]> git.saurik.com Git - apple/ipsec.git/blob - ipsec-tools/racoon/cftoken.l
5428f9717807da69c4b81405e6fa7a7455d6962e
[apple/ipsec.git] / ipsec-tools / racoon / cftoken.l
1 /* $NetBSD: cftoken.l,v 1.11.4.1 2007/08/01 11:52:20 vanhu Exp $ */
2
3 /* Id: cftoken.l,v 1.53 2006/08/22 18:17:17 manubsd Exp */
4 %option noyywrap
5 %{
6 /*
7 * Copyright (C) 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002 and 2003 WIDE Project.
8 * All rights reserved.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 * 3. Neither the name of the project nor the names of its contributors
19 * may be used to endorse or promote products derived from this software
20 * without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 */
34
35 #include "config.h"
36
37 #include <sys/types.h>
38 #include <sys/param.h>
39 #include <sys/socket.h>
40
41 #include <netinet/in.h>
42 #ifdef HAVE_NETINET6_IPSEC
43 # include <netinet6/ipsec.h>
44 #else
45 # include <netinet/ipsec.h>
46 #endif
47
48 #include <stdlib.h>
49 #include <stdio.h>
50 #include <string.h>
51 #include <errno.h>
52 #include <limits.h>
53 #include <ctype.h>
54 #include <glob.h>
55 #ifdef HAVE_STDARG_H
56 #include <stdarg.h>
57 #else
58 #include <varargs.h>
59 #endif
60
61 //%%% BUG FIX - 2 missing include files when not using
62 // the bison files
63 #ifdef HAVE_OPENSSL
64 #include <openssl/bn.h>
65 #include <openssl/rsa.h>
66 #endif
67
68 #include "var.h"
69 #include "misc.h"
70 #include "vmbuf.h"
71 #include "plog.h"
72 #include "debug.h"
73
74 #include "algorithm.h"
75 #include "cfparse_proto.h"
76 #include "cftoken_proto.h"
77 #include "localconf.h"
78 #include "oakley.h"
79 #include "isakmp_var.h"
80 #include "isakmp.h"
81 #include "ipsec_doi.h"
82 #include "policy.h"
83 #include "proposal.h"
84 #include "remoteconf.h"
85 #include "nattraversal.h"
86 #ifdef GC
87 #include "gcmalloc.h"
88 #endif
89
90 #include "y.tab.h"
91 #include "eap_sim.h"
92
93 int yyerrorcount = 0;
94
95 #if defined(YIPS_DEBUG)
96 # define YYDB plog(ASL_LEVEL_DEBUG, \
97 "begin <%d>%s\n", yy_start, yytext);
98 # define YYD { \
99 plog(ASL_LEVEL_DEBUG, "<%d>%s", \
100 yy_start, loglevel >= ASL_LEVEL_DEBUG ? "\n" : ""); \
101 }
102 #else
103 # define YYDB
104 # define YYD
105 #endif /* defined(YIPS_DEBUG) */
106
107 #define MAX_INCLUDE_DEPTH 10
108
109 static struct include_stack {
110 char *path;
111 FILE *fp;
112 YY_BUFFER_STATE prevstate;
113 int lineno;
114 glob_t matches;
115 int matchon;
116 } incstack[MAX_INCLUDE_DEPTH];
117 static int incstackp = 0;
118
119 static int yy_first_time = 1;
120 %}
121
122 /* common section */
123 nl \n
124 ws [ \t]+
125 digit [0-9]
126 letter [A-Za-z]
127 hexdigit [0-9A-Fa-f]
128 /*octet (([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */
129 special [()+\|\?\*]
130 comma \,
131 dot \.
132 slash \/
133 bcl \{
134 ecl \}
135 blcl \[
136 elcl \]
137 hyphen \-
138 percent \%
139 semi \;
140 comment \#.*
141 ccomment "/*"
142 bracketstring \<[^>]*\>
143 quotedstring \"[^"]*\"
144 addrstring [a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*)
145 decstring {digit}+
146 hexstring 0x{hexdigit}+
147
148 %s S_INI S_PRIV S_PTH S_INF S_LOG S_PAD S_LST S_RTRY S_CFG
149 %s S_ALGST S_ALGCL
150 %s S_SAINF S_SAINFS
151 %s S_RMT S_RMTS S_RMTP
152 %s S_SA
153 %s S_GSSENC
154
155 %%
156 %{
157 if (yy_first_time) {
158 BEGIN S_INI;
159 yy_first_time = 0;
160 }
161 %}
162
163
164 /* path */
165 <S_INI>path { BEGIN S_PTH; YYDB; return(PATH); }
166 <S_PTH>include { YYD; yylval.num = LC_PATHTYPE_INCLUDE;
167 return(PATHTYPE); }
168 <S_PTH>pre_shared_key { YYD; yylval.num = LC_PATHTYPE_PSK;
169 return(PATHTYPE); }
170 <S_PTH>certificate { YYD; yylval.num = LC_PATHTYPE_CERT;
171 return(PATHTYPE); }
172 <S_PTH>pidfile { YYD; yylval.num = LC_PATHTYPE_PIDFILE;
173 return(PATHTYPE); }
174 <S_PTH>logfile { YYD; yylval.num = LC_PATHTYPE_LOGFILE;
175 return(PATHTYPE); }
176 <S_PTH>{semi} { BEGIN S_INI; YYDB; return(EOS); }
177
178 /* include */
179 <S_INI>include { YYDB; return(INCLUDE); }
180
181 /* self information */
182 <S_INI>identifier { BEGIN S_INF; YYDB; racoon_yywarn("it is obsoleted. use \"my_identifier\" in each remote directives."); return(IDENTIFIER); }
183 <S_INF>{semi} { BEGIN S_INI; return(EOS); }
184
185 /* special */
186 <S_INI>complex_bundle { YYDB; return(COMPLEX_BUNDLE); }
187
188 /* logging */
189 <S_INI>log { BEGIN S_LOG; YYDB; return(LOGGING); }
190 <S_LOG>error { YYD; yylval.num = ASL_LEVEL_ERR; return(LOGLEV); }
191 <S_LOG>warning { YYD; yylval.num = ASL_LEVEL_WARNING; return(LOGLEV); }
192 <S_LOG>notify { YYD; yylval.num = ASL_LEVEL_NOTICE; return(LOGLEV); }
193 <S_LOG>info { YYD; yylval.num = ASL_LEVEL_INFO; return(LOGLEV); }
194 <S_LOG>debug { YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
195 <S_LOG>debug2 { YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
196 <S_LOG>debug3 { YYD; racoon_yywarn("it is obsoleted. use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
197 <S_LOG>debug4 { YYD; racoon_yywarn("it is obsoleted. use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
198 <S_LOG>{semi} { BEGIN S_INI; return(EOS); }
199
200 /* padding */
201 <S_INI>padding { BEGIN S_PAD; YYDB; return(PADDING); }
202 <S_PAD>{bcl} { return(BOC); }
203 <S_PAD>randomize { YYD; return(PAD_RANDOMIZE); }
204 <S_PAD>randomize_length { YYD; return(PAD_RANDOMIZELEN); }
205 <S_PAD>maximum_length { YYD; return(PAD_MAXLEN); }
206 <S_PAD>strict_check { YYD; return(PAD_STRICT); }
207 <S_PAD>exclusive_tail { YYD; return(PAD_EXCLTAIL); }
208 <S_PAD>{ecl} { BEGIN S_INI; return(EOC); }
209
210 /* listen */
211 <S_INI>listen { BEGIN S_LST; YYDB; return(LISTEN); }
212 <S_LST>{bcl} { return(BOC); }
213 <S_LST>isakmp { YYD; return(X_ISAKMP); }
214 <S_LST>isakmp_natt { YYD; return(X_ISAKMP_NATT); }
215 <S_LST>admin { YYD; return(X_ADMIN); }
216 <S_LST>adminsock { YYD; return(ADMINSOCK); }
217 <S_LST>disabled { YYD; return(DISABLED); }
218 <S_LST>strict_address { YYD; return(STRICT_ADDRESS); }
219 <S_LST>{ecl} { BEGIN S_INI; return(EOC); }
220
221 /* mode_cfg */
222 <S_INI>mode_cfg { BEGIN S_CFG; YYDB; return(MODECFG); }
223 <S_CFG>{bcl} { return(BOC); }
224 <S_CFG>network4 { YYD; return(CFG_NET4); }
225 <S_CFG>netmask4 { YYD; return(CFG_MASK4); }
226 <S_CFG>dns4 { YYD; return(CFG_DNS4); }
227 <S_CFG>wins4 { YYD; return(CFG_NBNS4); }
228 <S_CFG>default_domain { YYD; return(CFG_DEFAULT_DOMAIN); }
229 <S_CFG>auth_source { YYD; return(CFG_AUTH_SOURCE); }
230 <S_CFG>auth_groups { YYD; return(CFG_AUTH_GROUPS); }
231 <S_CFG>group_source { YYD; return(CFG_GROUP_SOURCE); }
232 <S_CFG>conf_source { YYD; return(CFG_CONF_SOURCE); }
233 <S_CFG>accounting { YYD; return(CFG_ACCOUNTING); }
234 <S_CFG>system { YYD; return(CFG_SYSTEM); }
235 <S_CFG>local { YYD; return(CFG_LOCAL); }
236 <S_CFG>none { YYD; return(CFG_NONE); }
237 <S_CFG>radius { YYD; return(CFG_RADIUS); }
238 <S_CFG>pam { YYD; return(CFG_PAM); }
239 <S_CFG>pool_size { YYD; return(CFG_POOL_SIZE); }
240 <S_CFG>banner { YYD; return(CFG_MOTD); }
241 <S_CFG>auth_throttle { YYD; return(CFG_AUTH_THROTTLE); }
242 <S_CFG>split_network { YYD; return(CFG_SPLIT_NETWORK); }
243 <S_CFG>local_lan { YYD; return(CFG_SPLIT_LOCAL); }
244 <S_CFG>include { YYD; return(CFG_SPLIT_INCLUDE); }
245 <S_CFG>split_dns { YYD; return(CFG_SPLIT_DNS); }
246 <S_CFG>pfs_group { YYD; return(CFG_PFS_GROUP); }
247 <S_CFG>save_passwd { YYD; return(CFG_SAVE_PASSWD); }
248 <S_CFG>{comma} { YYD; return(COMMA); }
249 <S_CFG>{ecl} { BEGIN S_INI; return(EOC); }
250
251 /* timer */
252 <S_INI>timer { BEGIN S_RTRY; YYDB; return(RETRY); }
253 <S_RTRY>{bcl} { return(BOC); }
254 <S_RTRY>counter { YYD; return(RETRY_COUNTER); }
255 <S_RTRY>interval { YYD; return(RETRY_INTERVAL); }
256 <S_RTRY>persend { YYD; return(RETRY_PERSEND); }
257 <S_RTRY>phase1 { YYD; return(RETRY_PHASE1); }
258 <S_RTRY>phase2 { YYD; return(RETRY_PHASE2); }
259 <S_RTRY>natt_keepalive { YYD; return(NATT_KA); }
260 <S_RTRY>auto_exit_delay { YYD; return(AUTO_EXIT_DELAY); }
261 <S_RTRY>{ecl} { BEGIN S_INI; return(EOC); }
262
263 /* sainfo */
264 <S_INI>sainfo { BEGIN S_SAINF; YYDB; return(SAINFO); }
265 <S_SAINF>anonymous { YYD; return(ANONYMOUS); }
266 <S_SAINF>{blcl}any{elcl} { YYD; return(PORTANY); }
267 <S_SAINF>any { YYD; return(ANY); }
268 <S_SAINF>from { YYD; return(FROM); }
269 <S_SAINF>group { YYD; return(GROUP); }
270 /* sainfo spec */
271 <S_SAINF>{bcl} { BEGIN S_SAINFS; return(BOC); }
272 <S_SAINF>{semi} { BEGIN S_INI; return(EOS); }
273 <S_SAINFS>{ecl} { BEGIN S_INI; return(EOC); }
274 <S_SAINFS>pfs_group { YYD; return(PFS_GROUP); }
275 <S_SAINFS>remoteid { YYD; return(REMOTEID); }
276 <S_SAINFS>identifier { YYD; racoon_yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
277 <S_SAINFS>my_identifier { YYD; return(MY_IDENTIFIER); }
278 <S_SAINFS>lifetime { YYD; return(LIFETIME); }
279 <S_SAINFS>time { YYD; return(LIFETYPE_TIME); }
280 <S_SAINFS>byte { YYD; return(LIFETYPE_BYTE); }
281 <S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); }
282 <S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); }
283 <S_SAINFS>compression_algorithm { YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); }
284 <S_SAINFS>{comma} { YYD; return(COMMA); }
285
286 /* remote */
287 <S_INI>remote { BEGIN S_RMT; YYDB; return(REMOTE); }
288 <S_RMT>anonymous { YYD; return(ANONYMOUS); }
289 <S_RMT>inherit { YYD; return(INHERIT); }
290 /* remote spec */
291 <S_RMT>{bcl} { BEGIN S_RMTS; return(BOC); }
292 <S_RMTS>{ecl} { BEGIN S_INI; return(EOC); }
293 <S_RMTS>exchange_mode { YYD; return(EXCHANGE_MODE); }
294 <S_RMTS>{comma} { YYD; /* XXX ignored, but to be handled. */ ; }
295 <S_RMTS>main { YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); }
296 <S_RMTS>aggressive { YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); }
297 <S_RMTS>doi { YYD; return(DOI); }
298 <S_RMTS>ipsec_doi { YYD; yylval.num = IPSEC_DOI; return(DOITYPE); }
299 <S_RMTS>situation { YYD; return(SITUATION); }
300 <S_RMTS>ike_version { YYD; return(IKE_VERSION); }
301 <S_RMTS>identity_only { YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); }
302 <S_RMTS>secrecy { YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); }
303 <S_RMTS>integrity { YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); }
304 <S_RMTS>identifier { YYD; racoon_yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
305 <S_RMTS>my_identifier { YYD; return(MY_IDENTIFIER); }
306 <S_RMTS>xauth_login { YYD; return(XAUTH_LOGIN); /* formerly identifier type login */ }
307 <S_RMTS>peers_identifier { YYD; return(PEERS_IDENTIFIER); }
308 <S_RMTS>verify_identifier { YYD; return(VERIFY_IDENTIFIER); }
309 <S_RMTS>certificate_type { YYD; return(CERTIFICATE_TYPE); }
310 <S_RMTS>ca_type { YYD; return(CA_TYPE); }
311 <S_RMTS>x509 { YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); }
312 <S_RMTS>plain_rsa {
313 racoon_yyerror("plainrsa not supported.");
314 }
315 <S_RMTS>open_dir_auth_group {
316 #if HAVE_OPENDIR
317 YYD;
318 return(OPEN_DIR_AUTH_GROUP);
319 #else
320 racoon_yyerror("Apple specific features not compiled in.");
321 #endif
322 }
323 <S_RMTS>shared_secret {
324 YYD;
325 return(SHARED_SECRET);
326 }
327 <S_RMTS>in_keychain {
328 YYD;
329 return(IN_KEYCHAIN);
330 }
331 <S_RMTS>certificate_verification {
332 YYD;
333 return(CERTIFICATE_VERIFICATION);
334 }
335 <S_RMTS>peers_certfile { YYD; return(PEERS_CERTFILE); }
336 <S_RMTS>dnssec { YYD; return(DNSSEC); }
337 <S_RMTS>verify_cert { YYD; return(VERIFY_CERT); }
338 <S_RMTS>send_cert { YYD; return(SEND_CERT); }
339 <S_RMTS>send_cr { YYD; return(SEND_CR); }
340 <S_RMTS>dh_group { YYD; return(DH_GROUP); }
341 <S_RMTS>nonce_size { YYD; return(NONCE_SIZE); }
342 <S_RMTS>generate_policy { YYD; return(GENERATE_POLICY); }
343 <S_RMTS>support_mip6 { YYD; racoon_yywarn("it is obsoleted. use \"support_proxy\"."); return(SUPPORT_PROXY); }
344 <S_RMTS>support_proxy { YYD; return(SUPPORT_PROXY); }
345 <S_RMTS>initial_contact { YYD; return(INITIAL_CONTACT); }
346 <S_RMTS>nat_traversal { YYD; return(NAT_TRAVERSAL); }
347 <S_RMTS>force { YYD; yylval.num = NATT_FORCE; return(NAT_TRAVERSAL_LEVEL); }
348 <S_RMTS>nat_traversal_multi_user {
349 YYD;
350 return(NAT_TRAVERSAL_MULTI_USER);
351 }
352 <S_RMTS>nat_traversal_keepalive {
353 YYD;
354 return(NAT_TRAVERSAL_KEEPALIVE);
355 }
356 <S_RMTS>proposal_check { YYD; return(PROPOSAL_CHECK); }
357 <S_RMTS>obey { YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); }
358 <S_RMTS>strict { YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); }
359 <S_RMTS>exact { YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); }
360 <S_RMTS>claim { YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); }
361 <S_RMTS>keepalive { YYD; return(KEEPALIVE); }
362 <S_RMTS>passive { YYD; return(PASSIVE); }
363 <S_RMTS>lifetime { YYD; return(LIFETIME); }
364 <S_RMTS>time { YYD; return(LIFETYPE_TIME); }
365 <S_RMTS>byte { YYD; return(LIFETYPE_BYTE); }
366 <S_RMTS>dpd { YYD; return(DPD); }
367 <S_RMTS>dpd_delay { YYD; return(DPD_DELAY); }
368 <S_RMTS>dpd_retry { YYD; return(DPD_RETRY); }
369 <S_RMTS>dpd_maxfail { YYD; return(DPD_MAXFAIL); }
370 <S_RMTS>dpd_algorithm { YYD; return(DPD_ALGORITHM); }
371 <S_RMTS>disconnect_on_idle { YYD; return(DISCONNECT_ON_IDLE); }
372 <S_RMTS>idle_timeout { YYD; return(IDLE_TIMEOUT); }
373 <S_RMTS>idle_direction { YYD; return(IDLE_DIRECTION); }
374 <S_RMTS>ike_frag { YYD; return(IKE_FRAG); }
375 <S_RMTS>esp_frag { YYD; return(ESP_FRAG); }
376 <S_RMTS>mode_cfg { YYD; return(MODE_CFG); }
377 <S_RMTS>weak_phase1_check { YYD; return(WEAK_PHASE1_CHECK); }
378 <S_RMTS>eap_types { YYD; return(EAP_TYPES); }
379 <S_RMTS>eap_any { YYD; yylval.num = EAP_TYPE_NONE; return(EAP_TYPE); }
380 <S_RMTS>eap_sim { YYD; yylval.num = EAP_TYPE_SIM; return(EAP_TYPE); }
381 <S_RMTS>eap_aka { YYD; yylval.num = EAP_TYPE_AKA; return(EAP_TYPE); }
382 <S_RMTS>eap_options { YYD; return(EAP_OPTIONS); }
383 /* remote proposal */
384 <S_RMTS>proposal { BEGIN S_RMTP; YYDB; return(PROPOSAL); }
385 <S_RMTP>{bcl} { return(BOC); }
386 <S_RMTP>{ecl} { BEGIN S_RMTS; return(EOC); }
387 <S_RMTP>lifetime { YYD; return(LIFETIME); }
388 <S_RMTP>time { YYD; return(LIFETYPE_TIME); }
389 <S_RMTP>byte { YYD; return(LIFETYPE_BYTE); }
390 <S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); }
391 <S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); }
392 <S_RMTP>hash_algorithm { YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); }
393 <S_RMTP>prf_algorithm { YYD; yylval.num = algclass_ikev2_prf; return(ALGORITHM_CLASS); }
394 <S_RMTP>integ_algorithm { YYD; yylval.num = algclass_ikev2_integ; return(ALGORITHM_CLASS); }
395 <S_RMTP>dh_group { YYD; return(DH_GROUP); }
396 <S_RMTP>gss_id { YYD; return(GSS_ID); }
397 <S_RMTP>gssapi_id { YYD; return(GSS_ID); } /* for back compatibility */
398
399 /* GSS ID encoding type (global) */
400 <S_INI>gss_id_enc { BEGIN S_GSSENC; YYDB; return(GSS_ID_ENC); }
401 <S_GSSENC>latin1 { YYD; yylval.num = LC_GSSENC_LATIN1;
402 return(GSS_ID_ENCTYPE); }
403 <S_GSSENC>utf-16le { YYD; yylval.num = LC_GSSENC_UTF16LE;
404 return(GSS_ID_ENCTYPE); }
405 <S_GSSENC>{semi} { BEGIN S_INI; YYDB; return(EOS); }
406
407 /* parameter */
408 on { YYD; yylval.num = TRUE; return(SWITCH); }
409 off { YYD; yylval.num = FALSE; return(SWITCH); }
410
411 /* prefix */
412 {slash}({digit}{1,3}) {
413 YYD;
414 yytext++;
415 yylval.num = atoi(yytext);
416 return(PREFIX);
417 }
418
419 /* port number */
420 {blcl}{decstring}{elcl} {
421 char *p = yytext;
422 YYD;
423 while (*++p != ']') ;
424 *p = 0;
425 yytext++;
426 yylval.num = atoi(yytext);
427 return(PORT);
428 }
429
430 /* address range */
431 {hyphen}{addrstring} {
432 YYD;
433 yytext++;
434 yylval.val = vmalloc(yyleng + 1);
435 if (yylval.val == NULL) {
436 racoon_yyerror("vmalloc failed");
437 return -1;
438 }
439 memcpy(yylval.val->v, yytext, yylval.val->l);
440 return(ADDRRANGE);
441 }
442
443 /* upper protocol */
444 esp { YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); }
445 ah { YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); }
446 ipcomp { YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); }
447 icmp { YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); }
448 icmp6 { YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); }
449 tcp { YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); }
450 udp { YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); }
451
452 /* algorithm type */
453 des_iv64 { YYD; yylval.num = algtype_des_iv64; return(ALGORITHMTYPE); }
454 des { YYD; yylval.num = algtype_des; return(ALGORITHMTYPE); }
455 3des { YYD; yylval.num = algtype_3des; return(ALGORITHMTYPE); }
456 rc5 { YYD; yylval.num = algtype_rc5; return(ALGORITHMTYPE); }
457 idea { YYD; yylval.num = algtype_idea; return(ALGORITHMTYPE); }
458 cast128 { YYD; yylval.num = algtype_cast128; return(ALGORITHMTYPE); }
459 blowfish { YYD; yylval.num = algtype_blowfish; return(ALGORITHMTYPE); }
460 3idea { YYD; yylval.num = algtype_3idea; return(ALGORITHMTYPE); }
461 des_iv32 { YYD; yylval.num = algtype_des_iv32; return(ALGORITHMTYPE); }
462 rc4 { YYD; yylval.num = algtype_rc4; return(ALGORITHMTYPE); }
463 null_enc { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); }
464 null { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); }
465 aes { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); }
466 rijndael { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); }
467 twofish { YYD; yylval.num = algtype_twofish; return(ALGORITHMTYPE); }
468 non_auth { YYD; yylval.num = algtype_non_auth; return(ALGORITHMTYPE); }
469 hmac_md5 { YYD; yylval.num = algtype_hmac_md5_128; return(ALGORITHMTYPE); }
470 hmac_sha1 { YYD; yylval.num = algtype_hmac_sha1_160; return(ALGORITHMTYPE); }
471 hmac_sha2_256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); }
472 hmac_sha256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); }
473 hmac_sha2_384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); }
474 hmac_sha384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); }
475 hmac_sha2_512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); }
476 hmac_sha512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); }
477 hmac_md5_96 { YYD; yylval.num = algtype_hmac_md5_96; return(ALGORITHMTYPE); }
478 hmac_sha1_96 { YYD; yylval.num = algtype_hmac_sha1_96; return(ALGORITHMTYPE); }
479 des_mac { YYD; yylval.num = algtype_des_mac; return(ALGORITHMTYPE); }
480 kpdk { YYD; yylval.num = algtype_kpdk; return(ALGORITHMTYPE); }
481 md5 { YYD; yylval.num = algtype_md5; return(ALGORITHMTYPE); }
482 sha1 { YYD; yylval.num = algtype_sha1; return(ALGORITHMTYPE); }
483 tiger { YYD; yylval.num = algtype_tiger; return(ALGORITHMTYPE); }
484 sha2_256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); }
485 sha256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); }
486 sha2_384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); }
487 sha384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); }
488 sha2_512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); }
489 sha512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); }
490 oui { YYD; yylval.num = algtype_oui; return(ALGORITHMTYPE); }
491 deflate { YYD; yylval.num = algtype_deflate; return(ALGORITHMTYPE); }
492 lzs { YYD; yylval.num = algtype_lzs; return(ALGORITHMTYPE); }
493 modp768 { YYD; yylval.num = algtype_modp768; return(ALGORITHMTYPE); }
494 modp1024 { YYD; yylval.num = algtype_modp1024; return(ALGORITHMTYPE); }
495 modp1536 { YYD; yylval.num = algtype_modp1536; return(ALGORITHMTYPE); }
496 ec2n155 { YYD; yylval.num = algtype_ec2n155; return(ALGORITHMTYPE); }
497 ec2n185 { YYD; yylval.num = algtype_ec2n185; return(ALGORITHMTYPE); }
498 modp2048 { YYD; yylval.num = algtype_modp2048; return(ALGORITHMTYPE); }
499 modp3072 { YYD; yylval.num = algtype_modp3072; return(ALGORITHMTYPE); }
500 modp4096 { YYD; yylval.num = algtype_modp4096; return(ALGORITHMTYPE); }
501 modp6144 { YYD; yylval.num = algtype_modp6144; return(ALGORITHMTYPE); }
502 modp8192 { YYD; yylval.num = algtype_modp8192; return(ALGORITHMTYPE); }
503 pre_shared_key { YYD; yylval.num = algtype_psk; return(ALGORITHMTYPE); }
504 rsasig { YYD; yylval.num = algtype_rsasig; return(ALGORITHMTYPE); }
505 dsssig { YYD; yylval.num = algtype_dsssig; return(ALGORITHMTYPE); }
506 rsaenc { YYD; yylval.num = algtype_rsaenc; return(ALGORITHMTYPE); }
507 rsarev { YYD; yylval.num = algtype_rsarev; return(ALGORITHMTYPE); }
508 gssapi_krb { YYD; yylval.num = algtype_gssapikrb; return(ALGORITHMTYPE); }
509 hybrid_rsa_server {
510 #ifdef ENABLE_HYBRID
511 YYD; yylval.num = algtype_hybrid_rsa_s; return(ALGORITHMTYPE);
512 #else
513 racoon_yyerror("racoon not configured with --enable-hybrid");
514 #endif
515 }
516 hybrid_dss_server {
517 #ifdef ENABLE_HYBRID
518 YYD; yylval.num = algtype_hybrid_dss_s; return(ALGORITHMTYPE);
519 #else
520 racoon_yyerror("racoon not configured with --enable-hybrid");
521 #endif
522 }
523 hybrid_rsa_client {
524 #ifdef ENABLE_HYBRID
525 YYD; yylval.num = algtype_hybrid_rsa_c; return(ALGORITHMTYPE);
526 #else
527 racoon_yyerror("racoon not configured with --enable-hybrid");
528 #endif
529 }
530 hybrid_dss_client {
531 #ifdef ENABLE_HYBRID
532 YYD; yylval.num = algtype_hybrid_dss_c; return(ALGORITHMTYPE);
533 #else
534 racoon_yyerror("racoon not configured with --enable-hybrid");
535 #endif
536 }
537
538 xauth_psk_server {
539 #ifdef ENABLE_HYBRID
540 YYD; yylval.num = algtype_xauth_psk_s; return(ALGORITHMTYPE);
541 #else
542 racoon_yyerror("racoon not configured with --enable-hybrid");
543 #endif
544 }
545 xauth_psk_client {
546 #ifdef ENABLE_HYBRID
547 YYD; yylval.num = algtype_xauth_psk_c; return(ALGORITHMTYPE);
548 #else
549 racoon_yyerror("racoon not configured with --enable-hybrid");
550 #endif
551 }
552 xauth_rsa_server {
553 #ifdef ENABLE_HYBRID
554 YYD; yylval.num = algtype_xauth_rsa_s; return(ALGORITHMTYPE);
555 #else
556 racoon_yyerror("racoon not configured with --enable-hybrid");
557 #endif
558 }
559 xauth_rsa_client {
560 #ifdef ENABLE_HYBRID
561 YYD; yylval.num = algtype_xauth_rsa_c; return(ALGORITHMTYPE);
562 #else
563 racoon_yyerror("racoon not configured with --enable-hybrid");
564 #endif
565 }
566 eap_psk_client {
567 #ifdef ENABLE_HYBRID
568 YYD; yylval.num = algtype_eap_psk_c; return(ALGORITHMTYPE);
569 #else
570 racoon_yyerror("racoon not configured with --enable-hybrid");
571 #endif
572 }
573 eap_rsa_client {
574 #ifdef ENABLE_HYBRID
575 YYD; yylval.num = algtype_eap_rsa_c; return(ALGORITHMTYPE);
576 #else
577 racoon_yyerror("racoon not configured with --enable-hybrid");
578 #endif
579 }
580
581
582
583 /* identifier type */
584 vendor_id { YYD; racoon_yywarn("it is obsoleted."); return(VENDORID); }
585 user_fqdn { YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); }
586 fqdn { YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); }
587 keyid { YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); }
588 keyid_use {
589 YYD;
590 yylval.num = IDTYPE_KEYIDUSE;
591 return(IDENTIFIERTYPE);
592 }
593 address { YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); }
594 subnet { YYD; yylval.num = IDTYPE_SUBNET; return(IDENTIFIERTYPE); }
595 asn1dn { YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
596 certname { YYD; racoon_yywarn("certname will be obsoleted in near future."); yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
597
598 /* shared secret type */
599 use {
600 YYD;
601 yylval.num = SECRETTYPE_USE;
602 return(SECRETTYPE);
603 }
604 key {
605 YYD;
606 yylval.num = SECRETTYPE_KEY;
607 return(SECRETTYPE);
608 }
609 keychain {
610 #if HAVE_KEYCHAIN
611 YYD;
612 yylval.num = SECRETTYPE_KEYCHAIN;
613 return(SECRETTYPE);
614 #else
615 racoon_yyerror("Apple specific features not compiled in.");
616 #endif
617 }
618 keychain_by_id {
619 YYD;
620 yylval.num = SECRETTYPE_KEYCHAIN_BY_ID;
621 return(SECRETTYPE);
622 }
623
624 /* certificate verification */
625 openssl {
626 YYD;
627 yylval.num = VERIFICATION_MODULE_OPENSSL;
628 return(VERIFICATION_MODULE);
629 }
630 sec_framework {
631 YYD;
632 yylval.num = VERIFICATION_MODULE_SEC_FRAMEWORK;
633 return(VERIFICATION_MODULE);
634 }
635 use_open_dir {
636 YYD;
637 yylval.num = VERIFICATION_OPTION_OPEN_DIR;
638 return(VERIFICATION_OPTION);
639 }
640 use_peers_identifier {
641 YYD;
642 yylval.num = VERIFICATION_OPTION_PEERS_IDENTIFIER;
643 return(VERIFICATION_OPTION);
644 }
645
646 /* identifier qualifier */
647 tag { YYD; yylval.num = IDQUAL_TAG; return(IDENTIFIERQUAL); }
648 file { YYD; yylval.num = IDQUAL_FILE; return(IDENTIFIERQUAL); }
649
650 /* units */
651 B|byte|bytes { YYD; return(UNITTYPE_BYTE); }
652 KB { YYD; return(UNITTYPE_KBYTES); }
653 MB { YYD; return(UNITTYPE_MBYTES); }
654 TB { YYD; return(UNITTYPE_TBYTES); }
655 sec|secs|second|seconds { YYD; return(UNITTYPE_SEC); }
656 min|mins|minute|minutes { YYD; return(UNITTYPE_MIN); }
657 hour|hours { YYD; return(UNITTYPE_HOUR); }
658
659 dpd_default { YYD; return(DPD_ALGO_TYPE_DEFAULT); }
660 dpd_inbound_detect { YYD; return(DPD_ALGO_TYPE_INBOUND); }
661 dpd_blackhole_detect { YYD; return(DPD_ALGO_TYPE_BLACKHOLE); }
662
663 idle_any { YYD; return(IDLE_DIRECTION_ANY); }
664 idle_inbound { YYD; return(IDLE_DIRECTION_IN); }
665 idle_outbound { YYD; return(IDLE_DIRECTION_OUT); }
666
667 /* boolean */
668 yes { YYD; yylval.num = TRUE; return(BOOLEAN); }
669 no { YYD; yylval.num = FALSE; return(BOOLEAN); }
670
671 {decstring} {
672 char *bp;
673
674 YYD;
675 yylval.num = strtol(yytext, &bp, 10);
676 return(NUMBER);
677 }
678
679 {hexstring} {
680 char *p;
681
682 YYD;
683 yylval.val = vmalloc(yyleng + (yyleng & 1) + 1);
684 if (yylval.val == NULL) {
685 racoon_yyerror("vmalloc failed");
686 return -1;
687 }
688
689 p = yylval.val->v;
690 *p++ = '0';
691 *p++ = 'x';
692
693 /* fixed string if length is odd. */
694 if (yyleng & 1)
695 *p++ = '0';
696 memcpy(p, &yytext[2], yyleng - 1);
697
698 return(HEXSTRING);
699 }
700
701 {quotedstring} {
702 char *p = yytext;
703
704 YYD;
705 while (*++p != '"') ;
706 *p = '\0';
707
708 yylval.val = vmalloc(yyleng - 1);
709 if (yylval.val == NULL) {
710 racoon_yyerror("vmalloc failed");
711 return -1;
712 }
713 memcpy(yylval.val->v, &yytext[1], yylval.val->l);
714
715 return(QUOTEDSTRING);
716 }
717
718 {addrstring} {
719 YYD;
720
721 yylval.val = vmalloc(yyleng + 1);
722 if (yylval.val == NULL) {
723 racoon_yyerror("vmalloc failed");
724 return -1;
725 }
726 memcpy(yylval.val->v, yytext, yylval.val->l);
727
728 return(ADDRSTRING);
729 }
730
731 <<EOF>> {
732 yy_delete_buffer(YY_CURRENT_BUFFER);
733 incstackp--;
734 nextfile:
735 if (incstack[incstackp].matches.gl_pathc != 0 &&
736 incstack[incstackp].matches.gl_pathv &&
737 incstack[incstackp].matchon <
738 incstack[incstackp].matches.gl_pathc) {
739 char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
740 incstack[incstackp].matchon++;
741 incstackp++;
742 if (yycf_set_buffer(filepath) != 0) {
743 incstackp--;
744 goto nextfile;
745 }
746 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
747 BEGIN(S_INI);
748 } else {
749 globfree(&incstack[incstackp].matches);
750 if (incstackp == 0)
751 yyterminate();
752 else
753 yy_switch_to_buffer(incstack[incstackp].prevstate);
754 }
755 }
756
757 /* ... */
758 {ws} { ; }
759 {nl} { incstack[incstackp].lineno++; }
760 {comment} { YYD; }
761 {semi} { return(EOS); }
762 . { yymore(); }
763
764 %%
765
766 void
767 yyerror(const char *msg)
768 {
769 plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg);
770 yyerrorcount++;
771 }
772
773 void
774 yywarn(const char *msg)
775 {
776 plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg);
777 }
778
779 void
780 racoon_yyerror(const char *fmt, ...)
781 {
782 va_list ap;
783 char msg[512];
784
785 va_start(ap, fmt);
786 vsnprintf(msg, sizeof(msg), fmt, ap);
787 va_end(ap);
788
789 yyerror(msg);
790 }
791
792 void
793 racoon_yywarn(const char *fmt, ...)
794 {
795 va_list ap;
796 char msg[512];
797
798 va_start(ap, fmt);
799 vsnprintf(msg, sizeof(msg), fmt, ap);
800 va_end(ap);
801
802 yywarn(msg);
803 }
804
805 int
806 yycf_switch_buffer(path)
807 char *path;
808 {
809 char *filepath = NULL;
810
811 /* got the include file name */
812 if (incstackp >= MAX_INCLUDE_DEPTH) {
813 plog(ASL_LEVEL_ERR,
814 "Includes nested too deeply");
815 return -1;
816 }
817
818 if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 ||
819 incstack[incstackp].matches.gl_pathc == 0) {
820 plog(ASL_LEVEL_WARNING,
821 "glob found no matches for path \"%s\"\n", path);
822 return 0;
823 }
824 incstack[incstackp].matchon = 0;
825 incstack[incstackp].prevstate = YY_CURRENT_BUFFER;
826
827 nextmatch:
828 if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc)
829 return -1;
830 filepath =
831 incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
832 incstack[incstackp].matchon++;
833 incstackp++;
834
835 if (yycf_set_buffer(filepath) != 0) {
836 incstackp--;
837 goto nextmatch;
838 }
839
840 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
841
842 BEGIN(S_INI);
843
844 return 0;
845 }
846
847 int
848 yycf_set_buffer(path)
849 char *path;
850 {
851 yyin = fopen(path, "r");
852 if (yyin == NULL) {
853 fprintf(stderr, "failed to open file %s (%s)\n",
854 path, strerror(errno));
855 plog(ASL_LEVEL_ERR,
856 "failed to open file %s (%s)\n",
857 path, strerror(errno));
858 return -1;
859 }
860
861 /* initialize */
862 if (incstack[incstackp].path != NULL) {
863 fclose(incstack[incstackp].fp);
864 racoon_free(incstack[incstackp].path);
865 }
866 incstack[incstackp].fp = yyin;
867 incstack[incstackp].path = racoon_strdup(path);
868 STRDUP_FATAL(incstack[incstackp].path);
869 incstack[incstackp].lineno = 1;
870 plog(ASL_LEVEL_DEBUG,
871 "reading configuration file %s\n", path);
872
873 return 0;
874 }
875
876 void
877 yycf_init_buffer()
878 {
879 int i;
880
881 for (i = 0; i < MAX_INCLUDE_DEPTH; i++)
882 memset(&incstack[i], 0, sizeof(incstack[i]));
883 incstackp = 0;
884 }
885
886 void
887 yycf_clean_buffer()
888 {
889 int i;
890
891 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) {
892 if (incstack[i].path != NULL) {
893 fclose(incstack[i].fp);
894 racoon_free(incstack[i].path);
895 incstack[i].path = NULL;
896 }
897 }
898 }
899