ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing:
ircd-hybrid-8/src/ircd_parser.y (file contents), Revision 1264 by michael, Tue Jan 17 12:30:57 2012 UTC vs.
ircd-hybrid/trunk/src/conf_parser.y (file contents), Revision 1648 by michael, Sat Nov 10 17:34:09 2012 UTC

# Line 1 | Line 1
1   /*
2   *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  ircd_parser.y: Parses the ircd configuration file.
3 > *  conf_parser.y: Parses the ircd configuration file.
4   *
5   *  Copyright (C) 2005 by the past and present ircd coders, and others.
6   *
# Line 32 | Line 32
32   #include "stdinc.h"
33   #include "ircd.h"
34   #include "list.h"
35 < #include "s_conf.h"
35 > #include "conf.h"
36 > #include "conf_class.h"
37   #include "event.h"
38 < #include "s_log.h"
38 > #include "log.h"
39   #include "client.h"     /* for UMODE_ALL only */
40   #include "irc_string.h"
41   #include "sprintf_irc.h"
# Line 52 | Line 53
53   #include <openssl/rsa.h>
54   #include <openssl/bio.h>
55   #include <openssl/pem.h>
56 + #include <openssl/dh.h>
57   #endif
58  
59 < static char *class_name = NULL;
58 < static struct ConfItem *yy_conf = NULL;
59 < static struct AccessItem *yy_aconf = NULL;
60 < static struct MatchItem *yy_match_item = NULL;
61 < static struct ClassItem *yy_class = NULL;
62 < static char *yy_class_name = NULL;
63 <
64 < static dlink_list col_conf_list  = { NULL, NULL, 0 };
65 < static dlink_list hub_conf_list  = { NULL, NULL, 0 };
66 < static dlink_list leaf_conf_list = { NULL, NULL, 0 };
67 < static unsigned int listener_flags = 0;
68 < static unsigned int regex_ban = 0;
69 < static char userbuf[IRCD_BUFSIZE];
70 < static char hostbuf[IRCD_BUFSIZE];
71 < static char reasonbuf[REASONLEN + 1];
72 < static char gecos_name[REALLEN * 4];
73 < static char lfile[IRCD_BUFSIZE];
74 < static unsigned int ltype = 0;
75 < static unsigned int lsize = 0;
76 < static char *resv_reason = NULL;
77 < static char *listener_address = NULL;
78 <
79 < struct CollectItem
80 < {
81 <  dlink_node node;
82 <  char *name;
83 <  char *user;
84 <  char *host;
85 <  char *passwd;
86 <  int  port;
87 <  int  flags;
88 < #ifdef HAVE_LIBCRYPTO
89 <  char *rsa_public_key_file;
90 <  RSA *rsa_public_key;
91 < #endif
92 < };
59 > int yylex(void);
60  
61 < static void
95 < free_collect_item(struct CollectItem *item)
61 > static struct
62   {
63 <  MyFree(item->name);
64 <  MyFree(item->user);
65 <  MyFree(item->host);
66 <  MyFree(item->passwd);
67 < #ifdef HAVE_LIBCRYPTO
68 <  MyFree(item->rsa_public_key_file);
69 < #endif
70 <  MyFree(item);
71 < }
63 >  struct {
64 >    dlink_list list;
65 >  } mask,
66 >    leaf,
67 >    hub;
68 >
69 >  struct {
70 >    char buf[IRCD_BUFSIZE];
71 >  } name,
72 >    user,
73 >    host,
74 >    addr,
75 >    bind,
76 >    file,
77 >    ciph,
78 >    rpass,
79 >    spass,
80 >    class;
81 >
82 >  struct {
83 >    unsigned int value;
84 >  } flags,
85 >    modes,
86 >    size,
87 >    type,
88 >    port,
89 >    aftype,
90 >    ping_freq,
91 >    max_perip,
92 >    con_freq,
93 >    max_total,
94 >    max_global,
95 >    max_local,
96 >    max_ident,
97 >    max_sendq,
98 >    max_recvq,
99 >    cidr_bitlen_ipv4,
100 >    cidr_bitlen_ipv6,
101 >    number_per_cidr;
102 > } block_state;
103  
104   static void
105 < unhook_hub_leaf_confs(void)
105 > reset_block_state(void)
106   {
107 <  dlink_node *ptr;
111 <  dlink_node *next_ptr;
112 <  struct CollectItem *yy_hconf;
113 <  struct CollectItem *yy_lconf;
107 >  dlink_node *ptr = NULL, *ptr_next = NULL;
108  
109 <  DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
109 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.mask.list.head)
110    {
111 <    yy_hconf = ptr->data;
112 <    dlinkDelete(&yy_hconf->node, &hub_conf_list);
113 <    free_collect_item(yy_hconf);
111 >    MyFree(ptr->data);
112 >    dlinkDelete(ptr, &block_state.mask.list);
113 >    free_dlink_node(ptr);
114    }
115  
116 <  DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
116 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.leaf.list.head)
117    {
118 <    yy_lconf = ptr->data;
119 <    dlinkDelete(&yy_lconf->node, &leaf_conf_list);
120 <    free_collect_item(yy_lconf);
118 >    MyFree(ptr->data);
119 >    dlinkDelete(ptr, &block_state.leaf.list);
120 >    free_dlink_node(ptr);
121    }
122 +
123 +  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.hub.list.head)
124 +  {
125 +    MyFree(ptr->data);
126 +    dlinkDelete(ptr, &block_state.hub.list);
127 +    free_dlink_node(ptr);
128 +  }
129 +
130 +  memset(&block_state, 0, sizeof(block_state));
131   }
132  
133   %}
# Line 135 | Line 138 | unhook_hub_leaf_confs(void)
138   }
139  
140   %token  ACCEPT_PASSWORD
138 %token  ACTION
141   %token  ADMIN
142   %token  AFTYPE
141 %token  T_ALLOW
143   %token  ANTI_NICK_FLOOD
144   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
145   %token  AUTOCONN
146 < %token  T_BLOCK
146 < %token  BURST_AWAY
147 < %token  BURST_TOPICWHO
148 < %token  BYTES KBYTES MBYTES GBYTES TBYTES
146 > %token  BYTES KBYTES MBYTES
147   %token  CALLER_ID_WAIT
148   %token  CAN_FLOOD
149   %token  CHANNEL
150   %token  CIDR_BITLEN_IPV4
151   %token  CIDR_BITLEN_IPV6
154 %token  CIPHER_PREFERENCE
152   %token  CLASS
156 %token  COMPRESSED
157 %token  COMPRESSION_LEVEL
153   %token  CONNECT
154   %token  CONNECTFREQ
160 %token  CRYPTLINK
161 %token  DEFAULT_CIPHER_PREFERENCE
155   %token  DEFAULT_FLOODCOUNT
156   %token  DEFAULT_SPLIT_SERVER_COUNT
157   %token  DEFAULT_SPLIT_USER_COUNT
# Line 167 | Line 160 | unhook_hub_leaf_confs(void)
160   %token  DIE
161   %token  DISABLE_AUTH
162   %token  DISABLE_FAKE_CHANNELS
170 %token  DISABLE_HIDDEN
171 %token  DISABLE_LOCAL_CHANNELS
163   %token  DISABLE_REMOTE_COMMANDS
164   %token  DOTS_IN_IDENT
174 %token  DURATION
165   %token  EGDPOOL_PATH
166   %token  EMAIL
177 %token  ENABLE
167   %token  ENCRYPTED
168   %token  EXCEED_LIMIT
169   %token  EXEMPT
# Line 184 | Line 173 | unhook_hub_leaf_confs(void)
173   %token  GECOS
174   %token  GENERAL
175   %token  GLINE
176 < %token  GLINES
176 > %token  GLINE_DURATION
177 > %token  GLINE_ENABLE
178   %token  GLINE_EXEMPT
179 < %token  GLINE_TIME
179 > %token  GLINE_REQUEST_DURATION
180   %token  GLINE_MIN_CIDR
181   %token  GLINE_MIN_CIDR6
182   %token  GLOBAL_KILL
# Line 194 | Line 184 | unhook_hub_leaf_confs(void)
184   %token  NEED_IDENT
185   %token  HAVENT_READ_CONF
186   %token  HIDDEN
197 %token  HIDDEN_ADMIN
187   %token  HIDDEN_NAME
199 %token  HIDDEN_OPER
188   %token  HIDE_SERVER_IPS
189   %token  HIDE_SERVERS
190   %token  HIDE_SPOOF_IPS
# Line 210 | Line 198 | unhook_hub_leaf_confs(void)
198   %token  KILL_CHASE_TIME_LIMIT
199   %token  KLINE
200   %token  KLINE_EXEMPT
213 %token  KLINE_REASON
214 %token  KLINE_WITH_REASON
201   %token  KNOCK_DELAY
202   %token  KNOCK_DELAY_CHANNEL
203   %token  LEAF_MASK
# Line 220 | Line 206 | unhook_hub_leaf_confs(void)
206   %token  T_LOG
207   %token  MAX_ACCEPT
208   %token  MAX_BANS
209 + %token  MAX_CHANS_PER_OPER
210   %token  MAX_CHANS_PER_USER
211   %token  MAX_GLOBAL
212   %token  MAX_IDENT
# Line 245 | Line 232 | unhook_hub_leaf_confs(void)
232   %token  NO_OPER_FLOOD
233   %token  NO_TILDE
234   %token  NUMBER
248 %token  NUMBER_PER_IDENT
235   %token  NUMBER_PER_CIDR
236   %token  NUMBER_PER_IP
251 %token  NUMBER_PER_IP_GLOBAL
237   %token  OPERATOR
238   %token  OPERS_BYPASS_CALLERID
239   %token  OPER_ONLY_UMODES
# Line 263 | Line 248 | unhook_hub_leaf_confs(void)
248   %token  PATH
249   %token  PING_COOKIE
250   %token  PING_TIME
266 %token  PING_WARNING
251   %token  PORT
252   %token  QSTRING
253   %token  QUIET_ON_BAN
# Line 272 | Line 256 | unhook_hub_leaf_confs(void)
256   %token  REDIRSERV
257   %token  REGEX_T
258   %token  REHASH
275 %token  TREJECT_HOLD_TIME
259   %token  REMOTE
260   %token  REMOTEBAN
261   %token  RESTRICT_CHANNELS
279 %token  RESTRICTED
262   %token  RSA_PRIVATE_KEY_FILE
263   %token  RSA_PUBLIC_KEY_FILE
264   %token  SSL_CERTIFICATE_FILE
265 < %token  T_SSL_CONNECTION_METHOD
265 > %token  SSL_DH_PARAM_FILE
266 > %token  T_SSL_CLIENT_METHOD
267 > %token  T_SSL_SERVER_METHOD
268   %token  T_SSLV3
269   %token  T_TLSV1
270   %token  RESV
# Line 290 | Line 274 | unhook_hub_leaf_confs(void)
274   %token  SEND_PASSWORD
275   %token  SERVERHIDE
276   %token  SERVERINFO
293 %token  SERVLINK_PATH
277   %token  IRCD_SID
278   %token  TKLINE_EXPIRE_NOTICES
279   %token  T_SHARED
280   %token  T_CLUSTER
281   %token  TYPE
282   %token  SHORT_MOTD
300 %token  SILENT
283   %token  SPOOF
284   %token  SPOOF_NOTICE
285   %token  STATS_E_DISABLED
# Line 307 | Line 289 | unhook_hub_leaf_confs(void)
289   %token  STATS_P_OPER_ONLY
290   %token  TBOOL
291   %token  TMASKED
310 %token  T_REJECT
292   %token  TS_MAX_DELTA
293   %token  TS_WARN_DELTA
294   %token  TWODOTS
# Line 317 | Line 298 | unhook_hub_leaf_confs(void)
298   %token  T_CALLERID
299   %token  T_CCONN
300   %token  T_CCONN_FULL
301 < %token  T_CLIENT_FLOOD
301 > %token  T_SSL_CIPHER_LIST
302   %token  T_DEAF
303   %token  T_DEBUG
304   %token  T_DLINE
324 %token  T_DRONE
305   %token  T_EXTERNAL
306   %token  T_FULL
307   %token  T_INVISIBLE
# Line 331 | Line 311 | unhook_hub_leaf_confs(void)
311   %token  T_MAX_CLIENTS
312   %token  T_NCHANGE
313   %token  T_OPERWALL
314 + %token  T_RECVQ
315   %token  T_REJ
316   %token  T_SERVER
317   %token  T_SERVNOTICE
318 + %token  T_SET
319   %token  T_SKILL
320   %token  T_SPY
321   %token  T_SSL
322   %token  T_UMODES
323   %token  T_UNAUTH
324 + %token  T_UNDLINE
325   %token  T_UNLIMITED
326   %token  T_UNRESV
327   %token  T_UNXLINE
# Line 347 | Line 330 | unhook_hub_leaf_confs(void)
330   %token  T_RESTART
331   %token  T_SERVICE
332   %token  T_SERVICES_NAME
350 %token  T_TIMESTAMP
333   %token  THROTTLE_TIME
352 %token  TOPICBURST
334   %token  TRUE_NO_OPER_FLOOD
354 %token  TKLINE
355 %token  TXLINE
356 %token  TRESV
335   %token  UNKLINE
336   %token  USER
337   %token  USE_EGD
360 %token  USE_EXCEPT
361 %token  USE_INVEX
362 %token  USE_KNOCK
338   %token  USE_LOGGING
364 %token  USE_WHOIS_ACTUALLY
339   %token  VHOST
340   %token  VHOST6
341   %token  XLINE
368 %token  WARN
342   %token  WARN_NO_NLINE
343   %token  T_SIZE
344   %token  T_FILE
# Line 400 | Line 373 | conf_item:        admin_entry
373                  | deny_entry
374                  | exempt_entry
375                  | general_entry
403                | gline_entry
376                  | gecos_entry
377                  | modules_entry
378                  | error ';'
# Line 471 | Line 443 | serverinfo_items:       serverinfo_items
443   serverinfo_item:        serverinfo_name | serverinfo_vhost |
444                          serverinfo_hub | serverinfo_description |
445                          serverinfo_network_name | serverinfo_network_desc |
446 <                        serverinfo_max_clients |
446 >                        serverinfo_max_clients | serverinfo_ssl_dh_param_file |
447                          serverinfo_rsa_private_key_file | serverinfo_vhost6 |
448                          serverinfo_sid | serverinfo_ssl_certificate_file |
449 <                        serverinfo_ssl_connection_method |
449 >                        serverinfo_ssl_client_method | serverinfo_ssl_server_method |
450 >                        serverinfo_ssl_cipher_list |
451                          error ';' ;
452  
453  
454 < serverinfo_ssl_connection_method: T_SSL_CONNECTION_METHOD
454 > serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
455 > serverinfo_ssl_server_method: T_SSL_SERVER_METHOD '=' server_method_types ';' ;
456 >
457 > client_method_types: client_method_types ',' client_method_type_item | client_method_type_item;
458 > client_method_type_item: T_SSLV3
459   {
460   #ifdef HAVE_LIBCRYPTO
461 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
462 <    ServerInfo.tls_version = 0;
461 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
462 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv3);
463   #endif
464 < } '=' method_types ';'
464 > } | T_TLSV1
465   {
466   #ifdef HAVE_LIBCRYPTO
467 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
468 <  {
492 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_SSLV3))
493 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
494 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_TLSV1))
495 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
496 <  }
467 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
468 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_TLSv1);
469   #endif
470   };
471  
472 < method_types: method_types ',' method_type_item | method_type_item;
473 < method_type_item: T_SSLV3
472 > server_method_types: server_method_types ',' server_method_type_item | server_method_type_item;
473 > server_method_type_item: T_SSLV3
474   {
475   #ifdef HAVE_LIBCRYPTO
476 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
477 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_SSLV3;
476 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
477 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
478   #endif
479   } | T_TLSV1
480   {
481   #ifdef HAVE_LIBCRYPTO
482 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
483 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_TLSV1;
482 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
483 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
484   #endif
485   };
486  
# Line 524 | Line 496 | serverinfo_ssl_certificate_file: SSL_CER
496      }
497  
498      if (SSL_CTX_use_certificate_file(ServerInfo.server_ctx, yylval.string,
499 +                                     SSL_FILETYPE_PEM) <= 0 ||
500 +        SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
501                                       SSL_FILETYPE_PEM) <= 0)
502      {
503        yyerror(ERR_lib_error_string(ERR_get_error()));
# Line 531 | Line 505 | serverinfo_ssl_certificate_file: SSL_CER
505      }
506  
507      if (SSL_CTX_use_PrivateKey_file(ServerInfo.server_ctx, ServerInfo.rsa_private_key_file,
508 +                                    SSL_FILETYPE_PEM) <= 0 ||
509 +        SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
510                                      SSL_FILETYPE_PEM) <= 0)
511      {
512        yyerror(ERR_lib_error_string(ERR_get_error()));
513        break;
514      }
515  
516 <    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx))
516 >    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
517 >        !SSL_CTX_check_private_key(ServerInfo.client_ctx))
518      {
519        yyerror(ERR_lib_error_string(ERR_get_error()));
520        break;
# Line 565 | Line 542 | serverinfo_rsa_private_key_file: RSA_PRI
542        ServerInfo.rsa_private_key_file = NULL;
543      }
544  
545 <    DupString(ServerInfo.rsa_private_key_file, yylval.string);
545 >    ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
546  
547      if ((file = BIO_new_file(yylval.string, "r")) == NULL)
548      {
# Line 573 | Line 550 | serverinfo_rsa_private_key_file: RSA_PRI
550        break;
551      }
552  
553 <    ServerInfo.rsa_private_key = (RSA *)PEM_read_bio_RSAPrivateKey(file, NULL,
577 <      0, NULL);
553 >    ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
554  
555      BIO_set_close(file, BIO_CLOSE);
556      BIO_free(file);
# Line 606 | Line 582 | serverinfo_rsa_private_key_file: RSA_PRI
582   #endif
583   };
584  
585 + serverinfo_ssl_dh_param_file: SSL_DH_PARAM_FILE '=' QSTRING ';'
586 + {
587 + /* TBD - XXX: error reporting */
588 + #ifdef HAVE_LIBCRYPTO
589 +  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
590 +  {
591 +    BIO *file = BIO_new_file(yylval.string, "r");
592 +
593 +    if (file)
594 +    {
595 +      DH *dh = PEM_read_bio_DHparams(file, NULL, NULL, NULL);
596 +
597 +      BIO_free(file);
598 +
599 +      if (dh)
600 +      {
601 +        if (DH_size(dh) < 128)
602 +          ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
603 +        else
604 +          SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
605 +
606 +        DH_free(dh);
607 +      }
608 +    }
609 +  }
610 + #endif
611 + };
612 +
613 + serverinfo_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
614 + {
615 + #ifdef HAVE_LIBCRYPTO
616 +  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
617 +    SSL_CTX_set_cipher_list(ServerInfo.server_ctx, yylval.string);
618 + #endif
619 + };
620 +
621   serverinfo_name: NAME '=' QSTRING ';'
622   {
623    /* this isn't rehashable */
624    if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
625    {
626      if (valid_servname(yylval.string))
627 <      DupString(ServerInfo.name, yylval.string);
627 >      ServerInfo.name = xstrdup(yylval.string);
628      else
629      {
630        ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::name -- invalid name. Aborting.");
# Line 627 | Line 639 | serverinfo_sid: IRCD_SID '=' QSTRING ';'
639    if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
640    {
641      if (valid_sid(yylval.string))
642 <      DupString(ServerInfo.sid, yylval.string);
642 >      ServerInfo.sid = xstrdup(yylval.string);
643      else
644      {
645        ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::sid -- invalid SID. Aborting.");
# Line 641 | Line 653 | serverinfo_description: DESCRIPTION '='
653    if (conf_parser_ctx.pass == 2)
654    {
655      MyFree(ServerInfo.description);
656 <    DupString(ServerInfo.description,yylval.string);
656 >    ServerInfo.description = xstrdup(yylval.string);
657    }
658   };
659  
# Line 655 | Line 667 | serverinfo_network_name: NETWORK_NAME '=
667        p = '\0';
668  
669      MyFree(ServerInfo.network_name);
670 <    DupString(ServerInfo.network_name, yylval.string);
670 >    ServerInfo.network_name = xstrdup(yylval.string);
671    }
672   };
673  
# Line 664 | Line 676 | serverinfo_network_desc: NETWORK_DESC '=
676    if (conf_parser_ctx.pass == 2)
677    {
678      MyFree(ServerInfo.network_desc);
679 <    DupString(ServerInfo.network_desc, yylval.string);
679 >    ServerInfo.network_desc = xstrdup(yylval.string);
680    }
681   };
682  
# Line 769 | Line 781 | admin_name: NAME '=' QSTRING ';'
781    if (conf_parser_ctx.pass == 2)
782    {
783      MyFree(AdminInfo.name);
784 <    DupString(AdminInfo.name, yylval.string);
784 >    AdminInfo.name = xstrdup(yylval.string);
785    }
786   };
787  
# Line 778 | Line 790 | admin_email: EMAIL '=' QSTRING ';'
790    if (conf_parser_ctx.pass == 2)
791    {
792      MyFree(AdminInfo.email);
793 <    DupString(AdminInfo.email, yylval.string);
793 >    AdminInfo.email = xstrdup(yylval.string);
794    }
795   };
796  
# Line 787 | Line 799 | admin_description: DESCRIPTION '=' QSTRI
799    if (conf_parser_ctx.pass == 2)
800    {
801      MyFree(AdminInfo.description);
802 <    DupString(AdminInfo.description, yylval.string);
802 >    AdminInfo.description = xstrdup(yylval.string);
803    }
804   };
805  
# Line 797 | Line 809 | admin_description: DESCRIPTION '=' QSTRI
809   logging_entry:          T_LOG  '{' logging_items '}' ';' ;
810   logging_items:          logging_items logging_item | logging_item ;
811  
812 < logging_item:           logging_use_logging | logging_timestamp | logging_file_entry |
812 > logging_item:           logging_use_logging | logging_file_entry |
813                          error ';' ;
814  
815   logging_use_logging: USE_LOGGING '=' TBOOL ';'
# Line 806 | Line 818 | logging_use_logging: USE_LOGGING '=' TBO
818      ConfigLoggingEntry.use_logging = yylval.number;
819   };
820  
809 logging_timestamp: T_TIMESTAMP '=' TBOOL ';'
810 {
811  if (conf_parser_ctx.pass == 2)
812    ConfigLoggingEntry.timestamp = yylval.number;
813 };
814
821   logging_file_entry:
822   {
823 <  lfile[0] = '\0';
824 <  ltype = 0;
819 <  lsize = 0;
823 >  if (conf_parser_ctx.pass == 2)
824 >    reset_block_state();
825   } T_FILE  '{' logging_file_items '}' ';'
826   {
827 <  if (conf_parser_ctx.pass == 2 && ltype > 0)
828 <    log_add_file(ltype, lsize, lfile);
827 >  if (conf_parser_ctx.pass != 2)
828 >    break;
829 >
830 >  if (block_state.type.value && block_state.file.buf[0])
831 >    log_add_file(block_state.type.value, block_state.size.value,
832 >                 block_state.file.buf);
833   };
834  
835   logging_file_items: logging_file_items logging_file_item |
# Line 831 | Line 840 | logging_file_item:  logging_file_name |
840  
841   logging_file_name: NAME '=' QSTRING ';'
842   {
843 <  strlcpy(lfile, yylval.string, sizeof(lfile));
843 >  if (conf_parser_ctx.pass != 2)
844 >    break;
845 >
846 >  strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
847   }
848  
849   logging_file_size: T_SIZE '=' sizespec ';'
850   {
851 <  lsize = $3;
851 >  block_state.size.value = $3;
852   } | T_SIZE '=' T_UNLIMITED ';'
853   {
854 <  lsize = 0;
854 >  block_state.size.value = 0;
855   };
856  
857   logging_file_type: TYPE
858   {
859    if (conf_parser_ctx.pass == 2)
860 <    ltype = 0;
860 >    block_state.type.value = 0;
861   } '='  logging_file_type_items ';' ;
862  
863   logging_file_type_items: logging_file_type_items ',' logging_file_type_item | logging_file_type_item;
864   logging_file_type_item:  USER
865   {
866    if (conf_parser_ctx.pass == 2)
867 <    ltype = LOG_TYPE_USER;
867 >    block_state.type.value = LOG_TYPE_USER;
868   } | OPERATOR
869   {
870    if (conf_parser_ctx.pass == 2)
871 <    ltype = LOG_TYPE_OPER;
871 >    block_state.type.value = LOG_TYPE_OPER;
872   } | GLINE
873   {
874    if (conf_parser_ctx.pass == 2)
875 <    ltype = LOG_TYPE_GLINE;
875 >    block_state.type.value = LOG_TYPE_GLINE;
876   } | T_DLINE
877   {
878    if (conf_parser_ctx.pass == 2)
879 <    ltype = LOG_TYPE_DLINE;
879 >    block_state.type.value = LOG_TYPE_DLINE;
880   } | KLINE
881   {
882    if (conf_parser_ctx.pass == 2)
883 <    ltype = LOG_TYPE_KLINE;
883 >    block_state.type.value = LOG_TYPE_KLINE;
884   } | KILL
885   {
886    if (conf_parser_ctx.pass == 2)
887 <    ltype = LOG_TYPE_KILL;
887 >    block_state.type.value = LOG_TYPE_KILL;
888   } | T_DEBUG
889   {
890    if (conf_parser_ctx.pass == 2)
891 <    ltype = LOG_TYPE_DEBUG;
891 >    block_state.type.value = LOG_TYPE_DEBUG;
892   };
893  
894  
# Line 885 | Line 897 | logging_file_type_item:  USER
897   ***************************************************************************/
898   oper_entry: OPERATOR
899   {
900 <  if (conf_parser_ctx.pass == 2)
901 <  {
902 <    yy_conf = make_conf_item(OPER_TYPE);
903 <    yy_aconf = map_to_conf(yy_conf);
904 <    SetConfEncrypted(yy_aconf); /* Yes, the default is encrypted */
905 <  }
894 <  else
895 <  {
896 <    MyFree(class_name);
897 <    class_name = NULL;
898 <  }
899 < } oper_name_b '{' oper_items '}' ';'
900 >  if (conf_parser_ctx.pass != 2)
901 >    break;
902 >
903 >  reset_block_state();
904 >  block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
905 > } '{' oper_items '}' ';'
906   {
907 <  if (conf_parser_ctx.pass == 2)
902 <  {
903 <    struct CollectItem *yy_tmp;
904 <    dlink_node *ptr;
905 <    dlink_node *next_ptr;
907 >  dlink_node *ptr = NULL;
908  
909 <    conf_add_class_to_conf(yy_conf, class_name);
909 >  if (conf_parser_ctx.pass != 2)
910 >    break;
911  
912 <    /* Now, make sure there is a copy of the "base" given oper
913 <     * block in each of the collected copies
914 <     */
912 >  if (!block_state.name.buf[0])
913 >    break;
914 > #ifdef HAVE_LIBCRYPTO
915 >  if (!(block_state.file.buf[0] ||
916 >        block_state.rpass.buf[0]))
917 >    break;
918 > #else
919 >  if (!block_state.rpass.buf[0])
920 >    break;
921 > #endif
922  
923 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
924 <    {
925 <      struct AccessItem *new_aconf;
926 <      struct ConfItem *new_conf;
917 <      yy_tmp = ptr->data;
923 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
924 >  {
925 >    struct MaskItem *conf = NULL;
926 >    struct split_nuh_item nuh;
927  
928 <      new_conf = make_conf_item(OPER_TYPE);
929 <      new_aconf = (struct AccessItem *)map_to_conf(new_conf);
928 >    nuh.nuhmask  = ptr->data;
929 >    nuh.nickptr  = NULL;
930 >    nuh.userptr  = block_state.user.buf;
931 >    nuh.hostptr  = block_state.host.buf;
932 >    nuh.nicksize = 0;
933 >    nuh.usersize = sizeof(block_state.user.buf);
934 >    nuh.hostsize = sizeof(block_state.host.buf);
935 >    split_nuh(&nuh);
936  
937 <      new_aconf->flags = yy_aconf->flags;
937 >    conf        = conf_make(CONF_OPER);
938 >    conf->user  = xstrdup(block_state.user.buf);
939 >    conf->host  = xstrdup(block_state.host.buf);
940 >
941 >    if (block_state.rpass.buf[0])
942 >      conf->passwd = xstrdup(block_state.rpass.buf);
943 >
944 >    conf->flags = block_state.flags.value;
945 >    conf->modes = block_state.modes.value;
946 >    conf->port  = block_state.port.value;
947 >    conf->htype = parse_netmask(conf->host, &conf->addr, &conf->bits);
948  
949 <      if (yy_conf->name != NULL)
925 <        DupString(new_conf->name, yy_conf->name);
926 <      if (yy_tmp->user != NULL)
927 <        DupString(new_aconf->user, yy_tmp->user);
928 <      else
929 <        DupString(new_aconf->user, "*");
930 <      if (yy_tmp->host != NULL)
931 <        DupString(new_aconf->host, yy_tmp->host);
932 <      else
933 <        DupString(new_aconf->host, "*");
934 <      conf_add_class_to_conf(new_conf, class_name);
935 <      if (yy_aconf->passwd != NULL)
936 <        DupString(new_aconf->passwd, yy_aconf->passwd);
949 >    conf_add_class_to_conf(conf, block_state.class.buf);
950  
938      new_aconf->port = yy_aconf->port;
951   #ifdef HAVE_LIBCRYPTO
952 <      if (yy_aconf->rsa_public_key_file != NULL)
953 <      {
954 <        BIO *file;
955 <
944 <        DupString(new_aconf->rsa_public_key_file,
945 <                  yy_aconf->rsa_public_key_file);
952 >    if (block_state.file.buf[0])
953 >    {
954 >      BIO *file = NULL;
955 >      RSA *pkey = NULL;
956  
957 <        file = BIO_new_file(yy_aconf->rsa_public_key_file, "r");
958 <        new_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file,
959 <                                                           NULL, 0, NULL);
960 <        BIO_set_close(file, BIO_CLOSE);
951 <        BIO_free(file);
957 >      if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
958 >      {
959 >        yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
960 >        break;
961        }
953 #endif
962  
963 < #ifdef HAVE_LIBCRYPTO
956 <      if (yy_tmp->name && (yy_tmp->passwd || yy_aconf->rsa_public_key)
957 <          && yy_tmp->host)
958 < #else
959 <      if (yy_tmp->name && yy_tmp->passwd && yy_tmp->host)
960 < #endif
963 >      if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
964        {
965 <        conf_add_class_to_conf(new_conf, class_name);
966 <        if (yy_tmp->name != NULL)
964 <          DupString(new_conf->name, yy_tmp->name);
965 >        yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
966 >        break;
967        }
968  
969 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
970 <      free_collect_item(yy_tmp);
969 >      conf->rsa_public_key = pkey;
970 >      BIO_set_close(file, BIO_CLOSE);
971 >      BIO_free(file);
972      }
973 <
971 <    yy_conf = NULL;
972 <    yy_aconf = NULL;
973 <
974 <
975 <    MyFree(class_name);
976 <    class_name = NULL;
973 > #endif /* HAVE_LIBCRYPTO */
974    }
975 < };
975 > };
976  
980 oper_name_b: | oper_name_t;
977   oper_items:     oper_items oper_item | oper_item;
978   oper_item:      oper_name | oper_user | oper_password |
979                  oper_umodes | oper_class | oper_encrypted |
# Line 986 | Line 982 | oper_item:      oper_name | oper_user |
982   oper_name: NAME '=' QSTRING ';'
983   {
984    if (conf_parser_ctx.pass == 2)
985 <  {
990 <    if (strlen(yylval.string) > OPERNICKLEN)
991 <      yylval.string[OPERNICKLEN] = '\0';
992 <
993 <    MyFree(yy_conf->name);
994 <    DupString(yy_conf->name, yylval.string);
995 <  }
996 < };
997 <
998 < oper_name_t: QSTRING
999 < {
1000 <  if (conf_parser_ctx.pass == 2)
1001 <  {
1002 <    if (strlen(yylval.string) > OPERNICKLEN)
1003 <      yylval.string[OPERNICKLEN] = '\0';
1004 <
1005 <    MyFree(yy_conf->name);
1006 <    DupString(yy_conf->name, yylval.string);
1007 <  }
985 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
986   };
987  
988   oper_user: USER '=' QSTRING ';'
989   {
990    if (conf_parser_ctx.pass == 2)
991 <  {
1014 <    struct split_nuh_item nuh;
1015 <
1016 <    nuh.nuhmask  = yylval.string;
1017 <    nuh.nickptr  = NULL;
1018 <    nuh.userptr  = userbuf;
1019 <    nuh.hostptr  = hostbuf;
1020 <
1021 <    nuh.nicksize = 0;
1022 <    nuh.usersize = sizeof(userbuf);
1023 <    nuh.hostsize = sizeof(hostbuf);
1024 <
1025 <    split_nuh(&nuh);
1026 <
1027 <    if (yy_aconf->user == NULL)
1028 <    {
1029 <      DupString(yy_aconf->user, userbuf);
1030 <      DupString(yy_aconf->host, hostbuf);
1031 <    }
1032 <    else
1033 <    {
1034 <      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
1035 <
1036 <      DupString(yy_tmp->user, userbuf);
1037 <      DupString(yy_tmp->host, hostbuf);
1038 <
1039 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1040 <    }
1041 <  }
991 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
992   };
993  
994   oper_password: PASSWORD '=' QSTRING ';'
995   {
996    if (conf_parser_ctx.pass == 2)
997 <  {
1048 <    if (yy_aconf->passwd != NULL)
1049 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1050 <
1051 <    MyFree(yy_aconf->passwd);
1052 <    DupString(yy_aconf->passwd, yylval.string);
1053 <  }
997 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
998   };
999  
1000   oper_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 1058 | Line 1002 | oper_encrypted: ENCRYPTED '=' TBOOL ';'
1002    if (conf_parser_ctx.pass == 2)
1003    {
1004      if (yylval.number)
1005 <      SetConfEncrypted(yy_aconf);
1005 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1006      else
1007 <      ClearConfEncrypted(yy_aconf);
1007 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1008    }
1009   };
1010  
1011   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
1012   {
1069 #ifdef HAVE_LIBCRYPTO
1013    if (conf_parser_ctx.pass == 2)
1014 <  {
1072 <    BIO *file;
1073 <
1074 <    if (yy_aconf->rsa_public_key != NULL)
1075 <    {
1076 <      RSA_free(yy_aconf->rsa_public_key);
1077 <      yy_aconf->rsa_public_key = NULL;
1078 <    }
1079 <
1080 <    if (yy_aconf->rsa_public_key_file != NULL)
1081 <    {
1082 <      MyFree(yy_aconf->rsa_public_key_file);
1083 <      yy_aconf->rsa_public_key_file = NULL;
1084 <    }
1085 <
1086 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
1087 <    file = BIO_new_file(yylval.string, "r");
1088 <
1089 <    if (file == NULL)
1090 <    {
1091 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
1092 <      break;
1093 <    }
1094 <
1095 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
1096 <
1097 <    if (yy_aconf->rsa_public_key == NULL)
1098 <    {
1099 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1100 <      break;
1101 <    }
1102 <
1103 <    BIO_set_close(file, BIO_CLOSE);
1104 <    BIO_free(file);
1105 <  }
1106 < #endif /* HAVE_LIBCRYPTO */
1014 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1015   };
1016  
1017   oper_class: CLASS '=' QSTRING ';'
1018   {
1019    if (conf_parser_ctx.pass == 2)
1020 <  {
1113 <    MyFree(class_name);
1114 <    DupString(class_name, yylval.string);
1115 <  }
1020 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1021   };
1022  
1023   oper_umodes: T_UMODES
1024   {
1025    if (conf_parser_ctx.pass == 2)
1026 <    yy_aconf->modes = 0;
1026 >    block_state.modes.value = 0;
1027   } '='  oper_umodes_items ';' ;
1028  
1029   oper_umodes_items: oper_umodes_items ',' oper_umodes_item | oper_umodes_item;
1030   oper_umodes_item:  T_BOTS
1031   {
1032    if (conf_parser_ctx.pass == 2)
1033 <    yy_aconf->modes |= UMODE_BOTS;
1033 >    block_state.modes.value |= UMODE_BOTS;
1034   } | T_CCONN
1035   {
1036    if (conf_parser_ctx.pass == 2)
1037 <    yy_aconf->modes |= UMODE_CCONN;
1037 >    block_state.modes.value |= UMODE_CCONN;
1038   } | T_CCONN_FULL
1039   {
1040    if (conf_parser_ctx.pass == 2)
1041 <    yy_aconf->modes |= UMODE_CCONN_FULL;
1041 >    block_state.modes.value |= UMODE_CCONN_FULL;
1042   } | T_DEAF
1043   {
1044    if (conf_parser_ctx.pass == 2)
1045 <    yy_aconf->modes |= UMODE_DEAF;
1045 >    block_state.modes.value |= UMODE_DEAF;
1046   } | T_DEBUG
1047   {
1048    if (conf_parser_ctx.pass == 2)
1049 <    yy_aconf->modes |= UMODE_DEBUG;
1049 >    block_state.modes.value |= UMODE_DEBUG;
1050   } | T_FULL
1051   {
1052    if (conf_parser_ctx.pass == 2)
1053 <    yy_aconf->modes |= UMODE_FULL;
1053 >    block_state.modes.value |= UMODE_FULL;
1054 > } | HIDDEN
1055 > {
1056 >  if (conf_parser_ctx.pass == 2)
1057 >    block_state.modes.value |= UMODE_HIDDEN;
1058   } | T_SKILL
1059   {
1060    if (conf_parser_ctx.pass == 2)
1061 <    yy_aconf->modes |= UMODE_SKILL;
1061 >    block_state.modes.value |= UMODE_SKILL;
1062   } | T_NCHANGE
1063   {
1064    if (conf_parser_ctx.pass == 2)
1065 <    yy_aconf->modes |= UMODE_NCHANGE;
1065 >    block_state.modes.value |= UMODE_NCHANGE;
1066   } | T_REJ
1067   {
1068    if (conf_parser_ctx.pass == 2)
1069 <    yy_aconf->modes |= UMODE_REJ;
1069 >    block_state.modes.value |= UMODE_REJ;
1070   } | T_UNAUTH
1071   {
1072    if (conf_parser_ctx.pass == 2)
1073 <    yy_aconf->modes |= UMODE_UNAUTH;
1073 >    block_state.modes.value |= UMODE_UNAUTH;
1074   } | T_SPY
1075   {
1076    if (conf_parser_ctx.pass == 2)
1077 <    yy_aconf->modes |= UMODE_SPY;
1077 >    block_state.modes.value |= UMODE_SPY;
1078   } | T_EXTERNAL
1079   {
1080    if (conf_parser_ctx.pass == 2)
1081 <    yy_aconf->modes |= UMODE_EXTERNAL;
1081 >    block_state.modes.value |= UMODE_EXTERNAL;
1082   } | T_OPERWALL
1083   {
1084    if (conf_parser_ctx.pass == 2)
1085 <    yy_aconf->modes |= UMODE_OPERWALL;
1085 >    block_state.modes.value |= UMODE_OPERWALL;
1086   } | T_SERVNOTICE
1087   {
1088    if (conf_parser_ctx.pass == 2)
1089 <    yy_aconf->modes |= UMODE_SERVNOTICE;
1089 >    block_state.modes.value |= UMODE_SERVNOTICE;
1090   } | T_INVISIBLE
1091   {
1092    if (conf_parser_ctx.pass == 2)
1093 <    yy_aconf->modes |= UMODE_INVISIBLE;
1093 >    block_state.modes.value |= UMODE_INVISIBLE;
1094   } | T_WALLOP
1095   {
1096    if (conf_parser_ctx.pass == 2)
1097 <    yy_aconf->modes |= UMODE_WALLOP;
1097 >    block_state.modes.value |= UMODE_WALLOP;
1098   } | T_SOFTCALLERID
1099   {
1100    if (conf_parser_ctx.pass == 2)
1101 <    yy_aconf->modes |= UMODE_SOFTCALLERID;
1101 >    block_state.modes.value |= UMODE_SOFTCALLERID;
1102   } | T_CALLERID
1103   {
1104    if (conf_parser_ctx.pass == 2)
1105 <    yy_aconf->modes |= UMODE_CALLERID;
1105 >    block_state.modes.value |= UMODE_CALLERID;
1106   } | T_LOCOPS
1107   {
1108    if (conf_parser_ctx.pass == 2)
1109 <    yy_aconf->modes |= UMODE_LOCOPS;
1109 >    block_state.modes.value |= UMODE_LOCOPS;
1110   };
1111  
1112   oper_flags: IRCD_FLAGS
1113   {
1114    if (conf_parser_ctx.pass == 2)
1115 <    yy_aconf->port = 0;
1115 >    block_state.port.value = 0;
1116   } '='  oper_flags_items ';';
1117  
1118   oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1119   oper_flags_item: GLOBAL_KILL
1120   {
1121    if (conf_parser_ctx.pass == 2)
1122 <    yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1122 >    block_state.port.value |= OPER_FLAG_GLOBAL_KILL;
1123   } | REMOTE
1124   {
1125    if (conf_parser_ctx.pass == 2)
1126 <    yy_aconf->port |= OPER_FLAG_REMOTE;
1126 >    block_state.port.value |= OPER_FLAG_REMOTE;
1127   } | KLINE
1128   {
1129    if (conf_parser_ctx.pass == 2)
1130 <    yy_aconf->port |= OPER_FLAG_K;
1130 >    block_state.port.value |= OPER_FLAG_K;
1131   } | UNKLINE
1132   {
1133    if (conf_parser_ctx.pass == 2)
1134 <    yy_aconf->port |= OPER_FLAG_UNKLINE;
1134 >    block_state.port.value |= OPER_FLAG_UNKLINE;
1135 > } | T_DLINE
1136 > {
1137 >  if (conf_parser_ctx.pass == 2)
1138 >    block_state.port.value |= OPER_FLAG_DLINE;
1139 > } | T_UNDLINE
1140 > {
1141 >  if (conf_parser_ctx.pass == 2)
1142 >    block_state.port.value |= OPER_FLAG_UNDLINE;
1143   } | XLINE
1144   {
1145    if (conf_parser_ctx.pass == 2)
1146 <    yy_aconf->port |= OPER_FLAG_X;
1146 >    block_state.port.value |= OPER_FLAG_X;
1147   } | GLINE
1148   {
1149    if (conf_parser_ctx.pass == 2)
1150 <    yy_aconf->port |= OPER_FLAG_GLINE;
1150 >    block_state.port.value |= OPER_FLAG_GLINE;
1151   } | DIE
1152   {
1153    if (conf_parser_ctx.pass == 2)
1154 <    yy_aconf->port |= OPER_FLAG_DIE;
1154 >    block_state.port.value |= OPER_FLAG_DIE;
1155   } | T_RESTART
1156   {
1157    if (conf_parser_ctx.pass == 2)
1158 <    yy_aconf->port |= OPER_FLAG_RESTART;
1158 >    block_state.port.value |= OPER_FLAG_RESTART;
1159   } | REHASH
1160   {
1161    if (conf_parser_ctx.pass == 2)
1162 <    yy_aconf->port |= OPER_FLAG_REHASH;
1162 >    block_state.port.value |= OPER_FLAG_REHASH;
1163   } | ADMIN
1164   {
1165    if (conf_parser_ctx.pass == 2)
1166 <    yy_aconf->port |= OPER_FLAG_ADMIN;
1250 < } | HIDDEN_ADMIN
1251 < {
1252 <  if (conf_parser_ctx.pass == 2)
1253 <    yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1166 >    block_state.port.value |= OPER_FLAG_ADMIN;
1167   } | NICK_CHANGES
1168   {
1169    if (conf_parser_ctx.pass == 2)
1170 <    yy_aconf->port |= OPER_FLAG_N;
1170 >    block_state.port.value |= OPER_FLAG_N;
1171   } | T_OPERWALL
1172   {
1173    if (conf_parser_ctx.pass == 2)
1174 <    yy_aconf->port |= OPER_FLAG_OPERWALL;
1174 >    block_state.port.value |= OPER_FLAG_OPERWALL;
1175   } | T_GLOBOPS
1176   {
1177    if (conf_parser_ctx.pass == 2)
1178 <    yy_aconf->port |= OPER_FLAG_GLOBOPS;
1178 >    block_state.port.value |= OPER_FLAG_GLOBOPS;
1179   } | OPER_SPY_T
1180   {
1181    if (conf_parser_ctx.pass == 2)
1182 <    yy_aconf->port |= OPER_FLAG_OPER_SPY;
1183 < } | HIDDEN_OPER
1182 >    block_state.port.value |= OPER_FLAG_OPER_SPY;
1183 > } | REMOTEBAN
1184   {
1185    if (conf_parser_ctx.pass == 2)
1186 <    yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1187 < } | REMOTEBAN
1186 >    block_state.port.value |= OPER_FLAG_REMOTEBAN;
1187 > } | T_SET
1188   {
1189    if (conf_parser_ctx.pass == 2)
1190 <    yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1190 >    block_state.port.value |= OPER_FLAG_SET;
1191   } | MODULE
1192   {
1193    if (conf_parser_ctx.pass == 2)
1194 <    yy_aconf->port |= OPER_FLAG_MODULE;
1194 >    block_state.port.value |= OPER_FLAG_MODULE;
1195   };
1196  
1197  
# Line 1288 | Line 1201 | oper_flags_item: GLOBAL_KILL
1201   class_entry: CLASS
1202   {
1203    if (conf_parser_ctx.pass == 1)
1204 <  {
1205 <    yy_conf = make_conf_item(CLASS_TYPE);
1293 <    yy_class = map_to_conf(yy_conf);
1294 <  }
1295 < } class_name_b '{' class_items '}' ';'
1204 >    reset_block_state();
1205 > } '{' class_items '}' ';'
1206   {
1207 <  if (conf_parser_ctx.pass == 1)
1298 <  {
1299 <    struct ConfItem *cconf = NULL;
1300 <    struct ClassItem *class = NULL;
1301 <
1302 <    if (yy_class_name == NULL)
1303 <      delete_conf_item(yy_conf);
1304 <    else
1305 <    {
1306 <      cconf = find_exact_name_conf(CLASS_TYPE, yy_class_name, NULL, NULL);
1307 <
1308 <      if (cconf != NULL)                /* The class existed already */
1309 <      {
1310 <        int user_count = 0;
1311 <
1312 <        rebuild_cidr_class(cconf, yy_class);
1207 >  struct ClassItem *class = NULL;
1208  
1209 <        class = map_to_conf(cconf);
1209 >  if (conf_parser_ctx.pass != 1)
1210 >    break;
1211  
1212 <        user_count = class->curr_user_count;
1213 <        memcpy(class, yy_class, sizeof(*class));
1214 <        class->curr_user_count = user_count;
1215 <        class->active = 1;
1216 <
1217 <        delete_conf_item(yy_conf);
1218 <
1219 <        MyFree(cconf->name);            /* Allows case change of class name */
1220 <        cconf->name = yy_class_name;
1221 <      }
1222 <      else      /* Brand new class */
1223 <      {
1224 <        MyFree(yy_conf->name);          /* just in case it was allocated */
1225 <        yy_conf->name = yy_class_name;
1226 <        yy_class->active = 1;
1227 <      }
1228 <    }
1229 <
1230 <    yy_class_name = NULL;
1231 <  }
1212 >  if (!block_state.class.buf[0])
1213 >    break;
1214 >
1215 >  if (!(class = class_find(block_state.class.buf, 0)))
1216 >    class = class_make();
1217 >
1218 >  class->active = 1;
1219 >  MyFree(class->name);
1220 >  class->name = xstrdup(block_state.class.buf);
1221 >  class->ping_freq = block_state.ping_freq.value;
1222 >  class->max_perip = block_state.max_perip.value;
1223 >  class->con_freq = block_state.con_freq.value;
1224 >  class->max_total = block_state.max_total.value;
1225 >  class->max_global = block_state.max_global.value;
1226 >  class->max_local = block_state.max_local.value;
1227 >  class->max_ident = block_state.max_ident.value;
1228 >  class->max_sendq = block_state.max_sendq.value;
1229 >  class->max_recvq = block_state.max_recvq.value;
1230 >
1231 >  if (class->number_per_cidr && block_state.number_per_cidr.value)
1232 >    if ((class->cidr_bitlen_ipv4 && block_state.cidr_bitlen_ipv4.value) ||
1233 >        (class->cidr_bitlen_ipv6 && block_state.cidr_bitlen_ipv6.value))
1234 >      if ((class->cidr_bitlen_ipv4 != block_state.cidr_bitlen_ipv4.value) ||
1235 >          (class->cidr_bitlen_ipv6 != block_state.cidr_bitlen_ipv6.value))
1236 >        rebuild_cidr_list(class);
1237 >
1238 >  class->cidr_bitlen_ipv4 = block_state.cidr_bitlen_ipv4.value;
1239 >  class->cidr_bitlen_ipv6 = block_state.cidr_bitlen_ipv6.value;
1240 >  class->number_per_cidr = block_state.number_per_cidr.value;
1241   };
1242  
1338 class_name_b: | class_name_t;
1339
1243   class_items:    class_items class_item | class_item;
1244   class_item:     class_name |
1245                  class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1246                  class_ping_time |
1344                class_ping_warning |
1247                  class_number_per_cidr |
1248                  class_number_per_ip |
1249                  class_connectfreq |
# Line 1349 | Line 1251 | class_item:     class_name |
1251                  class_max_global |
1252                  class_max_local |
1253                  class_max_ident |
1254 <                class_sendq |
1254 >                class_sendq | class_recvq |
1255                  error ';' ;
1256  
1257   class_name: NAME '=' QSTRING ';'
1258   {
1259    if (conf_parser_ctx.pass == 1)
1260 <  {
1359 <    MyFree(yy_class_name);
1360 <    DupString(yy_class_name, yylval.string);
1361 <  }
1362 < };
1363 <
1364 < class_name_t: QSTRING
1365 < {
1366 <  if (conf_parser_ctx.pass == 1)
1367 <  {
1368 <    MyFree(yy_class_name);
1369 <    DupString(yy_class_name, yylval.string);
1370 <  }
1260 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1261   };
1262  
1263   class_ping_time: PING_TIME '=' timespec ';'
1264   {
1265    if (conf_parser_ctx.pass == 1)
1266 <    PingFreq(yy_class) = $3;
1377 < };
1378 <
1379 < class_ping_warning: PING_WARNING '=' timespec ';'
1380 < {
1381 <  if (conf_parser_ctx.pass == 1)
1382 <    PingWarning(yy_class) = $3;
1266 >    block_state.ping_freq.value = $3;
1267   };
1268  
1269   class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1270   {
1271    if (conf_parser_ctx.pass == 1)
1272 <    MaxPerIp(yy_class) = $3;
1272 >    block_state.max_perip.value = $3;
1273   };
1274  
1275   class_connectfreq: CONNECTFREQ '=' timespec ';'
1276   {
1277    if (conf_parser_ctx.pass == 1)
1278 <    ConFreq(yy_class) = $3;
1278 >    block_state.con_freq.value = $3;
1279   };
1280  
1281   class_max_number: MAX_NUMBER '=' NUMBER ';'
1282   {
1283    if (conf_parser_ctx.pass == 1)
1284 <    MaxTotal(yy_class) = $3;
1284 >    block_state.max_total.value = $3;
1285   };
1286  
1287   class_max_global: MAX_GLOBAL '=' NUMBER ';'
1288   {
1289    if (conf_parser_ctx.pass == 1)
1290 <    MaxGlobal(yy_class) = $3;
1290 >    block_state.max_global.value = $3;
1291   };
1292  
1293   class_max_local: MAX_LOCAL '=' NUMBER ';'
1294   {
1295    if (conf_parser_ctx.pass == 1)
1296 <    MaxLocal(yy_class) = $3;
1296 >    block_state.max_local.value = $3;
1297   };
1298  
1299   class_max_ident: MAX_IDENT '=' NUMBER ';'
1300   {
1301    if (conf_parser_ctx.pass == 1)
1302 <    MaxIdent(yy_class) = $3;
1302 >    block_state.max_ident.value = $3;
1303   };
1304  
1305   class_sendq: SENDQ '=' sizespec ';'
1306   {
1307    if (conf_parser_ctx.pass == 1)
1308 <    MaxSendq(yy_class) = $3;
1308 >    block_state.max_sendq.value = $3;
1309 > };
1310 >
1311 > class_recvq: T_RECVQ '=' sizespec ';'
1312 > {
1313 >  if (conf_parser_ctx.pass == 1)
1314 >    if ($3 >= CLIENT_FLOOD_MIN && $3 <= CLIENT_FLOOD_MAX)
1315 >      block_state.max_recvq.value = $3;
1316   };
1317  
1318   class_cidr_bitlen_ipv4: CIDR_BITLEN_IPV4 '=' NUMBER ';'
1319   {
1320    if (conf_parser_ctx.pass == 1)
1321 <    CidrBitlenIPV4(yy_class) = $3;
1321 >    block_state.cidr_bitlen_ipv4.value = $3 > 32 ? 32 : $3;
1322   };
1323  
1324   class_cidr_bitlen_ipv6: CIDR_BITLEN_IPV6 '=' NUMBER ';'
1325   {
1326    if (conf_parser_ctx.pass == 1)
1327 <    CidrBitlenIPV6(yy_class) = $3;
1327 >    block_state.cidr_bitlen_ipv6.value = $3 > 128 ? 128 : $3;
1328   };
1329  
1330   class_number_per_cidr: NUMBER_PER_CIDR '=' NUMBER ';'
1331   {
1332    if (conf_parser_ctx.pass == 1)
1333 <    NumberPerCidr(yy_class) = $3;
1333 >    block_state.number_per_cidr.value = $3;
1334   };
1335  
1336   /***************************************************************************
# Line 1448 | Line 1339 | class_number_per_cidr: NUMBER_PER_CIDR '
1339   listen_entry: LISTEN
1340   {
1341    if (conf_parser_ctx.pass == 2)
1342 <  {
1343 <    listener_address = NULL;
1453 <    listener_flags = 0;
1454 <  }
1455 < } '{' listen_items '}' ';'
1456 < {
1457 <  if (conf_parser_ctx.pass == 2)
1458 <  {
1459 <    MyFree(listener_address);
1460 <    listener_address = NULL;
1461 <  }
1462 < };
1342 >    reset_block_state();
1343 > } '{' listen_items '}' ';';
1344  
1345   listen_flags: IRCD_FLAGS
1346   {
1347 <  listener_flags = 0;
1347 >  block_state.flags.value = 0;
1348   } '='  listen_flags_items ';';
1349  
1350   listen_flags_items: listen_flags_items ',' listen_flags_item | listen_flags_item;
1351   listen_flags_item: T_SSL
1352   {
1353    if (conf_parser_ctx.pass == 2)
1354 <    listener_flags |= LISTENER_SSL;
1354 >    block_state.flags.value |= LISTENER_SSL;
1355   } | HIDDEN
1356   {
1357    if (conf_parser_ctx.pass == 2)
1358 <    listener_flags |= LISTENER_HIDDEN;
1358 >    block_state.flags.value |= LISTENER_HIDDEN;
1359   } | T_SERVER
1360   {
1361    if (conf_parser_ctx.pass == 2)
1362 <    listener_flags |= LISTENER_SERVER;
1362 >   block_state.flags.value |= LISTENER_SERVER;
1363   };
1364  
1484
1485
1365   listen_items:   listen_items listen_item | listen_item;
1366   listen_item:    listen_port | listen_flags | listen_address | listen_host | error ';';
1367  
1368 < listen_port: PORT '=' port_items { listener_flags = 0; } ';';
1368 > listen_port: PORT '=' port_items { block_state.flags.value = 0; } ';';
1369  
1370   port_items: port_items ',' port_item | port_item;
1371  
# Line 1494 | Line 1373 | port_item: NUMBER
1373   {
1374    if (conf_parser_ctx.pass == 2)
1375    {
1376 <    if ((listener_flags & LISTENER_SSL))
1376 >    if (block_state.flags.value & LISTENER_SSL)
1377   #ifdef HAVE_LIBCRYPTO
1378        if (!ServerInfo.server_ctx)
1379   #endif
# Line 1502 | Line 1381 | port_item: NUMBER
1381          yyerror("SSL not available - port closed");
1382          break;
1383        }
1384 <    add_listener($1, listener_address, listener_flags);
1384 >    add_listener($1, block_state.addr.buf, block_state.flags.value);
1385    }
1386   } | NUMBER TWODOTS NUMBER
1387   {
# Line 1510 | Line 1389 | port_item: NUMBER
1389    {
1390      int i;
1391  
1392 <    if ((listener_flags & LISTENER_SSL))
1392 >    if (block_state.flags.value & LISTENER_SSL)
1393   #ifdef HAVE_LIBCRYPTO
1394        if (!ServerInfo.server_ctx)
1395   #endif
# Line 1520 | Line 1399 | port_item: NUMBER
1399        }
1400  
1401      for (i = $1; i <= $3; ++i)
1402 <      add_listener(i, listener_address, listener_flags);
1402 >      add_listener(i, block_state.addr.buf, block_state.flags.value);
1403    }
1404   };
1405  
1406   listen_address: IP '=' QSTRING ';'
1407   {
1408    if (conf_parser_ctx.pass == 2)
1409 <  {
1531 <    MyFree(listener_address);
1532 <    DupString(listener_address, yylval.string);
1533 <  }
1409 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1410   };
1411  
1412   listen_host: HOST '=' QSTRING ';'
1413   {
1414    if (conf_parser_ctx.pass == 2)
1415 <  {
1540 <    MyFree(listener_address);
1541 <    DupString(listener_address, yylval.string);
1542 <  }
1415 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1416   };
1417  
1418   /***************************************************************************
# Line 1548 | Line 1421 | listen_host: HOST '=' QSTRING ';'
1421   auth_entry: IRCD_AUTH
1422   {
1423    if (conf_parser_ctx.pass == 2)
1424 <  {
1552 <    yy_conf = make_conf_item(CLIENT_TYPE);
1553 <    yy_aconf = map_to_conf(yy_conf);
1554 <  }
1555 <  else
1556 <  {
1557 <    MyFree(class_name);
1558 <    class_name = NULL;
1559 <  }
1424 >    reset_block_state();
1425   } '{' auth_items '}' ';'
1426   {
1427 <  if (conf_parser_ctx.pass == 2)
1563 <  {
1564 <    struct CollectItem *yy_tmp = NULL;
1565 <    dlink_node *ptr = NULL, *next_ptr = NULL;
1566 <
1567 <    if (yy_aconf->user && yy_aconf->host)
1568 <    {
1569 <      conf_add_class_to_conf(yy_conf, class_name);
1570 <      add_conf_by_address(CONF_CLIENT, yy_aconf);
1571 <    }
1572 <    else
1573 <      delete_conf_item(yy_conf);
1574 <
1575 <    /* copy over settings from first struct */
1576 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1577 <    {
1578 <      struct AccessItem *new_aconf;
1579 <      struct ConfItem *new_conf;
1580 <
1581 <      new_conf = make_conf_item(CLIENT_TYPE);
1582 <      new_aconf = map_to_conf(new_conf);
1427 >  dlink_node *ptr = NULL;
1428  
1429 <      yy_tmp = ptr->data;
1429 >  if (conf_parser_ctx.pass != 2)
1430 >    break;
1431  
1432 <      assert(yy_tmp->user && yy_tmp->host);
1433 <
1434 <      if (yy_aconf->passwd != NULL)
1435 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1590 <      if (yy_conf->name != NULL)
1591 <        DupString(new_conf->name, yy_conf->name);
1592 <      if (yy_aconf->passwd != NULL)
1593 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1594 <
1595 <      new_aconf->flags = yy_aconf->flags;
1596 <      new_aconf->port  = yy_aconf->port;
1432 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1433 >  {
1434 >    struct MaskItem *conf = NULL;
1435 >    struct split_nuh_item nuh;
1436  
1437 <      DupString(new_aconf->user, yy_tmp->user);
1438 <      collapse(new_aconf->user);
1437 >    nuh.nuhmask  = ptr->data;
1438 >    nuh.nickptr  = NULL;
1439 >    nuh.userptr  = block_state.user.buf;
1440 >    nuh.hostptr  = block_state.host.buf;
1441 >    nuh.nicksize = 0;
1442 >    nuh.usersize = sizeof(block_state.user.buf);
1443 >    nuh.hostsize = sizeof(block_state.host.buf);
1444 >    split_nuh(&nuh);
1445  
1446 <      DupString(new_aconf->host, yy_tmp->host);
1447 <      collapse(new_aconf->host);
1446 >    conf        = conf_make(CONF_CLIENT);
1447 >    conf->user  = xstrdup(collapse(block_state.user.buf));
1448 >    conf->host  = xstrdup(collapse(block_state.host.buf));
1449 >
1450 >    if (block_state.rpass.buf[0])
1451 >      conf->passwd = xstrdup(block_state.rpass.buf);
1452 >    if (block_state.name.buf[0])
1453 >      conf->passwd = xstrdup(block_state.name.buf);
1454  
1455 <      conf_add_class_to_conf(new_conf, class_name);
1456 <      add_conf_by_address(CONF_CLIENT, new_aconf);
1606 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1607 <      free_collect_item(yy_tmp);
1608 <    }
1455 >    conf->flags = block_state.flags.value;
1456 >    conf->port  = block_state.port.value;
1457  
1458 <    MyFree(class_name);
1459 <    class_name = NULL;
1612 <    yy_conf = NULL;
1613 <    yy_aconf = NULL;
1458 >    conf_add_class_to_conf(conf, block_state.class.buf);
1459 >    add_conf_by_address(CONF_CLIENT, conf);
1460    }
1461   };
1462  
# Line 1622 | Line 1468 | auth_item:      auth_user | auth_passwd
1468   auth_user: USER '=' QSTRING ';'
1469   {
1470    if (conf_parser_ctx.pass == 2)
1471 <  {
1626 <    struct CollectItem *yy_tmp = NULL;
1627 <    struct split_nuh_item nuh;
1628 <
1629 <    nuh.nuhmask  = yylval.string;
1630 <    nuh.nickptr  = NULL;
1631 <    nuh.userptr  = userbuf;
1632 <    nuh.hostptr  = hostbuf;
1633 <
1634 <    nuh.nicksize = 0;
1635 <    nuh.usersize = sizeof(userbuf);
1636 <    nuh.hostsize = sizeof(hostbuf);
1637 <
1638 <    split_nuh(&nuh);
1639 <
1640 <    if (yy_aconf->user == NULL)
1641 <    {
1642 <      DupString(yy_aconf->user, userbuf);
1643 <      DupString(yy_aconf->host, hostbuf);
1644 <    }
1645 <    else
1646 <    {
1647 <      yy_tmp = MyMalloc(sizeof(struct CollectItem));
1648 <
1649 <      DupString(yy_tmp->user, userbuf);
1650 <      DupString(yy_tmp->host, hostbuf);
1651 <
1652 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1653 <    }
1654 <  }
1471 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1472   };
1473  
1657 /* XXX - IP/IPV6 tags don't exist anymore - put IP/IPV6 into user. */
1658
1474   auth_passwd: PASSWORD '=' QSTRING ';'
1475   {
1476    if (conf_parser_ctx.pass == 2)
1477 <  {
1663 <    /* be paranoid */
1664 <    if (yy_aconf->passwd != NULL)
1665 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1666 <
1667 <    MyFree(yy_aconf->passwd);
1668 <    DupString(yy_aconf->passwd, yylval.string);
1669 <  }
1477 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1478   };
1479  
1480   auth_class: CLASS '=' QSTRING ';'
1481   {
1482    if (conf_parser_ctx.pass == 2)
1483 <  {
1676 <    MyFree(class_name);
1677 <    DupString(class_name, yylval.string);
1678 <  }
1483 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1484   };
1485  
1486   auth_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 1683 | Line 1488 | auth_encrypted: ENCRYPTED '=' TBOOL ';'
1488    if (conf_parser_ctx.pass == 2)
1489    {
1490      if (yylval.number)
1491 <      SetConfEncrypted(yy_aconf);
1491 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1492      else
1493 <      ClearConfEncrypted(yy_aconf);
1493 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1494    }
1495   };
1496  
1497   auth_flags: IRCD_FLAGS
1498   {
1499 +  if (conf_parser_ctx.pass == 2)
1500 +    block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
1501   } '='  auth_flags_items ';';
1502  
1503   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
1504   auth_flags_item: SPOOF_NOTICE
1505   {
1506    if (conf_parser_ctx.pass == 2)
1507 <    yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1507 >    block_state.flags.value |= CONF_FLAGS_SPOOF_NOTICE;
1508   } | EXCEED_LIMIT
1509   {
1510    if (conf_parser_ctx.pass == 2)
1511 <    yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
1511 >    block_state.flags.value |= CONF_FLAGS_NOLIMIT;
1512   } | KLINE_EXEMPT
1513   {
1514    if (conf_parser_ctx.pass == 2)
1515 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
1515 >    block_state.flags.value |= CONF_FLAGS_EXEMPTKLINE;
1516   } | NEED_IDENT
1517   {
1518    if (conf_parser_ctx.pass == 2)
1519 <    yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
1519 >    block_state.flags.value |= CONF_FLAGS_NEED_IDENTD;
1520   } | CAN_FLOOD
1521   {
1522    if (conf_parser_ctx.pass == 2)
1523 <    yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
1523 >    block_state.flags.value |= CONF_FLAGS_CAN_FLOOD;
1524   } | NO_TILDE
1525   {
1526    if (conf_parser_ctx.pass == 2)
1527 <    yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
1527 >    block_state.flags.value |= CONF_FLAGS_NO_TILDE;
1528   } | GLINE_EXEMPT
1529   {
1530    if (conf_parser_ctx.pass == 2)
1531 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
1531 >    block_state.flags.value |= CONF_FLAGS_EXEMPTGLINE;
1532   } | RESV_EXEMPT
1533   {
1534    if (conf_parser_ctx.pass == 2)
1535 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTRESV;
1535 >    block_state.flags.value |= CONF_FLAGS_EXEMPTRESV;
1536   } | NEED_PASSWORD
1537   {
1538    if (conf_parser_ctx.pass == 2)
1539 <    yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
1539 >    block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1540   };
1541  
1735 /* XXX - need check for illegal hostnames here */
1542   auth_spoof: SPOOF '=' QSTRING ';'
1543   {
1544 <  if (conf_parser_ctx.pass == 2)
1545 <  {
1740 <    MyFree(yy_conf->name);
1544 >  if (conf_parser_ctx.pass != 2)
1545 >    break;
1546  
1547 <    if (strlen(yylval.string) < HOSTLEN)
1548 <    {    
1549 <      DupString(yy_conf->name, yylval.string);
1550 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_IP;
1746 <    }
1747 <    else
1748 <    {
1749 <      ilog(LOG_TYPE_IRCD, "Spoofs must be less than %d..ignoring it", HOSTLEN);
1750 <      yy_conf->name = NULL;
1751 <    }
1547 >  if (strlen(yylval.string) <= HOSTLEN && valid_hostname(yylval.string))
1548 >  {
1549 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1550 >    block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
1551    }
1552 +  else
1553 +    ilog(LOG_TYPE_IRCD, "Spoof either is too long or contains invalid characters. Ignoring it.");
1554   };
1555  
1556   auth_redir_serv: REDIRSERV '=' QSTRING ';'
1557   {
1558 <  if (conf_parser_ctx.pass == 2)
1559 <  {
1560 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1561 <    MyFree(yy_conf->name);
1562 <    DupString(yy_conf->name, yylval.string);
1762 <  }
1558 >  if (conf_parser_ctx.pass != 2)
1559 >    break;
1560 >
1561 >  strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1562 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1563   };
1564  
1565   auth_redir_port: REDIRPORT '=' NUMBER ';'
1566   {
1567 <  if (conf_parser_ctx.pass == 2)
1568 <  {
1569 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1570 <    yy_aconf->port = $3;
1571 <  }
1567 >  if (conf_parser_ctx.pass != 2)
1568 >    break;
1569 >
1570 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1571 >  block_state.port.value = $3;
1572   };
1573  
1574  
# Line 1777 | Line 1577 | auth_redir_port: REDIRPORT '=' NUMBER ';
1577   ***************************************************************************/
1578   resv_entry: RESV
1579   {
1580 <  if (conf_parser_ctx.pass == 2)
1581 <  {
1582 <    MyFree(resv_reason);
1583 <    resv_reason = NULL;
1584 <  }
1585 < } '{' resv_items '}' ';'
1786 < {
1787 <  if (conf_parser_ctx.pass == 2)
1788 <  {
1789 <    MyFree(resv_reason);
1790 <    resv_reason = NULL;
1791 <  }
1792 < };
1580 >  if (conf_parser_ctx.pass != 2)
1581 >    break;
1582 >
1583 >  reset_block_state();
1584 >  strlcpy(block_state.rpass.buf, CONF_NOREASON, sizeof(block_state.rpass.buf));
1585 > } '{' resv_items '}' ';';
1586  
1587   resv_items:     resv_items resv_item | resv_item;
1588   resv_item:      resv_creason | resv_channel | resv_nick | error ';' ;
# Line 1797 | Line 1590 | resv_item:     resv_creason | resv_channel |
1590   resv_creason: REASON '=' QSTRING ';'
1591   {
1592    if (conf_parser_ctx.pass == 2)
1593 <  {
1801 <    MyFree(resv_reason);
1802 <    DupString(resv_reason, yylval.string);
1803 <  }
1593 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1594   };
1595  
1596   resv_channel: CHANNEL '=' QSTRING ';'
1597   {
1598 <  if (conf_parser_ctx.pass == 2)
1599 <  {
1810 <    if (IsChanPrefix(*yylval.string))
1811 <    {
1812 <      char def_reason[] = "No reason";
1598 >  if (conf_parser_ctx.pass != 2)
1599 >    break;
1600  
1601 <      create_channel_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1602 <    }
1816 <  }
1817 <  /* ignore it for now.. but we really should make a warning if
1818 <   * its an erroneous name --fl_ */
1601 >  if (IsChanPrefix(*yylval.string))
1602 >    create_channel_resv(yylval.string, block_state.rpass.buf, 1);
1603   };
1604  
1605   resv_nick: NICK '=' QSTRING ';'
1606   {
1607    if (conf_parser_ctx.pass == 2)
1608 <  {
1825 <    char def_reason[] = "No reason";
1826 <
1827 <    create_nick_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1828 <  }
1608 >    create_nick_resv(yylval.string, block_state.rpass.buf, 1);
1609   };
1610  
1611   /***************************************************************************
# Line 1842 | Line 1622 | service_name: NAME '=' QSTRING ';'
1622    {
1623      if (valid_servname(yylval.string))
1624      {
1625 <      yy_conf = make_conf_item(SERVICE_TYPE);
1626 <      DupString(yy_conf->name, yylval.string);
1625 >      struct MaskItem *conf = conf_make(CONF_SERVICE);
1626 >      conf->name = xstrdup(yylval.string);
1627      }
1628    }
1629   };
# Line 1853 | Line 1633 | service_name: NAME '=' QSTRING ';'
1633   ***************************************************************************/
1634   shared_entry: T_SHARED
1635   {
1636 <  if (conf_parser_ctx.pass == 2)
1637 <  {
1638 <    yy_conf = make_conf_item(ULINE_TYPE);
1639 <    yy_match_item = map_to_conf(yy_conf);
1640 <    yy_match_item->action = SHARED_ALL;
1641 <  }
1636 >  if (conf_parser_ctx.pass != 2)
1637 >    break;
1638 >
1639 >  reset_block_state();
1640 >
1641 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1642 >  strlcpy(block_state.user.buf, "*", sizeof(block_state.user.buf));
1643 >  strlcpy(block_state.host.buf, "*", sizeof(block_state.host.buf));
1644 >  block_state.flags.value = SHARED_ALL;
1645   } '{' shared_items '}' ';'
1646   {
1647 <  if (conf_parser_ctx.pass == 2)
1648 <  {
1649 <    yy_conf = NULL;
1650 <  }
1647 >  struct MaskItem *conf = NULL;
1648 >
1649 >  if (conf_parser_ctx.pass != 2)
1650 >    break;
1651 >
1652 >  conf = conf_make(CONF_ULINE);
1653 >  conf->flags = block_state.flags.value;
1654 >  conf->name = xstrdup(block_state.name.buf);
1655 >  conf->user = xstrdup(block_state.user.buf);
1656 >  conf->user = xstrdup(block_state.host.buf);
1657   };
1658  
1659   shared_items: shared_items shared_item | shared_item;
# Line 1873 | Line 1662 | shared_item:  shared_name | shared_user
1662   shared_name: NAME '=' QSTRING ';'
1663   {
1664    if (conf_parser_ctx.pass == 2)
1665 <  {
1877 <    MyFree(yy_conf->name);
1878 <    DupString(yy_conf->name, yylval.string);
1879 <  }
1665 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1666   };
1667  
1668   shared_user: USER '=' QSTRING ';'
# Line 1887 | Line 1673 | shared_user: USER '=' QSTRING ';'
1673  
1674      nuh.nuhmask  = yylval.string;
1675      nuh.nickptr  = NULL;
1676 <    nuh.userptr  = userbuf;
1677 <    nuh.hostptr  = hostbuf;
1676 >    nuh.userptr  = block_state.user.buf;
1677 >    nuh.hostptr  = block_state.host.buf;
1678  
1679      nuh.nicksize = 0;
1680 <    nuh.usersize = sizeof(userbuf);
1681 <    nuh.hostsize = sizeof(hostbuf);
1680 >    nuh.usersize = sizeof(block_state.user.buf);
1681 >    nuh.hostsize = sizeof(block_state.host.buf);
1682  
1683      split_nuh(&nuh);
1898
1899    DupString(yy_match_item->user, userbuf);
1900    DupString(yy_match_item->host, hostbuf);
1684    }
1685   };
1686  
1687   shared_type: TYPE
1688   {
1689    if (conf_parser_ctx.pass == 2)
1690 <    yy_match_item->action = 0;
1690 >    block_state.flags.value = 0;
1691   } '=' shared_types ';' ;
1692  
1693   shared_types: shared_types ',' shared_type_item | shared_type_item;
1694   shared_type_item: KLINE
1695   {
1696    if (conf_parser_ctx.pass == 2)
1697 <    yy_match_item->action |= SHARED_KLINE;
1698 < } | TKLINE
1697 >    block_state.flags.value |= SHARED_KLINE;
1698 > } | UNKLINE
1699   {
1700    if (conf_parser_ctx.pass == 2)
1701 <    yy_match_item->action |= SHARED_TKLINE;
1702 < } | UNKLINE
1701 >    block_state.flags.value |= SHARED_UNKLINE;
1702 > } | T_DLINE
1703   {
1704    if (conf_parser_ctx.pass == 2)
1705 <    yy_match_item->action |= SHARED_UNKLINE;
1706 < } | XLINE
1705 >    block_state.flags.value |= SHARED_DLINE;
1706 > } | T_UNDLINE
1707   {
1708    if (conf_parser_ctx.pass == 2)
1709 <    yy_match_item->action |= SHARED_XLINE;
1710 < } | TXLINE
1709 >    block_state.flags.value |= SHARED_UNDLINE;
1710 > } | XLINE
1711   {
1712    if (conf_parser_ctx.pass == 2)
1713 <    yy_match_item->action |= SHARED_TXLINE;
1713 >    block_state.flags.value |= SHARED_XLINE;
1714   } | T_UNXLINE
1715   {
1716    if (conf_parser_ctx.pass == 2)
1717 <    yy_match_item->action |= SHARED_UNXLINE;
1717 >    block_state.flags.value |= SHARED_UNXLINE;
1718   } | RESV
1719   {
1720    if (conf_parser_ctx.pass == 2)
1721 <    yy_match_item->action |= SHARED_RESV;
1939 < } | TRESV
1940 < {
1941 <  if (conf_parser_ctx.pass == 2)
1942 <    yy_match_item->action |= SHARED_TRESV;
1721 >    block_state.flags.value |= SHARED_RESV;
1722   } | T_UNRESV
1723   {
1724    if (conf_parser_ctx.pass == 2)
1725 <    yy_match_item->action |= SHARED_UNRESV;
1725 >    block_state.flags.value |= SHARED_UNRESV;
1726   } | T_LOCOPS
1727   {
1728    if (conf_parser_ctx.pass == 2)
1729 <    yy_match_item->action |= SHARED_LOCOPS;
1729 >    block_state.flags.value |= SHARED_LOCOPS;
1730   } | T_ALL
1731   {
1732    if (conf_parser_ctx.pass == 2)
1733 <    yy_match_item->action = SHARED_ALL;
1733 >    block_state.flags.value = SHARED_ALL;
1734   };
1735  
1736   /***************************************************************************
# Line 1959 | Line 1738 | shared_type_item: KLINE
1738   ***************************************************************************/
1739   cluster_entry: T_CLUSTER
1740   {
1741 <  if (conf_parser_ctx.pass == 2)
1742 <  {
1743 <    yy_conf = make_conf_item(CLUSTER_TYPE);
1744 <    yy_conf->flags = SHARED_ALL;
1745 <  }
1741 >  if (conf_parser_ctx.pass != 2)
1742 >    break;
1743 >
1744 >  reset_block_state();
1745 >
1746 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1747 >  block_state.flags.value = SHARED_ALL;
1748   } '{' cluster_items '}' ';'
1749   {
1750 <  if (conf_parser_ctx.pass == 2)
1751 <  {
1752 <    if (yy_conf->name == NULL)
1753 <      DupString(yy_conf->name, "*");
1754 <    yy_conf = NULL;
1755 <  }
1750 >  struct MaskItem *conf = NULL;
1751 >
1752 >  if (conf_parser_ctx.pass != 2)
1753 >    break;
1754 >
1755 >  conf = conf_make(CONF_CLUSTER);
1756 >  conf->flags = block_state.flags.value;
1757 >  conf->name = xstrdup(block_state.name.buf);
1758   };
1759  
1760   cluster_items:  cluster_items cluster_item | cluster_item;
# Line 1980 | Line 1763 | cluster_item:  cluster_name | cluster_typ
1763   cluster_name: NAME '=' QSTRING ';'
1764   {
1765    if (conf_parser_ctx.pass == 2)
1766 <    DupString(yy_conf->name, yylval.string);
1766 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1767   };
1768  
1769   cluster_type: TYPE
1770   {
1771    if (conf_parser_ctx.pass == 2)
1772 <    yy_conf->flags = 0;
1772 >    block_state.flags.value = 0;
1773   } '=' cluster_types ';' ;
1774  
1775   cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
1776   cluster_type_item: KLINE
1777   {
1778    if (conf_parser_ctx.pass == 2)
1779 <    yy_conf->flags |= SHARED_KLINE;
1780 < } | TKLINE
1779 >    block_state.flags.value |= SHARED_KLINE;
1780 > } | UNKLINE
1781   {
1782    if (conf_parser_ctx.pass == 2)
1783 <    yy_conf->flags |= SHARED_TKLINE;
1784 < } | UNKLINE
1783 >    block_state.flags.value |= SHARED_UNKLINE;
1784 > } | T_DLINE
1785   {
1786    if (conf_parser_ctx.pass == 2)
1787 <    yy_conf->flags |= SHARED_UNKLINE;
1788 < } | XLINE
1787 >    block_state.flags.value |= SHARED_DLINE;
1788 > } | T_UNDLINE
1789   {
1790    if (conf_parser_ctx.pass == 2)
1791 <    yy_conf->flags |= SHARED_XLINE;
1792 < } | TXLINE
1791 >    block_state.flags.value |= SHARED_UNDLINE;
1792 > } | XLINE
1793   {
1794    if (conf_parser_ctx.pass == 2)
1795 <    yy_conf->flags |= SHARED_TXLINE;
1795 >    block_state.flags.value |= SHARED_XLINE;
1796   } | T_UNXLINE
1797   {
1798    if (conf_parser_ctx.pass == 2)
1799 <    yy_conf->flags |= SHARED_UNXLINE;
1799 >    block_state.flags.value |= SHARED_UNXLINE;
1800   } | RESV
1801   {
1802    if (conf_parser_ctx.pass == 2)
1803 <    yy_conf->flags |= SHARED_RESV;
2021 < } | TRESV
2022 < {
2023 <  if (conf_parser_ctx.pass == 2)
2024 <    yy_conf->flags |= SHARED_TRESV;
1803 >    block_state.flags.value |= SHARED_RESV;
1804   } | T_UNRESV
1805   {
1806    if (conf_parser_ctx.pass == 2)
1807 <    yy_conf->flags |= SHARED_UNRESV;
1807 >    block_state.flags.value |= SHARED_UNRESV;
1808   } | T_LOCOPS
1809   {
1810    if (conf_parser_ctx.pass == 2)
1811 <    yy_conf->flags |= SHARED_LOCOPS;
1811 >    block_state.flags.value |= SHARED_LOCOPS;
1812   } | T_ALL
1813   {
1814    if (conf_parser_ctx.pass == 2)
1815 <    yy_conf->flags = SHARED_ALL;
1815 >    block_state.flags.value = SHARED_ALL;
1816   };
1817  
1818   /***************************************************************************
# Line 2041 | Line 1820 | cluster_type_item: KLINE
1820   ***************************************************************************/
1821   connect_entry: CONNECT  
1822   {
2044  if (conf_parser_ctx.pass == 2)
2045  {
2046    yy_conf = make_conf_item(SERVER_TYPE);
2047    yy_aconf = (struct AccessItem *)map_to_conf(yy_conf);
2048    yy_aconf->passwd = NULL;
2049    /* defaults */
2050    yy_aconf->port = PORTNUM;
2051  }
2052  else
2053  {
2054    MyFree(class_name);
2055    class_name = NULL;
2056  }
2057 } connect_name_b '{' connect_items '}' ';'
2058 {
2059  if (conf_parser_ctx.pass == 2)
2060  {
2061    struct CollectItem *yy_hconf=NULL;
2062    struct CollectItem *yy_lconf=NULL;
2063    dlink_node *ptr;
2064    dlink_node *next_ptr;
2065 #ifdef HAVE_LIBCRYPTO
2066    if (yy_aconf->host &&
2067        ((yy_aconf->passwd && yy_aconf->spasswd) ||
2068         (yy_aconf->rsa_public_key && IsConfCryptLink(yy_aconf))))
2069 #else /* !HAVE_LIBCRYPTO */
2070      if (yy_aconf->host && !IsConfCryptLink(yy_aconf) &&
2071          yy_aconf->passwd && yy_aconf->spasswd)
2072 #endif /* !HAVE_LIBCRYPTO */
2073        {
2074          if (conf_add_server(yy_conf, class_name) == -1)
2075          {
2076            delete_conf_item(yy_conf);
2077            yy_conf = NULL;
2078            yy_aconf = NULL;
2079          }
2080        }
2081        else
2082        {
2083          /* Even if yy_conf ->name is NULL
2084           * should still unhook any hub/leaf confs still pending
2085           */
2086          unhook_hub_leaf_confs();
2087
2088          if (yy_conf->name != NULL)
2089          {
2090 #ifndef HAVE_LIBCRYPTO
2091            if (IsConfCryptLink(yy_aconf))
2092              yyerror("Ignoring connect block -- no OpenSSL support");
2093 #else
2094            if (IsConfCryptLink(yy_aconf) && !yy_aconf->rsa_public_key)
2095              yyerror("Ignoring connect block -- missing key");
2096 #endif
2097            if (yy_aconf->host == NULL)
2098              yyerror("Ignoring connect block -- missing host");
2099            else if (!IsConfCryptLink(yy_aconf) &&
2100                    (!yy_aconf->passwd || !yy_aconf->spasswd))
2101              yyerror("Ignoring connect block -- missing password");
2102          }
2103
2104
2105          /* XXX
2106           * This fixes a try_connections() core (caused by invalid class_ptr
2107           * pointers) reported by metalrock. That's an ugly fix, but there
2108           * is currently no better way. The entire config subsystem needs an
2109           * rewrite ASAP. make_conf_item() shouldn't really add things onto
2110           * a doubly linked list immediately without any sanity checks!  -Michael
2111           */
2112          delete_conf_item(yy_conf);
2113
2114          yy_aconf = NULL;
2115          yy_conf = NULL;
2116        }
2117
2118      /*
2119       * yy_conf is still pointing at the server that is having
2120       * a connect block built for it. This means, y_aconf->name
2121       * points to the actual irc name this server will be known as.
2122       * Now this new server has a set or even just one hub_mask (or leaf_mask)
2123       * given in the link list at yy_hconf. Fill in the HUB confs
2124       * from this link list now.
2125       */        
2126      DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
2127      {
2128        struct ConfItem *new_hub_conf;
2129        struct MatchItem *match_item;
1823  
1824 <        yy_hconf = ptr->data;
1824 >  if (conf_parser_ctx.pass != 2)
1825 >    break;
1826  
1827 <        /* yy_conf == NULL is a fatal error for this connect block! */
1828 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
1829 <        {
1830 <          new_hub_conf = make_conf_item(HUB_TYPE);
1831 <          match_item = (struct MatchItem *)map_to_conf(new_hub_conf);
1832 <          DupString(new_hub_conf->name, yy_conf->name);
1833 <          if (yy_hconf->user != NULL)
1834 <            DupString(match_item->user, yy_hconf->user);
1835 <          else
1836 <            DupString(match_item->user, "*");
1837 <          if (yy_hconf->host != NULL)
1838 <            DupString(match_item->host, yy_hconf->host);
1839 <          else
1840 <            DupString(match_item->host, "*");
1841 <        }
1842 <        dlinkDelete(&yy_hconf->node, &hub_conf_list);
1843 <        free_collect_item(yy_hconf);
1844 <      }
1827 >  reset_block_state();
1828 >  block_state.port.value = PORTNUM;
1829 > } '{' connect_items '}' ';'
1830 > {
1831 >  struct MaskItem *conf = NULL;
1832 >  struct addrinfo hints, *res;
1833 >
1834 >  if (conf_parser_ctx.pass != 2)
1835 >    break;
1836 >
1837 >  if (!block_state.name.buf[0] ||
1838 >      !block_state.host.buf[0])
1839 >    break;
1840 >
1841 >  if (!(block_state.rpass.buf[0] ||
1842 >        block_state.spass.buf[0]))
1843 >    break;
1844 >
1845 >  if (has_wildcards(block_state.name.buf) ||
1846 >      has_wildcards(block_state.host.buf))
1847 >    break;
1848 >
1849 >  conf = conf_make(CONF_SERVER);
1850 >  conf->port = block_state.port.value;
1851 >  conf->flags = block_state.flags.value;
1852 >  conf->aftype = block_state.aftype.value;
1853 >  conf->host = xstrdup(block_state.host.buf);
1854 >  conf->name = xstrdup(block_state.name.buf);
1855 >  conf->passwd = xstrdup(block_state.rpass.buf);
1856 >  conf->spasswd = xstrdup(block_state.spass.buf);
1857 >  conf->cipher_list = xstrdup(block_state.ciph.buf);
1858  
1859 <      /* Ditto for the LEAF confs */
1859 >  dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
1860 >  dlinkMoveList(&block_state.hub.list, &conf->hub_list);
1861  
1862 <      DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
1863 <      {
1864 <        struct ConfItem *new_leaf_conf;
1865 <        struct MatchItem *match_item;
1862 >  if (block_state.bind.buf[0])
1863 >  {
1864 >    memset(&hints, 0, sizeof(hints));
1865 >
1866 >    hints.ai_family   = AF_UNSPEC;
1867 >    hints.ai_socktype = SOCK_STREAM;
1868 >    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
1869  
1870 <        yy_lconf = ptr->data;
1870 >    if (getaddrinfo(block_state.bind.buf, NULL, &hints, &res))
1871 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
1872 >    else
1873 >    {
1874 >      assert(res != NULL);
1875  
1876 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
1877 <        {
1878 <          new_leaf_conf = make_conf_item(LEAF_TYPE);
1879 <          match_item = (struct MatchItem *)map_to_conf(new_leaf_conf);
1880 <          DupString(new_leaf_conf->name, yy_conf->name);
2166 <          if (yy_lconf->user != NULL)
2167 <            DupString(match_item->user, yy_lconf->user);
2168 <          else
2169 <            DupString(match_item->user, "*");
2170 <          if (yy_lconf->host != NULL)
2171 <            DupString(match_item->host, yy_lconf->host);
2172 <          else
2173 <            DupString(match_item->host, "*");
2174 <        }
2175 <        dlinkDelete(&yy_lconf->node, &leaf_conf_list);
2176 <        free_collect_item(yy_lconf);
2177 <      }
2178 <      MyFree(class_name);
2179 <      class_name = NULL;
2180 <      yy_conf = NULL;
2181 <      yy_aconf = NULL;
1876 >      memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
1877 >      conf->bind.ss.ss_family = res->ai_family;
1878 >      conf->bind.ss_len = res->ai_addrlen;
1879 >      freeaddrinfo(res);
1880 >    }
1881    }
1882 +
1883 +  conf_add_class_to_conf(conf, block_state.class.buf);
1884 +  lookup_confhost(conf);
1885   };
1886  
2185 connect_name_b: | connect_name_t;
1887   connect_items:  connect_items connect_item | connect_item;
1888   connect_item:   connect_name | connect_host | connect_vhost |
1889                  connect_send_password | connect_accept_password |
1890 <                connect_aftype | connect_port |
1890 >                connect_aftype | connect_port | connect_ssl_cipher_list |
1891                  connect_flags | connect_hub_mask | connect_leaf_mask |
1892 <                connect_class | connect_encrypted |
2192 <                connect_rsa_public_key_file | connect_cipher_preference |
1892 >                connect_class | connect_encrypted |
1893                  error ';' ;
1894  
1895   connect_name: NAME '=' QSTRING ';'
1896   {
1897    if (conf_parser_ctx.pass == 2)
1898 <  {
2199 <    if (yy_conf->name != NULL)
2200 <      yyerror("Multiple connect name entry");
2201 <
2202 <    MyFree(yy_conf->name);
2203 <    DupString(yy_conf->name, yylval.string);
2204 <  }
2205 < };
2206 <
2207 < connect_name_t: QSTRING
2208 < {
2209 <  if (conf_parser_ctx.pass == 2)
2210 <  {
2211 <    if (yy_conf->name != NULL)
2212 <      yyerror("Multiple connect name entry");
2213 <
2214 <    MyFree(yy_conf->name);
2215 <    DupString(yy_conf->name, yylval.string);
2216 <  }
1898 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1899   };
1900  
1901   connect_host: HOST '=' QSTRING ';'
1902   {
1903    if (conf_parser_ctx.pass == 2)
1904 <  {
2223 <    MyFree(yy_aconf->host);
2224 <    DupString(yy_aconf->host, yylval.string);
2225 <  }
1904 >    strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
1905   };
1906  
1907   connect_vhost: VHOST '=' QSTRING ';'
1908   {
1909    if (conf_parser_ctx.pass == 2)
1910 <  {
2232 <    struct addrinfo hints, *res;
2233 <
2234 <    memset(&hints, 0, sizeof(hints));
2235 <
2236 <    hints.ai_family   = AF_UNSPEC;
2237 <    hints.ai_socktype = SOCK_STREAM;
2238 <    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2239 <
2240 <    if (getaddrinfo(yylval.string, NULL, &hints, &res))
2241 <      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
2242 <    else
2243 <    {
2244 <      assert(res != NULL);
2245 <
2246 <      memcpy(&yy_aconf->my_ipnum, res->ai_addr, res->ai_addrlen);
2247 <      yy_aconf->my_ipnum.ss.ss_family = res->ai_family;
2248 <      yy_aconf->my_ipnum.ss_len = res->ai_addrlen;
2249 <      freeaddrinfo(res);
2250 <    }
2251 <  }
1910 >    strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
1911   };
1912  
1913   connect_send_password: SEND_PASSWORD '=' QSTRING ';'
1914   {
1915 <  if (conf_parser_ctx.pass == 2)
1916 <  {
2258 <    if ($3[0] == ':')
2259 <      yyerror("Server passwords cannot begin with a colon");
2260 <    else if (strchr($3, ' ') != NULL)
2261 <      yyerror("Server passwords cannot contain spaces");
2262 <    else {
2263 <      if (yy_aconf->spasswd != NULL)
2264 <        memset(yy_aconf->spasswd, 0, strlen(yy_aconf->spasswd));
1915 >  if (conf_parser_ctx.pass != 2)
1916 >    break;
1917  
1918 <      MyFree(yy_aconf->spasswd);
1919 <      DupString(yy_aconf->spasswd, yylval.string);
1920 <    }
1921 <  }
1918 >  if ($3[0] == ':')
1919 >    yyerror("Server passwords cannot begin with a colon");
1920 >  else if (strchr($3, ' ') != NULL)
1921 >    yyerror("Server passwords cannot contain spaces");
1922 >  else
1923 >    strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
1924   };
1925  
1926   connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
1927   {
1928 <  if (conf_parser_ctx.pass == 2)
1929 <  {
2276 <    if ($3[0] == ':')
2277 <      yyerror("Server passwords cannot begin with a colon");
2278 <    else if (strchr($3, ' ') != NULL)
2279 <      yyerror("Server passwords cannot contain spaces");
2280 <    else {
2281 <      if (yy_aconf->passwd != NULL)
2282 <        memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1928 >  if (conf_parser_ctx.pass != 2)
1929 >    break;
1930  
1931 <      MyFree(yy_aconf->passwd);
1932 <      DupString(yy_aconf->passwd, yylval.string);
1933 <    }
1934 <  }
1931 >  if ($3[0] == ':')
1932 >    yyerror("Server passwords cannot begin with a colon");
1933 >  else if (strchr($3, ' ') != NULL)
1934 >    yyerror("Server passwords cannot contain spaces");
1935 >  else
1936 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1937   };
1938  
1939   connect_port: PORT '=' NUMBER ';'
1940   {
1941    if (conf_parser_ctx.pass == 2)
1942 <    yy_aconf->port = $3;
1942 >    block_state.port.value = $3;
1943   };
1944  
1945   connect_aftype: AFTYPE '=' T_IPV4 ';'
1946   {
1947    if (conf_parser_ctx.pass == 2)
1948 <    yy_aconf->aftype = AF_INET;
1948 >    block_state.aftype.value = AF_INET;
1949   } | AFTYPE '=' T_IPV6 ';'
1950   {
1951   #ifdef IPV6
1952    if (conf_parser_ctx.pass == 2)
1953 <    yy_aconf->aftype = AF_INET6;
1953 >    block_state.aftype.value = AF_INET6;
1954   #endif
1955   };
1956  
1957   connect_flags: IRCD_FLAGS
1958   {
1959 +  block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
1960   } '='  connect_flags_items ';';
1961  
1962   connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
1963 < connect_flags_item: COMPRESSED
1963 > connect_flags_item: AUTOCONN
1964   {
1965    if (conf_parser_ctx.pass == 2)
1966 < #ifndef HAVE_LIBZ
1967 <    yyerror("Ignoring flags = compressed; -- no zlib support");
2318 < #else
2319 < {
2320 <   SetConfCompressed(yy_aconf);
2321 < }
2322 < #endif
2323 < } | CRYPTLINK
1966 >    block_state.flags.value |= CONF_FLAGS_ALLOW_AUTO_CONN;
1967 > } | T_SSL
1968   {
1969    if (conf_parser_ctx.pass == 2)
1970 <    SetConfCryptLink(yy_aconf);
2327 < } | AUTOCONN
2328 < {
2329 <  if (conf_parser_ctx.pass == 2)
2330 <    SetConfAllowAutoConn(yy_aconf);
2331 < } | BURST_AWAY
2332 < {
2333 <  if (conf_parser_ctx.pass == 2)
2334 <    SetConfAwayBurst(yy_aconf);
2335 < } | TOPICBURST
2336 < {
2337 <  if (conf_parser_ctx.pass == 2)
2338 <    SetConfTopicBurst(yy_aconf);
2339 < };
2340 <
2341 < connect_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
2342 < {
2343 < #ifdef HAVE_LIBCRYPTO
2344 <  if (conf_parser_ctx.pass == 2)
2345 <  {
2346 <    BIO *file;
2347 <
2348 <    if (yy_aconf->rsa_public_key != NULL)
2349 <    {
2350 <      RSA_free(yy_aconf->rsa_public_key);
2351 <      yy_aconf->rsa_public_key = NULL;
2352 <    }
2353 <
2354 <    if (yy_aconf->rsa_public_key_file != NULL)
2355 <    {
2356 <      MyFree(yy_aconf->rsa_public_key_file);
2357 <      yy_aconf->rsa_public_key_file = NULL;
2358 <    }
2359 <
2360 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
2361 <
2362 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
2363 <    {
2364 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
2365 <      break;
2366 <    }
2367 <
2368 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
2369 <
2370 <    if (yy_aconf->rsa_public_key == NULL)
2371 <    {
2372 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
2373 <      break;
2374 <    }
2375 <      
2376 <    BIO_set_close(file, BIO_CLOSE);
2377 <    BIO_free(file);
2378 <  }
2379 < #endif /* HAVE_LIBCRYPTO */
1970 >    block_state.flags.value |= CONF_FLAGS_SSL;
1971   };
1972  
1973   connect_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 2384 | Line 1975 | connect_encrypted: ENCRYPTED '=' TBOOL '
1975    if (conf_parser_ctx.pass == 2)
1976    {
1977      if (yylval.number)
1978 <      yy_aconf->flags |= CONF_FLAGS_ENCRYPTED;
1978 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1979      else
1980 <      yy_aconf->flags &= ~CONF_FLAGS_ENCRYPTED;
1980 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1981    }
1982   };
1983  
1984   connect_hub_mask: HUB_MASK '=' QSTRING ';'
1985   {
1986    if (conf_parser_ctx.pass == 2)
1987 <  {
2397 <    struct CollectItem *yy_tmp;
2398 <
2399 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2400 <    DupString(yy_tmp->host, yylval.string);
2401 <    DupString(yy_tmp->user, "*");
2402 <    dlinkAdd(yy_tmp, &yy_tmp->node, &hub_conf_list);
2403 <  }
1987 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
1988   };
1989  
1990   connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
1991   {
1992    if (conf_parser_ctx.pass == 2)
1993 <  {
2410 <    struct CollectItem *yy_tmp;
2411 <
2412 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2413 <    DupString(yy_tmp->host, yylval.string);
2414 <    DupString(yy_tmp->user, "*");
2415 <    dlinkAdd(yy_tmp, &yy_tmp->node, &leaf_conf_list);
2416 <  }
1993 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
1994   };
1995  
1996   connect_class: CLASS '=' QSTRING ';'
1997   {
1998    if (conf_parser_ctx.pass == 2)
1999 <  {
2423 <    MyFree(class_name);
2424 <    DupString(class_name, yylval.string);
2425 <  }
1999 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
2000   };
2001  
2002 < connect_cipher_preference: CIPHER_PREFERENCE '=' QSTRING ';'
2002 > connect_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
2003   {
2004   #ifdef HAVE_LIBCRYPTO
2005    if (conf_parser_ctx.pass == 2)
2006 <  {
2433 <    struct EncCapability *ecap;
2434 <    const char *cipher_name;
2435 <    int found = 0;
2436 <
2437 <    yy_aconf->cipher_preference = NULL;
2438 <    cipher_name = yylval.string;
2439 <
2440 <    for (ecap = CipherTable; ecap->name; ecap++)
2441 <    {
2442 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
2443 <          (ecap->cap & CAP_ENC_MASK))
2444 <      {
2445 <        yy_aconf->cipher_preference = ecap;
2446 <        found = 1;
2447 <        break;
2448 <      }
2449 <    }
2450 <
2451 <    if (!found)
2452 <      yyerror("Invalid cipher");
2453 <  }
2006 >    strlcpy(block_state.ciph.buf, yylval.string, sizeof(block_state.ciph.buf));
2007   #else
2008    if (conf_parser_ctx.pass == 2)
2009 <    yyerror("Ignoring cipher_preference -- no OpenSSL support");
2009 >    yyerror("Ignoring connect::ciphers -- no OpenSSL support");
2010   #endif
2011   };
2012  
2013 +
2014   /***************************************************************************
2015   *  section kill
2016   ***************************************************************************/
2017   kill_entry: KILL
2018   {
2019    if (conf_parser_ctx.pass == 2)
2020 <  {
2467 <    userbuf[0] = hostbuf[0] = reasonbuf[0] = '\0';
2468 <    regex_ban = 0;
2469 <  }
2020 >    reset_block_state();
2021   } '{' kill_items '}' ';'
2022   {
2023 <  if (conf_parser_ctx.pass == 2)
2023 >  struct MaskItem *conf = NULL;
2024 >
2025 >  if (conf_parser_ctx.pass != 2)
2026 >    break;
2027 >
2028 >  if (!block_state.user.buf[0] ||
2029 >      !block_state.host.buf[0])
2030 >    break;
2031 >
2032 >
2033 >  if (block_state.port.value == 1)
2034    {
2474    if (userbuf[0] && hostbuf[0])
2475    {
2476      if (regex_ban)
2477      {
2035   #ifdef HAVE_LIBPCRE
2036 <        void *exp_user = NULL;
2037 <        void *exp_host = NULL;
2038 <        const char *errptr = NULL;
2039 <
2040 <        if (!(exp_user = ircd_pcre_compile(userbuf, &errptr)) ||
2041 <            !(exp_host = ircd_pcre_compile(hostbuf, &errptr)))
2042 <        {
2043 <          ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: %s",
2044 <               errptr);
2045 <          break;
2046 <        }
2490 <
2491 <        yy_aconf = map_to_conf(make_conf_item(RKLINE_TYPE));
2492 <        yy_aconf->regexuser = exp_user;
2493 <        yy_aconf->regexhost = exp_host;
2036 >    void *exp_user = NULL;
2037 >    void *exp_host = NULL;
2038 >    const char *errptr = NULL;
2039 >
2040 >    if (!(exp_user = ircd_pcre_compile(block_state.user.buf, &errptr)) ||
2041 >        !(exp_host = ircd_pcre_compile(block_state.host.buf, &errptr)))
2042 >    {
2043 >      ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: %s",
2044 >           errptr);
2045 >      break;
2046 >    }
2047  
2048 <        DupString(yy_aconf->user, userbuf);
2049 <        DupString(yy_aconf->host, hostbuf);
2048 >    conf = conf_make(CONF_RKLINE);
2049 >    conf->regexuser = exp_user;
2050 >    conf->regexhost = exp_host;
2051  
2052 <        if (reasonbuf[0])
2053 <          DupString(yy_aconf->reason, reasonbuf);
2054 <        else
2055 <          DupString(yy_aconf->reason, "No reason");
2052 >    conf->user = xstrdup(block_state.user.buf);
2053 >    conf->host = xstrdup(block_state.host.buf);
2054 >
2055 >    if (block_state.rpass.buf[0])
2056 >      conf->reason = xstrdup(block_state.rpass.buf);
2057 >    else
2058 >      conf->reason = xstrdup(CONF_NOREASON);
2059   #else
2060 <        ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: no PCRE support");
2061 <        break;
2060 >    ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: no PCRE support");
2061 >    break;
2062   #endif
2063 <      }
2064 <      else
2065 <      {
2066 <        yy_aconf = map_to_conf(make_conf_item(KLINE_TYPE));
2510 <
2511 <        DupString(yy_aconf->user, userbuf);
2512 <        DupString(yy_aconf->host, hostbuf);
2063 >  }
2064 >  else
2065 >  {
2066 >    conf = conf_make(CONF_KLINE);
2067  
2068 <        if (reasonbuf[0])
2069 <          DupString(yy_aconf->reason, reasonbuf);
2516 <        else
2517 <          DupString(yy_aconf->reason, "No reason");
2518 <        add_conf_by_address(CONF_KILL, yy_aconf);
2519 <      }
2520 <    }
2068 >    conf->user = xstrdup(block_state.user.buf);
2069 >    conf->host = xstrdup(block_state.host.buf);
2070  
2071 <    yy_aconf = NULL;
2071 >    if (block_state.rpass.buf[0])
2072 >      conf->reason = xstrdup(block_state.rpass.buf);
2073 >    else
2074 >      conf->reason = xstrdup(CONF_NOREASON);
2075 >    add_conf_by_address(CONF_KLINE, conf);
2076    }
2077   };
2078  
2079   kill_type: TYPE
2080   {
2081 +  if (conf_parser_ctx.pass == 2)
2082 +    block_state.port.value = 0;
2083   } '='  kill_type_items ';';
2084  
2085   kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2086   kill_type_item: REGEX_T
2087   {
2088    if (conf_parser_ctx.pass == 2)
2089 <    regex_ban = 1;
2089 >    block_state.port.value = 1;
2090   };
2091  
2092   kill_items:     kill_items kill_item | kill_item;
# Line 2539 | Line 2094 | kill_item:      kill_user | kill_reason
2094  
2095   kill_user: USER '=' QSTRING ';'
2096   {
2097 +
2098    if (conf_parser_ctx.pass == 2)
2099    {
2100      struct split_nuh_item nuh;
2101  
2102      nuh.nuhmask  = yylval.string;
2103      nuh.nickptr  = NULL;
2104 <    nuh.userptr  = userbuf;
2105 <    nuh.hostptr  = hostbuf;
2104 >    nuh.userptr  = block_state.user.buf;
2105 >    nuh.hostptr  = block_state.host.buf;
2106  
2107      nuh.nicksize = 0;
2108 <    nuh.usersize = sizeof(userbuf);
2109 <    nuh.hostsize = sizeof(hostbuf);
2108 >    nuh.usersize = sizeof(block_state.user.buf);
2109 >    nuh.hostsize = sizeof(block_state.host.buf);
2110  
2111      split_nuh(&nuh);
2112    }
# Line 2559 | Line 2115 | kill_user: USER '=' QSTRING ';'
2115   kill_reason: REASON '=' QSTRING ';'
2116   {
2117    if (conf_parser_ctx.pass == 2)
2118 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2118 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2119   };
2120  
2121   /***************************************************************************
# Line 2568 | Line 2124 | kill_reason: REASON '=' QSTRING ';'
2124   deny_entry: DENY
2125   {
2126    if (conf_parser_ctx.pass == 2)
2127 <    hostbuf[0] = reasonbuf[0] = '\0';
2127 >    reset_block_state();
2128   } '{' deny_items '}' ';'
2129   {
2130 <  if (conf_parser_ctx.pass == 2)
2130 >  struct MaskItem *conf = NULL;
2131 >
2132 >  if (conf_parser_ctx.pass != 2)
2133 >    break;
2134 >
2135 >  if (!block_state.addr.buf[0])
2136 >    break;
2137 >
2138 >  if (parse_netmask(block_state.addr.buf, NULL, NULL) != HM_HOST)
2139    {
2140 <    if (hostbuf[0] && parse_netmask(hostbuf, NULL, NULL) != HM_HOST)
2141 <    {
2578 <      yy_aconf = map_to_conf(make_conf_item(DLINE_TYPE));
2579 <      DupString(yy_aconf->host, hostbuf);
2140 >    conf = conf_make(CONF_DLINE);
2141 >    conf->host = xstrdup(block_state.addr.buf);
2142  
2143 <      if (reasonbuf[0])
2144 <        DupString(yy_aconf->reason, reasonbuf);
2145 <      else
2146 <        DupString(yy_aconf->reason, "No reason");
2147 <      add_conf_by_address(CONF_DLINE, yy_aconf);
2586 <      yy_aconf = NULL;
2587 <    }
2143 >    if (block_state.rpass.buf[0])
2144 >      conf->reason = xstrdup(block_state.rpass.buf);
2145 >    else
2146 >      conf->reason = xstrdup(CONF_NOREASON);
2147 >    add_conf_by_address(CONF_DLINE, conf);
2148    }
2149   };
2150  
# Line 2594 | Line 2154 | deny_item:      deny_ip | deny_reason |
2154   deny_ip: IP '=' QSTRING ';'
2155   {
2156    if (conf_parser_ctx.pass == 2)
2157 <    strlcpy(hostbuf, yylval.string, sizeof(hostbuf));
2157 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2158   };
2159  
2160   deny_reason: REASON '=' QSTRING ';'
2161   {
2162    if (conf_parser_ctx.pass == 2)
2163 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2163 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2164   };
2165  
2166   /***************************************************************************
# Line 2617 | Line 2177 | exempt_ip: IP '=' QSTRING ';'
2177    {
2178      if (yylval.string[0] && parse_netmask(yylval.string, NULL, NULL) != HM_HOST)
2179      {
2180 <      yy_aconf = map_to_conf(make_conf_item(EXEMPTDLINE_TYPE));
2181 <      DupString(yy_aconf->host, yylval.string);
2180 >      struct MaskItem *conf = conf_make(CONF_EXEMPT);
2181 >      conf->host = xstrdup(yylval.string);
2182  
2183 <      add_conf_by_address(CONF_EXEMPTDLINE, yy_aconf);
2624 <      yy_aconf = NULL;
2183 >      add_conf_by_address(CONF_EXEMPT, conf);
2184      }
2185    }
2186   };
# Line 2632 | Line 2191 | exempt_ip: IP '=' QSTRING ';'
2191   gecos_entry: GECOS
2192   {
2193    if (conf_parser_ctx.pass == 2)
2194 <  {
2636 <    regex_ban = 0;
2637 <    reasonbuf[0] = gecos_name[0] = '\0';
2638 <  }
2194 >    reset_block_state();
2195   } '{' gecos_items '}' ';'
2196   {
2197 <  if (conf_parser_ctx.pass == 2)
2197 >  struct MaskItem *conf = NULL;
2198 >
2199 >  if (conf_parser_ctx.pass != 2)
2200 >    break;
2201 >
2202 >  if (!block_state.name.buf[0])
2203 >    break;
2204 >
2205 >  if (block_state.port.value == 1)
2206    {
2643    if (gecos_name[0])
2644    {
2645      if (regex_ban)
2646      {
2207   #ifdef HAVE_LIBPCRE
2208 <        void *exp_p = NULL;
2209 <        const char *errptr = NULL;
2208 >    void *exp_p = NULL;
2209 >    const char *errptr = NULL;
2210  
2211 <        if (!(exp_p = ircd_pcre_compile(gecos_name, &errptr)))
2212 <        {
2213 <          ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: %s",
2214 <               errptr);
2215 <          break;
2216 <        }
2211 >    if (!(exp_p = ircd_pcre_compile(block_state.name.buf, &errptr)))
2212 >    {
2213 >      ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: %s",
2214 >           errptr);
2215 >      break;
2216 >    }
2217  
2218 <        yy_conf = make_conf_item(RXLINE_TYPE);
2219 <        yy_conf->regexpname = exp_p;
2218 >    conf = conf_make(CONF_RXLINE);
2219 >    conf->regexuser = exp_p;
2220   #else
2221 <        ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: no PCRE support");
2222 <        break;
2221 >    ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: no PCRE support");
2222 >    break;
2223   #endif
2224 <      }
2225 <      else
2226 <        yy_conf = make_conf_item(XLINE_TYPE);
2224 >  }
2225 >  else
2226 >    conf = conf_make(CONF_XLINE);
2227  
2228 <      yy_match_item = map_to_conf(yy_conf);
2669 <      DupString(yy_conf->name, gecos_name);
2228 >  conf->name = xstrdup(block_state.name.buf);
2229  
2230 <      if (reasonbuf[0])
2231 <        DupString(yy_match_item->reason, reasonbuf);
2232 <      else
2233 <        DupString(yy_match_item->reason, "No reason");
2675 <    }
2676 <  }
2230 >  if (block_state.rpass.buf[0])
2231 >    conf->reason = xstrdup(block_state.rpass.buf);
2232 >  else
2233 >    conf->reason = xstrdup(CONF_NOREASON);
2234   };
2235  
2236   gecos_flags: TYPE
2237   {
2238 +  if (conf_parser_ctx.pass == 2)
2239 +    block_state.port.value = 0;
2240   } '='  gecos_flags_items ';';
2241  
2242   gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2243   gecos_flags_item: REGEX_T
2244   {
2245    if (conf_parser_ctx.pass == 2)
2246 <    regex_ban = 1;
2246 >    block_state.port.value = 1;
2247   };
2248  
2249   gecos_items: gecos_items gecos_item | gecos_item;
# Line 2693 | Line 2252 | gecos_item:  gecos_name | gecos_reason |
2252   gecos_name: NAME '=' QSTRING ';'
2253   {
2254    if (conf_parser_ctx.pass == 2)
2255 <    strlcpy(gecos_name, yylval.string, sizeof(gecos_name));
2255 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2256   };
2257  
2258   gecos_reason: REASON '=' QSTRING ';'
2259   {
2260    if (conf_parser_ctx.pass == 2)
2261 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2261 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2262   };
2263  
2264   /***************************************************************************
# Line 2714 | Line 2273 | general_item:       general_hide_spoof_i
2273                      general_max_nick_time | general_max_nick_changes |
2274                      general_max_accept | general_anti_spam_exit_message_time |
2275                      general_ts_warn_delta | general_ts_max_delta |
2276 <                    general_kill_chase_time_limit | general_kline_with_reason |
2277 <                    general_kline_reason | general_invisible_on_connect |
2276 >                    general_kill_chase_time_limit |
2277 >                    general_invisible_on_connect |
2278                      general_warn_no_nline | general_dots_in_ident |
2279                      general_stats_o_oper_only | general_stats_k_oper_only |
2280                      general_pace_wait | general_stats_i_oper_only |
# Line 2728 | Line 2287 | general_item:       general_hide_spoof_i
2287                      general_oper_umodes | general_caller_id_wait |
2288                      general_opers_bypass_callerid | general_default_floodcount |
2289                      general_min_nonwildcard | general_min_nonwildcard_simple |
2290 <                    general_servlink_path | general_disable_remote_commands |
2732 <                    general_default_cipher_preference |
2733 <                    general_compression_level | general_client_flood |
2290 >                    general_disable_remote_commands |
2291                      general_throttle_time | general_havent_read_conf |
2292                      general_ping_cookie |
2293                      general_disable_auth |
2294 <                    general_tkline_expire_notices | general_gline_min_cidr |
2295 <                    general_gline_min_cidr6 | general_use_whois_actually |
2296 <                    general_reject_hold_time | general_stats_e_disabled |
2294 >                    general_tkline_expire_notices | general_gline_enable |
2295 >                    general_gline_duration | general_gline_request_duration |
2296 >                    general_gline_min_cidr |
2297 >                    general_gline_min_cidr6 |
2298 >                    general_stats_e_disabled |
2299                      general_max_watch | general_services_name |
2300                      error;
2301  
# Line 2746 | Line 2305 | general_max_watch: MAX_WATCH '=' NUMBER
2305    ConfigFileEntry.max_watch = $3;
2306   };
2307  
2308 < general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2308 > general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2309   {
2310 <  ConfigFileEntry.gline_min_cidr = $3;
2310 >  if (conf_parser_ctx.pass == 2)
2311 >    ConfigFileEntry.glines = yylval.number;
2312   };
2313  
2314 < general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2314 > general_gline_duration: GLINE_DURATION '=' timespec ';'
2315   {
2316 <  ConfigFileEntry.gline_min_cidr6 = $3;
2316 >  if (conf_parser_ctx.pass == 2)
2317 >    ConfigFileEntry.gline_time = $3;
2318   };
2319  
2320 < general_use_whois_actually: USE_WHOIS_ACTUALLY '=' TBOOL ';'
2320 > general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2321   {
2322 <  ConfigFileEntry.use_whois_actually = yylval.number;
2322 >  if (conf_parser_ctx.pass == 2)
2323 >    ConfigFileEntry.gline_request_time = $3;
2324   };
2325  
2326 < general_reject_hold_time: TREJECT_HOLD_TIME '=' timespec ';'
2326 > general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2327   {
2328 <  GlobalSetOptions.rejecttime = yylval.number;
2328 >  ConfigFileEntry.gline_min_cidr = $3;
2329 > };
2330 >
2331 > general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2332 > {
2333 >  ConfigFileEntry.gline_min_cidr6 = $3;
2334   };
2335  
2336   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
# Line 2843 | Line 2410 | general_havent_read_conf: HAVENT_READ_CO
2410    }
2411   };
2412  
2846 general_kline_with_reason: KLINE_WITH_REASON '=' TBOOL ';'
2847 {
2848  ConfigFileEntry.kline_with_reason = yylval.number;
2849 };
2850
2851 general_kline_reason: KLINE_REASON '=' QSTRING ';'
2852 {
2853  if (conf_parser_ctx.pass == 2)
2854  {
2855    MyFree(ConfigFileEntry.kline_reason);
2856    DupString(ConfigFileEntry.kline_reason, yylval.string);
2857  }
2858 };
2859
2413   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2414   {
2415    ConfigFileEntry.invisible_on_connect = yylval.number;
# Line 2959 | Line 2512 | general_max_targets: MAX_TARGETS '=' NUM
2512    ConfigFileEntry.max_targets = $3;
2513   };
2514  
2962 general_servlink_path: SERVLINK_PATH '=' QSTRING ';'
2963 {
2964  if (conf_parser_ctx.pass == 2)
2965  {
2966    MyFree(ConfigFileEntry.servlink_path);
2967    DupString(ConfigFileEntry.servlink_path, yylval.string);
2968  }
2969 };
2970
2971 general_default_cipher_preference: DEFAULT_CIPHER_PREFERENCE '=' QSTRING ';'
2972 {
2973 #ifdef HAVE_LIBCRYPTO
2974  if (conf_parser_ctx.pass == 2)
2975  {
2976    struct EncCapability *ecap;
2977    const char *cipher_name;
2978    int found = 0;
2979
2980    ConfigFileEntry.default_cipher_preference = NULL;
2981    cipher_name = yylval.string;
2982
2983    for (ecap = CipherTable; ecap->name; ecap++)
2984    {
2985      if ((irccmp(ecap->name, cipher_name) == 0) &&
2986          (ecap->cap & CAP_ENC_MASK))
2987      {
2988        ConfigFileEntry.default_cipher_preference = ecap;
2989        found = 1;
2990        break;
2991      }
2992    }
2993
2994    if (!found)
2995      yyerror("Invalid cipher");
2996  }
2997 #else
2998  if (conf_parser_ctx.pass == 2)
2999    yyerror("Ignoring default_cipher_preference -- no OpenSSL support");
3000 #endif
3001 };
3002
3003 general_compression_level: COMPRESSION_LEVEL '=' NUMBER ';'
3004 {
3005  if (conf_parser_ctx.pass == 2)
3006  {
3007    ConfigFileEntry.compression_level = $3;
3008 #ifndef HAVE_LIBZ
3009    yyerror("Ignoring compression_level -- no zlib support");
3010 #else
3011    if ((ConfigFileEntry.compression_level < 1) ||
3012        (ConfigFileEntry.compression_level > 9))
3013    {
3014      yyerror("Ignoring invalid compression_level, using default");
3015      ConfigFileEntry.compression_level = 0;
3016    }
3017 #endif
3018  }
3019 };
3020
2515   general_use_egd: USE_EGD '=' TBOOL ';'
2516   {
2517    ConfigFileEntry.use_egd = yylval.number;
# Line 3028 | Line 2522 | general_egdpool_path: EGDPOOL_PATH '=' Q
2522    if (conf_parser_ctx.pass == 2)
2523    {
2524      MyFree(ConfigFileEntry.egdpool_path);
2525 <    DupString(ConfigFileEntry.egdpool_path, yylval.string);
2525 >    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2526    }
2527   };
2528  
# Line 3037 | Line 2531 | general_services_name: T_SERVICES_NAME '
2531    if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2532    {
2533      MyFree(ConfigFileEntry.service_name);
2534 <    DupString(ConfigFileEntry.service_name, yylval.string);
2534 >    ConfigFileEntry.service_name = xstrdup(yylval.string);
2535    }
2536   };
2537  
# Line 3080 | Line 2574 | umode_oitem:     T_BOTS
2574   } | T_FULL
2575   {
2576    ConfigFileEntry.oper_umodes |= UMODE_FULL;
2577 + } | HIDDEN
2578 + {
2579 +  ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2580   } | T_SKILL
2581   {
2582    ConfigFileEntry.oper_umodes |= UMODE_SKILL;
# Line 3148 | Line 2645 | umode_item:    T_BOTS
2645   } | T_SKILL
2646   {
2647    ConfigFileEntry.oper_only_umodes |= UMODE_SKILL;
2648 + } | HIDDEN
2649 + {
2650 +  ConfigFileEntry.oper_only_umodes |= UMODE_HIDDEN;
2651   } | T_NCHANGE
2652   {
2653    ConfigFileEntry.oper_only_umodes |= UMODE_NCHANGE;
# Line 3201 | Line 2701 | general_default_floodcount: DEFAULT_FLOO
2701    ConfigFileEntry.default_floodcount = $3;
2702   };
2703  
3204 general_client_flood: T_CLIENT_FLOOD '=' sizespec ';'
3205 {
3206  ConfigFileEntry.client_flood = $3;
3207 };
3208
3209
3210 /***************************************************************************
3211 *  section glines
3212 ***************************************************************************/
3213 gline_entry: GLINES
3214 {
3215  if (conf_parser_ctx.pass == 2)
3216  {
3217    yy_conf = make_conf_item(GDENY_TYPE);
3218    yy_aconf = map_to_conf(yy_conf);
3219  }
3220 } '{' gline_items '}' ';'
3221 {
3222  if (conf_parser_ctx.pass == 2)
3223  {
3224    /*
3225     * since we re-allocate yy_conf/yy_aconf after the end of action=, at the
3226     * end we will have one extra, so we should free it.
3227     */
3228    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3229    {
3230      delete_conf_item(yy_conf);
3231      yy_conf = NULL;
3232      yy_aconf = NULL;
3233    }
3234  }
3235 };
3236
3237 gline_items:        gline_items gline_item | gline_item;
3238 gline_item:         gline_enable |
3239                    gline_duration |
3240                    gline_logging |
3241                    gline_user |
3242                    gline_server |
3243                    gline_action |
3244                    error;
3245
3246 gline_enable: ENABLE '=' TBOOL ';'
3247 {
3248  if (conf_parser_ctx.pass == 2)
3249    ConfigFileEntry.glines = yylval.number;
3250 };
3251
3252 gline_duration: DURATION '=' timespec ';'
3253 {
3254  if (conf_parser_ctx.pass == 2)
3255    ConfigFileEntry.gline_time = $3;
3256 };
3257
3258 gline_logging: T_LOG
3259 {
3260  if (conf_parser_ctx.pass == 2)
3261    ConfigFileEntry.gline_logging = 0;
3262 } '=' gline_logging_types ';';
3263 gline_logging_types:     gline_logging_types ',' gline_logging_type_item | gline_logging_type_item;
3264 gline_logging_type_item: T_REJECT
3265 {
3266  if (conf_parser_ctx.pass == 2)
3267    ConfigFileEntry.gline_logging |= GDENY_REJECT;
3268 } | T_BLOCK
3269 {
3270  if (conf_parser_ctx.pass == 2)
3271    ConfigFileEntry.gline_logging |= GDENY_BLOCK;
3272 };
3273
3274 gline_user: USER '=' QSTRING ';'
3275 {
3276  if (conf_parser_ctx.pass == 2)
3277  {
3278    struct split_nuh_item nuh;
3279
3280    nuh.nuhmask  = yylval.string;
3281    nuh.nickptr  = NULL;
3282    nuh.userptr  = userbuf;
3283    nuh.hostptr  = hostbuf;
3284
3285    nuh.nicksize = 0;
3286    nuh.usersize = sizeof(userbuf);
3287    nuh.hostsize = sizeof(hostbuf);
3288
3289    split_nuh(&nuh);
3290
3291    if (yy_aconf->user == NULL)
3292    {
3293      DupString(yy_aconf->user, userbuf);
3294      DupString(yy_aconf->host, hostbuf);
3295    }
3296    else
3297    {
3298      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
3299
3300      DupString(yy_tmp->user, userbuf);
3301      DupString(yy_tmp->host, hostbuf);
3302
3303      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
3304    }
3305  }
3306 };
3307
3308 gline_server: NAME '=' QSTRING ';'
3309 {
3310  if (conf_parser_ctx.pass == 2)  
3311  {
3312    MyFree(yy_conf->name);
3313    DupString(yy_conf->name, yylval.string);
3314  }
3315 };
3316
3317 gline_action: ACTION
3318 {
3319  if (conf_parser_ctx.pass == 2)
3320    yy_aconf->flags = 0;
3321 } '=' gdeny_types ';'
3322 {
3323  if (conf_parser_ctx.pass == 2)
3324  {
3325    struct CollectItem *yy_tmp = NULL;
3326    dlink_node *ptr, *next_ptr;
3327
3328    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
3329    {
3330      struct AccessItem *new_aconf;
3331      struct ConfItem *new_conf;
3332
3333      yy_tmp = ptr->data;
3334      new_conf = make_conf_item(GDENY_TYPE);
3335      new_aconf = map_to_conf(new_conf);
3336
3337      new_aconf->flags = yy_aconf->flags;
3338
3339      if (yy_conf->name != NULL)
3340        DupString(new_conf->name, yy_conf->name);
3341      else
3342        DupString(new_conf->name, "*");
3343      if (yy_aconf->user != NULL)
3344         DupString(new_aconf->user, yy_tmp->user);
3345      else  
3346        DupString(new_aconf->user, "*");
3347      if (yy_aconf->host != NULL)
3348        DupString(new_aconf->host, yy_tmp->host);
3349      else
3350        DupString(new_aconf->host, "*");
3351
3352      dlinkDelete(&yy_tmp->node, &col_conf_list);
3353    }
3354
3355    /*
3356     * In case someone has fed us with more than one action= after user/name
3357     * which would leak memory  -Michael
3358     */
3359    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3360      delete_conf_item(yy_conf);
3361
3362    yy_conf = make_conf_item(GDENY_TYPE);
3363    yy_aconf = map_to_conf(yy_conf);
3364  }
3365 };
3366
3367 gdeny_types: gdeny_types ',' gdeny_type_item | gdeny_type_item;
3368 gdeny_type_item: T_REJECT
3369 {
3370  if (conf_parser_ctx.pass == 2)
3371    yy_aconf->flags |= GDENY_REJECT;
3372 } | T_BLOCK
3373 {
3374  if (conf_parser_ctx.pass == 2)
3375    yy_aconf->flags |= GDENY_BLOCK;
3376 };
2704  
2705   /***************************************************************************
2706   *  section channel
# Line 3382 | Line 2709 | channel_entry: CHANNEL
2709    '{' channel_items '}' ';';
2710  
2711   channel_items:      channel_items channel_item | channel_item;
2712 < channel_item:       channel_disable_local_channels | channel_use_except |
2713 <                    channel_use_invex | channel_use_knock |
2714 <                    channel_max_bans | channel_knock_delay |
3388 <                    channel_knock_delay_channel | channel_max_chans_per_user |
2712 > channel_item:       channel_max_bans |
2713 >                    channel_knock_delay | channel_knock_delay_channel |
2714 >                    channel_max_chans_per_user | channel_max_chans_per_oper |
2715                      channel_quiet_on_ban | channel_default_split_user_count |
2716                      channel_default_split_server_count |
2717                      channel_no_create_on_split | channel_restrict_channels |
2718 <                    channel_no_join_on_split | channel_burst_topicwho |
2718 >                    channel_no_join_on_split |
2719                      channel_jflood_count | channel_jflood_time |
2720                      channel_disable_fake_channels | error;
2721  
# Line 3403 | Line 2729 | channel_restrict_channels: RESTRICT_CHAN
2729    ConfigChannel.restrict_channels = yylval.number;
2730   };
2731  
3406 channel_disable_local_channels: DISABLE_LOCAL_CHANNELS '=' TBOOL ';'
3407 {
3408  ConfigChannel.disable_local_channels = yylval.number;
3409 };
3410
3411 channel_use_except: USE_EXCEPT '=' TBOOL ';'
3412 {
3413  ConfigChannel.use_except = yylval.number;
3414 };
3415
3416 channel_use_invex: USE_INVEX '=' TBOOL ';'
3417 {
3418  ConfigChannel.use_invex = yylval.number;
3419 };
3420
3421 channel_use_knock: USE_KNOCK '=' TBOOL ';'
3422 {
3423  ConfigChannel.use_knock = yylval.number;
3424 };
3425
2732   channel_knock_delay: KNOCK_DELAY '=' timespec ';'
2733   {
2734    ConfigChannel.knock_delay = $3;
# Line 3438 | Line 2744 | channel_max_chans_per_user: MAX_CHANS_PE
2744    ConfigChannel.max_chans_per_user = $3;
2745   };
2746  
2747 + channel_max_chans_per_oper: MAX_CHANS_PER_OPER '=' NUMBER ';'
2748 + {
2749 +  ConfigChannel.max_chans_per_oper = $3;
2750 + };
2751 +
2752   channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
2753   {
2754    ConfigChannel.quiet_on_ban = yylval.number;
# Line 3468 | Line 2779 | channel_no_join_on_split: NO_JOIN_ON_SPL
2779    ConfigChannel.no_join_on_split = yylval.number;
2780   };
2781  
3471 channel_burst_topicwho: BURST_TOPICWHO '=' TBOOL ';'
3472 {
3473  ConfigChannel.burst_topicwho = yylval.number;
3474 };
3475
2782   channel_jflood_count: JOIN_FLOOD_COUNT '=' NUMBER ';'
2783   {
2784    GlobalSetOptions.joinfloodcount = yylval.number;
# Line 3492 | Line 2798 | serverhide_entry: SERVERHIDE
2798   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
2799   serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
2800                      serverhide_links_delay |
3495                    serverhide_disable_hidden |
2801                      serverhide_hidden | serverhide_hidden_name |
2802                      serverhide_hide_server_ips |
2803                      error;
# Line 3514 | Line 2819 | serverhide_hidden_name: HIDDEN_NAME '='
2819    if (conf_parser_ctx.pass == 2)
2820    {
2821      MyFree(ConfigServerHide.hidden_name);
2822 <    DupString(ConfigServerHide.hidden_name, yylval.string);
2822 >    ConfigServerHide.hidden_name = xstrdup(yylval.string);
2823    }
2824   };
2825  
# Line 3538 | Line 2843 | serverhide_hidden: HIDDEN '=' TBOOL ';'
2843      ConfigServerHide.hidden = yylval.number;
2844   };
2845  
3541 serverhide_disable_hidden: DISABLE_HIDDEN '=' TBOOL ';'
3542 {
3543  if (conf_parser_ctx.pass == 2)
3544    ConfigServerHide.disable_hidden = yylval.number;
3545 };
3546
2846   serverhide_hide_server_ips: HIDE_SERVER_IPS '=' TBOOL ';'
2847   {
2848    if (conf_parser_ctx.pass == 2)

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)