ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing:
ircd-hybrid-8/src/conf_parser.y (file contents), Revision 1389 by michael, Tue May 1 13:08:29 2012 UTC vs.
ircd-hybrid/trunk/src/conf_parser.y (file contents), Revision 3506 by michael, Sun May 11 17:03:20 2014 UTC

# Line 1 | Line 1
1   /*
2 < *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  conf_parser.y: Parses the ircd configuration file.
2 > *  ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3   *
4 < *  Copyright (C) 2005 by the past and present ircd coders, and others.
4 > *  Copyright (c) 2000-2014 ircd-hybrid development team
5   *
6   *  This program is free software; you can redistribute it and/or modify
7   *  it under the terms of the GNU General Public License as published by
# Line 18 | Line 17
17   *  along with this program; if not, write to the Free Software
18   *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
19   *  USA
21 – *
22 – *  $Id$
20   */
21  
22 + /*! \file conf_parser.y
23 + * \brief Parses the ircd configuration file.
24 + * \version $Id$
25 + */
26 +
27 +
28   %{
29  
30   #define YY_NO_UNPUT
# Line 33 | Line 36
36   #include "ircd.h"
37   #include "list.h"
38   #include "conf.h"
39 + #include "conf_class.h"
40   #include "event.h"
41   #include "log.h"
42   #include "client.h"     /* for UMODE_ALL only */
43   #include "irc_string.h"
40 – #include "sprintf_irc.h"
44   #include "memory.h"
45   #include "modules.h"
46 < #include "s_serv.h"
46 > #include "server.h"
47   #include "hostmask.h"
48   #include "send.h"
49   #include "listener.h"
50   #include "resv.h"
51   #include "numeric.h"
52 < #include "s_user.h"
52 > #include "user.h"
53 > #include "motd.h"
54  
55   #ifdef HAVE_LIBCRYPTO
56   #include <openssl/rsa.h>
# Line 55 | Line 59
59   #include <openssl/dh.h>
60   #endif
61  
62 + #include "rsa.h"
63 +
64   int yylex(void);
65  
66 < static char *class_name = NULL;
67 < static struct ConfItem *yy_conf = NULL;
68 < static struct AccessItem *yy_aconf = NULL;
69 < static struct MatchItem *yy_match_item = NULL;
70 < static struct ClassItem *yy_class = NULL;
71 < static char *yy_class_name = NULL;
72 <
73 < static dlink_list col_conf_list  = { NULL, NULL, 0 };
74 < static unsigned int listener_flags = 0;
75 < static unsigned int regex_ban = 0;
76 < static char userbuf[IRCD_BUFSIZE];
77 < static char hostbuf[IRCD_BUFSIZE];
78 < static char reasonbuf[REASONLEN + 1];
79 < static char gecos_name[REALLEN * 4];
80 < static char lfile[IRCD_BUFSIZE];
81 < static unsigned int ltype = 0;
82 < static unsigned int lsize = 0;
83 < static char *resv_reason = NULL;
84 < static char *listener_address = NULL;
85 <
86 < struct CollectItem
87 < {
88 <  dlink_node node;
89 <  char *name;
90 <  char *user;
91 <  char *host;
92 <  char *passwd;
93 <  int  port;
94 <  int  flags;
95 < #ifdef HAVE_LIBCRYPTO
96 <  char *rsa_public_key_file;
97 <  RSA *rsa_public_key;
98 < #endif
99 < };
66 > static struct
67 > {
68 >  struct
69 >  {
70 >    dlink_list list;
71 >  } mask,
72 >    leaf,
73 >    hub;
74 >
75 >  struct
76 >  {
77 >    char buf[IRCD_BUFSIZE];
78 >  } name,
79 >    user,
80 >    host,
81 >    addr,
82 >    bind,
83 >    file,
84 >    ciph,
85 >    cert,
86 >    rpass,
87 >    spass,
88 >    class;
89 >
90 >  struct
91 >  {
92 >    unsigned int value;
93 >  } flags,
94 >    modes,
95 >    size,
96 >    type,
97 >    port,
98 >    aftype,
99 >    ping_freq,
100 >    max_perip,
101 >    con_freq,
102 >    min_idle,
103 >    max_idle,
104 >    max_total,
105 >    max_global,
106 >    max_local,
107 >    max_ident,
108 >    max_sendq,
109 >    max_recvq,
110 >    cidr_bitlen_ipv4,
111 >    cidr_bitlen_ipv6,
112 >    number_per_cidr;
113 > } block_state;
114  
115   static void
116 < free_collect_item(struct CollectItem *item)
116 > reset_block_state(void)
117   {
118 <  MyFree(item->name);
119 <  MyFree(item->user);
120 <  MyFree(item->host);
121 <  MyFree(item->passwd);
122 < #ifdef HAVE_LIBCRYPTO
123 <  MyFree(item->rsa_public_key_file);
124 < #endif
125 <  MyFree(item);
118 >  dlink_node *ptr = NULL, *ptr_next = NULL;
119 >
120 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.mask.list.head)
121 >  {
122 >    MyFree(ptr->data);
123 >    dlinkDelete(ptr, &block_state.mask.list);
124 >    free_dlink_node(ptr);
125 >  }
126 >
127 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.leaf.list.head)
128 >  {
129 >    MyFree(ptr->data);
130 >    dlinkDelete(ptr, &block_state.leaf.list);
131 >    free_dlink_node(ptr);
132 >  }
133 >
134 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.hub.list.head)
135 >  {
136 >    MyFree(ptr->data);
137 >    dlinkDelete(ptr, &block_state.hub.list);
138 >    free_dlink_node(ptr);
139 >  }
140 >
141 >  memset(&block_state, 0, sizeof(block_state));
142   }
143  
144   %}
# Line 113 | Line 149 | free_collect_item(struct CollectItem *it
149   }
150  
151   %token  ACCEPT_PASSWORD
116 – %token  ACTION
152   %token  ADMIN
153   %token  AFTYPE
119 – %token  T_ALLOW
154   %token  ANTI_NICK_FLOOD
155   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
156   %token  AUTOCONN
157 < %token  T_BLOCK
124 < %token  BURST_AWAY
125 < %token  BURST_TOPICWHO
126 < %token  BYTES KBYTES MBYTES GBYTES TBYTES
157 > %token  BYTES KBYTES MBYTES
158   %token  CALLER_ID_WAIT
159   %token  CAN_FLOOD
160   %token  CHANNEL
161 < %token  CIDR_BITLEN_IPV4
162 < %token  CIDR_BITLEN_IPV6
161 > %token  CIDR_BITLEN_IPV4
162 > %token  CIDR_BITLEN_IPV6
163   %token  CLASS
164   %token  CONNECT
165   %token  CONNECTFREQ
166 + %token  CYCLE_ON_HOST_CHANGE
167   %token  DEFAULT_FLOODCOUNT
168   %token  DEFAULT_SPLIT_SERVER_COUNT
169   %token  DEFAULT_SPLIT_USER_COUNT
# Line 140 | Line 172 | free_collect_item(struct CollectItem *it
172   %token  DIE
173   %token  DISABLE_AUTH
174   %token  DISABLE_FAKE_CHANNELS
143 – %token  DISABLE_HIDDEN
144 – %token  DISABLE_LOCAL_CHANNELS
175   %token  DISABLE_REMOTE_COMMANDS
176   %token  DOTS_IN_IDENT
147 – %token  DURATION
177   %token  EGDPOOL_PATH
178   %token  EMAIL
150 – %token  ENABLE
179   %token  ENCRYPTED
180   %token  EXCEED_LIMIT
181   %token  EXEMPT
182   %token  FAILED_OPER_NOTICE
155 – %token  IRCD_FLAGS
183   %token  FLATTEN_LINKS
184   %token  GECOS
185   %token  GENERAL
186   %token  GLINE
187 < %token  GLINES
187 > %token  GLINE_DURATION
188 > %token  GLINE_ENABLE
189   %token  GLINE_EXEMPT
162 – %token  GLINE_TIME
190   %token  GLINE_MIN_CIDR
191   %token  GLINE_MIN_CIDR6
192 + %token  GLINE_REQUEST_DURATION
193   %token  GLOBAL_KILL
166 – %token  IRCD_AUTH
167 – %token  NEED_IDENT
194   %token  HAVENT_READ_CONF
195   %token  HIDDEN
196 < %token  HIDDEN_NAME
196 > %token  HIDDEN_NAME
197 > %token  HIDE_IDLE
198 > %token  HIDE_IDLE_FROM_OPERS
199   %token  HIDE_SERVER_IPS
200   %token  HIDE_SERVERS
201 < %token  HIDE_SPOOF_IPS
201 > %token  HIDE_SERVICES
202 > %token  HIDE_SPOOF_IPS
203   %token  HOST
204   %token  HUB
205   %token  HUB_MASK
206   %token  IGNORE_BOGUS_TS
207   %token  INVISIBLE_ON_CONNECT
208   %token  IP
209 + %token  IRCD_AUTH
210 + %token  IRCD_FLAGS
211 + %token  IRCD_SID
212 + %token  JOIN_FLOOD_COUNT
213 + %token  JOIN_FLOOD_TIME
214   %token  KILL
215 < %token  KILL_CHASE_TIME_LIMIT
215 > %token  KILL_CHASE_TIME_LIMIT
216   %token  KLINE
217   %token  KLINE_EXEMPT
184 – %token  KLINE_REASON
185 – %token  KLINE_WITH_REASON
218   %token  KNOCK_DELAY
219   %token  KNOCK_DELAY_CHANNEL
220   %token  LEAF_MASK
221   %token  LINKS_DELAY
222   %token  LISTEN
223 < %token  T_LOG
223 > %token  MASK
224   %token  MAX_ACCEPT
225   %token  MAX_BANS
226 + %token  MAX_CHANS_PER_OPER
227   %token  MAX_CHANS_PER_USER
228   %token  MAX_GLOBAL
229   %token  MAX_IDENT
230 + %token  MAX_IDLE
231   %token  MAX_LOCAL
232   %token  MAX_NICK_CHANGES
233 + %token  MAX_NICK_LENGTH
234   %token  MAX_NICK_TIME
235   %token  MAX_NUMBER
236   %token  MAX_TARGETS
237 + %token  MAX_TOPIC_LENGTH
238   %token  MAX_WATCH
239 < %token  MESSAGE_LOCALE
239 > %token  MIN_IDLE
240   %token  MIN_NONWILDCARD
241   %token  MIN_NONWILDCARD_SIMPLE
242   %token  MODULE
243   %token  MODULES
244 + %token  MOTD
245   %token  NAME
246 + %token  NEED_IDENT
247   %token  NEED_PASSWORD
248   %token  NETWORK_DESC
249   %token  NETWORK_NAME
250   %token  NICK
213 – %token  NICK_CHANGES
251   %token  NO_CREATE_ON_SPLIT
252   %token  NO_JOIN_ON_SPLIT
253   %token  NO_OPER_FLOOD
254   %token  NO_TILDE
255   %token  NUMBER
219 – %token  NUMBER_PER_IDENT
256   %token  NUMBER_PER_CIDR
257   %token  NUMBER_PER_IP
222 – %token  NUMBER_PER_IP_GLOBAL
223 – %token  OPERATOR
224 – %token  OPERS_BYPASS_CALLERID
258   %token  OPER_ONLY_UMODES
259   %token  OPER_PASS_RESV
227 – %token  OPER_SPY_T
260   %token  OPER_UMODES
261 < %token  JOIN_FLOOD_COUNT
262 < %token  JOIN_FLOOD_TIME
261 > %token  OPERATOR
262 > %token  OPERS_BYPASS_CALLERID
263   %token  PACE_WAIT
264   %token  PACE_WAIT_SIMPLE
265   %token  PASSWORD
266   %token  PATH
267   %token  PING_COOKIE
268   %token  PING_TIME
237 – %token  PING_WARNING
269   %token  PORT
270   %token  QSTRING
271 < %token  QUIET_ON_BAN
271 > %token  RANDOM_IDLE
272   %token  REASON
273   %token  REDIRPORT
274   %token  REDIRSERV
244 – %token  REGEX_T
275   %token  REHASH
246 – %token  TREJECT_HOLD_TIME
276   %token  REMOTE
277   %token  REMOTEBAN
249 – %token  RESTRICT_CHANNELS
250 – %token  RESTRICTED
251 – %token  RSA_PRIVATE_KEY_FILE
252 – %token  RSA_PUBLIC_KEY_FILE
253 – %token  SSL_CERTIFICATE_FILE
254 – %token  SSL_DH_PARAM_FILE
255 – %token  T_SSL_CLIENT_METHOD
256 – %token  T_SSL_SERVER_METHOD
257 – %token  T_SSLV3
258 – %token  T_TLSV1
278   %token  RESV
279   %token  RESV_EXEMPT
280 < %token  SECONDS MINUTES HOURS DAYS WEEKS
281 < %token  SENDQ
280 > %token  RSA_PRIVATE_KEY_FILE
281 > %token  RSA_PUBLIC_KEY_FILE
282 > %token  SECONDS MINUTES HOURS DAYS WEEKS MONTHS YEARS
283   %token  SEND_PASSWORD
284 + %token  SENDQ
285   %token  SERVERHIDE
286   %token  SERVERINFO
266 – %token  IRCD_SID
267 – %token  TKLINE_EXPIRE_NOTICES
268 – %token  T_SHARED
269 – %token  T_CLUSTER
270 – %token  TYPE
287   %token  SHORT_MOTD
272 – %token  SILENT
288   %token  SPOOF
289   %token  SPOOF_NOTICE
290 + %token  SQUIT
291 + %token  SSL_CERTIFICATE_FILE
292 + %token  SSL_CERTIFICATE_FINGERPRINT
293 + %token  SSL_CONNECTION_REQUIRED
294 + %token  SSL_DH_PARAM_FILE
295   %token  STATS_E_DISABLED
296   %token  STATS_I_OPER_ONLY
297   %token  STATS_K_OPER_ONLY
298   %token  STATS_O_OPER_ONLY
299   %token  STATS_P_OPER_ONLY
300 < %token  TBOOL
281 < %token  TMASKED
282 < %token  T_REJECT
283 < %token  TS_MAX_DELTA
284 < %token  TS_WARN_DELTA
285 < %token  TWODOTS
300 > %token  STATS_U_OPER_ONLY
301   %token  T_ALL
302   %token  T_BOTS
288 – %token  T_SOFTCALLERID
303   %token  T_CALLERID
304   %token  T_CCONN
305 < %token  T_CCONN_FULL
292 < %token  T_SSL_CIPHER_LIST
293 < %token  T_CLIENT_FLOOD
305 > %token  T_CLUSTER
306   %token  T_DEAF
307   %token  T_DEBUG
308   %token  T_DLINE
297 – %token  T_DRONE
309   %token  T_EXTERNAL
310 + %token  T_FARCONNECT
311 + %token  T_FILE
312   %token  T_FULL
313 + %token  T_GLOBOPS
314   %token  T_INVISIBLE
315   %token  T_IPV4
316   %token  T_IPV6
317   %token  T_LOCOPS
318 + %token  T_LOG
319   %token  T_MAX_CLIENTS
320   %token  T_NCHANGE
321 + %token  T_NONONREG
322   %token  T_OPERWALL
323 + %token  T_RECVQ
324   %token  T_REJ
325 + %token  T_RESTART
326   %token  T_SERVER
327 + %token  T_SERVICE
328 + %token  T_SERVICES_NAME
329   %token  T_SERVNOTICE
330 + %token  T_SET
331 + %token  T_SHARED
332 + %token  T_SIZE
333   %token  T_SKILL
334 + %token  T_SOFTCALLERID
335   %token  T_SPY
336   %token  T_SSL
337 + %token  T_SSL_CIPHER_LIST
338 + %token  T_SSL_CLIENT_METHOD
339 + %token  T_SSL_SERVER_METHOD
340 + %token  T_SSLV3
341 + %token  T_TLSV1
342   %token  T_UMODES
343   %token  T_UNAUTH
344   %token  T_UNDLINE
345   %token  T_UNLIMITED
346   %token  T_UNRESV
347   %token  T_UNXLINE
319 – %token  T_GLOBOPS
348   %token  T_WALLOP
349 < %token  T_RESTART
350 < %token  T_SERVICE
351 < %token  T_SERVICES_NAME
349 > %token  T_WALLOPS
350 > %token  T_WEBIRC
351 > %token  TBOOL
352   %token  THROTTLE_TIME
353 < %token  TOPICBURST
353 > %token  TKLINE_EXPIRE_NOTICES
354 > %token  TMASKED
355   %token  TRUE_NO_OPER_FLOOD
356 < %token  TKLINE
357 < %token  TXLINE
358 < %token  TRESV
356 > %token  TS_MAX_DELTA
357 > %token  TS_WARN_DELTA
358 > %token  TWODOTS
359 > %token  TYPE
360   %token  UNKLINE
331 – %token  USER
361   %token  USE_EGD
333 – %token  USE_EXCEPT
334 – %token  USE_INVEX
335 – %token  USE_KNOCK
362   %token  USE_LOGGING
363 < %token  USE_WHOIS_ACTUALLY
363 > %token  USER
364   %token  VHOST
365   %token  VHOST6
366 + %token  WARN_NO_CONNECT_BLOCK
367   %token  XLINE
341 – %token  WARN
342 – %token  WARN_NO_NLINE
343 – %token  T_SIZE
344 – %token  T_FILE
368  
369 < %type <string> QSTRING
370 < %type <number> NUMBER
371 < %type <number> timespec
372 < %type <number> timespec_
373 < %type <number> sizespec
374 < %type <number> sizespec_
369 > %type  <string> QSTRING
370 > %type  <number> NUMBER
371 > %type  <number> timespec
372 > %type  <number> timespec_
373 > %type  <number> sizespec
374 > %type  <number> sizespec_
375  
376   %%
377 < conf:  
377 > conf:
378          | conf conf_item
379          ;
380  
381   conf_item:        admin_entry
382                  | logging_entry
383                  | oper_entry
384 <                | channel_entry
385 <                | class_entry
384 >                | channel_entry
385 >                | class_entry
386                  | listen_entry
387                  | auth_entry
388                  | serverinfo_entry
389 <                | serverhide_entry
389 >                | serverhide_entry
390                  | resv_entry
391                  | service_entry
392                  | shared_entry
393 <                | cluster_entry
393 >                | cluster_entry
394                  | connect_entry
395                  | kill_entry
396                  | deny_entry
397 <                | exempt_entry
398 <                | general_entry
376 <                | gline_entry
397 >                | exempt_entry
398 >                | general_entry
399                  | gecos_entry
400                  | modules_entry
401 +                | motd_entry
402                  | error ';'
403                  | error '}'
404          ;
405  
406  
407   timespec_: { $$ = 0; } | timespec;
408 < timespec:       NUMBER timespec_
409 <                {
410 <                        $$ = $1 + $2;
411 <                }
412 <                | NUMBER SECONDS timespec_
413 <                {
414 <                        $$ = $1 + $3;
415 <                }
416 <                | NUMBER MINUTES timespec_
417 <                {
418 <                        $$ = $1 * 60 + $3;
419 <                }
420 <                | NUMBER HOURS timespec_
421 <                {
422 <                        $$ = $1 * 60 * 60 + $3;
423 <                }
401 <                | NUMBER DAYS timespec_
402 <                {
403 <                        $$ = $1 * 60 * 60 * 24 + $3;
404 <                }
405 <                | NUMBER WEEKS timespec_
406 <                {
407 <                        $$ = $1 * 60 * 60 * 24 * 7 + $3;
408 <                }
409 <                ;
410 <
411 < sizespec_:      { $$ = 0; } | sizespec;
412 < sizespec:       NUMBER sizespec_ { $$ = $1 + $2; }
413 <                | NUMBER BYTES sizespec_ { $$ = $1 + $3; }
414 <                | NUMBER KBYTES sizespec_ { $$ = $1 * 1024 + $3; }
415 <                | NUMBER MBYTES sizespec_ { $$ = $1 * 1024 * 1024 + $3; }
416 <                ;
408 > timespec:  NUMBER timespec_         { $$ = $1 + $2; } |
409 >           NUMBER SECONDS timespec_ { $$ = $1 + $3; } |
410 >           NUMBER MINUTES timespec_ { $$ = $1 * 60 + $3; } |
411 >           NUMBER HOURS timespec_   { $$ = $1 * 60 * 60 + $3; } |
412 >           NUMBER DAYS timespec_    { $$ = $1 * 60 * 60 * 24 + $3; } |
413 >           NUMBER WEEKS timespec_   { $$ = $1 * 60 * 60 * 24 * 7 + $3; } |
414 >           NUMBER MONTHS timespec_  { $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3; } |
415 >           NUMBER YEARS timespec_   { $$ = $1 * 60 * 60 * 24 * 365 + $3; }
416 >           ;
417 >
418 > sizespec_:  { $$ = 0; } | sizespec;
419 > sizespec:   NUMBER sizespec_ { $$ = $1 + $2; } |
420 >            NUMBER BYTES sizespec_ { $$ = $1 + $3; } |
421 >            NUMBER KBYTES sizespec_ { $$ = $1 * 1024 + $3; } |
422 >            NUMBER MBYTES sizespec_ { $$ = $1 * 1024 * 1024 + $3; }
423 >            ;
424  
425  
426   /***************************************************************************
# Line 441 | Line 448 | modules_path: PATH '=' QSTRING ';'
448   serverinfo_entry: SERVERINFO '{' serverinfo_items '}' ';';
449  
450   serverinfo_items:       serverinfo_items serverinfo_item | serverinfo_item ;
451 < serverinfo_item:        serverinfo_name | serverinfo_vhost |
452 <                        serverinfo_hub | serverinfo_description |
453 <                        serverinfo_network_name | serverinfo_network_desc |
454 <                        serverinfo_max_clients | serverinfo_ssl_dh_param_file |
455 <                        serverinfo_rsa_private_key_file | serverinfo_vhost6 |
456 <                        serverinfo_sid | serverinfo_ssl_certificate_file |
457 <                        serverinfo_ssl_client_method | serverinfo_ssl_server_method |
451 > serverinfo_item:        serverinfo_name |
452 >                        serverinfo_vhost |
453 >                        serverinfo_hub |
454 >                        serverinfo_description |
455 >                        serverinfo_network_name |
456 >                        serverinfo_network_desc |
457 >                        serverinfo_max_clients |
458 >                        serverinfo_max_nick_length |
459 >                        serverinfo_max_topic_length |
460 >                        serverinfo_ssl_dh_param_file |
461 >                        serverinfo_rsa_private_key_file |
462 >                        serverinfo_vhost6 |
463 >                        serverinfo_sid |
464 >                        serverinfo_ssl_certificate_file |
465 >                        serverinfo_ssl_client_method |
466 >                        serverinfo_ssl_server_method |
467                          serverinfo_ssl_cipher_list |
468 <                        error ';' ;
468 >                        error ';' ;
469  
470  
471   serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
# Line 488 | Line 504 | server_method_type_item: T_SSLV3
504   serverinfo_ssl_certificate_file: SSL_CERTIFICATE_FILE '=' QSTRING ';'
505   {
506   #ifdef HAVE_LIBCRYPTO
507 <  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
507 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
508    {
509      if (!ServerInfo.rsa_private_key_file)
510      {
511 <      yyerror("No rsa_private_key_file specified, SSL disabled");
511 >      conf_error_report("No rsa_private_key_file specified, SSL disabled");
512        break;
513      }
514  
# Line 501 | Line 517 | serverinfo_ssl_certificate_file: SSL_CER
517          SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
518                                       SSL_FILETYPE_PEM) <= 0)
519      {
520 <      yyerror(ERR_lib_error_string(ERR_get_error()));
520 >      report_crypto_errors();
521 >      conf_error_report("Could not open/read certificate file");
522        break;
523      }
524  
# Line 510 | Line 527 | serverinfo_ssl_certificate_file: SSL_CER
527          SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
528                                      SSL_FILETYPE_PEM) <= 0)
529      {
530 <      yyerror(ERR_lib_error_string(ERR_get_error()));
530 >      report_crypto_errors();
531 >      conf_error_report("Could not read RSA private key");
532        break;
533      }
534  
535      if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
536          !SSL_CTX_check_private_key(ServerInfo.client_ctx))
537      {
538 <      yyerror(ERR_lib_error_string(ERR_get_error()));
538 >      report_crypto_errors();
539 >      conf_error_report("Could not read RSA private key");
540        break;
541      }
542    }
# Line 527 | Line 546 | serverinfo_ssl_certificate_file: SSL_CER
546   serverinfo_rsa_private_key_file: RSA_PRIVATE_KEY_FILE '=' QSTRING ';'
547   {
548   #ifdef HAVE_LIBCRYPTO
549 <  if (conf_parser_ctx.pass == 1)
531 <  {
532 <    BIO *file;
549 >  BIO *file = NULL;
550  
551 <    if (ServerInfo.rsa_private_key)
552 <    {
536 <      RSA_free(ServerInfo.rsa_private_key);
537 <      ServerInfo.rsa_private_key = NULL;
538 <    }
551 >  if (conf_parser_ctx.pass != 1)
552 >    break;
553  
554 <    if (ServerInfo.rsa_private_key_file)
555 <    {
556 <      MyFree(ServerInfo.rsa_private_key_file);
557 <      ServerInfo.rsa_private_key_file = NULL;
558 <    }
554 >  if (ServerInfo.rsa_private_key)
555 >  {
556 >    RSA_free(ServerInfo.rsa_private_key);
557 >    ServerInfo.rsa_private_key = NULL;
558 >  }
559  
560 <    DupString(ServerInfo.rsa_private_key_file, yylval.string);
560 >  if (ServerInfo.rsa_private_key_file)
561 >  {
562 >    MyFree(ServerInfo.rsa_private_key_file);
563 >    ServerInfo.rsa_private_key_file = NULL;
564 >  }
565  
566 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
549 <    {
550 <      yyerror("File open failed, ignoring");
551 <      break;
552 <    }
566 >  ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
567  
568 <    ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
568 >  if ((file = BIO_new_file(yylval.string, "r")) == NULL)
569 >  {
570 >    conf_error_report("File open failed, ignoring");
571 >    break;
572 >  }
573  
574 <    BIO_set_close(file, BIO_CLOSE);
557 <    BIO_free(file);
574 >  ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
575  
576 <    if (ServerInfo.rsa_private_key == NULL)
577 <    {
561 <      yyerror("Couldn't extract key, ignoring");
562 <      break;
563 <    }
576 >  BIO_set_close(file, BIO_CLOSE);
577 >  BIO_free(file);
578  
579 <    if (!RSA_check_key(ServerInfo.rsa_private_key))
580 <    {
581 <      RSA_free(ServerInfo.rsa_private_key);
582 <      ServerInfo.rsa_private_key = NULL;
579 >  if (ServerInfo.rsa_private_key == NULL)
580 >  {
581 >    conf_error_report("Couldn't extract key, ignoring");
582 >    break;
583 >  }
584  
585 <      yyerror("Invalid key, ignoring");
586 <      break;
587 <    }
585 >  if (!RSA_check_key(ServerInfo.rsa_private_key))
586 >  {
587 >    RSA_free(ServerInfo.rsa_private_key);
588 >    ServerInfo.rsa_private_key = NULL;
589  
590 <    /* require 2048 bit (256 byte) key */
591 <    if (RSA_size(ServerInfo.rsa_private_key) != 256)
592 <    {
577 <      RSA_free(ServerInfo.rsa_private_key);
578 <      ServerInfo.rsa_private_key = NULL;
590 >    conf_error_report("Invalid key, ignoring");
591 >    break;
592 >  }
593  
594 <      yyerror("Not a 2048 bit key, ignoring");
595 <    }
594 >  if (RSA_size(ServerInfo.rsa_private_key) < 128)
595 >  {
596 >    RSA_free(ServerInfo.rsa_private_key);
597 >    ServerInfo.rsa_private_key = NULL;
598 >
599 >    conf_error_report("Ignoring serverinfo::rsa_private_key_file -- need at least a 1024 bit key size");
600    }
601   #endif
602   };
# Line 600 | Line 618 | serverinfo_ssl_dh_param_file: SSL_DH_PAR
618        if (dh)
619        {
620          if (DH_size(dh) < 128)
621 <          ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
621 >          conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
622          else
623            SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
624  
# Line 619 | Line 637 | serverinfo_ssl_cipher_list: T_SSL_CIPHER
637   #endif
638   };
639  
640 < serverinfo_name: NAME '=' QSTRING ';'
640 > serverinfo_name: NAME '=' QSTRING ';'
641   {
642    /* this isn't rehashable */
643    if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
644    {
645      if (valid_servname(yylval.string))
646 <      DupString(ServerInfo.name, yylval.string);
646 >      ServerInfo.name = xstrdup(yylval.string);
647      else
648      {
649 <      ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::name -- invalid name. Aborting.");
649 >      conf_error_report("Ignoring serverinfo::name -- invalid name. Aborting.");
650        exit(0);
651      }
652    }
653   };
654  
655 < serverinfo_sid: IRCD_SID '=' QSTRING ';'
655 > serverinfo_sid: IRCD_SID '=' QSTRING ';'
656   {
657    /* this isn't rehashable */
658    if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
659    {
660      if (valid_sid(yylval.string))
661 <      DupString(ServerInfo.sid, yylval.string);
661 >      ServerInfo.sid = xstrdup(yylval.string);
662      else
663      {
664 <      ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::sid -- invalid SID. Aborting.");
664 >      conf_error_report("Ignoring serverinfo::sid -- invalid SID. Aborting.");
665        exit(0);
666      }
667    }
# Line 654 | Line 672 | serverinfo_description: DESCRIPTION '='
672    if (conf_parser_ctx.pass == 2)
673    {
674      MyFree(ServerInfo.description);
675 <    DupString(ServerInfo.description,yylval.string);
675 >    ServerInfo.description = xstrdup(yylval.string);
676    }
677   };
678  
# Line 664 | Line 682 | serverinfo_network_name: NETWORK_NAME '=
682    {
683      char *p;
684  
685 <    if ((p = strchr(yylval.string, ' ')) != NULL)
685 >    if ((p = strchr(yylval.string, ' ')))
686        p = '\0';
687  
688      MyFree(ServerInfo.network_name);
689 <    DupString(ServerInfo.network_name, yylval.string);
689 >    ServerInfo.network_name = xstrdup(yylval.string);
690    }
691   };
692  
693   serverinfo_network_desc: NETWORK_DESC '=' QSTRING ';'
694   {
695 <  if (conf_parser_ctx.pass == 2)
696 <  {
697 <    MyFree(ServerInfo.network_desc);
698 <    DupString(ServerInfo.network_desc, yylval.string);
699 <  }
695 >  if (conf_parser_ctx.pass != 2)
696 >    break;
697 >
698 >  MyFree(ServerInfo.network_desc);
699 >  ServerInfo.network_desc = xstrdup(yylval.string);
700   };
701  
702   serverinfo_vhost: VHOST '=' QSTRING ';'
# Line 697 | Line 715 | serverinfo_vhost: VHOST '=' QSTRING ';'
715        ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
716      else
717      {
718 <      assert(res != NULL);
718 >      assert(res);
719  
720        memcpy(&ServerInfo.ip, res->ai_addr, res->ai_addrlen);
721        ServerInfo.ip.ss.ss_family = res->ai_family;
# Line 726 | Line 744 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
744        ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost6(%s)", yylval.string);
745      else
746      {
747 <      assert(res != NULL);
747 >      assert(res);
748  
749        memcpy(&ServerInfo.ip6, res->ai_addr, res->ai_addrlen);
750        ServerInfo.ip6.ss.ss_family = res->ai_family;
# Line 741 | Line 759 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
759  
760   serverinfo_max_clients: T_MAX_CLIENTS '=' NUMBER ';'
761   {
762 <  if (conf_parser_ctx.pass == 2)
762 >  if (conf_parser_ctx.pass != 2)
763 >    break;
764 >
765 >  if ($3 < MAXCLIENTS_MIN)
766    {
767 <    recalc_fdlimit(NULL);
767 >    char buf[IRCD_BUFSIZE] = "";
768  
769 <    if ($3 < MAXCLIENTS_MIN)
770 <    {
771 <      char buf[IRCD_BUFSIZE];
772 <      ircsprintf(buf, "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
773 <      yyerror(buf);
774 <    }
775 <    else if ($3 > MAXCLIENTS_MAX)
776 <    {
777 <      char buf[IRCD_BUFSIZE];
778 <      ircsprintf(buf, "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
779 <      yyerror(buf);
780 <    }
781 <    else
782 <      ServerInfo.max_clients = $3;
769 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
770 >    conf_error_report(buf);
771 >    ServerInfo.max_clients = MAXCLIENTS_MIN;
772 >  }
773 >  else if ($3 > MAXCLIENTS_MAX)
774 >  {
775 >    char buf[IRCD_BUFSIZE] = "";
776 >
777 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
778 >    conf_error_report(buf);
779 >    ServerInfo.max_clients = MAXCLIENTS_MAX;
780 >  }
781 >  else
782 >    ServerInfo.max_clients = $3;
783 > };
784 >
785 > serverinfo_max_nick_length: MAX_NICK_LENGTH '=' NUMBER ';'
786 > {
787 >  if (conf_parser_ctx.pass != 2)
788 >    break;
789 >
790 >  if ($3 < 9)
791 >  {
792 >    conf_error_report("max_nick_length too low, setting to 9");
793 >    ServerInfo.max_nick_length = 9;
794 >  }
795 >  else if ($3 > NICKLEN)
796 >  {
797 >    char buf[IRCD_BUFSIZE] = "";
798 >
799 >    snprintf(buf, sizeof(buf), "max_nick_length too high, setting to %d", NICKLEN);
800 >    conf_error_report(buf);
801 >    ServerInfo.max_nick_length = NICKLEN;
802 >  }
803 >  else
804 >    ServerInfo.max_nick_length = $3;
805 > };
806 >
807 > serverinfo_max_topic_length: MAX_TOPIC_LENGTH '=' NUMBER ';'
808 > {
809 >  if (conf_parser_ctx.pass != 2)
810 >    break;
811 >
812 >  if ($3 < 80)
813 >  {
814 >    conf_error_report("max_topic_length too low, setting to 80");
815 >    ServerInfo.max_topic_length = 80;
816    }
817 +  else if ($3 > TOPICLEN)
818 +  {
819 +    char buf[IRCD_BUFSIZE] = "";
820 +
821 +    snprintf(buf, sizeof(buf), "max_topic_length too high, setting to %d", TOPICLEN);
822 +    conf_error_report(buf);
823 +    ServerInfo.max_topic_length = TOPICLEN;
824 +  }
825 +  else
826 +    ServerInfo.max_topic_length = $3;
827   };
828  
829 < serverinfo_hub: HUB '=' TBOOL ';'
829 > serverinfo_hub: HUB '=' TBOOL ';'
830   {
831    if (conf_parser_ctx.pass == 2)
832      ServerInfo.hub = yylval.number;
# Line 774 | Line 838 | serverinfo_hub: HUB '=' TBOOL ';'
838   admin_entry: ADMIN  '{' admin_items '}' ';' ;
839  
840   admin_items: admin_items admin_item | admin_item;
841 < admin_item:  admin_name | admin_description |
842 <             admin_email | error ';' ;
841 > admin_item:  admin_name |
842 >             admin_description |
843 >             admin_email |
844 >             error ';' ;
845  
846 < admin_name: NAME '=' QSTRING ';'
846 > admin_name: NAME '=' QSTRING ';'
847   {
848 <  if (conf_parser_ctx.pass == 2)
849 <  {
850 <    MyFree(AdminInfo.name);
851 <    DupString(AdminInfo.name, yylval.string);
852 <  }
848 >  if (conf_parser_ctx.pass != 2)
849 >    break;
850 >
851 >  MyFree(AdminInfo.name);
852 >  AdminInfo.name = xstrdup(yylval.string);
853   };
854  
855   admin_email: EMAIL '=' QSTRING ';'
856   {
857 <  if (conf_parser_ctx.pass == 2)
858 <  {
859 <    MyFree(AdminInfo.email);
860 <    DupString(AdminInfo.email, yylval.string);
861 <  }
857 >  if (conf_parser_ctx.pass != 2)
858 >    break;
859 >
860 >  MyFree(AdminInfo.email);
861 >  AdminInfo.email = xstrdup(yylval.string);
862   };
863  
864   admin_description: DESCRIPTION '=' QSTRING ';'
865   {
866 +  if (conf_parser_ctx.pass != 2)
867 +    break;
868 +
869 +  MyFree(AdminInfo.description);
870 +  AdminInfo.description = xstrdup(yylval.string);
871 + };
872 +
873 + /***************************************************************************
874 + * motd section
875 + ***************************************************************************/
876 + motd_entry: MOTD
877 + {
878    if (conf_parser_ctx.pass == 2)
879 <  {
880 <    MyFree(AdminInfo.description);
881 <    DupString(AdminInfo.description, yylval.string);
882 <  }
879 >    reset_block_state();
880 > } '{' motd_items '}' ';'
881 > {
882 >  dlink_node *ptr = NULL;
883 >
884 >  if (conf_parser_ctx.pass != 2)
885 >    break;
886 >
887 >  if (!block_state.file.buf[0])
888 >    break;
889 >
890 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
891 >    motd_add(ptr->data, block_state.file.buf);
892 > };
893 >
894 > motd_items: motd_items motd_item | motd_item;
895 > motd_item:  motd_mask | motd_file | error ';' ;
896 >
897 > motd_mask: MASK '=' QSTRING ';'
898 > {
899 >  if (conf_parser_ctx.pass == 2)
900 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
901 > };
902 >
903 > motd_file: T_FILE '=' QSTRING ';'
904 > {
905 >  if (conf_parser_ctx.pass == 2)
906 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
907   };
908  
909   /***************************************************************************
# Line 810 | Line 912 | admin_description: DESCRIPTION '=' QSTRI
912   logging_entry:          T_LOG  '{' logging_items '}' ';' ;
913   logging_items:          logging_items logging_item | logging_item ;
914  
915 < logging_item:           logging_use_logging | logging_file_entry |
916 <                        error ';' ;
915 > logging_item:           logging_use_logging | logging_file_entry |
916 >                        error ';' ;
917  
918   logging_use_logging: USE_LOGGING '=' TBOOL ';'
919   {
# Line 821 | Line 923 | logging_use_logging: USE_LOGGING '=' TBO
923  
924   logging_file_entry:
925   {
926 <  lfile[0] = '\0';
927 <  ltype = 0;
826 <  lsize = 0;
926 >  if (conf_parser_ctx.pass == 2)
927 >    reset_block_state();
928   } T_FILE  '{' logging_file_items '}' ';'
929   {
930 <  if (conf_parser_ctx.pass == 2 && ltype > 0)
931 <    log_add_file(ltype, lsize, lfile);
930 >  if (conf_parser_ctx.pass != 2)
931 >    break;
932 >
933 >  if (block_state.type.value && block_state.file.buf[0])
934 >    log_set_file(block_state.type.value, block_state.size.value,
935 >                 block_state.file.buf);
936   };
937  
938   logging_file_items: logging_file_items logging_file_item |
# Line 838 | Line 943 | logging_file_item:  logging_file_name |
943  
944   logging_file_name: NAME '=' QSTRING ';'
945   {
946 <  strlcpy(lfile, yylval.string, sizeof(lfile));
946 >  if (conf_parser_ctx.pass != 2)
947 >    break;
948 >
949 >  strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
950   }
951  
952   logging_file_size: T_SIZE '=' sizespec ';'
953   {
954 <  lsize = $3;
954 >  block_state.size.value = $3;
955   } | T_SIZE '=' T_UNLIMITED ';'
956   {
957 <  lsize = 0;
957 >  block_state.size.value = 0;
958   };
959  
960   logging_file_type: TYPE
961   {
962    if (conf_parser_ctx.pass == 2)
963 <    ltype = 0;
963 >    block_state.type.value = 0;
964   } '='  logging_file_type_items ';' ;
965  
966   logging_file_type_items: logging_file_type_items ',' logging_file_type_item | logging_file_type_item;
967   logging_file_type_item:  USER
968   {
969    if (conf_parser_ctx.pass == 2)
970 <    ltype = LOG_TYPE_USER;
970 >    block_state.type.value = LOG_TYPE_USER;
971   } | OPERATOR
972   {
973    if (conf_parser_ctx.pass == 2)
974 <    ltype = LOG_TYPE_OPER;
974 >    block_state.type.value = LOG_TYPE_OPER;
975   } | GLINE
976   {
977    if (conf_parser_ctx.pass == 2)
978 <    ltype = LOG_TYPE_GLINE;
978 >    block_state.type.value = LOG_TYPE_GLINE;
979 > } | XLINE
980 > {
981 >  if (conf_parser_ctx.pass == 2)
982 >    block_state.type.value = LOG_TYPE_XLINE;
983 > } | RESV
984 > {
985 >  if (conf_parser_ctx.pass == 2)
986 >    block_state.type.value = LOG_TYPE_RESV;
987   } | T_DLINE
988   {
989    if (conf_parser_ctx.pass == 2)
990 <    ltype = LOG_TYPE_DLINE;
990 >    block_state.type.value = LOG_TYPE_DLINE;
991   } | KLINE
992   {
993    if (conf_parser_ctx.pass == 2)
994 <    ltype = LOG_TYPE_KLINE;
994 >    block_state.type.value = LOG_TYPE_KLINE;
995   } | KILL
996   {
997    if (conf_parser_ctx.pass == 2)
998 <    ltype = LOG_TYPE_KILL;
998 >    block_state.type.value = LOG_TYPE_KILL;
999   } | T_DEBUG
1000   {
1001    if (conf_parser_ctx.pass == 2)
1002 <    ltype = LOG_TYPE_DEBUG;
1002 >    block_state.type.value = LOG_TYPE_DEBUG;
1003   };
1004  
1005  
1006   /***************************************************************************
1007   * section oper
1008   ***************************************************************************/
1009 < oper_entry: OPERATOR
1009 > oper_entry: OPERATOR
1010   {
1011 <  if (conf_parser_ctx.pass == 2)
1012 <  {
1013 <    yy_conf = make_conf_item(OPER_TYPE);
1014 <    yy_aconf = map_to_conf(yy_conf);
1015 <    SetConfEncrypted(yy_aconf); /* Yes, the default is encrypted */
900 <  }
901 <  else
902 <  {
903 <    MyFree(class_name);
904 <    class_name = NULL;
905 <  }
1011 >  if (conf_parser_ctx.pass != 2)
1012 >    break;
1013 >
1014 >  reset_block_state();
1015 >  block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1016   } '{' oper_items '}' ';'
1017   {
1018 <  if (conf_parser_ctx.pass == 2)
909 <  {
910 <    struct CollectItem *yy_tmp;
911 <    dlink_node *ptr;
912 <    dlink_node *next_ptr;
1018 >  dlink_node *ptr = NULL;
1019  
1020 <    conf_add_class_to_conf(yy_conf, class_name);
1020 >  if (conf_parser_ctx.pass != 2)
1021 >    break;
1022  
1023 <    /* Now, make sure there is a copy of the "base" given oper
1024 <     * block in each of the collected copies
1025 <     */
1023 >  if (!block_state.name.buf[0])
1024 >    break;
1025 > #ifdef HAVE_LIBCRYPTO
1026 >  if (!block_state.file.buf[0] &&
1027 >      !block_state.rpass.buf[0])
1028 >    break;
1029 > #else
1030 >  if (!block_state.rpass.buf[0])
1031 >    break;
1032 > #endif
1033  
1034 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1035 <    {
1036 <      struct AccessItem *new_aconf;
1037 <      struct ConfItem *new_conf;
924 <      yy_tmp = ptr->data;
925 <
926 <      new_conf = make_conf_item(OPER_TYPE);
927 <      new_aconf = (struct AccessItem *)map_to_conf(new_conf);
928 <
929 <      new_aconf->flags = yy_aconf->flags;
930 <
931 <      if (yy_conf->name != NULL)
932 <        DupString(new_conf->name, yy_conf->name);
933 <      if (yy_tmp->user != NULL)
934 <        DupString(new_aconf->user, yy_tmp->user);
935 <      else
936 <        DupString(new_aconf->user, "*");
937 <      if (yy_tmp->host != NULL)
938 <        DupString(new_aconf->host, yy_tmp->host);
939 <      else
940 <        DupString(new_aconf->host, "*");
941 <
942 <      new_aconf->type = parse_netmask(new_aconf->host, &new_aconf->addr,
943 <                                     &new_aconf->bits);
944 <
945 <      conf_add_class_to_conf(new_conf, class_name);
946 <      if (yy_aconf->passwd != NULL)
947 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1034 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1035 >  {
1036 >    struct MaskItem *conf = NULL;
1037 >    struct split_nuh_item nuh;
1038  
1039 <      new_aconf->port = yy_aconf->port;
1040 < #ifdef HAVE_LIBCRYPTO
1041 <      if (yy_aconf->rsa_public_key_file != NULL)
1042 <      {
1043 <        BIO *file;
1039 >    nuh.nuhmask  = ptr->data;
1040 >    nuh.nickptr  = NULL;
1041 >    nuh.userptr  = block_state.user.buf;
1042 >    nuh.hostptr  = block_state.host.buf;
1043 >    nuh.nicksize = 0;
1044 >    nuh.usersize = sizeof(block_state.user.buf);
1045 >    nuh.hostsize = sizeof(block_state.host.buf);
1046 >    split_nuh(&nuh);
1047  
1048 <        DupString(new_aconf->rsa_public_key_file,
1049 <                  yy_aconf->rsa_public_key_file);
1048 >    conf         = conf_make(CONF_OPER);
1049 >    conf->name   = xstrdup(block_state.name.buf);
1050 >    conf->user   = xstrdup(block_state.user.buf);
1051 >    conf->host   = xstrdup(block_state.host.buf);
1052 >
1053 >    if (block_state.cert.buf[0])
1054 >      conf->certfp = xstrdup(block_state.cert.buf);
1055 >
1056 >    if (block_state.rpass.buf[0])
1057 >      conf->passwd = xstrdup(block_state.rpass.buf);
1058 >
1059 >    conf->flags = block_state.flags.value;
1060 >    conf->modes = block_state.modes.value;
1061 >    conf->port  = block_state.port.value;
1062 >    conf->htype = parse_netmask(conf->host, &conf->addr, &conf->bits);
1063  
1064 <        file = BIO_new_file(yy_aconf->rsa_public_key_file, "r");
959 <        new_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file,
960 <                                                           NULL, 0, NULL);
961 <        BIO_set_close(file, BIO_CLOSE);
962 <        BIO_free(file);
963 <      }
964 < #endif
1064 >    conf_add_class_to_conf(conf, block_state.class.buf);
1065  
1066   #ifdef HAVE_LIBCRYPTO
1067 <      if (yy_tmp->name && (yy_tmp->passwd || yy_aconf->rsa_public_key)
1068 <          && yy_tmp->host)
1069 < #else
1070 <      if (yy_tmp->name && yy_tmp->passwd && yy_tmp->host)
1071 < #endif
1067 >    if (block_state.file.buf[0])
1068 >    {
1069 >      BIO *file = NULL;
1070 >      RSA *pkey = NULL;
1071 >
1072 >      if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
1073        {
1074 <        conf_add_class_to_conf(new_conf, class_name);
1075 <        if (yy_tmp->name != NULL)
975 <          DupString(new_conf->name, yy_tmp->name);
1074 >        conf_error_report("Ignoring rsa_public_key_file -- file doesn't exist");
1075 >        break;
1076        }
1077  
1078 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1079 <      free_collect_item(yy_tmp);
980 <    }
981 <
982 <    yy_conf = NULL;
983 <    yy_aconf = NULL;
1078 >      if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
1079 >        conf_error_report("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1080  
1081 <
1082 <    MyFree(class_name);
1083 <    class_name = NULL;
1081 >      conf->rsa_public_key = pkey;
1082 >      BIO_set_close(file, BIO_CLOSE);
1083 >      BIO_free(file);
1084 >    }
1085 > #endif /* HAVE_LIBCRYPTO */
1086    }
1087 < };
1087 > };
1088  
1089   oper_items:     oper_items oper_item | oper_item;
1090 < oper_item:      oper_name | oper_user | oper_password |
1091 <                oper_umodes | oper_class | oper_encrypted |
1092 <                oper_rsa_public_key_file | oper_flags | error ';' ;
1090 > oper_item:      oper_name |
1091 >                oper_user |
1092 >                oper_password |
1093 >                oper_umodes |
1094 >                oper_class |
1095 >                oper_encrypted |
1096 >                oper_rsa_public_key_file |
1097 >                oper_ssl_certificate_fingerprint |
1098 >                oper_ssl_connection_required |
1099 >                oper_flags |
1100 >                error ';' ;
1101  
1102   oper_name: NAME '=' QSTRING ';'
1103   {
1104    if (conf_parser_ctx.pass == 2)
1105 <  {
1000 <    MyFree(yy_conf->name);
1001 <    DupString(yy_conf->name, yylval.string);
1002 <  }
1105 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1106   };
1107  
1108   oper_user: USER '=' QSTRING ';'
1109   {
1110    if (conf_parser_ctx.pass == 2)
1111 <  {
1009 <    struct split_nuh_item nuh;
1010 <
1011 <    nuh.nuhmask  = yylval.string;
1012 <    nuh.nickptr  = NULL;
1013 <    nuh.userptr  = userbuf;
1014 <    nuh.hostptr  = hostbuf;
1015 <
1016 <    nuh.nicksize = 0;
1017 <    nuh.usersize = sizeof(userbuf);
1018 <    nuh.hostsize = sizeof(hostbuf);
1019 <
1020 <    split_nuh(&nuh);
1021 <
1022 <    if (yy_aconf->user == NULL)
1023 <    {
1024 <      DupString(yy_aconf->user, userbuf);
1025 <      DupString(yy_aconf->host, hostbuf);
1026 <
1027 <      yy_aconf->type = parse_netmask(yy_aconf->host, &yy_aconf->addr,
1028 <                                    &yy_aconf->bits);
1029 <    }
1030 <    else
1031 <    {
1032 <      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
1033 <
1034 <      DupString(yy_tmp->user, userbuf);
1035 <      DupString(yy_tmp->host, hostbuf);
1036 <
1037 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1038 <    }
1039 <  }
1111 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1112   };
1113  
1114   oper_password: PASSWORD '=' QSTRING ';'
1115   {
1116    if (conf_parser_ctx.pass == 2)
1117 <  {
1046 <    if (yy_aconf->passwd != NULL)
1047 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1048 <
1049 <    MyFree(yy_aconf->passwd);
1050 <    DupString(yy_aconf->passwd, yylval.string);
1051 <  }
1117 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1118   };
1119  
1120   oper_encrypted: ENCRYPTED '=' TBOOL ';'
1121   {
1122 <  if (conf_parser_ctx.pass == 2)
1123 <  {
1124 <    if (yylval.number)
1125 <      SetConfEncrypted(yy_aconf);
1126 <    else
1127 <      ClearConfEncrypted(yy_aconf);
1128 <  }
1122 >  if (conf_parser_ctx.pass != 2)
1123 >    break;
1124 >
1125 >  if (yylval.number)
1126 >    block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1127 >  else
1128 >    block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1129   };
1130  
1131   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
1132   {
1067 – #ifdef HAVE_LIBCRYPTO
1133    if (conf_parser_ctx.pass == 2)
1134 <  {
1135 <    BIO *file;
1071 <
1072 <    if (yy_aconf->rsa_public_key != NULL)
1073 <    {
1074 <      RSA_free(yy_aconf->rsa_public_key);
1075 <      yy_aconf->rsa_public_key = NULL;
1076 <    }
1077 <
1078 <    if (yy_aconf->rsa_public_key_file != NULL)
1079 <    {
1080 <      MyFree(yy_aconf->rsa_public_key_file);
1081 <      yy_aconf->rsa_public_key_file = NULL;
1082 <    }
1083 <
1084 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
1085 <    file = BIO_new_file(yylval.string, "r");
1086 <
1087 <    if (file == NULL)
1088 <    {
1089 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
1090 <      break;
1091 <    }
1134 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1135 > };
1136  
1137 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
1137 > oper_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
1138 > {
1139 >  if (conf_parser_ctx.pass == 2)
1140 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
1141 > };
1142  
1143 <    if (yy_aconf->rsa_public_key == NULL)
1144 <    {
1145 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1146 <      break;
1099 <    }
1143 > oper_ssl_connection_required: SSL_CONNECTION_REQUIRED '=' TBOOL ';'
1144 > {
1145 >  if (conf_parser_ctx.pass != 2)
1146 >    break;
1147  
1148 <    BIO_set_close(file, BIO_CLOSE);
1149 <    BIO_free(file);
1150 <  }
1151 < #endif /* HAVE_LIBCRYPTO */
1148 >  if (yylval.number)
1149 >    block_state.flags.value |= CONF_FLAGS_SSL;
1150 >  else
1151 >    block_state.flags.value &= ~CONF_FLAGS_SSL;
1152   };
1153  
1154   oper_class: CLASS '=' QSTRING ';'
1155   {
1156    if (conf_parser_ctx.pass == 2)
1157 <  {
1111 <    MyFree(class_name);
1112 <    DupString(class_name, yylval.string);
1113 <  }
1157 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1158   };
1159  
1160   oper_umodes: T_UMODES
1161   {
1162    if (conf_parser_ctx.pass == 2)
1163 <    yy_aconf->modes = 0;
1163 >    block_state.modes.value = 0;
1164   } '='  oper_umodes_items ';' ;
1165  
1166   oper_umodes_items: oper_umodes_items ',' oper_umodes_item | oper_umodes_item;
1167   oper_umodes_item:  T_BOTS
1168   {
1169    if (conf_parser_ctx.pass == 2)
1170 <    yy_aconf->modes |= UMODE_BOTS;
1170 >    block_state.modes.value |= UMODE_BOTS;
1171   } | T_CCONN
1172   {
1173    if (conf_parser_ctx.pass == 2)
1174 <    yy_aconf->modes |= UMODE_CCONN;
1131 < } | T_CCONN_FULL
1132 < {
1133 <  if (conf_parser_ctx.pass == 2)
1134 <    yy_aconf->modes |= UMODE_CCONN_FULL;
1174 >    block_state.modes.value |= UMODE_CCONN;
1175   } | T_DEAF
1176   {
1177    if (conf_parser_ctx.pass == 2)
1178 <    yy_aconf->modes |= UMODE_DEAF;
1178 >    block_state.modes.value |= UMODE_DEAF;
1179   } | T_DEBUG
1180   {
1181    if (conf_parser_ctx.pass == 2)
1182 <    yy_aconf->modes |= UMODE_DEBUG;
1182 >    block_state.modes.value |= UMODE_DEBUG;
1183   } | T_FULL
1184   {
1185    if (conf_parser_ctx.pass == 2)
1186 <    yy_aconf->modes |= UMODE_FULL;
1186 >    block_state.modes.value |= UMODE_FULL;
1187   } | HIDDEN
1188   {
1189    if (conf_parser_ctx.pass == 2)
1190 <    yy_aconf->modes |= UMODE_HIDDEN;
1190 >    block_state.modes.value |= UMODE_HIDDEN;
1191 > } | HIDE_IDLE
1192 > {
1193 >  if (conf_parser_ctx.pass == 2)
1194 >    block_state.modes.value |= UMODE_HIDEIDLE;
1195   } | T_SKILL
1196   {
1197    if (conf_parser_ctx.pass == 2)
1198 <    yy_aconf->modes |= UMODE_SKILL;
1198 >    block_state.modes.value |= UMODE_SKILL;
1199   } | T_NCHANGE
1200   {
1201    if (conf_parser_ctx.pass == 2)
1202 <    yy_aconf->modes |= UMODE_NCHANGE;
1202 >    block_state.modes.value |= UMODE_NCHANGE;
1203   } | T_REJ
1204   {
1205    if (conf_parser_ctx.pass == 2)
1206 <    yy_aconf->modes |= UMODE_REJ;
1206 >    block_state.modes.value |= UMODE_REJ;
1207   } | T_UNAUTH
1208   {
1209    if (conf_parser_ctx.pass == 2)
1210 <    yy_aconf->modes |= UMODE_UNAUTH;
1210 >    block_state.modes.value |= UMODE_UNAUTH;
1211   } | T_SPY
1212   {
1213    if (conf_parser_ctx.pass == 2)
1214 <    yy_aconf->modes |= UMODE_SPY;
1214 >    block_state.modes.value |= UMODE_SPY;
1215   } | T_EXTERNAL
1216   {
1217    if (conf_parser_ctx.pass == 2)
1218 <    yy_aconf->modes |= UMODE_EXTERNAL;
1218 >    block_state.modes.value |= UMODE_EXTERNAL;
1219   } | T_OPERWALL
1220   {
1221    if (conf_parser_ctx.pass == 2)
1222 <    yy_aconf->modes |= UMODE_OPERWALL;
1222 >    block_state.modes.value |= UMODE_OPERWALL;
1223   } | T_SERVNOTICE
1224   {
1225    if (conf_parser_ctx.pass == 2)
1226 <    yy_aconf->modes |= UMODE_SERVNOTICE;
1226 >    block_state.modes.value |= UMODE_SERVNOTICE;
1227   } | T_INVISIBLE
1228   {
1229    if (conf_parser_ctx.pass == 2)
1230 <    yy_aconf->modes |= UMODE_INVISIBLE;
1230 >    block_state.modes.value |= UMODE_INVISIBLE;
1231   } | T_WALLOP
1232   {
1233    if (conf_parser_ctx.pass == 2)
1234 <    yy_aconf->modes |= UMODE_WALLOP;
1234 >    block_state.modes.value |= UMODE_WALLOP;
1235   } | T_SOFTCALLERID
1236   {
1237    if (conf_parser_ctx.pass == 2)
1238 <    yy_aconf->modes |= UMODE_SOFTCALLERID;
1238 >    block_state.modes.value |= UMODE_SOFTCALLERID;
1239   } | T_CALLERID
1240   {
1241    if (conf_parser_ctx.pass == 2)
1242 <    yy_aconf->modes |= UMODE_CALLERID;
1242 >    block_state.modes.value |= UMODE_CALLERID;
1243   } | T_LOCOPS
1244   {
1245    if (conf_parser_ctx.pass == 2)
1246 <    yy_aconf->modes |= UMODE_LOCOPS;
1246 >    block_state.modes.value |= UMODE_LOCOPS;
1247 > } | T_NONONREG
1248 > {
1249 >  if (conf_parser_ctx.pass == 2)
1250 >    block_state.modes.value |= UMODE_REGONLY;
1251 > } | T_FARCONNECT
1252 > {
1253 >  if (conf_parser_ctx.pass == 2)
1254 >    block_state.modes.value |= UMODE_FARCONNECT;
1255   };
1256  
1257   oper_flags: IRCD_FLAGS
1258   {
1259    if (conf_parser_ctx.pass == 2)
1260 <    yy_aconf->port = 0;
1260 >    block_state.port.value = 0;
1261   } '='  oper_flags_items ';';
1262  
1263   oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1264 < oper_flags_item: GLOBAL_KILL
1264 > oper_flags_item: KILL ':' REMOTE
1265   {
1266    if (conf_parser_ctx.pass == 2)
1267 <    yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1268 < } | REMOTE
1267 >    block_state.port.value |= OPER_FLAG_KILL_REMOTE;
1268 > } | KILL
1269   {
1270    if (conf_parser_ctx.pass == 2)
1271 <    yy_aconf->port |= OPER_FLAG_REMOTE;
1271 >    block_state.port.value |= OPER_FLAG_KILL;
1272 > } | CONNECT ':' REMOTE
1273 > {
1274 >  if (conf_parser_ctx.pass == 2)
1275 >    block_state.port.value |= OPER_FLAG_CONNECT_REMOTE;
1276 > } | CONNECT
1277 > {
1278 >  if (conf_parser_ctx.pass == 2)
1279 >    block_state.port.value |= OPER_FLAG_CONNECT;
1280 > } | SQUIT ':' REMOTE
1281 > {
1282 >  if (conf_parser_ctx.pass == 2)
1283 >    block_state.port.value |= OPER_FLAG_SQUIT_REMOTE;
1284 > } | SQUIT
1285 > {
1286 >  if (conf_parser_ctx.pass == 2)
1287 >    block_state.port.value |= OPER_FLAG_SQUIT;
1288   } | KLINE
1289   {
1290    if (conf_parser_ctx.pass == 2)
1291 <    yy_aconf->port |= OPER_FLAG_K;
1291 >    block_state.port.value |= OPER_FLAG_K;
1292   } | UNKLINE
1293   {
1294    if (conf_parser_ctx.pass == 2)
1295 <    yy_aconf->port |= OPER_FLAG_UNKLINE;
1295 >    block_state.port.value |= OPER_FLAG_UNKLINE;
1296   } | T_DLINE
1297   {
1298    if (conf_parser_ctx.pass == 2)
1299 <    yy_aconf->port |= OPER_FLAG_DLINE;
1299 >    block_state.port.value |= OPER_FLAG_DLINE;
1300   } | T_UNDLINE
1301   {
1302    if (conf_parser_ctx.pass == 2)
1303 <    yy_aconf->port |= OPER_FLAG_UNDLINE;
1303 >    block_state.port.value |= OPER_FLAG_UNDLINE;
1304   } | XLINE
1305   {
1306    if (conf_parser_ctx.pass == 2)
1307 <    yy_aconf->port |= OPER_FLAG_X;
1307 >    block_state.port.value |= OPER_FLAG_XLINE;
1308 > } | T_UNXLINE
1309 > {
1310 >  if (conf_parser_ctx.pass == 2)
1311 >    block_state.port.value |= OPER_FLAG_UNXLINE;
1312   } | GLINE
1313   {
1314    if (conf_parser_ctx.pass == 2)
1315 <    yy_aconf->port |= OPER_FLAG_GLINE;
1315 >    block_state.port.value |= OPER_FLAG_GLINE;
1316   } | DIE
1317   {
1318    if (conf_parser_ctx.pass == 2)
1319 <    yy_aconf->port |= OPER_FLAG_DIE;
1319 >    block_state.port.value |= OPER_FLAG_DIE;
1320   } | T_RESTART
1321   {
1322    if (conf_parser_ctx.pass == 2)
1323 <    yy_aconf->port |= OPER_FLAG_RESTART;
1323 >    block_state.port.value |= OPER_FLAG_RESTART;
1324   } | REHASH
1325   {
1326    if (conf_parser_ctx.pass == 2)
1327 <    yy_aconf->port |= OPER_FLAG_REHASH;
1327 >    block_state.port.value |= OPER_FLAG_REHASH;
1328   } | ADMIN
1329   {
1330    if (conf_parser_ctx.pass == 2)
1331 <    yy_aconf->port |= OPER_FLAG_ADMIN;
1260 < } | NICK_CHANGES
1261 < {
1262 <  if (conf_parser_ctx.pass == 2)
1263 <    yy_aconf->port |= OPER_FLAG_N;
1331 >    block_state.port.value |= OPER_FLAG_ADMIN;
1332   } | T_OPERWALL
1333   {
1334    if (conf_parser_ctx.pass == 2)
1335 <    yy_aconf->port |= OPER_FLAG_OPERWALL;
1335 >    block_state.port.value |= OPER_FLAG_OPERWALL;
1336   } | T_GLOBOPS
1337   {
1338    if (conf_parser_ctx.pass == 2)
1339 <    yy_aconf->port |= OPER_FLAG_GLOBOPS;
1340 < } | OPER_SPY_T
1339 >    block_state.port.value |= OPER_FLAG_GLOBOPS;
1340 > } | T_WALLOPS
1341   {
1342    if (conf_parser_ctx.pass == 2)
1343 <    yy_aconf->port |= OPER_FLAG_OPER_SPY;
1343 >    block_state.port.value |= OPER_FLAG_WALLOPS;
1344 > } | T_LOCOPS
1345 > {
1346 >  if (conf_parser_ctx.pass == 2)
1347 >    block_state.port.value |= OPER_FLAG_LOCOPS;
1348   } | REMOTEBAN
1349   {
1350    if (conf_parser_ctx.pass == 2)
1351 <    yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1351 >    block_state.port.value |= OPER_FLAG_REMOTEBAN;
1352 > } | T_SET
1353 > {
1354 >  if (conf_parser_ctx.pass == 2)
1355 >    block_state.port.value |= OPER_FLAG_SET;
1356   } | MODULE
1357   {
1358    if (conf_parser_ctx.pass == 2)
1359 <    yy_aconf->port |= OPER_FLAG_MODULE;
1359 >    block_state.port.value |= OPER_FLAG_MODULE;
1360   };
1361  
1362  
# Line 1289 | Line 1365 | oper_flags_item: GLOBAL_KILL
1365   ***************************************************************************/
1366   class_entry: CLASS
1367   {
1368 <  if (conf_parser_ctx.pass == 1)
1369 <  {
1294 <    yy_conf = make_conf_item(CLASS_TYPE);
1295 <    yy_class = map_to_conf(yy_conf);
1296 <  }
1297 < } '{' class_items '}' ';'
1298 < {
1299 <  if (conf_parser_ctx.pass == 1)
1300 <  {
1301 <    struct ConfItem *cconf = NULL;
1302 <    struct ClassItem *class = NULL;
1368 >  if (conf_parser_ctx.pass != 1)
1369 >    break;
1370  
1371 <    if (yy_class_name == NULL)
1305 <      delete_conf_item(yy_conf);
1306 <    else
1307 <    {
1308 <      cconf = find_exact_name_conf(CLASS_TYPE, NULL, yy_class_name, NULL, NULL);
1309 <
1310 <      if (cconf != NULL)                /* The class existed already */
1311 <      {
1312 <        int user_count = 0;
1313 <
1314 <        rebuild_cidr_class(cconf, yy_class);
1315 <
1316 <        class = map_to_conf(cconf);
1371 >  reset_block_state();
1372  
1373 <        user_count = class->curr_user_count;
1374 <        memcpy(class, yy_class, sizeof(*class));
1375 <        class->curr_user_count = user_count;
1376 <        class->active = 1;
1373 >  block_state.ping_freq.value = DEFAULT_PINGFREQUENCY;
1374 >  block_state.con_freq.value  = DEFAULT_CONNECTFREQUENCY;
1375 >  block_state.max_total.value = MAXIMUM_LINKS_DEFAULT;
1376 >  block_state.max_sendq.value = DEFAULT_SENDQ;
1377 >  block_state.max_recvq.value = DEFAULT_RECVQ;
1378 > } '{' class_items '}' ';'
1379 > {
1380 >  struct ClassItem *class = NULL;
1381  
1382 <        delete_conf_item(yy_conf);
1382 >  if (conf_parser_ctx.pass != 1)
1383 >    break;
1384  
1385 <        MyFree(cconf->name);            /* Allows case change of class name */
1386 <        cconf->name = yy_class_name;
1327 <      }
1328 <      else      /* Brand new class */
1329 <      {
1330 <        MyFree(yy_conf->name);          /* just in case it was allocated */
1331 <        yy_conf->name = yy_class_name;
1332 <        yy_class->active = 1;
1333 <      }
1334 <    }
1385 >  if (!block_state.class.buf[0])
1386 >    break;
1387  
1388 <    yy_class_name = NULL;
1389 <  }
1388 >  if (!(class = class_find(block_state.class.buf, 0)))
1389 >    class = class_make();
1390 >
1391 >  class->active = 1;
1392 >  MyFree(class->name);
1393 >  class->name = xstrdup(block_state.class.buf);
1394 >  class->ping_freq = block_state.ping_freq.value;
1395 >  class->max_perip = block_state.max_perip.value;
1396 >  class->con_freq = block_state.con_freq.value;
1397 >  class->max_total = block_state.max_total.value;
1398 >  class->max_global = block_state.max_global.value;
1399 >  class->max_local = block_state.max_local.value;
1400 >  class->max_ident = block_state.max_ident.value;
1401 >  class->max_sendq = block_state.max_sendq.value;
1402 >  class->max_recvq = block_state.max_recvq.value;
1403 >
1404 >  if (block_state.min_idle.value > block_state.max_idle.value)
1405 >  {
1406 >    block_state.min_idle.value = 0;
1407 >    block_state.max_idle.value = 0;
1408 >    block_state.flags.value &= ~CLASS_FLAGS_FAKE_IDLE;
1409 >  }
1410 >
1411 >  class->flags = block_state.flags.value;
1412 >  class->min_idle = block_state.min_idle.value;
1413 >  class->max_idle = block_state.max_idle.value;
1414 >
1415 >  if (class->number_per_cidr && block_state.number_per_cidr.value)
1416 >    if ((class->cidr_bitlen_ipv4 && block_state.cidr_bitlen_ipv4.value) ||
1417 >        (class->cidr_bitlen_ipv6 && block_state.cidr_bitlen_ipv6.value))
1418 >      if ((class->cidr_bitlen_ipv4 != block_state.cidr_bitlen_ipv4.value) ||
1419 >          (class->cidr_bitlen_ipv6 != block_state.cidr_bitlen_ipv6.value))
1420 >        rebuild_cidr_list(class);
1421 >
1422 >  class->cidr_bitlen_ipv4 = block_state.cidr_bitlen_ipv4.value;
1423 >  class->cidr_bitlen_ipv6 = block_state.cidr_bitlen_ipv6.value;
1424 >  class->number_per_cidr = block_state.number_per_cidr.value;
1425   };
1426  
1427   class_items:    class_items class_item | class_item;
1428   class_item:     class_name |
1429 <                class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1429 >                class_cidr_bitlen_ipv4 |
1430 >                class_cidr_bitlen_ipv6 |
1431                  class_ping_time |
1432 <                class_ping_warning |
1345 <                class_number_per_cidr |
1432 >                class_number_per_cidr |
1433                  class_number_per_ip |
1434                  class_connectfreq |
1435                  class_max_number |
1436 <                class_max_global |
1437 <                class_max_local |
1438 <                class_max_ident |
1439 <                class_sendq |
1440 <                error ';' ;
1436 >                class_max_global |
1437 >                class_max_local |
1438 >                class_max_ident |
1439 >                class_sendq | class_recvq |
1440 >                class_min_idle |
1441 >                class_max_idle |
1442 >                class_flags |
1443 >                error ';' ;
1444  
1445 < class_name: NAME '=' QSTRING ';'
1445 > class_name: NAME '=' QSTRING ';'
1446   {
1447    if (conf_parser_ctx.pass == 1)
1448 <  {
1359 <    MyFree(yy_class_name);
1360 <    DupString(yy_class_name, yylval.string);
1361 <  }
1448 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1449   };
1450  
1451   class_ping_time: PING_TIME '=' timespec ';'
1452   {
1453    if (conf_parser_ctx.pass == 1)
1454 <    yy_class->ping_freq = $3;
1368 < };
1369 <
1370 < class_ping_warning: PING_WARNING '=' timespec ';'
1371 < {
1372 <  if (conf_parser_ctx.pass == 1)
1373 <    yy_class->ping_warning = $3;
1454 >    block_state.ping_freq.value = $3;
1455   };
1456  
1457   class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1458   {
1459    if (conf_parser_ctx.pass == 1)
1460 <    yy_class->max_perip = $3;
1460 >    block_state.max_perip.value = $3;
1461   };
1462  
1463   class_connectfreq: CONNECTFREQ '=' timespec ';'
1464   {
1465    if (conf_parser_ctx.pass == 1)
1466 <    yy_class->con_freq = $3;
1466 >    block_state.con_freq.value = $3;
1467   };
1468  
1469   class_max_number: MAX_NUMBER '=' NUMBER ';'
1470   {
1471    if (conf_parser_ctx.pass == 1)
1472 <    yy_class->max_total = $3;
1472 >    block_state.max_total.value = $3;
1473   };
1474  
1475   class_max_global: MAX_GLOBAL '=' NUMBER ';'
1476   {
1477    if (conf_parser_ctx.pass == 1)
1478 <    yy_class->max_global = $3;
1478 >    block_state.max_global.value = $3;
1479   };
1480  
1481   class_max_local: MAX_LOCAL '=' NUMBER ';'
1482   {
1483    if (conf_parser_ctx.pass == 1)
1484 <    yy_class->max_local = $3;
1484 >    block_state.max_local.value = $3;
1485   };
1486  
1487   class_max_ident: MAX_IDENT '=' NUMBER ';'
1488   {
1489    if (conf_parser_ctx.pass == 1)
1490 <    yy_class->max_ident = $3;
1490 >    block_state.max_ident.value = $3;
1491   };
1492  
1493   class_sendq: SENDQ '=' sizespec ';'
1494   {
1495    if (conf_parser_ctx.pass == 1)
1496 <    yy_class->max_sendq = $3;
1496 >    block_state.max_sendq.value = $3;
1497 > };
1498 >
1499 > class_recvq: T_RECVQ '=' sizespec ';'
1500 > {
1501 >  if (conf_parser_ctx.pass == 1)
1502 >    if ($3 >= CLIENT_FLOOD_MIN && $3 <= CLIENT_FLOOD_MAX)
1503 >      block_state.max_recvq.value = $3;
1504   };
1505  
1506   class_cidr_bitlen_ipv4: CIDR_BITLEN_IPV4 '=' NUMBER ';'
1507   {
1508    if (conf_parser_ctx.pass == 1)
1509 <    yy_class->cidr_bitlen_ipv4 = $3;
1509 >    block_state.cidr_bitlen_ipv4.value = $3 > 32 ? 32 : $3;
1510   };
1511  
1512   class_cidr_bitlen_ipv6: CIDR_BITLEN_IPV6 '=' NUMBER ';'
1513   {
1514    if (conf_parser_ctx.pass == 1)
1515 <    yy_class->cidr_bitlen_ipv6 = $3;
1515 >    block_state.cidr_bitlen_ipv6.value = $3 > 128 ? 128 : $3;
1516   };
1517  
1518   class_number_per_cidr: NUMBER_PER_CIDR '=' NUMBER ';'
1519   {
1520    if (conf_parser_ctx.pass == 1)
1521 <    yy_class->number_per_cidr = $3;
1521 >    block_state.number_per_cidr.value = $3;
1522   };
1523  
1524 + class_min_idle: MIN_IDLE '=' timespec ';'
1525 + {
1526 +  if (conf_parser_ctx.pass != 1)
1527 +    break;
1528 +
1529 +  block_state.min_idle.value = $3;
1530 +  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1531 + };
1532 +
1533 + class_max_idle: MAX_IDLE '=' timespec ';'
1534 + {
1535 +  if (conf_parser_ctx.pass != 1)
1536 +    break;
1537 +
1538 +  block_state.max_idle.value = $3;
1539 +  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1540 + };
1541 +
1542 + class_flags: IRCD_FLAGS
1543 + {
1544 +  if (conf_parser_ctx.pass == 1)
1545 +    block_state.flags.value &= CLASS_FLAGS_FAKE_IDLE;
1546 + } '='  class_flags_items ';';
1547 +
1548 + class_flags_items: class_flags_items ',' class_flags_item | class_flags_item;
1549 + class_flags_item: RANDOM_IDLE
1550 + {
1551 +  if (conf_parser_ctx.pass == 1)
1552 +    block_state.flags.value |= CLASS_FLAGS_RANDOM_IDLE;
1553 + } | HIDE_IDLE_FROM_OPERS
1554 + {
1555 +  if (conf_parser_ctx.pass == 1)
1556 +    block_state.flags.value |= CLASS_FLAGS_HIDE_IDLE_FROM_OPERS;
1557 + };
1558 +
1559 +
1560   /***************************************************************************
1561   *  section listen
1562   ***************************************************************************/
1563   listen_entry: LISTEN
1564   {
1565    if (conf_parser_ctx.pass == 2)
1566 <  {
1567 <    listener_address = NULL;
1444 <    listener_flags = 0;
1445 <  }
1446 < } '{' listen_items '}' ';'
1447 < {
1448 <  if (conf_parser_ctx.pass == 2)
1449 <  {
1450 <    MyFree(listener_address);
1451 <    listener_address = NULL;
1452 <  }
1453 < };
1566 >    reset_block_state();
1567 > } '{' listen_items '}' ';';
1568  
1569   listen_flags: IRCD_FLAGS
1570   {
1571 <  listener_flags = 0;
1571 >  block_state.flags.value = 0;
1572   } '='  listen_flags_items ';';
1573  
1574   listen_flags_items: listen_flags_items ',' listen_flags_item | listen_flags_item;
1575   listen_flags_item: T_SSL
1576   {
1577    if (conf_parser_ctx.pass == 2)
1578 <    listener_flags |= LISTENER_SSL;
1578 >    block_state.flags.value |= LISTENER_SSL;
1579   } | HIDDEN
1580   {
1581    if (conf_parser_ctx.pass == 2)
1582 <    listener_flags |= LISTENER_HIDDEN;
1582 >    block_state.flags.value |= LISTENER_HIDDEN;
1583   } | T_SERVER
1584   {
1585    if (conf_parser_ctx.pass == 2)
1586 <    listener_flags |= LISTENER_SERVER;
1586 >   block_state.flags.value |= LISTENER_SERVER;
1587   };
1588  
1475 –
1476 –
1589   listen_items:   listen_items listen_item | listen_item;
1590   listen_item:    listen_port | listen_flags | listen_address | listen_host | error ';';
1591  
1592 < listen_port: PORT '=' port_items { listener_flags = 0; } ';';
1592 > listen_port: PORT '=' port_items { block_state.flags.value = 0; } ';';
1593  
1594   port_items: port_items ',' port_item | port_item;
1595  
# Line 1485 | Line 1597 | port_item: NUMBER
1597   {
1598    if (conf_parser_ctx.pass == 2)
1599    {
1600 <    if ((listener_flags & LISTENER_SSL))
1600 >    if (block_state.flags.value & LISTENER_SSL)
1601   #ifdef HAVE_LIBCRYPTO
1602        if (!ServerInfo.server_ctx)
1603   #endif
1604        {
1605 <        yyerror("SSL not available - port closed");
1606 <        break;
1605 >        conf_error_report("SSL not available - port closed");
1606 >        break;
1607        }
1608 <    add_listener($1, listener_address, listener_flags);
1608 >    add_listener($1, block_state.addr.buf, block_state.flags.value);
1609    }
1610   } | NUMBER TWODOTS NUMBER
1611   {
1612    if (conf_parser_ctx.pass == 2)
1613    {
1614 <    int i;
1503 <
1504 <    if ((listener_flags & LISTENER_SSL))
1614 >    if (block_state.flags.value & LISTENER_SSL)
1615   #ifdef HAVE_LIBCRYPTO
1616        if (!ServerInfo.server_ctx)
1617   #endif
1618        {
1619 <        yyerror("SSL not available - port closed");
1620 <        break;
1619 >        conf_error_report("SSL not available - port closed");
1620 >        break;
1621        }
1622  
1623 <    for (i = $1; i <= $3; ++i)
1624 <      add_listener(i, listener_address, listener_flags);
1623 >    for (int i = $1; i <= $3; ++i)
1624 >      add_listener(i, block_state.addr.buf, block_state.flags.value);
1625    }
1626   };
1627  
1628   listen_address: IP '=' QSTRING ';'
1629   {
1630    if (conf_parser_ctx.pass == 2)
1631 <  {
1522 <    MyFree(listener_address);
1523 <    DupString(listener_address, yylval.string);
1524 <  }
1631 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1632   };
1633  
1634   listen_host: HOST '=' QSTRING ';'
1635   {
1636    if (conf_parser_ctx.pass == 2)
1637 <  {
1531 <    MyFree(listener_address);
1532 <    DupString(listener_address, yylval.string);
1533 <  }
1637 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1638   };
1639  
1640   /***************************************************************************
# Line 1539 | Line 1643 | listen_host: HOST '=' QSTRING ';'
1643   auth_entry: IRCD_AUTH
1644   {
1645    if (conf_parser_ctx.pass == 2)
1646 <  {
1543 <    yy_conf = make_conf_item(CLIENT_TYPE);
1544 <    yy_aconf = map_to_conf(yy_conf);
1545 <  }
1546 <  else
1547 <  {
1548 <    MyFree(class_name);
1549 <    class_name = NULL;
1550 <  }
1646 >    reset_block_state();
1647   } '{' auth_items '}' ';'
1648   {
1649 <  if (conf_parser_ctx.pass == 2)
1554 <  {
1555 <    struct CollectItem *yy_tmp = NULL;
1556 <    dlink_node *ptr = NULL, *next_ptr = NULL;
1557 <
1558 <    if (yy_aconf->user && yy_aconf->host)
1559 <    {
1560 <      conf_add_class_to_conf(yy_conf, class_name);
1561 <      add_conf_by_address(CONF_CLIENT, yy_aconf);
1562 <    }
1563 <    else
1564 <      delete_conf_item(yy_conf);
1565 <
1566 <    /* copy over settings from first struct */
1567 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1568 <    {
1569 <      struct AccessItem *new_aconf;
1570 <      struct ConfItem *new_conf;
1571 <
1572 <      new_conf = make_conf_item(CLIENT_TYPE);
1573 <      new_aconf = map_to_conf(new_conf);
1574 <
1575 <      yy_tmp = ptr->data;
1649 >  dlink_node *ptr = NULL;
1650  
1651 <      assert(yy_tmp->user && yy_tmp->host);
1651 >  if (conf_parser_ctx.pass != 2)
1652 >    break;
1653  
1654 <      if (yy_aconf->passwd != NULL)
1580 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1581 <      if (yy_conf->name != NULL)
1582 <        DupString(new_conf->name, yy_conf->name);
1583 <      if (yy_aconf->passwd != NULL)
1584 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1585 <
1586 <      new_aconf->flags = yy_aconf->flags;
1587 <      new_aconf->port  = yy_aconf->port;
1588 <
1589 <      DupString(new_aconf->user, yy_tmp->user);
1590 <      collapse(new_aconf->user);
1591 <
1592 <      DupString(new_aconf->host, yy_tmp->host);
1593 <      collapse(new_aconf->host);
1594 <
1595 <      conf_add_class_to_conf(new_conf, class_name);
1596 <      add_conf_by_address(CONF_CLIENT, new_aconf);
1597 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1598 <      free_collect_item(yy_tmp);
1599 <    }
1600 <
1601 <    MyFree(class_name);
1602 <    class_name = NULL;
1603 <    yy_conf = NULL;
1604 <    yy_aconf = NULL;
1605 <  }
1606 < };
1607 <
1608 < auth_items:     auth_items auth_item | auth_item;
1609 < auth_item:      auth_user | auth_passwd | auth_class | auth_flags |
1610 <                auth_spoof | auth_redir_serv | auth_redir_port |
1611 <                auth_encrypted | error ';' ;
1612 <
1613 < auth_user: USER '=' QSTRING ';'
1614 < {
1615 <  if (conf_parser_ctx.pass == 2)
1654 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1655    {
1656 <    struct CollectItem *yy_tmp = NULL;
1656 >    struct MaskItem *conf = NULL;
1657      struct split_nuh_item nuh;
1658  
1659 <    nuh.nuhmask  = yylval.string;
1659 >    nuh.nuhmask  = ptr->data;
1660      nuh.nickptr  = NULL;
1661 <    nuh.userptr  = userbuf;
1662 <    nuh.hostptr  = hostbuf;
1624 <
1661 >    nuh.userptr  = block_state.user.buf;
1662 >    nuh.hostptr  = block_state.host.buf;
1663      nuh.nicksize = 0;
1664 <    nuh.usersize = sizeof(userbuf);
1665 <    nuh.hostsize = sizeof(hostbuf);
1628 <
1664 >    nuh.usersize = sizeof(block_state.user.buf);
1665 >    nuh.hostsize = sizeof(block_state.host.buf);
1666      split_nuh(&nuh);
1667  
1668 <    if (yy_aconf->user == NULL)
1669 <    {
1670 <      DupString(yy_aconf->user, userbuf);
1671 <      DupString(yy_aconf->host, hostbuf);
1672 <    }
1673 <    else
1674 <    {
1675 <      yy_tmp = MyMalloc(sizeof(struct CollectItem));
1668 >    conf        = conf_make(CONF_CLIENT);
1669 >    conf->user  = xstrdup(block_state.user.buf);
1670 >    conf->host  = xstrdup(block_state.host.buf);
1671 >
1672 >    if (block_state.rpass.buf[0])
1673 >      conf->passwd = xstrdup(block_state.rpass.buf);
1674 >    if (block_state.name.buf[0])
1675 >      conf->name = xstrdup(block_state.name.buf);
1676  
1677 <      DupString(yy_tmp->user, userbuf);
1678 <      DupString(yy_tmp->host, hostbuf);
1677 >    conf->flags = block_state.flags.value;
1678 >    conf->port  = block_state.port.value;
1679  
1680 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1681 <    }
1680 >    conf_add_class_to_conf(conf, block_state.class.buf);
1681 >    add_conf_by_address(CONF_CLIENT, conf);
1682    }
1683   };
1684  
1685 < /* XXX - IP/IPV6 tags don't exist anymore - put IP/IPV6 into user. */
1685 > auth_items:     auth_items auth_item | auth_item;
1686 > auth_item:      auth_user |
1687 >                auth_passwd |
1688 >                auth_class |
1689 >                auth_flags |
1690 >                auth_spoof |
1691 >                auth_redir_serv |
1692 >                auth_redir_port |
1693 >                auth_encrypted |
1694 >                error ';' ;
1695  
1696 < auth_passwd: PASSWORD '=' QSTRING ';'
1696 > auth_user: USER '=' QSTRING ';'
1697   {
1698    if (conf_parser_ctx.pass == 2)
1699 <  {
1700 <    /* be paranoid */
1655 <    if (yy_aconf->passwd != NULL)
1656 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1699 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1700 > };
1701  
1702 <    MyFree(yy_aconf->passwd);
1703 <    DupString(yy_aconf->passwd, yylval.string);
1704 <  }
1702 > auth_passwd: PASSWORD '=' QSTRING ';'
1703 > {
1704 >  if (conf_parser_ctx.pass == 2)
1705 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1706   };
1707  
1708   auth_class: CLASS '=' QSTRING ';'
1709   {
1710    if (conf_parser_ctx.pass == 2)
1711 <  {
1667 <    MyFree(class_name);
1668 <    DupString(class_name, yylval.string);
1669 <  }
1711 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1712   };
1713  
1714   auth_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 1674 | Line 1716 | auth_encrypted: ENCRYPTED '=' TBOOL ';'
1716    if (conf_parser_ctx.pass == 2)
1717    {
1718      if (yylval.number)
1719 <      SetConfEncrypted(yy_aconf);
1719 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1720      else
1721 <      ClearConfEncrypted(yy_aconf);
1721 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1722    }
1723   };
1724  
1725   auth_flags: IRCD_FLAGS
1726   {
1727 +  if (conf_parser_ctx.pass == 2)
1728 +    block_state.flags.value &= (CONF_FLAGS_ENCRYPTED | CONF_FLAGS_SPOOF_IP);
1729   } '='  auth_flags_items ';';
1730  
1731   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
1732   auth_flags_item: SPOOF_NOTICE
1733   {
1734    if (conf_parser_ctx.pass == 2)
1735 <    yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1735 >    block_state.flags.value |= CONF_FLAGS_SPOOF_NOTICE;
1736   } | EXCEED_LIMIT
1737   {
1738    if (conf_parser_ctx.pass == 2)
1739 <    yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
1739 >    block_state.flags.value |= CONF_FLAGS_NOLIMIT;
1740   } | KLINE_EXEMPT
1741   {
1742    if (conf_parser_ctx.pass == 2)
1743 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
1743 >    block_state.flags.value |= CONF_FLAGS_EXEMPTKLINE;
1744   } | NEED_IDENT
1745   {
1746    if (conf_parser_ctx.pass == 2)
1747 <    yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
1747 >    block_state.flags.value |= CONF_FLAGS_NEED_IDENTD;
1748   } | CAN_FLOOD
1749   {
1750    if (conf_parser_ctx.pass == 2)
1751 <    yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
1751 >    block_state.flags.value |= CONF_FLAGS_CAN_FLOOD;
1752   } | NO_TILDE
1753   {
1754    if (conf_parser_ctx.pass == 2)
1755 <    yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
1755 >    block_state.flags.value |= CONF_FLAGS_NO_TILDE;
1756   } | GLINE_EXEMPT
1757   {
1758    if (conf_parser_ctx.pass == 2)
1759 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
1759 >    block_state.flags.value |= CONF_FLAGS_EXEMPTGLINE;
1760   } | RESV_EXEMPT
1761   {
1762    if (conf_parser_ctx.pass == 2)
1763 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTRESV;
1763 >    block_state.flags.value |= CONF_FLAGS_EXEMPTRESV;
1764 > } | T_WEBIRC
1765 > {
1766 >  if (conf_parser_ctx.pass == 2)
1767 >    block_state.flags.value |= CONF_FLAGS_WEBIRC;
1768   } | NEED_PASSWORD
1769   {
1770    if (conf_parser_ctx.pass == 2)
1771 <    yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
1771 >    block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1772   };
1773  
1774 < /* XXX - need check for illegal hostnames here */
1727 < auth_spoof: SPOOF '=' QSTRING ';'
1774 > auth_spoof: SPOOF '=' QSTRING ';'
1775   {
1776 <  if (conf_parser_ctx.pass == 2)
1777 <  {
1731 <    MyFree(yy_conf->name);
1776 >  if (conf_parser_ctx.pass != 2)
1777 >    break;
1778  
1779 <    if (strlen(yylval.string) < HOSTLEN)
1780 <    {    
1781 <      DupString(yy_conf->name, yylval.string);
1782 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_IP;
1737 <    }
1738 <    else
1739 <    {
1740 <      ilog(LOG_TYPE_IRCD, "Spoofs must be less than %d..ignoring it", HOSTLEN);
1741 <      yy_conf->name = NULL;
1742 <    }
1779 >  if (valid_hostname(yylval.string))
1780 >  {
1781 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1782 >    block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
1783    }
1784 +  else
1785 +    ilog(LOG_TYPE_IRCD, "Spoof either is too long or contains invalid characters. Ignoring it.");
1786   };
1787  
1788   auth_redir_serv: REDIRSERV '=' QSTRING ';'
1789   {
1790 <  if (conf_parser_ctx.pass == 2)
1791 <  {
1792 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1793 <    MyFree(yy_conf->name);
1794 <    DupString(yy_conf->name, yylval.string);
1753 <  }
1790 >  if (conf_parser_ctx.pass != 2)
1791 >    break;
1792 >
1793 >  strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1794 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1795   };
1796  
1797   auth_redir_port: REDIRPORT '=' NUMBER ';'
1798   {
1799 <  if (conf_parser_ctx.pass == 2)
1800 <  {
1801 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1802 <    yy_aconf->port = $3;
1803 <  }
1799 >  if (conf_parser_ctx.pass != 2)
1800 >    break;
1801 >
1802 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1803 >  block_state.port.value = $3;
1804   };
1805  
1806  
# Line 1768 | Line 1809 | auth_redir_port: REDIRPORT '=' NUMBER ';
1809   ***************************************************************************/
1810   resv_entry: RESV
1811   {
1812 <  if (conf_parser_ctx.pass == 2)
1813 <  {
1814 <    MyFree(resv_reason);
1815 <    resv_reason = NULL;
1816 <  }
1812 >  if (conf_parser_ctx.pass != 2)
1813 >    break;
1814 >
1815 >  reset_block_state();
1816 >  strlcpy(block_state.rpass.buf, CONF_NOREASON, sizeof(block_state.rpass.buf));
1817   } '{' resv_items '}' ';'
1818   {
1819 <  if (conf_parser_ctx.pass == 2)
1820 <  {
1821 <    MyFree(resv_reason);
1822 <    resv_reason = NULL;
1782 <  }
1819 >  if (conf_parser_ctx.pass != 2)
1820 >    break;
1821 >
1822 >  create_resv(block_state.name.buf, block_state.rpass.buf, &block_state.mask.list);
1823   };
1824  
1825 < resv_items:     resv_items resv_item | resv_item;
1826 < resv_item:      resv_creason | resv_channel | resv_nick | error ';' ;
1825 > resv_items:     resv_items resv_item | resv_item;
1826 > resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1827  
1828 < resv_creason: REASON '=' QSTRING ';'
1828 > resv_mask: MASK '=' QSTRING ';'
1829   {
1830    if (conf_parser_ctx.pass == 2)
1831 <  {
1792 <    MyFree(resv_reason);
1793 <    DupString(resv_reason, yylval.string);
1794 <  }
1831 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1832   };
1833  
1834 < resv_channel: CHANNEL '=' QSTRING ';'
1834 > resv_reason: REASON '=' QSTRING ';'
1835   {
1836    if (conf_parser_ctx.pass == 2)
1837 <  {
1801 <    if (IsChanPrefix(*yylval.string))
1802 <    {
1803 <      char def_reason[] = "No reason";
1804 <
1805 <      create_channel_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1806 <    }
1807 <  }
1808 <  /* ignore it for now.. but we really should make a warning if
1809 <   * its an erroneous name --fl_ */
1837 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1838   };
1839  
1840 < resv_nick: NICK '=' QSTRING ';'
1840 > resv_exempt: EXEMPT '=' QSTRING ';'
1841   {
1842    if (conf_parser_ctx.pass == 2)
1843 <  {
1816 <    char def_reason[] = "No reason";
1817 <
1818 <    create_nick_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1819 <  }
1843 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1844   };
1845  
1846 +
1847   /***************************************************************************
1848   *  section service
1849   ***************************************************************************/
# Line 1829 | Line 1854 | service_item:      service_name | error;
1854  
1855   service_name: NAME '=' QSTRING ';'
1856   {
1857 <  if (conf_parser_ctx.pass == 2)
1857 >  if (conf_parser_ctx.pass != 2)
1858 >    break;
1859 >
1860 >  if (valid_servname(yylval.string))
1861    {
1862 <    if (valid_servname(yylval.string))
1863 <    {
1836 <      yy_conf = make_conf_item(SERVICE_TYPE);
1837 <      DupString(yy_conf->name, yylval.string);
1838 <    }
1862 >    struct MaskItem *conf = conf_make(CONF_SERVICE);
1863 >    conf->name = xstrdup(yylval.string);
1864    }
1865   };
1866  
# Line 1844 | Line 1869 | service_name: NAME '=' QSTRING ';'
1869   ***************************************************************************/
1870   shared_entry: T_SHARED
1871   {
1872 <  if (conf_parser_ctx.pass == 2)
1873 <  {
1874 <    yy_conf = make_conf_item(ULINE_TYPE);
1875 <    yy_match_item = map_to_conf(yy_conf);
1876 <    yy_match_item->action = SHARED_ALL;
1877 <  }
1872 >  if (conf_parser_ctx.pass != 2)
1873 >    break;
1874 >
1875 >  reset_block_state();
1876 >
1877 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1878 >  strlcpy(block_state.user.buf, "*", sizeof(block_state.user.buf));
1879 >  strlcpy(block_state.host.buf, "*", sizeof(block_state.host.buf));
1880 >  block_state.flags.value = SHARED_ALL;
1881   } '{' shared_items '}' ';'
1882   {
1883 <  if (conf_parser_ctx.pass == 2)
1884 <  {
1885 <    yy_conf = NULL;
1886 <  }
1883 >  struct MaskItem *conf = NULL;
1884 >
1885 >  if (conf_parser_ctx.pass != 2)
1886 >    break;
1887 >
1888 >  conf = conf_make(CONF_ULINE);
1889 >  conf->flags = block_state.flags.value;
1890 >  conf->name = xstrdup(block_state.name.buf);
1891 >  conf->user = xstrdup(block_state.user.buf);
1892 >  conf->host = xstrdup(block_state.host.buf);
1893   };
1894  
1895   shared_items: shared_items shared_item | shared_item;
# Line 1864 | Line 1898 | shared_item:  shared_name | shared_user
1898   shared_name: NAME '=' QSTRING ';'
1899   {
1900    if (conf_parser_ctx.pass == 2)
1901 <  {
1868 <    MyFree(yy_conf->name);
1869 <    DupString(yy_conf->name, yylval.string);
1870 <  }
1901 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1902   };
1903  
1904   shared_user: USER '=' QSTRING ';'
# Line 1878 | Line 1909 | shared_user: USER '=' QSTRING ';'
1909  
1910      nuh.nuhmask  = yylval.string;
1911      nuh.nickptr  = NULL;
1912 <    nuh.userptr  = userbuf;
1913 <    nuh.hostptr  = hostbuf;
1912 >    nuh.userptr  = block_state.user.buf;
1913 >    nuh.hostptr  = block_state.host.buf;
1914  
1915      nuh.nicksize = 0;
1916 <    nuh.usersize = sizeof(userbuf);
1917 <    nuh.hostsize = sizeof(hostbuf);
1916 >    nuh.usersize = sizeof(block_state.user.buf);
1917 >    nuh.hostsize = sizeof(block_state.host.buf);
1918  
1919      split_nuh(&nuh);
1889 –
1890 –    DupString(yy_match_item->user, userbuf);
1891 –    DupString(yy_match_item->host, hostbuf);
1920    }
1921   };
1922  
1923   shared_type: TYPE
1924   {
1925    if (conf_parser_ctx.pass == 2)
1926 <    yy_match_item->action = 0;
1926 >    block_state.flags.value = 0;
1927   } '=' shared_types ';' ;
1928  
1929   shared_types: shared_types ',' shared_type_item | shared_type_item;
1930   shared_type_item: KLINE
1931   {
1932    if (conf_parser_ctx.pass == 2)
1933 <    yy_match_item->action |= SHARED_KLINE;
1933 >    block_state.flags.value |= SHARED_KLINE;
1934   } | UNKLINE
1935   {
1936    if (conf_parser_ctx.pass == 2)
1937 <    yy_match_item->action |= SHARED_UNKLINE;
1937 >    block_state.flags.value |= SHARED_UNKLINE;
1938   } | T_DLINE
1939   {
1940    if (conf_parser_ctx.pass == 2)
1941 <    yy_match_item->action |= SHARED_DLINE;
1941 >    block_state.flags.value |= SHARED_DLINE;
1942   } | T_UNDLINE
1943   {
1944    if (conf_parser_ctx.pass == 2)
1945 <    yy_match_item->action |= SHARED_UNDLINE;
1945 >    block_state.flags.value |= SHARED_UNDLINE;
1946   } | XLINE
1947   {
1948    if (conf_parser_ctx.pass == 2)
1949 <    yy_match_item->action |= SHARED_XLINE;
1949 >    block_state.flags.value |= SHARED_XLINE;
1950   } | T_UNXLINE
1951   {
1952    if (conf_parser_ctx.pass == 2)
1953 <    yy_match_item->action |= SHARED_UNXLINE;
1953 >    block_state.flags.value |= SHARED_UNXLINE;
1954   } | RESV
1955   {
1956    if (conf_parser_ctx.pass == 2)
1957 <    yy_match_item->action |= SHARED_RESV;
1957 >    block_state.flags.value |= SHARED_RESV;
1958   } | T_UNRESV
1959   {
1960    if (conf_parser_ctx.pass == 2)
1961 <    yy_match_item->action |= SHARED_UNRESV;
1961 >    block_state.flags.value |= SHARED_UNRESV;
1962   } | T_LOCOPS
1963   {
1964    if (conf_parser_ctx.pass == 2)
1965 <    yy_match_item->action |= SHARED_LOCOPS;
1965 >    block_state.flags.value |= SHARED_LOCOPS;
1966   } | T_ALL
1967   {
1968    if (conf_parser_ctx.pass == 2)
1969 <    yy_match_item->action = SHARED_ALL;
1969 >    block_state.flags.value = SHARED_ALL;
1970   };
1971  
1972   /***************************************************************************
# Line 1946 | Line 1974 | shared_type_item: KLINE
1974   ***************************************************************************/
1975   cluster_entry: T_CLUSTER
1976   {
1977 <  if (conf_parser_ctx.pass == 2)
1978 <  {
1979 <    yy_conf = make_conf_item(CLUSTER_TYPE);
1980 <    yy_conf->flags = SHARED_ALL;
1981 <  }
1977 >  if (conf_parser_ctx.pass != 2)
1978 >    break;
1979 >
1980 >  reset_block_state();
1981 >
1982 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1983 >  block_state.flags.value = SHARED_ALL;
1984   } '{' cluster_items '}' ';'
1985   {
1986 <  if (conf_parser_ctx.pass == 2)
1987 <  {
1988 <    if (yy_conf->name == NULL)
1989 <      DupString(yy_conf->name, "*");
1990 <    yy_conf = NULL;
1991 <  }
1986 >  struct MaskItem *conf = NULL;
1987 >
1988 >  if (conf_parser_ctx.pass != 2)
1989 >    break;
1990 >
1991 >  conf = conf_make(CONF_CLUSTER);
1992 >  conf->flags = block_state.flags.value;
1993 >  conf->name = xstrdup(block_state.name.buf);
1994   };
1995  
1996 < cluster_items:  cluster_items cluster_item | cluster_item;
1997 < cluster_item:   cluster_name | cluster_type | error ';' ;
1996 > cluster_items:  cluster_items cluster_item | cluster_item;
1997 > cluster_item:   cluster_name | cluster_type | error ';' ;
1998  
1999   cluster_name: NAME '=' QSTRING ';'
2000   {
2001    if (conf_parser_ctx.pass == 2)
2002 <    DupString(yy_conf->name, yylval.string);
2002 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2003   };
2004  
2005   cluster_type: TYPE
2006   {
2007    if (conf_parser_ctx.pass == 2)
2008 <    yy_conf->flags = 0;
2008 >    block_state.flags.value = 0;
2009   } '=' cluster_types ';' ;
2010  
2011 < cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2011 > cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2012   cluster_type_item: KLINE
2013   {
2014    if (conf_parser_ctx.pass == 2)
2015 <    yy_conf->flags |= SHARED_KLINE;
2015 >    block_state.flags.value |= SHARED_KLINE;
2016   } | UNKLINE
2017   {
2018    if (conf_parser_ctx.pass == 2)
2019 <    yy_conf->flags |= SHARED_UNKLINE;
2019 >    block_state.flags.value |= SHARED_UNKLINE;
2020   } | T_DLINE
2021   {
2022    if (conf_parser_ctx.pass == 2)
2023 <    yy_conf->flags |= SHARED_DLINE;
2023 >    block_state.flags.value |= SHARED_DLINE;
2024   } | T_UNDLINE
2025   {
2026    if (conf_parser_ctx.pass == 2)
2027 <    yy_conf->flags |= SHARED_UNDLINE;
2027 >    block_state.flags.value |= SHARED_UNDLINE;
2028   } | XLINE
2029   {
2030    if (conf_parser_ctx.pass == 2)
2031 <    yy_conf->flags |= SHARED_XLINE;
2031 >    block_state.flags.value |= SHARED_XLINE;
2032   } | T_UNXLINE
2033   {
2034    if (conf_parser_ctx.pass == 2)
2035 <    yy_conf->flags |= SHARED_UNXLINE;
2035 >    block_state.flags.value |= SHARED_UNXLINE;
2036   } | RESV
2037   {
2038    if (conf_parser_ctx.pass == 2)
2039 <    yy_conf->flags |= SHARED_RESV;
2039 >    block_state.flags.value |= SHARED_RESV;
2040   } | T_UNRESV
2041   {
2042    if (conf_parser_ctx.pass == 2)
2043 <    yy_conf->flags |= SHARED_UNRESV;
2043 >    block_state.flags.value |= SHARED_UNRESV;
2044   } | T_LOCOPS
2045   {
2046    if (conf_parser_ctx.pass == 2)
2047 <    yy_conf->flags |= SHARED_LOCOPS;
2047 >    block_state.flags.value |= SHARED_LOCOPS;
2048   } | T_ALL
2049   {
2050    if (conf_parser_ctx.pass == 2)
2051 <    yy_conf->flags = SHARED_ALL;
2051 >    block_state.flags.value = SHARED_ALL;
2052   };
2053  
2054   /***************************************************************************
2055   *  section connect
2056   ***************************************************************************/
2057 < connect_entry: CONNECT  
2057 > connect_entry: CONNECT
2058   {
2027 –  if (conf_parser_ctx.pass == 2)
2028 –  {
2029 –    yy_conf = make_conf_item(SERVER_TYPE);
2030 –    yy_aconf = map_to_conf(yy_conf);
2059  
2060 <    /* defaults */
2061 <    yy_aconf->port = PORTNUM;
2062 <  }
2063 <  else
2064 <  {
2065 <    MyFree(class_name);
2038 <    class_name = NULL;
2039 <  }
2060 >  if (conf_parser_ctx.pass != 2)
2061 >    break;
2062 >
2063 >  reset_block_state();
2064 >  block_state.aftype.value = AF_INET;
2065 >  block_state.port.value = PORTNUM;
2066   } '{' connect_items '}' ';'
2067   {
2068 <  if (conf_parser_ctx.pass == 2)
2068 >  struct MaskItem *conf = NULL;
2069 >  struct addrinfo hints, *res;
2070 >
2071 >  if (conf_parser_ctx.pass != 2)
2072 >    break;
2073 >
2074 >  if (!block_state.name.buf[0] ||
2075 >      !block_state.host.buf[0])
2076 >    break;
2077 >
2078 >  if (!block_state.rpass.buf[0] ||
2079 >      !block_state.spass.buf[0])
2080 >    break;
2081 >
2082 >  if (has_wildcards(block_state.name.buf) ||
2083 >      has_wildcards(block_state.host.buf))
2084 >    break;
2085 >
2086 >  conf = conf_make(CONF_SERVER);
2087 >  conf->port = block_state.port.value;
2088 >  conf->flags = block_state.flags.value;
2089 >  conf->aftype = block_state.aftype.value;
2090 >  conf->host = xstrdup(block_state.host.buf);
2091 >  conf->name = xstrdup(block_state.name.buf);
2092 >  conf->passwd = xstrdup(block_state.rpass.buf);
2093 >  conf->spasswd = xstrdup(block_state.spass.buf);
2094 >
2095 >  if (block_state.cert.buf[0])
2096 >    conf->certfp = xstrdup(block_state.cert.buf);
2097 >
2098 >  if (block_state.ciph.buf[0])
2099 >    conf->cipher_list = xstrdup(block_state.ciph.buf);
2100 >
2101 >  dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
2102 >  dlinkMoveList(&block_state.hub.list, &conf->hub_list);
2103 >
2104 >  if (block_state.bind.buf[0])
2105    {
2106 <    if (yy_aconf->host && yy_aconf->passwd && yy_aconf->spasswd)
2107 <    {
2108 <      if (conf_add_server(yy_conf, class_name) == -1)
2109 <        delete_conf_item(yy_conf);
2110 <    }
2106 >    memset(&hints, 0, sizeof(hints));
2107 >
2108 >    hints.ai_family   = AF_UNSPEC;
2109 >    hints.ai_socktype = SOCK_STREAM;
2110 >    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2111 >
2112 >    if (getaddrinfo(block_state.bind.buf, NULL, &hints, &res))
2113 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
2114      else
2115      {
2116 <      if (yy_conf->name != NULL)
2052 <      {
2053 <        if (yy_aconf->host == NULL)
2054 <          yyerror("Ignoring connect block -- missing host");
2055 <        else if (!yy_aconf->passwd || !yy_aconf->spasswd)
2056 <          yyerror("Ignoring connect block -- missing password");
2057 <      }
2116 >      assert(res);
2117  
2118 <      /* XXX
2119 <       * This fixes a try_connections() core (caused by invalid class_ptr
2120 <       * pointers) reported by metalrock. That's an ugly fix, but there
2121 <       * is currently no better way. The entire config subsystem needs an
2063 <       * rewrite ASAP. make_conf_item() shouldn't really add things onto
2064 <       * a doubly linked list immediately without any sanity checks!  -Michael
2065 <       */
2066 <      delete_conf_item(yy_conf);
2118 >      memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
2119 >      conf->bind.ss.ss_family = res->ai_family;
2120 >      conf->bind.ss_len = res->ai_addrlen;
2121 >      freeaddrinfo(res);
2122      }
2068 –
2069 –    MyFree(class_name);
2070 –    class_name = NULL;
2071 –    yy_conf = NULL;
2072 –    yy_aconf = NULL;
2123    }
2124 +
2125 +  conf_add_class_to_conf(conf, block_state.class.buf);
2126 +  lookup_confhost(conf);
2127   };
2128  
2129   connect_items:  connect_items connect_item | connect_item;
2130 < connect_item:   connect_name | connect_host | connect_vhost |
2131 <                connect_send_password | connect_accept_password |
2132 <                connect_aftype | connect_port | connect_ssl_cipher_list |
2133 <                connect_flags | connect_hub_mask | connect_leaf_mask |
2134 <                connect_class | connect_encrypted |
2130 > connect_item:   connect_name |
2131 >                connect_host |
2132 >                connect_vhost |
2133 >                connect_send_password |
2134 >                connect_accept_password |
2135 >                connect_ssl_certificate_fingerprint |
2136 >                connect_aftype |
2137 >                connect_port |
2138 >                connect_ssl_cipher_list |
2139 >                connect_flags |
2140 >                connect_hub_mask |
2141 >                connect_leaf_mask |
2142 >                connect_class |
2143 >                connect_encrypted |
2144                  error ';' ;
2145  
2146   connect_name: NAME '=' QSTRING ';'
2147   {
2148    if (conf_parser_ctx.pass == 2)
2149 <  {
2088 <    MyFree(yy_conf->name);
2089 <    DupString(yy_conf->name, yylval.string);
2090 <  }
2149 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2150   };
2151  
2152 < connect_host: HOST '=' QSTRING ';'
2152 > connect_host: HOST '=' QSTRING ';'
2153   {
2154    if (conf_parser_ctx.pass == 2)
2155 <  {
2097 <    MyFree(yy_aconf->host);
2098 <    DupString(yy_aconf->host, yylval.string);
2099 <  }
2155 >    strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
2156   };
2157  
2158 < connect_vhost: VHOST '=' QSTRING ';'
2158 > connect_vhost: VHOST '=' QSTRING ';'
2159   {
2160    if (conf_parser_ctx.pass == 2)
2161 <  {
2106 <    struct addrinfo hints, *res;
2107 <
2108 <    memset(&hints, 0, sizeof(hints));
2109 <
2110 <    hints.ai_family   = AF_UNSPEC;
2111 <    hints.ai_socktype = SOCK_STREAM;
2112 <    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2113 <
2114 <    if (getaddrinfo(yylval.string, NULL, &hints, &res))
2115 <      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
2116 <    else
2117 <    {
2118 <      assert(res != NULL);
2119 <
2120 <      memcpy(&yy_aconf->bind, res->ai_addr, res->ai_addrlen);
2121 <      yy_aconf->bind.ss.ss_family = res->ai_family;
2122 <      yy_aconf->bind.ss_len = res->ai_addrlen;
2123 <      freeaddrinfo(res);
2124 <    }
2125 <  }
2161 >    strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
2162   };
2163 <
2163 >
2164   connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2165   {
2166 <  if (conf_parser_ctx.pass == 2)
2167 <  {
2132 <    if ($3[0] == ':')
2133 <      yyerror("Server passwords cannot begin with a colon");
2134 <    else if (strchr($3, ' ') != NULL)
2135 <      yyerror("Server passwords cannot contain spaces");
2136 <    else {
2137 <      if (yy_aconf->spasswd != NULL)
2138 <        memset(yy_aconf->spasswd, 0, strlen(yy_aconf->spasswd));
2166 >  if (conf_parser_ctx.pass != 2)
2167 >    break;
2168  
2169 <      MyFree(yy_aconf->spasswd);
2170 <      DupString(yy_aconf->spasswd, yylval.string);
2171 <    }
2172 <  }
2169 >  if ($3[0] == ':')
2170 >    conf_error_report("Server passwords cannot begin with a colon");
2171 >  else if (strchr($3, ' '))
2172 >    conf_error_report("Server passwords cannot contain spaces");
2173 >  else
2174 >    strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
2175   };
2176  
2177   connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2178   {
2179 <  if (conf_parser_ctx.pass == 2)
2180 <  {
2150 <    if ($3[0] == ':')
2151 <      yyerror("Server passwords cannot begin with a colon");
2152 <    else if (strchr($3, ' ') != NULL)
2153 <      yyerror("Server passwords cannot contain spaces");
2154 <    else {
2155 <      if (yy_aconf->passwd != NULL)
2156 <        memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
2179 >  if (conf_parser_ctx.pass != 2)
2180 >    break;
2181  
2182 <      MyFree(yy_aconf->passwd);
2183 <      DupString(yy_aconf->passwd, yylval.string);
2184 <    }
2185 <  }
2182 >  if ($3[0] == ':')
2183 >    conf_error_report("Server passwords cannot begin with a colon");
2184 >  else if (strchr($3, ' '))
2185 >    conf_error_report("Server passwords cannot contain spaces");
2186 >  else
2187 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2188 > };
2189 >
2190 > connect_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
2191 > {
2192 >  if (conf_parser_ctx.pass == 2)
2193 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
2194   };
2195  
2196   connect_port: PORT '=' NUMBER ';'
2197   {
2198    if (conf_parser_ctx.pass == 2)
2199 <    yy_aconf->port = $3;
2199 >    block_state.port.value = $3;
2200   };
2201  
2202   connect_aftype: AFTYPE '=' T_IPV4 ';'
2203   {
2204    if (conf_parser_ctx.pass == 2)
2205 <    yy_aconf->aftype = AF_INET;
2205 >    block_state.aftype.value = AF_INET;
2206   } | AFTYPE '=' T_IPV6 ';'
2207   {
2208   #ifdef IPV6
2209    if (conf_parser_ctx.pass == 2)
2210 <    yy_aconf->aftype = AF_INET6;
2210 >    block_state.aftype.value = AF_INET6;
2211   #endif
2212   };
2213  
2214   connect_flags: IRCD_FLAGS
2215   {
2216 +  block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
2217   } '='  connect_flags_items ';';
2218  
2219   connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
2220   connect_flags_item: AUTOCONN
2221   {
2222    if (conf_parser_ctx.pass == 2)
2223 <    SetConfAllowAutoConn(yy_aconf);
2191 < } | BURST_AWAY
2192 < {
2193 <  if (conf_parser_ctx.pass == 2)
2194 <    SetConfAwayBurst(yy_aconf);
2195 < } | TOPICBURST
2196 < {
2197 <  if (conf_parser_ctx.pass == 2)
2198 <    SetConfTopicBurst(yy_aconf);
2223 >    block_state.flags.value |= CONF_FLAGS_ALLOW_AUTO_CONN;
2224   } | T_SSL
2225   {
2226    if (conf_parser_ctx.pass == 2)
2227 <    SetConfSSL(yy_aconf);
2227 >    block_state.flags.value |= CONF_FLAGS_SSL;
2228   };
2229  
2230   connect_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 2207 | Line 2232 | connect_encrypted: ENCRYPTED '=' TBOOL '
2232    if (conf_parser_ctx.pass == 2)
2233    {
2234      if (yylval.number)
2235 <      yy_aconf->flags |= CONF_FLAGS_ENCRYPTED;
2235 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
2236      else
2237 <      yy_aconf->flags &= ~CONF_FLAGS_ENCRYPTED;
2237 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
2238    }
2239   };
2240  
2241 < connect_hub_mask: HUB_MASK '=' QSTRING ';'
2241 > connect_hub_mask: HUB_MASK '=' QSTRING ';'
2242   {
2243    if (conf_parser_ctx.pass == 2)
2244 <  {
2220 <    char *mask;
2221 <
2222 <    DupString(mask, yylval.string);
2223 <    dlinkAdd(mask, make_dlink_node(), &yy_aconf->hub_list);
2224 <  }
2244 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
2245   };
2246  
2247 < connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2247 > connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2248   {
2249    if (conf_parser_ctx.pass == 2)
2250 <  {
2231 <    char *mask;
2232 <
2233 <    DupString(mask, yylval.string);
2234 <    dlinkAdd(mask, make_dlink_node(), &yy_aconf->leaf_list);
2235 <  }
2250 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
2251   };
2252  
2253   connect_class: CLASS '=' QSTRING ';'
2254   {
2255    if (conf_parser_ctx.pass == 2)
2256 <  {
2242 <    MyFree(class_name);
2243 <    DupString(class_name, yylval.string);
2244 <  }
2256 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
2257   };
2258  
2259   connect_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
2260   {
2261   #ifdef HAVE_LIBCRYPTO
2262    if (conf_parser_ctx.pass == 2)
2263 <  {
2252 <    MyFree(yy_aconf->cipher_list);
2253 <    DupString(yy_aconf->cipher_list, yylval.string);
2254 <  }
2263 >    strlcpy(block_state.ciph.buf, yylval.string, sizeof(block_state.ciph.buf));
2264   #else
2265    if (conf_parser_ctx.pass == 2)
2266 <    yyerror("Ignoring connect::ciphers -- no OpenSSL support");
2266 >    conf_error_report("Ignoring connect::ciphers -- no OpenSSL support");
2267   #endif
2268   };
2269  
# Line 2265 | Line 2274 | connect_ssl_cipher_list: T_SSL_CIPHER_LI
2274   kill_entry: KILL
2275   {
2276    if (conf_parser_ctx.pass == 2)
2277 <  {
2269 <    userbuf[0] = hostbuf[0] = reasonbuf[0] = '\0';
2270 <    regex_ban = 0;
2271 <  }
2277 >    reset_block_state();
2278   } '{' kill_items '}' ';'
2279   {
2280 <  if (conf_parser_ctx.pass == 2)
2275 <  {
2276 <    if (userbuf[0] && hostbuf[0])
2277 <    {
2278 <      if (regex_ban)
2279 <      {
2280 < #ifdef HAVE_LIBPCRE
2281 <        void *exp_user = NULL;
2282 <        void *exp_host = NULL;
2283 <        const char *errptr = NULL;
2284 <
2285 <        if (!(exp_user = ircd_pcre_compile(userbuf, &errptr)) ||
2286 <            !(exp_host = ircd_pcre_compile(hostbuf, &errptr)))
2287 <        {
2288 <          ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: %s",
2289 <               errptr);
2290 <          break;
2291 <        }
2292 <
2293 <        yy_aconf = map_to_conf(make_conf_item(RKLINE_TYPE));
2294 <        yy_aconf->regexuser = exp_user;
2295 <        yy_aconf->regexhost = exp_host;
2296 <
2297 <        DupString(yy_aconf->user, userbuf);
2298 <        DupString(yy_aconf->host, hostbuf);
2299 <
2300 <        if (reasonbuf[0])
2301 <          DupString(yy_aconf->reason, reasonbuf);
2302 <        else
2303 <          DupString(yy_aconf->reason, "No reason");
2304 < #else
2305 <        ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: no PCRE support");
2306 <        break;
2307 < #endif
2308 <      }
2309 <      else
2310 <      {
2311 <        find_and_delete_temporary(userbuf, hostbuf, CONF_KLINE);
2312 <
2313 <        yy_aconf = map_to_conf(make_conf_item(KLINE_TYPE));
2314 <
2315 <        DupString(yy_aconf->user, userbuf);
2316 <        DupString(yy_aconf->host, hostbuf);
2280 >  struct MaskItem *conf = NULL;
2281  
2282 <        if (reasonbuf[0])
2283 <          DupString(yy_aconf->reason, reasonbuf);
2320 <        else
2321 <          DupString(yy_aconf->reason, "No reason");
2322 <        add_conf_by_address(CONF_KLINE, yy_aconf);
2323 <      }
2324 <    }
2282 >  if (conf_parser_ctx.pass != 2)
2283 >    break;
2284  
2285 <    yy_aconf = NULL;
2286 <  }
2287 < };
2285 >  if (!block_state.user.buf[0] ||
2286 >      !block_state.host.buf[0])
2287 >    break;
2288  
2289 < kill_type: TYPE
2290 < {
2291 < } '='  kill_type_items ';';
2289 >  conf = conf_make(CONF_KLINE);
2290 >  conf->user = xstrdup(block_state.user.buf);
2291 >  conf->host = xstrdup(block_state.host.buf);
2292  
2293 < kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2294 < kill_type_item: REGEX_T
2295 < {
2296 <  if (conf_parser_ctx.pass == 2)
2297 <    regex_ban = 1;
2293 >  if (block_state.rpass.buf[0])
2294 >    conf->reason = xstrdup(block_state.rpass.buf);
2295 >  else
2296 >    conf->reason = xstrdup(CONF_NOREASON);
2297 >  add_conf_by_address(CONF_KLINE, conf);
2298   };
2299  
2300   kill_items:     kill_items kill_item | kill_item;
2301 < kill_item:      kill_user | kill_reason | kill_type | error;
2301 > kill_item:      kill_user | kill_reason | error;
2302  
2303   kill_user: USER '=' QSTRING ';'
2304   {
2305 +
2306    if (conf_parser_ctx.pass == 2)
2307    {
2308      struct split_nuh_item nuh;
2309  
2310      nuh.nuhmask  = yylval.string;
2311      nuh.nickptr  = NULL;
2312 <    nuh.userptr  = userbuf;
2313 <    nuh.hostptr  = hostbuf;
2312 >    nuh.userptr  = block_state.user.buf;
2313 >    nuh.hostptr  = block_state.host.buf;
2314  
2315      nuh.nicksize = 0;
2316 <    nuh.usersize = sizeof(userbuf);
2317 <    nuh.hostsize = sizeof(hostbuf);
2316 >    nuh.usersize = sizeof(block_state.user.buf);
2317 >    nuh.hostsize = sizeof(block_state.host.buf);
2318  
2319      split_nuh(&nuh);
2320    }
2321   };
2322  
2323 < kill_reason: REASON '=' QSTRING ';'
2323 > kill_reason: REASON '=' QSTRING ';'
2324   {
2325    if (conf_parser_ctx.pass == 2)
2326 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2326 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2327   };
2328  
2329   /***************************************************************************
2330   *  section deny
2331   ***************************************************************************/
2332 < deny_entry: DENY
2332 > deny_entry: DENY
2333   {
2334    if (conf_parser_ctx.pass == 2)
2335 <    hostbuf[0] = reasonbuf[0] = '\0';
2335 >    reset_block_state();
2336   } '{' deny_items '}' ';'
2337   {
2338 <  if (conf_parser_ctx.pass == 2)
2379 <  {
2380 <    if (hostbuf[0] && parse_netmask(hostbuf, NULL, NULL) != HM_HOST)
2381 <    {
2382 <      find_and_delete_temporary(NULL, hostbuf, CONF_DLINE);
2338 >  struct MaskItem *conf = NULL;
2339  
2340 <      yy_aconf = map_to_conf(make_conf_item(DLINE_TYPE));
2341 <      DupString(yy_aconf->host, hostbuf);
2340 >  if (conf_parser_ctx.pass != 2)
2341 >    break;
2342  
2343 <      if (reasonbuf[0])
2344 <        DupString(yy_aconf->reason, reasonbuf);
2345 <      else
2346 <        DupString(yy_aconf->reason, "No reason");
2347 <      add_conf_by_address(CONF_DLINE, yy_aconf);
2348 <      yy_aconf = NULL;
2349 <    }
2343 >  if (!block_state.addr.buf[0])
2344 >    break;
2345 >
2346 >  if (parse_netmask(block_state.addr.buf, NULL, NULL) != HM_HOST)
2347 >  {
2348 >    conf = conf_make(CONF_DLINE);
2349 >    conf->host = xstrdup(block_state.addr.buf);
2350 >
2351 >    if (block_state.rpass.buf[0])
2352 >      conf->reason = xstrdup(block_state.rpass.buf);
2353 >    else
2354 >      conf->reason = xstrdup(CONF_NOREASON);
2355 >    add_conf_by_address(CONF_DLINE, conf);
2356    }
2357 < };
2357 > };
2358  
2359   deny_items:     deny_items deny_item | deny_item;
2360   deny_item:      deny_ip | deny_reason | error;
# Line 2400 | Line 2362 | deny_item:      deny_ip | deny_reason |
2362   deny_ip: IP '=' QSTRING ';'
2363   {
2364    if (conf_parser_ctx.pass == 2)
2365 <    strlcpy(hostbuf, yylval.string, sizeof(hostbuf));
2365 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2366   };
2367  
2368 < deny_reason: REASON '=' QSTRING ';'
2368 > deny_reason: REASON '=' QSTRING ';'
2369   {
2370    if (conf_parser_ctx.pass == 2)
2371 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2371 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2372   };
2373  
2374   /***************************************************************************
# Line 2423 | Line 2385 | exempt_ip: IP '=' QSTRING ';'
2385    {
2386      if (yylval.string[0] && parse_netmask(yylval.string, NULL, NULL) != HM_HOST)
2387      {
2388 <      yy_aconf = map_to_conf(make_conf_item(EXEMPTDLINE_TYPE));
2389 <      DupString(yy_aconf->host, yylval.string);
2388 >      struct MaskItem *conf = conf_make(CONF_EXEMPT);
2389 >      conf->host = xstrdup(yylval.string);
2390  
2391 <      add_conf_by_address(CONF_EXEMPTDLINE, yy_aconf);
2430 <      yy_aconf = NULL;
2391 >      add_conf_by_address(CONF_EXEMPT, conf);
2392      }
2393    }
2394   };
# Line 2438 | Line 2399 | exempt_ip: IP '=' QSTRING ';'
2399   gecos_entry: GECOS
2400   {
2401    if (conf_parser_ctx.pass == 2)
2402 <  {
2442 <    regex_ban = 0;
2443 <    reasonbuf[0] = gecos_name[0] = '\0';
2444 <  }
2402 >    reset_block_state();
2403   } '{' gecos_items '}' ';'
2404   {
2405 <  if (conf_parser_ctx.pass == 2)
2448 <  {
2449 <    if (gecos_name[0])
2450 <    {
2451 <      if (regex_ban)
2452 <      {
2453 < #ifdef HAVE_LIBPCRE
2454 <        void *exp_p = NULL;
2455 <        const char *errptr = NULL;
2456 <
2457 <        if (!(exp_p = ircd_pcre_compile(gecos_name, &errptr)))
2458 <        {
2459 <          ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: %s",
2460 <               errptr);
2461 <          break;
2462 <        }
2463 <
2464 <        yy_conf = make_conf_item(RXLINE_TYPE);
2465 <        yy_conf->regexpname = exp_p;
2466 < #else
2467 <        ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: no PCRE support");
2468 <        break;
2469 < #endif
2470 <      }
2471 <      else
2472 <        yy_conf = make_conf_item(XLINE_TYPE);
2405 >  struct MaskItem *conf = NULL;
2406  
2407 <      yy_match_item = map_to_conf(yy_conf);
2408 <      DupString(yy_conf->name, gecos_name);
2407 >  if (conf_parser_ctx.pass != 2)
2408 >    break;
2409  
2410 <      if (reasonbuf[0])
2411 <        DupString(yy_match_item->reason, reasonbuf);
2479 <      else
2480 <        DupString(yy_match_item->reason, "No reason");
2481 <    }
2482 <  }
2483 < };
2410 >  if (!block_state.name.buf[0])
2411 >    break;
2412  
2413 < gecos_flags: TYPE
2414 < {
2487 < } '='  gecos_flags_items ';';
2413 >  conf = conf_make(CONF_XLINE);
2414 >  conf->name = xstrdup(block_state.name.buf);
2415  
2416 < gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2417 < gecos_flags_item: REGEX_T
2418 < {
2419 <  if (conf_parser_ctx.pass == 2)
2493 <    regex_ban = 1;
2416 >  if (block_state.rpass.buf[0])
2417 >    conf->reason = xstrdup(block_state.rpass.buf);
2418 >  else
2419 >    conf->reason = xstrdup(CONF_NOREASON);
2420   };
2421  
2422   gecos_items: gecos_items gecos_item | gecos_item;
2423 < gecos_item:  gecos_name | gecos_reason | gecos_flags | error;
2423 > gecos_item:  gecos_name | gecos_reason | error;
2424  
2425 < gecos_name: NAME '=' QSTRING ';'
2425 > gecos_name: NAME '=' QSTRING ';'
2426   {
2427    if (conf_parser_ctx.pass == 2)
2428 <    strlcpy(gecos_name, yylval.string, sizeof(gecos_name));
2428 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2429   };
2430  
2431 < gecos_reason: REASON '=' QSTRING ';'
2431 > gecos_reason: REASON '=' QSTRING ';'
2432   {
2433    if (conf_parser_ctx.pass == 2)
2434 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2434 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2435   };
2436  
2437   /***************************************************************************
# Line 2515 | Line 2441 | general_entry: GENERAL
2441    '{' general_items '}' ';';
2442  
2443   general_items:      general_items general_item | general_item;
2444 < general_item:       general_hide_spoof_ips | general_ignore_bogus_ts |
2445 <                    general_failed_oper_notice | general_anti_nick_flood |
2446 <                    general_max_nick_time | general_max_nick_changes |
2447 <                    general_max_accept | general_anti_spam_exit_message_time |
2448 <                    general_ts_warn_delta | general_ts_max_delta |
2449 <                    general_kill_chase_time_limit | general_kline_with_reason |
2450 <                    general_kline_reason | general_invisible_on_connect |
2451 <                    general_warn_no_nline | general_dots_in_ident |
2452 <                    general_stats_o_oper_only | general_stats_k_oper_only |
2453 <                    general_pace_wait | general_stats_i_oper_only |
2454 <                    general_pace_wait_simple | general_stats_P_oper_only |
2455 <                    general_short_motd | general_no_oper_flood |
2456 <                    general_true_no_oper_flood | general_oper_pass_resv |
2457 <                    general_message_locale |
2458 <                    general_oper_only_umodes | general_max_targets |
2459 <                    general_use_egd | general_egdpool_path |
2460 <                    general_oper_umodes | general_caller_id_wait |
2461 <                    general_opers_bypass_callerid | general_default_floodcount |
2462 <                    general_min_nonwildcard | general_min_nonwildcard_simple |
2463 <                    general_disable_remote_commands |
2464 <                    general_client_flood |
2465 <                    general_throttle_time | general_havent_read_conf |
2444 > general_item:       general_hide_spoof_ips |
2445 >                    general_ignore_bogus_ts |
2446 >                    general_failed_oper_notice |
2447 >                    general_anti_nick_flood |
2448 >                    general_max_nick_time |
2449 >                    general_max_nick_changes |
2450 >                    general_max_accept |
2451 >                    general_anti_spam_exit_message_time |
2452 >                    general_ts_warn_delta |
2453 >                    general_ts_max_delta |
2454 >                    general_kill_chase_time_limit |
2455 >                    general_invisible_on_connect |
2456 >                    general_warn_no_connect_block |
2457 >                    general_dots_in_ident |
2458 >                    general_stats_o_oper_only |
2459 >                    general_stats_k_oper_only |
2460 >                    general_pace_wait |
2461 >                    general_stats_i_oper_only |
2462 >                    general_pace_wait_simple |
2463 >                    general_stats_P_oper_only |
2464 >                    general_stats_u_oper_only |
2465 >                    general_short_motd |
2466 >                    general_no_oper_flood |
2467 >                    general_true_no_oper_flood |
2468 >                    general_oper_pass_resv |
2469 >                    general_oper_only_umodes |
2470 >                    general_max_targets |
2471 >                    general_use_egd |
2472 >                    general_egdpool_path |
2473 >                    general_oper_umodes |
2474 >                    general_caller_id_wait |
2475 >                    general_opers_bypass_callerid |
2476 >                    general_default_floodcount |
2477 >                    general_min_nonwildcard |
2478 >                    general_min_nonwildcard_simple |
2479 >                    general_throttle_time |
2480 >                    general_havent_read_conf |
2481                      general_ping_cookie |
2482 <                    general_disable_auth |
2483 <                    general_tkline_expire_notices | general_gline_min_cidr |
2484 <                    general_gline_min_cidr6 | general_use_whois_actually |
2485 <                    general_reject_hold_time | general_stats_e_disabled |
2486 <                    general_max_watch | general_services_name |
2487 <                    error;
2482 >                    general_disable_auth |
2483 >                    general_tkline_expire_notices |
2484 >                    general_gline_enable |
2485 >                    general_gline_duration |
2486 >                    general_gline_request_duration |
2487 >                    general_gline_min_cidr |
2488 >                    general_gline_min_cidr6 |
2489 >                    general_stats_e_disabled |
2490 >                    general_max_watch |
2491 >                    general_services_name |
2492 >                    general_cycle_on_host_change |
2493 >                    error;
2494  
2495  
2496   general_max_watch: MAX_WATCH '=' NUMBER ';'
# Line 2551 | Line 2498 | general_max_watch: MAX_WATCH '=' NUMBER
2498    ConfigFileEntry.max_watch = $3;
2499   };
2500  
2501 < general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2501 > general_cycle_on_host_change: CYCLE_ON_HOST_CHANGE '=' TBOOL ';'
2502   {
2503 <  ConfigFileEntry.gline_min_cidr = $3;
2503 >  if (conf_parser_ctx.pass == 2)
2504 >    ConfigFileEntry.cycle_on_host_change = yylval.number;
2505   };
2506  
2507 < general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2507 > general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2508   {
2509 <  ConfigFileEntry.gline_min_cidr6 = $3;
2509 >  if (conf_parser_ctx.pass == 2)
2510 >    ConfigFileEntry.glines = yylval.number;
2511   };
2512  
2513 < general_use_whois_actually: USE_WHOIS_ACTUALLY '=' TBOOL ';'
2513 > general_gline_duration: GLINE_DURATION '=' timespec ';'
2514   {
2515 <  ConfigFileEntry.use_whois_actually = yylval.number;
2515 >  if (conf_parser_ctx.pass == 2)
2516 >    ConfigFileEntry.gline_time = $3;
2517 > };
2518 >
2519 > general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2520 > {
2521 >  if (conf_parser_ctx.pass == 2)
2522 >    ConfigFileEntry.gline_request_time = $3;
2523   };
2524  
2525 < general_reject_hold_time: TREJECT_HOLD_TIME '=' timespec ';'
2525 > general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2526   {
2527 <  GlobalSetOptions.rejecttime = yylval.number;
2527 >  ConfigFileEntry.gline_min_cidr = $3;
2528 > };
2529 >
2530 > general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2531 > {
2532 >  ConfigFileEntry.gline_min_cidr6 = $3;
2533   };
2534  
2535   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
# Line 2591 | Line 2552 | general_ignore_bogus_ts: IGNORE_BOGUS_TS
2552    ConfigFileEntry.ignore_bogus_ts = yylval.number;
2553   };
2554  
2594 – general_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2595 – {
2596 –  ConfigFileEntry.disable_remote = yylval.number;
2597 – };
2598 –
2555   general_failed_oper_notice: FAILED_OPER_NOTICE '=' TBOOL ';'
2556   {
2557    ConfigFileEntry.failed_oper_notice = yylval.number;
# Line 2608 | Line 2564 | general_anti_nick_flood: ANTI_NICK_FLOOD
2564  
2565   general_max_nick_time: MAX_NICK_TIME '=' timespec ';'
2566   {
2567 <  ConfigFileEntry.max_nick_time = $3;
2567 >  ConfigFileEntry.max_nick_time = $3;
2568   };
2569  
2570   general_max_nick_changes: MAX_NICK_CHANGES '=' NUMBER ';'
# Line 2648 | Line 2604 | general_havent_read_conf: HAVENT_READ_CO
2604    }
2605   };
2606  
2651 – general_kline_with_reason: KLINE_WITH_REASON '=' TBOOL ';'
2652 – {
2653 –  ConfigFileEntry.kline_with_reason = yylval.number;
2654 – };
2655 –
2656 – general_kline_reason: KLINE_REASON '=' QSTRING ';'
2657 – {
2658 –  if (conf_parser_ctx.pass == 2)
2659 –  {
2660 –    MyFree(ConfigFileEntry.kline_reason);
2661 –    DupString(ConfigFileEntry.kline_reason, yylval.string);
2662 –  }
2663 – };
2664 –
2607   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2608   {
2609    ConfigFileEntry.invisible_on_connect = yylval.number;
2610   };
2611  
2612 < general_warn_no_nline: WARN_NO_NLINE '=' TBOOL ';'
2612 > general_warn_no_connect_block: WARN_NO_CONNECT_BLOCK '=' TBOOL ';'
2613   {
2614 <  ConfigFileEntry.warn_no_nline = yylval.number;
2614 >  ConfigFileEntry.warn_no_connect_block = yylval.number;
2615   };
2616  
2617   general_stats_e_disabled: STATS_E_DISABLED '=' TBOOL ';'
# Line 2687 | Line 2629 | general_stats_P_oper_only: STATS_P_OPER_
2629    ConfigFileEntry.stats_P_oper_only = yylval.number;
2630   };
2631  
2632 + general_stats_u_oper_only: STATS_U_OPER_ONLY '=' TBOOL ';'
2633 + {
2634 +  ConfigFileEntry.stats_u_oper_only = yylval.number;
2635 + };
2636 +
2637   general_stats_k_oper_only: STATS_K_OPER_ONLY '=' TBOOL ';'
2638   {
2639    ConfigFileEntry.stats_k_oper_only = 2 * yylval.number;
# Line 2727 | Line 2674 | general_short_motd: SHORT_MOTD '=' TBOOL
2674   {
2675    ConfigFileEntry.short_motd = yylval.number;
2676   };
2677 <  
2677 >
2678   general_no_oper_flood: NO_OPER_FLOOD '=' TBOOL ';'
2679   {
2680    ConfigFileEntry.no_oper_flood = yylval.number;
# Line 2743 | Line 2690 | general_oper_pass_resv: OPER_PASS_RESV '
2690    ConfigFileEntry.oper_pass_resv = yylval.number;
2691   };
2692  
2746 – general_message_locale: MESSAGE_LOCALE '=' QSTRING ';'
2747 – {
2748 –  if (conf_parser_ctx.pass == 2)
2749 –  {
2750 –    if (strlen(yylval.string) > LOCALE_LENGTH-2)
2751 –      yylval.string[LOCALE_LENGTH-1] = '\0';
2752 –
2753 –    set_locale(yylval.string);
2754 –  }
2755 – };
2756 –
2693   general_dots_in_ident: DOTS_IN_IDENT '=' NUMBER ';'
2694   {
2695    ConfigFileEntry.dots_in_ident = $3;
# Line 2774 | Line 2710 | general_egdpool_path: EGDPOOL_PATH '=' Q
2710    if (conf_parser_ctx.pass == 2)
2711    {
2712      MyFree(ConfigFileEntry.egdpool_path);
2713 <    DupString(ConfigFileEntry.egdpool_path, yylval.string);
2713 >    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2714    }
2715   };
2716  
# Line 2783 | Line 2719 | general_services_name: T_SERVICES_NAME '
2719    if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2720    {
2721      MyFree(ConfigFileEntry.service_name);
2722 <    DupString(ConfigFileEntry.service_name, yylval.string);
2722 >    ConfigFileEntry.service_name = xstrdup(yylval.string);
2723    }
2724   };
2725  
# Line 2799 | Line 2735 | general_disable_auth: DISABLE_AUTH '=' T
2735  
2736   general_throttle_time: THROTTLE_TIME '=' timespec ';'
2737   {
2738 <  ConfigFileEntry.throttle_time = yylval.number;
2738 >  ConfigFileEntry.throttle_time = $3;
2739   };
2740  
2741   general_oper_umodes: OPER_UMODES
# Line 2814 | Line 2750 | umode_oitem:     T_BOTS
2750   } | T_CCONN
2751   {
2752    ConfigFileEntry.oper_umodes |= UMODE_CCONN;
2817 – } | T_CCONN_FULL
2818 – {
2819 –  ConfigFileEntry.oper_umodes |= UMODE_CCONN_FULL;
2753   } | T_DEAF
2754   {
2755    ConfigFileEntry.oper_umodes |= UMODE_DEAF;
# Line 2829 | Line 2762 | umode_oitem:     T_BOTS
2762   } | HIDDEN
2763   {
2764    ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2765 + } | HIDE_IDLE
2766 + {
2767 +  ConfigFileEntry.oper_umodes |= UMODE_HIDEIDLE;
2768   } | T_SKILL
2769   {
2770    ConfigFileEntry.oper_umodes |= UMODE_SKILL;
# Line 2868 | Line 2804 | umode_oitem:     T_BOTS
2804   } | T_LOCOPS
2805   {
2806    ConfigFileEntry.oper_umodes |= UMODE_LOCOPS;
2807 + } | T_NONONREG
2808 + {
2809 +  ConfigFileEntry.oper_umodes |= UMODE_REGONLY;
2810 + } | T_FARCONNECT
2811 + {
2812 +  ConfigFileEntry.oper_umodes |= UMODE_FARCONNECT;
2813   };
2814  
2815 < general_oper_only_umodes: OPER_ONLY_UMODES
2815 > general_oper_only_umodes: OPER_ONLY_UMODES
2816   {
2817    ConfigFileEntry.oper_only_umodes = 0;
2818   } '='  umode_items ';' ;
2819  
2820 < umode_items:    umode_items ',' umode_item | umode_item;
2821 < umode_item:     T_BOTS
2820 > umode_items:  umode_items ',' umode_item | umode_item;
2821 > umode_item:   T_BOTS
2822   {
2823    ConfigFileEntry.oper_only_umodes |= UMODE_BOTS;
2824   } | T_CCONN
2825   {
2826    ConfigFileEntry.oper_only_umodes |= UMODE_CCONN;
2885 – } | T_CCONN_FULL
2886 – {
2887 –  ConfigFileEntry.oper_only_umodes |= UMODE_CCONN_FULL;
2827   } | T_DEAF
2828   {
2829    ConfigFileEntry.oper_only_umodes |= UMODE_DEAF;
# Line 2892 | Line 2831 | umode_item:    T_BOTS
2831   {
2832    ConfigFileEntry.oper_only_umodes |= UMODE_DEBUG;
2833   } | T_FULL
2834 < {
2834 > {
2835    ConfigFileEntry.oper_only_umodes |= UMODE_FULL;
2836   } | T_SKILL
2837   {
# Line 2936 | Line 2875 | umode_item:    T_BOTS
2875   } | T_LOCOPS
2876   {
2877    ConfigFileEntry.oper_only_umodes |= UMODE_LOCOPS;
2878 + } | T_NONONREG
2879 + {
2880 +  ConfigFileEntry.oper_only_umodes |= UMODE_REGONLY;
2881 + } | T_FARCONNECT
2882 + {
2883 +  ConfigFileEntry.oper_only_umodes |= UMODE_FARCONNECT;
2884   };
2885  
2886   general_min_nonwildcard: MIN_NONWILDCARD '=' NUMBER ';'
# Line 2953 | Line 2898 | general_default_floodcount: DEFAULT_FLOO
2898    ConfigFileEntry.default_floodcount = $3;
2899   };
2900  
2956 – general_client_flood: T_CLIENT_FLOOD '=' sizespec ';'
2957 – {
2958 –  ConfigFileEntry.client_flood = $3;
2959 – };
2960 –
2961 –
2962 – /***************************************************************************
2963 – *  section glines
2964 – ***************************************************************************/
2965 – gline_entry: GLINES
2966 – {
2967 –  if (conf_parser_ctx.pass == 2)
2968 –  {
2969 –    yy_conf = make_conf_item(GDENY_TYPE);
2970 –    yy_aconf = map_to_conf(yy_conf);
2971 –  }
2972 – } '{' gline_items '}' ';'
2973 – {
2974 –  if (conf_parser_ctx.pass == 2)
2975 –  {
2976 –    /*
2977 –     * since we re-allocate yy_conf/yy_aconf after the end of action=, at the
2978 –     * end we will have one extra, so we should free it.
2979 –     */
2980 –    if (yy_conf->name == NULL || yy_aconf->user == NULL)
2981 –    {
2982 –      delete_conf_item(yy_conf);
2983 –      yy_conf = NULL;
2984 –      yy_aconf = NULL;
2985 –    }
2986 –  }
2987 – };
2988 –
2989 – gline_items:        gline_items gline_item | gline_item;
2990 – gline_item:         gline_enable |
2991 –                    gline_duration |
2992 –                    gline_logging |
2993 –                    gline_user |
2994 –                    gline_server |
2995 –                    gline_action |
2996 –                    error;
2997 –
2998 – gline_enable: ENABLE '=' TBOOL ';'
2999 – {
3000 –  if (conf_parser_ctx.pass == 2)
3001 –    ConfigFileEntry.glines = yylval.number;
3002 – };
3003 –
3004 – gline_duration: DURATION '=' timespec ';'
3005 – {
3006 –  if (conf_parser_ctx.pass == 2)
3007 –    ConfigFileEntry.gline_time = $3;
3008 – };
3009 –
3010 – gline_logging: T_LOG
3011 – {
3012 –  if (conf_parser_ctx.pass == 2)
3013 –    ConfigFileEntry.gline_logging = 0;
3014 – } '=' gline_logging_types ';';
3015 – gline_logging_types:     gline_logging_types ',' gline_logging_type_item | gline_logging_type_item;
3016 – gline_logging_type_item: T_REJECT
3017 – {
3018 –  if (conf_parser_ctx.pass == 2)
3019 –    ConfigFileEntry.gline_logging |= GDENY_REJECT;
3020 – } | T_BLOCK
3021 – {
3022 –  if (conf_parser_ctx.pass == 2)
3023 –    ConfigFileEntry.gline_logging |= GDENY_BLOCK;
3024 – };
3025 –
3026 – gline_user: USER '=' QSTRING ';'
3027 – {
3028 –  if (conf_parser_ctx.pass == 2)
3029 –  {
3030 –    struct split_nuh_item nuh;
3031 –
3032 –    nuh.nuhmask  = yylval.string;
3033 –    nuh.nickptr  = NULL;
3034 –    nuh.userptr  = userbuf;
3035 –    nuh.hostptr  = hostbuf;
3036 –
3037 –    nuh.nicksize = 0;
3038 –    nuh.usersize = sizeof(userbuf);
3039 –    nuh.hostsize = sizeof(hostbuf);
3040 –
3041 –    split_nuh(&nuh);
3042 –
3043 –    if (yy_aconf->user == NULL)
3044 –    {
3045 –      DupString(yy_aconf->user, userbuf);
3046 –      DupString(yy_aconf->host, hostbuf);
3047 –    }
3048 –    else
3049 –    {
3050 –      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
3051 –
3052 –      DupString(yy_tmp->user, userbuf);
3053 –      DupString(yy_tmp->host, hostbuf);
3054 –
3055 –      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
3056 –    }
3057 –  }
3058 – };
3059 –
3060 – gline_server: NAME '=' QSTRING ';'
3061 – {
3062 –  if (conf_parser_ctx.pass == 2)  
3063 –  {
3064 –    MyFree(yy_conf->name);
3065 –    DupString(yy_conf->name, yylval.string);
3066 –  }
3067 – };
3068 –
3069 – gline_action: ACTION
3070 – {
3071 –  if (conf_parser_ctx.pass == 2)
3072 –    yy_aconf->flags = 0;
3073 – } '=' gdeny_types ';'
3074 – {
3075 –  if (conf_parser_ctx.pass == 2)
3076 –  {
3077 –    struct CollectItem *yy_tmp = NULL;
3078 –    dlink_node *ptr, *next_ptr;
3079 –
3080 –    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
3081 –    {
3082 –      struct AccessItem *new_aconf;
3083 –      struct ConfItem *new_conf;
3084 –
3085 –      yy_tmp = ptr->data;
3086 –      new_conf = make_conf_item(GDENY_TYPE);
3087 –      new_aconf = map_to_conf(new_conf);
3088 –
3089 –      new_aconf->flags = yy_aconf->flags;
3090 –
3091 –      if (yy_conf->name != NULL)
3092 –        DupString(new_conf->name, yy_conf->name);
3093 –      else
3094 –        DupString(new_conf->name, "*");
3095 –      if (yy_aconf->user != NULL)
3096 –         DupString(new_aconf->user, yy_tmp->user);
3097 –      else  
3098 –        DupString(new_aconf->user, "*");
3099 –      if (yy_aconf->host != NULL)
3100 –        DupString(new_aconf->host, yy_tmp->host);
3101 –      else
3102 –        DupString(new_aconf->host, "*");
3103 –
3104 –      dlinkDelete(&yy_tmp->node, &col_conf_list);
3105 –    }
3106 –
3107 –    /*
3108 –     * In case someone has fed us with more than one action= after user/name
3109 –     * which would leak memory  -Michael
3110 –     */
3111 –    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3112 –      delete_conf_item(yy_conf);
3113 –
3114 –    yy_conf = make_conf_item(GDENY_TYPE);
3115 –    yy_aconf = map_to_conf(yy_conf);
3116 –  }
3117 – };
3118 –
3119 – gdeny_types: gdeny_types ',' gdeny_type_item | gdeny_type_item;
3120 – gdeny_type_item: T_REJECT
3121 – {
3122 –  if (conf_parser_ctx.pass == 2)
3123 –    yy_aconf->flags |= GDENY_REJECT;
3124 – } | T_BLOCK
3125 – {
3126 –  if (conf_parser_ctx.pass == 2)
3127 –    yy_aconf->flags |= GDENY_BLOCK;
3128 – };
2901  
2902   /***************************************************************************
2903   *  section channel
# Line 3134 | Line 2906 | channel_entry: CHANNEL
2906    '{' channel_items '}' ';';
2907  
2908   channel_items:      channel_items channel_item | channel_item;
2909 < channel_item:       channel_disable_local_channels | channel_use_except |
2910 <                    channel_use_invex | channel_use_knock |
2911 <                    channel_max_bans | channel_knock_delay |
2912 <                    channel_knock_delay_channel | channel_max_chans_per_user |
2913 <                    channel_quiet_on_ban | channel_default_split_user_count |
2909 > channel_item:       channel_max_bans |
2910 >                    channel_knock_delay |
2911 >                    channel_knock_delay_channel |
2912 >                    channel_max_chans_per_user |
2913 >                    channel_max_chans_per_oper |
2914 >                    channel_default_split_user_count |
2915                      channel_default_split_server_count |
2916 <                    channel_no_create_on_split | channel_restrict_channels |
2917 <                    channel_no_join_on_split | channel_burst_topicwho |
2918 <                    channel_jflood_count | channel_jflood_time |
2919 <                    channel_disable_fake_channels | error;
2916 >                    channel_no_create_on_split |
2917 >                    channel_no_join_on_split |
2918 >                    channel_jflood_count |
2919 >                    channel_jflood_time |
2920 >                    channel_disable_fake_channels |
2921 >                    error;
2922  
2923   channel_disable_fake_channels: DISABLE_FAKE_CHANNELS '=' TBOOL ';'
2924   {
2925    ConfigChannel.disable_fake_channels = yylval.number;
2926   };
2927  
3153 – channel_restrict_channels: RESTRICT_CHANNELS '=' TBOOL ';'
3154 – {
3155 –  ConfigChannel.restrict_channels = yylval.number;
3156 – };
3157 –
3158 – channel_disable_local_channels: DISABLE_LOCAL_CHANNELS '=' TBOOL ';'
3159 – {
3160 –  ConfigChannel.disable_local_channels = yylval.number;
3161 – };
3162 –
3163 – channel_use_except: USE_EXCEPT '=' TBOOL ';'
3164 – {
3165 –  ConfigChannel.use_except = yylval.number;
3166 – };
3167 –
3168 – channel_use_invex: USE_INVEX '=' TBOOL ';'
3169 – {
3170 –  ConfigChannel.use_invex = yylval.number;
3171 – };
3172 –
3173 – channel_use_knock: USE_KNOCK '=' TBOOL ';'
3174 – {
3175 –  ConfigChannel.use_knock = yylval.number;
3176 – };
3177 –
2928   channel_knock_delay: KNOCK_DELAY '=' timespec ';'
2929   {
2930    ConfigChannel.knock_delay = $3;
# Line 3190 | Line 2940 | channel_max_chans_per_user: MAX_CHANS_PE
2940    ConfigChannel.max_chans_per_user = $3;
2941   };
2942  
2943 < channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
2943 > channel_max_chans_per_oper: MAX_CHANS_PER_OPER '=' NUMBER ';'
2944   {
2945 <  ConfigChannel.quiet_on_ban = yylval.number;
2945 >  ConfigChannel.max_chans_per_oper = $3;
2946   };
2947  
2948   channel_max_bans: MAX_BANS '=' NUMBER ';'
# Line 3220 | Line 2970 | channel_no_join_on_split: NO_JOIN_ON_SPL
2970    ConfigChannel.no_join_on_split = yylval.number;
2971   };
2972  
3223 – channel_burst_topicwho: BURST_TOPICWHO '=' TBOOL ';'
3224 – {
3225 –  ConfigChannel.burst_topicwho = yylval.number;
3226 – };
3227 –
2973   channel_jflood_count: JOIN_FLOOD_COUNT '=' NUMBER ';'
2974   {
2975    GlobalSetOptions.joinfloodcount = yylval.number;
# Line 3232 | Line 2977 | channel_jflood_count: JOIN_FLOOD_COUNT '
2977  
2978   channel_jflood_time: JOIN_FLOOD_TIME '=' timespec ';'
2979   {
2980 <  GlobalSetOptions.joinfloodtime = yylval.number;
2980 >  GlobalSetOptions.joinfloodtime = $3;
2981   };
2982  
2983   /***************************************************************************
# Line 3242 | Line 2987 | serverhide_entry: SERVERHIDE
2987    '{' serverhide_items '}' ';';
2988  
2989   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
2990 < serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
2991 <                    serverhide_links_delay |
2992 <                    serverhide_disable_hidden |
2993 <                    serverhide_hidden | serverhide_hidden_name |
2994 <                    serverhide_hide_server_ips |
2990 > serverhide_item:    serverhide_flatten_links |
2991 >                    serverhide_disable_remote_commands |
2992 >                    serverhide_hide_servers |
2993 >                    serverhide_hide_services |
2994 >                    serverhide_links_delay |
2995 >                    serverhide_hidden |
2996 >                    serverhide_hidden_name |
2997 >                    serverhide_hide_server_ips |
2998                      error;
2999  
3000   serverhide_flatten_links: FLATTEN_LINKS '=' TBOOL ';'
# Line 3255 | Line 3003 | serverhide_flatten_links: FLATTEN_LINKS
3003      ConfigServerHide.flatten_links = yylval.number;
3004   };
3005  
3006 + serverhide_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
3007 + {
3008 +  if (conf_parser_ctx.pass == 2)
3009 +    ConfigServerHide.disable_remote_commands = yylval.number;
3010 + };
3011 +
3012   serverhide_hide_servers: HIDE_SERVERS '=' TBOOL ';'
3013   {
3014    if (conf_parser_ctx.pass == 2)
3015      ConfigServerHide.hide_servers = yylval.number;
3016   };
3017  
3018 + serverhide_hide_services: HIDE_SERVICES '=' TBOOL ';'
3019 + {
3020 +  if (conf_parser_ctx.pass == 2)
3021 +    ConfigServerHide.hide_services = yylval.number;
3022 + };
3023 +
3024   serverhide_hidden_name: HIDDEN_NAME '=' QSTRING ';'
3025   {
3026    if (conf_parser_ctx.pass == 2)
3027    {
3028      MyFree(ConfigServerHide.hidden_name);
3029 <    DupString(ConfigServerHide.hidden_name, yylval.string);
3029 >    ConfigServerHide.hidden_name = xstrdup(yylval.string);
3030    }
3031   };
3032  
# Line 3290 | Line 3050 | serverhide_hidden: HIDDEN '=' TBOOL ';'
3050      ConfigServerHide.hidden = yylval.number;
3051   };
3052  
3293 – serverhide_disable_hidden: DISABLE_HIDDEN '=' TBOOL ';'
3294 – {
3295 –  if (conf_parser_ctx.pass == 2)
3296 –    ConfigServerHide.disable_hidden = yylval.number;
3297 – };
3298 –
3053   serverhide_hide_server_ips: HIDE_SERVER_IPS '=' TBOOL ';'
3054   {
3055    if (conf_parser_ctx.pass == 2)

Diff Legend

– Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)