+
                                a  R t0 t ^ RIHt ^ RIt^RIHt ^RIHt ^RIH	t	 ^RI
Ht Rt] ^ k Rt] ^k R	t] ^k Rt] ^k  ! R R
]	4      tR# )    )defaultdictN)	policyrep)TERuleQuery)CheckerModule)ConfigSetDescriptorexempt_write_domainexempt_load_domainexempt_fileReadOnlyKernelModulesc                   (  a a ] tR t^t oRtRt]! ]]]	34      t
]]P                  ,          ! RRRR7      t]]P                  ,          ! RRRR7      t]]P                  ,          ! RRRR7      tV3R lV 3R lltV3R	 lR
 ltV3R lR ltRtVtV ;t# )r   z>Checker module for asserting all kernel modules are read-only.ro_kmodslookup_type_or_attrFT)strictexpandc                Z   < V ^8  d   QhRS[ P                  RS[RS[S[S[3,          RR/# )   policy	checknameconfigreturnN)r   SELinuxPolicystrdict)format__classdict__s   "=/usr/lib64/python3.14/site-packages/setools/checker/rokmod.py__annotate__"ReadOnlyKernelModules.__annotate__$   s9     : :y66 :3 :c3h:,0:    c                   < \         SV `  WV4       VP                  \        4      V n        VP                  \
        4      V n        VP                  \        4      V n        R # )N)	super__init__getEXEMPT_WRITEr   EXEMPT_FILEr
   EXEMPT_LOADr	   )selfr   r   r   	__class__s   &&&&r   r"   ReadOnlyKernelModules.__init__$   sG     	F3#)::l#; !::k2"(**["9r   c                n   < V ^8  d   QhRS[ S[P                  S[S[P                  ,          3,          /# r   r   )r   r   TypesetAVRule)r   r   s   "r   r   r   ,   s-      k)..#iFVFVBW2W&X r   c                   V P                   P                  R 4       V P                   P                  RV P                  : 24       \        V P                  RR	R
R7      p\
        \        P                  \        \        P                  ,          3,          ! \        4      pVP                  4        EF  p\        VP                  P                  4       4      V P                  ,
          p\        VP                  P                  4       4      V P                  ,
          pWT,          pV'       d	   V'       g!   V P                   P                  RV 24       K  V Fo  pV P                   P                  RV RV 24       \        V\        P                  4      '       g   Q R\!        V4       R24       hW&,          P#                  V4       Kq  	  EK  	  V# )z'Collecting list of kernel module types.zself.exempt_load_domain=ruletypetclasspermsz!Ignoring empty module_load rule: zDetermined z is a kernel module by: zExpected AVRule, got z, this is an SETools bug.allow)system)module_load)logdebugr	   r   r   r   r   r,   r-   r.   resultssourcer   targetr
   
isinstancetypeadd)r'   query	collectedrulesourcestargetsts   &      r   _collect_kernel_mods*ReadOnlyKernelModules._collect_kernel_mods,   sc   @A2$11345DKK%/#."24
  	I4D4D0E EFsK	MMOD$++,,./$2I2IIG$++,,./$2B2BBG G '!B4&IJQC/GvNO!$	(8(899 R+DJ<7PQR9  &	  $$ r   c                D   < V ^8  d   QhRS[ S[P                  ,          /# r+   )listr   r,   )r   r   s   "r   r   r   I   s     ' 'T)..) 'r   c                x   V P                   P                  R 4       \        V P                  RRRR7      pV P	                  4       p\        \        4      pVP                  4        F  pV P                   P                  RV R24       WAn	        \        VP                  4       4       FV  p\        VP                  P                  4       4      V P                  ,
          '       g   K?  W4,          P                  V4       KX  	  K  	  \        VP                  4       4       F  pV P                   P#                  R4       V P                   P#                  RV R24       V P                   P#                  R4       \        W$,          4       F"  pV P                   P#                  RV R	24       K$  	  V P                   P#                  R
4       \        W4,          4       F  pV P%                  \'        V4      4       K  	  K  	  V P                   P                  \)        V4       R24       \        VP                  4       4      # )z&Checking kernel modules are read-only.r0   zChecking if kernel module type z is writable.z
------------

zKernel module type z is writable.

zModule load rules:
z    * 
z
Write rules:
z failure(s)r4   )file)writeappend)r8   infor   r   rF   r   r-   keysr9   r<   sortedr:   r;   r   r   r?   outputrM   log_failr   len)r'   r@   kmodsfailures	kmod_typerB   s   &     r   runReadOnlyKernelModules.runI   s   >?DKK%/#,"57 ))+s#IHHNN<YK}UV$Lu}}/t{{))+,t/G/GGG'++D1 0	 &  0IKK23KK 3I;>OPQKK45u/0!!F4&"34 1 KK01x23c$i( 4 1 	#h-45hmmo&&r   )r
   r	   r   )__name__
__module____qualname____firstlineno____doc__
check_type	frozensetr$   r&   r%   check_configr   r   r,   r   r
   r	   r"   rF   rX   __static_attributes____classdictcell____classcell__)r(   r   s   @@r   r   r      s     HJlKEFL-inn=eD:%inn5eD:K,Y^^<eD:: : :' ' 'r   c                z   V ^8  d   Qh/ ^ \         9   d   \        P                  \        ,          ;R&   ^\         9   d   \        P                  \        ,          ;R&   ^\         9   d   \        P                  \        ,          ;R&   ^\         9   d,   \        P                  \        \        R3,          ,          ;R&   # )r   r$   r&   r%   .__all__)__conditional_annotations__typingFinalr   tuple)r   s   "r   r   r      s}     # # 8 7fll3 7 $ 6 5V\\# 5 $ / .V\\# . $ D CeCHo	& C $r   )r   )rg   collectionsr   rh    r   terulequeryr   checkermoduler   descriptorsr   r$   r&   r%   rf   r   r   )rg   s   @r   <module>rp      sK    $ #   % ( ,"7 7!5 5!. .)C CQ'M Q'r   