+
    ,i  c                   s   a  R t0 t ^ RIHt ^ RIt^RIHtHtHtHtH	t	 ^RI
HtHt Rt] ^ k  ! R R]P                  ]P                  ]P                   4      tR# )	i    )IterableN)	exceptionmixins	policyrepqueryutil)CriteriaDescriptorCriteriaSetDescriptorConstraintQueryc                   sL  a  ] tR t^t o Rt]]P                  ,          ! ]P                  R7      t]	]P                  ,          ! RR4      tRt]	]P                  ,          ! RR4      tRtRt]	]P"                  ,          ! R	R
4      tRtRtV 3R lR ltV 3R lR ltV 3R ltRtV tR# )r   a-  
Query constraint rules, (mls)constrain/(mls)validatetrans.

Parameter:
policy            The policy to query.

Keyword Parameters/Class attributes:
ruletype          The list of rule type(s) to match.
tclass            The object class(es) to match.
tclass_regex      If true, use a regular expression for
                  matching the rule's object class.
perms             The permission(s) to match.
perms_equal       If true, the permission set of the rule
                  must exactly match the permissions
                  criteria.  If false, any set intersection
                  will match.
perms_regex       If true, regular expression matching will be used
                  on the permission names instead of set logic.
role              The name of the role to match in the
                  constraint expression.
role_indirect     If true, members of an attribute will be
                  matched rather than the attribute itself.
role_regex        If true, regular expression matching will
                  be used on the role.
type_             The name of the type/attribute to match in the
                  constraint expression.
type_indirect     If true, members of an attribute will be
                  matched rather than the attribute itself.
type_regex        If true, regular expression matching will
                  be used on the type/attribute.
user              The name of the user to match in the
                  constraint expression.
user_regex        If true, regular expression matching will
                  be used on the user.
)Z
enum_class
user_regexZlookup_userF
role_regexZlookup_roleT
type_regexZlookup_type_or_attrc                s   < V ^8  d   QhRS[ S[P                  ,          S[ S[P                  ,          ,          S[ S[P                  ,          ,          RS[RS[RS[/# )   exprindirectregexreturn)Z	frozensetr   UserRoleTypeboolformat__classdict__   ">/usr/lib64/python3.14/site-packages/setools/constraintquery.py__annotate__ConstraintQuery.__annotate__?   sT     7 7	).. 9Iinn<U Uinn-!. 7CG7PT7Y]7    c                s    V'       d4   \        4       pV F"  pVP                  VP                  4       4       K$  	  MTp\        P                  ! WRV4      # )a9  
Match roles/types/users in a constraint expression,
optionally by expanding the contents of attributes.

Parameters:
expr        The expression to match.
criteria    The criteria to match.
indirect    If attributes in the expression should be expanded.
regex       If regular expression matching should be used.
)ZsetZupdateZexpandr   Zmatch_in_set)selfr   Zcriteriar   r   ZobjZitems   &&&&&  r   _match_exprZConstraintQuery._match_expr?   sD     %C

4;;=)  C  66r   c                sD   < V ^8  d   QhRS[ S[P                  ,          /# )r   r   )r    r   ZAnyConstraintr   r   r   r   r   V   s     - -)"9"9: -r   c              #  s  "   V P                   P                  RV P                   24       V P                   P                  RV P                  : 24       V P                  V P                   4       V P                  V P                   4       V P                   P                  RV P                  : RV P                  : 24       V P                   P                  RV P                  : RV P                  : 24       V P                   P                  RV P                  : RV P                  : 24       V P                  P                  4        EF  pV P                  '       d   VP                  V P                  9  d   K3  V P                  V4      '       g   KL   V P                  V4      '       g   Kf   T P                  '       dO   T P%                  TP&                  P(                  T P                  T P*                  T P                  4      '       g   K  T P                  '       dP   T P%                  TP&                  P,                  T P                  T P.                  T P                  4      '       g   EK(  T P                  '       dF   T P%                  TP&                  P0                  T P                  R	T P                  4      '       g   EK  Tx  EK  	  R
#   \         P"                   d     EK  i ; i5i)z6Generator which yields all matching constraints rules.z#Generating constraint results from zself.ruletype=z
self.user=z, self.user_regex=z
self.role=z, self.role_regex=zself.type_=z, self.type_regex=FN)ZlogZinfoZpolicyZdebugruletypeZ_match_object_class_debugZ_match_perms_debuguserr	   roler
   type_r   ZconstraintsZ_match_object_classZ_match_permsr   ZConstraintUseErrorr   Z
expressionZrolesrole_indirectZtypestype_indirectZusers)r   Zcs   & r   resultsZConstraintQuery.resultsV   s"    ;DKK=IJ.$--)*+&&txx0)*$))%8'9:;*$))%8'9:;+$**&9(:;<((*A}}}::T]]2++A..((++ ,
 yyy!1!1LL&&II&&OO	"% "%
 zzz$"2"2LL&&JJ&&OO	#% #%
 yyy!1!1LL&&IIOO	"% "%
 GG + // sW   FK0K0K-K0AK0K0"AK0.K0AK0K0K-(K0,K--K0c                sV   < V ^8  d   Qh/ S[ ;R&   S[ ;R&   S[ ;R&   S[ ;R&   S[ ;R&   # )r   r	   r
   r#   r   r$   )r   r   r   r   r   r      sP     R S V W X Y \ ] ^ _ r   ) N)Z__name__Z
__module__Z__qualname__Z__firstlineno__Z__doc__r   r   ZConstraintRuletyper   r   r   r    r	   r   r!   r
   r#   r   r"   r   r$   r   r%   Z__annotate_func__Z__static_attributes__Z__classdictcell__)r      @r   r   r      s     "H %Y%A%AB//1Hinn-lMJDJinn-lMJDJMy~~.|=RSEJM7 7.- -Q  r   c                s    V ^8  d   Qh/ ^ \         9   d,   \        P                  \        \        R3,          ,          ;R&   # )r   .__all__)__conditional_annotations__typingZFinalZtupleZstr)r   s   "r   r   r      s+     $ $ > =eCHo	& = %r   )r   )r(   Zcollections.abcr    r)   Z r   r   r   r   r   Zdescriptorsr   r   r'   ZMatchObjClassZMatchPermissionZPolicyQueryr   r   )r(   r&   r   <module>r*      sF   
 % $  7 7 B)= =uf**F,B,BEDUDU ur   