
­­­­­­­­­­­­­­­­­­
<!DOCTYPE html>
<html>
3
^                 @   sb   d dl Z d dlZddlmZmZ ddlmZ ddlmZ ddl	m
Z
mZmZ G dd deeZdS )	    N   )CriteriaDescriptorCriteriaSetDescriptor)	MatchName)PolicyQuery)match_regex_or_setmatch_levelmatch_rangec                   sj   e Zd ZdZeddZdZdZdZeddZ	dZ
dZdZdZeddZdZdZ fdd	Zd
d Z  ZS )	UserQueryaf  
    Query SELinux policy users.

    Parameter:
    policy            The policy to query.

    Keyword Parameters/Class attributes:
    name            The user name to match.
    name_regex      If true, regular expression matching
                    will be used on the user names.
    roles           The attribute to match.
    roles_equal     If true, only types with role sets
                    that are equal to the criteria will
                    match.  Otherwise, any intersection
                    will match.
    roles_regex     If true, regular expression matching
                    will be used on the role names instead
                    of set logic.
    level           The criteria to match the user's default level.
    level_dom       If true, the criteria will match if it dominates
                    the user's default level.
    level_domby     If true, the criteria will match if it is dominated
                    by the user's default level.
    level_incomp    If true, the criteria will match if it is incomparable
                    to the user's default level.
    range_          The criteria to match the user's range.
    range_subset    If true, the criteria will match if it is a subset
                    of the user's range.
    range_overlap   If true, the criteria will match if it overlaps
                    any of the user's range.
    range_superset  If true, the criteria will match if it is a superset
                    of the user's range.
    range_proper    If true, use proper superset/subset operations.
                    No effect if not using set operations.
    Zlookup_level)Zlookup_functionFZlookup_rangeroles_regexZlookup_rolec                s$   t t| j|f| tjt| _d S )N)superr
   __init__loggingZ	getLogger__name__log)selfpolicykwargs)	__class__ !/usr/lib64/python3.6/userquery.pyr   O   s    zUserQuery.__init__c             c   s   | j jdj|  | j| j  | j jdj|  | j jdj|  | j jdj|  x| jj D ]}| j|spq`| jrt	|j| j| j
| j rq`| jrt|j| j| j| j| j rq`| jrt|j| j| j| j| j| j rq`|V  q`W dS )z*Generator which yields all matching users.z'Generating user results from {0.policy}z?Roles: {0.roles!r}, regex: {0.roles_regex}, eq: {0.roles_equal}zXLevel: {0.level!r}, dom: {0.level_dom}, domby: {0.level_domby}, incomp: {0.level_incomp}zRange: {0.range_!r}, subset: {0.range_subset}, overlap: {0.range_overlap}, superset: {0.range_superset}, proper: {0.range_proper}N)r   infoformatZ_match_name_debugdebugr   ZusersZ_match_namerolesr   roles_equalr   levelr   Z	mls_level	level_domlevel_dombylevel_incomprange_r	   Z	mls_rangerange_subsetrange_overlaprange_supersetrange_proper)r   userr   r   r   resultsS   sB    






zUserQuery.results)r   
__module____qualname____doc__r   r   r   r   r   r    r"   r!   r#   r$   r   r   r   r   r   r&   __classcell__r   r   )r   r   r
      s   $


r
   )r   reZdescriptorsr   r   Zmixinsr   Zqueryr   utilr   r   r	   r
   r   r   r   r   <module>   s   