ó
    üÞ jy9  ã                  óT  • S r SSKJr  SSKJr  SSKJrJrJrJ	r	  SSK
Jr  SSKJrJrJr   " S S\S	S
9r " S S\S	S
9r " S S\5      r " S S\S	S
9r " S S\5      r " S S\5      r " S S\S	S
9r " S S\5      r " S S\5      r " S S\5      r " S S\S	S
9r " S S \5      r " S! S"\5      r " S# S$\S	S
9r " S% S&\5      r\	\\\\4   r " S' S(\5      r  " S) S*\5      r! " S+ S,\S	S
9r"\r# " S- S.\5      r$SGS/ jr%SHS0 jr&SIS1 jr'SJS2 jr(SKS3 jr)S4S5S6S	S5S5S7.                   SLS8 jjr*S5S5S9.           SMS: jjr+S5S5S5S;.             SNS< jjr,S5S=.         SOS> jjr-SPS? jr.1 S@kr/SQSA jr0    SRSB jr1SCSD.     SSSE jjr2      STSF jr3g5)Uz>Helpers and type definitions for sandbox mount configurations.é    )Úannotations)ÚSequence)ÚAnyÚLiteralÚ	TypedDictÚUnion)Úurlsplit)ÚSandboxProxyConfigÚSandboxProxyRuleÚSandboxProxySecretc                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)ÚMountCacheConfigé   zBOptional per-mount cache configuration supported by bucket mounts.ÚintÚmax_size_bytesÚwriteback_seconds© N©Ú__name__Ú
__module__Ú__qualname__Ú__firstlineno__Ú__doc__Ú__annotations__Ú__static_attributes__r   ó    ÚS/var/www/html/gaurav/venv/lib/python3.13/site-packages/langsmith/sandbox/_mounts.pyr   r      s   ‡ ÙLàÓØÖr   r   F)Útotalc                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)	ÚBucketMountSpecBaseé   z8Optional fields applied per bucket-backed sandbox mount.ÚboolÚ	read_onlyr   Úcacher   Nr   r   r   r   r    r       s   ‡ ÙBàƒOØÖr   r    c                  ó8   • \ rS rSr% SrS\S'   S\S'   S\S'   Srg)	ÚS3MountConfigRequiredé   z.Required S3 configuration for a sandbox mount.ÚstrÚendpoint_urlÚregionÚbucketr   Nr   r   r   r   r&   r&      s   ‡ Ù8àÓØƒKØ†Kr   r&   c                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)	ÚS3MountConfigé&   z%S3 configuration for a sandbox mount.r(   Úprefixr"   Ú
path_styler   Nr   r   r   r   r-   r-   &   s   ‡ Ù/àƒKØÖr   r-   c                  óB   • \ rS rSr% SrS\S'   S\S'   S\S'   S\S	'   S
rg)ÚS3MountSpecé-   z&S3-backed sandbox mount specification.r(   ÚidzLiteral['s3']ÚtypeÚ
mount_pathr-   Ús3r   Nr   r   r   r   r2   r2   -   s   ‡ Ù0àƒGØ
ÓØƒOØÖr   r2   c                  ó$   • \ rS rSr% SrS\S'   Srg)ÚGCSMountConfigRequiredé6   z/Required GCS configuration for a sandbox mount.r(   r+   r   Nr   r   r   r   r9   r9   6   s
   ‡ Ù9à†Kr   r9   c                  ó$   • \ rS rSr% SrS\S'   Srg)ÚGCSMountConfigé<   z&GCS configuration for a sandbox mount.r(   r/   r   Nr   r   r   r   r<   r<   <   s
   ‡ Ù0à†Kr   r<   c                  óB   • \ rS rSr% SrS\S'   S\S'   S\S'   S\S	'   S
rg)ÚGCSMountSpecéB   z'GCS-backed sandbox mount specification.r(   r4   zLiteral['gcs']r5   r6   r<   Úgcsr   Nr   r   r   r   r?   r?   B   ó   ‡ Ù1àƒGØ
ÓØƒOØ	Ör   r?   c                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)	ÚGitMountRefSpecéK   z%Git ref selected for a sandbox mount.zLiteral['branch', 'tag']r5   r(   Únamer   Nr   r   r   r   rD   rD   K   s   ‡ Ù/à
"Ó"Ø
†Ir   rD   c                  ó$   • \ rS rSr% SrS\S'   Srg)ÚGitMountConfigRequiredéR   z/Required Git configuration for a sandbox mount.r(   Ú
remote_urlr   Nr   r   r   r   rH   rH   R   s
   ‡ Ù9à†Or   rH   c                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)	ÚGitMountConfigéX   z&Git configuration for a sandbox mount.rD   Úrefr   Úrefresh_interval_secondsr   Nr   r   r   r   rL   rL   X   s   ‡ Ù0à	ÓØ!Ö!r   rL   c                  óB   • \ rS rSr% SrS\S'   S\S'   S\S'   S\S	'   S
rg)ÚGitMountSpecé_   z'Git-backed sandbox mount specification.r(   r4   zLiteral['git']r5   r6   rL   Úgitr   Nr   r   r   r   rQ   rQ   _   rB   r   rQ   c                  ó$   • \ rS rSr% SrS\S'   Srg)ÚContextHubMountConfigRequiredéh   z7Required Context Hub configuration for a sandbox mount.r(   Úrepor   Nr   r   r   r   rU   rU   h   s
   ‡ ÙAà
†Ir   rU   c                  ó$   • \ rS rSr% SrS\S'   Srg)ÚContextHubMountConfigén   z.Context Hub configuration for a sandbox mount.r"   Úinitial_pull_onlyr   Nr   r   r   r   rY   rY   n   s   ‡ Ù8àÖr   rY   c                  óB   • \ rS rSr% SrS\S'   S\S'   S\S'   S\S	'   S
rg)ÚContextHubMountSpecét   z9Read-only Context Hub-backed sandbox mount specification.r(   r4   zLiteral['contexthub']r5   r6   rY   Ú
contexthubr   Nr   r   r   r   r]   r]   t   s   ‡ ÙCàƒGØ
ÓØƒOØ%Ö%r   r]   c                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)ÚAWSMountAuthConfigé€   z>AWS credentials used by the backend to authenticate S3 mounts.r   Úaccess_key_idÚsecret_access_keyr   Nr   r   r   r   ra   ra   €   s   ‡ ÙHà%Ó%Ø)Ö)r   ra   c                  ó$   • \ rS rSr% SrS\S'   Srg)ÚGCPMountAuthConfigé‡   z?GCP credentials used by the backend to authenticate GCS mounts.r   Úservice_account_jsonr   Nr   r   r   r   rf   rf   ‡   s   ‡ ÙIà,Ö,r   rf   c                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)	ÚSandboxMountAuthConfigé�   z(Provider auth blocks for sandbox mounts.ra   Úawsrf   Úgcpr   Nr   r   r   r   rj   rj   �   s   ‡ Ù2à	ÓØ	Ör   rj   c                  ó.   • \ rS rSr% SrS\S'   S\S'   Srg)	ÚSandboxMountConfigé—   z,Public mount config sent to the sandbox API.rj   Úauthúlist[SandboxMount]Úmountsr   Nr   r   r   r   ro   ro   —   s   ‡ Ù6à
 Ó ØÖr   ro   c                ó’   • [        U [        5      (       a  U R                  5       (       d  [        U S35      eU R                  5       $ )Nz must be a non-empty string)Ú
isinstancer(   ÚstripÚ
ValueError)ÚvalueÚfields     r   Ú_require_non_empty_stringrz   ž   s8   € Ü�eœS×!Ñ!¨¯©¯©Ü˜E˜7Ð"=Ð>Ó?Ð?Ø�;‰;‹=Ðr   c                óB   • 0 nSU ;   a  U S   US'   SU ;   a  U S   US'   U$ )Nr   r   r   )r$   Úcopieds     r   Ú_copy_cache_configr}   ¤   s>   € Ø!€FØ˜5Ó Ø#(Ð)9Ñ#:ˆÐÑ Ø˜eÓ#Ø&+Ð,?Ñ&@ˆÐ"Ñ#Ø€Mr   c                ó,  • [        U [        5      (       d  [        U S35      eU R                  S5      nUS;  a  [        U S35      eU R                  S5      n[        U[        5      (       a  UR                  5       (       d  [        U S35      eX#S.$ )Nz must be a sandbox secretr5   >   ÚopaqueÚworkspace_secretz$ must use workspace_secret or opaquerx   z!.value must be a non-empty string)r5   rx   )ru   Údictrw   Úgetr(   rv   )Úsecretry   Úsecret_typerx   s       r   Ú_copy_mount_secretr…   ­   s�   € Ü�fœd×#Ñ#Ü˜E˜7Ð";Ð<Ó=Ð=Ø—*‘*˜VÓ$€KØÐ8Ó8Ü˜E˜7Ð"FÐGÓHÐHØ�J‰J�wÓ€EÜ�eœS×!Ñ!¨¯©¯©Ü˜E˜7Ð"CÐDÓEÐEØÑ0Ð0r   c                ó6  • [        U [        5      (       a  U S:X  a  [        S5      eX R                  5       :w  d  [	        S U  5       5      (       a  [        S5      e[        U 5      nUR                  S:w  d  UR                  (       d  [        S5      eUR                  (       d  UR                  (       a  [        S5      eUR                  (       a  UR                  S:X  a  [        S	5      eUR                  (       d  UR                  (       a  [        S
5      eU $ )NÚ z%remote_url must be a non-empty stringc              3  óV   #   • U H   oR                  5       =(       d    US :H  v •  M"     g7f)Ú N)Úisspace)Ú.0Úchars     r   Ú	<genexpr>Ú*_require_git_remote_url.<locals>.<genexpr>¼   s#   é € ð /Ù5?¨T�‰‹×(˜$ &™.Ô(²Zùs   ‚')z3remote_url must not contain whitespace or NUL bytesÚhttpsz(remote_url must be an absolute HTTPS URLz0remote_url must not include embedded credentialsÚ/z)remote_url must include a repository pathz-remote_url must not include query or fragment)ru   r(   rw   rv   Úanyr	   ÚschemeÚnetlocÚusernameÚpasswordÚpathÚqueryÚfragment)rJ   Úparseds     r   Ú_require_git_remote_urlrš   ¹   sÖ   € Ü�j¤#×&Ñ&¨*¸Ó*:ÜÐ@ÓAÐAØ×%Ñ%Ó'Ó'¬3ñ /Ù5?ó/÷ ,ñ ,ô ÐNÓOÐOä�jÓ!€FØ‡}�}˜Ó v§}§}ÜÐCÓDÐDØ‡‡˜&Ÿ/Ÿ/ÜÐKÓLÐLØ�;�;˜&Ÿ+™+¨Ó,ÜÐDÓEÐEØ‡|‡|�v——ÜÐHÓIÐIØÐr   c                óÄ   • [        U [        5      (       d  [        S5      eU R                  S5      nUS;  a  [        S5      eU[	        U R                  SS5      S5      S.$ )	Nzref must be a dictionaryr5   >   ÚtagÚbranchzref.type must be branch or tagrF   r‡   zref.name)r5   rF   )ru   r�   rw   r‚   rz   )rN   Úref_types     r   Ú_copy_git_refrŸ   Í   s_   € Ü�cœ4× Ñ ÜÐ3Ó4Ð4Ø�w‰w�v‹€HØÐ(Ó(ÜÐ9Ó:Ð:àÜ)¨#¯'©'°&¸"Ó*=¸zÓJñð r   z	us-east-1Nzhttps://s3.amazonaws.com)r*   r/   r)   r0   r#   r$   c        	        óÚ   • [        US5      [        US5      [        US5      US.n	Ub  [        US5      U	S'   [        U S5      S[        US5      U	S	.n
Ub  XzS
'   Ub  [        U5      U
S'   U
$ )z/Build an S3-backed sandbox mount specification.r)   r*   r+   )r)   r*   r+   r0   r/   r4   r7   r6   )r4   r5   r6   r7   r#   r$   ©rz   r}   )r4   r6   r+   r*   r/   r)   r0   r#   r$   r7   Úmounts              r   Ús3_mountr£   Ù   s�   € ô 2°,ÀÓOÜ+¨F°HÓ=Ü+¨F°HÓ=Ø ñ	€Bð ÑÜ0°¸ÓBˆˆ8‰ô (¨¨DÓ1ØÜ/°
¸LÓIØñ	€Eð ÑØ&ˆkÑØÑÜ+¨EÓ2ˆˆg‰Ø€Lr   )rN   rO   c                ó¤   • S[        U5      0nUb  [        U5      US'   Ub  US:  a  [        S5      eXES'   [        U S5      S[        US5      US	.$ )
z6Build a public Git-backed sandbox mount specification.rJ   rN   é   z+refresh_interval_seconds must be at least 1rO   r4   rS   r6   )r4   r5   r6   rS   )rš   rŸ   rw   rz   )r4   r6   rJ   rN   rO   rS   s         r   Ú	git_mountr¦   ü   st   € ð 	Ô-¨jÓ9ð€Cð �Ü" 3Ó'ˆˆE‰
ØÑ+Ø# aÓ'ÜÐJÓKÐKØ*BÐ&Ñ'ô (¨¨DÓ1ØÜ/°
¸LÓIØñ	ð r   )r/   r#   r$   c                ó¬   • S[        US5      0nUb  [        US5      US'   [        U S5      S[        US5      US.nUb  XGS'   Ub  [        U5      US'   U$ )	z/Build a GCS-backed sandbox mount specification.r+   r/   r4   rA   r6   )r4   r5   r6   rA   r#   r$   r¡   )r4   r6   r+   r/   r#   r$   rA   r¢   s           r   Ú	gcs_mountr¨     s|   € ð 	Ô+¨F°HÓ=ð€Cð ÑÜ1°&¸(ÓCˆˆH‰ô (¨¨DÓ1ØÜ/°
¸LÓIØñ	€Eð ÑØ&ˆkÑØÑÜ+¨EÓ2ˆˆg‰Ø€Lr   )r[   c                óf   • S[        US5      0nUb  X4S'   [        U S5      S[        US5      US.nU$ )ac  Build a read-only Context Hub-backed sandbox mount specification.

The repo's latest commit tree is mirrored into ``mount_path`` and kept in
sync for the sandbox's lifetime unless ``initial_pull_only`` is set. The
sync is one-way: files written under ``mount_path`` inside the sandbox are
never pushed back to the repo, and the next sync overwrites them.
rW   r[   r4   r_   r6   )r4   r5   r6   r_   )rz   )r4   r6   rW   r[   r_   r¢   s         r   Úcontext_hub_mountrª   4  sS   € ð 	Ô)¨$°Ó7ð)€Jð Ñ$Ø*;Ð&Ñ'ô (¨¨DÓ1ØÜ/°
¸LÓIØ ñ	"€Eð €Lr   c                ó^  • [        U [        5      (       d  [        U [        5      (       d  U (       d  [        S5      e/ nU  Hh  n[        U[        5      (       a  U(       d  [        S5      eUR	                  S5      nUS;  a  [        S5      e[        U5        UR                  U5        Mj     U$ )Nz5mounts must be a non-empty list of mount dictionariesr5   >   r7   rA   rS   r_   z>mount_config only supports s3, gcs, git, and contexthub mounts)ru   r�   r(   rw   r‚   Ú%_reject_provider_credentials_in_mountÚappend)rs   Ú
normalizedr¢   Ú
mount_types       r   Ú_normalize_mountsr°   Q  sš   € Ü�&œ$×Ñ¤:¨f´c×#:Ñ#:Æ&ÜÐPÓQÐQØ%'€JÛˆÜ˜%¤×&Ñ&®eÜÐTÓUÐUØ—Y‘Y˜vÓ&ˆ
ØÐ?Ó?ÜØPóð ô 	.¨eÔ4Ø×Ñ˜%Ö ñ ð Ðr   >   Ú
credentialÚcredentialsÚaccess_tokenrc   Úrefresh_tokenÚsession_tokenrd   rh   c                óö   • [        U [        5      (       a:  U R                  5        H%  u  pU[        ;   a  [	        S5      e[        U5        M'     g [        U [        5      (       a  U  H  n[        U5        M     g g )NzVprovider credentials must be supplied in mount_config.auth, not individual mount specs)ru   r�   ÚitemsÚ"_FORBIDDEN_MOUNT_CREDENTIAL_FIELDSrw   r¬   Úlist)rx   ÚkeyÚchilds      r   r¬   r¬   n  sl   € Ü�%œ×ÑØŸ+™+ž-‰JˆCØÔ8Ó8Ü ð1óð ô 2°%Ö8ò (ô 
�Eœ4×	 Ñ	 ÛˆEÜ1°%Ö8ò ð 
!r   c                óÌ  • [        U [        5      (       d  [        U [        5      (       a  [        S5      e0 nU  GH%  n[        U[        5      (       a  U(       d  [        S5      eUR	                  S5      nUS;  a  [        S5      eX1;   a  [        SU S35      eUS:X  am  UR	                  S5      n[        U[        5      (       d  [        S5      e[        UR	                  S	5      S	5      [        UR	                  S
5      S
5      S.US'   MÔ  UR	                  S5      n[        U[        5      (       d  [        S5      eS[        UR	                  S5      S5      0US'   GM(     U$ )Nz+auth must be a list of provider auth blocksr5   ¾   rl   rm   z2mount_config auth only supports aws and gcp blocksz
duplicate z auth rule in mount_configrl   z(aws mount auth must include an aws blockrc   rd   )rc   rd   rm   z'gcp mount auth must include a gcp blockrh   )ru   r�   r(   rw   r‚   r…   )rq   Úby_providerÚblockÚproviderrl   rm   s         r   Ú_normalize_mount_authrÁ   |  sS  € ô �$œ×Ñ¤¨D´#×!6Ñ!6ÜÐFÓGÐGØ*,€KÜˆÜ˜%¤×&Ñ&®eÜÐJÓKÐKØ—9‘9˜VÓ$ˆØ˜>Ó)ÜÐQÓRÐRØÓ"Ü˜z¨(¨Ð3MÐNÓOÐOØ�uÓØ—)‘)˜EÓ"ˆCÜ˜c¤4×(Ñ(Ü Ð!KÓLÐLä!3Ø—G‘G˜OÓ,¨oó"ô &8Ø—G‘GÐ/Ó0Ð2Eó&ñ	"ˆK˜Óð —)‘)˜EÓ"ˆCÜ˜c¤4×(Ñ(Ü Ð!JÓKÐKà&Ô(:Ø—G‘GÐ2Ó3Ð5Kó)ð"ˆK˜Ôñ1 ð: Ðr   r   )rq   c                ó   • [        U 5      n[        U5      nU Vs1 sH  oDS   iM	     nnSU;   a  SU;  a  [        S5      eSU;   a  SU;  a  [        S5      eSU;   a  SU;  a  [        S5      eSU;   a  SU;  a  [        S	5      eUUS
.$ s  snf )zÂBuild a high-level mount config from provider auth and mount specs.

The returned value is sent as the public ``mount_config`` field. The
backend expands provider auth into runtime proxy rules.
r5   r7   rl   z*s3 mounts require aws auth in mount_configrA   rm   z+gcs mounts require gcp auth in mount_configz7aws auth requires at least one s3 mount in mount_configz8gcp auth requires at least one gcs mount in mount_config)rq   rs   )r°   rÁ   rw   )rs   rq   Únormalized_mountsÚauth_by_providerr¢   Úmount_providerss         r   Úmount_configrÆ   ¢  sº   € ô *¨&Ó1ÐÜ,¨TÓ2ÐÙ2CÓDÑ2C¨˜V”}Ñ2C€OÐDàˆÓ 5Ð0@Ó#@ÜÐEÓFÐFØ�Ó EÐ1AÓ$AÜÐFÓGÐGØÐ Ó  T°Ó%@ÜÐRÓSÐSØÐ Ó  U°/Ó%AÜÐSÓTÐTð !Ø#ñð ùò Es   ›Bc                ó,  • Uc  gU R                  S0 5      nUR                  S/ 5      n[        U[        5      (       d  [        S5      eU HF  n[        U[        5      (       d  M  UR                  S5      nUS;   d  M3  XR;   d  M:  [        U S35      e   g)z@Reject explicit provider proxy rules owned by mount_config auth.Nrq   Úrulesz!proxy_config rules must be a listr5   r½   z> auth cannot be provided in both mount_config and proxy_config)r‚   ru   r¹   rw   r�   )rÆ   Úproxy_configrq   rÈ   ÚruleÚ	rule_types         r   Ú"validate_mount_config_proxy_configrÌ   ¿  s›   € ð
 ÑØØ×Ñ˜F BÓ'€DØ×Ñ˜W bÓ)€EÜ�eœT×"Ñ"ÜÐ<Ó=Ð=ÛˆÜ˜$¤×%Ñ%ÙØ—H‘H˜VÓ$ˆ	Ø˜Õ&¨9Õ+<ÜØ�+ð 0ð 0óð ò r   )rx   r(   ry   r(   Úreturnr(   )r$   r   rÍ   r   )rƒ   r   ry   r(   rÍ   r   )rJ   r(   rÍ   r(   )rN   rD   rÍ   rD   )r4   r(   r6   r(   r+   r(   r*   r(   r/   ú
str | Noner)   r(   r0   r"   r#   úbool | Noner$   úMountCacheConfig | NonerÍ   r2   )r4   r(   r6   r(   rJ   r(   rN   zGitMountRefSpec | NonerO   z
int | NonerÍ   rQ   )r4   r(   r6   r(   r+   r(   r/   rÎ   r#   rÏ   r$   rÐ   rÍ   r?   )
r4   r(   r6   r(   rW   r(   r[   rÏ   rÍ   r]   )rs   úSequence[SandboxMount]rÍ   rr   )rx   r   rÍ   ÚNone)rq   úSequence[SandboxMountAuth]rÍ   rj   )rs   rÑ   rq   rÓ   rÍ   ro   )rÆ   ro   rÉ   zSandboxProxyConfig | NonerÍ   rÒ   )4r   Ú
__future__r   Úcollections.abcr   Útypingr   r   r   r   Úurllib.parser	   Úlangsmith.sandbox._proxy_configr
   r   r   r   r    r&   r-   r2   r9   r<   r?   rD   rH   rL   rQ   rU   rY   r]   ÚSandboxMountra   rf   rj   ÚSandboxMountAuthro   rz   r}   r…   rš   rŸ   r£   r¦   r¨   rª   r°   r¸   r¬   rÁ   rÆ   rÌ   r   r   r   Ú<module>rÛ      s  ðÙ Då "å $ß 1Ó 1Ý !÷ñ ô�y¨ò ô˜)¨5ò ô˜Iô ôÐ)°ò ôÐ%ô ô˜Yô ôÐ+°5ò ôÐ&ô ô�iô ô˜Yô ô"Ð+°5ò "ô�9ô ô Iô ôÐ9Àò ô&˜)ô &ð �[ ,°Ð>QÐQÑR€ô*˜ô *ô-˜ô -ô˜Y¨eò ð $Ð ô˜ô ôôô	1ôô(	ð" ØØ2ØØ!Ø%)ñ àð ð ð ð ð	 ð
 ð ð ð ð ð ð ð ð ð ð #ð ð õ ðP #'Ø+/ñàðð ðð ð	ð
 
 ðð )ðð õð@ Ø!Ø%)ñàðð ðð ð	ð
 ðð ðð #ðð õðD &*ñàðð ðð ð	ð
 #ðð õô:ò"	&Ð "ô9ð#Ø
$ð#àô#ðR (*ñà"ðð %ðð õ	ð:Ø$ðà+ðð 
õr   