]> git.saurik.com Git - apple/ipsec.git/blame - ipsec-tools/racoon/cftoken.l
ipsec-93.13.tar.gz
[apple/ipsec.git] / ipsec-tools / racoon / cftoken.l
CommitLineData
d1e348cf
A
1/* $NetBSD: cftoken.l,v 1.11.4.1 2007/08/01 11:52:20 vanhu Exp $ */
2
3/* Id: cftoken.l,v 1.53 2006/08/22 18:17:17 manubsd Exp */
52b7d2ce
A
4%option noyywrap
5%{
6/*
7 * Copyright (C) 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002 and 2003 WIDE Project.
8 * All rights reserved.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 * 3. Neither the name of the project nor the names of its contributors
19 * may be used to endorse or promote products derived from this software
20 * without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 */
34
35#include "config.h"
36
37#include <sys/types.h>
38#include <sys/param.h>
39#include <sys/socket.h>
40
41#include <netinet/in.h>
42#ifdef HAVE_NETINET6_IPSEC
43# include <netinet6/ipsec.h>
44#else
45# include <netinet/ipsec.h>
46#endif
47
48#include <stdlib.h>
49#include <stdio.h>
50#include <string.h>
51#include <errno.h>
52#include <limits.h>
53#include <ctype.h>
54#include <glob.h>
55#ifdef HAVE_STDARG_H
56#include <stdarg.h>
57#else
58#include <varargs.h>
59#endif
60
61//%%% BUG FIX - 2 missing include files when not using
62// the bison files
63#include <openssl/bn.h>
64#include <openssl/rsa.h>
65
66#include "var.h"
67#include "misc.h"
68#include "vmbuf.h"
69#include "plog.h"
70#include "debug.h"
71
72#include "algorithm.h"
73#include "cfparse_proto.h"
74#include "cftoken_proto.h"
75#include "localconf.h"
76#include "oakley.h"
77#include "isakmp_var.h"
78#include "isakmp.h"
79#include "ipsec_doi.h"
d1e348cf 80#include "policy.h"
52b7d2ce 81#include "proposal.h"
d1e348cf 82#include "remoteconf.h"
52b7d2ce
A
83#include "nattraversal.h"
84#ifdef GC
85#include "gcmalloc.h"
86#endif
87
88#ifdef __APPLE__
89#include "y.tab.h"
90#else
91#include "cfparse.h"
92#endif
93
94int yyerrorcount = 0;
95
96#if defined(YIPS_DEBUG)
97# define YYDB plog(LLV_DEBUG2, LOCATION, NULL, \
98 "begin <%d>%s\n", yy_start, yytext);
99# define YYD { \
100 plog(LLV_DEBUG2, LOCATION, NULL, "<%d>%s", \
101 yy_start, loglevel >= LLV_DEBUG2 ? "\n" : ""); \
102}
103#else
104# define YYDB
105# define YYD
106#endif /* defined(YIPS_DEBUG) */
107
108#define MAX_INCLUDE_DEPTH 10
109
110static struct include_stack {
111 char *path;
112 FILE *fp;
113 YY_BUFFER_STATE prevstate;
114 int lineno;
115 glob_t matches;
116 int matchon;
117} incstack[MAX_INCLUDE_DEPTH];
118static int incstackp = 0;
119
120static int yy_first_time = 1;
121%}
122
123/* common section */
124nl \n
125ws [ \t]+
126digit [0-9]
127letter [A-Za-z]
128hexdigit [0-9A-Fa-f]
129/*octet (([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */
130special [()+\|\?\*]
131comma \,
132dot \.
133slash \/
134bcl \{
135ecl \}
136blcl \[
137elcl \]
d1e348cf 138hyphen \-
52b7d2ce
A
139percent \%
140semi \;
141comment \#.*
142ccomment "/*"
143bracketstring \<[^>]*\>
144quotedstring \"[^"]*\"
145addrstring [a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*)
146decstring {digit}+
147hexstring 0x{hexdigit}+
148
149%s S_INI S_PRIV S_PTH S_INF S_LOG S_PAD S_LST S_RTRY S_CFG
150%s S_ALGST S_ALGCL
151%s S_SAINF S_SAINFS
152%s S_RMT S_RMTS S_RMTP
153%s S_SA
154%s S_GSSENC
155
156%%
157%{
158 if (yy_first_time) {
159 BEGIN S_INI;
160 yy_first_time = 0;
161 }
162%}
163
164 /* privsep */
165<S_INI>privsep { BEGIN S_PRIV; YYDB; return(PRIVSEP); }
166<S_PRIV>{bcl} { return(BOC); }
167<S_PRIV>user { YYD; return(USER); }
168<S_PRIV>group { YYD; return(GROUP); }
169<S_PRIV>chroot { YYD; return(CHROOT); }
170<S_PRIV>{ecl} { BEGIN S_INI; return(EOC); }
171
172 /* path */
173<S_INI>path { BEGIN S_PTH; YYDB; return(PATH); }
174<S_PTH>include { YYD; yylval.num = LC_PATHTYPE_INCLUDE;
175 return(PATHTYPE); }
176<S_PTH>pre_shared_key { YYD; yylval.num = LC_PATHTYPE_PSK;
177 return(PATHTYPE); }
178<S_PTH>certificate { YYD; yylval.num = LC_PATHTYPE_CERT;
179 return(PATHTYPE); }
d1e348cf 180<S_PTH>script { YYD; yylval.num = LC_PATHTYPE_SCRIPT;
52b7d2ce
A
181 return(PATHTYPE); }
182<S_PTH>backupsa { YYD; yylval.num = LC_PATHTYPE_BACKUPSA;
183 return(PATHTYPE); }
184<S_PTH>pidfile { YYD; yylval.num = LC_PATHTYPE_PIDFILE;
185 return(PATHTYPE); }
186<S_PTH>logfile { YYD; yylval.num = LC_PATHTYPE_LOGFILE;
187 return(PATHTYPE); }
188<S_PTH>{semi} { BEGIN S_INI; YYDB; return(EOS); }
189
190 /* include */
191<S_INI>include { YYDB; return(INCLUDE); }
192
193 /* self information */
194<S_INI>identifier { BEGIN S_INF; YYDB; yywarn("it is obsoleted. use \"my_identifier\" in each remote directives."); return(IDENTIFIER); }
195<S_INF>{semi} { BEGIN S_INI; return(EOS); }
196
197 /* special */
198<S_INI>complex_bundle { YYDB; return(COMPLEX_BUNDLE); }
199
200 /* logging */
201<S_INI>log { BEGIN S_LOG; YYDB; return(LOGGING); }
d1e348cf
A
202<S_LOG>error { YYD; yylval.num = LLV_ERROR; return(LOGLEV); }
203<S_LOG>warning { YYD; yylval.num = LLV_WARNING; return(LOGLEV); }
204<S_LOG>notify { YYD; yylval.num = LLV_NOTIFY; return(LOGLEV); }
205<S_LOG>info { YYD; yylval.num = LLV_INFO; return(LOGLEV); }
206<S_LOG>debug { YYD; yylval.num = LLV_DEBUG; return(LOGLEV); }
207<S_LOG>debug2 { YYD; yylval.num = LLV_DEBUG2; return(LOGLEV); }
208<S_LOG>debug3 { YYD; yywarn("it is obsoleted. use \"debug2\""); yylval.num = LLV_DEBUG2; return(LOGLEV); }
209<S_LOG>debug4 { YYD; yywarn("it is obsoleted. use \"debug2\""); yylval.num = LLV_DEBUG2; return(LOGLEV); }
52b7d2ce
A
210<S_LOG>{semi} { BEGIN S_INI; return(EOS); }
211
212 /* padding */
213<S_INI>padding { BEGIN S_PAD; YYDB; return(PADDING); }
214<S_PAD>{bcl} { return(BOC); }
215<S_PAD>randomize { YYD; return(PAD_RANDOMIZE); }
216<S_PAD>randomize_length { YYD; return(PAD_RANDOMIZELEN); }
217<S_PAD>maximum_length { YYD; return(PAD_MAXLEN); }
218<S_PAD>strict_check { YYD; return(PAD_STRICT); }
219<S_PAD>exclusive_tail { YYD; return(PAD_EXCLTAIL); }
220<S_PAD>{ecl} { BEGIN S_INI; return(EOC); }
221
222 /* listen */
223<S_INI>listen { BEGIN S_LST; YYDB; return(LISTEN); }
224<S_LST>{bcl} { return(BOC); }
225<S_LST>isakmp { YYD; return(X_ISAKMP); }
226<S_LST>isakmp_natt { YYD; return(X_ISAKMP_NATT); }
227<S_LST>admin { YYD; return(X_ADMIN); }
228<S_LST>adminsock { YYD; return(ADMINSOCK); }
229<S_LST>disabled { YYD; return(DISABLED); }
230<S_LST>strict_address { YYD; return(STRICT_ADDRESS); }
231<S_LST>{ecl} { BEGIN S_INI; return(EOC); }
232
233 /* mode_cfg */
234<S_INI>mode_cfg { BEGIN S_CFG; YYDB; return(MODECFG); }
235<S_CFG>{bcl} { return(BOC); }
236<S_CFG>network4 { YYD; return(CFG_NET4); }
237<S_CFG>netmask4 { YYD; return(CFG_MASK4); }
238<S_CFG>dns4 { YYD; return(CFG_DNS4); }
239<S_CFG>wins4 { YYD; return(CFG_NBNS4); }
d1e348cf 240<S_CFG>default_domain { YYD; return(CFG_DEFAULT_DOMAIN); }
52b7d2ce 241<S_CFG>auth_source { YYD; return(CFG_AUTH_SOURCE); }
d1e348cf
A
242<S_CFG>auth_groups { YYD; return(CFG_AUTH_GROUPS); }
243<S_CFG>group_source { YYD; return(CFG_GROUP_SOURCE); }
52b7d2ce
A
244<S_CFG>conf_source { YYD; return(CFG_CONF_SOURCE); }
245<S_CFG>accounting { YYD; return(CFG_ACCOUNTING); }
246<S_CFG>system { YYD; return(CFG_SYSTEM); }
247<S_CFG>local { YYD; return(CFG_LOCAL); }
248<S_CFG>none { YYD; return(CFG_NONE); }
249<S_CFG>radius { YYD; return(CFG_RADIUS); }
250<S_CFG>pam { YYD; return(CFG_PAM); }
251<S_CFG>pool_size { YYD; return(CFG_POOL_SIZE); }
252<S_CFG>banner { YYD; return(CFG_MOTD); }
253<S_CFG>auth_throttle { YYD; return(CFG_AUTH_THROTTLE); }
d1e348cf
A
254<S_CFG>split_network { YYD; return(CFG_SPLIT_NETWORK); }
255<S_CFG>local_lan { YYD; return(CFG_SPLIT_LOCAL); }
256<S_CFG>include { YYD; return(CFG_SPLIT_INCLUDE); }
257<S_CFG>split_dns { YYD; return(CFG_SPLIT_DNS); }
52b7d2ce
A
258<S_CFG>pfs_group { YYD; return(CFG_PFS_GROUP); }
259<S_CFG>save_passwd { YYD; return(CFG_SAVE_PASSWD); }
d1e348cf 260<S_CFG>{comma} { YYD; return(COMMA); }
52b7d2ce
A
261<S_CFG>{ecl} { BEGIN S_INI; return(EOC); }
262
263 /* timer */
264<S_INI>timer { BEGIN S_RTRY; YYDB; return(RETRY); }
265<S_RTRY>{bcl} { return(BOC); }
266<S_RTRY>counter { YYD; return(RETRY_COUNTER); }
267<S_RTRY>interval { YYD; return(RETRY_INTERVAL); }
268<S_RTRY>persend { YYD; return(RETRY_PERSEND); }
269<S_RTRY>phase1 { YYD; return(RETRY_PHASE1); }
270<S_RTRY>phase2 { YYD; return(RETRY_PHASE2); }
271<S_RTRY>natt_keepalive { YYD; return(NATT_KA); }
272<S_RTRY>auto_exit_delay { YYD; return(AUTO_EXIT_DELAY); }
273<S_RTRY>{ecl} { BEGIN S_INI; return(EOC); }
274
275 /* sainfo */
276<S_INI>sainfo { BEGIN S_SAINF; YYDB; return(SAINFO); }
277<S_SAINF>anonymous { YYD; return(ANONYMOUS); }
278<S_SAINF>{blcl}any{elcl} { YYD; return(PORTANY); }
279<S_SAINF>any { YYD; return(ANY); }
280<S_SAINF>from { YYD; return(FROM); }
d1e348cf 281<S_SAINF>group { YYD; return(GROUP); }
52b7d2ce
A
282 /* sainfo spec */
283<S_SAINF>{bcl} { BEGIN S_SAINFS; return(BOC); }
284<S_SAINF>{semi} { BEGIN S_INI; return(EOS); }
285<S_SAINFS>{ecl} { BEGIN S_INI; return(EOC); }
286<S_SAINFS>pfs_group { YYD; return(PFS_GROUP); }
d1e348cf 287<S_SAINFS>remoteid { YYD; return(REMOTEID); }
52b7d2ce
A
288<S_SAINFS>identifier { YYD; yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
289<S_SAINFS>my_identifier { YYD; return(MY_IDENTIFIER); }
290<S_SAINFS>lifetime { YYD; return(LIFETIME); }
291<S_SAINFS>time { YYD; return(LIFETYPE_TIME); }
292<S_SAINFS>byte { YYD; return(LIFETYPE_BYTE); }
293<S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); }
294<S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); }
295<S_SAINFS>compression_algorithm { YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); }
296<S_SAINFS>{comma} { YYD; return(COMMA); }
297
298 /* remote */
299<S_INI>remote { BEGIN S_RMT; YYDB; return(REMOTE); }
300<S_RMT>anonymous { YYD; return(ANONYMOUS); }
301<S_RMT>inherit { YYD; return(INHERIT); }
302 /* remote spec */
303<S_RMT>{bcl} { BEGIN S_RMTS; return(BOC); }
304<S_RMTS>{ecl} { BEGIN S_INI; return(EOC); }
305<S_RMTS>exchange_mode { YYD; return(EXCHANGE_MODE); }
306<S_RMTS>{comma} { YYD; /* XXX ignored, but to be handled. */ ; }
307<S_RMTS>base { YYD; yylval.num = ISAKMP_ETYPE_BASE; return(EXCHANGETYPE); }
308<S_RMTS>main { YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); }
309<S_RMTS>aggressive { YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); }
310<S_RMTS>doi { YYD; return(DOI); }
311<S_RMTS>ipsec_doi { YYD; yylval.num = IPSEC_DOI; return(DOITYPE); }
312<S_RMTS>situation { YYD; return(SITUATION); }
313<S_RMTS>identity_only { YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); }
314<S_RMTS>secrecy { YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); }
315<S_RMTS>integrity { YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); }
316<S_RMTS>identifier { YYD; yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
317<S_RMTS>my_identifier { YYD; return(MY_IDENTIFIER); }
318<S_RMTS>xauth_login { YYD; return(XAUTH_LOGIN); /* formerly identifier type login */ }
319<S_RMTS>peers_identifier { YYD; return(PEERS_IDENTIFIER); }
320<S_RMTS>verify_identifier { YYD; return(VERIFY_IDENTIFIER); }
321<S_RMTS>certificate_type { YYD; return(CERTIFICATE_TYPE); }
322<S_RMTS>ca_type { YYD; return(CA_TYPE); }
323<S_RMTS>x509 { YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); }
324<S_RMTS>plain_rsa { YYD; yylval.num = ISAKMP_CERT_PLAINRSA; return(CERT_PLAINRSA); }
325<S_RMTS>open_dir_auth_group {
d1e348cf 326#if defined(__APPLE__) && HAVE_OPENDIR
52b7d2ce
A
327 YYD;
328 return(OPEN_DIR_AUTH_GROUP);
329#else
330 yyerror("Apple specific features not compiled in.");
331#endif
332}
333<S_RMTS>shared_secret {
334#ifdef __APPLE__
335 YYD;
336 return(SHARED_SECRET);
337#else
338 yyerror("Apple specific features not compiled in.");
339#endif
340}
341<S_RMTS>in_keychain {
342#ifdef __APPLE__
343 YYD;
344 return(IN_KEYCHAIN);
345#else
346 yyerror("Apple specific features not compiled in.");
347#endif
348}
349<S_RMTS>certificate_verification {
350#ifdef __APPLE__
351 YYD;
352 return(CERTIFICATE_VERIFICATION);
353#else
354 yyerror("Apple specific features not compiled in.");
355#endif
356}
357<S_RMTS>peers_certfile { YYD; return(PEERS_CERTFILE); }
358<S_RMTS>dnssec { YYD; return(DNSSEC); }
359<S_RMTS>verify_cert { YYD; return(VERIFY_CERT); }
360<S_RMTS>send_cert { YYD; return(SEND_CERT); }
361<S_RMTS>send_cr { YYD; return(SEND_CR); }
362<S_RMTS>dh_group { YYD; return(DH_GROUP); }
363<S_RMTS>nonce_size { YYD; return(NONCE_SIZE); }
364<S_RMTS>generate_policy { YYD; return(GENERATE_POLICY); }
365<S_RMTS>support_mip6 { YYD; yywarn("it is obsoleted. use \"support_proxy\"."); return(SUPPORT_PROXY); }
366<S_RMTS>support_proxy { YYD; return(SUPPORT_PROXY); }
367<S_RMTS>initial_contact { YYD; return(INITIAL_CONTACT); }
368<S_RMTS>nat_traversal { YYD; return(NAT_TRAVERSAL); }
369<S_RMTS>force { YYD; yylval.num = NATT_FORCE; return(NAT_TRAVERSAL_LEVEL); }
370<S_RMTS>nat_traversal_multi_user {
371#ifdef __APPLE__
372 YYD;
373 return(NAT_TRAVERSAL_MULTI_USER);
374#else
375 yyerror("Apple specific features not compiled in.");
376#endif
377}
d1e348cf
A
378<S_RMTS>nat_traversal_keepalive {
379#ifdef __APPLE__
380 YYD;
381 return(NAT_TRAVERSAL_KEEPALIVE);
382#else
383 yyerror("Apple specific features not compiled in.");
384#endif
385}
52b7d2ce
A
386<S_RMTS>proposal_check { YYD; return(PROPOSAL_CHECK); }
387<S_RMTS>obey { YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); }
388<S_RMTS>strict { YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); }
389<S_RMTS>exact { YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); }
390<S_RMTS>claim { YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); }
391<S_RMTS>keepalive { YYD; return(KEEPALIVE); }
392<S_RMTS>passive { YYD; return(PASSIVE); }
393<S_RMTS>lifetime { YYD; return(LIFETIME); }
394<S_RMTS>time { YYD; return(LIFETYPE_TIME); }
395<S_RMTS>byte { YYD; return(LIFETYPE_BYTE); }
396<S_RMTS>dpd { YYD; return(DPD); }
397<S_RMTS>dpd_delay { YYD; return(DPD_DELAY); }
398<S_RMTS>dpd_retry { YYD; return(DPD_RETRY); }
399<S_RMTS>dpd_maxfail { YYD; return(DPD_MAXFAIL); }
d1e348cf
A
400<S_RMTS>dpd_algorithm { YYD; return(DPD_ALGORITHM); }
401<S_RMTS>disconnect_on_idle { YYD; return(DISCONNECT_ON_IDLE); }
402<S_RMTS>idle_timeout { YYD; return(IDLE_TIMEOUT); }
403<S_RMTS>idle_direction { YYD; return(IDLE_DIRECTION); }
52b7d2ce
A
404<S_RMTS>ike_frag { YYD; return(IKE_FRAG); }
405<S_RMTS>esp_frag { YYD; return(ESP_FRAG); }
406<S_RMTS>script { YYD; return(SCRIPT); }
407<S_RMTS>phase1_up { YYD; return(PHASE1_UP); }
408<S_RMTS>phase1_down { YYD; return(PHASE1_DOWN); }
409<S_RMTS>mode_cfg { YYD; return(MODE_CFG); }
d1e348cf 410<S_RMTS>weak_phase1_check { YYD; return(WEAK_PHASE1_CHECK); }
52b7d2ce
A
411 /* remote proposal */
412<S_RMTS>proposal { BEGIN S_RMTP; YYDB; return(PROPOSAL); }
413<S_RMTP>{bcl} { return(BOC); }
414<S_RMTP>{ecl} { BEGIN S_RMTS; return(EOC); }
415<S_RMTP>lifetime { YYD; return(LIFETIME); }
416<S_RMTP>time { YYD; return(LIFETYPE_TIME); }
417<S_RMTP>byte { YYD; return(LIFETYPE_BYTE); }
418<S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); }
419<S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); }
420<S_RMTP>hash_algorithm { YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); }
421<S_RMTP>dh_group { YYD; return(DH_GROUP); }
422<S_RMTP>gss_id { YYD; return(GSS_ID); }
423<S_RMTP>gssapi_id { YYD; return(GSS_ID); } /* for back compatibility */
424
425 /* GSS ID encoding type (global) */
426<S_INI>gss_id_enc { BEGIN S_GSSENC; YYDB; return(GSS_ID_ENC); }
427<S_GSSENC>latin1 { YYD; yylval.num = LC_GSSENC_LATIN1;
428 return(GSS_ID_ENCTYPE); }
429<S_GSSENC>utf-16le { YYD; yylval.num = LC_GSSENC_UTF16LE;
430 return(GSS_ID_ENCTYPE); }
431<S_GSSENC>{semi} { BEGIN S_INI; YYDB; return(EOS); }
432
433 /* parameter */
434on { YYD; yylval.num = TRUE; return(SWITCH); }
435off { YYD; yylval.num = FALSE; return(SWITCH); }
436
437 /* prefix */
438{slash}({digit}{1,3}) {
439 YYD;
440 yytext++;
441 yylval.num = atoi(yytext);
442 return(PREFIX);
443 }
444
445 /* port number */
446{blcl}{decstring}{elcl} {
447 char *p = yytext;
448 YYD;
449 while (*++p != ']') ;
450 *p = 0;
451 yytext++;
452 yylval.num = atoi(yytext);
453 return(PORT);
454 }
455
d1e348cf
A
456 /* address range */
457{hyphen}{addrstring} {
458 YYD;
459 yytext++;
460 yylval.val = vmalloc(yyleng + 1);
461 if (yylval.val == NULL) {
462 yyerror("vmalloc failed");
463 return -1;
464 }
465 memcpy(yylval.val->v, yytext, yylval.val->l);
466 return(ADDRRANGE);
467 }
468
52b7d2ce
A
469 /* upper protocol */
470esp { YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); }
471ah { YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); }
472ipcomp { YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); }
473icmp { YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); }
474icmp6 { YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); }
475tcp { YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); }
476udp { YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); }
477
478 /* algorithm type */
479des_iv64 { YYD; yylval.num = algtype_des_iv64; return(ALGORITHMTYPE); }
480des { YYD; yylval.num = algtype_des; return(ALGORITHMTYPE); }
4813des { YYD; yylval.num = algtype_3des; return(ALGORITHMTYPE); }
482rc5 { YYD; yylval.num = algtype_rc5; return(ALGORITHMTYPE); }
483idea { YYD; yylval.num = algtype_idea; return(ALGORITHMTYPE); }
484cast128 { YYD; yylval.num = algtype_cast128; return(ALGORITHMTYPE); }
485blowfish { YYD; yylval.num = algtype_blowfish; return(ALGORITHMTYPE); }
4863idea { YYD; yylval.num = algtype_3idea; return(ALGORITHMTYPE); }
487des_iv32 { YYD; yylval.num = algtype_des_iv32; return(ALGORITHMTYPE); }
488rc4 { YYD; yylval.num = algtype_rc4; return(ALGORITHMTYPE); }
489null_enc { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); }
490null { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); }
491aes { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); }
492rijndael { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); }
493twofish { YYD; yylval.num = algtype_twofish; return(ALGORITHMTYPE); }
494non_auth { YYD; yylval.num = algtype_non_auth; return(ALGORITHMTYPE); }
495hmac_md5 { YYD; yylval.num = algtype_hmac_md5; return(ALGORITHMTYPE); }
496hmac_sha1 { YYD; yylval.num = algtype_hmac_sha1; return(ALGORITHMTYPE); }
497hmac_sha2_256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); }
498hmac_sha256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); }
499hmac_sha2_384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); }
500hmac_sha384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); }
501hmac_sha2_512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); }
502hmac_sha512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); }
503des_mac { YYD; yylval.num = algtype_des_mac; return(ALGORITHMTYPE); }
504kpdk { YYD; yylval.num = algtype_kpdk; return(ALGORITHMTYPE); }
505md5 { YYD; yylval.num = algtype_md5; return(ALGORITHMTYPE); }
506sha1 { YYD; yylval.num = algtype_sha1; return(ALGORITHMTYPE); }
507tiger { YYD; yylval.num = algtype_tiger; return(ALGORITHMTYPE); }
508sha2_256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); }
509sha256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); }
510sha2_384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); }
511sha384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); }
512sha2_512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); }
513sha512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); }
514oui { YYD; yylval.num = algtype_oui; return(ALGORITHMTYPE); }
515deflate { YYD; yylval.num = algtype_deflate; return(ALGORITHMTYPE); }
516lzs { YYD; yylval.num = algtype_lzs; return(ALGORITHMTYPE); }
517modp768 { YYD; yylval.num = algtype_modp768; return(ALGORITHMTYPE); }
518modp1024 { YYD; yylval.num = algtype_modp1024; return(ALGORITHMTYPE); }
519modp1536 { YYD; yylval.num = algtype_modp1536; return(ALGORITHMTYPE); }
520ec2n155 { YYD; yylval.num = algtype_ec2n155; return(ALGORITHMTYPE); }
521ec2n185 { YYD; yylval.num = algtype_ec2n185; return(ALGORITHMTYPE); }
522modp2048 { YYD; yylval.num = algtype_modp2048; return(ALGORITHMTYPE); }
523modp3072 { YYD; yylval.num = algtype_modp3072; return(ALGORITHMTYPE); }
524modp4096 { YYD; yylval.num = algtype_modp4096; return(ALGORITHMTYPE); }
525modp6144 { YYD; yylval.num = algtype_modp6144; return(ALGORITHMTYPE); }
526modp8192 { YYD; yylval.num = algtype_modp8192; return(ALGORITHMTYPE); }
527pre_shared_key { YYD; yylval.num = algtype_psk; return(ALGORITHMTYPE); }
528rsasig { YYD; yylval.num = algtype_rsasig; return(ALGORITHMTYPE); }
529dsssig { YYD; yylval.num = algtype_dsssig; return(ALGORITHMTYPE); }
530rsaenc { YYD; yylval.num = algtype_rsaenc; return(ALGORITHMTYPE); }
531rsarev { YYD; yylval.num = algtype_rsarev; return(ALGORITHMTYPE); }
532gssapi_krb { YYD; yylval.num = algtype_gssapikrb; return(ALGORITHMTYPE); }
533hybrid_rsa_server {
534#ifdef ENABLE_HYBRID
535 YYD; yylval.num = algtype_hybrid_rsa_s; return(ALGORITHMTYPE);
536#else
537 yyerror("racoon not configured with --enable-hybrid");
538#endif
539}
540hybrid_dss_server {
541#ifdef ENABLE_HYBRID
542 YYD; yylval.num = algtype_hybrid_dss_s; return(ALGORITHMTYPE);
543#else
544 yyerror("racoon not configured with --enable-hybrid");
545#endif
546}
547hybrid_rsa_client {
548#ifdef ENABLE_HYBRID
549 YYD; yylval.num = algtype_hybrid_rsa_c; return(ALGORITHMTYPE);
550#else
551 yyerror("racoon not configured with --enable-hybrid");
552#endif
553}
554hybrid_dss_client {
555#ifdef ENABLE_HYBRID
556 YYD; yylval.num = algtype_hybrid_dss_c; return(ALGORITHMTYPE);
557#else
558 yyerror("racoon not configured with --enable-hybrid");
559#endif
560}
561
d1e348cf
A
562xauth_psk_server {
563#ifdef ENABLE_HYBRID
564 YYD; yylval.num = algtype_xauth_psk_s; return(ALGORITHMTYPE);
565#else
566 yyerror("racoon not configured with --enable-hybrid");
567#endif
568}
569xauth_psk_client {
570#ifdef ENABLE_HYBRID
571 YYD; yylval.num = algtype_xauth_psk_c; return(ALGORITHMTYPE);
572#else
573 yyerror("racoon not configured with --enable-hybrid");
574#endif
575}
576xauth_rsa_server {
577#ifdef ENABLE_HYBRID
578 YYD; yylval.num = algtype_xauth_rsa_s; return(ALGORITHMTYPE);
579#else
580 yyerror("racoon not configured with --enable-hybrid");
581#endif
582}
583xauth_rsa_client {
584#ifdef ENABLE_HYBRID
585 YYD; yylval.num = algtype_xauth_rsa_c; return(ALGORITHMTYPE);
586#else
587 yyerror("racoon not configured with --enable-hybrid");
588#endif
589}
590
591
52b7d2ce
A
592
593 /* identifier type */
594vendor_id { YYD; yywarn("it is obsoleted."); return(VENDORID); }
595user_fqdn { YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); }
596fqdn { YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); }
597keyid { YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); }
598keyid_use {
599#ifdef __APPLE__
600 YYD;
601 yylval.num = IDTYPE_KEYIDUSE;
602 return(IDENTIFIERTYPE);
603#else
604 yyerror("Apple specific features not compiled in.");
605#endif
606}
607address { YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); }
608subnet { YYD; yylval.num = IDTYPE_SUBNET; return(IDENTIFIERTYPE); }
609asn1dn { YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
610certname { YYD; yywarn("certname will be obsoleted in near future."); yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
611
612 /* shared secret type */
613use {
614#ifdef __APPLE__
615 YYD;
616 yylval.num = SECRETTYPE_USE;
617 return(SECRETTYPE);
618#else
619 yyerror("Apple specific features not compiled in.");
620#endif
621}
622key {
623#ifdef __APPLE__
624 YYD;
625 yylval.num = SECRETTYPE_KEY;
626 return(SECRETTYPE);
627#else
628 yyerror("Apple specific features not compiled in.");
629#endif
630}
631keychain {
d1e348cf 632#if defined(__APPLE__) && HAVE_KEYCHAIN
52b7d2ce
A
633 YYD;
634 yylval.num = SECRETTYPE_KEYCHAIN;
635 return(SECRETTYPE);
636#else
637 yyerror("Apple specific features not compiled in.");
638#endif
639}
640keychain_by_id {
641#ifdef __APPLE__
642 YYD;
643 yylval.num = SECRETTYPE_KEYCHAIN_BY_ID;
644 return(SECRETTYPE);
645#else
646 yyerror("Apple specific features not compiled in.");
647#endif
648}
649
650 /* certificate verification */
651openssl {
652#ifdef __APPLE__
653 YYD;
654 yylval.num = VERIFICATION_MODULE_OPENSSL;
655 return(VERIFICATION_MODULE);
656#else
657 yyerror("Apple specific features not compiled in.");
658#endif
659}
660sec_framework {
661#ifdef __APPLE__
662 YYD;
663 yylval.num = VERIFICATION_MODULE_SEC_FRAMEWORK;
664 return(VERIFICATION_MODULE);
665#else
666 yyerror("Apple specific features not compiled in.");
667#endif
668}
669use_open_dir {
670#ifdef __APPLE__
671 YYD;
672 yylval.num = VERIFICATION_OPTION_OPEN_DIR;
673 return(VERIFICATION_OPTION);
674#else
675 yyerror("Apple specific features not compiled in.");
676#endif
677}
678use_peers_identifier {
679#ifdef __APPLE__
680 YYD;
681 yylval.num = VERIFICATION_OPTION_PEERS_IDENTIFIER;
682 return(VERIFICATION_OPTION);
683#else
684 yyerror("Apple specific features not compiled in.");
685#endif
686}
687
d1e348cf
A
688 /* identifier qualifier */
689tag { YYD; yylval.num = IDQUAL_TAG; return(IDENTIFIERQUAL); }
690file { YYD; yylval.num = IDQUAL_FILE; return(IDENTIFIERQUAL); }
691
52b7d2ce
A
692 /* units */
693B|byte|bytes { YYD; return(UNITTYPE_BYTE); }
694KB { YYD; return(UNITTYPE_KBYTES); }
695MB { YYD; return(UNITTYPE_MBYTES); }
696TB { YYD; return(UNITTYPE_TBYTES); }
697sec|secs|second|seconds { YYD; return(UNITTYPE_SEC); }
698min|mins|minute|minutes { YYD; return(UNITTYPE_MIN); }
699hour|hours { YYD; return(UNITTYPE_HOUR); }
700
d1e348cf
A
701dpd_default { YYD; return(DPD_ALGO_TYPE_DEFAULT); }
702dpd_inbound_detect { YYD; return(DPD_ALGO_TYPE_INBOUND); }
703dpd_blackhole_detect { YYD; return(DPD_ALGO_TYPE_BLACKHOLE); }
704
705idle_any { YYD; return(IDLE_DIRECTION_ANY); }
706idle_inbound { YYD; return(IDLE_DIRECTION_IN); }
707idle_outbound { YYD; return(IDLE_DIRECTION_OUT); }
708
52b7d2ce
A
709 /* boolean */
710yes { YYD; yylval.num = TRUE; return(BOOLEAN); }
711no { YYD; yylval.num = FALSE; return(BOOLEAN); }
712
713{decstring} {
714 char *bp;
715
716 YYD;
717 yylval.num = strtol(yytext, &bp, 10);
718 return(NUMBER);
719 }
720
721{hexstring} {
722 char *p;
723
724 YYD;
725 yylval.val = vmalloc(yyleng + (yyleng & 1) + 1);
726 if (yylval.val == NULL) {
727 yyerror("vmalloc failed");
728 return -1;
729 }
730
731 p = yylval.val->v;
732 *p++ = '0';
733 *p++ = 'x';
734
735 /* fixed string if length is odd. */
736 if (yyleng & 1)
737 *p++ = '0';
738 memcpy(p, &yytext[2], yyleng - 1);
739
740 return(HEXSTRING);
741 }
742
743{quotedstring} {
744 char *p = yytext;
745
746 YYD;
747 while (*++p != '"') ;
748 *p = '\0';
749
750 yylval.val = vmalloc(yyleng - 1);
751 if (yylval.val == NULL) {
752 yyerror("vmalloc failed");
753 return -1;
754 }
755 memcpy(yylval.val->v, &yytext[1], yylval.val->l);
756
757 return(QUOTEDSTRING);
758 }
759
760{addrstring} {
761 YYD;
762
763 yylval.val = vmalloc(yyleng + 1);
764 if (yylval.val == NULL) {
765 yyerror("vmalloc failed");
766 return -1;
767 }
768 memcpy(yylval.val->v, yytext, yylval.val->l);
769
770 return(ADDRSTRING);
771 }
772
773<<EOF>> {
774 yy_delete_buffer(YY_CURRENT_BUFFER);
52b7d2ce
A
775 incstackp--;
776 nextfile:
777 if (incstack[incstackp].matchon <
778 incstack[incstackp].matches.gl_pathc) {
779 char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
780 incstack[incstackp].matchon++;
781 incstackp++;
782 if (yycf_set_buffer(filepath) != 0) {
783 incstackp--;
784 goto nextfile;
785 }
786 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
787 BEGIN(S_INI);
788 } else {
789 globfree(&incstack[incstackp].matches);
790 if (incstackp == 0)
791 yyterminate();
792 else
793 yy_switch_to_buffer(incstack[incstackp].prevstate);
794 }
795 }
796
797 /* ... */
798{ws} { ; }
799{nl} { incstack[incstackp].lineno++; }
800{comment} { YYD; }
801{semi} { return(EOS); }
802. { yymore(); }
803
804%%
805
806void
807yyerror(char *s, ...)
808{
809 char fmt[512];
810
811 va_list ap;
812#ifdef HAVE_STDARG_H
813 va_start(ap, s);
814#else
815 va_start(ap);
816#endif
817 snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n",
818 incstack[incstackp].path, incstack[incstackp].lineno,
819 yytext, s);
d1e348cf 820 plogv(LLV_ERROR, LOCATION, NULL, fmt, &ap);
52b7d2ce
A
821 va_end(ap);
822
823 yyerrorcount++;
824}
825
826void
827yywarn(char *s, ...)
828{
829 char fmt[512];
830
831 va_list ap;
832#ifdef HAVE_STDARG_H
833 va_start(ap, s);
834#else
835 va_start(ap);
836#endif
837 snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n",
838 incstack[incstackp].path, incstack[incstackp].lineno,
839 yytext, s);
d1e348cf 840 plogv(LLV_WARNING, LOCATION, NULL, fmt, &ap);
52b7d2ce
A
841 va_end(ap);
842}
843
844int
845yycf_switch_buffer(path)
846 char *path;
847{
848 char *filepath = NULL;
849
850 /* got the include file name */
851 if (incstackp >= MAX_INCLUDE_DEPTH) {
852 plog(LLV_ERROR, LOCATION, NULL,
853 "Includes nested too deeply");
854 return -1;
855 }
856
857 if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 ||
858 incstack[incstackp].matches.gl_pathc == 0) {
d1e348cf
A
859 plog(LLV_WARNING, LOCATION, NULL,
860 "glob found no matches for path \"%s\"\n", path);
861 return 0;
52b7d2ce
A
862 }
863 incstack[incstackp].matchon = 0;
864 incstack[incstackp].prevstate = YY_CURRENT_BUFFER;
865
866 nextmatch:
867 if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc)
868 return -1;
869 filepath =
870 incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
871 incstack[incstackp].matchon++;
872 incstackp++;
873
874 if (yycf_set_buffer(filepath) != 0) {
875 incstackp--;
876 goto nextmatch;
877 }
878
879 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
880
881 BEGIN(S_INI);
882
883 return 0;
884}
885
886int
887yycf_set_buffer(path)
888 char *path;
889{
890 yyin = fopen(path, "r");
891 if (yyin == NULL) {
892 fprintf(stderr, "failed to open file %s (%s)\n",
893 path, strerror(errno));
894 plog(LLV_ERROR, LOCATION, NULL,
895 "failed to open file %s (%s)\n",
896 path, strerror(errno));
897 return -1;
898 }
899
900 /* initialize */
d1e348cf
A
901 if (incstack[incstackp].path != NULL) {
902 fclose(incstack[incstackp].fp);
903 racoon_free(incstack[incstackp].path);
904 }
52b7d2ce 905 incstack[incstackp].fp = yyin;
d1e348cf
A
906 incstack[incstackp].path = racoon_strdup(path);
907 STRDUP_FATAL(incstack[incstackp].path);
52b7d2ce
A
908 incstack[incstackp].lineno = 1;
909 plog(LLV_DEBUG, LOCATION, NULL,
910 "reading config file %s\n", path);
911
912 return 0;
913}
914
915void
916yycf_init_buffer()
917{
918 int i;
919
920 for (i = 0; i < MAX_INCLUDE_DEPTH; i++)
921 memset(&incstack[i], 0, sizeof(incstack[i]));
922 incstackp = 0;
923}
924
52b7d2ce
A
925void
926yycf_clean_buffer()
927{
928 int i;
929
d1e348cf
A
930 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) {
931 if (incstack[i].path != NULL) {
932 fclose(incstack[i].fp);
933 racoon_free(incstack[i].path);
934 incstack[i].path = NULL;
935 }
936 }
52b7d2ce
A
937}
938