Ë
    ÚŠ±jë  ã                   óf   — d Z ddlZddlmZ dZdZdZdZdZd	„ Z	d
„ Z
d„ Zd„ Zd„ Zd„ Zdd„ZdZd„ Zy)a$  Cleartext HTTP/2 (h2c) negotiation, shared by every worker.

The I/O differs per worker: gthread and gevent read from a socket, the ASGI
worker is handed bytes by asyncio. The decisions do not. Keeping the pure,
I/O-free part here stops the blocking and push-based paths from drifting apart.
é    N)Ú_ip_in_allow_lists   PRI * HTTP/2.0

SM

g      ð?ÚmatchÚpartialÚmismatchc                 ó¼   — t        | «      t        t        «      k\  r!| j                  t        «      rt        S t        S t        j                  | «      rt
        S t        S )a  Compare buffered bytes against the connection preface.

    Returns ``MATCH`` when the whole preface is present, ``PARTIAL`` when the
    bytes so far are a prefix of it and more could still arrive, and
    ``MISMATCH`` as soon as a byte diverges. Never blocks and never reads.
    )ÚlenÚH2C_PREFACEÚ
startswithÚMATCHÚMISMATCHÚPARTIAL)Úbufs    ú_/var/www/io.vulcan-creative.com/venv/lib/python3.12/site-packages/gunicorn/http2/negotiation.pyÚpreface_matchr      sC   € ô ˆ3ƒx”3”{Ó#Ò#ØŸ™¤{Ô3ŒuÐA¼ÐAÜ!×,Ñ,¨SÔ1Œ7Ð?´xÐ?ó    c                 ót   — t        |t        «      syt        |d   | j                  | j	                  «       «      S )a;  Whether this peer may negotiate cleartext HTTP/2.

    Reuses the ``forwarded_allow_ips`` trust list: h2c is only ever expected
    from the TLS-terminating proxy in front of gunicorn, which is the same
    peer already trusted to set forwarded headers. Unix socket peers are
    trusted, matching that policy.
    Tr   )Ú
isinstanceÚtupler   Úforwarded_allow_ipsÚforwarded_allow_networks©ÚcfgÚ	peer_addrs     r   Úpeer_trusted_for_h2cr   )   s8   € ô �i¤Ô'ØÜØ�!‰�c×-Ñ-¨s×/KÑ/KÓ/Móð r   c                 ó`   — d| j                   v xr t        | dd«      dk(  xr | j                   S )z;Whether cleartext HTTP/2 could apply to this server at all.Úh2ÚprotocolÚhttp)Úhttp_protocolsÚgetattrÚis_ssl©r   s    r   Ú_h2c_availabler#   8   s;   € ð 	�×"Ñ"Ð"ò 	Ü�C˜ VÓ,°Ñ6ò	à—
‘
ˆNðr   c                 óR   — | j                   dvryt        | «      xr t        | |«      S )z·Whether to sniff for the connection preface from this peer.

    Deliberately separate from :func:`upgrade_allowed`: enabling one mechanism
    must not quietly enable the other.
    )úprior-knowledgeÚbothF©Úhttp2_cleartextr#   r   r   s     r   Úprior_knowledge_allowedr)   A   s.   € ð ×ÑÐ"=Ñ=ØÜ˜#ÓÒGÔ#7¸¸YÓ#GÐGr   c                 ó    — | j                   dk(  S )aa  Whether a trusted peer failing to send the preface is a 400.

    Only when prior knowledge is the sole mechanism: such a peer is expected
    to speak HTTP/2 and a silent downgrade would hide a misconfiguration.
    When upgrade is also enabled, an HTTP/1 request is not a mistake, it is
    how an upgrade begins, so it has to be allowed through.
    r%   )r(   r"   s    r   Úmismatch_is_errorr+   L   s   € ð ×ÑÐ"3Ñ3Ð3r   c                 óR   — | j                   dvryt        | «      xr t        | |«      S )z=Whether to honour an ``Upgrade: h2c`` request from this peer.)Úupgrader&   Fr'   r   s     r   Úupgrade_allowedr.   W   s,   € à
×ÑÐ"5Ñ5ØÜ˜#ÓÒGÔ#7¸¸YÓ#GÐGr   c                 ó†  — |€t         }d}t        j                  «       |z   }| j                  «       }	 	 |t        j                  «       z
  }|dk  rd|f| j	                  |«       S | j	                  |«       	 | j                  t        t        «      t        |«      z
  «      }|sd|f| j	                  |«       S ||z  }t        |«      }|t        u rd|f| j	                  |«       S |t        u rd|f| j	                  |«       S ŒÏ# t        t        f$ r d|fcY | j	                  |«       S w xY w# | j	                  |«       w xY w)a/  Read up to the length of the preface from a blocking socket.

    Returns ``(matched, consumed_bytes)``. The caller owns the consumed bytes
    and must hand them to whichever protocol wins, since they have already
    left the socket.

    The timeout is an absolute budget for the whole preface, checked before
    every read. ``socket.settimeout()`` alone would bound each call instead,
    which lets a client trickle one byte per interval and hold the connection
    (and, on gthread, a pool slot) for as many intervals as the preface has
    bytes.
    r   Tr   F)ÚH2C_PREFACE_TIMEOUTÚtimeÚ	monotonicÚ
gettimeoutÚ
settimeoutÚrecvr   r	   ÚTimeoutErrorÚOSErrorr   r   r   )ÚsockÚtimeoutr   ÚdeadlineÚoriginalÚ	remainingÚchunkÚstates           r   Úread_preface_blockingr?   ^   s>  € ð €ä%ˆØ
€CÜ�~‰~Ó 'Ñ)€HØ�‰Ó €Hð"ØØ ¤4§>¡>Ó#3Ñ3ˆIØ˜AŠ~Ø˜c�zð 	�‰˜Õ!ð �O‰O˜IÔ&ð"ØŸ	™	¤#¤kÓ"2´S¸³XÑ"=Ó>�ñ Ø˜c�zð 	�‰˜Õ!ð �5‰LˆCÜ! #Ó&ˆEØœ‰~Ø˜S�yð 	�‰˜Õ!ð œÑ Ø˜c�zà�‰˜Õ!ð% øô !¤'Ð*ò "Ø˜c�zÑ!ð 	�‰˜Õ!ð"ûð 	�‰˜Õ!úsG   ³ D- Á%D- Á7*D Â!D- Â8D- Ã%D- ÄD- ÄD*ÄD- Ä)D*Ä*D- Ä-E sG   HTTP/1.1 101 Switching Protocols
Connection: Upgrade
Upgrade: h2c

c                 óX  — d}g }d}| j                   D ]d  \  }}|dk(  r|j                  «       j                  «       }Œ*|dk(  r |j                  |j                  «       «       ŒO|dk(  sŒU|j                  «       }Œf |dk7  ryt	        |«      dk7  ryd|vsd	|vry|d
   j                  d«      S )aN  Return the HTTP2-Settings payload if this request asks for h2c.

    RFC 7540 section 3.2: the request must name ``h2c`` in Upgrade and carry
    exactly one HTTP2-Settings header, itself named in Connection. Returns
    None when the request is not a well-formed upgrade attempt, so the caller
    simply carries on with HTTP/1.
    NÚ ÚUPGRADEzHTTP2-SETTINGSÚ
CONNECTIONÚh2cé   zhttp2-settingsr-   r   zlatin-1)ÚheadersÚstripÚlowerÚappendr   Úencode)Úreqr-   ÚsettingsÚ
connectionÚnameÚvalues         r   Úupgrade_settingsrP   �   s·   € ð €GØ€HØ€JØ—{‘{ò '‰ˆˆeØ�9ÒØ—k‘k“m×)Ñ)Ó+‰GØÐ%Ò%Ø�O‰O˜EŸK™K›MÕ*Ø�\Ó!ØŸ™›‰Jð'ð �%ÒØä
ˆ8ƒ}˜ÒØØ˜zÑ)¨Y¸jÑ-HØØ�A‰;×Ñ˜iÓ(Ð(r   )N)Ú__doc__r1   Úgunicorn.http.messager   r	   r0   r   r   r   r   r   r#   r)   r+   r.   r?   ÚUPGRADE_101rP   © r   r   ú<module>rU      sf   ðñ
ó å 3ð 2€ð Ð à€Ø
€Ø€ò	@òòòHò4òHó&"ðVð ó)r   