
Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­Â�Â­
<!DOCTYPE html>
<html>
3
\¼me  ã               @   sr   d Z ddlZddlZddlmZ ejeƒZdddddgZd	d
„ Z	dd„ Z
ddd„Zddd„Zdd„ Zddd„ZdS )z0gpg.py - Collection of gpg key related functionsé    N)ÚsubpÚgpgz--with-fingerprintz--no-default-keyringz--list-keysz	--keyringc             C   sZ   yt j ddd| gdd�\}}W n6 t jk
rT } ztjd| |ƒ d}W Y dd}~X nX |S )z*Export gpg key, armoured key gets returnedr   z--exportz--armourT)Úcapturez&Failed to export armoured key "%s": %sN)r   ÚProcessExecutionErrorÚLOGÚdebug)ÚkeyÚarmourÚ_Úerror© r   ú/usr/lib/python3.6/gpg.pyÚexport_armour   s    r   c             C   s   t j ddg| dd�jS )z~Dearmor gpg key, dearmored key gets returned

    note: man gpg(1) makes no mention of an --armour spelling, only --armor
    r   z	--dearmorF)ÚdataÚdecode)r   Ústdout)r   r   r   r   Údearmor'   s    r   Fc             C   sN   g }|j tƒ |s|jdƒ |j| ƒ tj|dd�\}}|rJtjd| |ƒ |S )zâList keys from a keyring with fingerprints. Default to a stable machine
    parseable format.

    @param key_file: a string containing a filepath to a key
    @param human_output: return output intended for human parsing
    z--with-colonsT)r   z&Failed to export armoured key "%s": %s)ÚextendÚGPG_LISTÚappendr   r   Úwarning)Zkey_fileZhuman_outputÚcmdr   Ústderrr   r   r   Úlist/   s    


r   é   c       	       C   sú   t jd| |ƒ ddd| d| g}|dkr,g }d}d}t|ƒ}x¸|d7 }y"tj|d	d
� t jd| ||ƒ dS  tjk
r� } z
|}W Y dd}~X nX y&t|ƒ}t jd|j|ƒ tj|ƒ W q> t	k
rð } zt
d| |||f ƒ|‚W Y dd}~X q>X q>W dS )aÁ  Receive gpg key from the specified keyserver.

    Retries are done by default because keyservers can be unreliable.
    Additionally, there is no way to determine the difference between
    a non-existant key and a failure.  In both cases gpg (at least 2.2.4)
    exits with status 2 and stderr: "keyserver receive failed: No data"
    It is assumed that a key provided to cloud-init exists on the keyserver
    so re-trying makes better sense than failing.

    @param key: a string key fingerprint (as passed to gpg --recv-keys).
    @param keyserver: the keyserver to request keys from.
    @param retries: an iterable of sleep lengths for retries.
                    Use None to indicate no retries.z&Importing key '%s' from keyserver '%s'r   z--no-ttyz--keyserver=%sz--recv-keysNr   r   T)r   z/Imported key '%s' from keyserver '%s' on try %dz6Import failed with exit code %d, will try again in %ssz@Failed to import key '%s' from keyserver '%s' after %d tries: %s)r   r   Úiterr   r   ÚnextZ	exit_codeÚtimeZsleepÚStopIterationÚ
ValueError)	r   Ú	keyserverZretriesr   Ztrynumr   ZsleepsÚeZnaplenr   r   r   Úrecv_keyB   s>    r"   c             C   sT   yt j dddd| gdd� W n2 t jk
rN } ztjd| |ƒ W Y dd}~X nX dS )	z0Delete the specified key from the local gpg ringr   z--batchz--yesz--delete-keysT)r   zFailed delete key "%s": %sN)r   r   r   r   )r   r   r   r   r   Ú
delete_keys   s
    r#   úkeyserver.ubuntu.comc             C   s\   t | ƒ}|sXz@yt| |d� t | ƒ}W n" tk
rH   tjd| ƒ ‚ Y nX W dt| ƒ X |S )zget gpg keyid from keyserver)r    zFailed to obtain gpg key %sN)r   r"   r   r   Z	exceptionr#   )Zkeyidr    r	   r   r   r   Ú
getkeybyid}   s    
r%   )F©r   r   )r&   )r$   )Ú__doc__Zloggingr   Z	cloudinitr   Z	getLoggerÚ__name__r   r   r   r   r   r"   r#   r%   r   r   r   r   Ú<module>   s   


1
