+
    Dfj)2              
       ^   R t ^ RIHtHtHt ^ RIHtHt ^ RIH	t	H
t
 ^ RIHtHtHt ^ RIHt ^ RIHtHtHt ^ RIHtHtHt ^ RIHtHtHt ^ R	IHt ^ R
IH t H!t!H"t" ^ RI#H$t$ ^ RI%H&t& ^ RI'H(t( ^ RI)H*t*  ^ RI+H,t, ^ RI-H.t.H/t/H0t0  ! R R4      t2 ! R R4      t3]! ]4       ! R R4      4       t4 ! R R]]34      t5 ! R R4      t6 ! R R]2]]4      t7 ! R R]]34      t8 ! R  R!]2]]3]]64      t9 ! R" R#]2]3]6]!]"]4      t:];! 4       Py                  ]9P{                  4       4       ];! 4       Py                  ]7P{                  4       4       ];! 4       Py                  ]:! 4       P{                  4       4        ! R$ R%]] ]34      t>];! 4       Py                  ]>P{                  4       4       R#   ]1 d    Rt, EL'i ; i)&z0
Tests for implementations of L{ITLSTransport}.
)OptionalSequenceType)	Interfaceimplementer)DeferredDeferredList)SSL4ClientEndpointSSL4ServerEndpointTCP4ClientEndpoint)ConnectionClosed)IReactorSSLIStreamClientEndpointITLSTransport)ClientFactoryProtocolServerFactory)BrokenContextFactoryConnectionTestsMixinEndpointCreator)ReactorBuilder)AbortConnectionMixinConnectToTCPListenerMixinStreamTransportTestsMixin)networkString)FilePath)platform)SkipTest)FILETYPE_PEM)ClientContextFactoryKeyPairPrivateCertificateNc                   p   a  ] tR t^2t o ].t]P                  ! 4       '       d	   RtR]R]/t	V 3R lt
RtV tR# )TLSMixinzcFor some reason, these reactors don't deal with SSL disconnection correctly on Windows.  See #3371.z*twisted.internet.glib2reactor.Glib2Reactorz(twisted.internet.gtk2reactor.Gtk2Reactorc                V   < V ^8  d   Qh/ S[ S[S[S[,          ,          ,          ;R&   # )   requiredInterfaces)r   r   r   r   )format__classdict__s   "@/usr/lib/python3/dist-packages/twisted/internet/test/test_tls.py__annotate__TLSMixin.__annotate__2   s      $y/!:;K      N)__name__
__module____qualname____firstlineno__r   r&   r   	isWindowsmsgskippedReactors__annotate_func____static_attributes____classdictcell__r(   s   @r)   r#   r#   2   s@     ?Jm> 	
 9#6
  r,   r#   c                      a  ] tR t^@t o ^ RIt]! ]! ]P                  4      4      P                  R4      P                  R4      t
AR tR tRtV tR# )ContextGeneratingMixinNs   tests
   server.pemc                    V P                   P                  4       p\        P                  ! V\        P                  ! V\
        4      \
        4      pVP                  4       # )z=
Return a new SSL context suitable for use in a test server.
)_pem
getContentr!   loadr    r   options)selfpemcerts   &  r)   getServerContext'ContextGeneratingMixin.getServerContextH   sF     ii""$!&&c<0,
 ||~r,   c                    \        4       # N)r   r@   s   &r)   getClientContext'ContextGeneratingMixin.getClientContextR   s    #%%r,   r-   )r.   r/   r0   r1   twistedr   r   __file__siblingchildr<   rC   rH   r6   r7   r8   s   @r)   r:   r:   @   sL      	w//0199'BHHW 	 	& &r,   r:   c                   0   a  ] tR t^Vt o RtR tR tRtV tR# )StartTLSClientEndpointa	  
An endpoint which wraps another one and adds a TLS layer immediately when
connections are set up.

@ivar wrapped: A L{IStreamClientEndpoint} provider which will be used to
    really set up connections.

@ivar contextFactory: A L{ContextFactory} to use to do TLS.
c                    Wn         W n        R # rF   )wrappedcontextFactory)r@   rQ   rR   s   &&&r)   __init__StartTLSClientEndpoint.__init__b   s    ,r,   c                l   a a  ! VV 3R lR\         4      pS P                  P                  V! 4       4      # )z
Establish a connection using a protocol build by C{factory} and
immediately start TLS on it.  Return a L{Deferred} which fires with the
protocol instance.
c                   0   <a  ] tR t^ot o VV3R ltRtV tR# )6StartTLSClientEndpoint.connect.<locals>.WrapperFactoryc                b   <a SP                  V4      oSP                  3VV3R  llpVSn        S# )c                 `   < SP                   P                  SP                  4       V ! 4        R # rF   )	transportstartTLSrR   )origprotocolr@   s   &r)   connectionMade\StartTLSClientEndpoint.connect.<locals>.WrapperFactory.buildProtocol.<locals>.connectionMades   s"    &&//0C0CDFr,   )buildProtocolr^   )wrapperSelfaddrr^   r]   factoryr@   s   && @r)   r`   DStartTLSClientEndpoint.connect.<locals>.WrapperFactory.buildProtocolp   s5    "006(0(?(?   +9'r,   r-   N)r.   r/   r0   r1   r`   r6   r7   )r(   rc   r@   s   @r)   WrapperFactoryrW   o   s        r,   re   )r   rQ   connect)r@   rc   re   s   ff r)   rf   StartTLSClientEndpoint.connectf   s.    		  		 ] 		  ||##N$455r,   )rR   rQ   N)	r.   r/   r0   r1   __doc__rS   rf   r6   r7   r8   s   @r)   rO   rO   V   s     -6 6r,   rO   c                   0   a  ] tR t^}t o RtR tR tRtV tR# )StartTLSClientCreatorzo
Create L{ITLSTransport.startTLS} endpoint for the client, and normal SSL
for server just because it's easier.
c                8    \        V^ V P                  4       4      # )z
Construct an SSL server endpoint.  This should be constructing a TCP
server endpoint which immediately calls C{startTLS} instead, but that
is hard.
r
   rC   r@   reactors   &&r)   serverStartTLSClientCreator.server   s     "'1d.C.C.EFFr,   c                T    \        \        VRVP                  4      \        4       4      # )zC
Construct a TCP client endpoint wrapped to immediately start TLS.
	127.0.0.1)rO   r   portr   r@   rn   serverAddresss   &&&r)   clientStartTLSClientCreator.client   s)     &w]5G5GH "
 	
r,   r-   N	r.   r/   r0   r1   rh   ro   rv   r6   r7   r8   s   @r)   rj   rj   }   s     
G
 
r,   rj   c                   *   a  ] tR t^t o RtR tRtV tR# )BadContextTestsMixinzu
Mixin for L{ReactorBuilder} subclasses which defines a helper for testing
the handling of broken context factories.
c                    V P                  4       pV P                  \        W\        4       4      pV P	                  \        P
                  \        V4      4       R# )a  
Assert that the exception raised by a broken context factory's
C{getContext} method is raised by some reactor method.  If it is not, an
exception will be raised to fail the test.

@param useIt: A two-argument callable which will be called with a
    reactor and a broken context factory and which is expected to raise
    the same exception as the broken context factory's C{getContext}
    method.
N)buildReactorassertRaises
ValueErrorr   assertEqualmessagestr)r@   useItrn   excs   &&  r)   _testBadContext$BadContextTestsMixin._testBadContext   sE     ##%
E<P<RS-55s3x@r,   r-   N)r.   r/   r0   r1   rh   r   r6   r7   r8   s   @r)   rz   rz      s     
A Ar,   rz   c                   (    ] tR t^tRt]! 4       tRtR# )StartTLSClientTestsMixinz
Tests for TLS connections established using L{ITLSTransport.startTLS} (as
opposed to L{IReactorSSL.connectSSL} or L{IReactorSSL.listenSSL}).
r-   N)r.   r/   r0   r1   rh   rj   	endpointsr6   r-   r,   r)   r   r      s    
 &'Ir,   r   c                   0   a  ] tR t^t o RtR tR tRtV tR# )
SSLCreatorz
Create SSL endpoints.
c                8    \        V^ V P                  4       4      # )zA
Create an SSL server endpoint on a TCP/IP-stack allocated port.
rl   rm   s   &&r)   ro   SSLCreator.server   s     "'1d.C.C.EFFr,   c                B    \        VRVP                  \        4       4      # )z
Create an SSL client endpoint which will connect localhost on
the port given by C{serverAddress}.

@type serverAddress: L{IPv4Address}
rr   )r	   rs   r   rt   s   &&&r)   rv   SSLCreator.client   s$     "[-"4"46J6L
 	
r,   r-   Nrx   r8   s   @r)   r   r      s     G	
 	
r,   r   c                   >   a  ] tR t^t o Rt]! 4       tR tR tRt	V t
R# )SSLClientTestsMixinz4
Mixin defining tests relating to L{ITLSTransport}.
c                .    R pV P                  V4       R# )z
If the context factory passed to L{IReactorSSL.connectSSL} raises an
exception from its C{getContext} method, that exception is raised by
L{IReactorSSL.connectSSL}.
c                 :    V P                  R R\        4       V4      # )rr   i  )
connectSSLr   rn   rR   s   &&r)   r   2SSLClientTestsMixin.test_badContext.<locals>.useIt   s     %%T=?N r,   Nr   r@   r   s   & r)   test_badContext#SSLClientTestsMixin.test_badContext   s    	
 	U#r,   c                  aa	  ! R R\         4      pV P                  4       o	\        4       p\        4       Vn        Wn        V P                  4       Vn        \        4       p\        4       Vn        Wn        V P                  4       Vn        VP                  P                  VP                  n
        . o\        VP                  VP                  .RR7      pV3R lpVP                  V4       S	P                  ^ VRR7      pV P                  VP                  4       S	P!                  VP#                  4       P$                  VP#                  4       P&                  V4      pV P                  VP(                  4       VP                  V	3R l4       V P+                  S	4       S^ ,          P-                  \.        4       S^,          P-                  \.        4       R	# )
a  
L{ITCPTransport.loseConnection} ends a connection which was set up with
L{ITLSTransport.startTLS} and which has recently been written to.  This
is intended to verify that a socket send error masked by the TLS
implementation doesn't prevent the connection from being reported as
closed.
c                   2   a  ] tR t^t o R tR tR tRtV tR# )QSSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocolc                l   \         P                  ! V P                  4      '       gD   V P                  P                  pR V P                  n        VP                  \        R4      4       R # V P                  P                  V P                  P                  4       V P                  P                  R4       R # )NzNo ITLSTransport support   x)
r   
providedByrZ   rc   finishederrbackr   r[   contextwrite)r@   r   s   & r)   r^   `SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocol.connectionMade   s{    $//??#||44H,0DLL)$$X.H%IJ ''(<(<= $$T*r,   c                p    V P                   P                  R 4       V P                   P                  4        R# )   yN)rZ   r   loseConnection)r@   datas   &&r)   dataReceived^SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocol.dataReceived   s(    
 $$T* --/r,   c                    V P                   P                  pVe%   R V P                   n        VP                  V4       R # R # rF   )rc   r   callback)r@   reasonr   s   && r)   connectionLost`SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocol.connectionLost  s8      <<00',0DLL)%%f- (r,   r-   N)	r.   r/   r0   r1   r^   r   r   r6   r7   r8   s   @r)   ShortProtocolr      s     +0. .r,   r   T)consumeErrorsc                 f   < SP                  V ^ ,          ^,          V ^,          ^,          .4       R# )    N)extend)resultslostConnectionResultss   &r)   
cbFinishedNSSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.cbFinished"  s&    !(('!*Q-A)GHr,   rr   )	interfacec                 $   < SP                  4       # rF   )stop)ignrn   s   &r)   <lambda>LSSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.<lambda>/  s    r,   N)r   r|   r   r   r   r]   rC   r   r   rH   methodr   addCallback	listenTCP
addCleanupstopListening
connectTCPgetHosthostrs   
disconnect
runReactortrapr   )
r@   r   serverFactoryclientFactoryr   r   rs   	connectorr   rn   s
   &       @@r)   &test_disconnectAfterWriteAfterStartTLS:SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS   su   	.H 	.B ##%%!)!. $ 5 5 7%!)!. $ 5 5 7'4'<'<'C'C$ "##]%;%;<D
	I 	Z(  M[ I**+&&LLN!4!4m
	 		,,-78 a %%&67a %%&67r,   r-   N)r.   r/   r0   r1   rh   r   r   r   r   r6   r7   r8   s   @r)   r   r      s$      I$L8 L8r,   r   c                   B   a  ] tR tRt o RtR tR tR tR tR t	Rt
V tR	# )
TLSPortTestsBuilderi5  z$
Tests for L{IReactorSSL.listenSSL}
c                B    VP                  ^ W P                  4       4      # )z 
Get a TLS port from a reactor.
)	listenSSLrC   )r@   rn   rc   s   &&&r)   getListeningPort$TLSPortTestsBuilder.getListeningPortA  s        G-B-B-DEEr,   c                F    RW!P                  4       P                  3,          # )zI
Get the message expected to be logged when a TLS port starts listening.
z%s (TLS) starting on %dr   rs   )r@   rs   rc   s   &&&r)   #getExpectedStartListeningLogMessage7TLSPortTestsBuilder.getExpectedStartListeningLogMessageG  s     )G\\^5H5H+IIIr,   c                >    RVP                  4       P                   R2# )z:
Get the expected connection lost message for a TLS port.
z
(TLS Port z Closed)r   )r@   rs   s   &&r)   getExpectedConnectionLostLogMsg3TLSPortTestsBuilder.getExpectedConnectionLostLogMsgM  s      DLLN//099r,   c                .    R pV P                  V4       R# )z
If the context factory passed to L{IReactorSSL.listenSSL} raises an
exception from its C{getContext} method, that exception is raised by
L{IReactorSSL.listenSSL}.
c                 8    V P                  ^ \        4       V4      # )r   )r   r   r   s   &&r)   r   2TLSPortTestsBuilder.test_badContext.<locals>.useItZ  s    $$QHHr,   Nr   r   s   & r)   r   #TLSPortTestsBuilder.test_badContextS  s    	I 	U#r,   c                n    VP                  V P                  VP                  VV P                  4       4      # )a  
Connect to the given listening TLS port, assuming the
underlying transport is TCP.

@param reactor: The reactor under test.
@type reactor: L{IReactorSSL}

@param address: The listening's address.  Only the C{port}
    component is used; see
    L{ConnectToTCPListenerMixin.LISTENER_HOST}.
@type address: L{IPv4Address} or L{IPv6Address}

@param factory: The client factory.
@type factory: L{ClientFactory}

@return: The connector
)r   LISTENER_HOSTrs   rH   )r@   rn   addressrc   s   &&&&r)   connectToListener%TLSPortTestsBuilder.connectToListener_  s6    $ !!LL!!#	
 	
r,   r-   N)r.   r/   r0   r1   rh   r   r   r   r   r   r6   r7   r8   s   @r)   r   r   5  s*     FJ:
$
 
r,   r   c                   >   a  ] tR tRt o Rt]3t]! 4       tR t	Rt
V tR# )AbortSSLConnectionTestsi~  z%
C{abortConnection} tests using SSL.
c                ,    \         f   \        R4      hR # )NzOpenSSL not available.)r   r   rG   s   &r)   setUpAbortSSLConnectionTests.setUp  s    344  r,   r-   N)r.   r/   r0   r1   rh   r   r&   r   r   r   r6   r7   r8   s   @r)   r   r   ~  s%      &I5 5r,   r   )?rh   typingr   r   r   zope.interfacer   r   twisted.internet.deferr   r   twisted.internet.endpointsr	   r
   r   twisted.internet.errorr   twisted.internet.interfacesr   r   r   twisted.internet.protocolr   r   r   &twisted.internet.test.connectionmixinsr   r   r   #twisted.internet.test.reactormixinsr   twisted.internet.test.test_tcpr   r   r   twisted.python.compatr   twisted.python.filepathr   twisted.python.runtimer   twisted.trial.unittestr   OpenSSL.cryptor   twisted.internet.sslr   r    r!   ImportErrorr#   r:   rO   rj   rz   r   r   r   r   globalsupdatemakeTestCaseClassesr   r-   r,   r)   <module>r      s  
 , + 1 9 
 4 
 M L 
 ? 
 0 , + +W+ WV
 
& &, "##6 #6 $#6L
O-C 
0A A,(x9M (
"8 
.g8g8TA
A
H 	  $88: ; 	  )==? @ 	  $&::< =5(*@5 	  (<<> ?C  Ls   4F 	F,+F,