2 * parser.c Parse various things
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
20 * Copyright 2013 Alan DeKok <aland@freeradius.org>
25 #include <freeradius-devel/radiusd.h>
26 #include <freeradius-devel/parser.h>
27 #include <freeradius-devel/rad_assert.h>
32 * This file shouldn't use any functions from the server core.
35 size_t fr_cond_sprint(char *buffer, size_t bufsize, fr_cond_t const *c)
39 char *end = buffer + bufsize - 1;
43 *(p++) = '!'; /* FIXME: only allow for child? */
47 case COND_TYPE_EXISTS:
48 rad_assert(c->data.vpt != NULL);
50 len = snprintf(p, end - p, "<%s>", fr_int2str(dict_attr_types,
51 c->cast->type, "??"));
55 len = radius_tmpl2str(p, end - p, c->data.vpt);
60 rad_assert(c->data.map != NULL);
62 *(p++) = '['; /* for extra-clear debugging */
65 len = snprintf(p, end - p, "<%s>", fr_int2str(dict_attr_types,
66 c->cast->type, "??"));
70 len = radius_map2str(p, end - p, c->data.map);
78 rad_assert(c->data.child != NULL);
80 len = fr_cond_sprint(p, end - p, c->data.child);
90 if (c->next_op == COND_NONE) {
91 rad_assert(c->next == NULL);
96 if (c->next_op == COND_AND) {
97 strlcpy(p, " && ", end - p);
100 } else if (c->next_op == COND_OR) {
101 strlcpy(p, " || ", end - p);
113 static ssize_t condition_tokenize_string(TALLOC_CTX *ctx, char const *start, char **out,
114 FR_TOKEN *op, char const **error)
116 const char *p = start;
124 *op = T_DOUBLE_QUOTED_STRING;
128 *op = T_SINGLE_QUOTED_STRING;
132 *op = T_BACK_QUOTED_STRING;
136 *op = T_OP_REG_EQ; /* a bit of a hack. */
141 *out = talloc_array(ctx, char, strlen(start) - 1); /* + 2 - 1 */
142 if (!*out) return -1;
156 *error = "End of string after escape";
181 *error = "Unterminated string";
185 static ssize_t condition_tokenize_word(TALLOC_CTX *ctx, char const *start, char **out,
186 FR_TOKEN *op, char const **error)
189 char const *p = start;
191 if ((*p == '"') || (*p == '\'') || (*p == '`') || (*p == '/')) {
192 return condition_tokenize_string(ctx, start, out, op, error);
196 if (*p == '&') p++; /* special-case &User-Name */
200 * The LHS should really be limited to only a few
201 * things. For now, we allow pretty much anything.
204 *error = "Unexpected escape";
216 * Spaces or special characters delineate the word
218 if (isspace((int) *p) || (*p == '&') || (*p == '|') ||
219 (*p == '!') || (*p == '=') || (*p == '<') || (*p == '>')) {
223 if ((*p == '"') || (*p == '\'') || (*p == '`')) {
224 *error = "Unexpected start of string";
233 *error = "Empty string is invalid";
237 *out = talloc_array(ctx, char, len + 1);
238 memcpy(*out, start, len);
244 static ssize_t condition_tokenize_cast(char const *start, DICT_ATTR const **pda, char const **error)
246 char const *p = start;
250 while (isspace((int) *p)) p++; /* skip spaces before condition */
252 if (*p != '<') return 0;
256 while (*q && *q != '>') q++;
258 cast = fr_substr2int(dict_attr_types, p, PW_TYPE_INVALID, q - p);
259 if (cast == PW_TYPE_INVALID) {
260 *error = "Invalid data type in cast";
264 *pda = dict_attrbyvalue(1850 + cast, 0);
266 *error = "Cannot cast to this data type";
272 while (isspace((int) *q)) q++; /* skip spaces after cast */
278 * Less code means less bugs
280 #define return_P(_x) talloc_free(c);*error = _x;return -(p - start)
281 #define return_SLEN talloc_free(c);return slen -(p - start)
284 /** Tokenize a conditional check
286 * @param[in] ctx for talloc
287 * @param[in] start the start of the string to process. Should be "(..."
288 * @param[in] brace look for a closing brace
289 * @param[out] pcond pointer to the returned condition structure
290 * @param[out] error the parse error (if any)
291 * @return length of the string skipped, or when negative, the offset to the offending error
293 static ssize_t condition_tokenize(TALLOC_CTX *ctx, char const *start, int brace, fr_cond_t **pcond, char const **error)
296 const char *p = start;
299 FR_TOKEN op, lhs_type, rhs_type;
301 c = talloc_zero(ctx, fr_cond_t);
303 rad_assert(c != NULL);
305 while (isspace((int) *p)) p++; /* skip spaces before condition */
308 return_P("Empty condition is invalid");
317 while (isspace((int) *p)) p++; /* skip spaces after negation */
323 return_P("Double negation is invalid");
334 * We've already eaten one layer of
335 * brackets. Go recurse to get more.
337 c->type = COND_TYPE_CHILD;
338 slen = condition_tokenize(c, p, true, &c->data.child, error);
343 if (!c->data.child) {
344 return_P("Empty condition is invalid");
348 while (isspace((int) *p)) p++; /* skip spaces after (COND)*/
350 } else { /* it's a bare FOO==BAR */
352 * We didn't see anything special. The condition must be one of
362 return_P("Conditional check cannot begin with a regular expression");
365 slen = condition_tokenize_cast(p, &c->cast, error);
371 slen = condition_tokenize_word(c, p, &lhs, &lhs_type, error);
377 while (isspace((int)*p)) p++; /* skip spaces after LHS */
380 * We may (or not) have an operator
389 * don't skip the brace. We'll look for it later.
398 return_P("No closing brace at end of string");
406 } else if (((p[0] == '&') && (p[1] == '&')) ||
407 ((p[0] == '|') && (p[1] == '|'))) {
412 *error = "Cannot do cast for existence check";
416 c->type = COND_TYPE_EXISTS;
417 c->data.vpt = radius_str2tmpl(c, lhs, lhs_type);
419 return_P("Failed creating exists");
422 } else { /* it's an operator */
426 * The next thing should now be a comparison operator.
429 c->type = COND_TYPE_MAP;
432 return_P("Invalid text. Expected comparison operator");
439 } else if (p[1] == '~') {
445 } else if (p[1] == '*') {
452 * really re-write it...
458 goto invalid_operator;
467 } else if (p[1] == '~') {
473 } else if (p[1] == '*') {
479 return_P("Invalid operator");
507 while (isspace((int) *p)) p++; /* skip spaces after operator */
510 return_P("Expected text after operator");
514 * Cannot have a cast on the RHS
517 return_P("Unexpected cast");
523 slen = condition_tokenize_word(c, p, &rhs, &rhs_type, error);
529 * Sanity checks for regexes.
533 return_P("Expected regular expression");
539 if (p[slen] == 'i') {
544 } else if (!regex && (*p == '/')) {
545 return_P("Unexpected regular expression");
548 c->data.map = radius_str2map(c, lhs, lhs_type, op, rhs, rhs_type,
549 REQUEST_CURRENT, PAIR_LIST_REQUEST,
550 REQUEST_CURRENT, PAIR_LIST_REQUEST);
552 return_P("Failed creating check");
556 * @todo: check LHS and RHS separately, to
559 if ((c->data.map->src->type == VPT_TYPE_LIST) ||
560 (c->data.map->dst->type == VPT_TYPE_LIST)) {
562 *error = "Cannot use list references in condition";
567 * Check cast type. We can have the RHS
568 * a string if the LHS has a cast. But
569 * if the RHS is an attr, it MUST be the
570 * same type as the LHS.
573 if ((c->data.map->src->type == VPT_TYPE_ATTR) &&
574 (c->cast->type != c->data.map->src->da->type)) {
578 if (c->data.map->src->type == VPT_TYPE_REGEX) {
580 *error = "Cannot use cast with regex comparison";
586 * Without a cast, we can't compare "foo" to User-Name,
587 * it has to be done the other way around.
589 if ((c->data.map->src->type == VPT_TYPE_ATTR) &&
590 (c->data.map->dst->type != VPT_TYPE_ATTR)) {
592 *error = "Cannot use attribute reference on right side of condition";
597 * Two attributes? They must be of the same type
599 if ((c->data.map->src->type == VPT_TYPE_ATTR) &&
600 (c->data.map->dst->type == VPT_TYPE_ATTR) &&
601 (c->data.map->dst->da->type != c->data.map->src->da->type)) {
604 *error = "Attribute comparisons must be of the same attribute type";
610 while (isspace((int) *p)) p++; /* skip spaces after RHS */
612 } /* parse a condition (COND) or FOO OP BAR*/
619 return_P("Unexpected closing brace");
623 while (isspace((int) *p)) p++; /* skip spaces after closing brace */
629 * End of string is now allowed.
633 return_P("No closing brace at end of string");
639 if (!(((p[0] == '&') && (p[1] == '&')) ||
640 ((p[0] == '|') && (p[1] == '|')))) {
641 return_P("Unexpected text after condition");
645 * Recurse to parse the next condition.
651 * May still be looking for a closing brace.
653 slen = condition_tokenize(c, p, brace, &c->next, error);
661 * Normalize it before returning it.
666 * (FOO) ... --> FOO ...
668 if ((c->type == COND_TYPE_CHILD) && !c->data.child->next) {
671 child = talloc_steal(ctx, c->data.child);
672 c->data.child = NULL;
674 child->next = talloc_steal(child, c->next);
677 child->next_op = c->next_op;
680 * Set the negation properly
682 if ((c->negate && !child->negate) ||
683 (!c->negate && child->negate)) {
684 child->negate = true;
686 child->negate = false;
694 * (FOO ...) --> FOO ...
696 * But don't do !(FOO || BAR) --> !FOO || BAR
697 * Because that's different.
699 if ((c->type == COND_TYPE_CHILD) &&
700 !c->next && !c->negate) {
703 child = talloc_steal(ctx, c->data.child);
704 c->data.child = NULL;
711 * Normalize negation. This doesn't really make any
712 * difference, but it simplifies the run-time code in
715 if (c->type == COND_TYPE_MAP) {
717 * !FOO !~ BAR --> FOO =~ BAR
719 if (c->negate && (c->data.map->op == T_OP_REG_NE)) {
721 c->data.map->op = T_OP_REG_EQ;
725 * FOO !~ BAR --> !FOO =~ BAR
727 if (!c->negate && (c->data.map->op == T_OP_REG_NE)) {
729 c->data.map->op = T_OP_REG_EQ;
733 * !FOO != BAR --> FOO == BAR
735 if (c->negate && (c->data.map->op == T_OP_NE)) {
737 c->data.map->op = T_OP_CMP_EQ;
741 * This next one catches "LDAP-Group != foo",
742 * which doesn't really work, but this hack fixes it.
744 * FOO != BAR --> !FOO == BAR
746 if (!c->negate && (c->data.map->op == T_OP_NE)) {
748 c->data.map->op = T_OP_CMP_EQ;
756 /** Tokenize a conditional check
758 * @param[in] ctx for talloc
759 * @param[in] start the start of the string to process. Should be "(..."
760 * @param[out] head the parsed condition structure
761 * @param[out] error the parse error (if any)
762 * @return length of the string skipped, or when negative, the offset to the offending error
764 ssize_t fr_condition_tokenize(TALLOC_CTX *ctx, char const *start, fr_cond_t **head, char const **error)
766 return condition_tokenize(ctx, start, false, head, error);