xref: /freebsd/sbin/devfs/devfs.8 (revision d54277a7)
1a1dc2096SDima Dorfman.\"
2a1dc2096SDima Dorfman.\" Copyright (c) 2002 Dima Dorfman.
3a1dc2096SDima Dorfman.\" All rights reserved.
4a1dc2096SDima Dorfman.\"
5a1dc2096SDima Dorfman.\" Redistribution and use in source and binary forms, with or without
6a1dc2096SDima Dorfman.\" modification, are permitted provided that the following conditions
7a1dc2096SDima Dorfman.\" are met:
8a1dc2096SDima Dorfman.\" 1. Redistributions of source code must retain the above copyright
9a1dc2096SDima Dorfman.\"    notice, this list of conditions and the following disclaimer.
10a1dc2096SDima Dorfman.\" 2. Redistributions in binary form must reproduce the above copyright
11a1dc2096SDima Dorfman.\"    notice, this list of conditions and the following disclaimer in the
12a1dc2096SDima Dorfman.\"    documentation and/or other materials provided with the distribution.
13a1dc2096SDima Dorfman.\"
14a1dc2096SDima Dorfman.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15a1dc2096SDima Dorfman.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16a1dc2096SDima Dorfman.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17a1dc2096SDima Dorfman.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18a1dc2096SDima Dorfman.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19a1dc2096SDima Dorfman.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20a1dc2096SDima Dorfman.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21a1dc2096SDima Dorfman.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22a1dc2096SDima Dorfman.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23a1dc2096SDima Dorfman.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
24a1dc2096SDima Dorfman.\" SUCH DAMAGE.
25a1dc2096SDima Dorfman.\"
26a1dc2096SDima Dorfman.\" $FreeBSD$
27a1dc2096SDima Dorfman.\"
28a1dc2096SDima Dorfman.Dd July 1, 2002
297ba06023SRuslan Ermilov.Dt DEVFS 8
30a1dc2096SDima Dorfman.Os
31a1dc2096SDima Dorfman.Sh NAME
32a1dc2096SDima Dorfman.Nm devfs
33a1dc2096SDima Dorfman.Nd "DEVFS control"
34a1dc2096SDima Dorfman.Sh SYNOPSIS
35a1dc2096SDima Dorfman.Nm
36a1dc2096SDima Dorfman.Op Fl m Ar mount-point
377ba06023SRuslan Ermilov.Ar keyword
38a1dc2096SDima Dorfman.Ar argument ...
39a1dc2096SDima Dorfman.Sh DESCRIPTION
40a1dc2096SDima DorfmanThe
41a1dc2096SDima Dorfman.Nm
42a1dc2096SDima Dorfmanutility provides an interface to manipulate properties of
43a1dc2096SDima Dorfman.Xr devfs 5
44a1dc2096SDima Dorfmanmounts.
45a1dc2096SDima Dorfman.Pp
46*d54277a7SSimon L. B. NielsenThe
47*d54277a7SSimon L. B. Nielsen.Ar keyword
48*d54277a7SSimon L. B. Nielsenargument determines the context for
49a1dc2096SDima Dorfmanthe rest of the arguments.
50a1dc2096SDima DorfmanFor example,
51a1dc2096SDima Dorfmanmost of the commands related to the rule subsystem must be preceded by the
52a1dc2096SDima Dorfman.Cm rule
53a1dc2096SDima Dorfmankeyword.
54a1dc2096SDima DorfmanThe following flags are common to all keywords:
55a1dc2096SDima Dorfman.Bl -tag -offset indent
56a1dc2096SDima Dorfman.It Fl m Ar mount-point
57a1dc2096SDima DorfmanOperate on
58a1dc2096SDima Dorfman.Ar mount-point ,
59a1dc2096SDima Dorfmanwhich is expected to be a
60a1dc2096SDima Dorfman.Xr devfs 5
61a1dc2096SDima Dorfmanmount.
62a1dc2096SDima DorfmanIf this option is not specified,
63a1dc2096SDima Dorfman.Nm
64a1dc2096SDima Dorfmanoperates on
65a1dc2096SDima Dorfman.Pa /dev .
66a1dc2096SDima Dorfman.El
67014c2ea5SDima Dorfman.Ss Rule Subsystem
68a1dc2096SDima DorfmanThe
69a1dc2096SDima Dorfman.Xr devfs 5
70a1dc2096SDima Dorfmanrule subsystem provides a way for the administrator of a system to control
71a1dc2096SDima Dorfmanthe attributes of DEVFS nodes.
72a1dc2096SDima Dorfman.\" XXX devfs node?  entry?  what?
73a1dc2096SDima DorfmanEach DEVFS mount-point has a
74a1dc2096SDima Dorfman.Dq ruleset ,
75a1dc2096SDima Dorfmanor a list of rules,
76a1dc2096SDima Dorfmanassociated with it.
77a1dc2096SDima DorfmanWhen a device driver creates a new node,
78a1dc2096SDima Dorfmanall the rules in the ruleset associated with each mount-point are applied
79a1dc2096SDima Dorfman(see below) before the node becomes visible to the userland.
80a1dc2096SDima DorfmanThis permits the administrator to change the properties,
81a1dc2096SDima Dorfmanincluding the visibility,
82a1dc2096SDima Dorfmanof certain nodes.
83a1dc2096SDima DorfmanFor example, one might want to hide all disk nodes in a
84a1dc2096SDima Dorfman.Xr jail 2 Ns 's
85a1dc2096SDima Dorfman.Pa /dev .
86a1dc2096SDima Dorfman.Ss Rule Manipulation
87a1dc2096SDima DorfmanRule manipulation commands follow the
88a1dc2096SDima Dorfman.Cm rule
89a1dc2096SDima Dorfmankeyword.
90a1dc2096SDima DorfmanThe following flags are common to all of the rule manipulation commands:
91a1dc2096SDima Dorfman.Bl -tag -offset indent
92a1dc2096SDima Dorfman.It Fl s Ar ruleset
93a1dc2096SDima DorfmanOperate on the ruleset with the number
94a1dc2096SDima Dorfman.Ar ruleset .
95a1dc2096SDima DorfmanIf this is not specified,
96a1dc2096SDima Dorfmanthe commands operate on the ruleset currently associated with the
97a1dc2096SDima Dorfmanspecified mount-point.
98a1dc2096SDima Dorfman.El
99a1dc2096SDima Dorfman.Pp
100a1dc2096SDima DorfmanThe following commands are recognized:
101a1dc2096SDima Dorfman.Bl -tag -offset indent
102a1dc2096SDima Dorfman.It Cm rule add Oo Ar rulenum Oc Ar rulespec
103a1dc2096SDima DorfmanAdd the rule described by
104a1dc2096SDima Dorfman.Ar rulespec
105a1dc2096SDima Dorfman(defined below)
106a1dc2096SDima Dorfmanto the ruleset.
107a1dc2096SDima DorfmanThe rule has the number
108a1dc2096SDima Dorfman.Ar rulenum
109a1dc2096SDima Dorfmanif it is explicitly specified;
110a1dc2096SDima Dorfmanotherwise, the rule number is automatically determined by the kernel.
1117ba06023SRuslan Ermilov.It Cm rule apply Ar rulenum | rulespec
112a1dc2096SDima DorfmanApply rule number
113a1dc2096SDima Dorfman.Ar rulenum
114a1dc2096SDima Dorfmanor the rule described by
115a1dc2096SDima Dorfman.Ar rulespec
116a1dc2096SDima Dorfmanto the mount-point.
1177ba06023SRuslan ErmilovRules that are
1187ba06023SRuslan Ermilov.Dq applied
1197ba06023SRuslan Ermilovhave their conditions checked against all nodes
120a1dc2096SDima Dorfmanin the mount-point, and the actions taken if they match.
121a1dc2096SDima Dorfman.It Cm rule applyset
122a1dc2096SDima DorfmanApply all the rules in the ruleset to the mount-point
1237ba06023SRuslan Ermilov(see above for the definition of
1247ba06023SRuslan Ermilov.Dq apply ) .
125a1dc2096SDima Dorfman.It Cm rule del Ar rulenum
126a1dc2096SDima DorfmanDelete rule number
127a1dc2096SDima Dorfman.Ar rulenum
128a1dc2096SDima Dorfmanfrom the ruleset.
129a1dc2096SDima Dorfman.It Cm rule delset
130a1dc2096SDima DorfmanDelete all rules from the ruleset.
131a1dc2096SDima Dorfman.It Cm rule show Op Ar rulenum
132a1dc2096SDima DorfmanDisplay the rule number
133a1dc2096SDima Dorfman.Ar rulenum ,
134a1dc2096SDima Dorfmanor all the rules in the ruleset.
135a1dc2096SDima DorfmanThe output lines (one line per rule) are expected to be valid
136a1dc2096SDima Dorfman.Ar rulespec Ns s .
137a1dc2096SDima Dorfman.It Cm rule showsets
138a1dc2096SDima DorfmanReport the numbers of existing rulesets.
139a1dc2096SDima Dorfman.It Cm ruleset Ar ruleset
140a1dc2096SDima DorfmanSet ruleset number
141a1dc2096SDima Dorfman.Ar ruleset
142a1dc2096SDima Dorfmanas the current ruleset for the mount-point.
143a1dc2096SDima Dorfman.El
144a1dc2096SDima Dorfman.Ss Rule Specification
145a1dc2096SDima DorfmanRules have two parts: the conditions and the actions.
146a1dc2096SDima DorfmanThe conditions determine which DEVFS nodes the rule matches,
147a1dc2096SDima Dorfmanand the actions determine what should be done when a rule matches a node.
148a1dc2096SDima DorfmanFor example, a rule can be written that sets the GID to
1497ba06023SRuslan Ermilov.Dq Li games
150a1dc2096SDima Dorfmanfor all devices with major number 53.
151072af151SDima DorfmanIf the first token of a rule specification is a single dash
1527ba06023SRuslan Ermilov.Pq Sq Fl ,
153072af151SDima Dorfmanrules are read from the standard input and the rest of the specification
154072af151SDima Dorfmanis ignored.
155a1dc2096SDima Dorfman.Pp
156a1dc2096SDima DorfmanThe following conditions are recognized.
157a1dc2096SDima DorfmanConditions are ANDed together when matching a device;
158a1dc2096SDima Dorfmanif OR is desired, multiple rules can be written.
159a1dc2096SDima Dorfman.Bl -tag -offset indent
160a1dc2096SDima Dorfman.It Cm major Ar majdev
161a1dc2096SDima DorfmanMatches any node with a major number equal to
162a1dc2096SDima Dorfman.Ar majdev .
163a1dc2096SDima Dorfman.It Cm path Ar pattern
164a1dc2096SDima DorfmanMatches any node with a path that matches
165a1dc2096SDima Dorfman.Ar pattern .
166a1dc2096SDima DorfmanThe latter is interpreted as a
167a1dc2096SDima Dorfman.Xr glob 3 Ns -style
168a1dc2096SDima Dorfmanpattern.
169a1dc2096SDima Dorfman.It Cm type Ar devtype
170a1dc2096SDima DorfmanMatches any node that is of type
171a1dc2096SDima Dorfman.Ar devtype .
172a1dc2096SDima DorfmanValid types are
1737ba06023SRuslan Ermilov.Cm disk , mem , tape
174a1dc2096SDima Dorfmanand
1757ba06023SRuslan Ermilov.Cm tty .
176a1dc2096SDima Dorfman.El
177a1dc2096SDima Dorfman.Pp
178a1dc2096SDima DorfmanThe following actions are recognized.
179a1dc2096SDima DorfmanAlthough there is no explicit delimiter between conditions and actions,
180a1dc2096SDima Dorfmanthey may not be intermixed.
181a1dc2096SDima Dorfman.Bl -tag -offset indent
182a1dc2096SDima Dorfman.It Cm group Ar gid
183a1dc2096SDima DorfmanSet the GID of the node to
184a1dc2096SDima Dorfman.Ar gid ,
185a1dc2096SDima Dorfmanwhich may be a group name
186a1dc2096SDima Dorfman(looked up in
187a1dc2096SDima Dorfman.Pa /etc/group )
188a1dc2096SDima Dorfmanor number.
189a1dc2096SDima Dorfman.It Cm hide
190a1dc2096SDima DorfmanHide the node.
191a1dc2096SDima DorfmanNodes may later be revived manually with
192a1dc2096SDima Dorfman.Xr mknod 8 ,
193a1dc2096SDima Dorfmanor with the
194a1dc2096SDima Dorfman.Cm unhide
195a1dc2096SDima Dorfmanaction.
196a1dc2096SDima Dorfman.It Cm include Ar ruleset
197a1dc2096SDima DorfmanApply all the rules in ruleset number
198a1dc2096SDima Dorfman.Ar ruleset
199a1dc2096SDima Dorfmanto the node.
200a1dc2096SDima DorfmanThis does not necessarily result in any changes to the node
201a1dc2096SDima Dorfman(e.g., if none of the rules in the included ruleset match).
202a1dc2096SDima Dorfman.It Cm mode Ar filemode
203a1dc2096SDima DorfmanSet the file mode to
204a1dc2096SDima Dorfman.Ar filemode ,
205a1dc2096SDima Dorfmanwhich is interpreted in octal.
206a1dc2096SDima Dorfman.It Cm user Ar uid
207a1dc2096SDima DorfmanSet the UID to
208a1dc2096SDima Dorfman.Ar uid ,
209a1dc2096SDima Dorfmanwhich may be a user name
210a1dc2096SDima Dorfman(looked up in
211a1dc2096SDima Dorfman.Pa /etc/passwd )
212a1dc2096SDima Dorfmanor number.
213a1dc2096SDima Dorfman.It Cm unhide
214a1dc2096SDima DorfmanUnhide the node.
215a1dc2096SDima Dorfman.El
216014c2ea5SDima Dorfman.Sh IMPLEMENTATION NOTES
217a1dc2096SDima DorfmanRulesets are created by the kernel at the first reference,
218a1dc2096SDima Dorfmanand destroyed when the last reference disappears.
219a1dc2096SDima DorfmanE.g., a ruleset is created when a rule is added to it or when it is set
220a1dc2096SDima Dorfmanas the current ruleset for a mount-point;
221a1dc2096SDima Dorfmana ruleset is destroyed when the last rule in it is deleted,
222a1dc2096SDima Dorfmanand no other references to it exist
223a1dc2096SDima Dorfman(i.e., it is not included by any rules, and it is not the current ruleset
224a1dc2096SDima Dorfmanfor any mount-point).
225014c2ea5SDima Dorfman.Pp
226a1dc2096SDima DorfmanRuleset number 0 is the default ruleset for all new mount-points.
227a1dc2096SDima DorfmanIt is always empty, cannot be modified or deleted, and does not show up
228a1dc2096SDima Dorfmanin the output of
229a1dc2096SDima Dorfman.Cm showsets .
230014c2ea5SDima Dorfman.Pp
231a1dc2096SDima DorfmanRules and rulesets are unique to the entire system,
232a1dc2096SDima Dorfmannot a particular mount-point.
233a1dc2096SDima DorfmanI.e., a
234a1dc2096SDima Dorfman.Cm showsets
235a1dc2096SDima Dorfmanwill return the same information regardless of the mount-point specified with
236a1dc2096SDima Dorfman.Fl m .
237a1dc2096SDima DorfmanThe mount-point is only relevant when changing what its current ruleset is,
238a1dc2096SDima Dorfmanor when using one of the apply commands.
239014c2ea5SDima Dorfman.Sh EXAMPLES
240a1dc2096SDima DorfmanWhen the system boots,
241a1dc2096SDima Dorfmanthe only ruleset that exists is ruleset number 0;
242a1dc2096SDima Dorfmansince the latter may not be modified, we have to create another ruleset
243a1dc2096SDima Dorfmanbefore adding rules.
2447ba06023SRuslan ErmilovNote that since most of the following examples do not specify
245a1dc2096SDima Dorfman.Fl m ,
246a1dc2096SDima Dorfmanthe operations are performed on
247a1dc2096SDima Dorfman.Pa /dev
248a1dc2096SDima Dorfman(this only matters for things that might change the properties of nodes).
249a1dc2096SDima Dorfman.Pp
2507ba06023SRuslan Ermilov.Dl "devfs ruleset 10"
251a1dc2096SDima Dorfman.Pp
252a1dc2096SDima DorfmanSpecify that ruleset 10 should be the current ruleset for
253a1dc2096SDima Dorfman.Pa /dev
254a1dc2096SDima Dorfman(if it does not already exist, it is created).
255a1dc2096SDima Dorfman.Pp
2567ba06023SRuslan Ermilov.Dl "devfs rule add path speaker mode 666"
257a1dc2096SDima Dorfman.Pp
258a1dc2096SDima DorfmanAdd a rule that causes all nodes that have a path that matches
2597ba06023SRuslan Ermilov.Dq Li speaker
260a1dc2096SDima Dorfman(this is only
261a1dc2096SDima Dorfman.Pa /dev/speaker )
262a1dc2096SDima Dorfmanto have the file mode 666 (read and write for all).
263a1dc2096SDima DorfmanNote that if any such nodes already exist, their mode will not be changed
264a1dc2096SDima Dorfmanunless this rule (or ruleset) is explicitly applied (see below).
265a1dc2096SDima DorfmanThe mode
266a1dc2096SDima Dorfman.Em will
267a1dc2096SDima Dorfmanbe changed if the node is created
268a1dc2096SDima Dorfman.Em after
269a1dc2096SDima Dorfmanthe rule is added
270a1dc2096SDima Dorfman(e.g., the
271a1dc2096SDima Dorfman.Pa atspeaker
272a1dc2096SDima Dorfmanmodule is loaded after the above rule is added).
273a1dc2096SDima Dorfman.Pp
2747ba06023SRuslan Ermilov.Dl "devfs rule applyset"
275a1dc2096SDima Dorfman.Pp
276a1dc2096SDima DorfmanApply all the rules in the current ruleset to all the existing nodes.
277a1dc2096SDima DorfmanE.g., if the above rule was added after
278a1dc2096SDima Dorfman.Pa /dev/speaker
279a1dc2096SDima Dorfmanwas created,
280a1dc2096SDima Dorfmanthis command will cause its file mode to be changed to 666,
281a1dc2096SDima Dorfmanas rule rule prescribes.
282a1dc2096SDima Dorfman.Pp
283a1dc2096SDima Dorfman.Dl devfs rule add path "snp*" mode 660 group snoopers
284a1dc2096SDima Dorfman.Pp
285a1dc2096SDima Dorfman(Quoting the argument to
286a1dc2096SDima Dorfman.Cm path
287a1dc2096SDima Dorfmanis often necessary to disable the shell's globbing features.)
2887ba06023SRuslan ErmilovFor all devices with a path that matches
2897ba06023SRuslan Ermilov.Dq Li snp* ,
290a1dc2096SDima Dorfmanset the file more to 660, and the GID to
2917ba06023SRuslan Ermilov.Dq Li snoopers .
292a1dc2096SDima DorfmanThis permits users in the
2937ba06023SRuslan Ermilov.Dq Li snoopers
294a1dc2096SDima Dorfmangroup to use the
295a1dc2096SDima Dorfman.Xr snp 4
296a1dc2096SDima Dorfmandevices.
297a1dc2096SDima Dorfman.Pp
2987ba06023SRuslan Ermilov.Dl "devfs rule -s 20 add major 53 group games"
299a1dc2096SDima Dorfman.Pp
300a1dc2096SDima DorfmanAdd a rule to ruleset number 20.
301a1dc2096SDima DorfmanSince this ruleset is not the current ruleset for any mount-points,
302a1dc2096SDima Dorfmanthis rule is never applied automatically (unless ruleset 20 becomes
303a1dc2096SDima Dorfmana current ruleset for some mount-point at a later time).
304a1dc2096SDima DorfmanHowever, it can be applied explicitly, as such:
305a1dc2096SDima Dorfman.Pp
3067ba06023SRuslan Ermilov.Dl "devfs -m /my/jail/dev rule -s 20 applyset"
307a1dc2096SDima Dorfman.Pp
308a1dc2096SDima DorfmanThis will apply all rules in ruleset number 20 to the DEVFS mount on
309a1dc2096SDima Dorfman.Pa /my/jail/dev .
3107ba06023SRuslan ErmilovIt does not matter that ruleset 20 is not the current ruleset for that
311a1dc2096SDima Dorfmanmount-point; the rules are applied regardless.
312a1dc2096SDima Dorfman.Pp
3137ba06023SRuslan Ermilov.Dl "devfs rule apply hide"
314a1dc2096SDima Dorfman.Pp
315a1dc2096SDima DorfmanSince this rule has no conditions, the action
316a1dc2096SDima Dorfman.Pq Cm hide
317a1dc2096SDima Dorfmanwill be applied to all nodes.
3187ba06023SRuslan ErmilovSince hiding all nodes is not very useful, we can undo like so:
319a1dc2096SDima Dorfman.Pp
3207ba06023SRuslan Ermilov.Dl "devfs rule apply unhide"
321072af151SDima Dorfman.Pp
322072af151SDima Dorfmanwhich applies
323072af151SDima Dorfman.Cm unhide
324072af151SDima Dorfmanto all the nodes,
325072af151SDima Dorfmancausing them to reappear.
326072af151SDima Dorfman.Pp
3277ba06023SRuslan Ermilov.Dl "cat my_rules | devfs rule -s 10 add -"
328072af151SDima Dorfman.Pp
329072af151SDima DorfmanAdd all the rules from the file
330072af151SDima Dorfman.Pa my_rules
331072af151SDima Dorfmanto ruleset 10.
332072af151SDima Dorfman.Pp
3337ba06023SRuslan Ermilov.Dl "devfs rule -s 20 show | devfs rule -s 10 add -"
334072af151SDima Dorfman.Pp
335072af151SDima DorfmanSince
336072af151SDima Dorfman.Cm show
337072af151SDima Dorfmanoutputs valid rules,
338072af151SDima Dorfmanthis feature can be used to copy rulesets.
339072af151SDima DorfmanThe above copies all the rules from ruleset 20 into ruleset 10.
340072af151SDima DorfmanThe rule numbers are preserved,
341072af151SDima Dorfmanbut ruleset 10 may already have rules with non-conflicting numbers
342072af151SDima Dorfman(these will be preserved).
343a1dc2096SDima Dorfman.Sh SEE ALSO
344*d54277a7SSimon L. B. Nielsen.Xr chmod 1 ,
345a1dc2096SDima Dorfman.Xr jail 2 ,
346a1dc2096SDima Dorfman.Xr glob 3 ,
347a1dc2096SDima Dorfman.Xr devfs 5 ,
348a1dc2096SDima Dorfman.Xr chown 8 ,
349a1dc2096SDima Dorfman.Xr jail 8 ,
350a1dc2096SDima Dorfman.Xr mknod 8
351a1dc2096SDima Dorfman.Sh AUTHORS
352a1dc2096SDima Dorfman.An Dima Dorfman
353