]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/udev/udev-rules.c
Merge pull request #13265 from keszybz/timedated-ntp-logging
[thirdparty/systemd.git] / src / udev / udev-rules.c
1 /* SPDX-License-Identifier: GPL-2.0+ */
2
3 #include <ctype.h>
4
5 #include "alloc-util.h"
6 #include "conf-files.h"
7 #include "def.h"
8 #include "device-util.h"
9 #include "dirent-util.h"
10 #include "escape.h"
11 #include "fd-util.h"
12 #include "fileio.h"
13 #include "format-util.h"
14 #include "fs-util.h"
15 #include "glob-util.h"
16 #include "libudev-util.h"
17 #include "list.h"
18 #include "mkdir.h"
19 #include "nulstr-util.h"
20 #include "parse-util.h"
21 #include "path-util.h"
22 #include "proc-cmdline.h"
23 #include "stat-util.h"
24 #include "strv.h"
25 #include "strxcpyx.h"
26 #include "sysctl-util.h"
27 #include "udev-builtin.h"
28 #include "udev-event.h"
29 #include "udev-rules.h"
30 #include "user-util.h"
31
32 #define RULES_DIRS (const char* const*) CONF_PATHS_STRV("udev/rules.d")
33
34 typedef enum {
35 OP_MATCH, /* == */
36 OP_NOMATCH, /* != */
37 OP_ADD, /* += */
38 OP_REMOVE, /* -= */
39 OP_ASSIGN, /* = */
40 OP_ASSIGN_FINAL, /* := */
41 _OP_TYPE_MAX,
42 _OP_TYPE_INVALID = -1
43 } UdevRuleOperatorType;
44
45 typedef enum {
46 MATCH_TYPE_EMPTY, /* empty string */
47 MATCH_TYPE_PLAIN, /* no special characters */
48 MATCH_TYPE_GLOB, /* shell globs ?,*,[] */
49 MATCH_TYPE_SUBSYSTEM, /* "subsystem", "bus", or "class" */
50 _MATCH_TYPE_MAX,
51 _MATCH_TYPE_INVALID = -1
52 } UdevRuleMatchType;
53
54 typedef enum {
55 SUBST_TYPE_PLAIN, /* no substitution */
56 SUBST_TYPE_FORMAT, /* % or $ */
57 SUBST_TYPE_SUBSYS, /* "[<SUBSYSTEM>/<KERNEL>]<attribute>" format */
58 _SUBST_TYPE_MAX,
59 _SUBST_TYPE_INVALID = -1
60 } UdevRuleSubstituteType;
61
62 typedef enum {
63 /* lvalues which take match or nomatch operator */
64 TK_M_ACTION, /* string, device_get_action() */
65 TK_M_DEVPATH, /* path, sd_device_get_devpath() */
66 TK_M_KERNEL, /* string, sd_device_get_sysname() */
67 TK_M_DEVLINK, /* strv, sd_device_get_devlink_first(), sd_device_get_devlink_next() */
68 TK_M_NAME, /* string, name of network interface */
69 TK_M_ENV, /* string, device property, takes key through attribute */
70 TK_M_TAG, /* strv, sd_device_get_tag_first(), sd_device_get_tag_next() */
71 TK_M_SUBSYSTEM, /* string, sd_device_get_subsystem() */
72 TK_M_DRIVER, /* string, sd_device_get_driver() */
73 TK_M_ATTR, /* string, takes filename through attribute, sd_device_get_sysattr_value(), util_resolve_subsys_kernel(), etc. */
74 TK_M_SYSCTL, /* string, takes kernel parameter through attribute */
75
76 /* matches parent paramters */
77 TK_M_PARENTS_KERNEL, /* string */
78 TK_M_PARENTS_SUBSYSTEM, /* string */
79 TK_M_PARENTS_DRIVER, /* string */
80 TK_M_PARENTS_ATTR, /* string */
81 TK_M_PARENTS_TAG, /* strv */
82
83 TK_M_TEST, /* path, optionally mode_t can be specified by attribute, test the existence of a file */
84 TK_M_PROGRAM, /* string, execute a program */
85 TK_M_IMPORT_FILE, /* path */
86 TK_M_IMPORT_PROGRAM, /* string, import properties from the result of program */
87 TK_M_IMPORT_BUILTIN, /* string, import properties from the result of built-in command */
88 TK_M_IMPORT_DB, /* string, import properties from database */
89 TK_M_IMPORT_CMDLINE, /* string, kernel command line */
90 TK_M_IMPORT_PARENT, /* string, parent property */
91 TK_M_RESULT, /* string, result of TK_M_PROGRAM */
92
93 #define _TK_M_MAX (TK_M_RESULT + 1)
94 #define _TK_A_MIN _TK_M_MAX
95
96 /* lvalues which take one of assign operators */
97 TK_A_OPTIONS_STRING_ESCAPE_NONE, /* no argument */
98 TK_A_OPTIONS_STRING_ESCAPE_REPLACE, /* no argument */
99 TK_A_OPTIONS_DB_PERSIST, /* no argument */
100 TK_A_OPTIONS_INOTIFY_WATCH, /* boolean */
101 TK_A_OPTIONS_DEVLINK_PRIORITY, /* int */
102 TK_A_OWNER, /* user name */
103 TK_A_GROUP, /* group name */
104 TK_A_MODE, /* mode string */
105 TK_A_OWNER_ID, /* uid_t */
106 TK_A_GROUP_ID, /* gid_t */
107 TK_A_MODE_ID, /* mode_t */
108 TK_A_TAG, /* string */
109 TK_A_OPTIONS_STATIC_NODE, /* device path, /dev/... */
110 TK_A_SECLABEL, /* string with attribute */
111 TK_A_ENV, /* string with attribute */
112 TK_A_NAME, /* ifname */
113 TK_A_DEVLINK, /* string */
114 TK_A_ATTR, /* string with attribute */
115 TK_A_SYSCTL, /* string with attribute */
116 TK_A_RUN_BUILTIN, /* string */
117 TK_A_RUN_PROGRAM, /* string */
118
119 _TK_TYPE_MAX,
120 _TK_TYPE_INVALID = -1,
121 } UdevRuleTokenType;
122
123 typedef enum {
124 LINE_HAS_NAME = 1 << 0, /* has NAME= */
125 LINE_HAS_DEVLINK = 1 << 1, /* has SYMLINK=, OWNER=, GROUP= or MODE= */
126 LINE_HAS_STATIC_NODE = 1 << 2, /* has OPTIONS=static_node */
127 LINE_HAS_GOTO = 1 << 3, /* has GOTO= */
128 LINE_HAS_LABEL = 1 << 4, /* has LABEL= */
129 LINE_UPDATE_SOMETHING = 1 << 5, /* has other TK_A_* or TK_M_IMPORT tokens */
130 } UdevRuleLineType;
131
132 typedef struct UdevRuleFile UdevRuleFile;
133 typedef struct UdevRuleLine UdevRuleLine;
134 typedef struct UdevRuleToken UdevRuleToken;
135
136 struct UdevRuleToken {
137 UdevRuleTokenType type:8;
138 UdevRuleOperatorType op:8;
139 UdevRuleMatchType match_type:8;
140 UdevRuleSubstituteType attr_subst_type:7;
141 bool attr_match_remove_trailing_whitespace:1;
142 const char *value;
143 void *data;
144 LIST_FIELDS(UdevRuleToken, tokens);
145 };
146
147 struct UdevRuleLine {
148 char *line;
149 unsigned line_number;
150 UdevRuleLineType type;
151
152 const char *label;
153 const char *goto_label;
154 UdevRuleLine *goto_line;
155
156 UdevRuleFile *rule_file;
157 UdevRuleToken *current_token;
158 LIST_HEAD(UdevRuleToken, tokens);
159 LIST_FIELDS(UdevRuleLine, rule_lines);
160 };
161
162 struct UdevRuleFile {
163 char *filename;
164 UdevRuleLine *current_line;
165 LIST_HEAD(UdevRuleLine, rule_lines);
166 LIST_FIELDS(UdevRuleFile, rule_files);
167 };
168
169 struct UdevRules {
170 usec_t dirs_ts_usec;
171 ResolveNameTiming resolve_name_timing;
172 Hashmap *known_users;
173 Hashmap *known_groups;
174 UdevRuleFile *current_file;
175 LIST_HEAD(UdevRuleFile, rule_files);
176 };
177
178 /*** Logging helpers ***/
179
180 #define log_rule_full(device, rules, level, error, fmt, ...) \
181 ({ \
182 UdevRules *_r = (rules); \
183 UdevRuleFile *_f = _r ? _r->current_file : NULL; \
184 UdevRuleLine *_l = _f ? _f->current_line : NULL; \
185 const char *_n = _f ? _f->filename : NULL; \
186 \
187 log_device_full(device, level, error, "%s:%u " fmt, \
188 strna(_n), _l ? _l->line_number : 0, \
189 ##__VA_ARGS__); \
190 })
191
192 #define log_rule_debug(device, rules, ...) log_rule_full(device, rules, LOG_DEBUG, 0, ##__VA_ARGS__)
193 #define log_rule_info(device, rules, ...) log_rule_full(device, rules, LOG_INFO, 0, ##__VA_ARGS__)
194 #define log_rule_notice(device, rules, ...) log_rule_full(device, rules, LOG_NOTICE, 0, ##__VA_ARGS__)
195 #define log_rule_warning(device, rules, ...) log_rule_full(device, rules, LOG_WARNING, 0, ##__VA_ARGS__)
196 #define log_rule_error(device, rules, ...) log_rule_full(device, rules, LOG_ERR, 0, ##__VA_ARGS__)
197
198 #define log_rule_debug_errno(device, rules, error, ...) log_rule_full(device, rules, LOG_DEBUG, error, ##__VA_ARGS__)
199 #define log_rule_info_errno(device, rules, error, ...) log_rule_full(device, rules, LOG_INFO, error, ##__VA_ARGS__)
200 #define log_rule_notice_errno(device, rules, error, ...) log_rule_full(device, rules, LOG_NOTICE, error, ##__VA_ARGS__)
201 #define log_rule_warning_errno(device, rules, error, ...) log_rule_full(device, rules, LOG_WARNING, error, ##__VA_ARGS__)
202 #define log_rule_error_errno(device, rules, error, ...) log_rule_full(device, rules, LOG_ERR, error, ##__VA_ARGS__)
203
204 #define log_token_full(rules, ...) log_rule_full(NULL, rules, ##__VA_ARGS__)
205
206 #define log_token_debug(rules, ...) log_token_full(rules, LOG_DEBUG, 0, ##__VA_ARGS__)
207 #define log_token_info(rules, ...) log_token_full(rules, LOG_INFO, 0, ##__VA_ARGS__)
208 #define log_token_notice(rules, ...) log_token_full(rules, LOG_NOTICE, 0, ##__VA_ARGS__)
209 #define log_token_warning(rules, ...) log_token_full(rules, LOG_WARNING, 0, ##__VA_ARGS__)
210 #define log_token_error(rules, ...) log_token_full(rules, LOG_ERR, 0, ##__VA_ARGS__)
211
212 #define log_token_debug_errno(rules, error, ...) log_token_full(rules, LOG_DEBUG, error, ##__VA_ARGS__)
213 #define log_token_info_errno(rules, error, ...) log_token_full(rules, LOG_INFO, error, ##__VA_ARGS__)
214 #define log_token_notice_errno(rules, error, ...) log_token_full(rules, LOG_NOTICE, error, ##__VA_ARGS__)
215 #define log_token_warning_errno(rules, error, ...) log_token_full(rules, LOG_WARNING, error, ##__VA_ARGS__)
216 #define log_token_error_errno(rules, error, ...) log_token_full(rules, LOG_ERR, error, ##__VA_ARGS__)
217
218 #define _log_token_invalid(rules, key, type) \
219 log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL), \
220 "Invalid %s for %s.", type, key)
221
222 #define log_token_invalid_op(rules, key) _log_token_invalid(rules, key, "operator")
223 #define log_token_invalid_attr(rules, key) _log_token_invalid(rules, key, "attribute")
224
225 #define log_token_invalid_attr_format(rules, key, attr, offset, hint) \
226 log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL), \
227 "Invalid attribute \"%s\" for %s (char %zu: %s), ignoring, but please fix it.", \
228 attr, key, offset, hint)
229 #define log_token_invalid_value(rules, key, value, offset, hint) \
230 log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL), \
231 "Invalid value \"%s\" for %s (char %zu: %s), ignoring, but please fix it.", \
232 value, key, offset, hint)
233
234 static void log_unknown_owner(sd_device *dev, UdevRules *rules, int error, const char *entity, const char *name) {
235 if (IN_SET(abs(error), ENOENT, ESRCH))
236 log_rule_error(dev, rules, "Unknown %s '%s', ignoring", entity, name);
237 else
238 log_rule_error_errno(dev, rules, error, "Failed to resolve %s '%s', ignoring: %m", entity, name);
239 }
240
241 /*** Other functions ***/
242
243 static void udev_rule_token_free(UdevRuleToken *token) {
244 free(token);
245 }
246
247 static void udev_rule_line_clear_tokens(UdevRuleLine *rule_line) {
248 UdevRuleToken *i, *next;
249
250 assert(rule_line);
251
252 LIST_FOREACH_SAFE(tokens, i, next, rule_line->tokens)
253 udev_rule_token_free(i);
254
255 rule_line->tokens = NULL;
256 }
257
258 static void udev_rule_line_free(UdevRuleLine *rule_line) {
259 if (!rule_line)
260 return;
261
262 udev_rule_line_clear_tokens(rule_line);
263
264 if (rule_line->rule_file) {
265 if (rule_line->rule_file->current_line == rule_line)
266 rule_line->rule_file->current_line = rule_line->rule_lines_prev;
267
268 LIST_REMOVE(rule_lines, rule_line->rule_file->rule_lines, rule_line);
269 }
270
271 free(rule_line->line);
272 free(rule_line);
273 }
274
275 DEFINE_TRIVIAL_CLEANUP_FUNC(UdevRuleLine*, udev_rule_line_free);
276
277 static void udev_rule_file_free(UdevRuleFile *rule_file) {
278 UdevRuleLine *i, *next;
279
280 if (!rule_file)
281 return;
282
283 LIST_FOREACH_SAFE(rule_lines, i, next, rule_file->rule_lines)
284 udev_rule_line_free(i);
285
286 free(rule_file->filename);
287 free(rule_file);
288 }
289
290 UdevRules *udev_rules_free(UdevRules *rules) {
291 UdevRuleFile *i, *next;
292
293 if (!rules)
294 return NULL;
295
296 LIST_FOREACH_SAFE(rule_files, i, next, rules->rule_files)
297 udev_rule_file_free(i);
298
299 hashmap_free_free_key(rules->known_users);
300 hashmap_free_free_key(rules->known_groups);
301 return mfree(rules);
302 }
303
304 static int rule_resolve_user(UdevRules *rules, const char *name, uid_t *ret) {
305 _cleanup_free_ char *n = NULL;
306 uid_t uid;
307 void *val;
308 int r;
309
310 assert(rules);
311 assert(name);
312
313 val = hashmap_get(rules->known_users, name);
314 if (val) {
315 *ret = PTR_TO_UID(val);
316 return 0;
317 }
318
319 r = get_user_creds(&name, &uid, NULL, NULL, NULL, USER_CREDS_ALLOW_MISSING);
320 if (r < 0) {
321 log_unknown_owner(NULL, rules, r, "user", name);
322 *ret = UID_INVALID;
323 return 0;
324 }
325
326 n = strdup(name);
327 if (!n)
328 return -ENOMEM;
329
330 r = hashmap_ensure_allocated(&rules->known_users, &string_hash_ops);
331 if (r < 0)
332 return r;
333
334 r = hashmap_put(rules->known_users, n, UID_TO_PTR(uid));
335 if (r < 0)
336 return r;
337
338 TAKE_PTR(n);
339 *ret = uid;
340 return 0;
341 }
342
343 static int rule_resolve_group(UdevRules *rules, const char *name, gid_t *ret) {
344 _cleanup_free_ char *n = NULL;
345 gid_t gid;
346 void *val;
347 int r;
348
349 assert(rules);
350 assert(name);
351
352 val = hashmap_get(rules->known_groups, name);
353 if (val) {
354 *ret = PTR_TO_GID(val);
355 return 0;
356 }
357
358 r = get_group_creds(&name, &gid, USER_CREDS_ALLOW_MISSING);
359 if (r < 0) {
360 log_unknown_owner(NULL, rules, r, "group", name);
361 *ret = GID_INVALID;
362 return 0;
363 }
364
365 n = strdup(name);
366 if (!n)
367 return -ENOMEM;
368
369 r = hashmap_ensure_allocated(&rules->known_groups, &string_hash_ops);
370 if (r < 0)
371 return r;
372
373 r = hashmap_put(rules->known_groups, n, GID_TO_PTR(gid));
374 if (r < 0)
375 return r;
376
377 TAKE_PTR(n);
378 *ret = gid;
379 return 0;
380 }
381
382 static UdevRuleSubstituteType rule_get_substitution_type(const char *str) {
383 assert(str);
384
385 if (str[0] == '[')
386 return SUBST_TYPE_SUBSYS;
387 if (strchr(str, '%') || strchr(str, '$'))
388 return SUBST_TYPE_FORMAT;
389 return SUBST_TYPE_PLAIN;
390 }
391
392 static void rule_line_append_token(UdevRuleLine *rule_line, UdevRuleToken *token) {
393 assert(rule_line);
394 assert(token);
395
396 if (rule_line->current_token)
397 LIST_APPEND(tokens, rule_line->current_token, token);
398 else
399 LIST_APPEND(tokens, rule_line->tokens, token);
400
401 rule_line->current_token = token;
402 }
403
404 static int rule_line_add_token(UdevRuleLine *rule_line, UdevRuleTokenType type, UdevRuleOperatorType op, char *value, void *data) {
405 UdevRuleToken *token;
406 UdevRuleMatchType match_type = _MATCH_TYPE_INVALID;
407 UdevRuleSubstituteType subst_type = _SUBST_TYPE_INVALID;
408 bool remove_trailing_whitespace = false;
409 size_t len;
410
411 assert(rule_line);
412 assert(type >= 0 && type < _TK_TYPE_MAX);
413 assert(op >= 0 && op < _OP_TYPE_MAX);
414
415 if (type < _TK_M_MAX) {
416 assert(value);
417 assert(IN_SET(op, OP_MATCH, OP_NOMATCH));
418
419 if (type == TK_M_SUBSYSTEM && STR_IN_SET(value, "subsystem", "bus", "class"))
420 match_type = MATCH_TYPE_SUBSYSTEM;
421 else if (isempty(value))
422 match_type = MATCH_TYPE_EMPTY;
423 else if (streq(value, "?*")) {
424 /* Convert KEY=="?*" -> KEY!="" */
425 match_type = MATCH_TYPE_EMPTY;
426 op = op == OP_MATCH ? OP_NOMATCH : OP_MATCH;
427 } else if (string_is_glob(value))
428 match_type = MATCH_TYPE_GLOB;
429 else
430 match_type = MATCH_TYPE_PLAIN;
431
432 if (type < TK_M_TEST || type == TK_M_RESULT) {
433 /* Convert value string to nulstr. */
434 len = strlen(value);
435 if (len > 1 && (value[len - 1] == '|' || strstr(value, "||"))) {
436 /* In this case, just replacing '|' -> '\0' does not work... */
437 _cleanup_free_ char *tmp = NULL;
438 char *i, *j;
439 bool v = true;
440
441 tmp = strdup(value);
442 if (!tmp)
443 return log_oom();
444
445 for (i = tmp, j = value; *i != '\0'; i++)
446 if (*i == '|')
447 v = true;
448 else {
449 if (v) {
450 *j++ = '\0';
451 v = false;
452 }
453 *j++ = *i;
454 }
455 j[0] = j[1] = '\0';
456 } else {
457 /* Simple conversion. */
458 char *i;
459
460 for (i = value; *i != '\0'; i++)
461 if (*i == '|')
462 *i = '\0';
463 }
464 }
465 }
466
467 if (IN_SET(type, TK_M_ATTR, TK_M_PARENTS_ATTR)) {
468 assert(value);
469 assert(data);
470
471 len = strlen(value);
472 if (len > 0 && !isspace(value[len - 1]))
473 remove_trailing_whitespace = true;
474
475 subst_type = rule_get_substitution_type((const char*) data);
476 }
477
478 token = new(UdevRuleToken, 1);
479 if (!token)
480 return -ENOMEM;
481
482 *token = (UdevRuleToken) {
483 .type = type,
484 .op = op,
485 .value = value,
486 .data = data,
487 .match_type = match_type,
488 .attr_subst_type = subst_type,
489 .attr_match_remove_trailing_whitespace = remove_trailing_whitespace,
490 };
491
492 rule_line_append_token(rule_line, token);
493
494 if (token->type == TK_A_NAME)
495 SET_FLAG(rule_line->type, LINE_HAS_NAME, true);
496
497 else if (IN_SET(token->type, TK_A_DEVLINK,
498 TK_A_OWNER, TK_A_GROUP, TK_A_MODE,
499 TK_A_OWNER_ID, TK_A_GROUP_ID, TK_A_MODE_ID))
500 SET_FLAG(rule_line->type, LINE_HAS_DEVLINK, true);
501
502 else if (token->type >= _TK_A_MIN ||
503 IN_SET(token->type, TK_M_PROGRAM,
504 TK_M_IMPORT_FILE, TK_M_IMPORT_PROGRAM, TK_M_IMPORT_BUILTIN,
505 TK_M_IMPORT_DB, TK_M_IMPORT_CMDLINE, TK_M_IMPORT_PARENT))
506 SET_FLAG(rule_line->type, LINE_UPDATE_SOMETHING, true);
507
508 return 0;
509 }
510
511 static void check_value_format_and_warn(UdevRules *rules, const char *key, const char *value, bool nonempty) {
512 size_t offset;
513 const char *hint;
514
515 if (nonempty && isempty(value))
516 log_token_invalid_value(rules, key, value, (size_t) 0, "empty value");
517 else if (udev_check_format(value, &offset, &hint) < 0)
518 log_token_invalid_value(rules, key, value, offset + 1, hint);
519 }
520
521 static int check_attr_format_and_warn(UdevRules *rules, const char *key, const char *value) {
522 size_t offset;
523 const char *hint;
524
525 if (isempty(value))
526 return log_token_invalid_attr(rules, key);
527 if (udev_check_format(value, &offset, &hint) < 0)
528 log_token_invalid_attr_format(rules, key, value, offset + 1, hint);
529 return 0;
530 }
531
532 static int parse_token(UdevRules *rules, const char *key, char *attr, UdevRuleOperatorType op, char *value) {
533 bool is_match = IN_SET(op, OP_MATCH, OP_NOMATCH);
534 UdevRuleLine *rule_line;
535 int r;
536
537 assert(rules);
538 assert(rules->current_file);
539 assert(rules->current_file->current_line);
540 assert(key);
541 assert(value);
542
543 rule_line = rules->current_file->current_line;
544
545 if (streq(key, "ACTION")) {
546 if (attr)
547 return log_token_invalid_attr(rules, key);
548 if (!is_match)
549 return log_token_invalid_op(rules, key);
550
551 r = rule_line_add_token(rule_line, TK_M_ACTION, op, value, NULL);
552 } else if (streq(key, "DEVPATH")) {
553 if (attr)
554 return log_token_invalid_attr(rules, key);
555 if (!is_match)
556 return log_token_invalid_op(rules, key);
557
558 r = rule_line_add_token(rule_line, TK_M_DEVPATH, op, value, NULL);
559 } else if (streq(key, "KERNEL")) {
560 if (attr)
561 return log_token_invalid_attr(rules, key);
562 if (!is_match)
563 return log_token_invalid_op(rules, key);
564
565 r = rule_line_add_token(rule_line, TK_M_KERNEL, op, value, NULL);
566 } else if (streq(key, "SYMLINK")) {
567 if (attr)
568 return log_token_invalid_attr(rules, key);
569 if (op == OP_REMOVE)
570 return log_token_invalid_op(rules, key);
571
572 if (!is_match) {
573 check_value_format_and_warn(rules, key, value, false);
574 r = rule_line_add_token(rule_line, TK_A_DEVLINK, op, value, NULL);
575 } else
576 r = rule_line_add_token(rule_line, TK_M_DEVLINK, op, value, NULL);
577 } else if (streq(key, "NAME")) {
578 if (attr)
579 return log_token_invalid_attr(rules, key);
580 if (op == OP_REMOVE)
581 return log_token_invalid_op(rules, key);
582 if (op == OP_ADD) {
583 log_token_warning(rules, "%s key takes '==', '!=', '=', or ':=' operator, assuming '=', but please fix it.", key);
584 op = OP_ASSIGN;
585 }
586
587 if (!is_match) {
588 if (streq(value, "%k"))
589 return log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL),
590 "Ignoring NAME=\"%%k\" is ignored, as it breaks kernel supplied names.");
591 if (isempty(value))
592 return log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL),
593 "Ignoring NAME=\"\", as udev will not delete any device nodes.");
594 check_value_format_and_warn(rules, key, value, false);
595
596 r = rule_line_add_token(rule_line, TK_A_NAME, op, value, NULL);
597 } else
598 r = rule_line_add_token(rule_line, TK_M_NAME, op, value, NULL);
599 } else if (streq(key, "ENV")) {
600 if (isempty(attr))
601 return log_token_invalid_attr(rules, key);
602 if (op == OP_REMOVE)
603 return log_token_invalid_op(rules, key);
604 if (op == OP_ASSIGN_FINAL) {
605 log_token_warning(rules, "%s key takes '==', '!=', '=', or '+=' operator, assuming '=', but please fix it.", key);
606 op = OP_ASSIGN;
607 }
608
609 if (!is_match) {
610 if (STR_IN_SET(attr,
611 "ACTION", "DEVLINKS", "DEVNAME", "DEVPATH", "DEVTYPE", "DRIVER",
612 "IFINDEX", "MAJOR", "MINOR", "SEQNUM", "SUBSYSTEM", "TAGS"))
613 return log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL),
614 "Invalid ENV attribute. '%s' cannot be set.", attr);
615
616 check_value_format_and_warn(rules, key, value, false);
617
618 r = rule_line_add_token(rule_line, TK_A_ENV, op, value, attr);
619 } else
620 r = rule_line_add_token(rule_line, TK_M_ENV, op, value, attr);
621 } else if (streq(key, "TAG")) {
622 if (attr)
623 return log_token_invalid_attr(rules, key);
624 if (op == OP_ASSIGN_FINAL) {
625 log_token_warning(rules, "%s key takes '==', '!=', '=', or '+=' operator, assuming '=', but please fix it.", key);
626 op = OP_ASSIGN;
627 }
628
629 if (!is_match) {
630 check_value_format_and_warn(rules, key, value, true);
631
632 r = rule_line_add_token(rule_line, TK_A_TAG, op, value, NULL);
633 } else
634 r = rule_line_add_token(rule_line, TK_M_TAG, op, value, NULL);
635 } else if (streq(key, "SUBSYSTEM")) {
636 if (attr)
637 return log_token_invalid_attr(rules, key);
638 if (!is_match)
639 return log_token_invalid_op(rules, key);
640
641 if (STR_IN_SET(value, "bus", "class"))
642 log_token_warning(rules, "'%s' must be specified as 'subsystem'; please fix it", value);
643
644 r = rule_line_add_token(rule_line, TK_M_SUBSYSTEM, op, value, NULL);
645 } else if (streq(key, "DRIVER")) {
646 if (attr)
647 return log_token_invalid_attr(rules, key);
648 if (!is_match)
649 return log_token_invalid_op(rules, key);
650
651 r = rule_line_add_token(rule_line, TK_M_DRIVER, op, value, NULL);
652 } else if (streq(key, "ATTR")) {
653 r = check_attr_format_and_warn(rules, key, attr);
654 if (r < 0)
655 return r;
656 if (op == OP_REMOVE)
657 return log_token_invalid_op(rules, key);
658 if (IN_SET(op, OP_ADD, OP_ASSIGN_FINAL)) {
659 log_token_warning(rules, "%s key takes '==', '!=', or '=' operator, assuming '=', but please fix it.", key);
660 op = OP_ASSIGN;
661 }
662
663 if (!is_match) {
664 check_value_format_and_warn(rules, key, value, false);
665 r = rule_line_add_token(rule_line, TK_A_ATTR, op, value, attr);
666 } else
667 r = rule_line_add_token(rule_line, TK_M_ATTR, op, value, attr);
668 } else if (streq(key, "SYSCTL")) {
669 r = check_attr_format_and_warn(rules, key, attr);
670 if (r < 0)
671 return r;
672 if (op == OP_REMOVE)
673 return log_token_invalid_op(rules, key);
674 if (IN_SET(op, OP_ADD, OP_ASSIGN_FINAL)) {
675 log_token_warning(rules, "%s key takes '==', '!=', or '=' operator, assuming '=', but please fix it.", key);
676 op = OP_ASSIGN;
677 }
678
679 if (!is_match) {
680 check_value_format_and_warn(rules, key, value, false);
681 r = rule_line_add_token(rule_line, TK_A_SYSCTL, op, value, attr);
682 } else
683 r = rule_line_add_token(rule_line, TK_M_SYSCTL, op, value, attr);
684 } else if (streq(key, "KERNELS")) {
685 if (attr)
686 return log_token_invalid_attr(rules, key);
687 if (!is_match)
688 return log_token_invalid_op(rules, key);
689
690 r = rule_line_add_token(rule_line, TK_M_PARENTS_KERNEL, op, value, NULL);
691 } else if (streq(key, "SUBSYSTEMS")) {
692 if (attr)
693 return log_token_invalid_attr(rules, key);
694 if (!is_match)
695 return log_token_invalid_op(rules, key);
696
697 r = rule_line_add_token(rule_line, TK_M_PARENTS_SUBSYSTEM, op, value, NULL);
698 } else if (streq(key, "DRIVERS")) {
699 if (attr)
700 return log_token_invalid_attr(rules, key);
701 if (!is_match)
702 return log_token_invalid_op(rules, key);
703
704 r = rule_line_add_token(rule_line, TK_M_PARENTS_DRIVER, op, value, NULL);
705 } else if (streq(key, "ATTRS")) {
706 r = check_attr_format_and_warn(rules, key, attr);
707 if (r < 0)
708 return r;
709 if (!is_match)
710 return log_token_invalid_op(rules, key);
711
712 if (startswith(attr, "device/"))
713 log_token_warning(rules, "'device' link may not be available in future kernels; please fix it.");
714 if (strstr(attr, "../"))
715 log_token_warning(rules, "Direct reference to parent sysfs directory, may break in future kernels; please fix it.");
716
717 r = rule_line_add_token(rule_line, TK_M_PARENTS_ATTR, op, value, attr);
718 } else if (streq(key, "TAGS")) {
719 if (attr)
720 return log_token_invalid_attr(rules, key);
721 if (!is_match)
722 return log_token_invalid_op(rules, key);
723
724 r = rule_line_add_token(rule_line, TK_M_PARENTS_TAG, op, value, NULL);
725 } else if (streq(key, "TEST")) {
726 mode_t mode = MODE_INVALID;
727
728 if (!isempty(attr)) {
729 r = parse_mode(attr, &mode);
730 if (r < 0)
731 return log_token_error_errno(rules, r, "Failed to parse mode '%s': %m", attr);
732 }
733 check_value_format_and_warn(rules, key, value, true);
734 if (!is_match)
735 return log_token_invalid_op(rules, key);
736
737 r = rule_line_add_token(rule_line, TK_M_TEST, op, value, MODE_TO_PTR(mode));
738 } else if (streq(key, "PROGRAM")) {
739 if (attr)
740 return log_token_invalid_attr(rules, key);
741 check_value_format_and_warn(rules, key, value, true);
742 if (op == OP_REMOVE)
743 return log_token_invalid_op(rules, key);
744 if (!is_match) {
745 if (op == OP_ASSIGN)
746 log_token_debug(rules, "Operator '=' is specified to %s key, assuming '=='.", key);
747 else
748 log_token_warning(rules, "%s key takes '==' or '!=' operator, assuming '==', but please fix it.", key);
749 op = OP_MATCH;
750 }
751
752 r = rule_line_add_token(rule_line, TK_M_PROGRAM, op, value, NULL);
753 } else if (streq(key, "IMPORT")) {
754 if (isempty(attr))
755 return log_token_invalid_attr(rules, key);
756 check_value_format_and_warn(rules, key, value, true);
757 if (op == OP_REMOVE)
758 return log_token_invalid_op(rules, key);
759 if (!is_match) {
760 if (op == OP_ASSIGN)
761 log_token_debug(rules, "Operator '=' is specified to %s key, assuming '=='.", key);
762 else
763 log_token_warning(rules, "%s key takes '==' or '!=' operator, assuming '==', but please fix it.", key);
764 op = OP_MATCH;
765 }
766
767 if (streq(attr, "file"))
768 r = rule_line_add_token(rule_line, TK_M_IMPORT_FILE, op, value, NULL);
769 else if (streq(attr, "program")) {
770 UdevBuiltinCommand cmd;
771
772 cmd = udev_builtin_lookup(value);
773 if (cmd >= 0) {
774 log_token_debug(rules,"Found builtin command '%s' for %s, replacing attribute", value, key);
775 r = rule_line_add_token(rule_line, TK_M_IMPORT_BUILTIN, op, value, UDEV_BUILTIN_CMD_TO_PTR(cmd));
776 } else
777 r = rule_line_add_token(rule_line, TK_M_IMPORT_PROGRAM, op, value, NULL);
778 } else if (streq(attr, "builtin")) {
779 UdevBuiltinCommand cmd;
780
781 cmd = udev_builtin_lookup(value);
782 if (cmd < 0)
783 return log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL),
784 "Unknown builtin command: %s", value);
785 r = rule_line_add_token(rule_line, TK_M_IMPORT_BUILTIN, op, value, UDEV_BUILTIN_CMD_TO_PTR(cmd));
786 } else if (streq(attr, "db"))
787 r = rule_line_add_token(rule_line, TK_M_IMPORT_DB, op, value, NULL);
788 else if (streq(attr, "cmdline"))
789 r = rule_line_add_token(rule_line, TK_M_IMPORT_CMDLINE, op, value, NULL);
790 else if (streq(attr, "parent"))
791 r = rule_line_add_token(rule_line, TK_M_IMPORT_PARENT, op, value, NULL);
792 else
793 return log_token_invalid_attr(rules, key);
794 } else if (streq(key, "RESULT")) {
795 if (attr)
796 return log_token_invalid_attr(rules, key);
797 if (!is_match)
798 return log_token_invalid_op(rules, key);
799
800 r = rule_line_add_token(rule_line, TK_M_RESULT, op, value, NULL);
801 } else if (streq(key, "OPTIONS")) {
802 char *tmp;
803
804 if (attr)
805 return log_token_invalid_attr(rules, key);
806 if (is_match || op == OP_REMOVE)
807 return log_token_invalid_op(rules, key);
808 if (op == OP_ADD) {
809 log_token_debug(rules, "Operator '+=' is specified to %s key, assuming '='.", key);
810 op = OP_ASSIGN;
811 }
812
813 if (streq(value, "string_escape=none"))
814 r = rule_line_add_token(rule_line, TK_A_OPTIONS_STRING_ESCAPE_NONE, op, NULL, NULL);
815 else if (streq(value, "string_escape=replace"))
816 r = rule_line_add_token(rule_line, TK_A_OPTIONS_STRING_ESCAPE_REPLACE, op, NULL, NULL);
817 else if (streq(value, "db_persist"))
818 r = rule_line_add_token(rule_line, TK_A_OPTIONS_DB_PERSIST, op, NULL, NULL);
819 else if (streq(value, "watch"))
820 r = rule_line_add_token(rule_line, TK_A_OPTIONS_INOTIFY_WATCH, op, NULL, INT_TO_PTR(1));
821 else if (streq(value, "nowatch"))
822 r = rule_line_add_token(rule_line, TK_A_OPTIONS_INOTIFY_WATCH, op, NULL, INT_TO_PTR(0));
823 else if ((tmp = startswith(value, "static_node=")))
824 r = rule_line_add_token(rule_line, TK_A_OPTIONS_STATIC_NODE, op, tmp, NULL);
825 else if ((tmp = startswith(value, "link_priority="))) {
826 int prio;
827
828 r = safe_atoi(tmp, &prio);
829 if (r < 0)
830 return log_token_error_errno(rules, r, "Failed to parse link priority '%s': %m", tmp);
831 r = rule_line_add_token(rule_line, TK_A_OPTIONS_DEVLINK_PRIORITY, op, NULL, INT_TO_PTR(prio));
832 } else {
833 log_token_warning(rules, "Invalid value for OPTIONS key, ignoring: '%s'", value);
834 return 0;
835 }
836 } else if (streq(key, "OWNER")) {
837 uid_t uid;
838
839 if (attr)
840 return log_token_invalid_attr(rules, key);
841 if (is_match || op == OP_REMOVE)
842 return log_token_invalid_op(rules, key);
843 if (op == OP_ADD) {
844 log_token_warning(rules, "%s key takes '=' or ':=' operator, assuming '=', but please fix it.", key);
845 op = OP_ASSIGN;
846 }
847
848 if (parse_uid(value, &uid) >= 0)
849 r = rule_line_add_token(rule_line, TK_A_OWNER_ID, op, NULL, UID_TO_PTR(uid));
850 else if (rules->resolve_name_timing == RESOLVE_NAME_EARLY &&
851 rule_get_substitution_type(value) == SUBST_TYPE_PLAIN) {
852 r = rule_resolve_user(rules, value, &uid);
853 if (r < 0)
854 return log_token_error_errno(rules, r, "Failed to resolve user name '%s': %m", value);
855
856 r = rule_line_add_token(rule_line, TK_A_OWNER_ID, op, NULL, UID_TO_PTR(uid));
857 } else if (rules->resolve_name_timing != RESOLVE_NAME_NEVER) {
858 check_value_format_and_warn(rules, key, value, true);
859 r = rule_line_add_token(rule_line, TK_A_OWNER, op, value, NULL);
860 } else {
861 log_token_debug(rules, "Resolving user name is disabled, ignoring %s=%s", key, value);
862 return 0;
863 }
864 } else if (streq(key, "GROUP")) {
865 gid_t gid;
866
867 if (attr)
868 return log_token_invalid_attr(rules, key);
869 if (is_match || op == OP_REMOVE)
870 return log_token_invalid_op(rules, key);
871 if (op == OP_ADD) {
872 log_token_warning(rules, "%s key takes '=' or ':=' operator, assuming '=', but please fix it.", key);
873 op = OP_ASSIGN;
874 }
875
876 if (parse_gid(value, &gid) >= 0)
877 r = rule_line_add_token(rule_line, TK_A_GROUP_ID, op, NULL, GID_TO_PTR(gid));
878 else if (rules->resolve_name_timing == RESOLVE_NAME_EARLY &&
879 rule_get_substitution_type(value) == SUBST_TYPE_PLAIN) {
880 r = rule_resolve_group(rules, value, &gid);
881 if (r < 0)
882 return log_token_error_errno(rules, r, "Failed to resolve group name '%s': %m", value);
883
884 r = rule_line_add_token(rule_line, TK_A_GROUP_ID, op, NULL, GID_TO_PTR(gid));
885 } else if (rules->resolve_name_timing != RESOLVE_NAME_NEVER) {
886 check_value_format_and_warn(rules, key, value, true);
887 r = rule_line_add_token(rule_line, TK_A_GROUP, op, value, NULL);
888 } else {
889 log_token_debug(rules, "Resolving group name is disabled, ignoring %s=%s", key, value);
890 return 0;
891 }
892 } else if (streq(key, "MODE")) {
893 mode_t mode;
894
895 if (attr)
896 return log_token_invalid_attr(rules, key);
897 if (is_match || op == OP_REMOVE)
898 return log_token_invalid_op(rules, key);
899 if (op == OP_ADD) {
900 log_token_warning(rules, "%s key takes '=' or ':=' operator, assuming '=', but please fix it.", key);
901 op = OP_ASSIGN;
902 }
903
904 if (parse_mode(value, &mode) >= 0)
905 r = rule_line_add_token(rule_line, TK_A_MODE_ID, op, NULL, MODE_TO_PTR(mode));
906 else {
907 check_value_format_and_warn(rules, key, value, true);
908 r = rule_line_add_token(rule_line, TK_A_MODE, op, value, NULL);
909 }
910 } else if (streq(key, "SECLABEL")) {
911 if (isempty(attr))
912 return log_token_invalid_attr(rules, key);
913 check_value_format_and_warn(rules, key, value, true);
914 if (is_match || op == OP_REMOVE)
915 return log_token_invalid_op(rules, key);
916 if (op == OP_ASSIGN_FINAL) {
917 log_token_warning(rules, "%s key takes '=' or '+=' operator, assuming '=', but please fix it.", key);
918 op = OP_ASSIGN;
919 }
920
921 r = rule_line_add_token(rule_line, TK_A_SECLABEL, op, value, NULL);
922 } else if (streq(key, "RUN")) {
923 if (is_match || op == OP_REMOVE)
924 return log_token_invalid_op(rules, key);
925 check_value_format_and_warn(rules, key, value, true);
926 if (!attr || streq(attr, "program"))
927 r = rule_line_add_token(rule_line, TK_A_RUN_PROGRAM, op, value, NULL);
928 else if (streq(attr, "builtin")) {
929 UdevBuiltinCommand cmd;
930
931 cmd = udev_builtin_lookup(value);
932 if (cmd < 0)
933 return log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL),
934 "Unknown builtin command '%s', ignoring", value);
935 r = rule_line_add_token(rule_line, TK_A_RUN_BUILTIN, op, value, UDEV_BUILTIN_CMD_TO_PTR(cmd));
936 } else
937 return log_token_invalid_attr(rules, key);
938 } else if (streq(key, "GOTO")) {
939 if (attr)
940 return log_token_invalid_attr(rules, key);
941 if (op != OP_ASSIGN)
942 return log_token_invalid_op(rules, key);
943 if (FLAGS_SET(rule_line->type, LINE_HAS_GOTO)) {
944 log_token_warning(rules, "Contains multiple GOTO key, ignoring GOTO=\"%s\".", value);
945 return 0;
946 }
947
948 rule_line->goto_label = value;
949 SET_FLAG(rule_line->type, LINE_HAS_GOTO, true);
950 return 1;
951 } else if (streq(key, "LABEL")) {
952 if (attr)
953 return log_token_invalid_attr(rules, key);
954 if (op != OP_ASSIGN)
955 return log_token_invalid_op(rules, key);
956
957 rule_line->label = value;
958 SET_FLAG(rule_line->type, LINE_HAS_LABEL, true);
959 return 1;
960 } else
961 return log_token_error_errno(rules, SYNTHETIC_ERRNO(EINVAL), "Invalid key '%s'", key);
962 if (r < 0)
963 return log_oom();
964
965 return 1;
966 }
967
968 static UdevRuleOperatorType parse_operator(const char *op) {
969 assert(op);
970
971 if (startswith(op, "=="))
972 return OP_MATCH;
973 if (startswith(op, "!="))
974 return OP_NOMATCH;
975 if (startswith(op, "+="))
976 return OP_ADD;
977 if (startswith(op, "-="))
978 return OP_REMOVE;
979 if (startswith(op, "="))
980 return OP_ASSIGN;
981 if (startswith(op, ":="))
982 return OP_ASSIGN_FINAL;
983
984 return _OP_TYPE_INVALID;
985 }
986
987 static int parse_line(char **line, char **ret_key, char **ret_attr, UdevRuleOperatorType *ret_op, char **ret_value) {
988 char *key_begin, *key_end, *attr, *tmp, *value, *i, *j;
989 UdevRuleOperatorType op;
990
991 assert(line);
992 assert(*line);
993 assert(ret_key);
994 assert(ret_op);
995 assert(ret_value);
996
997 key_begin = skip_leading_chars(*line, WHITESPACE ",");
998
999 if (isempty(key_begin))
1000 return 0;
1001
1002 for (key_end = key_begin; ; key_end++) {
1003 if (key_end[0] == '\0')
1004 return -EINVAL;
1005 if (strchr(WHITESPACE "={", key_end[0]))
1006 break;
1007 if (strchr("+-!:", key_end[0]) && key_end[1] == '=')
1008 break;
1009 }
1010 if (key_end[0] == '{') {
1011 attr = key_end + 1;
1012 tmp = strchr(attr, '}');
1013 if (!tmp)
1014 return -EINVAL;
1015 *tmp++ = '\0';
1016 } else {
1017 attr = NULL;
1018 tmp = key_end;
1019 }
1020
1021 tmp = skip_leading_chars(tmp, NULL);
1022 op = parse_operator(tmp);
1023 if (op < 0)
1024 return -EINVAL;
1025
1026 key_end[0] = '\0';
1027
1028 tmp += op == OP_ASSIGN ? 1 : 2;
1029 value = skip_leading_chars(tmp, NULL);
1030
1031 /* value must be double quotated */
1032 if (value[0] != '"')
1033 return -EINVAL;
1034 value++;
1035
1036 /* unescape double quotation '\"' -> '"' */
1037 for (i = j = value; ; i++, j++) {
1038 if (*i == '"')
1039 break;
1040 if (*i == '\0')
1041 return -EINVAL;
1042 if (i[0] == '\\' && i[1] == '"')
1043 i++;
1044 *j = *i;
1045 }
1046 j[0] = '\0';
1047
1048 *line = i+1;
1049 *ret_key = key_begin;
1050 *ret_attr = attr;
1051 *ret_op = op;
1052 *ret_value = value;
1053 return 1;
1054 }
1055
1056 static void sort_tokens(UdevRuleLine *rule_line) {
1057 UdevRuleToken *head_old;
1058
1059 assert(rule_line);
1060
1061 head_old = TAKE_PTR(rule_line->tokens);
1062 rule_line->current_token = NULL;
1063
1064 while (!LIST_IS_EMPTY(head_old)) {
1065 UdevRuleToken *t, *min_token = NULL;
1066
1067 LIST_FOREACH(tokens, t, head_old)
1068 if (!min_token || min_token->type > t->type)
1069 min_token = t;
1070
1071 LIST_REMOVE(tokens, head_old, min_token);
1072 rule_line_append_token(rule_line, min_token);
1073 }
1074 }
1075
1076 static int rule_add_line(UdevRules *rules, const char *line_str, unsigned line_nr) {
1077 _cleanup_(udev_rule_line_freep) UdevRuleLine *rule_line = NULL;
1078 _cleanup_free_ char *line = NULL;
1079 UdevRuleFile *rule_file;
1080 char *p;
1081 int r;
1082
1083 assert(rules);
1084 assert(rules->current_file);
1085 assert(line_str);
1086
1087 rule_file = rules->current_file;
1088
1089 if (isempty(line_str))
1090 return 0;
1091
1092 line = strdup(line_str);
1093 if (!line)
1094 return log_oom();
1095
1096 rule_line = new(UdevRuleLine, 1);
1097 if (!rule_line)
1098 return log_oom();
1099
1100 *rule_line = (UdevRuleLine) {
1101 .line = TAKE_PTR(line),
1102 .line_number = line_nr,
1103 .rule_file = rule_file,
1104 };
1105
1106 if (rule_file->current_line)
1107 LIST_APPEND(rule_lines, rule_file->current_line, rule_line);
1108 else
1109 LIST_APPEND(rule_lines, rule_file->rule_lines, rule_line);
1110
1111 rule_file->current_line = rule_line;
1112
1113 for (p = rule_line->line; !isempty(p); ) {
1114 char *key, *attr, *value;
1115 UdevRuleOperatorType op;
1116
1117 r = parse_line(&p, &key, &attr, &op, &value);
1118 if (r < 0)
1119 return log_token_error_errno(rules, r, "Invalid key/value pair, ignoring.");
1120 if (r == 0)
1121 break;
1122
1123 r = parse_token(rules, key, attr, op, value);
1124 if (r < 0)
1125 return r;
1126 }
1127
1128 if (rule_line->type == 0) {
1129 log_token_warning(rules, "The line takes no effect, ignoring.");
1130 return 0;
1131 }
1132
1133 sort_tokens(rule_line);
1134 TAKE_PTR(rule_line);
1135 return 0;
1136 }
1137
1138 static void rule_resolve_goto(UdevRuleFile *rule_file) {
1139 UdevRuleLine *line, *line_next, *i;
1140
1141 assert(rule_file);
1142
1143 /* link GOTOs to LABEL rules in this file to be able to fast-forward */
1144 LIST_FOREACH_SAFE(rule_lines, line, line_next, rule_file->rule_lines) {
1145 if (!FLAGS_SET(line->type, LINE_HAS_GOTO))
1146 continue;
1147
1148 LIST_FOREACH_AFTER(rule_lines, i, line)
1149 if (streq_ptr(i->label, line->goto_label)) {
1150 line->goto_line = i;
1151 break;
1152 }
1153
1154 if (!line->goto_line) {
1155 log_error("%s:%u: GOTO=\"%s\" has no matching label, ignoring",
1156 rule_file->filename, line->line_number, line->goto_label);
1157
1158 SET_FLAG(line->type, LINE_HAS_GOTO, false);
1159 line->goto_label = NULL;
1160
1161 if ((line->type & ~LINE_HAS_LABEL) == 0) {
1162 log_notice("%s:%u: The line takes no effect any more, dropping",
1163 rule_file->filename, line->line_number);
1164 if (line->type == LINE_HAS_LABEL)
1165 udev_rule_line_clear_tokens(line);
1166 else
1167 udev_rule_line_free(line);
1168 }
1169 }
1170 }
1171 }
1172
1173 static int parse_file(UdevRules *rules, const char *filename) {
1174 _cleanup_free_ char *continuation = NULL, *name = NULL;
1175 _cleanup_fclose_ FILE *f = NULL;
1176 UdevRuleFile *rule_file;
1177 bool ignore_line = false;
1178 unsigned line_nr = 0;
1179 int r;
1180
1181 f = fopen(filename, "re");
1182 if (!f) {
1183 if (errno == ENOENT)
1184 return 0;
1185
1186 return -errno;
1187 }
1188
1189 (void) fd_warn_permissions(filename, fileno(f));
1190
1191 if (null_or_empty_fd(fileno(f))) {
1192 log_debug("Skipping empty file: %s", filename);
1193 return 0;
1194 }
1195
1196 log_debug("Reading rules file: %s", filename);
1197
1198 name = strdup(filename);
1199 if (!name)
1200 return log_oom();
1201
1202 rule_file = new(UdevRuleFile, 1);
1203 if (!rule_file)
1204 return log_oom();
1205
1206 *rule_file = (UdevRuleFile) {
1207 .filename = TAKE_PTR(name),
1208 };
1209
1210 if (rules->current_file)
1211 LIST_APPEND(rule_files, rules->current_file, rule_file);
1212 else
1213 LIST_APPEND(rule_files, rules->rule_files, rule_file);
1214
1215 rules->current_file = rule_file;
1216
1217 for (;;) {
1218 _cleanup_free_ char *buf = NULL;
1219 size_t len;
1220 char *line;
1221
1222 r = read_line(f, UTIL_LINE_SIZE, &buf);
1223 if (r < 0)
1224 return r;
1225 if (r == 0)
1226 break;
1227
1228 line_nr++;
1229 line = skip_leading_chars(buf, NULL);
1230
1231 if (line[0] == '#')
1232 continue;
1233
1234 len = strlen(line);
1235
1236 if (continuation && !ignore_line) {
1237 if (strlen(continuation) + len >= UTIL_LINE_SIZE)
1238 ignore_line = true;
1239
1240 if (!strextend(&continuation, line, NULL))
1241 return log_oom();
1242
1243 if (!ignore_line) {
1244 line = continuation;
1245 len = strlen(line);
1246 }
1247 }
1248
1249 if (len > 0 && line[len - 1] == '\\') {
1250 if (ignore_line)
1251 continue;
1252
1253 line[len - 1] = '\0';
1254 if (!continuation) {
1255 continuation = strdup(line);
1256 if (!continuation)
1257 return log_oom();
1258 }
1259
1260 continue;
1261 }
1262
1263 if (ignore_line)
1264 log_error("%s:%u: Line is too long, ignored", filename, line_nr);
1265 else if (len > 0)
1266 (void) rule_add_line(rules, line, line_nr);
1267
1268 continuation = mfree(continuation);
1269 ignore_line = false;
1270 }
1271
1272 rule_resolve_goto(rule_file);
1273 return 0;
1274 }
1275
1276 int udev_rules_new(UdevRules **ret_rules, ResolveNameTiming resolve_name_timing) {
1277 _cleanup_(udev_rules_freep) UdevRules *rules = NULL;
1278 _cleanup_strv_free_ char **files = NULL;
1279 char **f;
1280 int r;
1281
1282 assert(resolve_name_timing >= 0 && resolve_name_timing < _RESOLVE_NAME_TIMING_MAX);
1283
1284 rules = new(UdevRules, 1);
1285 if (!rules)
1286 return -ENOMEM;
1287
1288 *rules = (UdevRules) {
1289 .resolve_name_timing = resolve_name_timing,
1290 };
1291
1292 (void) udev_rules_check_timestamp(rules);
1293
1294 r = conf_files_list_strv(&files, ".rules", NULL, 0, RULES_DIRS);
1295 if (r < 0)
1296 return log_error_errno(r, "Failed to enumerate rules files: %m");
1297
1298 STRV_FOREACH(f, files)
1299 (void) parse_file(rules, *f);
1300
1301 *ret_rules = TAKE_PTR(rules);
1302 return 0;
1303 }
1304
1305 bool udev_rules_check_timestamp(UdevRules *rules) {
1306 if (!rules)
1307 return false;
1308
1309 return paths_check_timestamp(RULES_DIRS, &rules->dirs_ts_usec, true);
1310 }
1311
1312 static bool token_match_string(UdevRuleToken *token, const char *str) {
1313 const char *i, *value;
1314 bool match = false;
1315
1316 assert(token);
1317 assert(token->value);
1318 assert(token->type < _TK_M_MAX);
1319
1320 str = strempty(str);
1321 value = token->value;
1322
1323 switch (token->match_type) {
1324 case MATCH_TYPE_EMPTY:
1325 match = isempty(str);
1326 break;
1327 case MATCH_TYPE_SUBSYSTEM:
1328 value = "subsystem\0class\0bus\0";
1329 _fallthrough_;
1330 case MATCH_TYPE_PLAIN:
1331 NULSTR_FOREACH(i, value)
1332 if (streq(i, str)) {
1333 match = true;
1334 break;
1335 }
1336 break;
1337 case MATCH_TYPE_GLOB:
1338 NULSTR_FOREACH(i, value)
1339 if ((fnmatch(i, str, 0) == 0)) {
1340 match = true;
1341 break;
1342 }
1343 break;
1344 default:
1345 assert_not_reached("Invalid match type");
1346 }
1347
1348 return token->op == (match ? OP_MATCH : OP_NOMATCH);
1349 }
1350
1351 static bool token_match_attr(UdevRuleToken *token, sd_device *dev, UdevEvent *event) {
1352 char nbuf[UTIL_NAME_SIZE], vbuf[UTIL_NAME_SIZE];
1353 const char *name, *value;
1354
1355 assert(token);
1356 assert(dev);
1357 assert(event);
1358
1359 name = (const char*) token->data;
1360
1361 switch (token->attr_subst_type) {
1362 case SUBST_TYPE_FORMAT:
1363 (void) udev_event_apply_format(event, name, nbuf, sizeof(nbuf), false);
1364 name = nbuf;
1365 _fallthrough_;
1366 case SUBST_TYPE_PLAIN:
1367 if (sd_device_get_sysattr_value(dev, name, &value) < 0)
1368 return false;
1369 break;
1370 case SUBST_TYPE_SUBSYS:
1371 if (util_resolve_subsys_kernel(name, vbuf, sizeof(vbuf), true) < 0)
1372 return false;
1373 value = vbuf;
1374 break;
1375 default:
1376 assert_not_reached("Invalid attribute substitution type");
1377 }
1378
1379 /* remove trailing whitespace, if not asked to match for it */
1380 if (token->attr_match_remove_trailing_whitespace) {
1381 if (value != vbuf) {
1382 strscpy(vbuf, sizeof(vbuf), value);
1383 value = vbuf;
1384 }
1385
1386 delete_trailing_chars(vbuf, NULL);
1387 }
1388
1389 return token_match_string(token, value);
1390 }
1391
1392 static int get_property_from_string(char *line, char **ret_key, char **ret_value) {
1393 char *key, *val;
1394 size_t len;
1395
1396 assert(line);
1397 assert(ret_key);
1398 assert(ret_value);
1399
1400 /* find key */
1401 key = skip_leading_chars(line, NULL);
1402
1403 /* comment or empty line */
1404 if (IN_SET(key[0], '#', '\0')) {
1405 *ret_key = *ret_value = NULL;
1406 return 0;
1407 }
1408
1409 /* split key/value */
1410 val = strchr(key, '=');
1411 if (!val)
1412 return -EINVAL;
1413 *val++ = '\0';
1414
1415 key = strstrip(key);
1416 if (isempty(key))
1417 return -EINVAL;
1418
1419 val = strstrip(val);
1420 if (isempty(val))
1421 return -EINVAL;
1422
1423 /* unquote */
1424 if (IN_SET(val[0], '"', '\'')) {
1425 len = strlen(val);
1426 if (len == 1 || val[len-1] != val[0])
1427 return -EINVAL;
1428 val[len-1] = '\0';
1429 val++;
1430 }
1431
1432 *ret_key = key;
1433 *ret_value = val;
1434 return 1;
1435 }
1436
1437 static int import_parent_into_properties(sd_device *dev, const char *filter) {
1438 const char *key, *val;
1439 sd_device *parent;
1440 int r;
1441
1442 assert(dev);
1443 assert(filter);
1444
1445 r = sd_device_get_parent(dev, &parent);
1446 if (r == -ENOENT)
1447 return 0;
1448 if (r < 0)
1449 return r;
1450
1451 FOREACH_DEVICE_PROPERTY(parent, key, val) {
1452 if (fnmatch(filter, key, 0) != 0)
1453 continue;
1454 r = device_add_property(dev, key, val);
1455 if (r < 0)
1456 return r;
1457 }
1458
1459 return 1;
1460 }
1461
1462 static int attr_subst_subdir(char attr[static UTIL_PATH_SIZE]) {
1463 _cleanup_closedir_ DIR *dir = NULL;
1464 struct dirent *dent;
1465 char buf[UTIL_PATH_SIZE], *p;
1466 const char *tail;
1467 size_t len, size;
1468
1469 assert(attr);
1470
1471 tail = strstr(attr, "/*/");
1472 if (!tail)
1473 return 0;
1474
1475 len = tail - attr + 1; /* include slash at the end */
1476 tail += 2; /* include slash at the beginning */
1477
1478 p = buf;
1479 size = sizeof(buf);
1480 size -= strnpcpy(&p, size, attr, len);
1481
1482 dir = opendir(buf);
1483 if (!dir)
1484 return -errno;
1485
1486 FOREACH_DIRENT_ALL(dent, dir, break) {
1487 if (dent->d_name[0] == '.')
1488 continue;
1489
1490 strscpyl(p, size, dent->d_name, tail, NULL);
1491 if (faccessat(dirfd(dir), p, F_OK, 0) < 0)
1492 continue;
1493
1494 strcpy(attr, buf);
1495 return 0;
1496 }
1497
1498 return -ENOENT;
1499 }
1500
1501 static int udev_rule_apply_token_to_event(
1502 UdevRules *rules,
1503 sd_device *dev,
1504 UdevEvent *event,
1505 usec_t timeout_usec,
1506 Hashmap *properties_list) {
1507
1508 UdevRuleToken *token;
1509 char buf[UTIL_PATH_SIZE];
1510 const char *val;
1511 size_t count;
1512 bool match;
1513 int r;
1514
1515 assert(rules);
1516 assert(dev);
1517 assert(event);
1518
1519 /* This returns the following values:
1520 * 0 on the current token does not match the event,
1521 * 1 on the current token matches the event, and
1522 * negative errno on some critical errors. */
1523
1524 token = rules->current_file->current_line->current_token;
1525
1526 switch (token->type) {
1527 case TK_M_ACTION: {
1528 DeviceAction a;
1529
1530 r = device_get_action(dev, &a);
1531 if (r < 0)
1532 return log_rule_error_errno(dev, rules, r, "Failed to get uevent action type: %m");
1533
1534 return token_match_string(token, device_action_to_string(a));
1535 }
1536 case TK_M_DEVPATH:
1537 r = sd_device_get_devpath(dev, &val);
1538 if (r < 0)
1539 return log_rule_error_errno(dev, rules, r, "Failed to get devpath: %m");
1540
1541 return token_match_string(token, val);
1542 case TK_M_KERNEL:
1543 case TK_M_PARENTS_KERNEL:
1544 r = sd_device_get_sysname(dev, &val);
1545 if (r < 0)
1546 return log_rule_error_errno(dev, rules, r, "Failed to get sysname: %m");
1547
1548 return token_match_string(token, val);
1549 case TK_M_DEVLINK:
1550 FOREACH_DEVICE_DEVLINK(dev, val)
1551 if (token_match_string(token, strempty(startswith(val, "/dev/"))))
1552 return token->op == OP_MATCH;
1553 return token->op == OP_NOMATCH;
1554 case TK_M_NAME:
1555 return token_match_string(token, event->name);
1556 case TK_M_ENV:
1557 if (sd_device_get_property_value(dev, (const char*) token->data, &val) < 0)
1558 val = hashmap_get(properties_list, token->data);
1559
1560 return token_match_string(token, val);
1561 case TK_M_TAG:
1562 case TK_M_PARENTS_TAG:
1563 FOREACH_DEVICE_TAG(dev, val)
1564 if (token_match_string(token, val))
1565 return token->op == OP_MATCH;
1566 return token->op == OP_NOMATCH;
1567 case TK_M_SUBSYSTEM:
1568 case TK_M_PARENTS_SUBSYSTEM:
1569 r = sd_device_get_subsystem(dev, &val);
1570 if (r == -ENOENT)
1571 val = NULL;
1572 else if (r < 0)
1573 return log_rule_error_errno(dev, rules, r, "Failed to get subsystem: %m");
1574
1575 return token_match_string(token, val);
1576 case TK_M_DRIVER:
1577 case TK_M_PARENTS_DRIVER:
1578 r = sd_device_get_driver(dev, &val);
1579 if (r == -ENOENT)
1580 val = NULL;
1581 else if (r < 0)
1582 return log_rule_error_errno(dev, rules, r, "Failed to get driver: %m");
1583
1584 return token_match_string(token, val);
1585 case TK_M_ATTR:
1586 case TK_M_PARENTS_ATTR:
1587 return token_match_attr(token, dev, event);
1588 case TK_M_SYSCTL: {
1589 _cleanup_free_ char *value = NULL;
1590
1591 (void) udev_event_apply_format(event, (const char*) token->data, buf, sizeof(buf), false);
1592 r = sysctl_read(sysctl_normalize(buf), &value);
1593 if (r < 0 && r != -ENOENT)
1594 return log_rule_error_errno(dev, rules, r, "Failed to read sysctl '%s': %m", buf);
1595
1596 return token_match_string(token, strstrip(value));
1597 }
1598 case TK_M_TEST: {
1599 mode_t mode = PTR_TO_MODE(token->data);
1600 struct stat statbuf;
1601
1602 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1603 if (!path_is_absolute(buf) &&
1604 util_resolve_subsys_kernel(buf, buf, sizeof(buf), false) < 0) {
1605 char tmp[UTIL_PATH_SIZE];
1606
1607 r = sd_device_get_syspath(dev, &val);
1608 if (r < 0)
1609 return log_rule_error_errno(dev, rules, r, "Failed to get syspath: %m");
1610
1611 strscpy(tmp, sizeof(tmp), buf);
1612 strscpyl(buf, sizeof(buf), val, "/", tmp, NULL);
1613 }
1614
1615 r = attr_subst_subdir(buf);
1616 if (r == -ENOENT)
1617 return token->op == OP_NOMATCH;
1618 if (r < 0)
1619 return log_rule_error_errno(dev, rules, r, "Failed to test the existence of '%s': %m", buf);
1620
1621 if (stat(buf, &statbuf) < 0)
1622 return token->op == OP_NOMATCH;
1623
1624 if (mode == MODE_INVALID)
1625 return token->op == OP_MATCH;
1626
1627 match = (((statbuf.st_mode ^ mode) & 07777) == 0);
1628 return token->op == (match ? OP_MATCH : OP_NOMATCH);
1629 }
1630 case TK_M_PROGRAM: {
1631 char result[UTIL_LINE_SIZE];
1632
1633 event->program_result = mfree(event->program_result);
1634 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1635 log_rule_debug(dev, rules, "Running PROGRAM '%s'", buf);
1636
1637 r = udev_event_spawn(event, timeout_usec, true, buf, result, sizeof(result));
1638 if (r < 0)
1639 return log_rule_error_errno(dev, rules, r, "Failed to execute '%s': %m", buf);
1640 if (r > 0)
1641 return token->op == OP_NOMATCH;
1642
1643 delete_trailing_chars(result, "\n");
1644 count = util_replace_chars(result, UDEV_ALLOWED_CHARS_INPUT);
1645 if (count > 0)
1646 log_rule_debug(dev, rules, "Replaced %zu character(s) from result of '%s'",
1647 count, buf);
1648
1649 event->program_result = strdup(result);
1650 return token->op == OP_MATCH;
1651 }
1652 case TK_M_IMPORT_FILE: {
1653 _cleanup_fclose_ FILE *f = NULL;
1654
1655 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1656 log_rule_debug(dev, rules, "Importing properties from '%s'", buf);
1657
1658 f = fopen(buf, "re");
1659 if (!f) {
1660 if (errno != ENOENT)
1661 return log_rule_error_errno(dev, rules, errno,
1662 "Failed to open '%s': %m", buf);
1663 return token->op == OP_NOMATCH;
1664 }
1665
1666 for (;;) {
1667 _cleanup_free_ char *line = NULL;
1668 char *key, *value;
1669
1670 r = read_line(f, LONG_LINE_MAX, &line);
1671 if (r < 0) {
1672 log_rule_debug_errno(dev, rules, r,
1673 "Failed to read '%s', ignoring: %m", buf);
1674 return token->op == OP_NOMATCH;
1675 }
1676 if (r == 0)
1677 break;
1678
1679 r = get_property_from_string(line, &key, &value);
1680 if (r < 0) {
1681 log_rule_debug_errno(dev, rules, r,
1682 "Failed to parse key and value from '%s', ignoring: %m",
1683 line);
1684 continue;
1685 }
1686 if (r == 0)
1687 continue;
1688
1689 r = device_add_property(dev, key, value);
1690 if (r < 0)
1691 return log_rule_error_errno(dev, rules, r,
1692 "Failed to add property %s=%s: %m",
1693 key, value);
1694 }
1695
1696 return token->op == OP_MATCH;
1697 }
1698 case TK_M_IMPORT_PROGRAM: {
1699 char result[UTIL_LINE_SIZE], *line, *pos;
1700
1701 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1702 log_rule_debug(dev, rules, "Importing properties from results of '%s'", buf);
1703
1704 r = udev_event_spawn(event, timeout_usec, true, buf, result, sizeof result);
1705 if (r < 0)
1706 return log_rule_error_errno(dev, rules, r, "Failed to execute '%s': %m", buf);
1707 if (r > 0) {
1708 log_rule_debug(dev, rules, "Command \"%s\" returned %d (error), ignoring", buf, r);
1709 return token->op == OP_NOMATCH;
1710 }
1711
1712 for (line = result; !isempty(line); line = pos) {
1713 char *key, *value;
1714
1715 pos = strchr(line, '\n');
1716 if (pos)
1717 *pos++ = '\0';
1718
1719 r = get_property_from_string(line, &key, &value);
1720 if (r < 0) {
1721 log_rule_debug_errno(dev, rules, r,
1722 "Failed to parse key and value from '%s', ignoring: %m",
1723 line);
1724 continue;
1725 }
1726 if (r == 0)
1727 continue;
1728
1729 r = device_add_property(dev, key, value);
1730 if (r < 0)
1731 return log_rule_error_errno(dev, rules, r,
1732 "Failed to add property %s=%s: %m",
1733 key, value);
1734 }
1735
1736 return token->op == OP_MATCH;
1737 }
1738 case TK_M_IMPORT_BUILTIN: {
1739 UdevBuiltinCommand cmd = PTR_TO_UDEV_BUILTIN_CMD(token->data);
1740 unsigned mask = 1U << (int) cmd;
1741
1742 if (udev_builtin_run_once(cmd)) {
1743 /* check if we ran already */
1744 if (event->builtin_run & mask) {
1745 log_rule_debug(dev, rules, "Skipping builtin '%s' in IMPORT key",
1746 udev_builtin_name(cmd));
1747 /* return the result from earlier run */
1748 return token->op == (event->builtin_ret & mask ? OP_NOMATCH : OP_MATCH);
1749 }
1750 /* mark as ran */
1751 event->builtin_run |= mask;
1752 }
1753
1754 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1755 log_rule_debug(dev, rules, "Importing properties from results of builtin command '%s'", buf);
1756
1757 r = udev_builtin_run(dev, cmd, buf, false);
1758 if (r < 0) {
1759 /* remember failure */
1760 log_rule_debug_errno(dev, rules, r, "Failed to run builtin '%s': %m", buf);
1761 event->builtin_ret |= mask;
1762 }
1763 return token->op == (r >= 0 ? OP_MATCH : OP_NOMATCH);
1764 }
1765 case TK_M_IMPORT_DB: {
1766 if (!event->dev_db_clone)
1767 return token->op == OP_NOMATCH;
1768 r = sd_device_get_property_value(event->dev_db_clone, token->value, &val);
1769 if (r == -ENOENT)
1770 return token->op == OP_NOMATCH;
1771 if (r < 0)
1772 return log_rule_error_errno(dev, rules, r,
1773 "Failed to get property '%s' from database: %m",
1774 token->value);
1775
1776 r = device_add_property(dev, token->value, val);
1777 if (r < 0)
1778 return log_rule_error_errno(dev, rules, r, "Failed to add property '%s=%s': %m",
1779 token->value, val);
1780 return token->op == OP_MATCH;
1781 }
1782 case TK_M_IMPORT_CMDLINE: {
1783 _cleanup_free_ char *value = NULL;
1784
1785 r = proc_cmdline_get_key(token->value, PROC_CMDLINE_VALUE_OPTIONAL, &value);
1786 if (r < 0)
1787 return log_rule_error_errno(dev, rules, r,
1788 "Failed to read '%s' option from /proc/cmdline: %m",
1789 token->value);
1790 if (r == 0)
1791 return token->op == OP_NOMATCH;
1792
1793 r = device_add_property(dev, token->value, value ?: "1");
1794 if (r < 0)
1795 return log_rule_error_errno(dev, rules, r, "Failed to add property '%s=%s': %m",
1796 token->value, value ?: "1");
1797 return token->op == OP_MATCH;
1798 }
1799 case TK_M_IMPORT_PARENT: {
1800 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1801 r = import_parent_into_properties(dev, buf);
1802 if (r < 0)
1803 return log_rule_error_errno(dev, rules, r,
1804 "Failed to import properties '%s' from parent: %m",
1805 buf);
1806 return token->op == (r > 0 ? OP_MATCH : OP_NOMATCH);
1807 }
1808 case TK_M_RESULT:
1809 return token_match_string(token, event->program_result);
1810 case TK_A_OPTIONS_STRING_ESCAPE_NONE:
1811 event->esc = ESCAPE_NONE;
1812 break;
1813 case TK_A_OPTIONS_STRING_ESCAPE_REPLACE:
1814 event->esc = ESCAPE_REPLACE;
1815 break;
1816 case TK_A_OPTIONS_DB_PERSIST:
1817 device_set_db_persist(dev);
1818 break;
1819 case TK_A_OPTIONS_INOTIFY_WATCH:
1820 if (event->inotify_watch_final)
1821 break;
1822 if (token->op == OP_ASSIGN_FINAL)
1823 event->inotify_watch_final = true;
1824
1825 event->inotify_watch = token->data;
1826 break;
1827 case TK_A_OPTIONS_DEVLINK_PRIORITY:
1828 device_set_devlink_priority(dev, PTR_TO_INT(token->data));
1829 break;
1830 case TK_A_OWNER: {
1831 char owner[UTIL_NAME_SIZE];
1832 const char *ow = owner;
1833
1834 if (event->owner_final)
1835 break;
1836 if (token->op == OP_ASSIGN_FINAL)
1837 event->owner_final = true;
1838
1839 (void) udev_event_apply_format(event, token->value, owner, sizeof(owner), false);
1840 r = get_user_creds(&ow, &event->uid, NULL, NULL, NULL, USER_CREDS_ALLOW_MISSING);
1841 if (r < 0)
1842 log_unknown_owner(dev, rules, r, "user", owner);
1843 else
1844 log_rule_debug(dev, rules, "OWNER %s(%u)", owner, event->uid);
1845 break;
1846 }
1847 case TK_A_GROUP: {
1848 char group[UTIL_NAME_SIZE];
1849 const char *gr = group;
1850
1851 if (event->group_final)
1852 break;
1853 if (token->op == OP_ASSIGN_FINAL)
1854 event->group_final = true;
1855
1856 (void) udev_event_apply_format(event, token->value, group, sizeof(group), false);
1857 r = get_group_creds(&gr, &event->gid, USER_CREDS_ALLOW_MISSING);
1858 if (r < 0)
1859 log_unknown_owner(dev, rules, r, "group", group);
1860 else
1861 log_rule_debug(dev, rules, "GROUP %s(%u)", group, event->gid);
1862 break;
1863 }
1864 case TK_A_MODE: {
1865 char mode_str[UTIL_NAME_SIZE];
1866
1867 if (event->mode_final)
1868 break;
1869 if (token->op == OP_ASSIGN_FINAL)
1870 event->mode_final = true;
1871
1872 (void) udev_event_apply_format(event, token->value, mode_str, sizeof(mode_str), false);
1873 r = parse_mode(mode_str, &event->mode);
1874 if (r < 0)
1875 log_rule_error_errno(dev, rules, r, "Failed to parse mode '%s', ignoring: %m", mode_str);
1876 else
1877 log_rule_debug(dev, rules, "MODE %#o", event->mode);
1878 break;
1879 }
1880 case TK_A_OWNER_ID:
1881 if (event->owner_final)
1882 break;
1883 if (token->op == OP_ASSIGN_FINAL)
1884 event->owner_final = true;
1885 if (!token->data)
1886 break;
1887 event->uid = PTR_TO_UID(token->data);
1888 log_rule_debug(dev, rules, "OWNER %u", event->uid);
1889 break;
1890 case TK_A_GROUP_ID:
1891 if (event->group_final)
1892 break;
1893 if (token->op == OP_ASSIGN_FINAL)
1894 event->group_final = true;
1895 if (!token->data)
1896 break;
1897 event->gid = PTR_TO_GID(token->data);
1898 log_rule_debug(dev, rules, "GROUP %u", event->gid);
1899 break;
1900 case TK_A_MODE_ID:
1901 if (event->mode_final)
1902 break;
1903 if (token->op == OP_ASSIGN_FINAL)
1904 event->mode_final = true;
1905 if (!token->data)
1906 break;
1907 event->mode = PTR_TO_MODE(token->data);
1908 log_rule_debug(dev, rules, "MODE %#o", event->mode);
1909 break;
1910 case TK_A_SECLABEL: {
1911 _cleanup_free_ char *name = NULL, *label = NULL;
1912 char label_str[UTIL_LINE_SIZE] = {};
1913
1914 name = strdup((const char*) token->data);
1915 if (!name)
1916 return log_oom();
1917
1918 (void) udev_event_apply_format(event, token->value, label_str, sizeof(label_str), false);
1919 if (!isempty(label_str))
1920 label = strdup(label_str);
1921 else
1922 label = strdup(token->value);
1923 if (!label)
1924 return log_oom();
1925
1926 if (token->op == OP_ASSIGN)
1927 ordered_hashmap_clear_free_free(event->seclabel_list);
1928
1929 r = ordered_hashmap_ensure_allocated(&event->seclabel_list, NULL);
1930 if (r < 0)
1931 return log_oom();
1932
1933 r = ordered_hashmap_put(event->seclabel_list, name, label);
1934 if (r < 0)
1935 return log_oom();
1936 log_rule_debug(dev, rules, "SECLABEL{%s}='%s'", name, label);
1937 name = label = NULL;
1938 break;
1939 }
1940 case TK_A_ENV: {
1941 const char *name = (const char*) token->data;
1942 char value_new[UTIL_NAME_SIZE], *p = value_new;
1943 size_t l = sizeof(value_new);
1944
1945 if (isempty(token->value)) {
1946 if (token->op == OP_ADD)
1947 break;
1948 r = device_add_property(dev, name, NULL);
1949 if (r < 0)
1950 return log_rule_error_errno(dev, rules, r, "Failed to remove property '%s': %m", name);
1951 break;
1952 }
1953
1954 if (token->op == OP_ADD &&
1955 sd_device_get_property_value(dev, name, &val) >= 0)
1956 l = strpcpyl(&p, l, val, " ", NULL);
1957
1958 (void) udev_event_apply_format(event, token->value, p, l, false);
1959
1960 r = device_add_property(dev, name, value_new);
1961 if (r < 0)
1962 return log_rule_error_errno(dev, rules, r, "Failed to add property '%s=%s': %m", name, value_new);
1963 break;
1964 }
1965 case TK_A_TAG: {
1966 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1967 if (token->op == OP_ASSIGN)
1968 device_cleanup_tags(dev);
1969
1970 if (buf[strspn(buf, ALPHANUMERICAL "-_")] != '\0') {
1971 log_rule_error(dev, rules, "Invalid tag name '%s', ignoring", buf);
1972 break;
1973 }
1974 if (token->op == OP_REMOVE)
1975 device_remove_tag(dev, buf);
1976 else {
1977 r = device_add_tag(dev, buf);
1978 if (r < 0)
1979 return log_rule_error_errno(dev, rules, r, "Failed to add tag '%s': %m", buf);
1980 }
1981 break;
1982 }
1983 case TK_A_NAME: {
1984 if (event->name_final)
1985 break;
1986 if (token->op == OP_ASSIGN_FINAL)
1987 event->name_final = true;
1988
1989 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
1990 if (IN_SET(event->esc, ESCAPE_UNSET, ESCAPE_REPLACE)) {
1991 count = util_replace_chars(buf, "/");
1992 if (count > 0)
1993 log_rule_debug(dev, rules, "Replaced %zu character(s) from result of NAME=\"%s\"",
1994 count, token->value);
1995 }
1996 if (sd_device_get_devnum(dev, NULL) >= 0 &&
1997 (sd_device_get_devname(dev, &val) < 0 ||
1998 !streq_ptr(buf, startswith(val, "/dev/")))) {
1999 log_rule_error(dev, rules,
2000 "Kernel device nodes cannot be renamed, ignoring NAME=\"%s\"; please fix it.",
2001 token->value);
2002 break;
2003 }
2004 if (free_and_strdup(&event->name, buf) < 0)
2005 return log_oom();
2006
2007 log_rule_debug(dev, rules, "NAME '%s'", event->name);
2008 break;
2009 }
2010 case TK_A_DEVLINK: {
2011 char *p;
2012
2013 if (event->devlink_final)
2014 break;
2015 if (sd_device_get_devnum(dev, NULL) < 0)
2016 break;
2017 if (token->op == OP_ASSIGN_FINAL)
2018 event->devlink_final = true;
2019 if (IN_SET(token->op, OP_ASSIGN, OP_ASSIGN_FINAL))
2020 device_cleanup_devlinks(dev);
2021
2022 /* allow multiple symlinks separated by spaces */
2023 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), event->esc != ESCAPE_NONE);
2024 if (event->esc == ESCAPE_UNSET)
2025 count = util_replace_chars(buf, "/ ");
2026 else if (event->esc == ESCAPE_REPLACE)
2027 count = util_replace_chars(buf, "/");
2028 else
2029 count = 0;
2030 if (count > 0)
2031 log_rule_debug(dev, rules, "Replaced %zu character(s) from result of LINK", count);
2032
2033 p = skip_leading_chars(buf, NULL);
2034 while (!isempty(p)) {
2035 char filename[UTIL_PATH_SIZE], *next;
2036
2037 next = strchr(p, ' ');
2038 if (next) {
2039 *next++ = '\0';
2040 next = skip_leading_chars(next, NULL);
2041 }
2042
2043 strscpyl(filename, sizeof(filename), "/dev/", p, NULL);
2044 r = device_add_devlink(dev, filename);
2045 if (r < 0)
2046 return log_rule_error_errno(dev, rules, r, "Failed to add devlink '%s': %m", filename);
2047
2048 log_rule_debug(dev, rules, "LINK '%s'", p);
2049 p = next;
2050 }
2051 break;
2052 }
2053 case TK_A_ATTR: {
2054 const char *key_name = (const char*) token->data;
2055 char value[UTIL_NAME_SIZE];
2056
2057 if (util_resolve_subsys_kernel(key_name, buf, sizeof(buf), false) < 0 &&
2058 sd_device_get_syspath(dev, &val) >= 0)
2059 strscpyl(buf, sizeof(buf), val, "/", key_name, NULL);
2060
2061 r = attr_subst_subdir(buf);
2062 if (r < 0) {
2063 log_rule_error_errno(dev, rules, r, "Could not find file matches '%s', ignoring: %m", buf);
2064 break;
2065 }
2066 (void) udev_event_apply_format(event, token->value, value, sizeof(value), false);
2067
2068 log_rule_debug(dev, rules, "ATTR '%s' writing '%s'", buf, value);
2069 r = write_string_file(buf, value, WRITE_STRING_FILE_VERIFY_ON_FAILURE | WRITE_STRING_FILE_DISABLE_BUFFER);
2070 if (r < 0)
2071 log_rule_error_errno(dev, rules, r, "Failed to write ATTR{%s}, ignoring: %m", buf);
2072 break;
2073 }
2074 case TK_A_SYSCTL: {
2075 char value[UTIL_NAME_SIZE];
2076
2077 (void) udev_event_apply_format(event, (const char*) token->data, buf, sizeof(buf), false);
2078 (void) udev_event_apply_format(event, token->value, value, sizeof(value), false);
2079 sysctl_normalize(buf);
2080 log_rule_debug(dev, rules, "SYSCTL '%s' writing '%s'", buf, value);
2081 r = sysctl_write(buf, value);
2082 if (r < 0)
2083 log_rule_error_errno(dev, rules, r, "Failed to write SYSCTL{%s}='%s', ignoring: %m", buf, value);
2084 break;
2085 }
2086 case TK_A_RUN_BUILTIN:
2087 case TK_A_RUN_PROGRAM: {
2088 _cleanup_free_ char *cmd = NULL;
2089
2090 if (event->run_final)
2091 break;
2092 if (token->op == OP_ASSIGN_FINAL)
2093 event->run_final = true;
2094
2095 if (IN_SET(token->op, OP_ASSIGN, OP_ASSIGN_FINAL))
2096 ordered_hashmap_clear_free_key(event->run_list);
2097
2098 r = ordered_hashmap_ensure_allocated(&event->run_list, NULL);
2099 if (r < 0)
2100 return log_oom();
2101
2102 (void) udev_event_apply_format(event, token->value, buf, sizeof(buf), false);
2103
2104 cmd = strdup(buf);
2105 if (!cmd)
2106 return log_oom();
2107
2108 r = ordered_hashmap_put(event->run_list, cmd, token->data);
2109 if (r < 0)
2110 return log_oom();
2111
2112 TAKE_PTR(cmd);
2113
2114 log_rule_debug(dev, rules, "RUN '%s'", token->value);
2115 break;
2116 }
2117 case TK_A_OPTIONS_STATIC_NODE:
2118 /* do nothing for events. */
2119 break;
2120 default:
2121 assert_not_reached("Invalid token type");
2122 }
2123
2124 return true;
2125 }
2126
2127 static bool token_is_for_parents(UdevRuleToken *token) {
2128 return token->type >= TK_M_PARENTS_KERNEL && token->type <= TK_M_PARENTS_TAG;
2129 }
2130
2131 static int udev_rule_apply_parent_token_to_event(
2132 UdevRules *rules,
2133 UdevEvent *event) {
2134
2135 UdevRuleLine *line;
2136 UdevRuleToken *head;
2137 int r;
2138
2139 line = rules->current_file->current_line;
2140 head = rules->current_file->current_line->current_token;
2141 event->dev_parent = event->dev;
2142 for (;;) {
2143 LIST_FOREACH(tokens, line->current_token, head) {
2144 if (!token_is_for_parents(line->current_token))
2145 return true; /* All parent tokens match. */
2146 r = udev_rule_apply_token_to_event(rules, event->dev_parent, event, 0, NULL);
2147 if (r < 0)
2148 return r;
2149 if (r == 0)
2150 break;
2151 }
2152 if (!line->current_token)
2153 /* All parent tokens match. But no assign tokens in the line. Hmm... */
2154 return true;
2155
2156 if (sd_device_get_parent(event->dev_parent, &event->dev_parent) < 0) {
2157 event->dev_parent = NULL;
2158 return false;
2159 }
2160 }
2161 }
2162
2163 static int udev_rule_apply_line_to_event(
2164 UdevRules *rules,
2165 UdevEvent *event,
2166 usec_t timeout_usec,
2167 Hashmap *properties_list,
2168 UdevRuleLine **next_line) {
2169
2170 UdevRuleLine *line = rules->current_file->current_line;
2171 UdevRuleLineType mask = LINE_HAS_GOTO | LINE_UPDATE_SOMETHING;
2172 UdevRuleToken *token, *next_token;
2173 bool parents_done = false;
2174 DeviceAction action;
2175 int r;
2176
2177 r = device_get_action(event->dev, &action);
2178 if (r < 0)
2179 return r;
2180
2181 if (action != DEVICE_ACTION_REMOVE) {
2182 if (sd_device_get_devnum(event->dev, NULL) >= 0)
2183 mask |= LINE_HAS_DEVLINK;
2184
2185 if (sd_device_get_ifindex(event->dev, NULL) >= 0)
2186 mask |= LINE_HAS_NAME;
2187 }
2188
2189 if ((line->type & mask) == 0)
2190 return 0;
2191
2192 event->esc = ESCAPE_UNSET;
2193 LIST_FOREACH_SAFE(tokens, token, next_token, line->tokens) {
2194 line->current_token = token;
2195
2196 if (token_is_for_parents(token)) {
2197 if (parents_done)
2198 continue;
2199
2200 r = udev_rule_apply_parent_token_to_event(rules, event);
2201 if (r <= 0)
2202 return r;
2203
2204 parents_done = true;
2205 continue;
2206 }
2207
2208 r = udev_rule_apply_token_to_event(rules, event->dev, event, timeout_usec, properties_list);
2209 if (r <= 0)
2210 return r;
2211 }
2212
2213 if (line->goto_line)
2214 *next_line = line->goto_line;
2215
2216 return 0;
2217 }
2218
2219 int udev_rules_apply_to_event(
2220 UdevRules *rules,
2221 UdevEvent *event,
2222 usec_t timeout_usec,
2223 Hashmap *properties_list) {
2224
2225 UdevRuleFile *file;
2226 UdevRuleLine *next_line;
2227 int r;
2228
2229 assert(rules);
2230 assert(event);
2231
2232 LIST_FOREACH(rule_files, file, rules->rule_files) {
2233 rules->current_file = file;
2234 LIST_FOREACH_SAFE(rule_lines, file->current_line, next_line, file->rule_lines) {
2235 r = udev_rule_apply_line_to_event(rules, event, timeout_usec, properties_list, &next_line);
2236 if (r < 0)
2237 return r;
2238 }
2239 }
2240
2241 return 0;
2242 }
2243
2244 static int apply_static_dev_perms(const char *devnode, uid_t uid, gid_t gid, mode_t mode, char **tags) {
2245 char device_node[UTIL_PATH_SIZE], tags_dir[UTIL_PATH_SIZE], tag_symlink[UTIL_PATH_SIZE];
2246 _cleanup_free_ char *unescaped_filename = NULL;
2247 struct stat stats;
2248 char **t;
2249 int r;
2250
2251 assert(devnode);
2252
2253 if (uid == UID_INVALID && gid == GID_INVALID && mode == MODE_INVALID && !tags)
2254 return 0;
2255
2256 strscpyl(device_node, sizeof(device_node), "/dev/", devnode, NULL);
2257 if (stat(device_node, &stats) < 0) {
2258 if (errno != ENOENT)
2259 return log_error_errno(errno, "Failed to stat %s: %m", device_node);
2260 return 0;
2261 }
2262
2263 if (!S_ISBLK(stats.st_mode) && !S_ISCHR(stats.st_mode)) {
2264 log_warning("%s is neither block nor character device, ignoring.", device_node);
2265 return 0;
2266 }
2267
2268 if (!strv_isempty(tags)) {
2269 unescaped_filename = xescape(devnode, "/.");
2270 if (!unescaped_filename)
2271 return log_oom();
2272 }
2273
2274 /* export the tags to a directory as symlinks, allowing otherwise dead nodes to be tagged */
2275 STRV_FOREACH(t, tags) {
2276 strscpyl(tags_dir, sizeof(tags_dir), "/run/udev/static_node-tags/", *t, "/", NULL);
2277 r = mkdir_p(tags_dir, 0755);
2278 if (r < 0)
2279 return log_error_errno(r, "Failed to create %s: %m", tags_dir);
2280
2281 strscpyl(tag_symlink, sizeof(tag_symlink), tags_dir, unescaped_filename, NULL);
2282 r = symlink(device_node, tag_symlink);
2283 if (r < 0 && errno != EEXIST)
2284 return log_error_errno(errno, "Failed to create symlink %s -> %s: %m",
2285 tag_symlink, device_node);
2286 }
2287
2288 /* don't touch the permissions if only the tags were set */
2289 if (uid == UID_INVALID && gid == GID_INVALID && mode == MODE_INVALID)
2290 return 0;
2291
2292 if (mode == MODE_INVALID)
2293 mode = gid_is_valid(gid) ? 0660 : 0600;
2294 if (!uid_is_valid(uid))
2295 uid = 0;
2296 if (!gid_is_valid(gid))
2297 gid = 0;
2298
2299 r = chmod_and_chown(device_node, mode, uid, gid);
2300 if (r < 0)
2301 return log_error_errno(errno, "Failed to chown '%s' %u %u: %m",
2302 device_node, uid, gid);
2303 else
2304 log_debug("chown '%s' %u:%u", device_node, uid, gid);
2305
2306 (void) utimensat(AT_FDCWD, device_node, NULL, 0);
2307 return 0;
2308 }
2309
2310 static int udev_rule_line_apply_static_dev_perms(UdevRuleLine *rule_line) {
2311 UdevRuleToken *token;
2312 _cleanup_free_ char **tags = NULL;
2313 uid_t uid = UID_INVALID;
2314 gid_t gid = GID_INVALID;
2315 mode_t mode = MODE_INVALID;
2316 int r;
2317
2318 assert(rule_line);
2319
2320 if (!FLAGS_SET(rule_line->type, LINE_HAS_STATIC_NODE))
2321 return 0;
2322
2323 LIST_FOREACH(tokens, token, rule_line->tokens)
2324 if (token->type == TK_A_OWNER_ID)
2325 uid = PTR_TO_UID(token->data);
2326 else if (token->type == TK_A_GROUP_ID)
2327 gid = PTR_TO_GID(token->data);
2328 else if (token->type == TK_A_MODE_ID)
2329 mode = PTR_TO_MODE(token->data);
2330 else if (token->type == TK_A_TAG) {
2331 r = strv_extend(&tags, token->value);
2332 if (r < 0)
2333 return log_oom();
2334 } else if (token->type == TK_A_OPTIONS_STATIC_NODE) {
2335 r = apply_static_dev_perms(token->value, uid, gid, mode, tags);
2336 if (r < 0)
2337 return r;
2338 }
2339
2340 return 0;
2341 }
2342
2343 int udev_rules_apply_static_dev_perms(UdevRules *rules) {
2344 UdevRuleFile *file;
2345 UdevRuleLine *line;
2346 int r;
2347
2348 assert(rules);
2349
2350 LIST_FOREACH(rule_files, file, rules->rule_files)
2351 LIST_FOREACH(rule_lines, line, file->rule_lines) {
2352 r = udev_rule_line_apply_static_dev_perms(line);
2353 if (r < 0)
2354 return r;
2355 }
2356
2357 return 0;
2358 }