U
    g1                     @  sP  d dl mZ d dlZd dlZd dlZd dlZd dlmZmZ d dl	m
Z
 d dlmZ d dlmZmZmZ ddlmZmZmZmZ dd	lmZmZ dd
lmZmZmZmZ ejdkrd dlmZm Z  nd dl!mZm Z  edZ"edZ#eee$e$f df Z%ee%df Z&G dd deZ'e
ddG dd deZ(e
ddG dd dee( Z)dS )    )annotationsN)CallableMapping)	dataclass)wraps)AnyTupleTypeVar   )BrokenResourceErrorEndOfStreamaclose_forcefullyget_cancelled_exc_class)TypedAttributeSettyped_attribute)AnyByteStream
ByteStreamListener	TaskGroup)      )TypeVarTupleUnpackT_RetvalPosArgsT.c                   @  s   e Zd ZU dZe Zded< e Zded< e Zded< e Z	ded	< e Z
d
ed< e Zded< e Zded< e Zded< e Zded< e Zded< dS )TLSAttributez5Contains Transport Layer Security related attributes.
str | Nonealpn_protocolbyteschannel_binding_tls_uniqueztuple[str, str, int]cipherz*None | dict[str, str | _PCTRTTT | _PCTRTT]peer_certificatezbytes | Nonepeer_certificate_binaryboolserver_sidez!list[tuple[str, str, int]] | Noneshared_ciphersssl.SSLObject
ssl_objectstandard_compatiblestrtls_versionN)__name__
__module____qualname____doc__r   r   __annotations__r   r    r!   r"   r$   r%   r'   r(   r*    r0   r0   5/tmp/pip-unpacked-wheel-3u0cc9gf/anyio/streams/tls.pyr       s   
r   F)eqc                	   @  s   e Zd ZU dZded< ded< ded< ded	< ded
< eddddddddddd dddZddddddZddddZdddd Z	d/d"d#d$d%d&Z
d#dd'd(d)Zddd*d+Zed,dd-d.ZdS )0	TLSStreama  
    A stream wrapper that encrypts all sent data and decrypts received data.

    This class has no public initializer; use :meth:`wrap` instead.
    All extra attributes from :class:`~TLSAttribute` are supported.

    :var AnyByteStream transport_stream: the wrapped stream

    r   transport_streamr#   r(   r&   _ssl_objectzssl.MemoryBIO	_read_bio
_write_bioNT)r$   hostnamessl_contextr(   zbool | Noner   zssl.SSLContext | None)r4   r$   r8   r9   r(   returnc                  s   |dkr| }|sL|rt jjnt jj}t |}tt drL| jt j M  _t  }t  }|j	||||d}	| |||	||d}
|

|	jI dH  |
S )a  
        Wrap an existing stream with Transport Layer Security.

        This performs a TLS handshake with the peer.

        :param transport_stream: a bytes-transporting stream to wrap
        :param server_side: ``True`` if this is the server side of the connection,
            ``False`` if this is the client side (if omitted, will be set to ``False``
            if ``hostname`` has been provided, ``False`` otherwise). Used only to create
            a default context when an explicit context has not been provided.
        :param hostname: host name of the peer (if host name checking is desired)
        :param ssl_context: the SSLContext object to use (if not provided, a secure
            default will be created)
        :param standard_compatible: if ``False``, skip the closing handshake when
            closing the connection, and don't raise an exception if the peer does the
            same
        :raises ~ssl.SSLError: if the TLS handshake fails

        NOP_IGNORE_UNEXPECTED_EOF)r$   server_hostname)r4   r(   r5   r6   r7   )sslPurposeCLIENT_AUTHSERVER_AUTHcreate_default_contexthasattroptionsr;   	MemoryBIOwrap_bio_call_sslobject_methoddo_handshake)clsr4   r$   r8   r9   r(   purposeZbio_inZbio_outr'   wrapperr0   r0   r1   wrapN   s2    

   zTLSStream.wrapz&Callable[[Unpack[PosArgsT]], T_Retval]zUnpack[PosArgsT]r   )funcargsr:   c                   s  z|| }W n t jk
r   z4| jjrB| j| j I d H  | j I d H }W nX tk
rr   | j	
  Y nH tk
r } z| j	
  | j
  t|W 5 d }~X Y nX | j	| Y q  t jk
r   | j| j I d H  Y q  t jk
r( } z| j	
  | j
  t|W 5 d }~X Y q  t jk
r } zR| j	
  | j
  t|t jsr|jrd|jkr| jrt|ntd  W 5 d }~X Y q X | jjr| j| j I d H  |S q d S )NZUNEXPECTED_EOF_WHILE_READING)r=   SSLWantReadErrorr7   pendingr4   sendreadreceiver   r6   	write_eofOSErrorr   writeSSLWantWriteErrorSSLSyscallErrorSSLError
isinstanceSSLEOFErrorstrerrorr(   )selfrL   rM   resultdataexcr0   r0   r1   rF      sF    






z TLSStream._call_sslobject_methodztuple[AnyByteStream, bytes]r:   c                   s8   |  | jjI dH  | j  | j  | j| j fS )z
        Does the TLS closing handshake.

        :return: a tuple of (wrapped byte stream, bytes left in the read buffer)

        N)rF   r5   unwrapr6   rS   r7   r4   rQ   r\   r0   r0   r1   ra      s    

zTLSStream.unwrapNonec                   sT   | j r@z|  I d H  W n& tk
r>   t| jI d H   Y nX | j I d H  d S N)r(   ra   BaseExceptionr   r4   acloserb   r0   r0   r1   rf      s    zTLSStream.aclose   intr   )	max_bytesr:   c                   s"   |  | jj|I d H }|st|S rd   )rF   r5   rQ   r   )r\   ri   r^   r0   r0   r1   rR      s    zTLSStream.receive)itemr:   c                   s   |  | jj|I d H  d S rd   )rF   r5   rU   )r\   rj   r0   r0   r1   rP      s    zTLSStream.sendc                   sd   |  tj}td|}|rXt|dt|dp6d }}||fdk rXtd| tdd S )NzTLSv(\d+)(?:\.(\d+))?   r
   r   )rk   r   z;send_eof() requires at least TLSv1.3; current session uses z7send_eof() has not yet been implemented for TLS streams)extrar   r*   rematchrh   groupNotImplementedError)r\   r*   rn   majorminorr0   r0   r1   send_eof   s    "zTLSStream.send_eofMapping[Any, Callable[[], Any]]c                   s    j jtj jjtj jjtj jjtj	 fddtj
 fddtj fddtj fddtj fddtj fddtj jji
S )Nc                     s    j dS )NFr5   getpeercertr0   rb   r0   r1   <lambda>       z,TLSStream.extra_attributes.<locals>.<lambda>c                     s    j dS )NTru   r0   rb   r0   r1   rw      s   c                     s    j jS rd   )r5   r$   r0   rb   r0   r1   rw      rx   c                     s    j jr j  S d S rd   )r5   r$   r%   r0   rb   r0   r1   rw      s    c                     s    j S rd   r(   r0   rb   r0   r1   rw      rx   c                     s    j S rd   )r5   r0   rb   r0   r1   rw      rx   )r4   extra_attributesr   r   r5   selected_alpn_protocolr   get_channel_bindingr    r!   r"   r$   r%   r(   r'   r*   versionrb   r0   rb   r1   rz      s,       
 
 
 
 
 
 zTLSStream.extra_attributes)rg   )r+   r,   r-   r.   r/   classmethodrK   rF   ra   rf   rR   rP   rs   propertyrz   r0   r0   r0   r1   r3   <   s(   

8.
r3   c                   @  s   e Zd ZU dZded< ded< dZded< d	Zd
ed< eddddddZdddddddZ	ddddZ
eddddZdS )TLSListenera  
    A convenience listener that wraps another listener and auto-negotiates a TLS session
    on every accepted connection.

    If the TLS handshake times out or raises an exception,
    :meth:`handle_handshake_error` is called to do whatever post-mortem processing is
    deemed necessary.

    Supports only the :attr:`~TLSAttribute.standard_compatible` extra attribute.

    :param Listener listener: the listener to wrap
    :param ssl_context: the SSL context object
    :param standard_compatible: a flag passed through to :meth:`TLSStream.wrap`
    :param handshake_timeout: time limit for the TLS handshake
        (passed to :func:`~anyio.fail_after`)
    zListener[Any]listenerzssl.SSLContextr9   Tr#   r(      floathandshake_timeoutre   r   rc   )r_   streamr:   c                   sJ   t |I dH  t| t s.ttjd| d t| trDt| t rF dS )a  
        Handle an exception raised during the TLS handshake.

        This method does 3 things:

        #. Forcefully closes the original stream
        #. Logs the exception (unless it was a cancellation exception) using the
           ``anyio.streams.tls`` logger
        #. Reraises the exception if it was a base exception or a cancellation exception

        :param exc: the exception
        :param stream: the original stream

        NzError during TLS handshake)exc_info)r   rY   r   logging	getLoggerr+   	exception	Exception)r_   r   r0   r0   r1   handle_handshake_error  s    
 z"TLSListener.handle_handshake_errorNzCallable[[TLSStream], Any]zTaskGroup | None)handler
task_groupr:   c                   s6   t  ddd fdd}j||I d H  d S )Nr   rc   )r   r:   c              
     s   ddl m} z4|j  tj| jjdI d H }W 5 Q R X W n4 tk
rt } z|| I d H  W 5 d }~X Y nX  |I d H  d S )Nr
   )
fail_after)r9   r(   )	 r   r   r3   rK   r9   r(   re   r   )r   r   Zwrapped_streamr_   r   r\   r0   r1   handler_wrapper8  s    $z*TLSListener.serve.<locals>.handler_wrapper)r   r   serve)r\   r   r   r   r0   r   r1   r   3  s    zTLSListener.server`   c                   s   | j  I d H  d S rd   )r   rf   rb   r0   r0   r1   rf   J  s    zTLSListener.aclosert   c                   s   t j fddiS )Nc                     s    j S rd   ry   r0   rb   r0   r1   rw   P  rx   z.TLSListener.extra_attributes.<locals>.<lambda>)r   r(   rb   r0   rb   r1   rz   M  s     
zTLSListener.extra_attributes)N)r+   r,   r-   r.   r/   r(   r   staticmethodr   r   rf   r   rz   r0   r0   r0   r1   r      s   
" r   )*
__future__r   r   rm   r=   syscollections.abcr   r   Zdataclassesr   	functoolsr   typingr   r   r	   r   r   r   r   r   Z_core._typedattrr   r   abcr   r   r   r   version_infor   r   Ztyping_extensionsr   r   r)   Z_PCTRTTZ_PCTRTTTr   r3   r   r0   r0   r0   r1   <module>   s0   
 ?