�ɲɾ�����ӯ�����һ��ˣ��������С���˴��ͣ�������P���ҹ��ñ˽��ά�Բ��������˸߸ԣ�������ơ��ҹ��ñ�����ά�Բ���ˡ���˳^�ӣ������ӡ� ���ͯj�ӣ��ƺ���ӣ� ? PNG ?%k25u25%fgd5n!? PNG ?%k25u25%fgd5n!? PNG ?%k25u25%fgd5n!? PNG ?%k25u25%fgd5n!usr/bin/diff000075500001030010152525025120006755 0ustar00ELF>S@H(@8 @@@@00ppp77 0?0?"0?"B  J J" J" DDPtdQtdRtd0?0?"0?"/lib64/ld-linux-x86-64.so.2GNUGNUGNUjK>p n.yMayz)PvfUa,crbA92YGQm l' r%b;9xV[]| Uh6%C{"<  2g>(c@Uk,L RL Ig^/( mE_& "F(Q" Q"!0Q"-!HQ"HQ"x! Q"`Q"u8Q"@Q"libc.so.6strcpygmtime_r__printf_chkre_set_syntaxfnmatchreaddirexecvsetlocalembrtowctowlowerfopenstrncmpoptindstrrchrfflush_unlockedregexecpipedcgettextwcrtombclosedirerrorsignalputsforkiswspacesigprocmaskregfree__stack_chk_fail__lxstatiswprintreallocabortstdin_exitprogram_invocation_namestrdupstrftime__assert_failiswalnumlocaltime_r__ctype_get_mb_cur_maxisattycallocstrlenungetcsigemptysetmemset__errno_locationreadmemcmpmempcpydup2unsetenv_setjmp__fprintf_chksigaddsetstdoutstrnlenlseeksigaltstackmemcpyfclosemallocstrcasecmptimegmraisembsinittzsetre_compile_pattern__uflownl_langinfoopendir__ctype_b_locgetenvregcompoptargstderrwcwidthreadlinkfscanfgetopt_long__fxstatfilenore_searchfwriteiconv_closegettimeofdaysigactionsigismemberclock_gettimewaitpidlocaltimestrchriswcntrlmktimeiconvprogram_invocation_short_namefdopenqsorticonv_open__ctype_toupper_loc__ctype_tolower_loc__cxa_finalize__vasprintf_chk__sprintf_chk__xstatmemmovebindtextdomainrawmemchrfwrite_unlockedstrcmp__libc_start_mainstrcoll__overflow__strtoul_internalfputs_unlocked__progname__progname_fullGLIBC_2.3.4GLIBC_2.8GLIBC_2.14GLIBC_2.4GLIBC_2.17GLIBC_2.2.5GLIBC_2.3_ITM_deregisterTMCloneTable__gmon_start___ITM_registerTMCloneTableti ii ii ui ii 0?"T8?"PT@?"@?"`?" h?"p?"Px?"?"?"8?"p?"?"?"0?"?"?"?"?"P?"?"?"?"X?"@"@"@"@@" @"(@"0@"X8@"@@"H@"(P@"xX@"`@"Hh@"p@"x@"@"`@"@"@"(@"x@"@"@"@"@"@@"@"@" @"h@"@" A"A"A"A"@ A"(A"0A" 8A"@A"HA"@PA"xXA"`A"hA"pA"PxA"xA"A"A"JB" B"@B"`B"B"B" B"B"C"" C"'@C"5`C";C"LC"_C",C"kD" D"@D"`D"D"D"D"D"7E" E"@E"`E" E"E")E"BE"IF"Z F"j@F"s`F"{F"F"F"F"G" G"@G"`G"G"G"G"*G"@H" H"v@H"H`H"_H"uH"H"H"I"@I"DHI"PI"XI"`I"hI"pI"xI"I"6I">I"DI"QI"^I"xI"rI"WI"I"z(P"8P" XP"%hP"xP"P"P"P"T"P"Q"Q"Q"`t"J"KJ"VJ"O" O"/O"9O"BO"jO"q Q"z(Q"y0Q"{8Q"@Q"HQ"}`Q"(L"0L"8L"@L"HL"PL"XL"`L"hL" pL" xL" L" L"L"L"L"L"L"L"L"L"L"L"L"L"L"L"M"M"M"M" M"!(M""0M"#8M"$@M"%HM"&PM"'XM"(`M")hM"*pM"+xM",M"-M".M"0M"1M"2M"3M"4M"5M"6M"7M"8M":M";M"<M"=M">N"?N"@N"AN"C N"D(N"E0N"F8N"G@N"HHN"IPN"JXN"K`N"LhN"MpN"NxN"ON"PN"QN"RN"SN"TN"UN"VN"WN"XN"YN"ZN"[N"\N"]N"^N"_O"`O"aO"bO"c O"d(O"e0O"f8O"g@O"hHO"iPO"kXO"l`O"mhO"npO"oxO"pO"qO"rO"sO"tO"uO"vO"wO"xHHQ"HtH5r"%s"hhhhhhhhqhah Qh Ah 1h !h hhhhhhhhhhqhahQhAh1h!hhhh h!h"h#h$h%h&h'qh(ah)Qh*Ah+1h,!h-h.h/h0h1h2h3h4h5h6h7qh8ah9Qh:Ah;1h<!h=h>h?h@hAhBhChDhEhFhGqhHahIQhJAhK1hL!hMhNhOhPhQhRhShThUhVhWqhXahYQhZAh[1h\!h]h^h_h`hahbhchdhehfhgqhhahiQhjAhk1hl!hmhnhohphqhr%="D%5"D%-"D%%"D%"D%"D% "D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%}"D%u"D%m"D%e"D%]"D%U"D%M"D%E"D%="D%5"D%-"D%%"D%"D%"D% "D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%}"D%u"D%m"D%e"D%]"D%U"D%M"D%E"D%="D%5"D%-"D%%"D%"D%"D% "D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%}"D%u"D%m"D%e"D%]"D%U"D%M"D%E"D%="D%5"D%-"D%%"D%"D%"D% "D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"D%"DKFA<72-(# fDAWAVAUATLcUHSHHH>dH%(HD$81HD$ HD$("H5ͪCH5H=H=t1=H="F H"H>"H"2="H<"H HD$E1HoH>"HD$AHD$@E1H &"HDHtAǃ ADHcH>=="H"A H59<"H=E|<"t<"ElH H5"IcHkHH ;"H<0?+<"t@n<"EoH PH5"IcHkHH ;"H<>H5"H|$(H˃E>;"E<"t;"e;"E;";"EV;"EG;"E8;"E)H= " Ht$01AHPHHT$0:H:"H9aH|H:"E;"E;"t;"H5j "HXH=L:"E=H5M "H;H=7:"j=H53 "H!H=%:"P=K9"EH5H1H "1H5HHH5|;f.H=q "HG(H;G0HPHW( II4$Hm>tʺ1H(fHXHLH1H)H HHuE< 1<-@1!HHcLpL- "MnH5LWH5ݯL X6"EH5 "H|$ H}E91 "E6"EH5;}H= "E7D$b6"s 6"E9= 17"EFo6"EL6"EM6"` 26"E$6"7  6"Ev5"E5" 5"o==5"E\*5"M4"E>5"E,4"H="1Ht$0 6HZ HT$0:L I9bM IE{4"EH5"H{H=4"E7"E"EH=k4"H=e4"H0"EHN4"QH5"H=s"E564"E'H5"H="Eq5 3"E3"F4"t/4"HH="1HHHH<HkHaL o"E1HH aHIžAQ1AQAQjAQAQjAQH 2"H@Hl$HLHHyHF6LMlH2"H9uHl$E H="He1ɺ Ht$0/HT$0:H?H9HF1AU 43"9t3"H953"cH(3"ED$3"EA0A HL$1A3HH)HeffffffH9Hk AGEHHHD$=HF=1"~2"HLxH|$Ha2"M2"H5f2"H=1"u H1"2"MEuH=1"HOLHHL!HH1HHHHH)HL9H)J2HWH9HGHH0"LEH951"L51"}H51"H="3H=N"3s1" 0"\1"1" K1" 0"H=" B1" H]!ȈH1"z"%;1"IALlI>ITN|8M9uLbI H3HxHuI9uH|$ L50"H|$(H=}}XB d|$(O0"H|$)HvH+0"AGEHHD$H/"EH."(AH."?ACED$?H/"z0HyuH|/"H5/".H=."H=."H=."H=N."HW."H=A."oH=#."HH= ."?RЃG"1A9~4HHt$ 1HT19L؋""D9|ߐz@1҃=."ZH|$(Hc"D)ƒ*HtH=Dv'0H"EH-"'."HtH;t$||$HD$H."HH?EHD$xH=uH?H5uHt(,"H5puQ1҅H,"1Ҁ8H5uL$z,"EHAsHD-"11/JtH=t.I[H=tH= ,"HWH5 ,"H=+"H花H+","UHtH,"RHHrHEH+"wHHrHEH+"OHGtH+"'H4tH+"H1rH5d,"HE,"3/H=!WH5!H=bs-/H=LrsH5l!H=r-1H=x-LH=s-H5"x2"H 3XHcH>H-"L LmA<$/HI0I9ufDA:M M>1E1E1LLHIMMLLfB<3BD=AAuIII9|I9|HLM@@IB<#uLL)H|$MIB|-uLL)HD$0LD$8Ht$0HL$(HT$ H|$Ht$0LD$8HL$(LpMHxH|$Lx HT$ MH0HHx7H5V1HMIH:HEW111_A="uH-"H1E1="E1=c"yHzHD$HD$KHg@w.H&;H1Hb1H81ξH1H}H\E1HAH8LH{IHD$THD$I$N{f.H(dH%(HD$1HL$LD$譐LD$HL$I96H=_"L1H6UQHD$dH3%(u%H(@H=)"HU1H(dH%(HD$1HL$LD$HL$HT$H9>HTHTH="HM1HD$dH3%(u2H(@HH="HѾH)H`TL@1yBfUHSHHHG(H9G0&HPHW(  w3H>Hs HA'1 u1sfDH1A'FHA9| H| u9~BHcD< w6H>Hs&AIHc‰9}L v)HcHH[]PMHIMuHSE1A ApH׀ wMHIIt tAA( FL "HHOHG O\HtPSHrz(MMEHOHGII)LLB LH)H9L9}HHLHHuH[ÐHff.AVAUATUSHH@dH%(HD$81HtDIHH=g "HRR^HD$8dH3%(H@[]A\A]A^DH~hHIIVLupHt"H "E1EH+LHu"LEhEH Q1+LH= "MMHHQ1S|ff.AVIAUAATL%!UH5!SH9@I,H= "HHHITHIGE11Ay3HI9~H!1HH9tI,[H]A\A]A^fHHV![]A\A]A^f.AWAVAUATUSHH8HL$HT$dH%(HD$(1Ht$LD$ r Ht$AHT$Hf "H "H)HH9HLH)H9HLHL$Ht$HT$H "H<IHI)I9HL$ HOHT$H "HHH)HH9HNH= "HD$ H=& "iInH- "H=OHMt LHaHE(H;E0HPHU( ^HH=OUHT$Ht$H= "HH=O& HE(H;E0HPHU( AtHD$H9D$ӄHH=0OHT$ Ht$H= "THH=O聄HE(H;E0`HPHU( AtHD$ H9D$~XfDHD$(dH3%(_H8[]A\A]A^A_DmH-_"H=aNH}L|$L;|$ L%JNL5.NHu HHtxHC HSHL9~I9|cH{H=)NIOH54 "N,LwL9|$ tXH "JD*x t&IL9|$ Huf.LHE(H;E0HPHU( D뜿L|$L;|$%IMuDM6MtxIFIVHL9~I9|cI~H=FMHMHOH5 "N,L萆L9|$tYH"JD*x t'IL9|$MuH=LHE(H;E0s4HPHU( f6뛾 H H댾 Hv Hd HRuAWAVAUIATUSHHHL$(HT$ dH%(HD$81Ht$LD$0袇H"Ht$H "HT$(H)HH9HLH)H9HLHL$ Ht$HT$(H"H<IHI)I9HL$0HOHT$ H"HHH)HH9HNH="HD$0H=Y"HiH%"ӀH=>KHHT$ Ht$H=Y"HٺH=KHT$0Ht$(H=Z"H=JHٺlRHt HH"HC(H;C0HPHS( HD$(Ld$H$L9d$ }H$H9D$0DMt M9e1HR"=b"Il$N$t I$8 t(="HC( H;C0HPHS(@0L1IH$L9d$ }H$H9D$0}HD$8dH3%(kHH[]A\A]A^A_KhH"JH=IHAHT$ Ht$H="[HٺH=IHT$0Ht$(H=",HٺH=\I~@M}MSM}MuMmHI~H$L|$H,'IFx IHIL5"HC(IH;C0HPHS(+=n"t&="tI8 tHC(H;C0sqHPHS( 1LׁMv}IFx uJHC(H;C0HPHS( R@+H qfD H닐H$HL$HDH$fJ,N}IGHD$I IFx IHIL5"HC(IH;C0HPHS(-=F"t&=l"tI8 tHC(H;C0sqHPHS( 1L诀Mv|IFx uRHC(H;C0sXHPHS( V-HqfD H˽fHD$Md H製fD H苽 HyDf.AUAATUH1SHL0H{H T"HHEtAH=*F]HSLH 7"H= FCH[]A\A]{H=EHSLH !H=EAWAVAUATUSHHHt$ dH%(HD$81="uH="HtLHD$ILt$0H$Ll$(Ld$ I/ILMH4$LLI/AG(IHuHP"H؀|$ HQ!HH8!u6HH5H zHD$8dH3%(uaHH[]A\A]A^A_ÐHH5HyHHu@@(HHa@(HHuP*f.AVAUATUHHSHHU HHI8Ht#IHHRD[1]A\1A]A^pLmLuHuMȈELHcLLHMH9r)HHDDHH9sHuLLHEJ<0Mt\J|0BD0|IT$H[]A\A]A^ff.SHt#HH1عH11H1跽HX!H5H1譹1HH1艽fH?t"USHRHo 6{HE uX[]HS HsH;HtH IHC11'ATUHSHH?Ht IuH+[]A\úH5>H111IHL1Ӽ11f.PX1H=-HHff.AWAVAUIATIUSHHdH%(H$1HH„ut{=E!Hl$ L1L$HHMD$ DŽ$PIMuZLl$(H$XHD$H$qHl$ L1L$HHD$ DŽ$PMtI|$1L?I$81HH$HD$($HD$H$XII1A>Ht$(H$XK{foD$0D$ foL$@foT$P)$`fo\$`fod$pfo$$Pfo$)$pfo$fo$)$)$)$)$)$)$)$I0 !=!L`<+H|D$ $P)ƒ%T$T$H|$(HÉZ+$PH$XZH=!蟺 H<$~H|$tH$dH3 %( HĘ[]A\A]A^A_f=!3Hl$ L1L$HHMD$ HDŽ$PL@@tVA@ƃ@MHiAAHHI0YD_fDMVH=w>IVL=!LֿشV+AHU1H׋$xHT$Hk)MD$H$x%=@@8AHA)HMcHPHLD(LLD$RKIVHHH|(HT$$HT$LD$H=M=H$HD(Lp =!HTH4$賵tH<$W<L$ $P,|$HD$xH$hH9D$8D%=`E1=  s=@@ǁ@A@EzE1Mǁuׁt 1H=#<HHHPLHItX-AW(ցI@y@CVfA1HT$HT$1謴)AF(%=I~hGfD$ HTDŽ$PI@D$ 0蓱fDE1%=@A@@E@=1!Mt =W!9H52H Å1ۀ=!D$H%=@Hn!HH5V!HH=@1Vf.MH=):LDHHHPLHItVQDH@1HHD$H$x@'D$H$xE1%DŽ$PH$X111Ƴ$P}H$XT|$ xȰjH|$(S$Px;|$ t蠰h;fDD$T$H H$`H9D$0D9H$pH9D$@ E1%H@HH$xfH@TL%u!IMH}8H5Q!HMLH=>H#ScfD`L$L9\$Xz/@@t fg=!t=!(=!t MH U1H57H=7ǮH$X&Ht$()fDH$XHt$(H==Sf@=A@=!t 1ۃBElD$ $P&|$ $P/;|$ %8H$X^Qf11蒭HI)F@I~@IIF@IF@Ht$( L$X=!;E@H|$(HHH$XIHHHvH譪L襪@۪+A\H$|9D$L$9D$PH$H9D$`H$H9$H$H9$=!A%>H|$(111DD$fDD$D$ xi$PHT$`H$H@H9@HH!HH5!HH=3EQH|$(DD$LO$PDD$vH$XHt$(H=:PHLv1HcûHi0H|(NHN1H5D4FHQH QMH53H=4H=9QH=9QHt$( H$XHH=m! u諩uHH=3fQ1H53賩H Qf.HcHHFHH DH`H}HHqH9pt:D(%=`tD= uˋA(%= uHA8H9D8uHqH9ptD(%=`uA(%=`tH`Hu1UHSHH诧=!HHtH[]_H[]齫f.USH=!HH.uHHH[]ffDHHutH[]f.UHSHH=!uHHH[]f.+u =0!tH[]AWAVAUATUHSH8HBHBH>讧HD$HAI?fHEIjHD$HD$HD$(HD$H|$˩Hx.LhuPtЀ.LoH=!LHyuHCH\$HD$ HL9v&M9MLLIHEI9rH|$HT$ LLHD$(H\$H#HD$H81[]A\A]A^A_xWHD$H|$uuHL|$(I9w{JHL}HEHkMt_HHDL3LHaMtH9uHH8[]A\A]A^A_ÿHEHHE<H(fDAVAUATUSHpDH<$Ht$dH%(HD$h1D$At 1tsH$0tHtU1AH$H5N1HHHPHH\E11HH1$yDH$HT$0DHpH$HT$H0H8yD$H|$8tHfH|$@\H|$PRH|$XHD$H\$hdH3%( Hp[]A\A]A^HD$PH|$ H=!ü!HD$(!>H|$ Ht$0H 芣Ht$HH|$(H oH5!HtH$H`1f.HT$(HD$ H2H8=!tHT$(HD$ H2H8赥HD$(HPHT$(HHD$ HHH0HL$ H<$HD$ЋT$9 HD$ H8t)HD$ H0HD$(Ht/H8]HHD$(H8uH|$8`HPHT$(Hf.xHD$(HHPHT$(HjD)HcLl HD I}MuL LHuHH}HLgH}L蓤xHLLL)hMeD$H$H8FD$D$H|$8kH$HxFD$h!HD$ H8u(hfDHD$ HHD$ HD$ H8tIH5!HD$ H8x/DHD$(H5t!H8lHD$(HHD$(HD$(H8uAVUSHH|$H4$dH %(H$x1ɀ=~!Ht$HD$(HD$0uUHt$H|$1|H|$(H跟H|$0譟HH$xdH3%(HĀ[]A^H|$HHT$ 1Ht$HD$@tH=G!!ktH$HD$`DH\$(H;HuIfDHH;H3L4$LuH+LHJtHD$H;$uHl$@Hl$聠ATUSH0HL$HT$dH%(HD$(1Ht$LD$ ;eu'HD$(dH3%(H0[]A\f.GHT$HL$H5!,dH=!H.P4HG(H;G0HPHW(@0H=!HG(H;G0 HPHW( aH\$L%HH;\$ @DH5!HHH:.u z Hht9ZfH5ZHZfH5YH>YfFH< HDHcH>DHHGH+GHHHwH?p_HHHHwH?HL_@HHwH?8_HHHHwH?H_@e@ wHD@HcH>fHX@AWHFAVAUATUSHHX-t't0tDA0A wfHDHDA0A v.DSA IADIIHL`0HIAts@'umP'td\tWx'uQL`HtKHE(H;E0YHHHM(1fDHDHDA0A vDSA Y@E1HL[]A\A]A^A_H@nuLH]HH $HtLL)HzLzHT$HT$LHILDLLD$ҚLD$H $1C>lHLAA@ LXLUHHv%FHD$@E1HD$A0FЃ cLL\$LD$ H|$L\$JHALD$ I@H >L@B<@88I1HD$@H;D$HLIHD:LLEHpL)LXHMƉfDHD$H5!IULD$H#HD$LD$XL[DHD$LH5y!LD$fHD$LH5i!LD$f.11MHHnHDL\$(LD$ YLD$ Ht$1 LHD$eHL$L\$(LL$JAHD$8uDH͓ALA `AUATUSHhHL$HT$HdH%(HD$X1LD$XÅu%HD$XdH3%(Hh[]A\A]fD:H!H $H!H|$H9| H9L-_!H|$HHl$ H=!H5!HL$0HM0HT$@1Ll$ HD$(Ld$8]H|$H $HD$H5h!H|$@H4H=!HL$(HHPHD$Ll$ HT$0HHJ!1Ld$8HD$HH/!DL-!Hl$ M0fDHHH5QPHdH%(HD$81HK!HHɩ!Hʩ!=PH!H9!-H!H9/!HD$8dH3%(uvHHK9H!H1H$Hl!H5M!H=~!HD$H!HD$H!HD$H2!HD$ H!HD$(zfATUSHHHt|( t( HƇ Ƈ HtfL$(HI$=>!tGA$ H*I9t0HfHH u 18 @HI9wH)H)H[]A\fUHSHHHHH?HtHH9!H[]H{%7DvUSHHG(%=HHH)t !bHHH?H9ukH9NH4HH[HHHHH)t!uHHHH9tf.HpHHHHH[]Ho@HHHH9HH9H9rTHH9HH)Ht!uHOHH9|f.HHEH@HHODf.USHHHHwHHHtH@t Hǃ1ƃ!H[]DHHt !tCH1HHH[]DHLJHfHHDf.Ht !tDAWAVIAUATUSH!H|$` dH%(H$1A0 舄$A9>upH|$`$HHHHHHt[H$dH3<%($H[]A\A]A^A_fDI0 %$$uLt$`L7L/A0A9oHt$`HHLH HLHPI (!LD$M8HL$DPHH5!HL9u,HHL9ty uLJHtHLHL9uHT$`HHA?HD$LHD$P8 HD$`Ht$=*!HH tH=!HH$HDHH9HGE1HIHLD$ Z=!LD$ HHD$`HHD$ t H9OM1L;D$ HLD$(L|$ HLl$0#L4IA~ uM9LH$LmH!L9uHI9MHJ4DII)IH9LGM9OHT$MKA[HB8Z4M)I!@IQHXDpE8qHIL9uM9=Ay 2HHLfDL9tH{ uHHuHL)LHD$.DMHLl$0HHD$`Ht$LD$(L\!H+MM9MMN I ~HD$ 1L)HH1HD$H+D$AHLD$ IHIDL9IGHL9LN1HHHLEHM9MGK\5LL9H9ˆ$H< M9LD$ ,M~LH+}!HMTHH!H9wQH<@I"ML9}I}H<$>HD$LLT$M軤E1 HD$PLHD$`H-H H5ZH=\tH AH5;H==sH qH5H=sH RH5H=ssAf.AUATUSH8HL$HT$dH%(HD$(1Ht$LD$ 7u%HD$(dH3%(H8[]A\A]fDAX^1HT$HL$H5!,6H=!DH"4HG(H;G00HPHW(@0HL$ HT$,H5߷!60H=1!HG(H;G0HPHW( AtHD$H9D$A`AHD$ H9D$0H\$H;\$ H,L%~HH9\$ H5!LH24H9\$ Hȷ!HH(x uH=c!HG(H;G0HPHW( 똿/H\$H;\$,H,L-DHH9\$H5"!LH3H9\$t3H!HH(x uH=ϳ!HG(H;G0sUHPHW( 렿f/@V/H !H=CsfD pIf vp fp![ppH5U.Hi.fAUATIUHSH=I!H!}L-=!H1IIL=HH)H9w^HHC(H;C0s"HPHS( ID-I9rLHL$H|$ HH)LL$0LT$(>LT$(LL$0IH@HLH9l$vIF(I;F0KHPIV(D I9wHt$XdH34%(L!Hh[]A\A]A^A_ÐH q!H1HH)I9HLDLHtHH9l$vL9 IF(I;F0wHPIIV(kHUH9l$vmIF(I;F0HHLIHIN(D 6fDIF(I;F0BHPIV( Ht$1LT$(L1AE1LT$(@LHD=y!J H;\$IF(I;F0HPIIV( |$LLL$8LT$0L\$(nL\$(LT$0HcLL$8HHOH;l$w$H !LھH_oLT$0L\$(IL:f.HD$H9HGL9fHl$(MLIF(I;F0snHPIV( II9uIMHl$(-f LLT$(>lLT$(@ALLL$0LT$(lLT$(LL$0 LHL$0kHL$0yMLIF(I;F0s"HPIV( HH9uMLID LkALLT$0LHT$(kHT$(LT$0IHLLT$(ekILT$( LLT$0HL$(AkIHL$(LT$0 jf.AWHIAVAUATUSH(H !H-ԭ!@t$L%x!HL$@<A@>E1HHPHǀz LA1RH€ MtIGx A I8 u;EtHE(H;E0XHPHU( EH([]A\A]A^A_DHt$HLLHEtfDE11Ҁ tHD$HItHHP|IG|x D8A-/A-/D$bH([]A\A]A^A_8(H|$!(HD$AHHD$1E1ItH6HPHE(H;E0sML$HpHu(H|$'HD$f. HifDHHT$hHT$KAWAVAUIATIUSH=!u&H!H-!H9AH9AEu"EuL%!L-!H[]A\A]A^A_À=!=L!ujEt`Et[H!HH HTHH!H|&I9t,I9u%f.HQ!)1HHI9uI9ZH!1Ҿ(H=5!1AAt:H\$H;\$ 'DH!!>1HHH9\$ }H~!AfH\$H9\$|#H!1Ҿ<H!HHDaftf.rf.bf.nf.vf.ff.@SH?@t[IE11.f.;tHVH<HDIA8@t@ uIA8A@uHuEu H[@I)J|#"3IL@@u)"LfAH[A\IA@H3@t@t;<u׉A\I0A@0Ap0A@A0IAWLE1HAVLAAUATAUH~SHfDIA IIA=t~~[\t6^uZAHMpDiA>vƀ?tyM1LLL[]A\A]A^A_AHIxwDNc,I>At,:t'IA IIA=uEtfDfAIIMF@-fDE1DE(AMЀ6wCMIA~IAtIAGt5E(AMЀ6v@E1II fDfDfD fDufDE(0EuAZIALE(EuAv;@ -fD fD fD fDAIGt5fDAIGt5@f.AWAVAUATUSHH!dH%(H$1H|v!n=(!Au Ex!E4H-1AH=x!aL},HLd$ L5x! fDD+H1LD^H|$ t DLydL9ufoLx!fo Tx!DŽ$AfoKx!foSx!L=x!L5ufo%Mx!fo-Ux!D$(fo5Xx!fo=`x!L$8T$H\$Xd$hl$x$$ DDmHDLct!AHLDID1HD$ ^H9uH$dH3%(H[]A\A]A^A_@tt6w!DHE1`]!A:DE1H=v!v!H|$H4?+??Ƅ$L5L-l!f$H$HD$HD$*6:HPHT$$xHPHT$P$HPHT$x=E1LH$IKtHt@H:_uIcHt$H|$1HHr!H HD$HAJH5 1\H11H1`H51\11H1`H<$T[H=mu!H@H_ 7[HHuf.(Hl$ALD$HHHu!LHD$HLD$HC HD$Ht!HCpLD$EHD$HPHT$8=.HD$1HKLHHC2 HD$ADHHD$\f.t!u|t!st!fHH !HH8^fDSHCZHH)10[1M_f.AVIAUIATIULSHH`dH%(HD$X1=ڟ!thH HH<$AHDMHt$HDHT$H\$1Hl$ Hl$0 [HHDHIH(H<f=W!t H=(q!HG(H;G0HPHW( L1xZHt$XdH34%(H`IIL[L]HA\A]1A^]DL1IHHLdHLHL0\HLH(t L,fDHo!L5o!L0IHD$XdH3%(u H`[]A\A]A^ZfD NZ"fE11BfAWAVAUATUSHHHr!dH%(HD$81HD$HD$HHl$0LkL#Lt$Ll$LI[YMlM.I9uLL$0Ht$1L|$(Lt$ Ll$L $XL $MLHL1Y\HL^WMuHD$8dH3%(uHH[]A\A]A^A_XDUHSH^WH1H6_\Df.SHH1DXH1H1\ff.H=p!@H=p!H5p!p!He!ff.SHPdH%(HD$H1H=7!tHD$HdH3%(HP[H=ap!H=Mp!HD$HT$H5!H=/HD$H1豉=!HHm!1H!=o!HUQ!uHt$H=!=H|$H;=o!tzUH|$H;=o!cUfDH=Im!\[HEH|$H\$0HD$ HcHD$(HD$8W [o!uw|$ W|$t1V|$~WH=Ht$ =[T18@ǃ~UHt$1H=!=|$'W|$ H57YHH!Hthq@H= @HTlU1H5UHH=HH=7H=:SHH=!dH%(HD$1HtMH;=k!tD T=m!1Ht$X\$߅u!HK!HD$dH3%(u9H[H56~um1TA1HH )1zXT1H5rTHH=HH=`H5듃H5HHDyf.AWAVIAUM~E1ATIMUIT$SHH!=!!H5!HT$0$@|$HD$L|$8MIA,$AL@8<$wEHD$H5HcH><$t"@ u @ u @MIԀ|$t~XH,@8  uL1ILH)IIT$MGHLD$(HT$ HT$LD$'XDDH|$HLL$HT$ LD$(FPfA BDX fEo @  "L;L$07AI DH _@ H;|$8vWDP CIM̽ f.LD$ HT$LD$\WH|$HT$L@LD$ ADA rADA c@ tH\$xH$MD5ҏ!f.At0D$A A u$ z@LL=!$9$_ ~ 'H !HD$@1HHH)DLD$x$4OLD$xW$OLD$xfH=V!H5V!H=U!H5U!U![fH=)V!H5*V!H=U!H5U!uH=U!H5U!]H=U!H5U!EUSHdH%(H$1H+zX!#>1H>bX!u TX!tHH=U! DHH5@X!1='X!X!u1@AfDH$dH3%(u HĘ[]f?fDAWIAVAUATUHSH(=!HL$ubH)tGADH)IHt*HLLHFH #!HAH9vH([]A\A]A^A_HY!IH!E1AHD$H9v@IAw@ @ @t$ @4$lC<$t$ HxfIHC(H;C0HpHs(@8L9SIIuIAwE1@ uHL$L1HH)HIDHpHs( HtHC(H;C0r HH$$>H$fDMtkIHC(H;C0seHPHS([DHC(H;C0sVHPHS( Mt.L9v)A? tHL$LH1AE1@E1H=H=fDAWAVAAUATUSHL.HnL=5!HHE1tV= !HL%HLD=3!LtA} u1< H-HL1@EudHLHL+;tp} tjVH51@1DHHFHHDHHHDIf.HHTLLH|~!L9}DHHǾH1b?fHLɾ1H,G?AWAVAUATUSHhh!H|$ HT$HLD$PD$4H= !HE1H|$ L-/!HD$@HD$8L=!HWLl$XMHHW HH|$ H_HOHWLw HtHT$@HL$8H9J|2Ht$ H<$T$3uBVH=~!tvE1AH=Q~!1<HH9\$nfID1Itx L|LH)HEH9uD$3ELl$(1H|$ HHL$ H HL$HH|$1H9HL$PH<$H9u1H|$8ƒH|$@DHh[]A\A]A^A_D6A nHt$HT$#>Ht$HT$HHHD0A t"BDq uLL$4H)HHDfI)LL;4$!È\$3|$3Ll$(L|$XECfDH=}!E1AH=|!1v;IL94$KD1K4x LdLH)HEuFH9uD$3빋{!v1A@1|$4bE11D$4P tHt$HT$Et DGHEuu tHOHDEtG<(tHfD1DUHSHH6^HSHhHHCH[]7_fAUATIUSHHHtvCL+uLH{ H{t<1fDHH;k s(HDHtHxH.H{H;k rQ-HLF-MuI\$Ht#H{H+$-HH-HuHL[]A\A]-fH{HL,M3렐AVAցAUIATL%USHtL%MC!DHLAԅA@u#ttRHkC/t&Hu1[]A\A]A^DEHHHLHt1Hq+AD$ H1[]A\A]A^A_fA@u'/H:-HtHHhI$HIAD$Ml$ I\$MtHE11Ht$E111HD/LIHHM9tSuHt$H;H|$6,HxZHDH1[]A\A]A^A_DAWAVAUIATIUSHHL}Ht {([H@h I$I$HLs HKH{I9IFHC KLHÉ[]ûf.fG%=tH=@}==`= tP==t^H51%H0uH51$H51$f.H51$fH5|1$fH51$fH5f1$fH5d1$fH5~1r$fHHtHU@AWAVAUIATIUSHH$IHLL)HHHt A|/A$D$tHVHtHRHHuH9HBHH9rfHHw1E1H9r?fHH9s-H9tHAIHHtH@HHuHH9r1L9GtH9W fAUATUHS1HHO LgLoH7HH9r@HH9s4H>tHFHtH@HHuH9HBHH9rH@H1!1LH8Ht!MxgfI*YMxzfI*^LHH*0!HHH[H]A\1A] !DLLfHH H*XY<MyLAfHL H*XpATIUHS}H0Ht"HH3H9t#HAT$8uH[Hu[1]A\@H+H[]A\f.H t5HHHOH9rD!HH9sHHtHf.1!UHSHHHHHtHHRH9uHu*HU @HHu HH9w1H[]fDHH[]fDHHH9WvaE1LMuHH9WwLL9vNLBIIMt$f.H9tMHLLM@MuI묐1ff.AWAVAUATUSHL7L9wvYIII1I>Hu"IM9wwHH[]A\A]A^A_fDLH[HHtH;LAԄu11҄t HHHH)1HHuHDf.H?GHHL??HGff.AWHIAVMAUIATIUHPSHHLDHHLD HHHx(MLx(AHHH=H<rXHuSHkHtJHHHt5HHCHHC HkLc0Lk8Ls@HCH@H1FHH[]A\A]A^A_@H9HC(0 PtHxJfH*^/7s/2rP\(H,H?fAOHyHfHH H*Xf.H,fDATUHSL'L;gr}f.IL9eviI<$tI\$HE@Ht.Ht H;HE@HSHMHHHKH]HHHuHtI<$I$IID$L9ew[HEHE ]A\ATIUSH@H/HGtZH tSH9rfDHH9v6H}HtH fH;AT$@H[HuID$HH9wI,$H9s4H}HtH_GHHuHI9l$wI|$HHtf.H_HHuI<$[L]A\f.ATUHSH`Lg(dH%(HD$X1A|$uEHtfH*A^D$///r\H,H?HhHHH=HҺHHHHH9]+H~H$HH\$H1HHHE0Ld$(ILH\$HD$0HE8HD$HD$8HE@HD$ HD$@HEHHD$HUÄHD$HLHHEH21LH~H<$| f.1HL$XdH3 %(H`[]A\HfHH H*Xwf.H,fDfH}H$HEHD$HEHD$HEHD$HEHD$HHEHXAUATUSHdH%(HD$1HHI1HHIsHHt+1MtIUHL$dH3 %(0H[]A\A]ÐHCHxwfHS(H*HCHfH*YB/H,$H}HCHH HPHSHHUL HPHEHC d@HƒfHH HCH*HS(XHyHfHH H*XYB/iH{(HS(HCRHfH*HCHxvfH*(Y/YB z/[LeHC HCHt@HfHH H*Xuf.HfHH H*X;fYa/s7H,HzI1HLHBH3B@\xH,H?SHHdH%(HD$1HHD$8H|$0*D$@T$DHD$8D$,>D$AH AH5H=H "H5H=H H5įH=kfDATHUH1SVHH9tHHtH[]A\HXHIMI|+IIؾIH1HLH KJH[]A\fAWAVAUATIUSHH1HH9H5HI_7LH|HtwIIE1FLHu/HD$MtYLHtJH|$t H|$MtLHH[]A\A]A^A_fLMtLHpuHHI I|*IIHI1HH HD$HtH'LWLH5H-LIHx I*LLHqHH5HIH//TRANSLIITHfAGAG HL$8-HL$HHH?HHtMHuLHMLH>Ll$LE1E1ELHMI9t?HLDLHMMuE1E1Lf.L HLHHD$E1L fE1E1L_DIIOLHBuIILl$LME1YILl$TfDH1unH3!HHnf.UHSHH2!Ht'HoHIH[H11]7oH2!fATIUH-2!SHHt.LILHHHnH[]A\fD3H-\2!f.UHSHH<2!HtHHHH[H]oH 2!f.ATUSHH?HteHE1HH}MdHuL&HHf HxH3HH;uH[]A\@[H=Ш]A\(ATUHSHt-IHZA HTHHuH[]A\Df.ATUHSHt-IHZA HTHHuH[]A\Df.AWHIIAVAUIATUSHLa0DyH$H $LL$ Ht$DD$CdH%(H$1MLDA A AE1t\H$D|$DH$H|$Ld$(H\$L<%LL)Hv6HtHILEL]uIMtMtADE1H$dH3%(LH[]A\A]A^A_fE DD;DL$C1E1DIAA<0tk<#u!f.<^uLA@<-t@0A vNEt9Ot4E1zPH5%HcH>@<_uA|@AKIDE1ACIsPA ,A;t GIF|GЃ vAy@7~ڃ wACAIPAIA9E@DEͺ %HD$LE1f$E1DHT$@H $H$HDT$XDD$PDL$HHD$0(HHHELAIHH9ILCL)L9HDD$PDL$HEuMH9sHIcDT$XHL$PH)L\$XL<A05H߾ DL$HLL\$XHL$PDL$HHt$0L\$HHHHL$0HEEHL$0L\$HHMfAO> E1 %f$ELHD$H$H|$L\$XH$DT$PL$o` oDL$HoPH@0)$)$)d$0)$H$,DL$HDT$P0HHH$L\$XHD$0@HgfffffffHHH?HH)HHHH)HH)Ѓ0HHIA$HuEAOljD$HH HD$0HHLL)L)A-tl$H)ͅEALEIMcL9MLCI9Hy|$HuHL9sCIcHL$PH)L\$HL<DL$0A0H߾ LHL$PL\$HDL$0L\$HHLHHL$0EAEIMcMLDLL)L9/HtEAIHcHHEH9LcILHu^HvXIcL\$pHLD$hH,HL$`DT$XDL$0A0+H߾ HL\$pLD$hHL$`DT$XDL$0D$PHL݈CHtIcDT$XL\$PL)DL$HL<A0@ H߾ LL\$PDL$HL\$HLHt$(H@ E fDMAHD$0ED$8Hl$(D$DIȾH1H`'rfLK8HC1LCH5>Lk0Lc(L{ LL$LsHH$LD$`HLL$HHH1AQAUATAWAVLL$0LD$8H0H([]A\A]A^A_LS@LK8H5HCLCLk0Lc(LT$L{ LsLL$H$HLD$1LT$ARgHH5s1H(HHH[1]A\A]A^A_LcH1H5=fH(MHH[H]1A\A]A^A_LkLc1HH5"H(MMHH[H]1A\A]A^A_yf1LsLkH5LcHHAVHMMHH1-XZH([]A\A]A^A_@L{ 1LsH5LkLcHrAWfDLCLc(1L{ LsH5L$LkH:HMATAWAVLD$ HHH1H H([]A\A]A^A_LKLk01Lc(L{ H5jLsLCLL$HL$AUATAWAVLL$(f.LS@LK8H5HCLCLk0Lc(LT$L{ LsLL$H$HLD$fE1I8tIK<uHhE1dH%(HD$X1I#AƒMPAIKHt/II t%A/vMPIBI@IKHuDM`HD$XdH3%(uHhfDUA S1HL$L$LD$ L$E1dH%(HD$x1H$D$ HD$H$HD$H)@DлAHHKHt%II tA/vLIHKHuftDT$HD$xdH3%(u Hĸ[]#SH5Ċ1HˊH1"H5Ɗ1H H^\H1H 1H5XH[H f.fSHHuHu[rfHHHHx HuPKf.f.SHHuHuHHuHu[f.;1[fHHHHx HuPf.IHHt1HTUUUUUUU1IH9v8HHHLHIHSHt#HIHxHtP_1ҸE1IIAI f.HHt,HSUUUUUUUH9w7HHHDHHHuHHyPSH3H1Hv[@HHHHxHuHtH~@f.UHHSHHHHHH[]UHSHHXHHHHH[]f.PXH5͊1H= HFX1H1j5DS HHtH[f8 uS&KÅx[@8 uifSMHHtH[f8 u1SOHHtH[f8 uHHt$(HT$0HL$8LD$@LL$Ht7)D$P)L$`)T$p)$)$)$)$)$dH%(HD$1H$H$HD$HD$ D$0HD$sQHT$dH3%(uHFfDAWIAVIAUAATL$USHH DHL9s@LHDH)L9IGH-Hta8u,Hv#AL9rHHL)[]A\A]A^A_HH[]A\A]A^A_f.IHtDHt6HH1HHu?H1HHHIL9w1HHL9HDHDH HEHHHAUIATIUSHHdH%(HD$1HHD$HDHHHvMu'HT$dH3%(Hu-H[]A\A]f1yuAEfHtHH=lH=YT@Ht#Sf.HHHu[fDAUATUHSH}H} HD u1wt#D#E1HD#HD[]A\A]@AATUSHtcIvHhHvHCHHHHt$HH{ HfCLFD+ H[]A\fHHt1HHfS[]A\fAWAVAUATUSHLf0MHIL9wHV8I9r}A<$H] }DLH}tQ;uLu I9}HH\;uHEHtHX LHH0u@I]0H[]A\A]A^A_H zH[]A\A]A^A_@L LxHL)HHL9s! 1@LLx1LHvw!LLHB;afLHEHt @HX :1@HZ@8HM L<@sH@8A4@uoHD$hD$pD$\HD$Ƅ$1H$PƄ$L$H$HD$HHDŽ$L$Ƅ$HDŽ$Ƅ$HD$HD$(D$HD$0@H$$IH$ ADHDŽ$Ƅ$$Ƅ$D$ENH|$ "D$Ht$HH9D$H|$pD$t9$fo$LEfo$Ƅ$Pfo$HE)$ H$(fo$H$ HD$)$H$`)$0)$@Ƅ$Ƅ$\ADHDŽ$h$tƄ$pƄ$\$tkH$hƄ$\HH$`$H$` AD>HDŽ$hƄ$p$t$tƄ$\$$H$  ADHDŽ$(Ƅ$0$4Ƅ$$4F$p49$tHS4H$(H$ HH$hH$`Ƅ$Ƅ$\$P茫L$`HL9HMH}$LHvH$hHHHu,H$`HDŽ$h8Q $t*H}Ƅ$p訯tƄ$P$tƄ$\|H$CHDŽ$(Ƅ$0Ƅ$H$(H;$hH$H$Ƅ$HD$ I~l Ƅ$ZL$ HLINI~$LHDH$(HRHHu,H$ HDŽ$(8 $4I~Ƅ$0vtƄ$$4Ƅ$1f$0DH$`H$ fH}TƄ$PfHDŽ$Ƅ$Ƅ$H|$ "D$Ht$HH9D$HH$H;L$hNHt$`H$HHL$ JHL$ 'HDŽ$hƄ$pƄ$\&H$H$ImƄ$[L$HLLD$ LD$ IOI$HL;H$HHHu,H$HDŽ$8$LƄ$HjtƄ$Ƅ$H$`賧Ƅ$pH$hƄ$\fDH$ 胧Ƅ$0H$(Ƅ$fDHvH@HH+t$($It2$u~H$H$LHƄ$I$H$ AD9HDŽ$Ƅ$$Ƅ$D$Eq$HT$0Ht$LD$$H$HD$.L$HLLD$ Ht$LD$ HHNH~$L H$HHHu.H$HDŽ$8D$EH|$Ƅ$H4tƄ$Ƅ$H$H$HD$[Ƅ$fHDŽ$Ƅ$H$#Ƅ$H$fDH$Ƅ$H$Ƅ$fD$=H$ ADHDŽ$Ƅ$$Ƅ$D$ED$$HCH\$(HÄoDLLD$8˨(Ƅ$PL$`HLLL$ LD$8LL$ H}$HLLH$hHH'Hu,H$`HDŽ$h8$tH}Ƅ$p$tƄ$PƄ$\xH]D$PNLt$`HLH{$HLHƄ$H$茡Ƅ$H$Ƅ$HD$HH|$`[D$pHD$hD$\CHDŽ$Ƅ$Ƅ$F$H D]H5SH=S謡H ]H5RH=R舡UHSH߀UuMP߀Tu^P߀FuRx-uLx8uFxu@}`H\H\HEH[]fDGuP߀Bu x1ux8t# H\HmRHEH[]x0u׀x3uрx0uˀxuŀ}`HN\HK\HEH[]AWAVIAUATIUHSDHH$HT$DD$ HD$ H$D$HD$hH$HD$`dH%(H$1bD\$ HD$XD$CA ҤH \DHcH>D$AE1Ƅ$HD$PD$CD$BH[QE1AHD$HD$HE1DEILAI9AIu HD$<(AEAH|$"D$BL /D$ HD$H1H\Iu-Hv'DT$8DD$0LL$(tDT$8DD$0LL$(IL9HT$Ht$HLDT$DL\$8DD$0LL$(袟LL$(DD$0L\$8DT$D|$CA~H ZHcH>fD$ IIu HD$xAH|$Ct T$BFHt$ Htډҋu |$ 5A€|$CkD t/M9vC>'IWI9vCD>$IWI9vCD>'IAM9sC>\IHM9sC>|$AIED@|$AfD$ AAA?E1 D$ A1D$1'DD$ \$C\$Bt H|$q\\f|$BE11|$C|$ HD!CD$ 1E1qfrE1A€|$C@ D$BLEӀ|$BDEHEHt$hLLt$xjD$HT$0AH IH$dH3%(L7H[]A\A]A^A_DfA|$CiE1/n;fDD$ t@b붐af|$C D$ ADƒ M9vC>'IOI9vCD>$IOI9vCD>'IOI9@A\ALyAq HE0L9sHD$D(D$(0<  D$BDAD$ H|$XwDT$8L\$0DD$(3DD$(L\$0HDT$8Pf%@A"T$B*AIA~wH XHcH> rA"T$CT$ QLA v1 f! n@ t@ba|$B%D$ 1$HA|$C~ HDE1\@M9vC>'IGI9vCD>'IE1AE1fA A@A~H HYHcH>1Dl$ D$ 1D1HDl$ D$ 1t@1 AELMu T$Ce D$C u $i |$A MH|$P  Ld$PA'HIAAH\$HHD$D$C$`|$CMP1H|$PBLd$PI1E1D$IԻ'$tHEL9sH\$|+?D1E1?I|$ChE11?\fDH$HDŽ$HD$pIu,H|$DT$8DD$0LL$(舖DT$8DD$0LL$(I1H$$Lt$xHLt$pHD$8D$Hl$0L$L$L$L\$(DT$D+$ĚLDDH莚hHD$0HT$(LH|$8L<HD$L)N$8LHH2HHV|$Du|$CzHpH|$H4/JD?LDHH9K[!wH+HHtLt$xL$AHl$(V@D$ E11f.LM9fDVM9vC>'IGI9vCD>\IGI9LCD>'Ld$PT$BE1HDl$(1Dl$CH|$ LL$fAEDƃ@ t/M9vC>'IwI9vCD>$IwI9vCD>'IAM9vC>\IGI9v 0CD>IGI9v0CD>HI0H9VM9vC>A)IJD!@tM9vC>\IHH9s,M9vC>'IGI9vCD>'I1E1Dl$(L݈D$BEvkIAE10D$BMHxED$AE1AHD$PAƄ$D$CHD$HD$HCMA"E1D$AƄ$HD$PHOD$CAD$BHD$HD$HA tjH5N1D\$ RD\$ HHD$hHNH9rH5D1D\$ D\$ HHD$`H|DH9!E1JH\$`D\$ E1HH\$HD\$ HD$D$AƄ$HD$PD$BH-ND$AE1E1Ƅ$AHD$PD$CD$BHD$HD$HD$AE1E1Ƅ$HD$PD$CD$BHD$HD$H]D$AE1E1Ƅ$HD$PD$CD$BHD$HD$H D$AE1Ƅ$HD$PD$CD$BD$ D$ D$ M9vC>0HAI9vAD0Ly0KqD$B]fDl$(1HDHl$0Lt$x$L\$(D$L$L$DT$D"T$BHHHD$PE1D$AƄ$UD0E1>HpH|$CM9vC>?IWI9vCD>"IWI9vCD>"IWI9vCD>?I1E1H2HHl$0Lt$xE1D$$L$L$L\$(DT$DT$B L\$(LLHHHl$0D$$L$L$Lt$xL$DT$DL9s >u A<tHHTI9wHT$BE1HT$hM9vC>IB:uHJD$AE1E1Ƅ$HD$PD$CD$BHD$HD$HlLELEHD$HHt)t%tLL)I9vA H uIM9C>~H|$`DBD\$ HD$`H|$hD&D\$ HD$hrALED$B$aHAHLt$ht$xt$8D$HT$0Ht$pH IAE1D$A1HD$PLLd$P E[Hw?D$AE1E1Ƅ$HD$PD$CD$BHD$HD$Hf.AWLcAVIAUATUHSH(Ht$oH IŋD$E7D9=ע bAQEgHբ IcHH9HmH HHc= D1)HHcHH2D%s EIHDELL}LLLcD$$Au0LLu(AWHT$(L\$0$H L\$I9wgHpH{ H3I9tLHt$6Ht$HHt$THDELHCHIu0u(AWDL$HH1HÐHt JtDHHHHHHHHH)HH: H HtH9u6f.H9tHHAHuDHHGHHxH f.@AVAUATUSHHPdH%(HD$H1yHw2HyHHt$HdH34%(HHP[]A\A]A^HH\$L%Q/1$LmHD$D$ ^HT$ AHD$D$ D$$D$ D$$eHD$HD$HD$ <$tyLt$HL辚HMH}$LHHD$HthHtzHu#HD$HD$8T$$H}D$ D}t$D$ ZfL(}t=$hHD$D$ 9DH|$fxD$ HD$H p;H5Q*H=T*xSxH L;H5-*H=G*xH -;H5*H=?*xDAWIAVIAUAATL%4| UH-4| SL)HgnHt1LLDAHH9uH[]A\A]A^A_Ðf.HHFiles %s and %s differ No newline at end of fileBinary files %s and %s differ 8|-!ԩ%ld,%ld%ld,0%s %s %ld.%.9d%s %s %s !****************** ****--- ----@@ - + @@+++%s: %sOnly in %s: %s diff.cparentno_dereference_symlinksstandard outputwrite failed%Y-%m-%d %H:%M:%S.%N %z%a %b %e %T %Y%<%>/usr/share/localeinvalid context length '%s'-Dtoo many file label options^[[:alpha:]$_]-SLen TowerRichard StallmanDavid HayesMike HaertelPaul EggertGNU diffutilsdiffinvalid width '%s'conflicting width options--from-fileUsage: %s [OPTION]... FILES Compare FILES line by line.%s %.*s %s invalid horizon length '%s'--line-formatinvalid tabsize '%s'conflicting tabsize options--to-fileautoneverinvalid color '%s'TERMdumb%l %=missing operand after '%s'extra operand '%s'binarybriefcolorcontextexcludeexclude-fromexpand-tabsforward-edhelphorizon-linesifdefignore-all-spaceignore-blank-linesignore-caseignore-matching-linesignore-space-changeignore-tab-expansionignore-trailing-spaceinhibit-hunk-mergeinitial-tablabelleft-columnminimalnew-group-formatnew-line-formatno-dereferenceno-ignore-file-name-casenormalold-group-formatold-line-formatpaginatepalettercsrecursivereport-identical-filessdiff-merge-assistshow-c-functionshow-function-lineside-by-sidespeed-large-filesstarting-filestrip-trailing-crsuppress-blank-emptysuppress-common-linestabsizeunchanged-group-formatunchanged-line-formatunidirectional-new-fileunifiedversionwidth-presume-output-ttyTry '%s --help' for more information.conflicting %s option value '%s'conflicting output style optionscannot compare '-' to a directory-D option not supported with directoriesCommon subdirectories: %s and %s File %s is a %s while file %s is a %s Symbolic links %s and %s differ Files %s and %s are identical --normal output a normal diff (the default)pagination not supported on this hostMandatory arguments to long options are mandatory for short options too. --from-file and --to-file both specified-q, --brief report only when files differ-s, --report-identical-files report when two files are the same-c, -C NUM, --context[=NUM] output NUM (default 3) lines of copied context-u, -U NUM, --unified[=NUM] output NUM (default 3) lines of unified context-e, --ed output an ed script-n, --rcs output an RCS format diff-y, --side-by-side output in two columns-W, --width=NUM output at most NUM (default 130) print columns --left-column output only the left column of common lines --suppress-common-lines do not output common lines-p, --show-c-function show which C function each change is in-F, --show-function-line=RE show the most recent line matching RE --label LABEL use LABEL instead of file name and timestamp (can be repeated)-t, --expand-tabs expand tabs to spaces in output-T, --initial-tab make tabs line up by prepending a tab --tabsize=NUM tab stops every NUM (default 8) print columns --suppress-blank-empty suppress space or tab before empty output lines-l, --paginate pass output through 'pr' to paginate it-r, --recursive recursively compare any subdirectories found --no-dereference don't follow symbolic links-N, --new-file treat absent files as empty --unidirectional-new-file treat absent first files as empty --ignore-file-name-case ignore case when comparing file names --no-ignore-file-name-case consider case when comparing file names-x, --exclude=PAT exclude files that match PAT-X, --exclude-from=FILE exclude files that match any pattern in FILE-S, --starting-file=FILE start with FILE when comparing directories --from-file=FILE1 compare FILE1 to all operands; FILE1 can be a directory --to-file=FILE2 compare all operands to FILE2; FILE2 can be a directory-i, --ignore-case ignore case differences in file contents-E, --ignore-tab-expansion ignore changes due to tab expansion-Z, --ignore-trailing-space ignore white space at line end-b, --ignore-space-change ignore changes in the amount of white space-w, --ignore-all-space ignore all white space-B, --ignore-blank-lines ignore changes where lines are all blank-I, --ignore-matching-lines=RE ignore changes where all lines match RE-a, --text treat all files as text --strip-trailing-cr strip trailing carriage return on input-D, --ifdef=NAME output merged file with '#ifdef NAME' diffs --GTYPE-group-format=GFMT format GTYPE input groups with GFMT --line-format=LFMT format all input lines with LFMT --LTYPE-line-format=LFMT format LTYPE input lines with LFMT These format options provide fine-grained control over the output of diff, generalizing -D/--ifdef. LTYPE is 'old', 'new', or 'unchanged'. GTYPE is LTYPE or 'changed'. GFMT (only) may contain: %< lines from FILE1 %> lines from FILE2 %= lines common to FILE1 and FILE2 %[-][WIDTH][.[PREC]]{doxX}LETTER printf-style spec for LETTER LETTERs are as follows for new group, lower case for old group: F first line number L last line number N number of lines = L-F+1 E F-1 M L+1 %(A=B?T:E) if A equals B then T else E LFMT (only) may contain: %L contents of line %l contents of line, excluding any trailing newline %[-][WIDTH][.[PREC]]{doxX}n printf-style spec for input line number Both GFMT and LFMT may contain: %% % %c'C' the single character C %c'\OOO' the character with octal code OOO C the character C (other characters represent themselves)-d, --minimal try hard to find a smaller set of changes --horizon-lines=NUM keep NUM lines of the common prefix and suffix --speed-large-files assume large files and many scattered small changes --color[=WHEN] colorize the output; WHEN can be 'never', 'always', or 'auto' (the default) --palette=PALETTE the colors to use when --color is active; PALETTE is a colon-separated list of terminfo capabilities --help display this help and exit-v, --version output version information and exitFILES are 'FILE1 FILE2' or 'DIR1 DIR2' or 'DIR FILE' or 'FILE DIR'.If --from-file or --to-file is given, there are no restrictions on FILE(s).If a FILE is '-', read standard input.Exit status is 0 if inputs are the same, 1 if different, 2 if trouble.,bqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq$l$l$l$l$l$l$l$l$l$lqqqqqqqqlkjjjqzj_jqq-jqjqjqqiikqiaqriqqqqqqciDiiihhq,bhqqwhqNhq.hhheeeddddqqqqqq,bgNffe,bedccZc1ccbxciccbbbb4b4b4b4bgtdhcompare_files%%=%c#ifndef %s %%<#endif /* ! %s */ %c#ifdef %s %%>#endif /* %s */ %c#ifndef %s %%<#else /* %s */ %%>#endif /* %s */ --unchanged-line-format--old-line-format--new-line-format--unchanged-group-format--old-group-format--new-group-format--changed-group-format0123456789abBcC:dD:eEfF:hHiI:lL:nNpPqrsS:tTuU:vwW:x:X:yZ%s: recursive directory loopa .. . s/.// d%ld %ld a%ld %ld Ļܻ ػhtttttttttttttttttttttT<=?io.cmblength != (size_t)-1 && mblength != (size_t)-2find_and_hash_each_line  ''9# )-W 97s;Q/o!7 7]9--- xQ%%i%ld,%ld c%ld,%ld  00000000000000000000000000000000000000000000000000000000000000000000000000000r777777777777777777777777777777777777777777777777777777777777777777777777777777777777777x77777770777 777b44Dt dac/usr/bin/prlcunrecognized prefix: %sdiff%s %s %s-hpipeforkdup2fdopenwaitpid%s %s \ %s %ld%c%ld%s%s%srcecrshdadlnnparsable value for --palettesubsidiary program '%s' failed (exit status %d)subsidiary program '%s' could not be invokedsubsidiary program '%s' failedsubsidiary program '%s' not found%3ld %3ld delete %ld insert %ld 3.6: program errorstack overflowmbuiter.hmbsinit (&iter->state)*iter->cur.ptr == '\0'iter->cur.wc == 0mbuiter_multi_nextregular empty fileregular filedirectorysymbolic linkblock special filecharacter special filefifosocketweird fileCPOSIX# entries: %lu # buckets: %lu max bucket length: %lu # buckets used: %lu (%.2f%%) ?L??=fff?̌??L?__Y@mbuiter_multi_nextA NULL argv[0] was passed through an exec system call. /.libs/lt-%s (%s)UTF-8mbuiter_multi_next%H:%M:%S%m/%d/%y%H:%M%Y-%m-%d`$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$cZb$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$c$cMd$c$c$c$c$c$cTTa]$c]][_y_$c$c$c__$c_$cMYQZxdnZ]`UZ\$c$c$c$c$c$cTcUecc$c]c$cXY=Y a9a$cpdbU VW1X$cXUacmbiter.hmbiter_multi_next%s (%s) %s (C)Written by %s. Written by %s and %s. Written by %s, %s, and %s. Report bugs to: %s bug-diffutils@gnu.org%s home page: <%s> License GPLv3+: GNU GPL version 3 or later . This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Written by %s, %s, %s, and %s. Written by %s, %s, %s, %s, and %s. Written by %s, %s, %s, %s, %s, and %s. Written by %s, %s, %s, %s, %s, %s, and %s. Written by %s, %s, %s, %s, %s, %s, %s, and %s. Written by %s, %s, %s, %s, %s, %s, %s, %s, and %s. Written by %s, %s, %s, %s, %s, %s, %s, %s, %s, and others. http://www.gnu.org/software/diffutils/General help using GNU software: IxnnnHooo8pm nCopyright %s %d Free Software Foundation, Inc.memory exhaustedTZASCII/usr/lib64CHARSETALIASDIR%50s %50smbuiter_multi_next"’e‘`literalshellshell-alwaysshell-escapeshell-escape-alwaysc-maybeclocaleұ|ޯ8O٧ħ i 9 ))اŦŦŦŦŦŦȧxHŦŦŦŦŦŦŦŦŦŦŦŦŦŦŦŦŦŦx````m```````=Ŧ```-`- ĤĤĤĤĤĤܣ̣ ĤĤĤĤĤĤĤĤĤĤĤĤĤĤĤĤĤĤ̦l̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦<Ĥ̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦̦,, mbuiter_multi_next;3: B B B$B| Bt"%B@$*B$/B&4B*9B0>B1CB 2HB2MBl3RB5WB5\Bt6aB7lB UV `P `| |p q( qD rp |s |t ,uL y  |$ ́t l ̃8 T L`Ld l\Dp<\|\,,ܫLxܬ(t PL4Th|L8L`L| 8FBB B(D0A8D 8A0A(B BBBK !;FBB B(D0D8G`hWpBxBBBS`D 8A0A(B BBBD P hH Z 8O0C(B BBBL ^ 8J0I(D BBBE b 8M0I(D BBBN fhBp\hA`D 8A0A(B BBBE h hH rhEpBxB^`D 8A0A(B BBBA y hBpBxBQ zRx `(`P"T> d"`>Hp| A (">EGI AAA "?Ew"?ES A "?%`"@ #@>E` K H A 4#0@%`H#L@\L`#@XSx# AEV#A2Ka A $#4A-EGG WAA(#DQ^xrWz x1 X0?"8?"op@ 6 L" &0 ooooo J"1111122 202@2P2`2p22222222233 303@3P3`3p33333333344 404@4P4`4p44444444455 505@5P5`5p55555555566 606@6P6`6p66666666677 707@7P7`7p77777777788 808@8P8`8p8888888 %T"Q"`t" GA$3h878SS GA$3c878@@ GA$3s878j@j@ GA$3e878j@j@GA$3a1SSGA$3a1SS GA$3p878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realignGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realignGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realignGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realignGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realignGA$3a1SSGA$3a1x11GA$3a1X`GA$3a1ST GA$3p878TunGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878nGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878j@SGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA* p@SGA!stack_realignGA*GA+stack_clashGA*cf_protectionGA+omit_frame_pointerGA* GA*GOW*EGA! GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3p878oGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878pwGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878ީGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878 GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p8784GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p87844GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878@.GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p8780LGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878P1GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878@LGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878PGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878 GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878 |+GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878@3@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878+.,GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8783@3@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p8780,;3GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8783@3@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878@33GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8783@3@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p8783 AGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8783@8@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878ABGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8788@8@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878Bz\GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8788@8@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878\\GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8788@8@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878\.cGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8788@8@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p8780cTiGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c8788@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878TiTiGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878`ikGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878k+lGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p8780l_lGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878`llGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878lmGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878mnGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878n^oGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878`o uGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@=@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878u_uGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878=@B@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878`uuGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878B@B@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878uwGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878B@B@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878wc}GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878B@B@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878p}GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878B@L@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878L@e@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878e@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3p878UGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA*FORTIFYGA+GLIBCXX_ASSERTIONS GA$3h878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3c878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3s878SSGA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realign GA$3e878j@j@GA$gcc 8.3.1 20191121 GA*GOW*EGA*GA+stack_clashGA*cf_protection GA*FORTIFYGA+GLIBCXX_ASSERTIONSGA*GA!GA+omit_frame_pointer GA* GA!stack_realignGA$3a1UUGA$3a1UUGA$3a111GA$3a1`ediff-3.6-6.el8.x86_64.debug7zXZִF!t/8g]?Eh=ڊ2Nv ]oة8#,ܣ?Sexn" E\^{6-alx. 2т3|k;mE}1IMe5T6|0>wsd70U"7ވY;nlke]oW4YbxUƼ&*yƴlpPjxr]>;0k~ 3_g܂/ UbzQrdKtBMj D[LFcw8"1mOx ,6if?^E`ȻsJ 5/#Ex']gRf"A;|'NeV?G6߿mb ݸiO !) w!#jD:-F2k"m̾xn۸ P6ȿ{خ~ pLA'm|/Qu֜ 곁Z Y[LTPv21y5 wѪYw^HK,53 7 tLN*hٚ2R( }˝m>T~x.Y~;ŖJ喴1vo6de!quq_XDMI̥療.+* o[uT| vAIJW圞r)j`$ަIԹ$yd \덈:ߵZnI qc6gBA JhG̯;vu79.Q?P ĊmWm$?KCjE)\J#dx`vTugE֞8?C8jH9Q*`H4h'}]%TY<"6[~цt`1iA*;;ێl}Q&pJc,RGx&95@K nX3(gtD,f$ Bu%m_̛YThG۷{~"ʅkv̩1{-~;d1׉TqR^~i9-ح \7Ӯ4퉄3{[A`D}pcP ^||*7'# hr* [T%'%{ɣ[)hGu:,):сҠrs+-#8֋5nپL q6S;lk;cZtPs8BU~;25;d{7sU{-oA4ї۵N>_b/RPWQ)"L6ڏ(E~8Y; Ĕxoa֢fEKzm߭4XX6q0Qš vy{gj7y|ª̇핣zfR9WZ/z[[&BڑXmG%6ۥxOaT` ɢl~Ojd D5kO"ݎD|3 lCӊ0%H 3e='! ydo_d^_IȞ~7hӒÃA_v1CGQxg8X)%i7~dLP^o&l~\n"'Ne}~F{zRjyӘ pw+g_//dZ`ĩ+: +Q wӬ/w1'5]kT8KżeUJ@YGd7"^_?7shSsW %~`ZNfIT#.JgѼ̚v=a2Q̗}[aĭnNႱwV5p#z 󢦔8P{KHڤJ4!SoφXi+c|"H!p˩,]. sZJͱ-Z% Jf& DNcQ|M xhѿ׻2!o\p 4c}!J9+m\CO5Quҍ:xmRIg#DuP9~vP8Ã'YzRg8pe$ZGK0AҼ"9{j6~.<j騒l}F%BGL,w/ЎJn;mU>w9wT{B#s52Aj|OS )epjIgYZ.shstrtab.interp.note.gnu.property.note.ABI-tag.note.gnu.build-id.gnu.hash.dynsym.dynstr.gnu.version.gnu.version_r.rela.dyn.rela.plt.init.plt.sec.text.fini.rodata.eh_frame_hdr.eh_frame.init_array.fini_array.data.rel.ro.dynamic.got.data.bss.gnu.build.attributes.gnu_debuglink.gnu_debugdata pp & 4$GoHQ @@0 Ypp6aono}00B&& x1x111@880@@EXX : 10?"0?8?"8?@?"@?  J" JL"LP"P   Q" Q0 b Q  /('>initsid.py000064400000004757152534333500006601 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper modified_initsids_record = namedtuple("modified_initsid", ["added_context", "removed_context"]) class InitialSIDsDifference(Difference): """Determine the difference in initsids between two policies.""" added_initialsids = DiffResultDescriptor("diff_initialsids") removed_initialsids = DiffResultDescriptor("diff_initialsids") modified_initialsids = DiffResultDescriptor("diff_initialsids") def diff_initialsids(self): """Generate the difference in initial SIDs between the policies.""" self.log.info("Generating initial SID differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_initialsids, self.removed_initialsids, matched_initialsids = self._set_diff( (SymbolWrapper(i) for i in self.left_policy.initialsids()), (SymbolWrapper(i) for i in self.right_policy.initialsids())) self.modified_initialsids = dict() for left_initialsid, right_initialsid in matched_initialsids: # Criteria for modified initialsids # 1. change to context if ContextWrapper(left_initialsid.context) != ContextWrapper(right_initialsid.context): self.modified_initialsids[left_initialsid] = modified_initsids_record( right_initialsid.context, left_initialsid.context) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting initialsid differences") self.added_initialsids = None self.removed_initialsids = None self.modified_initialsids = None bool.py000064400000005522152534333500006060 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper modified_bool_record = namedtuple("modified_boolean", ["added_state", "removed_state"]) _bool_cache = defaultdict(dict) def boolean_wrapper(policy, boolean): """ Wrap booleans from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _bool_cache[policy][boolean] except KeyError: b = SymbolWrapper(boolean) _bool_cache[policy][boolean] = b return b class BooleansDifference(Difference): """Determine the difference in type attributes between two policies.""" added_booleans = DiffResultDescriptor("diff_booleans") removed_booleans = DiffResultDescriptor("diff_booleans") modified_booleans = DiffResultDescriptor("diff_booleans") def diff_booleans(self): """Generate the difference in type attributes between the policies.""" self.log.info("Generating Boolean differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_booleans, self.removed_booleans, matched_booleans = \ self._set_diff( (SymbolWrapper(b) for b in self.left_policy.bools()), (SymbolWrapper(b) for b in self.right_policy.bools())) self.modified_booleans = dict() for left_boolean, right_boolean in matched_booleans: # Criteria for modified booleans # 1. change to default state if left_boolean.state != right_boolean.state: self.modified_booleans[left_boolean] = modified_bool_record(right_boolean.state, left_boolean.state) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting Boolean differences") self.added_booleans = None self.removed_booleans = None self.modified_booleans = None typeattr.py000064400000006432152534333500007002 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper modified_typeattr_record = namedtuple("modified_typeattr", ["added_types", "removed_types", "matched_types"]) _typeattr_cache = defaultdict(dict) def typeattr_wrapper_factory(attr): """ Wrap type attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _typeattr_cache[attr.policy][attr] except KeyError: a = SymbolWrapper(attr) _typeattr_cache[attr.policy][attr] = a return a class TypeAttributesDifference(Difference): """Determine the difference in type attributes between two policies.""" added_type_attributes = DiffResultDescriptor("diff_type_attributes") removed_type_attributes = DiffResultDescriptor("diff_type_attributes") modified_type_attributes = DiffResultDescriptor("diff_type_attributes") def diff_type_attributes(self): """Generate the difference in type attributes between the policies.""" self.log.info( "Generating type attribute differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_type_attributes, self.removed_type_attributes, matched_attributes = \ self._set_diff( (SymbolWrapper(r) for r in self.left_policy.typeattributes()), (SymbolWrapper(r) for r in self.right_policy.typeattributes())) self.modified_type_attributes = dict() for left_attribute, right_attribute in matched_attributes: # Criteria for modified attributes # 1. change to type set added_types, removed_types, matched_types = self._set_diff( (SymbolWrapper(t) for t in left_attribute.expand()), (SymbolWrapper(t) for t in right_attribute.expand())) if added_types or removed_types: self.modified_type_attributes[left_attribute] = modified_typeattr_record( added_types, removed_types, matched_types) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting type attribute differences") self.added_type_attributes = None self.removed_type_attributes = None self.modified_type_attributes = None users.py000064400000012634152534333500006270 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from ..exception import MLSDisabled from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper from .mls import LevelWrapper, RangeWrapper from .roles import role_wrapper_factory modified_users_record = namedtuple("modified_user", ["added_roles", "removed_roles", "matched_roles", "added_level", "removed_level", "added_range", "removed_range"]) _users_cache = defaultdict(dict) def user_wrapper_factory(user): """ Wrap users from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _users_cache[user.policy][user] except KeyError: r = SymbolWrapper(user) _users_cache[user.policy][user] = r return r class UsersDifference(Difference): """Determine the difference in users between two policies.""" added_users = DiffResultDescriptor("diff_users") removed_users = DiffResultDescriptor("diff_users") modified_users = DiffResultDescriptor("diff_users") def diff_users(self): """Generate the difference in users between the policies.""" self.log.info( "Generating user differences from {0.left_policy} to {0.right_policy}".format(self)) self.added_users, self.removed_users, matched_users = self._set_diff( (user_wrapper_factory(r) for r in self.left_policy.users()), (user_wrapper_factory(r) for r in self.right_policy.users())) self.modified_users = dict() for left_user, right_user in matched_users: # Criteria for modified users # 1. change to role set, or # 2. change to default level, or # 3. change to range added_roles, removed_roles, matched_roles = self._set_diff( (role_wrapper_factory(r) for r in left_user.roles), (role_wrapper_factory(r) for r in right_user.roles)) # keep wrapped and unwrapped MLS objects here so there # are not several nested try blocks try: left_level_wrap = LevelWrapper(left_user.mls_level) left_range_wrap = RangeWrapper(left_user.mls_range) left_level = left_user.mls_level left_range = left_user.mls_range except MLSDisabled: left_level_wrap = None left_range_wrap = None left_level = "None (MLS Disabled)" left_range = "None (MLS Disabled)" try: right_level_wrap = LevelWrapper(right_user.mls_level) right_range_wrap = RangeWrapper(right_user.mls_range) right_level = right_user.mls_level right_range = right_user.mls_range except MLSDisabled: right_level_wrap = None right_range_wrap = None right_level = "None (MLS Disabled)" right_range = "None (MLS Disabled)" if left_level_wrap != right_level_wrap: added_level = right_level removed_level = left_level else: added_level = None removed_level = None if left_range_wrap != right_range_wrap: added_range = right_range removed_range = left_range else: added_range = None removed_range = None if added_roles or removed_roles or removed_level or removed_range: self.modified_users[left_user] = modified_users_record(added_roles, removed_roles, matched_roles, added_level, removed_level, added_range, removed_range) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting user differences") self.added_users = None self.removed_users = None self.modified_users = None ibendportcon.py000064400000006441152534333500007614 0ustar00# Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper modified_ibendportcon_record = namedtuple("modified_ibendportcon", ["rule", "added_context", "removed_context"]) class IbendportconsDifference(Difference): """Determine the difference in ibendportcons between two policies.""" added_ibendportcons = DiffResultDescriptor("diff_ibendportcons") removed_ibendportcons = DiffResultDescriptor("diff_ibendportcons") modified_ibendportcons = DiffResultDescriptor("diff_ibendportcons") def diff_ibendportcons(self): """Generate the difference in ibendportcons between the policies.""" self.log.info( "Generating ibendportcon differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_ibendportcons, self.removed_ibendportcons, matched_ibendportcons = \ self._set_diff( (IbendportconWrapper(n) for n in self.left_policy.ibendportcons()), (IbendportconWrapper(n) for n in self.right_policy.ibendportcons())) self.modified_ibendportcons = [] for left_ibep, right_ibep in matched_ibendportcons: # Criteria for modified ibendportcons # 1. change to context if ContextWrapper(left_ibep.context) != ContextWrapper(right_ibep.context): self.modified_ibendportcons.append( modified_ibendportcon_record(left_ibep, right_ibep.context, left_ibep.context)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting ibendportcon differences") self.added_ibendportcons = None self.removed_ibendportcons = None self.modified_ibendportcons = None class IbendportconWrapper(Wrapper): """Wrap ibendportcon statements for diff purposes.""" __slots__ = ("name", "port") def __init__(self, ocon): self.origin = ocon self.name = ocon.name self.port = ocon.port self.key = hash(ocon) def __hash__(self): return self.key def __lt__(self, other): return self.origin < other.origin def __eq__(self, other): return self.name == other.name and \ self.port == other.port properties.py000064400000004525152534333500007323 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference modified_properties_record = namedtuple("modified_property", ["property", "added", "removed"]) class PropertiesDifference(Difference): """ Determine the difference in policy properties (unknown permissions, MLS, etc.) between two policies. """ modified_properties = DiffResultDescriptor("diff_properties") def diff_properties(self): self.modified_properties = [] if self.left_policy.handle_unknown != self.right_policy.handle_unknown: self.modified_properties.append( modified_properties_record("handle_unknown", self.right_policy.handle_unknown, self.left_policy.handle_unknown)) if self.left_policy.mls != self.right_policy.mls: self.modified_properties.append( modified_properties_record("MLS", self.right_policy.mls, self.left_policy.mls)) if self.left_policy.version != self.right_policy.version: self.modified_properties.append( modified_properties_record("version", self.right_policy.version, self.left_policy.version)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting property differences") self.modified_properties = None genfscon.py000064400000006400152534333500006723 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper modified_genfs_record = namedtuple("modified_genfs", ["rule", "added_context", "removed_context"]) class GenfsconsDifference(Difference): """Determine the difference in genfscon rules between two policies.""" added_genfscons = DiffResultDescriptor("diff_genfscons") removed_genfscons = DiffResultDescriptor("diff_genfscons") modified_genfscons = DiffResultDescriptor("diff_genfscons") def diff_genfscons(self): """Generate the difference in genfscon rules between the policies.""" self.log.info( "Generating genfscon differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_genfscons, self.removed_genfscons, matched = self._set_diff( (GenfsconWrapper(fs) for fs in self.left_policy.genfscons()), (GenfsconWrapper(fs) for fs in self.right_policy.genfscons())) self.modified_genfscons = [] for left_rule, right_rule in matched: # Criteria for modified rules # 1. change to context if ContextWrapper(left_rule.context) != ContextWrapper(right_rule.context): self.modified_genfscons.append(modified_genfs_record(left_rule, right_rule.context, left_rule.context)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting genfscon rule differences") self.added_genfscons = None self.removed_genfscons = None self.modified_genfscons = None class GenfsconWrapper(Wrapper): """Wrap genfscon rules to allow set operations.""" __slots__ = ("fs", "path", "filetype", "context") def __init__(self, rule): self.origin = rule self.fs = rule.fs self.path = rule.path self.filetype = rule.filetype self.context = ContextWrapper(rule.context) self.key = hash(rule) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): return self.fs == other.fs and \ self.path == other.path and \ self.filetype == other.filetype constraints.py000064400000021213152534333500007467 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from ..policyrep import ConstraintRuletype from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper, Wrapper from .objclass import class_wrapper_factory from .types import type_wrapper_factory class ConstraintsDifference(Difference): """ Determine the difference in constraints between two policies. Since the compiler does not union constraints, there may be multiple constraints with the same ruletype, object class, and permission set, so constraints can only be added or removed, not modified. The constraint expressions are compared only on a basic level. Expressions that are logically equivalent but are structurally different, for example, by associativity, will be considered different. Type and role attributes are also not expanded, so if there are changes to attribute members, it will not be reflected as a difference. """ added_constrains = DiffResultDescriptor("diff_constrains") removed_constrains = DiffResultDescriptor("diff_constrains") added_mlsconstrains = DiffResultDescriptor("diff_mlsconstrains") removed_mlsconstrains = DiffResultDescriptor("diff_mlsconstrains") added_validatetrans = DiffResultDescriptor("diff_validatetrans") removed_validatetrans = DiffResultDescriptor("diff_validatetrans") added_mlsvalidatetrans = DiffResultDescriptor("diff_mlsvalidatetrans") removed_mlsvalidatetrans = DiffResultDescriptor("diff_mlsvalidatetrans") # Lists of rules for each policy _left_constrains = None _right_constrains = None _left_mlsconstrains = None _right_mlsconstrains = None _left_validatetrans = None _right_validatetrans = None _left_mlsvalidatetrans = None _right_mlsvalidatetrans = None def diff_constrains(self): """Generate the difference in constraint rules between the policies.""" self.log.info("Generating constraint differences from {0.left_policy} to {0.right_policy}". format(self)) if self._left_constrains is None or self._right_constrains is None: self._create_constrain_lists() self.added_constrains, self.removed_constrains, _ = self._set_diff( (ConstraintWrapper(c) for c in self._left_constrains), (ConstraintWrapper(c) for c in self._right_constrains)) def diff_mlsconstrains(self): """Generate the difference in MLS constraint rules between the policies.""" self.log.info( "Generating MLS constraint differences from {0.left_policy} to {0.right_policy}". format(self)) if self._left_mlsconstrains is None or self._right_mlsconstrains is None: self._create_constrain_lists() self.added_mlsconstrains, self.removed_mlsconstrains, _ = self._set_diff( (ConstraintWrapper(c) for c in self._left_mlsconstrains), (ConstraintWrapper(c) for c in self._right_mlsconstrains)) def diff_validatetrans(self): """Generate the difference in validatetrans rules between the policies.""" self.log.info( "Generating validatetrans differences from {0.left_policy} to {0.right_policy}". format(self)) if self._left_validatetrans is None or self._right_validatetrans is None: self._create_constrain_lists() self.added_validatetrans, self.removed_validatetrans, _ = self._set_diff( (ConstraintWrapper(c) for c in self._left_validatetrans), (ConstraintWrapper(c) for c in self._right_validatetrans)) def diff_mlsvalidatetrans(self): """Generate the difference in MLS validatetrans rules between the policies.""" self.log.info( "Generating mlsvalidatetrans differences from {0.left_policy} to {0.right_policy}". format(self)) if self._left_mlsvalidatetrans is None or self._right_mlsvalidatetrans is None: self._create_constrain_lists() self.added_mlsvalidatetrans, self.removed_mlsvalidatetrans, _ = self._set_diff( (ConstraintWrapper(c) for c in self._left_mlsvalidatetrans), (ConstraintWrapper(c) for c in self._right_mlsvalidatetrans)) # # Internal functions # def _create_constrain_lists(self): """Create rule lists for both policies.""" self._left_constrains = [] self._left_mlsconstrains = [] self._left_validatetrans = [] self._left_mlsvalidatetrans = [] for rule in self.left_policy.constraints(): if rule.ruletype == ConstraintRuletype.constrain: self._left_constrains.append(rule) elif rule.ruletype == ConstraintRuletype.mlsconstrain: self._left_mlsconstrains.append(rule) elif rule.ruletype == ConstraintRuletype.validatetrans: self._left_validatetrans.append(rule) elif rule.ruletype == ConstraintRuletype.mlsvalidatetrans: self._left_mlsvalidatetrans.append(rule) else: self.log.error("Unknown rule type: {0} (This is an SETools bug)". format(rule.ruletype)) self._right_constrains = [] self._right_mlsconstrains = [] self._right_validatetrans = [] self._right_mlsvalidatetrans = [] for rule in self.right_policy.constraints(): if rule.ruletype == ConstraintRuletype.constrain: self._right_constrains.append(rule) elif rule.ruletype == ConstraintRuletype.mlsconstrain: self._right_mlsconstrains.append(rule) elif rule.ruletype == ConstraintRuletype.validatetrans: self._right_validatetrans.append(rule) elif rule.ruletype == ConstraintRuletype.mlsvalidatetrans: self._right_mlsvalidatetrans.append(rule) else: self.log.error("Unknown rule type: {0} (This is an SETools bug)". format(rule.ruletype)) def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting all constraints differences") self.added_constrains = None self.removed_constrains = None self.added_mlsconstrains = None self.removed_mlsconstrains = None self.added_validatetrans = None self.removed_validatetrans = None self.added_mlsvalidatetrans = None self.removed_mlsvalidatetrans = None # Sets of rules for each policy self._left_constrains = None self._left_mlsconstrains = None self._left_validatetrans = None self._left_mlsvalidatetrans = None self._right_constrains = None self._right_mlsconstrains = None self._right_validatetrans = None self._right_mlsvalidatetrans = None class ConstraintWrapper(Wrapper): """Wrap constraints for diff purposes.""" __slots__ = ("ruletype", "tclass", "perms", "expr") def __init__(self, rule): self.origin = rule self.ruletype = rule.ruletype self.tclass = class_wrapper_factory(rule.tclass) try: self.perms = rule.perms except AttributeError: # (mls)validatetrans self.perms = None self.key = hash(rule) self.expr = [] for op in rule.expression: if isinstance(op, frozenset): # lists of types/users/roles self.expr.append(frozenset(SymbolWrapper(item) for item in op)) else: # strings in the expression such as u1/r1/t1 or "==" self.expr.append(op) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): return self.ruletype == other.ruletype and \ self.tclass == other.tclass and \ self.perms == other.perms and \ self.expr == other.expr netifcon.py000064400000007326152534333500006736 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper modified_netifcon_record = namedtuple("modified_netifcon", ["rule", "added_context", "removed_context", "added_packet", "removed_packet"]) class NetifconsDifference(Difference): """Determine the difference in netifcons between two policies.""" added_netifcons = DiffResultDescriptor("diff_netifcons") removed_netifcons = DiffResultDescriptor("diff_netifcons") modified_netifcons = DiffResultDescriptor("diff_netifcons") def diff_netifcons(self): """Generate the difference in netifcons between the policies.""" self.log.info("Generating netifcon differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_netifcons, self.removed_netifcons, matched_netifcons = self._set_diff( (NetifconWrapper(n) for n in self.left_policy.netifcons()), (NetifconWrapper(n) for n in self.right_policy.netifcons())) self.modified_netifcons = [] for left_netifcon, right_netifcon in matched_netifcons: # Criteria for modified netifcons # 1. change to context # 2. change to packet context if ContextWrapper(left_netifcon.context) != ContextWrapper(right_netifcon.context): removed_context = left_netifcon.context added_context = right_netifcon.context else: removed_context = None added_context = None if ContextWrapper(left_netifcon.packet) != ContextWrapper(right_netifcon.packet): removed_packet = left_netifcon.packet added_packet = right_netifcon.packet else: removed_packet = None added_packet = None if removed_context or removed_packet: self.modified_netifcons.append(modified_netifcon_record( left_netifcon, added_context, removed_context, added_packet, removed_packet)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting netifcon differences") self.added_netifcons = None self.removed_netifcons = None self.modified_netifcons = None class NetifconWrapper(Wrapper): """Wrap netifcon statements for diff purposes.""" __slots__ = ("netif") def __init__(self, ocon): self.origin = ocon self.netif = ocon.netif self.key = hash(ocon) def __hash__(self): return self.key def __lt__(self, other): return self.netif < other.netif def __eq__(self, other): return self.netif == other.netif portcon.py000064400000006305152534333500006611 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper modified_portcon_record = namedtuple("modified_portcon", ["rule", "added_context", "removed_context"]) class PortconsDifference(Difference): """Determine the difference in portcons between two policies.""" added_portcons = DiffResultDescriptor("diff_portcons") removed_portcons = DiffResultDescriptor("diff_portcons") modified_portcons = DiffResultDescriptor("diff_portcons") def diff_portcons(self): """Generate the difference in portcons between the policies.""" self.log.info("Generating portcon differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_portcons, self.removed_portcons, matched_portcons = self._set_diff( (PortconWrapper(n) for n in self.left_policy.portcons()), (PortconWrapper(n) for n in self.right_policy.portcons())) self.modified_portcons = [] for left_portcon, right_portcon in matched_portcons: # Criteria for modified portcons # 1. change to context if ContextWrapper(left_portcon.context) != ContextWrapper(right_portcon.context): self.modified_portcons.append(modified_portcon_record(left_portcon, right_portcon.context, left_portcon.context)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting portcon differences") self.added_portcons = None self.removed_portcons = None self.modified_portcons = None class PortconWrapper(Wrapper): """Wrap portcon statements for diff purposes.""" __slots__ = ("protocol", "low", "high") def __init__(self, ocon): self.origin = ocon self.protocol = ocon.protocol self.low, self.high = ocon.ports self.key = hash(ocon) def __hash__(self): return self.key def __lt__(self, other): return self.origin < other.origin def __eq__(self, other): return self.protocol == other.protocol and \ self.low == other.low and \ self.high == other.high bounds.py000064400000010150152534333500006410 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from ..policyrep import BoundsRuletype from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper from .types import type_wrapper_factory modified_bounds_record = namedtuple("modified_bound", ["rule", "added_bound", "removed_bound"]) class BoundsDifference(Difference): """Determine the difference in *bounds between two policies.""" added_typebounds = DiffResultDescriptor("diff_typebounds") removed_typebounds = DiffResultDescriptor("diff_typebounds") modified_typebounds = DiffResultDescriptor("diff_typebounds") # Lists of rules for each policy _left_typebounds = None _right_typebounds = None def diff_typebounds(self): """Generate the difference in typebound rules between the policies.""" self.log.info("Generating typebounds differences from {0.left_policy} to {0.right_policy}". format(self)) if self._left_typebounds is None or self._right_typebounds is None: self._create_typebound_lists() self.added_typebounds, self.removed_typebounds, matched_typebounds = self._set_diff( (BoundsWrapper(c) for c in self._left_typebounds), (BoundsWrapper(c) for c in self._right_typebounds), key=lambda b: str(b.child)) self.modified_typebounds = [] for left_bound, right_bound in matched_typebounds: if type_wrapper_factory(left_bound.parent) != type_wrapper_factory(right_bound.parent): self.modified_typebounds.append(modified_bounds_record( left_bound, right_bound.parent, left_bound.parent)) # # Internal functions # def _create_typebound_lists(self): """Create rule lists for both policies.""" self._left_typebounds = [] for rule in self.left_policy.bounds(): if rule.ruletype == BoundsRuletype.typebounds: self._left_typebounds.append(rule) else: self.log.error("Unknown rule type: {0} (This is an SETools bug)". format(rule.ruletype)) self._right_typebounds = [] for rule in self.right_policy.bounds(): if rule.ruletype == BoundsRuletype.typebounds: self._right_typebounds.append(rule) else: self.log.error("Unknown rule type: {0} (This is an SETools bug)". format(rule.ruletype)) def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting all *bounds differences") self.added_typebounds = None self.removed_typebounds = None # Sets of rules for each policy self._left_typebounds = None self._right_typebounds = None class BoundsWrapper(Wrapper): """Wrap *bounds for diff purposes.""" __slots__ = ("ruletype", "parent", "child") def __init__(self, rule): self.origin = rule self.ruletype = rule.ruletype self.parent = type_wrapper_factory(rule.parent) self.child = type_wrapper_factory(rule.child) self.key = hash(rule) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): return self.ruletype == other.ruletype and \ self.child == other.child mlsrules.py000064400000011464152534333500006775 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from .. import MLSRuletype from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper from .mls import RangeWrapper from .objclass import class_wrapper_factory from .types import type_or_attr_wrapper_factory modified_mlsrule_record = namedtuple("modified_mlsrule", ["rule", "added_default", "removed_default"]) class MLSRulesDifference(Difference): """Determine the difference in MLS rules between two policies.""" added_range_transitions = DiffResultDescriptor("diff_range_transitions") removed_range_transitions = DiffResultDescriptor("diff_range_transitions") modified_range_transitions = DiffResultDescriptor("diff_range_transitions") # Lists of rules for each policy _left_mls_rules = defaultdict(list) _right_mls_rules = defaultdict(list) def diff_range_transitions(self): """Generate the difference in range_transition rules between the policies.""" self.log.info( "Generating range_transition differences from {0.left_policy} to {0.right_policy}". format(self)) if not self._left_mls_rules or not self._right_mls_rules: self._create_mls_rule_lists() added, removed, matched = self._set_diff( self._expand_generator(self._left_mls_rules[MLSRuletype.range_transition], MLSRuleWrapper), self._expand_generator(self._right_mls_rules[MLSRuletype.range_transition], MLSRuleWrapper)) modified = [] for left_rule, right_rule in matched: # Criteria for modified rules # 1. change to default range if RangeWrapper(left_rule.default) != RangeWrapper(right_rule.default): modified.append(modified_mlsrule_record(left_rule, right_rule.default, left_rule.default)) self.added_range_transitions = added self.removed_range_transitions = removed self.modified_range_transitions = modified # # Internal functions # def _create_mls_rule_lists(self): """Create rule lists for both policies.""" # do not expand yet, to keep memory # use down as long as possible self.log.debug("Building MLS rule lists from {0.left_policy}".format(self)) for rule in self.left_policy.mlsrules(): self._left_mls_rules[rule.ruletype].append(rule) self.log.debug("Building MLS rule lists from {0.right_policy}".format(self)) for rule in self.right_policy.mlsrules(): self._right_mls_rules[rule.ruletype].append(rule) self.log.debug("Completed building MLS rule lists.") def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting MLS rule differences") self.added_range_transitions = None self.removed_range_transitions = None self.modified_range_transitions = None # Sets of rules for each policy self._left_mls_rules.clear() self._right_mls_rules.clear() class MLSRuleWrapper(Wrapper): """Wrap MLS rules to allow set operations.""" __slots__ = ("ruletype", "source", "target", "tclass") def __init__(self, rule): self.origin = rule self.source = type_or_attr_wrapper_factory(rule.source) self.target = type_or_attr_wrapper_factory(rule.target) self.tclass = class_wrapper_factory(rule.tclass) self.key = hash(rule) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): # because MLSRuleDifference groups rules by ruletype, # the ruletype always matches. return self.source == other.source and \ self.target == other.target and \ self.tclass == other.tclass polcap.py000064400000003316152534333500006402 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper class PolCapsDifference(Difference): """Determine the difference in polcaps between two policies.""" added_polcaps = DiffResultDescriptor("diff_polcaps") removed_polcaps = DiffResultDescriptor("diff_polcaps") def diff_polcaps(self): """Generate the difference in polcaps between the policies.""" self.log.info("Generating policy cap differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_polcaps, self.removed_polcaps, _ = self._set_diff( (SymbolWrapper(n) for n in self.left_policy.polcaps()), (SymbolWrapper(n) for n in self.right_policy.polcaps())) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting policy capability differences") self.added_polcaps = None self.removed_polcaps = None descriptors.py000064400000003145152534333500007465 0ustar00# Copyright 2015, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from weakref import WeakKeyDictionary class DiffResultDescriptor: """Descriptor for managing diff results.""" # @properties could be used instead, but there are so # many result attributes, this will keep the code cleaner. def __init__(self, diff_function): self.diff_function = diff_function # use weak references so instances can be # garbage collected, rather than unnecessarily # kept around due to this descriptor. self.instances = WeakKeyDictionary() def __get__(self, obj, objtype=None): if obj is None: return self if self.instances.setdefault(obj, None) is None: diff = getattr(obj, self.diff_function) diff() return self.instances[obj] def __set__(self, obj, value): self.instances[obj] = value def __delete__(self, obj): self.instances[obj] = None __pycache__/portcon.cpython-36.pyc000064400000005266152534333500013102 0ustar003 ^ @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_portconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)PortconsDifferencez:Determine the difference in portcons between two policies. diff_portconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z9Generate the difference in portcons between the policies.zGGenerating portcon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)PortconWrapper).0nr /usr/lib64/python3.6/portcon.py .sz3PortconsDifference.diff_portcons..css|]}t|VqdS)N)r )r r r r rr/sN)loginfoformatZ _set_diffZ left_policyZportconsZ right_policyadded_portconsremoved_portconsmodified_portconsrcontextappendmodified_portcon_record)selfZmatched_portconsZ left_portconZ right_portconr r rr 's   z PortconsDifference.diff_portconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting portcon differencesN)rdebugrrr)rr r r _reset_diff>s zPortconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rrs rc@s4eZdZdZdZddZddZd d Zd d Zd S)r z*Wrap portcon statements for diff purposes.protocollowhighcCs*||_|j|_|j\|_|_t||_dS)N)originr Zportsr!r"hashkey)rZoconr r r__init__LszPortconWrapper.__init__cCs|jS)N)r%)rr r r__hash__RszPortconWrapper.__hash__cCs |j|jkS)N)r#)rotherr r r__lt__UszPortconWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r r!r")rr(r r r__eq__Xs  zPortconWrapper.__eq__N)r r!r") rrrr __slots__r&r'r)r*r r r rr Fs r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   '__pycache__/ibpkeycon.cpython-36.opt-1.pyc000064400000005357152534333500014341 0ustar003 ^' @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_ibpkeyconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)IbpkeyconsDifferencez0sz7IbpkeyconsDifference.diff_ibpkeycons..css|]}t|VqdS)N)r )r r r r rr1sN)loginfoformatZ _set_diffZ left_policyZ ibpkeyconsZ right_policyadded_ibpkeyconsremoved_ibpkeyconsmodified_ibpkeyconsrcontextappendmodified_ibpkeycon_record)selfZmatched_ibpkeyconsZ left_ibpkeyZ right_ibpkeyr r rr 's z$IbpkeyconsDifference.diff_ibpkeyconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting ibpkeycon differencesN)rdebugrrr)rr r r _reset_diffAs z IbpkeyconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rrs rc@s4eZdZdZdZddZddZd d Zd d Zd S)r z,Wrap ibpkeycon statements for diff purposes. subnet_prefixlowhighcCs*||_|j|_|j\|_|_t||_dS)N)originr Zpkeysr!r"hashkey)rZoconr r r__init__OszIbpkeyconWrapper.__init__cCs|jS)N)r%)rr r r__hash__UszIbpkeyconWrapper.__hash__cCs |j|jkS)N)r#)rotherr r r__lt__XszIbpkeyconWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r r!r")rr(r r r__eq__[s  zIbpkeyconWrapper.__eq__N)r r!r") rrrr __slots__r&r'r)r*r r r rr Is r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   *__pycache__/mlsrules.cpython-36.pyc000064400000006634152534333500013264 0ustar003 ^4@sddlmZmZddlmZddlmZddlmZm Z ddl m Z ddl m Z dd lmZed d d d gZGdddeZGddde ZdS)) defaultdict namedtuple) MLSRuletype)DiffResultDescriptor) DifferenceWrapper) RangeWrapper)class_wrapper_factory)type_or_attr_wrapper_factoryZmodified_mlsruleruleZ added_defaultZremoved_defaultc@sPeZdZdZedZedZedZee Z ee Z ddZ ddZ ddZd S) MLSRulesDifferencez;Determine the difference in MLS rules between two policies.diff_range_transitionscCs|jjdj||j s"|j r*|j|j|j|jtj t |j|jtj t \}}}g}x:|D]2\}}t |j t |j krf|j t||j |j qfW||_||_||_dS)zGGenerate the difference in range_transition rules between the policies.zPGenerating range_transition differences from {0.left_policy} to {0.right_policy}N)loginfoformat_left_mls_rules_right_mls_rules_create_mls_rule_listsZ _set_diffZ_expand_generatorrZrange_transitionMLSRuleWrapperr defaultappendmodified_mlsrule_recordadded_range_transitionsremoved_range_transitionsmodified_range_transitions)selfZaddedZremovedZmatchedZmodifiedZ left_ruleZ right_ruler /usr/lib64/python3.6/mlsrules.pyr/s&z)MLSRulesDifference.diff_range_transitionscCs|jjdj|x$|jjD]}|j|jj|qW|jjdj|x$|jjD]}|j |jj|qVW|jjddS)z$Create rule lists for both policies.z,Building MLS rule lists from {0.left_policy}z-Building MLS rule lists from {0.right_policy}z"Completed building MLS rule lists.N) rdebugrZ left_policyZmlsrulesrruletyperZ right_policyr)rr rrrrPsz)MLSRulesDifference._create_mls_rule_listscCs6|jjdd|_d|_d|_|jj|jjdS)z%Reset diff results on policy changes.zResetting MLS rule differencesN)rr rrrrclearr)rrrr _reset_diff^s   zMLSRulesDifference._reset_diffN)__name__ __module__ __qualname____doc__rrrrrlistrrrrr#rrrrr#s!rc@s4eZdZdZdZddZdd Zd d Zd d ZdS)rz'Wrap MLS rules to allow set operations.r!sourcetargettclasscCs8||_t|j|_t|j|_t|j|_t||_dS)N)originr r)r*r r+hashkey)rr rrr__init__ps    zMLSRuleWrapper.__init__cCs|jS)N)r.)rrrr__hash__wszMLSRuleWrapper.__hash__cCs |j|jkS)N)r.)rotherrrr__lt__zszMLSRuleWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r)r*r+)rr1rrr__eq__}s  zMLSRuleWrapper.__eq__N)r!r)r*r+) r$r%r&r' __slots__r/r0r2r3rrrrrjs rN) collectionsrrrZ descriptorsr differencerr Zmlsr Zobjclassr typesr rrrrrrrs     G__pycache__/bool.cpython-36.opt-1.pyc000064400000004177152534333500013310 0ustar003 ^R @s^ddlmZmZddlmZddlmZmZedddgZee Z dd Z Gd d d eZ d S) ) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapperZmodified_booleanZ added_stateZ removed_statec Cs:y t||Stk r4t|}|t||<|SXdS)z Wrap booleans from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _bool_cacheKeyErrorr)ZpolicyZbooleanbr /usr/lib64/python3.6/bool.pyboolean_wrappers   r c@s8eZdZdZedZedZedZddZddZ dS)BooleansDifferencezADetermine the difference in type attributes between two policies. diff_booleanscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x0|D](\}}|j |j krVt |j |j |j |<qVWdS)z@Generate the difference in type attributes between the policies.zGGenerating Boolean differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0r r r r >sz3BooleansDifference.diff_booleans..css|]}t|VqdS)N)r)rr r r r r?sN) loginfoformatZ _set_diffZ left_policyZboolsZ right_policyadded_booleansremoved_booleansdictmodified_booleansstatemodified_bool_record)selfZmatched_booleansZ left_booleanZ right_booleanr r r r6s   z BooleansDifference.diff_booleanscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting Boolean differencesN)rdebugrrr)rr r r _reset_diffMs zBooleansDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrrr r r r r.s rN) collectionsrrZ descriptorsr differencerrrrrr rr r r r s  __pycache__/users.cpython-36.opt-1.pyc000064400000006066152534333500013515 0ustar003 ^ @sddlmZmZddlmZddlmZddlmZm Z ddl m Z m Z ddl mZed d d d d dddgZeeZddZGdddeZdS)) defaultdict namedtuple) MLSDisabled)DiffResultDescriptor) Difference SymbolWrapper) LevelWrapper RangeWrapper)role_wrapper_factoryZ modified_user added_roles removed_roles matched_roles added_level removed_level added_range removed_rangec Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap users from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _users_cacheZpolicyKeyErrorr )userrr/usr/lib64/python3.6/users.pyuser_wrapper_factory)s rc@s8eZdZdZedZedZedZddZddZ dS)UsersDifferencez7Determine the difference in users between two policies. diff_userscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x:|D]0\}}|jdd|j Ddd|j D\}}}y$t |j }t|j}|j } |j} Wn$tk rd}d}d} d} YnXy$t |j } t|j} |j } |j}Wn&tk r d} d} d} d}YnX|| kr6| }| }nd}d}|| krR|}| }nd}d}|sp|sp|sp|rXt||||||||j |<qXWdS) z6Generate the difference in users between the policies.zDGenerating user differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr Gsz-UsersDifference.diff_users..css|]}t|VqdS)N)r)rrrrrrHscss|]}t|VqdS)N)r )rrrrrrRscss|]}t|VqdS)N)r )rrrrrrSsNzNone (MLS Disabled))loginfoformatZ _set_diffZ left_policyZusersZ right_policy added_users removed_usersdictmodified_usersrolesr Z mls_levelr Z mls_rangermodified_users_record)selfZ matched_usersZ left_userZ right_userr rrZleft_level_wrapZleft_range_wrapZ left_levelZ left_rangeZright_level_wrapZright_range_wrapZ right_levelZ right_rangerrrrrrrr@s`            zUsersDifference.diff_userscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting user differencesN)rdebugr"r#r%)r(rrr _reset_diffs zUsersDifference._reset_diffN) __name__ __module__ __qualname____doc__rr"r#r%rr*rrrrr8s GrN) collectionsrrZ exceptionrZ descriptorsr differencerr Zmlsr r r&r r'r$rrrrrrrs   __pycache__/roles.cpython-36.pyc000064400000004615152534333500012537 0ustar003 ^ @slddlmZmZddlmZddlmZmZddlm Z edddd gZ ee Z d d Z Gd d d eZdS)) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapper)type_wrapper_factoryZ modified_role added_types removed_types matched_typesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap roles from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _roles_cacheZpolicyKeyErrorr)Zrolerr/usr/lib64/python3.6/roles.pyrole_wrapper_factory"s rc@s8eZdZdZedZedZedZddZddZ dS)RolesDifferencez7Determine the difference in roles between two policies. diff_rolescCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xX|D]P\}}|jdd|j Ddd|j D\}}}|s|rVt ||||j |<qVWdS)z6Generate the difference in roles between the policies.zDGenerating role differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr @sz-RolesDifference.diff_roles..css|]}t|VqdS)N)r)rrrrrrAscss|]}t|VqdS)N)r)rtrrrrJscss|]}t|VqdS)N)r)rrrrrrKsN) loginfoformatZ _set_diffZ left_policyZrolesZ right_policy added_roles removed_rolesdictmodified_rolestypesmodified_roles_record)selfZ matched_rolesZ left_roleZ right_roler r r rrrr9s  zRolesDifference.diff_rolescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting role differencesN)rdebugrrr)r rrr _reset_diffUs zRolesDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr"rrrrr1s rN) collectionsrrZ descriptorsr differencerrrrrrr rrrrrrs  __pycache__/objclass.cpython-36.opt-1.pyc000064400000004665152534333500014157 0ustar003 ^j@sxddlmZmZddlmZddlmZddlmZddl m Z m Z edd d d gZ ee Zd d ZGddde ZdS)) defaultdict namedtuple)suppress)NoCommon)DiffResultDescriptor) Difference SymbolWrapperZmodified_class added_perms removed_perms matched_permsc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap class from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _class_cacheZpolicyKeyErrorr )Zclass_cr /usr/lib64/python3.6/objclass.pyclass_wrapper_factory$s rc@s8eZdZdZedZedZedZddZddZ dS)ObjClassDifferencezN Determine the difference in object classes between two policies. diff_classesc Cs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x|D]\}}|j }t t ||jj O}WdQRX|j }t t ||jj O}WdQRX|j||dd\}}}|s|rVt||||j |<qVWdS)z?Generate the difference in object classes between the policies.zEGenerating class differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r ).0rrrr Fsz2ObjClassDifference.diff_classes..css|]}t|VqdS)N)r )rrrrrrGsNF)Zunwrap)loginfoformatZ _set_diffZ left_policyclassesZ right_policy added_classesremoved_classesdictmodified_classesZpermsrrcommonmodified_classes_record) selfZmatched_classesZ left_classZ right_classZ left_permsZ right_permsr r r rrrr?s(    zObjClassDifference.diff_classescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z"Resetting object class differencesN)rdebugrrr)r"rrr _reset_diffcs zObjClassDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr$rrrrr4s $rN) collectionsrr contextlibrZ exceptionrZ descriptorsr differencer r r!rrrrrrrrs   __pycache__/default.cpython-36.pyc000064400000005543152534333500013040 0ustar003 ^@sdddlmZddlmZddlmZmZmZeddddd d gZGd d d eZ Gd ddeZ dS)) namedtuple)DiffResultDescriptor) Difference SymbolWrapperWrapperZmodified_defaultZrule added_defaultremoved_defaultadded_default_rangeremoved_default_rangec@s8eZdZdZedZedZedZddZddZ dS)DefaultsDifferencez;Determine the difference in default_* between two policies. diff_defaultscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x|D]\}}|j |j krv|j }|j }nd}d}y&|j |j kr|j }|j }nd}d}Wnt k rd}d}YnX|s|rT|j j t|||||qTWdS)z>Generate the difference in type defaults between the policies.zIGenerating default_* differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)DefaultWrapper).0dr/usr/lib64/python3.6/default.py 0sz3DefaultsDifference.diff_defaults..css|]}t|VqdS)N)r)rrrrrr1sN)loginfoformatZ _set_diffZ left_policyZdefaultsZ right_policyadded_defaultsremoved_defaultsmodified_defaultsdefaultZ default_rangeAttributeErrorappendmodified_default_record)selfZmatched_defaultsZ left_defaultZ right_defaultr rr r rrrr (s:    z DefaultsDifference.diff_defaultscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting default_* differencesN)rdebugrrr)rrrr _reset_diffWs zDefaultsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr r rrrrr s /r c@s4eZdZdZd ZddZddZdd Zd d Zd S)rz$Wrap default_* to allow comparisons.ruletypetclasscCs(||_|j|_t|j|_t||_dS)N)originr%rr&hashkey)rrrrr__init__es zDefaultWrapper.__init__cCs|jS)N)r))rrrr__hash__kszDefaultWrapper.__hash__cCs |j|jkS)N)r))rotherrrr__lt__nszDefaultWrapper.__lt__cCs|j|jko|j|jkS)N)r%r&)rr,rrr__eq__qs zDefaultWrapper.__eq__N)r%r&) r!r"r#r$ __slots__r*r+r-r.rrrrr_s rN) collectionsrZ descriptorsr differencerrrrr rrrrrs  ?__pycache__/bounds.cpython-36.opt-1.pyc000064400000006652152534333500013647 0ustar003 ^h@stddlmZddlmZddlmZddlmZmZddl m Z edd d d gZ Gd d d eZ GdddeZ dS)) namedtuple)BoundsRuletype)DiffResultDescriptor) DifferenceWrapper)type_wrapper_factoryZmodified_boundruleZ added_boundZ removed_boundc@sHeZdZdZedZedZedZdZdZ ddZ ddZ dd Z dS) BoundsDifferencez9Determine the difference in *bounds between two policies.diff_typeboundsNcCs|jjdj||jdks&|jdkr.|j|jdd|jDdd|jDddd\|_|_}g|_ x<|D]4\}}t |j t |j krp|j j t ||j |j qpWdS) z@Generate the difference in typebound rules between the policies.zJGenerating typebounds differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N) BoundsWrapper).0cr/usr/lib64/python3.6/bounds.py 5sz3BoundsDifference.diff_typebounds..css|]}t|VqdS)N)r )rrrrrr6scSs t|jS)N)strchild)brrr7sz2BoundsDifference.diff_typebounds..)key)loginfoformat_left_typebounds_right_typebounds_create_typebound_listsZ _set_diffadded_typeboundsremoved_typeboundsmodified_typeboundsr parentappendmodified_bounds_record)selfZmatched_typeboundsZ left_boundZ right_boundrrrr +s z BoundsDifference.diff_typeboundscCsg|_x@|jjD]2}|jtjkr0|jj|q|jjdj |jqWg|_ x@|j jD]2}|jtjkrx|j j|qZ|jjdj |jqZWdS)z$Create rule lists for both policies.z/Unknown rule type: {0} (This is an SETools bug)N) rZ left_policyZboundsruletyperZ typeboundsr"rerrorrrZ right_policy)r$r rrrrCs    z(BoundsDifference._create_typebound_listscCs(|jjdd|_d|_d|_d|_dS)z%Reset diff results on policy changes.z!Resetting all *bounds differencesN)rdebugrrrr)r$rrr _reset_diffUs  zBoundsDifference._reset_diff) __name__ __module__ __qualname____doc__rrrr rrr rr(rrrrr sr c@s4eZdZdZdZddZddZd d Zd d Zd S)r zWrap *bounds for diff purposes.r%r!rcCs4||_|j|_t|j|_t|j|_t||_dS)N)originr%r r!rhashr)r$r rrr__init__fs   zBoundsWrapper.__init__cCs|jS)N)r)r$rrr__hash__mszBoundsWrapper.__hash__cCs |j|jkS)N)r)r$otherrrr__lt__pszBoundsWrapper.__lt__cCs|j|jko|j|jkS)N)r%r)r$r1rrr__eq__ss zBoundsWrapper.__eq__N)r%r!r) r)r*r+r, __slots__r/r0r2r3rrrrr `s r N) collectionsrZ policyreprZ descriptorsr differencerrtypesr r#r r rrrrs    A__pycache__/objclass.cpython-36.pyc000064400000004665152534333500013220 0ustar003 ^j@sxddlmZmZddlmZddlmZddlmZddl m Z m Z edd d d gZ ee Zd d ZGddde ZdS)) defaultdict namedtuple)suppress)NoCommon)DiffResultDescriptor) Difference SymbolWrapperZmodified_class added_perms removed_perms matched_permsc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap class from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _class_cacheZpolicyKeyErrorr )Zclass_cr /usr/lib64/python3.6/objclass.pyclass_wrapper_factory$s rc@s8eZdZdZedZedZedZddZddZ dS)ObjClassDifferencezN Determine the difference in object classes between two policies. diff_classesc Cs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x|D]\}}|j }t t ||jj O}WdQRX|j }t t ||jj O}WdQRX|j||dd\}}}|s|rVt||||j |<qVWdS)z?Generate the difference in object classes between the policies.zEGenerating class differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r ).0rrrr Fsz2ObjClassDifference.diff_classes..css|]}t|VqdS)N)r )rrrrrrGsNF)Zunwrap)loginfoformatZ _set_diffZ left_policyclassesZ right_policy added_classesremoved_classesdictmodified_classesZpermsrrcommonmodified_classes_record) selfZmatched_classesZ left_classZ right_classZ left_permsZ right_permsr r r rrrr?s(    zObjClassDifference.diff_classescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z"Resetting object class differencesN)rdebugrrr)r"rrr _reset_diffcs zObjClassDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr$rrrrr4s $rN) collectionsrr contextlibrZ exceptionrZ descriptorsr differencer r r!rrrrrrrrs   __pycache__/users.cpython-36.pyc000064400000006066152534333500012556 0ustar003 ^ @sddlmZmZddlmZddlmZddlmZm Z ddl m Z m Z ddl mZed d d d d dddgZeeZddZGdddeZdS)) defaultdict namedtuple) MLSDisabled)DiffResultDescriptor) Difference SymbolWrapper) LevelWrapper RangeWrapper)role_wrapper_factoryZ modified_user added_roles removed_roles matched_roles added_level removed_level added_range removed_rangec Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap users from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _users_cacheZpolicyKeyErrorr )userrr/usr/lib64/python3.6/users.pyuser_wrapper_factory)s rc@s8eZdZdZedZedZedZddZddZ dS)UsersDifferencez7Determine the difference in users between two policies. diff_userscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x:|D]0\}}|jdd|j Ddd|j D\}}}y$t |j }t|j}|j } |j} Wn$tk rd}d}d} d} YnXy$t |j } t|j} |j } |j}Wn&tk r d} d} d} d}YnX|| kr6| }| }nd}d}|| krR|}| }nd}d}|sp|sp|sp|rXt||||||||j |<qXWdS) z6Generate the difference in users between the policies.zDGenerating user differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr Gsz-UsersDifference.diff_users..css|]}t|VqdS)N)r)rrrrrrHscss|]}t|VqdS)N)r )rrrrrrRscss|]}t|VqdS)N)r )rrrrrrSsNzNone (MLS Disabled))loginfoformatZ _set_diffZ left_policyZusersZ right_policy added_users removed_usersdictmodified_usersrolesr Z mls_levelr Z mls_rangermodified_users_record)selfZ matched_usersZ left_userZ right_userr rrZleft_level_wrapZleft_range_wrapZ left_levelZ left_rangeZright_level_wrapZright_range_wrapZ right_levelZ right_rangerrrrrrrr@s`            zUsersDifference.diff_userscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting user differencesN)rdebugr"r#r%)r(rrr _reset_diffs zUsersDifference._reset_diffN) __name__ __module__ __qualname____doc__rr"r#r%rr*rrrrr8s GrN) collectionsrrZ exceptionrZ descriptorsr differencerr Zmlsr r r&r r'r$rrrrrrrs   __pycache__/terules.cpython-36.pyc000064400000034376152534333500013105 0ustar003 ^^@spddlZddlmZmZddlmZddlmZddlm Z m Z m Z ddl m Z mZdd lmZdd lmZdd lmZmZdd lmZmZdd lmZedZedZedddddgZeddddgZGdddeZedddgZ edddgZ!ed ddgZ"d!d"Z#d#d$Z$d%d&Z%d'd(Z&d)d*Z'd+d,Z(d-d.Z)Gd/d0d0eZ*Gd1d2d2eZ+Gd3d4d4eZ,dS)5N) defaultdict namedtuple)intern)Enum)RuleNotConditional RuleUseErrorTERuleNoFilename)IoctlSet TERuletype)conditional_wrapper_factory)DiffResultDescriptor) DifferenceWrapper)type_wrapper_factorytype_or_attr_wrapper_factory)class_wrapper_factoryz<>TrueZmodified_avrulerule added_perms removed_perms matched_permsZmodified_teruleZ added_defaultZremoved_defaultc@seZdZdZdZdS)Siderr N)__name__ __module__ __qualname__leftrightrr/usr/lib64/python3.6/terules.pyr-srZrule_db_side_dataperms orig_ruleZ rule_db_sidesrrZType_dbcCs|tjkr|j}n|j}x|D]}t}t}y tt|j}tt|j}Wnt k rbYnX||krt ||<t |||<n|||krt |||<|j j }dd|j D} t| |} |||} x.|jjD]} | j } | |kr| || <| | kr t | | <x|jjD]}|j }||kr4|||<|| | krPt | | |<d}d}|| | |kr| | ||}|j}|j}|tjkr|s| }n|j | B}|j}t||}n&|s| }n|j | B}|j}t||}t||| | ||<qWqWq WdS)aP Using rule_list, build up rule_db which is a data structure which consists of nested dicts that store BOTH the left and the right policies. All of the keys are interned strings. The permissions are stored as a set. The basic structure is rule_db[cond_exp][block_bool][src][tgt][tclass] = sides where: cond_exp is a boolean expression block_bool is either true or false src is the source type tgt is the target type tclass is the target class sides is a named tuple with attributes "left" and "right" referring to the left or right policy. Each attribute in the sides named tuple refers to a named tuple with attributes "perms" and "orig_rule" which refer to a permission set and the original unexpanded rule. sides = ((left_perms, left_orig_rule),(right_perms, right_orig_rule)) There are a few advantages to this structure. First, it takes up way less memory. Second, it allows redundant rules to be easily eliminated. And, third, it makes it easy to create the added, removed, and modified rules. cSsh|]}|qSrr).0prrr csz+_avrule_expand_generator..N)rrrTERULES_UNCONDITIONALTERULES_UNCONDITIONAL_BLOCKrstr conditionalconditional_blockrdicttclassnamer!rule_db_side_data_recordsourceexpandtargetr"rule_db_sides_record) rule_listrule_dbtype_dbZsidetypesunexpanded_rulecond_exp block_boolr,r! side_datablocksrcZsrc_strtgtZtgt_str left_side right_sideZsidesr$Zorigrrr _avrule_expand_generator9sd             r@cCsx|tt}xd|jD]V\}}|tkr,qx@|jD]2\}}x&|jD]\}}||krbqNx|jD]\}} |||krqnx| jD]\} } | |||krq|||| } | j} | j}| jo| r| j| jj@}|r| j|}|rt|| j} nd} t| || | <| jr|r|j| jj@}|r|j|}|rNt||j}nd}t| || | <qWqnWqNWq8WqWdS)N) r&r'itemsrrr!r.r"r2)r4Z uncond_blockr8 cond_blocksr9r;r<src_datar=tgt_datar,r:Zuncond_side_datar>r?cr$rrr _av_remove_redundant_rulessB      rFc Cs|g}g}g}xb|jD]T\}}xH|jD]:\}} x.| jD] \} } x| jD]\} } x| jD]\}}|jr|jr|jj|jj@}|jj|}|jj|}|s|r|jj}|j|j| |j| |jj}|jt||||qn|jr(|jj}|j|j| |j| |jj}|j|qn|jrn|jj}|j|j| |j| |jj}|j|qnWqZWqDWq.WqW|||fS)N)rArrr!r"Zderive_expandedappendmodified_avrule_record)ruletyper4r5addedremovedmodifiedr8rBr9r;r<rCr=rDr,r:Z common_permsZ left_permsZ right_permsZ original_rulerrrr _av_generate_diffssB         rMcstjfdd}|S)z This is a template for the access vector diff functions. Parameters: ruletype The rule type, e.g. "allow". cs|jjdj||j s$|j r,|jttt}t}t|t<t|tt <t jdt |j||t j t jdt |j||t jt jdt|t jdt||\}}}|j j|jj|jt|dj|t|dj|t|dj|d S) z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}zExpanding left policyzExpanding right policyzRemoving redundant rulesz0Generating added, removed, and modified av rulesz added_{0}sz removed_{0}sz modified_{0}sN)loginfoformat_left_te_rules_right_te_rules_create_te_rule_liststype_db_recordr+r&r'loggingr@rrrrFrMclearsetattr)selfr5r4rJrKrL)rIrr diffs.        zav_diff_template..diff)r lookup)rIrYr)rIr av_diff_templates  #r[c Cst}x\|D]T}xN|jD]B}||}y||j|jO_Wqtk rZ|||<YqXqWq W|rtjtjdj|t ||j S)z` Generator that yields wrapped, expanded, av(x) rules with unioned permission sets. z/Expanded {0.ruletype} rules for {0.policy}: {1}) r+r0r!KeyErrorrUZ getLoggerrdebugrPlenkeys)r3Z WrapperClassrAr7Z expanded_ruleZexpanded_wrapped_rulerrr _avxrule_expand_generator s  r`cstjfdd}|S)z This is a template for the extended permission access vector diff functions. Parameters: ruletype The rule type, e.g. "allowxperm". c s|jjdj||j s$|j r,|j|jt|jtt|jtdd\}}}g}x^|D]V\}}|j|j |j dd\}}} |s|rd|j t |j t |t |t dd| DqdWt|djtdd|Dt|djtd d|Dt|d j|d S) z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}F)Zunwrapcss|]}|dVqdS)rNr)r#r$rrr Qsz2avx_diff_template..diff..z added_{0}scss|] }|jVqdS)N)origin)r#arrr raSsz removed_{0}scss|] }|jVqdS)N)rb)r#rrrr raTsz modified_{0}sN)rNrOrPrQrRrS _set_diffr`AVRuleXpermWrapperr!rGrHrbr rWset) rXrJrKmatchedrL left_rule right_rulerrr)rIrr rY3s,    zavx_diff_template..diff)r rZ)rIrYr)rIr avx_diff_template)s  $rkcstjfdd}|S)z This is a template for the type_* diff functions. Parameters: ruletype The rule type, e.g. "type_transition". cs|jjdj||j s$|j r,|j|j|j|jt|j|jt\}}}g}x:|D]2\}}t |j t |j krd|j t ||j |j qdWt |dj|t |dj|t |dj|dS)z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}z added_{0}sz removed_{0}sz modified_{0}sN)rNrOrPrQrRrSreZ_expand_generator TERuleWrapperrdefaultrGmodified_terule_recordrW)rXrJrKrhrLrirj)rIrr rYds" zte_diff_template..diff)r rZ)rIrYr)rIr te_diff_templateZs  roc@seZdZdZedZedZedZedZ edZ edZ edZ edZ edZedZedZedZedZed Zed Zed Zed Zed Zed Zed Zed Zed Zed Zed ZedZedZ edZ!edZ"edZ#edZ$edZ%edZ&e'dZ(edZ)edZ*edZ+e'dZ,edZ-edZ.edZ/e'dZ0edZ1edZ2edZ3e4e5Z6e4e5Z7ddZ8ddZ9dS)TERulesDifferencezV Determine the difference in type enforcement rules between two policies. Zallow diff_allowsZ auditallowdiff_auditallowsZ neverallowdiff_neverallowsZ dontauditdiff_dontauditsZ allowxpermdiff_allowxpermsZauditallowxpermdiff_auditallowxpermsZneverallowxpermdiff_neverallowxpermsZdontauditxpermdiff_dontauditxpermsZtype_transitiondiff_type_transitionsZ type_changediff_type_changesZ type_memberdiff_type_memberscCs|jjdj|x$|jjD]}|j|jj|qWx.|jjD] \}}|jjdjt ||qDW|jjdj|x$|j jD]}|j |jj|qWx.|j jD] \}}|jjdjt ||qW|jjddS)z$Create rule lists for both policies.z+Building TE rule lists from {0.left_policy}zLoaded {0} {1} rules.z,Building TE rule lists from {0.right_policy}z!Completed building TE rule lists.N) rNr]rPZ left_policyZterulesrQrIrGrAr^Z right_policyrR)rXrrIZrulesrrr rSsz'TERulesDifference._create_te_rule_listscCs|jjdd|_d|_d|_d|_d|_d|_d|_d|_ d|_ d|_ d|_ d|_ d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_ d|_!d|_"|j#j$|j%j$dS)z%Reset diff results on policy changes.zResetting TE rule differencesN)&rNr] added_allowsremoved_allowsmodified_allowsadded_auditallowsremoved_auditallowsmodified_auditallowsadded_neverallowsremoved_neverallowsmodified_neverallowsadded_dontauditsremoved_dontauditsmodified_dontauditsadded_allowxpermsremoved_allowxpermsmodified_allowxpermsadded_auditallowxpermsremoved_auditallowxpermsmodified_auditallowxpermsadded_neverallowxpermsremoved_neverallowxpermsmodified_neverallowxpermsadded_dontauditxpermsremoved_dontauditxpermsmodified_dontauditxpermsadded_type_transitionsremoved_type_transitionsmodified_type_transitionsadded_type_changesremoved_type_changesmodified_type_changesadded_type_membersremoved_type_membersmodified_type_membersrQrVrR)rXrrr _reset_diffsH  zTERulesDifference._reset_diffN):rrr__doc__r[rqrr|r}r~rrrrrrsrrrrtrrrrkrurrrrvrrrrwrrrrxrrrroryrrrrzrrrr{rrrrlistrQrRrSrrrrr rpsbrpc@s4eZdZdZdZddZd d Zd d Zd dZdS)rfzEWrap extended permission access vector rules to allow set operations.r/r1r, xperm_typer!cCsH||_t|j|_t|j|_t|j|_|j|_|j|_t||_ dS)N) rbrr/r1rr,rr!hashkey)rXrrrr __init__ s   zAVRuleXpermWrapper.__init__cCs|jS)N)r)rXrrr __hash__szAVRuleXpermWrapper.__hash__cCs |j|jkS)N)r)rXotherrrr __lt__szAVRuleXpermWrapper.__lt__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r/r1r,r)rXrrrr __eq__s   zAVRuleXpermWrapper.__eq__N)r/r1r,rr!) rrrr __slots__rrrrrrrr rfs  rfc@s4eZdZdZdZdd Zd d Zd d ZddZdS)rlz*Wrap type_* rules to allow set operations.r/r1r,r)r*filenamecCs||_t|j|_t|j|_t|j|_t||_yt|j |_ |j |_ Wn t k rld|_ d|_ YnXy |j |_ Wnt tfk rd|_ YnXdS)N)rbrr/r1rr,rrr r)r*rrrr )rXrrrr r)s        zTERuleWrapper.__init__cCs|jS)N)r)rXrrr r<szTERuleWrapper.__hash__cCs |j|jkS)N)r)rXrrrr r?szTERuleWrapper.__lt__cCsH|j|jkoF|j|jkoF|j|jkoF|j|jkoF|j|jkoF|j|jkS)N)r/r1r,r)r*r)rXrrrr rBs      zTERuleWrapper.__eq__N)r/r1r,r)r*r) rrrrrrrrrrrrr rl#s rl)-rU collectionsrrsysrenumrZ exceptionrrr Z policyrepr r r)r Z descriptorsr differencerrr6rrZobjclassrr&r'rHrnrr.r2rTr@rFrMr[r`rkrorprfrlrrrr s@     Z&$01(__pycache__/properties.cpython-36.pyc000064400000002462152534333500013605 0ustar003 ^U @sHddlmZddlmZddlmZeddddgZGd d d eZd S) ) namedtuple)DiffResultDescriptor) DifferenceZmodified_propertypropertyZaddedZremovedc@s(eZdZdZedZddZddZdS)PropertiesDifferencezr Determine the difference in policy properties (unknown permissions, MLS, etc.) between two policies. diff_propertiescCsg|_|jj|jjkr2|jjtd|jj|jj|jj|jjkr^|jjtd|jj|jj|jj|jjkr|jjtd|jj|jjdS)Nhandle_unknownZMLSversion)modified_propertiesZ left_policyr Z right_policyappendmodified_properties_recordZmlsr )selfr"/usr/lib64/python3.6/properties.pyr%s   z$PropertiesDifference.diff_propertiescCs|jjdd|_dS)z%Reset diff results on policy changes.zResetting property differencesN)logdebugr )rrrr _reset_diff=s z PropertiesDifference._reset_diffN)__name__ __module__ __qualname____doc__rr rrrrrrrsrN) collectionsrZ descriptorsr differencerr rrrrrs   __pycache__/ibpkeycon.cpython-36.pyc000064400000005357152534333500013402 0ustar003 ^' @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_ibpkeyconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)IbpkeyconsDifferencez0sz7IbpkeyconsDifference.diff_ibpkeycons..css|]}t|VqdS)N)r )r r r r rr1sN)loginfoformatZ _set_diffZ left_policyZ ibpkeyconsZ right_policyadded_ibpkeyconsremoved_ibpkeyconsmodified_ibpkeyconsrcontextappendmodified_ibpkeycon_record)selfZmatched_ibpkeyconsZ left_ibpkeyZ right_ibpkeyr r rr 's z$IbpkeyconsDifference.diff_ibpkeyconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting ibpkeycon differencesN)rdebugrrr)rr r r _reset_diffAs z IbpkeyconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rrs rc@s4eZdZdZdZddZddZd d Zd d Zd S)r z,Wrap ibpkeycon statements for diff purposes. subnet_prefixlowhighcCs*||_|j|_|j\|_|_t||_dS)N)originr Zpkeysr!r"hashkey)rZoconr r r__init__OszIbpkeyconWrapper.__init__cCs|jS)N)r%)rr r r__hash__UszIbpkeyconWrapper.__hash__cCs |j|jkS)N)r#)rotherr r r__lt__XszIbpkeyconWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r r!r")rr(r r r__eq__[s  zIbpkeyconWrapper.__eq__N)r r!r") rrrr __slots__r&r'r)r*r r r rr Is r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   *__pycache__/types.cpython-36.pyc000064400000006122152534333500012552 0ustar003 ^o @sddlmZmZddlmZddlmZmZddlm Z ddl m Z edd d d d d dddgZ ee ZddZddZGdddeZdS)) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapper)typeattr_wrapper_factory)TypeZ modified_typeZadded_attributesZremoved_attributesZmatched_attributesZmodified_permissiveZ permissive added_aliasesremoved_aliasesmatched_aliasesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap types from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _types_cacheZpolicyKeyErrorr)type_tr/usr/lib64/python3.6/types.pytype_wrapper_factory)s rcCst|trt|St|SdS)z Wrap types or attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) isinstancer rr)rrrrtype_or_attr_wrapper_factory8s rc@s8eZdZdZedZedZedZddZddZ dS)TypesDifferencez7Determine the difference in types between two policies. diff_typesc Cs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x|D]\}}|jdd|j Ddd|j D\}}}|j|j |j dd\}}} |j } |j } | | k} |s|s|s|s| rVt|||| | ||| |j |<qVWd S) z6Generate the difference in types between the policies.zDGenerating type differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr Tsz-TypesDifference.diff_types..css|]}t|VqdS)N)r)rrrrrrUscss|]}t|VqdS)N)r)rarrrr_scss|]}t|VqdS)N)r)rrrrrr`sF)ZunwrapN)loginfoformatZ _set_diffZ left_policytypesZ right_policy added_types removed_typesdictmodified_typesZ attributesaliasesZ ispermissivemodified_types_record) selfZ matched_typesZ left_typeZ right_typeZ added_attrZ removed_attrZ matched_attrr r r Zleft_permissiveZright_permissiveZmod_permissiverrrrMs2   zTypesDifference.diff_typescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting type differencesN)rdebugr r!r#)r&rrr _reset_diffws zTypesDifference._reset_diffN) __name__ __module__ __qualname____doc__rr r!r#rr(rrrrrEs *rN) collectionsrrZ descriptorsr differencerrZtypeattrrZ policyrepr r%r"rrrrrrrrs     __pycache__/__init__.cpython-36.opt-1.pyc000064400000003770152534333500014112 0ustar003 ^ @stddlmZddlmZddlmZddlmZddlm Z ddl m Z ddl m Z ddlmZdd lmZdd lmZdd lmZmZmZdd lmZdd lmZddlmZddlmZddl m!Z!ddl"m#Z#ddl$m%Z%ddl&m'Z'ddl(m)Z)ddl*m+Z+ddl,m-Z-ddl.m/Z/ddl0m1Z1dgZ2Gdddeeeeee e e eeeeeeeee!e#e%e'e)ee+e-e/e1Z3dS))BooleansDifference)BoundsDifference)CommonDifference)ConstraintsDifference)DefaultsDifference)FSUsesDifference)GenfsconsDifference)IbendportconsDifference)IbpkeyconsDifference)InitialSIDsDifference)CategoriesDifferenceLevelDeclsDifferenceSensitivitiesDifference)MLSRulesDifference)NetifconsDifference)NodeconsDifference)ObjClassDifference)PolCapsDifference)PortconsDifference)PropertiesDifference)RBACRulesDifference)RolesDifference)TERulesDifference)TypeAttributesDifference)TypesDifference)UsersDifferencePolicyDifferencec@seZdZdZddZdS)rz Determine the differences from the left policy to the right policy. Parameters: left A policy right A policy cCsxtjD]}|j|qWdS)z%Reset diff results on policy changes.N)r __bases__ _reset_diff)selfcr! /usr/lib64/python3.6/__init__.pyrRs zPolicyDifference._reset_diffN)__name__ __module__ __qualname____doc__rr!r!r!r"r/s!N)4boolrZboundsrZcommonsrZ constraintsrdefaultrZfsuserZgenfsconrZ ibendportconr Z ibpkeyconr Zinitsidr Zmlsr r rZmlsrulesrZnetifconrZnodeconrZobjclassrZpolcaprZportconrZ propertiesrZ rbacrulesrZrolesrZterulesrZtypeattrrtypesrZusersr__all__rr!r!r!r"sd                        __pycache__/ibendportcon.cpython-36.pyc000064400000005376152534333500014106 0ustar003 ^! @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_ibendportconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)IbendportconsDifferencez?Determine the difference in ibendportcons between two policies.diff_ibendportconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z>Generate the difference in ibendportcons between the policies.zLGenerating ibendportcon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)IbendportconWrapper).0nr $/usr/lib64/python3.6/ibendportcon.py 0sz=IbendportconsDifference.diff_ibendportcons..css|]}t|VqdS)N)r )r r r r rr1sN)loginfoformatZ _set_diffZ left_policyZ ibendportconsZ right_policyadded_ibendportconsremoved_ibendportconsmodified_ibendportconsrcontextappendmodified_ibendportcon_record)selfZmatched_ibendportconsZ left_ibepZ right_ibepr r rr 's z*IbendportconsDifference.diff_ibendportconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z"Resetting ibendportcon differencesN)rdebugrrr)rr r r _reset_diffAs z#IbendportconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rrs rc@s4eZdZdZd ZddZddZdd Zd d Zd S)r z/Wrap ibendportcon statements for diff purposes.nameportcCs$||_|j|_|j|_t||_dS)N)originr r!hashkey)rZoconr r r__init__OszIbendportconWrapper.__init__cCs|jS)N)r$)rr r r__hash__UszIbendportconWrapper.__hash__cCs |j|jkS)N)r")rotherr r r__lt__XszIbendportconWrapper.__lt__cCs|j|jko|j|jkS)N)r r!)rr'r r r__eq__[s zIbendportconWrapper.__eq__N)r r!) rrrr __slots__r%r&r(r)r r r rr Is r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   *__pycache__/fsuse.cpython-36.pyc000064400000005215152534333500012535 0ustar003 ^p @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_fsuseruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)FSUsesDifferencez@Determine the difference in fs_use_* rules between two policies. diff_fs_usescCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z=Generate the difference in fs_use rules between the policies.zHGenerating fs_use_* differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N) FSUseWrapper).0fsr/usr/lib64/python3.6/fsuse.py /sz0FSUsesDifference.diff_fs_uses..css|]}t|VqdS)N)r )r r rrrr0sN)loginfoformatZ _set_diffZ left_policyZfs_usesZ right_policy added_fs_usesremoved_fs_usesmodified_fs_usesrcontextappendmodified_fsuse_record)selfZmatchedZ left_ruleZ right_rulerrrr 's  zFSUsesDifference.diff_fs_usescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z#Resetting fs_use_* rule differencesN)rdebugrrr)rrrr _reset_diff?s zFSUsesDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr s r c@s4eZdZdZdZddZddZd d Zd d Zd S)r z,Wrap fs_use_* rules to allow set operations.ruletyper rcCs0||_|j|_|j|_t|j|_t||_dS)N)originr!r rrhashkey)rrrrr__init__Ms  zFSUseWrapper.__init__cCs|jS)N)r$)rrrr__hash__TszFSUseWrapper.__hash__cCs |j|jkS)N)r$)rotherrrr__lt__WszFSUseWrapper.__lt__cCs|j|jko|j|jkS)N)r!r )rr'rrr__eq__ZszFSUseWrapper.__eq__N)r!r r) rrrr __slots__r%r&r(r)rrrrr Gs r N) collectionsrrrZ descriptorsr differencerrrr r rrrrs   (__pycache__/rbacrules.cpython-36.opt-1.pyc000064400000011545152534333500014334 0ustar003 ^@sddlmZmZddlmZddlmZddlmZm Z ddl m Z ddl m Z dd lmZed d d d gZGdddeZGddde ZGddde ZdS)) defaultdict namedtuple) RBACRuletype)DiffResultDescriptor) DifferenceWrapper)class_wrapper_factory)role_wrapper_factory)type_or_attr_wrapper_factoryZmodified_rbacruleruleZ added_defaultZremoved_defaultc@sheZdZdZedZedZedZedZedZ e e Z e e Z ddZddZdd Zd d Zd S) RBACRulesDifferencezs     [__pycache__/properties.cpython-36.opt-1.pyc000064400000002462152534333500014544 0ustar003 ^U @sHddlmZddlmZddlmZeddddgZGd d d eZd S) ) namedtuple)DiffResultDescriptor) DifferenceZmodified_propertypropertyZaddedZremovedc@s(eZdZdZedZddZddZdS)PropertiesDifferencezr Determine the difference in policy properties (unknown permissions, MLS, etc.) between two policies. diff_propertiescCsg|_|jj|jjkr2|jjtd|jj|jj|jj|jjkr^|jjtd|jj|jj|jj|jjkr|jjtd|jj|jjdS)Nhandle_unknownZMLSversion)modified_propertiesZ left_policyr Z right_policyappendmodified_properties_recordZmlsr )selfr"/usr/lib64/python3.6/properties.pyr%s   z$PropertiesDifference.diff_propertiescCs|jjdd|_dS)z%Reset diff results on policy changes.zResetting property differencesN)logdebugr )rrrr _reset_diff=s z PropertiesDifference._reset_diffN)__name__ __module__ __qualname____doc__rr rrrrrrrsrN) collectionsrZ descriptorsr differencerr rrrrrs   __pycache__/initsid.cpython-36.opt-1.pyc000064400000003554152534333500014016 0ustar003 ^ @sVddlmZddlmZddlmZddlmZmZedddgZ Gd d d eZ d S) ) namedtuple)ContextWrapper)DiffResultDescriptor) Difference SymbolWrapperZmodified_initsidZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)InitialSIDsDifferencez:Determine the difference in initsids between two policies.diff_initialsidscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x8|D]0\}}t |j t |j krVt |j |j |j |<qVWdS)z=Generate the difference in initial SIDs between the policies.zKGenerating initial SID differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0ir /usr/lib64/python3.6/initsid.py ,sz9InitialSIDsDifference.diff_initialsids..css|]}t|VqdS)N)r)r r r r r r-sN)loginfoformatZ _set_diffZ left_policyZ initialsidsZ right_policyadded_initialsidsremoved_initialsidsdictmodified_initialsidsrcontextmodified_initsids_record)selfZmatched_initialsidsZleft_initialsidZright_initialsidr r r r %s  z&InitialSIDsDifference.diff_initialsidscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z Resetting initialsid differencesN)rdebugrrr)rr r r _reset_diff;s z!InitialSIDsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r r rs rN) collectionsrrrZ descriptorsr differencerrrrr r r r s   __pycache__/rbacrules.cpython-36.pyc000064400000011545152534333500013375 0ustar003 ^@sddlmZmZddlmZddlmZddlmZm Z ddl m Z ddl m Z dd lmZed d d d gZGdddeZGddde ZGddde ZdS)) defaultdict namedtuple) RBACRuletype)DiffResultDescriptor) DifferenceWrapper)class_wrapper_factory)role_wrapper_factory)type_or_attr_wrapper_factoryZmodified_rbacruleruleZ added_defaultZremoved_defaultc@sheZdZdZedZedZedZedZedZ e e Z e e Z ddZddZdd Zd d Zd S) RBACRulesDifferencezs     [__pycache__/typeattr.cpython-36.opt-1.pyc000064400000005027152534333500014224 0ustar003 ^ @s`ddlmZmZddlmZddlmZmZeddddgZee Z d d Z Gd d d eZ d S)) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapperZmodified_typeattr added_types removed_types matched_typesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap type attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N)_typeattr_cacheZpolicyKeyErrorr)attrar /usr/lib64/python3.6/typeattr.pytypeattr_wrapper_factory!s rc@s8eZdZdZedZedZedZddZddZ dS)TypeAttributesDifferencezADetermine the difference in type attributes between two policies.diff_type_attributescCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xX|D]P\}}|jdd|j Ddd|j D\}}}|s|rVt ||||j |<qVWdS)z@Generate the difference in type attributes between the policies.zNGenerating type attribute differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr Asz@TypeAttributesDifference.diff_type_attributes..css|]}t|VqdS)N)r)rrrrrrBscss|]}t|VqdS)N)r)rtrrrrJscss|]}t|VqdS)N)r)rrrrrrKsN) loginfoformatZ _set_diffZ left_policyZtypeattributesZ right_policyadded_type_attributesremoved_type_attributesdictmodified_type_attributesexpandmodified_typeattr_record)selfZmatched_attributesZleft_attributeZright_attributerr r rrrr8s z-TypeAttributesDifference.diff_type_attributescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z$Resetting type attribute differencesN)rdebugrrr)r!rrr _reset_diffTs z$TypeAttributesDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr#rrrrr0s rN) collectionsrrZ descriptorsr differencerrr rr rrrrrrs __pycache__/descriptors.cpython-36.pyc000064400000002112152534333500013742 0ustar003 ^e@sddlmZGdddZdS))WeakKeyDictionaryc@s2eZdZdZddZd ddZddZd d ZdS) DiffResultDescriptorz%Descriptor for managing diff results.cCs||_t|_dS)N) diff_functionr instances)selfrr#/usr/lib64/python3.6/descriptors.py__init__szDiffResultDescriptor.__init__NcCs:|dkr |S|jj|ddkr0t||j}||j|S)N)r setdefaultgetattrr)robjZobjtypeZdiffrrr__get__%s  zDiffResultDescriptor.__get__cCs||j|<dS)N)r)rr valuerrr__set__/szDiffResultDescriptor.__set__cCsd|j|<dS)N)r)rr rrr __delete__2szDiffResultDescriptor.__delete__)N)__name__ __module__ __qualname____doc__r r rrrrrrrs  rN)weakrefrrrrrrs __pycache__/terules.cpython-36.opt-1.pyc000064400000034376152534333500014044 0ustar003 ^^@spddlZddlmZmZddlmZddlmZddlm Z m Z m Z ddl m Z mZdd lmZdd lmZdd lmZmZdd lmZmZdd lmZedZedZedddddgZeddddgZGdddeZedddgZ edddgZ!ed ddgZ"d!d"Z#d#d$Z$d%d&Z%d'd(Z&d)d*Z'd+d,Z(d-d.Z)Gd/d0d0eZ*Gd1d2d2eZ+Gd3d4d4eZ,dS)5N) defaultdict namedtuple)intern)Enum)RuleNotConditional RuleUseErrorTERuleNoFilename)IoctlSet TERuletype)conditional_wrapper_factory)DiffResultDescriptor) DifferenceWrapper)type_wrapper_factorytype_or_attr_wrapper_factory)class_wrapper_factoryz<>TrueZmodified_avrulerule added_perms removed_perms matched_permsZmodified_teruleZ added_defaultZremoved_defaultc@seZdZdZdZdS)Siderr N)__name__ __module__ __qualname__leftrightrr/usr/lib64/python3.6/terules.pyr-srZrule_db_side_dataperms orig_ruleZ rule_db_sidesrrZType_dbcCs|tjkr|j}n|j}x|D]}t}t}y tt|j}tt|j}Wnt k rbYnX||krt ||<t |||<n|||krt |||<|j j }dd|j D} t| |} |||} x.|jjD]} | j } | |kr| || <| | kr t | | <x|jjD]}|j }||kr4|||<|| | krPt | | |<d}d}|| | |kr| | ||}|j}|j}|tjkr|s| }n|j | B}|j}t||}n&|s| }n|j | B}|j}t||}t||| | ||<qWqWq WdS)aP Using rule_list, build up rule_db which is a data structure which consists of nested dicts that store BOTH the left and the right policies. All of the keys are interned strings. The permissions are stored as a set. The basic structure is rule_db[cond_exp][block_bool][src][tgt][tclass] = sides where: cond_exp is a boolean expression block_bool is either true or false src is the source type tgt is the target type tclass is the target class sides is a named tuple with attributes "left" and "right" referring to the left or right policy. Each attribute in the sides named tuple refers to a named tuple with attributes "perms" and "orig_rule" which refer to a permission set and the original unexpanded rule. sides = ((left_perms, left_orig_rule),(right_perms, right_orig_rule)) There are a few advantages to this structure. First, it takes up way less memory. Second, it allows redundant rules to be easily eliminated. And, third, it makes it easy to create the added, removed, and modified rules. cSsh|]}|qSrr).0prrr csz+_avrule_expand_generator..N)rrrTERULES_UNCONDITIONALTERULES_UNCONDITIONAL_BLOCKrstr conditionalconditional_blockrdicttclassnamer!rule_db_side_data_recordsourceexpandtargetr"rule_db_sides_record) rule_listrule_dbtype_dbZsidetypesunexpanded_rulecond_exp block_boolr,r! side_datablocksrcZsrc_strtgtZtgt_str left_side right_sideZsidesr$Zorigrrr _avrule_expand_generator9sd             r@cCsx|tt}xd|jD]V\}}|tkr,qx@|jD]2\}}x&|jD]\}}||krbqNx|jD]\}} |||krqnx| jD]\} } | |||krq|||| } | j} | j}| jo| r| j| jj@}|r| j|}|rt|| j} nd} t| || | <| jr|r|j| jj@}|r|j|}|rNt||j}nd}t| || | <qWqnWqNWq8WqWdS)N) r&r'itemsrrr!r.r"r2)r4Z uncond_blockr8 cond_blocksr9r;r<src_datar=tgt_datar,r:Zuncond_side_datar>r?cr$rrr _av_remove_redundant_rulessB      rFc Cs|g}g}g}xb|jD]T\}}xH|jD]:\}} x.| jD] \} } x| jD]\} } x| jD]\}}|jr|jr|jj|jj@}|jj|}|jj|}|s|r|jj}|j|j| |j| |jj}|jt||||qn|jr(|jj}|j|j| |j| |jj}|j|qn|jrn|jj}|j|j| |j| |jj}|j|qnWqZWqDWq.WqW|||fS)N)rArrr!r"Zderive_expandedappendmodified_avrule_record)ruletyper4r5addedremovedmodifiedr8rBr9r;r<rCr=rDr,r:Z common_permsZ left_permsZ right_permsZ original_rulerrrr _av_generate_diffssB         rMcstjfdd}|S)z This is a template for the access vector diff functions. Parameters: ruletype The rule type, e.g. "allow". cs|jjdj||j s$|j r,|jttt}t}t|t<t|tt <t jdt |j||t j t jdt |j||t jt jdt|t jdt||\}}}|j j|jj|jt|dj|t|dj|t|dj|d S) z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}zExpanding left policyzExpanding right policyzRemoving redundant rulesz0Generating added, removed, and modified av rulesz added_{0}sz removed_{0}sz modified_{0}sN)loginfoformat_left_te_rules_right_te_rules_create_te_rule_liststype_db_recordr+r&r'loggingr@rrrrFrMclearsetattr)selfr5r4rJrKrL)rIrr diffs.        zav_diff_template..diff)r lookup)rIrYr)rIr av_diff_templates  #r[c Cst}x\|D]T}xN|jD]B}||}y||j|jO_Wqtk rZ|||<YqXqWq W|rtjtjdj|t ||j S)z` Generator that yields wrapped, expanded, av(x) rules with unioned permission sets. z/Expanded {0.ruletype} rules for {0.policy}: {1}) r+r0r!KeyErrorrUZ getLoggerrdebugrPlenkeys)r3Z WrapperClassrAr7Z expanded_ruleZexpanded_wrapped_rulerrr _avxrule_expand_generator s  r`cstjfdd}|S)z This is a template for the extended permission access vector diff functions. Parameters: ruletype The rule type, e.g. "allowxperm". c s|jjdj||j s$|j r,|j|jt|jtt|jtdd\}}}g}x^|D]V\}}|j|j |j dd\}}} |s|rd|j t |j t |t |t dd| DqdWt|djtdd|Dt|djtd d|Dt|d j|d S) z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}F)Zunwrapcss|]}|dVqdS)rNr)r#r$rrr Qsz2avx_diff_template..diff..z added_{0}scss|] }|jVqdS)N)origin)r#arrr raSsz removed_{0}scss|] }|jVqdS)N)rb)r#rrrr raTsz modified_{0}sN)rNrOrPrQrRrS _set_diffr`AVRuleXpermWrapperr!rGrHrbr rWset) rXrJrKmatchedrL left_rule right_rulerrr)rIrr rY3s,    zavx_diff_template..diff)r rZ)rIrYr)rIr avx_diff_template)s  $rkcstjfdd}|S)z This is a template for the type_* diff functions. Parameters: ruletype The rule type, e.g. "type_transition". cs|jjdj||j s$|j r,|j|j|j|jt|j|jt\}}}g}x:|D]2\}}t |j t |j krd|j t ||j |j qdWt |dj|t |dj|t |dj|dS)z6Generate the difference in rules between the policies.zCGenerating {0} differences from {1.left_policy} to {1.right_policy}z added_{0}sz removed_{0}sz modified_{0}sN)rNrOrPrQrRrSreZ_expand_generator TERuleWrapperrdefaultrGmodified_terule_recordrW)rXrJrKrhrLrirj)rIrr rYds" zte_diff_template..diff)r rZ)rIrYr)rIr te_diff_templateZs  roc@seZdZdZedZedZedZedZ edZ edZ edZ edZ edZedZedZedZedZed Zed Zed Zed Zed Zed Zed Zed Zed Zed Zed ZedZedZ edZ!edZ"edZ#edZ$edZ%edZ&e'dZ(edZ)edZ*edZ+e'dZ,edZ-edZ.edZ/e'dZ0edZ1edZ2edZ3e4e5Z6e4e5Z7ddZ8ddZ9dS)TERulesDifferencezV Determine the difference in type enforcement rules between two policies. Zallow diff_allowsZ auditallowdiff_auditallowsZ neverallowdiff_neverallowsZ dontauditdiff_dontauditsZ allowxpermdiff_allowxpermsZauditallowxpermdiff_auditallowxpermsZneverallowxpermdiff_neverallowxpermsZdontauditxpermdiff_dontauditxpermsZtype_transitiondiff_type_transitionsZ type_changediff_type_changesZ type_memberdiff_type_memberscCs|jjdj|x$|jjD]}|j|jj|qWx.|jjD] \}}|jjdjt ||qDW|jjdj|x$|j jD]}|j |jj|qWx.|j jD] \}}|jjdjt ||qW|jjddS)z$Create rule lists for both policies.z+Building TE rule lists from {0.left_policy}zLoaded {0} {1} rules.z,Building TE rule lists from {0.right_policy}z!Completed building TE rule lists.N) rNr]rPZ left_policyZterulesrQrIrGrAr^Z right_policyrR)rXrrIZrulesrrr rSsz'TERulesDifference._create_te_rule_listscCs|jjdd|_d|_d|_d|_d|_d|_d|_d|_ d|_ d|_ d|_ d|_ d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_d|_ d|_!d|_"|j#j$|j%j$dS)z%Reset diff results on policy changes.zResetting TE rule differencesN)&rNr] added_allowsremoved_allowsmodified_allowsadded_auditallowsremoved_auditallowsmodified_auditallowsadded_neverallowsremoved_neverallowsmodified_neverallowsadded_dontauditsremoved_dontauditsmodified_dontauditsadded_allowxpermsremoved_allowxpermsmodified_allowxpermsadded_auditallowxpermsremoved_auditallowxpermsmodified_auditallowxpermsadded_neverallowxpermsremoved_neverallowxpermsmodified_neverallowxpermsadded_dontauditxpermsremoved_dontauditxpermsmodified_dontauditxpermsadded_type_transitionsremoved_type_transitionsmodified_type_transitionsadded_type_changesremoved_type_changesmodified_type_changesadded_type_membersremoved_type_membersmodified_type_membersrQrVrR)rXrrr _reset_diffsH  zTERulesDifference._reset_diffN):rrr__doc__r[rqrr|r}r~rrrrrrsrrrrtrrrrkrurrrrvrrrrwrrrrxrrrroryrrrrzrrrr{rrrrlistrQrRrSrrrrr rpsbrpc@s4eZdZdZdZddZd d Zd d Zd dZdS)rfzEWrap extended permission access vector rules to allow set operations.r/r1r, xperm_typer!cCsH||_t|j|_t|j|_t|j|_|j|_|j|_t||_ dS)N) rbrr/r1rr,rr!hashkey)rXrrrr __init__ s   zAVRuleXpermWrapper.__init__cCs|jS)N)r)rXrrr __hash__szAVRuleXpermWrapper.__hash__cCs |j|jkS)N)r)rXotherrrr __lt__szAVRuleXpermWrapper.__lt__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r/r1r,r)rXrrrr __eq__s   zAVRuleXpermWrapper.__eq__N)r/r1r,rr!) rrrr __slots__rrrrrrrr rfs  rfc@s4eZdZdZdZdd Zd d Zd d ZddZdS)rlz*Wrap type_* rules to allow set operations.r/r1r,r)r*filenamecCs||_t|j|_t|j|_t|j|_t||_yt|j |_ |j |_ Wn t k rld|_ d|_ YnXy |j |_ Wnt tfk rd|_ YnXdS)N)rbrr/r1rr,rrr r)r*rrrr )rXrrrr r)s        zTERuleWrapper.__init__cCs|jS)N)r)rXrrr r<szTERuleWrapper.__hash__cCs |j|jkS)N)r)rXrrrr r?szTERuleWrapper.__lt__cCsH|j|jkoF|j|jkoF|j|jkoF|j|jkoF|j|jkoF|j|jkS)N)r/r1r,r)r*r)rXrrrr rBs      zTERuleWrapper.__eq__N)r/r1r,r)r*r) rrrrrrrrrrrrr rl#s rl)-rU collectionsrrsysrenumrZ exceptionrrr Z policyrepr r r)r Z descriptorsr differencerrr6rrZobjclassrr&r'rHrnrr.r2rTr@rFrMr[r`rkrorprfrlrrrr s@     Z&$01(__pycache__/conditional.cpython-36.pyc000064400000002661152534333500013715 0ustar003 ^@s<ddlmZddlmZeeZddZGdddeZdS) ) defaultdict)Wrapperc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap type attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _cond_cacheZpolicyKeyErrorConditionalWrapper)condar #/usr/lib64/python3.6/conditional.pyconditional_wrapper_factorys r c@s4eZdZdZdZddZddZddZd d Zd S) rzHWrap conditional policy expressions to allow comparisons by truth table. truth_tablecCs||_|j|_dS)N)originr )selfrr r r __init__1szConditionalWrapper.__init__cCs t|jS)N)hashr)rr r r __hash__5szConditionalWrapper.__hash__cCs |j|jkS)N)r )rotherr r r __eq__8szConditionalWrapper.__eq__cCst|jt|kS)N)strr)rrr r r __lt__;szConditionalWrapper.__lt__N) __name__ __module__ __qualname____doc__ __slots__rrrrr r r r r+s rN) collectionsr differencerdictrr rr r r r s  __pycache__/constraints.cpython-36.pyc000064400000016032152534333500013756 0ustar003 ^"@stddlmZddlmZddlmZddlmZmZm Z ddl m Z ddl m Z Gd d d eZGd d d e Zd S)) namedtuple)ConstraintRuletype)DiffResultDescriptor) Difference SymbolWrapperWrapper)class_wrapper_factory)type_wrapper_factoryc@seZdZdZedZedZedZedZedZ edZ edZ edZ dZ dZdZdZdZdZdZdZddZd d Zd d Zd dZddZddZdS)ConstraintsDifferencea Determine the difference in constraints between two policies. Since the compiler does not union constraints, there may be multiple constraints with the same ruletype, object class, and permission set, so constraints can only be added or removed, not modified. The constraint expressions are compared only on a basic level. Expressions that are logically equivalent but are structurally different, for example, by associativity, will be considered different. Type and role attributes are also not expanded, so if there are changes to attribute members, it will not be reflected as a difference. diff_constrainsdiff_mlsconstrainsdiff_validatetransdiff_mlsvalidatetransNcCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zAGenerate the difference in constraint rules between the policies.zJGenerating constraint differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)ConstraintWrapper).0cr#/usr/lib64/python3.6/constraints.py Qsz8ConstraintsDifference.diff_constrains..css|]}t|VqdS)N)r)rrrrrrRs) loginfoformat_left_constrains_right_constrains_create_constrain_lists _set_diffadded_constrainsremoved_constrains)self_rrrr Gs z%ConstraintsDifference.diff_constrainscCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zEGenerate the difference in MLS constraint rules between the policies.zNGenerating MLS constraint differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)r)rrrrrr_sz;ConstraintsDifference.diff_mlsconstrains..css|]}t|VqdS)N)r)rrrrrr`s) rrr_left_mlsconstrains_right_mlsconstrainsrradded_mlsconstrainsremoved_mlsconstrains)r r!rrrrTsz(ConstraintsDifference.diff_mlsconstrainscCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zDGenerate the difference in validatetrans rules between the policies.zMGenerating validatetrans differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)r)rrrrrrmsz;ConstraintsDifference.diff_validatetrans..css|]}t|VqdS)N)r)rrrrrrns) rrr_left_validatetrans_right_validatetransrradded_validatetransremoved_validatetrans)r r!rrrrbsz(ConstraintsDifference.diff_validatetranscCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zHGenerate the difference in MLS validatetrans rules between the policies.zPGenerating mlsvalidatetrans differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)r)rrrrrr{sz>ConstraintsDifference.diff_mlsvalidatetrans..css|]}t|VqdS)N)r)rrrrrr|s) rrr_left_mlsvalidatetrans_right_mlsvalidatetransrradded_mlsvalidatetransremoved_mlsvalidatetrans)r r!rrrrpsz+ConstraintsDifference.diff_mlsvalidatetranscCsZg|_g|_g|_g|_x|jjD]}|jtjkrB|jj |q$|jtj kr\|jj |q$|jtj krv|jj |q$|jtj kr|jj |q$|j jdj|jq$Wg|_g|_g|_g|_x|jjD]}|jtjkr|jj |q|jtj kr|jj |q|jtj kr"|jj |q|jtj kr>|jj |q|j jdj|jqWdS)z$Create rule lists for both policies.z/Unknown rule type: {0} (This is an SETools bug)N)rr"r&r*Z left_policyZ constraintsruletyperZ constrainappendZ mlsconstrainZ validatetransZmlsvalidatetransrerrorrrr#r'r+Z right_policy)r rulerrrrs<       z-ConstraintsDifference._create_constrain_listscCsp|jjdd|_d|_d|_d|_d|_d|_d|_d|_ d|_ d|_ d|_ d|_ d|_d|_d|_d|_dS)z%Reset diff results on policy changes.z%Resetting all constraints differencesN)rdebugrrr$r%r(r)r,r-rr"r&r*rr#r'r+)r rrr _reset_diffs" z!ConstraintsDifference._reset_diff)__name__ __module__ __qualname____doc__rrrr$r%r(r)r,r-rrr"r#r&r'r*r+r rrrrr3rrrrr s. $r c@s4eZdZdZdZddZdd Zd d Zd d ZdS)rz#Wrap constraints for diff purposes.r.tclasspermsexprc Cs||_|j|_t|j|_y |j|_Wntk r@d|_YnXt||_g|_x@|j D]6}t |t r|jj t dd|DqZ|jj |qZWdS)Ncss|]}t|VqdS)N)r)ritemrrrrsz-ConstraintWrapper.__init__..) originr.r r8r9AttributeErrorhashkeyr:Z expression isinstance frozensetr/)r r1oprrr__init__s      zConstraintWrapper.__init__cCs|jS)N)r?)r rrr__hash__szConstraintWrapper.__hash__cCs |j|jkS)N)r?)r otherrrr__lt__szConstraintWrapper.__lt__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r.r8r9r:)r rErrr__eq__s   zConstraintWrapper.__eq__N)r.r8r9r:) r4r5r6r7 __slots__rCrDrFrGrrrrrs rN) collectionsrZ policyreprZ descriptorsr differencerrr Zobjclassr typesr r rrrrrs      __pycache__/roles.cpython-36.opt-1.pyc000064400000004615152534333500013476 0ustar003 ^ @slddlmZmZddlmZddlmZmZddlm Z edddd gZ ee Z d d Z Gd d d eZdS)) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapper)type_wrapper_factoryZ modified_role added_types removed_types matched_typesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap roles from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _roles_cacheZpolicyKeyErrorr)Zrolerr/usr/lib64/python3.6/roles.pyrole_wrapper_factory"s rc@s8eZdZdZedZedZedZddZddZ dS)RolesDifferencez7Determine the difference in roles between two policies. diff_rolescCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xX|D]P\}}|jdd|j Ddd|j D\}}}|s|rVt ||||j |<qVWdS)z6Generate the difference in roles between the policies.zDGenerating role differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr @sz-RolesDifference.diff_roles..css|]}t|VqdS)N)r)rrrrrrAscss|]}t|VqdS)N)r)rtrrrrJscss|]}t|VqdS)N)r)rrrrrrKsN) loginfoformatZ _set_diffZ left_policyZrolesZ right_policy added_roles removed_rolesdictmodified_rolestypesmodified_roles_record)selfZ matched_rolesZ left_roleZ right_roler r r rrrr9s  zRolesDifference.diff_rolescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting role differencesN)rdebugrrr)r rrr _reset_diffUs zRolesDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr"rrrrr1s rN) collectionsrrZ descriptorsr differencerrrrrrr rrrrrrs  __pycache__/bool.cpython-36.pyc000064400000004177152534333500012351 0ustar003 ^R @s^ddlmZmZddlmZddlmZmZedddgZee Z dd Z Gd d d eZ d S) ) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapperZmodified_booleanZ added_stateZ removed_statec Cs:y t||Stk r4t|}|t||<|SXdS)z Wrap booleans from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _bool_cacheKeyErrorr)ZpolicyZbooleanbr /usr/lib64/python3.6/bool.pyboolean_wrappers   r c@s8eZdZdZedZedZedZddZddZ dS)BooleansDifferencezADetermine the difference in type attributes between two policies. diff_booleanscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x0|D](\}}|j |j krVt |j |j |j |<qVWdS)z@Generate the difference in type attributes between the policies.zGGenerating Boolean differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0r r r r >sz3BooleansDifference.diff_booleans..css|]}t|VqdS)N)r)rr r r r r?sN) loginfoformatZ _set_diffZ left_policyZboolsZ right_policyadded_booleansremoved_booleansdictmodified_booleansstatemodified_bool_record)selfZmatched_booleansZ left_booleanZ right_booleanr r r r6s   z BooleansDifference.diff_booleanscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting Boolean differencesN)rdebugrrr)rr r r _reset_diffMs zBooleansDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrrr r r r r.s rN) collectionsrrZ descriptorsr differencerrrrrr rr r r r s  __pycache__/difference.cpython-36.pyc000064400000011776152534333500013513 0ustar003 ^@sdddlZddlmZmZddlmZedddgZGdddZGd d d eZGd d d eZ dS) N)ABCabstractmethod) namedtupleZ modified_itemleftrightc@sneZdZdZddZeddZejddZeddZejd dZd d Z e d d Z e dddZ dS) Differencez&Base class for all policy differences.cCstjt|_||_||_dS)N)loggingZ getLogger__name__log left_policy right_policy)selfr r r"/usr/lib64/python3.6/difference.py__init__s zDifference.__init__cCs|jS)N) _left_policy)r rrrr 'szDifference.left_policycCs$|jjdj|||_|jdS)Nz"Policy diff left policy set to {0})r infoformatr _reset_diff)r policyrrrr +scCs|jS)N) _right_policy)r rrrr 1szDifference.right_policycCs$|jjdj|||_|jdS)Nz#Policy diff right policy set to {0})r rrrr)r rrrrr 5scCstdS)z%Reset diff results on policy changes.N)NotImplementedError)r rrrr>szDifference._reset_diffccs.x(|D] }x|jD]}||VqWqWdS)z4Generator that yields a wrapped, expanded rule list.N)expand)Z rule_listWrapperZunexpanded_ruleZ expanded_rulerrr_expand_generatorBs zDifference._expand_generatorNTc Cst|}t|}||}||}t}t|||d} t|||d} t| t| ksntdjt| t| xsz'Difference._set_diff..css|] }|jVqdS)N)r)rrrrrrscss|]\}}|j|jfVqdS)N)r)rrrrrrrsN)setsortedlenAssertionErrorrzipadd) rrrZunwrapZ left_itemsZ right_itemsZ added_itemsZ removed_itemsZ matched_itemsZleft_matched_itemsZright_matched_itemsrrr _set_diffLs(  zDifference._set_diff)NT) r __module__ __qualname____doc__rpropertyr setterr r staticmethodrr&rrrrrs    rc@sHeZdZdZdZddZeddZedd Zed d Z d d Z dS)rz/Abstract base class for policy object wrappers.rrcCsdj|t|jS)Nz&<{0.__class__.__name__}(Wrapping {1})>)rreprr)r rrr__repr__szWrapper.__repr__cCsdS)Nr)r rrr__hash__szWrapper.__hash__cCsdS)Nr)r otherrrr__eq__szWrapper.__eq__cCsdS)Nr)r r0rrr__lt__szWrapper.__lt__cCs ||k S)Nr)r r0rrr__ne__szWrapper.__ne__N)rr) r r'r(r) __slots__r.rr/r1r2r3rrrrrs   rc@s4eZdZdZdZddZddZddZd d Zd S) SymbolWrapperz General wrapper for policy symbols, e.g. types, roles to provide a diff-specific equality operation based on its name. namecCs ||_t||_t|j|_dS)N)rstrr6hashr)r Zsymbolrrrrs zSymbolWrapper.__init__cCs|jS)N)r)r rrrr/szSymbolWrapper.__hash__cCs |j|jkS)N)r6)r r0rrrr2szSymbolWrapper.__lt__cCs |j|jkS)N)r6)r r0rrrr1szSymbolWrapper.__eq__N) r r'r(r)r4rr/r2r1rrrrr5s r5) rabcrr collectionsrZmodified_item_recordrrr5rrrrs  k__pycache__/commons.cpython-36.pyc000064400000003512152534333500013061 0ustar003 ^C @sLddlmZddlmZddlmZmZeddddgZGd d d eZd S) ) namedtuple)DiffResultDescriptor) Difference SymbolWrapperZmodified_common added_perms removed_perms matched_permsc@s8eZdZdZedZedZedZddZddZ dS)CommonDifferencezV Determine the difference in common permission sets between two policies. diff_commonscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xD|D]<\}}|j|j |j dd\}}}|s|rVt ||||j |<qVWdS)z8Generate the difference in commons between the policies.zFGenerating common differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0cr/usr/lib64/python3.6/commons.py 0sz0CommonDifference.diff_commons..css|]}t|VqdS)N)r)r r rrrr1sF)ZunwrapN) loginfoformatZ _set_diffZ left_policyZcommonsZ right_policy added_commonsremoved_commonsdictmodified_commonsZpermsmodified_commons_record)selfZmatched_commonsZ left_commonZ right_commonrrr rrrr )s  zCommonDifference.diff_commonscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting common differencesN)rdebugrrr)rrrr _reset_diffDs zCommonDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr s r N) collectionsrZ descriptorsr differencerrrr rrrrs  __pycache__/genfscon.cpython-36.pyc000064400000005352152534333500013214 0ustar003 ^ @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_genfsruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)GenfsconsDifferencez@Determine the difference in genfscon rules between two policies.diff_genfsconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z?Generate the difference in genfscon rules between the policies.zHGenerating genfscon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)GenfsconWrapper).0fsr /usr/lib64/python3.6/genfscon.py /sz5GenfsconsDifference.diff_genfscons..css|]}t|VqdS)N)r )r r rrrr0sN)loginfoformatZ _set_diffZ left_policyZ genfsconsZ right_policyadded_genfsconsremoved_genfsconsmodified_genfsconsrcontextappendmodified_genfs_record)selfZmatchedZ left_ruleZ right_rulerrrr 's  z"GenfsconsDifference.diff_genfsconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z#Resetting genfscon rule differencesN)rdebugrrr)rrrr _reset_diff?s zGenfsconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr s r c@s4eZdZdZdZddZdd Zd d Zd d ZdS)r z,Wrap genfscon rules to allow set operations.r pathfiletypercCs8||_|j|_|j|_|j|_t|j|_t||_dS)N)originr r!r"rrhashkey)rrrrr__init__Ms  zGenfsconWrapper.__init__cCs|jS)N)r%)rrrr__hash__UszGenfsconWrapper.__hash__cCs |j|jkS)N)r%)rotherrrr__lt__XszGenfsconWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r r!r")rr(rrr__eq__[s  zGenfsconWrapper.__eq__N)r r!r"r) rrrr __slots__r&r'r)r*rrrrr Gs r N) collectionsrrrZ descriptorsr differencerrrr r rrrrs   (__pycache__/typeattr.cpython-36.pyc000064400000005027152534333500013265 0ustar003 ^ @s`ddlmZmZddlmZddlmZmZeddddgZee Z d d Z Gd d d eZ d S)) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapperZmodified_typeattr added_types removed_types matched_typesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap type attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N)_typeattr_cacheZpolicyKeyErrorr)attrar /usr/lib64/python3.6/typeattr.pytypeattr_wrapper_factory!s rc@s8eZdZdZedZedZedZddZddZ dS)TypeAttributesDifferencezADetermine the difference in type attributes between two policies.diff_type_attributescCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xX|D]P\}}|jdd|j Ddd|j D\}}}|s|rVt ||||j |<qVWdS)z@Generate the difference in type attributes between the policies.zNGenerating type attribute differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr Asz@TypeAttributesDifference.diff_type_attributes..css|]}t|VqdS)N)r)rrrrrrBscss|]}t|VqdS)N)r)rtrrrrJscss|]}t|VqdS)N)r)rrrrrrKsN) loginfoformatZ _set_diffZ left_policyZtypeattributesZ right_policyadded_type_attributesremoved_type_attributesdictmodified_type_attributesexpandmodified_typeattr_record)selfZmatched_attributesZleft_attributeZright_attributerr r rrrr8s z-TypeAttributesDifference.diff_type_attributescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z$Resetting type attribute differencesN)rdebugrrr)r!rrr _reset_diffTs z$TypeAttributesDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr#rrrrr0s rN) collectionsrrZ descriptorsr differencerrr rr rrrrrrs __pycache__/difference.cpython-36.opt-1.pyc000064400000011522152534333500014437 0ustar003 ^@sdddlZddlmZmZddlmZedddgZGdddZGd d d eZGd d d eZ dS) N)ABCabstractmethod) namedtupleZ modified_itemleftrightc@sneZdZdZddZeddZejddZeddZejd dZd d Z e d d Z e dddZ dS) Differencez&Base class for all policy differences.cCstjt|_||_||_dS)N)loggingZ getLogger__name__log left_policy right_policy)selfr r r"/usr/lib64/python3.6/difference.py__init__s zDifference.__init__cCs|jS)N) _left_policy)r rrrr 'szDifference.left_policycCs$|jjdj|||_|jdS)Nz"Policy diff left policy set to {0})r infoformatr _reset_diff)r policyrrrr +scCs|jS)N) _right_policy)r rrrr 1szDifference.right_policycCs$|jjdj|||_|jdS)Nz#Policy diff right policy set to {0})r rrrr)r rrrrr 5scCstdS)z%Reset diff results on policy changes.N)NotImplementedError)r rrrr>szDifference._reset_diffccs.x(|D] }x|jD]}||VqWqWdS)z4Generator that yields a wrapped, expanded rule list.N)expand)Z rule_listWrapperZunexpanded_ruleZ expanded_rulerrr_expand_generatorBs zDifference._expand_generatorNTc Cst|}t|}||}||}t}t|||d} t|||d} x$t| | D]\}}|j||fqRW|rtdd|Dtdd|Dtdd|DfS|||fSdS)a Standard diff of two sets. Parameters: left An iterable right An iterable Return: tuple (added, removed, matched) added Set of items in right but not left removed Set of items in left but not right matched Set of items in both left and right. This is in the form of tuples with the matching item from left and right )keycss|] }|jVqdS)N)origin).0irrr sz'Difference._set_diff..css|] }|jVqdS)N)r)rrrrrrscss|]\}}|j|jfVqdS)N)r)rrrrrrrsN)setsortedzipadd) rrrZunwrapZ left_itemsZ right_itemsZ added_itemsZ removed_itemsZ matched_itemsZleft_matched_itemsZright_matched_itemsrrr _set_diffLszDifference._set_diff)NT) r __module__ __qualname____doc__rpropertyr setterr r staticmethodrr$rrrrrs    rc@sHeZdZdZdZddZeddZedd Zed d Z d d Z dS)rz/Abstract base class for policy object wrappers.rrcCsdj|t|jS)Nz&<{0.__class__.__name__}(Wrapping {1})>)rreprr)r rrr__repr__szWrapper.__repr__cCsdS)Nr)r rrr__hash__szWrapper.__hash__cCsdS)Nr)r otherrrr__eq__szWrapper.__eq__cCsdS)Nr)r r.rrr__lt__szWrapper.__lt__cCs ||k S)Nr)r r.rrr__ne__szWrapper.__ne__N)rr) r r%r&r' __slots__r,rr-r/r0r1rrrrrs   rc@s4eZdZdZdZddZddZddZd d Zd S) SymbolWrapperz General wrapper for policy symbols, e.g. types, roles to provide a diff-specific equality operation based on its name. namecCs ||_t||_t|j|_dS)N)rstrr4hashr)r Zsymbolrrrrs zSymbolWrapper.__init__cCs|jS)N)r)r rrrr-szSymbolWrapper.__hash__cCs |j|jkS)N)r4)r r.rrrr0szSymbolWrapper.__lt__cCs |j|jkS)N)r4)r r.rrrr/szSymbolWrapper.__eq__N) r r%r&r'r2rr-r0r/rrrrr3s r3) rabcrr collectionsrZmodified_item_recordrrr3rrrrs  k__pycache__/constraints.cpython-36.opt-1.pyc000064400000016032152534333500014715 0ustar003 ^"@stddlmZddlmZddlmZddlmZmZm Z ddl m Z ddl m Z Gd d d eZGd d d e Zd S)) namedtuple)ConstraintRuletype)DiffResultDescriptor) Difference SymbolWrapperWrapper)class_wrapper_factory)type_wrapper_factoryc@seZdZdZedZedZedZedZedZ edZ edZ edZ dZ dZdZdZdZdZdZdZddZd d Zd d Zd dZddZddZdS)ConstraintsDifferencea Determine the difference in constraints between two policies. Since the compiler does not union constraints, there may be multiple constraints with the same ruletype, object class, and permission set, so constraints can only be added or removed, not modified. The constraint expressions are compared only on a basic level. Expressions that are logically equivalent but are structurally different, for example, by associativity, will be considered different. Type and role attributes are also not expanded, so if there are changes to attribute members, it will not be reflected as a difference. diff_constrainsdiff_mlsconstrainsdiff_validatetransdiff_mlsvalidatetransNcCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zAGenerate the difference in constraint rules between the policies.zJGenerating constraint differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)ConstraintWrapper).0cr#/usr/lib64/python3.6/constraints.py Qsz8ConstraintsDifference.diff_constrains..css|]}t|VqdS)N)r)rrrrrrRs) loginfoformat_left_constrains_right_constrains_create_constrain_lists _set_diffadded_constrainsremoved_constrains)self_rrrr Gs z%ConstraintsDifference.diff_constrainscCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zEGenerate the difference in MLS constraint rules between the policies.zNGenerating MLS constraint differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)r)rrrrrr_sz;ConstraintsDifference.diff_mlsconstrains..css|]}t|VqdS)N)r)rrrrrr`s) rrr_left_mlsconstrains_right_mlsconstrainsrradded_mlsconstrainsremoved_mlsconstrains)r r!rrrrTsz(ConstraintsDifference.diff_mlsconstrainscCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zDGenerate the difference in validatetrans rules between the policies.zMGenerating validatetrans differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)r)rrrrrrmsz;ConstraintsDifference.diff_validatetrans..css|]}t|VqdS)N)r)rrrrrrns) rrr_left_validatetrans_right_validatetransrradded_validatetransremoved_validatetrans)r r!rrrrbsz(ConstraintsDifference.diff_validatetranscCs`|jjdj||jdks&|jdkr.|j|jdd|jDdd|jD\|_|_}dS)zHGenerate the difference in MLS validatetrans rules between the policies.zPGenerating mlsvalidatetrans differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N)r)rrrrrr{sz>ConstraintsDifference.diff_mlsvalidatetrans..css|]}t|VqdS)N)r)rrrrrr|s) rrr_left_mlsvalidatetrans_right_mlsvalidatetransrradded_mlsvalidatetransremoved_mlsvalidatetrans)r r!rrrrpsz+ConstraintsDifference.diff_mlsvalidatetranscCsZg|_g|_g|_g|_x|jjD]}|jtjkrB|jj |q$|jtj kr\|jj |q$|jtj krv|jj |q$|jtj kr|jj |q$|j jdj|jq$Wg|_g|_g|_g|_x|jjD]}|jtjkr|jj |q|jtj kr|jj |q|jtj kr"|jj |q|jtj kr>|jj |q|j jdj|jqWdS)z$Create rule lists for both policies.z/Unknown rule type: {0} (This is an SETools bug)N)rr"r&r*Z left_policyZ constraintsruletyperZ constrainappendZ mlsconstrainZ validatetransZmlsvalidatetransrerrorrrr#r'r+Z right_policy)r rulerrrrs<       z-ConstraintsDifference._create_constrain_listscCsp|jjdd|_d|_d|_d|_d|_d|_d|_d|_ d|_ d|_ d|_ d|_ d|_d|_d|_d|_dS)z%Reset diff results on policy changes.z%Resetting all constraints differencesN)rdebugrrr$r%r(r)r,r-rr"r&r*rr#r'r+)r rrr _reset_diffs" z!ConstraintsDifference._reset_diff)__name__ __module__ __qualname____doc__rrrr$r%r(r)r,r-rrr"r#r&r'r*r+r rrrrr3rrrrr s. $r c@s4eZdZdZdZddZdd Zd d Zd d ZdS)rz#Wrap constraints for diff purposes.r.tclasspermsexprc Cs||_|j|_t|j|_y |j|_Wntk r@d|_YnXt||_g|_x@|j D]6}t |t r|jj t dd|DqZ|jj |qZWdS)Ncss|]}t|VqdS)N)r)ritemrrrrsz-ConstraintWrapper.__init__..) originr.r r8r9AttributeErrorhashkeyr:Z expression isinstance frozensetr/)r r1oprrr__init__s      zConstraintWrapper.__init__cCs|jS)N)r?)r rrr__hash__szConstraintWrapper.__hash__cCs |j|jkS)N)r?)r otherrrr__lt__szConstraintWrapper.__lt__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r.r8r9r:)r rErrr__eq__s   zConstraintWrapper.__eq__N)r.r8r9r:) r4r5r6r7 __slots__rCrDrFrGrrrrrs rN) collectionsrZ policyreprZ descriptorsr differencerrr Zobjclassr typesr r rrrrrs      __pycache__/portcon.cpython-36.opt-1.pyc000064400000005266152534333500014041 0ustar003 ^ @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_portconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)PortconsDifferencez:Determine the difference in portcons between two policies. diff_portconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z9Generate the difference in portcons between the policies.zGGenerating portcon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)PortconWrapper).0nr /usr/lib64/python3.6/portcon.py .sz3PortconsDifference.diff_portcons..css|]}t|VqdS)N)r )r r r r rr/sN)loginfoformatZ _set_diffZ left_policyZportconsZ right_policyadded_portconsremoved_portconsmodified_portconsrcontextappendmodified_portcon_record)selfZmatched_portconsZ left_portconZ right_portconr r rr 's   z PortconsDifference.diff_portconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting portcon differencesN)rdebugrrr)rr r r _reset_diff>s zPortconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rrs rc@s4eZdZdZdZddZddZd d Zd d Zd S)r z*Wrap portcon statements for diff purposes.protocollowhighcCs*||_|j|_|j\|_|_t||_dS)N)originr Zportsr!r"hashkey)rZoconr r r__init__LszPortconWrapper.__init__cCs|jS)N)r%)rr r r__hash__RszPortconWrapper.__hash__cCs |j|jkS)N)r#)rotherr r r__lt__UszPortconWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r r!r")rr(r r r__eq__Xs  zPortconWrapper.__eq__N)r r!r") rrrr __slots__r&r'r)r*r r r rr Fs r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   '__pycache__/mlsrules.cpython-36.opt-1.pyc000064400000006634152534333500014223 0ustar003 ^4@sddlmZmZddlmZddlmZddlmZm Z ddl m Z ddl m Z dd lmZed d d d gZGdddeZGddde ZdS)) defaultdict namedtuple) MLSRuletype)DiffResultDescriptor) DifferenceWrapper) RangeWrapper)class_wrapper_factory)type_or_attr_wrapper_factoryZmodified_mlsruleruleZ added_defaultZremoved_defaultc@sPeZdZdZedZedZedZee Z ee Z ddZ ddZ ddZd S) MLSRulesDifferencez;Determine the difference in MLS rules between two policies.diff_range_transitionscCs|jjdj||j s"|j r*|j|j|j|jtj t |j|jtj t \}}}g}x:|D]2\}}t |j t |j krf|j t||j |j qfW||_||_||_dS)zGGenerate the difference in range_transition rules between the policies.zPGenerating range_transition differences from {0.left_policy} to {0.right_policy}N)loginfoformat_left_mls_rules_right_mls_rules_create_mls_rule_listsZ _set_diffZ_expand_generatorrZrange_transitionMLSRuleWrapperr defaultappendmodified_mlsrule_recordadded_range_transitionsremoved_range_transitionsmodified_range_transitions)selfZaddedZremovedZmatchedZmodifiedZ left_ruleZ right_ruler /usr/lib64/python3.6/mlsrules.pyr/s&z)MLSRulesDifference.diff_range_transitionscCs|jjdj|x$|jjD]}|j|jj|qW|jjdj|x$|jjD]}|j |jj|qVW|jjddS)z$Create rule lists for both policies.z,Building MLS rule lists from {0.left_policy}z-Building MLS rule lists from {0.right_policy}z"Completed building MLS rule lists.N) rdebugrZ left_policyZmlsrulesrruletyperZ right_policyr)rr rrrrPsz)MLSRulesDifference._create_mls_rule_listscCs6|jjdd|_d|_d|_|jj|jjdS)z%Reset diff results on policy changes.zResetting MLS rule differencesN)rr rrrrclearr)rrrr _reset_diff^s   zMLSRulesDifference._reset_diffN)__name__ __module__ __qualname____doc__rrrrrlistrrrrr#rrrrr#s!rc@s4eZdZdZdZddZdd Zd d Zd d ZdS)rz'Wrap MLS rules to allow set operations.r!sourcetargettclasscCs8||_t|j|_t|j|_t|j|_t||_dS)N)originr r)r*r r+hashkey)rr rrr__init__ps    zMLSRuleWrapper.__init__cCs|jS)N)r.)rrrr__hash__wszMLSRuleWrapper.__hash__cCs |j|jkS)N)r.)rotherrrr__lt__zszMLSRuleWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r)r*r+)rr1rrr__eq__}s  zMLSRuleWrapper.__eq__N)r!r)r*r+) r$r%r&r' __slots__r/r0r2r3rrrrrjs rN) collectionsrrrZ descriptorsr differencerr Zmlsr Zobjclassr typesr rrrrrrrs     G__pycache__/mls.cpython-36.opt-1.pyc000064400000021166152534333500013145 0ustar003 ^B)@sddlmZmZddlmZddlmZmZmZeddddgZ ed dddgZ ed d d d dgZ ee Z ee ZddZddZGdddeZGdddeZGdddeZGdddeZGdddeZGdddeZdS) ) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapperWrapperZmodified_category added_aliasesremoved_aliasesmatched_aliasesZmodified_sensitivityZmodified_levelleveladded_categoriesremoved_categoriesmatched_categoriesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap category from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _cats_cachepolicyKeyErrorr)categorycr/usr/lib64/python3.6/mls.pycategory_wrapper_factory+s rc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap sensitivity from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _sens_cacherrr) sensitivityrrrrsensitivity_wrapper_factory:s rc@s8eZdZdZedZedZedZddZddZ dS)CategoriesDifferencezXsz7CategoriesDifference.diff_categories..css|]}t|VqdS)N)r)rrrrrrYsF)unwrapN) loginfoformat _set_diff left_policy categories right_policyr rdictmodified_categoriesaliasesmodified_cat_record)selfrZ left_categoryZright_categoryr r r rrrrQs  z$CategoriesDifference.diff_categoriescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting category differencesN)r debugr rr()r+rrr _reset_diffks z CategoriesDifference._reset_diffN) __name__ __module__ __qualname____doc__rr rr(rr-rrrrrIs rc@s8eZdZdZedZedZedZddZddZ dS)SensitivitiesDifferencez?Determine the difference in sensitivities between two policies.diff_sensitivitiescCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xH|D]@\}}|j|j |j dd\}}}|s|rVt ||||j |<qVWdS)z>Generate the difference in sensitivities between the policies.zKGenerating sensitivity differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r)rsrrrrsz=SensitivitiesDifference.diff_sensitivities..css|]}t|VqdS)N)r)rr4rrrrsF)rN) r r!r"r#r$Z sensitivitiesr&added_sensitivitiesremoved_sensitivitiesr'modified_sensitivitiesr)modified_sens_record)r+Zmatched_sensitivitiesZ left_sensZ right_sensr r r rrrr3{s z*SensitivitiesDifference.diff_sensitivitiescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z!Resetting sensitivity differencesN)r r,r5r6r7)r+rrrr-s z#SensitivitiesDifference._reset_diffN) r.r/r0r1rr5r6r7r3r-rrrrr2ss r2c@s8eZdZdZedZedZedZddZddZ dS)LevelDeclsDifferencez8Determine the difference in levels between two policies. diff_levelscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x\|D]T\}}|jdd|j Ddd|j D\}}}|s|rT|j j t ||||qTWdS)z7Generate the difference in levels between the policies.zJGenerating level decl differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)LevelDeclWrapper)rr4rrrrsz3LevelDeclsDifference.diff_levels..css|]}t|VqdS)N)r;)rr4rrrrscss|]}t|VqdS)N)r)rrrrrrscss|]}t|VqdS)N)r)rrrrrrsN) r r!r"r#r$Zlevelsr& added_levelsremoved_levelsmodified_levelsr%appendmodified_level_record)r+Zmatched_levelsZ left_levelZ right_levelr rrrrrr:s z LevelDeclsDifference.diff_levelscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z!Resetting sensitivity differencesN)r r,r<r=r>)r+rrrr-s z LevelDeclsDifference._reset_diffN) r.r/r0r1rr<r=r>r:r-rrrrr9s r9c@s4eZdZdZdZddZddZddZd d Zd S) r;z-Wrap level declarations to allow comparisons.rcCs ||_t|j|_t||_dS)N)originrrhashkey)r+r rrr__init__s zLevelDeclWrapper.__init__cCs|jS)N)rC)r+rrr__hash__szLevelDeclWrapper.__hash__cCs |j|jkS)N)r)r+otherrrr__eq__szLevelDeclWrapper.__eq__cCs |j|jkS)N)r)r+rFrrr__lt__szLevelDeclWrapper.__lt__N) r.r/r0r1 __slots__rDrErGrHrrrrr;s r;c@s4eZdZdZd ZddZddZdd Zd d Zd S) LevelWrapperz!Wrap levels to allow comparisons.rr%cCs.||_t|j|_tdd|jD|_dS)Ncss|]}t|VqdS)N)r)rrrrrrsz(LevelWrapper.__init__..)rArrsetr%)r+r rrrrDs zLevelWrapper.__init__cCs t|jS)N)rBrA)r+rrrrEszLevelWrapper.__hash__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rr%AttributeError)r+rFrrrrGs   zLevelWrapper.__eq__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rr%rL)r+rFrrrrHs   zLevelWrapper.__lt__N)rr%) r.r/r0r1rIrDrErGrHrrrrrJs  rJc@s4eZdZdZd ZddZddZdd Zd d Zd S) RangeWrapperz Wrap ranges to allow comparisons. This only compares the low and high levels of the range. It does not detect additions/removals/modifications to levels between the low and high levels of the range. lowhighcCs"||_t|j|_t|j|_dS)N)rArJrNrO)r+Zrange_rrrrDs zRangeWrapper.__init__cCs t|jS)N)rBrA)r+rrrrEszRangeWrapper.__hash__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rNrOrL)r+rFrrrrGs   zRangeWrapper.__eq__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rNrOrL)r+rFrrrrH s   zRangeWrapper.__lt__N)rNrO) r.r/r0r1rIrDrErGrHrrrrrMs  rMN) collectionsrrZ descriptorsr differencerrrr*r8r@r'rrrrrr2r9r;rJrMrrrrs, *,,!__pycache__/ibendportcon.cpython-36.opt-1.pyc000064400000005376152534333500015045 0ustar003 ^! @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_ibendportconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)IbendportconsDifferencez?Determine the difference in ibendportcons between two policies.diff_ibendportconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z>Generate the difference in ibendportcons between the policies.zLGenerating ibendportcon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)IbendportconWrapper).0nr $/usr/lib64/python3.6/ibendportcon.py 0sz=IbendportconsDifference.diff_ibendportcons..css|]}t|VqdS)N)r )r r r r rr1sN)loginfoformatZ _set_diffZ left_policyZ ibendportconsZ right_policyadded_ibendportconsremoved_ibendportconsmodified_ibendportconsrcontextappendmodified_ibendportcon_record)selfZmatched_ibendportconsZ left_ibepZ right_ibepr r rr 's z*IbendportconsDifference.diff_ibendportconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z"Resetting ibendportcon differencesN)rdebugrrr)rr r r _reset_diffAs z#IbendportconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rrs rc@s4eZdZdZd ZddZddZdd Zd d Zd S)r z/Wrap ibendportcon statements for diff purposes.nameportcCs$||_|j|_|j|_t||_dS)N)originr r!hashkey)rZoconr r r__init__OszIbendportconWrapper.__init__cCs|jS)N)r$)rr r r__hash__UszIbendportconWrapper.__hash__cCs |j|jkS)N)r")rotherr r r__lt__XszIbendportconWrapper.__lt__cCs|j|jko|j|jkS)N)r r!)rr'r r r__eq__[s zIbendportconWrapper.__eq__N)r r!) rrrr __slots__r%r&r(r)r r r rr Is r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   *__pycache__/types.cpython-36.opt-1.pyc000064400000006122152534333500013511 0ustar003 ^o @sddlmZmZddlmZddlmZmZddlm Z ddl m Z edd d d d d dddgZ ee ZddZddZGdddeZdS)) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapper)typeattr_wrapper_factory)TypeZ modified_typeZadded_attributesZremoved_attributesZmatched_attributesZmodified_permissiveZ permissive added_aliasesremoved_aliasesmatched_aliasesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z| Wrap types from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _types_cacheZpolicyKeyErrorr)type_tr/usr/lib64/python3.6/types.pytype_wrapper_factory)s rcCst|trt|St|SdS)z Wrap types or attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) isinstancer rr)rrrrtype_or_attr_wrapper_factory8s rc@s8eZdZdZedZedZedZddZddZ dS)TypesDifferencez7Determine the difference in types between two policies. diff_typesc Cs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x|D]\}}|jdd|j Ddd|j D\}}}|j|j |j dd\}}} |j } |j } | | k} |s|s|s|s| rVt|||| | ||| |j |<qVWd S) z6Generate the difference in types between the policies.zDGenerating type differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0rrrr Tsz-TypesDifference.diff_types..css|]}t|VqdS)N)r)rrrrrrUscss|]}t|VqdS)N)r)rarrrr_scss|]}t|VqdS)N)r)rrrrrr`sF)ZunwrapN)loginfoformatZ _set_diffZ left_policytypesZ right_policy added_types removed_typesdictmodified_typesZ attributesaliasesZ ispermissivemodified_types_record) selfZ matched_typesZ left_typeZ right_typeZ added_attrZ removed_attrZ matched_attrr r r Zleft_permissiveZright_permissiveZmod_permissiverrrrMs2   zTypesDifference.diff_typescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting type differencesN)rdebugr r!r#)r&rrr _reset_diffws zTypesDifference._reset_diffN) __name__ __module__ __qualname____doc__rr r!r#rr(rrrrrEs *rN) collectionsrrZ descriptorsr differencerrZtypeattrrZ policyrepr r%r"rrrrrrrrs     __pycache__/mls.cpython-36.pyc000064400000021166152534333500012206 0ustar003 ^B)@sddlmZmZddlmZddlmZmZmZeddddgZ ed dddgZ ed d d d dgZ ee Z ee ZddZddZGdddeZGdddeZGdddeZGdddeZGdddeZGdddeZdS) ) defaultdict namedtuple)DiffResultDescriptor) Difference SymbolWrapperWrapperZmodified_category added_aliasesremoved_aliasesmatched_aliasesZmodified_sensitivityZmodified_levelleveladded_categoriesremoved_categoriesmatched_categoriesc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap category from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _cats_cachepolicyKeyErrorr)categorycr/usr/lib64/python3.6/mls.pycategory_wrapper_factory+s rc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap sensitivity from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _sens_cacherrr) sensitivityrrrrsensitivity_wrapper_factory:s rc@s8eZdZdZedZedZedZddZddZ dS)CategoriesDifferencezXsz7CategoriesDifference.diff_categories..css|]}t|VqdS)N)r)rrrrrrYsF)unwrapN) loginfoformat _set_diff left_policy categories right_policyr rdictmodified_categoriesaliasesmodified_cat_record)selfrZ left_categoryZright_categoryr r r rrrrQs  z$CategoriesDifference.diff_categoriescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting category differencesN)r debugr rr()r+rrr _reset_diffks z CategoriesDifference._reset_diffN) __name__ __module__ __qualname____doc__rr rr(rr-rrrrrIs rc@s8eZdZdZedZedZedZddZddZ dS)SensitivitiesDifferencez?Determine the difference in sensitivities between two policies.diff_sensitivitiescCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xH|D]@\}}|j|j |j dd\}}}|s|rVt ||||j |<qVWdS)z>Generate the difference in sensitivities between the policies.zKGenerating sensitivity differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r)rsrrrrsz=SensitivitiesDifference.diff_sensitivities..css|]}t|VqdS)N)r)rr4rrrrsF)rN) r r!r"r#r$Z sensitivitiesr&added_sensitivitiesremoved_sensitivitiesr'modified_sensitivitiesr)modified_sens_record)r+Zmatched_sensitivitiesZ left_sensZ right_sensr r r rrrr3{s z*SensitivitiesDifference.diff_sensitivitiescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z!Resetting sensitivity differencesN)r r,r5r6r7)r+rrrr-s z#SensitivitiesDifference._reset_diffN) r.r/r0r1rr5r6r7r3r-rrrrr2ss r2c@s8eZdZdZedZedZedZddZddZ dS)LevelDeclsDifferencez8Determine the difference in levels between two policies. diff_levelscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x\|D]T\}}|jdd|j Ddd|j D\}}}|s|rT|j j t ||||qTWdS)z7Generate the difference in levels between the policies.zJGenerating level decl differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)LevelDeclWrapper)rr4rrrrsz3LevelDeclsDifference.diff_levels..css|]}t|VqdS)N)r;)rr4rrrrscss|]}t|VqdS)N)r)rrrrrrscss|]}t|VqdS)N)r)rrrrrrsN) r r!r"r#r$Zlevelsr& added_levelsremoved_levelsmodified_levelsr%appendmodified_level_record)r+Zmatched_levelsZ left_levelZ right_levelr rrrrrr:s z LevelDeclsDifference.diff_levelscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z!Resetting sensitivity differencesN)r r,r<r=r>)r+rrrr-s z LevelDeclsDifference._reset_diffN) r.r/r0r1rr<r=r>r:r-rrrrr9s r9c@s4eZdZdZdZddZddZddZd d Zd S) r;z-Wrap level declarations to allow comparisons.rcCs ||_t|j|_t||_dS)N)originrrhashkey)r+r rrr__init__s zLevelDeclWrapper.__init__cCs|jS)N)rC)r+rrr__hash__szLevelDeclWrapper.__hash__cCs |j|jkS)N)r)r+otherrrr__eq__szLevelDeclWrapper.__eq__cCs |j|jkS)N)r)r+rFrrr__lt__szLevelDeclWrapper.__lt__N) r.r/r0r1 __slots__rDrErGrHrrrrr;s r;c@s4eZdZdZd ZddZddZdd Zd d Zd S) LevelWrapperz!Wrap levels to allow comparisons.rr%cCs.||_t|j|_tdd|jD|_dS)Ncss|]}t|VqdS)N)r)rrrrrrsz(LevelWrapper.__init__..)rArrsetr%)r+r rrrrDs zLevelWrapper.__init__cCs t|jS)N)rBrA)r+rrrrEszLevelWrapper.__hash__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rr%AttributeError)r+rFrrrrGs   zLevelWrapper.__eq__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rr%rL)r+rFrrrrHs   zLevelWrapper.__lt__N)rr%) r.r/r0r1rIrDrErGrHrrrrrJs  rJc@s4eZdZdZd ZddZddZdd Zd d Zd S) RangeWrapperz Wrap ranges to allow comparisons. This only compares the low and high levels of the range. It does not detect additions/removals/modifications to levels between the low and high levels of the range. lowhighcCs"||_t|j|_t|j|_dS)N)rArJrNrO)r+Zrange_rrrrDs zRangeWrapper.__init__cCs t|jS)N)rBrA)r+rrrrEszRangeWrapper.__hash__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rNrOrL)r+rFrrrrGs   zRangeWrapper.__eq__c Cs2y|j|jko|j|jkStk r,dSXdS)NF)rNrOrL)r+rFrrrrH s   zRangeWrapper.__lt__N)rNrO) r.r/r0r1rIrDrErGrHrrrrrMs  rMN) collectionsrrZ descriptorsr differencerrrr*r8r@r'rrrrrr2r9r;rJrMrrrrs, *,,!__pycache__/netifcon.cpython-36.pyc000064400000005407152534333500013220 0ustar003 ^@slddlmZddlmZddlmZddlmZmZedddd d d gZ Gd d d eZ GdddeZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_netifconZrule added_contextremoved_context added_packetremoved_packetc@s8eZdZdZedZedZedZddZddZ dS)NetifconsDifferencez;Determine the difference in netifcons between two policies.diff_netifconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x|D]|\}}t |j t |j kr~|j }|j }nd}d}t |j t |j kr|j }|j }nd}d}|s|rT|j j t|||||qTWdS)z:Generate the difference in netifcons between the policies.zHGenerating netifcon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)NetifconWrapper).0nr /usr/lib64/python3.6/netifcon.py 0sz5NetifconsDifference.diff_netifcons..css|]}t|VqdS)N)r)rrrrrr1sN)loginfoformatZ _set_diffZ left_policyZ netifconsZ right_policyadded_netifconsremoved_netifconsmodified_netifconsrcontextZpacketappendmodified_netifcon_record)selfZmatched_netifconsZ left_netifconZright_netifconr rr r rrrr )s(  z"NetifconsDifference.diff_netifconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting netifcon differencesN)rdebugrrr)rrrr _reset_diffNs zNetifconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr !s %r c@s4eZdZdZdZddZddZddZd d Zd S) rz+Wrap netifcon statements for diff purposes.netifcCs||_|j|_t||_dS)N)originr$hashkey)rZoconrrr__init__\szNetifconWrapper.__init__cCs|jS)N)r')rrrr__hash__aszNetifconWrapper.__hash__cCs |j|jkS)N)r$)rotherrrr__lt__dszNetifconWrapper.__lt__cCs |j|jkS)N)r$)rr*rrr__eq__gszNetifconWrapper.__eq__N) r r!r"r# __slots__r(r)r+r,rrrrrVs rN) collectionsrrrZ descriptorsr differencerrrr rrrrrs   5__pycache__/context.cpython-36.opt-1.pyc000064400000002717152534333500014037 0ustar003 ^@s`ddlmZddlmZmZddlmZddlmZddl m Z ddl m Z Gdd d eZ d S) ) MLSDisabled) SymbolWrapperWrapper) RangeWrapper)role_wrapper_factory)type_wrapper_factory)user_wrapper_factoryc@s4eZdZdZdZddZdd Zd d Zd d ZdS)ContextWrapperz#Wrap contexts to allow comparisons.userroletype_range_c CsZ||_t|j|_t|j|_t|j|_yt|j|_Wnt k rTd|_YnXdS)N) originr r rr rr rrr)selfZctxr/usr/lib64/python3.6/context.py__init__#s   zContextWrapper.__init__cCs t|jS)N)hashr)rrrr__hash__.szContextWrapper.__hash__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r r r r)rotherrrr__eq__1s   zContextWrapper.__eq__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r r r r)rrrrr__lt__7s   zContextWrapper.__lt__N)r r r r) __name__ __module__ __qualname____doc__ __slots__rrrrrrrrr s  r N)Z exceptionr differencerrZmlsrZrolesrtypesrZusersr r rrrrs     __pycache__/polcap.cpython-36.pyc000064400000002676152534333500012676 0ustar003 ^@s0ddlmZddlmZmZGdddeZdS))DiffResultDescriptor) Difference SymbolWrapperc@s0eZdZdZedZedZddZddZdS)PolCapsDifferencez9Determine the difference in polcaps between two policies. diff_polcapscCsL|jjdj||jdd|jjDdd|jjD\|_|_}dS)z8Generate the difference in polcaps between the policies.zJGenerating policy cap differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0nr /usr/lib64/python3.6/polcap.py %sz1PolCapsDifference.diff_polcaps..css|]}t|VqdS)N)r)rrr r r r &sN) loginfoformatZ _set_diffZ left_policyZpolcapsZ right_policy added_polcapsremoved_polcaps)self_r r r rs  zPolCapsDifference.diff_polcapscCs|jjdd|_d|_dS)z%Reset diff results on policy changes.z'Resetting policy capability differencesN)r debugrr)rr r r _reset_diff+s zPolCapsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr r r r rs  rN)Z descriptorsr differencerrrr r r r s __pycache__/bounds.cpython-36.pyc000064400000006652152534333500012710 0ustar003 ^h@stddlmZddlmZddlmZddlmZmZddl m Z edd d d gZ Gd d d eZ GdddeZ dS)) namedtuple)BoundsRuletype)DiffResultDescriptor) DifferenceWrapper)type_wrapper_factoryZmodified_boundruleZ added_boundZ removed_boundc@sHeZdZdZedZedZedZdZdZ ddZ ddZ dd Z dS) BoundsDifferencez9Determine the difference in *bounds between two policies.diff_typeboundsNcCs|jjdj||jdks&|jdkr.|j|jdd|jDdd|jDddd\|_|_}g|_ x<|D]4\}}t |j t |j krp|j j t ||j |j qpWdS) z@Generate the difference in typebound rules between the policies.zJGenerating typebounds differences from {0.left_policy} to {0.right_policy}Ncss|]}t|VqdS)N) BoundsWrapper).0cr/usr/lib64/python3.6/bounds.py 5sz3BoundsDifference.diff_typebounds..css|]}t|VqdS)N)r )rrrrrr6scSs t|jS)N)strchild)brrr7sz2BoundsDifference.diff_typebounds..)key)loginfoformat_left_typebounds_right_typebounds_create_typebound_listsZ _set_diffadded_typeboundsremoved_typeboundsmodified_typeboundsr parentappendmodified_bounds_record)selfZmatched_typeboundsZ left_boundZ right_boundrrrr +s z BoundsDifference.diff_typeboundscCsg|_x@|jjD]2}|jtjkr0|jj|q|jjdj |jqWg|_ x@|j jD]2}|jtjkrx|j j|qZ|jjdj |jqZWdS)z$Create rule lists for both policies.z/Unknown rule type: {0} (This is an SETools bug)N) rZ left_policyZboundsruletyperZ typeboundsr"rerrorrrZ right_policy)r$r rrrrCs    z(BoundsDifference._create_typebound_listscCs(|jjdd|_d|_d|_d|_dS)z%Reset diff results on policy changes.z!Resetting all *bounds differencesN)rdebugrrrr)r$rrr _reset_diffUs  zBoundsDifference._reset_diff) __name__ __module__ __qualname____doc__rrrr rrr rr(rrrrr sr c@s4eZdZdZdZddZddZd d Zd d Zd S)r zWrap *bounds for diff purposes.r%r!rcCs4||_|j|_t|j|_t|j|_t||_dS)N)originr%r r!rhashr)r$r rrr__init__fs   zBoundsWrapper.__init__cCs|jS)N)r)r$rrr__hash__mszBoundsWrapper.__hash__cCs |j|jkS)N)r)r$otherrrr__lt__pszBoundsWrapper.__lt__cCs|j|jko|j|jkS)N)r%r)r$r1rrr__eq__ss zBoundsWrapper.__eq__N)r%r!r) r)r*r+r, __slots__r/r0r2r3rrrrr `s r N) collectionsrZ policyreprZ descriptorsr differencerrtypesr r#r r rrrrs    A__pycache__/conditional.cpython-36.opt-1.pyc000064400000002661152534333500014654 0ustar003 ^@s<ddlmZddlmZeeZddZGdddeZdS) ) defaultdict)Wrapperc Cs>yt|j|Stk r8t|}|t|j|<|SXdS)z Wrap type attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. N) _cond_cacheZpolicyKeyErrorConditionalWrapper)condar #/usr/lib64/python3.6/conditional.pyconditional_wrapper_factorys r c@s4eZdZdZdZddZddZddZd d Zd S) rzHWrap conditional policy expressions to allow comparisons by truth table. truth_tablecCs||_|j|_dS)N)originr )selfrr r r __init__1szConditionalWrapper.__init__cCs t|jS)N)hashr)rr r r __hash__5szConditionalWrapper.__hash__cCs |j|jkS)N)r )rotherr r r __eq__8szConditionalWrapper.__eq__cCst|jt|kS)N)strr)rrr r r __lt__;szConditionalWrapper.__lt__N) __name__ __module__ __qualname____doc__ __slots__rrrrr r r r r+s rN) collectionsr differencerdictrr rr r r r s  __pycache__/polcap.cpython-36.opt-1.pyc000064400000002676152534333500013635 0ustar003 ^@s0ddlmZddlmZmZGdddeZdS))DiffResultDescriptor) Difference SymbolWrapperc@s0eZdZdZedZedZddZddZdS)PolCapsDifferencez9Determine the difference in polcaps between two policies. diff_polcapscCsL|jjdj||jdd|jjDdd|jjD\|_|_}dS)z8Generate the difference in polcaps between the policies.zJGenerating policy cap differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0nr /usr/lib64/python3.6/polcap.py %sz1PolCapsDifference.diff_polcaps..css|]}t|VqdS)N)r)rrr r r r &sN) loginfoformatZ _set_diffZ left_policyZpolcapsZ right_policy added_polcapsremoved_polcaps)self_r r r rs  zPolCapsDifference.diff_polcapscCs|jjdd|_d|_dS)z%Reset diff results on policy changes.z'Resetting policy capability differencesN)r debugrr)rr r r _reset_diff+s zPolCapsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrrr r r r rs  rN)Z descriptorsr differencerrrr r r r s __pycache__/descriptors.cpython-36.opt-1.pyc000064400000002112152534333500014701 0ustar003 ^e@sddlmZGdddZdS))WeakKeyDictionaryc@s2eZdZdZddZd ddZddZd d ZdS) DiffResultDescriptorz%Descriptor for managing diff results.cCs||_t|_dS)N) diff_functionr instances)selfrr#/usr/lib64/python3.6/descriptors.py__init__szDiffResultDescriptor.__init__NcCs:|dkr |S|jj|ddkr0t||j}||j|S)N)r setdefaultgetattrr)robjZobjtypeZdiffrrr__get__%s  zDiffResultDescriptor.__get__cCs||j|<dS)N)r)rr valuerrr__set__/szDiffResultDescriptor.__set__cCsd|j|<dS)N)r)rr rrr __delete__2szDiffResultDescriptor.__delete__)N)__name__ __module__ __qualname____doc__r r rrrrrrrs  rN)weakrefrrrrrrs __pycache__/netifcon.cpython-36.opt-1.pyc000064400000005407152534333500014157 0ustar003 ^@slddlmZddlmZddlmZddlmZmZedddd d d gZ Gd d d eZ GdddeZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_netifconZrule added_contextremoved_context added_packetremoved_packetc@s8eZdZdZedZedZedZddZddZ dS)NetifconsDifferencez;Determine the difference in netifcons between two policies.diff_netifconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x|D]|\}}t |j t |j kr~|j }|j }nd}d}t |j t |j kr|j }|j }nd}d}|s|rT|j j t|||||qTWdS)z:Generate the difference in netifcons between the policies.zHGenerating netifcon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)NetifconWrapper).0nr /usr/lib64/python3.6/netifcon.py 0sz5NetifconsDifference.diff_netifcons..css|]}t|VqdS)N)r)rrrrrr1sN)loginfoformatZ _set_diffZ left_policyZ netifconsZ right_policyadded_netifconsremoved_netifconsmodified_netifconsrcontextZpacketappendmodified_netifcon_record)selfZmatched_netifconsZ left_netifconZright_netifconr rr r rrrr )s(  z"NetifconsDifference.diff_netifconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting netifcon differencesN)rdebugrrr)rrrr _reset_diffNs zNetifconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr !s %r c@s4eZdZdZdZddZddZddZd d Zd S) rz+Wrap netifcon statements for diff purposes.netifcCs||_|j|_t||_dS)N)originr$hashkey)rZoconrrr__init__\szNetifconWrapper.__init__cCs|jS)N)r')rrrr__hash__aszNetifconWrapper.__hash__cCs |j|jkS)N)r$)rotherrrr__lt__dszNetifconWrapper.__lt__cCs |j|jkS)N)r$)rr*rrr__eq__gszNetifconWrapper.__eq__N) r r!r"r# __slots__r(r)r+r,rrrrrVs rN) collectionsrrrZ descriptorsr differencerrrr rrrrrs   5__pycache__/nodecon.cpython-36.opt-1.pyc000064400000005214152534333500013773 0ustar003 ^ @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_nodeconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)NodeconsDifferencez:Determine the difference in nodecons between two policies. diff_nodeconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z9Generate the difference in nodecons between the policies.zGGenerating nodecon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)NodeconWrapper).0nr /usr/lib64/python3.6/nodecon.py /sz3NodeconsDifference.diff_nodecons..css|]}t|VqdS)N)r )r r r r rr0sN)loginfoformatZ _set_diffZ left_policyZnodeconsZ right_policyadded_nodeconsremoved_nodeconsmodified_nodeconsrcontextappendmodified_nodecon_record)selfZmatched_nodeconsZ left_nodeconZ right_nodeconr r rr (s   z NodeconsDifference.diff_nodeconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting nodecon differencesN)rdebugrrr)rr r r _reset_diff?s zNodeconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rr s rc@s4eZdZdZd ZddZddZdd Zd d Zd S)r z*Wrap nodecon statements for diff purposes. ip_versionnetworkcCs$||_|j|_|j|_t||_dS)N)originr r!hashkey)rZoconr r r__init__MszNodeconWrapper.__init__cCs|jS)N)r$)rr r r__hash__SszNodeconWrapper.__hash__cCs |j|jkS)N)r")rotherr r r__lt__VszNodeconWrapper.__lt__cCs|j|jko|j|jkS)N)r r!)rr'r r r__eq__Ys zNodeconWrapper.__eq__N)r r!) rrrr __slots__r%r&r(r)r r r rr Gs r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   '__pycache__/commons.cpython-36.opt-1.pyc000064400000003512152534333500014020 0ustar003 ^C @sLddlmZddlmZddlmZmZeddddgZGd d d eZd S) ) namedtuple)DiffResultDescriptor) Difference SymbolWrapperZmodified_common added_perms removed_perms matched_permsc@s8eZdZdZedZedZedZddZddZ dS)CommonDifferencezV Determine the difference in common permission sets between two policies. diff_commonscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ xD|D]<\}}|j|j |j dd\}}}|s|rVt ||||j |<qVWdS)z8Generate the difference in commons between the policies.zFGenerating common differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0cr/usr/lib64/python3.6/commons.py 0sz0CommonDifference.diff_commons..css|]}t|VqdS)N)r)r r rrrr1sF)ZunwrapN) loginfoformatZ _set_diffZ left_policyZcommonsZ right_policy added_commonsremoved_commonsdictmodified_commonsZpermsmodified_commons_record)selfZmatched_commonsZ left_commonZ right_commonrrr rrrr )s  zCommonDifference.diff_commonscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting common differencesN)rdebugrrr)rrrr _reset_diffDs zCommonDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr s r N) collectionsrZ descriptorsr differencerrrr rrrrs  __pycache__/context.cpython-36.pyc000064400000002717152534333500013100 0ustar003 ^@s`ddlmZddlmZmZddlmZddlmZddl m Z ddl m Z Gdd d eZ d S) ) MLSDisabled) SymbolWrapperWrapper) RangeWrapper)role_wrapper_factory)type_wrapper_factory)user_wrapper_factoryc@s4eZdZdZdZddZdd Zd d Zd d ZdS)ContextWrapperz#Wrap contexts to allow comparisons.userroletype_range_c CsZ||_t|j|_t|j|_t|j|_yt|j|_Wnt k rTd|_YnXdS)N) originr r rr rr rrr)selfZctxr/usr/lib64/python3.6/context.py__init__#s   zContextWrapper.__init__cCs t|jS)N)hashr)rrrr__hash__.szContextWrapper.__hash__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r r r r)rotherrrr__eq__1s   zContextWrapper.__eq__cCs0|j|jko.|j|jko.|j|jko.|j|jkS)N)r r r r)rrrrr__lt__7s   zContextWrapper.__lt__N)r r r r) __name__ __module__ __qualname____doc__ __slots__rrrrrrrrr s  r N)Z exceptionr differencerrZmlsrZrolesrtypesrZusersr r rrrrs     __pycache__/genfscon.cpython-36.opt-1.pyc000064400000005352152534333500014153 0ustar003 ^ @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_genfsruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)GenfsconsDifferencez@Determine the difference in genfscon rules between two policies.diff_genfsconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z?Generate the difference in genfscon rules between the policies.zHGenerating genfscon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)GenfsconWrapper).0fsr /usr/lib64/python3.6/genfscon.py /sz5GenfsconsDifference.diff_genfscons..css|]}t|VqdS)N)r )r r rrrr0sN)loginfoformatZ _set_diffZ left_policyZ genfsconsZ right_policyadded_genfsconsremoved_genfsconsmodified_genfsconsrcontextappendmodified_genfs_record)selfZmatchedZ left_ruleZ right_rulerrrr 's  z"GenfsconsDifference.diff_genfsconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z#Resetting genfscon rule differencesN)rdebugrrr)rrrr _reset_diff?s zGenfsconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr s r c@s4eZdZdZdZddZdd Zd d Zd d ZdS)r z,Wrap genfscon rules to allow set operations.r pathfiletypercCs8||_|j|_|j|_|j|_t|j|_t||_dS)N)originr r!r"rrhashkey)rrrrr__init__Ms  zGenfsconWrapper.__init__cCs|jS)N)r%)rrrr__hash__UszGenfsconWrapper.__hash__cCs |j|jkS)N)r%)rotherrrr__lt__XszGenfsconWrapper.__lt__cCs$|j|jko"|j|jko"|j|jkS)N)r r!r")rr(rrr__eq__[s  zGenfsconWrapper.__eq__N)r r!r"r) rrrr __slots__r&r'r)r*rrrrr Gs r N) collectionsrrrZ descriptorsr differencerrrr r rrrrs   (__pycache__/fsuse.cpython-36.opt-1.pyc000064400000005215152534333500013474 0ustar003 ^p @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_fsuseruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)FSUsesDifferencez@Determine the difference in fs_use_* rules between two policies. diff_fs_usescCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z=Generate the difference in fs_use rules between the policies.zHGenerating fs_use_* differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N) FSUseWrapper).0fsr/usr/lib64/python3.6/fsuse.py /sz0FSUsesDifference.diff_fs_uses..css|]}t|VqdS)N)r )r r rrrr0sN)loginfoformatZ _set_diffZ left_policyZfs_usesZ right_policy added_fs_usesremoved_fs_usesmodified_fs_usesrcontextappendmodified_fsuse_record)selfZmatchedZ left_ruleZ right_rulerrrr 's  zFSUsesDifference.diff_fs_usescCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z#Resetting fs_use_* rule differencesN)rdebugrrr)rrrr _reset_diff?s zFSUsesDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rrrrrr s r c@s4eZdZdZdZddZddZd d Zd d Zd S)r z,Wrap fs_use_* rules to allow set operations.ruletyper rcCs0||_|j|_|j|_t|j|_t||_dS)N)originr!r rrhashkey)rrrrr__init__Ms  zFSUseWrapper.__init__cCs|jS)N)r$)rrrr__hash__TszFSUseWrapper.__hash__cCs |j|jkS)N)r$)rotherrrr__lt__WszFSUseWrapper.__lt__cCs|j|jko|j|jkS)N)r!r )rr'rrr__eq__ZszFSUseWrapper.__eq__N)r!r r) rrrr __slots__r%r&r(r)rrrrr Gs r N) collectionsrrrZ descriptorsr differencerrrr r rrrrs   (__pycache__/nodecon.cpython-36.pyc000064400000005214152534333500013034 0ustar003 ^ @shddlmZddlmZddlmZddlmZmZedddd gZ Gd d d eZ Gd d d eZ dS)) namedtuple)ContextWrapper)DiffResultDescriptor) DifferenceWrapperZmodified_nodeconZruleZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)NodeconsDifferencez:Determine the difference in nodecons between two policies. diff_nodeconscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x<|D]4\}}t |j t |j krT|j j t ||j |j qTWdS)z9Generate the difference in nodecons between the policies.zGGenerating nodecon differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)NodeconWrapper).0nr /usr/lib64/python3.6/nodecon.py /sz3NodeconsDifference.diff_nodecons..css|]}t|VqdS)N)r )r r r r rr0sN)loginfoformatZ _set_diffZ left_policyZnodeconsZ right_policyadded_nodeconsremoved_nodeconsmodified_nodeconsrcontextappendmodified_nodecon_record)selfZmatched_nodeconsZ left_nodeconZ right_nodeconr r rr (s   z NodeconsDifference.diff_nodeconscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting nodecon differencesN)rdebugrrr)rr r r _reset_diff?s zNodeconsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r rr s rc@s4eZdZdZd ZddZddZdd Zd d Zd S)r z*Wrap nodecon statements for diff purposes. ip_versionnetworkcCs$||_|j|_|j|_t||_dS)N)originr r!hashkey)rZoconr r r__init__MszNodeconWrapper.__init__cCs|jS)N)r$)rr r r__hash__SszNodeconWrapper.__hash__cCs |j|jkS)N)r")rotherr r r__lt__VszNodeconWrapper.__lt__cCs|j|jko|j|jkS)N)r r!)rr'r r r__eq__Ys zNodeconWrapper.__eq__N)r r!) rrrr __slots__r%r&r(r)r r r rr Gs r N) collectionsrrrZ descriptorsr differencerrrrr r r r rs   '__pycache__/default.cpython-36.opt-1.pyc000064400000005543152534333500013777 0ustar003 ^@sdddlmZddlmZddlmZmZmZeddddd d gZGd d d eZ Gd ddeZ dS)) namedtuple)DiffResultDescriptor) Difference SymbolWrapperWrapperZmodified_defaultZrule added_defaultremoved_defaultadded_default_rangeremoved_default_rangec@s8eZdZdZedZedZedZddZddZ dS)DefaultsDifferencez;Determine the difference in default_* between two policies. diff_defaultscCs|jjdj||jdd|jjDdd|jjD\|_|_}g|_ x|D]\}}|j |j krv|j }|j }nd}d}y&|j |j kr|j }|j }nd}d}Wnt k rd}d}YnX|s|rT|j j t|||||qTWdS)z>Generate the difference in type defaults between the policies.zIGenerating default_* differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)DefaultWrapper).0dr/usr/lib64/python3.6/default.py 0sz3DefaultsDifference.diff_defaults..css|]}t|VqdS)N)r)rrrrrr1sN)loginfoformatZ _set_diffZ left_policyZdefaultsZ right_policyadded_defaultsremoved_defaultsmodified_defaultsdefaultZ default_rangeAttributeErrorappendmodified_default_record)selfZmatched_defaultsZ left_defaultZ right_defaultr rr r rrrr (s:    z DefaultsDifference.diff_defaultscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.zResetting default_* differencesN)rdebugrrr)rrrr _reset_diffWs zDefaultsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr r rrrrr s /r c@s4eZdZdZd ZddZddZdd Zd d Zd S)rz$Wrap default_* to allow comparisons.ruletypetclasscCs(||_|j|_t|j|_t||_dS)N)originr%rr&hashkey)rrrrr__init__es zDefaultWrapper.__init__cCs|jS)N)r))rrrr__hash__kszDefaultWrapper.__hash__cCs |j|jkS)N)r))rotherrrr__lt__nszDefaultWrapper.__lt__cCs|j|jko|j|jkS)N)r%r&)rr,rrr__eq__qs zDefaultWrapper.__eq__N)r%r&) r!r"r#r$ __slots__r*r+r-r.rrrrr_s rN) collectionsrZ descriptorsr differencerrrrr rrrrrs  ?__pycache__/initsid.cpython-36.pyc000064400000003554152534333500013057 0ustar003 ^ @sVddlmZddlmZddlmZddlmZmZedddgZ Gd d d eZ d S) ) namedtuple)ContextWrapper)DiffResultDescriptor) Difference SymbolWrapperZmodified_initsidZ added_contextZremoved_contextc@s8eZdZdZedZedZedZddZddZ dS)InitialSIDsDifferencez:Determine the difference in initsids between two policies.diff_initialsidscCs|jjdj||jdd|jjDdd|jjD\|_|_}t |_ x8|D]0\}}t |j t |j krVt |j |j |j |<qVWdS)z=Generate the difference in initial SIDs between the policies.zKGenerating initial SID differences from {0.left_policy} to {0.right_policy}css|]}t|VqdS)N)r).0ir /usr/lib64/python3.6/initsid.py ,sz9InitialSIDsDifference.diff_initialsids..css|]}t|VqdS)N)r)r r r r r r-sN)loginfoformatZ _set_diffZ left_policyZ initialsidsZ right_policyadded_initialsidsremoved_initialsidsdictmodified_initialsidsrcontextmodified_initsids_record)selfZmatched_initialsidsZleft_initialsidZright_initialsidr r r r %s  z&InitialSIDsDifference.diff_initialsidscCs"|jjdd|_d|_d|_dS)z%Reset diff results on policy changes.z Resetting initialsid differencesN)rdebugrrr)rr r r _reset_diff;s z!InitialSIDsDifference._reset_diffN) __name__ __module__ __qualname____doc__rrrrr rr r r r rs rN) collectionsrrrZ descriptorsr differencerrrrr r r r s   __pycache__/__init__.cpython-36.pyc000064400000003770152534333500013153 0ustar003 ^ @stddlmZddlmZddlmZddlmZddlm Z ddl m Z ddl m Z ddlmZdd lmZdd lmZdd lmZmZmZdd lmZdd lmZddlmZddlmZddl m!Z!ddl"m#Z#ddl$m%Z%ddl&m'Z'ddl(m)Z)ddl*m+Z+ddl,m-Z-ddl.m/Z/ddl0m1Z1dgZ2Gdddeeeeee e e eeeeeeeee!e#e%e'e)ee+e-e/e1Z3dS))BooleansDifference)BoundsDifference)CommonDifference)ConstraintsDifference)DefaultsDifference)FSUsesDifference)GenfsconsDifference)IbendportconsDifference)IbpkeyconsDifference)InitialSIDsDifference)CategoriesDifferenceLevelDeclsDifferenceSensitivitiesDifference)MLSRulesDifference)NetifconsDifference)NodeconsDifference)ObjClassDifference)PolCapsDifference)PortconsDifference)PropertiesDifference)RBACRulesDifference)RolesDifference)TERulesDifference)TypeAttributesDifference)TypesDifference)UsersDifferencePolicyDifferencec@seZdZdZddZdS)rz Determine the differences from the left policy to the right policy. Parameters: left A policy right A policy cCsxtjD]}|j|qWdS)z%Reset diff results on policy changes.N)r __bases__ _reset_diff)selfcr! /usr/lib64/python3.6/__init__.pyrRs zPolicyDifference._reset_diffN)__name__ __module__ __qualname____doc__rr!r!r!r"r/s!N)4boolrZboundsrZcommonsrZ constraintsrdefaultrZfsuserZgenfsconrZ ibendportconr Z ibpkeyconr Zinitsidr Zmlsr r rZmlsrulesrZnetifconrZnodeconrZobjclassrZpolcaprZportconrZ propertiesrZ rbacrulesrZrolesrZterulesrZtypeattrrtypesrZusersr__all__rr!r!r!r"sd                        ibpkeycon.py000064400000006447152534333500007117 0ustar00# Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper modified_ibpkeycon_record = namedtuple("modified_ibpkeycon", ["rule", "added_context", "removed_context"]) class IbpkeyconsDifference(Difference): """Determine the difference in ibpkeycons between two policies.""" added_ibpkeycons = DiffResultDescriptor("diff_ibpkeycons") removed_ibpkeycons = DiffResultDescriptor("diff_ibpkeycons") modified_ibpkeycons = DiffResultDescriptor("diff_ibpkeycons") def diff_ibpkeycons(self): """Generate the difference in ibpkeycons between the policies.""" self.log.info( "Generating ibpkeycon differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_ibpkeycons, self.removed_ibpkeycons, matched_ibpkeycons = \ self._set_diff( (IbpkeyconWrapper(n) for n in self.left_policy.ibpkeycons()), (IbpkeyconWrapper(n) for n in self.right_policy.ibpkeycons())) self.modified_ibpkeycons = [] for left_ibpkey, right_ibpkey in matched_ibpkeycons: # Criteria for modified ibpkeycons # 1. change to context if ContextWrapper(left_ibpkey.context) != ContextWrapper(right_ibpkey.context): self.modified_ibpkeycons.append( modified_ibpkeycon_record(left_ibpkey, right_ibpkey.context, left_ibpkey.context)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting ibpkeycon differences") self.added_ibpkeycons = None self.removed_ibpkeycons = None self.modified_ibpkeycons = None class IbpkeyconWrapper(Wrapper): """Wrap ibpkeycon statements for diff purposes.""" __slots__ = ("subnet_prefix", "low", "high") def __init__(self, ocon): self.origin = ocon self.subnet_prefix = ocon.subnet_prefix self.low, self.high = ocon.pkeys self.key = hash(ocon) def __hash__(self): return self.key def __lt__(self, other): return self.origin < other.origin def __eq__(self, other): return self.subnet_prefix == other.subnet_prefix and \ self.low == other.low and \ self.high == other.high commons.py000064400000005503152534333500006577 0ustar00# Copyright 2015, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper modified_commons_record = namedtuple("modified_common", ["added_perms", "removed_perms", "matched_perms"]) class CommonDifference(Difference): """ Determine the difference in common permission sets between two policies. """ added_commons = DiffResultDescriptor("diff_commons") removed_commons = DiffResultDescriptor("diff_commons") modified_commons = DiffResultDescriptor("diff_commons") def diff_commons(self): """Generate the difference in commons between the policies.""" self.log.info( "Generating common differences from {0.left_policy} to {0.right_policy}".format(self)) self.added_commons, self.removed_commons, matched_commons = self._set_diff( (SymbolWrapper(c) for c in self.left_policy.commons()), (SymbolWrapper(c) for c in self.right_policy.commons())) self.modified_commons = dict() for left_common, right_common in matched_commons: # Criteria for modified commons # 1. change to permissions added_perms, removed_perms, matched_perms = self._set_diff(left_common.perms, right_common.perms, unwrap=False) if added_perms or removed_perms: self.modified_commons[left_common] = modified_commons_record(added_perms, removed_perms, matched_perms) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting common differences") self.added_commons = None self.removed_commons = None self.modified_commons = None mls.py000064400000024502152534333500005717 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper, Wrapper modified_cat_record = namedtuple("modified_category", ["added_aliases", "removed_aliases", "matched_aliases"]) modified_sens_record = namedtuple("modified_sensitivity", ["added_aliases", "removed_aliases", "matched_aliases"]) modified_level_record = namedtuple("modified_level", ["level", "added_categories", "removed_categories", "matched_categories"]) _cats_cache = defaultdict(dict) _sens_cache = defaultdict(dict) def category_wrapper_factory(category): """ Wrap category from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _cats_cache[category.policy][category] except KeyError: c = SymbolWrapper(category) _cats_cache[category.policy][category] = c return c def sensitivity_wrapper_factory(sensitivity): """ Wrap sensitivity from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _sens_cache[sensitivity.policy][sensitivity] except KeyError: c = SymbolWrapper(sensitivity) _sens_cache[sensitivity.policy][sensitivity] = c return c class CategoriesDifference(Difference): """Determine the difference in categories between two policies.""" added_categories = DiffResultDescriptor("diff_categories") removed_categories = DiffResultDescriptor("diff_categories") modified_categories = DiffResultDescriptor("diff_categories") def diff_categories(self): """Generate the difference in categories between the policies.""" self.log.info( "Generating category differences from {0.left_policy} to {0.right_policy}".format(self)) self.added_categories, self.removed_categories, matched_categories = self._set_diff( (category_wrapper_factory(c) for c in self.left_policy.categories()), (category_wrapper_factory(c) for c in self.right_policy.categories())) self.modified_categories = dict() for left_category, right_category in matched_categories: # Criteria for modified categories # 1. change to aliases added_aliases, removed_aliases, matched_aliases = self._set_diff( left_category.aliases(), right_category.aliases(), unwrap=False) if added_aliases or removed_aliases: self.modified_categories[left_category] = modified_cat_record(added_aliases, removed_aliases, matched_aliases) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting category differences") self.added_categories = None self.removed_categories = None self.modified_categories = None class SensitivitiesDifference(Difference): """Determine the difference in sensitivities between two policies.""" added_sensitivities = DiffResultDescriptor("diff_sensitivities") removed_sensitivities = DiffResultDescriptor("diff_sensitivities") modified_sensitivities = DiffResultDescriptor("diff_sensitivities") def diff_sensitivities(self): """Generate the difference in sensitivities between the policies.""" self.log.info( "Generating sensitivity differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_sensitivities, self.removed_sensitivities, matched_sensitivities = \ self._set_diff( (sensitivity_wrapper_factory(s) for s in self.left_policy.sensitivities()), (sensitivity_wrapper_factory(s) for s in self.right_policy.sensitivities())) self.modified_sensitivities = dict() for left_sens, right_sens in matched_sensitivities: # Criteria for modified sensitivities # 1. change to aliases added_aliases, removed_aliases, matched_aliases = self._set_diff( left_sens.aliases(), right_sens.aliases(), unwrap=False) if added_aliases or removed_aliases: self.modified_sensitivities[left_sens] = modified_sens_record(added_aliases, removed_aliases, matched_aliases) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting sensitivity differences") self.added_sensitivities = None self.removed_sensitivities = None self.modified_sensitivities = None class LevelDeclsDifference(Difference): """Determine the difference in levels between two policies.""" added_levels = DiffResultDescriptor("diff_levels") removed_levels = DiffResultDescriptor("diff_levels") modified_levels = DiffResultDescriptor("diff_levels") def diff_levels(self): """Generate the difference in levels between the policies.""" self.log.info( "Generating level decl differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_levels, self.removed_levels, matched_levels = \ self._set_diff( (LevelDeclWrapper(s) for s in self.left_policy.levels()), (LevelDeclWrapper(s) for s in self.right_policy.levels())) self.modified_levels = [] for left_level, right_level in matched_levels: # Criteria for modified levels # 1. change to allowed categories added_categories, removed_categories, matched_categories = self._set_diff( (category_wrapper_factory(c) for c in left_level.categories()), (category_wrapper_factory(c) for c in right_level.categories())) if added_categories or removed_categories: self.modified_levels.append(modified_level_record( left_level, added_categories, removed_categories, matched_categories)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting sensitivity differences") self.added_levels = None self.removed_levels = None self.modified_levels = None class LevelDeclWrapper(Wrapper): """Wrap level declarations to allow comparisons.""" __slots__ = ("sensitivity") def __init__(self, level): self.origin = level self.sensitivity = sensitivity_wrapper_factory(level.sensitivity) self.key = hash(level) def __hash__(self): return self.key def __eq__(self, other): # non-MLS policies have no level declarations so there # should be no AttributeError possiblity here return self.sensitivity == other.sensitivity def __lt__(self, other): return self.sensitivity < other.sensitivity class LevelWrapper(Wrapper): """Wrap levels to allow comparisons.""" __slots__ = ("sensitivity", "categories") def __init__(self, level): self.origin = level self.sensitivity = sensitivity_wrapper_factory(level.sensitivity) self.categories = set(category_wrapper_factory(c) for c in level.categories()) def __hash__(self): return hash(self.origin) def __eq__(self, other): try: return self.sensitivity == other.sensitivity and \ self.categories == other.categories except AttributeError: # comparing an MLS policy to non-MLS policy will result in # other being None return False def __lt__(self, other): try: return self.sensitivity < other.sensitivity and \ self.categories < other.categories except AttributeError: # comparing an MLS policy to non-MLS policy will result in # other being None return False class RangeWrapper(Wrapper): """ Wrap ranges to allow comparisons. This only compares the low and high levels of the range. It does not detect additions/removals/modifications to levels between the low and high levels of the range. """ __slots__ = ("low", "high") def __init__(self, range_): self.origin = range_ self.low = LevelWrapper(range_.low) self.high = LevelWrapper(range_.high) def __hash__(self): return hash(self.origin) def __eq__(self, other): try: return self.low == other.low and \ self.high == other.high except AttributeError: # comparing an MLS policy to non-MLS policy will result in # other being None return False def __lt__(self, other): try: return self.low < other.low and \ self.high < other.high except AttributeError: # comparing an MLS policy to non-MLS policy will result in # other being None return False default.py000064400000010220152534333500006540 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper, Wrapper modified_default_record = namedtuple("modified_default", ["rule", "added_default", "removed_default", "added_default_range", "removed_default_range"]) class DefaultsDifference(Difference): """Determine the difference in default_* between two policies.""" added_defaults = DiffResultDescriptor("diff_defaults") removed_defaults = DiffResultDescriptor("diff_defaults") modified_defaults = DiffResultDescriptor("diff_defaults") def diff_defaults(self): """Generate the difference in type defaults between the policies.""" self.log.info( "Generating default_* differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_defaults, self.removed_defaults, matched_defaults = self._set_diff( (DefaultWrapper(d) for d in self.left_policy.defaults()), (DefaultWrapper(d) for d in self.right_policy.defaults())) self.modified_defaults = [] for left_default, right_default in matched_defaults: # Criteria for modified defaults # 1. change to default setting # 2. change to default range if left_default.default != right_default.default: removed_default = left_default.default added_default = right_default.default else: removed_default = None added_default = None try: if left_default.default_range != right_default.default_range: removed_default_range = left_default.default_range added_default_range = right_default.default_range else: removed_default_range = None added_default_range = None except AttributeError: removed_default_range = None added_default_range = None if removed_default or removed_default_range: self.modified_defaults.append( modified_default_record(left_default, added_default, removed_default, added_default_range, removed_default_range)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting default_* differences") self.added_defaults = None self.removed_defaults = None self.modified_defaults = None class DefaultWrapper(Wrapper): """Wrap default_* to allow comparisons.""" __slots__ = ("ruletype", "tclass") def __init__(self, default): self.origin = default self.ruletype = default.ruletype self.tclass = SymbolWrapper(default.tclass) self.key = hash(default) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): return self.ruletype == other.ruletype and \ self.tclass == other.tclass types.py000064400000011557152534333500006276 0ustar00# Copyright 2015, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper from .typeattr import typeattr_wrapper_factory from ..policyrep import Type modified_types_record = namedtuple("modified_type", ["added_attributes", "removed_attributes", "matched_attributes", "modified_permissive", "permissive", "added_aliases", "removed_aliases", "matched_aliases"]) _types_cache = defaultdict(dict) def type_wrapper_factory(type_): """ Wrap types from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _types_cache[type_.policy][type_] except KeyError: t = SymbolWrapper(type_) _types_cache[type_.policy][type_] = t return t def type_or_attr_wrapper_factory(type_): """ Wrap types or attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ if isinstance(type_, Type): return type_wrapper_factory(type_) else: return typeattr_wrapper_factory(type_) class TypesDifference(Difference): """Determine the difference in types between two policies.""" added_types = DiffResultDescriptor("diff_types") removed_types = DiffResultDescriptor("diff_types") modified_types = DiffResultDescriptor("diff_types") def diff_types(self): """Generate the difference in types between the policies.""" self.log.info( "Generating type differences from {0.left_policy} to {0.right_policy}".format(self)) self.added_types, self.removed_types, matched_types = self._set_diff( (SymbolWrapper(t) for t in self.left_policy.types()), (SymbolWrapper(t) for t in self.right_policy.types())) self.modified_types = dict() for left_type, right_type in matched_types: # Criteria for modified types # 1. change to attribute set, or # 2. change to alias set, or # 3. different permissive setting added_attr, removed_attr, matched_attr = self._set_diff( (SymbolWrapper(a) for a in left_type.attributes()), (SymbolWrapper(a) for a in right_type.attributes())) added_aliases, removed_aliases, matched_aliases = self._set_diff(left_type.aliases(), right_type.aliases(), unwrap=False) left_permissive = left_type.ispermissive right_permissive = right_type.ispermissive mod_permissive = left_permissive != right_permissive if added_attr or removed_attr or added_aliases or removed_aliases or mod_permissive: self.modified_types[left_type] = modified_types_record(added_attr, removed_attr, matched_attr, mod_permissive, left_permissive, added_aliases, removed_aliases, matched_aliases) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting type differences") self.added_types = None self.removed_types = None self.modified_types = None conditional.py000064400000003265152534333500007432 0ustar00# Copyright 2015-2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict from .difference import Wrapper _cond_cache = defaultdict(dict) def conditional_wrapper_factory(cond): """ Wrap type attributes from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _cond_cache[cond.policy][cond] except KeyError: a = ConditionalWrapper(cond) _cond_cache[cond.policy][cond] = a return a class ConditionalWrapper(Wrapper): """Wrap conditional policy expressions to allow comparisons by truth table.""" __slots__ = ("truth_table") def __init__(self, cond): self.origin = cond self.truth_table = cond.truth_table() def __hash__(self): return hash(self.origin) def __eq__(self, other): return self.truth_table == other.truth_table def __lt__(self, other): return str(self.origin) < str(other) fsuse.py000064400000006160152534333500006251 0ustar00# Copyright 2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper modified_fsuse_record = namedtuple("modified_fsuse", ["rule", "added_context", "removed_context"]) class FSUsesDifference(Difference): """Determine the difference in fs_use_* rules between two policies.""" added_fs_uses = DiffResultDescriptor("diff_fs_uses") removed_fs_uses = DiffResultDescriptor("diff_fs_uses") modified_fs_uses = DiffResultDescriptor("diff_fs_uses") def diff_fs_uses(self): """Generate the difference in fs_use rules between the policies.""" self.log.info( "Generating fs_use_* differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_fs_uses, self.removed_fs_uses, matched = self._set_diff( (FSUseWrapper(fs) for fs in self.left_policy.fs_uses()), (FSUseWrapper(fs) for fs in self.right_policy.fs_uses())) self.modified_fs_uses = [] for left_rule, right_rule in matched: # Criteria for modified rules # 1. change to context if ContextWrapper(left_rule.context) != ContextWrapper(right_rule.context): self.modified_fs_uses.append(modified_fsuse_record(left_rule, right_rule.context, left_rule.context)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting fs_use_* rule differences") self.added_fs_uses = None self.removed_fs_uses = None self.modified_fs_uses = None class FSUseWrapper(Wrapper): """Wrap fs_use_* rules to allow set operations.""" __slots__ = ("ruletype", "fs", "context") def __init__(self, rule): self.origin = rule self.ruletype = rule.ruletype self.fs = rule.fs self.context = ContextWrapper(rule.context) self.key = hash(rule) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): return self.ruletype == other.ruletype and self.fs == other.fs context.py000064400000003616152534333500006613 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from ..exception import MLSDisabled from .difference import SymbolWrapper, Wrapper from .mls import RangeWrapper from .roles import role_wrapper_factory from .types import type_wrapper_factory from .users import user_wrapper_factory class ContextWrapper(Wrapper): """Wrap contexts to allow comparisons.""" __slots__ = ("user", "role", "type_", "range_") def __init__(self, ctx): self.origin = ctx self.user = user_wrapper_factory(ctx.user) self.role = role_wrapper_factory(ctx.role) self.type_ = type_wrapper_factory(ctx.type_) try: self.range_ = RangeWrapper(ctx.range_) except MLSDisabled: self.range_ = None def __hash__(self): return hash(self.origin) def __eq__(self, other): return self.user == other.user and \ self.role == other.role and \ self.type_ == other.type_ and \ self.range_ == other.range_ def __lt__(self, other): return self.user < other.user and \ self.role < other.role and \ self.type_ < other.type_ and \ self.range_ < other.range_ rbacrules.py000064400000014663152534333500007115 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from ..policyrep import RBACRuletype from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper from .objclass import class_wrapper_factory from .roles import role_wrapper_factory from .types import type_or_attr_wrapper_factory modified_rbacrule_record = namedtuple("modified_rbacrule", ["rule", "added_default", "removed_default"]) class RBACRulesDifference(Difference): """Determine the difference in RBAC rules between two policies.""" added_role_allows = DiffResultDescriptor("diff_role_allows") removed_role_allows = DiffResultDescriptor("diff_role_allows") # role allows cannot be modified, only added/removed added_role_transitions = DiffResultDescriptor("diff_role_transitions") removed_role_transitions = DiffResultDescriptor("diff_role_transitions") modified_role_transitions = DiffResultDescriptor("diff_role_transitions") # Lists of rules for each policy _left_rbac_rules = defaultdict(list) _right_rbac_rules = defaultdict(list) def diff_role_allows(self): """Generate the difference in role allow rules between the policies.""" self.log.info( "Generating role allow differences from {0.left_policy} to {0.right_policy}". format(self)) if not self._left_rbac_rules or not self._right_rbac_rules: self._create_rbac_rule_lists() self.added_role_allows, self.removed_role_allows, _ = self._set_diff( self._expand_generator(self._left_rbac_rules[RBACRuletype.allow], RoleAllowWrapper), self._expand_generator(self._right_rbac_rules[RBACRuletype.allow], RoleAllowWrapper)) def diff_role_transitions(self): """Generate the difference in role_transition rules between the policies.""" self.log.info( "Generating role_transition differences from {0.left_policy} to {0.right_policy}". format(self)) if not self._left_rbac_rules or not self._right_rbac_rules: self._create_rbac_rule_lists() added, removed, matched = self._set_diff( self._expand_generator(self._left_rbac_rules[RBACRuletype.role_transition], RoleTransitionWrapper), self._expand_generator(self._right_rbac_rules[RBACRuletype.role_transition], RoleTransitionWrapper)) modified = [] for left_rule, right_rule in matched: # Criteria for modified rules # 1. change to default role if role_wrapper_factory(left_rule.default) != role_wrapper_factory(right_rule.default): modified.append(modified_rbacrule_record(left_rule, right_rule.default, left_rule.default)) self.added_role_transitions = added self.removed_role_transitions = removed self.modified_role_transitions = modified # # Internal functions # def _create_rbac_rule_lists(self): """Create rule lists for both policies.""" # do not expand yet, to keep memory # use down as long as possible self.log.debug("Building RBAC rule lists from {0.left_policy}".format(self)) for rule in self.left_policy.rbacrules(): self._left_rbac_rules[rule.ruletype].append(rule) self.log.debug("Building RBAC rule lists from {0.right_policy}".format(self)) for rule in self.right_policy.rbacrules(): self._right_rbac_rules[rule.ruletype].append(rule) self.log.debug("Completed building RBAC rule lists.") def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting RBAC rule differences") self.added_role_allows = None self.removed_role_allows = None self.modified_role_allows = None self.added_role_transitions = None self.removed_role_transitions = None self.modified_role_transitions = None # Sets of rules for each policy self._left_rbac_rules.clear() self._right_rbac_rules.clear() class RoleAllowWrapper(Wrapper): """Wrap role allow rules to allow set operations.""" __slots__ = ("source", "target") def __init__(self, rule): self.origin = rule self.source = role_wrapper_factory(rule.source) self.target = role_wrapper_factory(rule.target) self.key = hash(rule) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): # because RBACRuleDifference groups rules by ruletype, # the ruletype always matches. return self.source == other.source and self.target == other.target class RoleTransitionWrapper(Wrapper): """Wrap role_transition rules to allow set operations.""" __slots__ = ("source", "target", "tclass") def __init__(self, rule): self.origin = rule self.source = role_wrapper_factory(rule.source) self.target = type_or_attr_wrapper_factory(rule.target) self.tclass = class_wrapper_factory(rule.tclass) self.key = hash(rule) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): # because RBACRuleDifference groups rules by ruletype, # the ruletype always matches. return self.source == other.source and \ self.target == other.target and \ self.tclass == other.tclass terules.py000064400000057332152534333500006616 0ustar00# Copyright 2015-2016, Tresys Technology, LLC # Copyright 2016, 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # import logging from collections import defaultdict, namedtuple from sys import intern from enum import Enum from ..exception import RuleNotConditional, RuleUseError, TERuleNoFilename from ..policyrep import IoctlSet, TERuletype from .conditional import conditional_wrapper_factory from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper from .types import type_wrapper_factory, type_or_attr_wrapper_factory from .objclass import class_wrapper_factory TERULES_UNCONDITIONAL = intern("<>") TERULES_UNCONDITIONAL_BLOCK = intern("True") modified_avrule_record = namedtuple("modified_avrule", ["rule", "added_perms", "removed_perms", "matched_perms"]) modified_terule_record = namedtuple("modified_terule", ["rule", "added_default", "removed_default"]) class Side(Enum): left = 0 right = 1 rule_db_side_data_record = namedtuple("rule_db_side_data", ["perms", "orig_rule"]) rule_db_sides_record = namedtuple("rule_db_sides", ["left", "right"]) type_db_record = namedtuple("Type_db", ["left", "right"]) def _avrule_expand_generator(rule_list, rule_db, type_db, side): """ Using rule_list, build up rule_db which is a data structure which consists of nested dicts that store BOTH the left and the right policies. All of the keys are interned strings. The permissions are stored as a set. The basic structure is rule_db[cond_exp][block_bool][src][tgt][tclass] = sides where: cond_exp is a boolean expression block_bool is either true or false src is the source type tgt is the target type tclass is the target class sides is a named tuple with attributes "left" and "right" referring to the left or right policy. Each attribute in the sides named tuple refers to a named tuple with attributes "perms" and "orig_rule" which refer to a permission set and the original unexpanded rule. sides = ((left_perms, left_orig_rule),(right_perms, right_orig_rule)) There are a few advantages to this structure. First, it takes up way less memory. Second, it allows redundant rules to be easily eliminated. And, third, it makes it easy to create the added, removed, and modified rules. """ if side == Side.left: types = type_db.left else: types = type_db.right for unexpanded_rule in rule_list: cond_exp = TERULES_UNCONDITIONAL block_bool = TERULES_UNCONDITIONAL_BLOCK try: cond_exp = intern(str(unexpanded_rule.conditional)) block_bool = intern(str(unexpanded_rule.conditional_block)) except RuleNotConditional: pass if cond_exp not in rule_db: rule_db[cond_exp] = dict() rule_db[cond_exp][block_bool] = dict() elif block_bool not in rule_db[cond_exp]: rule_db[cond_exp][block_bool] = dict() tclass = unexpanded_rule.tclass.name perms = {p for p in unexpanded_rule.perms} side_data = rule_db_side_data_record(perms, unexpanded_rule) block = rule_db[cond_exp][block_bool] for src in unexpanded_rule.source.expand(): src_str = src.name if src_str not in types: types[src_str] = src if src_str not in block: block[src_str] = dict() for tgt in unexpanded_rule.target.expand(): tgt_str = tgt.name if tgt_str not in types: types[tgt_str] = tgt if tgt_str not in block[src_str]: block[src_str][tgt_str] = dict() left_side = None right_side = None if tclass in block[src_str][tgt_str]: sides = block[src_str][tgt_str][tclass] left_side = sides.left right_side = sides.right if side == Side.left: if not left_side: left_side = side_data else: """ The original tuple and perm set might be shared with many expanded rules so a new ones must created. Using "|=" would cause the old perm set to be modified instead of creating a new one. """ p = left_side.perms | perms orig = left_side.orig_rule left_side = rule_db_side_data_record(p, orig) else: if not right_side: right_side = side_data else: """ Must create new tuple and perm set as explained above. """ p = right_side.perms | perms orig = right_side.orig_rule right_side = rule_db_side_data_record(p, orig) block[src_str][tgt_str][tclass] = rule_db_sides_record(left_side, right_side) def _av_remove_redundant_rules(rule_db): uncond_block = rule_db[TERULES_UNCONDITIONAL][TERULES_UNCONDITIONAL_BLOCK] for cond_exp, cond_blocks in rule_db.items(): if cond_exp == TERULES_UNCONDITIONAL: continue for block_bool, block in cond_blocks.items(): for src, src_data in block.items(): if src not in uncond_block: continue for tgt, tgt_data in src_data.items(): if tgt not in uncond_block[src]: continue for tclass, side_data in tgt_data.items(): if tclass not in uncond_block[src][tgt]: continue uncond_side_data = uncond_block[src][tgt][tclass] left_side = side_data.left right_side = side_data.right if uncond_side_data.left and left_side: c = left_side.perms & uncond_side_data.left.perms if c: p = left_side.perms - c if p: left_side = rule_db_side_data_record(p, left_side.orig_rule) else: left_side = None tgt_data[tclass] = rule_db_sides_record(left_side, right_side) if uncond_side_data.right and right_side: c = right_side.perms & uncond_side_data.right.perms if c: p = right_side.perms - c if p: right_side = rule_db_side_data_record(p, right_side.orig_rule) else: right_side = None tgt_data[tclass] = rule_db_sides_record(left_side, right_side) def _av_generate_diffs(ruletype, rule_db, type_db): added = [] removed = [] modified = [] for cond_exp, cond_blocks in rule_db.items(): for block_bool, block in cond_blocks.items(): for src, src_data in block.items(): for tgt, tgt_data in src_data.items(): for tclass, side_data in tgt_data.items(): if side_data.left and side_data.right: common_perms = side_data.left.perms & side_data.right.perms left_perms = side_data.left.perms - common_perms right_perms = side_data.right.perms - common_perms if left_perms or right_perms: original_rule = side_data.left.orig_rule rule = original_rule.derive_expanded( type_db.left[src], type_db.left[tgt], side_data.left.perms) modified.append(modified_avrule_record(rule, right_perms, left_perms, common_perms)) elif side_data.left: original_rule = side_data.left.orig_rule rule = original_rule.derive_expanded( type_db.left[src], type_db.left[tgt], side_data.left.perms) removed.append(rule) elif side_data.right: original_rule = side_data.right.orig_rule rule = original_rule.derive_expanded( type_db.right[src], type_db.right[tgt], side_data.right.perms) added.append(rule) return added, removed, modified def av_diff_template(ruletype): """ This is a template for the access vector diff functions. Parameters: ruletype The rule type, e.g. "allow". """ ruletype = TERuletype.lookup(ruletype) def diff(self): """Generate the difference in rules between the policies.""" self.log.info( "Generating {0} differences from {1.left_policy} to {1.right_policy}". format(ruletype, self)) if not self._left_te_rules or not self._right_te_rules: self._create_te_rule_lists() type_db = type_db_record(dict(), dict()) rule_db = dict() rule_db[TERULES_UNCONDITIONAL] = dict() rule_db[TERULES_UNCONDITIONAL][TERULES_UNCONDITIONAL_BLOCK] = dict() logging.info("Expanding left policy") _avrule_expand_generator(self._left_te_rules[ruletype], rule_db, type_db, Side.left) logging.info("Expanding right policy") _avrule_expand_generator(self._right_te_rules[ruletype], rule_db, type_db, Side.right) logging.info("Removing redundant rules") _av_remove_redundant_rules(rule_db) logging.info("Generating added, removed, and modified av rules") added, removed, modified = _av_generate_diffs(ruletype, rule_db, type_db) type_db.left.clear() type_db.right.clear() rule_db.clear() setattr(self, "added_{0}s".format(ruletype), added) setattr(self, "removed_{0}s".format(ruletype), removed) setattr(self, "modified_{0}s".format(ruletype), modified) return diff def _avxrule_expand_generator(rule_list, WrapperClass): """ Generator that yields wrapped, expanded, av(x) rules with unioned permission sets. """ items = dict() for unexpanded_rule in rule_list: for expanded_rule in unexpanded_rule.expand(): expanded_wrapped_rule = WrapperClass(expanded_rule) # create a hash table (dict) with the first rule # as the key and value. Rules where permission sets should # be unioned together have the same hash, so this will union # the permissions together. try: items[expanded_wrapped_rule].perms |= expanded_wrapped_rule.perms except KeyError: items[expanded_wrapped_rule] = expanded_wrapped_rule if items: logging.getLogger(__name__).debug( "Expanded {0.ruletype} rules for {0.policy}: {1}".format( unexpanded_rule, len(items))) return items.keys() def avx_diff_template(ruletype): """ This is a template for the extended permission access vector diff functions. Parameters: ruletype The rule type, e.g. "allowxperm". """ ruletype = TERuletype.lookup(ruletype) def diff(self): """Generate the difference in rules between the policies.""" self.log.info( "Generating {0} differences from {1.left_policy} to {1.right_policy}". format(ruletype, self)) if not self._left_te_rules or not self._right_te_rules: self._create_te_rule_lists() added, removed, matched = self._set_diff( _avxrule_expand_generator(self._left_te_rules[ruletype], AVRuleXpermWrapper), _avxrule_expand_generator(self._right_te_rules[ruletype], AVRuleXpermWrapper), unwrap=False) modified = [] for left_rule, right_rule in matched: # Criteria for modified rules # 1. change to permissions added_perms, removed_perms, matched_perms = self._set_diff(left_rule.perms, right_rule.perms, unwrap=False) # the final set comprehension is to avoid having lists # like [("perm1", "perm1"), ("perm2", "perm2")], as the # matched_perms return from _set_diff is a set of tuples if added_perms or removed_perms: modified.append(modified_avrule_record(left_rule.origin, IoctlSet(added_perms), IoctlSet(removed_perms), IoctlSet(p[0] for p in matched_perms))) setattr(self, "added_{0}s".format(ruletype), set(a.origin for a in added)) setattr(self, "removed_{0}s".format(ruletype), set(r.origin for r in removed)) setattr(self, "modified_{0}s".format(ruletype), modified) return diff def te_diff_template(ruletype): """ This is a template for the type_* diff functions. Parameters: ruletype The rule type, e.g. "type_transition". """ ruletype = TERuletype.lookup(ruletype) def diff(self): """Generate the difference in rules between the policies.""" self.log.info( "Generating {0} differences from {1.left_policy} to {1.right_policy}". format(ruletype, self)) if not self._left_te_rules or not self._right_te_rules: self._create_te_rule_lists() added, removed, matched = self._set_diff( self._expand_generator(self._left_te_rules[ruletype], TERuleWrapper), self._expand_generator(self._right_te_rules[ruletype], TERuleWrapper)) modified = [] for left_rule, right_rule in matched: # Criteria for modified rules # 1. change to default type if type_wrapper_factory(left_rule.default) != type_wrapper_factory(right_rule.default): modified.append(modified_terule_record(left_rule, right_rule.default, left_rule.default)) setattr(self, "added_{0}s".format(ruletype), added) setattr(self, "removed_{0}s".format(ruletype), removed) setattr(self, "modified_{0}s".format(ruletype), modified) return diff class TERulesDifference(Difference): """ Determine the difference in type enforcement rules between two policies. """ diff_allows = av_diff_template("allow") added_allows = DiffResultDescriptor("diff_allows") removed_allows = DiffResultDescriptor("diff_allows") modified_allows = DiffResultDescriptor("diff_allows") diff_auditallows = av_diff_template("auditallow") added_auditallows = DiffResultDescriptor("diff_auditallows") removed_auditallows = DiffResultDescriptor("diff_auditallows") modified_auditallows = DiffResultDescriptor("diff_auditallows") diff_neverallows = av_diff_template("neverallow") added_neverallows = DiffResultDescriptor("diff_neverallows") removed_neverallows = DiffResultDescriptor("diff_neverallows") modified_neverallows = DiffResultDescriptor("diff_neverallows") diff_dontaudits = av_diff_template("dontaudit") added_dontaudits = DiffResultDescriptor("diff_dontaudits") removed_dontaudits = DiffResultDescriptor("diff_dontaudits") modified_dontaudits = DiffResultDescriptor("diff_dontaudits") diff_allowxperms = avx_diff_template("allowxperm") added_allowxperms = DiffResultDescriptor("diff_allowxperms") removed_allowxperms = DiffResultDescriptor("diff_allowxperms") modified_allowxperms = DiffResultDescriptor("diff_allowxperms") diff_auditallowxperms = avx_diff_template("auditallowxperm") added_auditallowxperms = DiffResultDescriptor("diff_auditallowxperms") removed_auditallowxperms = DiffResultDescriptor("diff_auditallowxperms") modified_auditallowxperms = DiffResultDescriptor("diff_auditallowxperms") diff_neverallowxperms = avx_diff_template("neverallowxperm") added_neverallowxperms = DiffResultDescriptor("diff_neverallowxperms") removed_neverallowxperms = DiffResultDescriptor("diff_neverallowxperms") modified_neverallowxperms = DiffResultDescriptor("diff_neverallowxperms") diff_dontauditxperms = avx_diff_template("dontauditxperm") added_dontauditxperms = DiffResultDescriptor("diff_dontauditxperms") removed_dontauditxperms = DiffResultDescriptor("diff_dontauditxperms") modified_dontauditxperms = DiffResultDescriptor("diff_dontauditxperms") diff_type_transitions = te_diff_template("type_transition") added_type_transitions = DiffResultDescriptor("diff_type_transitions") removed_type_transitions = DiffResultDescriptor("diff_type_transitions") modified_type_transitions = DiffResultDescriptor("diff_type_transitions") diff_type_changes = te_diff_template("type_change") added_type_changes = DiffResultDescriptor("diff_type_changes") removed_type_changes = DiffResultDescriptor("diff_type_changes") modified_type_changes = DiffResultDescriptor("diff_type_changes") diff_type_members = te_diff_template("type_member") added_type_members = DiffResultDescriptor("diff_type_members") removed_type_members = DiffResultDescriptor("diff_type_members") modified_type_members = DiffResultDescriptor("diff_type_members") # Lists of rules for each policy _left_te_rules = defaultdict(list) _right_te_rules = defaultdict(list) # # Internal functions # def _create_te_rule_lists(self): """Create rule lists for both policies.""" # do not expand yet, to keep memory # use down as long as possible self.log.debug("Building TE rule lists from {0.left_policy}".format(self)) for rule in self.left_policy.terules(): self._left_te_rules[rule.ruletype].append(rule) for ruletype, rules in self._left_te_rules.items(): self.log.debug("Loaded {0} {1} rules.".format(len(rules), ruletype)) self.log.debug("Building TE rule lists from {0.right_policy}".format(self)) for rule in self.right_policy.terules(): self._right_te_rules[rule.ruletype].append(rule) for ruletype, rules in self._right_te_rules.items(): self.log.debug("Loaded {0} {1} rules.".format(len(rules), ruletype)) self.log.debug("Completed building TE rule lists.") def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting TE rule differences") self.added_allows = None self.removed_allows = None self.modified_allows = None self.added_auditallows = None self.removed_auditallows = None self.modified_auditallows = None self.added_neverallows = None self.removed_neverallows = None self.modified_neverallows = None self.added_dontaudits = None self.removed_dontaudits = None self.modified_dontaudits = None self.added_allowxperms = None self.removed_allowxperms = None self.modified_allowxperms = None self.added_auditallowxperms = None self.removed_auditallowxperms = None self.modified_auditallowxperms = None self.added_neverallowxperms = None self.removed_neverallowxperms = None self.modified_neverallowxperms = None self.added_dontauditxperms = None self.removed_dontauditxperms = None self.modified_dontauditxperms = None self.added_type_transitions = None self.removed_type_transitions = None self.modified_type_transitions = None self.added_type_changes = None self.removed_type_changes = None self.modified_type_changes = None self.added_type_members = None self.removed_type_members = None self.modified_type_members = None # Sets of rules for each policy self._left_te_rules.clear() self._right_te_rules.clear() class AVRuleXpermWrapper(Wrapper): """Wrap extended permission access vector rules to allow set operations.""" __slots__ = ("source", "target", "tclass", "xperm_type", "perms") def __init__(self, rule): self.origin = rule self.source = type_or_attr_wrapper_factory(rule.source) self.target = type_or_attr_wrapper_factory(rule.target) self.tclass = class_wrapper_factory(rule.tclass) self.xperm_type = rule.xperm_type self.perms = rule.perms self.key = hash(rule) def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): # because TERuleDifference groups rules by ruletype, # the ruletype always matches. return self.source == other.source and \ self.target == other.target and \ self.tclass == other.tclass and \ self.xperm_type == other.xperm_type class TERuleWrapper(Wrapper): """Wrap type_* rules to allow set operations.""" __slots__ = ("source", "target", "tclass", "conditional", "conditional_block", "filename") def __init__(self, rule): self.origin = rule self.source = type_or_attr_wrapper_factory(rule.source) self.target = type_or_attr_wrapper_factory(rule.target) self.tclass = class_wrapper_factory(rule.tclass) self.key = hash(rule) try: self.conditional = conditional_wrapper_factory(rule.conditional) self.conditional_block = rule.conditional_block except RuleNotConditional: self.conditional = None self.conditional_block = None try: self.filename = rule.filename except (RuleUseError, TERuleNoFilename): self.filename = None def __hash__(self): return self.key def __lt__(self, other): return self.key < other.key def __eq__(self, other): # because TERuleDifference groups rules by ruletype, # the ruletype always matches. return self.source == other.source and \ self.target == other.target and \ self.tclass == other.tclass and \ self.conditional == other.conditional and \ self.conditional_block == other.conditional_block and \ self.filename == other.filename difference.py000064400000013244152534333500007217 0ustar00# Copyright 2015-2016, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # import logging from abc import ABC, abstractmethod from collections import namedtuple modified_item_record = namedtuple("modified_item", ["left", "right"]) class Difference: """Base class for all policy differences.""" def __init__(self, left_policy, right_policy): self.log = logging.getLogger(__name__) self.left_policy = left_policy self.right_policy = right_policy # # Policies to compare # @property def left_policy(self): return self._left_policy @left_policy.setter def left_policy(self, policy): self.log.info("Policy diff left policy set to {0}".format(policy)) self._left_policy = policy self._reset_diff() @property def right_policy(self): return self._right_policy @right_policy.setter def right_policy(self, policy): self.log.info("Policy diff right policy set to {0}".format(policy)) self._right_policy = policy self._reset_diff() # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" raise NotImplementedError @staticmethod def _expand_generator(rule_list, Wrapper): """Generator that yields a wrapped, expanded rule list.""" # this is to delay creating any containers # as long as possible, since rule lists # are typically massive. for unexpanded_rule in rule_list: for expanded_rule in unexpanded_rule.expand(): yield Wrapper(expanded_rule) @staticmethod def _set_diff(left, right, key=None, unwrap=True): """ Standard diff of two sets. Parameters: left An iterable right An iterable Return: tuple (added, removed, matched) added Set of items in right but not left removed Set of items in left but not right matched Set of items in both left and right. This is in the form of tuples with the matching item from left and right """ left_items = set(left) right_items = set(right) added_items = right_items - left_items removed_items = left_items - right_items # The problem here is the symbol from both policies are # needed to build each tuple in the matched items set. # Using the standard Python set intersection code will only result # in one object. # # This tuple-generating code creates lists from the sets, to sort them. # This should result in all of the symbols lining up. If they don't, # this will break the caller. This should work since there is no remapping. # # This has extra checking to make sure this assertion holds, to fail # instead of giving wrong results. If there is a better way to, # ensure the items match up, please let me know how or submit a patch. matched_items = set() left_matched_items = sorted((left_items - removed_items), key=key) right_matched_items = sorted((right_items - added_items), key=key) assert len(left_matched_items) == len(right_matched_items), \ "Matched items assertion failure (this is an SETools bug), {0} != {1}". \ format(len(left_matched_items), len(right_matched_items)) for left, right in zip(left_matched_items, right_matched_items): assert left == right, \ "Matched items assertion failure (this is an SETools bug), {0} != {1}".format( left, right) matched_items.add((left, right)) if unwrap: return set(i.origin for i in added_items), \ set(i.origin for i in removed_items), \ set((left.origin, right.origin) for (left, right) in matched_items) else: return added_items, removed_items, matched_items class Wrapper(ABC): """Abstract base class for policy object wrappers.""" __slots__ = ("origin", "key") def __repr__(self): # pylint: disable=no-member return "<{0.__class__.__name__}(Wrapping {1})>".format(self, repr(self.origin)) @abstractmethod def __hash__(self): pass @abstractmethod def __eq__(self, other): pass @abstractmethod def __lt__(self, other): pass def __ne__(self, other): return not self == other class SymbolWrapper(Wrapper): """ General wrapper for policy symbols, e.g. types, roles to provide a diff-specific equality operation based on its name. """ __slots__ = ("name") def __init__(self, symbol): self.origin = symbol self.name = str(symbol) self.key = hash(self.name) def __hash__(self): return self.key def __lt__(self, other): return self.name < other.name def __eq__(self, other): return self.name == other.name __init__.py000064400000006226152534333500006666 0ustar00# Copyright 2015-2016, Tresys Technology, LLC # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from .bool import BooleansDifference from .bounds import BoundsDifference from .commons import CommonDifference from .constraints import ConstraintsDifference from .default import DefaultsDifference from .fsuse import FSUsesDifference from .genfscon import GenfsconsDifference from .ibendportcon import IbendportconsDifference from .ibpkeycon import IbpkeyconsDifference from .initsid import InitialSIDsDifference from .mls import CategoriesDifference, LevelDeclsDifference, SensitivitiesDifference from .mlsrules import MLSRulesDifference from .netifcon import NetifconsDifference from .nodecon import NodeconsDifference from .objclass import ObjClassDifference from .polcap import PolCapsDifference from .portcon import PortconsDifference from .properties import PropertiesDifference from .rbacrules import RBACRulesDifference from .roles import RolesDifference from .terules import TERulesDifference from .typeattr import TypeAttributesDifference from .types import TypesDifference from .users import UsersDifference __all__ = ['PolicyDifference'] class PolicyDifference(BooleansDifference, BoundsDifference, CategoriesDifference, CommonDifference, ConstraintsDifference, DefaultsDifference, FSUsesDifference, GenfsconsDifference, IbendportconsDifference, IbpkeyconsDifference, InitialSIDsDifference, LevelDeclsDifference, MLSRulesDifference, NetifconsDifference, NodeconsDifference, ObjClassDifference, PolCapsDifference, PortconsDifference, PropertiesDifference, RBACRulesDifference, RolesDifference, SensitivitiesDifference, TERulesDifference, TypeAttributesDifference, TypesDifference, UsersDifference): """ Determine the differences from the left policy to the right policy. Parameters: left A policy right A policy """ def _reset_diff(self): """Reset diff results on policy changes.""" for c in PolicyDifference.__bases__: c._reset_diff(self) objclass.py000064400000007152152534333500006726 0ustar00# Copyright 2015, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from contextlib import suppress from ..exception import NoCommon from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper modified_classes_record = namedtuple("modified_class", ["added_perms", "removed_perms", "matched_perms"]) _class_cache = defaultdict(dict) def class_wrapper_factory(class_): """ Wrap class from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _class_cache[class_.policy][class_] except KeyError: c = SymbolWrapper(class_) _class_cache[class_.policy][class_] = c return c class ObjClassDifference(Difference): """ Determine the difference in object classes between two policies. """ added_classes = DiffResultDescriptor("diff_classes") removed_classes = DiffResultDescriptor("diff_classes") modified_classes = DiffResultDescriptor("diff_classes") def diff_classes(self): """Generate the difference in object classes between the policies.""" self.log.info( "Generating class differences from {0.left_policy} to {0.right_policy}".format(self)) self.added_classes, self.removed_classes, matched_classes = self._set_diff( (SymbolWrapper(c) for c in self.left_policy.classes()), (SymbolWrapper(c) for c in self.right_policy.classes())) self.modified_classes = dict() for left_class, right_class in matched_classes: # Criteria for modified classes # 1. change to permissions (inherited common is expanded) left_perms = left_class.perms with suppress(NoCommon): left_perms |= left_class.common.perms right_perms = right_class.perms with suppress(NoCommon): right_perms |= right_class.common.perms added_perms, removed_perms, matched_perms = self._set_diff(left_perms, right_perms, unwrap=False) if added_perms or removed_perms: self.modified_classes[left_class] = modified_classes_record(added_perms, removed_perms, matched_perms) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting object class differences") self.added_classes = None self.removed_classes = None self.modified_classes = None nodecon.py000064400000006331152534333500006551 0ustar00# Copyright 2016, Tresys Technology, LLC # Copyright 2017, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import namedtuple from .context import ContextWrapper from .descriptors import DiffResultDescriptor from .difference import Difference, Wrapper modified_nodecon_record = namedtuple("modified_nodecon", ["rule", "added_context", "removed_context"]) class NodeconsDifference(Difference): """Determine the difference in nodecons between two policies.""" added_nodecons = DiffResultDescriptor("diff_nodecons") removed_nodecons = DiffResultDescriptor("diff_nodecons") modified_nodecons = DiffResultDescriptor("diff_nodecons") def diff_nodecons(self): """Generate the difference in nodecons between the policies.""" self.log.info("Generating nodecon differences from {0.left_policy} to {0.right_policy}". format(self)) self.added_nodecons, self.removed_nodecons, matched_nodecons = self._set_diff( (NodeconWrapper(n) for n in self.left_policy.nodecons()), (NodeconWrapper(n) for n in self.right_policy.nodecons())) self.modified_nodecons = [] for left_nodecon, right_nodecon in matched_nodecons: # Criteria for modified nodecons # 1. change to context if ContextWrapper(left_nodecon.context) != ContextWrapper(right_nodecon.context): self.modified_nodecons.append(modified_nodecon_record(left_nodecon, right_nodecon.context, left_nodecon.context)) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting nodecon differences") self.added_nodecons = None self.removed_nodecons = None self.modified_nodecons = None class NodeconWrapper(Wrapper): """Wrap nodecon statements for diff purposes.""" __slots__ = ("ip_version", "network") def __init__(self, ocon): self.origin = ocon self.ip_version = ocon.ip_version self.network = ocon.network self.key = hash(ocon) def __hash__(self): return self.key def __lt__(self, other): return self.origin < other.origin def __eq__(self, other): return self.ip_version == other.ip_version and \ self.network == other.network roles.py000064400000006313152534333500006250 0ustar00# Copyright 2015, Tresys Technology, LLC # Copyright 2018, Chris PeBenito # # This file is part of SETools. # # SETools is free software: you can redistribute it and/or modify # it under the terms of the GNU Lesser General Public License as # published by the Free Software Foundation, either version 2.1 of # the License, or (at your option) any later version. # # SETools is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Lesser General Public License for more details. # # You should have received a copy of the GNU Lesser General Public # License along with SETools. If not, see # . # from collections import defaultdict, namedtuple from .descriptors import DiffResultDescriptor from .difference import Difference, SymbolWrapper from .types import type_wrapper_factory modified_roles_record = namedtuple("modified_role", ["added_types", "removed_types", "matched_types"]) _roles_cache = defaultdict(dict) def role_wrapper_factory(role): """ Wrap roles from the specified policy. This caches results to prevent duplicate wrapper objects in memory. """ try: return _roles_cache[role.policy][role] except KeyError: r = SymbolWrapper(role) _roles_cache[role.policy][role] = r return r class RolesDifference(Difference): """Determine the difference in roles between two policies.""" added_roles = DiffResultDescriptor("diff_roles") removed_roles = DiffResultDescriptor("diff_roles") modified_roles = DiffResultDescriptor("diff_roles") def diff_roles(self): """Generate the difference in roles between the policies.""" self.log.info( "Generating role differences from {0.left_policy} to {0.right_policy}".format(self)) self.added_roles, self.removed_roles, matched_roles = self._set_diff( (role_wrapper_factory(r) for r in self.left_policy.roles()), (role_wrapper_factory(r) for r in self.right_policy.roles())) self.modified_roles = dict() for left_role, right_role in matched_roles: # Criteria for modified roles # 1. change to type set, or # 2. change to attribute set (not implemented) added_types, removed_types, matched_types = self._set_diff( (type_wrapper_factory(t) for t in left_role.types()), (type_wrapper_factory(t) for t in right_role.types())) if added_types or removed_types: self.modified_roles[left_role] = modified_roles_record(added_types, removed_types, matched_types) # # Internal functions # def _reset_diff(self): """Reset diff results on policy changes.""" self.log.debug("Resetting role differences") self.added_roles = None self.removed_roles = None self.modified_roles = None