a ԏi7@s*ddlZddlZddlZddlZddlZddlZddlZddlmZm Z ddl Z ddl Z ddl Z dde_ dZdZdZdZdadadadadadad d Zd*d d Zd dZddZddZddZddZddZddZ ddZ!d+ddZ"Gd d!d!Z#d"d#Z$d,d%d&Z%d'd(Z&e'd)kr&e&dS)-N)mkdtempmkstempcOs2|jdt|ddt|dddS)Nz:  )__name__strupper)msgcategoryZ _unused_aZ _unused_kwar ;/usr/share/crypto-policies/python/update-crypto-policies.pysr z/usr/share/crypto-policiesz/etc/crypto-policieszreload-cmds.shz/proc/sys/crypto/fips_enabledcOst|dtji|dS)Nfile)printsysstderr)argskwargsr r r eprint&srcCsztjdattj_Wnty,taYn0|dur<|an.ztjdattj_ Wntyht aYn0tj tda tj tdatj tdatj ttadS)N profile_dirbase_dirzlocal.dz back-endsstate)osenvironrcryptopoliciesUnscopedCryptoPolicyZ SHARE_DIRKeyErrorDEFAULT_PROFILE_DIRrZ CONFIG_DIRDEFAULT_BASE_DIRpathjoin local_dirbackend_config_dir state_dirRELOAD_CMD_NAMEreload_cmd_pathalt_baser r r dir_paths*s         r(cCs@t}t|td}dd|D}t|}t||S)N.css&|]\}}}|t|t|fVqdSN)sorted).0rootdirsfilesr r r Pzget_walk..)rgetcwdchdirwalkr+)rZold_cwdr4r r r get_walkIs   r5cCstjdd}|}|jdddddd|jd d d d |jd d dd |jdd dd |jdd tjd |jdd dd |S)zParse the command lineF) allow_abbrevz--set?ZPOLICYzset the policy POLICY)nargsdefaultmetavarhelpz--show store_truez.show the current policy from the configuration)actionr<z --is-appliedz+check whether the current policy is appliedz--checkzAcheck whether the generated policy files match the current policyz --no-checkz --no-reloadz3do not run the reload scripts when setting a policy)argparseArgumentParseradd_mutually_exclusive_group add_argumentSUPPRESS parse_args)parsergroupr r r rDVs*  rDcCs~z0ttjtdj}ttjtdj}WntyLt dYn0||krht dt dt dt ddS)NcurrentconfigMz The configured policy is appliedrz$The configured policy is NOT appliedr) rstatrr r#st_mtimerOSErrorrexitr)Ztime1Ztime2r r r is_appliedks  rNc Cst}t}t}t}t}t|dtj|tdtjt j |dt j tddt t }t|dddt|}tt}t|}tt} d} ||krd} || krd} |t|f} |t| f} | | fD]\} }}|D]\}}}|D]}| rqt j | ||}t j |||}t|dr}t|dF}| sX|d}|d}||krJd} |s"qXq"Wdn1sn0YWdq1s0Yqqqt|| rtd td ntd td dS) Nr&)srcdstrHF) print_enabledallow_symlinkingTrbi z9The configured policy does NOT match the generated policyrz2The configured policy matches the generated policyr)rr!r"r#rr(shutilcopytreecopyrrr setup_directories parse_pconfig apply_policyr5openreadrmtreerrrMr)Z orig_base_dirZorig_local_dirZorig_backend_config_dirZorig_state_dirr'pconfigZwalk_orig_backendZ walk_backendZwalk_orig_stateZ walk_stateerrZ_backend_stateZ orig_prefixZ tmp_prefixr4d_ZflfZf_origZf_tmpfp1fp2b1b2r r r checkysZ       N  rgcCs<z$tjtdddtjtdddWnty6Yn0dS)NiT)modeexist_ok)rmakedirsr"r#rLr r r r rWs  rWcCs\zBttdd"}t|dkWdWS1s60YWntyVYdS0dS)NasciiencodingrF)rZFIPS_MODE_FLAGintr[rL)rbr r r fips_modes 4 rpc Cst||d\}}t|t|dt|t|dzRzt|tj||Wn(t y|t |t |Yn0Wt |n t |0dS)Nprefixdirutf-8i) rrwritebytesfsyncfchmodrenamerr rLunlinkclose) directoryfilenamecontentsfdrr r r safe_writes      rcCsnt||d\}}t|t|t||zt|tj||Wntyht|Yn0dS)Nrq) rrr{rzsymlinkryrr rL)r|r}targetrrr r r safe_symlinks     rFc Cstj||d}tt|} d} | D]} tj| r(d} qBq(tj|t||d} t| tj} | s| r|rt ||d| dS| r|j s|rt | dd}| }Wdn1s0Yt ||d|| rtj||d}zt |ddd}| D]} z:t | dd}| }Wdn1s:0YWn(tyntd | YqYn0z||Wn(tytd | d |Yn0qWdn1s0YWn$tytd |d Yn0dS)Nz -*.configFTz.txtz.configrtrlazCannot read local policy file z$Error appending local configuration z to zError opening configuration z" for appending local configuration)rrr r+globexistsraccessR_OKr subpoliciesrZr[rrLrru)r]ZcfgnameZcfgdataZcfgdirZlocaldirZ profiledirpolicy_was_emptyrRZlocal_cfg_pathZ local_cfgsZlocal_cfg_presentZlcfgZ profilepathZprofilepath_existsZf_preZcfgfilecfZlfZ local_datar r r save_configsJ  &, 6rc@s>eZdZddZdddZddZdd Zd d Zd d ZdS) ProfileConfigcCsd|_g|_dS)Nr8)policyrselfr r r __init__szProfileConfig.__init__Fcs^|ddr0|s0d|_ddfddD|rT|jn|_dS)N:rrcsg|] }r|qSr r r,ilr r r1z.ProfileConfig.parse_string..)rsplitrrextend)rs subpolicyr rr parse_strings   zProfileConfig.parse_stringcCsjd}t|ddF}|D]0}|ddd}|}|r|||d}qWdn1s\0YdS)NFrtrl#rrT)rZrstripr)rr}rrbliner r r parse_file"s zProfileConfig.parse_filecs(|dfdd|jD|_dS)Nrcsg|]}|vr|qSr r rrr r r.r1z4ProfileConfig.remove_subpolicies..)rrr)rrr rr remove_subpolicies,sz ProfileConfig.remove_subpoliciescCs&|j}d|j}|r"|d|}|S)Nr)rr r)rrZsubsr r r __str__0s   zProfileConfig.__str__cCstt|dSr*)rrrr r r show7szProfileConfig.showN)F) r __module__ __qualname__rrrrrrr r r r rs   rcCsXt}tjtd}t|tjr.||n&tr@| dn|tjt d|S)NrHFIPSzdefault-config) rrrr rrrrrprr)r]Z configfiler r r rX;s  rXTc Csd}d}|r|j}||d}tjd}|j|kr|r|jdkrb|stdtdtdn&trtd td td td ttkrt dkrtd t dzt j |jg|jR}Wn|t jjy} zt| t dWYd} ~ nJd} ~ 0t jjyD} z$td| t dWYd} ~ n d} ~ 00|r\tdt|ddttD} | D]} tj| } | } z| || j}Wn.tytd| jtdd}Yn0z"t|| j|ttt| |dWn.t!ytd| jtdd}Yn0qr|rbzt"tdt|dWn t!y`tdd}Yn0zt"t#dt|dWn t!ytdd}Yn0zt"t#dt|Wn t!ytdd}Yn0|rtd td!td"|S)#NrFTz/usr/bin/bootcrzHWarning: Using 'update-crypto-policies --set FIPS' is not sufficient forz FIPS compliance.z8 Use 'fips-mode-setup --enable' command instead.zOWarning: Using 'update-crypto-policies --set' in FIPS mode will make the systemz! non-compliant with FIPS.z8 It can also break the ssh access to the system.zI Use 'fips-mode-setup --disable' to disable the system FIPS mode.z/You must be root to run update-crypto-policies.rz%Errors found in policy, first one: zSetting system policy to cSsg|]}d|vr|qS) Generatorr )r,gr r r rwr1z apply_policy..zError generating config for zKeeping original configuration)rrRzError saving config for rHrz.Error setting the current policy configurationrGz$Error updating current policy markerz CURRENT.polz"Error updating current policy dumpzFNote: System-wide crypto policies are applied on application start-up.zBIt is recommended to restart the system for the change of policieszto fully take place.)$rrrrrrrprrgeteuidrrMrrrZ validationZPolicyFileNotFoundErrorZPolicySyntaxErrorrrrspolicygenerators__dict__Zgenerate_configZscopedZSCOPES LookupErrorZ CONFIG_NAMErr"r!rZis_emptyrLrr#)r]profilerQrRr^Z set_configZ oldpolicyZbootcZcpex generatorsrclsgenrHr r r rYIs               rYcCstt}|jr"ttd|jr8ttdtt}|jr\|td|j }t ||}|j st dtgt|dS)z!The actual command implementationrz /bin/bashN)r(rDrNrrMrgrWrXrsetrYZ no_reload subprocesscallr%)Zcmdliner]rr^r r r mains$    r__main__)N)F)NTT)(r?rrrTrrwarningsZtempfilerrrZcryptopolicies.validationr formatwarningrrr$rnrrr!r"r#r%rr(r5rDrNrgrWrprrrrrXrYrrr r r r sR   : 3) a!