chiark / gitweb /
No need to canonicalize fixed paths
[elogind.git] / src / udev / udev-rules.c
1 /*
2  * Copyright (C) 2003-2012 Kay Sievers <kay@vrfy.org>
3  *
4  * This program is free software: you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License as published by
6  * the Free Software Foundation, either version 2 of the License, or
7  * (at your option) any later version.
8  *
9  * This program is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
16  */
17
18 #include <stddef.h>
19 #include <limits.h>
20 #include <stdlib.h>
21 #include <stdbool.h>
22 #include <string.h>
23 #include <stdio.h>
24 #include <fcntl.h>
25 #include <ctype.h>
26 #include <unistd.h>
27 #include <errno.h>
28 #include <dirent.h>
29 #include <fnmatch.h>
30 #include <time.h>
31
32 #include "udev.h"
33 #include "path-util.h"
34 #include "conf-files.h"
35 #include "strbuf.h"
36 #include "strv.h"
37 #include "util.h"
38
39 #define PREALLOC_TOKEN          2048
40
41 struct uid_gid {
42         unsigned int name_off;
43         union {
44                 uid_t uid;
45                 gid_t gid;
46         };
47 };
48
49 static const char* const rules_dirs[] = {
50         "/etc/udev/rules.d",
51         "/run/udev/rules.d",
52         UDEVLIBEXECDIR "/rules.d",
53         NULL};
54
55 struct udev_rules {
56         struct udev *udev;
57         usec_t dirs_ts_usec;
58         int resolve_names;
59
60         /* every key in the rules file becomes a token */
61         struct token *tokens;
62         unsigned int token_cur;
63         unsigned int token_max;
64
65         /* all key strings are copied and de-duplicated in a single continuous string buffer */
66         struct strbuf *strbuf;
67
68         /* during rule parsing, uid/gid lookup results are cached */
69         struct uid_gid *uids;
70         unsigned int uids_cur;
71         unsigned int uids_max;
72         struct uid_gid *gids;
73         unsigned int gids_cur;
74         unsigned int gids_max;
75 };
76
77 static char *rules_str(struct udev_rules *rules, unsigned int off) {
78         return rules->strbuf->buf + off;
79 }
80
81 static unsigned int rules_add_string(struct udev_rules *rules, const char *s) {
82         return strbuf_add_string(rules->strbuf, s, strlen(s));
83 }
84
85 /* KEY=="", KEY!="", KEY+="", KEY="", KEY:="" */
86 enum operation_type {
87         OP_UNSET,
88
89         OP_MATCH,
90         OP_NOMATCH,
91         OP_MATCH_MAX,
92
93         OP_ADD,
94         OP_ASSIGN,
95         OP_ASSIGN_FINAL,
96 };
97
98 enum string_glob_type {
99         GL_UNSET,
100         GL_PLAIN,                       /* no special chars */
101         GL_GLOB,                        /* shell globs ?,*,[] */
102         GL_SPLIT,                       /* multi-value A|B */
103         GL_SPLIT_GLOB,                  /* multi-value with glob A*|B* */
104         GL_SOMETHING,                   /* commonly used "?*" */
105 };
106
107 enum string_subst_type {
108         SB_UNSET,
109         SB_NONE,
110         SB_FORMAT,
111         SB_SUBSYS,
112 };
113
114 /* tokens of a rule are sorted/handled in this order */
115 enum token_type {
116         TK_UNSET,
117         TK_RULE,
118
119         TK_M_ACTION,                    /* val */
120         TK_M_DEVPATH,                   /* val */
121         TK_M_KERNEL,                    /* val */
122         TK_M_DEVLINK,                   /* val */
123         TK_M_NAME,                      /* val */
124         TK_M_ENV,                       /* val, attr */
125         TK_M_TAG,                       /* val */
126         TK_M_SUBSYSTEM,                 /* val */
127         TK_M_DRIVER,                    /* val */
128         TK_M_WAITFOR,                   /* val */
129         TK_M_ATTR,                      /* val, attr */
130
131         TK_M_PARENTS_MIN,
132         TK_M_KERNELS,                   /* val */
133         TK_M_SUBSYSTEMS,                /* val */
134         TK_M_DRIVERS,                   /* val */
135         TK_M_ATTRS,                     /* val, attr */
136         TK_M_TAGS,                      /* val */
137         TK_M_PARENTS_MAX,
138
139         TK_M_TEST,                      /* val, mode_t */
140         TK_M_EVENT_TIMEOUT,             /* int */
141         TK_M_PROGRAM,                   /* val */
142         TK_M_IMPORT_FILE,               /* val */
143         TK_M_IMPORT_PROG,               /* val */
144         TK_M_IMPORT_BUILTIN,            /* val */
145         TK_M_IMPORT_DB,                 /* val */
146         TK_M_IMPORT_CMDLINE,            /* val */
147         TK_M_IMPORT_PARENT,             /* val */
148         TK_M_RESULT,                    /* val */
149         TK_M_MAX,
150
151         TK_A_STRING_ESCAPE_NONE,
152         TK_A_STRING_ESCAPE_REPLACE,
153         TK_A_DB_PERSIST,
154         TK_A_INOTIFY_WATCH,             /* int */
155         TK_A_DEVLINK_PRIO,              /* int */
156         TK_A_OWNER,                     /* val */
157         TK_A_GROUP,                     /* val */
158         TK_A_MODE,                      /* val */
159         TK_A_OWNER_ID,                  /* uid_t */
160         TK_A_GROUP_ID,                  /* gid_t */
161         TK_A_MODE_ID,                   /* mode_t */
162         TK_A_TAG,                       /* val */
163         TK_A_STATIC_NODE,               /* val */
164         TK_A_SECLABEL,                  /* val, attr */
165         TK_A_ENV,                       /* val, attr */
166         TK_A_NAME,                      /* val */
167         TK_A_DEVLINK,                   /* val */
168         TK_A_ATTR,                      /* val, attr */
169         TK_A_RUN_BUILTIN,               /* val, bool */
170         TK_A_RUN_PROGRAM,               /* val, bool */
171         TK_A_GOTO,                      /* size_t */
172
173         TK_END,
174 };
175
176 /* we try to pack stuff in a way that we take only 12 bytes per token */
177 struct token {
178         union {
179                 unsigned char type;                /* same in rule and key */
180                 struct {
181                         enum token_type type:8;
182                         bool can_set_name:1;
183                         bool has_static_node:1;
184                         unsigned int unused:6;
185                         unsigned short token_count;
186                         unsigned int label_off;
187                         unsigned short filename_off;
188                         unsigned short filename_line;
189                 } rule;
190                 struct {
191                         enum token_type type:8;
192                         enum operation_type op:8;
193                         enum string_glob_type glob:8;
194                         enum string_subst_type subst:4;
195                         enum string_subst_type attrsubst:4;
196                         unsigned int value_off;
197                         union {
198                                 unsigned int attr_off;
199                                 unsigned int rule_goto;
200                                 mode_t  mode;
201                                 uid_t uid;
202                                 gid_t gid;
203                                 int devlink_prio;
204                                 int event_timeout;
205                                 int watch;
206                                 enum udev_builtin_cmd builtin_cmd;
207                         };
208                 } key;
209         };
210 };
211
212 #define MAX_TK                64
213 struct rule_tmp {
214         struct udev_rules *rules;
215         struct token rule;
216         struct token token[MAX_TK];
217         unsigned int token_cur;
218 };
219
220 #ifdef DEBUG
221 static const char *operation_str(enum operation_type type)
222 {
223         static const char *operation_strs[] = {
224                 [OP_UNSET] =            "UNSET",
225                 [OP_MATCH] =            "match",
226                 [OP_NOMATCH] =          "nomatch",
227                 [OP_MATCH_MAX] =        "MATCH_MAX",
228
229                 [OP_ADD] =              "add",
230                 [OP_ASSIGN] =           "assign",
231                 [OP_ASSIGN_FINAL] =     "assign-final",
232 }        ;
233
234         return operation_strs[type];
235 }
236
237 static const char *string_glob_str(enum string_glob_type type)
238 {
239         static const char *string_glob_strs[] = {
240                 [GL_UNSET] =            "UNSET",
241                 [GL_PLAIN] =            "plain",
242                 [GL_GLOB] =             "glob",
243                 [GL_SPLIT] =            "split",
244                 [GL_SPLIT_GLOB] =       "split-glob",
245                 [GL_SOMETHING] =        "split-glob",
246         };
247
248         return string_glob_strs[type];
249 }
250
251 static const char *token_str(enum token_type type)
252 {
253         static const char *token_strs[] = {
254                 [TK_UNSET] =                    "UNSET",
255                 [TK_RULE] =                     "RULE",
256
257                 [TK_M_ACTION] =                 "M ACTION",
258                 [TK_M_DEVPATH] =                "M DEVPATH",
259                 [TK_M_KERNEL] =                 "M KERNEL",
260                 [TK_M_DEVLINK] =                "M DEVLINK",
261                 [TK_M_NAME] =                   "M NAME",
262                 [TK_M_ENV] =                    "M ENV",
263                 [TK_M_TAG] =                    "M TAG",
264                 [TK_M_SUBSYSTEM] =              "M SUBSYSTEM",
265                 [TK_M_DRIVER] =                 "M DRIVER",
266                 [TK_M_WAITFOR] =                "M WAITFOR",
267                 [TK_M_ATTR] =                   "M ATTR",
268
269                 [TK_M_PARENTS_MIN] =            "M PARENTS_MIN",
270                 [TK_M_KERNELS] =                "M KERNELS",
271                 [TK_M_SUBSYSTEMS] =             "M SUBSYSTEMS",
272                 [TK_M_DRIVERS] =                "M DRIVERS",
273                 [TK_M_ATTRS] =                  "M ATTRS",
274                 [TK_M_TAGS] =                   "M TAGS",
275                 [TK_M_PARENTS_MAX] =            "M PARENTS_MAX",
276
277                 [TK_M_TEST] =                   "M TEST",
278                 [TK_M_EVENT_TIMEOUT] =          "M EVENT_TIMEOUT",
279                 [TK_M_PROGRAM] =                "M PROGRAM",
280                 [TK_M_IMPORT_FILE] =            "M IMPORT_FILE",
281                 [TK_M_IMPORT_PROG] =            "M IMPORT_PROG",
282                 [TK_M_IMPORT_BUILTIN] =         "M IMPORT_BUILTIN",
283                 [TK_M_IMPORT_DB] =              "M IMPORT_DB",
284                 [TK_M_IMPORT_CMDLINE] =         "M IMPORT_CMDLINE",
285                 [TK_M_IMPORT_PARENT] =          "M IMPORT_PARENT",
286                 [TK_M_RESULT] =                 "M RESULT",
287                 [TK_M_MAX] =                    "M MAX",
288
289                 [TK_A_STRING_ESCAPE_NONE] =     "A STRING_ESCAPE_NONE",
290                 [TK_A_STRING_ESCAPE_REPLACE] =  "A STRING_ESCAPE_REPLACE",
291                 [TK_A_DB_PERSIST] =             "A DB_PERSIST",
292                 [TK_A_INOTIFY_WATCH] =          "A INOTIFY_WATCH",
293                 [TK_A_DEVLINK_PRIO] =           "A DEVLINK_PRIO",
294                 [TK_A_OWNER] =                  "A OWNER",
295                 [TK_A_GROUP] =                  "A GROUP",
296                 [TK_A_MODE] =                   "A MODE",
297                 [TK_A_OWNER_ID] =               "A OWNER_ID",
298                 [TK_A_GROUP_ID] =               "A GROUP_ID",
299                 [TK_A_STATIC_NODE] =            "A STATIC_NODE",
300                 [TK_A_SECLABEL] =               "A SECLABEL",
301                 [TK_A_MODE_ID] =                "A MODE_ID",
302                 [TK_A_ENV] =                    "A ENV",
303                 [TK_A_TAG] =                    "A ENV",
304                 [TK_A_NAME] =                   "A NAME",
305                 [TK_A_DEVLINK] =                "A DEVLINK",
306                 [TK_A_ATTR] =                   "A ATTR",
307                 [TK_A_RUN_BUILTIN] =            "A RUN_BUILTIN",
308                 [TK_A_RUN_PROGRAM] =            "A RUN_PROGRAM",
309                 [TK_A_GOTO] =                   "A GOTO",
310
311                 [TK_END] =                      "END",
312         };
313
314         return token_strs[type];
315 }
316
317 static void dump_token(struct udev_rules *rules, struct token *token)
318 {
319         enum token_type type = token->type;
320         enum operation_type op = token->key.op;
321         enum string_glob_type glob = token->key.glob;
322         const char *value = str(rules, token->key.value_off);
323         const char *attr = &rules->buf[token->key.attr_off];
324
325         switch (type) {
326         case TK_RULE:
327                 {
328                         const char *tks_ptr = (char *)rules->tokens;
329                         const char *tk_ptr = (char *)token;
330                         unsigned int idx = (tk_ptr - tks_ptr) / sizeof(struct token);
331
332                         log_debug("* RULE %s:%u, token: %u, count: %u, label: '%s'",
333                                   &rules->buf[token->rule.filename_off], token->rule.filename_line,
334                                   idx, token->rule.token_count,
335                                   &rules->buf[token->rule.label_off]);
336                         break;
337                 }
338         case TK_M_ACTION:
339         case TK_M_DEVPATH:
340         case TK_M_KERNEL:
341         case TK_M_SUBSYSTEM:
342         case TK_M_DRIVER:
343         case TK_M_WAITFOR:
344         case TK_M_DEVLINK:
345         case TK_M_NAME:
346         case TK_M_KERNELS:
347         case TK_M_SUBSYSTEMS:
348         case TK_M_DRIVERS:
349         case TK_M_TAGS:
350         case TK_M_PROGRAM:
351         case TK_M_IMPORT_FILE:
352         case TK_M_IMPORT_PROG:
353         case TK_M_IMPORT_DB:
354         case TK_M_IMPORT_CMDLINE:
355         case TK_M_IMPORT_PARENT:
356         case TK_M_RESULT:
357         case TK_A_NAME:
358         case TK_A_DEVLINK:
359         case TK_A_OWNER:
360         case TK_A_GROUP:
361         case TK_A_MODE:
362         case TK_A_RUN_BUILTIN:
363         case TK_A_RUN_PROGRAM:
364                 log_debug("%s %s '%s'(%s)",
365                           token_str(type), operation_str(op), value, string_glob_str(glob));
366                 break;
367         case TK_M_IMPORT_BUILTIN:
368                 log_debug("%s %i '%s'", token_str(type), token->key.builtin_cmd, value);
369                 break;
370         case TK_M_ATTR:
371         case TK_M_ATTRS:
372         case TK_M_ENV:
373         case TK_A_ATTR:
374         case TK_A_ENV:
375                 log_debug("%s %s '%s' '%s'(%s)",
376                           token_str(type), operation_str(op), attr, value, string_glob_str(glob));
377                 break;
378         case TK_M_TAG:
379         case TK_A_TAG:
380                 log_debug("%s %s '%s'", token_str(type), operation_str(op), value);
381                 break;
382         case TK_A_STRING_ESCAPE_NONE:
383         case TK_A_STRING_ESCAPE_REPLACE:
384         case TK_A_DB_PERSIST:
385                 log_debug("%s", token_str(type));
386                 break;
387         case TK_M_TEST:
388                 log_debug("%s %s '%s'(%s) %#o",
389                           token_str(type), operation_str(op), value, string_glob_str(glob), token->key.mode);
390                 break;
391         case TK_A_INOTIFY_WATCH:
392                 log_debug("%s %u", token_str(type), token->key.watch);
393                 break;
394         case TK_A_DEVLINK_PRIO:
395                 log_debug("%s %u", token_str(type), token->key.devlink_prio);
396                 break;
397         case TK_A_OWNER_ID:
398                 log_debug("%s %s %u", token_str(type), operation_str(op), token->key.uid);
399                 break;
400         case TK_A_GROUP_ID:
401                 log_debug("%s %s %u", token_str(type), operation_str(op), token->key.gid);
402                 break;
403         case TK_A_MODE_ID:
404                 log_debug("%s %s %#o", token_str(type), operation_str(op), token->key.mode);
405                 break;
406         case TK_A_STATIC_NODE:
407                 log_debug("%s '%s'", token_str(type), value);
408                 break;
409         case TK_A_SECLABEL:
410                 log_debug("%s %s '%s' '%s'", token_str(type), operation_str(op), attr, value);
411                 break;
412         case TK_M_EVENT_TIMEOUT:
413                 log_debug("%s %u", token_str(type), token->key.event_timeout);
414                 break;
415         case TK_A_GOTO:
416                 log_debug("%s '%s' %u", token_str(type), value, token->key.rule_goto);
417                 break;
418         case TK_END:
419                 log_debug("* %s", token_str(type));
420                 break;
421         case TK_M_PARENTS_MIN:
422         case TK_M_PARENTS_MAX:
423         case TK_M_MAX:
424         case TK_UNSET:
425                 log_debug("unknown type %u", type);
426                 break;
427         }
428 }
429
430 static void dump_rules(struct udev_rules *rules)
431 {
432         unsigned int i;
433
434         log_debug("dumping %u (%zu bytes) tokens, %u (%zu bytes) strings",
435                   rules->token_cur,
436                   rules->token_cur * sizeof(struct token),
437                   rules->buf_count,
438                   rules->buf_cur);
439         for (i = 0; i < rules->token_cur; i++)
440                 dump_token(rules, &rules->tokens[i]);
441 }
442 #else
443 static inline const char *operation_str(enum operation_type type) { return NULL; }
444 static inline const char *token_str(enum token_type type) { return NULL; }
445 static inline void dump_token(struct udev_rules *rules, struct token *token) {}
446 static inline void dump_rules(struct udev_rules *rules) {}
447 #endif /* DEBUG */
448
449 static int add_token(struct udev_rules *rules, struct token *token)
450 {
451         /* grow buffer if needed */
452         if (rules->token_cur+1 >= rules->token_max) {
453                 struct token *tokens;
454                 unsigned int add;
455
456                 /* double the buffer size */
457                 add = rules->token_max;
458                 if (add < 8)
459                         add = 8;
460
461                 tokens = realloc(rules->tokens, (rules->token_max + add ) * sizeof(struct token));
462                 if (tokens == NULL)
463                         return -1;
464                 rules->tokens = tokens;
465                 rules->token_max += add;
466         }
467         memcpy(&rules->tokens[rules->token_cur], token, sizeof(struct token));
468         rules->token_cur++;
469         return 0;
470 }
471
472 static uid_t add_uid(struct udev_rules *rules, const char *owner)
473 {
474         unsigned int i;
475         uid_t uid;
476         unsigned int off;
477
478         /* lookup, if we know it already */
479         for (i = 0; i < rules->uids_cur; i++) {
480                 off = rules->uids[i].name_off;
481                 if (streq(rules_str(rules, off), owner)) {
482                         uid = rules->uids[i].uid;
483                         return uid;
484                 }
485         }
486         uid = util_lookup_user(rules->udev, owner);
487
488         /* grow buffer if needed */
489         if (rules->uids_cur+1 >= rules->uids_max) {
490                 struct uid_gid *uids;
491                 unsigned int add;
492
493                 /* double the buffer size */
494                 add = rules->uids_max;
495                 if (add < 1)
496                         add = 8;
497
498                 uids = realloc(rules->uids, (rules->uids_max + add ) * sizeof(struct uid_gid));
499                 if (uids == NULL)
500                         return uid;
501                 rules->uids = uids;
502                 rules->uids_max += add;
503         }
504         rules->uids[rules->uids_cur].uid = uid;
505         off = rules_add_string(rules, owner);
506         if (off <= 0)
507                 return uid;
508         rules->uids[rules->uids_cur].name_off = off;
509         rules->uids_cur++;
510         return uid;
511 }
512
513 static gid_t add_gid(struct udev_rules *rules, const char *group)
514 {
515         unsigned int i;
516         gid_t gid;
517         unsigned int off;
518
519         /* lookup, if we know it already */
520         for (i = 0; i < rules->gids_cur; i++) {
521                 off = rules->gids[i].name_off;
522                 if (streq(rules_str(rules, off), group)) {
523                         gid = rules->gids[i].gid;
524                         return gid;
525                 }
526         }
527         gid = util_lookup_group(rules->udev, group);
528
529         /* grow buffer if needed */
530         if (rules->gids_cur+1 >= rules->gids_max) {
531                 struct uid_gid *gids;
532                 unsigned int add;
533
534                 /* double the buffer size */
535                 add = rules->gids_max;
536                 if (add < 1)
537                         add = 8;
538
539                 gids = realloc(rules->gids, (rules->gids_max + add ) * sizeof(struct uid_gid));
540                 if (gids == NULL)
541                         return gid;
542                 rules->gids = gids;
543                 rules->gids_max += add;
544         }
545         rules->gids[rules->gids_cur].gid = gid;
546         off = rules_add_string(rules, group);
547         if (off <= 0)
548                 return gid;
549         rules->gids[rules->gids_cur].name_off = off;
550         rules->gids_cur++;
551         return gid;
552 }
553
554 static int import_property_from_string(struct udev_device *dev, char *line)
555 {
556         char *key;
557         char *val;
558         size_t len;
559         struct udev_list_entry *entry;
560
561         /* find key */
562         key = line;
563         while (isspace(key[0]))
564                 key++;
565
566         /* comment or empty line */
567         if (key[0] == '#' || key[0] == '\0')
568                 return -1;
569
570         /* split key/value */
571         val = strchr(key, '=');
572         if (val == NULL)
573                 return -1;
574         val[0] = '\0';
575         val++;
576
577         /* find value */
578         while (isspace(val[0]))
579                 val++;
580
581         /* terminate key */
582         len = strlen(key);
583         if (len == 0)
584                 return -1;
585         while (isspace(key[len-1]))
586                 len--;
587         key[len] = '\0';
588
589         /* terminate value */
590         len = strlen(val);
591         if (len == 0)
592                 return -1;
593         while (isspace(val[len-1]))
594                 len--;
595         val[len] = '\0';
596
597         if (len == 0)
598                 return -1;
599
600         /* unquote */
601         if (val[0] == '"' || val[0] == '\'') {
602                 if (val[len-1] != val[0]) {
603                         log_debug("inconsistent quoting: '%s', skip", line);
604                         return -1;
605                 }
606                 val[len-1] = '\0';
607                 val++;
608         }
609
610         entry = udev_device_add_property(dev, key, val);
611         /* store in db, skip private keys */
612         if (key[0] != '.')
613                 udev_list_entry_set_num(entry, true);
614
615         return 0;
616 }
617
618 static int import_file_into_properties(struct udev_device *dev, const char *filename)
619 {
620         FILE *f;
621         char line[UTIL_LINE_SIZE];
622
623         f = fopen(filename, "re");
624         if (f == NULL)
625                 return -1;
626         while (fgets(line, sizeof(line), f) != NULL)
627                 import_property_from_string(dev, line);
628         fclose(f);
629         return 0;
630 }
631
632 static int import_program_into_properties(struct udev_event *event, const char *program, const sigset_t *sigmask)
633 {
634         struct udev_device *dev = event->dev;
635         char **envp;
636         char result[UTIL_LINE_SIZE];
637         char *line;
638         int err;
639
640         envp = udev_device_get_properties_envp(dev);
641         err = udev_event_spawn(event, program, envp, sigmask, result, sizeof(result));
642         if (err < 0)
643                 return err;
644
645         line = result;
646         while (line != NULL) {
647                 char *pos;
648
649                 pos = strchr(line, '\n');
650                 if (pos != NULL) {
651                         pos[0] = '\0';
652                         pos = &pos[1];
653                 }
654                 import_property_from_string(dev, line);
655                 line = pos;
656         }
657         return 0;
658 }
659
660 static int import_parent_into_properties(struct udev_device *dev, const char *filter)
661 {
662         struct udev_device *dev_parent;
663         struct udev_list_entry *list_entry;
664
665         dev_parent = udev_device_get_parent(dev);
666         if (dev_parent == NULL)
667                 return -1;
668
669         udev_list_entry_foreach(list_entry, udev_device_get_properties_list_entry(dev_parent)) {
670                 const char *key = udev_list_entry_get_name(list_entry);
671                 const char *val = udev_list_entry_get_value(list_entry);
672
673                 if (fnmatch(filter, key, 0) == 0) {
674                         struct udev_list_entry *entry;
675
676                         entry = udev_device_add_property(dev, key, val);
677                         /* store in db, skip private keys */
678                         if (key[0] != '.')
679                                 udev_list_entry_set_num(entry, true);
680                 }
681         }
682         return 0;
683 }
684
685 #define WAIT_LOOP_PER_SECOND                50
686 static int wait_for_file(struct udev_device *dev, const char *file, int timeout)
687 {
688         char filepath[UTIL_PATH_SIZE];
689         char devicepath[UTIL_PATH_SIZE];
690         struct stat stats;
691         int loop = timeout * WAIT_LOOP_PER_SECOND;
692
693         /* a relative path is a device attribute */
694         devicepath[0] = '\0';
695         if (file[0] != '/') {
696                 strscpyl(devicepath, sizeof(devicepath), udev_device_get_syspath(dev), NULL);
697                 strscpyl(filepath, sizeof(filepath), devicepath, "/", file, NULL);
698                 file = filepath;
699         }
700
701         while (--loop) {
702                 const struct timespec duration = { 0, 1000 * 1000 * 1000 / WAIT_LOOP_PER_SECOND };
703
704                 /* lookup file */
705                 if (stat(file, &stats) == 0) {
706                         log_debug("file '%s' appeared after %i loops", file, (timeout * WAIT_LOOP_PER_SECOND) - loop-1);
707                         return 0;
708                 }
709                 /* make sure, the device did not disappear in the meantime */
710                 if (devicepath[0] != '\0' && stat(devicepath, &stats) != 0) {
711                         log_debug("device disappeared while waiting for '%s'", file);
712                         return -2;
713                 }
714                 log_debug("wait for '%s' for %i mseconds", file, 1000 / WAIT_LOOP_PER_SECOND);
715                 nanosleep(&duration, NULL);
716         }
717         log_debug("waiting for '%s' failed", file);
718         return -1;
719 }
720
721 static int attr_subst_subdir(char *attr, size_t len)
722 {
723         bool found = false;
724
725         if (strstr(attr, "/*/")) {
726                 char *pos;
727                 char dirname[UTIL_PATH_SIZE];
728                 const char *tail;
729                 DIR *dir;
730
731                 strscpy(dirname, sizeof(dirname), attr);
732                 pos = strstr(dirname, "/*/");
733                 if (pos == NULL)
734                         return -1;
735                 pos[0] = '\0';
736                 tail = &pos[2];
737                 dir = opendir(dirname);
738                 if (dir != NULL) {
739                         struct dirent *dent;
740
741                         for (dent = readdir(dir); dent != NULL; dent = readdir(dir)) {
742                                 struct stat stats;
743
744                                 if (dent->d_name[0] == '.')
745                                         continue;
746                                 strscpyl(attr, len, dirname, "/", dent->d_name, tail, NULL);
747                                 if (stat(attr, &stats) == 0) {
748                                         found = true;
749                                         break;
750                                 }
751                         }
752                         closedir(dir);
753                 }
754         }
755
756         return found;
757 }
758
759 static int get_key(struct udev *udev, char **line, char **key, enum operation_type *op, char **value)
760 {
761         char *linepos;
762         char *temp;
763
764         linepos = *line;
765         if (linepos == NULL || linepos[0] == '\0')
766                 return -1;
767
768         /* skip whitespace */
769         while (isspace(linepos[0]) || linepos[0] == ',')
770                 linepos++;
771
772         /* get the key */
773         if (linepos[0] == '\0')
774                 return -1;
775         *key = linepos;
776
777         for (;;) {
778                 linepos++;
779                 if (linepos[0] == '\0')
780                         return -1;
781                 if (isspace(linepos[0]))
782                         break;
783                 if (linepos[0] == '=')
784                         break;
785                 if ((linepos[0] == '+') || (linepos[0] == '!') || (linepos[0] == ':'))
786                         if (linepos[1] == '=')
787                                 break;
788         }
789
790         /* remember end of key */
791         temp = linepos;
792
793         /* skip whitespace after key */
794         while (isspace(linepos[0]))
795                 linepos++;
796         if (linepos[0] == '\0')
797                 return -1;
798
799         /* get operation type */
800         if (linepos[0] == '=' && linepos[1] == '=') {
801                 *op = OP_MATCH;
802                 linepos += 2;
803         } else if (linepos[0] == '!' && linepos[1] == '=') {
804                 *op = OP_NOMATCH;
805                 linepos += 2;
806         } else if (linepos[0] == '+' && linepos[1] == '=') {
807                 *op = OP_ADD;
808                 linepos += 2;
809         } else if (linepos[0] == '=') {
810                 *op = OP_ASSIGN;
811                 linepos++;
812         } else if (linepos[0] == ':' && linepos[1] == '=') {
813                 *op = OP_ASSIGN_FINAL;
814                 linepos += 2;
815         } else
816                 return -1;
817
818         /* terminate key */
819         temp[0] = '\0';
820
821         /* skip whitespace after operator */
822         while (isspace(linepos[0]))
823                 linepos++;
824         if (linepos[0] == '\0')
825                 return -1;
826
827         /* get the value */
828         if (linepos[0] == '"')
829                 linepos++;
830         else
831                 return -1;
832         *value = linepos;
833
834         /* terminate */
835         temp = strchr(linepos, '"');
836         if (!temp)
837                 return -1;
838         temp[0] = '\0';
839         temp++;
840
841         /* move line to next key */
842         *line = temp;
843         return 0;
844 }
845
846 /* extract possible KEY{attr} */
847 static const char *get_key_attribute(struct udev *udev, char *str)
848 {
849         char *pos;
850         char *attr;
851
852         attr = strchr(str, '{');
853         if (attr != NULL) {
854                 attr++;
855                 pos = strchr(attr, '}');
856                 if (pos == NULL) {
857                         log_error("missing closing brace for format");
858                         return NULL;
859                 }
860                 pos[0] = '\0';
861                 return attr;
862         }
863         return NULL;
864 }
865
866 static int rule_add_key(struct rule_tmp *rule_tmp, enum token_type type,
867                         enum operation_type op,
868                         const char *value, const void *data)
869 {
870         struct token *token = &rule_tmp->token[rule_tmp->token_cur];
871         const char *attr = NULL;
872
873         memset(token, 0x00, sizeof(struct token));
874
875         switch (type) {
876         case TK_M_ACTION:
877         case TK_M_DEVPATH:
878         case TK_M_KERNEL:
879         case TK_M_SUBSYSTEM:
880         case TK_M_DRIVER:
881         case TK_M_WAITFOR:
882         case TK_M_DEVLINK:
883         case TK_M_NAME:
884         case TK_M_KERNELS:
885         case TK_M_SUBSYSTEMS:
886         case TK_M_DRIVERS:
887         case TK_M_TAGS:
888         case TK_M_PROGRAM:
889         case TK_M_IMPORT_FILE:
890         case TK_M_IMPORT_PROG:
891         case TK_M_IMPORT_DB:
892         case TK_M_IMPORT_CMDLINE:
893         case TK_M_IMPORT_PARENT:
894         case TK_M_RESULT:
895         case TK_A_OWNER:
896         case TK_A_GROUP:
897         case TK_A_MODE:
898         case TK_A_DEVLINK:
899         case TK_A_NAME:
900         case TK_A_GOTO:
901         case TK_M_TAG:
902         case TK_A_TAG:
903                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
904                 break;
905         case TK_M_IMPORT_BUILTIN:
906                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
907                 token->key.builtin_cmd = *(enum udev_builtin_cmd *)data;
908                 break;
909         case TK_M_ENV:
910         case TK_M_ATTR:
911         case TK_M_ATTRS:
912         case TK_A_ATTR:
913         case TK_A_ENV:
914         case TK_A_SECLABEL:
915                 attr = data;
916                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
917                 token->key.attr_off = rules_add_string(rule_tmp->rules, attr);
918                 break;
919         case TK_M_TEST:
920                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
921                 if (data != NULL)
922                         token->key.mode = *(mode_t *)data;
923                 break;
924         case TK_A_STRING_ESCAPE_NONE:
925         case TK_A_STRING_ESCAPE_REPLACE:
926         case TK_A_DB_PERSIST:
927                 break;
928         case TK_A_RUN_BUILTIN:
929         case TK_A_RUN_PROGRAM:
930                 token->key.builtin_cmd = *(enum udev_builtin_cmd *)data;
931                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
932                 break;
933         case TK_A_INOTIFY_WATCH:
934         case TK_A_DEVLINK_PRIO:
935                 token->key.devlink_prio = *(int *)data;
936                 break;
937         case TK_A_OWNER_ID:
938                 token->key.uid = *(uid_t *)data;
939                 break;
940         case TK_A_GROUP_ID:
941                 token->key.gid = *(gid_t *)data;
942                 break;
943         case TK_A_MODE_ID:
944                 token->key.mode = *(mode_t *)data;
945                 break;
946         case TK_A_STATIC_NODE:
947                 token->key.value_off = rules_add_string(rule_tmp->rules, value);
948                 break;
949         case TK_M_EVENT_TIMEOUT:
950                 token->key.event_timeout = *(int *)data;
951                 break;
952         case TK_RULE:
953         case TK_M_PARENTS_MIN:
954         case TK_M_PARENTS_MAX:
955         case TK_M_MAX:
956         case TK_END:
957         case TK_UNSET:
958                 log_error("wrong type %u", type);
959                 return -1;
960         }
961
962         if (value != NULL && type < TK_M_MAX) {
963                 /* check if we need to split or call fnmatch() while matching rules */
964                 enum string_glob_type glob;
965                 int has_split;
966                 int has_glob;
967
968                 has_split = (strchr(value, '|') != NULL);
969                 has_glob = string_is_glob(value);
970                 if (has_split && has_glob) {
971                         glob = GL_SPLIT_GLOB;
972                 } else if (has_split) {
973                         glob = GL_SPLIT;
974                 } else if (has_glob) {
975                         if (streq(value, "?*"))
976                                 glob = GL_SOMETHING;
977                         else
978                                 glob = GL_GLOB;
979                 } else {
980                         glob = GL_PLAIN;
981                 }
982                 token->key.glob = glob;
983         }
984
985         if (value != NULL && type > TK_M_MAX) {
986                 /* check if assigned value has substitution chars */
987                 if (value[0] == '[')
988                         token->key.subst = SB_SUBSYS;
989                 else if (strchr(value, '%') != NULL || strchr(value, '$') != NULL)
990                         token->key.subst = SB_FORMAT;
991                 else
992                         token->key.subst = SB_NONE;
993         }
994
995         if (attr != NULL) {
996                 /* check if property/attribut name has substitution chars */
997                 if (attr[0] == '[')
998                         token->key.attrsubst = SB_SUBSYS;
999                 else if (strchr(attr, '%') != NULL || strchr(attr, '$') != NULL)
1000                         token->key.attrsubst = SB_FORMAT;
1001                 else
1002                         token->key.attrsubst = SB_NONE;
1003         }
1004
1005         token->key.type = type;
1006         token->key.op = op;
1007         rule_tmp->token_cur++;
1008         if (rule_tmp->token_cur >= ELEMENTSOF(rule_tmp->token)) {
1009                 log_error("temporary rule array too small");
1010                 return -1;
1011         }
1012         return 0;
1013 }
1014
1015 static int sort_token(struct udev_rules *rules, struct rule_tmp *rule_tmp)
1016 {
1017         unsigned int i;
1018         unsigned int start = 0;
1019         unsigned int end = rule_tmp->token_cur;
1020
1021         for (i = 0; i < rule_tmp->token_cur; i++) {
1022                 enum token_type next_val = TK_UNSET;
1023                 unsigned int next_idx = 0;
1024                 unsigned int j;
1025
1026                 /* find smallest value */
1027                 for (j = start; j < end; j++) {
1028                         if (rule_tmp->token[j].type == TK_UNSET)
1029                                 continue;
1030                         if (next_val == TK_UNSET || rule_tmp->token[j].type < next_val) {
1031                                 next_val = rule_tmp->token[j].type;
1032                                 next_idx = j;
1033                         }
1034                 }
1035
1036                 /* add token and mark done */
1037                 if (add_token(rules, &rule_tmp->token[next_idx]) != 0)
1038                         return -1;
1039                 rule_tmp->token[next_idx].type = TK_UNSET;
1040
1041                 /* shrink range */
1042                 if (next_idx == start)
1043                         start++;
1044                 if (next_idx+1 == end)
1045                         end--;
1046         }
1047         return 0;
1048 }
1049
1050 static int add_rule(struct udev_rules *rules, char *line,
1051                     const char *filename, unsigned int filename_off, unsigned int lineno)
1052 {
1053         char *linepos;
1054         const char *attr;
1055         struct rule_tmp rule_tmp;
1056
1057         memset(&rule_tmp, 0x00, sizeof(struct rule_tmp));
1058         rule_tmp.rules = rules;
1059         rule_tmp.rule.type = TK_RULE;
1060         /* the offset in the rule is limited to unsigned short */
1061         if (filename_off < USHRT_MAX)
1062                 rule_tmp.rule.rule.filename_off = filename_off;
1063         rule_tmp.rule.rule.filename_line = lineno;
1064
1065         linepos = line;
1066         for (;;) {
1067                 char *key;
1068                 char *value;
1069                 enum operation_type op;
1070
1071                 if (get_key(rules->udev, &linepos, &key, &op, &value) != 0) {
1072                         /* Avoid erroring on trailing whitespace. This is probably rare
1073                          * so save the work for the error case instead of always trying
1074                          * to strip the trailing whitespace with strstrip(). */
1075                         while (isblank(*linepos))
1076                                 linepos++;
1077
1078                         /* If we aren't at the end of the line, this is a parsing error.
1079                          * Make a best effort to describe where the problem is. */
1080                         if (*linepos != '\n') {
1081                                 char buf[2] = {linepos[1]};
1082                                 _cleanup_free_ char *tmp;
1083
1084                                 tmp = cescape(buf);
1085                                 log_error("invalid key/value pair in file %s on line %u,"
1086                                           "starting at character %tu ('%s')\n",
1087                                           filename, lineno, linepos - line + 1, tmp);
1088                                 if (linepos[1] == '#')
1089                                         log_error("hint: comments can only start at beginning of line");
1090                         }
1091                         break;
1092                 }
1093
1094                 if (streq(key, "ACTION")) {
1095                         if (op > OP_MATCH_MAX) {
1096                                 log_error("invalid ACTION operation");
1097                                 goto invalid;
1098                         }
1099                         rule_add_key(&rule_tmp, TK_M_ACTION, op, value, NULL);
1100                         continue;
1101                 }
1102
1103                 if (streq(key, "DEVPATH")) {
1104                         if (op > OP_MATCH_MAX) {
1105                                 log_error("invalid DEVPATH operation");
1106                                 goto invalid;
1107                         }
1108                         rule_add_key(&rule_tmp, TK_M_DEVPATH, op, value, NULL);
1109                         continue;
1110                 }
1111
1112                 if (streq(key, "KERNEL")) {
1113                         if (op > OP_MATCH_MAX) {
1114                                 log_error("invalid KERNEL operation");
1115                                 goto invalid;
1116                         }
1117                         rule_add_key(&rule_tmp, TK_M_KERNEL, op, value, NULL);
1118                         continue;
1119                 }
1120
1121                 if (streq(key, "SUBSYSTEM")) {
1122                         if (op > OP_MATCH_MAX) {
1123                                 log_error("invalid SUBSYSTEM operation");
1124                                 goto invalid;
1125                         }
1126                         /* bus, class, subsystem events should all be the same */
1127                         if (streq(value, "subsystem") ||
1128                             streq(value, "bus") ||
1129                             streq(value, "class")) {
1130                                 if (streq(value, "bus") || streq(value, "class"))
1131                                         log_error("'%s' must be specified as 'subsystem' "
1132                                             "please fix it in %s:%u", value, filename, lineno);
1133                                 rule_add_key(&rule_tmp, TK_M_SUBSYSTEM, op, "subsystem|class|bus", NULL);
1134                         } else
1135                                 rule_add_key(&rule_tmp, TK_M_SUBSYSTEM, op, value, NULL);
1136                         continue;
1137                 }
1138
1139                 if (streq(key, "DRIVER")) {
1140                         if (op > OP_MATCH_MAX) {
1141                                 log_error("invalid DRIVER operation");
1142                                 goto invalid;
1143                         }
1144                         rule_add_key(&rule_tmp, TK_M_DRIVER, op, value, NULL);
1145                         continue;
1146                 }
1147
1148                 if (startswith(key, "ATTR{")) {
1149                         attr = get_key_attribute(rules->udev, key + sizeof("ATTR")-1);
1150                         if (attr == NULL) {
1151                                 log_error("error parsing ATTR attribute");
1152                                 goto invalid;
1153                         }
1154                         if (op < OP_MATCH_MAX) {
1155                                 rule_add_key(&rule_tmp, TK_M_ATTR, op, value, attr);
1156                         } else {
1157                                 rule_add_key(&rule_tmp, TK_A_ATTR, op, value, attr);
1158                         }
1159                         continue;
1160                 }
1161
1162                 if (startswith(key, "SECLABEL{")) {
1163                         attr = get_key_attribute(rules->udev, key + sizeof("SECLABEL")-1);
1164                         if (!attr) {
1165                                 log_error("error parsing SECLABEL attribute");
1166                                 goto invalid;
1167                         }
1168
1169                         rule_add_key(&rule_tmp, TK_A_SECLABEL, op, value, attr);
1170                         continue;
1171                 }
1172
1173                 if (streq(key, "KERNELS")) {
1174                         if (op > OP_MATCH_MAX) {
1175                                 log_error("invalid KERNELS operation");
1176                                 goto invalid;
1177                         }
1178                         rule_add_key(&rule_tmp, TK_M_KERNELS, op, value, NULL);
1179                         continue;
1180                 }
1181
1182                 if (streq(key, "SUBSYSTEMS")) {
1183                         if (op > OP_MATCH_MAX) {
1184                                 log_error("invalid SUBSYSTEMS operation");
1185                                 goto invalid;
1186                         }
1187                         rule_add_key(&rule_tmp, TK_M_SUBSYSTEMS, op, value, NULL);
1188                         continue;
1189                 }
1190
1191                 if (streq(key, "DRIVERS")) {
1192                         if (op > OP_MATCH_MAX) {
1193                                 log_error("invalid DRIVERS operation");
1194                                 goto invalid;
1195                         }
1196                         rule_add_key(&rule_tmp, TK_M_DRIVERS, op, value, NULL);
1197                         continue;
1198                 }
1199
1200                 if (startswith(key, "ATTRS{")) {
1201                         if (op > OP_MATCH_MAX) {
1202                                 log_error("invalid ATTRS operation");
1203                                 goto invalid;
1204                         }
1205                         attr = get_key_attribute(rules->udev, key + sizeof("ATTRS")-1);
1206                         if (attr == NULL) {
1207                                 log_error("error parsing ATTRS attribute");
1208                                 goto invalid;
1209                         }
1210                         if (startswith(attr, "device/"))
1211                                 log_error("the 'device' link may not be available in a future kernel, "
1212                                     "please fix it in %s:%u", filename, lineno);
1213                         else if (strstr(attr, "../") != NULL)
1214                                 log_error("do not reference parent sysfs directories directly, "
1215                                     "it may break with a future kernel, please fix it in %s:%u", filename, lineno);
1216                         rule_add_key(&rule_tmp, TK_M_ATTRS, op, value, attr);
1217                         continue;
1218                 }
1219
1220                 if (streq(key, "TAGS")) {
1221                         if (op > OP_MATCH_MAX) {
1222                                 log_error("invalid TAGS operation");
1223                                 goto invalid;
1224                         }
1225                         rule_add_key(&rule_tmp, TK_M_TAGS, op, value, NULL);
1226                         continue;
1227                 }
1228
1229                 if (startswith(key, "ENV{")) {
1230                         attr = get_key_attribute(rules->udev, key + sizeof("ENV")-1);
1231                         if (attr == NULL) {
1232                                 log_error("error parsing ENV attribute");
1233                                 goto invalid;
1234                         }
1235                         if (op < OP_MATCH_MAX) {
1236                                 if (rule_add_key(&rule_tmp, TK_M_ENV, op, value, attr) != 0)
1237                                         goto invalid;
1238                         } else {
1239                                 static const char *blacklist[] = {
1240                                         "ACTION",
1241                                         "SUBSYSTEM",
1242                                         "DEVTYPE",
1243                                         "MAJOR",
1244                                         "MINOR",
1245                                         "DRIVER",
1246                                         "IFINDEX",
1247                                         "DEVNAME",
1248                                         "DEVLINKS",
1249                                         "DEVPATH",
1250                                         "TAGS",
1251                                 };
1252                                 unsigned int i;
1253
1254                                 for (i = 0; i < ELEMENTSOF(blacklist); i++) {
1255                                         if (!streq(attr, blacklist[i]))
1256                                                 continue;
1257                                         log_error("invalid ENV attribute, '%s' can not be set %s:%u", attr, filename, lineno);
1258                                         goto invalid;
1259                                 }
1260                                 if (rule_add_key(&rule_tmp, TK_A_ENV, op, value, attr) != 0)
1261                                         goto invalid;
1262                         }
1263                         continue;
1264                 }
1265
1266                 if (streq(key, "TAG")) {
1267                         if (op < OP_MATCH_MAX)
1268                                 rule_add_key(&rule_tmp, TK_M_TAG, op, value, NULL);
1269                         else
1270                                 rule_add_key(&rule_tmp, TK_A_TAG, op, value, NULL);
1271                         continue;
1272                 }
1273
1274                 if (streq(key, "PROGRAM")) {
1275                         rule_add_key(&rule_tmp, TK_M_PROGRAM, op, value, NULL);
1276                         continue;
1277                 }
1278
1279                 if (streq(key, "RESULT")) {
1280                         if (op > OP_MATCH_MAX) {
1281                                 log_error("invalid RESULT operation");
1282                                 goto invalid;
1283                         }
1284                         rule_add_key(&rule_tmp, TK_M_RESULT, op, value, NULL);
1285                         continue;
1286                 }
1287
1288                 if (startswith(key, "IMPORT")) {
1289                         attr = get_key_attribute(rules->udev, key + sizeof("IMPORT")-1);
1290                         if (attr == NULL) {
1291                                 log_error("IMPORT{} type missing, ignoring IMPORT %s:%u", filename, lineno);
1292                                 continue;
1293                         }
1294                         if (streq(attr, "program")) {
1295                                 /* find known built-in command */
1296                                 if (value[0] != '/') {
1297                                         enum udev_builtin_cmd cmd;
1298
1299                                         cmd = udev_builtin_lookup(value);
1300                                         if (cmd < UDEV_BUILTIN_MAX) {
1301                                                 log_debug("IMPORT found builtin '%s', replacing %s:%u",
1302                                                           value, filename, lineno);
1303                                                 rule_add_key(&rule_tmp, TK_M_IMPORT_BUILTIN, op, value, &cmd);
1304                                                 continue;
1305                                         }
1306                                 }
1307                                 rule_add_key(&rule_tmp, TK_M_IMPORT_PROG, op, value, NULL);
1308                         } else if (streq(attr, "builtin")) {
1309                                 enum udev_builtin_cmd cmd = udev_builtin_lookup(value);
1310
1311                                 if (cmd < UDEV_BUILTIN_MAX)
1312                                         rule_add_key(&rule_tmp, TK_M_IMPORT_BUILTIN, op, value, &cmd);
1313                                 else
1314                                         log_error("IMPORT{builtin}: '%s' unknown %s:%u", value, filename, lineno);
1315                         } else if (streq(attr, "file")) {
1316                                 rule_add_key(&rule_tmp, TK_M_IMPORT_FILE, op, value, NULL);
1317                         } else if (streq(attr, "db")) {
1318                                 rule_add_key(&rule_tmp, TK_M_IMPORT_DB, op, value, NULL);
1319                         } else if (streq(attr, "cmdline")) {
1320                                 rule_add_key(&rule_tmp, TK_M_IMPORT_CMDLINE, op, value, NULL);
1321                         } else if (streq(attr, "parent")) {
1322                                 rule_add_key(&rule_tmp, TK_M_IMPORT_PARENT, op, value, NULL);
1323                         } else
1324                                 log_error("IMPORT{} unknown type, ignoring IMPORT %s:%u", filename, lineno);
1325                         continue;
1326                 }
1327
1328                 if (startswith(key, "TEST")) {
1329                         mode_t mode = 0;
1330
1331                         if (op > OP_MATCH_MAX) {
1332                                 log_error("invalid TEST operation");
1333                                 goto invalid;
1334                         }
1335                         attr = get_key_attribute(rules->udev, key + sizeof("TEST")-1);
1336                         if (attr != NULL) {
1337                                 mode = strtol(attr, NULL, 8);
1338                                 rule_add_key(&rule_tmp, TK_M_TEST, op, value, &mode);
1339                         } else {
1340                                 rule_add_key(&rule_tmp, TK_M_TEST, op, value, NULL);
1341                         }
1342                         continue;
1343                 }
1344
1345                 if (startswith(key, "RUN")) {
1346                         attr = get_key_attribute(rules->udev, key + sizeof("RUN")-1);
1347                         if (attr == NULL)
1348                                 attr = "program";
1349
1350                         if (streq(attr, "builtin")) {
1351                                 enum udev_builtin_cmd cmd = udev_builtin_lookup(value);
1352
1353                                 if (cmd < UDEV_BUILTIN_MAX)
1354                                         rule_add_key(&rule_tmp, TK_A_RUN_BUILTIN, op, value, &cmd);
1355                                 else
1356                                         log_error("IMPORT{builtin}: '%s' unknown %s:%u", value, filename, lineno);
1357                         } else if (streq(attr, "program")) {
1358                                 enum udev_builtin_cmd cmd = UDEV_BUILTIN_MAX;
1359
1360                                 rule_add_key(&rule_tmp, TK_A_RUN_PROGRAM, op, value, &cmd);
1361                         } else {
1362                                 log_error("RUN{} unknown type, ignoring RUN %s:%u", filename, lineno);
1363                         }
1364
1365                         continue;
1366                 }
1367
1368                 if (streq(key, "WAIT_FOR") || streq(key, "WAIT_FOR_SYSFS")) {
1369                         rule_add_key(&rule_tmp, TK_M_WAITFOR, 0, value, NULL);
1370                         continue;
1371                 }
1372
1373                 if (streq(key, "LABEL")) {
1374                         rule_tmp.rule.rule.label_off = rules_add_string(rules, value);
1375                         continue;
1376                 }
1377
1378                 if (streq(key, "GOTO")) {
1379                         rule_add_key(&rule_tmp, TK_A_GOTO, 0, value, NULL);
1380                         continue;
1381                 }
1382
1383                 if (startswith(key, "NAME")) {
1384                         if (op < OP_MATCH_MAX) {
1385                                 rule_add_key(&rule_tmp, TK_M_NAME, op, value, NULL);
1386                         } else {
1387                                 if (streq(value, "%k")) {
1388                                         log_error("NAME=\"%%k\" is ignored, because it breaks kernel supplied names, "
1389                                             "please remove it from %s:%u\n", filename, lineno);
1390                                         continue;
1391                                 }
1392                                 if (value[0] == '\0') {
1393                                         log_debug("NAME=\"\" is ignored, because udev will not delete any device nodes, "
1394                                                   "please remove it from %s:%u\n", filename, lineno);
1395                                         continue;
1396                                 }
1397                                 rule_add_key(&rule_tmp, TK_A_NAME, op, value, NULL);
1398                         }
1399                         rule_tmp.rule.rule.can_set_name = true;
1400                         continue;
1401                 }
1402
1403                 if (streq(key, "SYMLINK")) {
1404                         if (op < OP_MATCH_MAX)
1405                                 rule_add_key(&rule_tmp, TK_M_DEVLINK, op, value, NULL);
1406                         else
1407                                 rule_add_key(&rule_tmp, TK_A_DEVLINK, op, value, NULL);
1408                         rule_tmp.rule.rule.can_set_name = true;
1409                         continue;
1410                 }
1411
1412                 if (streq(key, "OWNER")) {
1413                         uid_t uid;
1414                         char *endptr;
1415
1416                         uid = strtoul(value, &endptr, 10);
1417                         if (endptr[0] == '\0') {
1418                                 rule_add_key(&rule_tmp, TK_A_OWNER_ID, op, NULL, &uid);
1419                         } else if ((rules->resolve_names > 0) && strchr("$%", value[0]) == NULL) {
1420                                 uid = add_uid(rules, value);
1421                                 rule_add_key(&rule_tmp, TK_A_OWNER_ID, op, NULL, &uid);
1422                         } else if (rules->resolve_names >= 0) {
1423                                 rule_add_key(&rule_tmp, TK_A_OWNER, op, value, NULL);
1424                         }
1425                         rule_tmp.rule.rule.can_set_name = true;
1426                         continue;
1427                 }
1428
1429                 if (streq(key, "GROUP")) {
1430                         gid_t gid;
1431                         char *endptr;
1432
1433                         gid = strtoul(value, &endptr, 10);
1434                         if (endptr[0] == '\0') {
1435                                 rule_add_key(&rule_tmp, TK_A_GROUP_ID, op, NULL, &gid);
1436                         } else if ((rules->resolve_names > 0) && strchr("$%", value[0]) == NULL) {
1437                                 gid = add_gid(rules, value);
1438                                 rule_add_key(&rule_tmp, TK_A_GROUP_ID, op, NULL, &gid);
1439                         } else if (rules->resolve_names >= 0) {
1440                                 rule_add_key(&rule_tmp, TK_A_GROUP, op, value, NULL);
1441                         }
1442                         rule_tmp.rule.rule.can_set_name = true;
1443                         continue;
1444                 }
1445
1446                 if (streq(key, "MODE")) {
1447                         mode_t mode;
1448                         char *endptr;
1449
1450                         mode = strtol(value, &endptr, 8);
1451                         if (endptr[0] == '\0')
1452                                 rule_add_key(&rule_tmp, TK_A_MODE_ID, op, NULL, &mode);
1453                         else
1454                                 rule_add_key(&rule_tmp, TK_A_MODE, op, value, NULL);
1455                         rule_tmp.rule.rule.can_set_name = true;
1456                         continue;
1457                 }
1458
1459                 if (streq(key, "OPTIONS")) {
1460                         const char *pos;
1461
1462                         pos = strstr(value, "link_priority=");
1463                         if (pos != NULL) {
1464                                 int prio = atoi(&pos[strlen("link_priority=")]);
1465
1466                                 rule_add_key(&rule_tmp, TK_A_DEVLINK_PRIO, op, NULL, &prio);
1467                         }
1468
1469                         pos = strstr(value, "event_timeout=");
1470                         if (pos != NULL) {
1471                                 int tout = atoi(&pos[strlen("event_timeout=")]);
1472
1473                                 rule_add_key(&rule_tmp, TK_M_EVENT_TIMEOUT, op, NULL, &tout);
1474                         }
1475
1476                         pos = strstr(value, "string_escape=");
1477                         if (pos != NULL) {
1478                                 pos = &pos[strlen("string_escape=")];
1479                                 if (startswith(pos, "none"))
1480                                         rule_add_key(&rule_tmp, TK_A_STRING_ESCAPE_NONE, op, NULL, NULL);
1481                                 else if (startswith(pos, "replace"))
1482                                         rule_add_key(&rule_tmp, TK_A_STRING_ESCAPE_REPLACE, op, NULL, NULL);
1483                         }
1484
1485                         pos = strstr(value, "db_persist");
1486                         if (pos != NULL)
1487                                 rule_add_key(&rule_tmp, TK_A_DB_PERSIST, op, NULL, NULL);
1488
1489                         pos = strstr(value, "nowatch");
1490                         if (pos != NULL) {
1491                                 const int off = 0;
1492
1493                                 rule_add_key(&rule_tmp, TK_A_INOTIFY_WATCH, op, NULL, &off);
1494                         } else {
1495                                 pos = strstr(value, "watch");
1496                                 if (pos != NULL) {
1497                                         const int on = 1;
1498
1499                                         rule_add_key(&rule_tmp, TK_A_INOTIFY_WATCH, op, NULL, &on);
1500                                 }
1501                         }
1502
1503                         pos = strstr(value, "static_node=");
1504                         if (pos != NULL) {
1505                                 rule_add_key(&rule_tmp, TK_A_STATIC_NODE, op, &pos[strlen("static_node=")], NULL);
1506                                 rule_tmp.rule.rule.has_static_node = true;
1507                         }
1508
1509                         continue;
1510                 }
1511
1512                 log_error("unknown key '%s' in %s:%u", key, filename, lineno);
1513                 goto invalid;
1514         }
1515
1516         /* add rule token */
1517         rule_tmp.rule.rule.token_count = 1 + rule_tmp.token_cur;
1518         if (add_token(rules, &rule_tmp.rule) != 0)
1519                 goto invalid;
1520
1521         /* add tokens to list, sorted by type */
1522         if (sort_token(rules, &rule_tmp) != 0)
1523                 goto invalid;
1524
1525         return 0;
1526 invalid:
1527         log_error("invalid rule '%s:%u'", filename, lineno);
1528         return -1;
1529 }
1530
1531 static int parse_file(struct udev_rules *rules, const char *filename)
1532 {
1533         FILE *f;
1534         unsigned int first_token;
1535         unsigned int filename_off;
1536         char line[UTIL_LINE_SIZE];
1537         int line_nr = 0;
1538         unsigned int i;
1539
1540         if (null_or_empty_path(filename)) {
1541                 log_debug("skip empty file: %s", filename);
1542                 return 0;
1543         }
1544         log_debug("read rules file: %s", filename);
1545
1546         f = fopen(filename, "re");
1547         if (f == NULL)
1548                 return -1;
1549
1550         first_token = rules->token_cur;
1551         filename_off = rules_add_string(rules, filename);
1552
1553         while (fgets(line, sizeof(line), f) != NULL) {
1554                 char *key;
1555                 size_t len;
1556
1557                 /* skip whitespace */
1558                 line_nr++;
1559                 key = line;
1560                 while (isspace(key[0]))
1561                         key++;
1562
1563                 /* comment */
1564                 if (key[0] == '#')
1565                         continue;
1566
1567                 len = strlen(line);
1568                 if (len < 3)
1569                         continue;
1570
1571                 /* continue reading if backslash+newline is found */
1572                 while (line[len-2] == '\\') {
1573                         if (fgets(&line[len-2], (sizeof(line)-len)+2, f) == NULL)
1574                                 break;
1575                         if (strlen(&line[len-2]) < 2)
1576                                 break;
1577                         line_nr++;
1578                         len = strlen(line);
1579                 }
1580
1581                 if (len+1 >= sizeof(line)) {
1582                         log_error("line too long '%s':%u, ignored", filename, line_nr);
1583                         continue;
1584                 }
1585                 add_rule(rules, key, filename, filename_off, line_nr);
1586         }
1587         fclose(f);
1588
1589         /* link GOTOs to LABEL rules in this file to be able to fast-forward */
1590         for (i = first_token+1; i < rules->token_cur; i++) {
1591                 if (rules->tokens[i].type == TK_A_GOTO) {
1592                         char *label = rules_str(rules, rules->tokens[i].key.value_off);
1593                         unsigned int j;
1594
1595                         for (j = i+1; j < rules->token_cur; j++) {
1596                                 if (rules->tokens[j].type != TK_RULE)
1597                                         continue;
1598                                 if (rules->tokens[j].rule.label_off == 0)
1599                                         continue;
1600                                 if (!streq(label, rules_str(rules, rules->tokens[j].rule.label_off)))
1601                                         continue;
1602                                 rules->tokens[i].key.rule_goto = j;
1603                                 break;
1604                         }
1605                         if (rules->tokens[i].key.rule_goto == 0)
1606                                 log_error("GOTO '%s' has no matching label in: '%s'", label, filename);
1607                 }
1608         }
1609         return 0;
1610 }
1611
1612 struct udev_rules *udev_rules_new(struct udev *udev, int resolve_names)
1613 {
1614         struct udev_rules *rules;
1615         struct udev_list file_list;
1616         struct token end_token;
1617         char **files, **f;
1618         int r;
1619
1620         rules = calloc(1, sizeof(struct udev_rules));
1621         if (rules == NULL)
1622                 return NULL;
1623         rules->udev = udev;
1624         rules->resolve_names = resolve_names;
1625         udev_list_init(udev, &file_list, true);
1626
1627         /* init token array and string buffer */
1628         rules->tokens = malloc(PREALLOC_TOKEN * sizeof(struct token));
1629         if (rules->tokens == NULL)
1630                 return udev_rules_unref(rules);
1631         rules->token_max = PREALLOC_TOKEN;
1632
1633         rules->strbuf = strbuf_new();
1634         if (!rules->strbuf)
1635                 return udev_rules_unref(rules);
1636
1637         udev_rules_check_timestamp(rules);
1638
1639         r = conf_files_list_strv(&files, ".rules", NULL, rules_dirs);
1640         if (r < 0) {
1641                 log_error("failed to enumerate rules files: %s", strerror(-r));
1642                 return udev_rules_unref(rules);
1643         }
1644
1645         /*
1646          * The offset value in the rules strct is limited; add all
1647          * rules file names to the beginning of the string buffer.
1648          */
1649         STRV_FOREACH(f, files)
1650                 rules_add_string(rules, *f);
1651
1652         STRV_FOREACH(f, files)
1653                 parse_file(rules, *f);
1654
1655         strv_free(files);
1656
1657         memset(&end_token, 0x00, sizeof(struct token));
1658         end_token.type = TK_END;
1659         add_token(rules, &end_token);
1660         log_debug("rules contain %zu bytes tokens (%u * %zu bytes), %zu bytes strings",
1661                   rules->token_max * sizeof(struct token), rules->token_max, sizeof(struct token), rules->strbuf->len);
1662
1663         /* cleanup temporary strbuf data */
1664         log_debug("%zu strings (%zu bytes), %zu de-duplicated (%zu bytes), %zu trie nodes used",
1665                   rules->strbuf->in_count, rules->strbuf->in_len,
1666                   rules->strbuf->dedup_count, rules->strbuf->dedup_len, rules->strbuf->nodes_count);
1667         strbuf_complete(rules->strbuf);
1668
1669         /* cleanup uid/gid cache */
1670         free(rules->uids);
1671         rules->uids = NULL;
1672         rules->uids_cur = 0;
1673         rules->uids_max = 0;
1674         free(rules->gids);
1675         rules->gids = NULL;
1676         rules->gids_cur = 0;
1677         rules->gids_max = 0;
1678
1679         dump_rules(rules);
1680         return rules;
1681 }
1682
1683 struct udev_rules *udev_rules_unref(struct udev_rules *rules)
1684 {
1685         if (rules == NULL)
1686                 return NULL;
1687         free(rules->tokens);
1688         strbuf_cleanup(rules->strbuf);
1689         free(rules->uids);
1690         free(rules->gids);
1691         free(rules);
1692         return NULL;
1693 }
1694
1695 bool udev_rules_check_timestamp(struct udev_rules *rules)
1696 {
1697         if (!rules)
1698                 return false;
1699
1700         return paths_check_timestamp(rules_dirs, &rules->dirs_ts_usec, true);
1701 }
1702
1703 static int match_key(struct udev_rules *rules, struct token *token, const char *val)
1704 {
1705         char *key_value = rules_str(rules, token->key.value_off);
1706         char *pos;
1707         bool match = false;
1708
1709         if (val == NULL)
1710                 val = "";
1711
1712         switch (token->key.glob) {
1713         case GL_PLAIN:
1714                 match = (streq(key_value, val));
1715                 break;
1716         case GL_GLOB:
1717                 match = (fnmatch(key_value, val, 0) == 0);
1718                 break;
1719         case GL_SPLIT:
1720                 {
1721                         const char *s;
1722                         size_t len;
1723
1724                         s = rules_str(rules, token->key.value_off);
1725                         len = strlen(val);
1726                         for (;;) {
1727                                 const char *next;
1728
1729                                 next = strchr(s, '|');
1730                                 if (next != NULL) {
1731                                         size_t matchlen = (size_t)(next - s);
1732
1733                                         match = (matchlen == len && strneq(s, val, matchlen));
1734                                         if (match)
1735                                                 break;
1736                                 } else {
1737                                         match = (streq(s, val));
1738                                         break;
1739                                 }
1740                                 s = &next[1];
1741                         }
1742                         break;
1743                 }
1744         case GL_SPLIT_GLOB:
1745                 {
1746                         char value[UTIL_PATH_SIZE];
1747
1748                         strscpy(value, sizeof(value), rules_str(rules, token->key.value_off));
1749                         key_value = value;
1750                         while (key_value != NULL) {
1751                                 pos = strchr(key_value, '|');
1752                                 if (pos != NULL) {
1753                                         pos[0] = '\0';
1754                                         pos = &pos[1];
1755                                 }
1756                                 match = (fnmatch(key_value, val, 0) == 0);
1757                                 if (match)
1758                                         break;
1759                                 key_value = pos;
1760                         }
1761                         break;
1762                 }
1763         case GL_SOMETHING:
1764                 match = (val[0] != '\0');
1765                 break;
1766         case GL_UNSET:
1767                 return -1;
1768         }
1769
1770         if (match && (token->key.op == OP_MATCH))
1771                 return 0;
1772         if (!match && (token->key.op == OP_NOMATCH))
1773                 return 0;
1774         return -1;
1775 }
1776
1777 static int match_attr(struct udev_rules *rules, struct udev_device *dev, struct udev_event *event, struct token *cur)
1778 {
1779         const char *name;
1780         char nbuf[UTIL_NAME_SIZE];
1781         const char *value;
1782         char vbuf[UTIL_NAME_SIZE];
1783         size_t len;
1784
1785         name = rules_str(rules, cur->key.attr_off);
1786         switch (cur->key.attrsubst) {
1787         case SB_FORMAT:
1788                 udev_event_apply_format(event, name, nbuf, sizeof(nbuf));
1789                 name = nbuf;
1790                 /* fall through */
1791         case SB_NONE:
1792                 value = udev_device_get_sysattr_value(dev, name);
1793                 if (value == NULL)
1794                         return -1;
1795                 break;
1796         case SB_SUBSYS:
1797                 if (util_resolve_subsys_kernel(event->udev, name, vbuf, sizeof(vbuf), 1) != 0)
1798                         return -1;
1799                 value = vbuf;
1800                 break;
1801         default:
1802                 return -1;
1803         }
1804
1805         /* remove trailing whitespace, if not asked to match for it */
1806         len = strlen(value);
1807         if (len > 0 && isspace(value[len-1])) {
1808                 const char *key_value;
1809                 size_t klen;
1810
1811                 key_value = rules_str(rules, cur->key.value_off);
1812                 klen = strlen(key_value);
1813                 if (klen > 0 && !isspace(key_value[klen-1])) {
1814                         if (value != vbuf) {
1815                                 strscpy(vbuf, sizeof(vbuf), value);
1816                                 value = vbuf;
1817                         }
1818                         while (len > 0 && isspace(vbuf[--len]))
1819                                 vbuf[len] = '\0';
1820                 }
1821         }
1822
1823         return match_key(rules, cur, value);
1824 }
1825
1826 enum escape_type {
1827         ESCAPE_UNSET,
1828         ESCAPE_NONE,
1829         ESCAPE_REPLACE,
1830 };
1831
1832 int udev_rules_apply_to_event(struct udev_rules *rules, struct udev_event *event, const sigset_t *sigmask)
1833 {
1834         struct token *cur;
1835         struct token *rule;
1836         enum escape_type esc = ESCAPE_UNSET;
1837         bool can_set_name;
1838
1839         if (rules->tokens == NULL)
1840                 return -1;
1841
1842         can_set_name = ((!streq(udev_device_get_action(event->dev), "remove")) &&
1843                         (major(udev_device_get_devnum(event->dev)) > 0 ||
1844                          udev_device_get_ifindex(event->dev) > 0));
1845
1846         /* loop through token list, match, run actions or forward to next rule */
1847         cur = &rules->tokens[0];
1848         rule = cur;
1849         for (;;) {
1850                 dump_token(rules, cur);
1851                 switch (cur->type) {
1852                 case TK_RULE:
1853                         /* current rule */
1854                         rule = cur;
1855                         /* possibly skip rules which want to set NAME, SYMLINK, OWNER, GROUP, MODE */
1856                         if (!can_set_name && rule->rule.can_set_name)
1857                                 goto nomatch;
1858                         esc = ESCAPE_UNSET;
1859                         break;
1860                 case TK_M_ACTION:
1861                         if (match_key(rules, cur, udev_device_get_action(event->dev)) != 0)
1862                                 goto nomatch;
1863                         break;
1864                 case TK_M_DEVPATH:
1865                         if (match_key(rules, cur, udev_device_get_devpath(event->dev)) != 0)
1866                                 goto nomatch;
1867                         break;
1868                 case TK_M_KERNEL:
1869                         if (match_key(rules, cur, udev_device_get_sysname(event->dev)) != 0)
1870                                 goto nomatch;
1871                         break;
1872                 case TK_M_DEVLINK: {
1873                         struct udev_list_entry *list_entry;
1874                         bool match = false;
1875
1876                         udev_list_entry_foreach(list_entry, udev_device_get_devlinks_list_entry(event->dev)) {
1877                                 const char *devlink;
1878
1879                                 devlink =  udev_list_entry_get_name(list_entry) + strlen("/dev/");
1880                                 if (match_key(rules, cur, devlink) == 0) {
1881                                         match = true;
1882                                         break;
1883                                 }
1884                         }
1885                         if (!match)
1886                                 goto nomatch;
1887                         break;
1888                 }
1889                 case TK_M_NAME:
1890                         if (match_key(rules, cur, event->name) != 0)
1891                                 goto nomatch;
1892                         break;
1893                 case TK_M_ENV: {
1894                         const char *key_name = rules_str(rules, cur->key.attr_off);
1895                         const char *value;
1896
1897                         value = udev_device_get_property_value(event->dev, key_name);
1898                         if (value == NULL)
1899                                 value = "";
1900                         if (match_key(rules, cur, value))
1901                                 goto nomatch;
1902                         break;
1903                 }
1904                 case TK_M_TAG: {
1905                         struct udev_list_entry *list_entry;
1906                         bool match = false;
1907
1908                         udev_list_entry_foreach(list_entry, udev_device_get_tags_list_entry(event->dev)) {
1909                                 if (streq(rules_str(rules, cur->key.value_off), udev_list_entry_get_name(list_entry))) {
1910                                         match = true;
1911                                         break;
1912                                 }
1913                         }
1914                         if (!match && (cur->key.op != OP_NOMATCH))
1915                                 goto nomatch;
1916                         break;
1917                 }
1918                 case TK_M_SUBSYSTEM:
1919                         if (match_key(rules, cur, udev_device_get_subsystem(event->dev)) != 0)
1920                                 goto nomatch;
1921                         break;
1922                 case TK_M_DRIVER:
1923                         if (match_key(rules, cur, udev_device_get_driver(event->dev)) != 0)
1924                                 goto nomatch;
1925                         break;
1926                 case TK_M_WAITFOR: {
1927                         char filename[UTIL_PATH_SIZE];
1928                         int found;
1929
1930                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), filename, sizeof(filename));
1931                         found = (wait_for_file(event->dev, filename, 10) == 0);
1932                         if (!found && (cur->key.op != OP_NOMATCH))
1933                                 goto nomatch;
1934                         break;
1935                 }
1936                 case TK_M_ATTR:
1937                         if (match_attr(rules, event->dev, event, cur) != 0)
1938                                 goto nomatch;
1939                         break;
1940                 case TK_M_KERNELS:
1941                 case TK_M_SUBSYSTEMS:
1942                 case TK_M_DRIVERS:
1943                 case TK_M_ATTRS:
1944                 case TK_M_TAGS: {
1945                         struct token *next;
1946
1947                         /* get whole sequence of parent matches */
1948                         next = cur;
1949                         while (next->type > TK_M_PARENTS_MIN && next->type < TK_M_PARENTS_MAX)
1950                                 next++;
1951
1952                         /* loop over parents */
1953                         event->dev_parent = event->dev;
1954                         for (;;) {
1955                                 struct token *key;
1956
1957                                 /* loop over sequence of parent match keys */
1958                                 for (key = cur; key < next; key++ ) {
1959                                         dump_token(rules, key);
1960                                         switch(key->type) {
1961                                         case TK_M_KERNELS:
1962                                                 if (match_key(rules, key, udev_device_get_sysname(event->dev_parent)) != 0)
1963                                                         goto try_parent;
1964                                                 break;
1965                                         case TK_M_SUBSYSTEMS:
1966                                                 if (match_key(rules, key, udev_device_get_subsystem(event->dev_parent)) != 0)
1967                                                         goto try_parent;
1968                                                 break;
1969                                         case TK_M_DRIVERS:
1970                                                 if (match_key(rules, key, udev_device_get_driver(event->dev_parent)) != 0)
1971                                                         goto try_parent;
1972                                                 break;
1973                                         case TK_M_ATTRS:
1974                                                 if (match_attr(rules, event->dev_parent, event, key) != 0)
1975                                                         goto try_parent;
1976                                                 break;
1977                                         case TK_M_TAGS: {
1978                                                 bool match = udev_device_has_tag(event->dev_parent, rules_str(rules, cur->key.value_off));
1979
1980                                                 if (match && key->key.op == OP_NOMATCH)
1981                                                         goto try_parent;
1982                                                 if (!match && key->key.op == OP_MATCH)
1983                                                         goto try_parent;
1984                                                 break;
1985                                         }
1986                                         default:
1987                                                 goto nomatch;
1988                                         }
1989                                 }
1990                                 break;
1991
1992                         try_parent:
1993                                 event->dev_parent = udev_device_get_parent(event->dev_parent);
1994                                 if (event->dev_parent == NULL)
1995                                         goto nomatch;
1996                         }
1997                         /* move behind our sequence of parent match keys */
1998                         cur = next;
1999                         continue;
2000                 }
2001                 case TK_M_TEST: {
2002                         char filename[UTIL_PATH_SIZE];
2003                         struct stat statbuf;
2004                         int match;
2005
2006                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), filename, sizeof(filename));
2007                         if (util_resolve_subsys_kernel(event->udev, filename, filename, sizeof(filename), 0) != 0) {
2008                                 if (filename[0] != '/') {
2009                                         char tmp[UTIL_PATH_SIZE];
2010
2011                                         strscpy(tmp, sizeof(tmp), filename);
2012                                         strscpyl(filename, sizeof(filename),
2013                                                       udev_device_get_syspath(event->dev), "/", tmp, NULL);
2014                                 }
2015                         }
2016                         attr_subst_subdir(filename, sizeof(filename));
2017
2018                         match = (stat(filename, &statbuf) == 0);
2019                         if (match && cur->key.mode > 0)
2020                                 match = ((statbuf.st_mode & cur->key.mode) > 0);
2021                         if (match && cur->key.op == OP_NOMATCH)
2022                                 goto nomatch;
2023                         if (!match && cur->key.op == OP_MATCH)
2024                                 goto nomatch;
2025                         break;
2026                 }
2027                 case TK_M_EVENT_TIMEOUT:
2028                         log_debug("OPTIONS event_timeout=%u", cur->key.event_timeout);
2029                         event->timeout_usec = cur->key.event_timeout * 1000 * 1000;
2030                         break;
2031                 case TK_M_PROGRAM: {
2032                         char program[UTIL_PATH_SIZE];
2033                         char **envp;
2034                         char result[UTIL_PATH_SIZE];
2035
2036                         free(event->program_result);
2037                         event->program_result = NULL;
2038                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), program, sizeof(program));
2039                         envp = udev_device_get_properties_envp(event->dev);
2040                         log_debug("PROGRAM '%s' %s:%u",
2041                                   program,
2042                                   rules_str(rules, rule->rule.filename_off),
2043                                   rule->rule.filename_line);
2044
2045                         if (udev_event_spawn(event, program, envp, sigmask, result, sizeof(result)) < 0) {
2046                                 if (cur->key.op != OP_NOMATCH)
2047                                         goto nomatch;
2048                         } else {
2049                                 int count;
2050
2051                                 util_remove_trailing_chars(result, '\n');
2052                                 if (esc == ESCAPE_UNSET || esc == ESCAPE_REPLACE) {
2053                                         count = util_replace_chars(result, UDEV_ALLOWED_CHARS_INPUT);
2054                                         if (count > 0)
2055                                                 log_debug("%i character(s) replaced" , count);
2056                                 }
2057                                 event->program_result = strdup(result);
2058                                 if (cur->key.op == OP_NOMATCH)
2059                                         goto nomatch;
2060                         }
2061                         break;
2062                 }
2063                 case TK_M_IMPORT_FILE: {
2064                         char import[UTIL_PATH_SIZE];
2065
2066                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), import, sizeof(import));
2067                         if (import_file_into_properties(event->dev, import) != 0)
2068                                 if (cur->key.op != OP_NOMATCH)
2069                                         goto nomatch;
2070                         break;
2071                 }
2072                 case TK_M_IMPORT_PROG: {
2073                         char import[UTIL_PATH_SIZE];
2074
2075                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), import, sizeof(import));
2076                         log_debug("IMPORT '%s' %s:%u",
2077                                   import,
2078                                   rules_str(rules, rule->rule.filename_off),
2079                                   rule->rule.filename_line);
2080
2081                         if (import_program_into_properties(event, import, sigmask) != 0)
2082                                 if (cur->key.op != OP_NOMATCH)
2083                                         goto nomatch;
2084                         break;
2085                 }
2086                 case TK_M_IMPORT_BUILTIN: {
2087                         char command[UTIL_PATH_SIZE];
2088
2089                         if (udev_builtin_run_once(cur->key.builtin_cmd)) {
2090                                 /* check if we ran already */
2091                                 if (event->builtin_run & (1 << cur->key.builtin_cmd)) {
2092                                         log_debug("IMPORT builtin skip '%s' %s:%u",
2093                                                   udev_builtin_name(cur->key.builtin_cmd),
2094                                                   rules_str(rules, rule->rule.filename_off),
2095                                                   rule->rule.filename_line);
2096                                         /* return the result from earlier run */
2097                                         if (event->builtin_ret & (1 << cur->key.builtin_cmd))
2098                                         if (cur->key.op != OP_NOMATCH)
2099                                                         goto nomatch;
2100                                         break;
2101                                 }
2102                                 /* mark as ran */
2103                                 event->builtin_run |= (1 << cur->key.builtin_cmd);
2104                         }
2105
2106                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), command, sizeof(command));
2107                         log_debug("IMPORT builtin '%s' %s:%u",
2108                                   udev_builtin_name(cur->key.builtin_cmd),
2109                                   rules_str(rules, rule->rule.filename_off),
2110                                   rule->rule.filename_line);
2111
2112                         if (udev_builtin_run(event->dev, cur->key.builtin_cmd, command, false) != 0) {
2113                                 /* remember failure */
2114                                 log_debug("IMPORT builtin '%s' returned non-zero",
2115                                           udev_builtin_name(cur->key.builtin_cmd));
2116                                 event->builtin_ret |= (1 << cur->key.builtin_cmd);
2117                                 if (cur->key.op != OP_NOMATCH)
2118                                         goto nomatch;
2119                         }
2120                         break;
2121                 }
2122                 case TK_M_IMPORT_DB: {
2123                         const char *key = rules_str(rules, cur->key.value_off);
2124                         const char *value;
2125
2126                         value = udev_device_get_property_value(event->dev_db, key);
2127                         if (value != NULL) {
2128                                 struct udev_list_entry *entry;
2129
2130                                 entry = udev_device_add_property(event->dev, key, value);
2131                                 udev_list_entry_set_num(entry, true);
2132                         } else {
2133                                 if (cur->key.op != OP_NOMATCH)
2134                                         goto nomatch;
2135                         }
2136                         break;
2137                 }
2138                 case TK_M_IMPORT_CMDLINE: {
2139                         FILE *f;
2140                         bool imported = false;
2141
2142                         f = fopen("/proc/cmdline", "re");
2143                         if (f != NULL) {
2144                                 char cmdline[4096];
2145
2146                                 if (fgets(cmdline, sizeof(cmdline), f) != NULL) {
2147                                         const char *key = rules_str(rules, cur->key.value_off);
2148                                         char *pos;
2149
2150                                         pos = strstr(cmdline, key);
2151                                         if (pos != NULL) {
2152                                                 struct udev_list_entry *entry;
2153
2154                                                 pos += strlen(key);
2155                                                 if (pos[0] == '\0' || isspace(pos[0])) {
2156                                                         /* we import simple flags as 'FLAG=1' */
2157                                                         entry = udev_device_add_property(event->dev, key, "1");
2158                                                         udev_list_entry_set_num(entry, true);
2159                                                         imported = true;
2160                                                 } else if (pos[0] == '=') {
2161                                                         const char *value;
2162
2163                                                         pos++;
2164                                                         value = pos;
2165                                                         while (pos[0] != '\0' && !isspace(pos[0]))
2166                                                                 pos++;
2167                                                         pos[0] = '\0';
2168                                                         entry = udev_device_add_property(event->dev, key, value);
2169                                                         udev_list_entry_set_num(entry, true);
2170                                                         imported = true;
2171                                                 }
2172                                         }
2173                                 }
2174                                 fclose(f);
2175                         }
2176                         if (!imported && cur->key.op != OP_NOMATCH)
2177                                 goto nomatch;
2178                         break;
2179                 }
2180                 case TK_M_IMPORT_PARENT: {
2181                         char import[UTIL_PATH_SIZE];
2182
2183                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), import, sizeof(import));
2184                         if (import_parent_into_properties(event->dev, import) != 0)
2185                                 if (cur->key.op != OP_NOMATCH)
2186                                         goto nomatch;
2187                         break;
2188                 }
2189                 case TK_M_RESULT:
2190                         if (match_key(rules, cur, event->program_result) != 0)
2191                                 goto nomatch;
2192                         break;
2193                 case TK_A_STRING_ESCAPE_NONE:
2194                         esc = ESCAPE_NONE;
2195                         break;
2196                 case TK_A_STRING_ESCAPE_REPLACE:
2197                         esc = ESCAPE_REPLACE;
2198                         break;
2199                 case TK_A_DB_PERSIST:
2200                         udev_device_set_db_persist(event->dev);
2201                         break;
2202                 case TK_A_INOTIFY_WATCH:
2203                         if (event->inotify_watch_final)
2204                                 break;
2205                         if (cur->key.op == OP_ASSIGN_FINAL)
2206                                 event->inotify_watch_final = true;
2207                         event->inotify_watch = cur->key.watch;
2208                         break;
2209                 case TK_A_DEVLINK_PRIO:
2210                         udev_device_set_devlink_priority(event->dev, cur->key.devlink_prio);
2211                         break;
2212                 case TK_A_OWNER: {
2213                         char owner[UTIL_NAME_SIZE];
2214
2215                         if (event->owner_final)
2216                                 break;
2217                         if (cur->key.op == OP_ASSIGN_FINAL)
2218                                 event->owner_final = true;
2219                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), owner, sizeof(owner));
2220                         event->owner_set = true;
2221                         event->uid = util_lookup_user(event->udev, owner);
2222                         log_debug("OWNER %u %s:%u",
2223                                   event->uid,
2224                                   rules_str(rules, rule->rule.filename_off),
2225                                   rule->rule.filename_line);
2226                         break;
2227                 }
2228                 case TK_A_GROUP: {
2229                         char group[UTIL_NAME_SIZE];
2230
2231                         if (event->group_final)
2232                                 break;
2233                         if (cur->key.op == OP_ASSIGN_FINAL)
2234                                 event->group_final = true;
2235                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), group, sizeof(group));
2236                         event->group_set = true;
2237                         event->gid = util_lookup_group(event->udev, group);
2238                         log_debug("GROUP %u %s:%u",
2239                                   event->gid,
2240                                   rules_str(rules, rule->rule.filename_off),
2241                                   rule->rule.filename_line);
2242                         break;
2243                 }
2244                 case TK_A_MODE: {
2245                         char mode_str[UTIL_NAME_SIZE];
2246                         mode_t mode;
2247                         char *endptr;
2248
2249                         if (event->mode_final)
2250                                 break;
2251                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), mode_str, sizeof(mode_str));
2252                         mode = strtol(mode_str, &endptr, 8);
2253                         if (endptr[0] != '\0') {
2254                                 log_error("ignoring invalid mode '%s'", mode_str);
2255                                 break;
2256                         }
2257                         if (cur->key.op == OP_ASSIGN_FINAL)
2258                                 event->mode_final = true;
2259                         event->mode_set = true;
2260                         event->mode = mode;
2261                         log_debug("MODE %#o %s:%u",
2262                                   event->mode,
2263                                   rules_str(rules, rule->rule.filename_off),
2264                                   rule->rule.filename_line);
2265                         break;
2266                 }
2267                 case TK_A_OWNER_ID:
2268                         if (event->owner_final)
2269                                 break;
2270                         if (cur->key.op == OP_ASSIGN_FINAL)
2271                                 event->owner_final = true;
2272                         event->owner_set = true;
2273                         event->uid = cur->key.uid;
2274                         log_debug("OWNER %u %s:%u",
2275                                   event->uid,
2276                                   rules_str(rules, rule->rule.filename_off),
2277                                   rule->rule.filename_line);
2278                         break;
2279                 case TK_A_GROUP_ID:
2280                         if (event->group_final)
2281                                 break;
2282                         if (cur->key.op == OP_ASSIGN_FINAL)
2283                                 event->group_final = true;
2284                         event->group_set = true;
2285                         event->gid = cur->key.gid;
2286                         log_debug("GROUP %u %s:%u",
2287                                   event->gid,
2288                                   rules_str(rules, rule->rule.filename_off),
2289                                   rule->rule.filename_line);
2290                         break;
2291                 case TK_A_MODE_ID:
2292                         if (event->mode_final)
2293                                 break;
2294                         if (cur->key.op == OP_ASSIGN_FINAL)
2295                                 event->mode_final = true;
2296                         event->mode_set = true;
2297                         event->mode = cur->key.mode;
2298                         log_debug("MODE %#o %s:%u",
2299                                   event->mode,
2300                                   rules_str(rules, rule->rule.filename_off),
2301                                   rule->rule.filename_line);
2302                         break;
2303                 case TK_A_SECLABEL: {
2304                         const char *name, *label;
2305
2306                         name = rules_str(rules, cur->key.attr_off);
2307                         label = rules_str(rules, cur->key.value_off);
2308                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2309                                 udev_list_cleanup(&event->seclabel_list);
2310                         udev_list_entry_add(&event->seclabel_list, name, label);
2311                         log_debug("SECLABEL{%s}='%s' %s:%u",
2312                                   name, label,
2313                                   rules_str(rules, rule->rule.filename_off),
2314                                   rule->rule.filename_line);
2315                         break;
2316                 }
2317                 case TK_A_ENV: {
2318                         const char *name = rules_str(rules, cur->key.attr_off);
2319                         char *value = rules_str(rules, cur->key.value_off);
2320                         char value_new[UTIL_NAME_SIZE];
2321                         const char *value_old = NULL;
2322                         struct udev_list_entry *entry;
2323
2324                         if (value[0] == '\0') {
2325                                 if (cur->key.op == OP_ADD)
2326                                         break;
2327                                 udev_device_add_property(event->dev, name, NULL);
2328                                 break;
2329                         }
2330
2331                         if (cur->key.op == OP_ADD)
2332                                 value_old = udev_device_get_property_value(event->dev, name);
2333                         if (value_old) {
2334                                 char temp[UTIL_NAME_SIZE];
2335
2336                                 /* append value separated by space */
2337                                 udev_event_apply_format(event, value, temp, sizeof(temp));
2338                                 strscpyl(value_new, sizeof(value_new), value_old, " ", temp, NULL);
2339                         } else
2340                                 udev_event_apply_format(event, value, value_new, sizeof(value_new));
2341
2342                         entry = udev_device_add_property(event->dev, name, value_new);
2343                         /* store in db, skip private keys */
2344                         if (name[0] != '.')
2345                                 udev_list_entry_set_num(entry, true);
2346                         break;
2347                 }
2348                 case TK_A_TAG: {
2349                         char tag[UTIL_PATH_SIZE];
2350                         const char *p;
2351
2352                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), tag, sizeof(tag));
2353                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2354                                 udev_device_cleanup_tags_list(event->dev);
2355                         for (p = tag; *p != '\0'; p++) {
2356                                 if ((*p >= 'a' && *p <= 'z') ||
2357                                     (*p >= 'A' && *p <= 'Z') ||
2358                                     (*p >= '0' && *p <= '9') ||
2359                                     *p == '-' || *p == '_')
2360                                         continue;
2361                                 log_error("ignoring invalid tag name '%s'", tag);
2362                                 break;
2363                         }
2364                         udev_device_add_tag(event->dev, tag);
2365                         break;
2366                 }
2367                 case TK_A_NAME: {
2368                         const char *name  = rules_str(rules, cur->key.value_off);
2369
2370                         char name_str[UTIL_PATH_SIZE];
2371                         int count;
2372
2373                         if (event->name_final)
2374                                 break;
2375                         if (cur->key.op == OP_ASSIGN_FINAL)
2376                                 event->name_final = true;
2377                         udev_event_apply_format(event, name, name_str, sizeof(name_str));
2378                         if (esc == ESCAPE_UNSET || esc == ESCAPE_REPLACE) {
2379                                 count = util_replace_chars(name_str, "/");
2380                                 if (count > 0)
2381                                         log_debug("%i character(s) replaced", count);
2382                         }
2383                         if (major(udev_device_get_devnum(event->dev)) &&
2384                             (!streq(name_str, udev_device_get_devnode(event->dev) + strlen("/dev/")))) {
2385                                 log_error("NAME=\"%s\" ignored, kernel device nodes "
2386                                     "can not be renamed; please fix it in %s:%u\n", name,
2387                                     rules_str(rules, rule->rule.filename_off), rule->rule.filename_line);
2388                                 break;
2389                         }
2390                         free(event->name);
2391                         event->name = strdup(name_str);
2392                         log_debug("NAME '%s' %s:%u",
2393                                   event->name,
2394                                   rules_str(rules, rule->rule.filename_off),
2395                                   rule->rule.filename_line);
2396                         break;
2397                 }
2398                 case TK_A_DEVLINK: {
2399                         char temp[UTIL_PATH_SIZE];
2400                         char filename[UTIL_PATH_SIZE];
2401                         char *pos, *next;
2402                         int count = 0;
2403
2404                         if (event->devlink_final)
2405                                 break;
2406                         if (major(udev_device_get_devnum(event->dev)) == 0)
2407                                 break;
2408                         if (cur->key.op == OP_ASSIGN_FINAL)
2409                                 event->devlink_final = true;
2410                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2411                                 udev_device_cleanup_devlinks_list(event->dev);
2412
2413                         /* allow  multiple symlinks separated by spaces */
2414                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), temp, sizeof(temp));
2415                         if (esc == ESCAPE_UNSET)
2416                                 count = util_replace_chars(temp, "/ ");
2417                         else if (esc == ESCAPE_REPLACE)
2418                                 count = util_replace_chars(temp, "/");
2419                         if (count > 0)
2420                                 log_debug("%i character(s) replaced" , count);
2421                         pos = temp;
2422                         while (isspace(pos[0]))
2423                                 pos++;
2424                         next = strchr(pos, ' ');
2425                         while (next != NULL) {
2426                                 next[0] = '\0';
2427                                 log_debug("LINK '%s' %s:%u", pos,
2428                                           rules_str(rules, rule->rule.filename_off), rule->rule.filename_line);
2429                                 strscpyl(filename, sizeof(filename), "/dev/", pos, NULL);
2430                                 udev_device_add_devlink(event->dev, filename);
2431                                 while (isspace(next[1]))
2432                                         next++;
2433                                 pos = &next[1];
2434                                 next = strchr(pos, ' ');
2435                         }
2436                         if (pos[0] != '\0') {
2437                                 log_debug("LINK '%s' %s:%u", pos,
2438                                           rules_str(rules, rule->rule.filename_off), rule->rule.filename_line);
2439                                 strscpyl(filename, sizeof(filename), "/dev/", pos, NULL);
2440                                 udev_device_add_devlink(event->dev, filename);
2441                         }
2442                         break;
2443                 }
2444                 case TK_A_ATTR: {
2445                         const char *key_name = rules_str(rules, cur->key.attr_off);
2446                         char attr[UTIL_PATH_SIZE];
2447                         char value[UTIL_NAME_SIZE];
2448                         FILE *f;
2449
2450                         if (util_resolve_subsys_kernel(event->udev, key_name, attr, sizeof(attr), 0) != 0)
2451                                 strscpyl(attr, sizeof(attr), udev_device_get_syspath(event->dev), "/", key_name, NULL);
2452                         attr_subst_subdir(attr, sizeof(attr));
2453
2454                         udev_event_apply_format(event, rules_str(rules, cur->key.value_off), value, sizeof(value));
2455                         log_debug("ATTR '%s' writing '%s' %s:%u", attr, value,
2456                                   rules_str(rules, rule->rule.filename_off),
2457                                   rule->rule.filename_line);
2458                         f = fopen(attr, "we");
2459                         if (f != NULL) {
2460                                 if (fprintf(f, "%s", value) <= 0)
2461                                         log_error("error writing ATTR{%s}: %m", attr);
2462                                 fclose(f);
2463                         } else {
2464                                 log_error("error opening ATTR{%s} for writing: %m", attr);
2465                         }
2466                         break;
2467                 }
2468                 case TK_A_RUN_BUILTIN:
2469                 case TK_A_RUN_PROGRAM: {
2470                         struct udev_list_entry *entry;
2471
2472                         if (cur->key.op == OP_ASSIGN || cur->key.op == OP_ASSIGN_FINAL)
2473                                 udev_list_cleanup(&event->run_list);
2474                         log_debug("RUN '%s' %s:%u",
2475                                   rules_str(rules, cur->key.value_off),
2476                                   rules_str(rules, rule->rule.filename_off),
2477                                   rule->rule.filename_line);
2478                         entry = udev_list_entry_add(&event->run_list, rules_str(rules, cur->key.value_off), NULL);
2479                         udev_list_entry_set_num(entry, cur->key.builtin_cmd);
2480                         break;
2481                 }
2482                 case TK_A_GOTO:
2483                         if (cur->key.rule_goto == 0)
2484                                 break;
2485                         cur = &rules->tokens[cur->key.rule_goto];
2486                         continue;
2487                 case TK_END:
2488                         return 0;
2489
2490                 case TK_M_PARENTS_MIN:
2491                 case TK_M_PARENTS_MAX:
2492                 case TK_M_MAX:
2493                 case TK_UNSET:
2494                         log_error("wrong type %u", cur->type);
2495                         goto nomatch;
2496                 }
2497
2498                 cur++;
2499                 continue;
2500         nomatch:
2501                 /* fast-forward to next rule */
2502                 cur = rule + rule->rule.token_count;
2503         }
2504 }
2505
2506 int udev_rules_apply_static_dev_perms(struct udev_rules *rules)
2507 {
2508         struct token *cur;
2509         struct token *rule;
2510         uid_t uid = 0;
2511         gid_t gid = 0;
2512         mode_t mode = 0;
2513         _cleanup_strv_free_ char **tags = NULL;
2514         char **t;
2515         FILE *f = NULL;
2516         _cleanup_free_ char *path = NULL;
2517         int r = 0;
2518
2519         if (rules->tokens == NULL)
2520                 return 0;
2521
2522         cur = &rules->tokens[0];
2523         rule = cur;
2524         for (;;) {
2525                 switch (cur->type) {
2526                 case TK_RULE:
2527                         /* current rule */
2528                         rule = cur;
2529
2530                         /* skip rules without a static_node tag */
2531                         if (!rule->rule.has_static_node)
2532                                 goto next;
2533
2534                         uid = 0;
2535                         gid = 0;
2536                         mode = 0;
2537                         strv_free(tags);
2538                         tags = NULL;
2539                         break;
2540                 case TK_A_OWNER_ID:
2541                         uid = cur->key.uid;
2542                         break;
2543                 case TK_A_GROUP_ID:
2544                         gid = cur->key.gid;
2545                         break;
2546                 case TK_A_MODE_ID:
2547                         mode = cur->key.mode;
2548                         break;
2549                 case TK_A_TAG:
2550                         r = strv_extend(&tags, rules_str(rules, cur->key.value_off));
2551                         if (r < 0)
2552                                 goto finish;
2553
2554                         break;
2555                 case TK_A_STATIC_NODE: {
2556                         char device_node[UTIL_PATH_SIZE];
2557                         char tags_dir[UTIL_PATH_SIZE];
2558                         char tag_symlink[UTIL_PATH_SIZE];
2559                         struct stat stats;
2560
2561                         /* we assure, that the permissions tokens are sorted before the static token */
2562                         if (mode == 0 && uid == 0 && gid == 0 && tags == NULL)
2563                                 goto next;
2564                         strscpyl(device_node, sizeof(device_node), "/dev/", rules_str(rules, cur->key.value_off), NULL);
2565                         if (stat(device_node, &stats) != 0)
2566                                 goto next;
2567                         if (!S_ISBLK(stats.st_mode) && !S_ISCHR(stats.st_mode))
2568                                 goto next;
2569
2570                         if (tags) {
2571                                 /* Export the tags to a directory as symlinks, allowing otherwise dead nodes to be tagged */
2572
2573                                 STRV_FOREACH(t, tags) {
2574                                         _cleanup_free_ char *unescaped_filename = NULL;
2575
2576                                         strscpyl(tags_dir, sizeof(tags_dir), "/run/udev/static_node-tags/", *t, "/", NULL);
2577                                         r = mkdir_p(tags_dir, 0755);
2578                                         if (r < 0) {
2579                                                 log_error("failed to create %s: %s", tags_dir, strerror(-r));
2580                                                 return r;
2581                                         }
2582
2583                                         unescaped_filename = xescape(rules_str(rules, cur->key.value_off), "/.");
2584
2585                                         strscpyl(tag_symlink, sizeof(tag_symlink), tags_dir, unescaped_filename, NULL);
2586                                         r = symlink(device_node, tag_symlink);
2587                                         if (r < 0 && errno != EEXIST) {
2588                                                 log_error("failed to create symlink %s -> %s: %m", tag_symlink, device_node);
2589                                                 return -errno;
2590                                         } else
2591                                                 r = 0;
2592                                 }
2593                         }
2594
2595                         /* don't touch the permissions if only the tags were set */
2596                         if (mode == 0 && uid == 0 && gid == 0)
2597                                 goto next;
2598
2599                         if (mode == 0) {
2600                                 if (gid > 0)
2601                                         mode = 0660;
2602                                 else
2603                                         mode = 0600;
2604                         }
2605                         if (mode != (stats.st_mode & 01777)) {
2606                                 r = chmod(device_node, mode);
2607                                 if (r < 0) {
2608                                         log_error("failed to chmod '%s' %#o", device_node, mode);
2609                                         return -errno;
2610                                 } else
2611                                         log_debug("chmod '%s' %#o", device_node, mode);
2612                         }
2613
2614                         if ((uid != 0 && uid != stats.st_uid) || (gid != 0 && gid != stats.st_gid)) {
2615                                 r = chown(device_node, uid, gid);
2616                                 if (r < 0) {
2617                                         log_error("failed to chown '%s' %u %u ", device_node, uid, gid);
2618                                         return -errno;
2619                                 } else
2620                                         log_debug("chown '%s' %u %u", device_node, uid, gid);
2621                         }
2622
2623                         utimensat(AT_FDCWD, device_node, NULL, 0);
2624                         break;
2625                 }
2626                 case TK_END:
2627                         goto finish;
2628                 }
2629
2630                 cur++;
2631                 continue;
2632 next:
2633                 /* fast-forward to next rule */
2634                 cur = rule + rule->rule.token_count;
2635                 continue;
2636         }
2637
2638 finish:
2639         if (f) {
2640                 fflush(f);
2641                 fchmod(fileno(f), 0644);
2642                 if (ferror(f) || rename(path, "/run/udev/static_node-tags") < 0) {
2643                         r = -errno;
2644                         unlink("/run/udev/static_node-tags");
2645                         unlink(path);
2646                 }
2647                 fclose(f);
2648         }
2649
2650         return r;
2651 }