Ë
    M/Åe”)  ã                   ó¢  — U d Z ddlZddlmZ ddlmZ ddlmZ ddlmZ ddlmZ ddlm	Z	 dd	lm
Z
 dd
lmZ ddlmZ ddlmZ ddlmZ dd	lm
Z  ej(                  e«      Zdej.                  ddfd„Zdedee   fd„Zdededdfd„Zdej.                  ddfd„Z e«       Zee   ed<   deddfd„Z dej.                  dee   ddfd„Z!g Z"ee   ed<   deddfd„Z#dee   dee   ddfd„Z$dej.                  dee   d eddfd!„Z%dej.                  dee   d eddfd"„Z&dedee   d ed#e'd$e'ddfd%„Z(d+d&eded'eeeef      defd(„Z)d)edee   fd*„Z*y),z;Facilities for implementing hooks that call shell commands.é    N)ÚDict)ÚList)ÚOptional)ÚSet)Úconfiguration)Úerrors)Úutil)Ú
filesystem)Úmisc)Úos)ÚopsÚconfigÚreturnc                 ó´   — t        | j                  d«       t        | j                  d«       t        | j                  d«       t        | j                  d«       y)z#Check hook commands are executable.ÚpreÚpostÚdeployÚrenewN)Úvalidate_hookÚpre_hookÚ	post_hookÚdeploy_hookÚ
renew_hook)r   s    ú9/usr/lib/python3/dist-packages/certbot/_internal/hooks.pyÚvalidate_hooksr      s@   € ä�&—/‘/ 5Ô)Ü�&×"Ñ" FÔ+Ü�&×$Ñ$ hÔ/Ü�&×#Ñ# WÕ-ó    Ú	shell_cmdc                 óÀ   — t        j                  | «      s+t        j                  | «       t        j                  | «      syt        j
                  j                  | «      S )zÁExtract the program run by a shell command.

    :param str shell_cmd: command to be executed

    :returns: basename of command or None if the command isn't found
    :rtype: str or None

    N)r	   Ú
exe_existsÚ	plug_utilÚpath_surgeryr   ÚpathÚbasename)r   s    r   Ú_progr$      sB   € ô �?‰?˜9Ô%Ü×Ñ˜yÔ)Ü�‰˜yÔ)Øä�7‰7×Ñ˜IÓ&Ð&r   Ú	hook_namec                 ó  — | r}| j                  dd«      d   }t        |«      s\t        j                  d   }t        j                  j                  |«      r	|› d|› d�}nd|› d|› d|› d	�}t        j                  |«      ‚yy)
z‹Check that a command provided as a hook is plausibly executable.

    :raises .errors.HookCommandNotFound: if the command is not found
    Né   r   ÚPATHz-hook command z exists, but is not executable.zUnable to find z in the PATH.
(PATH is z0)
See also the --disable-hook-validation option.)Úsplitr$   r   Úenvironr"   Úexistsr   ÚHookCommandNotFound)r   r%   Úcmdr"   Úmsgs        r   r   r   .   s–   € ñ
 Ø�o‰o˜d AÓ& qÑ)ˆÜ�SŒzÜ—:‘:˜fÑ%ˆDÜ�w‰w�~‰~˜cÔ"Ø˜˜^¨I¨;Ð6UÐV‘ð & i [°¸s¸eÐC[Ø�fÐMðOð ô
 ×,Ñ,¨SÓ1Ð1ð ð r   c                 ó¸   — | j                   dk(  r1| j                  r%t        | j                  «      D ]  }t	        |«       Œ | j
                  }|rt	        |«       yy)aå  Run pre-hooks if they exist and haven't already been run.

    When Certbot is running with the renew subcommand, this function
    runs any hooks found in the config.renewal_pre_hooks_dir (if they
    have not already been run) followed by any pre-hook in the config.
    If hooks in config.renewal_pre_hooks_dir are run and the pre-hook in
    the config is a path to one of these scripts, it is not run twice.

    :param configuration.NamespaceConfig config: Certbot settings

    r   N)ÚverbÚdirectory_hooksÚ
list_hooksÚrenewal_pre_hooks_dirÚ_run_pre_hook_if_necessaryr   )r   Úhookr-   s      r   r   r   B   sU   € ð ‡{�{�gÒ &×"8Ò"8Ü˜v×;Ñ;Ó<ò 	-ˆDÜ& tÕ,ð	-ð �/‰/€CÙ
Ü" 3Õ'ð r   Úexecuted_pre_hooksÚcommandc                 ó„   — | t         v rt        j                  d| «       yt        d| «       t         j	                  | «       y)zÑRun the specified pre-hook if we haven't already.

    If we've already run this exact command before, a message is logged
    saying the pre-hook was skipped.

    :param str command: pre-hook to be run

    z*Pre-hook command already run, skipping: %szpre-hookN)r6   ÚloggerÚinfoÚ	_run_hookÚadd©r7   s    r   r4   r4   Z   s4   € ð Ô$Ñ$Ü�‰Ð@À'ÕJä�*˜gÔ&Ü×Ñ˜wÕ'r   Úrenewed_domainsc                 óR  — | j                   }| j                  dk(  r@| j                  r%t        | j                  «      D ]  }t        |«       Œ |rt        |«       yy|rJdj                  |«      }t        |«      dkD  rt        j                  d«       |dd }t        d||ddœ«       yy)	a…  Run post-hooks if defined.

    This function also registers any executables found in
    config.renewal_post_hooks_dir to be run when Certbot is used with
    the renew subcommand.

    If the verb is renew, we delay executing any post-hooks until
    :func:`run_saved_post_hooks` is called. In this case, this function
    registers all hooks found in config.renewal_post_hooks_dir to be
    called followed by any post-hook in the config. If the post-hook in
    the config is a path to an executable in the post-hook directory, it
    is not scheduled to be run twice.

    :param configuration.NamespaceConfig config: Certbot settings

    r   ú i }  z?Limiting RENEWED_DOMAINS environment variable to 32k charactersNú	post-hookÚ ©ÚRENEWED_DOMAINSÚFAILED_DOMAINS)r   r0   r1   r2   Úrenewal_post_hooks_dirÚ_run_eventuallyÚjoinÚlenr9   Úwarningr;   )r   r>   r-   r5   Úrenewed_domains_strs        r   r   r   j   s²   € ð, ×
Ñ
€Cà‡{�{�gÒØ×!Ò!Ü" 6×#@Ñ#@ÓAò &�Ü Õ%ð&áÜ˜CÕ ð ñ 
Ø!Ÿh™h Ó7ÐäÐ"Ó# fÒ,Ü�N‰NÐ\Ô]Ø"5°g°vÐ">ÐäØØà#6ð #%ñ	õ		
ð 
r   Ú
post_hooksc                 ó@   — | t         vrt         j                  | «       yy)zúRegisters a post-hook to be run eventually.

    All commands given to this function will be run exactly once in the
    order they were given when :func:`run_saved_post_hooks` is called.

    :param str command: post-hook to register to be run

    N)rL   Úappendr=   s    r   rG   rG   Ÿ   s   € ð ”jÑ Ü×Ñ˜'Õ"ð !r   Úfailed_domainsc                 ó  — dj                  | «      }dj                  |«      }t        |«      dkD  rt        j                  d«       |dd }t        |«      dkD  rt        j                  d«       |dd }t        D ]  }t        d|||dœ«       Œ y)zGRun any post hooks that were saved up in the course of the 'renew' verbr@   i€>  z?Limiting RENEWED_DOMAINS environment variable to 16k charactersNz>Limiting FAILED_DOMAINS environment variable to 16k charactersrA   rC   )rH   rI   r9   rJ   rL   r;   )r>   rO   rK   Úfailed_domains_strr-   s        r   Úrun_saved_post_hooksrR   ¬   sœ   € ð Ÿ(™( ?Ó3ÐØŸ™ .Ó1Ðô ÐÓ &Ò(Ü�‰ÐXÔYØ1°'°6Ð:Ðä
ÐÓ Ò'Ü�‰ÐWÔXØ0°°&Ð9Ðäò 
ˆÜØØà#6Ø"4ñõ	
ñ
r   ÚdomainsÚlineage_pathc                 óx   — | j                   r.t        | j                   ||| j                  | j                  «       yy)a  Run post-issuance hook if defined.

    :param configuration.NamespaceConfig config: Certbot settings
    :param domains: domains in the obtained certificate
    :type domains: `list` of `str`
    :param str lineage_path: live directory path for the new cert

    N)r   Ú_run_deploy_hookÚdry_runÚrun_deploy_hooks)r   rS   rT   s      r   r   r   Æ   s6   € ð ×ÒÜ˜×+Ñ+¨WØ% v§~¡~°v×7NÑ7Nõ	Pð r   c                 óž  — t        «       }| j                  rNt        | j                  «      D ]6  }t	        |||| j
                  | j                  «       |j                  |«       Œ8 | j                  r]| j                  |v r!t        j                  d| j                  «       yt	        | j                  ||| j
                  | j                  «       yy)a]  Run post-renewal hooks.

    This function runs any hooks found in
    config.renewal_deploy_hooks_dir followed by any renew-hook in the
    config. If the renew-hook in the config is a path to a script in
    config.renewal_deploy_hooks_dir, it is not run twice.

    If Certbot is doing a dry run, no hooks are run and messages are
    logged saying that they were skipped.

    :param configuration.NamespaceConfig config: Certbot settings
    :param domains: domains in the obtained certificate
    :type domains: `list` of `str`
    :param str lineage_path: live directory path for the new cert

    z0Skipping deploy-hook '%s' as it was already run.N)Úsetr1   r2   Úrenewal_deploy_hooks_dirrV   rW   rX   r<   r   r9   r:   )r   rS   rT   Úexecuted_dir_hooksr5   s        r   r   r   Õ   s´   € ô$ ›ÐØ×ÒÜ˜v×>Ñ>Ó?ò 	)ˆDÜ˜T 7¨L¸&¿.¹.È&×JaÑJaÔbØ×"Ñ" 4Õ(ð	)ð ×ÒØ×ÑÐ 2Ñ2Ü�K‰KÐJØ×)Ñ)õ+ô ˜V×.Ñ.°Ø)¨6¯>©>¸6×;RÑ;RõTð r   rW   rX   c                 ó¼   — |r|st         j                  d| «       ydj                  |«      t        j                  d<   |t        j                  d<   t        d| «       y)at  Run the specified deploy-hook (if not doing a dry run).

    If dry_run is True, command is not run and a message is logged
    saying that it was skipped. If dry_run is False, the hook is run
    after setting the appropriate environment variables.

    :param str command: command to run as a deploy-hook
    :param domains: domains in the obtained certificate
    :type domains: `list` of `str`
    :param str lineage_path: live directory path for the new cert
    :param bool dry_run: True iff Certbot is doing a dry run
    :param bool run_deploy_hooks: True if deploy hooks should run despite Certbot doing a dry run

    z)Dry run: skipping deploy hook command: %sNr@   rD   ÚRENEWED_LINEAGEzdeploy-hook)r9   r:   rH   r   r*   r;   )r7   rS   rT   rW   rX   s        r   rV   rV   ö   sP   € ñ  Ñ'Ü�‰Ð?Øô	 àà$'§H¡H¨WÓ$5„B‡J�JÐ Ñ!Ø$0„B‡J�JÐ Ñ!Üˆm˜WÕ%r   Úcmd_nameÚ	extra_envc                 óÈ   — t        j                  «       }|j                  |xs i «       t        j                  | ||¬«      \  }}}t        j                  d| › d�|||«       |S )aH  Run a hook command.

    :param str cmd_name: the user facing name of the hook being run
    :param shell_cmd: shell command to execute
    :type shell_cmd: `list` of `str` or `str`
    :param dict extra_env: extra environment variables to set
    :type extra_env: `dict` of `str` to `str`

    :returns: stderr if there was any)ÚenvzHook 'ú')r	   Úenv_no_snap_for_external_callsÚupdater   Úexecute_command_statusÚdisplay_opsÚreport_executed_command)r_   r   r`   rb   Ú
returncodeÚerrÚouts          r   r;   r;     sb   € ô ×
-Ñ
-Ó
/€CØ‡J�JˆyŠ˜BÔÜ×6Ñ6Ø�) ô&Ñ€J��Sä×'Ñ'¨&°°
¸!Ð(<¸jÈ#ÈsÔSØ€Jr   Údir_pathc                 óÎ   ‡ — ˆ fd„t        j                  ‰ «      D «       }|D �cg c],  }t        j                  |«      sŒ|j	                  d«      rŒ+|‘Œ. }}t        |«      S c c}w )zÒList paths to all hooks found in dir_path in sorted order.

    :param str dir_path: directory to search

    :returns: `list` of `str`
    :rtype: sorted list of absolute paths to executables in dir_path

    c              3   ó^   •K  — | ]$  }t         j                  j                  ‰|«      –— Œ& y ­w©N)r   r"   rH   )Ú.0Úfrl   s     €r   ú	<genexpr>zlist_hooks.<locals>.<genexpr>+  s    øè ø€ ÒH¨a”—‘—‘˜X q×)ÑHùs   ƒ*-ú~)r   Úlistdirr
   Úis_executableÚendswithÚsorted)rl   Úallpathsr"   Úhookss   `   r   r2   r2   "  sX   ø€ ó I´2·:±:¸hÓ3GÔH€HØ&Öd�d¬*×*BÑ*BÀ4Õ*HÐQU×Q^ÑQ^Ð_bÕQcŠTÐd€EÐdÜ�%‹=Ðùò es   ¤A"¿A"ÁA"ro   )+Ú__doc__ÚloggingÚtypingr   r   r   r   Úcertbotr   r   r	   Úcertbot.compatr
   r   r   Úcertbot.displayr   rg   Úcertbot.pluginsr    Ú	getLoggerÚ__name__r9   ÚNamespaceConfigr   Ústrr$   r   r   rZ   r6   Ú__annotations__r4   r   rL   rG   rR   r   r   ÚboolrV   r;   r2   © r   r   ú<module>rˆ      s  ðÚ Aã Ý Ý Ý Ý å !Ý Ý Ý %Ý Ý Ý .Ý -à	ˆ×	Ñ	˜8Ó	$€ð.˜=×8Ñ8ð .¸Tó .ð'�Sð '˜X c™]ó 'ð"2˜Sð 2¨Sð 2°Tó 2ð((�]×2Ñ2ð (°tó (ñ*  #›uÐ �C˜‘HÓ $ð(¨ð (°ó (ð /
Ø×)Ñ)ð/
à˜#‘Yð/
ð 
ó/
ðd €
ˆD�‰IÓ ð
#˜Sð 
# Tó 
#ð
¨$¨s©)ð 
ÀTÈ#ÁYð 
ÐSWó 
ð4P˜×5Ñ5ð PÀÀSÁ	ð PØ!ðPØ&*óPðT�}×4Ñ4ð T¸tÀC¹yð TØ ðTØ%)óTðB&˜cð &¨D°©Ið &ÀSð &ÐSWð &Ø'+ð&Ø04ó&ñ4˜ð ¨ð ¸ÀÀcÈ3ÀhÁÑ8Pð Ð\_ó ð$˜ð   c¡ô r   