apol: implement common query tab

Closes #77
This commit is contained in:
Chris PeBenito 2016-04-05 15:00:05 -04:00
parent 27bc09c0e3
commit f1a8077f79
4 changed files with 779 additions and 0 deletions

513
data/commonquery.ui Normal file
View File

@ -0,0 +1,513 @@
<?xml version="1.0" encoding="UTF-8"?>
<ui version="4.0">
<class>CommonQueryTab_ui</class>
<widget class="QScrollArea" name="CommonQueryTab_ui">
<property name="geometry">
<rect>
<x>0</x>
<y>0</y>
<width>774</width>
<height>846</height>
</rect>
</property>
<property name="sizeAdjustPolicy">
<enum>QAbstractScrollArea::AdjustToContents</enum>
</property>
<property name="widgetResizable">
<bool>true</bool>
</property>
<widget class="QWidget" name="contents">
<property name="geometry">
<rect>
<x>0</x>
<y>0</y>
<width>772</width>
<height>844</height>
</rect>
</property>
<property name="minimumSize">
<size>
<width>0</width>
<height>0</height>
</size>
</property>
<layout class="QGridLayout" name="gridLayout_3">
<item row="0" column="0">
<widget class="QLabel" name="label">
<property name="sizePolicy">
<sizepolicy hsizetype="Preferred" vsizetype="Fixed">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<property name="maximumSize">
<size>
<width>16777215</width>
<height>20</height>
</size>
</property>
<property name="font">
<font>
<pointsize>11</pointsize>
<weight>75</weight>
<bold>true</bold>
</font>
</property>
<property name="text">
<string>Common Permission Sets</string>
</property>
</widget>
</item>
<item row="3" column="0" colspan="5">
<widget class="QTextEdit" name="notes">
<property name="minimumSize">
<size>
<width>0</width>
<height>80</height>
</size>
</property>
<property name="toolTip">
<string>Optionally enter notes here about the query.</string>
</property>
<property name="placeholderText">
<string>Enter notes here.</string>
</property>
</widget>
</item>
<item row="0" column="1">
<spacer name="horizontalSpacer">
<property name="orientation">
<enum>Qt::Horizontal</enum>
</property>
<property name="sizeHint" stdset="0">
<size>
<width>440</width>
<height>20</height>
</size>
</property>
</spacer>
</item>
<item row="0" column="2">
<widget class="QLabel" name="label_2">
<property name="text">
<string>Show:</string>
</property>
</widget>
</item>
<item row="0" column="3">
<widget class="QCheckBox" name="criteria_expander">
<property name="toolTip">
<string>Show or hide the search criteria (no settings are lost)</string>
</property>
<property name="text">
<string>Criteria</string>
</property>
<property name="checked">
<bool>true</bool>
</property>
</widget>
</item>
<item row="0" column="4">
<widget class="QCheckBox" name="notes_expander">
<property name="toolTip">
<string>Show or hide the notes field (no data is lost)</string>
</property>
<property name="text">
<string>Notes</string>
</property>
</widget>
</item>
<item row="1" column="0" rowspan="2" colspan="5">
<widget class="QSplitter" name="splitter">
<property name="sizePolicy">
<sizepolicy hsizetype="Expanding" vsizetype="Preferred">
<horstretch>0</horstretch>
<verstretch>1</verstretch>
</sizepolicy>
</property>
<property name="orientation">
<enum>Qt::Horizontal</enum>
</property>
<widget class="QGroupBox" name="browser_groupBox">
<property name="title">
<string>Common Browser</string>
</property>
<layout class="QGridLayout" name="gridLayout">
<item row="0" column="0">
<widget class="GetDetailsListView" name="commons"/>
</item>
</layout>
</widget>
<widget class="QWidget" name="verticalLayoutWidget">
<layout class="QVBoxLayout" name="verticalLayout">
<item>
<widget class="QGroupBox" name="criteria_frame">
<property name="sizePolicy">
<sizepolicy hsizetype="Preferred" vsizetype="Preferred">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<property name="maximumSize">
<size>
<width>16777215</width>
<height>16777215</height>
</size>
</property>
<property name="title">
<string>Search Criteria</string>
</property>
<layout class="QGridLayout" name="gridLayout_2">
<item row="1" column="0" rowspan="4" colspan="2">
<widget class="QGroupBox" name="perms_criteria">
<property name="title">
<string>Permission Set</string>
</property>
<layout class="QGridLayout" name="gridLayout_4">
<item row="0" column="0" rowspan="3">
<widget class="QListView" name="perms">
<property name="sizePolicy">
<sizepolicy hsizetype="Expanding" vsizetype="Preferred">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<property name="maximumSize">
<size>
<width>250</width>
<height>16777215</height>
</size>
</property>
<property name="toolTip">
<string>A matching common will have the selected permissions.</string>
</property>
<property name="selectionMode">
<enum>QAbstractItemView::ExtendedSelection</enum>
</property>
</widget>
</item>
<item row="0" column="1">
<widget class="QPushButton" name="clear_perms">
<property name="text">
<string>Clear</string>
</property>
</widget>
</item>
<item row="0" column="2">
<widget class="QCheckBox" name="perms_equal">
<property name="toolTip">
<string>A matching common will a permission set equal to the selected permissions.</string>
</property>
<property name="text">
<string>Equal</string>
</property>
</widget>
</item>
<item row="0" column="3">
<spacer name="horizontalSpacer_5">
<property name="orientation">
<enum>Qt::Horizontal</enum>
</property>
<property name="sizeHint" stdset="0">
<size>
<width>40</width>
<height>20</height>
</size>
</property>
</spacer>
</item>
<item row="1" column="1">
<widget class="QPushButton" name="invert_perms">
<property name="text">
<string>Invert</string>
</property>
</widget>
</item>
<item row="2" column="1">
<spacer name="verticalSpacer">
<property name="orientation">
<enum>Qt::Vertical</enum>
</property>
<property name="sizeHint" stdset="0">
<size>
<width>20</width>
<height>40</height>
</size>
</property>
</spacer>
</item>
</layout>
</widget>
</item>
<item row="5" column="1">
<widget class="QDialogButtonBox" name="buttonBox">
<property name="standardButtons">
<set>QDialogButtonBox::Apply</set>
</property>
</widget>
</item>
<item row="0" column="0" colspan="2">
<widget class="QGroupBox" name="name_criteria">
<property name="maximumSize">
<size>
<width>16777215</width>
<height>120</height>
</size>
</property>
<property name="title">
<string>Name</string>
</property>
<layout class="QGridLayout" name="gridLayout_8">
<property name="leftMargin">
<number>6</number>
</property>
<property name="topMargin">
<number>6</number>
</property>
<property name="rightMargin">
<number>6</number>
</property>
<property name="bottomMargin">
<number>6</number>
</property>
<property name="spacing">
<number>3</number>
</property>
<item row="0" column="1">
<widget class="QLineEdit" name="name">
<property name="sizePolicy">
<sizepolicy hsizetype="Expanding" vsizetype="Fixed">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<property name="minimumSize">
<size>
<width>150</width>
<height>20</height>
</size>
</property>
<property name="maximumSize">
<size>
<width>250</width>
<height>16777215</height>
</size>
</property>
</widget>
</item>
<item row="0" column="2">
<widget class="QCheckBox" name="name_regex">
<property name="toolTip">
<string>Use regular expressions to match the role's name.</string>
</property>
<property name="text">
<string>Regex</string>
</property>
</widget>
</item>
</layout>
</widget>
</item>
</layout>
</widget>
</item>
<item>
<widget class="QTabWidget" name="results_frame">
<property name="sizePolicy">
<sizepolicy hsizetype="Preferred" vsizetype="MinimumExpanding">
<horstretch>0</horstretch>
<verstretch>1</verstretch>
</sizepolicy>
</property>
<property name="currentIndex">
<number>0</number>
</property>
<widget class="QWidget" name="table_page">
<property name="sizePolicy">
<sizepolicy hsizetype="Preferred" vsizetype="MinimumExpanding">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<attribute name="title">
<string>Results</string>
</attribute>
<layout class="QVBoxLayout" name="verticalLayout_3">
<property name="leftMargin">
<number>6</number>
</property>
<property name="topMargin">
<number>6</number>
</property>
<property name="rightMargin">
<number>6</number>
</property>
<property name="bottomMargin">
<number>6</number>
</property>
<item>
<widget class="QTableView" name="table_results">
<property name="sizePolicy">
<sizepolicy hsizetype="Expanding" vsizetype="MinimumExpanding">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<property name="sizeAdjustPolicy">
<enum>QAbstractScrollArea::AdjustIgnored</enum>
</property>
<property name="alternatingRowColors">
<bool>true</bool>
</property>
<property name="sortingEnabled">
<bool>true</bool>
</property>
</widget>
</item>
</layout>
</widget>
<widget class="QWidget" name="raw_page">
<property name="sizePolicy">
<sizepolicy hsizetype="Preferred" vsizetype="MinimumExpanding">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<attribute name="title">
<string>Raw Results</string>
</attribute>
<layout class="QVBoxLayout" name="verticalLayout_2">
<property name="leftMargin">
<number>6</number>
</property>
<property name="topMargin">
<number>6</number>
</property>
<property name="rightMargin">
<number>6</number>
</property>
<property name="bottomMargin">
<number>6</number>
</property>
<item>
<widget class="QPlainTextEdit" name="raw_results">
<property name="sizePolicy">
<sizepolicy hsizetype="Expanding" vsizetype="MinimumExpanding">
<horstretch>0</horstretch>
<verstretch>0</verstretch>
</sizepolicy>
</property>
<property name="minimumSize">
<size>
<width>0</width>
<height>0</height>
</size>
</property>
<property name="font">
<font>
<family>Monospace</family>
</font>
</property>
<property name="documentTitle">
<string/>
</property>
<property name="lineWrapMode">
<enum>QPlainTextEdit::NoWrap</enum>
</property>
<property name="readOnly">
<bool>true</bool>
</property>
</widget>
</item>
</layout>
</widget>
</widget>
</item>
</layout>
</widget>
</widget>
</item>
</layout>
<zorder>splitter</zorder>
<zorder>notes</zorder>
<zorder>label</zorder>
<zorder>label_2</zorder>
<zorder>horizontalSpacer</zorder>
<zorder>criteria_expander</zorder>
<zorder>notes_expander</zorder>
</widget>
</widget>
<customwidgets>
<customwidget>
<class>GetDetailsListView</class>
<extends>QListView</extends>
<header>setoolsgui/getdetailslist.h</header>
</customwidget>
</customwidgets>
<tabstops>
<tabstop>criteria_expander</tabstop>
<tabstop>notes_expander</tabstop>
<tabstop>commons</tabstop>
<tabstop>name</tabstop>
<tabstop>name_regex</tabstop>
<tabstop>perms</tabstop>
<tabstop>clear_perms</tabstop>
<tabstop>invert_perms</tabstop>
<tabstop>perms_equal</tabstop>
<tabstop>results_frame</tabstop>
<tabstop>table_results</tabstop>
<tabstop>raw_results</tabstop>
<tabstop>notes</tabstop>
</tabstops>
<resources/>
<connections>
<connection>
<sender>notes_expander</sender>
<signal>toggled(bool)</signal>
<receiver>notes</receiver>
<slot>setVisible(bool)</slot>
<hints>
<hint type="sourcelabel">
<x>732</x>
<y>20</y>
</hint>
<hint type="destinationlabel">
<x>386</x>
<y>754</y>
</hint>
</hints>
</connection>
<connection>
<sender>criteria_expander</sender>
<signal>toggled(bool)</signal>
<receiver>criteria_frame</receiver>
<slot>setVisible(bool)</slot>
<hints>
<hint type="sourcelabel">
<x>583</x>
<y>20</y>
</hint>
<hint type="destinationlabel">
<x>496</x>
<y>226</y>
</hint>
</hints>
</connection>
<connection>
<sender>clear_perms</sender>
<signal>clicked()</signal>
<receiver>perms</receiver>
<slot>clearSelection()</slot>
<hints>
<hint type="sourcelabel">
<x>592</x>
<y>216</y>
</hint>
<hint type="destinationlabel">
<x>442</x>
<y>276</y>
</hint>
</hints>
</connection>
</connections>
</ui>

View File

@ -0,0 +1,197 @@
# Copyright 2016, Tresys Technology, LLC
#
# This file is part of SETools.
#
# SETools is free software: you can redistribute it and/or modify
# it under the terms of the GNU Lesser General Public License as
# published by the Free Software Foundation, either version 2.1 of
# the License, or (at your option) any later version.
#
# SETools is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Lesser General Public License for more details.
#
# You should have received a copy of the GNU Lesser General Public
# License along with SETools. If not, see
# <http://www.gnu.org/licenses/>.
#
import logging
from PyQt5.QtCore import Qt, QSortFilterProxyModel, QStringListModel, QThread
from PyQt5.QtGui import QPalette, QTextCursor
from PyQt5.QtWidgets import QCompleter, QHeaderView, QMessageBox, QProgressDialog, QScrollArea
from setools import CommonQuery
from ..logtosignal import LogHandlerToSignal
from ..models import SEToolsListModel, invert_list_selection
from ..commonmodel import CommonTableModel, common_detail
from ..widget import SEToolsWidget
from .queryupdater import QueryResultsUpdater
class CommonQueryTab(SEToolsWidget, QScrollArea):
"""Common browser and query tab."""
def __init__(self, parent, policy, perm_map):
super(CommonQueryTab, self).__init__(parent)
self.log = logging.getLogger(__name__)
self.policy = policy
self.query = CommonQuery(policy)
self.setupUi()
def __del__(self):
self.thread.quit()
self.thread.wait(5000)
logging.getLogger("setools.commonquery").removeHandler(self.handler)
def setupUi(self):
self.load_ui("commonquery.ui")
# populate commons list
self.common_model = SEToolsListModel(self)
self.common_model.item_list = sorted(c for c in self.policy.commons())
self.commons.setModel(self.common_model)
# populate perm list
self.perms_model = SEToolsListModel(self)
perms = set()
for com in self.policy.commons():
perms.update(com.perms)
self.perms_model.item_list = sorted(perms)
self.perms.setModel(self.perms_model)
# set up results
self.table_results_model = CommonTableModel(self)
self.sort_proxy = QSortFilterProxyModel(self)
self.sort_proxy.setSourceModel(self.table_results_model)
self.table_results.setModel(self.sort_proxy)
self.table_results.sortByColumn(0, Qt.AscendingOrder)
# setup indications of errors
self.orig_palette = self.name.palette()
self.error_palette = self.name.palette()
self.error_palette.setColor(QPalette.Base, Qt.red)
self.clear_name_error()
# set up processing thread
self.thread = QThread()
self.worker = QueryResultsUpdater(self.query, self.table_results_model)
self.worker.moveToThread(self.thread)
self.worker.raw_line.connect(self.raw_results.appendPlainText)
self.worker.finished.connect(self.update_complete)
self.worker.finished.connect(self.thread.quit)
self.thread.started.connect(self.worker.update)
# create a "busy, please wait" dialog
self.busy = QProgressDialog(self)
self.busy.setModal(True)
self.busy.setRange(0, 0)
self.busy.setMinimumDuration(0)
self.busy.canceled.connect(self.thread.requestInterruption)
self.busy.reset()
# update busy dialog from query INFO logs
self.handler = LogHandlerToSignal()
self.handler.message.connect(self.busy.setLabelText)
logging.getLogger("setools.commonquery").addHandler(self.handler)
# Ensure settings are consistent with the initial .ui state
self.set_name_regex(self.name_regex.isChecked())
self.notes.setHidden(not self.notes_expander.isChecked())
# connect signals
self.commons.doubleClicked.connect(self.get_detail)
self.commons.get_detail.triggered.connect(self.get_detail)
self.name.textEdited.connect(self.clear_name_error)
self.name.editingFinished.connect(self.set_name)
self.name_regex.toggled.connect(self.set_name_regex)
self.perms.selectionModel().selectionChanged.connect(self.set_perms)
self.invert_perms.clicked.connect(self.invert_perms_selection)
self.buttonBox.clicked.connect(self.run)
#
# Class browser
#
def get_detail(self):
# .ui is set for single item selection.
index = self.commons.selectedIndexes()[0]
item = self.common_model.data(index, Qt.UserRole)
self.log.debug("Generating detail window for {0}".format(item))
common_detail(self, item)
#
# Name criteria
#
def clear_name_error(self):
self.name.setToolTip("Match the common name.")
self.name.setPalette(self.orig_palette)
def set_name(self):
try:
self.query.name = self.name.text()
except Exception as ex:
self.log.error("Common name error: {0}".format(ex))
self.name.setToolTip("Error: " + str(ex))
self.name.setPalette(self.error_palette)
def set_name_regex(self, state):
self.log.debug("Setting name_regex {0}".format(state))
self.query.name_regex = state
self.clear_name_error()
self.set_name()
#
# Permissions criteria
#
def set_perms(self):
selected_perms = []
for index in self.perms.selectionModel().selectedIndexes():
selected_perms.append(self.perms_model.data(index, Qt.UserRole))
self.query.perms = selected_perms
def invert_perms_selection(self):
invert_list_selection(self.perms.selectionModel())
#
# Results runner
#
def run(self, button):
# right now there is only one button.
self.query.perms_equal = self.perms_equal.isChecked()
# start processing
self.busy.setLabelText("Processing query...")
self.busy.show()
self.raw_results.clear()
self.thread.start()
def update_complete(self, count):
self.log.info("{0} common(s) found.".format(count))
# update sizes/location of result displays
if not self.busy.wasCanceled():
self.busy.setLabelText("Resizing the result table's columns; GUI may be unresponsive")
self.busy.repaint()
self.table_results.resizeColumnsToContents()
# If the permissions column width is too long, pull back
# to a reasonable size
header = self.table_results.horizontalHeader()
if header.sectionSize(1) > 400:
header.resizeSection(1, 400)
if not self.busy.wasCanceled():
self.busy.setLabelText("Resizing the result table's rows; GUI may be unresponsive")
self.busy.repaint()
self.table_results.resizeRowsToContents()
if not self.busy.wasCanceled():
self.busy.setLabelText("Moving the raw result to top; GUI may be unresponsive")
self.busy.repaint()
self.raw_results.moveCursor(QTextCursor.Start)
self.busy.reset()

View File

@ -28,6 +28,7 @@ from ..widget import SEToolsWidget
from ..logtosignal import LogHandlerToSignal
# Analysis tabs:
from .boolquery import BoolQueryTab
from .commonquery import CommonQueryTab
from .constraintquery import ConstraintQueryTab
from .dta import DomainTransitionAnalysisTab
from .fsusequery import FSUseQueryTab
@ -279,6 +280,7 @@ class ChooseAnalysis(SEToolsWidget, QDialog):
_analysis_map = {"Domain Transition Analysis": DomainTransitionAnalysisTab,
"Information Flow Analysis": InfoFlowAnalysisTab}
_components_map = {"Booleans": BoolQueryTab,
"Commons": CommonQueryTab,
"Roles": RoleQueryTab,
"Object Classes": ObjClassQueryTab,
"Types": TypeQueryTab,

67
setoolsgui/commonmodel.py Normal file
View File

@ -0,0 +1,67 @@
# Copyright 2016, Tresys Technology, LLC
#
# This file is part of SETools.
#
# SETools is free software: you can redistribute it and/or modify
# it under the terms of the GNU Lesser General Public License as
# published by the Free Software Foundation, either version 2.1 of
# the License, or (at your option) any later version.
#
# SETools is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Lesser General Public License for more details.
#
# You should have received a copy of the GNU Lesser General Public
# License along with SETools. If not, see
# <http://www.gnu.org/licenses/>.
#
from collections import defaultdict
from PyQt5.QtCore import Qt
from PyQt5.QtGui import QPalette, QTextCursor
from setools.policyrep.exception import NoCommon
from .details import DetailsPopup
from .models import SEToolsTableModel
def common_detail(parent, common):
"""
Create a dialog box for common perm set details.
Parameters:
parent The parent Qt Widget
class_ The type
"""
detail = DetailsPopup(parent, "Common detail: {0}".format(common))
detail.append_header("Permissions ({0}):".format(len(common.perms)))
for p in sorted(common.perms):
detail.append(" {0}".format(p))
detail.show()
class CommonTableModel(SEToolsTableModel):
"""Table-based model for common permission sets."""
headers = defaultdict(str, {0: "Name", 1: "Permissions"})
def data(self, index, role):
if self.resultlist:
row = index.row()
col = index.column()
item = self.resultlist[row]
if role == Qt.DisplayRole:
if col == 0:
return str(item)
elif col == 1:
return ", ".join(sorted(str(p) for p in item.perms))
elif role == Qt.UserRole:
return item