]> git.saurik.com Git - apple/ipsec.git/blame - ipsec-tools/racoon/cftoken.l
ipsec-326.tar.gz
[apple/ipsec.git] / ipsec-tools / racoon / cftoken.l
CommitLineData
d1e348cf
A
1/* $NetBSD: cftoken.l,v 1.11.4.1 2007/08/01 11:52:20 vanhu Exp $ */
2
3/* Id: cftoken.l,v 1.53 2006/08/22 18:17:17 manubsd Exp */
52b7d2ce
A
4%option noyywrap
5%{
6/*
7 * Copyright (C) 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002 and 2003 WIDE Project.
8 * All rights reserved.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 * 3. Neither the name of the project nor the names of its contributors
19 * may be used to endorse or promote products derived from this software
20 * without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 */
34
35#include "config.h"
36
37#include <sys/types.h>
38#include <sys/param.h>
39#include <sys/socket.h>
40
41#include <netinet/in.h>
42#ifdef HAVE_NETINET6_IPSEC
43# include <netinet6/ipsec.h>
44#else
45# include <netinet/ipsec.h>
46#endif
47
48#include <stdlib.h>
49#include <stdio.h>
50#include <string.h>
51#include <errno.h>
52#include <limits.h>
53#include <ctype.h>
54#include <glob.h>
55#ifdef HAVE_STDARG_H
56#include <stdarg.h>
57#else
58#include <varargs.h>
59#endif
60
61//%%% BUG FIX - 2 missing include files when not using
62// the bison files
e8d9021d 63#ifdef HAVE_OPENSSL
52b7d2ce
A
64#include <openssl/bn.h>
65#include <openssl/rsa.h>
e8d9021d
A
66#endif
67
52b7d2ce
A
68#include "var.h"
69#include "misc.h"
70#include "vmbuf.h"
71#include "plog.h"
72#include "debug.h"
73
74#include "algorithm.h"
75#include "cfparse_proto.h"
76#include "cftoken_proto.h"
77#include "localconf.h"
78#include "oakley.h"
79#include "isakmp_var.h"
80#include "isakmp.h"
81#include "ipsec_doi.h"
d1e348cf 82#include "policy.h"
52b7d2ce 83#include "proposal.h"
d1e348cf 84#include "remoteconf.h"
52b7d2ce
A
85#include "nattraversal.h"
86#ifdef GC
87#include "gcmalloc.h"
88#endif
89
52b7d2ce 90#include "y.tab.h"
52b7d2ce
A
91
92int yyerrorcount = 0;
93
94#if defined(YIPS_DEBUG)
65c25746 95# define YYDB plog(ASL_LEVEL_DEBUG, \
52b7d2ce
A
96 "begin <%d>%s\n", yy_start, yytext);
97# define YYD { \
65c25746
A
98 plog(ASL_LEVEL_DEBUG, "<%d>%s", \
99 yy_start, loglevel >= ASL_LEVEL_DEBUG ? "\n" : ""); \
52b7d2ce
A
100}
101#else
102# define YYDB
103# define YYD
104#endif /* defined(YIPS_DEBUG) */
105
106#define MAX_INCLUDE_DEPTH 10
107
108static struct include_stack {
109 char *path;
110 FILE *fp;
111 YY_BUFFER_STATE prevstate;
112 int lineno;
113 glob_t matches;
114 int matchon;
115} incstack[MAX_INCLUDE_DEPTH];
116static int incstackp = 0;
117
118static int yy_first_time = 1;
119%}
120
121/* common section */
122nl \n
123ws [ \t]+
124digit [0-9]
125letter [A-Za-z]
126hexdigit [0-9A-Fa-f]
127/*octet (([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */
128special [()+\|\?\*]
129comma \,
130dot \.
131slash \/
132bcl \{
133ecl \}
134blcl \[
135elcl \]
d1e348cf 136hyphen \-
52b7d2ce
A
137percent \%
138semi \;
139comment \#.*
140ccomment "/*"
141bracketstring \<[^>]*\>
142quotedstring \"[^"]*\"
143addrstring [a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*)
144decstring {digit}+
145hexstring 0x{hexdigit}+
146
147%s S_INI S_PRIV S_PTH S_INF S_LOG S_PAD S_LST S_RTRY S_CFG
148%s S_ALGST S_ALGCL
149%s S_SAINF S_SAINFS
150%s S_RMT S_RMTS S_RMTP
151%s S_SA
152%s S_GSSENC
153
154%%
155%{
156 if (yy_first_time) {
157 BEGIN S_INI;
158 yy_first_time = 0;
159 }
160%}
161
52b7d2ce
A
162
163 /* path */
164<S_INI>path { BEGIN S_PTH; YYDB; return(PATH); }
165<S_PTH>include { YYD; yylval.num = LC_PATHTYPE_INCLUDE;
166 return(PATHTYPE); }
167<S_PTH>pre_shared_key { YYD; yylval.num = LC_PATHTYPE_PSK;
168 return(PATHTYPE); }
169<S_PTH>certificate { YYD; yylval.num = LC_PATHTYPE_CERT;
170 return(PATHTYPE); }
52b7d2ce
A
171<S_PTH>pidfile { YYD; yylval.num = LC_PATHTYPE_PIDFILE;
172 return(PATHTYPE); }
173<S_PTH>logfile { YYD; yylval.num = LC_PATHTYPE_LOGFILE;
174 return(PATHTYPE); }
175<S_PTH>{semi} { BEGIN S_INI; YYDB; return(EOS); }
176
177 /* include */
178<S_INI>include { YYDB; return(INCLUDE); }
179
180 /* self information */
85f41bec 181<S_INI>identifier { BEGIN S_INF; YYDB; racoon_yywarn("it is obsoleted. use \"my_identifier\" in each remote directives."); return(IDENTIFIER); }
52b7d2ce
A
182<S_INF>{semi} { BEGIN S_INI; return(EOS); }
183
184 /* special */
185<S_INI>complex_bundle { YYDB; return(COMPLEX_BUNDLE); }
186
187 /* logging */
188<S_INI>log { BEGIN S_LOG; YYDB; return(LOGGING); }
65c25746
A
189<S_LOG>error { YYD; yylval.num = ASL_LEVEL_ERR; return(LOGLEV); }
190<S_LOG>warning { YYD; yylval.num = ASL_LEVEL_WARNING; return(LOGLEV); }
191<S_LOG>notify { YYD; yylval.num = ASL_LEVEL_NOTICE; return(LOGLEV); }
192<S_LOG>info { YYD; yylval.num = ASL_LEVEL_INFO; return(LOGLEV); }
193<S_LOG>debug { YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
194<S_LOG>debug2 { YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
195<S_LOG>debug3 { YYD; racoon_yywarn("it is obsoleted. use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
196<S_LOG>debug4 { YYD; racoon_yywarn("it is obsoleted. use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
52b7d2ce
A
197<S_LOG>{semi} { BEGIN S_INI; return(EOS); }
198
199 /* padding */
200<S_INI>padding { BEGIN S_PAD; YYDB; return(PADDING); }
201<S_PAD>{bcl} { return(BOC); }
202<S_PAD>randomize { YYD; return(PAD_RANDOMIZE); }
203<S_PAD>randomize_length { YYD; return(PAD_RANDOMIZELEN); }
204<S_PAD>maximum_length { YYD; return(PAD_MAXLEN); }
205<S_PAD>strict_check { YYD; return(PAD_STRICT); }
206<S_PAD>exclusive_tail { YYD; return(PAD_EXCLTAIL); }
207<S_PAD>{ecl} { BEGIN S_INI; return(EOC); }
208
209 /* listen */
210<S_INI>listen { BEGIN S_LST; YYDB; return(LISTEN); }
211<S_LST>{bcl} { return(BOC); }
212<S_LST>isakmp { YYD; return(X_ISAKMP); }
213<S_LST>isakmp_natt { YYD; return(X_ISAKMP_NATT); }
214<S_LST>admin { YYD; return(X_ADMIN); }
215<S_LST>adminsock { YYD; return(ADMINSOCK); }
216<S_LST>disabled { YYD; return(DISABLED); }
217<S_LST>strict_address { YYD; return(STRICT_ADDRESS); }
218<S_LST>{ecl} { BEGIN S_INI; return(EOC); }
219
220 /* mode_cfg */
221<S_INI>mode_cfg { BEGIN S_CFG; YYDB; return(MODECFG); }
222<S_CFG>{bcl} { return(BOC); }
223<S_CFG>network4 { YYD; return(CFG_NET4); }
224<S_CFG>netmask4 { YYD; return(CFG_MASK4); }
225<S_CFG>dns4 { YYD; return(CFG_DNS4); }
226<S_CFG>wins4 { YYD; return(CFG_NBNS4); }
d1e348cf 227<S_CFG>default_domain { YYD; return(CFG_DEFAULT_DOMAIN); }
52b7d2ce 228<S_CFG>auth_source { YYD; return(CFG_AUTH_SOURCE); }
d1e348cf
A
229<S_CFG>auth_groups { YYD; return(CFG_AUTH_GROUPS); }
230<S_CFG>group_source { YYD; return(CFG_GROUP_SOURCE); }
52b7d2ce
A
231<S_CFG>conf_source { YYD; return(CFG_CONF_SOURCE); }
232<S_CFG>accounting { YYD; return(CFG_ACCOUNTING); }
233<S_CFG>system { YYD; return(CFG_SYSTEM); }
234<S_CFG>local { YYD; return(CFG_LOCAL); }
235<S_CFG>none { YYD; return(CFG_NONE); }
236<S_CFG>radius { YYD; return(CFG_RADIUS); }
237<S_CFG>pam { YYD; return(CFG_PAM); }
238<S_CFG>pool_size { YYD; return(CFG_POOL_SIZE); }
239<S_CFG>banner { YYD; return(CFG_MOTD); }
240<S_CFG>auth_throttle { YYD; return(CFG_AUTH_THROTTLE); }
d1e348cf
A
241<S_CFG>split_network { YYD; return(CFG_SPLIT_NETWORK); }
242<S_CFG>local_lan { YYD; return(CFG_SPLIT_LOCAL); }
243<S_CFG>include { YYD; return(CFG_SPLIT_INCLUDE); }
244<S_CFG>split_dns { YYD; return(CFG_SPLIT_DNS); }
52b7d2ce
A
245<S_CFG>pfs_group { YYD; return(CFG_PFS_GROUP); }
246<S_CFG>save_passwd { YYD; return(CFG_SAVE_PASSWD); }
d1e348cf 247<S_CFG>{comma} { YYD; return(COMMA); }
52b7d2ce
A
248<S_CFG>{ecl} { BEGIN S_INI; return(EOC); }
249
250 /* timer */
251<S_INI>timer { BEGIN S_RTRY; YYDB; return(RETRY); }
252<S_RTRY>{bcl} { return(BOC); }
253<S_RTRY>counter { YYD; return(RETRY_COUNTER); }
254<S_RTRY>interval { YYD; return(RETRY_INTERVAL); }
255<S_RTRY>persend { YYD; return(RETRY_PERSEND); }
256<S_RTRY>phase1 { YYD; return(RETRY_PHASE1); }
257<S_RTRY>phase2 { YYD; return(RETRY_PHASE2); }
258<S_RTRY>natt_keepalive { YYD; return(NATT_KA); }
259<S_RTRY>auto_exit_delay { YYD; return(AUTO_EXIT_DELAY); }
260<S_RTRY>{ecl} { BEGIN S_INI; return(EOC); }
261
262 /* sainfo */
263<S_INI>sainfo { BEGIN S_SAINF; YYDB; return(SAINFO); }
264<S_SAINF>anonymous { YYD; return(ANONYMOUS); }
265<S_SAINF>{blcl}any{elcl} { YYD; return(PORTANY); }
266<S_SAINF>any { YYD; return(ANY); }
267<S_SAINF>from { YYD; return(FROM); }
d1e348cf 268<S_SAINF>group { YYD; return(GROUP); }
52b7d2ce
A
269 /* sainfo spec */
270<S_SAINF>{bcl} { BEGIN S_SAINFS; return(BOC); }
271<S_SAINF>{semi} { BEGIN S_INI; return(EOS); }
272<S_SAINFS>{ecl} { BEGIN S_INI; return(EOC); }
273<S_SAINFS>pfs_group { YYD; return(PFS_GROUP); }
d1e348cf 274<S_SAINFS>remoteid { YYD; return(REMOTEID); }
85f41bec 275<S_SAINFS>identifier { YYD; racoon_yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
52b7d2ce
A
276<S_SAINFS>my_identifier { YYD; return(MY_IDENTIFIER); }
277<S_SAINFS>lifetime { YYD; return(LIFETIME); }
278<S_SAINFS>time { YYD; return(LIFETYPE_TIME); }
279<S_SAINFS>byte { YYD; return(LIFETYPE_BYTE); }
280<S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); }
281<S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); }
282<S_SAINFS>compression_algorithm { YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); }
283<S_SAINFS>{comma} { YYD; return(COMMA); }
284
285 /* remote */
286<S_INI>remote { BEGIN S_RMT; YYDB; return(REMOTE); }
287<S_RMT>anonymous { YYD; return(ANONYMOUS); }
288<S_RMT>inherit { YYD; return(INHERIT); }
289 /* remote spec */
290<S_RMT>{bcl} { BEGIN S_RMTS; return(BOC); }
291<S_RMTS>{ecl} { BEGIN S_INI; return(EOC); }
292<S_RMTS>exchange_mode { YYD; return(EXCHANGE_MODE); }
293<S_RMTS>{comma} { YYD; /* XXX ignored, but to be handled. */ ; }
52b7d2ce
A
294<S_RMTS>main { YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); }
295<S_RMTS>aggressive { YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); }
296<S_RMTS>doi { YYD; return(DOI); }
297<S_RMTS>ipsec_doi { YYD; yylval.num = IPSEC_DOI; return(DOITYPE); }
298<S_RMTS>situation { YYD; return(SITUATION); }
65c25746 299<S_RMTS>ike_version { YYD; return(IKE_VERSION); }
52b7d2ce
A
300<S_RMTS>identity_only { YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); }
301<S_RMTS>secrecy { YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); }
302<S_RMTS>integrity { YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); }
85f41bec 303<S_RMTS>identifier { YYD; racoon_yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
52b7d2ce
A
304<S_RMTS>my_identifier { YYD; return(MY_IDENTIFIER); }
305<S_RMTS>xauth_login { YYD; return(XAUTH_LOGIN); /* formerly identifier type login */ }
306<S_RMTS>peers_identifier { YYD; return(PEERS_IDENTIFIER); }
307<S_RMTS>verify_identifier { YYD; return(VERIFY_IDENTIFIER); }
d9c572c0 308<S_RMTS>local_address { YYD; return(LOCAL_ADDRESS); }
52b7d2ce
A
309<S_RMTS>certificate_type { YYD; return(CERTIFICATE_TYPE); }
310<S_RMTS>ca_type { YYD; return(CA_TYPE); }
311<S_RMTS>x509 { YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); }
e8d9021d 312<S_RMTS>plain_rsa {
85f41bec 313 racoon_yyerror("plainrsa not supported.");
e8d9021d 314}
52b7d2ce 315<S_RMTS>open_dir_auth_group {
e8d9021d 316#if HAVE_OPENDIR
52b7d2ce
A
317 YYD;
318 return(OPEN_DIR_AUTH_GROUP);
319#else
85f41bec 320 racoon_yyerror("Apple specific features not compiled in.");
52b7d2ce
A
321#endif
322}
323<S_RMTS>shared_secret {
52b7d2ce
A
324 YYD;
325 return(SHARED_SECRET);
52b7d2ce
A
326}
327<S_RMTS>in_keychain {
52b7d2ce
A
328 YYD;
329 return(IN_KEYCHAIN);
52b7d2ce
A
330}
331<S_RMTS>certificate_verification {
52b7d2ce
A
332 YYD;
333 return(CERTIFICATE_VERIFICATION);
52b7d2ce
A
334}
335<S_RMTS>peers_certfile { YYD; return(PEERS_CERTFILE); }
336<S_RMTS>dnssec { YYD; return(DNSSEC); }
337<S_RMTS>verify_cert { YYD; return(VERIFY_CERT); }
338<S_RMTS>send_cert { YYD; return(SEND_CERT); }
339<S_RMTS>send_cr { YYD; return(SEND_CR); }
340<S_RMTS>dh_group { YYD; return(DH_GROUP); }
341<S_RMTS>nonce_size { YYD; return(NONCE_SIZE); }
342<S_RMTS>generate_policy { YYD; return(GENERATE_POLICY); }
85f41bec 343<S_RMTS>support_mip6 { YYD; racoon_yywarn("it is obsoleted. use \"support_proxy\"."); return(SUPPORT_PROXY); }
52b7d2ce
A
344<S_RMTS>support_proxy { YYD; return(SUPPORT_PROXY); }
345<S_RMTS>initial_contact { YYD; return(INITIAL_CONTACT); }
346<S_RMTS>nat_traversal { YYD; return(NAT_TRAVERSAL); }
347<S_RMTS>force { YYD; yylval.num = NATT_FORCE; return(NAT_TRAVERSAL_LEVEL); }
348<S_RMTS>nat_traversal_multi_user {
52b7d2ce
A
349 YYD;
350 return(NAT_TRAVERSAL_MULTI_USER);
52b7d2ce 351}
d1e348cf 352<S_RMTS>nat_traversal_keepalive {
d1e348cf
A
353 YYD;
354 return(NAT_TRAVERSAL_KEEPALIVE);
d1e348cf 355}
52b7d2ce
A
356<S_RMTS>proposal_check { YYD; return(PROPOSAL_CHECK); }
357<S_RMTS>obey { YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); }
358<S_RMTS>strict { YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); }
359<S_RMTS>exact { YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); }
360<S_RMTS>claim { YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); }
361<S_RMTS>keepalive { YYD; return(KEEPALIVE); }
362<S_RMTS>passive { YYD; return(PASSIVE); }
363<S_RMTS>lifetime { YYD; return(LIFETIME); }
364<S_RMTS>time { YYD; return(LIFETYPE_TIME); }
365<S_RMTS>byte { YYD; return(LIFETYPE_BYTE); }
366<S_RMTS>dpd { YYD; return(DPD); }
367<S_RMTS>dpd_delay { YYD; return(DPD_DELAY); }
368<S_RMTS>dpd_retry { YYD; return(DPD_RETRY); }
369<S_RMTS>dpd_maxfail { YYD; return(DPD_MAXFAIL); }
d1e348cf
A
370<S_RMTS>dpd_algorithm { YYD; return(DPD_ALGORITHM); }
371<S_RMTS>disconnect_on_idle { YYD; return(DISCONNECT_ON_IDLE); }
372<S_RMTS>idle_timeout { YYD; return(IDLE_TIMEOUT); }
373<S_RMTS>idle_direction { YYD; return(IDLE_DIRECTION); }
52b7d2ce
A
374<S_RMTS>ike_frag { YYD; return(IKE_FRAG); }
375<S_RMTS>esp_frag { YYD; return(ESP_FRAG); }
52b7d2ce 376<S_RMTS>mode_cfg { YYD; return(MODE_CFG); }
d1e348cf 377<S_RMTS>weak_phase1_check { YYD; return(WEAK_PHASE1_CHECK); }
52b7d2ce
A
378 /* remote proposal */
379<S_RMTS>proposal { BEGIN S_RMTP; YYDB; return(PROPOSAL); }
380<S_RMTP>{bcl} { return(BOC); }
381<S_RMTP>{ecl} { BEGIN S_RMTS; return(EOC); }
382<S_RMTP>lifetime { YYD; return(LIFETIME); }
383<S_RMTP>time { YYD; return(LIFETYPE_TIME); }
384<S_RMTP>byte { YYD; return(LIFETYPE_BYTE); }
385<S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); }
386<S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); }
387<S_RMTP>hash_algorithm { YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); }
388<S_RMTP>dh_group { YYD; return(DH_GROUP); }
389<S_RMTP>gss_id { YYD; return(GSS_ID); }
390<S_RMTP>gssapi_id { YYD; return(GSS_ID); } /* for back compatibility */
391
392 /* GSS ID encoding type (global) */
393<S_INI>gss_id_enc { BEGIN S_GSSENC; YYDB; return(GSS_ID_ENC); }
394<S_GSSENC>latin1 { YYD; yylval.num = LC_GSSENC_LATIN1;
395 return(GSS_ID_ENCTYPE); }
396<S_GSSENC>utf-16le { YYD; yylval.num = LC_GSSENC_UTF16LE;
397 return(GSS_ID_ENCTYPE); }
398<S_GSSENC>{semi} { BEGIN S_INI; YYDB; return(EOS); }
399
400 /* parameter */
401on { YYD; yylval.num = TRUE; return(SWITCH); }
402off { YYD; yylval.num = FALSE; return(SWITCH); }
403
404 /* prefix */
405{slash}({digit}{1,3}) {
406 YYD;
407 yytext++;
408 yylval.num = atoi(yytext);
409 return(PREFIX);
410 }
411
412 /* port number */
413{blcl}{decstring}{elcl} {
414 char *p = yytext;
415 YYD;
416 while (*++p != ']') ;
417 *p = 0;
418 yytext++;
419 yylval.num = atoi(yytext);
420 return(PORT);
421 }
422
d1e348cf
A
423 /* address range */
424{hyphen}{addrstring} {
425 YYD;
426 yytext++;
427 yylval.val = vmalloc(yyleng + 1);
428 if (yylval.val == NULL) {
85f41bec 429 racoon_yyerror("vmalloc failed");
d1e348cf
A
430 return -1;
431 }
432 memcpy(yylval.val->v, yytext, yylval.val->l);
433 return(ADDRRANGE);
434 }
435
52b7d2ce
A
436 /* upper protocol */
437esp { YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); }
438ah { YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); }
439ipcomp { YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); }
440icmp { YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); }
441icmp6 { YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); }
442tcp { YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); }
443udp { YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); }
444
445 /* algorithm type */
446des_iv64 { YYD; yylval.num = algtype_des_iv64; return(ALGORITHMTYPE); }
447des { YYD; yylval.num = algtype_des; return(ALGORITHMTYPE); }
4483des { YYD; yylval.num = algtype_3des; return(ALGORITHMTYPE); }
449rc5 { YYD; yylval.num = algtype_rc5; return(ALGORITHMTYPE); }
450idea { YYD; yylval.num = algtype_idea; return(ALGORITHMTYPE); }
451cast128 { YYD; yylval.num = algtype_cast128; return(ALGORITHMTYPE); }
452blowfish { YYD; yylval.num = algtype_blowfish; return(ALGORITHMTYPE); }
4533idea { YYD; yylval.num = algtype_3idea; return(ALGORITHMTYPE); }
454des_iv32 { YYD; yylval.num = algtype_des_iv32; return(ALGORITHMTYPE); }
455rc4 { YYD; yylval.num = algtype_rc4; return(ALGORITHMTYPE); }
456null_enc { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); }
457null { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); }
458aes { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); }
459rijndael { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); }
460twofish { YYD; yylval.num = algtype_twofish; return(ALGORITHMTYPE); }
461non_auth { YYD; yylval.num = algtype_non_auth; return(ALGORITHMTYPE); }
65c25746
A
462hmac_md5 { YYD; yylval.num = algtype_hmac_md5_128; return(ALGORITHMTYPE); }
463hmac_sha1 { YYD; yylval.num = algtype_hmac_sha1_160; return(ALGORITHMTYPE); }
52b7d2ce
A
464hmac_sha2_256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); }
465hmac_sha256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); }
466hmac_sha2_384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); }
467hmac_sha384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); }
468hmac_sha2_512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); }
469hmac_sha512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); }
65c25746
A
470hmac_md5_96 { YYD; yylval.num = algtype_hmac_md5_96; return(ALGORITHMTYPE); }
471hmac_sha1_96 { YYD; yylval.num = algtype_hmac_sha1_96; return(ALGORITHMTYPE); }
52b7d2ce
A
472des_mac { YYD; yylval.num = algtype_des_mac; return(ALGORITHMTYPE); }
473kpdk { YYD; yylval.num = algtype_kpdk; return(ALGORITHMTYPE); }
474md5 { YYD; yylval.num = algtype_md5; return(ALGORITHMTYPE); }
475sha1 { YYD; yylval.num = algtype_sha1; return(ALGORITHMTYPE); }
476tiger { YYD; yylval.num = algtype_tiger; return(ALGORITHMTYPE); }
477sha2_256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); }
478sha256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); }
479sha2_384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); }
480sha384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); }
481sha2_512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); }
482sha512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); }
483oui { YYD; yylval.num = algtype_oui; return(ALGORITHMTYPE); }
484deflate { YYD; yylval.num = algtype_deflate; return(ALGORITHMTYPE); }
485lzs { YYD; yylval.num = algtype_lzs; return(ALGORITHMTYPE); }
486modp768 { YYD; yylval.num = algtype_modp768; return(ALGORITHMTYPE); }
487modp1024 { YYD; yylval.num = algtype_modp1024; return(ALGORITHMTYPE); }
488modp1536 { YYD; yylval.num = algtype_modp1536; return(ALGORITHMTYPE); }
489ec2n155 { YYD; yylval.num = algtype_ec2n155; return(ALGORITHMTYPE); }
490ec2n185 { YYD; yylval.num = algtype_ec2n185; return(ALGORITHMTYPE); }
491modp2048 { YYD; yylval.num = algtype_modp2048; return(ALGORITHMTYPE); }
492modp3072 { YYD; yylval.num = algtype_modp3072; return(ALGORITHMTYPE); }
493modp4096 { YYD; yylval.num = algtype_modp4096; return(ALGORITHMTYPE); }
494modp6144 { YYD; yylval.num = algtype_modp6144; return(ALGORITHMTYPE); }
495modp8192 { YYD; yylval.num = algtype_modp8192; return(ALGORITHMTYPE); }
496pre_shared_key { YYD; yylval.num = algtype_psk; return(ALGORITHMTYPE); }
497rsasig { YYD; yylval.num = algtype_rsasig; return(ALGORITHMTYPE); }
498dsssig { YYD; yylval.num = algtype_dsssig; return(ALGORITHMTYPE); }
499rsaenc { YYD; yylval.num = algtype_rsaenc; return(ALGORITHMTYPE); }
500rsarev { YYD; yylval.num = algtype_rsarev; return(ALGORITHMTYPE); }
501gssapi_krb { YYD; yylval.num = algtype_gssapikrb; return(ALGORITHMTYPE); }
502hybrid_rsa_server {
503#ifdef ENABLE_HYBRID
504 YYD; yylval.num = algtype_hybrid_rsa_s; return(ALGORITHMTYPE);
505#else
85f41bec 506 racoon_yyerror("racoon not configured with --enable-hybrid");
52b7d2ce
A
507#endif
508}
509hybrid_dss_server {
510#ifdef ENABLE_HYBRID
511 YYD; yylval.num = algtype_hybrid_dss_s; return(ALGORITHMTYPE);
512#else
85f41bec 513 racoon_yyerror("racoon not configured with --enable-hybrid");
52b7d2ce
A
514#endif
515}
516hybrid_rsa_client {
517#ifdef ENABLE_HYBRID
518 YYD; yylval.num = algtype_hybrid_rsa_c; return(ALGORITHMTYPE);
519#else
85f41bec 520 racoon_yyerror("racoon not configured with --enable-hybrid");
52b7d2ce
A
521#endif
522}
523hybrid_dss_client {
524#ifdef ENABLE_HYBRID
525 YYD; yylval.num = algtype_hybrid_dss_c; return(ALGORITHMTYPE);
526#else
85f41bec 527 racoon_yyerror("racoon not configured with --enable-hybrid");
52b7d2ce
A
528#endif
529}
530
d1e348cf
A
531xauth_psk_server {
532#ifdef ENABLE_HYBRID
533 YYD; yylval.num = algtype_xauth_psk_s; return(ALGORITHMTYPE);
534#else
85f41bec 535 racoon_yyerror("racoon not configured with --enable-hybrid");
d1e348cf
A
536#endif
537}
538xauth_psk_client {
539#ifdef ENABLE_HYBRID
540 YYD; yylval.num = algtype_xauth_psk_c; return(ALGORITHMTYPE);
541#else
85f41bec 542 racoon_yyerror("racoon not configured with --enable-hybrid");
d1e348cf
A
543#endif
544}
545xauth_rsa_server {
546#ifdef ENABLE_HYBRID
547 YYD; yylval.num = algtype_xauth_rsa_s; return(ALGORITHMTYPE);
548#else
85f41bec 549 racoon_yyerror("racoon not configured with --enable-hybrid");
d1e348cf
A
550#endif
551}
552xauth_rsa_client {
553#ifdef ENABLE_HYBRID
554 YYD; yylval.num = algtype_xauth_rsa_c; return(ALGORITHMTYPE);
555#else
85f41bec 556 racoon_yyerror("racoon not configured with --enable-hybrid");
d1e348cf
A
557#endif
558}
65c25746
A
559eap_psk_client {
560 #ifdef ENABLE_HYBRID
561 YYD; yylval.num = algtype_eap_psk_c; return(ALGORITHMTYPE);
562 #else
563 racoon_yyerror("racoon not configured with --enable-hybrid");
564 #endif
565}
566eap_rsa_client {
567 #ifdef ENABLE_HYBRID
568 YYD; yylval.num = algtype_eap_rsa_c; return(ALGORITHMTYPE);
569 #else
570 racoon_yyerror("racoon not configured with --enable-hybrid");
571 #endif
572}
d1e348cf
A
573
574
52b7d2ce
A
575
576 /* identifier type */
85f41bec 577vendor_id { YYD; racoon_yywarn("it is obsoleted."); return(VENDORID); }
52b7d2ce
A
578user_fqdn { YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); }
579fqdn { YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); }
580keyid { YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); }
581keyid_use {
52b7d2ce
A
582 YYD;
583 yylval.num = IDTYPE_KEYIDUSE;
584 return(IDENTIFIERTYPE);
52b7d2ce
A
585}
586address { YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); }
587subnet { YYD; yylval.num = IDTYPE_SUBNET; return(IDENTIFIERTYPE); }
588asn1dn { YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
85f41bec 589certname { YYD; racoon_yywarn("certname will be obsoleted in near future."); yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
52b7d2ce
A
590
591 /* shared secret type */
592use {
52b7d2ce
A
593 YYD;
594 yylval.num = SECRETTYPE_USE;
595 return(SECRETTYPE);
52b7d2ce
A
596}
597key {
52b7d2ce
A
598 YYD;
599 yylval.num = SECRETTYPE_KEY;
600 return(SECRETTYPE);
52b7d2ce
A
601}
602keychain {
e8d9021d 603#if HAVE_KEYCHAIN
52b7d2ce
A
604 YYD;
605 yylval.num = SECRETTYPE_KEYCHAIN;
606 return(SECRETTYPE);
607#else
85f41bec 608 racoon_yyerror("Apple specific features not compiled in.");
52b7d2ce
A
609#endif
610}
611keychain_by_id {
52b7d2ce
A
612 YYD;
613 yylval.num = SECRETTYPE_KEYCHAIN_BY_ID;
614 return(SECRETTYPE);
52b7d2ce
A
615}
616
617 /* certificate verification */
618openssl {
52b7d2ce
A
619 YYD;
620 yylval.num = VERIFICATION_MODULE_OPENSSL;
621 return(VERIFICATION_MODULE);
52b7d2ce
A
622}
623sec_framework {
52b7d2ce
A
624 YYD;
625 yylval.num = VERIFICATION_MODULE_SEC_FRAMEWORK;
626 return(VERIFICATION_MODULE);
52b7d2ce
A
627}
628use_open_dir {
52b7d2ce
A
629 YYD;
630 yylval.num = VERIFICATION_OPTION_OPEN_DIR;
631 return(VERIFICATION_OPTION);
52b7d2ce
A
632}
633use_peers_identifier {
52b7d2ce
A
634 YYD;
635 yylval.num = VERIFICATION_OPTION_PEERS_IDENTIFIER;
636 return(VERIFICATION_OPTION);
52b7d2ce
A
637}
638
d1e348cf
A
639 /* identifier qualifier */
640tag { YYD; yylval.num = IDQUAL_TAG; return(IDENTIFIERQUAL); }
641file { YYD; yylval.num = IDQUAL_FILE; return(IDENTIFIERQUAL); }
642
52b7d2ce
A
643 /* units */
644B|byte|bytes { YYD; return(UNITTYPE_BYTE); }
645KB { YYD; return(UNITTYPE_KBYTES); }
646MB { YYD; return(UNITTYPE_MBYTES); }
647TB { YYD; return(UNITTYPE_TBYTES); }
648sec|secs|second|seconds { YYD; return(UNITTYPE_SEC); }
649min|mins|minute|minutes { YYD; return(UNITTYPE_MIN); }
650hour|hours { YYD; return(UNITTYPE_HOUR); }
651
d1e348cf
A
652dpd_default { YYD; return(DPD_ALGO_TYPE_DEFAULT); }
653dpd_inbound_detect { YYD; return(DPD_ALGO_TYPE_INBOUND); }
654dpd_blackhole_detect { YYD; return(DPD_ALGO_TYPE_BLACKHOLE); }
655
656idle_any { YYD; return(IDLE_DIRECTION_ANY); }
657idle_inbound { YYD; return(IDLE_DIRECTION_IN); }
658idle_outbound { YYD; return(IDLE_DIRECTION_OUT); }
659
52b7d2ce
A
660 /* boolean */
661yes { YYD; yylval.num = TRUE; return(BOOLEAN); }
662no { YYD; yylval.num = FALSE; return(BOOLEAN); }
663
664{decstring} {
665 char *bp;
666
667 YYD;
668 yylval.num = strtol(yytext, &bp, 10);
669 return(NUMBER);
670 }
671
672{hexstring} {
673 char *p;
674
675 YYD;
676 yylval.val = vmalloc(yyleng + (yyleng & 1) + 1);
677 if (yylval.val == NULL) {
85f41bec 678 racoon_yyerror("vmalloc failed");
52b7d2ce
A
679 return -1;
680 }
681
682 p = yylval.val->v;
683 *p++ = '0';
684 *p++ = 'x';
685
686 /* fixed string if length is odd. */
687 if (yyleng & 1)
688 *p++ = '0';
689 memcpy(p, &yytext[2], yyleng - 1);
690
691 return(HEXSTRING);
692 }
693
694{quotedstring} {
695 char *p = yytext;
696
697 YYD;
698 while (*++p != '"') ;
699 *p = '\0';
700
701 yylval.val = vmalloc(yyleng - 1);
702 if (yylval.val == NULL) {
85f41bec 703 racoon_yyerror("vmalloc failed");
52b7d2ce
A
704 return -1;
705 }
706 memcpy(yylval.val->v, &yytext[1], yylval.val->l);
707
708 return(QUOTEDSTRING);
709 }
710
711{addrstring} {
712 YYD;
713
714 yylval.val = vmalloc(yyleng + 1);
715 if (yylval.val == NULL) {
85f41bec 716 racoon_yyerror("vmalloc failed");
52b7d2ce
A
717 return -1;
718 }
719 memcpy(yylval.val->v, yytext, yylval.val->l);
720
721 return(ADDRSTRING);
722 }
723
724<<EOF>> {
725 yy_delete_buffer(YY_CURRENT_BUFFER);
52b7d2ce
A
726 incstackp--;
727 nextfile:
e8d9021d
A
728 if (incstack[incstackp].matches.gl_pathc != 0 &&
729 incstack[incstackp].matches.gl_pathv &&
730 incstack[incstackp].matchon <
52b7d2ce
A
731 incstack[incstackp].matches.gl_pathc) {
732 char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
733 incstack[incstackp].matchon++;
734 incstackp++;
735 if (yycf_set_buffer(filepath) != 0) {
736 incstackp--;
737 goto nextfile;
738 }
739 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
740 BEGIN(S_INI);
741 } else {
742 globfree(&incstack[incstackp].matches);
743 if (incstackp == 0)
744 yyterminate();
745 else
746 yy_switch_to_buffer(incstack[incstackp].prevstate);
747 }
748 }
749
750 /* ... */
751{ws} { ; }
752{nl} { incstack[incstackp].lineno++; }
753{comment} { YYD; }
754{semi} { return(EOS); }
755. { yymore(); }
756
757%%
758
759void
85f41bec 760yyerror(const char *msg)
52b7d2ce 761{
65c25746 762 plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg);
52b7d2ce
A
763 yyerrorcount++;
764}
765
766void
85f41bec 767yywarn(const char *msg)
52b7d2ce 768{
65c25746 769 plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg);
85f41bec 770}
52b7d2ce 771
85f41bec
A
772void
773racoon_yyerror(const char *fmt, ...)
774{
775 va_list ap;
776 char msg[512];
777
778 va_start(ap, fmt);
779 vsnprintf(msg, sizeof(msg), fmt, ap);
780 va_end(ap);
781
782 yyerror(msg);
783}
784
785void
786racoon_yywarn(const char *fmt, ...)
787{
788 va_list ap;
789 char msg[512];
790
791 va_start(ap, fmt);
792 vsnprintf(msg, sizeof(msg), fmt, ap);
793 va_end(ap);
794
795 yywarn(msg);
52b7d2ce
A
796}
797
798int
799yycf_switch_buffer(path)
800 char *path;
801{
802 char *filepath = NULL;
803
804 /* got the include file name */
805 if (incstackp >= MAX_INCLUDE_DEPTH) {
65c25746 806 plog(ASL_LEVEL_ERR,
52b7d2ce
A
807 "Includes nested too deeply");
808 return -1;
809 }
810
811 if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 ||
812 incstack[incstackp].matches.gl_pathc == 0) {
65c25746 813 plog(ASL_LEVEL_WARNING,
d1e348cf
A
814 "glob found no matches for path \"%s\"\n", path);
815 return 0;
52b7d2ce
A
816 }
817 incstack[incstackp].matchon = 0;
818 incstack[incstackp].prevstate = YY_CURRENT_BUFFER;
819
820 nextmatch:
821 if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc)
822 return -1;
823 filepath =
824 incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
825 incstack[incstackp].matchon++;
826 incstackp++;
827
828 if (yycf_set_buffer(filepath) != 0) {
829 incstackp--;
830 goto nextmatch;
831 }
832
833 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
834
835 BEGIN(S_INI);
836
837 return 0;
838}
839
840int
841yycf_set_buffer(path)
842 char *path;
843{
844 yyin = fopen(path, "r");
845 if (yyin == NULL) {
846 fprintf(stderr, "failed to open file %s (%s)\n",
847 path, strerror(errno));
65c25746 848 plog(ASL_LEVEL_ERR,
52b7d2ce
A
849 "failed to open file %s (%s)\n",
850 path, strerror(errno));
851 return -1;
852 }
853
854 /* initialize */
d1e348cf
A
855 if (incstack[incstackp].path != NULL) {
856 fclose(incstack[incstackp].fp);
857 racoon_free(incstack[incstackp].path);
858 }
52b7d2ce 859 incstack[incstackp].fp = yyin;
d1e348cf
A
860 incstack[incstackp].path = racoon_strdup(path);
861 STRDUP_FATAL(incstack[incstackp].path);
52b7d2ce 862 incstack[incstackp].lineno = 1;
65c25746
A
863 plog(ASL_LEVEL_DEBUG,
864 "reading configuration file %s\n", path);
52b7d2ce
A
865
866 return 0;
867}
868
869void
870yycf_init_buffer()
871{
872 int i;
873
874 for (i = 0; i < MAX_INCLUDE_DEPTH; i++)
875 memset(&incstack[i], 0, sizeof(incstack[i]));
876 incstackp = 0;
877}
878
52b7d2ce
A
879void
880yycf_clean_buffer()
881{
882 int i;
883
d1e348cf
A
884 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) {
885 if (incstack[i].path != NULL) {
886 fclose(incstack[i].fp);
887 racoon_free(incstack[i].path);
888 incstack[i].path = NULL;
889 }
890 }
52b7d2ce
A
891}
892