Ë
    ojâ‚  ã                   ó,  — U d Z ddlmZ ddlmZ ddlmZ ddlmZm	Z	 ddl
mZ ddlmZmZmZ ddlmZ dd	lmZmZ dd
lmZmZ ddlmZ ddlmZ ddlmZ dZee   ed<    ed«      rddl m!Z! ddl"mZm#Z#m$Z$ ddl%m&Z& ddl'm(Z( n G d„ d«      Z# G d„ d«      Z$ G d„ de$jR                  «      Z* G d„ de$jR                  «      Z+ G d„ de$jR                  «      Z, G d„ d e#jZ                  «      Z. ee«       G d!„ d"«      «       Z/ ee«       G d#„ d$«      «       Z0 ee«       G d%„ d&«      «       Z1 ee«       G d'„ d(«      «       Z2 G d)„ d*ejf                  «      Z4 G d+„ d,ejf                  «      Z5 G d-„ d.ejf                  «      Z6 G d/„ d0ejf                  «      Z7y)1zT
Tests for the implementation of the ssh-userauth service.

Maintainer: Paul Swartz
é    )Ú
ModuleType)ÚOptional)Úimplementer)Ú
ConchErrorÚValidPublicKey)ÚICredentialsChecker)Ú
IAnonymousÚISSHPrivateKeyÚIUsernamePassword)ÚUnauthorizedLogin)ÚIRealmÚPortal)ÚdeferÚtask)Úloopback)ÚrequireModule)ÚunittestNÚkeysÚcryptography)ÚSSHProtocolChecker)r   Ú	transportÚuserauth)ÚNS)Úkeydatac                   ó    — e Zd Z G d„ d«      Zy)r   c                   ó   — e Zd ZdZy)útransport.SSHTransportBaseúQ
            A stub class so that later class definitions won't die.
            N©Ú__name__Ú
__module__Ú__qualname__Ú__doc__© ó    úB/usr/lib/python3/dist-packages/twisted/conch/test/test_userauth.pyÚSSHTransportBaser   "   ó   „ òr%   r'   N)r    r!   r"   r'   r$   r%   r&   r   r   !   ó   „ ÷	ò 	r%   r   c                   ó    — e Zd Z G d„ d«      Zy)r   c                   ó   — e Zd ZdZy)úuserauth.SSHUserAuthClientr   Nr   r$   r%   r&   ÚSSHUserAuthClientr,   (   r(   r%   r-   N)r    r!   r"   r-   r$   r%   r&   r   r   '   r)   r%   r   c                   ó*   — e Zd ZdZd„ Zd„ Zdd„Zd„ Zy)ÚClientUserAuthz"
    A mock user auth client.
    c                 óô   — | j                   r-t        j                  j                  t        j
                  «      S t        j                  t        j                  j                  t        j                  «      «      S )z˜
        If this is the first time we've been called, return a blob for
        the DSA key.  Otherwise, return a blob
        for the RSA key.
        )	ÚlastPublicKeyr   ÚKeyÚ
fromStringr   ÚpublicRSA_opensshr   ÚsucceedÚpublicDSA_openssh©Úselfs    r&   ÚgetPublicKeyzClientUserAuth.getPublicKey3   sL   € ð ×ÒÜ—8‘8×&Ñ&¤w×'@Ñ'@ÓAÐAä—=‘=¤§¡×!4Ñ!4´W×5NÑ5NÓ!OÓPÐPr%   c                 ó‚   — t        j                  t        j                  j	                  t
        j                  «      «      S )z@
        Return the private key object for the RSA key.
        )r   r5   r   r2   r3   r   ÚprivateRSA_opensshr7   s    r&   ÚgetPrivateKeyzClientUserAuth.getPrivateKey>   s(   € ô �}‰}œTŸX™X×0Ñ0´×1KÑ1KÓLÓMÐMr%   Nc                 ó,   — t        j                  d«      S )z/
        Return 'foo' as the password.
        ó   foo©r   r5   )r8   Úprompts     r&   ÚgetPasswordzClientUserAuth.getPasswordD   s   € ô �}‰}˜VÓ$Ð$r%   c                 ó,   — t        j                  d«      S )z>
        Return 'foo' as the answer to two questions.
        )ÚfoorC   r?   )r8   ÚnameÚinformationÚanswerss       r&   ÚgetGenericAnswersz ClientUserAuth.getGenericAnswersJ   s   € ô �}‰}˜^Ó,Ð,r%   ©N)r    r!   r"   r#   r9   r<   rA   rG   r$   r%   r&   r/   r/   .   s   „ ñò	QòNó%ó-r%   r/   c                   ó   — e Zd ZdZd„ Zd„ Zy)ÚOldClientAuthz~
    The old SSHUserAuthClient returned a cryptography key object from
    getPrivateKey() and a string from getPublicKey
    c                 ó–   — t        j                  t        j                  j	                  t
        j                  «      j                  «      S rH   )r   r5   r   r2   r3   r   r;   Ú	keyObjectr7   s    r&   r<   zOldClientAuth.getPrivateKeyW   s,   € Ü�}‰}œTŸX™X×0Ñ0´×1KÑ1KÓL×VÑVÓWÐWr%   c                 óx   — t         j                  j                  t        j                  «      j                  «       S rH   )r   r2   r3   r   r4   Úblobr7   s    r&   r9   zOldClientAuth.getPublicKeyZ   s&   € Ü�x‰x×"Ñ"¤7×#<Ñ#<Ó=×BÑBÓDÐDr%   N©r    r!   r"   r#   r<   r9   r$   r%   r&   rJ   rJ   Q   s   „ ñò
XóEr%   rJ   c                   ó   — e Zd ZdZd„ Zd„ Zy)ÚClientAuthWithoutPrivateKeyzP
    This client doesn't have a private key, but it does have a public key.
    c                  ó   — y rH   r$   r7   s    r&   r<   z)ClientAuthWithoutPrivateKey.getPrivateKeyc   s   € Ør%   c                 ó\   — t         j                  j                  t        j                  «      S rH   )r   r2   r3   r   r4   r7   s    r&   r9   z(ClientAuthWithoutPrivateKey.getPublicKeyf   s   € Ü�x‰x×"Ñ"¤7×#<Ñ#<Ó=Ð=r%   NrO   r$   r%   r&   rQ   rQ   ^   s   „ ñòó>r%   rQ   c                   óP   — e Zd ZdZ G d„ d«      Z G d„ d«      Zd„ Zd„ Zd„ Zd	„ Z	y
)ÚFakeTransporta_  
    L{userauth.SSHUserAuthServer} expects an SSH transport which has a factory
    attribute which has a portal attribute. Because the portal is important for
    testing authentication, we need to be able to provide an interesting portal
    object to the L{SSHUserAuthServer}.

    In addition, we want to be able to capture any packets sent over the
    transport.

    @ivar packets: a list of 2-tuples: (messageType, data).  Each 2-tuple is
        a sent packet.
    @type packets: C{list}
    @param lostConnecion: True if loseConnection has been called on us.
    @type lostConnection: L{bool}
    c                   ó   — e Zd ZdZdZd„ Zy)úFakeTransport.ServicezW
        A mock service, representing the other service offered by the server.
        ó   nancyc                  ó   — y rH   r$   r7   s    r&   ÚserviceStartedz$FakeTransport.Service.serviceStarted‚   s   € Ør%   N)r    r!   r"   r#   rD   rZ   r$   r%   r&   ÚServicerW   {   s   „ ñ	ð ˆó	r%   r[   c                   ó   — e Zd ZdZd„ Zy)úFakeTransport.Factoryzg
        A mock factory, representing the factory that spawned this user auth
        service.
        c                 ó.   — |dk(  rt         j                  S y)z2
            Return our fake service.
            ó   noneN)rU   r[   )r8   r   Úservices      r&   Ú
getServicez FakeTransport.Factory.getService‹   s   € ð ˜'Ò!Ü$×,Ñ,Ð,ð "r%   N)r    r!   r"   r#   ra   r$   r%   r&   ÚFactoryr]   …   s   „ ñ	ó
	-r%   rb   c                 óz   — | j                  «       | _        || j                  _        d| _        | | _        g | _        y ©NF)rb   ÚfactoryÚportalÚlostConnectionr   Úpackets)r8   rf   s     r&   Ú__init__zFakeTransport.__init__’   s1   € Ø—|‘|“~ˆŒØ$ˆ�‰ÔØ#ˆÔØˆŒØˆ�r%   c                 ó>   — | j                   j                  ||f«       y)z8
        Record the packet sent by the service.
        N)rh   Úappend)r8   ÚmessageTypeÚmessages      r&   Ú
sendPacketzFakeTransport.sendPacket™   s   € ð 	�‰×Ñ˜[¨'Ð2Õ3r%   c                  ó   — y)z»
        Pretend that this transport encrypts traffic in both directions. The
        SSHUserAuthServer disables password authentication if the transport
        isn't encrypted.
        Tr$   )r8   Ú	directions     r&   ÚisEncryptedzFakeTransport.isEncryptedŸ   s   € ð r%   c                 ó   — d| _         y ©NT)rg   r7   s    r&   ÚloseConnectionzFakeTransport.loseConnection§   s
   € Ø"ˆÕr%   N)
r    r!   r"   r#   r[   rb   ri   rn   rq   rt   r$   r%   r&   rU   rU   j   s/   „ ñ÷ ñ ÷-ñ -òò4òó#r%   rU   c                   ó   — e Zd ZdZd„ Zy)ÚRealmz¿
    A mock realm for testing L{userauth.SSHUserAuthServer}.

    This realm is not actually used in the course of testing, so it returns the
    simplest thing that could possibly work.
    c                 ó:   — t        j                  |d   d d„ f«      S )Nr   c                   ó   — y rH   r$   r$   r%   r&   ú<lambda>z%Realm.requestAvatar.<locals>.<lambda>µ   ó   � r%   r?   )r8   ÚavatarIdÚmindÚ
interfacess       r&   ÚrequestAvatarzRealm.requestAvatar´   s   € Ü�}‰}˜j¨™m¨T±<Ð@ÓAÐAr%   N)r    r!   r"   r#   r~   r$   r%   r&   rv   rv   «   s   „ ñóBr%   rv   c                   ó   — e Zd ZdZefZd„ Zy)ÚPasswordCheckerzŽ
    A very simple username/password checker which authenticates anyone whose
    password matches their username and rejects all others.
    c                 ó®   — |j                   |j                  k(  rt        j                  |j                   «      S t        j                  t        d«      «      S )NzInvalid username/password pair)ÚusernameÚpasswordr   r5   Úfailr   )r8   Úcredss     r&   ÚrequestAvatarIdzPasswordChecker.requestAvatarIdÁ   s;   € Ø�>‰>˜UŸ^™^Ò+Ü—=‘= §¡Ó0Ð0Ü�z‰zÔ+Ð,LÓMÓNÐNr%   N)r    r!   r"   r#   r   ÚcredentialInterfacesr†   r$   r%   r&   r€   r€   ¸   s   „ ñð
 .Ð/ÐóOr%   r€   c                   ó   — e Zd ZdZefZd„ Zy)ÚPrivateKeyCheckerz•
    A very simple public key checker which authenticates anyone whose
    public/private keypair is the same keydata.public/privateRSA_openssh.
    c                 óœ  — |j                   t        j                  j                  t        j
                  «      j                  «       k(  r{|j                  �et        j                  j                  |j                   «      }|j                  |j                  |j                  «      r|j                  S t        «       ‚t        «       ‚t        «       ‚rH   )rN   r   r2   r3   r   r4   Ú	signatureÚverifyÚsigDatar‚   r   r   )r8   r…   Úobjs      r&   r†   z!PrivateKeyChecker.requestAvatarIdÐ   s�   € Ø�:‰:œŸ™×,Ñ,¬W×-FÑ-FÓG×LÑLÓNÒNØ�‰Ð*Ü—h‘h×)Ñ)¨%¯*©*Ó5�Ø—:‘:˜eŸo™o¨u¯}©}Ô=Ø Ÿ>™>Ð)ô  Ó!Ð!ô %Ó&Ð&ÜÓ!Ð!r%   N)r    r!   r"   r#   r
   r‡   r†   r$   r%   r&   r‰   r‰   Ç   s   „ ñð
 +Ð,Ðó"r%   r‰   c                   ó   — e Zd ZdZefZd„ Zy)ÚAnonymousCheckerzI
    A simple checker which isn't supported by L{SSHUserAuthServer}.
    c                  ó   — y rH   r$   )r8   Úcredentialss     r&   r†   z AnonymousChecker.requestAvatarIdã   s   € àr%   N)r    r!   r"   r#   r	   r‡   r†   r$   r%   r&   r�   r�   Û   s   „ ñð '˜=Ðór%   r�   c                   ó�   — e Zd ZdZe€dZd„ Zd„ Zd„ Zd„ Z	d„ Z
d	„ Zd
„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zy)ÚSSHUserAuthServerTestsz&
    Tests for SSHUserAuthServer.
    Núcannot run without cryptographyc                 óØ  — t        «       | _        t        | j                  «      | _        | j                  j	                  t        «       «       | j                  j	                  t        «       «       t        j                  «       | _	        t        | j                  «      | j                  _        | j                  j                  «        | j                  j                  j                  «        y rH   )rv   Úrealmr   rf   ÚregisterCheckerr€   r‰   r   ÚSSHUserAuthServerÚ
authServerrU   r   rZ   ÚsupportedAuthenticationsÚsortr7   s    r&   ÚsetUpzSSHUserAuthServerTests.setUpð   s‘   € Ü“WˆŒ
Ü˜TŸZ™ZÓ(ˆŒØ�‰×#Ñ#¤OÓ$5Ô6Ø�‰×#Ñ#Ô$5Ó$7Ô8Ü"×4Ñ4Ó6ˆŒÜ$1°$·+±+Ó$>ˆ�‰Ô!Ø�‰×&Ñ&Ô(Ø�‰×0Ñ0×5Ñ5Õ7r%   c                 óF   — | j                   j                  «        d | _         y rH   )rš   ÚserviceStoppedr7   s    r&   ÚtearDownzSSHUserAuthServerTests.tearDownû   ó   € Ø�‰×&Ñ&Ô(Øˆ�r%   c                 ó¢   — | j                  | j                  j                  j                  d   t        j
                  t        d«      dz   f«       y)z;
        Check that the authentication has failed.
        éÿÿÿÿs   password,publickeyó    N)ÚassertEqualrš   r   rh   r   ÚMSG_USERAUTH_FAILUREr   ©r8   Úignoreds     r&   Ú_checkFailedz#SSHUserAuthServerTests._checkFailedÿ   sC   € ð 	×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1Ü×*Ñ*¬BÐ/DÓ,EÈÑ,OÐPõ	
r%   c                 ó°   — | j                   j                  t        d«      t        d«      z   t        d«      z   «      }|j                  | j                  «      S )zÃ
        A client may request a list of authentication 'method name' values
        that may continue by using the "none" authentication 'method name'.

        See RFC 4252 Section 5.2.
        r>   s   servicer_   )rš   Ússh_USERAUTH_REQUESTr   ÚaddCallbackr©   )r8   Úds     r&   Útest_noneAuthenticationz.SSHUserAuthServerTests.test_noneAuthentication  sH   € ð �O‰O×0Ñ0Üˆv‹Jœ˜J›Ñ'¬"¨W«+Ñ5ó
ˆð �}‰}˜T×.Ñ.Ó/Ð/r%   c           	      óÚ   ‡ — dj                  t        d«      t        d«      t        d«      dt        d«      g«      }‰ j                  j                  |«      }ˆ fd„}|j	                  |«      S )zÝ
        When provided with correct password authentication information, the
        server should respond by sending a MSG_USERAUTH_SUCCESS message with
        no other data.

        See RFC 4252, Section 5.1.
        r%   r>   r_   ó   passwordr¤   c                 óˆ   •— ‰j                  ‰j                  j                  j                  t        j
                  dfg«       y ©Nr%   ©r¥   rš   r   rh   r   ÚMSG_USERAUTH_SUCCESS©r¨   r8   s    €r&   ÚcheckzKSSHUserAuthServerTests.test_successfulPasswordAuthentication.<locals>.check  ó5   ø€ Ø×ÑØ—‘×)Ñ)×1Ñ1Ü×/Ñ/°Ð5Ð6õr%   )Újoinr   rš   r«   r¬   )r8   Úpacketr­   r¶   s   `   r&   Ú%test_successfulPasswordAuthenticationz<SSHUserAuthServerTests.test_successfulPasswordAuthentication  sX   ø€ ð —‘œ2˜f›:¤r¨'£{´B°{³OÀUÌBÈvËJÐWÓXˆØ�O‰O×0Ñ0°Ó8ˆô	ð �}‰}˜UÓ#Ð#r%   c           	      óÒ  — dj                  t        d«      t        d«      t        d«      dt        d«      g«      }t        j                  «       | j                  _        | j                  j                  |«      }| j                  | j                  j                  j                  g «       | j                  j
                  j                  d«       |j                  | j                  «      S )a;  
        When provided with invalid authentication details, the server should
        respond by sending a MSG_USERAUTH_FAILURE message which states whether
        the authentication was partially successful, and provides other, open
        options for authentication.

        See RFC 4252, Section 5.1.
        r%   r>   r_   r°   r¤   ó   baré   )r¸   r   r   ÚClockrš   Úclockr«   r¥   r   rh   Úadvancer¬   r©   ©r8   r¹   r­   s      r&   Ú!test_failedPasswordAuthenticationz8SSHUserAuthServerTests.test_failedPasswordAuthentication'  s    € ð —‘œ2˜f›:¤r¨'£{´B°{³OÀUÌBÈvËJÐWÓXˆÜ $§
¡
£ˆ�‰ÔØ�O‰O×0Ñ0°Ó8ˆØ×Ñ˜Ÿ™×2Ñ2×:Ñ:¸BÔ?Ø�‰×Ñ×%Ñ% aÔ(Ø�}‰}˜T×.Ñ.Ó/Ð/r%   c                 ó�  ‡ — t         j                  j                  t        j                  «      j                  «       }t         j                  j                  t        j                  «      }t        d«      t        d«      z   t        d«      z   dz   t        |j                  «       «      z   t        |«      z   }d‰ j                  j                  _        |j                  t        d«      t        t        j                  f«      z   |z   «      }|t        |«      z  }‰ j                  j!                  |«      }ˆ fd„}|j#                  |«      S )zN
        Test that private key authentication completes successfully,
        r>   r_   ó	   publickeyó   ÿó   testc                 óˆ   •— ‰j                  ‰j                  j                  j                  t        j
                  dfg«       y r²   r³   rµ   s    €r&   r¶   zMSSHUserAuthServerTests.test_successfulPrivateKeyAuthentication.<locals>.checkM  r·   r%   )r   r2   r3   r   r4   rN   r;   r   ÚsshTyperš   r   Ú	sessionIDÚsignÚbytesr   ÚMSG_USERAUTH_REQUESTr«   r¬   )r8   rN   rŽ   r¹   r‹   r­   r¶   s   `      r&   Ú'test_successfulPrivateKeyAuthenticationz>SSHUserAuthServerTests.test_successfulPrivateKeyAuthentication8  s  ø€ ô �x‰x×"Ñ"¤7×#<Ñ#<Ó=×BÑBÓDˆÜ�h‰h×!Ñ!¤'×"<Ñ"<Ó=ˆäˆv‹JÜ�‹kñä�Óñð ñô �—‘“Óñ	 ô
 �‹hñð 	ð /6ˆ�‰×!Ñ!Ô+Ø—H‘HÜˆw‹Kœ%¤×!>Ñ!>Ð @ÓAÑAÀFÑJó
ˆ	ð 	”"�Y“-ÑˆØ�O‰O×0Ñ0°Ó8ˆô	ð �}‰}˜UÓ#Ð#r%   c                 ó°  ‡— t        j                  «       Šd„ }d„ }ˆfd„}| j                  | j                  d|«       | j                  | j                  d|«       | j                  | j                  d|«       t	        d«      t	        d«      z   t	        d	«      z   t	        d
«      z   }| j                  j                  |«       | j                  ‰t        «      S )z‹
        ssh_USERAUTH_REQUEST should raise a ConchError if tryAuth returns
        None. Added to catch a bug noticed by pyflakes.
        c                 ó&   — | j                  d«       y )Nz&request should have raised ConochError)r„   r§   s     r&   ÚmockCbFinishedAuthzOSSHUserAuthServerTests.test_requestRaisesConchError.<locals>.mockCbFinishedAuth\  s   € Ø�I‰IÐ>Õ?r%   c                  ó   — y rH   r$   )ÚkindÚuserÚdatas      r&   ÚmockTryAuthzHSSHUserAuthServerTests.test_requestRaisesConchError.<locals>.mockTryAuth_  ó   € Ør%   c                 ó<   •— ‰j                  | j                  «       y rH   )ÚerrbackÚvalue)Úreasonr­   s    €r&   ÚmockEbBadAuthzJSSHUserAuthServerTests.test_requestRaisesConchError.<locals>.mockEbBadAuthb  s   ø€ Ø�I‰I�f—l‘lÕ#r%   ÚtryAuthÚ_cbFinishedAuthÚ
_ebBadAuths   userr_   s
   public-keys   data)r   ÚDeferredÚpatchrš   r   r«   ÚassertFailurer   )r8   rÐ   rÕ   rÛ   r¹   r­   s        @r&   Útest_requestRaisesConchErrorz3SSHUserAuthServerTests.test_requestRaisesConchErrorU  s­   ø€ ô
 �N‰NÓˆò	@ò	ô	$ð 	�
‰
�4—?‘? I¨{Ô;Ø�
‰
�4—?‘?Ð$5Ð7IÔJØ�
‰
�4—?‘? L°-Ô@ä�G“œr '›{Ñ*¬R°Ó->Ñ>ÄÀGÃÑLˆð 	�‰×,Ñ,¨VÔ4Ø×!Ñ! !¤ZÓ0Ð0r%   c                 ó\  ‡ ‡— t         j                  j                  t        j                  «      j                  «       Št        d«      t        d«      z   t        d«      z   dz   t        d«      z   t        ‰«      z   }‰ j                  j                  |«      }ˆˆ fd„}|j                  |«      S )z@
        Test that verifying a valid private key works.
        r>   r_   rÄ   r¤   ó   ssh-rsac                 ó²   •— ‰j                  ‰j                  j                  j                  t        j
                  t        d«      t        ‰«      z   fg«       y )Nrä   )r¥   rš   r   rh   r   ÚMSG_USERAUTH_PK_OKr   )r¨   rN   r8   s    €€r&   r¶   z@SSHUserAuthServerTests.test_verifyValidPrivateKey.<locals>.check~  sB   ø€ Ø×ÑØ—‘×)Ñ)×1Ñ1Ü×-Ñ-¬r°*«~ÄÀ4ÃÑ/HÐIÐJõr%   )
r   r2   r3   r   r4   rN   r   rš   r«   r¬   )r8   r¹   r­   r¶   rN   s   `   @r&   Útest_verifyValidPrivateKeyz1SSHUserAuthServerTests.test_verifyValidPrivateKeyo  sŸ   ù€ ô �x‰x×"Ñ"¤7×#<Ñ#<Ó=×BÑBÓDˆäˆv‹JÜ�‹kñä�Óñð ñô �‹nñ	ô
 �‹hñð 	ð �O‰O×0Ñ0°Ó8ˆõ	ð �}‰}˜UÓ#Ð#r%   c                 ó`  — t         j                  j                  t        j                  «      j                  «       }t        d«      t        d«      z   t        d«      z   dz   t        d«      z   t        |«      z   }| j                  j                  |«      }|j                  | j                  «      S )úd
        Test that private key authentication fails when the public key
        is invalid.
        r>   r_   rÄ   r¤   s   ssh-dsa©r   r2   r3   r   r6   rN   r   rš   r«   r¬   r©   ©r8   rN   r¹   r­   s       r&   Ú3test_failedPrivateKeyAuthenticationWithoutSignaturezJSSHUserAuthServerTests.test_failedPrivateKeyAuthenticationWithoutSignature†  s�   € ô
 �x‰x×"Ñ"¤7×#<Ñ#<Ó=×BÑBÓDˆäˆv‹JÜ�‹kñä�Óñð ñô �‹nñ	ô
 �‹hñð 	ð �O‰O×0Ñ0°Ó8ˆØ�}‰}˜T×.Ñ.Ó/Ð/r%   c                 ó&  — t         j                  j                  t        j                  «      j                  «       }t         j                  j                  t        j                  «      }t        d«      t        d«      z   t        d«      z   dz   t        d«      z   t        |«      z   t        |j                  |«      «      z   }d| j                  j                  _        | j                  j                  |«      }|j                  | j                  «      S )ré   r>   r_   rÄ   rÅ   rä   rÆ   )r   r2   r3   r   r4   rN   r;   r   rÊ   rš   r   rÉ   r«   r¬   r©   )r8   rN   rŽ   r¹   r­   s        r&   Ú0test_failedPrivateKeyAuthenticationWithSignaturezGSSHUserAuthServerTests.test_failedPrivateKeyAuthenticationWithSignature—  sà   € ô
 �x‰x×"Ñ"¤7×#<Ñ#<Ó=×BÑBÓDˆÜ�h‰h×!Ñ!¤'×"<Ñ"<Ó=ˆäˆv‹JÜ�‹kñä�Óñð ñô �‹nñ	ô
 �‹hñô �—‘˜$“Ó ñ!ð 	ð /6ˆ�‰×!Ñ!Ô+Ø�O‰O×0Ñ0°Ó8ˆØ�}‰}˜T×.Ñ.Ó/Ð/r%   c                 ó‚  — t         j                  j                  t        j                  «      j                  «       }t        d«      |dd z   }t        d«      t        d«      z   t        d«      z   dz   t        d«      z   t        |«      z   }| j                  j                  |«      }|j                  | j                  «      S )	z€
        Private key authentication fails when the public key type is
        unsupported or the public key is corrupt.
        s   ssh-bad-typeé   Nr>   r_   rÄ   r¤   rä   rê   rë   s       r&   Útest_unsupported_publickeyz1SSHUserAuthServerTests.test_unsupported_publickey«  s¶   € ô
 �x‰x×"Ñ"¤7×#<Ñ#<Ó=×BÑBÓDˆô �/Ó" T¨"¨# YÑ.ˆô ˆv‹JÜ�‹kñä�Óñð ñô �‹nñ	ô
 �‹hñð 	ð �O‰O×0Ñ0°Ó8ˆà�}‰}˜T×.Ñ.Ó/Ð/r%   c                 óV  — t        j                  «       }t        | j                  «      |_        | j                  j                  t        «       «       |j                  «        |j                  «        |j                  j                  «        | j                  |j                  ddg«       y)ah  
        L{SSHUserAuthServer} sets up
        C{SSHUserAuthServer.supportedAuthentications} by checking the portal's
        credentials interfaces and mapping them to SSH authentication method
        strings.  If the Portal advertises an interface that
        L{SSHUserAuthServer} can't map, it should be ignored.  This is a white
        box test.
        r°   rÄ   N)r   r™   rU   rf   r   r˜   r�   rZ   rŸ   r›   rœ   r¥   )r8   Úservers     r&   Ú test_ignoreUnknownCredInterfacesz7SSHUserAuthServerTests.test_ignoreUnknownCredInterfacesÁ  s~   € ô ×+Ñ+Ó-ˆÜ(¨¯©Ó5ˆÔØ�‰×#Ñ#Ô$4Ó$6Ô7Ø×ÑÔØ×ÑÔØ×'Ñ'×,Ñ,Ô.Ø×Ñ˜×8Ñ8¸;ÈÐ:UÕVr%   c                 ó@  — | j                  d| j                  j                  «       t        j                  «       }t        | j                  «      |_        d„ |j                  _        |j                  «        |j                  «        | j                  d|j                  «       t        j                  «       }t        | j                  «      |_        d„ |j                  _        |j                  «        |j                  «        | j                  d|j                  «       y)z�
        Test that the userauth service does not advertise password
        authentication if the password would be send in cleartext.
        r°   c                  ó   — yrd   r$   ©Úxs    r&   ry   zISSHUserAuthServerTests.test_removePasswordIfUnencrypted.<locals>.<lambda>Û  rz   r%   c                 ó   — | dk(  S ©NÚinr$   r÷   s    r&   ry   zISSHUserAuthServerTests.test_removePasswordIfUnencrypted.<locals>.<lambda>â  ó
   € ¸¸d¹€ r%   N)ÚassertInrš   r›   r   r™   rU   rf   r   rq   rZ   rŸ   ÚassertNotIn)r8   ÚclearAuthServerÚhalfAuthServers      r&   Ú test_removePasswordIfUnencryptedz7SSHUserAuthServerTests.test_removePasswordIfUnencryptedÒ  sÐ   € ð
 	�‰�k 4§?¡?×#KÑ#KÔLä"×4Ñ4Ó6ˆÜ$1°$·+±+Ó$>ˆÔ!Ù0?ˆ×!Ñ!Ô-Ø×&Ñ&Ô(Ø×&Ñ&Ô(Ø×Ñ˜ o×&NÑ&NÔOä!×3Ñ3Ó5ˆÜ#0°·±Ó#=ˆÔ Ù/Bˆ× Ñ Ô,Ø×%Ñ%Ô'Ø×%Ñ%Ô'Ø�‰�k >×#JÑ#JÕKr%   c                 ó,  — t        | j                  «      }|j                  t        «       «       t	        j
                  «       }t        |«      |_        d„ |j                  _        |j                  «        |j                  «        | j                  |j                  dg«       t	        j
                  «       }t        |«      |_        d„ |j                  _        |j                  «        |j                  «        | j                  |j                  dg«       y)zÁ
        If the L{SSHUserAuthServer} is not advertising passwords, then an
        unencrypted connection should not cause any warnings or exceptions.
        This is a white box test.
        c                  ó   — yrd   r$   r÷   s    r&   ry   zSSSHUserAuthServerTests.test_unencryptedConnectionWithoutPasswords.<locals>.<lambda>ô  rz   r%   rÄ   c                 ó   — | dk(  S rú   r$   r÷   s    r&   ry   zSSSHUserAuthServerTests.test_unencryptedConnectionWithoutPasswords.<locals>.<lambda>ü  rü   r%   N)r   r—   r˜   r‰   r   r™   rU   r   rq   rZ   rŸ   r¥   r›   )r8   rf   rÿ   r   s       r&   Ú*test_unencryptedConnectionWithoutPasswordszASSHUserAuthServerTests.test_unencryptedConnectionWithoutPasswordsç  sÚ   € ô ˜Ÿ
™
Ó#ˆØ×ÑÔ0Ó2Ô3ô #×4Ñ4Ó6ˆÜ$1°&Ó$9ˆÔ!Ù0?ˆ×!Ñ!Ô-Ø×&Ñ&Ô(Ø×&Ñ&Ô(Ø×Ñ˜×AÑAÀLÀ>ÔRô "×3Ñ3Ó5ˆÜ#0°Ó#8ˆÔ Ù/Bˆ× Ñ Ô,Ø×%Ñ%Ô'Ø×%Ñ%Ô'Ø×Ñ˜×AÑAÀLÀ>ÕRr%   c                 ó&  — t        j                  «       }t        j                  «       |_        t        | j                  «      |_        |j                  «        |j                  j                  d«       |j                  «        | j                  |j                  j                  t        j                  dt        t        j                  f«      z   t!        d«      z   t!        d«      z   fg«       | j#                  |j                  j$                  «       y)z0
        Test that the login times out.
        é°š  ó      s   you took too longr%   N)r   r™   r   r¾   r¿   rU   rf   r   rZ   rÀ   rŸ   r¥   rh   ÚMSG_DISCONNECTrË   Ú)DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLEr   Ú
assertTruerg   ©r8   ÚtimeoutAuthServers     r&   Útest_loginTimeoutz(SSHUserAuthServerTests.test_loginTimeout  sã   € ô %×6Ñ6Ó8ÐÜ"&§*¡*£,ÐÔÜ&3°D·K±KÓ&@ÐÔ#Ø×(Ñ(Ô*Ø×Ñ×'Ñ'¨Ô5Ø×(Ñ(Ô*Ø×ÑØ×'Ñ'×/Ñ/ô ×,Ñ,ØÜœY×PÑPÐRÓSñTäÐ-Ó.ñ/ô ˜“gñððô	
ð 	�‰Ð)×3Ñ3×BÑBÕCr%   c                 óž  — t        j                  «       }t        j                  «       |_        t        | j                  «      |_        |j                  «        |j                  «        |j                  j                  d«       | j                  |j                  j                  g «       | j                  |j                  j                  «       y)zN
        Test that stopping the service also stops the login timeout.
        r  N)r   r™   r   r¾   r¿   rU   rf   r   rZ   rŸ   rÀ   r¥   rh   ÚassertFalserg   r  s     r&   Útest_cancelLoginTimeoutz.SSHUserAuthServerTests.test_cancelLoginTimeout  s˜   € ô %×6Ñ6Ó8ÐÜ"&§*¡*£,ÐÔÜ&3°D·K±KÓ&@ÐÔ#Ø×(Ñ(Ô*Ø×(Ñ(Ô*Ø×Ñ×'Ñ'¨Ô5Ø×ÑÐ*×4Ñ4×<Ñ<¸bÔAØ×ÑÐ*×4Ñ4×CÑCÕDr%   c           	      óŠ  ‡ — dj                  t        d«      t        d«      t        d«      dt        d«      g«      }t        j                  «       ‰ j                  _        t        d«      D ]B  }‰ j                  j                  |«      }‰ j                  j
                  j                  d«       ŒD ˆ fd	„}j                  |«      S )
zm
        Test that the server disconnects if the client fails authentication
        too many times.
        r%   r>   r_   r°   r¤   r¼   é   r½   c                 óò   •— ‰j                  ‰j                  j                  j                  d   t        j                  dt        t        j                  f«      z   t        d«      z   t        d«      z   f«       y )Nr£   r  s   too many bad authsr%   )r¥   rš   r   rh   r	  rË   r
  r   rµ   s    €r&   r¶   z:SSHUserAuthServerTests.test_tooManyAttempts.<locals>.check1  sm   ø€ Ø×ÑØ—‘×)Ñ)×1Ñ1°"Ñ5ä×,Ñ,ØÜœY×PÑPÐRÓSñTäÐ.Ó/ñ0ô ˜“gñðõ	r%   )
r¸   r   r   r¾   rš   r¿   Úranger«   rÀ   r¬   )r8   r¹   Úir­   r¶   s   `    r&   Útest_tooManyAttemptsz+SSHUserAuthServerTests.test_tooManyAttempts&  s•   ø€ ð
 —‘œ2˜f›:¤r¨'£{´B°{³OÀUÌBÈvËJÐWÓXˆÜ $§
¡
£ˆ�‰ÔÜ�r“ò 	-ˆAØ—‘×4Ñ4°VÓ<ˆAØ�O‰O×!Ñ!×)Ñ)¨!Õ,ð	-ô
	ð �}‰}˜UÓ#Ð#r%   c                 ó  — t        d«      t        d«      z   t        d«      z   dz   t        d«      z   }t        j                  «       | j                  _        | j                  j                  |«      }|j                  | j                  «      S )zo
        If the user requests a service that we don't support, the
        authentication should fail.
        r>   r%   r°   r¤   )r   r   r¾   rš   r¿   r«   r¬   r©   rÁ   s      r&   Útest_failIfUnknownServicez0SSHUserAuthServerTests.test_failIfUnknownService?  sh   € ô
 �F“œb ›gÑ%¬¨;«Ñ7¸%Ñ?Ä"ÀVÃ*ÑLˆÜ $§
¡
£ˆ�‰ÔØ�O‰O×0Ñ0°Ó8ˆØ�}‰}˜T×.Ñ.Ó/Ð/r%   c                 ó  ‡ — d„ }‰ j                  ‰ j                  d|«       ‰ j                  ‰ j                  dd«       ˆ fd„}‰ j                  j                  ddd«      }‰ j                  |t        «      j                  |«      S )aZ  
        tryAuth() has two edge cases that are difficult to reach.

        1) an authentication method auth_* returns None instead of a Deferred.
        2) an authentication type that is defined does not have a matching
           auth_* method.

        Both these cases should return a Deferred which fails with a
        ConchError.
        c                  ó   — y rH   r$   )r¹   s    r&   ÚmockAuthz>SSHUserAuthServerTests.test_tryAuthEdgeCases.<locals>.mockAuthU  rÖ   r%   Úauth_publickeyÚauth_passwordNc                 ój   •— ‰j                   j                  dd d «      }‰j                  |t        «      S )Nr°   )rš   rÜ   rá   r   )r¨   Úd2r8   s     €r&   Ú
secondTestz@SSHUserAuthServerTests.test_tryAuthEdgeCases.<locals>.secondTest[  s.   ø€ Ø—‘×(Ñ(¨°d¸DÓAˆBØ×%Ñ% b¬*Ó5Ð5r%   rÄ   )rà   rš   rÜ   rá   r   r¬   )r8   r  r!  Úd1s   `   r&   Útest_tryAuthEdgeCasesz,SSHUserAuthServerTests.test_tryAuthEdgeCasesI  sp   ø€ ò	ð 	�
‰
�4—?‘?Ð$4°hÔ?Ø�
‰
�4—?‘? O°TÔ:ô	6ð �_‰_×$Ñ$ \°4¸Ó>ˆØ×!Ñ! "¤jÓ1×=Ñ=¸jÓIÐIr%   )r    r!   r"   r#   r   Úskipr�   r    r©   r®   rº   rÂ   rÍ   râ   rç   rì   rî   rñ   rô   r  r  r  r  r  r  r#  r$   r%   r&   r”   r”   è   s}   „ ñð €|Ø0ˆò8òò
ò
0ò$ò&0ò"$ò:1ò4$ò.0ò"0ò(0ò,Wò"Lò*Sò4Dò0Eò$ò20óJr%   r”   c                   ór   — e Zd ZdZe€dZd„ Zd„ Zd„ Zd„ Z	d„ Z
d	„ Zd
„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zd„ Zy)ÚSSHUserAuthClientTestsz&
    Tests for SSHUserAuthClient.
    Nr•   c                 óè   — t        dt        j                  «       «      | _        t        d «      | j                  _        d| j                  j                  _        | j                  j                  «        y )Nr>   rÆ   )r/   rU   r[   Ú
authClientr   rÉ   rZ   r7   s    r&   r�   zSSHUserAuthClientTests.setUpk  sL   € Ü(¨´×1FÑ1FÓ1HÓIˆŒÜ$1°$Ó$7ˆ�‰Ô!Ø.5ˆ�‰×!Ñ!Ô+Ø�‰×&Ñ&Õ(r%   c                 óF   — | j                   j                  «        d | _         y rH   )r(  rŸ   r7   s    r&   r    zSSHUserAuthClientTests.tearDownq  r¡   r%   c                 ót  — | j                  | j                  j                  d«       | j                  | j                  j                  j                  d«       | j                  | j                  j
                  j                  t        j                  t        d«      t        d«      z   t        d«      z   fg«       y)z;
        Test that client is initialized properly.
        r>   rX   r_   N)
r¥   r(  rÓ   ÚinstancerD   r   rh   r   rÌ   r   r7   s    r&   Ú	test_initz SSHUserAuthClientTests.test_initu  s†   € ð 	×Ñ˜Ÿ™×-Ñ-¨vÔ6Ø×Ñ˜Ÿ™×1Ñ1×6Ñ6¸ÔAØ×ÑØ�O‰O×%Ñ%×-Ñ-Ü×+Ñ+¬R°«Z¼"¸X»,Ñ-FÌÈGËÑ-TÐUÐVõ	
r%   c                 óÔ   ‡— dgŠˆfd„}|| j                   j                  _        | j                   j                  d«       | j	                  ‰d   | j                   j
                  «       y)z9
        Test that the client succeeds properly.
        Nc                 ó   •— | ‰d<   y )Nr   r$   )r`   r+  s    €r&   ÚstubSetServicezDSSHUserAuthClientTests.test_USERAUTH_SUCCESS.<locals>.stubSetService†  s   ø€ Ø!ˆH�QŠKr%   r%   r   )r(  r   Ú
setServiceÚssh_USERAUTH_SUCCESSr¥   r+  )r8   r/  r+  s     @r&   Útest_USERAUTH_SUCCESSz,SSHUserAuthClientTests.test_USERAUTH_SUCCESS€  sU   ø€ ð �6ˆô	"ð 0>ˆ�‰×!Ñ!Ô,Ø�‰×,Ñ,¨SÔ1Ø×Ñ˜ !™ d§o¡o×&>Ñ&>Õ?r%   c           
      óÆ  — | j                   j                  t        d«      dz   «       | j                  | j                   j                  j
                  d   t        j                  t        d«      t        d«      z   t        d«      z   dz   t        d«      z   t        t        j                  j                  t        j                  «      j                  «       «      z   f«       | j                   j                  t        d«      dz   «       t        t        j                  j                  t        j                  «      j                  «       «      }| j                  | j                   j                  j
                  d   t        j                  t        d«      t        d«      z   t        d«      z   dz   t        d«      z   |z   f«       | j                   j                  t        d«      t        t        j                  j                  t        j                  «      j                  «       «      z   «       t        | j                   j                  j                   «      t#        t        j                  f«      z   t        d«      z   t        d«      z   t        d«      z   dz   t        d«      z   |z   }t        j                  j                  t        j$                  «      }| j                  | j                   j                  j
                  d   t        j                  t        d«      t        d«      z   t        d«      z   dz   t        d«      z   |z   t        |j'                  |«      «      z   f«       y	)
zJ
        Test that the client can authenticate with a public key.
        rÄ   r¤   r£   r>   rX   s   ssh-dssrä   ó   N)r(  Ússh_USERAUTH_FAILUREr   r¥   r   rh   r   rÌ   r   r2   r3   r   r6   rN   r4   Ússh_USERAUTH_PK_OKrÉ   rË   r;   rÊ   )r8   rN   r�   rŽ   s       r&   Útest_publickeyz%SSHUserAuthClientTests.test_publickey�  sã  € ð 	�‰×,Ñ,¬R°Ó-=ÀÑ-GÔHØ×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×-Ñ-Ü�6“
Ü�X“,ñä�\Ó"ñ#ð ñô �Z“.ñ	!ô
 ”T—X‘X×(Ñ(¬×)BÑ)BÓC×HÑHÓJÓKñLðô	
ð 	�‰×,Ñ,¬R°Ó-=ÀÑ-GÔHÜ”$—(‘(×%Ñ%¤g×&?Ñ&?Ó@×EÑEÓGÓHˆØ×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×-Ñ-ä�v“JÜ˜“lñ#ä˜Ó&ñ'ð ñô ˜“nñ	%ð
 ñð
ô	
ð 	�‰×*Ñ*Üˆz‹NœR¤§¡× 3Ñ 3´G×4MÑ4MÓ N× SÑ SÓ UÓVÑVô	
ô ˆt�‰×(Ñ(×2Ñ2Ó3Ü”X×2Ñ2Ð4Ó5ñ6ä�‹jñô �‹lñô �Óñ	ð
 ñô �‹nñð ñð 	ô �h‰h×!Ñ!¤'×"<Ñ"<Ó=ˆØ×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×-Ñ-Ü�6“
Ü�X“,ñä�\Ó"ñ#ð ñô �Z“.ñ	!ð
 ñô �S—X‘X˜gÓ&Ó'ñ(ð	õ	
r%   c                 óÖ  — t        dt        j                  «       «      }t        d«      |_        d|j                  _        |j                  «        |j                  d«       g |j                  _        | j                  |j                  d«      «       | j                  |j                  j                  t        j                  t        d«      t        d«      z   t        d«      z   fg«       y)z¼
        If the SSHUserAuthClient doesn't return anything from signData,
        the client should start the authentication over again by requesting
        'none' authentication.
        r>   NrÆ   rÄ   r%   rX   r_   )rQ   rU   r[   r   rÉ   rZ   rÜ   rh   ÚassertIsNoner6  r¥   r   rÌ   r   )r8   r(  s     r&   Ú!test_publickey_without_privatekeyz8SSHUserAuthClientTests.test_publickey_without_privatekeyË  s¹   € ô 1°¼×9NÑ9NÓ9PÓQˆ
ä,¨TÓ2ˆ
ÔØ)0ˆ
×ÑÔ&Ø×!Ñ!Ô#Ø×Ñ˜<Ô(Ø')ˆ
×ÑÔ$Ø×Ñ˜*×7Ñ7¸Ó<Ô=Ø×ÑØ× Ñ ×(Ñ(Ü×+Ñ+¬R°«Z¼"¸X»,Ñ-FÌÈGËÑ-TÐUÐVõ	
r%   c                 óŠ   ‡ — d„ ‰ j                   _        ‰ j                   j                  d«      }ˆ fd„}|j                  |«      S )z{
        If there's no public key, auth_publickey should return a Deferred
        called back with a False value.
        c                  ó   — y rH   r$   r÷   s    r&   ry   z:SSHUserAuthClientTests.test_no_publickey.<locals>.<lambda>ã  rz   r%   rÄ   c                 ó(   •— ‰j                  | «       y rH   )r  )Úresultr8   s    €r&   r¶   z7SSHUserAuthClientTests.test_no_publickey.<locals>.checkæ  s   ø€ Ø×Ñ˜VÕ$r%   )r(  r9   rÜ   r¬   )r8   r­   r¶   s   `  r&   Útest_no_publickeyz(SSHUserAuthClientTests.test_no_publickeyÞ  s;   ø€ ñ
 (6ˆ�‰Ô$Ø�O‰O×#Ñ# LÓ1ˆô	%ð �}‰}˜UÓ#Ð#r%   c                 ó„  — | j                   j                  t        d«      dz   «       | j                  | j                   j                  j
                  d   t        j                  t        d«      t        d«      z   t        d«      z   dz   t        d«      z   f«       | j                   j                  t        d«      t        d«      z   «       | j                  | j                   j                  j
                  d   t        j                  t        d«      t        d«      z   t        d«      z   dz   t        d«      dz  z   f«       y	)
zx
        Test that the client can authentication with a password.  This
        includes changing the password.
        r°   r¤   r£   r>   rX   r%   rÅ   r½   N)	r(  r5  r   r¥   r   rh   r   rÌ   r6  r7   s    r&   Útest_passwordz$SSHUserAuthClientTests.test_passwordë  sû   € ð
 	�‰×,Ñ,¬R°«_¸wÑ-FÔGØ×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×-Ñ-Ü�6“
œR ›\Ñ)¬B¨{«OÑ;¸gÑEÌÈ6Ë
ÑRðô	
ð 	�‰×*Ñ*¬2¨c«7´R¸³WÑ+<Ô=Ø×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×-Ñ-Ü�6“
œR ›\Ñ)¬B¨{«OÑ;¸gÑEÌÈ6Ë
ÐUVÉÑVðõ	
r%   c                 ó|   — d„ | j                   _        | j                  | j                   j                  d«      «       y)zK
        If getPassword returns None, tryAuth should return False.
        c                   ó   — y rH   r$   r$   r%   r&   ry   z9SSHUserAuthClientTests.test_no_password.<locals>.<lambda>  rz   r%   r°   N)r(  rA   r  rÜ   r7   s    r&   Útest_no_passwordz'SSHUserAuthClientTests.test_no_password  s-   € ñ '3ˆ�‰Ô#Ø×Ñ˜Ÿ™×0Ñ0°Ó=Õ>r%   c                 óV  — | j                   j                  t        d«      t        d«      z   t        d«      z   dz   t        d«      z   dz   «       | j                  | j                   j                  j
                  d   t        j                  dt        d«      z   t        d«      z   f«       y)	zj
        Make sure that the client can authenticate with the keyboard
        interactive method.
        r%   s      s
   Password: r¤   r£   s      r>   N)r(  Ú'ssh_USERAUTH_PK_OK_keyboard_interactiver   r¥   r   rh   r   ÚMSG_USERAUTH_INFO_RESPONSEr7   s    r&   Útest_keyboardInteractivez/SSHUserAuthClientTests.test_keyboardInteractive  s£   € ð
 	�‰×?Ñ?Üˆs‹GÜ�‹gñä�‹gñð "ñ"ô �Óñ	 ð
 ñô	
ð 	×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×3Ñ3Ø#¤b¨£jÑ0´2°f³:Ñ=ðõ	
r%   c                 óV  — d| j                   _        g | j                   j                  _        | j                   j	                  d«       | j                  | j                   j                  j                  t        j                  t        d«      t        d«      z   t        d«      z   fg«       y)z¾
        If C{SSHUserAuthClient} gets a MSG_USERAUTH_PK_OK packet when it's not
        expecting it, it should fail the current authentication and move on to
        the next type.
        s   unknownr%   r>   rX   r_   N)	r(  ÚlastAuthr   rh   r6  r¥   r   rÌ   r   r7   s    r&   Ú"test_USERAUTH_PK_OK_unknown_methodz9SSHUserAuthClientTests.test_USERAUTH_PK_OK_unknown_method  s|   € ð $.ˆ�‰Ô Ø,.ˆ�‰×!Ñ!Ô)Ø�‰×*Ñ*¨3Ô/Ø×ÑØ�O‰O×%Ñ%×-Ñ-Ü×+Ñ+¬R°«Z¼"¸X»,Ñ-FÌÈGËÑ-TÐUÐVõ	
r%   c                 óJ  ‡ — ˆ fd„}ˆ fd„}|‰ j                   _        |‰ j                   _        ‰ j                   j                  t	        d«      dz   «       ‰ j                  ‰ j                   j                  j                  d   t        j                  t	        d«      t	        d«      z   t	        d«      z   dz   t	        d«      z   f«       ‰ j                   j                  t	        d	«      d
z   «       ‰ j                  ‰ j                   j                  j                  dd ddg«       y)z×
        ssh_USERAUTH_FAILURE should sort the methods by their position
        in SSHUserAuthClient.preferredOrder.  Methods that are not in
        preferredOrder should be sorted at the end of that list.
        c                  óR   •— ‰ j                   j                  j                  dd«       y )Néÿ   ó   here is data©r(  r   rn   r7   s   €r&   Úauth_firstmethodzNSSHUserAuthClientTests.test_USERAUTH_FAILURE_sorting.<locals>.auth_firstmethod2  s   ø€ Ø�O‰O×%Ñ%×0Ñ0°°oÕFr%   c                  óR   •— ‰ j                   j                  j                  dd«       y)Néþ   ó
   other dataTrP  r7   s   €r&   Úauth_anothermethodzPSSHUserAuthClientTests.test_USERAUTH_FAILURE_sorting.<locals>.auth_anothermethod5  s    ø€ Ø�O‰O×%Ñ%×0Ñ0°°mÔDØr%   s   anothermethod,passwordr¤   r£   r>   rX   r°   s"   firstmethod,anothermethod,passwordrÅ   éþÿÿÿN)rN  rO  )rS  rT  )
r(  rQ  rU  r5  r   r¥   r   rh   r   rÌ   )r8   rQ  rU  s   `  r&   Útest_USERAUTH_FAILURE_sortingz4SSHUserAuthClientTests.test_USERAUTH_FAILURE_sorting+  s÷   ø€ ô	Gô	ð ,<ˆ�‰Ô(Ø-?ˆ�‰Ô*ð 	�‰×,Ñ,¬RÐ0IÓ-JÈWÑ-TÔUà×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×-Ñ-Ü�6“
œR ›\Ñ)¬B¨{«OÑ;¸gÑEÌÈ6Ë
ÑRðô	
ð 	�‰×,Ñ,ÜÐ4Ó5¸Ñ?ô	
ð 	×ÑØ�O‰O×%Ñ%×-Ñ-¨b¨cÐ2Ø#Ð%9Ð:õ	
r%   c                 óD  — | j                   j                  t        d«      dz   «       | j                   j                  t        d«      dz   «       | j                  | j                   j                  j
                  d   t        j                  dt        d«      z   dz   f«       y)	z»
        If there are no more available user authentication messages,
        the SSHUserAuthClient should disconnect with code
        DISCONNECT_NO_MORE_AUTH_METHODS_AVAILABLE.
        r°   r¤   rÅ   r£   s      s(   no more authentication methods availables       N)r(  r5  r   r¥   r   rh   r	  r7   s    r&   Ú%test_disconnectIfNoMoreAuthenticationz<SSHUserAuthClientTests.test_disconnectIfNoMoreAuthenticationO  sˆ   € ð 	�‰×,Ñ,¬R°«_¸wÑ-FÔGØ�‰×,Ñ,¬R°«_¸wÑ-FÔGØ×ÑØ�O‰O×%Ñ%×-Ñ-¨bÑ1ä×(Ñ(Ø#ÜÐ@ÓAñBà%ñ&ðõ	
r%   c                 ó4  — g | j                   j                  _        | j                   j                  d«       | j	                  | j                   j                  j                  t
        j                  t        d«      t        d«      z   t        d«      z   fg«       y)zˆ
        _ebAuth (the generic authentication error handler) should send
        a request for the 'none' authentication method.
        Nr>   rX   r_   )r(  r   rh   Ú_ebAuthr¥   r   rÌ   r   r7   s    r&   Útest_ebAuthz"SSHUserAuthClientTests.test_ebAutha  sp   € ð
 -/ˆ�‰×!Ñ!Ô)Ø�‰×Ñ Ô%Ø×ÑØ�O‰O×%Ñ%×-Ñ-Ü×+Ñ+¬R°«Z¼"¸X»,Ñ-FÌÈGËÑ-TÐUÐVõ	
r%   c                 ó.  ‡ ‡‡‡— t        j                  dt        j                  «       «      Š‰ j	                  ‰j                  «       «       ˆˆˆ fd„}ˆˆˆ fd„Šd„ Š‰j                  «       }|j                  ‰ j                  «      j                  |«      S )zÛ
        getPublicKey() should return None.  getPrivateKey() should return a
        failed Deferred.  getPassword() should return a failed Deferred.
        getGenericAnswers() should return a failed Deferred.
        r>   c                 ó¢   •— | j                  t        «       ‰j                  «       }|j                  ‰j                  «      j                  ‰«      S rH   )ÚtrapÚNotImplementedErrorrA   r¬   r„   Ú
addErrback)r>  r­   r(  Úcheck2r8   s     €€€r&   r¶   z3SSHUserAuthClientTests.test_defaults.<locals>.checkv  s<   ø€ Ø�K‰KÔ+Ô,Ø×&Ñ&Ó(ˆAØ—=‘= §¡Ó+×6Ñ6°vÓ>Ð>r%   c                 ó¨   •— | j                  t        «       ‰j                  d d d «      }|j                  ‰j                  «      j                  ‰«      S rH   )r_  r`  rG   r¬   r„   ra  )r>  r­   r(  Úcheck3r8   s     €€€r&   rb  z4SSHUserAuthClientTests.test_defaults.<locals>.check2{  sB   ø€ Ø�K‰KÔ+Ô,Ø×,Ñ,¨T°4¸Ó>ˆAØ—=‘= §¡Ó+×6Ñ6°vÓ>Ð>r%   c                 ó.   — | j                  t        «       y rH   )r_  r`  )r>  s    r&   rd  z4SSHUserAuthClientTests.test_defaults.<locals>.check3€  s   € Ø�K‰KÔ+Õ,r%   )
r   r-   rU   r[   r9  r9   r<   r¬   r„   ra  )r8   r¶   r­   r(  rb  rd  s   `  @@@r&   Útest_defaultsz$SSHUserAuthClientTests.test_defaultsm  st   û€ ô ×/Ñ/°¼×8MÑ8MÓ8OÓPˆ
Ø×Ñ˜*×1Ñ1Ó3Ô4ö	?ö
	?ò
	-ð ×$Ñ$Ó&ˆØ�}‰}˜TŸY™YÓ'×2Ñ2°5Ó9Ð9r%   )r    r!   r"   r#   r   r$  r�   r    r,  r2  r7  r:  r?  rA  rD  rH  rK  rW  rY  r\  rf  r$   r%   r&   r&  r&  c  sa   „ ñð €|Ø0ˆò)òò	
ò@ò<
ò|
ò&$ò
ò,?ò
ò*
ò"
òH
ò$

ó:r%   r&  c                   ó.   — e Zd Ze€dZ G d„ d«      Zd„ Zy)ÚLoopbackTestsNr•   c                   ó&   — e Zd Z G d„ d«      Zd„ Zy)úLoopbackTests.Factoryc                   ó   — e Zd ZdZd„ Zd„ Zy)úLoopbackTests.Factory.Serviceó   TestServicec                 ó8   — | j                   j                  «        y rH   )r   rt   r7   s    r&   rZ   z,LoopbackTests.Factory.Service.serviceStarted�  s   € Ø—‘×-Ñ-Õ/r%   c                  ó   — y rH   r$   r7   s    r&   rŸ   z,LoopbackTests.Factory.Service.serviceStopped’  s   € Ør%   N)r    r!   r"   rD   rZ   rŸ   r$   r%   r&   r[   rl  Œ  s   „ Ø!ˆDò0ór%   r[   c                 ó   — | j                   S rH   )r[   )r8   ÚavatarrD   s      r&   ra   z LoopbackTests.Factory.getService•  s   € Ø—<‘<Ðr%   N)r    r!   r"   r[   ra   r$   r%   r&   rb   rj  ‹  s   „ ÷	ñ 	ó	 r%   rb   c                 óZ  ‡ ‡‡— t        j                  «       Št        d‰ j                  j	                  «       «      }t        j                  «       ‰_        ‰‰j
                  _        d„ ‰j
                  _        t        j                  «       |_        ||j
                  _        dx‰j
                  _	        |j
                  _	        d„ x‰j
                  _
        |j
                  _
        ‰ j                  «       ‰j
                  _        d‰_        t        «       }t        |«      }t        «       Š‰j!                  t#        «       «       ‰j!                  t%        «       «       ˆfd„‰_        |j!                  ‰«       |‰j
                  j                  _        t+        j,                  ‰j
                  |j
                  «      }d„ ‰j
                  j
                  _        d„ |j
                  j
                  _        ‰j1                  «        |j1                  «        ˆ ˆfd	„}|j3                  |«      S )
zW
        Test that the userauth server and client play nicely with each other.
        r>   c                  ó   — yrs   r$   r÷   s    r&   ry   z-LoopbackTests.test_loopback.<locals>.<lambda>¢  rz   r%   r%   c                   ó   — y rH   r$   r$   r%   r&   ry   z-LoopbackTests.test_loopback.<locals>.<lambda>§  rz   r%   r   c                 ó:   •— t        ‰j                  |    «      dk(  S )Nr½   )ÚlenÚsuccessfulCredentials)ÚaIdÚcheckers    €r&   ry   z-LoopbackTests.test_loopback.<locals>.<lambda>±  s   ø€ ¤s¨7×+HÑ+HÈÑ+MÓ'NÐRSÑ'S€ r%   c                   ó   — y)NÚ_ServerLoopbackr$   r$   r%   r&   ry   z-LoopbackTests.test_loopback.<locals>.<lambda>¶  rz   r%   c                   ó   — y)NÚ_ClientLoopbackr$   r$   r%   r&   ry   z-LoopbackTests.test_loopback.<locals>.<lambda>·  rz   r%   c                 óf   •— ‰j                  ‰j                  j                  j                  d«       y )Nrm  )r¥   r   r`   rD   )r¨   r8   ró   s    €€r&   r¶   z*LoopbackTests.test_loopback.<locals>.check¼  s%   ø€ Ø×Ñ˜V×-Ñ-×5Ñ5×:Ñ:¸NÕKr%   )r   r™   r/   rb   r[   r   r'   r`   rq   rÉ   ÚsendKexInitre   ÚpasswordDelayrv   r   r   r˜   r€   r‰   ÚareDonerf   r   ÚloopbackAsyncÚ	logPrefixrZ   r¬   )r8   Úclientr—   rf   r­   r¶   ry  ró   s   `     @@r&   Útest_loopbackzLoopbackTests.test_loopback˜  s©  ú€ ô ×+Ñ+Ó-ˆÜ ¨¯©×(<Ñ(<Ó(>Ó?ˆô %×5Ñ5Ó7ˆÔØ#)ˆ×ÑÔ Ù'5ˆ×ÑÔ$Ü$×5Ñ5Ó7ˆÔØ#)ˆ×ÑÔ ØBEÐEˆ×ÑÔ" V×%5Ñ%5Ô%?áFRÐRˆ×ÑÔ$ v×'7Ñ'7Ô'Cð $(§<¡<£>ˆ×ÑÔ Ø ˆÔÜ“ˆÜ˜“ˆÜ$Ó&ˆØ×Ñ¤Ó 1Ô2Ø×ÑÔ 1Ó 3Ô4ÛTˆŒØ×Ñ˜wÔ'Ø*0ˆ×Ñ× Ñ Ô'ä×"Ñ" 6×#3Ñ#3°V×5EÑ5EÓFˆÙ/Hˆ×Ñ×"Ñ"Ô,Ù/Hˆ×Ñ×"Ñ"Ô,à×ÑÔØ×ÑÔõ	Lð �}‰}˜UÓ#Ð#r%   )r    r!   r"   r   r$  rb   r…  r$   r%   r&   rh  rh  ‡  s   „ Ø€|Ø0ˆ÷ ñ  ó'$r%   rh  c                   ó   — e Zd Ze€dZd„ Zy)ÚModuleInitializationTestsNr•   c                 ó¸   — | j                  t        j                  j                  d   d«       | j                  t        j                  j                  d   d«       y )Né<   ræ   )r¥   r   r™   ÚprotocolMessagesr-   r7   s    r&   Útest_messagesz'ModuleInitializationTests.test_messagesÆ  sP   € ð 	×ÑÜ×&Ñ&×7Ñ7¸Ñ;Ð=Qô	
ð 	×ÑÜ×&Ñ&×7Ñ7¸Ñ;Ð=Qõ	
r%   )r    r!   r"   r   r$  r‹  r$   r%   r&   r‡  r‡  Â  s   „ Ø€|Ø0ˆó
r%   r‡  )8r#   Útypesr   Útypingr   Úzope.interfacer   Útwisted.conch.errorr   r   Útwisted.cred.checkersr   Útwisted.cred.credentialsr	   r
   r   Útwisted.cred.errorr   Útwisted.cred.portalr   r   Útwisted.internetr   r   Útwisted.protocolsr   Útwisted.python.reflectr   Útwisted.trialr   r   Ú__annotations__Útwisted.conch.checkersr   Útwisted.conch.sshr   r   Útwisted.conch.ssh.commonr   Útwisted.conch.testr   r-   r/   rJ   rQ   r'   rU   rv   r€   r‰   r�   ÚTestCaser”   r&  rh  r‡  r$   r%   r&   ú<module>rž     s‹  ðòõ Ý å &ç :Ý 5ß RÑ RÝ 0ß .ß (Ý &Ý 0Ý "à!€€hˆzÑÓ !Ù�Ô Ý9ß;Ñ;Ý+Þ*÷ñ ÷ñ ô -�X×/Ñ/ô  -ôF
E�H×.Ñ.ô 
Eô	> (×"<Ñ"<ô 	>ô>#�I×.Ñ.ô >#ñB ˆVÓ÷	Bð 	Bó ð	Bñ Ð Ó!÷Oð Oó "ðOñ Ð Ó!÷"ð "ó "ð"ñ& Ð Ó!÷	ð 	ó "ð	ôxJ˜X×.Ñ.ô xJôva:˜X×.Ñ.ô a:ôH	8$�H×%Ñ%ô 8$ôv
 × 1Ñ 1õ 
r%   