]> git.ipfire.org Git - thirdparty/nftables.git/commitdiff
scanner: synproxy: Move to own scope
authorPhil Sutter <phil@nwl.cc>
Fri, 23 Jul 2021 12:34:34 +0000 (14:34 +0200)
committerPhil Sutter <phil@nwl.cc>
Tue, 1 Mar 2022 09:54:03 +0000 (10:54 +0100)
Quite a few keywords are shared with PARSER_SC_TCP.

Signed-off-by: Phil Sutter <phil@nwl.cc>
include/parser.h
src/parser_bison.y
src/scanner.l

index 16e02a1ffe12931ce48dd37206bb7d8885e5baee..0e75bad48207523349ad2a3a739ba08cb7e84303 100644 (file)
@@ -55,6 +55,7 @@ enum startcond_type {
        PARSER_SC_EXPR_SOCKET,
 
        PARSER_SC_STMT_LOG,
+       PARSER_SC_STMT_SYNPROXY,
 };
 
 struct mnl_socket;
index 8a1081a0f4c65a6fd38d82a4acbd770883ee250d..0fc8e85575f01a234dc65b4dd5514c129d325c31 100644 (file)
@@ -954,6 +954,7 @@ close_scope_socket  : { scanner_pop_start_cond(nft->scanner, PARSER_SC_EXPR_SOCKE
 close_scope_tcp                : { scanner_pop_start_cond(nft->scanner, PARSER_SC_TCP); };
 
 close_scope_log                : { scanner_pop_start_cond(nft->scanner, PARSER_SC_STMT_LOG); }
+close_scope_synproxy   : { scanner_pop_start_cond(nft->scanner, PARSER_SC_STMT_SYNPROXY); }
 
 common_block           :       INCLUDE         QUOTED_STRING   stmt_separator
                        {
@@ -1154,11 +1155,11 @@ add_cmd                 :       TABLE           table_spec
                        {
                                $$ = cmd_alloc(CMD_ADD, CMD_OBJ_SECMARK, &$2, &@$, $3);
                        }
-                       |       SYNPROXY        obj_spec        synproxy_obj    synproxy_config
+                       |       SYNPROXY        obj_spec        synproxy_obj    synproxy_config close_scope_synproxy
                        {
                                $$ = cmd_alloc(CMD_ADD, CMD_OBJ_SYNPROXY, &$2, &@$, $3);
                        }
-                       |       SYNPROXY        obj_spec        synproxy_obj    '{' synproxy_block '}'
+                       |       SYNPROXY        obj_spec        synproxy_obj    '{' synproxy_block '}'  close_scope_synproxy
                        {
                                $$ = cmd_alloc(CMD_ADD, CMD_OBJ_SYNPROXY, &$2, &@$, $3);
                        }
@@ -1255,7 +1256,7 @@ create_cmd                :       TABLE           table_spec
                        {
                                $$ = cmd_alloc(CMD_CREATE, CMD_OBJ_SECMARK, &$2, &@$, $3);
                        }
-                       |       SYNPROXY        obj_spec        synproxy_obj    synproxy_config
+                       |       SYNPROXY        obj_spec        synproxy_obj    synproxy_config close_scope_synproxy
                        {
                                $$ = cmd_alloc(CMD_CREATE, CMD_OBJ_SYNPROXY, &$2, &@$, $3);
                        }
@@ -1344,7 +1345,7 @@ delete_cmd                :       TABLE           table_or_id_spec
                        {
                                $$ = cmd_alloc(CMD_DELETE, CMD_OBJ_SECMARK, &$2, &@$, NULL);
                        }
-                       |       SYNPROXY        obj_or_id_spec
+                       |       SYNPROXY        obj_or_id_spec  close_scope_synproxy
                        {
                                $$ = cmd_alloc(CMD_DELETE, CMD_OBJ_SYNPROXY, &$2, &@$, NULL);
                        }
@@ -1440,7 +1441,7 @@ list_cmd          :       TABLE           table_spec
                        {
                                $$ = cmd_alloc(CMD_LIST, CMD_OBJ_SYNPROXYS, &$3, &@$, NULL);
                        }
-                       |       SYNPROXY        obj_spec
+                       |       SYNPROXY        obj_spec        close_scope_synproxy
                        {
                                $$ = cmd_alloc(CMD_LIST, CMD_OBJ_SYNPROXY, &$2, &@$, NULL);
                        }
@@ -1796,7 +1797,7 @@ table_block               :       /* empty */     { $$ = $<table>-1; }
                        }
                        |       table_block     SYNPROXY        obj_identifier
                                        obj_block_alloc '{'     synproxy_block  '}'
-                                       stmt_separator
+                                       stmt_separator  close_scope_synproxy
                        {
                                $4->location = @3;
                                $4->type = NFT_OBJECT_SYNPROXY;
@@ -2831,7 +2832,7 @@ stmt                      :       verdict_stmt
                        |       fwd_stmt
                        |       set_stmt
                        |       map_stmt
-                       |       synproxy_stmt
+                       |       synproxy_stmt   close_scope_synproxy
                        |       chain_stmt
                        |       optstrip_stmt
                        ;
index 95dcd0330bd3ebebb82a8f464ddfb523b5cddd24..01cb501cb8cb36a69b2260e4a7f03c02e22b387b 100644 (file)
@@ -221,6 +221,7 @@ addrstring  ({macaddr}|{ip4addr}|{ip6addr})
 %s SCANSTATE_EXPR_SOCKET
 
 %s SCANSTATE_STMT_LOG
+%s SCANSTATE_STMT_SYNPROXY
 
 %%
 
@@ -492,6 +493,9 @@ addrstring  ({macaddr}|{ip4addr}|{ip6addr})
        "sack1"                 { return SACK1; }
        "sack2"                 { return SACK2; }
        "sack3"                 { return SACK3; }
+       "sack-permitted"        { return SACK_PERM; }
+       "sack-perm"             { return SACK_PERM; }
+       "timestamp"             { return TIMESTAMP; }
        "fastopen"              { return FASTOPEN; }
        "mptcp"                 { return MPTCP; }
        "md5sig"                { return MD5SIG; }
@@ -508,11 +512,6 @@ addrstring ({macaddr}|{ip4addr}|{ip6addr})
        "option"                { return OPTION; }
 }
 "time"                 { return TIME; }
-"maxseg"               { return MSS; }
-"mss"                  { return MSS; }
-"sack-permitted"       { return SACK_PERM; }
-"sack-perm"            { return SACK_PERM; }
-"timestamp"            { return TIMESTAMP; }
 
 "icmp"                 { scanner_push_start_cond(yyscanner, SCANSTATE_ICMP); return ICMP; }
 "icmpv6"               { scanner_push_start_cond(yyscanner, SCANSTATE_ICMP); return ICMP6; }
@@ -694,8 +693,15 @@ addrstring ({macaddr}|{ip4addr}|{ip6addr})
 
 "osf"                  { return OSF; }
 
-"synproxy"             { return SYNPROXY; }
-"wscale"               { return WSCALE; }
+"synproxy"             { scanner_push_start_cond(yyscanner, SCANSTATE_STMT_SYNPROXY); return SYNPROXY; }
+<SCANSTATE_STMT_SYNPROXY>{
+       "wscale"                { return WSCALE; }
+       "maxseg"                { return MSS; }
+       "mss"                   { return MSS; }
+       "timestamp"             { return TIMESTAMP; }
+       "sack-permitted"        { return SACK_PERM; }
+       "sack-perm"             { return SACK_PERM; }
+}
 
 "notrack"              { return NOTRACK; }