Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 1 | ## fcontextPage.py - show selinux mappings |
| 2 | ## Copyright (C) 2006 Red Hat, Inc. |
| 3 | |
| 4 | ## This program is free software; you can redistribute it and/or modify |
| 5 | ## it under the terms of the GNU General Public License as published by |
| 6 | ## the Free Software Foundation; either version 2 of the License, or |
| 7 | ## (at your option) any later version. |
| 8 | |
| 9 | ## This program is distributed in the hope that it will be useful, |
| 10 | ## but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 11 | ## MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
| 12 | ## GNU General Public License for more details. |
| 13 | |
| 14 | ## You should have received a copy of the GNU General Public License |
| 15 | ## along with this program; if not, write to the Free Software |
| 16 | ## Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. |
| 17 | |
| 18 | ## Author: Dan Walsh |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 19 | from gi.repository import GObject, Gtk |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 20 | import seobject |
Jason Zaman | 05d1cea | 2016-08-05 02:34:04 +0800 | [diff] [blame] | 21 | try: |
| 22 | from subprocess import getstatusoutput |
| 23 | except ImportError: |
| 24 | from commands import getstatusoutput |
| 25 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 26 | from semanagePage import * |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 27 | |
| 28 | SPEC_COL = 0 |
| 29 | TYPE_COL = 1 |
| 30 | FTYPE_COL = 2 |
| 31 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 32 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 33 | class context: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 34 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 35 | def __init__(self, scontext): |
| 36 | self.scontext = scontext |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 37 | con = scontext.split(":") |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 38 | self.type = con[0] |
| 39 | if len(con) > 1: |
| 40 | self.mls = con[1] |
| 41 | else: |
| 42 | self.mls = "s0" |
| 43 | |
| 44 | def __str__(self): |
| 45 | return self.scontext |
| 46 | |
| 47 | ## |
| 48 | ## I18N |
| 49 | ## |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 50 | PROGNAME = "policycoreutils" |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 51 | try: |
Jason Zaman | af59544 | 2016-08-05 02:34:02 +0800 | [diff] [blame] | 52 | import gettext |
| 53 | kwargs = {} |
| 54 | if sys.version_info < (3,): |
| 55 | kwargs['unicode'] = True |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 56 | gettext.install(PROGNAME, |
| 57 | localedir="/usr/share/locale", |
Jason Zaman | af59544 | 2016-08-05 02:34:02 +0800 | [diff] [blame] | 58 | codeset='utf-8', |
| 59 | **kwargs) |
| 60 | except: |
| 61 | try: |
| 62 | import builtins |
| 63 | builtins.__dict__['_'] = str |
| 64 | except ImportError: |
| 65 | import __builtin__ |
| 66 | __builtin__.__dict__['_'] = unicode |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 67 | |
| 68 | |
| 69 | class fcontextPage(semanagePage): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 70 | |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 71 | def __init__(self, xml): |
| 72 | semanagePage.__init__(self, xml, "fcontext", _("File Labeling")) |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 73 | self.fcontextFilter = xml.get_object("fcontextFilterEntry") |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 74 | self.fcontextFilter.connect("focus_out_event", self.filter_changed) |
| 75 | self.fcontextFilter.connect("activate", self.filter_changed) |
| 76 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 77 | self.store = Gtk.ListStore(GObject.TYPE_STRING, GObject.TYPE_STRING, GObject.TYPE_STRING) |
| 78 | self.view = xml.get_object("fcontextView") |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 79 | self.view.set_model(self.store) |
| 80 | self.view.set_search_equal_func(self.search) |
| 81 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 82 | col = Gtk.TreeViewColumn(_("File\nSpecification"), Gtk.CellRendererText(), text=SPEC_COL) |
| 83 | col.set_sizing(Gtk.TreeViewColumnSizing.FIXED) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 84 | col.set_fixed_width(250) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 85 | |
| 86 | col.set_sort_column_id(SPEC_COL) |
| 87 | col.set_resizable(True) |
| 88 | self.view.append_column(col) |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 89 | col = Gtk.TreeViewColumn(_("Selinux\nFile Type"), Gtk.CellRendererText(), text=TYPE_COL) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 90 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 91 | col.set_sizing(Gtk.TreeViewColumnSizing.FIXED) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 92 | col.set_fixed_width(250) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 93 | col.set_sort_column_id(TYPE_COL) |
| 94 | col.set_resizable(True) |
| 95 | self.view.append_column(col) |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 96 | col = Gtk.TreeViewColumn(_("File\nType"), Gtk.CellRendererText(), text=2) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 97 | col.set_sort_column_id(FTYPE_COL) |
| 98 | col.set_resizable(True) |
| 99 | self.view.append_column(col) |
| 100 | |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 101 | self.store.set_sort_column_id(SPEC_COL, Gtk.SortType.ASCENDING) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 102 | self.load() |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 103 | self.fcontextEntry = xml.get_object("fcontextEntry") |
| 104 | self.fcontextFileTypeCombo = xml.get_object("fcontextFileTypeCombo") |
| 105 | self.fcontextTypeEntry = xml.get_object("fcontextTypeEntry") |
| 106 | self.fcontextMLSEntry = xml.get_object("fcontextMLSEntry") |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 107 | |
| 108 | def match(self, fcon_dict, k, filter): |
| 109 | try: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 110 | f = filter.lower() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 111 | for con in k: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 112 | k = con.lower() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 113 | if k.find(f) >= 0: |
| 114 | return True |
| 115 | for con in fcon_dict[k]: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 116 | k = con.lower() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 117 | if k.find(f) >= 0: |
| 118 | return True |
| 119 | except: |
| 120 | pass |
| 121 | return False |
| 122 | |
| 123 | def load(self, filter=""): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 124 | self.filter = filter |
| 125 | self.fcontext = seobject.fcontextRecords() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 126 | self.store.clear() |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 127 | fcon_dict = self.fcontext.get_all(self.local) |
Jason Zaman | 4d340e4 | 2016-08-05 02:34:03 +0800 | [diff] [blame] | 128 | for k in sorted(fcon_dict.keys()): |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 129 | if not self.match(fcon_dict, k, filter): |
| 130 | continue |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 131 | iter = self.store.append() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 132 | self.store.set_value(iter, SPEC_COL, k[0]) |
| 133 | self.store.set_value(iter, FTYPE_COL, k[1]) |
| 134 | if fcon_dict[k]: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 135 | rec = "%s:%s" % (fcon_dict[k][2], seobject.translate(fcon_dict[k][3], False)) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 136 | else: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 137 | rec = "<<None>>" |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 138 | self.store.set_value(iter, TYPE_COL, rec) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 139 | self.view.get_selection().select_path((0,)) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 140 | |
| 141 | def filter_changed(self, *arg): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 142 | filter = arg[0].get_text() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 143 | if filter != self.filter: |
| 144 | self.load(filter) |
| 145 | |
| 146 | def dialogInit(self): |
| 147 | store, iter = self.view.get_selection().get_selected() |
| 148 | self.fcontextEntry.set_text(store.get_value(iter, SPEC_COL)) |
| 149 | self.fcontextEntry.set_sensitive(False) |
| 150 | scontext = store.get_value(iter, TYPE_COL) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 151 | scon = context(scontext) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 152 | self.fcontextTypeEntry.set_text(scon.type) |
| 153 | self.fcontextMLSEntry.set_text(scon.mls) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 154 | type = store.get_value(iter, FTYPE_COL) |
| 155 | liststore = self.fcontextFileTypeCombo.get_model() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 156 | iter = liststore.get_iter_first() |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 157 | while iter != None and liststore.get_value(iter, 0) != type: |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 158 | iter = liststore.iter_next(iter) |
| 159 | if iter != None: |
| 160 | self.fcontextFileTypeCombo.set_active_iter(iter) |
| 161 | self.fcontextFileTypeCombo.set_sensitive(False) |
| 162 | |
| 163 | def dialogClear(self): |
| 164 | self.fcontextEntry.set_text("") |
| 165 | self.fcontextEntry.set_sensitive(True) |
| 166 | self.fcontextFileTypeCombo.set_sensitive(True) |
Vit Mojzis | 3217d71 | 2018-03-01 12:03:06 +0100 | [diff] [blame] | 167 | self.fcontextFileTypeCombo.set_active(0) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 168 | self.fcontextTypeEntry.set_text("") |
| 169 | self.fcontextMLSEntry.set_text("s0") |
| 170 | |
| 171 | def delete(self): |
| 172 | store, iter = self.view.get_selection().get_selected() |
| 173 | try: |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 174 | fspec = store.get_value(iter, SPEC_COL) |
| 175 | ftype = store.get_value(iter, FTYPE_COL) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 176 | self.wait() |
Vit Mojzis | 530904e | 2016-10-19 14:36:03 +0200 | [diff] [blame] | 177 | (rc, out) = getstatusoutput("semanage fcontext -d -f '%s' '%s'" % (seobject.file_type_str_to_option[ftype], fspec)) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 178 | self.ready() |
| 179 | |
| 180 | if rc != 0: |
| 181 | return self.error(out) |
| 182 | store.remove(iter) |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 183 | self.view.get_selection().select_path((0,)) |
Jason Zaman | 4d340e4 | 2016-08-05 02:34:03 +0800 | [diff] [blame] | 184 | except ValueError as e: |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 185 | self.error(e.args[0]) |
| 186 | |
| 187 | def add(self): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 188 | fspec = self.fcontextEntry.get_text().strip() |
| 189 | type = self.fcontextTypeEntry.get_text().strip() |
| 190 | mls = self.fcontextMLSEntry.get_text().strip() |
| 191 | list_model = self.fcontextFileTypeCombo.get_model() |
Vit Mojzis | 530904e | 2016-10-19 14:36:03 +0200 | [diff] [blame] | 192 | it = self.fcontextFileTypeCombo.get_active_iter() |
Nicolas Iooss | 0f3beeb | 2017-09-20 08:56:54 +0200 | [diff] [blame] | 193 | ftype = list_model.get_value(it, 0) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 194 | self.wait() |
Vit Mojzis | 530904e | 2016-10-19 14:36:03 +0200 | [diff] [blame] | 195 | (rc, out) = getstatusoutput("semanage fcontext -a -t %s -r %s -f '%s' '%s'" % (type, mls, seobject.file_type_str_to_option[ftype], fspec)) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 196 | self.ready() |
| 197 | if rc != 0: |
| 198 | self.error(out) |
| 199 | return False |
| 200 | |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 201 | iter = self.store.append() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 202 | self.store.set_value(iter, SPEC_COL, fspec) |
| 203 | self.store.set_value(iter, FTYPE_COL, ftype) |
| 204 | self.store.set_value(iter, TYPE_COL, "%s:%s" % (type, mls)) |
| 205 | |
| 206 | def modify(self): |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 207 | fspec = self.fcontextEntry.get_text().strip() |
| 208 | type = self.fcontextTypeEntry.get_text().strip() |
| 209 | mls = self.fcontextMLSEntry.get_text().strip() |
| 210 | list_model = self.fcontextFileTypeCombo.get_model() |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 211 | iter = self.fcontextFileTypeCombo.get_active_iter() |
Jason Zaman | 789d0eb | 2015-07-24 16:07:13 +0800 | [diff] [blame] | 212 | ftype = list_model.get_value(iter, 0) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 213 | self.wait() |
Vit Mojzis | 530904e | 2016-10-19 14:36:03 +0200 | [diff] [blame] | 214 | (rc, out) = getstatusoutput("semanage fcontext -m -t %s -r %s -f '%s' '%s'" % (type, mls, seobject.file_type_str_to_option[ftype], fspec)) |
Dan Walsh | 514af85 | 2012-04-13 11:04:45 -0400 | [diff] [blame] | 215 | self.ready() |
| 216 | if rc != 0: |
| 217 | self.error(out) |
| 218 | return False |
| 219 | |
| 220 | store, iter = self.view.get_selection().get_selected() |
| 221 | self.store.set_value(iter, SPEC_COL, fspec) |
| 222 | self.store.set_value(iter, FTYPE_COL, ftype) |
| 223 | self.store.set_value(iter, TYPE_COL, "%s:%s" % (type, mls)) |