1 /* $KAME: cftoken.l,v 1.69 2002/09/27 06:03:51 itojun Exp $ */
6 #include <sys/socket.h>
8 #include <netinet/in.h>
9 #include <netinet6/ipsec.h>
30 #include "algorithm.h"
33 #include "localconf.h"
35 #include "isakmp_var.h"
37 #include "ipsec_doi.h"
43 /*#include "y.tab.h"*/
47 #if defined(YIPS_DEBUG)
48 # define YYDB plog(LLV_DEBUG2, LOCATION, NULL, \
49 "begin <%d>%s\n", yy_start, yytext);
51 plog(LLV_DEBUG2, LOCATION, NULL, "<%d>%s", \
52 yy_start, loglevel >= LLV_DEBUG2 ? "\n" : ""); \
57 #endif /* defined(YIPS_DEBUG) */
59 #define MAX_INCLUDE_DEPTH 10
61 static struct include_stack {
64 YY_BUFFER_STATE prevstate;
68 } incstack[MAX_INCLUDE_DEPTH];
69 static int incstackp = 0;
71 static int yy_first_time = 1;
80 /*octet (([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */
93 bracketstring \<[^>]*\>
94 quotedstring \"[^"]*\"
95 addrstring [a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*)
97 hexstring 0x{hexdigit}+
99 %s S_INI S_PTH S_INF S_LOG S_PAD S_LST S_RTRY
102 %s S_RMT S_RMTS S_RMTP
114 <S_INI>path { BEGIN S_PTH; YYDB; return(PATH); }
115 <S_PTH>include { YYD; yylval.num = LC_PATHTYPE_INCLUDE;
117 <S_PTH>pre_shared_key { YYD; yylval.num = LC_PATHTYPE_PSK;
119 <S_PTH>certificate { YYD; yylval.num = LC_PATHTYPE_CERT;
121 <S_PTH>backupsa { YYD; yylval.num = LC_PATHTYPE_BACKUPSA;
123 <S_PTH>{semi} { BEGIN S_INI; YYDB; return(EOS); }
126 <S_INI>include { YYDB; return(INCLUDE); }
128 /* self information */
129 <S_INI>identifier { BEGIN S_INF; YYDB; yywarn("it is obsoleted. use \"my_identifier\" in each remote directives."); return(IDENTIFIER); }
130 <S_INF>{semi} { BEGIN S_INI; return(EOS); }
133 <S_INI>complex_bundle { YYDB; return(COMPLEX_BUNDLE); }
136 <S_INI>log { BEGIN S_LOG; YYDB; return(LOGGING); }
137 <S_LOG>info { YYD; yywarn("it is obsoleted. use \"notify\""); yylval.num = 0; return(LOGLEV); }
138 <S_LOG>notify { YYD; yylval.num = 0; return(LOGLEV); }
139 <S_LOG>debug { YYD; yylval.num = 1; return(LOGLEV); }
140 <S_LOG>debug2 { YYD; yylval.num = 2; return(LOGLEV); }
141 <S_LOG>debug3 { YYD; yywarn("it is osboleted. use \"debug2\""); yylval.num = 2; return(LOGLEV); }
142 <S_LOG>debug4 { YYD; yywarn("it is obsoleted. use \"debug2\""); yylval.num = 2; return(LOGLEV); }
143 <S_LOG>{semi} { BEGIN S_INI; return(EOS); }
146 <S_INI>padding { BEGIN S_PAD; YYDB; return(PADDING); }
147 <S_PAD>{bcl} { return(BOC); }
148 <S_PAD>randomize { YYD; return(PAD_RANDOMIZE); }
149 <S_PAD>randomize_length { YYD; return(PAD_RANDOMIZELEN); }
150 <S_PAD>maximum_length { YYD; return(PAD_MAXLEN); }
151 <S_PAD>strict_check { YYD; return(PAD_STRICT); }
152 <S_PAD>exclusive_tail { YYD; return(PAD_EXCLTAIL); }
153 <S_PAD>{ecl} { BEGIN S_INI; return(EOC); }
156 <S_INI>listen { BEGIN S_LST; YYDB; return(LISTEN); }
157 <S_LST>{bcl} { return(BOC); }
158 <S_LST>isakmp { YYD; return(X_ISAKMP); }
159 <S_LST>admin { YYD; return(X_ADMIN); }
160 <S_LST>strict_address { YYD; return(STRICT_ADDRESS); }
161 <S_LST>{ecl} { BEGIN S_INI; return(EOC); }
164 <S_INI>timer { BEGIN S_RTRY; YYDB; return(RETRY); }
165 <S_RTRY>{bcl} { return(BOC); }
166 <S_RTRY>counter { YYD; return(RETRY_COUNTER); }
167 <S_RTRY>interval { YYD; return(RETRY_INTERVAL); }
168 <S_RTRY>persend { YYD; return(RETRY_PERSEND); }
169 <S_RTRY>phase1 { YYD; return(RETRY_PHASE1); }
170 <S_RTRY>phase2 { YYD; return(RETRY_PHASE2); }
171 <S_RTRY>{ecl} { BEGIN S_INI; return(EOC); }
174 <S_INI>sainfo { BEGIN S_SAINF; YYDB; return(SAINFO); }
175 <S_SAINF>anonymous { YYD; return(ANONYMOUS); }
176 <S_SAINF>{blcl}any{elcl} { YYD; return(PORTANY); }
177 <S_SAINF>any { YYD; return(ANY); }
179 <S_SAINF>{bcl} { BEGIN S_SAINFS; return(BOC); }
180 <S_SAINF>{semi} { BEGIN S_INI; return(EOS); }
181 <S_SAINFS>{ecl} { BEGIN S_INI; return(EOC); }
182 <S_SAINFS>pfs_group { YYD; return(PFS_GROUP); }
183 <S_SAINFS>identifier { YYD; yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
184 <S_SAINFS>my_identifier { YYD; return(MY_IDENTIFIER); }
185 <S_SAINFS>lifetime { YYD; return(LIFETIME); }
186 <S_SAINFS>time { YYD; return(LIFETYPE_TIME); }
187 <S_SAINFS>byte { YYD; return(LIFETYPE_BYTE); }
188 <S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); }
189 <S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); }
190 <S_SAINFS>compression_algorithm { YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); }
191 <S_SAINFS>{comma} { YYD; return(COMMA); }
194 <S_INI>remote { BEGIN S_RMT; YYDB; return(REMOTE); }
195 <S_RMT>anonymous { YYD; return(ANONYMOUS); }
197 <S_RMT>{bcl} { BEGIN S_RMTS; return(BOC); }
198 <S_RMTS>{ecl} { BEGIN S_INI; return(EOC); }
199 <S_RMTS>exchange_mode { YYD; return(EXCHANGE_MODE); }
200 <S_RMTS>{comma} { YYD; /* XXX ignored, but to be handled. */ ; }
201 <S_RMTS>base { YYD; yylval.num = ISAKMP_ETYPE_BASE; return(EXCHANGETYPE); }
202 <S_RMTS>main { YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); }
203 <S_RMTS>aggressive { YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); }
204 <S_RMTS>doi { YYD; return(DOI); }
205 <S_RMTS>ipsec_doi { YYD; yylval.num = IPSEC_DOI; return(DOITYPE); }
206 <S_RMTS>situation { YYD; return(SITUATION); }
207 <S_RMTS>identity_only { YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); }
208 <S_RMTS>secrecy { YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); }
209 <S_RMTS>integrity { YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); }
210 <S_RMTS>identifier { YYD; yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); }
211 <S_RMTS>my_identifier { YYD; return(MY_IDENTIFIER); }
212 <S_RMTS>peers_identifier { YYD; return(PEERS_IDENTIFIER); }
213 <S_RMTS>verify_identifier { YYD; return(VERIFY_IDENTIFIER); }
214 <S_RMTS>certificate_type { YYD; return(CERTIFICATE_TYPE); }
215 <S_RMTS>shared_secret { YYD; return(SHARED_SECRET); }
216 <S_RMTS>x509 { YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); }
217 <S_RMTS>peers_certfile { YYD; return(PEERS_CERTFILE); }
218 <S_RMTS>dnssec { YYD; return(DNSSEC); }
219 <S_RMTS>verify_cert { YYD; return(VERIFY_CERT); }
220 <S_RMTS>send_cert { YYD; return(SEND_CERT); }
221 <S_RMTS>send_cr { YYD; return(SEND_CR); }
222 <S_RMTS>dh_group { YYD; return(DH_GROUP); }
223 <S_RMTS>nonce_size { YYD; return(NONCE_SIZE); }
224 <S_RMTS>generate_policy { YYD; return(GENERATE_POLICY); }
225 <S_RMTS>support_mip6 { YYD; return(SUPPORT_MIP6); }
226 <S_RMTS>initial_contact { YYD; return(INITIAL_CONTACT); }
227 <S_RMTS>proposal_check { YYD; return(PROPOSAL_CHECK); }
228 <S_RMTS>obey { YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); }
229 <S_RMTS>strict { YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); }
230 <S_RMTS>exact { YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); }
231 <S_RMTS>claim { YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); }
232 <S_RMTS>keepalive { YYD; return(KEEPALIVE); }
233 <S_RMTS>passive { YYD; return(PASSIVE); }
234 <S_RMTS>lifetime { YYD; return(LIFETIME); }
235 <S_RMTS>time { YYD; return(LIFETYPE_TIME); }
236 <S_RMTS>byte { YYD; return(LIFETYPE_BYTE); }
237 /* remote proposal */
238 <S_RMTS>proposal { BEGIN S_RMTP; YYDB; return(PROPOSAL); }
239 <S_RMTP>{bcl} { return(BOC); }
240 <S_RMTP>{ecl} { BEGIN S_RMTS; return(EOC); }
241 <S_RMTP>lifetime { YYD; return(LIFETIME); }
242 <S_RMTP>time { YYD; return(LIFETYPE_TIME); }
243 <S_RMTP>byte { YYD; return(LIFETYPE_BYTE); }
244 <S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); }
245 <S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); }
246 <S_RMTP>hash_algorithm { YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); }
247 <S_RMTP>dh_group { YYD; return(DH_GROUP); }
248 <S_RMTP>gssapi_id { YYD; return(GSSAPI_ID); }
251 on { YYD; yylval.num = TRUE; return(SWITCH); }
252 off { YYD; yylval.num = FALSE; return(SWITCH); }
255 {slash}{digit}{1,3} {
258 yylval.num = atoi(yytext);
263 {blcl}{decstring}{elcl} {
266 while (*++p != ']') ;
269 yylval.num = atoi(yytext);
274 esp { YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); }
275 ah { YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); }
276 ipcomp { YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); }
277 icmp { YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); }
278 icmp6 { YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); }
279 tcp { YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); }
280 udp { YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); }
283 des_iv64 { YYD; yylval.num = algtype_des_iv64; return(ALGORITHMTYPE); }
284 des { YYD; yylval.num = algtype_des; return(ALGORITHMTYPE); }
285 3des { YYD; yylval.num = algtype_3des; return(ALGORITHMTYPE); }
286 rc5 { YYD; yylval.num = algtype_rc5; return(ALGORITHMTYPE); }
287 idea { YYD; yylval.num = algtype_idea; return(ALGORITHMTYPE); }
288 cast128 { YYD; yylval.num = algtype_cast128; return(ALGORITHMTYPE); }
289 blowfish { YYD; yylval.num = algtype_blowfish; return(ALGORITHMTYPE); }
290 3idea { YYD; yylval.num = algtype_3idea; return(ALGORITHMTYPE); }
291 des_iv32 { YYD; yylval.num = algtype_des_iv32; return(ALGORITHMTYPE); }
292 rc4 { YYD; yylval.num = algtype_rc4; return(ALGORITHMTYPE); }
293 null_enc { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); }
294 rijndael { YYD; yylval.num = algtype_rijndael; return(ALGORITHMTYPE); }
295 aes { YYD; yylval.num = algtype_rijndael; return(ALGORITHMTYPE); }
296 twofish { YYD; yylval.num = algtype_twofish; return(ALGORITHMTYPE); }
297 non_auth { YYD; yylval.num = algtype_non_auth; return(ALGORITHMTYPE); }
298 hmac_md5 { YYD; yylval.num = algtype_hmac_md5; return(ALGORITHMTYPE); }
299 hmac_sha1 { YYD; yylval.num = algtype_hmac_sha1; return(ALGORITHMTYPE); }
300 hmac_sha2_256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); }
301 hmac_sha2_384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); }
302 hmac_sha2_512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); }
303 des_mac { YYD; yylval.num = algtype_des_mac; return(ALGORITHMTYPE); }
304 kpdk { YYD; yylval.num = algtype_kpdk; return(ALGORITHMTYPE); }
305 md5 { YYD; yylval.num = algtype_md5; return(ALGORITHMTYPE); }
306 sha1 { YYD; yylval.num = algtype_sha1; return(ALGORITHMTYPE); }
307 tiger { YYD; yylval.num = algtype_tiger; return(ALGORITHMTYPE); }
308 sha2_256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); }
309 sha2_384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); }
310 sha2_512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); }
311 oui { YYD; yylval.num = algtype_oui; return(ALGORITHMTYPE); }
312 deflate { YYD; yylval.num = algtype_deflate; return(ALGORITHMTYPE); }
313 lzs { YYD; yylval.num = algtype_lzs; return(ALGORITHMTYPE); }
314 modp768 { YYD; yylval.num = algtype_modp768; return(ALGORITHMTYPE); }
315 modp1024 { YYD; yylval.num = algtype_modp1024; return(ALGORITHMTYPE); }
316 modp1536 { YYD; yylval.num = algtype_modp1536; return(ALGORITHMTYPE); }
317 ec2n155 { YYD; yylval.num = algtype_ec2n155; return(ALGORITHMTYPE); }
318 ec2n185 { YYD; yylval.num = algtype_ec2n185; return(ALGORITHMTYPE); }
319 modp2048 { YYD; yylval.num = algtype_modp2048; return(ALGORITHMTYPE); }
320 modp3072 { YYD; yylval.num = algtype_modp3072; return(ALGORITHMTYPE); }
321 modp4096 { YYD; yylval.num = algtype_modp4096; return(ALGORITHMTYPE); }
322 modp6144 { YYD; yylval.num = algtype_modp6144; return(ALGORITHMTYPE); }
323 modp8192 { YYD; yylval.num = algtype_modp8192; return(ALGORITHMTYPE); }
324 pre_shared_key { YYD; yylval.num = algtype_psk; return(ALGORITHMTYPE); }
325 rsasig { YYD; yylval.num = algtype_rsasig; return(ALGORITHMTYPE); }
326 dsssig { YYD; yylval.num = algtype_dsssig; return(ALGORITHMTYPE); }
327 rsaenc { YYD; yylval.num = algtype_rsaenc; return(ALGORITHMTYPE); }
328 rsarev { YYD; yylval.num = algtype_rsarev; return(ALGORITHMTYPE); }
329 gssapi_krb { YYD; yylval.num = algtype_gssapikrb; return(ALGORITHMTYPE); }
331 /* identifier type */
332 vendor_id { YYD; yywarn("it is obsoleted."); return(VENDORID); }
333 user_fqdn { YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); }
334 fqdn { YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); }
335 keyid { YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); }
336 address { YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); }
337 asn1dn { YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
338 certname { YYD; yywarn("certname will be obsoleted in near future."); yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
340 /* shared secret type */
341 use { YYD; yylval.num = SECRETTYPE_USE; return(SECRETTYPE); }
342 key { YYD; yylval.num = SECRETTYPE_KEY; return(SECRETTYPE); }
343 keychain { YYD; yylval.num = SECRETTYPE_KEYCHAIN; return(SECRETTYPE); }
346 B|byte|bytes { YYD; return(UNITTYPE_BYTE); }
347 KB { YYD; return(UNITTYPE_KBYTES); }
348 MB { YYD; return(UNITTYPE_MBYTES); }
349 TB { YYD; return(UNITTYPE_TBYTES); }
350 sec|secs|second|seconds { YYD; return(UNITTYPE_SEC); }
351 min|mins|minute|minutes { YYD; return(UNITTYPE_MIN); }
352 hour|hours { YYD; return(UNITTYPE_HOUR); }
355 yes { YYD; yylval.num = TRUE; return(BOOLEAN); }
356 no { YYD; yylval.num = FALSE; return(BOOLEAN); }
362 yylval.num = strtol(yytext, &bp, 10);
370 yylval.val = vmalloc(yyleng + (yyleng & 1) + 1);
371 if (yylval.val == NULL) {
372 yyerror("vmalloc failed");
380 /* fixed string if length is odd. */
383 memcpy(p, &yytext[2], yyleng - 1);
392 while (*++p != '"') ;
395 yylval.val = vmalloc(yyleng - 1);
396 if (yylval.val == NULL) {
397 yyerror("vmalloc failed");
400 memcpy(yylval.val->v, &yytext[1], yylval.val->l);
402 return(QUOTEDSTRING);
408 yylval.val = vmalloc(yyleng + 1);
409 if (yylval.val == NULL) {
410 yyerror("vmalloc failed");
413 memcpy(yylval.val->v, yytext, yylval.val->l);
419 yy_delete_buffer(YY_CURRENT_BUFFER);
420 fclose(incstack[incstackp].fp);
421 incstack[incstackp].fp = -1;
422 racoon_free(incstack[incstackp].path);
423 incstack[incstackp].path = NULL;
426 if (incstack[incstackp].matchon < incstack[incstackp].matches.gl_pathc)
428 char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
429 incstack[incstackp].matchon++;
431 if (yycf_set_buffer(filepath) != 0)
437 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
443 globfree(&incstack[incstackp].matches);
447 yy_switch_to_buffer(incstack[incstackp].prevstate);
453 {nl} { incstack[incstackp].lineno++; }
455 {semi} { return(EOS); }
461 yyerror(char *s, ...)
471 snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n",
472 incstack[incstackp].path, incstack[incstackp].lineno,
474 plogv(LLV_ERROR, LOCATION, NULL, fmt, ap);
491 snprintf(fmt, sizeof(fmt), "%s:%d: \"%s\" %s\n",
492 incstack[incstackp].path, incstack[incstackp].lineno,
494 plogv(LLV_WARNING, LOCATION, NULL, fmt, ap);
499 yycf_switch_buffer(path)
502 char* filepath = NULL;
503 /* got the include file name */
504 if (incstackp >= MAX_INCLUDE_DEPTH) {
505 plog(LLV_ERROR, LOCATION, NULL,
506 "Includes nested too deeply");
510 if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 ||
511 incstack[incstackp].matches.gl_pathc == 0)
513 plog(LLV_DEBUG, LOCATION, NULL,
514 "glob found no matches for path\n");
517 incstack[incstackp].matchon = 0;
518 incstack[incstackp].prevstate = YY_CURRENT_BUFFER;
521 if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc) return -1;
522 filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
523 incstack[incstackp].matchon++;
526 if (yycf_set_buffer(filepath) != 0)
532 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
540 yycf_set_buffer(path)
543 yyin = fopen(path, "r");
545 fprintf(stderr, "failed to open file %s (%s)\n",
546 path, strerror(errno));
547 plog(LLV_ERROR, LOCATION, NULL,
548 "failed to open file %s (%s)\n",
549 path, strerror(errno));
554 incstack[incstackp].fp = yyin;
555 incstack[incstackp].path = strdup(path);
556 incstack[incstackp].lineno = 1;
557 plog(LLV_DEBUG, LOCATION, NULL,
558 "reading config file %s\n",
569 for (i = 0; i < MAX_INCLUDE_DEPTH; i++)
570 memset(&incstack[i], 0, sizeof(incstack[i]));
579 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) {
580 if (incstack[i].path != NULL) {
581 if (incstack[i].fp >= 0)
582 fclose(incstack[i].fp);
583 racoon_free(incstack[i].path);
584 incstack[i].path = NULL;