Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 1 | # |
| 2 | # booleansPage.py - GUI for Booleans page in system-config-securitylevel |
| 3 | # |
| 4 | # Dan Walsh <dwalsh@redhat.com> |
| 5 | # |
| 6 | # Copyright 2006, 2007 Red Hat, Inc. |
| 7 | # |
| 8 | # This program is free software; you can redistribute it and/or modify |
| 9 | # it under the terms of the GNU General Public License as published by |
| 10 | # the Free Software Foundation; either version 2 of the License, or |
| 11 | # (at your option) any later version. |
| 12 | # |
| 13 | # This program is distributed in the hope that it will be useful, |
| 14 | # but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 15 | # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
| 16 | # GNU General Public License for more details. |
| 17 | # |
| 18 | # You should have received a copy of the GNU General Public License |
| 19 | # Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. |
| 20 | # |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 21 | import sys |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 22 | from gi.repository import Gdk, GObject, Gtk |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 23 | import seobject |
| 24 | import semanagePage |
| 25 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 26 | INSTALLPATH = '/usr/share/system-config-selinux' |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 27 | sys.path.append(INSTALLPATH) |
| 28 | |
Jason Zaman | 05d1cea | 2016-08-05 02:34:04 +0800 | [diff] [blame] | 29 | try: |
| 30 | from subprocess import getstatusoutput |
| 31 | except ImportError: |
| 32 | from commands import getstatusoutput |
| 33 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 34 | ENFORCING = 0 |
| 35 | PERMISSIVE = 1 |
| 36 | DISABLED = 2 |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 37 | |
| 38 | ## |
| 39 | ## I18N |
| 40 | ## |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 41 | PROGNAME = "policycoreutils" |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 42 | try: |
Jason Zaman | af59544 | 2016-08-05 02:34:02 +0800 | [diff] [blame] | 43 | import gettext |
| 44 | kwargs = {} |
| 45 | if sys.version_info < (3,): |
| 46 | kwargs['unicode'] = True |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 47 | gettext.install(PROGNAME, |
| 48 | localedir="/usr/share/locale", |
Jason Zaman | af59544 | 2016-08-05 02:34:02 +0800 | [diff] [blame] | 49 | codeset='utf-8', |
| 50 | **kwargs) |
| 51 | except: |
| 52 | try: |
| 53 | import builtins |
| 54 | builtins.__dict__['_'] = str |
| 55 | except ImportError: |
| 56 | import __builtin__ |
| 57 | __builtin__.__dict__['_'] = unicode |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 58 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 59 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 60 | class Modifier: |
| 61 | |
| 62 | def __init__(self, name, on, save): |
| 63 | self.on = on |
| 64 | self.name = name |
| 65 | self.save = save |
| 66 | |
| 67 | def set(self, value): |
| 68 | self.on = value |
| 69 | self.save = True |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 70 | |
| 71 | def isOn(self): |
| 72 | return self.on |
| 73 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 74 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 75 | class Boolean(Modifier): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 76 | |
| 77 | def __init__(self, name, val, save=False): |
| 78 | Modifier.__init__(self, name, val, save) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 79 | |
| 80 | ACTIVE = 0 |
| 81 | MODULE = 1 |
| 82 | DESC = 2 |
| 83 | BOOLEAN = 3 |
| 84 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 85 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 86 | class booleansPage: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 87 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 88 | def __init__(self, xml, doDebug=None): |
| 89 | self.xml = xml |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 90 | self.window = self.xml.get_object("mainWindow").get_root_window() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 91 | self.local = False |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 92 | self.types = [] |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 93 | self.selinuxsupport = True |
| 94 | self.typechanged = False |
| 95 | self.doDebug = doDebug |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 96 | self.busy_cursor = Gdk.Cursor.new(Gdk.CursorType.WATCH) |
| 97 | self.ready_cursor = Gdk.Cursor.new(Gdk.CursorType.LEFT_PTR) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 98 | |
| 99 | # Bring in widgets from glade file. |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 100 | self.booleansFilter = xml.get_object("booleansFilter") |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 101 | self.booleansFilter.connect("focus_out_event", self.filter_changed) |
| 102 | self.booleansFilter.connect("activate", self.filter_changed) |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 103 | self.booleansFilter.connect("changed", self.filter_changed) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 104 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 105 | self.booleansView = xml.get_object("booleansView") |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 106 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 107 | self.revertButton = xml.get_object("booleanRevertButton") |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 108 | self.revertButton.set_sensitive(self.local) |
| 109 | self.revertButton.connect("clicked", self.on_revert_clicked) |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 110 | listStore = Gtk.ListStore(GObject.TYPE_STRING) |
| 111 | cell = Gtk.CellRendererText() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 112 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 113 | self.store = Gtk.ListStore(GObject.TYPE_BOOLEAN, GObject.TYPE_STRING, GObject.TYPE_STRING, GObject.TYPE_STRING) |
| 114 | self.store.set_sort_column_id(1, Gtk.SortType.ASCENDING) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 115 | self.booleansView.set_model(self.store) |
| 116 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 117 | checkbox = Gtk.CellRendererToggle() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 118 | checkbox.connect("toggled", self.boolean_toggled) |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 119 | col = Gtk.TreeViewColumn('Active', checkbox, active=ACTIVE) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 120 | col.set_clickable(True) |
| 121 | col.set_sort_column_id(ACTIVE) |
| 122 | self.booleansView.append_column(col) |
| 123 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 124 | col = Gtk.TreeViewColumn("Module", Gtk.CellRendererText(), text=MODULE) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 125 | col.set_sort_column_id(MODULE) |
| 126 | col.set_resizable(True) |
| 127 | self.booleansView.append_column(col) |
| 128 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 129 | col = Gtk.TreeViewColumn("Description", Gtk.CellRendererText(), text=DESC) |
| 130 | col.set_sizing(Gtk.TreeViewColumnSizing.FIXED) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 131 | col.set_fixed_width(400) |
| 132 | col.set_sort_column_id(DESC) |
| 133 | col.set_resizable(True) |
| 134 | self.booleansView.append_column(col) |
| 135 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 136 | col = Gtk.TreeViewColumn("Name", Gtk.CellRendererText(), text=BOOLEAN) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 137 | col.set_sort_column_id(BOOLEAN) |
| 138 | col.set_resizable(True) |
| 139 | self.booleansView.set_search_equal_func(self.__search) |
| 140 | self.booleansView.append_column(col) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 141 | self.filter = "" |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 142 | self.load(self.filter) |
| 143 | |
Dan Walsh | 39d6b46 | 2012-05-24 05:51:41 -0400 | [diff] [blame] | 144 | def error(self, message): |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 145 | dlg = Gtk.MessageDialog(None, 0, Gtk.MessageType.ERROR, |
| 146 | Gtk.ButtonsType.CLOSE, |
Dan Walsh | 39d6b46 | 2012-05-24 05:51:41 -0400 | [diff] [blame] | 147 | message) |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 148 | dlg.set_position(Gtk.WindowPosition.MOUSE) |
Dan Walsh | 39d6b46 | 2012-05-24 05:51:41 -0400 | [diff] [blame] | 149 | dlg.show_all() |
| 150 | dlg.run() |
| 151 | dlg.destroy() |
| 152 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 153 | def __search(self, model, col, key, i): |
| 154 | sort_col = self.store.get_sort_column_id()[0] |
| 155 | if sort_col > 0: |
| 156 | val = model.get_value(i, sort_col) |
| 157 | if val.lower().startswith(key.lower()): |
| 158 | return False |
| 159 | return True |
| 160 | |
| 161 | def wait(self): |
| 162 | self.window.set_cursor(self.busy_cursor) |
| 163 | semanagePage.idle_func() |
| 164 | |
| 165 | def ready(self): |
| 166 | self.window.set_cursor(self.ready_cursor) |
| 167 | semanagePage.idle_func() |
| 168 | |
| 169 | def deleteDialog(self): |
| 170 | store, iter = self.booleansView.get_selection().get_selected() |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 171 | if iter is None: |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 172 | return |
| 173 | boolean = store.get_value(iter, BOOLEAN) |
| 174 | # change cursor |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 175 | if boolean is None: |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 176 | return |
| 177 | try: |
| 178 | self.wait() |
Jason Zaman | 05d1cea | 2016-08-05 02:34:04 +0800 | [diff] [blame] | 179 | (rc, out) = getstatusoutput("semanage boolean -d %s" % boolean) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 180 | |
| 181 | self.ready() |
| 182 | if rc != 0: |
| 183 | return self.error(out) |
| 184 | self.load(self.filter) |
Jason Zaman | 4d340e4 | 2016-08-05 02:34:03 +0800 | [diff] [blame] | 185 | except ValueError as e: |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 186 | self.error(e.args[0]) |
| 187 | |
| 188 | def filter_changed(self, *arg): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 189 | filter = arg[0].get_text() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 190 | if filter != self.filter: |
| 191 | self.load(filter) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 192 | self.filter = filter |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 193 | |
| 194 | def use_menus(self): |
| 195 | return False |
| 196 | |
| 197 | def get_description(self): |
| 198 | return _("Boolean") |
| 199 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 200 | def match(self, key, filter=""): |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 201 | try: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 202 | f = filter.lower() |
| 203 | cat = self.booleans.get_category(key).lower() |
| 204 | val = self.booleans.get_desc(key).lower() |
| 205 | k = key.lower() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 206 | return val.find(f) >= 0 or k.find(f) >= 0 or cat.find(f) >= 0 |
| 207 | except: |
| 208 | return False |
| 209 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 210 | def load(self, filter=None): |
| 211 | self.store.clear() |
| 212 | self.booleans = seobject.booleanRecords() |
| 213 | booleansList = self.booleans.get_all(self.local) |
| 214 | for name in booleansList: |
| 215 | rec = booleansList[name] |
| 216 | if self.match(name, filter): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 217 | iter = self.store.append() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 218 | self.store.set_value(iter, ACTIVE, rec[2] == 1) |
| 219 | self.store.set_value(iter, MODULE, self.booleans.get_category(name)) |
| 220 | self.store.set_value(iter, DESC, self.booleans.get_desc(name)) |
| 221 | self.store.set_value(iter, BOOLEAN, name) |
| 222 | |
| 223 | def boolean_toggled(self, widget, row): |
| 224 | iter = self.store.get_iter(row) |
| 225 | val = self.store.get_value(iter, ACTIVE) |
| 226 | key = self.store.get_value(iter, BOOLEAN) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 227 | self.store.set_value(iter, ACTIVE, not val) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 228 | self.wait() |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 229 | setsebool = "/usr/sbin/setsebool -P %s %d" % (key, not val) |
Jason Zaman | 05d1cea | 2016-08-05 02:34:04 +0800 | [diff] [blame] | 230 | rc, out = getstatusoutput(setsebool) |
Dan Walsh | 39d6b46 | 2012-05-24 05:51:41 -0400 | [diff] [blame] | 231 | if rc != 0: |
| 232 | self.error(out) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 233 | self.load(self.filter) |
| 234 | self.ready() |
| 235 | |
| 236 | def on_revert_clicked(self, button): |
| 237 | self.wait() |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 238 | setsebool = "semanage boolean --deleteall" |
Jason Zaman | 05d1cea | 2016-08-05 02:34:04 +0800 | [diff] [blame] | 239 | getstatusoutput(setsebool) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 240 | self.load(self.filter) |
| 241 | self.ready() |
| 242 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 243 | def on_local_clicked(self, button): |
| 244 | self.local = not self.local |
| 245 | self.revertButton.set_sensitive(self.local) |
| 246 | |
| 247 | if self.local: |
| 248 | button.set_label(_("all")) |
| 249 | else: |
| 250 | button.set_label(_("Customized")) |
| 251 | |
| 252 | self.load(self.filter) |
| 253 | return True |