3 \me @sUdZddlZddlZddlZddlZddlZddlZddlZddlm Z m Z ddl m Z m Z mZmZddlmZmZmZmZmZddlmZddlmZddlmZmZdd lmZeje Z!d Z"d Z#d Z$d Z%dZ&eZ'ddgZ(dddZ)ee*e*f)ddde de(e de dge'gdZ+e+ee+ZdZ,dZ-dZ.dZ/dd d!Z0d"d"d!Z1d#d$gZ2d%d&d'd(d)d*gZ3d}d+d,Z4e*eee5dd-d.d/Z6d0d1Z7d2d3Z8d~d4d5Z9dd6d7Z:dd8d9Z;d:d;Zd?Z>d@dAZ?e*e*dBdCdDZ@e*dEdFdGZAe*dEdHdIZBdJdKZCe*eDdLdMdNZEdOdPdQdRZFdSZGe e*e*fdEdTdUZHdVdWZIddYdZZJd[d\ZKdd]d^ZLd_d`ZMddadbZNdcddZOdedfZPdgdhZQdidjZRdkdlZSdmdnZTdodpZUdqdrZVdsdtZWddudvZXdwdxZYddzd{ZZd|e.sources`. When the value of `sources_list` does not appear to be deb822 format, or stable distribution releases disable deb822 format, :file:`/etc/apt/sources.list` will be written instead. .. note:: To ensure that apt configuration is valid yaml, any strings containing special characters, especially ``:`` should be quoted. .. note:: For more information about apt configuration, see the ``Additional apt configuration`` example.a- apt: preserve_sources_list: false disable_suites: - $RELEASE-updates - backports - $RELEASE - mysuite primary: - arches: - amd64 - i386 - default uri: 'http://us.archive.ubuntu.com/ubuntu' search: - 'http://cool.but-sometimes-unreachable.com/ubuntu' - 'http://us.archive.ubuntu.com/ubuntu' search_dns: false - arches: - s390x - arm64 uri: 'http://archive-to-use-for-arm64.example.com/ubuntu' security: - arches: - default search_dns: true sources_list: | deb $MIRROR $RELEASE main restricted deb-src $MIRROR $RELEASE main restricted deb $PRIMARY $RELEASE universe restricted deb $SECURITY $RELEASE-security multiverse debconf_selections: set1: the-package the-package/some-flag boolean true conf: | APT { Get { Assume-Yes 'true'; Fix-Broken 'true'; } } proxy: 'http://[[user][:pass]@]host[:port]/' http_proxy: 'http://[[user][:pass]@]host[:port]/' ftp_proxy: 'ftp://[[user][:pass]@]host[:port]/' https_proxy: 'https://[[user][:pass]@]host[:port]/' sources: source1: keyid: 'keyid' keyserver: 'keyserverurl' source: 'deb [signed-by=$KEY_FILE] http:/// bionic main' source2: source: 'ppa:' source3: source: 'deb $MIRROR $RELEASE multiverse' key: | ------BEGIN PGP PUBLIC KEY BLOCK------- ------END PGP PUBLIC KEY BLOCK------- source4: source: 'deb $MIRROR $RELEASE multiverse' append: false key: | ------BEGIN PGP PUBLIC KEY BLOCK------- ------END PGP PUBLIC KEY BLOCK-------a # cloud-init version 23.4 will generate a deb822 formatted sources # file at /etc/apt/sources.list.d/.sources instead of # /etc/apt/sources.list when `sources_list` content is deb822 # format. apt: sources_list: | Types: deb URIs: http://archive.ubuntu.com/ubuntu/ Suites: $RELEASE Components: main )idnametitle descriptiondistrosZexamples frequencyZactivate_by_schema_keysz/var/lib/apt/listsz'/etc/apt/apt.conf.d/94cloud-init-configz)/etc/apt/apt.conf.d/90cloud-init-aptproxyzkeyserver.ubuntu.comz!http://archive.ubuntu.com/ubuntu/z"http://security.ubuntu.com/ubuntu/)PRIMARYSECURITYz$http://ports.ubuntu.com/ubuntu-portsamd64Zi386Zs390xZarm64ZarmhfZpowerpcZppc64elZriscv64cCsB|dkrtj|}|tkr"tjS|tkr2tjStd|dS)zreturns the default mirrors for the target. These depend on the architecture, for more see: https://wiki.ubuntu.com/UbuntuDevelopment/PackageArchive#PortsNz#No default mirror known for arch %s)r get_dpkg_architecturePRIMARY_ARCHESPRIMARY_ARCH_MIRRORScopy PORTS_ARCHES PORTS_MIRRORS ValueError)archtargetr$&/usr/lib/python3.6/cc_apt_configure.pyget_default_mirrorss r&)rcfgcloudargsreturncCsPd}t|}|jdi}t|ts6tdjt|dt||t|||dS)zprocess the config for apt_config. This can be called from curthooks if a global apt config was provided or via the "apt" standalone command.Naptz9Expected dictionary for 'apt' config, found {config_type})Z config_type) convert_to_v3_apt_formatget isinstancedictr!formattypeapply_debconf_selections apply_apt)rr'r(r)r#apt_cfgr$r$r%handles   r5cCs(tjr dStjdptjds$d Sd S) NFsystem is snappy.zapt-getr+no apt commands.TApt is available.)Fr6)Fr7)Tr8)r Zsystem_is_snappyr whichr$r$r$r%_should_configure_on_empty_apts r:cCs|s"t\}}|s"tjd|dStjd|tj|dd}tj|}t|||d}tjd|d}|jdt} | rt j | j }t |||tj |jdd rt|||t||||t|||yt|ttWn"ttfk rtjd YnXd |kr2|} || d <|d | d <t|d ||| |dtjdddddddg|dddgd\} } t jd| } dd| D}|rtjd|x|D]}tj|tjqWdS)Nz#Nothing to do: No apt config and %szhandling apt config: %s)r#codename)r"zApt Mirror info: %sadd_apt_repo_matchpreserve_sources_listFz)Failed to apply proxy or apt config info:sourcesRELEASEMIRROR)r#template_params aa_repo_matchZpsz-ozppid,pidz-CZdirmngrz gpg-agentTr)r#capturercsz(?P\d+)\s+(?P\d+)cSs$g|]}|ddkrt|dqS)r1rC)int).0pidr$r$r% szapply_apt..z&Killing gpg-agent and dirmngr pids: %s)r:LOGdebugr Z lsb_releaserfind_apt_mirror_infor-ADD_APT_REPO_MATCHrecompilesearch_ensure_dependenciesis_falseadd_mirror_keysgenerate_sources_listrename_apt_listsapply_apt_config APT_PROXY_FN APT_CONFIG_FNIOErrorOSError exceptionadd_apt_sourcesr findalloskillsignalSIGKILL)r'r(r#Z should_configmsgreleaser"mirrorsZmatcherZmatchcfgparamsZgpg_process_outZ_errZgpg_pidsZ root_gpg_pidsZgpg_pidr$r$r%r3sX               r3cCs*|jds|d7}tjdg||dddS)N zdebconf-set-selectionsT)datar#rD)endswithr ) selectionsr#r$r$r%debconf_set_selections#s rkcCsg}g}xB|D]:}|tkr>tjd|t|||j|q|j|qWt|r`tjd|t|rtjddgt|d|dddS)Nzunconfiguring %szSThe following packages were installed and preseeded, but cannot be unconfigured: %szdpkg-reconfigurez--frontend=noninteractiveT)rhr#rD)CONFIG_CLEANERSrKrLappendlenwarningr list)Zpackagesr#Z unhandledZ to_configpkgr$r$r%dpkg_reconfigure.s&    rrc s|jdstjddSdjfddtjD}t|j|dt}xJj D]>\}}x4|j D](}|j dr~qnt j d d |}|j|qnWq\Wtj|}tjd ||j|} t| d krtjd dSt| |ddS)z2apply_debconf_selections - push content to debconfZdebconf_selectionsz(debconf_selections was not set in configN csg|] }|qSr$r$)rHkey)selsetsr$r%rJZsz,apply_debconf_selections..)r##z[:\s].*z pkgs_cfgd: %srzno need for reconfig)r-rKrLjoinsortedkeysrkencodesetitems splitlines startswithrOsubaddr Zget_installed_packages intersectionrnrr) r'r#rjZ pkgs_cfgdZ_keyZcontentlinerqZpkgs_installedZ need_reconfigr$)rur%r2Os(         r2cCs:tjtj|d}tjd|x|D]}tj|q$WdS)z%clean out any local cloud-init configz/etc/cloud/cloud.cfg.d/*dpkg*z#cleaning cloud-init config from: %sN)globr target_pathrKrLr_unlink)r#flistZdpkg_cfgr$r$r%clean_cloud_initrs   rcCsL|}|jdr|dd}|jd}|dkr<||dd}|jdd}|S) zmirrorurl_to_apt_fileprefix Convert a mirror url to the file prefix used by apt on disk to store cache information for that mirror. To do so do: - take off ???:// - drop tailing / - convert in string / to _/rrCz://N_)rifindreplace)mirrorstringposr$r$r%mirrorurl_to_apt_fileprefix}s    rc Cst|}tj|t}x|jD]\}}|j|}|s6q|tjjt |}|tjjt |} || krhqt |} xlt j d|D]Z} d| | | df} t j d| | ytj| | Wqtk rt jdddYqXqWqWdS)z>rename_apt_lists - rename apt lists to preserve old cache dataz%s_*z%s%sNzRenaming apt list %s to %szFailed to rename apt list:T)exc_info)r&r r APT_LISTSr}r-r_pathseprrnrrKrLrenamer[ro) Z new_mirrorsr#r"Zdefault_mirrorsZprerZomirrorZnmirrorZoprefixZnprefixZolenfilenameZnewnamer$r$r%rVs$  rVc Cs:dddddd}y ||}Wntk r4|}YnX|S)zthere are a few default names which will be auto-extended. This comes at the inability to use those names literally as suites, but on the other hand increases readability of the cfg quite a lotz$RELEASE-updatesz$RELEASE-backportsz$RELEASE-securityz$RELEASE-proposedz$RELEASE)ZupdatesZ backportssecurityZproposedrd)KeyError)suitemappingZretsuiter$r$r%map_known_suitess  r) deb822_entryr*cCs<tjd|s8tjdd|}tjtd|}dt|dS|S)z0If no active Suites, disable this deb822 source.z\nSuites:[ \t]+([\w-]+)z \nSuites:.*rwz7## Entry disabled by cloud-init, due to disable_suites z# disabled by cloud-init: )rOr^rDISABLE_SUITES_REDACT_PREFIXr)rr$r$r%%disable_deb822_section_without_suitess   r)r*c s*g}fdd|Dtjd|d}x|jD]}|jdr`|rT||d7}q2|j|q2| sn|jr|r|jt|d}|j|q2|}|jds||d7}q2r|jdd }fd d|D}||kr|t|d7}d d j |}||d7}q2W|r |jt|dj |S) z:reads the deb822 format config and comment disabled suitescs g|]}tjt|diqS)r?)r render_stringr)rHr)rdr$r%rJsz)disable_suites_deb822..zDisabling suites %s as %srwrvrszSuites:rCNcsg|]}|kr|qSr$r$)rHr)disabled_suite_namesr$r%rJszSuites:  ) rKrLr~rrmisspacersplitrrx) disabledsrcrdZnew_srcZnew_deb822_entryrZnew_lineZ orig_suitesZ new_suitesr$)rrdr%disable_suites_deb822sB        rc Cs|s|S|}t|r t|||Sx|D]}t|}tj|d|i}tjd||d}x|jdD]}|jdrx||7}q`|j }t |dkrd} |djdrx(|dd D]} | d7} | j d rPqW|| |krd |}||7}q`W|}q&W|S) zRreads the config for suites to be disabled and removes those from the templater?zDisabling suite %s as %srwTrvrC[N]z"# suite disabled by cloud-init: %s) is_deb822_sources_formatrrr rrKrLr~rrrnri) rrrdZretsrcrZ releasesuiteZnewsrcrZcolsZpcolcolr$r$r%disable_suitess6       rcCs8x2dD]*}x$|j|gD]}t||||dqWqWdS)z=Adds any keys included in the primary/security mirror clausesprimaryr) file_nameN)rr)r- add_apt_key)r'r(r#rtrr$r$r%rT!s rT)apt_src_contentr*cCs6tjd|tjrdStjd|tjr(dStjddS)a?Simple check for deb822 format for apt source content Only validates that minimal required keys are present in the file, which indicates we are likely deb822 format. Doesn't handle if multiple sections all contain deb822 keys. Return True if content looks like it is deb822 formatted APT source. z^(deb |deb-src )Fz'^(Types: |Suites: |Components: |URIs: )Tzapt.sources_list value does not match either deb822 source keys or deb/deb-src list keys. Assuming APT deb/deb-src list format.)rOr^MrKro)rr$r$r%r(s  rzetc/aptz sources.listzsources.list.d)zDir::EtczDir::Etc::sourcelistzDir::Etc::sourcepartsz@(Dir::Etc|Dir::Etc::sourceparts|Dir::Etc::sourcelist) \"([^\"]+)cCs0yJddl}|j|jjdtd}|jjdtd}|jjdtd}Wntk r ytjddg\}}WnNtjk rtd}td}td}d|d|d|d|dd SXtj t |}t |}|jdtd}|jdtd}|jdtd}YnXd|d|d|d|dd S) aReturn a dict of applicable apt configuration or defaults. Prefer python apt_pkg if present. Fallback to apt-config dump command if present out output parsed Fallback to DEFAULT_APT_CFG if apt-config commmand absent or output unparsable. rNzDir::EtczDir::Etc::sourcelistzDir::Etc::sourcepartsz apt-configdumpr) sourcelist sourceparts) apt_pkgZ init_configconfigr-DEFAULT_APT_CFG ImportErrorr ProcessExecutionErrorrOr^ APT_CFG_REr/)rZetcrrZapt_dumprZ matched_cfgZapt_cmd_configr$r$r% get_apt_cfgLs4   rcCsBt}|d}|d|jjd}tjr0|}n|}||d}x(|D] } || || <|| || j<qDW|jdd} | stjdtjrdnd } |j d |jj| } | s|j d } | stj d |dSt j | } t j| |} | rt| r ||krtjd ||}ntjd||}t|jd| |}t j||dddS)zgenerate_sources_list create a source.list file based on a custom or default template by replacing mirrors and release in the templaterrz.sources)r?r; sources_listNz1No custom template provided, fall back to builtinz.deb822rwz sources.list.z sources.listz#No template found, not rendering %szAProvided 'sources_list' user-data is deb822 format, writing to %szFProvided 'sources_list' user-data is not deb822 format, fallback to %sri)mode)rdistrorrZAPT_DEB822_SOURCE_LIST_FILElowerr-rKinfoZget_template_filenameror Z load_filer rrrLr write_file)r'rdrer(r4Zapt_sources_listZapt_sources_deb822Z aptsrc_filerfkZtmplZtmpl_fmtZ template_fnZrenderedrr$r$r%rUsH           rUFc CsPtjd|ytj|j}td|||dStjk rJtjdYnXdS)zM actual adding of a key as defined in key argument to the system zAdding key: '%s'r) output_filerhhardenedz(failed to add apt GPG Key to apt keyringN) rKrLpathlibZPathZstemapt_keyr rr\)rtrrr#rr$r$r%add_apt_key_raws   rc Csg}t}tj|jddr^x@d D]8}|j|r"x(||D]}ddhj|r:|jdq:Wq"W|jdi}xB|jD]6}ddhj|r|jd||jd d rt|jd qtWx$|D]} tj| s|j t | qW|r|j j t |d S)aInstall missing package dependencies based on apt_sources config. Inspect the cloud config user-data provided. When user-data indicates conditions where add_apt_key or add-apt-repository will be called, ensure the required command dependencies are present installed. Perform this inspection upfront because it is very expensive to call distro.install_packages due to a preliminary 'apt update' called before package installation. r=Frrrtkeyidr r>sourcerwzadd-apt-repositoryN)rr)r|r rSr-rrvaluesshutilr9rmPACKAGE_DEPENDENCY_BY_COMMANDrZinstall_packagesry) r'rBr(Zmissing_packagesZ required_cmdsZ mirror_keyZ mirror_itemZapt_sources_dictentcommandr$r$r%rRs&       rRcCs^d|kr8d|kr8t}d|kr$|d}tj|d||d<d|krZt|d|pR|d|dSdS)z Add key to the system as defined in ent (if any). Supports raw keys or keyid's The latter will as a first step fetched to get the raw key rrt keyserverr)rN)DEFAULT_KEYSERVERr Z getkeybyidr)rr(r#rrrr$r$r%rsrcCs|jjdS)N)rZupdate_package_sources)r(r$r$r%update_packagessrc Cs|dkr i}|dkrtdt|ts2td|x|D]}||}tjd|d|kr|r|j|r|t|d|d<n||d<d|krd|dkrt|||dd }||d <n t|||d|krq:|d}t j ||}|djd st j j d |d|d<|djd s&|dd 7<||rpytjdd|g|dWq:tjk rltjdYq:Xq:tj||d} y:d|} d} d|kr|d rd} tj| | | dWq:tk r} ztjd| | WYdd} ~ Xq:Xq:Wt|dS)a install keys and repo source .list files defined in 'sources' for each 'source' entry in the config: 1. expand template variables and write source .list file in /etc/apt/sources.list.d/ 2. install defined keys 3. update packages via distro-specific method (i.e. apt-key update) @param srcdict: a dict containing elements required @param cloud: cloud instance object Example srcdict value: { 'rio-grande-repo': { 'source': 'deb [signed-by=$KEY_FILE] $MIRROR $RELEASE main', 'keyid': 'B59D 5F15 97A5 04B7 E230 6DCA 0620 BBCF 0368 3F77', 'keyserver': 'pgp.mit.edu' } } Note: Deb822 format is not supported Nz did not get a valid repo matcherzunknown apt format: %szadding source/key '%s'rrz $KEY_FILET)rZKEY_FILErz/etc/apt/sources.list.d/z.listzadd-apt-repositoryz --no-update)r#zadd-apt-repository failed.z%s armw)omodezfailed write to file %s: %s)r!r.r/ TypeErrorrKrLrrnrr rr_rrxrir rr\rr rrZr) srcdictr(r#rArBrrkey_filerZsourcefncontentsrZdetailr$r$r%r]s^         r]cCsi}tjddddt|trftjdxT|D]2}d|krPd|d<tj|d}n|d}|||<q.Wnt|trv|}ntd|S) z1convert v1 apt format to v2 (dict in apt_sources)zConfig key 'apt_sources'z22.1zUse 'apt' instead) deprecateddeprecated_versionZ extra_messagez9apt config: convert V1 to V2 format (source list to dict)rzcloud_config_sources.listzunknown apt_sources format) r deprecater.rprKrLZ rand_dict_keyr/r!)ZsrclistrZsrcentrtr$r$r%convert_v1_to_v2_apt_formatXs"    rcCs,|j|ddk r(|j|||<||=dSdS)ziconvert an old key to the new one if the old one exists returns true if a key was found and convertedNTF)r-)oldcfgaptcfgoldkeynewkeyr$r$r% convert_keyts rcCsNd ddg}d}dd gi}x"|D]\}}t||||rd }qW|rJ|g|d <d S)zBconvert old apt_mirror keys into the new more advanced mirror spec apt_mirroruriapt_mirror_searchrQapt_mirror_search_dns search_dnsFarchesdefaultTrN)rr)rrQ)rr)r)rrZkeymapZ convertedZnewmcfgrrr$r$r%convert_mirror~s rc Csnddddddddddd d }g}x2|D]*}||kr&||dkrF||=q&|j|q&W|s\|Stjd |d d|jdd}|dk rtjdd dx^|D]V}||}||}||=|dks|j|ddkrq|||krtd||||fqW|Si}x.|D]&}||dk rt|||||qWt||x,|D]$}|j|ddk r:td|q:W||d<|S)z:convert old to new keys and adapt restructured mirror specr>Nproxy http_proxy https_proxy ftp_proxyr=rr<) apt_sourcesrrrZ apt_proxyZapt_http_proxyZ apt_ftp_proxyZapt_https_proxyZapt_preserve_sources_listZapt_custom_sources_listr<rwzThe following config key(s): z22.1)rrr+z0Support for combined old and new apt module keysz@Old and New apt format defined with unequal values %s vs %s @ %sz&old apt key '%s' left after conversion)Nrw)rmr rr-r!rr)rZ mapoldkeysZ needtoconvertrZ newaptcfgrZverifyrr$r$r%convert_v2_to_v3_apt_formats`        rcCs,|jdd}|dk r t||d<t|}|S)zconvert the old list based format to the new dict based one. After that convert the old dict keys/format to v3 a.k.a 'new apt config'rN)r-rr)r'rr$r$r%r,s   r,c Csd}|rd}g}|dkrd}n|dkr,d}ntdtj||j}dj|jdd d}|rl|jd ||jdg} |jj } d | |d | f} x|D]} | j| | qWtj | }|S)zG Try to resolve a list of predefines DNS names to pick mirrors Nrwrrrzsecurity-mirrorzunknown mirror type.rCz.%s .localdomainzhttp://%s-%s%s/%sz%s)rrw) r!r Zget_hostname_fqdnfqdnrxrrmextendrrsearch_for_mirror) Z configured mirrortyper'r(rZmydomZdomsZ mirrordnsrZ mirror_listrZ mirrorfmtZpostr$r$r%search_for_mirror_dnss.  rcCsX|dk r|dkr|}||dS|jj}|rP|j}|d|d<|d|d<|St|S)z^sets security mirror to primary if not defined. returns defaults if no mirrors are definedN)rrrrrr)Z datasourceZget_package_mirror_inforr&)pmirrorsmirrorr"r( mirror_infomr$r$r%update_mirror_infos    rcCsT|j|d}|dkrdSd}x2|D]*}|jdp2g}||kr@|Sd|kr"|}q"W|S)zuout of a list of potential mirror configurations select and return the one matching the architecture (or default)Nrr)r-)r'rr"Zmirror_cfg_listrZmirror_cfg_elemrr$r$r%get_arch_mirrorconfig*s  rcCs`t|||}|dkrdS|jdd}|dkr>tj|jdd}|dkr\t|jdd|||}|S)zpass the three potential stages of mirror specification returns None is neither of them found anything otherwise the first hit is returnedNrrQr)rr-r rr)r'rr"r(Zmcfgrr$r$r% get_mirror=s  rcCsn|dkrtj}tjd|t|d||}tjd|t|d||}tjd|t||||}|d|d<|S) afind_apt_mirror_info find an apt_mirror given the cfg provided. It can check for separate config of primary and security mirrors If only primary is given security is assumed to be equal to primary If the generic apt_mirror is given that is defining for both Nz!got arch for mirror selection: %srzgot primary mirror: %srzgot security mirror: %srr@)r rrKrLrr)r'r(r"rrrr$r$r%rMWs    rMcsd}fdd |D}t|rBtjd |tj|d j|d n"tjj|rdtj |tjd |j d drtjd|tj|j d n"tjj|rtj |tjd|dS)zHapply_apt_config Applies any apt*proxy config from if specified rAcquire::http::Proxy "%s";rrAcquire::ftp::Proxy "%s";rAcquire::https::Proxy "%s";cs(g|] \}}j|r|j|qSr$)r-)rHrZfmt)r'r$r%rJ{sz$apply_apt_config..zwrite apt proxy info to %srsz#no apt proxy configured, removed %sZconfNzwrite apt config info to %sz$no apt config configured, removed %srrrrrrrr)rrrr) rnrKrLr rrxr_risfileZdel_filer-)r'Z proxy_fnameZ config_fnameZcfgsZproxiesr$)r'r%rWos"        rWTcsVddfdd}fdd}|dkr4|S|dksD|d krJ|Std d S) adapt-key replacement commands implemented: 'add', 'list', 'finger' @param output_file: name of output gpg file (without .gpg or .asc) @param data: key contents @param human_output: list keys formatted for human parsing @param hardened: write keys to to /etc/apt/cloud-init.gpg.d/ (referred to with [signed-by] in sources file) cSsNtjjtrtgng}x*tjtD]}|jdr"|jt|q"W|rJ|SdS)zreturn all apt keys /etc/apt/trusted.gpg (if it exists) and all keyfiles (and symlinks to keyfiles) in /etc/apt/trusted.gpg.d/ are returned based on apt-key implementation .gpg.ascrw)rr )r_rrAPT_LOCAL_KEYSlistdirAPT_TRUSTED_GPG_DIRrirm)Z key_filesfiler$r$r%_get_key_filess  zapt_key.._get_key_filesc sd}stjtdjny2r&tnt}tj}dj|}tj||WnLt j k rvtjtdjYn&t k rtjtdjYnX|S)ziapt-key add returns filepath to new keyring, or '/dev/null' when an error occurs z /dev/nullz)Unknown filename, failed to add key: "{}"z{}{}.gpgz Gpg error, failed to add key: {}z#Decode error, failed to add key: {}) r ZlogexcrKr0CLOUD_INIT_GPG_DIRr r Zdearmorrr rUnicodeDecodeError)rZkey_dirstdout)rhrrr$r% apt_key_adds    zapt_key..apt_key_addcsjg}xZD]P}y|jtj|dWq tjk rZ}ztjd||WYdd}~Xq Xq Wdj|S)zapt-key list returns string of all trusted keys (in /etc/apt/trusted.gpg and /etc/apt/trusted.gpg.d/) ) human_outputzFailed to list key "%s": %sNrs)rmr rpr rrKrorx)Zkey_listrerror)rrr$r% apt_key_lists $zapt_key..apt_key_listrZfingerrpz@apt_key() commands add, list, and finger are currently supportedN)r!)rrrhrrrrr$)rrhrrrr%rsrz cloud-init)NN)N)N)N)FN)NFN)NNN)N)NNFT)\__doc__rZloggingr_rrOrratextwraprrZtypingrrrrZ cloudinitrr r r r Zcloudinit.cloudr Zcloudinit.configrZcloudinit.config.schemarrZcloudinit.settingsrZ getLogger__name__rKrNr r rrrrrstrmetarrYrXrrr rrr&rpr5r:r3rkrrr2rrrVrrrrrTboolrrrrrUrrRrrr]rrrrr,rrrrrMrWrrlr$r$r$r% s    A    < ! # /(44 "  \ J)  Q