rule-compiler.js 36 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154
  1. /* This Source Code Form is subject to the terms of the Mozilla Public
  2. * License, v. 2.0. If a copy of the MPL was not distributed with this
  3. * file, You can obtain one at https://mozilla.org/MPL/2.0/.
  4. *
  5. * (c) ZeroTier, Inc.
  6. * https://www.zerotier.com/
  7. */
  8. "use strict";
  9. // Names for bits in characteristics -- 0==LSB, 63==MSB
  10. const CHARACTERISTIC_BITS = {
  11. inbound: 63,
  12. multicast: 62,
  13. broadcast: 61,
  14. ipauth: 60,
  15. macauth: 59,
  16. tcp_fin: 0,
  17. tcp_syn: 1,
  18. tcp_rst: 2,
  19. tcp_psh: 3,
  20. tcp_ack: 4,
  21. tcp_urg: 5,
  22. tcp_ece: 6,
  23. tcp_cwr: 7,
  24. tcp_ns: 8,
  25. tcp_rs2: 9,
  26. tcp_rs1: 10,
  27. tcp_rs0: 11,
  28. };
  29. // Shorthand names for common ethernet types
  30. const ETHERTYPES = {
  31. ipv4: 0x0800,
  32. arp: 0x0806,
  33. wol: 0x0842,
  34. rarp: 0x8035,
  35. ipv6: 0x86dd,
  36. atalk: 0x809b,
  37. aarp: 0x80f3,
  38. ipx_a: 0x8137,
  39. ipx_b: 0x8138,
  40. };
  41. // Shorthand names for common IP protocols
  42. const IP_PROTOCOLS = {
  43. icmp: 0x01,
  44. icmp4: 0x01,
  45. icmpv4: 0x01,
  46. igmp: 0x02,
  47. ipip: 0x04,
  48. tcp: 0x06,
  49. egp: 0x08,
  50. igp: 0x09,
  51. udp: 0x11,
  52. rdp: 0x1b,
  53. esp: 0x32,
  54. ah: 0x33,
  55. icmp6: 0x3a,
  56. icmpv6: 0x3a,
  57. l2tp: 0x73,
  58. sctp: 0x84,
  59. udplite: 0x88,
  60. };
  61. // Keywords that open new blocks that must be terminated by a semicolon
  62. const OPEN_BLOCK_KEYWORDS = {
  63. macro: true,
  64. tag: true,
  65. cap: true,
  66. drop: true,
  67. accept: true,
  68. tee: true,
  69. watch: true,
  70. redirect: true,
  71. break: true,
  72. priority: true,
  73. };
  74. // Reserved words that can't be used as tag, capability, or rule set names
  75. const RESERVED_WORDS = {
  76. macro: true,
  77. tag: true,
  78. cap: true,
  79. default: true,
  80. drop: true,
  81. accept: true,
  82. tee: true,
  83. watch: true,
  84. redirect: true,
  85. break: true,
  86. priority: true,
  87. ztsrc: true,
  88. ztdest: true,
  89. vlan: true,
  90. vlanpcp: true,
  91. vlandei: true,
  92. ethertype: true,
  93. macsrc: true,
  94. macdest: true,
  95. ipsrc: true,
  96. ipdest: true,
  97. iptos: true,
  98. ipprotocol: true,
  99. icmp: true,
  100. sport: true,
  101. dport: true,
  102. chr: true,
  103. framesize: true,
  104. random: true,
  105. tand: true,
  106. tor: true,
  107. txor: true,
  108. tdiff: true,
  109. teq: true,
  110. tseq: true,
  111. treq: true,
  112. type: true,
  113. enum: true,
  114. class: true,
  115. define: true,
  116. import: true,
  117. include: true,
  118. log: true,
  119. not: true,
  120. xor: true,
  121. or: true,
  122. and: true,
  123. set: true,
  124. var: true,
  125. let: true,
  126. };
  127. const KEYWORD_TO_API_MAP = {
  128. drop: "ACTION_DROP",
  129. accept: "ACTION_ACCEPT",
  130. tee: "ACTION_TEE",
  131. watch: "ACTION_WATCH",
  132. redirect: "ACTION_REDIRECT",
  133. break: "ACTION_BREAK",
  134. priority: "ACTION_PRIORITY",
  135. ztsrc: "MATCH_SOURCE_ZEROTIER_ADDRESS",
  136. ztdest: "MATCH_DEST_ZEROTIER_ADDRESS",
  137. vlan: "MATCH_VLAN_ID",
  138. vlanpcp: "MATCH_VLAN_PCP",
  139. vlandei: "MATCH_VLAN_DEI",
  140. ethertype: "MATCH_ETHERTYPE",
  141. macsrc: "MATCH_MAC_SOURCE",
  142. macdest: "MATCH_MAC_DEST",
  143. //'ipsrc': '', // special handling since we programmatically differentiate between V4 and V6
  144. //'ipdest': '', // special handling
  145. iptos: "MATCH_IP_TOS",
  146. ipprotocol: "MATCH_IP_PROTOCOL",
  147. icmp: "MATCH_ICMP",
  148. sport: "MATCH_IP_SOURCE_PORT_RANGE",
  149. dport: "MATCH_IP_DEST_PORT_RANGE",
  150. chr: "MATCH_CHARACTERISTICS",
  151. framesize: "MATCH_FRAME_SIZE_RANGE",
  152. random: "MATCH_RANDOM",
  153. tand: "MATCH_TAGS_BITWISE_AND",
  154. tor: "MATCH_TAGS_BITWISE_OR",
  155. txor: "MATCH_TAGS_BITWISE_XOR",
  156. tdiff: "MATCH_TAGS_DIFFERENCE",
  157. teq: "MATCH_TAGS_EQUAL",
  158. tseq: "MATCH_TAG_SENDER",
  159. treq: "MATCH_TAG_RECEIVER",
  160. };
  161. // Number of args for each match
  162. const MATCH_ARG_COUNTS = {
  163. ztsrc: 1,
  164. ztdest: 1,
  165. vlan: 1,
  166. vlanpcp: 1,
  167. vlandei: 1,
  168. ethertype: 1,
  169. macsrc: 1,
  170. macdest: 1,
  171. ipsrc: 1,
  172. ipdest: 1,
  173. iptos: 2,
  174. ipprotocol: 1,
  175. icmp: 2,
  176. sport: 1,
  177. dport: 1,
  178. chr: 1,
  179. framesize: 1,
  180. random: 1,
  181. tand: 2,
  182. tor: 2,
  183. txor: 2,
  184. tdiff: 2,
  185. teq: 2,
  186. tseq: 2,
  187. treq: 2,
  188. };
  189. // Regex of all alphanumeric characters in Unicode
  190. const INTL_ALPHANUM_REGEX = new RegExp(
  191. "[0-9A-Za-z\xAA\xB5\xBA\xC0-\xD6\xD8-\xF6\xF8-\u02C1\u02C6-\u02D1\u02E0-\u02E4\u02EC\u02EE\u0370-\u0374\u0376\u0377\u037A-\u037D\u0386\u0388-\u038A\u038C\u038E-\u03A1\u03A3-\u03F5\u03F7-\u0481\u048A-\u0527\u0531-\u0556\u0559\u0561-\u0587\u05D0-\u05EA\u05F0-\u05F2\u0620-\u064A\u066E\u066F\u0671-\u06D3\u06D5\u06E5\u06E6\u06EE\u06EF\u06FA-\u06FC\u06FF\u0710\u0712-\u072F\u074D-\u07A5\u07B1\u07CA-\u07EA\u07F4\u07F5\u07FA\u0800-\u0815\u081A\u0824\u0828\u0840-\u0858\u08A0\u08A2-\u08AC\u0904-\u0939\u093D\u0950\u0958-\u0961\u0971-\u0977\u0979-\u097F\u0985-\u098C\u098F\u0990\u0993-\u09A8\u09AA-\u09B0\u09B2\u09B6-\u09B9\u09BD\u09CE\u09DC\u09DD\u09DF-\u09E1\u09F0\u09F1\u0A05-\u0A0A\u0A0F\u0A10\u0A13-\u0A28\u0A2A-\u0A30\u0A32\u0A33\u0A35\u0A36\u0A38\u0A39\u0A59-\u0A5C\u0A5E\u0A72-\u0A74\u0A85-\u0A8D\u0A8F-\u0A91\u0A93-\u0AA8\u0AAA-\u0AB0\u0AB2\u0AB3\u0AB5-\u0AB9\u0ABD\u0AD0\u0AE0\u0AE1\u0B05-\u0B0C\u0B0F\u0B10\u0B13-\u0B28\u0B2A-\u0B30\u0B32\u0B33\u0B35-\u0B39\u0B3D\u0B5C\u0B5D\u0B5F-\u0B61\u0B71\u0B83\u0B85-\u0B8A\u0B8E-\u0B90\u0B92-\u0B95\u0B99\u0B9A\u0B9C\u0B9E\u0B9F\u0BA3\u0BA4\u0BA8-\u0BAA\u0BAE-\u0BB9\u0BD0\u0C05-\u0C0C\u0C0E-\u0C10\u0C12-\u0C28\u0C2A-\u0C33\u0C35-\u0C39\u0C3D\u0C58\u0C59\u0C60\u0C61\u0C85-\u0C8C\u0C8E-\u0C90\u0C92-\u0CA8\u0CAA-\u0CB3\u0CB5-\u0CB9\u0CBD\u0CDE\u0CE0\u0CE1\u0CF1\u0CF2\u0D05-\u0D0C\u0D0E-\u0D10\u0D12-\u0D3A\u0D3D\u0D4E\u0D60\u0D61\u0D7A-\u0D7F\u0D85-\u0D96\u0D9A-\u0DB1\u0DB3-\u0DBB\u0DBD\u0DC0-\u0DC6\u0E01-\u0E30\u0E32\u0E33\u0E40-\u0E46\u0E81\u0E82\u0E84\u0E87\u0E88\u0E8A\u0E8D\u0E94-\u0E97\u0E99-\u0E9F\u0EA1-\u0EA3\u0EA5\u0EA7\u0EAA\u0EAB\u0EAD-\u0EB0\u0EB2\u0EB3\u0EBD\u0EC0-\u0EC4\u0EC6\u0EDC-\u0EDF\u0F00\u0F40-\u0F47\u0F49-\u0F6C\u0F88-\u0F8C\u1000-\u102A\u103F\u1050-\u1055\u105A-\u105D\u1061\u1065\u1066\u106E-\u1070\u1075-\u1081\u108E\u10A0-\u10C5\u10C7\u10CD\u10D0-\u10FA\u10FC-\u1248\u124A-\u124D\u1250-\u1256\u1258\u125A-\u125D\u1260-\u1288\u128A-\u128D\u1290-\u12B0\u12B2-\u12B5\u12B8-\u12BE\u12C0\u12C2-\u12C5\u12C8-\u12D6\u12D8-\u1310\u1312-\u1315\u1318-\u135A\u1380-\u138F\u13A0-\u13F4\u1401-\u166C\u166F-\u167F\u1681-\u169A\u16A0-\u16EA\u1700-\u170C\u170E-\u1711\u1720-\u1731\u1740-\u1751\u1760-\u176C\u176E-\u1770\u1780-\u17B3\u17D7\u17DC\u1820-\u1877\u1880-\u18A8\u18AA\u18B0-\u18F5\u1900-\u191C\u1950-\u196D\u1970-\u1974\u1980-\u19AB\u19C1-\u19C7\u1A00-\u1A16\u1A20-\u1A54\u1AA7\u1B05-\u1B33\u1B45-\u1B4B\u1B83-\u1BA0\u1BAE\u1BAF\u1BBA-\u1BE5\u1C00-\u1C23\u1C4D-\u1C4F\u1C5A-\u1C7D\u1CE9-\u1CEC\u1CEE-\u1CF1\u1CF5\u1CF6\u1D00-\u1DBF\u1E00-\u1F15\u1F18-\u1F1D\u1F20-\u1F45\u1F48-\u1F4D\u1F50-\u1F57\u1F59\u1F5B\u1F5D\u1F5F-\u1F7D\u1F80-\u1FB4\u1FB6-\u1FBC\u1FBE\u1FC2-\u1FC4\u1FC6-\u1FCC\u1FD0-\u1FD3\u1FD6-\u1FDB\u1FE0-\u1FEC\u1FF2-\u1FF4\u1FF6-\u1FFC\u2071\u207F\u2090-\u209C\u2102\u2107\u210A-\u2113\u2115\u2119-\u211D\u2124\u2126\u2128\u212A-\u212D\u212F-\u2139\u213C-\u213F\u2145-\u2149\u214E\u2183\u2184\u2C00-\u2C2E\u2C30-\u2C5E\u2C60-\u2CE4\u2CEB-\u2CEE\u2CF2\u2CF3\u2D00-\u2D25\u2D27\u2D2D\u2D30-\u2D67\u2D6F\u2D80-\u2D96\u2DA0-\u2DA6\u2DA8-\u2DAE\u2DB0-\u2DB6\u2DB8-\u2DBE\u2DC0-\u2DC6\u2DC8-\u2DCE\u2DD0-\u2DD6\u2DD8-\u2DDE\u2E2F\u3005\u3006\u3031-\u3035\u303B\u303C\u3041-\u3096\u309D-\u309F\u30A1-\u30FA\u30FC-\u30FF\u3105-\u312D\u3131-\u318E\u31A0-\u31BA\u31F0-\u31FF\u3400-\u4DB5\u4E00-\u9FCC\uA000-\uA48C\uA4D0-\uA4FD\uA500-\uA60C\uA610-\uA61F\uA62A\uA62B\uA640-\uA66E\uA67F-\uA697\uA6A0-\uA6E5\uA717-\uA71F\uA722-\uA788\uA78B-\uA78E\uA790-\uA793\uA7A0-\uA7AA\uA7F8-\uA801\uA803-\uA805\uA807-\uA80A\uA80C-\uA822\uA840-\uA873\uA882-\uA8B3\uA8F2-\uA8F7\uA8FB\uA90A-\uA925\uA930-\uA946\uA960-\uA97C\uA984-\uA9B2\uA9CF\uAA00-\uAA28\uAA40-\uAA42\uAA44-\uAA4B\uAA60-\uAA76\uAA7A\uAA80-\uAAAF\uAAB1\uAAB5\uAAB6\uAAB9-\uAABD\uAAC0\uAAC2\uAADB-\uAADD\uAAE0-\uAAEA\uAAF2-\uAAF4\uAB01-\uAB06\uAB09-\uAB0E\uAB11-\uAB16\uAB20-\uAB26\uAB28-\uAB2E\uABC0-\uABE2\uAC00-\uD7A3\uD7B0-\uD7C6\uD7CB-\uD7FB\uF900-\uFA6D\uFA70-\uFAD9\uFB00-\uFB06\uFB13-\uFB17\uFB1D\uFB1F-\uFB28\uFB2A-\uFB36\uFB38-\uFB3C\uFB3E\uFB40\uFB41\uFB43\uFB44\uFB46-\uFBB1\uFBD3-\uFD3D\uFD50-\uFD8F\uFD92-\uFDC7\uFDF0-\uFDFB\uFE70-\uFE74\uFE76-\uFEFC\uFF21-\uFF3A\uFF41-\uFF5A\uFF66-\uFFBE\uFFC2-\uFFC7\uFFCA-\uFFCF\uFFD2-\uFFD7\uFFDA-\uFFDC]",
  192. );
  193. // Checks whether something is a valid capability, tag, or macro name
  194. function _isValidName(n) {
  195. if (typeof n !== "string" || n.length === 0) return false;
  196. if ("0123456789".indexOf(n.charAt(0)) >= 0) return false;
  197. for (let i = 0; i < n.length; ++i) {
  198. let c = n.charAt(i);
  199. if (c !== "_" && !INTL_ALPHANUM_REGEX.test(c)) return false;
  200. }
  201. return true;
  202. }
  203. // Regexes for checking the basic syntactic validity of IP addresses
  204. const IPV6_REGEX = new RegExp(
  205. "(([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))",
  206. );
  207. const IPV4_REGEX = new RegExp(
  208. "((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])",
  209. );
  210. function _parseNum(n) {
  211. try {
  212. if (typeof n !== "string" || n.length === 0) return -1;
  213. n = n.toLowerCase();
  214. if (n.length > 2 && n.substr(0, 2) === "0x") n = parseInt(n.substr(2), 16);
  215. else n = parseInt(n, 10);
  216. return typeof n === "number" && n !== null && !isNaN(n) ? n : -1;
  217. } catch (e) {
  218. return -1;
  219. }
  220. }
  221. function _cleanMac(m) {
  222. m = m.toLowerCase();
  223. var m2 = "";
  224. let charcount = 0;
  225. for (let i = 0; i < m.length && m2.length < 17; ++i) {
  226. let c = m.charAt(i);
  227. if ("0123456789abcdef".indexOf(c) >= 0) {
  228. m2 += c;
  229. charcount++;
  230. if (m2.length > 0 && m2.length !== 17 && charcount >= 2) {
  231. m2 += ":";
  232. charcount = 0;
  233. }
  234. }
  235. }
  236. return m2;
  237. }
  238. function _cleanHex(m) {
  239. m = m.toLowerCase();
  240. var m2 = "";
  241. for (let i = 0; i < m.length; ++i) {
  242. let c = m.charAt(i);
  243. if ("0123456789abcdef".indexOf(c) >= 0) m2 += c;
  244. }
  245. return m2;
  246. }
  247. function _renderMatches(mtree, rules, macros, caps, tags, params) {
  248. let not = false;
  249. let or = false;
  250. for (let k = 0; k < mtree.length; ++k) {
  251. let match =
  252. typeof mtree[k][0] === "string" ? mtree[k][0].toLowerCase() : "";
  253. if (match.length === 0 || match === "and") {
  254. // AND is the default
  255. continue;
  256. } else if (match === "not") {
  257. not = true;
  258. } else if (match === "or") {
  259. or = true;
  260. } else {
  261. let args = [];
  262. let argCount = MATCH_ARG_COUNTS[match];
  263. if (!argCount)
  264. return [
  265. mtree[k][1],
  266. mtree[k][2],
  267. 'Unrecognized match type "' + match + '".',
  268. ];
  269. for (let i = 0; i < argCount; ++i) {
  270. if (++k >= mtree.length)
  271. return [
  272. mtree[k - 1][1],
  273. mtree[k - 1][2],
  274. "Missing argument(s) to match.",
  275. ];
  276. let arg = mtree[k][0];
  277. if (
  278. typeof arg !== "string" ||
  279. arg in RESERVED_WORDS ||
  280. arg.length === 0
  281. )
  282. return [
  283. mtree[k - 1][1],
  284. mtree[k - 1][2],
  285. "Missing argument(s) to match (invalid argument or argument is reserved word).",
  286. ];
  287. if (arg.charAt(0) === "$") {
  288. let tmp = params[arg];
  289. if (typeof tmp === "undefined")
  290. return [mtree[k][1], mtree[k][2], "Undefined variable name."];
  291. args.push([tmp, mtree[k][1], mtree[k][2]]);
  292. } else {
  293. args.push(mtree[k]);
  294. }
  295. }
  296. switch (match) {
  297. case "ztsrc":
  298. case "ztdest":
  299. {
  300. let zt = _cleanHex(args[0][0]);
  301. if (zt.length !== 10)
  302. return [args[0][1], args[0][2], "Invalid ZeroTier address."];
  303. rules.push({
  304. type: KEYWORD_TO_API_MAP[match],
  305. not: not,
  306. or: or,
  307. zt: zt,
  308. });
  309. }
  310. break;
  311. case "vlan":
  312. case "vlanpcp":
  313. case "vlandei":
  314. case "ethertype":
  315. case "ipprotocol":
  316. {
  317. let num = null;
  318. switch (match) {
  319. case "ethertype":
  320. num = ETHERTYPES[args[0][0]];
  321. break;
  322. case "ipprotocol":
  323. num = IP_PROTOCOLS[args[0][0]];
  324. break;
  325. }
  326. if (typeof num !== "number") num = _parseNum(args[0][0]);
  327. if (
  328. typeof num !== "number" ||
  329. num < 0 ||
  330. num > 0xffffffff ||
  331. num === null
  332. )
  333. return [args[0][1], args[0][2], "Invalid numeric value."];
  334. let r = {
  335. type: KEYWORD_TO_API_MAP[match],
  336. not: not,
  337. or: or,
  338. };
  339. switch (match) {
  340. case "vlan":
  341. r["vlanId"] = num;
  342. break;
  343. case "vlanpcp":
  344. r["vlanPcp"] = num;
  345. break;
  346. case "vlandei":
  347. r["vlanDei"] = num;
  348. break;
  349. case "ethertype":
  350. r["etherType"] = num;
  351. break;
  352. case "ipprotocol":
  353. r["ipProtocol"] = num;
  354. break;
  355. }
  356. rules.push(r);
  357. }
  358. break;
  359. case "random":
  360. {
  361. let num = parseFloat(args[0][0]) || 0.0;
  362. if (num < 0.0) num = 0.0;
  363. if (num > 1.0) num = 1.0;
  364. rules.push({
  365. type: KEYWORD_TO_API_MAP[match],
  366. not: not,
  367. or: or,
  368. probability: Math.floor(4294967295 * num),
  369. });
  370. }
  371. break;
  372. case "macsrc":
  373. case "macdest":
  374. {
  375. let mac = _cleanMac(args[0][0]);
  376. if (mac.length !== 17)
  377. return [args[0][1], args[0][2], "Invalid MAC address."];
  378. rules.push({
  379. type: KEYWORD_TO_API_MAP[match],
  380. not: not,
  381. or: or,
  382. mac: mac,
  383. });
  384. }
  385. break;
  386. case "ipsrc":
  387. case "ipdest":
  388. {
  389. let ip = args[0][0];
  390. let slashIdx = ip.indexOf("/");
  391. if (slashIdx <= 0)
  392. return [
  393. args[0][1],
  394. args[0][2],
  395. "Missing /bits netmask length designation in IP.",
  396. ];
  397. let ipOnly = ip.substr(0, slashIdx);
  398. if (IPV6_REGEX.test(ipOnly)) {
  399. rules.push({
  400. type:
  401. match === "ipsrc" ? "MATCH_IPV6_SOURCE" : "MATCH_IPV6_DEST",
  402. not: not,
  403. or: or,
  404. ip: ip,
  405. });
  406. } else if (IPV4_REGEX.test(ipOnly)) {
  407. rules.push({
  408. type:
  409. match === "ipsrc" ? "MATCH_IPV4_SOURCE" : "MATCH_IPV4_DEST",
  410. not: not,
  411. or: or,
  412. ip: ip,
  413. });
  414. } else {
  415. return [
  416. args[0][1],
  417. args[0][2],
  418. "Invalid IP address (not valid IPv4 or IPv6).",
  419. ];
  420. }
  421. }
  422. break;
  423. case "icmp":
  424. {
  425. let icmpType = _parseNum(args[0][0]);
  426. if (icmpType < 0 || icmpType > 0xff)
  427. return [args[0][1], args[0][2], "Missing or invalid ICMP type."];
  428. let icmpCode = _parseNum(args[1][0]); // -1 okay, indicates don't match code
  429. if (icmpCode > 0xff)
  430. return [
  431. args[1][1],
  432. args[1][2],
  433. "Invalid ICMP code (use -1 for none).",
  434. ];
  435. rules.push({
  436. type: "MATCH_ICMP",
  437. not: not,
  438. or: or,
  439. icmpType: icmpType,
  440. icmpCode: icmpCode < 0 ? null : icmpCode,
  441. });
  442. }
  443. break;
  444. case "sport":
  445. case "dport":
  446. case "framesize":
  447. {
  448. let arg = args[0][0];
  449. let fn = null;
  450. let tn = null;
  451. if (arg.indexOf("-") > 0) {
  452. let asplit = arg.split("-");
  453. if (asplit.length !== 2) {
  454. return [args[0][1], args[0][2], "Invalid numeric range."];
  455. } else {
  456. fn = _parseNum(asplit[0]);
  457. tn = _parseNum(asplit[1]);
  458. }
  459. } else {
  460. fn = _parseNum(arg);
  461. tn = fn;
  462. }
  463. if (fn < 0 || fn > 0xffff || tn < 0 || tn > 0xffff || tn < fn)
  464. return [args[0][1], args[0][2], "Invalid numeric range."];
  465. rules.push({
  466. type: KEYWORD_TO_API_MAP[match],
  467. not: not,
  468. or: or,
  469. start: fn,
  470. end: tn,
  471. });
  472. }
  473. break;
  474. case "iptos":
  475. {
  476. let mask = _parseNum(args[0][0]);
  477. if (
  478. typeof mask !== "number" ||
  479. mask < 0 ||
  480. mask > 0xff ||
  481. mask === null
  482. )
  483. return [args[0][1], args[0][2], "Invalid mask."];
  484. let arg = args[1][0];
  485. let fn = null;
  486. let tn = null;
  487. if (arg.indexOf("-") > 0) {
  488. let asplit = arg.split("-");
  489. if (asplit.length !== 2) {
  490. return [args[1][1], args[1][2], "Invalid value range."];
  491. } else {
  492. fn = _parseNum(asplit[0]);
  493. tn = _parseNum(asplit[1]);
  494. }
  495. } else {
  496. fn = _parseNum(arg);
  497. tn = fn;
  498. }
  499. if (fn < 0 || fn > 0xff || tn < 0 || tn > 0xff || tn < fn)
  500. return [args[1][1], args[1][2], "Invalid value range."];
  501. rules.push({
  502. type: "MATCH_IP_TOS",
  503. not: not,
  504. or: or,
  505. mask: mask,
  506. start: fn,
  507. end: tn,
  508. });
  509. }
  510. break;
  511. case "chr":
  512. {
  513. let chrb = args[0][0].split(/[,]+/);
  514. let maskhi = 0;
  515. let masklo = 0;
  516. for (let i = 0; i < chrb.length; ++i) {
  517. if (chrb[i].length > 0) {
  518. let tmp = CHARACTERISTIC_BITS[chrb[i]];
  519. let bit = typeof tmp === "number" ? tmp : _parseNum(chrb[i]);
  520. if (bit < 0 || bit > 63)
  521. return [
  522. args[0][1],
  523. args[0][2],
  524. "Invalid bit index (range 0-63) or unrecognized name.",
  525. ];
  526. if (bit >= 32) maskhi |= Math.abs(1 << (bit - 32));
  527. else masklo |= Math.abs(1 << bit);
  528. }
  529. }
  530. maskhi = Math.abs(maskhi).toString(16);
  531. while (maskhi.length < 8) maskhi = "0" + maskhi;
  532. masklo = Math.abs(masklo).toString(16);
  533. while (masklo.length < 8) masklo = "0" + masklo;
  534. rules.push({
  535. type: "MATCH_CHARACTERISTICS",
  536. not: not,
  537. or: or,
  538. mask: maskhi + masklo,
  539. });
  540. }
  541. break;
  542. case "tand":
  543. case "tor":
  544. case "txor":
  545. case "tdiff":
  546. case "teq":
  547. case "tseq":
  548. case "treq":
  549. {
  550. let tag = tags[args[0][0]];
  551. let tagId = -1;
  552. let tagValue = -1;
  553. if (tag) {
  554. tagId = tag.id;
  555. tagValue = args[1][0];
  556. if (tagValue in tag.flags) tagValue = tag.flags[tagValue];
  557. else if (tagValue in tag.enums) tagValue = tag.enums[tagValue];
  558. else tagValue = _parseNum(tagValue);
  559. } else {
  560. tagId = _parseNum(args[0][0]);
  561. tagValue = _parseNum(args[1][0]);
  562. }
  563. if (tagId < 0 || tagId > 0xffffffff)
  564. return [
  565. args[0][1],
  566. args[0][2],
  567. "Undefined tag name and invalid tag value.",
  568. ];
  569. if (tagValue < 0 || tagValue > 0xffffffff)
  570. return [
  571. args[1][1],
  572. args[1][2],
  573. "Invalid tag value or unrecognized flag/enum name.",
  574. ];
  575. rules.push({
  576. type: KEYWORD_TO_API_MAP[match],
  577. not: not,
  578. or: or,
  579. id: tagId,
  580. value: tagValue,
  581. });
  582. }
  583. break;
  584. }
  585. not = false;
  586. or = false;
  587. }
  588. }
  589. return null;
  590. }
  591. function _renderActions(rtree, rules, macros, caps, tags, params) {
  592. for (let k = 0; k < rtree.length; ++k) {
  593. let action =
  594. typeof rtree[k][0] === "string" ? rtree[k][0].toLowerCase() : "";
  595. if (action.length === 0) {
  596. continue;
  597. } else if (action === "include") {
  598. if (k + 1 >= rtree.length)
  599. return [
  600. rtree[k][1],
  601. rtree[k][2],
  602. "Include directive is missing a macro name.",
  603. ];
  604. let macroName = rtree[k + 1][0];
  605. ++k;
  606. let macroParamArray = [];
  607. let parenIdx = macroName.indexOf("(");
  608. if (parenIdx > 0) {
  609. let pns = macroName.substr(parenIdx + 1).split(/[,)]+/);
  610. for (let k = 0; k < pns.length; ++k) {
  611. if (pns[k].length > 0) macroParamArray.push(pns[k]);
  612. }
  613. macroName = macroName.substr(0, parenIdx);
  614. }
  615. let macro = macros[macroName];
  616. if (!macro) return [rtree[k][1], rtree[k][2], "Macro name not found."];
  617. let macroParams = {};
  618. for (let param in macro.params) {
  619. let pidx = macro.params[param];
  620. if (pidx >= macroParamArray.length)
  621. return [
  622. rtree[k][1],
  623. rtree[k][2],
  624. "Missing one or more required macro parameter.",
  625. ];
  626. macroParams[param] = macroParamArray[pidx];
  627. }
  628. let err = _renderActions(
  629. macro.rules,
  630. rules,
  631. macros,
  632. caps,
  633. tags,
  634. macroParams,
  635. );
  636. if (err !== null) return err;
  637. } else if (action === "drop" || action === "accept" || action === "break") {
  638. // actions without arguments
  639. if (k + 1 < rtree.length && Array.isArray(rtree[k + 1][0])) {
  640. let mtree = rtree[k + 1];
  641. ++k;
  642. let err = _renderMatches(mtree, rules, macros, caps, tags, params);
  643. if (err !== null) return err;
  644. }
  645. rules.push({
  646. type: KEYWORD_TO_API_MAP[action],
  647. });
  648. } else if (action === "tee" || action === "watch") {
  649. // actions with arguments (ZeroTier address)
  650. if (
  651. k + 1 < rtree.length &&
  652. Array.isArray(rtree[k + 1][0]) &&
  653. rtree[k + 1][0].length >= 2
  654. ) {
  655. let mtree = rtree[k + 1];
  656. ++k;
  657. let maxLength = _parseNum(mtree[0][0]);
  658. if (maxLength < -1 || maxLength > 0xffff)
  659. return [
  660. mtree[0][1],
  661. mtree[1][2],
  662. "Tee/watch max packet length to forward invalid or out of range.",
  663. ];
  664. let target = mtree[1][0];
  665. if (typeof target !== "string" || target.length !== 10)
  666. return [
  667. mtree[1][1],
  668. mtree[1][2],
  669. "Missing or invalid ZeroTier address target for tee/watch.",
  670. ];
  671. let err = _renderMatches(
  672. mtree.slice(2),
  673. rules,
  674. macros,
  675. caps,
  676. tags,
  677. params,
  678. );
  679. if (err !== null) return err;
  680. rules.push({
  681. type: KEYWORD_TO_API_MAP[action],
  682. address: target,
  683. length: maxLength,
  684. });
  685. } else {
  686. return [
  687. rtree[k][1],
  688. rtree[k][2],
  689. "The tee and watch actions require two paremters (max length or 0 for all, target).",
  690. ];
  691. }
  692. } else if (action === "redirect") {
  693. if (
  694. k + 1 < rtree.length &&
  695. Array.isArray(rtree[k + 1][0]) &&
  696. rtree[k + 1][0].length >= 1
  697. ) {
  698. let mtree = rtree[k + 1];
  699. ++k;
  700. let target = mtree[0][0];
  701. if (typeof target !== "string" || target.length !== 10)
  702. return [
  703. mtree[0][1],
  704. mtree[0][2],
  705. "Missing or invalid ZeroTier address target for redirect.",
  706. ];
  707. let err = _renderMatches(
  708. mtree.slice(1),
  709. rules,
  710. macros,
  711. caps,
  712. tags,
  713. params,
  714. );
  715. if (err !== null) return err;
  716. rules.push({
  717. type: KEYWORD_TO_API_MAP[action],
  718. address: target,
  719. });
  720. } else {
  721. return [
  722. rtree[k][1],
  723. rtree[k][2],
  724. "The redirect action requires a target parameter.",
  725. ];
  726. }
  727. } else {
  728. return [
  729. rtree[k][1],
  730. rtree[k][2],
  731. "Unrecognized action or directive in rule set.",
  732. ];
  733. }
  734. }
  735. return null;
  736. }
  737. function compile(src, rules, caps, tags) {
  738. try {
  739. if (typeof src !== "string")
  740. return [0, 0, '"src" parameter must be a string.'];
  741. // Pass 1: parse source into a tree of arrays of elements. Each element is a 3-item
  742. // tuple consisting of string, line number, and character index in line to enable
  743. // informative error messages to be returned.
  744. var blockStack = [[]];
  745. var curr = ["", -1, -1];
  746. var skipRestOfLine = false;
  747. for (
  748. let idx = 0, lineNo = 1, lineIdx = 0;
  749. idx < src.length;
  750. ++idx, ++lineIdx
  751. ) {
  752. let ch = src.charAt(idx);
  753. if (skipRestOfLine) {
  754. if (ch === "\r" || ch === "\n") {
  755. skipRestOfLine = false;
  756. ++lineNo;
  757. lineIdx = 0;
  758. }
  759. } else {
  760. switch (ch) {
  761. case "\n":
  762. ++lineNo;
  763. lineIdx = 0;
  764. case "\r":
  765. case "\t":
  766. case " ":
  767. if (curr[0].length > 0) {
  768. let endOfBlock = false;
  769. if (curr[0].charAt(curr[0].length - 1) === ";") {
  770. endOfBlock = true;
  771. curr[0] = curr[0].substr(0, curr[0].length - 1);
  772. }
  773. if (curr[0].length > 0) {
  774. blockStack[blockStack.length - 1].push(curr);
  775. }
  776. if (
  777. endOfBlock &&
  778. blockStack.length > 1 &&
  779. blockStack[blockStack.length - 1].length > 0
  780. ) {
  781. blockStack[blockStack.length - 2].push(
  782. blockStack[blockStack.length - 1],
  783. );
  784. blockStack.pop();
  785. } else if (curr[0] in OPEN_BLOCK_KEYWORDS) {
  786. blockStack.push([]);
  787. }
  788. curr = ["", -1, -1];
  789. }
  790. break;
  791. default:
  792. if (curr[0].length === 0) {
  793. if (ch === "#") {
  794. skipRestOfLine = true;
  795. continue;
  796. } else {
  797. curr[1] = lineNo;
  798. curr[2] = lineIdx;
  799. }
  800. }
  801. curr[0] += ch;
  802. break;
  803. }
  804. }
  805. }
  806. if (curr[0].length > 0) {
  807. if (curr[0].charAt(curr[0].length - 1) === ";")
  808. curr[0] = curr[0].substr(0, curr[0].length - 1);
  809. if (curr[0].length > 0) blockStack[blockStack.length - 1].push(curr);
  810. }
  811. while (
  812. blockStack.length > 1 &&
  813. blockStack[blockStack.length - 1].length > 0
  814. ) {
  815. blockStack[blockStack.length - 2].push(blockStack[blockStack.length - 1]);
  816. blockStack.pop();
  817. }
  818. var parsed = blockStack[0];
  819. // Pass 2: parse tree into capabilities, tags, rule sets, and document-level rules.
  820. let baseRuleTree = [];
  821. let macros = {};
  822. for (let i = 0; i < parsed.length; ++i) {
  823. let keyword =
  824. typeof parsed[i][0] === "string" ? parsed[i][0].toLowerCase() : null;
  825. if (keyword === "macro") {
  826. // Define macros
  827. if (
  828. i + 1 >= parsed.length ||
  829. !Array.isArray(parsed[i + 1]) ||
  830. parsed[i + 1].length < 1 ||
  831. !Array.isArray(parsed[i + 1][0])
  832. )
  833. return [
  834. parsed[i][1],
  835. parsed[i][2],
  836. "Macro definition is missing name.",
  837. ];
  838. let macro = parsed[++i];
  839. let macroName = macro[0][0].toLowerCase();
  840. let params = {};
  841. let parenIdx = macroName.indexOf("(");
  842. if (parenIdx > 0) {
  843. let pns = macroName.substr(parenIdx + 1).split(/[,)]+/);
  844. for (let k = 0; k < pns.length; ++k) {
  845. if (pns[k].length > 0) params[pns[k]] = k;
  846. }
  847. macroName = macroName.substr(0, parenIdx);
  848. }
  849. if (!_isValidName(macroName))
  850. return [macro[0][1], macro[0][2], "Invalid macro name."];
  851. if (macroName in RESERVED_WORDS)
  852. return [macro[0][1], macro[0][2], "Macro name is a reserved word."];
  853. if (macroName in macros)
  854. return [
  855. macro[0][1],
  856. macro[0][2],
  857. "Multiple definition of macro name.",
  858. ];
  859. macros[macroName] = {
  860. params: params,
  861. rules: macro.slice(1),
  862. };
  863. } else if (keyword === "tag") {
  864. // Define tags
  865. if (
  866. i + 1 >= parsed.length ||
  867. !Array.isArray(parsed[i + 1]) ||
  868. parsed[i + 1].length < 1 ||
  869. !Array.isArray(parsed[i + 1][0])
  870. )
  871. return [
  872. parsed[i][1],
  873. parsed[i][2],
  874. "Tag definition is missing name.",
  875. ];
  876. let tag = parsed[++i];
  877. let tagName = tag[0][0].toLowerCase();
  878. if (!_isValidName(tagName))
  879. return [tag[0][1], tag[0][2], "Invalid tag name."];
  880. if (tagName in RESERVED_WORDS)
  881. return [tag[0][1], tag[0][2], "Tag name is a reserved word."];
  882. if (tagName in tags)
  883. return [tag[0][1], tag[0][2], "Multiple definition of tag name."];
  884. let flags = {};
  885. let enums = {};
  886. let id = -1;
  887. let dfl = null;
  888. for (let k = 1; k < tag.length; ++k) {
  889. let tkeyword = tag[k][0].toLowerCase();
  890. if (tkeyword === "id") {
  891. if (id >= 0)
  892. return [tag[k][1], tag[k][2], "Duplicate tag id definition."];
  893. if (k + 1 >= tag.length)
  894. return [tag[k][1], tag[k][2], "Missing numeric value for ID."];
  895. id = _parseNum(tag[++k][0]);
  896. if (id < 0 || id > 0xffffffff)
  897. return [tag[k][1], tag[k][2], "Invalid or out of range tag ID."];
  898. } else if (tkeyword === "default") {
  899. if (dfl !== null)
  900. return [tag[k][1], tag[k][2], "Duplicate tag default directive."];
  901. if (k + 1 >= tag.length)
  902. return [tag[k][1], tag[k][2], "Missing value for default."];
  903. dfl = tag[++k][0];
  904. } else if (tkeyword === "flag") {
  905. if (k + 2 >= tag.length)
  906. return [
  907. tag[k][1],
  908. tag[k][2],
  909. "Missing tag flag name or bit index.",
  910. ];
  911. ++k;
  912. let bits = tag[k][0].split(/[,]+/);
  913. let mask = 0;
  914. for (let j = 0; j < bits.length; ++j) {
  915. let b = bits[j].toLowerCase();
  916. if (b in flags) {
  917. mask |= flags[b];
  918. } else {
  919. b = _parseNum(b);
  920. if (b < 0 || b > 31)
  921. return [
  922. tag[k][1],
  923. tag[k][2],
  924. "Bit index invalid, out of range, or references an undefined flag name.",
  925. ];
  926. mask |= 1 << b;
  927. }
  928. }
  929. let flagName = tag[++k][0].toLowerCase();
  930. if (!_isValidName(flagName))
  931. return [tag[k][1], tag[k][2], "Invalid or reserved flag name."];
  932. if (flagName in flags)
  933. return [
  934. tag[k][1],
  935. tag[k][2],
  936. "Duplicate flag name in tag definition.",
  937. ];
  938. flags[flagName] = mask;
  939. } else if (tkeyword === "enum") {
  940. if (k + 2 >= tag.length)
  941. return [tag[k][1], tag[k][2], "Missing tag enum name or value."];
  942. ++k;
  943. let value = _parseNum(tag[k][0]);
  944. if (value < 0 || value > 0xffffffff)
  945. return [
  946. tag[k][1],
  947. tag[k][2],
  948. "Tag enum value invalid or out of range.",
  949. ];
  950. let enumName = tag[++k][0].toLowerCase();
  951. if (!_isValidName(enumName))
  952. return [
  953. tag[k][1],
  954. tag[k][2],
  955. "Invalid or reserved tag enum name.",
  956. ];
  957. if (enumName in enums)
  958. return [
  959. tag[k][1],
  960. tag[k][2],
  961. "Duplicate enum name in tag definition.",
  962. ];
  963. enums[enumName] = value;
  964. } else {
  965. return [
  966. tag[k][1],
  967. tag[k][2],
  968. "Unrecognized keyword in tag definition.",
  969. ];
  970. }
  971. }
  972. if (id < 0)
  973. return [
  974. tag[0][1],
  975. tag[0][2],
  976. "Tag definition is missing a numeric ID.",
  977. ];
  978. if (typeof dfl === "string") {
  979. let dfl2 = enums[dfl];
  980. if (typeof dfl2 === "number") {
  981. dfl = dfl2;
  982. } else {
  983. dfl2 = flags[dfl];
  984. if (typeof dfl2 === "number") {
  985. dfl = dfl2;
  986. } else {
  987. dfl = Math.abs(parseInt(dfl) || 0) & 0xffffffff;
  988. }
  989. }
  990. } else if (typeof dfl === "number") {
  991. dfl = Math.abs(dfl) & 0xffffffff;
  992. }
  993. tags[tagName] = {
  994. id: id,
  995. default: dfl,
  996. enums: enums,
  997. flags: flags,
  998. };
  999. } else if (keyword === "cap") {
  1000. // Define capabilities
  1001. if (
  1002. i + 1 >= parsed.length ||
  1003. !Array.isArray(parsed[i + 1]) ||
  1004. parsed[i + 1].length < 1 ||
  1005. !Array.isArray(parsed[i + 1][0])
  1006. )
  1007. return [
  1008. parsed[i][1],
  1009. parsed[i][2],
  1010. "Capability definition is missing name.",
  1011. ];
  1012. let cap = parsed[++i];
  1013. let capName = cap[0][0].toLowerCase();
  1014. if (!_isValidName(capName))
  1015. return [cap[0][1], cap[0][2], "Invalid capability name."];
  1016. if (capName in RESERVED_WORDS)
  1017. return [cap[0][1], cap[0][2], "Capability name is a reserved word."];
  1018. if (capName in caps)
  1019. return [
  1020. cap[0][1],
  1021. cap[0][2],
  1022. "Multiple definition of capability name.",
  1023. ];
  1024. let capRules = [];
  1025. let id = -1;
  1026. let dfl = false;
  1027. for (let k = 1; k < cap.length; ++k) {
  1028. let dn =
  1029. typeof cap[k][0] === "string" ? cap[k][0].toLowerCase() : null;
  1030. if (dn === "id") {
  1031. if (id >= 0)
  1032. return [
  1033. cap[k][1],
  1034. cap[k][2],
  1035. "Duplicate id directive in capability definition.",
  1036. ];
  1037. if (k + 1 >= cap.length)
  1038. return [cap[k][1], cap[k][2], "Missing value for ID."];
  1039. id = _parseNum(cap[++k][0]);
  1040. if (id < 0 || id > 0xffffffff)
  1041. return [
  1042. cap[k - 1][1],
  1043. cap[k - 1][2],
  1044. "Invalid or out of range capability ID.",
  1045. ];
  1046. for (let cn in caps) {
  1047. if (caps[cn].id === id)
  1048. return [
  1049. cap[k - 1][1],
  1050. cap[k - 1][2],
  1051. "Duplicate capability ID.",
  1052. ];
  1053. }
  1054. } else if (dn === "default") {
  1055. dfl = true;
  1056. } else {
  1057. capRules.push(cap[k]);
  1058. }
  1059. }
  1060. if (id < 0)
  1061. return [
  1062. cap[0][1],
  1063. cap[0][2],
  1064. "Capability definition is missing a numeric ID.",
  1065. ];
  1066. caps[capName] = {
  1067. id: id,
  1068. default: dfl,
  1069. rules: capRules,
  1070. };
  1071. } else {
  1072. baseRuleTree.push(parsed[i]);
  1073. }
  1074. }
  1075. // Pass 3: render low-level ZeroTier rules arrays for capabilities and base.
  1076. for (let capName in caps) {
  1077. let r = [];
  1078. let err = _renderActions(caps[capName].rules, r, macros, caps, tags, {});
  1079. if (err !== null) return err;
  1080. caps[capName].rules = r;
  1081. }
  1082. let err = _renderActions(baseRuleTree, rules, macros, caps, tags, {});
  1083. if (err !== null) return err;
  1084. return null;
  1085. } catch (e) {
  1086. console.log(e.stack);
  1087. return [0, 0, "Unexpected exception: " + e.toString()];
  1088. }
  1089. }
  1090. exports.compile = compile;