4 * Copyright (c) 2021, 2022 Omar Polo <op@omarpolo.com>
5 * Copyright (c) 2018 Florian Obser <florian@openbsd.org>
6 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
7 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
8 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
9 * Copyright (c) 2001 Markus Friedl. All rights reserved.
10 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
11 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
13 * Permission to use, copy, modify, and distribute this software for any
14 * purpose with or without fee is hereby granted, provided that the above
15 * copyright notice and this permission notice appear in all copies.
17 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
18 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
20 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
21 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
22 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
23 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
40 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
42 TAILQ_ENTRY(file) entry;
53 struct file *pushfile(const char *, int);
57 void yyerror(const char *, ...)
58 __attribute__((__format__ (printf, 1, 2)))
59 __attribute__((__nonnull__ (1)));
60 void yywarn(const char *, ...)
61 __attribute__((__format__ (printf, 1, 2)))
62 __attribute__((__nonnull__ (1)));
63 int kw_cmp(const void *, const void *);
75 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
77 TAILQ_ENTRY(sym) entry;
84 int symset(const char *, const char *, int);
85 char *symget(const char *);
87 struct vhost *new_vhost(void);
88 struct location *new_location(void);
89 struct proxy *new_proxy(void);
90 char *ensure_absolute_path(char*);
91 int check_block_code(int);
92 char *check_block_fmt(char*);
93 int check_strip_no(int);
94 int check_port_num(int);
95 int check_prefork_num(int);
96 void advance_loc(void);
97 void advance_proxy(void);
98 void parsehp(char *, char **, const char **, const char *);
99 int fastcgi_conf(const char *, const char *);
100 void add_param(char *, char *);
101 int getservice(const char *);
103 static struct vhost *host;
104 static struct location *loc;
105 static struct proxy *proxy;
106 static char *current_media;
120 /* %define parse.error verbose */
124 %token CA CERT CHROOT CLIENT
126 %token FASTCGI FOR_HOST
127 %token INCLUDE INDEX IPV6
129 %token LANG LOCATION LOG
131 %token PARAM PORT PREFORK PROTO PROTOCOLS PROXY
132 %token RELAY_TO REQUIRE RETURN ROOT
133 %token SERVER SNI STRIP
134 %token TCP TOEXT TYPE TYPES
140 %token <v.string> STRING
141 %token <v.number> NUM
143 %type <v.number> bool proxy_port
144 %type <v.string> string numberstring
155 | conf error '\n' { file->errors++; }
158 include : INCLUDE STRING {
161 if ((nfile = pushfile($2, 0)) == NULL) {
162 yyerror("failed to include file %s", $2);
173 bool : ON { $$ = 1; }
177 string : string STRING {
178 if (asprintf(&$$, "%s%s", $1, $2) == -1) {
181 yyerror("string: asprintf: %s", strerror(errno));
192 if (asprintf(&s, "%d", $1) == -1) {
193 yyerror("asprintf: number");
201 varset : STRING '=' string {
204 if (isspace((unsigned char)*s)) {
205 yyerror("macro name cannot contain "
218 option : CHROOT string {
219 if (strlcpy(conf->chroot, $2, sizeof(conf->chroot)) >=
220 sizeof(conf->chroot))
221 yyerror("chroot path too long");
224 | IPV6 bool { conf->ipv6 = $2; }
225 | PORT NUM { conf->port = check_port_num($2); }
226 | PREFORK NUM { conf->prefork = check_prefork_num($2); }
228 if (tls_config_parse_protocols(&conf->protos, $2) == -1)
229 yyerror("invalid protocols string \"%s\"", $2);
233 if (strlcpy(conf->user, $2, sizeof(conf->user)) >=
235 yyerror("user name too long");
240 vhost : SERVER string {
242 TAILQ_INSERT_HEAD(&conf->hosts, host, vhosts);
244 loc = new_location();
245 TAILQ_INSERT_HEAD(&host->locations, loc, locations);
247 TAILQ_INIT(&host->proxies);
249 (void) strlcpy(loc->match, "*", sizeof(loc->match));
250 (void) strlcpy(host->domain, $2, sizeof(host->domain));
252 if (strstr($2, "xn--") != NULL) {
253 yywarn("\"%s\" looks like punycode: you "
254 "should use the decoded hostname", $2);
258 } '{' optnl servbody '}' {
259 if (host->cert_path == NULL ||
260 host->key_path == NULL)
261 yyerror("invalid vhost definition: %s", $2);
263 | error '}' { yyerror("bad server directive"); }
266 servbody : /* empty */
267 | servbody servopt optnl
268 | servbody location optnl
269 | servbody proxy optnl
272 servopt : ALIAS string {
275 a = xcalloc(1, sizeof(*a));
276 (void) strlcpy(a->alias, $2, sizeof(a->alias));
278 TAILQ_INSERT_TAIL(&host->aliases, a, aliases);
281 ensure_absolute_path($2);
282 free(host->cert_path);
283 host->cert_path = $2;
286 ensure_absolute_path($2);
287 free(host->key_path);
291 ensure_absolute_path($2);
292 free(host->ocsp_path);
293 host->ocsp_path = $2;
295 | PARAM string '=' string {
301 proxy : PROXY { advance_proxy(); }
302 proxy_matches '{' optnl proxy_opts '}' {
303 if (*proxy->host == '\0')
304 yyerror("invalid proxy block: missing `relay-to' option");
306 if ((proxy->cert_path == NULL && proxy->key_path != NULL) ||
307 (proxy->cert_path != NULL && proxy->key_path == NULL))
308 yyerror("invalid proxy block: missing cert or key");
312 proxy_matches : /* empty */
313 | proxy_matches proxy_match
316 proxy_port : /* empty */ { $$ = 1965; }
318 if (($$ = getservice($2)) == -1)
319 yyerror("invalid port number %s", $2);
322 | PORT NUM { $$ = $2; }
325 proxy_match : PROTO string {
326 (void) strlcpy(proxy->match_proto, $2, sizeof(proxy->match_proto));
329 | FOR_HOST string proxy_port {
330 (void) strlcpy(proxy->match_host, $2, sizeof(proxy->match_host));
331 (void) snprintf(proxy->match_port, sizeof(proxy->match_port),
337 proxy_opts : /* empty */
338 | proxy_opts proxy_opt optnl
341 proxy_opt : CERT string {
343 ensure_absolute_path($2);
344 proxy->cert_path = $2;
348 ensure_absolute_path($2);
349 proxy->key_path = $2;
352 if (tls_config_parse_protocols(&proxy->protocols, $2) == -1)
353 yyerror("invalid protocols string \"%s\"", $2);
356 | RELAY_TO string proxy_port {
357 (void) strlcpy(proxy->host, $2, sizeof(proxy->host));
358 (void) snprintf(proxy->port, sizeof(proxy->port),
362 | REQUIRE CLIENT CA string {
363 ensure_absolute_path($4);
364 proxy->reqca_path = $4;
367 (void) strlcpy(proxy->sni, $2, sizeof(proxy->sni));
374 proxy->noverifyname = !$2;
378 location : LOCATION { advance_loc(); } string '{' optnl locopts '}' {
379 /* drop the starting '/' if any */
381 memmove($3, $3+1, strlen($3));
382 (void) strlcpy(loc->match, $3, sizeof(loc->match));
388 locopts : /* empty */
389 | locopts locopt optnl
392 locopt : AUTO INDEX bool { loc->auto_index = $3 ? 1 : -1; }
393 | BLOCK RETURN NUM string {
395 (void) strlcpy(loc->block_fmt, $4, sizeof(loc->block_fmt));
396 loc->block_code = check_block_code($3);
400 (void) strlcpy(loc->block_fmt, "temporary failure",
401 sizeof(loc->block_fmt));
402 loc->block_code = check_block_code($3);
403 if ($3 >= 30 && $3 < 40)
404 yyerror("missing `meta' for block return %d", $3);
407 (void) strlcpy(loc->block_fmt, "temporary failure",
408 sizeof(loc->block_fmt));
409 loc->block_code = 40;
411 | DEFAULT TYPE string {
412 (void) strlcpy(loc->default_mime, $3,
413 sizeof(loc->default_mime));
418 (void) strlcpy(loc->index, $2, sizeof(loc->index));
422 (void) strlcpy(loc->lang, $2,
426 | LOG bool { loc->disable_log = !$2; }
427 | REQUIRE CLIENT CA string {
428 ensure_absolute_path($4);
429 loc->reqca_path = $4;
432 (void) strlcpy(loc->dir, $2, sizeof(loc->dir));
435 | STRIP NUM { loc->strip = check_strip_no($2); }
439 loc->fcgi = fastcgi_conf($1, NULL);
442 | TCP string PORT NUM {
444 if (asprintf(&c, "%d", $4) == -1)
446 loc->fcgi = fastcgi_conf($2, c);
450 loc->fcgi = fastcgi_conf($2, "9000");
453 | TCP string PORT string {
454 loc->fcgi = fastcgi_conf($2, $4);
460 types : TYPES '{' optnl mediaopts_l '}' ;
462 mediaopts_l : mediaopts_l mediaoptsl nl
466 mediaoptsl : STRING {
469 } medianames_l optsemicolon
473 medianames_l : medianames_l medianamesl
477 medianamesl : numberstring {
478 if (add_mime(&conf->mime, current_media, $1) == -1)
487 optnl : '\n' optnl /* zero or more newlines */
488 | ';' optnl /* semicolons too */
498 static const struct keyword {
502 /* these MUST be sorted */
510 {"default", DEFAULT},
511 {"fastcgi", FASTCGI},
512 {"for-host", FOR_HOST},
513 {"include", INCLUDE},
518 {"location", LOCATION},
525 {"prefork", PREFORK},
527 {"protocols", PROTOCOLS},
529 {"relay-to", RELAY_TO},
530 {"require", REQUIRE},
540 {"use-tls", USE_TLS},
542 {"verifyname", VERIFYNAME},
546 yyerror(const char *msg, ...)
553 fprintf(stderr, "%s:%d error: ", config_path, yylval.lineno);
554 vfprintf(stderr, msg, ap);
555 fprintf(stderr, "\n");
560 yywarn(const char *msg, ...)
565 fprintf(stderr, "%s:%d warning: ", config_path, yylval.lineno);
566 vfprintf(stderr, msg, ap);
567 fprintf(stderr, "\n");
572 kw_cmp(const void *k, const void *e)
574 return strcmp(k, ((struct keyword *)e)->word);
580 const struct keyword *p;
582 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
583 sizeof(keywords[0]), kw_cmp);
591 #define START_EXPAND 1
592 #define DONE_EXPAND 2
594 static int expanding;
602 if (file->ungetpos > 0)
603 c = file->ungetbuf[--file->ungetpos];
605 c = getc(file->stream);
607 if (c == START_EXPAND)
609 else if (c == DONE_EXPAND)
623 if ((c = igetc()) == EOF) {
624 yyerror("reached end of file while parsing "
626 if (file == topfile || popfile() == EOF)
633 while ((c = igetc()) == '\\') {
639 yylval.lineno = file->lineno;
645 * Fake EOL when hit EOF for the first time. This gets line
646 * count right if last line in included file is syntactically
647 * invalid and has no newline.
649 if (file->eof_reached == 0) {
650 file->eof_reached = 1;
654 if (file == topfile || popfile() == EOF)
668 if (file->ungetpos >= file->ungetsize) {
669 void *p = reallocarray(file->ungetbuf, file->ungetsize, 2);
673 file->ungetsize *= 2;
675 file->ungetbuf[file->ungetpos++] = c;
683 /* Skip to either EOF or the first real EOL. */
706 while ((c = lgetc(0)) == ' ' || c == '\t')
709 yylval.lineno = file->lineno;
711 while ((c = lgetc(0)) != '\n' && c != EOF)
713 if (c == '$' && !expanding) {
715 if ((c = lgetc(0)) == EOF)
717 if (p + 1 >= buf + sizeof(buf) -1) {
718 yyerror("string too long");
721 if (isalnum(c) || c == '_') {
731 yyerror("macro `%s' not defined", buf);
734 yylval.v.string = xstrdup(val);
737 if (c == '@' && !expanding) {
739 if ((c = lgetc(0)) == EOF)
742 if (p + 1 >= buf + sizeof(buf) - 1) {
743 yyerror("string too long");
746 if (isalnum(c) || c == '_') {
756 yyerror("macro '%s' not defined", buf);
759 p = val + strlen(val) - 1;
760 lungetc(DONE_EXPAND);
765 lungetc(START_EXPAND);
774 if ((c = lgetc(quotec)) == EOF)
779 } else if (c == '\\') {
780 if ((next = lgetc(quotec)) == EOF)
782 if (next == quotec || next == ' ' ||
785 else if (next == '\n') {
790 } else if (c == quotec) {
793 } else if (c == '\0') {
794 yyerror("invalid syntax");
797 if (p + 1 >= buf + sizeof(buf) - 1) {
798 yyerror("string too long");
803 yylval.v.string = strdup(buf);
804 if (yylval.v.string == NULL)
805 fatal("yylex: strdup");
809 #define allowed_to_end_number(x) \
810 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
812 if (c == '-' || isdigit(c)) {
815 if ((size_t)(p-buf) >= sizeof(buf)) {
816 yyerror("string too long");
819 } while ((c = lgetc(0)) != EOF && isdigit(c));
821 if (p == buf + 1 && buf[0] == '-')
823 if (c == EOF || allowed_to_end_number(c)) {
824 const char *errstr = NULL;
827 yylval.v.number = strtonum(buf, LLONG_MIN,
830 yyerror("\"%s\" invalid number: %s",
845 #define allowed_in_string(x) \
846 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
847 x != '{' && x != '}' && \
848 x != '!' && x != '=' && x != '#' && \
849 x != ',' && x != ';'))
851 if (isalnum(c) || c == ':' || c == '_') {
854 if ((size_t)(p-buf) >= sizeof(buf)) {
855 yyerror("string too long");
858 } while ((c = lgetc(0)) != EOF && (allowed_in_string(c)));
861 if ((token = lookup(buf)) == STRING)
862 yylval.v.string = xstrdup(buf);
866 yylval.lineno = file->lineno;
875 pushfile(const char *name, int secret)
879 nfile = xcalloc(1, sizeof(*nfile));
880 nfile->name = xstrdup(name);
881 if ((nfile->stream = fopen(nfile->name, "r")) == NULL) {
882 log_warn("can't open %s", nfile->name);
887 nfile->lineno = TAILQ_EMPTY(&files) ? 1 : 0;
888 nfile->ungetsize = 16;
889 nfile->ungetbuf = xcalloc(1, nfile->ungetsize);
890 TAILQ_INSERT_TAIL(&files, nfile, entry);
899 if ((prev = TAILQ_PREV(file, files, entry)) != NULL)
900 prev->errors += file->errors;
902 TAILQ_REMOVE(&files, file, entry);
903 fclose(file->stream);
905 free(file->ungetbuf);
908 return file ? 0 : EOF;
912 parse_conf(struct conf *c, const char *filename)
914 struct sym *sym, *next;
918 file = pushfile(filename, 0);
924 errors = file->errors;
927 /* Free macros and check which have not been used. */
928 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
929 /* TODO: warn if !sym->used */
933 TAILQ_REMOVE(&symhead, sym, entry);
944 symset(const char *name, const char *val, int persist)
948 TAILQ_FOREACH(sym, &symhead, entry) {
949 if (!strcmp(name, sym->name))
959 TAILQ_REMOVE(&symhead, sym, entry);
964 sym = xcalloc(1, sizeof(*sym));
965 sym->name = xstrdup(name);
966 sym->val = xstrdup(val);
968 sym->persist = persist;
970 TAILQ_INSERT_TAIL(&symhead, sym, entry);
975 cmdline_symset(char *s)
980 if ((val = strrchr(s, '=')) == NULL)
982 sym = xcalloc(1, val - s + 1);
983 memcpy(sym, s, val - s);
984 ret = symset(sym, val + 1, 1);
990 symget(const char *nam)
994 TAILQ_FOREACH(sym, &symhead, entry) {
995 if (strcmp(nam, sym->name) == 0) {
1004 ensure_absolute_path(char *path)
1006 if (path == NULL || *path != '/')
1007 yyerror("not an absolute path: %s", path);
1012 check_block_code(int n)
1014 if (n < 10 || n >= 70 || (n >= 20 && n <= 29))
1015 yyerror("invalid block code %d", n);
1020 check_block_fmt(char *fmt)
1024 for (s = fmt; *s; ++s) {
1035 yyerror("invalid format specifier %%%c", *s);
1043 check_strip_no(int n)
1046 yyerror("invalid strip number %d", n);
1051 check_port_num(int n)
1053 if (n <= 0 || n >= UINT16_MAX)
1054 yyerror("port number is %s: %d",
1055 n <= 0 ? "too small" : "too large",
1061 check_prefork_num(int n)
1063 if (n <= 0 || n >= PROC_MAX_INSTANCES)
1064 yyerror("invalid prefork number %d", n);
1071 loc = new_location();
1072 TAILQ_INSERT_TAIL(&host->locations, loc, locations);
1078 proxy = new_proxy();
1079 TAILQ_INSERT_TAIL(&host->proxies, proxy, proxies);
1083 parsehp(char *str, char **host, const char **port, const char *def)
1090 if ((at = strchr(str, ':')) != NULL) {
1096 strtonum(*port, 1, UINT16_MAX, &errstr);
1098 yyerror("port is %s: %s", errstr, *port);
1102 fastcgi_conf(const char *path, const char *port)
1107 TAILQ_FOREACH(f, &conf->fcgi, fcgi) {
1108 if (!strcmp(f->path, path) &&
1109 ((port == NULL && *f->port == '\0') ||
1110 !strcmp(f->port, port)))
1115 f = xcalloc(1, sizeof(*f));
1117 (void)strlcpy(f->path, path, sizeof(f->path));
1119 (void)strlcpy(f->port, port, sizeof(f->port));
1120 TAILQ_INSERT_TAIL(&conf->fcgi, f, fcgi);
1126 add_param(char *name, char *val)
1129 struct envhead *h = &host->params;
1131 e = xcalloc(1, sizeof(*e));
1132 (void) strlcpy(e->name, name, sizeof(e->name));
1133 (void) strlcpy(e->value, val, sizeof(e->value));
1134 TAILQ_INSERT_TAIL(h, e, envs);
1138 getservice(const char *n)
1144 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1146 s = getservbyname(n, "tcp");
1148 s = getservbyname(n, "udp");
1151 return (ntohs(s->s_port));
1154 return ((unsigned short)llval);