+
    	:il  c                   s(   R t ^ RIt^ RIt^ RIt^ RIHt ^ RIHt R.t	 ]P                  t
 ! R R4      tR#   ] d    ^ RIt^ RIt]P                  ! 4       ^,          t]P                   ! R]4      '       d   ^t
 LP]P                   ! R]4      '       d   ^t
 Lm]P                   ! R]4      '       d   ^t
 L]P                   ! R]4      '       d   ^t
 L]P                   ! R	]4      '       d   ^@t
 L]P                   ! R
]4      '       d   Rt
 L^t
 Li ; i)zAccess control for setroubleshoot. For now this is only used for
determining which users are allowed to connect to the server: see
UserServerAccess for more information.N)
get_config)syslog_traceServerAccessz^i\d86z^x86_64z^(ppc|powerpc)z^(alpha|mips)z^sparcz^parisci@  c                   sb   a  ] tR t^Bt o RtRRR/RRR//tR tR tR	 tR
 t	R t
R tR tRtV tR# )r   z[
Determine if a user should be given access to the server based
on the configuration file.
ZclientwildcardTZfix_cmdFc                s    / V n         \        \        P                   P                  4       4       F!  pV P	                  V4      V P                   V&   K#  	  R # )N)
privilegesZlistr   Zkeysinit_privilegeself	privileges   & B/usr/lib/python3.14/site-packages/setroubleshoot/access_control.py__init__ZServerAccess.__init__L   sB     l55::<=I)-)<)<Y)GDOOI& >    c                s    \        R RV,          4      P                  R4       Uu. uF  q"P                  4       NK  	  ppV# u upi )Zaccessz%s_usersZ,)r    ZsplitZstrip)r   r   ZnameZ	cfg_namess   &&  r	   r   ZServerAccess.init_privilegeW   sK    *y*@AGGLNL '+ZZ\L 	 NNs   Ac                s    V\         P                  9   pV'       d   R # \        P                  ! \        P                  RV,          4       R# )Tzunknown access privilege (%s)F)r   r   syslogLOG_ERR)r   r   Zvalids   && r	   valid_privilegeZServerAccess.valid_privilege\   s3    \444fnn&E	&QRr   c                s    V P                  V4      '       g   R # \        P                  V,          R,          '       g   R # RV P                  V,          9   # )Fr   Z*)r   r   r   r   s   &&r	   unrestricted_privilegeZ#ServerAccess.unrestricted_privilegec   sC    ##I..&&y1*==dooi000r   c                s    V P                  V4      '       g   R# V P                  V4      '       d   R# W P                  V,          9   d   R# R# )zk
Determine if the given user name is allowed access.
Returns True if access should be given, False if not.
FT)r   r   r   )r   r   Zusers   &&&r	   user_allowedZServerAccess.user_allowedk   sA    
 ##I..&&y11??9--r   c                s    V P                  V4      '       g   R# V P                  V4      '       d   R#  ^ RIpVP                  V4      pT P                  Y^ ,          4      #   \         d     R# i ; i)z
Determine if the given uid is allowed access. No error
is returned if the uid is invalid (False is returned).
Returns True if access should be given, False if not.
FTN)r   r   pwdZgetpwuidZKeyErrorr   )r   r   uidr   Z	pwd_entrys   &&&  r	   uid_allowedZServerAccess.uid_allowedz   so     ##I..&&y11	S)I   aL99  	 	s   A! !A0/A0c                s4   R;p;r4 VP                   pV\        P                  8w  d   W43#  Rp\        P
                  ! V4      p VP                  \        P                  \        V4      p\        P                  ! Wh4      w  r#pVR8X  d   RpVR8X  d   RpVR8X  d   RpW43#   \         d     Li ; i  \         d[   p	R;p;r4^ RIp
\        T
P                  4       4       \        P                  ! \        P                  RT	,          4        Rp	?	Y43# Rp	?	ii ; i)zObtain the effective user and group IDs of the process on
the other end of a socket. SO_PEERCRED is used so the information
returned is generally trustworthy (though root processes can
impersonate any uid/gid).NZIIIzget_credentials(): %si)familySocketZAF_UNIXAttributeErrorstructZcalcsizeZ
getsockoptZ
SOL_SOCKETSO_PEERCREDZunpackZ	Exception	tracebackr   Z
format_excr   r   )r   ZsockZpidr   Zgidr   Zformat_ucredZsizeof_ucredZucredZer   s   &&         r	   get_credentialsZServerAccess.get_credentials   s    c	[[F'x ( |4	GOOF$5$5{LQE"MM,>MCcbybyby x-  		   	G""C"#--/0MM&..*AA*EFFx	Gs+   #B! AB2 !B/.B/2D=ADD)r   N)Z__name__Z
__module__Z__qualname__Z__firstlineno____doc__r   r
   r   r   r   r   r   r   Z__static_attributes__Z__classdictcell__)Z__classdict__s   @r	   r   r   B   sP     
 Z.j%0J	H
1:," "r   )r   r   Zsocketr   r   Zsetroubleshoot.configr    Zsetroubleshoot.utilr   Z__all__r   r   ZosZreZunameZmachineZsearchr   ) r   r	   <module>r      s   (*    , , $$K,p p+  hhjmG	yyG$$	:w	'	'	$g	.	.	#W	-	-	9g	&	&	:w	'	'#sW   7 ?D7D;DDD1D5DDD+D/DDDD