+
    	:i>  c                   s    R t ^ RIt^ RIt^ RIHt  ^ RI5 ^RIHt ^RIHt ^RIH	t	 ^RIH
t
 ^RIHt ^RIHt ^ t^t^t ! R	 R
4      tR]3R ltR t ! R R4      tR tR#     LQ; i)z>
classes and algorithms for the generation of SELinux policy.
N)Z*)	refpolicy)objectmodel)access)
interfaces)matching)utilc                   s   a  ] tR t^-t o RtRR ltRR ltRR lt]3R lt	R t
R tR	 tR
 tRR ltR tR tR tR tR tRtV tR# )PolicyGeneratora  Generate a reference policy module from access vectors.

PolicyGenerator generates a new reference policy module
or updates an existing module based on requested access
in the form of access vectors.

It generates allow rules and optionally module require
statements, reference policy interfaces, and extended
permission access vector rules. By default only allow rules
are generated. The methods .set_gen_refpol, .set_gen_requires
and .set_gen_xperms turns on interface generation,
requires generation, and xperms rules generation respectively.

PolicyGenerator can also optionally add comments explaining
why a particular access was allowed based on the audit
messages that generated the access. The access vectors
passed in must have the .audit_msgs field set correctly
and .explain set to SHORT|LONG_EXPLANATION to enable this
feature.

The module created by PolicyGenerator can be passed to
output.ModuleWriter to output a text representation.
Nc                s    RV n         \        V n        RV n        V'       d   Wn        M\
        P                  ! 4       V n        RV n        RV n        RV n	        RV n
        RV n        R# )zInitialize a PolicyGenerator with an optional
existing module.

If the module parameter is not None then access
will be added to the passed in module. Otherwise
a new reference policy module will be created.
NF#)ifgenNO_EXPLANATIONexplaingen_requiresmoduler    ZModule	dontauditxpermsdomainsgen_cilcomment_start)selfr      &&7/usr/lib/python3.14/site-packages/sepolgen/policygen.py__init__ZPolicyGenerator.__init__E   sV     
%! K#**,DK     c                st    V'       d   \        W4      V n        RV n        MRV n        V P                  4        R# )a  Set whether reference policy interfaces are generated.

To turn on interface generation pass in an interface set
to use for interface generation. To turn off interface
generation pass in None.

If interface generation is enabled requires generation
will also be enabled.
TN)InterfaceGeneratorr   r   "_PolicyGenerator__set_module_style)r   Zif_set	perm_maps   &&&r   set_gen_refpolZPolicyGenerator.set_gen_refpol[   s.     +F>DJ $DDJ!r   c                    Wn         R# )zSet whether module requires are generated.

Passing in true will turn on requires generation and
False will disable generation. If requires generation is
disabled interface generation will also be disabled and
can only be re-enabled via .set_gen_refpol.
N)r   )r   Zstatusr   r   set_gen_requiresZ PolicyGenerator.set_gen_requiresm   s
     #r   c                r   )z)Set whether access is explained.
        N)r
   )r   r
   r   r   set_gen_explainZPolicyGenerator.set_gen_explainw   s	     r   c                s    Wn         R # N)r   )r   r   r   r   set_gen_dontauditZ!PolicyGenerator.set_gen_dontaudit|   s    "r   c                r   )zCSet whether extended permission access vector rules
are generated.
N)r   )r   r   r   r   set_gen_xpermsZPolicyGenerator.set_gen_xperms   s	     r   c                sB    Wn         V'       d
   R V n        R# RV n        R# )Z;r   N)r   r   )r   r   r   r   set_gen_cilZPolicyGenerator.set_gen_cil   s    !$D!$Dr   c                s    V P                   '       d   R pMRpV P                  P                  4        F	  pWn        K  	  R# )TFN)r   r   module_declarationsr    )r   r    mod   &  r   Z__set_module_styleZ"PolicyGenerator.__set_module_style   s1    :::II;;224C%M 5r   c                s2   RpV P                   P                  4        F  pTpK  	  V'       g<   \        P                  ! 4       pV P                   P                  P                  ^ V4       Wn        W#n        V P                  '       d
   RVn        R# RVn        R# )z?Set the name of the module and optionally the version.
        NTF)	r   r#   r    ZModuleDeclarationchildreninsertnameversionr   )r   r(   r)   Zmr$   s   &&&  r   set_module_nameZPolicyGenerator.set_module_name   sq     ;;224CA 5++-AKK  ''1-	:::AKAKr   c                sj    V P                   '       d   \        V P                  4        V P                  # r   )r   r   )r      &r   
get_moduleZPolicyGenerator.get_module   s'    %){{r   c                sV   \         P                  ! V4      pV P                  '       d   VP                  Vn        RVn        V P                  '       dV   \         P                  ! \        WP                  R7      4      pVP                  V P                  4       \        V4      Vn        VP                  \        P                  8X  dg   V;P
                  RV P                  ,          ,          un        VP                   '       d+   V;P
                  RV P                  ,          ,          un        VP                  \        P                  8X  d+   V;P
                  RV P                  ,          ,          un        VP                  \        P"                  8X  d   \%        VP&                  4      ^8  dj   T;P
                  RV P                  : RV P                  : RR	P)                  VP&                   Uu. uF  qD^ ,          NK  	  up4      : 2,          un        MDV;P
                  RV P                  : R
VP&                  ^ ,          ^ ,          : R2,          un        VP                  \        P*                  8X  d   V;P
                  RV P                  ,          ,          un        V;P
                  RV P                  ,          ,          un        V;P
                  RV P                  ,          VP&                  ^ ,          ,           ,          un        VP&                  R,           FM  pV;P
                  RV P                  ,          ,          un        V;P
                  RV,          ,          un        KO  	   VP                  \        P,                  8X  Ed   RVP.                  9   Ed   RVP0                  9   g   RVP.                  9   Ed   V P2                  '       g%   \5        \6        RR7      ^ ,          R,          V n        . p\9        \        .\:        VP<                  \>        VP0                  \@        VP.                  /4       Uu. uF  qD\B        ,          NK  	  up F&  pWpP2                  9  g   K  VPE                  V4       K(  	  \%        V4      ^8X  dg   V;P
                  RV P                  : RVP<                  : RVP0                  : RV P                  : RR	P)                  V4      : R2,          un        Mu\%        V4      ^8  df   V;P
                  RV P                  : RVP<                  : RVP0                  : RV P                  : RR	P)                  V4      : R2,          un        V PF                  PH                  PE                  V4       R# u upi u upi     L5; i)z Add access vector rule.
         )	verbosityz1
%s!!!! This avc is allowed in the current policyzO
%s!!!! This av rule may have been overridden by an extended permission av rulez;
%s!!!! This avc has a dontaudit rule in the current policyZ
z>!!!! This avc can be allowed using one of the these booleans:
z     z, z0!!!! This avc can be allowed using the boolean 'Z'z
%s!!!! This avc is a constraint violation.  You would need to modify the attributes of either the source or target types to allow this access.z
%sConstraint rule: z
%s	:i   NNz
%sz=	Possible cause is the source %s and target %s are different.ZwriteZdirZopenZdomain)r(   typesz!!!! The source type 'z' can write to a 'z' of the following type:
Z z' of the following types:
N)%r    ZAVRuler   Z	DONTAUDIT	rule_typecommentr
   Commentexplain_accessr"   r   strtype	audit2whyZALLOWr   r   ZBOOLEANlenZdataZjoinZ
CONSTRAINTZTERULEperms	obj_classr   ZseinfoZ	ATTRIBUTEZsesearchZSCONTEXTsrc_typeZCLASSZPERMSZTCONTEXTappendr   r&   )r   avZruler1   xZreasonr/   is   &&      r   Z__add_av_ruleZPolicyGenerator.__add_av_rule   s    #>>>!^^DN<<<''r\\(RSG-w<DL77ioo%LLPSWSeSeeeLyyy ruy  vH  vH  !H  H77i)))LLZ]a]o]oooL77i'''277|arv  sE  sE  GK  GY  GY  [_  [d  [d  tv  t{  t{  e|  t{  op  hi  fj  fj  t{  e|  [}  !~  ~]a]o]oqsqxqxyzq{|}q~q~ 77i***LL  o  rv  rD  rD  D  DLLL3d6H6HHHLLLHt'9'99BGGAJFFL''"++);); ;; `ci ii &	I,,,BHH$BLL(Fbhh,>|||#))(#CA#Fw#ODL/7(BKKY^`b`l`lnsuwu}u}A~/  A/!H++/  AA,Q A u:?LL{  |N  |N  PR  P[  P[  ]_  ]i  ]i  ko  k}  k}  C  H  H  IN  O  %P  PLZ1_LL  }A  }O  }O  QS  Q\  Q\  ^`  ^j  ^j  lp  l~  l~  @D  @I  @I  JO  @P  %Q  QL 	##D)= e|( A	s:   1V6A&V$ A)V$ VV$ 3B
V$ >A5V$ V$ $V(c                s   VP                   P                  4        Fa  p\        P                  ! W4      pV P                  '       d   VP
                  Vn        V P                  P                  P                  V4       Kc  	  R# )z5Add extended permission access vector rules.
        N)
r   Zkeysr    Z	AVExtRuler   ZDONTAUDITXPERMr0   r   r&   r;   )r   r<   ZopZextrules   &&  r   Z__add_ext_av_rulesZ"PolicyGenerator.__add_ext_av_rules   sX     )).."B))"1G~~~$+$:$:!KK  ''0 #r   c                sn   V P                   '       dN   V P                   P                  WP                  4      w  r#V P                  P                  P                  V4       MTpV FM  pV P                  V4       V P                  '       g   K(  VP                  '       g   K<  V P                  V4       KO  	  R# )z:Add the access from the access vector set to this
module.
N)	r   genr
   r   r&   extend_PolicyGenerator__add_av_ruler   "_PolicyGenerator__add_ext_av_rules)r   Zav_setZ	raw_allowifcallsr<      &&   r   
add_accessZPolicyGenerator.add_access   s|     :::!%!EIKK  ''0I Br"{{{ryyy''+ r   c                sb    V F(  pV P                   P                  P                  V4       K*  	  R # r   )r   r&   r;   )r   Zrole_type_set	role_types   && r   add_role_typesZPolicyGenerator.add_role_types  s$    &IKK  ''	2 'r   )	r   r   r   r
   r   r   r   r   r   r   )NN)T)z1.0)__name__
__module____qualname____firstlineno____doc__r   r   r   SHORT_EXPLANATIONr   r    r!   r"   r   r*   r,   rA   rB   rE   rG   __static_attributes____classdictcell__Z__classdict__   @r   r   r   -   s[     .!,"$# '8 
#%& "6*p	1,*3 3r   r   c                sR  aa . oVV3R lpV\         8X  Ed@   V P                   EF%  pSP                  RVP                  ,          4       SP                  R\	        VP
                  4      : R\	        VP                  4      : R24       SP                  RVP                  : R\        P                  ! VP                  4      : R24       SP                  RVP                  : R	VP                  : R
VP                  : R24       SP                  \        P                   ! RVP"                  ,           R,           ^PRRR7      4       EK(  	  V! 4        S# V'       d   SP                  RV P$                  : RV P&                  : RV P(                  : RV P*                  P-                  4       : R2	4       \/        V P                  4      ^ 8  dP   V P                  ^ ,          pSP                  RVP                  : R	VP                  : R
VP                  : R24       V! 4        S# )an  Explain why a policy statement was generated.

Return a string containing a text explanation of
why a policy statement was generated. The string is
commented and wrapped and can be directly inserted
into a policy.

Params:
  av - access vector representing the access. Should
   have .audit_msgs set appropriately.
  verbosity - the amount of explanation provided. Should
   be set to NO_EXPLANATION, SHORT_EXPLANATION, or
   LONG_EXPLANATION.
Returns:
  list of strings - strings explaining the access or an empty
   string if verbosity=NO_EXPLANATION or there is not sufficient
   information to provide an explanation.
c                  s  < S'       g   R # SP                  R4       SP                  4        FU  p \        V P                  SP                  4      pSP                  RVP                  4       V P                  3,          4       KW  	  R # )Nz Interface options:z   %s # [%d])r;   Zallcall_interface	interfacer<   Z	to_stringZdist)matchifcallmlss     r   explain_interfacesZ*explain_access.<locals>.explain_interfaces  s]    	&'VVXE#EOORUU;FHH^v'7'7'95::&FFG r   z %sz  scontext="z" tcontext="Z"z	  class="z	" perms="z  comm="z" exe="z" path="z	message="z  z   )Zinitial_indentZsubsequent_indentz src="z" tgt="z	" class="z
", perms="z comm=")LONG_EXPLANATIONZ
audit_msgsr;   Zheaderr4   ZscontextZtcontextZtclassr    Zlist_to_space_strZaccessesZcommZexeZpathr@   textwrapZwrapZmessager:   tgt_typer9   r8   Zto_space_strr7   )r<   rV   r.   rX   ZmsgrW   s   &f&  @r   r3   r3   	  ss   & 	AH $$==CHHUSZZ'(HH#,,'S\\):< =HHjj)"="=cll"KM NHH377CHHUVHHX]];#<s#BBW[5:< = ! 	 H 
	++r{{BLL"((:O:O:QS 	T
 r}}!--"CHH#''388TUHr   c                 sB   . p. pVP                  V P                  P                  4       4       VP                  R  RR7       \        P
                  ! 4       pV P                  Vn        \        \        V4      4       EF  pW%,          P                  \        P                  8X  d(   VP                  P                  VP                  4       KP  W%,          P                  \        P                  8X  d(   VP                  P                  VP                   4       K  W%,          P                  \        P"                  8X  d(   VP                  P                  VP$                  4       K  \'        W%,          P                  4       Q h	  \        VP                  4      ^ 8  g   Q hV# )c                     V P                   # r   numZparamr+   r   <lambda>Z call_interface.<locals>.<lambda>E  s    %))r   TZkeyZreverse)r@   paramsvaluessortr    ZInterfaceCallr(   Zifnameranger7   r5   SRC_TYPEargsr;   r:   TGT_TYPEr[   	OBJ_CLASSr9   Zprint)rS   r<   rb   rg   rU   r>   s   &&    r   rR   rR   @  s   FD
MM)""))+,
KK+TK:$$&FNNFM3v;9>>Y///KKr{{+Y^^y111KKr{{+Y^^y222KKr||,&)..!1   v{{aMr   c                   s<   a  ] tR tRt o RR ltR tR tR tRtV t	R# )	r   iY  Nc                sx    Wn         V P                  V4       \        P                  ! V4      V n        . V n        R # r   )ifshack_check_ifsr   ZAccessMatchermatchercalls)r   rj   r   r   r   r   ZInterfaceGenerator.__init__Z  s.    C --i8
r   c                s   VP                   P                  4        F  p. pVP                  VP                  P                  4       4       VP	                  R  RR7       \        \        V4      4       Fy  pV^,           W4,          P                  8w  d   RVn         K  W4,          P                  \        P                  \        P                  \        P                  39  g   Kq  RVn         K  	  K  	  R# )c                 r\   r   r]   r_   r+   r   r`   Z3InterfaceGenerator.hack_check_ifs.<locals>.<lambda>h  s    %))r   Tra   FN)r   rc   r@   rb   rd   re   r7   r^   Zenabledr5   r    rf   rh   ri   )r   rj   r=   rb   r>   rD   r   rk   Z!InterfaceGenerator.hack_check_ifs`  s    
 &&(AFMM!((//+,KK3TKB3v;' Efimm+ %AI 9>>)*<*<i>P>P*3*=*=*? ? %AI (	 )r   c                sp   V P                  V4      p. pV P                   Fz  p\        VP                  4       P                  VP
                  4      pV'       d0   \        P                  ! \        VP
                  WR4      4      Vn	        VP                  We34       K|  	  . pV F  w  rhR p	V Fg  p
V
P                  V4      '       g   K  V
P                  '       d8   VP                  '       d&   V
P                  P                  VP                  4       Rp	Ki  	  V	'       d   K~  VP                  V4       K  	  W73# )FT)rT   rm   rR   ZbestrS   r<   r    r2   r3   r1   r;   ZmatchesZmerge)r   avsr.   raw_avrC   rV   rU   Zdrj   ZfoundZo_ifcalls   &&&        r   r?   ZInterfaceGenerator.genw  s    C**B#BGGI$7$7?F!*!2!2>"%%3W!XNNF<(	  "KFE##F++'''FNNN ((..v~~> E	 
 5  # {r   c                s   . pV F}  p\         P                  ! 4       pV P                  P                  V P                  W44       \        V4      '       d   V P                  P                  V4       Kl  VP                  V4       K  	  V# r   )r   Z	MatchListrl   Z
search_ifsrj   r7   rm   r;   )r   rn   ro   r<   ZansrD   r   rT   ZInterfaceGenerator.match  se    B$$&CLL##DHHb63xx

!!#&b!  r   )rm   rj   rl   r   )
rH   rI   rJ   rK   r   rk   r?   rT   rN   rO   rP   rQ   r   r   r   Y  s     ..
 
r   r   c                sJ    R pV P                  4        F  pV! V4       K  	  R# )z*Add require statements to the module.
    c                 s   \         P                  ! 4       pV P                  4        F{  pVP                  P	                  VP
                  4       VP                  P	                  VP                  4       VP                   F  pVP                  W2P                  4       K   	  K}  	  V P                  4        F1  pVP                   F  pVP                  P                  V4       K   	  K3  	  V P                  4        FM  pVP                  P                  VP                  4       VP                  P	                  VP                  4       KO  	  VP                  P!                  R 4       V P"                  P%                  ^ V4       R# )r   N)r    ZRequireZavrulesr/   ZupdateZ	src_typesZ	tgt_typesZobj_classesZadd_obj_classr8   Zinterface_callsrg   ZaddZ
role_typesZrolesZroleZdiscardr&   r'   )nodeZrZavruleZobjrU   ZargrF   s   &      r   collect_requiresZ&gen_requires.<locals>.collect_requires  s   llnFGGNN6++,GGNN6++,))\\2 * % **,F{{ C  # - *IGGKK	'GGNN9??+ + 	
Q"r   N)Znodes)r   rq   rp   r%   r   r   r     s!    #0  r   )rL   Z	itertoolsrZ   Zselinux.audit2whyr6   Zsetoolsr-   r    r   r   r   r   r   r	   rM   rY   r   r3   rR   r   r   ) r   r   <module>rr      s   (   %	         Z3 Z3x *; 5n2? ?D{	s   A$ $A(