1/*	$NetBSD: cftoken.l,v 1.11.4.1 2007/08/01 11:52:20 vanhu Exp $	*/
2
3/* Id: cftoken.l,v 1.53 2006/08/22 18:17:17 manubsd Exp */
4%option noyywrap
5%{
6/*
7 * Copyright (C) 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002 and 2003 WIDE Project.
8 * All rights reserved.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 *    notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 *    notice, this list of conditions and the following disclaimer in the
17 *    documentation and/or other materials provided with the distribution.
18 * 3. Neither the name of the project nor the names of its contributors
19 *    may be used to endorse or promote products derived from this software
20 *    without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 */
34
35#include "config.h"
36
37#include <sys/types.h>
38#include <sys/param.h>
39#include <sys/socket.h>
40
41#include <netinet/in.h>
42#ifdef HAVE_NETINET6_IPSEC
43#  include <netinet6/ipsec.h>
44#else
45#  include <netinet/ipsec.h>
46#endif
47
48#include <stdlib.h>
49#include <stdio.h>
50#include <string.h>
51#include <errno.h>
52#include <limits.h>
53#include <ctype.h>
54#include <glob.h>
55#ifdef HAVE_STDARG_H
56#include <stdarg.h>
57#else
58#include <varargs.h>
59#endif
60
61//%%% BUG FIX - 2 missing include files when not using
62// the bison files
63#ifdef HAVE_OPENSSL
64#include <openssl/bn.h>
65#include <openssl/rsa.h>
66#endif
67
68#include "var.h"
69#include "misc.h"
70#include "vmbuf.h"
71#include "plog.h"
72#include "debug.h"
73
74#include "algorithm.h"
75#include "cfparse_proto.h"
76#include "cftoken_proto.h"
77#include "localconf.h"
78#include "oakley.h"
79#include "isakmp_var.h"
80#include "isakmp.h"
81#include "ipsec_doi.h"
82#include "policy.h"
83#include "proposal.h"
84#include "remoteconf.h"
85#include "nattraversal.h"
86#ifdef GC
87#include "gcmalloc.h"
88#endif
89
90#include "y.tab.h"
91#include "eap_sim.h"
92
93int yyerrorcount = 0;
94
95#if defined(YIPS_DEBUG)
96#  define YYDB plog(ASL_LEVEL_DEBUG,                                \
97		"begin <%d>%s\n", yy_start, yytext);
98#  define YYD {                                                                \
99	plog(ASL_LEVEL_DEBUG, "<%d>%s",                             \
100	    yy_start, loglevel >= ASL_LEVEL_DEBUG ? "\n" : "");                     \
101}
102#else
103#  define YYDB
104#  define YYD
105#endif /* defined(YIPS_DEBUG) */
106
107#define MAX_INCLUDE_DEPTH 10
108
109static struct include_stack {
110	char *path;
111	FILE *fp;
112	YY_BUFFER_STATE prevstate;
113	int lineno;
114	glob_t matches;
115	int matchon;
116} incstack[MAX_INCLUDE_DEPTH];
117static int incstackp = 0;
118
119static int yy_first_time = 1;
120%}
121
122/* common section */
123nl		\n
124ws		[ \t]+
125digit		[0-9]
126letter		[A-Za-z]
127hexdigit	[0-9A-Fa-f]
128/*octet		(([01]?{digit}?{digit})|((2([0-4]{digit}))|(25[0-5]))) */
129special		[()+\|\?\*]
130comma		\,
131dot		\.
132slash		\/
133bcl		\{
134ecl		\}
135blcl		\[
136elcl		\]
137hyphen          \-
138percent		\%
139semi		\;
140comment		\#.*
141ccomment	"/*"
142bracketstring	\<[^>]*\>
143quotedstring	\"[^"]*\"
144addrstring	[a-fA-F0-9:]([a-fA-F0-9:\.]*|[a-fA-F0-9:\.]*%[a-zA-Z0-9]*)
145decstring	{digit}+
146hexstring	0x{hexdigit}+
147
148%s S_INI S_PRIV S_PTH S_INF S_LOG S_PAD S_LST S_RTRY S_CFG
149%s S_ALGST S_ALGCL
150%s S_SAINF S_SAINFS
151%s S_RMT S_RMTS S_RMTP
152%s S_SA
153%s S_GSSENC
154
155%%
156%{
157	if (yy_first_time) {
158		BEGIN S_INI;
159		yy_first_time = 0;
160	}
161%}
162
163
164	/* path */
165<S_INI>path		{ BEGIN S_PTH; YYDB; return(PATH); }
166<S_PTH>include		{ YYD; yylval.num = LC_PATHTYPE_INCLUDE;
167				return(PATHTYPE); }
168<S_PTH>pre_shared_key	{ YYD; yylval.num = LC_PATHTYPE_PSK;
169				return(PATHTYPE); }
170<S_PTH>certificate	{ YYD; yylval.num = LC_PATHTYPE_CERT;
171				return(PATHTYPE); }
172<S_PTH>pidfile		{ YYD; yylval.num = LC_PATHTYPE_PIDFILE;
173				return(PATHTYPE); }
174<S_PTH>logfile		{ YYD; yylval.num = LC_PATHTYPE_LOGFILE;
175				return(PATHTYPE); }
176<S_PTH>{semi}		{ BEGIN S_INI; YYDB; return(EOS); }
177
178	/* include */
179<S_INI>include		{ YYDB; return(INCLUDE); }
180
181	/* self information */
182<S_INI>identifier	{ BEGIN S_INF; YYDB; racoon_yywarn("it is obsoleted.  use \"my_identifier\" in each remote directives."); return(IDENTIFIER); }
183<S_INF>{semi}		{ BEGIN S_INI; return(EOS); }
184
185	/* special */
186<S_INI>complex_bundle	{ YYDB; return(COMPLEX_BUNDLE); }
187
188	/* logging */
189<S_INI>log		{ BEGIN S_LOG; YYDB; return(LOGGING); }
190<S_LOG>error		{ YYD; yylval.num = ASL_LEVEL_ERR; return(LOGLEV); }
191<S_LOG>warning		{ YYD; yylval.num = ASL_LEVEL_WARNING; return(LOGLEV); }
192<S_LOG>notify		{ YYD; yylval.num = ASL_LEVEL_NOTICE; return(LOGLEV); }
193<S_LOG>info		{ YYD; yylval.num = ASL_LEVEL_INFO; return(LOGLEV); }
194<S_LOG>debug		{ YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
195<S_LOG>debug2		{ YYD; yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
196<S_LOG>debug3		{ YYD; racoon_yywarn("it is obsoleted.  use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
197<S_LOG>debug4		{ YYD; racoon_yywarn("it is obsoleted.  use \"debug2\""); yylval.num = ASL_LEVEL_DEBUG; return(LOGLEV); }
198<S_LOG>{semi}		{ BEGIN S_INI; return(EOS); }
199
200	/* padding */
201<S_INI>padding		{ BEGIN S_PAD; YYDB; return(PADDING); }
202<S_PAD>{bcl}		{ return(BOC); }
203<S_PAD>randomize	{ YYD; return(PAD_RANDOMIZE); }
204<S_PAD>randomize_length	{ YYD; return(PAD_RANDOMIZELEN); }
205<S_PAD>maximum_length	{ YYD; return(PAD_MAXLEN); }
206<S_PAD>strict_check	{ YYD; return(PAD_STRICT); }
207<S_PAD>exclusive_tail	{ YYD; return(PAD_EXCLTAIL); }
208<S_PAD>{ecl}		{ BEGIN S_INI; return(EOC); }
209
210	/* listen */
211<S_INI>listen		{ BEGIN S_LST; YYDB; return(LISTEN); }
212<S_LST>{bcl}		{ return(BOC); }
213<S_LST>isakmp		{ YYD; return(X_ISAKMP); }
214<S_LST>isakmp_natt	{ YYD; return(X_ISAKMP_NATT); }
215<S_LST>admin		{ YYD; return(X_ADMIN); }
216<S_LST>adminsock	{ YYD; return(ADMINSOCK); }
217<S_LST>disabled		{ YYD; return(DISABLED); }
218<S_LST>strict_address	{ YYD; return(STRICT_ADDRESS); }
219<S_LST>{ecl}		{ BEGIN S_INI; return(EOC); }
220
221	/* mode_cfg */
222<S_INI>mode_cfg		{ BEGIN S_CFG; YYDB; return(MODECFG); }
223<S_CFG>{bcl}		{ return(BOC); }
224<S_CFG>network4		{ YYD; return(CFG_NET4); }
225<S_CFG>netmask4		{ YYD; return(CFG_MASK4); }
226<S_CFG>dns4		{ YYD; return(CFG_DNS4); }
227<S_CFG>wins4		{ YYD; return(CFG_NBNS4); }
228<S_CFG>default_domain	{ YYD; return(CFG_DEFAULT_DOMAIN); }
229<S_CFG>auth_source	{ YYD; return(CFG_AUTH_SOURCE); }
230<S_CFG>auth_groups	{ YYD; return(CFG_AUTH_GROUPS); }
231<S_CFG>group_source	{ YYD; return(CFG_GROUP_SOURCE); }
232<S_CFG>conf_source	{ YYD; return(CFG_CONF_SOURCE); }
233<S_CFG>accounting	{ YYD; return(CFG_ACCOUNTING); }
234<S_CFG>system		{ YYD; return(CFG_SYSTEM); }
235<S_CFG>local		{ YYD; return(CFG_LOCAL); }
236<S_CFG>none		{ YYD; return(CFG_NONE); }
237<S_CFG>radius		{ YYD; return(CFG_RADIUS); }
238<S_CFG>pam		{ YYD; return(CFG_PAM); }
239<S_CFG>pool_size	{ YYD; return(CFG_POOL_SIZE); }
240<S_CFG>banner		{ YYD; return(CFG_MOTD); }
241<S_CFG>auth_throttle	{ YYD; return(CFG_AUTH_THROTTLE); }
242<S_CFG>split_network	{ YYD; return(CFG_SPLIT_NETWORK); }
243<S_CFG>local_lan	{ YYD; return(CFG_SPLIT_LOCAL); }
244<S_CFG>include		{ YYD; return(CFG_SPLIT_INCLUDE); }
245<S_CFG>split_dns	{ YYD; return(CFG_SPLIT_DNS); }
246<S_CFG>pfs_group	{ YYD; return(CFG_PFS_GROUP); }
247<S_CFG>save_passwd	{ YYD; return(CFG_SAVE_PASSWD); }
248<S_CFG>{comma}		{ YYD; return(COMMA); }
249<S_CFG>{ecl}		{ BEGIN S_INI; return(EOC); }
250
251	/* timer */
252<S_INI>timer		{ BEGIN S_RTRY; YYDB; return(RETRY); }
253<S_RTRY>{bcl}		{ return(BOC); }
254<S_RTRY>counter		{ YYD; return(RETRY_COUNTER); }
255<S_RTRY>interval	{ YYD; return(RETRY_INTERVAL); }
256<S_RTRY>persend		{ YYD; return(RETRY_PERSEND); }
257<S_RTRY>phase1		{ YYD; return(RETRY_PHASE1); }
258<S_RTRY>phase2		{ YYD; return(RETRY_PHASE2); }
259<S_RTRY>natt_keepalive	{ YYD; return(NATT_KA); }
260<S_RTRY>auto_exit_delay	{ YYD; return(AUTO_EXIT_DELAY); }
261<S_RTRY>{ecl}		{ BEGIN S_INI; return(EOC); }
262
263	/* sainfo */
264<S_INI>sainfo		{ BEGIN S_SAINF; YYDB; return(SAINFO); }
265<S_SAINF>anonymous	{ YYD; return(ANONYMOUS); }
266<S_SAINF>{blcl}any{elcl}	{ YYD; return(PORTANY); }
267<S_SAINF>any		{ YYD; return(ANY); }
268<S_SAINF>from		{ YYD; return(FROM); }
269<S_SAINF>group		{ YYD; return(GROUP); }
270	/* sainfo spec */
271<S_SAINF>{bcl}		{ BEGIN S_SAINFS; return(BOC); }
272<S_SAINF>{semi}		{ BEGIN S_INI; return(EOS); }
273<S_SAINFS>{ecl}		{ BEGIN S_INI; return(EOC); }
274<S_SAINFS>pfs_group	{ YYD; return(PFS_GROUP); }
275<S_SAINFS>remoteid	{ YYD; return(REMOTEID); }
276<S_SAINFS>identifier	{ YYD; racoon_yywarn("it is obsoleted.  use \"my_identifier\"."); return(IDENTIFIER); }
277<S_SAINFS>my_identifier	{ YYD; return(MY_IDENTIFIER); }
278<S_SAINFS>lifetime	{ YYD; return(LIFETIME); }
279<S_SAINFS>time		{ YYD; return(LIFETYPE_TIME); }
280<S_SAINFS>byte		{ YYD; return(LIFETYPE_BYTE); }
281<S_SAINFS>encryption_algorithm { YYD; yylval.num = algclass_ipsec_enc; return(ALGORITHM_CLASS); }
282<S_SAINFS>authentication_algorithm { YYD; yylval.num = algclass_ipsec_auth; return(ALGORITHM_CLASS); }
283<S_SAINFS>compression_algorithm	{ YYD; yylval.num = algclass_ipsec_comp; return(ALGORITHM_CLASS); }
284<S_SAINFS>{comma}	{ YYD; return(COMMA); }
285
286	/* remote */
287<S_INI>remote		{ BEGIN S_RMT; YYDB; return(REMOTE); }
288<S_RMT>anonymous	{ YYD; return(ANONYMOUS); }
289<S_RMT>inherit		{ YYD; return(INHERIT); }
290	/* remote spec */
291<S_RMT>{bcl}		{ BEGIN S_RMTS; return(BOC); }
292<S_RMTS>{ecl}		{ BEGIN S_INI; return(EOC); }
293<S_RMTS>exchange_mode	{ YYD; return(EXCHANGE_MODE); }
294<S_RMTS>{comma}		{ YYD; /* XXX ignored, but to be handled. */ ; }
295<S_RMTS>main		{ YYD; yylval.num = ISAKMP_ETYPE_IDENT; return(EXCHANGETYPE); }
296<S_RMTS>aggressive	{ YYD; yylval.num = ISAKMP_ETYPE_AGG; return(EXCHANGETYPE); }
297<S_RMTS>doi		{ YYD; return(DOI); }
298<S_RMTS>ipsec_doi	{ YYD; yylval.num = IPSEC_DOI; return(DOITYPE); }
299<S_RMTS>situation	{ YYD; return(SITUATION); }
300<S_RMTS>ike_version	{ YYD; return(IKE_VERSION); }
301<S_RMTS>identity_only	{ YYD; yylval.num = IPSECDOI_SIT_IDENTITY_ONLY; return(SITUATIONTYPE); }
302<S_RMTS>secrecy		{ YYD; yylval.num = IPSECDOI_SIT_SECRECY; return(SITUATIONTYPE); }
303<S_RMTS>integrity	{ YYD; yylval.num = IPSECDOI_SIT_INTEGRITY; return(SITUATIONTYPE); }
304<S_RMTS>identifier	{ YYD; racoon_yywarn("it is obsoleted.  use \"my_identifier\"."); return(IDENTIFIER); }
305<S_RMTS>my_identifier	{ YYD; return(MY_IDENTIFIER); }
306<S_RMTS>xauth_login	{ YYD; return(XAUTH_LOGIN); /* formerly identifier type login */ }
307<S_RMTS>peers_identifier	{ YYD; return(PEERS_IDENTIFIER); }
308<S_RMTS>verify_identifier	{ YYD; return(VERIFY_IDENTIFIER); }
309<S_RMTS>certificate_type	{ YYD; return(CERTIFICATE_TYPE); }
310<S_RMTS>ca_type		{ YYD; return(CA_TYPE); }
311<S_RMTS>x509		{ YYD; yylval.num = ISAKMP_CERT_X509SIGN; return(CERT_X509); }
312<S_RMTS>plain_rsa	{
313	racoon_yyerror("plainrsa not supported.");
314}
315<S_RMTS>open_dir_auth_group	{
316#if HAVE_OPENDIR
317	YYD;
318	return(OPEN_DIR_AUTH_GROUP);
319#else
320	racoon_yyerror("Apple specific features not compiled in.");
321#endif
322}
323<S_RMTS>shared_secret {
324	YYD;
325	return(SHARED_SECRET);
326}
327<S_RMTS>in_keychain {
328	YYD;
329	return(IN_KEYCHAIN);
330}
331<S_RMTS>certificate_verification {
332	YYD;
333	return(CERTIFICATE_VERIFICATION);
334}
335<S_RMTS>peers_certfile	{ YYD; return(PEERS_CERTFILE); }
336<S_RMTS>dnssec		{ YYD; return(DNSSEC); }
337<S_RMTS>verify_cert	{ YYD; return(VERIFY_CERT); }
338<S_RMTS>send_cert	{ YYD; return(SEND_CERT); }
339<S_RMTS>send_cr		{ YYD; return(SEND_CR); }
340<S_RMTS>dh_group	{ YYD; return(DH_GROUP); }
341<S_RMTS>nonce_size	{ YYD; return(NONCE_SIZE); }
342<S_RMTS>generate_policy	{ YYD; return(GENERATE_POLICY); }
343<S_RMTS>support_mip6	{ YYD; racoon_yywarn("it is obsoleted.  use \"support_proxy\"."); return(SUPPORT_PROXY); }
344<S_RMTS>support_proxy	{ YYD; return(SUPPORT_PROXY); }
345<S_RMTS>initial_contact	{ YYD; return(INITIAL_CONTACT); }
346<S_RMTS>nat_traversal	{ YYD; return(NAT_TRAVERSAL); }
347<S_RMTS>force		{ YYD; yylval.num = NATT_FORCE; return(NAT_TRAVERSAL_LEVEL); }
348<S_RMTS>nat_traversal_multi_user {
349	YYD;
350	return(NAT_TRAVERSAL_MULTI_USER);
351}
352<S_RMTS>nat_traversal_keepalive {
353	YYD;
354	return(NAT_TRAVERSAL_KEEPALIVE);
355}
356<S_RMTS>proposal_check	{ YYD; return(PROPOSAL_CHECK); }
357<S_RMTS>obey		{ YYD; yylval.num = PROP_CHECK_OBEY; return(PROPOSAL_CHECK_LEVEL); }
358<S_RMTS>strict		{ YYD; yylval.num = PROP_CHECK_STRICT; return(PROPOSAL_CHECK_LEVEL); }
359<S_RMTS>exact		{ YYD; yylval.num = PROP_CHECK_EXACT; return(PROPOSAL_CHECK_LEVEL); }
360<S_RMTS>claim		{ YYD; yylval.num = PROP_CHECK_CLAIM; return(PROPOSAL_CHECK_LEVEL); }
361<S_RMTS>keepalive	{ YYD; return(KEEPALIVE); }
362<S_RMTS>passive		{ YYD; return(PASSIVE); }
363<S_RMTS>lifetime	{ YYD; return(LIFETIME); }
364<S_RMTS>time		{ YYD; return(LIFETYPE_TIME); }
365<S_RMTS>byte		{ YYD; return(LIFETYPE_BYTE); }
366<S_RMTS>dpd			{ YYD; return(DPD); }
367<S_RMTS>dpd_delay	{ YYD; return(DPD_DELAY); }
368<S_RMTS>dpd_retry	{ YYD; return(DPD_RETRY); }
369<S_RMTS>dpd_maxfail	{ YYD; return(DPD_MAXFAIL); }
370<S_RMTS>dpd_algorithm	{ YYD; return(DPD_ALGORITHM); }
371<S_RMTS>disconnect_on_idle { YYD; return(DISCONNECT_ON_IDLE); }
372<S_RMTS>idle_timeout { YYD; return(IDLE_TIMEOUT); }
373<S_RMTS>idle_direction { YYD; return(IDLE_DIRECTION); }
374<S_RMTS>ike_frag	{ YYD; return(IKE_FRAG); }
375<S_RMTS>esp_frag	{ YYD; return(ESP_FRAG); }
376<S_RMTS>mode_cfg	{ YYD; return(MODE_CFG); }
377<S_RMTS>weak_phase1_check { YYD; return(WEAK_PHASE1_CHECK); }
378<S_RMTS>eap_types	{ YYD; return(EAP_TYPES); }
379<S_RMTS>eap_any     { YYD; yylval.num = EAP_TYPE_NONE; return(EAP_TYPE); }
380<S_RMTS>eap_sim     { YYD; yylval.num = EAP_TYPE_SIM; return(EAP_TYPE); }
381<S_RMTS>eap_aka     { YYD; yylval.num = EAP_TYPE_AKA; return(EAP_TYPE); }
382<S_RMTS>eap_options	{ YYD; return(EAP_OPTIONS); }
383	/* remote proposal */
384<S_RMTS>proposal	{ BEGIN S_RMTP; YYDB; return(PROPOSAL); }
385<S_RMTP>{bcl}		{ return(BOC); }
386<S_RMTP>{ecl}		{ BEGIN S_RMTS; return(EOC); }
387<S_RMTP>lifetime	{ YYD; return(LIFETIME); }
388<S_RMTP>time		{ YYD; return(LIFETYPE_TIME); }
389<S_RMTP>byte		{ YYD; return(LIFETYPE_BYTE); }
390<S_RMTP>encryption_algorithm { YYD; yylval.num = algclass_isakmp_enc; return(ALGORITHM_CLASS); }
391<S_RMTP>authentication_method { YYD; yylval.num = algclass_isakmp_ameth; return(ALGORITHM_CLASS); }
392<S_RMTP>hash_algorithm	{ YYD; yylval.num = algclass_isakmp_hash; return(ALGORITHM_CLASS); }
393<S_RMTP>prf_algorithm	{ YYD; yylval.num = algclass_ikev2_prf; return(ALGORITHM_CLASS); }
394<S_RMTP>integ_algorithm	{ YYD; yylval.num = algclass_ikev2_integ; return(ALGORITHM_CLASS); }
395<S_RMTP>dh_group	{ YYD; return(DH_GROUP); }
396<S_RMTP>gss_id		{ YYD; return(GSS_ID); }
397<S_RMTP>gssapi_id	{ YYD; return(GSS_ID); } /* for back compatibility */
398
399	/* GSS ID encoding type (global) */
400<S_INI>gss_id_enc	{ BEGIN S_GSSENC; YYDB; return(GSS_ID_ENC); }
401<S_GSSENC>latin1	{ YYD; yylval.num = LC_GSSENC_LATIN1;
402				return(GSS_ID_ENCTYPE); }
403<S_GSSENC>utf-16le	{ YYD; yylval.num = LC_GSSENC_UTF16LE;
404				return(GSS_ID_ENCTYPE); }
405<S_GSSENC>{semi}	{ BEGIN S_INI; YYDB; return(EOS); }
406
407	/* parameter */
408on		{ YYD; yylval.num = TRUE; return(SWITCH); }
409off		{ YYD; yylval.num = FALSE; return(SWITCH); }
410
411	/* prefix */
412{slash}({digit}{1,3}) {
413			YYD;
414			yytext++;
415			yylval.num = atoi(yytext);
416			return(PREFIX);
417		}
418
419	/* port number */
420{blcl}{decstring}{elcl}	{
421			char *p = yytext;
422			YYD;
423			while (*++p != ']') ;
424			*p = 0;
425			yytext++;
426			yylval.num = atoi(yytext);
427			return(PORT);
428		}
429
430	/* address range */
431{hyphen}{addrstring} {
432                        YYD;
433                        yytext++;
434			yylval.val = vmalloc(yyleng + 1);
435			if (yylval.val == NULL) {
436				racoon_yyerror("vmalloc failed");
437				return -1;
438			}
439			memcpy(yylval.val->v, yytext, yylval.val->l);
440                        return(ADDRRANGE);
441                }
442
443	/* upper protocol */
444esp		{ YYD; yylval.num = IPPROTO_ESP; return(UL_PROTO); }
445ah		{ YYD; yylval.num = IPPROTO_AH; return(UL_PROTO); }
446ipcomp		{ YYD; yylval.num = IPPROTO_IPCOMP; return(UL_PROTO); }
447icmp		{ YYD; yylval.num = IPPROTO_ICMP; return(UL_PROTO); }
448icmp6		{ YYD; yylval.num = IPPROTO_ICMPV6; return(UL_PROTO); }
449tcp		{ YYD; yylval.num = IPPROTO_TCP; return(UL_PROTO); }
450udp		{ YYD; yylval.num = IPPROTO_UDP; return(UL_PROTO); }
451
452	/* algorithm type */
453des_iv64	{ YYD; yylval.num = algtype_des_iv64;	return(ALGORITHMTYPE); }
454des		{ YYD; yylval.num = algtype_des;	return(ALGORITHMTYPE); }
4553des		{ YYD; yylval.num = algtype_3des;	return(ALGORITHMTYPE); }
456rc5		{ YYD; yylval.num = algtype_rc5;	return(ALGORITHMTYPE); }
457idea 		{ YYD; yylval.num = algtype_idea;	return(ALGORITHMTYPE); }
458cast128		{ YYD; yylval.num = algtype_cast128;	return(ALGORITHMTYPE); }
459blowfish	{ YYD; yylval.num = algtype_blowfish;	return(ALGORITHMTYPE); }
4603idea		{ YYD; yylval.num = algtype_3idea;	return(ALGORITHMTYPE); }
461des_iv32	{ YYD; yylval.num = algtype_des_iv32;	return(ALGORITHMTYPE); }
462rc4 		{ YYD; yylval.num = algtype_rc4;	return(ALGORITHMTYPE); }
463null_enc	{ YYD; yylval.num = algtype_null_enc;	return(ALGORITHMTYPE); }
464null		{ YYD; yylval.num = algtype_null_enc;	return(ALGORITHMTYPE); }
465aes		{ YYD; yylval.num = algtype_aes;	return(ALGORITHMTYPE); }
466rijndael	{ YYD; yylval.num = algtype_aes;	return(ALGORITHMTYPE); }
467twofish		{ YYD; yylval.num = algtype_twofish;	return(ALGORITHMTYPE); }
468non_auth	{ YYD; yylval.num = algtype_non_auth;	return(ALGORITHMTYPE); }
469hmac_md5	{ YYD; yylval.num = algtype_hmac_md5_128;	return(ALGORITHMTYPE); }
470hmac_sha1	{ YYD; yylval.num = algtype_hmac_sha1_160;	return(ALGORITHMTYPE); }
471hmac_sha2_256	{ YYD; yylval.num = algtype_hmac_sha2_256;	return(ALGORITHMTYPE); }
472hmac_sha256	{ YYD; yylval.num = algtype_hmac_sha2_256;	return(ALGORITHMTYPE); }
473hmac_sha2_384	{ YYD; yylval.num = algtype_hmac_sha2_384;	return(ALGORITHMTYPE); }
474hmac_sha384	{ YYD; yylval.num = algtype_hmac_sha2_384;	return(ALGORITHMTYPE); }
475hmac_sha2_512	{ YYD; yylval.num = algtype_hmac_sha2_512;	return(ALGORITHMTYPE); }
476hmac_sha512	{ YYD; yylval.num = algtype_hmac_sha2_512;	return(ALGORITHMTYPE); }
477hmac_md5_96	{ YYD; yylval.num = algtype_hmac_md5_96;	return(ALGORITHMTYPE); }
478hmac_sha1_96	{ YYD; yylval.num = algtype_hmac_sha1_96;	return(ALGORITHMTYPE); }
479des_mac		{ YYD; yylval.num = algtype_des_mac;	return(ALGORITHMTYPE); }
480kpdk		{ YYD; yylval.num = algtype_kpdk;	return(ALGORITHMTYPE); }
481md5		{ YYD; yylval.num = algtype_md5;	return(ALGORITHMTYPE); }
482sha1		{ YYD; yylval.num = algtype_sha1;	return(ALGORITHMTYPE); }
483tiger		{ YYD; yylval.num = algtype_tiger;	return(ALGORITHMTYPE); }
484sha2_256	{ YYD; yylval.num = algtype_sha2_256;	return(ALGORITHMTYPE); }
485sha256		{ YYD; yylval.num = algtype_sha2_256;	return(ALGORITHMTYPE); }
486sha2_384	{ YYD; yylval.num = algtype_sha2_384;	return(ALGORITHMTYPE); }
487sha384		{ YYD; yylval.num = algtype_sha2_384;	return(ALGORITHMTYPE); }
488sha2_512	{ YYD; yylval.num = algtype_sha2_512;	return(ALGORITHMTYPE); }
489sha512		{ YYD; yylval.num = algtype_sha2_512;	return(ALGORITHMTYPE); }
490oui		{ YYD; yylval.num = algtype_oui;	return(ALGORITHMTYPE); }
491deflate		{ YYD; yylval.num = algtype_deflate;	return(ALGORITHMTYPE); }
492lzs		{ YYD; yylval.num = algtype_lzs;	return(ALGORITHMTYPE); }
493modp768		{ YYD; yylval.num = algtype_modp768;	return(ALGORITHMTYPE); }
494modp1024	{ YYD; yylval.num = algtype_modp1024;	return(ALGORITHMTYPE); }
495modp1536	{ YYD; yylval.num = algtype_modp1536;	return(ALGORITHMTYPE); }
496ec2n155		{ YYD; yylval.num = algtype_ec2n155;	return(ALGORITHMTYPE); }
497ec2n185		{ YYD; yylval.num = algtype_ec2n185;	return(ALGORITHMTYPE); }
498modp2048	{ YYD; yylval.num = algtype_modp2048;	return(ALGORITHMTYPE); }
499modp3072	{ YYD; yylval.num = algtype_modp3072;	return(ALGORITHMTYPE); }
500modp4096	{ YYD; yylval.num = algtype_modp4096;	return(ALGORITHMTYPE); }
501modp6144	{ YYD; yylval.num = algtype_modp6144;	return(ALGORITHMTYPE); }
502modp8192	{ YYD; yylval.num = algtype_modp8192;	return(ALGORITHMTYPE); }
503pre_shared_key	{ YYD; yylval.num = algtype_psk;	return(ALGORITHMTYPE); }
504rsasig		{ YYD; yylval.num = algtype_rsasig;	return(ALGORITHMTYPE); }
505dsssig		{ YYD; yylval.num = algtype_dsssig;	return(ALGORITHMTYPE); }
506rsaenc		{ YYD; yylval.num = algtype_rsaenc;	return(ALGORITHMTYPE); }
507rsarev		{ YYD; yylval.num = algtype_rsarev;	return(ALGORITHMTYPE); }
508gssapi_krb	{ YYD; yylval.num = algtype_gssapikrb;	return(ALGORITHMTYPE); }
509hybrid_rsa_server {
510#ifdef ENABLE_HYBRID
511	YYD; yylval.num = algtype_hybrid_rsa_s; return(ALGORITHMTYPE);
512#else
513	racoon_yyerror("racoon not configured with --enable-hybrid");
514#endif
515}
516hybrid_dss_server {
517#ifdef ENABLE_HYBRID
518	YYD; yylval.num = algtype_hybrid_dss_s; return(ALGORITHMTYPE);
519#else
520	racoon_yyerror("racoon not configured with --enable-hybrid");
521#endif
522}
523hybrid_rsa_client {
524#ifdef ENABLE_HYBRID
525	YYD; yylval.num = algtype_hybrid_rsa_c; return(ALGORITHMTYPE);
526#else
527	racoon_yyerror("racoon not configured with --enable-hybrid");
528#endif
529}
530hybrid_dss_client {
531#ifdef ENABLE_HYBRID
532	YYD; yylval.num = algtype_hybrid_dss_c; return(ALGORITHMTYPE);
533#else
534	racoon_yyerror("racoon not configured with --enable-hybrid");
535#endif
536}
537
538xauth_psk_server {
539#ifdef ENABLE_HYBRID
540	YYD; yylval.num = algtype_xauth_psk_s; return(ALGORITHMTYPE);
541#else
542	racoon_yyerror("racoon not configured with --enable-hybrid");
543#endif
544}
545xauth_psk_client {
546#ifdef ENABLE_HYBRID
547	YYD; yylval.num = algtype_xauth_psk_c; return(ALGORITHMTYPE);
548#else
549	racoon_yyerror("racoon not configured with --enable-hybrid");
550#endif
551}
552xauth_rsa_server {
553#ifdef ENABLE_HYBRID
554	YYD; yylval.num = algtype_xauth_rsa_s; return(ALGORITHMTYPE);
555#else
556	racoon_yyerror("racoon not configured with --enable-hybrid");
557#endif
558}
559xauth_rsa_client {
560#ifdef ENABLE_HYBRID
561	YYD; yylval.num = algtype_xauth_rsa_c; return(ALGORITHMTYPE);
562#else
563	racoon_yyerror("racoon not configured with --enable-hybrid");
564#endif
565}
566eap_psk_client {
567    #ifdef ENABLE_HYBRID
568	YYD; yylval.num = algtype_eap_psk_c; return(ALGORITHMTYPE);
569    #else
570	racoon_yyerror("racoon not configured with --enable-hybrid");
571    #endif
572}
573eap_rsa_client {
574    #ifdef ENABLE_HYBRID
575	YYD; yylval.num = algtype_eap_rsa_c; return(ALGORITHMTYPE);
576    #else
577	racoon_yyerror("racoon not configured with --enable-hybrid");
578    #endif
579}
580
581
582
583	/* identifier type */
584vendor_id	{ YYD; racoon_yywarn("it is obsoleted."); return(VENDORID); }
585user_fqdn	{ YYD; yylval.num = IDTYPE_USERFQDN; return(IDENTIFIERTYPE); }
586fqdn		{ YYD; yylval.num = IDTYPE_FQDN; return(IDENTIFIERTYPE); }
587keyid		{ YYD; yylval.num = IDTYPE_KEYID; return(IDENTIFIERTYPE); }
588keyid_use	{
589	YYD;
590	yylval.num = IDTYPE_KEYIDUSE;
591	return(IDENTIFIERTYPE);
592}
593address		{ YYD; yylval.num = IDTYPE_ADDRESS; return(IDENTIFIERTYPE); }
594subnet		{ YYD; yylval.num = IDTYPE_SUBNET; return(IDENTIFIERTYPE); }
595asn1dn		{ YYD; yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
596certname	{ YYD; racoon_yywarn("certname will be obsoleted in near future."); yylval.num = IDTYPE_ASN1DN; return(IDENTIFIERTYPE); }
597
598	/* shared secret type */
599use		{
600	YYD;
601	yylval.num = SECRETTYPE_USE;
602	return(SECRETTYPE);
603}
604key		{
605	YYD;
606	yylval.num = SECRETTYPE_KEY;
607	return(SECRETTYPE);
608}
609keychain	{
610#if HAVE_KEYCHAIN
611	YYD;
612	yylval.num = SECRETTYPE_KEYCHAIN;
613	return(SECRETTYPE);
614#else
615	racoon_yyerror("Apple specific features not compiled in.");
616#endif
617}
618keychain_by_id	{
619	YYD;
620	yylval.num = SECRETTYPE_KEYCHAIN_BY_ID;
621	return(SECRETTYPE);
622}
623
624	/* certificate verification */
625openssl			{
626	YYD;
627	yylval.num = VERIFICATION_MODULE_OPENSSL;
628	return(VERIFICATION_MODULE);
629}
630sec_framework	{
631	YYD;
632	yylval.num = VERIFICATION_MODULE_SEC_FRAMEWORK;
633	return(VERIFICATION_MODULE);
634}
635use_open_dir	{
636	YYD;
637	yylval.num = VERIFICATION_OPTION_OPEN_DIR;
638	return(VERIFICATION_OPTION);
639}
640use_peers_identifier	{
641	YYD;
642	yylval.num = VERIFICATION_OPTION_PEERS_IDENTIFIER;
643	return(VERIFICATION_OPTION);
644}
645
646	/* identifier qualifier */
647tag		{ YYD; yylval.num = IDQUAL_TAG;  return(IDENTIFIERQUAL); }
648file		{ YYD; yylval.num = IDQUAL_FILE; return(IDENTIFIERQUAL); }
649
650	/* units */
651B|byte|bytes		{ YYD; return(UNITTYPE_BYTE); }
652KB			{ YYD; return(UNITTYPE_KBYTES); }
653MB			{ YYD; return(UNITTYPE_MBYTES); }
654TB			{ YYD; return(UNITTYPE_TBYTES); }
655sec|secs|second|seconds	{ YYD; return(UNITTYPE_SEC); }
656min|mins|minute|minutes	{ YYD; return(UNITTYPE_MIN); }
657hour|hours		{ YYD; return(UNITTYPE_HOUR); }
658
659dpd_default             { YYD; return(DPD_ALGO_TYPE_DEFAULT); }
660dpd_inbound_detect      { YYD; return(DPD_ALGO_TYPE_INBOUND); }
661dpd_blackhole_detect    { YYD; return(DPD_ALGO_TYPE_BLACKHOLE); }
662
663idle_any                { YYD; return(IDLE_DIRECTION_ANY); }
664idle_inbound            { YYD; return(IDLE_DIRECTION_IN); }
665idle_outbound           { YYD; return(IDLE_DIRECTION_OUT); }
666
667	/* boolean */
668yes		{ YYD; yylval.num = TRUE; return(BOOLEAN); }
669no		{ YYD; yylval.num = FALSE; return(BOOLEAN); }
670
671{decstring}	{
672			char *bp;
673
674			YYD;
675			yylval.num = strtol(yytext, &bp, 10);
676			return(NUMBER);
677		}
678
679{hexstring}	{
680			char *p;
681
682			YYD;
683			yylval.val = vmalloc(yyleng + (yyleng & 1) + 1);
684			if (yylval.val == NULL) {
685				racoon_yyerror("vmalloc failed");
686				return -1;
687			}
688
689			p = yylval.val->v;
690			*p++ = '0';
691			*p++ = 'x';
692
693			/* fixed string if length is odd. */
694			if (yyleng & 1)
695				*p++ = '0';
696			memcpy(p, &yytext[2], yyleng - 1);
697
698			return(HEXSTRING);
699		}
700
701{quotedstring}	{
702			char *p = yytext;
703
704			YYD;
705			while (*++p != '"') ;
706			*p = '\0';
707
708			yylval.val = vmalloc(yyleng - 1);
709			if (yylval.val == NULL) {
710				racoon_yyerror("vmalloc failed");
711				return -1;
712			}
713			memcpy(yylval.val->v, &yytext[1], yylval.val->l);
714
715			return(QUOTEDSTRING);
716		}
717
718{addrstring}	{
719			YYD;
720
721			yylval.val = vmalloc(yyleng + 1);
722			if (yylval.val == NULL) {
723				racoon_yyerror("vmalloc failed");
724				return -1;
725			}
726			memcpy(yylval.val->v, yytext, yylval.val->l);
727
728			return(ADDRSTRING);
729		}
730
731<<EOF>>		{
732			yy_delete_buffer(YY_CURRENT_BUFFER);
733			incstackp--;
734    nextfile:
735			if (incstack[incstackp].matches.gl_pathc != 0 &&
736				incstack[incstackp].matches.gl_pathv &&
737				incstack[incstackp].matchon <
738			    incstack[incstackp].matches.gl_pathc) {
739				char* filepath = incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
740				incstack[incstackp].matchon++;
741				incstackp++;
742				if (yycf_set_buffer(filepath) != 0) {
743					incstackp--;
744					goto nextfile;
745				}
746				yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
747				BEGIN(S_INI);
748			} else {
749				globfree(&incstack[incstackp].matches);
750				if (incstackp == 0)
751					yyterminate();
752				else
753					yy_switch_to_buffer(incstack[incstackp].prevstate);
754			}
755		}
756
757	/* ... */
758{ws}		{ ; }
759{nl}		{ incstack[incstackp].lineno++; }
760{comment}	{ YYD; }
761{semi}		{ return(EOS); }
762.		{ yymore(); }
763
764%%
765
766void
767yyerror(const char *msg)
768{
769    plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg);
770	yyerrorcount++;
771}
772
773void
774yywarn(const char *msg)
775{
776	 plog(ASL_LEVEL_ERR, "%s:%d: %s\n", incstack[incstackp].path, incstack[incstackp].lineno, msg);
777}
778
779void
780racoon_yyerror(const char *fmt, ...)
781{
782    va_list ap;
783    char msg[512];
784
785    va_start(ap, fmt);
786    vsnprintf(msg, sizeof(msg), fmt, ap);
787    va_end(ap);
788
789    yyerror(msg);
790}
791
792void
793racoon_yywarn(const char *fmt, ...)
794{
795    va_list ap;
796	char msg[512];
797
798    va_start(ap, fmt);
799    vsnprintf(msg, sizeof(msg), fmt, ap);
800    va_end(ap);
801
802    yywarn(msg);
803}
804
805int
806yycf_switch_buffer(path)
807	char *path;
808{
809	char *filepath = NULL;
810
811	/* got the include file name */
812	if (incstackp >= MAX_INCLUDE_DEPTH) {
813		plog(ASL_LEVEL_ERR,
814			"Includes nested too deeply");
815		return -1;
816	}
817
818	if (glob(path, GLOB_TILDE, NULL, &incstack[incstackp].matches) != 0 ||
819	    incstack[incstackp].matches.gl_pathc == 0) {
820		plog(ASL_LEVEL_WARNING,
821			"glob found no matches for path \"%s\"\n", path);
822		return 0;
823	}
824	incstack[incstackp].matchon = 0;
825	incstack[incstackp].prevstate = YY_CURRENT_BUFFER;
826
827    nextmatch:
828	if (incstack[incstackp].matchon >= incstack[incstackp].matches.gl_pathc)
829		return -1;
830	filepath =
831	    incstack[incstackp].matches.gl_pathv[incstack[incstackp].matchon];
832	incstack[incstackp].matchon++;
833	incstackp++;
834
835	if (yycf_set_buffer(filepath) != 0) {
836	      incstackp--;
837	      goto nextmatch;
838	}
839
840	yy_switch_to_buffer(yy_create_buffer(yyin, YY_BUF_SIZE));
841
842	BEGIN(S_INI);
843
844	return 0;
845}
846
847int
848yycf_set_buffer(path)
849	char *path;
850{
851	yyin = fopen(path, "r");
852	if (yyin == NULL) {
853		fprintf(stderr, "failed to open file %s (%s)\n",
854			path, strerror(errno));
855		plog(ASL_LEVEL_ERR,
856			"failed to open file %s (%s)\n",
857			path, strerror(errno));
858		return -1;
859	}
860
861	/* initialize */
862	if (incstack[incstackp].path != NULL) {
863		fclose(incstack[incstackp].fp);
864		racoon_free(incstack[incstackp].path);
865	}
866	incstack[incstackp].fp = yyin;
867	incstack[incstackp].path = racoon_strdup(path);
868	STRDUP_FATAL(incstack[incstackp].path);
869	incstack[incstackp].lineno = 1;
870	plog(ASL_LEVEL_DEBUG,
871		"reading configuration file %s\n", path);
872
873	return 0;
874}
875
876void
877yycf_init_buffer()
878{
879	int i;
880
881	for (i = 0; i < MAX_INCLUDE_DEPTH; i++)
882		memset(&incstack[i], 0, sizeof(incstack[i]));
883	incstackp = 0;
884}
885
886void
887yycf_clean_buffer()
888{
889	int i;
890
891	for (i = 0; i < MAX_INCLUDE_DEPTH; i++) {
892		if (incstack[i].path != NULL) {
893			fclose(incstack[i].fp);
894			racoon_free(incstack[i].path);
895			incstack[i].path = NULL;
896		}
897	}
898}
899
900