chiark / gitweb /
selinux: more context settings
[elogind.git] / udev_rules_parse.c
index 5ce91df383dfdb5c924b7008549b6d7b8679d70c..d2392c36e054b144907e0c9b080e2cbc36b05ba9 100644 (file)
@@ -232,6 +232,7 @@ static int add_rule_key_pair(struct udev_rule *rule, struct key_pairs *pairs,
 
 static int add_to_rules(struct udev_rules *rules, char *line, const char *filename, unsigned int lineno)
 {
+       char buf[sizeof(struct udev_rule) + LINE_SIZE];
        struct udev_rule *rule;
        size_t rule_size;
        int valid;
@@ -241,15 +242,12 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
        int physdev = 0;
        int retval;
 
-       /* get all the keys */
-       rule = calloc(1, sizeof (struct udev_rule) + LINE_SIZE);
-       if (!rule) {
-               err("malloc failed");
-               return -1;
-       }
+       memset(buf, 0x00, sizeof(buf));
+       rule = (struct udev_rule *) buf;
        linepos = line;
        valid = 0;
 
+       /* get all the keys */
        while (1) {
                char *key;
                char *value;
@@ -298,7 +296,16 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
                                err("invalid SUBSYSTEM operation");
                                goto invalid;
                        }
-                       add_rule_key(rule, &rule->subsystem, operation, value);
+                       /* bus, class, subsystem events should all be the same */
+                       if (strcmp(value, "subsystem") == 0 ||
+                           strcmp(value, "bus") == 0 ||
+                           strcmp(value, "class") == 0) {
+                               if (strcmp(value, "bus") == 0 || strcmp(value, "class") == 0)
+                                       err("'%s' must be specified as 'subsystem' "
+                                           "please fix it in %s:%u", value, filename, lineno);
+                               add_rule_key(rule, &rule->subsystem, operation, "subsystem|class|bus");
+                       } else
+                               add_rule_key(rule, &rule->subsystem, operation, value);
                        valid = 1;
                        continue;
                }
@@ -376,7 +383,7 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
                        if (strncmp(attr, "device/", 7) == 0)
                                err("the 'device' link is deprecated and will be removed from a future kernel, "
                                    "please fix it in %s:%u", filename, lineno);
-                       else if (strchr(attr, '/') != NULL)
+                       else if (strstr(attr, "../") != NULL)
                                err("do not reference parent sysfs directories directly, that may break with a future kernel, "
                                    "please fix it in %s:%u", filename, lineno);
                        if (add_rule_key_pair(rule, &rule->attrs, operation, attr, value) != 0)
@@ -418,20 +425,20 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
 
                if (strncasecmp(key, "IMPORT", sizeof("IMPORT")-1) == 0) {
                        attr = get_key_attribute(key + sizeof("IMPORT")-1);
-                       if (attr && strstr(attr, "program")) {
+                       if (attr != NULL && strstr(attr, "program")) {
                                dbg("IMPORT will be executed");
                                rule->import_type  = IMPORT_PROGRAM;
-                       } else if (attr && strstr(attr, "file")) {
+                       } else if (attr != NULL && strstr(attr, "file")) {
                                dbg("IMPORT will be included as file");
                                rule->import_type  = IMPORT_FILE;
-                       } else if (attr && strstr(attr, "parent")) {
+                       } else if (attr != NULL && strstr(attr, "parent")) {
                                dbg("IMPORT will include the parent values");
                                rule->import_type = IMPORT_PARENT;
                        } else {
                                /* figure it out if it is executable */
                                char file[PATH_SIZE];
                                char *pos;
-                               struct stat stats;
+                               struct stat statbuf;
 
                                strlcpy(file, value, sizeof(file));
                                pos = strchr(file, ' ');
@@ -448,7 +455,7 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
                                }
 
                                dbg("IMPORT auto mode for '%s'", file);
-                               if (!lstat(file, &stats) && (stats.st_mode & S_IXUSR)) {
+                               if (!lstat(file, &statbuf) && (statbuf.st_mode & S_IXUSR)) {
                                        dbg("IMPORT is executable, will be executed (autotype)");
                                        rule->import_type  = IMPORT_PROGRAM;
                                } else {
@@ -461,7 +468,26 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
                        continue;
                }
 
-               if (strcasecmp(key, "RUN") == 0) {
+               if (strncasecmp(key, "TEST", sizeof("TEST")-1) == 0) {
+                       if (operation != KEY_OP_MATCH &&
+                           operation != KEY_OP_NOMATCH) {
+                               err("invalid TEST operation");
+                               goto invalid;
+                       }
+                       attr = get_key_attribute(key + sizeof("TEST")-1);
+                       if (attr != NULL)
+                               rule->test_mode_mask = strtol(attr, NULL, 8);
+                       add_rule_key(rule, &rule->test, operation, value);
+                       valid = 1;
+                       continue;
+               }
+
+               if (strncasecmp(key, "RUN", sizeof("RUN")-1) == 0) {
+                       attr = get_key_attribute(key + sizeof("RUN")-1);
+                       if (attr != NULL) {
+                               if (strstr(attr, "ignore_error"))
+                                       rule->run_ignore_error = 1;
+                       }
                        add_rule_key(rule, &rule->run, operation, value);
                        valid = 1;
                        continue;
@@ -504,7 +530,11 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
                }
 
                if (strcasecmp(key, "SYMLINK") == 0) {
-                       add_rule_key(rule, &rule->symlink, operation, value);
+                       if (operation == KEY_OP_MATCH ||
+                           operation == KEY_OP_NOMATCH)
+                               add_rule_key(rule, &rule->symlink_match, operation, value);
+                       else
+                               add_rule_key(rule, &rule->symlink, operation, value);
                        valid = 1;
                        continue;
                }
@@ -555,6 +585,8 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
                }
 
                if (strcasecmp(key, "OPTIONS") == 0) {
+                       const char *pos;
+
                        if (strstr(value, "last_rule") != NULL) {
                                dbg("last rule to be applied");
                                rule->last_rule = 1;
@@ -567,6 +599,19 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
                                dbg("remove event should be ignored");
                                rule->ignore_remove = 1;
                        }
+                       pos = strstr(value, "link_priority=");
+                       if (pos != NULL) {
+                               rule->link_priority = atoi(&pos[strlen("link_priority=")]);
+                               dbg("link priority=%i", rule->link_priority);
+                       }
+                       pos = strstr(value, "string_escape=");
+                       if (pos != NULL) {
+                               pos = &pos[strlen("string_escape=")];
+                               if (strncmp(pos, "none", strlen("none")) == 0)
+                                       rule->string_escape = ESCAPE_NONE;
+                               else if (strncmp(pos, "replace", strlen("replace")) == 0)
+                                       rule->string_escape = ESCAPE_REPLACE;
+                       }
                        if (strstr(value, "all_partitions") != NULL) {
                                dbg("creation of partition nodes requested");
                                rule->partitions = DEFAULT_PARTITIONS_COUNT;
@@ -602,11 +647,9 @@ static int add_to_rules(struct udev_rules *rules, char *line, const char *filena
        memcpy(rules->buf + rules->bufsize, rule, rule_size);
        rules->bufsize += rule_size;
 exit:
-       free(rule);
        return 0;
 
 invalid:
-       free(rule);
        err("invalid rule '%s:%u'", filename, lineno);
        return -1;
 }
@@ -675,37 +718,69 @@ static int parse_file(struct udev_rules *rules, const char *filename)
 
 int udev_rules_init(struct udev_rules *rules, int resolve_names)
 {
-       struct stat stats;
-       int retval;
+       struct stat statbuf;
+       char filename[PATH_MAX];
+       LIST_HEAD(name_list);
+       LIST_HEAD(dyn_list);
+       struct name_entry *name_loop, *name_tmp;
+       struct name_entry *dyn_loop, *dyn_tmp;
+       int retval = 0;
 
        memset(rules, 0x00, sizeof(struct udev_rules));
        rules->resolve_names = resolve_names;
 
-       /* parse rules file or all matching files in directory */
-       if (stat(udev_rules_dir, &stats) != 0)
+       /* read main config from single file or all files in a directory */
+       if (stat(udev_rules_dir, &statbuf) != 0)
                return -1;
-
-       if ((stats.st_mode & S_IFMT) != S_IFDIR) {
+       if ((statbuf.st_mode & S_IFMT) != S_IFDIR) {
                dbg("parse single rules file '%s'", udev_rules_dir);
-               retval = parse_file(rules, udev_rules_dir);
+               name_list_add(&name_list, udev_rules_dir, 1);
        } else {
-               struct name_entry *name_loop, *name_tmp;
-               LIST_HEAD(name_list);
-
                dbg("parse rules directory '%s'", udev_rules_dir);
                retval = add_matching_files(&name_list, udev_rules_dir, RULESFILE_SUFFIX);
+       }
+
+       /* read dynamic rules directory */
+       strlcpy(filename, udev_root, sizeof(filename));
+       strlcat(filename, "/"RULES_DYN_DIR, sizeof(filename));
+       if (stat(filename, &statbuf) != 0) {
+               create_path(filename);
+               selinux_setfscreatecon(filename, NULL, S_IFDIR|0755);
+               mkdir(filename, 0755);
+               selinux_resetfscreatecon();
+       }
+       add_matching_files(&dyn_list, filename, RULESFILE_SUFFIX);
+
+       /* sort dynamic rules files by basename into list of files */
+       list_for_each_entry_safe(dyn_loop, dyn_tmp, &dyn_list, node) {
+               const char *dyn_base = strrchr(dyn_loop->name, '/');
+
+               if (dyn_base == NULL)
+                       continue;
 
                list_for_each_entry_safe(name_loop, name_tmp, &name_list, node) {
-                       if (stat(name_loop->name, &stats) == 0) {
-                               if (stats.st_size)
-                                       parse_file(rules, name_loop->name);
-                               else
-                                       dbg("empty rules file '%s'", name_loop->name);
-                       } else
-                               err("could not read '%s': %s", name_loop->name, strerror(errno));
-                       list_del(&name_loop->node);
-                       free(name_loop);
+                       const char *name_base = strrchr(name_loop->name, '/');
+
+                       if (name_base == NULL)
+                               continue;
+
+                       if (strcmp(name_base, dyn_base) > 0)
+                               break;
                }
+               list_move_tail(&dyn_loop->node, &name_loop->node);
+       }
+
+       /* parse list of files */
+       list_for_each_entry_safe(name_loop, name_tmp, &name_list, node) {
+               if (stat(name_loop->name, &statbuf) == 0) {
+                       if (statbuf.st_size)
+                               parse_file(rules, name_loop->name);
+                       else
+                               dbg("empty rules file '%s'", name_loop->name);
+               } else
+                       err("could not read '%s': %s", name_loop->name, strerror(errno));
+               list_del(&name_loop->node);
+               free(name_loop);
        }
 
        return retval;
@@ -718,3 +793,4 @@ void udev_rules_cleanup(struct udev_rules *rules)
                rules->buf = NULL;
        }
 }
+