3 ^@sbddlZddlZddlmZmZddlmZddlmZddl m Z m Z m Z GdddeeZ dS) N)CriteriaDescriptorCriteriaSetDescriptor) MatchName) PolicyQuery)match_regex_or_set match_level match_rangecsjeZdZdZeddZdZdZdZeddZ dZ dZ dZ dZ eddZdZdZfdd Zd d ZZS) UserQueryaf Query SELinux policy users. Parameter: policy The policy to query. Keyword Parameters/Class attributes: name The user name to match. name_regex If true, regular expression matching will be used on the user names. roles The attribute to match. roles_equal If true, only types with role sets that are equal to the criteria will match. Otherwise, any intersection will match. roles_regex If true, regular expression matching will be used on the role names instead of set logic. level The criteria to match the user's default level. level_dom If true, the criteria will match if it dominates the user's default level. level_domby If true, the criteria will match if it is dominated by the user's default level. level_incomp If true, the criteria will match if it is incomparable to the user's default level. range_ The criteria to match the user's range. range_subset If true, the criteria will match if it is a subset of the user's range. range_overlap If true, the criteria will match if it overlaps any of the user's range. range_superset If true, the criteria will match if it is a superset of the user's range. range_proper If true, use proper superset/subset operations. No effect if not using set operations. Z lookup_level)Zlookup_functionFZ lookup_range roles_regexZ lookup_rolec s$tt|j|f|tjt|_dS)N)superr __init__loggingZ getLogger__name__log)selfpolicykwargs) __class__!/usr/lib64/python3.6/userquery.pyr OszUserQuery.__init__ccs|jjdj||j|j|jjdj||jjdj||jjdj|x|jjD]}|j|spq`|jrt |j|j|j |j  rq`|j rt |j|j |j|j|j rq`|jrt|j|j|j|j|j|j rq`|Vq`WdS)z*Generator which yields all matching users.z'Generating user results from {0.policy}z?Roles: {0.roles!r}, regex: {0.roles_regex}, eq: {0.roles_equal}zXLevel: {0.level!r}, dom: {0.level_dom}, domby: {0.level_domby}, incomp: {0.level_incomp}zRange: {0.range_!r}, subset: {0.range_subset}, overlap: {0.range_overlap}, superset: {0.range_superset}, proper: {0.range_proper}N)rinfoformatZ_match_name_debugdebugrZusersZ _match_namerolesr roles_equalr levelrZ mls_level level_dom level_domby level_incomprange_r Z mls_range range_subset range_overlaprange_superset range_proper)ruserrrrresultsSsB        zUserQuery.results)r __module__ __qualname____doc__rrrrrr r"r!r#r$rrrr r r& __classcell__rr)rrr s$    r )rreZ descriptorsrrZmixinsrZqueryrutilrrr r rrrrs