4 * Copyright (c) 2021, 2022, 2023 Omar Polo <op@omarpolo.com>
5 * Copyright (c) 2018 Florian Obser <florian@openbsd.org>
6 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
7 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
8 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
9 * Copyright (c) 2001 Markus Friedl. All rights reserved.
10 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
11 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
13 * Permission to use, copy, modify, and distribute this software for any
14 * purpose with or without fee is hereby granted, provided that the above
15 * copyright notice and this permission notice appear in all copies.
17 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
18 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
20 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
21 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
22 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
23 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
40 static const char *default_host = "*";
41 static uint16_t default_port = 1965;
43 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
45 TAILQ_ENTRY(file) entry;
56 struct file *pushfile(const char *, int);
60 void yyerror(const char *, ...)
61 __attribute__((__format__ (printf, 1, 2)))
62 __attribute__((__nonnull__ (1)));
63 void yywarn(const char *, ...)
64 __attribute__((__format__ (printf, 1, 2)))
65 __attribute__((__nonnull__ (1)));
66 int kw_cmp(const void *, const void *);
78 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
80 TAILQ_ENTRY(sym) entry;
87 int symset(const char *, const char *, int);
88 char *symget(const char *);
90 char *ensure_absolute_path(char*);
91 int check_block_code(int);
92 char *check_block_fmt(char*);
93 int check_strip_no(int);
94 int check_port_num(int);
95 int check_prefork_num(int);
96 void advance_loc(void);
97 void advance_proxy(void);
98 void parsehp(char *, char **, const char **, const char *);
99 int fastcgi_conf(const char *, const char *);
100 void add_param(char *, char *);
101 int getservice(const char *);
102 void listen_on(const char *, const char *);
104 static struct vhost *host;
105 static struct location *loc;
106 static struct proxy *proxy;
107 static char *current_media;
118 #define YYSTYPE YYSTYPE
123 /* %define parse.error verbose */
125 %token ACCESS ALIAS AUTO
127 %token CA CERT CHROOT CLIENT
129 %token FASTCGI FOR_HOST
130 %token INCLUDE INDEX IPV6
132 %token LANG LISTEN LOCATION LOG
134 %token PARAM PORT PREFORK PROTO PROTOCOLS PROXY
135 %token RELAY_TO REQUIRE RETURN ROOT
136 %token SERVER SNI SOCKET STRIP SYSLOG
137 %token TCP TOEXT TYPE TYPES
143 %token <v.string> STRING
144 %token <v.number> NUM
146 %type <v.number> bool proxy_port
147 %type <v.string> string numberstring listen_addr
158 | conf error '\n' { file->errors++; }
161 include : INCLUDE STRING {
164 if ((nfile = pushfile($2, 0)) == NULL) {
165 yyerror("failed to include file %s", $2);
176 bool : ON { $$ = 1; }
180 string : string STRING {
181 if (asprintf(&$$, "%s%s", $1, $2) == -1) {
184 yyerror("string: asprintf: %s", strerror(errno));
195 if (asprintf(&s, "%d", $1) == -1) {
196 yyerror("asprintf: number");
204 varset : STRING '=' string {
207 if (isspace((unsigned char)*s)) {
208 yyerror("macro name cannot contain "
221 option : CHROOT string {
222 if (strlcpy(conf->chroot, $2, sizeof(conf->chroot)) >=
223 sizeof(conf->chroot))
224 yyerror("chroot path too long");
228 yywarn("option `ipv6' is deprecated,"
229 " please use `listen on'");
233 default_host = "0.0.0.0";
237 yywarn("option `port' is deprecated,"
238 " please use `listen on'");
241 | PREFORK NUM { conf->prefork = check_prefork_num($2); }
243 if (tls_config_parse_protocols(&conf->protos, $2) == -1)
244 yyerror("invalid protocols string \"%s\"", $2);
248 if (strlcpy(conf->user, $2, sizeof(conf->user)) >=
250 yyerror("user name too long");
255 log : LOG '{' optnl logopts '}'
259 logopts : /* empty */
260 | logopts logopt optnl
264 free(conf->log_access);
265 conf->log_access = NULL;
268 free(conf->log_access);
269 conf->log_access = $2;
273 vhost : SERVER string {
275 TAILQ_INSERT_HEAD(&conf->hosts, host, vhosts);
277 loc = new_location();
278 TAILQ_INSERT_HEAD(&host->locations, loc, locations);
280 TAILQ_INIT(&host->proxies);
282 (void) strlcpy(loc->match, "*", sizeof(loc->match));
283 (void) strlcpy(host->domain, $2, sizeof(host->domain));
285 if (strstr($2, "xn--") != NULL) {
286 yywarn("\"%s\" looks like punycode: you "
287 "should use the decoded hostname", $2);
291 } '{' optnl servbody '}' {
292 if (host->cert_path == NULL ||
293 host->key_path == NULL)
294 yyerror("invalid vhost definition: %s",
296 if (TAILQ_EMPTY(&host->addrs)) {
300 r = snprintf(portno, sizeof(portno), "%d",
302 if (r < 0 || (size_t)r >= sizeof(portno))
305 yywarn("missing `listen on' in server %s,"
306 " assuming %s port %d", $2, default_host,
308 listen_on(default_host, portno);
311 | error '}' { yyerror("bad server directive"); }
314 servbody : /* empty */
315 | servbody servopt optnl
316 | servbody location optnl
317 | servbody proxy optnl
320 listen_addr : '*' { $$ = NULL; }
324 servopt : ALIAS string {
327 a = xcalloc(1, sizeof(*a));
328 (void) strlcpy(a->alias, $2, sizeof(a->alias));
330 TAILQ_INSERT_TAIL(&host->aliases, a, aliases);
333 ensure_absolute_path($2);
334 free(host->cert_path);
335 host->cert_path = $2;
338 ensure_absolute_path($2);
339 free(host->key_path);
343 ensure_absolute_path($2);
344 free(host->ocsp_path);
345 host->ocsp_path = $2;
347 | PARAM string '=' string {
348 yywarn("the top-level `param' directive is deprecated."
349 " Please use `fastcgi { param ... }`");
352 | LISTEN ON listen_addr {
353 listen_on($3, "1965");
355 | LISTEN ON listen_addr PORT STRING {
360 | LISTEN ON listen_addr PORT NUM {
364 r = snprintf(portno, sizeof(portno), "%d", $5);
365 if (r < 0 || (size_t)r >= sizeof(portno))
368 listen_on($3, portno);
374 proxy : PROXY { advance_proxy(); }
375 proxy_matches '{' optnl proxy_opts '}' {
376 if (*proxy->host == '\0')
377 yyerror("invalid proxy block: missing `relay-to' option");
379 if ((proxy->cert_path == NULL && proxy->key_path != NULL) ||
380 (proxy->cert_path != NULL && proxy->key_path == NULL))
381 yyerror("invalid proxy block: missing cert or key");
385 proxy_matches : /* empty */
386 | proxy_matches proxy_match
389 proxy_port : /* empty */ { $$ = 1965; }
391 if (($$ = getservice($2)) == -1)
392 yyerror("invalid port number %s", $2);
395 | PORT NUM { $$ = $2; }
398 proxy_match : PROTO string {
399 (void) strlcpy(proxy->match_proto, $2, sizeof(proxy->match_proto));
402 | FOR_HOST string proxy_port {
403 (void) strlcpy(proxy->match_host, $2, sizeof(proxy->match_host));
404 (void) snprintf(proxy->match_port, sizeof(proxy->match_port),
410 proxy_opts : /* empty */
411 | proxy_opts proxy_opt optnl
414 proxy_opt : CERT string {
416 ensure_absolute_path($2);
417 proxy->cert_path = $2;
421 ensure_absolute_path($2);
422 proxy->key_path = $2;
425 if (tls_config_parse_protocols(&proxy->protocols, $2) == -1)
426 yyerror("invalid protocols string \"%s\"", $2);
429 | RELAY_TO string proxy_port {
430 (void) strlcpy(proxy->host, $2, sizeof(proxy->host));
431 (void) snprintf(proxy->port, sizeof(proxy->port),
435 | REQUIRE CLIENT CA string {
436 ensure_absolute_path($4);
437 proxy->reqca_path = $4;
440 (void) strlcpy(proxy->sni, $2, sizeof(proxy->sni));
447 proxy->noverifyname = !$2;
451 location : LOCATION { advance_loc(); } string '{' optnl locopts '}' {
452 /* drop the starting '/' if any */
454 memmove($3, $3+1, strlen($3));
455 (void) strlcpy(loc->match, $3, sizeof(loc->match));
461 locopts : /* empty */
462 | locopts locopt optnl
465 locopt : AUTO INDEX bool { loc->auto_index = $3 ? 1 : -1; }
466 | BLOCK RETURN NUM string {
468 (void) strlcpy(loc->block_fmt, $4, sizeof(loc->block_fmt));
469 loc->block_code = check_block_code($3);
473 (void) strlcpy(loc->block_fmt, "temporary failure",
474 sizeof(loc->block_fmt));
475 loc->block_code = check_block_code($3);
476 if ($3 >= 30 && $3 < 40)
477 yyerror("missing `meta' for block return %d", $3);
480 (void) strlcpy(loc->block_fmt, "temporary failure",
481 sizeof(loc->block_fmt));
482 loc->block_code = 40;
484 | DEFAULT TYPE string {
485 (void) strlcpy(loc->default_mime, $3,
486 sizeof(loc->default_mime));
491 (void) strlcpy(loc->index, $2, sizeof(loc->index));
495 (void) strlcpy(loc->lang, $2,
499 | LOG bool { loc->disable_log = !$2; }
500 | REQUIRE CLIENT CA string {
501 ensure_absolute_path($4);
502 loc->reqca_path = $4;
505 (void) strlcpy(loc->dir, $2, sizeof(loc->dir));
508 | STRIP NUM { loc->strip = check_strip_no($2); }
511 fastcgi : FASTCGI '{' optnl fastcgiopts '}'
518 yywarn("`fastcgi path' is deprecated. "
519 "Please use `fastcgi socket path' instead.");
520 loc->fcgi = fastcgi_conf($2, NULL);
525 fastcgiopts : /* empty */
526 | fastcgiopts fastcgiopt optnl
529 fastcgiopt : PARAM string '=' string {
533 loc->fcgi = fastcgi_conf($2, NULL);
536 | SOCKET TCP string PORT NUM {
539 if (asprintf(&c, "%d", $5) == -1)
541 loc->fcgi = fastcgi_conf($3, c);
545 | SOCKET TCP string {
546 loc->fcgi = fastcgi_conf($3, "9000");
548 | SOCKET TCP string PORT string {
549 loc->fcgi = fastcgi_conf($3, $5);
555 types : TYPES '{' optnl mediaopts_l '}' ;
557 mediaopts_l : mediaopts_l mediaoptsl nl
561 mediaoptsl : STRING {
564 } medianames_l optsemicolon
568 medianames_l : medianames_l medianamesl
572 medianamesl : numberstring {
573 if (add_mime(&conf->mime, current_media, $1) == -1)
582 optnl : '\n' optnl /* zero or more newlines */
583 | ';' optnl /* semicolons too */
593 static const struct keyword {
597 /* these MUST be sorted */
606 {"default", DEFAULT},
607 {"fastcgi", FASTCGI},
608 {"for-host", FOR_HOST},
609 {"include", INCLUDE},
615 {"location", LOCATION},
622 {"prefork", PREFORK},
624 {"protocols", PROTOCOLS},
626 {"relay-to", RELAY_TO},
627 {"require", REQUIRE},
639 {"use-tls", USE_TLS},
641 {"verifyname", VERIFYNAME},
645 yyerror(const char *msg, ...)
652 fprintf(stderr, "%s:%d error: ", config_path, yylval.lineno);
653 vfprintf(stderr, msg, ap);
654 fprintf(stderr, "\n");
659 yywarn(const char *msg, ...)
664 fprintf(stderr, "%s:%d warning: ", config_path, yylval.lineno);
665 vfprintf(stderr, msg, ap);
666 fprintf(stderr, "\n");
671 kw_cmp(const void *k, const void *e)
673 return strcmp(k, ((struct keyword *)e)->word);
679 const struct keyword *p;
681 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
682 sizeof(keywords[0]), kw_cmp);
690 #define START_EXPAND 1
691 #define DONE_EXPAND 2
693 static int expanding;
701 if (file->ungetpos > 0)
702 c = file->ungetbuf[--file->ungetpos];
704 c = getc(file->stream);
706 if (c == START_EXPAND)
708 else if (c == DONE_EXPAND)
722 if ((c = igetc()) == EOF) {
723 yyerror("reached end of file while parsing "
725 if (file == topfile || popfile() == EOF)
732 while ((c = igetc()) == '\\') {
738 yylval.lineno = file->lineno;
744 * Fake EOL when hit EOF for the first time. This gets line
745 * count right if last line in included file is syntactically
746 * invalid and has no newline.
748 if (file->eof_reached == 0) {
749 file->eof_reached = 1;
753 if (file == topfile || popfile() == EOF)
767 if (file->ungetpos >= file->ungetsize) {
768 void *p = reallocarray(file->ungetbuf, file->ungetsize, 2);
772 file->ungetsize *= 2;
774 file->ungetbuf[file->ungetpos++] = c;
782 /* Skip to either EOF or the first real EOL. */
805 while ((c = lgetc(0)) == ' ' || c == '\t')
808 yylval.lineno = file->lineno;
810 while ((c = lgetc(0)) != '\n' && c != EOF)
812 if (c == '$' && !expanding) {
814 if ((c = lgetc(0)) == EOF)
816 if (p + 1 >= buf + sizeof(buf) -1) {
817 yyerror("string too long");
820 if (isalnum(c) || c == '_') {
830 yyerror("macro `%s' not defined", buf);
833 yylval.v.string = xstrdup(val);
836 if (c == '@' && !expanding) {
838 if ((c = lgetc(0)) == EOF)
841 if (p + 1 >= buf + sizeof(buf) - 1) {
842 yyerror("string too long");
845 if (isalnum(c) || c == '_') {
855 yyerror("macro '%s' not defined", buf);
858 p = val + strlen(val) - 1;
859 lungetc(DONE_EXPAND);
864 lungetc(START_EXPAND);
873 if ((c = lgetc(quotec)) == EOF)
878 } else if (c == '\\') {
879 if ((next = lgetc(quotec)) == EOF)
881 if (next == quotec || next == ' ' ||
884 else if (next == '\n') {
889 } else if (c == quotec) {
892 } else if (c == '\0') {
893 yyerror("invalid syntax");
896 if (p + 1 >= buf + sizeof(buf) - 1) {
897 yyerror("string too long");
902 yylval.v.string = strdup(buf);
903 if (yylval.v.string == NULL)
904 fatal("yylex: strdup");
908 #define allowed_to_end_number(x) \
909 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
911 if (c == '-' || isdigit(c)) {
914 if ((size_t)(p-buf) >= sizeof(buf)) {
915 yyerror("string too long");
918 } while ((c = lgetc(0)) != EOF && isdigit(c));
920 if (p == buf + 1 && buf[0] == '-')
922 if (c == EOF || allowed_to_end_number(c)) {
923 const char *errstr = NULL;
926 yylval.v.number = strtonum(buf, LLONG_MIN,
929 yyerror("\"%s\" invalid number: %s",
944 #define allowed_in_string(x) \
945 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
946 x != '{' && x != '}' && \
947 x != '!' && x != '=' && x != '#' && \
948 x != ',' && x != ';'))
950 if (isalnum(c) || c == ':' || c == '_') {
953 if ((size_t)(p-buf) >= sizeof(buf)) {
954 yyerror("string too long");
957 } while ((c = lgetc(0)) != EOF && (allowed_in_string(c)));
960 if ((token = lookup(buf)) == STRING)
961 yylval.v.string = xstrdup(buf);
965 yylval.lineno = file->lineno;
974 pushfile(const char *name, int secret)
978 nfile = xcalloc(1, sizeof(*nfile));
979 nfile->name = xstrdup(name);
980 if ((nfile->stream = fopen(nfile->name, "r")) == NULL) {
981 log_warn("can't open %s", nfile->name);
986 nfile->lineno = TAILQ_EMPTY(&files) ? 1 : 0;
987 nfile->ungetsize = 16;
988 nfile->ungetbuf = xcalloc(1, nfile->ungetsize);
989 TAILQ_INSERT_TAIL(&files, nfile, entry);
998 if ((prev = TAILQ_PREV(file, files, entry)) != NULL)
999 prev->errors += file->errors;
1001 TAILQ_REMOVE(&files, file, entry);
1002 fclose(file->stream);
1004 free(file->ungetbuf);
1007 return file ? 0 : EOF;
1011 parse_conf(struct conf *c, const char *filename)
1013 struct sym *sym, *next;
1016 default_port = 1965;
1020 file = pushfile(filename, 0);
1026 errors = file->errors;
1029 /* Free macros and check which have not been used. */
1030 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
1031 /* TODO: warn if !sym->used */
1032 if (!sym->persist) {
1035 TAILQ_REMOVE(&symhead, sym, entry);
1046 symset(const char *name, const char *val, int persist)
1050 TAILQ_FOREACH(sym, &symhead, entry) {
1051 if (!strcmp(name, sym->name))
1061 TAILQ_REMOVE(&symhead, sym, entry);
1066 sym = xcalloc(1, sizeof(*sym));
1067 sym->name = xstrdup(name);
1068 sym->val = xstrdup(val);
1070 sym->persist = persist;
1072 TAILQ_INSERT_TAIL(&symhead, sym, entry);
1077 cmdline_symset(char *s)
1082 if ((val = strrchr(s, '=')) == NULL)
1084 sym = xcalloc(1, val - s + 1);
1085 memcpy(sym, s, val - s);
1086 ret = symset(sym, val + 1, 1);
1092 symget(const char *nam)
1096 TAILQ_FOREACH(sym, &symhead, entry) {
1097 if (strcmp(nam, sym->name) == 0) {
1106 ensure_absolute_path(char *path)
1108 if (path == NULL || *path != '/')
1109 yyerror("not an absolute path: %s", path);
1114 check_block_code(int n)
1116 if (n < 10 || n >= 70 || (n >= 20 && n <= 29))
1117 yyerror("invalid block code %d", n);
1122 check_block_fmt(char *fmt)
1126 for (s = fmt; *s; ++s) {
1137 yyerror("invalid format specifier %%%c", *s);
1145 check_strip_no(int n)
1148 yyerror("invalid strip number %d", n);
1153 check_port_num(int n)
1155 if (n <= 0 || n >= UINT16_MAX)
1156 yyerror("port number is %s: %d",
1157 n <= 0 ? "too small" : "too large",
1163 check_prefork_num(int n)
1165 if (n <= 0 || n >= PROC_MAX_INSTANCES)
1166 yyerror("invalid prefork number %d", n);
1173 loc = new_location();
1174 TAILQ_INSERT_TAIL(&host->locations, loc, locations);
1180 proxy = new_proxy();
1181 TAILQ_INSERT_TAIL(&host->proxies, proxy, proxies);
1185 parsehp(char *str, char **host, const char **port, const char *def)
1192 if ((at = strchr(str, ':')) != NULL) {
1198 strtonum(*port, 1, UINT16_MAX, &errstr);
1200 yyerror("port is %s: %s", errstr, *port);
1204 fastcgi_conf(const char *path, const char *port)
1209 TAILQ_FOREACH(f, &conf->fcgi, fcgi) {
1210 if (!strcmp(f->path, path) &&
1211 ((port == NULL && *f->port == '\0') ||
1212 !strcmp(f->port, port)))
1217 f = xcalloc(1, sizeof(*f));
1219 (void)strlcpy(f->path, path, sizeof(f->path));
1221 (void)strlcpy(f->port, port, sizeof(f->port));
1222 TAILQ_INSERT_TAIL(&conf->fcgi, f, fcgi);
1228 add_param(char *name, char *val)
1231 struct envhead *h = &loc->params;
1233 e = xcalloc(1, sizeof(*e));
1234 (void) strlcpy(e->name, name, sizeof(e->name));
1235 (void) strlcpy(e->value, val, sizeof(e->value));
1236 TAILQ_INSERT_TAIL(h, e, envs);
1240 getservice(const char *n)
1246 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1248 s = getservbyname(n, "tcp");
1250 s = getservbyname(n, "udp");
1253 return (ntohs(s->s_port));
1256 return ((unsigned short)llval);
1260 add_to_addr_queue(struct addrhead *a, struct addrinfo *ai)
1262 struct address *addr;
1263 struct sockaddr_in *sin;
1264 struct sockaddr_in6 *sin6;
1266 if (ai->ai_addrlen > sizeof(addr->ss))
1267 fatalx("ai_addrlen larger than a sockaddr_storage");
1269 TAILQ_FOREACH(addr, a, addrs) {
1270 if (addr->ai_flags == ai->ai_flags &&
1271 addr->ai_family == ai->ai_family &&
1272 addr->ai_socktype == ai->ai_socktype &&
1273 addr->ai_protocol == ai->ai_protocol &&
1274 addr->slen == ai->ai_addrlen &&
1275 !memcmp(&addr->ss, ai->ai_addr, addr->slen))
1279 addr = xcalloc(1, sizeof(*addr));
1280 addr->ai_flags = ai->ai_flags;
1281 addr->ai_family = ai->ai_family;
1282 addr->ai_socktype = ai->ai_socktype;
1283 addr->ai_protocol = ai->ai_protocol;
1284 addr->slen = ai->ai_addrlen;
1285 memcpy(&addr->ss, ai->ai_addr, ai->ai_addrlen);
1288 switch (addr->ai_family) {
1290 sin = (struct sockaddr_in *)&addr->ss;
1291 addr->port = ntohs(sin->sin_port);
1294 sin6 = (struct sockaddr_in6 *)&addr->ss;
1295 addr->port = ntohs(sin6->sin6_port);
1298 fatalx("unknown socket family %d", addr->ai_family);
1303 TAILQ_INSERT_HEAD(a, addr, addrs);
1307 listen_on(const char *hostname, const char *servname)
1309 struct addrinfo hints, *res, *res0;
1312 memset(&hints, 0, sizeof(hints));
1313 hints.ai_family = AF_UNSPEC;
1314 hints.ai_socktype = SOCK_STREAM;
1315 hints.ai_flags = AI_PASSIVE;
1316 error = getaddrinfo(hostname, servname, &hints, &res0);
1318 yyerror("listen on \"%s\" port %s: %s", hostname, servname,
1319 gai_strerror(errno));
1323 for (res = res0; res; res = res->ai_next) {
1324 add_to_addr_queue(&host->addrs, res);
1325 add_to_addr_queue(&conf->addrs, res);