4 * Copyright (c) 2021, 2022 Omar Polo <op@omarpolo.com>
5 * Copyright (c) 2018 Florian Obser <florian@openbsd.org>
6 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
7 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
8 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
9 * Copyright (c) 2001 Markus Friedl. All rights reserved.
10 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
11 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
13 * Permission to use, copy, modify, and distribute this software for any
14 * purpose with or without fee is hereby granted, provided that the above
15 * copyright notice and this permission notice appear in all copies.
17 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
18 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
20 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
21 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
22 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
23 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
38 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
40 TAILQ_ENTRY(file) entry;
51 struct file *pushfile(const char *, int);
55 void yyerror(const char *, ...)
56 __attribute__((__format__ (printf, 1, 2)))
57 __attribute__((__nonnull__ (1)));
58 void yywarn(const char *, ...)
59 __attribute__((__format__ (printf, 1, 2)))
60 __attribute__((__nonnull__ (1)));
61 int kw_cmp(const void *, const void *);
73 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
75 TAILQ_ENTRY(sym) entry;
82 int symset(const char *, const char *, int);
83 char *symget(const char *);
85 struct vhost *new_vhost(void);
86 struct location *new_location(void);
87 struct proxy *new_proxy(void);
88 char *ensure_absolute_path(char*);
89 int check_block_code(int);
90 char *check_block_fmt(char*);
91 int check_strip_no(int);
92 int check_port_num(int);
93 int check_prefork_num(int);
94 void advance_loc(void);
95 void advance_proxy(void);
96 void parsehp(char *, char **, const char **, const char *);
97 int fastcgi_conf(const char *, const char *);
98 void add_param(char *, char *);
99 int getservice(const char *);
101 static struct vhost *host;
102 static struct location *loc;
103 static struct proxy *proxy;
104 static char *current_media;
118 /* %define parse.error verbose */
122 %token CA CERT CHROOT CLIENT
124 %token FASTCGI FOR_HOST
125 %token INCLUDE INDEX IPV6
127 %token LANG LOCATION LOG
129 %token PARAM PORT PREFORK PROTO PROTOCOLS PROXY
130 %token RELAY_TO REQUIRE RETURN ROOT
131 %token SERVER SNI STRIP
132 %token TCP TOEXT TYPE TYPES
138 %token <v.string> STRING
139 %token <v.number> NUM
141 %type <v.number> bool proxy_port
142 %type <v.string> string numberstring
153 | conf error '\n' { file->errors++; }
156 include : INCLUDE STRING {
159 if ((nfile = pushfile($2, 0)) == NULL) {
160 yyerror("failed to include file %s", $2);
171 bool : ON { $$ = 1; }
175 string : string STRING {
176 if (asprintf(&$$, "%s%s", $1, $2) == -1) {
179 yyerror("string: asprintf: %s", strerror(errno));
190 if (asprintf(&s, "%d", $1) == -1) {
191 yyerror("asprintf: number");
199 varset : STRING '=' string {
202 if (isspace((unsigned char)*s)) {
203 yyerror("macro name cannot contain "
216 option : CHROOT string {
217 if (strlcpy(conf.chroot, $2, sizeof(conf.chroot)) >=
219 yyerror("chroot path too long");
222 | IPV6 bool { conf.ipv6 = $2; }
223 | PORT NUM { conf.port = check_port_num($2); }
224 | PREFORK NUM { conf.prefork = check_prefork_num($2); }
226 if (tls_config_parse_protocols(&conf.protos, $2) == -1)
227 yyerror("invalid protocols string \"%s\"", $2);
231 if (strlcpy(conf.user, $2, sizeof(conf.user)) >=
233 yyerror("user name too long");
238 vhost : SERVER string {
240 TAILQ_INSERT_HEAD(&hosts, host, vhosts);
242 loc = new_location();
243 TAILQ_INSERT_HEAD(&host->locations, loc, locations);
245 TAILQ_INIT(&host->proxies);
247 (void) strlcpy(loc->match, "*", sizeof(loc->match));
248 (void) strlcpy(host->domain, $2, sizeof(host->domain));
250 if (strstr($2, "xn--") != NULL) {
251 yywarn("\"%s\" looks like punycode: you "
252 "should use the decoded hostname", $2);
256 } '{' optnl servbody '}' {
257 if (*host->cert == '\0' || *host->key == '\0')
258 yyerror("invalid vhost definition: %s", $2);
260 | error '}' { yyerror("bad server directive"); }
263 servbody : /* empty */
264 | servbody servopt optnl
265 | servbody location optnl
266 | servbody proxy optnl
269 servopt : ALIAS string {
272 a = xcalloc(1, sizeof(*a));
273 (void) strlcpy(a->alias, $2, sizeof(a->alias));
275 TAILQ_INSERT_TAIL(&host->aliases, a, aliases);
278 ensure_absolute_path($2);
279 (void) strlcpy(host->cert, $2, sizeof(host->cert));
283 ensure_absolute_path($2);
284 (void) strlcpy(host->key, $2, sizeof(host->key));
288 ensure_absolute_path($2);
289 (void) strlcpy(host->ocsp, $2, sizeof(host->ocsp));
292 | PARAM string '=' string {
298 proxy : PROXY { advance_proxy(); }
299 proxy_matches '{' optnl proxy_opts '}' {
300 if (*proxy->host == '\0')
301 yyerror("invalid proxy block: missing `relay-to' option");
303 if ((proxy->cert == NULL && proxy->key != NULL) ||
304 (proxy->cert != NULL && proxy->key == NULL))
305 yyerror("invalid proxy block: missing cert or key");
309 proxy_matches : /* empty */
310 | proxy_matches proxy_match
313 proxy_port : /* empty */ { $$ = 1965; }
315 if (($$ = getservice($2)) == -1)
316 yyerror("invalid port number %s", $2);
319 | PORT NUM { $$ = $2; }
322 proxy_match : PROTO string {
323 (void) strlcpy(proxy->match_proto, $2, sizeof(proxy->match_proto));
326 | FOR_HOST string proxy_port {
327 (void) strlcpy(proxy->match_host, $2, sizeof(proxy->match_host));
328 (void) snprintf(proxy->match_port, sizeof(proxy->match_port),
334 proxy_opts : /* empty */
335 | proxy_opts proxy_opt optnl
338 proxy_opt : CERT string {
339 tls_unload_file(proxy->cert, proxy->certlen);
340 ensure_absolute_path($2);
341 proxy->cert = tls_load_file($2, &proxy->certlen, NULL);
342 if (proxy->cert == NULL)
343 yyerror("can't load cert %s", $2);
347 tls_unload_file(proxy->key, proxy->keylen);
348 ensure_absolute_path($2);
349 proxy->key = tls_load_file($2, &proxy->keylen, NULL);
350 if (proxy->key == NULL)
351 yyerror("can't load key %s", $2);
355 if (tls_config_parse_protocols(&proxy->protocols, $2) == -1)
356 yyerror("invalid protocols string \"%s\"", $2);
359 | RELAY_TO string proxy_port {
360 (void) strlcpy(proxy->host, $2, sizeof(proxy->host));
361 (void) snprintf(proxy->port, sizeof(proxy->port),
365 | REQUIRE CLIENT CA string {
366 ensure_absolute_path($4);
367 if ((proxy->reqca = load_ca($4)) == NULL)
368 yyerror("couldn't load ca cert: %s", $4);
372 (void) strlcpy(proxy->sni, $2, sizeof(proxy->sni));
379 proxy->noverifyname = !$2;
383 location : LOCATION { advance_loc(); } string '{' optnl locopts '}' {
384 /* drop the starting '/' if any */
386 memmove($3, $3+1, strlen($3));
387 (void) strlcpy(loc->match, $3, sizeof(loc->match));
393 locopts : /* empty */
394 | locopts locopt optnl
397 locopt : AUTO INDEX bool { loc->auto_index = $3 ? 1 : -1; }
398 | BLOCK RETURN NUM string {
400 (void) strlcpy(loc->block_fmt, $4, sizeof(loc->block_fmt));
401 loc->block_code = check_block_code($3);
405 (void) strlcpy(loc->block_fmt, "temporary failure",
406 sizeof(loc->block_fmt));
407 loc->block_code = check_block_code($3);
408 if ($3 >= 30 && $3 < 40)
409 yyerror("missing `meta' for block return %d", $3);
412 (void) strlcpy(loc->block_fmt, "temporary failure",
413 sizeof(loc->block_fmt));
414 loc->block_code = 40;
416 | DEFAULT TYPE string {
417 (void) strlcpy(loc->default_mime, $3,
418 sizeof(loc->default_mime));
423 (void) strlcpy(loc->index, $2, sizeof(loc->index));
427 (void) strlcpy(loc->lang, $2,
431 | LOG bool { loc->disable_log = !$2; }
432 | REQUIRE CLIENT CA string {
433 ensure_absolute_path($4);
434 if ((loc->reqca = load_ca($4)) == NULL)
435 yyerror("couldn't load ca cert: %s", $4);
439 (void) strlcpy(loc->dir, $2, sizeof(loc->dir));
442 | STRIP NUM { loc->strip = check_strip_no($2); }
446 loc->fcgi = fastcgi_conf($1, NULL);
449 | TCP string PORT NUM {
451 if (asprintf(&c, "%d", $4) == -1)
453 loc->fcgi = fastcgi_conf($2, c);
457 loc->fcgi = fastcgi_conf($2, "9000");
460 | TCP string PORT string {
461 loc->fcgi = fastcgi_conf($2, $4);
467 types : TYPES '{' optnl mediaopts_l '}' ;
469 mediaopts_l : mediaopts_l mediaoptsl nl
473 mediaoptsl : STRING {
476 } medianames_l optsemicolon
480 medianames_l : medianames_l medianamesl
484 medianamesl : numberstring {
485 if (add_mime(&conf.mime, current_media, $1) == -1)
494 optnl : '\n' optnl /* zero or more newlines */
495 | ';' optnl /* semicolons too */
505 static const struct keyword {
509 /* these MUST be sorted */
517 {"default", DEFAULT},
518 {"fastcgi", FASTCGI},
519 {"for-host", FOR_HOST},
520 {"include", INCLUDE},
525 {"location", LOCATION},
532 {"prefork", PREFORK},
534 {"protocols", PROTOCOLS},
536 {"relay-to", RELAY_TO},
537 {"require", REQUIRE},
547 {"use-tls", USE_TLS},
549 {"verifyname", VERIFYNAME},
553 yyerror(const char *msg, ...)
560 fprintf(stderr, "%s:%d error: ", config_path, yylval.lineno);
561 vfprintf(stderr, msg, ap);
562 fprintf(stderr, "\n");
567 yywarn(const char *msg, ...)
572 fprintf(stderr, "%s:%d warning: ", config_path, yylval.lineno);
573 vfprintf(stderr, msg, ap);
574 fprintf(stderr, "\n");
579 kw_cmp(const void *k, const void *e)
581 return strcmp(k, ((struct keyword *)e)->word);
587 const struct keyword *p;
589 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
590 sizeof(keywords[0]), kw_cmp);
598 #define START_EXPAND 1
599 #define DONE_EXPAND 2
601 static int expanding;
609 if (file->ungetpos > 0)
610 c = file->ungetbuf[--file->ungetpos];
612 c = getc(file->stream);
614 if (c == START_EXPAND)
616 else if (c == DONE_EXPAND)
630 if ((c = igetc()) == EOF) {
631 yyerror("reached end of file while parsing "
633 if (file == topfile || popfile() == EOF)
640 while ((c = igetc()) == '\\') {
646 yylval.lineno = file->lineno;
652 * Fake EOL when hit EOF for the first time. This gets line
653 * count right if last line in included file is syntactically
654 * invalid and has no newline.
656 if (file->eof_reached == 0) {
657 file->eof_reached = 1;
661 if (file == topfile || popfile() == EOF)
675 if (file->ungetpos >= file->ungetsize) {
676 void *p = reallocarray(file->ungetbuf, file->ungetsize, 2);
680 file->ungetsize *= 2;
682 file->ungetbuf[file->ungetpos++] = c;
690 /* Skip to either EOF or the first real EOL. */
713 while ((c = lgetc(0)) == ' ' || c == '\t')
716 yylval.lineno = file->lineno;
718 while ((c = lgetc(0)) != '\n' && c != EOF)
720 if (c == '$' && !expanding) {
722 if ((c = lgetc(0)) == EOF)
724 if (p + 1 >= buf + sizeof(buf) -1) {
725 yyerror("string too long");
728 if (isalnum(c) || c == '_') {
738 yyerror("macro `%s' not defined", buf);
741 yylval.v.string = xstrdup(val);
744 if (c == '@' && !expanding) {
746 if ((c = lgetc(0)) == EOF)
749 if (p + 1 >= buf + sizeof(buf) - 1) {
750 yyerror("string too long");
753 if (isalnum(c) || c == '_') {
763 yyerror("macro '%s' not defined", buf);
766 p = val + strlen(val) - 1;
767 lungetc(DONE_EXPAND);
772 lungetc(START_EXPAND);
781 if ((c = lgetc(quotec)) == EOF)
786 } else if (c == '\\') {
787 if ((next = lgetc(quotec)) == EOF)
789 if (next == quotec || next == ' ' ||
792 else if (next == '\n') {
797 } else if (c == quotec) {
800 } else if (c == '\0') {
801 yyerror("invalid syntax");
804 if (p + 1 >= buf + sizeof(buf) - 1) {
805 yyerror("string too long");
810 yylval.v.string = strdup(buf);
811 if (yylval.v.string == NULL)
812 fatal("yylex: strdup");
816 #define allowed_to_end_number(x) \
817 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
819 if (c == '-' || isdigit(c)) {
822 if ((size_t)(p-buf) >= sizeof(buf)) {
823 yyerror("string too long");
826 } while ((c = lgetc(0)) != EOF && isdigit(c));
828 if (p == buf + 1 && buf[0] == '-')
830 if (c == EOF || allowed_to_end_number(c)) {
831 const char *errstr = NULL;
834 yylval.v.number = strtonum(buf, LLONG_MIN,
837 yyerror("\"%s\" invalid number: %s",
852 #define allowed_in_string(x) \
853 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
854 x != '{' && x != '}' && \
855 x != '!' && x != '=' && x != '#' && \
856 x != ',' && x != ';'))
858 if (isalnum(c) || c == ':' || c == '_') {
861 if ((size_t)(p-buf) >= sizeof(buf)) {
862 yyerror("string too long");
865 } while ((c = lgetc(0)) != EOF && (allowed_in_string(c)));
868 if ((token = lookup(buf)) == STRING)
869 yylval.v.string = xstrdup(buf);
873 yylval.lineno = file->lineno;
882 pushfile(const char *name, int secret)
886 nfile = xcalloc(1, sizeof(*nfile));
887 nfile->name = xstrdup(name);
888 if ((nfile->stream = fopen(nfile->name, "r")) == NULL) {
889 log_warn("can't open %s", nfile->name);
894 nfile->lineno = TAILQ_EMPTY(&files) ? 1 : 0;
895 nfile->ungetsize = 16;
896 nfile->ungetbuf = xcalloc(1, nfile->ungetsize);
897 TAILQ_INSERT_TAIL(&files, nfile, entry);
906 if ((prev = TAILQ_PREV(file, files, entry)) != NULL)
907 prev->errors += file->errors;
909 TAILQ_REMOVE(&files, file, entry);
910 fclose(file->stream);
912 free(file->ungetbuf);
915 return file ? 0 : EOF;
919 parse_conf(const char *filename)
921 struct sym *sym, *next;
923 file = pushfile(filename, 0);
929 errors = file->errors;
932 /* Free macros and check which have not been used. */
933 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
934 /* TODO: warn if !sym->used */
938 TAILQ_REMOVE(&symhead, sym, entry);
951 /* struct location *l; */
952 /* struct envlist *e; */
953 /* struct alist *a; */
955 if (*conf.chroot != '\0')
956 printf("chroot \"%s\"\n", conf.chroot);
957 printf("ipv6 %s\n", conf.ipv6 ? "on" : "off");
958 /* XXX: defined mimes? */
959 printf("port %d\n", conf.port);
960 printf("prefork %d\n", conf.prefork);
961 /* XXX: protocols? */
962 if (*conf.user != '\0')
963 printf("user \"%s\"\n", conf.user);
965 TAILQ_FOREACH(h, &hosts, vhosts) {
966 printf("\nserver \"%s\" {\n", h->domain);
967 printf(" cert \"%s\"\n", h->cert);
968 printf(" key \"%s\"\n", h->key);
969 /* TODO: print locations... */
975 symset(const char *name, const char *val, int persist)
979 TAILQ_FOREACH(sym, &symhead, entry) {
980 if (!strcmp(name, sym->name))
990 TAILQ_REMOVE(&symhead, sym, entry);
995 sym = xcalloc(1, sizeof(*sym));
996 sym->name = xstrdup(name);
997 sym->val = xstrdup(val);
999 sym->persist = persist;
1001 TAILQ_INSERT_TAIL(&symhead, sym, entry);
1006 cmdline_symset(char *s)
1011 if ((val = strrchr(s, '=')) == NULL)
1013 sym = xcalloc(1, val - s + 1);
1014 memcpy(sym, s, val - s);
1015 ret = symset(sym, val + 1, 1);
1021 symget(const char *nam)
1025 TAILQ_FOREACH(sym, &symhead, entry) {
1026 if (strcmp(nam, sym->name) == 0) {
1039 h = xcalloc(1, sizeof(*h));
1040 TAILQ_INIT(&h->locations);
1041 TAILQ_INIT(&h->params);
1042 TAILQ_INIT(&h->aliases);
1043 TAILQ_INIT(&h->proxies);
1052 l = xcalloc(1, sizeof(*l));
1063 p = xcalloc(1, sizeof(*p));
1064 p->protocols = TLS_PROTOCOLS_DEFAULT;
1069 ensure_absolute_path(char *path)
1071 if (path == NULL || *path != '/')
1072 yyerror("not an absolute path: %s", path);
1077 check_block_code(int n)
1079 if (n < 10 || n >= 70 || (n >= 20 && n <= 29))
1080 yyerror("invalid block code %d", n);
1085 check_block_fmt(char *fmt)
1089 for (s = fmt; *s; ++s) {
1100 yyerror("invalid format specifier %%%c", *s);
1108 check_strip_no(int n)
1111 yyerror("invalid strip number %d", n);
1116 check_port_num(int n)
1118 if (n <= 0 || n >= UINT16_MAX)
1119 yyerror("port number is %s: %d",
1120 n <= 0 ? "too small" : "too large",
1126 check_prefork_num(int n)
1128 if (n <= 0 || n >= PREFORK_MAX)
1129 yyerror("invalid prefork number %d", n);
1136 loc = new_location();
1137 TAILQ_INSERT_TAIL(&host->locations, loc, locations);
1143 proxy = new_proxy();
1144 TAILQ_INSERT_TAIL(&host->proxies, proxy, proxies);
1148 parsehp(char *str, char **host, const char **port, const char *def)
1155 if ((at = strchr(str, ':')) != NULL) {
1161 strtonum(*port, 1, UINT16_MAX, &errstr);
1163 yyerror("port is %s: %s", errstr, *port);
1167 fastcgi_conf(const char *path, const char *port)
1172 for (i = 0; i < FCGI_MAX; ++i) {
1175 if (*f->path == '\0') {
1177 (void) strlcpy(f->path, path, sizeof(f->path));
1179 (void) strlcpy(f->port, port, sizeof(f->port));
1183 if (!strcmp(f->path, path) &&
1184 ((port == NULL && *f->port == '\0') ||
1185 !strcmp(f->port, port)))
1189 yyerror("too much `fastcgi' rules defined.");
1194 add_param(char *name, char *val)
1197 struct envhead *h = &host->params;
1199 e = xcalloc(1, sizeof(*e));
1200 (void) strlcpy(e->name, name, sizeof(e->name));
1201 (void) strlcpy(e->value, val, sizeof(e->value));
1202 TAILQ_INSERT_TAIL(h, e, envs);
1206 getservice(const char *n)
1212 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1214 s = getservbyname(n, "tcp");
1216 s = getservbyname(n, "udp");
1219 return (ntohs(s->s_port));
1222 return ((unsigned short)llval);