o
    ¯b%4  ã                	   @   s0  d Z ddlmZmZmZ ddlmZmZ ddlm	Z	m
Z
 ddlmZmZmZ ddlmZ ddlmZmZmZ ddlmZmZmZ dd	lmZ dd
lmZmZmZ ddlm Z  ddl!m"Z"m#Z#m$Z$ ddl%m&Z& ddl'm(Z( ddl)m*Z* ddl+m,Z, zddl-m.Z. W n e/y‹   dZ.Y nw ddl0m1Z1m2Z2m3Z3 G dd„ dƒZ4G dd„ dƒZ5eeƒG dd„ dƒƒZ6G dd„ dee5ƒZ7G dd„ dƒZ8G dd„ de4e eƒZ9G d d!„ d!ee5ƒZ:G d"d#„ d#e4e e5ee8ƒZ;G d$d%„ d%e4e5e8e#e$e ƒZ<e=ƒ  >e; ?¡ ¡ e=ƒ  >e9 ?¡ ¡ e=ƒ  >e<ƒ  ?¡ ¡ G d&d'„ d'e e"e5ƒZ@e=ƒ  >e@ ?¡ ¡ dS )(z0
Tests for implementations of L{ITLSTransport}.
é    )ÚOptionalÚSequenceÚType)Ú	InterfaceÚimplementer)ÚDeferredÚDeferredList)ÚSSL4ClientEndpointÚSSL4ServerEndpointÚTCP4ClientEndpoint)ÚConnectionClosed)ÚIReactorSSLÚIStreamClientEndpointÚITLSTransport)ÚClientFactoryÚProtocolÚServerFactory)Ú
Cooperator)ÚBrokenContextFactoryÚConnectionTestsMixinÚEndpointCreator)ÚReactorBuilder)ÚAbortConnectionMixinÚConnectToTCPListenerMixinÚStreamTransportTestsMixin)ÚnetworkString)ÚFilePath)Úplatform)ÚSkipTest)ÚFILETYPE_PEMN)ÚClientContextFactoryÚKeyPairÚPrivateCertificatec                   @   sB   e Zd ZU egZeeee   e	d< e
 ¡ rdZeedœZdS dS )ÚTLSMixinÚrequiredInterfaceszcFor some reason, these reactors don't deal with SSL disconnection correctly on Windows.  See #3371.)z*twisted.internet.glib2reactor.Glib2Reactorz(twisted.internet.gtk2reactor.Gtk2ReactorN)Ú__name__Ú
__module__Ú__qualname__r   r$   r   r   r   r   Ú__annotations__r   Ú	isWindowsÚmsgÚskippedReactors© r,   r,   ú@/usr/lib/python3/dist-packages/twisted/internet/test/test_tls.pyr#   3   s   
 ÿ
þûr#   c                   @   s@   e Zd ZddlZeeejƒƒ d¡ d¡Z	[dd„ Z
dd„ ZdS )	ÚContextGeneratingMixinr   Ns   tests
   server.pemc                 C   s(   | j  ¡ }t |t |t¡t¡}| ¡ S )zM
        Return a new SSL context suitable for use in a test server.
        )Ú_pemÚ
getContentr"   Úloadr!   r   Úoptions)ÚselfÚpemÚcertr,   r,   r-   ÚgetServerContextI   s
   
ÿz'ContextGeneratingMixin.getServerContextc                 C   s   t ƒ S ©N)r    ©r3   r,   r,   r-   ÚgetClientContextS   s   z'ContextGeneratingMixin.getClientContext)r%   r&   r'   Útwistedr   r   Ú__file__ÚsiblingÚchildr/   r6   r9   r,   r,   r,   r-   r.   A   s    ÿ
r.   c                   @   ó    e Zd ZdZdd„ Zdd„ ZdS )ÚStartTLSClientEndpointa!  
    An endpoint which wraps another one and adds a TLS layer immediately when
    connections are set up.

    @ivar wrapped: A L{IStreamClientEndpoint} provider which will be used to
        really set up connections.

    @ivar contextFactory: A L{ContextFactory} to use to do TLS.
    c                 C   s   || _ || _d S r7   )ÚwrappedÚcontextFactory)r3   r@   rA   r,   r,   r-   Ú__init__c   s   
zStartTLSClientEndpoint.__init__c                    s$   G ‡ ‡fdd„dt ƒ}ˆj |ƒ ¡S )z¼
        Establish a connection using a protocol build by C{factory} and
        immediately start TLS on it.  Return a L{Deferred} which fires with the
        protocol instance.
        c                       s   e Zd Z‡ ‡fdd„ZdS )z6StartTLSClientEndpoint.connect.<locals>.WrapperFactoryc                    s(   ˆ  |¡‰ ˆ jf‡ ‡fdd„	}|ˆ _ˆ S )Nc                    s   ˆ j  ˆj¡ | ƒ  d S r7   )Ú	transportÚstartTLSrA   )Úorig)Úprotocolr3   r,   r-   ÚconnectionMades   s   
z\StartTLSClientEndpoint.connect.<locals>.WrapperFactory.buildProtocol.<locals>.connectionMade)ÚbuildProtocolrG   )ÚwrapperSelfÚaddrrG   ©Úfactoryr3   )rF   r-   rH   p   s   
zDStartTLSClientEndpoint.connect.<locals>.WrapperFactory.buildProtocolN)r%   r&   r'   rH   r,   rK   r,   r-   ÚWrapperFactoryo   s    rM   )r   r@   Úconnect)r3   rL   rM   r,   rK   r-   rN   g   s   zStartTLSClientEndpoint.connectN)r%   r&   r'   Ú__doc__rB   rN   r,   r,   r,   r-   r?   W   s    
r?   c                   @   r>   )ÚStartTLSClientCreatorz{
    Create L{ITLSTransport.startTLS} endpoint for the client, and normal SSL
    for server just because it's easier.
    c                 C   ó   t |d|  ¡ ƒS )zµ
        Construct an SSL server endpoint.  This should be constructing a TCP
        server endpoint which immediately calls C{startTLS} instead, but that
        is hard.
        r   ©r
   r6   ©r3   Úreactorr,   r,   r-   Úserverƒ   s   zStartTLSClientCreator.serverc                 C   s   t t|d|jƒtƒ ƒS )zS
        Construct a TCP client endpoint wrapped to immediately start TLS.
        ú	127.0.0.1)r?   r   Úportr    ©r3   rT   ÚserverAddressr,   r,   r-   Úclient‹   s   þzStartTLSClientCreator.clientN©r%   r&   r'   rO   rU   rZ   r,   r,   r,   r-   rP   }   s    rP   c                   @   s   e Zd ZdZdd„ ZdS )ÚBadContextTestsMixinz�
    Mixin for L{ReactorBuilder} subclasses which defines a helper for testing
    the handling of broken context factories.
    c                 C   s0   |   ¡ }|  t||tƒ ¡}|  tjt|ƒ¡ dS )aÐ  
        Assert that the exception raised by a broken context factory's
        C{getContext} method is raised by some reactor method.  If it is not, an
        exception will be raised to fail the test.

        @param useIt: A two-argument callable which will be called with a
            reactor and a broken context factory and which is expected to raise
            the same exception as the broken context factory's C{getContext}
            method.
        N)ÚbuildReactorÚassertRaisesÚ
ValueErrorr   ÚassertEqualÚmessageÚstr)r3   ÚuseItrT   Úexcr,   r,   r-   Ú_testBadContext›   s   z$BadContextTestsMixin._testBadContextN)r%   r&   r'   rO   re   r,   r,   r,   r-   r\   •   s    r\   c                   @   s   e Zd ZdZeƒ ZdS )ÚStartTLSClientTestsMixinzš
    Tests for TLS connections established using L{ITLSTransport.startTLS} (as
    opposed to L{IReactorSSL.connectSSL} or L{IReactorSSL.listenSSL}).
    N)r%   r&   r'   rO   rP   Ú	endpointsr,   r,   r,   r-   rf   «   s    
rf   c                   @   r>   )Ú
SSLCreatorz
    Create SSL endpoints.
    c                 C   rQ   )zQ
        Create an SSL server endpoint on a TCP/IP-stack allocated port.
        r   rR   rS   r,   r,   r-   rU   ¹   s   zSSLCreator.serverc                 C   s   t |d|jtƒ ƒS )z¨
        Create an SSL client endpoint which will connect localhost on
        the port given by C{serverAddress}.

        @type serverAddress: L{IPv4Address}
        rV   )r	   rW   r    rX   r,   r,   r-   rZ   ¿   s   ÿzSSLCreator.clientNr[   r,   r,   r,   r-   rh   ´   s    rh   c                   @   s&   e Zd ZdZeƒ Zdd„ Zdd„ ZdS )ÚSSLClientTestsMixinz<
    Mixin defining tests relating to L{ITLSTransport}.
    c                 C   ó   dd„ }|   |¡ dS )zÆ
        If the context factory passed to L{IReactorSSL.connectSSL} raises an
        exception from its C{getContext} method, that exception is raised by
        L{IReactorSSL.connectSSL}.
        c                 S   s   |   ddtƒ |¡S )NrV   iÒ  )Ú
connectSSLr   ©rT   rA   r,   r,   r-   rc   ß   s   
ÿz2SSLClientTestsMixin.test_badContext.<locals>.useItN©re   ©r3   rc   r,   r,   r-   Útest_badContextØ   s   z#SSLClientTestsMixin.test_badContextc                    s  G dd„ dt ƒ}|  ¡ ‰tƒ }tƒ |_||_|  ¡ |_tƒ }tƒ |_||_|  	¡ |_|jj
|j_
g ‰ t|j|jgdd�}‡ fdd„}| |¡ ˆjd|dd	�}|  |j¡ ˆ | ¡ j| ¡ j|¡}|  |j¡ | ‡fd
d„¡ |  ˆ¡ ˆ d  t¡ ˆ d  t¡ dS )aO  
        L{ITCPTransport.loseConnection} ends a connection which was set up with
        L{ITLSTransport.startTLS} and which has recently been written to.  This
        is intended to verify that a socket send error masked by the TLS
        implementation doesn't prevent the connection from being reported as
        closed.
        c                   @   s$   e Zd Zdd„ Zdd„ Zdd„ ZdS )zQSSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocolc                 S   sN   t  | j¡s| jj}d | j_| tdƒ¡ d S | j | jj¡ | j 	d¡ d S )NzNo ITLSTransport supportó   x)
r   Ú
providedByrC   rL   ÚfinishedÚerrbackr   rD   ÚcontextÚwrite)r3   rr   r,   r,   r-   rG   ð   s   z`SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocol.connectionMadec                 S   s   | j  d¡ | j  ¡  d S )Nó   y)rC   ru   ÚloseConnection)r3   Údatar,   r,   r-   ÚdataReceivedþ   s   z^SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocol.dataReceivedc                 S   s*   | j j}|d urd | j _| |¡ d S d S r7   )rL   rr   Úcallback)r3   Úreasonrr   r,   r,   r-   ÚconnectionLost  s
   þz`SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.ShortProtocol.connectionLostN)r%   r&   r'   rG   ry   r|   r,   r,   r,   r-   ÚShortProtocolï   s    
r}   T)ÚconsumeErrorsc                    s"   ˆ   | d d | d d g¡ d S )Nr   é   )Úextend)Úresults)ÚlostConnectionResultsr,   r-   Ú
cbFinished"  s   "zNSSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.cbFinishedr   rV   )Ú	interfacec                    s   ˆ   ¡ S r7   )Ústop)Úign©rT   r,   r-   Ú<lambda>/  s    zLSSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLS.<locals>.<lambda>r   N)r   r]   r   r   rr   rF   r6   rt   r   r9   Úmethodr   ÚaddCallbackÚ	listenTCPÚ
addCleanupÚstopListeningÚ
connectTCPÚgetHostÚhostrW   Ú
disconnectÚ
runReactorÚtrapr   )r3   r}   ÚserverFactoryÚclientFactoryrr   rƒ   rW   Ú	connectorr,   )r‚   rT   r-   Ú&test_disconnectAfterWriteAfterStartTLSæ   s6   	!

ÿ
ÿ
z:SSLClientTestsMixin.test_disconnectAfterWriteAfterStartTLSN)r%   r&   r'   rO   rh   rg   ro   r—   r,   r,   r,   r-   ri   Ë   s
    ri   c                   @   s8   e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
d„ ZdS )ÚTLSPortTestsBuilderz,
    Tests for L{IReactorSSL.listenSSL}
    c                 C   s   |  d||  ¡ ¡S )z0
        Get a TLS port from a reactor.
        r   )Ú	listenSSLr6   )r3   rT   rL   r,   r,   r-   ÚgetListeningPortA  ó   z$TLSPortTestsBuilder.getListeningPortc                 C   s   d||  ¡ jf S )zY
        Get the message expected to be logged when a TLS port starts listening.
        z%s (TLS) starting on %d©r�   rW   )r3   rW   rL   r,   r,   r-   Ú#getExpectedStartListeningLogMessageG  r›   z7TLSPortTestsBuilder.getExpectedStartListeningLogMessagec                 C   s   d|  ¡ j› d�S )zJ
        Get the expected connection lost message for a TLS port.
        z
(TLS Port z Closed)rœ   )r3   rW   r,   r,   r-   ÚgetExpectedConnectionLostLogMsgM  r›   z3TLSPortTestsBuilder.getExpectedConnectionLostLogMsgc                 C   rj   )zÄ
        If the context factory passed to L{IReactorSSL.listenSSL} raises an
        exception from its C{getContext} method, that exception is raised by
        L{IReactorSSL.listenSSL}.
        c                 S   s   |   dtƒ |¡S )Nr   )r™   r   rl   r,   r,   r-   rc   Z  s   z2TLSPortTestsBuilder.test_badContext.<locals>.useItNrm   rn   r,   r,   r-   ro   S  s   z#TLSPortTestsBuilder.test_badContextc                 C   s   |  | j|j||  ¡ ¡S )a  
        Connect to the given listening TLS port, assuming the
        underlying transport is TCP.

        @param reactor: The reactor under test.
        @type reactor: L{IReactorSSL}

        @param address: The listening's address.  Only the C{port}
            component is used; see
            L{ConnectToTCPListenerMixin.LISTENER_HOST}.
        @type address: L{IPv4Address} or L{IPv6Address}

        @param factory: The client factory.
        @type factory: L{ClientFactory}

        @return: The connector
        )rk   ÚLISTENER_HOSTrW   r9   )r3   rT   ÚaddressrL   r,   r,   r-   ÚconnectToListener_  s   üz%TLSPortTestsBuilder.connectToListenerN)	r%   r&   r'   rO   rš   r�   rž   ro   r¡   r,   r,   r,   r-   r˜   5  s    r˜   c                   @   s,   e Zd ZdZefZeƒ Zdd„ Zdd„ Z	dS )ÚAbortSSLConnectionTestsz-
    C{abortConnection} tests using SSL.
    c                    s<   t  | ¡‰ ddlm} t‡ fdd„d�}|  |d|j¡ ˆ S )Nr   )Ú_producer_helpersc                    s   ˆ   d| ¡S )Ngñhãˆµøä>)Ú	callLater)Úxr‡   r,   r-   rˆ   Ž  s    z6AbortSSLConnectionTests.buildReactor.<locals>.<lambda>)Ú	schedulerÚ	cooperate)r   r]   Útwisted.internetr£   r   Úpatchr§   )r3   r£   Ú
cooperatorr,   r‡   r-   r]   ˆ  s
   
z$AbortSSLConnectionTests.buildReactorc                 C   s   t d u rtdƒ‚d S )NzOpenSSL not available.)r   r   r8   r,   r,   r-   ÚsetUp’  s   ÿzAbortSSLConnectionTests.setUpN)
r%   r&   r'   rO   r   r$   rh   rg   r]   r«   r,   r,   r,   r-   r¢   ~  s    
r¢   )ArO   Útypingr   r   r   Úzope.interfacer   r   Útwisted.internet.deferr   r   Útwisted.internet.endpointsr	   r
   r   Útwisted.internet.errorr   Útwisted.internet.interfacesr   r   r   Útwisted.internet.protocolr   r   r   Útwisted.internet.taskr   Ú&twisted.internet.test.connectionmixinsr   r   r   Ú#twisted.internet.test.reactormixinsr   Útwisted.internet.test.test_tcpr   r   r   Útwisted.python.compatr   Útwisted.python.filepathr   Útwisted.python.runtimer   Útwisted.trial.unittestr   ÚOpenSSL.cryptor   ÚImportErrorÚtwisted.internet.sslr    r!   r"   r#   r.   r?   rP   r\   rf   rh   ri   r˜   ÚglobalsÚupdateÚmakeTestCaseClassesr¢   r,   r,   r,   r-   Ú<module>   sh   ÿ%	
û
júD
ÿ