4 * Copyright (c) 2021, 2022 Omar Polo <op@omarpolo.com>
5 * Copyright (c) 2018 Florian Obser <florian@openbsd.org>
6 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
7 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
8 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
9 * Copyright (c) 2001 Markus Friedl. All rights reserved.
10 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
11 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
13 * Permission to use, copy, modify, and distribute this software for any
14 * purpose with or without fee is hereby granted, provided that the above
15 * copyright notice and this permission notice appear in all copies.
17 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
18 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
20 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
21 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
22 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
23 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
35 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
37 TAILQ_ENTRY(file) entry;
48 struct file *pushfile(const char *, int);
52 void yyerror(const char *, ...)
53 __attribute__((__format__ (printf, 1, 2)))
54 __attribute__((__nonnull__ (1)));
55 void yywarn(const char *, ...)
56 __attribute__((__format__ (printf, 1, 2)))
57 __attribute__((__nonnull__ (1)));
58 int kw_cmp(const void *, const void *);
70 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
72 TAILQ_ENTRY(sym) entry;
79 int symset(const char *, const char *, int);
80 char *symget(const char *);
82 struct vhost *new_vhost(void);
83 struct location *new_location(void);
84 struct proxy *new_proxy(void);
85 char *ensure_absolute_path(char*);
86 int check_block_code(int);
87 char *check_block_fmt(char*);
88 int check_strip_no(int);
89 int check_port_num(int);
90 int check_prefork_num(int);
91 void advance_loc(void);
92 void advance_proxy(void);
93 void parsehp(char *, char **, const char **, const char *);
94 void only_once(const void*, const char*);
95 void only_oncei(int, const char*);
96 int fastcgi_conf(char *, char *, char *);
97 void add_param(char *, char *, int);
99 static struct vhost *host;
100 static struct location *loc;
101 static struct proxy *proxy;
102 static char *current_media;
116 /* %define parse.error verbose */
120 %token CA CERT CHROOT CLIENT
122 %token FASTCGI FOR_HOST
123 %token INCLUDE INDEX IPV6
125 %token LANG LOCATION LOG
128 %token PARAM PORT PREFORK PROTO PROTOCOLS PROXY
129 %token RELAY_TO REQUIRE RETURN ROOT
130 %token SERVER SNI SPAWN STRIP
131 %token TCP TOEXT TYPE TYPES
137 %token <v.string> STRING
138 %token <v.number> NUM
140 %type <v.number> bool
141 %type <v.string> string numberstring
152 | conf error '\n' { file->errors++; }
155 include : INCLUDE STRING {
158 if ((nfile = pushfile($2, 0)) == NULL) {
159 yyerror("failed to include file %s", $2);
170 bool : ON { $$ = 1; }
174 string : string STRING {
175 if (asprintf(&$$, "%s%s", $1, $2) == -1) {
178 yyerror("string: asprintf: %s", strerror(errno));
189 if (asprintf(&s, "%d", $1) == -1) {
190 yyerror("asprintf: number");
198 varset : STRING '=' string {
201 if (isspace((unsigned char)*s)) {
202 yyerror("macro name cannot contain "
215 option : CHROOT string { conf.chroot = $2; }
216 | IPV6 bool { conf.ipv6 = $2; }
217 | MIME STRING string {
218 yywarn("`mime MIME EXT' is deprecated and will be "
219 "removed in a future version, please use the new "
221 if (add_mime(&conf.mime, $2, $3) == -1)
224 | MAP string TOEXT string {
225 yywarn("`map mime to-ext' is deprecated and will be "
226 "removed in a future version, please use the new "
228 if (add_mime(&conf.mime, $2, $4) == -1)
231 | PORT NUM { conf.port = check_port_num($2); }
232 | PREFORK NUM { conf.prefork = check_prefork_num($2); }
234 if (tls_config_parse_protocols(&conf.protos, $2) == -1)
235 yyerror("invalid protocols string \"%s\"", $2);
238 | USER string { conf.user = $2; }
241 vhost : SERVER string {
243 TAILQ_INSERT_HEAD(&hosts, host, vhosts);
245 loc = new_location();
246 TAILQ_INSERT_HEAD(&host->locations, loc, locations);
248 TAILQ_INIT(&host->proxies);
250 loc->match = xstrdup("*");
253 if (strstr($2, "xn--") != NULL) {
254 yywarn("\"%s\" looks like punycode: you "
255 "should use the decoded hostname", $2);
257 } '{' optnl servbody '}' {
258 if (host->cert == NULL || host->key == NULL)
259 yyerror("invalid vhost definition: %s", $2);
261 | error '}' { yyerror("bad server directive"); }
264 servbody : /* empty */
265 | servbody servopt optnl
266 | servbody location optnl
267 | servbody proxy optnl
270 servopt : ALIAS string {
273 a = xcalloc(1, sizeof(*a));
275 if (TAILQ_EMPTY(&host->aliases))
276 TAILQ_INSERT_HEAD(&host->aliases, a, aliases);
278 TAILQ_INSERT_TAIL(&host->aliases, a, aliases);
281 only_once(host->cert, "cert");
282 host->cert = ensure_absolute_path($2);
285 only_once(host->key, "key");
286 host->key = ensure_absolute_path($2);
289 only_once(host->ocsp, "ocsp");
290 host->ocsp = ensure_absolute_path($2);
292 | PARAM string '=' string {
293 add_param($2, $4, 0);
298 proxy : PROXY { advance_proxy(); }
299 proxy_matches '{' optnl proxy_opts '}' {
300 if (proxy->host == NULL)
301 yyerror("invalid proxy block: missing `relay-to' option");
303 if ((proxy->cert == NULL && proxy->key != NULL) ||
304 (proxy->cert != NULL && proxy->key == NULL))
305 yyerror("invalid proxy block: missing cert or key");
309 proxy_matches : /* empty */
310 | proxy_matches proxy_match
313 proxy_match : PROTO string {
314 only_once(proxy->match_proto, "proxy proto");
315 free(proxy->match_proto);
316 proxy->match_proto = $2;
319 only_once(proxy->match_host, "proxy for-host");
320 free(proxy->match_host);
321 parsehp($2, &proxy->match_host, &proxy->match_port, "10965");
325 proxy_opts : /* empty */
326 | proxy_opts proxy_opt optnl
329 proxy_opt : CERT string {
330 only_once(proxy->cert, "proxy cert");
331 tls_unload_file(proxy->cert, proxy->certlen);
332 ensure_absolute_path($2);
333 proxy->cert = tls_load_file($2, &proxy->certlen, NULL);
334 if (proxy->cert == NULL)
335 yyerror("can't load cert %s", $2);
339 only_once(proxy->key, "proxy key");
340 tls_unload_file(proxy->key, proxy->keylen);
341 ensure_absolute_path($2);
342 proxy->key = tls_load_file($2, &proxy->keylen, NULL);
343 if (proxy->key == NULL)
344 yyerror("can't load key %s", $2);
348 if (tls_config_parse_protocols(&proxy->protocols, $2) == -1)
349 yyerror("invalid protocols string \"%s\"", $2);
353 only_once(proxy->host, "proxy relay-to");
355 parsehp($2, &proxy->host, &proxy->port, "1965");
357 | REQUIRE CLIENT CA string {
358 only_once(proxy->reqca, "require client ca");
359 ensure_absolute_path($4);
360 if ((proxy->reqca = load_ca($4)) == NULL)
361 yyerror("couldn't load ca cert: %s", $4);
365 only_once(proxy->sni, "proxy sni");
373 proxy->noverifyname = !$2;
377 location : LOCATION { advance_loc(); } string '{' optnl locopts '}' {
378 /* drop the starting '/' if any */
380 memmove($3, $3+1, strlen($3));
386 locopts : /* empty */
387 | locopts locopt optnl
390 locopt : AUTO INDEX bool { loc->auto_index = $3 ? 1 : -1; }
391 | BLOCK RETURN NUM string {
392 only_once(loc->block_fmt, "block");
393 loc->block_fmt = check_block_fmt($4);
394 loc->block_code = check_block_code($3);
397 only_once(loc->block_fmt, "block");
398 loc->block_fmt = xstrdup("temporary failure");
399 loc->block_code = check_block_code($3);
400 if ($3 >= 30 && $3 < 40)
401 yyerror("missing `meta' for block return %d", $3);
404 only_once(loc->block_fmt, "block");
405 loc->block_fmt = xstrdup("temporary failure");
406 loc->block_code = 40;
408 | DEFAULT TYPE string {
409 only_once(loc->default_mime, "default type");
410 loc->default_mime = $3;
414 only_once(loc->index, "index");
418 only_once(loc->lang, "lang");
421 | LOG bool { loc->disable_log = !$2; }
422 | REQUIRE CLIENT CA string {
423 only_once(loc->reqca, "require client ca");
424 ensure_absolute_path($4);
425 if ((loc->reqca = load_ca($4)) == NULL)
426 yyerror("couldn't load ca cert: %s", $4);
430 only_once(loc->dir, "root");
431 loc->dir = ensure_absolute_path($2);
433 | STRIP NUM { loc->strip = check_strip_no($2); }
436 fastcgi : SPAWN string {
437 only_oncei(loc->fcgi, "fastcgi");
438 loc->fcgi = fastcgi_conf(NULL, NULL, $2);
441 only_oncei(loc->fcgi, "fastcgi");
442 loc->fcgi = fastcgi_conf($1, NULL, NULL);
444 | TCP string PORT NUM {
446 if (asprintf(&c, "%d", $4) == -1)
448 only_oncei(loc->fcgi, "fastcgi");
449 loc->fcgi = fastcgi_conf($2, c, NULL);
452 only_oncei(loc->fcgi, "fastcgi");
453 loc->fcgi = fastcgi_conf($2, xstrdup("9000"), NULL);
455 | TCP string PORT string {
456 only_oncei(loc->fcgi, "fastcgi");
457 loc->fcgi = fastcgi_conf($2, $4, NULL);
461 types : TYPES '{' optnl mediaopts_l '}' {
462 conf.mime.skip_defaults = 1;
466 mediaopts_l : mediaopts_l mediaoptsl nl
470 mediaoptsl : STRING { current_media = $1; } medianames_l optsemicolon
474 medianames_l : medianames_l medianamesl
478 medianamesl : numberstring {
479 if (add_mime(&conf.mime, current_media, $1) == -1)
487 optnl : '\n' optnl /* zero or more newlines */
488 | ';' optnl /* semicolons too */
498 static const struct keyword {
502 /* these MUST be sorted */
510 {"default", DEFAULT},
511 {"fastcgi", FASTCGI},
512 {"for-host", FOR_HOST},
513 {"include", INCLUDE},
518 {"location", LOCATION},
527 {"prefork", PREFORK},
529 {"protocols", PROTOCOLS},
531 {"relay-to", RELAY_TO},
532 {"require", REQUIRE},
543 {"use-tls", USE_TLS},
545 {"verifyname", VERIFYNAME},
549 yyerror(const char *msg, ...)
556 fprintf(stderr, "%s:%d error: ", config_path, yylval.lineno);
557 vfprintf(stderr, msg, ap);
558 fprintf(stderr, "\n");
563 yywarn(const char *msg, ...)
568 fprintf(stderr, "%s:%d warning: ", config_path, yylval.lineno);
569 vfprintf(stderr, msg, ap);
570 fprintf(stderr, "\n");
575 kw_cmp(const void *k, const void *e)
577 return strcmp(k, ((struct keyword *)e)->word);
583 const struct keyword *p;
585 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
586 sizeof(keywords[0]), kw_cmp);
594 #define START_EXPAND 1
595 #define DONE_EXPAND 2
597 static int expanding;
605 if (file->ungetpos > 0)
606 c = file->ungetbuf[--file->ungetpos];
608 c = getc(file->stream);
610 if (c == START_EXPAND)
612 else if (c == DONE_EXPAND)
626 if ((c = igetc()) == EOF) {
627 yyerror("reached end of file while parsing "
629 if (file == topfile || popfile() == EOF)
636 while ((c = igetc()) == '\\') {
642 yylval.lineno = file->lineno;
648 * Fake EOL when hit EOF for the first time. This gets line
649 * count right if last line in included file is syntactically
650 * invalid and has no newline.
652 if (file->eof_reached == 0) {
653 file->eof_reached = 1;
657 if (file == topfile || popfile() == EOF)
671 if (file->ungetpos >= file->ungetsize) {
672 void *p = reallocarray(file->ungetbuf, file->ungetsize, 2);
676 file->ungetsize *= 2;
678 file->ungetbuf[file->ungetpos++] = c;
686 /* Skip to either EOF or the first real EOL. */
709 while ((c = lgetc(0)) == ' ' || c == '\t')
712 yylval.lineno = file->lineno;
714 while ((c = lgetc(0)) != '\n' && c != EOF)
716 if (c == '$' && !expanding) {
718 if ((c = lgetc(0)) == EOF)
720 if (p + 1 >= buf + sizeof(buf) -1) {
721 yyerror("string too long");
724 if (isalnum(c) || c == '_') {
734 yyerror("macro `%s' not defined", buf);
737 yylval.v.string = xstrdup(val);
740 if (c == '@' && !expanding) {
742 if ((c = lgetc(0)) == EOF)
745 if (p + 1 >= buf + sizeof(buf) - 1) {
746 yyerror("string too long");
749 if (isalnum(c) || c == '_') {
759 yyerror("macro '%s' not defined", buf);
762 p = val + strlen(val) - 1;
763 lungetc(DONE_EXPAND);
768 lungetc(START_EXPAND);
777 if ((c = lgetc(quotec)) == EOF)
782 } else if (c == '\\') {
783 if ((next = lgetc(quotec)) == EOF)
785 if (next == quotec || next == ' ' ||
788 else if (next == '\n') {
793 } else if (c == quotec) {
796 } else if (c == '\0') {
797 yyerror("invalid syntax");
800 if (p + 1 >= buf + sizeof(buf) - 1) {
801 yyerror("string too long");
806 yylval.v.string = strdup(buf);
807 if (yylval.v.string == NULL)
808 err(1, "yylex: strdup");
812 #define allowed_to_end_number(x) \
813 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
815 if (c == '-' || isdigit(c)) {
818 if ((size_t)(p-buf) >= sizeof(buf)) {
819 yyerror("string too long");
822 } while ((c = lgetc(0)) != EOF && isdigit(c));
824 if (p == buf + 1 && buf[0] == '-')
826 if (c == EOF || allowed_to_end_number(c)) {
827 const char *errstr = NULL;
830 yylval.v.number = strtonum(buf, LLONG_MIN,
833 yyerror("\"%s\" invalid number: %s",
848 #define allowed_in_string(x) \
849 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
850 x != '{' && x != '}' && \
851 x != '!' && x != '=' && x != '#' && \
852 x != ',' && x != ';'))
854 if (isalnum(c) || c == ':' || c == '_') {
857 if ((size_t)(p-buf) >= sizeof(buf)) {
858 yyerror("string too long");
861 } while ((c = lgetc(0)) != EOF && (allowed_in_string(c)));
864 if ((token = lookup(buf)) == STRING)
865 yylval.v.string = xstrdup(buf);
869 yylval.lineno = file->lineno;
878 pushfile(const char *name, int secret)
882 nfile = xcalloc(1, sizeof(*nfile));
883 nfile->name = xstrdup(name);
884 if ((nfile->stream = fopen(nfile->name, "r")) == NULL) {
885 log_warn(NULL, "can't open %s: %s", nfile->name,
891 nfile->lineno = TAILQ_EMPTY(&files) ? 1 : 0;
892 nfile->ungetsize = 16;
893 nfile->ungetbuf = xcalloc(1, nfile->ungetsize);
894 TAILQ_INSERT_TAIL(&files, nfile, entry);
903 if ((prev = TAILQ_PREV(file, files, entry)) != NULL)
904 prev->errors += file->errors;
906 TAILQ_REMOVE(&files, file, entry);
907 fclose(file->stream);
909 free(file->ungetbuf);
912 return file ? 0 : EOF;
916 parse_conf(const char *filename)
918 struct sym *sym, *next;
920 file = pushfile(filename, 0);
926 errors = file->errors;
929 /* Free macros and check which have not been used. */
930 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
931 /* TODO: warn if !sym->used */
935 TAILQ_REMOVE(&symhead, sym, entry);
948 /* struct location *l; */
949 /* struct envlist *e; */
950 /* struct alist *a; */
952 if (conf.chroot != NULL)
953 printf("chroot \"%s\"\n", conf.chroot);
954 printf("ipv6 %s\n", conf.ipv6 ? "on" : "off");
955 /* XXX: defined mimes? */
956 printf("port %d\n", conf.port);
957 printf("prefork %d\n", conf.prefork);
958 /* XXX: protocols? */
959 if (conf.user != NULL)
960 printf("user \"%s\"\n", conf.user);
962 TAILQ_FOREACH(h, &hosts, vhosts) {
963 printf("\nserver \"%s\" {\n", h->domain);
964 printf(" cert \"%s\"\n", h->cert);
965 printf(" key \"%s\"\n", h->key);
966 /* TODO: print locations... */
972 symset(const char *name, const char *val, int persist)
976 TAILQ_FOREACH(sym, &symhead, entry) {
977 if (!strcmp(name, sym->name))
987 TAILQ_REMOVE(&symhead, sym, entry);
992 sym = xcalloc(1, sizeof(*sym));
993 sym->name = xstrdup(name);
994 sym->val = xstrdup(val);
996 sym->persist = persist;
998 TAILQ_INSERT_TAIL(&symhead, sym, entry);
1003 cmdline_symset(char *s)
1008 if ((val = strrchr(s, '=')) == NULL)
1010 sym = xcalloc(1, val - s + 1);
1011 memcpy(sym, s, val - s);
1012 ret = symset(sym, val + 1, 1);
1018 symget(const char *nam)
1022 TAILQ_FOREACH(sym, &symhead, entry) {
1023 if (strcmp(nam, sym->name) == 0) {
1034 return xcalloc(1, sizeof(struct vhost));
1042 l = xcalloc(1, sizeof(*l));
1053 conf.can_open_sockets = 1;
1055 p = xcalloc(1, sizeof(*p));
1056 p->protocols = TLS_PROTOCOLS_DEFAULT;
1061 ensure_absolute_path(char *path)
1063 if (path == NULL || *path != '/')
1064 yyerror("not an absolute path: %s", path);
1069 check_block_code(int n)
1071 if (n < 10 || n >= 70 || (n >= 20 && n <= 29))
1072 yyerror("invalid block code %d", n);
1077 check_block_fmt(char *fmt)
1081 for (s = fmt; *s; ++s) {
1092 yyerror("invalid format specifier %%%c", *s);
1100 check_strip_no(int n)
1103 yyerror("invalid strip number %d", n);
1108 check_port_num(int n)
1110 if (n <= 0 || n >= UINT16_MAX)
1111 yyerror("port number is %s: %d",
1112 n <= 0 ? "too small" : "too large",
1118 check_prefork_num(int n)
1120 if (n <= 0 || n >= PROC_MAX)
1121 yyerror("invalid prefork number %d", n);
1128 loc = new_location();
1129 TAILQ_INSERT_TAIL(&host->locations, loc, locations);
1135 proxy = new_proxy();
1136 TAILQ_INSERT_TAIL(&host->proxies, proxy, proxies);
1140 parsehp(char *str, char **host, const char **port, const char *def)
1147 if ((at = strchr(str, ':')) != NULL) {
1153 strtonum(*port, 1, UINT16_MAX, &errstr);
1155 yyerror("port is %s: %s", errstr, *port);
1159 only_once(const void *ptr, const char *name)
1162 yyerror("`%s' specified more than once", name);
1166 only_oncei(int i, const char *name)
1169 yyerror("`%s' specified more than once", name);
1173 fastcgi_conf(char *path, char *port, char *prog)
1178 conf.can_open_sockets = 1;
1180 for (i = 0; i < FCGI_MAX; ++i) {
1183 if (f->path == NULL) {
1191 /* XXX: what to do with prog? */
1192 if (!strcmp(f->path, path) &&
1193 ((port == NULL && f->port == NULL) ||
1194 !strcmp(f->port, port))) {
1201 yyerror("too much `fastcgi' rules defined.");
1206 add_param(char *name, char *val, int env)
1216 e = xcalloc(1, sizeof(*e));
1220 TAILQ_INSERT_HEAD(h, e, envs);
1222 TAILQ_INSERT_TAIL(h, e, envs);