/usr/lib/python3.9/site-packages/sepolgen/__pycache__
NameSizeModeActions
access.cpython-39.opt-1.pyc113610644editdlrm
access.cpython-39.pyc113610644editdlrm
audit.cpython-39.opt-1.pyc172600644editdlrm
audit.cpython-39.pyc172600644editdlrm
classperms.cpython-39.opt-1.pyc24710644editdlrm
classperms.cpython-39.pyc24710644editdlrm
defaults.cpython-39.opt-1.pyc22980644editdlrm
defaults.cpython-39.pyc22980644editdlrm
interfaces.cpython-39.opt-1.pyc125920644editdlrm
interfaces.cpython-39.pyc125920644editdlrm
lex.cpython-39.opt-1.pyc213770644editdlrm
lex.cpython-39.pyc213770644editdlrm
matching.cpython-39.opt-1.pyc61690644editdlrm
matching.cpython-39.pyc61690644editdlrm
module.cpython-39.opt-1.pyc71700644editdlrm
module.cpython-39.pyc71700644editdlrm
objectmodel.cpython-39.opt-1.pyc39710644editdlrm
objectmodel.cpython-39.pyc39710644editdlrm
output.cpython-39.opt-1.pyc35450644editdlrm
output.cpython-39.pyc35450644editdlrm
policygen.cpython-39.opt-1.pyc128870644editdlrm
policygen.cpython-39.pyc129200644editdlrm
refparser.cpython-39.opt-1.pyc292590644editdlrm
refparser.cpython-39.pyc292590644editdlrm
refpolicy.cpython-39.opt-1.pyc401730644editdlrm
refpolicy.cpython-39.pyc401730644editdlrm
sepolgeni18n.cpython-39.opt-1.pyc3940644editdlrm
sepolgeni18n.cpython-39.pyc3940644editdlrm
util.cpython-39.opt-1.pyc63640644editdlrm
util.cpython-39.pyc63640644editdlrm
yacc.cpython-39.opt-1.pyc531330644editdlrm
yacc.cpython-39.pyc532120644editdlrm
__init__.cpython-39.opt-1.pyc1440644editdlrm
__init__.cpython-39.pyc1440644editdlrm
Edit: /usr/lib/python3.9/site-packages/sepolgen/__pycache__/refpolicy.cpython-39.pyc (40173B)
a BÒi©}ã@sZddlZddlZdZdZdZdZdZdZgd¢ZeeeeeedœZ Gdd „d ƒZ Gd d „d e ƒZ Gd d „d e ƒZ dsdd„Z dtdd„Zdudd„Zdd„ZGdd„deƒZGdd„de ƒZGdd„de ƒZGdd „d ƒZGd!d"„d"e ƒZGd#d$„d$e ƒZGd%d&„d&e ƒZGd'd(„d(e ƒZGd)d*„d*e ƒZGd+d,„d,e ƒZGd-d.„d.e ƒZGd/d0„d0e ƒZGd1d2„d2e ƒZGd3d4„d4e ƒZGd5d6„d6e ƒZ Gd7d8„d8e ƒZ!Gd9d:„d:e ƒZ"Gd;d<„d„d>e ƒZ$Gd?d@„d@e ƒZ%GdAdB„dBe ƒZ&GdCdD„dDe ƒZ'GdEdF„dFe ƒZ(GdGdH„dHe ƒZ)GdIdJ„dJe ƒZ*GdKdL„dLe ƒZ+GdMdN„dNe ƒZ,GdOdP„dPe ƒZ-GdQdR„dRe ƒZ.GdSdT„dTe ƒZ/GdUdV„dVe ƒZ0dWdX„Z1GdYdZ„dZe ƒZ2Gd[d\„d\e ƒZ3Gd]d^„d^e ƒZ4Gd_d`„d`e ƒZ5Gdadb„dbe ƒZ6Gdcdd„dde ƒZ7Gdedf„dfe ƒZ8Gdgdh„dhe ƒZ9Gdidj„dje ƒZ:Gdkdl„dle ƒZ;Gdmdn„dnƒZdS)véNééééé)ÚsourceÚtargetÚobjectZ permissionÚroleZ destinationc@seZdZddd„ZdS)Ú PolicyBaseNcCsd|_d|_dS©N)ÚparentÚcomment©Úselfr ©rú6/usr/lib/python3.9/site-packages/sepolgen/refpolicy.pyÚ__init__5szPolicyBase.__init__)N)Ú__name__Ú __module__Ú __qualname__rrrrrr 4sr c@sÂeZdZdZd/dd„Zdd„Zdd„Zd d „Zd d „Zd d„Z dd„Z dd„Z dd„Z dd„Z dd„Zdd„Zdd„Zdd„Zdd „Zd!d"„Zd#d$„Zd%d&„Zd'd(„Zd)d*„Zd+d,„Zd-d.„ZdS)0ÚNodeaÁBase class objects produced from parsing the reference policy. The Node class is used as the base class for any non-leaf object produced by parsing the reference policy. This object should contain a reference to its parent (or None for a top-level object) and 0 or more children. The general idea here is to have a very simple tree structure. Children are not separated out by type. Instead the tree structure represents fairly closely the real structure of the policy statements. The object should be iterable - by default over all children but subclasses are free to provide additional iterators over a subset of their childre (see Interface for example). NcCst ||¡g|_dSr )r rÚchildrenrrrrrJs z Node.__init__cCs t|jƒSr )Úiterr©rrrrÚ__iter__Nsz Node.__iter__cCstdd„t|ƒƒS)NcSs t|tƒSr )Ú isinstancer©ÚxrrrÚWózNode.nodes..©ÚfilterÚwalktreerrrrÚnodesVsz Node.nodescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚModulerrrrrZr zNode.modules..r!rrrrÚmodulesYsz Node.modulescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚ Interfacerrrrr]r z!Node.interfaces..r!rrrrÚ interfaces\szNode.interfacescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚTemplaterrrrr`r z Node.templates..r!rrrrÚ templates_szNode.templatescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚ SupportMacrosrrrrrcr z%Node.support_macros..r!rrrrÚsupport_macrosbszNode.support_macroscCstdd„t|ƒƒS)NcSs t|tƒSr )rÚModuleDeclarationrrrrrhr z*Node.module_declarations..r!rrrrÚmodule_declarationsgszNode.module_declarationscCstdd„t|ƒƒS)NcSs t|tƒSr )rÚ InterfaceCallrrrrrkr z&Node.interface_calls..r!rrrrÚinterface_callsjszNode.interface_callscCstdd„t|ƒƒS)NcSs t|tƒSr )rÚAVRulerrrrrnr zNode.avrules..r!rrrrÚavrulesmsz Node.avrulescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚ AVExtRulerrrrrqr z!Node.avextrules..r!rrrrÚ avextrulespszNode.avextrulescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚTypeRulerrrrrtr z Node.typerules..r!rrrrÚ typerulessszNode.typerulescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚ TypeBoundrrrrrwr z!Node.typebounds..r!rrrrÚ typeboundsvszNode.typeboundscCstdd„t|ƒƒS)zAIterate over all of the TypeAttribute children of this Interface.cSs t|tƒSr )rÚ TypeAttributerrrrr{r z%Node.typeattributes..r!rrrrÚtypeattributesyszNode.typeattributescCstdd„t|ƒƒS)zAIterate over all of the RoleAttribute children of this Interface.cSs t|tƒSr )rÚ RoleAttributerrrrrr z%Node.roleattributes..r!rrrrÚroleattributes}szNode.roleattributescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚRequirerrrrr‚r zNode.requires..r!rrrrÚrequires�sz Node.requirescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚRolerrrrr…r zNode.roles..r!rrrrÚroles„sz Node.rolescCstdd„t|ƒƒS)NcSs t|tƒSr )rÚ RoleAllowrrrrrˆr z"Node.role_allows..r!rrrrÚ role_allows‡szNode.role_allowscCstdd„t|ƒƒS)NcSs t|tƒSr )rÚRoleTyperrrrr‹r z!Node.role_types..r!rrrrÚ role_typesŠszNode.role_typescCs(|jrt|jƒd| ¡S| ¡SdS©NÚ ©rÚstrÚ to_stringrrrrÚ__str__�sz Node.__str__cCsd|jj| ¡fS©Nz<%s(%s)>©Ú __class__rrIrrrrÚ__repr__“sz Node.__repr__cCsdS©NÚrrrrrrI–szNode.to_string)N)rrrÚ__doc__rrr$r&r(r*r,r.r0r2r4r6r8r:r<r>r@rBrDrJrNrIrrrrr9s. rc@s.eZdZd dd„Zdd„Zdd„Zdd „ZdS) ÚLeafNcCst ||¡dSr )r rrrrrr›sz Leaf.__init__cCs(|jrt|jƒd| ¡S| ¡SdSrErGrrrrrJžsz Leaf.__str__cCsd|jj| ¡fSrKrLrrrrrN¤sz Leaf.__repr__cCsdSrOrrrrrrI§szLeaf.to_string)N)rrrrrJrNrIrrrrrRšs rRTFc cs¶|r d}nd}|dfg}t|ƒdkr²| |¡\}}|rB||fVn|Vt|tƒrg}t|jƒd} | dkr¦|dus„t|j| |ƒrœ| |j| |df¡| d8} qd| |¡qdS)a™Iterate over a Node and its Children. The walktree function iterates over a tree containing Nodes and leaf objects. The iteration can perform a depth first or a breadth first traversal of the tree (controlled by the depthfirst parameter. The passed in node will be returned. This function will only work correctly for trees - arbitrary graphs will likely cause infinite looping. éÿÿÿÿrrN)ÚlenÚpoprrrÚappendÚextend) ÚnodeZ depthfirstÚ showdepthÚtypeÚindexÚstackZcurÚdepthÚitemsÚirrrr#®s"      r#ccs&|D]}|dust||ƒr|VqdS)aIterate over the direct children of a Node. The walktree function iterates over the children of a Node. Unlike walktree it does note return the passed in node or the children of any Node objects (that is, it does not go beyond the current level in the tree). N)r)rXrZrrrrÚwalknodeÔsr`©Ú{Ú}cCsRt|ƒ}d}|dkrtdƒ‚d |¡}|dkr2|S|dd|d|dSdS)záConvert a set (or any sequence type) into a string representation formatted to match SELinux space separated list conventions. For example the list ['read', 'write'] would be converted into: '{ read write }' rPrz"cannot convert 0 len set to stringú rN©rTÚ ValueErrorÚjoin)ÚsÚcontÚlrHrrrÚlist_to_space_strás rkcCs"t|ƒ}|dkrtdƒ‚d |¡S)Nrz(cannot convert 0 len set to comma stringz, re)rhrjrrrÚlist_to_comma_stròsrlc@s&eZdZddd„Zdd„Zdd„ZdS) ÚIdSetNcCs&|rt ||¡n t |¡d|_dS)NF)ÚsetrZ compliment)rÚlistrrrrüs zIdSet.__init__cCs tt|ƒƒSr )rkÚsortedrrrrÚ to_space_strszIdSet.to_space_strcCs tt|ƒƒSr )rlrprrrrÚ to_comma_strszIdSet.to_comma_str)N)rrrrrqrrrrrrrmûs rmc@s4eZdZdZd dd„Zdd„Zdd„Zd d d „ZdS) ÚSecurityContextz;An SELinux security context with optional MCS / MLS fields.NcCs:t ||¡d|_d|_d|_d|_|dur6| |¡dS)zßCreate a SecurityContext object, optionally from a string. Parameters: [context] - string representing a security context. Same format as a string passed to the from_string method. rPN)rRrÚuserr rZÚlevelÚ from_string)rÚcontextr rrrr s zSecurityContext.__init__cCsŠt |¡}|ddkr|d}| d¡}t|ƒdkr@td|ƒ‚|d|_|d|_|d|_t|ƒdkr€d |dd…¡|_ nd|_ dS)zóParse a string representing a context into a SecurityContext. The string should be in the standard format - e.g., 'user:role:type:level'. Raises ValueError if the string is not parsable as a security context. rrú:rz)context string [%s] not in a valid formatrN) ÚselinuxZselinux_trans_to_raw_contextÚsplitrTrfrtr rZrgru)rrwÚrawÚfieldsrrrrvs         zSecurityContext.from_stringcCs0|j|jko.|j|jko.|j|jko.|j|jkS)aCompare two SecurityContext objects - all fields must be exactly the the same for the comparison to work. It is possible for the level fields to be semantically the same yet syntactically different - in this case this function will return false. )rtr rZru)rÚotherrrrÚ__eq__4s  ÿ þ ýzSecurityContext.__eq__cCs\|j|j|jg}|jdurF|dur:t ¡dkrD| d¡qR| |¡n | |j¡d |¡S)a½Return a string representing this security context. By default, the string will contiain a MCS / MLS level potentially from the default which is passed in if none was set. Arguments: default_level - the default level to use if self.level is an empty string. Returns: A string represening the security context in the form 'user:role:type:level'. NrZs0rx)rtr rZruryZis_selinux_mls_enabledrVrg)rZ default_levelr|rrrrI?s     zSecurityContext.to_string)NN)N)rrrrQrrvr~rIrrrrrs s   rsc@seZdZdZddd„ZdS)Ú ObjectClassa"SELinux object class and permissions. This class is a basic representation of an SELinux object class - it does not represent separate common permissions - just the union of the common and class specific permissions. It is meant to be convenient for policy generation. rPNcCst ||¡||_tƒ|_dSr )rRrÚnamermÚperms©rr€r rrrras zObjectClass.__init__)rPN)rrrrQrrrrrrYsrc@s<eZdZdZddd„Zdd„Zdd„Zdd d „Zd d „Zd S)ÚXpermSeta)Extended permission set. This class represents one or more extended permissions represented by numeric values or ranges of values. The .complement attribute is used to specify all permission except those specified. Two xperm set can be merged using the .extend() method. FcCs||_g|_dSr )Ú complementÚranges)rr„rrrrpszXpermSet.__init__cCs¨|j ¡d}|t|jƒkr¤|dt|jƒkrš|j|dd|j|ddkrš|j|dt|j|d|j|ddƒf|j|<|j|d=qqšq|d7}qdS)z0Ensure that ranges are not overlapping. rrN)r…ÚsortrTÚmax)rr_rrrZ__normalize_rangests $ÿ zXpermSet.__normalize_rangescCs|j |j¡| ¡dS)z%Add ranges from an xperm set N)r…rWÚ_XpermSet__normalize_ranges©rrhrrrrW„szXpermSet.extendNcCs(|dur |}|j ||f¡| ¡dS)z7Add value of range of values to the xperm set. N)r…rVrˆ)rZminimumZmaximumrrrÚaddŠsz XpermSet.addcCsz|js dS|jrdnd}t|jƒdkrX|jdd|jddkrX|t|jddƒStdd„|jƒ}d|d |¡fS) NrPz~ rrcSs8|d|dkrt|dƒSdt|dƒt|dƒfS)Nrrz%s-%s)Úhexrrrrrœr z$XpermSet.to_string..z%s{ %s }rd)r…r„rTr‹Úmaprg)rZcomplZvalsrrrrI’s*zXpermSet.to_string)F)N) rrrrQrrˆrWrŠrIrrrrrƒfs   rƒc@s"eZdZdZddd„Zdd„ZdS)r9z[SElinux typeattribute statement. This class represents a typeattribute statement. NcCst ||¡d|_tƒ|_dSrO)rRrrZrmÚ attributesrrrrr§s zTypeAttribute.__init__cCsd|j|j ¡fS)Nztypeattribute %s %s;)rZr�rrrrrrrI¬szTypeAttribute.to_string)N©rrrrQrrIrrrrr9¢s r9c@s"eZdZdZddd„Zdd„ZdS)r;z[SElinux roleattribute statement. This class represents a roleattribute statement. NcCst ||¡d|_tƒ|_dSrO)rRrr rmr<rrrrr´s zRoleAttribute.__init__cCsd|j|j ¡fS)Nzroleattribute %s %s;)r r<rrrrrrrI¹szRoleAttribute.to_string)NrŽrrrrr;¯s r;c@seZdZddd„Zdd„ZdS)r?NcCst ||¡d|_tƒ|_dSrO©rRrr rmÚtypesrrrrr¾s z Role.__init__cCs&d}|jD]}|d|j|f7}q |S©NrPzrole %s types %s; ©r�r ©rrhÚtrrrrIÃs zRole.to_string)N©rrrrrIrrrrr?½s r?c@seZdZddd„Zdd„ZdS)ÚTyperPNcCs&t ||¡||_tƒ|_tƒ|_dSr )rRrr€rmr�Úaliasesr‚rrrrÊs z Type.__init__cCsRd|j}t|jƒdkr*|d|j ¡}t|jƒdkrJ|d|j ¡}|dS)Nztype %srzalias %sú, %sú;)r€rTr—rqr�rrr‰rrrrIÐs  zType.to_string)rPNr•rrrrr–És r–c@seZdZddd„Zdd„ZdS)Ú TypeAliasNcCst ||¡d|_tƒ|_dSrO)rRrrZrmr—rrrrrÙs zTypeAlias.__init__cCsd|j|j ¡fS)Nztypealias %s alias %s;)rZr—rqrrrrrIÞszTypeAlias.to_string)Nr•rrrrršØs ršc@seZdZddd„Zdd„ZdS)Ú AttributerPNcCst ||¡||_dSr ©rRrr€r‚rrrrâs zAttribute.__init__cCs d|jS)Nz attribute %s;©r€rrrrrIæszAttribute.to_string)rPNr•rrrrr›ás r›c@seZdZddd„Zdd„ZdS)ÚAttribute_RolerPNcCst ||¡||_dSr rœr‚rrrrês zAttribute_Role.__init__cCs d|jS)Nzattribute_role %s;r�rrrrrIîszAttribute_Role.to_string)rPNr•rrrrržés ržc@sBeZdZdZdZdZdZdZddd„Zd d „Z d d „Z d d„Z dS)r1a»SELinux access vector (AV) rule. The AVRule class represents all varieties of AV rules including allow, dontaudit, and auditallow (indicated by the flags self.ALLOW, self.DONTAUDIT, and self.AUDITALLOW respectively). The source and target types, object classes, and perms are all represented by sets containing strings. Sets are used to make it simple to add strings repeatedly while avoiding duplicates. No checking is done to make certain that the symbols are valid or consistent (e.g., perms that don't match the object classes). It is even possible to put invalid types like '$1' into the rules to allow storage of the reference policy interfaces. rrrrNcCsFt ||¡tƒ|_tƒ|_tƒ|_tƒ|_|j|_|rB|  |¡dSr ) rRrrmÚ src_typesÚ tgt_typesÚ obj_classesr�ÚALLOWÚ rule_typeÚfrom_av)rÚavr rrrr s zAVRule.__init__cCsD|j|jkrdS|j|jkr dS|j|jkr0dS|j|jkr@dSdS)NZallowZ dontauditZ auditallowZ neverallow)r£r¢Ú DONTAUDITÚ AUDITALLOWÚ NEVERALLOWrrrrÚ__rule_type_strs    zAVRule.__rule_type_strcCsV|j |j¡|j|jkr(|j d¡n|j |j¡|j |j¡|j |j¡dS)zIAdd the access from an access vector to this allow rule. rN) rŸrŠÚsrc_typeÚtgt_typer r¡Ú obj_classr�Úupdate)rr¥rrrr¤s  zAVRule.from_avcCs.d| ¡|j ¡|j ¡|j ¡|j ¡fS)z«Return a string representation of the rule that is a valid policy language representation (assuming that the types, object class, etc. are valie). ú%s %s %s:%s %s;)Ú_AVRule__rule_type_strrŸrqr r¡r�rrrrrI)s üzAVRule.to_string)NN) rrrrQr¢r¦r§r¨rr¯r¤rIrrrrr1ôs   r1c@sBeZdZdZdZdZdZdZddd„Zd d „Z d d „Z d d„Z dS)r3ajExtended permission access vector rule. The AVExtRule class represents allowxperm, dontauditxperm, auditallowxperm, and neverallowxperm rules. The source and target types, and object classes are represented by sets containing strings. The operation is a single string, e.g. 'ioctl'. Extended permissions are represented by an XpermSet. rrrrNcCsNt ||¡tƒ|_tƒ|_tƒ|_|j|_tƒ|_ ||_ |rJ|  ||¡dSr ) rRrrmrŸr r¡Ú ALLOWXPERMr£rƒÚxpermsÚ operationr¤)rr¥Úopr rrrrCs zAVExtRule.__init__cCsD|j|jkrdS|j|jkr dS|j|jkr0dS|j|jkr@dSdS)NZ allowxpermZdontauditxpermZauditallowxpermZneverallowxperm)r£r°ÚDONTAUDITXPERMÚAUDITALLOWXPERMÚNEVERALLOWXPERMrrrrr©Ns    zAVExtRule.__rule_type_strcCsZ|j |j¡|j|jkr(|j d¡n|j |j¡|j |j¡||_|j||_dS)Nr) rŸrŠrªr«r r¡r¬r²r±)rr¥r³rrrr¤Xs zAVExtRule.from_avcCs2d| ¡|j ¡|j ¡|j ¡|j|j ¡fS)z«Return a string representation of the rule that is a valid policy language representation (assuming that the types, object class, etc. are valid). z%s %s %s:%s %s %s;)Ú_AVExtRule__rule_type_strrŸrqr r¡r²r±rIrrrrrIbsûzAVExtRule.to_string)NNN) rrrrQr°r´rµr¶rr·r¤rIrrrrr34s    r3c@s6eZdZdZdZdZdZd dd„Zdd „Zd d „Z dS) r5zöSELinux type rules. This class is very similar to the AVRule class, but is for representing the type rules (type_trans, type_change, and type_member). The major difference is the lack of perms and only and sing destination type. rrrNcCs6t ||¡tƒ|_tƒ|_tƒ|_d|_|j|_dSrO) rRrrmrŸr r¡Ú dest_typeÚTYPE_TRANSITIONr£rrrrrys  zTypeRule.__init__cCs(|j|jkrdS|j|jkr dSdSdS)NZtype_transitionZ type_changeZ type_member)r£r¹Ú TYPE_CHANGErrrrr©�s   zTypeRule.__rule_type_strcCs*d| ¡|j ¡|j ¡|j ¡|jfS)Nr®)Ú_TypeRule__rule_type_strrŸrqr r¡r¸rrrrrI‰s üzTypeRule.to_string)N) rrrrQr¹rºZ TYPE_MEMBERrr»rIrrrrr5ns r5c@s"eZdZdZddd„Zdd„ZdS)r7zSSElinux typebound statement. This class represents a typebound statement. NcCst ||¡d|_tƒ|_dSrO)rRrrZrmr rrrrr”s zTypeBound.__init__cCsd|j|j ¡fS)Nztypebounds %s %s;)rZr rrrrrrrI™szTypeBound.to_string)NrŽrrrrr7�s r7c@seZdZddd„Zdd„ZdS)rANcCs t ||¡tƒ|_tƒ|_dSr )rRrrmÚ src_rolesÚ tgt_rolesrrrrržs zRoleAllow.__init__cCsd|j ¡|j ¡fS)Nz allow %s %s;)r¼rrr½rrrrrI£s ÿzRoleAllow.to_string)Nr•rrrrrA�s rAc@seZdZddd„Zdd„ZdS)rCNcCst ||¡d|_tƒ|_dSrOr�rrrrr¨s zRoleType.__init__cCs&d}|jD]}|d|j|f7}q |Sr‘r’r“rrrrI­s zRoleType.to_string)Nr•rrrrrC§s rCc@seZdZddd„Zdd„ZdS)r-NcCs"t ||¡d|_d|_d|_dS©NrPF)rRrr€ÚversionÚ refpolicyrrrrr´s zModuleDeclaration.__init__cCs*|jrd|j|jfSd|j|jfSdS)Nzpolicy_module(%s, %s)z module %s %s;)rÀr€r¿rrrrrIºszModuleDeclaration.to_string)Nr•rrrrr-³s r-c@seZdZddd„Zdd„ZdS)Ú ConditionalNcCst ||¡g|_dSr ©rrÚ cond_exprrrrrrÁs zConditional.__init__cCsdt|jdd�S)Nz[If %s]©rPrP©ri©rkrÃrrrrrIÅszConditional.to_string)Nr•rrrrrÁÀs rÁc@seZdZddd„Zdd„ZdS)ÚBoolNcCst ||¡d|_d|_dSr¾)rRrr€ÚstaterrrrrÉs z Bool.__init__cCs$d|j}|jr|dS|dSdS)Nzbool %s ÚtrueZfalse)r€rÈr‰rrrrIÎs zBool.to_string)Nr•rrrrrÇÈs rÇc@seZdZddd„Zdd„ZdS)Ú InitialSidNcCst ||¡d|_d|_dSrO)rRrr€rwrrrrZ__initÖs zInitialSid.__initcCsd|jt|jƒfS)Nz sid %s %s)r€rHrwrrrrrIÛszInitialSid.to_string)N)rrrZ_InitialSid__initrIrrrrrÊÕs rÊc@seZdZddd„Zdd„ZdS)ÚGenfsConNcCs"t ||¡d|_d|_d|_dSrO)rRrÚ filesystemÚpathrwrrrrrßs zGenfsCon.__init__cCsd|j|jt|jƒfS)Nzgenfscon %s %s %s)rÌrÍrHrwrrrrrIåszGenfsCon.to_string)Nr•rrrrrËÞs rËc@s*eZdZdZdZdZd dd„Zdd„ZdS) Ú FilesystemUserrrNcCs$t ||¡|j|_d|_d|_dSrO)rRrÚXATTRrZrÌrwrrrrrís zFilesystemUse.__init__cCsNd}|j|jkrd}n"|j|jkr(d}n|j|jkr8d}d||jt|jƒfS)NrPz fs_use_xattr z fs_use_trans z fs_use_task z %s %s %s;)rZrÏÚTRANSÚTASKrÌrHrwr‰rrrrIós   zFilesystemUse.to_string)N)rrrrÏrÐrÑrrIrrrrrÎès  rÎc@seZdZddd„Zdd„ZdS)ÚPortConNcCs"t ||¡d|_d|_d|_dSrO)rRrÚ port_typeÚ port_numberrwrrrrrÿs zPortCon.__init__cCsd|j|jt|jƒfS)Nzportcon %s %s %s)rÓrÔrHrwrrrrrIszPortCon.to_string)Nr•rrrrrÒþs rÒc@seZdZddd„Zdd„ZdS)ÚNodeConNcCs"t ||¡d|_d|_d|_dSrO)rRrÚstartÚendrwrrrrr s zNodeCon.__init__cCsd|j|jt|jƒfS)Nznodecon %s %s %s)rÖr×rHrwrrrrrIszNodeCon.to_string)Nr•rrrrrÕs rÕc@seZdZddd„Zdd„ZdS)ÚNetifConNcCs"t ||¡d|_d|_d|_dSrO)rRrÚ interfaceÚinterface_contextÚpacket_contextrrrrrs zNetifCon.__init__cCsd|jt|jƒt|jƒfS)Nznetifcon %s %s %s)rÙrHrÚrÛrrrrrIsÿzNetifCon.to_string)Nr•rrrrrØs rØc@seZdZddd„Zdd„ZdS)ÚPirqConNcCst ||¡d|_d|_dSrO)rRrÚ pirq_numberrwrrrrrs zPirqCon.__init__cCsd|jt|jƒfS)Nz pirqcon %s %s)rÝrHrwrrrrrI"szPirqCon.to_string)Nr•rrrrrÜs rÜc@seZdZddd„Zdd„ZdS)ÚIomemConNcCst ||¡d|_d|_dSrO)rRrÚ device_memrwrrrrr&s zIomemCon.__init__cCsd|jt|jƒfS)Nziomemcon %s %s)rßrHrwrrrrrI+szIomemCon.to_string)Nr•rrrrrÞ%s rÞc@seZdZddd„Zdd„ZdS)Ú IoportConNcCst ||¡d|_d|_dSrO)rRrÚioportrwrrrrr/s zIoportCon.__init__cCsd|jt|jƒfS)Nzioportcon %s %s)rárHrwrrrrrI4szIoportCon.to_string)Nr•rrrrrà.s ràc@seZdZddd„Zdd„ZdS)Ú PciDeviceConNcCst ||¡d|_d|_dSrO)rRrÚdevicerwrrrrr8s zPciDeviceCon.__init__cCsd|jt|jƒfS)Nzpcidevicecon %s %s)rãrHrwrrrrrI=szPciDeviceCon.to_string)Nr•rrrrrâ7s râc@seZdZddd„Zdd„ZdS)Ú DeviceTreeConNcCst ||¡d|_d|_dSrO)rRrrÍrwrrrrrAs zDeviceTreeCon.__init__cCsd|jt|jƒfS)Nzdevicetreecon %s %s)rÍrHrwrrrrrIFszDeviceTreeCon.to_string)Nr•rrrrrä@s räcCsDt|dd�D]2\}}d}t|ƒD] }|d}q t|t|ƒƒq dS)NT)rYrPú )r#ÚrangeÚprintrH)ÚheadrXr]rhr_rrrÚ print_treeKs   réc@seZdZddd„Zdd„ZdS)ÚHeadersNcCst ||¡dSr ©rrrrrrrTszHeaders.__init__cCsdS)Nz [Headers]rrrrrrIWszHeaders.to_string)Nr•rrrrrêSs rêc@seZdZddd„Zdd„ZdS)r%NcCst ||¡dSr rërrrrr\szModule.__init__cCsdSrOrrrrrrI_szModule.to_string)Nr•rrrrr%[s r%c@s"eZdZdZddd„Zdd„ZdS) r'zqA reference policy interface definition. This class represents a reference policy interface definition. rPNcCst ||¡||_dSr ©rrr€r‚rrrrgs zInterface.__init__cCs d|jS)Nz[Interface name: %s]r�rrrrrIkszInterface.to_string)rPNrŽrrrrr'bs r'c@seZdZddd„Zdd„ZdS)Ú TunablePolicyNcCst ||¡g|_dSr rÂrrrrros zTunablePolicy.__init__cCsdt|jdd�S)Nz[Tunable Policy %s]rÄrÅrÆrrrrrIsszTunablePolicy.to_string)Nr•rrrrríns ríc@seZdZddd„Zdd„ZdS)r)rPNcCst ||¡||_dSr rìr‚rrrrws zTemplate.__init__cCs d|jS)Nz[Template name: %s]r�rrrrrI{szTemplate.to_string)rPNr•rrrrr)vs r)c@seZdZddd„Zdd„ZdS)ÚIfDefrPNcCst ||¡||_dSr rìr‚rrrrs zIfDef.__init__cCs d|jS)Nz[Ifdef name: %s]r�rrrrrIƒszIfDef.to_string)rPNr•rrrrrî~s rîc@s&eZdZd dd„Zdd„Zdd„ZdS) r/rPNcCs"t ||¡||_g|_g|_dSr )rRrÚifnameÚargsZcomments)rrïr rrrr‡s zInterfaceCall.__init__cCsR|j|jkrdSt|jƒt|jƒkr(dSt|j|jƒD]\}}||kr6dSq6dS)NFT)rïrTrðÚzip)rr}ÚaÚbrrrÚmatches�s zInterfaceCall.matchescCs`d|j}d}|jD]B}t|tƒr,t|ƒ}n|}|dkrF|d|}n||}|d7}q|dS)Nz%s(rr˜rú))rïrðrrork)rrhr_ròrHrrrrI—s     zInterfaceCall.to_string)rPN)rrrrrôrIrrrrr/†s  r/c@seZdZddd„Zdd„ZdS)ÚOptionalPolicyNcCst ||¡dSr rërrrrr¨szOptionalPolicy.__init__cCsdS)Nz[Optional Policy]rrrrrrI«szOptionalPolicy.to_string)Nr•rrrrrö§s röc@s>eZdZddd„Zdd„Zdd„Zdd „Zd d „Zd d „ZdS)r+NcCst ||¡d|_dSr )rrrŒrrrrr¯s zSupportMacros.__init__cCsdS)Nz[Support Macros]rrrrrrI³szSupportMacros.to_stringcCs@tƒ}||jvr2| |¡D]}| | |¡¡qn | |¡|Sr )rnrŒÚby_namer­Ú_SupportMacros__expand_permrŠ)rÚpermrhÚprrrZ __expand_perm¶s   zSupportMacros.__expand_permcCsBi|_|D]2}tƒ}|jD]}| | |¡¡q||j|j<q dSr )rŒrnr�r­rør€)rrZ exp_permsrùrrrZ __gen_mapÂs  zSupportMacros.__gen_mapcCs|js| ¡|j|Sr ©rŒÚ_SupportMacros__gen_map©rr€rrrr÷ÊszSupportMacros.by_namecCs|js| ¡||jvSr rûrýrrrÚhas_keyÏszSupportMacros.has_key)N) rrrrrIrørür÷rþrrrrr+®s   r+c@s&eZdZddd„Zdd„Zdd„ZdS) r=NcCs6t ||¡tƒ|_i|_tƒ|_tƒ|_tƒ|_dSr )rRrrmr�r¡r@ÚdataÚusersrrrrrÕs  zRequire.__init__cCs|j |tƒ¡}| |¡dSr )r¡Ú setdefaultrmr­)rr¬r�rúrrrÚ add_obj_classÝszRequire.add_obj_classcCsÄg}| d¡|jD]}| d|¡q|j ¡D]\}}| d|| ¡f¡q2|jD]}| d|¡qX|jD]}| d|¡qr|jD]}| d|¡qŒ| d¡t|ƒdkrºd Sd   |¡S) Nz require {z type %s;z class %s %s;z role %s;z bool %s;z user %s;rcrrPrF) rVr�r¡r^rqr@rÿrrTrg)rrhrZr¬r�r ÚboolrtrrrrIâs        zRequire.to_string)N)rrrrrrIrrrrr=Ôs r=c@seZdZdd„Zdd„ZdS)Ú ObjPermSetcCs||_tƒ|_dSr )r€rnr�rýrrrrùszObjPermSet.__init__cCsd|j|j ¡fS)Nzdefine(`%s', `%s'))r€r�rqrrrrrIýszObjPermSet.to_stringNr•rrrrrøsrc@seZdZdd„Zdd„ZdS)ÚClassMapcCs||_||_dSr ©r¬r�)rr¬r�rrrrszClassMap.__init__cCs|jd|jS)Nz: rrrrrrIszClassMap.to_stringNr•rrrrrsrc@s.eZdZd dd„Zdd„Zdd„Zdd „ZdS) ÚCommentNcCs|r ||_ng|_dSr )Úlines)rrjrrrr szComment.__init__cCs>t|jƒdkrdSg}|jD]}| d|¡qd |¡SdS)NrrPú#rF)rTrrVrg)rÚoutÚlinerrrrIs  zComment.to_stringcCs.t|jƒr*|jD]}|dkr|j |¡qdSrO)rTrrV)rr}r rrrÚmerges  z Comment.mergecCs| ¡Sr )rIrrrrrJ szComment.__str__)N)rrrrrIr rJrrrrrs  r)TFN)N)ra)?ÚstringryZSRC_TYPEZTGT_TYPEZ OBJ_CLASSZPERMSZROLEZ DEST_TYPEZ field_to_strZ str_to_fieldr rrRr#r`rkrlrnrmrsrrƒr9r;r?r–ršr›ržr1r3r5r7rArCr-rÁrÇrÊrËrÎrÒrÕrØrÜrÞràrârärérêr%r'rír)rîr/rör+r=rrrrrrrÚs~ÿa &  P <    @:!               !&$