%PDF- %PDF-
Mini Shell

Mini Shell

Direktori : /lib/python3/dist-packages/sos/cleaner/__pycache__/
Upload File :
Create Path :
Current File : //lib/python3/dist-packages/sos/cleaner/__pycache__/__init__.cpython-312.pyc

�

i��d����*�ddlZddlZddlZddlZddlZddlZddlZddlm	Z	ddl
m
Z
ddlmZddlm
Z
ddlmZddlmZddlmZdd	lmZdd
lmZddlmZddlmZdd
lmZmZmZm Z ddl!m"Z"m#Z#ddl$m%Z%ddl&m'Z'm(Z(m)Z)ddl*m+Z+Gd�de�Z,y)�N)�ThreadPoolExecutor)�datetime)�getpwuid)�__version__)�SoSComponent)�SoSIPParser)�SoSMacParser)�SoSHostnameParser)�SoSKeywordParser)�SoSUsernameParser)�
SoSIPv6Parser)�SoSReportArchive�SoSReportDirectory�SoSCollectorArchive�SoSCollectorDirectory)�DataDirArchive�TarballArchive)�InsightsArchive)�get_human_readable�
import_module�ImporterHelper)�fillc�0��eZdZdZdZdggdgdddddgd	�Z		d,�fd
�	Zd-d�Zd-d�Zd-d
�Z	d-d�Z
d�Zed��Z
d�Zd�Zed��Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd.d�Zd�Zd�Zd �Zd!�Zd"�Zd#�Z d$�Z!d%�Z"d/d&�Z#d'�Z$d(�Z%d)�Z&d-d*�Z'd+�Z(�xZ)S)0�
SoSCleanera
    This function is designed to obfuscate potentially sensitive information
    from an sos report archive in a consistent and reproducible manner.

    It may either be invoked during the creation of a report by using the
    --clean option in the report command, or may be used on an already existing
    archive by way of 'sos clean'.

    The target of obfuscation are items such as IP addresses, MAC addresses,
    hostnames, usernames, and also keywords provided by users via the
    --keywords and/or --keyword-file options.

    For every collection made in a report the collection is parsed for such
    items, and when items are found SoS will generate an obfuscated replacement
    for it, and in all places that item is found replace the text with the
    obfuscated replacement mapped to it. These mappings are saved locally so
    that future iterations will maintain the same consistent obfuscation
    pairing.

    In the case of IP addresses, support is for IPv4 and IPv6 - effort is made
    to keep network topology intact so that later analysis is as accurate and
    easily understandable as possible. If an IP address is encountered that we
    cannot determine the netmask for, a random IP address is used instead.

    For IPv6, note that IPv4-mapped addresses, e.g. ::ffff:10.11.12.13, are
    NOT supported currently, and will remain unobfuscated.

    For hostnames, domains are obfuscated as whole units, leaving the TLD in
    place.

    For instance, 'example.com' may be obfuscated to 'obfuscateddomain0.com'
    and 'foo.example.com' may end up being 'obfuscateddomain1.com'.

    Users will be notified of a 'mapping' file that records all items and the
    obfuscated counterpart mapped to them for ease of reference later on. This
    file should be kept private.
    z6Obfuscate sensitive networking information in a report�auto�N� /etc/sos/cleaner/default_mappingF�)�archive_type�domains�disable_parsers�jobs�keywords�keyword_file�map_file�	no_update�keep_binary_files�target�	usernamesc�f��|stt|�|||�d|_n�|d|_|d|_|d|_|d|_|d|_d|_t|jd�sd	|j_
d
|j_tjd�|_tjd�|_t!j"t j$j'|j
d
�d��|j)�|j+�|_t!j.d�||_|jj3�|_|jj6j9d
�|_t=|j,�t?|j,�tA|j,�tC|j,�tE|j,�tG|j,�g|_$|jjJD]�}|jHD]�}|jLjO�jQd�djS�}|jO�jS�|k(s�_|jUd|z�|jjWd|z�|jHjY|�����tZt\t^t`tbtdtfg|_4d|_5|jUd|jz�y)NT�options�tmpdir�sys_tmp�policy�manifestFr"rr�sos�sos_ui�cleaner��exist_ok�?�parserrzDisabling parser: %szaDisabling the '%s' parser. Be aware that this may leave sensitive plain-text data in the archive.z%Cleaner initialized. From cmdline: %s)6�superr�__init__�from_cmdline�optsr,r-r.r/�hasattrr"r�logging�	getLogger�soslog�ui_log�os�makedirs�path�join�validate_parser_values�
load_map_file�cleaner_mapping�umask�in_place�get_preferred_hash_name�	hash_name�
components�add_section�
cleaner_mdr
rr
r	rr�parsersr!�name�lower�split�strip�log_info�warning�removerrrrrrr�
archive_types�nested_archive)
�selfr6�args�cmdlinerH�hook_commons�_parser�_loaded�_loaded_name�	__class__s
         ��6/usr/lib/python3/dist-packages/sos/cleaner/__init__.pyr8zSoSCleaner.__init__^s������*�d�,�V�T�7�C� $�D��
%�Y�/�D�I�&�x�0�D�K�'�	�2�D�L�&�x�0�D�K�(��4�D�M� %�D���4�9�9�f�-�!"��	�	��%+�D�I�I�"�!�+�+�E�2�D�K�!�+�+�H�5�D�K�
�K�K������T�[�[�)�<�t�L��#�#�%�#�1�1�3���
����� ��
����<�<�>����-�-�2�2�>�>�y�I���
�d�2�2�3���,�,�-��$�.�.�/���-�-�.��T�1�1�2��d�2�2�3�

����y�y�0�0�
	1�G��<�<�	
1��&�|�|�1�1�3�9�9�(�C�A�F�L�L�N���=�=�?�(�(�*�l�:��M�M�"8�<�"G�H��K�K�'�'�J�!�"��
�L�L�'�'��0�	
1�
	1�
��!�����	
���#����
�
�=��)�)�*�	+�c� �d|rd|znd�d|��S)Nz[cleanerz:%srz] ��rX�msg�callers   r`�_fmt_log_msgzSoSCleaner._fmt_log_msg�s��5;�5�6�>��#C�S�I�Irac�Z�|jj|j||��y�N)r>�debugrgrds   r`�	log_debugzSoSCleaner.log_debug��!�������$�+�+�C��8�9rac�Z�|jj|j||��yri)r>�inforgrds   r`rSzSoSCleaner.log_info�s!��������*�*�3��7�8rac�Z�|jj|j||��yri)r>�errorrgrds   r`�	log_errorzSoSCleaner.log_error�rlrac�`�d}d}|j�D]}|t||d��zdz}�|S)N�PrF)�replace_whitespace�
)�
splitlinesr)rXre�width�_fmt�lines     r`�_fmt_msgzSoSCleaner._fmt_msg�sA�������N�N�$�	M�D��$�t�U�u�E�E��L�D�	M��rac�\�|jd�|j|j�y)NzSoS Cleaner Detailed Help)�	set_title�add_text�__doc__)�cls�sections  r`�display_helpzSoSCleaner.display_help�s#�����5�6�������%rac��i}d}tjj|jj�r"td|jjz��tjj
|jj�sC|jj|k7r(|jd|jjz�|St|jjd�5}	tj|�}ddd�|S#tj$r|jd�Y�0t
$r5}|jd|jj�d|���Yd}~�hd}~wwxYw#1swY|SxYw)	z�Verifies that the map file exists and has usable content.

        If the provided map file does not exist, or it is empty, we will print
        a warning and continue on with cleaning building a fresh map
        rz$Requested map file %s is a directoryzHERROR: map file %s does not exist, will not load any obfuscation matches�rzOERROR: Unable to parse map file, json is malformed. Will not load any mappings.zERROR: Could not load '�': N)r@rB�isdirr:r%�	Exception�existsrq�open�json�load�JSONDecodeError)rX�_conf�default_map�mf�errs     r`rEzSoSCleaner.load_map_file�sJ����8��
�7�7�=�=����+�+�,��B�"�i�i�0�0�1�2�
2��w�w�~�~�d�i�i�0�0�1��y�y�!�!�[�0����*�,0�I�I�,>�,>�?�@����d�i�i�(�(�#�.�
@�"�@� �I�I�b�M�E�
@����
�+�+�M��N�N�$L�M� �@��N�N�&*�i�i�&8�&8�#�$?�@�@��@��

@���s<�0E7�2D�$E4�5E7�7E4�?+E/�*E7�/E4�4E7�7Fc��|jd�}|jjdtz�|jj|�|jj
s
	t
d�yy#t$r/|jjd�|jd�Yyt$r}|jd|�Yd}~yd}~wwxYw)z�When we are directly running `sos clean`, rather than hooking into
        SoSCleaner via report or collect, print a disclaimer banner
        a�This command will attempt to obfuscate information that is generally considered to be potentially sensitive. Such information includes IP addresses, MAC addresses, domain names, and any user-provided keywords.

Note that this utility provides a best-effort approach to data obfuscation, but it does not guarantee that such obfuscation provides complete coverage of all such data in the archive, or that any obfuscation is provided to data that does not fit the description above.

Users should review any resulting data and/or archives generated or processed by this utility for remaining sensitive content before being passed to a third party.
z
sos clean (version %s)
z-
Press ENTER to continue, or CTRL-C to quit.
z
Exiting on user cancel��N)
rzr?rnrr:�batch�input�KeyboardInterrupt�_exitr�)rXre�es   r`�print_disclaimerzSoSCleaner.print_disclaimer�s����m�m�
�
��	
�����5��C�D���������y�y���
!��G�H���%�
 ���� � �!;�<��
�
�3���
!��
�
�1�a� � ��
!�s�&A3�35C�*C�2C	�	Cc��d|_|jdd�}|jddd��|jdd	gd
�d��|jd
dgd��|jddgdd��|jdddtd��|jddgdd��|jdddd� �|jd!d"d#d$�%�|jd&d'd(d)d*�+�|jd,d(d)d-d.�/�|jd0d1gdd2�+�y)3Nzsos clean|mask TARGET [options]zCleaner/Masking Optionsz7These options control how data obfuscation is performedr(�TARGETz%The directory or archive to obfuscate)�metavar�helpz--archive-typer)r�report�collect�insightszdata-dir�tarballz8Specify what kind of archive the target was generated as)�default�choicesr�z	--domains�extendz!List of domain names to obfuscate)�actionr�r�z--disable-parsersr!zCDisable specific parsers, so that those elements are not obfuscated)r�r��destr�z-jz--jobsrz&Number of concurrent archives to clean)r��typer�z
--keywordsr#zList of keywords to obfuscatez--keyword-filer$z&Provide a file a keywords to obfuscate)r�r�r�z
--map-filer%rz;Provide a previously generated mapping file for obfuscation)r�r�r�z--no-updater&F�
store_truez<Do not update the --map-file with new mappings from this run)r�r�r�r�z--keep-binary-filesr'zGKeep unprocessable binary files in the archive instead of removing them)r�r�r�r�z--usernamesr)zList of usernames to obfuscate)�usage�add_argument_group�add_argument�int)rr6�	clean_grps   r`�add_parser_optionszSoSCleaner.add_parser_options�s���8����-�-�%�E�
�	�	���x��$K�	�	M����/��(K�&8�	�	:�
	���{�8�R�$G�	�	I����2�8�')�0A�&C�	�	E�	���t�X�q�s�$L�	�	N����|�H�b�$.�$C�	�	E�	���/��$2�$L�	�	N�	���|�*�'I�&<�	�	>�	���}�;��&2�%=�	�	>�	���4�e�&2�$7�%G�	�	H�
	���}�;��&.�$D�	�	Frac�&�||j_y)z�For use by report and collect to set the TARGET option appropriately
        so that execute() can be called just as if we were running `sos clean`
        directly from the cmdline.
        N)r:r()rXrBs  r`�set_target_pathzSoSCleaner.set_target_path"s��
 ��	�	�rac�$�d}|jjdk7ro|jjjdd�}|jD]9}|j|k(s�||jj
|j�}�;n_|jD]P}|j|jj
�s�)||jj
|j�}n|sy|jj|�|jrK|jj|j��|jj|�||_|jr&|jj|j_yy)z�The target path is not a directory, so inspect it for being an
        archive or an archive of archives.

        In the event the target path is not an archive, abort.
        Nr�-�_)r:r�replacerV�	type_namer(r,�
check_is_type�report_paths�append�	is_nestedr��get_nested_archivesrUrW�description�ui_name)rX�_arc�
check_type�archive�arcs     r`�inspect_target_archivez!SoSCleaner.inspect_target_archive)sH�����9�9�!�!�V�+����/�/�7�7��S�A�J��-�-�
B���$�$�
�2�"�4�9�9�#3�#3�T�[�[�A�D�
B��)�)�
���$�$�T�Y�Y�%5�%5�6��t�y�y�/�/����=�D��
������ � ��&��>�>����$�$�T�%=�%=�%?�@�
���$�$�T�*�"&�D�����*.�*=�*=�*I�*I�D���'�rac��|jjD].}t|jd��dks�!t	d|�d���y)z�Check any values passed to the parsers via the commandline, e.g.
        the --domains option, to ensure that they are valid for the parser in
        question.
        �.�zInvalid value 'z0' given: --domains values must be actual domainsN)r:r �lenrQr�)rX�_doms  r`rDz!SoSCleaner.validate_parser_valuesFsP��
�I�I�%�%�	�D��4�:�:�c�?�#�a�'��%�d�V�,%�%���	rac�	�|jjjd�djd�d|_|jr|j�g|_tjj|jj�sC|jjd|jjz�|jd�|j�|js,|jjd�|jd�g|_|jD],}|j dk(s�|j"j%��.|j'�|j)�|j+�|js9|j,ry	|jj/d
�|jd�|jj/dt1|j�z�|j3�}|j5|�}|j7|�|j9�|j,r'|jD�cgc]}|j:��}}||fSd	}t1|j�dkDr|j=�}n�|jd}|j:}|j?|j:�}	|	��|jA|jd�d�d|jB���}
tEtjjG|jH|
�d
�5}|jK|	�d	d	d	�|jM�tjjG|jH|jA|jd�d��}tOjP||�tjR|�}|jj/d|���|jj/d|�d��|jj/dtU|jV����|jj/dtY|jZ�j\�d��|jj/d�|j_�y	cc}w#1swY��kxYw)a,SoSCleaner will begin by inspecting the TARGET option to determine
        if it is a directory, archive, or archive of archives.

        In the case of a directory, the default behavior will be to edit the
        data in place. For an archive will we unpack the archive, iterate
        over the contents, and then repack the archive. In the case of an
        archive of archives, such as one from SoSCollector, each archive will
        be unpacked, cleaned, and repacked and the final top-level archive will
        then be repacked as well.
        �/���z.tarrz,Invalid target: no such file or directory %sr�z'No valid archives or directories found
zHostname ParserNz#No reports obfuscated, aborting...
z&
Successfully obfuscated %s report(s)
r��wz2A mapping of obfuscated elements is available at
	z)
The obfuscated archive is available at
	ruz	Size	z	Owner	zcPlease send the obfuscated archive to your support representative and keep the mapping file private)0r:r(rQ�arc_namer9r�r�r@rBr�r?rpr�r��completed_reportsrNrO�mapping�set_initial_counts�preload_all_archives_into_maps�generate_parser_item_regexes�obfuscate_report_pathsrHrnr��compile_mapping_dict�write_map_for_archive�write_map_for_config�write_stats_to_manifest�final_archive_path�rebuild_nested_archive�get_new_checksum�obfuscate_stringrJr�rCr-�write�write_cleaner_log�shutil�move�statr�st_sizer�st_uid�pw_name�cleanup)
rXr6�_map�map_path�a�	arc_paths�
final_path�arc_pathr��checksum�chksum_name�cf�arcstats
             r`�executezSoSCleaner.executeRs����	�	�(�(�.�.�s�3�B�7�=�=�f�E�a�H��
�����!�!�#�����w�w�~�~�d�i�i�.�.�/��K�K���L� $�	�	� 0� 0�1�
2��J�J�q�M��#�#�%�� � ��K�K���H�I��J�J�q�M�"$����l�l�	4�F��{�{�/�/����1�1�3�	4�	
�+�+�-��)�)�+��#�#�%��%�%��}�}���K�K���C�D��J�J�q�M������C��t�5�5�6�7�	8��(�(�*���-�-�d�3���!�!�$�'��$�$�&��=�=�7;�7M�7M�N�!��-�-�N�I�N��Y�&�&��
��t�%�%�&��*��2�2�4�H��(�(��+�C��-�-�H��,�,�S�-C�-C�D�H��#�"�3�3�'�~�~�c�2�2�6����G����"�'�'�,�,�t�|�|�[�A�3�G�'�2��H�H�X�&�'��"�"�$��W�W�\�\��L�L��!�!�(�.�.��"5�b�"9�:�
�
�	���H�j�)��'�'�*�%��
	
�����B�8�*�M�	
�	
�����:�:�,�b�I�	
�	
�����8�$6�w���$G�#H�I�J������9�X�g�n�n�%=�%E�%E�$F�b�I�J������L�	M�	
�����QO�'�'�s�%R=�S�Sc�F�|jdz}|j|��|jD]m}|jj	d�d}|j|j�}|��?d|�d|j��}|jj||���otj|jj�D]�\}}}|D]�}	tjj||	�}
|
j	|jj�d}|jd�}|jj!|
|��tj"|
�����|j%d�	�|jj'|j(j*�S)
z�Handles repacking the nested tarball, now containing only obfuscated
        copies of the reports, log files, manifest, etc...
        z-obfuscated)rOr�r�z
checksums/r��r�T)r�)r��
setup_archiver�r�rQr�rJr��
add_stringr@�walkrW�extracted_pathrBrC�lstrip�add_filerUr��finalizer:�compression_type)rXr�r��arc_destr��dname�dirn�dirs�files�filename�fnames           r`r�z!SoSCleaner.rebuild_nested_archive�sf��
�=�=�=�0�������)��-�-�	>�G��1�1�7�7��<�R�@�H��,�,�W�-G�-G�H�H��#�-5�t�~�~�F�����'�'��u�'�=�	>�"$����)<�)<�)K�)K�!L�	!��D�$��!�
!�������T�8�4�����D�$7�$7�$F�$F�G��K�����S�)�����%�%�e�%�%�8��	�	�%� �

!�	!�	
���t��,��|�|�$�$�T�Y�Y�%?�%?�@�@rac��i}|jD]=}i||j<||jj|j���?|S)aBuild a dict that contains each parser's map as a key, with the
        contents as that key's value. This will then be written to disk in the
        same directory as the obfuscated report so that sysadmins have a way
        to 'decode' the obfuscation locally
        )rN�map_file_key�update�get_map_contents)rXr�r6s   r`r�zSoSCleaner.compile_mapping_dict�sW�����l�l�	H�F�(*�D��$�$�%���$�$�%�,�,�V�-D�-D�-F�G�	H��rac��t|d�5}|jtj|d���ddd�|S#1swY|SxYw)zjWrite the mapping to a file on disk that is in the same location as
        the final archive(s).
        r�r)�indentN)r�r�r��dumps)rXr�rBr�s    r`�write_map_to_filezSoSCleaner.write_map_to_file�s@���$��_�	1���H�H�T�Z�Z��Q�/�0�	1���	1���s	�'>�Ac��	tjj|j|j	d|j
z��}|j
||�S#t$r}|jd|z�Yd}~yd}~wwxYw)Nz%s-private_mapz$Could not write private map file: %s)	r@rBrCr-r�r�rr�rq)rXr�r�r�s    r`r�z SoSCleaner.write_map_for_archive�sr��	��w�w�|�|�����%�%�&6����&F�G��H��)�)�$��9�9���	��N�N�A�C�G�H���	�s�AA�	B�#A<�<Bc���|jjr�|jjs�tjj|jj�}		tj|d��|j||jj�|jd|jjz�yyy#t$r}|jd|z�Yd}~yd}~wwxYw)z}Write the mapping to the config file so that subsequent runs are
        able to provide the same consistent mapping
        Tr3zWrote mapping to %sz(Could not update mapping config file: %sN)r:r%r&r@rB�dirnamerArrkr�rq)rXr��cleaner_dirr�s    r`r�zSoSCleaner.write_map_for_config�s����9�9���d�i�i�&9�&9��'�'�/�/�$�)�)�*<�*<�=�K�
�
&����K�$�7��&�&�t�T�Y�Y�-?�-?�@����4�t�y�y�7I�7I�I�J�':����
&����I�!$� %�&�&��
&�s�"A%C
�
	C1�C,�,C1c��tjj|jd|jz�}t|d�5}|jjd�|jj�D]}|j|��	ddd�|r/|j|�|jj|d��yy#1swY�;xYw)z�When invoked via the command line, the logging from SoSCleaner will
        not be added to the archive(s) it processes, so we need to write it
        separately to disk
        z%s-obfuscation.logr�rNzsos_logs/cleaner.logr�)
r@rBrCr-r�r��sos_log_file�seek�	readlinesr��obfuscate_filer�r�)rXr��log_name�logfilerys     r`r�zSoSCleaner.write_cleaner_log�s���
�7�7�<�<��L�L�.����>�
���(�C�
 �	$�G����"�"�1�%��)�)�3�3�5�
$���
�
�d�#�
$�	$�
�����)��L�L�!�!�(�1G�!�H��	$�	$�s
�AC�Cc�F�	d}t|d�}tj|j�}	|j	|�}|sn|j|��&|j
�|j�dzS#t$r}|jd|z�Yd}~yd}~wwxYw)zvCalculate a new checksum for the obfuscated archive, as the previous
        checksum will no longer be valid
        i�rbruz#Could not generate new checksum: %sN)
r��hashlib�newrJ�readr�close�	hexdigestr�rk)rX�archive_path�	hash_size�
archive_fp�digest�hashdatar�s       r`r�zSoSCleaner.get_new_checksum
s���	H��I��l�D�1�J��[�[����0�F��%�?�?�9�5�����
�
�h�'�	�

�����#�#�%��,�,���	H��N�N�@�3�F�G�G���	H�s�A6A9�9	B �B�B c��dt|j��d|jj�d�}|jj|�|jjr|jjd�t|jj�}|j|j|jd��|jd��|jr,|j�|j|j�yy#t$r3|jjd	�tj d
�YywxYw)z�Perform the obfuscation for each archive or sos directory discovered
        during setup.

        Each archive is handled in a separate thread, up to self.opts.jobs will
        be obfuscated concurrently.
        zFound z. total reports to obfuscate, processing up to z concurrently
zpWARNING: binary files that potentially contain sensitive information will NOT be removed from the final archive
r�)�	chunksizeT)�waitzExiting on user cancelr�N)r�r�r:r"r?rnr'rTr�map�obfuscate_report�shutdownrW�_replace_obfuscated_archivesr�r@r�)rXre�pools   r`r�z!SoSCleaner.obfuscate_report_pathss��	�%(��(9�(9�$:�D�I�I�N�N�L�
�
�K�K���S�!��y�y�*�*����#�#�O��&�d�i�i�n�n�5�D��H�H�T�*�*�D�,=�,=��H�K��M�M�t�M�$��"�"��1�1�3��%�%�d�&9�&9�:�#��!�	��K�K���5�6��H�H�S�M�	�s�DD�9E�
Ec�Z�|jD]�}tj|j�|jj
}|jjd�d}tjj||�}tj|j|�||_��y)z�When we have a nested archive, we need to rebuild the original
        archive, which entails replacing the existing archives with their
        obfuscated counterparts
        r�r�N)r�r@rUrrWr�r�rQrBrCr�r�)rXr�r�r��	dest_names     r`r#z'SoSCleaner._replace_obfuscated_archives:s���
�-�-�	3�G��I�I�g�*�*�+��&�&�5�5�D��0�0�6�6�s�;�B�?�G������T�7�3�I��K�K��2�2�D�9�)2�G�&�
	3rac�F�|jD]}|j��y)z�For the parsers that use prebuilt lists of items, generate those
        regexes now since all the parsers should be preloaded by the archive(s)
        as well as being handed cmdline options and mapping file configuration.
        N)rN�generate_item_regexes)rXr6s  r`r�z'SoSCleaner.generate_parser_item_regexesGs#��
�l�l�	+�F��(�(�*�	+rac���|jD�]8}|jj�j�dj	�}|j||�D]a}|j
|�}|s�|jd|�d|�d|j���|j�D]}	|j|���c|j||�}	|	rC|jd|�d	|j���|	D]}
|jj|
��|j|D]}|jj!|����;y#t$r$}|jd|�d|�d|���Yd}~��d}~wwxYw)
a*
        For each archive we've determined we need to operate on, pass it to
        each prepper so that we can extract necessary files and/or items for
        direct regex replacement. Preppers define these methods per parser,
        so it is possible that a single prepper will read the same file for
        different parsers/mappings. This is preferable to the alternative of
        building up monolithic lists of file paths, as we'd still need to
        manipulate these on a per-archive basis.

        :param archive: The archive we are currently using to prepare our
                        mappings with
        :type archive:  ``SoSObfuscationArchive`` subclass

        :param prepper: The individual prepper we're using to source items
        :type prepper:  ``SoSPrepper`` subclass
        rz	Prepping z parser with file z from zFailed to prep z
 map from �: Nz mapping with items from )rNrOrPrQrR�get_parser_file_list�get_file_contentrkr�rv�
parse_liner��get_items_for_mapr��add�regex_items�add_regex_item)rXr��prepperr\�pname�_file�contentryr��	map_items�item�ritems            r`�_prepare_archive_with_prepperz(SoSCleaner._prepare_archive_with_prepperOs���"�|�|�	6�G��L�L�&�&�(�.�.�0��3�9�9�;�E� �5�5�e�W�E�
��!�2�2�5�9��������5�'�1C�E�7�K'�'.���&7� 9�:�#�.�.�0��D���*�*�4�0��

� �1�1�%��A�I������5�'�1J�")�/�/�!2� 4�5�%�.�D��O�O�'�'��-�.�!�,�,�U�3�
6�����.�.�u�5�
6�-	6��%�����-�e�W�J�u�g�R��u�M�����s�+E
�
	E7	�E2	�2E7	c#�
K�ttjj�}g}|j	�D]}|jt
d|�����!t|d���D]}||j�����y�w)a
        Discover all locally available preppers so that we can prepare the
        mappings with obfuscation matches in a controlled manner

        :returns: All preppers that can be leveraged locally
        :rtype:   A generator of `SoSPrepper` items
        zsos.cleaner.preppers.c��|jSri)�priority)�xs r`�<lambda>z)SoSCleaner.get_preppers.<locals>.<lambda>�s
��1�:�:�ra)�key)r+N)	rr0r2�preppers�get_modulesr�r�sortedr:)rX�helper�preps�_prepr2s     r`�get_prepperszSoSCleaner.get_preppersysz���� ���� 4� 4�5�����'�'�)�	I�E��L�L��)>�u�g�'F�G�H�	I��e�)=�>�	-�G��$�)�)�,�,�	-�s�BBc��|jd�|j�D]%}|jD]}|j||���'y)aBefore doing the actual obfuscation, if we have multiple archives
        to obfuscate then we need to preload each of them into the mappings
        to ensure that node1 is obfuscated in node2 as well as node2 being
        obfuscated in node1's archive.
        z.Pre-loading all archives into obfuscation mapsN)rSrFr�r9)rXr2r�s   r`r�z)SoSCleaner.preload_all_archives_into_maps�sR��	
�
�
�F�G��(�(�*�	E�G��,�,�
E���2�2�7�G�D�
E�	Erac�^�	|jj|j�}tj�}|jd|�|js|j�|jd�|j�D]�}|j|jdz�d}|j|�r�6|jjs#|j|�r|j|��o	|j!|||j�}|r|j#||���	|j)|�	|j-|�|j.sz|j1�}|rM|jd�	|j3|j5|j��|j7|�|j8j;|�tj�}	|jd|	�|jd|	|z
�|jdt=|j>��|jd|j@�d}
|jBrd}
|
|jBz}
|jd|
z�y#t$$r"}|j'd|�d|���Yd}~��#d}~wwxYw#t$$r+}|j+d|z|j�	�Yd}~���d}~wwxYw#t$$r+}|j+d
|z|j�	�Yd}~���d}~wwxYw#t$$r?}|j'd|j�d
|���|jd|z�Yd}~yd}~wwxYw#t$$r5}|jDjGd|j�d|���Yd}~yd}~wwxYw)z�Individually handle each archive or directory we've discovered by
        running through each file therein.

        Positional arguments:

            :param report str:      Filepath to the directory or archive
        �
start_timezBeginning obfuscation...r�r�zUnable to parse file r*Nz#Failed to obfuscate directories: %s�rfz Failed to obfuscate symlinks: %szRe-compressing...zArchive z failed to compress: z!Failed to re-compress archive: %s�end_time�run_time�files_obfuscated�total_substitutionsrz! [removed %s unprocessable files]zObfuscation completed%szException while processing )$rMrL�archive_namer�now�	add_field�is_extracted�extract�
report_msg�
get_file_listrQ�should_skip_filer:r'�should_remove_file�remove_filer�update_sub_countr�rk�obfuscate_directory_namesrS�obfuscate_symlinksr��get_compression�rename_top_dirr��compressr�r�r��
file_sub_list�total_sub_count�removed_file_countr?rn)rXr��arc_mdrIr��
short_name�countr��methodrK�rmsgs           r`r!zSoSCleaner.obfuscate_report�sb��E	<��_�_�0�0��1E�1E�F�F�!����J����\�:�6��'�'����!����9�:� �.�.�0�
8��"�[�[��)=�)=��)C�D�Q�G�
��+�+�J�7���	�	�3�3��2�2�:�>��'�'�
�3��8� �/�/��z�07�0D�0D�F�E���0�0��U�C��
8�"
;��.�.�w�7�

;��'�'��0��$�$� �0�0�2����&�&�':�;�
��.�.� �1�1�'�2F�2F�G�� �(�(��0��&�&�-�-�g�6��|�|�~�H����Z��2����Z��J�)>�?����/��W�5J�5J�1K�L����2�G�4K�4K�L��D��)�)�:���g�8�8�8�����8�4�?�@��W!�8��N�N�&0�#�$7�8�8��8���
;��
�
�C�c�I�%,�%9�%9��;�;��
;���
;��
�
�@�3�F�%,�%9�%9��;�;��
;��%�����*1�*>�*>��(E�F��*�*�+N�-0�,1�2�����&�	<��K�K��� '� 4� 4�c�;�
<�
<��	<�s��C7M.�:1J�+M.�.J5�K,�/M.�;L#�<C
M.�	J2�J-�'M.�-J2�2M.�5	K)�> K$�M.�$K)�)M.�,	L �5 L�M.�L � M.�#	M+�,5M&�!M.�&M+�+M.�.	N,�7+N'�'N,c	���|syd}�s|jd�d�tjj|��s|j	d�zxs||��tjd|j��}|jD�cgc]"}t�fd	�|jD��s|��$}}t|d
d��5}|D].}		|j|	|�\}	}
||
z
}|j|	��0	ddd�|jd�|r t!j"|j$|�|j'�|j)�jd�d�}�j+�jd�d|�}
|
�k7r�|j��d}tjj-||
�}tjj|�stj.||�|S|j)tj0|��}tj2|�tj4||�|Scc}w#t$r$}|j	d
��d|��|��Yd}~���d}~wwxYw#1swY���xYw)a5Obfuscate and individual file, line by line.

        Lines processed, even if no substitutions occur, are then written to a
        temp file without our own tmpdir. Once the file has been completely
        iterated through, if there have been substitutions then the temp file
        overwrites the original file. If there are no substitutions, then the
        original file is left in place.

        Positional arguments:

            :param filename str:        Filename relative to the extracted
                                        archive root
        Nrr�r�zObfuscating %srJr�)�mode�dirc3�@�K�|]}|j�����y�wri)�match)�.0�_skiprcs  �r`�	<genexpr>z,SoSCleaner.obfuscate_file.<locals>.<genexpr>�s������05�E�K�K�
�+��s�r�r�)�errorszUnable to obfuscate r*)rQr@rB�islinkrk�tempfile�NamedTemporaryFiler,rN�any�
skip_patternsr��obfuscate_liner�r�rr��copyfilerOrr�r�rC�rename�readlinkrU�symlink)rXr�rcr��subs�tfile�_p�_parsersr�ryrdr��_ob_short_name�_ob_filenamer��_ob_path�
_target_obs  `              r`rzSoSCleaner.obfuscate_file�s[��������!����,�R�0�J��w�w�~�~�h�'�
�N�N�+�j�8�D�H�"*�
�
,��/�/�S�d�k�k�J�E�!�\�\�����9;�9I�9I�����H���h��I�6�
M�%�!�M�D�M�&*�&9�&9�$��&I���e���
�����D�)�	M�
M�
�J�J�q�M������
�
�H�5��K�K�M��.�.�z�/?�/?��/D�R�/H�I��!�)�)�*�*:�*:�3�*?��*C�*8�:���:�%��~�~�j�1�!�4�H��w�w�|�|�H�l�;�H��7�7�>�>�(�+��	�	�(�H�-���"�2�2�2�;�;�x�3H�I�
��	�	�(�#��
�
�:�x�0����U��%�M����*4�c�(;�CK�'�M�M��M��

M�
M�s<�'I�=I:�+I
�/I:�
	I7�I2�,I:�2I7�7I:�:Jc��|jd|j��|j�D]�}	|j|j�djd�}|j
d|z|j��tj|�}tjj|j|j|��}|j|�}||k7s||k7r+tj|�tj||���y#t$r"}|jd|�d|���Yd}~��d}~wwxYw)	a�Iterate over symlinks in the archive and obfuscate their names.
        The content of the link target will have already been cleaned, and this
        second pass over just the names of the links is to ensure we avoid a
        possible race condition dependent on the order in which the link or the
        target get obfuscated.

        :param archive:     The archive being obfuscated
        :type archive:      ``SoSObfuscationArchive``
        zObfuscating symlink namesrJr�r�zObfuscating symlink %szError obfuscating symlink 'r�N)rSrO�get_symlinksrQr�r�rkr@rxrBrCr�rUryr�)rXr�ry�_sym�_target�_ob_sym_name�
_ob_targetr�s        r`r[zSoSCleaner.obfuscate_symlinks(s$��	
�
�
�1�'�:N�:N�
�O��+�+�-�	0�G�
0��}�}�W�%;�%;�<�Q�?�F�F�s�K�����7�$�>�&-�&:�&:��<��+�+�g�.�� "�w�w�|�|�G�,B�,B�,0�,A�,A�$�,G� I��"�2�2�7�;�
�!�G�+��w�1F��I�I�g�&��J�J�z�<�8��'	0��(�
0��
�
�!(�#�/�0�0��
0�s�C!D�	E�D<�<Ec�`�|jd|jz�t|j�d��D]�}t	j
|�D]�}tjj||�}|j|j�d}tjj|�s�a|j|�}||k7s�x|j|�}tjj|j|jd�|�}t	j||�����y)z�For all directories that exist within the archive, obfuscate the
        directory name if it contains sensitive strings found during execution
        z)Obfuscating directory names in archive %sT)�reverser�r�N)rSrOrB�get_directory_listr@�listdirrBrCrQr�r�r��rstripr�rw)rXr��dirpath�_name�_dirname�_arc_dir�_ob_dirname�_ob_arc_dirs        r`rZz$SoSCleaner.obfuscate_directory_namesKs���	
�
�
�A��,�,�-�	.��g�8�8�:�D�I�
	9�G����G�,�
9���7�7�<�<���7��#�>�>�'�*@�*@�A�"�E���7�7�=�=��*�"&�"7�"7��">�K�"�e�+�&.�o�o�e�&<��&(�g�g�l�l�#�2�2�'�.�.�s�3�'�'��
�	�	�(�K�8�
9�
	9rac��|jD]}	|j|�}�|S#t$r}|jd|z�Yd}~�;d}~wwxYw)Nz!Error obfuscating string data: %s)rN�parse_string_for_keysr�rS)rX�string_datar6r�s    r`r�zSoSCleaner.obfuscate_string`s^���l�l�	I�F�
I�$�:�:�;�G��	I�
����
I��
�
�A�C�G�H�H��
I�s�&�	A
�A�A
c��d}|j�s||fS|�|j}|D]}	|j|�\}}||z
}�||fS#t$r)}|j	d|z|j
�Yd}~�Pd}~wwxYw)a�Run a line through each of the obfuscation parsers, keeping a
        cumulative total of substitutions done on that particular line.

        Positional arguments:

            :param line str:        The raw line as read from the file being
                                    processed
            :param parsers:         A list of parser objects to obfuscate
                                    with. If None, use all.

        Returns the fully obfuscated line and the number of substitutions made
        rNzfailed to parse line: %s)rRrNr-r�rkrO)rXryrNrdr6�_countr�s       r`ruzSoSCleaner.obfuscate_linehs������z�z�|���;���?��l�l�G��	N�F�
N�%�0�0��6���f�����	N��U�{����
N����9�C�?����M�M��
N�s�A
�
	A<�A7�7A<c�H�|jjd�}|jD]x}|j|jj	dd�j��}|j
dt|jjj����zy)zLWrite some cleaner-level, non-report-specific stats to the manifest
        rN� r��entriesN)rMrLrNrOr�rPrQr�r��dataset�keys)rX�	parse_secr6�_secs    r`r�z"SoSCleaner.write_stats_to_manifest�s}���O�O�/�/�	�:�	��l�l�	J�F��(�(����)<�)<�S�#�)F�)L�)L�)N�O�D��N�N�9�c�&�.�.�*@�*@�*E�*E�*G�&H�I�	Jra)NNNFNri)F)NN)*�__name__�
__module__�__qualname__r~�desc�arg_defaultsr8rgrkrSrqrz�classmethodr�rEr�r�r�r�rDr�r�r�rr�r�r�r�r�r#r�r9rFr�r!rr[rZr�rur��
__classcell__)r_s@r`rr's ���$�LD�D�������6��"����L�GL�"�D+�LJ�:�9�:���&��&��8!�:�*F��*F�X �J�:
�\�|A�0��	�&�"I�"�&�:3�+�(6�T
-�	E�M<�^D�L!0�F9�*��8Jrar)-rr�r<r@r��sos.cleaner.preppersr0rq�concurrent.futuresrr�pwdrr�
sos.componentr�sos.cleaner.parsers.ip_parserr�sos.cleaner.parsers.mac_parserr	�#sos.cleaner.parsers.hostname_parserr
�"sos.cleaner.parsers.keyword_parserr�#sos.cleaner.parsers.username_parserr�sos.cleaner.parsers.ipv6_parserr
�sos.cleaner.archives.sosrrrr�sos.cleaner.archives.genericrr�sos.cleaner.archives.insightsr�
sos.utilitiesrrr�textwraprrrcrar`�<module>r�si�����	�
���1����&�5�7�A�?�A�9�=�=�H�9�K�K��c
J��c
Jra

Zerion Mini Shell 1.0