4      4        R x  \         P                  ! V4       R #   \         P                  ! T4       i ; i5iN)osgetcwdchdirpath
expanduser)newdirprevdirs   & r#   cdr      sK     iikGHHRWW'(
s   A	BA( B(B  Brk   retry_sleeptimeout_minutesc                    V ^8  d   QhR\         R\        R\        \        ,          R\        R\        R\
        P                  /# )r   urlheadersrk   r   r   r!   )ra   dictr
   bytesintr   UrlResponse)r"   s   "r#   r$   r$      sP     3 3	3 3 5/	3
 3 3 3r%   c          	        V^<,          \        4       ,           p^ pRpV'       g%   V^,          p \        P                  ! WVRR7      p \	        RW3,          \        P                  R7       V#   \        P                   dk   p\	        RYYP
                  TP                  3,          \        P                  R7       \        4       T,           T8  g   R\        T4      9   d   h  Rp?MRp?ii ; i\        T4       K  )zReadurl wrapper for querying wireserver.

:param retry_sleep: Time to sleep before retrying.
:param timeout_minutes: Retry up to specified number of minutes.
:raises UrlError: on error fetching data.
N)r   rk   timeoutzdFailed HTTP request with Azure endpoint %s during attempt %d with exception: %s (code=%r headers=%r)r~   zNetwork is unreachablez@Successful HTTP request with Azure endpoint %s after %d attempts)   <   )r   r   readurlUrlErrorrh   coder   r=   r>   ra   r   )	r   r   rk   r   r   r   attemptresponserL   s	   &$$$$    r#   http_with_retriesr      s     "TV+GGH1	!))4H , 		'II
 O5 "" 	#EFFAII67  II	 $/+s1v5 6	& 	ks   A. .C-A C((C-c                    V ^8  d   QhR\         \        ,          R\         \        ,          R\         \        ,          R\        /# )r   usernamehostnamedisable_ssh_password_authr!   )r
   ra   boolr   )r"   s   "r#   r$   r$     s>     - -sm- sm-  (~	-
 -r%   c           	          V '       d   R V  R2pMRpVf   RpMR\        V4      P                  4        R2pRV R2p\        P                  ! RV RV RV R	24      P	                  R
4      # )z<ns1:UserName>z</ns1:UserName> z&<ns1:DisableSshPasswordAuthentication>z'</ns1:DisableSshPasswordAuthentication>z<ns1:HostName>z</ns1:HostName>a          <ns0:Environment xmlns:ns0="http://schemas.dmtf.org/ovf/environment/1"
         xmlns:ns1="http://schemas.microsoft.com/windowsazure"
         xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
          <ns1:ProvisioningSection>
            <ns1:Version>1.0</ns1:Version>
            <ns1:LinuxProvisioningConfigurationSet>
              <ns1:ConfigurationSetType>LinuxProvisioningConfiguration
              </ns1:ConfigurationSetType>
              z
              a  
            </ns1:LinuxProvisioningConfigurationSet>
          </ns1:ProvisioningSection>
          <ns1:PlatformSettingsSection>
            <ns1:Version>1.0</ns1:Version>
            <ns1:PlatformSettings>
              <ns1:ProvisionGuestAgent>true</ns1:ProvisionGuestAgent>
            </ns1:PlatformSettings>
          </ns1:PlatformSettingsSection>
        </ns0:Environment>
        utf-8)ra   lowertextwrapdedentencode)r   r   r   ns_usernamens_disable_ssh_password_authns_hostnames   $$$   r#   build_minimal_ovfr     s     &xj@ (')$ 5,-335656 	% #8*O<K??	 m +, -m 
		. fWo/r%   c                   ^   a  ] tR tRt o RRRR/tR tRV 3R lR lltRV 3R
 lR lltRtV t	R	# )AzureEndpointHttpClientiL  zx-ms-agent-nameWALinuxAgentzx-ms-versionz
2012-11-30c                    R RRV/V n         R# )zx-ms-cipher-nameDES_EDE3_CBCz!x-ms-guest-agent-public-x509-certNextra_secure_headers)selfcertificates   &&r#   __init__ AzureEndpointHttpClient.__init__R  s    /%
!r%   c                4   < V ^8  d   QhRS[ P                  /# r   r!   )r   r   )r"   __classdict__s   "r#   r$   $AzureEndpointHttpClient.__annotate__X  s     7 7
(>(> 7r%   c                    V P                   pV'       d6   V P                   P                  4       pVP                  V P                  4       \	        WR 7      # ))r   )r   copyupdater   r   )r   r   securer   s   &&& r#   getAzureEndpointHttpClient.getX  s=    ,,ll'')GNN4445 66r%   Nc                J   < V ^8  d   QhRS[ S[,          RS[P                  /# )r   rk   r!   )r
   r   r   r   )r"   r   s   "r#   r$   r   _  s+     B B!%B			Br%   c                    V P                   pVe,   V P                   P                  4       pVP                  V4       \        WVR7      # )N)rk   r   )r   r   r   r   )r   r   rk   extra_headersr   s   &&&& r#   postAzureEndpointHttpClient.post_  s>     ,,$ll'')GNN=) AAr%   r   )FNN)
r+   
__module____qualname____firstlineno__r   r   r   r   __static_attributes____classdictcell__r   s   @r#   r   r   L  s7     >G

7 7B B Br%   r   c                       ] tR tRtRtRtR# )InvalidGoalStateXMLExceptionii  z9Raised when GoalState XML is invalid or has missing data.r1   N)r+   r   r   r   __doc__r   r1   r%   r#   r   r   i  s    Cr%   r   c                   <   a  ] tR tRt o RV 3R lR lltR tRtV tR# )	GoalStateim  c                F   < V ^8  d   QhRS[ S[S[3,          RS[RS[RR/# )r   unparsed_xmlazure_endpoint_clientneed_certificater!   N)r   ra   r   r   r   )r"   r   s   "r#   r$   GoalState.__annotate__n  s<     5 5CJ'5  75 	5
 
5r%   c                8   W n          \        P                  ! V4      V n        T P                  R4      T n	        T P                  R4      T n
        T P                  R4      T n        R F?  p\        Y4      e   K  RT,          p\        T\        P                  R7       \        T4      h	  RT n        T P                  R4      pTe   T'       dw   \        P                   ! R	R
\"        R7      ;_uu_ 4        T P                   P%                  TRR7      P&                  T n        T P                  f   \        R4      h RRR4       R# R# R#   \        P                   d)   p\        RT,          \        P                  R7       h Rp?ii ; i  + '       g   i     R# ; i)a@  Parses a GoalState XML string and returns a GoalState object.

@param unparsed_xml: string representing a GoalState XML.
@param azure_endpoint_client: instance of AzureEndpointHttpClient.
@param need_certificate: switch to know if certificates is needed.
@return: GoalState object representing the GoalState XML string.
z!Failed to parse GoalState XML: %sr~   Nz./Container/ContainerIdz4./Container/RoleInstanceList/RoleInstance/InstanceIdz./IncarnationzMissing %s in GoalState XMLzD./Container/RoleInstanceList/RoleInstance/Configuration/Certificateszget-certificates-xmlzget certificates xmlr(   T)r   z/Azure endpoint returned empty certificates xml.)container_idinstance_idincarnation)r   ET
fromstringroot
ParseErrorrh   r=   r   _text_from_xpathr   r   r   getattrr   certificates_xmlr   r*   r,   r   contents)r   r   r   r   rL   attrr`   r   s   &&&&    r#   r   GoalState.__init__n  s    &;"	l3DI !112KL00B
  00ABDt"*3d:'E2377	 C !%##*
 ?/((+2( 
 )-(B(B(F(F )G )( % ((06I  1   0?1 }} 	#3a7KK 	2  s$   E 3AFF#F  FF	c                \    V P                   P                  V4      pVe   VP                  # R # r   )r   findtext)r   xpathelements   && r#   r   GoalState._text_from_xpath  s'    ))..'<<r%   )r   r   r   r   r   r   N)T)r+   r   r   r   r   r   r   r   r   s   @r#   r   r   m  s     5 5n r%   r   c                      a  ] tR tRt o RRRR/tR tR t]R 4       t]P                  R	 4       t]
R
 4       t]]
R 4       4       t]
R 4       t]
R 4       t]
R 4       t]
R 4       tRtV tR# )OpenSSLManageri  private_keyzTransportPrivate.pemr   zTransportCert.pemc                h    \         P                  ! 4       V n        R V n        V P	                  4        R # r   )r   mkdtemptmpdir_certificategenerate_certificater   s   &r#   r   OpenSSLManager.__init__  s&     ((* !!#r%   c                F    \         P                  ! V P                  4       R # r   )r   del_dirr   r   s   &r#   clean_upOpenSSLManager.clean_up  s    T[[!r%   c                    V P                   # r   r   r   s   &r#   r   OpenSSLManager.certificate  s       r%   c                    Wn         R # r   r   )r   values   &&r#   r   r     s    !r%   c                h   \         P                  R 4       V P                  e   \         P                  R4       R# \        V P                  4      ;_uu_ 4        \
        P
                  ! RRRRRRR	R
RRRV P                  R,          RV P                  R,          .4       Rp\        P                  ! V P                  R,          4      P                  4        F"  pRV9  g   K  WP                  4       ,          pK$  	  Wn        RRR4       \         P                  R4       R#   + '       g   i     L'; i)z7Generating certificate for communication with fabric...NzCertificate already generated.opensslreqz-x509z-nodesz-subjz/CN=LinuxTransportz-days32768z-newkeyzrsa:3072z-keyoutr   z-outr   r   CERTIFICATEzNew certificate generated.)r=   r>   r   r   r   r   certificate_namesr   load_text_file
splitlinesrstrip)r   r   lines   &  r#   r   #OpenSSLManager.generate_certificate  s    		KL'II67__II(**=9**=9$ K++&&}5jl !,;;=0K	
  +3 4 			./5 _s   BD!" D!!D1	c                D    R RRV .p\         P                   ! W!R7      w  r4V# )r  x509z-nooutrk   )r   )actioncertcmdresultrN   s   &&   r#   _run_x509_actionOpenSSLManager._run_x509_action  s'     &(F3IIc-	r%   c                d    V P                  R V4      p. ROp\        P                  ! W2R7      w  rEV# )z-pubkeyr  )z
ssh-keygenz-iz-mPKCS8z-fz
/dev/stdin)r  r   )r   r   pub_key
keygen_cmdssh_keyrN   s   &&    r#   _get_ssh_key_from_cert%OpenSSLManager._get_ssh_key_from_cert  s.    ''	;?L
YYz8
r%   c                    V P                  RV4      pVP                  R4      pW#^,           R P                  R4      pRP                  V4      # )zopenssl x509 formats fingerprints as so:
'SHA1 Fingerprint=07:3E:19:D1:4D:1C:79:92:24:C6:A0:FD:8D:DA:\
B6:A8:BF:27:D4:73\n'

Azure control plane passes that fingerprint as so:
'073E19D14D1C799224C6A0FD8DDAB6A8BF27D473'
z-fingerprintr5   :r   )r  r   rB   join)r   r   raw_fpeqoctetss   &&   r#   _get_fingerprint_from_cert)OpenSSLManager._get_fingerprint_from_cert  sK     &&~{C[[Q$**3/wwvr%   c           	        \         P                  ! V4      P                  R4      pVP                  pRRRRRVP	                  R4      .p\        V P                  4      ;_uu_ 4        \        P                  ! RP                  ! R/ V P                  B R	R
P                  V4      R7      w  rVRRR4       V#   + '       g   i     X# ; i)zDecrypt the certificates XML document using the our private key;
return the list of certs and private keys contained in the doc.
z.//Datas   MIME-Version: 1.0s<   Content-Disposition: attachment; filename="Certificates.p7m"s?   Content-Type: application/x-pkcs7-mime; name="Certificates.p7m"s!   Content-Transfer-Encoding: base64r%   r   zuopenssl cms -decrypt -in /dev/stdin -inkey {private_key} -recip {certificate} | openssl pkcs12 -nodes -password pass:T   
)shellrk   Nr1   )r   r   r   r   r   r   r   r   r"   r  r!  )r   r   tagcertificates_contentlinesrM   rN   s   &&     r#   _decrypt_certs_from_xml&OpenSSLManager._decrypt_certs_from_xml   s    
 mm,-229="xx KN0 ''0
 __YY##)6* D,0,B,BD ZZ&FC  
 _ 
s   &AB55C	c                r   V P                  V4      p. p/ pVP                  4        F  pVP                  V4       \        P                  ! RV4      '       d   . pK5  \        P                  ! RV4      '       g   KT  RP                  V4      pV P                  V4      pV P                  V4      pWtV&   . pK  	  V# )zxGiven the Certificates XML document, return a dictionary of
fingerprints and associated SSH keys derived from the certs.z[-]+END .*?KEY[-]+$z[-]+END .*?CERTIFICATE[-]+$
)r-  r
  appendrematchr!  r  r%  )	r   r   rM   currentkeysr  r   r  fingerprints	   &&       r#   parse_certificates!OpenSSLManager.parse_certificates  s     **+;<NN$DNN4 xx.558$??"ii055kB"==kJ$+[! % r%   )r   r   r   N)r+   r   r   r   r  r   r   propertyr   setterr2   r   staticmethodr  r  r%  r-  r7  r   r   r   s   @r#   r   r     s     -*
$
" ! ! " " !0 !0B   ! 
 ! ! ! ! ! !0 ! !r%   r   c                      a  ] tR tRt o ]P
                  ! R4      t]P
                  ! R4      tRtRt	Rt
RtV 3R lR	 lt]V 3R
 lR l4       t]V 3R lR l4       tRV 3R lR llt]V 3R lR l4       tRtV tR# )GoalStateHealthReporteri.  a          <?xml version="1.0" encoding="utf-8"?>
        <Health xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xmlns:xsd="http://www.w3.org/2001/XMLSchema">
          <GoalStateIncarnation>{incarnation}</GoalStateIncarnation>
          <Container>
            <ContainerId>{container_id}</ContainerId>
            <RoleInstanceList>
              <Role>
                <InstanceId>{instance_id}</InstanceId>
                <Health>
                  <State>{health_status}</State>
                  {health_detail_subsection}
                </Health>
              </Role>
            </RoleInstanceList>
          </Container>
        </Health>
        z        <Details>
          <SubStatus>{health_substatus}</SubStatus>
          <Description>{health_description}</Description>
        </Details>
        ReadyNotReadyProvisioningFailedi   c                0   < V ^8  d   QhRS[ RS[RS[RR/# )r   
goal_stater   endpointr!   N)r   r   ra   )r"   r   s   "r#   r$   $GoalStateHealthReporter.__annotate__T  s3     " ""  7" 	"
 
"r%   c                *    Wn         W n        W0n        R# )a  Creates instance that will report provisioning status to an endpoint

@param goal_state: An instance of class GoalState that contains
    goal state info such as incarnation, container id, and instance id.
    These 3 values are needed when reporting the provisioning status
    to Azure
@param azure_endpoint_client: Instance of class AzureEndpointHttpClient
@param endpoint: Endpoint (string) where the provisioning status report
    will be sent to
@return: Instance of class GoalStateHealthReporter
N)_goal_state_azure_endpoint_client	_endpoint)r   rB  r   rC  s   &&&&r#   r    GoalStateHealthReporter.__init__T  s    " &&;#!r%   c                   < V ^8  d   QhRR/# )r   r!   Nr1   )r"   r   s   "r#   r$   rD  j  s     4 44 4r%   c                   V P                  V P                  P                  V P                  P                  V P                  P                  V P
                  R 7      p\        P                  R4        V P                  VR7       \        P                  R4       R#   \         d)   p\        RT,          \        P                  R7       h Rp?ii ; i))r   r   r   statusz Reporting ready to Azure fabric.documentz#exception while reporting ready: %sr~   NzReported ready to Azure fabric.)build_reportrF  r   r   r   PROVISIONING_SUCCESS_STATUSr=   r>   _post_health_reportr   rh   errorr\   )r   rN  rL   s   &  r#   send_ready_signal)GoalStateHealthReporter.send_ready_signali  s    $$((44))66((4433	 % 
 			45	$$h$7 	23  	#59II 	s   2B C&#C		Cc                $   < V ^8  d   QhRS[ RR/# r   r   r!   Nra   )r"   r   s   "r#   r$   rD  ~  s     9 9s 9t 9r%   c           	        V P                  V P                  P                  V P                  P                  V P                  P                  V P
                  V P                  VR 7      p V P                  VR7       \        P                  R4       R#   \         d+   pRT,          p\        T\        P                  R7       h Rp?ii ; i))r   r   r   rL  	substatusr   rM  z%exception while reporting failure: %sr~   Nz!Reported failure to Azure fabric.)rO  rF  r   r   r   PROVISIONING_NOT_READY_STATUSPROVISIONING_FAILURE_SUBSTATUSrQ  r   rh   r=   rR  r   )r   r   rN  rL   r`   s   &&   r#   send_failure_signal+GoalStateHealthReporter.send_failure_signal}  s    $$((44))66((445599# % 
	$$h$7 	78  	9A=C#CSYY?	s   )B C%CCNc          
      8   < V ^8  d   QhRS[ RS[ RS[ RS[ RS[/# )r   r   r   r   rL  r!   )ra   r   )r"   r   s   "r#   r$   rD    s=     - -- - 	-
 - 
-r%   c                B   R pVe=   V P                   P                  \        V4      \        VRV P                   4      R7      pV P                  P                  \        \        V4      4      \        V4      \        V4      \        V4      VR7      pVP                  R4      # )r   N)health_substatushealth_description)r   r   r   health_statushealth_detail_subsectionr   )%HEALTH_DETAIL_SUBSECTION_XML_TEMPLATEr"   r   "HEALTH_REPORT_DESCRIPTION_TRIM_LENHEALTH_REPORT_XML_TEMPLATEra   r   )	r   r   r   r   rL  rY  r   health_detailhealth_reports	   &&&&&&&  r#   rO  $GoalStateHealthReporter.build_report  s       FFMM!'	!2#) I$"I"IJ$ N M 77>>s;/0-{+ .%2 ? 
 ##G,,r%   c                $   < V ^8  d   QhRS[ RR/# )r   rN  r!   Nr   )r"   r   s   "r#   r$   rD    s     E EE Ed Er%   c                    \        ^ 4       \        P                  R4       RP                  V P                  4      pV P
                  P                  VVRR/R7       \        P                  R4       R# )r   z&Sending health report to Azure fabric.zhttp://{}/machine?comp=healthzContent-Typeztext/xml; charset=utf-8)rk   r   z/Successfully sent health report to Azure fabricN)r   r=   r>   r"   rH  rG  r   )r   rN  r   s   && r#   rQ  +GoalStateHealthReporter._post_health_report  sc    ( 	a		:;-44T^^D##(()+DE 	) 	

 			CDr%   )rG  rH  rF  r   )r+   r   r   r   r   r   rf  rd  rP  rZ  r[  re  r   r2   rS  r\  rO  rQ  r   r   r   s   @r#   r=  r=  .  s     !)	", -5OO	-) #*$.!%9"),&" "* !4 !4& !9 !9$- -8 !E !Er%   r=  c                     a  ] tR tRt o V 3R lR ltR t]V 3R lR l4       t]RV 3R lR	 ll4       t]V 3R
 lR l4       t	]V 3R lR l4       t
]V 3R lR l4       t]V 3R lR l4       t]V 3R lR l4       t]V 3R lR l4       tRtV tR# )WALinuxAgentShimi  c                    < V ^8  d   QhRS[ /# )r   rC  rW  )r"   r   s   "r#   r$   WALinuxAgentShim.__annotate__  s     M M Mr%   c                .    Wn         R V n        R V n        R # r   )rC  openssl_managerr   )r   rC  s   &&r#   r   WALinuxAgentShim.__init__  s     9=HL"r%   c                Z    V P                   e   V P                   P                  4        R # R # r   )rs  r   r   s   &r#   r   WALinuxAgentShim.clean_up  s%    +  ))+ ,r%   c                8   < V ^8  d   QhRS[ P                  RR/# )r   distror!   N)r   Distro)r"   r   s   "r#   r$   rq    s       D r%   c                    \         P                  R 4        VP                  V4       R#   \         d.   p\	        RT,          \         P
                  R7        Rp?R# Rp?ii ; i)zEjecting the provisioning isoz(Failed ejecting the provisioning iso: %sr~   N)r=   r>   eject_mediar   rh   rR  )r   iso_devrx  rL   s   &&& r#   	eject_isoWALinuxAgentShim.eject_iso  sN    		12	w' 	#:Q>II 	s   * A""AA"Nc                Z   < V ^8  d   QhRS[ P                  RS[S[S[,          ,          /# )r   rx  r!   )r   ry  r
   r	   ra   )r"   r   s   "r#   r$   rq    s*     # #nn#	$s)	#r%   c                   RpV P                   f*   Ve&   \        4       V n         V P                   P                  pV P                  f   \	        V4      V n        V P                  VRJR7      pRpVe   V P                  WR4      p\        WPP                  V P                  4      pVe   V P                  W1R7       VP                  4        V# )a  Gets the VM's GoalState from Azure, uses the GoalState information
to report ready/send the ready signal/provisioning complete signal to
Azure, and then uses pubkey_info to filter and obtain the user's
pubkeys from the GoalState.

@param pubkey_info: List of pubkey values and fingerprints which are
    used to filter and obtain the user's pubkey values from the
    GoalState.
@return: The list of user's authorized pubkey values.
Nr   )rx  )rs  r   r   r   r   _fetch_goal_state_from_azure_get_user_pubkeysr=  rC  r}  rS  )r   rx  pubkey_infor|  http_client_certificaterB  ssh_keyshealth_reporters   &&&&    r#   "register_with_azure_and_fetch_data3WALinuxAgentShim.register_with_azure_and_fetch_data  s     #''K,C#1#3D &*&:&:&F&F#%%-)@'*D& 664D@ 7 

 "--jFH122DMM
 NN7N2))+r%   c                $   < V ^8  d   QhRS[ RR/# rV  rW  )r"   r   s   "r#   r$   rq    s     E E# E$ Er%   c                    V P                   f   \        R4      V n         V P                  RR7      p\        W P                   V P                  4      pVP                  VR7       R# )zGets the VM's GoalState from Azure, uses the GoalState information
to report failure/send provisioning failure signal to Azure.

@param: user visible error description of provisioning failure.
NFr  r   )r   r   r  r=  rC  r\  )r   r   rB  r  s   &&  r#   &register_with_azure_and_report_failure7WALinuxAgentShim.register_with_azure_and_report_failure  s\     %%-)@)FD&666N
122DMM
 	+++Dr%   c                &   < V ^8  d   QhRS[ RS[/# )r   r   r!   )r   r   )r"   r   s   "r#   r$   rq    s     
 
 $
	
r%   c                D    V P                  4       pV P                  W!4      # )zFetches the GoalState XML from the Azure endpoint, parses the XML,
and returns a GoalState object.

@param need_certificate: switch to know if certificates is needed.
@return: GoalState object representing the GoalState XML
)"_get_raw_goal_state_xml_from_azure_parse_raw_goal_state_xml)r   r   unparsed_goal_state_xmls   && r#   r  -WALinuxAgentShim._fetch_goal_state_from_azure  s)     #'"I"I"K--#
 	
r%   c                    < V ^8  d   QhRS[ /# r   rk  )r"   r   s   "r#   r$   rq  &  s     ! !E !r%   c                   \         P                  R4       RP                  V P                  4      p \        P
                  ! RR\        R7      ;_uu_ 4        V P                  P                  V4      pRRR4       \         P                  R	4       XP                  #   + '       g   i     L1; i  \         d)   p\        RT,          \         P                  R7       h Rp?ii ; i)
zrFetches the GoalState XML from the Azure endpoint and returns
the XML as a string.

@return: GoalState XML string
zRegistering with Azure...z!http://{}/machine/?comp=goalstatezgoalstate-retrievalzretrieve goalstater(   Nz9failed to register with Azure and fetch GoalState XML: %sr~   z#Successfully fetched GoalState XML.)r=   r\   r"   rC  r   r*   r,   r   r   r   rh   r   r>   r   )r   r   r   rL   s   &   r#   r  3WALinuxAgentShim._get_raw_goal_state_xml_from_azure%  s     	,-188G	((*0( 
  5599#> 			78      	#KKK
 	s5   %B/ B3B/ B,	'B/ ,B/ /C":#CC"c                B   < V ^8  d   QhRS[ S[S[3,          RS[RS[/# )r   r  r   r!   )r   ra   r   r   r   )r"   r   s   "r#   r$   rq  A  s2      !&sEz!2  
	r%   c                f    \        VV P                  V4      pRP                  RTP                  ,          RTP                  ,          RTP                  ,          .4      p\        T\        P                  R7       T#   \         d)   p\        RT,          \        P
                  R7       h Rp?ii ; i)zParses a GoalState XML string and returns a GoalState object.

@param unparsed_goal_state_xml: GoalState XML string
@param need_certificate: switch to know if certificates is needed.
@return: GoalState object representing the GoalState XML
z"Error processing GoalState XML: %sr~   Nz, zGoalState XML container id: %szGoalState XML instance id: %szGoalState XML incarnation: %s)r   r   r   rh   r=   r   r!  r   r   r   r>   )r   r  r   rB  rL   r`   s   &&&   r#   r  *WALinuxAgentShim._parse_raw_goal_state_xml@  s    	"'** J ii0:3J3JJ/*2H2HH/*2H2HH
 	 ;  	#4q8KK 	s   A= =B0#B++B0c                ,   < V ^8  d   QhRS[ RS[RS[/# )r   rB  r  r!   )r   list)r"   r   s   "r#   r$   rq  c  s%     ' '#'26'	'r%   c                    . pVP                   e^   VeZ   V P                  eL   \        P                  R4       V P                  P	                  VP                   4      pV P                  WB4      pV# )a  Gets and filters the VM admin user's authorized pubkeys.

The admin user in this case is the username specified as "admin"
when deploying VMs on Azure.
See https://docs.microsoft.com/en-us/cli/azure/vm#az-vm-create.
cloud-init expects a straightforward array of keys to be dropped
into the admin user's authorized_keys file. Azure control plane exposes
multiple public keys to the VM via wireserver. Select just the
admin user's key(s) and return them, ignoring any other certs.

@param goal_state: GoalState object. The GoalState object contains
    a certificate XML, which contains both the VM user's authorized
    pubkeys and other non-user pubkeys, which are used for
    MSI and protected extension handling.
@param pubkey_info: List of VM user pubkey dicts that were previously
    obtained from provisioning data.
    Each pubkey dict in this list can either have the format
    pubkey['value'] or pubkey['fingerprint'].
    Each pubkey['fingerprint'] in the list is used to filter
    and obtain the actual pubkey value from the GoalState
    certificates XML.
    Each pubkey['value'] requires no further processing and is
    immediately added to the return list.
@return: A list of the VM user's authorized pubkey values.
z/Certificate XML found; parsing out public keys.)r   rs  r=   r>   r7  _filter_pubkeys)r   rB  r  r  keys_by_fingerprints   &&&  r#   r  "WALinuxAgentShim._get_user_pubkeysb  sl    : ''3'$$0IIGH"&"6"6"I"I++# ++,?MHr%   c                ,   < V ^8  d   QhRS[ RS[RS[/# )r   r  r  r!   )r   r  )r"   r   s   "r#   r$   rq    s"     ! !T ! ! !r%   c                T   . pV F  pRV9   d*   VR,          '       d   VP                  VR,          4       K3  RV9   dP   VR,          '       dA   VR,          pW@9   d   VP                  W,          4       Kq  \        P                  RV4       K  \        P                  RV4       K  	  V# )a  Filter and return only the user's actual pubkeys.

@param keys_by_fingerprint: pubkey fingerprint -> pubkey value dict
    that was obtained from GoalState Certificates XML. May contain
    non-user pubkeys.
@param pubkey_info: List of VM user pubkeys. Pubkey values are added
    to the return list without further processing. Pubkey fingerprints
    are used to filter and obtain the actual pubkey values from
    keys_by_fingerprint.
@return: A list of the VM user's authorized pubkey values.
r  r6  zIovf-env.xml specified PublicKey fingerprint %s not found in goalstate XMLzFovf-env.xml specified PublicKey with neither value nor fingerprint: %s)r1  r=   r   )r  r  r5  pubkeyr6  s   &&   r#   r   WALinuxAgentShim._filter_pubkeys  s     !F& VG__F7O,&(VM-B-B$]35KK 3 @AKK8# 0 "( r%   )r   rC  rs  r   )r+   r   r   r   r   r   r2   r}  r  r  r  r  r  r  r;  r  r   r   r   s   @r#   ro  ro    s     M M
, ! ! !# # !#J !E !E !
 !
 !! !!4 ! !B !' !'R ! !r%   ro  c          	          V ^8  d   QhR\         R\        P                  R\        \        \         ,          ,          R\        \         ,          /# )r   rC  rx  r  r|  )ra   r   ry  r
   r	   )r"   s   "r#   r$   r$     sA      NN $s)$ c]	r%   c                     \        V R 7      p VP                  WVR7      VP                  4        #   TP                  4        i ; i)rC  )rx  r  r|  )ro  r  r   )rC  rx  r  r|  shims   &&&& r#   get_metadata_from_fabricr    s@     X.D66G 7 
 	s	   1 Ac                0    V ^8  d   QhR\         R\         /# )r   rC  encoded_reportrW  )r"   s   "r#   r$   r$     s      s s r%   c                    \        V R 7      p VP                  VR7       VP                  4        R#   TP                  4        i ; i)r  r  N)ro  r  r   )rC  r  r  s   &$ r#   report_failure_to_fabricr    s5    X.D333Os	   2 Ac                @    V ^8  d   QhR\         R\         R\         RR/# )r   	interfacerM   errr!   NrW  )r"   s   "r#   r$   r$     s(      3 S s t r%   c                     \        R V  RV 2\        P                  R7       \        RV  RV 2\        P                  R7       R# )z!dhcp client stdout for interface=z: r~   z!dhcp client stderr for interface=N)rh   r=   r>   )r  rM   r  s   &&&r#   dhcp_log_cbr    sB    
+I;b>II 
+I;b>IIr%   c                       ] tR tRtRtR# )NonAzureDataSourcei  r1   N)r+   r   r   r   r   r1   r%   r#   r  r    s    r%   r  c                      a  ] tR tRt o RRRR/tRRRRR	RR
RRRRRRRRRRR/	V 3R lR lltV 3R lR lt]V 3R lR l4       tRV 3R lR llt	R V 3R lR llt
R tR tR tRtV tR# )!	OvfEnvXmli  ovfz)http://schemas.dmtf.org/ovf/environment/1waz)http://schemas.microsoft.com/windowsazurer   Npasswordr   custom_datar   public_keyspreprovisioned_vmFpreprovisioned_vm_typeprovision_guest_proxy_agentc                   < V ^8  d   QhRS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          RS[ S[,          RS[ S[S[,          ,          RS[RS[ S[,          R	S[R
R/
# )r   r   r  r   r  r   r  r  r  r  r!   N)r
   ra   r   r   r	   r   )r"   r   s   "r#   r$   OvfEnvXml.__annotate__  s     G G 3-G 3-	G
 3-G e_G $,D>G d4j)G  G !)G &*G 
Gr%   c       	            Wn         W n        W0n        W@n        WPn        T;'       g    . V n        Wpn        Wn        Wn        R # r   )	r   r  r   r  r   r  r  r  r  )
r   r   r  r   r  r   r  r  r  r  s
   &$$$$$$$$$r#   r   OvfEnvXml.__init__  sA     !  &)B&'2'8'8b!2&<#+F(r%   c                    < V ^8  d   QhRS[ /# r   )r   )r"   r   s   "r#   r$   r    s     / /t /r%   c                4    V P                   VP                   8H  # r   )__dict__)r   others   &&r#   __eq__OvfEnvXml.__eq__  s    }}..r%   c                $   < V ^8  d   QhRS[ RR/# )r   ovf_env_xmlr!   r  rW  )r"   r   s   "r#   r$   r    s      S [ r%   c                H    \         P                  ! V4      pTP                  RT P                  4      f   \        R4      h\        4       pTP                  T4       TP                  T4       T#   \         P                   d   p\        P                  ! TR7      ThRp?ii ; i)zParser for ovf-env.xml data.

:raises NonAzureDataSource: if XML is not in Azure's format.
:raises errors.ReportableErrorOvfParsingException: if XML is
        unparsable or invalid.
)	exceptionNz./wa:ProvisioningSectionz=Ignoring non-Azure ovf-env.xml: ProvisioningSection not found)r   r   r   r   "ReportableErrorOvfParsingExceptionr   
NAMESPACESr  r  &_parse_linux_configuration_set_section _parse_platform_settings_section)clsr  r   rL   instances   &&   r#   
parse_textOvfEnvXml.parse_text  s    	P==-D
 99/@H$O  ;77=11$7 }} 	P;;aHaO	Ps   A/ /B!BB!c                ,   < V ^8  d   QhRS[ RS[RS[ /# )r   r   required	namespacera   r   )r"   r   s   "r#   r$   r    s+        	
 r%   c                `   VP                  R V: RV: 2\        P                  4      pV'       g?   RV,          p\        P	                  V4       V'       d   \
        P                  ! V4      hR# \        V4      ^8  d)   \
        P                  ! RV\        V4      3,          4      hV^ ,          # )z./r  missing configuration for %rN*multiple configuration matches for %r (%d))findallr  r  r=   r>   r   !ReportableErrorOvfInvalidMetadatalen)r   noder   r  r  matchesr`   s   &&&&&  r#   _findOvfEnvXml._find  s     ,,"D)9+?+?
 047CIIcN>>sCC\A::<W&' 
 qzr%   c                2   < V ^8  d   QhRS[ RS[RS[RS[/# )r   r   r  decode_base64
parse_boolr  )r"   r   s   "r#   r$   r  *  s5     # # # 	#
 # #r%   c                <   VP                  R V,           \        P                  4      pV'       g?   RV,          p\        P	                  V4       V'       d   \
        P                  ! V4      hV# \        V4      ^8  d)   \
        P                  ! RV\        V4      3,          4      hV^ ,          P                  p	V	f   Tp	V'       d8   V	e4   \        P                  ! RP                  V	P                  4       4      4      p	V'       d   \        P                  ! V	4      p	V	# )z./wa:r  r  r   )r  r  r  r=   r>   r   r  r  r   ro   	b64decoder!  rB   r   translate_bool)
r   r  r   r  r  r  defaultr  r`   r  s
   &&&&&&&   r#   _parse_propertyOvfEnvXml._parse_property*  s     ,,w~y/C/CD047CIIcN>>sCCNw<!::<W&' 
 
 =EU.$$RWWU[[]%;<E''.Er%   c                v   V P                  VR RR7      pV P                  VRRR7      pV P                  VRRRR7      V n        V P                  VRRR7      V n        V P                  VRRR7      V n        V P                  VR	RR7      V n        V P                  VR
RRR7      V n        V P                  V4       R# )ProvisioningSectionTr  !LinuxProvisioningConfigurationSet
CustomDataF)r  r  UserNameUserPasswordHostName DisableSshPasswordAuthentication)r  r  N)r  r  r  r   r  r   r   _parse_ssh_section)r   r   provisioning_section
config_sets   &&  r#   r  0OvfEnvXml._parse_linux_configuration_set_sectionO  s    #zz'$  *  
 ZZ /   

  //	 0 
 ,,
U - 
 ,, - 
 ,,
T - 
 *.)=)=.	 *> *
& 	
+r%   c                    V P                  VR RR7      pV P                  VRRR7      pV P                  VRRRRR7      V n        V P                  VRRR7      V n        V P                  VRRRRR7      V n        R	# )
PlatformSettingsSectionTr  PlatformSettingsPreprovisionedVmF)r  r  r  PreprovisionedVMTypeProvisionGuestProxyAgentN)r  r  r  r  r  )r   r   platform_settings_sectionplatform_settingss   &&  r#   r  *OvfEnvXml._parse_platform_settings_sectionq  s    $(JJ+d %/ %
! !JJ%'9D ' 
 "&!5!5 "6 "
 '+&:&:" '; '
#
 ,0+?+?& ,@ ,
(r%   c                   . V n         V P                  VR RR7      pVf   R# V P                  VRRR7      pVf   R# VP                  R\        P                  4       Fc  pV P                  VRRR7      pV P                  VRRR7      pV P                  VRR	RR
7      pRVRVRV/pV P                   P                  V4       Ke  	  R# )SSHFr  N
PublicKeysz./wa:PublicKeyFingerprintPathValuer   )r  r  r6  r   r  )r  r  r  r  r  r  r1  )	r   r  ssh_sectionpublic_keys_section
public_keyr6  r   r  r  s	   &&       r#   r  OvfEnvXml._parse_ssh_section  s    jjUUjC"jj ) 
 &-55i22
J ..ME / K ''
FU'KD((GR% ) E {G
 ##G,
r%   )	r  r   r   r  r  r  r  r  r   )r  )FFN)r+   r   r   r   r  r   r  classmethodr  r  r  r  r  r  r   r   r   s   @r#   r  r    s     :9J
G #'G #'	G
 #'G (,G 59G -1G #(G 15G -2G G./ /  0 0# #J ,D
8- -r%   r  r   )Cro   ru   loggingr   r2  r   rq   
contextlibr   r   r   r   r   typingr   r	   r
   r   r   	xml.etreer   r   xml.sax.saxutilsr   	cloudinitr   r   r   r   r   r   cloudinit.reportingr   cloudinit.sources.azurer   	getLoggerr+   r=   DEFAULT_WIRESERVER_ENDPOINTrE   rZ   rg   rt   r*   r,   r   r2   rS   r]   rh   r{   r   r   r   r   r   r   r   r   r   r=  ro  r  r  r  r  r  r1   r%   r#   <module>r     s  
    	 	   % '  ; ; ' # J J & *! . "% $ $ ++	2  CL	 R Rj  4!$* 

 

   3 !	3
 3 3 3l-`B B:D9 D< <~ D[E [E|b bJ    	 	P- P-r%   