3 ^ @ sb d dl Z d dlZddlmZmZ ddlmZ ddlmZ ddl m Z mZmZ G dd deeZ dS ) N )CriteriaDescriptorCriteriaSetDescriptor) MatchName)PolicyQuery)match_regex_or_setmatch_levelmatch_rangec sj e Zd ZdZeddZdZdZdZeddZ dZ dZdZdZ eddZdZdZ fdd Zd d Z ZS ) UserQueryaf Query SELinux policy users. Parameter: policy The policy to query. Keyword Parameters/Class attributes: name The user name to match. name_regex If true, regular expression matching will be used on the user names. roles The attribute to match. roles_equal If true, only types with role sets that are equal to the criteria will match. Otherwise, any intersection will match. roles_regex If true, regular expression matching will be used on the role names instead of set logic. level The criteria to match the user's default level. level_dom If true, the criteria will match if it dominates the user's default level. level_domby If true, the criteria will match if it is dominated by the user's default level. level_incomp If true, the criteria will match if it is incomparable to the user's default level. range_ The criteria to match the user's range. range_subset If true, the criteria will match if it is a subset of the user's range. range_overlap If true, the criteria will match if it overlaps any of the user's range. range_superset If true, the criteria will match if it is a superset of the user's range. range_proper If true, use proper superset/subset operations. No effect if not using set operations. Zlookup_level)Zlookup_functionFZlookup_rangeroles_regexZlookup_rolec s$ t t| j|f| tjt| _d S )N)superr __init__loggingZ getLogger__name__log)selfpolicykwargs) __class__ !/usr/lib64/python3.6/userquery.pyr O s zUserQuery.__init__c c s | j jdj| | j| j | j jdj| | j jdj| | j jdj| x| jj D ]}| j|spq`| jrt |j| j| j | j rq`| jrt |j| j| j| j| j rq`| jrt|j| j| j| j| j| j rq`|V q`W dS )z*Generator which yields all matching users.z'Generating user results from {0.policy}z?Roles: {0.roles!r}, regex: {0.roles_regex}, eq: {0.roles_equal}zXLevel: {0.level!r}, dom: {0.level_dom}, domby: {0.level_domby}, incomp: {0.level_incomp}zRange: {0.range_!r}, subset: {0.range_subset}, overlap: {0.range_overlap}, superset: {0.range_superset}, proper: {0.range_proper}N)r infoformatZ_match_name_debugdebugr ZusersZ_match_namerolesr roles_equalr levelr Z mls_level level_domlevel_dombylevel_incomprange_r Z mls_rangerange_subset range_overlaprange_supersetrange_proper)r userr r r resultsS sB zUserQuery.results)r __module____qualname____doc__r r r r r r r" r! r# r$ r r r r r r&