/usr/lib64/python3.9/site-packages/setools/__pycache__
NameSizeModeActions
boolquery.cpython-39.opt-1.pyc21010644editdlrm
boolquery.cpython-39.pyc21010644editdlrm
boundsquery.cpython-39.opt-1.pyc18830644editdlrm
boundsquery.cpython-39.pyc18830644editdlrm
categoryquery.cpython-39.opt-1.pyc16820644editdlrm
categoryquery.cpython-39.pyc16820644editdlrm
commonquery.cpython-39.opt-1.pyc19120644editdlrm
commonquery.cpython-39.pyc19120644editdlrm
constraintquery.cpython-39.opt-1.pyc47580644editdlrm
constraintquery.cpython-39.pyc47580644editdlrm
defaultquery.cpython-39.opt-1.pyc23630644editdlrm
defaultquery.cpython-39.pyc23630644editdlrm
descriptors.cpython-39.opt-1.pyc101200644editdlrm
descriptors.cpython-39.pyc103130644editdlrm
devicetreeconquery.cpython-39.opt-1.pyc25900644editdlrm
devicetreeconquery.cpython-39.pyc25900644editdlrm
dta.cpython-39.opt-1.pyc156130644editdlrm
dta.cpython-39.pyc156130644editdlrm
exception.cpython-39.opt-1.pyc93230644editdlrm
exception.cpython-39.pyc93230644editdlrm
fsusequery.cpython-39.opt-1.pyc30420644editdlrm
fsusequery.cpython-39.pyc30420644editdlrm
genfsconquery.cpython-39.opt-1.pyc32760644editdlrm
genfsconquery.cpython-39.pyc32760644editdlrm
ibendportconquery.cpython-39.opt-1.pyc33510644editdlrm
ibendportconquery.cpython-39.pyc33510644editdlrm
ibpkeyconquery.cpython-39.opt-1.pyc47630644editdlrm
ibpkeyconquery.cpython-39.pyc47630644editdlrm
infoflow.cpython-39.opt-1.pyc130470644editdlrm
infoflow.cpython-39.pyc130470644editdlrm
initsidquery.cpython-39.opt-1.pyc26180644editdlrm
initsidquery.cpython-39.pyc26180644editdlrm
iomemconquery.cpython-39.opt-1.pyc40960644editdlrm
iomemconquery.cpython-39.pyc40960644editdlrm
ioportconquery.cpython-39.opt-1.pyc41000644editdlrm
ioportconquery.cpython-39.pyc41000644editdlrm
mixins.cpython-39.opt-1.pyc69470644editdlrm
mixins.cpython-39.pyc69470644editdlrm
mlsrulequery.cpython-39.opt-1.pyc32900644editdlrm
mlsrulequery.cpython-39.pyc32900644editdlrm
netifconquery.cpython-39.opt-1.pyc26960644editdlrm
netifconquery.cpython-39.pyc26960644editdlrm
nodeconquery.cpython-39.opt-1.pyc40320644editdlrm
nodeconquery.cpython-39.pyc40320644editdlrm
objclassquery.cpython-39.opt-1.pyc31880644editdlrm
objclassquery.cpython-39.pyc31880644editdlrm
pcideviceconquery.cpython-39.opt-1.pyc29900644editdlrm
pcideviceconquery.cpython-39.pyc29900644editdlrm
permmap.cpython-39.opt-1.pyc128200644editdlrm
permmap.cpython-39.pyc130540644editdlrm
pirqconquery.cpython-39.opt-1.pyc29120644editdlrm
pirqconquery.cpython-39.pyc29120644editdlrm
polcapquery.cpython-39.opt-1.pyc14820644editdlrm
polcapquery.cpython-39.pyc14820644editdlrm
portconquery.cpython-39.opt-1.pyc47530644editdlrm
portconquery.cpython-39.pyc47530644editdlrm
query.cpython-39.opt-1.pyc12720644editdlrm
query.cpython-39.pyc12720644editdlrm
rbacrulequery.cpython-39.opt-1.pyc43520644editdlrm
rbacrulequery.cpython-39.pyc43520644editdlrm
rolequery.cpython-39.opt-1.pyc21900644editdlrm
rolequery.cpython-39.pyc21900644editdlrm
sensitivityquery.cpython-39.opt-1.pyc24020644editdlrm
sensitivityquery.cpython-39.pyc24020644editdlrm
terulequery.cpython-39.opt-1.pyc67030644editdlrm
terulequery.cpython-39.pyc67030644editdlrm
typeattrquery.cpython-39.opt-1.pyc23520644editdlrm
typeattrquery.cpython-39.pyc23520644editdlrm
typequery.cpython-39.opt-1.pyc31460644editdlrm
typequery.cpython-39.pyc31460644editdlrm
userquery.cpython-39.opt-1.pyc40200644editdlrm
userquery.cpython-39.pyc40200644editdlrm
util.cpython-39.opt-1.pyc77230644editdlrm
util.cpython-39.pyc77230644editdlrm
__init__.cpython-39.opt-1.pyc37560644editdlrm
__init__.cpython-39.pyc37560644editdlrm
Edit: /usr/lib64/python3.9/site-packages/setools/__pycache__/infoflow.cpython-39.pyc (13047B)
a qéqe)>ã@sâddlZddlZddlmZddlmZmZmZmZm Z m Z z ddl Z ddl mZmZmZWn"ey~e e¡ d¡Yn0ddlmZmZddlmZdd lmZmZmZmZd gZed Z Gd d „d ƒZ!Gd d „d ƒZ"dS)éN)Úsuppress)ÚcastÚIterableÚListÚMappingÚOptionalÚUnion)Ú NetworkXErrorÚNetworkXNoPathÚ NodeNotFoundzNetworkX failed to import.é)ÚEdgeAttrIntMaxÚ EdgeAttrList)Ú PermissionMap)ÚAVRuleÚ SELinuxPolicyÚ TERuletypeÚTypeÚInfoFlowAnalysisÚ InfoFlowStepc @s´eZdZUdZeeed<eed<eed<d.e eee e e ee fe ee efddœdd „Zeed œd d „ƒZejedd œdd „ƒZeed œdd„ƒZejeddœdd„ƒZeeed œdd„ƒZeje e e ee fddœdd„ƒZeee edœdd„Zd/e ee fe ee fee edœdd„Ze ee fe ee fe edœdd„Zd0e ee fee d!d"œd#d$„Ze d œd%d&„Zeeed'œd(d)„Zdd œd*d+„Zdd œd,d-„ZdS)1rzInformation flow analysis.Ú_excludeÚ _min_weightÚ _perm_mapr N)ÚpolicyÚperm_mapÚ min_weightÚexcludeÚbooleansÚreturncCs‚t t¡|_||_||_||_||_||_d|_ d|_ zt   ¡|_ |j  ¡|_Wn,ty||j d¡|j d¡‚Yn0dS)a¨ Parameters: policy The policy to analyze. perm_map The permission map or path to the permission map file. minweight The minimum permission weight to include in the analysis. (default is 1) exclude The types excluded from the information flow analysis. (default is none) booleans If None, all rules will be added to the analysis (default). otherwise it should be set to a dict with keys corresponding to boolean names and values of True/False. Any unspecified booleans will use the policy's default values. TzKNetworkX is not available. This is requried for Information Flow Analysis.z2This is typically in the python3-networkx package.N)ÚloggingÚ getLoggerÚ__name__ÚlogrrrrrÚ rebuildgraphÚrebuildsubgraphÚnxZDiGraphÚGÚcopyÚsubGÚ NameErrorZcritical)Úselfrrrrr©r+ú6/usr/lib64/python3.9/site-packages/setools/infoflow.pyÚ__init__!s     zInfoFlowAnalysis.__init__)rcCs|jS©N)r©r*r+r+r,rEszInfoFlowAnalysis.min_weight)ÚweightrcCs.d|krdksntdƒ‚||_d|_dS)Nr é z4Min information flow weight must be an integer 1-10.T)Ú ValueErrorrr$)r*r0r+r+r,rIs ÿcCs|jSr.)rr/r+r+r,rRszInfoFlowAnalysis.perm_map)rrcCs||_d|_d|_dS)NT)rr#r$)r*rr+r+r,rVscCs|jSr.)rr/r+r+r,r\szInfoFlowAnalysis.exclude)Útypesrcs*|r‡fdd„|Dƒˆ_ngˆ_dˆ_dS)Ncsg|]}ˆj |¡‘qSr+)rÚ lookup_type)Ú.0Útr/r+r,Ú cóz,InfoFlowAnalysis.exclude..T)rr$)r*r3r+r/r,r`s)ÚsourceÚtargetrccs‚|j |¡}|j |¡}|jr&| ¡|j d ||¡¡ttt ƒ�*|  t j |j ||d�¡VWdƒn1st0YdS)a Generator which yields one shortest path between the source and target types (there may be more). Parameters: source The source type. target The target type. Yield: generator(steps) steps Yield: tuple(source, target, rules) source The source type for this step of the information flow. target The target type for this step of the information flow. rules The list of rules creating this information flow step. z@Generating one shortest information flow path from {0} to {1}...)r9r:N)rr4r$Ú_build_subgraphr"ÚinfoÚformatrr r Ú!_InfoFlowAnalysis__generate_stepsr%Ú shortest_pathr()r*r9r:Úsr6r+r+r,r?is   ÿ zInfoFlowAnalysis.shortest_pathé)r9r:Úmaxlenrccsž|dkrtdƒ‚|j |¡}|j |¡}|jr6| ¡|j d |||¡¡tt t ƒ�4t   |j |||¡D]}| |¡VqjWdƒn1s�0YdS)a¨ Generator which yields all paths between the source and target up to the specified maximum path length. This algorithm tends to get very expensive above 3-5 steps, depending on the policy complexity. Parameters: source The source type. target The target type. maxlen Maximum length of paths. Yield: generator(steps) steps Yield: tuple(source, target, rules) source The source type for this step of the information flow. target The target type for this step of the information flow. rules The list of rules creating this information flow step. r z%Maximum path length must be positive.zHGenerating all information flow paths from {0} to {1}, max length {2}...N)r2rr4r$r;r"r<r=rr r r%Zall_simple_pathsr(r>)r*r9r:rBr@r6Úpathr+r+r,Ú all_paths‹s   ÿ zInfoFlowAnalysis.all_pathsccsŠ|j |¡}|j |¡}|jr&| ¡|j d ||¡¡ttt ƒ�2t   |j ||¡D]}|  |¡VqVWdƒn1s|0YdS)aî Generator which yields all shortest paths between the source and target types. Parameters: source The source type. target The target type. Yield: generator(steps) steps Yield: tuple(source, target, rules) source The source type for this step of the information flow. target The target type for this step of the information flow. rules The list of rules creating this information flow step. zAGenerating all shortest information flow paths from {0} to {1}...N)rr4r$r;r"r<r=rr r r%Úall_shortest_pathsr(r>)r*r9r:r@r6rCr+r+r,rE´s   ÿ z#InfoFlowAnalysis.all_shortest_pathsTr)Útype_Úoutrccsž|j |¡}|jr| ¡|j d |r,dnd|¡¡ttƒ�L|rR|j   |¡}n |j   |¡}|D]\}}t |j ||ƒVqbWdƒn1s�0YdS)a( Generator which yields all information flows in/out of a specified source type. Parameters: source The starting type. Keyword Parameters: out If true, information flows out of the type will be returned. If false, information flows in to the type will be returned. Default is true. Yield: generator(steps) steps A generator that returns the tuple of source, target, and rules for each information flow. z(Generating all information flows {0} {1}zout ofZintoN) rr4r$r;r"r<r=rr r(Z out_edgesZin_edgesr)r*rFrGr@Zflowsr9r:r+r+r,Ú infoflows×s   ÿ   zInfoFlowAnalysis.infoflowscCs.|jr| ¡dt |j¡›dt |j¡›�S)zQ Get the information flow graph statistics. Return: str z Graph nodes: z Graph edges: )r#Ú _build_graphr%Únumber_of_nodesr&Únumber_of_edgesr/r+r+r,Ú get_statsþs  ÿzInfoFlowAnalysis.get_stats)rCrccs4tdt|ƒƒD] }t|j||d||ƒVqdS)aâ Generator which returns the source, target, and associated rules for each information flow step. Parameter: path A list of graph node names representing an information flow path. Yield: tuple(source, target, rules) source The source type for this step of the information flow. target The target type for this step of the information flow. rules The list of rules creating this information flow step. r N)ÚrangeÚlenrr()r*rCr@r+r+r,Z__generate_stepssz!InfoFlowAnalysis.__generate_stepscCs*|j ¡d |j¡|j_|j |j¡|j d |j¡¡|j  ¡D]¢}|j t j krXqF|j  tt|ƒ¡\}}t |j ¡|j ¡¡D]`\}}||kr†|r¾t|j||dd�}|j |¡||_|r†t|j||dd�}|j |¡||_q†qFd|_d|_|j d¡|j d t |j¡t |j¡¡¡dS)NzInformation flow graph for {0}.z+Building information flow graph from {0}...T)ÚcreateFz*Completed building information flow graph.z$Graph stats: nodes: {0}, edges: {1}.)r&Úclearr=rÚnamerZ map_policyr"r<ZterulesZruletyperZallowZ rule_weightrrÚ itertoolsÚproductr9Úexpandr:rÚrulesÚappendr0r#r$Údebugr%rJrK)r*ÚruleZrweightZwweightr@r6Úedger+r+r,rI.s2          þzInfoFlowAnalysis._build_graphc s¾ˆjrˆ ¡ˆj d¡ˆj d ˆj¡¡ˆj d ˆj¡¡ˆj d ˆjdu¡¡‡fdd„ˆj   ¡Dƒ}ˆj   |¡  ¡ˆ_ ˆjdkrÖg}ˆj  ¡D],\}}tˆj ||ƒ}|jˆjkrœ| |¡qœˆj  |¡ˆjdu�r„g}ˆj  ¡D]†\}}tˆj ||ƒ}g}|jD]$}|jfiˆj¤Ž�s| |¡�qg}|D]&}||v�r>|j |¡| |¡�q>|jsð| |¡qðˆj  |¡dˆ_ˆj d ¡ˆj d  t ˆj ¡t ˆj ¡¡¡dS) Nz%Building information flow subgraph...zExcluding {0!r}zMin weight {0}z(Exclude disabled conditional policy: {0}csg|]}|ˆjvr|‘qSr+)r)r5Únr/r+r,r7\r8z4InfoFlowAnalysis._build_subgraph..r Fz-Completed building information flow subgraph.z'Subgraph stats: nodes: {0}, edges: {1}.)r#rIr"r<rWr=rrrr&ÚnodesZsubgraphr'r(Zedgesrr0rVZremove_edges_fromrUZenabledÚremover$r%rJrK) r*r[Z delete_listr@r6rYZ rule_listrXZ deleted_rulesr+r/r,r;QsN  ÿ              þz InfoFlowAnalysis._build_subgraph)r NN)rA)T)r!Ú __module__Ú __qualname__Ú__doc__rrÚ__annotations__ÚintrrrrrÚstrrÚboolr-ÚpropertyrÚsetterrrÚ InfoFlowPathr?rDrErHrLr>rIr;r+r+r+r,rsF  þþ $""ÿ )ÿ # ' #c@sFeZdZdZedƒZedƒZd eee ddœdd„Z d d „Z d d „Z dS)raR A graph edge. Also used for returning information flow steps. Parameters: graph The NetworkX graph. source The source type of the edge. target The target type of the edge. Keyword Parameters: create (T/F) create the edge if it does not exist. The default is False. rUZcapacityFN)r9r:rOrcCsP||_||_||_|j ||¡sL|rD|jj||dd�d|_d|_ntdƒ‚dS)Nr )r0z$InfoFlowStep does not exist in graph)r&r9r:Zhas_edgeZadd_edgerUr0r2)r*Zgraphr9r:rOr+r+r,r-¡szInfoFlowStep.__init__cs4t|tƒr&‡fdd„t| d¡ŽDƒSˆ |¡SdS)Ncsg|]}ˆ |¡‘qSr+)Ú_index_to_item)r5Úir/r+r,r7²r8z,InfoFlowStep.__getitem__..rA)Ú isinstanceÚslicerMÚindicesrg)r*Úkeyr+r/r,Ú __getitem__®s zInfoFlowStep.__getitem__cCs.|dkr|jS|dkr|jStd |¡ƒ‚dS)z'Return source or target based on index.rr z,Invalid index (edges only have 2 items): {0}N)r9r:Ú IndexErrorr=)r*Úindexr+r+r,rg¶s zInfoFlowStep._index_to_item)F) r!r]r^r_rrUr r0rrcr-rmrgr+r+r+r,r‰s   )#rRrÚ contextlibrÚtypingrrrrrrZnetworkxr%Znetworkx.exceptionr r r Ú ImportErrorr r!rWZ descriptorsr rZpermmaprZ policyreprrrrÚ__all__rfrrr+r+r+r,Ús"    r