+
    IV-jg  ã                  ó´   € R t ^ RIHt ^ RIt^ RIt^ RIt^ RIHtHt ]P                  '       d   ^RI	H
t
 Rt ! R R]4      tRR R	 lltR
 R ltRR R lltR# )zHThe match_hostname() function from Python 3.5, essential when using SSL.)ÚannotationsN)ÚIPv4AddressÚIPv6Address)Ú_TYPE_PEER_CERT_RET_DICTz3.5.0.1c                  ó   € ] tR t^tRtR# )ÚCertificateError© N)Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__static_attributes__r   ó    Úp/Volumes/fast/ai/experiments/ui-tars-smoke/.venv/lib/python3.14/site-packages/urllib3/util/ssl_match_hostname.pyr   r      s   † Ûr   r   c               ó(   € V ^8„  d   QhRRRRRRRR/# )	é   Údnz
typing.AnyÚhostnameÚstrÚmax_wildcardsÚintÚreturnztyping.Match[str] | None | boolr   )Úformats   "r   Ú__annotate__r      s,   € ÷ 5ñ 5Øð5Ø!ð5Ø25ð5à$ñ5r   c                ón  € . pV '       g   R# V P                  R4      pV^ ,          pVR,          pVP                  R4      pWr8”  d   \        R\        V 4      ,           4      hV'       g+   \	        V P                  4       VP                  4       8H  4      # VR8X  d   VP                  R4       M‰VP                  R4      '       g   VP                  R4      '       d'   VP                  \        P                  ! V4      4       M5VP                  \        P                  ! V4      P                  RR	4      4       V F(  pVP                  \        P                  ! V4      4       K*  	  \        P                  ! R
RP                  V4      ,           R,           \        P                  4      p	V	P                  V4      # )z`Matching according to RFC 6125, section 6.4.3

http://tools.ietf.org/html/rfc6125#section-6.4.3
FÚ.:é   NNÚ*z,too many wildcards in certificate DNS name: z[^.]+zxn--z\*z[^.]*z\Az\.z\Z)ÚsplitÚcountr   ÚreprÚboolÚlowerÚappendÚ
startswithÚreÚescapeÚreplaceÚcompileÚjoinÚ
IGNORECASEÚmatch)
r   r   r   ÚpatsÚpartsÚleftmostÚ	remainderÚ	wildcardsÚfragÚpats
   &&&       r   Ú_dnsname_matchr3      sL  € ð €DßÙð �H‰H�T‹N€EØ�Q�x€HØ�b•	€Ià—‘˜sÓ#€IØÔ ô
 Ø:¼TÀ"»XÕEó
ð 	
÷
 Ü�B—H‘H“J (§.¡.Ó"2Ñ2Ó3Ð3ð
 �3„ð 	�‰�GÕØ	×	Ñ	˜V×	$Ò	$¨×(;Ñ(;¸F×(CÒ(Cð
 	�‰”B—I’I˜hÓ'Õ(ð 	�‰”B—I’I˜hÓ'×/Ñ/°°wÓ?Ô@ó ˆØ�‰”B—I’I˜d“OÖ$ñ ô �*Š*�U˜UŸZ™Z¨Ó-Õ-°Õ5´r·}±}Ó
E€CØ�9‰9�XÓÐr   c               ó$   € V ^8„  d   QhRRRRRR/# )r   Úipnamer   Úhost_ipzIPv4Address | IPv6Addressr   r!   r   )r   s   "r   r   r   P   s"   € ÷ -ñ -˜Sð -Ð+Dð -Èñ -r   c                óŽ   € \         P                  ! V P                  4       4      p\        VP                  VP                  8H  4      # )am  Exact matching of IP addresses.

RFC 9110 section 4.3.5: "A reference identity of IP-ID contains the decoded
bytes of the IP address. An IP version 4 address is 4 octets, and an IP
version 6 address is 16 octets. [...] A reference identity of type IP-ID
matches if the address is identical to an iPAddress value of the
subjectAltName extension of the certificate."
)Ú	ipaddressÚ
ip_addressÚrstripr!   Úpacked)r5   r6   Úips   && r   Ú_ipaddress_matchr=   P   s2   € ô 
×	Ò	˜fŸm™m›oÓ	.€BÜ�—	‘	˜WŸ^™^Ñ+Ó,Ð,r   c               ó(   € V ^8„  d   QhRRRRRRRR/# )	r   Úcertz_TYPE_PEER_CERT_RET_DICT | Noner   r   Úhostname_checks_common_namer!   r   ÚNoner   )r   s   "r   r   r   _   s6   € ÷ :Rñ :RØ
)ð:Ràð:Rð "&ð:Rð 
ñ	:Rr   c                ó<  € V '       g   \        R4      h \        P                  ! V4      p. pV P                  RR4      pV Fi  w  rgVR8X  d,   Vf   \	        Wq4      '       d    R# VP                  V4       K7  VR8X  g   K@  Ve   \        Ws4      '       d    R# VP                  V4       Kk  	  V'       d`   Vf\   V'       gT   V P                  RR4       F=  pV F4  w  rgVR8X  g   K  \	        Wq4      '       d     R# VP                  V4       K6  	  K?  	  \        V4      ^8”  d1   \        RV: R	R
P                  \        \        V4      4      : 24      h\        V4      ^8X  d   \        RV: RV^ ,          : 24      h\        R4      h  \          d    Rp ELoi ; i)a  Verify that *cert* (in decoded format as returned by
SSLSocket.getpeercert()) matches the *hostname*.  RFC 2818 and RFC 6125
rules are followed, but IP addresses are not accepted for *hostname*.

CertificateError is raised on failure. On success, the function
returns nothing.
ztempty or no certificate, match_hostname needs a SSL socket or SSL context with either CERT_OPTIONAL or CERT_REQUIREDNÚsubjectAltNameÚDNSz
IP AddressÚsubjectÚ
commonNamez	hostname z doesn't match either of z, z doesn't match z/no appropriate subjectAltName fields were foundr   )Ú
ValueErrorr8   r9   Úgetr3   r#   r=   Úlenr   r)   Úmapr    )	r?   r   r@   r6   ÚdnsnamesÚsanÚkeyÚvalueÚsubs	   &&&      r   Úmatch_hostnamerP   _   su  € ÷ Üð-ó
ð 	
ðÜ×&Ò& xÓ0ˆð €HØ'+§x¡xÐ0@À"Ó'E€Có ‰
ˆØ�%Œ<ØŠ¤>°%×#BÒ#BÚØ�O‰O˜EÖ"Ø�LÖ ØÒ"Ô'7¸×'GÒ'GÚØ�O‰O˜EÖ"ñ ÷ # w¢¿xØ—8‘8˜I rÖ*ˆCÛ!‘
�Ø˜,Ö&Ü% e×6Ò6ÛØ—O‘OØöó	 "ñ +ô ˆ8ƒ}�qÔÝã,4°d·i±iÄÄDÈ(Ó@SÕ6TðVó
ð 	
ô 
ˆX‹˜!Ô	Ü ¨8©,°oÀhÈqÅkÁ_ÐUÓVÐVäÐPÓQÐQøôK ô à‹ðús   •F
 Æ
FÆF)r   )F)Ú__doc__Ú
__future__r   r8   r%   Útypingr   r   ÚTYPE_CHECKINGÚssl_r   Ú__version__rG   r   r3   r=   rP   r   r   r   Ú<module>rW      sP   ðÙ Nõ #ã Û 	Û ß .à	××ÐÝ.à€ô	�zô 	÷5õp-÷:Rñ :Rr   