4 * Copyright (c) 2021 Omar Polo <op@omarpolo.com>
5 * Copyright (c) 2018 Florian Obser <florian@openbsd.org>
6 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
7 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
8 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
9 * Copyright (c) 2001 Markus Friedl. All rights reserved.
10 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
11 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
13 * Permission to use, copy, modify, and distribute this software for any
14 * purpose with or without fee is hereby granted, provided that the above
15 * copyright notice and this permission notice appear in all copies.
17 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
18 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
20 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
21 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
22 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
23 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
35 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
37 TAILQ_ENTRY(file) entry;
48 struct file *pushfile(const char *, int);
52 void yyerror(const char *, ...)
53 __attribute__((__format__ (printf, 1, 2)))
54 __attribute__((__nonnull__ (1)));
55 void yywarn(const char *, ...)
56 __attribute__((__format__ (printf, 1, 2)))
57 __attribute__((__nonnull__ (1)));
58 int kw_cmp(const void *, const void *);
70 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
72 TAILQ_ENTRY(sym) entry;
79 int symset(const char *, const char *, int);
80 char *symget(const char *);
82 struct vhost *new_vhost(void);
83 struct location *new_location(void);
84 char *ensure_absolute_path(char*);
85 int check_block_code(int);
86 char *check_block_fmt(char*);
87 int check_strip_no(int);
88 int check_port_num(int);
89 int check_prefork_num(int);
90 void advance_loc(void);
91 void only_once(const void*, const char*);
92 void only_oncei(int, const char*);
93 int fastcgi_conf(char *, char *, char *);
94 void add_param(char *, char *, int);
96 static struct vhost *host;
97 static struct location *loc;
111 /* %define parse.error verbose */
115 %token CA CERT CGI CHROOT CLIENT
117 %token ENTRYPOINT ENV
119 %token INCLUDE INDEX IPV6
121 %token LANG LOCATION LOG
124 %token PARAM PORT PREFORK PROTOCOLS PROXY
125 %token RELAY_TO REQUIRE RETURN ROOT
126 %token SERVER SPAWN STRIP
127 %token TCP TOEXT TYPE USER
132 %token <v.string> STRING
133 %token <v.number> NUM
135 %type <v.number> bool
136 %type <v.string> string
146 | conf error '\n' { file->errors++; }
149 include : INCLUDE STRING {
152 if ((nfile = pushfile($2, 0)) == NULL) {
153 yyerror("failed to include file %s", $2);
164 bool : ON { $$ = 1; }
168 string : string STRING {
169 if (asprintf(&$$, "%s%s", $1, $2) == -1) {
172 yyerror("string: asprintf: %s", strerror(errno));
181 varset : STRING '=' string {
184 if (isspace((unsigned char)*s)) {
185 yyerror("macro name cannot contain "
198 option : CHROOT string { conf.chroot = $2; }
199 | IPV6 bool { conf.ipv6 = $2; }
200 | MIME STRING string {
201 yywarn("`mime MIME EXT' is deprecated and will be "
202 "removed in a future version, please use the new "
203 "syntax: `map MIME to-ext EXT'");
204 add_mime(&conf.mime, $2, $3);
206 | MAP string TOEXT string { add_mime(&conf.mime, $2, $4); }
207 | PORT NUM { conf.port = check_port_num($2); }
208 | PREFORK NUM { conf.prefork = check_prefork_num($2); }
210 if (tls_config_parse_protocols(&conf.protos, $2) == -1)
211 yyerror("invalid protocols string \"%s\"", $2);
213 | USER string { conf.user = $2; }
216 vhost : SERVER string {
218 TAILQ_INSERT_HEAD(&hosts, host, vhosts);
220 loc = new_location();
221 TAILQ_INSERT_HEAD(&host->locations, loc, locations);
223 loc->match = xstrdup("*");
226 if (strstr($2, "xn--") != NULL) {
227 yywarn("\"%s\" looks like punycode: you "
228 "should use the decoded hostname", $2);
230 } '{' optnl servopts locations '}' {
231 if (host->cert == NULL || host->key == NULL)
232 yyerror("invalid vhost definition: %s", $2);
234 | error '}' { yyerror("bad server directive"); }
237 servopts : /* empty */
238 | servopts servopt optnl
241 servopt : ALIAS string {
244 a = xcalloc(1, sizeof(*a));
246 if (TAILQ_EMPTY(&host->aliases))
247 TAILQ_INSERT_HEAD(&host->aliases, a, aliases);
249 TAILQ_INSERT_TAIL(&host->aliases, a, aliases);
252 only_once(host->cert, "cert");
253 host->cert = ensure_absolute_path($2);
256 only_once(host->cgi, "cgi");
257 /* drop the starting '/', if any */
259 memmove($2, $2+1, strlen($2));
262 | ENTRYPOINT string {
263 only_once(host->entrypoint, "entrypoint");
265 memmove($2, $2+1, strlen($2));
266 host->entrypoint = $2;
268 | ENV string '=' string {
269 add_param($2, $4, 1);
272 only_once(host->key, "key");
273 host->key = ensure_absolute_path($2);
276 only_once(host->ocsp, "ocsp");
277 host->ocsp = ensure_absolute_path($2);
279 | PARAM string '=' string {
280 add_param($2, $4, 0);
286 proxy : PROXY proxy_opt
287 | PROXY '{' optnl proxy_opts '}'
290 proxy_opts : /* empty */
291 | proxy_opts proxy_opt optnl
294 proxy_opt : CERT string {
295 struct proxy *p = &host->proxy;
297 only_once(p->cert, "proxy cert");
298 ensure_absolute_path($2);
299 p->cert = tls_load_file($2, &p->certlen, NULL);
301 yyerror("can't load cert %s", $2);
304 struct proxy *p = &host->proxy;
306 only_once(p->key, "proxy key");
307 ensure_absolute_path($2);
308 p->key = tls_load_file($2, &p->keylen, NULL);
310 yyerror("can't load key %s", $2);
313 struct proxy *p = &host->proxy;
315 if (tls_config_parse_protocols(&p->protocols, $2) == -1)
316 yyerror("invalid protocols string \"%s\"", $2);
321 struct proxy *p = &host->proxy;
323 only_once(p->host, "proxy relay-to");
326 if ((at = strchr($2, ':')) != NULL) {
332 strtonum(p->port, 1, UINT16_MAX, &errstr);
334 yyerror("proxy port is %s: %s", errstr,
338 host->proxy.noverifyname = !$2;
342 locations : /* empty */
343 | locations location optnl
346 location : LOCATION { advance_loc(); } string '{' optnl locopts '}' {
347 /* drop the starting '/' if any */
349 memmove($3, $3+1, strlen($3));
355 locopts : /* empty */
356 | locopts locopt optnl
359 locopt : AUTO INDEX bool { loc->auto_index = $3 ? 1 : -1; }
360 | BLOCK RETURN NUM string {
361 only_once(loc->block_fmt, "block");
362 loc->block_fmt = check_block_fmt($4);
363 loc->block_code = check_block_code($3);
366 only_once(loc->block_fmt, "block");
367 loc->block_fmt = xstrdup("temporary failure");
368 loc->block_code = check_block_code($3);
369 if ($3 >= 30 && $3 < 40)
370 yyerror("missing `meta' for block return %d", $3);
373 only_once(loc->block_fmt, "block");
374 loc->block_fmt = xstrdup("temporary failure");
375 loc->block_code = 40;
377 | DEFAULT TYPE string {
378 only_once(loc->default_mime, "default type");
379 loc->default_mime = $3;
383 only_once(loc->index, "index");
387 only_once(loc->lang, "lang");
390 | LOG bool { loc->disable_log = !$2; }
391 | REQUIRE CLIENT CA string {
392 only_once(loc->reqca, "require client ca");
393 ensure_absolute_path($4);
394 if ((loc->reqca = load_ca($4)) == NULL)
395 yyerror("couldn't load ca cert: %s", $4);
399 only_once(loc->dir, "root");
400 loc->dir = ensure_absolute_path($2);
402 | STRIP NUM { loc->strip = check_strip_no($2); }
405 fastcgi : SPAWN string {
406 only_oncei(loc->fcgi, "fastcgi");
407 loc->fcgi = fastcgi_conf(NULL, NULL, $2);
410 only_oncei(loc->fcgi, "fastcgi");
411 loc->fcgi = fastcgi_conf($1, NULL, NULL);
413 | TCP string PORT NUM {
415 if (asprintf(&c, "%d", $4) == -1)
417 only_oncei(loc->fcgi, "fastcgi");
418 loc->fcgi = fastcgi_conf($2, c, NULL);
421 only_oncei(loc->fcgi, "fastcgi");
422 loc->fcgi = fastcgi_conf($2, xstrdup("9000"), NULL);
424 | TCP string PORT string {
425 only_oncei(loc->fcgi, "fastcgi");
426 loc->fcgi = fastcgi_conf($2, $4, NULL);
430 optnl : '\n' optnl /* zero or more newlines */
431 | ';' optnl /* semicolons too */
437 static struct keyword {
441 /* these MUST be sorted */
450 {"default", DEFAULT},
451 {"entrypoint", ENTRYPOINT},
453 {"fastcgi", FASTCGI},
458 {"location", LOCATION},
467 {"prefork", PREFORK},
468 {"protocols", PROTOCOLS},
470 {"relay-to", RELAY_TO},
471 {"require", REQUIRE},
481 {"verifyname", VERIFYNAME},
485 yyerror(const char *msg, ...)
492 fprintf(stderr, "%s:%d error: ", config_path, yylval.lineno);
493 vfprintf(stderr, msg, ap);
494 fprintf(stderr, "\n");
499 yywarn(const char *msg, ...)
504 fprintf(stderr, "%s:%d warning: ", config_path, yylval.lineno);
505 vfprintf(stderr, msg, ap);
506 fprintf(stderr, "\n");
511 kw_cmp(const void *k, const void *e)
513 return strcmp(k, ((struct keyword *)e)->word);
519 const struct keyword *p;
521 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
522 sizeof(keywords[0]), kw_cmp);
530 #define START_EXPAND 1
531 #define DONE_EXPAND 2
533 static int expanding;
541 if (file->ungetpos > 0)
542 c = file->ungetbuf[--file->ungetpos];
544 c = getc(file->stream);
546 if (c == START_EXPAND)
548 else if (c == DONE_EXPAND)
562 if ((c = igetc()) == EOF) {
563 yyerror("reached end of file while parsing "
565 if (file == topfile || popfile() == EOF)
572 while ((c = igetc()) == '\\') {
578 yylval.lineno = file->lineno;
584 * Fake EOL when hit EOF for the first time. This gets line
585 * count right if last line in included file is syntactically
586 * invalid and has no newline.
588 if (file->eof_reached == 0) {
589 file->eof_reached = 1;
593 if (file == topfile || popfile() == EOF)
607 if (file->ungetpos >= file->ungetsize) {
608 void *p = reallocarray(file->ungetbuf, file->ungetsize, 2);
612 file->ungetsize *= 2;
614 file->ungetbuf[file->ungetpos++] = c;
622 /* Skip to either EOF or the first real EOL. */
645 while ((c = lgetc(0)) == ' ' || c == '\t')
648 yylval.lineno = file->lineno;
650 while ((c = lgetc(0)) != '\n' && c != EOF)
652 if (c == '$' && !expanding) {
654 if ((c = lgetc(0)) == EOF)
656 if (p + 1 >= buf + sizeof(buf) -1) {
657 yyerror("string too long");
660 if (isalnum(c) || c == '_') {
670 yyerror("macro `%s' not defined", buf);
673 yylval.v.string = xstrdup(val);
676 if (c == '@' && !expanding) {
678 if ((c = lgetc(0)) == EOF)
681 if (p + 1 >= buf + sizeof(buf) - 1) {
682 yyerror("string too long");
685 if (isalnum(c) || c == '_') {
695 yyerror("macro '%s' not defined", buf);
698 p = val + strlen(val) - 1;
699 lungetc(DONE_EXPAND);
704 lungetc(START_EXPAND);
713 if ((c = lgetc(quotec)) == EOF)
718 } else if (c == '\\') {
719 if ((next = lgetc(quotec)) == EOF)
721 if (next == quotec || next == ' ' ||
724 else if (next == '\n') {
729 } else if (c == quotec) {
732 } else if (c == '\0') {
733 yyerror("invalid syntax");
736 if (p + 1 >= buf + sizeof(buf) - 1) {
737 yyerror("string too long");
742 yylval.v.string = strdup(buf);
743 if (yylval.v.string == NULL)
744 err(1, "yylex: strdup");
748 #define allowed_to_end_number(x) \
749 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
751 if (c == '-' || isdigit(c)) {
754 if ((size_t)(p-buf) >= sizeof(buf)) {
755 yyerror("string too long");
758 } while ((c = lgetc(0)) != EOF && isdigit(c));
760 if (p == buf + 1 && buf[0] == '-')
762 if (c == EOF || allowed_to_end_number(c)) {
763 const char *errstr = NULL;
766 yylval.v.number = strtonum(buf, LLONG_MIN,
769 yyerror("\"%s\" invalid number: %s",
784 #define allowed_in_string(x) \
785 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
786 x != '{' && x != '}' && \
787 x != '!' && x != '=' && x != '#' && \
788 x != ',' && x != ';'))
790 if (isalnum(c) || c == ':' || c == '_') {
793 if ((size_t)(p-buf) >= sizeof(buf)) {
794 yyerror("string too long");
797 } while ((c = lgetc(0)) != EOF && (allowed_in_string(c)));
800 if ((token = lookup(buf)) == STRING)
801 yylval.v.string = xstrdup(buf);
805 yylval.lineno = file->lineno;
814 pushfile(const char *name, int secret)
818 nfile = xcalloc(1, sizeof(*nfile));
819 nfile->name = xstrdup(name);
820 if ((nfile->stream = fopen(nfile->name, "r")) == NULL) {
821 log_warn(NULL, "can't open %s: %s", nfile->name,
827 nfile->lineno = TAILQ_EMPTY(&files) ? 1 : 0;
828 nfile->ungetsize = 16;
829 nfile->ungetbuf = xcalloc(1, nfile->ungetsize);
830 TAILQ_INSERT_TAIL(&files, nfile, entry);
839 if ((prev = TAILQ_PREV(file, files, entry)) != NULL)
840 prev->errors += file->errors;
842 TAILQ_REMOVE(&files, file, entry);
843 fclose(file->stream);
845 free(file->ungetbuf);
848 return file ? 0 : EOF;
852 parse_conf(const char *filename)
854 struct sym *sym, *next;
856 file = pushfile(filename, 0);
862 errors = file->errors;
865 /* Free macros and check which have not been used. */
866 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
867 /* TODO: warn if !sym->used */
871 TAILQ_REMOVE(&symhead, sym, entry);
884 /* struct location *l; */
885 /* struct envlist *e; */
886 /* struct alist *a; */
888 if (conf.chroot != NULL)
889 printf("chroot \"%s\"\n", conf.chroot);
890 printf("ipv6 %s\n", conf.ipv6 ? "on" : "off");
891 /* XXX: defined mimes? */
892 printf("port %d\n", conf.port);
893 printf("prefork %d\n", conf.prefork);
894 /* XXX: protocols? */
895 if (conf.user != NULL)
896 printf("user \"%s\"\n", conf.user);
898 TAILQ_FOREACH(h, &hosts, vhosts) {
899 printf("\nserver \"%s\" {\n", h->domain);
900 printf(" cert \"%s\"\n", h->cert);
901 printf(" key \"%s\"\n", h->key);
902 /* TODO: print locations... */
908 symset(const char *name, const char *val, int persist)
912 TAILQ_FOREACH(sym, &symhead, entry) {
913 if (!strcmp(name, sym->name))
923 TAILQ_REMOVE(&symhead, sym, entry);
928 sym = xcalloc(1, sizeof(*sym));
929 sym->name = xstrdup(name);
930 sym->val = xstrdup(val);
932 sym->persist = persist;
934 TAILQ_INSERT_TAIL(&symhead, sym, entry);
939 cmdline_symset(char *s)
944 if ((val = strrchr(s, '=')) == NULL)
946 sym = xcalloc(1, val - s + 1);
947 memcpy(sym, s, val - s);
948 ret = symset(sym, val + 1, 1);
954 symget(const char *nam)
958 TAILQ_FOREACH(sym, &symhead, entry) {
959 if (strcmp(nam, sym->name) == 0) {
972 v = xcalloc(1, sizeof(*v));
973 v->proxy.protocols = TLS_PROTOCOLS_DEFAULT;
982 l = xcalloc(1, sizeof(*l));
989 ensure_absolute_path(char *path)
991 if (path == NULL || *path != '/')
992 yyerror("not an absolute path: %s", path);
997 check_block_code(int n)
999 if (n < 10 || n >= 70 || (n >= 20 && n <= 29))
1000 yyerror("invalid block code %d", n);
1005 check_block_fmt(char *fmt)
1009 for (s = fmt; *s; ++s) {
1020 yyerror("invalid format specifier %%%c", *s);
1028 check_strip_no(int n)
1031 yyerror("invalid strip number %d", n);
1036 check_port_num(int n)
1038 if (n <= 0 || n >= UINT16_MAX)
1039 yyerror("port number is %s: %d",
1040 n <= 0 ? "too small" : "too large",
1046 check_prefork_num(int n)
1048 if (n <= 0 || n >= PROC_MAX)
1049 yyerror("invalid prefork number %d", n);
1056 loc = new_location();
1057 TAILQ_INSERT_TAIL(&host->locations, loc, locations);
1061 only_once(const void *ptr, const char *name)
1064 yyerror("`%s' specified more than once", name);
1068 only_oncei(int i, const char *name)
1071 yyerror("`%s' specified more than once", name);
1075 fastcgi_conf(char *path, char *port, char *prog)
1080 for (i = 0; i < FCGI_MAX; ++i) {
1083 if (f->path == NULL) {
1091 /* XXX: what to do with prog? */
1092 if (!strcmp(f->path, path) &&
1093 ((port == NULL && f->port == NULL) ||
1094 !strcmp(f->port, port))) {
1101 yyerror("too much `fastcgi' rules defined.");
1106 add_param(char *name, char *val, int env)
1116 e = xcalloc(1, sizeof(*e));
1120 TAILQ_INSERT_HEAD(h, e, envs);
1122 TAILQ_INSERT_TAIL(h, e, envs);