VULN_CHECK_I913V6 (f0PddlmZddlmZddlmZddlmZddlZddlZddlZddl Z ddl m Z ddl Z ddlZ ejdZdZGd d e j$j&Zdd ZGd d eZGddZGddZGddZdZdZGddZy))print_function)absolute_import)unicode_literals)EnumN_dnf=ceZdZdZdZy) DnssecErrorz- Exception used in the dnssec module c\dj|j|jSdS)Nzz Not specified)formatvalueselfs //usr/lib/python3.12/site-packages/dnf/dnssec.py__repr__zDnssecError.__repr__-s.* V$**"8DJJ N O>M N ON)__name__ __module__ __qualname____doc__rrrr r )s Orr cz|jdd}t|dk7r d}t||d}|d}tj}|j |j dtj|jddjdj}|dz|zdz|zS) z Implements RFC 7929, section 3 https://tools.ietf.org/html/rfc7929#section-3 :param email_address: :param tag: :return: @z0Email address must contain exactly one '@' sign.rzutf-8.) rsplitlenr hashlibsha256updateencodebase64 b16encodedigestdecodelower) email_addresstagsplitmsglocaldomainhashr(s remail2locationr22s  a (E 5zQ@# !HE 1XF >> DKK W%&   dkkmAb1 2    C<#  #f ,,rc(eZdZdZdZdZdZdZdZdZ y) Validityz Output of the verification algorithm. TODO: this type might be simplified in order to less reflect the underlying DNS layer. TODO: more specifically the variants from 3 to 5 should have more understandable names rr N) rrrrVALIDREVOKEDPROVEN_NONEXISTENCERESULT_NOT_SECURE BOGUS_RESULTERRORrrrr4r4Js) EGL Err4ceZdZdZy)NoKeyz This class represents an absence of a key in the cache. It is an expression of non-existence using the Python's type system. N)rrrrrrrr@r@Xs  rr@c.eZdZdZddZdZedZy)KeyInfozv Wrapper class for email and associated verification key, where both are represented in form of a string. Nc ||_||_y)N)emailkey)rrDrEs r__init__zKeyInfo.__init__es rcrdj|j|jjdddS)NzKeyInfo("{}", "{}...")ascii)rrDrEr)rs rrzKeyInfo.__repr__is/'..tzz488??7;STVUV;WXXrcptjd|}|t|jd}|j dj d}d}d}t dt|D]}||dk(r|}||dk(s|}dj||d z|dz jd}t||S) z Since dnf uses different format of the key than the one used in DNS RR, I need to convert the former one into the new one. <(.*@.*)>rrH rz$-----BEGIN PGP PUBLIC KEY BLOCK-----z"-----END PGP PUBLIC KEY BLOCK-----r) researchr groupr)r-ranger!joinr%rB) useridraw_key input_emailrDrEstartstopicat_keys rfrom_rpm_key_objectzKeyInfo.from_rpm_key_objectlsii V4   !!!$nnW%++D1q#c(#A1v??1v== $ ''#eaiq1299'Bug&&r)NN)rrrrrFr staticmethodrZrrrrBrB`s&Y''rrBcDeZdZdZiZedZedZedZy)DNSSECKeyVerificationz The main class when it comes to verification itself. It wraps Unbound context and a cache with already obtained results. cp||k(r%tjdtjSt |t r%tjdtj Stjdj|tjdj|tjS)zD Compare the key in case it was found in the cache. zCache hit, valid keyzCache hit, proven non-existencezKey in cache: {}Input key : {}) loggerdebugr4r9 isinstancer@r;rr:) key_unioninput_key_strings r _cache_hitz DNSSECKeyVerification._cache_hits ( ( LL/ 0>> !  5 ) LL: ;// / LL+229= > LL+223CD E## #rc ddl}|j}|jdddk7rtjd|jdddk7rtjd |jdk7rtjd |jd dk7rtjd |j%tjd tjS|j!t#|jt$|j&\}}|dk7r%tjdtjS|j(r>tjdj|j*tj,S|j.s%tjdtj0S|j2s%|j4|j6k(r1|j8s%tjdtj:S|j8s>tjdj|j<tjS|j>jAd}tCjD|}||jFk(rtjHStjdj|tjdj|jFtjJS#t$r>}tdj|}tj j |d}~wwxYw)zz In case the key was not found in the cache, create an Unbound context and contact the DNS system rNzLConfiguration option 'gpgkey_dns_verification' requires python3-unbound ({})z verbosity:0z(Unbound context: Failed to set verbosityzqname-minimisation:yesz1Unbound context: Failed to set qname minimisationz+Unbound context: Failed to read resolv.confz/var/lib/unbound/root.keyz0Unbound context: Failed to add trust anchor filez&A key has no associated e-mail addressz%Communication with DNS servers failedz DNSSEC signatures are wrong ({})z!Result is not secured with DNSSECz1Non-existence of this record was proven by DNSSECz&Unknown error in DNS communication: {}zKey from DNS: {}r_)&unbound ImportErrorrrr exceptionsErrorub_ctx set_optionr`ra resolvconf add_ta_filerDr4r>resolver2RR_TYPE_OPENPGPKEY RR_CLASS_INbogus why_bogusr=securer<nxdomainrcode RCODE_NOERRORhavedatar; rcode_strdata as_raw_datar& b64encoderEr9r:) input_keyrier.ctxstatusresultr| dns_data_b64s r _cache_missz!DNSSECKeyVerification._cache_missst ,  nn >>, , 1 LLC D >>/ 71 < LLL M >> q LLF G ??6 71 < LLK L ?? " LLA B>> !^IOO%D%79L9LN Q; LL@ A>> ! << LL;BB6CSCST U(( (}} LL< =-- - ??v||w/D/DDV__ LLL M// / LLAHHIYIYZ [>> !;;**,Q/D!++D1Ly}},~~% /66|DE /66y}}EF'''g ,++16!96C..&&s+ + ,sL M"$9MM"c tjdj|jtj j |j}| tj||jStj|}|tjk(r)|jtj |j<|S|tjk(r%ttj |j<|S)zI Public API. Use this method to verify a KeyInfo object. z(Running verification for key with id: {})r`rarrDr]_cachegetrerErr4r9r;r@)rrcrs rverifyzDNSSECKeyVerification.verifys  ?FFyWX)0044Y__E  (33Iy}}M M*66yAF'@I %,,Y__=M8777@E%,,Y__=MrN) rrrrrr[rerrrrrr]r]sK F$$ ;(;(zrr]ctd|jzdz}|tjk(r|tdzS|tdzS)zE Inform the user about key validity in a human readable way. zDNSSEC extension: Key for user  z is valid.zhas unknown status.)rrDr4r9)kivprefixs r nice_user_msgrsI 0 1BHH } |r)t jd | t j s+d}.|j#| @dj%|} |t'|| j)dgz }P|S)Nnamez gpg-pubkeypackagerrKrzWExempting key package {} from a validation because it's not bound to any e-mail addressnevra descriptionTrLrz\A\s*\ZFrMrH)r rpm transactionTransactionWrapperdbMatch getheaderrNrOrPr`rarrrr-matchNOFLAGappendrRrBr%) transaction_setpackages return_listpkgrrDr key_lines in_headerslinekey_strs r_query_db_for_gpg_keysz&RpmImportedKeys._query_db_for_gpg_keyss`''--@@B"**6<@ Cww((j9H +x8>>qA} WQC&DDJF))#w7E9:;''++C?KIJ#))$/"5xx D"))<%* $$T* 6 ggi(G GE7>>'+BCD DK14rc tj}tjt t d|D]}} t j|}|tjk(r8tjt dj|je|tj k(r8tjt dj|j|tj"k(r8tjt dj|j|tj$k(r9tjt dj|jGtjt dj|jy#t$rD}tjdj|j|jYd}~d}~wwxYw)Nz1Testing already imported keys for their validity.z%DNSSEC extension error (email={}): {}zGPG Key {} is validz,GPG Key {} does not support DNS verificationzGPG Key {} could not be verified, because DNSSEC signatures are bogus. Possible causes: wrong configuration of the DNS server, MITM attackz=GPG Key {} has been revoked and should be removed immediatelyzGPG Key {} could not be tested)rrr`inforrr]rr warningrrDrr4r9rar;r=r:)keysrErrs rcheck_imported_keys_validityz,RpmImportedKeys.check_imported_keys_validity2sw557 GAQRSTC .55c:' W%:%A%A#))%LMN8777 W&44:F3994EGH8000 G%;;A6#));LNO8+++ G%>>DfSYY>OQR W%E%L%LSYY%WXY/ F$fSYY8:  sG H  9HH N)rrrrr[rrrrrrrs2  DZZrr) _openpgpkey) __future__rrrenumrr&r"loggingrNdnf.i18nrdnf.rpmr dnf.exceptions getLoggerr`rrrkrlr r2r4r@rBr]rrrrrrrs*&&'     5 !O#..&&O-0 t   #'#'LiiX 1'GZGZr