§
    ¥”jÚ*  ã            	       óø   — d dl mZ d dlmZmZmZ d dlmZ ddlm	Z	 ddl
mZ ddd	ed
eded         fd„Zd„ Zdeej                 de	fd„Zd	edefd„Zded         fd„Z G d„ d¦  «        Z G d„ de¦  «        ZdS )é    )Údefaultdict)ÚIterableÚOptionalÚSet)Úx509é   )ÚValProcState)ÚPathValidationErrorÚvalid_policy_treeÚPolicyTreeRootÚdepthÚany_policy_uninhibitedÚreturnc                 ó*  — d}t          ¦   «         }| D ]¡}|d         j        }|dk    r|}Œ|                     |¦  «         |d         }d}	d}
|                     |dz
  ¦  «        D ]3}|j        dk    r|}
||j        vrŒd}	|                     |||h¦  «         Œ4|	s|
r|
                     |||h¦  «         Œ¢|rI|rG|                     |dz
  ¦  «        D ].}|j        D ]$}||vr|                     ||d         |h¦  «         Œ%Œ/t          ||dz
  ¦  «        }|S )zO
    Internal method to update the policy tree during RFC 5280 validation.
    NÚpolicy_identifierÚ
any_policyÚpolicy_qualifiersFr   T)ÚsetÚnativeÚaddÚat_depthÚvalid_policyÚexpected_policy_setÚ	add_childÚ_prune_policy_tree)Úcertificate_policiesr   r   r   Úcert_any_policyÚcert_policy_identifiersÚpolicyr   r   Úpolicy_id_matchÚparent_any_policyÚnodeÚexpected_policy_identifiers                úp/var/www/finuniver-perm.ru/html/portfolio/venv/lib/python3.11/site-packages/pyhanko_certvalidator/policy_tree.pyÚupdate_policy_treer%   
   sº  € ð €OÝ!™eœeÐð 'ð ð ˆØ"Ð#6Ô7Ô>Ðà Ò,Ð,Ø$ˆOØà×#Ò#Ð$5Ñ6Ô6Ð6à"Ð#6Ô7ÐàˆØ Ðð &×.Ò.¨u°q©yÑ9Ô9ð 	ð 	ˆDØÔ  LÒ0Ð0Ø$(Ð!Ø ¨Ô(@Ð@Ð@ØØ"ˆOØ�NŠNØ!Ð#4Ð7HÐ6Iñô ð ð ð
 ð 	Ð#4ð 	Ø×'Ò'Ø!Ð#4Ð7HÐ6Iñô ð øð
 ð Ð1ð Ø%×.Ò.¨u°q©yÑ9Ô9ð 	ð 	ˆDØ.2Ô.Fð ð Ð*Ø-Ð5LÐLÐLØ—N’NØ2Ø'Ð(;Ô<Ø3Ð4ñô ð øðõ +Ð+<¸eÀa¹iÑHÔHÐØÐó    c                 óŠ   — |                       |¦  «        D ]#}|j        s|j                             |¦  «         Œ$| j        sd } | S ©N)Úwalk_upÚchildrenÚparentÚremove_child)r   r   r"   s      r$   r   r   G   sW   € Ø!×)Ò)¨%Ñ0Ô0ð +ð +ˆØŒ}ð 	+ØŒK×$Ò$ TÑ*Ô*Ð*øØÔ%ð !Ø ÐØÐr&   ÚmappingsÚ
proc_statec                 ó  — t          t          ¦  «        }| D ]n}|d         j        }|d         j        }||                              |¦  «         |dk    s|dk    r+t	          j        d|                     ¦   «         › d�|¦  «        ‚Œo|S )zÂ
    Internal function to process policy mapping extension values into
    a Python dictionary mapping issuer domain policies to the corresponding
    policies in the subject policy domain.
    Úissuer_domain_policyÚsubject_domain_policyr   z(The path could not be validated because z/ contains a policy mapping for the "any policy")r   r   r   r   r
   Ú
from_stateÚdescribe_cert)r-   r.   Ú
policy_mapÚmappingr0   r1   s         r$   Úenumerate_policy_mappingsr6   P   s»   € õ �SÑ!Ô!€JØð ð ˆØ&Ð'=Ô>ÔEÐØ 'Ð(?Ô @Ô GÐàÐ'Ô(×,Ò,Ð-BÑCÔCÐCð ! LÒ0Ð0Ø$¨Ò4Ð4å%Ô0ð;Ø×+Ò+Ñ-Ô-ð;ð ;ð ;ð ñ	ô ð ð 5ð Ðr&   Úpolicy_mapping_uninhibitedc                 ó¤  — |                       ¦   «         D ]º\  }}|rcd}d}|                     |¦  «        D ]#}|j        dk    r|}|j        |k    r	d}||_        Œ$|s#|r!|j                             ||j        |¦  «         Œj|                     |¦  «        D ]'}|j        |k    r|j                             |¦  «         Œ(t          ||dz
  ¦  «        }Œ»|S )z„
    Internal function to apply the policy mapping to the current policy tree
    in accordance with the algorithm in RFC 5280.
    FNr   Tr   )	Úitemsr   r   r   r+   r   Úqualifier_setr,   r   )	r4   r   r   r7   r0   Úsubject_domain_policiesÚissuer_domain_policy_matchr   r"   s	            r$   Úapply_policy_mappingr=   n   s'  € ð :D×9IÒ9IÑ9KÔ9Kð Qð QÑ5ÐÐ5à%ð 	QØ).Ð&Ø"ˆOà)×2Ò2°5Ñ9Ô9ð Gð G�ØÔ$¨Ò4Ð4Ø&*�OØÔ$Ð(<Ò<Ð<Ø15Ð.Ø/F�DÔ,øà-ð °/ð ØÔ&×0Ò0Ø(Ø#Ô1Ø+ñô ð øð *×2Ò2°5Ñ9Ô9ð 3ð 3�ØÔ$Ð(<Ò<Ð<Ø”K×,Ò,¨TÑ2Ô2Ð2øÝ 2Ð3DÀeÈaÁiÑ PÔ PÐÐØÐr&   c                 ó²  ‡‡	— t          |                     ¦   «         ¦  «        Š	ˆˆ	fd„}t           |¦   «         ¦  «        }	 t          d„ |                     | ¦  «        D ¦   «         ¦  «        }|j        }|€J ‚|j        }‰|z
  D ]}|                     |||h¦  «         Œ|                     |¦  «         n# t          $ r Y nw xY wt          || dz
  ¦  «        S )Nc               3   óv   •K  — ‰D ]2} | j         }|dk    s|‰v r|V — Œ| j                             | ¦  «         Œ3d S )Nr   )r   r+   r,   )Úpolicy_nodeÚ	policy_idÚacceptable_policiesÚvalid_policy_node_sets     €€r$   Ú_filter_acceptablez7prune_unacceptable_policies.<locals>._filter_acceptable¡   sc   øè è € Ø0ð 	=ð 	=ˆKØ#Ô0ˆIØ˜LÒ(Ð(¨IÐ9LÐ,LÐ,LØ����àÔ"×/Ò/°Ñ<Ô<Ð<Ð<ð	=ð 	=r&   c              3   ó0   K  — | ]}|j         d k    ¯|V — ŒdS )r   N)r   )Ú.0r@   s     r$   ú	<genexpr>z.prune_unacceptable_policies.<locals>.<genexpr>°   s<   è è € ð 0
ð 0
àØÔ'¨<Ò7Ð7ð à7Ð7Ð7Ð7ð0
ð 0
r&   r   )
r   Únodes_in_current_domainÚnextr   r+   r:   r   r,   ÚStopIterationr   )
Úpath_lengthr   rB   rD   Úvalid_and_acceptableÚfinal_any_policyÚwildcard_parentÚwildcard_qualsÚacceptable_policyrC   s
     `      @r$   Úprune_unacceptable_policiesrQ   “   sE  øø€ õ  Ð 1× IÒ IÑ KÔ KÑLÔLÐð=ð =ð =ð =ð =ð =õ Ð1Ð1Ñ3Ô3Ñ4Ô4Ðð
Ý+/ð 0
ð 0
à0×9Ò9¸+ÑFÔFð0
ñ 0
ô 0
ñ ,
ô ,
Ðð
 +Ô1ˆØÐ*Ð*Ð*Ø)Ô7ˆØ!4Ð7KÑ!Kð 	ð 	ÐØ×%Ò%Ø! >Ð4EÐ3Fñô ð ð ð 	×$Ò$Ð%5Ñ6Ô6Ð6Ð6øÝð ð ð Øˆðøøøõ Ð/°¸q±ÑAÔAÐAs   ÁA3B6 Â6
CÃCc                   óp   — e Zd ZdZed„ ¦   «         Zd„ Zd„ Zd„ Zde	d         fd„Z
d	„ Zde	d         fd
„ZdS )r   zH
    A generic policy tree node, used for the root node in the tree
    c                 óP   — t          ¦   «         }|                     |||¦  «         |S )aq  
        Accepts values for a PolicyTreeNode that will be created at depth 0

        :param valid_policy:
            A unicode string of a policy name or OID

        :param qualifier_set:
            An instance of asn1crypto.x509.PolicyQualifierInfos

        :param expected_policy_set:
            A set of unicode strings containing policy names or OIDs
        )r   r   )Úclsr   r:   r   Úroots        r$   Úinit_policy_treezPolicyTreeRoot.init_policy_treeÊ   s+   € õ ÑÔˆØ�Š�| ]Ð4GÑHÔHÐHØˆr&   c                 ó"   — d | _         g | _        d S r(   )r+   r*   )Úselfs    r$   Ú__init__zPolicyTreeRoot.__init__Ü   s   € ØˆŒØˆŒˆˆr&   c                 ój   — t          |||¦  «        }| |_        | j                             |¦  «         dS )ab  
        Creates a new PolicyTreeNode as a child of this node

        :param valid_policy:
            A unicode string of a policy name or OID

        :param qualifier_set:
            An instance of asn1crypto.x509.PolicyQualifierInfos

        :param expected_policy_set:
            A set of unicode strings containing policy names or OIDs
        N)ÚPolicyTreeNoder+   r*   Úappend)rX   r   r:   r   Úchilds        r$   r   zPolicyTreeRoot.add_childà   s9   € õ ˜|¨]Ð<OÑPÔPˆØˆŒØŒ×Ò˜UÑ#Ô#Ð#Ð#Ð#r&   c                 ó:   — | j                              |¦  «         dS )zq
        Removes a child from this node

        :param child:
            An instance of PolicyTreeNode
        N)r*   Úremove©rX   r]   s     r$   r,   zPolicyTreeRoot.remove_childò   s    € ð 	Œ×Ò˜UÑ#Ô#Ð#Ð#Ð#r&   r   r[   c              #   óŒ   K  — t          | j        ¦  «        D ],}|dk    r|V — Œ|                     |dz
  ¦  «        D ]}|V — ŒŒ-dS )zô
        Returns a generator yielding all nodes in the tree at a specific depth

        :param depth:
            An integer >= 0 of the depth of nodes to yield

        :return:
            A generator yielding PolicyTreeNode objects
        r   r   N)Úlistr*   r   ©rX   r   r]   Ú
grandchilds       r$   r   zPolicyTreeRoot.at_depthü   sr   è è € õ ˜$œ-Ñ(Ô(ð 	%ð 	%ˆEØ˜ŠzˆzØ����à"'§.¢.°¸±Ñ";Ô";ð %ð %�JØ$Ð$Ð$Ð$Ð$ð%ð		%ð 	%r&   c              #   óŠ   K  — t          | j        ¦  «        D ]+}|dk    r|                     |dz
  ¦  «        D ]}|V — Œ|V — Œ,dS )aW  
        Returns a generator yielding all nodes in the tree at a specific depth,
        or above. Yields nodes starting with leaves and traversing up to the
        root.

        :param depth:
            An integer >= 0 of the depth of nodes to walk up from

        :return:
            A generator yielding PolicyTreeNode objects
        r   r   N)rb   r*   r)   rc   s       r$   r)   zPolicyTreeRoot.walk_up  sm   è è € õ ˜$œ-Ñ(Ô(ð 	ð 	ˆEØ˜ŠzˆzØ"'§-¢-°¸±	Ñ":Ô":ð %ð %�JØ$Ð$Ð$Ð$Ð$ØˆKˆKˆKˆKð		ð 	r&   c              #   óp   K  — | j         D ]+}|V — |j        dk    r|                     ¦   «         E d{V —† Œ,dS )zy
        Returns a generator yielding all nodes in the tree that are children
        of an ``any_policy`` node.
        r   N)r*   r   rH   r`   s     r$   rH   z&PolicyTreeRoot.nodes_in_current_domain!  s_   è è € ð ”]ð 	;ð 	;ˆEØˆKˆKˆKØÔ! \Ò1Ð1Ø ×8Ò8Ñ:Ô:Ð:Ð:Ð:Ð:Ð:Ð:Ð:øð	;ð 	;r&   N)Ú__name__Ú
__module__Ú__qualname__Ú__doc__ÚclassmethodrV   rY   r   r,   r   r   r)   rH   © r&   r$   r   r   Å   s·   € € € € € ðð ð ðð ñ „[ðð"ð ð ð$ð $ð $ð$$ð $ð $ð% Ð*:Ô!;ð %ð %ð %ð %ð$ð ð ð&	;¨Ð2BÔ)Cð 	;ð 	;ð 	;ð 	;ð 	;ð 	;r&   c                   óL   ‡ — e Zd ZdZdedej        dee         fˆ fd„Zd„ Z	ˆ xZ
S )r[   zD
    A policy tree node that is used for all nodes but the root
    r   r:   r   c                 ór   •— t          ¦   «                              ¦   «          || _        || _        || _        dS )a$  
        :param valid_policy:
            A unicode string of a policy name or OID

        :param qualifier_set:
            An instance of asn1crypto.x509.PolicyQualifierInfos

        :param expected_policy_set:
            A set of unicode strings containing policy names or OIDs
        N)ÚsuperrY   r   r:   r   )rX   r   r:   r   Ú	__class__s       €r$   rY   zPolicyTreeNode.__init__2  s9   ø€ õ  	‰Œ×ÒÑÔÐà(ˆÔØ*ˆÔØ#6ˆÔ Ð Ð r&   c              #   ó0   K  — | }|�|V — |j         }|­d S d S r(   )r+   )rX   r"   s     r$   Úpath_to_rootzPolicyTreeNode.path_to_rootH  s5   è è € ØˆØÐØˆJˆJˆJØ”;ˆDð ÐÐÐÐÐr&   )rg   rh   ri   rj   Ústrr   ÚPolicyQualifierInfosr   rY   rr   Ú__classcell__)rp   s   @r$   r[   r[   -  sy   ø€ € € € € ðð ð7àð7ð Ô0ð7ð ! œXð	7ð 7ð 7ð 7ð 7ð 7ð,ð ð ð ð ð ð r&   r[   N)Úcollectionsr   Útypingr   r   r   Ú
asn1cryptor   Ú_stater	   Úerrorsr
   ÚintÚboolr%   r   ÚPolicyMappingr6   r=   rQ   r   r[   rl   r&   r$   ú<module>r~      s™  ðØ #Ð #Ð #Ð #Ð #Ð #Ø *Ð *Ð *Ð *Ð *Ð *Ð *Ð *Ð *Ð *à Ð Ð Ð Ð Ð à  Ð  Ð  Ð  Ð  Ð  Ø 'Ð 'Ð 'Ð 'Ð 'Ð 'ð:à'ð:ð ð:ð !ð	:ð
 ÐÔð:ð :ð :ð :ðzð ð ðØ�tÔ)Ô*ðØ8Dðð ð ð ð<"Ø*-ð"ØKOð"ð "ð "ð "ðJ/BàÐÔð/Bð /Bð /Bð /Bðde;ð e;ð e;ð e;ð e;ñ e;ô e;ð e;ðPð ð ð ð �^ñ ô ð ð ð r&   