+
    Dfj3                        R t ^ RIt^ RIHt ^ RIHt  ^ RIt]t ^ RI	H
tHt ]]utt
^ RIHtHt ^ RIHt  ! R R4      t ! R	 R
]P(                  4      t ! R R]4      t ! R R]4      t]
e    ! R R]
P0                  4      t ! R R]4      t ! R R]4      t ! R R]4      t ! R R]4      t ! R R]4      tR#   ] d    Rt Li ; i  ] d    R;tt
 Li ; i)z'
Tests for L{twisted.conch.ssh.agent}.
N)iosim)unittest)agentkeys)
ConchErrorMissingKeyStoreError)keydatac                   *   a  ] tR t^t o RtR tRtV tR# )StubFactoryzV
Mock factory that provides the keys attribute required by the
SSHAgentServerProtocol
c                    / V n         R # Nr   selfs   &?/usr/lib/python3/dist-packages/twisted/conch/test/test_agent.py__init__StubFactory.__init__%   s	    	    r   N)__name__
__module____qualname____firstlineno____doc__r   __static_attributes____classdictcell____classdict__s   @r   r
   r
      s     
 r   r
   c                   >   a  ] tR t^)t o Rt]e   ]f   RtR tRt	V t
R# )AgentTestBasez"
Tests for SSHAgentServer/Client.
NzCannot run without cryptographyc                T   \         P                  ! \        P                  \        P                  4      w  V n        V n        V n        \        4       V P                  n	        \        P                  P                  \        P                  4      V n        \        P                  P                  \        P                   4      V n        \        P                  P                  \        P$                  4      V n        \        P                  P                  \        P(                  4      V n        R # r   )r   connectedServerAndClientr   SSHAgentServerSSHAgentClientclientserverpumpr
   factoryr   Key
fromStringr   privateRSA_openssh
rsaPrivateprivateDSA_openssh
dsaPrivatepublicRSA_openssh	rsaPublicpublicDSA_openssh	dsaPublicr   s   &r   setUpAgentTestBase.setUp1   s    .3.L.L  %"6"6/
+T[$) *m ((--g.H.HI((--g.H.HI,,W-F-FG,,W-F-FGr   )r#   r,   r0   r%   r*   r.   r$   )r   r   r   r   r   r   r   skipr1   r   r   r   s   @r   r   r   )   s&      }0H Hr   r   c                   *   a  ] tR t^Ct o RtR tRtV tR# )&ServerProtocolContractWithFactoryTestsz
The server protocol is stateful and so uses its factory to track state
across requests.  This test asserts that the protocol raises if its factory
doesn't provide the necessary storage for that state.
c                    \         P                  ! R ^\        P                  4      pV P                  P
                  P                  R V P                  \        V P                  P                  V4       R# )z!LBr   N)
structpackr   AGENTC_REQUEST_IDENTITIESr$   r&   __dict__assertRaisesr   dataReceived)r   msgs   & r   /test_factorySuppliesKeyStorageForServerProtocolVServerProtocolContractWithFactoryTests.test_factorySuppliesKeyStorageForServerProtocolJ   sO    kk%E$C$CDKK((0.0H0H#Nr    N)r   r   r   r   r   r>   r   r   r   s   @r   r5   r5   C   s     O Or   r5   c                   6   a  ] tR t^Qt o RtR tR tR tRtV t	R# )"UnimplementedVersionOneServerTestsa  
Tests for methods with no-op implementations on the server. We need these
for clients, such as openssh, that try v1 methods before going to v2.

Because the client doesn't expose these operations with nice method names,
we invoke sendRequest directly with an op code.
c                   a  S P                   P                  \        P                  R4      pS P                  P                  4        V 3R lpVP                  V4      # )zF
assert that we get the correct op code for an RSA identities request
r   c                 h   < SP                  \        P                  \        V R ,          4      4       R# ):       NN)assertEqualr   AGENT_RSA_IDENTITIES_ANSWERord)packetr   s   &r   _cbRUnimplementedVersionOneServerTests.test_agentc_REQUEST_RSA_IDENTITIES.<locals>._cba   s"    U>>F3K@PQr   )r#   sendRequestr   AGENTC_REQUEST_RSA_IDENTITIESr%   flushaddCallback)r   drK   s   f  r   "test_agentc_REQUEST_RSA_IDENTITIESEUnimplementedVersionOneServerTests.test_agentc_REQUEST_RSA_IDENTITIESZ   sF     KK##E$G$GM			R }}S!!r   c                    V P                   P                  \        P                  R4      pV P                  P                  4        VP                  V P                  R4      # )zK
assert that we get the correct op code for an RSA remove identity request
r   )r#   rM   r   AGENTC_REMOVE_RSA_IDENTITYr%   rO   rP   rG   r   rQ   s   & r   test_agentc_REMOVE_RSA_IDENTITYBUnimplementedVersionOneServerTests.test_agentc_REMOVE_RSA_IDENTITYf   sE     KK##E$D$DcJ		}}T--s33r   c                    V P                   P                  \        P                  R4      pV P                  P                  4        VP                  V P                  R4      # )zR
assert that we get the correct op code for an RSA remove all identities
request.
r   )r#   rM   r    AGENTC_REMOVE_ALL_RSA_IDENTITIESr%   rO   rP   rG   rV   s   & r   %test_agentc_REMOVE_ALL_RSA_IDENTITIESHUnimplementedVersionOneServerTests.test_agentc_REMOVE_ALL_RSA_IDENTITIESn   sE    
 KK##E$J$JCP		}}T--s33r   r@   N)
r   r   r   r   r   rR   rW   r[   r   r   r   s   @r   rB   rB   Q   s     
"44 4r   rB   c                   0   a  ] tR t^zt o RtR tR tRtV tR# )CorruptServerz
A misbehaving server that returns bogus response op codes so that we can
verify that our callbacks that deal with these op codes handle such
miscreants.
c                *    V P                  ^R4       R#    r   NsendResponser   datas   &&r   agentc_REQUEST_IDENTITIES'CorruptServer.agentc_REQUEST_IDENTITIES       c3'r   c                *    V P                  ^R4       R# r`   rb   rd   s   &&r   agentc_SIGN_REQUEST!CorruptServer.agentc_SIGN_REQUEST   rh   r   r@   N)	r   r   r   r   r   rf   rj   r   r   r   s   @r   r^   r^   z   s     		(	( 	(r   r^   c                   6   a  ] tR t^t o RtR tR tR tRtV t	R# )ClientWithBrokenServerTestszE
verify error handling code in the client using a misbehaving server
c                    \         P                  V 4       \        P                  ! \        \
        P                  4      w  V n        V n        V n	        \        4       V P                  n        R # r   )r   r1   r   r    r^   r   r"   r#   r$   r%   r
   r&   r   s   &r   r1   !ClientWithBrokenServerTests.setUp   sH    D!.3.L.L5///
+T[$)
 *mr   c                    V P                   P                  V P                  P                  4       R4      pV P                  P                  4        V P                  V\        4      # )z
Assert that L{SSHAgentClient.signData} raises a ConchError
if we get a response from the server whose opcode doesn't match
the protocol for data signing requests.
   John Hancock)r#   signDatar.   blobr%   rO   assertFailurer   rV   s   & r   "test_signDataCallbackErrorHandling>ClientWithBrokenServerTests.test_signDataCallbackErrorHandling   sH     KK  !4!4!6H		!!!Z00r   c                    V P                   P                  4       pV P                  P                  4        V P	                  V\
        4      # )z
Assert that L{SSHAgentClient.requestIdentities} raises a ConchError
if we get a response from the server whose opcode doesn't match
the protocol for identity requests.
)r#   requestIdentitiesr%   rO   rt   r   rV   s   & r   +test_requestIdentitiesCallbackErrorHandlingGClientWithBrokenServerTests.test_requestIdentitiesCallbackErrorHandling   s7     KK))+		!!!Z00r   )r#   r%   r$   N)
r   r   r   r   r   r1   ru   ry   r   r   r   s   @r   rm   rm      s     ,11 1r   rm   c                   <   a  ] tR t^t o RtR tR tR tR tRt	V t
R# )AgentKeyAdditionTestsz4
Test adding different flavors of keys to an agent.
c                   a  S P                   P                  S P                  P                  4       4      pS P                  P                  4        V 3R lpVP                  V4      # )  
L{SSHAgentClient.addIdentity} adds the private key it is called
with to the SSH agent server to which it is connected, associating
it with the comment it is called with.

This test asserts that omitting the comment produces an
empty string for the comment on the server.
c                    < SP                   P                  P                  SP                  P	                  4       ,          pSP                  SP                  V^ ,          4       SP                  RV^,          4       R# rE   r   Nr$   r&   r   r*   rs   rG   ignored	serverKeyr   s   & r   _checkBAgentKeyAdditionTests.test_addRSAIdentityNoComment.<locals>._check   V    ++001E1E1GHIT__il;S)A,/r   r#   addIdentityr*   privateBlobr%   rO   rP   r   rQ   r   s   f  r   test_addRSAIdentityNoComment2AgentKeyAdditionTests.test_addRSAIdentityNoComment   J     KK##DOO$?$?$AB			0
 }}V$$r   c                   a  S P                   P                  S P                  P                  4       4      pS P                  P                  4        V 3R lpVP                  V4      # )r~   c                    < SP                   P                  P                  SP                  P	                  4       ,          pSP                  SP                  V^ ,          4       SP                  RV^,          4       R# r   r$   r&   r   r,   rs   rG   r   s   & r   r   BAgentKeyAdditionTests.test_addDSAIdentityNoComment.<locals>._check   r   r   r#   r   r,   r   r%   rO   rP   r   s   f  r   test_addDSAIdentityNoComment2AgentKeyAdditionTests.test_addDSAIdentityNoComment   r   r   c                   a  S P                   P                  S P                  P                  4       RR7      pS P                  P                  4        V 3R lpVP                  V4      # )  
L{SSHAgentClient.addIdentity} adds the private key it is called
with to the SSH agent server to which it is connected, associating
it with the comment it is called with.

This test asserts that the server receives/stores the comment
as sent by the client.
   My special keycommentc                    < SP                   P                  P                  SP                  P	                  4       ,          pSP                  SP                  V^ ,          4       SP                  RV^,          4       R# rE   r   Nr   r   s   & r   r   DAgentKeyAdditionTests.test_addRSAIdentityWithComment.<locals>._check   W    ++001E1E1GHIT__il;.	!=r   r   r   s   f  r   test_addRSAIdentityWithComment4AgentKeyAdditionTests.test_addRSAIdentityWithComment   W     KK##OO'')3D $ 
 				>
 }}V$$r   c                   a  S P                   P                  S P                  P                  4       RR7      pS P                  P                  4        V 3R lpVP                  V4      # )r   r   r   c                    < SP                   P                  P                  SP                  P	                  4       ,          pSP                  SP                  V^ ,          4       SP                  RV^,          4       R# r   r   r   s   & r   r   DAgentKeyAdditionTests.test_addDSAIdentityWithComment.<locals>._check   r   r   r   r   s   f  r   test_addDSAIdentityWithComment4AgentKeyAdditionTests.test_addDSAIdentityWithComment   r   r   r@   N)r   r   r   r   r   r   r   r   r   r   r   r   s   @r   r|   r|      s#     %&%&%*% %r   r|   c                   &   a  ] tR tRt o R tRtV tR# )AgentClientFailureTestsi  c                    V P                   P                  ^R4      pV P                  P                  4        V P	                  V\
        4      # )z;
verify that the client raises ConchError on AGENT_FAILURE
r   )r#   rM   r%   rO   rt   r   rV   s   & r   test_agentFailure)AgentClientFailureTests.test_agentFailure  s;     KK##C-		!!!Z00r   r@   N)r   r   r   r   r   r   r   r   s   @r   r   r     s     1 1r   r   c                   B   a  ] tR tRt o RtR tR tR tR tR t	Rt
V tR	# )
AgentIdentityRequestsTestsi  zB
Test operations against a server with identities already loaded.
c                L   \         P                  V 4       V P                  R 3V P                  P                  P
                  V P                  P                  4       &   V P                  R3V P                  P                  P
                  V P                  P                  4       &   R# 	   a comment   another commentNr   r1   r,   r$   r&   r   rs   r*   r   s   &r   r1    AgentIdentityRequestsTests.setUp  x    D!OO<
  !5!5!78
 OO<
  !5!5!78r   c                r   V P                   P                  V P                  P                  4       R4      pV P                  P                  4        V P                  V4      pV P                  P                  R4      pV P                  W24       V P                  V P                  P                  VR4      4       R# )zK
Sign data with an RSA private key and then verify it with the public
key.
rq   N)r#   rr   r.   rs   r%   rO   successResultOfr*   signrG   
assertTrueverify)r   rQ   	signatureexpecteds   &   r   test_signDataRSA+AgentIdentityRequestsTests.test_signDataRSA  s    
 KK  !4!4!6H		((+	??''8---iIJr   c                   a  S P                   P                  S P                  P                  4       R4      pS P                  P                  4        V 3R lpVP                  V4      # )zJ
Sign data with a DSA private key and then verify it with the public
key.
rq   c                 ^   < SP                  SP                  P                  V R 4      4       R# )rq   N)r   r0   r   )sigr   s   &r   r   ;AgentIdentityRequestsTests.test_signDataDSA.<locals>._check0  s"     OODNN11#GHr   )r#   rr   r0   rs   r%   rO   rP   r   s   f  r   test_signDataDSA+AgentIdentityRequestsTests.test_signDataDSA(  sM    
 KK  !4!4!6H			I }}V$$r   c                <   V P                   P                  P                  V P                  P	                  4        V P
                  P                  V P                  P	                  4       R4      pV P                  P                  4        V P                  V\        4      # )zU
Assert that we get an errback if we try to sign data using a key that
wasn't added.
rq   )r$   r&   r   r.   rs   r#   rr   r%   rO   rt   r   rV   s   & r   $test_signDataRSAErrbackOnUnknownBlob?AgentIdentityRequestsTests.test_signDataRSAErrbackOnUnknownBlob8  sm    
 KK$$T^^%8%8%:;KK  !4!4!6H		!!!Z00r   c                   a  S P                   P                  4       pS P                  P                  4        V 3R lpVP	                  V4      # )ze
Assert that we get all of the keys/comments that we add when we issue a
request for all identities.
c                 8  < / pR VSP                   P                  4       &   RVSP                  P                  4       &   / pV  FC  pV^,          V\        P                  P                  V^ ,          RR7      P                  4       &   KE  	  SP                  W4       R# )r   r   rs   )typeN)r0   rs   r.   r   r'   r(   rG   )keytr   receivedkr   s   &   r   r   AAgentIdentityRequestsTests.test_requestIdentities.<locals>._checkJ  s    H.:HT^^((*+.@HT^^((*+HJKA$,,QqT,?DDFG X0r   )r#   rx   r%   rO   rP   r   s   f  r   test_requestIdentities1AgentIdentityRequestsTests.test_requestIdentitiesB  s;    
 KK))+			1 }}V$$r   r@   N)r   r   r   r   r   r1   r   r   r   r   r   r   r   s   @r   r   r     s)     	
K% 1% %r   r   c                   <   a  ] tR tRt o RtR tR tR tR tRt	V t
R# )	AgentKeyRemovalTestsiW  z4
Test support for removing keys in a remote server.
c                L   \         P                  V 4       V P                  R 3V P                  P                  P
                  V P                  P                  4       &   V P                  R3V P                  P                  P
                  V P                  P                  4       &   R# r   r   r   s   &r   r1   AgentKeyRemovalTests.setUp\  r   r   c                   a  S P                   P                  S P                  P                  4       4      pS P                  P                  4        V 3R lpVP                  V4      # )z,
Assert that we can remove an RSA identity.
c                   < SP                  ^\        SP                  P                  P                  4      4       SP                  SP                  P                  4       SP                  P                  P                  4       SP                  SP                  P                  4       SP                  P                  P                  4       R# rF   N)
rG   lenr$   r&   r   assertInr,   rs   assertNotInr*   r   r   s   &r   r   ;AgentKeyRemovalTests.test_removeRSAIdentity.<locals>._checko  s    QDKK$7$7$<$< =>MM$//..0$++2E2E2J2JKT__113T[[5H5H5M5MNr   )r#   removeIdentityr*   rs   r%   rO   rP   r   s   f  r   test_removeRSAIdentity+AgentKeyRemovalTests.test_removeRSAIdentityg  sK    
 KK&&t';';'=>			O
 }}V$$r   c                   a  S P                   P                  S P                  P                  4       4      pS P                  P                  4        V 3R lpVP                  V4      # )z+
Assert that we can remove a DSA identity.
c                 
  < SP                  ^\        SP                  P                  P                  4      4       SP                  SP                  P                  4       SP                  P                  P                  4       R# r   )rG   r   r$   r&   r   r   r*   rs   r   s   &r   r   ;AgentKeyRemovalTests.test_removeDSAIdentity.<locals>._check~  sS    QDKK$7$7$<$< =>MM$//..0$++2E2E2J2JKr   )r#   r   r,   rs   r%   rO   rP   r   s   f  r   test_removeDSAIdentity+AgentKeyRemovalTests.test_removeDSAIdentityv  sK    
 KK&&t';';'=>			L }}V$$r   c                   a  S P                   P                  4       pS P                  P                  4        V 3R lpVP	                  V4      # )z+
Assert that we can remove all identities.
c                 z   < SP                  ^ \        SP                  P                  P                  4      4       R# )rE   N)rG   r   r$   r&   r   r   s   &r   r   =AgentKeyRemovalTests.test_removeAllIdentities.<locals>._check  s(    QDKK$7$7$<$< =>r   )r#   removeAllIdentitiesr%   rO   rP   r   s   f  r   test_removeAllIdentities-AgentKeyRemovalTests.test_removeAllIdentities  s;     KK++-			? }}V$$r   r@   N)r   r   r   r   r   r1   r   r   r   r   r   r   s   @r   r   r   W  s#     	
%%
% 
%r   r   )r   r7   twisted.testr   twisted.trialr   cryptography_cryptographyImportErrortwisted.conch.sshr   _agentr   _keystwisted.conch.errorr   r   twisted.conch.testr   r
   TestCaser   r5   rB   r!   r^   rm   r|   r   r   r   r@   r   r   <module>r      s     "!( !L @ KD% @ & HH%% H4O] O$4 $4N 	(,, ( 1-  1FS%M S%l1m 1I% I%X7%= 7%Q
  L  D5s"   B= C =	C	C	CC