xref: /netbsd-src/usr.sbin/npf/npfctl/npf_scan.l (revision 48fb7bfab72acd4281a53bbee5ccf3f809019e75)
1 /*	$NetBSD: npf_scan.l,v 1.19 2014/02/13 03:34:40 rmind Exp $	*/
2 
3 /*-
4  * Copyright (c) 2011-2012 The NetBSD Foundation, Inc.
5  * All rights reserved.
6  *
7  * This code is derived from software contributed to The NetBSD Foundation
8  * by Martin Husemann.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  *
19  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29  * POSSIBILITY OF SUCH DAMAGE.
30  */
31 
32 %{
33 #include <stdio.h>
34 #include <stdlib.h>
35 #include <err.h>
36 
37 #include "npfctl.h"
38 #include "npf_parse.h"
39 
40 int	yycolumn;
41 
42 #define	YY_USER_ACTION	yycolumn += yyleng;
43 
44 extern int		yyparsetarget;
45 extern int		yylineno;
46 extern const char *	yyfilename;
47 extern int		yyparse(void);
48 extern void		yyrestart(FILE *);
49 
50 void
51 npfctl_parse_file(const char *name)
52 {
53 	FILE *fp;
54 
55 	fp = fopen(name, "r");
56 	if (fp == NULL) {
57 		err(EXIT_FAILURE, "open '%s'", name);
58 	}
59 	yyparsetarget = NPFCTL_PARSE_FILE;
60 	yyrestart(fp);
61 	yylineno = 1;
62 	yycolumn = 0;
63 	yyfilename = name;
64 	yyparse();
65 	fclose(fp);
66 }
67 
68 void
69 npfctl_parse_string(const char *str)
70 {
71 	YY_BUFFER_STATE bs;
72 
73 	yyparsetarget = NPFCTL_PARSE_STRING;
74 	bs = yy_scan_string(str);
75 	yyfilename = "stdin";
76 	yyparse();
77 	yy_delete_buffer(bs);
78 }
79 
80 %}
81 
82 %option noyywrap nounput noinput
83 
84 ID	[a-zA-Z_][a-zA-Z_0-9]*
85 DID	[a-zA-Z_][a-zA-Z_0-9-]*
86 NUMBER	[0-9]+
87 
88 %%
89 alg			return ALG;
90 table			return TABLE;
91 type			return TYPE;
92 hash			return HASH;
93 tree			return TREE;
94 cdb			return CDB;
95 static			return TSTATIC;
96 dynamic			return TDYNAMIC;
97 file			return TFILE;
98 map			return MAP;
99 "<->"			return ARROWBOTH;
100 "<-"			return ARROWLEFT;
101 "->"			return ARROWRIGHT;
102 algo			return ALGO;
103 npt66			return NPT66;
104 "-"			return MINUS;
105 procedure		return PROCEDURE;
106 \\\n			yylineno++; yycolumn = 0;
107 \n			yylineno++; yycolumn = 0; return SEPLINE;
108 ;			return SEPLINE;
109 name			return NAME;
110 group			return GROUP;
111 default			return DEFAULT;
112 in			return IN;
113 out			return OUT;
114 forw			return FORW;
115 interface		return INTERFACE;
116 all			return ALL;
117 block			return BLOCK;
118 pass			return PASS;
119 pcap-filter		return PCAP_FILTER;
120 stateful		return STATEFUL;
121 apply			return APPLY;
122 final			return FINAL;
123 quick			return FINAL;
124 on			return ON;
125 inet6			return INET6;
126 inet4			return INET4;
127 proto			return PROTO;
128 family			return FAMILY;
129 tcp			return TCP;
130 icmp			{ yylval.num = IPPROTO_ICMP; return ICMP; }
131 ipv6-icmp		{ yylval.num = IPPROTO_ICMPV6; return ICMP6; }
132 \"ipv6-icmp\"		{ yylval.num = IPPROTO_ICMPV6; return ICMP6; }
133 return-rst		return RETURNRST;
134 return-icmp		return RETURNICMP;
135 return			return RETURN;
136 ruleset			return RULESET;
137 from			return FROM;
138 to			return TO;
139 port			return PORT;
140 flags			return FLAGS;
141 icmp-type		return ICMPTYPE;
142 code			return CODE;
143 any			return ANY;
144 
145 "/"			return SLASH;
146 "{"			return CURLY_OPEN;
147 "}"			return CURLY_CLOSE;
148 "("			return PAR_OPEN;
149 ")"			return PAR_CLOSE;
150 ","			return COMMA;
151 "="			return EQ;
152 
153 "0x"[0-9a-fA-F]+ {
154 			char *endp, *buf = ecalloc(1, yyleng + 1);
155 			buf[yyleng] = 0;
156 			yylval.num = strtoul(buf+2, &endp, 16);
157 			free(buf);
158 			return HEX;
159 		}
160 
161 {NUMBER}"."{NUMBER} {
162 			char *endp, *buf = estrndup(yytext, yyleng);
163 			yylval.fpnum = strtod(buf, &endp);
164 			free(buf);
165 			return FPNUM;
166 		}
167 
168 [0-9a-fA-F]+":"[0-9a-fA-F:]* {
169 			yylval.str = estrndup(yytext, yyleng);
170 			return IPV6ADDR;
171 		}
172 
173 {NUMBER}"."[0-9][0-9.]* {
174 			yylval.str = estrndup(yytext, yyleng);
175 			return IPV4ADDR;
176 		}
177 
178 {NUMBER}	{
179 			char *endp, *buf = estrndup(yytext, yyleng);
180 			yylval.num = strtoul(buf, &endp, 10);
181 			free(buf);
182 			return NUM;
183 		}
184 
185 "<"{DID}">"	{
186 			yylval.str = estrndup(yytext + 1, yyleng - 2);
187 			return TABLE_ID;
188 		}
189 
190 "$"{ID}		{
191 			yylval.str = estrndup(yytext + 1, yyleng - 1);
192 			return VAR_ID;
193 		}
194 
195 {ID}		{
196 			yylval.str = estrndup(yytext, yyleng);
197 			return IDENTIFIER;
198 		}
199 
200 \"[^\"]*\"	{
201 			yylval.str = estrndup(yytext + 1, yyleng - 2);
202 			return STRING;
203 		}
204 
205 #.*$		/* drop comment until end of line */
206 [ \t]		/* eat whitespace */
207 
208 :		return COLON;
209