npf_scan.l revision 1.26 1 /* $NetBSD: npf_scan.l,v 1.26 2017/12/10 22:04:41 rmind Exp $ */
2
3 /*-
4 * Copyright (c) 2011-2012 The NetBSD Foundation, Inc.
5 * All rights reserved.
6 *
7 * This code is derived from software contributed to The NetBSD Foundation
8 * by Martin Husemann.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 *
19 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29 * POSSIBILITY OF SUCH DAMAGE.
30 */
31
32 %{
33 #include <stdio.h>
34 #include <stdlib.h>
35 #include <err.h>
36
37 #include "npfctl.h"
38 #include "npf_parse.h"
39
40 int yycolumn;
41
42 #define YY_USER_ACTION yycolumn += yyleng;
43
44 extern int yyparsetarget;
45 extern int yylineno;
46 extern const char * yyfilename;
47 extern int yyparse(void);
48 extern void yyrestart(FILE *);
49
50 void
51 npfctl_parse_file(const char *name)
52 {
53 FILE *fp;
54
55 fp = fopen(name, "r");
56 if (fp == NULL) {
57 err(EXIT_FAILURE, "open '%s'", name);
58 }
59 yyparsetarget = NPFCTL_PARSE_FILE;
60 yyrestart(fp);
61 yylineno = 1;
62 yycolumn = 0;
63 yyfilename = name;
64 yyparse();
65 fclose(fp);
66 }
67
68 void
69 npfctl_parse_string(const char *str)
70 {
71 YY_BUFFER_STATE bs;
72
73 yyparsetarget = NPFCTL_PARSE_STRING;
74 bs = yy_scan_string(str);
75 yyfilename = "stdin";
76 yyparse();
77 yy_delete_buffer(bs);
78 }
79
80 %}
81
82 %option noyywrap nounput noinput
83
84 ID [a-zA-Z_][a-zA-Z_0-9]*
85 DID [a-zA-Z_][a-zA-Z_0-9-]*
86 NUMBER [0-9]+
87 HEXDIG [0-9a-fA-F]+
88
89 %%
90 alg return ALG;
91 table return TABLE;
92 type return TYPE;
93 hash return HASH;
94 tree return TREE;
95 cdb return CDB;
96 static return TSTATIC;
97 dynamic return TDYNAMIC;
98 file return TFILE;
99 map return MAP;
100 no-ports return NO_PORTS;
101 set return SET;
102 "<->" return ARROWBOTH;
103 "<-" return ARROWLEFT;
104 "->" return ARROWRIGHT;
105 algo return ALGO;
106 npt66 return NPT66;
107 "-" return MINUS;
108 procedure return PROCEDURE;
109 \\\n yylineno++; yycolumn = 0;
110 \n yylineno++; yycolumn = 0; return SEPLINE;
111 ; return SEPLINE;
112 name return NAME;
113 group return GROUP;
114 default return DEFAULT;
115 in return IN;
116 out return OUT;
117 forw return FORW;
118 interface return INTERFACE;
119 all return ALL;
120 block return BLOCK;
121 pass return PASS;
122 pcap-filter return PCAP_FILTER;
123 stateful return STATEFUL;
124 stateful-ends return STATEFUL_ENDS;
125 apply return APPLY;
126 final return FINAL;
127 quick return FINAL;
128 on return ON;
129 off return OFF;
130 bpf.jit return BPFJIT;
131 inet6 return INET6;
132 inet4 return INET4;
133 ifaddrs return IFADDRS;
134 proto return PROTO;
135 family return FAMILY;
136 tcp return TCP;
137 icmp { yylval.num = IPPROTO_ICMP; return ICMP; }
138 ipv6-icmp { yylval.num = IPPROTO_ICMPV6; return ICMP6; }
139 \"ipv6-icmp\" { yylval.num = IPPROTO_ICMPV6; return ICMP6; }
140 return-rst return RETURNRST;
141 return-icmp return RETURNICMP;
142 return return RETURN;
143 ruleset return RULESET;
144 from return FROM;
145 to return TO;
146 port return PORT;
147 flags return FLAGS;
148 icmp-type return ICMPTYPE;
149 code return CODE;
150 any return ANY;
151
152 "/" return SLASH;
153 "{" return CURLY_OPEN;
154 "}" return CURLY_CLOSE;
155 "(" return PAR_OPEN;
156 ")" return PAR_CLOSE;
157 "," return COMMA;
158 "=" return EQ;
159 "!" return EXCL_MARK;
160
161 "0x"{HEXDIG} {
162 char *endp, *buf = ecalloc(1, yyleng + 1);
163 buf[yyleng] = 0;
164 yylval.num = strtoul(buf+2, &endp, 16);
165 free(buf);
166 return HEX;
167 }
168
169 {NUMBER}"."{NUMBER} {
170 char *endp, *buf = estrndup(yytext, yyleng);
171 yylval.fpnum = strtod(buf, &endp);
172 free(buf);
173 return FPNUM;
174 }
175
176 {HEXDIG}":"[0-9a-fA-F:]* {
177 yylval.str = estrndup(yytext, yyleng);
178 return IPV6ADDR;
179 }
180
181 "::"{HEXDIG}[0-9a-fA-F:.]* {
182 yylval.str = estrndup(yytext, yyleng);
183 return IPV6ADDR;
184 }
185
186 {NUMBER}"."[0-9][0-9.]* {
187 yylval.str = estrndup(yytext, yyleng);
188 return IPV4ADDR;
189 }
190
191 {NUMBER} {
192 char *endp, *buf = estrndup(yytext, yyleng);
193 yylval.num = strtoul(buf, &endp, 10);
194 free(buf);
195 return NUM;
196 }
197
198 "<"{DID}">" {
199 yylval.str = estrndup(yytext + 1, yyleng - 2);
200 return TABLE_ID;
201 }
202
203 "$"{ID} {
204 yylval.str = estrndup(yytext + 1, yyleng - 1);
205 return VAR_ID;
206 }
207
208 {ID} {
209 yylval.str = estrndup(yytext, yyleng);
210 return IDENTIFIER;
211 }
212
213 \"[^\"]*\" {
214 yylval.str = estrndup(yytext + 1, yyleng - 2);
215 return STRING;
216 }
217
218 #.*$ /* drop comment until end of line */
219 [ \t] /* eat whitespace */
220
221 : return COLON;
222