xref: /netbsd-src/crypto/dist/ipsec-tools/src/racoon/cftoken.l (revision 82797af728c02b45dc5884fba0c83f5d8d59aa78)
1 /*	$NetBSD: cftoken.l,v 1.29 2020/11/25 18:11:00 bouyer Exp $	*/
2 
3 /* Id: cftoken.l,v 1.53 2006/08/22 18:17:17 manubsd Exp */
4 
5 %{
6 /*
7  * Copyright (C) 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002 and 2003 WIDE Project.
8  * All rights reserved.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  * 3. Neither the name of the project nor the names of its contributors
19  *    may be used to endorse or promote products derived from this software
20  *    without specific prior written permission.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
23  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25  * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
26  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32  * SUCH DAMAGE.
33  */
34 
35 #include "config.h"
36 
37 #include <sys/types.h>
38 #include <sys/param.h>
39 #include <sys/socket.h>
40 
41 #include <netinet/in.h>
42 #include PATH_IPSEC_H
43 
44 #include <stdlib.h>
45 #include <stdio.h>
46 #include <string.h>
47 #include <errno.h>
48 #include <limits.h>
49 #include <ctype.h>
50 #include <glob.h>
51 #ifdef HAVE_STDARG_H
52 #include <stdarg.h>
53 #else
54 #include <varargs.h>
55 #endif
56 
57 #include "var.h"
58 #include "misc.h"
59 #include "vmbuf.h"
60 #include "plog.h"
61 #include "debug.h"
62 
63 #include "algorithm.h"
64 #include "cfparse_proto.h"
65 #include "cftoken_proto.h"
66 #include "localconf.h"
67 #include "oakley.h"
68 #include "isakmp_var.h"
69 #include "isakmp.h"
70 #include "ipsec_doi.h"
71 #include "policy.h"
72 #include "proposal.h"
73 #include "remoteconf.h"
74 #ifdef GC
75 #include "gcmalloc.h"
76 #endif
77 
78 #include "cfparse.h"
79 
80 int yyerrorcount = 0;
81 
82 #if defined(YIPS_DEBUG)
83 #  define YYDB plog(LLV_DEBUG2, LOCATION, NULL,                                \
84 		"begin <%d>%s\n", yy_start, yytext);
85 #  define YYD {                                                                \
86 	plog(LLV_DEBUG2, LOCATION, NULL, "<%d>%s",                             \
87 	    yy_start, loglevel >= LLV_DEBUG2 ? "\n" : "");                     \
88 }
89 #else
90 #  define YYDB
91 #  define YYD
92 #endif /* defined(YIPS_DEBUG) */
93 
94 #define MAX_INCLUDE_DEPTH 10
95 
96 static struct include_stack {
97 	char *path;
98 	FILE *fp;
99 	YY_BUFFER_STATE prevstate;
100 	int lineno;
101 	glob_t matches;
102 	int matchon;
103 } incstack[MAX_INCLUDE_DEPTH];
104 static int incstackp = 0;
105 
106 static int yy_first_time = 1;
107 %}
108 
109 /* common section */
110 nl		\n
111 ws		[ \t]+
112 digit		[0-9]
113 letter		[A-Za-z]
114 hexdigit	[0-9A-Fa-f]
115 /*octet		(([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */
116 special		[()+\|\?\*]
117 comma		\,
118 dot		\.
119 slash		\/
120 bcl		\{
121 ecl		\}
122 blcl		\[
123 elcl		\]
124 hyphen          \-
125 percent		\%
126 semi		\;
127 comment		\#.*
128 ccomment	"/*"
129 bracketstring	\<[^>]*\>
130 quotedstring	\"[^"]*\"
131 addrstring	[a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*)
132 decstring	{digit}+
133 hexstring	0x{hexdigit}+
134 
135 %s S_INI S_PRIV S_PTH S_LOG S_PAD S_LST S_RTRY S_CFG S_LDAP S_RAD
136 %s S_ALGST S_ALGCL
137 %s S_SAINF S_SAINFS
138 %s S_RMT S_RMTS S_RMTP
139 %s S_SA
140 %s S_GSSENC
141 
142 %%
143 %{
144 	if (yy_first_time) {
145 		BEGIN S_INI;
146 		yy_first_time = 0;
147 	}
148 %}
149 
150 	/* privsep */
151 <S_INI>privsep		{ BEGIN S_PRIV; YYDB; return(PRIVSEP); }
152 <S_PRIV>{bcl}		{ return(BOC); }
153 <S_PRIV>user		{ YYD; return(USER); }
154 <S_PRIV>group		{ YYD; return(GROUP); }
155 <S_PRIV>chroot		{ YYD; return(CHROOT); }
156 <S_PRIV>{ecl}		{ BEGIN S_INI; return(EOC); }
157 
158 	/* path */
159 <S_INI>path		{ BEGIN S_PTH; YYDB; return(PATH); }
160 <S_PTH>include		{ YYD; yylval.num = LC_PATHTYPE_INCLUDE;
161 				return(PATHTYPE); }
162 <S_PTH>pre_shared_key	{ YYD; yylval.num = LC_PATHTYPE_PSK;
163 				return(PATHTYPE); }
164 <S_PTH>certificate	{ YYD; yylval.num = LC_PATHTYPE_CERT;
165 				return(PATHTYPE); }
166 <S_PTH>script		{ YYD; yylval.num = LC_PATHTYPE_SCRIPT;
167 				return(PATHTYPE); }
168 <S_PTH>backupsa		{ YYD; yylval.num = LC_PATHTYPE_BACKUPSA;
169 				return(PATHTYPE); }
170 <S_PTH>pidfile		{ YYD; yylval.num = LC_PATHTYPE_PIDFILE;
171 				return(PATHTYPE); }
172 <S_PTH>{semi}		{ BEGIN S_INI; YYDB; return(EOS); }
173 
174 	/* include */
175 <S_INI>include		{ YYDB; return(INCLUDE); }
176 
177     /* pfkey_buffer */
178 <S_INI>pfkey_buffer { YYDB; return(PFKEY_BUFFER); }
179 
180 	/* special */
181 <S_INI>complex_bundle	{ YYDB; return(COMPLEX_BUNDLE); }
182 
183 	/* logging */
184 <S_INI>log		{ BEGIN S_LOG; YYDB; return(LOGGING); }
185 <S_LOG>error		{ YYD; yylval.num = LLV_ERROR; return(LOGLEV); }
186 <S_LOG>warning		{ YYD; yylval.num = LLV_WARNING; return(LOGLEV); }
187 <S_LOG>notify		{ YYD; yylval.num = LLV_NOTIFY; return(LOGLEV); }
188 <S_LOG>info		{ YYD; yylval.num = LLV_INFO; return(LOGLEV); }
189 <S_LOG>debug		{ YYD; yylval.num = LLV_DEBUG; return(LOGLEV); }
190 <S_LOG>debug2		{ YYD; yylval.num = LLV_DEBUG2; return(LOGLEV); }
191 <S_LOG>{semi}		{ BEGIN S_INI; return(EOS); }
192 
193 	/* padding */
194 <S_INI>padding		{ BEGIN S_PAD; YYDB; return(PADDING); }
195 <S_PAD>{bcl}		{ return(BOC); }
196 <S_PAD>randomize	{ YYD; return(PAD_RANDOMIZE); }
197 <S_PAD>randomize_length	{ YYD; return(PAD_RANDOMIZELEN); }
198 <S_PAD>maximum_length	{ YYD; return(PAD_MAXLEN); }
199 <S_PAD>strict_check	{ YYD; return(PAD_STRICT); }
200 <S_PAD>exclusive_tail	{ YYD; return(PAD_EXCLTAIL); }
201 <S_PAD>{ecl}		{ BEGIN S_INI; return(EOC); }
202 
203 	/* listen */
204 <S_INI>listen		{ BEGIN S_LST; YYDB; return(LISTEN); }
205 <S_LST>{bcl}		{ return(BOC); }
206 <S_LST>isakmp		{ YYD; return(X_ISAKMP); }
207 <S_LST>isakmp_natt	{ YYD; return(X_ISAKMP_NATT); }
208 <S_LST>admin		{ YYD; return(X_ADMIN); }
209 <S_LST>adminsock	{ YYD; return(ADMINSOCK); }
210 <S_LST>disabled		{ YYD; return(DISABLED); }
211 <S_LST>strict_address	{ YYD; return(STRICT_ADDRESS); }
212 <S_LST>{ecl}		{ BEGIN S_INI; return(EOC); }
213 
214 	/* radius config */
215 <S_INI>radiuscfg	{ BEGIN S_RAD; YYDB; return(RADCFG); }
216 <S_RAD>{bcl}		{ return(BOC); }
217 <S_RAD>auth		{ YYD; return(RAD_AUTH); }
218 <S_RAD>acct		{ YYD; return(RAD_ACCT); }
219 <S_RAD>timeout		{ YYD; return(RAD_TIMEOUT); }
220 <S_RAD>retries		{ YYD; return(RAD_RETRIES); }
221 <S_RAD>{ecl}		{ BEGIN S_INI; return(EOC); }
222 
223 	/* ldap config */
224 <S_INI>ldapcfg		{ BEGIN S_LDAP; YYDB; return(LDAPCFG); }
225 <S_LDAP>{bcl}		{ return(BOC); }
226 <S_LDAP>version		{ YYD; return(LDAP_PVER); }
227 <S_LDAP>debug		{ YYD; return(LDAP_DEBUG); }
228 <S_LDAP>timeout		{ YYD; return(LDAP_TIMEOUT); }
229 <S_LDAP>uri		{ YYD; return(LDAP_URI); }
230 <S_LDAP>host		{ YYD; return(LDAP_HOST); }
231 <S_LDAP>port		{ YYD; return(LDAP_PORT); }
232 <S_LDAP>tls		{ YYD; return(LDAP_TLS); }
233 <S_LDAP>base		{ YYD; return(LDAP_BASE); }
234 <S_LDAP>subtree		{ YYD; return(LDAP_SUBTREE); }
235 <S_LDAP>bind_dn		{ YYD; return(LDAP_BIND_DN); }
236 <S_LDAP>bind_pw		{ YYD; return(LDAP_BIND_PW); }
237 <S_LDAP>attr_user	{ YYD; return(LDAP_ATTR_USER); }
238 <S_LDAP>attr_addr	{ YYD; return(LDAP_ATTR_ADDR); }
239 <S_LDAP>attr_mask	{ YYD; return(LDAP_ATTR_MASK); }
240 <S_LDAP>attr_group	{ YYD; return(LDAP_ATTR_GROUP); }
241 <S_LDAP>attr_member	{ YYD; return(LDAP_ATTR_MEMBER); }
242 <S_LDAP>{ecl}		{ BEGIN S_INI; return(EOC); }
243 
244 	/* mode_cfg */
245 <S_INI>mode_cfg		{ BEGIN S_CFG; YYDB; return(MODECFG); }
246 <S_CFG>{bcl}		{ return(BOC); }
247 <S_CFG>network4		{ YYD; return(CFG_NET4); }
248 <S_CFG>netmask4		{ YYD; return(CFG_MASK4); }
249 <S_CFG>dns4		{ YYD; return(CFG_DNS4); }
250 <S_CFG>nbns4		{ YYD; return(CFG_NBNS4); }
251 <S_CFG>wins4		{ YYD; return(CFG_NBNS4); }
252 <S_CFG>default_domain	{ YYD; return(CFG_DEFAULT_DOMAIN); }
253 <S_CFG>auth_source	{ YYD; return(CFG_AUTH_SOURCE); }
254 <S_CFG>auth_groups	{ YYD; return(CFG_AUTH_GROUPS); }
255 <S_CFG>group_source	{ YYD; return(CFG_GROUP_SOURCE); }
256 <S_CFG>conf_source	{ YYD; return(CFG_CONF_SOURCE); }
257 <S_CFG>accounting	{ YYD; return(CFG_ACCOUNTING); }
258 <S_CFG>system		{ YYD; return(CFG_SYSTEM); }
259 <S_CFG>local		{ YYD; return(CFG_LOCAL); }
260 <S_CFG>none		{ YYD; return(CFG_NONE); }
261 <S_CFG>radius		{ YYD; return(CFG_RADIUS); }
262 <S_CFG>pam		{ YYD; return(CFG_PAM); }
263 <S_CFG>ldap		{ YYD; return(CFG_LDAP); }
264 <S_CFG>pool_size	{ YYD; return(CFG_POOL_SIZE); }
265 <S_CFG>banner		{ YYD; return(CFG_MOTD); }
266 <S_CFG>auth_throttle	{ YYD; return(CFG_AUTH_THROTTLE); }
267 <S_CFG>split_network	{ YYD; return(CFG_SPLIT_NETWORK); }
268 <S_CFG>local_lan	{ YYD; return(CFG_SPLIT_LOCAL); }
269 <S_CFG>include		{ YYD; return(CFG_SPLIT_INCLUDE); }
270 <S_CFG>split_dns	{ YYD; return(CFG_SPLIT_DNS); }
271 <S_CFG>pfs_group	{ YYD; return(CFG_PFS_GROUP); }
272 <S_CFG>save_passwd	{ YYD; return(CFG_SAVE_PASSWD); }
273 <S_CFG>{comma}		{ YYD; return(COMMA); }
274 <S_CFG>{ecl}		{ BEGIN S_INI; return(EOC); }
275 
276 	/* timer */
277 <S_INI>timer		{ BEGIN S_RTRY; YYDB; return(RETRY); }
278 <S_RTRY>{bcl}		{ return(BOC); }
279 <S_RTRY>counter		{ YYD; return(RETRY_COUNTER); }
280 <S_RTRY>interval	{ YYD; return(RETRY_INTERVAL); }
281 <S_RTRY>persend		{ YYD; return(RETRY_PERSEND); }
282 <S_RTRY>phase1		{ YYD; return(RETRY_PHASE1); }
283 <S_RTRY>phase2		{ YYD; return(RETRY_PHASE2); }
284 <S_RTRY>natt_keepalive	{ YYD; return(NATT_KA); }
285 <S_RTRY>{ecl}		{ BEGIN S_INI; return(EOC); }
286 
287 	/* sainfo */
288 <S_INI>sainfo		{ BEGIN S_SAINF; YYDB; return(SAINFO); }
289 <S_SAINF>anonymous	{ YYD; return(ANONYMOUS); }
290 <S_SAINF>clientaddr	{ YYD; return(CLIENTADDR); }
291 <S_SAINF>{blcl}any{elcl}	{ YYD; return(PORTANY); }
292 <S_SAINF>any		{ YYD; return(ANY); }
293 <S_SAINF>from		{ YYD; return(FROM); }
294 <S_SAINF>group		{ YYD; return(GROUP); }
295 	/* sainfo spec */
296 <S_SAINF>{bcl}		{ BEGIN S_SAINFS; return(BOC); }
297 <S_SAINF>{semi}		{ BEGIN S_INI; return(EOS); }
298 <S_SAINFS>{ecl}		{ BEGIN S_INI; return(EOC); }
299 <S_SAINFS>pfs_group	{ YYD; return(PFS_GROUP); }
300 <S_SAINFS>remoteid	{ YYD; return(REMOTEID); }
301 <S_SAINFS>my_identifier	{ YYD; return(MY_IDENTIFIER); }
302 <S_SAINFS>lifetime	{ YYD; return(LIFETIME); }
303 <S_SAINFS>time		{ YYD; return(LIFETYPE_TIME); }
304 <S_SAINFS>byte		{ YYD; return(LIFETYPE_BYTE); }
305 <S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); }
306 <S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); }
307 <S_SAINFS>compression_algorithm	{ YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); }
308 <S_SAINFS>{comma}	{ YYD; return(COMMA); }
309 
310 	/* remote */
311 <S_INI>remote		{ BEGIN S_RMT; YYDB; return(REMOTE); }
312 <S_RMT>anonymous	{ YYD; return(ANONYMOUS); }
313 <S_RMT>inherit		{ YYD; return(INHERIT); }
314 <S_RMT>{semi}		{ BEGIN S_INI; YYDB; return(EOS); }
315 	/* remote spec */
316 <S_RMT>{bcl}		{ BEGIN S_RMTS; return(BOC); }
317 <S_RMTS>{ecl}		{ BEGIN S_INI; return(EOC); }
318 <S_RMTS>remote_address	{ YYD; return(REMOTE_ADDRESS); }
319 <S_RMTS>exchange_mode	{ YYD; return(EXCHANGE_MODE); }
320 <S_RMTS>{comma}		{ YYD; /* XXX ignored, but to be handled. */ ; }
321 <S_RMTS>base		{ YYD; yylval.num = ISAKMP_ETYPE_BASE; return(EXCHANGETYPE); }
322 <S_RMTS>main		{ YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); }
323 <S_RMTS>aggressive	{ YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); }
324 <S_RMTS>doi		{ YYD; return(DOI); }
325 <S_RMTS>ipsec_doi	{ YYD; yylval.num = IPSEC_DOI; return(DOITYPE); }
326 <S_RMTS>situation	{ YYD; return(SITUATION); }
327 <S_RMTS>identity_only	{ YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); }
328 <S_RMTS>secrecy		{ YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); }
329 <S_RMTS>integrity	{ YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); }
330 <S_RMTS>my_identifier	{ YYD; return(MY_IDENTIFIER); }
331 <S_RMTS>xauth_login	{ YYD; return(XAUTH_LOGIN); /* formerly identifier type login */ }
332 <S_RMTS>peers_identifier	{ YYD; return(PEERS_IDENTIFIER); }
333 <S_RMTS>verify_identifier	{ YYD; return(VERIFY_IDENTIFIER); }
334 <S_RMTS>certificate_type	{ YYD; return(CERTIFICATE_TYPE); }
335 <S_RMTS>ca_type		{ YYD; return(CA_TYPE); }
336 <S_RMTS>x509		{ YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); }
337 <S_RMTS>plain_rsa	{ YYD; yylval.num = ISAKMP_CERT_PLAINRSA; return(CERT_PLAINRSA); }
338 <S_RMTS>peers_certfile	{ YYD; return(PEERS_CERTFILE); }
339 <S_RMTS>dnssec		{ YYD; return(DNSSEC); }
340 <S_RMTS>verify_cert	{ YYD; return(VERIFY_CERT); }
341 <S_RMTS>send_cert	{ YYD; return(SEND_CERT); }
342 <S_RMTS>send_cr		{ YYD; return(SEND_CR); }
343 <S_RMTS>match_empty_cr	{ YYD; return(MATCH_EMPTY_CR); }
344 <S_RMTS>dh_group	{ YYD; return(DH_GROUP); }
345 <S_RMTS>nonce_size	{ YYD; return(NONCE_SIZE); }
346 <S_RMTS>generate_policy	{ YYD; return(GENERATE_POLICY); }
347 <S_RMTS>unique		{ YYD; yylval.num = GENERATE_POLICY_UNIQUE; return(GENERATE_LEVEL); }
348 <S_RMTS>require		{ YYD; yylval.num = GENERATE_POLICY_REQUIRE; return(GENERATE_LEVEL); }
349 <S_RMTS>support_proxy	{ YYD; return(SUPPORT_PROXY); }
350 <S_RMTS>initial_contact	{ YYD; return(INITIAL_CONTACT); }
351 <S_RMTS>nat_traversal	{ YYD; return(NAT_TRAVERSAL); }
352 <S_RMTS>force		{ YYD; return(REMOTE_FORCE_LEVEL); }
353 <S_RMTS>proposal_check	{ YYD; return(PROPOSAL_CHECK); }
354 <S_RMTS>obey		{ YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); }
355 <S_RMTS>strict		{ YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); }
356 <S_RMTS>exact		{ YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); }
357 <S_RMTS>claim		{ YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); }
358 <S_RMTS>keepalive	{ YYD; return(KEEPALIVE); }
359 <S_RMTS>passive		{ YYD; return(PASSIVE); }
360 <S_RMTS>lifetime	{ YYD; return(LIFETIME); }
361 <S_RMTS>time		{ YYD; return(LIFETYPE_TIME); }
362 <S_RMTS>byte		{ YYD; return(LIFETYPE_BYTE); }
363 <S_RMTS>dpd			{ YYD; return(DPD); }
364 <S_RMTS>dpd_delay	{ YYD; return(DPD_DELAY); }
365 <S_RMTS>dpd_retry	{ YYD; return(DPD_RETRY); }
366 <S_RMTS>dpd_maxfail	{ YYD; return(DPD_MAXFAIL); }
367 <S_RMTS>ph1id		{ YYD; return(PH1ID); }
368 <S_RMTS>ike_frag	{ YYD; return(IKE_FRAG); }
369 <S_RMTS>esp_frag	{ YYD; return(ESP_FRAG); }
370 <S_RMTS>script		{ YYD; return(SCRIPT); }
371 <S_RMTS>phase1_up	{ YYD; return(PHASE1_UP); }
372 <S_RMTS>phase1_down	{ YYD; return(PHASE1_DOWN); }
373 <S_RMTS>phase1_dead	{ YYD; return(PHASE1_DEAD); }
374 <S_RMTS>mode_cfg	{ YYD; return(MODE_CFG); }
375 <S_RMTS>weak_phase1_check { YYD; return(WEAK_PHASE1_CHECK); }
376 <S_RMTS>rekey		{ YYD; return(REKEY); }
377 	/* remote proposal */
378 <S_RMTS>proposal	{ BEGIN S_RMTP; YYDB; return(PROPOSAL); }
379 <S_RMTP>{bcl}		{ return(BOC); }
380 <S_RMTP>{ecl}		{ BEGIN S_RMTS; return(EOC); }
381 <S_RMTP>lifetime	{ YYD; return(LIFETIME); }
382 <S_RMTP>time		{ YYD; return(LIFETYPE_TIME); }
383 <S_RMTP>byte		{ YYD; return(LIFETYPE_BYTE); }
384 <S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); }
385 <S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); }
386 <S_RMTP>hash_algorithm	{ YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); }
387 <S_RMTP>dh_group	{ YYD; return(DH_GROUP); }
388 <S_RMTP>gss_id		{ YYD; return(GSS_ID); }
389 <S_RMTP>gssapi_id	{ YYD; return(GSS_ID); } /* for back compatibility */
390 
391 	/* GSS ID encoding type (global) */
392 <S_INI>gss_id_enc	{ BEGIN S_GSSENC; YYDB; return(GSS_ID_ENC); }
393 <S_GSSENC>latin1	{ YYD; yylval.num = LC_GSSENC_LATIN1;
394 				return(GSS_ID_ENCTYPE); }
395 <S_GSSENC>utf-16le	{ YYD; yylval.num = LC_GSSENC_UTF16LE;
396 				return(GSS_ID_ENCTYPE); }
397 <S_GSSENC>{semi}	{ BEGIN S_INI; YYDB; return(EOS); }
398 
399 	/* parameter */
400 on		{ YYD; yylval.num = TRUE; return(SWITCH); }
401 off		{ YYD; yylval.num = FALSE; return(SWITCH); }
402 
403 	/* prefix */
404 {slash}{digit}{1,3} {
405 			YYD;
406 			yytext++;
407 			yylval.num = atoi(yytext);
408 			return(PREFIX);
409 		}
410 
411 	/* port number */
412 {blcl}{decstring}{elcl}	{
413 			char *p = yytext;
414 			YYD;
415 			while (*++p != ']') ;
416 			*p = 0;
417 			yytext++;
418 			yylval.num = atoi(yytext);
419 			return(PORT);
420 		}
421 
422 	/* address range */
423 {hyphen}{addrstring} {
424                         YYD;
425                         yytext++;
426 			yylval.val = vmalloc(yyleng + 1);
427 			if (yylval.val == NULL) {
428 				yyerror("vmalloc failed");
429 				return -1;
430 			}
431 			memcpy(yylval.val->v, yytext, yylval.val->l);
432                         return(ADDRRANGE);
433                 }
434 
435 	/* upper protocol */
436 esp		{ YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); }
437 ah		{ YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); }
438 ipcomp		{ YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); }
439 icmp		{ YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); }
440 icmp6		{ YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); }
441 tcp		{ YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); }
442 udp		{ YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); }
443 gre		{ YYD; yylval.num = IPPROTO_GRE; return(UL_PROTO); }
444 
445 	/* algorithm type */
446 des_iv64	{ YYD; yylval.num = algtype_des_iv64;	return(ALGORITHMTYPE); }
447 des		{ YYD; yylval.num = algtype_des;	return(ALGORITHMTYPE); }
448 3des		{ YYD; yylval.num = algtype_3des;	return(ALGORITHMTYPE); }
449 rc5		{ YYD; yylval.num = algtype_rc5;	return(ALGORITHMTYPE); }
450 idea 		{ YYD; yylval.num = algtype_idea;	return(ALGORITHMTYPE); }
451 cast128		{ YYD; yylval.num = algtype_cast128;	return(ALGORITHMTYPE); }
452 blowfish	{ YYD; yylval.num = algtype_blowfish;	return(ALGORITHMTYPE); }
453 3idea		{ YYD; yylval.num = algtype_3idea;	return(ALGORITHMTYPE); }
454 des_iv32	{ YYD; yylval.num = algtype_des_iv32;	return(ALGORITHMTYPE); }
455 rc4 		{ YYD; yylval.num = algtype_rc4;	return(ALGORITHMTYPE); }
456 null_enc	{ YYD; yylval.num = algtype_null_enc;	return(ALGORITHMTYPE); }
457 null		{ YYD; yylval.num = algtype_null_enc;	return(ALGORITHMTYPE); }
458 aes		{ YYD; yylval.num = algtype_aes;	return(ALGORITHMTYPE); }
459 aes_gcm_16		{ YYD; yylval.num = algtype_aesgcm16;	return(ALGORITHMTYPE); }
460 rijndael	{ YYD; yylval.num = algtype_aes;	return(ALGORITHMTYPE); }
461 twofish		{ YYD; yylval.num = algtype_twofish;	return(ALGORITHMTYPE); }
462 camellia	{ YYD; yylval.num = algtype_camellia;	return(ALGORITHMTYPE); }
463 non_auth	{ YYD; yylval.num = algtype_non_auth;	return(ALGORITHMTYPE); }
464 hmac_md5	{ YYD; yylval.num = algtype_hmac_md5;	return(ALGORITHMTYPE); }
465 hmac_sha1	{ YYD; yylval.num = algtype_hmac_sha1;	return(ALGORITHMTYPE); }
466 hmac_sha2_256	{ YYD; yylval.num = algtype_hmac_sha2_256;	return(ALGORITHMTYPE); }
467 hmac_sha256	{ YYD; yylval.num = algtype_hmac_sha2_256;	return(ALGORITHMTYPE); }
468 hmac_sha2_384	{ YYD; yylval.num = algtype_hmac_sha2_384;	return(ALGORITHMTYPE); }
469 hmac_sha384	{ YYD; yylval.num = algtype_hmac_sha2_384;	return(ALGORITHMTYPE); }
470 hmac_sha2_512	{ YYD; yylval.num = algtype_hmac_sha2_512;	return(ALGORITHMTYPE); }
471 hmac_sha512	{ YYD; yylval.num = algtype_hmac_sha2_512;	return(ALGORITHMTYPE); }
472 des_mac		{ YYD; yylval.num = algtype_des_mac;	return(ALGORITHMTYPE); }
473 kpdk		{ YYD; yylval.num = algtype_kpdk;	return(ALGORITHMTYPE); }
474 md5		{ YYD; yylval.num = algtype_md5;	return(ALGORITHMTYPE); }
475 sha1		{ YYD; yylval.num = algtype_sha1;	return(ALGORITHMTYPE); }
476 tiger		{ YYD; yylval.num = algtype_tiger;	return(ALGORITHMTYPE); }
477 sha2_256	{ YYD; yylval.num = algtype_sha2_256;	return(ALGORITHMTYPE); }
478 sha256		{ YYD; yylval.num = algtype_sha2_256;	return(ALGORITHMTYPE); }
479 sha2_384	{ YYD; yylval.num = algtype_sha2_384;	return(ALGORITHMTYPE); }
480 sha384		{ YYD; yylval.num = algtype_sha2_384;	return(ALGORITHMTYPE); }
481 sha2_512	{ YYD; yylval.num = algtype_sha2_512;	return(ALGORITHMTYPE); }
482 sha512		{ YYD; yylval.num = algtype_sha2_512;	return(ALGORITHMTYPE); }
483 oui		{ YYD; yylval.num = algtype_oui;	return(ALGORITHMTYPE); }
484 deflate		{ YYD; yylval.num = algtype_deflate;	return(ALGORITHMTYPE); }
485 lzs		{ YYD; yylval.num = algtype_lzs;	return(ALGORITHMTYPE); }
486 modp768		{ YYD; yylval.num = algtype_modp768;	return(ALGORITHMTYPE); }
487 modp1024	{ YYD; yylval.num = algtype_modp1024;	return(ALGORITHMTYPE); }
488 modp1536	{ YYD; yylval.num = algtype_modp1536;	return(ALGORITHMTYPE); }
489 ec2n155		{ YYD; yylval.num = algtype_ec2n155;	return(ALGORITHMTYPE); }
490 ec2n185		{ YYD; yylval.num = algtype_ec2n185;	return(ALGORITHMTYPE); }
491 modp2048	{ YYD; yylval.num = algtype_modp2048;	return(ALGORITHMTYPE); }
492 modp3072	{ YYD; yylval.num = algtype_modp3072;	return(ALGORITHMTYPE); }
493 modp4096	{ YYD; yylval.num = algtype_modp4096;	return(ALGORITHMTYPE); }
494 modp6144	{ YYD; yylval.num = algtype_modp6144;	return(ALGORITHMTYPE); }
495 modp8192	{ YYD; yylval.num = algtype_modp8192;	return(ALGORITHMTYPE); }
496 pre_shared_key	{ YYD; yylval.num = algtype_psk;	return(ALGORITHMTYPE); }
497 rsasig		{ YYD; yylval.num = algtype_rsasig;	return(ALGORITHMTYPE); }
498 dsssig		{ YYD; yylval.num = algtype_dsssig;	return(ALGORITHMTYPE); }
499 rsaenc		{ YYD; yylval.num = algtype_rsaenc;	return(ALGORITHMTYPE); }
500 rsarev		{ YYD; yylval.num = algtype_rsarev;	return(ALGORITHMTYPE); }
501 gssapi_krb	{ YYD; yylval.num = algtype_gssapikrb;	return(ALGORITHMTYPE); }
502 hybrid_rsa_server {
503 #ifdef ENABLE_HYBRID
504 	YYD; yylval.num = algtype_hybrid_rsa_s; return(ALGORITHMTYPE);
505 #else
506 	yyerror("racoon not configured with --enable-hybrid");
507 #endif
508 }
509 hybrid_dss_server {
510 #ifdef ENABLE_HYBRID
511 	YYD; yylval.num = algtype_hybrid_dss_s; return(ALGORITHMTYPE);
512 #else
513 	yyerror("racoon not configured with --enable-hybrid");
514 #endif
515 }
516 hybrid_rsa_client {
517 #ifdef ENABLE_HYBRID
518 	YYD; yylval.num = algtype_hybrid_rsa_c; return(ALGORITHMTYPE);
519 #else
520 	yyerror("racoon not configured with --enable-hybrid");
521 #endif
522 }
523 hybrid_dss_client {
524 #ifdef ENABLE_HYBRID
525 	YYD; yylval.num = algtype_hybrid_dss_c; return(ALGORITHMTYPE);
526 #else
527 	yyerror("racoon not configured with --enable-hybrid");
528 #endif
529 }
530 xauth_psk_server {
531 #ifdef ENABLE_HYBRID
532 	YYD; yylval.num = algtype_xauth_psk_s; return(ALGORITHMTYPE);
533 #else
534 	yyerror("racoon not configured with --enable-hybrid");
535 #endif
536 }
537 xauth_psk_client {
538 #ifdef ENABLE_HYBRID
539 	YYD; yylval.num = algtype_xauth_psk_c; return(ALGORITHMTYPE);
540 #else
541 	yyerror("racoon not configured with --enable-hybrid");
542 #endif
543 }
544 xauth_rsa_server {
545 #ifdef ENABLE_HYBRID
546 	YYD; yylval.num = algtype_xauth_rsa_s; return(ALGORITHMTYPE);
547 #else
548 	yyerror("racoon not configured with --enable-hybrid");
549 #endif
550 }
551 xauth_rsa_client {
552 #ifdef ENABLE_HYBRID
553 	YYD; yylval.num = algtype_xauth_rsa_c; return(ALGORITHMTYPE);
554 #else
555 	yyerror("racoon not configured with --enable-hybrid");
556 #endif
557 }
558 
559 
560 	/* identifier type */
561 user_fqdn	{ YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); }
562 fqdn		{ YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); }
563 keyid		{ YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); }
564 address		{ YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); }
565 subnet		{ YYD; yylval.num = IDTYPE_SUBNET; return(IDENTIFIERTYPE); }
566 asn1dn		{ YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
567 
568 	/* identifier qualifier */
569 tag		{ YYD; yylval.num = IDQUAL_TAG;  return(IDENTIFIERQUAL); }
570 file		{ YYD; yylval.num = IDQUAL_FILE; return(IDENTIFIERQUAL); }
571 
572 	/* units */
573 B|byte|bytes		{ YYD; return(UNITTYPE_BYTE); }
574 KB			{ YYD; return(UNITTYPE_KBYTES); }
575 MB			{ YYD; return(UNITTYPE_MBYTES); }
576 TB			{ YYD; return(UNITTYPE_TBYTES); }
577 sec|secs|second|seconds	{ YYD; return(UNITTYPE_SEC); }
578 min|mins|minute|minutes	{ YYD; return(UNITTYPE_MIN); }
579 hour|hours		{ YYD; return(UNITTYPE_HOUR); }
580 
581 	/* boolean */
582 yes		{ YYD; yylval.num = TRUE; return(BOOLEAN); }
583 no		{ YYD; yylval.num = FALSE; return(BOOLEAN); }
584 
585 {decstring}	{
586 			char *bp;
587 
588 			YYD;
589 			yylval.num = strtoul(yytext, &bp, 10);
590 			return(NUMBER);
591 		}
592 
593 {hexstring}	{
594 			char *p;
595 
596 			YYD;
597 			yylval.val = vmalloc(yyleng + (yyleng & 1) + 1);
598 			if (yylval.val == NULL) {
599 				yyerror("vmalloc failed");
600 				return -1;
601 			}
602 
603 			p = yylval.val->v;
604 			*p++ = '0';
605 			*p++ = 'x';
606 
607 			/* fixed string if length is odd. */
608 			if (yyleng & 1)
609 				*p++ = '0';
610 			memcpy(p, &yytext[2], yyleng - 1);
611 
612 			return(HEXSTRING);
613 		}
614 
615 {quotedstring}	{
616 			char *p = yytext;
617 
618 			YYD;
619 			while (*++p != '"') ;
620 			*p = '\0';
621 
622 			yylval.val = vmalloc(yyleng - 1);
623 			if (yylval.val == NULL) {
624 				yyerror("vmalloc failed");
625 				return -1;
626 			}
627 			memcpy(yylval.val->v, &yytext[1], yylval.val->l);
628 
629 			return(QUOTEDSTRING);
630 		}
631 
632 {addrstring}	{
633 			YYD;
634 
635 			yylval.val = vmalloc(yyleng + 1);
636 			if (yylval.val == NULL) {
637 				yyerror("vmalloc failed");
638 				return -1;
639 			}
640 			memcpy(yylval.val->v, yytext, yylval.val->l);
641 
642 			return(ADDRSTRING);
643 		}
644 
645 <<EOF>>		{
646 			yy_delete_buffer(YY_CURRENT_BUFFER);
647 			fclose (incstack[incstackp].fp);
648 			incstack[incstackp].fp = NULL;
649 			racoon_free(incstack[incstackp].path);
650 			incstack[incstackp].path = NULL;
651 			incstackp--;
652     nextfile:
653 			if (incstack[incstackp].matchon <
654 			    incstack[incstackp].matches.gl_pathc) {
655 				char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
656 				incstack[incstackp].matchon++;
657 				incstackp++;
658 				if (yycf_set_buffer(filepath) != 0) {
659 					incstackp--;
660 					goto nextfile;
661 				}
662 				yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
663 				BEGIN(S_INI);
664 			} else {
665 				globfree(&incstack[incstackp].matches);
666 				if (incstackp == 0)
667 					yyterminate();
668 				else
669 					yy_switch_to_buffer(incstack[incstackp].prevstate);
670 			}
671 		}
672 
673 	/* ... */
674 {ws}		{ ; }
675 {nl}		{ incstack[incstackp].lineno++; }
676 {comment}	{ YYD; }
677 {semi}		{ return(EOS); }
678 .		{ yymore(); }
679 
680 %%
681 
682 void
683 yyerror(const char *s, ...)
684 {
685 	char fmt[512];
686 
687 	va_list ap;
688 #ifdef HAVE_STDARG_H
689 	va_start(ap, s);
690 #else
691 	va_start(ap);
692 #endif
693 	snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n",
694 		incstack[incstackp].path, incstack[incstackp].lineno,
695 		yytext, s);
696 	plogv(LLV_ERROR, LOCATION, NULL, fmt, ap);
697 	va_end(ap);
698 
699 	yyerrorcount++;
700 }
701 
702 void
703 yywarn(const char *s, ...)
704 {
705 	char fmt[512];
706 
707 	va_list ap;
708 #ifdef HAVE_STDARG_H
709 	va_start(ap, s);
710 #else
711 	va_start(ap);
712 #endif
713 	snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n",
714 		incstack[incstackp].path, incstack[incstackp].lineno,
715 		yytext, s);
716 	plogv(LLV_WARNING, LOCATION, NULL, fmt, ap);
717 	va_end(ap);
718 }
719 
720 int
721 yycf_switch_buffer(path)
722 	char *path;
723 {
724 	char *filepath = NULL;
725 
726 	/* got the include file name */
727 	if (incstackp >= MAX_INCLUDE_DEPTH) {
728 		plog(LLV_ERROR, LOCATION, NULL,
729 			"Includes nested too deeply");
730 		return -1;
731 	}
732 
733 	if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 ||
734 	    incstack[incstackp].matches.gl_pathc == 0) {
735 		plog(LLV_ERROR, LOCATION, NULL,
736 			"glob found no matches for path \"%s\"\n", path);
737 		return -1;
738 	}
739 	incstack[incstackp].matchon = 0;
740 	incstack[incstackp].prevstate = YY_CURRENT_BUFFER;
741 
742     nextmatch:
743 	if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc)
744 		return -1;
745 	filepath =
746 	    incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
747 	incstack[incstackp].matchon++;
748 	incstackp++;
749 
750 	if (yycf_set_buffer(filepath) != 0) {
751 	      incstackp--;
752 	      goto nextmatch;
753 	}
754 
755 	yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
756 
757 	BEGIN(S_INI);
758 
759 	return 0;
760 }
761 
762 int
763 yycf_set_buffer(path)
764 	char *path;
765 {
766 	yyin = fopen(path, "r");
767 	if (yyin == NULL) {
768 		fprintf(stderr, "failed to open file %s (%s)\n",
769 			path, strerror(errno));
770 		plog(LLV_ERROR, LOCATION, NULL,
771 			"failed to open file %s (%s)\n",
772 			path, strerror(errno));
773 		return -1;
774 	}
775 
776 	/* initialize */
777 	incstack[incstackp].fp = yyin;
778 	if (incstack[incstackp].path != NULL)
779 		racoon_free(incstack[incstackp].path);
780 	incstack[incstackp].path = racoon_strdup(path);
781 	STRDUP_FATAL(incstack[incstackp].path);
782 	incstack[incstackp].lineno = 1;
783 	plog(LLV_DEBUG, LOCATION, NULL,
784 		"reading config file %s\n", path);
785 
786 	return 0;
787 }
788 
789 void
790 yycf_init_buffer()
791 {
792 	int i;
793 
794 	for (i = 0; i < MAX_INCLUDE_DEPTH; i++)
795 		memset(&incstack[i], 0, sizeof(incstack[i]));
796 	incstackp = 0;
797 }
798 
799 void
800 yycf_clean_buffer()
801 {
802 	int i;
803 
804 	for (i = 0; i < MAX_INCLUDE_DEPTH; i++) {
805 		if (incstack[i].path != NULL) {
806 			fclose(incstack[i].fp);
807 			racoon_free(incstack[i].path);
808 			incstack[i].path = NULL;
809 		}
810 	}
811 }
812 
813