/snap/core18/2999/usr/lib/python3.6/__pycache__
NameSizeModeActions
abc.cpython-36.pyc75150644editdlrm
aifc.cpython-36.pyc259430644editdlrm
antigravity.cpython-36.pyc7790644editdlrm
argparse.cpython-36.pyc604560644editdlrm
ast.cpython-36.pyc117040644editdlrm
asynchat.cpython-36.pyc68150644editdlrm
asyncore.cpython-36.pyc158380644editdlrm
base64.cpython-36.pyc170590644editdlrm
bdb.cpython-36.pyc170330644editdlrm
binhex.cpython-36.pyc120860644editdlrm
bisect.cpython-36.pyc26760644editdlrm
bz2.cpython-36.pyc112820644editdlrm
calendar.cpython-36.pyc258820644editdlrm
cgi.cpython-36.pyc284160644editdlrm
cgitb.cpython-36.pyc100800644editdlrm
chunk.cpython-36.pyc49000644editdlrm
cmd.cpython-36.pyc125750644editdlrm
code.cpython-36.pyc98360644editdlrm
codecs.cpython-36.pyc339000644editdlrm
codeop.cpython-36.pyc62700644editdlrm
colorsys.cpython-36.pyc33110644editdlrm
compileall.cpython-36.pyc82780644editdlrm
configparser.cpython-36.pyc452440644editdlrm
contextlib.cpython-36.pyc111580644editdlrm
copy.cpython-36.pyc70790644editdlrm
copyreg.cpython-36.pyc42440644editdlrm
cProfile.cpython-36.pyc42940644editdlrm
crypt.cpython-36.pyc22420644editdlrm
csv.cpython-36.pyc118550644editdlrm
datetime.cpython-36.pyc545110644editdlrm
decimal.cpython-36.pyc3510644editdlrm
difflib.cpython-36.pyc596420644editdlrm
dis.cpython-36.pyc141810644editdlrm
doctest.cpython-36.pyc755890644editdlrm
dummy_threading.cpython-36.pyc11020644editdlrm
enum.cpython-36.pyc234530644editdlrm
filecmp.cpython-36.pyc83050644editdlrm
fileinput.cpython-36.pyc131520644editdlrm
fnmatch.cpython-36.pyc28740644editdlrm
formatter.cpython-36.pyc175790644editdlrm
fractions.cpython-36.pyc184260644editdlrm
ftplib.cpython-36.pyc283570644editdlrm
functools.cpython-36.pyc240620644editdlrm
genericpath.cpython-36.pyc37260644editdlrm
getopt.cpython-36.pyc62170644editdlrm
getpass.cpython-36.pyc41770644editdlrm
gettext.cpython-36.pyc143060644editdlrm
glob.cpython-36.pyc42590644editdlrm
gzip.cpython-36.pyc162260644editdlrm
hashlib.cpython-36.pyc66920644editdlrm
heapq.cpython-36.pyc142920644editdlrm
hmac.cpython-36.pyc48360644editdlrm
imaplib.cpython-36.pyc421380644editdlrm
imghdr.cpython-36.pyc41500644editdlrm
imp.cpython-36.pyc96960644editdlrm
inspect.cpython-36.pyc797390644editdlrm
io.cpython-36.pyc33870644editdlrm
ipaddress.cpython-36.pyc623860644editdlrm
keyword.cpython-36.pyc17650644editdlrm
linecache.cpython-36.pyc37780644editdlrm
locale.cpython-36.pyc340300644editdlrm
lzma.cpython-36.pyc119920644editdlrm
macpath.cpython-36.pyc56410644editdlrm
macurl2path.cpython-36.pyc18670644editdlrm
mailbox.cpython-36.pyc637520644editdlrm
mailcap.cpython-36.pyc72090644editdlrm
mimetypes.cpython-36.pyc155530644editdlrm
modulefinder.cpython-36.pyc153660644editdlrm
netrc.cpython-36.pyc38360644editdlrm
nntplib.cpython-36.pyc337800644editdlrm
ntpath.cpython-36.pyc131900644editdlrm
nturl2path.cpython-36.pyc14990644editdlrm
numbers.cpython-36.pyc121420644editdlrm
opcode.cpython-36.pyc54130644editdlrm
operator.cpython-36.pyc139130644editdlrm
optparse.cpython-36.pyc480540644editdlrm
os.cpython-36.pyc296280644editdlrm
pathlib.cpython-36.pyc420070644editdlrm
pdb.cpython-36.pyc460940644editdlrm
pickle.cpython-36.pyc426910644editdlrm
pickletools.cpython-36.pyc660200644editdlrm
pipes.cpython-36.pyc78080644editdlrm
pkgutil.cpython-36.pyc162610644editdlrm
platform.cpython-36.pyc291970644editdlrm
plistlib.cpython-36.pyc280550644editdlrm
poplib.cpython-36.pyc133290644editdlrm
posixpath.cpython-36.pyc104560644editdlrm
pprint.cpython-36.pyc158240644editdlrm
profile.cpython-36.pyc139010644editdlrm
pstats.cpython-36.pyc218570644editdlrm
pty.cpython-36.pyc38610644editdlrm
pyclbr.cpython-36.pyc83650644editdlrm
pydoc.cpython-36.pyc837750644editdlrm
py_compile.cpython-36.pyc65440644editdlrm
queue.cpython-36.pyc87550644editdlrm
quopri.cpython-36.pyc57730644editdlrm
random.cpython-36.pyc193300644editdlrm
re.cpython-36.pyc140580644editdlrm
reprlib.cpython-36.pyc54000644editdlrm
rlcompleter.cpython-36.pyc57800644editdlrm
runpy.cpython-36.pyc79820644editdlrm
sched.cpython-36.pyc65640644editdlrm
secrets.cpython-36.pyc21620644editdlrm
selectors.cpython-36.pyc176970644editdlrm
shelve.cpython-36.pyc94580644editdlrm
shlex.cpython-36.pyc69700644editdlrm
shutil.cpython-36.pyc307040644editdlrm
signal.cpython-36.pyc25150644editdlrm
site.cpython-36.pyc165600644editdlrm
sitecustomize.cpython-36.pyc2120644editdlrm
smtpd.cpython-36.pyc266830644editdlrm
smtplib.cpython-36.pyc353400644editdlrm
sndhdr.cpython-36.pyc69130644editdlrm
socket.cpython-36.pyc220130644editdlrm
socketserver.cpython-36.pyc242500644editdlrm
sre_compile.cpython-36.pyc102780644editdlrm
sre_constants.cpython-36.pyc59720644editdlrm
sre_parse.cpython-36.pyc203580644editdlrm
ssl.cpython-36.pyc369390644editdlrm
stat.cpython-36.pyc38510644editdlrm
statistics.cpython-36.pyc181740644editdlrm
string.cpython-36.pyc79640644editdlrm
stringprep.cpython-36.pyc100300644editdlrm
struct.cpython-36.pyc3120644editdlrm
subprocess.cpython-36.pyc354850644editdlrm
sunau.cpython-36.pyc169380644editdlrm
symbol.cpython-36.pyc25170644editdlrm
symtable.cpython-36.pyc104280644editdlrm
sysconfig.cpython-36.pyc159160644editdlrm
tabnanny.cpython-36.pyc69750644editdlrm
tarfile.cpython-36.pyc630850644editdlrm
telnetlib.cpython-36.pyc180970644editdlrm
tempfile.cpython-36.pyc253090644editdlrm
textwrap.cpython-36.pyc136840644editdlrm
this.cpython-36.pyc12650644editdlrm
threading.cpython-36.pyc372340644editdlrm
timeit.cpython-36.pyc116030644editdlrm
token.cpython-36.pyc33200644editdlrm
tokenize.cpython-36.pyc186470644editdlrm
trace.cpython-36.pyc194950644editdlrm
traceback.cpython-36.pyc196460644editdlrm
tracemalloc.cpython-36.pyc172290644editdlrm
tty.cpython-36.pyc10720644editdlrm
turtle.cpython-36.pyc1317510644editdlrm
types.cpython-36.pyc82010644editdlrm
typing.cpython-36.pyc733060644editdlrm
uu.cpython-36.pyc34980644editdlrm
uuid.cpython-36.pyc209180644editdlrm
warnings.cpython-36.pyc132580644editdlrm
wave.cpython-36.pyc178850644editdlrm
weakref.cpython-36.pyc191430644editdlrm
webbrowser.cpython-36.pyc157970644editdlrm
xdrlib.cpython-36.pyc83020644editdlrm
zipapp.cpython-36.pyc55340644editdlrm
zipfile.cpython-36.pyc497280644editdlrm
_bootlocale.cpython-36.pyc9800644editdlrm
_collections_abc.cpython-36.pyc287970644editdlrm
_compat_pickle.cpython-36.pyc65660644editdlrm
_compression.cpython-36.pyc41040644editdlrm
_dummy_thread.cpython-36.pyc48510644editdlrm
_markupbase.cpython-36.pyc79910644editdlrm
_osx_support.cpython-36.pyc96840644editdlrm
_pydecimal.cpython-36.pyc1634020644editdlrm
_pyio.cpython-36.pyc713860644editdlrm
_sitebuiltins.cpython-36.pyc34350644editdlrm
_strptime.cpython-36.pyc159630644editdlrm
_sysconfigdata_m_linux_x86_64-linux-gnu.cpython-36.pyc187790644editdlrm
_threading_local.cpython-36.pyc64250644editdlrm
_weakrefset.cpython-36.pyc78280644editdlrm
__future__.cpython-36.pyc41670644editdlrm
__phello__.foo.cpython-36.pyc1190644editdlrm
Edit: /snap/core18/2999/usr/lib/python3.6/__pycache__/ssl.cpython-36.pyc (36939B)
3 Nqi@@shdZddlZddlZddlZddlZddlZddlmZddlm Z m Z m ZddlZddlmZmZmZddlmZmZmZddlmZmZmZmZmZmZddlmZmZdd lm Z m!Z!m"Z"m#Z#ydd lm$Z$Wne%k rYnXdd lm&Z&m'Z'm(Z(m)Z)m*Z*dd lm+Z+e j,d e-ddedej,de-ddede j,de-ddede j,de-ddedej,de-ddede j,de-ddede.j/Z0e._0dde.j1j2DZ3e4e.ddZ5ej6dkrddlm7Z7m8Z8dd l9m9Z9m:Z:m;Z;mZ>ddl?Z?ddl@Z@ddlAZAeBZCejDr2d"gZEngZEd#ZFd$ZGGd%d&d&eHZIdSd(d)ZJd*d+ZKd,d-ZLed.d/ZMd0d1ZNGd2d3d3ed3d4ZOGd5d6d6eOe ZPGd7d8d8eZQePjRfdddd9d:d;ZSe/fddd?ZTeSZUeTZVGd@dAdAZWGdBdCdCe9ZXddd|sr%)sourceOptionscCs |jdS)NZOP_)r!)r"r#r#r$r%sZAlertDescriptioncCs |jdS)NZALERT_DESCRIPTION_)r!)r"r#r#r$r%sZSSLErrorNumbercCs |jdS)NZ SSL_ERROR_)r!)r"r#r#r$r%s VerifyFlagscCs |jdS)NZVERIFY_)r!)r"r#r#r$r%s VerifyModecCs |jdS)NZCERT_)r!)r"r#r#r$r%scCsi|]\}}||qSr#r#).0r"valuer#r#r$ sr,ZPROTOCOL_SSLv2win32)enum_certificates enum_crls)socketAF_INET SOCK_STREAMcreate_connection) SOL_SOCKETSO_TYPEz tls-uniquezTLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:DH+CHACHA20:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:DH+HIGH:RSA+AESGCM:RSA+AES:RSA+HIGH:!aNULL:!eNULL:!MD5:!3DESzTLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:ECDH+AESGCM:ECDH+CHACHA20:DH+AESGCM:DH+CHACHA20:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:DH+HIGH:RSA+AESGCM:RSA+AES:RSA+HIGH:!aNULL:!eNULL:!MD5:!DSS:!RC4:!3DESc@s eZdZdS)CertificateErrorN)__name__ __module__ __qualname__r#r#r#r$r6sr6c Csg}|s dS|jd^}}|jd}||kr|jdsx|jdr|jtj|n|jtj|j ddx|D]}|jtj|qWtj d d j |d tj }|j |S) zhMatching according to RFC 6125, section 6.4.3 http://tools.ietf.org/html/rfc6125#section-6.4.3 F.*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)splitcountr6reprlowerappendr!reescapereplacecompilejoin IGNORECASEmatch) ZdnhostnameZ max_wildcardsZpatsZleftmostZ remainderZ wildcardsZfragZpatr#r#r$_dnsname_matchs&   rJcCstj|j}||kS)zExact matching of IP addresses. RFC 6125 explicitly doesn't define an algorithm for this (section 1.7.2 - "Out of Scope"). ) ipaddress ip_addressrstrip)Zipnamehost_ipZipr#r#r$_ipaddress_matchsrOcCsP|s tdytj|}Wntk r2d}YnXg}|jdf}xb|D]Z\}}|dkr||dkrpt||rpdS|j|qJ|dkrJ|dk rt||rdS|j|qJW|sxF|jdfD]6}x0|D](\}}|dkrt||rdS|j|qWqWt|dkr td |d j t t |fn,t|dkrDtd ||d fntd dS)a)Verify that *cert* (in decoded format as returned by SSLSocket.getpeercert()) matches the *hostname*. RFC 2818 and RFC 6125 rules are followed, but IP addresses are not accepted for *hostname*. CertificateError is raised on failure. On success, the function returns nothing. ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDNZsubjectAltNameZDNSz IP AddressZsubjectZ commonNamer:z&hostname %r doesn't match either of %sz, zhostname %r doesn't match %rrz=no appropriate commonName or subjectAltName fields were found) ValueErrorrKrLgetrJrArOlenr6rFmapr?)certrIrNZdnsnamesZsankeyr+subr#r#r$match_hostnames>    rWDefaultVerifyPathszQcafile capath openssl_cafile_env openssl_cafile openssl_capath_env openssl_capathcCsdtj}tjj|d|d}tjj|d|d}ttjj|rF|ndtjj|rX|ndf|S)z/Return paths to default cafile and capath. rr:N) _sslget_default_verify_pathsosenvironrQrXpathisfileisdir)partscafilecapathr#r#r$r\Us r\csDeZdZdZfZfddZefddZefddZZ S) _ASN1Objectz#ASN.1 object identifier lookup cstj|ft|ddS)NF)r")super__new___txt2obj)clsoid) __class__r#r$rghsz_ASN1Object.__new__cstj|ft|S)z3Create _ASN1Object from OpenSSL numeric ID )rfrg_nid2obj)riZnid)rkr#r$fromnidksz_ASN1Object.fromnidcstj|ft|ddS)z=Create _ASN1Object from short name, long name or OID T)r")rfrgrh)rir")rkr#r$fromnameqsz_ASN1Object.fromname) r7r8r9__doc__ __slots__rg classmethodrmrn __classcell__r#r#)rkr$recs  reznid shortname longname oidc@seZdZdZdZdZdS)PurposezDSSLContext purpose flags with X509v3 Extended Key Usage objects z1.3.6.1.5.5.7.3.1z1.3.6.1.5.5.7.3.2N)r7r8r9ro SERVER_AUTH CLIENT_AUTHr#r#r#r$rsxsrscseZdZdZd"Zd#ZefddZefdd Zd$d dZ d%ddZ ddZ ddZ ddZ ejfddZefddZejfddZefddZejfddZefdd Zejfd!d ZZS)& SSLContextz|An SSLContext holds various SSL-related configuration options and data, such as certificates and possibly a private key.protocol __weakref__CAROOTcOs"tj||}|tkr|jt|S)N)r rg_SSLv2_IF_EXISTS set_ciphers_DEFAULT_CIPHERS)rirwargskwargsselfr#r#r$rgs  zSSLContext.__new__cCs ||_dS)N)rw)rrwr#r#r$__init__szSSLContext.__init__FTNc Cst|||||||dS)N)sock server_sidedo_handshake_on_connectsuppress_ragged_eofsserver_hostname_context_session) SSLSocket)rrrrrrsessionr#r#r$ wrap_sockets zSSLContext.wrap_socketcCs|j||||d}t||dS)N)rr)r)Z _wrap_bio SSLObject)rZincomingZoutgoingrrrsslobjr#r#r$wrap_bios zSSLContext.wrap_biocCsdt}xN|D]F}t|d}t|dks2t|dkr:td|jt||j|q W|j|dS)Nasciirz(NPN protocols must be 1 to 255 in length) bytearraybytesrRr rAextendZ_set_npn_protocols)r npn_protocolsprotosrwbr#r#r$set_npn_protocolss  zSSLContext.set_npn_protocolscCsdt}xN|D]F}t|d}t|dks2t|dkr:td|jt||j|q W|j|dS)Nrrrz)ALPN protocols must be 1 to 255 in length)rrrRr rArZ_set_alpn_protocols)rZalpn_protocolsrrwrr#r#r$set_alpn_protocolss  zSSLContext.set_alpn_protocolsc Cszt}y@x:t|D].\}}}|dkr|dks6|j|kr|j|qWWntk rdtjdYnX|rv|j|d|S)NZx509_asnTz-unable to enumerate Windows certificate store)cadata)rr.rjrPermissionErrorwarningswarnload_verify_locations)r storenamepurposeZcertsrTencodingZtrustr#r#r$_load_windows_store_certss z$SSLContext._load_windows_store_certscCsDt|tst|tjdkr8x|jD]}|j||q$W|jdS)Nr-) isinstancere TypeErrorsysplatform_windows_cert_storesrZset_default_verify_paths)rrrr#r#r$load_default_certss    zSSLContext.load_default_certscs ttjS)N)r'rfoptions)r)rkr#r$rszSSLContext.optionscstttjj||dS)N)rfrvr__set__)rr+)rkr#r$rscs ttjS)N)r(rf verify_flags)r)rkr#r$rszSSLContext.verify_flagscstttjj||dS)N)rfrvrr)rr+)rkr#r$rsc s*tj}yt|Stk r$|SXdS)N)rf verify_moder)rP)rr+)rkr#r$rs zSSLContext.verify_modecstttjj||dS)N)rfrvrr)rr+)rkr#r$rs)rwrx)ryrz)FTTNN)FNN)r7r8r9rorpr PROTOCOL_TLSrgrrrrrrrsrtrpropertyrsetterrrrrr#r#)rkr$rvs*      rv)rcrdrcCszt|tst|tt}|tjkr2t|_d|_ n|tj krF|j t |sR|sR|rb|j |||n|jtkrv|j||S)zCreate a SSLContext object with default settings. NOTE: The protocol and settings may change anytime without prior deprecation. The values represent a fair balance between maximum compatibility and security. T)rrerrvrrsrt CERT_REQUIREDrcheck_hostnamerur|_RESTRICTED_SERVER_CIPHERSr CERT_NONEr)rrcrdrcontextr#r#r$create_default_contexts       rF) cert_reqsrrcertfilekeyfilercrdrc Cst|tst|t|} |dk r(|| _|| _|r@| r@td|sH|rT| j|||s`|s`|rp| j|||n| jt kr| j || S)a/Create a SSLContext object for Python stdlib modules All Python stdlib modules shall use this function to create SSLContext objects in order to keep common settings in one place. The configuration is less restrict than create_default_context()'s to increase backward compatibility. Nzcertfile must be specified) rrerrvrrrPload_cert_chainrrr) rwrrrrrrcrdrrr#r#r$_create_unverified_contexts      rc@seZdZdZd0ddZeddZejddZedd Zejd d Zed d Z ed dZ eddZ d1ddZ ddZ d2ddZddZddZddZdd Zd!d"Zd#d$Zd%d&Zd'd(Zd3d*d+Zd,d-Zd.d/ZdS)4raThis class implements an interface on top of a low-level SSL object as implemented by OpenSSL. This object captures the state of an SSL connection but does not provide any network IO itself. IO needs to be performed through separate "BIO" objects which are OpenSSL's IO abstraction layer. This class does not have a public constructor. Instances are returned by ``SSLContext.wrap_bio``. This class is typically used by framework authors that want to implement asynchronous IO for SSL through memory buffers. When compared to ``SSLSocket``, this object lacks the following features: * Any form of network IO, including methods such as ``recv`` and ``send``. * The ``do_handshake_on_connect`` and ``suppress_ragged_eofs`` machinery. NcCs&||_|p ||j_|dk r"||j_dS)N)_sslobjownerr)rrrrr#r#r$rGs zSSLObject.__init__cCs|jjS)z(The SSLContext that is currently in use.)rr)rr#r#r$rNszSSLObject.contextcCs ||j_dS)N)rr)rctxr#r#r$rSscCs|jjS)z!The SSLSession for client socket.)rr)rr#r#r$rWszSSLObject.sessioncCs ||j_dS)N)rr)rrr#r#r$r\scCs|jjS)z.Was the client session reused during handshake)rsession_reused)rr#r#r$r`szSSLObject.session_reusedcCs|jjS)z%Whether this is a server-side socket.)rr)rr#r#r$reszSSLObject.server_sidecCs|jjS)z]The currently set server hostname (for SNI), or ``None`` if no server hostame is set.)rr)rr#r#r$rjszSSLObject.server_hostnamecCs(|dk r|jj||}n |jj|}|S)zRead up to 'len' bytes from the SSL object and return them. If 'buffer' is provided, read into this buffer and return the number of bytes read. N)rread)rrRbuffervr#r#r$rps zSSLObject.readcCs |jj|S)zWrite 'data' to the SSL object and return the number of bytes written. The 'data' argument must support the buffer interface. )rwrite)rdatar#r#r$r|szSSLObject.writeFcCs |jj|S)zReturns a formatted version of the data in the certificate provided by the other end of the SSL channel. Return None if no certificate was provided, {} if a certificate was provided, but not validated. )rZpeer_certificate)r binary_formr#r#r$ getpeercertszSSLObject.getpeercertcCstjr|jjSdS)zReturn the currently selected NPN protocol as a string, or ``None`` if a next protocol was not negotiated or if NPN is not supported by one of the peers.N)r[rrselected_npn_protocol)rr#r#r$rszSSLObject.selected_npn_protocolcCstjr|jjSdS)zReturn the currently selected ALPN protocol as a string, or ``None`` if a next protocol was not negotiated or if ALPN is not supported by one of the peers.N)r[rrselected_alpn_protocol)rr#r#r$rsz SSLObject.selected_alpn_protocolcCs |jjS)z_Return the currently selected cipher as a 3-tuple ``(name, ssl_version, secret_bits)``.)rcipher)rr#r#r$rszSSLObject.ciphercCs |jjS)zReturn a list of ciphers shared by the client during the handshake or None if this is not a valid server connection. )rshared_ciphers)rr#r#r$rszSSLObject.shared_cipherscCs |jjS)zReturn the current compression algorithm in use, or ``None`` if compression was not negotiated or not supported by one of the peers.)r compression)rr#r#r$rszSSLObject.compressioncCs |jjS)z8Return the number of bytes that can be read immediately.)rpending)rr#r#r$rszSSLObject.pendingcCs4|jj|jjr0|js tdt|j|jdS)zStart the SSL/TLS handshake.z-check_hostname needs server_hostname argumentN)r do_handshakerrrrPrWr)rr#r#r$rs  zSSLObject.do_handshakecCs |jjS)z!Start the SSL shutdown handshake.)rshutdown)rr#r#r$unwrapszSSLObject.unwrap tls-uniquecCs0|tkrtd|dkr&tdj||jjS)zGet channel binding data for current connection. Raise ValueError if the requested `cb_type` is not supported. Return bytes of the data or None if the data is not available (e.g. before the handshake).z Unsupported channel binding typez tls-uniquez({0} channel binding type not implemented)CHANNEL_BINDING_TYPESrPNotImplementedErrorformatrZ tls_unique_cb)rcb_typer#r#r$get_channel_bindingszSSLObject.get_channel_bindingcCs |jjS)zZReturn a string identifying the protocol version used by the current SSL channel. )rversion)rr#r#r$rszSSLObject.versioncCs |jjS)N)rverify_client_post_handshake)rr#r#r$rsz&SSLObject.verify_client_post_handshake)NN)rN)F)r)r7r8r9rorrrrrrrrrrrrrrrrrrrrrrr#r#r#r$r7s.          rcseZdZdZddddeeddeeddddddddfddZe dd Z e j d d Z e d d Z e j d d Z e ddZ ddZdVddZddZdWddZddZdXddZddZdd Zd!d"Zd#d$Zd%d&ZdYd'd(ZdZd)d*Zd+d,Zd[d-d.Zd\fd/d0 Zd]d1d2Zd^d3d4Zd_d5d6Z d`d7d8Z!d9d:Z"d;d<Z#d=d>Z$d?d@Z%dAdBZ&dCdDZ'dEdFZ(dadGdHZ)dIdJZ*dKdLZ+dMdNZ,dOdPZ-dbdRdSZ.dTdUZ/Z0S)crzThis class implements a subtype of socket.socket that wraps the underlying OS socket in an SSL context when necessary, and provides read and write methods over that channel.NFTrc.Cs&|r ||_n|r| rtd|r0| r0td|r>| r>|}t||_||j_|r`|jj||rr|jj|||r|jj||r|jj|||_||_ ||_ ||_ ||_ ||_ |jtttkrtd|r|rtd|dk rtd|jjo| rtdd|_d|_||_||_||_||_| |_|dk rjtj||j|j|j|j d|j!}|j"n,| dk rtj|| d ntj|| | | d y |j#Wnt$k r}z|j%t%j&krƂd}|j!d k}|j'dy|j(d }Wn>t$k r,}z |j%t%j&t%j)fkrd }WYdd}~XnX|j'||rd}t*|j%|}||_+d|_,y |j-Wnt$k r|YnX|WYdd}~XnXd}|j.|||_/|r"yN|jj0|||}t1|||jd|_|r|j!}|dkrtd|j2Wn$t$tfk r |j-YnXdS)Nz5certfile must be specified for server-side operationszcertfile must be specifiedz!only stream sockets are supportedz4server_hostname can only be specified in client modez,session can only be specified in client modez'check_hostname requires server_hostnameF)familytypeprotofileno)r)rrrrr:z5Closed before TLS handshake with data in recv buffer.T)rrgzHdo_handshake_on_connect should not be specified for non-blocking sockets)3rrPrvrrrrr|rrr ssl_versionca_certsciphersZ getsockoptr4r5r2rrZ_closedrrrrrrr0rrrrr gettimeoutdetach getpeernameOSErrorerrnoZENOTCONNZ setblockingrecvZEINVALr reasonZlibraryclose settimeout _connected _wrap_socketrr)rrrrrrrrrrrrrrrrrrrZ sock_timeouteZ connectedZblockingZnotconn_pre_handshake_datarZ notconn_pre_handshake_data_errorrtimeoutr#r#r$rs                       zSSLSocket.__init__cCs|jS)N)r)rr#r#r$rTszSSLSocket.contextcCs||_||j_dS)N)rrr)rrr#r#r$rXscCs|jdk r|jjSdS)z!The SSLSession for client socket.N)rr)rr#r#r$r]s zSSLSocket.sessioncCs||_|jdk r||j_dS)N)rrr)rrr#r#r$rcs cCs|jdk r|jjSdS)z.Was the client session reused during handshakeN)rr)rr#r#r$ris zSSLSocket.session_reusedcCstd|jjdS)NzCan't dup() %s instances)rrkr7)rr#r#r$duposz SSLSocket.dupcCsdS)Nr#)rmsgr#r#r$ _checkClosedsszSSLSocket._checkClosedcCs|js|jdS)N)rr)rr#r#r$_check_connectedwszSSLSocket._check_connectedcCst|j|jstdy|jj||Stk rn}z.|jdtkr\|jr\|dk rVdSdSnWYdd}~XnXdS)zORead up to LEN bytes and return them. Return zero-length string on EOF.z'Read on closed or unwrapped SSL socket.rNr)rrrPrr r~Z SSL_ERROR_EOFr)rrRrxr#r#r$rszSSLSocket.readcCs"|j|jstd|jj|S)zhWrite DATA to the underlying SSL channel. Returns number of bytes of DATA actually transmitted.z(Write on closed or unwrapped SSL socket.)rrrPr)rrr#r#r$rszSSLSocket.writecCs|j|j|jj|S)zReturns a formatted version of the data in the certificate provided by the other end of the SSL channel. Return None if no certificate was provided, {} if a certificate was provided, but not validated.)rrrr)rrr#r#r$rszSSLSocket.getpeercertcCs*|j|j stj rdS|jjSdS)N)rrr[rr)rr#r#r$rszSSLSocket.selected_npn_protocolcCs*|j|j stj rdS|jjSdS)N)rrr[rr)rr#r#r$rsz SSLSocket.selected_alpn_protocolcCs |j|jsdS|jjSdS)N)rrr)rr#r#r$rszSSLSocket.ciphercCs|j|jsdS|jjS)N)rrr)rr#r#r$rszSSLSocket.shared_cipherscCs |j|jsdS|jjSdS)N)rrr)rr#r#r$rszSSLSocket.compressioncCsB|j|jr0|dkr$td|j|jj|Stj|||SdS)Nrz3non-zero flags not allowed in calls to send() on %s)rrrPrkrr0send)rrflagsr#r#r$rs  zSSLSocket.sendcCsH|j|jrtd|jn&|dkr4tj|||Stj||||SdS)Nz%sendto not allowed on instances of %s)rrrPrkr0sendto)rrZ flags_or_addraddrr#r#r$rs zSSLSocket.sendtocOstd|jdS)Nz&sendmsg not allowed on instances of %s)rrk)rr~rr#r#r$sendmsgszSSLSocket.sendmsgcCs|j|jr|dkr$td|jd}t|L}|jd6}t|}x&||krl|j||d}||7}qHWWdQRXWdQRXntj |||SdS)Nrz6non-zero flags not allowed in calls to sendall() on %sB) rrrPrk memoryviewcastrRrr0sendall)rrrr>ZviewZ byte_viewZamountrr#r#r$rs  "zSSLSocket.sendallcs,|jdkrtj|||S|j|||SdS)zSend a file, possibly by using os.sendfile() if this is a clear-text socket. Return the total number of bytes sent. N)rrfsendfileZ_sendfile_use_send)rfileoffsetr>)rkr#r$rs zSSLSocket.sendfilecCs@|j|jr.|dkr$td|j|j|Stj|||SdS)Nrz3non-zero flags not allowed in calls to recv() on %s)rrrPrkrr0r)rbuflenrr#r#r$rs  zSSLSocket.recvcCsf|j|r|dkrt|}n |dkr*d}|jrR|dkrFtd|j|j||Stj||||SdS)Nirz8non-zero flags not allowed in calls to recv_into() on %s)rrRrrPrkrr0 recv_into)rrnbytesrr#r#r$rs    zSSLSocket.recv_intocCs0|j|jrtd|jntj|||SdS)Nz'recvfrom not allowed on instances of %s)rrrPrkr0recvfrom)rrrr#r#r$rs  zSSLSocket.recvfromcCs2|j|jrtd|jntj||||SdS)Nz,recvfrom_into not allowed on instances of %s)rrrPrkr0 recvfrom_into)rrrrr#r#r$rs  zSSLSocket.recvfrom_intocOstd|jdS)Nz&recvmsg not allowed on instances of %s)rrk)rr~rr#r#r$recvmsg%szSSLSocket.recvmsgcOstd|jdS)Nz+recvmsg_into not allowed on instances of %s)rrk)rr~rr#r#r$ recvmsg_into)szSSLSocket.recvmsg_intocCs |j|jr|jjSdSdS)Nr)rrr)rr#r#r$r-s zSSLSocket.pendingcCs|jd|_tj||dS)N)rrr0r)rZhowr#r#r$r4szSSLSocket.shutdowncCs.|jr|jj}d|_|Stdt|dS)NzNo SSL wrapper around )rrrPstr)rsr#r#r$r9s  zSSLSocket.unwrapcCs$|jr|jjStdt|dS)NzNo SSL wrapper around )rrrPr)rr#r#r$rAs z&SSLSocket.verify_client_post_handshakecCsd|_tj|dS)N)rr0 _real_close)rr#r#r$rGszSSLSocket._real_closec CsF|j|j}z$|dkr(|r(|jd|jjWd|j|XdS)zPerform a TLS/SSL handshake.gN)rrrrr)rblockrr#r#r$rKs  zSSLSocket.do_handshakec Cs|jrtd|jrtd|jj|d|j}t|||jd|_y>|rTt j ||}nd}t j |||s|d|_|j r||j |Sttfk rd|_YnXdS)Nz!can't connect in server-side modez/attempt to connect already-connected SSLSocket!F)rrT)rrPrrrrrrrr0 connect_exconnectrrr)rrr rZrcr#r#r$ _real_connectVs(  zSSLSocket._real_connectcCs|j|ddS)zQConnects to remote ADDR, and then wraps the connection in an SSL channel.FN)r )rrr#r#r$r oszSSLSocket.connectcCs |j|dS)zQConnects to remote ADDR, and then wraps the connection in an SSL channel.T)r )rrr#r#r$r tszSSLSocket.connect_excCs.tj|\}}|jj||j|jdd}||fS)zAccepts a new connection from a remote client, and returns a tuple containing that new connection wrapped with a server-side SSL channel, and the address of the remote client.T)rrr)r0acceptrrrr)rZnewsockrr#r#r$r ys zSSLSocket.accept tls-uniquecCs|jdkrdS|jj|S)zGet channel binding data for current connection. Raise ValueError if the requested `cb_type` is not supported. Return bytes of the data or None if the data is not available (e.g. before the handshake). N)rr)rrr#r#r$rs zSSLSocket.get_channel_bindingcCs|jdkrdS|jjS)z Return a string identifying the protocol version used by the current SSL channel, or None if there is no established channel. N)rr)rr#r#r$rs zSSLSocket.version)N)rN)F)r)N)r)rN)rr)Nr)rr)Nr)F)r )1r7r8r9rorrr1r2rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr r r r rrrrr#r#)rkr$rs`w             rTc Cst|||||||||| d S)N) rrrrrrrrrr)r) rrrrrrrrrrr#r#r$rs rc Csddlm}ddlm}d}d}y|j|ddjd}Wn$tk rbtd||fYn0X||dd|}||d|f|ddSdS)aReturn the time in seconds since the Epoch, given the timestring representing the "notBefore" or "notAfter" date from a certificate in ``"%b %d %H:%M:%S %Y %Z"`` strptime format (C locale). "notBefore" or "notAfter" dates must use UTC (RFC 5280). Month is one of: Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec UTC should be specified as GMT (see ASN1_TIME_print()) r)strptime)timegmJanFebMarAprMayJunJulAugSepOctNovDecz %d %H:%M:%S %Y GMTNrZr:z*time data %r does not match format "%%b%s"rY) rrrrrrrrrrrr)ZtimerZcalendarrindextitlerP)Z cert_timerrZmonthsZ time_formatZ month_numberZttr#r#r$cert_time_to_secondss  rz-----BEGIN CERTIFICATE-----z-----END CERTIFICATE-----cCs2ttj|dd}tdtj|ddtdS)z[Takes a certificate in binary DER format and returns the PEM version of it as a string.ASCIIstrict @)rbase64Zstandard_b64encode PEM_HEADERtextwrapZfill PEM_FOOTER)Zder_cert_bytesfr#r#r$DER_cert_to_PEM_certsr)cCs\|jtstdt|jjts0tdt|jtttt }tj|j ddS)zhTakes a certificate in ASCII PEM format and returns the DER-encoded version of it as a byte sequencez(Invalid PEM encoding; must start with %sz&Invalid PEM encoding; must end with %sr r!) r!r%rPstripendswithr'rRr$Z decodebytesencode)Zpem_cert_stringdr#r#r$PEM_cert_to_DER_certs r.c Csd|\}}|dk rt}nt}t|||d}t|&}|j|}|jd} WdQRXWdQRXt| S)zRetrieve the certificate from the server at the specified address, and return it as a PEM-encoded string. If 'ca_certs' is specified, validate the server cert against it. If 'ssl_version' is specified, use it in the connection attempt.N)rrcT)rr_create_stdlib_contextr3rrr)) rrrZhostZportrrrZsslsockZdercertr#r#r$get_server_certificates  r0cCs tj|dS)Nz )_PROTOCOL_NAMESrQ)Z protocol_coder#r#r$get_protocol_namesr2)r:)brorKr&rBrr] collectionsrenumrZ_EnumrZ_IntEnumrZ_IntFlagr[rrrr r r r r rrrrrrhrrlrrrrr ImportErrorrrrrrr_convertr7rrr __members__itemsr1getattrr{rr.r/r0r1r2r3r4r5r$rrrZ socket_errorZHAS_TLS_UNIQUErr}rrPr6rJrOrWrXr\rersrvrtrrZ_create_default_https_contextr/rrrrrr%r'r)r.r0r2r#r#r#r$[s       1 4i%J