chiark / gitweb /
udev: link-config - use new0 instead of calloc
[elogind.git] / src / udev / udev-rules.c
1 /*
2  * Copyright (C) 2003-2012 Kay Sievers <kay@vrfy.org>
3  *
4  * This program is free software: you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License as published by
6  * the Free Software Foundation, either version 2 of the License, or
7  * (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
16  */
17
18 #include <stddef.h>
19 #include <limits.h>
20 #include <stdlib.h>
21 #include <stdbool.h>
22 #include <string.h>
23 #include <stdio.h>
24 #include <fcntl.h>
25 #include <ctype.h>
26 #include <unistd.h>
27 #include <errno.h>
28 #include <dirent.h>
29 #include <fnmatch.h>
30 #include <time.h>
31
32 #include "udev.h"
33 #include "path-util.h"
34 #include "conf-files.h"
35 #include "strbuf.h"
36 #include "strv.h"
37 #include "util.h"
38
39 #define PREALLOC_TOKEN          2048
40
41 struct uid_gid {
42         unsigned int name_off;
43         union {
44                 uid_t uid;
45                 gid_t gid;
46         };
47 };
48
49 struct udev_rules {
50         struct udev *udev;
51         char **dirs;
52         usec_t dirs_ts_usec;
53         int resolve_names;
54
55         /* every key in the rules file becomes a token */
56         struct token *tokens;
57         unsigned int token_cur;
58         unsigned int token_max;
59
60         /* all key strings are copied and de-duplicated in a single continuous string buffer */
61         struct strbuf *strbuf;
62
63         /* during rule parsing, uid/gid lookup results are cached */
64         struct uid_gid *uids;
65         unsigned int uids_cur;
66         unsigned int uids_max;
67         struct uid_gid *gids;
68         unsigned int gids_cur;
69         unsigned int gids_max;
70 };
71
72 static char *rules_str(struct udev_rules *rules, unsigned int off) {
73         return rules->strbuf->buf + off;
74 }
75
76 static unsigned int rules_add_string(struct udev_rules *rules, const char *s) {
77         return strbuf_add_string(rules->strbuf, s, strlen(s));
78 }
79
80 /* KEY=="", KEY!="", KEY+="", KEY="", KEY:="" */
81 enum operation_type {
82         OP_UNSET,
83
84         OP_MATCH,
85         OP_NOMATCH,
86         OP_MATCH_MAX,
87
88         OP_ADD,
89         OP_ASSIGN,
90         OP_ASSIGN_FINAL,
91 };
92
93 enum string_glob_type {
94         GL_UNSET,
95         GL_PLAIN,                       /* no special chars */
96         GL_GLOB,                        /* shell globs ?,*,[] */
97         GL_SPLIT,                       /* multi-value A|B */
98         GL_SPLIT_GLOB,                  /* multi-value with glob A*|B* */
99         GL_SOMETHING,                   /* commonly used "?*" */
100 };
101
102 enum string_subst_type {
103         SB_UNSET,
104         SB_NONE,
105         SB_FORMAT,
106         SB_SUBSYS,
107 };
108
109 /* tokens of a rule are sorted/handled in this order */
110 enum token_type {
111         TK_UNSET,
112         TK_RULE,
113
114         TK_M_ACTION,                    /* val */
115         TK_M_DEVPATH,                   /* val */
116         TK_M_KERNEL,                    /* val */
117         TK_M_DEVLINK,                   /* val */
118         TK_M_NAME,                      /* val */
119         TK_M_ENV,                       /* val, attr */
120         TK_M_TAG,                       /* val */
121         TK_M_SUBSYSTEM,                 /* val */
122         TK_M_DRIVER,                    /* val */
123         TK_M_WAITFOR,                   /* val */
124         TK_M_ATTR,                      /* val, attr */
125
126         TK_M_PARENTS_MIN,
127         TK_M_KERNELS,                   /* val */
128         TK_M_SUBSYSTEMS,                /* val */
129         TK_M_DRIVERS,                   /* val */
130         TK_M_ATTRS,                     /* val, attr */
131         TK_M_TAGS,                      /* val */
132         TK_M_PARENTS_MAX,
133
134         TK_M_TEST,                      /* val, mode_t */
135         TK_M_EVENT_TIMEOUT,             /* int */
136         TK_M_PROGRAM,                   /* val */
137         TK_M_IMPORT_FILE,               /* val */
138         TK_M_IMPORT_PROG,               /* val */
139         TK_M_IMPORT_BUILTIN,            /* val */
140         TK_M_IMPORT_DB,                 /* val */
141         TK_M_IMPORT_CMDLINE,            /* val */
142         TK_M_IMPORT_PARENT,             /* val */
143         TK_M_RESULT,                    /* val */
144         TK_M_MAX,
145
146         TK_A_STRING_ESCAPE_NONE,
147         TK_A_STRING_ESCAPE_REPLACE,
148         TK_A_DB_PERSIST,
149         TK_A_INOTIFY_WATCH,             /* int */
150         TK_A_DEVLINK_PRIO,              /* int */
151         TK_A_OWNER,                     /* val */
152         TK_A_GROUP,                     /* val */
153         TK_A_MODE,                      /* val */
154         TK_A_OWNER_ID,                  /* uid_t */
155         TK_A_GROUP_ID,                  /* gid_t */
156         TK_A_MODE_ID,                   /* mode_t */
157         TK_A_TAG,                       /* val */
158         TK_A_STATIC_NODE,               /* val */
159         TK_A_SECLABEL,                  /* val, attr */
160         TK_A_ENV,                       /* val, attr */
161         TK_A_NAME,                      /* val */
162         TK_A_DEVLINK,                   /* val */
163         TK_A_ATTR,                      /* val, attr */
164         TK_A_RUN_BUILTIN,               /* val, bool */
165         TK_A_RUN_PROGRAM,               /* val, bool */
166         TK_A_GOTO,                      /* size_t */
167
168         TK_END,
169 };
170
171 /* we try to pack stuff in a way that we take only 12 bytes per token */
172 struct token {
173         union {
174                 unsigned char type;                /* same in rule and key */
175                 struct {
176                         enum token_type type:8;
177                         bool can_set_name:1;
178                         bool has_static_node:1;
179                         unsigned int unused:6;
180                         unsigned short token_count;
181                         unsigned int label_off;
182                         unsigned short filename_off;
183                         unsigned short filename_line;
184                 } rule;
185                 struct {
186                         enum token_type type:8;
187                         enum operation_type op:8;
188                         enum string_glob_type glob:8;
189                         enum string_subst_type subst:4;
190                         enum string_subst_type attrsubst:4;
191                         unsigned int value_off;
192                         union {
193                                 unsigned int attr_off;
194                                 unsigned int rule_goto;
195                                 mode_t  mode;
196                                 uid_t uid;
197                                 gid_t gid;
198                                 int devlink_prio;
199                                 int event_timeout;
200                                 int watch;
201                                 enum udev_builtin_cmd builtin_cmd;
202                         };
203                 } key;
204         };
205 };
206
207 #define MAX_TK                64
208 struct rule_tmp {
209         struct udev_rules *rules;
210         struct token rule;
211         struct token token[MAX_TK];
212         unsigned int token_cur;
213 };
214
215 #ifdef DEBUG
216 static const char *operation_str(enum operation_type type)
217 {
218         static const char *operation_strs[] = {
219                 [OP_UNSET] =            "UNSET",
220                 [OP_MATCH] =            "match",
221                 [OP_NOMATCH] =          "nomatch",
222                 [OP_MATCH_MAX] =        "MATCH_MAX",
223
224                 [OP_ADD] =              "add",
225                 [OP_ASSIGN] =           "assign",
226                 [OP_ASSIGN_FINAL] =     "assign-final",
227 }        ;
228
229         return operation_strs[type];
230 }
231
232 static const char *string_glob_str(enum string_glob_type type)
233 {
234         static const char *string_glob_strs[] = {
235                 [GL_UNSET] =            "UNSET",
236                 [GL_PLAIN] =            "plain",
237                 [GL_GLOB] =             "glob",
238                 [GL_SPLIT] =            "split",
239                 [GL_SPLIT_GLOB] =       "split-glob",
240                 [GL_SOMETHING] =        "split-glob",
241         };
242
243         return string_glob_strs[type];
244 }
245
246 static const char *token_str(enum token_type type)
247 {
248         static const char *token_strs[] = {
249                 [TK_UNSET] =                    "UNSET",
250                 [TK_RULE] =                     "RULE",
251
252                 [TK_M_ACTION] =                 "M ACTION",
253                 [TK_M_DEVPATH] =                "M DEVPATH",
254                 [TK_M_KERNEL] =                 "M KERNEL",
255                 [TK_M_DEVLINK] =                "M DEVLINK",
256                 [TK_M_NAME] =                   "M NAME",
257                 [TK_M_ENV] =                    "M ENV",
258                 [TK_M_TAG] =                    "M TAG",
259                 [TK_M_SUBSYSTEM] =              "M SUBSYSTEM",
260                 [TK_M_DRIVER] =                 "M DRIVER",
261                 [TK_M_WAITFOR] =                "M WAITFOR",
262                 [TK_M_ATTR] =                   "M ATTR",
263
264                 [TK_M_PARENTS_MIN] =            "M PARENTS_MIN",
265                 [TK_M_KERNELS] =                "M KERNELS",
266                 [TK_M_SUBSYSTEMS] =             "M SUBSYSTEMS",
267                 [TK_M_DRIVERS] =                "M DRIVERS",
268                 [TK_M_ATTRS] =                  "M ATTRS",
269                 [TK_M_TAGS] =                   "M TAGS",
270                 [TK_M_PARENTS_MAX] =            "M PARENTS_MAX",
271
272                 [TK_M_TEST] =                   "M TEST",
273                 [TK_M_EVENT_TIMEOUT] =          "M EVENT_TIMEOUT",
274                 [TK_M_PROGRAM] =                "M PROGRAM",
275                 [TK_M_IMPORT_FILE] =            "M IMPORT_FILE",
276                 [TK_M_IMPORT_PROG] =            "M IMPORT_PROG",
277                 [TK_M_IMPORT_BUILTIN] =         "M IMPORT_BUILTIN",
278                 [TK_M_IMPORT_DB] =              "M IMPORT_DB",
279                 [TK_M_IMPORT_CMDLINE] =         "M IMPORT_CMDLINE",
280                 [TK_M_IMPORT_PARENT] =          "M IMPORT_PARENT",
281                 [TK_M_RESULT] =                 "M RESULT",
282                 [TK_M_MAX] =                    "M MAX",
283
284                 [TK_A_STRING_ESCAPE_NONE] =     "A STRING_ESCAPE_NONE",
285                 [TK_A_STRING_ESCAPE_REPLACE] =  "A STRING_ESCAPE_REPLACE",
286                 [TK_A_DB_PERSIST] =             "A DB_PERSIST",
287                 [TK_A_INOTIFY_WATCH] =          "A INOTIFY_WATCH",
288                 [TK_A_DEVLINK_PRIO] =           "A DEVLINK_PRIO",
289                 [TK_A_OWNER] =                  "A OWNER",
290                 [TK_A_GROUP] =                  "A GROUP",
291                 [TK_A_MODE] =                   "A MODE",
292                 [TK_A_OWNER_ID] =               "A OWNER_ID",
293                 [TK_A_GROUP_ID] =               "A GROUP_ID",
294                 [TK_A_STATIC_NODE] =            "A STATIC_NODE",
295                 [TK_A_SECLABEL] =               "A SECLABEL",
296                 [TK_A_MODE_ID] =                "A MODE_ID",
297                 [TK_A_ENV] =                    "A ENV",
298                 [TK_A_TAG] =                    "A ENV",
299                 [TK_A_NAME] =                   "A NAME",
300                 [TK_A_DEVLINK] =                "A DEVLINK",
301                 [TK_A_ATTR] =                   "A ATTR",
302                 [TK_A_RUN_BUILTIN] =            "A RUN_BUILTIN",
303                 [TK_A_RUN_PROGRAM] =            "A RUN_PROGRAM",
304                 [TK_A_GOTO] =                   "A GOTO",
305
306                 [TK_END] =                      "END",
307         };
308
309         return token_strs[type];
310 }
311
312 static void dump_token(struct udev_rules *rules, struct token *token)
313 {
314         enum token_type type = token->type;
315         enum operation_type op = token->key.op;
316         enum string_glob_type glob = token->key.glob;
317         const char *value = str(rules, token->key.value_off);
318         const char *attr = &rules->buf[token->key.attr_off];
319
320         switch (type) {
321         case TK_RULE:
322                 {
323                         const char *tks_ptr = (char *)rules->tokens;
324                         const char *tk_ptr = (char *)token;
325                         unsigned int idx = (tk_ptr - tks_ptr) / sizeof(struct token);
326
327                         log_debug("* RULE %s:%u, token: %u, count: %u, label: '%s'\n",
328                                   &rules->buf[token->rule.filename_off], token->rule.filename_line,
329                                   idx, token->rule.token_count,
330                                   &rules->buf[token->rule.label_off]);
331                         break;
332                 }
333         case TK_M_ACTION:
334         case TK_M_DEVPATH:
335         case TK_M_KERNEL:
336         case TK_M_SUBSYSTEM:
337         case TK_M_DRIVER:
338         case TK_M_WAITFOR:
339         case TK_M_DEVLINK:
340         case TK_M_NAME:
341         case TK_M_KERNELS:
342         case TK_M_SUBSYSTEMS:
343         case TK_M_DRIVERS:
344         case TK_M_TAGS:
345         case TK_M_PROGRAM:
346         case TK_M_IMPORT_FILE:
347         case TK_M_IMPORT_PROG:
348         case TK_M_IMPORT_DB:
349         case TK_M_IMPORT_CMDLINE:
350         case TK_M_IMPORT_PARENT:
351         case TK_M_RESULT:
352         case TK_A_NAME:
353         case TK_A_DEVLINK:
354         case TK_A_OWNER:
355         case TK_A_GROUP:
356         case TK_A_MODE:
357         case TK_A_RUN_BUILTIN:
358         case TK_A_RUN_PROGRAM:
359                 log_debug("%s %s '%s'(%s)\n",
360                           token_str(type), operation_str(op), value, string_glob_str(glob));
361                 break;
362         case TK_M_IMPORT_BUILTIN:
363                 log_debug("%s %i '%s'\n", token_str(type), token->key.builtin_cmd, value);
364                 break;
365         case TK_M_ATTR:
366         case TK_M_ATTRS:
367         case TK_M_ENV:
368         case TK_A_ATTR:
369         case TK_A_ENV:
370                 log_debug("%s %s '%s' '%s'(%s)\n",
371                           token_str(type), operation_str(op), attr, value, string_glob_str(glob));
372                 break;
373         case TK_M_TAG:
374         case TK_A_TAG:
375                 log_debug("%s %s '%s'\n", token_str(type), operation_str(op), value);
376                 break;
377         case TK_A_STRING_ESCAPE_NONE:
378         case TK_A_STRING_ESCAPE_REPLACE:
379         case TK_A_DB_PERSIST:
380                 log_debug("%s\n", token_str(type));
381                 break;
382         case TK_M_TEST:
383                 log_debug("%s %s '%s'(%s) %#o\n",
384                           token_str(type), operation_str(op), value, string_glob_str(glob), token->key.mode);
385                 break;
386         case TK_A_INOTIFY_WATCH:
387                 log_debug("%s %u\n", token_str(type), token->key.watch);
388                 break;
389         case TK_A_DEVLINK_PRIO:
390                 log_debug("%s %u\n", token_str(type), token->key.devlink_prio);
391                 break;
392         case TK_A_OWNER_ID:
393                 log_debug("%s %s %u\n", token_str(type), operation_str(op), token->key.uid);
394                 break;
395         case TK_A_GROUP_ID:
396                 log_debug("%s %s %u\n", token_str(type), operation_str(op), token->key.gid);
397                 break;
398         case TK_A_MODE_ID:
399                 log_debug("%s %s %#o\n", token_str(type), operation_str(op), token->key.mode);
400                 break;
401         case TK_A_STATIC_NODE:
402                 log_debug("%s '%s'\n", token_str(type), value);
403                 break;
404         case TK_A_SECLABEL:
405                 log_debug("%s %s '%s' '%s'\n", token_str(type), operation_str(op), attr, value);
406                 break;
407         case TK_M_EVENT_TIMEOUT:
408                 log_debug("%s %u\n", token_str(type), token->key.event_timeout);
409                 break;
410         case TK_A_GOTO:
411                 log_debug("%s '%s' %u\n", token_str(type), value, token->key.rule_goto);
412                 break;
413         case TK_END:
414                 log_debug("* %s\n", token_str(type));
415                 break;
416         case TK_M_PARENTS_MIN:
417         case TK_M_PARENTS_MAX:
418         case TK_M_MAX:
419         case TK_UNSET:
420                 log_debug("unknown type %u\n", type);
421                 break;
422         }
423 }
424
425 static void dump_rules(struct udev_rules *rules)
426 {
427         unsigned int i;
428
429         log_debug("dumping %u (%zu bytes) tokens, %u (%zu bytes) strings\n",
430                   rules->token_cur,
431                   rules->token_cur * sizeof(struct token),
432                   rules->buf_count,
433                   rules->buf_cur);
434         for(i = 0; i < rules->token_cur; i++)
435                 dump_token(rules, &rules->tokens[i]);
436 }
437 #else
438 static inline const char *operation_str(enum operation_type type) { return NULL; }
439 static inline const char *token_str(enum token_type type) { return NULL; }
440 static inline void dump_token(struct udev_rules *rules, struct token *token) {}
441 static inline void dump_rules(struct udev_rules *rules) {}
442 #endif /* DEBUG */
443
444 static int add_token(struct udev_rules *rules, struct token *token)
445 {
446         /* grow buffer if needed */
447         if (rules->token_cur+1 >= rules->token_max) {
448                 struct token *tokens;
449                 unsigned int add;
450
451                 /* double the buffer size */
452                 add = rules->token_max;
453                 if (add < 8)
454                         add = 8;
455
456                 tokens = realloc(rules->tokens, (rules->token_max + add ) * sizeof(struct token));
457                 if (tokens == NULL)
458                         return -1;
459                 rules->tokens = tokens;
460                 rules->token_max += add;
461         }
462         memcpy(&rules->tokens[rules->token_cur], token, sizeof(struct token));
463         rules->token_cur++;
464         return 0;
465 }
466
467 static uid_t add_uid(struct udev_rules *rules, const char *owner)
468 {
469         unsigned int i;
470         uid_t uid;
471         unsigned int off;
472
473         /* lookup, if we know it already */
474         for (i = 0; i < rules->uids_cur; i++) {
475                 off = rules->uids[i].name_off;
476                 if (streq(rules_str(rules, off), owner)) {
477                         uid = rules->uids[i].uid;
478                         return uid;
479                 }
480         }
481         uid = util_lookup_user(rules->udev, owner);
482
483         /* grow buffer if needed */
484         if (rules->uids_cur+1 >= rules->uids_max) {
485                 struct uid_gid *uids;
486                 unsigned int add;
487
488                 /* double the buffer size */
489                 add = rules->uids_max;
490                 if (add < 1)
491                         add = 8;
492
493                 uids = realloc(rules->uids, (rules->uids_max + add ) * sizeof(struct uid_gid));
494                 if (uids == NULL)
495                         return uid;
496                 rules->uids = uids;
497                 rules->uids_max += add;
498         }
499         rules->uids[rules->uids_cur].uid = uid;
500         off = rules_add_string(rules, owner);
501         if (off <= 0)
502                 return uid;
503         rules->uids[rules->uids_cur].name_off = off;
504         rules->uids_cur++;
505         return uid;
506 }
507
508 static gid_t add_gid(struct udev_rules *rules, const char *group)
509 {
510         unsigned int i;
511         gid_t gid;
512         unsigned int off;
513
514         /* lookup, if we know it already */
515         for (i = 0; i < rules->gids_cur; i++) {
516                 off = rules->gids[i].name_off;
517                 if (streq(rules_str(rules, off), group)) {
518                         gid = rules->gids[i].gid;
519                         return gid;
520                 }
521         }
522         gid = util_lookup_group(rules->udev, group);
523
524         /* grow buffer if needed */
525         if (rules->gids_cur+1 >= rules->gids_max) {
526                 struct uid_gid *gids;
527                 unsigned int add;
528
529                 /* double the buffer size */
530                 add = rules->gids_max;
531                 if (add < 1)
532                         add = 8;
533
534                 gids = realloc(rules->gids, (rules->gids_max + add ) * sizeof(struct uid_gid));
535                 if (gids == NULL)
536                         return gid;
537                 rules->gids = gids;
538                 rules->gids_max += add;
539         }
540         rules->gids[rules->gids_cur].gid = gid;
541         off = rules_add_string(rules, group);
542         if (off <= 0)
543                 return gid;
544         rules->gids[rules->gids_cur].name_off = off;
545         rules->gids_cur++;
546         return gid;
547 }
548
549 static int import_property_from_string(struct udev_device *dev, char *line)
550 {
551         char *key;
552         char *val;
553         size_t len;
554
555         /* find key */
556         key = line;
557         while (isspace(key[0]))
558                 key++;
559
560         /* comment or empty line */
561         if (key[0] == '#' || key[0] == '\0')
562                 return -1;
563
564         /* split key/value */
565         val = strchr(key, '=');
566         if (val == NULL)
567                 return -1;
568         val[0] = '\0';
569         val++;
570
571         /* find value */
572         while (isspace(val[0]))
573                 val++;
574
575         /* terminate key */
576         len = strlen(key);
577         if (len == 0)
578                 return -1;
579         while (isspace(key[len-1]))
580                 len--;
581         key[len] = '\0';
582
583         /* terminate value */
584         len = strlen(val);
585         if (len == 0)
586                 return -1;
587         while (isspace(val[len-1]))
588                 len--;
589         val[len] = '\0';
590
591         if (len == 0)
592                 return -1;
593
594         /* unquote */
595         if (val[0] == '"' || val[0] == '\'') {
596                 if (val[len-1] != val[0]) {
597                         log_debug("inconsistent quoting: '%s', skip\n", line);
598                         return -1;
599                 }
600                 val[len-1] = '\0';
601                 val++;
602         }
603
604         /* handle device, renamed by external tool, returning new path */
605         if (streq(key, "DEVPATH")) {
606                 char syspath[UTIL_PATH_SIZE];
607
608                 log_debug("updating devpath from '%s' to '%s'\n",
609                           udev_device_get_devpath(dev), val);
610                 strscpyl(syspath, sizeof(syspath), "/sys", val, NULL);
611                 udev_device_set_syspath(dev, syspath);
612         } else {
613                 struct udev_list_entry *entry;
614
615                 entry = udev_device_add_property(dev, key, val);
616                 /* store in db, skip private keys */
617                 if (key[0] != '.')
618                         udev_list_entry_set_num(entry, true);
619         }
620         return 0;
621 }
622
623 static int import_file_into_properties(struct udev_device *dev, const char *filename)
624 {
625         FILE *f;
626         char line[UTIL_LINE_SIZE];
627
628         f = fopen(filename, "re");
629         if (f == NULL)
630                 return -1;
631         while (fgets(line, sizeof(line), f) != NULL)
632                 import_property_from_string(dev, line);
633         fclose(f);
634         return 0;
635 }
636
637 static int import_program_into_properties(struct udev_event *event, const char *program, const sigset_t *sigmask)
638 {
639         struct udev_device *dev = event->dev;
640         char **envp;
641         char result[UTIL_LINE_SIZE];
642         char *line;
643         int err;
644
645         envp = udev_device_get_properties_envp(dev);
646         err = udev_event_spawn(event, program, envp, sigmask, result, sizeof(result));
647         if (err < 0)
648                 return err;
649
650         line = result;
651         while (line != NULL) {
652                 char *pos;
653
654                 pos = strchr(line, '\n');
655                 if (pos != NULL) {
656                         pos[0] = '\0';
657                         pos = &pos[1];
658                 }
659                 import_property_from_string(dev, line);
660                 line = pos;
661         }
662         return 0;
663 }
664
665 static int import_parent_into_properties(struct udev_device *dev, const char *filter)
666 {
667         struct udev_device *dev_parent;
668         struct udev_list_entry *list_entry;
669
670         dev_parent = udev_device_get_parent(dev);
671         if (dev_parent == NULL)
672                 return -1;
673
674         udev_list_entry_foreach(list_entry, udev_device_get_properties_list_entry(dev_parent)) {
675                 const char *key = udev_list_entry_get_name(list_entry);
676                 const char *val = udev_list_entry_get_value(list_entry);
677
678                 if (fnmatch(filter, key, 0) == 0) {
679                         struct udev_list_entry *entry;
680
681                         entry = udev_device_add_property(dev, key, val);
682                         /* store in db, skip private keys */
683                         if (key[0] != '.')
684                                 udev_list_entry_set_num(entry, true);
685                 }
686         }
687         return 0;
688 }
689
690 #define WAIT_LOOP_PER_SECOND                50
691 static int wait_for_file(struct udev_device *dev, const char *file, int timeout)
692 {
693         char filepath[UTIL_PATH_SIZE];
694         char devicepath[UTIL_PATH_SIZE];
695         struct stat stats;
696         int loop = timeout * WAIT_LOOP_PER_SECOND;
697
698         /* a relative path is a device attribute */
699         devicepath[0] = '\0';
700         if (file[0] != '/') {
701                 strscpyl(devicepath, sizeof(devicepath), udev_device_get_syspath(dev), NULL);
702                 strscpyl(filepath, sizeof(filepath), devicepath, "/", file, NULL);
703                 file = filepath;
704         }
705
706         while (--loop) {
707                 const struct timespec duration = { 0, 1000 * 1000 * 1000 / WAIT_LOOP_PER_SECOND };
708
709                 /* lookup file */
710                 if (stat(file, &stats) == 0) {
711                         log_debug("file '%s' appeared after %i loops\n", file, (timeout * WAIT_LOOP_PER_SECOND) - loop-1);
712                         return 0;
713                 }
714                 /* make sure, the device did not disappear in the meantime */
715                 if (devicepath[0] != '\0' && stat(devicepath, &stats) != 0) {
716                         log_debug("device disappeared while waiting for '%s'\n", file);
717                         return -2;
718                 }
719                 log_debug("wait for '%s' for %i mseconds\n", file, 1000 / WAIT_LOOP_PER_SECOND);
720                 nanosleep(&duration, NULL);
721         }
722         log_debug("waiting for '%s' failed\n", file);
723         return -1;
724 }
725
726 static int attr_subst_subdir(char *attr, size_t len)
727 {
728         bool found = false;
729
730         if (strstr(attr, "/*/")) {
731                 char *pos;
732                 char dirname[UTIL_PATH_SIZE];
733                 const char *tail;
734                 DIR *dir;
735
736                 strscpy(dirname, sizeof(dirname), attr);
737                 pos = strstr(dirname, "/*/");
738                 if (pos == NULL)
739                         return -1;
740                 pos[0] = '\0';
741                 tail = &pos[2];
742                 dir = opendir(dirname);
743                 if (dir != NULL) {
744                         struct dirent *dent;
745
746                         for (dent = readdir(dir); dent != NULL; dent = readdir(dir)) {
747                                 struct stat stats;
748
749                                 if (dent->d_name[0] == '.')
750                                         continue;
751                                 strscpyl(attr, len, dirname, "/", dent->d_name, tail, NULL);
752                                 if (stat(attr, &stats) == 0) {
753                                         found = true;
754                                         break;
755                                 }
756                         }
757                         closedir(dir);
758                 }
759         }
760
761         return found;
762 }
763
764 static int get_key(struct udev *udev, char **line, char **key, enum operation_type *op, char **value)
765 {
766         char *linepos;
767         char *temp;
768
769         linepos = *line;
770         if (linepos == NULL || linepos[0] == '\0')
771                 return -1;
772
773         /* skip whitespace */
774         while (isspace(linepos[0]) || linepos[0] == ',')
775                 linepos++;
776
777         /* get the key */
778         if (linepos[0] == '\0')
779                 return -1;
780         *key = linepos;
781
782         for (;;) {
783                 linepos++;
784                 if (linepos[0] == '\0')
785                         return -1;
786                 if (isspace(linepos[0]))
787                         break;
788                 if (linepos[0] == '=')
789                         break;
790                 if ((linepos[0] == '+') || (linepos[0] == '!') || (linepos[0] == ':'))
791                         if (linepos[1] == '=')
792                                 break;
793         }
794
795         /* remember end of key */
796         temp = linepos;
797
798         /* skip whitespace after key */
799         while (isspace(linepos[0]))
800                 linepos++;
801         if (linepos[0] == '\0')
802                 return -1;
803
804         /* get operation type */
805         if (linepos[0] == '=' && linepos[1] == '=') {
806                 *op = OP_MATCH;
807                 linepos += 2;
808         } else if (linepos[0] == '!' && linepos[1] == '=') {
809                 *op = OP_NOMATCH;
810                 linepos += 2;
811         } else if (linepos[0] == '+' && linepos[1] == '=') {
812                 *op = OP_ADD;
813                 linepos += 2;
814         } else if (linepos[0] == '=') {
815                 *op = OP_ASSIGN;
816                 linepos++;
817         } else if (linepos[0] == ':' && linepos[1] == '=') {
818                 *op = OP_ASSIGN_FINAL;
819                 linepos += 2;
820         } else
821                 return -1;
822
823         /* terminate key */
824         temp[0] = '\0';
825
826         /* skip whitespace after operator */
827         while (isspace(linepos[0]))
828                 linepos++;
829         if (linepos[0] == '\0')
830                 return -1;
831
832         /* get the value */
833         if (linepos[0] == '"')
834                 linepos++;
835         else
836                 return -1;
837         *value = linepos;
838
839         /* terminate */
840         temp = strchr(linepos, '"');
841         if (!temp)
842                 return -1;
843         temp[0] = '\0';
844         temp++;
845
846         /* move line to next key */
847         *line = temp;
848         return 0;
849 }
850
851 /* extract possible KEY{attr} */
852 static const char *get_key_attribute(struct udev *udev, char *str)
853 {
854         char *pos;
855         char *attr;
856
857         attr = strchr(str, '{');
858         if (attr != NULL) {
859                 attr++;
860                 pos = strchr(attr, '}');
861                 if (pos == NULL) {
862                         log_error("missing closing brace for format\n");
863                         return NULL;
864                 }
865                 pos[0] = '\0';
866                 return attr;
867         }
868         return NULL;
869 }
870
871 static int rule_add_key(struct rule_tmp *rule_tmp, enum token_type type,
872                         enum operation_type op,
873                         const char *value, const void *data)
874 {
875         struct token *token = &rule_tmp->token[rule_tmp->token_cur];
876         const char *attr = NULL;
877
878         memset(token, 0x00, sizeof(struct token));
879
880         switch (type) {
881         case TK_M_ACTION:
882         case TK_M_DEVPATH:
883         case TK_M_KERNEL:
884         case TK_M_SUBSYSTEM:
885         case TK_M_DRIVER:
886         case TK_M_WAITFOR:
887         case TK_M_DEVLINK:
888         case TK_M_NAME:
889         case TK_M_KERNELS:
890         case TK_M_SUBSYSTEMS:
891         case TK_M_DRIVERS:
892         case TK_M_TAGS:
893         case TK_M_PROGRAM:
894         case TK_M_IMPORT_FILE:
895         case TK_M_IMPORT_PROG:
896         case TK_M_IMPORT_DB:
897         case TK_M_IMPORT_CMDLINE:
898         case TK_M_IMPORT_PARENT:
899         case TK_M_RESULT:
900         case TK_A_OWNER:
901         case TK_A_GROUP:
902         case TK_A_MODE:
903         case TK_A_DEVLINK:
904         case TK_A_NAME:
905         case TK_A_GOTO:
906         case TK_M_TAG:
907         case TK_A_TAG:
908                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
909                 break;
910         case TK_M_IMPORT_BUILTIN:
911                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
912                 token->key.builtin_cmd = *(enum udev_builtin_cmd *)data;
913                 break;
914         case TK_M_ENV:
915         case TK_M_ATTR:
916         case TK_M_ATTRS:
917         case TK_A_ATTR:
918         case TK_A_ENV:
919         case TK_A_SECLABEL:
920                 attr = data;
921                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
922                 token->key.attr_off = rules_add_string(rule_tmp->rules, attr);
923                 break;
924         case TK_M_TEST:
925                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
926                 if (data != NULL)
927                         token->key.mode = *(mode_t *)data;
928                 break;
929         case TK_A_STRING_ESCAPE_NONE:
930         case TK_A_STRING_ESCAPE_REPLACE:
931         case TK_A_DB_PERSIST:
932                 break;
933         case TK_A_RUN_BUILTIN:
934         case TK_A_RUN_PROGRAM:
935                 token->key.builtin_cmd = *(enum udev_builtin_cmd *)data;
936                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
937                 break;
938         case TK_A_INOTIFY_WATCH:
939         case TK_A_DEVLINK_PRIO:
940                 token->key.devlink_prio = *(int *)data;
941                 break;
942         case TK_A_OWNER_ID:
943                 token->key.uid = *(uid_t *)data;
944                 break;
945         case TK_A_GROUP_ID:
946                 token->key.gid = *(gid_t *)data;
947                 break;
948         case TK_A_MODE_ID:
949                 token->key.mode = *(mode_t *)data;
950                 break;
951         case TK_A_STATIC_NODE:
952                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
953                 break;
954         case TK_M_EVENT_TIMEOUT:
955                 token->key.event_timeout = *(int *)data;
956                 break;
957         case TK_RULE:
958         case TK_M_PARENTS_MIN:
959         case TK_M_PARENTS_MAX:
960         case TK_M_MAX:
961         case TK_END:
962         case TK_UNSET:
963                 log_error("wrong type %u\n", type);
964                 return -1;
965         }
966
967         if (value != NULL && type < TK_M_MAX) {
968                 /* check if we need to split or call fnmatch() while matching rules */
969                 enum string_glob_type glob;
970                 int has_split;
971                 int has_glob;
972
973                 has_split = (strchr(value, '|') != NULL);
974                 has_glob = (strchr(value, '*') != NULL || strchr(value, '?') != NULL || strchr(value, '[') != NULL);
975                 if (has_split && has_glob) {
976                         glob = GL_SPLIT_GLOB;
977                 } else if (has_split) {
978                         glob = GL_SPLIT;
979                 } else if (has_glob) {
980                         if (streq(value, "?*"))
981                                 glob = GL_SOMETHING;
982                         else
983                                 glob = GL_GLOB;
984                 } else {
985                         glob = GL_PLAIN;
986                 }
987                 token->key.glob = glob;
988         }
989
990         if (value != NULL && type > TK_M_MAX) {
991                 /* check if assigned value has substitution chars */
992                 if (value[0] == '[')
993                         token->key.subst = SB_SUBSYS;
994                 else if (strchr(value, '%') != NULL || strchr(value, '$') != NULL)
995                         token->key.subst = SB_FORMAT;
996                 else
997                         token->key.subst = SB_NONE;
998         }
999
1000         if (attr != NULL) {
1001                 /* check if property/attribut name has substitution chars */
1002                 if (attr[0] == '[')
1003                         token->key.attrsubst = SB_SUBSYS;
1004                 else if (strchr(attr, '%') != NULL || strchr(attr, '$') != NULL)
1005                         token->key.attrsubst = SB_FORMAT;
1006                 else
1007                         token->key.attrsubst = SB_NONE;
1008         }
1009
1010         token->key.type = type;
1011         token->key.op = op;
1012         rule_tmp->token_cur++;
1013         if (rule_tmp->token_cur >= ELEMENTSOF(rule_tmp->token)) {
1014                 log_error("temporary rule array too small\n");
1015                 return -1;
1016         }
1017         return 0;
1018 }
1019
1020 static int sort_token(struct udev_rules *rules, struct rule_tmp *rule_tmp)
1021 {
1022         unsigned int i;
1023         unsigned int start = 0;
1024         unsigned int end = rule_tmp->token_cur;
1025
1026         for (i = 0; i < rule_tmp->token_cur; i++) {
1027                 enum token_type next_val = TK_UNSET;
1028                 unsigned int next_idx = 0;
1029                 unsigned int j;
1030
1031                 /* find smallest value */
1032                 for (j = start; j < end; j++) {
1033                         if (rule_tmp->token[j].type == TK_UNSET)
1034                                 continue;
1035                         if (next_val == TK_UNSET || rule_tmp->token[j].type < next_val) {
1036                                 next_val = rule_tmp->token[j].type;
1037                                 next_idx = j;
1038                         }
1039                 }
1040
1041                 /* add token and mark done */
1042                 if (add_token(rules, &rule_tmp->token[next_idx]) != 0)
1043                         return -1;
1044                 rule_tmp->token[next_idx].type = TK_UNSET;
1045
1046                 /* shrink range */
1047                 if (next_idx == start)
1048                         start++;
1049                 if (next_idx+1 == end)
1050                         end--;
1051         }
1052         return 0;
1053 }
1054
1055 static int add_rule(struct udev_rules *rules, char *line,
1056                     const char *filename, unsigned int filename_off, unsigned int lineno)
1057 {
1058         char *linepos;
1059         const char *attr;
1060         struct rule_tmp rule_tmp;
1061
1062         memset(&rule_tmp, 0x00, sizeof(struct rule_tmp));
1063         rule_tmp.rules = rules;
1064         rule_tmp.rule.type = TK_RULE;
1065         /* the offset in the rule is limited to unsigned short */
1066         if (filename_off < USHRT_MAX)
1067                 rule_tmp.rule.rule.filename_off = filename_off;
1068         rule_tmp.rule.rule.filename_line = lineno;
1069
1070         linepos = line;
1071         for (;;) {
1072                 char *key;
1073                 char *value;
1074                 enum operation_type op;
1075
1076                 if (get_key(rules->udev, &linepos, &key, &op, &value) != 0) {
1077                         /* Avoid erroring on trailing whitespace. This is probably rare
1078                          * so save the work for the error case instead of always trying
1079                          * to strip the trailing whitespace with strstrip(). */
1080                         while (isblank(*linepos))
1081                                 linepos++;
1082
1083                         /* If we aren't at the end of the line, this is a parsing error.
1084                          * Make a best effort to describe where the problem is. */
1085                         if (*linepos != '\n') {
1086                                 char buf[2] = {linepos[1]};
1087                                 _cleanup_free_ char *tmp;
1088
1089                                 tmp = cescape(buf);
1090                                 log_error("invalid key/value pair in file %s on line %u,"
1091                                           "starting at character %tu ('%s')\n",
1092                                           filename, lineno, linepos - line + 1, tmp);
1093                                 if (linepos[1] == '#')
1094                                         log_info("hint: comments can only start at beginning of line");
1095                         }
1096                         break;
1097                 }
1098
1099                 if (streq(key, "ACTION")) {
1100                         if (op > OP_MATCH_MAX) {
1101                                 log_error("invalid ACTION operation\n");
1102                                 goto invalid;
1103                         }
1104                         rule_add_key(&rule_tmp, TK_M_ACTION, op, value, NULL);
1105                         continue;
1106                 }
1107
1108                 if (streq(key, "DEVPATH")) {
1109                         if (op > OP_MATCH_MAX) {
1110                                 log_error("invalid DEVPATH operation\n");
1111                                 goto invalid;
1112                         }
1113                         rule_add_key(&rule_tmp, TK_M_DEVPATH, op, value, NULL);
1114                         continue;
1115                 }
1116
1117                 if (streq(key, "KERNEL")) {
1118                         if (op > OP_MATCH_MAX) {
1119                                 log_error("invalid KERNEL operation\n");
1120                                 goto invalid;
1121                         }
1122                         rule_add_key(&rule_tmp, TK_M_KERNEL, op, value, NULL);
1123                         continue;
1124                 }
1125
1126                 if (streq(key, "SUBSYSTEM")) {
1127                         if (op > OP_MATCH_MAX) {
1128                                 log_error("invalid SUBSYSTEM operation\n");
1129                                 goto invalid;
1130                         }
1131                         /* bus, class, subsystem events should all be the same */
1132                         if (streq(value, "subsystem") ||
1133                             streq(value, "bus") ||
1134                             streq(value, "class")) {
1135                                 if (streq(value, "bus") || streq(value, "class"))
1136                                         log_error("'%s' must be specified as 'subsystem' \n"
1137                                             "please fix it in %s:%u", value, filename, lineno);
1138                                 rule_add_key(&rule_tmp, TK_M_SUBSYSTEM, op, "subsystem|class|bus", NULL);
1139                         } else
1140                                 rule_add_key(&rule_tmp, TK_M_SUBSYSTEM, op, value, NULL);
1141                         continue;
1142                 }
1143
1144                 if (streq(key, "DRIVER")) {
1145                         if (op > OP_MATCH_MAX) {
1146                                 log_error("invalid DRIVER operation\n");
1147                                 goto invalid;
1148                         }
1149                         rule_add_key(&rule_tmp, TK_M_DRIVER, op, value, NULL);
1150                         continue;
1151                 }
1152
1153                 if (startswith(key, "ATTR{")) {
1154                         attr = get_key_attribute(rules->udev, key + sizeof("ATTR")-1);
1155                         if (attr == NULL) {
1156                                 log_error("error parsing ATTR attribute\n");
1157                                 goto invalid;
1158                         }
1159                         if (op < OP_MATCH_MAX) {
1160                                 rule_add_key(&rule_tmp, TK_M_ATTR, op, value, attr);
1161                         } else {
1162                                 rule_add_key(&rule_tmp, TK_A_ATTR, op, value, attr);
1163                         }
1164                         continue;
1165                 }
1166
1167                 if (startswith(key, "SECLABEL{")) {
1168                         attr = get_key_attribute(rules->udev, key + sizeof("SECLABEL")-1);
1169                         if (!attr) {
1170                                 log_error("error parsing SECLABEL attribute\n");
1171                                 goto invalid;
1172                         }
1173
1174                         rule_add_key(&rule_tmp, TK_A_SECLABEL, op, value, attr);
1175                         continue;
1176                 }
1177
1178                 if (streq(key, "KERNELS")) {
1179                         if (op > OP_MATCH_MAX) {
1180                                 log_error("invalid KERNELS operation\n");
1181                                 goto invalid;
1182                         }
1183                         rule_add_key(&rule_tmp, TK_M_KERNELS, op, value, NULL);
1184                         continue;
1185                 }
1186
1187                 if (streq(key, "SUBSYSTEMS")) {
1188                         if (op > OP_MATCH_MAX) {
1189                                 log_error("invalid SUBSYSTEMS operation\n");
1190                                 goto invalid;
1191                         }
1192                         rule_add_key(&rule_tmp, TK_M_SUBSYSTEMS, op, value, NULL);
1193                         continue;
1194                 }
1195
1196                 if (streq(key, "DRIVERS")) {
1197                         if (op > OP_MATCH_MAX) {
1198                                 log_error("invalid DRIVERS operation\n");
1199                                 goto invalid;
1200                         }
1201                         rule_add_key(&rule_tmp, TK_M_DRIVERS, op, value, NULL);
1202                         continue;
1203                 }
1204
1205                 if (startswith(key, "ATTRS{")) {
1206                         if (op > OP_MATCH_MAX) {
1207                                 log_error("invalid ATTRS operation\n");
1208                                 goto invalid;
1209                         }
1210                         attr = get_key_attribute(rules->udev, key + sizeof("ATTRS")-1);
1211                         if (attr == NULL) {
1212                                 log_error("error parsing ATTRS attribute\n");
1213                                 goto invalid;
1214                         }
1215                         if (startswith(attr, "device/"))
1216                                 log_error("the 'device' link may not be available in a future kernel, "
1217                                     "please fix it in %s:%u", filename, lineno);
1218                         else if (strstr(attr, "../") != NULL)
1219                                 log_error("do not reference parent sysfs directories directly, "
1220                                     "it may break with a future kernel, please fix it in %s:%u", filename, lineno);
1221                         rule_add_key(&rule_tmp, TK_M_ATTRS, op, value, attr);
1222                         continue;
1223                 }
1224
1225                 if (streq(key, "TAGS")) {
1226                         if (op > OP_MATCH_MAX) {
1227                                 log_error("invalid TAGS operation\n");
1228                                 goto invalid;
1229                         }
1230                         rule_add_key(&rule_tmp, TK_M_TAGS, op, value, NULL);
1231                         continue;
1232                 }
1233
1234                 if (startswith(key, "ENV{")) {
1235                         attr = get_key_attribute(rules->udev, key + sizeof("ENV")-1);
1236                         if (attr == NULL) {
1237                                 log_error("error parsing ENV attribute\n");
1238                                 goto invalid;
1239                         }
1240                         if (op < OP_MATCH_MAX) {
1241                                 if (rule_add_key(&rule_tmp, TK_M_ENV, op, value, attr) != 0)
1242                                         goto invalid;
1243                         } else {
1244                                 static const char *blacklist[] = {
1245                                         "ACTION",
1246                                         "SUBSYSTEM",
1247                                         "DEVTYPE",
1248                                         "MAJOR",
1249                                         "MINOR",
1250                                         "DRIVER",
1251                                         "IFINDEX",
1252                                         "DEVNAME",
1253                                         "DEVLINKS",
1254                                         "DEVPATH",
1255                                         "TAGS",
1256                                 };
1257                                 unsigned int i;
1258
1259                                 for (i = 0; i < ELEMENTSOF(blacklist); i++) {
1260                                         if (!streq(attr, blacklist[i]))
1261                                                 continue;
1262                                         log_error("invalid ENV attribute, '%s' can not be set %s:%u\n", attr, filename, lineno);
1263                                         goto invalid;
1264                                 }
1265                                 if (rule_add_key(&rule_tmp, TK_A_ENV, op, value, attr) != 0)
1266                                         goto invalid;
1267                         }
1268                         continue;
1269                 }
1270
1271                 if (streq(key, "TAG")) {
1272                         if (op < OP_MATCH_MAX)
1273                                 rule_add_key(&rule_tmp, TK_M_TAG, op, value, NULL);
1274                         else
1275                                 rule_add_key(&rule_tmp, TK_A_TAG, op, value, NULL);
1276                         continue;
1277                 }
1278
1279                 if (streq(key, "PROGRAM")) {
1280                         rule_add_key(&rule_tmp, TK_M_PROGRAM, op, value, NULL);
1281                         continue;
1282                 }
1283
1284                 if (streq(key, "RESULT")) {
1285                         if (op > OP_MATCH_MAX) {
1286                                 log_error("invalid RESULT operation\n");
1287                                 goto invalid;
1288                         }
1289                         rule_add_key(&rule_tmp, TK_M_RESULT, op, value, NULL);
1290                         continue;
1291                 }
1292
1293                 if (startswith(key, "IMPORT")) {
1294                         attr = get_key_attribute(rules->udev, key + sizeof("IMPORT")-1);
1295                         if (attr == NULL) {
1296                                 log_error("IMPORT{} type missing, ignoring IMPORT %s:%u\n", filename, lineno);
1297                                 continue;
1298                         }
1299                         if (streq(attr, "program")) {
1300                                 /* find known built-in command */
1301                                 if (value[0] != '/') {
1302                                         enum udev_builtin_cmd cmd;
1303
1304                                         cmd = udev_builtin_lookup(value);
1305                                         if (cmd < UDEV_BUILTIN_MAX) {
1306                                                 log_debug("IMPORT found builtin '%s', replacing %s:%u\n",
1307                                                           value, filename, lineno);
1308                                                 rule_add_key(&rule_tmp, TK_M_IMPORT_BUILTIN, op, value, &cmd);
1309                                                 continue;
1310                                         }
1311                                 }
1312                                 rule_add_key(&rule_tmp, TK_M_IMPORT_PROG, op, value, NULL);
1313                         } else if (streq(attr, "builtin")) {
1314                                 enum udev_builtin_cmd cmd = udev_builtin_lookup(value);
1315
1316                                 if (cmd < UDEV_BUILTIN_MAX)
1317                                         rule_add_key(&rule_tmp, TK_M_IMPORT_BUILTIN, op, value, &cmd);
1318                                 else
1319                                         log_error("IMPORT{builtin}: '%s' unknown %s:%u\n", value, filename, lineno);
1320                         } else if (streq(attr, "file")) {
1321                                 rule_add_key(&rule_tmp, TK_M_IMPORT_FILE, op, value, NULL);
1322                         } else if (streq(attr, "db")) {
1323                                 rule_add_key(&rule_tmp, TK_M_IMPORT_DB, op, value, NULL);
1324                         } else if (streq(attr, "cmdline")) {
1325                                 rule_add_key(&rule_tmp, TK_M_IMPORT_CMDLINE, op, value, NULL);
1326                         } else if (streq(attr, "parent")) {
1327                                 rule_add_key(&rule_tmp, TK_M_IMPORT_PARENT, op, value, NULL);
1328                         } else
1329                                 log_error("IMPORT{} unknown type, ignoring IMPORT %s:%u\n", filename, lineno);
1330                         continue;
1331                 }
1332
1333                 if (startswith(key, "TEST")) {
1334                         mode_t mode = 0;
1335
1336                         if (op > OP_MATCH_MAX) {
1337                                 log_error("invalid TEST operation\n");
1338                                 goto invalid;
1339                         }
1340                         attr = get_key_attribute(rules->udev, key + sizeof("TEST")-1);
1341                         if (attr != NULL) {
1342                                 mode = strtol(attr, NULL, 8);
1343                                 rule_add_key(&rule_tmp, TK_M_TEST, op, value, &mode);
1344                         } else {
1345                                 rule_add_key(&rule_tmp, TK_M_TEST, op, value, NULL);
1346                         }
1347                         continue;
1348                 }
1349
1350                 if (startswith(key, "RUN")) {
1351                         attr = get_key_attribute(rules->udev, key + sizeof("RUN")-1);
1352                         if (attr == NULL)
1353                                 attr = "program";
1354
1355                         if (streq(attr, "builtin")) {
1356                                 enum udev_builtin_cmd cmd = udev_builtin_lookup(value);
1357
1358                                 if (cmd < UDEV_BUILTIN_MAX)
1359                                         rule_add_key(&rule_tmp, TK_A_RUN_BUILTIN, op, value, &cmd);
1360                                 else
1361                                         log_error("IMPORT{builtin}: '%s' unknown %s:%u\n", value, filename, lineno);
1362                         } else if (streq(attr, "program")) {
1363                                 enum udev_builtin_cmd cmd = UDEV_BUILTIN_MAX;
1364
1365                                 rule_add_key(&rule_tmp, TK_A_RUN_PROGRAM, op, value, &cmd);
1366                         } else {
1367                                 log_error("RUN{} unknown type, ignoring RUN %s:%u\n", filename, lineno);
1368                         }
1369
1370                         continue;
1371                 }
1372
1373                 if (streq(key, "WAIT_FOR") || streq(key, "WAIT_FOR_SYSFS")) {
1374                         rule_add_key(&rule_tmp, TK_M_WAITFOR, 0, value, NULL);
1375                         continue;
1376                 }
1377
1378                 if (streq(key, "LABEL")) {
1379                         rule_tmp.rule.rule.label_off = rules_add_string(rules, value);
1380                         continue;
1381                 }
1382
1383                 if (streq(key, "GOTO")) {
1384                         rule_add_key(&rule_tmp, TK_A_GOTO, 0, value, NULL);
1385                         continue;
1386                 }
1387
1388                 if (startswith(key, "NAME")) {
1389                         if (op < OP_MATCH_MAX) {
1390                                 rule_add_key(&rule_tmp, TK_M_NAME, op, value, NULL);
1391                         } else {
1392                                 if (streq(value, "%k")) {
1393                                         log_error("NAME=\"%%k\" is ignored, because it breaks kernel supplied names, "
1394                                             "please remove it from %s:%u\n", filename, lineno);
1395                                         continue;
1396                                 }
1397                                 if (value[0] == '\0') {
1398                                         log_debug("NAME=\"\" is ignored, because udev will not delete any device nodes, "
1399                                                   "please remove it from %s:%u\n", filename, lineno);
1400                                         continue;
1401                                 }
1402                                 rule_add_key(&rule_tmp, TK_A_NAME, op, value, NULL);
1403                         }
1404                         rule_tmp.rule.rule.can_set_name = true;
1405                         continue;
1406                 }
1407
1408                 if (streq(key, "SYMLINK")) {
1409                         if (op < OP_MATCH_MAX)
1410                                 rule_add_key(&rule_tmp, TK_M_DEVLINK, op, value, NULL);
1411                         else
1412                                 rule_add_key(&rule_tmp, TK_A_DEVLINK, op, value, NULL);
1413                         rule_tmp.rule.rule.can_set_name = true;
1414                         continue;
1415                 }
1416
1417                 if (streq(key, "OWNER")) {
1418                         uid_t uid;
1419                         char *endptr;
1420
1421                         uid = strtoul(value, &endptr, 10);
1422                         if (endptr[0] == '\0') {
1423                                 rule_add_key(&rule_tmp, TK_A_OWNER_ID, op, NULL, &uid);
1424                         } else if ((rules->resolve_names > 0) && strchr("$%", value[0]) == NULL) {
1425                                 uid = add_uid(rules, value);
1426                                 rule_add_key(&rule_tmp, TK_A_OWNER_ID, op, NULL, &uid);
1427                         } else if (rules->resolve_names >= 0) {
1428                                 rule_add_key(&rule_tmp, TK_A_OWNER, op, value, NULL);
1429                         }
1430                         rule_tmp.rule.rule.can_set_name = true;
1431                         continue;
1432                 }
1433
1434                 if (streq(key, "GROUP")) {
1435                         gid_t gid;
1436                         char *endptr;
1437
1438                         gid = strtoul(value, &endptr, 10);
1439                         if (endptr[0] == '\0') {
1440                                 rule_add_key(&rule_tmp, TK_A_GROUP_ID, op, NULL, &gid);
1441                         } else if ((rules->resolve_names > 0) && strchr("$%", value[0]) == NULL) {
1442                                 gid = add_gid(rules, value);
1443                                 rule_add_key(&rule_tmp, TK_A_GROUP_ID, op, NULL, &gid);
1444                         } else if (rules->resolve_names >= 0) {
1445                                 rule_add_key(&rule_tmp, TK_A_GROUP, op, value, NULL);
1446                         }
1447                         rule_tmp.rule.rule.can_set_name = true;
1448                         continue;
1449                 }
1450
1451                 if (streq(key, "MODE")) {
1452                         mode_t mode;
1453                         char *endptr;
1454
1455                         mode = strtol(value, &endptr, 8);
1456                         if (endptr[0] == '\0')
1457                                 rule_add_key(&rule_tmp, TK_A_MODE_ID, op, NULL, &mode);
1458                         else
1459                                 rule_add_key(&rule_tmp, TK_A_MODE, op, value, NULL);
1460                         rule_tmp.rule.rule.can_set_name = true;
1461                         continue;
1462                 }
1463
1464                 if (streq(key, "OPTIONS")) {
1465                         const char *pos;
1466
1467                         pos = strstr(value, "link_priority=");
1468                         if (pos != NULL) {
1469                                 int prio = atoi(&pos[strlen("link_priority=")]);
1470
1471                                 rule_add_key(&rule_tmp, TK_A_DEVLINK_PRIO, op, NULL, &prio);
1472                         }
1473
1474                         pos = strstr(value, "event_timeout=");
1475                         if (pos != NULL) {
1476                                 int tout = atoi(&pos[strlen("event_timeout=")]);
1477
1478                                 rule_add_key(&rule_tmp, TK_M_EVENT_TIMEOUT, op, NULL, &tout);
1479                         }
1480
1481                         pos = strstr(value, "string_escape=");
1482                         if (pos != NULL) {
1483                                 pos = &pos[strlen("string_escape=")];
1484                                 if (startswith(pos, "none"))
1485                                         rule_add_key(&rule_tmp, TK_A_STRING_ESCAPE_NONE, op, NULL, NULL);
1486                                 else if (startswith(pos, "replace"))
1487                                         rule_add_key(&rule_tmp, TK_A_STRING_ESCAPE_REPLACE, op, NULL, NULL);
1488                         }
1489
1490                         pos = strstr(value, "db_persist");
1491                         if (pos != NULL)
1492                                 rule_add_key(&rule_tmp, TK_A_DB_PERSIST, op, NULL, NULL);
1493
1494                         pos = strstr(value, "nowatch");
1495                         if (pos != NULL) {
1496                                 const int off = 0;
1497
1498                                 rule_add_key(&rule_tmp, TK_A_INOTIFY_WATCH, op, NULL, &off);
1499                         } else {
1500                                 pos = strstr(value, "watch");
1501                                 if (pos != NULL) {
1502                                         const int on = 1;
1503
1504                                         rule_add_key(&rule_tmp, TK_A_INOTIFY_WATCH, op, NULL, &on);
1505                                 }
1506                         }
1507
1508                         pos = strstr(value, "static_node=");
1509                         if (pos != NULL) {
1510                                 rule_add_key(&rule_tmp, TK_A_STATIC_NODE, op, &pos[strlen("static_node=")], NULL);
1511                                 rule_tmp.rule.rule.has_static_node = true;
1512                         }
1513
1514                         continue;
1515                 }
1516
1517                 log_error("unknown key '%s' in %s:%u\n", key, filename, lineno);
1518                 goto invalid;
1519         }
1520
1521         /* add rule token */
1522         rule_tmp.rule.rule.token_count = 1 + rule_tmp.token_cur;
1523         if (add_token(rules, &rule_tmp.rule) != 0)
1524                 goto invalid;
1525
1526         /* add tokens to list, sorted by type */
1527         if (sort_token(rules, &rule_tmp) != 0)
1528                 goto invalid;
1529
1530         return 0;
1531 invalid:
1532         log_error("invalid rule '%s:%u'\n", filename, lineno);
1533         return -1;
1534 }
1535
1536 static int parse_file(struct udev_rules *rules, const char *filename)
1537 {
1538         FILE *f;
1539         unsigned int first_token;
1540         unsigned int filename_off;
1541         char line[UTIL_LINE_SIZE];
1542         int line_nr = 0;
1543         unsigned int i;
1544
1545         if (null_or_empty_path(filename)) {
1546                 log_debug("skip empty file: %s\n", filename);
1547                 return 0;
1548         }
1549         log_debug("read rules file: %s\n", filename);
1550
1551         f = fopen(filename, "re");
1552         if (f == NULL)
1553                 return -1;
1554
1555         first_token = rules->token_cur;
1556         filename_off = rules_add_string(rules, filename);
1557
1558         while (fgets(line, sizeof(line), f) != NULL) {
1559                 char *key;
1560                 size_t len;
1561
1562                 /* skip whitespace */
1563                 line_nr++;
1564                 key = line;
1565                 while (isspace(key[0]))
1566                         key++;
1567
1568                 /* comment */
1569                 if (key[0] == '#')
1570                         continue;
1571
1572                 len = strlen(line);
1573                 if (len < 3)
1574                         continue;
1575
1576                 /* continue reading if backslash+newline is found */
1577                 while (line[len-2] == '\\') {
1578                         if (fgets(&line[len-2], (sizeof(line)-len)+2, f) == NULL)
1579                                 break;
1580                         if (strlen(&line[len-2]) < 2)
1581                                 break;
1582                         line_nr++;
1583                         len = strlen(line);
1584                 }
1585
1586                 if (len+1 >= sizeof(line)) {
1587                         log_error("line too long '%s':%u, ignored\n", filename, line_nr);
1588                         continue;
1589                 }
1590                 add_rule(rules, key, filename, filename_off, line_nr);
1591         }
1592         fclose(f);
1593
1594         /* link GOTOs to LABEL rules in this file to be able to fast-forward */
1595         for (i = first_token+1; i < rules->token_cur; i++) {
1596                 if (rules->tokens[i].type == TK_A_GOTO) {
1597                         char *label = rules_str(rules, rules->tokens[i].key.value_off);
1598                         unsigned int j;
1599
1600                         for (j = i+1; j < rules->token_cur; j++) {
1601                                 if (rules->tokens[j].type != TK_RULE)
1602                                         continue;
1603                                 if (rules->tokens[j].rule.label_off == 0)
1604                                         continue;
1605                                 if (!streq(label, rules_str(rules, rules->tokens[j].rule.label_off)))
1606                                         continue;
1607                                 rules->tokens[i].key.rule_goto = j;
1608                                 break;
1609                         }
1610                         if (rules->tokens[i].key.rule_goto == 0)
1611                                 log_error("GOTO '%s' has no matching label in: '%s'\n", label, filename);
1612                 }
1613         }
1614         return 0;
1615 }
1616
1617 struct udev_rules *udev_rules_new(struct udev *udev, int resolve_names)
1618 {
1619         struct udev_rules *rules;
1620         struct udev_list file_list;
1621         struct token end_token;
1622         char **files, **f;
1623         int r;
1624
1625         rules = calloc(1, sizeof(struct udev_rules));
1626         if (rules == NULL)
1627                 return NULL;
1628         rules->udev = udev;
1629         rules->resolve_names = resolve_names;
1630         udev_list_init(udev, &file_list, true);
1631
1632         /* init token array and string buffer */
1633         rules->tokens = malloc(PREALLOC_TOKEN * sizeof(struct token));
1634         if (rules->tokens == NULL)
1635                 return udev_rules_unref(rules);
1636         rules->token_max = PREALLOC_TOKEN;
1637
1638         rules->strbuf = strbuf_new();
1639         if (!rules->strbuf)
1640                 return udev_rules_unref(rules);
1641
1642         rules->dirs = strv_new("/etc/udev/rules.d",
1643                                "/run/udev/rules.d",
1644                                UDEVLIBEXECDIR "/rules.d",
1645                                NULL);
1646         if (!rules->dirs) {
1647                 log_error("failed to build config directory array");
1648                 return udev_rules_unref(rules);
1649         }
1650         if (!path_strv_canonicalize(rules->dirs)) {
1651                 log_error("failed to canonicalize config directories\n");
1652                 return udev_rules_unref(rules);
1653         }
1654         strv_uniq(rules->dirs);
1655
1656         udev_rules_check_timestamp(rules);
1657
1658         r = conf_files_list_strv(&files, ".rules", NULL, (const char **)rules->dirs);
1659         if (r < 0) {
1660                 log_error("failed to enumerate rules files: %s\n", strerror(-r));
1661                 return udev_rules_unref(rules);
1662         }
1663
1664         /*
1665          * The offset value in the rules strct is limited; add all
1666          * rules file names to the beginning of the string buffer.
1667          */
1668         STRV_FOREACH(f, files)
1669                 rules_add_string(rules, *f);
1670
1671         STRV_FOREACH(f, files)
1672                 parse_file(rules, *f);
1673
1674         strv_free(files);
1675
1676         memset(&end_token, 0x00, sizeof(struct token));
1677         end_token.type = TK_END;
1678         add_token(rules, &end_token);
1679         log_debug("rules contain %zu bytes tokens (%u * %zu bytes), %zu bytes strings\n",
1680                   rules->token_max * sizeof(struct token), rules->token_max, sizeof(struct token), rules->strbuf->len);
1681
1682         /* cleanup temporary strbuf data */
1683         log_debug("%zu strings (%zu bytes), %zu de-duplicated (%zu bytes), %zu trie nodes used\n",
1684                   rules->strbuf->in_count, rules->strbuf->in_len,
1685                   rules->strbuf->dedup_count, rules->strbuf->dedup_len, rules->strbuf->nodes_count);
1686         strbuf_complete(rules->strbuf);
1687
1688         /* cleanup uid/gid cache */
1689         free(rules->uids);
1690         rules->uids = NULL;
1691         rules->uids_cur = 0;
1692         rules->uids_max = 0;
1693         free(rules->gids);
1694         rules->gids = NULL;
1695         rules->gids_cur = 0;
1696         rules->gids_max = 0;
1697
1698         dump_rules(rules);
1699         return rules;
1700 }
1701
1702 struct udev_rules *udev_rules_unref(struct udev_rules *rules)
1703 {
1704         if (rules == NULL)
1705                 return NULL;
1706         free(rules->tokens);
1707         strbuf_cleanup(rules->strbuf);
1708         free(rules->uids);
1709         free(rules->gids);
1710         strv_free(rules->dirs);
1711         free(rules);
1712         return NULL;
1713 }
1714
1715 bool udev_rules_check_timestamp(struct udev_rules *rules)
1716 {
1717         return paths_check_timestamp(rules->dirs, &rules->dirs_ts_usec, true);
1718 }
1719
1720 static int match_key(struct udev_rules *rules, struct token *token, const char *val)
1721 {
1722         char *key_value = rules_str(rules, token->key.value_off);
1723         char *pos;
1724         bool match = false;
1725
1726         if (val == NULL)
1727                 val = "";
1728
1729         switch (token->key.glob) {
1730         case GL_PLAIN:
1731                 match = (streq(key_value, val));
1732                 break;
1733         case GL_GLOB:
1734                 match = (fnmatch(key_value, val, 0) == 0);
1735                 break;
1736         case GL_SPLIT:
1737                 {
1738                         const char *s;
1739                         size_t len;
1740
1741                         s = rules_str(rules, token->key.value_off);
1742                         len = strlen(val);
1743                         for (;;) {
1744                                 const char *next;
1745
1746                                 next = strchr(s, '|');
1747                                 if (next != NULL) {
1748                                         size_t matchlen = (size_t)(next - s);
1749
1750                                         match = (matchlen == len && strneq(s, val, matchlen));
1751                                         if (match)
1752                                                 break;
1753                                 } else {
1754                                         match = (streq(s, val));
1755                                         break;
1756                                 }
1757                                 s = &next[1];
1758                         }
1759                         break;
1760                 }
1761         case GL_SPLIT_GLOB:
1762                 {
1763                         char value[UTIL_PATH_SIZE];
1764
1765                         strscpy(value, sizeof(value), rules_str(rules, token->key.value_off));
1766                         key_value = value;
1767                         while (key_value != NULL) {
1768                                 pos = strchr(key_value, '|');
1769                                 if (pos != NULL) {
1770                                         pos[0] = '\0';
1771                                         pos = &pos[1];
1772                                 }
1773                                 match = (fnmatch(key_value, val, 0) == 0);
1774                                 if (match)
1775                                         break;
1776                                 key_value = pos;
1777                         }
1778                         break;
1779                 }
1780         case GL_SOMETHING:
1781                 match = (val[0] != '\0');
1782                 break;
1783         case GL_UNSET:
1784                 return -1;
1785         }
1786
1787         if (match && (token->key.op == OP_MATCH))
1788                 return 0;
1789         if (!match && (token->key.op == OP_NOMATCH))
1790                 return 0;
1791         return -1;
1792 }
1793
1794 static int match_attr(struct udev_rules *rules, struct udev_device *dev, struct udev_event *event, struct token *cur)
1795 {
1796         const char *name;
1797         char nbuf[UTIL_NAME_SIZE];
1798         const char *value;
1799         char vbuf[UTIL_NAME_SIZE];
1800         size_t len;
1801
1802         name = rules_str(rules, cur->key.attr_off);
1803         switch (cur->key.attrsubst) {
1804         case SB_FORMAT:
1805                 udev_event_apply_format(event, name, nbuf, sizeof(nbuf));
1806                 name = nbuf;
1807                 /* fall through */
1808         case SB_NONE:
1809                 value = udev_device_get_sysattr_value(dev, name);
1810                 if (value == NULL)
1811                         return -1;
1812                 break;
1813         case SB_SUBSYS:
1814                 if (util_resolve_subsys_kernel(event->udev, name, vbuf, sizeof(vbuf), 1) != 0)
1815                         return -1;
1816                 value = vbuf;
1817                 break;
1818         default:
1819                 return -1;
1820         }
1821
1822         /* remove trailing whitespace, if not asked to match for it */
1823         len = strlen(value);
1824         if (len > 0 && isspace(value[len-1])) {
1825                 const char *key_value;
1826                 size_t klen;
1827
1828                 key_value = rules_str(rules, cur->key.value_off);
1829                 klen = strlen(key_value);
1830                 if (klen > 0 && !isspace(key_value[klen-1])) {
1831                         if (value != vbuf) {
1832                                 strscpy(vbuf, sizeof(vbuf), value);
1833                                 value = vbuf;
1834                         }
1835                         while (len > 0 && isspace(vbuf[--len]))
1836                                 vbuf[len] = '\0';
1837                 }
1838         }
1839
1840         return match_key(rules, cur, value);
1841 }
1842
1843 enum escape_type {
1844         ESCAPE_UNSET,
1845         ESCAPE_NONE,
1846         ESCAPE_REPLACE,
1847 };
1848
1849 int udev_rules_apply_to_event(struct udev_rules *rules, struct udev_event *event, const sigset_t *sigmask)
1850 {
1851         struct token *cur;
1852         struct token *rule;
1853         enum escape_type esc = ESCAPE_UNSET;
1854         bool can_set_name;
1855
1856         if (rules->tokens == NULL)
1857                 return -1;
1858
1859         can_set_name = ((!streq(udev_device_get_action(event->dev), "remove")) &&
1860                         (major(udev_device_get_devnum(event->dev)) > 0 ||
1861                          udev_device_get_ifindex(event->dev) > 0));
1862
1863         /* loop through token list, match, run actions or forward to next rule */
1864         cur = &rules->tokens[0];
1865         rule = cur;
1866         for (;;) {
1867                 dump_token(rules, cur);
1868                 switch (cur->type) {
1869                 case TK_RULE:
1870                         /* current rule */
1871                         rule = cur;
1872                         /* possibly skip rules which want to set NAME, SYMLINK, OWNER, GROUP, MODE */
1873                         if (!can_set_name && rule->rule.can_set_name)
1874                                 goto nomatch;
1875                         esc = ESCAPE_UNSET;
1876                         break;
1877                 case TK_M_ACTION:
1878                         if (match_key(rules, cur, udev_device_get_action(event->dev)) != 0)
1879                                 goto nomatch;
1880                         break;
1881                 case TK_M_DEVPATH:
1882                         if (match_key(rules, cur, udev_device_get_devpath(event->dev)) != 0)
1883                                 goto nomatch;
1884                         break;
1885                 case TK_M_KERNEL:
1886                         if (match_key(rules, cur, udev_device_get_sysname(event->dev)) != 0)
1887                                 goto nomatch;
1888                         break;
1889                 case TK_M_DEVLINK: {
1890                         struct udev_list_entry *list_entry;
1891                         bool match = false;
1892
1893                         udev_list_entry_foreach(list_entry, udev_device_get_devlinks_list_entry(event->dev)) {
1894                                 const char *devlink;
1895
1896                                 devlink =  udev_list_entry_get_name(list_entry) + strlen("/dev/");
1897                                 if (match_key(rules, cur, devlink) == 0) {
1898                                         match = true;
1899                                         break;
1900                                 }
1901                         }
1902                         if (!match)
1903                                 goto nomatch;
1904                         break;
1905                 }
1906                 case TK_M_NAME:
1907                         if (match_key(rules, cur, event->name) != 0)
1908                                 goto nomatch;
1909                         break;
1910                 case TK_M_ENV: {
1911                         const char *key_name = rules_str(rules, cur->key.attr_off);
1912                         const char *value;
1913
1914                         value = udev_device_get_property_value(event->dev, key_name);
1915                         if (value == NULL)
1916                                 value = "";
1917                         if (match_key(rules, cur, value))
1918                                 goto nomatch;
1919                         break;
1920                 }
1921                 case TK_M_TAG: {
1922                         struct udev_list_entry *list_entry;
1923                         bool match = false;
1924
1925                         udev_list_entry_foreach(list_entry, udev_device_get_tags_list_entry(event->dev)) {
1926                                 if (streq(rules_str(rules, cur->key.value_off), udev_list_entry_get_name(list_entry))) {
1927                                         match = true;
1928                                         break;
1929                                 }
1930                         }
1931                         if (!match && (cur->key.op != OP_NOMATCH))
1932                                 goto nomatch;
1933                         break;
1934                 }
1935                 case TK_M_SUBSYSTEM:
1936                         if (match_key(rules, cur, udev_device_get_subsystem(event->dev)) != 0)
1937                                 goto nomatch;
1938                         break;
1939                 case TK_M_DRIVER:
1940                         if (match_key(rules, cur, udev_device_get_driver(event->dev)) != 0)
1941                                 goto nomatch;
1942                         break;
1943                 case TK_M_WAITFOR: {
1944                         char filename[UTIL_PATH_SIZE];
1945                         int found;
1946
1947                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), filename, sizeof(filename));
1948                         found = (wait_for_file(event->dev, filename, 10) == 0);
1949                         if (!found && (cur->key.op != OP_NOMATCH))
1950                                 goto nomatch;
1951                         break;
1952                 }
1953                 case TK_M_ATTR:
1954                         if (match_attr(rules, event->dev, event, cur) != 0)
1955                                 goto nomatch;
1956                         break;
1957                 case TK_M_KERNELS:
1958                 case TK_M_SUBSYSTEMS:
1959                 case TK_M_DRIVERS:
1960                 case TK_M_ATTRS:
1961                 case TK_M_TAGS: {
1962                         struct token *next;
1963
1964                         /* get whole sequence of parent matches */
1965                         next = cur;
1966                         while (next->type > TK_M_PARENTS_MIN && next->type < TK_M_PARENTS_MAX)
1967                                 next++;
1968
1969                         /* loop over parents */
1970                         event->dev_parent = event->dev;
1971                         for (;;) {
1972                                 struct token *key;
1973
1974                                 /* loop over sequence of parent match keys */
1975                                 for (key = cur; key < next; key++ ) {
1976                                         dump_token(rules, key);
1977                                         switch(key->type) {
1978                                         case TK_M_KERNELS:
1979                                                 if (match_key(rules, key, udev_device_get_sysname(event->dev_parent)) != 0)
1980                                                         goto try_parent;
1981                                                 break;
1982                                         case TK_M_SUBSYSTEMS:
1983                                                 if (match_key(rules, key, udev_device_get_subsystem(event->dev_parent)) != 0)
1984                                                         goto try_parent;
1985                                                 break;
1986                                         case TK_M_DRIVERS:
1987                                                 if (match_key(rules, key, udev_device_get_driver(event->dev_parent)) != 0)
1988                                                         goto try_parent;
1989                                                 break;
1990                                         case TK_M_ATTRS:
1991                                                 if (match_attr(rules, event->dev_parent, event, key) != 0)
1992                                                         goto try_parent;
1993                                                 break;
1994                                         case TK_M_TAGS: {
1995                                                 bool match = udev_device_has_tag(event->dev_parent, rules_str(rules, cur->key.value_off));
1996
1997                                                 if (match && key->key.op == OP_NOMATCH)
1998                                                         goto try_parent;
1999                                                 if (!match && key->key.op == OP_MATCH)
2000                                                         goto try_parent;
2001                                                 break;
2002                                         }
2003                                         default:
2004                                                 goto nomatch;
2005                                         }
2006                                 }
2007                                 break;
2008
2009                         try_parent:
2010                                 event->dev_parent = udev_device_get_parent(event->dev_parent);
2011                                 if (event->dev_parent == NULL)
2012                                         goto nomatch;
2013                         }
2014                         /* move behind our sequence of parent match keys */
2015                         cur = next;
2016                         continue;
2017                 }
2018                 case TK_M_TEST: {
2019                         char filename[UTIL_PATH_SIZE];
2020                         struct stat statbuf;
2021                         int match;
2022
2023                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), filename, sizeof(filename));
2024                         if (util_resolve_subsys_kernel(event->udev, filename, filename, sizeof(filename), 0) != 0) {
2025                                 if (filename[0] != '/') {
2026                                         char tmp[UTIL_PATH_SIZE];
2027
2028                                         strscpy(tmp, sizeof(tmp), filename);
2029                                         strscpyl(filename, sizeof(filename),
2030                                                       udev_device_get_syspath(event->dev), "/", tmp, NULL);
2031                                 }
2032                         }
2033                         attr_subst_subdir(filename, sizeof(filename));
2034
2035                         match = (stat(filename, &statbuf) == 0);
2036                         if (match && cur->key.mode > 0)
2037                                 match = ((statbuf.st_mode & cur->key.mode) > 0);
2038                         if (match && cur->key.op == OP_NOMATCH)
2039                                 goto nomatch;
2040                         if (!match && cur->key.op == OP_MATCH)
2041                                 goto nomatch;
2042                         break;
2043                 }
2044                 case TK_M_EVENT_TIMEOUT:
2045                         log_debug("OPTIONS event_timeout=%u\n", cur->key.event_timeout);
2046                         event->timeout_usec = cur->key.event_timeout * 1000 * 1000;
2047                         break;
2048                 case TK_M_PROGRAM: {
2049                         char program[UTIL_PATH_SIZE];
2050                         char **envp;
2051                         char result[UTIL_PATH_SIZE];
2052
2053                         free(event->program_result);
2054                         event->program_result = NULL;
2055                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), program, sizeof(program));
2056                         envp = udev_device_get_properties_envp(event->dev);
2057                         log_debug("PROGRAM '%s' %s:%u\n",
2058                                   program,
2059                                   rules_str(rules, rule->rule.filename_off),
2060                                   rule->rule.filename_line);
2061
2062                         if (udev_event_spawn(event, program, envp, sigmask, result, sizeof(result)) < 0) {
2063                                 if (cur->key.op != OP_NOMATCH)
2064                                         goto nomatch;
2065                         } else {
2066                                 int count;
2067
2068                                 util_remove_trailing_chars(result, '\n');
2069                                 if (esc == ESCAPE_UNSET || esc == ESCAPE_REPLACE) {
2070                                         count = util_replace_chars(result, UDEV_ALLOWED_CHARS_INPUT);
2071                                         if (count > 0)
2072                                                 log_debug("%i character(s) replaced\n" , count);
2073                                 }
2074                                 event->program_result = strdup(result);
2075                                 if (cur->key.op == OP_NOMATCH)
2076                                         goto nomatch;
2077                         }
2078                         break;
2079                 }
2080                 case TK_M_IMPORT_FILE: {
2081                         char import[UTIL_PATH_SIZE];
2082
2083                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), import, sizeof(import));
2084                         if (import_file_into_properties(event->dev, import) != 0)
2085                                 if (cur->key.op != OP_NOMATCH)
2086                                         goto nomatch;
2087                         break;
2088                 }
2089                 case TK_M_IMPORT_PROG: {
2090                         char import[UTIL_PATH_SIZE];
2091
2092                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), import, sizeof(import));
2093                         log_debug("IMPORT '%s' %s:%u\n",
2094                                   import,
2095                                   rules_str(rules, rule->rule.filename_off),
2096                                   rule->rule.filename_line);
2097
2098                         if (import_program_into_properties(event, import, sigmask) != 0)
2099                                 if (cur->key.op != OP_NOMATCH)
2100                                         goto nomatch;
2101                         break;
2102                 }
2103                 case TK_M_IMPORT_BUILTIN: {
2104                         char command[UTIL_PATH_SIZE];
2105
2106                         if (udev_builtin_run_once(cur->key.builtin_cmd)) {
2107                                 /* check if we ran already */
2108                                 if (event->builtin_run & (1 << cur->key.builtin_cmd)) {
2109                                         log_debug("IMPORT builtin skip '%s' %s:%u\n",
2110                                                   udev_builtin_name(cur->key.builtin_cmd),
2111                                                   rules_str(rules, rule->rule.filename_off),
2112                                                   rule->rule.filename_line);
2113                                         /* return the result from earlier run */
2114                                         if (event->builtin_ret & (1 << cur->key.builtin_cmd))
2115                                         if (cur->key.op != OP_NOMATCH)
2116                                                         goto nomatch;
2117                                         break;
2118                                 }
2119                                 /* mark as ran */
2120                                 event->builtin_run |= (1 << cur->key.builtin_cmd);
2121                         }
2122
2123                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), command, sizeof(command));
2124                         log_debug("IMPORT builtin '%s' %s:%u\n",
2125                                   udev_builtin_name(cur->key.builtin_cmd),
2126                                   rules_str(rules, rule->rule.filename_off),
2127                                   rule->rule.filename_line);
2128
2129                         if (udev_builtin_run(event->dev, cur->key.builtin_cmd, command, false) != 0) {
2130                                 /* remember failure */
2131                                 log_debug("IMPORT builtin '%s' returned non-zero\n",
2132                                           udev_builtin_name(cur->key.builtin_cmd));
2133                                 event->builtin_ret |= (1 << cur->key.builtin_cmd);
2134                                 if (cur->key.op != OP_NOMATCH)
2135                                         goto nomatch;
2136                         }
2137                         break;
2138                 }
2139                 case TK_M_IMPORT_DB: {
2140                         const char *key = rules_str(rules, cur->key.value_off);
2141                         const char *value;
2142
2143                         value = udev_device_get_property_value(event->dev_db, key);
2144                         if (value != NULL) {
2145                                 struct udev_list_entry *entry;
2146
2147                                 entry = udev_device_add_property(event->dev, key, value);
2148                                 udev_list_entry_set_num(entry, true);
2149                         } else {
2150                                 if (cur->key.op != OP_NOMATCH)
2151                                         goto nomatch;
2152                         }
2153                         break;
2154                 }
2155                 case TK_M_IMPORT_CMDLINE: {
2156                         FILE *f;
2157                         bool imported = false;
2158
2159                         f = fopen("/proc/cmdline", "re");
2160                         if (f != NULL) {
2161                                 char cmdline[4096];
2162
2163                                 if (fgets(cmdline, sizeof(cmdline), f) != NULL) {
2164                                         const char *key = rules_str(rules, cur->key.value_off);
2165                                         char *pos;
2166
2167                                         pos = strstr(cmdline, key);
2168                                         if (pos != NULL) {
2169                                                 struct udev_list_entry *entry;
2170
2171                                                 pos += strlen(key);
2172                                                 if (pos[0] == '\0' || isspace(pos[0])) {
2173                                                         /* we import simple flags as 'FLAG=1' */
2174                                                         entry = udev_device_add_property(event->dev, key, "1");
2175                                                         udev_list_entry_set_num(entry, true);
2176                                                         imported = true;
2177                                                 } else if (pos[0] == '=') {
2178                                                         const char *value;
2179
2180                                                         pos++;
2181                                                         value = pos;
2182                                                         while (pos[0] != '\0' && !isspace(pos[0]))
2183                                                                 pos++;
2184                                                         pos[0] = '\0';
2185                                                         entry = udev_device_add_property(event->dev, key, value);
2186                                                         udev_list_entry_set_num(entry, true);
2187                                                         imported = true;
2188                                                 }
2189                                         }
2190                                 }
2191                                 fclose(f);
2192                         }
2193                         if (!imported && cur->key.op != OP_NOMATCH)
2194                                 goto nomatch;
2195                         break;
2196                 }
2197                 case TK_M_IMPORT_PARENT: {
2198                         char import[UTIL_PATH_SIZE];
2199
2200                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), import, sizeof(import));
2201                         if (import_parent_into_properties(event->dev, import) != 0)
2202                                 if (cur->key.op != OP_NOMATCH)
2203                                         goto nomatch;
2204                         break;
2205                 }
2206                 case TK_M_RESULT:
2207                         if (match_key(rules, cur, event->program_result) != 0)
2208                                 goto nomatch;
2209                         break;
2210                 case TK_A_STRING_ESCAPE_NONE:
2211                         esc = ESCAPE_NONE;
2212                         break;
2213                 case TK_A_STRING_ESCAPE_REPLACE:
2214                         esc = ESCAPE_REPLACE;
2215                         break;
2216                 case TK_A_DB_PERSIST:
2217                         udev_device_set_db_persist(event->dev);
2218                         break;
2219                 case TK_A_INOTIFY_WATCH:
2220                         if (event->inotify_watch_final)
2221                                 break;
2222                         if (cur->key.op == OP_ASSIGN_FINAL)
2223                                 event->inotify_watch_final = true;
2224                         event->inotify_watch = cur->key.watch;
2225                         break;
2226                 case TK_A_DEVLINK_PRIO:
2227                         udev_device_set_devlink_priority(event->dev, cur->key.devlink_prio);
2228                         break;
2229                 case TK_A_OWNER: {
2230                         char owner[UTIL_NAME_SIZE];
2231
2232                         if (event->owner_final)
2233                                 break;
2234                         if (cur->key.op == OP_ASSIGN_FINAL)
2235                                 event->owner_final = true;
2236                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), owner, sizeof(owner));
2237                         event->owner_set = true;
2238                         event->uid = util_lookup_user(event->udev, owner);
2239                         log_debug("OWNER %u %s:%u\n",
2240                                   event->uid,
2241                                   rules_str(rules, rule->rule.filename_off),
2242                                   rule->rule.filename_line);
2243                         break;
2244                 }
2245                 case TK_A_GROUP: {
2246                         char group[UTIL_NAME_SIZE];
2247
2248                         if (event->group_final)
2249                                 break;
2250                         if (cur->key.op == OP_ASSIGN_FINAL)
2251                                 event->group_final = true;
2252                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), group, sizeof(group));
2253                         event->group_set = true;
2254                         event->gid = util_lookup_group(event->udev, group);
2255                         log_debug("GROUP %u %s:%u\n",
2256                                   event->gid,
2257                                   rules_str(rules, rule->rule.filename_off),
2258                                   rule->rule.filename_line);
2259                         break;
2260                 }
2261                 case TK_A_MODE: {
2262                         char mode_str[UTIL_NAME_SIZE];
2263                         mode_t mode;
2264                         char *endptr;
2265
2266                         if (event->mode_final)
2267                                 break;
2268                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), mode_str, sizeof(mode_str));
2269                         mode = strtol(mode_str, &endptr, 8);
2270                         if (endptr[0] != '\0') {
2271                                 log_error("ignoring invalid mode '%s'\n", mode_str);
2272                                 break;
2273                         }
2274                         if (cur->key.op == OP_ASSIGN_FINAL)
2275                                 event->mode_final = true;
2276                         event->mode_set = true;
2277                         event->mode = mode;
2278                         log_debug("MODE %#o %s:%u\n",
2279                                   event->mode,
2280                                   rules_str(rules, rule->rule.filename_off),
2281                                   rule->rule.filename_line);
2282                         break;
2283                 }
2284                 case TK_A_OWNER_ID:
2285                         if (event->owner_final)
2286                                 break;
2287                         if (cur->key.op == OP_ASSIGN_FINAL)
2288                                 event->owner_final = true;
2289                         event->owner_set = true;
2290                         event->uid = cur->key.uid;
2291                         log_debug("OWNER %u %s:%u\n",
2292                                   event->uid,
2293                                   rules_str(rules, rule->rule.filename_off),
2294                                   rule->rule.filename_line);
2295                         break;
2296                 case TK_A_GROUP_ID:
2297                         if (event->group_final)
2298                                 break;
2299                         if (cur->key.op == OP_ASSIGN_FINAL)
2300                                 event->group_final = true;
2301                         event->group_set = true;
2302                         event->gid = cur->key.gid;
2303                         log_debug("GROUP %u %s:%u\n",
2304                                   event->gid,
2305                                   rules_str(rules, rule->rule.filename_off),
2306                                   rule->rule.filename_line);
2307                         break;
2308                 case TK_A_MODE_ID:
2309                         if (event->mode_final)
2310                                 break;
2311                         if (cur->key.op == OP_ASSIGN_FINAL)
2312                                 event->mode_final = true;
2313                         event->mode_set = true;
2314                         event->mode = cur->key.mode;
2315                         log_debug("MODE %#o %s:%u\n",
2316                                   event->mode,
2317                                   rules_str(rules, rule->rule.filename_off),
2318                                   rule->rule.filename_line);
2319                         break;
2320                 case TK_A_SECLABEL: {
2321                         const char *name, *label;
2322
2323                         name = rules_str(rules, cur->key.attr_off);
2324                         label = rules_str(rules, cur->key.value_off);
2325                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2326                                 udev_list_cleanup(&event->seclabel_list);
2327                         udev_list_entry_add(&event->seclabel_list, name, label);
2328                         log_debug("SECLABEL{%s}='%s' %s:%u\n",
2329                                   name, label,
2330                                   rules_str(rules, rule->rule.filename_off),
2331                                   rule->rule.filename_line);
2332                         break;
2333                 }
2334                 case TK_A_ENV: {
2335                         const char *name = rules_str(rules, cur->key.attr_off);
2336                         char *value = rules_str(rules, cur->key.value_off);
2337                         char value_new[UTIL_NAME_SIZE];
2338                         const char *value_old = NULL;
2339                         struct udev_list_entry *entry;
2340
2341                         if (value[0] == '\0') {
2342                                 if (cur->key.op == OP_ADD)
2343                                         break;
2344                                 udev_device_add_property(event->dev, name, NULL);
2345                                 break;
2346                         }
2347
2348                         if (cur->key.op == OP_ADD)
2349                                 value_old = udev_device_get_property_value(event->dev, name);
2350                         if (value_old) {
2351                                 char temp[UTIL_NAME_SIZE];
2352
2353                                 /* append value separated by space */
2354                                 udev_event_apply_format(event, value, temp, sizeof(temp));
2355                                 strscpyl(value_new, sizeof(value_new), value_old, " ", temp, NULL);
2356                         } else
2357                                 udev_event_apply_format(event, value, value_new, sizeof(value_new));
2358
2359                         entry = udev_device_add_property(event->dev, name, value_new);
2360                         /* store in db, skip private keys */
2361                         if (name[0] != '.')
2362                                 udev_list_entry_set_num(entry, true);
2363                         break;
2364                 }
2365                 case TK_A_TAG: {
2366                         char tag[UTIL_PATH_SIZE];
2367                         const char *p;
2368
2369                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), tag, sizeof(tag));
2370                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2371                                 udev_device_cleanup_tags_list(event->dev);
2372                         for (p = tag; *p != '\0'; p++) {
2373                                 if ((*p >= 'a' && *p <= 'z') ||
2374                                     (*p >= 'A' && *p <= 'Z') ||
2375                                     (*p >= '0' && *p <= '9') ||
2376                                     *p == '-' || *p == '_')
2377                                         continue;
2378                                 log_error("ignoring invalid tag name '%s'\n", tag);
2379                                 break;
2380                         }
2381                         udev_device_add_tag(event->dev, tag);
2382                         break;
2383                 }
2384                 case TK_A_NAME: {
2385                         const char *name  = rules_str(rules, cur->key.value_off);
2386
2387                         char name_str[UTIL_PATH_SIZE];
2388                         int count;
2389
2390                         if (event->name_final)
2391                                 break;
2392                         if (cur->key.op == OP_ASSIGN_FINAL)
2393                                 event->name_final = true;
2394                         udev_event_apply_format(event, name, name_str, sizeof(name_str));
2395                         if (esc == ESCAPE_UNSET || esc == ESCAPE_REPLACE) {
2396                                 count = util_replace_chars(name_str, "/");
2397                                 if (count > 0)
2398                                         log_debug("%i character(s) replaced\n", count);
2399                         }
2400                         if (major(udev_device_get_devnum(event->dev)) &&
2401                             (!streq(name_str, udev_device_get_devnode(event->dev) + strlen("/dev/")))) {
2402                                 log_error("NAME=\"%s\" ignored, kernel device nodes "
2403                                     "can not be renamed; please fix it in %s:%u\n", name,
2404                                     rules_str(rules, rule->rule.filename_off), rule->rule.filename_line);
2405                                 break;
2406                         }
2407                         free(event->name);
2408                         event->name = strdup(name_str);
2409                         log_debug("NAME '%s' %s:%u\n",
2410                                   event->name,
2411                                   rules_str(rules, rule->rule.filename_off),
2412                                   rule->rule.filename_line);
2413                         break;
2414                 }
2415                 case TK_A_DEVLINK: {
2416                         char temp[UTIL_PATH_SIZE];
2417                         char filename[UTIL_PATH_SIZE];
2418                         char *pos, *next;
2419                         int count = 0;
2420
2421                         if (event->devlink_final)
2422                                 break;
2423                         if (major(udev_device_get_devnum(event->dev)) == 0)
2424                                 break;
2425                         if (cur->key.op == OP_ASSIGN_FINAL)
2426                                 event->devlink_final = true;
2427                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2428                                 udev_device_cleanup_devlinks_list(event->dev);
2429
2430                         /* allow  multiple symlinks separated by spaces */
2431                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), temp, sizeof(temp));
2432                         if (esc == ESCAPE_UNSET)
2433                                 count = util_replace_chars(temp, "/ ");
2434                         else if (esc == ESCAPE_REPLACE)
2435                                 count = util_replace_chars(temp, "/");
2436                         if (count > 0)
2437                                 log_debug("%i character(s) replaced\n" , count);
2438                         pos = temp;
2439                         while (isspace(pos[0]))
2440                                 pos++;
2441                         next = strchr(pos, ' ');
2442                         while (next != NULL) {
2443                                 next[0] = '\0';
2444                                 log_debug("LINK '%s' %s:%u\n", pos,
2445                                           rules_str(rules, rule->rule.filename_off), rule->rule.filename_line);
2446                                 strscpyl(filename, sizeof(filename), "/dev/", pos, NULL);
2447                                 udev_device_add_devlink(event->dev, filename);
2448                                 while (isspace(next[1]))
2449                                         next++;
2450                                 pos = &next[1];
2451                                 next = strchr(pos, ' ');
2452                         }
2453                         if (pos[0] != '\0') {
2454                                 log_debug("LINK '%s' %s:%u\n", pos,
2455                                           rules_str(rules, rule->rule.filename_off), rule->rule.filename_line);
2456                                 strscpyl(filename, sizeof(filename), "/dev/", pos, NULL);
2457                                 udev_device_add_devlink(event->dev, filename);
2458                         }
2459                         break;
2460                 }
2461                 case TK_A_ATTR: {
2462                         const char *key_name = rules_str(rules, cur->key.attr_off);
2463                         char attr[UTIL_PATH_SIZE];
2464                         char value[UTIL_NAME_SIZE];
2465                         FILE *f;
2466
2467                         if (util_resolve_subsys_kernel(event->udev, key_name, attr, sizeof(attr), 0) != 0)
2468                                 strscpyl(attr, sizeof(attr), udev_device_get_syspath(event->dev), "/", key_name, NULL);
2469                         attr_subst_subdir(attr, sizeof(attr));
2470
2471                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), value, sizeof(value));
2472                         log_debug("ATTR '%s' writing '%s' %s:%u\n", attr, value,
2473                                   rules_str(rules, rule->rule.filename_off),
2474                                   rule->rule.filename_line);
2475                         f = fopen(attr, "we");
2476                         if (f != NULL) {
2477                                 if (fprintf(f, "%s", value) <= 0)
2478                                         log_error("error writing ATTR{%s}: %m\n", attr);
2479                                 fclose(f);
2480                         } else {
2481                                 log_error("error opening ATTR{%s} for writing: %m\n", attr);
2482                         }
2483                         break;
2484                 }
2485                 case TK_A_RUN_BUILTIN:
2486                 case TK_A_RUN_PROGRAM: {
2487                         struct udev_list_entry *entry;
2488
2489                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2490                                 udev_list_cleanup(&event->run_list);
2491                         log_debug("RUN '%s' %s:%u\n",
2492                                   rules_str(rules, cur->key.value_off),
2493                                   rules_str(rules, rule->rule.filename_off),
2494                                   rule->rule.filename_line);
2495                         entry = udev_list_entry_add(&event->run_list, rules_str(rules, cur->key.value_off), NULL);
2496                         udev_list_entry_set_num(entry, cur->key.builtin_cmd);
2497                         break;
2498                 }
2499                 case TK_A_GOTO:
2500                         if (cur->key.rule_goto == 0)
2501                                 break;
2502                         cur = &rules->tokens[cur->key.rule_goto];
2503                         continue;
2504                 case TK_END:
2505                         return 0;
2506
2507                 case TK_M_PARENTS_MIN:
2508                 case TK_M_PARENTS_MAX:
2509                 case TK_M_MAX:
2510                 case TK_UNSET:
2511                         log_error("wrong type %u\n", cur->type);
2512                         goto nomatch;
2513                 }
2514
2515                 cur++;
2516                 continue;
2517         nomatch:
2518                 /* fast-forward to next rule */
2519                 cur = rule + rule->rule.token_count;
2520         }
2521 }
2522
2523 int udev_rules_apply_static_dev_perms(struct udev_rules *rules)
2524 {
2525         struct token *cur;
2526         struct token *rule;
2527         uid_t uid = 0;
2528         gid_t gid = 0;
2529         mode_t mode = 0;
2530         _cleanup_strv_free_ char **tags = NULL;
2531         char **t;
2532         FILE *f = NULL;
2533         _cleanup_free_ char *path = NULL;
2534         int r = 0;
2535
2536         if (rules->tokens == NULL)
2537                 return 0;
2538
2539         cur = &rules->tokens[0];
2540         rule = cur;
2541         for (;;) {
2542                 switch (cur->type) {
2543                 case TK_RULE:
2544                         /* current rule */
2545                         rule = cur;
2546
2547                         /* skip rules without a static_node tag */
2548                         if (!rule->rule.has_static_node)
2549                                 goto next;
2550
2551                         uid = 0;
2552                         gid = 0;
2553                         mode = 0;
2554                         strv_free(tags);
2555                         tags = NULL;
2556                         break;
2557                 case TK_A_OWNER_ID:
2558                         uid = cur->key.uid;
2559                         break;
2560                 case TK_A_GROUP_ID:
2561                         gid = cur->key.gid;
2562                         break;
2563                 case TK_A_MODE_ID:
2564                         mode = cur->key.mode;
2565                         break;
2566                 case TK_A_TAG:
2567                         r = strv_extend(&tags, rules_str(rules, cur->key.value_off));
2568                         if (r < 0)
2569                                 goto finish;
2570
2571                         break;
2572                 case TK_A_STATIC_NODE: {
2573                         char device_node[UTIL_PATH_SIZE];
2574                         char tags_dir[UTIL_PATH_SIZE];
2575                         char tag_symlink[UTIL_PATH_SIZE];
2576                         struct stat stats;
2577
2578                         /* we assure, that the permissions tokens are sorted before the static token */
2579                         if (mode == 0 && uid == 0 && gid == 0 && tags == NULL)
2580                                 goto next;
2581                         strscpyl(device_node, sizeof(device_node), "/dev/", rules_str(rules, cur->key.value_off), NULL);
2582                         if (stat(device_node, &stats) != 0)
2583                                 goto next;
2584                         if (!S_ISBLK(stats.st_mode) && !S_ISCHR(stats.st_mode))
2585                                 goto next;
2586
2587                         if (tags) {
2588                                 /* Export the tags to a directory as symlinks, allowing otherwise dead nodes to be tagged */
2589
2590                                 STRV_FOREACH(t, tags) {
2591                                         _cleanup_free_ char *unescaped_filename = NULL;
2592
2593                                         strscpyl(tags_dir, sizeof(tags_dir), "/run/udev/static_node-tags/", *t, "/", NULL);
2594                                         r = mkdir_p(tags_dir, 0755);
2595                                         if (r < 0) {
2596                                                 log_error("failed to create %s: %s\n", tags_dir, strerror(-r));
2597                                                 return r;
2598                                         }
2599
2600                                         unescaped_filename = xescape(rules_str(rules, cur->key.value_off), "/.");
2601
2602                                         strscpyl(tag_symlink, sizeof(tag_symlink), tags_dir, unescaped_filename, NULL);
2603                                         r = symlink(device_node, tag_symlink);
2604                                         if (r < 0 && errno != EEXIST) {
2605                                                 log_error("failed to create symlink %s -> %s: %s\n", tag_symlink, device_node, strerror(errno));
2606                                                 return -errno;
2607                                         } else
2608                                                 r = 0;
2609                                 }
2610                         }
2611
2612                         /* don't touch the permissions if only the tags were set */
2613                         if (mode == 0 && uid == 0 && gid == 0)
2614                                 goto next;
2615
2616                         if (mode == 0) {
2617                                 if (gid > 0)
2618                                         mode = 0660;
2619                                 else
2620                                         mode = 0600;
2621                         }
2622                         if (mode != (stats.st_mode & 01777)) {
2623                                 r = chmod(device_node, mode);
2624                                 if (r < 0) {
2625                                         log_error("failed to chmod '%s' %#o\n", device_node, mode);
2626                                         return -errno;
2627                                 } else
2628                                         log_debug("chmod '%s' %#o\n", device_node, mode);
2629                         }
2630
2631                         if ((uid != 0 && uid != stats.st_uid) || (gid != 0 && gid != stats.st_gid)) {
2632                                 r = chown(device_node, uid, gid);
2633                                 if (r < 0) {
2634                                         log_error("failed to chown '%s' %u %u \n", device_node, uid, gid);
2635                                         return -errno;
2636                                 } else
2637                                         log_debug("chown '%s' %u %u\n", device_node, uid, gid);
2638                         }
2639
2640                         utimensat(AT_FDCWD, device_node, NULL, 0);
2641                         break;
2642                 }
2643                 case TK_END:
2644                         goto finish;
2645                 }
2646
2647                 cur++;
2648                 continue;
2649 next:
2650                 /* fast-forward to next rule */
2651                 cur = rule + rule->rule.token_count;
2652                 continue;
2653         }
2654
2655 finish:
2656         if (f) {
2657                 fflush(f);
2658                 fchmod(fileno(f), 0644);
2659                 if (ferror(f) || rename(path, "/run/udev/static_node-tags") < 0) {
2660                         r = -errno;
2661                         unlink("/run/udev/static_node-tags");
2662                         unlink(path);
2663                 }
2664                 fclose(f);
2665         }
2666
2667         return r;
2668 }