3 ^^@spddlZddlmZmZddlmZddlmZddlm Z m Z m Z ddl m Z mZdd lmZdd lmZdd lmZmZdd lmZmZdd lmZedZedZedddddgZeddddgZGdddeZedddgZ edddgZ!ed ddgZ"d!d"Z#d#d$Z$d%d&Z%d'd(Z&d)d*Z'd+d,Z(d-d.Z)Gd/d0d0eZ*Gd1d2d2eZ+Gd3d4d4eZ,dS)5N) defaultdict namedtuple)intern)Enum)RuleNotConditional RuleUseErrorTERuleNoFilename)IoctlSet TERuletype)conditional_wrapper_factory)DiffResultDescriptor) DifferenceWrapper)type_wrapper_factorytype_or_attr_wrapper_factory)class_wrapper_factoryz<>TrueZmodified_avrulerule added_perms removed_perms matched_permsZmodified_teruleZ added_defaultZremoved_defaultc@seZdZdZdZdS)Siderr N)__name__ __module__ __qualname__leftrightrr/usr/lib64/python3.6/terules.pyr-srZrule_db_side_dataperms orig_ruleZ rule_db_sidesrrZType_dbcCs|tjkr|j}n|j}x|D]}t}t}y tt|j}tt|j}Wnt k rbYnX||krt ||<t |||<n|||krt |||<|j j }dd|j D} t| |} |||} x.|jjD]} | j } | |kr| || <| | kr t | | <x|jjD]}|j }||kr4|||<|| | krPt | | |<d}d}|| | |kr| | ||}|j}|j}|tjkr|s| }n|j | B}|j}t||}n&|s| }n|j | B}|j}t||}t||| | ||<qWqWq WdS)aP Using rule_list, build up rule_db which is a data structure which consists of nested dicts that store BOTH the left and the right policies. All of the keys are interned strings. The permissions are stored as a set. The basic structure is rule_db[cond_exp][block_bool][src][tgt][tclass] = sides where: cond_exp is a boolean expression block_bool is either true or false src is the source type tgt is the target type tclass is the target class sides is a named tuple with attributes "left" and "right" referring to the left or right policy. Each attribute in the sides named tuple refers to a named tuple with attributes "perms" and "orig_rule" which refer to a permission set and the original unexpanded rule. sides = ((left_perms, left_orig_rule),(right_perms, right_orig_rule)) There are a few advantages to this structure. First, it takes up way less memory. Second, it allows redundant rules to be easily eliminated. And, third, it makes it easy to create the added, removed, and modified rules. cSsh|]}|qSrr).0prrr csz+_avrule_expand_generator..N)rrrTERULES_UNCONDITIONALTERULES_UNCONDITIONAL_BLOCKrstr conditionalconditional_blockrdicttclassnamer!rule_db_side_data_recordsourceexpandtargetr"rule_db_sides_record) rule_listrule_dbtype_dbZsidetypesunexpanded_rulecond_exp block_boolr,r! side_datablocksrcZsrc_strtgtZtgt_str left_side right_sideZsidesr$Zorigrrr _avrule_expand_generator9sd             r@cCsx|tt}xd|jD]V\}}|tkr,qx@|jD]2\}}x&|jD]\}}||krbqNx|jD]\}} |||krqnx| jD]\} } | |||krq|||| } | j} | j}| jo| r| j| jj@}|r| j|}|rt|| j} nd} t| || | <| jr|r|j| jj@}|r|j|}|rNt||j}nd}t| || | <qWqnWqNWq8WqWdS)N) r&r'itemsrrr!r.r"r2)r4Z uncond_blockr8 cond_blocksr9r;r<src_datar=tgt_datar,r:Zuncond_side_datar>r?cr$rrr _av_remove_redundant_rulessB      rFc Cs|g}g}g}xb|jD]T\}}xH|jD]:\}} x.| jD] \} } x| jD]\} } x| jD]\}}|jr|jr|jj|jj@}|jj|}|jj|}|s|r|jj}|j|j| |j| |jj}|jt||||qn|jr(|jj}|j|j| |j| |jj}|j|qn|jrn|jj}|j|j| |j| |jj}|j|qnWqZWqDWq.WqW|||fS)N)rArrr!r"Zderive_expandedappendmodified_avrule_record)ruletyper4r5addedremovedmodifiedr8rBr9r;r<rCr=rDr,r:Z common_permsZ left_permsZ right_permsZ original_rulerrrr _av_generate_diffssB         rMcstjfdd}|S)z This is a template for the access vector diff functions. Parameters: ruletype The rule type, e.g. "allow". cs|jjdj||j s$|j r,|jttt}t}t|t<t|tt <t jdt |j||t j t jdt |j||t jt jdt|t jdt||\}}}|j j|jj|jt|dj|t|dj|t|dj|d S) z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}zExpanding left policyzExpanding right policyzRemoving redundant rulesz0Generating added, removed, and modified av rulesz added_{0}sz removed_{0}sz modified_{0}sN)loginfoformat_left_te_rules_right_te_rules_create_te_rule_liststype_db_recordr+r&r'loggingr@rrrrFrMclearsetattr)selfr5r4rJrKrL)rIrr diffs.        zav_diff_template..diff)r lookup)rIrYr)rIr av_diff_templates  #r[c Cst}x\|D]T}xN|jD]B}||}y||j|jO_Wqtk rZ|||<YqXqWq W|rtjtjdj|t ||j S)z` Generator that yields wrapped, expanded, av(x) rules with unioned permission sets. z/Expanded {0.ruletype} rules for {0.policy}: {1}) r+r0r!KeyErrorrUZ getLoggerrdebugrPlenkeys)r3Z WrapperClassrAr7Z expanded_ruleZexpanded_wrapped_rulerrr _avxrule_expand_generator s  r`cstjfdd}|S)z This is a template for the extended permission access vector diff functions. Parameters: ruletype The rule type, e.g. "allowxperm". c s|jjdj||j s$|j r,|j|jt|jtt|jtdd\}}}g}x^|D]V\}}|j|j |j dd\}}} |s|rd|j t |j t |t |t dd| DqdWt|djtdd|Dt|djtd d|Dt|d j|d S) z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}F)Zunwrapcss|]}|dVqdS)rNr)r#r$rrr Qsz2avx_diff_template..diff..z added_{0}scss|] }|jVqdS)N)origin)r#arrr raSsz removed_{0}scss|] }|jVqdS)N)rb)r#rrrr raTsz modified_{0}sN)rNrOrPrQrRrS _set_diffr`AVRuleXpermWrapperr!rGrHrbr rWset) rXrJrKmatchedrL left_rule right_rulerrr)rIrr rY3s,    zavx_diff_template..diff)r rZ)rIrYr)rIr avx_diff_template)s  $rkcstjfdd}|S)z This is a template for the type_* diff functions. Parameters: ruletype The rule type, e.g. "type_transition". cs|jjdj||j s$|j r,|j|j|j|jt|j|jt\}}}g}x:|D]2\}}t |j t |j krd|j t ||j |j qdWt |dj|t |dj|t |dj|dS)z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}z added_{0}sz removed_{0}sz modified_{0}sN)rNrOrPrQrRrSreZ_expand_generator TERuleWrapperrdefaultrGmodified_terule_recordrW)rXrJrKrhrLrirj)rIrr rYds" zte_diff_template..diff)r rZ)rIrYr)rIr te_diff_templateZs  roc@seZdZdZedZedZedZedZ edZ edZ edZ edZ edZedZedZedZedZed Zed Zed Zed Zed Zed Zed Zed Zed Zed Zed ZedZedZ edZ!edZ"edZ#edZ$edZ%edZ&e'dZ(edZ)edZ*edZ+e'dZ,edZ-edZ.edZ/e'dZ0edZ1edZ2edZ3e4e5Z6e4e5Z7ddZ8ddZ9dS)TERulesDifferencezV Determine the difference in type enforcement rules between two policies. Zallow diff_allowsZ auditallowdiff_auditallowsZ neverallowdiff_neverallowsZ dontauditdiff_dontauditsZ allowxpermdiff_allowxpermsZauditallowxpermdiff_auditallowxpermsZneverallowxpermdiff_neverallowxpermsZdontauditxpermdiff_dontauditxpermsZtype_transitiondiff_type_transitionsZ type_changediff_type_changesZ type_memberdiff_type_memberscCs|jjdj|x$|jjD]}|j|jj|qWx.|jjD] \}}|jjdjt ||qDW|jjdj|x$|j jD]}|j |jj|qWx.|j jD] \}}|jjdjt ||qW|jjddS)z$Create rule lists for both policies.z+Building TE rule lists from {0.left_policy}zLoaded {0} {1} rules.z,Building TE rule lists from {0.right_policy}z!Completed building TE rule lists.N) rNr]rPZ left_policyZterulesrQrIrGrAr^Z right_policyrR)rXrrIZrulesrrr rSsz'TERulesDifference._create_te_rule_listscCs|jjdd|_d|_d|_d|_d|_d|_d|_d|_ d|_ d|_ d|_ d|_ d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_ d|_!d|_"|j#j$|j%j$dS)z%Reset diff results on policy changes.zResetting TE rule differencesN)&rNr] added_allowsremoved_allowsmodified_allowsadded_auditallowsremoved_auditallowsmodified_auditallowsadded_neverallowsremoved_neverallowsmodified_neverallowsadded_dontauditsremoved_dontauditsmodified_dontauditsadded_allowxpermsremoved_allowxpermsmodified_allowxpermsadded_auditallowxpermsremoved_auditallowxpermsmodified_auditallowxpermsadded_neverallowxpermsremoved_neverallowxpermsmodified_neverallowxpermsadded_dontauditxpermsremoved_dontauditxpermsmodified_dontauditxpermsadded_type_transitionsremoved_type_transitionsmodified_type_transitionsadded_type_changesremoved_type_changesmodified_type_changesadded_type_membersremoved_type_membersmodified_type_membersrQrVrR)rXrrr _reset_diffsH  zTERulesDifference._reset_diffN):rrr__doc__r[rqrr|r}r~rrrrrrsrrrrtrrrrkrurrrrvrrrrwrrrrxrrrroryrrrrzrrrr{rrrrlistrQrRrSrrrrr rpsbrpc@s4eZdZdZdZddZd d Zd d Zd dZdS)rfzEWrap extended permission access vector rules to allow set operations.r/r1r, xperm_typer!cCsH||_t|j|_t|j|_t|j|_|j|_|j|_t||_ dS)N) rbrr/r1rr,rr!hashkey)rXrrrr __init__ s   zAVRuleXpermWrapper.__init__cCs|jS)N)r)rXrrr __hash__szAVRuleXpermWrapper.__hash__cCs |j|jkS)N)r)rXotherrrr __lt__szAVRuleXpermWrapper.__lt__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r/r1r,r)rXrrrr __eq__s   zAVRuleXpermWrapper.__eq__N)r/r1r,rr!) rrrr __slots__rrrrrrrr rfs  rfc@s4eZdZdZdZdd Zd d Zd d ZddZdS)rlz*Wrap type_* rules to allow set operations.r/r1r,r)r*filenamecCs||_t|j|_t|j|_t|j|_t||_yt|j |_ |j |_ Wn t k rld|_ d|_ YnXy |j |_ Wnt tfk rd|_ YnXdS)N)rbrr/r1rr,rrr r)r*rrrr )rXrrrr r)s        zTERuleWrapper.__init__cCs|jS)N)r)rXrrr r<szTERuleWrapper.__hash__cCs |j|jkS)N)r)rXrrrr r?szTERuleWrapper.__lt__cCsH|j|jkoF|j|jkoF|j|jkoF|j|jkoF|j|jkoF|j|jkS)N)r/r1r,r)r*r)rXrrrr rBs      zTERuleWrapper.__eq__N)r/r1r,r)r*r) rrrrrrrrrrrrr rl#s rl)-rU collectionsrrsysrenumrZ exceptionrrr Z policyrepr r r)r Z descriptorsr differencerrr6rrZobjclassrr&r'rHrnrr.r2rTr@rFrMr[r`rkrorprfrlrrrr s@     Z&$01(