ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing:
ircd-hybrid-7.2/src/ircd_parser.y (file contents), Revision 1024 by michael, Sun Nov 1 23:14:25 2009 UTC vs.
ircd-hybrid/trunk/src/conf_parser.y (file contents), Revision 2244 by michael, Sat Jun 15 22:08:10 2013 UTC

# Line 1 | Line 1
1   /*
2   *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  ircd_parser.y: Parses the ircd configuration file.
3 > *  conf_parser.y: Parses the ircd configuration file.
4   *
5   *  Copyright (C) 2005 by the past and present ircd coders, and others.
6   *
# Line 32 | Line 32
32   #include "stdinc.h"
33   #include "ircd.h"
34   #include "list.h"
35 < #include "s_conf.h"
35 > #include "conf.h"
36 > #include "conf_class.h"
37   #include "event.h"
38 < #include "s_log.h"
38 > #include "log.h"
39   #include "client.h"     /* for UMODE_ALL only */
40   #include "irc_string.h"
40 #include "irc_getaddrinfo.h"
41 #include "sprintf_irc.h"
41   #include "memory.h"
42   #include "modules.h"
43   #include "s_serv.h"
# Line 48 | Line 47
47   #include "resv.h"
48   #include "numeric.h"
49   #include "s_user.h"
50 + #include "motd.h"
51  
52   #ifdef HAVE_LIBCRYPTO
53   #include <openssl/rsa.h>
54   #include <openssl/bio.h>
55   #include <openssl/pem.h>
56 + #include <openssl/dh.h>
57   #endif
58  
59 < static char *class_name = NULL;
59 < static struct ConfItem *yy_conf = NULL;
60 < static struct AccessItem *yy_aconf = NULL;
61 < static struct MatchItem *yy_match_item = NULL;
62 < static struct ClassItem *yy_class = NULL;
63 < static char *yy_class_name = NULL;
64 <
65 < static dlink_list col_conf_list  = { NULL, NULL, 0 };
66 < static dlink_list hub_conf_list  = { NULL, NULL, 0 };
67 < static dlink_list leaf_conf_list = { NULL, NULL, 0 };
68 < static unsigned int listener_flags = 0;
69 < static unsigned int regex_ban = 0;
70 < static char userbuf[IRCD_BUFSIZE];
71 < static char hostbuf[IRCD_BUFSIZE];
72 < static char reasonbuf[REASONLEN + 1];
73 < static char gecos_name[REALLEN * 4];
74 <
75 < static char *resv_reason = NULL;
76 < static char *listener_address = NULL;
77 < static int not_atom = 0;
78 <
79 < struct CollectItem
80 < {
81 <  dlink_node node;
82 <  char *name;
83 <  char *user;
84 <  char *host;
85 <  char *passwd;
86 <  int  port;
87 <  int  flags;
88 < #ifdef HAVE_LIBCRYPTO
89 <  char *rsa_public_key_file;
90 <  RSA *rsa_public_key;
91 < #endif
92 < };
59 > #include "rsa.h"
60  
61 < static void
62 < free_collect_item(struct CollectItem *item)
61 > int yylex(void);
62 >
63 > static struct
64   {
65 <  MyFree(item->name);
66 <  MyFree(item->user);
67 <  MyFree(item->host);
68 <  MyFree(item->passwd);
69 < #ifdef HAVE_LIBCRYPTO
70 <  MyFree(item->rsa_public_key_file);
71 < #endif
72 <  MyFree(item);
73 < }
65 >  struct {
66 >    dlink_list list;
67 >  } mask,
68 >    leaf,
69 >    hub;
70 >
71 >  struct {
72 >    char buf[IRCD_BUFSIZE];
73 >  } name,
74 >    user,
75 >    host,
76 >    addr,
77 >    bind,
78 >    file,
79 >    ciph,
80 >    cert,
81 >    rpass,
82 >    spass,
83 >    class;
84 >
85 >  struct {
86 >    unsigned int value;
87 >  } flags,
88 >    modes,
89 >    size,
90 >    type,
91 >    port,
92 >    aftype,
93 >    ping_freq,
94 >    max_perip,
95 >    con_freq,
96 >    min_idle,
97 >    max_idle,
98 >    max_total,
99 >    max_global,
100 >    max_local,
101 >    max_ident,
102 >    max_sendq,
103 >    max_recvq,
104 >    cidr_bitlen_ipv4,
105 >    cidr_bitlen_ipv6,
106 >    number_per_cidr;
107 > } block_state;
108  
109   static void
110 < unhook_hub_leaf_confs(void)
110 > reset_block_state(void)
111   {
112 <  dlink_node *ptr;
113 <  dlink_node *next_ptr;
114 <  struct CollectItem *yy_hconf;
115 <  struct CollectItem *yy_lconf;
112 >  dlink_node *ptr = NULL, *ptr_next = NULL;
113 >
114 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.mask.list.head)
115 >  {
116 >    MyFree(ptr->data);
117 >    dlinkDelete(ptr, &block_state.mask.list);
118 >    free_dlink_node(ptr);
119 >  }
120  
121 <  DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
121 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.leaf.list.head)
122    {
123 <    yy_hconf = ptr->data;
124 <    dlinkDelete(&yy_hconf->node, &hub_conf_list);
125 <    free_collect_item(yy_hconf);
123 >    MyFree(ptr->data);
124 >    dlinkDelete(ptr, &block_state.leaf.list);
125 >    free_dlink_node(ptr);
126    }
127  
128 <  DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
128 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.hub.list.head)
129    {
130 <    yy_lconf = ptr->data;
131 <    dlinkDelete(&yy_lconf->node, &leaf_conf_list);
132 <    free_collect_item(yy_lconf);
130 >    MyFree(ptr->data);
131 >    dlinkDelete(ptr, &block_state.hub.list);
132 >    free_dlink_node(ptr);
133    }
134 +
135 +  memset(&block_state, 0, sizeof(block_state));
136   }
137  
138   %}
# Line 135 | Line 143 | unhook_hub_leaf_confs(void)
143   }
144  
145   %token  ACCEPT_PASSWORD
138 %token  ACTION
146   %token  ADMIN
147   %token  AFTYPE
141 %token  T_ALLOW
148   %token  ANTI_NICK_FLOOD
149   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
150   %token  AUTOCONN
151 < %token  T_BLOCK
146 < %token  BURST_AWAY
147 < %token  BURST_TOPICWHO
148 < %token  BYTES KBYTES MBYTES GBYTES TBYTES
151 > %token  BYTES KBYTES MBYTES
152   %token  CALLER_ID_WAIT
153   %token  CAN_FLOOD
151 %token  CAN_IDLE
154   %token  CHANNEL
155 < %token  CIDR_BITLEN_IPV4
156 < %token  CIDR_BITLEN_IPV6
155 < %token  CIPHER_PREFERENCE
155 > %token  CIDR_BITLEN_IPV4
156 > %token  CIDR_BITLEN_IPV6
157   %token  CLASS
157 %token  COMPRESSED
158 %token  COMPRESSION_LEVEL
158   %token  CONNECT
159   %token  CONNECTFREQ
161 %token  CRYPTLINK
162 %token  DEFAULT_CIPHER_PREFERENCE
160   %token  DEFAULT_FLOODCOUNT
161   %token  DEFAULT_SPLIT_SERVER_COUNT
162   %token  DEFAULT_SPLIT_USER_COUNT
# Line 168 | Line 165 | unhook_hub_leaf_confs(void)
165   %token  DIE
166   %token  DISABLE_AUTH
167   %token  DISABLE_FAKE_CHANNELS
171 %token  DISABLE_HIDDEN
172 %token  DISABLE_LOCAL_CHANNELS
168   %token  DISABLE_REMOTE_COMMANDS
174 %token  DOT_IN_IP6_ADDR
169   %token  DOTS_IN_IDENT
176 %token  DURATION
170   %token  EGDPOOL_PATH
171   %token  EMAIL
179 %token  ENABLE
172   %token  ENCRYPTED
173   %token  EXCEED_LIMIT
174   %token  EXEMPT
175   %token  FAILED_OPER_NOTICE
184 %token  FAKENAME
185 %token  IRCD_FLAGS
176   %token  FLATTEN_LINKS
187 %token  FFAILED_OPERLOG
188 %token  FKILLLOG
189 %token  FKLINELOG
190 %token  FGLINELOG
191 %token  FIOERRLOG
192 %token  FOPERLOG
193 %token  FOPERSPYLOG
194 %token  FUSERLOG
177   %token  GECOS
178   %token  GENERAL
179   %token  GLINE
180 < %token  GLINES
180 > %token  GLINE_DURATION
181 > %token  GLINE_ENABLE
182   %token  GLINE_EXEMPT
200 %token  GLINE_LOG
201 %token  GLINE_TIME
183   %token  GLINE_MIN_CIDR
184   %token  GLINE_MIN_CIDR6
185 + %token  GLINE_REQUEST_DURATION
186   %token  GLOBAL_KILL
205 %token  IRCD_AUTH
206 %token  NEED_IDENT
187   %token  HAVENT_READ_CONF
188   %token  HIDDEN
189 < %token  HIDDEN_ADMIN
190 < %token  HIDDEN_NAME
211 < %token  HIDDEN_OPER
189 > %token  HIDDEN_NAME
190 > %token  HIDE_IDLE_FROM_OPERS
191   %token  HIDE_SERVER_IPS
192   %token  HIDE_SERVERS
193 < %token  HIDE_SPOOF_IPS
193 > %token  HIDE_SERVICES
194 > %token  HIDE_SPOOF_IPS
195   %token  HOST
196   %token  HUB
197   %token  HUB_MASK
218 %token  IDLETIME
198   %token  IGNORE_BOGUS_TS
199   %token  INVISIBLE_ON_CONNECT
200   %token  IP
201 + %token  IRCD_AUTH
202 + %token  IRCD_FLAGS
203 + %token  IRCD_SID
204 + %token  JOIN_FLOOD_COUNT
205 + %token  JOIN_FLOOD_TIME
206   %token  KILL
207 < %token  KILL_CHASE_TIME_LIMIT
207 > %token  KILL_CHASE_TIME_LIMIT
208   %token  KLINE
209   %token  KLINE_EXEMPT
226 %token  KLINE_REASON
227 %token  KLINE_WITH_REASON
210   %token  KNOCK_DELAY
211   %token  KNOCK_DELAY_CHANNEL
212   %token  LEAF_MASK
213   %token  LINKS_DELAY
214   %token  LISTEN
215 < %token  T_LOG
234 < %token  LOGGING
235 < %token  LOG_LEVEL
215 > %token  MASK
216   %token  MAX_ACCEPT
217   %token  MAX_BANS
218 + %token  MAX_CHANS_PER_OPER
219   %token  MAX_CHANS_PER_USER
220   %token  MAX_GLOBAL
221   %token  MAX_IDENT
222 + %token  MAX_IDLE
223   %token  MAX_LOCAL
224   %token  MAX_NICK_CHANGES
225 + %token  MAX_NICK_LENGTH
226   %token  MAX_NICK_TIME
227   %token  MAX_NUMBER
228   %token  MAX_TARGETS
229 + %token  MAX_TOPIC_LENGTH
230   %token  MAX_WATCH
231 < %token  MESSAGE_LOCALE
231 > %token  MIN_IDLE
232   %token  MIN_NONWILDCARD
233   %token  MIN_NONWILDCARD_SIMPLE
234   %token  MODULE
235   %token  MODULES
236 + %token  MOTD
237   %token  NAME
238 + %token  NEED_IDENT
239   %token  NEED_PASSWORD
240   %token  NETWORK_DESC
241   %token  NETWORK_NAME
242   %token  NICK
257 %token  NICK_CHANGES
243   %token  NO_CREATE_ON_SPLIT
244   %token  NO_JOIN_ON_SPLIT
245   %token  NO_OPER_FLOOD
246   %token  NO_TILDE
262 %token  NOT
247   %token  NUMBER
264 %token  NUMBER_PER_IDENT
248   %token  NUMBER_PER_CIDR
249   %token  NUMBER_PER_IP
267 %token  NUMBER_PER_IP_GLOBAL
268 %token  OPERATOR
269 %token  OPERS_BYPASS_CALLERID
270 %token  OPER_LOG
250   %token  OPER_ONLY_UMODES
251   %token  OPER_PASS_RESV
273 %token  OPER_SPY_T
252   %token  OPER_UMODES
253 < %token  JOIN_FLOOD_COUNT
254 < %token  JOIN_FLOOD_TIME
253 > %token  OPERATOR
254 > %token  OPERS_BYPASS_CALLERID
255   %token  PACE_WAIT
256   %token  PACE_WAIT_SIMPLE
257   %token  PASSWORD
258   %token  PATH
259   %token  PING_COOKIE
260   %token  PING_TIME
283 %token  PING_WARNING
261   %token  PORT
262   %token  QSTRING
263 < %token  QUIET_ON_BAN
263 > %token  RANDOM_IDLE
264   %token  REASON
265   %token  REDIRPORT
266   %token  REDIRSERV
290 %token  REGEX_T
267   %token  REHASH
292 %token  TREJECT_HOLD_TIME
268   %token  REMOTE
269   %token  REMOTEBAN
295 %token  RESTRICT_CHANNELS
296 %token  RESTRICTED
297 %token  RSA_PRIVATE_KEY_FILE
298 %token  RSA_PUBLIC_KEY_FILE
299 %token  SSL_CERTIFICATE_FILE
300 %token  T_SSL_CONNECTION_METHOD
301 %token  T_SSLV3
302 %token  T_TLSV1
270   %token  RESV
271   %token  RESV_EXEMPT
272 < %token  SECONDS MINUTES HOURS DAYS WEEKS
273 < %token  SENDQ
272 > %token  RSA_PRIVATE_KEY_FILE
273 > %token  RSA_PUBLIC_KEY_FILE
274 > %token  SECONDS MINUTES HOURS DAYS WEEKS MONTHS YEARS
275   %token  SEND_PASSWORD
276 + %token  SENDQ
277   %token  SERVERHIDE
278   %token  SERVERINFO
310 %token  SERVLINK_PATH
311 %token  IRCD_SID
312 %token  TKLINE_EXPIRE_NOTICES
313 %token  T_SHARED
314 %token  T_CLUSTER
315 %token  TYPE
279   %token  SHORT_MOTD
317 %token  SILENT
280   %token  SPOOF
281   %token  SPOOF_NOTICE
282 + %token  SQUIT
283 + %token  SSL_CERTIFICATE_FILE
284 + %token  SSL_CERTIFICATE_FINGERPRINT
285 + %token  SSL_DH_PARAM_FILE
286   %token  STATS_E_DISABLED
287   %token  STATS_I_OPER_ONLY
288   %token  STATS_K_OPER_ONLY
289   %token  STATS_O_OPER_ONLY
290   %token  STATS_P_OPER_ONLY
325 %token  TBOOL
326 %token  TMASKED
327 %token  T_REJECT
328 %token  TS_MAX_DELTA
329 %token  TS_WARN_DELTA
330 %token  TWODOTS
291   %token  T_ALL
292   %token  T_BOTS
333 %token  T_SOFTCALLERID
293   %token  T_CALLERID
294   %token  T_CCONN
295 < %token  T_CCONN_FULL
337 < %token  T_CLIENT_FLOOD
295 > %token  T_CLUSTER
296   %token  T_DEAF
297   %token  T_DEBUG
298 < %token  T_DRONE
298 > %token  T_DLINE
299   %token  T_EXTERNAL
300 + %token  T_FARCONNECT
301 + %token  T_FILE
302   %token  T_FULL
303 + %token  T_GLOBOPS
304   %token  T_INVISIBLE
305   %token  T_IPV4
306   %token  T_IPV6
307   %token  T_LOCOPS
308 < %token  T_LOGPATH
348 < %token  T_L_CRIT
349 < %token  T_L_DEBUG
350 < %token  T_L_ERROR
351 < %token  T_L_INFO
352 < %token  T_L_NOTICE
353 < %token  T_L_TRACE
354 < %token  T_L_WARN
308 > %token  T_LOG
309   %token  T_MAX_CLIENTS
310   %token  T_NCHANGE
311 + %token  T_NONONREG
312   %token  T_OPERWALL
313 + %token  T_RECVQ
314   %token  T_REJ
315 + %token  T_RESTART
316   %token  T_SERVER
317 + %token  T_SERVICE
318 + %token  T_SERVICES_NAME
319   %token  T_SERVNOTICE
320 + %token  T_SET
321 + %token  T_SHARED
322 + %token  T_SIZE
323   %token  T_SKILL
324 + %token  T_SOFTCALLERID
325   %token  T_SPY
326   %token  T_SSL
327 + %token  T_SSL_CIPHER_LIST
328 + %token  T_SSL_CLIENT_METHOD
329 + %token  T_SSL_SERVER_METHOD
330 + %token  T_SSLV3
331 + %token  T_TLSV1
332   %token  T_UMODES
333   %token  T_UNAUTH
334 + %token  T_UNDLINE
335 + %token  T_UNLIMITED
336   %token  T_UNRESV
337   %token  T_UNXLINE
338   %token  T_WALLOP
339 + %token  T_WALLOPS
340 + %token  T_WEBIRC
341 + %token  TBOOL
342   %token  THROTTLE_TIME
343 < %token  TOPICBURST
343 > %token  TKLINE_EXPIRE_NOTICES
344 > %token  TMASKED
345   %token  TRUE_NO_OPER_FLOOD
346 < %token  TKLINE
347 < %token  TXLINE
348 < %token  TRESV
346 > %token  TS_MAX_DELTA
347 > %token  TS_WARN_DELTA
348 > %token  TWODOTS
349 > %token  TYPE
350   %token  UNKLINE
376 %token  USER
351   %token  USE_EGD
378 %token  USE_EXCEPT
379 %token  USE_INVEX
380 %token  USE_KNOCK
352   %token  USE_LOGGING
353 < %token  USE_WHOIS_ACTUALLY
353 > %token  USER
354   %token  VHOST
355   %token  VHOST6
385 %token  XLINE
386 %token  WARN
356   %token  WARN_NO_NLINE
357 + %token  XLINE
358  
359 < %type <string> QSTRING
360 < %type <number> NUMBER
361 < %type <number> timespec
362 < %type <number> timespec_
363 < %type <number> sizespec
364 < %type <number> sizespec_
359 > %type  <string> QSTRING
360 > %type  <number> NUMBER
361 > %type  <number> timespec
362 > %type  <number> timespec_
363 > %type  <number> sizespec
364 > %type  <number> sizespec_
365  
366   %%
367   conf:  
# Line 408 | Line 378 | conf_item:        admin_entry
378                  | serverinfo_entry
379                  | serverhide_entry
380                  | resv_entry
381 +                | service_entry
382                  | shared_entry
383                  | cluster_entry
384                  | connect_entry
# Line 415 | Line 386 | conf_item:        admin_entry
386                  | deny_entry
387                  | exempt_entry
388                  | general_entry
418                | gline_entry
389                  | gecos_entry
390                  | modules_entry
391 +                | motd_entry
392                  | error ';'
393                  | error '}'
394          ;
# Line 448 | Line 419 | timespec:      NUMBER timespec_
419                  {
420                          $$ = $1 * 60 * 60 * 24 * 7 + $3;
421                  }
422 +                | NUMBER MONTHS timespec_
423 +                {
424 +                        $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3;
425 +                }
426 +                | NUMBER YEARS timespec_
427 +                {
428 +                        $$ = $1 * 60 * 60 * 24 * 365 + $3;
429 +                }
430                  ;
431  
432   sizespec_:      { $$ = 0; } | sizespec;
# Line 469 | Line 448 | modules_item:   modules_module | modules
448  
449   modules_module: MODULE '=' QSTRING ';'
450   {
472 #ifndef STATIC_MODULES /* NOOP in the static case */
451    if (conf_parser_ctx.pass == 2)
452      add_conf_module(libio_basename(yylval.string));
475 #endif
453   };
454  
455   modules_path: PATH '=' QSTRING ';'
456   {
480 #ifndef STATIC_MODULES
457    if (conf_parser_ctx.pass == 2)
458      mod_add_path(yylval.string);
483 #endif
459   };
460  
461  
# Line 490 | Line 465 | serverinfo_items:       serverinfo_items
465   serverinfo_item:        serverinfo_name | serverinfo_vhost |
466                          serverinfo_hub | serverinfo_description |
467                          serverinfo_network_name | serverinfo_network_desc |
468 <                        serverinfo_max_clients |
468 >                        serverinfo_max_clients | serverinfo_max_nick_length |
469 >                        serverinfo_max_topic_length | serverinfo_ssl_dh_param_file |
470                          serverinfo_rsa_private_key_file | serverinfo_vhost6 |
471                          serverinfo_sid | serverinfo_ssl_certificate_file |
472 <                        serverinfo_ssl_connection_method |
472 >                        serverinfo_ssl_client_method | serverinfo_ssl_server_method |
473 >                        serverinfo_ssl_cipher_list |
474                          error ';' ;
475  
476  
477 < serverinfo_ssl_connection_method: T_SSL_CONNECTION_METHOD
477 > serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
478 > serverinfo_ssl_server_method: T_SSL_SERVER_METHOD '=' server_method_types ';' ;
479 >
480 > client_method_types: client_method_types ',' client_method_type_item | client_method_type_item;
481 > client_method_type_item: T_SSLV3
482   {
483   #ifdef HAVE_LIBCRYPTO
484 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
485 <    ServerInfo.tls_version = 0;
484 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
485 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv3);
486   #endif
487 < } '=' method_types ';'
487 > } | T_TLSV1
488   {
489   #ifdef HAVE_LIBCRYPTO
490 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
491 <  {
511 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_SSLV3))
512 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
513 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_TLSV1))
514 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
515 <  }
490 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
491 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_TLSv1);
492   #endif
493   };
494  
495 < method_types: method_types ',' method_type_item | method_type_item;
496 < method_type_item: T_SSLV3
495 > server_method_types: server_method_types ',' server_method_type_item | server_method_type_item;
496 > server_method_type_item: T_SSLV3
497   {
498   #ifdef HAVE_LIBCRYPTO
499 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
500 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_SSLV3;
499 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
500 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
501   #endif
502   } | T_TLSV1
503   {
504   #ifdef HAVE_LIBCRYPTO
505 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
506 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_TLSV1;
505 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
506 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
507   #endif
508   };
509  
# Line 538 | Line 514 | serverinfo_ssl_certificate_file: SSL_CER
514    {
515      if (!ServerInfo.rsa_private_key_file)
516      {
517 <      yyerror("No rsa_private_key_file specified, SSL disabled");
517 >      conf_error_report("No rsa_private_key_file specified, SSL disabled");
518        break;
519      }
520  
521      if (SSL_CTX_use_certificate_file(ServerInfo.server_ctx, yylval.string,
522 +                                     SSL_FILETYPE_PEM) <= 0 ||
523 +        SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
524                                       SSL_FILETYPE_PEM) <= 0)
525      {
526 <      yyerror(ERR_lib_error_string(ERR_get_error()));
526 >      report_crypto_errors();
527 >      conf_error_report("Could not open/read certificate file");
528        break;
529      }
530  
531      if (SSL_CTX_use_PrivateKey_file(ServerInfo.server_ctx, ServerInfo.rsa_private_key_file,
532 +                                    SSL_FILETYPE_PEM) <= 0 ||
533 +        SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
534                                      SSL_FILETYPE_PEM) <= 0)
535      {
536 <      yyerror(ERR_lib_error_string(ERR_get_error()));
536 >      report_crypto_errors();
537 >      conf_error_report("Could not read RSA private key");
538        break;
539      }
540  
541 <    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx))
541 >    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
542 >        !SSL_CTX_check_private_key(ServerInfo.client_ctx))
543      {
544 <      yyerror(ERR_lib_error_string(ERR_get_error()));
544 >      report_crypto_errors();
545 >      conf_error_report("Could not read RSA private key");
546        break;
547      }
548    }
# Line 568 | Line 552 | serverinfo_ssl_certificate_file: SSL_CER
552   serverinfo_rsa_private_key_file: RSA_PRIVATE_KEY_FILE '=' QSTRING ';'
553   {
554   #ifdef HAVE_LIBCRYPTO
555 <  if (conf_parser_ctx.pass == 1)
555 >  BIO *file = NULL;
556 >
557 >  if (conf_parser_ctx.pass != 1)
558 >    break;
559 >
560 >  if (ServerInfo.rsa_private_key)
561    {
562 <    BIO *file;
562 >    RSA_free(ServerInfo.rsa_private_key);
563 >    ServerInfo.rsa_private_key = NULL;
564 >  }
565  
566 <    if (ServerInfo.rsa_private_key)
567 <    {
568 <      RSA_free(ServerInfo.rsa_private_key);
569 <      ServerInfo.rsa_private_key = NULL;
570 <    }
566 >  if (ServerInfo.rsa_private_key_file)
567 >  {
568 >    MyFree(ServerInfo.rsa_private_key_file);
569 >    ServerInfo.rsa_private_key_file = NULL;
570 >  }
571  
572 <    if (ServerInfo.rsa_private_key_file)
582 <    {
583 <      MyFree(ServerInfo.rsa_private_key_file);
584 <      ServerInfo.rsa_private_key_file = NULL;
585 <    }
572 >  ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
573  
574 <    DupString(ServerInfo.rsa_private_key_file, yylval.string);
574 >  if ((file = BIO_new_file(yylval.string, "r")) == NULL)
575 >  {
576 >    conf_error_report("File open failed, ignoring");
577 >    break;
578 >  }
579  
580 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
590 <    {
591 <      yyerror("File open failed, ignoring");
592 <      break;
593 <    }
580 >  ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
581  
582 <    ServerInfo.rsa_private_key = (RSA *)PEM_read_bio_RSAPrivateKey(file, NULL,
583 <      0, NULL);
582 >  BIO_set_close(file, BIO_CLOSE);
583 >  BIO_free(file);
584  
585 <    BIO_set_close(file, BIO_CLOSE);
586 <    BIO_free(file);
585 >  if (ServerInfo.rsa_private_key == NULL)
586 >  {
587 >    conf_error_report("Couldn't extract key, ignoring");
588 >    break;
589 >  }
590  
591 <    if (ServerInfo.rsa_private_key == NULL)
592 <    {
593 <      yyerror("Couldn't extract key, ignoring");
594 <      break;
605 <    }
591 >  if (!RSA_check_key(ServerInfo.rsa_private_key))
592 >  {
593 >    RSA_free(ServerInfo.rsa_private_key);
594 >    ServerInfo.rsa_private_key = NULL;
595  
596 <    if (!RSA_check_key(ServerInfo.rsa_private_key))
597 <    {
598 <      RSA_free(ServerInfo.rsa_private_key);
610 <      ServerInfo.rsa_private_key = NULL;
596 >    conf_error_report("Invalid key, ignoring");
597 >    break;
598 >  }
599  
600 <      yyerror("Invalid key, ignoring");
601 <      break;
602 <    }
600 >  /* require 2048 bit (256 byte) key */
601 >  if (RSA_size(ServerInfo.rsa_private_key) != 256)
602 >  {
603 >    RSA_free(ServerInfo.rsa_private_key);
604 >    ServerInfo.rsa_private_key = NULL;
605 >
606 >    conf_error_report("Not a 2048 bit key, ignoring");
607 >  }
608 > #endif
609 > };
610 >
611 > serverinfo_ssl_dh_param_file: SSL_DH_PARAM_FILE '=' QSTRING ';'
612 > {
613 > /* TBD - XXX: error reporting */
614 > #ifdef HAVE_LIBCRYPTO
615 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
616 >  {
617 >    BIO *file = BIO_new_file(yylval.string, "r");
618  
619 <    /* require 2048 bit (256 byte) key */
617 <    if (RSA_size(ServerInfo.rsa_private_key) != 256)
619 >    if (file)
620      {
621 <      RSA_free(ServerInfo.rsa_private_key);
622 <      ServerInfo.rsa_private_key = NULL;
621 >      DH *dh = PEM_read_bio_DHparams(file, NULL, NULL, NULL);
622 >
623 >      BIO_free(file);
624 >
625 >      if (dh)
626 >      {
627 >        if (DH_size(dh) < 128)
628 >          conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
629 >        else
630 >          SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
631  
632 <      yyerror("Not a 2048 bit key, ignoring");
632 >        DH_free(dh);
633 >      }
634      }
635    }
636   #endif
637   };
638  
639 + serverinfo_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
640 + {
641 + #ifdef HAVE_LIBCRYPTO
642 +  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
643 +    SSL_CTX_set_cipher_list(ServerInfo.server_ctx, yylval.string);
644 + #endif
645 + };
646 +
647   serverinfo_name: NAME '=' QSTRING ';'
648   {
649    /* this isn't rehashable */
650 <  if (conf_parser_ctx.pass == 2)
650 >  if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
651    {
652 <    if (ServerInfo.name == NULL)
652 >    if (valid_servname(yylval.string))
653 >      ServerInfo.name = xstrdup(yylval.string);
654 >    else
655      {
656 <      /* the ircd will exit() in main() if we dont set one */
657 <      if (strlen(yylval.string) <= HOSTLEN)
637 <        DupString(ServerInfo.name, yylval.string);
656 >      conf_error_report("Ignoring serverinfo::name -- invalid name. Aborting.");
657 >      exit(0);
658      }
659    }
660   };
# Line 645 | Line 665 | serverinfo_sid: IRCD_SID '=' QSTRING ';'
665    if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
666    {
667      if (valid_sid(yylval.string))
668 <      DupString(ServerInfo.sid, yylval.string);
668 >      ServerInfo.sid = xstrdup(yylval.string);
669      else
670      {
671 <      ilog(L_ERROR, "Ignoring config file entry SID -- invalid SID. Aborting.");
671 >      conf_error_report("Ignoring serverinfo::sid -- invalid SID. Aborting.");
672        exit(0);
673      }
674    }
# Line 659 | Line 679 | serverinfo_description: DESCRIPTION '='
679    if (conf_parser_ctx.pass == 2)
680    {
681      MyFree(ServerInfo.description);
682 <    DupString(ServerInfo.description,yylval.string);
682 >    ServerInfo.description = xstrdup(yylval.string);
683    }
684   };
685  
# Line 673 | Line 693 | serverinfo_network_name: NETWORK_NAME '=
693        p = '\0';
694  
695      MyFree(ServerInfo.network_name);
696 <    DupString(ServerInfo.network_name, yylval.string);
696 >    ServerInfo.network_name = xstrdup(yylval.string);
697    }
698   };
699  
700   serverinfo_network_desc: NETWORK_DESC '=' QSTRING ';'
701   {
702 <  if (conf_parser_ctx.pass == 2)
703 <  {
704 <    MyFree(ServerInfo.network_desc);
705 <    DupString(ServerInfo.network_desc, yylval.string);
706 <  }
702 >  if (conf_parser_ctx.pass != 2)
703 >    break;
704 >
705 >  MyFree(ServerInfo.network_desc);
706 >  ServerInfo.network_desc = xstrdup(yylval.string);
707   };
708  
709   serverinfo_vhost: VHOST '=' QSTRING ';'
# Line 698 | Line 718 | serverinfo_vhost: VHOST '=' QSTRING ';'
718      hints.ai_socktype = SOCK_STREAM;
719      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
720  
721 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
722 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
721 >    if (getaddrinfo(yylval.string, NULL, &hints, &res))
722 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
723      else
724      {
725        assert(res != NULL);
# Line 707 | Line 727 | serverinfo_vhost: VHOST '=' QSTRING ';'
727        memcpy(&ServerInfo.ip, res->ai_addr, res->ai_addrlen);
728        ServerInfo.ip.ss.ss_family = res->ai_family;
729        ServerInfo.ip.ss_len = res->ai_addrlen;
730 <      irc_freeaddrinfo(res);
730 >      freeaddrinfo(res);
731  
732        ServerInfo.specific_ipv4_vhost = 1;
733      }
# Line 727 | Line 747 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
747      hints.ai_socktype = SOCK_STREAM;
748      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
749  
750 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
751 <      ilog(L_ERROR, "Invalid netmask for server vhost6(%s)", yylval.string);
750 >    if (getaddrinfo(yylval.string, NULL, &hints, &res))
751 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost6(%s)", yylval.string);
752      else
753      {
754        assert(res != NULL);
# Line 736 | Line 756 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
756        memcpy(&ServerInfo.ip6, res->ai_addr, res->ai_addrlen);
757        ServerInfo.ip6.ss.ss_family = res->ai_family;
758        ServerInfo.ip6.ss_len = res->ai_addrlen;
759 <      irc_freeaddrinfo(res);
759 >      freeaddrinfo(res);
760  
761        ServerInfo.specific_ipv6_vhost = 1;
762      }
# Line 746 | Line 766 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
766  
767   serverinfo_max_clients: T_MAX_CLIENTS '=' NUMBER ';'
768   {
769 <  if (conf_parser_ctx.pass == 2)
769 >  if (conf_parser_ctx.pass != 2)
770 >    break;
771 >
772 >  if ($3 < MAXCLIENTS_MIN)
773    {
774 <    recalc_fdlimit(NULL);
774 >    char buf[IRCD_BUFSIZE];
775  
776 <    if ($3 < MAXCLIENTS_MIN)
777 <    {
778 <      char buf[IRCD_BUFSIZE];
779 <      ircsprintf(buf, "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
780 <      yyerror(buf);
781 <    }
782 <    else if ($3 > MAXCLIENTS_MAX)
783 <    {
784 <      char buf[IRCD_BUFSIZE];
785 <      ircsprintf(buf, "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
786 <      yyerror(buf);
764 <    }
765 <    else
766 <      ServerInfo.max_clients = $3;
776 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
777 >    conf_error_report(buf);
778 >    ServerInfo.max_clients = MAXCLIENTS_MIN;
779 >  }
780 >  else if ($3 > MAXCLIENTS_MAX)
781 >  {
782 >    char buf[IRCD_BUFSIZE];
783 >
784 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
785 >    conf_error_report(buf);
786 >    ServerInfo.max_clients = MAXCLIENTS_MAX;
787    }
788 +  else
789 +    ServerInfo.max_clients = $3;
790   };
791  
792 < serverinfo_hub: HUB '=' TBOOL ';'
792 > serverinfo_max_nick_length: MAX_NICK_LENGTH '=' NUMBER ';'
793   {
794 <  if (conf_parser_ctx.pass == 2)
794 >  if (conf_parser_ctx.pass != 2)
795 >    break;
796 >
797 >  if ($3 < 9)
798    {
799 <    if (yylval.number)
800 <    {
801 <      ServerInfo.hub = 1;
802 <      delete_capability("HUB");
803 <      add_capability("HUB", CAP_HUB, 1);
804 <    }
780 <    else if (ServerInfo.hub)
781 <    {
799 >    conf_error_report("max_nick_length too low, setting to 9");
800 >    ServerInfo.max_nick_length = 9;
801 >  }
802 >  else if ($3 > NICKLEN)
803 >  {
804 >    char buf[IRCD_BUFSIZE];
805  
806 <      ServerInfo.hub = 0;
807 <      delete_capability("HUB");
808 <    }
806 >    snprintf(buf, sizeof(buf), "max_nick_length too high, setting to %d", NICKLEN);
807 >    conf_error_report(buf);
808 >    ServerInfo.max_nick_length = NICKLEN;
809    }
810 +  else
811 +    ServerInfo.max_nick_length = $3;
812 + };
813 +
814 + serverinfo_max_topic_length: MAX_TOPIC_LENGTH '=' NUMBER ';'
815 + {
816 +  if (conf_parser_ctx.pass != 2)
817 +    break;
818 +
819 +  if ($3 < 80)
820 +  {
821 +    conf_error_report("max_topic_length too low, setting to 80");
822 +    ServerInfo.max_topic_length = 80;
823 +  }
824 +  else if ($3 > TOPICLEN)
825 +  {
826 +    char buf[IRCD_BUFSIZE];
827 +
828 +    snprintf(buf, sizeof(buf), "max_topic_length too high, setting to %d", TOPICLEN);
829 +    conf_error_report(buf);
830 +    ServerInfo.max_topic_length = TOPICLEN;
831 +  }
832 +  else
833 +    ServerInfo.max_topic_length = $3;
834 + };
835 +
836 + serverinfo_hub: HUB '=' TBOOL ';'
837 + {
838 +  if (conf_parser_ctx.pass == 2)
839 +    ServerInfo.hub = yylval.number;
840   };
841  
842   /***************************************************************************
# Line 797 | Line 850 | admin_item:  admin_name | admin_descript
850  
851   admin_name: NAME '=' QSTRING ';'
852   {
853 <  if (conf_parser_ctx.pass == 2)
854 <  {
855 <    MyFree(AdminInfo.name);
856 <    DupString(AdminInfo.name, yylval.string);
857 <  }
853 >  if (conf_parser_ctx.pass != 2)
854 >    break;
855 >
856 >  MyFree(AdminInfo.name);
857 >  AdminInfo.name = xstrdup(yylval.string);
858   };
859  
860   admin_email: EMAIL '=' QSTRING ';'
861   {
862 <  if (conf_parser_ctx.pass == 2)
863 <  {
864 <    MyFree(AdminInfo.email);
865 <    DupString(AdminInfo.email, yylval.string);
866 <  }
862 >  if (conf_parser_ctx.pass != 2)
863 >    break;
864 >
865 >  MyFree(AdminInfo.email);
866 >  AdminInfo.email = xstrdup(yylval.string);
867   };
868  
869   admin_description: DESCRIPTION '=' QSTRING ';'
870   {
871 <  if (conf_parser_ctx.pass == 2)
872 <  {
873 <    MyFree(AdminInfo.description);
874 <    DupString(AdminInfo.description, yylval.string);
875 <  }
871 >  if (conf_parser_ctx.pass != 2)
872 >    break;
873 >
874 >  MyFree(AdminInfo.description);
875 >  AdminInfo.description = xstrdup(yylval.string);
876   };
877  
878   /***************************************************************************
879 < *  section logging
879 > * motd section
880   ***************************************************************************/
881 < /* XXX */
882 < logging_entry:          LOGGING  '{' logging_items '}' ';' ;
881 > motd_entry: MOTD
882 > {
883 >  if (conf_parser_ctx.pass == 2)
884 >    reset_block_state();
885 > } '{' motd_items '}' ';'
886 > {
887 >  dlink_node *ptr = NULL;
888  
889 < logging_items:          logging_items logging_item |
890 <                        logging_item ;
889 >  if (conf_parser_ctx.pass != 2)
890 >    break;
891  
892 < logging_item:           logging_path | logging_oper_log |
893 <                        logging_log_level |
836 <                        logging_use_logging | logging_fuserlog |
837 <                        logging_foperlog | logging_fglinelog |
838 <                        logging_fklinelog | logging_killlog |
839 <                        logging_foperspylog | logging_ioerrlog |
840 <                        logging_ffailed_operlog |
841 <                        error ';' ;
892 >  if (!block_state.file.buf[0])
893 >    break;
894  
895 < logging_path:           T_LOGPATH '=' QSTRING ';'
896 <                        {
897 <                        };
895 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
896 >    motd_add(ptr->data, block_state.file.buf);
897 > };
898  
899 < logging_oper_log:       OPER_LOG '=' QSTRING ';'
900 <                        {
849 <                        };
899 > motd_items: motd_items motd_item | motd_item;
900 > motd_item:  motd_mask | motd_file | error ';' ;
901  
902 < logging_fuserlog: FUSERLOG '=' QSTRING ';'
902 > motd_mask: MASK '=' QSTRING ';'
903   {
904    if (conf_parser_ctx.pass == 2)
905 <    strlcpy(ConfigLoggingEntry.userlog, yylval.string,
855 <            sizeof(ConfigLoggingEntry.userlog));
905 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
906   };
907  
908 < logging_ffailed_operlog: FFAILED_OPERLOG '=' QSTRING ';'
908 > motd_file: T_FILE '=' QSTRING ';'
909   {
910    if (conf_parser_ctx.pass == 2)
911 <    strlcpy(ConfigLoggingEntry.failed_operlog, yylval.string,
862 <            sizeof(ConfigLoggingEntry.failed_operlog));
911 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
912   };
913  
914 < logging_foperlog: FOPERLOG '=' QSTRING ';'
915 < {
916 <  if (conf_parser_ctx.pass == 2)
917 <    strlcpy(ConfigLoggingEntry.operlog, yylval.string,
918 <            sizeof(ConfigLoggingEntry.operlog));
870 < };
914 > /***************************************************************************
915 > *  section logging
916 > ***************************************************************************/
917 > logging_entry:          T_LOG  '{' logging_items '}' ';' ;
918 > logging_items:          logging_items logging_item | logging_item ;
919  
920 < logging_foperspylog: FOPERSPYLOG '=' QSTRING ';'
920 > logging_item:           logging_use_logging | logging_file_entry |
921 >                        error ';' ;
922 >
923 > logging_use_logging: USE_LOGGING '=' TBOOL ';'
924   {
925    if (conf_parser_ctx.pass == 2)
926 <    strlcpy(ConfigLoggingEntry.operspylog, yylval.string,
876 <            sizeof(ConfigLoggingEntry.operspylog));
926 >    ConfigLoggingEntry.use_logging = yylval.number;
927   };
928  
929 < logging_fglinelog: FGLINELOG '=' QSTRING ';'
929 > logging_file_entry:
930   {
931    if (conf_parser_ctx.pass == 2)
932 <    strlcpy(ConfigLoggingEntry.glinelog, yylval.string,
933 <            sizeof(ConfigLoggingEntry.glinelog));
932 >    reset_block_state();
933 > } T_FILE  '{' logging_file_items '}' ';'
934 > {
935 >  if (conf_parser_ctx.pass != 2)
936 >    break;
937 >
938 >  if (block_state.type.value && block_state.file.buf[0])
939 >    log_set_file(block_state.type.value, block_state.size.value,
940 >                 block_state.file.buf);
941   };
942  
943 < logging_fklinelog: FKLINELOG '=' QSTRING ';'
943 > logging_file_items: logging_file_items logging_file_item |
944 >                    logging_file_item ;
945 >
946 > logging_file_item:  logging_file_name | logging_file_type |
947 >                    logging_file_size | error ';' ;
948 >
949 > logging_file_name: NAME '=' QSTRING ';'
950   {
951 <  if (conf_parser_ctx.pass == 2)
952 <    strlcpy(ConfigLoggingEntry.klinelog, yylval.string,
953 <            sizeof(ConfigLoggingEntry.klinelog));
954 < };
951 >  if (conf_parser_ctx.pass != 2)
952 >    break;
953 >
954 >  strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
955 > }
956  
957 < logging_ioerrlog: FIOERRLOG '=' QSTRING ';'
957 > logging_file_size: T_SIZE '=' sizespec ';'
958   {
959 <  if (conf_parser_ctx.pass == 2)
960 <    strlcpy(ConfigLoggingEntry.ioerrlog, yylval.string,
961 <            sizeof(ConfigLoggingEntry.ioerrlog));
959 >  block_state.size.value = $3;
960 > } | T_SIZE '=' T_UNLIMITED ';'
961 > {
962 >  block_state.size.value = 0;
963   };
964  
965 < logging_killlog: FKILLLOG '=' QSTRING ';'
965 > logging_file_type: TYPE
966   {
967    if (conf_parser_ctx.pass == 2)
968 <    strlcpy(ConfigLoggingEntry.killlog, yylval.string,
969 <            sizeof(ConfigLoggingEntry.killlog));
905 < };
968 >    block_state.type.value = 0;
969 > } '='  logging_file_type_items ';' ;
970  
971 < logging_log_level: LOG_LEVEL '=' T_L_CRIT ';'
972 < {
909 <  if (conf_parser_ctx.pass == 2)
910 <    set_log_level(L_CRIT);
911 < } | LOG_LEVEL '=' T_L_ERROR ';'
971 > logging_file_type_items: logging_file_type_items ',' logging_file_type_item | logging_file_type_item;
972 > logging_file_type_item:  USER
973   {
974    if (conf_parser_ctx.pass == 2)
975 <    set_log_level(L_ERROR);
976 < } | LOG_LEVEL '=' T_L_WARN ';'
975 >    block_state.type.value = LOG_TYPE_USER;
976 > } | OPERATOR
977   {
978    if (conf_parser_ctx.pass == 2)
979 <    set_log_level(L_WARN);
980 < } | LOG_LEVEL '=' T_L_NOTICE ';'
979 >    block_state.type.value = LOG_TYPE_OPER;
980 > } | GLINE
981   {
982    if (conf_parser_ctx.pass == 2)
983 <    set_log_level(L_NOTICE);
984 < } | LOG_LEVEL '=' T_L_TRACE ';'
983 >    block_state.type.value = LOG_TYPE_GLINE;
984 > } | T_DLINE
985   {
986    if (conf_parser_ctx.pass == 2)
987 <    set_log_level(L_TRACE);
988 < } | LOG_LEVEL '=' T_L_INFO ';'
987 >    block_state.type.value = LOG_TYPE_DLINE;
988 > } | KLINE
989   {
990    if (conf_parser_ctx.pass == 2)
991 <    set_log_level(L_INFO);
992 < } | LOG_LEVEL '=' T_L_DEBUG ';'
991 >    block_state.type.value = LOG_TYPE_KLINE;
992 > } | KILL
993   {
994    if (conf_parser_ctx.pass == 2)
995 <    set_log_level(L_DEBUG);
996 < };
936 <
937 < logging_use_logging: USE_LOGGING '=' TBOOL ';'
995 >    block_state.type.value = LOG_TYPE_KILL;
996 > } | T_DEBUG
997   {
998    if (conf_parser_ctx.pass == 2)
999 <    ConfigLoggingEntry.use_logging = yylval.number;
999 >    block_state.type.value = LOG_TYPE_DEBUG;
1000   };
1001  
1002 +
1003   /***************************************************************************
1004   * section oper
1005   ***************************************************************************/
1006   oper_entry: OPERATOR
1007   {
1008 <  if (conf_parser_ctx.pass == 2)
1009 <  {
1010 <    yy_conf = make_conf_item(OPER_TYPE);
1011 <    yy_aconf = map_to_conf(yy_conf);
1012 <    SetConfEncrypted(yy_aconf); /* Yes, the default is encrypted */
1013 <  }
954 <  else
955 <  {
956 <    MyFree(class_name);
957 <    class_name = NULL;
958 <  }
959 < } oper_name_b '{' oper_items '}' ';'
1008 >  if (conf_parser_ctx.pass != 2)
1009 >    break;
1010 >
1011 >  reset_block_state();
1012 >  block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1013 > } '{' oper_items '}' ';'
1014   {
1015 <  if (conf_parser_ctx.pass == 2)
962 <  {
963 <    struct CollectItem *yy_tmp;
964 <    dlink_node *ptr;
965 <    dlink_node *next_ptr;
1015 >  dlink_node *ptr = NULL;
1016  
1017 <    conf_add_class_to_conf(yy_conf, class_name);
1017 >  if (conf_parser_ctx.pass != 2)
1018 >    break;
1019  
1020 <    /* Now, make sure there is a copy of the "base" given oper
1021 <     * block in each of the collected copies
1022 <     */
1020 >  if (!block_state.name.buf[0])
1021 >    break;
1022 > #ifdef HAVE_LIBCRYPTO
1023 >  if (!block_state.file.buf[0] &&
1024 >      !block_state.rpass.buf[0])
1025 >    break;
1026 > #else
1027 >  if (!block_state.rpass.buf[0])
1028 >    break;
1029 > #endif
1030  
1031 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1032 <    {
1033 <      struct AccessItem *new_aconf;
1034 <      struct ConfItem *new_conf;
977 <      yy_tmp = ptr->data;
978 <
979 <      new_conf = make_conf_item(OPER_TYPE);
980 <      new_aconf = (struct AccessItem *)map_to_conf(new_conf);
981 <
982 <      new_aconf->flags = yy_aconf->flags;
983 <
984 <      if (yy_conf->name != NULL)
985 <        DupString(new_conf->name, yy_conf->name);
986 <      if (yy_tmp->user != NULL)
987 <        DupString(new_aconf->user, yy_tmp->user);
988 <      else
989 <        DupString(new_aconf->user, "*");
990 <      if (yy_tmp->host != NULL)
991 <        DupString(new_aconf->host, yy_tmp->host);
992 <      else
993 <        DupString(new_aconf->host, "*");
994 <      conf_add_class_to_conf(new_conf, class_name);
995 <      if (yy_aconf->passwd != NULL)
996 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1031 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1032 >  {
1033 >    struct MaskItem *conf = NULL;
1034 >    struct split_nuh_item nuh;
1035  
1036 <      new_aconf->port = yy_aconf->port;
1037 < #ifdef HAVE_LIBCRYPTO
1038 <      if (yy_aconf->rsa_public_key_file != NULL)
1039 <      {
1040 <        BIO *file;
1036 >    nuh.nuhmask  = ptr->data;
1037 >    nuh.nickptr  = NULL;
1038 >    nuh.userptr  = block_state.user.buf;
1039 >    nuh.hostptr  = block_state.host.buf;
1040 >    nuh.nicksize = 0;
1041 >    nuh.usersize = sizeof(block_state.user.buf);
1042 >    nuh.hostsize = sizeof(block_state.host.buf);
1043 >    split_nuh(&nuh);
1044  
1045 <        DupString(new_aconf->rsa_public_key_file,
1046 <                  yy_aconf->rsa_public_key_file);
1045 >    conf         = conf_make(CONF_OPER);
1046 >    conf->name   = xstrdup(block_state.name.buf);
1047 >    conf->user   = xstrdup(block_state.user.buf);
1048 >    conf->host   = xstrdup(block_state.host.buf);
1049 >
1050 >    if (block_state.cert.buf[0])
1051 >      conf->certfp = xstrdup(block_state.cert.buf);
1052 >
1053 >    if (block_state.rpass.buf[0])
1054 >      conf->passwd = xstrdup(block_state.rpass.buf);
1055 >
1056 >    conf->flags = block_state.flags.value;
1057 >    conf->modes = block_state.modes.value;
1058 >    conf->port  = block_state.port.value;
1059 >    conf->htype = parse_netmask(conf->host, &conf->addr, &conf->bits);
1060  
1061 <        file = BIO_new_file(yy_aconf->rsa_public_key_file, "r");
1008 <        new_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file,
1009 <                                                           NULL, 0, NULL);
1010 <        BIO_set_close(file, BIO_CLOSE);
1011 <        BIO_free(file);
1012 <      }
1013 < #endif
1061 >    conf_add_class_to_conf(conf, block_state.class.buf);
1062  
1063   #ifdef HAVE_LIBCRYPTO
1064 <      if (yy_tmp->name && (yy_tmp->passwd || yy_aconf->rsa_public_key)
1065 <          && yy_tmp->host)
1066 < #else
1067 <      if (yy_tmp->name && yy_tmp->passwd && yy_tmp->host)
1068 < #endif
1064 >    if (block_state.file.buf[0])
1065 >    {
1066 >      BIO *file = NULL;
1067 >      RSA *pkey = NULL;
1068 >
1069 >      if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
1070        {
1071 <        conf_add_class_to_conf(new_conf, class_name);
1072 <        if (yy_tmp->name != NULL)
1024 <          DupString(new_conf->name, yy_tmp->name);
1071 >        conf_error_report("Ignoring rsa_public_key_file -- file doesn't exist");
1072 >        break;
1073        }
1074  
1075 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1076 <      free_collect_item(yy_tmp);
1029 <    }
1030 <
1031 <    yy_conf = NULL;
1032 <    yy_aconf = NULL;
1033 <
1075 >      if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
1076 >        conf_error_report("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1077  
1078 <    MyFree(class_name);
1079 <    class_name = NULL;
1078 >      conf->rsa_public_key = pkey;
1079 >      BIO_set_close(file, BIO_CLOSE);
1080 >      BIO_free(file);
1081 >    }
1082 > #endif /* HAVE_LIBCRYPTO */
1083    }
1084 < };
1084 > };
1085  
1040 oper_name_b: | oper_name_t;
1086   oper_items:     oper_items oper_item | oper_item;
1087 < oper_item:      oper_name | oper_user | oper_password | oper_hidden_admin |
1088 <                oper_hidden_oper | oper_umodes |
1089 <                oper_class | oper_global_kill | oper_remote |
1090 <                oper_kline | oper_xline | oper_unkline |
1046 <                oper_gline | oper_nick_changes | oper_remoteban |
1047 <                oper_die | oper_rehash | oper_admin | oper_operwall |
1048 <                oper_encrypted | oper_rsa_public_key_file |
1049 <                oper_flags | error ';' ;
1087 > oper_item:      oper_name | oper_user | oper_password |
1088 >                oper_umodes | oper_class | oper_encrypted |
1089 >                oper_rsa_public_key_file | oper_ssl_certificate_fingerprint |
1090 >                oper_flags | error ';' ;
1091  
1092   oper_name: NAME '=' QSTRING ';'
1093   {
1094    if (conf_parser_ctx.pass == 2)
1095 <  {
1055 <    if (strlen(yylval.string) > OPERNICKLEN)
1056 <      yylval.string[OPERNICKLEN] = '\0';
1057 <
1058 <    MyFree(yy_conf->name);
1059 <    DupString(yy_conf->name, yylval.string);
1060 <  }
1061 < };
1062 <
1063 < oper_name_t: QSTRING
1064 < {
1065 <  if (conf_parser_ctx.pass == 2)
1066 <  {
1067 <    if (strlen(yylval.string) > OPERNICKLEN)
1068 <      yylval.string[OPERNICKLEN] = '\0';
1069 <
1070 <    MyFree(yy_conf->name);
1071 <    DupString(yy_conf->name, yylval.string);
1072 <  }
1095 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1096   };
1097  
1098   oper_user: USER '=' QSTRING ';'
1099   {
1100    if (conf_parser_ctx.pass == 2)
1101 <  {
1079 <    struct split_nuh_item nuh;
1080 <
1081 <    nuh.nuhmask  = yylval.string;
1082 <    nuh.nickptr  = NULL;
1083 <    nuh.userptr  = userbuf;
1084 <    nuh.hostptr  = hostbuf;
1085 <
1086 <    nuh.nicksize = 0;
1087 <    nuh.usersize = sizeof(userbuf);
1088 <    nuh.hostsize = sizeof(hostbuf);
1089 <
1090 <    split_nuh(&nuh);
1091 <
1092 <    if (yy_aconf->user == NULL)
1093 <    {
1094 <      DupString(yy_aconf->user, userbuf);
1095 <      DupString(yy_aconf->host, hostbuf);
1096 <    }
1097 <    else
1098 <    {
1099 <      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
1100 <
1101 <      DupString(yy_tmp->user, userbuf);
1102 <      DupString(yy_tmp->host, hostbuf);
1103 <
1104 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1105 <    }
1106 <  }
1101 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1102   };
1103  
1104   oper_password: PASSWORD '=' QSTRING ';'
1105   {
1106    if (conf_parser_ctx.pass == 2)
1107 <  {
1113 <    if (yy_aconf->passwd != NULL)
1114 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1115 <
1116 <    MyFree(yy_aconf->passwd);
1117 <    DupString(yy_aconf->passwd, yylval.string);
1118 <  }
1107 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1108   };
1109  
1110   oper_encrypted: ENCRYPTED '=' TBOOL ';'
1111   {
1112 <  if (conf_parser_ctx.pass == 2)
1113 <  {
1114 <    if (yylval.number)
1115 <      SetConfEncrypted(yy_aconf);
1116 <    else
1117 <      ClearConfEncrypted(yy_aconf);
1118 <  }
1112 >  if (conf_parser_ctx.pass != 2)
1113 >    break;
1114 >
1115 >  if (yylval.number)
1116 >    block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1117 >  else
1118 >    block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1119   };
1120  
1121   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
1122   {
1134 #ifdef HAVE_LIBCRYPTO
1123    if (conf_parser_ctx.pass == 2)
1124 <  {
1125 <    BIO *file;
1138 <
1139 <    if (yy_aconf->rsa_public_key != NULL)
1140 <    {
1141 <      RSA_free(yy_aconf->rsa_public_key);
1142 <      yy_aconf->rsa_public_key = NULL;
1143 <    }
1144 <
1145 <    if (yy_aconf->rsa_public_key_file != NULL)
1146 <    {
1147 <      MyFree(yy_aconf->rsa_public_key_file);
1148 <      yy_aconf->rsa_public_key_file = NULL;
1149 <    }
1150 <
1151 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
1152 <    file = BIO_new_file(yylval.string, "r");
1153 <
1154 <    if (file == NULL)
1155 <    {
1156 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
1157 <      break;
1158 <    }
1159 <
1160 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
1161 <
1162 <    if (yy_aconf->rsa_public_key == NULL)
1163 <    {
1164 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1165 <      break;
1166 <    }
1124 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1125 > };
1126  
1127 <    BIO_set_close(file, BIO_CLOSE);
1128 <    BIO_free(file);
1129 <  }
1130 < #endif /* HAVE_LIBCRYPTO */
1127 > oper_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
1128 > {
1129 >  if (conf_parser_ctx.pass == 2)
1130 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
1131   };
1132  
1133   oper_class: CLASS '=' QSTRING ';'
1134   {
1135    if (conf_parser_ctx.pass == 2)
1136 <  {
1178 <    MyFree(class_name);
1179 <    DupString(class_name, yylval.string);
1180 <  }
1136 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1137   };
1138  
1139   oper_umodes: T_UMODES
1140   {
1141    if (conf_parser_ctx.pass == 2)
1142 <    yy_aconf->modes = 0;
1142 >    block_state.modes.value = 0;
1143   } '='  oper_umodes_items ';' ;
1144  
1145   oper_umodes_items: oper_umodes_items ',' oper_umodes_item | oper_umodes_item;
1146   oper_umodes_item:  T_BOTS
1147   {
1148    if (conf_parser_ctx.pass == 2)
1149 <    yy_aconf->modes |= UMODE_BOTS;
1149 >    block_state.modes.value |= UMODE_BOTS;
1150   } | T_CCONN
1151   {
1152    if (conf_parser_ctx.pass == 2)
1153 <    yy_aconf->modes |= UMODE_CCONN;
1198 < } | T_CCONN_FULL
1199 < {
1200 <  if (conf_parser_ctx.pass == 2)
1201 <    yy_aconf->modes |= UMODE_CCONN_FULL;
1153 >    block_state.modes.value |= UMODE_CCONN;
1154   } | T_DEAF
1155   {
1156    if (conf_parser_ctx.pass == 2)
1157 <    yy_aconf->modes |= UMODE_DEAF;
1157 >    block_state.modes.value |= UMODE_DEAF;
1158   } | T_DEBUG
1159   {
1160    if (conf_parser_ctx.pass == 2)
1161 <    yy_aconf->modes |= UMODE_DEBUG;
1161 >    block_state.modes.value |= UMODE_DEBUG;
1162   } | T_FULL
1163   {
1164    if (conf_parser_ctx.pass == 2)
1165 <    yy_aconf->modes |= UMODE_FULL;
1165 >    block_state.modes.value |= UMODE_FULL;
1166 > } | HIDDEN
1167 > {
1168 >  if (conf_parser_ctx.pass == 2)
1169 >    block_state.modes.value |= UMODE_HIDDEN;
1170   } | T_SKILL
1171   {
1172    if (conf_parser_ctx.pass == 2)
1173 <    yy_aconf->modes |= UMODE_SKILL;
1173 >    block_state.modes.value |= UMODE_SKILL;
1174   } | T_NCHANGE
1175   {
1176    if (conf_parser_ctx.pass == 2)
1177 <    yy_aconf->modes |= UMODE_NCHANGE;
1177 >    block_state.modes.value |= UMODE_NCHANGE;
1178   } | T_REJ
1179   {
1180    if (conf_parser_ctx.pass == 2)
1181 <    yy_aconf->modes |= UMODE_REJ;
1181 >    block_state.modes.value |= UMODE_REJ;
1182   } | T_UNAUTH
1183   {
1184    if (conf_parser_ctx.pass == 2)
1185 <    yy_aconf->modes |= UMODE_UNAUTH;
1185 >    block_state.modes.value |= UMODE_UNAUTH;
1186   } | T_SPY
1187   {
1188    if (conf_parser_ctx.pass == 2)
1189 <    yy_aconf->modes |= UMODE_SPY;
1189 >    block_state.modes.value |= UMODE_SPY;
1190   } | T_EXTERNAL
1191   {
1192    if (conf_parser_ctx.pass == 2)
1193 <    yy_aconf->modes |= UMODE_EXTERNAL;
1193 >    block_state.modes.value |= UMODE_EXTERNAL;
1194   } | T_OPERWALL
1195   {
1196    if (conf_parser_ctx.pass == 2)
1197 <    yy_aconf->modes |= UMODE_OPERWALL;
1197 >    block_state.modes.value |= UMODE_OPERWALL;
1198   } | T_SERVNOTICE
1199   {
1200    if (conf_parser_ctx.pass == 2)
1201 <    yy_aconf->modes |= UMODE_SERVNOTICE;
1201 >    block_state.modes.value |= UMODE_SERVNOTICE;
1202   } | T_INVISIBLE
1203   {
1204    if (conf_parser_ctx.pass == 2)
1205 <    yy_aconf->modes |= UMODE_INVISIBLE;
1205 >    block_state.modes.value |= UMODE_INVISIBLE;
1206   } | T_WALLOP
1207   {
1208    if (conf_parser_ctx.pass == 2)
1209 <    yy_aconf->modes |= UMODE_WALLOP;
1209 >    block_state.modes.value |= UMODE_WALLOP;
1210   } | T_SOFTCALLERID
1211   {
1212    if (conf_parser_ctx.pass == 2)
1213 <    yy_aconf->modes |= UMODE_SOFTCALLERID;
1213 >    block_state.modes.value |= UMODE_SOFTCALLERID;
1214   } | T_CALLERID
1215   {
1216    if (conf_parser_ctx.pass == 2)
1217 <    yy_aconf->modes |= UMODE_CALLERID;
1217 >    block_state.modes.value |= UMODE_CALLERID;
1218   } | T_LOCOPS
1219   {
1220    if (conf_parser_ctx.pass == 2)
1221 <    yy_aconf->modes |= UMODE_LOCOPS;
1222 < };
1267 <
1268 < oper_global_kill: GLOBAL_KILL '=' TBOOL ';'
1269 < {
1270 <  if (conf_parser_ctx.pass == 2)
1271 <  {
1272 <    if (yylval.number)
1273 <      yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1274 <    else
1275 <      yy_aconf->port &= ~OPER_FLAG_GLOBAL_KILL;
1276 <  }
1277 < };
1278 <
1279 < oper_remote: REMOTE '=' TBOOL ';'
1280 < {
1281 <  if (conf_parser_ctx.pass == 2)
1282 <  {
1283 <    if (yylval.number)
1284 <      yy_aconf->port |= OPER_FLAG_REMOTE;
1285 <    else
1286 <      yy_aconf->port &= ~OPER_FLAG_REMOTE;
1287 <  }
1288 < };
1289 <
1290 < oper_remoteban: REMOTEBAN '=' TBOOL ';'
1291 < {
1292 <  if (conf_parser_ctx.pass == 2)
1293 <  {
1294 <    if (yylval.number)
1295 <      yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1296 <    else
1297 <      yy_aconf->port &= ~OPER_FLAG_REMOTEBAN;
1298 <  }
1299 < };
1300 <
1301 < oper_kline: KLINE '=' TBOOL ';'
1302 < {
1303 <  if (conf_parser_ctx.pass == 2)
1304 <  {
1305 <    if (yylval.number)
1306 <      yy_aconf->port |= OPER_FLAG_K;
1307 <    else
1308 <      yy_aconf->port &= ~OPER_FLAG_K;
1309 <  }
1310 < };
1311 <
1312 < oper_xline: XLINE '=' TBOOL ';'
1313 < {
1314 <  if (conf_parser_ctx.pass == 2)
1315 <  {
1316 <    if (yylval.number)
1317 <      yy_aconf->port |= OPER_FLAG_X;
1318 <    else
1319 <      yy_aconf->port &= ~OPER_FLAG_X;
1320 <  }
1321 < };
1322 <
1323 < oper_unkline: UNKLINE '=' TBOOL ';'
1221 >    block_state.modes.value |= UMODE_LOCOPS;
1222 > } | T_NONONREG
1223   {
1224    if (conf_parser_ctx.pass == 2)
1225 <  {
1226 <    if (yylval.number)
1328 <      yy_aconf->port |= OPER_FLAG_UNKLINE;
1329 <    else
1330 <      yy_aconf->port &= ~OPER_FLAG_UNKLINE;
1331 <  }
1332 < };
1333 <
1334 < oper_gline: GLINE '=' TBOOL ';'
1225 >    block_state.modes.value |= UMODE_REGONLY;
1226 > } | T_FARCONNECT
1227   {
1228    if (conf_parser_ctx.pass == 2)
1229 <  {
1338 <    if (yylval.number)
1339 <      yy_aconf->port |= OPER_FLAG_GLINE;
1340 <    else
1341 <      yy_aconf->port &= ~OPER_FLAG_GLINE;
1342 <  }
1229 >    block_state.modes.value |= UMODE_FARCONNECT;
1230   };
1231  
1232 < oper_nick_changes: NICK_CHANGES '=' TBOOL ';'
1232 > oper_flags: IRCD_FLAGS
1233   {
1234    if (conf_parser_ctx.pass == 2)
1235 <  {
1236 <    if (yylval.number)
1350 <      yy_aconf->port |= OPER_FLAG_N;
1351 <    else
1352 <      yy_aconf->port &= ~OPER_FLAG_N;
1353 <  }
1354 < };
1235 >    block_state.port.value = 0;
1236 > } '='  oper_flags_items ';';
1237  
1238 < oper_die: DIE '=' TBOOL ';'
1238 > oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1239 > oper_flags_item: KILL ':' REMOTE
1240   {
1241    if (conf_parser_ctx.pass == 2)
1242 <  {
1243 <    if (yylval.number)
1361 <      yy_aconf->port |= OPER_FLAG_DIE;
1362 <    else
1363 <      yy_aconf->port &= ~OPER_FLAG_DIE;
1364 <  }
1365 < };
1366 <
1367 < oper_rehash: REHASH '=' TBOOL ';'
1242 >    block_state.port.value |= OPER_FLAG_KILL_REMOTE;
1243 > } | KILL
1244   {
1245    if (conf_parser_ctx.pass == 2)
1246 <  {
1247 <    if (yylval.number)
1372 <      yy_aconf->port |= OPER_FLAG_REHASH;
1373 <    else
1374 <      yy_aconf->port &= ~OPER_FLAG_REHASH;
1375 <  }
1376 < };
1377 <
1378 < oper_admin: ADMIN '=' TBOOL ';'
1246 >    block_state.port.value |= OPER_FLAG_KILL;
1247 > } | CONNECT ':' REMOTE
1248   {
1249    if (conf_parser_ctx.pass == 2)
1250 <  {
1251 <    if (yylval.number)
1383 <      yy_aconf->port |= OPER_FLAG_ADMIN;
1384 <    else
1385 <      yy_aconf->port &= ~OPER_FLAG_ADMIN;
1386 <  }
1387 < };
1388 <
1389 < oper_hidden_admin: HIDDEN_ADMIN '=' TBOOL ';'
1250 >    block_state.port.value |= OPER_FLAG_CONNECT_REMOTE;
1251 > } | CONNECT
1252   {
1253    if (conf_parser_ctx.pass == 2)
1254 <  {
1255 <    if (yylval.number)
1394 <      yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1395 <    else
1396 <      yy_aconf->port &= ~OPER_FLAG_HIDDEN_ADMIN;
1397 <  }
1398 < };
1399 <
1400 < oper_hidden_oper: HIDDEN_OPER '=' TBOOL ';'
1254 >    block_state.port.value |= OPER_FLAG_CONNECT;
1255 > } | SQUIT ':' REMOTE
1256   {
1257    if (conf_parser_ctx.pass == 2)
1258 <  {
1259 <    if (yylval.number)
1405 <      yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1406 <    else
1407 <      yy_aconf->port &= ~OPER_FLAG_HIDDEN_OPER;
1408 <  }
1409 < };
1410 <
1411 < oper_operwall: T_OPERWALL '=' TBOOL ';'
1258 >    block_state.port.value |= OPER_FLAG_SQUIT_REMOTE;
1259 > } | SQUIT
1260   {
1261    if (conf_parser_ctx.pass == 2)
1262 <  {
1263 <    if (yylval.number)
1416 <      yy_aconf->port |= OPER_FLAG_OPERWALL;
1417 <    else
1418 <      yy_aconf->port &= ~OPER_FLAG_OPERWALL;
1419 <  }
1420 < };
1421 <
1422 < oper_flags: IRCD_FLAGS
1423 < {
1424 < } '='  oper_flags_items ';';
1425 <
1426 < oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1427 < oper_flags_item: NOT { not_atom = 1; } oper_flags_item_atom
1428 <                | { not_atom = 0; } oper_flags_item_atom;
1429 <
1430 < oper_flags_item_atom: GLOBAL_KILL
1262 >    block_state.port.value |= OPER_FLAG_SQUIT;
1263 > } | KLINE
1264   {
1265    if (conf_parser_ctx.pass == 2)
1266 <  {
1267 <    if (not_atom)yy_aconf->port &= ~OPER_FLAG_GLOBAL_KILL;
1435 <    else yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1436 <  }
1437 < } | REMOTE
1266 >    block_state.port.value |= OPER_FLAG_K;
1267 > } | UNKLINE
1268   {
1269    if (conf_parser_ctx.pass == 2)
1270 <  {
1271 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTE;
1442 <    else yy_aconf->port |= OPER_FLAG_REMOTE;
1443 <  }
1444 < } | KLINE
1270 >    block_state.port.value |= OPER_FLAG_UNKLINE;
1271 > } | T_DLINE
1272   {
1273    if (conf_parser_ctx.pass == 2)
1274 <  {
1275 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_K;
1449 <    else yy_aconf->port |= OPER_FLAG_K;
1450 <  }
1451 < } | UNKLINE
1274 >    block_state.port.value |= OPER_FLAG_DLINE;
1275 > } | T_UNDLINE
1276   {
1277    if (conf_parser_ctx.pass == 2)
1278 <  {
1455 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_UNKLINE;
1456 <    else yy_aconf->port |= OPER_FLAG_UNKLINE;
1457 <  }
1278 >    block_state.port.value |= OPER_FLAG_UNDLINE;
1279   } | XLINE
1280   {
1281    if (conf_parser_ctx.pass == 2)
1282 <  {
1462 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_X;
1463 <    else yy_aconf->port |= OPER_FLAG_X;
1464 <  }
1282 >    block_state.port.value |= OPER_FLAG_X;
1283   } | GLINE
1284   {
1285    if (conf_parser_ctx.pass == 2)
1286 <  {
1469 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_GLINE;
1470 <    else yy_aconf->port |= OPER_FLAG_GLINE;
1471 <  }
1286 >    block_state.port.value |= OPER_FLAG_GLINE;
1287   } | DIE
1288   {
1289    if (conf_parser_ctx.pass == 2)
1290 <  {
1291 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_DIE;
1292 <    else yy_aconf->port |= OPER_FLAG_DIE;
1293 <  }
1290 >    block_state.port.value |= OPER_FLAG_DIE;
1291 > } | T_RESTART
1292 > {
1293 >  if (conf_parser_ctx.pass == 2)
1294 >    block_state.port.value |= OPER_FLAG_RESTART;
1295   } | REHASH
1296   {
1297    if (conf_parser_ctx.pass == 2)
1298 <  {
1483 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REHASH;
1484 <    else yy_aconf->port |= OPER_FLAG_REHASH;
1485 <  }
1298 >    block_state.port.value |= OPER_FLAG_REHASH;
1299   } | ADMIN
1300   {
1301    if (conf_parser_ctx.pass == 2)
1302 <  {
1303 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_ADMIN;
1491 <    else yy_aconf->port |= OPER_FLAG_ADMIN;
1492 <  }
1493 < } | HIDDEN_ADMIN
1302 >    block_state.port.value |= OPER_FLAG_ADMIN;
1303 > } | T_OPERWALL
1304   {
1305    if (conf_parser_ctx.pass == 2)
1306 <  {
1307 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_ADMIN;
1498 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1499 <  }
1500 < } | NICK_CHANGES
1306 >    block_state.port.value |= OPER_FLAG_OPERWALL;
1307 > } | T_GLOBOPS
1308   {
1309    if (conf_parser_ctx.pass == 2)
1310 <  {
1311 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_N;
1505 <    else yy_aconf->port |= OPER_FLAG_N;
1506 <  }
1507 < } | T_OPERWALL
1310 >    block_state.port.value |= OPER_FLAG_GLOBOPS;
1311 > } | T_WALLOPS
1312   {
1313    if (conf_parser_ctx.pass == 2)
1314 <  {
1315 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPERWALL;
1512 <    else yy_aconf->port |= OPER_FLAG_OPERWALL;
1513 <  }
1514 < } | OPER_SPY_T
1314 >    block_state.port.value |= OPER_FLAG_WALLOPS;
1315 > } | T_LOCOPS
1316   {
1317    if (conf_parser_ctx.pass == 2)
1318 <  {
1319 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPER_SPY;
1519 <    else yy_aconf->port |= OPER_FLAG_OPER_SPY;
1520 <  }
1521 < } | HIDDEN_OPER
1318 >    block_state.port.value |= OPER_FLAG_LOCOPS;
1319 > } | REMOTEBAN
1320   {
1321    if (conf_parser_ctx.pass == 2)
1322 <  {
1323 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_OPER;
1526 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1527 <  }
1528 < } | REMOTEBAN
1322 >    block_state.port.value |= OPER_FLAG_REMOTEBAN;
1323 > } | T_SET
1324   {
1325    if (conf_parser_ctx.pass == 2)
1326 <  {
1327 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTEBAN;
1533 <    else yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1534 <  }
1535 < } | ENCRYPTED
1326 >    block_state.port.value |= OPER_FLAG_SET;
1327 > } | MODULE
1328   {
1329    if (conf_parser_ctx.pass == 2)
1330 <  {
1539 <    if (not_atom) ClearConfEncrypted(yy_aconf);
1540 <    else SetConfEncrypted(yy_aconf);
1541 <  }
1330 >    block_state.port.value |= OPER_FLAG_MODULE;
1331   };
1332  
1333  
# Line 1547 | Line 1336 | oper_flags_item_atom: GLOBAL_KILL
1336   ***************************************************************************/
1337   class_entry: CLASS
1338   {
1339 <  if (conf_parser_ctx.pass == 1)
1340 <  {
1552 <    yy_conf = make_conf_item(CLASS_TYPE);
1553 <    yy_class = map_to_conf(yy_conf);
1554 <  }
1555 < } class_name_b '{' class_items '}' ';'
1556 < {
1557 <  if (conf_parser_ctx.pass == 1)
1558 <  {
1559 <    struct ConfItem *cconf = NULL;
1560 <    struct ClassItem *class = NULL;
1561 <
1562 <    if (yy_class_name == NULL)
1563 <      delete_conf_item(yy_conf);
1564 <    else
1565 <    {
1566 <      cconf = find_exact_name_conf(CLASS_TYPE, yy_class_name, NULL, NULL);
1567 <
1568 <      if (cconf != NULL)                /* The class existed already */
1569 <      {
1570 <        int user_count = 0;
1571 <
1572 <        rebuild_cidr_class(cconf, yy_class);
1573 <
1574 <        class = map_to_conf(cconf);
1575 <
1576 <        user_count = class->curr_user_count;
1577 <        memcpy(class, yy_class, sizeof(*class));
1578 <        class->curr_user_count = user_count;
1579 <        class->active = 1;
1339 >  if (conf_parser_ctx.pass != 1)
1340 >    break;
1341  
1342 <        delete_conf_item(yy_conf);
1342 >  reset_block_state();
1343  
1344 <        MyFree(cconf->name);            /* Allows case change of class name */
1345 <        cconf->name = yy_class_name;
1346 <      }
1347 <      else      /* Brand new class */
1348 <      {
1349 <        MyFree(yy_conf->name);          /* just in case it was allocated */
1350 <        yy_conf->name = yy_class_name;
1351 <        yy_class->active = 1;
1352 <      }
1353 <    }
1354 <
1355 <    yy_class_name = NULL;
1356 <  }
1344 >  block_state.ping_freq.value = DEFAULT_PINGFREQUENCY;
1345 >  block_state.con_freq.value  = DEFAULT_CONNECTFREQUENCY;
1346 >  block_state.max_total.value = MAXIMUM_LINKS_DEFAULT;
1347 >  block_state.max_sendq.value = DEFAULT_SENDQ;
1348 >  block_state.max_recvq.value = DEFAULT_RECVQ;
1349 > } '{' class_items '}' ';'
1350 > {
1351 >  struct ClassItem *class = NULL;
1352 >
1353 >  if (conf_parser_ctx.pass != 1)
1354 >    break;
1355 >
1356 >  if (!block_state.class.buf[0])
1357 >    break;
1358 >
1359 >  if (!(class = class_find(block_state.class.buf, 0)))
1360 >    class = class_make();
1361 >
1362 >  class->active = 1;
1363 >  MyFree(class->name);
1364 >  class->name = xstrdup(block_state.class.buf);
1365 >  class->ping_freq = block_state.ping_freq.value;
1366 >  class->max_perip = block_state.max_perip.value;
1367 >  class->con_freq = block_state.con_freq.value;
1368 >  class->max_total = block_state.max_total.value;
1369 >  class->max_global = block_state.max_global.value;
1370 >  class->max_local = block_state.max_local.value;
1371 >  class->max_ident = block_state.max_ident.value;
1372 >  class->max_sendq = block_state.max_sendq.value;
1373 >  class->max_recvq = block_state.max_recvq.value;
1374 >
1375 >  if (block_state.min_idle.value > block_state.max_idle.value)
1376 >  {
1377 >    block_state.min_idle.value = 0;
1378 >    block_state.max_idle.value = 0;
1379 >    block_state.flags.value &= ~CLASS_FLAGS_FAKE_IDLE;
1380 >  }
1381 >
1382 >  class->flags = block_state.flags.value;
1383 >  class->min_idle = block_state.min_idle.value;
1384 >  class->max_idle = block_state.max_idle.value;
1385 >
1386 >  if (class->number_per_cidr && block_state.number_per_cidr.value)
1387 >    if ((class->cidr_bitlen_ipv4 && block_state.cidr_bitlen_ipv4.value) ||
1388 >        (class->cidr_bitlen_ipv6 && block_state.cidr_bitlen_ipv6.value))
1389 >      if ((class->cidr_bitlen_ipv4 != block_state.cidr_bitlen_ipv4.value) ||
1390 >          (class->cidr_bitlen_ipv6 != block_state.cidr_bitlen_ipv6.value))
1391 >        rebuild_cidr_list(class);
1392 >
1393 >  class->cidr_bitlen_ipv4 = block_state.cidr_bitlen_ipv4.value;
1394 >  class->cidr_bitlen_ipv6 = block_state.cidr_bitlen_ipv6.value;
1395 >  class->number_per_cidr = block_state.number_per_cidr.value;
1396   };
1397  
1598 class_name_b: | class_name_t;
1599
1398   class_items:    class_items class_item | class_item;
1399   class_item:     class_name |
1400                  class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1401                  class_ping_time |
1604                class_ping_warning |
1402                  class_number_per_cidr |
1403                  class_number_per_ip |
1404                  class_connectfreq |
# Line 1609 | Line 1406 | class_item:     class_name |
1406                  class_max_global |
1407                  class_max_local |
1408                  class_max_ident |
1409 <                class_sendq |
1409 >                class_sendq | class_recvq |
1410 >                class_min_idle |
1411 >                class_max_idle |
1412 >                class_flags |
1413                  error ';' ;
1414  
1415   class_name: NAME '=' QSTRING ';'
1416   {
1417    if (conf_parser_ctx.pass == 1)
1418 <  {
1619 <    MyFree(yy_class_name);
1620 <    DupString(yy_class_name, yylval.string);
1621 <  }
1622 < };
1623 <
1624 < class_name_t: QSTRING
1625 < {
1626 <  if (conf_parser_ctx.pass == 1)
1627 <  {
1628 <    MyFree(yy_class_name);
1629 <    DupString(yy_class_name, yylval.string);
1630 <  }
1418 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1419   };
1420  
1421   class_ping_time: PING_TIME '=' timespec ';'
1422   {
1423    if (conf_parser_ctx.pass == 1)
1424 <    PingFreq(yy_class) = $3;
1637 < };
1638 <
1639 < class_ping_warning: PING_WARNING '=' timespec ';'
1640 < {
1641 <  if (conf_parser_ctx.pass == 1)
1642 <    PingWarning(yy_class) = $3;
1424 >    block_state.ping_freq.value = $3;
1425   };
1426  
1427   class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1428   {
1429    if (conf_parser_ctx.pass == 1)
1430 <    MaxPerIp(yy_class) = $3;
1430 >    block_state.max_perip.value = $3;
1431   };
1432  
1433   class_connectfreq: CONNECTFREQ '=' timespec ';'
1434   {
1435    if (conf_parser_ctx.pass == 1)
1436 <    ConFreq(yy_class) = $3;
1436 >    block_state.con_freq.value = $3;
1437   };
1438  
1439   class_max_number: MAX_NUMBER '=' NUMBER ';'
1440   {
1441    if (conf_parser_ctx.pass == 1)
1442 <    MaxTotal(yy_class) = $3;
1442 >    block_state.max_total.value = $3;
1443   };
1444  
1445   class_max_global: MAX_GLOBAL '=' NUMBER ';'
1446   {
1447    if (conf_parser_ctx.pass == 1)
1448 <    MaxGlobal(yy_class) = $3;
1448 >    block_state.max_global.value = $3;
1449   };
1450  
1451   class_max_local: MAX_LOCAL '=' NUMBER ';'
1452   {
1453    if (conf_parser_ctx.pass == 1)
1454 <    MaxLocal(yy_class) = $3;
1454 >    block_state.max_local.value = $3;
1455   };
1456  
1457   class_max_ident: MAX_IDENT '=' NUMBER ';'
1458   {
1459    if (conf_parser_ctx.pass == 1)
1460 <    MaxIdent(yy_class) = $3;
1460 >    block_state.max_ident.value = $3;
1461   };
1462  
1463   class_sendq: SENDQ '=' sizespec ';'
1464   {
1465    if (conf_parser_ctx.pass == 1)
1466 <    MaxSendq(yy_class) = $3;
1466 >    block_state.max_sendq.value = $3;
1467 > };
1468 >
1469 > class_recvq: T_RECVQ '=' sizespec ';'
1470 > {
1471 >  if (conf_parser_ctx.pass == 1)
1472 >    if ($3 >= CLIENT_FLOOD_MIN && $3 <= CLIENT_FLOOD_MAX)
1473 >      block_state.max_recvq.value = $3;
1474   };
1475  
1476   class_cidr_bitlen_ipv4: CIDR_BITLEN_IPV4 '=' NUMBER ';'
1477   {
1478    if (conf_parser_ctx.pass == 1)
1479 <    CidrBitlenIPV4(yy_class) = $3;
1479 >    block_state.cidr_bitlen_ipv4.value = $3 > 32 ? 32 : $3;
1480   };
1481  
1482   class_cidr_bitlen_ipv6: CIDR_BITLEN_IPV6 '=' NUMBER ';'
1483   {
1484    if (conf_parser_ctx.pass == 1)
1485 <    CidrBitlenIPV6(yy_class) = $3;
1485 >    block_state.cidr_bitlen_ipv6.value = $3 > 128 ? 128 : $3;
1486   };
1487  
1488   class_number_per_cidr: NUMBER_PER_CIDR '=' NUMBER ';'
1489   {
1490    if (conf_parser_ctx.pass == 1)
1491 <    NumberPerCidr(yy_class) = $3;
1491 >    block_state.number_per_cidr.value = $3;
1492 > };
1493 >
1494 > class_min_idle: MIN_IDLE '=' timespec ';'
1495 > {
1496 >  if (conf_parser_ctx.pass != 1)
1497 >    break;
1498 >
1499 >  block_state.min_idle.value = $3;
1500 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1501   };
1502  
1503 + class_max_idle: MAX_IDLE '=' timespec ';'
1504 + {
1505 +  if (conf_parser_ctx.pass != 1)
1506 +    break;
1507 +
1508 +  block_state.max_idle.value = $3;
1509 +  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1510 + };
1511 +
1512 + class_flags: IRCD_FLAGS
1513 + {
1514 +  if (conf_parser_ctx.pass == 1)
1515 +    block_state.flags.value &= CLASS_FLAGS_FAKE_IDLE;
1516 + } '='  class_flags_items ';';
1517 +
1518 + class_flags_items: class_flags_items ',' class_flags_item | class_flags_item;
1519 + class_flags_item: RANDOM_IDLE
1520 + {
1521 +  if (conf_parser_ctx.pass == 1)
1522 +    block_state.flags.value |= CLASS_FLAGS_RANDOM_IDLE;
1523 + } | HIDE_IDLE_FROM_OPERS
1524 + {
1525 +  if (conf_parser_ctx.pass == 1)
1526 +    block_state.flags.value |= CLASS_FLAGS_HIDE_IDLE_FROM_OPERS;
1527 + };
1528 +
1529 +
1530   /***************************************************************************
1531   *  section listen
1532   ***************************************************************************/
1533   listen_entry: LISTEN
1534   {
1535    if (conf_parser_ctx.pass == 2)
1536 <  {
1537 <    listener_address = NULL;
1713 <    listener_flags = 0;
1714 <  }
1715 < } '{' listen_items '}' ';'
1716 < {
1717 <  if (conf_parser_ctx.pass == 2)
1718 <  {
1719 <    MyFree(listener_address);
1720 <    listener_address = NULL;
1721 <  }
1722 < };
1536 >    reset_block_state();
1537 > } '{' listen_items '}' ';';
1538  
1539   listen_flags: IRCD_FLAGS
1540   {
1541 <  listener_flags = 0;
1541 >  block_state.flags.value = 0;
1542   } '='  listen_flags_items ';';
1543  
1544   listen_flags_items: listen_flags_items ',' listen_flags_item | listen_flags_item;
1545   listen_flags_item: T_SSL
1546   {
1547    if (conf_parser_ctx.pass == 2)
1548 <    listener_flags |= LISTENER_SSL;
1548 >    block_state.flags.value |= LISTENER_SSL;
1549   } | HIDDEN
1550   {
1551    if (conf_parser_ctx.pass == 2)
1552 <    listener_flags |= LISTENER_HIDDEN;
1552 >    block_state.flags.value |= LISTENER_HIDDEN;
1553   } | T_SERVER
1554   {
1555    if (conf_parser_ctx.pass == 2)
1556 <    listener_flags |= LISTENER_SERVER;
1556 >   block_state.flags.value |= LISTENER_SERVER;
1557   };
1558  
1744
1745
1559   listen_items:   listen_items listen_item | listen_item;
1560   listen_item:    listen_port | listen_flags | listen_address | listen_host | error ';';
1561  
1562 < listen_port: PORT '=' port_items { listener_flags = 0; } ';';
1562 > listen_port: PORT '=' port_items { block_state.flags.value = 0; } ';';
1563  
1564   port_items: port_items ',' port_item | port_item;
1565  
# Line 1754 | Line 1567 | port_item: NUMBER
1567   {
1568    if (conf_parser_ctx.pass == 2)
1569    {
1570 <    if ((listener_flags & LISTENER_SSL))
1570 >    if (block_state.flags.value & LISTENER_SSL)
1571   #ifdef HAVE_LIBCRYPTO
1572        if (!ServerInfo.server_ctx)
1573   #endif
1574        {
1575 <        yyerror("SSL not available - port closed");
1575 >        conf_error_report("SSL not available - port closed");
1576          break;
1577        }
1578 <    add_listener($1, listener_address, listener_flags);
1578 >    add_listener($1, block_state.addr.buf, block_state.flags.value);
1579    }
1580   } | NUMBER TWODOTS NUMBER
1581   {
# Line 1770 | Line 1583 | port_item: NUMBER
1583    {
1584      int i;
1585  
1586 <    if ((listener_flags & LISTENER_SSL))
1586 >    if (block_state.flags.value & LISTENER_SSL)
1587   #ifdef HAVE_LIBCRYPTO
1588        if (!ServerInfo.server_ctx)
1589   #endif
1590        {
1591 <        yyerror("SSL not available - port closed");
1591 >        conf_error_report("SSL not available - port closed");
1592          break;
1593        }
1594  
1595      for (i = $1; i <= $3; ++i)
1596 <      add_listener(i, listener_address, listener_flags);
1596 >      add_listener(i, block_state.addr.buf, block_state.flags.value);
1597    }
1598   };
1599  
1600   listen_address: IP '=' QSTRING ';'
1601   {
1602    if (conf_parser_ctx.pass == 2)
1603 <  {
1791 <    MyFree(listener_address);
1792 <    DupString(listener_address, yylval.string);
1793 <  }
1603 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1604   };
1605  
1606   listen_host: HOST '=' QSTRING ';'
1607   {
1608    if (conf_parser_ctx.pass == 2)
1609 <  {
1800 <    MyFree(listener_address);
1801 <    DupString(listener_address, yylval.string);
1802 <  }
1609 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1610   };
1611  
1612   /***************************************************************************
# Line 1808 | Line 1615 | listen_host: HOST '=' QSTRING ';'
1615   auth_entry: IRCD_AUTH
1616   {
1617    if (conf_parser_ctx.pass == 2)
1618 <  {
1812 <    yy_conf = make_conf_item(CLIENT_TYPE);
1813 <    yy_aconf = map_to_conf(yy_conf);
1814 <  }
1815 <  else
1816 <  {
1817 <    MyFree(class_name);
1818 <    class_name = NULL;
1819 <  }
1618 >    reset_block_state();
1619   } '{' auth_items '}' ';'
1620   {
1621 <  if (conf_parser_ctx.pass == 2)
1823 <  {
1824 <    struct CollectItem *yy_tmp = NULL;
1825 <    dlink_node *ptr = NULL, *next_ptr = NULL;
1826 <
1827 <    if (yy_aconf->user && yy_aconf->host)
1828 <    {
1829 <      conf_add_class_to_conf(yy_conf, class_name);
1830 <      add_conf_by_address(CONF_CLIENT, yy_aconf);
1831 <    }
1832 <    else
1833 <      delete_conf_item(yy_conf);
1834 <
1835 <    /* copy over settings from first struct */
1836 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1837 <    {
1838 <      struct AccessItem *new_aconf;
1839 <      struct ConfItem *new_conf;
1840 <
1841 <      new_conf = make_conf_item(CLIENT_TYPE);
1842 <      new_aconf = map_to_conf(new_conf);
1843 <
1844 <      yy_tmp = ptr->data;
1845 <
1846 <      assert(yy_tmp->user && yy_tmp->host);
1847 <
1848 <      if (yy_aconf->passwd != NULL)
1849 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1850 <      if (yy_conf->name != NULL)
1851 <        DupString(new_conf->name, yy_conf->name);
1852 <      if (yy_aconf->passwd != NULL)
1853 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1854 <
1855 <      new_aconf->flags = yy_aconf->flags;
1856 <      new_aconf->port  = yy_aconf->port;
1621 >  dlink_node *ptr = NULL;
1622  
1623 <      DupString(new_aconf->user, yy_tmp->user);
1624 <      collapse(new_aconf->user);
1623 >  if (conf_parser_ctx.pass != 2)
1624 >    break;
1625  
1626 <      DupString(new_aconf->host, yy_tmp->host);
1862 <      collapse(new_aconf->host);
1863 <
1864 <      conf_add_class_to_conf(new_conf, class_name);
1865 <      add_conf_by_address(CONF_CLIENT, new_aconf);
1866 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1867 <      free_collect_item(yy_tmp);
1868 <    }
1869 <
1870 <    MyFree(class_name);
1871 <    class_name = NULL;
1872 <    yy_conf = NULL;
1873 <    yy_aconf = NULL;
1874 <  }
1875 < };
1876 <
1877 < auth_items:     auth_items auth_item | auth_item;
1878 < auth_item:      auth_user | auth_passwd | auth_class | auth_flags |
1879 <                auth_kline_exempt | auth_need_ident |
1880 <                auth_exceed_limit | auth_no_tilde | auth_gline_exempt |
1881 <                auth_spoof | auth_spoof_notice |
1882 <                auth_redir_serv | auth_redir_port | auth_can_flood |
1883 <                auth_need_password | auth_encrypted | error ';' ;
1884 <
1885 < auth_user: USER '=' QSTRING ';'
1886 < {
1887 <  if (conf_parser_ctx.pass == 2)
1626 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1627    {
1628 <    struct CollectItem *yy_tmp = NULL;
1628 >    struct MaskItem *conf = NULL;
1629      struct split_nuh_item nuh;
1630  
1631 <    nuh.nuhmask  = yylval.string;
1631 >    nuh.nuhmask  = ptr->data;
1632      nuh.nickptr  = NULL;
1633 <    nuh.userptr  = userbuf;
1634 <    nuh.hostptr  = hostbuf;
1896 <
1633 >    nuh.userptr  = block_state.user.buf;
1634 >    nuh.hostptr  = block_state.host.buf;
1635      nuh.nicksize = 0;
1636 <    nuh.usersize = sizeof(userbuf);
1637 <    nuh.hostsize = sizeof(hostbuf);
1900 <
1636 >    nuh.usersize = sizeof(block_state.user.buf);
1637 >    nuh.hostsize = sizeof(block_state.host.buf);
1638      split_nuh(&nuh);
1639  
1640 <    if (yy_aconf->user == NULL)
1641 <    {
1642 <      DupString(yy_aconf->user, userbuf);
1643 <      DupString(yy_aconf->host, hostbuf);
1644 <    }
1645 <    else
1646 <    {
1647 <      yy_tmp = MyMalloc(sizeof(struct CollectItem));
1640 >    conf        = conf_make(CONF_CLIENT);
1641 >    conf->user  = xstrdup(block_state.user.buf);
1642 >    conf->host  = xstrdup(block_state.host.buf);
1643 >
1644 >    if (block_state.rpass.buf[0])
1645 >      conf->passwd = xstrdup(block_state.rpass.buf);
1646 >    if (block_state.name.buf[0])
1647 >      conf->name = xstrdup(block_state.name.buf);
1648  
1649 <      DupString(yy_tmp->user, userbuf);
1650 <      DupString(yy_tmp->host, hostbuf);
1649 >    conf->flags = block_state.flags.value;
1650 >    conf->port  = block_state.port.value;
1651  
1652 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1653 <    }
1652 >    conf_add_class_to_conf(conf, block_state.class.buf);
1653 >    add_conf_by_address(CONF_CLIENT, conf);
1654    }
1655 < };
1655 > };
1656  
1657 < /* XXX - IP/IPV6 tags don't exist anymore - put IP/IPV6 into user. */
1657 > auth_items:     auth_items auth_item | auth_item;
1658 > auth_item:      auth_user | auth_passwd | auth_class | auth_flags |
1659 >                auth_spoof | auth_redir_serv | auth_redir_port |
1660 >                auth_encrypted | error ';' ;
1661  
1662 < auth_passwd: PASSWORD '=' QSTRING ';'
1662 > auth_user: USER '=' QSTRING ';'
1663   {
1664    if (conf_parser_ctx.pass == 2)
1665 <  {
1926 <    /* be paranoid */
1927 <    if (yy_aconf->passwd != NULL)
1928 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1929 <
1930 <    MyFree(yy_aconf->passwd);
1931 <    DupString(yy_aconf->passwd, yylval.string);
1932 <  }
1665 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1666   };
1667  
1668 < auth_spoof_notice: SPOOF_NOTICE '=' TBOOL ';'
1668 > auth_passwd: PASSWORD '=' QSTRING ';'
1669   {
1670    if (conf_parser_ctx.pass == 2)
1671 <  {
1939 <    if (yylval.number)
1940 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1941 <    else
1942 <      yy_aconf->flags &= ~CONF_FLAGS_SPOOF_NOTICE;
1943 <  }
1671 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1672   };
1673  
1674   auth_class: CLASS '=' QSTRING ';'
1675   {
1676    if (conf_parser_ctx.pass == 2)
1677 <  {
1950 <    MyFree(class_name);
1951 <    DupString(class_name, yylval.string);
1952 <  }
1677 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1678   };
1679  
1680   auth_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 1957 | Line 1682 | auth_encrypted: ENCRYPTED '=' TBOOL ';'
1682    if (conf_parser_ctx.pass == 2)
1683    {
1684      if (yylval.number)
1685 <      SetConfEncrypted(yy_aconf);
1685 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1686      else
1687 <      ClearConfEncrypted(yy_aconf);
1687 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1688    }
1689   };
1690  
1691   auth_flags: IRCD_FLAGS
1692   {
1693 +  if (conf_parser_ctx.pass == 2)
1694 +    block_state.flags.value &= (CONF_FLAGS_ENCRYPTED | CONF_FLAGS_SPOOF_IP);
1695   } '='  auth_flags_items ';';
1696  
1697   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
1698 < auth_flags_item: NOT { not_atom = 1; } auth_flags_item_atom
1972 <                | { not_atom = 0; } auth_flags_item_atom;
1973 <
1974 < auth_flags_item_atom: SPOOF_NOTICE
1698 > auth_flags_item: SPOOF_NOTICE
1699   {
1700    if (conf_parser_ctx.pass == 2)
1701 <  {
1978 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_SPOOF_NOTICE;
1979 <    else yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1980 <  }
1981 <
1701 >    block_state.flags.value |= CONF_FLAGS_SPOOF_NOTICE;
1702   } | EXCEED_LIMIT
1703   {
1704    if (conf_parser_ctx.pass == 2)
1705 <  {
1986 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NOLIMIT;
1987 <    else yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
1988 <  }
1705 >    block_state.flags.value |= CONF_FLAGS_NOLIMIT;
1706   } | KLINE_EXEMPT
1707   {
1708    if (conf_parser_ctx.pass == 2)
1709 <  {
1993 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTKLINE;
1994 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
1995 <  }
1709 >    block_state.flags.value |= CONF_FLAGS_EXEMPTKLINE;
1710   } | NEED_IDENT
1711   {
1712    if (conf_parser_ctx.pass == 2)
1713 <  {
2000 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_IDENTD;
2001 <    else yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
2002 <  }
1713 >    block_state.flags.value |= CONF_FLAGS_NEED_IDENTD;
1714   } | CAN_FLOOD
1715   {
1716    if (conf_parser_ctx.pass == 2)
1717 <  {
2007 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_CAN_FLOOD;
2008 <    else yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
2009 <  }
2010 < } | CAN_IDLE
2011 < {
2012 <  if (conf_parser_ctx.pass == 2)
2013 <  {
2014 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_IDLE_LINED;
2015 <    else yy_aconf->flags |= CONF_FLAGS_IDLE_LINED;
2016 <  }
1717 >    block_state.flags.value |= CONF_FLAGS_CAN_FLOOD;
1718   } | NO_TILDE
1719   {
1720    if (conf_parser_ctx.pass == 2)
1721 <  {
2021 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NO_TILDE;
2022 <    else yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
2023 <  }
1721 >    block_state.flags.value |= CONF_FLAGS_NO_TILDE;
1722   } | GLINE_EXEMPT
1723   {
1724    if (conf_parser_ctx.pass == 2)
1725 <  {
2028 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTGLINE;
2029 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
2030 <  }
1725 >    block_state.flags.value |= CONF_FLAGS_EXEMPTGLINE;
1726   } | RESV_EXEMPT
1727   {
1728    if (conf_parser_ctx.pass == 2)
1729 <  {
1730 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTRESV;
2036 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTRESV;
2037 <  }
2038 < } | NEED_PASSWORD
2039 < {
2040 <  if (conf_parser_ctx.pass == 2)
2041 <  {
2042 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_PASSWORD;
2043 <    else yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
2044 <  }
2045 < };
2046 <
2047 < auth_kline_exempt: KLINE_EXEMPT '=' TBOOL ';'
2048 < {
2049 <  if (conf_parser_ctx.pass == 2)
2050 <  {
2051 <    if (yylval.number)
2052 <      yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
2053 <    else
2054 <      yy_aconf->flags &= ~CONF_FLAGS_EXEMPTKLINE;
2055 <  }
2056 < };
2057 <
2058 < auth_need_ident: NEED_IDENT '=' TBOOL ';'
2059 < {
2060 <  if (conf_parser_ctx.pass == 2)
2061 <  {
2062 <    if (yylval.number)
2063 <      yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
2064 <    else
2065 <      yy_aconf->flags &= ~CONF_FLAGS_NEED_IDENTD;
2066 <  }
2067 < };
2068 <
2069 < auth_exceed_limit: EXCEED_LIMIT '=' TBOOL ';'
2070 < {
2071 <  if (conf_parser_ctx.pass == 2)
2072 <  {
2073 <    if (yylval.number)
2074 <      yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
2075 <    else
2076 <      yy_aconf->flags &= ~CONF_FLAGS_NOLIMIT;
2077 <  }
2078 < };
2079 <
2080 < auth_can_flood: CAN_FLOOD '=' TBOOL ';'
2081 < {
2082 <  if (conf_parser_ctx.pass == 2)
2083 <  {
2084 <    if (yylval.number)
2085 <      yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
2086 <    else
2087 <      yy_aconf->flags &= ~CONF_FLAGS_CAN_FLOOD;
2088 <  }
2089 < };
2090 <
2091 < auth_no_tilde: NO_TILDE '=' TBOOL ';'
1729 >    block_state.flags.value |= CONF_FLAGS_EXEMPTRESV;
1730 > } | T_WEBIRC
1731   {
1732    if (conf_parser_ctx.pass == 2)
1733 <  {
1734 <    if (yylval.number)
2096 <      yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
2097 <    else
2098 <      yy_aconf->flags &= ~CONF_FLAGS_NO_TILDE;
2099 <  }
2100 < };
2101 <
2102 < auth_gline_exempt: GLINE_EXEMPT '=' TBOOL ';'
1733 >    block_state.flags.value |= CONF_FLAGS_WEBIRC;
1734 > } | NEED_PASSWORD
1735   {
1736    if (conf_parser_ctx.pass == 2)
1737 <  {
2106 <    if (yylval.number)
2107 <      yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
2108 <    else
2109 <      yy_aconf->flags &= ~CONF_FLAGS_EXEMPTGLINE;
2110 <  }
1737 >    block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1738   };
1739  
2113 /* XXX - need check for illegal hostnames here */
1740   auth_spoof: SPOOF '=' QSTRING ';'
1741   {
1742 <  if (conf_parser_ctx.pass == 2)
1743 <  {
2118 <    MyFree(yy_conf->name);
1742 >  if (conf_parser_ctx.pass != 2)
1743 >    break;
1744  
1745 <    if (strlen(yylval.string) < HOSTLEN)
1746 <    {    
1747 <      DupString(yy_conf->name, yylval.string);
1748 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_IP;
2124 <    }
2125 <    else
2126 <    {
2127 <      ilog(L_ERROR, "Spoofs must be less than %d..ignoring it", HOSTLEN);
2128 <      yy_conf->name = NULL;
2129 <    }
1745 >  if (strlen(yylval.string) <= HOSTLEN && valid_hostname(yylval.string))
1746 >  {
1747 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1748 >    block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
1749    }
1750 +  else
1751 +    ilog(LOG_TYPE_IRCD, "Spoof either is too long or contains invalid characters. Ignoring it.");
1752   };
1753  
1754   auth_redir_serv: REDIRSERV '=' QSTRING ';'
1755   {
1756 <  if (conf_parser_ctx.pass == 2)
1757 <  {
1758 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1759 <    MyFree(yy_conf->name);
1760 <    DupString(yy_conf->name, yylval.string);
2140 <  }
1756 >  if (conf_parser_ctx.pass != 2)
1757 >    break;
1758 >
1759 >  strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1760 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1761   };
1762  
1763   auth_redir_port: REDIRPORT '=' NUMBER ';'
1764   {
1765 <  if (conf_parser_ctx.pass == 2)
1766 <  {
2147 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
2148 <    yy_aconf->port = $3;
2149 <  }
2150 < };
1765 >  if (conf_parser_ctx.pass != 2)
1766 >    break;
1767  
1768 < auth_need_password: NEED_PASSWORD '=' TBOOL ';'
1769 < {
2154 <  if (conf_parser_ctx.pass == 2)
2155 <  {
2156 <    if (yylval.number)
2157 <      yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
2158 <    else
2159 <      yy_aconf->flags &= ~CONF_FLAGS_NEED_PASSWORD;
2160 <  }
1768 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1769 >  block_state.port.value = $3;
1770   };
1771  
1772  
# Line 2166 | Line 1775 | auth_need_password: NEED_PASSWORD '=' TB
1775   ***************************************************************************/
1776   resv_entry: RESV
1777   {
1778 <  if (conf_parser_ctx.pass == 2)
1779 <  {
1780 <    MyFree(resv_reason);
1781 <    resv_reason = NULL;
1782 <  }
1778 >  if (conf_parser_ctx.pass != 2)
1779 >    break;
1780 >
1781 >  reset_block_state();
1782 >  strlcpy(block_state.rpass.buf, CONF_NOREASON, sizeof(block_state.rpass.buf));
1783   } '{' resv_items '}' ';'
1784   {
1785 <  if (conf_parser_ctx.pass == 2)
1786 <  {
1787 <    MyFree(resv_reason);
1788 <    resv_reason = NULL;
2180 <  }
1785 >  if (conf_parser_ctx.pass != 2)
1786 >    break;
1787 >
1788 >  create_resv(block_state.name.buf, block_state.rpass.buf, &block_state.mask.list);
1789   };
1790  
1791   resv_items:     resv_items resv_item | resv_item;
1792 < resv_item:      resv_creason | resv_channel | resv_nick | error ';' ;
1792 > resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1793  
1794 < resv_creason: REASON '=' QSTRING ';'
1794 > resv_mask: MASK '=' QSTRING ';'
1795   {
1796    if (conf_parser_ctx.pass == 2)
1797 <  {
2190 <    MyFree(resv_reason);
2191 <    DupString(resv_reason, yylval.string);
2192 <  }
1797 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1798   };
1799  
1800 < resv_channel: CHANNEL '=' QSTRING ';'
1800 > resv_reason: REASON '=' QSTRING ';'
1801   {
1802    if (conf_parser_ctx.pass == 2)
1803 <  {
2199 <    if (IsChanPrefix(*yylval.string))
2200 <    {
2201 <      char def_reason[] = "No reason";
2202 <
2203 <      create_channel_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
2204 <    }
2205 <  }
2206 <  /* ignore it for now.. but we really should make a warning if
2207 <   * its an erroneous name --fl_ */
1803 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1804   };
1805  
1806 < resv_nick: NICK '=' QSTRING ';'
1806 > resv_exempt: EXEMPT '=' QSTRING ';'
1807   {
1808    if (conf_parser_ctx.pass == 2)
1809 <  {
1810 <    char def_reason[] = "No reason";
1809 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1810 > };
1811 >
1812 >
1813 > /***************************************************************************
1814 > *  section service
1815 > ***************************************************************************/
1816 > service_entry: T_SERVICE '{' service_items '}' ';';
1817 >
1818 > service_items:     service_items service_item | service_item;
1819 > service_item:      service_name | error;
1820 >
1821 > service_name: NAME '=' QSTRING ';'
1822 > {
1823 >  if (conf_parser_ctx.pass != 2)
1824 >    break;
1825  
1826 <    create_nick_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1826 >  if (valid_servname(yylval.string))
1827 >  {
1828 >    struct MaskItem *conf = conf_make(CONF_SERVICE);
1829 >    conf->name = xstrdup(yylval.string);
1830    }
1831   };
1832  
# Line 2222 | Line 1835 | resv_nick: NICK '=' QSTRING ';'
1835   ***************************************************************************/
1836   shared_entry: T_SHARED
1837   {
1838 <  if (conf_parser_ctx.pass == 2)
1839 <  {
1840 <    yy_conf = make_conf_item(ULINE_TYPE);
1841 <    yy_match_item = map_to_conf(yy_conf);
1842 <    yy_match_item->action = SHARED_ALL;
1843 <  }
1838 >  if (conf_parser_ctx.pass != 2)
1839 >    break;
1840 >
1841 >  reset_block_state();
1842 >
1843 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1844 >  strlcpy(block_state.user.buf, "*", sizeof(block_state.user.buf));
1845 >  strlcpy(block_state.host.buf, "*", sizeof(block_state.host.buf));
1846 >  block_state.flags.value = SHARED_ALL;
1847   } '{' shared_items '}' ';'
1848   {
1849 <  if (conf_parser_ctx.pass == 2)
1850 <  {
1851 <    yy_conf = NULL;
1852 <  }
1849 >  struct MaskItem *conf = NULL;
1850 >
1851 >  if (conf_parser_ctx.pass != 2)
1852 >    break;
1853 >
1854 >  conf = conf_make(CONF_ULINE);
1855 >  conf->flags = block_state.flags.value;
1856 >  conf->name = xstrdup(block_state.name.buf);
1857 >  conf->user = xstrdup(block_state.user.buf);
1858 >  conf->host = xstrdup(block_state.host.buf);
1859   };
1860  
1861   shared_items: shared_items shared_item | shared_item;
# Line 2242 | Line 1864 | shared_item:  shared_name | shared_user
1864   shared_name: NAME '=' QSTRING ';'
1865   {
1866    if (conf_parser_ctx.pass == 2)
1867 <  {
2246 <    MyFree(yy_conf->name);
2247 <    DupString(yy_conf->name, yylval.string);
2248 <  }
1867 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1868   };
1869  
1870   shared_user: USER '=' QSTRING ';'
# Line 2256 | Line 1875 | shared_user: USER '=' QSTRING ';'
1875  
1876      nuh.nuhmask  = yylval.string;
1877      nuh.nickptr  = NULL;
1878 <    nuh.userptr  = userbuf;
1879 <    nuh.hostptr  = hostbuf;
1878 >    nuh.userptr  = block_state.user.buf;
1879 >    nuh.hostptr  = block_state.host.buf;
1880  
1881      nuh.nicksize = 0;
1882 <    nuh.usersize = sizeof(userbuf);
1883 <    nuh.hostsize = sizeof(hostbuf);
1882 >    nuh.usersize = sizeof(block_state.user.buf);
1883 >    nuh.hostsize = sizeof(block_state.host.buf);
1884  
1885      split_nuh(&nuh);
2267
2268    DupString(yy_match_item->user, userbuf);
2269    DupString(yy_match_item->host, hostbuf);
1886    }
1887   };
1888  
1889   shared_type: TYPE
1890   {
1891    if (conf_parser_ctx.pass == 2)
1892 <    yy_match_item->action = 0;
1892 >    block_state.flags.value = 0;
1893   } '=' shared_types ';' ;
1894  
1895   shared_types: shared_types ',' shared_type_item | shared_type_item;
1896   shared_type_item: KLINE
1897   {
1898    if (conf_parser_ctx.pass == 2)
1899 <    yy_match_item->action |= SHARED_KLINE;
1900 < } | TKLINE
1899 >    block_state.flags.value |= SHARED_KLINE;
1900 > } | UNKLINE
1901   {
1902    if (conf_parser_ctx.pass == 2)
1903 <    yy_match_item->action |= SHARED_TKLINE;
1904 < } | UNKLINE
1903 >    block_state.flags.value |= SHARED_UNKLINE;
1904 > } | T_DLINE
1905   {
1906    if (conf_parser_ctx.pass == 2)
1907 <    yy_match_item->action |= SHARED_UNKLINE;
1908 < } | XLINE
1907 >    block_state.flags.value |= SHARED_DLINE;
1908 > } | T_UNDLINE
1909   {
1910    if (conf_parser_ctx.pass == 2)
1911 <    yy_match_item->action |= SHARED_XLINE;
1912 < } | TXLINE
1911 >    block_state.flags.value |= SHARED_UNDLINE;
1912 > } | XLINE
1913   {
1914    if (conf_parser_ctx.pass == 2)
1915 <    yy_match_item->action |= SHARED_TXLINE;
1915 >    block_state.flags.value |= SHARED_XLINE;
1916   } | T_UNXLINE
1917   {
1918    if (conf_parser_ctx.pass == 2)
1919 <    yy_match_item->action |= SHARED_UNXLINE;
1919 >    block_state.flags.value |= SHARED_UNXLINE;
1920   } | RESV
1921   {
1922    if (conf_parser_ctx.pass == 2)
1923 <    yy_match_item->action |= SHARED_RESV;
2308 < } | TRESV
2309 < {
2310 <  if (conf_parser_ctx.pass == 2)
2311 <    yy_match_item->action |= SHARED_TRESV;
1923 >    block_state.flags.value |= SHARED_RESV;
1924   } | T_UNRESV
1925   {
1926    if (conf_parser_ctx.pass == 2)
1927 <    yy_match_item->action |= SHARED_UNRESV;
1927 >    block_state.flags.value |= SHARED_UNRESV;
1928   } | T_LOCOPS
1929   {
1930    if (conf_parser_ctx.pass == 2)
1931 <    yy_match_item->action |= SHARED_LOCOPS;
1931 >    block_state.flags.value |= SHARED_LOCOPS;
1932   } | T_ALL
1933   {
1934    if (conf_parser_ctx.pass == 2)
1935 <    yy_match_item->action = SHARED_ALL;
1935 >    block_state.flags.value = SHARED_ALL;
1936   };
1937  
1938   /***************************************************************************
# Line 2328 | Line 1940 | shared_type_item: KLINE
1940   ***************************************************************************/
1941   cluster_entry: T_CLUSTER
1942   {
1943 <  if (conf_parser_ctx.pass == 2)
1944 <  {
1945 <    yy_conf = make_conf_item(CLUSTER_TYPE);
1946 <    yy_conf->flags = SHARED_ALL;
1947 <  }
1943 >  if (conf_parser_ctx.pass != 2)
1944 >    break;
1945 >
1946 >  reset_block_state();
1947 >
1948 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1949 >  block_state.flags.value = SHARED_ALL;
1950   } '{' cluster_items '}' ';'
1951   {
1952 <  if (conf_parser_ctx.pass == 2)
1953 <  {
1954 <    if (yy_conf->name == NULL)
1955 <      DupString(yy_conf->name, "*");
1956 <    yy_conf = NULL;
1957 <  }
1952 >  struct MaskItem *conf = NULL;
1953 >
1954 >  if (conf_parser_ctx.pass != 2)
1955 >    break;
1956 >
1957 >  conf = conf_make(CONF_CLUSTER);
1958 >  conf->flags = block_state.flags.value;
1959 >  conf->name = xstrdup(block_state.name.buf);
1960   };
1961  
1962   cluster_items:  cluster_items cluster_item | cluster_item;
# Line 2349 | Line 1965 | cluster_item:  cluster_name | cluster_typ
1965   cluster_name: NAME '=' QSTRING ';'
1966   {
1967    if (conf_parser_ctx.pass == 2)
1968 <    DupString(yy_conf->name, yylval.string);
1968 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1969   };
1970  
1971   cluster_type: TYPE
1972   {
1973    if (conf_parser_ctx.pass == 2)
1974 <    yy_conf->flags = 0;
1974 >    block_state.flags.value = 0;
1975   } '=' cluster_types ';' ;
1976  
1977   cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
1978   cluster_type_item: KLINE
1979   {
1980    if (conf_parser_ctx.pass == 2)
1981 <    yy_conf->flags |= SHARED_KLINE;
1982 < } | TKLINE
1981 >    block_state.flags.value |= SHARED_KLINE;
1982 > } | UNKLINE
1983   {
1984    if (conf_parser_ctx.pass == 2)
1985 <    yy_conf->flags |= SHARED_TKLINE;
1986 < } | UNKLINE
1985 >    block_state.flags.value |= SHARED_UNKLINE;
1986 > } | T_DLINE
1987   {
1988    if (conf_parser_ctx.pass == 2)
1989 <    yy_conf->flags |= SHARED_UNKLINE;
1990 < } | XLINE
1989 >    block_state.flags.value |= SHARED_DLINE;
1990 > } | T_UNDLINE
1991   {
1992    if (conf_parser_ctx.pass == 2)
1993 <    yy_conf->flags |= SHARED_XLINE;
1994 < } | TXLINE
1993 >    block_state.flags.value |= SHARED_UNDLINE;
1994 > } | XLINE
1995   {
1996    if (conf_parser_ctx.pass == 2)
1997 <    yy_conf->flags |= SHARED_TXLINE;
1997 >    block_state.flags.value |= SHARED_XLINE;
1998   } | T_UNXLINE
1999   {
2000    if (conf_parser_ctx.pass == 2)
2001 <    yy_conf->flags |= SHARED_UNXLINE;
2001 >    block_state.flags.value |= SHARED_UNXLINE;
2002   } | RESV
2003   {
2004    if (conf_parser_ctx.pass == 2)
2005 <    yy_conf->flags |= SHARED_RESV;
2390 < } | TRESV
2391 < {
2392 <  if (conf_parser_ctx.pass == 2)
2393 <    yy_conf->flags |= SHARED_TRESV;
2005 >    block_state.flags.value |= SHARED_RESV;
2006   } | T_UNRESV
2007   {
2008    if (conf_parser_ctx.pass == 2)
2009 <    yy_conf->flags |= SHARED_UNRESV;
2009 >    block_state.flags.value |= SHARED_UNRESV;
2010   } | T_LOCOPS
2011   {
2012    if (conf_parser_ctx.pass == 2)
2013 <    yy_conf->flags |= SHARED_LOCOPS;
2013 >    block_state.flags.value |= SHARED_LOCOPS;
2014   } | T_ALL
2015   {
2016    if (conf_parser_ctx.pass == 2)
2017 <    yy_conf->flags = SHARED_ALL;
2017 >    block_state.flags.value = SHARED_ALL;
2018   };
2019  
2020   /***************************************************************************
# Line 2410 | Line 2022 | cluster_type_item: KLINE
2022   ***************************************************************************/
2023   connect_entry: CONNECT  
2024   {
2413  if (conf_parser_ctx.pass == 2)
2414  {
2415    yy_conf = make_conf_item(SERVER_TYPE);
2416    yy_aconf = (struct AccessItem *)map_to_conf(yy_conf);
2417    yy_aconf->passwd = NULL;
2418    /* defaults */
2419    yy_aconf->port = PORTNUM;
2025  
2026 <    if (ConfigFileEntry.burst_away)
2027 <      yy_aconf->flags = CONF_FLAGS_BURST_AWAY;
2028 <  }
2029 <  else
2030 <  {
2031 <    MyFree(class_name);
2427 <    class_name = NULL;
2428 <  }
2429 < } connect_name_b '{' connect_items '}' ';'
2026 >  if (conf_parser_ctx.pass != 2)
2027 >    break;
2028 >
2029 >  reset_block_state();
2030 >  block_state.port.value = PORTNUM;
2031 > } '{' connect_items '}' ';'
2032   {
2033 <  if (conf_parser_ctx.pass == 2)
2034 <  {
2433 <    struct CollectItem *yy_hconf=NULL;
2434 <    struct CollectItem *yy_lconf=NULL;
2435 <    dlink_node *ptr;
2436 <    dlink_node *next_ptr;
2437 < #ifdef HAVE_LIBCRYPTO
2438 <    if (yy_aconf->host &&
2439 <        ((yy_aconf->passwd && yy_aconf->spasswd) ||
2440 <         (yy_aconf->rsa_public_key && IsConfCryptLink(yy_aconf))))
2441 < #else /* !HAVE_LIBCRYPTO */
2442 <      if (yy_aconf->host && !IsConfCryptLink(yy_aconf) &&
2443 <          yy_aconf->passwd && yy_aconf->spasswd)
2444 < #endif /* !HAVE_LIBCRYPTO */
2445 <        {
2446 <          if (conf_add_server(yy_conf, class_name) == -1)
2447 <          {
2448 <            delete_conf_item(yy_conf);
2449 <            yy_conf = NULL;
2450 <            yy_aconf = NULL;
2451 <          }
2452 <        }
2453 <        else
2454 <        {
2455 <          /* Even if yy_conf ->name is NULL
2456 <           * should still unhook any hub/leaf confs still pending
2457 <           */
2458 <          unhook_hub_leaf_confs();
2459 <
2460 <          if (yy_conf->name != NULL)
2461 <          {
2462 < #ifndef HAVE_LIBCRYPTO
2463 <            if (IsConfCryptLink(yy_aconf))
2464 <              yyerror("Ignoring connect block -- no OpenSSL support");
2465 < #else
2466 <            if (IsConfCryptLink(yy_aconf) && !yy_aconf->rsa_public_key)
2467 <              yyerror("Ignoring connect block -- missing key");
2468 < #endif
2469 <            if (yy_aconf->host == NULL)
2470 <              yyerror("Ignoring connect block -- missing host");
2471 <            else if (!IsConfCryptLink(yy_aconf) &&
2472 <                    (!yy_aconf->passwd || !yy_aconf->spasswd))
2473 <              yyerror("Ignoring connect block -- missing password");
2474 <          }
2475 <
2476 <
2477 <          /* XXX
2478 <           * This fixes a try_connections() core (caused by invalid class_ptr
2479 <           * pointers) reported by metalrock. That's an ugly fix, but there
2480 <           * is currently no better way. The entire config subsystem needs an
2481 <           * rewrite ASAP. make_conf_item() shouldn't really add things onto
2482 <           * a doubly linked list immediately without any sanity checks!  -Michael
2483 <           */
2484 <          delete_conf_item(yy_conf);
2485 <
2486 <          yy_aconf = NULL;
2487 <          yy_conf = NULL;
2488 <        }
2489 <
2490 <      /*
2491 <       * yy_conf is still pointing at the server that is having
2492 <       * a connect block built for it. This means, y_aconf->name
2493 <       * points to the actual irc name this server will be known as.
2494 <       * Now this new server has a set or even just one hub_mask (or leaf_mask)
2495 <       * given in the link list at yy_hconf. Fill in the HUB confs
2496 <       * from this link list now.
2497 <       */        
2498 <      DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
2499 <      {
2500 <        struct ConfItem *new_hub_conf;
2501 <        struct MatchItem *match_item;
2033 >  struct MaskItem *conf = NULL;
2034 >  struct addrinfo hints, *res;
2035  
2036 <        yy_hconf = ptr->data;
2036 >  if (conf_parser_ctx.pass != 2)
2037 >    break;
2038  
2039 <        /* yy_conf == NULL is a fatal error for this connect block! */
2040 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2041 <        {
2508 <          new_hub_conf = make_conf_item(HUB_TYPE);
2509 <          match_item = (struct MatchItem *)map_to_conf(new_hub_conf);
2510 <          DupString(new_hub_conf->name, yy_conf->name);
2511 <          if (yy_hconf->user != NULL)
2512 <            DupString(match_item->user, yy_hconf->user);
2513 <          else
2514 <            DupString(match_item->user, "*");
2515 <          if (yy_hconf->host != NULL)
2516 <            DupString(match_item->host, yy_hconf->host);
2517 <          else
2518 <            DupString(match_item->host, "*");
2519 <        }
2520 <        dlinkDelete(&yy_hconf->node, &hub_conf_list);
2521 <        free_collect_item(yy_hconf);
2522 <      }
2039 >  if (!block_state.name.buf[0] ||
2040 >      !block_state.host.buf[0])
2041 >    break;
2042  
2043 <      /* Ditto for the LEAF confs */
2043 >  if (!block_state.rpass.buf[0] ||
2044 >      !block_state.spass.buf[0])
2045 >    break;
2046  
2047 <      DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
2048 <      {
2049 <        struct ConfItem *new_leaf_conf;
2529 <        struct MatchItem *match_item;
2047 >  if (has_wildcards(block_state.name.buf) ||
2048 >      has_wildcards(block_state.host.buf))
2049 >    break;
2050  
2051 <        yy_lconf = ptr->data;
2051 >  conf = conf_make(CONF_SERVER);
2052 >  conf->port = block_state.port.value;
2053 >  conf->flags = block_state.flags.value;
2054 >  conf->aftype = block_state.aftype.value;
2055 >  conf->host = xstrdup(block_state.host.buf);
2056 >  conf->name = xstrdup(block_state.name.buf);
2057 >  conf->passwd = xstrdup(block_state.rpass.buf);
2058 >  conf->spasswd = xstrdup(block_state.spass.buf);
2059  
2060 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2061 <        {
2062 <          new_leaf_conf = make_conf_item(LEAF_TYPE);
2063 <          match_item = (struct MatchItem *)map_to_conf(new_leaf_conf);
2064 <          DupString(new_leaf_conf->name, yy_conf->name);
2065 <          if (yy_lconf->user != NULL)
2066 <            DupString(match_item->user, yy_lconf->user);
2067 <          else
2068 <            DupString(match_item->user, "*");
2069 <          if (yy_lconf->host != NULL)
2070 <            DupString(match_item->host, yy_lconf->host);
2071 <          else
2072 <            DupString(match_item->host, "*");
2073 <        }
2074 <        dlinkDelete(&yy_lconf->node, &leaf_conf_list);
2075 <        free_collect_item(yy_lconf);
2076 <      }
2077 <      MyFree(class_name);
2078 <      class_name = NULL;
2079 <      yy_conf = NULL;
2080 <      yy_aconf = NULL;
2060 >  if (block_state.cert.buf[0])
2061 >    conf->certfp = xstrdup(block_state.cert.buf);
2062 >
2063 >  conf->cipher_list = xstrdup(block_state.ciph.buf);
2064 >
2065 >  dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
2066 >  dlinkMoveList(&block_state.hub.list, &conf->hub_list);
2067 >
2068 >  if (block_state.bind.buf[0])
2069 >  {
2070 >    memset(&hints, 0, sizeof(hints));
2071 >
2072 >    hints.ai_family   = AF_UNSPEC;
2073 >    hints.ai_socktype = SOCK_STREAM;
2074 >    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2075 >
2076 >    if (getaddrinfo(block_state.bind.buf, NULL, &hints, &res))
2077 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
2078 >    else
2079 >    {
2080 >      assert(res != NULL);
2081 >
2082 >      memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
2083 >      conf->bind.ss.ss_family = res->ai_family;
2084 >      conf->bind.ss_len = res->ai_addrlen;
2085 >      freeaddrinfo(res);
2086 >    }
2087    }
2088 +
2089 +  conf_add_class_to_conf(conf, block_state.class.buf);
2090 +  lookup_confhost(conf);
2091   };
2092  
2557 connect_name_b: | connect_name_t;
2093   connect_items:  connect_items connect_item | connect_item;
2094   connect_item:   connect_name | connect_host | connect_vhost |
2095                  connect_send_password | connect_accept_password |
2096 <                connect_aftype | connect_port |
2097 <                connect_fakename | connect_flags | connect_hub_mask |
2098 <                connect_leaf_mask | connect_class | connect_auto |
2099 <                connect_encrypted | connect_compressed | connect_cryptlink |
2100 <                connect_rsa_public_key_file | connect_cipher_preference |
2566 <                connect_topicburst | error ';' ;
2096 >                connect_ssl_certificate_fingerprint |
2097 >                connect_aftype | connect_port | connect_ssl_cipher_list |
2098 >                connect_flags | connect_hub_mask | connect_leaf_mask |
2099 >                connect_class | connect_encrypted |
2100 >                error ';' ;
2101  
2102   connect_name: NAME '=' QSTRING ';'
2103   {
2104    if (conf_parser_ctx.pass == 2)
2105 <  {
2572 <    if (yy_conf->name != NULL)
2573 <      yyerror("Multiple connect name entry");
2574 <
2575 <    MyFree(yy_conf->name);
2576 <    DupString(yy_conf->name, yylval.string);
2577 <  }
2578 < };
2579 <
2580 < connect_name_t: QSTRING
2581 < {
2582 <  if (conf_parser_ctx.pass == 2)
2583 <  {
2584 <    if (yy_conf->name != NULL)
2585 <      yyerror("Multiple connect name entry");
2586 <
2587 <    MyFree(yy_conf->name);
2588 <    DupString(yy_conf->name, yylval.string);
2589 <  }
2105 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2106   };
2107  
2108   connect_host: HOST '=' QSTRING ';'
2109   {
2110    if (conf_parser_ctx.pass == 2)
2111 <  {
2596 <    MyFree(yy_aconf->host);
2597 <    DupString(yy_aconf->host, yylval.string);
2598 <  }
2111 >    strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
2112   };
2113  
2114   connect_vhost: VHOST '=' QSTRING ';'
2115   {
2116    if (conf_parser_ctx.pass == 2)
2117 <  {
2605 <    struct addrinfo hints, *res;
2606 <
2607 <    memset(&hints, 0, sizeof(hints));
2608 <
2609 <    hints.ai_family   = AF_UNSPEC;
2610 <    hints.ai_socktype = SOCK_STREAM;
2611 <    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2612 <
2613 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
2614 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
2615 <    else
2616 <    {
2617 <      assert(res != NULL);
2618 <
2619 <      memcpy(&yy_aconf->my_ipnum, res->ai_addr, res->ai_addrlen);
2620 <      yy_aconf->my_ipnum.ss.ss_family = res->ai_family;
2621 <      yy_aconf->my_ipnum.ss_len = res->ai_addrlen;
2622 <      irc_freeaddrinfo(res);
2623 <    }
2624 <  }
2117 >    strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
2118   };
2119  
2120   connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2121   {
2122 <  if (conf_parser_ctx.pass == 2)
2123 <  {
2631 <    if ($3[0] == ':')
2632 <      yyerror("Server passwords cannot begin with a colon");
2633 <    else if (strchr($3, ' ') != NULL)
2634 <      yyerror("Server passwords cannot contain spaces");
2635 <    else {
2636 <      if (yy_aconf->spasswd != NULL)
2637 <        memset(yy_aconf->spasswd, 0, strlen(yy_aconf->spasswd));
2122 >  if (conf_parser_ctx.pass != 2)
2123 >    break;
2124  
2125 <      MyFree(yy_aconf->spasswd);
2126 <      DupString(yy_aconf->spasswd, yylval.string);
2127 <    }
2128 <  }
2125 >  if ($3[0] == ':')
2126 >    conf_error_report("Server passwords cannot begin with a colon");
2127 >  else if (strchr($3, ' ') != NULL)
2128 >    conf_error_report("Server passwords cannot contain spaces");
2129 >  else
2130 >    strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
2131   };
2132  
2133   connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2134   {
2135 <  if (conf_parser_ctx.pass == 2)
2136 <  {
2649 <    if ($3[0] == ':')
2650 <      yyerror("Server passwords cannot begin with a colon");
2651 <    else if (strchr($3, ' ') != NULL)
2652 <      yyerror("Server passwords cannot contain spaces");
2653 <    else {
2654 <      if (yy_aconf->passwd != NULL)
2655 <        memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
2135 >  if (conf_parser_ctx.pass != 2)
2136 >    break;
2137  
2138 <      MyFree(yy_aconf->passwd);
2139 <      DupString(yy_aconf->passwd, yylval.string);
2140 <    }
2141 <  }
2138 >  if ($3[0] == ':')
2139 >    conf_error_report("Server passwords cannot begin with a colon");
2140 >  else if (strchr($3, ' ') != NULL)
2141 >    conf_error_report("Server passwords cannot contain spaces");
2142 >  else
2143 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2144 > };
2145 >
2146 > connect_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
2147 > {
2148 >  if (conf_parser_ctx.pass == 2)
2149 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
2150   };
2151  
2152   connect_port: PORT '=' NUMBER ';'
2153   {
2154    if (conf_parser_ctx.pass == 2)
2155 <    yy_aconf->port = $3;
2155 >    block_state.port.value = $3;
2156   };
2157  
2158   connect_aftype: AFTYPE '=' T_IPV4 ';'
2159   {
2160    if (conf_parser_ctx.pass == 2)
2161 <    yy_aconf->aftype = AF_INET;
2161 >    block_state.aftype.value = AF_INET;
2162   } | AFTYPE '=' T_IPV6 ';'
2163   {
2164   #ifdef IPV6
2165    if (conf_parser_ctx.pass == 2)
2166 <    yy_aconf->aftype = AF_INET6;
2166 >    block_state.aftype.value = AF_INET6;
2167   #endif
2168   };
2169  
2681 connect_fakename: FAKENAME '=' QSTRING ';'
2682 {
2683  if (conf_parser_ctx.pass == 2)
2684  {
2685    MyFree(yy_aconf->fakename);
2686    DupString(yy_aconf->fakename, yylval.string);
2687  }
2688 };
2689
2170   connect_flags: IRCD_FLAGS
2171   {
2172 +  block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
2173   } '='  connect_flags_items ';';
2174  
2175   connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
2176 < connect_flags_item: NOT  { not_atom = 1; } connect_flags_item_atom
2696 <                        |  { not_atom = 0; } connect_flags_item_atom;
2697 <
2698 < connect_flags_item_atom: COMPRESSED
2699 < {
2700 <  if (conf_parser_ctx.pass == 2)
2701 < #ifndef HAVE_LIBZ
2702 <    yyerror("Ignoring flags = compressed; -- no zlib support");
2703 < #else
2704 < {
2705 <   if (not_atom)ClearConfCompressed(yy_aconf);
2706 <   else SetConfCompressed(yy_aconf);
2707 < }
2708 < #endif
2709 < } | CRYPTLINK
2710 < {
2711 <  if (conf_parser_ctx.pass == 2)
2712 <  {
2713 <    if (not_atom)ClearConfCryptLink(yy_aconf);
2714 <    else SetConfCryptLink(yy_aconf);
2715 <  }
2716 < } | AUTOCONN
2717 < {
2718 <  if (conf_parser_ctx.pass == 2)
2719 <  {
2720 <    if (not_atom)ClearConfAllowAutoConn(yy_aconf);
2721 <    else SetConfAllowAutoConn(yy_aconf);
2722 <  }
2723 < } | BURST_AWAY
2176 > connect_flags_item: AUTOCONN
2177   {
2178    if (conf_parser_ctx.pass == 2)
2179 <  {
2180 <    if (not_atom)ClearConfAwayBurst(yy_aconf);
2728 <    else SetConfAwayBurst(yy_aconf);
2729 <  }
2730 < } | TOPICBURST
2179 >    block_state.flags.value |= CONF_FLAGS_ALLOW_AUTO_CONN;
2180 > } | T_SSL
2181   {
2182    if (conf_parser_ctx.pass == 2)
2183 <  {
2734 <    if (not_atom)ClearConfTopicBurst(yy_aconf);
2735 <    else SetConfTopicBurst(yy_aconf);
2736 <  }
2737 < }
2738 < ;
2739 <
2740 < connect_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
2741 < {
2742 < #ifdef HAVE_LIBCRYPTO
2743 <  if (conf_parser_ctx.pass == 2)
2744 <  {
2745 <    BIO *file;
2746 <
2747 <    if (yy_aconf->rsa_public_key != NULL)
2748 <    {
2749 <      RSA_free(yy_aconf->rsa_public_key);
2750 <      yy_aconf->rsa_public_key = NULL;
2751 <    }
2752 <
2753 <    if (yy_aconf->rsa_public_key_file != NULL)
2754 <    {
2755 <      MyFree(yy_aconf->rsa_public_key_file);
2756 <      yy_aconf->rsa_public_key_file = NULL;
2757 <    }
2758 <
2759 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
2760 <
2761 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
2762 <    {
2763 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
2764 <      break;
2765 <    }
2766 <
2767 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
2768 <
2769 <    if (yy_aconf->rsa_public_key == NULL)
2770 <    {
2771 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
2772 <      break;
2773 <    }
2774 <      
2775 <    BIO_set_close(file, BIO_CLOSE);
2776 <    BIO_free(file);
2777 <  }
2778 < #endif /* HAVE_LIBCRYPTO */
2183 >    block_state.flags.value |= CONF_FLAGS_SSL;
2184   };
2185  
2186   connect_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 2783 | Line 2188 | connect_encrypted: ENCRYPTED '=' TBOOL '
2188    if (conf_parser_ctx.pass == 2)
2189    {
2190      if (yylval.number)
2191 <      yy_aconf->flags |= CONF_FLAGS_ENCRYPTED;
2787 <    else
2788 <      yy_aconf->flags &= ~CONF_FLAGS_ENCRYPTED;
2789 <  }
2790 < };
2791 <
2792 < connect_cryptlink: CRYPTLINK '=' TBOOL ';'
2793 < {
2794 <  if (conf_parser_ctx.pass == 2)
2795 <  {
2796 <    if (yylval.number)
2797 <      yy_aconf->flags |= CONF_FLAGS_CRYPTLINK;
2798 <    else
2799 <      yy_aconf->flags &= ~CONF_FLAGS_CRYPTLINK;
2800 <  }
2801 < };
2802 <
2803 < connect_compressed: COMPRESSED '=' TBOOL ';'
2804 < {
2805 <  if (conf_parser_ctx.pass == 2)
2806 <  {
2807 <    if (yylval.number)
2808 < #ifndef HAVE_LIBZ
2809 <      yyerror("Ignoring compressed=yes; -- no zlib support");
2810 < #else
2811 <      yy_aconf->flags |= CONF_FLAGS_COMPRESSED;
2812 < #endif
2813 <    else
2814 <      yy_aconf->flags &= ~CONF_FLAGS_COMPRESSED;
2815 <  }
2816 < };
2817 <
2818 < connect_auto: AUTOCONN '=' TBOOL ';'
2819 < {
2820 <  if (conf_parser_ctx.pass == 2)
2821 <  {
2822 <    if (yylval.number)
2823 <      yy_aconf->flags |= CONF_FLAGS_ALLOW_AUTO_CONN;
2824 <    else
2825 <      yy_aconf->flags &= ~CONF_FLAGS_ALLOW_AUTO_CONN;
2826 <  }
2827 < };
2828 <
2829 < connect_topicburst: TOPICBURST '=' TBOOL ';'
2830 < {
2831 <  if (conf_parser_ctx.pass == 2)
2832 <  {
2833 <    if (yylval.number)
2834 <      SetConfTopicBurst(yy_aconf);
2191 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
2192      else
2193 <      ClearConfTopicBurst(yy_aconf);
2193 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
2194    }
2195   };
2196  
2197   connect_hub_mask: HUB_MASK '=' QSTRING ';'
2198   {
2199    if (conf_parser_ctx.pass == 2)
2200 <  {
2844 <    struct CollectItem *yy_tmp;
2845 <
2846 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2847 <    DupString(yy_tmp->host, yylval.string);
2848 <    DupString(yy_tmp->user, "*");
2849 <    dlinkAdd(yy_tmp, &yy_tmp->node, &hub_conf_list);
2850 <  }
2200 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
2201   };
2202  
2203   connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2204   {
2205    if (conf_parser_ctx.pass == 2)
2206 <  {
2857 <    struct CollectItem *yy_tmp;
2858 <
2859 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2860 <    DupString(yy_tmp->host, yylval.string);
2861 <    DupString(yy_tmp->user, "*");
2862 <    dlinkAdd(yy_tmp, &yy_tmp->node, &leaf_conf_list);
2863 <  }
2206 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
2207   };
2208  
2209   connect_class: CLASS '=' QSTRING ';'
2210   {
2211    if (conf_parser_ctx.pass == 2)
2212 <  {
2870 <    MyFree(class_name);
2871 <    DupString(class_name, yylval.string);
2872 <  }
2212 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
2213   };
2214  
2215 < connect_cipher_preference: CIPHER_PREFERENCE '=' QSTRING ';'
2215 > connect_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
2216   {
2217   #ifdef HAVE_LIBCRYPTO
2218    if (conf_parser_ctx.pass == 2)
2219 <  {
2880 <    struct EncCapability *ecap;
2881 <    const char *cipher_name;
2882 <    int found = 0;
2883 <
2884 <    yy_aconf->cipher_preference = NULL;
2885 <    cipher_name = yylval.string;
2886 <
2887 <    for (ecap = CipherTable; ecap->name; ecap++)
2888 <    {
2889 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
2890 <          (ecap->cap & CAP_ENC_MASK))
2891 <      {
2892 <        yy_aconf->cipher_preference = ecap;
2893 <        found = 1;
2894 <        break;
2895 <      }
2896 <    }
2897 <
2898 <    if (!found)
2899 <      yyerror("Invalid cipher");
2900 <  }
2219 >    strlcpy(block_state.ciph.buf, yylval.string, sizeof(block_state.ciph.buf));
2220   #else
2221    if (conf_parser_ctx.pass == 2)
2222 <    yyerror("Ignoring cipher_preference -- no OpenSSL support");
2222 >    conf_error_report("Ignoring connect::ciphers -- no OpenSSL support");
2223   #endif
2224   };
2225  
2226 +
2227   /***************************************************************************
2228   *  section kill
2229   ***************************************************************************/
2230   kill_entry: KILL
2231   {
2232    if (conf_parser_ctx.pass == 2)
2233 <  {
2914 <    userbuf[0] = hostbuf[0] = reasonbuf[0] = '\0';
2915 <    regex_ban = 0;
2916 <  }
2233 >    reset_block_state();
2234   } '{' kill_items '}' ';'
2235   {
2236 <  if (conf_parser_ctx.pass == 2)
2920 <  {
2921 <    if (userbuf[0] && hostbuf[0])
2922 <    {
2923 <      if (regex_ban)
2924 <      {
2925 < #ifdef HAVE_LIBPCRE
2926 <        void *exp_user = NULL;
2927 <        void *exp_host = NULL;
2928 <        const char *errptr = NULL;
2929 <
2930 <        if (!(exp_user = ircd_pcre_compile(userbuf, &errptr)) ||
2931 <            !(exp_host = ircd_pcre_compile(hostbuf, &errptr)))
2932 <        {
2933 <          ilog(L_ERROR, "Failed to add regular expression based K-Line: %s",
2934 <               errptr);
2935 <          break;
2936 <        }
2937 <
2938 <        yy_aconf = map_to_conf(make_conf_item(RKLINE_TYPE));
2939 <        yy_aconf->regexuser = exp_user;
2940 <        yy_aconf->regexhost = exp_host;
2236 >  struct MaskItem *conf = NULL;
2237  
2238 <        DupString(yy_aconf->user, userbuf);
2239 <        DupString(yy_aconf->host, hostbuf);
2238 >  if (conf_parser_ctx.pass != 2)
2239 >    break;
2240  
2241 <        if (reasonbuf[0])
2242 <          DupString(yy_aconf->reason, reasonbuf);
2243 <        else
2948 <          DupString(yy_aconf->reason, "No reason");
2949 < #else
2950 <        ilog(L_ERROR, "Failed to add regular expression based K-Line: no PCRE support");
2951 <        break;
2952 < #endif
2953 <      }
2954 <      else
2955 <      {
2956 <        yy_aconf = map_to_conf(make_conf_item(KLINE_TYPE));
2957 <
2958 <        DupString(yy_aconf->user, userbuf);
2959 <        DupString(yy_aconf->host, hostbuf);
2241 >  if (!block_state.user.buf[0] ||
2242 >      !block_state.host.buf[0])
2243 >    break;
2244  
2245 <        if (reasonbuf[0])
2246 <          DupString(yy_aconf->reason, reasonbuf);
2247 <        else
2964 <          DupString(yy_aconf->reason, "No reason");
2965 <        add_conf_by_address(CONF_KILL, yy_aconf);
2966 <      }
2967 <    }
2245 >  conf = conf_make(CONF_KLINE);
2246 >  conf->user = xstrdup(block_state.user.buf);
2247 >  conf->host = xstrdup(block_state.host.buf);
2248  
2249 <    yy_aconf = NULL;
2250 <  }
2249 >  if (block_state.rpass.buf[0])
2250 >    conf->reason = xstrdup(block_state.rpass.buf);
2251 >  else
2252 >    conf->reason = xstrdup(CONF_NOREASON);
2253 >  add_conf_by_address(CONF_KLINE, conf);
2254   };
2255  
2973 kill_type: TYPE
2974 {
2975 } '='  kill_type_items ';';
2976
2977 kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2978 kill_type_item: REGEX_T
2979 {
2980  if (conf_parser_ctx.pass == 2)
2981    regex_ban = 1;
2982 };
2983
2256   kill_items:     kill_items kill_item | kill_item;
2257 < kill_item:      kill_user | kill_reason | kill_type | error;
2257 > kill_item:      kill_user | kill_reason | error;
2258  
2259   kill_user: USER '=' QSTRING ';'
2260   {
2261 +
2262    if (conf_parser_ctx.pass == 2)
2263    {
2264      struct split_nuh_item nuh;
2265  
2266      nuh.nuhmask  = yylval.string;
2267      nuh.nickptr  = NULL;
2268 <    nuh.userptr  = userbuf;
2269 <    nuh.hostptr  = hostbuf;
2268 >    nuh.userptr  = block_state.user.buf;
2269 >    nuh.hostptr  = block_state.host.buf;
2270  
2271      nuh.nicksize = 0;
2272 <    nuh.usersize = sizeof(userbuf);
2273 <    nuh.hostsize = sizeof(hostbuf);
2272 >    nuh.usersize = sizeof(block_state.user.buf);
2273 >    nuh.hostsize = sizeof(block_state.host.buf);
2274  
2275      split_nuh(&nuh);
2276    }
# Line 3006 | Line 2279 | kill_user: USER '=' QSTRING ';'
2279   kill_reason: REASON '=' QSTRING ';'
2280   {
2281    if (conf_parser_ctx.pass == 2)
2282 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2282 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2283   };
2284  
2285   /***************************************************************************
# Line 3015 | Line 2288 | kill_reason: REASON '=' QSTRING ';'
2288   deny_entry: DENY
2289   {
2290    if (conf_parser_ctx.pass == 2)
2291 <    hostbuf[0] = reasonbuf[0] = '\0';
2291 >    reset_block_state();
2292   } '{' deny_items '}' ';'
2293   {
2294 <  if (conf_parser_ctx.pass == 2)
2294 >  struct MaskItem *conf = NULL;
2295 >
2296 >  if (conf_parser_ctx.pass != 2)
2297 >    break;
2298 >
2299 >  if (!block_state.addr.buf[0])
2300 >    break;
2301 >
2302 >  if (parse_netmask(block_state.addr.buf, NULL, NULL) != HM_HOST)
2303    {
2304 <    if (hostbuf[0] && parse_netmask(hostbuf, NULL, NULL) != HM_HOST)
2305 <    {
3025 <      yy_aconf = map_to_conf(make_conf_item(DLINE_TYPE));
3026 <      DupString(yy_aconf->host, hostbuf);
2304 >    conf = conf_make(CONF_DLINE);
2305 >    conf->host = xstrdup(block_state.addr.buf);
2306  
2307 <      if (reasonbuf[0])
2308 <        DupString(yy_aconf->reason, reasonbuf);
2309 <      else
2310 <        DupString(yy_aconf->reason, "No reason");
2311 <      add_conf_by_address(CONF_DLINE, yy_aconf);
3033 <      yy_aconf = NULL;
3034 <    }
2307 >    if (block_state.rpass.buf[0])
2308 >      conf->reason = xstrdup(block_state.rpass.buf);
2309 >    else
2310 >      conf->reason = xstrdup(CONF_NOREASON);
2311 >    add_conf_by_address(CONF_DLINE, conf);
2312    }
2313   };
2314  
# Line 3041 | Line 2318 | deny_item:      deny_ip | deny_reason |
2318   deny_ip: IP '=' QSTRING ';'
2319   {
2320    if (conf_parser_ctx.pass == 2)
2321 <    strlcpy(hostbuf, yylval.string, sizeof(hostbuf));
2321 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2322   };
2323  
2324   deny_reason: REASON '=' QSTRING ';'
2325   {
2326    if (conf_parser_ctx.pass == 2)
2327 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2327 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2328   };
2329  
2330   /***************************************************************************
# Line 3064 | Line 2341 | exempt_ip: IP '=' QSTRING ';'
2341    {
2342      if (yylval.string[0] && parse_netmask(yylval.string, NULL, NULL) != HM_HOST)
2343      {
2344 <      yy_aconf = map_to_conf(make_conf_item(EXEMPTDLINE_TYPE));
2345 <      DupString(yy_aconf->host, yylval.string);
2344 >      struct MaskItem *conf = conf_make(CONF_EXEMPT);
2345 >      conf->host = xstrdup(yylval.string);
2346  
2347 <      add_conf_by_address(CONF_EXEMPTDLINE, yy_aconf);
3071 <      yy_aconf = NULL;
2347 >      add_conf_by_address(CONF_EXEMPT, conf);
2348      }
2349    }
2350   };
# Line 3079 | Line 2355 | exempt_ip: IP '=' QSTRING ';'
2355   gecos_entry: GECOS
2356   {
2357    if (conf_parser_ctx.pass == 2)
2358 <  {
3083 <    regex_ban = 0;
3084 <    reasonbuf[0] = gecos_name[0] = '\0';
3085 <  }
2358 >    reset_block_state();
2359   } '{' gecos_items '}' ';'
2360   {
2361 <  if (conf_parser_ctx.pass == 2)
3089 <  {
3090 <    if (gecos_name[0])
3091 <    {
3092 <      if (regex_ban)
3093 <      {
3094 < #ifdef HAVE_LIBPCRE
3095 <        void *exp_p = NULL;
3096 <        const char *errptr = NULL;
3097 <
3098 <        if (!(exp_p = ircd_pcre_compile(gecos_name, &errptr)))
3099 <        {
3100 <          ilog(L_ERROR, "Failed to add regular expression based X-Line: %s",
3101 <               errptr);
3102 <          break;
3103 <        }
3104 <
3105 <        yy_conf = make_conf_item(RXLINE_TYPE);
3106 <        yy_conf->regexpname = exp_p;
3107 < #else
3108 <        ilog(L_ERROR, "Failed to add regular expression based X-Line: no PCRE support");
3109 <        break;
3110 < #endif
3111 <      }
3112 <      else
3113 <        yy_conf = make_conf_item(XLINE_TYPE);
2361 >  struct MaskItem *conf = NULL;
2362  
2363 <      yy_match_item = map_to_conf(yy_conf);
2364 <      DupString(yy_conf->name, gecos_name);
2363 >  if (conf_parser_ctx.pass != 2)
2364 >    break;
2365  
2366 <      if (reasonbuf[0])
2367 <        DupString(yy_match_item->reason, reasonbuf);
3120 <      else
3121 <        DupString(yy_match_item->reason, "No reason");
3122 <    }
3123 <  }
3124 < };
2366 >  if (!block_state.name.buf[0])
2367 >    break;
2368  
2369 < gecos_flags: TYPE
2370 < {
3128 < } '='  gecos_flags_items ';';
2369 >  conf = conf_make(CONF_XLINE);
2370 >  conf->name = xstrdup(block_state.name.buf);
2371  
2372 < gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2373 < gecos_flags_item: REGEX_T
2374 < {
2375 <  if (conf_parser_ctx.pass == 2)
3134 <    regex_ban = 1;
2372 >  if (block_state.rpass.buf[0])
2373 >    conf->reason = xstrdup(block_state.rpass.buf);
2374 >  else
2375 >    conf->reason = xstrdup(CONF_NOREASON);
2376   };
2377  
2378   gecos_items: gecos_items gecos_item | gecos_item;
2379 < gecos_item:  gecos_name | gecos_reason | gecos_flags | error;
2379 > gecos_item:  gecos_name | gecos_reason | error;
2380  
2381   gecos_name: NAME '=' QSTRING ';'
2382   {
2383    if (conf_parser_ctx.pass == 2)
2384 <    strlcpy(gecos_name, yylval.string, sizeof(gecos_name));
2384 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2385   };
2386  
2387   gecos_reason: REASON '=' QSTRING ';'
2388   {
2389    if (conf_parser_ctx.pass == 2)
2390 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2390 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2391   };
2392  
2393   /***************************************************************************
# Line 3161 | Line 2402 | general_item:       general_hide_spoof_i
2402                      general_max_nick_time | general_max_nick_changes |
2403                      general_max_accept | general_anti_spam_exit_message_time |
2404                      general_ts_warn_delta | general_ts_max_delta |
2405 <                    general_kill_chase_time_limit | general_kline_with_reason |
2406 <                    general_kline_reason | general_invisible_on_connect |
2405 >                    general_kill_chase_time_limit |
2406 >                    general_invisible_on_connect |
2407                      general_warn_no_nline | general_dots_in_ident |
2408                      general_stats_o_oper_only | general_stats_k_oper_only |
2409                      general_pace_wait | general_stats_i_oper_only |
2410                      general_pace_wait_simple | general_stats_P_oper_only |
2411                      general_short_motd | general_no_oper_flood |
2412                      general_true_no_oper_flood | general_oper_pass_resv |
3172                    general_idletime | general_message_locale |
2413                      general_oper_only_umodes | general_max_targets |
2414                      general_use_egd | general_egdpool_path |
2415                      general_oper_umodes | general_caller_id_wait |
2416                      general_opers_bypass_callerid | general_default_floodcount |
2417                      general_min_nonwildcard | general_min_nonwildcard_simple |
3178                    general_servlink_path | general_disable_remote_commands |
3179                    general_default_cipher_preference |
3180                    general_compression_level | general_client_flood |
2418                      general_throttle_time | general_havent_read_conf |
2419 <                    general_dot_in_ip6_addr | general_ping_cookie |
2420 <                    general_disable_auth | general_burst_away |
2421 <                    general_tkline_expire_notices | general_gline_min_cidr |
2422 <                    general_gline_min_cidr6 | general_use_whois_actually |
2423 <                    general_reject_hold_time | general_stats_e_disabled |
2424 <                    general_max_watch |
2419 >                    general_ping_cookie |
2420 >                    general_disable_auth |
2421 >                    general_tkline_expire_notices | general_gline_enable |
2422 >                    general_gline_duration | general_gline_request_duration |
2423 >                    general_gline_min_cidr |
2424 >                    general_gline_min_cidr6 |
2425 >                    general_stats_e_disabled |
2426 >                    general_max_watch | general_services_name |
2427                      error;
2428  
2429  
# Line 3193 | Line 2432 | general_max_watch: MAX_WATCH '=' NUMBER
2432    ConfigFileEntry.max_watch = $3;
2433   };
2434  
2435 < general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2435 > general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2436   {
2437 <  ConfigFileEntry.gline_min_cidr = $3;
2437 >  if (conf_parser_ctx.pass == 2)
2438 >    ConfigFileEntry.glines = yylval.number;
2439   };
2440  
2441 < general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2441 > general_gline_duration: GLINE_DURATION '=' timespec ';'
2442   {
2443 <  ConfigFileEntry.gline_min_cidr6 = $3;
2443 >  if (conf_parser_ctx.pass == 2)
2444 >    ConfigFileEntry.gline_time = $3;
2445   };
2446  
2447 < general_burst_away: BURST_AWAY '=' TBOOL ';'
2447 > general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2448   {
2449 <  ConfigFileEntry.burst_away = yylval.number;
2449 >  if (conf_parser_ctx.pass == 2)
2450 >    ConfigFileEntry.gline_request_time = $3;
2451   };
2452  
2453 < general_use_whois_actually: USE_WHOIS_ACTUALLY '=' TBOOL ';'
2453 > general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2454   {
2455 <  ConfigFileEntry.use_whois_actually = yylval.number;
2455 >  ConfigFileEntry.gline_min_cidr = $3;
2456   };
2457  
2458 < general_reject_hold_time: TREJECT_HOLD_TIME '=' timespec ';'
2458 > general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2459   {
2460 <  GlobalSetOptions.rejecttime = yylval.number;
2460 >  ConfigFileEntry.gline_min_cidr6 = $3;
2461   };
2462  
2463   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
# Line 3223 | Line 2465 | general_tkline_expire_notices: TKLINE_EX
2465    ConfigFileEntry.tkline_expire_notices = yylval.number;
2466   };
2467  
2468 < general_kill_chase_time_limit: KILL_CHASE_TIME_LIMIT '=' NUMBER ';'
2468 > general_kill_chase_time_limit: KILL_CHASE_TIME_LIMIT '=' timespec ';'
2469   {
2470    ConfigFileEntry.kill_chase_time_limit = $3;
2471   };
# Line 3238 | Line 2480 | general_ignore_bogus_ts: IGNORE_BOGUS_TS
2480    ConfigFileEntry.ignore_bogus_ts = yylval.number;
2481   };
2482  
3241 general_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
3242 {
3243  ConfigFileEntry.disable_remote = yylval.number;
3244 };
3245
2483   general_failed_oper_notice: FAILED_OPER_NOTICE '=' TBOOL ';'
2484   {
2485    ConfigFileEntry.failed_oper_notice = yylval.number;
# Line 3288 | Line 2525 | general_havent_read_conf: HAVENT_READ_CO
2525   {
2526    if (($3 > 0) && conf_parser_ctx.pass == 1)
2527    {
2528 <    ilog(L_CRIT, "You haven't read your config file properly.");
2529 <    ilog(L_CRIT, "There is a line in the example conf that will kill your server if not removed.");
2530 <    ilog(L_CRIT, "Consider actually reading/editing the conf file, and removing this line.");
2528 >    ilog(LOG_TYPE_IRCD, "You haven't read your config file properly.");
2529 >    ilog(LOG_TYPE_IRCD, "There is a line in the example conf that will kill your server if not removed.");
2530 >    ilog(LOG_TYPE_IRCD, "Consider actually reading/editing the conf file, and removing this line.");
2531      exit(0);
2532    }
2533   };
2534  
3298 general_kline_with_reason: KLINE_WITH_REASON '=' TBOOL ';'
3299 {
3300  ConfigFileEntry.kline_with_reason = yylval.number;
3301 };
3302
3303 general_kline_reason: KLINE_REASON '=' QSTRING ';'
3304 {
3305  if (conf_parser_ctx.pass == 2)
3306  {
3307    MyFree(ConfigFileEntry.kline_reason);
3308    DupString(ConfigFileEntry.kline_reason, yylval.string);
3309  }
3310 };
3311
2535   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2536   {
2537    ConfigFileEntry.invisible_on_connect = yylval.number;
# Line 3390 | Line 2613 | general_oper_pass_resv: OPER_PASS_RESV '
2613    ConfigFileEntry.oper_pass_resv = yylval.number;
2614   };
2615  
3393 general_message_locale: MESSAGE_LOCALE '=' QSTRING ';'
3394 {
3395  if (conf_parser_ctx.pass == 2)
3396  {
3397    if (strlen(yylval.string) > LOCALE_LENGTH-2)
3398      yylval.string[LOCALE_LENGTH-1] = '\0';
3399
3400    set_locale(yylval.string);
3401  }
3402 };
3403
3404 general_idletime: IDLETIME '=' timespec ';'
3405 {
3406  ConfigFileEntry.idletime = $3;
3407 };
3408
2616   general_dots_in_ident: DOTS_IN_IDENT '=' NUMBER ';'
2617   {
2618    ConfigFileEntry.dots_in_ident = $3;
# Line 3416 | Line 2623 | general_max_targets: MAX_TARGETS '=' NUM
2623    ConfigFileEntry.max_targets = $3;
2624   };
2625  
2626 < general_servlink_path: SERVLINK_PATH '=' QSTRING ';'
3420 < {
3421 <  if (conf_parser_ctx.pass == 2)
3422 <  {
3423 <    MyFree(ConfigFileEntry.servlink_path);
3424 <    DupString(ConfigFileEntry.servlink_path, yylval.string);
3425 <  }
3426 < };
3427 <
3428 < general_default_cipher_preference: DEFAULT_CIPHER_PREFERENCE '=' QSTRING ';'
2626 > general_use_egd: USE_EGD '=' TBOOL ';'
2627   {
2628 < #ifdef HAVE_LIBCRYPTO
3431 <  if (conf_parser_ctx.pass == 2)
3432 <  {
3433 <    struct EncCapability *ecap;
3434 <    const char *cipher_name;
3435 <    int found = 0;
3436 <
3437 <    ConfigFileEntry.default_cipher_preference = NULL;
3438 <    cipher_name = yylval.string;
3439 <
3440 <    for (ecap = CipherTable; ecap->name; ecap++)
3441 <    {
3442 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
3443 <          (ecap->cap & CAP_ENC_MASK))
3444 <      {
3445 <        ConfigFileEntry.default_cipher_preference = ecap;
3446 <        found = 1;
3447 <        break;
3448 <      }
3449 <    }
3450 <
3451 <    if (!found)
3452 <      yyerror("Invalid cipher");
3453 <  }
3454 < #else
3455 <  if (conf_parser_ctx.pass == 2)
3456 <    yyerror("Ignoring default_cipher_preference -- no OpenSSL support");
3457 < #endif
2628 >  ConfigFileEntry.use_egd = yylval.number;
2629   };
2630  
2631 < general_compression_level: COMPRESSION_LEVEL '=' NUMBER ';'
2631 > general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
2632   {
2633    if (conf_parser_ctx.pass == 2)
2634    {
2635 <    ConfigFileEntry.compression_level = $3;
2636 < #ifndef HAVE_LIBZ
3466 <    yyerror("Ignoring compression_level -- no zlib support");
3467 < #else
3468 <    if ((ConfigFileEntry.compression_level < 1) ||
3469 <        (ConfigFileEntry.compression_level > 9))
3470 <    {
3471 <      yyerror("Ignoring invalid compression_level, using default");
3472 <      ConfigFileEntry.compression_level = 0;
3473 <    }
3474 < #endif
2635 >    MyFree(ConfigFileEntry.egdpool_path);
2636 >    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2637    }
2638   };
2639  
2640 < general_use_egd: USE_EGD '=' TBOOL ';'
2640 > general_services_name: T_SERVICES_NAME '=' QSTRING ';'
2641   {
2642 <  ConfigFileEntry.use_egd = yylval.number;
3481 < };
3482 <
3483 < general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
3484 < {
3485 <  if (conf_parser_ctx.pass == 2)
2642 >  if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2643    {
2644 <    MyFree(ConfigFileEntry.egdpool_path);
2645 <    DupString(ConfigFileEntry.egdpool_path, yylval.string);
2644 >    MyFree(ConfigFileEntry.service_name);
2645 >    ConfigFileEntry.service_name = xstrdup(yylval.string);
2646    }
2647   };
2648  
# Line 3516 | Line 2673 | umode_oitem:     T_BOTS
2673   } | T_CCONN
2674   {
2675    ConfigFileEntry.oper_umodes |= UMODE_CCONN;
3519 } | T_CCONN_FULL
3520 {
3521  ConfigFileEntry.oper_umodes |= UMODE_CCONN_FULL;
2676   } | T_DEAF
2677   {
2678    ConfigFileEntry.oper_umodes |= UMODE_DEAF;
# Line 3528 | Line 2682 | umode_oitem:     T_BOTS
2682   } | T_FULL
2683   {
2684    ConfigFileEntry.oper_umodes |= UMODE_FULL;
2685 + } | HIDDEN
2686 + {
2687 +  ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2688   } | T_SKILL
2689   {
2690    ConfigFileEntry.oper_umodes |= UMODE_SKILL;
# Line 3567 | Line 2724 | umode_oitem:     T_BOTS
2724   } | T_LOCOPS
2725   {
2726    ConfigFileEntry.oper_umodes |= UMODE_LOCOPS;
2727 + } | T_NONONREG
2728 + {
2729 +  ConfigFileEntry.oper_umodes |= UMODE_REGONLY;
2730 + } | T_FARCONNECT
2731 + {
2732 +  ConfigFileEntry.oper_umodes |= UMODE_FARCONNECT;
2733   };
2734  
2735   general_oper_only_umodes: OPER_ONLY_UMODES
# Line 3581 | Line 2744 | umode_item:    T_BOTS
2744   } | T_CCONN
2745   {
2746    ConfigFileEntry.oper_only_umodes |= UMODE_CCONN;
3584 } | T_CCONN_FULL
3585 {
3586  ConfigFileEntry.oper_only_umodes |= UMODE_CCONN_FULL;
2747   } | T_DEAF
2748   {
2749    ConfigFileEntry.oper_only_umodes |= UMODE_DEAF;
# Line 3596 | Line 2756 | umode_item:    T_BOTS
2756   } | T_SKILL
2757   {
2758    ConfigFileEntry.oper_only_umodes |= UMODE_SKILL;
2759 + } | HIDDEN
2760 + {
2761 +  ConfigFileEntry.oper_only_umodes |= UMODE_HIDDEN;
2762   } | T_NCHANGE
2763   {
2764    ConfigFileEntry.oper_only_umodes |= UMODE_NCHANGE;
# Line 3632 | Line 2795 | umode_item:    T_BOTS
2795   } | T_LOCOPS
2796   {
2797    ConfigFileEntry.oper_only_umodes |= UMODE_LOCOPS;
2798 + } | T_NONONREG
2799 + {
2800 +  ConfigFileEntry.oper_only_umodes |= UMODE_REGONLY;
2801 + } | T_FARCONNECT
2802 + {
2803 +  ConfigFileEntry.oper_only_umodes |= UMODE_FARCONNECT;
2804   };
2805  
2806   general_min_nonwildcard: MIN_NONWILDCARD '=' NUMBER ';'
# Line 3649 | Line 2818 | general_default_floodcount: DEFAULT_FLOO
2818    ConfigFileEntry.default_floodcount = $3;
2819   };
2820  
3652 general_client_flood: T_CLIENT_FLOOD '=' sizespec ';'
3653 {
3654  ConfigFileEntry.client_flood = $3;
3655 };
3656
3657 general_dot_in_ip6_addr: DOT_IN_IP6_ADDR '=' TBOOL ';'
3658 {
3659  ConfigFileEntry.dot_in_ip6_addr = yylval.number;
3660 };
3661
3662 /***************************************************************************
3663 *  section glines
3664 ***************************************************************************/
3665 gline_entry: GLINES
3666 {
3667  if (conf_parser_ctx.pass == 2)
3668  {
3669    yy_conf = make_conf_item(GDENY_TYPE);
3670    yy_aconf = map_to_conf(yy_conf);
3671  }
3672 } '{' gline_items '}' ';'
3673 {
3674  if (conf_parser_ctx.pass == 2)
3675  {
3676    /*
3677     * since we re-allocate yy_conf/yy_aconf after the end of action=, at the
3678     * end we will have one extra, so we should free it.
3679     */
3680    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3681    {
3682      delete_conf_item(yy_conf);
3683      yy_conf = NULL;
3684      yy_aconf = NULL;
3685    }
3686  }
3687 };
3688
3689 gline_items:        gline_items gline_item | gline_item;
3690 gline_item:         gline_enable |
3691                    gline_duration |
3692                    gline_logging |
3693                    gline_user |
3694                    gline_server |
3695                    gline_action |
3696                    error;
3697
3698 gline_enable: ENABLE '=' TBOOL ';'
3699 {
3700  if (conf_parser_ctx.pass == 2)
3701    ConfigFileEntry.glines = yylval.number;
3702 };
3703
3704 gline_duration: DURATION '=' timespec ';'
3705 {
3706  if (conf_parser_ctx.pass == 2)
3707    ConfigFileEntry.gline_time = $3;
3708 };
3709
3710 gline_logging: LOGGING
3711 {
3712  if (conf_parser_ctx.pass == 2)
3713    ConfigFileEntry.gline_logging = 0;
3714 } '=' gline_logging_types ';';
3715 gline_logging_types:     gline_logging_types ',' gline_logging_type_item | gline_logging_type_item;
3716 gline_logging_type_item: T_REJECT
3717 {
3718  if (conf_parser_ctx.pass == 2)
3719    ConfigFileEntry.gline_logging |= GDENY_REJECT;
3720 } | T_BLOCK
3721 {
3722  if (conf_parser_ctx.pass == 2)
3723    ConfigFileEntry.gline_logging |= GDENY_BLOCK;
3724 };
3725
3726 gline_user: USER '=' QSTRING ';'
3727 {
3728  if (conf_parser_ctx.pass == 2)
3729  {
3730    struct split_nuh_item nuh;
3731
3732    nuh.nuhmask  = yylval.string;
3733    nuh.nickptr  = NULL;
3734    nuh.userptr  = userbuf;
3735    nuh.hostptr  = hostbuf;
3736
3737    nuh.nicksize = 0;
3738    nuh.usersize = sizeof(userbuf);
3739    nuh.hostsize = sizeof(hostbuf);
3740
3741    split_nuh(&nuh);
3742
3743    if (yy_aconf->user == NULL)
3744    {
3745      DupString(yy_aconf->user, userbuf);
3746      DupString(yy_aconf->host, hostbuf);
3747    }
3748    else
3749    {
3750      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
3751
3752      DupString(yy_tmp->user, userbuf);
3753      DupString(yy_tmp->host, hostbuf);
3754
3755      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
3756    }
3757  }
3758 };
3759
3760 gline_server: NAME '=' QSTRING ';'
3761 {
3762  if (conf_parser_ctx.pass == 2)  
3763  {
3764    MyFree(yy_conf->name);
3765    DupString(yy_conf->name, yylval.string);
3766  }
3767 };
3768
3769 gline_action: ACTION
3770 {
3771  if (conf_parser_ctx.pass == 2)
3772    yy_aconf->flags = 0;
3773 } '=' gdeny_types ';'
3774 {
3775  if (conf_parser_ctx.pass == 2)
3776  {
3777    struct CollectItem *yy_tmp = NULL;
3778    dlink_node *ptr, *next_ptr;
3779
3780    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
3781    {
3782      struct AccessItem *new_aconf;
3783      struct ConfItem *new_conf;
3784
3785      yy_tmp = ptr->data;
3786      new_conf = make_conf_item(GDENY_TYPE);
3787      new_aconf = map_to_conf(new_conf);
3788
3789      new_aconf->flags = yy_aconf->flags;
3790
3791      if (yy_conf->name != NULL)
3792        DupString(new_conf->name, yy_conf->name);
3793      else
3794        DupString(new_conf->name, "*");
3795      if (yy_aconf->user != NULL)
3796         DupString(new_aconf->user, yy_tmp->user);
3797      else  
3798        DupString(new_aconf->user, "*");
3799      if (yy_aconf->host != NULL)
3800        DupString(new_aconf->host, yy_tmp->host);
3801      else
3802        DupString(new_aconf->host, "*");
3803
3804      dlinkDelete(&yy_tmp->node, &col_conf_list);
3805    }
3806
3807    /*
3808     * In case someone has fed us with more than one action= after user/name
3809     * which would leak memory  -Michael
3810     */
3811    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3812      delete_conf_item(yy_conf);
3813
3814    yy_conf = make_conf_item(GDENY_TYPE);
3815    yy_aconf = map_to_conf(yy_conf);
3816  }
3817 };
3818
3819 gdeny_types: gdeny_types ',' gdeny_type_item | gdeny_type_item;
3820 gdeny_type_item: T_REJECT
3821 {
3822  if (conf_parser_ctx.pass == 2)
3823    yy_aconf->flags |= GDENY_REJECT;
3824 } | T_BLOCK
3825 {
3826  if (conf_parser_ctx.pass == 2)
3827    yy_aconf->flags |= GDENY_BLOCK;
3828 };
2821  
2822   /***************************************************************************
2823   *  section channel
# Line 3834 | Line 2826 | channel_entry: CHANNEL
2826    '{' channel_items '}' ';';
2827  
2828   channel_items:      channel_items channel_item | channel_item;
2829 < channel_item:       channel_disable_local_channels | channel_use_except |
2830 <                    channel_use_invex | channel_use_knock |
2831 <                    channel_max_bans | channel_knock_delay |
2832 <                    channel_knock_delay_channel | channel_max_chans_per_user |
3841 <                    channel_quiet_on_ban | channel_default_split_user_count |
2829 > channel_item:       channel_max_bans |
2830 >                    channel_knock_delay | channel_knock_delay_channel |
2831 >                    channel_max_chans_per_user | channel_max_chans_per_oper |
2832 >                    channel_default_split_user_count |
2833                      channel_default_split_server_count |
2834 <                    channel_no_create_on_split | channel_restrict_channels |
2835 <                    channel_no_join_on_split | channel_burst_topicwho |
2834 >                    channel_no_create_on_split |
2835 >                    channel_no_join_on_split |
2836                      channel_jflood_count | channel_jflood_time |
2837                      channel_disable_fake_channels | error;
2838  
# Line 3850 | Line 2841 | channel_disable_fake_channels: DISABLE_F
2841    ConfigChannel.disable_fake_channels = yylval.number;
2842   };
2843  
3853 channel_restrict_channels: RESTRICT_CHANNELS '=' TBOOL ';'
3854 {
3855  ConfigChannel.restrict_channels = yylval.number;
3856 };
3857
3858 channel_disable_local_channels: DISABLE_LOCAL_CHANNELS '=' TBOOL ';'
3859 {
3860  ConfigChannel.disable_local_channels = yylval.number;
3861 };
3862
3863 channel_use_except: USE_EXCEPT '=' TBOOL ';'
3864 {
3865  ConfigChannel.use_except = yylval.number;
3866 };
3867
3868 channel_use_invex: USE_INVEX '=' TBOOL ';'
3869 {
3870  ConfigChannel.use_invex = yylval.number;
3871 };
3872
3873 channel_use_knock: USE_KNOCK '=' TBOOL ';'
3874 {
3875  ConfigChannel.use_knock = yylval.number;
3876 };
3877
2844   channel_knock_delay: KNOCK_DELAY '=' timespec ';'
2845   {
2846    ConfigChannel.knock_delay = $3;
# Line 3890 | Line 2856 | channel_max_chans_per_user: MAX_CHANS_PE
2856    ConfigChannel.max_chans_per_user = $3;
2857   };
2858  
2859 < channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
2859 > channel_max_chans_per_oper: MAX_CHANS_PER_OPER '=' NUMBER ';'
2860   {
2861 <  ConfigChannel.quiet_on_ban = yylval.number;
2861 >  ConfigChannel.max_chans_per_oper = $3;
2862   };
2863  
2864   channel_max_bans: MAX_BANS '=' NUMBER ';'
# Line 3920 | Line 2886 | channel_no_join_on_split: NO_JOIN_ON_SPL
2886    ConfigChannel.no_join_on_split = yylval.number;
2887   };
2888  
3923 channel_burst_topicwho: BURST_TOPICWHO '=' TBOOL ';'
3924 {
3925  ConfigChannel.burst_topicwho = yylval.number;
3926 };
3927
2889   channel_jflood_count: JOIN_FLOOD_COUNT '=' NUMBER ';'
2890   {
2891    GlobalSetOptions.joinfloodcount = yylval.number;
# Line 3942 | Line 2903 | serverhide_entry: SERVERHIDE
2903    '{' serverhide_items '}' ';';
2904  
2905   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
2906 < serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
2906 > serverhide_item:    serverhide_flatten_links | serverhide_disable_remote_commands |
2907 >                    serverhide_hide_servers |
2908 >                    serverhide_hide_services |
2909                      serverhide_links_delay |
3947                    serverhide_disable_hidden |
2910                      serverhide_hidden | serverhide_hidden_name |
2911                      serverhide_hide_server_ips |
2912                      error;
# Line 3955 | Line 2917 | serverhide_flatten_links: FLATTEN_LINKS
2917      ConfigServerHide.flatten_links = yylval.number;
2918   };
2919  
2920 + serverhide_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2921 + {
2922 +  if (conf_parser_ctx.pass == 2)
2923 +    ConfigServerHide.disable_remote_commands = yylval.number;
2924 + };
2925 +
2926   serverhide_hide_servers: HIDE_SERVERS '=' TBOOL ';'
2927   {
2928    if (conf_parser_ctx.pass == 2)
2929      ConfigServerHide.hide_servers = yylval.number;
2930   };
2931  
2932 + serverhide_hide_services: HIDE_SERVICES '=' TBOOL ';'
2933 + {
2934 +  if (conf_parser_ctx.pass == 2)
2935 +    ConfigServerHide.hide_services = yylval.number;
2936 + };
2937 +
2938   serverhide_hidden_name: HIDDEN_NAME '=' QSTRING ';'
2939   {
2940    if (conf_parser_ctx.pass == 2)
2941    {
2942      MyFree(ConfigServerHide.hidden_name);
2943 <    DupString(ConfigServerHide.hidden_name, yylval.string);
2943 >    ConfigServerHide.hidden_name = xstrdup(yylval.string);
2944    }
2945   };
2946  
# Line 3990 | Line 2964 | serverhide_hidden: HIDDEN '=' TBOOL ';'
2964      ConfigServerHide.hidden = yylval.number;
2965   };
2966  
3993 serverhide_disable_hidden: DISABLE_HIDDEN '=' TBOOL ';'
3994 {
3995  if (conf_parser_ctx.pass == 2)
3996    ConfigServerHide.disable_hidden = yylval.number;
3997 };
3998
2967   serverhide_hide_server_ips: HIDE_SERVER_IPS '=' TBOOL ';'
2968   {
2969    if (conf_parser_ctx.pass == 2)

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)