ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing:
ircd-hybrid-7.2/src/ircd_parser.y (file contents), Revision 1024 by michael, Sun Nov 1 23:14:25 2009 UTC vs.
ircd-hybrid/trunk/src/conf_parser.y (file contents), Revision 4070 by michael, Thu Jun 26 15:36:08 2014 UTC

# Line 1 | Line 1
1   /*
2 < *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  ircd_parser.y: Parses the ircd configuration file.
2 > *  ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3   *
4 < *  Copyright (C) 2005 by the past and present ircd coders, and others.
4 > *  Copyright (c) 2000-2014 ircd-hybrid development team
5   *
6   *  This program is free software; you can redistribute it and/or modify
7   *  it under the terms of the GNU General Public License as published by
# Line 18 | Line 17
17   *  along with this program; if not, write to the Free Software
18   *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
19   *  USA
21 *
22 *  $Id$
20   */
21  
22 + /*! \file conf_parser.y
23 + * \brief Parses the ircd configuration file.
24 + * \version $Id$
25 + */
26 +
27 +
28   %{
29  
30   #define YY_NO_UNPUT
# Line 32 | Line 35
35   #include "stdinc.h"
36   #include "ircd.h"
37   #include "list.h"
38 < #include "s_conf.h"
38 > #include "conf.h"
39 > #include "conf_class.h"
40   #include "event.h"
41 < #include "s_log.h"
41 > #include "log.h"
42   #include "client.h"     /* for UMODE_ALL only */
43   #include "irc_string.h"
40 #include "irc_getaddrinfo.h"
41 #include "sprintf_irc.h"
44   #include "memory.h"
45   #include "modules.h"
46 < #include "s_serv.h"
46 > #include "server.h"
47   #include "hostmask.h"
48   #include "send.h"
49   #include "listener.h"
50   #include "resv.h"
51   #include "numeric.h"
52 < #include "s_user.h"
52 > #include "user.h"
53 > #include "motd.h"
54  
55   #ifdef HAVE_LIBCRYPTO
56   #include <openssl/rsa.h>
57   #include <openssl/bio.h>
58   #include <openssl/pem.h>
59 + #include <openssl/dh.h>
60   #endif
61  
62 < static char *class_name = NULL;
59 < static struct ConfItem *yy_conf = NULL;
60 < static struct AccessItem *yy_aconf = NULL;
61 < static struct MatchItem *yy_match_item = NULL;
62 < static struct ClassItem *yy_class = NULL;
63 < static char *yy_class_name = NULL;
64 <
65 < static dlink_list col_conf_list  = { NULL, NULL, 0 };
66 < static dlink_list hub_conf_list  = { NULL, NULL, 0 };
67 < static dlink_list leaf_conf_list = { NULL, NULL, 0 };
68 < static unsigned int listener_flags = 0;
69 < static unsigned int regex_ban = 0;
70 < static char userbuf[IRCD_BUFSIZE];
71 < static char hostbuf[IRCD_BUFSIZE];
72 < static char reasonbuf[REASONLEN + 1];
73 < static char gecos_name[REALLEN * 4];
74 <
75 < static char *resv_reason = NULL;
76 < static char *listener_address = NULL;
77 < static int not_atom = 0;
78 <
79 < struct CollectItem
80 < {
81 <  dlink_node node;
82 <  char *name;
83 <  char *user;
84 <  char *host;
85 <  char *passwd;
86 <  int  port;
87 <  int  flags;
88 < #ifdef HAVE_LIBCRYPTO
89 <  char *rsa_public_key_file;
90 <  RSA *rsa_public_key;
91 < #endif
92 < };
62 > #include "rsa.h"
63  
64 < static void
65 < free_collect_item(struct CollectItem *item)
64 > int yylex(void);
65 >
66 > static struct
67   {
68 <  MyFree(item->name);
69 <  MyFree(item->user);
70 <  MyFree(item->host);
71 <  MyFree(item->passwd);
72 < #ifdef HAVE_LIBCRYPTO
73 <  MyFree(item->rsa_public_key_file);
74 < #endif
75 <  MyFree(item);
76 < }
68 >  struct
69 >  {
70 >    dlink_list list;
71 >  } mask,
72 >    leaf,
73 >    hub;
74 >
75 >  struct
76 >  {
77 >    char buf[IRCD_BUFSIZE];
78 >  } name,
79 >    user,
80 >    host,
81 >    addr,
82 >    bind,
83 >    file,
84 >    ciph,
85 >    cert,
86 >    rpass,
87 >    spass,
88 >    class;
89 >
90 >  struct
91 >  {
92 >    unsigned int value;
93 >  } flags,
94 >    modes,
95 >    size,
96 >    type,
97 >    port,
98 >    aftype,
99 >    ping_freq,
100 >    max_perip,
101 >    con_freq,
102 >    min_idle,
103 >    max_idle,
104 >    max_total,
105 >    max_global,
106 >    max_local,
107 >    max_ident,
108 >    max_sendq,
109 >    max_recvq,
110 >    max_channels,
111 >    cidr_bitlen_ipv4,
112 >    cidr_bitlen_ipv6,
113 >    number_per_cidr;
114 > } block_state;
115  
116   static void
117 < unhook_hub_leaf_confs(void)
117 > reset_block_state(void)
118   {
119 <  dlink_node *ptr;
120 <  dlink_node *next_ptr;
121 <  struct CollectItem *yy_hconf;
122 <  struct CollectItem *yy_lconf;
119 >  dlink_node *ptr = NULL, *ptr_next = NULL;
120 >
121 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.mask.list.head)
122 >  {
123 >    MyFree(ptr->data);
124 >    dlinkDelete(ptr, &block_state.mask.list);
125 >    free_dlink_node(ptr);
126 >  }
127  
128 <  DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
128 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.leaf.list.head)
129    {
130 <    yy_hconf = ptr->data;
131 <    dlinkDelete(&yy_hconf->node, &hub_conf_list);
132 <    free_collect_item(yy_hconf);
130 >    MyFree(ptr->data);
131 >    dlinkDelete(ptr, &block_state.leaf.list);
132 >    free_dlink_node(ptr);
133    }
134  
135 <  DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
135 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.hub.list.head)
136    {
137 <    yy_lconf = ptr->data;
138 <    dlinkDelete(&yy_lconf->node, &leaf_conf_list);
139 <    free_collect_item(yy_lconf);
137 >    MyFree(ptr->data);
138 >    dlinkDelete(ptr, &block_state.hub.list);
139 >    free_dlink_node(ptr);
140    }
141 +
142 +  memset(&block_state, 0, sizeof(block_state));
143   }
144  
145   %}
# Line 135 | Line 150 | unhook_hub_leaf_confs(void)
150   }
151  
152   %token  ACCEPT_PASSWORD
138 %token  ACTION
153   %token  ADMIN
154   %token  AFTYPE
141 %token  T_ALLOW
155   %token  ANTI_NICK_FLOOD
156   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
157   %token  AUTOCONN
158 < %token  T_BLOCK
146 < %token  BURST_AWAY
147 < %token  BURST_TOPICWHO
148 < %token  BYTES KBYTES MBYTES GBYTES TBYTES
158 > %token  BYTES KBYTES MBYTES
159   %token  CALLER_ID_WAIT
160   %token  CAN_FLOOD
151 %token  CAN_IDLE
161   %token  CHANNEL
162 < %token  CIDR_BITLEN_IPV4
163 < %token  CIDR_BITLEN_IPV6
155 < %token  CIPHER_PREFERENCE
162 > %token  CIDR_BITLEN_IPV4
163 > %token  CIDR_BITLEN_IPV6
164   %token  CLASS
157 %token  COMPRESSED
158 %token  COMPRESSION_LEVEL
165   %token  CONNECT
166   %token  CONNECTFREQ
167 < %token  CRYPTLINK
162 < %token  DEFAULT_CIPHER_PREFERENCE
167 > %token  CYCLE_ON_HOST_CHANGE
168   %token  DEFAULT_FLOODCOUNT
169   %token  DEFAULT_SPLIT_SERVER_COUNT
170   %token  DEFAULT_SPLIT_USER_COUNT
# Line 168 | Line 173 | unhook_hub_leaf_confs(void)
173   %token  DIE
174   %token  DISABLE_AUTH
175   %token  DISABLE_FAKE_CHANNELS
171 %token  DISABLE_HIDDEN
172 %token  DISABLE_LOCAL_CHANNELS
176   %token  DISABLE_REMOTE_COMMANDS
174 %token  DOT_IN_IP6_ADDR
177   %token  DOTS_IN_IDENT
176 %token  DURATION
178   %token  EGDPOOL_PATH
179   %token  EMAIL
179 %token  ENABLE
180   %token  ENCRYPTED
181   %token  EXCEED_LIMIT
182   %token  EXEMPT
183   %token  FAILED_OPER_NOTICE
184 %token  FAKENAME
185 %token  IRCD_FLAGS
184   %token  FLATTEN_LINKS
187 %token  FFAILED_OPERLOG
188 %token  FKILLLOG
189 %token  FKLINELOG
190 %token  FGLINELOG
191 %token  FIOERRLOG
192 %token  FOPERLOG
193 %token  FOPERSPYLOG
194 %token  FUSERLOG
185   %token  GECOS
186   %token  GENERAL
187   %token  GLINE
188 < %token  GLINES
188 > %token  GLINE_DURATION
189 > %token  GLINE_ENABLE
190   %token  GLINE_EXEMPT
200 %token  GLINE_LOG
201 %token  GLINE_TIME
191   %token  GLINE_MIN_CIDR
192   %token  GLINE_MIN_CIDR6
193 + %token  GLINE_REQUEST_DURATION
194   %token  GLOBAL_KILL
205 %token  IRCD_AUTH
206 %token  NEED_IDENT
195   %token  HAVENT_READ_CONF
196   %token  HIDDEN
197 < %token  HIDDEN_ADMIN
198 < %token  HIDDEN_NAME
199 < %token  HIDDEN_OPER
197 > %token  HIDDEN_NAME
198 > %token  HIDE_CHANS
199 > %token  HIDE_IDLE
200 > %token  HIDE_IDLE_FROM_OPERS
201   %token  HIDE_SERVER_IPS
202   %token  HIDE_SERVERS
203 < %token  HIDE_SPOOF_IPS
203 > %token  HIDE_SERVICES
204 > %token  HIDE_SPOOF_IPS
205   %token  HOST
206   %token  HUB
207   %token  HUB_MASK
218 %token  IDLETIME
208   %token  IGNORE_BOGUS_TS
209   %token  INVISIBLE_ON_CONNECT
210 + %token  INVITE_CLIENT_COUNT
211 + %token  INVITE_CLIENT_TIME
212   %token  IP
213 + %token  IRCD_AUTH
214 + %token  IRCD_FLAGS
215 + %token  IRCD_SID
216 + %token  JOIN_FLOOD_COUNT
217 + %token  JOIN_FLOOD_TIME
218   %token  KILL
219 < %token  KILL_CHASE_TIME_LIMIT
219 > %token  KILL_CHASE_TIME_LIMIT
220   %token  KLINE
221   %token  KLINE_EXEMPT
222 < %token  KLINE_REASON
223 < %token  KLINE_WITH_REASON
228 < %token  KNOCK_DELAY
222 > %token  KNOCK_CLIENT_COUNT
223 > %token  KNOCK_CLIENT_TIME
224   %token  KNOCK_DELAY_CHANNEL
225   %token  LEAF_MASK
226   %token  LINKS_DELAY
227   %token  LISTEN
228 < %token  T_LOG
234 < %token  LOGGING
235 < %token  LOG_LEVEL
228 > %token  MASK
229   %token  MAX_ACCEPT
230   %token  MAX_BANS
231 < %token  MAX_CHANS_PER_USER
231 > %token  MAX_CHANNELS
232   %token  MAX_GLOBAL
233   %token  MAX_IDENT
234 + %token  MAX_IDLE
235   %token  MAX_LOCAL
236   %token  MAX_NICK_CHANGES
237 + %token  MAX_NICK_LENGTH
238   %token  MAX_NICK_TIME
239   %token  MAX_NUMBER
240   %token  MAX_TARGETS
241 + %token  MAX_TOPIC_LENGTH
242   %token  MAX_WATCH
243 < %token  MESSAGE_LOCALE
243 > %token  MIN_IDLE
244   %token  MIN_NONWILDCARD
245   %token  MIN_NONWILDCARD_SIMPLE
246   %token  MODULE
247   %token  MODULES
248 + %token  MOTD
249   %token  NAME
250 + %token  NEED_IDENT
251   %token  NEED_PASSWORD
252   %token  NETWORK_DESC
253   %token  NETWORK_NAME
254   %token  NICK
257 %token  NICK_CHANGES
255   %token  NO_CREATE_ON_SPLIT
256   %token  NO_JOIN_ON_SPLIT
257   %token  NO_OPER_FLOOD
258   %token  NO_TILDE
262 %token  NOT
259   %token  NUMBER
264 %token  NUMBER_PER_IDENT
260   %token  NUMBER_PER_CIDR
261   %token  NUMBER_PER_IP
267 %token  NUMBER_PER_IP_GLOBAL
268 %token  OPERATOR
269 %token  OPERS_BYPASS_CALLERID
270 %token  OPER_LOG
262   %token  OPER_ONLY_UMODES
263   %token  OPER_PASS_RESV
273 %token  OPER_SPY_T
264   %token  OPER_UMODES
265 < %token  JOIN_FLOOD_COUNT
266 < %token  JOIN_FLOOD_TIME
265 > %token  OPERATOR
266 > %token  OPERS_BYPASS_CALLERID
267   %token  PACE_WAIT
268   %token  PACE_WAIT_SIMPLE
269   %token  PASSWORD
270   %token  PATH
271   %token  PING_COOKIE
272   %token  PING_TIME
283 %token  PING_WARNING
273   %token  PORT
274   %token  QSTRING
275 < %token  QUIET_ON_BAN
275 > %token  RANDOM_IDLE
276   %token  REASON
277   %token  REDIRPORT
278   %token  REDIRSERV
290 %token  REGEX_T
279   %token  REHASH
292 %token  TREJECT_HOLD_TIME
280   %token  REMOTE
281   %token  REMOTEBAN
295 %token  RESTRICT_CHANNELS
296 %token  RESTRICTED
297 %token  RSA_PRIVATE_KEY_FILE
298 %token  RSA_PUBLIC_KEY_FILE
299 %token  SSL_CERTIFICATE_FILE
300 %token  T_SSL_CONNECTION_METHOD
301 %token  T_SSLV3
302 %token  T_TLSV1
282   %token  RESV
283   %token  RESV_EXEMPT
284 < %token  SECONDS MINUTES HOURS DAYS WEEKS
285 < %token  SENDQ
284 > %token  RSA_PRIVATE_KEY_FILE
285 > %token  RSA_PUBLIC_KEY_FILE
286 > %token  SECONDS MINUTES HOURS DAYS WEEKS MONTHS YEARS
287   %token  SEND_PASSWORD
288 + %token  SENDQ
289   %token  SERVERHIDE
290   %token  SERVERINFO
310 %token  SERVLINK_PATH
311 %token  IRCD_SID
312 %token  TKLINE_EXPIRE_NOTICES
313 %token  T_SHARED
314 %token  T_CLUSTER
315 %token  TYPE
291   %token  SHORT_MOTD
317 %token  SILENT
292   %token  SPOOF
293   %token  SPOOF_NOTICE
294 + %token  SQUIT
295 + %token  SSL_CERTIFICATE_FILE
296 + %token  SSL_CERTIFICATE_FINGERPRINT
297 + %token  SSL_CONNECTION_REQUIRED
298 + %token  SSL_DH_ELLIPTIC_CURVE
299 + %token  SSL_DH_PARAM_FILE
300   %token  STATS_E_DISABLED
301   %token  STATS_I_OPER_ONLY
302   %token  STATS_K_OPER_ONLY
303   %token  STATS_O_OPER_ONLY
304   %token  STATS_P_OPER_ONLY
305 < %token  TBOOL
326 < %token  TMASKED
327 < %token  T_REJECT
328 < %token  TS_MAX_DELTA
329 < %token  TS_WARN_DELTA
330 < %token  TWODOTS
305 > %token  STATS_U_OPER_ONLY
306   %token  T_ALL
307   %token  T_BOTS
333 %token  T_SOFTCALLERID
308   %token  T_CALLERID
309   %token  T_CCONN
310 < %token  T_CCONN_FULL
337 < %token  T_CLIENT_FLOOD
310 > %token  T_CLUSTER
311   %token  T_DEAF
312   %token  T_DEBUG
313 < %token  T_DRONE
313 > %token  T_DLINE
314   %token  T_EXTERNAL
315 + %token  T_FARCONNECT
316 + %token  T_FILE
317   %token  T_FULL
318 + %token  T_GLOBOPS
319   %token  T_INVISIBLE
320   %token  T_IPV4
321   %token  T_IPV6
322   %token  T_LOCOPS
323 < %token  T_LOGPATH
348 < %token  T_L_CRIT
349 < %token  T_L_DEBUG
350 < %token  T_L_ERROR
351 < %token  T_L_INFO
352 < %token  T_L_NOTICE
353 < %token  T_L_TRACE
354 < %token  T_L_WARN
323 > %token  T_LOG
324   %token  T_MAX_CLIENTS
325   %token  T_NCHANGE
326 < %token  T_OPERWALL
326 > %token  T_NONONREG
327 > %token  T_RECVQ
328   %token  T_REJ
329 + %token  T_RESTART
330   %token  T_SERVER
331 + %token  T_SERVICE
332 + %token  T_SERVICES_NAME
333   %token  T_SERVNOTICE
334 + %token  T_SET
335 + %token  T_SHARED
336 + %token  T_SIZE
337   %token  T_SKILL
338 + %token  T_SOFTCALLERID
339   %token  T_SPY
340   %token  T_SSL
341 + %token  T_SSL_CIPHER_LIST
342 + %token  T_SSL_CLIENT_METHOD
343 + %token  T_SSL_SERVER_METHOD
344 + %token  T_SSLV3
345 + %token  T_TLSV1
346   %token  T_UMODES
347   %token  T_UNAUTH
348 + %token  T_UNDLINE
349 + %token  T_UNLIMITED
350   %token  T_UNRESV
351   %token  T_UNXLINE
352   %token  T_WALLOP
353 + %token  T_WALLOPS
354 + %token  T_WEBIRC
355 + %token  TBOOL
356 + %token  THROTTLE_COUNT
357   %token  THROTTLE_TIME
358 < %token  TOPICBURST
358 > %token  TKLINE_EXPIRE_NOTICES
359 > %token  TMASKED
360   %token  TRUE_NO_OPER_FLOOD
361 < %token  TKLINE
362 < %token  TXLINE
363 < %token  TRESV
361 > %token  TS_MAX_DELTA
362 > %token  TS_WARN_DELTA
363 > %token  TWODOTS
364 > %token  TYPE
365   %token  UNKLINE
376 %token  USER
366   %token  USE_EGD
378 %token  USE_EXCEPT
379 %token  USE_INVEX
380 %token  USE_KNOCK
367   %token  USE_LOGGING
368 < %token  USE_WHOIS_ACTUALLY
368 > %token  USER
369   %token  VHOST
370   %token  VHOST6
371 + %token  WARN_NO_CONNECT_BLOCK
372   %token  XLINE
386 %token  WARN
387 %token  WARN_NO_NLINE
373  
374 < %type <string> QSTRING
375 < %type <number> NUMBER
376 < %type <number> timespec
377 < %type <number> timespec_
378 < %type <number> sizespec
379 < %type <number> sizespec_
374 > %type  <string> QSTRING
375 > %type  <number> NUMBER
376 > %type  <number> timespec
377 > %type  <number> timespec_
378 > %type  <number> sizespec
379 > %type  <number> sizespec_
380  
381   %%
382 < conf:  
382 > conf:
383          | conf conf_item
384          ;
385  
386   conf_item:        admin_entry
387                  | logging_entry
388                  | oper_entry
389 <                | channel_entry
390 <                | class_entry
389 >                | channel_entry
390 >                | class_entry
391                  | listen_entry
392                  | auth_entry
393                  | serverinfo_entry
394 <                | serverhide_entry
394 >                | serverhide_entry
395                  | resv_entry
396 +                | service_entry
397                  | shared_entry
398 <                | cluster_entry
398 >                | cluster_entry
399                  | connect_entry
400                  | kill_entry
401                  | deny_entry
402 <                | exempt_entry
403 <                | general_entry
418 <                | gline_entry
402 >                | exempt_entry
403 >                | general_entry
404                  | gecos_entry
405                  | modules_entry
406 +                | motd_entry
407                  | error ';'
408                  | error '}'
409          ;
410  
411  
412   timespec_: { $$ = 0; } | timespec;
413 < timespec:       NUMBER timespec_
414 <                {
415 <                        $$ = $1 + $2;
416 <                }
417 <                | NUMBER SECONDS timespec_
418 <                {
419 <                        $$ = $1 + $3;
420 <                }
421 <                | NUMBER MINUTES timespec_
422 <                {
423 <                        $$ = $1 * 60 + $3;
424 <                }
425 <                | NUMBER HOURS timespec_
426 <                {
427 <                        $$ = $1 * 60 * 60 + $3;
428 <                }
443 <                | NUMBER DAYS timespec_
444 <                {
445 <                        $$ = $1 * 60 * 60 * 24 + $3;
446 <                }
447 <                | NUMBER WEEKS timespec_
448 <                {
449 <                        $$ = $1 * 60 * 60 * 24 * 7 + $3;
450 <                }
451 <                ;
452 <
453 < sizespec_:      { $$ = 0; } | sizespec;
454 < sizespec:       NUMBER sizespec_ { $$ = $1 + $2; }
455 <                | NUMBER BYTES sizespec_ { $$ = $1 + $3; }
456 <                | NUMBER KBYTES sizespec_ { $$ = $1 * 1024 + $3; }
457 <                | NUMBER MBYTES sizespec_ { $$ = $1 * 1024 * 1024 + $3; }
458 <                ;
413 > timespec:  NUMBER timespec_         { $$ = $1 + $2; } |
414 >           NUMBER SECONDS timespec_ { $$ = $1 + $3; } |
415 >           NUMBER MINUTES timespec_ { $$ = $1 * 60 + $3; } |
416 >           NUMBER HOURS timespec_   { $$ = $1 * 60 * 60 + $3; } |
417 >           NUMBER DAYS timespec_    { $$ = $1 * 60 * 60 * 24 + $3; } |
418 >           NUMBER WEEKS timespec_   { $$ = $1 * 60 * 60 * 24 * 7 + $3; } |
419 >           NUMBER MONTHS timespec_  { $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3; } |
420 >           NUMBER YEARS timespec_   { $$ = $1 * 60 * 60 * 24 * 365 + $3; }
421 >           ;
422 >
423 > sizespec_:  { $$ = 0; } | sizespec;
424 > sizespec:   NUMBER sizespec_ { $$ = $1 + $2; } |
425 >            NUMBER BYTES sizespec_ { $$ = $1 + $3; } |
426 >            NUMBER KBYTES sizespec_ { $$ = $1 * 1024 + $3; } |
427 >            NUMBER MBYTES sizespec_ { $$ = $1 * 1024 * 1024 + $3; }
428 >            ;
429  
430  
431   /***************************************************************************
# Line 469 | Line 439 | modules_item:   modules_module | modules
439  
440   modules_module: MODULE '=' QSTRING ';'
441   {
472 #ifndef STATIC_MODULES /* NOOP in the static case */
442    if (conf_parser_ctx.pass == 2)
443      add_conf_module(libio_basename(yylval.string));
475 #endif
444   };
445  
446   modules_path: PATH '=' QSTRING ';'
447   {
480 #ifndef STATIC_MODULES
448    if (conf_parser_ctx.pass == 2)
449      mod_add_path(yylval.string);
483 #endif
450   };
451  
452  
453   serverinfo_entry: SERVERINFO '{' serverinfo_items '}' ';';
454  
455   serverinfo_items:       serverinfo_items serverinfo_item | serverinfo_item ;
456 < serverinfo_item:        serverinfo_name | serverinfo_vhost |
457 <                        serverinfo_hub | serverinfo_description |
458 <                        serverinfo_network_name | serverinfo_network_desc |
459 <                        serverinfo_max_clients |
460 <                        serverinfo_rsa_private_key_file | serverinfo_vhost6 |
461 <                        serverinfo_sid | serverinfo_ssl_certificate_file |
462 <                        serverinfo_ssl_connection_method |
463 <                        error ';' ;
456 > serverinfo_item:        serverinfo_name |
457 >                        serverinfo_vhost |
458 >                        serverinfo_hub |
459 >                        serverinfo_description |
460 >                        serverinfo_network_name |
461 >                        serverinfo_network_desc |
462 >                        serverinfo_max_clients |
463 >                        serverinfo_max_nick_length |
464 >                        serverinfo_max_topic_length |
465 >                        serverinfo_ssl_dh_param_file |
466 >                        serverinfo_ssl_dh_elliptic_curve |
467 >                        serverinfo_rsa_private_key_file |
468 >                        serverinfo_vhost6 |
469 >                        serverinfo_sid |
470 >                        serverinfo_ssl_certificate_file |
471 >                        serverinfo_ssl_client_method |
472 >                        serverinfo_ssl_server_method |
473 >                        serverinfo_ssl_cipher_list |
474 >                        error ';' ;
475 >
476  
477 + serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
478 + serverinfo_ssl_server_method: T_SSL_SERVER_METHOD '=' server_method_types ';' ;
479  
480 < serverinfo_ssl_connection_method: T_SSL_CONNECTION_METHOD
480 > client_method_types: client_method_types ',' client_method_type_item | client_method_type_item;
481 > client_method_type_item: T_SSLV3
482   {
483   #ifdef HAVE_LIBCRYPTO
484 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
485 <    ServerInfo.tls_version = 0;
484 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
485 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv3);
486   #endif
487 < } '=' method_types ';'
487 > } | T_TLSV1
488   {
489   #ifdef HAVE_LIBCRYPTO
490 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
491 <  {
511 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_SSLV3))
512 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
513 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_TLSV1))
514 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
515 <  }
490 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
491 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_TLSv1);
492   #endif
493   };
494  
495 < method_types: method_types ',' method_type_item | method_type_item;
496 < method_type_item: T_SSLV3
495 > server_method_types: server_method_types ',' server_method_type_item | server_method_type_item;
496 > server_method_type_item: T_SSLV3
497   {
498   #ifdef HAVE_LIBCRYPTO
499 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
500 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_SSLV3;
499 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
500 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
501   #endif
502   } | T_TLSV1
503   {
504   #ifdef HAVE_LIBCRYPTO
505 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
506 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_TLSV1;
505 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
506 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
507   #endif
508   };
509  
510   serverinfo_ssl_certificate_file: SSL_CERTIFICATE_FILE '=' QSTRING ';'
511   {
512   #ifdef HAVE_LIBCRYPTO
513 <  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
513 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
514    {
515      if (!ServerInfo.rsa_private_key_file)
516      {
517 <      yyerror("No rsa_private_key_file specified, SSL disabled");
517 >      conf_error_report("No rsa_private_key_file specified, SSL disabled");
518        break;
519      }
520  
521      if (SSL_CTX_use_certificate_file(ServerInfo.server_ctx, yylval.string,
522 +                                     SSL_FILETYPE_PEM) <= 0 ||
523 +        SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
524                                       SSL_FILETYPE_PEM) <= 0)
525      {
526 <      yyerror(ERR_lib_error_string(ERR_get_error()));
526 >      report_crypto_errors();
527 >      conf_error_report("Could not open/read certificate file");
528        break;
529      }
530  
531      if (SSL_CTX_use_PrivateKey_file(ServerInfo.server_ctx, ServerInfo.rsa_private_key_file,
532 +                                    SSL_FILETYPE_PEM) <= 0 ||
533 +        SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
534                                      SSL_FILETYPE_PEM) <= 0)
535      {
536 <      yyerror(ERR_lib_error_string(ERR_get_error()));
536 >      report_crypto_errors();
537 >      conf_error_report("Could not read RSA private key");
538        break;
539      }
540  
541 <    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx))
541 >    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
542 >        !SSL_CTX_check_private_key(ServerInfo.client_ctx))
543      {
544 <      yyerror(ERR_lib_error_string(ERR_get_error()));
544 >      report_crypto_errors();
545 >      conf_error_report("Could not read RSA private key");
546        break;
547      }
548    }
# Line 568 | Line 552 | serverinfo_ssl_certificate_file: SSL_CER
552   serverinfo_rsa_private_key_file: RSA_PRIVATE_KEY_FILE '=' QSTRING ';'
553   {
554   #ifdef HAVE_LIBCRYPTO
555 <  if (conf_parser_ctx.pass == 1)
555 >  BIO *file = NULL;
556 >
557 >  if (conf_parser_ctx.pass != 1)
558 >    break;
559 >
560 >  if (ServerInfo.rsa_private_key)
561    {
562 <    BIO *file;
562 >    RSA_free(ServerInfo.rsa_private_key);
563 >    ServerInfo.rsa_private_key = NULL;
564 >  }
565  
566 <    if (ServerInfo.rsa_private_key)
567 <    {
568 <      RSA_free(ServerInfo.rsa_private_key);
569 <      ServerInfo.rsa_private_key = NULL;
570 <    }
566 >  if (ServerInfo.rsa_private_key_file)
567 >  {
568 >    MyFree(ServerInfo.rsa_private_key_file);
569 >    ServerInfo.rsa_private_key_file = NULL;
570 >  }
571  
572 <    if (ServerInfo.rsa_private_key_file)
582 <    {
583 <      MyFree(ServerInfo.rsa_private_key_file);
584 <      ServerInfo.rsa_private_key_file = NULL;
585 <    }
572 >  ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
573  
574 <    DupString(ServerInfo.rsa_private_key_file, yylval.string);
574 >  if ((file = BIO_new_file(yylval.string, "r")) == NULL)
575 >  {
576 >    conf_error_report("File open failed, ignoring");
577 >    break;
578 >  }
579 >
580 >  ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
581 >
582 >  BIO_set_close(file, BIO_CLOSE);
583 >  BIO_free(file);
584  
585 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
585 >  if (ServerInfo.rsa_private_key == NULL)
586 >  {
587 >    conf_error_report("Couldn't extract key, ignoring");
588 >    break;
589 >  }
590 >
591 >  if (!RSA_check_key(ServerInfo.rsa_private_key))
592 >  {
593 >    RSA_free(ServerInfo.rsa_private_key);
594 >    ServerInfo.rsa_private_key = NULL;
595 >
596 >    conf_error_report("Invalid key, ignoring");
597 >    break;
598 >  }
599 >
600 >  if (RSA_size(ServerInfo.rsa_private_key) < 128)
601 >  {
602 >    RSA_free(ServerInfo.rsa_private_key);
603 >    ServerInfo.rsa_private_key = NULL;
604 >
605 >    conf_error_report("Ignoring serverinfo::rsa_private_key_file -- need at least a 1024 bit key size");
606 >  }
607 > #endif
608 > };
609 >
610 > serverinfo_ssl_dh_param_file: SSL_DH_PARAM_FILE '=' QSTRING ';'
611 > {
612 > /* TBD - XXX: error reporting */
613 > #ifdef HAVE_LIBCRYPTO
614 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
615 >  {
616 >    BIO *file = BIO_new_file(yylval.string, "r");
617 >
618 >    if (file)
619      {
620 <      yyerror("File open failed, ignoring");
621 <      break;
620 >      DH *dh = PEM_read_bio_DHparams(file, NULL, NULL, NULL);
621 >
622 >      BIO_free(file);
623 >
624 >      if (dh)
625 >      {
626 >        if (DH_size(dh) < 128)
627 >          conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
628 >        else
629 >          SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
630 >
631 >        DH_free(dh);
632 >      }
633      }
634 +  }
635 + #endif
636 + };
637  
638 <    ServerInfo.rsa_private_key = (RSA *)PEM_read_bio_RSAPrivateKey(file, NULL,
639 <      0, NULL);
638 > serverinfo_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
639 > {
640 > #ifdef HAVE_LIBCRYPTO
641 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
642 >    SSL_CTX_set_cipher_list(ServerInfo.server_ctx, yylval.string);
643 > #endif
644 > };
645  
646 <    BIO_set_close(file, BIO_CLOSE);
647 <    BIO_free(file);
646 > serverinfo_ssl_dh_elliptic_curve: SSL_DH_ELLIPTIC_CURVE '=' QSTRING ';'
647 > {
648 > #ifdef HAVE_LIBCRYPTO
649 > #if OPENSSL_VERSION_NUMBER >= 0x1000005FL && !defined(OPENSSL_NO_ECDH)
650 >  int nid = 0;
651 >  EC_KEY *key = NULL;
652  
653 <    if (ServerInfo.rsa_private_key == NULL)
653 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
654 >  {
655 >    if ((nid = OBJ_sn2nid(yylval.string)) == 0)
656      {
657 <      yyerror("Couldn't extract key, ignoring");
658 <      break;
657 >        conf_error_report("Ignoring serverinfo::serverinfo_ssl_dh_elliptic_curve -- unknown curve name");
658 >        break;
659      }
660  
661 <    if (!RSA_check_key(ServerInfo.rsa_private_key))
661 >    if ((key = EC_KEY_new_by_curve_name(nid)) == NULL)
662      {
663 <      RSA_free(ServerInfo.rsa_private_key);
610 <      ServerInfo.rsa_private_key = NULL;
611 <
612 <      yyerror("Invalid key, ignoring");
663 >      conf_error_report("Ignoring serverinfo::serverinfo_ssl_dh_elliptic_curve -- could not create curve");
664        break;
665      }
666  
667 <    /* require 2048 bit (256 byte) key */
668 <    if (RSA_size(ServerInfo.rsa_private_key) != 256)
669 <    {
670 <      RSA_free(ServerInfo.rsa_private_key);
620 <      ServerInfo.rsa_private_key = NULL;
621 <
622 <      yyerror("Not a 2048 bit key, ignoring");
623 <    }
624 <  }
667 >    SSL_CTX_set_tmp_ecdh(ServerInfo.server_ctx, key);
668 >    EC_KEY_free(key);
669 > }
670 > #endif
671   #endif
672   };
673  
674 < serverinfo_name: NAME '=' QSTRING ';'
674 > serverinfo_name: NAME '=' QSTRING ';'
675   {
676    /* this isn't rehashable */
677 <  if (conf_parser_ctx.pass == 2)
677 >  if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
678    {
679 <    if (ServerInfo.name == NULL)
679 >    if (valid_servname(yylval.string))
680 >      ServerInfo.name = xstrdup(yylval.string);
681 >    else
682      {
683 <      /* the ircd will exit() in main() if we dont set one */
684 <      if (strlen(yylval.string) <= HOSTLEN)
637 <        DupString(ServerInfo.name, yylval.string);
683 >      conf_error_report("Ignoring serverinfo::name -- invalid name. Aborting.");
684 >      exit(0);
685      }
686    }
687   };
688  
689 < serverinfo_sid: IRCD_SID '=' QSTRING ';'
689 > serverinfo_sid: IRCD_SID '=' QSTRING ';'
690   {
691    /* this isn't rehashable */
692    if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
693    {
694      if (valid_sid(yylval.string))
695 <      DupString(ServerInfo.sid, yylval.string);
695 >      ServerInfo.sid = xstrdup(yylval.string);
696      else
697      {
698 <      ilog(L_ERROR, "Ignoring config file entry SID -- invalid SID. Aborting.");
698 >      conf_error_report("Ignoring serverinfo::sid -- invalid SID. Aborting.");
699        exit(0);
700      }
701    }
# Line 659 | Line 706 | serverinfo_description: DESCRIPTION '='
706    if (conf_parser_ctx.pass == 2)
707    {
708      MyFree(ServerInfo.description);
709 <    DupString(ServerInfo.description,yylval.string);
709 >    ServerInfo.description = xstrdup(yylval.string);
710    }
711   };
712  
# Line 669 | Line 716 | serverinfo_network_name: NETWORK_NAME '=
716    {
717      char *p;
718  
719 <    if ((p = strchr(yylval.string, ' ')) != NULL)
720 <      p = '\0';
719 >    if ((p = strchr(yylval.string, ' ')))
720 >      *p = '\0';
721  
722      MyFree(ServerInfo.network_name);
723 <    DupString(ServerInfo.network_name, yylval.string);
723 >    ServerInfo.network_name = xstrdup(yylval.string);
724    }
725   };
726  
727   serverinfo_network_desc: NETWORK_DESC '=' QSTRING ';'
728   {
729 <  if (conf_parser_ctx.pass == 2)
730 <  {
731 <    MyFree(ServerInfo.network_desc);
732 <    DupString(ServerInfo.network_desc, yylval.string);
733 <  }
729 >  if (conf_parser_ctx.pass != 2)
730 >    break;
731 >
732 >  MyFree(ServerInfo.network_desc);
733 >  ServerInfo.network_desc = xstrdup(yylval.string);
734   };
735  
736   serverinfo_vhost: VHOST '=' QSTRING ';'
# Line 698 | Line 745 | serverinfo_vhost: VHOST '=' QSTRING ';'
745      hints.ai_socktype = SOCK_STREAM;
746      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
747  
748 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
749 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
748 >    if (getaddrinfo(yylval.string, NULL, &hints, &res))
749 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
750      else
751      {
752 <      assert(res != NULL);
752 >      assert(res);
753  
754        memcpy(&ServerInfo.ip, res->ai_addr, res->ai_addrlen);
755        ServerInfo.ip.ss.ss_family = res->ai_family;
756        ServerInfo.ip.ss_len = res->ai_addrlen;
757 <      irc_freeaddrinfo(res);
757 >      freeaddrinfo(res);
758  
759        ServerInfo.specific_ipv4_vhost = 1;
760      }
# Line 727 | Line 774 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
774      hints.ai_socktype = SOCK_STREAM;
775      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
776  
777 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
778 <      ilog(L_ERROR, "Invalid netmask for server vhost6(%s)", yylval.string);
777 >    if (getaddrinfo(yylval.string, NULL, &hints, &res))
778 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost6(%s)", yylval.string);
779      else
780      {
781 <      assert(res != NULL);
781 >      assert(res);
782  
783        memcpy(&ServerInfo.ip6, res->ai_addr, res->ai_addrlen);
784        ServerInfo.ip6.ss.ss_family = res->ai_family;
785        ServerInfo.ip6.ss_len = res->ai_addrlen;
786 <      irc_freeaddrinfo(res);
786 >      freeaddrinfo(res);
787  
788        ServerInfo.specific_ipv6_vhost = 1;
789      }
# Line 746 | Line 793 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
793  
794   serverinfo_max_clients: T_MAX_CLIENTS '=' NUMBER ';'
795   {
796 <  if (conf_parser_ctx.pass == 2)
796 >  if (conf_parser_ctx.pass != 2)
797 >    break;
798 >
799 >  if ($3 < MAXCLIENTS_MIN)
800    {
801 <    recalc_fdlimit(NULL);
801 >    char buf[IRCD_BUFSIZE] = "";
802  
803 <    if ($3 < MAXCLIENTS_MIN)
804 <    {
805 <      char buf[IRCD_BUFSIZE];
806 <      ircsprintf(buf, "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
807 <      yyerror(buf);
808 <    }
809 <    else if ($3 > MAXCLIENTS_MAX)
810 <    {
811 <      char buf[IRCD_BUFSIZE];
812 <      ircsprintf(buf, "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
813 <      yyerror(buf);
764 <    }
765 <    else
766 <      ServerInfo.max_clients = $3;
803 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
804 >    conf_error_report(buf);
805 >    ServerInfo.max_clients = MAXCLIENTS_MIN;
806 >  }
807 >  else if ($3 > MAXCLIENTS_MAX)
808 >  {
809 >    char buf[IRCD_BUFSIZE] = "";
810 >
811 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
812 >    conf_error_report(buf);
813 >    ServerInfo.max_clients = MAXCLIENTS_MAX;
814    }
815 +  else
816 +    ServerInfo.max_clients = $3;
817   };
818  
819 < serverinfo_hub: HUB '=' TBOOL ';'
819 > serverinfo_max_nick_length: MAX_NICK_LENGTH '=' NUMBER ';'
820   {
821 <  if (conf_parser_ctx.pass == 2)
821 >  if (conf_parser_ctx.pass != 2)
822 >    break;
823 >
824 >  if ($3 < 9)
825    {
826 <    if (yylval.number)
827 <    {
828 <      ServerInfo.hub = 1;
829 <      delete_capability("HUB");
830 <      add_capability("HUB", CAP_HUB, 1);
831 <    }
780 <    else if (ServerInfo.hub)
781 <    {
826 >    conf_error_report("max_nick_length too low, setting to 9");
827 >    ServerInfo.max_nick_length = 9;
828 >  }
829 >  else if ($3 > NICKLEN)
830 >  {
831 >    char buf[IRCD_BUFSIZE] = "";
832  
833 <      ServerInfo.hub = 0;
834 <      delete_capability("HUB");
835 <    }
833 >    snprintf(buf, sizeof(buf), "max_nick_length too high, setting to %d", NICKLEN);
834 >    conf_error_report(buf);
835 >    ServerInfo.max_nick_length = NICKLEN;
836    }
837 +  else
838 +    ServerInfo.max_nick_length = $3;
839 + };
840 +
841 + serverinfo_max_topic_length: MAX_TOPIC_LENGTH '=' NUMBER ';'
842 + {
843 +  if (conf_parser_ctx.pass != 2)
844 +    break;
845 +
846 +  if ($3 < 80)
847 +  {
848 +    conf_error_report("max_topic_length too low, setting to 80");
849 +    ServerInfo.max_topic_length = 80;
850 +  }
851 +  else if ($3 > TOPICLEN)
852 +  {
853 +    char buf[IRCD_BUFSIZE] = "";
854 +
855 +    snprintf(buf, sizeof(buf), "max_topic_length too high, setting to %d", TOPICLEN);
856 +    conf_error_report(buf);
857 +    ServerInfo.max_topic_length = TOPICLEN;
858 +  }
859 +  else
860 +    ServerInfo.max_topic_length = $3;
861 + };
862 +
863 + serverinfo_hub: HUB '=' TBOOL ';'
864 + {
865 +  if (conf_parser_ctx.pass == 2)
866 +    ServerInfo.hub = yylval.number;
867   };
868  
869   /***************************************************************************
# Line 792 | Line 872 | serverinfo_hub: HUB '=' TBOOL ';'
872   admin_entry: ADMIN  '{' admin_items '}' ';' ;
873  
874   admin_items: admin_items admin_item | admin_item;
875 < admin_item:  admin_name | admin_description |
876 <             admin_email | error ';' ;
875 > admin_item:  admin_name |
876 >             admin_description |
877 >             admin_email |
878 >             error ';' ;
879  
880 < admin_name: NAME '=' QSTRING ';'
880 > admin_name: NAME '=' QSTRING ';'
881   {
882 <  if (conf_parser_ctx.pass == 2)
883 <  {
884 <    MyFree(AdminInfo.name);
885 <    DupString(AdminInfo.name, yylval.string);
886 <  }
882 >  if (conf_parser_ctx.pass != 2)
883 >    break;
884 >
885 >  MyFree(AdminInfo.name);
886 >  AdminInfo.name = xstrdup(yylval.string);
887   };
888  
889   admin_email: EMAIL '=' QSTRING ';'
890   {
891 <  if (conf_parser_ctx.pass == 2)
892 <  {
893 <    MyFree(AdminInfo.email);
894 <    DupString(AdminInfo.email, yylval.string);
895 <  }
891 >  if (conf_parser_ctx.pass != 2)
892 >    break;
893 >
894 >  MyFree(AdminInfo.email);
895 >  AdminInfo.email = xstrdup(yylval.string);
896   };
897  
898   admin_description: DESCRIPTION '=' QSTRING ';'
899   {
900 <  if (conf_parser_ctx.pass == 2)
901 <  {
902 <    MyFree(AdminInfo.description);
903 <    DupString(AdminInfo.description, yylval.string);
904 <  }
900 >  if (conf_parser_ctx.pass != 2)
901 >    break;
902 >
903 >  MyFree(AdminInfo.description);
904 >  AdminInfo.description = xstrdup(yylval.string);
905   };
906  
907   /***************************************************************************
908 < *  section logging
908 > * motd section
909   ***************************************************************************/
910 < /* XXX */
911 < logging_entry:          LOGGING  '{' logging_items '}' ';' ;
910 > motd_entry: MOTD
911 > {
912 >  if (conf_parser_ctx.pass == 2)
913 >    reset_block_state();
914 > } '{' motd_items '}' ';'
915 > {
916 >  dlink_node *ptr = NULL;
917  
918 < logging_items:          logging_items logging_item |
919 <                        logging_item ;
918 >  if (conf_parser_ctx.pass != 2)
919 >    break;
920  
921 < logging_item:           logging_path | logging_oper_log |
922 <                        logging_log_level |
836 <                        logging_use_logging | logging_fuserlog |
837 <                        logging_foperlog | logging_fglinelog |
838 <                        logging_fklinelog | logging_killlog |
839 <                        logging_foperspylog | logging_ioerrlog |
840 <                        logging_ffailed_operlog |
841 <                        error ';' ;
921 >  if (!block_state.file.buf[0])
922 >    break;
923  
924 < logging_path:           T_LOGPATH '=' QSTRING ';'
925 <                        {
926 <                        };
924 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
925 >    motd_add(ptr->data, block_state.file.buf);
926 > };
927  
928 < logging_oper_log:       OPER_LOG '=' QSTRING ';'
929 <                        {
849 <                        };
928 > motd_items: motd_items motd_item | motd_item;
929 > motd_item:  motd_mask | motd_file | error ';' ;
930  
931 < logging_fuserlog: FUSERLOG '=' QSTRING ';'
931 > motd_mask: MASK '=' QSTRING ';'
932   {
933    if (conf_parser_ctx.pass == 2)
934 <    strlcpy(ConfigLoggingEntry.userlog, yylval.string,
855 <            sizeof(ConfigLoggingEntry.userlog));
934 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
935   };
936  
937 < logging_ffailed_operlog: FFAILED_OPERLOG '=' QSTRING ';'
937 > motd_file: T_FILE '=' QSTRING ';'
938   {
939    if (conf_parser_ctx.pass == 2)
940 <    strlcpy(ConfigLoggingEntry.failed_operlog, yylval.string,
862 <            sizeof(ConfigLoggingEntry.failed_operlog));
940 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
941   };
942  
943 < logging_foperlog: FOPERLOG '=' QSTRING ';'
943 > /***************************************************************************
944 > *  section logging
945 > ***************************************************************************/
946 > logging_entry:          T_LOG  '{' logging_items '}' ';' ;
947 > logging_items:          logging_items logging_item | logging_item ;
948 >
949 > logging_item:           logging_use_logging | logging_file_entry |
950 >                        error ';' ;
951 >
952 > logging_use_logging: USE_LOGGING '=' TBOOL ';'
953   {
954    if (conf_parser_ctx.pass == 2)
955 <    strlcpy(ConfigLoggingEntry.operlog, yylval.string,
869 <            sizeof(ConfigLoggingEntry.operlog));
955 >    ConfigLoggingEntry.use_logging = yylval.number;
956   };
957  
958 < logging_foperspylog: FOPERSPYLOG '=' QSTRING ';'
958 > logging_file_entry:
959   {
960    if (conf_parser_ctx.pass == 2)
961 <    strlcpy(ConfigLoggingEntry.operspylog, yylval.string,
962 <            sizeof(ConfigLoggingEntry.operspylog));
961 >    reset_block_state();
962 > } T_FILE  '{' logging_file_items '}' ';'
963 > {
964 >  if (conf_parser_ctx.pass != 2)
965 >    break;
966 >
967 >  if (block_state.type.value && block_state.file.buf[0])
968 >    log_set_file(block_state.type.value, block_state.size.value,
969 >                 block_state.file.buf);
970   };
971  
972 < logging_fglinelog: FGLINELOG '=' QSTRING ';'
972 > logging_file_items: logging_file_items logging_file_item |
973 >                    logging_file_item ;
974 >
975 > logging_file_item:  logging_file_name | logging_file_type |
976 >                    logging_file_size | error ';' ;
977 >
978 > logging_file_name: NAME '=' QSTRING ';'
979   {
980 <  if (conf_parser_ctx.pass == 2)
981 <    strlcpy(ConfigLoggingEntry.glinelog, yylval.string,
883 <            sizeof(ConfigLoggingEntry.glinelog));
884 < };
980 >  if (conf_parser_ctx.pass != 2)
981 >    break;
982  
983 < logging_fklinelog: FKLINELOG '=' QSTRING ';'
983 >  strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
984 > }
985 >
986 > logging_file_size: T_SIZE '=' sizespec ';'
987   {
988 <  if (conf_parser_ctx.pass == 2)
989 <    strlcpy(ConfigLoggingEntry.klinelog, yylval.string,
990 <            sizeof(ConfigLoggingEntry.klinelog));
988 >  block_state.size.value = $3;
989 > } | T_SIZE '=' T_UNLIMITED ';'
990 > {
991 >  block_state.size.value = 0;
992   };
993  
994 < logging_ioerrlog: FIOERRLOG '=' QSTRING ';'
994 > logging_file_type: TYPE
995   {
996    if (conf_parser_ctx.pass == 2)
997 <    strlcpy(ConfigLoggingEntry.ioerrlog, yylval.string,
998 <            sizeof(ConfigLoggingEntry.ioerrlog));
898 < };
997 >    block_state.type.value = 0;
998 > } '='  logging_file_type_items ';' ;
999  
1000 < logging_killlog: FKILLLOG '=' QSTRING ';'
1000 > logging_file_type_items: logging_file_type_items ',' logging_file_type_item | logging_file_type_item;
1001 > logging_file_type_item:  USER
1002   {
1003    if (conf_parser_ctx.pass == 2)
1004 <    strlcpy(ConfigLoggingEntry.killlog, yylval.string,
1005 <            sizeof(ConfigLoggingEntry.killlog));
1006 < };
906 <
907 < logging_log_level: LOG_LEVEL '=' T_L_CRIT ';'
908 < {
1004 >    block_state.type.value = LOG_TYPE_USER;
1005 > } | OPERATOR
1006 > {
1007    if (conf_parser_ctx.pass == 2)
1008 <    set_log_level(L_CRIT);
1009 < } | LOG_LEVEL '=' T_L_ERROR ';'
1008 >    block_state.type.value = LOG_TYPE_OPER;
1009 > } | GLINE
1010   {
1011    if (conf_parser_ctx.pass == 2)
1012 <    set_log_level(L_ERROR);
1013 < } | LOG_LEVEL '=' T_L_WARN ';'
1012 >    block_state.type.value = LOG_TYPE_GLINE;
1013 > } | XLINE
1014   {
1015    if (conf_parser_ctx.pass == 2)
1016 <    set_log_level(L_WARN);
1017 < } | LOG_LEVEL '=' T_L_NOTICE ';'
1016 >    block_state.type.value = LOG_TYPE_XLINE;
1017 > } | RESV
1018   {
1019    if (conf_parser_ctx.pass == 2)
1020 <    set_log_level(L_NOTICE);
1021 < } | LOG_LEVEL '=' T_L_TRACE ';'
1020 >    block_state.type.value = LOG_TYPE_RESV;
1021 > } | T_DLINE
1022   {
1023    if (conf_parser_ctx.pass == 2)
1024 <    set_log_level(L_TRACE);
1025 < } | LOG_LEVEL '=' T_L_INFO ';'
1024 >    block_state.type.value = LOG_TYPE_DLINE;
1025 > } | KLINE
1026   {
1027    if (conf_parser_ctx.pass == 2)
1028 <    set_log_level(L_INFO);
1029 < } | LOG_LEVEL '=' T_L_DEBUG ';'
1028 >    block_state.type.value = LOG_TYPE_KLINE;
1029 > } | KILL
1030   {
1031    if (conf_parser_ctx.pass == 2)
1032 <    set_log_level(L_DEBUG);
1033 < };
936 <
937 < logging_use_logging: USE_LOGGING '=' TBOOL ';'
1032 >    block_state.type.value = LOG_TYPE_KILL;
1033 > } | T_DEBUG
1034   {
1035    if (conf_parser_ctx.pass == 2)
1036 <    ConfigLoggingEntry.use_logging = yylval.number;
1036 >    block_state.type.value = LOG_TYPE_DEBUG;
1037   };
1038  
1039 +
1040   /***************************************************************************
1041   * section oper
1042   ***************************************************************************/
1043 < oper_entry: OPERATOR
1043 > oper_entry: OPERATOR
1044   {
1045 <  if (conf_parser_ctx.pass == 2)
1046 <  {
1047 <    yy_conf = make_conf_item(OPER_TYPE);
1048 <    yy_aconf = map_to_conf(yy_conf);
1049 <    SetConfEncrypted(yy_aconf); /* Yes, the default is encrypted */
1050 <  }
954 <  else
955 <  {
956 <    MyFree(class_name);
957 <    class_name = NULL;
958 <  }
959 < } oper_name_b '{' oper_items '}' ';'
1045 >  if (conf_parser_ctx.pass != 2)
1046 >    break;
1047 >
1048 >  reset_block_state();
1049 >  block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1050 > } '{' oper_items '}' ';'
1051   {
1052 <  if (conf_parser_ctx.pass == 2)
962 <  {
963 <    struct CollectItem *yy_tmp;
964 <    dlink_node *ptr;
965 <    dlink_node *next_ptr;
1052 >  dlink_node *ptr = NULL;
1053  
1054 <    conf_add_class_to_conf(yy_conf, class_name);
1054 >  if (conf_parser_ctx.pass != 2)
1055 >    break;
1056  
1057 <    /* Now, make sure there is a copy of the "base" given oper
1058 <     * block in each of the collected copies
1059 <     */
1057 >  if (!block_state.name.buf[0])
1058 >    break;
1059 > #ifdef HAVE_LIBCRYPTO
1060 >  if (!block_state.file.buf[0] &&
1061 >      !block_state.rpass.buf[0])
1062 >    break;
1063 > #else
1064 >  if (!block_state.rpass.buf[0])
1065 >    break;
1066 > #endif
1067  
1068 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1069 <    {
1070 <      struct AccessItem *new_aconf;
1071 <      struct ConfItem *new_conf;
977 <      yy_tmp = ptr->data;
978 <
979 <      new_conf = make_conf_item(OPER_TYPE);
980 <      new_aconf = (struct AccessItem *)map_to_conf(new_conf);
981 <
982 <      new_aconf->flags = yy_aconf->flags;
983 <
984 <      if (yy_conf->name != NULL)
985 <        DupString(new_conf->name, yy_conf->name);
986 <      if (yy_tmp->user != NULL)
987 <        DupString(new_aconf->user, yy_tmp->user);
988 <      else
989 <        DupString(new_aconf->user, "*");
990 <      if (yy_tmp->host != NULL)
991 <        DupString(new_aconf->host, yy_tmp->host);
992 <      else
993 <        DupString(new_aconf->host, "*");
994 <      conf_add_class_to_conf(new_conf, class_name);
995 <      if (yy_aconf->passwd != NULL)
996 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1068 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1069 >  {
1070 >    struct MaskItem *conf = NULL;
1071 >    struct split_nuh_item nuh;
1072  
1073 <      new_aconf->port = yy_aconf->port;
1074 < #ifdef HAVE_LIBCRYPTO
1075 <      if (yy_aconf->rsa_public_key_file != NULL)
1076 <      {
1077 <        BIO *file;
1073 >    nuh.nuhmask  = ptr->data;
1074 >    nuh.nickptr  = NULL;
1075 >    nuh.userptr  = block_state.user.buf;
1076 >    nuh.hostptr  = block_state.host.buf;
1077 >    nuh.nicksize = 0;
1078 >    nuh.usersize = sizeof(block_state.user.buf);
1079 >    nuh.hostsize = sizeof(block_state.host.buf);
1080 >    split_nuh(&nuh);
1081  
1082 <        DupString(new_aconf->rsa_public_key_file,
1083 <                  yy_aconf->rsa_public_key_file);
1082 >    conf         = conf_make(CONF_OPER);
1083 >    conf->name   = xstrdup(block_state.name.buf);
1084 >    conf->user   = xstrdup(block_state.user.buf);
1085 >    conf->host   = xstrdup(block_state.host.buf);
1086 >
1087 >    if (block_state.cert.buf[0])
1088 >      conf->certfp = xstrdup(block_state.cert.buf);
1089 >
1090 >    if (block_state.rpass.buf[0])
1091 >      conf->passwd = xstrdup(block_state.rpass.buf);
1092 >
1093 >    conf->flags = block_state.flags.value;
1094 >    conf->modes = block_state.modes.value;
1095 >    conf->port  = block_state.port.value;
1096 >    conf->htype = parse_netmask(conf->host, &conf->addr, &conf->bits);
1097  
1098 <        file = BIO_new_file(yy_aconf->rsa_public_key_file, "r");
1008 <        new_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file,
1009 <                                                           NULL, 0, NULL);
1010 <        BIO_set_close(file, BIO_CLOSE);
1011 <        BIO_free(file);
1012 <      }
1013 < #endif
1098 >    conf_add_class_to_conf(conf, block_state.class.buf);
1099  
1100   #ifdef HAVE_LIBCRYPTO
1101 <      if (yy_tmp->name && (yy_tmp->passwd || yy_aconf->rsa_public_key)
1102 <          && yy_tmp->host)
1103 < #else
1104 <      if (yy_tmp->name && yy_tmp->passwd && yy_tmp->host)
1105 < #endif
1101 >    if (block_state.file.buf[0])
1102 >    {
1103 >      BIO *file = NULL;
1104 >      RSA *pkey = NULL;
1105 >
1106 >      if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
1107        {
1108 <        conf_add_class_to_conf(new_conf, class_name);
1109 <        if (yy_tmp->name != NULL)
1024 <          DupString(new_conf->name, yy_tmp->name);
1108 >        conf_error_report("Ignoring rsa_public_key_file -- file doesn't exist");
1109 >        break;
1110        }
1111  
1112 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1113 <      free_collect_item(yy_tmp);
1029 <    }
1030 <
1031 <    yy_conf = NULL;
1032 <    yy_aconf = NULL;
1033 <
1112 >      if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
1113 >        conf_error_report("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1114  
1115 <    MyFree(class_name);
1116 <    class_name = NULL;
1115 >      conf->rsa_public_key = pkey;
1116 >      BIO_set_close(file, BIO_CLOSE);
1117 >      BIO_free(file);
1118 >    }
1119 > #endif /* HAVE_LIBCRYPTO */
1120    }
1121 < };
1121 > };
1122  
1040 oper_name_b: | oper_name_t;
1123   oper_items:     oper_items oper_item | oper_item;
1124 < oper_item:      oper_name | oper_user | oper_password | oper_hidden_admin |
1125 <                oper_hidden_oper | oper_umodes |
1126 <                oper_class | oper_global_kill | oper_remote |
1127 <                oper_kline | oper_xline | oper_unkline |
1128 <                oper_gline | oper_nick_changes | oper_remoteban |
1129 <                oper_die | oper_rehash | oper_admin | oper_operwall |
1130 <                oper_encrypted | oper_rsa_public_key_file |
1131 <                oper_flags | error ';' ;
1124 > oper_item:      oper_name |
1125 >                oper_user |
1126 >                oper_password |
1127 >                oper_umodes |
1128 >                oper_class |
1129 >                oper_encrypted |
1130 >                oper_rsa_public_key_file |
1131 >                oper_ssl_certificate_fingerprint |
1132 >                oper_ssl_connection_required |
1133 >                oper_flags |
1134 >                error ';' ;
1135  
1136   oper_name: NAME '=' QSTRING ';'
1137   {
1138    if (conf_parser_ctx.pass == 2)
1139 <  {
1055 <    if (strlen(yylval.string) > OPERNICKLEN)
1056 <      yylval.string[OPERNICKLEN] = '\0';
1057 <
1058 <    MyFree(yy_conf->name);
1059 <    DupString(yy_conf->name, yylval.string);
1060 <  }
1061 < };
1062 <
1063 < oper_name_t: QSTRING
1064 < {
1065 <  if (conf_parser_ctx.pass == 2)
1066 <  {
1067 <    if (strlen(yylval.string) > OPERNICKLEN)
1068 <      yylval.string[OPERNICKLEN] = '\0';
1069 <
1070 <    MyFree(yy_conf->name);
1071 <    DupString(yy_conf->name, yylval.string);
1072 <  }
1139 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1140   };
1141  
1142   oper_user: USER '=' QSTRING ';'
1143   {
1144    if (conf_parser_ctx.pass == 2)
1145 <  {
1079 <    struct split_nuh_item nuh;
1080 <
1081 <    nuh.nuhmask  = yylval.string;
1082 <    nuh.nickptr  = NULL;
1083 <    nuh.userptr  = userbuf;
1084 <    nuh.hostptr  = hostbuf;
1085 <
1086 <    nuh.nicksize = 0;
1087 <    nuh.usersize = sizeof(userbuf);
1088 <    nuh.hostsize = sizeof(hostbuf);
1089 <
1090 <    split_nuh(&nuh);
1091 <
1092 <    if (yy_aconf->user == NULL)
1093 <    {
1094 <      DupString(yy_aconf->user, userbuf);
1095 <      DupString(yy_aconf->host, hostbuf);
1096 <    }
1097 <    else
1098 <    {
1099 <      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
1100 <
1101 <      DupString(yy_tmp->user, userbuf);
1102 <      DupString(yy_tmp->host, hostbuf);
1103 <
1104 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1105 <    }
1106 <  }
1145 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1146   };
1147  
1148   oper_password: PASSWORD '=' QSTRING ';'
1149   {
1150    if (conf_parser_ctx.pass == 2)
1151 <  {
1113 <    if (yy_aconf->passwd != NULL)
1114 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1115 <
1116 <    MyFree(yy_aconf->passwd);
1117 <    DupString(yy_aconf->passwd, yylval.string);
1118 <  }
1151 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1152   };
1153  
1154   oper_encrypted: ENCRYPTED '=' TBOOL ';'
1155   {
1156 <  if (conf_parser_ctx.pass == 2)
1157 <  {
1158 <    if (yylval.number)
1159 <      SetConfEncrypted(yy_aconf);
1160 <    else
1161 <      ClearConfEncrypted(yy_aconf);
1162 <  }
1156 >  if (conf_parser_ctx.pass != 2)
1157 >    break;
1158 >
1159 >  if (yylval.number)
1160 >    block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1161 >  else
1162 >    block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1163   };
1164  
1165   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
1166   {
1134 #ifdef HAVE_LIBCRYPTO
1167    if (conf_parser_ctx.pass == 2)
1168 <  {
1169 <    BIO *file;
1138 <
1139 <    if (yy_aconf->rsa_public_key != NULL)
1140 <    {
1141 <      RSA_free(yy_aconf->rsa_public_key);
1142 <      yy_aconf->rsa_public_key = NULL;
1143 <    }
1144 <
1145 <    if (yy_aconf->rsa_public_key_file != NULL)
1146 <    {
1147 <      MyFree(yy_aconf->rsa_public_key_file);
1148 <      yy_aconf->rsa_public_key_file = NULL;
1149 <    }
1150 <
1151 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
1152 <    file = BIO_new_file(yylval.string, "r");
1153 <
1154 <    if (file == NULL)
1155 <    {
1156 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
1157 <      break;
1158 <    }
1168 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1169 > };
1170  
1171 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
1171 > oper_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
1172 > {
1173 >  if (conf_parser_ctx.pass == 2)
1174 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
1175 > };
1176  
1177 <    if (yy_aconf->rsa_public_key == NULL)
1178 <    {
1179 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1180 <      break;
1166 <    }
1177 > oper_ssl_connection_required: SSL_CONNECTION_REQUIRED '=' TBOOL ';'
1178 > {
1179 >  if (conf_parser_ctx.pass != 2)
1180 >    break;
1181  
1182 <    BIO_set_close(file, BIO_CLOSE);
1183 <    BIO_free(file);
1184 <  }
1185 < #endif /* HAVE_LIBCRYPTO */
1182 >  if (yylval.number)
1183 >    block_state.flags.value |= CONF_FLAGS_SSL;
1184 >  else
1185 >    block_state.flags.value &= ~CONF_FLAGS_SSL;
1186   };
1187  
1188   oper_class: CLASS '=' QSTRING ';'
1189   {
1190    if (conf_parser_ctx.pass == 2)
1191 <  {
1178 <    MyFree(class_name);
1179 <    DupString(class_name, yylval.string);
1180 <  }
1191 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1192   };
1193  
1194   oper_umodes: T_UMODES
1195   {
1196    if (conf_parser_ctx.pass == 2)
1197 <    yy_aconf->modes = 0;
1197 >    block_state.modes.value = 0;
1198   } '='  oper_umodes_items ';' ;
1199  
1200   oper_umodes_items: oper_umodes_items ',' oper_umodes_item | oper_umodes_item;
1201   oper_umodes_item:  T_BOTS
1202   {
1203    if (conf_parser_ctx.pass == 2)
1204 <    yy_aconf->modes |= UMODE_BOTS;
1204 >    block_state.modes.value |= UMODE_BOTS;
1205   } | T_CCONN
1206   {
1207    if (conf_parser_ctx.pass == 2)
1208 <    yy_aconf->modes |= UMODE_CCONN;
1198 < } | T_CCONN_FULL
1199 < {
1200 <  if (conf_parser_ctx.pass == 2)
1201 <    yy_aconf->modes |= UMODE_CCONN_FULL;
1208 >    block_state.modes.value |= UMODE_CCONN;
1209   } | T_DEAF
1210   {
1211    if (conf_parser_ctx.pass == 2)
1212 <    yy_aconf->modes |= UMODE_DEAF;
1212 >    block_state.modes.value |= UMODE_DEAF;
1213   } | T_DEBUG
1214   {
1215    if (conf_parser_ctx.pass == 2)
1216 <    yy_aconf->modes |= UMODE_DEBUG;
1216 >    block_state.modes.value |= UMODE_DEBUG;
1217   } | T_FULL
1218   {
1219    if (conf_parser_ctx.pass == 2)
1220 <    yy_aconf->modes |= UMODE_FULL;
1220 >    block_state.modes.value |= UMODE_FULL;
1221 > } | HIDDEN
1222 > {
1223 >  if (conf_parser_ctx.pass == 2)
1224 >    block_state.modes.value |= UMODE_HIDDEN;
1225 > } | HIDE_CHANS
1226 > {
1227 >  if (conf_parser_ctx.pass == 2)
1228 >    block_state.modes.value |= UMODE_HIDECHANS;
1229 > } | HIDE_IDLE
1230 > {
1231 >  if (conf_parser_ctx.pass == 2)
1232 >    block_state.modes.value |= UMODE_HIDEIDLE;
1233   } | T_SKILL
1234   {
1235    if (conf_parser_ctx.pass == 2)
1236 <    yy_aconf->modes |= UMODE_SKILL;
1236 >    block_state.modes.value |= UMODE_SKILL;
1237   } | T_NCHANGE
1238   {
1239    if (conf_parser_ctx.pass == 2)
1240 <    yy_aconf->modes |= UMODE_NCHANGE;
1240 >    block_state.modes.value |= UMODE_NCHANGE;
1241   } | T_REJ
1242   {
1243    if (conf_parser_ctx.pass == 2)
1244 <    yy_aconf->modes |= UMODE_REJ;
1244 >    block_state.modes.value |= UMODE_REJ;
1245   } | T_UNAUTH
1246   {
1247    if (conf_parser_ctx.pass == 2)
1248 <    yy_aconf->modes |= UMODE_UNAUTH;
1248 >    block_state.modes.value |= UMODE_UNAUTH;
1249   } | T_SPY
1250   {
1251    if (conf_parser_ctx.pass == 2)
1252 <    yy_aconf->modes |= UMODE_SPY;
1252 >    block_state.modes.value |= UMODE_SPY;
1253   } | T_EXTERNAL
1254   {
1255    if (conf_parser_ctx.pass == 2)
1256 <    yy_aconf->modes |= UMODE_EXTERNAL;
1238 < } | T_OPERWALL
1239 < {
1240 <  if (conf_parser_ctx.pass == 2)
1241 <    yy_aconf->modes |= UMODE_OPERWALL;
1256 >    block_state.modes.value |= UMODE_EXTERNAL;
1257   } | T_SERVNOTICE
1258   {
1259    if (conf_parser_ctx.pass == 2)
1260 <    yy_aconf->modes |= UMODE_SERVNOTICE;
1260 >    block_state.modes.value |= UMODE_SERVNOTICE;
1261   } | T_INVISIBLE
1262   {
1263    if (conf_parser_ctx.pass == 2)
1264 <    yy_aconf->modes |= UMODE_INVISIBLE;
1264 >    block_state.modes.value |= UMODE_INVISIBLE;
1265   } | T_WALLOP
1266   {
1267    if (conf_parser_ctx.pass == 2)
1268 <    yy_aconf->modes |= UMODE_WALLOP;
1268 >    block_state.modes.value |= UMODE_WALLOP;
1269   } | T_SOFTCALLERID
1270   {
1271    if (conf_parser_ctx.pass == 2)
1272 <    yy_aconf->modes |= UMODE_SOFTCALLERID;
1272 >    block_state.modes.value |= UMODE_SOFTCALLERID;
1273   } | T_CALLERID
1274   {
1275    if (conf_parser_ctx.pass == 2)
1276 <    yy_aconf->modes |= UMODE_CALLERID;
1276 >    block_state.modes.value |= UMODE_CALLERID;
1277   } | T_LOCOPS
1278   {
1279    if (conf_parser_ctx.pass == 2)
1280 <    yy_aconf->modes |= UMODE_LOCOPS;
1281 < };
1267 <
1268 < oper_global_kill: GLOBAL_KILL '=' TBOOL ';'
1280 >    block_state.modes.value |= UMODE_LOCOPS;
1281 > } | T_NONONREG
1282   {
1283    if (conf_parser_ctx.pass == 2)
1284 <  {
1285 <    if (yylval.number)
1273 <      yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1274 <    else
1275 <      yy_aconf->port &= ~OPER_FLAG_GLOBAL_KILL;
1276 <  }
1277 < };
1278 <
1279 < oper_remote: REMOTE '=' TBOOL ';'
1280 < {
1281 <  if (conf_parser_ctx.pass == 2)
1282 <  {
1283 <    if (yylval.number)
1284 <      yy_aconf->port |= OPER_FLAG_REMOTE;
1285 <    else
1286 <      yy_aconf->port &= ~OPER_FLAG_REMOTE;
1287 <  }
1288 < };
1289 <
1290 < oper_remoteban: REMOTEBAN '=' TBOOL ';'
1291 < {
1292 <  if (conf_parser_ctx.pass == 2)
1293 <  {
1294 <    if (yylval.number)
1295 <      yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1296 <    else
1297 <      yy_aconf->port &= ~OPER_FLAG_REMOTEBAN;
1298 <  }
1299 < };
1300 <
1301 < oper_kline: KLINE '=' TBOOL ';'
1302 < {
1303 <  if (conf_parser_ctx.pass == 2)
1304 <  {
1305 <    if (yylval.number)
1306 <      yy_aconf->port |= OPER_FLAG_K;
1307 <    else
1308 <      yy_aconf->port &= ~OPER_FLAG_K;
1309 <  }
1310 < };
1311 <
1312 < oper_xline: XLINE '=' TBOOL ';'
1313 < {
1314 <  if (conf_parser_ctx.pass == 2)
1315 <  {
1316 <    if (yylval.number)
1317 <      yy_aconf->port |= OPER_FLAG_X;
1318 <    else
1319 <      yy_aconf->port &= ~OPER_FLAG_X;
1320 <  }
1321 < };
1322 <
1323 < oper_unkline: UNKLINE '=' TBOOL ';'
1284 >    block_state.modes.value |= UMODE_REGONLY;
1285 > } | T_FARCONNECT
1286   {
1287    if (conf_parser_ctx.pass == 2)
1288 <  {
1327 <    if (yylval.number)
1328 <      yy_aconf->port |= OPER_FLAG_UNKLINE;
1329 <    else
1330 <      yy_aconf->port &= ~OPER_FLAG_UNKLINE;
1331 <  }
1288 >    block_state.modes.value |= UMODE_FARCONNECT;
1289   };
1290  
1291 < oper_gline: GLINE '=' TBOOL ';'
1291 > oper_flags: IRCD_FLAGS
1292   {
1293    if (conf_parser_ctx.pass == 2)
1294 <  {
1295 <    if (yylval.number)
1339 <      yy_aconf->port |= OPER_FLAG_GLINE;
1340 <    else
1341 <      yy_aconf->port &= ~OPER_FLAG_GLINE;
1342 <  }
1343 < };
1294 >    block_state.port.value = 0;
1295 > } '='  oper_flags_items ';';
1296  
1297 < oper_nick_changes: NICK_CHANGES '=' TBOOL ';'
1297 > oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1298 > oper_flags_item: KILL ':' REMOTE
1299   {
1300    if (conf_parser_ctx.pass == 2)
1301 <  {
1302 <    if (yylval.number)
1350 <      yy_aconf->port |= OPER_FLAG_N;
1351 <    else
1352 <      yy_aconf->port &= ~OPER_FLAG_N;
1353 <  }
1354 < };
1355 <
1356 < oper_die: DIE '=' TBOOL ';'
1301 >    block_state.port.value |= OPER_FLAG_KILL_REMOTE;
1302 > } | KILL
1303   {
1304    if (conf_parser_ctx.pass == 2)
1305 <  {
1306 <    if (yylval.number)
1361 <      yy_aconf->port |= OPER_FLAG_DIE;
1362 <    else
1363 <      yy_aconf->port &= ~OPER_FLAG_DIE;
1364 <  }
1365 < };
1366 <
1367 < oper_rehash: REHASH '=' TBOOL ';'
1305 >    block_state.port.value |= OPER_FLAG_KILL;
1306 > } | CONNECT ':' REMOTE
1307   {
1308    if (conf_parser_ctx.pass == 2)
1309 <  {
1310 <    if (yylval.number)
1372 <      yy_aconf->port |= OPER_FLAG_REHASH;
1373 <    else
1374 <      yy_aconf->port &= ~OPER_FLAG_REHASH;
1375 <  }
1376 < };
1377 <
1378 < oper_admin: ADMIN '=' TBOOL ';'
1309 >    block_state.port.value |= OPER_FLAG_CONNECT_REMOTE;
1310 > } | CONNECT
1311   {
1312    if (conf_parser_ctx.pass == 2)
1313 <  {
1314 <    if (yylval.number)
1383 <      yy_aconf->port |= OPER_FLAG_ADMIN;
1384 <    else
1385 <      yy_aconf->port &= ~OPER_FLAG_ADMIN;
1386 <  }
1387 < };
1388 <
1389 < oper_hidden_admin: HIDDEN_ADMIN '=' TBOOL ';'
1313 >    block_state.port.value |= OPER_FLAG_CONNECT;
1314 > } | SQUIT ':' REMOTE
1315   {
1316    if (conf_parser_ctx.pass == 2)
1317 <  {
1318 <    if (yylval.number)
1394 <      yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1395 <    else
1396 <      yy_aconf->port &= ~OPER_FLAG_HIDDEN_ADMIN;
1397 <  }
1398 < };
1399 <
1400 < oper_hidden_oper: HIDDEN_OPER '=' TBOOL ';'
1317 >    block_state.port.value |= OPER_FLAG_SQUIT_REMOTE;
1318 > } | SQUIT
1319   {
1320    if (conf_parser_ctx.pass == 2)
1321 <  {
1322 <    if (yylval.number)
1405 <      yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1406 <    else
1407 <      yy_aconf->port &= ~OPER_FLAG_HIDDEN_OPER;
1408 <  }
1409 < };
1410 <
1411 < oper_operwall: T_OPERWALL '=' TBOOL ';'
1321 >    block_state.port.value |= OPER_FLAG_SQUIT;
1322 > } | KLINE
1323   {
1324    if (conf_parser_ctx.pass == 2)
1325 <  {
1326 <    if (yylval.number)
1416 <      yy_aconf->port |= OPER_FLAG_OPERWALL;
1417 <    else
1418 <      yy_aconf->port &= ~OPER_FLAG_OPERWALL;
1419 <  }
1420 < };
1421 <
1422 < oper_flags: IRCD_FLAGS
1423 < {
1424 < } '='  oper_flags_items ';';
1425 <
1426 < oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1427 < oper_flags_item: NOT { not_atom = 1; } oper_flags_item_atom
1428 <                | { not_atom = 0; } oper_flags_item_atom;
1429 <
1430 < oper_flags_item_atom: GLOBAL_KILL
1325 >    block_state.port.value |= OPER_FLAG_KLINE;
1326 > } | UNKLINE
1327   {
1328    if (conf_parser_ctx.pass == 2)
1329 <  {
1330 <    if (not_atom)yy_aconf->port &= ~OPER_FLAG_GLOBAL_KILL;
1435 <    else yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1436 <  }
1437 < } | REMOTE
1329 >    block_state.port.value |= OPER_FLAG_UNKLINE;
1330 > } | T_DLINE
1331   {
1332    if (conf_parser_ctx.pass == 2)
1333 <  {
1334 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTE;
1442 <    else yy_aconf->port |= OPER_FLAG_REMOTE;
1443 <  }
1444 < } | KLINE
1333 >    block_state.port.value |= OPER_FLAG_DLINE;
1334 > } | T_UNDLINE
1335   {
1336    if (conf_parser_ctx.pass == 2)
1337 <  {
1338 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_K;
1449 <    else yy_aconf->port |= OPER_FLAG_K;
1450 <  }
1451 < } | UNKLINE
1337 >    block_state.port.value |= OPER_FLAG_UNDLINE;
1338 > } | XLINE
1339   {
1340    if (conf_parser_ctx.pass == 2)
1341 <  {
1342 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_UNKLINE;
1456 <    else yy_aconf->port |= OPER_FLAG_UNKLINE;
1457 <  }
1458 < } | XLINE
1341 >    block_state.port.value |= OPER_FLAG_XLINE;
1342 > } | T_UNXLINE
1343   {
1344    if (conf_parser_ctx.pass == 2)
1345 <  {
1462 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_X;
1463 <    else yy_aconf->port |= OPER_FLAG_X;
1464 <  }
1345 >    block_state.port.value |= OPER_FLAG_UNXLINE;
1346   } | GLINE
1347   {
1348    if (conf_parser_ctx.pass == 2)
1349 <  {
1469 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_GLINE;
1470 <    else yy_aconf->port |= OPER_FLAG_GLINE;
1471 <  }
1349 >    block_state.port.value |= OPER_FLAG_GLINE;
1350   } | DIE
1351   {
1352    if (conf_parser_ctx.pass == 2)
1353 <  {
1354 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_DIE;
1355 <    else yy_aconf->port |= OPER_FLAG_DIE;
1356 <  }
1353 >    block_state.port.value |= OPER_FLAG_DIE;
1354 > } | T_RESTART
1355 > {
1356 >  if (conf_parser_ctx.pass == 2)
1357 >    block_state.port.value |= OPER_FLAG_RESTART;
1358   } | REHASH
1359   {
1360    if (conf_parser_ctx.pass == 2)
1361 <  {
1483 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REHASH;
1484 <    else yy_aconf->port |= OPER_FLAG_REHASH;
1485 <  }
1361 >    block_state.port.value |= OPER_FLAG_REHASH;
1362   } | ADMIN
1363   {
1364    if (conf_parser_ctx.pass == 2)
1365 <  {
1366 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_ADMIN;
1491 <    else yy_aconf->port |= OPER_FLAG_ADMIN;
1492 <  }
1493 < } | HIDDEN_ADMIN
1365 >    block_state.port.value |= OPER_FLAG_ADMIN;
1366 > } | T_GLOBOPS
1367   {
1368    if (conf_parser_ctx.pass == 2)
1369 <  {
1370 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_ADMIN;
1498 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1499 <  }
1500 < } | NICK_CHANGES
1369 >    block_state.port.value |= OPER_FLAG_GLOBOPS;
1370 > } | T_WALLOPS
1371   {
1372    if (conf_parser_ctx.pass == 2)
1373 <  {
1374 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_N;
1505 <    else yy_aconf->port |= OPER_FLAG_N;
1506 <  }
1507 < } | T_OPERWALL
1508 < {
1509 <  if (conf_parser_ctx.pass == 2)
1510 <  {
1511 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPERWALL;
1512 <    else yy_aconf->port |= OPER_FLAG_OPERWALL;
1513 <  }
1514 < } | OPER_SPY_T
1373 >    block_state.port.value |= OPER_FLAG_WALLOPS;
1374 > } | T_LOCOPS
1375   {
1376    if (conf_parser_ctx.pass == 2)
1377 <  {
1378 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPER_SPY;
1519 <    else yy_aconf->port |= OPER_FLAG_OPER_SPY;
1520 <  }
1521 < } | HIDDEN_OPER
1377 >    block_state.port.value |= OPER_FLAG_LOCOPS;
1378 > } | REMOTEBAN
1379   {
1380    if (conf_parser_ctx.pass == 2)
1381 <  {
1382 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_OPER;
1526 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1527 <  }
1528 < } | REMOTEBAN
1381 >    block_state.port.value |= OPER_FLAG_REMOTEBAN;
1382 > } | T_SET
1383   {
1384    if (conf_parser_ctx.pass == 2)
1385 <  {
1386 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTEBAN;
1533 <    else yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1534 <  }
1535 < } | ENCRYPTED
1385 >    block_state.port.value |= OPER_FLAG_SET;
1386 > } | MODULE
1387   {
1388    if (conf_parser_ctx.pass == 2)
1389 <  {
1539 <    if (not_atom) ClearConfEncrypted(yy_aconf);
1540 <    else SetConfEncrypted(yy_aconf);
1541 <  }
1389 >    block_state.port.value |= OPER_FLAG_MODULE;
1390   };
1391  
1392  
# Line 1547 | Line 1395 | oper_flags_item_atom: GLOBAL_KILL
1395   ***************************************************************************/
1396   class_entry: CLASS
1397   {
1398 <  if (conf_parser_ctx.pass == 1)
1399 <  {
1552 <    yy_conf = make_conf_item(CLASS_TYPE);
1553 <    yy_class = map_to_conf(yy_conf);
1554 <  }
1555 < } class_name_b '{' class_items '}' ';'
1556 < {
1557 <  if (conf_parser_ctx.pass == 1)
1558 <  {
1559 <    struct ConfItem *cconf = NULL;
1560 <    struct ClassItem *class = NULL;
1561 <
1562 <    if (yy_class_name == NULL)
1563 <      delete_conf_item(yy_conf);
1564 <    else
1565 <    {
1566 <      cconf = find_exact_name_conf(CLASS_TYPE, yy_class_name, NULL, NULL);
1567 <
1568 <      if (cconf != NULL)                /* The class existed already */
1569 <      {
1570 <        int user_count = 0;
1571 <
1572 <        rebuild_cidr_class(cconf, yy_class);
1398 >  if (conf_parser_ctx.pass != 1)
1399 >    break;
1400  
1401 <        class = map_to_conf(cconf);
1401 >  reset_block_state();
1402  
1403 <        user_count = class->curr_user_count;
1404 <        memcpy(class, yy_class, sizeof(*class));
1405 <        class->curr_user_count = user_count;
1406 <        class->active = 1;
1407 <
1408 <        delete_conf_item(yy_conf);
1409 <
1410 <        MyFree(cconf->name);            /* Allows case change of class name */
1411 <        cconf->name = yy_class_name;
1412 <      }
1413 <      else      /* Brand new class */
1414 <      {
1415 <        MyFree(yy_conf->name);          /* just in case it was allocated */
1416 <        yy_conf->name = yy_class_name;
1417 <        yy_class->active = 1;
1418 <      }
1419 <    }
1420 <
1421 <    yy_class_name = NULL;
1422 <  }
1403 >  block_state.ping_freq.value = DEFAULT_PINGFREQUENCY;
1404 >  block_state.con_freq.value  = DEFAULT_CONNECTFREQUENCY;
1405 >  block_state.max_total.value = MAXIMUM_LINKS_DEFAULT;
1406 >  block_state.max_sendq.value = DEFAULT_SENDQ;
1407 >  block_state.max_recvq.value = DEFAULT_RECVQ;
1408 > } '{' class_items '}' ';'
1409 > {
1410 >  struct ClassItem *class = NULL;
1411 >
1412 >  if (conf_parser_ctx.pass != 1)
1413 >    break;
1414 >
1415 >  if (!block_state.class.buf[0])
1416 >    break;
1417 >
1418 >  if (!(class = class_find(block_state.class.buf, 0)))
1419 >    class = class_make();
1420 >
1421 >  class->active = 1;
1422 >  MyFree(class->name);
1423 >  class->name = xstrdup(block_state.class.buf);
1424 >  class->ping_freq = block_state.ping_freq.value;
1425 >  class->max_perip = block_state.max_perip.value;
1426 >  class->con_freq = block_state.con_freq.value;
1427 >  class->max_total = block_state.max_total.value;
1428 >  class->max_global = block_state.max_global.value;
1429 >  class->max_local = block_state.max_local.value;
1430 >  class->max_ident = block_state.max_ident.value;
1431 >  class->max_sendq = block_state.max_sendq.value;
1432 >  class->max_recvq = block_state.max_recvq.value;
1433 >  class->max_channels = block_state.max_channels.value;
1434 >
1435 >  if (block_state.min_idle.value > block_state.max_idle.value)
1436 >  {
1437 >    block_state.min_idle.value = 0;
1438 >    block_state.max_idle.value = 0;
1439 >    block_state.flags.value &= ~CLASS_FLAGS_FAKE_IDLE;
1440 >  }
1441 >
1442 >  class->flags = block_state.flags.value;
1443 >  class->min_idle = block_state.min_idle.value;
1444 >  class->max_idle = block_state.max_idle.value;
1445 >
1446 >  if (class->number_per_cidr && block_state.number_per_cidr.value)
1447 >    if ((class->cidr_bitlen_ipv4 && block_state.cidr_bitlen_ipv4.value) ||
1448 >        (class->cidr_bitlen_ipv6 && block_state.cidr_bitlen_ipv6.value))
1449 >      if ((class->cidr_bitlen_ipv4 != block_state.cidr_bitlen_ipv4.value) ||
1450 >          (class->cidr_bitlen_ipv6 != block_state.cidr_bitlen_ipv6.value))
1451 >        rebuild_cidr_list(class);
1452 >
1453 >  class->cidr_bitlen_ipv4 = block_state.cidr_bitlen_ipv4.value;
1454 >  class->cidr_bitlen_ipv6 = block_state.cidr_bitlen_ipv6.value;
1455 >  class->number_per_cidr = block_state.number_per_cidr.value;
1456   };
1457  
1598 class_name_b: | class_name_t;
1599
1458   class_items:    class_items class_item | class_item;
1459   class_item:     class_name |
1460 <                class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1460 >                class_cidr_bitlen_ipv4 |
1461 >                class_cidr_bitlen_ipv6 |
1462                  class_ping_time |
1463 <                class_ping_warning |
1605 <                class_number_per_cidr |
1463 >                class_number_per_cidr |
1464                  class_number_per_ip |
1465                  class_connectfreq |
1466 +                class_max_channels |
1467                  class_max_number |
1468 <                class_max_global |
1469 <                class_max_local |
1470 <                class_max_ident |
1471 <                class_sendq |
1472 <                error ';' ;
1468 >                class_max_global |
1469 >                class_max_local |
1470 >                class_max_ident |
1471 >                class_sendq | class_recvq |
1472 >                class_min_idle |
1473 >                class_max_idle |
1474 >                class_flags |
1475 >                error ';' ;
1476  
1477 < class_name: NAME '=' QSTRING ';'
1477 > class_name: NAME '=' QSTRING ';'
1478   {
1479    if (conf_parser_ctx.pass == 1)
1480 <  {
1619 <    MyFree(yy_class_name);
1620 <    DupString(yy_class_name, yylval.string);
1621 <  }
1622 < };
1623 <
1624 < class_name_t: QSTRING
1625 < {
1626 <  if (conf_parser_ctx.pass == 1)
1627 <  {
1628 <    MyFree(yy_class_name);
1629 <    DupString(yy_class_name, yylval.string);
1630 <  }
1480 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1481   };
1482  
1483   class_ping_time: PING_TIME '=' timespec ';'
1484   {
1485    if (conf_parser_ctx.pass == 1)
1486 <    PingFreq(yy_class) = $3;
1486 >    block_state.ping_freq.value = $3;
1487   };
1488  
1489 < class_ping_warning: PING_WARNING '=' timespec ';'
1489 > class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1490   {
1491    if (conf_parser_ctx.pass == 1)
1492 <    PingWarning(yy_class) = $3;
1492 >    block_state.max_perip.value = $3;
1493   };
1494  
1495 < class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1495 > class_connectfreq: CONNECTFREQ '=' timespec ';'
1496   {
1497    if (conf_parser_ctx.pass == 1)
1498 <    MaxPerIp(yy_class) = $3;
1498 >    block_state.con_freq.value = $3;
1499   };
1500  
1501 < class_connectfreq: CONNECTFREQ '=' timespec ';'
1501 > class_max_channels: MAX_CHANNELS '=' NUMBER ';'
1502   {
1503    if (conf_parser_ctx.pass == 1)
1504 <    ConFreq(yy_class) = $3;
1504 >    block_state.max_channels.value = $3;
1505   };
1506  
1507   class_max_number: MAX_NUMBER '=' NUMBER ';'
1508   {
1509    if (conf_parser_ctx.pass == 1)
1510 <    MaxTotal(yy_class) = $3;
1510 >    block_state.max_total.value = $3;
1511   };
1512  
1513   class_max_global: MAX_GLOBAL '=' NUMBER ';'
1514   {
1515    if (conf_parser_ctx.pass == 1)
1516 <    MaxGlobal(yy_class) = $3;
1516 >    block_state.max_global.value = $3;
1517   };
1518  
1519   class_max_local: MAX_LOCAL '=' NUMBER ';'
1520   {
1521    if (conf_parser_ctx.pass == 1)
1522 <    MaxLocal(yy_class) = $3;
1522 >    block_state.max_local.value = $3;
1523   };
1524  
1525   class_max_ident: MAX_IDENT '=' NUMBER ';'
1526   {
1527    if (conf_parser_ctx.pass == 1)
1528 <    MaxIdent(yy_class) = $3;
1528 >    block_state.max_ident.value = $3;
1529   };
1530  
1531   class_sendq: SENDQ '=' sizespec ';'
1532   {
1533    if (conf_parser_ctx.pass == 1)
1534 <    MaxSendq(yy_class) = $3;
1534 >    block_state.max_sendq.value = $3;
1535 > };
1536 >
1537 > class_recvq: T_RECVQ '=' sizespec ';'
1538 > {
1539 >  if (conf_parser_ctx.pass == 1)
1540 >    if ($3 >= CLIENT_FLOOD_MIN && $3 <= CLIENT_FLOOD_MAX)
1541 >      block_state.max_recvq.value = $3;
1542   };
1543  
1544   class_cidr_bitlen_ipv4: CIDR_BITLEN_IPV4 '=' NUMBER ';'
1545   {
1546    if (conf_parser_ctx.pass == 1)
1547 <    CidrBitlenIPV4(yy_class) = $3;
1547 >    block_state.cidr_bitlen_ipv4.value = $3 > 32 ? 32 : $3;
1548   };
1549  
1550   class_cidr_bitlen_ipv6: CIDR_BITLEN_IPV6 '=' NUMBER ';'
1551   {
1552    if (conf_parser_ctx.pass == 1)
1553 <    CidrBitlenIPV6(yy_class) = $3;
1553 >    block_state.cidr_bitlen_ipv6.value = $3 > 128 ? 128 : $3;
1554   };
1555  
1556   class_number_per_cidr: NUMBER_PER_CIDR '=' NUMBER ';'
1557   {
1558    if (conf_parser_ctx.pass == 1)
1559 <    NumberPerCidr(yy_class) = $3;
1559 >    block_state.number_per_cidr.value = $3;
1560 > };
1561 >
1562 > class_min_idle: MIN_IDLE '=' timespec ';'
1563 > {
1564 >  if (conf_parser_ctx.pass != 1)
1565 >    break;
1566 >
1567 >  block_state.min_idle.value = $3;
1568 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1569 > };
1570 >
1571 > class_max_idle: MAX_IDLE '=' timespec ';'
1572 > {
1573 >  if (conf_parser_ctx.pass != 1)
1574 >    break;
1575 >
1576 >  block_state.max_idle.value = $3;
1577 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1578 > };
1579 >
1580 > class_flags: IRCD_FLAGS
1581 > {
1582 >  if (conf_parser_ctx.pass == 1)
1583 >    block_state.flags.value &= CLASS_FLAGS_FAKE_IDLE;
1584 > } '='  class_flags_items ';';
1585 >
1586 > class_flags_items: class_flags_items ',' class_flags_item | class_flags_item;
1587 > class_flags_item: RANDOM_IDLE
1588 > {
1589 >  if (conf_parser_ctx.pass == 1)
1590 >    block_state.flags.value |= CLASS_FLAGS_RANDOM_IDLE;
1591 > } | HIDE_IDLE_FROM_OPERS
1592 > {
1593 >  if (conf_parser_ctx.pass == 1)
1594 >    block_state.flags.value |= CLASS_FLAGS_HIDE_IDLE_FROM_OPERS;
1595   };
1596  
1597 +
1598   /***************************************************************************
1599   *  section listen
1600   ***************************************************************************/
1601   listen_entry: LISTEN
1602   {
1603    if (conf_parser_ctx.pass == 2)
1604 <  {
1605 <    listener_address = NULL;
1713 <    listener_flags = 0;
1714 <  }
1715 < } '{' listen_items '}' ';'
1716 < {
1717 <  if (conf_parser_ctx.pass == 2)
1718 <  {
1719 <    MyFree(listener_address);
1720 <    listener_address = NULL;
1721 <  }
1722 < };
1604 >    reset_block_state();
1605 > } '{' listen_items '}' ';';
1606  
1607   listen_flags: IRCD_FLAGS
1608   {
1609 <  listener_flags = 0;
1609 >  block_state.flags.value = 0;
1610   } '='  listen_flags_items ';';
1611  
1612   listen_flags_items: listen_flags_items ',' listen_flags_item | listen_flags_item;
1613   listen_flags_item: T_SSL
1614   {
1615    if (conf_parser_ctx.pass == 2)
1616 <    listener_flags |= LISTENER_SSL;
1616 >    block_state.flags.value |= LISTENER_SSL;
1617   } | HIDDEN
1618   {
1619    if (conf_parser_ctx.pass == 2)
1620 <    listener_flags |= LISTENER_HIDDEN;
1620 >    block_state.flags.value |= LISTENER_HIDDEN;
1621   } | T_SERVER
1622   {
1623    if (conf_parser_ctx.pass == 2)
1624 <    listener_flags |= LISTENER_SERVER;
1624 >   block_state.flags.value |= LISTENER_SERVER;
1625   };
1626  
1744
1745
1627   listen_items:   listen_items listen_item | listen_item;
1628   listen_item:    listen_port | listen_flags | listen_address | listen_host | error ';';
1629  
1630 < listen_port: PORT '=' port_items { listener_flags = 0; } ';';
1630 > listen_port: PORT '=' port_items { block_state.flags.value = 0; } ';';
1631  
1632   port_items: port_items ',' port_item | port_item;
1633  
# Line 1754 | Line 1635 | port_item: NUMBER
1635   {
1636    if (conf_parser_ctx.pass == 2)
1637    {
1638 <    if ((listener_flags & LISTENER_SSL))
1638 >    if (block_state.flags.value & LISTENER_SSL)
1639   #ifdef HAVE_LIBCRYPTO
1640        if (!ServerInfo.server_ctx)
1641   #endif
1642        {
1643 <        yyerror("SSL not available - port closed");
1644 <        break;
1643 >        conf_error_report("SSL not available - port closed");
1644 >        break;
1645        }
1646 <    add_listener($1, listener_address, listener_flags);
1646 >    add_listener($1, block_state.addr.buf, block_state.flags.value);
1647    }
1648   } | NUMBER TWODOTS NUMBER
1649   {
1650    if (conf_parser_ctx.pass == 2)
1651    {
1652 <    int i;
1772 <
1773 <    if ((listener_flags & LISTENER_SSL))
1652 >    if (block_state.flags.value & LISTENER_SSL)
1653   #ifdef HAVE_LIBCRYPTO
1654        if (!ServerInfo.server_ctx)
1655   #endif
1656        {
1657 <        yyerror("SSL not available - port closed");
1658 <        break;
1657 >        conf_error_report("SSL not available - port closed");
1658 >        break;
1659        }
1660  
1661 <    for (i = $1; i <= $3; ++i)
1662 <      add_listener(i, listener_address, listener_flags);
1661 >    for (int i = $1; i <= $3; ++i)
1662 >      add_listener(i, block_state.addr.buf, block_state.flags.value);
1663    }
1664   };
1665  
1666   listen_address: IP '=' QSTRING ';'
1667   {
1668    if (conf_parser_ctx.pass == 2)
1669 <  {
1791 <    MyFree(listener_address);
1792 <    DupString(listener_address, yylval.string);
1793 <  }
1669 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1670   };
1671  
1672   listen_host: HOST '=' QSTRING ';'
1673   {
1674    if (conf_parser_ctx.pass == 2)
1675 <  {
1800 <    MyFree(listener_address);
1801 <    DupString(listener_address, yylval.string);
1802 <  }
1675 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1676   };
1677  
1678   /***************************************************************************
# Line 1808 | Line 1681 | listen_host: HOST '=' QSTRING ';'
1681   auth_entry: IRCD_AUTH
1682   {
1683    if (conf_parser_ctx.pass == 2)
1684 <  {
1812 <    yy_conf = make_conf_item(CLIENT_TYPE);
1813 <    yy_aconf = map_to_conf(yy_conf);
1814 <  }
1815 <  else
1816 <  {
1817 <    MyFree(class_name);
1818 <    class_name = NULL;
1819 <  }
1684 >    reset_block_state();
1685   } '{' auth_items '}' ';'
1686   {
1687 <  if (conf_parser_ctx.pass == 2)
1823 <  {
1824 <    struct CollectItem *yy_tmp = NULL;
1825 <    dlink_node *ptr = NULL, *next_ptr = NULL;
1826 <
1827 <    if (yy_aconf->user && yy_aconf->host)
1828 <    {
1829 <      conf_add_class_to_conf(yy_conf, class_name);
1830 <      add_conf_by_address(CONF_CLIENT, yy_aconf);
1831 <    }
1832 <    else
1833 <      delete_conf_item(yy_conf);
1834 <
1835 <    /* copy over settings from first struct */
1836 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1837 <    {
1838 <      struct AccessItem *new_aconf;
1839 <      struct ConfItem *new_conf;
1840 <
1841 <      new_conf = make_conf_item(CLIENT_TYPE);
1842 <      new_aconf = map_to_conf(new_conf);
1843 <
1844 <      yy_tmp = ptr->data;
1845 <
1846 <      assert(yy_tmp->user && yy_tmp->host);
1847 <
1848 <      if (yy_aconf->passwd != NULL)
1849 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1850 <      if (yy_conf->name != NULL)
1851 <        DupString(new_conf->name, yy_conf->name);
1852 <      if (yy_aconf->passwd != NULL)
1853 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1854 <
1855 <      new_aconf->flags = yy_aconf->flags;
1856 <      new_aconf->port  = yy_aconf->port;
1857 <
1858 <      DupString(new_aconf->user, yy_tmp->user);
1859 <      collapse(new_aconf->user);
1860 <
1861 <      DupString(new_aconf->host, yy_tmp->host);
1862 <      collapse(new_aconf->host);
1863 <
1864 <      conf_add_class_to_conf(new_conf, class_name);
1865 <      add_conf_by_address(CONF_CLIENT, new_aconf);
1866 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1867 <      free_collect_item(yy_tmp);
1868 <    }
1869 <
1870 <    MyFree(class_name);
1871 <    class_name = NULL;
1872 <    yy_conf = NULL;
1873 <    yy_aconf = NULL;
1874 <  }
1875 < };
1687 >  dlink_node *ptr = NULL;
1688  
1689 < auth_items:     auth_items auth_item | auth_item;
1690 < auth_item:      auth_user | auth_passwd | auth_class | auth_flags |
1879 <                auth_kline_exempt | auth_need_ident |
1880 <                auth_exceed_limit | auth_no_tilde | auth_gline_exempt |
1881 <                auth_spoof | auth_spoof_notice |
1882 <                auth_redir_serv | auth_redir_port | auth_can_flood |
1883 <                auth_need_password | auth_encrypted | error ';' ;
1689 >  if (conf_parser_ctx.pass != 2)
1690 >    break;
1691  
1692 < auth_user: USER '=' QSTRING ';'
1886 < {
1887 <  if (conf_parser_ctx.pass == 2)
1692 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1693    {
1694 <    struct CollectItem *yy_tmp = NULL;
1694 >    struct MaskItem *conf = NULL;
1695      struct split_nuh_item nuh;
1696  
1697 <    nuh.nuhmask  = yylval.string;
1697 >    nuh.nuhmask  = ptr->data;
1698      nuh.nickptr  = NULL;
1699 <    nuh.userptr  = userbuf;
1700 <    nuh.hostptr  = hostbuf;
1896 <
1699 >    nuh.userptr  = block_state.user.buf;
1700 >    nuh.hostptr  = block_state.host.buf;
1701      nuh.nicksize = 0;
1702 <    nuh.usersize = sizeof(userbuf);
1703 <    nuh.hostsize = sizeof(hostbuf);
1900 <
1702 >    nuh.usersize = sizeof(block_state.user.buf);
1703 >    nuh.hostsize = sizeof(block_state.host.buf);
1704      split_nuh(&nuh);
1705  
1706 <    if (yy_aconf->user == NULL)
1707 <    {
1708 <      DupString(yy_aconf->user, userbuf);
1709 <      DupString(yy_aconf->host, hostbuf);
1710 <    }
1711 <    else
1712 <    {
1713 <      yy_tmp = MyMalloc(sizeof(struct CollectItem));
1706 >    conf        = conf_make(CONF_CLIENT);
1707 >    conf->user  = xstrdup(block_state.user.buf);
1708 >    conf->host  = xstrdup(block_state.host.buf);
1709 >
1710 >    if (block_state.rpass.buf[0])
1711 >      conf->passwd = xstrdup(block_state.rpass.buf);
1712 >    if (block_state.name.buf[0])
1713 >      conf->name = xstrdup(block_state.name.buf);
1714  
1715 <      DupString(yy_tmp->user, userbuf);
1716 <      DupString(yy_tmp->host, hostbuf);
1715 >    conf->flags = block_state.flags.value;
1716 >    conf->port  = block_state.port.value;
1717  
1718 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1719 <    }
1718 >    conf_add_class_to_conf(conf, block_state.class.buf);
1719 >    add_conf_by_address(CONF_CLIENT, conf);
1720    }
1721   };
1722  
1723 < /* XXX - IP/IPV6 tags don't exist anymore - put IP/IPV6 into user. */
1723 > auth_items:     auth_items auth_item | auth_item;
1724 > auth_item:      auth_user |
1725 >                auth_passwd |
1726 >                auth_class |
1727 >                auth_flags |
1728 >                auth_spoof |
1729 >                auth_redir_serv |
1730 >                auth_redir_port |
1731 >                auth_encrypted |
1732 >                error ';' ;
1733  
1734 < auth_passwd: PASSWORD '=' QSTRING ';'
1734 > auth_user: USER '=' QSTRING ';'
1735   {
1736    if (conf_parser_ctx.pass == 2)
1737 <  {
1926 <    /* be paranoid */
1927 <    if (yy_aconf->passwd != NULL)
1928 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1929 <
1930 <    MyFree(yy_aconf->passwd);
1931 <    DupString(yy_aconf->passwd, yylval.string);
1932 <  }
1737 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1738   };
1739  
1740 < auth_spoof_notice: SPOOF_NOTICE '=' TBOOL ';'
1740 > auth_passwd: PASSWORD '=' QSTRING ';'
1741   {
1742    if (conf_parser_ctx.pass == 2)
1743 <  {
1939 <    if (yylval.number)
1940 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1941 <    else
1942 <      yy_aconf->flags &= ~CONF_FLAGS_SPOOF_NOTICE;
1943 <  }
1743 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1744   };
1745  
1746   auth_class: CLASS '=' QSTRING ';'
1747   {
1748    if (conf_parser_ctx.pass == 2)
1749 <  {
1950 <    MyFree(class_name);
1951 <    DupString(class_name, yylval.string);
1952 <  }
1749 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1750   };
1751  
1752   auth_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 1957 | Line 1754 | auth_encrypted: ENCRYPTED '=' TBOOL ';'
1754    if (conf_parser_ctx.pass == 2)
1755    {
1756      if (yylval.number)
1757 <      SetConfEncrypted(yy_aconf);
1757 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1758      else
1759 <      ClearConfEncrypted(yy_aconf);
1759 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1760    }
1761   };
1762  
1763   auth_flags: IRCD_FLAGS
1764   {
1765 +  if (conf_parser_ctx.pass == 2)
1766 +    block_state.flags.value &= (CONF_FLAGS_ENCRYPTED | CONF_FLAGS_SPOOF_IP);
1767   } '='  auth_flags_items ';';
1768  
1769   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
1770 < auth_flags_item: NOT { not_atom = 1; } auth_flags_item_atom
1972 <                | { not_atom = 0; } auth_flags_item_atom;
1973 <
1974 < auth_flags_item_atom: SPOOF_NOTICE
1770 > auth_flags_item: SPOOF_NOTICE
1771   {
1772    if (conf_parser_ctx.pass == 2)
1773 <  {
1978 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_SPOOF_NOTICE;
1979 <    else yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1980 <  }
1981 <
1773 >    block_state.flags.value |= CONF_FLAGS_SPOOF_NOTICE;
1774   } | EXCEED_LIMIT
1775   {
1776    if (conf_parser_ctx.pass == 2)
1777 <  {
1986 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NOLIMIT;
1987 <    else yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
1988 <  }
1777 >    block_state.flags.value |= CONF_FLAGS_NOLIMIT;
1778   } | KLINE_EXEMPT
1779   {
1780    if (conf_parser_ctx.pass == 2)
1781 <  {
1993 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTKLINE;
1994 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
1995 <  }
1781 >    block_state.flags.value |= CONF_FLAGS_EXEMPTKLINE;
1782   } | NEED_IDENT
1783   {
1784    if (conf_parser_ctx.pass == 2)
1785 <  {
2000 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_IDENTD;
2001 <    else yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
2002 <  }
1785 >    block_state.flags.value |= CONF_FLAGS_NEED_IDENTD;
1786   } | CAN_FLOOD
1787   {
1788    if (conf_parser_ctx.pass == 2)
1789 <  {
2007 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_CAN_FLOOD;
2008 <    else yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
2009 <  }
2010 < } | CAN_IDLE
2011 < {
2012 <  if (conf_parser_ctx.pass == 2)
2013 <  {
2014 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_IDLE_LINED;
2015 <    else yy_aconf->flags |= CONF_FLAGS_IDLE_LINED;
2016 <  }
1789 >    block_state.flags.value |= CONF_FLAGS_CAN_FLOOD;
1790   } | NO_TILDE
1791   {
1792    if (conf_parser_ctx.pass == 2)
1793 <  {
2021 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NO_TILDE;
2022 <    else yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
2023 <  }
1793 >    block_state.flags.value |= CONF_FLAGS_NO_TILDE;
1794   } | GLINE_EXEMPT
1795   {
1796    if (conf_parser_ctx.pass == 2)
1797 <  {
2028 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTGLINE;
2029 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
2030 <  }
1797 >    block_state.flags.value |= CONF_FLAGS_EXEMPTGLINE;
1798   } | RESV_EXEMPT
1799   {
1800    if (conf_parser_ctx.pass == 2)
1801 <  {
1802 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTRESV;
2036 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTRESV;
2037 <  }
2038 < } | NEED_PASSWORD
1801 >    block_state.flags.value |= CONF_FLAGS_EXEMPTRESV;
1802 > } | T_WEBIRC
1803   {
1804    if (conf_parser_ctx.pass == 2)
1805 <  {
1806 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_PASSWORD;
2043 <    else yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
2044 <  }
2045 < };
2046 <
2047 < auth_kline_exempt: KLINE_EXEMPT '=' TBOOL ';'
1805 >    block_state.flags.value |= CONF_FLAGS_WEBIRC;
1806 > } | NEED_PASSWORD
1807   {
1808    if (conf_parser_ctx.pass == 2)
1809 <  {
2051 <    if (yylval.number)
2052 <      yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
2053 <    else
2054 <      yy_aconf->flags &= ~CONF_FLAGS_EXEMPTKLINE;
2055 <  }
1809 >    block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1810   };
1811  
1812 < auth_need_ident: NEED_IDENT '=' TBOOL ';'
1812 > auth_spoof: SPOOF '=' QSTRING ';'
1813   {
1814 <  if (conf_parser_ctx.pass == 2)
1815 <  {
2062 <    if (yylval.number)
2063 <      yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
2064 <    else
2065 <      yy_aconf->flags &= ~CONF_FLAGS_NEED_IDENTD;
2066 <  }
2067 < };
1814 >  if (conf_parser_ctx.pass != 2)
1815 >    break;
1816  
1817 < auth_exceed_limit: EXCEED_LIMIT '=' TBOOL ';'
2070 < {
2071 <  if (conf_parser_ctx.pass == 2)
1817 >  if (valid_hostname(yylval.string))
1818    {
1819 <    if (yylval.number)
1820 <      yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
2075 <    else
2076 <      yy_aconf->flags &= ~CONF_FLAGS_NOLIMIT;
1819 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1820 >    block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
1821    }
1822 +  else
1823 +    ilog(LOG_TYPE_IRCD, "Spoof either is too long or contains invalid characters. Ignoring it.");
1824   };
1825  
1826 < auth_can_flood: CAN_FLOOD '=' TBOOL ';'
1826 > auth_redir_serv: REDIRSERV '=' QSTRING ';'
1827   {
1828 <  if (conf_parser_ctx.pass == 2)
1829 <  {
1830 <    if (yylval.number)
1831 <      yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
1832 <    else
2087 <      yy_aconf->flags &= ~CONF_FLAGS_CAN_FLOOD;
2088 <  }
1828 >  if (conf_parser_ctx.pass != 2)
1829 >    break;
1830 >
1831 >  strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1832 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1833   };
1834  
1835 < auth_no_tilde: NO_TILDE '=' TBOOL ';'
1835 > auth_redir_port: REDIRPORT '=' NUMBER ';'
1836   {
1837 <  if (conf_parser_ctx.pass == 2)
1838 <  {
1839 <    if (yylval.number)
1840 <      yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
1841 <    else
2098 <      yy_aconf->flags &= ~CONF_FLAGS_NO_TILDE;
2099 <  }
1837 >  if (conf_parser_ctx.pass != 2)
1838 >    break;
1839 >
1840 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1841 >  block_state.port.value = $3;
1842   };
1843  
1844 < auth_gline_exempt: GLINE_EXEMPT '=' TBOOL ';'
1844 >
1845 > /***************************************************************************
1846 > *  section resv
1847 > ***************************************************************************/
1848 > resv_entry: RESV
1849   {
1850 <  if (conf_parser_ctx.pass == 2)
1851 <  {
2106 <    if (yylval.number)
2107 <      yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
2108 <    else
2109 <      yy_aconf->flags &= ~CONF_FLAGS_EXEMPTGLINE;
2110 <  }
2111 < };
1850 >  if (conf_parser_ctx.pass != 2)
1851 >    break;
1852  
1853 < /* XXX - need check for illegal hostnames here */
1854 < auth_spoof: SPOOF '=' QSTRING ';'
1853 >  reset_block_state();
1854 >  strlcpy(block_state.rpass.buf, CONF_NOREASON, sizeof(block_state.rpass.buf));
1855 > } '{' resv_items '}' ';'
1856   {
1857 <  if (conf_parser_ctx.pass == 2)
1858 <  {
2118 <    MyFree(yy_conf->name);
1857 >  if (conf_parser_ctx.pass != 2)
1858 >    break;
1859  
1860 <    if (strlen(yylval.string) < HOSTLEN)
2121 <    {    
2122 <      DupString(yy_conf->name, yylval.string);
2123 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_IP;
2124 <    }
2125 <    else
2126 <    {
2127 <      ilog(L_ERROR, "Spoofs must be less than %d..ignoring it", HOSTLEN);
2128 <      yy_conf->name = NULL;
2129 <    }
2130 <  }
1860 >  create_resv(block_state.name.buf, block_state.rpass.buf, &block_state.mask.list);
1861   };
1862  
1863 < auth_redir_serv: REDIRSERV '=' QSTRING ';'
1863 > resv_items:     resv_items resv_item | resv_item;
1864 > resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1865 >
1866 > resv_mask: MASK '=' QSTRING ';'
1867   {
1868    if (conf_parser_ctx.pass == 2)
1869 <  {
2137 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
2138 <    MyFree(yy_conf->name);
2139 <    DupString(yy_conf->name, yylval.string);
2140 <  }
1869 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1870   };
1871  
1872 < auth_redir_port: REDIRPORT '=' NUMBER ';'
1872 > resv_reason: REASON '=' QSTRING ';'
1873   {
1874    if (conf_parser_ctx.pass == 2)
1875 <  {
2147 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
2148 <    yy_aconf->port = $3;
2149 <  }
1875 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1876   };
1877  
1878 < auth_need_password: NEED_PASSWORD '=' TBOOL ';'
1878 > resv_exempt: EXEMPT '=' QSTRING ';'
1879   {
1880    if (conf_parser_ctx.pass == 2)
1881 <  {
2156 <    if (yylval.number)
2157 <      yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
2158 <    else
2159 <      yy_aconf->flags &= ~CONF_FLAGS_NEED_PASSWORD;
2160 <  }
1881 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1882   };
1883  
1884  
1885   /***************************************************************************
1886 < *  section resv
1886 > *  section service
1887   ***************************************************************************/
1888 < resv_entry: RESV
2168 < {
2169 <  if (conf_parser_ctx.pass == 2)
2170 <  {
2171 <    MyFree(resv_reason);
2172 <    resv_reason = NULL;
2173 <  }
2174 < } '{' resv_items '}' ';'
2175 < {
2176 <  if (conf_parser_ctx.pass == 2)
2177 <  {
2178 <    MyFree(resv_reason);
2179 <    resv_reason = NULL;
2180 <  }
2181 < };
1888 > service_entry: T_SERVICE '{' service_items '}' ';';
1889  
1890 < resv_items:     resv_items resv_item | resv_item;
1891 < resv_item:      resv_creason | resv_channel | resv_nick | error ';' ;
1890 > service_items:     service_items service_item | service_item;
1891 > service_item:      service_name | error;
1892  
1893 < resv_creason: REASON '=' QSTRING ';'
1893 > service_name: NAME '=' QSTRING ';'
1894   {
1895 <  if (conf_parser_ctx.pass == 2)
1896 <  {
2190 <    MyFree(resv_reason);
2191 <    DupString(resv_reason, yylval.string);
2192 <  }
2193 < };
1895 >  if (conf_parser_ctx.pass != 2)
1896 >    break;
1897  
1898 < resv_channel: CHANNEL '=' QSTRING ';'
2196 < {
2197 <  if (conf_parser_ctx.pass == 2)
2198 <  {
2199 <    if (IsChanPrefix(*yylval.string))
2200 <    {
2201 <      char def_reason[] = "No reason";
2202 <
2203 <      create_channel_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
2204 <    }
2205 <  }
2206 <  /* ignore it for now.. but we really should make a warning if
2207 <   * its an erroneous name --fl_ */
2208 < };
2209 <
2210 < resv_nick: NICK '=' QSTRING ';'
2211 < {
2212 <  if (conf_parser_ctx.pass == 2)
1898 >  if (valid_servname(yylval.string))
1899    {
1900 <    char def_reason[] = "No reason";
1901 <
2216 <    create_nick_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1900 >    struct MaskItem *conf = conf_make(CONF_SERVICE);
1901 >    conf->name = xstrdup(yylval.string);
1902    }
1903   };
1904  
# Line 2222 | Line 1907 | resv_nick: NICK '=' QSTRING ';'
1907   ***************************************************************************/
1908   shared_entry: T_SHARED
1909   {
1910 <  if (conf_parser_ctx.pass == 2)
1911 <  {
1912 <    yy_conf = make_conf_item(ULINE_TYPE);
1913 <    yy_match_item = map_to_conf(yy_conf);
1914 <    yy_match_item->action = SHARED_ALL;
1915 <  }
1910 >  if (conf_parser_ctx.pass != 2)
1911 >    break;
1912 >
1913 >  reset_block_state();
1914 >
1915 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1916 >  strlcpy(block_state.user.buf, "*", sizeof(block_state.user.buf));
1917 >  strlcpy(block_state.host.buf, "*", sizeof(block_state.host.buf));
1918 >  block_state.flags.value = SHARED_ALL;
1919   } '{' shared_items '}' ';'
1920   {
1921 <  if (conf_parser_ctx.pass == 2)
1922 <  {
1923 <    yy_conf = NULL;
1924 <  }
1921 >  struct MaskItem *conf = NULL;
1922 >
1923 >  if (conf_parser_ctx.pass != 2)
1924 >    break;
1925 >
1926 >  conf = conf_make(CONF_ULINE);
1927 >  conf->flags = block_state.flags.value;
1928 >  conf->name = xstrdup(block_state.name.buf);
1929 >  conf->user = xstrdup(block_state.user.buf);
1930 >  conf->host = xstrdup(block_state.host.buf);
1931   };
1932  
1933   shared_items: shared_items shared_item | shared_item;
# Line 2242 | Line 1936 | shared_item:  shared_name | shared_user
1936   shared_name: NAME '=' QSTRING ';'
1937   {
1938    if (conf_parser_ctx.pass == 2)
1939 <  {
2246 <    MyFree(yy_conf->name);
2247 <    DupString(yy_conf->name, yylval.string);
2248 <  }
1939 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1940   };
1941  
1942   shared_user: USER '=' QSTRING ';'
# Line 2256 | Line 1947 | shared_user: USER '=' QSTRING ';'
1947  
1948      nuh.nuhmask  = yylval.string;
1949      nuh.nickptr  = NULL;
1950 <    nuh.userptr  = userbuf;
1951 <    nuh.hostptr  = hostbuf;
1950 >    nuh.userptr  = block_state.user.buf;
1951 >    nuh.hostptr  = block_state.host.buf;
1952  
1953      nuh.nicksize = 0;
1954 <    nuh.usersize = sizeof(userbuf);
1955 <    nuh.hostsize = sizeof(hostbuf);
1954 >    nuh.usersize = sizeof(block_state.user.buf);
1955 >    nuh.hostsize = sizeof(block_state.host.buf);
1956  
1957      split_nuh(&nuh);
2267
2268    DupString(yy_match_item->user, userbuf);
2269    DupString(yy_match_item->host, hostbuf);
1958    }
1959   };
1960  
1961   shared_type: TYPE
1962   {
1963    if (conf_parser_ctx.pass == 2)
1964 <    yy_match_item->action = 0;
1964 >    block_state.flags.value = 0;
1965   } '=' shared_types ';' ;
1966  
1967   shared_types: shared_types ',' shared_type_item | shared_type_item;
1968   shared_type_item: KLINE
1969   {
1970    if (conf_parser_ctx.pass == 2)
1971 <    yy_match_item->action |= SHARED_KLINE;
1972 < } | TKLINE
1971 >    block_state.flags.value |= SHARED_KLINE;
1972 > } | UNKLINE
1973   {
1974    if (conf_parser_ctx.pass == 2)
1975 <    yy_match_item->action |= SHARED_TKLINE;
1976 < } | UNKLINE
1975 >    block_state.flags.value |= SHARED_UNKLINE;
1976 > } | T_DLINE
1977   {
1978    if (conf_parser_ctx.pass == 2)
1979 <    yy_match_item->action |= SHARED_UNKLINE;
1980 < } | XLINE
1979 >    block_state.flags.value |= SHARED_DLINE;
1980 > } | T_UNDLINE
1981   {
1982    if (conf_parser_ctx.pass == 2)
1983 <    yy_match_item->action |= SHARED_XLINE;
1984 < } | TXLINE
1983 >    block_state.flags.value |= SHARED_UNDLINE;
1984 > } | XLINE
1985   {
1986    if (conf_parser_ctx.pass == 2)
1987 <    yy_match_item->action |= SHARED_TXLINE;
1987 >    block_state.flags.value |= SHARED_XLINE;
1988   } | T_UNXLINE
1989   {
1990    if (conf_parser_ctx.pass == 2)
1991 <    yy_match_item->action |= SHARED_UNXLINE;
1991 >    block_state.flags.value |= SHARED_UNXLINE;
1992   } | RESV
1993   {
1994    if (conf_parser_ctx.pass == 2)
1995 <    yy_match_item->action |= SHARED_RESV;
2308 < } | TRESV
2309 < {
2310 <  if (conf_parser_ctx.pass == 2)
2311 <    yy_match_item->action |= SHARED_TRESV;
1995 >    block_state.flags.value |= SHARED_RESV;
1996   } | T_UNRESV
1997   {
1998    if (conf_parser_ctx.pass == 2)
1999 <    yy_match_item->action |= SHARED_UNRESV;
1999 >    block_state.flags.value |= SHARED_UNRESV;
2000   } | T_LOCOPS
2001   {
2002    if (conf_parser_ctx.pass == 2)
2003 <    yy_match_item->action |= SHARED_LOCOPS;
2003 >    block_state.flags.value |= SHARED_LOCOPS;
2004   } | T_ALL
2005   {
2006    if (conf_parser_ctx.pass == 2)
2007 <    yy_match_item->action = SHARED_ALL;
2007 >    block_state.flags.value = SHARED_ALL;
2008   };
2009  
2010   /***************************************************************************
# Line 2328 | Line 2012 | shared_type_item: KLINE
2012   ***************************************************************************/
2013   cluster_entry: T_CLUSTER
2014   {
2015 <  if (conf_parser_ctx.pass == 2)
2016 <  {
2017 <    yy_conf = make_conf_item(CLUSTER_TYPE);
2018 <    yy_conf->flags = SHARED_ALL;
2019 <  }
2015 >  if (conf_parser_ctx.pass != 2)
2016 >    break;
2017 >
2018 >  reset_block_state();
2019 >
2020 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
2021 >  block_state.flags.value = SHARED_ALL;
2022   } '{' cluster_items '}' ';'
2023   {
2024 <  if (conf_parser_ctx.pass == 2)
2025 <  {
2026 <    if (yy_conf->name == NULL)
2027 <      DupString(yy_conf->name, "*");
2028 <    yy_conf = NULL;
2029 <  }
2024 >  struct MaskItem *conf = NULL;
2025 >
2026 >  if (conf_parser_ctx.pass != 2)
2027 >    break;
2028 >
2029 >  conf = conf_make(CONF_CLUSTER);
2030 >  conf->flags = block_state.flags.value;
2031 >  conf->name = xstrdup(block_state.name.buf);
2032   };
2033  
2034 < cluster_items:  cluster_items cluster_item | cluster_item;
2035 < cluster_item:   cluster_name | cluster_type | error ';' ;
2034 > cluster_items:  cluster_items cluster_item | cluster_item;
2035 > cluster_item:   cluster_name | cluster_type | error ';' ;
2036  
2037   cluster_name: NAME '=' QSTRING ';'
2038   {
2039    if (conf_parser_ctx.pass == 2)
2040 <    DupString(yy_conf->name, yylval.string);
2040 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2041   };
2042  
2043   cluster_type: TYPE
2044   {
2045    if (conf_parser_ctx.pass == 2)
2046 <    yy_conf->flags = 0;
2046 >    block_state.flags.value = 0;
2047   } '=' cluster_types ';' ;
2048  
2049 < cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2049 > cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2050   cluster_type_item: KLINE
2051   {
2052    if (conf_parser_ctx.pass == 2)
2053 <    yy_conf->flags |= SHARED_KLINE;
2054 < } | TKLINE
2053 >    block_state.flags.value |= SHARED_KLINE;
2054 > } | UNKLINE
2055   {
2056    if (conf_parser_ctx.pass == 2)
2057 <    yy_conf->flags |= SHARED_TKLINE;
2058 < } | UNKLINE
2057 >    block_state.flags.value |= SHARED_UNKLINE;
2058 > } | T_DLINE
2059   {
2060    if (conf_parser_ctx.pass == 2)
2061 <    yy_conf->flags |= SHARED_UNKLINE;
2062 < } | XLINE
2061 >    block_state.flags.value |= SHARED_DLINE;
2062 > } | T_UNDLINE
2063   {
2064    if (conf_parser_ctx.pass == 2)
2065 <    yy_conf->flags |= SHARED_XLINE;
2066 < } | TXLINE
2065 >    block_state.flags.value |= SHARED_UNDLINE;
2066 > } | XLINE
2067   {
2068    if (conf_parser_ctx.pass == 2)
2069 <    yy_conf->flags |= SHARED_TXLINE;
2069 >    block_state.flags.value |= SHARED_XLINE;
2070   } | T_UNXLINE
2071   {
2072    if (conf_parser_ctx.pass == 2)
2073 <    yy_conf->flags |= SHARED_UNXLINE;
2073 >    block_state.flags.value |= SHARED_UNXLINE;
2074   } | RESV
2075   {
2076    if (conf_parser_ctx.pass == 2)
2077 <    yy_conf->flags |= SHARED_RESV;
2390 < } | TRESV
2391 < {
2392 <  if (conf_parser_ctx.pass == 2)
2393 <    yy_conf->flags |= SHARED_TRESV;
2077 >    block_state.flags.value |= SHARED_RESV;
2078   } | T_UNRESV
2079   {
2080    if (conf_parser_ctx.pass == 2)
2081 <    yy_conf->flags |= SHARED_UNRESV;
2081 >    block_state.flags.value |= SHARED_UNRESV;
2082   } | T_LOCOPS
2083   {
2084    if (conf_parser_ctx.pass == 2)
2085 <    yy_conf->flags |= SHARED_LOCOPS;
2085 >    block_state.flags.value |= SHARED_LOCOPS;
2086   } | T_ALL
2087   {
2088    if (conf_parser_ctx.pass == 2)
2089 <    yy_conf->flags = SHARED_ALL;
2089 >    block_state.flags.value = SHARED_ALL;
2090   };
2091  
2092   /***************************************************************************
2093   *  section connect
2094   ***************************************************************************/
2095 < connect_entry: CONNECT  
2095 > connect_entry: CONNECT
2096   {
2413  if (conf_parser_ctx.pass == 2)
2414  {
2415    yy_conf = make_conf_item(SERVER_TYPE);
2416    yy_aconf = (struct AccessItem *)map_to_conf(yy_conf);
2417    yy_aconf->passwd = NULL;
2418    /* defaults */
2419    yy_aconf->port = PORTNUM;
2097  
2098 <    if (ConfigFileEntry.burst_away)
2099 <      yy_aconf->flags = CONF_FLAGS_BURST_AWAY;
2100 <  }
2101 <  else
2102 <  {
2103 <    MyFree(class_name);
2104 <    class_name = NULL;
2428 <  }
2429 < } connect_name_b '{' connect_items '}' ';'
2098 >  if (conf_parser_ctx.pass != 2)
2099 >    break;
2100 >
2101 >  reset_block_state();
2102 >  block_state.aftype.value = AF_INET;
2103 >  block_state.port.value = PORTNUM;
2104 > } '{' connect_items '}' ';'
2105   {
2106 <  if (conf_parser_ctx.pass == 2)
2107 <  {
2433 <    struct CollectItem *yy_hconf=NULL;
2434 <    struct CollectItem *yy_lconf=NULL;
2435 <    dlink_node *ptr;
2436 <    dlink_node *next_ptr;
2437 < #ifdef HAVE_LIBCRYPTO
2438 <    if (yy_aconf->host &&
2439 <        ((yy_aconf->passwd && yy_aconf->spasswd) ||
2440 <         (yy_aconf->rsa_public_key && IsConfCryptLink(yy_aconf))))
2441 < #else /* !HAVE_LIBCRYPTO */
2442 <      if (yy_aconf->host && !IsConfCryptLink(yy_aconf) &&
2443 <          yy_aconf->passwd && yy_aconf->spasswd)
2444 < #endif /* !HAVE_LIBCRYPTO */
2445 <        {
2446 <          if (conf_add_server(yy_conf, class_name) == -1)
2447 <          {
2448 <            delete_conf_item(yy_conf);
2449 <            yy_conf = NULL;
2450 <            yy_aconf = NULL;
2451 <          }
2452 <        }
2453 <        else
2454 <        {
2455 <          /* Even if yy_conf ->name is NULL
2456 <           * should still unhook any hub/leaf confs still pending
2457 <           */
2458 <          unhook_hub_leaf_confs();
2459 <
2460 <          if (yy_conf->name != NULL)
2461 <          {
2462 < #ifndef HAVE_LIBCRYPTO
2463 <            if (IsConfCryptLink(yy_aconf))
2464 <              yyerror("Ignoring connect block -- no OpenSSL support");
2465 < #else
2466 <            if (IsConfCryptLink(yy_aconf) && !yy_aconf->rsa_public_key)
2467 <              yyerror("Ignoring connect block -- missing key");
2468 < #endif
2469 <            if (yy_aconf->host == NULL)
2470 <              yyerror("Ignoring connect block -- missing host");
2471 <            else if (!IsConfCryptLink(yy_aconf) &&
2472 <                    (!yy_aconf->passwd || !yy_aconf->spasswd))
2473 <              yyerror("Ignoring connect block -- missing password");
2474 <          }
2475 <
2476 <
2477 <          /* XXX
2478 <           * This fixes a try_connections() core (caused by invalid class_ptr
2479 <           * pointers) reported by metalrock. That's an ugly fix, but there
2480 <           * is currently no better way. The entire config subsystem needs an
2481 <           * rewrite ASAP. make_conf_item() shouldn't really add things onto
2482 <           * a doubly linked list immediately without any sanity checks!  -Michael
2483 <           */
2484 <          delete_conf_item(yy_conf);
2485 <
2486 <          yy_aconf = NULL;
2487 <          yy_conf = NULL;
2488 <        }
2489 <
2490 <      /*
2491 <       * yy_conf is still pointing at the server that is having
2492 <       * a connect block built for it. This means, y_aconf->name
2493 <       * points to the actual irc name this server will be known as.
2494 <       * Now this new server has a set or even just one hub_mask (or leaf_mask)
2495 <       * given in the link list at yy_hconf. Fill in the HUB confs
2496 <       * from this link list now.
2497 <       */        
2498 <      DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
2499 <      {
2500 <        struct ConfItem *new_hub_conf;
2501 <        struct MatchItem *match_item;
2106 >  struct MaskItem *conf = NULL;
2107 >  struct addrinfo hints, *res;
2108  
2109 <        yy_hconf = ptr->data;
2109 >  if (conf_parser_ctx.pass != 2)
2110 >    break;
2111  
2112 <        /* yy_conf == NULL is a fatal error for this connect block! */
2113 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2114 <        {
2508 <          new_hub_conf = make_conf_item(HUB_TYPE);
2509 <          match_item = (struct MatchItem *)map_to_conf(new_hub_conf);
2510 <          DupString(new_hub_conf->name, yy_conf->name);
2511 <          if (yy_hconf->user != NULL)
2512 <            DupString(match_item->user, yy_hconf->user);
2513 <          else
2514 <            DupString(match_item->user, "*");
2515 <          if (yy_hconf->host != NULL)
2516 <            DupString(match_item->host, yy_hconf->host);
2517 <          else
2518 <            DupString(match_item->host, "*");
2519 <        }
2520 <        dlinkDelete(&yy_hconf->node, &hub_conf_list);
2521 <        free_collect_item(yy_hconf);
2522 <      }
2112 >  if (!block_state.name.buf[0] ||
2113 >      !block_state.host.buf[0])
2114 >    break;
2115  
2116 <      /* Ditto for the LEAF confs */
2116 >  if (!block_state.rpass.buf[0] ||
2117 >      !block_state.spass.buf[0])
2118 >    break;
2119  
2120 <      DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
2121 <      {
2122 <        struct ConfItem *new_leaf_conf;
2529 <        struct MatchItem *match_item;
2120 >  if (has_wildcards(block_state.name.buf) ||
2121 >      has_wildcards(block_state.host.buf))
2122 >    break;
2123  
2124 <        yy_lconf = ptr->data;
2124 >  conf = conf_make(CONF_SERVER);
2125 >  conf->port = block_state.port.value;
2126 >  conf->flags = block_state.flags.value;
2127 >  conf->aftype = block_state.aftype.value;
2128 >  conf->host = xstrdup(block_state.host.buf);
2129 >  conf->name = xstrdup(block_state.name.buf);
2130 >  conf->passwd = xstrdup(block_state.rpass.buf);
2131 >  conf->spasswd = xstrdup(block_state.spass.buf);
2132  
2133 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2134 <        {
2135 <          new_leaf_conf = make_conf_item(LEAF_TYPE);
2136 <          match_item = (struct MatchItem *)map_to_conf(new_leaf_conf);
2137 <          DupString(new_leaf_conf->name, yy_conf->name);
2138 <          if (yy_lconf->user != NULL)
2139 <            DupString(match_item->user, yy_lconf->user);
2140 <          else
2141 <            DupString(match_item->user, "*");
2142 <          if (yy_lconf->host != NULL)
2143 <            DupString(match_item->host, yy_lconf->host);
2144 <          else
2145 <            DupString(match_item->host, "*");
2146 <        }
2147 <        dlinkDelete(&yy_lconf->node, &leaf_conf_list);
2148 <        free_collect_item(yy_lconf);
2149 <      }
2150 <      MyFree(class_name);
2151 <      class_name = NULL;
2152 <      yy_conf = NULL;
2153 <      yy_aconf = NULL;
2133 >  if (block_state.cert.buf[0])
2134 >    conf->certfp = xstrdup(block_state.cert.buf);
2135 >
2136 >  if (block_state.ciph.buf[0])
2137 >    conf->cipher_list = xstrdup(block_state.ciph.buf);
2138 >
2139 >  dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
2140 >  dlinkMoveList(&block_state.hub.list, &conf->hub_list);
2141 >
2142 >  if (block_state.bind.buf[0])
2143 >  {
2144 >    memset(&hints, 0, sizeof(hints));
2145 >
2146 >    hints.ai_family   = AF_UNSPEC;
2147 >    hints.ai_socktype = SOCK_STREAM;
2148 >    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2149 >
2150 >    if (getaddrinfo(block_state.bind.buf, NULL, &hints, &res))
2151 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
2152 >    else
2153 >    {
2154 >      assert(res);
2155 >
2156 >      memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
2157 >      conf->bind.ss.ss_family = res->ai_family;
2158 >      conf->bind.ss_len = res->ai_addrlen;
2159 >      freeaddrinfo(res);
2160 >    }
2161    }
2162 +
2163 +  conf_add_class_to_conf(conf, block_state.class.buf);
2164 +  lookup_confhost(conf);
2165   };
2166  
2557 connect_name_b: | connect_name_t;
2167   connect_items:  connect_items connect_item | connect_item;
2168 < connect_item:   connect_name | connect_host | connect_vhost |
2169 <                connect_send_password | connect_accept_password |
2170 <                connect_aftype | connect_port |
2171 <                connect_fakename | connect_flags | connect_hub_mask |
2172 <                connect_leaf_mask | connect_class | connect_auto |
2173 <                connect_encrypted | connect_compressed | connect_cryptlink |
2174 <                connect_rsa_public_key_file | connect_cipher_preference |
2175 <                connect_topicburst | error ';' ;
2168 > connect_item:   connect_name |
2169 >                connect_host |
2170 >                connect_vhost |
2171 >                connect_send_password |
2172 >                connect_accept_password |
2173 >                connect_ssl_certificate_fingerprint |
2174 >                connect_aftype |
2175 >                connect_port |
2176 >                connect_ssl_cipher_list |
2177 >                connect_flags |
2178 >                connect_hub_mask |
2179 >                connect_leaf_mask |
2180 >                connect_class |
2181 >                connect_encrypted |
2182 >                error ';' ;
2183  
2184   connect_name: NAME '=' QSTRING ';'
2185   {
2186    if (conf_parser_ctx.pass == 2)
2187 <  {
2572 <    if (yy_conf->name != NULL)
2573 <      yyerror("Multiple connect name entry");
2574 <
2575 <    MyFree(yy_conf->name);
2576 <    DupString(yy_conf->name, yylval.string);
2577 <  }
2187 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2188   };
2189  
2190 < connect_name_t: QSTRING
2190 > connect_host: HOST '=' QSTRING ';'
2191   {
2192    if (conf_parser_ctx.pass == 2)
2193 <  {
2584 <    if (yy_conf->name != NULL)
2585 <      yyerror("Multiple connect name entry");
2586 <
2587 <    MyFree(yy_conf->name);
2588 <    DupString(yy_conf->name, yylval.string);
2589 <  }
2193 >    strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
2194   };
2195  
2196 < connect_host: HOST '=' QSTRING ';'
2196 > connect_vhost: VHOST '=' QSTRING ';'
2197   {
2198    if (conf_parser_ctx.pass == 2)
2199 <  {
2596 <    MyFree(yy_aconf->host);
2597 <    DupString(yy_aconf->host, yylval.string);
2598 <  }
2199 >    strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
2200   };
2201  
2202 < connect_vhost: VHOST '=' QSTRING ';'
2202 > connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2203   {
2204 <  if (conf_parser_ctx.pass == 2)
2205 <  {
2605 <    struct addrinfo hints, *res;
2606 <
2607 <    memset(&hints, 0, sizeof(hints));
2204 >  if (conf_parser_ctx.pass != 2)
2205 >    break;
2206  
2207 <    hints.ai_family   = AF_UNSPEC;
2208 <    hints.ai_socktype = SOCK_STREAM;
2209 <    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2210 <
2211 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
2212 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
2615 <    else
2616 <    {
2617 <      assert(res != NULL);
2618 <
2619 <      memcpy(&yy_aconf->my_ipnum, res->ai_addr, res->ai_addrlen);
2620 <      yy_aconf->my_ipnum.ss.ss_family = res->ai_family;
2621 <      yy_aconf->my_ipnum.ss_len = res->ai_addrlen;
2622 <      irc_freeaddrinfo(res);
2623 <    }
2624 <  }
2207 >  if ($3[0] == ':')
2208 >    conf_error_report("Server passwords cannot begin with a colon");
2209 >  else if (strchr($3, ' '))
2210 >    conf_error_report("Server passwords cannot contain spaces");
2211 >  else
2212 >    strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
2213   };
2214 <
2215 < connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2214 >
2215 > connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2216   {
2217 <  if (conf_parser_ctx.pass == 2)
2218 <  {
2631 <    if ($3[0] == ':')
2632 <      yyerror("Server passwords cannot begin with a colon");
2633 <    else if (strchr($3, ' ') != NULL)
2634 <      yyerror("Server passwords cannot contain spaces");
2635 <    else {
2636 <      if (yy_aconf->spasswd != NULL)
2637 <        memset(yy_aconf->spasswd, 0, strlen(yy_aconf->spasswd));
2217 >  if (conf_parser_ctx.pass != 2)
2218 >    break;
2219  
2220 <      MyFree(yy_aconf->spasswd);
2221 <      DupString(yy_aconf->spasswd, yylval.string);
2222 <    }
2223 <  }
2220 >  if ($3[0] == ':')
2221 >    conf_error_report("Server passwords cannot begin with a colon");
2222 >  else if (strchr($3, ' '))
2223 >    conf_error_report("Server passwords cannot contain spaces");
2224 >  else
2225 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2226   };
2227  
2228 < connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2228 > connect_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
2229   {
2230    if (conf_parser_ctx.pass == 2)
2231 <  {
2649 <    if ($3[0] == ':')
2650 <      yyerror("Server passwords cannot begin with a colon");
2651 <    else if (strchr($3, ' ') != NULL)
2652 <      yyerror("Server passwords cannot contain spaces");
2653 <    else {
2654 <      if (yy_aconf->passwd != NULL)
2655 <        memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
2656 <
2657 <      MyFree(yy_aconf->passwd);
2658 <      DupString(yy_aconf->passwd, yylval.string);
2659 <    }
2660 <  }
2231 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
2232   };
2233  
2234   connect_port: PORT '=' NUMBER ';'
2235   {
2236    if (conf_parser_ctx.pass == 2)
2237 <    yy_aconf->port = $3;
2237 >    block_state.port.value = $3;
2238   };
2239  
2240   connect_aftype: AFTYPE '=' T_IPV4 ';'
2241   {
2242    if (conf_parser_ctx.pass == 2)
2243 <    yy_aconf->aftype = AF_INET;
2243 >    block_state.aftype.value = AF_INET;
2244   } | AFTYPE '=' T_IPV6 ';'
2245   {
2246   #ifdef IPV6
2247    if (conf_parser_ctx.pass == 2)
2248 <    yy_aconf->aftype = AF_INET6;
2248 >    block_state.aftype.value = AF_INET6;
2249   #endif
2250   };
2251  
2681 connect_fakename: FAKENAME '=' QSTRING ';'
2682 {
2683  if (conf_parser_ctx.pass == 2)
2684  {
2685    MyFree(yy_aconf->fakename);
2686    DupString(yy_aconf->fakename, yylval.string);
2687  }
2688 };
2689
2252   connect_flags: IRCD_FLAGS
2253   {
2254 +  block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
2255   } '='  connect_flags_items ';';
2256  
2257   connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
2258 < connect_flags_item: NOT  { not_atom = 1; } connect_flags_item_atom
2696 <                        |  { not_atom = 0; } connect_flags_item_atom;
2697 <
2698 < connect_flags_item_atom: COMPRESSED
2258 > connect_flags_item: AUTOCONN
2259   {
2260    if (conf_parser_ctx.pass == 2)
2261 < #ifndef HAVE_LIBZ
2262 <    yyerror("Ignoring flags = compressed; -- no zlib support");
2703 < #else
2704 < {
2705 <   if (not_atom)ClearConfCompressed(yy_aconf);
2706 <   else SetConfCompressed(yy_aconf);
2707 < }
2708 < #endif
2709 < } | CRYPTLINK
2261 >    block_state.flags.value |= CONF_FLAGS_ALLOW_AUTO_CONN;
2262 > } | T_SSL
2263   {
2264    if (conf_parser_ctx.pass == 2)
2265 <  {
2713 <    if (not_atom)ClearConfCryptLink(yy_aconf);
2714 <    else SetConfCryptLink(yy_aconf);
2715 <  }
2716 < } | AUTOCONN
2717 < {
2718 <  if (conf_parser_ctx.pass == 2)
2719 <  {
2720 <    if (not_atom)ClearConfAllowAutoConn(yy_aconf);
2721 <    else SetConfAllowAutoConn(yy_aconf);
2722 <  }
2723 < } | BURST_AWAY
2724 < {
2725 <  if (conf_parser_ctx.pass == 2)
2726 <  {
2727 <    if (not_atom)ClearConfAwayBurst(yy_aconf);
2728 <    else SetConfAwayBurst(yy_aconf);
2729 <  }
2730 < } | TOPICBURST
2731 < {
2732 <  if (conf_parser_ctx.pass == 2)
2733 <  {
2734 <    if (not_atom)ClearConfTopicBurst(yy_aconf);
2735 <    else SetConfTopicBurst(yy_aconf);
2736 <  }
2737 < }
2738 < ;
2739 <
2740 < connect_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
2741 < {
2742 < #ifdef HAVE_LIBCRYPTO
2743 <  if (conf_parser_ctx.pass == 2)
2744 <  {
2745 <    BIO *file;
2746 <
2747 <    if (yy_aconf->rsa_public_key != NULL)
2748 <    {
2749 <      RSA_free(yy_aconf->rsa_public_key);
2750 <      yy_aconf->rsa_public_key = NULL;
2751 <    }
2752 <
2753 <    if (yy_aconf->rsa_public_key_file != NULL)
2754 <    {
2755 <      MyFree(yy_aconf->rsa_public_key_file);
2756 <      yy_aconf->rsa_public_key_file = NULL;
2757 <    }
2758 <
2759 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
2760 <
2761 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
2762 <    {
2763 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
2764 <      break;
2765 <    }
2766 <
2767 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
2768 <
2769 <    if (yy_aconf->rsa_public_key == NULL)
2770 <    {
2771 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
2772 <      break;
2773 <    }
2774 <      
2775 <    BIO_set_close(file, BIO_CLOSE);
2776 <    BIO_free(file);
2777 <  }
2778 < #endif /* HAVE_LIBCRYPTO */
2265 >    block_state.flags.value |= CONF_FLAGS_SSL;
2266   };
2267  
2268   connect_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 2783 | Line 2270 | connect_encrypted: ENCRYPTED '=' TBOOL '
2270    if (conf_parser_ctx.pass == 2)
2271    {
2272      if (yylval.number)
2273 <      yy_aconf->flags |= CONF_FLAGS_ENCRYPTED;
2787 <    else
2788 <      yy_aconf->flags &= ~CONF_FLAGS_ENCRYPTED;
2789 <  }
2790 < };
2791 <
2792 < connect_cryptlink: CRYPTLINK '=' TBOOL ';'
2793 < {
2794 <  if (conf_parser_ctx.pass == 2)
2795 <  {
2796 <    if (yylval.number)
2797 <      yy_aconf->flags |= CONF_FLAGS_CRYPTLINK;
2798 <    else
2799 <      yy_aconf->flags &= ~CONF_FLAGS_CRYPTLINK;
2800 <  }
2801 < };
2802 <
2803 < connect_compressed: COMPRESSED '=' TBOOL ';'
2804 < {
2805 <  if (conf_parser_ctx.pass == 2)
2806 <  {
2807 <    if (yylval.number)
2808 < #ifndef HAVE_LIBZ
2809 <      yyerror("Ignoring compressed=yes; -- no zlib support");
2810 < #else
2811 <      yy_aconf->flags |= CONF_FLAGS_COMPRESSED;
2812 < #endif
2813 <    else
2814 <      yy_aconf->flags &= ~CONF_FLAGS_COMPRESSED;
2815 <  }
2816 < };
2817 <
2818 < connect_auto: AUTOCONN '=' TBOOL ';'
2819 < {
2820 <  if (conf_parser_ctx.pass == 2)
2821 <  {
2822 <    if (yylval.number)
2823 <      yy_aconf->flags |= CONF_FLAGS_ALLOW_AUTO_CONN;
2273 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
2274      else
2275 <      yy_aconf->flags &= ~CONF_FLAGS_ALLOW_AUTO_CONN;
2275 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
2276    }
2277   };
2278  
2279 < connect_topicburst: TOPICBURST '=' TBOOL ';'
2279 > connect_hub_mask: HUB_MASK '=' QSTRING ';'
2280   {
2281    if (conf_parser_ctx.pass == 2)
2282 <  {
2833 <    if (yylval.number)
2834 <      SetConfTopicBurst(yy_aconf);
2835 <    else
2836 <      ClearConfTopicBurst(yy_aconf);
2837 <  }
2282 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
2283   };
2284  
2285 < connect_hub_mask: HUB_MASK '=' QSTRING ';'
2285 > connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2286   {
2287    if (conf_parser_ctx.pass == 2)
2288 <  {
2844 <    struct CollectItem *yy_tmp;
2845 <
2846 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2847 <    DupString(yy_tmp->host, yylval.string);
2848 <    DupString(yy_tmp->user, "*");
2849 <    dlinkAdd(yy_tmp, &yy_tmp->node, &hub_conf_list);
2850 <  }
2851 < };
2852 <
2853 < connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2854 < {
2855 <  if (conf_parser_ctx.pass == 2)
2856 <  {
2857 <    struct CollectItem *yy_tmp;
2858 <
2859 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2860 <    DupString(yy_tmp->host, yylval.string);
2861 <    DupString(yy_tmp->user, "*");
2862 <    dlinkAdd(yy_tmp, &yy_tmp->node, &leaf_conf_list);
2863 <  }
2288 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
2289   };
2290  
2291   connect_class: CLASS '=' QSTRING ';'
2292   {
2293    if (conf_parser_ctx.pass == 2)
2294 <  {
2870 <    MyFree(class_name);
2871 <    DupString(class_name, yylval.string);
2872 <  }
2294 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
2295   };
2296  
2297 < connect_cipher_preference: CIPHER_PREFERENCE '=' QSTRING ';'
2297 > connect_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
2298   {
2299   #ifdef HAVE_LIBCRYPTO
2300    if (conf_parser_ctx.pass == 2)
2301 <  {
2880 <    struct EncCapability *ecap;
2881 <    const char *cipher_name;
2882 <    int found = 0;
2883 <
2884 <    yy_aconf->cipher_preference = NULL;
2885 <    cipher_name = yylval.string;
2886 <
2887 <    for (ecap = CipherTable; ecap->name; ecap++)
2888 <    {
2889 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
2890 <          (ecap->cap & CAP_ENC_MASK))
2891 <      {
2892 <        yy_aconf->cipher_preference = ecap;
2893 <        found = 1;
2894 <        break;
2895 <      }
2896 <    }
2897 <
2898 <    if (!found)
2899 <      yyerror("Invalid cipher");
2900 <  }
2301 >    strlcpy(block_state.ciph.buf, yylval.string, sizeof(block_state.ciph.buf));
2302   #else
2303    if (conf_parser_ctx.pass == 2)
2304 <    yyerror("Ignoring cipher_preference -- no OpenSSL support");
2304 >    conf_error_report("Ignoring connect::ciphers -- no OpenSSL support");
2305   #endif
2306   };
2307  
2308 +
2309   /***************************************************************************
2310   *  section kill
2311   ***************************************************************************/
2312   kill_entry: KILL
2313   {
2314    if (conf_parser_ctx.pass == 2)
2315 <  {
2914 <    userbuf[0] = hostbuf[0] = reasonbuf[0] = '\0';
2915 <    regex_ban = 0;
2916 <  }
2315 >    reset_block_state();
2316   } '{' kill_items '}' ';'
2317   {
2318 <  if (conf_parser_ctx.pass == 2)
2920 <  {
2921 <    if (userbuf[0] && hostbuf[0])
2922 <    {
2923 <      if (regex_ban)
2924 <      {
2925 < #ifdef HAVE_LIBPCRE
2926 <        void *exp_user = NULL;
2927 <        void *exp_host = NULL;
2928 <        const char *errptr = NULL;
2929 <
2930 <        if (!(exp_user = ircd_pcre_compile(userbuf, &errptr)) ||
2931 <            !(exp_host = ircd_pcre_compile(hostbuf, &errptr)))
2932 <        {
2933 <          ilog(L_ERROR, "Failed to add regular expression based K-Line: %s",
2934 <               errptr);
2935 <          break;
2936 <        }
2937 <
2938 <        yy_aconf = map_to_conf(make_conf_item(RKLINE_TYPE));
2939 <        yy_aconf->regexuser = exp_user;
2940 <        yy_aconf->regexhost = exp_host;
2941 <
2942 <        DupString(yy_aconf->user, userbuf);
2943 <        DupString(yy_aconf->host, hostbuf);
2944 <
2945 <        if (reasonbuf[0])
2946 <          DupString(yy_aconf->reason, reasonbuf);
2947 <        else
2948 <          DupString(yy_aconf->reason, "No reason");
2949 < #else
2950 <        ilog(L_ERROR, "Failed to add regular expression based K-Line: no PCRE support");
2951 <        break;
2952 < #endif
2953 <      }
2954 <      else
2955 <      {
2956 <        yy_aconf = map_to_conf(make_conf_item(KLINE_TYPE));
2318 >  struct MaskItem *conf = NULL;
2319  
2320 <        DupString(yy_aconf->user, userbuf);
2321 <        DupString(yy_aconf->host, hostbuf);
2320 >  if (conf_parser_ctx.pass != 2)
2321 >    break;
2322  
2323 <        if (reasonbuf[0])
2324 <          DupString(yy_aconf->reason, reasonbuf);
2325 <        else
2964 <          DupString(yy_aconf->reason, "No reason");
2965 <        add_conf_by_address(CONF_KILL, yy_aconf);
2966 <      }
2967 <    }
2323 >  if (!block_state.user.buf[0] ||
2324 >      !block_state.host.buf[0])
2325 >    break;
2326  
2327 <    yy_aconf = NULL;
2328 <  }
2329 < };
2327 >  conf = conf_make(CONF_KLINE);
2328 >  conf->user = xstrdup(block_state.user.buf);
2329 >  conf->host = xstrdup(block_state.host.buf);
2330  
2331 < kill_type: TYPE
2332 < {
2333 < } '='  kill_type_items ';';
2334 <
2335 < kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2978 < kill_type_item: REGEX_T
2979 < {
2980 <  if (conf_parser_ctx.pass == 2)
2981 <    regex_ban = 1;
2331 >  if (block_state.rpass.buf[0])
2332 >    conf->reason = xstrdup(block_state.rpass.buf);
2333 >  else
2334 >    conf->reason = xstrdup(CONF_NOREASON);
2335 >  add_conf_by_address(CONF_KLINE, conf);
2336   };
2337  
2338   kill_items:     kill_items kill_item | kill_item;
2339 < kill_item:      kill_user | kill_reason | kill_type | error;
2339 > kill_item:      kill_user | kill_reason | error;
2340  
2341   kill_user: USER '=' QSTRING ';'
2342   {
2343 +
2344    if (conf_parser_ctx.pass == 2)
2345    {
2346      struct split_nuh_item nuh;
2347  
2348      nuh.nuhmask  = yylval.string;
2349      nuh.nickptr  = NULL;
2350 <    nuh.userptr  = userbuf;
2351 <    nuh.hostptr  = hostbuf;
2350 >    nuh.userptr  = block_state.user.buf;
2351 >    nuh.hostptr  = block_state.host.buf;
2352  
2353      nuh.nicksize = 0;
2354 <    nuh.usersize = sizeof(userbuf);
2355 <    nuh.hostsize = sizeof(hostbuf);
2354 >    nuh.usersize = sizeof(block_state.user.buf);
2355 >    nuh.hostsize = sizeof(block_state.host.buf);
2356  
2357      split_nuh(&nuh);
2358    }
2359   };
2360  
2361 < kill_reason: REASON '=' QSTRING ';'
2361 > kill_reason: REASON '=' QSTRING ';'
2362   {
2363    if (conf_parser_ctx.pass == 2)
2364 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2364 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2365   };
2366  
2367   /***************************************************************************
2368   *  section deny
2369   ***************************************************************************/
2370 < deny_entry: DENY
2370 > deny_entry: DENY
2371   {
2372    if (conf_parser_ctx.pass == 2)
2373 <    hostbuf[0] = reasonbuf[0] = '\0';
2373 >    reset_block_state();
2374   } '{' deny_items '}' ';'
2375   {
2376 <  if (conf_parser_ctx.pass == 2)
2376 >  struct MaskItem *conf = NULL;
2377 >
2378 >  if (conf_parser_ctx.pass != 2)
2379 >    break;
2380 >
2381 >  if (!block_state.addr.buf[0])
2382 >    break;
2383 >
2384 >  if (parse_netmask(block_state.addr.buf, NULL, NULL) != HM_HOST)
2385    {
2386 <    if (hostbuf[0] && parse_netmask(hostbuf, NULL, NULL) != HM_HOST)
2387 <    {
3025 <      yy_aconf = map_to_conf(make_conf_item(DLINE_TYPE));
3026 <      DupString(yy_aconf->host, hostbuf);
2386 >    conf = conf_make(CONF_DLINE);
2387 >    conf->host = xstrdup(block_state.addr.buf);
2388  
2389 <      if (reasonbuf[0])
2390 <        DupString(yy_aconf->reason, reasonbuf);
2391 <      else
2392 <        DupString(yy_aconf->reason, "No reason");
2393 <      add_conf_by_address(CONF_DLINE, yy_aconf);
3033 <      yy_aconf = NULL;
3034 <    }
2389 >    if (block_state.rpass.buf[0])
2390 >      conf->reason = xstrdup(block_state.rpass.buf);
2391 >    else
2392 >      conf->reason = xstrdup(CONF_NOREASON);
2393 >    add_conf_by_address(CONF_DLINE, conf);
2394    }
2395 < };
2395 > };
2396  
2397   deny_items:     deny_items deny_item | deny_item;
2398   deny_item:      deny_ip | deny_reason | error;
# Line 3041 | Line 2400 | deny_item:      deny_ip | deny_reason |
2400   deny_ip: IP '=' QSTRING ';'
2401   {
2402    if (conf_parser_ctx.pass == 2)
2403 <    strlcpy(hostbuf, yylval.string, sizeof(hostbuf));
2403 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2404   };
2405  
2406 < deny_reason: REASON '=' QSTRING ';'
2406 > deny_reason: REASON '=' QSTRING ';'
2407   {
2408    if (conf_parser_ctx.pass == 2)
2409 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2409 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2410   };
2411  
2412   /***************************************************************************
# Line 3064 | Line 2423 | exempt_ip: IP '=' QSTRING ';'
2423    {
2424      if (yylval.string[0] && parse_netmask(yylval.string, NULL, NULL) != HM_HOST)
2425      {
2426 <      yy_aconf = map_to_conf(make_conf_item(EXEMPTDLINE_TYPE));
2427 <      DupString(yy_aconf->host, yylval.string);
2426 >      struct MaskItem *conf = conf_make(CONF_EXEMPT);
2427 >      conf->host = xstrdup(yylval.string);
2428  
2429 <      add_conf_by_address(CONF_EXEMPTDLINE, yy_aconf);
3071 <      yy_aconf = NULL;
2429 >      add_conf_by_address(CONF_EXEMPT, conf);
2430      }
2431    }
2432   };
# Line 3079 | Line 2437 | exempt_ip: IP '=' QSTRING ';'
2437   gecos_entry: GECOS
2438   {
2439    if (conf_parser_ctx.pass == 2)
2440 <  {
3083 <    regex_ban = 0;
3084 <    reasonbuf[0] = gecos_name[0] = '\0';
3085 <  }
2440 >    reset_block_state();
2441   } '{' gecos_items '}' ';'
2442   {
2443 <  if (conf_parser_ctx.pass == 2)
3089 <  {
3090 <    if (gecos_name[0])
3091 <    {
3092 <      if (regex_ban)
3093 <      {
3094 < #ifdef HAVE_LIBPCRE
3095 <        void *exp_p = NULL;
3096 <        const char *errptr = NULL;
3097 <
3098 <        if (!(exp_p = ircd_pcre_compile(gecos_name, &errptr)))
3099 <        {
3100 <          ilog(L_ERROR, "Failed to add regular expression based X-Line: %s",
3101 <               errptr);
3102 <          break;
3103 <        }
3104 <
3105 <        yy_conf = make_conf_item(RXLINE_TYPE);
3106 <        yy_conf->regexpname = exp_p;
3107 < #else
3108 <        ilog(L_ERROR, "Failed to add regular expression based X-Line: no PCRE support");
3109 <        break;
3110 < #endif
3111 <      }
3112 <      else
3113 <        yy_conf = make_conf_item(XLINE_TYPE);
2443 >  struct MaskItem *conf = NULL;
2444  
2445 <      yy_match_item = map_to_conf(yy_conf);
2446 <      DupString(yy_conf->name, gecos_name);
2445 >  if (conf_parser_ctx.pass != 2)
2446 >    break;
2447  
2448 <      if (reasonbuf[0])
2449 <        DupString(yy_match_item->reason, reasonbuf);
3120 <      else
3121 <        DupString(yy_match_item->reason, "No reason");
3122 <    }
3123 <  }
3124 < };
2448 >  if (!block_state.name.buf[0])
2449 >    break;
2450  
2451 < gecos_flags: TYPE
2452 < {
3128 < } '='  gecos_flags_items ';';
2451 >  conf = conf_make(CONF_XLINE);
2452 >  conf->name = xstrdup(block_state.name.buf);
2453  
2454 < gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2455 < gecos_flags_item: REGEX_T
2456 < {
2457 <  if (conf_parser_ctx.pass == 2)
3134 <    regex_ban = 1;
2454 >  if (block_state.rpass.buf[0])
2455 >    conf->reason = xstrdup(block_state.rpass.buf);
2456 >  else
2457 >    conf->reason = xstrdup(CONF_NOREASON);
2458   };
2459  
2460   gecos_items: gecos_items gecos_item | gecos_item;
2461 < gecos_item:  gecos_name | gecos_reason | gecos_flags | error;
2461 > gecos_item:  gecos_name | gecos_reason | error;
2462  
2463 < gecos_name: NAME '=' QSTRING ';'
2463 > gecos_name: NAME '=' QSTRING ';'
2464   {
2465    if (conf_parser_ctx.pass == 2)
2466 <    strlcpy(gecos_name, yylval.string, sizeof(gecos_name));
2466 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2467   };
2468  
2469 < gecos_reason: REASON '=' QSTRING ';'
2469 > gecos_reason: REASON '=' QSTRING ';'
2470   {
2471    if (conf_parser_ctx.pass == 2)
2472 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2472 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2473   };
2474  
2475   /***************************************************************************
# Line 3156 | Line 2479 | general_entry: GENERAL
2479    '{' general_items '}' ';';
2480  
2481   general_items:      general_items general_item | general_item;
2482 < general_item:       general_hide_spoof_ips | general_ignore_bogus_ts |
2483 <                    general_failed_oper_notice | general_anti_nick_flood |
2484 <                    general_max_nick_time | general_max_nick_changes |
2485 <                    general_max_accept | general_anti_spam_exit_message_time |
2486 <                    general_ts_warn_delta | general_ts_max_delta |
2487 <                    general_kill_chase_time_limit | general_kline_with_reason |
2488 <                    general_kline_reason | general_invisible_on_connect |
2489 <                    general_warn_no_nline | general_dots_in_ident |
2490 <                    general_stats_o_oper_only | general_stats_k_oper_only |
2491 <                    general_pace_wait | general_stats_i_oper_only |
2492 <                    general_pace_wait_simple | general_stats_P_oper_only |
2493 <                    general_short_motd | general_no_oper_flood |
2494 <                    general_true_no_oper_flood | general_oper_pass_resv |
2495 <                    general_idletime | general_message_locale |
2496 <                    general_oper_only_umodes | general_max_targets |
2497 <                    general_use_egd | general_egdpool_path |
2498 <                    general_oper_umodes | general_caller_id_wait |
2499 <                    general_opers_bypass_callerid | general_default_floodcount |
2500 <                    general_min_nonwildcard | general_min_nonwildcard_simple |
2501 <                    general_servlink_path | general_disable_remote_commands |
2502 <                    general_default_cipher_preference |
2503 <                    general_compression_level | general_client_flood |
2504 <                    general_throttle_time | general_havent_read_conf |
2505 <                    general_dot_in_ip6_addr | general_ping_cookie |
2506 <                    general_disable_auth | general_burst_away |
2507 <                    general_tkline_expire_notices | general_gline_min_cidr |
2508 <                    general_gline_min_cidr6 | general_use_whois_actually |
2509 <                    general_reject_hold_time | general_stats_e_disabled |
2510 <                    general_max_watch |
2511 <                    error;
2482 > general_item:       general_hide_spoof_ips |
2483 >                    general_ignore_bogus_ts |
2484 >                    general_failed_oper_notice |
2485 >                    general_anti_nick_flood |
2486 >                    general_max_nick_time |
2487 >                    general_max_nick_changes |
2488 >                    general_max_accept |
2489 >                    general_anti_spam_exit_message_time |
2490 >                    general_ts_warn_delta |
2491 >                    general_ts_max_delta |
2492 >                    general_kill_chase_time_limit |
2493 >                    general_invisible_on_connect |
2494 >                    general_warn_no_connect_block |
2495 >                    general_dots_in_ident |
2496 >                    general_stats_o_oper_only |
2497 >                    general_stats_k_oper_only |
2498 >                    general_pace_wait |
2499 >                    general_stats_i_oper_only |
2500 >                    general_pace_wait_simple |
2501 >                    general_stats_P_oper_only |
2502 >                    general_stats_u_oper_only |
2503 >                    general_short_motd |
2504 >                    general_no_oper_flood |
2505 >                    general_true_no_oper_flood |
2506 >                    general_oper_pass_resv |
2507 >                    general_oper_only_umodes |
2508 >                    general_max_targets |
2509 >                    general_use_egd |
2510 >                    general_egdpool_path |
2511 >                    general_oper_umodes |
2512 >                    general_caller_id_wait |
2513 >                    general_opers_bypass_callerid |
2514 >                    general_default_floodcount |
2515 >                    general_min_nonwildcard |
2516 >                    general_min_nonwildcard_simple |
2517 >                    general_throttle_count |
2518 >                    general_throttle_time |
2519 >                    general_havent_read_conf |
2520 >                    general_ping_cookie |
2521 >                    general_disable_auth |
2522 >                    general_tkline_expire_notices |
2523 >                    general_gline_enable |
2524 >                    general_gline_duration |
2525 >                    general_gline_request_duration |
2526 >                    general_gline_min_cidr |
2527 >                    general_gline_min_cidr6 |
2528 >                    general_stats_e_disabled |
2529 >                    general_max_watch |
2530 >                    general_services_name |
2531 >                    general_cycle_on_host_change |
2532 >                    error;
2533  
2534  
2535   general_max_watch: MAX_WATCH '=' NUMBER ';'
# Line 3193 | Line 2537 | general_max_watch: MAX_WATCH '=' NUMBER
2537    ConfigFileEntry.max_watch = $3;
2538   };
2539  
2540 < general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2540 > general_cycle_on_host_change: CYCLE_ON_HOST_CHANGE '=' TBOOL ';'
2541   {
2542 <  ConfigFileEntry.gline_min_cidr = $3;
2542 >  if (conf_parser_ctx.pass == 2)
2543 >    ConfigFileEntry.cycle_on_host_change = yylval.number;
2544   };
2545  
2546 < general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2546 > general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2547   {
2548 <  ConfigFileEntry.gline_min_cidr6 = $3;
2548 >  if (conf_parser_ctx.pass == 2)
2549 >    ConfigFileEntry.glines = yylval.number;
2550   };
2551  
2552 < general_burst_away: BURST_AWAY '=' TBOOL ';'
2552 > general_gline_duration: GLINE_DURATION '=' timespec ';'
2553   {
2554 <  ConfigFileEntry.burst_away = yylval.number;
2554 >  if (conf_parser_ctx.pass == 2)
2555 >    ConfigFileEntry.gline_time = $3;
2556   };
2557  
2558 < general_use_whois_actually: USE_WHOIS_ACTUALLY '=' TBOOL ';'
2558 > general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2559   {
2560 <  ConfigFileEntry.use_whois_actually = yylval.number;
2560 >  if (conf_parser_ctx.pass == 2)
2561 >    ConfigFileEntry.gline_request_time = $3;
2562   };
2563  
2564 < general_reject_hold_time: TREJECT_HOLD_TIME '=' timespec ';'
2564 > general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2565   {
2566 <  GlobalSetOptions.rejecttime = yylval.number;
2566 >  ConfigFileEntry.gline_min_cidr = $3;
2567 > };
2568 >
2569 > general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2570 > {
2571 >  ConfigFileEntry.gline_min_cidr6 = $3;
2572   };
2573  
2574   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
# Line 3223 | Line 2576 | general_tkline_expire_notices: TKLINE_EX
2576    ConfigFileEntry.tkline_expire_notices = yylval.number;
2577   };
2578  
2579 < general_kill_chase_time_limit: KILL_CHASE_TIME_LIMIT '=' NUMBER ';'
2579 > general_kill_chase_time_limit: KILL_CHASE_TIME_LIMIT '=' timespec ';'
2580   {
2581    ConfigFileEntry.kill_chase_time_limit = $3;
2582   };
# Line 3238 | Line 2591 | general_ignore_bogus_ts: IGNORE_BOGUS_TS
2591    ConfigFileEntry.ignore_bogus_ts = yylval.number;
2592   };
2593  
3241 general_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
3242 {
3243  ConfigFileEntry.disable_remote = yylval.number;
3244 };
3245
2594   general_failed_oper_notice: FAILED_OPER_NOTICE '=' TBOOL ';'
2595   {
2596    ConfigFileEntry.failed_oper_notice = yylval.number;
# Line 3255 | Line 2603 | general_anti_nick_flood: ANTI_NICK_FLOOD
2603  
2604   general_max_nick_time: MAX_NICK_TIME '=' timespec ';'
2605   {
2606 <  ConfigFileEntry.max_nick_time = $3;
2606 >  ConfigFileEntry.max_nick_time = $3;
2607   };
2608  
2609   general_max_nick_changes: MAX_NICK_CHANGES '=' NUMBER ';'
# Line 3288 | Line 2636 | general_havent_read_conf: HAVENT_READ_CO
2636   {
2637    if (($3 > 0) && conf_parser_ctx.pass == 1)
2638    {
2639 <    ilog(L_CRIT, "You haven't read your config file properly.");
2640 <    ilog(L_CRIT, "There is a line in the example conf that will kill your server if not removed.");
2641 <    ilog(L_CRIT, "Consider actually reading/editing the conf file, and removing this line.");
2639 >    ilog(LOG_TYPE_IRCD, "You haven't read your config file properly.");
2640 >    ilog(LOG_TYPE_IRCD, "There is a line in the example conf that will kill your server if not removed.");
2641 >    ilog(LOG_TYPE_IRCD, "Consider actually reading/editing the conf file, and removing this line.");
2642      exit(0);
2643    }
2644   };
2645  
3298 general_kline_with_reason: KLINE_WITH_REASON '=' TBOOL ';'
3299 {
3300  ConfigFileEntry.kline_with_reason = yylval.number;
3301 };
3302
3303 general_kline_reason: KLINE_REASON '=' QSTRING ';'
3304 {
3305  if (conf_parser_ctx.pass == 2)
3306  {
3307    MyFree(ConfigFileEntry.kline_reason);
3308    DupString(ConfigFileEntry.kline_reason, yylval.string);
3309  }
3310 };
3311
2646   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2647   {
2648    ConfigFileEntry.invisible_on_connect = yylval.number;
2649   };
2650  
2651 < general_warn_no_nline: WARN_NO_NLINE '=' TBOOL ';'
2651 > general_warn_no_connect_block: WARN_NO_CONNECT_BLOCK '=' TBOOL ';'
2652   {
2653 <  ConfigFileEntry.warn_no_nline = yylval.number;
2653 >  ConfigFileEntry.warn_no_connect_block = yylval.number;
2654   };
2655  
2656   general_stats_e_disabled: STATS_E_DISABLED '=' TBOOL ';'
# Line 3334 | Line 2668 | general_stats_P_oper_only: STATS_P_OPER_
2668    ConfigFileEntry.stats_P_oper_only = yylval.number;
2669   };
2670  
2671 + general_stats_u_oper_only: STATS_U_OPER_ONLY '=' TBOOL ';'
2672 + {
2673 +  ConfigFileEntry.stats_u_oper_only = yylval.number;
2674 + };
2675 +
2676   general_stats_k_oper_only: STATS_K_OPER_ONLY '=' TBOOL ';'
2677   {
2678    ConfigFileEntry.stats_k_oper_only = 2 * yylval.number;
# Line 3374 | Line 2713 | general_short_motd: SHORT_MOTD '=' TBOOL
2713   {
2714    ConfigFileEntry.short_motd = yylval.number;
2715   };
2716 <  
2716 >
2717   general_no_oper_flood: NO_OPER_FLOOD '=' TBOOL ';'
2718   {
2719    ConfigFileEntry.no_oper_flood = yylval.number;
# Line 3390 | Line 2729 | general_oper_pass_resv: OPER_PASS_RESV '
2729    ConfigFileEntry.oper_pass_resv = yylval.number;
2730   };
2731  
3393 general_message_locale: MESSAGE_LOCALE '=' QSTRING ';'
3394 {
3395  if (conf_parser_ctx.pass == 2)
3396  {
3397    if (strlen(yylval.string) > LOCALE_LENGTH-2)
3398      yylval.string[LOCALE_LENGTH-1] = '\0';
3399
3400    set_locale(yylval.string);
3401  }
3402 };
3403
3404 general_idletime: IDLETIME '=' timespec ';'
3405 {
3406  ConfigFileEntry.idletime = $3;
3407 };
3408
2732   general_dots_in_ident: DOTS_IN_IDENT '=' NUMBER ';'
2733   {
2734    ConfigFileEntry.dots_in_ident = $3;
# Line 3416 | Line 2739 | general_max_targets: MAX_TARGETS '=' NUM
2739    ConfigFileEntry.max_targets = $3;
2740   };
2741  
2742 < general_servlink_path: SERVLINK_PATH '=' QSTRING ';'
3420 < {
3421 <  if (conf_parser_ctx.pass == 2)
3422 <  {
3423 <    MyFree(ConfigFileEntry.servlink_path);
3424 <    DupString(ConfigFileEntry.servlink_path, yylval.string);
3425 <  }
3426 < };
3427 <
3428 < general_default_cipher_preference: DEFAULT_CIPHER_PREFERENCE '=' QSTRING ';'
2742 > general_use_egd: USE_EGD '=' TBOOL ';'
2743   {
2744 < #ifdef HAVE_LIBCRYPTO
3431 <  if (conf_parser_ctx.pass == 2)
3432 <  {
3433 <    struct EncCapability *ecap;
3434 <    const char *cipher_name;
3435 <    int found = 0;
3436 <
3437 <    ConfigFileEntry.default_cipher_preference = NULL;
3438 <    cipher_name = yylval.string;
3439 <
3440 <    for (ecap = CipherTable; ecap->name; ecap++)
3441 <    {
3442 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
3443 <          (ecap->cap & CAP_ENC_MASK))
3444 <      {
3445 <        ConfigFileEntry.default_cipher_preference = ecap;
3446 <        found = 1;
3447 <        break;
3448 <      }
3449 <    }
3450 <
3451 <    if (!found)
3452 <      yyerror("Invalid cipher");
3453 <  }
3454 < #else
3455 <  if (conf_parser_ctx.pass == 2)
3456 <    yyerror("Ignoring default_cipher_preference -- no OpenSSL support");
3457 < #endif
2744 >  ConfigFileEntry.use_egd = yylval.number;
2745   };
2746  
2747 < general_compression_level: COMPRESSION_LEVEL '=' NUMBER ';'
2747 > general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
2748   {
2749    if (conf_parser_ctx.pass == 2)
2750    {
2751 <    ConfigFileEntry.compression_level = $3;
2752 < #ifndef HAVE_LIBZ
3466 <    yyerror("Ignoring compression_level -- no zlib support");
3467 < #else
3468 <    if ((ConfigFileEntry.compression_level < 1) ||
3469 <        (ConfigFileEntry.compression_level > 9))
3470 <    {
3471 <      yyerror("Ignoring invalid compression_level, using default");
3472 <      ConfigFileEntry.compression_level = 0;
3473 <    }
3474 < #endif
2751 >    MyFree(ConfigFileEntry.egdpool_path);
2752 >    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2753    }
2754   };
2755  
2756 < general_use_egd: USE_EGD '=' TBOOL ';'
2756 > general_services_name: T_SERVICES_NAME '=' QSTRING ';'
2757   {
2758 <  ConfigFileEntry.use_egd = yylval.number;
3481 < };
3482 <
3483 < general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
3484 < {
3485 <  if (conf_parser_ctx.pass == 2)
2758 >  if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2759    {
2760 <    MyFree(ConfigFileEntry.egdpool_path);
2761 <    DupString(ConfigFileEntry.egdpool_path, yylval.string);
2760 >    MyFree(ConfigFileEntry.service_name);
2761 >    ConfigFileEntry.service_name = xstrdup(yylval.string);
2762    }
2763   };
2764  
# Line 3499 | Line 2772 | general_disable_auth: DISABLE_AUTH '=' T
2772    ConfigFileEntry.disable_auth = yylval.number;
2773   };
2774  
2775 + general_throttle_count: THROTTLE_COUNT '=' NUMBER ';'
2776 + {
2777 +  ConfigFileEntry.throttle_count = $3;
2778 + };
2779 +
2780   general_throttle_time: THROTTLE_TIME '=' timespec ';'
2781   {
2782 <  ConfigFileEntry.throttle_time = yylval.number;
2782 >  ConfigFileEntry.throttle_time = $3;
2783   };
2784  
2785   general_oper_umodes: OPER_UMODES
# Line 3516 | Line 2794 | umode_oitem:     T_BOTS
2794   } | T_CCONN
2795   {
2796    ConfigFileEntry.oper_umodes |= UMODE_CCONN;
3519 } | T_CCONN_FULL
3520 {
3521  ConfigFileEntry.oper_umodes |= UMODE_CCONN_FULL;
2797   } | T_DEAF
2798   {
2799    ConfigFileEntry.oper_umodes |= UMODE_DEAF;
# Line 3528 | Line 2803 | umode_oitem:     T_BOTS
2803   } | T_FULL
2804   {
2805    ConfigFileEntry.oper_umodes |= UMODE_FULL;
2806 + } | HIDDEN
2807 + {
2808 +  ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2809 + } | HIDE_CHANS
2810 + {
2811 +  ConfigFileEntry.oper_umodes |= UMODE_HIDECHANS;
2812 + } | HIDE_IDLE
2813 + {
2814 +  ConfigFileEntry.oper_umodes |= UMODE_HIDEIDLE;
2815   } | T_SKILL
2816   {
2817    ConfigFileEntry.oper_umodes |= UMODE_SKILL;
# Line 3546 | Line 2830 | umode_oitem:     T_BOTS
2830   } | T_EXTERNAL
2831   {
2832    ConfigFileEntry.oper_umodes |= UMODE_EXTERNAL;
3549 } | T_OPERWALL
3550 {
3551  ConfigFileEntry.oper_umodes |= UMODE_OPERWALL;
2833   } | T_SERVNOTICE
2834   {
2835    ConfigFileEntry.oper_umodes |= UMODE_SERVNOTICE;
# Line 3567 | Line 2848 | umode_oitem:     T_BOTS
2848   } | T_LOCOPS
2849   {
2850    ConfigFileEntry.oper_umodes |= UMODE_LOCOPS;
2851 + } | T_NONONREG
2852 + {
2853 +  ConfigFileEntry.oper_umodes |= UMODE_REGONLY;
2854 + } | T_FARCONNECT
2855 + {
2856 +  ConfigFileEntry.oper_umodes |= UMODE_FARCONNECT;
2857   };
2858  
2859 < general_oper_only_umodes: OPER_ONLY_UMODES
2859 > general_oper_only_umodes: OPER_ONLY_UMODES
2860   {
2861    ConfigFileEntry.oper_only_umodes = 0;
2862   } '='  umode_items ';' ;
2863  
2864 < umode_items:    umode_items ',' umode_item | umode_item;
2865 < umode_item:     T_BOTS
2864 > umode_items:  umode_items ',' umode_item | umode_item;
2865 > umode_item:   T_BOTS
2866   {
2867    ConfigFileEntry.oper_only_umodes |= UMODE_BOTS;
2868   } | T_CCONN
2869   {
2870    ConfigFileEntry.oper_only_umodes |= UMODE_CCONN;
3584 } | T_CCONN_FULL
3585 {
3586  ConfigFileEntry.oper_only_umodes |= UMODE_CCONN_FULL;
2871   } | T_DEAF
2872   {
2873    ConfigFileEntry.oper_only_umodes |= UMODE_DEAF;
# Line 3591 | Line 2875 | umode_item:    T_BOTS
2875   {
2876    ConfigFileEntry.oper_only_umodes |= UMODE_DEBUG;
2877   } | T_FULL
2878 < {
2878 > {
2879    ConfigFileEntry.oper_only_umodes |= UMODE_FULL;
2880   } | T_SKILL
2881   {
2882    ConfigFileEntry.oper_only_umodes |= UMODE_SKILL;
2883 + } | HIDDEN
2884 + {
2885 +  ConfigFileEntry.oper_only_umodes |= UMODE_HIDDEN;
2886   } | T_NCHANGE
2887   {
2888    ConfigFileEntry.oper_only_umodes |= UMODE_NCHANGE;
# Line 3611 | Line 2898 | umode_item:    T_BOTS
2898   } | T_EXTERNAL
2899   {
2900    ConfigFileEntry.oper_only_umodes |= UMODE_EXTERNAL;
3614 } | T_OPERWALL
3615 {
3616  ConfigFileEntry.oper_only_umodes |= UMODE_OPERWALL;
2901   } | T_SERVNOTICE
2902   {
2903    ConfigFileEntry.oper_only_umodes |= UMODE_SERVNOTICE;
# Line 3632 | Line 2916 | umode_item:    T_BOTS
2916   } | T_LOCOPS
2917   {
2918    ConfigFileEntry.oper_only_umodes |= UMODE_LOCOPS;
2919 + } | T_NONONREG
2920 + {
2921 +  ConfigFileEntry.oper_only_umodes |= UMODE_REGONLY;
2922 + } | T_FARCONNECT
2923 + {
2924 +  ConfigFileEntry.oper_only_umodes |= UMODE_FARCONNECT;
2925   };
2926  
2927   general_min_nonwildcard: MIN_NONWILDCARD '=' NUMBER ';'
# Line 3649 | Line 2939 | general_default_floodcount: DEFAULT_FLOO
2939    ConfigFileEntry.default_floodcount = $3;
2940   };
2941  
3652 general_client_flood: T_CLIENT_FLOOD '=' sizespec ';'
3653 {
3654  ConfigFileEntry.client_flood = $3;
3655 };
3656
3657 general_dot_in_ip6_addr: DOT_IN_IP6_ADDR '=' TBOOL ';'
3658 {
3659  ConfigFileEntry.dot_in_ip6_addr = yylval.number;
3660 };
3661
3662 /***************************************************************************
3663 *  section glines
3664 ***************************************************************************/
3665 gline_entry: GLINES
3666 {
3667  if (conf_parser_ctx.pass == 2)
3668  {
3669    yy_conf = make_conf_item(GDENY_TYPE);
3670    yy_aconf = map_to_conf(yy_conf);
3671  }
3672 } '{' gline_items '}' ';'
3673 {
3674  if (conf_parser_ctx.pass == 2)
3675  {
3676    /*
3677     * since we re-allocate yy_conf/yy_aconf after the end of action=, at the
3678     * end we will have one extra, so we should free it.
3679     */
3680    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3681    {
3682      delete_conf_item(yy_conf);
3683      yy_conf = NULL;
3684      yy_aconf = NULL;
3685    }
3686  }
3687 };
3688
3689 gline_items:        gline_items gline_item | gline_item;
3690 gline_item:         gline_enable |
3691                    gline_duration |
3692                    gline_logging |
3693                    gline_user |
3694                    gline_server |
3695                    gline_action |
3696                    error;
3697
3698 gline_enable: ENABLE '=' TBOOL ';'
3699 {
3700  if (conf_parser_ctx.pass == 2)
3701    ConfigFileEntry.glines = yylval.number;
3702 };
3703
3704 gline_duration: DURATION '=' timespec ';'
3705 {
3706  if (conf_parser_ctx.pass == 2)
3707    ConfigFileEntry.gline_time = $3;
3708 };
3709
3710 gline_logging: LOGGING
3711 {
3712  if (conf_parser_ctx.pass == 2)
3713    ConfigFileEntry.gline_logging = 0;
3714 } '=' gline_logging_types ';';
3715 gline_logging_types:     gline_logging_types ',' gline_logging_type_item | gline_logging_type_item;
3716 gline_logging_type_item: T_REJECT
3717 {
3718  if (conf_parser_ctx.pass == 2)
3719    ConfigFileEntry.gline_logging |= GDENY_REJECT;
3720 } | T_BLOCK
3721 {
3722  if (conf_parser_ctx.pass == 2)
3723    ConfigFileEntry.gline_logging |= GDENY_BLOCK;
3724 };
3725
3726 gline_user: USER '=' QSTRING ';'
3727 {
3728  if (conf_parser_ctx.pass == 2)
3729  {
3730    struct split_nuh_item nuh;
3731
3732    nuh.nuhmask  = yylval.string;
3733    nuh.nickptr  = NULL;
3734    nuh.userptr  = userbuf;
3735    nuh.hostptr  = hostbuf;
3736
3737    nuh.nicksize = 0;
3738    nuh.usersize = sizeof(userbuf);
3739    nuh.hostsize = sizeof(hostbuf);
3740
3741    split_nuh(&nuh);
3742
3743    if (yy_aconf->user == NULL)
3744    {
3745      DupString(yy_aconf->user, userbuf);
3746      DupString(yy_aconf->host, hostbuf);
3747    }
3748    else
3749    {
3750      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
3751
3752      DupString(yy_tmp->user, userbuf);
3753      DupString(yy_tmp->host, hostbuf);
3754
3755      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
3756    }
3757  }
3758 };
3759
3760 gline_server: NAME '=' QSTRING ';'
3761 {
3762  if (conf_parser_ctx.pass == 2)  
3763  {
3764    MyFree(yy_conf->name);
3765    DupString(yy_conf->name, yylval.string);
3766  }
3767 };
3768
3769 gline_action: ACTION
3770 {
3771  if (conf_parser_ctx.pass == 2)
3772    yy_aconf->flags = 0;
3773 } '=' gdeny_types ';'
3774 {
3775  if (conf_parser_ctx.pass == 2)
3776  {
3777    struct CollectItem *yy_tmp = NULL;
3778    dlink_node *ptr, *next_ptr;
3779
3780    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
3781    {
3782      struct AccessItem *new_aconf;
3783      struct ConfItem *new_conf;
3784
3785      yy_tmp = ptr->data;
3786      new_conf = make_conf_item(GDENY_TYPE);
3787      new_aconf = map_to_conf(new_conf);
3788
3789      new_aconf->flags = yy_aconf->flags;
3790
3791      if (yy_conf->name != NULL)
3792        DupString(new_conf->name, yy_conf->name);
3793      else
3794        DupString(new_conf->name, "*");
3795      if (yy_aconf->user != NULL)
3796         DupString(new_aconf->user, yy_tmp->user);
3797      else  
3798        DupString(new_aconf->user, "*");
3799      if (yy_aconf->host != NULL)
3800        DupString(new_aconf->host, yy_tmp->host);
3801      else
3802        DupString(new_aconf->host, "*");
3803
3804      dlinkDelete(&yy_tmp->node, &col_conf_list);
3805    }
3806
3807    /*
3808     * In case someone has fed us with more than one action= after user/name
3809     * which would leak memory  -Michael
3810     */
3811    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3812      delete_conf_item(yy_conf);
3813
3814    yy_conf = make_conf_item(GDENY_TYPE);
3815    yy_aconf = map_to_conf(yy_conf);
3816  }
3817 };
3818
3819 gdeny_types: gdeny_types ',' gdeny_type_item | gdeny_type_item;
3820 gdeny_type_item: T_REJECT
3821 {
3822  if (conf_parser_ctx.pass == 2)
3823    yy_aconf->flags |= GDENY_REJECT;
3824 } | T_BLOCK
3825 {
3826  if (conf_parser_ctx.pass == 2)
3827    yy_aconf->flags |= GDENY_BLOCK;
3828 };
2942  
2943   /***************************************************************************
2944   *  section channel
# Line 3834 | Line 2947 | channel_entry: CHANNEL
2947    '{' channel_items '}' ';';
2948  
2949   channel_items:      channel_items channel_item | channel_item;
2950 < channel_item:       channel_disable_local_channels | channel_use_except |
2951 <                    channel_use_invex | channel_use_knock |
2952 <                    channel_max_bans | channel_knock_delay |
2953 <                    channel_knock_delay_channel | channel_max_chans_per_user |
2954 <                    channel_quiet_on_ban | channel_default_split_user_count |
2950 > channel_item:       channel_max_bans |
2951 >                    channel_invite_client_count |
2952 >                    channel_invite_client_time |
2953 >                    channel_knock_client_count |
2954 >                    channel_knock_client_time |
2955 >                    channel_knock_delay_channel |
2956 >                    channel_max_channels |
2957 >                    channel_default_split_user_count |
2958                      channel_default_split_server_count |
2959 <                    channel_no_create_on_split | channel_restrict_channels |
2960 <                    channel_no_join_on_split | channel_burst_topicwho |
2961 <                    channel_jflood_count | channel_jflood_time |
2962 <                    channel_disable_fake_channels | error;
2959 >                    channel_no_create_on_split |
2960 >                    channel_no_join_on_split |
2961 >                    channel_jflood_count |
2962 >                    channel_jflood_time |
2963 >                    channel_disable_fake_channels |
2964 >                    error;
2965  
2966   channel_disable_fake_channels: DISABLE_FAKE_CHANNELS '=' TBOOL ';'
2967   {
2968    ConfigChannel.disable_fake_channels = yylval.number;
2969   };
2970  
2971 < channel_restrict_channels: RESTRICT_CHANNELS '=' TBOOL ';'
3854 < {
3855 <  ConfigChannel.restrict_channels = yylval.number;
3856 < };
3857 <
3858 < channel_disable_local_channels: DISABLE_LOCAL_CHANNELS '=' TBOOL ';'
3859 < {
3860 <  ConfigChannel.disable_local_channels = yylval.number;
3861 < };
3862 <
3863 < channel_use_except: USE_EXCEPT '=' TBOOL ';'
2971 > channel_invite_client_count: INVITE_CLIENT_COUNT '=' NUMBER ';'
2972   {
2973 <  ConfigChannel.use_except = yylval.number;
2973 >  ConfigChannel.invite_client_count = $3;
2974   };
2975  
2976 < channel_use_invex: USE_INVEX '=' TBOOL ';'
2976 > channel_invite_client_time: INVITE_CLIENT_TIME '=' timespec ';'
2977   {
2978 <  ConfigChannel.use_invex = yylval.number;
2978 >  ConfigChannel.invite_client_time = $3;
2979   };
2980  
2981 < channel_use_knock: USE_KNOCK '=' TBOOL ';'
2981 > channel_knock_client_count: KNOCK_CLIENT_COUNT '=' NUMBER ';'
2982   {
2983 <  ConfigChannel.use_knock = yylval.number;
2983 >  ConfigChannel.knock_client_count = $3;
2984   };
2985  
2986 < channel_knock_delay: KNOCK_DELAY '=' timespec ';'
2986 > channel_knock_client_time: KNOCK_CLIENT_TIME '=' timespec ';'
2987   {
2988 <  ConfigChannel.knock_delay = $3;
2988 >  ConfigChannel.knock_client_time = $3;
2989   };
2990  
2991   channel_knock_delay_channel: KNOCK_DELAY_CHANNEL '=' timespec ';'
# Line 3885 | Line 2993 | channel_knock_delay_channel: KNOCK_DELAY
2993    ConfigChannel.knock_delay_channel = $3;
2994   };
2995  
2996 < channel_max_chans_per_user: MAX_CHANS_PER_USER '=' NUMBER ';'
2996 > channel_max_channels: MAX_CHANNELS '=' NUMBER ';'
2997   {
2998 <  ConfigChannel.max_chans_per_user = $3;
3891 < };
3892 <
3893 < channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
3894 < {
3895 <  ConfigChannel.quiet_on_ban = yylval.number;
2998 >  ConfigChannel.max_channels = $3;
2999   };
3000  
3001   channel_max_bans: MAX_BANS '=' NUMBER ';'
# Line 3920 | Line 3023 | channel_no_join_on_split: NO_JOIN_ON_SPL
3023    ConfigChannel.no_join_on_split = yylval.number;
3024   };
3025  
3923 channel_burst_topicwho: BURST_TOPICWHO '=' TBOOL ';'
3924 {
3925  ConfigChannel.burst_topicwho = yylval.number;
3926 };
3927
3026   channel_jflood_count: JOIN_FLOOD_COUNT '=' NUMBER ';'
3027   {
3028    GlobalSetOptions.joinfloodcount = yylval.number;
# Line 3932 | Line 3030 | channel_jflood_count: JOIN_FLOOD_COUNT '
3030  
3031   channel_jflood_time: JOIN_FLOOD_TIME '=' timespec ';'
3032   {
3033 <  GlobalSetOptions.joinfloodtime = yylval.number;
3033 >  GlobalSetOptions.joinfloodtime = $3;
3034   };
3035  
3036   /***************************************************************************
# Line 3942 | Line 3040 | serverhide_entry: SERVERHIDE
3040    '{' serverhide_items '}' ';';
3041  
3042   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
3043 < serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
3044 <                    serverhide_links_delay |
3045 <                    serverhide_disable_hidden |
3046 <                    serverhide_hidden | serverhide_hidden_name |
3047 <                    serverhide_hide_server_ips |
3043 > serverhide_item:    serverhide_flatten_links |
3044 >                    serverhide_disable_remote_commands |
3045 >                    serverhide_hide_servers |
3046 >                    serverhide_hide_services |
3047 >                    serverhide_links_delay |
3048 >                    serverhide_hidden |
3049 >                    serverhide_hidden_name |
3050 >                    serverhide_hide_server_ips |
3051                      error;
3052  
3053   serverhide_flatten_links: FLATTEN_LINKS '=' TBOOL ';'
# Line 3955 | Line 3056 | serverhide_flatten_links: FLATTEN_LINKS
3056      ConfigServerHide.flatten_links = yylval.number;
3057   };
3058  
3059 + serverhide_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
3060 + {
3061 +  if (conf_parser_ctx.pass == 2)
3062 +    ConfigServerHide.disable_remote_commands = yylval.number;
3063 + };
3064 +
3065   serverhide_hide_servers: HIDE_SERVERS '=' TBOOL ';'
3066   {
3067    if (conf_parser_ctx.pass == 2)
3068      ConfigServerHide.hide_servers = yylval.number;
3069   };
3070  
3071 + serverhide_hide_services: HIDE_SERVICES '=' TBOOL ';'
3072 + {
3073 +  if (conf_parser_ctx.pass == 2)
3074 +    ConfigServerHide.hide_services = yylval.number;
3075 + };
3076 +
3077   serverhide_hidden_name: HIDDEN_NAME '=' QSTRING ';'
3078   {
3079    if (conf_parser_ctx.pass == 2)
3080    {
3081      MyFree(ConfigServerHide.hidden_name);
3082 <    DupString(ConfigServerHide.hidden_name, yylval.string);
3082 >    ConfigServerHide.hidden_name = xstrdup(yylval.string);
3083    }
3084   };
3085  
# Line 3990 | Line 3103 | serverhide_hidden: HIDDEN '=' TBOOL ';'
3103      ConfigServerHide.hidden = yylval.number;
3104   };
3105  
3993 serverhide_disable_hidden: DISABLE_HIDDEN '=' TBOOL ';'
3994 {
3995  if (conf_parser_ctx.pass == 2)
3996    ConfigServerHide.disable_hidden = yylval.number;
3997 };
3998
3106   serverhide_hide_server_ips: HIDE_SERVER_IPS '=' TBOOL ';'
3107   {
3108    if (conf_parser_ctx.pass == 2)

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)