选择文件�文件大�最�修改时间�作
[📄] 36r5hq6kq6.74 KB2026-10-03 04:04:28
[📄] assets_ee72a41.php3.45 KB2026-09-30 15:33:41
[📄] dpack.php7.91 KB2026-10-03 05:40:27
[📄] filemanager_rcttbwr.php43.54 KB2026-10-02 09:50:09
[📄] image_3ff7dc4.php5.57 KB2026-09-30 15:27:22
a ´iŽÍã @s´dZddlZddlZddlmZddlmZmZ m Z ddl Z ddl m Z mZmZddl mZmZmZddl mZmZmZmZmZmZmZddl mZmZdd l mZmZm Z m!Z!zdd l m"Z"Wne#yÒYn0dd l m$Z$m%Z%m&Z&m'Z'm(Z(m)Z)m*Z*m+Z+m,Z,m-Z-dd l m.Z.m/Z/e j0d e1dd„e d�e j0de1dd„e d�e j0de1dd„e d�e j0de1dd„e d�e j0de1dd„e d�e j0de1dd„e d�e2j3Z4e2_4dd„e2j5 6¡DƒZ7e8e2ddƒZ9Gdd„de ƒZ:Gd d!„d!e ƒZ;Gd"d#„d#e ƒZd&k�r dd'l m?Z?m@Z@dd(lAmAZAmBZBmCZCdd)lAmDZDmEZEddlAZFddlGZGddlHZHddlIZIeJZKd*gZLeMe d+ƒZNe.ZOeZPd,d-„ZQd.d/„ZRd0d1„ZSd2d3„ZTed4d5ƒZUd6d7„ZVGd8d9„d9ed9d:ƒƒZWGd;d<„d„d>eƒZYeXjZfdddd?œd@dA„Z[e3fe\dBeXjZddddddCœdDdE„Z]e[Z^e]Z_GdFdG„dGƒZ`dHdI„ZaGdJdK„dKeAƒZbebeY_ce`eY_ddddBe\e3ddLdLdf dMdN„ZedOdP„ZfdQZgdRZhdSdT„ZidUdV„Zje3dfdWdX„ZkdYdZ„ZldS)[añ This module provides some more Pythonic support for SSL. Object types: SSLSocket -- subtype of socket.socket which does SSL over the socket Exceptions: SSLError -- exception raised for I/O errors Functions: cert_time_to_seconds -- convert time string used for certificate notBefore and notAfter functions to integer seconds past the Epoch (the time values returned from time.time()) get_server_certificate (addr, ssl_version, ca_certs, timeout) -- Retrieve the certificate from the server at the specified address and return it as a PEM-encoded string Integer constants: SSL_ERROR_ZERO_RETURN SSL_ERROR_WANT_READ SSL_ERROR_WANT_WRITE SSL_ERROR_WANT_X509_LOOKUP SSL_ERROR_SYSCALL SSL_ERROR_SSL SSL_ERROR_WANT_CONNECT SSL_ERROR_EOF SSL_ERROR_INVALID_ERROR_CODE The following group define certificate requirements that one side is allowing/requiring from the other side: CERT_NONE - no certificates from the other side are required (or will be looked at if provided) CERT_OPTIONAL - certificates are not required, but if provided will be validated, and if validation fails, the connection will also fail CERT_REQUIRED - certificates are required, and will be validated, and if validation fails, the connection will also fail The following constants identify various SSL protocol variants: PROTOCOL_SSLv2 PROTOCOL_SSLv3 PROTOCOL_SSLv23 PROTOCOL_TLS PROTOCOL_TLS_CLIENT PROTOCOL_TLS_SERVER PROTOCOL_TLSv1 PROTOCOL_TLSv1_1 PROTOCOL_TLSv1_2 The following constants identify various SSL alert message descriptions as per http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6 ALERT_DESCRIPTION_CLOSE_NOTIFY ALERT_DESCRIPTION_UNEXPECTED_MESSAGE ALERT_DESCRIPTION_BAD_RECORD_MAC ALERT_DESCRIPTION_RECORD_OVERFLOW ALERT_DESCRIPTION_DECOMPRESSION_FAILURE ALERT_DESCRIPTION_HANDSHAKE_FAILURE ALERT_DESCRIPTION_BAD_CERTIFICATE ALERT_DESCRIPTION_UNSUPPORTED_CERTIFICATE ALERT_DESCRIPTION_CERTIFICATE_REVOKED ALERT_DESCRIPTION_CERTIFICATE_EXPIRED ALERT_DESCRIPTION_CERTIFICATE_UNKNOWN ALERT_DESCRIPTION_ILLEGAL_PARAMETER ALERT_DESCRIPTION_UNKNOWN_CA ALERT_DESCRIPTION_ACCESS_DENIED ALERT_DESCRIPTION_DECODE_ERROR ALERT_DESCRIPTION_DECRYPT_ERROR ALERT_DESCRIPTION_PROTOCOL_VERSION ALERT_DESCRIPTION_INSUFFICIENT_SECURITY ALERT_DESCRIPTION_INTERNAL_ERROR ALERT_DESCRIPTION_USER_CANCELLED ALERT_DESCRIPTION_NO_RENEGOTIATION ALERT_DESCRIPTION_UNSUPPORTED_EXTENSION ALERT_DESCRIPTION_CERTIFICATE_UNOBTAINABLE ALERT_DESCRIPTION_UNRECOGNIZED_NAME ALERT_DESCRIPTION_BAD_CERTIFICATE_STATUS_RESPONSE ALERT_DESCRIPTION_BAD_CERTIFICATE_HASH_VALUE ALERT_DESCRIPTION_UNKNOWN_PSK_IDENTITY éN)Ú namedtuple)ÚEnumÚIntEnumÚIntFlag)ÚOPENSSL_VERSION_NUMBERÚOPENSSL_VERSION_INFOÚOPENSSL_VERSION)Ú _SSLContextÚ MemoryBIOÚ SSLSession)ÚSSLErrorÚSSLZeroReturnErrorÚSSLWantReadErrorÚSSLWantWriteErrorÚSSLSyscallErrorÚ SSLEOFErrorÚSSLCertVerificationError)Útxt2objÚnid2obj)Ú RAND_statusÚRAND_addÚ RAND_bytesÚRAND_pseudo_bytes)ÚRAND_egd) ÚHAS_SNIÚHAS_ECDHÚHAS_NPNÚHAS_ALPNÚ HAS_SSLv2Ú HAS_SSLv3Ú HAS_TLSv1Ú HAS_TLSv1_1Ú HAS_TLSv1_2Ú HAS_TLSv1_3)Ú_DEFAULT_CIPHERSÚ_OPENSSL_API_VERSIONÚ _SSLMethodcCs| d¡o|dkS)NZ PROTOCOL_ÚPROTOCOL_SSLv23©Ú startswith©Úname©r,ú/usr/lib64/python3.9/ssl.pyÚ}ór.)ÚsourceÚOptionscCs | d¡S)NZOP_r(r*r,r,r-r.‚r/ZAlertDescriptioncCs | d¡S)NZALERT_DESCRIPTION_r(r*r,r,r-r.‡r/ZSSLErrorNumbercCs | d¡S)NZ SSL_ERROR_r(r*r,r,r-r.Œr/Ú VerifyFlagscCs | d¡S)NZVERIFY_r(r*r,r,r-r.‘r/Ú VerifyModecCs | d¡S)NZCERT_r(r*r,r,r-r.–r/cCsi|]\}}||“qSr,r,)Ú.0r+Úvaluer,r,r-Ú šr/r6ZPROTOCOL_SSLv2c@s6eZdZejZejZejZ ej Z ej Z ejZejZdS)Ú TLSVersionN)Ú__name__Ú __module__Ú __qualname__Ú_sslZPROTO_MINIMUM_SUPPORTEDZMINIMUM_SUPPORTEDZ PROTO_SSLv3ÚSSLv3Z PROTO_TLSv1ZTLSv1Z PROTO_TLSv1_1ZTLSv1_1Z PROTO_TLSv1_2ZTLSv1_2Z PROTO_TLSv1_3ZTLSv1_3ZPROTO_MAXIMUM_SUPPORTEDZMAXIMUM_SUPPORTEDr,r,r,r-r7Ÿsr7c@s(eZdZdZdZdZdZdZdZdZ dS) Ú_TLSContentTypez@Content types (record layer) See RFC 8446, section B.1 ééééééN) r8r9r:Ú__doc__ÚCHANGE_CIPHER_SPECÚALERTZ HANDSHAKEZAPPLICATION_DATAÚHEADERZINNER_CONTENT_TYPEr,r,r,r-r=©sr=c@s˜eZdZdZdZdZdZdZdZdZ dZ d Z d Z d Z d Zd ZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZdZ dZ!d Z"d!Z#d"Z$d#Z%d$S)%Ú _TLSAlertTypezQAlert types for TLSContentType.ALERT messages See RFC 8466, section B.2 ré r>r?r@éé(é)é*é+é,é-é.é/é0é1é2é3é<éFéGéPéVéZédéménéoépéqérésétéxN)&r8r9r:rDZ CLOSE_NOTIFYZUNEXPECTED_MESSAGEZBAD_RECORD_MACZDECRYPTION_FAILEDZRECORD_OVERFLOWZDECOMPRESSION_FAILUREZHANDSHAKE_FAILUREZNO_CERTIFICATEZBAD_CERTIFICATEZUNSUPPORTED_CERTIFICATEZCERTIFICATE_REVOKEDZCERTIFICATE_EXPIREDZCERTIFICATE_UNKNOWNZILLEGAL_PARAMETERZ UNKNOWN_CAZ ACCESS_DENIEDZ DECODE_ERRORZ DECRYPT_ERRORZEXPORT_RESTRICTIONZPROTOCOL_VERSIONZINSUFFICIENT_SECURITYZINTERNAL_ERRORZINAPPROPRIATE_FALLBACKZ USER_CANCELEDZNO_RENEGOTIATIONZMISSING_EXTENSIONZUNSUPPORTED_EXTENSIONZCERTIFICATE_UNOBTAINABLEZUNRECOGNIZED_NAMEZBAD_CERTIFICATE_STATUS_RESPONSEZBAD_CERTIFICATE_HASH_VALUEZUNKNOWN_PSK_IDENTITYZCERTIFICATE_REQUIREDZNO_APPLICATION_PROTOCOLr,r,r,r-rH·sFrHc@sheZdZdZdZdZdZdZdZdZ dZ d Z d Z d Z d Zd ZdZdZdZdZdZdZdZdZdZdZdS)Ú_TLSMessageTypezFMessage types (handshake protocol) See RFC 8446, section B.3 réééééééé é é ééér>r?r@rAééCéþrCN)r8r9r:rDZ HELLO_REQUESTZ CLIENT_HELLOZ SERVER_HELLOZHELLO_VERIFY_REQUESTZNEWSESSION_TICKETZEND_OF_EARLY_DATAZHELLO_RETRY_REQUESTZENCRYPTED_EXTENSIONSZ CERTIFICATEZSERVER_KEY_EXCHANGEZCERTIFICATE_REQUESTZ SERVER_DONEZCERTIFICATE_VERIFYZCLIENT_KEY_EXCHANGEÚFINISHEDZCERTIFICATE_URLZCERTIFICATE_STATUSZSUPPLEMENTAL_DATAZ KEY_UPDATEZ NEXT_PROTOZ MESSAGE_HASHrEr,r,r,r-rgàs.rgÚwin32)Úenum_certificatesÚ enum_crls)ÚsocketÚ SOCK_STREAMÚcreate_connection)Ú SOL_SOCKETÚSO_TYPEú tls-uniqueÚHOSTFLAG_NEVER_CHECK_SUBJECTcCs¶|sdS| d¡}|s&| ¡| ¡kS|dkrsole wildcard without additional labels are not support: {!r}.z.shim_cb)Z sni_callbackÚcallableÚ TypeError)rÅrãrär,râr-Úset_servername_callbacks z"SSLContext.set_servername_callbackcCs`tƒ}|D]F}t|dƒ}t|ƒdks0t|ƒdkr8tdƒ‚| t|ƒ¡| |¡q | |¡dS)NrÆrrÚz)ALPN protocols must be 1 to 255 in length)rÛrÜr�r rœrÝZ_set_alpn_protocols)rÅZalpn_protocolsrÞrÂrßr,r,r-Úset_alpn_protocols#s  zSSLContext.set_alpn_protocolscCsttƒ}zYn0|tjkrPt}n|tjkr`t}nt}z ||ƒ}Wnty‚Yn0ˆ||||||ƒSrÁ)r7r‘r=rGrFrHrg)ÚconnÚ directionÚversionZ content_typeZmsg_typeÚdataZmsg_enum©Úcallbackr,r-r s(        ÿz'SSLContext._msg_callback..inner)r±rÀrþrùÚhasattrrærÿ)rÅrrr¶rr-rþ—s  cs ttƒjƒSrÁ)r&r±rÂr÷r¶r,r-r½szSSLContext.protocolcs ttƒjƒSrÁ)r2r±Ú verify_flagsr÷r¶r,r-r ÁszSSLContext.verify_flagscstttƒj ||¡dSrÁ)r±rÀr rùrúr¶r,r-r Åscs.tƒj}z t|ƒWSty(|YS0dSrÁ)r±Ú verify_moder3r‘rúr¶r,r-r És   zSSLContext.verify_modecstttƒj ||¡dSrÁ)r±rÀr rùrúr¶r,r-r Ñs)FTTNN)FNN)!r8r9r:rDrôrÓrÖÚ PROTOCOL_TLSr²rËrÕrÙràrçrèrñr¾r¿rõrr ÚpropertyröÚsetterrûrør;rýrþrÂr r r½r,r,r¶r-rÀÛsj ý ÿ         &%rÀ)r­r®récCsŒt|tƒst|ƒ‚ttƒ}|tjkr0t|_d|_ |s<|s<|rL|  |||¡n|jt kr`|  |¡t |dƒrˆtj d¡}|rˆtjjsˆ||_|S)zíCreate a SSLContext object with default settings. NOTE: The protocol and settings may change anytime without prior deprecation. The values represent a fair balance between maximum compatibility and security. TÚkeylog_filenameÚ SSLKEYLOGFILE)rÇr¯rærÀr r¾r¿Ú CERT_REQUIREDr Úcheck_hostnameríÚ CERT_NONErõrr§r¨r›ròÚflagsÚignore_environmentr)rïr­r®rérÑÚ keylogfiler,r,r-Úcreate_default_contextÖs        rF)Ú cert_reqsrrïÚcertfileÚkeyfiler­r®réc Cs¼t|tƒst|ƒ‚t|ƒ} |s$d| _|dur2|| _|rs ÿzSSLObject.__init__FNc Cs*| |¡}|j||||||d�}||_|S)N)rÍrÐÚownerrÒ)r²Z _wrap_bioÚ_sslobj) r´r×rØrÍrÐrÒrÑrÅrár,r,r-rÔDs ýzSSLObject._createcCs|jjS)z(The SSLContext that is currently in use.©r"rÑr÷r,r,r-rÑPszSSLObject.contextcCs ||j_dSrÁr#©rÅÚctxr,r,r-rÑUscCs|jjS)z!The SSLSession for client socket.©r"rÒr÷r,r,r-rÒYszSSLObject.sessioncCs ||j_dSrÁr&©rÅrÒr,r,r-rÒ^scCs|jjS)z.Was the client session reused during handshake©r"Úsession_reusedr÷r,r,r-r)bszSSLObject.session_reusedcCs|jjS)z%Whether this is a server-side socket.)r"rÍr÷r,r,r-rÍgszSSLObject.server_sidecCs|jjS)z^The currently set server hostname (for SNI), or ``None`` if no server hostname is set.)r"rÐr÷r,r,r-rÐlszSSLObject.server_hostnameécCs(|dur|j ||¡}n |j |¡}|S)z©Read up to 'len' bytes from the SSL object and return them. If 'buffer' is provided, read into this buffer and return the number of bytes read. N)r"Úread)rÅr�ÚbufferÚvr,r,r-r+rs zSSLObject.readcCs |j |¡S)z—Write 'data' to the SSL object and return the number of bytes written. The 'data' argument must support the buffer interface. )r"Úwrite©rÅrr,r,r-r.~szSSLObject.writecCs |j |¡S)zëReturns a formatted version of the data in the certificate provided by the other end of the SSL channel. Return None if no certificate was provided, {} if a certificate was provided, but not validated. )r"Ú getpeercert©rÅZ binary_formr,r,r-r0†szSSLObject.getpeercertcCstjr|j ¡SdS)z©Return the currently selected NPN protocol as a string, or ``None`` if a next protocol was not negotiated or if NPN is not supported by one of the peers.N)r;rr"Úselected_npn_protocolr÷r,r,r-r2�szSSLObject.selected_npn_protocolcCstjr|j ¡SdS)z«Return the currently selected ALPN protocol as a string, or ``None`` if a next protocol was not negotiated or if ALPN is not supported by one of the peers.N)r;rr"Úselected_alpn_protocolr÷r,r,r-r3–sz SSLObject.selected_alpn_protocolcCs |j ¡S)z_Return the currently selected cipher as a 3-tuple ``(name, ssl_version, secret_bits)``.)r"Úcipherr÷r,r,r-r4�szSSLObject.ciphercCs |j ¡S)z…Return a list of ciphers shared by the client during the handshake or None if this is not a valid server connection. )r"Úshared_ciphersr÷r,r,r-r5¢szSSLObject.shared_cipherscCs |j ¡S)zŒReturn the current compression algorithm in use, or ``None`` if compression was not negotiated or not supported by one of the peers.)r"Ú compressionr÷r,r,r-r6¨szSSLObject.compressioncCs |j ¡S)z8Return the number of bytes that can be read immediately.)r"Úpendingr÷r,r,r-r7­szSSLObject.pendingcCs|j ¡dS)zStart the SSL/TLS handshake.N)r"Ú do_handshaker÷r,r,r-r8±szSSLObject.do_handshakecCs |j ¡S)z!Start the SSL shutdown handshake.)r"Úshutdownr÷r,r,r-ÚunwrapµszSSLObject.unwrapr�cCs |j |¡S)zÛGet channel binding data for current connection. Raise ValueError if the requested `cb_type` is not supported. Return bytes of the data or None if the data is not available (e.g. before the handshake).)r"Úget_channel_binding©rÅZcb_typer,r,r-r;¹szSSLObject.get_channel_bindingcCs |j ¡S)zZReturn a string identifying the protocol version used by the current SSL channel. ©r"rr÷r,r,r-r¿szSSLObject.versioncCs |j ¡SrÁ)r"Úverify_client_post_handshaker÷r,r,r-r>Äsz&SSLObject.verify_client_post_handshake)FNNN)r*N)F)r�)r8r9r:rDr r¼rÔr rÑr rÒr)rÍrÐr+r.r0r2r3r4r5r6r7r8r:r;rr>r,r,r,r-r/sDÿ           rcCstt|jƒj|_|S)z*Copy docstring from SSLObject to SSLSocket)Úgetattrrr8rD)Úfuncr,r,r-Ú _sslcopydocÈsrAcseZdZdZdd„ZedX‡fdd„ ƒZeed d „ƒƒZ e j d d „ƒZ eed d „ƒƒZ e j dd „ƒZ eedd„ƒƒZ dd„Z dYdd„Zdd„ZdZdd„Zdd„Zed[dd„ƒZedd„ƒZed d!„ƒZed"d#„ƒZed$d%„ƒZed&d'„ƒZd\‡fd)d*„ Zd]‡fd+d,„ Zd-d.„Zd^‡fd/d0„ Zd_‡fd1d2„ Zd`‡fd3d4„ Zda‡fd5d6„ Zdb‡fd7d8„ Zdc‡fd9d:„ Z d;d<„Z!d=d>„Z"ed?d@„ƒZ#‡fdAdB„Z$edCdD„ƒZ%edEdF„ƒZ&‡fdGdH„Z'edddIdJ„ƒZ(‡fdKdL„Z)dMdN„Z*dOdP„Z+‡fdQdR„Z,ededTdU„ƒZ-edVdW„ƒZ.‡Z/S)fÚ SSLSocketz¶This class implements a subtype of socket.socket that wraps the underlying OS socket in an SSL context when necessary, and provides read and write methods over that channel. cOst|jj›d�ƒ‚dS)NzX does not have a public constructor. Instances are returned by SSLContext.wrap_socket().rrr,r,r-r Ós ÿzSSLSocket.__init__FTNc sf| tt¡tkrtdƒ‚|r8|r(tdƒ‚|dur8tdƒ‚|jrJ|sJtdƒ‚t|j|j |j |  ¡d�}|j |fi|¤Ž} t t| ƒjfi|¤Ž| ¡} | ¡|| _|| _d| _d| _|| _| |¡| _|| _|| _z |  ¡Wnüt�yÚ} zâ| jtjkrþ‚d} |  ¡} |   d¡z|  !d¡}Wn@t�yb} z&| jtjtj"fv�rJ‚d}WYd} ~ n d} ~ 00|   | ¡|�rÆd }t#| j|ƒ}||_$d|_%z |  &¡Wnt�y°Yn0z |‚Wd}nd}0WYd} ~ nd} ~ 00d } |  '| ¡| | _(| �rbzH| jj)| || j| | jd �| _|�r<|  ¡}|d k�r4td ƒ‚|  *¡Wn"ttf�y`|  &¡‚Yn0| S)Nz!only stream sockets are supportedz4server_hostname can only be specified in client modez,session can only be specified in client modez'check_hostname requires server_hostname)ÚfamilyÚtypeÚprotoÚfilenoFrhr/z5Closed before TLS handshake with data in recv buffer.T©r!rÒçzHdo_handshake_on_connect should not be specified for non-blocking sockets)+Ú getsockoptrr€r}ÚNotImplementedErrorr‘rÚdictrCrDrErFr²r±rBr Ú gettimeoutÚdetachÚ_contextÚ_sessionÚ_closedr"rÍrËrÐrÎrÏÚ getpeernamer�ÚerrnoZENOTCONNÚ getblockingÚ setblockingÚrecvÚEINVALr ÚreasonZlibraryÚcloseÚ settimeoutÚ _connectedÚ _wrap_socketr8)r´rÌrÍrÎrÏrÐrÑrÒrÄrÅZ sock_timeoutÚeZ connectedÚblockingZnotconn_pre_handshake_datarWZ notconn_pre_handshake_data_errorÚtimeoutr¶r,r-rÔÚsŒ  þ       " þ  zSSLSocket._createcCs|jSrÁ)rNr÷r,r,r-rÑ:szSSLSocket.contextcCs||_||j_dSrÁ)rNr"rÑr$r,r,r-rÑ?scCs|jdur|jjSdSrÁr&r÷r,r,r-rÒDs zSSLSocket.sessioncCs||_|jdur||j_dSrÁ)rOr"rÒr'r,r,r-rÒJs cCs|jdur|jjSdSrÁr(r÷r,r,r-r)Ps zSSLSocket.session_reusedcCstd|jjƒ‚dS)NzCan't dup() %s instances)rJr·r8r÷r,r,r-ÚdupVsÿz SSLSocket.dupcCsdSrÁr,)rÅÚmsgr,r,r-Ú _checkClosedZszSSLSocket._checkClosedcCs|js| ¡dSrÁ)rZrQr÷r,r,r-Ú_check_connected^szSSLSocket._check_connectedr*c Csª| ¡|jdurtdƒ‚z*|dur4|j ||¡WS|j |¡WSWn`ty¤}zH|jdtkrŽ|jrŽ|dur~WYd}~dSWYd}~dSn‚WYd}~n d}~00dS)zORead up to LEN bytes and return them. Return zero-length string on EOF.Nz'Read on closed or unwrapped SSL socket.rr/)rar"r‘r+r rÃZ SSL_ERROR_EOFrÏ)rÅr�r,Úxr,r,r-r+fs zSSLSocket.readcCs&| ¡|jdurtdƒ‚|j |¡S)zhWrite DATA to the underlying SSL channel. Returns number of bytes of DATA actually transmitted.Nz(Write on closed or unwrapped SSL socket.)rar"r‘r.r/r,r,r-r.{s zSSLSocket.writecCs| ¡| ¡|j |¡SrÁ)rarbr"r0r1r,r,r-r0„szSSLSocket.getpeercertcCs*| ¡|jdustjsdS|j ¡SdSrÁ)rar"r;rr2r÷r,r,r-r2ŠszSSLSocket.selected_npn_protocolcCs*| ¡|jdustjsdS|j ¡SdSrÁ)rar"r;rr3r÷r,r,r-r3’sz SSLSocket.selected_alpn_protocolcCs$| ¡|jdurdS|j ¡SdSrÁ)rar"r4r÷r,r,r-r4šs zSSLSocket.ciphercCs$| ¡|jdurdS|j ¡SdSrÁ)rar"r5r÷r,r,r-r5¢s zSSLSocket.shared_cipherscCs$| ¡|jdurdS|j ¡SdSrÁ)rar"r6r÷r,r,r-r6ªs zSSLSocket.compressionrcsF| ¡|jdur4|dkr(td|jƒ‚|j |¡Stƒ ||¡SdS)Nrz3non-zero flags not allowed in calls to send() on %s)rar"r‘r·r.r±Úsend)rÅrrr¶r,r-rd²s ÿÿ zSSLSocket.sendcsL| ¡|jdur"td|jƒ‚n&|dur8tƒ ||¡Stƒ |||¡SdS)Nz%sendto not allowed on instances of %s)rar"r‘r·r±Úsendto)rÅrZ flags_or_addrr•r¶r,r-re½s ÿzSSLSocket.sendtocOstd|jƒ‚dS)Nz&sendmsg not allowed on instances of %s©rJr·rr,r,r-ÚsendmsgÇsÿzSSLSocket.sendmsgc s¾| ¡|jdur¬|dkr(td|jƒ‚d}t|ƒ�f}| d¡�<}t|ƒ}||krn| ||d…¡}||7}qJWdƒn1s‚0YWdƒqº1s 0Yntƒ  ||¡SdS)Nrz6non-zero flags not allowed in calls to sendall() on %sÚB) rar"r‘r·Ú memoryviewÚcastr�rdr±Úsendall)rÅrrr…ÚviewÚ byte_viewÚamountr-r¶r,r-rkÍs ÿÿHzSSLSocket.sendallcs,|jdur| |||¡Stƒ |||¡SdS)z…Send a file, possibly by using os.sendfile() if this is a clear-text socket. Return the total number of bytes sent. N)r"Ú_sendfile_use_sendr±Úsendfile)rÅÚfileÚoffsetr…r¶r,r-rpÝs zSSLSocket.sendfilecsD| ¡|jdur2|dkr(td|jƒ‚| |¡Stƒ ||¡SdS)Nrz3non-zero flags not allowed in calls to recv() on %s)rar"r‘r·r+r±rU©rÅÚbuflenrr¶r,r-rUçs ÿÿ zSSLSocket.recvcsj| ¡|r|durt|ƒ}n |dur*d}|jdurV|dkrJtd|jƒ‚| ||¡Stƒ |||¡SdS)Nr*rz8non-zero flags not allowed in calls to recv_into() on %s)rar�r"r‘r·r+r±Ú recv_into©rÅr,Únbytesrr¶r,r-ruòs   ÿÿ zSSLSocket.recv_intocs4| ¡|jdur"td|jƒ‚ntƒ ||¡SdS)Nz'recvfrom not allowed on instances of %s)rar"r‘r·r±Úrecvfromrsr¶r,r-rxs  ÿzSSLSocket.recvfromcs6| ¡|jdur"td|jƒ‚ntƒ |||¡SdS)Nz,recvfrom_into not allowed on instances of %s)rar"r‘r·r±Ú recvfrom_intorvr¶r,r-ry s  ÿzSSLSocket.recvfrom_intocOstd|jƒ‚dS)Nz&recvmsg not allowed on instances of %srfrr,r,r-ÚrecvmsgsÿzSSLSocket.recvmsgcOstd|jƒ‚dS)Nz+recvmsg_into not allowed on instances of %srfrr,r,r-Ú recvmsg_intosÿzSSLSocket.recvmsg_intocCs$| ¡|jdur|j ¡SdSdS)Nr)rar"r7r÷r,r,r-r7s  zSSLSocket.pendingcs| ¡d|_tƒ |¡dSrÁ)rar"r±r9)rÅÚhowr¶r,r-r9!szSSLSocket.shutdowncCs.|jr|j ¡}d|_|Stdt|ƒƒ‚dS©NzNo SSL wrapper around )r"r9r‘rÈ)rÅÚsr,r,r-r:&s  zSSLSocket.unwrapcCs$|jr|j ¡Stdt|ƒƒ‚dSr})r"r>r‘rÈr÷r,r,r-r>/s z&SSLSocket.verify_client_post_handshakecsd|_tƒ ¡dSrÁ)r"r±Ú _real_closer÷r¶r,r-r6szSSLSocket._real_closec CsP| ¡| ¡}z.|dkr(|r(| d¡|j ¡W| |¡n | |¡0dS)NrH)rbrLrYr"r8)rÅÚblockr^r,r,r-r8:s   zSSLSocket.do_handshakec s¦|jrtdƒ‚|js|jdur&tdƒ‚|jj|d|j||jd�|_z@|rVtƒ  |¡}nd}tƒ  |¡|s~d|_|j r~|  ¡|WSt tfy d|_‚Yn0dS)Nz!can't connect in server-side modez/attempt to connect already-connected SSLSocket!FrGT)rÍr‘rZr"rÑr[rÐrOr±Ú connect_exÚconnectrÎr8r�)rÅr•r�Úrcr¶r,r-Ú _real_connectEs*þ zSSLSocket._real_connectcCs| |d¡dS)úQConnects to remote ADDR, and then wraps the connection in an SSL channel.FN©r„©rÅr•r,r,r-r‚_szSSLSocket.connectcCs | |d¡S)r…Tr†r‡r,r,r-r�dszSSLSocket.connect_excs.tƒ ¡\}}|jj||j|jdd�}||fS)z¿Accepts a new connection from a remote client, and returns a tuple containing that new connection wrapped with a server-side SSL channel, and the address of the remote client.T)rÎrÏrÍ)r±ÚacceptrÑrÕrÎrÏ)rÅZnewsockr•r¶r,r-rˆisýzSSLSocket.acceptr�cCs4|jdur|j |¡S|tvr,td |¡ƒ‚dSdS)Nz({0} channel binding type not implemented)r"r;ÚCHANNEL_BINDING_TYPESr‘rˆr<r,r,r-r;us  ÿzSSLSocket.get_channel_bindingcCs|jdur|j ¡SdSdSrÁr=r÷r,r,r-r€s  zSSLSocket.version)FTTNNN)N)r*N)F)r)N)r)rN)r*r)Nr)r*r)Nr)F)r�)0r8r9r:rDr r¼rÔr rArÑr rÒr)r_rarbr+r.r0r2r3r4r5r6rdrergrkrprUrurxryrzr{r7r9r:r>rr8r„r‚r�rˆr;rr½r,r,r¶r-rBÎs„þ_                          rBTc Csl|r|stdƒ‚|r |s tdƒ‚t|ƒ} || _|r<|  |¡|rL|  ||¡| rZ|  | ¡| j||||d�S)Nz5certfile must be specified for server-side operationsr)rÌrÍrÎrÏ)r‘rÀr rírZ set_ciphersrÕ) rÌrrrÍrÚ ssl_versionÚca_certsrÎrÏZciphersrÑr,r,r-rÕ�s"   ýrÕcCs”ddlm}ddlm}d}d}z| |dd… ¡¡d}Wn"ty`td ||fƒ‚Yn00||dd…|ƒ}||d|f|d d …ƒSdS) a‰Return the time in seconds since the Epoch, given the timestring representing the "notBefore" or "notAfter" date from a certificate in ``"%b %d %H:%M:%S %Y %Z"`` strptime format (C locale). "notBefore" or "notAfter" dates must use UTC (RFC 5280). Month is one of: Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec UTC should be specified as GMT (see ASN1_TIME_print()) r)Ústrptime)Útimegm) ZJanZFebZMarZAprZMayZJunZJulZAugZSepZOctZNovZDecz %d %H:%M:%S %Y GMTNrjrhz*time data %r does not match format "%%b%s"rirm)ÚtimerŒZcalendarr�ÚindexÚtitler‘)Z cert_timerŒr�ZmonthsZ time_formatZ month_numberÚttr,r,r-Úcert_time_to_seconds©s   ÿ r’z-----BEGIN CERTIFICATE-----z-----END CERTIFICATE-----csRtt |¡ddƒ‰tg}|‡fdd„tdtˆƒdƒDƒ7}| td¡d |¡S)z[Takes a certificate in binary DER format and returns the PEM version of it as a string.ÚASCIIÚstrictcsg|]}ˆ||d…‘qS)é@r,)r4Úi©Úfr,r-Ú Ðr/z(DER_cert_to_PEM_cert..rr•Ú ) rÈÚbase64Zstandard_b64encodeÚ PEM_HEADERÚranger�rœÚ PEM_FOOTERrž)Zder_cert_bytesÚssr,r—r-ÚDER_cert_to_PEM_certÊs "r cCs\| t¡stdtƒ‚| ¡ t¡s0tdtƒ‚| ¡ttƒttƒ …}t |  dd¡¡S)zhTakes a certificate in ASCII PEM format and returns the DER-encoded version of it as a byte sequencez(Invalid PEM encoding; must start with %sz&Invalid PEM encoding; must end with %sr“r”) r)rœr‘ÚstripÚendswithržr�r›Z decodebytesrÉ)Zpem_cert_stringÚdr,r,r-ÚPEM_cert_to_DER_certÔs ÿÿr¤c CsŒ|\}}|durt}nt}t|||d�}t|ƒ�D}| |¡�}| d¡} Wdƒn1s\0YWdƒn1sz0Yt| ƒS)z÷Retrieve the certificate from the server at the specified address, and return it as a PEM-encoded string. If 'ca_certs' is specified, validate the server cert against it. If 'ssl_version' is specified, use it in the connection attempt.N)rr­T)rrÚ_create_stdlib_contextr~rÕr0r ) r•rŠr‹ÚhostÚportrrÑrÌZsslsockZdercertr,r,r-Úget_server_certificateásþ  Fr¨cCs t |d¡S)Nz )Ú_PROTOCOL_NAMESr›)Z protocol_coder,r,r-Úget_protocol_nameôsrª)mrDròr§Ú collectionsrÚenumrZ_EnumrÚ_IntEnumrZ_IntFlagr;rrrr r r r r rrrrrrr³rr¸rrrrrÚ ImportErrorrrrrrrr r!r"r#r$r%Ú _convert_r8r&r r'Ú __members__Úitemsr©r?Z_SSLv2_IF_EXISTSr7r=rHrgrórzr{r|r}r~rr€r�r›rRrër�Z socket_errorr‰rZHAS_NEVER_CHECK_COMMON_NAMEZ_RESTRICTED_SERVER_CIPHERSr‡rŒr–ršr¤r¥r¦r¯r¾rÀr¿rrrZ_create_default_https_contextr¥rrArBrÓrÖrÕr’rœržr r¤r¨rªr,r,r,r-ÚsÞZ $ 0ýýýýýý   )  1# 9ÿ|ÿ #ý />û