ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing:
ircd-hybrid/src/ircd_parser.y (file contents), Revision 1155 by michael, Tue Aug 9 20:27:45 2011 UTC vs.
ircd-hybrid/trunk/src/conf_parser.y (file contents), Revision 2252 by michael, Sun Jun 16 13:29:13 2013 UTC

# Line 1 | Line 1
1   /*
2   *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  ircd_parser.y: Parses the ircd configuration file.
3 > *  conf_parser.y: Parses the ircd configuration file.
4   *
5   *  Copyright (C) 2005 by the past and present ircd coders, and others.
6   *
# Line 32 | Line 32
32   #include "stdinc.h"
33   #include "ircd.h"
34   #include "list.h"
35 < #include "s_conf.h"
35 > #include "conf.h"
36 > #include "conf_class.h"
37   #include "event.h"
38 < #include "s_log.h"
38 > #include "log.h"
39   #include "client.h"     /* for UMODE_ALL only */
40   #include "irc_string.h"
40 #include "sprintf_irc.h"
41   #include "memory.h"
42   #include "modules.h"
43   #include "s_serv.h"
# Line 47 | Line 47
47   #include "resv.h"
48   #include "numeric.h"
49   #include "s_user.h"
50 + #include "motd.h"
51  
52   #ifdef HAVE_LIBCRYPTO
53   #include <openssl/rsa.h>
54   #include <openssl/bio.h>
55   #include <openssl/pem.h>
56 + #include <openssl/dh.h>
57   #endif
58  
59 < static char *class_name = NULL;
58 < static struct ConfItem *yy_conf = NULL;
59 < static struct AccessItem *yy_aconf = NULL;
60 < static struct MatchItem *yy_match_item = NULL;
61 < static struct ClassItem *yy_class = NULL;
62 < static char *yy_class_name = NULL;
63 <
64 < static dlink_list col_conf_list  = { NULL, NULL, 0 };
65 < static dlink_list hub_conf_list  = { NULL, NULL, 0 };
66 < static dlink_list leaf_conf_list = { NULL, NULL, 0 };
67 < static unsigned int listener_flags = 0;
68 < static unsigned int regex_ban = 0;
69 < static char userbuf[IRCD_BUFSIZE];
70 < static char hostbuf[IRCD_BUFSIZE];
71 < static char reasonbuf[REASONLEN + 1];
72 < static char gecos_name[REALLEN * 4];
73 <
74 < static char *resv_reason = NULL;
75 < static char *listener_address = NULL;
76 < static int not_atom = 0;
77 <
78 < struct CollectItem
79 < {
80 <  dlink_node node;
81 <  char *name;
82 <  char *user;
83 <  char *host;
84 <  char *passwd;
85 <  int  port;
86 <  int  flags;
87 < #ifdef HAVE_LIBCRYPTO
88 <  char *rsa_public_key_file;
89 <  RSA *rsa_public_key;
90 < #endif
91 < };
59 > #include "rsa.h"
60  
61 < static void
62 < free_collect_item(struct CollectItem *item)
61 > int yylex(void);
62 >
63 > static struct
64   {
65 <  MyFree(item->name);
66 <  MyFree(item->user);
67 <  MyFree(item->host);
68 <  MyFree(item->passwd);
69 < #ifdef HAVE_LIBCRYPTO
70 <  MyFree(item->rsa_public_key_file);
71 < #endif
72 <  MyFree(item);
73 < }
65 >  struct {
66 >    dlink_list list;
67 >  } mask,
68 >    leaf,
69 >    hub;
70 >
71 >  struct {
72 >    char buf[IRCD_BUFSIZE];
73 >  } name,
74 >    user,
75 >    host,
76 >    addr,
77 >    bind,
78 >    file,
79 >    ciph,
80 >    cert,
81 >    rpass,
82 >    spass,
83 >    class;
84 >
85 >  struct {
86 >    unsigned int value;
87 >  } flags,
88 >    modes,
89 >    size,
90 >    type,
91 >    port,
92 >    aftype,
93 >    ping_freq,
94 >    max_perip,
95 >    con_freq,
96 >    min_idle,
97 >    max_idle,
98 >    max_total,
99 >    max_global,
100 >    max_local,
101 >    max_ident,
102 >    max_sendq,
103 >    max_recvq,
104 >    cidr_bitlen_ipv4,
105 >    cidr_bitlen_ipv6,
106 >    number_per_cidr;
107 > } block_state;
108  
109   static void
110 < unhook_hub_leaf_confs(void)
110 > reset_block_state(void)
111   {
112 <  dlink_node *ptr;
110 <  dlink_node *next_ptr;
111 <  struct CollectItem *yy_hconf;
112 <  struct CollectItem *yy_lconf;
112 >  dlink_node *ptr = NULL, *ptr_next = NULL;
113  
114 <  DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
114 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.mask.list.head)
115    {
116 <    yy_hconf = ptr->data;
117 <    dlinkDelete(&yy_hconf->node, &hub_conf_list);
118 <    free_collect_item(yy_hconf);
116 >    MyFree(ptr->data);
117 >    dlinkDelete(ptr, &block_state.mask.list);
118 >    free_dlink_node(ptr);
119    }
120  
121 <  DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
121 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.leaf.list.head)
122    {
123 <    yy_lconf = ptr->data;
124 <    dlinkDelete(&yy_lconf->node, &leaf_conf_list);
125 <    free_collect_item(yy_lconf);
123 >    MyFree(ptr->data);
124 >    dlinkDelete(ptr, &block_state.leaf.list);
125 >    free_dlink_node(ptr);
126    }
127 +
128 +  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.hub.list.head)
129 +  {
130 +    MyFree(ptr->data);
131 +    dlinkDelete(ptr, &block_state.hub.list);
132 +    free_dlink_node(ptr);
133 +  }
134 +
135 +  memset(&block_state, 0, sizeof(block_state));
136   }
137  
138   %}
# Line 134 | Line 143 | unhook_hub_leaf_confs(void)
143   }
144  
145   %token  ACCEPT_PASSWORD
137 %token  ACTION
146   %token  ADMIN
147   %token  AFTYPE
140 %token  T_ALLOW
148   %token  ANTI_NICK_FLOOD
149   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
150   %token  AUTOCONN
151 < %token  T_BLOCK
145 < %token  BURST_AWAY
146 < %token  BURST_TOPICWHO
147 < %token  BYTES KBYTES MBYTES GBYTES TBYTES
151 > %token  BYTES KBYTES MBYTES
152   %token  CALLER_ID_WAIT
153   %token  CAN_FLOOD
150 %token  CAN_IDLE
154   %token  CHANNEL
155 < %token  CIDR_BITLEN_IPV4
156 < %token  CIDR_BITLEN_IPV6
154 < %token  CIPHER_PREFERENCE
155 > %token  CIDR_BITLEN_IPV4
156 > %token  CIDR_BITLEN_IPV6
157   %token  CLASS
156 %token  COMPRESSED
157 %token  COMPRESSION_LEVEL
158   %token  CONNECT
159   %token  CONNECTFREQ
160 %token  CRYPTLINK
161 %token  DEFAULT_CIPHER_PREFERENCE
160   %token  DEFAULT_FLOODCOUNT
161   %token  DEFAULT_SPLIT_SERVER_COUNT
162   %token  DEFAULT_SPLIT_USER_COUNT
# Line 167 | Line 165 | unhook_hub_leaf_confs(void)
165   %token  DIE
166   %token  DISABLE_AUTH
167   %token  DISABLE_FAKE_CHANNELS
170 %token  DISABLE_HIDDEN
171 %token  DISABLE_LOCAL_CHANNELS
168   %token  DISABLE_REMOTE_COMMANDS
169   %token  DOTS_IN_IDENT
174 %token  DURATION
170   %token  EGDPOOL_PATH
171   %token  EMAIL
177 %token  ENABLE
172   %token  ENCRYPTED
173   %token  EXCEED_LIMIT
174   %token  EXEMPT
175   %token  FAILED_OPER_NOTICE
182 %token  IRCD_FLAGS
176   %token  FLATTEN_LINKS
184 %token  FFAILED_OPERLOG
185 %token  FKILLLOG
186 %token  FKLINELOG
187 %token  FGLINELOG
188 %token  FIOERRLOG
189 %token  FOPERLOG
190 %token  FOPERSPYLOG
191 %token  FUSERLOG
177   %token  GECOS
178   %token  GENERAL
179   %token  GLINE
180 < %token  GLINES
180 > %token  GLINE_DURATION
181 > %token  GLINE_ENABLE
182   %token  GLINE_EXEMPT
197 %token  GLINE_LOG
198 %token  GLINE_TIME
183   %token  GLINE_MIN_CIDR
184   %token  GLINE_MIN_CIDR6
185 + %token  GLINE_REQUEST_DURATION
186   %token  GLOBAL_KILL
202 %token  IRCD_AUTH
203 %token  NEED_IDENT
187   %token  HAVENT_READ_CONF
188   %token  HIDDEN
189 < %token  HIDDEN_ADMIN
190 < %token  HIDDEN_NAME
208 < %token  HIDDEN_OPER
189 > %token  HIDDEN_NAME
190 > %token  HIDE_IDLE_FROM_OPERS
191   %token  HIDE_SERVER_IPS
192   %token  HIDE_SERVERS
193 < %token  HIDE_SPOOF_IPS
193 > %token  HIDE_SERVICES
194 > %token  HIDE_SPOOF_IPS
195   %token  HOST
196   %token  HUB
197   %token  HUB_MASK
215 %token  IDLETIME
198   %token  IGNORE_BOGUS_TS
199   %token  INVISIBLE_ON_CONNECT
200   %token  IP
201 + %token  IRCD_AUTH
202 + %token  IRCD_FLAGS
203 + %token  IRCD_SID
204 + %token  JOIN_FLOOD_COUNT
205 + %token  JOIN_FLOOD_TIME
206   %token  KILL
207 < %token  KILL_CHASE_TIME_LIMIT
207 > %token  KILL_CHASE_TIME_LIMIT
208   %token  KLINE
209   %token  KLINE_EXEMPT
223 %token  KLINE_REASON
224 %token  KLINE_WITH_REASON
210   %token  KNOCK_DELAY
211   %token  KNOCK_DELAY_CHANNEL
212   %token  LEAF_MASK
213   %token  LINKS_DELAY
214   %token  LISTEN
215 < %token  T_LOG
231 < %token  LOGGING
232 < %token  LOG_LEVEL
215 > %token  MASK
216   %token  MAX_ACCEPT
217   %token  MAX_BANS
218 + %token  MAX_CHANS_PER_OPER
219   %token  MAX_CHANS_PER_USER
220   %token  MAX_GLOBAL
221   %token  MAX_IDENT
222 + %token  MAX_IDLE
223   %token  MAX_LOCAL
224   %token  MAX_NICK_CHANGES
225 + %token  MAX_NICK_LENGTH
226   %token  MAX_NICK_TIME
227   %token  MAX_NUMBER
228   %token  MAX_TARGETS
229 + %token  MAX_TOPIC_LENGTH
230   %token  MAX_WATCH
231 < %token  MESSAGE_LOCALE
231 > %token  MIN_IDLE
232   %token  MIN_NONWILDCARD
233   %token  MIN_NONWILDCARD_SIMPLE
234   %token  MODULE
235   %token  MODULES
236 + %token  MOTD
237   %token  NAME
238 + %token  NEED_IDENT
239   %token  NEED_PASSWORD
240   %token  NETWORK_DESC
241   %token  NETWORK_NAME
242   %token  NICK
254 %token  NICK_CHANGES
243   %token  NO_CREATE_ON_SPLIT
244   %token  NO_JOIN_ON_SPLIT
245   %token  NO_OPER_FLOOD
246   %token  NO_TILDE
259 %token  NOT
247   %token  NUMBER
261 %token  NUMBER_PER_IDENT
248   %token  NUMBER_PER_CIDR
249   %token  NUMBER_PER_IP
264 %token  NUMBER_PER_IP_GLOBAL
265 %token  OPERATOR
266 %token  OPERS_BYPASS_CALLERID
267 %token  OPER_LOG
250   %token  OPER_ONLY_UMODES
251   %token  OPER_PASS_RESV
270 %token  OPER_SPY_T
252   %token  OPER_UMODES
253 < %token  JOIN_FLOOD_COUNT
254 < %token  JOIN_FLOOD_TIME
253 > %token  OPERATOR
254 > %token  OPERS_BYPASS_CALLERID
255   %token  PACE_WAIT
256   %token  PACE_WAIT_SIMPLE
257   %token  PASSWORD
258   %token  PATH
259   %token  PING_COOKIE
260   %token  PING_TIME
280 %token  PING_WARNING
261   %token  PORT
262   %token  QSTRING
263 < %token  QUIET_ON_BAN
263 > %token  RANDOM_IDLE
264   %token  REASON
265   %token  REDIRPORT
266   %token  REDIRSERV
287 %token  REGEX_T
267   %token  REHASH
289 %token  TREJECT_HOLD_TIME
268   %token  REMOTE
269   %token  REMOTEBAN
292 %token  RESTRICT_CHANNELS
293 %token  RESTRICTED
294 %token  RSA_PRIVATE_KEY_FILE
295 %token  RSA_PUBLIC_KEY_FILE
296 %token  SSL_CERTIFICATE_FILE
297 %token  T_SSL_CONNECTION_METHOD
298 %token  T_SSLV3
299 %token  T_TLSV1
270   %token  RESV
271   %token  RESV_EXEMPT
272 < %token  SECONDS MINUTES HOURS DAYS WEEKS
273 < %token  SENDQ
272 > %token  RSA_PRIVATE_KEY_FILE
273 > %token  RSA_PUBLIC_KEY_FILE
274 > %token  SECONDS MINUTES HOURS DAYS WEEKS MONTHS YEARS
275   %token  SEND_PASSWORD
276 + %token  SENDQ
277   %token  SERVERHIDE
278   %token  SERVERINFO
307 %token  SERVLINK_PATH
308 %token  IRCD_SID
309 %token  TKLINE_EXPIRE_NOTICES
310 %token  T_SHARED
311 %token  T_CLUSTER
312 %token  TYPE
279   %token  SHORT_MOTD
314 %token  SILENT
280   %token  SPOOF
281   %token  SPOOF_NOTICE
282 + %token  SQUIT
283 + %token  SSL_CERTIFICATE_FILE
284 + %token  SSL_CERTIFICATE_FINGERPRINT
285 + %token  SSL_CONNECTION_REQUIRED
286 + %token  SSL_DH_PARAM_FILE
287   %token  STATS_E_DISABLED
288   %token  STATS_I_OPER_ONLY
289   %token  STATS_K_OPER_ONLY
290   %token  STATS_O_OPER_ONLY
291   %token  STATS_P_OPER_ONLY
322 %token  TBOOL
323 %token  TMASKED
324 %token  T_REJECT
325 %token  TS_MAX_DELTA
326 %token  TS_WARN_DELTA
327 %token  TWODOTS
292   %token  T_ALL
293   %token  T_BOTS
330 %token  T_SOFTCALLERID
294   %token  T_CALLERID
295   %token  T_CCONN
296 < %token  T_CCONN_FULL
334 < %token  T_CLIENT_FLOOD
296 > %token  T_CLUSTER
297   %token  T_DEAF
298   %token  T_DEBUG
299 < %token  T_DRONE
299 > %token  T_DLINE
300   %token  T_EXTERNAL
301 + %token  T_FARCONNECT
302 + %token  T_FILE
303   %token  T_FULL
304 + %token  T_GLOBOPS
305   %token  T_INVISIBLE
306   %token  T_IPV4
307   %token  T_IPV6
308   %token  T_LOCOPS
309 < %token  T_LOGPATH
345 < %token  T_L_CRIT
346 < %token  T_L_DEBUG
347 < %token  T_L_ERROR
348 < %token  T_L_INFO
349 < %token  T_L_NOTICE
350 < %token  T_L_TRACE
351 < %token  T_L_WARN
309 > %token  T_LOG
310   %token  T_MAX_CLIENTS
311   %token  T_NCHANGE
312 + %token  T_NONONREG
313   %token  T_OPERWALL
314 + %token  T_RECVQ
315   %token  T_REJ
316 + %token  T_RESTART
317   %token  T_SERVER
318 + %token  T_SERVICE
319 + %token  T_SERVICES_NAME
320   %token  T_SERVNOTICE
321 + %token  T_SET
322 + %token  T_SHARED
323 + %token  T_SIZE
324   %token  T_SKILL
325 + %token  T_SOFTCALLERID
326   %token  T_SPY
327   %token  T_SSL
328 + %token  T_SSL_CIPHER_LIST
329 + %token  T_SSL_CLIENT_METHOD
330 + %token  T_SSL_SERVER_METHOD
331 + %token  T_SSLV3
332 + %token  T_TLSV1
333   %token  T_UMODES
334   %token  T_UNAUTH
335 + %token  T_UNDLINE
336 + %token  T_UNLIMITED
337   %token  T_UNRESV
338   %token  T_UNXLINE
339   %token  T_WALLOP
340 + %token  T_WALLOPS
341 + %token  T_WEBIRC
342 + %token  TBOOL
343   %token  THROTTLE_TIME
344 < %token  TOPICBURST
344 > %token  TKLINE_EXPIRE_NOTICES
345 > %token  TMASKED
346   %token  TRUE_NO_OPER_FLOOD
347 < %token  TKLINE
348 < %token  TXLINE
349 < %token  TRESV
347 > %token  TS_MAX_DELTA
348 > %token  TS_WARN_DELTA
349 > %token  TWODOTS
350 > %token  TYPE
351   %token  UNKLINE
373 %token  USER
352   %token  USE_EGD
375 %token  USE_EXCEPT
376 %token  USE_INVEX
377 %token  USE_KNOCK
353   %token  USE_LOGGING
354 < %token  USE_WHOIS_ACTUALLY
354 > %token  USER
355   %token  VHOST
356   %token  VHOST6
382 %token  XLINE
383 %token  WARN
357   %token  WARN_NO_NLINE
358 + %token  XLINE
359  
360 < %type <string> QSTRING
361 < %type <number> NUMBER
362 < %type <number> timespec
363 < %type <number> timespec_
364 < %type <number> sizespec
365 < %type <number> sizespec_
360 > %type  <string> QSTRING
361 > %type  <number> NUMBER
362 > %type  <number> timespec
363 > %type  <number> timespec_
364 > %type  <number> sizespec
365 > %type  <number> sizespec_
366  
367   %%
368   conf:  
# Line 405 | Line 379 | conf_item:        admin_entry
379                  | serverinfo_entry
380                  | serverhide_entry
381                  | resv_entry
382 +                | service_entry
383                  | shared_entry
384                  | cluster_entry
385                  | connect_entry
# Line 412 | Line 387 | conf_item:        admin_entry
387                  | deny_entry
388                  | exempt_entry
389                  | general_entry
415                | gline_entry
390                  | gecos_entry
391                  | modules_entry
392 +                | motd_entry
393                  | error ';'
394                  | error '}'
395          ;
# Line 445 | Line 420 | timespec:      NUMBER timespec_
420                  {
421                          $$ = $1 * 60 * 60 * 24 * 7 + $3;
422                  }
423 +                | NUMBER MONTHS timespec_
424 +                {
425 +                        $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3;
426 +                }
427 +                | NUMBER YEARS timespec_
428 +                {
429 +                        $$ = $1 * 60 * 60 * 24 * 365 + $3;
430 +                }
431                  ;
432  
433   sizespec_:      { $$ = 0; } | sizespec;
# Line 483 | Line 466 | serverinfo_items:       serverinfo_items
466   serverinfo_item:        serverinfo_name | serverinfo_vhost |
467                          serverinfo_hub | serverinfo_description |
468                          serverinfo_network_name | serverinfo_network_desc |
469 <                        serverinfo_max_clients |
469 >                        serverinfo_max_clients | serverinfo_max_nick_length |
470 >                        serverinfo_max_topic_length | serverinfo_ssl_dh_param_file |
471                          serverinfo_rsa_private_key_file | serverinfo_vhost6 |
472                          serverinfo_sid | serverinfo_ssl_certificate_file |
473 <                        serverinfo_ssl_connection_method |
473 >                        serverinfo_ssl_client_method | serverinfo_ssl_server_method |
474 >                        serverinfo_ssl_cipher_list |
475                          error ';' ;
476  
477  
478 < serverinfo_ssl_connection_method: T_SSL_CONNECTION_METHOD
478 > serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
479 > serverinfo_ssl_server_method: T_SSL_SERVER_METHOD '=' server_method_types ';' ;
480 >
481 > client_method_types: client_method_types ',' client_method_type_item | client_method_type_item;
482 > client_method_type_item: T_SSLV3
483   {
484   #ifdef HAVE_LIBCRYPTO
485 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
486 <    ServerInfo.tls_version = 0;
485 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
486 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv3);
487   #endif
488 < } '=' method_types ';'
488 > } | T_TLSV1
489   {
490   #ifdef HAVE_LIBCRYPTO
491 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
492 <  {
504 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_SSLV3))
505 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
506 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_TLSV1))
507 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
508 <  }
491 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
492 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_TLSv1);
493   #endif
494   };
495  
496 < method_types: method_types ',' method_type_item | method_type_item;
497 < method_type_item: T_SSLV3
496 > server_method_types: server_method_types ',' server_method_type_item | server_method_type_item;
497 > server_method_type_item: T_SSLV3
498   {
499   #ifdef HAVE_LIBCRYPTO
500 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
501 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_SSLV3;
500 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
501 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
502   #endif
503   } | T_TLSV1
504   {
505   #ifdef HAVE_LIBCRYPTO
506 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
507 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_TLSV1;
506 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
507 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
508   #endif
509   };
510  
# Line 531 | Line 515 | serverinfo_ssl_certificate_file: SSL_CER
515    {
516      if (!ServerInfo.rsa_private_key_file)
517      {
518 <      yyerror("No rsa_private_key_file specified, SSL disabled");
518 >      conf_error_report("No rsa_private_key_file specified, SSL disabled");
519        break;
520      }
521  
522      if (SSL_CTX_use_certificate_file(ServerInfo.server_ctx, yylval.string,
523 +                                     SSL_FILETYPE_PEM) <= 0 ||
524 +        SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
525                                       SSL_FILETYPE_PEM) <= 0)
526      {
527 <      yyerror(ERR_lib_error_string(ERR_get_error()));
527 >      report_crypto_errors();
528 >      conf_error_report("Could not open/read certificate file");
529        break;
530      }
531  
532      if (SSL_CTX_use_PrivateKey_file(ServerInfo.server_ctx, ServerInfo.rsa_private_key_file,
533 +                                    SSL_FILETYPE_PEM) <= 0 ||
534 +        SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
535                                      SSL_FILETYPE_PEM) <= 0)
536      {
537 <      yyerror(ERR_lib_error_string(ERR_get_error()));
537 >      report_crypto_errors();
538 >      conf_error_report("Could not read RSA private key");
539        break;
540      }
541  
542 <    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx))
542 >    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
543 >        !SSL_CTX_check_private_key(ServerInfo.client_ctx))
544      {
545 <      yyerror(ERR_lib_error_string(ERR_get_error()));
545 >      report_crypto_errors();
546 >      conf_error_report("Could not read RSA private key");
547        break;
548      }
549    }
# Line 561 | Line 553 | serverinfo_ssl_certificate_file: SSL_CER
553   serverinfo_rsa_private_key_file: RSA_PRIVATE_KEY_FILE '=' QSTRING ';'
554   {
555   #ifdef HAVE_LIBCRYPTO
556 <  if (conf_parser_ctx.pass == 1)
556 >  BIO *file = NULL;
557 >
558 >  if (conf_parser_ctx.pass != 1)
559 >    break;
560 >
561 >  if (ServerInfo.rsa_private_key)
562    {
563 <    BIO *file;
563 >    RSA_free(ServerInfo.rsa_private_key);
564 >    ServerInfo.rsa_private_key = NULL;
565 >  }
566  
567 <    if (ServerInfo.rsa_private_key)
568 <    {
569 <      RSA_free(ServerInfo.rsa_private_key);
570 <      ServerInfo.rsa_private_key = NULL;
571 <    }
567 >  if (ServerInfo.rsa_private_key_file)
568 >  {
569 >    MyFree(ServerInfo.rsa_private_key_file);
570 >    ServerInfo.rsa_private_key_file = NULL;
571 >  }
572  
573 <    if (ServerInfo.rsa_private_key_file)
575 <    {
576 <      MyFree(ServerInfo.rsa_private_key_file);
577 <      ServerInfo.rsa_private_key_file = NULL;
578 <    }
573 >  ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
574  
575 <    DupString(ServerInfo.rsa_private_key_file, yylval.string);
575 >  if ((file = BIO_new_file(yylval.string, "r")) == NULL)
576 >  {
577 >    conf_error_report("File open failed, ignoring");
578 >    break;
579 >  }
580  
581 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
583 <    {
584 <      yyerror("File open failed, ignoring");
585 <      break;
586 <    }
581 >  ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
582  
583 <    ServerInfo.rsa_private_key = (RSA *)PEM_read_bio_RSAPrivateKey(file, NULL,
584 <      0, NULL);
583 >  BIO_set_close(file, BIO_CLOSE);
584 >  BIO_free(file);
585  
586 <    BIO_set_close(file, BIO_CLOSE);
587 <    BIO_free(file);
586 >  if (ServerInfo.rsa_private_key == NULL)
587 >  {
588 >    conf_error_report("Couldn't extract key, ignoring");
589 >    break;
590 >  }
591  
592 <    if (ServerInfo.rsa_private_key == NULL)
593 <    {
594 <      yyerror("Couldn't extract key, ignoring");
595 <      break;
598 <    }
592 >  if (!RSA_check_key(ServerInfo.rsa_private_key))
593 >  {
594 >    RSA_free(ServerInfo.rsa_private_key);
595 >    ServerInfo.rsa_private_key = NULL;
596  
597 <    if (!RSA_check_key(ServerInfo.rsa_private_key))
598 <    {
599 <      RSA_free(ServerInfo.rsa_private_key);
603 <      ServerInfo.rsa_private_key = NULL;
597 >    conf_error_report("Invalid key, ignoring");
598 >    break;
599 >  }
600  
601 <      yyerror("Invalid key, ignoring");
602 <      break;
603 <    }
601 >  /* require 2048 bit (256 byte) key */
602 >  if (RSA_size(ServerInfo.rsa_private_key) != 256)
603 >  {
604 >    RSA_free(ServerInfo.rsa_private_key);
605 >    ServerInfo.rsa_private_key = NULL;
606 >
607 >    conf_error_report("Not a 2048 bit key, ignoring");
608 >  }
609 > #endif
610 > };
611  
612 <    /* require 2048 bit (256 byte) key */
613 <    if (RSA_size(ServerInfo.rsa_private_key) != 256)
612 > serverinfo_ssl_dh_param_file: SSL_DH_PARAM_FILE '=' QSTRING ';'
613 > {
614 > /* TBD - XXX: error reporting */
615 > #ifdef HAVE_LIBCRYPTO
616 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
617 >  {
618 >    BIO *file = BIO_new_file(yylval.string, "r");
619 >
620 >    if (file)
621      {
622 <      RSA_free(ServerInfo.rsa_private_key);
613 <      ServerInfo.rsa_private_key = NULL;
622 >      DH *dh = PEM_read_bio_DHparams(file, NULL, NULL, NULL);
623  
624 <      yyerror("Not a 2048 bit key, ignoring");
624 >      BIO_free(file);
625 >
626 >      if (dh)
627 >      {
628 >        if (DH_size(dh) < 128)
629 >          conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
630 >        else
631 >          SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
632 >
633 >        DH_free(dh);
634 >      }
635      }
636    }
637   #endif
638   };
639  
640 + serverinfo_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
641 + {
642 + #ifdef HAVE_LIBCRYPTO
643 +  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
644 +    SSL_CTX_set_cipher_list(ServerInfo.server_ctx, yylval.string);
645 + #endif
646 + };
647 +
648   serverinfo_name: NAME '=' QSTRING ';'
649   {
650    /* this isn't rehashable */
651    if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
652    {
653      if (valid_servname(yylval.string))
654 <      DupString(ServerInfo.name, yylval.string);
654 >      ServerInfo.name = xstrdup(yylval.string);
655      else
656      {
657 <      ilog(L_ERROR, "Ignoring serverinfo::name -- invalid name. Aborting.");
657 >      conf_error_report("Ignoring serverinfo::name -- invalid name. Aborting.");
658        exit(0);
659      }
660    }
# Line 639 | Line 666 | serverinfo_sid: IRCD_SID '=' QSTRING ';'
666    if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
667    {
668      if (valid_sid(yylval.string))
669 <      DupString(ServerInfo.sid, yylval.string);
669 >      ServerInfo.sid = xstrdup(yylval.string);
670      else
671      {
672 <      ilog(L_ERROR, "Ignoring serverinfo::sid -- invalid SID. Aborting.");
672 >      conf_error_report("Ignoring serverinfo::sid -- invalid SID. Aborting.");
673        exit(0);
674      }
675    }
# Line 653 | Line 680 | serverinfo_description: DESCRIPTION '='
680    if (conf_parser_ctx.pass == 2)
681    {
682      MyFree(ServerInfo.description);
683 <    DupString(ServerInfo.description,yylval.string);
683 >    ServerInfo.description = xstrdup(yylval.string);
684    }
685   };
686  
# Line 667 | Line 694 | serverinfo_network_name: NETWORK_NAME '=
694        p = '\0';
695  
696      MyFree(ServerInfo.network_name);
697 <    DupString(ServerInfo.network_name, yylval.string);
697 >    ServerInfo.network_name = xstrdup(yylval.string);
698    }
699   };
700  
701   serverinfo_network_desc: NETWORK_DESC '=' QSTRING ';'
702   {
703 <  if (conf_parser_ctx.pass == 2)
704 <  {
705 <    MyFree(ServerInfo.network_desc);
706 <    DupString(ServerInfo.network_desc, yylval.string);
707 <  }
703 >  if (conf_parser_ctx.pass != 2)
704 >    break;
705 >
706 >  MyFree(ServerInfo.network_desc);
707 >  ServerInfo.network_desc = xstrdup(yylval.string);
708   };
709  
710   serverinfo_vhost: VHOST '=' QSTRING ';'
# Line 693 | Line 720 | serverinfo_vhost: VHOST '=' QSTRING ';'
720      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
721  
722      if (getaddrinfo(yylval.string, NULL, &hints, &res))
723 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
723 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
724      else
725      {
726        assert(res != NULL);
# Line 722 | Line 749 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
749      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
750  
751      if (getaddrinfo(yylval.string, NULL, &hints, &res))
752 <      ilog(L_ERROR, "Invalid netmask for server vhost6(%s)", yylval.string);
752 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost6(%s)", yylval.string);
753      else
754      {
755        assert(res != NULL);
# Line 740 | Line 767 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
767  
768   serverinfo_max_clients: T_MAX_CLIENTS '=' NUMBER ';'
769   {
770 <  if (conf_parser_ctx.pass == 2)
770 >  if (conf_parser_ctx.pass != 2)
771 >    break;
772 >
773 >  if ($3 < MAXCLIENTS_MIN)
774    {
775 <    recalc_fdlimit(NULL);
775 >    char buf[IRCD_BUFSIZE];
776  
777 <    if ($3 < MAXCLIENTS_MIN)
778 <    {
779 <      char buf[IRCD_BUFSIZE];
780 <      ircsprintf(buf, "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
781 <      yyerror(buf);
782 <    }
783 <    else if ($3 > MAXCLIENTS_MAX)
784 <    {
785 <      char buf[IRCD_BUFSIZE];
786 <      ircsprintf(buf, "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
787 <      yyerror(buf);
788 <    }
789 <    else
790 <      ServerInfo.max_clients = $3;
777 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
778 >    conf_error_report(buf);
779 >    ServerInfo.max_clients = MAXCLIENTS_MIN;
780 >  }
781 >  else if ($3 > MAXCLIENTS_MAX)
782 >  {
783 >    char buf[IRCD_BUFSIZE];
784 >
785 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
786 >    conf_error_report(buf);
787 >    ServerInfo.max_clients = MAXCLIENTS_MAX;
788 >  }
789 >  else
790 >    ServerInfo.max_clients = $3;
791 > };
792 >
793 > serverinfo_max_nick_length: MAX_NICK_LENGTH '=' NUMBER ';'
794 > {
795 >  if (conf_parser_ctx.pass != 2)
796 >    break;
797 >
798 >  if ($3 < 9)
799 >  {
800 >    conf_error_report("max_nick_length too low, setting to 9");
801 >    ServerInfo.max_nick_length = 9;
802 >  }
803 >  else if ($3 > NICKLEN)
804 >  {
805 >    char buf[IRCD_BUFSIZE];
806 >
807 >    snprintf(buf, sizeof(buf), "max_nick_length too high, setting to %d", NICKLEN);
808 >    conf_error_report(buf);
809 >    ServerInfo.max_nick_length = NICKLEN;
810    }
811 +  else
812 +    ServerInfo.max_nick_length = $3;
813 + };
814 +
815 + serverinfo_max_topic_length: MAX_TOPIC_LENGTH '=' NUMBER ';'
816 + {
817 +  if (conf_parser_ctx.pass != 2)
818 +    break;
819 +
820 +  if ($3 < 80)
821 +  {
822 +    conf_error_report("max_topic_length too low, setting to 80");
823 +    ServerInfo.max_topic_length = 80;
824 +  }
825 +  else if ($3 > TOPICLEN)
826 +  {
827 +    char buf[IRCD_BUFSIZE];
828 +
829 +    snprintf(buf, sizeof(buf), "max_topic_length too high, setting to %d", TOPICLEN);
830 +    conf_error_report(buf);
831 +    ServerInfo.max_topic_length = TOPICLEN;
832 +  }
833 +  else
834 +    ServerInfo.max_topic_length = $3;
835   };
836  
837   serverinfo_hub: HUB '=' TBOOL ';'
# Line 778 | Line 851 | admin_item:  admin_name | admin_descript
851  
852   admin_name: NAME '=' QSTRING ';'
853   {
854 <  if (conf_parser_ctx.pass == 2)
855 <  {
856 <    MyFree(AdminInfo.name);
857 <    DupString(AdminInfo.name, yylval.string);
858 <  }
854 >  if (conf_parser_ctx.pass != 2)
855 >    break;
856 >
857 >  MyFree(AdminInfo.name);
858 >  AdminInfo.name = xstrdup(yylval.string);
859   };
860  
861   admin_email: EMAIL '=' QSTRING ';'
862   {
863 <  if (conf_parser_ctx.pass == 2)
864 <  {
865 <    MyFree(AdminInfo.email);
866 <    DupString(AdminInfo.email, yylval.string);
867 <  }
863 >  if (conf_parser_ctx.pass != 2)
864 >    break;
865 >
866 >  MyFree(AdminInfo.email);
867 >  AdminInfo.email = xstrdup(yylval.string);
868   };
869  
870   admin_description: DESCRIPTION '=' QSTRING ';'
871   {
872 <  if (conf_parser_ctx.pass == 2)
873 <  {
874 <    MyFree(AdminInfo.description);
875 <    DupString(AdminInfo.description, yylval.string);
876 <  }
872 >  if (conf_parser_ctx.pass != 2)
873 >    break;
874 >
875 >  MyFree(AdminInfo.description);
876 >  AdminInfo.description = xstrdup(yylval.string);
877   };
878  
879   /***************************************************************************
880 < *  section logging
880 > * motd section
881   ***************************************************************************/
882 < /* XXX */
883 < logging_entry:          LOGGING  '{' logging_items '}' ';' ;
882 > motd_entry: MOTD
883 > {
884 >  if (conf_parser_ctx.pass == 2)
885 >    reset_block_state();
886 > } '{' motd_items '}' ';'
887 > {
888 >  dlink_node *ptr = NULL;
889  
890 < logging_items:          logging_items logging_item |
891 <                        logging_item ;
890 >  if (conf_parser_ctx.pass != 2)
891 >    break;
892  
893 < logging_item:           logging_path | logging_oper_log |
894 <                        logging_log_level |
817 <                        logging_use_logging | logging_fuserlog |
818 <                        logging_foperlog | logging_fglinelog |
819 <                        logging_fklinelog | logging_killlog |
820 <                        logging_foperspylog | logging_ioerrlog |
821 <                        logging_ffailed_operlog |
822 <                        error ';' ;
893 >  if (!block_state.file.buf[0])
894 >    break;
895  
896 < logging_path:           T_LOGPATH '=' QSTRING ';'
897 <                        {
898 <                        };
896 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
897 >    motd_add(ptr->data, block_state.file.buf);
898 > };
899  
900 < logging_oper_log:       OPER_LOG '=' QSTRING ';'
901 <                        {
830 <                        };
900 > motd_items: motd_items motd_item | motd_item;
901 > motd_item:  motd_mask | motd_file | error ';' ;
902  
903 < logging_fuserlog: FUSERLOG '=' QSTRING ';'
903 > motd_mask: MASK '=' QSTRING ';'
904   {
905    if (conf_parser_ctx.pass == 2)
906 <    strlcpy(ConfigLoggingEntry.userlog, yylval.string,
836 <            sizeof(ConfigLoggingEntry.userlog));
906 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
907   };
908  
909 < logging_ffailed_operlog: FFAILED_OPERLOG '=' QSTRING ';'
909 > motd_file: T_FILE '=' QSTRING ';'
910   {
911    if (conf_parser_ctx.pass == 2)
912 <    strlcpy(ConfigLoggingEntry.failed_operlog, yylval.string,
843 <            sizeof(ConfigLoggingEntry.failed_operlog));
912 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
913   };
914  
915 < logging_foperlog: FOPERLOG '=' QSTRING ';'
916 < {
917 <  if (conf_parser_ctx.pass == 2)
918 <    strlcpy(ConfigLoggingEntry.operlog, yylval.string,
919 <            sizeof(ConfigLoggingEntry.operlog));
851 < };
915 > /***************************************************************************
916 > *  section logging
917 > ***************************************************************************/
918 > logging_entry:          T_LOG  '{' logging_items '}' ';' ;
919 > logging_items:          logging_items logging_item | logging_item ;
920  
921 < logging_foperspylog: FOPERSPYLOG '=' QSTRING ';'
921 > logging_item:           logging_use_logging | logging_file_entry |
922 >                        error ';' ;
923 >
924 > logging_use_logging: USE_LOGGING '=' TBOOL ';'
925   {
926    if (conf_parser_ctx.pass == 2)
927 <    strlcpy(ConfigLoggingEntry.operspylog, yylval.string,
857 <            sizeof(ConfigLoggingEntry.operspylog));
927 >    ConfigLoggingEntry.use_logging = yylval.number;
928   };
929  
930 < logging_fglinelog: FGLINELOG '=' QSTRING ';'
930 > logging_file_entry:
931   {
932    if (conf_parser_ctx.pass == 2)
933 <    strlcpy(ConfigLoggingEntry.glinelog, yylval.string,
934 <            sizeof(ConfigLoggingEntry.glinelog));
933 >    reset_block_state();
934 > } T_FILE  '{' logging_file_items '}' ';'
935 > {
936 >  if (conf_parser_ctx.pass != 2)
937 >    break;
938 >
939 >  if (block_state.type.value && block_state.file.buf[0])
940 >    log_set_file(block_state.type.value, block_state.size.value,
941 >                 block_state.file.buf);
942   };
943  
944 < logging_fklinelog: FKLINELOG '=' QSTRING ';'
944 > logging_file_items: logging_file_items logging_file_item |
945 >                    logging_file_item ;
946 >
947 > logging_file_item:  logging_file_name | logging_file_type |
948 >                    logging_file_size | error ';' ;
949 >
950 > logging_file_name: NAME '=' QSTRING ';'
951   {
952 <  if (conf_parser_ctx.pass == 2)
953 <    strlcpy(ConfigLoggingEntry.klinelog, yylval.string,
954 <            sizeof(ConfigLoggingEntry.klinelog));
955 < };
952 >  if (conf_parser_ctx.pass != 2)
953 >    break;
954 >
955 >  strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
956 > }
957  
958 < logging_ioerrlog: FIOERRLOG '=' QSTRING ';'
958 > logging_file_size: T_SIZE '=' sizespec ';'
959   {
960 <  if (conf_parser_ctx.pass == 2)
961 <    strlcpy(ConfigLoggingEntry.ioerrlog, yylval.string,
962 <            sizeof(ConfigLoggingEntry.ioerrlog));
960 >  block_state.size.value = $3;
961 > } | T_SIZE '=' T_UNLIMITED ';'
962 > {
963 >  block_state.size.value = 0;
964   };
965  
966 < logging_killlog: FKILLLOG '=' QSTRING ';'
966 > logging_file_type: TYPE
967   {
968    if (conf_parser_ctx.pass == 2)
969 <    strlcpy(ConfigLoggingEntry.killlog, yylval.string,
970 <            sizeof(ConfigLoggingEntry.killlog));
886 < };
969 >    block_state.type.value = 0;
970 > } '='  logging_file_type_items ';' ;
971  
972 < logging_log_level: LOG_LEVEL '=' T_L_CRIT ';'
973 < {
890 <  if (conf_parser_ctx.pass == 2)
891 <    set_log_level(L_CRIT);
892 < } | LOG_LEVEL '=' T_L_ERROR ';'
972 > logging_file_type_items: logging_file_type_items ',' logging_file_type_item | logging_file_type_item;
973 > logging_file_type_item:  USER
974   {
975    if (conf_parser_ctx.pass == 2)
976 <    set_log_level(L_ERROR);
977 < } | LOG_LEVEL '=' T_L_WARN ';'
976 >    block_state.type.value = LOG_TYPE_USER;
977 > } | OPERATOR
978   {
979    if (conf_parser_ctx.pass == 2)
980 <    set_log_level(L_WARN);
981 < } | LOG_LEVEL '=' T_L_NOTICE ';'
980 >    block_state.type.value = LOG_TYPE_OPER;
981 > } | GLINE
982   {
983    if (conf_parser_ctx.pass == 2)
984 <    set_log_level(L_NOTICE);
985 < } | LOG_LEVEL '=' T_L_TRACE ';'
984 >    block_state.type.value = LOG_TYPE_GLINE;
985 > } | T_DLINE
986   {
987    if (conf_parser_ctx.pass == 2)
988 <    set_log_level(L_TRACE);
989 < } | LOG_LEVEL '=' T_L_INFO ';'
988 >    block_state.type.value = LOG_TYPE_DLINE;
989 > } | KLINE
990   {
991    if (conf_parser_ctx.pass == 2)
992 <    set_log_level(L_INFO);
993 < } | LOG_LEVEL '=' T_L_DEBUG ';'
992 >    block_state.type.value = LOG_TYPE_KLINE;
993 > } | KILL
994   {
995    if (conf_parser_ctx.pass == 2)
996 <    set_log_level(L_DEBUG);
997 < };
917 <
918 < logging_use_logging: USE_LOGGING '=' TBOOL ';'
996 >    block_state.type.value = LOG_TYPE_KILL;
997 > } | T_DEBUG
998   {
999    if (conf_parser_ctx.pass == 2)
1000 <    ConfigLoggingEntry.use_logging = yylval.number;
1000 >    block_state.type.value = LOG_TYPE_DEBUG;
1001   };
1002  
1003 +
1004   /***************************************************************************
1005   * section oper
1006   ***************************************************************************/
1007   oper_entry: OPERATOR
1008   {
1009 <  if (conf_parser_ctx.pass == 2)
1010 <  {
1011 <    yy_conf = make_conf_item(OPER_TYPE);
1012 <    yy_aconf = map_to_conf(yy_conf);
1013 <    SetConfEncrypted(yy_aconf); /* Yes, the default is encrypted */
1014 <  }
935 <  else
936 <  {
937 <    MyFree(class_name);
938 <    class_name = NULL;
939 <  }
940 < } oper_name_b '{' oper_items '}' ';'
1009 >  if (conf_parser_ctx.pass != 2)
1010 >    break;
1011 >
1012 >  reset_block_state();
1013 >  block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1014 > } '{' oper_items '}' ';'
1015   {
1016 <  if (conf_parser_ctx.pass == 2)
943 <  {
944 <    struct CollectItem *yy_tmp;
945 <    dlink_node *ptr;
946 <    dlink_node *next_ptr;
1016 >  dlink_node *ptr = NULL;
1017  
1018 <    conf_add_class_to_conf(yy_conf, class_name);
1018 >  if (conf_parser_ctx.pass != 2)
1019 >    break;
1020  
1021 <    /* Now, make sure there is a copy of the "base" given oper
1022 <     * block in each of the collected copies
1023 <     */
1021 >  if (!block_state.name.buf[0])
1022 >    break;
1023 > #ifdef HAVE_LIBCRYPTO
1024 >  if (!block_state.file.buf[0] &&
1025 >      !block_state.rpass.buf[0])
1026 >    break;
1027 > #else
1028 >  if (!block_state.rpass.buf[0])
1029 >    break;
1030 > #endif
1031  
1032 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1033 <    {
1034 <      struct AccessItem *new_aconf;
1035 <      struct ConfItem *new_conf;
958 <      yy_tmp = ptr->data;
959 <
960 <      new_conf = make_conf_item(OPER_TYPE);
961 <      new_aconf = (struct AccessItem *)map_to_conf(new_conf);
962 <
963 <      new_aconf->flags = yy_aconf->flags;
964 <
965 <      if (yy_conf->name != NULL)
966 <        DupString(new_conf->name, yy_conf->name);
967 <      if (yy_tmp->user != NULL)
968 <        DupString(new_aconf->user, yy_tmp->user);
969 <      else
970 <        DupString(new_aconf->user, "*");
971 <      if (yy_tmp->host != NULL)
972 <        DupString(new_aconf->host, yy_tmp->host);
973 <      else
974 <        DupString(new_aconf->host, "*");
975 <      conf_add_class_to_conf(new_conf, class_name);
976 <      if (yy_aconf->passwd != NULL)
977 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1032 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1033 >  {
1034 >    struct MaskItem *conf = NULL;
1035 >    struct split_nuh_item nuh;
1036  
1037 <      new_aconf->port = yy_aconf->port;
1038 < #ifdef HAVE_LIBCRYPTO
1039 <      if (yy_aconf->rsa_public_key_file != NULL)
1040 <      {
1041 <        BIO *file;
1037 >    nuh.nuhmask  = ptr->data;
1038 >    nuh.nickptr  = NULL;
1039 >    nuh.userptr  = block_state.user.buf;
1040 >    nuh.hostptr  = block_state.host.buf;
1041 >    nuh.nicksize = 0;
1042 >    nuh.usersize = sizeof(block_state.user.buf);
1043 >    nuh.hostsize = sizeof(block_state.host.buf);
1044 >    split_nuh(&nuh);
1045  
1046 <        DupString(new_aconf->rsa_public_key_file,
1047 <                  yy_aconf->rsa_public_key_file);
1046 >    conf         = conf_make(CONF_OPER);
1047 >    conf->name   = xstrdup(block_state.name.buf);
1048 >    conf->user   = xstrdup(block_state.user.buf);
1049 >    conf->host   = xstrdup(block_state.host.buf);
1050 >
1051 >    if (block_state.cert.buf[0])
1052 >      conf->certfp = xstrdup(block_state.cert.buf);
1053 >
1054 >    if (block_state.rpass.buf[0])
1055 >      conf->passwd = xstrdup(block_state.rpass.buf);
1056 >
1057 >    conf->flags = block_state.flags.value;
1058 >    conf->modes = block_state.modes.value;
1059 >    conf->port  = block_state.port.value;
1060 >    conf->htype = parse_netmask(conf->host, &conf->addr, &conf->bits);
1061  
1062 <        file = BIO_new_file(yy_aconf->rsa_public_key_file, "r");
989 <        new_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file,
990 <                                                           NULL, 0, NULL);
991 <        BIO_set_close(file, BIO_CLOSE);
992 <        BIO_free(file);
993 <      }
994 < #endif
1062 >    conf_add_class_to_conf(conf, block_state.class.buf);
1063  
1064   #ifdef HAVE_LIBCRYPTO
1065 <      if (yy_tmp->name && (yy_tmp->passwd || yy_aconf->rsa_public_key)
1066 <          && yy_tmp->host)
1067 < #else
1068 <      if (yy_tmp->name && yy_tmp->passwd && yy_tmp->host)
1069 < #endif
1065 >    if (block_state.file.buf[0])
1066 >    {
1067 >      BIO *file = NULL;
1068 >      RSA *pkey = NULL;
1069 >
1070 >      if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
1071        {
1072 <        conf_add_class_to_conf(new_conf, class_name);
1073 <        if (yy_tmp->name != NULL)
1005 <          DupString(new_conf->name, yy_tmp->name);
1072 >        conf_error_report("Ignoring rsa_public_key_file -- file doesn't exist");
1073 >        break;
1074        }
1075  
1076 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1077 <      free_collect_item(yy_tmp);
1010 <    }
1011 <
1012 <    yy_conf = NULL;
1013 <    yy_aconf = NULL;
1076 >      if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
1077 >        conf_error_report("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1078  
1079 <
1080 <    MyFree(class_name);
1081 <    class_name = NULL;
1079 >      conf->rsa_public_key = pkey;
1080 >      BIO_set_close(file, BIO_CLOSE);
1081 >      BIO_free(file);
1082 >    }
1083 > #endif /* HAVE_LIBCRYPTO */
1084    }
1085 < };
1085 > };
1086  
1021 oper_name_b: | oper_name_t;
1087   oper_items:     oper_items oper_item | oper_item;
1088   oper_item:      oper_name | oper_user | oper_password |
1089                  oper_umodes | oper_class | oper_encrypted |
1090 <                oper_rsa_public_key_file | oper_flags | error ';' ;
1090 >                oper_rsa_public_key_file | oper_ssl_certificate_fingerprint |
1091 >                oper_ssl_connection_required |
1092 >                oper_flags | error ';' ;
1093  
1094   oper_name: NAME '=' QSTRING ';'
1095   {
1096    if (conf_parser_ctx.pass == 2)
1097 <  {
1031 <    if (strlen(yylval.string) > OPERNICKLEN)
1032 <      yylval.string[OPERNICKLEN] = '\0';
1033 <
1034 <    MyFree(yy_conf->name);
1035 <    DupString(yy_conf->name, yylval.string);
1036 <  }
1037 < };
1038 <
1039 < oper_name_t: QSTRING
1040 < {
1041 <  if (conf_parser_ctx.pass == 2)
1042 <  {
1043 <    if (strlen(yylval.string) > OPERNICKLEN)
1044 <      yylval.string[OPERNICKLEN] = '\0';
1045 <
1046 <    MyFree(yy_conf->name);
1047 <    DupString(yy_conf->name, yylval.string);
1048 <  }
1097 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1098   };
1099  
1100   oper_user: USER '=' QSTRING ';'
1101   {
1102    if (conf_parser_ctx.pass == 2)
1103 <  {
1055 <    struct split_nuh_item nuh;
1056 <
1057 <    nuh.nuhmask  = yylval.string;
1058 <    nuh.nickptr  = NULL;
1059 <    nuh.userptr  = userbuf;
1060 <    nuh.hostptr  = hostbuf;
1061 <
1062 <    nuh.nicksize = 0;
1063 <    nuh.usersize = sizeof(userbuf);
1064 <    nuh.hostsize = sizeof(hostbuf);
1065 <
1066 <    split_nuh(&nuh);
1067 <
1068 <    if (yy_aconf->user == NULL)
1069 <    {
1070 <      DupString(yy_aconf->user, userbuf);
1071 <      DupString(yy_aconf->host, hostbuf);
1072 <    }
1073 <    else
1074 <    {
1075 <      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
1076 <
1077 <      DupString(yy_tmp->user, userbuf);
1078 <      DupString(yy_tmp->host, hostbuf);
1079 <
1080 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1081 <    }
1082 <  }
1103 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1104   };
1105  
1106   oper_password: PASSWORD '=' QSTRING ';'
1107   {
1108    if (conf_parser_ctx.pass == 2)
1109 <  {
1089 <    if (yy_aconf->passwd != NULL)
1090 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1091 <
1092 <    MyFree(yy_aconf->passwd);
1093 <    DupString(yy_aconf->passwd, yylval.string);
1094 <  }
1109 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1110   };
1111  
1112   oper_encrypted: ENCRYPTED '=' TBOOL ';'
1113   {
1114 <  if (conf_parser_ctx.pass == 2)
1115 <  {
1116 <    if (yylval.number)
1117 <      SetConfEncrypted(yy_aconf);
1118 <    else
1119 <      ClearConfEncrypted(yy_aconf);
1120 <  }
1114 >  if (conf_parser_ctx.pass != 2)
1115 >    break;
1116 >
1117 >  if (yylval.number)
1118 >    block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1119 >  else
1120 >    block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1121   };
1122  
1123   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
1124   {
1110 #ifdef HAVE_LIBCRYPTO
1125    if (conf_parser_ctx.pass == 2)
1126 <  {
1127 <    BIO *file;
1114 <
1115 <    if (yy_aconf->rsa_public_key != NULL)
1116 <    {
1117 <      RSA_free(yy_aconf->rsa_public_key);
1118 <      yy_aconf->rsa_public_key = NULL;
1119 <    }
1120 <
1121 <    if (yy_aconf->rsa_public_key_file != NULL)
1122 <    {
1123 <      MyFree(yy_aconf->rsa_public_key_file);
1124 <      yy_aconf->rsa_public_key_file = NULL;
1125 <    }
1126 <
1127 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
1128 <    file = BIO_new_file(yylval.string, "r");
1129 <
1130 <    if (file == NULL)
1131 <    {
1132 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
1133 <      break;
1134 <    }
1126 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1127 > };
1128  
1129 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
1129 > oper_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
1130 > {
1131 >  if (conf_parser_ctx.pass == 2)
1132 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
1133 > };
1134  
1135 <    if (yy_aconf->rsa_public_key == NULL)
1136 <    {
1137 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1138 <      break;
1142 <    }
1135 > oper_ssl_connection_required: SSL_CONNECTION_REQUIRED '=' TBOOL ';'
1136 > {
1137 >  if (conf_parser_ctx.pass != 2)
1138 >    break;
1139  
1140 <    BIO_set_close(file, BIO_CLOSE);
1141 <    BIO_free(file);
1142 <  }
1143 < #endif /* HAVE_LIBCRYPTO */
1140 >  if (yylval.number)
1141 >    block_state.flags.value |= CONF_FLAGS_SSL;
1142 >  else
1143 >    block_state.flags.value &= ~CONF_FLAGS_SSL;
1144   };
1145  
1146   oper_class: CLASS '=' QSTRING ';'
1147   {
1148    if (conf_parser_ctx.pass == 2)
1149 <  {
1154 <    MyFree(class_name);
1155 <    DupString(class_name, yylval.string);
1156 <  }
1149 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1150   };
1151  
1152   oper_umodes: T_UMODES
1153   {
1154    if (conf_parser_ctx.pass == 2)
1155 <    yy_aconf->modes = 0;
1155 >    block_state.modes.value = 0;
1156   } '='  oper_umodes_items ';' ;
1157  
1158   oper_umodes_items: oper_umodes_items ',' oper_umodes_item | oper_umodes_item;
1159   oper_umodes_item:  T_BOTS
1160   {
1161    if (conf_parser_ctx.pass == 2)
1162 <    yy_aconf->modes |= UMODE_BOTS;
1162 >    block_state.modes.value |= UMODE_BOTS;
1163   } | T_CCONN
1164   {
1165    if (conf_parser_ctx.pass == 2)
1166 <    yy_aconf->modes |= UMODE_CCONN;
1174 < } | T_CCONN_FULL
1175 < {
1176 <  if (conf_parser_ctx.pass == 2)
1177 <    yy_aconf->modes |= UMODE_CCONN_FULL;
1166 >    block_state.modes.value |= UMODE_CCONN;
1167   } | T_DEAF
1168   {
1169    if (conf_parser_ctx.pass == 2)
1170 <    yy_aconf->modes |= UMODE_DEAF;
1170 >    block_state.modes.value |= UMODE_DEAF;
1171   } | T_DEBUG
1172   {
1173    if (conf_parser_ctx.pass == 2)
1174 <    yy_aconf->modes |= UMODE_DEBUG;
1174 >    block_state.modes.value |= UMODE_DEBUG;
1175   } | T_FULL
1176   {
1177    if (conf_parser_ctx.pass == 2)
1178 <    yy_aconf->modes |= UMODE_FULL;
1178 >    block_state.modes.value |= UMODE_FULL;
1179 > } | HIDDEN
1180 > {
1181 >  if (conf_parser_ctx.pass == 2)
1182 >    block_state.modes.value |= UMODE_HIDDEN;
1183   } | T_SKILL
1184   {
1185    if (conf_parser_ctx.pass == 2)
1186 <    yy_aconf->modes |= UMODE_SKILL;
1186 >    block_state.modes.value |= UMODE_SKILL;
1187   } | T_NCHANGE
1188   {
1189    if (conf_parser_ctx.pass == 2)
1190 <    yy_aconf->modes |= UMODE_NCHANGE;
1190 >    block_state.modes.value |= UMODE_NCHANGE;
1191   } | T_REJ
1192   {
1193    if (conf_parser_ctx.pass == 2)
1194 <    yy_aconf->modes |= UMODE_REJ;
1194 >    block_state.modes.value |= UMODE_REJ;
1195   } | T_UNAUTH
1196   {
1197    if (conf_parser_ctx.pass == 2)
1198 <    yy_aconf->modes |= UMODE_UNAUTH;
1198 >    block_state.modes.value |= UMODE_UNAUTH;
1199   } | T_SPY
1200   {
1201    if (conf_parser_ctx.pass == 2)
1202 <    yy_aconf->modes |= UMODE_SPY;
1202 >    block_state.modes.value |= UMODE_SPY;
1203   } | T_EXTERNAL
1204   {
1205    if (conf_parser_ctx.pass == 2)
1206 <    yy_aconf->modes |= UMODE_EXTERNAL;
1206 >    block_state.modes.value |= UMODE_EXTERNAL;
1207   } | T_OPERWALL
1208   {
1209    if (conf_parser_ctx.pass == 2)
1210 <    yy_aconf->modes |= UMODE_OPERWALL;
1210 >    block_state.modes.value |= UMODE_OPERWALL;
1211   } | T_SERVNOTICE
1212   {
1213    if (conf_parser_ctx.pass == 2)
1214 <    yy_aconf->modes |= UMODE_SERVNOTICE;
1214 >    block_state.modes.value |= UMODE_SERVNOTICE;
1215   } | T_INVISIBLE
1216   {
1217    if (conf_parser_ctx.pass == 2)
1218 <    yy_aconf->modes |= UMODE_INVISIBLE;
1218 >    block_state.modes.value |= UMODE_INVISIBLE;
1219   } | T_WALLOP
1220   {
1221    if (conf_parser_ctx.pass == 2)
1222 <    yy_aconf->modes |= UMODE_WALLOP;
1222 >    block_state.modes.value |= UMODE_WALLOP;
1223   } | T_SOFTCALLERID
1224   {
1225    if (conf_parser_ctx.pass == 2)
1226 <    yy_aconf->modes |= UMODE_SOFTCALLERID;
1226 >    block_state.modes.value |= UMODE_SOFTCALLERID;
1227   } | T_CALLERID
1228   {
1229    if (conf_parser_ctx.pass == 2)
1230 <    yy_aconf->modes |= UMODE_CALLERID;
1230 >    block_state.modes.value |= UMODE_CALLERID;
1231   } | T_LOCOPS
1232   {
1233    if (conf_parser_ctx.pass == 2)
1234 <    yy_aconf->modes |= UMODE_LOCOPS;
1234 >    block_state.modes.value |= UMODE_LOCOPS;
1235 > } | T_NONONREG
1236 > {
1237 >  if (conf_parser_ctx.pass == 2)
1238 >    block_state.modes.value |= UMODE_REGONLY;
1239 > } | T_FARCONNECT
1240 > {
1241 >  if (conf_parser_ctx.pass == 2)
1242 >    block_state.modes.value |= UMODE_FARCONNECT;
1243   };
1244  
1245   oper_flags: IRCD_FLAGS
1246   {
1247 +  if (conf_parser_ctx.pass == 2)
1248 +    block_state.port.value = 0;
1249   } '='  oper_flags_items ';';
1250  
1251   oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1252 < oper_flags_item: NOT { not_atom = 1; } oper_flags_item_atom
1250 <                | { not_atom = 0; } oper_flags_item_atom;
1251 <
1252 < oper_flags_item_atom: GLOBAL_KILL
1252 > oper_flags_item: KILL ':' REMOTE
1253   {
1254    if (conf_parser_ctx.pass == 2)
1255 <  {
1256 <    if (not_atom)yy_aconf->port &= ~OPER_FLAG_GLOBAL_KILL;
1257 <    else yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1258 <  }
1259 < } | REMOTE
1255 >    block_state.port.value |= OPER_FLAG_KILL_REMOTE;
1256 > } | KILL
1257   {
1258    if (conf_parser_ctx.pass == 2)
1259 <  {
1260 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTE;
1261 <    else yy_aconf->port |= OPER_FLAG_REMOTE;
1262 <  }
1259 >    block_state.port.value |= OPER_FLAG_KILL;
1260 > } | CONNECT ':' REMOTE
1261 > {
1262 >  if (conf_parser_ctx.pass == 2)
1263 >    block_state.port.value |= OPER_FLAG_CONNECT_REMOTE;
1264 > } | CONNECT
1265 > {
1266 >  if (conf_parser_ctx.pass == 2)
1267 >    block_state.port.value |= OPER_FLAG_CONNECT;
1268 > } | SQUIT ':' REMOTE
1269 > {
1270 >  if (conf_parser_ctx.pass == 2)
1271 >    block_state.port.value |= OPER_FLAG_SQUIT_REMOTE;
1272 > } | SQUIT
1273 > {
1274 >  if (conf_parser_ctx.pass == 2)
1275 >    block_state.port.value |= OPER_FLAG_SQUIT;
1276   } | KLINE
1277   {
1278    if (conf_parser_ctx.pass == 2)
1279 <  {
1270 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_K;
1271 <    else yy_aconf->port |= OPER_FLAG_K;
1272 <  }
1279 >    block_state.port.value |= OPER_FLAG_K;
1280   } | UNKLINE
1281   {
1282    if (conf_parser_ctx.pass == 2)
1283 <  {
1284 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_UNKLINE;
1285 <    else yy_aconf->port |= OPER_FLAG_UNKLINE;
1286 <  }
1283 >    block_state.port.value |= OPER_FLAG_UNKLINE;
1284 > } | T_DLINE
1285 > {
1286 >  if (conf_parser_ctx.pass == 2)
1287 >    block_state.port.value |= OPER_FLAG_DLINE;
1288 > } | T_UNDLINE
1289 > {
1290 >  if (conf_parser_ctx.pass == 2)
1291 >    block_state.port.value |= OPER_FLAG_UNDLINE;
1292   } | XLINE
1293   {
1294    if (conf_parser_ctx.pass == 2)
1295 <  {
1284 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_X;
1285 <    else yy_aconf->port |= OPER_FLAG_X;
1286 <  }
1295 >    block_state.port.value |= OPER_FLAG_X;
1296   } | GLINE
1297   {
1298    if (conf_parser_ctx.pass == 2)
1299 <  {
1291 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_GLINE;
1292 <    else yy_aconf->port |= OPER_FLAG_GLINE;
1293 <  }
1299 >    block_state.port.value |= OPER_FLAG_GLINE;
1300   } | DIE
1301   {
1302    if (conf_parser_ctx.pass == 2)
1303 <  {
1304 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_DIE;
1305 <    else yy_aconf->port |= OPER_FLAG_DIE;
1306 <  }
1303 >    block_state.port.value |= OPER_FLAG_DIE;
1304 > } | T_RESTART
1305 > {
1306 >  if (conf_parser_ctx.pass == 2)
1307 >    block_state.port.value |= OPER_FLAG_RESTART;
1308   } | REHASH
1309   {
1310    if (conf_parser_ctx.pass == 2)
1311 <  {
1305 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REHASH;
1306 <    else yy_aconf->port |= OPER_FLAG_REHASH;
1307 <  }
1311 >    block_state.port.value |= OPER_FLAG_REHASH;
1312   } | ADMIN
1313   {
1314    if (conf_parser_ctx.pass == 2)
1315 <  {
1316 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_ADMIN;
1313 <    else yy_aconf->port |= OPER_FLAG_ADMIN;
1314 <  }
1315 < } | HIDDEN_ADMIN
1315 >    block_state.port.value |= OPER_FLAG_ADMIN;
1316 > } | T_OPERWALL
1317   {
1318    if (conf_parser_ctx.pass == 2)
1319 <  {
1320 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_ADMIN;
1320 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1321 <  }
1322 < } | NICK_CHANGES
1319 >    block_state.port.value |= OPER_FLAG_OPERWALL;
1320 > } | T_GLOBOPS
1321   {
1322    if (conf_parser_ctx.pass == 2)
1323 <  {
1324 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_N;
1327 <    else yy_aconf->port |= OPER_FLAG_N;
1328 <  }
1329 < } | T_OPERWALL
1323 >    block_state.port.value |= OPER_FLAG_GLOBOPS;
1324 > } | T_WALLOPS
1325   {
1326    if (conf_parser_ctx.pass == 2)
1327 <  {
1328 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPERWALL;
1334 <    else yy_aconf->port |= OPER_FLAG_OPERWALL;
1335 <  }
1336 < } | OPER_SPY_T
1327 >    block_state.port.value |= OPER_FLAG_WALLOPS;
1328 > } | T_LOCOPS
1329   {
1330    if (conf_parser_ctx.pass == 2)
1331 <  {
1332 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPER_SPY;
1341 <    else yy_aconf->port |= OPER_FLAG_OPER_SPY;
1342 <  }
1343 < } | HIDDEN_OPER
1331 >    block_state.port.value |= OPER_FLAG_LOCOPS;
1332 > } | REMOTEBAN
1333   {
1334    if (conf_parser_ctx.pass == 2)
1335 <  {
1336 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_OPER;
1348 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1349 <  }
1350 < } | REMOTEBAN
1335 >    block_state.port.value |= OPER_FLAG_REMOTEBAN;
1336 > } | T_SET
1337   {
1338    if (conf_parser_ctx.pass == 2)
1339 <  {
1340 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTEBAN;
1355 <    else yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1356 <  }
1357 < } | ENCRYPTED
1339 >    block_state.port.value |= OPER_FLAG_SET;
1340 > } | MODULE
1341   {
1342    if (conf_parser_ctx.pass == 2)
1343 <  {
1361 <    if (not_atom) ClearConfEncrypted(yy_aconf);
1362 <    else SetConfEncrypted(yy_aconf);
1363 <  }
1343 >    block_state.port.value |= OPER_FLAG_MODULE;
1344   };
1345  
1346  
# Line 1369 | Line 1349 | oper_flags_item_atom: GLOBAL_KILL
1349   ***************************************************************************/
1350   class_entry: CLASS
1351   {
1352 <  if (conf_parser_ctx.pass == 1)
1353 <  {
1374 <    yy_conf = make_conf_item(CLASS_TYPE);
1375 <    yy_class = map_to_conf(yy_conf);
1376 <  }
1377 < } class_name_b '{' class_items '}' ';'
1378 < {
1379 <  if (conf_parser_ctx.pass == 1)
1380 <  {
1381 <    struct ConfItem *cconf = NULL;
1382 <    struct ClassItem *class = NULL;
1383 <
1384 <    if (yy_class_name == NULL)
1385 <      delete_conf_item(yy_conf);
1386 <    else
1387 <    {
1388 <      cconf = find_exact_name_conf(CLASS_TYPE, yy_class_name, NULL, NULL);
1389 <
1390 <      if (cconf != NULL)                /* The class existed already */
1391 <      {
1392 <        int user_count = 0;
1393 <
1394 <        rebuild_cidr_class(cconf, yy_class);
1395 <
1396 <        class = map_to_conf(cconf);
1397 <
1398 <        user_count = class->curr_user_count;
1399 <        memcpy(class, yy_class, sizeof(*class));
1400 <        class->curr_user_count = user_count;
1401 <        class->active = 1;
1402 <
1403 <        delete_conf_item(yy_conf);
1352 >  if (conf_parser_ctx.pass != 1)
1353 >    break;
1354  
1355 <        MyFree(cconf->name);            /* Allows case change of class name */
1406 <        cconf->name = yy_class_name;
1407 <      }
1408 <      else      /* Brand new class */
1409 <      {
1410 <        MyFree(yy_conf->name);          /* just in case it was allocated */
1411 <        yy_conf->name = yy_class_name;
1412 <        yy_class->active = 1;
1413 <      }
1414 <    }
1355 >  reset_block_state();
1356  
1357 <    yy_class_name = NULL;
1358 <  }
1357 >  block_state.ping_freq.value = DEFAULT_PINGFREQUENCY;
1358 >  block_state.con_freq.value  = DEFAULT_CONNECTFREQUENCY;
1359 >  block_state.max_total.value = MAXIMUM_LINKS_DEFAULT;
1360 >  block_state.max_sendq.value = DEFAULT_SENDQ;
1361 >  block_state.max_recvq.value = DEFAULT_RECVQ;
1362 > } '{' class_items '}' ';'
1363 > {
1364 >  struct ClassItem *class = NULL;
1365 >
1366 >  if (conf_parser_ctx.pass != 1)
1367 >    break;
1368 >
1369 >  if (!block_state.class.buf[0])
1370 >    break;
1371 >
1372 >  if (!(class = class_find(block_state.class.buf, 0)))
1373 >    class = class_make();
1374 >
1375 >  class->active = 1;
1376 >  MyFree(class->name);
1377 >  class->name = xstrdup(block_state.class.buf);
1378 >  class->ping_freq = block_state.ping_freq.value;
1379 >  class->max_perip = block_state.max_perip.value;
1380 >  class->con_freq = block_state.con_freq.value;
1381 >  class->max_total = block_state.max_total.value;
1382 >  class->max_global = block_state.max_global.value;
1383 >  class->max_local = block_state.max_local.value;
1384 >  class->max_ident = block_state.max_ident.value;
1385 >  class->max_sendq = block_state.max_sendq.value;
1386 >  class->max_recvq = block_state.max_recvq.value;
1387 >
1388 >  if (block_state.min_idle.value > block_state.max_idle.value)
1389 >  {
1390 >    block_state.min_idle.value = 0;
1391 >    block_state.max_idle.value = 0;
1392 >    block_state.flags.value &= ~CLASS_FLAGS_FAKE_IDLE;
1393 >  }
1394 >
1395 >  class->flags = block_state.flags.value;
1396 >  class->min_idle = block_state.min_idle.value;
1397 >  class->max_idle = block_state.max_idle.value;
1398 >
1399 >  if (class->number_per_cidr && block_state.number_per_cidr.value)
1400 >    if ((class->cidr_bitlen_ipv4 && block_state.cidr_bitlen_ipv4.value) ||
1401 >        (class->cidr_bitlen_ipv6 && block_state.cidr_bitlen_ipv6.value))
1402 >      if ((class->cidr_bitlen_ipv4 != block_state.cidr_bitlen_ipv4.value) ||
1403 >          (class->cidr_bitlen_ipv6 != block_state.cidr_bitlen_ipv6.value))
1404 >        rebuild_cidr_list(class);
1405 >
1406 >  class->cidr_bitlen_ipv4 = block_state.cidr_bitlen_ipv4.value;
1407 >  class->cidr_bitlen_ipv6 = block_state.cidr_bitlen_ipv6.value;
1408 >  class->number_per_cidr = block_state.number_per_cidr.value;
1409   };
1410  
1420 class_name_b: | class_name_t;
1421
1411   class_items:    class_items class_item | class_item;
1412   class_item:     class_name |
1413                  class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1414                  class_ping_time |
1426                class_ping_warning |
1415                  class_number_per_cidr |
1416                  class_number_per_ip |
1417                  class_connectfreq |
# Line 1431 | Line 1419 | class_item:     class_name |
1419                  class_max_global |
1420                  class_max_local |
1421                  class_max_ident |
1422 <                class_sendq |
1422 >                class_sendq | class_recvq |
1423 >                class_min_idle |
1424 >                class_max_idle |
1425 >                class_flags |
1426                  error ';' ;
1427  
1428   class_name: NAME '=' QSTRING ';'
1429   {
1430    if (conf_parser_ctx.pass == 1)
1431 <  {
1441 <    MyFree(yy_class_name);
1442 <    DupString(yy_class_name, yylval.string);
1443 <  }
1444 < };
1445 <
1446 < class_name_t: QSTRING
1447 < {
1448 <  if (conf_parser_ctx.pass == 1)
1449 <  {
1450 <    MyFree(yy_class_name);
1451 <    DupString(yy_class_name, yylval.string);
1452 <  }
1431 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1432   };
1433  
1434   class_ping_time: PING_TIME '=' timespec ';'
1435   {
1436    if (conf_parser_ctx.pass == 1)
1437 <    PingFreq(yy_class) = $3;
1459 < };
1460 <
1461 < class_ping_warning: PING_WARNING '=' timespec ';'
1462 < {
1463 <  if (conf_parser_ctx.pass == 1)
1464 <    PingWarning(yy_class) = $3;
1437 >    block_state.ping_freq.value = $3;
1438   };
1439  
1440   class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1441   {
1442    if (conf_parser_ctx.pass == 1)
1443 <    MaxPerIp(yy_class) = $3;
1443 >    block_state.max_perip.value = $3;
1444   };
1445  
1446   class_connectfreq: CONNECTFREQ '=' timespec ';'
1447   {
1448    if (conf_parser_ctx.pass == 1)
1449 <    ConFreq(yy_class) = $3;
1449 >    block_state.con_freq.value = $3;
1450   };
1451  
1452   class_max_number: MAX_NUMBER '=' NUMBER ';'
1453   {
1454    if (conf_parser_ctx.pass == 1)
1455 <    MaxTotal(yy_class) = $3;
1455 >    block_state.max_total.value = $3;
1456   };
1457  
1458   class_max_global: MAX_GLOBAL '=' NUMBER ';'
1459   {
1460    if (conf_parser_ctx.pass == 1)
1461 <    MaxGlobal(yy_class) = $3;
1461 >    block_state.max_global.value = $3;
1462   };
1463  
1464   class_max_local: MAX_LOCAL '=' NUMBER ';'
1465   {
1466    if (conf_parser_ctx.pass == 1)
1467 <    MaxLocal(yy_class) = $3;
1467 >    block_state.max_local.value = $3;
1468   };
1469  
1470   class_max_ident: MAX_IDENT '=' NUMBER ';'
1471   {
1472    if (conf_parser_ctx.pass == 1)
1473 <    MaxIdent(yy_class) = $3;
1473 >    block_state.max_ident.value = $3;
1474   };
1475  
1476   class_sendq: SENDQ '=' sizespec ';'
1477   {
1478    if (conf_parser_ctx.pass == 1)
1479 <    MaxSendq(yy_class) = $3;
1479 >    block_state.max_sendq.value = $3;
1480 > };
1481 >
1482 > class_recvq: T_RECVQ '=' sizespec ';'
1483 > {
1484 >  if (conf_parser_ctx.pass == 1)
1485 >    if ($3 >= CLIENT_FLOOD_MIN && $3 <= CLIENT_FLOOD_MAX)
1486 >      block_state.max_recvq.value = $3;
1487   };
1488  
1489   class_cidr_bitlen_ipv4: CIDR_BITLEN_IPV4 '=' NUMBER ';'
1490   {
1491    if (conf_parser_ctx.pass == 1)
1492 <    CidrBitlenIPV4(yy_class) = $3;
1492 >    block_state.cidr_bitlen_ipv4.value = $3 > 32 ? 32 : $3;
1493   };
1494  
1495   class_cidr_bitlen_ipv6: CIDR_BITLEN_IPV6 '=' NUMBER ';'
1496   {
1497    if (conf_parser_ctx.pass == 1)
1498 <    CidrBitlenIPV6(yy_class) = $3;
1498 >    block_state.cidr_bitlen_ipv6.value = $3 > 128 ? 128 : $3;
1499   };
1500  
1501   class_number_per_cidr: NUMBER_PER_CIDR '=' NUMBER ';'
1502   {
1503    if (conf_parser_ctx.pass == 1)
1504 <    NumberPerCidr(yy_class) = $3;
1504 >    block_state.number_per_cidr.value = $3;
1505 > };
1506 >
1507 > class_min_idle: MIN_IDLE '=' timespec ';'
1508 > {
1509 >  if (conf_parser_ctx.pass != 1)
1510 >    break;
1511 >
1512 >  block_state.min_idle.value = $3;
1513 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1514 > };
1515 >
1516 > class_max_idle: MAX_IDLE '=' timespec ';'
1517 > {
1518 >  if (conf_parser_ctx.pass != 1)
1519 >    break;
1520 >
1521 >  block_state.max_idle.value = $3;
1522 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1523   };
1524  
1525 + class_flags: IRCD_FLAGS
1526 + {
1527 +  if (conf_parser_ctx.pass == 1)
1528 +    block_state.flags.value &= CLASS_FLAGS_FAKE_IDLE;
1529 + } '='  class_flags_items ';';
1530 +
1531 + class_flags_items: class_flags_items ',' class_flags_item | class_flags_item;
1532 + class_flags_item: RANDOM_IDLE
1533 + {
1534 +  if (conf_parser_ctx.pass == 1)
1535 +    block_state.flags.value |= CLASS_FLAGS_RANDOM_IDLE;
1536 + } | HIDE_IDLE_FROM_OPERS
1537 + {
1538 +  if (conf_parser_ctx.pass == 1)
1539 +    block_state.flags.value |= CLASS_FLAGS_HIDE_IDLE_FROM_OPERS;
1540 + };
1541 +
1542 +
1543   /***************************************************************************
1544   *  section listen
1545   ***************************************************************************/
1546   listen_entry: LISTEN
1547   {
1548    if (conf_parser_ctx.pass == 2)
1549 <  {
1550 <    listener_address = NULL;
1535 <    listener_flags = 0;
1536 <  }
1537 < } '{' listen_items '}' ';'
1538 < {
1539 <  if (conf_parser_ctx.pass == 2)
1540 <  {
1541 <    MyFree(listener_address);
1542 <    listener_address = NULL;
1543 <  }
1544 < };
1549 >    reset_block_state();
1550 > } '{' listen_items '}' ';';
1551  
1552   listen_flags: IRCD_FLAGS
1553   {
1554 <  listener_flags = 0;
1554 >  block_state.flags.value = 0;
1555   } '='  listen_flags_items ';';
1556  
1557   listen_flags_items: listen_flags_items ',' listen_flags_item | listen_flags_item;
1558   listen_flags_item: T_SSL
1559   {
1560    if (conf_parser_ctx.pass == 2)
1561 <    listener_flags |= LISTENER_SSL;
1561 >    block_state.flags.value |= LISTENER_SSL;
1562   } | HIDDEN
1563   {
1564    if (conf_parser_ctx.pass == 2)
1565 <    listener_flags |= LISTENER_HIDDEN;
1565 >    block_state.flags.value |= LISTENER_HIDDEN;
1566   } | T_SERVER
1567   {
1568    if (conf_parser_ctx.pass == 2)
1569 <    listener_flags |= LISTENER_SERVER;
1569 >   block_state.flags.value |= LISTENER_SERVER;
1570   };
1571  
1566
1567
1572   listen_items:   listen_items listen_item | listen_item;
1573   listen_item:    listen_port | listen_flags | listen_address | listen_host | error ';';
1574  
1575 < listen_port: PORT '=' port_items { listener_flags = 0; } ';';
1575 > listen_port: PORT '=' port_items { block_state.flags.value = 0; } ';';
1576  
1577   port_items: port_items ',' port_item | port_item;
1578  
# Line 1576 | Line 1580 | port_item: NUMBER
1580   {
1581    if (conf_parser_ctx.pass == 2)
1582    {
1583 <    if ((listener_flags & LISTENER_SSL))
1583 >    if (block_state.flags.value & LISTENER_SSL)
1584   #ifdef HAVE_LIBCRYPTO
1585        if (!ServerInfo.server_ctx)
1586   #endif
1587        {
1588 <        yyerror("SSL not available - port closed");
1588 >        conf_error_report("SSL not available - port closed");
1589          break;
1590        }
1591 <    add_listener($1, listener_address, listener_flags);
1591 >    add_listener($1, block_state.addr.buf, block_state.flags.value);
1592    }
1593   } | NUMBER TWODOTS NUMBER
1594   {
# Line 1592 | Line 1596 | port_item: NUMBER
1596    {
1597      int i;
1598  
1599 <    if ((listener_flags & LISTENER_SSL))
1599 >    if (block_state.flags.value & LISTENER_SSL)
1600   #ifdef HAVE_LIBCRYPTO
1601        if (!ServerInfo.server_ctx)
1602   #endif
1603        {
1604 <        yyerror("SSL not available - port closed");
1604 >        conf_error_report("SSL not available - port closed");
1605          break;
1606        }
1607  
1608      for (i = $1; i <= $3; ++i)
1609 <      add_listener(i, listener_address, listener_flags);
1609 >      add_listener(i, block_state.addr.buf, block_state.flags.value);
1610    }
1611   };
1612  
1613   listen_address: IP '=' QSTRING ';'
1614   {
1615    if (conf_parser_ctx.pass == 2)
1616 <  {
1613 <    MyFree(listener_address);
1614 <    DupString(listener_address, yylval.string);
1615 <  }
1616 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1617   };
1618  
1619   listen_host: HOST '=' QSTRING ';'
1620   {
1621    if (conf_parser_ctx.pass == 2)
1622 <  {
1622 <    MyFree(listener_address);
1623 <    DupString(listener_address, yylval.string);
1624 <  }
1622 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1623   };
1624  
1625   /***************************************************************************
# Line 1630 | Line 1628 | listen_host: HOST '=' QSTRING ';'
1628   auth_entry: IRCD_AUTH
1629   {
1630    if (conf_parser_ctx.pass == 2)
1631 <  {
1634 <    yy_conf = make_conf_item(CLIENT_TYPE);
1635 <    yy_aconf = map_to_conf(yy_conf);
1636 <  }
1637 <  else
1638 <  {
1639 <    MyFree(class_name);
1640 <    class_name = NULL;
1641 <  }
1631 >    reset_block_state();
1632   } '{' auth_items '}' ';'
1633   {
1634 <  if (conf_parser_ctx.pass == 2)
1645 <  {
1646 <    struct CollectItem *yy_tmp = NULL;
1647 <    dlink_node *ptr = NULL, *next_ptr = NULL;
1648 <
1649 <    if (yy_aconf->user && yy_aconf->host)
1650 <    {
1651 <      conf_add_class_to_conf(yy_conf, class_name);
1652 <      add_conf_by_address(CONF_CLIENT, yy_aconf);
1653 <    }
1654 <    else
1655 <      delete_conf_item(yy_conf);
1656 <
1657 <    /* copy over settings from first struct */
1658 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1659 <    {
1660 <      struct AccessItem *new_aconf;
1661 <      struct ConfItem *new_conf;
1662 <
1663 <      new_conf = make_conf_item(CLIENT_TYPE);
1664 <      new_aconf = map_to_conf(new_conf);
1634 >  dlink_node *ptr = NULL;
1635  
1636 <      yy_tmp = ptr->data;
1636 >  if (conf_parser_ctx.pass != 2)
1637 >    break;
1638  
1639 <      assert(yy_tmp->user && yy_tmp->host);
1640 <
1641 <      if (yy_aconf->passwd != NULL)
1642 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1672 <      if (yy_conf->name != NULL)
1673 <        DupString(new_conf->name, yy_conf->name);
1674 <      if (yy_aconf->passwd != NULL)
1675 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1639 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1640 >  {
1641 >    struct MaskItem *conf = NULL;
1642 >    struct split_nuh_item nuh;
1643  
1644 <      new_aconf->flags = yy_aconf->flags;
1645 <      new_aconf->port  = yy_aconf->port;
1644 >    nuh.nuhmask  = ptr->data;
1645 >    nuh.nickptr  = NULL;
1646 >    nuh.userptr  = block_state.user.buf;
1647 >    nuh.hostptr  = block_state.host.buf;
1648 >    nuh.nicksize = 0;
1649 >    nuh.usersize = sizeof(block_state.user.buf);
1650 >    nuh.hostsize = sizeof(block_state.host.buf);
1651 >    split_nuh(&nuh);
1652  
1653 <      DupString(new_aconf->user, yy_tmp->user);
1654 <      collapse(new_aconf->user);
1653 >    conf        = conf_make(CONF_CLIENT);
1654 >    conf->user  = xstrdup(block_state.user.buf);
1655 >    conf->host  = xstrdup(block_state.host.buf);
1656 >
1657 >    if (block_state.rpass.buf[0])
1658 >      conf->passwd = xstrdup(block_state.rpass.buf);
1659 >    if (block_state.name.buf[0])
1660 >      conf->name = xstrdup(block_state.name.buf);
1661  
1662 <      DupString(new_aconf->host, yy_tmp->host);
1663 <      collapse(new_aconf->host);
1662 >    conf->flags = block_state.flags.value;
1663 >    conf->port  = block_state.port.value;
1664  
1665 <      conf_add_class_to_conf(new_conf, class_name);
1666 <      add_conf_by_address(CONF_CLIENT, new_aconf);
1688 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1689 <      free_collect_item(yy_tmp);
1690 <    }
1691 <
1692 <    MyFree(class_name);
1693 <    class_name = NULL;
1694 <    yy_conf = NULL;
1695 <    yy_aconf = NULL;
1665 >    conf_add_class_to_conf(conf, block_state.class.buf);
1666 >    add_conf_by_address(CONF_CLIENT, conf);
1667    }
1668   };
1669  
# Line 1704 | Line 1675 | auth_item:      auth_user | auth_passwd
1675   auth_user: USER '=' QSTRING ';'
1676   {
1677    if (conf_parser_ctx.pass == 2)
1678 <  {
1708 <    struct CollectItem *yy_tmp = NULL;
1709 <    struct split_nuh_item nuh;
1710 <
1711 <    nuh.nuhmask  = yylval.string;
1712 <    nuh.nickptr  = NULL;
1713 <    nuh.userptr  = userbuf;
1714 <    nuh.hostptr  = hostbuf;
1715 <
1716 <    nuh.nicksize = 0;
1717 <    nuh.usersize = sizeof(userbuf);
1718 <    nuh.hostsize = sizeof(hostbuf);
1719 <
1720 <    split_nuh(&nuh);
1721 <
1722 <    if (yy_aconf->user == NULL)
1723 <    {
1724 <      DupString(yy_aconf->user, userbuf);
1725 <      DupString(yy_aconf->host, hostbuf);
1726 <    }
1727 <    else
1728 <    {
1729 <      yy_tmp = MyMalloc(sizeof(struct CollectItem));
1730 <
1731 <      DupString(yy_tmp->user, userbuf);
1732 <      DupString(yy_tmp->host, hostbuf);
1733 <
1734 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1735 <    }
1736 <  }
1678 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1679   };
1680  
1739 /* XXX - IP/IPV6 tags don't exist anymore - put IP/IPV6 into user. */
1740
1681   auth_passwd: PASSWORD '=' QSTRING ';'
1682   {
1683    if (conf_parser_ctx.pass == 2)
1684 <  {
1745 <    /* be paranoid */
1746 <    if (yy_aconf->passwd != NULL)
1747 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1748 <
1749 <    MyFree(yy_aconf->passwd);
1750 <    DupString(yy_aconf->passwd, yylval.string);
1751 <  }
1684 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1685   };
1686  
1687   auth_class: CLASS '=' QSTRING ';'
1688   {
1689    if (conf_parser_ctx.pass == 2)
1690 <  {
1758 <    MyFree(class_name);
1759 <    DupString(class_name, yylval.string);
1760 <  }
1690 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1691   };
1692  
1693   auth_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 1765 | Line 1695 | auth_encrypted: ENCRYPTED '=' TBOOL ';'
1695    if (conf_parser_ctx.pass == 2)
1696    {
1697      if (yylval.number)
1698 <      SetConfEncrypted(yy_aconf);
1698 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1699      else
1700 <      ClearConfEncrypted(yy_aconf);
1700 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1701    }
1702   };
1703  
1704   auth_flags: IRCD_FLAGS
1705   {
1706 +  if (conf_parser_ctx.pass == 2)
1707 +    block_state.flags.value &= (CONF_FLAGS_ENCRYPTED | CONF_FLAGS_SPOOF_IP);
1708   } '='  auth_flags_items ';';
1709  
1710   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
1711 < auth_flags_item: NOT { not_atom = 1; } auth_flags_item_atom
1780 <                | { not_atom = 0; } auth_flags_item_atom;
1781 <
1782 < auth_flags_item_atom: SPOOF_NOTICE
1711 > auth_flags_item: SPOOF_NOTICE
1712   {
1713    if (conf_parser_ctx.pass == 2)
1714 <  {
1786 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_SPOOF_NOTICE;
1787 <    else yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1788 <  }
1714 >    block_state.flags.value |= CONF_FLAGS_SPOOF_NOTICE;
1715   } | EXCEED_LIMIT
1716   {
1717    if (conf_parser_ctx.pass == 2)
1718 <  {
1793 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NOLIMIT;
1794 <    else yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
1795 <  }
1718 >    block_state.flags.value |= CONF_FLAGS_NOLIMIT;
1719   } | KLINE_EXEMPT
1720   {
1721    if (conf_parser_ctx.pass == 2)
1722 <  {
1800 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTKLINE;
1801 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
1802 <  }
1722 >    block_state.flags.value |= CONF_FLAGS_EXEMPTKLINE;
1723   } | NEED_IDENT
1724   {
1725    if (conf_parser_ctx.pass == 2)
1726 <  {
1807 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_IDENTD;
1808 <    else yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
1809 <  }
1726 >    block_state.flags.value |= CONF_FLAGS_NEED_IDENTD;
1727   } | CAN_FLOOD
1728   {
1729    if (conf_parser_ctx.pass == 2)
1730 <  {
1814 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_CAN_FLOOD;
1815 <    else yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
1816 <  }
1817 < } | CAN_IDLE
1818 < {
1819 <  if (conf_parser_ctx.pass == 2)
1820 <  {
1821 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_IDLE_LINED;
1822 <    else yy_aconf->flags |= CONF_FLAGS_IDLE_LINED;
1823 <  }
1730 >    block_state.flags.value |= CONF_FLAGS_CAN_FLOOD;
1731   } | NO_TILDE
1732   {
1733    if (conf_parser_ctx.pass == 2)
1734 <  {
1828 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NO_TILDE;
1829 <    else yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
1830 <  }
1734 >    block_state.flags.value |= CONF_FLAGS_NO_TILDE;
1735   } | GLINE_EXEMPT
1736   {
1737    if (conf_parser_ctx.pass == 2)
1738 <  {
1835 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTGLINE;
1836 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
1837 <  }
1738 >    block_state.flags.value |= CONF_FLAGS_EXEMPTGLINE;
1739   } | RESV_EXEMPT
1740   {
1741    if (conf_parser_ctx.pass == 2)
1742 <  {
1743 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTRESV;
1744 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTRESV;
1745 <  }
1742 >    block_state.flags.value |= CONF_FLAGS_EXEMPTRESV;
1743 > } | T_WEBIRC
1744 > {
1745 >  if (conf_parser_ctx.pass == 2)
1746 >    block_state.flags.value |= CONF_FLAGS_WEBIRC;
1747   } | NEED_PASSWORD
1748   {
1749    if (conf_parser_ctx.pass == 2)
1750 <  {
1849 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_PASSWORD;
1850 <    else yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
1851 <  }
1750 >    block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1751   };
1752  
1854 /* XXX - need check for illegal hostnames here */
1753   auth_spoof: SPOOF '=' QSTRING ';'
1754   {
1755 <  if (conf_parser_ctx.pass == 2)
1756 <  {
1859 <    MyFree(yy_conf->name);
1755 >  if (conf_parser_ctx.pass != 2)
1756 >    break;
1757  
1758 <    if (strlen(yylval.string) < HOSTLEN)
1759 <    {    
1760 <      DupString(yy_conf->name, yylval.string);
1761 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_IP;
1865 <    }
1866 <    else
1867 <    {
1868 <      ilog(L_ERROR, "Spoofs must be less than %d..ignoring it", HOSTLEN);
1869 <      yy_conf->name = NULL;
1870 <    }
1758 >  if (strlen(yylval.string) <= HOSTLEN && valid_hostname(yylval.string))
1759 >  {
1760 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1761 >    block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
1762    }
1763 +  else
1764 +    ilog(LOG_TYPE_IRCD, "Spoof either is too long or contains invalid characters. Ignoring it.");
1765   };
1766  
1767   auth_redir_serv: REDIRSERV '=' QSTRING ';'
1768   {
1769 <  if (conf_parser_ctx.pass == 2)
1770 <  {
1771 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1772 <    MyFree(yy_conf->name);
1773 <    DupString(yy_conf->name, yylval.string);
1881 <  }
1769 >  if (conf_parser_ctx.pass != 2)
1770 >    break;
1771 >
1772 >  strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1773 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1774   };
1775  
1776   auth_redir_port: REDIRPORT '=' NUMBER ';'
1777   {
1778 <  if (conf_parser_ctx.pass == 2)
1779 <  {
1780 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1781 <    yy_aconf->port = $3;
1782 <  }
1778 >  if (conf_parser_ctx.pass != 2)
1779 >    break;
1780 >
1781 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1782 >  block_state.port.value = $3;
1783   };
1784  
1785  
# Line 1896 | Line 1788 | auth_redir_port: REDIRPORT '=' NUMBER ';
1788   ***************************************************************************/
1789   resv_entry: RESV
1790   {
1791 <  if (conf_parser_ctx.pass == 2)
1792 <  {
1793 <    MyFree(resv_reason);
1794 <    resv_reason = NULL;
1795 <  }
1791 >  if (conf_parser_ctx.pass != 2)
1792 >    break;
1793 >
1794 >  reset_block_state();
1795 >  strlcpy(block_state.rpass.buf, CONF_NOREASON, sizeof(block_state.rpass.buf));
1796   } '{' resv_items '}' ';'
1797   {
1798 <  if (conf_parser_ctx.pass == 2)
1799 <  {
1800 <    MyFree(resv_reason);
1801 <    resv_reason = NULL;
1910 <  }
1798 >  if (conf_parser_ctx.pass != 2)
1799 >    break;
1800 >
1801 >  create_resv(block_state.name.buf, block_state.rpass.buf, &block_state.mask.list);
1802   };
1803  
1804   resv_items:     resv_items resv_item | resv_item;
1805 < resv_item:      resv_creason | resv_channel | resv_nick | error ';' ;
1805 > resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1806  
1807 < resv_creason: REASON '=' QSTRING ';'
1807 > resv_mask: MASK '=' QSTRING ';'
1808   {
1809    if (conf_parser_ctx.pass == 2)
1810 <  {
1920 <    MyFree(resv_reason);
1921 <    DupString(resv_reason, yylval.string);
1922 <  }
1810 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1811   };
1812  
1813 < resv_channel: CHANNEL '=' QSTRING ';'
1813 > resv_reason: REASON '=' QSTRING ';'
1814   {
1815    if (conf_parser_ctx.pass == 2)
1816 <  {
1929 <    if (IsChanPrefix(*yylval.string))
1930 <    {
1931 <      char def_reason[] = "No reason";
1932 <
1933 <      create_channel_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1934 <    }
1935 <  }
1936 <  /* ignore it for now.. but we really should make a warning if
1937 <   * its an erroneous name --fl_ */
1816 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1817   };
1818  
1819 < resv_nick: NICK '=' QSTRING ';'
1819 > resv_exempt: EXEMPT '=' QSTRING ';'
1820   {
1821    if (conf_parser_ctx.pass == 2)
1822 <  {
1823 <    char def_reason[] = "No reason";
1822 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1823 > };
1824 >
1825 >
1826 > /***************************************************************************
1827 > *  section service
1828 > ***************************************************************************/
1829 > service_entry: T_SERVICE '{' service_items '}' ';';
1830 >
1831 > service_items:     service_items service_item | service_item;
1832 > service_item:      service_name | error;
1833 >
1834 > service_name: NAME '=' QSTRING ';'
1835 > {
1836 >  if (conf_parser_ctx.pass != 2)
1837 >    break;
1838  
1839 <    create_nick_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1839 >  if (valid_servname(yylval.string))
1840 >  {
1841 >    struct MaskItem *conf = conf_make(CONF_SERVICE);
1842 >    conf->name = xstrdup(yylval.string);
1843    }
1844   };
1845  
# Line 1952 | Line 1848 | resv_nick: NICK '=' QSTRING ';'
1848   ***************************************************************************/
1849   shared_entry: T_SHARED
1850   {
1851 <  if (conf_parser_ctx.pass == 2)
1852 <  {
1853 <    yy_conf = make_conf_item(ULINE_TYPE);
1854 <    yy_match_item = map_to_conf(yy_conf);
1855 <    yy_match_item->action = SHARED_ALL;
1856 <  }
1851 >  if (conf_parser_ctx.pass != 2)
1852 >    break;
1853 >
1854 >  reset_block_state();
1855 >
1856 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1857 >  strlcpy(block_state.user.buf, "*", sizeof(block_state.user.buf));
1858 >  strlcpy(block_state.host.buf, "*", sizeof(block_state.host.buf));
1859 >  block_state.flags.value = SHARED_ALL;
1860   } '{' shared_items '}' ';'
1861   {
1862 <  if (conf_parser_ctx.pass == 2)
1863 <  {
1864 <    yy_conf = NULL;
1865 <  }
1862 >  struct MaskItem *conf = NULL;
1863 >
1864 >  if (conf_parser_ctx.pass != 2)
1865 >    break;
1866 >
1867 >  conf = conf_make(CONF_ULINE);
1868 >  conf->flags = block_state.flags.value;
1869 >  conf->name = xstrdup(block_state.name.buf);
1870 >  conf->user = xstrdup(block_state.user.buf);
1871 >  conf->host = xstrdup(block_state.host.buf);
1872   };
1873  
1874   shared_items: shared_items shared_item | shared_item;
# Line 1972 | Line 1877 | shared_item:  shared_name | shared_user
1877   shared_name: NAME '=' QSTRING ';'
1878   {
1879    if (conf_parser_ctx.pass == 2)
1880 <  {
1976 <    MyFree(yy_conf->name);
1977 <    DupString(yy_conf->name, yylval.string);
1978 <  }
1880 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1881   };
1882  
1883   shared_user: USER '=' QSTRING ';'
# Line 1986 | Line 1888 | shared_user: USER '=' QSTRING ';'
1888  
1889      nuh.nuhmask  = yylval.string;
1890      nuh.nickptr  = NULL;
1891 <    nuh.userptr  = userbuf;
1892 <    nuh.hostptr  = hostbuf;
1891 >    nuh.userptr  = block_state.user.buf;
1892 >    nuh.hostptr  = block_state.host.buf;
1893  
1894      nuh.nicksize = 0;
1895 <    nuh.usersize = sizeof(userbuf);
1896 <    nuh.hostsize = sizeof(hostbuf);
1895 >    nuh.usersize = sizeof(block_state.user.buf);
1896 >    nuh.hostsize = sizeof(block_state.host.buf);
1897  
1898      split_nuh(&nuh);
1997
1998    DupString(yy_match_item->user, userbuf);
1999    DupString(yy_match_item->host, hostbuf);
1899    }
1900   };
1901  
1902   shared_type: TYPE
1903   {
1904    if (conf_parser_ctx.pass == 2)
1905 <    yy_match_item->action = 0;
1905 >    block_state.flags.value = 0;
1906   } '=' shared_types ';' ;
1907  
1908   shared_types: shared_types ',' shared_type_item | shared_type_item;
1909   shared_type_item: KLINE
1910   {
1911    if (conf_parser_ctx.pass == 2)
1912 <    yy_match_item->action |= SHARED_KLINE;
1913 < } | TKLINE
1912 >    block_state.flags.value |= SHARED_KLINE;
1913 > } | UNKLINE
1914   {
1915    if (conf_parser_ctx.pass == 2)
1916 <    yy_match_item->action |= SHARED_TKLINE;
1917 < } | UNKLINE
1916 >    block_state.flags.value |= SHARED_UNKLINE;
1917 > } | T_DLINE
1918   {
1919    if (conf_parser_ctx.pass == 2)
1920 <    yy_match_item->action |= SHARED_UNKLINE;
1921 < } | XLINE
1920 >    block_state.flags.value |= SHARED_DLINE;
1921 > } | T_UNDLINE
1922   {
1923    if (conf_parser_ctx.pass == 2)
1924 <    yy_match_item->action |= SHARED_XLINE;
1925 < } | TXLINE
1924 >    block_state.flags.value |= SHARED_UNDLINE;
1925 > } | XLINE
1926   {
1927    if (conf_parser_ctx.pass == 2)
1928 <    yy_match_item->action |= SHARED_TXLINE;
1928 >    block_state.flags.value |= SHARED_XLINE;
1929   } | T_UNXLINE
1930   {
1931    if (conf_parser_ctx.pass == 2)
1932 <    yy_match_item->action |= SHARED_UNXLINE;
1932 >    block_state.flags.value |= SHARED_UNXLINE;
1933   } | RESV
1934   {
1935    if (conf_parser_ctx.pass == 2)
1936 <    yy_match_item->action |= SHARED_RESV;
2038 < } | TRESV
2039 < {
2040 <  if (conf_parser_ctx.pass == 2)
2041 <    yy_match_item->action |= SHARED_TRESV;
1936 >    block_state.flags.value |= SHARED_RESV;
1937   } | T_UNRESV
1938   {
1939    if (conf_parser_ctx.pass == 2)
1940 <    yy_match_item->action |= SHARED_UNRESV;
1940 >    block_state.flags.value |= SHARED_UNRESV;
1941   } | T_LOCOPS
1942   {
1943    if (conf_parser_ctx.pass == 2)
1944 <    yy_match_item->action |= SHARED_LOCOPS;
1944 >    block_state.flags.value |= SHARED_LOCOPS;
1945   } | T_ALL
1946   {
1947    if (conf_parser_ctx.pass == 2)
1948 <    yy_match_item->action = SHARED_ALL;
1948 >    block_state.flags.value = SHARED_ALL;
1949   };
1950  
1951   /***************************************************************************
# Line 2058 | Line 1953 | shared_type_item: KLINE
1953   ***************************************************************************/
1954   cluster_entry: T_CLUSTER
1955   {
1956 <  if (conf_parser_ctx.pass == 2)
1957 <  {
1958 <    yy_conf = make_conf_item(CLUSTER_TYPE);
1959 <    yy_conf->flags = SHARED_ALL;
1960 <  }
1956 >  if (conf_parser_ctx.pass != 2)
1957 >    break;
1958 >
1959 >  reset_block_state();
1960 >
1961 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1962 >  block_state.flags.value = SHARED_ALL;
1963   } '{' cluster_items '}' ';'
1964   {
1965 <  if (conf_parser_ctx.pass == 2)
1966 <  {
1967 <    if (yy_conf->name == NULL)
1968 <      DupString(yy_conf->name, "*");
1969 <    yy_conf = NULL;
1970 <  }
1965 >  struct MaskItem *conf = NULL;
1966 >
1967 >  if (conf_parser_ctx.pass != 2)
1968 >    break;
1969 >
1970 >  conf = conf_make(CONF_CLUSTER);
1971 >  conf->flags = block_state.flags.value;
1972 >  conf->name = xstrdup(block_state.name.buf);
1973   };
1974  
1975   cluster_items:  cluster_items cluster_item | cluster_item;
# Line 2079 | Line 1978 | cluster_item:  cluster_name | cluster_typ
1978   cluster_name: NAME '=' QSTRING ';'
1979   {
1980    if (conf_parser_ctx.pass == 2)
1981 <    DupString(yy_conf->name, yylval.string);
1981 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1982   };
1983  
1984   cluster_type: TYPE
1985   {
1986    if (conf_parser_ctx.pass == 2)
1987 <    yy_conf->flags = 0;
1987 >    block_state.flags.value = 0;
1988   } '=' cluster_types ';' ;
1989  
1990   cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
1991   cluster_type_item: KLINE
1992   {
1993    if (conf_parser_ctx.pass == 2)
1994 <    yy_conf->flags |= SHARED_KLINE;
1995 < } | TKLINE
1994 >    block_state.flags.value |= SHARED_KLINE;
1995 > } | UNKLINE
1996   {
1997    if (conf_parser_ctx.pass == 2)
1998 <    yy_conf->flags |= SHARED_TKLINE;
1999 < } | UNKLINE
1998 >    block_state.flags.value |= SHARED_UNKLINE;
1999 > } | T_DLINE
2000   {
2001    if (conf_parser_ctx.pass == 2)
2002 <    yy_conf->flags |= SHARED_UNKLINE;
2003 < } | XLINE
2002 >    block_state.flags.value |= SHARED_DLINE;
2003 > } | T_UNDLINE
2004   {
2005    if (conf_parser_ctx.pass == 2)
2006 <    yy_conf->flags |= SHARED_XLINE;
2007 < } | TXLINE
2006 >    block_state.flags.value |= SHARED_UNDLINE;
2007 > } | XLINE
2008   {
2009    if (conf_parser_ctx.pass == 2)
2010 <    yy_conf->flags |= SHARED_TXLINE;
2010 >    block_state.flags.value |= SHARED_XLINE;
2011   } | T_UNXLINE
2012   {
2013    if (conf_parser_ctx.pass == 2)
2014 <    yy_conf->flags |= SHARED_UNXLINE;
2014 >    block_state.flags.value |= SHARED_UNXLINE;
2015   } | RESV
2016   {
2017    if (conf_parser_ctx.pass == 2)
2018 <    yy_conf->flags |= SHARED_RESV;
2120 < } | TRESV
2121 < {
2122 <  if (conf_parser_ctx.pass == 2)
2123 <    yy_conf->flags |= SHARED_TRESV;
2018 >    block_state.flags.value |= SHARED_RESV;
2019   } | T_UNRESV
2020   {
2021    if (conf_parser_ctx.pass == 2)
2022 <    yy_conf->flags |= SHARED_UNRESV;
2022 >    block_state.flags.value |= SHARED_UNRESV;
2023   } | T_LOCOPS
2024   {
2025    if (conf_parser_ctx.pass == 2)
2026 <    yy_conf->flags |= SHARED_LOCOPS;
2026 >    block_state.flags.value |= SHARED_LOCOPS;
2027   } | T_ALL
2028   {
2029    if (conf_parser_ctx.pass == 2)
2030 <    yy_conf->flags = SHARED_ALL;
2030 >    block_state.flags.value = SHARED_ALL;
2031   };
2032  
2033   /***************************************************************************
# Line 2140 | Line 2035 | cluster_type_item: KLINE
2035   ***************************************************************************/
2036   connect_entry: CONNECT  
2037   {
2143  if (conf_parser_ctx.pass == 2)
2144  {
2145    yy_conf = make_conf_item(SERVER_TYPE);
2146    yy_aconf = (struct AccessItem *)map_to_conf(yy_conf);
2147    yy_aconf->passwd = NULL;
2148    /* defaults */
2149    yy_aconf->port = PORTNUM;
2038  
2039 <    if (ConfigFileEntry.burst_away)
2040 <      yy_aconf->flags = CONF_FLAGS_BURST_AWAY;
2153 <  }
2154 <  else
2155 <  {
2156 <    MyFree(class_name);
2157 <    class_name = NULL;
2158 <  }
2159 < } connect_name_b '{' connect_items '}' ';'
2160 < {
2161 <  if (conf_parser_ctx.pass == 2)
2162 <  {
2163 <    struct CollectItem *yy_hconf=NULL;
2164 <    struct CollectItem *yy_lconf=NULL;
2165 <    dlink_node *ptr;
2166 <    dlink_node *next_ptr;
2167 < #ifdef HAVE_LIBCRYPTO
2168 <    if (yy_aconf->host &&
2169 <        ((yy_aconf->passwd && yy_aconf->spasswd) ||
2170 <         (yy_aconf->rsa_public_key && IsConfCryptLink(yy_aconf))))
2171 < #else /* !HAVE_LIBCRYPTO */
2172 <      if (yy_aconf->host && !IsConfCryptLink(yy_aconf) &&
2173 <          yy_aconf->passwd && yy_aconf->spasswd)
2174 < #endif /* !HAVE_LIBCRYPTO */
2175 <        {
2176 <          if (conf_add_server(yy_conf, class_name) == -1)
2177 <          {
2178 <            delete_conf_item(yy_conf);
2179 <            yy_conf = NULL;
2180 <            yy_aconf = NULL;
2181 <          }
2182 <        }
2183 <        else
2184 <        {
2185 <          /* Even if yy_conf ->name is NULL
2186 <           * should still unhook any hub/leaf confs still pending
2187 <           */
2188 <          unhook_hub_leaf_confs();
2189 <
2190 <          if (yy_conf->name != NULL)
2191 <          {
2192 < #ifndef HAVE_LIBCRYPTO
2193 <            if (IsConfCryptLink(yy_aconf))
2194 <              yyerror("Ignoring connect block -- no OpenSSL support");
2195 < #else
2196 <            if (IsConfCryptLink(yy_aconf) && !yy_aconf->rsa_public_key)
2197 <              yyerror("Ignoring connect block -- missing key");
2198 < #endif
2199 <            if (yy_aconf->host == NULL)
2200 <              yyerror("Ignoring connect block -- missing host");
2201 <            else if (!IsConfCryptLink(yy_aconf) &&
2202 <                    (!yy_aconf->passwd || !yy_aconf->spasswd))
2203 <              yyerror("Ignoring connect block -- missing password");
2204 <          }
2205 <
2206 <
2207 <          /* XXX
2208 <           * This fixes a try_connections() core (caused by invalid class_ptr
2209 <           * pointers) reported by metalrock. That's an ugly fix, but there
2210 <           * is currently no better way. The entire config subsystem needs an
2211 <           * rewrite ASAP. make_conf_item() shouldn't really add things onto
2212 <           * a doubly linked list immediately without any sanity checks!  -Michael
2213 <           */
2214 <          delete_conf_item(yy_conf);
2215 <
2216 <          yy_aconf = NULL;
2217 <          yy_conf = NULL;
2218 <        }
2219 <
2220 <      /*
2221 <       * yy_conf is still pointing at the server that is having
2222 <       * a connect block built for it. This means, y_aconf->name
2223 <       * points to the actual irc name this server will be known as.
2224 <       * Now this new server has a set or even just one hub_mask (or leaf_mask)
2225 <       * given in the link list at yy_hconf. Fill in the HUB confs
2226 <       * from this link list now.
2227 <       */        
2228 <      DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
2229 <      {
2230 <        struct ConfItem *new_hub_conf;
2231 <        struct MatchItem *match_item;
2039 >  if (conf_parser_ctx.pass != 2)
2040 >    break;
2041  
2042 <        yy_hconf = ptr->data;
2042 >  reset_block_state();
2043 >  block_state.port.value = PORTNUM;
2044 > } '{' connect_items '}' ';'
2045 > {
2046 >  struct MaskItem *conf = NULL;
2047 >  struct addrinfo hints, *res;
2048 >
2049 >  if (conf_parser_ctx.pass != 2)
2050 >    break;
2051 >
2052 >  if (!block_state.name.buf[0] ||
2053 >      !block_state.host.buf[0])
2054 >    break;
2055 >
2056 >  if (!block_state.rpass.buf[0] ||
2057 >      !block_state.spass.buf[0])
2058 >    break;
2059 >
2060 >  if (has_wildcards(block_state.name.buf) ||
2061 >      has_wildcards(block_state.host.buf))
2062 >    break;
2063 >
2064 >  conf = conf_make(CONF_SERVER);
2065 >  conf->port = block_state.port.value;
2066 >  conf->flags = block_state.flags.value;
2067 >  conf->aftype = block_state.aftype.value;
2068 >  conf->host = xstrdup(block_state.host.buf);
2069 >  conf->name = xstrdup(block_state.name.buf);
2070 >  conf->passwd = xstrdup(block_state.rpass.buf);
2071 >  conf->spasswd = xstrdup(block_state.spass.buf);
2072 >
2073 >  if (block_state.cert.buf[0])
2074 >    conf->certfp = xstrdup(block_state.cert.buf);
2075  
2076 <        /* yy_conf == NULL is a fatal error for this connect block! */
2077 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2237 <        {
2238 <          new_hub_conf = make_conf_item(HUB_TYPE);
2239 <          match_item = (struct MatchItem *)map_to_conf(new_hub_conf);
2240 <          DupString(new_hub_conf->name, yy_conf->name);
2241 <          if (yy_hconf->user != NULL)
2242 <            DupString(match_item->user, yy_hconf->user);
2243 <          else
2244 <            DupString(match_item->user, "*");
2245 <          if (yy_hconf->host != NULL)
2246 <            DupString(match_item->host, yy_hconf->host);
2247 <          else
2248 <            DupString(match_item->host, "*");
2249 <        }
2250 <        dlinkDelete(&yy_hconf->node, &hub_conf_list);
2251 <        free_collect_item(yy_hconf);
2252 <      }
2076 >  if (block_state.ciph.buf[0])
2077 >    conf->cipher_list = xstrdup(block_state.ciph.buf);
2078  
2079 <      /* Ditto for the LEAF confs */
2079 >  dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
2080 >  dlinkMoveList(&block_state.hub.list, &conf->hub_list);
2081  
2082 <      DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
2083 <      {
2084 <        struct ConfItem *new_leaf_conf;
2259 <        struct MatchItem *match_item;
2082 >  if (block_state.bind.buf[0])
2083 >  {
2084 >    memset(&hints, 0, sizeof(hints));
2085  
2086 <        yy_lconf = ptr->data;
2086 >    hints.ai_family   = AF_UNSPEC;
2087 >    hints.ai_socktype = SOCK_STREAM;
2088 >    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2089  
2090 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2091 <        {
2092 <          new_leaf_conf = make_conf_item(LEAF_TYPE);
2093 <          match_item = (struct MatchItem *)map_to_conf(new_leaf_conf);
2094 <          DupString(new_leaf_conf->name, yy_conf->name);
2095 <          if (yy_lconf->user != NULL)
2096 <            DupString(match_item->user, yy_lconf->user);
2097 <          else
2098 <            DupString(match_item->user, "*");
2099 <          if (yy_lconf->host != NULL)
2100 <            DupString(match_item->host, yy_lconf->host);
2274 <          else
2275 <            DupString(match_item->host, "*");
2276 <        }
2277 <        dlinkDelete(&yy_lconf->node, &leaf_conf_list);
2278 <        free_collect_item(yy_lconf);
2279 <      }
2280 <      MyFree(class_name);
2281 <      class_name = NULL;
2282 <      yy_conf = NULL;
2283 <      yy_aconf = NULL;
2090 >    if (getaddrinfo(block_state.bind.buf, NULL, &hints, &res))
2091 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
2092 >    else
2093 >    {
2094 >      assert(res != NULL);
2095 >
2096 >      memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
2097 >      conf->bind.ss.ss_family = res->ai_family;
2098 >      conf->bind.ss_len = res->ai_addrlen;
2099 >      freeaddrinfo(res);
2100 >    }
2101    }
2102 +
2103 +  conf_add_class_to_conf(conf, block_state.class.buf);
2104 +  lookup_confhost(conf);
2105   };
2106  
2287 connect_name_b: | connect_name_t;
2107   connect_items:  connect_items connect_item | connect_item;
2108   connect_item:   connect_name | connect_host | connect_vhost |
2109                  connect_send_password | connect_accept_password |
2110 <                connect_aftype | connect_port |
2110 >                connect_ssl_certificate_fingerprint |
2111 >                connect_aftype | connect_port | connect_ssl_cipher_list |
2112                  connect_flags | connect_hub_mask | connect_leaf_mask |
2113 <                connect_class | connect_encrypted |
2294 <                connect_rsa_public_key_file | connect_cipher_preference |
2113 >                connect_class | connect_encrypted |
2114                  error ';' ;
2115  
2116   connect_name: NAME '=' QSTRING ';'
2117   {
2118    if (conf_parser_ctx.pass == 2)
2119 <  {
2301 <    if (yy_conf->name != NULL)
2302 <      yyerror("Multiple connect name entry");
2303 <
2304 <    MyFree(yy_conf->name);
2305 <    DupString(yy_conf->name, yylval.string);
2306 <  }
2307 < };
2308 <
2309 < connect_name_t: QSTRING
2310 < {
2311 <  if (conf_parser_ctx.pass == 2)
2312 <  {
2313 <    if (yy_conf->name != NULL)
2314 <      yyerror("Multiple connect name entry");
2315 <
2316 <    MyFree(yy_conf->name);
2317 <    DupString(yy_conf->name, yylval.string);
2318 <  }
2119 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2120   };
2121  
2122   connect_host: HOST '=' QSTRING ';'
2123   {
2124    if (conf_parser_ctx.pass == 2)
2125 <  {
2325 <    MyFree(yy_aconf->host);
2326 <    DupString(yy_aconf->host, yylval.string);
2327 <  }
2125 >    strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
2126   };
2127  
2128   connect_vhost: VHOST '=' QSTRING ';'
2129   {
2130    if (conf_parser_ctx.pass == 2)
2131 <  {
2334 <    struct addrinfo hints, *res;
2335 <
2336 <    memset(&hints, 0, sizeof(hints));
2337 <
2338 <    hints.ai_family   = AF_UNSPEC;
2339 <    hints.ai_socktype = SOCK_STREAM;
2340 <    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2341 <
2342 <    if (getaddrinfo(yylval.string, NULL, &hints, &res))
2343 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
2344 <    else
2345 <    {
2346 <      assert(res != NULL);
2347 <
2348 <      memcpy(&yy_aconf->my_ipnum, res->ai_addr, res->ai_addrlen);
2349 <      yy_aconf->my_ipnum.ss.ss_family = res->ai_family;
2350 <      yy_aconf->my_ipnum.ss_len = res->ai_addrlen;
2351 <      freeaddrinfo(res);
2352 <    }
2353 <  }
2131 >    strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
2132   };
2133  
2134   connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2135   {
2136 <  if (conf_parser_ctx.pass == 2)
2137 <  {
2360 <    if ($3[0] == ':')
2361 <      yyerror("Server passwords cannot begin with a colon");
2362 <    else if (strchr($3, ' ') != NULL)
2363 <      yyerror("Server passwords cannot contain spaces");
2364 <    else {
2365 <      if (yy_aconf->spasswd != NULL)
2366 <        memset(yy_aconf->spasswd, 0, strlen(yy_aconf->spasswd));
2136 >  if (conf_parser_ctx.pass != 2)
2137 >    break;
2138  
2139 <      MyFree(yy_aconf->spasswd);
2140 <      DupString(yy_aconf->spasswd, yylval.string);
2141 <    }
2142 <  }
2139 >  if ($3[0] == ':')
2140 >    conf_error_report("Server passwords cannot begin with a colon");
2141 >  else if (strchr($3, ' ') != NULL)
2142 >    conf_error_report("Server passwords cannot contain spaces");
2143 >  else
2144 >    strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
2145   };
2146  
2147   connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2148   {
2149 <  if (conf_parser_ctx.pass == 2)
2150 <  {
2378 <    if ($3[0] == ':')
2379 <      yyerror("Server passwords cannot begin with a colon");
2380 <    else if (strchr($3, ' ') != NULL)
2381 <      yyerror("Server passwords cannot contain spaces");
2382 <    else {
2383 <      if (yy_aconf->passwd != NULL)
2384 <        memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
2149 >  if (conf_parser_ctx.pass != 2)
2150 >    break;
2151  
2152 <      MyFree(yy_aconf->passwd);
2153 <      DupString(yy_aconf->passwd, yylval.string);
2154 <    }
2155 <  }
2152 >  if ($3[0] == ':')
2153 >    conf_error_report("Server passwords cannot begin with a colon");
2154 >  else if (strchr($3, ' ') != NULL)
2155 >    conf_error_report("Server passwords cannot contain spaces");
2156 >  else
2157 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2158 > };
2159 >
2160 > connect_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
2161 > {
2162 >  if (conf_parser_ctx.pass == 2)
2163 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
2164   };
2165  
2166   connect_port: PORT '=' NUMBER ';'
2167   {
2168    if (conf_parser_ctx.pass == 2)
2169 <    yy_aconf->port = $3;
2169 >    block_state.port.value = $3;
2170   };
2171  
2172   connect_aftype: AFTYPE '=' T_IPV4 ';'
2173   {
2174    if (conf_parser_ctx.pass == 2)
2175 <    yy_aconf->aftype = AF_INET;
2175 >    block_state.aftype.value = AF_INET;
2176   } | AFTYPE '=' T_IPV6 ';'
2177   {
2178   #ifdef IPV6
2179    if (conf_parser_ctx.pass == 2)
2180 <    yy_aconf->aftype = AF_INET6;
2180 >    block_state.aftype.value = AF_INET6;
2181   #endif
2182   };
2183  
2184   connect_flags: IRCD_FLAGS
2185   {
2186 +  block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
2187   } '='  connect_flags_items ';';
2188  
2189   connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
2190 < connect_flags_item: NOT  { not_atom = 1; } connect_flags_item_atom
2416 <                        |  { not_atom = 0; } connect_flags_item_atom;
2417 <
2418 < connect_flags_item_atom: COMPRESSED
2419 < {
2420 <  if (conf_parser_ctx.pass == 2)
2421 < #ifndef HAVE_LIBZ
2422 <    yyerror("Ignoring flags = compressed; -- no zlib support");
2423 < #else
2424 < {
2425 <   if (not_atom)ClearConfCompressed(yy_aconf);
2426 <   else SetConfCompressed(yy_aconf);
2427 < }
2428 < #endif
2429 < } | CRYPTLINK
2430 < {
2431 <  if (conf_parser_ctx.pass == 2)
2432 <  {
2433 <    if (not_atom)ClearConfCryptLink(yy_aconf);
2434 <    else SetConfCryptLink(yy_aconf);
2435 <  }
2436 < } | AUTOCONN
2437 < {
2438 <  if (conf_parser_ctx.pass == 2)
2439 <  {
2440 <    if (not_atom)ClearConfAllowAutoConn(yy_aconf);
2441 <    else SetConfAllowAutoConn(yy_aconf);
2442 <  }
2443 < } | BURST_AWAY
2190 > connect_flags_item: AUTOCONN
2191   {
2192    if (conf_parser_ctx.pass == 2)
2193 <  {
2194 <    if (not_atom)ClearConfAwayBurst(yy_aconf);
2448 <    else SetConfAwayBurst(yy_aconf);
2449 <  }
2450 < } | TOPICBURST
2193 >    block_state.flags.value |= CONF_FLAGS_ALLOW_AUTO_CONN;
2194 > } | T_SSL
2195   {
2196    if (conf_parser_ctx.pass == 2)
2197 <  {
2454 <    if (not_atom)ClearConfTopicBurst(yy_aconf);
2455 <    else SetConfTopicBurst(yy_aconf);
2456 <  }
2457 < }
2458 < ;
2459 <
2460 < connect_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
2461 < {
2462 < #ifdef HAVE_LIBCRYPTO
2463 <  if (conf_parser_ctx.pass == 2)
2464 <  {
2465 <    BIO *file;
2466 <
2467 <    if (yy_aconf->rsa_public_key != NULL)
2468 <    {
2469 <      RSA_free(yy_aconf->rsa_public_key);
2470 <      yy_aconf->rsa_public_key = NULL;
2471 <    }
2472 <
2473 <    if (yy_aconf->rsa_public_key_file != NULL)
2474 <    {
2475 <      MyFree(yy_aconf->rsa_public_key_file);
2476 <      yy_aconf->rsa_public_key_file = NULL;
2477 <    }
2478 <
2479 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
2480 <
2481 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
2482 <    {
2483 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
2484 <      break;
2485 <    }
2486 <
2487 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
2488 <
2489 <    if (yy_aconf->rsa_public_key == NULL)
2490 <    {
2491 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
2492 <      break;
2493 <    }
2494 <      
2495 <    BIO_set_close(file, BIO_CLOSE);
2496 <    BIO_free(file);
2497 <  }
2498 < #endif /* HAVE_LIBCRYPTO */
2197 >    block_state.flags.value |= CONF_FLAGS_SSL;
2198   };
2199  
2200   connect_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 2503 | Line 2202 | connect_encrypted: ENCRYPTED '=' TBOOL '
2202    if (conf_parser_ctx.pass == 2)
2203    {
2204      if (yylval.number)
2205 <      yy_aconf->flags |= CONF_FLAGS_ENCRYPTED;
2205 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
2206      else
2207 <      yy_aconf->flags &= ~CONF_FLAGS_ENCRYPTED;
2207 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
2208    }
2209   };
2210  
2211   connect_hub_mask: HUB_MASK '=' QSTRING ';'
2212   {
2213    if (conf_parser_ctx.pass == 2)
2214 <  {
2516 <    struct CollectItem *yy_tmp;
2517 <
2518 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2519 <    DupString(yy_tmp->host, yylval.string);
2520 <    DupString(yy_tmp->user, "*");
2521 <    dlinkAdd(yy_tmp, &yy_tmp->node, &hub_conf_list);
2522 <  }
2214 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
2215   };
2216  
2217   connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2218   {
2219    if (conf_parser_ctx.pass == 2)
2220 <  {
2529 <    struct CollectItem *yy_tmp;
2530 <
2531 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2532 <    DupString(yy_tmp->host, yylval.string);
2533 <    DupString(yy_tmp->user, "*");
2534 <    dlinkAdd(yy_tmp, &yy_tmp->node, &leaf_conf_list);
2535 <  }
2220 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
2221   };
2222  
2223   connect_class: CLASS '=' QSTRING ';'
2224   {
2225    if (conf_parser_ctx.pass == 2)
2226 <  {
2542 <    MyFree(class_name);
2543 <    DupString(class_name, yylval.string);
2544 <  }
2226 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
2227   };
2228  
2229 < connect_cipher_preference: CIPHER_PREFERENCE '=' QSTRING ';'
2229 > connect_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
2230   {
2231   #ifdef HAVE_LIBCRYPTO
2232    if (conf_parser_ctx.pass == 2)
2233 <  {
2552 <    struct EncCapability *ecap;
2553 <    const char *cipher_name;
2554 <    int found = 0;
2555 <
2556 <    yy_aconf->cipher_preference = NULL;
2557 <    cipher_name = yylval.string;
2558 <
2559 <    for (ecap = CipherTable; ecap->name; ecap++)
2560 <    {
2561 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
2562 <          (ecap->cap & CAP_ENC_MASK))
2563 <      {
2564 <        yy_aconf->cipher_preference = ecap;
2565 <        found = 1;
2566 <        break;
2567 <      }
2568 <    }
2569 <
2570 <    if (!found)
2571 <      yyerror("Invalid cipher");
2572 <  }
2233 >    strlcpy(block_state.ciph.buf, yylval.string, sizeof(block_state.ciph.buf));
2234   #else
2235    if (conf_parser_ctx.pass == 2)
2236 <    yyerror("Ignoring cipher_preference -- no OpenSSL support");
2236 >    conf_error_report("Ignoring connect::ciphers -- no OpenSSL support");
2237   #endif
2238   };
2239  
2240 +
2241   /***************************************************************************
2242   *  section kill
2243   ***************************************************************************/
2244   kill_entry: KILL
2245   {
2246    if (conf_parser_ctx.pass == 2)
2247 <  {
2586 <    userbuf[0] = hostbuf[0] = reasonbuf[0] = '\0';
2587 <    regex_ban = 0;
2588 <  }
2247 >    reset_block_state();
2248   } '{' kill_items '}' ';'
2249   {
2250 <  if (conf_parser_ctx.pass == 2)
2592 <  {
2593 <    if (userbuf[0] && hostbuf[0])
2594 <    {
2595 <      if (regex_ban)
2596 <      {
2597 < #ifdef HAVE_LIBPCRE
2598 <        void *exp_user = NULL;
2599 <        void *exp_host = NULL;
2600 <        const char *errptr = NULL;
2601 <
2602 <        if (!(exp_user = ircd_pcre_compile(userbuf, &errptr)) ||
2603 <            !(exp_host = ircd_pcre_compile(hostbuf, &errptr)))
2604 <        {
2605 <          ilog(L_ERROR, "Failed to add regular expression based K-Line: %s",
2606 <               errptr);
2607 <          break;
2608 <        }
2609 <
2610 <        yy_aconf = map_to_conf(make_conf_item(RKLINE_TYPE));
2611 <        yy_aconf->regexuser = exp_user;
2612 <        yy_aconf->regexhost = exp_host;
2613 <
2614 <        DupString(yy_aconf->user, userbuf);
2615 <        DupString(yy_aconf->host, hostbuf);
2250 >  struct MaskItem *conf = NULL;
2251  
2252 <        if (reasonbuf[0])
2253 <          DupString(yy_aconf->reason, reasonbuf);
2619 <        else
2620 <          DupString(yy_aconf->reason, "No reason");
2621 < #else
2622 <        ilog(L_ERROR, "Failed to add regular expression based K-Line: no PCRE support");
2623 <        break;
2624 < #endif
2625 <      }
2626 <      else
2627 <      {
2628 <        yy_aconf = map_to_conf(make_conf_item(KLINE_TYPE));
2252 >  if (conf_parser_ctx.pass != 2)
2253 >    break;
2254  
2255 <        DupString(yy_aconf->user, userbuf);
2256 <        DupString(yy_aconf->host, hostbuf);
2255 >  if (!block_state.user.buf[0] ||
2256 >      !block_state.host.buf[0])
2257 >    break;
2258  
2259 <        if (reasonbuf[0])
2260 <          DupString(yy_aconf->reason, reasonbuf);
2261 <        else
2636 <          DupString(yy_aconf->reason, "No reason");
2637 <        add_conf_by_address(CONF_KILL, yy_aconf);
2638 <      }
2639 <    }
2259 >  conf = conf_make(CONF_KLINE);
2260 >  conf->user = xstrdup(block_state.user.buf);
2261 >  conf->host = xstrdup(block_state.host.buf);
2262  
2263 <    yy_aconf = NULL;
2264 <  }
2263 >  if (block_state.rpass.buf[0])
2264 >    conf->reason = xstrdup(block_state.rpass.buf);
2265 >  else
2266 >    conf->reason = xstrdup(CONF_NOREASON);
2267 >  add_conf_by_address(CONF_KLINE, conf);
2268   };
2269  
2645 kill_type: TYPE
2646 {
2647 } '='  kill_type_items ';';
2648
2649 kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2650 kill_type_item: REGEX_T
2651 {
2652  if (conf_parser_ctx.pass == 2)
2653    regex_ban = 1;
2654 };
2655
2270   kill_items:     kill_items kill_item | kill_item;
2271 < kill_item:      kill_user | kill_reason | kill_type | error;
2271 > kill_item:      kill_user | kill_reason | error;
2272  
2273   kill_user: USER '=' QSTRING ';'
2274   {
2275 +
2276    if (conf_parser_ctx.pass == 2)
2277    {
2278      struct split_nuh_item nuh;
2279  
2280      nuh.nuhmask  = yylval.string;
2281      nuh.nickptr  = NULL;
2282 <    nuh.userptr  = userbuf;
2283 <    nuh.hostptr  = hostbuf;
2282 >    nuh.userptr  = block_state.user.buf;
2283 >    nuh.hostptr  = block_state.host.buf;
2284  
2285      nuh.nicksize = 0;
2286 <    nuh.usersize = sizeof(userbuf);
2287 <    nuh.hostsize = sizeof(hostbuf);
2286 >    nuh.usersize = sizeof(block_state.user.buf);
2287 >    nuh.hostsize = sizeof(block_state.host.buf);
2288  
2289      split_nuh(&nuh);
2290    }
# Line 2678 | Line 2293 | kill_user: USER '=' QSTRING ';'
2293   kill_reason: REASON '=' QSTRING ';'
2294   {
2295    if (conf_parser_ctx.pass == 2)
2296 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2296 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2297   };
2298  
2299   /***************************************************************************
# Line 2687 | Line 2302 | kill_reason: REASON '=' QSTRING ';'
2302   deny_entry: DENY
2303   {
2304    if (conf_parser_ctx.pass == 2)
2305 <    hostbuf[0] = reasonbuf[0] = '\0';
2305 >    reset_block_state();
2306   } '{' deny_items '}' ';'
2307   {
2308 <  if (conf_parser_ctx.pass == 2)
2308 >  struct MaskItem *conf = NULL;
2309 >
2310 >  if (conf_parser_ctx.pass != 2)
2311 >    break;
2312 >
2313 >  if (!block_state.addr.buf[0])
2314 >    break;
2315 >
2316 >  if (parse_netmask(block_state.addr.buf, NULL, NULL) != HM_HOST)
2317    {
2318 <    if (hostbuf[0] && parse_netmask(hostbuf, NULL, NULL) != HM_HOST)
2319 <    {
2697 <      yy_aconf = map_to_conf(make_conf_item(DLINE_TYPE));
2698 <      DupString(yy_aconf->host, hostbuf);
2318 >    conf = conf_make(CONF_DLINE);
2319 >    conf->host = xstrdup(block_state.addr.buf);
2320  
2321 <      if (reasonbuf[0])
2322 <        DupString(yy_aconf->reason, reasonbuf);
2323 <      else
2324 <        DupString(yy_aconf->reason, "No reason");
2325 <      add_conf_by_address(CONF_DLINE, yy_aconf);
2705 <      yy_aconf = NULL;
2706 <    }
2321 >    if (block_state.rpass.buf[0])
2322 >      conf->reason = xstrdup(block_state.rpass.buf);
2323 >    else
2324 >      conf->reason = xstrdup(CONF_NOREASON);
2325 >    add_conf_by_address(CONF_DLINE, conf);
2326    }
2327   };
2328  
# Line 2713 | Line 2332 | deny_item:      deny_ip | deny_reason |
2332   deny_ip: IP '=' QSTRING ';'
2333   {
2334    if (conf_parser_ctx.pass == 2)
2335 <    strlcpy(hostbuf, yylval.string, sizeof(hostbuf));
2335 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2336   };
2337  
2338   deny_reason: REASON '=' QSTRING ';'
2339   {
2340    if (conf_parser_ctx.pass == 2)
2341 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2341 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2342   };
2343  
2344   /***************************************************************************
# Line 2736 | Line 2355 | exempt_ip: IP '=' QSTRING ';'
2355    {
2356      if (yylval.string[0] && parse_netmask(yylval.string, NULL, NULL) != HM_HOST)
2357      {
2358 <      yy_aconf = map_to_conf(make_conf_item(EXEMPTDLINE_TYPE));
2359 <      DupString(yy_aconf->host, yylval.string);
2358 >      struct MaskItem *conf = conf_make(CONF_EXEMPT);
2359 >      conf->host = xstrdup(yylval.string);
2360  
2361 <      add_conf_by_address(CONF_EXEMPTDLINE, yy_aconf);
2743 <      yy_aconf = NULL;
2361 >      add_conf_by_address(CONF_EXEMPT, conf);
2362      }
2363    }
2364   };
# Line 2751 | Line 2369 | exempt_ip: IP '=' QSTRING ';'
2369   gecos_entry: GECOS
2370   {
2371    if (conf_parser_ctx.pass == 2)
2372 <  {
2755 <    regex_ban = 0;
2756 <    reasonbuf[0] = gecos_name[0] = '\0';
2757 <  }
2372 >    reset_block_state();
2373   } '{' gecos_items '}' ';'
2374   {
2375 <  if (conf_parser_ctx.pass == 2)
2761 <  {
2762 <    if (gecos_name[0])
2763 <    {
2764 <      if (regex_ban)
2765 <      {
2766 < #ifdef HAVE_LIBPCRE
2767 <        void *exp_p = NULL;
2768 <        const char *errptr = NULL;
2769 <
2770 <        if (!(exp_p = ircd_pcre_compile(gecos_name, &errptr)))
2771 <        {
2772 <          ilog(L_ERROR, "Failed to add regular expression based X-Line: %s",
2773 <               errptr);
2774 <          break;
2775 <        }
2375 >  struct MaskItem *conf = NULL;
2376  
2377 <        yy_conf = make_conf_item(RXLINE_TYPE);
2378 <        yy_conf->regexpname = exp_p;
2779 < #else
2780 <        ilog(L_ERROR, "Failed to add regular expression based X-Line: no PCRE support");
2781 <        break;
2782 < #endif
2783 <      }
2784 <      else
2785 <        yy_conf = make_conf_item(XLINE_TYPE);
2377 >  if (conf_parser_ctx.pass != 2)
2378 >    break;
2379  
2380 <      yy_match_item = map_to_conf(yy_conf);
2381 <      DupString(yy_conf->name, gecos_name);
2789 <
2790 <      if (reasonbuf[0])
2791 <        DupString(yy_match_item->reason, reasonbuf);
2792 <      else
2793 <        DupString(yy_match_item->reason, "No reason");
2794 <    }
2795 <  }
2796 < };
2380 >  if (!block_state.name.buf[0])
2381 >    break;
2382  
2383 < gecos_flags: TYPE
2384 < {
2800 < } '='  gecos_flags_items ';';
2383 >  conf = conf_make(CONF_XLINE);
2384 >  conf->name = xstrdup(block_state.name.buf);
2385  
2386 < gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2387 < gecos_flags_item: REGEX_T
2388 < {
2389 <  if (conf_parser_ctx.pass == 2)
2806 <    regex_ban = 1;
2386 >  if (block_state.rpass.buf[0])
2387 >    conf->reason = xstrdup(block_state.rpass.buf);
2388 >  else
2389 >    conf->reason = xstrdup(CONF_NOREASON);
2390   };
2391  
2392   gecos_items: gecos_items gecos_item | gecos_item;
2393 < gecos_item:  gecos_name | gecos_reason | gecos_flags | error;
2393 > gecos_item:  gecos_name | gecos_reason | error;
2394  
2395   gecos_name: NAME '=' QSTRING ';'
2396   {
2397    if (conf_parser_ctx.pass == 2)
2398 <    strlcpy(gecos_name, yylval.string, sizeof(gecos_name));
2398 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2399   };
2400  
2401   gecos_reason: REASON '=' QSTRING ';'
2402   {
2403    if (conf_parser_ctx.pass == 2)
2404 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2404 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2405   };
2406  
2407   /***************************************************************************
# Line 2833 | Line 2416 | general_item:       general_hide_spoof_i
2416                      general_max_nick_time | general_max_nick_changes |
2417                      general_max_accept | general_anti_spam_exit_message_time |
2418                      general_ts_warn_delta | general_ts_max_delta |
2419 <                    general_kill_chase_time_limit | general_kline_with_reason |
2420 <                    general_kline_reason | general_invisible_on_connect |
2419 >                    general_kill_chase_time_limit |
2420 >                    general_invisible_on_connect |
2421                      general_warn_no_nline | general_dots_in_ident |
2422                      general_stats_o_oper_only | general_stats_k_oper_only |
2423                      general_pace_wait | general_stats_i_oper_only |
2424                      general_pace_wait_simple | general_stats_P_oper_only |
2425                      general_short_motd | general_no_oper_flood |
2426                      general_true_no_oper_flood | general_oper_pass_resv |
2844                    general_idletime | general_message_locale |
2427                      general_oper_only_umodes | general_max_targets |
2428                      general_use_egd | general_egdpool_path |
2429                      general_oper_umodes | general_caller_id_wait |
2430                      general_opers_bypass_callerid | general_default_floodcount |
2431                      general_min_nonwildcard | general_min_nonwildcard_simple |
2850                    general_servlink_path | general_disable_remote_commands |
2851                    general_default_cipher_preference |
2852                    general_compression_level | general_client_flood |
2432                      general_throttle_time | general_havent_read_conf |
2433                      general_ping_cookie |
2434 <                    general_disable_auth | general_burst_away |
2435 <                    general_tkline_expire_notices | general_gline_min_cidr |
2436 <                    general_gline_min_cidr6 | general_use_whois_actually |
2437 <                    general_reject_hold_time | general_stats_e_disabled |
2438 <                    general_max_watch |
2434 >                    general_disable_auth |
2435 >                    general_tkline_expire_notices | general_gline_enable |
2436 >                    general_gline_duration | general_gline_request_duration |
2437 >                    general_gline_min_cidr |
2438 >                    general_gline_min_cidr6 |
2439 >                    general_stats_e_disabled |
2440 >                    general_max_watch | general_services_name |
2441                      error;
2442  
2443  
# Line 2865 | Line 2446 | general_max_watch: MAX_WATCH '=' NUMBER
2446    ConfigFileEntry.max_watch = $3;
2447   };
2448  
2449 < general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2449 > general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2450   {
2451 <  ConfigFileEntry.gline_min_cidr = $3;
2451 >  if (conf_parser_ctx.pass == 2)
2452 >    ConfigFileEntry.glines = yylval.number;
2453   };
2454  
2455 < general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2455 > general_gline_duration: GLINE_DURATION '=' timespec ';'
2456   {
2457 <  ConfigFileEntry.gline_min_cidr6 = $3;
2457 >  if (conf_parser_ctx.pass == 2)
2458 >    ConfigFileEntry.gline_time = $3;
2459   };
2460  
2461 < general_burst_away: BURST_AWAY '=' TBOOL ';'
2461 > general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2462   {
2463 <  ConfigFileEntry.burst_away = yylval.number;
2463 >  if (conf_parser_ctx.pass == 2)
2464 >    ConfigFileEntry.gline_request_time = $3;
2465   };
2466  
2467 < general_use_whois_actually: USE_WHOIS_ACTUALLY '=' TBOOL ';'
2467 > general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2468   {
2469 <  ConfigFileEntry.use_whois_actually = yylval.number;
2469 >  ConfigFileEntry.gline_min_cidr = $3;
2470   };
2471  
2472 < general_reject_hold_time: TREJECT_HOLD_TIME '=' timespec ';'
2472 > general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2473   {
2474 <  GlobalSetOptions.rejecttime = yylval.number;
2474 >  ConfigFileEntry.gline_min_cidr6 = $3;
2475   };
2476  
2477   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
# Line 2910 | Line 2494 | general_ignore_bogus_ts: IGNORE_BOGUS_TS
2494    ConfigFileEntry.ignore_bogus_ts = yylval.number;
2495   };
2496  
2913 general_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2914 {
2915  ConfigFileEntry.disable_remote = yylval.number;
2916 };
2917
2497   general_failed_oper_notice: FAILED_OPER_NOTICE '=' TBOOL ';'
2498   {
2499    ConfigFileEntry.failed_oper_notice = yylval.number;
# Line 2960 | Line 2539 | general_havent_read_conf: HAVENT_READ_CO
2539   {
2540    if (($3 > 0) && conf_parser_ctx.pass == 1)
2541    {
2542 <    ilog(L_CRIT, "You haven't read your config file properly.");
2543 <    ilog(L_CRIT, "There is a line in the example conf that will kill your server if not removed.");
2544 <    ilog(L_CRIT, "Consider actually reading/editing the conf file, and removing this line.");
2542 >    ilog(LOG_TYPE_IRCD, "You haven't read your config file properly.");
2543 >    ilog(LOG_TYPE_IRCD, "There is a line in the example conf that will kill your server if not removed.");
2544 >    ilog(LOG_TYPE_IRCD, "Consider actually reading/editing the conf file, and removing this line.");
2545      exit(0);
2546    }
2547   };
2548  
2970 general_kline_with_reason: KLINE_WITH_REASON '=' TBOOL ';'
2971 {
2972  ConfigFileEntry.kline_with_reason = yylval.number;
2973 };
2974
2975 general_kline_reason: KLINE_REASON '=' QSTRING ';'
2976 {
2977  if (conf_parser_ctx.pass == 2)
2978  {
2979    MyFree(ConfigFileEntry.kline_reason);
2980    DupString(ConfigFileEntry.kline_reason, yylval.string);
2981  }
2982 };
2983
2549   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2550   {
2551    ConfigFileEntry.invisible_on_connect = yylval.number;
# Line 3062 | Line 2627 | general_oper_pass_resv: OPER_PASS_RESV '
2627    ConfigFileEntry.oper_pass_resv = yylval.number;
2628   };
2629  
3065 general_message_locale: MESSAGE_LOCALE '=' QSTRING ';'
3066 {
3067  if (conf_parser_ctx.pass == 2)
3068  {
3069    if (strlen(yylval.string) > LOCALE_LENGTH-2)
3070      yylval.string[LOCALE_LENGTH-1] = '\0';
3071
3072    set_locale(yylval.string);
3073  }
3074 };
3075
3076 general_idletime: IDLETIME '=' timespec ';'
3077 {
3078  ConfigFileEntry.idletime = $3;
3079 };
3080
2630   general_dots_in_ident: DOTS_IN_IDENT '=' NUMBER ';'
2631   {
2632    ConfigFileEntry.dots_in_ident = $3;
# Line 3088 | Line 2637 | general_max_targets: MAX_TARGETS '=' NUM
2637    ConfigFileEntry.max_targets = $3;
2638   };
2639  
2640 < general_servlink_path: SERVLINK_PATH '=' QSTRING ';'
3092 < {
3093 <  if (conf_parser_ctx.pass == 2)
3094 <  {
3095 <    MyFree(ConfigFileEntry.servlink_path);
3096 <    DupString(ConfigFileEntry.servlink_path, yylval.string);
3097 <  }
3098 < };
3099 <
3100 < general_default_cipher_preference: DEFAULT_CIPHER_PREFERENCE '=' QSTRING ';'
2640 > general_use_egd: USE_EGD '=' TBOOL ';'
2641   {
2642 < #ifdef HAVE_LIBCRYPTO
3103 <  if (conf_parser_ctx.pass == 2)
3104 <  {
3105 <    struct EncCapability *ecap;
3106 <    const char *cipher_name;
3107 <    int found = 0;
3108 <
3109 <    ConfigFileEntry.default_cipher_preference = NULL;
3110 <    cipher_name = yylval.string;
3111 <
3112 <    for (ecap = CipherTable; ecap->name; ecap++)
3113 <    {
3114 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
3115 <          (ecap->cap & CAP_ENC_MASK))
3116 <      {
3117 <        ConfigFileEntry.default_cipher_preference = ecap;
3118 <        found = 1;
3119 <        break;
3120 <      }
3121 <    }
3122 <
3123 <    if (!found)
3124 <      yyerror("Invalid cipher");
3125 <  }
3126 < #else
3127 <  if (conf_parser_ctx.pass == 2)
3128 <    yyerror("Ignoring default_cipher_preference -- no OpenSSL support");
3129 < #endif
2642 >  ConfigFileEntry.use_egd = yylval.number;
2643   };
2644  
2645 < general_compression_level: COMPRESSION_LEVEL '=' NUMBER ';'
2645 > general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
2646   {
2647    if (conf_parser_ctx.pass == 2)
2648    {
2649 <    ConfigFileEntry.compression_level = $3;
2650 < #ifndef HAVE_LIBZ
3138 <    yyerror("Ignoring compression_level -- no zlib support");
3139 < #else
3140 <    if ((ConfigFileEntry.compression_level < 1) ||
3141 <        (ConfigFileEntry.compression_level > 9))
3142 <    {
3143 <      yyerror("Ignoring invalid compression_level, using default");
3144 <      ConfigFileEntry.compression_level = 0;
3145 <    }
3146 < #endif
2649 >    MyFree(ConfigFileEntry.egdpool_path);
2650 >    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2651    }
2652   };
2653  
2654 < general_use_egd: USE_EGD '=' TBOOL ';'
2654 > general_services_name: T_SERVICES_NAME '=' QSTRING ';'
2655   {
2656 <  ConfigFileEntry.use_egd = yylval.number;
3153 < };
3154 <
3155 < general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
3156 < {
3157 <  if (conf_parser_ctx.pass == 2)
2656 >  if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2657    {
2658 <    MyFree(ConfigFileEntry.egdpool_path);
2659 <    DupString(ConfigFileEntry.egdpool_path, yylval.string);
2658 >    MyFree(ConfigFileEntry.service_name);
2659 >    ConfigFileEntry.service_name = xstrdup(yylval.string);
2660    }
2661   };
2662  
# Line 3188 | Line 2687 | umode_oitem:     T_BOTS
2687   } | T_CCONN
2688   {
2689    ConfigFileEntry.oper_umodes |= UMODE_CCONN;
3191 } | T_CCONN_FULL
3192 {
3193  ConfigFileEntry.oper_umodes |= UMODE_CCONN_FULL;
2690   } | T_DEAF
2691   {
2692    ConfigFileEntry.oper_umodes |= UMODE_DEAF;
# Line 3200 | Line 2696 | umode_oitem:     T_BOTS
2696   } | T_FULL
2697   {
2698    ConfigFileEntry.oper_umodes |= UMODE_FULL;
2699 + } | HIDDEN
2700 + {
2701 +  ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2702   } | T_SKILL
2703   {
2704    ConfigFileEntry.oper_umodes |= UMODE_SKILL;
# Line 3239 | Line 2738 | umode_oitem:     T_BOTS
2738   } | T_LOCOPS
2739   {
2740    ConfigFileEntry.oper_umodes |= UMODE_LOCOPS;
2741 + } | T_NONONREG
2742 + {
2743 +  ConfigFileEntry.oper_umodes |= UMODE_REGONLY;
2744 + } | T_FARCONNECT
2745 + {
2746 +  ConfigFileEntry.oper_umodes |= UMODE_FARCONNECT;
2747   };
2748  
2749   general_oper_only_umodes: OPER_ONLY_UMODES
# Line 3253 | Line 2758 | umode_item:    T_BOTS
2758   } | T_CCONN
2759   {
2760    ConfigFileEntry.oper_only_umodes |= UMODE_CCONN;
3256 } | T_CCONN_FULL
3257 {
3258  ConfigFileEntry.oper_only_umodes |= UMODE_CCONN_FULL;
2761   } | T_DEAF
2762   {
2763    ConfigFileEntry.oper_only_umodes |= UMODE_DEAF;
# Line 3268 | Line 2770 | umode_item:    T_BOTS
2770   } | T_SKILL
2771   {
2772    ConfigFileEntry.oper_only_umodes |= UMODE_SKILL;
2773 + } | HIDDEN
2774 + {
2775 +  ConfigFileEntry.oper_only_umodes |= UMODE_HIDDEN;
2776   } | T_NCHANGE
2777   {
2778    ConfigFileEntry.oper_only_umodes |= UMODE_NCHANGE;
# Line 3304 | Line 2809 | umode_item:    T_BOTS
2809   } | T_LOCOPS
2810   {
2811    ConfigFileEntry.oper_only_umodes |= UMODE_LOCOPS;
2812 + } | T_NONONREG
2813 + {
2814 +  ConfigFileEntry.oper_only_umodes |= UMODE_REGONLY;
2815 + } | T_FARCONNECT
2816 + {
2817 +  ConfigFileEntry.oper_only_umodes |= UMODE_FARCONNECT;
2818   };
2819  
2820   general_min_nonwildcard: MIN_NONWILDCARD '=' NUMBER ';'
# Line 3321 | Line 2832 | general_default_floodcount: DEFAULT_FLOO
2832    ConfigFileEntry.default_floodcount = $3;
2833   };
2834  
3324 general_client_flood: T_CLIENT_FLOOD '=' sizespec ';'
3325 {
3326  ConfigFileEntry.client_flood = $3;
3327 };
3328
3329
3330 /***************************************************************************
3331 *  section glines
3332 ***************************************************************************/
3333 gline_entry: GLINES
3334 {
3335  if (conf_parser_ctx.pass == 2)
3336  {
3337    yy_conf = make_conf_item(GDENY_TYPE);
3338    yy_aconf = map_to_conf(yy_conf);
3339  }
3340 } '{' gline_items '}' ';'
3341 {
3342  if (conf_parser_ctx.pass == 2)
3343  {
3344    /*
3345     * since we re-allocate yy_conf/yy_aconf after the end of action=, at the
3346     * end we will have one extra, so we should free it.
3347     */
3348    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3349    {
3350      delete_conf_item(yy_conf);
3351      yy_conf = NULL;
3352      yy_aconf = NULL;
3353    }
3354  }
3355 };
3356
3357 gline_items:        gline_items gline_item | gline_item;
3358 gline_item:         gline_enable |
3359                    gline_duration |
3360                    gline_logging |
3361                    gline_user |
3362                    gline_server |
3363                    gline_action |
3364                    error;
3365
3366 gline_enable: ENABLE '=' TBOOL ';'
3367 {
3368  if (conf_parser_ctx.pass == 2)
3369    ConfigFileEntry.glines = yylval.number;
3370 };
3371
3372 gline_duration: DURATION '=' timespec ';'
3373 {
3374  if (conf_parser_ctx.pass == 2)
3375    ConfigFileEntry.gline_time = $3;
3376 };
3377
3378 gline_logging: LOGGING
3379 {
3380  if (conf_parser_ctx.pass == 2)
3381    ConfigFileEntry.gline_logging = 0;
3382 } '=' gline_logging_types ';';
3383 gline_logging_types:     gline_logging_types ',' gline_logging_type_item | gline_logging_type_item;
3384 gline_logging_type_item: T_REJECT
3385 {
3386  if (conf_parser_ctx.pass == 2)
3387    ConfigFileEntry.gline_logging |= GDENY_REJECT;
3388 } | T_BLOCK
3389 {
3390  if (conf_parser_ctx.pass == 2)
3391    ConfigFileEntry.gline_logging |= GDENY_BLOCK;
3392 };
3393
3394 gline_user: USER '=' QSTRING ';'
3395 {
3396  if (conf_parser_ctx.pass == 2)
3397  {
3398    struct split_nuh_item nuh;
3399
3400    nuh.nuhmask  = yylval.string;
3401    nuh.nickptr  = NULL;
3402    nuh.userptr  = userbuf;
3403    nuh.hostptr  = hostbuf;
3404
3405    nuh.nicksize = 0;
3406    nuh.usersize = sizeof(userbuf);
3407    nuh.hostsize = sizeof(hostbuf);
3408
3409    split_nuh(&nuh);
3410
3411    if (yy_aconf->user == NULL)
3412    {
3413      DupString(yy_aconf->user, userbuf);
3414      DupString(yy_aconf->host, hostbuf);
3415    }
3416    else
3417    {
3418      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
3419
3420      DupString(yy_tmp->user, userbuf);
3421      DupString(yy_tmp->host, hostbuf);
3422
3423      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
3424    }
3425  }
3426 };
3427
3428 gline_server: NAME '=' QSTRING ';'
3429 {
3430  if (conf_parser_ctx.pass == 2)  
3431  {
3432    MyFree(yy_conf->name);
3433    DupString(yy_conf->name, yylval.string);
3434  }
3435 };
3436
3437 gline_action: ACTION
3438 {
3439  if (conf_parser_ctx.pass == 2)
3440    yy_aconf->flags = 0;
3441 } '=' gdeny_types ';'
3442 {
3443  if (conf_parser_ctx.pass == 2)
3444  {
3445    struct CollectItem *yy_tmp = NULL;
3446    dlink_node *ptr, *next_ptr;
3447
3448    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
3449    {
3450      struct AccessItem *new_aconf;
3451      struct ConfItem *new_conf;
3452
3453      yy_tmp = ptr->data;
3454      new_conf = make_conf_item(GDENY_TYPE);
3455      new_aconf = map_to_conf(new_conf);
3456
3457      new_aconf->flags = yy_aconf->flags;
3458
3459      if (yy_conf->name != NULL)
3460        DupString(new_conf->name, yy_conf->name);
3461      else
3462        DupString(new_conf->name, "*");
3463      if (yy_aconf->user != NULL)
3464         DupString(new_aconf->user, yy_tmp->user);
3465      else  
3466        DupString(new_aconf->user, "*");
3467      if (yy_aconf->host != NULL)
3468        DupString(new_aconf->host, yy_tmp->host);
3469      else
3470        DupString(new_aconf->host, "*");
3471
3472      dlinkDelete(&yy_tmp->node, &col_conf_list);
3473    }
3474
3475    /*
3476     * In case someone has fed us with more than one action= after user/name
3477     * which would leak memory  -Michael
3478     */
3479    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3480      delete_conf_item(yy_conf);
3481
3482    yy_conf = make_conf_item(GDENY_TYPE);
3483    yy_aconf = map_to_conf(yy_conf);
3484  }
3485 };
3486
3487 gdeny_types: gdeny_types ',' gdeny_type_item | gdeny_type_item;
3488 gdeny_type_item: T_REJECT
3489 {
3490  if (conf_parser_ctx.pass == 2)
3491    yy_aconf->flags |= GDENY_REJECT;
3492 } | T_BLOCK
3493 {
3494  if (conf_parser_ctx.pass == 2)
3495    yy_aconf->flags |= GDENY_BLOCK;
3496 };
2835  
2836   /***************************************************************************
2837   *  section channel
# Line 3502 | Line 2840 | channel_entry: CHANNEL
2840    '{' channel_items '}' ';';
2841  
2842   channel_items:      channel_items channel_item | channel_item;
2843 < channel_item:       channel_disable_local_channels | channel_use_except |
2844 <                    channel_use_invex | channel_use_knock |
2845 <                    channel_max_bans | channel_knock_delay |
2846 <                    channel_knock_delay_channel | channel_max_chans_per_user |
3509 <                    channel_quiet_on_ban | channel_default_split_user_count |
2843 > channel_item:       channel_max_bans |
2844 >                    channel_knock_delay | channel_knock_delay_channel |
2845 >                    channel_max_chans_per_user | channel_max_chans_per_oper |
2846 >                    channel_default_split_user_count |
2847                      channel_default_split_server_count |
2848 <                    channel_no_create_on_split | channel_restrict_channels |
2849 <                    channel_no_join_on_split | channel_burst_topicwho |
2848 >                    channel_no_create_on_split |
2849 >                    channel_no_join_on_split |
2850                      channel_jflood_count | channel_jflood_time |
2851                      channel_disable_fake_channels | error;
2852  
# Line 3518 | Line 2855 | channel_disable_fake_channels: DISABLE_F
2855    ConfigChannel.disable_fake_channels = yylval.number;
2856   };
2857  
3521 channel_restrict_channels: RESTRICT_CHANNELS '=' TBOOL ';'
3522 {
3523  ConfigChannel.restrict_channels = yylval.number;
3524 };
3525
3526 channel_disable_local_channels: DISABLE_LOCAL_CHANNELS '=' TBOOL ';'
3527 {
3528  ConfigChannel.disable_local_channels = yylval.number;
3529 };
3530
3531 channel_use_except: USE_EXCEPT '=' TBOOL ';'
3532 {
3533  ConfigChannel.use_except = yylval.number;
3534 };
3535
3536 channel_use_invex: USE_INVEX '=' TBOOL ';'
3537 {
3538  ConfigChannel.use_invex = yylval.number;
3539 };
3540
3541 channel_use_knock: USE_KNOCK '=' TBOOL ';'
3542 {
3543  ConfigChannel.use_knock = yylval.number;
3544 };
3545
2858   channel_knock_delay: KNOCK_DELAY '=' timespec ';'
2859   {
2860    ConfigChannel.knock_delay = $3;
# Line 3558 | Line 2870 | channel_max_chans_per_user: MAX_CHANS_PE
2870    ConfigChannel.max_chans_per_user = $3;
2871   };
2872  
2873 < channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
2873 > channel_max_chans_per_oper: MAX_CHANS_PER_OPER '=' NUMBER ';'
2874   {
2875 <  ConfigChannel.quiet_on_ban = yylval.number;
2875 >  ConfigChannel.max_chans_per_oper = $3;
2876   };
2877  
2878   channel_max_bans: MAX_BANS '=' NUMBER ';'
# Line 3588 | Line 2900 | channel_no_join_on_split: NO_JOIN_ON_SPL
2900    ConfigChannel.no_join_on_split = yylval.number;
2901   };
2902  
3591 channel_burst_topicwho: BURST_TOPICWHO '=' TBOOL ';'
3592 {
3593  ConfigChannel.burst_topicwho = yylval.number;
3594 };
3595
2903   channel_jflood_count: JOIN_FLOOD_COUNT '=' NUMBER ';'
2904   {
2905    GlobalSetOptions.joinfloodcount = yylval.number;
# Line 3610 | Line 2917 | serverhide_entry: SERVERHIDE
2917    '{' serverhide_items '}' ';';
2918  
2919   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
2920 < serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
2920 > serverhide_item:    serverhide_flatten_links | serverhide_disable_remote_commands |
2921 >                    serverhide_hide_servers |
2922 >                    serverhide_hide_services |
2923                      serverhide_links_delay |
3615                    serverhide_disable_hidden |
2924                      serverhide_hidden | serverhide_hidden_name |
2925                      serverhide_hide_server_ips |
2926                      error;
# Line 3623 | Line 2931 | serverhide_flatten_links: FLATTEN_LINKS
2931      ConfigServerHide.flatten_links = yylval.number;
2932   };
2933  
2934 + serverhide_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2935 + {
2936 +  if (conf_parser_ctx.pass == 2)
2937 +    ConfigServerHide.disable_remote_commands = yylval.number;
2938 + };
2939 +
2940   serverhide_hide_servers: HIDE_SERVERS '=' TBOOL ';'
2941   {
2942    if (conf_parser_ctx.pass == 2)
2943      ConfigServerHide.hide_servers = yylval.number;
2944   };
2945  
2946 + serverhide_hide_services: HIDE_SERVICES '=' TBOOL ';'
2947 + {
2948 +  if (conf_parser_ctx.pass == 2)
2949 +    ConfigServerHide.hide_services = yylval.number;
2950 + };
2951 +
2952   serverhide_hidden_name: HIDDEN_NAME '=' QSTRING ';'
2953   {
2954    if (conf_parser_ctx.pass == 2)
2955    {
2956      MyFree(ConfigServerHide.hidden_name);
2957 <    DupString(ConfigServerHide.hidden_name, yylval.string);
2957 >    ConfigServerHide.hidden_name = xstrdup(yylval.string);
2958    }
2959   };
2960  
# Line 3658 | Line 2978 | serverhide_hidden: HIDDEN '=' TBOOL ';'
2978      ConfigServerHide.hidden = yylval.number;
2979   };
2980  
3661 serverhide_disable_hidden: DISABLE_HIDDEN '=' TBOOL ';'
3662 {
3663  if (conf_parser_ctx.pass == 2)
3664    ConfigServerHide.disable_hidden = yylval.number;
3665 };
3666
2981   serverhide_hide_server_ips: HIDE_SERVER_IPS '=' TBOOL ';'
2982   {
2983    if (conf_parser_ctx.pass == 2)

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)