45 items
NAME ↑ SIZE MODIFIED PERMS ACTIONS
.. / Parent Directory
__pycache__ — dir
2024-11-25 21:02 · rwxr-xr-x
2024-11-25 21:02 rwxr-xr-x
checker — dir
2024-11-25 21:02 · rwxr-xr-x
2024-11-25 21:02 rwxr-xr-x
diff — dir
2024-11-25 21:02 · rwxr-xr-x
2024-11-25 21:02 rwxr-xr-x
__init__.py — 3.24 KB
2023-12-07 15:49 · rw-r--r--
3.24 KB 2023-12-07 15:49 rw-r--r--
boolquery.py — 1.7 KB
2023-12-07 15:49 · rw-r--r--
1.7 KB 2023-12-07 15:49 rw-r--r--
boundsquery.py — 1.8 KB
2023-12-07 15:49 · rw-r--r--
1.8 KB 2023-12-07 15:49 rw-r--r--
categoryquery.py — 1.34 KB
2023-12-07 15:49 · rw-r--r--
1.34 KB 2023-12-07 15:49 rw-r--r--
commonquery.py — 1.58 KB
2023-12-07 15:49 · rw-r--r--
1.58 KB 2023-12-07 15:49 rw-r--r--
constraintquery.py — 4.99 KB
2023-12-07 15:49 · rw-r--r--
4.99 KB 2023-12-07 15:49 rw-r--r--
defaultquery.py — 2.29 KB
2023-12-07 15:49 · rw-r--r--
2.29 KB 2023-12-07 15:49 rw-r--r--
descriptors.py — 9.7 KB
2023-12-07 15:49 · rw-r--r--
9.7 KB 2023-12-07 15:49 rw-r--r--
devicetreeconquery.py — 2.22 KB
2023-12-07 15:49 · rw-r--r--
2.22 KB 2023-12-07 15:49 rw-r--r--
dta.py — 22.67 KB
2023-12-07 15:49 · rw-r--r--
22.67 KB 2023-12-07 15:49 rw-r--r--
exception.py — 5.96 KB
2023-12-07 15:49 · rw-r--r--
5.96 KB 2023-12-07 15:49 rw-r--r--
fsusequery.py — 2.8 KB
2023-12-07 15:49 · rw-r--r--
2.8 KB 2023-12-07 15:49 rw-r--r--
genfsconquery.py — 3.18 KB
2023-12-07 15:49 · rw-r--r--
3.18 KB 2023-12-07 15:49 rw-r--r--
ibendportconquery.py — 3.05 KB
2023-12-07 15:49 · rw-r--r--
3.05 KB 2023-12-07 15:49 rw-r--r--
ibpkeyconquery.py — 4.89 KB
2023-12-07 15:49 · rw-r--r--
4.89 KB 2023-12-07 15:49 rw-r--r--
infoflow.py — 15.54 KB
2023-12-07 15:49 · rw-r--r--
15.54 KB 2023-12-07 15:49 rw-r--r--
initsidquery.py — 2.25 KB
2023-12-07 15:49 · rw-r--r--
2.25 KB 2023-12-07 15:49 rw-r--r--
iomemconquery.py — 4 KB
2023-12-07 15:49 · rw-r--r--
4 KB 2023-12-07 15:49 rw-r--r--
ioportconquery.py — 4.02 KB
2023-12-07 15:49 · rw-r--r--
4.02 KB 2023-12-07 15:49 rw-r--r--
mixins.py — 6.82 KB
2023-12-07 15:49 · rw-r--r--
6.82 KB 2023-12-07 15:49 rw-r--r--
mlsrulequery.py — 4.09 KB
2023-12-07 15:49 · rw-r--r--
4.09 KB 2023-12-07 15:49 rw-r--r--
netifconquery.py — 2.4 KB
2023-12-07 15:49 · rw-r--r--
2.4 KB 2023-12-07 15:49 rw-r--r--
nodeconquery.py — 3.9 KB
2023-12-07 15:49 · rw-r--r--
3.9 KB 2023-12-07 15:49 rw-r--r--
objclassquery.py — 3.27 KB
2023-12-07 15:49 · rw-r--r--
3.27 KB 2023-12-07 15:49 rw-r--r--
pcideviceconquery.py — 2.58 KB
2023-12-07 15:49 · rw-r--r--
2.58 KB 2023-12-07 15:49 rw-r--r--
perm_map — 84.1 KB
2023-12-07 15:49 · rw-r--r--
84.1 KB 2023-12-07 15:49 rw-r--r--
permmap.py — 16.2 KB
2023-12-07 15:49 · rw-r--r--
16.2 KB 2023-12-07 15:49 rw-r--r--
pirqconquery.py — 2.48 KB
2023-12-07 15:49 · rw-r--r--
2.48 KB 2023-12-07 15:49 rw-r--r--
polcapquery.py — 1.12 KB
2023-12-07 15:49 · rw-r--r--
1.12 KB 2023-12-07 15:49 rw-r--r--
policyrep.cpython-39-x86_64-linux-gnu.so — 1.45 MB
2024-04-03 16:13 · rwxr-xr-x
1.45 MB 2024-04-03 16:13 rwxr-xr-x
policyrep.pyi — 51.03 KB
2023-12-07 15:49 · rw-r--r--
51.03 KB 2023-12-07 15:49 rw-r--r--
portconquery.py — 4.77 KB
2023-12-07 15:49 · rw-r--r--
4.77 KB 2023-12-07 15:49 rw-r--r--
py.typed — 0 B
2023-12-07 15:49 · rw-r--r--
0 B 2023-12-07 15:49 rw-r--r--
query.py — 1.24 KB
2023-12-07 15:49 · rw-r--r--
1.24 KB 2023-12-07 15:49 rw-r--r--
rbacrulequery.py — 5.33 KB
2023-12-07 15:49 · rw-r--r--
5.33 KB 2023-12-07 15:49 rw-r--r--
rolequery.py — 1.95 KB
2023-12-07 15:49 · rw-r--r--
1.95 KB 2023-12-07 15:49 rw-r--r--
sensitivityquery.py — 2.22 KB
2023-12-07 15:49 · rw-r--r--
2.22 KB 2023-12-07 15:49 rw-r--r--
terulequery.py — 8.73 KB
2023-12-07 15:49 · rw-r--r--
8.73 KB 2023-12-07 15:49 rw-r--r--
typeattrquery.py — 2.11 KB
2023-12-07 15:49 · rw-r--r--
2.11 KB 2023-12-07 15:49 rw-r--r--
typequery.py — 2.95 KB
2023-12-07 15:49 · rw-r--r--
2.95 KB 2023-12-07 15:49 rw-r--r--
userquery.py — 4.19 KB
2023-12-07 15:49 · rw-r--r--
4.19 KB 2023-12-07 15:49 rw-r--r--
util.py — 7.59 KB
2023-12-07 15:49 · rw-r--r--
7.59 KB 2023-12-07 15:49 rw-r--r--
ONLINE
setools
45 items
23:48:01
TERMINAL FM
Edit
Preview
Download
Rename
Copy
Chmod
Delete
# Copyright 2015, Tresys Technology, LLC # Copyright 2019, Chris PeBenito # # SPDX-License-Identifier: LGPL-2.1-only # # pylint: disable=attribute-defined-outside-init,no-member import re from logging import Logger from typing import Iterable from .descriptors import CriteriaDescriptor, CriteriaSetDescriptor, CriteriaPermissionSetDescriptor from .policyrep import Context from .util import match_in_set, match_regex, match_range, match_regex_or_set class MatchAlias: """Mixin for matching an object's aliases.""" alias = CriteriaDescriptor("alias_regex") alias_regex: bool = False def _match_alias_debug(self, log: Logger) -> None: """Emit log debugging info for alias matching.""" log.debug("Alias: {0.alias}, regex: {0.alias_regex}".format(self)) def _match_alias(self, obj): """ Match the alias criteria Parameter: obj An object with an alias generator method named "aliases" """ if not self.alias: # if there is no criteria, everything matches. return True return match_in_set(obj.aliases(), self.alias, self.alias_regex) class MatchContext: """ Mixin for matching contexts. Class attributes: user The user to match in the context. user_regex If true, regular expression matching will be used on the user. role The role to match in the context. role_regex If true, regular expression matching will be used on the role. type_ The type to match in the context. type_regex If true, regular expression matching will be used on the type. range_ The range to match in the context. range_subset If true, the criteria will match if it is a subset of the context's range. range_overlap If true, the criteria will match if it overlaps any of the context's range. range_superset If true, the criteria will match if it is a superset of the context's range. range_proper If true, use proper superset/subset on range matching operations. No effect if not using set operations. """ user = CriteriaDescriptor("user_regex", "lookup_user") user_regex: bool = False role = CriteriaDescriptor("role_regex", "lookup_role") role_regex: bool = False type_ = CriteriaDescriptor("type_regex", "lookup_type") type_regex: bool = False range_ = CriteriaDescriptor(lookup_function="lookup_range") range_overlap: bool = False range_subset: bool = False range_superset: bool = False range_proper: bool = False def _match_context_debug(self, log: Logger): """Emit log debugging info for context matching.""" log.debug("User: {0.user!r}, regex: {0.user_regex}".format(self)) log.debug("Role: {0.role!r}, regex: {0.role_regex}".format(self)) log.debug("Type: {0.type_!r}, regex: {0.type_regex}".format(self)) log.debug("Range: {0.range_!r}, subset: {0.range_subset}, overlap: {0.range_overlap}, " "superset: {0.range_superset}, proper: {0.range_proper}".format(self)) def _match_context(self, context: Context) -> bool: """ Match the context criteria. Parameter: obj An object with context attributes "user", "role", "type_" and "range_". """ if self.user and not match_regex( context.user, self.user, self.user_regex): return False if self.role and not match_regex( context.role, self.role, self.role_regex): return False if self.type_ and not match_regex( context.type_, self.type_, self.type_regex): return False if self.range_ and not match_range( context.range_, self.range_, self.range_subset, self.range_overlap, self.range_superset, self.range_proper): return False return True class MatchName: """Mixin for matching an object's name with alias dereferencing.""" name = CriteriaDescriptor("name_regex") name_regex: bool = False alias_deref: bool = False def _match_name_debug(self, log: Logger) -> None: """Log debugging messages for name matching.""" log.debug("Name: {0.name!r}, regex: {0.name_regex}, deref: {0.alias_deref}".format(self)) def _match_name(self, obj): """Match the object to the name criteria.""" if not self.name: # if there is no criteria, everything matches. return True if self.alias_deref: return match_regex(obj, self.name, self.name_regex) or \ match_in_set(obj.aliases(), self.name, self.name_regex) else: return match_regex(obj, self.name, self.name_regex) class MatchObjClass: """Mixin for matching an object's class.""" tclass = CriteriaSetDescriptor("tclass_regex", "lookup_class") tclass_regex: bool = False def _match_object_class_debug(self, log: Logger) -> None: """Emit log debugging info for permission matching.""" log.debug("Class: {0.tclass!r}, regex: {0.tclass_regex}".format(self)) def _match_object_class(self, obj): """ Match the object class criteria Parameter: obj An object with an object class attribute named "tclass" """ if not self.tclass: # if there is no criteria, everything matches. return True elif self.tclass_regex: return bool(self.tclass.search(str(obj.tclass))) else: return obj.tclass in self.tclass class MatchPermission: """Mixin for matching an object's permissions.""" perms = CriteriaPermissionSetDescriptor(name_regex="perms_regex") perms_equal: bool = False perms_regex: bool = False perms_subset: bool = False def _match_perms_debug(self, log: Logger): """Emit log debugging info for permission matching.""" log.debug("Perms: {0.perms!r}, regex: {0.perms_regex}, eq: {0.perms_equal}, " "subset: {0.perms_subset!r}".format(self)) def _match_perms(self, obj): """ Match the permission criteria Parameter: obj An object with a permission set class attribute named "perms" """ if not self.perms: # if there is no criteria, everything matches. return True if self.perms_subset: return obj.perms >= self.perms else: return match_regex_or_set(obj.perms, self.perms, self.perms_equal, self.perms_regex)