#!/usr/bin/env python3 """Infraveil Trust Console: one local entry point for release trust and setup. The console creates a private ``infraveil-control`` directory, prepares its own Python environment, generates the customer-held Ed25519 key, completes the one-time dashboard challenge, manages release approvals, and can install the launcher on the current host. The private key never leaves this machine. Security modes: manual Confirm named releases for the selected server (default). allowlist Sign only hashes listed in approved-hashes.txt. auto Sign every pending hash. This is convenient, but disables the practical release veto while it is enabled and requires an explicit confirmation. Common commands: python infraveil.py Continue the next required setup or run step. python infraveil.py --menu Open the advanced trust console. python infraveil.py --setup Complete guided trust enrollment. python infraveil.py --sign HASH Sign one challenge or release hash. python infraveil.py --once Review named changes for this server once. python infraveil.py --watch Continuously review pending releases. The customized copy downloaded from the dashboard contains a five-minute, single-use bootstrap capability. It is scrubbed from disk after enrollment. """ import argparse import getpass import hashlib import importlib.util import importlib.metadata import json import os import platform import plistlib import re import shutil import subprocess import sys import time import urllib.error import urllib.parse import urllib.request TOOL_VERSION = "2.1" TOOL_USER_AGENT = f"Infraveil-Trust-Console/{TOOL_VERSION} (+https://infraveil.com; machine-client)" MINIMUM_PYTHON = (3, 10) LOCK_FILE_NAME = "runtime-requirements.lock" CONTROL_DIR_NAME = "infraveil-control" LOCKED_WHEEL_HASHES = ( ('cryptography==46.0.7', ( '04959522f938493042d595a736e7dbdff6eb6cc2339c11465b3ff89343b65f65', '128c5edfe5e5938b86b03941e94fac9ee793a94452ad1365c9fc3f4f62216832', '1d25aee46d0c6f1a501adcddb2d2fee4b979381346a78558ed13e50aa8a59067', '24402210aa54baae71d99441d15bb5a1919c195398a87b563df84468160a65de', '258514877e15963bd43b558917bc9f54cf7cf866c38aa576ebf47a77ddbc43a4', '35719dc79d4730d30f1c2b6474bd6acda36ae2dfae1e3c16f2051f215df33ce0', '397655da831414d165029da9bc483bed2fe0e75dde6a1523ec2fe63f3c46046b', '3986ac1dee6def53797289999eabe84798ad7817f3e97779b5061a95b0ee4968', '420b1e4109cc95f0e5700eed79908cef9268265c773d3a66f7af1eef53d409ef', '42a1e5f98abb6391717978baf9f90dc28a743b7d9be7f0751a6f56a75d14065b', '462ad5cb1c148a22b2e3bcc5ad52504dff325d17daf5df8d88c17dda1f75f2a4', '506c4ff91eff4f82bdac7633318a526b1d1309fc07ca76a3ad182cb5b686d6d3', '5ad9ef796328c5e3c4ceed237a183f5d41d21150f972455a9d926593a1dcb308', '5d1c02a14ceb9148cc7816249f64f623fbfee39e8c03b3650d842ad3f34d637e', '5e51be372b26ef4ba3de3c167cd3d1022934bc838ae9eaad7e644986d2a3d163', '60627cf07e0d9274338521205899337c5d18249db56865f943cbe753aa96f40f', '65814c60f8cc400c63131584e3e1fad01235edba2614b61fbfbfa954082db0ee', '73510b83623e080a2c35c62c15298096e2a5dc8d51c3b4e1740211839d0dea77', '7bbc6ccf49d05ac8f7d7b5e2e2c33830d4fe2061def88210a126d130d7f71a85', '80406c3065e2c55d7f49a9550fe0c49b3f12e5bfff5dedb727e319e1afb9bf99', '84d4cced91f0f159a7ddacad249cc077e63195c36aac40b4150e7a57e84fffe7', '8a469028a86f12eb7d2fe97162d0634026d92a21f3ae0ac87ed1c4a447886c83', '91bbcb08347344f810cbe49065914fe048949648f6bd5c2519f34619142bbe85', '935ce7e3cfdb53e3536119a542b839bb94ec1ad081013e9ab9b7cfd478b05006', '9694078c5d44c157ef3162e3bf3946510b857df5a3955458381d1c7cfc143ddb', 'a1529d614f44b863a7b480c6d000fe93b59acee9c82ffa027cfadc77521a9f5e', 'abad9dac36cbf55de6eb49badd4016806b3165d396f64925bf2999bcb67837ba', 'b36a4695e29fe69215d75960b22577197aca3f7a25b9cf9d165dcfe9d80bc325', 'b7b412817be92117ec5ed95f880defe9cf18a832e8cafacf0a22337dc1981b4d', 'c5b1ccd1239f48b7151a65bc6dd54bcfcc15e028c8ac126d3fada09db0e07ef1', 'cbd5fb06b62bd0721e1170273d3f4d5a277044c47ca27ee257025146c34cbdd1', 'cdf1a610ef82abb396451862739e3fc93b071c844399e15b90726ef7470eeaf2', 'cdfbe22376065ffcf8be74dc9a909f032df19bc58a699456a21712d6e5eabfd0', 'd02c738dacda7dc2a74d1b2b3177042009d5cab7c7079db74afc19e56ca1b455', 'd151173275e1728cf7839aaa80c34fe550c04ddb27b34f48c232193df8db5842', 'd23c8ca48e44ee015cd0a54aeccdf9f09004eba9fc96f38c911011d9ff1bd457', 'd3b99c535a9de0adced13d159c5a9cf65c325601aa30f4be08afd680643e9c15', 'd5f7520159cd9c2154eb61eb67548ca05c5774d39e9c2c4339fd793fe7d097b2', 'db0f493b9181c7820c8134437eb8b0b4792085d37dbb24da050476ccb664e59c', 'e06acf3c99be55aa3b516397fe42f5855597f430add9c17fa46bf2e0fb34c9bb', 'ea42cbe97209df307fdc3b155f1b6fa2577c0defa8f1f7d3be7d31d189108ad4', 'ebd6daf519b9f189f85c479427bbd6e9c9037862cf8fe89ee35503bd209ed902', 'f247c8c1a1fb45e12586afbb436ef21ff1e80670b2861a90353d9b025583d246', 'fbfd0e5f273877695cb93baf14b185f4878128b250cc9f8e617ea0c025dfb022', 'fc9ab8856ae6cf7c9358430e49b368f3108f050031442eaeb6b9d87e4dcf4e4f', 'fcd8eac50d9138c1d7fc53a653ba60a2bee81a505f9f8850b6b2888555a45d0e', 'fdd1736fed309b4300346f88f74cd120c27c56852c3838cab416e7a166f67298', 'ffca7aa1d00cf7d6469b988c581598f2259e46215e0140af408966a24cf086ce', )), ('cffi==2.1.1', ( '046bfc24911b37851ee1b51aab8bffe713d89c68c6a057b09484ce9fd5f69b4e', '06c72bb76605a4b0cd0aad6930b69d4baf7dd5d806cfc409b824191099700e66', '0beceaabe56af686895136a2de78db54ecd8e4046b236b8fd6d6cb61389e9bf2', '154852545011f779917b11c78db2358d095da62a9a172b78ad0a583ee5adc0d0', '194cffa889098ced9976c3fc6340305e43f6303657d298da55366907c05c22d6', '19ee6127ee34de7d83ce3d371ebc5ed91addbdcc39f9ab15ce4eb35a4e534971', '1a18a57b58cfb21fc28d72e876acf10eaed67a1ed96226f92af4df681d571c4c', '1aa5645c30469b09530c4ebca77ebf8f17618293c58f8549cb1a543a50236e7d', '1dea0e4d7d4f11f619fe8c1d76caf49e24405b4b5743c0e3be16a500ecd930c9', '208f941bb9d18e768138677f0a6d2ce01f590df56043dda1df1535ac57c88517', '210019b6c7cf07f081b4c54635c8cf744377001350e29cc0f81c4377b4797735', '246fa40ce8645a614ff682e0b70f37134e460eaf93a775e0cbe3cca585a67a80', '25792eac27877609e7bb06d42ff88278a6624fff2ba9bbb523c09616b117e80f', '27350daa11d4f10c540e6e89dada4c54feb7256ad03e9a4dc075ebad7ba360d1', '28907ab9bfb6aa13184cfc17c6b8e1023c5ab6fd7076d8c20a35e59fe04f8f29', '2ae64be792b8966f2c69538199728b290e34726562896df1e5dc8ffd8d8188e8', '31348097ff5bbe827ccc41795d4dd099d9f0625e7def00ee653c137a490c2a6c', '3143d81e29e1e20a9ce10901ec369012947876596f75a222235965f2b7ae832e', '3222ba5d678f80a030e6afbcc33dc1ae5cb45facabb61cee2c7016b8432fde48', '3311ed60d36f83378794e1009ac6258bafbf81f7888b4caa7b35a521e3f95813', '334644fbac4eff73d985a17a91226df55d0f394160c4cfb880e084c8f7161cac', '34e261f78cb6ceaaa36f42f2613f4380d94d9c759a9c73c769ee6e0247364632', '363e05fa78e15116c3c32c210ee36884fd6b9afa6d440e47112c3bd511d64cb6', '398aff33cee2767e3e781d2554c54bd0dff386bb437581e0d8011fde1a942ec1', '3d22a20b1fb1632cc72c22f95f7b0d2961c3e1c235f245ba4c606c4771035659', '42a494cee34437f05546455144f2b5d9ac09b1face62bcfce597d2e521066688', '42e2f76b9455f5a9a844f770bf3e200ed3da0e15f5df3db9c31fe80b04b3d004', '42f6930c31dc7f50732c9ae793c2786c7b6b044195967bbdde40bb9be81c4cc0', '456a61fa52d579ebf9df2e9552ead5129855dbaff6c1e5a9b1bc408809bdc062', '471cee653ae88de62096552e6d24ccb4a5adb8c8c9f10b5054d0122c15bf2779', '49cbc70e6542d4ccccb936558d1064a8012541e78f821f955cff24e357776c94', '4a7c934f7360e8cd64fe9efadcbd10c7c6364f531e432b9a4bf5ccbc9e0e8b50', '4be96343e422f2dfcd12ab5c9f5aebe03f82f737c6bffeca6830b3875cb44aab', '4f42141fc14250de6dde5ee7ea4432be017252d91f19c5ad043c084cea629cac', '507a24c282e0f42f8ed737cf048572cbf580468da5555764a8331735e9c736b6', '51b31d1c98274844cfd7838ce00bfc27c7423a4dc00fc0772fc3331c2cc90676', '58acb8ab8e295e6c5ea12f888cbb13cf21511ef2a3303a23f4325c29d17fe5c1', '5a59cc1c4442bc3d5c703bf720b51138d0bfc173618807c9ee2490a7541dd3d9', '5bb4e7ea95dcd6a014a6fef62e62467d67d8e582326443f3d68e71d6320a9fcf', '5c58fe613dc5e5336357eff555824a314d8e43282600435c8d1cb6a7a2fedd13', '5e7cecbaadb83884793e05828cee59b210b24583b9c7425d0ba6a754fe22eb4e', '616f097f2fe415bc92a247f02e11f634e1f9e9a83d327e3c915c15089c87869e', '63bbfd5ded17c4840ac07cd8f1c21ba9d9708141f840b324f422f41b207e3973', '64faea20f4e2613363a1a9b9c7dd73058f3ecd00133a511e72ad7c511658f527', '661c298b4821edebead0c91edd2b00374d67ad7c5a1f7a91d4442633b79d6a72', '68e62fe11f30d5ca8289242866f0a5291402d8529ca2178ab8afc5c9694ae890', '6a8dddef476fab96d066d578fc88526767b836ab5ab21754e1d5bf3879c31c7c', '6e192623c49c94421616a5778fba35cf0d5a8d000650c1967ef4448ee5cdd990', '7225e4514edb64eb6740324353e0da0711954fd8d7da4576755b1c6e09b697cd', '75f80557d1389eddbd0de2681f6a390a0c5338c31ddaa821381c203fc3fd50d9', '770de9db11e84213beec501cfcaa013b019820ca881e03344dea5844f7876d94', '7750c6449dff7864bb9bb27ddfb0267756189201a3afc911d82b3caacd70dfc3', '7bde5e4cc5c10140859842b9d383af292b22639a4dffb725314baf45968cef80', '7ce713ace7c0e4520535b42b77eaa742c16dab813978064913e5a3cf82973b41', '7da0c5eff80f0197f3b3d1232ec5a682a9325f4ae9016a78f5f5ca35f9ced1f5', '7dbb61fe3a7699468030f71bbe5f8a0e326a151daa91beb11a6fc1f980c55e1c', '811bd1e21d32de12efca32393a0ab3f5133b54fce9bd44b8bd77ab07da14bf6a', '8ef53b2de9bcb9197d31854256575d59dbac0cba72ac627bb291ef5eceb74be4', '937c0052c05a31ca1daf18de3158eed4dbfcb9cc107adbea227728d647be701e', '9d2055050ea716bd38b7f7f1579c275386646b4894c155a3e2f3cd62ed41b7c6', '9f8d177621de5cb38ee3e731eda45d421db093ec0739f46a5594babda7987a98', 'a2d7755bef5a12ed488f4ef1f1b69ee9191d7396083b755a5d2295f6edb4768b', 'a48d62ab9d6f4f98c983223a547af44be6ca3691074c31cecced6facd3ba2dc1', 'a4f00aa42f75d6e4595e8866e748cc1705adc0cddfeb2ca86d0d03993d63ba03', 'a6e721d4b0e45d5b65e87534470e67b18dcd092c83f68fba09f152b9cbc061af', 'a730a083190634c65cca36ba5f489531576ebd79bcd5c8e172130f6453127231', 'a931079504ecc49efed7744c476a5c343a92fabf66dec2db95edb1b2fdc770e2', 'aa9511c62d14da7aacc9b4bf51f3f697a621e83b2d6919008243c3aad168eea3', 'ab36d55f9ed2d067327667c2fea18dda018eb628dd6347aa01dda6cf1f5d3836', 'ad2c86c495b899d862ea0f4b42891b8713a3bd45dd4105c7fd51c2a72f39f3a5', 'aeae0e330c9f6acd681f647d46cefd30c29f93e3392882e792e82080c9691399', 'b0431303acaea1089ad4b3e9ce4e6518193def1118d4073ca848635ee4ea2e96', 'b5bdfd1c873d4e093aabc0ca84c4ca6dbc4f752afb5c86f146d9742580c9da2e', 'baed1e86cc735622097354b9d1281406caf42ff42a886d29faa8e8d1630333be', 'c1453022f490d2459a11819d83ad1d586e9ff65a12ac3e705ffebd46d3685dcf', 'c26608d2222fb1e94487e4a387d85f13eb55d5ed725cb25a0c589ac4ee60e7bc', 'c7659f22557c5a0bc4855cd635f55edec690cc008a40768527762cb9fb263455', 'c8c69575568085ba0b1b10c0249d779a214aea6f6522e949a0fc9fb0fcb449d0', 'c8d2c9fd1f2d16f780d15127abb050d13d1a76c03a4bd87d7e4980e45e511e12', 'ca82be1a1d406ecfe1d25dc16cb33488e5a16bf4438c9fb590484ea29d92478b', 'cc572dace3f60ef98d7b12ff411d20f5362feb31a0439eab0085bbfd349982d7', 'd18e5ac0f2f03f4f518d3e23db0f0cad7faa1da8620e9c09461d443bbf6e6692', 'd28630f5854ab07ab1fd4aba756de52326c82e6be15d414b12793f1975048b54', 'd9c275eaacd24aa73f94ffd6de08fc3f932424d8b6c376f4bed7cde376fe7bc3', 'da0e573f9f97159390c89d9f1a9e41908b66d408cc5b58d08cf3847d844c531b', 'dddad92b554513a31f272570678ba307fb9f618f05e3d4a5eacafff9eae03e1d', 'df423d40ee8654634421812bc3b196da3f9bd7d32929da813f8394c4348a5358', 'df913725b79db7bcf03448f36b7bf8815363417d5b58deecf9305e3e30f0f21a', 'e0bcb7e0f677f543555d2adff3bf19c05f66cdb4796e5ff602442ab2fe3c4ef7', 'e2d65b31f36619cda3999b78b2aa9632e76b78448e7a56fc4240824200e7c4fc', 'e6e8cff14d6fb0be70a09c0bdc58096f501952d04624ebf867e0e56da2df8960', 'f16c709686a78c727bbbf059f92b0bf41c6fc60deec706d2dc19f529175a6125', 'f24fb43132a4c6b4cb4eb029492919b2db645be6808d738f244fd146c03c32cb', 'f53e442b08449d42821fa4a4fba000095af9f62742a500f978a9f557ec44339a', 'f5cfbc5fe74540d335175b656c725d74d90e3730c626d92575eea35029d9afaa', 'f81b3b8f3d4e343550fa4baa0e479bba9f2d29ce9c2e9b51d1ce1718d7442fcf', 'f8ec5e643a9a937f64e1999eb9f75d072263751912dc5cd06d3c85f8f44be7c3', 'fb92203a88b3d3053034db775110081c49d28be6551923805e039924093761e4', 'fcd22650c908d7b7da162bbfaab594a1227a15d1643a98c68b122ac642fa2264', )), ('pycparser==3.0', ( 'b727414169a36b7d524c1c3e31839a521725078d7b2ff038656844266160a992', )), ('requests==2.34.2', ( '2a0d60c172f83ac6ab31e4554906c0f3b3588d37b5cb939b1c061f4907e278e0', )), ('charset-normalizer==3.4.9', ( '0327fcd59a935777d83410750c50600ee9571af2846f71ce40f25b13da1ef380', '03d07803992c6c7bbc976327f34b18b6160327fc81cb82c9d504720ac0be3b62', '04ce310cb89c15df659582aee80a0603788732a5e017d5bd5c81158106ce249c', '0d861473f743244d349b50f850d10eb87aeb22bbdcc8e64f79273c94af5a8226', '0e94703ec9684807f20cfb5eed95c70f67f2a8f21ad620146d7b5a13677b93e5', '0fa1aec2d32bcc03c8fa0f6f1712caad1adc38509f31142112e5c9daf5b9c833', '16b65ea0f2465b6fb52aa22de5eca612aa964ddfec00a912e26f4656cbef890b', '16d10d789dd9bcca1173c95af82c58433122564b7bc39385124be735a35cbe99', '19ac87f93086ce37b86e098888555c4b4bc48102279bae3350098c0ed664b501', '1d22856ffbe153a602df38e4a5464f0b748a54002e0d69ac6d2ad0a197cc99ec', '21e764fd1e70b6a3e205a0e46f3051701f98a8cb3fad66eeb80e48bb502f8698', '231ddcbb35e2ff8973e1365db41fe0572662893b99a05deb183b68ad4c0c8bd4', '253a4a220747e8b5faf57ec320c4f5efb0cef05f647420bf267143ec15dba10a', '280081916dc341820640489a66e4696049401ef1cf6dd672f672e70ad915aca3', '2a441ea71902098ffe78c5abe6c494f44160b4af614ed16c3d9a3b1d17fd8ee2', '304b13570067b2547562e308af560b3963857b1fa90bd6afd978130130fe2d6a', '32286a2c8d167e897177b673176c1e3e00d4057caf5d2b64eef9a3666b03018e', '33bdcc2a32c0a0e861f60841a512c8acc658c87c2ac59d89e3a46dacf7d866e4', '375b83ed0aecfce76c16d198fbc21f3b11b337d68662bea0a995046682a11419', '3c09a49d6cde137258beb3d551994a2927fd35ad5cf96aed573f61bbd67c5f84', '3d92613ec25e43b05f042302531ec0f00b8445190e43325880cbd6ab7c2581da', '40a126142a56b2dfc0aacbad1de8310cbf60da7656db0e6b16eebd48e3e93519', '416c229f77e5ea25b3dfd4b582f8d73d7e43c22320302b9ab128a2d3a0b38efe', '432786d3561e69aeeae6c7e8648964ce0ad05736120135601f87ac26b9c83381', '43b9e366a31fdd1c87d0eb08f579b4a82b723ea54338f040d6b4e518a026ea29', '440eede837960000d74978f0eba527be106b5b9aee0daf779d395276ed0b0614', '45b0cc4e3556cd875e09102988d1ab8356c998b596c9fced84547c8138b487a0', '476743fe6dfe14a2da12e3ac79125dc84a3b2cf8094369a47a1529b0cd8549fe', '4773092f8019072343a7447203308b176e10199920eb02d6195e81bbb3274c29', '4b3dac63058cc36820b0dd072f89898604e2d39686fe05321729d00d8ac185a0', '4d1c96a7a18b9690a4d46df09e3e3382406ae3213727cd1019ebade1c4a81917', '51307f5c71007673a2bf8232ad973483d281e74cb99c8c5a990af1eefa6277d9', '51447e9aa2684679af07ca5021c3db526e0284347ebf4ffcec1154c3350cfe32', '58150c9f9b9a552505912d182ccdf26f6396fb6094816ceebcbb20eecabaed94', '5b10cd92fc5c498b35a8635df6d5a100207f88b63a4dc1de7ef9a548e1e2cd63', '5e226f6218febc71f6c1fc2fafb91c226f75bdc1d8fb12d66823716e891608fd', '609b3ba8fcc0fb5ab7af00719d0fb6ad0cb518e48e7712d12fd68f1327951198', '60f44ade2cf573dad7a277e6f8ca9a51a21dda572b13bd7d8539bb3cd5dbedde', '611057cc5d5c0afc743ba8be6bd828c17e0aaa8643f9d0a9b9bb7dea80eb8012', '6366a16e1a25018694d6a5d784d09b046edc9eac40ea2b54065c3052672516a1', '65a7ff3f705e57d392f7261b6d0550fe137c3019477431f1c355e0db0a7d3e15', '67830fc78e67501f47bb950471b2dcb9b35b140084429318e862895a8e89c993', '68ce9f4d6b26d5ccbf7fd4459bf75f74a0a146677ebba80597df60cbdb20e6f4', '68e5f26a1ad57ded6d1cfb85331d1c1a195314756471d97758c48498bb4dcdf5', '69b157c5d3292bcd443faca052f3096f637f1e074b98212a933c074ae23dc3b8', '75286256590a6320cf106a0d28970d3560aad9ee09aa7b34fb40524792436d35', '78841cccf1af7b40f6f716338d50c0902dbe88d9f800b3c973b7a9a0a693a642', '78fa18e436a1a0e58dbd7e02fc4473f3f32cceb12df9dfca542d075961c307d2', '79580094b00d1789d1f93ea55bc43cb2f611910c72235b7657f3482ddcc1b22d', '7b86a2b16095d250c6f58b3d9b2eee6f4147754344f3dab0922f7c9bf7d226c9', '83aed2c10721ddd90f68140685391b50811a880af20654c59af6b6c66c40513c', '84fd18bcc17526fc2b3c1af7d2b9217d32c9c04448c16ec693b9b4f1985c3d33', '871ff67ea1aad4dfd91736464934d56b32dac49f9fbe16cddba36198a7b3a0db', '898f0e9068ca27d37f8e83a5b962821df851532e6c4a7d615c1c033f9da6eedf', '8a79d9f4d8001473a30c163556b3c3bfebec837495a412dde78b51672f6134f9', '8c041122946b7ba21bb32c45b1aa57b1be35527690aeb3c5c234521085632eee', '90c44bc373b7687f6948b693cceaea1348ae0975d7474746559494468e3c1d84', '9104ed0bd76a429d46f9ec0dbc9b08ad1d2dcdf2b00a5a0daa1c145329b35b44', '920079c3f7456fa213e0829ed2073aaa727fd39d889ead5b4f35d0de5460d04f', '93d59d504b230e83c7a843251681959a0b6a9cd76f6e146ce1b8a80eb8739af9', '9b2aff1c7b3884512b9512c3eaadd9bab39fb45042ffaaa1dd08ff2b9f8109d9', '9b8e0f3107e2200b76f6054de99016eac3ee6762713587b36baaa7e4bd2ae177', '9bb41182d93ea91f60b4bc8fbf4c820c69ef8a12ab2d917f3f1834f1acad07e8', '9cdef90ae47919cae358d8ab15797a800ed41da7aba5d72419fb510729e2ed4b', 'a1786910334ed46ab1dd73222f2cd1e05c2c3bb39f6dddb4f8b36fc382058a39', 'a4cfde78a9f2880208d16a93b795726a3017d5977e08d1e162a7a31322479c41', 'a4fbdde9dd4a9ce5fd52c2b3a347bb50cc89483ef783f1cb00d408c13f7a96c0', 'aa99adc8f081b475a12843953db36831eaf83ec33eb46a90629ca6a5de45a616', 'ac351b3b8014eead140e77e9717e2992c6bbe30b63bc3422422eb84865412e3d', 'ad41ba96094304aa090f5a30cb6e4fb3b3f1c264c523394b4c39bbacc4dc92ba', 'b5314963fce9b0b12743891de876e724997864ee22aa496f903f426c7e2fa5b2', 'bcf74c1df76758a395bf0af608c04c82257523f55c9868b334f06270d0f2112b', 'bd47ba7fc3ca94896759ea0109775132d3e7ab921fbf54038e1bab2e46c313c9', 'c0323c9daef75ef2e5083624b4585018a0c9d5e3b40f607eed81a311270b934b', 'c1225416b463483160e4af85d5fc3a9690ccb53fd4b1865a6437825f5ede3209', 'c1c948747b03be832dceed96ca815cef7360de9aa19d37c730f8e3f6101aca48', 'c25fe15c70c59eb7c5ce8c06a1f3fa1da0ecc5ea1e7a5922c40fd2fa9b0d5046', 'cc1b0fff8ead343dae06305f954eb8468ba0ec1a97881f42489d198e4ce3c632', 'cd6280cf040f233bd7d3407b743b4b4c74f70e8e1c4199cb112a62c941c0772a', 'cd6c3d4b783c556fa00bf540854e42f135e2f256abd29669fcd0da0f2dec79c2', 'd4d6fcde76f94f5cb9e43e9e9a61f16dacefd228cbbf6f1a09bd9b219a92f1a1', 'ddf4af30b417d9fe16481e9b81c27ab2a7cde1ff7ba3e85653b02db7d145dc7b', 'df115d4d83168fdf2cae48ef1ff6d1cb4c466364e30861b37121de0f3bf1b990', 'df7276909358e5635ae203673ab7e509ddd224225a8d6b0790bf13eb2bde1cc5', 'e4fd89cc178bced6ad29cb3e6dd4aa63fa5017c3524dbd0b25998fb64a87cc8b', 'e9701d0049d92c16703a42771b98d560b95248949f23f8cf7b4eddd201814fb9', 'ee2f2a527e3c1a6e6411eb4209642e138b544a2d72fe5d0d76daf77b24063534', 'f7fb7d750cfa0a070d2c24e831fd3481019a60dd317ea2b39acbcebc08b6ed81', 'f840ed6d8ecba8255df8c42b87fadeda98ddfc6eeec05e2dc66e26d46dd6f58a', 'f86c6358749bd4fda175388691e3ba8c46e24c5347d0afd20f9b7edfc9faf07d', 'fa36ec09ef71d158186bc79e359ff5fdd6e7996fe8ab638f00d6b93139ba4fcf', 'fe2c7201c642b7c308f1675355ad7ff7b66acfe3541625efe5a3ad38f29d6115', )), ('idna==3.18', ( '7f952cbe720b688055e3f87de14f5c3e5fdaa8bc3928985c4077ca689de849a2', )), ('urllib3==2.7.0', ( '9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897', )), ('certifi==2026.7.22', ( '62f22742b58a1a33014a2b6b706588a8d7e2a88ae7bd1a6ebe8c992928483775', )), ('psutil==7.2.2', ( '076a2d2f923fd4821644f5ba89f059523da90dc9014e85f8e45a5774ca5bc6f9', '11fe5a4f613759764e79c65cf11ebdf26e33d6dd34336f8a337aa2996d71c841', '1a571f2330c966c62aeda00dd24620425d4b0cc86881c89861fbc04549e5dc63', '1a7b04c10f32cc88ab39cbf606e117fd74721c831c98a27dc04578deb0c16979', '1fa4ecf83bcdf6e6c8f4449aff98eefb5d0604bf88cb883d7da3d8d2d909546a', '2edccc433cbfa046b980b0df0171cd25bcaeb3a68fe9022db0979e7aa74a826b', '7b6d09433a10592ce39b13d7be5a54fbac1d1228ed29abc880fb23df7cb694c9', '8c233660f575a5a89e6d4cb65d9f938126312bca76d8fe087b947b3a1aaac9ee', '917e891983ca3c1887b4ef36447b1e0873e70c933afc831c6b6da078ba474312', 'ab486563df44c17f5173621c7b198955bd6b613fb87c71c161f827d3fb149a9b', 'ae0aefdd8796a7737eccea863f80f81e468a1e4cf14d926bd9b6f5f2d5f90ca9', 'b0726cecd84f9474419d67252add4ac0cd9811b04d61123054b9fb6f57df6e9e', 'b58fabe35e80b264a4e3bb23e6b96f9e45a3df7fb7eed419ac0e5947c61e47cc', 'c7663d4e37f13e884d13994247449e9f8f574bc4655d509c3b95e9ec9e2b9dc1', 'e452c464a02e7dc7822a05d25db4cde564444a67e58539a00f929c51eddda0cf', 'e78c8603dcd9a04c7364f1a3e670cea95d51ee865e4efb3556a3a63adef958ea', 'eb7e81434c8d223ec4a219b5fc1c47d0417b12be7ea866e24fb5ad6e84b3d988', 'ed0cace939114f62738d808fdcecd4c869222507e266e574799e9c0faa17d486', 'eed63d3b4d62449571547b60578c5b2c4bcccc5387148db46e0c2313dad0ee00', 'fd04ef36b4a6d599bbdb225dd1d3f51e00105f6d48a28f006da7f9822f2606d8', )), ('waitress==3.0.2', ( 'c56d67fd6e87c2ee598b76abdd4e96cfad1f24cacdea5078d382b1f9d7b5ed2e', )), ('aiohttp==3.14.3', ( '03cd2bde3d7f085b64e549c985f4bb928cad7e8ecf5323bfca320db548d81b39', '041badb8f84396357c4d3ad26de6afd7a32b112f43d3c63045c0c8278cfd2043', '0a5ff2dfbb9ce645fa5b8ef3e02c6c0b9cc3f6030ff863d0c51fffc50cb5541b', '0fdea2281997af69da84c77ffa6f5938a0285f21fb3887c249d67419ca865b3d', '11fb37ef075669eee52ab1928fbf6e1741fada40409fa309ebde9607a962aebf', '134ac5ddcf61c6fad984b9a5727d83492ada43d63471db20fb73042c13fca62f', '152516815ef926786a0b6ae2b8f1fd2e0c71582dee0b435636865316fd4891b7', '1576145bdceeb92382d899751e12743a3a5b8e460a841e3e50543859e54864dc', '16100ad3ab8d649fdfbee87602d9d2dcdca9df0b9eda8a1b5fdc0d41f96da559', '16ea7e24c309fb7c0bbd505d149abe4fe4dccfb8db911db7dbec0921bc889a6f', '18c441d0a8fca6de8d1f546849b9f0ab20d435993e2c5b59562b2fae6be2f929', '18cb43369747b2ae007bd2655fb8e63a099c2ff1d207962943636dac989b3147', '1b59533861b70a2185c8f4f350f791f39d64358ef6944ce71c5240c9ec0982c9', '1c5281acc88b92396f88c7e1e2748f8466689df22b80170e4f51efa712fb47a8', '1c5ec8fb1bcc31a8466f74aaf26c345d5c386fa4bd08a3f0eb9c7a4a3fe8b5bf', '1caa7b0d05f3e3a36f87788c59e970a7ee1cefcfcbb924a9f138c4a6551c9cb7', '21c016079415ed3fd676963e9793700a566d85dbbd6bfc564b9b2d209147dcc8', '2498f0fe69ead802f9675beca44a7c21c62fdaa4ec5145ea1c3ad6edbee29f85', '25bd2708db6bdf6a6630dd37bdcdfcb47c4434d22ac69c64665b802910140b30', '270d3dace9ca2f10f0da5d8ebe519b7a310fc6112ed916e32df5866df0888553', '2e1161602f45a54de2ce0905243a95f58cb42dcd378402f3697f5e0b21e9d2e7', '2e9878ae68e4a5f1c0abe4dd497dbc3d51946f5837b56759e2a02e78fa90ef86', '30402d03a7c0ff52bce290b57e564e9079fd9d0cb545c8aba73f86a103162d2e', '33a2d7c28d33797a2e99923dffa63f83d908a19b6bf26cfe80fa790aa5e1a75a', '362a3fd481769cac1a824514bcd86fda51c65e8fe6e051099e008fddde6db17c', '38901a84da3ce22249f6e860bf8f90d141bcab7da090cc398f8bb58c0e44b7da', '39aded8c7f3b935b54aab1d8d73c70ec0ee2d3ec3b943e0e86611bc150ba47f5', '3a26434dafe408229ff3403458ca58de24fb51936504decac49ce6755f77e59d', '3ae5b3a59436d089b5395d910121a390feed4d00578eb95a0fd1a329fe963100', '3d4f72af88ac2474bb5bca640030320e3d38a0163a1d7533500e87be458eef71', '3f42e9b78301f11c8f861746175d8b9c1ccef713fcad9eab396e2f6db8ed4a22', '42a67efc36300d052fb4508a53e8b6901b9284b599ae63945c377569c5fcc1e1', '48d67b87db6279c044760787eb01f6413032c2e6f3ba1cafaa492b1c8e578479', '498c6c623134f8e09a3c4e60bcd607a0b4590dd7dbf08dd40851b27cbb520ccb', '49f7325beb0f85ef4aef5f48f490269575f83e6e2acad00a1d80b807eb027062', '4e3ac92d90e92773b2362d506068e9a948192bd553e743c5b2429e28527c8661', '530125ee1163c4219af35dc3aa1206e541e7b31b6efc1a3f93b70a136f65d427', '5373dc80ad1aa2fb9ad95c83f24eef418bbda3a61375f128e5b0192e4f3f9b32', '53e5179d8abb5710f8e83ba207c41c8d1261fcffd4616500e15ca2b7a33be10a', '53e7b4ce82b54a8bcc71b3b67a5cbd177ca1d7f592cbc92cd38b7349f73482db', '543906c127fb1d929b95076db19b83fa2d46751006ff1e23b093aa5ac4d8db42', '54cfcdee2770dac994417cbb0ee1f3eb0e7cb6b30c79bf44f2c02ff79ec5124a', '55bdcc472aafe2de4a253045cc128007a64f1e0264fb675791e132ea5edaa3bd', '56f355e79f71aef2a85c80305cc915f894b170dba76de5fe84f6351939b83c06', '5895ef58c4620afe02fa16044f023dc4dafec08158f9d08874a46a7dbc0341b8', '5bcb6ff3fdab1258a192679ff1a05d44f59626430aa05cd1a9d2447423599228', '5f08ec777f35ee70720233b8b9811d3bb5d728137f30ac91b7457709c3261ac0', '614c61d478b83953e261d02bb2df750f17227cd33ef8002945bf5aebbde21919', '617105e2c3018ee38d0c8ce5ee3c84f621a6d8b9f723202aacaff28449ca91ee', '6debfa7312ff9d4c124dc71d72e9a0a4b9e0879e48ba6fcb42bef5c3300289e2', '7041d52c3a7fa20c9e8c182b534704abb19502c8bdcbde7ab23bfda6f642394f', '70c987b27534f9ae1a723f47ae921571d616da21d3208282bf4c52af5164ac43', '74ab5b6a9fb13e873e5a90946588baecaf488745e1db1a4a5c433f971f035098', '78253b573e6ffab5028924fc98bc281aae05445969982a10864bc360dea2016c', '7a75aa63cbf9b21cfaf60dc2657e19df2c2867d91707d653fee171ffeedd1371', '8800c996b01c2772a783e3e46f3e1abd5823029adca0df54231960de9bfefa5b', '89176250f686cb9853c0fb7ead90e639e915b84a6f43eedc2a4e7ec21f1037f0', '8a5fd34f7f7410d1730d5c2ba873cacb2eed3fede366feb268a70ba22581ed8f', '8b3b60de05f3dcb6f6a00f818bb2ec781cee4de0645f59ccaf99b1d1823b6100', '8f2f1c4c032c7cedd7d8da6f54c97b70266c6570c3108d3fdffee7188bb70529', '9aa6e61fdf20105c4144e755bd586008ff450791d67b1c8146fdc15959c4d51c', '9d9edccfe496b476db5f398d97b865e9a6752bcf8aec4eef8390ce20fb64bb41', '9fc7b5bfec6573f3ae844f457fdde5adeb713f8b8e4a81ad64fc207b49383716', 'a0dc483c00da8b673abbb367eb6f8d8f4bcec30eb58529ea13cb42e7fd2dfa33', 'a3a8296e7ab5c295f53f1041487cb088e1480775aafbf7fe545d93b770a0f96f', 'a3e22975f905b89a55a488c2a08f2fdb2186175349e917d48985cc468a3d4c6e', 'a4af35c443e0b1a1bd6a8af3f3485d7fda15c142751a00f3ff8090f0b93346fa', 'a94dbaae5ae27bd849c93570669bff91e0510f33a80805738e3de72a7be0447b', 'ac74facc01463f138b0da5580329cfcc82818dea5656e83ddcd11268fc12ff80', 'ad4c8b7488d745d2ca4838ebd8ae5ba9b56341d30b1da43640e4ce87f9f49646', 'b014a6ed7cf912e787149fdc529166d3ceabac23f26efeea3158c9aba2354e7e', 'b20032766aedf6261c7a566585a40867d092ac03a0d81592d5370ef9b054f99b', 'b2466434105a4e03113c36ec775cc2ebe6676b62eae326fa670bb607ef788c1c', 'b304db572b4368edd8dda8a2274f73156fe15558fca4a917cb8a09fc47af5963', 'ba59d59aba08ac02fc03b0c8983ccd5ee39a199d0552ce9e6d2b4845b34d59ae', 'bd52f811e65f6fb634b1047159657c98f52b407f8efec907bcfc09da9a4c0a25', 'bdd0e2834dce1a26c1bbe26464861e16bbe217042cbff619247c11594472518c', 'c23ec8ee9d5ab2f5421f9c7fffce208435607af27fd46d4a44e031954352838f', 'c39846c3aad97a8530c89d7a3869a8f8e9e3762c6ac0504481e5c80948f7e807', 'c3c200cf9757edd785051dc699c7ecbec22110dbfcb3fefc7a9f9695eda8ea7a', 'c7d3a97c678d34fc5b59da671ee9cd630096ddc643e7b5a30d54a2a6f3574d3f', 'c8653fd547c93a61aadc612007790f5555cdd18946fa48cf45e26d8ea4ea473d', 'cc7cb243a68167172f48c1fd43cee91ec4b1d40cefd190edd43369d1a6bc9c82', 'ccd4893707b3e2a13e39c90d43cf80edf2e4d0457935bcc103bf2346214c3f15', 'cd817772b2fcf2b8c0905795318485f9ec16eae60b29feb7f4c77085311637f0', 'cda5fd5c95ad7a125a2e8464acc78b98b94c475a3780d6aa0aa157c93f470f4d', 'cef89a58e628c4efcac3275c2d68083f82426dcdc89c1492a6f654f9f7ea6ab9', 'd1558173930a5a8d3069cee5c92fc91c87c4dbcb099debbb3622053717145a19', 'd6088ec9894113802bddb3c09e974929aed2c7b3a8c456219b8aab4481f1a239', 'd6218d92e450824e9b4881f44e8c09f1853b490f9a64130801024a4793b1b3b0', 'd77640cc618c1d99fc4f8589c0f24a730adfa54eb1e57ef7bf0c8dfb78da898c', 'd7d2deec16eeedf55f2c7cf75b521ea3856a5177e123844f8fd0f114ce252cb5', 'db332af25642007330fca8be5c4d194caf2bea7a7fc84415aff3497af5dfee6b', 'dd54d0e8717de95939766febac482ac0474d8ac3b048115f9f2b1d23a16e7db4', 'ddcac3c6b382e81f1dd0499199d4136b877beb4cb5ef770bbbfba56c4b8f55d2', 'df82f3787c940c94986b34222d59c9e38843fba85139f36e85255a82ad5355a9', 'dfa68deb2a443bdaa3ea5297b0699c1464f08aef3812b486d1348eee61b07dc0', 'dff9461ec275f22135650d5ba4b4931a11f3958df7dfbb8db630000d4dee0883', 'e1e74298bab6ee0d6e749ed4fd1901c7e604bdda32c03d787a2cc71c46d0433d', 'e2667f0bbe7eb6c74eae5e9691441ad186e5845ca3cff63230fc09c4e7514f5d', 'e3be98a7c30b8c25d573dafba7171d66dfb05ee6a9070fc46535464ff97700a6', 'e568e14940c09955aa51f4e645b6daa18a581c5dcfcd73744dcc86a856e3ced3', 'e72ee89e28d907a18f46959b4eb0bb06701cc7f8cf4366e00029e2ccfaaf5924', 'e92eb8acc45eb6a9f4935071a77edf5b85cc6f8dfad5cd99e97653c26593cdde', 'ea05e1f97ceea523942d9b2a7d7c0359d781d683d6b043f5943a602b14da4787', 'eac645b09bcfdf73df7536331f0678c1086ea250981118ddb5199e17ccef72bb', 'eb0495d778817619273c108784292be161a924b9f5ae5cbbc70a2caa6838250b', 'ebe8e504f058fe91223351cecd2d9d6946c9d241bb0250d898ffbdf584cc72b0', 'ed099d105449c4f9e84f24af203cd131349d4761d8813fa7e02c32e7128cd910', 'f0f177d1b195b9e06376cfd7d308d8a1b920909a609d03ac82a8c73bbb16d3b9', 'f3d2669fe7dec7fc359ecdb5984b29b50d85d5d00f8c1cb61de4f4a24ee42627', 'f4e05329faa0ea1a404b37de4f034fd2c2defcca06a68dc6745e4e56c88e8a48', 'f53bcd52f585e1ac3e590d61434eb61f9a88c38df041b4ea126d97144344a77b', 'f55119f7bf25f49ed210f6096090715da24f2943c62102448915fde3c62877ce', 'f631fe87a6f30df5fbe6d79640b25e4cffb38c31c7fb6f10871517b84b0f8c1a', 'f8fb78a83c9e5f741ca3a68cfb455c1f5bb83b4e7249a3848b3cd78d0a8563b0', 'fa9467a8113aa69d3d7c55a70ef0b7c636010a40993f3df9d9d0d73b3eb7ef24', 'fd51ebf9d3a00c074df4ede271023f4d2dba289bcc740b88191872716014e3c5', )), ('aiohappyeyeballs==2.7.1', ( '9243213661e29250eb41368e5daa826fc017156c3b8a11440826b2e3ed376472', )), ('aiosignal==1.4.0', ( '053243f8b92b990551949e63930a839ff0cf0b0ebbe0597b0f3fb19e1a0fe82e', )), ('attrs==26.1.0', ( 'c647aa4a12dfbad9333ca4e71fe62ddc36f4e63b2d260a37a8b83d2f043ac309', )), ('frozenlist==1.8.0', ( '0325024fe97f94c41c08872db482cf8ac4800d80e79222c6b0b7b162d5b13686', '032efa2674356903cd0261c4317a561a6850f3ac864a63fc1583147fb05a79b0', '03ae967b4e297f58f8c774c7eabcce57fe3c2434817d4385c50661845a058121', '06be8f67f39c8b1dc671f5d83aaefd3358ae5cdcf8314552c57e7ed3e6475bdd', '073f8bf8becba60aa931eb3bc420b217bb7d5b8f4750e6f8b3be7f3da85d38b7', '07cdca25a91a4386d2e76ad992916a85038a9b97561bf7a3fd12d5d9ce31870c', '09474e9831bc2b2199fad6da3c14c7b0fbdd377cce9d3d77131be28906cb7d84', '0c18a16eab41e82c295618a77502e17b195883241c563b00f0aa5106fc4eaa0d', '0f96534f8bfebc1a394209427d0f8a63d343c9779cda6fc25e8e121b5fd8555b', '102e6314ca4da683dca92e3b1355490fed5f313b768500084fbe6371fddfdb79', '11847b53d722050808926e785df837353bd4d75f1d494377e59b23594d834967', '119fb2a1bd47307e899c2fac7f28e85b9a543864df47aa7ec9d3c1b4545f096f', '13d23a45c4cebade99340c4165bd90eeb4a56c6d8a9d8aa49568cac19a6d0dc4', '154e55ec0655291b5dd1b8731c637ecdb50975a2ae70c606d100750a540082f7', '168c0969a329b416119507ba30b9ea13688fafffac1b7822802537569a1cb0ef', '17c883ab0ab67200b5f964d2b9ed6b00971917d5d8a92df149dc2c9779208ee9', '1a7607e17ad33361677adcd1443edf6f5da0ce5e5377b798fba20fae194825f3', '1a7fa382a4a223773ed64242dbe1c9c326ec09457e6b8428efb4118c685c3dfd', '1aa77cb5697069af47472e39612976ed05343ff2e84a3dcf15437b232cbfd087', '1b9290cf81e95e93fdf90548ce9d3c1211cf574b8e3f4b3b7cb0537cf2227068', '20e63c9493d33ee48536600d1a5c95eefc870cd71e7ab037763d1fbb89cc51e7', '21900c48ae04d13d416f0e1e0c4d81f7931f73a9dfa0b7a8746fb2fe7dd970ed', '229bf37d2e4acdaf808fd3f06e854a4a7a3661e871b10dc1f8f1896a3b05f18b', '2552f44204b744fba866e573be4c1f9048d6a324dfe14475103fd51613eb1d1f', '27c6e8077956cf73eadd514be8fb04d77fc946a7fe9f7fe167648b0b9085cc25', '28bd570e8e189d7f7b001966435f9dac6718324b5be2990ac496cf1ea9ddb7fe', '294e487f9ec720bd8ffcebc99d575f7eff3568a08a253d1ee1a0378754b74143', '29548f9b5b5e3460ce7378144c3010363d8035cea44bc0bf02d57f5a685e084e', '2c5dcbbc55383e5883246d11fd179782a9d07a986c40f49abe89ddf865913930', '2dc43a022e555de94c3b68a4ef0b11c4f747d12c024a520c7101709a2144fb37', '2f05983daecab868a31e1da44462873306d3cbfd76d1f0b5b69c473d21dbb128', '33139dc858c580ea50e7e60a1b0ea003efa1fd42e6ec7fdbad78fff65fad2fd2', '332db6b2563333c5671fecacd085141b5800cb866be16d5e3eb15a2086476675', '33f48f51a446114bc5d251fb2954ab0164d5be02ad3382abcbfe07e2531d650f', '34187385b08f866104f0c0617404c8eb08165ab1272e884abc89c112e9c00746', '342c97bf697ac5480c0a7ec73cd700ecfa5a8a40ac923bd035484616efecc2df', '3462dd9475af2025c31cc61be6652dfa25cbfb56cbbf52f4ccfe029f38decaf8', '39ecbc32f1390387d2aa4f5a995e465e9e2f79ba3adcac92d68e3e0afae6657c', '3e0761f4d1a44f1d1a47996511752cf3dcec5bbdd9cc2b4fe595caf97754b7a0', '3ef2d026f16a2b1866e1d86fc4e1291e1ed8a387b2c333809419a2f8b3a77b82', '405e8fe955c2280ce66428b3ca55e12b3c4e9c336fb2103a4937e891c69a4a29', '42145cd2748ca39f32801dad54aeea10039da6f86e303659db90db1c4b614c8c', '4314debad13beb564b708b4a496020e5306c7333fa9a3ab90374169a20ffab30', '433403ae80709741ce34038da08511d4a77062aa924baf411ef73d1146e74faf', '44389d135b3ff43ba8cc89ff7f51f5a0bb6b63d829c8300f79a2fe4fe61bcc62', '48e6d3f4ec5c7273dfe83ff27c91083c6c9065af655dc2684d2c200c94308bb5', '494a5952b1c597ba44e0e78113a7266e656b9794eec897b19ead706bd7074383', '4970ece02dbc8c3a92fcc5228e36a3e933a01a999f7094ff7c23fbd2beeaa67c', '4e0c11f2cc6717e0a741f84a527c52616140741cd812a50422f83dc31749fb52', '50066c3997d0091c411a66e710f4e11752251e6d2d73d70d8d5d4c76442a199d', '517279f58009d0b1f2e7c1b130b377a349405da3f7621ed6bfae50b10adf20c1', '54b2077180eb7f83dd52c40b2750d0a9f175e06a42e3213ce047219de902717a', '5500ef82073f599ac84d888e3a8c1f77ac831183244bfd7f11eaa0289fb30714', '581ef5194c48035a7de2aefc72ac6539823bb71508189e5de01d60c9dcd5fa65', '59a6a5876ca59d1b63af8cd5e7ffffb024c3dc1e9cf9301b21a2e76286505c95', '5a3a935c3a4e89c733303a2d5a7c257ea44af3a56c8202df486b7f5de40f37e1', '5c1c8e78426e59b3f8005e9b19f6ff46e5845895adbde20ece9218319eca6506', '5d63a068f978fc69421fb0e6eb91a9603187527c86b7cd3f534a5b77a592b888', '667c3777ca571e5dbeb76f331562ff98b957431df140b54c85fd4d52eea8d8f6', '6da155091429aeba16851ecb10a9104a108bcd32f6c1642867eadaee401c1c41', '6dc4126390929823e2d2d9dc79ab4046ed74680360fc5f38b585c12c66cdf459', '7398c222d1d405e796970320036b1b563892b65809d9e5261487bb2c7f7b5c6a', '74c51543498289c0c43656701be6b077f4b265868fa7f8a8859c197006efb608', '776f352e8329135506a1d6bf16ac3f87bc25b28e765949282dcc627af36123aa', '778a11b15673f6f1df23d9586f83c4846c471a8af693a22e066508b77d201ec8', '78f7b9e5d6f2fdb88cdde9440dc147259b62b9d3b019924def9f6478be254ac1', '799345ab092bee59f01a915620b5d014698547afd011e691a208637312db9186', '7bf6cdf8e07c8151fba6fe85735441240ec7f619f935a5205953d58009aef8c6', '8009897cdef112072f93a0efdce29cd819e717fd2f649ee3016efd3cd885a7ed', '80f85f0a7cc86e7a54c46d99c9e1318ff01f4687c172ede30fd52d19d1da1c8e', '8585e3bb2cdea02fc88ffa245069c36555557ad3609e83be0ec71f54fd4abb52', '878be833caa6a3821caf85eb39c5ba92d28e85df26d57afb06b35b2efd937231', '8a76ea0f0b9dfa06f254ee06053d93a600865b3274358ca48a352ce4f0798450', '8b7b94a067d1c504ee0b16def57ad5738701e4ba10cec90529f13fa03c833496', '8d92f1a84bb12d9e56f818b3a746f3efba93c1b63c8387a73dde655e1e42282a', '908bd3f6439f2fef9e85031b59fd4f1297af54415fb60e4254a95f75b3cab3f3', '92db2bf818d5cc8d9c1f1fc56b897662e24ea5adb36ad1f1d82875bd64e03c24', '940d4a017dbfed9daf46a3b086e1d2167e7012ee297fef9e1c545c4d022f5178', '957e7c38f250991e48a9a73e6423db1bb9dd14e722a10f6b8bb8e16a0f55f695', '96153e77a591c8adc2ee805756c61f59fef4cf4073a9275ee86fe8cba41241f7', '96f423a119f4777a4a056b66ce11527366a8bb92f54e541ade21f2374433f6d4', '97260ff46b207a82a7567b581ab4190bd4dfa09f4db8a8b49d1a958f6aa4940e', '974b28cf63cc99dfb2188d8d222bc6843656188164848c4f679e63dae4b0708e', '9ff15928d62a0b80bb875655c39bf517938c7d589554cbd2669be42d97c2cb61', 'a6483e309ca809f1efd154b4d37dc6d9f61037d6c6a81c2dc7a15cb22c8c5dca', 'a88f062f072d1589b7b46e951698950e7da00442fc1cacbe17e19e025dc327ad', 'ac913f8403b36a2c8610bbfd25b8013488533e71e62b4b4adce9c86c8cea905b', 'adbeebaebae3526afc3c96fad434367cafbfd1b25d72369a9e5858453b1bb71a', 'b2a095d45c5d46e5e79ba1e5b9cb787f541a8dee0433836cea4b96a2c439dcd8', 'b3210649ee28062ea6099cfda39e147fa1bc039583c8ee4481cb7811e2448c51', 'b37f6d31b3dcea7deb5e9696e529a6aa4a898adc33db82da12e4c60a7c4d2011', 'b4dec9482a65c54a5044486847b8a66bf10c9cb4926d42927ec4e8fd5db7fed8', 'b4f3b365f31c6cd4af24545ca0a244a53688cad8834e32f56831c4923b50a103', 'b6db2185db9be0a04fecf2f241c70b63b1a242e2805be291855078f2b404dd6b', 'b9be22a69a014bc47e78072d0ecae716f5eb56c15238acca0f43d6eb8e4a5bda', 'bac9c42ba2ac65ddc115d930c78d24ab8d4f465fd3fc473cdedfccadb9429806', 'bf0a7e10b077bf5fb9380ad3ae8ce20ef919a6ad93b4552896419ac7e1d8e042', 'c23c3ff005322a6e16f71bf8692fcf4d5a304aaafe1e262c98c6d4adc7be863e', 'c4c800524c9cd9bac5166cd6f55285957fcfc907db323e193f2afcd4d9abd69b', 'c7366fe1418a6133d5aa824ee53d406550110984de7637d65a178010f759c6ef', 'c8d1634419f39ea6f5c427ea2f90ca85126b54b50837f31497f3bf38266e853d', 'c9a63152fe95756b85f31186bddf42e4c02c6321207fd6601a1c89ebac4fe567', 'cb89a7f2de3602cfed448095bab3f178399646ab7c61454315089787df07733a', 'cba69cb73723c3f329622e34bdbf5ce1f80c21c290ff04256cff1cd3c2036ed2', 'cee686f1f4cadeb2136007ddedd0aaf928ab95216e7691c63e50a8ec066336d0', 'cf253e0e1c3ceb4aaff6df637ce033ff6535fb8c70a764a8f46aafd3d6ab798e', 'd1eaff1d00c7751b7c6662e9c5ba6eb2c17a2306ba5e2a37f24ddf3cc953402b', 'd3bb933317c52d7ea5004a1c442eef86f426886fba134ef8cf4226ea6ee1821d', 'd4d3214a0f8394edfa3e303136d0575eece0745ff2b47bd2cb2e66dd92d4351a', 'd6a5df73acd3399d893dafc71663ad22534b5aa4f94e8a2fabfe856c3c1b6a52', 'd8b7138e5cd0647e4523d6685b0eac5d4be9a184ae9634492f25c6eb38c12a47', 'db1e72ede2d0d7ccb213f218df6a078a9c09a7de257c2fe8fcef16d5925230b1', 'e25ac20a2ef37e91c1b39938b591457666a0fa835c7783c3a8f33ea42870db94', 'e2de870d16a7a53901e41b64ffdf26f2fbb8917b3e6ebf398098d72c5b20bd7f', 'e4a3408834f65da56c83528fb52ce7911484f0d1eaf7b761fc66001db1646eff', 'eaa352d7047a31d87dafcacbabe89df0aa506abb5b1b85a2fb91bc3faa02d822', 'eab8145831a0d56ec9c4139b6c3e594c7a83c2c8be25d5bcf2d86136a532287a', 'ec3cc8c5d4084591b4237c0a272cc4f50a5b03396a47d9caaf76f5d7b38a4f11', 'edee74874ce20a373d62dc28b0b18b93f645633c2943fd90ee9d898550770581', 'eefdba20de0d938cec6a89bd4d70f346a03108a19b9df4248d3cf0d88f1b0f51', 'ef2b7b394f208233e471abc541cc6991f907ffd47dc72584acee3147899d6565', 'f21f00a91358803399890ab167098c131ec2ddd5f8f5fd5fe9c9f2c6fcd91e40', 'f4be2e3d8bc8aabd566f8d5b8ba7ecc09249d74ba3c9ed52e54dc23a293f0b92', 'f57fb59d9f385710aa7060e89410aeb5058b99e62f4d16b08b91986b9a2140c2', 'f6292f1de555ffcc675941d65fffffb0a5bcd992905015f85d0592201793e0e5', 'f833670942247a14eafbb675458b4e61c82e002a148f49e68257b79296e865c4', 'fa47e444b8ba08fffd1c18e8cdb9a75db1b6a27f17507522834ad13ed5922b93', 'fb30f9626572a76dfe4293c7194a09fb1fe93ba94c7d4f720dfae3b646b45027', 'fe3c58d2f5db5fbd18c2987cba06d51b0529f52bc3a6cdc33d3f4eab725104bd', )), ('multidict==6.7.1', ( '026d264228bcd637d4e060844e39cdc60f86c479e463d49075dedc21b18fbbe0', '03ede2a6ffbe8ef936b92cb4529f27f42be7f56afcdab5ab739cd5f27fb1cbf9', '0458c978acd8e6ea53c81eefaddbbee9c6c5e591f41b3f5e8e194780fe026581', '067343c68cd6612d375710f895337b3a98a033c94f14b9a99eff902f205424e2', '08ccb2a6dc72009093ebe7f3f073e5ec5964cba9a706fa94b1a1484039b87941', '0b38ebffd9be37c1170d33bc0f36f4f262e0a09bc1aac1c34c7aa51a7293f0b3', '0b4c48648d7649c9335cf1927a8b87fa692de3dcb15faa676c6a6f1f1aabda43', '0d17522c37d03e85c8098ec8431636309b2682cf12e58f4dbc76121fb50e4962', '0e161ddf326db5577c3a4cc2d8648f81456e8a20d40415541587a71620d7a7d1', '0e697826df7eb63418ee190fd06ce9f1803593bb4b9517d08c60d9b9a7f69d8f', '10ae39c9cfe6adedcdb764f5e8411d4a92b055e35573a2eaa88d3323289ef93c', '121a34e5bfa410cdf2c8c49716de160de3b1dbcd86b49656f5681e4543bcd1a8', '128441d052254f42989ef98b7b6a6ecb1e6f708aa962c7984235316db59f50fa', '12fad252f8b267cc75b66e8fc51b3079604e8d43a75428ffe193cd9e2195dfd6', '14525a5f61d7d0c94b368a42cff4c9a4e7ba2d52e2672a7b23d84dc86fb02b0c', '17207077e29342fdc2c9a82e4b306f1127bf1ea91f8b71e02d4798a70bb99991', '17307b22c217b4cf05033dabefe68255a534d637c6c9b0cc8382718f87be4262', '1b99af4d9eec0b49927b4402bcbb58dea89d3e0db8806a4086117019939ad3dd', '1d540e51b7e8e170174555edecddbd5538105443754539193e3e1061864d444d', '1e3a8bb24342a8201d178c3b4984c26ba81a577c80d4d525727427460a50c22d', '1fa6609d0364f4f6f58351b4659a1f3e0e898ba2a8c5cac04cb2c7bc556b0bc5', '21f830fe223215dffd51f538e78c172ed7c7f60c9b96a2bf05c4848ad49921c3', '233b398c29d3f1b9676b4b6f75c518a06fcb2ea0b925119fb2c1bc35c05e1601', '24c0cf81544ca5e17cfcb6e482e7a82cd475925242b308b890c9452a074d4505', '25167cc263257660290fba06b9318d2026e3c910be240a146e1f66dd114af2b0', '253282d70d67885a15c8a7716f3a73edf2d635793ceda8173b9ecc21f2fb8292', '273d23f4b40f3dce4d6c8a821c741a86dec62cded82e1175ba3d99be128147ed', '283ddac99f7ac25a4acadbf004cb5ae34480bbeb063520f70ce397b281859362', '28ca5ce2fd9716631133d0e9a9b9a745ad7f60bac2bccafb56aa380fc0b6c511', '2b41f5fed0ed563624f1c17630cb9941cf2309d4df00e494b551b5f3e3d67a23', '2bbd113e0d4af5db41d5ebfe9ccaff89de2120578164f86a5d17d5a576d1e5b2', '2e1425e2f99ec5bd36c15a01b690a1a2456209c5deed58f95469ffb46039ccbb', '2e2d2ed645ea29f31c4c7ea1552fcfd7cb7ba656e1eafd4134a6620c9f5fdd9e', '3758692429e4e32f1ba0df23219cd0b4fc0a52f476726fff9337d1a57676a582', '38fb49540705369bab8484db0689d86c0a33a0a9f2c1b197f506b71b4b6c19b0', '3943debf0fbb57bdde5901695c11094a9a36723e5c03875f87718ee15ca2f4d2', '398c1478926eca669f2fd6a5856b6de9c0acf23a2cb59a14c0ba5844fa38077e', '3ab8b9d8b75aef9df299595d5388b14530839f6422333357af1339443cff777d', '3bd231490fa7217cc832528e1cd8752a96f0125ddd2b5749390f7c3ec8721b65', '3d51ff4785d58d3f6c91bdbffcb5e1f7ddfda557727043aa20d20ec4f65e324a', '3fccb473e87eaa1382689053e4a4618e7ba7b9b9b8d6adf2027ee474597128cd', '401c5a650f3add2472d1d288c26deebc540f99e2fb83e9525007a74cd2116f1d', '41f2952231456154ee479651491e94118229844dd7226541788be783be2b5108', '432feb25a1cb67fe82a9680b4d65fb542e4635cb3166cd9c01560651ad60f177', '439cbebd499f92e9aa6793016a8acaa161dfa749ae86d20960189f5398a19144', '4885cb0e817aef5d00a2e8451d4665c1808378dc27c2705f1bf4ef8505c0d2e5', '497394b3239fc6f0e13a78a3e1b61296e72bf1c5f94b4c4eb80b265c37a131cd', '497bde6223c212ba11d462853cfa4f0ae6ef97465033e7dc9940cdb3ab5b48e5', '4cfb48c6ea66c83bcaaf7e4dfa7ec1b6bbcf751b7db85a328902796dfde4c060', '538cec1e18c067d0e6103aa9a74f9e832904c957adc260e61cd9d8cf0c3b3d37', '55d97cc6dae627efa6a6e548885712d4864b81110ac76fa4e534c03819fa4a56', '563fe25c678aaba333d5399408f5ec3c383ca5b663e7f774dd179a520b8144df', '57b46b24b5d5ebcc978da4ec23a819a9402b4228b8a90d9c656422b4bdd8a963', '5884a04f4ff56c6120f6ccf703bdeb8b5079d808ba604d4d53aec0d55dc33568', '59bc83d3f66b41dac1e7460aac1d196edc70c9ba3094965c467715a70ecb46db', '5a37ca18e360377cfda1d62f5f382ff41f2b8c4ccb329ed974cc2e1643440118', '5c4b9bfc148f5a91be9244d6264c53035c8a0dcd2f51f1c3c6e30e30ebaa1c84', '5e01429a929600e7dab7b166062d9bb54a5eed752384c7384c968c2afab8f50f', '5fa6a95dfee63893d80a34758cd0e0c118a30b8dcb46372bf75106c591b77889', '619e5a1ac57986dbfec9f0b301d865dddf763696435e2962f6d9cf2fdff2bb71', '65573858d27cdeaca41893185677dc82395159aa28875a8867af66532d413a8f', '6704fa2b7453b2fb121740555fa1ee20cd98c4d011120caf4d2b8d4e7c76eec0', '6aac4f16b472d5b7dc6f66a0d49dd57b0e0902090be16594dc9ebfd3d17c47e7', '6b10359683bd8806a200fd2909e7c8ca3a7b24ec1d8132e483d58e791d881048', '6b83cabdc375ffaaa15edd97eb7c0c672ad788e2687004990074d7d6c9b140c8', '6d3bc717b6fe763b8be3f2bee2701d3c8eb1b2a8ae9f60910f1b2860c82b6c49', '6f77ce314a29263e67adadc7e7c1bc699fcb3a305059ab973d038f87caa42ed0', '749aa54f578f2e5f439538706a475aa844bfa8ef75854b1401e6e528e4937cf9', '7a7e590ff876a3eaf1c02a4dfe0724b6e69a9e9de6d8f556816f29c496046e59', '7dfb78d966b2c906ae1d28ccf6e6712a3cd04407ee5088cd276fe8cb42186190', '7eee46ccb30ff48a1e35bb818cc90846c6be2b68240e42a78599166722cea709', '7ff981b266af91d7b4b3793ca3382e53229088d193a85dfad6f5f4c27fc73e5d', '841189848ba629c3552035a6a7f5bf3b02eb304e9fea7492ca220a8eda6b0e5c', '844c5bca0b5444adb44a623fb0a1310c2f4cd41f402126bb269cd44c9b3f3e1e', '84e61e3af5463c19b67ced91f6c634effb89ef8bfc5ca0267f954451ed4bb6a2', '8affcf1c98b82bc901702eb73b6947a1bfa170823c153fe8a47b5f5f02e48e40', '8be1802715a8e892c784c0197c2ace276ea52702a0ede98b6310c8f255a5afb3', '8f333ec9c5eb1b7105e3b84b53141e66ca05a19a605368c55450b6ba208cb9ee', '9004d8386d133b7e6135679424c91b0b854d2d164af6ea3f289f8f2761064609', '90efbcf47dbe33dcf643a1e400d67d59abeac5db07dc3f27d6bdeae497a2198c', '935434b9853c7c112eee7ac891bc4cb86455aa631269ae35442cb316790c1445', '93b1818e4a6e0930454f0f2af7dfce69307ca03cdcfb3739bf4d91241967b6c1', '95922cee9a778659e91db6497596435777bd25ed116701a4c034f8e46544955a', '960c83bf01a95b12b08fd54324a4eb1d5b52c88932b5cba5d6e712bb3ed12eb5', '97231140a50f5d447d3164f994b86a0bed7cd016e2682f8650d6a9158e14fd31', '974e72a2474600827abaeda71af0c53d9ebbc3c2eb7da37b37d7829ae31232d8', '97891f3b1b3ffbded884e2916cacf3c6fc87b66bb0dde46f7357404750559f33', '98655c737850c064a65e006a3df7c997cd3b220be4ec8fe26215760b9697d4d7', '98bc624954ec4d2c7cb074b8eefc2b5d0ce7d482e410df446414355d158fe4ca', '98c5787b0a0d9a41d9311eae44c3b76e6753def8d8870ab501320efe75a6a5f8', '9b0d9b91d1aa44db9c1f1ecd0d9d2ae610b2f4f856448664e01a3b35899f3f92', '9c90fed18bffc0189ba814749fdcc102b536e83a9f738a9003e569acd540a733', '9d624335fd4fa1c08a53f8b4be7676ebde19cd092b3895c421045ca87895b429', '9f9af11306994335398293f9958071019e3ab95e9a707dc1383a35613f6abcb9', 'a0543217a6a017692aa6ae5cc39adb75e587af0f3a82288b1492eb73dd6cc2a4', 'a088b62bd733e2ad12c50dad01b7d0166c30287c166e137433d3b410add807a6', 'a407f13c188f804c759fc6a9f88286a565c242a76b27626594c133b82883b5c2', 'a90f75c956e32891a4eda3639ce6dd86e87105271f43d43442a3aedf3cddf172', 'a9fc4caa29e2e6ae408d1c450ac8bf19892c5fca83ee634ecd88a53332c59981', 'aa23b001d968faef416ff70dc0f1ab045517b9b42a90edd3e9bcdb06479e31d5', 'ac1c665bad8b5d762f5f85ebe4d94130c26965f11de70c708c75671297c776de', 'af959b9beeb66c822380f222f0e0a1889331597e81f1ded7f374f3ecb0fd6c52', 'b0fa96985700739c4c7853a43c0b3e169360d6855780021bfc6d0f1ce7c123e7', 'b26684587228afed0d50cf804cc71062cc9c1cdf55051c4c6345d372947b268c', 'b4938326284c4f1224178a560987b6cf8b4d38458b113d9b8c1db1a836e640a2', 'b8c990b037d2fff2f4e33d3f21b9b531c5745b33a49a7d6dbe7a177266af44f6', 'ba0a9fb644d0c1a2194cf7ffb043bd852cea63a57f66fbd33959f7dae18517bf', 'bb08271280173720e9fea9ede98e5231defcbad90f1624bea26f32ec8a956e2f', 'bdbf9f3b332abd0cdb306e7c2113818ab1e922dc84b8f8fd06ec89ed2a19ab8b', 'bfde23ef6ed9db7eaee6c37dcec08524cb43903c60b285b172b6c094711b3961', 'c0abd12629b0af3cf590982c0b413b1e7395cd4ec026f30986818ab95bfaa94a', 'c102791b1c4f3ab36ce4101154549105a53dc828f016356b3e3bcae2e3a039d3', 'c3a32d23520ee37bf327d1e1a656fec76a2edd5c038bf43eddfa0572ec49c60b', 'c524c6fb8fc342793708ab111c4dbc90ff9abd568de220432500e47e990c0358', 'c5f0c21549ab432b57dcc82130f388d84ad8179824cc3f223d5e7cfbfd4143f6', 'c6b3228e1d80af737b72925ce5fb4daf5a335e49cd7ab77ed7b9fdfbf58c526e', 'c76c4bec1538375dad9d452d246ca5368ad6e1c9039dadcf007ae59c70619ea1', 'c9035dde0f916702850ef66460bc4239d89d08df4d02023a5926e7446724212c', 'c93c3db7ea657dd4637d57e74ab73de31bccefe144d3d4ce370052035bc85fb5', 'cb2a55f408c3043e42b40cc8eecd575afa27b7e0b956dfb190de0f8499a57a53', 'cdea2e7b2456cfb6694fb113066fd0ec7ea4d67e3a35e1f4cbeea0b448bf5872', 'ce1bbd7d780bb5a0da032e095c951f7014d6b0a205f8318308140f1a6aba159e', 'cf37cbe5ced48d417ba045aca1b21bafca67489452debcde94778a576666a1df', 'd4f49cb5661344764e4c7c7973e92a47a59b8fc19b6523649ec9dc4960e58a03', 'd54ecf9f301853f2c5e802da559604b3e95bb7a3b01a9c295c6ee591b9882de8', 'd62b7f64ffde3b99d06b707a280db04fb3855b55f5a06df387236051d0668f4a', 'd82dd730a95e6643802f4454b8fdecdf08667881a9c5670db85bc5a56693f122', 'da62917e6076f512daccfbbde27f46fed1c98fee202f0559adec8ee0de67f71a', 'dd96c01a9dcd4889dcfcf9eb5544ca0c77603f239e3ffab0524ec17aea9a93ee', 'df9f19c28adcb40b6aae30bbaa1478c389efd50c28d541d76760199fc1037c32', 'e1c5988359516095535c4301af38d8a8838534158f649c05dd1050222321bcb3', 'e628ef0e6859ffd8273c69412a2465c4be4a9517d07261b33334b5ec6f3c7489', 'e82d14e3c948952a1a85503817e038cba5905a3352de76b9a465075d072fba23', 'e954b24433c768ce78ab7929e84ccf3422e46deb45a4dc9f93438f8217fa2d34', 'eb0ce7b2a32d09892b3dd6cc44877a0d02a33241fafca5f25c8b6b62374f8b75', 'eb304767bca2bb92fb9c5bd33cedc95baee5bb5f6c88e63706533a1c06ad08c8', 'eb351f72c26dc9abe338ca7294661aa22969ad8ffe7ef7d5541d19f368dc854a', 'f2a0a924d4c2e9afcd7ec64f9de35fcd96915149b2216e1cb2c10a56df483855', 'f33dc2a3abe9249ea5d8360f969ec7f4142e7ac45ee7014d8f8d5acddf178b7b', 'f537b55778cd3cbee430abe3131255d3a78202e0f9ea7ffc6ada893a4bcaeea4', 'f5dd81c45b05518b9aa4da4aa74e1c93d715efa234fd3e8a179df611cc85e5f4', 'f99fe611c312b3c1c0ace793f92464d8cd263cc3b26b5721950d977b006b6c4d', 'fa263a02f4f2dd2d11a7b1bb4362aa7cb1049f84a9235d31adf63f30143469a0', 'fc5907494fccf3e7d3f94f95c91d6336b092b5fc83811720fae5e2765890dfba', 'fcee94dfbd638784645b066074b338bc9cc155d4b4bffa4adce1615c5a426c19', )), ('propcache==0.5.2', ( '04dc2390d9edbbaef7461f33322555976ffddf0b650a038649d026358714e6c5', '06187263ddad280d05b4d8a8b3bb7d164cbebd469236544a42e6d9b28ac6a4fa', '0958834041a0166d343b8d2cedcd8bcbaeb4fdbe0cf08320c5379f143c3be6e7', '099aaf4b4d1a02265b92a977edf00b5c4f63b3b17ac6de39b0d637c9cac0188a', '0d2c9bf8528f135dbb805ce027567e09164f7efa51a2be07458a2c0420f292d0', '0fd59b5af35f74da48d905dcbad55449ba13be91823cb05a9bd590bbf5b61660', '10734b5484ea113152ee25a91dccedf81631791805d2c9ccb054958e51842c94', '13fef48778b5a2a756523fdb781326b028ca75e32858b04f2cdd19f394564917', '178b4a2cdaac1818e2bf1c5a99b94383fa73ea5382e032a48dec07dc5668dc42', '196913dea116aeb5a2ba95af4ddcb7ea85559ae07d8eee8751688310d09168c3', '1b31822f4474c4036bae62de9402710051d431a606d6a0f907fec79935a071aa', '1ca071adabaab6e9219924bbe00af821f1ee7de113a9eca1cdc292de3d120f4d', '1d1ad32d9d4355e2be65574fd0bfd3677e7066b009cd5b9b2dee8aa6a6393b33', '1dbcf7675229b35d31abb6547d8ebc8c27a830ac3f9a794edff6254873ec7c0a', '2293949b855ce597f2826452d17c2d545fb5622379c4ea6fdf525e9b8e8a2511', '26a4dca084132874e639895c3135dfad5eb20bae209f62d1aeb31b03e601c3c0', '2800a4a8ead6b28cccd1ec54b59346f0def7922ee1c7598e8499c733cfbb7c84', '29cbaac5ea0212663e6845e04b5e188d5a6ae6dd919810ac835bf1d3b42c3f4c', '29f9309a2e42b0d273be006fdb4be2d6c39a47f6f57d8fb1cf9f81481df81b66', '2d7aa89ebca5acc98cba9d1472d976e394782f587bad6661003602a619fd1821', '2f22cbbac9e26a8e864c0985ff1268d5d939d53d9d9411a9824279097e03a2cb', '2f8ea531c794b9d6274acd4e8d2c2ebcac590a4361d27482edd3010b79f1325e', '3115559b8effafd63b142ea5ed53d63a16ea6469cbc63dce4ee194b42db5d853', '32775082acd2d807ee3db715c7770d38767b817870acfa08c29e057f3c4d5b56', '3430bb2bfe1331885c427745a751e774ee679fd4344f80b97bf879815fe8fa55', '3b199b9b2b3d6a7edf3183ba8a9a137a22b97f7df525feb5ae1eccf026d2a9c6', '40314bca9ac559716fe374094fc81c11dcc34b64fd6c585360f5775690505704', '44e488ef40dbb452700b2b1f8188934121f6648f52c295055662d2191959ff82', '452b5065457eb9991ec5eb38ff41d6cd4c991c9ac7c531c4d5849ae473a9a13f', '45f11346f884bc47444f6e6647131055844134c3175b629f84952e2b5cd62b64', '46088abff4cba581dea21ae0467a480526cb25aa5f3c269e909f800328bc3999', '4621064bbf28fa77ff64dd5d94367c04684c67d3a5bf1dff25f0cd0d98a38f3b', '4bc8ff1feffc6a61c7002ffe84634c41b822e104990ae009f44a0834430070bb', '4db0ba63d693afd40d249bd93f842b5f144f8fcbb83de05660373bcf30517b1d', '51f96d685ab16e88cab128cd37a52c5da540809c8b879fa047731bfcb4ad35a4', '54adaa85a22078d1e306304a40984dc5be99d599bf3dc0a24dc98f7daeab89ab', '552ffadf6ad409844bc5919c42a0a83d88314cedddaea0e41e80a8b8fffe881f', '5538d2c13d93e4698af7e092b57bc7298fd35d1d58e656ae18f23ee0d0378e03', '5570dbcc97571c15f68068e529c92715a12f8d54030e272d264b377e22bd17a5', '5671d09a36b06d0fd4a3da0fccbcae360e9b1570924171a15e9e0997f0249fba', '583c19759d9eec1e5b69e2fbef36a7d9c326041be9746cb822d335c8cedc2979', '5aaa2b923c1944ac8febd6609cb373540a5563e7cbcb0fd770f75dace2eb817b', '5dbc581d2814337da56222fab8dc5f161cd798a434e49bac27930aaef798e144', '5fcb98e7598b1ee0addab320d90f65b530297a867dbfe9de52ea838077e16e3d', '6041d31504dc1779d700e1edcfb08eea334b357620b06681a4eabb57a74e574e', '66ea454f095ddf5b6b14f56c064c0941c4788be11e18d2464cf643bf7203ff67', '68ce1c44c7a813a7f71ea04315a8c7b330b63db99d059a797a4651bb6f69f117', '6a997d0489e9668a384fcfd5061b857aa5361de73191cac204d04b889cfbbafa', '6bf3be92233808fcd338eba0fb4d0b59ec5772af4f4ecfcec450d1bfc0f8b5eb', '6de8bd93ddde9b992cf2b2e0d796d501a19026b5b9fd87356d7d0779531a8d96', '6e7b8719005dd1175be4ab1cd25e9b98659a5e0347331506ec6760d2773a7fb5', '6f328175a2cde1f0ff2c4ed8ce968b9dcfb55f3a7153f39e2957ed994da13476', '72d61e16dd78228b58c5d47be830ff3da7e5f139abdf0aef9d86cde1c5cf2191', '74b70780220e2dd89175ca24b81b68b67c83db499ae611e7f2313cb329801c78', '79aa3ff0a9b566633b642fa9caf7e21ed1c13d6feca718187873f199e1514078', '7afa37062e6650640e932e4cc9297d81f9f42d9944029cc386b8247dea4da837', '80168e2ebe4d3ec6599d10ad8f520304ae1cad9b6c5a95372aef1b66b7bfb53a', '806719138ecd720339a12410fb9614ac9b2b2d3a5fdf8235d56981c36f4039ba', '8114f28879e0904748e831c3a7774261bd9e75f49be089f389a76f959dcd13fe', '81e3a30b0bb60caa22033dd0f8a3618d1d67356212514f62c57db75cb0ef410c', '823581fd5cb08b12a48bfa11fe962a7916766b6170c17b028fbdf762b85eb9bf', '85341b12b9d55bad0bded24cac341bb34289469e03a11f3f583ea1cc1db0326c', '857187f381f88c8e2fa2fe56ab94879d011b883d5a2ee5a1b60a8cd2a06846d9', '8a90efd5777e996e42d568db9ac740b944d691e565cbfd31b2f7832f9184b2b8', '8b73ab70f1a3351fbc71f663b3e645af6dd0329100c353081cf69c37433fc6fe', '8c7972d8f193740d9175f0998ab38717e6cd322d5935c5b0fef8c0d323fd9031', '8e778ebd44ef4f66ed60a0416b06b489687db264a9c0b3620362f26489492913', '9282fb1a3bccd038da9f768b927b24a0c753e466c086b7c4f3c6982851eefb2d', '949c91d1a990cf3b2e8188dfcfb25005e0b834a06c63fa4ef9f360878ce21ecf', '95f1e3f4760d404b13c9976c0229b2b49a3c8e2c62a9ce92efdd2b11ada75e3f', '97797ebb098e670a2f92dd66f32897e30d7615b14e7f59711de23e30a9072539', 'a0e399a2eccb91ed18721f86aa85757727400b6865c89e88934781deb9c8498b', 'a473b3440261e0c60706e732b2ed2f517857344fc21bf48fdfe211e2d98eb285', 'a4840ab0ae0216d952f4b53dc6d0b992bfc2bedbfe360bdd9b548bc184c08959', 'a592f5f3da71c8691c788c13cb6734b6d17663d2e1cb8caddf0673d01ef8847d', 'a6ae2198be502c10f09b2516e7b5d019816924bc3183a43ce792a7bd6625e6f4', 'a6ddc6ac9e25de626c1f129c1b467d7ecd33ce2237d3fd0c4e429feef0a7ee1f', 'acd2c8edba48e31e58a363b8cf4e5c7db3b04b3f9e371f601df30d9b0d244836', 'b05d643f944a8c3c4bd86d65ffd87bf3264b617f87791940302bc474d2ff5274', 'b96db7141a592cbc968daf1feea83a118e6ab378af4abbc72b248c895414c22d', 'ba338430e87ceb9c8f0cf754de38a9860560261e56c00376debd628698a7364f', 'ba57fffe4ac99c5d30076161b5866336d97600769bad35cc68f7774b15298a4e', 'be1ddfcbb376e3de5d2e2db1d58d6d67463e6b4f9f040c000de8e300295465fe', 'c0cb9ed24c8964e172768d455a38254c2dd8a552905729ce006cad3d3dda59b1', 'c60462af8e6dc30c35407c7237ea908d777b22862bbee27bc4699c0d8bcdc45a', 'c66afea89b1e43725731d2004732a046fe6fe955d51f952c3e95a7314a284a39', 'c6844ba6364fb12f403928a82cfd295ab103a2b315c77c747b2dbe4a41894ea7', 'c80f4ba3e8f00189165999a742ee526ebeccedf6c3f7beb0c7df821e9772435a', 'cafca7e56c12bb02ae16d283742bef25a61122e9dab2b5b3f2ccbe589ce32164', 'cc1177027eda740fdb152706bd215a3f124e3eea15afc39f2cb9fe351b50619e', 'cc49723e2f60d6b32a0f0b08a3fd6d13203c07f1cd9566cfce0f12a917c967a2', 'cc6fc3cc62e8501d3ed62894425040d2728ecddb1ed072737a5c70bd537aa9f0', 'cd416c1de191973c52ff1a12a57446bfc7642797b282d7caf2162d7d1b8aa9a0', 'cd645f03898405cabe694fb8bc35241e3a9c332ec85627584fe3de201452b335', 'cef6cea3922890dd6c9654971001fa797b526c16ab5e1e46c05fd6f877be7568', 'cfa21e036ce1e1db2be04ba3b85d2df1bb1702fa01932d984c5464c665228ff4', 'd0326e2e5e1f3163fa306c834e48e8d490e5fae607a097a40c0648109b47ba80', 'd310c013aad2c72f1c3f2f8dd3279d460a858c551f97aeb8c63e4693cca7b4d2', 'd447bb0b3054be5818458fbb171208b1d9ff11eba14e18ca18b90cbb45767370', 'd4dc37dec6c6cdad0b57881a5658fd14fbf53e333b1a86cf86559f190e1d9ec4', 'd5a81be28596d6559f6131ef33e10200de6e17643b3c74ce03f9eb103be6ae8b', 'd9ee8826a7d47863a08ac44e1a5f611a462eefc3a194b492da242128bec75b42', 'db2b80ea58eab4f86b2beec3cc8b39e8ff9276ac20e96b7cce43c8ae84cd6b5a', 'decfca4c79dd53ebab484b00cc4b6717d8c369f86e74aa4ca395a64ac651495e', 'dfed59d0a5aeb01e242e66ff0300bc4a265a7c05f612d30016f0b60b1017d757', 'e00820e192c8dbebcafb383ebbf99030895f09905e7a0eb2e0340a0bcc2bc825', 'e4294d04a94dcab1b3bccd8b66d962dcad411a1d19414b2a41d1445f1de32ad0', 'e59bc9e66329185b93dab73f210f1a37f81cb40f321501db8017c9aea15dba27', 'e5cbfac9f61484f7e9f3597775500cd3ebe8274e9b050c38f9525c77c97520bf', 'f064f8d2b59177878b7615df1735cd8fe3462ed6be8c7b217d17a276489c2b7f', 'f156a3529f38063b6dbaf356e15602a7f95f8055b1295a438433a6386f10463d', 'f19bb891234d72535764d703bfed1153cc34f4214d5bd7150aee1eec9e8f4366', 'f7467da8a9822bf1a55336f877340c5bcbd3c482afc43a99771169f74a26dedc', 'f78abfa8dfc32376fd1aacf597b2f2fbbe0ea751419aee718af5d4f82537ef8c', 'f7eabc04151c78a9f4d5bbb5f1faf571e4defeb4b585e0fe95b60ff2dbe4d3d7', 'f814362777a9f841adddb200ecdf8f5cb1e5a3c4b7a86378edbd6ccb26edd702', 'fc299c129490f55f254cd90be0deca4764e36e9a7c08b4aa588479a3bbed3098', 'fc76378c62a0f04d0cd82fbb1a2cd2d7e28fcb40d5873f28a6c44e388aaa2751', 'fc88b26f08d634f7bc819a7852e5214f5802641ab8d9fd5326892292eee1993e', 'fe67a3d11cd9b4efabfa45c3d00ffba2b26811442a73a581a94b67c2b5faccf6', )), ('yarl==1.24.5', ( '0055afc45e864b92729ac7600e2d102c17bef060647e74bca75fa84d66b9ff36', '0465ec8cedc2349b97a6b595ace64084a50c6e839eca40aa0626f38b8350e331', '0ebfaffe1a16cb72141c8e09f18cc76856dbe58639f393a4f2b26e474b96b871', '16a2f5010280020e90f5330257e6944bc33e73593b136cc5a241e6c1dc292498', '17f57620f5475b3c69109376cc87e42a7af5db13c9398e4292772a706ff10780', '2120b96872df4a117cde97d270bac96aea7cc52205d305cf4611df694a487027', '240cbec09667c1fed4c6cd0060b9ec57332427d7441289a2ed8875dc9fb2b224', '24e861e9630e0daddcb9191fb187f60f034e17a4426f8101279f0c475cd74144', '2729fcfc4f6a596fb0c50f32090400aa9367774ac296a00387e65098c0befa76', '2c1fe720934a16ea8e7146175cba2126f87f54912c8c5435e7f7c7a51ef808d3', '2cabe6546e41dabe439999a23fcb5246e0c3b595b4315b96ef755252be90caeb', '2dbe06fc16bc91502bca713704022182e5729861ae00277c3a23354b40929740', '3363fcc96e665878946ad7a106b9a13eac0541766a690ef287c0232ac768b6ec', '377fe3732edbaf78ee74efdf2c9f49f6e99f20e7f9d2649fda3eb4badd77d76e', '3ac6aff147deb9c09461b2d4bbdf6256831198f5d8a23f5d37138213090b6d8a', '3f45789ce415a7ec0820dc4f82925f9b5f7732070be1dec1f5f23ec381435a24', '4103b77b8a8225e413107d2349b65eb3c1c52627b5cc5c3c4c1c6a798b218950', '4377407001ca3c057773f44d8ddd6358fa5f691407c1ba92210bd3cf8d9e4c95', '46c2f213e23a04b93a392942d782eb9e413e6ef6bf7c8c53884e599a5c174dcb', '47e98aab9d8d82ff682e7b0b5dded33bf138a32b817fcf7fa3b27b2d7c412928', '4a36f9becdd4c5c52a20c3e9484128b070b1dcfc8944c006f3a528295a359a9c', '4af7b7e1be0a69bee8210735fe6dcfc38879adfac6d62e789d53ba432d1ffa41', '4d97a951a81039050e45f04e96689b58b8243fa5e62aa14fe67cb6075300885e', '4db9aecb141cb7a5447171b57aa1ed3a8fee06af40b992ffc31206c0b0121550', '53e549287ef628fecba270045c9701b0c564563a9b0577d24a4ec75b8ab8040f', '56b149b22de33b23b0c6077ab9518c6dcb538ad462e1830e68d06591ccf6e38b', '570fec8fbd22b032733625f03f10b7ff023bc399213db15e72a7acaef28c2f4e', '5b8ee53be440a0cffc991a27be3057e0530122548dbe7c0892df08822fce5ede', '5ba4f78df2bcc19f764a4b26a8a4f5049c110090ad5825993aacb052bf8003ad', '5c55256dee8f4b27bfbf636c8363383c7c8db7890c7cba5217d7bd5f5f21dab6', '5c88e5815a49d289e599f3513aa7fde0bc2092ff188f99c940f007f90f53d104', '5fede79c6f73ff2c3ef822864cb1ada23196e62756df53bc6231d351a49516a2', '65be18ec59496c13908f02a2472751d9ef840b4f3fb5726f129306bf6a2a7bba', '66410eb6345d467151934b49bfa70fb32f5b35a6140baa40ad97d6436abea2e9', '665b0a2c463cc9423dd647e0bfd9f4ccc9b50f768c55304d5e9f80b177c1de12', '6b8536851f9f65e7f00c7a1d49ba7f2be0ffe2c11555367fc9f50d9f842410a1', '6c95b17fe34ed802f17e205112e6e10db92275c34fee290aa9bdc55a9c724027', '6e73e7fe93f17a7b191f52ec9da9dd8c06a8fe735a1ecbd13b97d1c723bff385', '6efbccc3d7f75d5b03105172a8dc86d82ba4da86817952529dd93185f4a88be2', '709f1efed56c4a145793c046cd4939f9959bcd818979a787b77d8e09c57a0840', '79af890482fc94648e8cde4c68620378f7fef60932710fa17a66abc039244da2', '7bcbe0fcf850eae67b6b01749815a4f7161c560a844c769ad7b48fcd99f791c4', '7c0494a31a1ac5461a226e7947a9c9b78c44e1dc7185164fa7e9651557a5d9bc', '7ce27823052e2013b597e0c738b13e7e36b8ccb9400df8959417b052ab0fd92c', '7f72c74aa99359e27a2ee8d6613fefa28b5f76a983c083074dfc2aaa4ab46213', '7fa5e51397466ea7e98de493fa2ff1b8193cfef8a7b0f9b4842f92d342df0dba', '82632daed195dcc8ea664e8556dc9bdbd671960fb3776bd92806ce05792c2448', '82f75e05912e84b7a0fe57075d9c59de3cb352b928330f2eb69b2e1f54c3e1f0', '841f0852f48fefea3b12c9dfec00704dfa3aef5215d0e3ce564bb3d7cd8d57c6', '874019bd513008b009f58657134e5d0c5e030b3559bd0553976837adf52fe966', '88f50c94e21a0a7f14042c015b0eba1881af78562e7bf007e0033e624da59750', '89a1bbb58e0e3f7a283653d854b1e95d65e5cfd4af224dac5f02629ec1a3e621', '8a6987eaad834cb32dd57d9d582225f0054a5d1af706ccfbbdba735af4927e13', '8ac73abdc7ab75610f95a8fd994c6457e87752b02a63987e188f937a1fc180f0', '8ccf9aca873b767977c73df497a85dbedee4ee086ae9ae49dc461333b9b79f58', '90333fd89b43c0d08ac85f3f1447593fc2c66de18c3d6378d7125ea118dc7a54', '92ab3e11448f2ff7bf53c5a26eff0edc086898ec8b21fb154b85839ce1d88075', '9335a099ad87287c37fe5d1a982ff392fa5efe5d14b40a730b1ec1d6a41382b4', '96d30286dd02679e32a39aa8f0b7498fc847fcda46cfc09df5513e82ce252440', '9baafc71b04f8f4bb0703b21d6fc9f0c30b346c636a532ff16ec8491a5ea4b1f', '9d1216a7f6f77836617dba35687c5b78a4170afc3c3f18fc788f785ba26565c4', '9d399bdcfb4a0f659b9b3788bbc89babe63d9a6a65aacdf4d4e7065ff2e6316c', '9e4e16c73d717c5cf27626c524d0a2e261ad20e46932b2670f64ad5dde23e26f', '9f4d8cf085a4c6a40fb97ea0f46938a8df43c85d31f9d45e2a8867ea9293790d', 'a33700d13d9b7d84fd10947b09ff69fb9a792e519c8cb9764a3ca70baa6c23a7', 'a3732e66413163e72508da9eff9ce9d2846fde51fae45d3605393d3e6cd303e9', 'a4582acf7ef76482f6f511ebaf1946dae7f2e85ec4728b81a678c01df63bd723', 'a61834fb15d81322d872eaafd333838ae7c9cea84067f232656f75965933d047', 'a7cff474ab7cd149765bb784cf6d78b32e18e20473fb7bda860bce98ab58e9da', 'a8fe66b8f300da93798025a785a5b90b42f3810dc2b72283ff84a41aaaebc293', 'a929d878fec099030c292803b31e5d5540a7b6a31e6a3cc76cb4685fc2a2f51b', 'ad5d8201d310b031e6cd839d9bac2d4e5a01533ce5d3d5b50b7de1ef3af1de61', 'af3aefa655adb5869491fa907e652290386800ae99cc50095cba71e2c6aefdca', 'c0ebc836c47a6477e182169c6a476fc691d12b518894bf7dd2572f0d59f1c7ed', 'c687ed078e145f5fd53a14854beff320e1d2ab76df03e2009c98f39a0f68f39a', 'cbb833ccacdb5519eff9b8b71ee618cc2801c878e77e288775d77c3a2ced858a', 'cf139c02f5f23ef6532040a30ff662c00a318c952334f211046b8e60b7f17688', 'd46b86567dd4e248c6c159fcbcdcce01e0a5c8a7cd2334a0fff759d0fa075b16', 'd693396e5aea78db03decd60aec9ece16c9b40ba00a587f089615ff4e718a81d', 'd897129df1a22b12aeed2c2c98df0785a2e8e6e0bde87b389491d0025c187077', 'daba5e594f06114e37db186efd2dd916609071e59daca901a0a2e71f02b142ce', 'dd625535328fd9882374356269227670189adfcc6a2d90284f323c05862eecbd', 'e006d3a974c4ee19512e5f058abedb6eef36a5e553c14812bdeba1758d812e6d', 'e1ae548a9d901adca07899a4147a7c826bbcc06239d3ce9a59f57886a28a4c88', 'e2935f8c39e3b03e83519292d78f075189978f3f4adc15a78144c7c8e2a1cba5', 'e42d75862735da90e7fc5a7b23db0c976f737113a54b3c9777a9b665e9cbff75', 'e7d42c531243450ef0d4d9c172e7ed6ef052640f195629065041b5add4e058d1', 'e8ffa78582120024f476a611d7befc123cee59e47e8309d470cf667d806e613b', 'ebb0ec7f17803063d5aeb982f3b1bd2b2f4e4fae6751226cbd6ba1fcfe9e63ff', 'f08c7513ecef5aad65687bfdf6bc601ae9fccd04a42904501f8f7141abad9eb9', 'f0a658a6d3fafee5c6f63c58f3e785c8c43c93fbc02bf9f2b6663f8185e0971f', 'f0e466ed7511fe9d459a819edbc6c2585c0b6eabde9fa8a8947552468a7a6ef0', 'f141474e85b7e54998ec5180530a7cda99ab29e282fa50e0756d89981a9b43c5', 'f4239bbec5a3577ddb49e4b50aeb32d8e5792098262ae2f63723f916a29b1a25', 'f540c013589084679a6c7fac07096b10159737918174f5dfc5e11bf5bca4dfe6', 'f9f3e9c8a9ecffa57bef8fb4fa19e5fa4d2d8307cf6bac5b1fca5e5860f4ba00', 'fa139875ff98ab97da323cfadfaff08900d1ad42f1b5087b0b812a55c5a06373', 'fcd3b77e2f17bbe4ca56ec7bcb07992647d19d0b9c05d84886dcd6f9eb810afd', 'fd8c81f346b58f45818d09ea11db69a8d5fd34a224b79871f6d44f12cd7977b1', 'fe7b7bb170daccbba19ad33012d2b15f1e7942296fd4d45fc1b79013da8cc0f2', 'ff330d3c30db4eb6b01d79e29d2d0b407a7ecad39cfd9ec993ece57396a2ec0d', 'ff405d91509d88e8d44129cd87b18d70acd1f0c1aeabd7bc3c46792b1fe2acba', 'ffcd54362564dc1a30fb74d8b8a6e5a6b11ebd5e27266adc3b7427a21a6c9104', )), ('typing-extensions==4.16.0', ( '481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8', )), ('async-timeout==5.0.1', ( '39e3809566ff85354557ec2398b55e096c8364bacac9405a7a1fa429e77fe76c', )), ) APPROVAL_BATCH_SIZE = 250 APPROVAL_RETRY_ATTEMPTS = 5 _HEX64 = re.compile(r"^[0-9a-f]{64}$") _HEX128 = re.compile(r"^[0-9a-f]{128}$") # The server replaces these exact markers in the customized one-file download. # The public, readable copy intentionally contains no workspace capability. EMBEDDED_BASE_URL = "__INFRAVEIL_BASE_URL__" EMBEDDED_BOOTSTRAP_TOKEN = "__INFRAVEIL_BOOTSTRAP_TOKEN__" EMBEDDED_USERNAME = "__INFRAVEIL_USERNAME__" EMBEDDED_LAUNCHER_HOST_ID = "__INFRAVEIL_LAUNCHER_HOST_ID__" EMBEDDED_RELEASE_PUBLIC_KEY = "__INFRAVEIL_RELEASE_PUBLIC_KEY__" def _embedded(value, fallback=""): value = str(value or "").strip() return fallback if value.startswith("__INFRAVEIL_") else value DEFAULT_BASE_URL = _embedded(EMBEDDED_BASE_URL, "https://portal.infraveil.com") BOOTSTRAP_TOKEN = _embedded(EMBEDDED_BOOTSTRAP_TOKEN) WORKSPACE_USERNAME = _embedded(EMBEDDED_USERNAME) LAUNCHER_HOST_ID = _embedded(EMBEDDED_LAUNCHER_HOST_ID) RELEASE_PUBLIC_KEY = _embedded(EMBEDDED_RELEASE_PUBLIC_KEY).lower() _C = { "d": "\x1b[0m", "b": "\x1b[1m", "dim": "\x1b[90m", "g": "\x1b[92m", "y": "\x1b[93m", "r": "\x1b[91m", "c": "\x1b[96m", } def _col(value, key): return _C.get(key, "") + str(value) + _C["d"] def _enable_ansi(): if os.name == "nt": try: import ctypes kernel = ctypes.windll.kernel32 kernel.SetConsoleMode(kernel.GetStdHandle(-11), 7) except Exception: pass def _control_home(value=None): configured = str(value or os.environ.get("INFRAVEIL_CONTROL_HOME") or "").strip() if configured: return os.path.abspath(os.path.expanduser(configured)) script_dir = os.path.dirname(os.path.realpath(__file__)) working_dir = os.path.abspath(os.getcwd()) if os.path.basename(script_dir).lower() == CONTROL_DIR_NAME.lower(): return script_dir if os.path.basename(working_dir).lower() == CONTROL_DIR_NAME.lower(): return working_dir return os.path.join(working_dir, CONTROL_DIR_NAME) def _path(home, name): return os.path.join(home, name) _WINDOWS_SID = "" def _windows_current_sid(): global _WINDOWS_SID if _WINDOWS_SID: return _WINDOWS_SID try: output = subprocess.check_output( ["whoami", "/user", "/fo", "csv", "/nh"], text=True, stderr=subprocess.DEVNULL, timeout=15, ) except Exception as exc: raise RuntimeError("Could not identify the current Windows account for private-file ACLs") from exc match = re.search(r"S-\d+(?:-\d+)+", output, re.IGNORECASE) if not match: raise RuntimeError("Windows did not return a valid current-user SID") _WINDOWS_SID = match.group(0) return _WINDOWS_SID def _restrict_windows_acl(path, directory=False): sid = _windows_current_sid() permission = f"*{sid}:(OI)(CI)F" if directory else f"*{sid}:F" result = subprocess.run( ["icacls", os.path.abspath(path), "/inheritance:r", "/grant:r", permission], stdout=subprocess.DEVNULL, stderr=subprocess.PIPE, text=True, check=False, timeout=30, ) if result.returncode != 0: detail = (result.stderr or "").strip()[:160] raise RuntimeError(f"Could not restrict Windows ACL for {path}: {detail or 'icacls failed'}") def _secure_dir(path): absolute = os.path.abspath(path) if os.path.lexists(absolute) and os.path.islink(absolute): raise RuntimeError(f"Refusing symlinked private directory: {absolute}") os.makedirs(absolute, mode=0o700, exist_ok=True) if os.name == "nt": _restrict_windows_acl(absolute, directory=True) else: os.chmod(absolute, 0o700) def _secure_write(path, value): parent = os.path.dirname(os.path.abspath(path)) _secure_dir(parent) temporary = path + "." + os.urandom(8).hex() + ".tmp" # Signed source is an exact byte contract. Text-mode writes translate # LF to CRLF on Windows and would invalidate a verified source hash. data = value if isinstance(value, bytes) else value.encode("utf-8") flags = os.O_WRONLY | os.O_CREAT | os.O_EXCL descriptor = os.open(temporary, flags, 0o600) try: with os.fdopen(descriptor, "wb") as handle: handle.write(data) handle.flush() os.fsync(handle.fileno()) if os.name == "nt": _restrict_windows_acl(temporary, directory=False) else: os.chmod(temporary, 0o600) os.replace(temporary, path) if os.name == "nt": _restrict_windows_acl(path, directory=False) except Exception: try: os.remove(temporary) except OSError: pass raise def _read_secret_file(path, label): try: stat = os.stat(path) if os.name == "nt": _restrict_windows_acl(path, directory=False) elif stat.st_mode & 0o077: raise RuntimeError(f"{label} is readable by other users: chmod 600 {path}") except FileNotFoundError as exc: raise RuntimeError(f"{label} file not found: {path}") from exc with open(path, encoding="utf-8") as handle: return handle.read().strip() def _default_config(home): return { "base_url": DEFAULT_BASE_URL, "policy": "manual", "key_file": _path(home, "approval-private.key"), "token_file": _path(home, "approval-token.txt"), "allowlist_file": _path(home, "approved-hashes.txt"), "log": _path(home, "approval-decisions.log"), "interval": 30, "launcher_file": _path(home, os.path.join("runtime", "launcher.py")), "workspace_username": WORKSPACE_USERNAME, "launcher_host_id": LAUNCHER_HOST_ID, "pending_install_token": "", "pending_install_url": "", "pending_install_expires_at": 0, } def _config_path(home): return _path(home, "trust-console.json") def _load_config(home): config = _default_config(home) try: with open(_config_path(home), encoding="utf-8") as handle: loaded = json.load(handle) if isinstance(loaded, dict): config.update(loaded) except FileNotFoundError: pass except Exception as exc: print(_col(f"warning: could not read configuration: {exc}", "y")) return config def _save_config(home, config): _secure_write(_config_path(home), json.dumps(config, indent=2, sort_keys=True) + "\n") def _installed_script(home): return _path(home, "infraveil.py") def _install_self(home): source_path = os.path.realpath(__file__) destination = _installed_script(home) if os.path.abspath(source_path) == os.path.abspath(destination): return destination with open(source_path, encoding="utf-8") as handle: source = handle.read() _secure_write(destination, source) if os.name != "nt": os.chmod(destination, 0o700) return destination def _venv_python(home): return _path(_managed_runtime_directory(home), os.path.join("Scripts" if os.name == "nt" else "bin", "python.exe" if os.name == "nt" else "python")) def _runtime_ready(): try: for requirement, _hashes in LOCKED_WHEEL_HASHES: distribution, expected_version = requirement.split("==", 1) if importlib.metadata.version(distribution) != expected_version: return False for name in ("requests", "cryptography", "psutil", "waitress", "aiohttp"): importlib.import_module(name) return True except (ImportError, importlib.metadata.PackageNotFoundError, ValueError): return False def _runtime_probe_code(): expected = dict(requirement.split("==", 1) for requirement, _hashes in LOCKED_WHEEL_HASHES) return ( "import importlib.metadata as metadata; " f"expected={expected!r}; " "assert all(metadata.version(name) == version for name, version in expected.items()); " "import requests, cryptography, psutil, waitress, aiohttp" ) def _sanitized_runtime_env(home): env = os.environ.copy() for name in list(env): upper = name.upper() if upper.startswith("PYTHON") or upper.startswith("PIP_"): env.pop(name, None) for name in ("REQUESTS_CA_BUNDLE", "CURL_CA_BUNDLE", "SSL_CERT_FILE", "SSL_CERT_DIR"): env.pop(name, None) env.pop("VIRTUAL_ENV", None) env.pop("__PYVENV_LAUNCHER__", None) env.update({ "PIP_CONFIG_FILE": os.devnull, "PIP_DISABLE_PIP_VERSION_CHECK": "1", "PIP_NO_INPUT": "1", "PIP_REQUIRE_VIRTUALENV": "1", "PYTHONNOUSERSITE": "1", "INFRAVEIL_TRUST_CONSOLE_RUNTIME": "1", "INFRAVEIL_CONTROL_HOME": home, "INFRAVEIL_MANAGED_RUNTIME_HOME": os.path.abspath(home), "INFRAVEIL_RUNTIME_LOCK_SHA256": _runtime_lock_identity(), }) return env def _locked_requirements_text(): lines = [ "# Generated from release files published by pypi.org; wheel-only and hash-locked.", "# Infraveil Trust Console runtime lock v1.", ] for requirement, hashes in LOCKED_WHEEL_HASHES: lines.append(requirement + " \\") for index, digest in enumerate(hashes): suffix = " \\" if index < len(hashes) - 1 else "" lines.append(" --hash=sha256:" + digest + suffix) return "\n".join(lines) + "\n" def _runtime_lock_identity(): contract = {requirement: sorted(hashes) for requirement, hashes in LOCKED_WHEEL_HASHES} return hashlib.sha256(json.dumps(contract, sort_keys=True, separators=(",", ":")).encode("utf-8")).hexdigest() def _managed_runtime_directory(home): return _path(os.path.abspath(home), ".venv-" + _runtime_lock_identity()[:24]) def _windows_path_owner_sid(path): import ctypes owner, descriptor, text = ctypes.c_void_p(), ctypes.c_void_p(), ctypes.c_void_p() advapi = ctypes.WinDLL("advapi32", use_last_error=True) kernel = ctypes.WinDLL("kernel32", use_last_error=True) advapi.GetNamedSecurityInfoW.argtypes = [ctypes.c_wchar_p, ctypes.c_uint, ctypes.c_uint, ctypes.POINTER(ctypes.c_void_p), ctypes.c_void_p, ctypes.c_void_p, ctypes.c_void_p, ctypes.POINTER(ctypes.c_void_p)] advapi.GetNamedSecurityInfoW.restype = ctypes.c_uint advapi.ConvertSidToStringSidW.argtypes = [ctypes.c_void_p, ctypes.POINTER(ctypes.c_void_p)] advapi.ConvertSidToStringSidW.restype = ctypes.c_int kernel.LocalFree.argtypes = [ctypes.c_void_p] kernel.LocalFree.restype = ctypes.c_void_p try: code = advapi.GetNamedSecurityInfoW(os.path.abspath(path), 1, 1, ctypes.byref(owner), None, None, None, ctypes.byref(descriptor)) if code or not advapi.ConvertSidToStringSidW(owner, ctypes.byref(text)): raise RuntimeError("Could not verify the managed runtime path owner") return ctypes.wstring_at(text) finally: if text.value: kernel.LocalFree(text) if descriptor.value: kernel.LocalFree(descriptor) def _assert_runtime_path(path, directory=False, private=True): absolute = os.path.abspath(path) current = absolute while True: if os.path.lexists(current): info = os.lstat(current) if os.path.islink(current) or bool(getattr(info, "st_file_attributes", 0) & 0x400): raise RuntimeError("Managed runtime path contains a link or reparse point") parent = os.path.dirname(current) if parent == current: break current = parent if os.path.lexists(absolute): info = os.lstat(absolute) if directory and not os.path.isdir(absolute): raise RuntimeError("Managed runtime directory is not a directory") if not directory and not os.path.isfile(absolute): raise RuntimeError("Managed runtime marker is not a regular file") if os.name != "nt" and info.st_uid != os.geteuid(): raise RuntimeError("Managed runtime path belongs to another account") if os.name == "nt" and _windows_path_owner_sid(absolute) != _windows_current_sid(): raise RuntimeError("Managed runtime path belongs to another Windows account") if os.name != "nt" and info.st_mode & (0o077 if private else 0o022): raise RuntimeError("Managed runtime path is not private") return absolute def _private_runtime_directory(path): absolute = os.path.abspath(path) _assert_runtime_path(absolute, directory=True) _secure_dir(absolute) return _assert_runtime_path(absolute, directory=True) def _runtime_marker(home): directory = _managed_runtime_directory(home) _assert_runtime_path(home, directory=True) _assert_runtime_path(directory, directory=True) marker = _path(directory, ".infraveil-runtime.json") if not os.path.lexists(marker): return None _assert_runtime_path(_venv_python(home), private=False) _assert_runtime_path(marker) if os.path.getsize(marker) > 65536: raise RuntimeError("Managed runtime marker is oversized") flags = os.O_RDONLY | getattr(os, "O_NOFOLLOW", 0) with os.fdopen(os.open(marker, flags), "r", encoding="utf-8") as handle: value = json.load(handle) expected_versions = dict(requirement.split("==", 1) for requirement, _hashes in LOCKED_WHEEL_HASHES) if not isinstance(value, dict) or value.get("schema") != 1 or value.get("lock_sha256") != _runtime_lock_identity() or value.get("versions") != expected_versions or value.get("runtime_home") != os.path.abspath(home) or value.get("python") != _venv_python(home): raise RuntimeError("Managed runtime marker does not match this approved dependency lock") return value def _current_runtime_matches(home): directory = _managed_runtime_directory(home) if os.path.normcase(os.path.abspath(sys.prefix)) != os.path.normcase(directory) or sys.prefix == sys.base_prefix: return False return _runtime_marker(home) is not None and _runtime_ready() def _prepare_runtime(home): if sys.version_info < MINIMUM_PYTHON: required = ".".join(str(value) for value in MINIMUM_PYTHON) raise RuntimeError(f"Python {required} or newer is required; found {platform.python_version()}") home = _private_runtime_directory(home) directory = _managed_runtime_directory(home) venv_python = _venv_python(home) env = _sanitized_runtime_env(home) lock_path = _path(home, ".prepare-" + _runtime_lock_identity()[:24] + ".lock") deadline = time.monotonic() + 30 while True: try: os.mkdir(lock_path, 0o700) _private_runtime_directory(lock_path) break except FileExistsError: _assert_runtime_path(lock_path, directory=True) if time.monotonic() >= deadline: raise RuntimeError("Managed runtime preparation is busy; review the private preparation lock before retrying") time.sleep(0.1) try: marker = _runtime_marker(home) if marker is not None: check = subprocess.run([venv_python, "-I", "-c", _runtime_probe_code()], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, check=False, cwd=home, env=env, timeout=30) if check.returncode != 0: raise RuntimeError("Published managed runtime failed its lock check; it will not be modified while it may be running") return venv_python _private_runtime_directory(directory) if not os.path.exists(venv_python): subprocess.check_call([sys.executable, "-I", "-m", "venv", "--copies", directory], cwd=home, env=env, timeout=120) _assert_runtime_path(venv_python, private=False) requirements_path = _path(directory, LOCK_FILE_NAME) _secure_write(requirements_path, _locked_requirements_text()) subprocess.check_call([venv_python, "-I", "-m", "pip", "install", "--quiet", "--only-binary=:all:", "--require-hashes", "--index-url", "https://pypi.org/simple", "--requirement", requirements_path], cwd=home, env=env, timeout=300) check = subprocess.run([venv_python, "-I", "-c", _runtime_probe_code()], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, check=False, cwd=home, env=env, timeout=30) if check.returncode != 0: raise RuntimeError("Prepared managed runtime does not match the approved dependency lock") marker = {"schema": 1, "lock_sha256": _runtime_lock_identity(), "versions": dict(requirement.split("==", 1) for requirement, _hashes in LOCKED_WHEEL_HASHES), "runtime_home": home, "python": venv_python, "prepared_at": time.time()} _secure_write(_path(directory, ".infraveil-runtime.json"), json.dumps(marker, sort_keys=True, separators=(",", ":")) + "\n") return venv_python finally: os.rmdir(lock_path) def _ensure_runtime(home, script_path, argv): if _current_runtime_matches(home): return venv_python = _prepare_runtime(home) env = _sanitized_runtime_env(home) os.execve(venv_python, [venv_python, "-I", script_path] + list(argv), env) def _crypto(): from cryptography.hazmat.primitives import serialization from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey, Ed25519PublicKey return serialization, Ed25519PrivateKey, Ed25519PublicKey def _generate_key(path): if os.path.exists(path): raise RuntimeError(f"Refusing to overwrite existing private key: {path}") serialization, Ed25519PrivateKey, _ = _crypto() private_key = Ed25519PrivateKey.generate() seed = private_key.private_bytes( serialization.Encoding.Raw, serialization.PrivateFormat.Raw, serialization.NoEncryption(), ).hex() _secure_write(path, seed + "\n") return private_key def _load_private_key(path): raw = _read_secret_file(path, "approval private key").lower() if not _HEX64.fullmatch(raw): raise RuntimeError("approval private key must be a 32-byte Ed25519 seed encoded as 64 hex characters") _, Ed25519PrivateKey, _ = _crypto() return Ed25519PrivateKey.from_private_bytes(bytes.fromhex(raw)) def _public_key_hex(private_key): serialization, _, _ = _crypto() return private_key.public_key().public_bytes( serialization.Encoding.Raw, serialization.PublicFormat.Raw, ).hex() def _sign(private_key, value): normalized = str(value or "").strip().lower() if not _HEX64.fullmatch(normalized): raise RuntimeError("value must be exactly 64 hexadecimal characters") return private_key.sign(normalized.encode("utf-8")).hex() def _json_api(base_url, method, path, body=None, headers=None, timeout=25): parsed = urllib.parse.urlparse(str(base_url or "")) host = (parsed.hostname or "").lower() if parsed.scheme != "https" and not ( parsed.scheme == "http" and host in {"127.0.0.1", "localhost", "::1"} ): return 0, {"error": "Refusing to send an Infraveil capability over a non-HTTPS control-plane URL"} data = json.dumps(body).encode("utf-8") if body is not None else None request = urllib.request.Request(base_url.rstrip("/") + path, data=data, method=method) request.add_header("User-Agent", TOOL_USER_AGENT) request.add_header("Accept", "application/json") if data is not None: request.add_header("Content-Type", "application/json") for key, value in (headers or {}).items(): if value: request.add_header(key, str(value)) try: with urllib.request.urlopen(request, timeout=timeout) as response: return response.status, json.loads(response.read().decode("utf-8") or "{}") except urllib.error.HTTPError as exc: try: return exc.code, json.loads(exc.read().decode("utf-8") or "{}") except Exception: return exc.code, {} except Exception as exc: return 0, {"error": str(exc)} def _approval_api(config, token, method, path, body=None): return _json_api( config["base_url"], method, path, body, {"X-Infraveil-Approval-Token": token}, ) def _bootstrap_api(config, token, method, path, body=None): return _json_api( config["base_url"], method, path, body, {"X-Infraveil-Bootstrap-Token": token}, ) def _log(config, message): line = time.strftime("%Y-%m-%dT%H:%M:%S%z") + " " + message print(line) path = config.get("log") if path: try: with open(path, "a", encoding="utf-8") as handle: handle.write(line + "\n") if os.name != "nt": os.chmod(path, 0o600) except Exception: pass def _load_allowlist(path): if not path or not os.path.exists(path): return set() with open(path, encoding="utf-8") as handle: return {line.strip().lower() for line in handle if _HEX64.fullmatch(line.strip().lower())} def _ask(prompt, default=""): suffix = f" [{default}]" if default else "" try: value = input(prompt + suffix + ": ").strip() except EOFError: return default return value or default def _ask_yes_no(prompt, default=False): marker = "Y/n" if default else "y/N" answer = _ask(f"{prompt} ({marker})", "y" if default else "n").lower() return answer in {"y", "yes"} def _choose_policy(config): policy = _ask("Approval policy (manual / allowlist / auto)", config.get("policy", "manual")).lower() if policy not in {"manual", "allowlist", "auto"}: raise RuntimeError("policy must be manual, allowlist, or auto") if policy == "auto": print(_col("AUTO signs every control-plane requested hash. The customer veto is not meaningful while AUTO is enabled.", "y")) if _ask("Type AUTO to enable", "").strip() != "AUTO": print(_col("Auto approval was not enabled; keeping manual policy.", "y")) policy = "manual" if policy == "allowlist": allowlist_path = config["allowlist_file"] if not os.path.exists(allowlist_path): _secure_write(allowlist_path, "") print(f"Add one approved SHA-256 hash per line to {allowlist_path}") config["policy"] = policy return policy def _choose_setup_policy(config): print(_col("\nRelease approvals", "b")) print("Manual review preserves this machine's independent veto over each new release hash.") print("Automatic approval signs every control-plane requested hash and removes that practical veto.") automatic = _ask("Type AUTO to enable automatic approval, or press Enter for manual", "").strip() == "AUTO" config["policy"] = "auto" if automatic else "manual" if automatic: print(_col("Automatic approval enabled. Use --menu to switch back to manual review.", "y")) else: print(_col("Manual approval enabled. Pending release hashes will require confirmation.", "c")) return config["policy"] def _scrub_bootstrap_token(paths, token): if not token: return for path in dict.fromkeys(os.path.abspath(value) for value in paths if value): try: with open(path, encoding="utf-8") as handle: source = handle.read() exact = f'EMBEDDED_BOOTSTRAP_TOKEN = {json.dumps(token)}' replacement = 'EMBEDDED_BOOTSTRAP_TOKEN = ""' if exact in source: _secure_write(path, source.replace(exact, replacement, 1)) if os.name != "nt": os.chmod(path, 0o700) except Exception: pass def guided_setup(home, config, source_script): print(_col("\nINFRAVEIL TRUST CONSOLE — guided setup\n", "b")) print(f"Managed directory: {home}") token = BOOTSTRAP_TOKEN or os.environ.get("INFRAVEIL_BOOTSTRAP_TOKEN", "").strip() if not token: token = getpass.getpass("Paste the one-use bootstrap code from the dashboard (hidden): ").strip() if len(token) < 32: raise RuntimeError("No valid bootstrap capability is available. Download a fresh Trust Console from the dashboard.") key_file = config["key_file"] if os.path.exists(key_file): private_key = _load_private_key(key_file) print(_col("Using the existing local approval key.", "g")) else: private_key = _generate_key(key_file) print(_col(f"Created customer approval key: {key_file}", "g")) public_key = _public_key_hex(private_key) status, challenge_body = _bootstrap_api( config, token, "POST", "/client/api/trust-console/challenge", {"pubkey": public_key}, ) if status != 200: raise RuntimeError(challenge_body.get("error") or f"bootstrap challenge failed (HTTP {status})") challenge = str(challenge_body.get("challenge") or "").lower() signature = _sign(private_key, challenge) status, complete = _bootstrap_api( config, token, "POST", "/client/api/trust-console/complete", { "pubkey": public_key, "challenge": challenge, "signature": signature, "platform": "windows" if os.name == "nt" else "linux", }, ) if status != 200: raise RuntimeError(complete.get("error") or f"bootstrap completion failed (HTTP {status})") if str(complete.get("registered_pubkey") or "").lower() != public_key: raise RuntimeError("control plane registered a different approval public key") approval_token = str(complete.get("approval_token") or "") if len(approval_token) < 32: raise RuntimeError("bootstrap response did not contain a valid scoped approval token") _secure_write(config["token_file"], approval_token + "\n") config["workspace_username"] = str(complete.get("username") or config.get("workspace_username") or "") config["launcher_host_id"] = str(complete.get("launcher_host_id") or config.get("launcher_host_id") or "") config["pending_install_token"] = str(complete.get("install_token") or "") config["pending_install_url"] = str(complete.get("install_url") or "") config["pending_install_expires_at"] = float(complete.get("install_expires_at") or 0) config.pop("reviewed_launcher_source_hash", None) _save_config(home, config) _scrub_bootstrap_token([source_script, __file__, _installed_script(home)], token) # Basic setup never turns a setup confirmation into permission for future # releases. Automatic/allowlist policies remain explicit advanced choices. config["policy"] = "manual" print(_col("\nNew releases will stay paused until you review them.", "c")) _save_config(home, config) _prepare_approval_automation(home, config) print(_col("\nTrust enrollment complete.", "g")) print(f"Public key: {public_key}") print(f"Scoped approval token: stored in {config['token_file']}") print("The private key stayed on this machine.") return complete def _verify_launcher(body, headers): source_hash = hashlib.sha256(body).hexdigest() reported_hash = str(headers.get("X-Infraveil-Launcher-Source-SHA256") or "").strip().lower() if not reported_hash or not _HEX64.fullmatch(reported_hash) or reported_hash != source_hash: raise RuntimeError("launcher download hash did not match the signed response metadata") signature = str(headers.get("X-Infraveil-Launcher-Ed25519") or "").strip().lower() if not RELEASE_PUBLIC_KEY or not _HEX64.fullmatch(RELEASE_PUBLIC_KEY) or not _HEX128.fullmatch(signature): raise RuntimeError("launcher download did not include a verifiable Infraveil release signature") _, _, Ed25519PublicKey = _crypto() try: Ed25519PublicKey.from_public_bytes(bytes.fromhex(RELEASE_PUBLIC_KEY)).verify( bytes.fromhex(signature), source_hash.encode("utf-8") ) except Exception as exc: raise RuntimeError("launcher release signature verification failed") from exc return source_hash def run_installed_launcher(home, config): launcher_path = str(config.get("launcher_file") or "") if not launcher_path or not os.path.isfile(launcher_path): raise RuntimeError("The launcher is not installed on this machine. Download a fresh Trust Console from the dashboard first.") print(_col(f"Starting the installed launcher at {launcher_path}", "c")) if config.get("policy") == "auto": print(_col("Your advanced AUTO policy is still enabled: it signs future requested hashes and removes the practical veto. Use --menu to return to manual review.", "y")) elif config.get("policy") == "allowlist": print("Your advanced allowlist policy remains active; only explicitly listed hashes are preapproved.") else: print("Later changes are not automatically approved.") print("To review releases, open a second terminal and run:") review_command = [sys.executable, _installed_script(home), "--once", "--home", home] if os.name == "nt": print(" " + subprocess.list2cmdline(review_command)) else: import shlex print(" " + shlex.join(review_command)) env = _sanitized_runtime_env(home) return subprocess.call( [sys.executable, "-I", launcher_path], cwd=os.path.dirname(launcher_path), env=env, ) def install_launcher(home, config, run_after=True): token = str(config.get("pending_install_token") or "") expires_at = float(config.get("pending_install_expires_at") or 0) install_url = str(config.get("pending_install_url") or "") username = str(config.get("workspace_username") or "") reviewed_hash = str(config.get("reviewed_launcher_source_hash") or "") selected_host = str(config.get("launcher_host_id") or "") if not _HEX64.fullmatch(reviewed_hash) or not selected_host: raise RuntimeError("Review this server's named releases before installing it. Run the console normally or use --once.") if len(token) < 32 or not install_url or not username or expires_at <= time.time(): raise RuntimeError("The one-use launcher ticket is missing or expired. Download a fresh Trust Console from the dashboard.") nonce = os.urandom(16).hex() request = urllib.request.Request(install_url, data=b"", method="POST") request.add_header("User-Agent", TOOL_USER_AGENT) request.add_header("X-Infraveil-User", username) request.add_header("X-Infraveil-Install-Token", token) request.add_header("X-Infraveil-Nonce", nonce) try: with urllib.request.urlopen(request, timeout=40) as response: body = response.read() headers = response.headers except urllib.error.HTTPError as exc: raise RuntimeError(f"launcher download failed (HTTP {exc.code})") from exc source_hash = _verify_launcher(body, headers) if source_hash != reviewed_hash or str(headers.get("X-Infraveil-Launcher-Host-ID") or "") != selected_host: raise RuntimeError("The launcher download does not match the server and exact release you reviewed. Nothing was installed or started. The one-use download ticket has been consumed: download a fresh Trust Console from this server's dashboard, run that new file, and review the new releases before installation.") launcher_path = config["launcher_file"] _secure_dir(os.path.dirname(launcher_path)) _secure_write(launcher_path, body) if os.name != "nt": os.chmod(launcher_path, 0o700) config["pending_install_token"] = "" config["pending_install_url"] = "" config["pending_install_expires_at"] = 0 _save_config(home, config) print(_col(f"Verified launcher {source_hash[:16]}… and installed it at {launcher_path}", "g")) if run_after: print(_col("The launcher is verified. Its own guided setup will continue in this terminal.", "c")) return run_installed_launcher(home, config) return 0 def run_or_install_launcher(home, config): if os.path.isfile(config["launcher_file"]): return run_installed_launcher(home, config) return install_launcher(home, config, run_after=True) def _load_approval_token(config): return _read_secret_file(config["token_file"], "approval token") def _decide(config, payload_hash, agents, allowlist): policy = config.get("policy", "manual") if policy == "auto": return True if policy == "allowlist": return payload_hash in allowlist identities = ", ".join(item.get("name") or item.get("agent_id") or item.get("launcher_host_id") or "?" for item in agents) print(f"\nRelease awaiting approval:\n hash: {payload_hash}\n requested by: {identities or '(identity unavailable)'}") return _ask_yes_no("Approve this exact hash", False) def _submit_batch(config, token, approvals): for attempt in range(APPROVAL_RETRY_ATTEMPTS): status, body = _approval_api( config, token, "POST", "/client/api/release-approval/approve-batch", {"approvals": approvals}, ) if status != 429: return status, body retry_after = max(1, min(30, int(body.get("retry_after") or 2**attempt))) if attempt + 1 < APPROVAL_RETRY_ATTEMPTS: time.sleep(retry_after) return status, body def _selected_release_snapshot(body, config): """Map protocol identities, never approval from a name or unbound hash.""" host_id = str(config.get("launcher_host_id") or "").strip() if not host_id: raise RuntimeError("This console has no selected server. Download a fresh console from that server's dashboard.") raw_pending = body.get("pending") if not isinstance(raw_pending, list) or any(not _HEX64.fullmatch(str(value)) for value in raw_pending): raise RuntimeError("The control plane returned an invalid release list; nothing was signed.") pending = set(raw_pending) launchers = body.get("launchers") agents = body.get("agents") if not isinstance(launchers, list) or not isinstance(agents, list): raise RuntimeError("Named release information is missing; nothing was signed.") selected_hosts = [row for row in launchers if isinstance(row, dict) and str(row.get("launcher_host_id") or "") == host_id] if len(selected_hosts) != 1: raise RuntimeError("The selected server is missing or ambiguous; nothing was signed.") components = [] outside = set() unbound = set() def add(row, kind, identity, field, selected, bound): value = str(row.get(field) or "") if not value: return if not _HEX64.fullmatch(value): raise RuntimeError("A named component has an invalid release hash; nothing was signed.") if not bound or not identity: unbound.add(value) return if not selected: outside.add(value) return components.append((kind, identity, str(row.get("name") or identity), str(row.get("target_runtime_version") or ""), value)) for row in launchers: if isinstance(row, dict): identity = str(row.get("launcher_host_id") or "") install_field = "install_source_hash" if row.get("install_source_hash") else "runtime_source_hash" add(row, "Server controller", identity, install_field, identity == host_id, bool(identity)) for row in agents: if isinstance(row, dict): identity = str(row.get("agent_id") or "") assigned_host = str(row.get("launcher_host_id") or "") selected = assigned_host == host_id add(row, "App runtime", identity, "runtime_source_hash", selected, bool(assigned_host)) add(row, "Application release", identity, "payload_hash", selected, bool(assigned_host)) components = tuple(sorted(set(components))) identities = {} for component in components: key = component[:2] if key in identities and identities[key] != component: raise RuntimeError("A named component has conflicting release information; nothing was signed.") identities[key] = component selected_hashes = {component[4] for component in components} install_hash = str(selected_hosts[0].get("install_source_hash") or selected_hosts[0].get("runtime_source_hash") or "") if not _HEX64.fullmatch(install_hash): raise RuntimeError("The selected server's exact install release is unavailable. Nothing was signed or started.") install_approved = selected_hosts[0].get("install_source_approved") is True required_hashes = pending & selected_hashes if not install_approved: required_hashes.add(install_hash) ambiguous = required_hashes & (outside | unbound) if ambiguous: raise RuntimeError("A release is also bound outside this server or has an unbound identity. Review it in the advanced console; nothing was signed.") unknown = pending - selected_hashes - outside required = tuple(sorted(required_hashes)) held = tuple(sorted(pending - selected_hashes)) return { "host_id": host_id, "host_name": str(selected_hosts[0].get("name") or host_id), "components": components, "required": required, "held": held, "unbound": tuple(sorted((pending & unbound) | unknown)), "launcher_source_hash": install_hash, } def _read_selected_releases(config, token, public_key): status, body = _approval_api(config, token, "GET", "/client/api/release-approval/pending") if status != 200 or not isinstance(body, dict): raise RuntimeError(f"Could not read the current releases (HTTP {status}). Nothing was signed; run --once to retry.") if str(body.get("registered_pubkey") or "").lower() != public_key: raise RuntimeError("The workspace approval key does not match this local key. Nothing was signed.") return _selected_release_snapshot(body, config) def _confirm_named_release_set(snapshot): required = set(snapshot["required"]) components = [component for component in snapshot["components"] if component[4] in required] print(_col(f"\nRelease review for {snapshot['host_name']}", "b")) for index, (kind, _identity, name, version, _digest) in enumerate(components, 1): version_text = f" — version {version}" if version and kind != "Application release" else "" print(f" {index}) {name}: {kind.lower()}{version_text}") print("Approving this list signs only these current releases. Future or changed releases still need review.") while True: answer = _ask("Approve the displayed releases? (y/N, or details to inspect exact hashes)", "n").lower() if answer in {"details", "d"}: for kind, identity, name, version, digest in components: print(f" {name} | {kind} | {identity} | {version or 'current package'}\n SHA-256 {digest}") continue return answer in {"y", "yes"} def _review_selected_releases(config): private_key = _load_private_key(config["key_file"]) public_key = _public_key_hex(private_key) token = _load_approval_token(config) snapshot = _read_selected_releases(config, token, public_key) if snapshot["held"]: _log(config, f"HELD {len(snapshot['held'])} other or unbound release hashes; this review does not approve them.") if snapshot["unbound"]: raise RuntimeError("Some releases have no confirmed server/component identity. They remain held; setup is not complete and nothing was signed.") if not snapshot["required"]: _log(config, "No pending releases were reported for this selected server.") config["reviewed_launcher_source_hash"] = snapshot["launcher_source_hash"] return 0 if not _confirm_named_release_set(snapshot): raise RuntimeError("Release approval was cancelled. Nothing was signed or started; run --once when ready.") current = _read_selected_releases(config, token, public_key) if current["unbound"] or (current["components"], current["required"]) != (snapshot["components"], snapshot["required"]): raise RuntimeError("The displayed releases changed during review. Nothing was signed; run --once to review the new list.") approvals = [{"payload_hash": digest, "signature": _sign(private_key, digest)} for digest in snapshot["required"]] for offset in range(0, len(approvals), APPROVAL_BATCH_SIZE): batch = approvals[offset:offset + APPROVAL_BATCH_SIZE] status, response = _submit_batch(config, token, batch) expected = {entry["payload_hash"] for entry in batch} acknowledged = response.get("approved") if isinstance(response, dict) else None if status != 200 or not isinstance(acknowledged, list) or set(acknowledged) != expected: raise RuntimeError(f"The exact approval batch was not confirmed (HTTP {status}). Setup is not complete; run --once to reconcile.") final = _read_selected_releases(config, token, public_key) if final["unbound"] or final["components"] != snapshot["components"] or final["required"]: raise RuntimeError("The selected releases are still pending or changed after approval. Setup is not complete; run --once to review them.") _log(config, f"APPROVED {len(approvals)} displayed exact release hashes. Future changes remain manual.") config["reviewed_launcher_source_hash"] = final["launcher_source_hash"] return 0 def approve_pending(config, once=False): if config.get("policy", "manual") == "manual": while True: _review_selected_releases(config) if once: return 0 _sleep(config) private_key = _load_private_key(config["key_file"]) public_key = _public_key_hex(private_key) token = _load_approval_token(config) _log(config, f"trust console started | policy={config.get('policy')} | public_key={public_key[:16]}…") while True: status, body = _approval_api(config, token, "GET", "/client/api/release-approval/pending") if status in {401, 403}: _log(config, "ERROR: scoped approval token rejected. Download a fresh Trust Console to reconnect.") return 1 if once else _sleep(config) if status != 200: _log(config, f"WARN: pending release check failed (HTTP {status}): {body.get('error', '')}") if once: return 1 _sleep(config) continue registered = str(body.get("registered_pubkey") or "").lower() if registered != public_key: _log(config, "REFUSING: the workspace public key does not match this local private key.") return 1 pending = [str(value).lower() for value in body.get("pending") or [] if _HEX64.fullmatch(str(value).lower())] identities = {} for item in list(body.get("agents") or []) + list(body.get("launchers") or []): for key in ("payload_hash", "runtime_source_hash"): payload_hash = str(item.get(key) or "").lower() if payload_hash: identities.setdefault(payload_hash, []).append(item) allowlist = _load_allowlist(config.get("allowlist_file")) approvals = [] if not pending: _log(config, "ok: nothing pending; desired releases are approved.") for payload_hash in pending: if _decide(config, payload_hash, identities.get(payload_hash, []), allowlist): approvals.append({"payload_hash": payload_hash, "signature": _sign(private_key, payload_hash)}) else: _log(config, f"HELD {payload_hash[:16]}…") for offset in range(0, len(approvals), APPROVAL_BATCH_SIZE): batch = approvals[offset : offset + APPROVAL_BATCH_SIZE] status, response = _submit_batch(config, token, batch) if status != 200: _log(config, f"FAILED signed batch (HTTP {status}): {response.get('error', '')}") if once: return 1 else: _log(config, f"APPROVED {int(response.get('approved_count') or len(batch))} exact release hashes") if once: return 0 _sleep(config) def _approval_service_slug(config): value = str(config.get("workspace_username") or config.get("launcher_host_id") or "workspace").lower() value = re.sub(r"[^a-z0-9.-]+", "-", value).strip(".-") return (value or "workspace")[:48] def _approval_service_label(config): return "com.infraveil.approver." + _approval_service_slug(config) def _mac_approval_service(home, config): logs_dir = _path(home, "logs") return { "Label": _approval_service_label(config), "ProgramArguments": [ _venv_python(home), "-I", "-u", _installed_script(home), "--watch", "--home", home, ], "WorkingDirectory": home, "EnvironmentVariables": { "INFRAVEIL_CONTROL_HOME": home, "PATH": "/opt/homebrew/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin", }, "RunAtLoad": True, "KeepAlive": {"SuccessfulExit": False}, "ThrottleInterval": 10, "ProcessType": "Background", "Umask": 0o077, "StandardOutPath": _path(logs_dir, "approver.stdout.log"), "StandardErrorPath": _path(logs_dir, "approver.stderr.log"), } def _start_auto_approval_watcher(home, config): if config.get("policy") != "auto": return _secure_dir(_path(home, "logs")) if platform.system().lower() == "darwin": label = _approval_service_label(config) domain = f"gui/{os.getuid()}" service_path = os.path.expanduser(f"~/Library/LaunchAgents/{label}.plist") service = _mac_approval_service(home, config) _secure_write(service_path, plistlib.dumps(service, fmt=plistlib.FMT_XML).decode("utf-8")) subprocess.run( ["launchctl", "bootout", f"{domain}/{label}"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, check=False, ) subprocess.run( ["launchctl", "enable", f"{domain}/{label}"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, check=False, ) subprocess.check_call(["launchctl", "bootstrap", domain, service_path]) print(_col("Automatic release approval is running in the background.", "g")) return pid_file = _path(home, "approval-watcher.pid") try: existing_pid = int(_read_secret_file(pid_file, "approval watcher PID") or 0) if existing_pid > 1: os.kill(existing_pid, 0) return except Exception: pass stdout_path = _path(home, os.path.join("logs", "approver.stdout.log")) stderr_path = _path(home, os.path.join("logs", "approver.stderr.log")) popen_options = { "cwd": home, "env": _sanitized_runtime_env(home), "stdin": subprocess.DEVNULL, "close_fds": True, } if os.name == "nt": popen_options["creationflags"] = subprocess.CREATE_NEW_PROCESS_GROUP | subprocess.DETACHED_PROCESS else: popen_options["start_new_session"] = True with open(stdout_path, "ab", buffering=0) as stdout_handle, open(stderr_path, "ab", buffering=0) as stderr_handle: process = subprocess.Popen( [_venv_python(home), "-I", "-u", _installed_script(home), "--watch", "--home", home], stdout=stdout_handle, stderr=stderr_handle, **popen_options, ) _secure_write(pid_file, str(process.pid) + "\n") print(_col("Automatic release approval is running in the background for this login session.", "g")) def _stop_auto_approval_watcher(home, config): if platform.system().lower() == "darwin": label = _approval_service_label(config) domain = f"gui/{os.getuid()}" service_path = os.path.expanduser(f"~/Library/LaunchAgents/{label}.plist") subprocess.run( ["launchctl", "bootout", f"{domain}/{label}"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, check=False, ) try: os.remove(service_path) except FileNotFoundError: pass return pid_file = _path(home, "approval-watcher.pid") try: process_id = int(_read_secret_file(pid_file, "approval watcher PID") or 0) if process_id > 1: os.kill(process_id, 15) except Exception: pass try: os.remove(pid_file) except FileNotFoundError: pass def _prepare_approval_automation(home, config): if config.get("policy") == "auto": if approve_pending(config, once=True) != 0: raise RuntimeError("Could not verify the initial release-approval state") _start_auto_approval_watcher(home, config) else: _stop_auto_approval_watcher(home, config) if approve_pending(config, once=True) != 0: raise RuntimeError("Could not complete the manual release review") def _sleep(config): time.sleep(max(5, int(config.get("interval") or 30))) return 0 def _status(home, config): print(_col("\nINFRAVEIL TRUST CONSOLE\n", "b")) print(f" Managed home {home}") print(f" Approval key {'READY' if os.path.isfile(config['key_file']) else 'NOT SET'}") print(f" Approval token {'READY' if os.path.isfile(config['token_file']) else 'NOT SET'}") print(f" Policy {config.get('policy', 'manual')}") print(f" Launcher {'INSTALLED' if os.path.isfile(config['launcher_file']) else 'NOT INSTALLED'}") print(f" Workspace {config.get('workspace_username') or 'not connected'}") def interactive_menu(home, config, source_script): _enable_ansi() while True: _status(home, config) print("\n 1) Guided trust setup") print(" 2) Sign one challenge or release hash") print(" 3) Review pending releases once") print(" 4) Watch for pending releases") print(" 5) Choose approval policy") if os.path.isfile(config["launcher_file"]): print(" 6) Run installed launcher on this machine") else: print(" 6) Install and run launcher on this machine") print(" 7) Show security model") print(" 0) Quit") choice = _ask("Choose", "0").lower() try: if choice == "1": complete = guided_setup(home, config, source_script) if complete.get("install_token") and _ask_yes_no( "Install the launcher on this same machine now (keep the approval key on a separate admin machine for the strongest veto)", False, ): install_launcher(home, config, run_after=True) elif choice == "2": value = _ask("64-character challenge or release hash").lower() print("Signature:\n " + _sign(_load_private_key(config["key_file"]), value)) elif choice == "3": approve_pending(config, once=True) elif choice == "4": approve_pending(config, once=False) elif choice == "5": _choose_policy(config) _save_config(home, config) _prepare_approval_automation(home, config) elif choice == "6": _review_selected_releases(config) run_or_install_launcher(home, config) elif choice == "7": print("\nThe private Ed25519 key stays in this directory. Infraveil receives only the public key and signatures over exact SHA-256 hashes.") print("Manual and allowlist policies preserve a customer veto. Auto policy intentionally gives that veto up while enabled.") print("For the strongest boundary, keep this console on an admin workstation and run the launcher on a different server.\n") elif choice in {"0", "q", "quit", "exit"}: return 0 except KeyboardInterrupt: print("\nCancelled.") except Exception as exc: print(_col(f"ERROR: {exc}", "r")) def _run_state_aware_default(home, config, source_script): enrolled = os.path.isfile(config["key_file"]) and os.path.isfile(config["token_file"]) # A new dashboard capability must be honored even after an earlier setup # consumed its ticket. guided_setup reuses, never rotates, the local key. if BOOTSTRAP_TOKEN or not enrolled: if not BOOTSTRAP_TOKEN: print(_col("This is the public Trust Console source, so it has no workspace bootstrap capability.", "y")) print("Open Connect & review in the Infraveil dashboard and click Connect server.") return 1 print(_col("Fresh Trust Console download detected. Starting secure workspace setup automatically.", "c")) complete = guided_setup(home, config, source_script) if complete.get("install_token"): print(_col("Trust is ready. Installing and starting the launcher now.", "c")) return install_launcher(home, config, run_after=True) print(_col("Trust setup is complete, but the launcher ticket was not returned. Download a fresh Trust Console to retry installation.", "y")) return 0 install_ready = ( not os.path.isfile(config["launcher_file"]) and len(str(config.get("pending_install_token") or "")) >= 32 and float(config.get("pending_install_expires_at") or 0) > time.time() ) if install_ready: print(_col("Trust enrollment is complete and the launcher install is ready.", "c")) _prepare_approval_automation(home, config) if config.get("policy", "manual") != "manual": # Advanced policy processing is not itself a selected-host install # proof. Reconcile the named current set before the install gate. _review_selected_releases(config) return install_launcher(home, config, run_after=True) if os.path.isfile(config["launcher_file"]): print(_col("Trust and launcher are ready. Starting Infraveil.", "c")) _prepare_approval_automation(home, config) return run_installed_launcher(home, config) print(_col("The launcher is not installed and its one-use install ticket is missing or expired.", "y")) print("Download a fresh Trust Console from the dashboard and run that new file. Your existing approval key will be reused.") return 1 def _parser(): parser = argparse.ArgumentParser(description="Infraveil Trust Console") parser.add_argument("--home", help="managed console directory (default: ./infraveil-control)") parser.add_argument("--menu", action="store_true", help="open the advanced numbered trust console") parser.add_argument("--setup", action="store_true", help="complete guided dashboard bootstrap") parser.add_argument("--genkey", action="store_true", help="generate the local approval key and exit") parser.add_argument("--out", help="private-key output path for --genkey") parser.add_argument("--sign", "--hash", dest="sign_value", help="sign one 64-character challenge or release hash") parser.add_argument("--key-file", help="private key used by --sign") parser.add_argument("--once", action="store_true", help="review pending releases once") parser.add_argument("--watch", action="store_true", help="continuously review pending releases") parser.add_argument("--install-launcher", action="store_true", help="consume the pending one-use launcher ticket") parser.add_argument("--no-run", action="store_true", help="download and verify the launcher without running it") parser.add_argument("--prepare-runtime", action="store_true", help="prepare only the private hash-locked runtime without approval or key actions") return parser def main(argv=None): argv = list(sys.argv[1:] if argv is None else argv) args = _parser().parse_args(argv) home = _control_home(args.home) if args.prepare_runtime: python_path = _prepare_runtime(home) print(json.dumps({"python": python_path, "lock_sha256": _runtime_lock_identity(), "verified": True}, sort_keys=True)) return 0 _secure_dir(home) installed = _install_self(home) source_script = os.path.realpath(__file__) if BOOTSTRAP_TOKEN and os.path.abspath(source_script) != os.path.abspath(installed): _scrub_bootstrap_token([source_script], BOOTSTRAP_TOKEN) _ensure_runtime(home, installed, argv) config = _load_config(home) source_script = os.path.realpath(__file__) if args.menu: return interactive_menu(home, config, source_script) if args.genkey: path = os.path.abspath(os.path.expanduser(args.out or config["key_file"])) private_key = _generate_key(path) print(f"PRIVATE KEY written to {path}; keep it private and backed up.") print("PUBLIC KEY:\n " + _public_key_hex(private_key)) return 0 if args.sign_value: key_file = os.path.abspath(os.path.expanduser(args.key_file or config["key_file"])) print("SIGNATURE:\n " + _sign(_load_private_key(key_file), args.sign_value)) return 0 if args.setup: complete = guided_setup(home, config, source_script) print("Run this file again to review approvals or install the launcher.") return 0 if complete else 1 if args.once or args.watch: return approve_pending(config, once=args.once) if args.install_launcher: _review_selected_releases(config) return install_launcher(home, config, run_after=not args.no_run) return _run_state_aware_default(home, config, source_script) if __name__ == "__main__": try: raise SystemExit(main()) except KeyboardInterrupt: print("\nStopped. No unsigned release was approved.") raise SystemExit(130) except Exception as exc: print(_col(f"ERROR: {exc}", "r"), file=sys.stderr) raise SystemExit(1)