VULN_CHECK_I913V6 /i>dZddlZddlZddlmZ ddlddlmZddlmZddlm Z ddlm Z dd lm Z dd lm Z dZ dZd ZGd d ZdefdZdZGddZdZy#YOxYw)z> classes and algorithms for the generation of SELinux policy. N)*) refpolicy) objectmodel)access) interfaces)matching)utilcpeZdZdZddZddZddZefdZdZ dZ d Z d Z dd Z d Zd ZdZdZdZy)PolicyGeneratoraGenerate a reference policy module from access vectors. PolicyGenerator generates a new reference policy module or updates an existing module based on requested access in the form of access vectors. It generates allow rules and optionally module require statements, reference policy interfaces, and extended permission access vector rules. By default only allow rules are generated. The methods .set_gen_refpol, .set_gen_requires and .set_gen_xperms turns on interface generation, requires generation, and xperms rules generation respectively. PolicyGenerator can also optionally add comments explaining why a particular access was allowed based on the audit messages that generated the access. The access vectors passed in must have the .audit_msgs field set correctly and .explain set to SHORT|LONG_EXPLANATION to enable this feature. The module created by PolicyGenerator can be passed to output.ModuleWriter to output a text representation. Ncd|_t|_d|_|r||_nt j |_d|_d|_d|_ d|_ d|_ y)zInitialize a PolicyGenerator with an optional existing module. If the module parameter is not None then access will be added to the passed in module. Otherwise a new reference policy module will be created. NF#) ifgenNO_EXPLANATIONexplain gen_requiresmodulerModule dontauditxpermsdomainsgen_cil comment_start)selfrs 7/usr/lib/python3.12/site-packages/sepolgen/policygen.py__init__zPolicyGenerator.__init__EsX % !  DK#**,DK    ch|rt|||_d|_nd|_|jy)a?Set whether reference policy interfaces are generated. To turn on interface generation pass in an interface set to use for interface generation. To turn off interface generation pass in None. If interface generation is enabled requires generation will also be enabled. TN)InterfaceGeneratorrr"_PolicyGenerator__set_module_style)rif_set perm_mapss rset_gen_refpolzPolicyGenerator.set_gen_refpol[s0 +FI>DJ $D DJ !rc||_y)a&Set whether module requires are generated. Passing in true will turn on requires generation and False will disable generation. If requires generation is disabled interface generation will also be disabled and can only be re-enabled via .set_gen_refpol. N)r)rstatuss rset_gen_requiresz PolicyGenerator.set_gen_requiresms #rc||_y)z)Set whether access is explained. N)r)rrs rset_gen_explainzPolicyGenerator.set_gen_explainws  rc||_yN)r)rrs rset_gen_dontauditz!PolicyGenerator.set_gen_dontaudit|s "rc||_y)zSSet whether extended permission access vector rules are generated. N)r)rrs rset_gen_xpermszPolicyGenerator.set_gen_xpermss  rc4||_|rd|_yd|_y)N;r)rr)rrs r set_gen_cilzPolicyGenerator.set_gen_cils !$D !$D rcr|jrd}nd}|jjD] }||_ y)NTF)rrmodule_declarationsr)rrmods r__set_module_stylez"PolicyGenerator.__set_module_styles1 ::II;;224C%CM5rcd}|jjD]}|}|s:tj}|jjj d|||_||_|jrd|_yd|_y)z?Set the name of the module and optionally the version. NrTF) rr3rModuleDeclarationchildreninsertnameversionr)rr:r;mr4s rset_module_namezPolicyGenerator.set_module_namess ;;224CA5++-A KK ' '1 - ::AKAKrc^|jrt|j |jSr+)rr)rs r get_modulezPolicyGenerator.get_modules$     %){{rc tj|}|jr|j|_d|_|j rUtjt||j }|j|jt||_|jtjk(rP|xj d|jzz c_|j r"|xj d|jzz c_|jtjk(r"|xj d|jzz c_|jtj"k(rt%|j&dkDr]|xj d|jd|jd d j)|j&Dcgc]}|d  c}z c_n6|xj d|jd |j&d d d z c_|jtj*k(r|xj d|jzz c_|xj d|jzz c_|xj d|jz|j&d zz c_|j&ddD]<}|xj d|jzz c_|xj d|zz c_> |jtj,k(rd|j.vrd|j0vsd|j.vrz|j2st5t6dd d|_g}t9tgt:|j<t>|j0t@|j.iDcgc] }|tB c}D]"}||j2vs|jE|$t%|dk(r]|xj d|jd|j<d|j0d|jdd j)|d z c_njt%|dk\r\|xj d|jd|j<d|j0d|jdd j)|d z c_|jFjHjE|ycc}wcc}w#Y4xYw)z Add access vector rule. ) verbosityz1 %s!!!! This avc is allowed in the current policyzO %s!!!! This av rule may have been overridden by an extended permission av rulez; %s!!!! This avc has a dontaudit rule in the current policyr z>!!!! This avc can be allowed using one of the these booleans: z z, rz0!!!! This avc can be allowed using the boolean ''z %s!!!! This avc is a constraint violation. You would need to modify the attributes of either the source or target types to allow this access.z %sConstraint rule: z %s Nz %sz= Possible cause is the source %s and target %s are different.writediropendomain)r:typesz!!!! The source type 'z' can write to a 'z' of the following type:  z' of the following types: )%rAVRuler DONTAUDIT rule_typecommentrCommentexplain_accessr1rstrtype audit2whyALLOWrrBOOLEANlendatajoin CONSTRAINTTERULEperms obj_classrseinfo ATTRIBUTEsesearchSCONTEXTsrc_typeCLASSPERMSTCONTEXTappendrr8)ravrulerNxreasonrIis r __add_av_rulezPolicyGenerator.__add_av_rules# >>!^^DN <<''rT\\(RSG    -w||#))(#CA#Fw#ODL/7(BKKY^`b`l`lnsuwu}u}A~/A/!!H+/AA , QAu:?LL{|N|NPRP[P[]_]i]ikok}k}CHHINO%PPLZ1_LL}A}O}OQSQ\Q\^`^j^jlpl~l~@D@I@IJO@P%QQL ##D)=e|(A  s,< S1B7S%(S 8S% C(S% S%%S)c|jjD]Z}tj||}|jr|j |_|jjj|\y)z5Add extended permission access vector rules. N) rkeysr AVExtRulerDONTAUDITXPERMrMrr8re)rrfopextrules r__add_ext_av_rulesz"PolicyGenerator.__add_ext_av_rulessX)).."B))"b1G~~$+$:$:! KK ' ' 0 #rcD|jrO|jj||j\}}|jjj |n|}|D]>}|j ||js!|js.|j|@y)zJAdd the access from the access vector set to this module. N) rgenrrr8extend_PolicyGenerator__add_av_ruler"_PolicyGenerator__add_ext_av_rules)rav_set raw_allowifcallsrfs r add_accesszPolicyGenerator.add_accesssz ::!% !E Iw KK ' ' 0IB   r "{{ryy''+rc\|D]'}|jjj|)yr+)rr8re)r role_type_set role_types radd_role_typeszPolicyGenerator.add_role_typess$&I KK ' ' 2'rr+)NN)T)z1.0)__name__ __module__ __qualname____doc__rr$r'SHORT_EXPLANATIONr)r,r.r1r!r=r?rvrwr{rrrr r -sS.!,"$#'8 # %& "6*p 1,*3rr c gfd}|tk(r(|jD]}jd|jzjdt |j dt |j djd|jdtj|jdjd|jd |jd |jdjtj d |j"zdzd d d|S|rjd|j$d|j&d|j(d|j*j-d t/|jdkDrH|jd}jd|jd |jd |jd|S)aExplain why a policy statement was generated. Return a string containing a text explanation of why a policy statement was generated. The string is commented and wrapped and can be directly inserted into a policy. Params: av - access vector representing the access. Should have .audit_msgs set appropriately. verbosity - the amount of explanation provided. Should be set to NO_EXPLANATION, SHORT_EXPLANATION, or LONG_EXPLANATION. Returns: list of strings - strings explaining the access or an empty string if verbosity=NO_EXPLANATION or there is not sufficient information to provide an explanation. csyjdjD]P}t|jj}jd|j |j fzRy)Nz Interface options:z %s # [%d])reallcall_interface interfacerf to_stringdist)matchifcallmlss rexplain_interfacesz*explain_access..explain_interfacess]  &'VVXE#EOORUU;F HH^v'7'7'95::&FF Grz %sz scontext="z " tcontext=""z class="z " perms="z comm="z" exe="z" path="z message="Pz z )initial_indentsubsequent_indentz src="z" tgt="z " class="z ", perms="rz comm=")LONG_EXPLANATION audit_msgsreheaderrQscontexttcontexttclassrlist_to_space_straccessescommexepathrutextwrapwrapmessageratgt_typer\r[ to_space_strrV)rfrrBrmsgrs ` @rrPrP ss& AH$$==C HHUSZZ' ( HH#,,'S\\):< = HHjj)"="=cll"KM N HH377CHHU V HHX]];#z call_interface..Es%))rTkeyreverser)ruparamsvaluessortr InterfaceCallr:ifnamerangerVrRSRC_TYPEargsreraTGT_TYPEr OBJ_CLASSr\print)rrfrrrrjs rrr@s F D MM)""))+, KK+TK:  $ $ &FNNFM 3v;  !9>>Y// / KK  r{{ + AY^^y11 1 KK  r{{ + AY^^y22 2 KK  r|| , &).. ! 1  v{{ a   Mrc&eZdZddZdZdZdZy)r Ncv||_|j|tj||_g|_yr+)ifshack_check_ifsr AccessMatchermatchercalls)rrr#s rrzInterfaceGenerator.__init__Zs0 C --i8  rc|jjD]}g}|j|jj|j ddt t |D]g}|dz||jk7r d|_w||jtjtjtjfvs`d|_y)Nc|jSr+rrs rrz3InterfaceGenerator.hack_check_ifs..hs%))rTrrF)rrrurrrrVrenabledrRrrrr)rrrhrrjs rrz!InterfaceGenerator.hack_check_ifs`s &&(AF MM!((//+ , KK3TK B3v;'EfQimm+ %AI!9>>)*<*P>P*3*=*=*?? %AI( )rc*|j|}g}|jD]t}t|jj|j }|r/t jt|j |||_ |j||fvg}|D]s\}}d} |D]S} | j|s| jr1|jr%| jj|jd} U| rc|j|u||fS)NFT) rrrbestrrfrrOrPrNrematchesmerge) ravsrBraw_avrzrrdrfoundo_ifcalls rrtzInterfaceGenerator.genwsC**B#BGGI$7$7?F!*!2!2>"%%Y3W!X NNFB< (  "KFCE##F+''FNN ((..v~~> E   #{rcg}|D]u}tj}|jj|j||t |r|j j|e|j|w|Sr+)r MatchListr search_ifsrrVrre)rrrrfanss rrzInterfaceGenerator.matchseB$$&C LL # #DHHb# 63x !!#& b!  rr+)rrrrrrtrrrrr r Ys .. rr cDd}|jD] }|| y)z*Add require statements to the module. ctj}|jD]y}|jj |j |jj |j |jD]}|j||j {|jD].}|jD]}|jj|0|jD]L}|jj|j|jj |jN|jj!d|j"j%d|y)Nrr)rRequireavrulesrIupdate src_types tgt_types obj_classes add_obj_classr[interface_callsradd role_typesrolesrolediscardr8r9)noderavruleobjrargr~s rcollect_requiresz&gen_requires..collect_requiress    llnF GGNN6++ , GGNN6++ ,))V\\2*% **,F{{ C #- *I GGKK  ' GGNN9?? ++  Q"rN)nodes)rrrs rrrs!#0 r)r itertoolsrselinux.audit2whyrSsetoolsrArrrrr r rrrr rPrr rrrrrs(% Z3Z3x*;5 n2??D{  s A""A&