1/* $NetBSD: cftoken.l,v 1.11.4.1 2007/08/01 11:52:20 vanhu Exp $ */ 2 3/* Id: cftoken.l,v 1.53 2006/08/22 18:17:17 manubsd Exp */ 4%option noyywrap 5%{ 6/* 7 * Copyright (C) 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002 and 2003 WIDE Project. 8 * All rights reserved. 9 * 10 * Redistribution and use in source and binary forms, with or without 11 * modification, are permitted provided that the following conditions 12 * are met: 13 * 1. Redistributions of source code must retain the above copyright 14 * notice, this list of conditions and the following disclaimer. 15 * 2. Redistributions in binary form must reproduce the above copyright 16 * notice, this list of conditions and the following disclaimer in the 17 * documentation and/or other materials provided with the distribution. 18 * 3. Neither the name of the project nor the names of its contributors 19 * may be used to endorse or promote products derived from this software 20 * without specific prior written permission. 21 * 22 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND 23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 25 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE 26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 32 * SUCH DAMAGE. 33 */ 34 35#include "config.h" 36 37#include <sys/types.h> 38#include <sys/param.h> 39#include <sys/socket.h> 40 41#include <netinet/in.h> 42#ifdef HAVE_NETINET6_IPSEC 43# include <netinet6/ipsec.h> 44#else 45# include <netinet/ipsec.h> 46#endif 47 48#include <stdlib.h> 49#include <stdio.h> 50#include <string.h> 51#include <errno.h> 52#include <limits.h> 53#include <ctype.h> 54#include <glob.h> 55#ifdef HAVE_STDARG_H 56#include <stdarg.h> 57#else 58#include <varargs.h> 59#endif 60 61//%%% BUG FIX - 2 missing include files when not using 62// the bison files 63#ifdef HAVE_OPENSSL 64#include <openssl/bn.h> 65#include <openssl/rsa.h> 66#endif 67 68#include "var.h" 69#include "misc.h" 70#include "vmbuf.h" 71#include "plog.h" 72#include "debug.h" 73 74#include "algorithm.h" 75#include "cfparse_proto.h" 76#include "cftoken_proto.h" 77#include "localconf.h" 78#include "oakley.h" 79#include "isakmp_var.h" 80#include "isakmp.h" 81#include "ipsec_doi.h" 82#include "policy.h" 83#include "proposal.h" 84#include "remoteconf.h" 85#include "nattraversal.h" 86#ifdef GC 87#include "gcmalloc.h" 88#endif 89 90#include "y.tab.h" 91#include "eap_sim.h" 92 93int yyerrorcount = 0; 94 95#if defined(YIPS_DEBUG) 96# define YYDB plog(ASL_LEVEL_DEBUG, \ 97 "begin <%d>%s\n", yy_start, yytext); 98# define YYD { \ 99 plog(ASL_LEVEL_DEBUG, "<%d>%s", \ 100 yy_start, loglevel >= ASL_LEVEL_DEBUG ? "\n" : ""); \ 101} 102#else 103# define YYDB 104# define YYD 105#endif /* defined(YIPS_DEBUG) */ 106 107#define MAX_INCLUDE_DEPTH 10 108 109static struct include_stack { 110 char *path; 111 FILE *fp; 112 YY_BUFFER_STATE prevstate; 113 int lineno; 114 glob_t matches; 115 int matchon; 116} incstack[MAX_INCLUDE_DEPTH]; 117static int incstackp = 0; 118 119static int yy_first_time = 1; 120%} 121 122/* common section */ 123nl \n 124ws [ \t]+ 125digit [0-9] 126letter [A-Za-z] 127hexdigit [0-9A-Fa-f] 128/*octet (([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */ 129special [()+\|\?\*] 130comma \, 131dot \. 132slash \/ 133bcl \{ 134ecl \} 135blcl \[ 136elcl \] 137hyphen \- 138percent \% 139semi \; 140comment \#.* 141ccomment "/*" 142bracketstring \<[^>]*\> 143quotedstring \"[^"]*\" 144addrstring [a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*) 145decstring {digit}+ 146hexstring 0x{hexdigit}+ 147 148%s S_INI S_PRIV S_PTH S_INF S_LOG S_PAD S_LST S_RTRY S_CFG 149%s S_ALGST S_ALGCL 150%s S_SAINF S_SAINFS 151%s S_RMT S_RMTS S_RMTP 152%s S_SA 153%s S_GSSENC 154 155%% 156%{ 157 if (yy_first_time) { 158 BEGIN S_INI; 159 yy_first_time = 0; 160 } 161%} 162 163 164 /* path */ 165<S_INI>path { BEGIN S_PTH; YYDB; return(PATH); } 166<S_PTH>include { YYD; yylval.num = LC_PATHTYPE_INCLUDE; 167 return(PATHTYPE); } 168<S_PTH>pre_shared_key { YYD; yylval.num = LC_PATHTYPE_PSK; 169 return(PATHTYPE); } 170<S_PTH>certificate { YYD; yylval.num = LC_PATHTYPE_CERT; 171 return(PATHTYPE); } 172<S_PTH>pidfile { YYD; yylval.num = LC_PATHTYPE_PIDFILE; 173 return(PATHTYPE); } 174<S_PTH>logfile { YYD; yylval.num = LC_PATHTYPE_LOGFILE; 175 return(PATHTYPE); } 176<S_PTH>{semi} { BEGIN S_INI; YYDB; return(EOS); } 177 178 /* include */ 179<S_INI>include { YYDB; return(INCLUDE); } 180 181 /* self information */ 182<S_INI>identifier { BEGIN S_INF; YYDB; racoon_yywarn("it is obsoleted. use \"my_identifier\" in each remote directives."); return(IDENTIFIER); } 183<S_INF>{semi} { BEGIN S_INI; return(EOS); } 184 185 /* special */ 186<S_INI>complex_bundle { YYDB; return(COMPLEX_BUNDLE); } 187 188 /* logging */ 189<S_INI>log { BEGIN S_LOG; YYDB; return(LOGGING); } 190<S_LOG>error { YYD; yylval.num = ASL_LEVEL_ERR; return(LOGLEV); } 191<S_LOG>warning { YYD; yylval.num = ASL_LEVEL_WARNING; return(LOGLEV); } 192<S_LOG>notify { YYD; yylval.num = ASL_LEVEL_NOTICE; return(LOGLEV); } 193<S_LOG>info { YYD; yylval.num = ASL_LEVEL_INFO; return(LOGLEV); } 194<S_LOG>debug { YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); } 195<S_LOG>debug2 { YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); } 196<S_LOG>debug3 { YYD; racoon_yywarn("it is obsoleted. use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); } 197<S_LOG>debug4 { YYD; racoon_yywarn("it is obsoleted. use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); } 198<S_LOG>{semi} { BEGIN S_INI; return(EOS); } 199 200 /* padding */ 201<S_INI>padding { BEGIN S_PAD; YYDB; return(PADDING); } 202<S_PAD>{bcl} { return(BOC); } 203<S_PAD>randomize { YYD; return(PAD_RANDOMIZE); } 204<S_PAD>randomize_length { YYD; return(PAD_RANDOMIZELEN); } 205<S_PAD>maximum_length { YYD; return(PAD_MAXLEN); } 206<S_PAD>strict_check { YYD; return(PAD_STRICT); } 207<S_PAD>exclusive_tail { YYD; return(PAD_EXCLTAIL); } 208<S_PAD>{ecl} { BEGIN S_INI; return(EOC); } 209 210 /* listen */ 211<S_INI>listen { BEGIN S_LST; YYDB; return(LISTEN); } 212<S_LST>{bcl} { return(BOC); } 213<S_LST>isakmp { YYD; return(X_ISAKMP); } 214<S_LST>isakmp_natt { YYD; return(X_ISAKMP_NATT); } 215<S_LST>admin { YYD; return(X_ADMIN); } 216<S_LST>adminsock { YYD; return(ADMINSOCK); } 217<S_LST>disabled { YYD; return(DISABLED); } 218<S_LST>strict_address { YYD; return(STRICT_ADDRESS); } 219<S_LST>{ecl} { BEGIN S_INI; return(EOC); } 220 221 /* mode_cfg */ 222<S_INI>mode_cfg { BEGIN S_CFG; YYDB; return(MODECFG); } 223<S_CFG>{bcl} { return(BOC); } 224<S_CFG>network4 { YYD; return(CFG_NET4); } 225<S_CFG>netmask4 { YYD; return(CFG_MASK4); } 226<S_CFG>dns4 { YYD; return(CFG_DNS4); } 227<S_CFG>wins4 { YYD; return(CFG_NBNS4); } 228<S_CFG>default_domain { YYD; return(CFG_DEFAULT_DOMAIN); } 229<S_CFG>auth_source { YYD; return(CFG_AUTH_SOURCE); } 230<S_CFG>auth_groups { YYD; return(CFG_AUTH_GROUPS); } 231<S_CFG>group_source { YYD; return(CFG_GROUP_SOURCE); } 232<S_CFG>conf_source { YYD; return(CFG_CONF_SOURCE); } 233<S_CFG>accounting { YYD; return(CFG_ACCOUNTING); } 234<S_CFG>system { YYD; return(CFG_SYSTEM); } 235<S_CFG>local { YYD; return(CFG_LOCAL); } 236<S_CFG>none { YYD; return(CFG_NONE); } 237<S_CFG>radius { YYD; return(CFG_RADIUS); } 238<S_CFG>pam { YYD; return(CFG_PAM); } 239<S_CFG>pool_size { YYD; return(CFG_POOL_SIZE); } 240<S_CFG>banner { YYD; return(CFG_MOTD); } 241<S_CFG>auth_throttle { YYD; return(CFG_AUTH_THROTTLE); } 242<S_CFG>split_network { YYD; return(CFG_SPLIT_NETWORK); } 243<S_CFG>local_lan { YYD; return(CFG_SPLIT_LOCAL); } 244<S_CFG>include { YYD; return(CFG_SPLIT_INCLUDE); } 245<S_CFG>split_dns { YYD; return(CFG_SPLIT_DNS); } 246<S_CFG>pfs_group { YYD; return(CFG_PFS_GROUP); } 247<S_CFG>save_passwd { YYD; return(CFG_SAVE_PASSWD); } 248<S_CFG>{comma} { YYD; return(COMMA); } 249<S_CFG>{ecl} { BEGIN S_INI; return(EOC); } 250 251 /* timer */ 252<S_INI>timer { BEGIN S_RTRY; YYDB; return(RETRY); } 253<S_RTRY>{bcl} { return(BOC); } 254<S_RTRY>counter { YYD; return(RETRY_COUNTER); } 255<S_RTRY>interval { YYD; return(RETRY_INTERVAL); } 256<S_RTRY>persend { YYD; return(RETRY_PERSEND); } 257<S_RTRY>phase1 { YYD; return(RETRY_PHASE1); } 258<S_RTRY>phase2 { YYD; return(RETRY_PHASE2); } 259<S_RTRY>natt_keepalive { YYD; return(NATT_KA); } 260<S_RTRY>auto_exit_delay { YYD; return(AUTO_EXIT_DELAY); } 261<S_RTRY>{ecl} { BEGIN S_INI; return(EOC); } 262 263 /* sainfo */ 264<S_INI>sainfo { BEGIN S_SAINF; YYDB; return(SAINFO); } 265<S_SAINF>anonymous { YYD; return(ANONYMOUS); } 266<S_SAINF>{blcl}any{elcl} { YYD; return(PORTANY); } 267<S_SAINF>any { YYD; return(ANY); } 268<S_SAINF>from { YYD; return(FROM); } 269<S_SAINF>group { YYD; return(GROUP); } 270 /* sainfo spec */ 271<S_SAINF>{bcl} { BEGIN S_SAINFS; return(BOC); } 272<S_SAINF>{semi} { BEGIN S_INI; return(EOS); } 273<S_SAINFS>{ecl} { BEGIN S_INI; return(EOC); } 274<S_SAINFS>pfs_group { YYD; return(PFS_GROUP); } 275<S_SAINFS>remoteid { YYD; return(REMOTEID); } 276<S_SAINFS>identifier { YYD; racoon_yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); } 277<S_SAINFS>my_identifier { YYD; return(MY_IDENTIFIER); } 278<S_SAINFS>lifetime { YYD; return(LIFETIME); } 279<S_SAINFS>time { YYD; return(LIFETYPE_TIME); } 280<S_SAINFS>byte { YYD; return(LIFETYPE_BYTE); } 281<S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); } 282<S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); } 283<S_SAINFS>compression_algorithm { YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); } 284<S_SAINFS>{comma} { YYD; return(COMMA); } 285 286 /* remote */ 287<S_INI>remote { BEGIN S_RMT; YYDB; return(REMOTE); } 288<S_RMT>anonymous { YYD; return(ANONYMOUS); } 289<S_RMT>inherit { YYD; return(INHERIT); } 290 /* remote spec */ 291<S_RMT>{bcl} { BEGIN S_RMTS; return(BOC); } 292<S_RMTS>{ecl} { BEGIN S_INI; return(EOC); } 293<S_RMTS>exchange_mode { YYD; return(EXCHANGE_MODE); } 294<S_RMTS>{comma} { YYD; /* XXX ignored, but to be handled. */ ; } 295<S_RMTS>main { YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); } 296<S_RMTS>aggressive { YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); } 297<S_RMTS>doi { YYD; return(DOI); } 298<S_RMTS>ipsec_doi { YYD; yylval.num = IPSEC_DOI; return(DOITYPE); } 299<S_RMTS>situation { YYD; return(SITUATION); } 300<S_RMTS>ike_version { YYD; return(IKE_VERSION); } 301<S_RMTS>identity_only { YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); } 302<S_RMTS>secrecy { YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); } 303<S_RMTS>integrity { YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); } 304<S_RMTS>identifier { YYD; racoon_yywarn("it is obsoleted. use \"my_identifier\"."); return(IDENTIFIER); } 305<S_RMTS>my_identifier { YYD; return(MY_IDENTIFIER); } 306<S_RMTS>xauth_login { YYD; return(XAUTH_LOGIN); /* formerly identifier type login */ } 307<S_RMTS>peers_identifier { YYD; return(PEERS_IDENTIFIER); } 308<S_RMTS>verify_identifier { YYD; return(VERIFY_IDENTIFIER); } 309<S_RMTS>certificate_type { YYD; return(CERTIFICATE_TYPE); } 310<S_RMTS>ca_type { YYD; return(CA_TYPE); } 311<S_RMTS>x509 { YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); } 312<S_RMTS>plain_rsa { 313 racoon_yyerror("plainrsa not supported."); 314} 315<S_RMTS>open_dir_auth_group { 316#if HAVE_OPENDIR 317 YYD; 318 return(OPEN_DIR_AUTH_GROUP); 319#else 320 racoon_yyerror("Apple specific features not compiled in."); 321#endif 322} 323<S_RMTS>shared_secret { 324 YYD; 325 return(SHARED_SECRET); 326} 327<S_RMTS>in_keychain { 328 YYD; 329 return(IN_KEYCHAIN); 330} 331<S_RMTS>certificate_verification { 332 YYD; 333 return(CERTIFICATE_VERIFICATION); 334} 335<S_RMTS>peers_certfile { YYD; return(PEERS_CERTFILE); } 336<S_RMTS>dnssec { YYD; return(DNSSEC); } 337<S_RMTS>verify_cert { YYD; return(VERIFY_CERT); } 338<S_RMTS>send_cert { YYD; return(SEND_CERT); } 339<S_RMTS>send_cr { YYD; return(SEND_CR); } 340<S_RMTS>dh_group { YYD; return(DH_GROUP); } 341<S_RMTS>nonce_size { YYD; return(NONCE_SIZE); } 342<S_RMTS>generate_policy { YYD; return(GENERATE_POLICY); } 343<S_RMTS>support_mip6 { YYD; racoon_yywarn("it is obsoleted. use \"support_proxy\"."); return(SUPPORT_PROXY); } 344<S_RMTS>support_proxy { YYD; return(SUPPORT_PROXY); } 345<S_RMTS>initial_contact { YYD; return(INITIAL_CONTACT); } 346<S_RMTS>nat_traversal { YYD; return(NAT_TRAVERSAL); } 347<S_RMTS>force { YYD; yylval.num = NATT_FORCE; return(NAT_TRAVERSAL_LEVEL); } 348<S_RMTS>nat_traversal_multi_user { 349 YYD; 350 return(NAT_TRAVERSAL_MULTI_USER); 351} 352<S_RMTS>nat_traversal_keepalive { 353 YYD; 354 return(NAT_TRAVERSAL_KEEPALIVE); 355} 356<S_RMTS>proposal_check { YYD; return(PROPOSAL_CHECK); } 357<S_RMTS>obey { YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); } 358<S_RMTS>strict { YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); } 359<S_RMTS>exact { YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); } 360<S_RMTS>claim { YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); } 361<S_RMTS>keepalive { YYD; return(KEEPALIVE); } 362<S_RMTS>passive { YYD; return(PASSIVE); } 363<S_RMTS>lifetime { YYD; return(LIFETIME); } 364<S_RMTS>time { YYD; return(LIFETYPE_TIME); } 365<S_RMTS>byte { YYD; return(LIFETYPE_BYTE); } 366<S_RMTS>dpd { YYD; return(DPD); } 367<S_RMTS>dpd_delay { YYD; return(DPD_DELAY); } 368<S_RMTS>dpd_retry { YYD; return(DPD_RETRY); } 369<S_RMTS>dpd_maxfail { YYD; return(DPD_MAXFAIL); } 370<S_RMTS>dpd_algorithm { YYD; return(DPD_ALGORITHM); } 371<S_RMTS>disconnect_on_idle { YYD; return(DISCONNECT_ON_IDLE); } 372<S_RMTS>idle_timeout { YYD; return(IDLE_TIMEOUT); } 373<S_RMTS>idle_direction { YYD; return(IDLE_DIRECTION); } 374<S_RMTS>ike_frag { YYD; return(IKE_FRAG); } 375<S_RMTS>esp_frag { YYD; return(ESP_FRAG); } 376<S_RMTS>mode_cfg { YYD; return(MODE_CFG); } 377<S_RMTS>weak_phase1_check { YYD; return(WEAK_PHASE1_CHECK); } 378<S_RMTS>eap_types { YYD; return(EAP_TYPES); } 379<S_RMTS>eap_any { YYD; yylval.num = EAP_TYPE_NONE; return(EAP_TYPE); } 380<S_RMTS>eap_sim { YYD; yylval.num = EAP_TYPE_SIM; return(EAP_TYPE); } 381<S_RMTS>eap_aka { YYD; yylval.num = EAP_TYPE_AKA; return(EAP_TYPE); } 382<S_RMTS>eap_options { YYD; return(EAP_OPTIONS); } 383 /* remote proposal */ 384<S_RMTS>proposal { BEGIN S_RMTP; YYDB; return(PROPOSAL); } 385<S_RMTP>{bcl} { return(BOC); } 386<S_RMTP>{ecl} { BEGIN S_RMTS; return(EOC); } 387<S_RMTP>lifetime { YYD; return(LIFETIME); } 388<S_RMTP>time { YYD; return(LIFETYPE_TIME); } 389<S_RMTP>byte { YYD; return(LIFETYPE_BYTE); } 390<S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); } 391<S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); } 392<S_RMTP>hash_algorithm { YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); } 393<S_RMTP>prf_algorithm { YYD; yylval.num = algclass_ikev2_prf; return(ALGORITHM_CLASS); } 394<S_RMTP>integ_algorithm { YYD; yylval.num = algclass_ikev2_integ; return(ALGORITHM_CLASS); } 395<S_RMTP>dh_group { YYD; return(DH_GROUP); } 396<S_RMTP>gss_id { YYD; return(GSS_ID); } 397<S_RMTP>gssapi_id { YYD; return(GSS_ID); } /* for back compatibility */ 398 399 /* GSS ID encoding type (global) */ 400<S_INI>gss_id_enc { BEGIN S_GSSENC; YYDB; return(GSS_ID_ENC); } 401<S_GSSENC>latin1 { YYD; yylval.num = LC_GSSENC_LATIN1; 402 return(GSS_ID_ENCTYPE); } 403<S_GSSENC>utf-16le { YYD; yylval.num = LC_GSSENC_UTF16LE; 404 return(GSS_ID_ENCTYPE); } 405<S_GSSENC>{semi} { BEGIN S_INI; YYDB; return(EOS); } 406 407 /* parameter */ 408on { YYD; yylval.num = TRUE; return(SWITCH); } 409off { YYD; yylval.num = FALSE; return(SWITCH); } 410 411 /* prefix */ 412{slash}({digit}{1,3}) { 413 YYD; 414 yytext++; 415 yylval.num = atoi(yytext); 416 return(PREFIX); 417 } 418 419 /* port number */ 420{blcl}{decstring}{elcl} { 421 char *p = yytext; 422 YYD; 423 while (*++p != ']') ; 424 *p = 0; 425 yytext++; 426 yylval.num = atoi(yytext); 427 return(PORT); 428 } 429 430 /* address range */ 431{hyphen}{addrstring} { 432 YYD; 433 yytext++; 434 yylval.val = vmalloc(yyleng + 1); 435 if (yylval.val == NULL) { 436 racoon_yyerror("vmalloc failed"); 437 return -1; 438 } 439 memcpy(yylval.val->v, yytext, yylval.val->l); 440 return(ADDRRANGE); 441 } 442 443 /* upper protocol */ 444esp { YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); } 445ah { YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); } 446ipcomp { YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); } 447icmp { YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); } 448icmp6 { YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); } 449tcp { YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); } 450udp { YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); } 451 452 /* algorithm type */ 453des_iv64 { YYD; yylval.num = algtype_des_iv64; return(ALGORITHMTYPE); } 454des { YYD; yylval.num = algtype_des; return(ALGORITHMTYPE); } 4553des { YYD; yylval.num = algtype_3des; return(ALGORITHMTYPE); } 456rc5 { YYD; yylval.num = algtype_rc5; return(ALGORITHMTYPE); } 457idea { YYD; yylval.num = algtype_idea; return(ALGORITHMTYPE); } 458cast128 { YYD; yylval.num = algtype_cast128; return(ALGORITHMTYPE); } 459blowfish { YYD; yylval.num = algtype_blowfish; return(ALGORITHMTYPE); } 4603idea { YYD; yylval.num = algtype_3idea; return(ALGORITHMTYPE); } 461des_iv32 { YYD; yylval.num = algtype_des_iv32; return(ALGORITHMTYPE); } 462rc4 { YYD; yylval.num = algtype_rc4; return(ALGORITHMTYPE); } 463null_enc { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); } 464null { YYD; yylval.num = algtype_null_enc; return(ALGORITHMTYPE); } 465aes { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); } 466rijndael { YYD; yylval.num = algtype_aes; return(ALGORITHMTYPE); } 467twofish { YYD; yylval.num = algtype_twofish; return(ALGORITHMTYPE); } 468non_auth { YYD; yylval.num = algtype_non_auth; return(ALGORITHMTYPE); } 469hmac_md5 { YYD; yylval.num = algtype_hmac_md5_128; return(ALGORITHMTYPE); } 470hmac_sha1 { YYD; yylval.num = algtype_hmac_sha1_160; return(ALGORITHMTYPE); } 471hmac_sha2_256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); } 472hmac_sha256 { YYD; yylval.num = algtype_hmac_sha2_256; return(ALGORITHMTYPE); } 473hmac_sha2_384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); } 474hmac_sha384 { YYD; yylval.num = algtype_hmac_sha2_384; return(ALGORITHMTYPE); } 475hmac_sha2_512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); } 476hmac_sha512 { YYD; yylval.num = algtype_hmac_sha2_512; return(ALGORITHMTYPE); } 477hmac_md5_96 { YYD; yylval.num = algtype_hmac_md5_96; return(ALGORITHMTYPE); } 478hmac_sha1_96 { YYD; yylval.num = algtype_hmac_sha1_96; return(ALGORITHMTYPE); } 479des_mac { YYD; yylval.num = algtype_des_mac; return(ALGORITHMTYPE); } 480kpdk { YYD; yylval.num = algtype_kpdk; return(ALGORITHMTYPE); } 481md5 { YYD; yylval.num = algtype_md5; return(ALGORITHMTYPE); } 482sha1 { YYD; yylval.num = algtype_sha1; return(ALGORITHMTYPE); } 483tiger { YYD; yylval.num = algtype_tiger; return(ALGORITHMTYPE); } 484sha2_256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); } 485sha256 { YYD; yylval.num = algtype_sha2_256; return(ALGORITHMTYPE); } 486sha2_384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); } 487sha384 { YYD; yylval.num = algtype_sha2_384; return(ALGORITHMTYPE); } 488sha2_512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); } 489sha512 { YYD; yylval.num = algtype_sha2_512; return(ALGORITHMTYPE); } 490oui { YYD; yylval.num = algtype_oui; return(ALGORITHMTYPE); } 491deflate { YYD; yylval.num = algtype_deflate; return(ALGORITHMTYPE); } 492lzs { YYD; yylval.num = algtype_lzs; return(ALGORITHMTYPE); } 493modp768 { YYD; yylval.num = algtype_modp768; return(ALGORITHMTYPE); } 494modp1024 { YYD; yylval.num = algtype_modp1024; return(ALGORITHMTYPE); } 495modp1536 { YYD; yylval.num = algtype_modp1536; return(ALGORITHMTYPE); } 496ec2n155 { YYD; yylval.num = algtype_ec2n155; return(ALGORITHMTYPE); } 497ec2n185 { YYD; yylval.num = algtype_ec2n185; return(ALGORITHMTYPE); } 498modp2048 { YYD; yylval.num = algtype_modp2048; return(ALGORITHMTYPE); } 499modp3072 { YYD; yylval.num = algtype_modp3072; return(ALGORITHMTYPE); } 500modp4096 { YYD; yylval.num = algtype_modp4096; return(ALGORITHMTYPE); } 501modp6144 { YYD; yylval.num = algtype_modp6144; return(ALGORITHMTYPE); } 502modp8192 { YYD; yylval.num = algtype_modp8192; return(ALGORITHMTYPE); } 503pre_shared_key { YYD; yylval.num = algtype_psk; return(ALGORITHMTYPE); } 504rsasig { YYD; yylval.num = algtype_rsasig; return(ALGORITHMTYPE); } 505dsssig { YYD; yylval.num = algtype_dsssig; return(ALGORITHMTYPE); } 506rsaenc { YYD; yylval.num = algtype_rsaenc; return(ALGORITHMTYPE); } 507rsarev { YYD; yylval.num = algtype_rsarev; return(ALGORITHMTYPE); } 508gssapi_krb { YYD; yylval.num = algtype_gssapikrb; return(ALGORITHMTYPE); } 509hybrid_rsa_server { 510#ifdef ENABLE_HYBRID 511 YYD; yylval.num = algtype_hybrid_rsa_s; return(ALGORITHMTYPE); 512#else 513 racoon_yyerror("racoon not configured with --enable-hybrid"); 514#endif 515} 516hybrid_dss_server { 517#ifdef ENABLE_HYBRID 518 YYD; yylval.num = algtype_hybrid_dss_s; return(ALGORITHMTYPE); 519#else 520 racoon_yyerror("racoon not configured with --enable-hybrid"); 521#endif 522} 523hybrid_rsa_client { 524#ifdef ENABLE_HYBRID 525 YYD; yylval.num = algtype_hybrid_rsa_c; return(ALGORITHMTYPE); 526#else 527 racoon_yyerror("racoon not configured with --enable-hybrid"); 528#endif 529} 530hybrid_dss_client { 531#ifdef ENABLE_HYBRID 532 YYD; yylval.num = algtype_hybrid_dss_c; return(ALGORITHMTYPE); 533#else 534 racoon_yyerror("racoon not configured with --enable-hybrid"); 535#endif 536} 537 538xauth_psk_server { 539#ifdef ENABLE_HYBRID 540 YYD; yylval.num = algtype_xauth_psk_s; return(ALGORITHMTYPE); 541#else 542 racoon_yyerror("racoon not configured with --enable-hybrid"); 543#endif 544} 545xauth_psk_client { 546#ifdef ENABLE_HYBRID 547 YYD; yylval.num = algtype_xauth_psk_c; return(ALGORITHMTYPE); 548#else 549 racoon_yyerror("racoon not configured with --enable-hybrid"); 550#endif 551} 552xauth_rsa_server { 553#ifdef ENABLE_HYBRID 554 YYD; yylval.num = algtype_xauth_rsa_s; return(ALGORITHMTYPE); 555#else 556 racoon_yyerror("racoon not configured with --enable-hybrid"); 557#endif 558} 559xauth_rsa_client { 560#ifdef ENABLE_HYBRID 561 YYD; yylval.num = algtype_xauth_rsa_c; return(ALGORITHMTYPE); 562#else 563 racoon_yyerror("racoon not configured with --enable-hybrid"); 564#endif 565} 566eap_psk_client { 567 #ifdef ENABLE_HYBRID 568 YYD; yylval.num = algtype_eap_psk_c; return(ALGORITHMTYPE); 569 #else 570 racoon_yyerror("racoon not configured with --enable-hybrid"); 571 #endif 572} 573eap_rsa_client { 574 #ifdef ENABLE_HYBRID 575 YYD; yylval.num = algtype_eap_rsa_c; return(ALGORITHMTYPE); 576 #else 577 racoon_yyerror("racoon not configured with --enable-hybrid"); 578 #endif 579} 580 581 582 583 /* identifier type */ 584vendor_id { YYD; racoon_yywarn("it is obsoleted."); return(VENDORID); } 585user_fqdn { YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); } 586fqdn { YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); } 587keyid { YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); } 588keyid_use { 589 YYD; 590 yylval.num = IDTYPE_KEYIDUSE; 591 return(IDENTIFIERTYPE); 592} 593address { YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); } 594subnet { YYD; yylval.num = IDTYPE_SUBNET; return(IDENTIFIERTYPE); } 595asn1dn { YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); } 596certname { YYD; racoon_yywarn("certname will be obsoleted in near future."); yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); } 597 598 /* shared secret type */ 599use { 600 YYD; 601 yylval.num = SECRETTYPE_USE; 602 return(SECRETTYPE); 603} 604key { 605 YYD; 606 yylval.num = SECRETTYPE_KEY; 607 return(SECRETTYPE); 608} 609keychain { 610#if HAVE_KEYCHAIN 611 YYD; 612 yylval.num = SECRETTYPE_KEYCHAIN; 613 return(SECRETTYPE); 614#else 615 racoon_yyerror("Apple specific features not compiled in."); 616#endif 617} 618keychain_by_id { 619 YYD; 620 yylval.num = SECRETTYPE_KEYCHAIN_BY_ID; 621 return(SECRETTYPE); 622} 623 624 /* certificate verification */ 625openssl { 626 YYD; 627 yylval.num = VERIFICATION_MODULE_OPENSSL; 628 return(VERIFICATION_MODULE); 629} 630sec_framework { 631 YYD; 632 yylval.num = VERIFICATION_MODULE_SEC_FRAMEWORK; 633 return(VERIFICATION_MODULE); 634} 635use_open_dir { 636 YYD; 637 yylval.num = VERIFICATION_OPTION_OPEN_DIR; 638 return(VERIFICATION_OPTION); 639} 640use_peers_identifier { 641 YYD; 642 yylval.num = VERIFICATION_OPTION_PEERS_IDENTIFIER; 643 return(VERIFICATION_OPTION); 644} 645 646 /* identifier qualifier */ 647tag { YYD; yylval.num = IDQUAL_TAG; return(IDENTIFIERQUAL); } 648file { YYD; yylval.num = IDQUAL_FILE; return(IDENTIFIERQUAL); } 649 650 /* units */ 651B|byte|bytes { YYD; return(UNITTYPE_BYTE); } 652KB { YYD; return(UNITTYPE_KBYTES); } 653MB { YYD; return(UNITTYPE_MBYTES); } 654TB { YYD; return(UNITTYPE_TBYTES); } 655sec|secs|second|seconds { YYD; return(UNITTYPE_SEC); } 656min|mins|minute|minutes { YYD; return(UNITTYPE_MIN); } 657hour|hours { YYD; return(UNITTYPE_HOUR); } 658 659dpd_default { YYD; return(DPD_ALGO_TYPE_DEFAULT); } 660dpd_inbound_detect { YYD; return(DPD_ALGO_TYPE_INBOUND); } 661dpd_blackhole_detect { YYD; return(DPD_ALGO_TYPE_BLACKHOLE); } 662 663idle_any { YYD; return(IDLE_DIRECTION_ANY); } 664idle_inbound { YYD; return(IDLE_DIRECTION_IN); } 665idle_outbound { YYD; return(IDLE_DIRECTION_OUT); } 666 667 /* boolean */ 668yes { YYD; yylval.num = TRUE; return(BOOLEAN); } 669no { YYD; yylval.num = FALSE; return(BOOLEAN); } 670 671{decstring} { 672 char *bp; 673 674 YYD; 675 yylval.num = strtol(yytext, &bp, 10); 676 return(NUMBER); 677 } 678 679{hexstring} { 680 char *p; 681 682 YYD; 683 yylval.val = vmalloc(yyleng + (yyleng & 1) + 1); 684 if (yylval.val == NULL) { 685 racoon_yyerror("vmalloc failed"); 686 return -1; 687 } 688 689 p = yylval.val->v; 690 *p++ = '0'; 691 *p++ = 'x'; 692 693 /* fixed string if length is odd. */ 694 if (yyleng & 1) 695 *p++ = '0'; 696 memcpy(p, &yytext[2], yyleng - 1); 697 698 return(HEXSTRING); 699 } 700 701{quotedstring} { 702 char *p = yytext; 703 704 YYD; 705 while (*++p != '"') ; 706 *p = '\0'; 707 708 yylval.val = vmalloc(yyleng - 1); 709 if (yylval.val == NULL) { 710 racoon_yyerror("vmalloc failed"); 711 return -1; 712 } 713 memcpy(yylval.val->v, &yytext[1], yylval.val->l); 714 715 return(QUOTEDSTRING); 716 } 717 718{addrstring} { 719 YYD; 720 721 yylval.val = vmalloc(yyleng + 1); 722 if (yylval.val == NULL) { 723 racoon_yyerror("vmalloc failed"); 724 return -1; 725 } 726 memcpy(yylval.val->v, yytext, yylval.val->l); 727 728 return(ADDRSTRING); 729 } 730 731<<EOF>> { 732 yy_delete_buffer(YY_CURRENT_BUFFER); 733 incstackp--; 734 nextfile: 735 if (incstack[incstackp].matches.gl_pathc != 0 && 736 incstack[incstackp].matches.gl_pathv && 737 incstack[incstackp].matchon < 738 incstack[incstackp].matches.gl_pathc) { 739 char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon]; 740 incstack[incstackp].matchon++; 741 incstackp++; 742 if (yycf_set_buffer(filepath) != 0) { 743 incstackp--; 744 goto nextfile; 745 } 746 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE)); 747 BEGIN(S_INI); 748 } else { 749 globfree(&incstack[incstackp].matches); 750 if (incstackp == 0) 751 yyterminate(); 752 else 753 yy_switch_to_buffer(incstack[incstackp].prevstate); 754 } 755 } 756 757 /* ... */ 758{ws} { ; } 759{nl} { incstack[incstackp].lineno++; } 760{comment} { YYD; } 761{semi} { return(EOS); } 762. { yymore(); } 763 764%% 765 766void 767yyerror(const char *msg) 768{ 769 plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg); 770 yyerrorcount++; 771} 772 773void 774yywarn(const char *msg) 775{ 776 plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg); 777} 778 779void 780racoon_yyerror(const char *fmt, ...) 781{ 782 va_list ap; 783 char msg[512]; 784 785 va_start(ap, fmt); 786 vsnprintf(msg, sizeof(msg), fmt, ap); 787 va_end(ap); 788 789 yyerror(msg); 790} 791 792void 793racoon_yywarn(const char *fmt, ...) 794{ 795 va_list ap; 796 char msg[512]; 797 798 va_start(ap, fmt); 799 vsnprintf(msg, sizeof(msg), fmt, ap); 800 va_end(ap); 801 802 yywarn(msg); 803} 804 805int 806yycf_switch_buffer(path) 807 char *path; 808{ 809 char *filepath = NULL; 810 811 /* got the include file name */ 812 if (incstackp >= MAX_INCLUDE_DEPTH) { 813 plog(ASL_LEVEL_ERR, 814 "Includes nested too deeply"); 815 return -1; 816 } 817 818 if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 || 819 incstack[incstackp].matches.gl_pathc == 0) { 820 plog(ASL_LEVEL_WARNING, 821 "glob found no matches for path \"%s\"\n", path); 822 return 0; 823 } 824 incstack[incstackp].matchon = 0; 825 incstack[incstackp].prevstate = YY_CURRENT_BUFFER; 826 827 nextmatch: 828 if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc) 829 return -1; 830 filepath = 831 incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon]; 832 incstack[incstackp].matchon++; 833 incstackp++; 834 835 if (yycf_set_buffer(filepath) != 0) { 836 incstackp--; 837 goto nextmatch; 838 } 839 840 yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE)); 841 842 BEGIN(S_INI); 843 844 return 0; 845} 846 847int 848yycf_set_buffer(path) 849 char *path; 850{ 851 yyin = fopen(path, "r"); 852 if (yyin == NULL) { 853 fprintf(stderr, "failed to open file %s (%s)\n", 854 path, strerror(errno)); 855 plog(ASL_LEVEL_ERR, 856 "failed to open file %s (%s)\n", 857 path, strerror(errno)); 858 return -1; 859 } 860 861 /* initialize */ 862 if (incstack[incstackp].path != NULL) { 863 fclose(incstack[incstackp].fp); 864 racoon_free(incstack[incstackp].path); 865 } 866 incstack[incstackp].fp = yyin; 867 incstack[incstackp].path = racoon_strdup(path); 868 STRDUP_FATAL(incstack[incstackp].path); 869 incstack[incstackp].lineno = 1; 870 plog(ASL_LEVEL_DEBUG, 871 "reading configuration file %s\n", path); 872 873 return 0; 874} 875 876void 877yycf_init_buffer() 878{ 879 int i; 880 881 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) 882 memset(&incstack[i], 0, sizeof(incstack[i])); 883 incstackp = 0; 884} 885 886void 887yycf_clean_buffer() 888{ 889 int i; 890 891 for (i = 0; i < MAX_INCLUDE_DEPTH; i++) { 892 if (incstack[i].path != NULL) { 893 fclose(incstack[i].fp); 894 racoon_free(incstack[i].path); 895 incstack[i].path = NULL; 896 } 897 } 898} 899 900