/
usr
/
sbin
/
/usr/sbin
mkdir
upload
Name
Size
Mode
Actions
accessdb
15792
0755
edit
dl
rm
addgnupghome
3079
0755
edit
dl
rm
addpart
15520
0755
edit
dl
rm
adduser
141144
0755
edit
dl
rm
agetty
58072
0755
edit
dl
rm
alternatives
40544
0755
edit
dl
rm
anacron
40464
0755
edit
dl
rm
apachectl
4808
0755
edit
dl
rm
applygnupgdefaults
2221
0755
edit
dl
rm
arp
64728
0755
edit
dl
rm
arping
27904
0755
edit
dl
rm
arptables
236960
0755
edit
dl
rm
arptables-nft
236960
0755
edit
dl
rm
arptables-nft-restore
236960
0755
edit
dl
rm
arptables-nft-save
236960
0755
edit
dl
rm
arptables-restore
236960
0755
edit
dl
rm
arptables-save
236960
0755
edit
dl
rm
atd
32008
0755
edit
dl
rm
atrun
70
0755
edit
dl
rm
auditctl
52824
0755
edit
dl
rm
auditd
140336
0755
edit
dl
rm
augenrules
4146
0755
edit
dl
rm
aureport
123192
0755
edit
dl
rm
ausearch
123160
0755
edit
dl
rm
autrace
19632
0750
edit
dl
rm
avcstat
15720
0755
edit
dl
rm
badblocks
36200
0755
edit
dl
rm
blkdeactivate
16355
0555
edit
dl
rm
blkdiscard
23760
0755
edit
dl
rm
blkid
52848
0755
edit
dl
rm
blkmapd
40360
0755
edit
dl
rm
blkzone
36304
0755
edit
dl
rm
blockdev
32168
0755
edit
dl
rm
bridge
134088
0755
edit
dl
rm
cache_check
3046296
0755
edit
dl
rm
cache_dump
3046296
0755
edit
dl
rm
cache_metadata_size
3046296
0755
edit
dl
rm
cache_repair
3046296
0755
edit
dl
rm
cache_restore
3046296
0755
edit
dl
rm
cache_writeback
3046296
0755
edit
dl
rm
capsh
31960
0755
edit
dl
rm
cfdisk
98656
0755
edit
dl
rm
chcpu
32176
0755
edit
dl
rm
chgpasswd
61200
0755
edit
dl
rm
chkconfig
44832
0755
edit
dl
rm
chpasswd
56968
0755
edit
dl
rm
chronyd
382544
0755
edit
dl
rm
chroot
40504
0755
edit
dl
rm
clock
61200
0755
edit
dl
rm
consoletype
15648
0755
edit
dl
rm
convertquota
70664
0755
edit
dl
rm
cracklib-check
15472
0755
edit
dl
rm
cracklib-format
255
0755
edit
dl
rm
cracklib-packer
15472
0755
edit
dl
rm
cracklib-unpacker
15464
0755
edit
dl
rm
create-cracklib-dict
994
0755
edit
dl
rm
crond
77992
0755
edit
dl
rm
ctrlaltdel
15552
0755
edit
dl
rm
ctstat
24160
0755
edit
dl
rm
dcb
96960
0755
edit
dl
rm
ddns-confgen
27912
0755
edit
dl
rm
debugfs
238624
0755
edit
dl
rm
delpart
15480
0755
edit
dl
rm
depmod
169544
0755
edit
dl
rm
devlink
169816
0755
edit
dl
rm
dmeventd
53032
0555
edit
dl
rm
dmfilemapd
23856
0555
edit
dl
rm
dmsetup
160536
0555
edit
dl
rm
dmstats
160536
0555
edit
dl
rm
dnssec-cds
48816
0755
edit
dl
rm
dnssec-checkds
924
0755
edit
dl
rm
dnssec-coverage
926
0755
edit
dl
rm
dnssec-dsfromkey
40384
0755
edit
dl
rm
dnssec-importkey
36288
0755
edit
dl
rm
dnssec-keyfromlabel
40368
0755
edit
dl
rm
dnssec-keygen
48584
0755
edit
dl
rm
dnssec-keymgr
922
0755
edit
dl
rm
dnssec-revoke
32168
0755
edit
dl
rm
dnssec-settime
48576
0755
edit
dl
rm
dnssec-signzone
98184
0755
edit
dl
rm
dnssec-verify
32200
0755
edit
dl
rm
dosfsck
86592
0755
edit
dl
rm
dosfslabel
40976
0755
edit
dl
rm
dovecot
147480
0755
edit
dl
rm
dovecot_cpshutdown
3344
0755
edit
dl
rm
dpll
49312
0755
edit
dl
rm
dumpe2fs
32040
0755
edit
dl
rm
e2freefrag
15552
0755
edit
dl
rm
e2fsck
364632
0755
edit
dl
rm
e2image
44456
0755
edit
dl
rm
e2label
106968
0755
edit
dl
rm
e2mmpstatus
32040
0755
edit
dl
rm
e2undo
23712
0755
edit
dl
rm
e4crypt
32048
0755
edit
dl
rm
e4defrag
32008
0755
edit
dl
rm
ebtables
236960
0755
edit
dl
rm
ebtables-nft
236960
0755
edit
dl
rm
ebtables-nft-restore
236960
0755
edit
dl
rm
ebtables-nft-save
236960
0755
edit
dl
rm
ebtables-restore
236960
0755
edit
dl
rm
ebtables-save
236960
0755
edit
dl
rm
ebtables-translate
236960
0755
edit
dl
rm
edquota
91648
0755
edit
dl
rm
efibootdump
24440
0755
edit
dl
rm
efibootmgr
46264
0755
edit
dl
rm
era_check
3046296
0755
edit
dl
rm
era_dump
3046296
0755
edit
dl
rm
era_invalidate
3046296
0755
edit
dl
rm
era_restore
3046296
0755
edit
dl
rm
ether-wake
51448
0755
edit
dl
rm
ethtool
1012696
0755
edit
dl
rm
exicyclog
11365
0755
edit
dl
rm
exigrep
11710
0755
edit
dl
rm
exim
1728848
4755
edit
dl
rm
eximstats
152546
0755
edit
dl
rm
exim_checkaccess
4943
0755
edit
dl
rm
exim_dbmbuild
23040
0755
edit
dl
rm
exim_dumpdb
41872
0755
edit
dl
rm
exim_fixdb
46360
0755
edit
dl
rm
exim_lock
23328
0755
edit
dl
rm
exim_tidydb
33472
0755
edit
dl
rm
exinext
8217
0755
edit
dl
rm
exiqgrep
6739
0755
edit
dl
rm
exiqsumm
6443
0755
edit
dl
rm
exiwhat
4524
0755
edit
dl
rm
exportfs
70112
0755
edit
dl
rm
faillock
23736
0755
edit
dl
rm
fatlabel
40976
0755
edit
dl
rm
fcgistarter
25304
0755
edit
dl
rm
fdformat
23744
0755
edit
dl
rm
fdisk
114760
0755
edit
dl
rm
filefrag
19680
0755
edit
dl
rm
findfs
15520
0755
edit
dl
rm
firewalld
9989
0755
edit
dl
rm
fix-info-dir
8037
0755
edit
dl
rm
fixfiles
12387
0755
edit
dl
rm
fsadm
24602
0555
edit
dl
rm
fsck
44592
0755
edit
dl
rm
fsck.cramfs
32128
0755
edit
dl
rm
fsck.ext2
364632
0755
edit
dl
rm
fsck.ext3
364632
0755
edit
dl
rm
fsck.ext4
364632
0755
edit
dl
rm
fsck.fat
86592
0755
edit
dl
rm
fsck.minix
57048
0755
edit
dl
rm
fsck.msdos
86592
0755
edit
dl
rm
fsck.vfat
86592
0755
edit
dl
rm
fsck.xfs
2598
0755
edit
dl
rm
fsfreeze
15512
0755
edit
dl
rm
fstrim
44544
0755
edit
dl
rm
fuser
42072
0755
edit
dl
rm
g13-syshelp
90728
0755
edit
dl
rm
genhomedircon
32808
0755
edit
dl
rm
genhostid
15648
0755
edit
dl
rm
genl
133272
0755
edit
dl
rm
getcap
15496
0755
edit
dl
rm
getenforce
15640
0755
edit
dl
rm
getpcaps
15488
0755
edit
dl
rm
getpidprevcon
15656
0755
edit
dl
rm
getpolicyload
15648
0755
edit
dl
rm
getsebool
15664
0755
edit
dl
rm
groupadd
70424
0755
edit
dl
rm
groupdel
66080
0755
edit
dl
rm
groupmems
57112
0755
edit
dl
rm
groupmod
74504
0755
edit
dl
rm
grpck
61192
0755
edit
dl
rm
grpconv
52800
0755
edit
dl
rm
grpunconv
52768
0755
edit
dl
rm
grub2-bios-setup
1749904
0755
edit
dl
rm
grub2-get-kernel-settings
2746
0755
edit
dl
rm
grub2-install
2068520
0755
edit
dl
rm
grub2-macbless
1728872
0755
edit
dl
rm
grub2-mkconfig
9431
0755
edit
dl
rm
grub2-probe
1745984
0755
edit
dl
rm
grub2-reboot
4814
0755
edit
dl
rm
grub2-set-bootflag
15456
4755
edit
dl
rm
grub2-set-default
3538
0755
edit
dl
rm
grub2-set-password
2809
0755
edit
dl
rm
grub2-setpassword
2809
0755
edit
dl
rm
grub2-switch-to-blscfg
9024
0755
edit
dl
rm
grubby
260
0755
edit
dl
rm
gssproxy
127888
0755
edit
dl
rm
halt
305576
0755
edit
dl
rm
htcacheclean
54072
0755
edit
dl
rm
httpd
1139720
0755
edit
dl
rm
hwclock
61200
0755
edit
dl
rm
iconvconfig
32432
0755
edit
dl
rm
ifconfig
80880
0755
edit
dl
rm
ifdown
1097
0755
edit
dl
rm
ifenslave
24304
0755
edit
dl
rm
ifstat
40552
0755
edit
dl
rm
ifup
1066
0755
edit
dl
rm
imunify-notifier
10325616
0755
edit
dl
rm
init
98040
0755
edit
dl
rm
insmod
169544
0755
edit
dl
rm
install-info
109256
0755
edit
dl
rm
installkernel
323
0755
edit
dl
rm
intel_sdsi
22968
0755
edit
dl
rm
ip
792904
0755
edit
dl
rm
ip6tables
236960
0755
edit
dl
rm
ip6tables-nft
236960
0755
edit
dl
rm
ip6tables-nft-restore
236960
0755
edit
dl
rm
ip6tables-nft-save
236960
0755
edit
dl
rm
ip6tables-restore
236960
0755
edit
dl
rm
ip6tables-restore-translate
236960
0755
edit
dl
rm
ip6tables-save
236960
0755
edit
dl
rm
ip6tables-translate
236960
0755
edit
dl
rm
ipmaddr
19912
0755
edit
dl
rm
ipset
15640
0755
edit
dl
rm
ipset-translate
15640
0755
edit
dl
rm
iptables
236960
0755
edit
dl
rm
iptables-nft
236960
0755
edit
dl
rm
iptables-nft-restore
236960
0755
edit
dl
rm
iptables-nft-save
236960
0755
edit
dl
rm
iptables-restore
236960
0755
edit
dl
rm
iptables-restore-translate
236960
0755
edit
dl
rm
iptables-save
236960
0755
edit
dl
rm
iptables-translate
236960
0755
edit
dl
rm
iptunnel
19968
0755
edit
dl
rm
irqbalance
65992
0755
edit
dl
rm
irqbalance-ui
40536
0755
edit
dl
rm
kexec
197216
0755
edit
dl
rm
key.dns_resolver
32104
0755
edit
dl
rm
kpartx
48664
0755
edit
dl
rm
lchage
23720
0755
edit
dl
rm
ldattach
27880
0755
edit
dl
rm
ldconfig
1176464
0755
edit
dl
rm
lgroupadd
15480
0755
edit
dl
rm
lgroupdel
15472
0755
edit
dl
rm
lgroupmod
23680
0755
edit
dl
rm
lid
19592
0755
edit
dl
rm
lnewusers
23680
0755
edit
dl
rm
lnstat
24160
0755
edit
dl
rm
load_policy
15480
0755
edit
dl
rm
logrotate
97960
0755
edit
dl
rm
logsave
15552
0755
edit
dl
rm
losetup
73816
0755
edit
dl
rm
lpasswd
23680
0755
edit
dl
rm
lshw
874064
0755
edit
dl
rm
lsmod
169544
0755
edit
dl
rm
lspci
99912
0755
edit
dl
rm
luseradd
23680
0755
edit
dl
rm
luserdel
15480
0755
edit
dl
rm
lusermod
23688
0755
edit
dl
rm
lvchange
2831072
0555
edit
dl
rm
lvconvert
2831072
0555
edit
dl
rm
lvcreate
2831072
0555
edit
dl
rm
lvdisplay
2831072
0555
edit
dl
rm
lvextend
2831072
0555
edit
dl
rm
lvm
2831072
0555
edit
dl
rm
lvmconfig
2831072
0555
edit
dl
rm
lvmdevices
2831072
0555
edit
dl
rm
lvmdiskscan
2831072
0555
edit
dl
rm
lvmdump
10378
0555
edit
dl
rm
lvmpolld
215344
0555
edit
dl
rm
lvmsadc
2831072
0555
edit
dl
rm
lvmsar
2831072
0555
edit
dl
rm
lvm_import_vdo
23708
0555
edit
dl
rm
lvreduce
2831072
0555
edit
dl
rm
lvremove
2831072
0555
edit
dl
rm
lvrename
2831072
0555
edit
dl
rm
lvresize
2831072
0555
edit
dl
rm
lvs
2831072
0555
edit
dl
rm
lvscan
2831072
0555
edit
dl
rm
makedumpfile
442208
0755
edit
dl
rm
matchpathcon
15680
0755
edit
dl
rm
mii-diag
24776
0755
edit
dl
rm
mii-tool
28448
0755
edit
dl
rm
mkdict
255
0755
edit
dl
rm
mkdosfs
53768
0755
edit
dl
rm
mkdumprd
12418
0755
edit
dl
rm
mke2fs
135712
0755
edit
dl
rm
mkfs
15536
0755
edit
dl
rm
mkfs.cramfs
36224
0755
edit
dl
rm
mkfs.ext2
135712
0755
edit
dl
rm
mkfs.ext3
135712
0755
edit
dl
rm
mkfs.ext4
135712
0755
edit
dl
rm
mkfs.fat
53768
0755
edit
dl
rm
mkfs.minix
44600
0755
edit
dl
rm
mkfs.msdos
53768
0755
edit
dl
rm
mkfs.vfat
53768
0755
edit
dl
rm
mkfs.xfs
461592
0755
edit
dl
rm
mkhomedir_helper
23768
0755
edit
dl
rm
mklost+found
15480
0755
edit
dl
rm
mksquashfs
202360
0755
edit
dl
rm
mkswap
48640
0755
edit
dl
rm
modinfo
169544
0755
edit
dl
rm
modprobe
169544
0755
edit
dl
rm
modsec-sdbm-util
34368
0750
edit
dl
rm
mount.fuse
15704
0755
edit
dl
rm
mount.fuse3
19832
0755
edit
dl
rm
mount.nfs
102936
4755
edit
dl
rm
mount.nfs4
102936
4755
edit
dl
rm
mountstats
43519
0755
edit
dl
rm
mysqld
56687576
0755
edit
dl
rm
named
558104
0755
edit
dl
rm
named-checkconf
40344
0755
edit
dl
rm
named-checkzone
40288
0755
edit
dl
rm
named-compilezone
40288
0755
edit
dl
rm
named-journalprint
15496
0755
edit
dl
rm
named-nzd2nzf
15480
0755
edit
dl
rm
nameif
15952
0755
edit
dl
rm
NetworkManager
3893928
0755
edit
dl
rm
newusers
90832
0755
edit
dl
rm
nfsconf
40816
0755
edit
dl
rm
nfsdcld
57208
0755
edit
dl
rm
nfsdclddb
10230
0755
edit
dl
rm
nfsdclnts
9271
0755
edit
dl
rm
nfsdcltrack
40872
0755
edit
dl
rm
nfsidmap
23856
0755
edit
dl
rm
nfsiostat
23910
0755
edit
dl
rm
nfsref
44560
0755
edit
dl
rm
nfsstat
39192
0755
edit
dl
rm
nft
27824
0755
edit
dl
rm
nologin
15520
0755
edit
dl
rm
nscd
166856
0755
edit
dl
rm
nsec3hash
15560
0755
edit
dl
rm
nstat
32088
0755
edit
dl
rm
packer
15472
0755
edit
dl
rm
pam_console_apply
44552
0755
edit
dl
rm
pam_namespace_helper
471
0755
edit
dl
rm
pam_timestamp_check
15496
4755
edit
dl
rm
paperconfig
4173
0755
edit
dl
rm
parted
98704
0755
edit
dl
rm
partprobe
15704
0755
edit
dl
rm
partx
61200
0755
edit
dl
rm
pdata_tools
3046296
0755
edit
dl
rm
pdns_server
6162800
0755
edit
dl
rm
pidof
23888
0755
edit
dl
rm
ping
91472
0755
edit
dl
rm
ping6
91472
0755
edit
dl
rm
pivot_root
15520
0755
edit
dl
rm
plipconfig
15720
0755
edit
dl
rm
poweroff
305576
0755
edit
dl
rm
pure-authd
23568
0755
edit
dl
rm
pure-certd
23472
0755
edit
dl
rm
pure-config.pl
4755
0755
edit
dl
rm
pure-ftpd
181376
0755
edit
dl
rm
pure-ftpwho
27216
0755
edit
dl
rm
pure-mrtginfo
14896
0755
edit
dl
rm
pure-quotacheck
23104
0755
edit
dl
rm
pure-uploadscript
23376
0755
edit
dl
rm
pvchange
2831072
0555
edit
dl
rm
pvck
2831072
0555
edit
dl
rm
pvcreate
2831072
0555
edit
dl
rm
pvdisplay
2831072
0555
edit
dl
rm
pvmove
2831072
0555
edit
dl
rm
pvremove
2831072
0555
edit
dl
rm
pvresize
2831072
0555
edit
dl
rm
pvs
2831072
0555
edit
dl
rm
pvscan
2831072
0555
edit
dl
rm
pwck
56936
0755
edit
dl
rm
pwconv
48584
0755
edit
dl
rm
pwhistory_helper
19656
0755
edit
dl
rm
pwunconv
48544
0755
edit
dl
rm
quotacheck
95864
0755
edit
dl
rm
quotaoff
58032
0755
edit
dl
rm
quotaon
58032
0755
edit
dl
rm
quotastats
15704
0755
edit
dl
rm
rdisc
32112
0755
edit
dl
rm
rdma
119872
0755
edit
dl
rm
readprofile
23824
0755
edit
dl
rm
reboot
305576
0755
edit
dl
rm
repquota
79416
0755
edit
dl
rm
request-key
27944
0755
edit
dl
rm
resize2fs
69264
0755
edit
dl
rm
resizepart
23960
0755
edit
dl
rm
restorecon
23744
0755
edit
dl
rm
restorecon_xattr
15488
0755
edit
dl
rm
rfkill
32096
0755
edit
dl
rm
rmmod
169544
0755
edit
dl
rm
rndc
44288
0755
edit
dl
rm
rndc-confgen
23816
0755
edit
dl
rm
rotatelogs
39048
0755
edit
dl
rm
route
67352
0755
edit
dl
rm
rpc.gssd
90224
0755
edit
dl
rm
rpc.idmapd
48880
0755
edit
dl
rm
rpc.mountd
135736
0755
edit
dl
rm
rpc.nfsd
40960
0755
edit
dl
rm
rpc.statd
82728
0755
edit
dl
rm
rpcbind
61328
0755
edit
dl
rm
rpcctl
9645
0755
edit
dl
rm
rpcdebug
19104
0755
edit
dl
rm
rpcinfo
36432
0755
edit
dl
rm
rsyslogd
826240
0755
edit
dl
rm
rtacct
30048
0755
edit
dl
rm
rtcwake
36104
0755
edit
dl
rm
rtkitctl
15608
0755
edit
dl
rm
rtmon
129080
0755
edit
dl
rm
rtstat
24160
0755
edit
dl
rm
runlevel
305576
0755
edit
dl
rm
runq
1728848
4755
edit
dl
rm
runuser
56944
0755
edit
dl
rm
sasldblistusers2
15640
0755
edit
dl
rm
saslpasswd2
15608
0755
edit
dl
rm
sefcontext_compile
74120
0755
edit
dl
rm
selabel_digest
15680
0755
edit
dl
rm
selabel_get_digests_all_partial_matches
15696
0755
edit
dl
rm
selabel_lookup
15672
0755
edit
dl
rm
selabel_lookup_best_match
15680
0755
edit
dl
rm
selabel_partial_match
15672
0755
edit
dl
rm
selinuxconlist
15672
0755
edit
dl
rm
selinuxdefcon
15672
0755
edit
dl
rm
selinuxenabled
15640
0755
edit
dl
rm
selinuxexeccon
15656
0755
edit
dl
rm
selinux_check_access
15680
0755
edit
dl
rm
semanage
41614
0755
edit
dl
rm
semodule
32808
0755
edit
dl
rm
sendmail
18512
2755
edit
dl
rm
service
4623
0755
edit
dl
rm
sestatus
23680
0755
edit
dl
rm
setcap
15488
0755
edit
dl
rm
setenforce
15664
0755
edit
dl
rm
setfiles
23744
0755
edit
dl
rm
setpci
32104
0755
edit
dl
rm
setquota
83536
0755
edit
dl
rm
setsebool
19608
0755
edit
dl
rm
sfdisk
106480
0755
edit
dl
rm
showmount
15848
0755
edit
dl
rm
shutdown
305576
0755
edit
dl
rm
slattach
38472
0755
edit
dl
rm
sm-notify
53016
0755
edit
dl
rm
smartctl
874328
0755
edit
dl
rm
smartd
630240
0755
edit
dl
rm
ss
134472
0755
edit
dl
rm
sshd
416664
0755
edit
dl
rm
sssd
73328
0755
edit
dl
rm
sss_cache
36096
0755
edit
dl
rm
start-statd
1027
0755
edit
dl
rm
start-stop-daemon
49816
0755
edit
dl
rm
suexec
38504
4755
edit
dl
rm
sulogin
44440
0755
edit
dl
rm
sw-engine-fpm
25314680
0755
edit
dl
rm
swaplabel
19648
0755
edit
dl
rm
swapoff
23824
0755
edit
dl
rm
swapon
44352
0755
edit
dl
rm
switch_root
23760
0755
edit
dl
rm
sysctl
32248
0755
edit
dl
rm
tc
655456
0755
edit
dl
rm
tcpdump
1340256
0755
edit
dl
rm
tcpslice
28048
0755
edit
dl
rm
telinit
305576
0755
edit
dl
rm
thin_check
3046296
0755
edit
dl
rm
thin_delta
3046296
0755
edit
dl
rm
thin_dump
3046296
0755
edit
dl
rm
thin_ls
3046296
0755
edit
dl
rm
thin_metadata_pack
3046296
0755
edit
dl
rm
thin_metadata_size
3046296
0755
edit
dl
rm
thin_metadata_unpack
3046296
0755
edit
dl
rm
thin_migrate
3046296
0755
edit
dl
rm
thin_repair
3046296
0755
edit
dl
rm
thin_restore
3046296
0755
edit
dl
rm
thin_rmap
3046296
0755
edit
dl
rm
thin_trim
3046296
0755
edit
dl
rm
tipc
95024
0755
edit
dl
rm
tmpwatch
36896
0755
edit
dl
rm
tracepath
19680
0755
edit
dl
rm
tracepath6
19680
0755
edit
dl
rm
tsig-keygen
27912
0755
edit
dl
rm
tune2fs
106968
0755
edit
dl
rm
udevadm
601960
0755
edit
dl
rm
umount.nfs
102936
4755
edit
dl
rm
umount.nfs4
102936
4755
edit
dl
rm
unix_chkpwd
23848
4755
edit
dl
rm
unix_update
32080
0700
edit
dl
rm
unsquashfs
116536
0755
edit
dl
rm
update-alternatives
40544
0755
edit
dl
rm
update-pciids
1757
0755
edit
dl
rm
update-smart-drivedb
23885
0755
edit
dl
rm
useradd
141144
0755
edit
dl
rm
userdel
90968
0755
edit
dl
rm
usermod
132776
0755
edit
dl
rm
validatetrans
15656
0755
edit
dl
rm
vdpa
36736
0755
edit
dl
rm
vgcfgbackup
2831072
0555
edit
dl
rm
vgcfgrestore
2831072
0555
edit
dl
rm
vgchange
2831072
0555
edit
dl
rm
vgck
2831072
0555
edit
dl
rm
vgconvert
2831072
0555
edit
dl
rm
vgcreate
2831072
0555
edit
dl
rm
vgdisplay
2831072
0555
edit
dl
rm
vgexport
2831072
0555
edit
dl
rm
vgextend
2831072
0555
edit
dl
rm
vgimport
2831072
0555
edit
dl
rm
vgimportclone
2831072
0555
edit
dl
rm
vgimportdevices
2831072
0555
edit
dl
rm
vgmerge
2831072
0555
edit
dl
rm
vgmknodes
2831072
0555
edit
dl
rm
vgreduce
2831072
0555
edit
dl
rm
vgremove
2831072
0555
edit
dl
rm
vgrename
2831072
0555
edit
dl
rm
vgs
2831072
0555
edit
dl
rm
vgscan
2831072
0555
edit
dl
rm
vgsplit
2831072
0555
edit
dl
rm
vigr
59552
0755
edit
dl
rm
vipw
59552
0755
edit
dl
rm
visudo
273680
0755
edit
dl
rm
vmcore-dmesg
27952
0755
edit
dl
rm
weak-modules
34384
0755
edit
dl
rm
whmapi0
3478112
0755
edit
dl
rm
whmapi1
3478112
0755
edit
dl
rm
whmlogin
2390
0755
edit
dl
rm
wipefs
40224
0755
edit
dl
rm
xfs_admin
2178
0755
edit
dl
rm
xfs_bmap
699
0755
edit
dl
rm
xfs_copy
94840
0755
edit
dl
rm
xfs_db
725072
0755
edit
dl
rm
xfs_estimate
15528
0755
edit
dl
rm
xfs_freeze
804
0755
edit
dl
rm
xfs_fsr
44552
0755
edit
dl
rm
xfs_growfs
44680
0755
edit
dl
rm
xfs_info
1298
0755
edit
dl
rm
xfs_io
207456
0755
edit
dl
rm
xfs_logprint
90376
0755
edit
dl
rm
xfs_mdrestore
27936
0755
edit
dl
rm
xfs_metadump
786
0755
edit
dl
rm
xfs_mkfile
1044
0755
edit
dl
rm
xfs_ncheck
689
0755
edit
dl
rm
xfs_quota
94312
0755
edit
dl
rm
xfs_repair
702704
0755
edit
dl
rm
xfs_rtcp
19600
0755
edit
dl
rm
xfs_spaceman
44832
0755
edit
dl
rm
xqmstats
15696
0755
edit
dl
rm
xtables-monitor
236960
0755
edit
dl
rm
xtables-nft-multi
236960
0755
edit
dl
rm
zic
61056
0755
edit
dl
rm
zramctl
57208
0755
edit
dl
rm
Edit:
/usr/sbin/semanage
(41614B)
#!/usr/bin/python3 -EsI # Copyright (C) 2012-2013 Red Hat # AUTHOR: Miroslav Grepl <mgrepl@redhat.com> # AUTHOR: David Quigley <selinux@davequigley.com> # see file 'COPYING' for use and warranty information # # semanage is a tool for managing SELinux configuration files # # This program is free software; you can redistribute it and/or # modify it under the terms of the GNU General Public License as # published by the Free Software Foundation; either version 2 of # the License, or (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program; if not, write to the Free Software # Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA # 02111-1307 USA # # import argparse import os import re import seobject import sys import traceback PROGNAME = "selinux-python" try: import gettext kwargs = {} if sys.version_info < (3,): kwargs['unicode'] = True t = gettext.translation(PROGNAME, localedir="/usr/share/locale", **kwargs, fallback=True) _ = t.gettext except: try: import builtins builtins.__dict__['_'] = str except ImportError: import __builtin__ __builtin__.__dict__['_'] = unicode # define custom usages for selected main actions usage_login = "semanage login [-h] [-n] [-N] [-S STORE] [" usage_login_dict = {' --add': ('-s SEUSER', '-r RANGE', 'LOGIN',), ' --modify': ('-s SEUSER', '-r RANGE', 'LOGIN',), ' --delete': ('LOGIN',), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} usage_fcontext = "semanage fcontext [-h] [-n] [-N] [-S STORE] [" usage_fcontext_dict = {' --add': ('(', '-t TYPE', '-f FTYPE', '-r RANGE', '-s SEUSER', '|', '-e EQUAL', ')', 'FILE_SPEC',), ' --delete': ('(', '-t TYPE', '-f FTYPE', '|', '-e EQUAL', ')', 'FILE_SPEC',), ' --modify': ('(', '-t TYPE', '-f FTYPE', '-r RANGE', '-s SEUSER', '|', '-e EQUAL', ')', 'FILE_SPEC',), ' --list': ('[-C]',), ' --extract': ('',), ' --deleteall': ('',)} usage_user = "semanage user [-h] [-n] [-N] [-S STORE] [" usage_user_dict = {' --add': ('(', '-L LEVEL', '-R ROLES', '-r RANGE', 'SEUSER', ')'), ' --delete': ('SEUSER',), ' --modify': ('(', '-L LEVEL', '-R ROLES', '-r RANGE', '-s SEUSER', 'SEUSER', ')'), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} usage_port = "semanage port [-h] [-n] [-N] [-S STORE] [" usage_port_dict = {' --add': ('-t TYPE', '-p PROTOCOL', '-r RANGE', '(', 'port_name', '|', 'port_range', ')'), ' --modify': ('-t TYPE', '-p PROTOCOL', '-r RANGE', '(', 'port_name', '|', 'port_range', ')'), ' --delete': ('-p PROTOCOL', '(', 'port_name', '|', 'port_range', ')'), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} usage_ibpkey = "semanage ibpkey [-h] [-n] [-N] [-s STORE] [" usage_ibpkey_dict = {' --add': ('-t TYPE', '-x SUBNET_PREFIX', '-r RANGE', '(', 'ibpkey_name', '|', 'pkey_range', ')'), ' --modify': ('-t TYPE', '-x SUBNET_PREFIX', '-r RANGE', '(', 'ibpkey_name', '|', 'pkey_range', ')'), ' --delete': ('-x SUBNET_PREFIX', '(', 'ibpkey_name', '|', 'pkey_range', ')'), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} usage_ibendport = "semanage ibendport [-h] [-n] [-N] [-s STORE] [" usage_ibendport_dict = {' --add': ('-t TYPE', '-z IBDEV_NAME', '-r RANGE', '(', 'port', ')'), ' --modify': ('-t TYPE', '-z IBDEV_NAME', '-r RANGE', '(', 'port', ')'), ' --delete': ('-z IBDEV_NAME', '-r RANGE', '(', 'port', ')'), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} usage_node = "semanage node [-h] [-n] [-N] [-S STORE] [" usage_node_dict = {' --add': ('-M NETMASK', '-p PROTOCOL', '-t TYPE', '-r RANGE', 'node'), ' --modify': ('-M NETMASK', '-p PROTOCOL', '-t TYPE', '-r RANGE', 'node'), ' --delete': ('-M NETMASK', '-p PROTOCOL', 'node'), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} usage_interface = "semanage interface [-h] [-n] [-N] [-S STORE] [" usage_interface_dict = {' --add': ('-t TYPE', '-r RANGE', 'interface'), ' --modify': ('-t TYPE', '-r RANGE', 'interface'), ' --delete': ('interface',), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} usage_boolean = "semanage boolean [-h] [-n] [-N] [-S STORE] [" usage_boolean_dict = {' --modify': ('(', '--on', '|', '--off', ')', 'boolean'), ' --list': ('-C',), ' --extract': ('',), ' --deleteall': ('',)} class CheckRole(argparse.Action): def __call__(self, parser, namespace, value, option_string=None): newval = getattr(namespace, self.dest) if not newval: newval = [] try: # sepolicy tries to load the SELinux policy and raises ValueError if it fails. import sepolicy roles = sepolicy.get_all_roles() except ValueError: roles = [] for v in value.split(): if v not in roles: raise ValueError("%s must be an SELinux role:\nValid roles: %s" % (v, ", ".join(roles))) newval.append(v) setattr(namespace, self.dest, newval) class seParser(argparse.ArgumentParser): def error(self, message): if len(sys.argv) == 2: self.print_help() else: self.print_usage() self.exit(2, ('%s: error: %s\n') % (self.prog, message)) class SetExportFile(argparse.Action): def __call__(self, parser, namespace, values, option_string=None): if values: if values != "-": try: sys.stdout = open(values, 'w') except: sys.stderr.write(traceback.format_exc()) sys.exit(1) setattr(namespace, self.dest, values) class SetImportFile(argparse.Action): def __call__(self, parser, namespace, values, option_string=None): if values and values != "-": try: sys.stdin = open(values, 'r') except IOError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, str(e))) sys.exit(1) setattr(namespace, self.dest, values) # define dictionary for seobject OBJECTS object_dict = { 'login': seobject.loginRecords, 'user': seobject.seluserRecords, 'port': seobject.portRecords, 'module': seobject.moduleRecords, 'interface': seobject.interfaceRecords, 'node': seobject.nodeRecords, 'fcontext': seobject.fcontextRecords, 'boolean': seobject.booleanRecords, 'permissive': seobject.permissiveRecords, 'dontaudit': seobject.dontauditClass, 'ibpkey': seobject.ibpkeyRecords, 'ibendport': seobject.ibendportRecords } def generate_custom_usage(usage_text, usage_dict): # generate custom usage from given text and dictionary sorted_keys = [] for i in usage_dict.keys(): sorted_keys.append(i) sorted_keys.sort() for k in sorted_keys: usage_text += "%s %s |" % (k, (" ".join(usage_dict[k]))) usage_text = usage_text[:-1] + "]" usage_text = _(usage_text) return usage_text def handle_opts(args, dict, target_key): # handle conflict and required options for given dictionary # {action:[conflict_opts,require_opts]} # first we need to catch conflicts for k in args.__dict__.keys(): try: if k in dict[target_key][0] and args.__dict__[k]: print("%s option can not be used with --%s" % (target_key, k)) sys.exit(2) except KeyError: continue for k in args.__dict__.keys(): try: if k in dict[target_key][1] and not args.__dict__[k]: print("%s option is needed for %s" % (k, target_key)) sys.exit(2) except KeyError: continue def handleLogin(args): # {action:[conflict_opts,require_opts]} login_args = {'list': [('login', 'seuser'), ('')], 'add': [('locallist'), ('seuser', 'login')], 'modify': [('locallist'), ('login')], 'delete': [('locallist'), ('login')], 'extract': [('locallist', 'login', 'seuser'), ('')], 'deleteall': [('locallist'), ('')]} handle_opts(args, login_args, args.action) OBJECT = object_dict['login'](args) if args.action == "add": OBJECT.add(args.login, args.seuser, args.range) if args.action == "modify": OBJECT.modify(args.login, args.seuser, args.range) if args.action == "delete": OBJECT.delete(args.login) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("login %s" % (str(i))) def parser_add_store(parser, name): parser.add_argument('-S', '--store', default='', help=_("Select an alternate SELinux Policy Store to manage")) def parser_add_priority(parser, name): parser.add_argument('-P', '--priority', type=int, default=400, help=_("Select a priority for module operations")) def parser_add_noheading(parser, name): parser.add_argument('-n', '--noheading', action='store_false', default=True, help=_("Do not print heading when listing %s object types") % name) def parser_add_noreload(parser, name): parser.add_argument('-N', '--noreload', action='store_true', default=False, help=_('Do not reload policy after commit')) def parser_add_locallist(parser, name): parser.add_argument('-C', '--locallist', action='store_true', default=False, help=_("List %s local customizations") % name) def parser_add_add(parser, name): parser.add_argument('-a', '--add', dest='action', action='store_const', const='add', help=_("Add a record of the %s object type") % name) def parser_add_type(parser, name): parser.add_argument('-t', '--type', help=_('SELinux Type for the object')) def parser_add_level(parser, name): parser.add_argument('-L', '--level', default='s0', help=_('Default SELinux Level for SELinux user, s0 Default. (MLS/MCS Systems only)')) def parser_add_range(parser, name): parser.add_argument('-r', '--range', default='', help=_( "MLS/MCS Security Range (MLS/MCS Systems only) SELinux Range for SELinux login mapping defaults to the SELinux user record range. \ SELinux Range for SELinux user defaults to s0." )) def parser_add_proto(parser, name): parser.add_argument('-p', '--proto', help=_( "Protocol for the specified port (tcp|udp|dccp|sctp) or internet protocol version for the specified node (ipv4|ipv6)." )) def parser_add_subnet_prefix(parser, name): parser.add_argument('-x', '--subnet_prefix', help=_('Subnet prefix for the specified infiniband ibpkey.')) def parser_add_ibdev_name(parser, name): parser.add_argument('-z', '--ibdev_name', help=_("Name for the specified infiniband end port.")) def parser_add_modify(parser, name): parser.add_argument('-m', '--modify', dest='action', action='store_const', const='modify', help=_("Modify a record of the %s object type") % name) def parser_add_list(parser, name): parser.add_argument('-l', '--list', dest='action', action='store_const', const='list', help=_("List records of the %s object type") % name) def parser_add_delete(parser, name): parser.add_argument('-d', '--delete', dest='action', action='store_const', const='delete', help=_("Delete a record of the %s object type") % name) def parser_add_extract(parser, name): parser.add_argument('-E', '--extract', dest='action', action='store_const', const='extract', help=_("Extract customizable commands, for use within a transaction")) def parser_add_deleteall(parser, name): parser.add_argument('-D', '--deleteall', dest='action', action='store_const', const='deleteall', help=_('Remove all %s objects local customizations') % name) def parser_add_seuser(parser, name): parser.add_argument('-s', '--seuser', default="", help=_("SELinux user name")) def setupLoginParser(subparsers): generated_usage = generate_custom_usage(usage_login, usage_login_dict) loginParser = subparsers.add_parser('login', usage=generated_usage, help=_("Manage login mappings between linux users and SELinux confined users")) parser_add_locallist(loginParser, "login") parser_add_noheading(loginParser, "login") parser_add_noreload(loginParser, "login") parser_add_store(loginParser, "login") parser_add_range(loginParser, "login") login_action = loginParser.add_mutually_exclusive_group(required=True) parser_add_add(login_action, "login") parser_add_delete(login_action, "login") parser_add_modify(login_action, "login") parser_add_list(login_action, "login") parser_add_extract(login_action, "login") parser_add_deleteall(login_action, "login") parser_add_seuser(loginParser, "login") loginParser.add_argument('login', nargs='?', default=None, help=_("login_name | %%groupname")) loginParser.set_defaults(func=handleLogin) def handleFcontext(args): fcontext_args = {'list': [('equal', 'ftype', 'seuser', 'type'), ('')], 'add': [('locallist'), ('type', 'file_spec')], 'modify': [('locallist'), ('type', 'file_spec')], 'delete': [('locallist'), ('file_spec')], 'extract': [('locallist', 'equal', 'ftype', 'seuser', 'type'), ('')], 'deleteall': [('locallist'), ('')]} # we can not use mutually for equal because we can define some actions together with equal fcontext_equal_args = {'equal': [('list', 'locallist', 'type', 'ftype', 'seuser', 'deleteall', 'extract'), ()]} if args.action and args.equal: handle_opts(args, fcontext_equal_args, "equal") else: handle_opts(args, fcontext_args, args.action) OBJECT = object_dict['fcontext'](args) if args.action == "add": if args.equal: OBJECT.add_equal(args.file_spec, args.equal) else: OBJECT.add(args.file_spec, args.type, args.ftype, args.range, args.seuser) if args.action == "modify": if args.equal: OBJECT.modify_equal(args.file_spec, args.equal) else: OBJECT.modify(args.file_spec, args.type, args.ftype, args.range, args.seuser) if args.action == "delete": if args.equal: OBJECT.delete(args.file_spec, args.equal) else: OBJECT.delete(args.file_spec, args.ftype) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("fcontext %s" % str(i)) def setupFcontextParser(subparsers): generate_usage = generate_custom_usage(usage_fcontext, usage_fcontext_dict) fcontextParser = subparsers.add_parser('fcontext', usage=generate_usage, help=_("Manage file context mapping definitions")) parser_add_locallist(fcontextParser, "fcontext") parser_add_noheading(fcontextParser, "fcontext") parser_add_noreload(fcontextParser, "fcontext") parser_add_store(fcontextParser, "fcontext") fcontext_action = fcontextParser.add_mutually_exclusive_group(required=True) parser_add_add(fcontext_action, "fcontext") parser_add_delete(fcontext_action, "fcontext") parser_add_modify(fcontext_action, "fcontext") parser_add_list(fcontext_action, "fcontext") parser_add_extract(fcontext_action, "fcontext") parser_add_deleteall(fcontext_action, "fcontext") fcontextParser.add_argument('-e', '--equal', help=_( 'Substitute target path with sourcepath when generating default label. This is used with fcontext. Requires source and target \ path arguments. The context labeling for the target subtree is made equivalent to that defined for the source.' )) fcontextParser.add_argument('-f', '--ftype', default="", choices=["a", "f", "d", "c", "b", "s", "l", "p"], help=_( 'File Type. This is used with fcontext. Requires a file type as shown in the mode field by ls, e.g. use d to match only \ directories or f to match only regular files. The following file type options can be passed: f (regular file), d (directory), \ c (character device), b (block device), s (socket), l (symbolic link), p (named pipe). \ If you do not specify a file type, the file type will default to "all files".' )) parser_add_seuser(fcontextParser, "fcontext") parser_add_type(fcontextParser, "fcontext") parser_add_range(fcontextParser, "fcontext") fcontextParser.add_argument('file_spec', nargs='?', default=None, help=_('Path to be labeled (may be in the form of a Perl compatible regular expression)')) fcontextParser.set_defaults(func=handleFcontext) def handleUser(args): user_args = {'list': [('selinux_name', 'seuser', 'roles'), ('')], 'add': [('locallist'), ('roles', 'selinux_name')], 'modify': [('locallist'), ('selinux_name')], 'delete': [('locallist'), ('selinux_name')], 'extract': [('locallist', 'selinux_name', 'seuser', 'role'), ('')], 'deleteall': [('locallist'), ('')]} handle_opts(args, user_args, args.action) OBJECT = object_dict['user'](args) if args.action == "add": OBJECT.add(args.selinux_name, args.roles, args.level, args.range, args.prefix) if args.action == "modify": OBJECT.modify(args.selinux_name, args.roles, args.level, args.range, args.prefix) if args.action == "delete": OBJECT.delete(args.selinux_name) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("user %s" % str(i)) def setupUserParser(subparsers): generated_usage = generate_custom_usage(usage_user, usage_user_dict) userParser = subparsers.add_parser('user', usage=generated_usage, help=_('Manage SELinux confined users (Roles and levels for an SELinux user)')) parser_add_locallist(userParser, "user") parser_add_noheading(userParser, "user") parser_add_noreload(userParser, "user") parser_add_store(userParser, "user") user_action = userParser.add_mutually_exclusive_group(required=True) parser_add_add(user_action, "user") parser_add_delete(user_action, "user") parser_add_modify(user_action, "user") parser_add_list(user_action, "user") parser_add_extract(user_action, "user") parser_add_deleteall(user_action, "user") parser_add_level(userParser, "user") parser_add_range(userParser, "user") userParser.add_argument('-R', '--roles', default=[], action=CheckRole, help=_("SELinux Roles. You must enclose multiple roles within quotes, separate by spaces. Or specify -R multiple times.")) userParser.add_argument('-P', '--prefix', default="user", help=argparse.SUPPRESS) userParser.add_argument('selinux_name', nargs='?', default=None, help=_('selinux_name')) userParser.set_defaults(func=handleUser) def handlePort(args): port_args = {'list': [('port', 'type', 'proto'), ('')], 'add': [('locallist'), ('type', 'port', 'proto')], 'modify': [('localist'), ('port', 'proto')], 'delete': [('locallist'), ('port', 'proto')], 'extract': [('locallist', 'port', 'type', 'proto'), ('')], 'deleteall': [('locallist'), ('')]} handle_opts(args, port_args, args.action) OBJECT = object_dict['port'](args) if args.action == "add": OBJECT.add(args.port, args.proto, args.range, args.type) if args.action == "modify": OBJECT.modify(args.port, args.proto, args.range, args.type) if args.action == "delete": OBJECT.delete(args.port, args.proto) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("port %s" % str(i)) def setupPortParser(subparsers): generated_usage = generate_custom_usage(usage_port, usage_port_dict) portParser = subparsers.add_parser('port', usage=generated_usage, help=_('Manage network port type definitions')) parser_add_locallist(portParser, "port") parser_add_noheading(portParser, "port") parser_add_noreload(portParser, "port") parser_add_store(portParser, "port") port_action = portParser.add_mutually_exclusive_group(required=True) parser_add_add(port_action, "port") parser_add_delete(port_action, "port") parser_add_modify(port_action, "port") parser_add_list(port_action, "port") parser_add_extract(port_action, "port") parser_add_deleteall(port_action, "port") parser_add_type(portParser, "port") parser_add_range(portParser, "port") parser_add_proto(portParser, "port") portParser.add_argument('port', nargs='?', default=None, help=_('port | port_range')) portParser.set_defaults(func=handlePort) def handlePkey(args): ibpkey_args = {'list': [('ibpkey', 'type', 'subnet_prefix'), ('')], 'add': [('locallist'), ('type', 'ibpkey', 'subnet_prefix')], 'modify': [('localist'), ('ibpkey', 'subnet_prefix')], 'delete': [('locallist'), ('ibpkey', 'subnet_prefix')], 'extract': [('locallist', 'ibpkey', 'type', 'subnet prefix'), ('')], 'deleteall': [('locallist'), ('')]} handle_opts(args, ibpkey_args, args.action) OBJECT = object_dict['ibpkey'](args) if args.action == "add": OBJECT.add(args.ibpkey, args.subnet_prefix, args.range, args.type) if args.action == "modify": OBJECT.modify(args.ibpkey, args.subnet_prefix, args.range, args.type) if args.action == "delete": OBJECT.delete(args.ibpkey, args.subnet_prefix) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("ibpkey %s" % str(i)) def setupPkeyParser(subparsers): generated_usage = generate_custom_usage(usage_ibpkey, usage_ibpkey_dict) ibpkeyParser = subparsers.add_parser('ibpkey', usage=generated_usage, help=_('Manage infiniband ibpkey type definitions')) parser_add_locallist(ibpkeyParser, "ibpkey") parser_add_noheading(ibpkeyParser, "ibpkey") parser_add_noreload(ibpkeyParser, "ibpkey") parser_add_store(ibpkeyParser, "ibpkey") ibpkey_action = ibpkeyParser.add_mutually_exclusive_group(required=True) parser_add_add(ibpkey_action, "ibpkey") parser_add_delete(ibpkey_action, "ibpkey") parser_add_modify(ibpkey_action, "ibpkey") parser_add_list(ibpkey_action, "ibpkey") parser_add_extract(ibpkey_action, "ibpkey") parser_add_deleteall(ibpkey_action, "ibpkey") parser_add_type(ibpkeyParser, "ibpkey") parser_add_range(ibpkeyParser, "ibpkey") parser_add_subnet_prefix(ibpkeyParser, "ibpkey") ibpkeyParser.add_argument('ibpkey', nargs='?', default=None, help=_('pkey | pkey_range')) ibpkeyParser.set_defaults(func=handlePkey) def handleIbendport(args): ibendport_args = {'list': [('ibendport', 'type', 'ibdev_name'), ('')], 'add': [('locallist'), ('type', 'ibendport', 'ibdev_name'), ('')], 'modify': [('localist'), ('ibendport', 'ibdev_name')], 'delete': [('locallist'), ('ibendport', 'ibdev_name')], 'extract': [('locallist', 'ibendport', 'type', 'ibdev_name'), ('')], 'deleteall': [('locallist'), ('')]} handle_opts(args, ibendport_args, args.action) OBJECT = object_dict['ibendport'](args) if args.action == "add": OBJECT.add(args.ibendport, args.ibdev_name, args.range, args.type) if args.action == "modify": OBJECT.modify(args.ibendport, args.ibdev_name, args.range, args.type) if args.action == "delete": OBJECT.delete(args.ibendport, args.ibdev_name) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("ibendport %s" % str(i)) def setupIbendportParser(subparsers): generated_usage = generate_custom_usage(usage_ibendport, usage_ibendport_dict) ibendportParser = subparsers.add_parser('ibendport', usage=generated_usage, help=_('Manage infiniband end port type definitions')) parser_add_locallist(ibendportParser, "ibendport") parser_add_noheading(ibendportParser, "ibendport") parser_add_noreload(ibendportParser, "ibendport") parser_add_store(ibendportParser, "ibendport") ibendport_action = ibendportParser.add_mutually_exclusive_group(required=True) parser_add_add(ibendport_action, "ibendport") parser_add_delete(ibendport_action, "ibendport") parser_add_modify(ibendport_action, "ibendport") parser_add_list(ibendport_action, "ibendport") parser_add_extract(ibendport_action, "ibendport") parser_add_deleteall(ibendport_action, "ibendport") parser_add_type(ibendportParser, "ibendport") parser_add_range(ibendportParser, "ibendport") parser_add_ibdev_name(ibendportParser, "ibendport") ibendportParser.add_argument('ibendport', nargs='?', default=None, help=_('ibendport')) ibendportParser.set_defaults(func=handleIbendport) def handleInterface(args): interface_args = {'list': [('interface'), ('')], 'add': [('locallist'), ('type', 'interface')], 'modify': [('locallist'), ('type', 'interface')], 'delete': [('locallist'), ('interface')], 'extract': [('locallist', 'interface', 'type'), ('')], 'deleteall': [('locallist'), ('')]} handle_opts(args, interface_args, args.action) OBJECT = object_dict['interface'](args) if args.action == "add": OBJECT.add(args.interface, args.range, args.type) if args.action == "modify": OBJECT.modify(args.interface, args.range, args.type) if args.action == "delete": OBJECT.delete(args.interface) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("interface %s" % str(i)) def setupInterfaceParser(subparsers): generated_usage = generate_custom_usage(usage_interface, usage_interface_dict) interfaceParser = subparsers.add_parser('interface', usage=generated_usage, help=_('Manage network interface type definitions')) parser_add_locallist(interfaceParser, "interface") parser_add_noheading(interfaceParser, "interface") parser_add_noreload(interfaceParser, "interface") parser_add_store(interfaceParser, "interface") parser_add_type(interfaceParser, "interface") parser_add_range(interfaceParser, "interface") interface_action = interfaceParser.add_mutually_exclusive_group(required=True) parser_add_add(interface_action, "interface") parser_add_delete(interface_action, "interface") parser_add_modify(interface_action, "interface") parser_add_list(interface_action, "interface") parser_add_extract(interface_action, "interface") parser_add_deleteall(interface_action, "interface") interfaceParser.add_argument('interface', nargs='?', default=None, help=_('interface_spec')) interfaceParser.set_defaults(func=handleInterface) def handleModule(args): OBJECT = seobject.moduleRecords(args) if args.action_add: OBJECT.add(args.action_add[0], args.priority) if args.action_enable: OBJECT.set_enabled(" ".join(args.action_enable), True) if args.action_disable: OBJECT.set_enabled(" ".join(args.action_disable), False) if args.action_remove: OBJECT.delete(" ".join(args.action_remove), args.priority) if args.action == "deleteall": OBJECT.deleteall() if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "extract": for i in OBJECT.customized(): print("module %s" % str(i)) def setupModuleParser(subparsers): moduleParser = subparsers.add_parser('module', help=_('Manage SELinux policy modules')) parser_add_noheading(moduleParser, "module") parser_add_noreload(moduleParser, "module") parser_add_store(moduleParser, "module") parser_add_locallist(moduleParser, "module") parser_add_priority(moduleParser, "module") mgroup = moduleParser.add_mutually_exclusive_group(required=True) parser_add_list(mgroup, "module") parser_add_extract(mgroup, "module") parser_add_deleteall(mgroup, "module") mgroup.add_argument('-a', '--add', dest='action_add', action='store', nargs=1, metavar='module_name', help=_("Add a module")) mgroup.add_argument('-r', '--remove', dest='action_remove', action='store', nargs='+', metavar='module_name', help=_("Remove a module")) mgroup.add_argument('-d', '--disable', dest='action_disable', action='store', nargs='+', metavar='module_name', help=_("Disable a module")) mgroup.add_argument('-e', '--enable', dest='action_enable', action='store', nargs='+', metavar='module_name', help=_("Enable a module")) moduleParser.set_defaults(func=handleModule) def handleNode(args): node_args = {'list': [('node', 'type', 'proto', 'netmask'), ('')], 'add': [('locallist'), ('type', 'node', 'proto', 'netmask')], 'modify': [('locallist'), ('node', 'netmask', 'proto')], 'delete': [('locallist'), ('node', 'netmask', 'prototype')], 'extract': [('locallist', 'node', 'type', 'proto', 'netmask'), ('')], 'deleteall': [('locallist'), ('')]} handle_opts(args, node_args, args.action) OBJECT = object_dict['node'](args) if args.action == "add": OBJECT.add(args.node, args.netmask, args.proto, args.range, args.type) if args.action == "modify": OBJECT.modify(args.node, args.netmask, args.proto, args.range, args.type) if args.action == "delete": OBJECT.delete(args.node, args.netmask, args.proto) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("node %s" % str(i)) def setupNodeParser(subparsers): generated_usage = generate_custom_usage(usage_node, usage_node_dict) nodeParser = subparsers.add_parser('node', usage=generated_usage, help=_('Manage network node type definitions')) parser_add_locallist(nodeParser, "node") parser_add_noheading(nodeParser, "node") parser_add_noreload(nodeParser, "node") parser_add_store(nodeParser, "node") node_action = nodeParser.add_mutually_exclusive_group(required=True) parser_add_add(node_action, "node") parser_add_delete(node_action, "node") parser_add_modify(node_action, "node") parser_add_list(node_action, "node") parser_add_extract(node_action, "node") parser_add_deleteall(node_action, "node") nodeParser.add_argument('-M', '--netmask', help=_('Network Mask')) parser_add_type(nodeParser, "node") parser_add_range(nodeParser, "node") parser_add_proto(nodeParser, "node") nodeParser.add_argument('node', nargs='?', default=None, help=_('node')) nodeParser.set_defaults(func=handleNode) def handleBoolean(args): boolean_args = {'list': [('state', 'boolean'), ('')], 'modify': [('localist'), ('boolean', 'state')], 'extract': [('locallist', 'state', 'boolean'), ('')], 'deleteall': [('locallist'), ('')], 'state': [('locallist', 'list', 'extract', 'deleteall'), ('modify')]} handle_opts(args, boolean_args, args.action) OBJECT = object_dict['boolean'](args) if args.action == "modify": if args.boolean: OBJECT.modify(args.boolean, args.state, False) if args.action == "list": OBJECT.list(args.noheading, args.locallist) if args.action == "deleteall": OBJECT.deleteall() if args.action == "extract": for i in OBJECT.customized(): print("boolean %s" % str(i)) def setupBooleanParser(subparsers): generated_usage = generate_custom_usage(usage_boolean, usage_boolean_dict) booleanParser = subparsers.add_parser('boolean', usage=generated_usage, help=_('Manage booleans to selectively enable functionality')) parser_add_locallist(booleanParser, "boolean") parser_add_noheading(booleanParser, "boolean") parser_add_noreload(booleanParser, "boolean") parser_add_store(booleanParser, "boolean") booleanParser.add_argument('boolean', nargs="?", default=None, help=_('boolean')) boolean_action = booleanParser.add_mutually_exclusive_group(required=True) #add_add(boolean_action) parser_add_modify(boolean_action, "boolean") parser_add_list(boolean_action, "boolean") parser_add_extract(boolean_action, "boolean") parser_add_deleteall(boolean_action, "boolean") booleanGroup = booleanParser.add_mutually_exclusive_group(required=False) booleanGroup.add_argument('-1', '--on', dest='state', action='store_const', const='on', help=_('Enable the boolean')) booleanGroup.add_argument('-0', '--off', dest='state', action='store_const', const='off', help=_('Disable the boolean')) booleanParser.set_defaults(func=handleBoolean) def handlePermissive(args): OBJECT = object_dict['permissive'](args) if args.action == "list": OBJECT.list(args.noheading) elif args.action == "deleteall": OBJECT.deleteall() elif args.action == "extract": for i in OBJECT.customized(): print("permissive %s" % str(i)) elif args.type is not None: if args.action == "add": OBJECT.add(args.type) if args.action == "delete": OBJECT.delete(args.type) else: args.parser.error(message=_('semanage permissive: error: the following argument is required: type\n')) def setupPermissiveParser(subparsers): permissiveParser = subparsers.add_parser('permissive', help=_('Manage process type enforcement mode')) pgroup = permissiveParser.add_mutually_exclusive_group(required=True) parser_add_add(pgroup, "permissive") parser_add_delete(pgroup, "permissive") parser_add_deleteall(pgroup, "permissive") parser_add_extract(pgroup, "permissive") parser_add_list(pgroup, "permissive") parser_add_noheading(permissiveParser, "permissive") parser_add_noreload(permissiveParser, "permissive") parser_add_store(permissiveParser, "permissive") permissiveParser.add_argument('type', nargs='?', default=None, help=_('type')) permissiveParser.set_defaults(func=handlePermissive) permissiveParser.set_defaults(parser=permissiveParser) def handleDontaudit(args): OBJECT = object_dict['dontaudit'](args) OBJECT.toggle(args.action) def setupDontauditParser(subparsers): dontauditParser = subparsers.add_parser('dontaudit', help=_('Disable/Enable dontaudit rules in policy')) parser_add_noreload(dontauditParser, "dontaudit") parser_add_store(dontauditParser, "dontaudit") dontauditParser.add_argument('action', choices=["on", "off"]) dontauditParser.set_defaults(func=handleDontaudit) def handleExport(args): manageditems = ["boolean", "login", "interface", "user", "port", "node", "fcontext", "module", "ibendport", "ibpkey", "permissive"] for i in manageditems: print("%s -D" % i) for i in manageditems: OBJECT = object_dict[i](args) for c in OBJECT.customized(): print("%s %s" % (i, str(c))) sys.exit(0) def setupExportParser(subparsers): exportParser = subparsers.add_parser('export', help=_('Output local customizations')) parser_add_store(exportParser, "export") exportParser.add_argument('-f', '--output_file', dest='output_file', action=SetExportFile, help=_('Output file')) exportParser.set_defaults(func=handleExport) def mkargv(line): dquote = "\"" squote = "\'" l = line.split() ret = [] i = 0 while i < len(l): cnt = len(re.findall(dquote, l[i])) if cnt > 1: ret.append(l[i].strip(dquote)) i = i + 1 continue if cnt == 1: quote = [l[i].strip(dquote)] i = i + 1 while i < len(l) and dquote not in l[i]: quote.append(l[i]) i = i + 1 quote.append(l[i].strip(dquote)) ret.append(" ".join(quote)) i = i + 1 continue cnt = len(re.findall(squote, l[i])) if cnt > 1: ret.append(l[i].strip(squote)) i = i + 1 continue if cnt == 1: quote = [l[i].strip(squote)] i = i + 1 while i < len(l) and squote not in l[i]: quote.append(l[i]) i = i + 1 quote.append(l[i].strip(squote)) ret.append(" ".join(quote)) i = i + 1 continue ret.append(l[i]) i = i + 1 return ret def handleImport(args): trans = seobject.semanageRecords(args) trans.start() deleteCommands = [] commands = [] # separate commands for deletion from the rest so they can be # applied in a separate transaction for l in sys.stdin.readlines(): if len(l.strip()) == 0: continue if "-d" in l or "-D" in l: deleteCommands.append(l) else: commands.append(l) if deleteCommands: importHelper(deleteCommands) trans.finish() trans.start() importHelper(commands) trans.finish() def importHelper(commands): for l in commands: try: commandParser = createCommandParser() args = commandParser.parse_args(mkargv(l)) args.func(args) except ValueError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, str(e))) sys.exit(1) except IOError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, str(e))) sys.exit(1) except KeyboardInterrupt: sys.exit(0) def setupImportParser(subparsers): importParser = subparsers.add_parser('import', help=_('Import local customizations')) parser_add_noreload(importParser, "import") parser_add_store(importParser, "import") importParser.add_argument('-f', '--input_file', dest='input_file', action=SetImportFile, help=_('Input file')) importParser.set_defaults(func=handleImport) def createCommandParser(): commandParser = seParser(prog='semanage', formatter_class=argparse.ArgumentDefaultsHelpFormatter, description=_( "semanage is used to configure certain elements of SELinux policy with-out requiring modification or recompilation from policy source." )) #To add a new subcommand define the parser for it in a function above and call it here. subparsers = commandParser.add_subparsers(dest='subcommand') subparsers.required = True setupImportParser(subparsers) setupExportParser(subparsers) setupLoginParser(subparsers) setupUserParser(subparsers) setupPortParser(subparsers) setupPkeyParser(subparsers) setupIbendportParser(subparsers) setupInterfaceParser(subparsers) setupModuleParser(subparsers) setupNodeParser(subparsers) setupFcontextParser(subparsers) setupBooleanParser(subparsers) setupPermissiveParser(subparsers) setupDontauditParser(subparsers) return commandParser def make_io_args(args): # import/export backward compatibility args_origin = ["-S", "-o", "-i", "targeted", "minimum", "mls"] args_file = [] args_ie = [] args_subcommand = [] for i in args: if i == "-o": args_subcommand = ["export"] continue if i == "-i": args_subcommand = ["import"] continue if i not in args_origin: args_file = ["-f", i] continue args_ie.append(i) return args_subcommand + args_ie + args_file def make_args(sys_args): args = [] if "-o" in sys_args[1:] or "-i" in sys_args[1:]: args = make_io_args(sys_args[1:]) else: args = sys_args[1:] return args def do_parser(): try: commandParser = createCommandParser() args = commandParser.parse_args(make_args(sys.argv)) args.func(args) sys.exit(0) except BrokenPipeError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, str(e))) # Python flushes standard streams on exit; redirect remaining output # to devnull to avoid another BrokenPipeError at shutdown devnull = os.open(os.devnull, os.O_WRONLY) os.dup2(devnull, sys.stdout.fileno()) sys.exit(1) except OSError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, e.args[1])) sys.exit(1) except KeyboardInterrupt: sys.exit(0) except ValueError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, e.args[0])) sys.exit(1) except KeyError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, e.args[0])) sys.exit(1) except RuntimeError as e: sys.stderr.write("%s: %s\n" % (e.__class__.__name__, e.args[0])) sys.exit(1) if __name__ == '__main__': do_parser()
Save
cmd:
run