HEX
Server: Apache
System: Linux scp1.abinfocom.com 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64
User: confeduphaar (1010)
PHP: 8.1.33
Disabled: exec,passthru,shell_exec,system
Upload Files
File: //usr/lib/python3/dist-packages/twisted/conch/client/__pycache__/knownhosts.cpython-38.pyc
U

s�@g�M�@sfdZddlmZmZddlZddlmZmZm	Z	ddl
mZddlm
Z
ddlZddlmZddlmZdd	lmZmZmZdd
lmZmZmZddlmZddlmZdd
lm Z m!Z!ddl"m#Z#ddl$m%Z%dd�Z&dd�Z'Gdd�de(�Z)ee�Gdd�de)��Z*ee�Gdd�de(��Z+dd�Z,ee�Gdd�de)e%��Z-Gdd�de(�Z.Gd d!�d!e(�Z/dS)"zE
An implementation of the OpenSSH known_hosts database.

@since: 8.2
�)�absolute_import�divisionN)�Error�
b2a_base64�
a2b_base64)�closing)�sha1)�implementer)�IKnownHostEntry)�HostKeyChanged�UserRejectedKey�InvalidEntry)�Key�BadKeyError�FingerprintFormats)�defer)�log)�nativeString�unicode)�secureRandom)�FancyEqMixincCst|���S)z�
    Encode a binary string as base64 with no trailing newline.

    @param s: The string to encode.
    @type s: L{bytes}

    @return: The base64-encoded string.
    @rtype: L{bytes}
    )r�strip)�s�r�A/usr/lib/python3/dist-packages/twisted/conch/client/knownhosts.py�
_b64encodes
rc	Csz|�dd�}t|�dkrt��|\}}}|�dd�}t|�dkrT|\}}|�d�}n|d}d}t�t|��}||||fS)a�
    Extract common elements of base64 keys from an entry in a hosts file.

    @param string: A known hosts file entry (a single line).
    @type string: L{bytes}

    @return: a 4-tuple of hostname data (L{bytes}), ssh key type (L{bytes}), key
        (L{Key}), and comment (L{bytes} or L{None}).  The hostname data is
        simply the beginning of the line up to the first occurrence of
        whitespace.
    @rtype: L{tuple}
    N����
r)�split�lenr
�rstripr�
fromStringr)	�string�elements�	hostnames�keyTypeZ
keyAndCommentZsplitkeyZ	keyString�comment�keyrrr�_extractCommon-s

r*c@s eZdZdZdd�Zdd�ZdS)�
_BaseEntrya�
    Abstract base of both hashed and non-hashed entry objects, since they
    represent keys and key types the same way.

    @ivar keyType: The type of the key; either ssh-dss or ssh-rsa.
    @type keyType: L{bytes}

    @ivar publicKey: The server public key indicated by this line.
    @type publicKey: L{twisted.conch.ssh.keys.Key}

    @ivar comment: Trailing garbage after the key line.
    @type comment: L{bytes}
    cCs||_||_||_dS�N)r'�	publicKeyr()�selfr'r-r(rrr�__init__Ysz_BaseEntry.__init__cCs
|j|kS)a
        Check to see if this entry matches a given key object.

        @param keyObject: A public key object to check.
        @type keyObject: L{Key}

        @return: C{True} if this entry's key matches C{keyObject}, C{False}
            otherwise.
        @rtype: L{bool}
        )r-)r.Z	keyObjectrrr�
matchesKey_sz_BaseEntry.matchesKeyN)�__name__�
__module__�__qualname__�__doc__r/r0rrrrr+Jsr+cs<eZdZdZ�fdd�Zedd��Zdd�Zdd	�Z�Z	S)
�
PlainEntryz�
    A L{PlainEntry} is a representation of a plain-text entry in a known_hosts
    file.

    @ivar _hostnames: the list of all host-names associated with this entry.
    @type _hostnames: L{list} of L{bytes}
    cs||_tt|��|||�dSr,)�
_hostnames�superr5r/)r.r&r'r-r(��	__class__rrr/xszPlainEntry.__init__cCs(t|�\}}}}||�d�|||�}|S)a�
        Parse a plain-text entry in a known_hosts file, and return a
        corresponding L{PlainEntry}.

        @param string: a space-separated string formatted like "hostname
        key-type base64-key-data comment".

        @type string: L{bytes}

        @raise DecodeError: if the key is not valid encoded as valid base64.

        @raise InvalidEntry: if the entry does not have the right number of
        elements and is therefore invalid.

        @raise BadKeyError: if the key, once decoded from base64, is not
        actually an SSH key.

        @return: an IKnownHostEntry representing the hostname and key in the
        input line.

        @rtype: L{PlainEntry}
        �,)r*r )�clsr$r&r'r)r(r.rrrr#}szPlainEntry.fromStringcCst|t�r|�d�}||jkS)aT
        Check to see if this entry matches a given hostname.

        @param hostname: A hostname or IP address literal to check against this
            entry.
        @type hostname: L{bytes}

        @return: C{True} if this entry is for the given hostname or IP address,
            C{False} otherwise.
        @rtype: L{bool}
        �utf-8)�
isinstancer�encoder6�r.�hostnamerrr�matchesHost�s

zPlainEntry.matchesHostcCs>d�|j�|jt|j���g}|jdk	r4|�|j�d�|�S)a
        Implement L{IKnownHostEntry.toString} by recording the comma-separated
        hostnames, key type, and base-64 encoded key.

        @return: The string representation of this entry, with unhashed hostname
            information.
        @rtype: L{bytes}
        r:N� )�joinr6r'rr-�blobr(�append�r.Zfieldsrrr�toString�s	
�
zPlainEntry.toString)
r1r2r3r4r/�classmethodr#rArG�
__classcell__rrr8rr5ns
r5c@s0eZdZdZdd�Zdd�Zdd�Zdd	�Zd
S)�
UnparsedEntryz�
    L{UnparsedEntry} is an entry in a L{KnownHostsFile} which can't actually be
    parsed; therefore it matches no keys and no hosts.
    cCs
||_dS)zv
        Create an unparsed entry from a line in a known_hosts file which cannot
        otherwise be parsed.
        N)�_string)r.r$rrrr/�szUnparsedEntry.__init__cCsdS�z'
        Always returns False.
        Frr?rrrrA�szUnparsedEntry.matchesHostcCsdSrLr)r.r)rrrr0�szUnparsedEntry.matchesKeycCs|j�d�S)a
        Returns the input line, without its newline if one was given.

        @return: The string representation of this entry, almost exactly as was
            used to initialize this entry but without a trailing newline.
        @rtype: L{bytes}
        r)rKr"�r.rrrrG�szUnparsedEntry.toStringN)r1r2r3r4r/rAr0rGrrrrrJ�s
rJcCs4tj|td�}t|t�r"|�d�}|�|�|��S)z�
    Return the SHA-1 HMAC hash of the given key and string.

    @param key: The HMAC key.
    @type key: L{bytes}

    @param string: The string to be hashed.
    @type string: L{bytes}

    @return: The keyed hash value.
    @rtype: L{bytes}
    )Z	digestmodr<)�hmacZHMACrr=rr>�updateZdigest)r)r$�hashrrr�
_hmacedString�s




rQcsDeZdZdZdZdZ�fdd�Zedd��Zdd	�Z	d
d�Z
�ZS)�HashedEntrya�
    A L{HashedEntry} is a representation of an entry in a known_hosts file
    where the hostname has been hashed and salted.

    @ivar _hostSalt: the salt to combine with a hostname for hashing.

    @ivar _hostHash: the hashed representation of the hostname.

    @cvar MAGIC: the 'hash magic' string used to identify a hashed line in a
    known_hosts file as opposed to a plaintext one.
    s|1|)�	_hostSalt�	_hostHashr'r-r(cs$||_||_tt|��|||�dSr,)rSrTr7rRr/)r.�hostSalt�hostHashr'r-r(r8rrr/szHashedEntry.__init__c
Cs^t|�\}}}}|t|j�d��d�}t|�dkr:t��|\}}|t|�t|�|||�}	|	S)a#
        Load a hashed entry from a string representing a line in a known_hosts
        file.

        @param string: A complete single line from a I{known_hosts} file,
            formatted as defined by OpenSSH.
        @type string: L{bytes}

        @raise DecodeError: if the key, the hostname, or the is not valid
            encoded as valid base64

        @raise InvalidEntry: if the entry does not have the right number of
            elements and is therefore invalid, or the host/hash portion contains
            more items than just the host and hash.

        @raise BadKeyError: if the key, once decoded from base64, is not
            actually an SSH key.

        @return: The newly created L{HashedEntry} instance, initialized with the
            information from C{string}.
        N�|r)r*r!�MAGICr r
r)
r;r$Zstuffr'r)r(ZsaltAndHashrUrVr.rrrr#s�zHashedEntry.fromStringcCst|j|�|jkS)a�
        Implement L{IKnownHostEntry.matchesHost} to compare the hash of the
        input to the stored hash.

        @param hostname: A hostname or IP address literal to check against this
            entry.
        @type hostname: L{bytes}

        @return: C{True} if this entry is for the given hostname or IP address,
            C{False} otherwise.
        @rtype: L{bool}
        )rQrSrTr?rrrrA5s
zHashedEntry.matchesHostcCsR|jd�t|j�t|j�g�|jt|j���g}|jdk	rH|�	|j�d�|�S)z�
        Implement L{IKnownHostEntry.toString} by base64-encoding the salt, host
        hash, and key.

        @return: The string representation of this entry, with the hostname part
            hashed.
        @rtype: L{bytes}
        rWNrB)
rXrCrrSrTr'r-rDr(rErFrrrrGEs	��
zHashedEntry.toString)r1r2r3r4rXZcompareAttributesr/rHr#rArGrIrrr8rrR�s
 rRc@sXeZdZdZdd�Zedd��Zdd�Zdd	�Zd
d�Z	dd
�Z
dd�Zedd��Z
dS)�KnownHostsFileaz
    A structured representation of an OpenSSH-format ~/.ssh/known_hosts file.

    @ivar _added: A list of L{IKnownHostEntry} providers which have been added
        to this instance in memory but not yet saved.

    @ivar _clobber: A flag indicating whether the current contents of the save
        path will be disregarded and potentially overwritten or not.  If
        C{True}, this will be done.  If C{False}, entries in the save path will
        be read and new entries will be saved by appending rather than
        overwriting.
    @type _clobber: L{bool}

    @ivar _savePath: See C{savePath} parameter of L{__init__}.
    cCsg|_||_d|_dS)a$
        Create a new, empty KnownHostsFile.

        Unless you want to erase the current contents of C{savePath}, you want
        to use L{KnownHostsFile.fromPath} instead.

        @param savePath: The L{FilePath} to which to save new entries.
        @type savePath: L{FilePath}
        TN)�_added�	_savePath�_clobber)r.�savePathrrrr/is
zKnownHostsFile.__init__cCs|jS)z<
        @see: C{savePath} parameter of L{__init__}
        )r[rMrrrr]xszKnownHostsFile.savePathccs�|jD]
}|Vq|jrdSz|j��}Wntk
r@YdSX|�`|D]T}z&|�tj�rjt�|�}n
t	�|�}Wn"t
ttfk
r�t
|�}YnX|VqLW5QRXdS)aK
        Iterate over the host entries in this file.

        @return: An iterable the elements of which provide L{IKnownHostEntry}.
            There is an element for each entry in the file as well as an element
            for each added but not yet saved entry.
        @rtype: iterable of L{IKnownHostEntry} providers
        N)rZr\r[�open�IOError�
startswithrRrXr#r5�DecodeErrorr
rrJ)r.�entry�fp�linerrr�iterentries�s"	
zKnownHostsFile.iterentriescCsxt|��t|j��D]\\}}|�|�r|j|��kr|�|�rFdS|dkrXd}d}n|d}|j}t	|||��qdS)a
        Check for an entry with matching hostname and key.

        @param hostname: A hostname or IP address literal to check for.
        @type hostname: L{bytes}

        @param key: The public key to check for.
        @type key: L{Key}

        @return: C{True} if the given hostname and key are present in this file,
            C{False} if they are not.
        @rtype: L{bool}

        @raise HostKeyChanged: if the host key found for the given hostname
            does not match the given key.
        TrNrF)
�	enumeraterer!rZrAr'�sshTyper0r[r)r.r@r)Zlineidxrbrd�pathrrr�
hasHostKey�s
zKnownHostsFile.hasHostKeycs.t��j���}�����fdd�}|�|�S)a�
        Verify the given host key for the given IP and host, asking for
        confirmation from, and notifying, the given UI about changes to this
        file.

        @param ui: The user interface to request an IP address from.

        @param hostname: The hostname that the user requested to connect to.

        @param ip: The string representation of the IP address that is actually
        being connected to.

        @param key: The public key of the server.

        @return: a L{Deferred} that fires with True when the key has been
            verified, or fires with an errback when the key either cannot be
            verified or has changed.
        @rtype: L{Deferred}
        cs�|rB�����s>��d���t��f���������|S����fdd�}���}|dkrhd}dt��t��|�jtjd�f}��	|�
t����}|�
|�SdS)NzZWarning: Permanently added the %s host key for IP address '%s' to the list of known hosts.cs2|r(�������������|St��dSr,)�
addHostKey�saver)Zresponse)r@�ipr)r.rr�promptResponse�szGKnownHostsFile.verifyHostKey.<locals>.gotHasKey.<locals>.promptResponseZECZECDSAz�The authenticity of host '%s (%s)' can't be established.
%s key fingerprint is SHA256:%s.
Are you sure you want to continue connecting (yes/no)? )�format)ri�warn�typerrjrkZfingerprintrZ
SHA256_BASE64�promptr>�sys�getdefaultencoding�addCallback)�resultrmZkeytyperqZproceed�r@rlr)r.�uirr�	gotHasKey�s(�	���z/KnownHostsFile.verifyHostKey.<locals>.gotHasKey)rZ
maybeDeferredrirt)r.rwr@rlr)Zhhkrxrrvr�
verifyHostKey�s!zKnownHostsFile.verifyHostKeycCs6td�}|��}t|t||�||d�}|j�|�|S)a�
        Add a new L{HashedEntry} to the key database.

        Note that you still need to call L{KnownHostsFile.save} if you wish
        these changes to be persisted.

        @param hostname: A hostname or IP address literal to associate with the
            new entry.
        @type hostname: L{bytes}

        @param key: The public key to associate with the new entry.
        @type key: L{Key}

        @return: The L{HashedEntry} that was added.
        @rtype: L{HashedEntry}
        �N)rrgrRrQrZrE)r.r@r)Zsaltr'rbrrrrj�s�zKnownHostsFile.addHostKeyc	Csx|j��}|��s|��|jr&d}nd}|j�|��2}|jrd|�d�dd�|jD��d�g|_W5QRXd|_dS)zM
        Save this L{KnownHostsFile} to the path it was loaded from.
        �wbZabrcSsg|]}|���qSr)rG)�.0rbrrr�
<listcomp>$sz'KnownHostsFile.save.<locals>.<listcomp>FN)	r[�parent�isdir�makedirsr\r^rZ�writerC)r.�p�modeZhostsFileObjrrrrks
��zKnownHostsFile.savecCs||�}d|_|S)a�
        Create a new L{KnownHostsFile}, potentially reading existing known
        hosts information from the given file.

        @param path: A path object to use for both reading contents from and
            later saving to.  If no file exists at this path, it is not an
            error; a L{KnownHostsFile} with no entries is returned.
        @type path: L{FilePath}

        @return: A L{KnownHostsFile} initialized with entries from C{path}.
        @rtype: L{KnownHostsFile}
        F)r\)r;rhZ
knownHostsrrr�fromPath*szKnownHostsFile.fromPathN)r1r2r3r4r/�propertyr]reriryrjrkrHr�rrrrrYXs
 "9rYc@s(eZdZdZdd�Zdd�Zdd�ZdS)	�	ConsoleUIz�
    A UI object that can ask true/false questions and post notifications on the
    console, to be used during key verification.
    cCs
||_dS)aA
        @param opener: A no-argument callable which should open a console
            binary-mode file-like object to be used for reading and writing.
            This initializes the C{opener} attribute.
        @type opener: callable taking no arguments and returning a read/write
            file-like object
        N)�opener)r.r�rrrr/CszConsoleUI.__init__cs"t�d�}��fdd�}|�|�S)a�
        Write the given text as a prompt to the console output, then read a
        result from the console input.

        @param text: Something to present to a user to solicit a yes or no
            response.
        @type text: L{bytes}

        @return: a L{Deferred} which fires with L{True} when the user answers
            'yes' and L{False} when the user answers 'no'.  It may errback if
            there were any I/O errors.
        Nc	snt�����X}|���|������}|dkr>W5QR�dS|dkrTW5QR�dS|�d�qW5QRXdS)NsyesTsnoFsPlease type 'yes' or 'no': )rr�r��readliner�lower)Zignored�fZanswer�r.�textrr�body\s
zConsoleUI.prompt.<locals>.body)rZsucceedrt)r.r��dr�rr�rrqNs
zConsoleUI.promptc	Cs@z&t|����}|�|�W5QRXWnt��YnXdS)z�
        Notify the user (non-interactively) of the provided text, by writing it
        to the console.

        @param text: Some information the user is to be made aware of.
        @type text: L{bytes}
        N)rr�r�r�err)r.r�r�rrrrojs
zConsoleUI.warnN)r1r2r3r4r/rqrorrrrr�>sr�)0r4Z
__future__rrrNZbinasciirrarr�
contextlibrZhashlibrrrZzope.interfacer	Ztwisted.conch.interfacesr
Ztwisted.conch.errorrrr
Ztwisted.conch.ssh.keysrrrZtwisted.internetrZtwisted.pythonrZtwisted.python.compatrrZtwisted.python.randbytesrZtwisted.python.utilrrr*�objectr+r5rJrQrRrYr�rrrr�<module>s8$N(\g