+
     h-  c                   s    ^ RI t ^ RIt^ RIt^ RIHt ^ RIHtHtHt ^ RIH	t	 ^ RI
Ht ^ RIHtHtHt R tR t]R	8X  d
   ]! 4        R# R# )
i    N)parse_avc_file)
ENGINE_ALLENGINE_PODMANENGINE_DOCKER)version)parse)create_policyload_policygenerate_playbookc            
      sd   R \         P                  9   EdN   \        P                  ! RR7      p V P	                  R 4       V P	                  RRRRRRR	7       V P	                  R
RRRRRR	7       V P	                  RRRRRRR	7       V P	                  RRRRRRR	7       V P	                  RRRRRRR	7       V P	                  RRRRRRR	7       V P	                  RRRRR R!R	7       V P	                  R"R#RR$R%R&R	7       V P	                  R'R(RRR)R*R	7       V P	                  R+R,RRR-R.R	7       V P	                  R/R0R1R2R3R47       V P	                  R5R0R6R7R8R47       V P	                  R94       EM\        P                  ! R:R;\        P
                  R<R=7      p V P	                  R>R?R@\        RA7       V P	                  \        RBRCRD7       V P	                  RRE\        RFRGRHRI7       V P	                  RJRKRLRRMRHRN7       V P	                  RORPRRQRRR7       V P	                  RSRTRRURRR7       V P	                  RVRWRRXRRR7       V P	                  RYRZRR[RRR7       V P	                  RR\R]RR^R_7       V P	                  R"R`RaRRbRRR7       V P	                  R'RcRdRReRHRN7       V P	                  Rf\        RgRhRRHRi7       V P	                  RRjRkRRlRRR7       V P	                  RRm\        RnRoRRHRi7       V P	                  RpRq\        RrP                  RsP                  \        4      4      RtRRuRi7       V P                  4       p\        V4      # )vconfined_userz&SELinux confined user policy generator)descriptionz-az--admin_commandsZ
store_trueFZadmin_commandsz/Use administrative commands (vipw, passwd, ...))actiondefaultdesthelpz-gz--graphical_loginZgraphical_loginzUse graphical login environmentz-mz--mozilla_usageZmozilla_usagezUse mozilla firefoxz-nz--networkingZ
networkingz@Manage basic networking (ip, ifconfig, traceroute, tcpdump, ...)z-dz--security_advancedZsecurity_advancedz;Manage SELinux settings (semanage, semodule, sepolicy, ...)z-iz--security_basicZsecurity_basiczGUse read-only security-related tools (seinfo, getsebool, sesearch, ...)z-sz--sudoZsudozRun commands as root using sudoz-lz--user_loginTZ
user_loginz/Basic rules common to all users (tty, pty, ...)z-cz--ssh_connectZssh_connectzConnect over SSHz-bz--basic_commandsZbasic_commandszVUse basic commands (date, ls, ps, man, systemctl -user, journalctl -user, passwd, ...)z--levelZ?Zs0ZlevelzMLS/MCS level, defaults to "s0")Znargsr   r   r   z--rangezs0-s0:c0.c1023Zrangez+MLS/MCS range, defaults to "s0-s0:c0.c1023"Zunamez6Script generates SELinux policy for running container.zudica [confined_user]zjAdditional options:
  confined_user		Generate policy for a new confined user instead of a container policy)r
   ZprogZformatter_classZepilogz-Vz	--versionr   )r   r   zName for SELinux policy moduleContainerName)typer   r   z--container-idzRunning container IDContainerIDN)r   r   r   r   z-jz--jsonz.Load json from this file, use "-j -" for stdinJsonFile)r   requiredr   r   z--full-network-accessz$Allow container full Network access ZFullNetworkAccess)r   r   r   r   z--tty-accessz;Allow container to read and write the controlling terminal Z	TtyAccessz
--X-accessz,Allow container to communicate with Xserver ZXAccessz--virt-accessz,Allow container to communicate with libvirt Z
VirtAccessz--stream-connectz<Allow container to stream connect with given SELinux domain ZStreamConnect)r   r   r   z--load-modulesz/Load templates and module created by this tool ZLoadModulesz--capszList of capabilities, e.g "-c AUDIT_WRITE,CHOWN,DAC_OVERRIDE,FOWNER,FSETID,KILL,MKNOD,NET_BIND_SERVICE,NET_RAW,SETFCAP,SETGID,SETPCAP,SETUID,SYS_CHROOT"ZCapsz	--deviceszgList of devices the container should have access to, e.g "--devices /dev/dri/card0,/dev/dri/renderD128"ZDevices)r   r   r   r   r   z	--ansiblezBGenerate ansible playbook to deploy SELinux policy for containers Ansiblez--append-rulesz)Append more SELinux allow rules from fileFileAVCSz-ez--container-enginezQSpecify which container engine is used for the inspected container (supports: {})z, ContainerEngine-)sysZargvargparseZArgumentParserZadd_argumentZRawDescriptionHelpFormatterr   ZstrZformatZjoinr   Z
parse_argsZvars)ZparserZargss     3/usr/lib/python3.14/site-packages/udica/__main__.pyget_argsr      s   #(("((@
 	O,!B 	 	
 	"2 	 	
 	 & 	 	
 	S 	 	
 	!$N 	 	
 	!Z 	 	
 	2 	 	
 	B 	 	
 	# 	 	
 	!i 	 	
 	2 	 	
 	$> 	 	
 	G$ ((P($@@Z	
 	D+iQ;/ 	 	
 	' 	 	
 	A 	 	
 	#7$ 	 	
 	N 	 	
 	? 	 	
 	? 	 	
 	O  	 	
 	B 	 	
 	 l 	 	
 	z 	 	
 	U 	 	
 	< 	 	
 	 dkk		*% # 	 
	
 D:    c            	      s   \        4       p R V P                  4       9   d   ^ RIHp V! V 4       R# V R,          '       d   Rp\        \
        3 Fy  p \        P                  ! VRV R,          .\        P                  \        P                  R7      pVP                  4       ^ ,          pVP                  ^ 8w  d   RpT'       g   Kw  Tp M	  V'       g   \        R4       \        ^4       V R,          '       d   V R,          R8X  d    \        P                   P#                  4       pMw^ RIpVP&                  P)                  V R,          4      '       d6   \+        V R,          R	4      ;_uu_ 4       pVP#                  4       pRRR4       M\        R
4       \        ^4       V R,          '       g/   V R,          '       g     \        P                   P#                  4       p \.        P0                  ! XV R,          4      p	X	P3                  X4      p
V	P5                  V
4      pV	P7                  V
4      pV	P9                  V
4      pRpV R,          '       d   ^ RIpVP&                  P)                  V R,          4      '       dP   \+        V R,          R	4      ;_uu_ 4       p \;        VP#                  4       4      pRRR4       XP=                  4        M\        R4       \        ^4       . p\?        V	PA                  W4      4      p \C        V VVVVVV	PD                  4       \        RV R,          ,           R,           4       V R,          '       d   \G        V 4       M\I        V 4       \        RV R,          ,           R,           4       R#   \         d    Rp ELi ; i  + '       g   i     EL; i  \,         d#   p\        RT4       \        ^4        Rp?ELRp?ii ; i  \,         d#   p\        RT4       \        ^4        Rp?ELRp?ii ; i  \,         d#   p\        RT4       \        ^4        Rp?ELRp?ii ; i  + '       g   i     EL; i  \,         d#   p\        RT4       \        ^4        Rp?EL\Rp?ii ; i)r	   )create_confined_user_policyNr   Zinspect)ZstdoutZstderrz+Container with specified ID does not exits!r   r   ZrzJson file does not exists!z'Couldn't parse inspect data from stdin:r   zCouldn't parse inspect data:r   zCouldn't parse AVC file:zAVC file does not exists!zCouldn't create policy:z
Policy r   z	 created!r   z8
Restart the container with: "--security-opt label=type:z.process" parameter)%r   ZkeysZudica.confined_userr   r   r   
subprocessZPopenZPIPEZDEVNULLZcommunicateZ
returncodeZFileNotFoundErrorZprintZexitr   ZstdinZreadZos.pathZpathZisfileZopenZ	Exceptionr   Zget_engine_helperZparse_inspectZget_devicesZ
get_mountsZ	get_portsr    ZcloseZsortedZget_capsr   Zcontainer_enginer   r   )Zoptsr   Zcontainer_inspect_rawZbackendZrun_inspectZinspect_dataZosZfZeZengine_helperZcontainer_inspectZcontainer_devicesZcontainer_mountsZcontainer_portsZappend_rulesZcontainer_capss                   r   mainr      s   :D $))+%C#D)M $%}5G
$(..im)<=%??%--
  +668;))Q.#'L |(4% 6" %?@GJ
s"$'IINN$4!ww~~d:.//$z*C00A,-FFH) 10 23QtM':':	$'IINN$4!
//!4(9#:
 &334IJ%112CD$//0AB#--.?@O LJ77>>$z*++d:&,,#1!&&(#;L - GGI-.GNM223DKLN**	
 
+_-
-
;<I$D	C

	 
	 k % $#$$ 100  	;Q?GG	  ,a0Q" ! 4a8GG -,,2  '+Qs   A)M=+N:N% O P5P:Q	 =NNN"	%O0OOP O==PP2P-'P5-P22P55Q		Q6Q11Q6Z__main__)r   r   r   Zudica.parser    r   r   r   Zudica.versionr   Zudicar   Zudica.policyr   r   r   r   r   Z__name__) r   r   <module>r       sI       
 ' @ @ !  F F\~od zF r   