ipmon_y.y revision 7c478bd95313f5f23a4c958a745db2134aa03244
%{
#include "ipf.h"
#include "ipmon_l.h"
#include "ipmon.h"
#define YYDEBUG 1
extern int yydebug;
extern int yylineNum;
typedef struct opt {
int o_line;
int o_type;
int o_num;
char *o_str;
} opt_t;
%}
%union {
char *str;
}
%%
| assign
;
;
resetlexer();
free($1);
free($3);
}
;
;
option { $$ = $1; }
;
| dstip { $$ = $1; }
| dstport { $$ = $1; }
| every { $$ = $1; }
| execute { $$ = $1; }
| group { $$ = $1; }
| interface { $$ = $1; }
| protocol { $$ = $1; }
| result { $$ = $1; }
| rule { $$ = $1; }
| srcip { $$ = $1; }
| srcport { $$ = $1; }
| tag { $$ = $1; }
;
;
$$->o_ip = $3;
$$->o_num = $5; }
;
$$->o_num = $3; }
$$->o_str = $3; }
;
$$->o_num = 1; }
$$->o_num = $2; }
$$->o_num = 1; }
$$->o_num = $2; }
;
$$->o_str = $3; }
;
$$->o_num = $3; }
$$->o_str = $3; }
;
$$->o_str = $3; }
;
$$->o_num = $3; }
free($3);
}
;
$$->o_str = $3; }
;
;
$$->o_ip = $3;
$$->o_num = $5; }
;
$$->o_num = $3; }
$$->o_str = $3; }
;
$$->o_num = $3; }
;
{ if ($1 > 255 || $3 > 255 || $5 > 255 || $7 > 255) {
yyerror("Invalid octet string for IP address");
return 0;
}
}
%%
{ "action", IPM_ACTION },
{ "body", IPM_BODY },
{ "direction", IPM_DIRECTION },
{ "dstip", IPM_DSTIP },
{ "dstport", IPM_DSTPORT },
{ "every", IPM_EVERY },
{ "execute", IPM_EXECUTE },
{ "group", IPM_GROUP },
{ "in", IPM_IN },
{ "interface", IPM_INTERFACE },
{ "no", IPM_NO },
{ "out", IPM_OUT },
{ "packet", IPM_PACKET },
{ "packets", IPM_PACKETS },
{ "protocol", IPM_PROTOCOL },
{ "result", IPM_RESULT },
{ "rule", IPM_RULE },
{ "second", IPM_SECOND },
{ "seconds", IPM_SECONDS },
{ "srcip", IPM_SRCIP },
{ "srcport", IPM_SRCPORT },
{ "tag", IPM_TAG },
{ "yes", IPM_YES },
{ NULL, 0 }
};
{ IPM_DIRECTION, IPMAC_DIRECTION },
{ IPM_DSTIP, IPMAC_DSTIP },
{ IPM_DSTPORT, IPMAC_DSTPORT },
{ IPM_EXECUTE, IPMAC_EXECUTE },
{ IPM_GROUP, IPMAC_GROUP },
{ IPM_INTERFACE, IPMAC_INTERFACE },
{ IPM_PACKET, IPMAC_EVERY },
{ IPM_PROTOCOL, IPMAC_PROTOCOL },
{ IPM_RESULT, IPMAC_RESULT },
{ IPM_RULE, IPMAC_RULE },
{ IPM_SECOND, IPMAC_EVERY },
{ IPM_SRCIP, IPMAC_SRCIP },
{ IPM_SRCPORT, IPMAC_SRCPORT },
{ 0, 0 }
};
int type;
{
opt_t *o;
o->o_num = 0;
o->o_str = (char *)0;
return o;
}
static void build_action(olist)
{
action_t *a;
opt_t *o;
u_32_t m;
char c;
int i;
if (!a)
return;
while ((o = olist)) {
for (i = 0; macflags[i][0]; i++)
break;
free(o);
continue;
}
switch (o->o_type)
{
case IPM_DIRECTION :
a->ac_direction = o->o_num;
break;
case IPM_DSTIP :
for (i = o->o_num, m = 0; i; i--) {
m >>= 1;
m |= 0x80000000;
}
break;
case IPM_DSTPORT :
break;
case IPM_EXECUTE :
c = *o->o_str;
if (c== '"'|| c == '\'') {
} else
} else
break;
case IPM_INTERFACE :
break;
case IPM_GROUP :
else
break;
case IPM_PACKET :
break;
case IPM_PROTOCOL :
break;
case IPM_RULE :
break;
case IPM_RESULT :
a->ac_result = IPMR_BLOCK;
a->ac_result = IPMR_SHORT;
a->ac_result = IPMR_NOMATCH;
break;
case IPM_SECOND :
break;
case IPM_SRCIP :
for (i = o->o_num, m = 0; i; i--) {
m >>= 1;
m |= 0x80000000;
}
break;
case IPM_SRCPORT :
break;
case IPM_TAG :
break;
default :
break;
}
free(o);
}
alist = a;
}
char *buf;
int opts;
char *log;
{
action_t *a;
if (a->ac_mflag & IPMAC_DIRECTION) {
if (a->ac_direction == IPM_IN) {
continue;
} else if (a->ac_direction == IPM_OUT) {
continue;
}
}
if (a->ac_mflag & IPMAC_EVERY) {
t1--;
if (a->ac_second) {
continue;
}
if (a->ac_packet) {
if (!a->ac_pktcnt)
a->ac_pktcnt++;
a->ac_pktcnt = 0;
continue;
} else {
a->ac_pktcnt++;
continue;
}
}
}
if (a->ac_mflag & IPMAC_DSTIP) {
continue;
}
if (a->ac_mflag & IPMAC_DSTPORT) {
continue;
continue;
}
if (a->ac_mflag & IPMAC_GROUP) {
FR_GROUPLEN) != 0)
continue;
}
if (a->ac_mflag & IPMAC_INTERFACE) {
continue;
}
if (a->ac_mflag & IPMAC_PROTOCOL) {
continue;
}
if (a->ac_mflag & IPMAC_RESULT) {
if (a->ac_result != IPMR_SHORT)
continue;
continue;
if (a->ac_result != IPMR_BLOCK)
continue;
if (a->ac_result != IPMR_NOMATCH)
continue;
} else { /* Log only */
continue;
}
}
if (a->ac_mflag & IPMAC_RULE) {
continue;
}
if (a->ac_mflag & IPMAC_SRCIP) {
continue;
}
if (a->ac_mflag & IPMAC_SRCPORT) {
continue;
continue;
}
continue;
}
/*
* It matched so now execute the command
*/
if (a->ac_exec) {
switch (fork())
{
case 0 :
{
if (pi) {
if (opts & OPT_HEXHDR) {
sizeof(*ipl) +
sizeof(*ipf));
}
if (opts & OPT_HEXBODY) {
}
}
exit(1);
}
case -1 :
break;
default :
break;
}
}
}
}
int load_config(file)
char *file;
{
yylineNum = 0;
if (!fp) {
perror("load_config:fopen:");
return -1;
}
yyparse();
return 0;
}