3 ܓi>@sddlZddlZddlmZddlmZddlmZddl m Z ddl m Z ddl mZddlmZdd lmZdd lmZmZmZmZd Zd Zd ZGdddeZGdddeZdS)N)_sos)Policy) InitSystem) SystemdInit)CrioContainerRuntime)PodmanContainerRuntime)DockerContainerRuntime)LxdContainerRuntime) shell_out is_executableboldsos_get_command_outputz/etc/os-releaseZ containerZHOSTcs.eZdZdZdZdZdZdZdZdZ dZ dZ dZ dZ dZdZdZdZd ZdZdZd9fd d Zed dZed:ddZddZddZddZddZddZddZeddZedd Z ed!d"Z!d#d$Z"d%d&Z#d'd(Z$d)d*Z%d+d,Z&d-d.Z'd/d0Z(d1d2Z)d;d3d4Z*d5d6Z+d7d8Z,Z-S)< LinuxPolicyzfThis policy is meant to be an abc class that provides common implementations used in Linux distrosNonez/bin:/sbin:/usr/bin:/usr/sbinNdockerFz/usr/binzsos-collector-tmpTcs"tj|||d|r||_n|jp(d|_|j|dk rD||_n$tjjdr`t |jd|_nt |_i|_ |j rt |dt|dt|dt|dg}xN|D]F}|jr||j |j<|j|jkr|j |j|j d<|j |jjqW|j od|j krt|j j}|j |d|j d<dS)N)sysroot probe_runtime remote_exec/z/run/systemd/system/)chroot)Zpolicydefaultr)super__init__r_container_initinit_kernel_modulesZ init_systemospathisdirrrZruntimesrrrrr Zcheck_is_activenamedefault_container_runtimeZload_container_infolistkeys)selfrinitrrZ_crunZruntimeidx) __class__/usr/lib/python3.6/__init__.pyr;s6     zLinuxPolicy.__init__cCsddgS)Nz /etc/passwdz /etc/shadowr')clsr'r'r(set_forbidden_pathsdszLinuxPolicy.set_forbidden_pathsc stfdd}|r||StjjjrNtjjjtjjtjjjkrNdSttddd}||jSQRXdS)z| This function is responsible for determining if the underlying system is supported by this policy. csbjg}jr|jjxB|jD]6}|jd r$|jddddjd}||kr$dSq$WdS) NNAME=ID==rz"'TF)r+r,)os_release_name os_release_idappend splitlines startswithsplitstrip)ZcontentZ_matcheslineZ_distro)r)r'r(_check_releaseqs  z)LinuxPolicy.check.._check_releaseTrzutf-8)encodingN) rrisfileos_release_filebasenamerealpathopen OS_RELEASEread)r)remoter7fr')r)r(checkks  zLinuxPolicy.checkcCs|jS)N)release)r#r'r'r(kernel_versionszLinuxPolicy.kernel_versioncCs|jS)N)Zhostname)r#r'r'r( host_nameszLinuxPolicy.host_namecCs|jS)N)Zsmp)r#r'r'r( is_kernel_smpszLinuxPolicy.is_kernel_smpcCs|jS)N)machine)r#r'r'r(get_archszLinuxPolicy.get_archcCs|jS)z)Returns the name usd in the pre_work step)rF)r#r'r'r(get_local_nameszLinuxPolicy.get_local_namecCstjdd|S)Nz[^-a-z,A-Z.0-9]r)resub)r#rr'r'r(sanitize_filenameszLinuxPolicy.sanitize_filenamecCs4|tkr|j|n|j|jd|j|dS)Nz Distribution Policy)rdisplay_self_help set_titler/display_distro_help)r)sectionr'r'r( display_helps zLinuxPolicy.display_helpcCs|jd|jddS)NzSoS Distribution PolicieszDistributions supported by SoS will each have a specific policy defined for them, to ensure proper operation of SoS on those systems.)rOadd_text)r)rQr'r'r(rNs zLinuxPolicy.display_self_helpc Cs>|jr |jtjk r |j|jn |jd|ddd}|jd|j|jd|jdd|jd|jdd|jd}x6|jD],}|jdd |d d |d d ddqW|jd}|jtdd dddddd ddxN|j j D]@\}}dj |j j }|jdd |d|jd|d ddqWdS)Nz; Detailed help information for this policy is not availableFzDefault --upload location: zDefault container runtime: )newlinez $PATH used when running report: zReference URLs z>8rz<30r.z<40z#Presets Available With This Policy z Preset Namez<20Z Descriptionz<45zEnabled Options)__doc__rrS _upload_urlr PATHZ add_section vendor_urlsr ZpresetsitemsjoinZoptsZto_argsZdesc) r)rQZ_polZrefsecZurlZpresecZpresetvalueZ_optsr'r'r(rPs4     , zLinuxPolicy.display_distro_helpcCs^ttjkrZtjtdkrZd|_ttjkrZtjts6dStjjtjt|j|_tjtSdS)zCheck if sos is running in a container and perform container specific initialisation based on ENV_HOST_SYSROOT. rocipodmanTN)rr]r^) ENV_CONTAINERrenvironZ _in_containerENV_HOST_SYSROOTrabspathZ_tmp_dir)r#r'r'r(rs    zLinuxPolicy._container_initcCsg|_tjj}tdd|jdj}|jjdd|ddD|jd|d }yPt |d d d 8}x0|D](}|j d dj dd}|jj |qlWWdQRXWn4t k r}z|j jd|WYdd}~XnXddd}d|d|df} x<| D]$} |j| } tjj| r| } PqW|j jddSg} yLt | d d d 4} x,| D]$}d|krT| j |j ddqTWWdQRXWn6t k r}z|j jd|WYdd}~XnXx,|jD] \} }|| kr|jj | qWdS)zxObtain a list of loaded kernel modules to reference later for plugin enablement and SoSPredicate checks Zlsmodr)timeoutrcSsg|]}|jdjqS)r)r4r5).0r6r'r'r( sz3LinuxPolicy.init_kernel_modules..r.Nz/usr/lib/modules/z/modules.builtinr8zutf-8)r9rz.koz Unable to read kernel builtins: ZCONFIG_NET_DEVLINKZCONFIG_BLK_DEV_DM)ZdevlinkZdm_modz /boot/config-z /lib/modules/z/configz#Unable to find booted kernel configz=yz%Unable to read booted kernel config: )Z kernel_modsrunamerDr rr2extend join_sysrootr>r4r1IOErrorsoslogwarningrexistsrZ)r#rDlinesbuiltinsZmfiler6ZkmoderrZconfig_stringsZkconfigsZkconfigZ booted_configZkfileZbuiltinr\r'r'r(rsH  $     ($ zLinuxPolicy.init_kernel_modulescCs*|jr&|jdkr&tjj|j|jd}|S)Nr)rrrr[lstrip)r#rr'r'r(ri#szLinuxPolicy.join_sysrootcCs(|jd}|jr|j|j||_dS)NZ cmdlineopts)ZcommonsZ low_priority_configure_low_priorityprompt_for_case_idcase_id)r# cmdline_optsr'r'r(pre_work(s zLinuxPolicy.pre_workcCs<|j r$|j r$|js$ttd|_|jr0|jnd|_|jS)NzNOptionally, please enter the case id that you are generating this report for: r)Zbatchquietrtinput_)r#rur'r'r(rs3s zLinuxPolicy.prompt_for_case_idcCstj}tdrdtd|dd}|ddkr<|jjdqpd|d d |dd }|jj|n |jjd ytj d |jjdWn4t k r}z|jjd|WYdd}~XnXdS)ayUsed to constrain sos to a 'low priority' execution, potentially letting individual policies set their own definition of what that is. By default, this will attempt to assign sos to an idle io class via ionice if available. We will also renice our own pid to 19 in order to not cause competition with other host processes for CPU time. Zionicezionice -c3 -p )rcZstatusrzSet IO class to idlez Error setting IO class to idle: outputz (exit code )zNWarning: unable to constrain report to idle IO class: ionice is not available.zSet niceness of report to 19z%Error setting report niceness to 19: N) rgetpidr r rkinfoerrorZui_logrlnice Exception)r#Z_pidretmsgrpr'r'r(rr@s  z#LinuxPolicy._configure_low_prioritycCsdS)zIf sos report commands need to always be prefixed with something, for example running in a specific container image, then it should be defined here. If no prefix should be set, return an empty string instead of None. rr')r#r'r'r(set_sos_prefix_szLinuxPolicy.set_sos_prefixcCsdS)zcIf a host requires additional cleanup, the command should be set and returned here rr')r#r'r'r(set_cleanup_cmdhszLinuxPolicy.set_cleanup_cmdcCsdS)aIReturns the command that will create the container that will be used for running commands inside a container on hosts that require it. This will use the container runtime defined for the host type to launch a container. From there, we use the defined runtime to exec into the container's namespace. :param image: The name of the image if not using the policy default :type image: ``str`` or ``None`` :param auth: The auth string required by the runtime to pull an image from the registry :type auth: ``str`` or ``None`` :param force_pull: Should the runtime forcibly pull the image :type force_pull: ``bool`` :returns: The command to execute to launch the temp container :rtype: ``str`` rr')r#ZimageZauthZ force_pullr'r'r(create_sos_containerosz LinuxPolicy.create_sos_containercCs|jd|jS)aRestarts the container created for sos collect if it has stopped. This is called immediately after create_sos_container() as the command to create the container will exit and the container will stop. For current container runtimes, subsequently starting the container will default to opening a bash shell in the container to keep it running, thus allowing us to exec into it again. z start )container_runtimesos_container_name)r#r'r'r(restart_sos_containers z!LinuxPolicy.restart_sos_containercCs"|jr|jd|jd|S|S)aReturns the command that allows us to exec into the created container for sos collect. :param cmd: The command to run in the sos container :type cmd: ``str`` :returns: The command to execute to run `cmd` in the container :rtype: ``str`` z exec rU)rr)r#cmdr'r'r(format_container_commands z$LinuxPolicy.format_container_command)NNTN)r)NNF).__name__ __module__ __qualname__rVvendorrXr$r;r/r0rWr Z_preferred_hash_nameZ containerizedZcontainer_imageZsos_path_stripZ sos_pkg_nameZ sos_bin_pathrZcontainer_version_commandZcontainer_authfiler classmethodr*rCrErFrGrIrJrMrRrNrPrrrirvrsrrrrrrr __classcell__r'r')r&r(r#sV(    +;     rc@s,eZdZdZd gZdZdZed ddZd S) GenericLinuxPolicyzThis Policy will be returned if no other policy can be loaded. This should allow for IndependentPlugins to be executed on any systemUpstream Project https://github.com/sosreport/sosZSoSaSoS was unable to determine that the distribution of this system is supported, and has loaded a generic configuration. This may not provide desired behavior, and users are encouraged to request a new distribution-specifc policy at the GitHub project above. rcCstdS)z| This function is responsible for determining if the underlying system is supported by this policy. N)NotImplementedError)r)rAr'r'r(rCszGenericLinuxPolicy.checkN)rr)r) rrrrVrYrZ vendor_textrrCr'r'r'r(rs r)rrKZsosrryZ sos.policiesrZsos.policies.init_systemsrZ!sos.policies.init_systems.systemdrZsos.policies.runtimes.criorZsos.policies.runtimes.podmanrZsos.policies.runtimes.dockerrZsos.policies.runtimes.lxdr Z sos.utilitiesr r r r r?r_rarrr'r'r'r( s$