+
    ,i?  c                   sz  a  R t$0 t ^ RIt^ RIt^ RIHt ^ RIHt ^ RIHt ^ RI	H
t
 ^ RIHt ^ RIt^ RIt^RIHtHt ^RIHt R	t] ^ k Rt] ^k ^t] ^k ^
t] ^k Rt] ^k ]
 ! R R
4      4       tR R ltR R lt]]]]]]]],          ] ,          3,          3,          3,          t! ! R R4      t" ! R R4      t#R# )i    N)OrderedDict)Iterable)suppress)	dataclass)	resources)	exception	policyrep)PermissionMapDescriptorperm_map
RuleWeightMappingPermissionMapc                   s0   a  ] tR t^t o RtV 3R ltRtV tR# )r	   zDThe read and write weights for a rule, given all of its permissions.c                2   < V ^8  d   Qh/ S[ ;R&   S[ ;R&   # )   Zreadwriteintformat__classdict__   "6/usr/lib64/python3.14/site-packages/setools/permmap.py__annotate__ZRuleWeight.__annotate__   s     
 I  J      N)__name__
__module____qualname____firstlineno____doc____annotate_func____static_attributes____classdictcell__r      @r   r	   r	      s      O  r   c                0    V ^8  d   QhR\         R\         /# )r   weightreturnr   r      "r   r   r   (   s      C C r   c                 sT    \         T u;8:  d   \        8:  g   M \        R V  24      hV # )z!Permission weights must be 1-10: )
MIN_WEIGHT
MAX_WEIGHT
ValueError)r$      &r   validate_weightr,   (   s'    -:-<VHEFFMr   c                r#   )r   	directionr%   strr&   r'   r   r   r   /   s      # # r   c                 s8    V \         9  d   \        R V  24      hV # )z$Invalid information flow direction: )INFOFLOW_DIRECTIONSr*   )r-   r+   r   validate_directionr1   /   s$    ++?	{KLLr   c                   s   a  ] tR t^:t o Rt]! ]4      t]! ]4      t	]! ]
4      tR	V 3R lR lltV 3R lR ltV 3R ltRtV tR# )
r
   z1A mapping for a permission in the permission map.c          
      s6   < V ^8  d   QhRS[ RS[RS[RS[RR/# )r   r   	classname
permissioncreater%   N)	MapStructr/   boolr   r   r   r   Mapping.__annotate__D   s9     _ _ _s _ __*._r   c                s|   Wn         W n        W0n        V'       dF   W P                   9  d   \        4       V P                   V&   R RR^RR/V P                   V,          V&   R# W P                   9  d   \        P
                  ! V R24      hW0P                   V,          9  d   \        P                  ! V RV R24      hR# )r-   ur$   enabledT is not mapped.:N)	_perm_mapclass_permr    r   UnmappedClassZUnmappedPermission)selfr   r2   r3   r4   s   &&&&&r   __init__ZMapping.__init__D   s     "	.,7My)5@#5=q5>5FDNN9%j1
 .--?.KLL	!::22i[*_3]^^ ;r   c                    < V ^8  d   QhRS[ /# r   r%   )r6   r   r   r   r   r7   Z   s     * *t *r   c                s    V P                   VP                   8X  d   V P                  VP                  8  # V P                   VP                   8  # N)r=   r>   )r@   Zothers   &&r   __lt__ZMapping.__lt__Z   s8    ;;%,,&99uzz)){{U\\))r   c                r   )r   r=   r>   r.   r   r   r   r   r7   :   s      K  I r   )r<   r=   r>   N)F)r   r   r   r   r   r   r,   r$   r1   r-   r6   r9   rA   rE   r   r   r    r!   r"   r   r
   r
   :   sE     ;$_5F'(:;I%d+G_ _,* *A  r   c                   sn  a  ] tR t^at o Rt]t]tR'V 3R lR lltV 3R lR ltV 3R lR lt	V 3R	 lR
 lt
V 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR  ltV 3R! lR" ltV 3R# lR$ ltV 3R% ltR&tV tR# )(r   z-Permission Map for information flow analysis.Nc                sV   < V ^8  d   QhRS[ S[P                  ,          R,          RR/# )r   permmapfileNr%   r/   pathlibPathr   r   r   r   PermissionMap.__annotate__h   s)        C',,$6$=    r   c                sv   \         P                  ! \        4      V n        \	        4       V n        V  V'       d   V P                  V4       R# \        P                  ! R4      p\        P                  ! V\        ,          4      ;_uu_ 4       pV P                  V4       RRR4       R#   + '       g   i     R# ; i)D
Parameter:
permmapfile     The path to the permission map to load.
ZsetoolsN)loggingZ	getLoggerr   logr    _permmaploadpkg_resourcesZfilesZas_fileDEFAULT_PERM_MAP)r@   rF   Zpackage_locationZpath   &&  r   rA   ZPermissionMap.__init__h   sw    
 $$X.#.=IIk",229=&&'7:J'JKKt		$ LKKKs   B''B8	c                rB   rC   r.   r   r   r   r   rJ   x   s     & & &r   c                s,    \        V P                  4      # rD   )r/   _permmapfiler@   r+   r   __str__ZPermissionMap.__str__x   s    4$$%%r   c                s   < V ^8  d   QhRR/# )r   r%   r   r   r   r   r   r   rJ   {   s      O r   c                s    \         P                  \         4      pV P                  Vn        \        P                  ! V P
                  4      Vn        V P                  Vn        W!\        V 4      &   V# rD   )r   Z__new__rM   copyZdeepcopyrN   rS   Zid)r@   ZmemoZnewobj   && r   __deepcopy__ZPermissionMap.__deepcopy__{   sO    &&}5XX
--6"//RXr   c                0   < V ^8  d   QhRS[ S[,          /# rC   )r   r
   r   r   r   r   rJ      s      (7+ r   c              #  st   "   V P                  4        F  pV P                  V4       F  pVx  K	  	  K!  	  R # 5irD   )classesperms)r@   Zclsmappings   &  r   __iter__ZPermissionMap.__iter__   s,     <<>C::c? + "s   68c                sH   < V ^8  d   QhRS[ S[P                  ,          RR/# r   rF   r%   NrG   r   r   r   r   rJ      s,     i[ i[gll 2 i[t i[r   c                sV   V P                   P                  RV R24       \        VRRR7      ;_uu_ 4       p^ p^ p^ p^pV P                  P	                  4        \        V^R7       EF  w  rxVP                  4       p	\        V	4      ^ 8X  g   V	^ ,          ^ ,          R8X  d   K=  V^8X  d=    \        V	^ ,          4      pT^8  d   \        P                  ! T RT RT 24      h^pK  V^8X  d   \        V	4      ^8w  g   V	^ ,          R8w  d   \        P                  ! V RV RV	 24      h\        V	^,          4      p \        V	^,          4      pT^8  d   \        P                  ! T RT RT 24      hT^,          pYE8  d   \        P                  ! T RT RT 24      h\        4       T P                  T&   ^ p^pEKX  V^8X  g   EKb  \        V	^ ,          4      p\        V	^,          4      pV\        9  d   \        P                  ! V RV RV 24      h \        V	^,          4      p\        Tu;8:  d   \         8:  g/   M \        P                  ! T RT R\         R\          RT 2	4      hT P                   P#                  RX RT RT RT 24       TR8X  d#   T P                   P                  RT RT R24       \%        T P                  YRR7      pTTn        TTn        T^,          pX^,          pTX8  g   EK  ^pEK  	  R
R
R
4       \*        P,                  ! V4      V n        V P                   P                  RV R24       V P                   P#                  RX RX R24       R
#   \         d,   p
\        P                  ! T RT R	T	^ ,           24      T
hR
p
?
ii ; i  \         d,   p
\        P                  ! T RT RT	^,           24      T
hR
p
?
ii ; i  \         d,   p
\        P                  ! T RT RT	^,           24      T
hR
p
?
ii ; i  + '       g   i     EL; i) rK   zOpening permission map ""rutf-8Zencoding)ZstartZ#r;   z:Invalid number of classes: Nz%:Number of classes must be positive: Zclassz:Invalid class declaration: z :Invalid number of permissions: z):Number of permissions must be positive: z:Extra class found: z%:Invalid information flow direction: z:Invalid permission weight: z:Permission weight must be Z-z: zRead  r8   zPermission  is unmapped.Tr4   z$Successfully opened permission map "z classes and z total permissions.)rM   infoopenrN   ZclearZ	enumerateZsplitlenr   r*   r   ZPermissionMapParseErrorr/   r    r0   r(   r)   debugr
   r-   r$   rH   rI   rS   )r@   rF   mapfileZtotal_permsZclass_countZnum_classesZstateZline_numZlineZentryex
class_nameZ	num_permsZ
perm_count	perm_nameZflow_directionr$   r\   s   &&                r   rO   ZPermissionMap.load   sR   
 	1+bAB +sW55KKKEMM!"+G1"="=

u:?eAhqkS&8A:3&)%(m #Q'??*m1XJ6[*m-. . EaZ5zQ%(g*='??*m1XJ6RSXRYZ\ \ "%U1XJ3$'aM	 !1}'??*m1XJ6_(k+, ,  1$K"0'??*m1XJ6J:,WY Y 1<DMM*-!"JEaZ #E!HI%(q]N%-@@'??*m1XJ6[-.01 13!$U1X &=:='??*m1XJ6Q)l!J<r&CD D HHNNU:,a	{!NCSSTU[T\#]^%,J<q=&YZ%dmmZSWXG(6G%%+GN1$K!OJ!Y. !e #> 6x $LL5=k]"MN{m=EXYZ[ & 3'??*m1XJ6R$Qxj*+0233* & 3'??*m1XJ6V$Qxj*+0233< & 3'??*m1XJ6R$Qxj*+0233I 655s   A4P+M,=A>P<N%A4PAPO(CP?P,N"	7&N	N"	"P%O	0&O	O	PP	)&P	P	PP(	c                $   < V ^8  d   QhRS[ RR/# r^   r.   r   r   r   r   rJ      s     #U #U #U #Ur   c                s&   \        VRRR7      ;_uu_ 4       pV P                  P                  RV R24       VP                  \	        V P
                  4       R24       V P
                  P                  4        F  w  r4VP                  RV R\	        V4       R	24       VP                  4        F  w  rV\        P                  ! \        VR
,          4      p\        P                  ! \        VR,          4      pVR8X  d#   V P                  P                  RV RV R24       VP                  VR RVR RVR R	24       K  	  VP                  R	4       K  	  V P                  P                  RV R24       RRR4       R#   + '       g   i     R# ; i)z
Save the permission map to the specified path.  Existing files
will be overwritten.

Parameter:
permmapfile         The path to write the permission map.
wra   rb   zWriting permission map to "r_   z

zclass rc   Z
r-   r$   r8   zWarning: permission z
 in class rd   z>20z>9z&Successfully wrote permission map to "N)rg   rM   rf   r   rh   rN   ZitemstypingZcastr/   r   Zwarning)	r@   rF   rj   r2   r[   ZpermnameZsettingsr-   r$   s	   &&       r   saveZPermissionMap.save   sS    +sW55HHMM8RHIMMS/056$(MM$7$7$9 	yk3u:,bAB*/++-&H &C+1F GI#[[hx.@AF !C'((28*JykQ^_a MMXcN!Ib>6"+R"PQ! +8$ d#+ %:. HHMMCK=PRST7 6555s   EE??F	c                rY   rC   )r   r/   r   r   r   r   rJ     s     ( (# (r   c              #  sV   "   V P                   P                  4        Rj  xL
  R#  L5i)zW
Generate class names in the permission map.

Yield:
class       An object class name.
N)rN   keysrT   r+   r   rZ   ZPermissionMap.classes  s      ==%%'''s   )')c                s6   < V ^8  d   QhRS[ RS[S[,          /# )r   r=   r%   )r/   r   r
   r   r   r   r   rJ   !  s$     N NC NHW$5 Nr   c              #  s   "    V P                   V,          P                  4        F  p\        V P                   W4      x  K  	  R#   \         d    p\        P
                  ! T R24      ThRp?ii ; i5i)z
Generate permission mappings for the specified class.

Parameter:
class_      An object class name.

Yield:
Mapping     A permission's complete map (weight, direction, enabled)
r:   N)rN   rr   r
   ZKeyErrorr   r?   )r@   r=   r>   rk   rR   r   r[   ZPermissionMap.perms!  sc     	Nf-224dmmV:: 5 	N))VHO*DE2M	Ns)   A3A A A3A0A++A00A3c                s,   < V ^8  d   QhRS[ RS[ RS[/# )r   r=   r>   r%   )r/   r
   r   r   r   r   rJ   1  s"     4 4c 4 4 4r   c                s.    \        V P                  W4      # )z)Retrieve a specific permission's mapping.)r
   rN   r@   r=   r>      &&&r   r\   ZPermissionMap.mapping1  s    t}}f33r   c                rn   r   r=   r%   Nr.   r   r   r   r   rJ   5  s     ! !C !D !r   c                D    V P                  V4       F
  pRVn        K  	  R# )z
Exclude all permissions in an object class for calculating rule weights.

Parameter:
class_              The object class to exclude.

Exceptions:
UnmappedClass       The specified object class is not mapped.
FNr[   r9   rs   rW   r   exclude_classZPermissionMap.exclude_class5  s     JJv&D DL 'r   c                *   < V ^8  d   QhRS[ RS[ RR/# r   r=   r3   r%   Nr.   r   r   r   r   rJ   B  s'     C C C# C$ Cr   c                <    R\        V P                  W4      n        R# )aH  
Exclude a permission for calculating rule weights.

Parameter:
class_              The object class of the permission.
permission          The permission name to exclude.

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
FNr
   rN   r9   r@   r=   r3   rt   r   exclude_permissionZ PermissionMap.exclude_permissionB  s     >Cv2:r   c                rn   ru   r.   r   r   r   r   rJ   P  s        C  D  r   c                rv   )z
Include all permissions in an object class for calculating rule weights.

Parameter:
class_              The object class to include.

Exceptions:
UnmappedClass       The specified object class is not mapped.
TNrw   rs   rW   r   include_classZPermissionMap.include_classP  s     JJv&DDL 'r   c                ry   rz   r.   r   r   r   r   rJ   ^  s'     B B B# B$ Br   c                r{   )aH  
Include a permission for calculating rule weights.

Parameter:
class_              The object class of the permission.
permission          The permission name to include.

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
TNr|   r}   rt   r   include_permissionZ PermissionMap.include_permission^  s     >Bv2:r   c                s8   < V ^8  d   QhRS[ P                  RR/# )r   policyr%   N)r   ZSELinuxPolicyr   r   r   r   rJ   m  s%     O O!8!8 OT Or   c           
     sd   VP                  4        EF  p\        V4      pW0P                  9  d9   V P                  P	                  RV RV 24       \        4       V P                  V&   VP                  p\        \        P                  4      ;_uu_ 4        WBP                  P                  ,          pRRR4       V FX  pWPP                  V,          9  g   K  V P                  P	                  RV RV RV 24       \        V P                  W5RR7       KZ  	  EK
  	  R#   + '       g   i     Lu; i)zHCreate mappings for all classes and permissions in the specified policy.zAdding unmapped class z from NzAdding unmapped permission z in Tre   )rZ   r/   rN   rM   ri   r    r[   r   r   ZNoCommonZcommonr
   )r@   r   r=   rl   r[   rm   s   &&    r   
map_policyZPermissionMap.map_policym  s    nn&FVJ.!7
|6&RS,7Mj)LLE),,--,,, . #	MM*$==HHNN5i[ZLPVW]V^_aDMM:N	 # ' .-s   DD/c                s:   < V ^8  d   QhRS[ P                  RS[/# )r   ruler%   )r   ZAVRuler	   r   r   r   r   rJ     s!     %5 %5	 0 0 %5Z %5r   c                sv   ^ p^ p\        VP                  4      pVP                  \        P                  P
                  8w  d$   \        P                  ! VP                   R24      hVP                   F  p\        V P                  WE4      pVP                  '       g   K-  VP                  R8X  d   \        W6P                  4      pKU  VP                  R8X  d   \        W&P                  4      pK}  VP                  R8X  g   K  \        W6P                  4      p\        W&P                  4      pK  	  \        W24      # )a  
Get the type enforcement rule's information flow read and write weights.

Parameter:
rule            A type enforcement rule.

Return: Tuple(read_weight, write_weight)
read_weight     The type enforcement rule's read weight.
write_weight    The type enforcement rule's write weight.
z. rules cannot be used for calculating a weightr`   ro   b)r/   ZtclassZruletyper   Z
TERuletypeZallowr   ZRuleTypeErrorr[   r
   rN   r9   r-   Zmaxr$   r	   )r@   r   Zwrite_weightZread_weightrl   rm   r\   s   &&     r   rule_weightZPermissionMap.rule_weight  s     %
==I00666))==/!OPR R IdmmZCG???  C'!+~~>""c)"<@""c)!+~~>"<@ $ +44r   c                s0   < V ^8  d   QhRS[ RS[ RS[ RR/# )r   r=   r3   r-   r%   Nr.   r   r   r   r   rJ     s/     I IC IS IS IT Ir   c                <    V\        V P                  W4      n        R# )a  
Set the information flow direction of a permission.

Parameter:
class_              The object class of the permission.
permission          The permission name.
direction           The information flow direction the permission (r/w/b/n).

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
N)r
   rN   r-   )r@   r=   r3   r-      &&&&r   set_directionZPermissionMap.set_direction  s     @Iv2<r   c                s0   < V ^8  d   QhRS[ RS[ RS[RR/# )r   r=   r3   r$   r%   N)r/   r   r   r   r   r   rJ     s/     C C C# Cs Ct Cr   c                r   )ac  
Set the weight of a permission.

Parameter:
class_              The object class of the permission.
permission          The permission name.
weight              The weight of the permission (1-10).

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
N)r
   rN   r$   )r@   r=   r3   r$   r   r   
set_weightZPermissionMap.set_weight  s     =Cv29r   c                sz   < V ^8  d   Qh/ S[ P                  S[,          ;R&   S[ P                  S[,          ;R&   # )r   r(   r)   )rp   Finalr   r   r   r   r   rJ   a   s1      S!.	 
 S!. r   )rN   rS   rM   rD   )r   r   r   r   r   r(   r)   rA   rU   rX   r]   rO   rq   rZ   r[   r\   rx   r~   r   r   r   r   r   r   r   r   r    r!   r"   r   r   r   a   s     7$.J$.J    & &  
i[ i[V#U #UJ( (N N 4 4! !C C   B BO O(%5 %5NI IC Cm
  r   c                s   V ^8  d   Qh/ ^ \         9   d   \        P                  \        ,          ;R&   ^\         9   d   \        P                  ;R&   ^\         9   d   \        P                  \        ,          ;R&   ^\         9   d   \        P                  \        ,          ;R&   ^\         9   d,   \        P                  \
        \        R3,          ,          ;R&   # )r   rQ   r0   r(   r)   .__all__)__conditional_annotations__rp   r   r/   r   Ztupler&   r'   r   r   r      s     1 0&,,s# 0   > =V\\ =! " " !FLL !# $ # "FLL "% ( T SeCHo	& S) r   )r`   ro   r   Znr8   )r	   r
   r   )%r   rL   rV   Zcollectionsr    Zcollections.abcr   Z
contextlibr   Zdataclassesr   Z	importlibr   rP   rH   rp   Z r   r   Zdescriptorsr   rQ   r0   r(   r)   r   r	   r,   r1   Zdictr/   r6   r   r5   r
   r   r   )r   r"   r   <module>r      s   
   # $  ! 0   " 0 '1  0$=  = !
 ! "
 ")S S    d3S$*s*:%: ;;<<=	$* $*NcC cCr   