HEX
Server: Apache
System: Linux p102.lithium.hosting 4.18.0-553.141.1.el8_10.x86_64 #1 SMP Fri Jul 10 17:48:02 UTC 2026 x86_64
User: bvzmoamr (9955)
PHP: 8.1.34
Disabled: syslog
Upload Files
File: //lib64/python2.7/site-packages/mercurial/sslutil.pyo
�
1�3\c@@s�ddlmZddlZddlZddlZddlZddlmZddlm	Z	m
Z
mZmZddl
mZmZddd	hZeed
e�ZdhZejed�r�ejd�nejed�r�ejd	�ny%ejZeZejed
�ZWn3ek
rPeZeZdefd��YZnXd�Zd�Zdd�Z ddded�Z!de"fd��YZ#dd�Z$d�Z%d�Z&ddgZ'd�Z(d�Z)dS(i(tabsolute_importNi(t_(terrortnodetpycompattutil(tprocutilt
stringutilstls1.0stls1.1stls1.2tHAS_SNItPROTOCOL_TLSv1_1tPROTOCOL_TLSv1_2tload_default_certst
SSLContextcB@sVeZd�Zddd�Zdd�Zdddd�Zd�Zded�Z	RS(cC@sX||_t|_d|_tj|_d|_d|_	d|_
d|_d|_dS(Ni(
tprotocoltFalsetcheck_hostnametoptionstsslt	CERT_NONEtverify_modetNonet	_certfilet_keyfilet
_certpasswordt_cacertst_ciphers(tselfR
((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyt__init__As							cC@s||_||_||_dS(N(RRR(Rtcertfiletkeyfiletpassword((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pytload_cert_chainOs		cC@sdS(N((Rtpurpose((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyRTscC@sI|rtjtd���n|r<tjtd���n||_dS(Nscapath not supportedscadata not supported(RtAbortRR(Rtcafiletcapathtcadata((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pytload_verify_locationsWs
cC@s
||_dS(N(R(Rtciphers((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pytset_ciphers_scC@sYi|jd6|jd6|d6|jd6|jd6|jd6|jd6}tj||�S(NRRtserver_sidet	cert_reqstssl_versiontca_certsR&(RRRR
RRRtwrap_socket(Rtsockettserver_hostnameR(targs((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyR,bs





N(
t__name__t
__module__RRRRR%R'RR,(((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyR@s		c
C@sTtj|�}i
td6gd6d*d6td6td6d*d6d*d6d*d6d*d	6d*d
6}d�}dtkryd}n2|jd
d�s�|jtd�|�nd}d}|j	d
||�}|||�d|}|j	d
||�}|||�|j
rd}nt|�\|d<|d	<|d<|j	d
d
�}|j	d
d||�}||d
<|jd
d|�}	x�|	D]�}
|
j
d+�s�tjtd�||
fdtd���n|
jdd�\}}
|
jdd�j�}
|dj||
f�q�WxS|jd|�D]?}
|
jdd�j�}
|djd|
f�t|d<q%W|dr�tj|d<t|d<n-|j
r�t|d<tj|d<t|d<n|jd d!�r�t|d<n|j	d
d"|�}|dr|r|jtd#�|�n|dd*krP|r�tj|�}tjj|�sxtjtd$�d%|f|f��n||d<n�|j	d&d'�}|r�tj|�}tjj|�stjtd(�|��qn3|drt|�}|r|jd)|�qn||d<|s0tr@|dr@tj|d<qPtj|d<n|S(,shObtain security settings for a hostname.

    Returns a dict of settings relevant to that hostname.
    tallowloaddefaultcertstcertfingerprintsR"tdisablecertverificationtlegacyfingerprintR
t
protocoluit
verifymodet
ctxoptionsR&cS@sQ|tkrMtjtd�||fdtd�djtt����ndS(Ns-unsupported protocol from hostsecurity.%s: %sthintsvalid protocols: %st (tconfigprotocolsRR!Rtjointsorted(R
tkey((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pytvalidateprotocol�s	
	stls1.1thostsecuritytdisabletls10warnings�warning: connecting to %s using legacy security technology (TLS 1.0); see https://mercurial-scm.org/wiki/SecureConnections for more info
stls1.0tminimumprotocols%s:minimumprotocols
%s:cipherss%s:fingerprintsssha1:ssha256:ssha512:sinvalid fingerprint for %s: %sR9s0must begin with "sha1:", "sha256:", or "sha512:"t:itthostfingerprintstsha1tdeveltdisableloaddefaultcertss%s:verifycertsfiless(hostsecurity.%s:verifycertsfile ignored when host fingerprints defined; using host fingerprints for verification)
s'path specified by %s does not exist: %sshostsecurity.%s:verifycertsfiletwebtcacertsscould not find web.cacerts: %ssusing %s for CA file
N(ssha1:ssha256:ssha512:(RtbytesurltTrueRRtsupportedprotocolst
configbooltwarnRtconfigtinsecureconnectionstprotocolsettingst
configlistt
startswithRR!tsplittreplacetlowertappendRRRt
expandpathtostpathtexistst_defaultcacertstdebugt_canloaddefaultcertst
CERT_REQUIRED(
tuithostnamet	bhostnametsR?tdefaultprotocolR>R
R&tfingerprintstfingerprinttalgR"((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyt
_hostsettingsss�
		


		!





	






cC@s|tkrtd|��ntdhkrr|dkrbtjtd�|dtd���ntjddfStjtj	B}|dkr�nT|dkr�|tj
O}n8|dkr�|tj
tjBO}ntjtd	���|ttd
d�O}tj
||fS(s�Resolve the protocol for a config value.

    Returns a 3-tuple of (protocol, options, ui value) where the first
    2 items are values used by SSLContext and the last is a string value
    of the ``minimumprotocol`` config option equivalent.
    s protocol value not supported: %sstls1.0s3current Python does not support protocol setting %sR9sAupgrade Python or disable setting since only TLS 1.0 is supportedistls1.1stls1.2sthis should not happentOP_NO_COMPRESSION(R;t
ValueErrorRMRR!RRtPROTOCOL_TLSv1tOP_NO_SSLv2tOP_NO_SSLv3tOP_NO_TLSv1t
OP_NO_TLSv1_1tgetattrtPROTOCOL_SSLv23(R
R((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyRRs$
c
@s:|stjtd���nxd��fD]V}|r+tjj|�r+tjtd�|tj|�fdtd���q+q+Wt�|�}t	|d�}|j
|dO_
|d|_|drEy|jtj
|d��WqEtjk
rA}tjtd	�tj|jd
�dtd�|d��qEXn�d%k	r|���fd�}	|j��|	�n|d
d%k	r0y|jd
|d
�Wn�tjk
r&}t|j�dkr�|jd
}
n
|jd}
tjtd�|d
tj|
�fdtd���nXt}n#|drM|j�t}nt}y|j|d|�}Wn~tjk
r�}yF|r�|dtjkr�tr�|j�r��jtd��nWntjk
r�nXtj |d�r�|j!dkr�|ddkrgt"dhkrM�jtd�|dj#t$t"��f�q��jtd�|�q��jtd�|d|f��jtd�|��jtd��q�|j!dkr�tj%r��jtd��q�n�nX|j&�stjtd ���ni|d!6|d"6|d#6�d$6|_'|S(&s�Add SSL/TLS to a socket.

    This is a glorified wrapper for ``ssl.wrap_socket()``. It makes sane
    choices based on what security options are available.

    In addition to the arguments supported by ``ssl.wrap_socket``, we allow
    the following additional arguments:

    * serverhostname - The expected hostname of the remote server. If the
      server (and client) support SNI, this tells the server which certificate
      to use.
    s#serverhostname argument is requireds:certificate file (%s) does not exist; cannot connect to %sR9s:restore missing file or fix references in Mercurial configR
R8R7R&scould not set ciphers: %sis#change cipher string (%s) in configc@s&�p	�}�jtd�|d�S(Nspassphrase for %s: RD(tgetpassR(tf(RRRa(s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyR�sR"iserror loading CA file %s: %ssfile is empty or malformed?R2R.s�(an attempt was made to load CA certificates but none were loaded; see https://mercurial-scm.org/wiki/SecureConnections for how to configure Mercurial to avoid this error)
treasontUNSUPPORTED_PROTOCOLR6stls1.0s�(could not communicate with %s using security protocols %s; if you are using a modern Mercurial version, consider contacting the operator of this server; see https://mercurial-scm.org/wiki/SecureConnections for more info)
s, s�(could not communicate with %s using TLS 1.0; the likely cause of this is the server no longer supports TLS 1.0 because it has known security vulnerabilities; see https://mercurial-scm.org/wiki/SecureConnections for more info)
s�(could not negotiate a common security protocol (%s+) with %s; the likely cause is Mercurial is configured to be more secure than the server can support)
s�(consider contacting the operator of this server and ask them to support modern TLS protocol versions; or, set hostsecurity.%s:minimumprotocol=tls1.0 to allow use of legacy, less secure protocols when communicating with this server)
sE(see https://mercurial-scm.org/wiki/SecureConnections for more info)
tCERTIFICATE_VERIFY_FAILEDsR(the full certificate chain may not be available locally; see "hg help debugssl")
sssl connection failedtcaloadedRbtsettingsRaN((RR!RRZR[R\RRKRiRRRR'tsysstrRtSSLErrorRtforcebytestrR/RRR%tlenRLRRR,R`t	modernssltget_ca_certsRORtsafehasattrRuRMR<R=t	iswindowstciphert_hgstate(
tsockRRRatserverhostnameRtRyt
sslcontextteRtmsgRxt	sslsocket((RRRas7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyt
wrapsocketOs�
		

		
	

	
				
	
cC@sCxL|||fD];}|rtjj|�rtjtd�|��qqWtd�\}}}	|jdd�}
|
dkr�tj	}n�|
dkr�dt
kr�tjtd���ntj}n^|
dkrdt
kr�tjtd���ntj}n"|
r(tjtd	�|
��nt
r�t|�}|j|O_|jttd
d�O_|jttdd�O_tjtd
�r�|jttdd�O_|jtj�q�nttj	�}|r�tj|_ntj|_|s�|r|jd|d|�n|r0|jd|�n|j|dt�S(s�Wrap a socket for use by servers.

    ``certfile`` and ``keyfile`` specify the files containing the certificate's
    public and private keys, respectively. Both keys can be defined in the same
    file via ``certfile`` (the private key must come first in the file).

    ``cafile`` defines the path to certificate authorities.

    ``requireclientcert`` specifies whether to require client certificates.

    Typically ``cafile`` is only defined if ``requireclientcert`` is true.
    s/referenced certificate file (%s) does not existstls1.0RGtserverexactprotocolstls1.1s$TLS 1.1 not supported by this Pythonstls1.2s$TLS 1.2 not supported by this Pythons)invalid value for serverexactprotocol: %stOP_SINGLE_DH_USEitOP_SINGLE_ECDH_USEt_RESTRICTED_SERVER_CIPHERStOP_CIPHER_SERVER_PREFERENCERRR"R((RZR[R\RR!RRRRPRRlRMR	R
R~RRRqRR�R'R�R`RRRR%R,RL(R�RaRRR"trequireclientcertRtR
Rt_protocoluit
exactprotocolR�((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pytwrapserversocket�sH
t
wildcarderrorcB@seZdZRS(s2Represents an error parsing wildcards in DNS name.(R0R1t__doc__(((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyR�Dsc
C@svg}|stStj|�}tj|�}|jd�}|d}|d}|jd�}||kr�ttd�|��n|s�|j�|j�kS|dkr�|jd�nY|j	d�s�|j	d�r�|jt
j|��n"|jt
j|�jdd	��x$|D]}|jt
j|��qWt
jd
dj|�dt
j�}	|	j|�d
k	S(s�Match DNS names according RFC 6125 section 6.4.3.

    This code is effectively copied from CPython's ssl._dnsname_match.

    Returns a bool indicating whether the expected hostname matches
    the value in ``dn``.
    t.iit*s.too many wildcards in certificate DNS name: %ss[^.]+sxn--s\*s[^.]*s\As\.s\ZN(RRRKRUtcountR�RRWRXRTRtreescapeRVtretcompileR<t
IGNORECASEtmatchR(
tdnRbtmaxwildcardstpatstpiecestleftmostt	remaindert	wildcardstfragtpat((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyt
_dnsnamematchGs.

"
&c	C@s�|std�Sg}|jdg�}xn|D]f\}}|dkr/yt||�r]dSWn$tk
r�}tj|jd�SX|j|�q/q/W|s^x�|jdg�D]�}x�|D]�\}}|dkr�y|jd�}Wnt	k
rtd	�SXyt||�rdSWn$tk
rB}tj|jd�SX|j|�q�q�Wq�Wng|D]}t
j|�^qe}t|�d
kr�td�dj
|�St|�d
kr�td�|dStd
�SdS(s�Verify that cert (in socket.getpeercert() format) matches hostname.
    CRLs is not handled.

    Returns error message if any problems are found and None on success.
    sno certificate receivedtsubjectAltNametDNSNitsubjectt
commonNametasciis IDN in certificate not supportediscertificate is for %ss, s4no commonName or subjectAltName found in certificate(RtgetR�R�RR|R/RXtencodetUnicodeEncodeErrorRRKR}R<(	tcertRbtdnsnamestsanR>tvalueR�tsubtd((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyt_verifycertys@

"cC@s[tjs tj�s tjr$tStjjtj�j	�}|j
d�pZ|j
d�S(s@return true if this seems to be a pure Apple Python that
    * is unfrozen and presumably has the whole mercurial module in the file
      system
    * presumably is an Apple Python that uses Apple OpenSSL which has patches
      for using system certificate store CAs in addition to the provided
      cacerts file
    s/usr/bin/pythons,/system/library/frameworks/python.framework/(RtisdarwinRt
mainfrozent
sysexecutableRRZR[trealpathRWRT(texe((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyt_plainapplepython�s
s&/etc/pki/tls/certs/ca-bundle.trust.crts"/etc/ssl/certs/ca-certificates.crtcC@sUy?ddl}|j�}tjj|�r>|jd�|SWnttfk
rXnXtj	r�t
s~|jtd��ndSt�r�tjjtjjtjt��d�}tjj|�r�|Sntjr�t
s�|jtd��ndSt
sQx;tD]3}tjj|�r|jtd�|�|SqW|jtd��ndS(s�return path to default CA certificates or None.

    It is assumed this function is called when the returned certificates
    file will actually be used to validate connections. Therefore this
    function may print warnings or debug messages assuming this usage.

    We don't print a message when the Python is able to load default
    CA certs because this scenario is detected at socket connect time.
    iNs#using ca certificates from certifi
s�(unable to load Windows CA certificates; see https://mercurial-scm.org/wiki/SecureConnections for how to configure Mercurial to avoid this message)
s
dummycert.pems�(unable to load CA certificates; see https://mercurial-scm.org/wiki/SecureConnections for how to configure Mercurial to avoid this message)
s�(using CA certificates from %s; if you see this message, your Mercurial install is not properly configured; see https://mercurial-scm.org/wiki/SecureConnections for how to configure Mercurial to avoid this message)
(tcertifitwhereRZR[R\R^tImportErrortAttributeErrorRR�R_RORRR�R<tdirnametfsencodet__file__R�t_systemcacertpathstisfile(RaR�tcertst	dummycertR[((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyR]�s:
			!	
cC@s�|jd}tj|�}|jd}|jd}y|jt�}|j�}Wn*tk
r�tjtd�|��nX|s�tjtd�|��n|dr�|j	td�|�dSit
jtj
|�j��d	6t
jtj|�j��d
6t
jtj|�j��d6}d�}d
||d
�}	|drJx|dD]s\}
}||
j�|kr^|jd||
||�f�|dr�|j	td�|||	f�ndSq^W|dr�d}||d	�}
n d}d|
|||
�f}
tjtd�||
fdtd�|��n|jds�tjtd�|dtd�||	f��nt||�}|r�tjtd�||fdtd�||	f��ndS(sxValidate a socket meets security requirements.

    The passed socket must have been created with ``wrapsocket()``.
    RbRaRys%s ssl connection errors-%s certificate error: no certificate receivedR4s�warning: connection security to %s is disabled per current settings; communication is susceptible to eavesdropping and tampering
NRFtsha256tsha512cS@s=djgtdt|�d�D]}|||d!^q�S(NRCii(R<trangeR}(Rdtx((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pytfmtfingerprint=ss	sha256:%sR3s)%s certificate matched fingerprint %s:%s
R5s�(SHA-1 fingerprint for %s found in legacy [hostfingerprints] section; if you trust this fingerprint, remove the old SHA-1 fingerprint from [hostfingerprints] and add the following entry to the new [hostsecurity] section: %s:fingerprints=%s)
thostfingerprintR@s%s:%ss0certificate for %s has unexpected fingerprint %sR9scheck %s configurationRxsPunable to verify security of %s (no loaded CA certificates); refusing to connects�see https://mercurial-scm.org/wiki/SecureConnections for how to configure Mercurial to avoid this error or set hostsecurity.%s:fingerprints=%s to trust this servers%s certificate error: %ss^set hostsecurity.%s:certfingerprints=%s config setting or use --insecure to connect insecurely(R�RRKtgetpeercertRLR�RR!RRORthexthashlibRFtdigestR�R�RWR^R�(R�tshostthostRaRytpeercertt	peercert2tpeerfingerprintsR�tnicefingerprintthashRgtsectiontniceR�((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pytvalidatesocketsd





"	
	



			(*t
__future__RR�RZR�Rti18nRRDRRRRtutilsRRR;RqRthassniRMR�taddRRLR~R_R�tobjectRiRRRR�R�t	ExceptionR�R�R�R�R�R]R�(((s7/usr/lib64/python2.7/site-packages/mercurial/sslutil.pyt<module>
sJ"			
3	�	4�	F2	2			T