1 /* $NetBSD: cftoken.l,v 1.29 2020/11/25 18:11:00 bouyer Exp $ */ 2 3 /* Id: cftoken.l,v 1.53 2006/08/22 18:17:17 manubsd Exp */ 4 5 %{ 6 /* 7 * Copyright (C) 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002 and 2003 WIDE Project. 8 * All rights reserved. 9 * 10 * Redistribution and use in source and binary forms, with or without 11 * modification, are permitted provided that the following conditions 12 * are met: 13 * 1. Redistributions of source code must retain the above copyright 14 * notice, this list of conditions and the following disclaimer. 15 * 2. Redistributions in binary form must reproduce the above copyright 16 * notice, this list of conditions and the following disclaimer in the 17 * documentation and/or other materials provided with the distribution. 18 * 3. Neither the name of the project nor the names of its contributors 19 * may be used to endorse or promote products derived from this software 20 * without specific prior written permission. 21 * 22 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND 23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 25 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE 26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 32 * SUCH DAMAGE. 33 */ 34 35 #include "config.h" 36 37 #include <sys/types.h> 38 #include <sys/param.h> 39 #include <sys/socket.h> 40 41 #include <netinet/in.h> 42 #include PATH_IPSEC_H 43 44 #include <stdlib.h> 45 #include <stdio.h> 46 #include <string.h> 47 #include <errno.h> 48 #include <limits.h> 49 #include <ctype.h> 50 #include <glob.h> 51 #ifdef HAVE_STDARG_H 52 #include <stdarg.h> 53 #else 54 #include <varargs.h> 55 #endif 56 57 #include "var.h" 58 #include "misc.h" 59 #include "vmbuf.h" 60 #include "plog.h" 61 #include "debug.h" 62 63 #include "algorithm.h" 64 #include "cfparse_proto.h" 65 #include "cftoken_proto.h" 66 #include "localconf.h" 67 #include "oakley.h" 68 #include "isakmp_var.h" 69 #include "isakmp.h" 70 #include "ipsec_doi.h" 71 #include "policy.h" 72 #include "proposal.h" 73 #include "remoteconf.h" 74 #ifdef GC 75 #include "gcmalloc.h" 76 #endif 77 78 #include "cfparse.h" 79 80 int yyerrorcount = 0; 81 82 #if defined(YIPS_DEBUG) 83 # define YYDB plog(LLV_DEBUG2, LOCATION, NULL, \ 84 "begin <%d>%s\n", yy_start, yytext); 85 # define YYD { \ 86 plog(LLV_DEBUG2, LOCATION, NULL, "<%d>%s", \ 87 yy_start, loglevel >= LLV_DEBUG2 ? "\n" : ""); \ 88 } 89 #else 90 # define YYDB 91 # define YYD 92 #endif /* defined(YIPS_DEBUG) */ 93 94 #define MAX_INCLUDE_DEPTH 10 95 96 static struct include_stack { 97 char *path; 98 FILE *fp; 99 YY_BUFFER_STATE prevstate; 100 int lineno; 101 glob_t matches; 102 int matchon; 103 } incstack[MAX_INCLUDE_DEPTH]; 104 static int incstackp = 0; 105 106 static int yy_first_time = 1; 107 %} 108 109 /* common section */ 110 nl \n 111 ws [ \t]+ 112 digit [0-9] 113 letter [A-Za-z] 114 hexdigit [0-9A-Fa-f] 115 /*octet (([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */ 116 special [()+\|\?\*] 117 comma \, 118 dot \. 119 slash \/ 120 bcl \{ 121 ecl \} 122 blcl \[ 123 elcl \] 124 hyphen \- 125 percent \% 126 semi \; 127 comment \#.* 128 ccomment "/*" 129 bracketstring \<[^>]*\> 130 quotedstring \"[^"]*\" 131 addrstring [a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*) 132 decstring {digit}+ 133 hexstring 0x{hexdigit}+ 134 135 %s S_INI S_PRIV S_PTH S_LOG S_PAD S_LST S_RTRY S_CFG S_LDAP S_RAD 136 %s S_ALGST S_ALGCL 137 %s S_SAINF S_SAINFS 138 %s S_RMT S_RMTS S_RMTP 139 %s S_SA 140 %s S_GSSENC 141 142 %% 143 %{ 144 if (yy_first_time) { 145 BEGIN S_INI; 146 yy_first_time = 0; 147 } 148 %} 149 150 /* privsep */ 151 <S_INI>privsep { BEGIN S_PRIV; YYDB; return(PRIVSEP); } 152 <S_PRIV>{bcl} { return(BOC); } 153 <S_PRIV>user { YYD; return(USER); } 154 <S_PRIV>group { YYD; return(GROUP); } 155 <S_PRIV>chroot { YYD; return(CHROOT); } 156 <S_PRIV>{ecl} { BEGIN S_INI; return(EOC); } 157 158 /* path */ 159 <S_INI>path { BEGIN S_PTH; YYDB; return(PATH); } 160 <S_PTH>include { YYD; yylval.num = LC_PATHTYPE_INCLUDE; 161 return(PATHTYPE); } 162 <S_PTH>pre_shared_key { YYD; yylval.num = LC_PATHTYPE_PSK; 163 return(PATHTYPE); } 164 <S_PTH>certificate { YYD; yylval.num = LC_PATHTYPE_CERT; 165 return(PATHTYPE); } 166 <S_PTH>script { YYD; yylval.num = LC_PATHTYPE_SCRIPT; 167 return(PATHTYPE); } 168 <S_PTH>backupsa { YYD; yylval.num = LC_PATHTYPE_BACKUPSA; 169 return(PATHTYPE); } 170 <S_PTH>pidfile { YYD; yylval.num = LC_PATHTYPE_PIDFILE; 171 return(PATHTYPE); } 172 <S_PTH>{semi} { BEGIN S_INI; YYDB; return(EOS); } 173 174 /* include */ 175 <S_INI>include { YYDB; return(INCLUDE); } 176 177 /* pfkey_buffer */ 178 <S_INI>pfkey_buffer { YYDB; return(PFKEY_BUFFER); } 179 180 /* special */ 181 <S_INI>complex_bundle { YYDB; return(COMPLEX_BUNDLE); } 182 183 /* logging */ 184 <S_INI>log { BEGIN S_LOG; YYDB; return(LOGGING); } 185 <S_LOG>error { YYD; yylval.num = LLV_ERROR; return(LOGLEV); } 186 <S_LOG>warning { YYD; yylval.num = LLV_WARNING; return(LOGLEV); } 187 <S_LOG>notify { YYD; yylval.num = LLV_NOTIFY; return(LOGLEV); } 188 <S_LOG>info { YYD; yylval.num = LLV_INFO; return(LOGLEV); } 189 <S_LOG>debug { YYD; yylval.num = LLV_DEBUG; return(LOGLEV); } 190 <S_LOG>debug2 { YYD; yylval.num = LLV_DEBUG2; return(LOGLEV); } 191 <S_LOG>{semi} { BEGIN S_INI; return(EOS); } 192 193 /* padding */ 194 <S_INI>padding { BEGIN S_PAD; YYDB; return(PADDING); } 195 <S_PAD>{bcl} { return(BOC); } 196 <S_PAD>randomize { YYD; return(PAD_RANDOMIZE); } 197 <S_PAD>randomize_length { YYD; return(PAD_RANDOMIZELEN); } 198 <S_PAD>maximum_length { YYD; return(PAD_MAXLEN); } 199 <S_PAD>strict_check { YYD; return(PAD_STRICT); } 200 <S_PAD>exclusive_tail { YYD; return(PAD_EXCLTAIL); } 201 <S_PAD>{ecl} { BEGIN S_INI; return(EOC); } 202 203 /* listen */ 204 <S_INI>listen { BEGIN S_LST; YYDB; return(LISTEN); } 205 <S_LST>{bcl} { return(BOC); } 206 <S_LST>isakmp { YYD; return(X_ISAKMP); } 207 <S_LST>isakmp_natt { YYD; return(X_ISAKMP_NATT); } 208 <S_LST>admin { YYD; return(X_ADMIN); } 209 <S_LST>adminsock { YYD; return(ADMINSOCK); } 210 <S_LST>disabled { YYD; return(DISABLED); } 211 <S_LST>strict_address { YYD; return(STRICT_ADDRESS); } 212 <S_LST>{ecl} { BEGIN S_INI; return(EOC); } 213 214 /* radius config */ 215 <S_INI>radiuscfg { BEGIN S_RAD; YYDB; return(RADCFG); } 216 <S_RAD>{bcl} { return(BOC); } 217 <S_RAD>auth { YYD; return(RAD_AUTH); } 218 <S_RAD>acct { YYD; return(RAD_ACCT); } 219 <S_RAD>timeout { YYD; return(RAD_TIMEOUT); } 220 <S_RAD>retries { YYD; return(RAD_RETRIES); } 221 <S_RAD>{ecl} { BEGIN S_INI; return(EOC); } 222 223 /* ldap config */ 224 <S_INI>ldapcfg { BEGIN S_LDAP; YYDB; return(LDAPCFG); } 225 <S_LDAP>{bcl} { return(BOC); } 226 <S_LDAP>version { YYD; return(LDAP_PVER); } 227 <S_LDAP>debug { YYD; return(LDAP_DEBUG); } 228 <S_LDAP>timeout { YYD; return(LDAP_TIMEOUT); } 229 <S_LDAP>uri { YYD; return(LDAP_URI); } 230 <S_LDAP>host { YYD; return(LDAP_HOST); } 231 <S_LDAP>port { YYD; return(LDAP_PORT); } 232 <S_LDAP>tls { YYD; return(LDAP_TLS); } 233 <S_LDAP>base { YYD; return(LDAP_BASE); } 234 <S_LDAP>subtree { YYD; return(LDAP_SUBTREE); } 235 <S_LDAP>bind_dn { YYD; return(LDAP_BIND_DN); } 236 <S_LDAP>bind_pw { YYD; return(LDAP_BIND_PW); } 237 <S_LDAP>attr_user { YYD; return(LDAP_ATTR_USER); } 238 <S_LDAP>attr_addr { YYD; return(LDAP_ATTR_ADDR); } 239 <S_LDAP>attr_mask { YYD; return(LDAP_ATTR_MASK); } 240 <S_LDAP>attr_group { YYD; return(LDAP_ATTR_GROUP); } 241 <S_LDAP>attr_member { YYD; return(LDAP_ATTR_MEMBER); } 242 <S_LDAP>{ecl} { BEGIN S_INI; return(EOC); } 243 244 /* mode_cfg */ 245 <S_INI>mode_cfg { BEGIN S_CFG; YYDB; return(MODECFG); } 246 <S_CFG>{bcl} { return(BOC); } 247 <S_CFG>network4 { YYD; return(CFG_NET4); } 248 <S_CFG>netmask4 { YYD; return(CFG_MASK4); } 249 <S_CFG>dns4 { YYD; return(CFG_DNS4); } 250 <S_CFG>nbns4 { YYD; return(CFG_NBNS4); } 251 <S_CFG>wins4 { YYD; return(CFG_NBNS4); } 252 <S_CFG>default_domain { YYD; return(CFG_DEFAULT_DOMAIN); } 253 <S_CFG>auth_source { YYD; return(CFG_AUTH_SOURCE); } 254 <S_CFG>auth_groups { YYD; return(CFG_AUTH_GROUPS); } 255 <S_CFG>group_source { YYD; return(CFG_GROUP_SOURCE); } 256 <S_CFG>conf_source { YYD; return(CFG_CONF_SOURCE); } 257 <S_CFG>accounting { YYD; return(CFG_ACCOUNTING); } 258 <S_CFG>system { YYD; return(CFG_SYSTEM); } 259 <S_CFG>local { YYD; return(CFG_LOCAL); } 260 <S_CFG>none { YYD; return(CFG_NONE); } 261 <S_CFG>radius { YYD; return(CFG_RADIUS); } 262 <S_CFG>pam { YYD; return(CFG_PAM); } 263 <S_CFG>ldap { YYD; return(CFG_LDAP); } 264 <S_CFG>pool_size { YYD; return(CFG_POOL_SIZE); } 265 <S_CFG>banner { YYD; return(CFG_MOTD); } 266 <S_CFG>auth_throttle { YYD; return(CFG_AUTH_THROTTLE); } 267 <S_CFG>split_network { YYD; return(CFG_SPLIT_NETWORK); } 268 <S_CFG>local_lan { YYD; return(CFG_SPLIT_LOCAL); } 269 <S_CFG>include { YYD; return(CFG_SPLIT_INCLUDE); } 270 <S_CFG>split_dns { YYD; return(CFG_SPLIT_DNS); } 271 <S_CFG>pfs_group { YYD; return(CFG_PFS_GROUP); } 272 <S_CFG>save_passwd { YYD; return(CFG_SAVE_PASSWD); } 273 <S_CFG>{comma} { YYD; return(COMMA); } 274 <S_CFG>{ecl} { BEGIN S_INI; return(EOC); } 275 276 /* timer */ 277 <S_INI>timer { BEGIN S_RTRY; YYDB; return(RETRY); } 278 <S_RTRY>{bcl} { return(BOC); } 279 <S_RTRY>counter { YYD; return(RETRY_COUNTER); } 280 <S_RTRY>interval { YYD; return(RETRY_INTERVAL); } 281 <S_RTRY>persend { YYD; return(RETRY_PERSEND); } 282 <S_RTRY>phase1 { YYD; return(RETRY_PHASE1); } 283 <S_RTRY>phase2 { YYD; return(RETRY_PHASE2); } 284 <S_RTRY>natt_keepalive { YYD; return(NATT_KA); } 285 <S_RTRY>{ecl} { BEGIN S_INI; return(EOC); } 286 287 /* sainfo */ 288 <S_INI>sainfo { BEGIN S_SAINF; YYDB; return(SAINFO); } 289 <S_SAINF>anonymous { YYD; return(ANONYMOUS); } 290 <S_SAINF>clientaddr { YYD; return(CLIENTADDR); } 291 <S_SAINF>{blcl}any{elcl} { YYD; return(PORTANY); } 292 <S_SAINF>any { YYD; return(ANY); } 293 <S_SAINF>from { YYD; return(FROM); } 294 <S_SAINF>group { YYD; return(GROUP); } 295 /* sainfo spec */ 296 <S_SAINF>{bcl} { BEGIN S_SAINFS; return(BOC); } 297 <S_SAINF>{semi} { BEGIN S_INI; return(EOS); } 298 <S_SAINFS>{ecl} { BEGIN S_INI; return(EOC); } 299 <S_SAINFS>pfs_group { YYD; return(PFS_GROUP); } 300 <S_SAINFS>remoteid { YYD; return(REMOTEID); } 301 <S_SAINFS>my_identifier { YYD; return(MY_IDENTIFIER); } 302 <S_SAINFS>lifetime { YYD; return(LIFETIME); } 303 <S_SAINFS>time { YYD; return(LIFETYPE_TIME); } 304 <S_SAINFS>byte { YYD; return(LIFETYPE_BYTE); } 305 <S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); } 306 <S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); } 307 <S_SAINFS>compression_algorithm { YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); } 308 <S_SAINFS>{comma} { YYD; return(COMMA); } 309 310 /* remote */ 311 <S_INI>remote { BEGIN S_RMT; YYDB; return(REMOTE); } 312 <S_RMT>anonymous { YYD; return(ANONYMOUS); } 313 <S_RMT>inherit { YYD; return(INHERIT); } 314 <S_RMT>{semi} { BEGIN S_INI; YYDB; return(EOS); } 315 /* remote spec */ 316 <S_RMT>{bcl} { BEGIN S_RMTS; return(BOC); } 317 <S_RMTS>{ecl} { BEGIN S_INI; return(EOC); } 318 <S_RMTS>remote_address { YYD; return(REMOTE_ADDRESS); } 319 <S_RMTS>exchange_mode { YYD; return(EXCHANGE_MODE); } 320 <S_RMTS>{comma} { YYD; /* XXX ignored, but to be handled. */ ; } 321 <S_RMTS>base { YYD; yylval.num = ISAKMP_ETYPE_BASE; return(EXCHANGETYPE); } 322 <S_RMTS>main { YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); } 323 <S_RMTS>aggressive { YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); } 324 <S_RMTS>doi { YYD; return(DOI); } 325 <S_RMTS>ipsec_doi { YYD; yylval.num = IPSEC_DOI; return(DOITYPE); } 326 <S_RMTS>situation { YYD; return(SITUATION); } 327 <S_RMTS>identity_only { YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); } 328 <S_RMTS>secrecy { YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); } 329 <S_RMTS>integrity { YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); } 330 <S_RMTS>my_identifier { YYD; return(MY_IDENTIFIER); } 331 <S_RMTS>xauth_login { YYD; return(XAUTH_LOGIN); /* formerly identifier type login */ } 332 <S_RMTS>peers_identifier { YYD; return(PEERS_IDENTIFIER); } 333 <S_RMTS>verify_identifier { YYD; return(VERIFY_IDENTIFIER); } 334 <S_RMTS>certificate_type { YYD; return(CERTIFICATE_TYPE); } 335 <S_RMTS>ca_type { YYD; return(CA_TYPE); } 336 <S_RMTS>x509 { YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); } 337 <S_RMTS>plain_rsa { YYD; yylval.num = ISAKMP_CERT_PLAINRSA; return(CERT_PLAINRSA); } 338 <S_RMTS>peers_certfile { YYD; return(PEERS_CERTFILE); } 339 <S_RMTS>dnssec { YYD; return(DNSSEC); } 340 <S_RMTS>verify_cert { YYD; return(VERIFY_CERT); } 341 <S_RMTS>send_cert { YYD; return(SEND_CERT); } 342 <S_RMTS>send_cr { YYD; return(SEND_CR); } 343 <S_RMTS>match_empty_cr { YYD; return(MATCH_EMPTY_CR); } 344 <S_RMTS>dh_group { YYD; return(DH_GROUP); } 345 <S_RMTS>nonce_size { YYD; return(NONCE_SIZE); } 346 <S_RMTS>generate_policy { YYD; return(GENERATE_POLICY); } 347 <S_RMTS>unique { YYD; yylval.num = GENERATE_POLICY_UNIQUE; return(GENERATE_LEVEL); } 348 <S_RMTS>require { YYD; yylval.num = GENERATE_POLICY_REQUIRE; return(GENERATE_LEVEL); } 349 <S_RMTS>support_proxy { YYD; return(SUPPORT_PROXY); } 350 <S_RMTS>initial_contact { YYD; return(INITIAL_CONTACT); } 351 <S_RMTS>nat_traversal { YYD; return(NAT_TRAVERSAL); } 352 <S_RMTS>force { YYD; return(REMOTE_FORCE_LEVEL); } 353 <S_RMTS>proposal_check { YYD; return(PROPOSAL_CHECK); } 354 <S_RMTS>obey { YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); } 355 <S_RMTS>strict { YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); } 356 <S_RMTS>exact { YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); } 357 <S_RMTS>claim { YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); } 358 <S_RMTS>keepalive { YYD; return(KEEPALIVE); } 359 <S_RMTS>passive { YYD; return(PASSIVE); } 360 <S_RMTS>lifetime { YYD; return(LIFETIME); } 361 <S_RMTS>time { YYD; return(LIFETYPE_TIME); } 362 <S_RMTS>byte { YYD; return(LIFETYPE_BYTE); } 363 <S_RMTS>dpd { YYD; return(DPD); } 364 <S_RMTS>dpd_delay { YYD; return(DPD_DELAY); } 365 <S_RMTS>dpd_retry { YYD; return(DPD_RETRY); } 366 <S_RMTS>dpd_maxfail { YYD; return(DPD_MAXFAIL); } 367 <S_RMTS>ph1id { YYD; return(PH1ID); } 368 <S_RMTS>ike_frag { YYD; return(IKE_FRAG); } 369 <S_RMTS>esp_frag { YYD; return(ESP_FRAG); } 370 <S_RMTS>script { YYD; return(SCRIPT); } 371 <S_RMTS>phase1_up { YYD; return(PHASE1_UP); } 372 <S_RMTS>phase1_down { YYD; return(PHASE1_DOWN); } 373 <S_RMTS>phase1_dead { YYD; return(PHASE1_DEAD); } 374 <S_RMTS>mode_cfg { YYD; return(MODE_CFG); } 375 <S_RMTS>weak_phase1_check { YYD; return(WEAK_PHASE1_CHECK); } 376 <S_RMTS>rekey { YYD; return(REKEY); } 377 /* remote proposal */ 378 <S_RMTS>proposal { BEGIN S_RMTP; YYDB; return(PROPOSAL); } 379 <S_RMTP>{bcl} { return(BOC); } 380 <S_RMTP>{ecl} { BEGIN S_RMTS; return(EOC); } 381 <S_RMTP>lifetime { YYD; return(LIFETIME); } 382 <S_RMTP>time { YYD; return(LIFETYPE_TIME); } 383 <S_RMTP>byte { YYD; return(LIFETYPE_BYTE); } 384 <S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); } 385 <S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); } 386 <S_RMTP>hash_algorithm { YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); } 387 <S_RMTP>dh_group { YYD; return(DH_GROUP); } 388 <S_RMTP>gss_id { YYD; return(GSS_ID); } 389 <S_RMTP>gssapi_id { YYD; return(GSS_ID); } /* for back compatibility */ 390 391 /* GSS ID encoding type (global) */ 392 <S_INI>gss_id_enc { BEGIN S_GSSENC; YYDB; return(GSS_ID_ENC); } 393 <S_GSSENC>latin1 { YYD; yylval.num = LC_GSSENC_LATIN1; 394 return(GSS_ID_ENCTYPE); } 395 <S_GSSENC>utf-16le { YYD; yylval.num = LC_GSSENC_UTF16LE; 396 return(GSS_ID_ENCTYPE); } 397 <S_GSSENC>{semi} { BEGIN S_INI; YYDB; return(EOS); } 398 399 /* parameter */ 400 on { YYD; yylval.num = TRUE; return(SWITCH); } 401 off { YYD; yylval.num = FALSE; return(SWITCH); } 402 403 /* prefix */ 404 {slash}{digit}{1,3} { 405 YYD; 406 yytext++; 407 yylval.num = atoi(yytext); 408 return(PREFIX); 409 } 410 411 /* port number */ 412 {blcl}{decstring}{elcl} { 413 char *p = yytext; 414 YYD; 415 while (*++p != ']') ; 416 *p = 0; 417 yytext++; 418 yylval.num = atoi(yytext); 419 return(PORT); 420 } 421 422 /* address range */ 423 {hyphen}{addrstring} { 424 YYD; 425 yytext++; 426 yylval.val = vmalloc(yyleng + 1); 427 if (yylval.val == NULL) { 428 yyerror("vmalloc failed"); 429 return -1; 430 } 431 memcpy(yylval.val->v, yytext, yylval.val->l); 432 return(ADDRRANGE); 433 } 434 435 /* upper protocol */ 436 esp { YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); } 437 ah { YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); } 438 ipcomp { YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); } 439 icmp { YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); } 440 icmp6 { YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); } 441 tcp { YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); } 442 udp { YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); } 443 gre { YYD; yylval.num = IPPROTO_GRE; return(UL_PROTO); } 444 445 /* algorithm type */ 446 des_iv64 { YYD; yylval.num = algtype_des_iv64; return(ALGORITHMTYPE); } 447 des { YYD; yylval.num = algtype_des; return(ALGORITHMTYPE); } 448 3des { YYD; yylval.num = algtype_3des; return(ALGORITHMTYPE); } 449 rc5 { YYD; yylval.num = algtype_rc5; return(ALGORITHMTYPE); } 450 idea { YYD; yylval.num = algtype_idea; return(ALGORITHMTYPE); } 451 cast128 { YYD; yylval.num = algtype_cast128; return(ALGORITHMTYPE); } 452 blowfish { YYD; yylval.num = algtype_blowfish; return(ALGORITHMTYPE); } 453 3idea { YYD; yylval.num = algtype_3idea; return(ALGORITHMTYPE); } 454 des_iv32 { YYD; yylval.num = algtype_des_iv32; return(ALGORITHMTYPE); } 455 rc4 { YYD; yylval.num = algtype_rc4; return(ALGORITHMTYPE); } 456 null_enc { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); } 457 null { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); } 458 aes { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); } 459 aes_gcm_16 { YYD; yylval.num = algtype_aesgcm16; return(ALGORITHMTYPE); } 460 rijndael { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); } 461 twofish { YYD; yylval.num = algtype_twofish; return(ALGORITHMTYPE); } 462 camellia { YYD; yylval.num = algtype_camellia; return(ALGORITHMTYPE); } 463 non_auth { YYD; yylval.num = algtype_non_auth; return(ALGORITHMTYPE); } 464 hmac_md5 { YYD; yylval.num = algtype_hmac_md5; return(ALGORITHMTYPE); } 465 hmac_sha1 { YYD; yylval.num = algtype_hmac_sha1; return(ALGORITHMTYPE); } 466 hmac_sha2_256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); } 467 hmac_sha256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); } 468 hmac_sha2_384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); } 469 hmac_sha384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); } 470 hmac_sha2_512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); } 471 hmac_sha512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); } 472 des_mac { YYD; yylval.num = algtype_des_mac; return(ALGORITHMTYPE); } 473 kpdk { YYD; yylval.num = algtype_kpdk; return(ALGORITHMTYPE); } 474 md5 { YYD; yylval.num = algtype_md5; return(ALGORITHMTYPE); } 475 sha1 { YYD; yylval.num = algtype_sha1; return(ALGORITHMTYPE); } 476 tiger { YYD; yylval.num = algtype_tiger; return(ALGORITHMTYPE); } 477 sha2_256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); } 478 sha256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); } 479 sha2_384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); } 480 sha384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); } 481 sha2_512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); } 482 sha512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); } 483 oui { YYD; yylval.num = algtype_oui; return(ALGORITHMTYPE); } 484 deflate { YYD; yylval.num = algtype_deflate; return(ALGORITHMTYPE); } 485 lzs { YYD; yylval.num = algtype_lzs; return(ALGORITHMTYPE); } 486 modp768 { YYD; yylval.num = algtype_modp768; return(ALGORITHMTYPE); } 487 modp1024 { YYD; yylval.num = algtype_modp1024; return(ALGORITHMTYPE); } 488 modp1536 { YYD; yylval.num = algtype_modp1536; return(ALGORITHMTYPE); } 489 ec2n155 { YYD; yylval.num = algtype_ec2n155; return(ALGORITHMTYPE); } 490 ec2n185 { YYD; yylval.num = algtype_ec2n185; return(ALGORITHMTYPE); } 491 modp2048 { YYD; yylval.num = algtype_modp2048; return(ALGORITHMTYPE); } 492 modp3072 { YYD; yylval.num = algtype_modp3072; return(ALGORITHMTYPE); } 493 modp4096 { YYD; yylval.num = algtype_modp4096; return(ALGORITHMTYPE); } 494 modp6144 { YYD; yylval.num = algtype_modp6144; return(ALGORITHMTYPE); } 495 modp8192 { YYD; yylval.num = algtype_modp8192; return(ALGORITHMTYPE); } 496 pre_shared_key { YYD; yylval.num = algtype_psk; return(ALGORITHMTYPE); } 497 rsasig { YYD; yylval.num = algtype_rsasig; return(ALGORITHMTYPE); } 498 dsssig { YYD; yylval.num = algtype_dsssig; return(ALGORITHMTYPE); } 499 rsaenc { YYD; yylval.num = algtype_rsaenc; return(ALGORITHMTYPE); } 500 rsarev { YYD; yylval.num = algtype_rsarev; return(ALGORITHMTYPE); } 501 gssapi_krb { YYD; yylval.num = algtype_gssapikrb; return(ALGORITHMTYPE); } 502 hybrid_rsa_server { 503 #ifdef ENABLE_HYBRID 504 YYD; yylval.num = algtype_hybrid_rsa_s; return(ALGORITHMTYPE); 505 #else 506 yyerror("racoon not configured with --enable-hybrid"); 507 #endif 508 } 509 hybrid_dss_server { 510 #ifdef ENABLE_HYBRID 511 YYD; yylval.num = algtype_hybrid_dss_s; return(ALGORITHMTYPE); 512 #else 513 yyerror("racoon not configured with --enable-hybrid"); 514 #endif 515 } 516 hybrid_rsa_client { 517 #ifdef ENABLE_HYBRID 518 YYD; yylval.num = algtype_hybrid_rsa_c; return(ALGORITHMTYPE); 519 #else 520 yyerror("racoon not configured with --enable-hybrid"); 521 #endif 522 } 523 hybrid_dss_client { 524 #ifdef ENABLE_HYBRID 525 YYD; yylval.num = algtype_hybrid_dss_c; return(ALGORITHMTYPE); 526 #else 527 yyerror("racoon not configured with --enable-hybrid"); 528 #endif 529 } 530 xauth_psk_server { 531 #ifdef ENABLE_HYBRID 532 YYD; yylval.num = algtype_xauth_psk_s; return(ALGORITHMTYPE); 533 #else 534 yyerror("racoon not configured with --enable-hybrid"); 535 #endif 536 } 537 xauth_psk_client { 538 #ifdef ENABLE_HYBRID 539 YYD; yylval.num = algtype_xauth_psk_c; return(ALGORITHMTYPE); 540 #else 541 yyerror("racoon not configured with --enable-hybrid"); 542 #endif 543 } 544 xauth_rsa_server { 545 #ifdef ENABLE_HYBRID 546 YYD; yylval.num = algtype_xauth_rsa_s; return(ALGORITHMTYPE); 547 #else 548 yyerror("racoon not configured with --enable-hybrid"); 549 #endif 550 } 551 xauth_rsa_client { 552 #ifdef ENABLE_HYBRID 553 YYD; yylval.num = algtype_xauth_rsa_c; return(ALGORITHMTYPE); 554 #else 555 yyerror("racoon not configured with --enable-hybrid"); 556 #endif 557 } 558 559 560 /* identifier type */ 561 user_fqdn { YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); } 562 fqdn { YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); } 563 keyid { YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); } 564 address { YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); } 565 subnet { YYD; yylval.num = IDTYPE_SUBNET; return(IDENTIFIERTYPE); } 566 asn1dn { YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); } 567 568 /* identifier qualifier */ 569 tag { YYD; yylval.num = IDQUAL_TAG; return(IDENTIFIERQUAL); } 570 file { YYD; yylval.num = IDQUAL_FILE; return(IDENTIFIERQUAL); } 571 572 /* units */ 573 B|byte|bytes { YYD; return(UNITTYPE_BYTE); } 574 KB { YYD; return(UNITTYPE_KBYTES); } 575 MB { YYD; return(UNITTYPE_MBYTES); } 576 TB { YYD; return(UNITTYPE_TBYTES); } 577 sec|secs|second|seconds { YYD; return(UNITTYPE_SEC); } 578 min|mins|minute|minutes { YYD; return(UNITTYPE_MIN); } 579 hour|hours { YYD; return(UNITTYPE_HOUR); } 580 581 /* boolean */ 582 yes { YYD; yylval.num = TRUE; return(BOOLEAN); } 583 no { YYD; yylval.num = FALSE; return(BOOLEAN); } 584 585 {decstring} { 586 char *bp; 587 588 YYD; 589 yylval.num = strtoul(yytext, &bp, 10); 590 return(NUMBER); 591 } 592 593 {hexstring} { 594 char *p; 595 596 YYD; 597 yylval.val = vmalloc(yyleng + (yyleng & 1) + 1); 598 if (yylval.val == NULL) { 599 yyerror("vmalloc failed"); 600 return -1; 601 } 602 603 p = yylval.val->v; 604 *p++ = '0'; 605 *p++ = 'x'; 606 607 /* fixed string if length is odd. */ 608 if (yyleng & 1) 609 *p++ = '0'; 610 memcpy(p, &yytext[2], yyleng - 1); 611 612 return(HEXSTRING); 613 } 614 615 {quotedstring} { 616 char *p = yytext; 617 618 YYD; 619 while (*++p != '"') ; 620 *p = '\0'; 621 622 yylval.val = vmalloc(yyleng - 1); 623 if (yylval.val == NULL) { 624 yyerror("vmalloc failed"); 625 return -1; 626 } 627 memcpy(yylval.val->v, &yytext[1], yylval.val->l); 628 629 return(QUOTEDSTRING); 630 } 631 632 {addrstring} { 633 YYD; 634 635 yylval.val = vmalloc(yyleng + 1); 636 if (yylval.val == NULL) { 637 yyerror("vmalloc failed"); 638 return -1; 639 } 640 memcpy(yylval.val->v, yytext, yylval.val->l); 641 642 return(ADDRSTRING); 643 } 644 645 <<EOF>> { 646 yy_delete_buffer(YY_CURRENT_BUFFER); 647 fclose (incstack[incstackp].fp); 648 incstack[incstackp].fp = NULL; 649 racoon_free(incstack[incstackp].path); 650 incstack[incstackp].path = NULL; 651 incstackp--; 652 nextfile: 653 if (incstack[incstackp].matchon < 654 incstack[incstackp].matches.gl_pathc) { 655 char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon]; 656 incstack[incstackp].matchon++; 657 incstackp++; 658 if (yycf_set_buffer(filepath) != 0) { 659 incstackp--; 660 goto nextfile; 661 } 662 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE)); 663 BEGIN(S_INI); 664 } else { 665 globfree(&incstack[incstackp].matches); 666 if (incstackp == 0) 667 yyterminate(); 668 else 669 yy_switch_to_buffer(incstack[incstackp].prevstate); 670 } 671 } 672 673 /* ... */ 674 {ws} { ; } 675 {nl} { incstack[incstackp].lineno++; } 676 {comment} { YYD; } 677 {semi} { return(EOS); } 678 . { yymore(); } 679 680 %% 681 682 void 683 yyerror(const char *s, ...) 684 { 685 char fmt[512]; 686 687 va_list ap; 688 #ifdef HAVE_STDARG_H 689 va_start(ap, s); 690 #else 691 va_start(ap); 692 #endif 693 snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n", 694 incstack[incstackp].path, incstack[incstackp].lineno, 695 yytext, s); 696 plogv(LLV_ERROR, LOCATION, NULL, fmt, ap); 697 va_end(ap); 698 699 yyerrorcount++; 700 } 701 702 void 703 yywarn(const char *s, ...) 704 { 705 char fmt[512]; 706 707 va_list ap; 708 #ifdef HAVE_STDARG_H 709 va_start(ap, s); 710 #else 711 va_start(ap); 712 #endif 713 snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n", 714 incstack[incstackp].path, incstack[incstackp].lineno, 715 yytext, s); 716 plogv(LLV_WARNING, LOCATION, NULL, fmt, ap); 717 va_end(ap); 718 } 719 720 int 721 yycf_switch_buffer(path) 722 char *path; 723 { 724 char *filepath = NULL; 725 726 /* got the include file name */ 727 if (incstackp >= MAX_INCLUDE_DEPTH) { 728 plog(LLV_ERROR, LOCATION, NULL, 729 "Includes nested too deeply"); 730 return -1; 731 } 732 733 if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 || 734 incstack[incstackp].matches.gl_pathc == 0) { 735 plog(LLV_ERROR, LOCATION, NULL, 736 "glob found no matches for path \"%s\"\n", path); 737 return -1; 738 } 739 incstack[incstackp].matchon = 0; 740 incstack[incstackp].prevstate = YY_CURRENT_BUFFER; 741 742 nextmatch: 743 if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc) 744 return -1; 745 filepath = 746 incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon]; 747 incstack[incstackp].matchon++; 748 incstackp++; 749 750 if (yycf_set_buffer(filepath) != 0) { 751 incstackp--; 752 goto nextmatch; 753 } 754 755 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE)); 756 757 BEGIN(S_INI); 758 759 return 0; 760 } 761 762 int 763 yycf_set_buffer(path) 764 char *path; 765 { 766 yyin = fopen(path, "r"); 767 if (yyin == NULL) { 768 fprintf(stderr, "failed to open file %s (%s)\n", 769 path, strerror(errno)); 770 plog(LLV_ERROR, LOCATION, NULL, 771 "failed to open file %s (%s)\n", 772 path, strerror(errno)); 773 return -1; 774 } 775 776 /* initialize */ 777 incstack[incstackp].fp = yyin; 778 if (incstack[incstackp].path != NULL) 779 racoon_free(incstack[incstackp].path); 780 incstack[incstackp].path = racoon_strdup(path); 781 STRDUP_FATAL(incstack[incstackp].path); 782 incstack[incstackp].lineno = 1; 783 plog(LLV_DEBUG, LOCATION, NULL, 784 "reading config file %s\n", path); 785 786 return 0; 787 } 788 789 void 790 yycf_init_buffer() 791 { 792 int i; 793 794 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) 795 memset(&incstack[i], 0, sizeof(incstack[i])); 796 incstackp = 0; 797 } 798 799 void 800 yycf_clean_buffer() 801 { 802 int i; 803 804 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) { 805 if (incstack[i].path != NULL) { 806 fclose(incstack[i].fp); 807 racoon_free(incstack[i].path); 808 incstack[i].path = NULL; 809 } 810 } 811 } 812 813