o
    ¯b[  ã                   @   s   d Z ddlZddlZddlmZmZmZmZ ddlm	Z	 ddl
mZ ddlmZ ddlmZ ddlmZ dd	lmZ dd
lmZ zddlmamZ ddlma ddlmZmZ W n eyh   dd„ Zeƒ  Y nw ddlm Z  G dd„ dej!ƒZ"G dd„ dej!ƒZ#G dd„ dej$ƒZ%G dd„ dej$ƒZ&e ej'ƒG dd„ dej$ƒƒZ(dd„ Z)dd„ Z*G dd „ d ƒZ+tdur½G d!d"„ d"tj,ƒZ-G d#d$„ d$eeƒZ.G d%d&„ d&eƒZ/G d'd(„ d(e/ƒZ0G d)d*„ d*eƒZ1G d+d,„ d,ee+ƒZ2G d-d.„ d.ƒZ3G d/d0„ d0eƒZ4G d1d2„ d2eƒZ5dS )3z 
Tests for twisted SSL support.
é    N)ÚdeferÚ
interfacesÚprotocolÚreactor)ÚConnectionDone)Úbasic)ÚFilePath)Úplatform)ÚwaitUntilAllDisconnected)ÚProperlyCloseFilesMixin)ÚTestCase)ÚSSLÚcrypto)Ússl)ÚClientTLSContextÚcertPathc                   C   s   d  a ad S ©N)r   r   © r   r   ú7/usr/lib/python3/dist-packages/twisted/test/test_ssl.pyÚ_noSSL   s   r   )Úimplementerc                   @   s@   e Zd ZdZg d¢ZddgZdd„ Zdd„ Zd	d
„ Zdd„ Z	dS )ÚUnintelligentProtocola  
    @ivar deferred: a deferred that will fire at connection lost.
    @type deferred: L{defer.Deferred}

    @cvar pretext: text sent before TLS is set up.
    @type pretext: C{bytes}

    @cvar posttext: text sent after TLS is set up.
    @type posttext: C{bytes}
    )s
   first lines   last thing before tls startsó   STARTTLSs   first thing after tls starteds   last thing everc                 C   ó   t  ¡ | _d S r   ©r   ÚDeferredÚdeferred©Úselfr   r   r   Ú__init__7   ó   zUnintelligentProtocol.__init__c                 C   s   | j D ]}|  |¡ qd S r   )ÚpretextÚsendLine)r   Úlr   r   r   ÚconnectionMade:   s   
ÿz$UnintelligentProtocol.connectionMadec                 C   sD   |dkr | j  tƒ | jj¡ | jD ]}|  |¡ q| j  ¡  d S d S )Nó   READY)Ú	transportÚstartTLSr   ÚfactoryÚclientÚposttextr"   ÚloseConnection)r   Úliner#   r   r   r   ÚlineReceived>   s   
üz"UnintelligentProtocol.lineReceivedc                 C   ó   | j  d ¡ d S r   ©r   Úcallback©r   Úreasonr   r   r   ÚconnectionLostE   ó   z$UnintelligentProtocol.connectionLostN)
Ú__name__Ú
__module__Ú__qualname__Ú__doc__r!   r*   r   r$   r-   r3   r   r   r   r   r   '   s    r   c                   @   s:   e Zd ZdZddd„Zdd„ Zdd„ Zd	d
„ Zdd„ ZdS )ÚLineCollectoraJ  
    @ivar deferred: a deferred that will fire at connection lost.
    @type deferred: L{defer.Deferred}

    @ivar doTLS: whether the protocol is initiate TLS or not.
    @type doTLS: C{bool}

    @ivar fillBuffer: if set to True, it will send lots of data once
        C{STARTTLS} is received.
    @type fillBuffer: C{bool}
    Fc                 C   s   || _ || _t ¡ | _d S r   )ÚdoTLSÚ
fillBufferr   r   r   )r   r:   r;   r   r   r   r   V   s   zLineCollector.__init__c                 C   s   d| j _g | j _d S )Nó    )r(   ÚrawdataÚlinesr   r   r   r   r$   [   s   zLineCollector.connectionMadec                 C   sv   | j j |¡ |dkr9| jrtdƒD ]}|  d¡ q|  d¡ | jr3tttd�}| j	 
|| j j¡ d S |  ¡  d S d S )Nr   iô  sè  XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXr%   )ÚprivateKeyFileNameÚcertificateFileName)r(   r>   Úappendr;   Úranger"   r:   ÚServerTLSContextr   r&   r'   ÚserverÚ
setRawMode)r   r,   ÚxÚctxr   r   r   r-   _   s   
þôzLineCollector.lineReceivedc                 C   s   | j  j|7  _| j ¡  d S r   )r(   r=   r&   r+   ©r   Údatar   r   r   ÚrawDataReceivedo   s   zLineCollector.rawDataReceivedc                 C   r.   r   r/   r1   r   r   r   r3   s   r4   zLineCollector.connectionLostN©F)	r5   r6   r7   r8   r   r$   r-   rJ   r3   r   r   r   r   r9   I   s    
r9   c                   @   s   e Zd ZdZdd„ ZdS )ÚSingleLineServerProtocolzK
    A protocol that sends a single line of data at C{connectionMade}.
    c                 C   s   | j  d¡ | j  ¡  d S )Nó   +OK <some crap>
)r&   ÚwriteÚgetPeerCertificater   r   r   r   r$   |   s   z'SingleLineServerProtocol.connectionMadeN)r5   r6   r7   r8   r$   r   r   r   r   rL   w   s    rL   c                   @   ó(   e Zd ZdZdd„ Zdd„ Zdd„ ZdS )	ÚRecordingClientProtocolzv
    @ivar deferred: a deferred that will fire with first received content.
    @type deferred: L{defer.Deferred}
    c                 C   r   r   r   r   r   r   r   r   ‡   r    z RecordingClientProtocol.__init__c                 C   ó   | j  ¡  d S r   )r&   rO   r   r   r   r   r$   Š   r    z&RecordingClientProtocol.connectionMadec                 C   s   | j  |¡ d S r   r/   rH   r   r   r   ÚdataReceived�   r4   z$RecordingClientProtocol.dataReceivedN)r5   r6   r7   r8   r   r$   rS   r   r   r   r   rQ   �   s
    rQ   c                   @   ó    e Zd ZdZdd„ Zdd„ ZdS )Ú ImmediatelyDisconnectingProtocolz•
    A protocol that disconnect immediately on connection. It fires the
    C{connectionDisconnected} deferred of its factory on connetion lost.
    c                 C   rR   r   ©r&   r+   r   r   r   r   ÚhandshakeCompleted˜   r    z3ImmediatelyDisconnectingProtocol.handshakeCompletedc                 C   s   | j j d ¡ d S r   )r(   ÚconnectionDisconnectedr0   r1   r   r   r   r3   ›   ó   z/ImmediatelyDisconnectingProtocol.connectionLostN)r5   r6   r7   r8   rW   r3   r   r   r   r   rU   ‘   s    rU   c                 C   s®   t  ¡ }| t jd¡ t  ¡ }| ¡ }| |_||_| |¡ | 	|d¡ t  
¡ }| d¡ | d¡ | d¡ | | ¡ ¡ | | ¡ ¡ | | ¡ ¡ | 	|d¡ |||fS )z‘
    Create a certificate for given C{organization} and C{organizationalUnit}.

    @return: a tuple of (key, request, certificate) objects.
    i   Úmd5é   r   é<   )r   ÚPKeyÚgenerate_keyÚTYPE_RSAÚX509ReqÚget_subjectÚOÚOUÚ
set_pubkeyÚsignÚX509Úset_serial_numberÚgmtime_adj_notBeforeÚgmtime_adj_notAfterÚ
set_issuerÚset_subjectÚ
get_pubkey)ÚorganizationÚorganizationalUnitÚpkeyÚreqÚsubjectÚcertr   r   r   ÚgenerateCertificateObjectsŸ   s"   




rs   c           
      C   sn   t ||ƒ\}}}d|tjfd|tjfd|tjffD ]\}}}tj | |f¡ d¡}	t	|	ƒ 
|tj|ƒ¡ qdS )z…
    Create certificate files key, req and cert prefixed by C{basename} for
    given C{organization} and C{organizationalUnit}.
    Úkeyrp   rr   zutf-8N)rs   r   Údump_privatekeyÚdump_certificate_requestÚdump_certificateÚosÚextsepÚjoinÚencoder   Ú
setContentÚFILETYPE_PEM)
Úbasenamerm   rn   ro   rp   rr   ÚextÚobjÚdumpFuncÚfNamer   r   r   ÚgenerateCertificateFiles»   s   


ýúrƒ   c                   @   rT   )ÚContextGeneratingMixinah  
    Offer methods to create L{ssl.DefaultOpenSSLContextFactory} for both client
    and server.

    @ivar clientBase: prefix of client certificate files.
    @type clientBase: C{str}

    @ivar serverBase: prefix of server certificate files.
    @type serverBase: C{str}

    @ivar clientCtxFactory: a generated context factory to be used in
        L{IReactorSSL.connectSSL}.
    @type clientCtxFactory: L{ssl.DefaultOpenSSLContextFactory}

    @ivar serverCtxFactory: a generated context factory to be used in
        L{IReactorSSL.listenSSL}.
    @type serverCtxFactory: L{ssl.DefaultOpenSSLContextFactory}
    c                 O   sN   |   ¡ }t|||ƒ tjtj |df¡tj |df¡g|¢R i |¤Ž}||fS )Nrt   rr   )Úmktemprƒ   r   ÚDefaultOpenSSLContextFactoryrx   ry   rz   )r   ÚorgÚorgUnitÚargsÚkwArgsÚbaseÚserverCtxFactoryr   r   r   ÚmakeContextFactoryß   s   þýüz)ContextGeneratingMixin.makeContextFactoryc                 C   s4   | j |i |¤Ž\| _| _| j |i |¤Ž\| _| _d S r   )r�   Ú
clientBaseÚclientCtxFactoryÚ
serverBaserŒ   )r   Ú
clientArgsÚclientKwArgsÚ
serverArgsÚserverKwArgsr   r   r   ÚsetupServerAndClientë   s   ÿÿÿÿz+ContextGeneratingMixin.setupServerAndClientN)r5   r6   r7   r8   r�   r•   r   r   r   r   r„   Ë   s    r„   c                   @   s   e Zd ZdZdZdd„ ZdS )rC   zf
        A context factory with a default method set to
        L{OpenSSL.SSL.SSLv23_METHOD}.
        Fc                 O   s(   t j|d< tjj| g|¢R i |¤Ž d S )NÚ	sslmethod)r   ÚSSLv23_METHODr   r†   r   )r   r‰   Úkwr   r   r   r   þ   s   
zServerTLSContext.__init__N)r5   r6   r7   r8   ÚisClientr   r   r   r   r   rC   ö   s    rC   c                   @   óD   e Zd ZdZe ed¡du rdZdd„ Zdd„ Z	dd	„ Z
d
d„ ZdS )ÚStolenTCPTestszc
    For SSL transports, test many of the same things which are tested for
    TCP transports.
    Nú2Reactor does not support SSL, cannot run SSL testsc                 C   s.   t j ttƒ ¡ ¡}| ¡ }tj||||d�S )zY
        Create an SSL server with a certificate using L{IReactorSSL.listenSSL}.
        ©Ú	interface)	r   ÚPrivateCertificateÚloadPEMr   r   Ú
getContentÚoptionsr   Ú	listenSSL)r   ÚaddressÚ
portNumberr(   rr   ÚcontextFactoryr   r   r   ÚcreateServer  s   zStolenTCPTests.createServerc                 C   s   t  ¡ }| |||¡S )zG
        Create an SSL client using L{IReactorSSL.connectSSL}.
        )r   ÚCertificateOptionsÚ
connectSSL)r   r¤   r¥   ÚclientCreatorr¦   r   r   r   ÚconnectClient  s   zStolenTCPTests.connectClientc                 C   s   t jS )zº
        Return L{OpenSSL.SSL.Error} as the expected error type which will be
        raised by a write to the L{OpenSSL.SSL.Connection} object after it has
        been closed.
        )r   ÚErrorr   r   r   r   ÚgetHandleExceptionType  s   z%StolenTCPTests.getHandleExceptionTypec                 C   s4   t  t  t  d¡t  t  d¡t  d¡¡t  d¡¡¡S )a4  
        Return a L{hamcrest.core.matcher.Matcher} for the argument
        L{OpenSSL.SSL.Error} will be constructed with for this case.
        This is basically just a random OpenSSL implementation detail.
        It would be better if this test worked in a way which did not
        require this.
        zSSL routinesÚ	SSL_writeÚssl_write_internalzprotocol is shutdown)ÚhamcrestÚcontainsÚequal_toÚany_ofr   r   r   r   ÚgetHandleErrorCodeMatcher#  s   
þúÿz(StolenTCPTests.getHandleErrorCodeMatcher)r5   r6   r7   r8   r   ÚIReactorSSLr   Úskipr§   r«   r­   r´   r   r   r   r   r›     s    r›   c                   @   sZ   e Zd ZdZe ed¡du rdZdZdZ	dZ
dd„ Zddd„Zd	d
„ Zdd„ Zdd„ ZdS )ÚTLSTestszƒ
    Tests for startTLS support.

    @ivar fillBuffer: forwarded to L{LineCollector.fillBuffer}
    @type fillBuffer: C{bool}
    Nrœ   Fc                 C   s8   | j jd ur| j j ¡  | jjd ur| jj ¡  d S d S r   )ÚclientProtor&   r+   ÚserverProtor   r   r   r   ÚtearDownI  s
   ÿzTLSTests.tearDownc                    sª   ˆ | _ t ¡  }| _‡ fdd„|_|rd|_nd|_ˆ| _t ¡  }| _‡fdd„|_|r1d|_nd|_t	j
d|dd�}|  |j¡ t	 d| ¡ j|¡ t ˆ jˆjg¡S )	a½  
        Helper method to run TLS tests.

        @param clientProto: protocol instance attached to the client
            connection.
        @param serverProto: protocol instance attached to the server
            connection.
        @param clientIsServer: flag indicated if client should initiate
            startTLS instead of server.

        @return: a L{defer.Deferred} that will fire when both connections are
            lost.
        c                      ó   ˆ S r   r   r   ©r¸   r   r   Ú<lambda>_  ó    z#TLSTests._runTest.<locals>.<lambda>FTc                      r»   r   r   r   ©r¹   r   r   r½   g  r¾   r   ú	127.0.0.1r�   )r¸   r   ÚClientFactoryÚclientFactoryrD   r)   r¹   ÚServerFactoryÚserverFactoryr   Ú	listenTCPÚ
addCleanupÚstopListeningÚ
connectTCPÚgetHostÚportr   ÚgatherResultsr   )r   r¸   r¹   ÚclientIsServerÚcfÚsfrÊ   r   ©r¸   r¹   r   Ú_runTestO  s    zTLSTests._runTestc                    ó,   ‡ fdd„}ˆ   tƒ tdˆ jƒ¡}| |¡S )z~
        Test for server and client startTLS: client should received data both
        before and after the startTLS.
        c                    ó   ˆ   ˆ jjtjtj ¡ d S r   )ÚassertEqualrÄ   r>   r   r!   r*   )Úignorer   r   r   Úcheckz  ó   
þz TLSTests.test_TLS.<locals>.checkT©rÐ   r   r9   r;   ÚaddCallback©r   rÕ   Údr   r   r   Útest_TLSt  s   
zTLSTests.test_TLSc                    rÑ   )z›
        Test for server startTLS not followed by a startTLS in client: the data
        received after server startTLS should be received as raw.
        c                    s&   ˆ   ˆ jjtj¡ ˆ  ˆ jjd¡ d S )NzNo encrypted bytes received)rÓ   rÄ   r>   r   r!   Ú
assertTruer=   ©Úignoredr   r   r   rÕ   ‰  s   z"TLSTests.test_unTLS.<locals>.checkFr×   rÙ   r   r   r   Ú
test_unTLSƒ  s
   ÿ
zTLSTests.test_unTLSc                    s.   ‡ fdd„}ˆ   tdˆ jƒtƒ d¡}| |¡S )z:
        Test startTLS first initiated by client.
        c                    rÒ   r   )rÓ   rÂ   r>   r   r!   r*   rÝ   r   r   r   rÕ   —  rÖ   z)TLSTests.test_backwardsTLS.<locals>.checkT)rÐ   r9   r;   r   rØ   rÙ   r   r   r   Útest_backwardsTLS’  s
   ÿ
zTLSTests.test_backwardsTLSrK   )r5   r6   r7   r8   r   rµ   r   r¶   r;   r¸   r¹   rº   rÐ   rÛ   rß   rà   r   r   r   r   r·   9  s    
%r·   c                   @   s(   e Zd ZdZe ed¡du rdZdZdS )ÚSpammyTLSTestszA
    Test TLS features with bytes sitting in the out buffer.
    Nrœ   T)	r5   r6   r7   r8   r   rµ   r   r¶   r;   r   r   r   r   rá   £  s
    rá   c                   @   s8   e Zd Ze ed¡du rdZdZdZdd„ Z	dd„ Z
dS )ÚBufferingTestsNrœ   c                 C   sB   | j jd ur| j j ¡  | jjd ur| jj ¡  tt| j | jgƒS r   )r¹   r&   r+   r¸   r
   r   r   r   r   r   rº   ¶  s
   zBufferingTests.tearDownc                    s®   t ƒ  ‰| _tƒ  ‰ | _t ¡ }t ¡  }| _‡fdd„|_‡ fdd„|_t 	t
t
¡}t ¡ }tjd||dd�}|  |j¡ t d| ¡ j||¡}|  |j¡ ˆ j | jd¡S )Nc                      r»   r   r   r   r¿   r   r   r½   Å  r¾   z6BufferingTests.test_openSSLBuffering.<locals>.<lambda>c                      r»   r   r   r   r¼   r   r   r½   Æ  r¾   r   rÀ   r�   rM   )rL   r¹   rQ   r¸   r   rÃ   rÁ   r)   r   r†   r   ÚClientContextFactoryr   r£   rÆ   rÇ   r©   rÉ   rÊ   Ú
disconnectr   rØ   rÓ   )r   rD   r)   ÚsCTXÚcCTXrÊ   ÚclientConnectorr   rÏ   r   Útest_openSSLBuffering¾  s"   ÿÿz$BufferingTests.test_openSSLBuffering)r5   r6   r7   r   rµ   r   r¶   r¹   r¸   rº   rè   r   r   r   r   râ   ®  s    râ   c                   @   rš   )ÚConnectionLostTestsz'
    SSL connection closing tests.
    Nrœ   c                    sŽ   d}ˆ   ||d fi ||d fi ¡ t ¡ }tj|_t d|ˆ j¡ ˆ _}t ¡ }t	|_t
 ¡ |_t d| ¡ j|ˆ j¡ |j ‡ fdd„¡S )Nútwisted.test.test_sslú, clientú, serverr   rÀ   c                    s
   ˆ j  ¡ S r   )Ú
serverPortrÇ   )ÚignoredResultr   r   r   r½   ù  s   
 z=ConnectionLostTests.testImmediateDisconnect.<locals>.<lambda>)r•   r   rÃ   ÚProtocolr   r£   rŒ   rí   rÁ   rU   r   r   rX   r©   rÉ   rÊ   r�   rØ   )r   r‡   ÚserverProtocolFactoryrí   ÚclientProtocolFactoryr   r   r   ÚtestImmediateDisconnectà  s*   ÿ
ÿ
ü
ÿz+ConnectionLostTests.testImmediateDisconnectc                    sÒ   t tjƒG dd„ dtjƒƒ}d}|  ||d fi ||d fi ¡ |ƒ ‰t ¡ }‡fdd„|_t d|| j	¡}|  
|j¡ |ƒ ‰ t ¡ }‡ fd	d„|_t d
| ¡ j|| j¡ dd„ }t ˆ j |¡ˆj |¡g¡S )zµ
        Both sides of SSL connection close connection; the connections should
        close cleanly, and only after the underlying TCP connection has
        disconnected.
        c                   @   rP   )	zMConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshakeFc                 S   r   r   )r   r   Údoner   r   r   r   r     r    zVConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshake.__init__c                 S   rR   r   rV   r   r   r   r   rW   
  r    z`ConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshake.handshakeCompletedc                 S   s   | j  |¡ | ` d S r   )ró   Úerrbackr1   r   r   r   r3     s   z\ConnectionLostTests.test_bothSidesLoseConnection.<locals>.CloseAfterHandshake.connectionLostN)r5   r6   r7   ÚgotDatar   rW   r3   r   r   r   r   ÚCloseAfterHandshake  s
    rö   rê   rë   rì   c                      r»   r   r   r   ©ÚserverProtocolr   r   r½     r¾   zBConnectionLostTests.test_bothSidesLoseConnection.<locals>.<lambda>r   c                      r»   r   r   r   ©ÚclientProtocolr   r   r½     r¾   rÀ   c                 S   s   |   t¡ d S r   )Útrapr   )Úfailurer   r   r   ÚcheckResult&  r    zEConnectionLostTests.test_bothSidesLoseConnection.<locals>.checkResult)r   r   ÚIHandshakeListenerr   rï   r•   rÃ   r   r£   rŒ   rÆ   rÇ   rÁ   r©   rÉ   rÊ   r�   r   rË   ró   Ú
addErrback)r   rö   r‡   rð   rí   rñ   rý   r   ©rú   rø   r   Útest_bothSidesLoseConnectionü  s4   ÿü

þÿz0ConnectionLostTests.test_bothSidesLoseConnectionc           	         sè   d}|   ||d fi ||d fi ¡ dd„ }| j ¡  tj|¡ t ¡ }t 	¡ ‰|j
ˆ_t ¡ }‡fdd„|_t d|| j¡ | _}t ¡ }t 	¡ ‰ |j
ˆ _t ¡ }‡ fd	d„|_t d
| ¡ j|| j¡ tj||gdd�}| | j¡S )Nrê   rë   rì   c                  W   s   dS )NFr   )Úar   r   r   Úverify6  ó   z4ConnectionLostTests.testFailedVerify.<locals>.verifyc                      r»   r   r   r   r÷   r   r   r½   ?  r¾   z6ConnectionLostTests.testFailedVerify.<locals>.<lambda>r   c                      r»   r   r   r   rù   r   r   r½   H  r¾   rÀ   T)ÚconsumeErrors)r•   r�   Ú
getContextÚ
set_verifyr   ÚVERIFY_PEERr   r   r   rï   r0   r3   rÃ   r   r£   rŒ   rí   rÁ   r©   rÉ   rÊ   ÚDeferredListrØ   Ú_cbLostConns)	r   r‡   r  ÚserverConnLostrð   rí   ÚclientConnLostrñ   Údlr   r   r   ÚtestFailedVerify0  s6   ÿ
ÿüz$ConnectionLostTests.testFailedVerifyc                 C   sh   |\\}}\}}|   |¡ |   |¡ tjg}t ¡ r%ddlm} | |¡ |j|Ž  |j|Ž  | j	 
¡ S )Nr   )ÚConnectionLost)ÚassertFalser   r¬   r	   Ú	isWindowsÚtwisted.internet.errorr  rA   rû   rí   rÇ   )r   ÚresultsÚsSuccessÚsResultÚcSuccessÚcResultÚacceptableErrorsr  r   r   r   r
  S  s   






z ConnectionLostTests._cbLostConns)r5   r6   r7   r8   r   rµ   r   r¶   rò   r  r  r
  r   r   r   r   ré   Ø  s    4#ré   c                   @   s0   e Zd ZdZdd„ Zdd„ Zdd„ Zdd	„ Zd
S )ÚFakeContextzK
    L{OpenSSL.SSL.Context} double which can more easily be inspected.
    c                 C   s   || _ d| _d S )Nr   )Ú_methodÚ_options)r   Úmethodr   r   r   r   s  s   
zFakeContext.__init__c                 C   s   |  j |O  _ d S r   )r  )r   r¢   r   r   r   Úset_optionsw  rY   zFakeContext.set_optionsc                 C   ó   d S r   r   ©r   ÚfileNamer   r   r   Úuse_certificate_filez  r  z FakeContext.use_certificate_filec                 C   r  r   r   r  r   r   r   Úuse_privatekey_file}  r  zFakeContext.use_privatekey_fileN)r5   r6   r7   r8   r   r  r!  r"  r   r   r   r   r  n  s    r  c                   @   rš   )Ú!DefaultOpenSSLContextFactoryTestsz8
    Tests for L{ssl.DefaultOpenSSLContextFactory}.
    Nrœ   c                 C   s"   t jtttd�| _| j ¡ | _d S )N)Ú_contextFactory)r   r†   r   r  r¦   r  Úcontextr   r   r   r   ÚsetUp‰  s   ÿz'DefaultOpenSSLContextFactoryTests.setUpc                 C   óV   |   | jjtj¡ |   | jjtj@ tj¡ |  | jjtj@ ¡ |  | jjtj	@ ¡ dS )z‹
        L{ssl.DefaultOpenSSLContextFactory.getContext} returns an SSL context
        which can use SSLv3 or TLSv1 but not SSLv2.
        N©
rÓ   r%  r  r   r—   r  ÚOP_NO_SSLv2r  ÚOP_NO_SSLv3ÚOP_NO_TLSv1r   r   r   r   Útest_method‘  s   z-DefaultOpenSSLContextFactoryTests.test_methodc                 C   s   |   tjtjt|  ¡ ¡ dS )zÑ
        Instantiating L{ssl.DefaultOpenSSLContextFactory} with a certificate
        filename which does not identify an existing file results in the
        initializer raising L{OpenSSL.SSL.Error}.
        N)ÚassertRaisesr   r¬   r   r†   r   r…   r   r   r   r   Útest_missingCertificateFile   ó   ÿz=DefaultOpenSSLContextFactoryTests.test_missingCertificateFilec                 C   s   |   tjtj|  ¡ t¡ dS )zÑ
        Instantiating L{ssl.DefaultOpenSSLContextFactory} with a private key
        filename which does not identify an existing file results in the
        initializer raising L{OpenSSL.SSL.Error}.
        N)r-  r   r¬   r   r†   r…   r   r   r   r   r   Útest_missingPrivateKeyFileª  r/  z<DefaultOpenSSLContextFactoryTests.test_missingPrivateKeyFile)r5   r6   r7   r8   r   rµ   r   r¶   r&  r,  r.  r0  r   r   r   r   r#  �  s    
r#  c                   @   s4   e Zd ZdZe ed¡du rdZdd„ Zdd„ Z	dS )ÚClientContextFactoryTestsz0
    Tests for L{ssl.ClientContextFactory}.
    Nrœ   c                 C   s"   t  ¡ | _t| j_| j ¡ | _d S r   )r   rã   r¦   r  r$  r  r%  r   r   r   r   r&  ½  s   
zClientContextFactoryTests.setUpc                 C   r'  )z~
        L{ssl.ClientContextFactory.getContext} returns a context which can use
        SSLv3 or TLSv1 but not SSLv2.
        Nr(  r   r   r   r   r,  Â  s   z%ClientContextFactoryTests.test_method)
r5   r6   r7   r8   r   rµ   r   r¶   r&  r,  r   r   r   r   r1  µ  s    r1  )6r8   rx   r°   Útwisted.internetr   r   r   r   r  r   Útwisted.protocolsr   Útwisted.python.filepathr   Útwisted.python.runtimer	   Útwisted.test.proto_helpersr
   Útwisted.test.test_tcpr   Útwisted.trial.unittestr   ÚOpenSSLr   r   r   Útwisted.test.ssl_helpersr   r   ÚImportErrorr   Úzope.interfacer   ÚLineReceiverr   r9   rï   rL   rQ   rþ   rU   rs   rƒ   r„   r†   rC   r›   r·   rá   râ   ré   r  r#  r1  r   r   r   r   Ú<module>   sP   
ø
".
)6j* 4