+
        ?                     z  a  R t$0 t ^ RIt^ RIt^ RIHt ^ RIHt ^ RIHt ^ RI	H
t
 ^ RIHt ^ RIt^ RIt^RIHtHt ^RIHt R	t] ^ k Rt] ^k ^t] ^k ^
t] ^k Rt] ^k ]
 ! R R
4      4       tR R ltR R lt]]]]]]]],          ] ,          3,          3,          3,          t! ! R R4      t" ! R R4      t#R# )    N)OrderedDict)Iterable)suppress)	dataclass)	resources)	exception	policyrep)PermissionMapDescriptorperm_map
RuleWeightMappingPermissionMapc                   0   a  ] tR t^t o RtV 3R ltRtV tR# )r   zDThe read and write weights for a rule, given all of its permissions.c                2   < V ^8  d   Qh/ S[ ;R&   S[ ;R&   # )   readwriteint)format__classdict__s   "6/usr/lib64/python3.14/site-packages/setools/permmap.py__annotate__RuleWeight.__annotate__   s     
 I  J      N)__name__
__module____qualname____firstlineno____doc____annotate_func____static_attributes____classdictcell__r   s   @r   r   r      s      O  r   c                0    V ^8  d   QhR\         R\         /# )r   weightreturnr   )r   s   "r   r   r   (   s      C C r   c                 T    \         T u;8:  d   \        8:  g   M \        R V  24      hV # )z!Permission weights must be 1-10: )
MIN_WEIGHT
MAX_WEIGHT
ValueError)r'   s   &r   validate_weightr-   (   s'    -:-<VHEFFMr   c                0    V ^8  d   QhR\         R\         /# )r   	directionr(   str)r   s   "r   r   r   /   s      # # r   c                 8    V \         9  d   \        R V  24      hV # )z$Invalid information flow direction: )INFOFLOW_DIRECTIONSr,   )r/   s   &r   validate_directionr4   /   s$    ++?	{KLLr   c                      a  ] tR t^:t o Rt]! ]4      t]! ]4      t	]! ]
4      tR	V 3R lR lltV 3R lR ltV 3R ltRtV tR# )
r   z1A mapping for a permission in the permission map.c          
      6   < V ^8  d   QhRS[ RS[RS[RS[RR/# )r   r   	classname
permissioncreater(   N)	MapStructr1   bool)r   r   s   "r   r   Mapping.__annotate__D   s9     _ _ _s _ __*._r   c                |   Wn         W n        W0n        V'       dF   W P                   9  d   \        4       V P                   V&   R RR^RR/V P                   V,          V&   R# W P                   9  d   \        P
                  ! V R24      hW0P                   V,          9  d   \        P                  ! V RV R24      hR# )r/   ur'   enabledT is not mapped.:N)	_perm_mapclass_permr   r   UnmappedClassUnmappedPermission)selfr   r7   r8   r9   s   &&&&&r   __init__Mapping.__init__D   s     "	.,7My)5@#5=q5>5FDNN9%j1
 .--?.KLL	!::22i[*_3]^^ ;r   c                    < V ^8  d   QhRS[ /# r   r(   )r;   )r   r   s   "r   r   r<   Z   s     * *t *r   c                    V P                   VP                   8X  d   V P                  VP                  8  # V P                   VP                   8  # N)rC   rD   )rG   others   &&r   __lt__Mapping.__lt__Z   s8    ;;%,,&99uzz)){{U\\))r   c                2   < V ^8  d   Qh/ S[ ;R&   S[ ;R&   # )r   rC   rD   r0   )r   r   s   "r   r   r<   :   s      K  I r   )rB   rC   rD   N)F)r   r   r   r    r!   r
   r-   r'   r4   r/   r;   r?   rH   rO   r"   r#   r$   r%   s   @r   r   r   :   sE     ;$_5F'(:;I%d+G_ _,* *A  r   c                   n  a  ] tR t^at o Rt]t]tR'V 3R lR lltV 3R lR ltV 3R lR lt	V 3R	 lR
 lt
V 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR ltV 3R lR  ltV 3R! lR" ltV 3R# lR$ ltV 3R% ltR&tV tR# )(r   z-Permission Map for information flow analysis.Nc                V   < V ^8  d   QhRS[ S[P                  ,          R,          RR/# )r   permmapfileNr(   r1   pathlibPath)r   r   s   "r   r   PermissionMap.__annotate__h   s)        C',,$6$=    r   c                v   \         P                  ! \        4      V n        \	        4       V n        V  V'       d   V P                  V4       R# \        P                  ! R4      p\        P                  ! V\        ,          4      ;_uu_ 4       pV P                  V4       RRR4       R#   + '       g   i     R# ; i)D
Parameter:
permmapfile     The path to the permission map to load.
setoolsN)logging	getLoggerr   logr   _permmaploadpkg_resourcesfilesas_fileDEFAULT_PERM_MAP)rG   rT   package_locationpaths   &&  r   rH   PermissionMap.__init__h   sw    
 $$X.#.=IIk",229=&&'7:J'JKKt		$ LKKKs   B''B8	c                    < V ^8  d   QhRS[ /# rK   r0   )r   r   s   "r   r   rX   x   s     & & &r   c                ,    \        V P                  4      # rM   )r1   _permmapfilerG   s   &r   __str__PermissionMap.__str__x   s    4$$%%r   c                   < V ^8  d   QhRR/# )r   r(   r   r   )r   r   s   "r   r   rX   {   s      O r   c                    \         P                  \         4      pV P                  Vn        \        P                  ! V P
                  4      Vn        V P                  Vn        W!\        V 4      &   V# rM   )r   __new__r^   copydeepcopyr_   rj   id)rG   memonewobjs   && r   __deepcopy__PermissionMap.__deepcopy__{   sO    &&}5XX
--6"//RXr   c                0   < V ^8  d   QhRS[ S[,          /# rK   )r   r   )r   r   s   "r   r   rX      s      (7+ r   c              #  t   "   V P                  4        F  pV P                  V4       F  pVx  K	  	  K!  	  R # 5irM   )classesperms)rG   clsmappings   &  r   __iter__PermissionMap.__iter__   s,     <<>C::c? + "s   68c                H   < V ^8  d   QhRS[ S[P                  ,          RR/# r   rT   r(   NrU   )r   r   s   "r   r   rX      s,     i[ i[gll 2 i[t i[r   c                V   V P                   P                  RV R24       \        VRRR7      ;_uu_ 4       p^ p^ p^ p^pV P                  P	                  4        \        V^R7       EF  w  rxVP                  4       p	\        V	4      ^ 8X  g   V	^ ,          ^ ,          R8X  d   K=  V^8X  d=    \        V	^ ,          4      pT^8  d   \        P                  ! T RT RT 24      h^pK  V^8X  d   \        V	4      ^8w  g   V	^ ,          R8w  d   \        P                  ! V RV RV	 24      h\        V	^,          4      p \        V	^,          4      pT^8  d   \        P                  ! T RT RT 24      hT^,          pYE8  d   \        P                  ! T RT RT 24      h\        4       T P                  T&   ^ p^pEKX  V^8X  g   EKb  \        V	^ ,          4      p\        V	^,          4      pV\        9  d   \        P                  ! V RV RV 24      h \        V	^,          4      p\        Tu;8:  d   \         8:  g/   M \        P                  ! T RT R\         R\          RT 2	4      hT P                   P#                  RX RT RT RT 24       TR8X  d#   T P                   P                  RT RT R24       \%        T P                  YRR7      pTTn        TTn        T^,          pX^,          pTX8  g   EK  ^pEK  	  R
R
R
4       \*        P,                  ! V4      V n        V P                   P                  RV R24       V P                   P#                  RX RX R24       R
#   \         d,   p
\        P                  ! T RT R	T	^ ,           24      T
hR
p
?
ii ; i  \         d,   p
\        P                  ! T RT RT	^,           24      T
hR
p
?
ii ; i  \         d,   p
\        P                  ! T RT RT	^,           24      T
hR
p
?
ii ; i  + '       g   i     EL; i) rZ   zOpening permission map ""rutf-8encoding)start#rA   z:Invalid number of classes: Nz%:Number of classes must be positive: classz:Invalid class declaration: z :Invalid number of permissions: z):Number of permissions must be positive: z:Extra class found: z%:Invalid information flow direction: z:Invalid permission weight: z:Permission weight must be -z: zRead  r>   zPermission  is unmapped.Tr9   z$Successfully opened permission map "z classes and z total permissions.)r^   infoopenr_   clear	enumeratesplitlenr   r,   r   PermissionMapParseErrorr1   r   r3   r*   r+   debugr   r/   r'   rV   rW   rj   )rG   rT   mapfiletotal_permsclass_countnum_classesstateline_numlineentryex
class_name	num_perms
perm_count	perm_nameflow_directionr'   r}   s   &&                r   r`   PermissionMap.load   sR   
 	1+bAB +sW55KKKEMM!"+G1"="=

u:?eAhqkS&8A:3&)%(m #Q'??*m1XJ6[*m-. . EaZ5zQ%(g*='??*m1XJ6RSXRYZ\ \ "%U1XJ3$'aM	 !1}'??*m1XJ6_(k+, ,  1$K"0'??*m1XJ6J:,WY Y 1<DMM*-!"JEaZ #E!HI%(q]N%-@@'??*m1XJ6[-.01 13!$U1X &=:='??*m1XJ6Q)l!J<r&CD D HHNNU:,a	{!NCSSTU[T\#]^%,J<q=&YZ%dmmZSWXG(6G%%+GN1$K!OJ!Y. !e #> 6x $LL5=k]"MN{m=EXYZ[ & 3'??*m1XJ6R$Qxj*+0233* & 3'??*m1XJ6V$Qxj*+0233< & 3'??*m1XJ6R$Qxj*+0233I 655s   A4P+M,=A>P<N%A4PAPO(CP?P,N"	7&N	N"	"P%O	0&O	O	PP	)&P	P	PP(	c                $   < V ^8  d   QhRS[ RR/# r   r0   )r   r   s   "r   r   rX      s     #U #U #U #Ur   c                   \        VRRR7      ;_uu_ 4       pV P                  P                  RV R24       VP                  \	        V P
                  4       R24       V P
                  P                  4        EF  w  r4VP                  RV R\	        V4       R	24       VP                  4        F  w  rV\        P                  ! \        VR
,          4      p\        P                  ! \        VR,          4      p\        Tu;8:  d   \        8:  g   M Q V RV RV R24       hV\        9   g   Q V RV RV R24       hVR8X  d#   V P                  P                  RV RV R24       VP                  VR RVR RVR R	24       K  	  VP                  R	4       EK"  	  V P                  P                  RV R24       RRR4       R#   + '       g   i     R# ; i)z
Save the permission map to the specified path.  Existing files
will be overwritten.

Parameter:
permmapfile         The path to write the permission map.
wr   r   zWriting permission map to "r   z

zclass r   
r/   r'   rA   z weight is out of range (z). This is an SETools bug.z flow direction (z%) is invalid. This is an SETools bug.r>   zWarning: permission z
 in class r   z>20z>9z&Successfully wrote permission map to "N)r   r^   r   r   r   r_   itemstypingcastr1   r   r*   r+   r3   warning)	rG   rT   r   r7   r{   permnamesettingsr/   r'   s	   &&       r   savePermissionMap.save   s    +sW55HHMM8RHIMMS/056$(MM$7$7$9 	yk3u:,bAB*/++-&H &C+1F GI#[[hx.@AF%=:= 2$+Qxj0I& R2 22= %(;; 2$+Qxj0A) M2 22; !C'((28*JykQ^_a MMXcN!Ib>6"+R"PQ! +8$ d#+ %:. HHMMCK=PRST7 6555s   F$GG	c                0   < V ^8  d   QhRS[ S[,          /# rK   )r   r1   )r   r   s   "r   r   rX     s     ( (# (r   c              #  V   "   V P                   P                  4        Rj  xL
  R#  L5i)zW
Generate class names in the permission map.

Yield:
class       An object class name.
N)r_   keysrk   s   &r   rz   PermissionMap.classes  s      ==%%'''s   )')c                6   < V ^8  d   QhRS[ RS[S[,          /# )r   rC   r(   )r1   r   r   )r   r   s   "r   r   rX   !  s$     N NC NHW$5 Nr   c              #     "    V P                   V,          P                  4        F  p\        V P                   W4      x  K  	  R#   \         d    p\        P
                  ! T R24      ThRp?ii ; i5i)z
Generate permission mappings for the specified class.

Parameter:
class_      An object class name.

Yield:
Mapping     A permission's complete map (weight, direction, enabled)
r@   N)r_   r   r   KeyErrorr   rE   )rG   rC   rD   r   s   &&  r   r{   PermissionMap.perms!  sc     	Nf-224dmmV:: 5 	N))VHO*DE2M	Ns)   A3A A A3A0A++A00A3c                ,   < V ^8  d   QhRS[ RS[ RS[/# )r   rC   rD   r(   )r1   r   )r   r   s   "r   r   rX   1  s"     4 4c 4 4 4r   c                .    \        V P                  W4      # )z)Retrieve a specific permission's mapping.)r   r_   rG   rC   rD   s   &&&r   r}   PermissionMap.mapping1  s    t}}f33r   c                $   < V ^8  d   QhRS[ RR/# r   rC   r(   Nr0   )r   r   s   "r   r   rX   5  s     ! !C !D !r   c                D    V P                  V4       F
  pRVn        K  	  R# )z
Exclude all permissions in an object class for calculating rule weights.

Parameter:
class_              The object class to exclude.

Exceptions:
UnmappedClass       The specified object class is not mapped.
FNr{   r?   r   s   && r   exclude_classPermissionMap.exclude_class5  s     JJv&D DL 'r   c                *   < V ^8  d   QhRS[ RS[ RR/# r   rC   r8   r(   Nr0   )r   r   s   "r   r   rX   B  s'     C C C# C$ Cr   c                <    R\        V P                  W4      n        R# )aH  
Exclude a permission for calculating rule weights.

Parameter:
class_              The object class of the permission.
permission          The permission name to exclude.

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
FNr   r_   r?   rG   rC   r8   s   &&&r   exclude_permission PermissionMap.exclude_permissionB  s     >Cv2:r   c                $   < V ^8  d   QhRS[ RR/# r   r0   )r   r   s   "r   r   rX   P  s        C  D  r   c                D    V P                  V4       F
  pRVn        K  	  R# )z
Include all permissions in an object class for calculating rule weights.

Parameter:
class_              The object class to include.

Exceptions:
UnmappedClass       The specified object class is not mapped.
TNr   r   s   && r   include_classPermissionMap.include_classP  s     JJv&DDL 'r   c                *   < V ^8  d   QhRS[ RS[ RR/# r   r0   )r   r   s   "r   r   rX   ^  s'     B B B# B$ Br   c                <    R\        V P                  W4      n        R# )aH  
Include a permission for calculating rule weights.

Parameter:
class_              The object class of the permission.
permission          The permission name to include.

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
TNr   r   s   &&&r   include_permission PermissionMap.include_permission^  s     >Bv2:r   c                8   < V ^8  d   QhRS[ P                  RR/# )r   policyr(   N)r	   SELinuxPolicy)r   r   s   "r   r   rX   m  s%     O O!8!8 OT Or   c           
     d   VP                  4        EF  p\        V4      pW0P                  9  d9   V P                  P	                  RV RV 24       \        4       V P                  V&   VP                  p\        \        P                  4      ;_uu_ 4        WBP                  P                  ,          pRRR4       V FX  pWPP                  V,          9  g   K  V P                  P	                  RV RV RV 24       \        V P                  W5RR7       KZ  	  EK
  	  R#   + '       g   i     Lu; i)zHCreate mappings for all classes and permissions in the specified policy.zAdding unmapped class z from NzAdding unmapped permission z in Tr   )rz   r1   r_   r^   r   r   r{   r   r   NoCommoncommonr   )rG   r   rC   r   r{   r   s   &&    r   
map_policyPermissionMap.map_policym  s    nn&FVJ.!7
|6&RS,7Mj)LLE),,--,,, . #	MM*$==HHNN5i[ZLPVW]V^_aDMM:N	 # ' .-s   DD/c                :   < V ^8  d   QhRS[ P                  RS[/# )r   ruler(   )r	   AVRuler   )r   r   s   "r   r   rX     s!     %5 %5	 0 0 %5Z %5r   c                v   ^ p^ p\        VP                  4      pVP                  \        P                  P
                  8w  d$   \        P                  ! VP                   R24      hVP                   F  p\        V P                  WE4      pVP                  '       g   K-  VP                  R8X  d   \        W6P                  4      pKU  VP                  R8X  d   \        W&P                  4      pK}  VP                  R8X  g   K  \        W6P                  4      p\        W&P                  4      pK  	  \        W24      # )a  
Get the type enforcement rule's information flow read and write weights.

Parameter:
rule            A type enforcement rule.

Return: Tuple(read_weight, write_weight)
read_weight     The type enforcement rule's read weight.
write_weight    The type enforcement rule's write weight.
z. rules cannot be used for calculating a weightr   r   b)r1   tclassruletyper	   
TERuletypeallowr   RuleTypeErrorr{   r   r_   r?   r/   maxr'   r   )rG   r   write_weightread_weightr   r   r}   s   &&     r   rule_weightPermissionMap.rule_weight  s     %
==I00666))==/!OPR R IdmmZCG???  C'!+~~>""c)"<@""c)!+~~>"<@ $ +44r   c                0   < V ^8  d   QhRS[ RS[ RS[ RR/# )r   rC   r8   r/   r(   Nr0   )r   r   s   "r   r   rX     s/     I IC IS IS IT Ir   c                <    V\        V P                  W4      n        R# )a  
Set the information flow direction of a permission.

Parameter:
class_              The object class of the permission.
permission          The permission name.
direction           The information flow direction the permission (r/w/b/n).

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
N)r   r_   r/   )rG   rC   r8   r/   s   &&&&r   set_directionPermissionMap.set_direction  s     @Iv2<r   c                0   < V ^8  d   QhRS[ RS[ RS[RR/# )r   rC   r8   r'   r(   N)r1   r   )r   r   s   "r   r   rX     s/     C C C# Cs Ct Cr   c                <    V\        V P                  W4      n        R# )ac  
Set the weight of a permission.

Parameter:
class_              The object class of the permission.
permission          The permission name.
weight              The weight of the permission (1-10).

Exceptions:
UnmappedClass       The specified object class is not mapped.
UnmappedPermission  The specified permission is not mapped for the object class.
N)r   r_   r'   )rG   rC   r8   r'   s   &&&&r   
set_weightPermissionMap.set_weight  s     =Cv29r   c                z   < V ^8  d   Qh/ S[ P                  S[,          ;R&   S[ P                  S[,          ;R&   # )r   r*   r+   )r   Finalr   )r   r   s   "r   r   rX   a   s1      S!.	 
 S!. r   )r_   rj   r^   rM   )r   r   r   r    r!   r*   r+   rH   rl   rv   r~   r`   r   rz   r{   r}   r   r   r   r   r   r   r   r   r"   r#   r$   r%   s   @r   r   r   a   s     7$.J$.J    & &  
i[ i[V#U #UJ( (N N 4 4! !C C   B BO O(%5 %5NI IC Cm
  r   c                   V ^8  d   Qh/ ^ \         9   d   \        P                  \        ,          ;R&   ^\         9   d   \        P                  ;R&   ^\         9   d   \        P                  \        ,          ;R&   ^\         9   d   \        P                  \        ,          ;R&   ^\         9   d,   \        P                  \
        \        R3,          ,          ;R&   # )r   rd   r3   r*   r+   .__all__)__conditional_annotations__r   r   r1   r   tuple)r   s   "r   r   r      s     1 0&,,s# 0   > =V\\ =! " " !FLL !# $ # "FLL "% ( T SeCHo	& S) r   )r   r   r   nr>   )r   r   r   )%r   r\   rq   collectionsr   collections.abcr   
contextlibr   dataclassesr   	importlibr   ra   rV   r    r   r	   descriptorsr
   rd   r3   r*   r+   r   r   r-   r4   dictr1   r;   r   r:   r   r   r   )r   s   @r   <module>r     s   
   # $  ! 0   " 0 '1  0$=  = !
 ! "
 ")S S    d3S$*s*:%: ;;<<=	$* $*NcC cCr   