+
    JV-jÅn  ã                   ó:  € ^ RI t ^ RIHt ^ RIt ^ RIHt ^ RIHu H	t
 ^ RIHtHtHtHtHt RtRtRtRtRt] P.                  P0                  ] P.                  P                  .t] P4                  ! R	R
7      R 4       t] P4                  ! R	R
7      R 4       t] P4                  ! R	R
7      R 4       tR tR tR t R t!R t"R0R lt#R t$R t%R t&R t'R t(R t)R t*R t+R t,R t-R t.R  t/R! t0] P.                  Pc                  R"R#7      R$ 4       t2R% t3] P.                  Pi                  R1] Pj                  ! RRR&R'7      ] Pj                  ! R(RR)R'7      ] Pj                  ! RR(R*R'7      ] Pj                  ! R(R(R+R'7      .4      R, 4       t6R- t7R. t8R/ t9R#   ] d	    RtRt
 ELli ; i)2é    N)Ú	timedelta)ÚInMemoryKmsClientÚMockVersioningKmsClientÚverify_file_encryptedÚread_external_keys_to_dictÚparse_wrapped_keyzencrypted_table.in_mem.parquets   0123456789112345Ú
footer_keys   1234567890123450Úcol_keyÚmodule)Úscopec                  óÔ   € \         P                  P                  R \         P                  ! . RO4      R\         P                  ! . RO4      R\         P                  ! . RO4      /4      p V # )ÚaÚbÚc)é   é   é   )r   r   r   )ÚxÚyÚz)ÚpaÚTableÚfrom_pydictÚarray)Ú
data_tables    Úv/Volumes/fast/ai/experiments/ui-tars-smoke/.venv/lib/python3.14/site-packages/pyarrow/tests/parquet/test_encryption.pyr   r   2   sM   € ä—‘×%Ñ%ØŒR�XŠX’iÓ ØŒR�XŠX’oÓ&ØŒR�XŠX’oÓ&ð'ó €Jð
 Ðó    c                  óN   € \         P                  ! \        \        R R./R7      p V # )r   r   )r	   Úcolumn_keys©ÚpeÚEncryptionConfigurationÚFOOTER_KEY_NAMEÚCOL_KEY_NAME)Úbasic_encryption_configs    r   r%   r%   <   s,   € ä ×8Ò8Ü"ä˜3 ˜*ð
ôÐð
 #Ð"r   c                  óP   € \         P                  ! \        \        R R./RR7      p V # )r   r   F)r	   r   Úinternal_key_materialr    )Úexternal_encryption_configs    r   r(   r(   F   s1   € ä!#×!;Ò!;Ü"ä˜3 ˜*ð
ð $ô"%Ðð &Ð%r   c                óh   € \         P                  ! V R7      pR p\         P                  ! V4      pW3# )zy
Sets up and returns the KMS connection configuration and crypto factory
based on provided KMS configuration parameters.
©Úcustom_kms_confc                 ó   € \        V 4      # ©N©r   ©Úkms_connection_configurations   &r   Úkms_factoryÚ1setup_encryption_environment.<locals>.kms_factoryX   ó   € Ü Ð!=Ó>Ð>r   )r!   ÚKmsConnectionConfigÚCryptoFactory)r+   Úkms_connection_configr1   Úcrypto_factorys   &   r   Úsetup_encryption_environmentr8   Q   s5   € ô
 ×2Ò2À?ÔSÐò?ô ×%Ò% kÓ2€Nà Ð0Ð0r   c                ó€   € W$P                  R4      W5P                  R4      /p\        V4      w  r‰\        WVW‰4       W‰3# )zD
Writes an encrypted parquet file based on the provided parameters.
úUTF-8)Údecoder8   Úwrite_encrypted_parquet)
Úpathr   Úfooter_key_nameÚcol_key_namer	   r
   Úencryption_configr+   r6   r7   s
   &&&&&&&   r   Úwrite_encrypted_filerA   a   sW   € ð 	×*Ñ*¨7Ó3Ø—n‘n WÓ-ð€Oô -IØó-Ñ)Ðô ˜DÐ.?Ø1ôCð !Ð0Ð0r   c           	     óŒ  € V \         ,          p\        P                  ! \        \        RR./R\        RR7      RR7      pVP                  RJ g   Q h\        W!\        \        \        \        V4      w  rE\        V4       \        P                  ! \        RR7      R	7      p\        W&WE4      pVP                  V4      '       g   Q hR
# )úDWrite an encrypted parquet, verify it's encrypted, and then read it.r   r   Ú
AES_GCM_V1ç      @©Úminutesé   ©r	   r   Úencryption_algorithmÚcache_lifetimeÚdata_key_length_bitsF©rK   N)ÚPARQUET_NAMEr!   r"   r#   r$   r   Úuniform_encryptionrA   Ú
FOOTER_KEYÚCOL_KEYr   ÚDecryptionConfigurationÚread_encrypted_parquetÚequals©Útempdirr   r=   r@   r6   r7   Údecryption_configÚresult_tables   &&      r   Ú!test_encrypted_parquet_write_readrY   w   s¿   € à”\Õ!€Dô
 ×2Ò2Ü"ä˜3 ˜*ð
ð *Ü ¨Ô-Ø ô"Ðð ×/Ñ/°5Ó8Ð8Ð8ä,@Øœ/¬<¼ÄWØó-Ñ)Ðô ˜$Ôô ×2Ò2Ü ¨Ô-ô/Ðä)ØÐ!6óH€Là×Ñ˜\×*Ò*Ð*Ò*r   c           	     ót  € V \         ,          p\        P                  ! \        RR\	        RR7      RR7      pVP
                  RJ g   Q h\        W!\        \        \        RV4      w  rE\        V4       \        P                  ! \	        RR7      R7      p\        W&WE4      pVP                  V4      '       g   Q hR	# )
rC   TrD   rE   rF   rH   )r	   rO   rJ   rK   rL   r   rM   N)rN   r!   r"   r#   r   rO   rA   r$   rP   r   rR   rS   rT   rU   s   &&      r   Ú)test_uniform_encrypted_parquet_write_readr[   –   s²   € à”\Õ!€Dô ×2Ò2Ü"ØØ)Ü ¨Ô-Ø ô"Ðð ×/Ñ/°4Ó7Ð7Ð7ä,@Øœ/¬<¼ÀSØó-Ñ)Ðô ˜$Ôô ×2Ò2Ü ¨Ô-ô/Ðä)ØÐ!6óH€Là×Ñ˜\×*Ò*Ð*Ò*r   c                 ó.  € VP                   '       d   VP                  W24      pMVP                  W2V 4      pVf   Q h\        P                  ! WP                  VR7      ;_uu_ 4       pVP                  V4       R R R 4       R #   + '       g   i     R # ; i)N)Úencryption_properties)r'   Úfile_encryption_propertiesÚpqÚParquetWriterÚschemaÚwrite_table)r=   Útabler@   r6   r7   r^   Úwriters   &&&&&  r   r<   r<   ±   s‰   € à×.×.Ð.Ø%3×%NÑ%NØ!ó&6Ñ"ð &4×%NÑ%NØ!°dó&<Ð"à%Ò1Ð1Ð1Ü	×	Ò	Ø—,‘,Ø"<÷
>õ 
>àAGØ×Ñ˜5Ô!÷
>÷ 
>÷ 
>ò 
>ús   Á'BÂB	Tc                 ór  € V'       d   VP                  W!4      pMVP                  W!V 4      pVf   Q h\        P                  ! WR7      pVP                  ^8X  g   Q h\        P                  ! WR7      p\        VP                  4      ^8X  g   Q h\        P                  ! WR7      pVP                  RR7      # )N©Údecryption_propertiesT©Úuse_threads)	Úfile_decryption_propertiesr_   Úread_metadataÚnum_columnsÚread_schemaÚlenÚnamesÚParquetFileÚread)	r=   rW   r6   r7   r'   rj   Úmetara   Úresults	   &&&&&    r   rS   rS   À   sµ   € ÷ Ø%3×%NÑ%NØ!ó&6Ñ"ð &4×%NÑ%NØ!°dó&<Ð"ð &Ò1Ð1Ð1Ü×ÒØô@€Dà×Ñ˜qÔ Ð Ð Ü�^Š^Øô@€Fäˆv�|‰|Ó Ô!Ð!Ð!ä�^Š^Øô@€Fà�;‰; 4ˆ;Ó(Ð(r   c           	     ó4  € V \         ,          p\        P                  ! \        \        RR./R\        RR7      RR7      p\        W!\        \        \        \        V4       \        V4       \        \        \        P                  R4      \        \        P                  R4      /4      w  rE\        P                  ! \        RR7      R	7      p\        P                  ! \        R
R7      ;_uu_ 4        \!        W&VV4       RRR4       R#   + '       g   i     R# ; i)zUWrite an encrypted parquet, verify it's encrypted,
and then read it using wrong keys.r   r   rD   rE   rF   rH   rI   r:   rM   zIncorrect master key used©ÚmatchN)rN   r!   r"   r#   r$   r   rA   rP   rQ   r   r8   r;   rR   ÚpytestÚraisesÚ
ValueErrorrS   )rV   r   r=   r@   Úwrong_kms_connection_configÚwrong_crypto_factoryrW   s   &&     r   Ú+test_encrypted_parquet_write_read_wrong_keyr|   ×   så   € ð ”\Õ!€Dô
 ×2Ò2Ü"ä˜3 ˜*ð
ð *Ü ¨Ô-Ø ô"Ðô ˜¬?¼LÜ#¤WÐ.?ôAô ˜$Ôä8TÜœŸ™¨Ó0Ü”j×'Ñ'¨Ó0ðVó 9Ñ5Ðô
 ×2Ò2Ü ¨Ô-ô/Ðä	�Š”zÐ)E×	FÖ	FÜØÐ%@Ø ô	"÷ 
G×	F×	FÒ	Fús   Ã.DÄD	c                óü   € \        W4       \        P                  ! \        RR7      ;_uu_ 4        \        P
                  ! V \        ,          4      P                  4        RRR4       R#   + '       g   i     R# ; i)ziWrite an encrypted parquet, verify it's encrypted,
but then try to read it without decryption properties.úno decryptionru   N)rY   rw   rx   ÚIOErrorr_   rp   rN   rq   ©rV   r   s   &&r   Ú0test_encrypted_parquet_read_no_decryption_configr�   ú   sG   € ô & gÔ:ä	�Š”wÐ&6×	7Ö	7Ü
�Š�w¤Õ-Ó.×3Ñ3Ô5÷ 
8×	7×	7Ò	7ús   °0A*Á*A;	c                óà   € \        W4       \        P                  ! \        RR7      ;_uu_ 4        \        P
                  ! V \        ,          4       RRR4       R#   + '       g   i     R# ; i)zsWrite an encrypted parquet, verify it's encrypted,
but then try to read its metadata without decryption properties.r~   ru   N)rY   rw   rx   r   r_   rk   rN   r€   s   &&r   Ú9test_encrypted_parquet_read_metadata_no_decryption_configrƒ     s@   € ô & gÔ:ä	�Š”wÐ&6×	7Ö	7Ü
×Ò˜¤<Õ/Ô0÷ 
8×	7×	7Ò	7úó   °"AÁA-	c                óà   € \        W4       \        P                  ! \        RR7      ;_uu_ 4        \        P
                  ! V \        ,          4       RRR4       R#   + '       g   i     R# ; i)zqWrite an encrypted parquet, verify it's encrypted,
but then try to read its schema without decryption properties.r~   ru   N)rY   rw   rx   r   r_   rm   rN   r€   s   &&r   Ú7test_encrypted_parquet_read_schema_no_decryption_configr†     s>   € ô & gÔ:Ü	�Š”wÐ&6×	7Ö	7Ü
�Š�w¤Õ-Ô.÷ 
8×	7×	7Ò	7úr„   c                ó  € V R,          p\         P                  ! \        R7      p\        P                  ! \
        RR7      ;_uu_ 4        \        W!\        \        \        RV4       RRR4       R#   + '       g   i     R# ; i)úIWrite an encrypted parquet, but give only footer key,
without column key.z)encrypted_table_no_col_key.in_mem.parquet©r	   z4Either column_keys or uniform_encryption must be setru   r   N)	r!   r"   r#   rw   rx   ÚOSErrorrA   r$   rP   ©rV   r   r=   r@   s   &&  r   Ú'test_encrypted_parquet_write_no_col_keyrŒ     sm   € ð Ð@Õ@€Dô ×2Ò2Ü"ô$Ðô 
�Š”wð%÷
&ö 
&ô 	˜T¬ÄÜ'¨Ð.?ô	A÷	
&÷ 
&÷ 
&ò 
&ús   Á	A0Á0B	c                ó  € V R,          p\         P                  ! \        \        RR./RR7      p\        P
                  ! \        RR7      ;_uu_ 4        \        W!\        \        \        RV4       R	R	R	4       R	#   + '       g   i     R	# ; i)
rˆ   z=encrypted_table_col_key_and_uniform_encryption.in_mem.parquetr   r   T)r	   r   rO   z2Cannot set both column_keys and uniform_encryptionru   r   N)	r!   r"   r#   r$   rw   rx   rŠ   rA   rP   r‹   s   &&  r   Ú;test_encrypted_parquet_write_col_key_and_uniform_encryptionrŽ   '  s„   € ð ÐTÕT€Dô ×2Ò2Ü"ä˜3 ˜*ð
ð  ô!Ðô 
�Š”wØR÷
Tö 
Tô 	˜T¬ÄÜ'¨Ð.?ô	A÷
T÷ 
T÷ 
Tò 
Tús   ÁA:Á:B	c           	     ó  € V R,          pTp\         P                  ! 4       pR p\         P                  ! V4      p\        P                  ! \
        RR7      ;_uu_ 4        \        W1VWW4       RRR4       R#   + '       g   i     R# ; i)ú<Write an encrypted parquet, but raise KeyError in KmsClient.ú(encrypted_table_kms_error.in_mem.parquetc                 ó   € \        V 4      # r-   r.   r/   s   &r   r1   Ú;test_encrypted_parquet_write_kms_error.<locals>.kms_factoryD  s   € ô !Ð!=Ó>Ð>r   r	   ru   N)r!   r4   r5   rw   rx   ÚKeyErrorr<   ©rV   r   r%   r=   r@   r6   r1   r7   s   &&&     r   Ú&test_encrypted_parquet_write_kms_errorr–   ;  sn   € ð Ð?Õ?€DØ/Ðô ×2Ò2Ó4Ðò?ô
 ×%Ò% kÓ2€NÜ	�Š”x |×	4Ö	4ä Ð2CØ 5ô	G÷ 
5×	4×	4Ò	4úó   ÁA6Á6B	c           	     óN  a€ V R,          pTp\         P                  ! 4       p ! R R\         P                  4      oV3R lp\         P                  ! V4      p\        P
                  ! \        RR7      ;_uu_ 4        \        W1VWW4       RRR4       R#   + '       g   i     R# ; i)r�   r‘   c                   ó6   a € ] tR tRt o RtR tR tR tRtV t	R# )ÚJtest_encrypted_parquet_write_kms_specific_error.<locals>.ThrowingKmsClientiY  zFA KmsClient implementation that throws exception in
wrap/unwrap calls
c                óP   € \         P                  P                  V 4       Wn        R# )z%Create an InMemoryKmsClient instance.N)r!   Ú	KmsClientÚ__init__Úconfig©Úselfrž   s   &&r   r�   ÚStest_encrypted_parquet_write_kms_specific_error.<locals>.ThrowingKmsClient.__init__^  s   € ä�L‰L×!Ñ! $Ô'Ø ŽKr   c                ó   € \        R 4      h)úCannot Wrap Key©ry   ©r    Ú	key_bytesÚmaster_key_identifiers   &&&r   Úwrap_keyÚStest_encrypted_parquet_write_kms_specific_error.<locals>.ThrowingKmsClient.wrap_keyc  s   € ÜÐ.Ó/Ð/r   c                ó   € \        R 4      h)zCannot Unwrap Keyr¤   ©r    Úwrapped_keyr§   s   &&&r   Ú
unwrap_keyÚUtest_encrypted_parquet_write_kms_specific_error.<locals>.ThrowingKmsClient.unwrap_keyf  s   € ÜÐ0Ó1Ð1r   )rž   N©
Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__r�   r¨   r­   Ú__static_attributes__Ú__classdictcell__©Ú__classdict__s   @r   ÚThrowingKmsClientrš   Y  s   ø‡ € ñ	ò	!ò
	0÷	2ð 	2r   r¹   c                 ó   <€ S! V 4      # r-   © )r0   r¹   s   &€r   r1   ÚDtest_encrypted_parquet_write_kms_specific_error.<locals>.kms_factoryi  s   ø€ á Ð!=Ó>Ð>r   r£   ru   N)r!   r4   rœ   r5   rw   rx   ry   r<   )	rV   r   r%   r=   r@   r6   r1   r7   r¹   s	   &&&     @r   Ú/test_encrypted_parquet_write_kms_specific_errorr½   P  s€   ø€ ð Ð?Õ?€DØ/Ðô ×2Ò2Ó4Ðô2œBŸL™Lô 2õ ?ô ×%Ò% kÓ2€NÜ	�Š”zÐ):×	;Ö	;ä Ð2CØ 5ô	G÷ 
<×	;×	;Ò	;ús   Á;BÂB$	c           	     ó  € V R,          pTp\         P                  ! 4       pR p\         P                  ! V4      p\        P                  ! \
        RR7      ;_uu_ 4        \        W1VWW4       RRR4       R#   + '       g   i     R# ; i)z@Write an encrypted parquet, but raise ValueError in kms_factory.ú0encrypted_table_kms_factory_error.in_mem.parquetc                 ó   € \        R 4      h)úCannot create KmsClientr¤   r/   s   &r   r1   ÚCtest_encrypted_parquet_write_kms_factory_error.<locals>.kms_factory}  s   € ÜÐ2Ó3Ð3r   rÁ   ru   N)r!   r4   r5   rw   rx   ry   r<   r•   s   &&&     r   Ú.test_encrypted_parquet_write_kms_factory_errorrÃ   t  s{   € ð ÐGÕG€DØ/Ðô ×2Ò2Ó4Ðò4ô ×%Ò% kÓ2€NÜ	�Š”zØ6÷
8ö 
8ô 	  Ð2CØ 5ô	G÷
8÷ 
8÷ 
8ò 
8úr—   c           	     ó,  a€ V R,          pTp\         P                  ! 4       p ! R R4      oV3R lp\         P                  ! V4      p\        P                  ! \
        4      ;_uu_ 4        \        W1VWW4       RRR4       R#   + '       g   i     R# ; i)z[Write an encrypted parquet, but use wrong KMS client type
that doesn't implement KmsClient.r¿   c                   ó6   a € ] tR tRt o RtR tR tR tRtV t	R# )ÚOtest_encrypted_parquet_write_kms_factory_type_error.<locals>.WrongTypeKmsClienti’  z4This is not an implementation of KmsClient.
        c                ó(   € VP                   V n        R # r-   )r+   Úmaster_keys_maprŸ   s   &&r   r�   ÚXtest_encrypted_parquet_write_kms_factory_type_error.<locals>.WrongTypeKmsClient.__init__–  s   € Ø#)×#9Ñ#9ˆDÖ r   c                ó   € R # r-   r»   r¥   s   &&&r   r¨   ÚXtest_encrypted_parquet_write_kms_factory_type_error.<locals>.WrongTypeKmsClient.wrap_key™  ó   € Ùr   c                ó   € R # r-   r»   r«   s   &&&r   r­   ÚZtest_encrypted_parquet_write_kms_factory_type_error.<locals>.WrongTypeKmsClient.unwrap_keyœ  rÌ   r   )rÈ   Nr¯   r·   s   @r   ÚWrongTypeKmsClientrÆ   ’  s   ø‡ € ñ	ò	:ò	÷	ð 	r   rÏ   c                 ó   <€ S! V 4      # r-   r»   )r0   rÏ   s   &€r   r1   ÚHtest_encrypted_parquet_write_kms_factory_type_error.<locals>.kms_factoryŸ  s   ø€ Ù!Ð">Ó?Ð?r   N)r!   r4   r5   rw   rx   Ú	TypeErrorr<   )	rV   r   r%   r=   r@   r6   r1   r7   rÏ   s	   &&&     @r   Ú3test_encrypted_parquet_write_kms_factory_type_errorrÓ   ˆ  sx   ø€ ð ÐGÕG€DØ/Ðô ×2Ò2Ó4Ð÷ñ õ@ô ×%Ò% kÓ2€NÜ	�Š”y×	!Õ	!ä Ð2CØ 5ô	G÷ 
"×	!×	!Ò	!ús   Á*BÂB	c                  óP  € R  p \         P                  ! \        \        RR./RRR\	        RR7      R^ÀR7      pV ! V4       \         P                  ! \        R	7      p\        RR./Vn        RVn        RVn        RVn        \	        RR7      Vn	        RVn
        ^ÀVn        V ! V4       R
# )c                 ór  € \         V P                  8X  g   Q hR R.V P                  \        ,          8X  g   Q hRV P                  8X  g   Q hV P
                  '       g   Q hV P                  '       d   Q h\        RR7      V P                  8X  g   Q hV P                  '       d   Q h^ÀV P                  8X  g   Q hR# )r   r   ÚAES_GCM_CTR_V1ç      $@rF   N)r#   r	   r   r$   rJ   Úplaintext_footerÚdouble_wrappingr   rK   r'   rL   )r@   s   &r   Ú!validate_encryption_configurationÚZtest_encrypted_parquet_encryption_configuration.<locals>.validate_encryption_configurationª  s¯   € ÜÐ"3×">Ñ">Ô>Ð>Ð>Ø�SˆzÐ.×:Ñ:¼<ÕHÔHÐHÐHØÐ#4×#IÑ#IÔIÐIÐIØ ×1×1Ð1Ð1Ð1Ø$×4×4Ð4Ð4Ð4Ü Ô&Ð*;×*JÑ*JÔJÐJÐJØ$×:×:Ð:Ð:Ð:ØÐ'×<Ñ<Ô<Ð<Ò<r   r   r   rÖ   TFr×   rF   )r	   r   rJ   rØ   rÙ   rK   r'   rL   r‰   N)r!   r"   r#   r$   r   r   rJ   rØ   rÙ   rK   r'   rL   )rÚ   r@   Úencryption_config_1s      r   Ú/test_encrypted_parquet_encryption_configurationrÝ   ©  sµ   € ò=ô ×2Ò2Ü"Ü! C¨ :Ð0Ø-ØØÜ ¨Ô.Ø#Ø ô	Ðñ &Ð&7Ô8ä×4Ò4Ü"ô$Ðä'3°c¸3°ZÐ&BÐÔ#Ø/?ÐÔ,Ø+/ÐÔ(Ø*/ÐÔ'Ü)2¸4Ô)@ÐÔ&Ø05ÐÔ-Ø/2ÐÔ,Ù%Ð&9Ö:r   c                  ó  € \         P                  ! \        R R7      R7      p \        R R7      V P                  8X  g   Q h\         P                  ! 4       p\        R R7      Vn        \        R R7      VP                  8X  g   Q hR# )r×   rF   rM   N)r!   rR   r   rK   )rW   Údecryption_config_1s     r   Ú/test_encrypted_parquet_decryption_configurationrà   Ì  sl   € Ü×2Ò2Ü ¨Ô.ô0Ðä˜TÔ"Ð&7×&FÑ&FÔFÐFÐFä×4Ò4Ó6ÐÜ)2¸4Ô)@ÐÔ&Ü˜TÔ"Ð&9×&HÑ&HÔHÐHÒHr   c            	      óÒ   € R  p \         P                  ! RRRRRRR/R7      pV ! V4       \         P                  ! 4       pRVn        RVn        RVn        RRRR/Vn        V ! V4       R	# )
c                 ó¦   € R V P                   8X  g   Q hRV P                  8X  g   Q hRV P                  8X  g   Q hRRRR/V P                  8X  g   Q hR# )Ú	Instance1ÚURL1ÚMyTokenÚkey1Úkey_material_1Úkey2Úkey_material_2N©Úkms_instance_idÚkms_instance_urlÚkey_access_tokenr+   )r6   s   &r   Úvalidate_kms_connection_configÚPtest_encrypted_parquet_kms_configuration.<locals>.validate_kms_connection_config×  sg   € ØÐ3×CÑCÔCÐCÐCØÐ.×?Ñ?Ô?Ð?Ð?ØÐ1×BÑBÔBÐBÐBØÐ)¨6Ð3CÐDØ%×5Ñ5ô6ð 	7ò 6r   rã   rä   rå   ræ   rç   rè   ré   rê   N)r!   r4   rë   rì   rí   r+   )rî   r6   Úkms_connection_config_1s      r   Ú(test_encrypted_parquet_kms_configurationrñ   Ö  s‹   € ò7ô ×2Ò2Ø#ØØ"àÐ$ØÐ$ð
ô	Ðñ #Ð#8Ô9ä ×4Ò4Ó6ÐØ.9ÐÔ+Ø/5ÐÔ,Ø/8ÐÔ,àÐ ØÐ ð/ÐÔ+ñ #Ð#:Ö;r   zNPlaintext footer - reading plaintext column subset reads encrypted columns too)Úreasonc                óJ  € V \         ,          p\        P                  ! \        \        RR./RRR7      p\        P
                  ! \        \        P                  R4      \        \        P                  R4      /R7      pR p\        P                  ! V4      p\        W!VWF4       R	# )
zƒWrite an encrypted parquet, with plaintext footer
and with single wrapping,
verify it's encrypted, and then read plaintext columns.r   r   TF)r	   r   rØ   rÙ   r:   r*   c                 ó   € \        V 4      # r-   r.   r/   s   &r   r1   ÚStest_encrypted_parquet_write_read_plain_footer_single_wrapping.<locals>.kms_factory  r3   r   N)rN   r!   r"   r#   r$   r4   rP   r;   rQ   r5   r<   )rV   r   r=   r@   r6   r1   r7   s   &&     r   Ú>test_encrypted_parquet_write_read_plain_footer_single_wrappingrö   ó  s˜   € ð ”\Õ!€Dô
 ×2Ò2Ü"ä˜3 ˜*ð
ð ØôÐô ×2Ò2äœZ×.Ñ.¨wÓ7Üœ'Ÿ.™.¨Ó1ð
ôÐò?ô ×%Ò% kÓ2€Nä˜DÐ.?Ø1öCr   c           	     óB  € V \         ,          p\        W1\        \        \        \
        V4      w  rE\        V4       \        P                  ! 4       p\        W6WERR7      p\        P                  P                  P                  V4      p\        VP                  4       ;p	4      \        VP                   \        ,          4      ^,           8X  g   Q h\#        V	 U
u. uF  q¨P%                  V
4      RJNK  	  up
4      '       g   Q hVP'                  V4      '       g   Q hR# u up
i )z€Write an encrypted parquet file with external key material, verify
it's encrypted, then read both the table and external store.
F©r'   N)rN   rA   r#   r$   rP   rQ   r   r!   rR   rS   r   Ú_parquet_encryptionÚFileSystemKeyMaterialStoreÚfor_filern   Úget_key_id_setr   ÚallÚget_key_materialrT   )rV   r   r(   r=   r6   r7   rW   rX   ÚstoreÚkey_idsÚks   &&&        r   Ú*test_encrypted_parquet_write_read_externalr    s   € ð
 ”\Õ!€Dä,@Øœ/¬<¼ÄWØ"ó-$Ñ)Ðô ˜$Ôä×2Ò2Ó4ÐÜ)ØÐ!6Ø#ô%€Lô ×"Ñ"×=Ñ=×FÑFÀtÓL€Eä˜%×.Ñ.Ó0Ð0ˆwÓ1ÜÐ&×2Ñ2´<Õ@ÓAÀAÕEôGð Gð Gä¹wÓG¹w¸!×&Ñ& qÓ)°Ó5¹wÑG×HÒHÐHÐHØ×Ñ˜\×*Ò*Ð*Ò*ùò Hs   ÃDzdouble wrapping)ÚidFzsingle to double wrappedzdouble to singe wrappedzsingle wrappingc                ó¦  aaaa€ V \         ,          p\        P                  ! \        \        RR./RSR7      p\        P
                  ! RR7      pR p\        P                  ! V4      p\        VVVVV4       \        V4      oVP                  R4       VP                  VVSR	7       \        V4      o\        V4       \        V\        P                  ! 4       VVRR
7      p	\        S9   g   Q h\        S9   g   Q h\        S9   g   Q h\        S9   g   Q hR VVVV3R llp
V
! \        4       V
! \        4       VP                  V	4      '       g   Q hR# )a‹  Tests CryptoFactory.rotate_master_keys

Note: The CryptoFactory.rotate_master_keys() double_wrapping keword arg
may be either True (the default) or False regardless of whether
EncryptionConfig.double_wrapping was set to true (also the default) when
the external key material store was written. This means double wrapping may
be set one way initially and then applied or removed during rotation.
r   r   F)r	   r   r'   rÙ   Ú1)rí   c                 ó   € \        V 4      # r-   )r   r/   s   &r   r1   Ú8test_external_key_material_rotation.<locals>.kms_factoryR  s   € Ü&Ð'CÓDÐDr   Ú2)rÙ   rø   c                ó(   € V ^8„  d   QhR\         RR/# )r   Úmaster_key_idÚreturnN)Ústr)Úformats   "r   Ú__annotate__Ú9test_external_key_material_rotation.<locals>.__annotate__r  s   € ÷ &ñ &´3ð &¸4ñ &r   c                 óø   <€ S	V ,          pS
'       d   VP                   pMVP                  p\        V4      w  r4pSV ,          pS'       d   VP                   pMVP                  p\        V4      w  r7pWG8  g   Q hR # r-   )Úwrapped_kekÚwrapped_dekr   )r
  Úbefore_key_matÚbefore_key_wrappedÚ_Ú
before_verÚafter_key_matÚafter_key_wrappedÚ	after_verÚ
after_keysÚbefore_keysÚdouble_wrap_initialÚdouble_wrap_rotateds   &       €€€€r   Úcheck_rotated_external_keysÚHtest_external_key_material_rotation.<locals>.check_rotated_external_keysr  sz   ø€ Ø$ ]Õ3ˆßØ!/×!;Ñ!;Ñà!/×!;Ñ!;ÐÜ,Ð-?Ó@Ñˆ�qà" =Õ1ˆßØ -× 9Ñ 9Ñà -× 9Ñ 9ÐÜ+Ð,=Ó>‰ˆ�að Ô%Ð%Ò%r   N)rN   r!   r"   r#   r$   r4   r5   r<   r   Úrefresh_key_access_tokenÚrotate_master_keysr   rS   rR   rT   )Úreusable_tempdirr   r  r  r=   r@   r6   r1   r7   Útable_read_after_rotationr  r  r  s   &&ff       @@r   Ú#test_external_key_material_rotationr$  5  sR  û€ ð& œlÕ*€DÜ×2Ò2Ü"Ü! C¨ :Ð.Ø#Ø+ô	-Ðô ×2Ò2ÀCÔHÐòEä×%Ò% kÓ2€NÜØØØØØôô -¨TÓ2€Kð ×2Ñ2°3Ô7à×%Ñ%ØØØ+ð &ô -ô
 ,¨DÓ1€JÜ˜$ÔÜ 6ØÜ
×"Ò"Ó$ØØØ#ô!%Ðô ˜kÔ)Ð)Ð)Ü˜;Ô&Ð&Ð&Ü˜jÔ(Ð(Ð(Ü˜:Ô%Ð%Ð%÷&ó &ñ"  ¤Ô0Ù¤Ô-Ø×ÑÐ6×7Ò7Ð7Ò7r   c           	     ó’  € V \         ,          p\        W1\        \        \        \
        V4      w  rE\        V4       \        P                  ! \        RR7      R7      p\        ^24       F\  pVP                  WF4      pVf   Q h\        P                  ! W8R7      p	V	P                  RR7      p
VP                  V
4      '       d   K\  Q h	  R# )z\Write an encrypted parquet, verify it's encrypted,
and then read it multithreaded in a loop.rE   rF   rM   Nrf   Trh   )rN   rA   r#   r$   rP   rQ   r   r!   rR   r   Úrangerj   r_   rp   rq   rT   )rV   r   r%   r=   r6   r7   rW   Úirj   rs   rX   s   &&&        r   Útest_encrypted_parquet_loopr(  ˆ  s¹   € ð ”\Õ!€Dô
 -AØœ/¬<¼ÄWØó-!Ñ)Ðô ˜$Ôä×2Ò2Ü ¨Ô-ô/Ðô �2ŽYˆà%3×%NÑ%NØ!ó&6Ð"à)Ò5Ð5Ð5ä—’ØôDˆà—{‘{¨t�{Ó4ˆØ× Ñ  ×.Ô.Ð.Ð.ó r   c           	     ód  € V \         ,          p\        W1\        \        \        \
        V4      w  rE\        V4       \        P                  ! \        RR7      R7      pVP                  WF4      p?\        P                  ! W7R7      pVP                  RR7      p	VP                  V	4      '       g   Q hR# )zV
Test that decryption properties can be used if the crypto factory is no longer alive
rE   rF   rM   rf   Trh   N)rN   rA   r#   r$   rP   rQ   r   r!   rR   r   rj   r_   rp   rq   rT   )
rV   r   r%   r=   r6   r7   rW   rj   rs   rX   s
   &&&       r   Ú%test_read_with_deleted_crypto_factoryr*  ¥  sŸ   € ð ”\Õ!€DÜ,@Øœ/¬<¼ÄWØó-!Ñ)Ðô ˜$Ôô ×2Ò2Ü ¨Ô-ô/Ðà!/×!JÑ!JØó"2Ðàä�^Š^Øô@€Fà—;‘;¨4�;Ó0€LØ×Ñ˜\×*Ò*Ð*Ò*r   c           	     óˆ  € V \         ,          p\        W1\        \        \        \
        V4      w  rE\        P                  ! \        RR7      R7      pVP                  WF4      p\        P                  ! W7R7      pVP                  V4      '       g   Q h\        P                  ! WR7      pVP                  V4      '       g   Q hR# )z>Write an encrypted parquet then read it back using read_table.rE   rF   rM   rf   N)rN   rA   r#   r$   rP   rQ   r!   rR   r   rj   r_   Ú
read_tablerT   )	rV   r   r%   r=   r6   r7   rW   rj   rX   s	   &&&      r   Ú!test_encrypted_parquet_read_tabler-  ½  s®   € à”\Õ!€Dô -AØœ/¬<¼ÄWØó-!Ñ)Ðô ×2Ò2Ü ¨Ô-ô/Ðà!/×!JÑ!JØó"2Ðô —=’= ÔX€Lð ×Ñ˜\×*Ò*Ð*Ð*ô —=’=ØôC€Là×Ñ˜\×*Ò*Ð*Ò*r   )T)r  r  ):rw   Údatetimer   Úpyarrowr   Úpyarrow.parquetÚparquetr_   Úpyarrow.parquet.encryptionÚ
encryptionr!   Ú pyarrow.tests.parquet.encryptionr   r   r   r   r   ÚImportErrorrN   rP   r#   rQ   r$   ÚmarkÚparquet_encryptionÚ
pytestmarkÚfixturer   r%   r(   r8   rA   rY   r[   r<   rS   r|   r�   rƒ   r†   rŒ   rŽ   r–   r½   rÃ   rÓ   rÝ   rà   rñ   Úxfailrö   r  ÚparametrizeÚparamr$  r(  r*  r-  r»   r   r   Ú<module>r=     sú  ðó" Ý Û ðEÝ ß+Ð+÷
Eõ Eð 0€Ø €
Ø€Ø
€Ø€ð ‡K�K×"Ñ"Ø
‡K�K×Ñð€
ð ‡‚�hÔñó  ðð ‡‚�hÔñ#ó  ð#ð ‡‚�hÔñ&ó  ð&ò1ò 1ò,+ò>+ò6"ô)ò. "òF6ò1ò/òAò"Aò(Gò*!GòHGò(GòB ;òFIò<ð: ‡�×Ñð 2Ðó 3ñCó3ðCòN+ð2 ‡�×ÑØ2Ø�Š�T˜4Ð$5Ô6Ø�Š�U˜DÐ%?Ô@Ø�Š�T˜5Ð%>Ô?Ø�Š�U˜EÐ&7Ô8ð	5:ó;ñJ8ó;ðJ8òZ/ò:+ô0+øðM ô Ø	€BØ	ƒBðús   �F ÆFÆF