+
                                ^ RI t ^ RIt^ t^t^t^t^t^t. RmOtR]R]R]R]R]R]/t	 ! R R	4      t
 ! R
 R]
4      t ! R R]
4      tRnR ltRoR ltRpR ltR t ! R R]4      t ! R R]4      t ! R R]4      t ! R R4      t ! R R]4      t ! R R]4      t ! R R]4      t ! R  R!]4      t ! R" R#]4      t ! R$ R%]4      t ! R& R']4      t ! R( R)]4      t ! R* R+]4      t ! R, R-]4      t ! R. R/]4      t  ! R0 R1]4      t! ! R2 R3]4      t" ! R4 R5]4      t# ! R6 R7]4      t$ ! R8 R9]4      t% ! R: R;]4      t& ! R< R=]4      t' ! R> R?]4      t( ! R@ RA]4      t) ! RB RC]4      t* ! RD RE]4      t+ ! RF RG]4      t, ! RH RI]4      t- ! RJ RK]4      t. ! RL RM]4      t/ ! RN RO]4      t0RP t1 ! RQ RR]4      t2 ! RS RT]4      t3 ! RU RV]4      t4 ! RW RX]4      t5 ! RY RZ]4      t6 ! R[ R\]4      t7 ! R] R^]4      t8 ! R_ R`]4      t9 ! Ra Rb]4      t: ! Rc Rd]4      t; ! Re Rf]4      t< ! Rg Rh4      t= ! Ri Rj4      t> ! Rk Rl4      t?R# )q    Nsourcetargetobject
permissionroledestinationc                   *   a  ] tR t^4t o RR ltRtV tR# )
PolicyBaseNc                0    R V n         R V n        RV n        R # )NF)parentcommentgen_cilselfr   s   &&7/usr/lib/python3.14/site-packages/sepolgen/refpolicy.py__init__PolicyBase.__init__5   s        )r   r   r   N)__name__
__module____qualname____firstlineno__r   __static_attributes____classdictcell____classdict__s   @r   r
   r
   4   s      r   r
   c                      a  ] tR t^:t o RtRR ltR tR tR tR t	R t
R	 tR
 tR tR tR tR tR tR tR tR tR tR tR tR tR tR tR tRtV tR# )Nodea  Base class objects produced from parsing the reference policy.

The Node class is used as the base class for any non-leaf
object produced by parsing the reference policy. This object
should contain a reference to its parent (or None for a top-level
object) and 0 or more children.

The general idea here is to have a very simple tree structure. Children
are not separated out by type. Instead the tree structure represents
fairly closely the real structure of the policy statements.

The object should be iterable - by default over all children but
subclasses are free to provide additional iterators over a subset
of their childre (see Interface for example).
Nc                >    \         P                  W4       . V n        R # r   )r
   r   childrenr   s   &&r   r   Node.__init__K   s    D)r   c                ,    \        V P                  4      # r   )iterr!   r   s   &r   __iter__Node.__iter__O   s    DMM""r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )
isinstancer   xs   &r   <lambda>Node.nodes.<locals>.<lambda>X       
1d 3r   filterwalktreer%   s   &r   nodes
Node.nodesW       3Xd^DDr   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   Moduler+   s   &r   r-   Node.modules.<locals>.<lambda>[       
1f 5r   r0   r%   s   &r   modulesNode.modulesZ       5x~FFr   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   	Interfacer+   s   &r   r-   !Node.interfaces.<locals>.<lambda>^       
1i 8r   r0   r%   s   &r   
interfacesNode.interfaces]       8(4.IIr   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   Templater+   s   &r   r-    Node.templates.<locals>.<lambda>a       
1h 7r   r0   r%   s   &r   	templatesNode.templates`       7$HHr   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   SupportMacrosr+   s   &r   r-   %Node.support_macros.<locals>.<lambda>d       
1m <r   r0   r%   s   &r   support_macrosNode.support_macrosc       <htnMMr   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   ModuleDeclarationr+   s   &r   r-   *Node.module_declarations.<locals>.<lambda>i   s    
1.? @r   r0   r%   s   &r   module_declarationsNode.module_declarationsh   s    @(4.QQr   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   InterfaceCallr+   s   &r   r-   &Node.interface_calls.<locals>.<lambda>l   rR   r   r0   r%   s   &r   interface_callsNode.interface_callsk   rU   r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   AVRuler+   s   &r   r-   Node.avrules.<locals>.<lambda>o   r:   r   r0   r%   s   &r   avrulesNode.avrulesn   r=   r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   	AVExtRuler+   s   &r   r-   !Node.avextrules.<locals>.<lambda>r   rB   r   r0   r%   s   &r   
avextrulesNode.avextrulesq   rE   r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   TypeRuler+   s   &r   r-    Node.typerules.<locals>.<lambda>u   rJ   r   r0   r%   s   &r   	typerulesNode.typerulest   rM   r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   	TypeBoundr+   s   &r   r-   !Node.typebounds.<locals>.<lambda>x   rB   r   r0   r%   s   &r   
typeboundsNode.typeboundsw   rE   r   c                .    \        R \        V 4      4      # )zAIterate over all of the TypeAttribute children of this Interface.c                 "    \        V \        4      # r   )r*   TypeAttributer+   s   &r   r-   %Node.typeattributes.<locals>.<lambda>|   rR   r   r0   r%   s   &r   typeattributesNode.typeattributesz       <htnMMr   c                .    \        R \        V 4      4      # )zAIterate over all of the RoleAttribute children of this Interface.c                 "    \        V \        4      # r   )r*   RoleAttributer+   s   &r   r-   %Node.roleattributes.<locals>.<lambda>   rR   r   r0   r%   s   &r   roleattributesNode.roleattributes~   r   r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   Requirer+   s   &r   r-   Node.requires.<locals>.<lambda>   s    
1g 6r   r0   r%   s   &r   requiresNode.requires   s    6GGr   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   Roler+   s   &r   r-   Node.roles.<locals>.<lambda>   r/   r   r0   r%   s   &r   roles
Node.roles   r5   r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   	RoleAllowr+   s   &r   r-   "Node.role_allows.<locals>.<lambda>   rB   r   r0   r%   s   &r   role_allowsNode.role_allows   rE   r   c                .    \        R  \        V 4      4      # )c                 "    \        V \        4      # r   )r*   RoleTyper+   s   &r   r-   !Node.role_types.<locals>.<lambda>   rJ   r   r0   r%   s   &r   
role_typesNode.role_types   rM   r   c                    V P                   '       d2   \        V P                   4      R ,           V P                  4       ,           # V P                  4       # 
r   str	to_stringr%   s   &r   __str__Node.__str__   8    <<<t||$t+dnn.>>>>>##r   c                \    R V P                   P                  : RV P                  4       : R2# <(z)>	__class__r   r   r%   s   &r   __repr__Node.__repr__       !^^44dnn6FGGr   c                    R #   r%   s   &r   r   Node.to_string       r   c                    Wn         R # r   r   r   r   s   &&r   set_gen_cilNode.set_gen_cil       r   )r!   r   r   )r   r   r   r   __doc__r   r&   r3   r;   rC   rK   rS   rZ   r`   rf   rl   rr   rx   r~   r   r   r   r   r   r   r   r   r   r   r   r   s   @r   r   r   :   s      #EGJIN
RNGJIJNNHEJI$H r   r   c                   B   a  ] tR t^t o RR ltR tR tR tR tRt	V t
R# )	LeafNc                0    \         P                  W4       R # r   )r
   r   r   s   &&r   r   Leaf.__init__   s    D)r   c                    V P                   '       d2   \        V P                   4      R ,           V P                  4       ,           # V P                  4       # r   r   r%   s   &r   r   Leaf.__str__   r   r   c                \    R V P                   P                  : RV P                  4       : R2# r   r   r%   s   &r   r   Leaf.__repr__   r   r   c                    R # r   r   r%   s   &r   r   Leaf.to_string   r   r   c                    Wn         R # r   r   r   s   &&r   r   Leaf.set_gen_cil   r   r   r   r   )r   r   r   r   r   r   r   r   r   r   r   r   s   @r   r   r      s$     *$H r   r   c              #    "   V'       d   RpM^ pV ^ 3.p\        V4      ^ 8  d   VP                  V4      w  rgV'       d   Wg3x  MVx  \        V\        4      '       g   KM  . p\        VP                  4      ^,
          p	V	^ 8  d^   Ve$   \        VP                  V	,          V4      '       d,   VP                  VP                  V	,          V^,           34       V	^,          p	Kd  VP                  V4       K  R# 5i)a}  Iterate over a Node and its Children.

The walktree function iterates over a tree containing Nodes and
leaf objects. The iteration can perform a depth first or a breadth
first traversal of the tree (controlled by the depthfirst
parameter. The passed in node will be returned.

This function will only work correctly for trees - arbitrary graphs
will likely cause infinite looping.
N)lenpopr*   r   r!   appendextend)
node
depthfirst	showdepthtypeindexstackcurdepthitemsis
   &&&&      r   r2   r2      s      AYKE
e*q.YYu%
*I c4  ECLL!A%Aq&<:cll1ot#D#DLL#,,q/519!=>QLL# s   AC9"BC9c              #  V   "   V  F  pVe   \        W!4      '       g   K  Vx  K   	  R# 5i)a  Iterate over the direct children of a Node.

The walktree function iterates over the children of a Node.
Unlike walktree it does note return the passed in node or
the children of any Node objects (that is, it does not go
beyond the current level in the tree).
N)r*   )r   r   r,   s   && r   walknoder      s%      <:a..G s   )
)c                    \        V 4      pRpV^8  d   \        R4      hRP                  V 4      pV^8X  d   V# V^ ,          R,           V,           R,           V^,          ,           # )zConvert a set (or any sequence type) into a string representation
formatted to match SELinux space separated list conventions.

For example the list ['read', 'write'] would be converted into:
'{ read write }'
r   z"cannot convert 0 len set to string r   
ValueErrorjoin)scontlr   s   &&  r   list_to_space_strr      s_     	AA
C1u=>>
((1+CAv
Aw}s"S(4722r   c                 ^    \        V 4      pV^8  d   \        R4      hRP                  V 4      # )   z(cannot convert 0 len set to comma string, r   )r   r   s   & r   list_to_comma_strr      s,    AA1uCDD99Q<r   c                   6   a  ] tR tRt o RR ltR tR tRtV tR# )IdSet   Nc                z    V'       d   \         P                  W4       M\         P                  V 4       R V n        R# FN)setr   
compliment)r   lists   &&r   r   IdSet.__init__  s$    LL$LLr   c                *    \        \        V 4      4      # r   )r   sortedr%   s   &r   to_space_strIdSet.to_space_str       ..r   c                *    \        \        V 4      4      # r   )r   r   r%   s   &r   to_comma_strIdSet.to_comma_str  r   r   )r   r   )	r   r   r   r   r   r   r   r   r   r   s   @r   r   r      s      // /r   r   c                   D   a  ] tR tRt o RtR	R ltR tR tR
R ltRt	V t
R# )SecurityContexti  z;An SELinux security context with optional MCS / MLS fields.Nc                    \         P                  W4       RV n        RV n        RV n        RV n        Ve   V P                  V4       R# R# )zCreate a SecurityContext object, optionally from a string.

Parameters:
   [context] - string representing a security context. Same format
      as a string passed to the from_string method.
r   N)r   r   userr   r   levelfrom_string)r   contextr   s   &&&r   r   SecurityContext.__init__  sE     	d#			
W% r   c                   \         P                  ! V4      pV^ ,          ^ 8X  d
   V^,          pVP                  R4      p\        V4      ^8  d   \	        RV,          4      hV^ ,          V n        V^,          V n        V^,          V n        \        V4      ^8  d    RP                  VR,          4      V n	        R# RV n	        R# )zParse a string representing a context into a SecurityContext.

The string should be in the standard format - e.g.,
'user:role:type:level'.

Raises ValueError if the string is not parsable as a security context.
:z)context string [%s] not in a valid format:   NNN)
selinuxselinux_trans_to_raw_contextsplitr   r   r   r   r   r   r   )r   r   rawfieldss   &&  r   r   SecurityContext.from_string  s     227;q6Q;!fGs#v;?H7RSS1I	1I	1I	v;?&*-DJDJr   c                    V P                   VP                   8H  ;'       d\    V P                  VP                  8H  ;'       d;    V P                  VP                  8H  ;'       d    V P                  VP                  8H  # )zCompare two SecurityContext objects - all fields must be exactly the
the same for the comparison to work. It is possible for the level fields
to be semantically the same yet syntactically different - in this case
this function will return false.
)r   r   r   r   )r   others   &&r   __eq__SecurityContext.__eq__9  si     yyEJJ& ) )yyEJJ&) )yyEJJ&) ) zzU[[(	)r   c                @   V P                   V P                  V P                  .pV P                  fC   Vf-   \        P
                  ! 4       ^8X  d   VP                  R4       M-VP                  V4       MVP                  V P                  4       RP                  V4      # )am  Return a string representing this security context.

By default, the string will contain a MCS / MLS level
potentially from the default which is passed in if none was
set.

Arguments:
   default_level - the default level to use if self.level is an
     empty string.

Returns:
   A string representing the security context in the form
      'user:role:type:level'.
s0r  )r   r   r   r   r  is_selinux_mls_enabledr   r   )r   default_levelr	  s   && r   r   SecurityContext.to_stringD  su     ))TYY		2::$113q8MM$'m,MM$**%xxr   )r   r   r   r   NNr   )r   r   r   r   r   r   r   r  r   r   r   r   s   @r   r   r     s!     E&4	)   r   r   c                   .   a  ] tR tRt o RtRR ltRtV tR# )ObjectClassi^  a  SELinux object class and permissions.

This class is a basic representation of an SELinux object
class - it does not represent separate common permissions -
just the union of the common and class specific permissions.
It is meant to be convenient for policy generation.
Nc                Z    \         P                  W4       Wn        \        4       V n        R # r   )r   r   namer   permsr   r  r   s   &&&r   r   ObjectClass.__init__f  s    d#	W
r   r  r  r   N)r   r   r   r   r   r   r   r   r   s   @r   r  r  ^  s      r   r  c                   P   a  ] tR tRt o RtRR ltR tR tRR ltR t	R	 t
R
tV tR# )XpermSetik  a  Extended permission set.

This class represents one or more extended permissions
represented by numeric values or ranges of values. The
.complement attribute is used to specify all permission
except those specified.

Two xperm set can be merged using the .extend() method.
c                     Wn         . V n        R # r   
complementranges)r   r"  s   &&r   r   XpermSet.__init__u  s    $r   c                X   V P                   P                  4        ^ pV\        V P                   4      8  d   V^,           \        V P                   4      8  d   V P                   V^,           ,          ^ ,          V P                   V,          ^,          ^,           8:  d   V P                   V,          ^ ,          \        V P                   V,          ^,          V P                   V^,           ,          ^,          4      3V P                   V&   V P                   V^,            K   V^,          pEK  R# )z0Ensure that ranges are not overlapping.
        N)r#  sortr   max)r   r   s   & r   __normalize_rangesXpermSet.__normalize_rangesy  s     	#dkk""a%#dkk**;;q1u%a(DKKN1,=,AA&*kk!nQ&7T[[^A=N=A[[Q=OPQ=R:T &UDKKNAE*FA #r   c                p    V P                   P                  VP                   4       V P                  4        R# )z%Add ranges from an xperm set
        N)r#  r   _XpermSet__normalize_rangesr   r   s   &&r   r   XpermSet.extend  s&     	188$!r   Nc                j    Vf   TpV P                   P                  W34       V P                  4        R# )z7Add value of range of values to the xperm set.
        N)r#  r   r+  )r   minimummaximums   &&&r   addXpermSet.add  s/     ?GG-.!r   c                   V P                   '       g   R # V P                  '       d   RMR p\        V P                   4      ^8X  db   V P                   ^ ,          ^ ,          V P                   ^ ,          ^,          8X  d+   V\        V P                   ^ ,          ^ ,          4      ,           # \	        R V P                   4      pV: RRP                  V4      : R2# )r   z~ c                     V ^ ,          V ^,          8X  d   \        V ^ ,          4      # \        V ^ ,          4      : R\        V ^,          4      : 2# )r   -hexr+   s   &r   r-   $XpermSet.to_string.<locals>.<lambda>  s<    !A$!A$,S1Y^s1Q4yRUVWXYVZR[<^^r   z{ r   z })r#  r"  r   r7  mapr   r   complvalss   &  r   r   XpermSet.to_string  s    {{{R t{{q T[[^A%6$++a.:K%K3t{{1~a0111^`d`k`kl"CHHTN33r   c                    V P                   '       g   R # V P                  '       d   RMRp\        R V P                   4      pRV^ ,          : RP                  V4      : V^,          : R2# )r   )c                     V ^ ,          V ^,          8X  d   \        V ^ ,          4      # R\        V ^ ,          4      : R\        V ^,          4      : R2# )r   z(range r   r?  r6  r+   s   &r   r-   (XpermSet.to_string_cil.<locals>.<lambda>  sA    !A$!A$,S1Yf,sSTUVSWyZ]^_`a^bZc<ffr   r   r   )znot (r?  r   r   )r#  r"  r9  r   r:  s   &  r   to_string_cilXpermSet.to_string_cil  sP    {{{"&///xfhlhshst"1Xsxx~uQxx@@r   r!  )Fr   )r   r   r   r   r   r   r+  r   r1  r   rC  r   r   r   s   @r   r  r  k  s/      ""4A Ar   r  c                   4   a  ] tR tRt o RtRR ltR tRtV tR# )r|   i  zSSElinux typeattribute statement.

This class represents a typeattribute statement.
Nc                \    \         P                  W4       R V n        \        4       V n        R# r  )r   r   r   r   
attributesr   s   &&r   r   TypeAttribute.__init__  s    d#	'r   c                   V P                   '       dD   R pV P                   F/  pVRV,          ,          pVRV: RV P                  : R2,          pK1  	  V# RV P                  : RV P                  P                  4       : R2# )r   z(typeattribute %s)
(typeattributeset r   )
ztypeattribute ;)r   rG  r   r   r   r   as   &  r   r   TypeAttribute.to_string  sk    <<<A__+a//Q		BB % H  .2YY8T8T8VWWr   )rG  r   r   	r   r   r   r   r   r   r   r   r   r   s   @r   r|   r|     s     "
X Xr   r|   c                   4   a  ] tR tRt o RtRR ltR tRtV tR# )r   i  zSSElinux roleattribute statement.

This class represents a roleattribute statement.
Nc                \    \         P                  W4       R V n        \        4       V n        R# r  )r   r   r   r   r   r   s   &&r   r   RoleAttribute.__init__  s    d#	#gr   c                   V P                   '       dD   R pV P                   F/  pVRV,          ,          pVRV: RV P                  : R2,          pK1  	  V# RV P                  : RV P                  P	                  4       : R2# )r   z(roleattribute %s)
z(roleattributeset r   rK  zroleattribute rL  )r   r   r   r   r   rM  s   &  r   r   RoleAttribute.to_string  so    <<<A((+a//Q		BB ) H  .2YY8K8K8X8X8Z[[r   )r   r   r   rP  r   s   @r   r   r     s     &
\ \r   r   c                   0   a  ] tR tRt o RR ltR tRtV tR# )r   i  Nc                \    \         P                  W4       R V n        \        4       V n        R# r  r   r   r   r   typesr   s   &&r   r   Role.__init__      d#	W
r   c                   V P                   '       dE   R V P                  ,          pV P                   F  pVRV P                  : RV: R2,          pK!  	  V# RpV P                   F  pVRV P                  : RV: R2,          pK!  	  V# )z
(role %s)

(roletype r   rK  r   role  types ;
)r   r   rY  r   r   ts   &  r   r   Role.to_string  sj    <<<		)AZZTYY::  HAZZdii;;  Hr   r   rY  r   r   r   r   r   r   r   r   r   r   s   @r   r   r     s     

 
r   r   c                   0   a  ] tR tRt o RR ltR tRtV tR# )Typei  Nc                x    \         P                  W4       Wn        \        4       V n        \        4       V n        R # r   )r   r   r  r   rG  aliasesr  s   &&&r   r   Type.__init__  s%    d#	'wr   c                L   V P                   '       dt   R V P                  ,          pV P                   F  pVRV: RV P                  : R2,          pK!  	  V P                   F  pVRV: RV P                  : R2,          pK!  	  V# RV P                  ,          p\	        V P                  4      ^ 8  d)   VRV P                  P                  4       ,          ,           p\	        V P                  4      ^ 8  d)   VRV P                  P                  4       ,          ,           pVR,           # )	z
(type %s)
(typealiasactual r   rK  rJ  ztype %szalias %s, %srL  )r   r  ri  rG  r   r   r   rM  s   &  r   r   Type.to_string  s    <<<		)A\\AtyyAA "__Q		BB %HDII%A4<< 1$
T\\%>%>%@@@4??#a'!=!=!???s7Nr   )ri  rG  r  r  re  r   s   @r   rg  rg    s      r   rg  c                   0   a  ] tR tRt o RR ltR tRtV tR# )	TypeAliasi  Nc                \    \         P                  W4       R V n        \        4       V n        R# r  )r   r   r   r   ri  r   s   &&r   r   TypeAlias.__init__  s    d#	wr   c                   V P                   '       dD   R pV P                   F/  pVRV,          ,          pVRV: RV P                  : R2,          pK1  	  V# RV P                  : RV P                  P                  4       : R2# )r   z(typealias %s)
rl  r   rK  z
typealias z alias rL  )r   ri  r   r   rM  s   &  r   r   TypeAlias.to_string	  sk    <<<A\\'!++AtyyAA " H  04yy$,,:S:S:UVVr   )ri  r   r   re  r   s   @r   rp  rp    s     
W Wr   rp  c                   0   a  ] tR tRt o RR ltR tRtV tR# )	Attributei  Nc                <    \         P                  W4       Wn        R # r   r   r   r  r  s   &&&r   r   Attribute.__init__      d#	r   c                r    V P                   '       d   R V P                  ,          # RV P                  ,          # )zattribute %s;z(typeattribute %s)r   r  r%   s   &r   r   Attribute.to_string  s)    <<<"TYY..'$))33r   r  r  re  r   s   @r   rv  rv         4 4r   rv  c                   0   a  ] tR tRt o RR ltR tRtV tR# )Attribute_Rolei  Nc                <    \         P                  W4       Wn        R # r   rx  r  s   &&&r   r   Attribute_Role.__init__  rz  r   c                r    V P                   '       d   R V P                  ,          # RV P                  ,          # )z(roleattribute %s)zattribute_role %s;r|  r%   s   &r   r   Attribute_Role.to_string#  s)    <<<'$))33'$))33r   r~  r  re  r   s   @r   r  r    r  r   r  c                   P   a  ] tR tRt o Rt^ t^t^t^tR	R lt	R t
R tR tRtV tR# )
rd   i,  a  SELinux access vector (AV) rule.

The AVRule class represents all varieties of AV rules including
allow, dontaudit, and auditallow (indicated by the flags self.ALLOW,
self.DONTAUDIT, and self.AUDITALLOW respectively).

The source and target types, object classes, and perms are all represented
by sets containing strings. Sets are used to make it simple to add
strings repeatedly while avoiding duplicates.

No checking is done to make certain that the symbols are valid or
consistent (e.g., perms that don't match the object classes). It is
even possible to put invalid types like '$1' into the rules to allow
storage of the reference policy interfaces.
Nc                    \         P                  W4       \        4       V n        \        4       V n        \        4       V n        \        4       V n        V P                  V n        V'       d   V P                  V4       R # R # r   )
r   r   r   	src_types	tgt_typesobj_classesr  ALLOW	rule_typefrom_av)r   avr   s   &&&r   r   AVRule.__init__A  sR    d# 7W
LL r   c                    V P                   V P                  8X  d   R # V P                   V P                  8X  d   R# V P                   V P                  8X  d   R# V P                   V P                  8X  d   R# R# )allow	dontaudit
auditallow
neverallowN)r  r  	DONTAUDIT
AUDITALLOW
NEVERALLOWr%   s   &r   __rule_type_strAVRule.__rule_type_strK  sS    >>TZZ'^^t~~-^^t.^^t. /r   c                   V P                   P                  VP                  4       VP                  VP                  8X  d   V P                  P                  R4       M%V P                  P                  VP                  4       V P
                  P                  VP                  4       V P                  P                  VP                  4       R# )z9Add the access from an access vector to this allow
rule.
r   N)	r  r1  src_typetgt_typer  r  	obj_classr  update)r   r  s   &&r   r  AVRule.from_avU  s     	2;;';;"++%NNv&NNr{{+R\\*

"((#r   c                2   V P                   '       d   RpV P                   Fn  pV P                   F[  pV P                   FH  pVRV P	                  4       : RV: RV: RV: RRP                  V P                  4      : R2,          pKJ  	  K]  	  Kp  	  V# V P	                  4       : RV P                  P                  4       : RV P                  P                  4       : RV P                  P                  4       : RV P                  P                  4       : R2
# )zReturn a string representation of the rule
that is a valid policy language representation (assuming
that the types, object class, etc. are valid).
r   r   r    (z)))r  rL  )r   r  r  r  _AVRule__rule_type_strr   r  r   r   r   srctgtobjs   &    r   r   AVRule.to_stringa  s    
 <<<A~~>>C#//t7K7K7M7:C7:xx

7KM M  0 * & H(,(<(<(>(,(C(C(E(,(C(C(E(,(8(8(E(E(G(,

(?(?(A	C Cr   )r  r  r  r  r  r  )r   r   r   r   r   r  r  r  r  r   r  r  r   r   r   r   s   @r   rd   rd   ,  s;      EIJJ 
$C Cr   rd   c                   V   a  ] tR tRt o Rt^ t^t^t^tR
R lt	R t
R tR tR tR	tV tR# )rj   iv  aR  Extended permission access vector rule.

The AVExtRule class represents allowxperm, dontauditxperm,
auditallowxperm, and neverallowxperm rules.

The source and target types, and object classes are represented
by sets containing strings. The operation is a single string,
e.g. 'ioctl'. Extended permissions are represented by an XpermSet.
Nc                   \         P                  W4       \        4       V n        \        4       V n        \        4       V n        V P                  V n        \        4       V n	        W n
        V'       d   V P                  W4       R # R # r   )r   r   r   r  r  r  
ALLOWXPERMr  r  xperms	operationr  )r   r  opr   s   &&&&r   r   AVExtRule.__init__  sW    d# 7jLL  r   c                    V P                   V P                  8X  d   R # V P                   V P                  8X  d   R# V P                   V P                  8X  d   R# V P                   V P                  8X  d   R# R# )
allowxpermdontauditxpermauditallowxpermneverallowxpermNr  r  DONTAUDITXPERMAUDITALLOWXPERMNEVERALLOWXPERMr%   s   &r   r  AVExtRule.__rule_type_str  sY    >>T__,^^t222#^^t333$^^t333$ 4r   c                    V P                   V P                  8X  d   R # V P                   V P                  8X  d   R# V P                   V P                  8X  d   R# V P                   V P                  8X  d   R# R# )allowx
dontauditxauditallowxneverallowxNr  r%   s   &r   __rule_type_str_cilAVExtRule.__rule_type_str_cil  sY    >>T__,^^t222^^t333 ^^t333  4r   c                   V P                   P                  VP                  4       VP                  VP                  8X  d   V P                  P                  R 4       M%V P                  P                  VP                  4       V P
                  P                  VP                  4       W n        VP                  V,          V n        R# )r   N)	r  r1  r  r  r  r  r  r  r  )r   r  r  s   &&&r   r  AVExtRule.from_av  s|    2;;';;"++%NNv&NNr{{+R\\*iimr   c                h   V P                   '       d   RpV P                   F{  pV P                   Fh  pV P                   FU  pVRV P	                  4       : RV: RV: RV P
                  : RV: RV P                  P                  4       : R2,          pKW  	  Kj  	  K}  	  V# V P                  4       : RV P                  P                  4       : RV P                  P                  4       : RV P                  P                  4       : RV P
                  : RV P                  P                  4       : R2# )zReturn a string representation of the rule that is
a valid policy language representation (assuming that
the types, object class, etc. are valid).
r   r   r   r  z))r  rL  )r   r  r  r  _AVExtRule__rule_type_str_cilr  r  rC  _AVExtRule__rule_type_strr   r   r  s   &    r   r   AVExtRule.to_string  s    
 <<<A~~>>C#//8P8P8R8;S8<8;8<8Q8Q8S	U U  0 * & H+/+?+?+A+/>>+F+F+H+/>>+F+F+H+/+;+;+H+H+J+/>>+/;;+@+@+BD Dr   )r  r  r  r  r  r  )NNN)r   r   r   r   r   r  r  r  r  r   r  r  r  r   r   r   r   s   @r   rj   rj   v  s@      JNOO	!%!$D Dr   rj   c                   L   a  ] tR tRt o Rt^ t^t^tR	R ltR t	R t
R tRtV tR# )
rp   i  zSELinux type rules.

This class is very similar to the AVRule class, but is for representing
the type rules (type_trans, type_change, and type_member). The major
difference is the lack of perms and only and sing destination type.
Nc                    \         P                  W4       \        4       V n        \        4       V n        \        4       V n        R V n        V P                  V n        R# r  )	r   r   r   r  r  r  	dest_typeTYPE_TRANSITIONr  r   s   &&r   r   TypeRule.__init__  s>    d# 7--r   c                z    V P                   V P                  8X  d   R # V P                   V P                  8X  d   R# R# )type_transitiontype_changetype_memberr  r  TYPE_CHANGEr%   s   &r   r  TypeRule.__rule_type_str  s/    >>T111$^^t///  r   c                z    V P                   V P                  8X  d   R # V P                   V P                  8X  d   R# R# )typetransition
typechange
typememberr  r%   s   &r   r  TypeRule.__rule_type_str_cil  s/    >>T111#^^t///r   c                    V P                   '       dx   R V P                  4       : RV P                  P                  4       : RV P                  P                  4       : RV P
                  P                  4       : RV P                  : R2# V P                  4       : RV P                  P                  4       : RV P                  P                  4       : RV P
                  P                  4       : RV P                  : R2
# )r   r   r?  r  rL  )r   _TypeRule__rule_type_str_cilr  r   r  r  r  _TypeRule__rule_type_strr%   s   &r   r   TypeRule.to_string  s    <<<)-)A)A)C)-)D)D)F)-)D)D)F)-)9)9)F)F)H)-	9 9 )-(<(<(>(,(C(C(E(,(C(C(E(,(8(8(E(E(G(,	8 8r   )r  r  r  r  r  r   )r   r   r   r   r   r  r  TYPE_MEMBERr   r  r  r   r   r   r   s   @r   rp   rp     s4      OKK.! 8 8r   rp   c                   4   a  ] tR tRt o RtRR ltR tRtV tR# )rv   i  zKSElinux typebound statement.

This class represents a typebound statement.
Nc                \    \         P                  W4       R V n        \        4       V n        R# r  )r   r   r   r   r  r   s   &&r   r   TypeBound.__init__  s    d#	r   c                    V P                   '       d4   R pV P                   F  pVRV P                  : RV: R2,          pK!  	  V# RV P                  : RV P                  P                  4       : R2# )r   z(typebounds r   r?  ztypebounds rL  )r   r  r   r   ra  s   &  r   r   TypeBound.to_string  sY    <<<A^^TYY:: $H	  +/))T^^5P5P5RSSr   )r  r   r   rP  r   s   @r   rv   rv     s     !
T Tr   rv   c                   0   a  ] tR tRt o RR ltR tRtV tR# )r   i  Nc                l    \         P                  W4       \        4       V n        \        4       V n        R # r   )r   r   r   	src_roles	tgt_rolesr   s   &&r   r   RoleAllow.__init__  s     d#r   c                   V P                   '       d=   R pV P                   F(  pV P                   F  pVRV: RV: R2,          pK  	  K*  	  V# RV P                  P                  4       : RV P                  P                  4       : R2# )r   z(roleallow r   r?  zallow rL  )r   r  r  r   )r   r   r  r  s   &   r   r   RoleAllow.to_string  su    <<<A~~>>CS99A * & H  &*^^%@%@%B%)^^%@%@%BD Dr   )r  r  r   re  r   s   @r   r   r     s     !
	D 	Dr   r   c                   0   a  ] tR tRt o RR ltR tRtV tR# )r   i  Nc                \    \         P                  W4       R V n        \        4       V n        R# r  rX  r   s   &&r   r   RoleType.__init__  r[  r   c                    R pV P                    FO  pV P                  '       d   VRV P                  : RV: R2,          pK3  VRV P                  : RV: R2,          pKQ  	  V# )r   r]  r   rK  r^  r_  r`  )rY  r   r   ra  s   &  r   r   RoleType.to_string#  sK    A|||TYY::dii;;	 
 r   rd  r   re  r   s   @r   r   r     s     
 r   r   c                   0   a  ] tR tRt o RR ltR tRtV tR# )rX   i,  Nc                Z    \         P                  W4       R V n        R V n        RV n        R# r   FN)r   r   r  version	refpolicyr   s   &&r   r   ModuleDeclaration.__init__-  s#    d#	r   c                    V P                   '       d   R # V P                  '       d    RV P                  : RV P                  : R2# RV P                  : RV P                  : R2# )r   zpolicy_module(r   r?  zmodule r   rL  )r   r  r  r  r%   s   &r   r   ModuleDeclaration.to_string3  sD    <<<~~~26))T\\JJ  +/))T\\BBr   )r  r  r  r   re  r   s   @r   rX   rX   ,  s     C Cr   rX   c                   0   a  ] tR tRt o RR ltR tRtV tR# )Conditionali<  Nc                >    \         P                  W4       . V n        R # r   r   r   	cond_exprr   s   &&r   r   Conditional.__init__=      d#r   c                >    R \        V P                  RR7      ,          # )z[If %s]r   rB  r   r  r%   s   &r   r   Conditional.to_stringA  s    ,T^^(KKKr   r  r   re  r   s   @r   r  r  <  s     L Lr   r  c                   0   a  ] tR tRt o RR ltR tRtV tR# )BooliD  Nc                L    \         P                  W4       R V n        RV n        R# r  )r   r   r  stater   s   &&r   r   Bool.__init__E  s    d#	
r   c                p    R V P                   ,          pVP                  '       d
   VR,           # VR,           # )zbool %s truefalser  r  r,  s   & r   r   Bool.to_stringJ  s-    "777v:w;r   r	  r   re  r   s   @r   r  r  D  s     
 r   r  c                   0   a  ] tR tRt o RR ltR tRtV tR# )
InitialSidiQ  Nc                L    \         P                  W4       R V n        RV n        R# r  )r   r   r  r   r   s   &&r   __initInitialSid.__initR      d#	r   c                    V P                   '       d)   R V P                  : R\        V P                  4      : R2# RV P                  : R\        V P                  4      : 2# )z(sid r   r?  zsid )r   r  r   r   r%   s   &r   r   InitialSid.to_stringW  sB    <<<$(IIs4<</@AA  #'))S->??r   )r   r  r   )r   r   r   r   _InitialSid__initr   r   r   r   s   @r   r  r  Q  s     
@ @r   r  c                   0   a  ] tR tRt o RR ltR tRtV tR# )GenfsConi]  Nc                Z    \         P                  W4       R V n        R V n        RV n        R# r  )r   r   
filesystempathr   r   s   &&r   r   GenfsCon.__init__^  s#    d#	r   c                    V P                   '       d7   R V P                  : RV P                  : R\        V P                  4      : R2# RV P                  : RV P                  : R\        V P                  4      : 2# )z
(genfscon r   r?  z	genfscon )r   r  r  r   r   r%   s   &r   r   GenfsCon.to_stringd  sN    <<<,0OOTYYDLLHYZZ  +///499c$,,FWXXr   )r   r  r  r   re  r   s   @r   r  r  ]  s     Y Yr   r  c                   <   a  ] tR tRt o ^t^t^tRR ltR tRt	V t
R# )FilesystemUseij  Nc                n    \         P                  W4       V P                  V n        R V n        RV n        R# r  )r   r   XATTRr   r  r   r   s   &&r   r   FilesystemUse.__init__o  s'    d#JJ	r   c                <   R pV P                   '       d   V P                  V P                  8X  d   RpM;V P                  V P                  8X  d   RpMV P                  V P                  8X  d   RpRV: RV P
                  : R\        V P                  4      : R2# V P                  V P                  8X  d   RpM;V P                  V P                  8X  d   RpMV P                  V P                  8X  d   R	pV: RV P
                  : R\        V P                  4      : R
2# )r   zfsuse xattr zfsuse trans zfsuse task r   r   r?  zfs_use_xattr zfs_use_trans zfs_use_task rL  )r   r   r  TRANSTASKr  r   r   r,  s   & r   r   FilesystemUse.to_stringu  s    <<<yyDJJ&"djj("dii'!#$doos4<<7HIIyyDJJ&#djj(#dii'""#T__c$,,6GHHr   )r   r  r   r   )r   r   r   r   r  r"  r#  r   r   r   r   r   s   @r   r  r  j  s%     EEDI Ir   r  c                   0   a  ] tR tRt o RR ltR tRtV tR# )PortConi  Nc                Z    \         P                  W4       R V n        R V n        RV n        R# r  )r   r   	port_typeport_numberr   r   s   &&r   r   PortCon.__init__  s$    d#r   c                    V P                   '       d7   R V P                  : RV P                  : R\        V P                  4      : R2# RV P                  : RV P                  : R\        V P                  4      : 2# )z	(portcon r   r?  zportcon )r   r(  r)  r   r   r%   s   &r   r   PortCon.to_string  sU    <<<+/>>4;K;KSQUQ]Q]M^__  *.9I9I3t||K\]]r   )r   r)  r(  r   re  r   s   @r   r&  r&    s     ^ ^r   r&  c                   0   a  ] tR tRt o RR ltR tRtV tR# )NodeConi  Nc                Z    \         P                  W4       R V n        R V n        RV n        R# r  )r   r   startendr   r   s   &&r   r   NodeCon.__init__  s#    d#
r   c                    V P                   '       d7   R V P                  : RV P                  : R\        V P                  4      : R2# RV P                  : RV P                  : R\        V P                  4      : 2# )z	(nodecon r   r?  znodecon )r   r0  r1  r   r   r%   s   &r   r   NodeCon.to_string  sN    <<<+/::txxT\\ARSS  *.TXXs4<<?PQQr   )r   r1  r0  r   re  r   s   @r   r.  r.    s     R Rr   r.  c                   0   a  ] tR tRt o RR ltR tRtV tR# )NetifConi  Nc                Z    \         P                  W4       R V n        RV n        RV n        R# r  )r   r   	interfaceinterface_contextpacket_contextr   s   &&r   r   NetifCon.__init__  s%    d#!%"r   c                    V P                   '       d@   R V P                  : R\        V P                  4      : R\        V P                  4      : R2# RV P                  : R\        V P                  4      : R\        V P                  4      : 2# )z
(netifcon r   r?  z	netifcon )r   r8  r   r9  r:  r%   s   &r   r   NetifCon.to_string  sn    <<<,0NNC@V@V<W,/0C0C,DF F  +/..#d>T>T:U*-d.A.A*BD Dr   )r8  r9  r:  r   re  r   s   @r   r6  r6    s     #D Dr   r6  c                   0   a  ] tR tRt o RR ltR tRtV tR# )PirqConi  Nc                L    \         P                  W4       R V n        RV n        R# r  )r   r   pirq_numberr   r   s   &&r   r   PirqCon.__init__  s    d#r   c                    V P                   '       d)   R V P                  : R\        V P                  4      : R2# RV P                  : R\        V P                  4      : 2# )z	(pirqcon r   r?  zpirqcon )r   rA  r   r   r%   s   &r   r   PirqCon.to_string  sF    <<<(,(8(8#dll:KLL  '+&6&6DLL8IJJr   )r   rA  r   re  r   s   @r   r?  r?         
K Kr   r?  c                   0   a  ] tR tRt o RR ltR tRtV tR# )IomemConi  Nc                L    \         P                  W4       R V n        RV n        R# r  )r   r   
device_memr   r   s   &&r   r   IomemCon.__init__  s    d#r   c                    V P                   '       d)   R V P                  : R\        V P                  4      : R2# RV P                  : R\        V P                  4      : 2# )z
(iomemcon r   r?  z	iomemcon )r   rI  r   r   r%   s   &r   r   IomemCon.to_string  sB    <<<)-#dll:KLL  (,DLL8IJJr   )r   rI  r   re  r   s   @r   rG  rG    rE  r   rG  c                   0   a  ] tR tRt o RR ltR tRtV tR# )	IoportConi  Nc                L    \         P                  W4       R V n        RV n        R# r  )r   r   ioportr   r   s   &&r   r   IoportCon.__init__      d#r   c                    V P                   '       d)   R V P                  : R\        V P                  4      : R2# RV P                  : R\        V P                  4      : 2# )z(ioportcon r   r?  z
ioportcon )r   rP  r   r   r%   s   &r   r   IoportCon.to_string  sB    <<<*.++s4<<7HII  )-S5FGGr   )r   rP  r   re  r   s   @r   rN  rN    s     
H Hr   rN  c                   0   a  ] tR tRt o RR ltR tRtV tR# )PciDeviceConi  Nc                L    \         P                  W4       R V n        RV n        R# r  )r   r   devicer   r   s   &&r   r   PciDeviceCon.__init__  rR  r   c                    V P                   '       d)   R V P                  : R\        V P                  4      : R2# RV P                  : R\        V P                  4      : 2# )z(pcidevicecon r   r?  zpcidevicecon )r   rX  r   r   r%   s   &r   r   PciDeviceCon.to_string  sB    <<<-1[[#dll:KLL  ,0;;DLL8IJJr   )r   rX  r   re  r   s   @r   rV  rV    rE  r   rV  c                   0   a  ] tR tRt o RR ltR tRtV tR# )DeviceTreeConi  Nc                L    \         P                  W4       R V n        RV n        R# r  )r   r   r  r   r   s   &&r   r   DeviceTreeCon.__init__  r  r   c                    V P                   '       d)   R V P                  : R\        V P                  4      : R2# RV P                  : R\        V P                  4      : 2# )z(devicetreecon r   r?  zdevicetreecon )r   r  r   r   r%   s   &r   r   DeviceTreeCon.to_string  sB    <<<.2iiT\\9JKK  -1IIs4<<7HIIr   )r   r  r   re  r   s   @r   r]  r]    s     
J Jr   r]  c                     \        V R R7       F=  w  rRp\        V4       F  pVR,           pK  	  \        V\        V4      ,           4       K?  	  R# )T)r   r   	N)r2   rangeprintr   )headr   r   r   r   s   &    r   
print_treerg    sA    5uADA a#d)m	 6r   c                   0   a  ] tR tRt o RR ltR tRtV tR# )Headersi  Nc                0    \         P                  W4       R # r   r   r   r   s   &&r   r   Headers.__init__      d#r   c                    R # )z	[Headers]r   r%   s   &r   r   Headers.to_string  s    r   r   r   re  r   s   @r   ri  ri    s     $ r   ri  c                   0   a  ] tR tRt o RR ltR tRtV tR# )r8   i  Nc                0    \         P                  W4       R # r   rk  r   s   &&r   r   Module.__init__  rm  r   c                    R # r   r   r%   s   &r   r   Module.to_string  r   r   r   r   re  r   s   @r   r8   r8     s     $ r   r8   c                   4   a  ] tR tRt o RtRR ltR tRtV tR# )r@   i  ziA reference policy interface definition.

This class represents a reference policy interface definition.
Nc                <    \         P                  W4       Wn        R # r   r   r   r  r  s   &&&r   r   Interface.__init__  rz  r   c                (    R V P                   ,          # )z[Interface name: %s]r~  r%   s   &r   r   Interface.to_string  s    %		11r   r~  r  rP  r   s   @r   r@   r@     s     2 2r   r@   c                   0   a  ] tR tRt o RR ltR tRtV tR# )TunablePolicyi  Nc                >    \         P                  W4       . V n        R # r   r  r   s   &&r   r   TunablePolicy.__init__  r  r   c                >    R \        V P                  RR7      ,          # )z[Tunable Policy %s]r  rB  r  r%   s   &r   r   TunablePolicy.to_string  s    $'8h'WWWr   r   r   re  r   s   @r   r|  r|    s     X Xr   r|  c                   0   a  ] tR tRt o RR ltR tRtV tR# )rH   i  Nc                <    \         P                  W4       Wn        R # r   rw  r  s   &&&r   r   Template.__init__  rz  r   c                (    R V P                   ,          # )z[Template name: %s]r~  r%   s   &r   r   Template.to_string!  s    $tyy00r   r~  r  re  r   s   @r   rH   rH     s     1 1r   rH   c                   0   a  ] tR tRt o RR ltR tRtV tR# )IfDefi$  Nc                <    \         P                  W4       Wn        R # r   rw  r  s   &&&r   r   IfDef.__init__%  rz  r   c                (    R V P                   ,          # )z[Ifdef name: %s]r~  r%   s   &r   r   IfDef.to_string)  s    !DII--r   r~  r  re  r   s   @r   r  r  $  s     . .r   r  c                   0   a  ] tR tRt o RR ltR tRtV tR# )IfElsei,  Nc                <    \         P                  W4       Wn        R # r   rw  r  s   &&&r   r   IfElse.__init__-  rz  r   c                (    R V P                   ,          # )z[Ifelse name: %s]r~  r%   s   &r   r   IfElse.to_string1  s    "TYY..r   r~  r  re  r   s   @r   r  r  ,  s     / /r   r  c                   6   a  ] tR tRt o RR ltR tR tRtV tR# )r^   i4  Nc                X    \         P                  W4       Wn        . V n        . V n        R # r   )r   r   ifnameargscomments)r   r  r   s   &&&r   r   InterfaceCall.__init__5  s!    d#	r   c                   V P                   VP                   8w  d   R # \        V P                  4      \        VP                  4      8w  d   R # \        V P                  VP                  4       F  w  r#W#8w  g   K   R # 	  R# )FT)r  r   r  zip)r   r  rN  bs   &&  r   matchesInterfaceCall.matches;  sX    ;;%,,&tyy>S_,tyy%**-CAv . r   c                    R V P                   ,          p^ pV P                   FP  p\        V\        4      '       d   \	        V4      pMTpV^ 8w  d   VRV,          ,           pMW,           pV^,          pKR  	  VR,           # )z%s(rm  r?  )r  r  r*   r   r   )r   r   r   rN  r   s   &    r   r   InterfaceCall.to_stringE  so    DKKA!T""'*Av$GFA  3wr   )r  r  r  r  )	r   r   r   r   r   r  r   r   r   r   s   @r   r^   r^   4  s      r   r^   c                   0   a  ] tR tRt o RR ltR tRtV tR# )OptionalPolicyiU  Nc                0    \         P                  W4       R # r   rk  r   s   &&r   r   OptionalPolicy.__init__V  rm  r   c                    R # )z[Optional Policy]r   r%   s   &r   r   OptionalPolicy.to_stringY  s    "r   r   r   re  r   s   @r   r  r  U  s     $# #r   r  c                   H   a  ] tR tRt o R
R ltR tR tR tR tR t	R	t
V tR# )rP   i\  Nc                >    \         P                  W4       R V n        R # r   )r   r   r9  r   s   &&r   r   SupportMacros.__init__]  s    d#r   c                    R # )z[Support Macros]r   r%   s   &r   r   SupportMacros.to_stringa  s    !r   c                    \        4       pWP                  9   d;   V P                  V4       F#  pVP                  V P	                  V4      4       K%  	  V# VP                  V4       V# r   )r   r9  by_namer  _SupportMacros__expand_permr1  )r   permr   ps   &&  r   __expand_permSupportMacros.__expand_permd  sX     E88\\$'++A./ (  EE$Kr   c                    / V n         V  FX  p\        4       pVP                   F#  pVP                  V P	                  V4      4       K%  	  W P                   VP
                  &   KZ  	  R # r   )r9  r   r  r  r  r  )r   r,   	exp_permsr  s   &   r   	__gen_mapSupportMacros.__gen_mapp  sQ    AI  !3!3D!9:  (HHQVV	 r   c                l    V P                   '       g   V P                  4        V P                   V,          # r   r9  _SupportMacros__gen_mapr   r  s   &&r   r  SupportMacros.by_namex  s#    xxxNNxx~r   c                b    V P                   '       g   V P                  4        WP                   9   # r   r  r  s   &&r   has_keySupportMacros.has_key}  s"    xxxNNxxr   )r9  r   )r   r   r   r   r   r   r  r  r  r  r   r   r   s   @r   rP   rP   \  s(     "
)
   r   rP   c                   6   a  ] tR tRt o RR ltR tR tRtV tR# )r   i  Nc                    \         P                  W4       \        4       V n        / V n        \        4       V n        \        4       V n        \        4       V n        R # r   )r   r   r   rY  r  r   datausersr   s   &&r   r   Require.__init__  s:    d#W
W
G	W
r   c                p    V P                   P                  V\        4       4      pVP                  V4       R # r   )r  
setdefaultr   r  )r   r  r  r  s   &&& r   add_obj_classRequire.add_obj_class  s'    ''	57;	r   c                p   . pV P                   '       dh   V P                   F  pVP                  R V,          4       K  	  V P                   F  pVP                  RV,          4       K  	  RP	                  V4      # VP                  R4       V P                   F  pVP                  RV,          4       K  	  V P
                  P                  4        F-  w  rEVP                  RV: RVP                  4       : R24       K/  	  V P                   F  pVP                  RV,          4       K  	  V P                   F  pVP                  R	V,          4       K  	  V P                   F  pVP                  R
V,          4       K  	  VP                  R4       \        V4      ^8X  d   R# RP	                  V4      # )z%(typeattributeset cil_gen_require %s)z%(roleattributeset cil_gen_require %s)r   z	require {z		type %s;z	class r   rL  z		role %s;z		bool %s;z		user %s;}r   )r   rY  r   r   r   r  r   r   r  r  r   )r   r   r   r   r  r  boolr   s   &       r   r   Require.to_string  sG   <<<

@4GH #

@4GH # 99Q<HH[!

,- #$($4$4$:$:$< 	Y8J8J8LMN %=

,- #		,- "

,- #HHSM 1v{99Q<r   )r  r  r   rY  r  r   )	r   r   r   r   r   r  r   r   r   r   s   @r   r   r     s     
   r   r   c                   ,   a  ] tR tRt o R tR tRtV tR# )
ObjPermSeti  c                0    Wn         \        4       V n        R # r   )r  r   r  r  s   &&r   r   ObjPermSet.__init__  s    	U
r   c                \    R V P                   : RV P                  P                  4       : R2# )zdefine(`z', `z'))r  r  r   r%   s   &r   r   ObjPermSet.to_string  s    '+yy$**2I2I2KLLr   r  Nre  r   s   @r   r  r    s     M Mr   r  c                   ,   a  ] tR tRt o R tR tRtV tR# )ClassMapi  c                    Wn         W n        R # r   r  r  )r   r  r  s   &&&r   r   ClassMap.__init__  s    "
r   c                J    V P                   R ,           V P                  ,           # )z: r  r%   s   &r   r   ClassMap.to_string  s    ~~$tzz11r   r  Nre  r   s   @r   r  r    s     2 2r   r  c                   B   a  ] tR tRt o R	R ltR tR tR tR tRt	V t
R# )
Commenti  Nc                @    V'       d   Wn         M. V n         R V n        R# r   )linesr   )r   r   s   &&r   r   Comment.__init__  s    JDJr   c                   \        V P                  4      ^ 8X  d   R# . pV P                   FG  pV P                  '       d   VP                  RV,           4       K/  VP                  RV,           4       KI  	  RP	                  V4      # )r   r   rL  #r   )r   r  r   r   r   )r   outlines   &  r   r   Comment.to_string  sc     tzz?aC

<<<JJsTz*JJsTz*	 #
 99S>!r   c                    \        VP                  4      '       d:   VP                   F'  pVR 8w  g   K  V P                  P                  V4       K)  	  R# R# r  )r   r  r   )r   r  r  s   && r   mergeComment.merge  s=    u{{2:JJ%%d+ $ r   c                "    V P                  4       # r   )r   r%   s   &r   r   Comment.__str__  s    ~~r   c                    Wn         R # r   r   r   s   &&r   r   Comment.set_gen_cil  r   r   )r   r  r   )r   r   r   r   r   r   r  r   r   r   r   r   s   @r   r  r    s#     ",  r   r  )r   r   r   r   r   r   )TFNr   )){r  )@stringr  SRC_TYPETGT_TYPE	OBJ_CLASSPERMSROLE	DEST_TYPEfield_to_strstr_to_fieldr
   r   r   r2   r   r   r   r   r   r   r  r  r|   r   r   rg  rp  rv  r  rd   rj   rp   rv   r   r   rX   r  r  r  r  r  r&  r.  r6  r?  rG  rN  rV  r]  rg  ri  r8   r@   r|  rH   r  r  r^   r  rP   r   r  r  r  r   r   r   <module>r     s  (  " 		 THh8iuft]YQ
 a: aF: ,$ L
3"/C /N d N `$ BA BALXD X(\D \*4 $4 .W W 	4 	4	4T 	4HCT HCTND NDb08t 08dT T&D D"t C C L$ L4 
@ 
@Yt YID I@^d ^Rd RDt D
Kd 
K
Kt 
K
H 
H
K4 
K
JD 
Jd T 
2 
2XD X1t 1.D ./T /D B#T #$ D $ L* d * XM M2 2   r   