1# Copyright: (c) 2012-2014, Michael DeHaan <michael.dehaan@gmail.com>
2# Copyright: (c) 2017, Ansible Project
3# GNU General Public License v3.0+ (see COPYING or https://www.gnu.org/licenses/gpl-3.0.txt)
4
5from __future__ import (absolute_import, division, print_function)
6__metaclass__ = type
7
8import os
9import re
10
11from ast import literal_eval
12from jinja2 import Template
13from string import ascii_letters, digits
14
15from ansible.module_utils._text import to_text
16from ansible.module_utils.common.collections import Sequence
17from ansible.module_utils.parsing.convert_bool import boolean, BOOLEANS_TRUE
18from ansible.module_utils.six import string_types
19from ansible.config.manager import ConfigManager, ensure_type, get_ini_config_value
20from ansible.utils.fqcn import add_internal_fqcns
21
22
23def _warning(msg):
24    ''' display is not guaranteed here, nor it being the full class, but try anyways, fallback to sys.stderr.write '''
25    try:
26        from ansible.utils.display import Display
27        Display().warning(msg)
28    except Exception:
29        import sys
30        sys.stderr.write(' [WARNING] %s\n' % (msg))
31
32
33def _deprecated(msg, version='2.8'):
34    ''' display is not guaranteed here, nor it being the full class, but try anyways, fallback to sys.stderr.write '''
35    try:
36        from ansible.utils.display import Display
37        Display().deprecated(msg, version=version)
38    except Exception:
39        import sys
40        sys.stderr.write(' [DEPRECATED] %s, to be removed in %s\n' % (msg, version))
41
42
43def mk_boolean(value):
44    ''' moved to module_utils'''
45    _deprecated('ansible.constants.mk_boolean() is deprecated.  Use ansible.module_utils.parsing.convert_bool.boolean() instead')
46    return boolean(value, strict=False)
47
48
49def get_config(parser, section, key, env_var, default_value, value_type=None, expand_relative_paths=False):
50    ''' kept for backwarsd compatibility, but deprecated '''
51    _deprecated('ansible.constants.get_config() is deprecated. There is new config API, see porting docs.')
52
53    value = None
54    # small reconstruction of the old code env/ini/default
55    value = os.environ.get(env_var, None)
56    if value is None:
57        try:
58            value = get_ini_config_value(parser, {'key': key, 'section': section})
59        except Exception:
60            pass
61    if value is None:
62        value = default_value
63
64    value = ensure_type(value, value_type)
65
66    return value
67
68
69def set_constant(name, value, export=vars()):
70    ''' sets constants and returns resolved options dict '''
71    export[name] = value
72
73
74class _DeprecatedSequenceConstant(Sequence):
75    def __init__(self, value, msg, version):
76        self._value = value
77        self._msg = msg
78        self._version = version
79
80    def __len__(self):
81        _deprecated(self._msg, version=self._version)
82        return len(self._value)
83
84    def __getitem__(self, y):
85        _deprecated(self._msg, version=self._version)
86        return self._value[y]
87
88
89# Deprecated constants
90BECOME_METHODS = _DeprecatedSequenceConstant(
91    ['sudo', 'su', 'pbrun', 'pfexec', 'doas', 'dzdo', 'ksu', 'runas', 'pmrun', 'enable', 'machinectl'],
92    ('ansible.constants.BECOME_METHODS is deprecated, please use '
93     'ansible.plugins.loader.become_loader. This list is statically '
94     'defined and may not include all become methods'),
95    '2.10'
96)
97
98# CONSTANTS ### yes, actual ones
99BLACKLIST_EXTS = ('.pyc', '.pyo', '.swp', '.bak', '~', '.rpm', '.md', '.txt', '.rst')
100BOOL_TRUE = BOOLEANS_TRUE
101DEFAULT_BECOME_PASS = None
102DEFAULT_PASSWORD_CHARS = to_text(ascii_letters + digits + ".,:-_", errors='strict')  # characters included in auto-generated passwords
103DEFAULT_REMOTE_PASS = None
104DEFAULT_SUBSET = None
105# FIXME: expand to other plugins, but never doc fragments
106CONFIGURABLE_PLUGINS = ('become', 'cache', 'callback', 'cliconf', 'connection', 'httpapi', 'inventory', 'lookup', 'netconf', 'shell')
107# NOTE: always update the docs/docsite/Makefile to match
108DOCUMENTABLE_PLUGINS = CONFIGURABLE_PLUGINS + ('module', 'strategy', 'vars')
109IGNORE_FILES = ("COPYING", "CONTRIBUTING", "LICENSE", "README", "VERSION", "GUIDELINES")  # ignore during module search
110INTERNAL_RESULT_KEYS = ('add_host', 'add_group')
111LOCALHOST = ('127.0.0.1', 'localhost', '::1')
112MODULE_REQUIRE_ARGS = tuple(add_internal_fqcns(('command', 'win_command', 'shell', 'win_shell', 'raw', 'script')))
113MODULE_NO_JSON = tuple(add_internal_fqcns(('command', 'win_command', 'shell', 'win_shell', 'raw')))
114RESTRICTED_RESULT_KEYS = ('ansible_rsync_path', 'ansible_playbook_python', 'ansible_facts')
115TREE_DIR = None
116VAULT_VERSION_MIN = 1.0
117VAULT_VERSION_MAX = 1.0
118
119# This matches a string that cannot be used as a valid python variable name i.e 'not-valid', 'not!valid@either' '1_nor_This'
120INVALID_VARIABLE_NAMES = re.compile(r'^[\d\W]|[^\w]')
121
122
123# FIXME: remove once play_context mangling is removed
124# the magic variable mapping dictionary below is used to translate
125# host/inventory variables to fields in the PlayContext
126# object. The dictionary values are tuples, to account for aliases
127# in variable names.
128
129COMMON_CONNECTION_VARS = frozenset(('ansible_connection', 'ansible_host', 'ansible_user', 'ansible_shell_executable',
130                                    'ansible_port', 'ansible_pipelining', 'ansible_password', 'ansible_timeout',
131                                    'ansible_shell_type', 'ansible_module_compression', 'ansible_private_key_file'))
132
133MAGIC_VARIABLE_MAPPING = dict(
134
135    # base
136    connection=('ansible_connection', ),
137    module_compression=('ansible_module_compression', ),
138    shell=('ansible_shell_type', ),
139    executable=('ansible_shell_executable', ),
140
141    # connection common
142    remote_addr=('ansible_ssh_host', 'ansible_host'),
143    remote_user=('ansible_ssh_user', 'ansible_user'),
144    password=('ansible_ssh_pass', 'ansible_password'),
145    port=('ansible_ssh_port', 'ansible_port'),
146    pipelining=('ansible_ssh_pipelining', 'ansible_pipelining'),
147    timeout=('ansible_ssh_timeout', 'ansible_timeout'),
148    private_key_file=('ansible_ssh_private_key_file', 'ansible_private_key_file'),
149
150    # networking modules
151    network_os=('ansible_network_os', ),
152    connection_user=('ansible_connection_user',),
153
154    # ssh TODO: remove
155    ssh_executable=('ansible_ssh_executable', ),
156    ssh_common_args=('ansible_ssh_common_args', ),
157    sftp_extra_args=('ansible_sftp_extra_args', ),
158    scp_extra_args=('ansible_scp_extra_args', ),
159    ssh_extra_args=('ansible_ssh_extra_args', ),
160    ssh_transfer_method=('ansible_ssh_transfer_method', ),
161
162    # docker TODO: remove
163    docker_extra_args=('ansible_docker_extra_args', ),
164
165    # become
166    become=('ansible_become', ),
167    become_method=('ansible_become_method', ),
168    become_user=('ansible_become_user', ),
169    become_pass=('ansible_become_password', 'ansible_become_pass'),
170    become_exe=('ansible_become_exe', ),
171    become_flags=('ansible_become_flags', ),
172)
173
174# POPULATE SETTINGS FROM CONFIG ###
175config = ConfigManager()
176
177# Generate constants from config
178for setting in config.data.get_settings():
179
180    value = setting.value
181    if setting.origin == 'default' and \
182       isinstance(setting.value, string_types) and \
183       (setting.value.startswith('{{') and setting.value.endswith('}}')):
184        try:
185            t = Template(setting.value)
186            value = t.render(vars())
187            try:
188                value = literal_eval(value)
189            except ValueError:
190                pass  # not a python data structure
191        except Exception:
192            pass  # not templatable
193
194        value = ensure_type(value, setting.type)
195
196    set_constant(setting.name, value)
197
198for warn in config.WARNINGS:
199    _warning(warn)
200
201
202# The following are hard-coded action names
203_ACTION_DEBUG = add_internal_fqcns(('debug', ))
204_ACTION_IMPORT_PLAYBOOK = add_internal_fqcns(('import_playbook', ))
205_ACTION_IMPORT_ROLE = add_internal_fqcns(('import_role', ))
206_ACTION_IMPORT_TASKS = add_internal_fqcns(('import_tasks', ))
207_ACTION_INCLUDE = add_internal_fqcns(('include', ))
208_ACTION_INCLUDE_ROLE = add_internal_fqcns(('include_role', ))
209_ACTION_INCLUDE_TASKS = add_internal_fqcns(('include_tasks', ))
210_ACTION_INCLUDE_VARS = add_internal_fqcns(('include_vars', ))
211_ACTION_META = add_internal_fqcns(('meta', ))
212_ACTION_SET_FACT = add_internal_fqcns(('set_fact', ))
213_ACTION_SETUP = add_internal_fqcns(('setup', ))
214_ACTION_HAS_CMD = add_internal_fqcns(('command', 'shell', 'script'))
215_ACTION_ALLOWS_RAW_ARGS = _ACTION_HAS_CMD + add_internal_fqcns(('raw', ))
216_ACTION_ALL_INCLUDES = _ACTION_INCLUDE + _ACTION_INCLUDE_TASKS + _ACTION_INCLUDE_ROLE
217_ACTION_ALL_IMPORT_PLAYBOOKS = _ACTION_INCLUDE + _ACTION_IMPORT_PLAYBOOK
218_ACTION_ALL_INCLUDE_IMPORT_TASKS = _ACTION_INCLUDE + _ACTION_INCLUDE_TASKS + _ACTION_IMPORT_TASKS
219_ACTION_ALL_PROPER_INCLUDE_IMPORT_ROLES = _ACTION_INCLUDE_ROLE + _ACTION_IMPORT_ROLE
220_ACTION_ALL_PROPER_INCLUDE_IMPORT_TASKS = _ACTION_INCLUDE_TASKS + _ACTION_IMPORT_TASKS
221_ACTION_ALL_INCLUDE_ROLE_TASKS = _ACTION_INCLUDE_ROLE + _ACTION_INCLUDE_TASKS
222_ACTION_ALL_INCLUDE_TASKS = _ACTION_INCLUDE + _ACTION_INCLUDE_TASKS
223_ACTION_FACT_GATHERING = _ACTION_SETUP + add_internal_fqcns(('gather_facts', ))
224_ACTION_WITH_CLEAN_FACTS = _ACTION_SET_FACT + _ACTION_INCLUDE_VARS
225