+
    DfjZ                         R t ^ RIt^ RIt^ RIHtHtHtHt ^ RIH	t	 ^ RI
Ht ^ RIHt ^ RIHt ^ RIHt ^ RIHt ^ R	IHt  ^ R
IHsHt ^ RIHs ^ RIHtHt ^ RIH t   ! R R]PB                  4      t" ! R R]PB                  4      t# ! R R]PH                  4      t% ! R R]PH                  4      t&] ! ]PN                  4       ! R R]PH                  4      4       t(R t)R t* ! R R4      t+\.        e    ! R R\2        PX                  4      t- ! R R ]]4      t. ! R! R"]4      t/ ! R# R$]/4      t0 ! R% R&]4      t1 ! R' R(]]+4      t2 ! R) R*4      t3 ! R+ R,]4      t4 ! R- R.]4      t5R#   ] d    R t]! 4         EL$i ; i)/z 
Tests for twisted SSL support.
N)defer
interfacesprotocolreactor)ConnectionDone)waitUntilAllDisconnected)basic)FilePath)platform)ProperlyCloseFilesMixin)TestCase)SSLcrypto)ssl)ClientTLSContextcertPathc                      R ;s sR # N)r   r        7/usr/lib/python3/dist-packages/twisted/test/test_ssl.py_noSSLr      s     cr   )implementerc                   L   a  ] tR t^'t o Rt. R
OtRR.tR tR tR t	R t
RtV tR	# )UnintelligentProtocolz
@ivar deferred: a deferred that will fire at connection lost.
@type deferred: L{defer.Deferred}

@cvar pretext: text sent before TLS is set up.
@type pretext: C{bytes}

@cvar posttext: text sent after TLS is set up.
@type posttext: C{bytes}
s   first thing after tls starteds   last thing everc                :    \         P                  ! 4       V n        R # r   r   Deferreddeferredselfs   &r   __init__UnintelligentProtocol.__init__7       (r   c                N    V P                    F  pV P                  V4       K  	  R # r   )pretextsendLine)r    ls   & r   connectionMade$UnintelligentProtocol.connectionMade:   s    AMM! r   c                   VR 8X  dy   V P                   P                  \        4       V P                  P                  4       V P
                   F  pV P                  V4       K  	  V P                   P                  4        R# R# )   READYN)	transportstartTLSr   factoryclientposttextr&   loseConnection)r    liner'   s   && r   lineReceived"UnintelligentProtocol.lineReceived>   s[    8NN##$4$68K8KL]]a  #NN))+	 r   c                <    V P                   P                  R 4       R # r   r   callbackr    reasons   &&r   connectionLost$UnintelligentProtocol.connectionLostE       t$r   r   N)s
   first lines   last thing before tls starts   STARTTLS)__name__
__module____qualname____firstlineno____doc__r%   r0   r!   r(   r3   r:   __static_attributes____classdictcell____classdict__s   @r   r   r   '   s6     	 LG02DEH),% %r   r   c                   F   a  ] tR t^It o RtR	R ltR tR tR tR t	Rt
V tR# )
LineCollectora*  
@ivar deferred: a deferred that will fire at connection lost.
@type deferred: L{defer.Deferred}

@ivar doTLS: whether the protocol is initiate TLS or not.
@type doTLS: C{bool}

@ivar fillBuffer: if set to True, it will send lots of data once
    C{STARTTLS} is received.
@type fillBuffer: C{bool}
c                R    Wn         W n        \        P                  ! 4       V n        R # r   )doTLS
fillBufferr   r   r   )r    rK   rL   s   &&&r   r!   LineCollector.__init__V   s    
$(r   c                J    R V P                   n        . V P                   n        R# )r   N)r.   rawdatalinesr   s   &r   r(   LineCollector.connectionMade[   s    "r   c                   V P                   P                  P                  V4       VR 8X  d   V P                  '       d$   \	        R4       F  pV P                  R4       K  	  V P                  R4       V P                  '       dG   \        \        \        R7      pV P                  P                  W0P                   P                  4       R# V P                  4        R# R# )r>   i  r+   )privateKeyFileNamecertificateFileNameNs  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX)r.   rP   appendrL   ranger&   rK   ServerTLSContextr   r,   r-   server
setRawMode)r    r2   xctxs   &&  r   r3   LineCollector.lineReceived_   s    !!$';sAMM+. $MM(#zzz&'/(0 ''\\-@-@A! r   c                    V P                   ;P                  V,          un        V P                  P                  4        R # r   )r.   rO   r,   r1   r    datas   &&r   rawDataReceivedLineCollector.rawDataReceivedo   s'    $%%'r   c                <    V P                   P                  R 4       R # r   r6   r8   s   &&r   r:   LineCollector.connectionLosts   r<   r   )r   rK   rL   NF)r?   r@   rA   rB   rC   r!   r(   r3   r`   r:   rD   rE   rF   s   @r   rI   rI   I   s(     
)
 " (% %r   rI   c                   *   a  ] tR t^wt o RtR tRtV tR# )SingleLineServerProtocolzC
A protocol that sends a single line of data at C{connectionMade}.
c                p    V P                   P                  R 4       V P                   P                  4        R# )   +OK <some crap>
N)r,   writegetPeerCertificater   s   &r   r(   'SingleLineServerProtocol.connectionMade|   s%    34))+r   r   N)r?   r@   rA   rB   rC   r(   rD   rE   rF   s   @r   rf   rf   w   s     , ,r   rf   c                   6   a  ] tR t^t o RtR tR tR tRtV t	R# )RecordingClientProtocolzj
@ivar deferred: a deferred that will fire with first received content.
@type deferred: L{defer.Deferred}
c                :    \         P                  ! 4       V n        R # r   r   r   s   &r   r!    RecordingClientProtocol.__init__   r#   r   c                :    V P                   P                  4        R # r   )r,   rj   r   s   &r   r(   &RecordingClientProtocol.connectionMade   s    ))+r   c                <    V P                   P                  V4       R # r   r6   r^   s   &&r   dataReceived$RecordingClientProtocol.dataReceived   r<   r   r=   N)
r?   r@   rA   rB   rC   r!   r(   rs   rD   rE   rF   s   @r   rm   rm      s     
),% %r   rm   c                   0   a  ] tR t^t o RtR tR tRtV tR# ) ImmediatelyDisconnectingProtocolz
A protocol that disconnect immediately on connection. It fires the
C{connectionDisconnected} deferred of its factory on connetion lost.
c                :    V P                   P                  4        R # r   r,   r1   r   s   &r   handshakeCompleted3ImmediatelyDisconnectingProtocol.handshakeCompleted   s    %%'r   c                P    V P                   P                  P                  R 4       R # r   )r.   connectionDisconnectedr7   r8   s   &&r   r:   /ImmediatelyDisconnectingProtocol.connectionLost   s    ++44T:r   r   N)	r?   r@   rA   rB   rC   ry   r:   rD   rE   rF   s   @r   rv   rv      s     
(; ;r   rv   c                   \         P                  ! 4       pVP                  \         P                  R4       \         P                  ! 4       pVP                  4       pWn        Wn        VP                  V4       VP                  VR4       \         P                  ! 4       pVP                  ^4       VP                  ^ 4       VP                  ^<4       VP                  VP                  4       4       VP                  VP                  4       4       VP                  VP!                  4       4       VP                  VR4       W#V3# )z
Create a certificate for given C{organization} and C{organizationalUnit}.

@return: a tuple of (key, request, certificate) objects.
i   md5)r   PKeygenerate_keyTYPE_RSAX509Reqget_subjectOOU
set_pubkeysignX509set_serial_numbergmtime_adj_notBeforegmtime_adj_notAfter
set_issuerset_subject
get_pubkey)organizationorganizationalUnitpkeyreqsubjectcerts   &&    r   generateCertificateObjectsr      s     ;;=Dfoot,
..
CooGI#JNN4HHT5 ;;=D1a R OOCOO%&S__&'OOCNN$%IIdEd?r   c                b   \        W4      w  r4pRV\        P                  3RV\        P                  3RV\        P                  33 Fd  w  rgp\
        P                  P                  W34      P                  R4      p	\        V	4      P                  V! \        P                  V4      4       Kf  	  R# )zy
Create certificate files key, req and cert prefixed by C{basename} for
given C{organization} and C{organizationalUnit}.
keyr   r   zutf-8N)r   r   dump_privatekeydump_certificate_requestdump_certificateosextsepjoinencoder	   
setContentFILETYPE_PEM)
basenamer   r   r   r   r   extobjdumpFuncfNames
   &&&       r   generateCertificateFilesr      s    
 1RODt 
f,,-	V445	v../(
 		/66w?""8F,?,?#EFr   c                   0   a  ] tR t^t o RtR tR tRtV tR# )ContextGeneratingMixina4  
Offer methods to create L{ssl.DefaultOpenSSLContextFactory} for both client
and server.

@ivar clientBase: prefix of client certificate files.
@type clientBase: C{str}

@ivar serverBase: prefix of server certificate files.
@type serverBase: C{str}

@ivar clientCtxFactory: a generated context factory to be used in
    L{IReactorSSL.connectSSL}.
@type clientCtxFactory: L{ssl.DefaultOpenSSLContextFactory}

@ivar serverCtxFactory: a generated context factory to be used in
    L{IReactorSSL.listenSSL}.
@type serverCtxFactory: L{ssl.DefaultOpenSSLContextFactory}
c                    V P                  4       p\        WQV4       \        P                  ! \        P
                  P                  VR 34      \        P
                  P                  VR34      .VO5/ VB pWV3# )r   r   )mktempr   r   DefaultOpenSSLContextFactoryr   r   r   )r    orgorgUnitargskwArgsbaseserverCtxFactorys   &&&*,  r   makeContextFactory)ContextGeneratingMixin.makeContextFactory   so    {{} G4;;IINND%=)IINND&>*
 
 	
 %%r   c                    V P                   ! V/ VB w  V n        V n        V P                   ! V/ VB w  V n        V n        R # r   )r   
clientBaseclientCtxFactory
serverBaser   )r    
clientArgsclientKwArgs
serverArgsserverKwArgss   &&&&&r   setupServerAndClient+ContextGeneratingMixin.setupServerAndClient   sN    151H1H2
'2
.. 261H1H2
'2
..r   )r   r   r   r   N)	r?   r@   rA   rB   rC   r   r   rD   rE   rF   s   @r   r   r      s     &
&
 
r   r   c                   .   a  ] tR t^t o RtRtR tRtV tR# )rW   zN
A context factory with a default method set to
L{OpenSSL.SSL.SSLv23_METHOD}.
Fc                t    \         P                  VR &   \        P                  P                  ! V .VO5/ VB  R# )	sslmethodN)r   SSLv23_METHODr   r   r!   )r    r   kws   &*,r   r!   ServerTLSContext.__init__   s/    !//B{O,,55dHTHRHr   r   N)	r?   r@   rA   rB   rC   isClientr!   rD   rE   rF   s   @r   rW   rW      s     	
 	I 	Ir   rW   c                   j   a  ] tR tRt o Rt]P                  ! ]R4      f   RtR t	R t
R tR tR	tV tR# )
StolenTCPTestsi  zW
For SSL transports, test many of the same things which are tested for
TCP transports.
N2Reactor does not support SSL, cannot run SSL testsc                    \         P                  P                  \        \        4      P                  4       4      pVP                  4       p\        P                  ! W#WQR7      # )zI
Create an SSL server with a certificate using L{IReactorSSL.listenSSL}.
	interface)	r   PrivateCertificateloadPEMr	   r   
getContentoptionsr   	listenSSL)r    address
portNumberr.   r   contextFactorys   &&&&  r   createServerStolenTCPTests.createServer  sF     %%--hx.@.K.K.MN  nXXr   c                P    \         P                  ! 4       pVP                  WV4      # )z7
Create an SSL client using L{IReactorSSL.connectSSL}.
)r   CertificateOptions
connectSSL)r    r   r   clientCreatorr   s   &&&& r   connectClientStolenTCPTests.connectClient  s%     //1''^LLr   c                "    \         P                  # )z
Return L{OpenSSL.SSL.Error} as the expected error type which will be
raised by a write to the L{OpenSSL.SSL.Connection} object after it has
been closed.
)r   Errorr   s   &r   getHandleExceptionType%StolenTCPTests.getHandleExceptionType  s     yyr   c                N   \         P                  ! \         P                  ! \         P                  ! R4      \         P                  ! \         P                  ! R4      \         P                  ! R4      \         P                  ! R4      4      \         P                  ! R4      4      4      # )a  
Return a L{hamcrest.core.matcher.Matcher} for the argument
L{OpenSSL.SSL.Error} will be constructed with for this case.
This is basically just a random OpenSSL implementation detail.
It would be better if this test worked in a way which did not
require this.
zSSL routines	SSL_writessl_write_internal zprotocol is shutdown)hamcrestcontainsequal_toany_ofr   s   &r   getHandleErrorCodeMatcher(StolenTCPTests.getHandleErrorCodeMatcher#  s{       !!.1%%k2%%&:;%%b)
 !!"89

 
	
r   r   )r?   r@   rA   rB   rC   r   IReactorSSLr   skipr   r   r   r   rD   rE   rF   s   @r   r   r     s?     
 gt,4CYM
 
r   r   c                      a  ] tR tRt o Rt]P                  ! ]R4      f   RtRt	Rt
RtR tRR ltR tR	 tR
 tRtV tR# )TLSTestsi:  zs
Tests for startTLS support.

@ivar fillBuffer: forwarded to L{LineCollector.fillBuffer}
@type fillBuffer: C{bool}
Nr   Fc                    V P                   P                  e%   V P                   P                  P                  4        V P                  P                  e'   V P                  P                  P                  4        R # R # r   )clientProtor,   r1   serverProtor   s   &r   tearDownTLSTests.tearDownJ  s[    %%1&&557%%1&&557 2r   c                6  aa SV n         \        P                  ! 4       ;q@n        V3R lVn        V'       d	   RVn        MRVn        SV n        \        P                  ! 4       ;qPn        V3R lVn        V'       d	   RVn        MRVn        \        P                  ! ^ VRR7      pV P                  VP                  4       \        P                  ! RVP                  4       P                  V4       \         P"                  ! SP$                  SP$                  .4      # )am  
Helper method to run TLS tests.

@param clientProto: protocol instance attached to the client
    connection.
@param serverProto: protocol instance attached to the server
    connection.
@param clientIsServer: flag indicated if client should initiate
    startTLS instead of server.

@return: a L{defer.Deferred} that will fire when both connections are
    lost.
c                     < S # r   r   r   s   r   <lambda>#TLSTests._runTest.<locals>.<lambda>`      kr   FTc                     < S # r   r   r   s   r   r   r   h  r   r   	127.0.0.1r   )r   r   ClientFactoryclientFactoryrX   r/   r   ServerFactoryserverFactoryr   	listenTCP
addCleanupstopListening
connectTCPgetHostportr   gatherResultsr   )r    r   r   clientIsServercfsfr  s   &ff&   r   _runTestTLSTests._runTestP  s     '"*"8"8"::)BIBI&"*"8"8"::)BIBI  B+>**+;(;(;R@""K$8$8+:N:N#OPPr   c                   a  V 3R lpS P                  \        4       \        RS P                  4      4      pVP	                  V4      # )zf
Test for server and client startTLS: client should received data both
before and after the startTLS.
c                    < SP                  SP                  P                  \        P                  \        P
                  ,           4       R # r   )assertEqualr   rP   r   r%   r0   )ignorer    s   &r   check TLSTests.test_TLS.<locals>.check{  5    ""((%--0E0N0NNr   Tr
  r   rI   rL   addCallbackr    r  ds   f  r   test_TLSTLSTests.test_TLSu  s8    	 MM/1=t3WX}}U##r   c                   a  V 3R lpS P                  \        4       \        RS P                  4      4      pVP	                  V4      # )z
Test for server startTLS not followed by a startTLS in client: the data
received after server startTLS should be received as raw.
c                    < SP                  SP                  P                  \        P                  4       SP                  SP                  P                  R 4       R# )zNo encrypted bytes receivedN)r  r   rP   r   r%   
assertTruerO   ignoredr    s   &r   r  "TLSTests.test_unTLS.<locals>.check  sA    T//557L7T7TUOOD..668UVr   Fr  r  s   f  r   
test_unTLSTLSTests.test_unTLS  s=    	W MM!#]5$//%J
 }}U##r   c                   a  V 3R lpS P                  \        RS P                  4      \        4       R4      pVP	                  V4      # )z*
Test startTLS first initiated by client.
c                    < SP                  SP                  P                  \        P                  \        P
                  ,           4       R # r   )r  r   rP   r   r%   r0   r  s   &r   r  )TLSTests.test_backwardsTLS.<locals>.check  r  r   T)r
  rI   rL   r   r  r  s   f  r   test_backwardsTLSTLSTests.test_backwardsTLS  s?    
	 MM$02G2I4
 }}U##r   )r   r   r   r   rd   )r?   r@   rA   rB   rC   r   r   r   r   rL   r   r   r   r
  r  r  r$  rD   rE   rF   s   @r   r   r   :  sS      gt,4CJKK8#QJ$$$ $r   r   c                   L    ] tR tRtRt]P                  ! ]R4      f   RtRt	Rt
R# )SpammyTLSTestsi  z9
Test TLS features with bytes sitting in the out buffer.
Nr   Tr   )r?   r@   rA   rB   rC   r   r   r   r   rL   rD   r   r   r   r'  r'    s&     gt,4CJr   r'  c                   b   a  ] tR tRt o ]P
                  ! ]R4      f   RtRtRt	R t
R tRtV tR# )BufferingTestsi  Nr   c                >   V P                   P                  e%   V P                   P                  P                  4        V P                  P                  e%   V P                  P                  P                  4        \	        \
        V P                   V P                  .4      # r   )r   r,   r1   r   r   r   r   s   &r   r   BufferingTests.tearDown  st    %%1&&557%%1&&557'$2B2BDDTDT1UVVr   c                  aa \        4       ;oV n        \        4       ;oV n        \        P
                  ! 4       p\        P                  ! 4       ;q n        V3R  lVn        V3R lVn        \        P                  ! \        \        4      p\        P                  ! 4       p\        P                  ! ^ WRR7      pV P                  VP                  4       \        P                   ! RVP#                  4       P$                  W$4      pV P                  VP&                  4       SP(                  P+                  V P,                  R4      # )c                     < S # r   r   r   s   r   r   6BufferingTests.test_openSSLBuffering.<locals>.<lambda>      +r   c                     < S # r   r   r   s   r   r   r.    r/  r   r   r   rh   )rf   r   rm   r   r   r   r   r/   r   r   r   ClientContextFactoryr   r   r  r  r   r  r  
disconnectr   r  r  )	r    rX   r/   sCTXcCTXr  clientConnectorr   r   s	   &      @@r   test_openSSLBuffering$BufferingTests.test_openSSLBuffering  s    )A)CCd&)@)BBd&'')'5577--//(C'')  FKH**+!,,,,f
 	223##//4
 	
r   )r/   r   r   )r?   r@   rA   rB   r   r   r   r   r   r   r   r6  rD   rE   rF   s   @r   r)  r)    s7     gt,4CKKW
 
r   r)  c                   j   a  ] tR tRt o Rt]P                  ! ]R4      f   RtR t	R t
R tR tR	tV tR# )
ConnectionLostTestsi  z
SSL connection closing tests.
Nr   c                  a  R pS P                  WR,           3/ WR,           3/ 4       \        P                  ! 4       p\        P                  Vn        \        P
                  ! ^ VS P                  4      ;S n        p\        P                  ! 4       p\        Vn        \        P                  ! 4       Vn        \        P                  ! RVP                  4       P                  VS P                   4       VP                  P#                  V 3R l4      # )twisted.test.test_ssl, client, serverr   c                 8   < SP                   P                  4       # r   )
serverPortr  )ignoredResultr    s   &r   r   =ConnectionLostTests.testImmediateDisconnect.<locals>.<lambda>  s    $//"?"?"Ar   )r   r   r   Protocolr   r   r   r?  r   rv   r   r   r|   r   r  r  r   r  )r    r   serverProtocolFactoryr?  clientProtocolFactorys   f    r   testImmediateDisconnect+ConnectionLostTests.testImmediateDisconnect  s    %!!
"#R#Z/?)@"	
 !) 6 6 8)1):):&'.'8'8$d&;&;(
 	
* !) 6 6 8)I&7<~~7G4 %%!!!		
 %;;GGA
 	
r   c                  aa \        \        P                  4       ! R R\        P                  4      4       pRpV P                  W"R,           3/ W"R,           3/ 4       V! 4       o\        P                  ! 4       pV3R lVn        \        P                  ! ^ W0P                  4      pV P                  VP                  4       V! 4       o\        P                  ! 4       pV3R lVn        \        P                  ! RVP                  4       P                  VV P                   4       R	 p\"        P$                  ! SP&                  P)                  V4      SP&                  P)                  V4      .4      # )
z
Both sides of SSL connection close connection; the connections should
close cleanly, and only after the underlying TCP connection has
disconnected.
c                   6   a  ] tR tRt o RtR tR tR tRtV t	R# )MConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshakei  Fc                :    \         P                  ! 4       V n        R # r   )r   r   doner   s   &r   r!   VConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshake.__init__  s    !NN,	r   c                :    V P                   P                  4        R # r   rx   r   s   &r   ry   `ConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshake.handshakeCompleted
  s    --/r   c                @    V P                   P                  V4       V = R # r   )rK  errbackr8   s   &&r   r:   \ConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshake.connectionLost  s    		!!&)Ir   )rK  N)
r?   r@   rA   rB   gotDatar!   ry   r:   rD   rE   rF   s   @r   CloseAfterHandshakerI    s     G-0 r   rS  r;  r<  r=  c                     < S # r   r   serverProtocols   r   r   BConnectionLostTests.test_bothSidesLoseConnection.<locals>.<lambda>      r   c                     < S # r   r   clientProtocols   r   r   rW    rX  r   r   c                 0    V P                  \        4       R # r   )trapr   )failures   &r   checkResultEConnectionLostTests.test_bothSidesLoseConnection.<locals>.checkResult&  s    LL(r   )r   r   IHandshakeListenerr   rB  r   r   r   r   r   r  r  r   r   r  r  r   r   r  rK  
addErrback)	r    rS  r   rC  r?  rD  r_  r[  rV  s	   &      @@r   test_bothSidesLoseConnection0ConnectionLostTests.test_bothSidesLoseConnection  s@    
Z22	3	("3"3 	 
4	 &!!
"#R#Z/?)@"	
 -. ( 6 6 8)?&&&q*?AVAVW

001,. ( 6 6 8)?& %%!!!		
	) ""##..{;##..{;
 	
r   c                b  a	a
 R pV P                  WR,           3/ WR,           3/ 4       R pV P                  P                  4       P                  \        P
                  V4       \        P                  ! 4       p\        P                  ! 4       o
VP                  S
n        \        P                  ! 4       pV
3R lVn        \        P                  ! ^ W@P                  4      ;V n        p\        P                  ! 4       p\        P                  ! 4       o	VP                  S	n        \        P"                  ! 4       pV	3R lVn        \        P$                  ! RVP'                  4       P(                  VV P                  4       \        P*                  ! W6.RR7      pVP-                  V P.                  4      # )	r;  r<  r=  c                      R # rd   r   )as   *r   verify4ConnectionLostTests.testFailedVerify.<locals>.verify6  s    r   c                     < S # r   r   rU  s   r   r   6ConnectionLostTests.testFailedVerify.<locals>.<lambda>?  rX  r   c                     < S # r   r   rZ  s   r   r   rk  H  rX  r   r   T)consumeErrors)r   r   
getContext
set_verifyr   VERIFY_PEERr   r   r   rB  r7   r:   r   r   r   r   r?  r   r   r  r  DeferredListr  _cbLostConns)r    r   rh  serverConnLostrC  r?  clientConnLostrD  dlr[  rV  s   &        @@r   testFailedVerify$ConnectionLostTests.testFailedVerify0  s\   %!!
"#R#Z/?)@"	
	 	((*55coovN)!**,(6(?(?% ( 6 6 8)?&'.'8'8$&;&;(
 	
* )!**,(6(?(?% ( 6 6 8)?& %%!!!		
  @PTU~~d//00r   c                R   Vw  w  r#w  rEV P                  V4       V P                  V4       \        P                  .p\        P                  ! 4       '       d   ^ RIHp VP                  V4       VP                  ! V!   VP                  ! V!   V P                  P                  4       # )    )ConnectionLost)assertFalser   r   r
   	isWindowstwisted.internet.errorrz  rU   r]  r?  r  )r    resultssSuccesssResultcSuccesscResultacceptableErrorsrz  s   &&      r   rr   ConnectionLostTests._cbLostConnsS  s    3:00h""II; =##N3&'&',,..r   )r?  )r?   r@   rA   rB   rC   r   r   r   r   rE  rc  rv  rr  rD   rE   rF   s   @r   r9  r9    s?      gt,4C
82
h!1F/ /r   r9  c                   <   a  ] tR tRt o RtR tR tR tR tRt	V t
R# )	FakeContextin  zC
L{OpenSSL.SSL.Context} double which can more easily be inspected.
c                     Wn         ^ V n        R# )ry  N_method_options)r    methods   &&r   r!   FakeContext.__init__s  s    r   c                8    V ;P                   V,          un         R # r   )r  )r    r   s   &&r   set_optionsFakeContext.set_optionsw  s     r   c                    R # r   r   r    fileNames   &&r   use_certificate_file FakeContext.use_certificate_filez      r   c                    R # r   r   r  s   &&r   use_privatekey_fileFakeContext.use_privatekey_file}  r  r   r  N)r?   r@   rA   rB   rC   r!   r  r  r  rD   rE   rF   s   @r   r  r  n  s#     ! r   r  c                   j   a  ] tR tRt o Rt]P                  ! ]R4      f   RtR t	R t
R tR tR	tV tR# )
!DefaultOpenSSLContextFactoryTestsi  z0
Tests for L{ssl.DefaultOpenSSLContextFactory}.
Nr   c                    \         P                  ! \        \        \        R 7      V n        V P                  P                  4       V n        R# ))_contextFactoryN)r   r   r   r  r   rn  contextr   s   &r   setUp'DefaultOpenSSLContextFactoryTests.setUp  s6     ">>h
 **557r   c                t   V P                  V P                  P                  \        P                  4       V P                  V P                  P
                  \        P                  ,          \        P                  4       V P                  V P                  P
                  \        P                  ,          4       R# )zs
L{ssl.DefaultOpenSSLContextFactory.getContext} returns an SSL context
which can use SSLv3 or TLSv1 but not SSLv2.
N)	r  r  r  r   
TLS_METHODr  OP_NO_SSLv2r{  OP_NO_TLSv1_2r   s   &r   test_method-DefaultOpenSSLContextFactoryTests.test_method  sp     	--s~~> 	..@#//R 	..1B1BBCr   c                    V P                  \        P                  \        P                  \
        V P                  4       4       R# )z
Instantiating L{ssl.DefaultOpenSSLContextFactory} with a certificate
filename which does not identify an existing file results in the
initializer raising L{OpenSSL.SSL.Error}.
N)assertRaisesr   r   r   r   r   r   r   s   &r   test_missingCertificateFile=DefaultOpenSSLContextFactoryTests.test_missingCertificateFile  s+     	IIs774;;=	
r   c                    V P                  \        P                  \        P                  V P                  4       \        4       R# )z
Instantiating L{ssl.DefaultOpenSSLContextFactory} with a private key
filename which does not identify an existing file results in the
initializer raising L{OpenSSL.SSL.Error}.
N)r  r   r   r   r   r   r   r   s   &r   test_missingPrivateKeyFile<DefaultOpenSSLContextFactoryTests.test_missingPrivateKeyFile  s+     	IIs77	
r   r  r   )r?   r@   rA   rB   rC   r   r   r   r   r  r  r  r  rD   rE   rF   s   @r   r  r    s>      gt,4C8D

 
r   r  c                   ^   a  ] tR tRt o Rt]P                  ! ]R4      f   RtR t	R t
RtV tR# )ClientContextFactoryTestsi  z(
Tests for L{ssl.ClientContextFactory}.
Nr   c                    \         P                  ! 4       V n        \        V P                  n        V P                  P                  4       V n        R # r   )r   r1  r   r  r  rn  r  r   s   &r   r  ClientContextFactoryTests.setUp  s7    !668.9+**557r   c                   V P                  V P                  P                  \        P                  4       V P                  V P                  P
                  \        P                  ,          \        P                  4       V P                  V P                  P
                  \        P                  ,          4       V P                  V P                  P
                  \        P                  ,          4       R# )zl
L{ssl.ClientContextFactory.getContext} returns a context which can use
TLSv1.2 or 1.3 but nothing earlier.
N)
r  r  r  r   r  r  r  r  OP_NO_SSLv3OP_NO_TLSv1r   s   &r   r  %ClientContextFactoryTests.test_method  s    
 	--s~~>..@#//R--?@--?@r   r  )r?   r@   rA   rB   rC   r   r   r   r   r  r  rD   rE   rF   s   @r   r  r    s5      gt,4C8
A Ar   r  )6rC   r   r   twisted.internetr   r   r   r   r}  r   twisted.internet.testingr   twisted.protocolsr   twisted.python.filepathr	   twisted.python.runtimer
   twisted.test.test_tcpr   twisted.trial.unittestr   OpenSSLr   r   r   twisted.test.ssl_helpersr   r   ImportErrorr   zope.interfacer   LineReceiverr   rI   rB  rf   rm   ra  rv   r   r   r   r   rW   r   r   r'  r)  r9  r  r  r  r   r   r   <module>r     st   
  A A 1 = # , + 9 +#$C '%E.. %D+%E&& +%\,x00 ,%h// %  Z**+
;x'8'8 
; ,
;8G &
 &
R ?
I3;; 
I4
,h 4
ng$x g$TX &
X &
RS/($: S/l &0
 0
fA Au   Hs   E( (E=<E=