1 # Copyright 2016, Tresys Technology, LLC 2 # 3 # This file is part of SETools. 4 # 5 # SETools is free software: you can redistribute it and/or modify 6 # it under the terms of the GNU Lesser General Public License as 7 # published by the Free Software Foundation, either version 2.1 of 8 # the License, or (at your option) any later version. 9 # 10 # SETools is distributed in the hope that it will be useful, 11 # but WITHOUT ANY WARRANTY; without even the implied warranty of 12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 13 # GNU Lesser General Public License for more details. 14 # 15 # You should have received a copy of the GNU Lesser General Public 16 # License along with SETools. If not, see 17 # <http://www.gnu.org/licenses/>. 18 # 19 from collections import namedtuple 20 21 from .descriptors import DiffResultDescriptor 22 from .difference import Difference, SymbolWrapper, Wrapper 23 24 25 modified_rbacrule_record = namedtuple("modified_rbacrule", ["rule", 26 "added_default", 27 "removed_default"]) 28 29 30 class RBACRulesDifference(Difference): 31 32 """Determine the difference in RBAC rules between two policies.""" 33 34 added_role_allows = DiffResultDescriptor("diff_role_allows") 35 removed_role_allows = DiffResultDescriptor("diff_role_allows") 36 # role allows cannot be modified, only added/removed 37 38 added_role_transitions = DiffResultDescriptor("diff_role_transitions") 39 removed_role_transitions = DiffResultDescriptor("diff_role_transitions") 40 modified_role_transitions = DiffResultDescriptor("diff_role_transitions") 41 42 # Lists of rules for each policy 43 _left_role_allows = None 44 _right_role_allows = None 45 46 _left_role_transitions = None 47 _right_role_transitions = None 48 49 def diff_role_allows(self): 50 """Generate the difference in role allow rules between the policies.""" 51 52 self.log.info( 53 "Generating role allow differences from {0.left_policy} to {0.right_policy}". 54 format(self)) 55 56 if self._left_role_allows is None or self._right_role_allows is None: 57 self._create_rbac_rule_lists() 58 59 self.added_role_allows, self.removed_role_allows, _ = \ 60 self._set_diff(self._expand_generator(self._left_role_allows, RoleAllowWrapper), 61 self._expand_generator(self._right_role_allows, RoleAllowWrapper)) 62 63 def diff_role_transitions(self): 64 """Generate the difference in role_transition rules between the policies.""" 65 66 self.log.info( 67 "Generating role_transition differences from {0.left_policy} to {0.right_policy}". 68 format(self)) 69 70 if self._left_role_transitions is None or self._right_role_transitions is None: 71 self._create_rbac_rule_lists() 72 73 self.added_role_transitions, \ 74 self.removed_role_transitions, \ 75 self.modified_role_transitions = self._diff_rbac_rules( 76 self._expand_generator(self._left_role_transitions, RoleTransitionWrapper), 77 self._expand_generator(self._right_role_transitions, RoleTransitionWrapper)) 78 79 # 80 # Internal functions 81 # 82 def _create_rbac_rule_lists(self): 83 """Create rule lists for both policies.""" 84 self._left_role_allows = [] 85 self._left_role_transitions = [] 86 for rule in self.left_policy.rbacrules(): 87 # do not expand yet, to keep memory 88 # use down as long as possible 89 if rule.ruletype == "allow": 90 self._left_role_allows.append(rule) 91 elif rule.ruletype == "role_transition": 92 self._left_role_transitions.append(rule) 93 else: 94 self.log.error("Unknown rule type: {0} (This is an SETools bug)". 95 format(rule.ruletype)) 96 97 self._right_role_allows = [] 98 self._right_role_transitions = [] 99 for rule in self.right_policy.rbacrules(): 100 # do not expand yet, to keep memory 101 # use down as long as possible 102 if rule.ruletype == "allow": 103 self._right_role_allows.append(rule) 104 elif rule.ruletype == "role_transition": 105 self._right_role_transitions.append(rule) 106 else: 107 self.log.error("Unknown rule type: {0} (This is an SETools bug)". 108 format(rule.ruletype)) 109 110 def _diff_rbac_rules(self, left_list, right_list): 111 """Common method for comparing rbac rules.""" 112 added, removed, matched = self._set_diff(left_list, right_list) 113 114 modified = [] 115 116 for left_rule, right_rule in matched: 117 # Criteria for modified rules 118 # 1. change to default role 119 if SymbolWrapper(left_rule.default) != SymbolWrapper(right_rule.default): 120 modified.append(modified_rbacrule_record(left_rule, 121 right_rule.default, 122 left_rule.default)) 123 124 return added, removed, modified 125 126 def _reset_diff(self): 127 """Reset diff results on policy changes.""" 128 self.log.debug("Resetting RBAC rule differences") 129 self.added_role_allows = None 130 self.removed_role_allows = None 131 self.modified_role_allows = None 132 self.added_role_transitions = None 133 self.removed_role_transitions = None 134 self.modified_role_transitions = None 135 136 # Sets of rules for each policy 137 self._left_role_allows = None 138 self._right_role_allows = None 139 self._left_role_transitions = None 140 self._right_role_transitions = None 141 142 143 class RoleAllowWrapper(Wrapper): 144 145 """Wrap role allow rules to allow set operations.""" 146 147 def __init__(self, rule): 148 self.origin = rule 149 self.ruletype = rule.ruletype 150 self.source = SymbolWrapper(rule.source) 151 self.target = SymbolWrapper(rule.target) 152 self.key = hash(rule) 153 154 def __hash__(self): 155 return self.key 156 157 def __lt__(self, other): 158 return self.key < other.key 159 160 def __eq__(self, other): 161 # because RBACRuleDifference groups rules by ruletype, 162 # the ruletype always matches. 163 return self.source == other.source and self.target == other.target 164 165 166 class RoleTransitionWrapper(Wrapper): 167 168 """Wrap role_transition rules to allow set operations.""" 169 170 def __init__(self, rule): 171 self.origin = rule 172 self.ruletype = rule.ruletype 173 self.source = SymbolWrapper(rule.source) 174 self.target = SymbolWrapper(rule.target) 175 self.tclass = SymbolWrapper(rule.tclass) 176 self.key = hash(rule) 177 178 def __hash__(self): 179 return self.key 180 181 def __lt__(self, other): 182 return self.key < other.key 183 184 def __eq__(self, other): 185 # because RBACRuleDifference groups rules by ruletype, 186 # the ruletype always matches. 187 return self.source == other.source and \ 188 self.target == other.target and \ 189 self.tclass == other.tclass 190