ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing:
ircd-hybrid-8/src/ircd_parser.y (file contents), Revision 1265 by michael, Tue Jan 17 12:54:17 2012 UTC vs.
ircd-hybrid/trunk/src/conf_parser.y (file contents), Revision 2336 by michael, Wed Jul 3 12:58:28 2013 UTC

# Line 1 | Line 1
1   /*
2   *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  ircd_parser.y: Parses the ircd configuration file.
3 > *  conf_parser.y: Parses the ircd configuration file.
4   *
5   *  Copyright (C) 2005 by the past and present ircd coders, and others.
6   *
# Line 32 | Line 32
32   #include "stdinc.h"
33   #include "ircd.h"
34   #include "list.h"
35 < #include "s_conf.h"
35 > #include "conf.h"
36 > #include "conf_class.h"
37   #include "event.h"
38 < #include "s_log.h"
38 > #include "log.h"
39   #include "client.h"     /* for UMODE_ALL only */
40   #include "irc_string.h"
40 #include "sprintf_irc.h"
41   #include "memory.h"
42   #include "modules.h"
43   #include "s_serv.h"
# Line 47 | Line 47
47   #include "resv.h"
48   #include "numeric.h"
49   #include "s_user.h"
50 + #include "motd.h"
51  
52   #ifdef HAVE_LIBCRYPTO
53   #include <openssl/rsa.h>
54   #include <openssl/bio.h>
55   #include <openssl/pem.h>
56 + #include <openssl/dh.h>
57   #endif
58  
59 < static char *class_name = NULL;
58 < static struct ConfItem *yy_conf = NULL;
59 < static struct AccessItem *yy_aconf = NULL;
60 < static struct MatchItem *yy_match_item = NULL;
61 < static struct ClassItem *yy_class = NULL;
62 < static char *yy_class_name = NULL;
63 <
64 < static dlink_list col_conf_list  = { NULL, NULL, 0 };
65 < static dlink_list hub_conf_list  = { NULL, NULL, 0 };
66 < static dlink_list leaf_conf_list = { NULL, NULL, 0 };
67 < static unsigned int listener_flags = 0;
68 < static unsigned int regex_ban = 0;
69 < static char userbuf[IRCD_BUFSIZE];
70 < static char hostbuf[IRCD_BUFSIZE];
71 < static char reasonbuf[REASONLEN + 1];
72 < static char gecos_name[REALLEN * 4];
73 < static char lfile[IRCD_BUFSIZE];
74 < static unsigned int ltype = 0;
75 < static unsigned int lsize = 0;
76 < static char *resv_reason = NULL;
77 < static char *listener_address = NULL;
78 <
79 < struct CollectItem
80 < {
81 <  dlink_node node;
82 <  char *name;
83 <  char *user;
84 <  char *host;
85 <  char *passwd;
86 <  int  port;
87 <  int  flags;
88 < #ifdef HAVE_LIBCRYPTO
89 <  char *rsa_public_key_file;
90 <  RSA *rsa_public_key;
91 < #endif
92 < };
59 > #include "rsa.h"
60  
61 < static void
62 < free_collect_item(struct CollectItem *item)
61 > int yylex(void);
62 >
63 > static struct
64   {
65 <  MyFree(item->name);
66 <  MyFree(item->user);
67 <  MyFree(item->host);
68 <  MyFree(item->passwd);
69 < #ifdef HAVE_LIBCRYPTO
70 <  MyFree(item->rsa_public_key_file);
71 < #endif
72 <  MyFree(item);
73 < }
65 >  struct {
66 >    dlink_list list;
67 >  } mask,
68 >    leaf,
69 >    hub;
70 >
71 >  struct {
72 >    char buf[IRCD_BUFSIZE];
73 >  } name,
74 >    user,
75 >    host,
76 >    addr,
77 >    bind,
78 >    file,
79 >    ciph,
80 >    cert,
81 >    rpass,
82 >    spass,
83 >    class;
84 >
85 >  struct {
86 >    unsigned int value;
87 >  } flags,
88 >    modes,
89 >    size,
90 >    type,
91 >    port,
92 >    aftype,
93 >    ping_freq,
94 >    max_perip,
95 >    con_freq,
96 >    min_idle,
97 >    max_idle,
98 >    max_total,
99 >    max_global,
100 >    max_local,
101 >    max_ident,
102 >    max_sendq,
103 >    max_recvq,
104 >    cidr_bitlen_ipv4,
105 >    cidr_bitlen_ipv6,
106 >    number_per_cidr;
107 > } block_state;
108  
109   static void
110 < unhook_hub_leaf_confs(void)
110 > reset_block_state(void)
111   {
112 <  dlink_node *ptr;
113 <  dlink_node *next_ptr;
114 <  struct CollectItem *yy_hconf;
115 <  struct CollectItem *yy_lconf;
112 >  dlink_node *ptr = NULL, *ptr_next = NULL;
113 >
114 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.mask.list.head)
115 >  {
116 >    MyFree(ptr->data);
117 >    dlinkDelete(ptr, &block_state.mask.list);
118 >    free_dlink_node(ptr);
119 >  }
120  
121 <  DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
121 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.leaf.list.head)
122    {
123 <    yy_hconf = ptr->data;
124 <    dlinkDelete(&yy_hconf->node, &hub_conf_list);
125 <    free_collect_item(yy_hconf);
123 >    MyFree(ptr->data);
124 >    dlinkDelete(ptr, &block_state.leaf.list);
125 >    free_dlink_node(ptr);
126    }
127  
128 <  DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
128 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.hub.list.head)
129    {
130 <    yy_lconf = ptr->data;
131 <    dlinkDelete(&yy_lconf->node, &leaf_conf_list);
132 <    free_collect_item(yy_lconf);
130 >    MyFree(ptr->data);
131 >    dlinkDelete(ptr, &block_state.hub.list);
132 >    free_dlink_node(ptr);
133    }
134 +
135 +  memset(&block_state, 0, sizeof(block_state));
136   }
137  
138   %}
# Line 135 | Line 143 | unhook_hub_leaf_confs(void)
143   }
144  
145   %token  ACCEPT_PASSWORD
138 %token  ACTION
146   %token  ADMIN
147   %token  AFTYPE
141 %token  T_ALLOW
148   %token  ANTI_NICK_FLOOD
149   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
150   %token  AUTOCONN
151 < %token  T_BLOCK
146 < %token  BURST_AWAY
147 < %token  BURST_TOPICWHO
148 < %token  BYTES KBYTES MBYTES GBYTES TBYTES
151 > %token  BYTES KBYTES MBYTES
152   %token  CALLER_ID_WAIT
153   %token  CAN_FLOOD
154   %token  CHANNEL
155 < %token  CIDR_BITLEN_IPV4
156 < %token  CIDR_BITLEN_IPV6
154 < %token  CIPHER_PREFERENCE
155 > %token  CIDR_BITLEN_IPV4
156 > %token  CIDR_BITLEN_IPV6
157   %token  CLASS
156 %token  COMPRESSED
157 %token  COMPRESSION_LEVEL
158   %token  CONNECT
159   %token  CONNECTFREQ
160 < %token  CRYPTLINK
161 < %token  DEFAULT_CIPHER_PREFERENCE
160 > %token  CYCLE_ON_HOST_CHANGE
161   %token  DEFAULT_FLOODCOUNT
162   %token  DEFAULT_SPLIT_SERVER_COUNT
163   %token  DEFAULT_SPLIT_USER_COUNT
# Line 167 | Line 166 | unhook_hub_leaf_confs(void)
166   %token  DIE
167   %token  DISABLE_AUTH
168   %token  DISABLE_FAKE_CHANNELS
170 %token  DISABLE_HIDDEN
171 %token  DISABLE_LOCAL_CHANNELS
169   %token  DISABLE_REMOTE_COMMANDS
170   %token  DOTS_IN_IDENT
174 %token  DURATION
171   %token  EGDPOOL_PATH
172   %token  EMAIL
177 %token  ENABLE
173   %token  ENCRYPTED
174   %token  EXCEED_LIMIT
175   %token  EXEMPT
176   %token  FAILED_OPER_NOTICE
182 %token  IRCD_FLAGS
177   %token  FLATTEN_LINKS
178   %token  GECOS
179   %token  GENERAL
180   %token  GLINE
181 < %token  GLINES
181 > %token  GLINE_DURATION
182 > %token  GLINE_ENABLE
183   %token  GLINE_EXEMPT
189 %token  GLINE_TIME
184   %token  GLINE_MIN_CIDR
185   %token  GLINE_MIN_CIDR6
186 + %token  GLINE_REQUEST_DURATION
187   %token  GLOBAL_KILL
193 %token  IRCD_AUTH
194 %token  NEED_IDENT
188   %token  HAVENT_READ_CONF
189   %token  HIDDEN
190 < %token  HIDDEN_ADMIN
191 < %token  HIDDEN_NAME
199 < %token  HIDDEN_OPER
190 > %token  HIDDEN_NAME
191 > %token  HIDE_IDLE_FROM_OPERS
192   %token  HIDE_SERVER_IPS
193   %token  HIDE_SERVERS
194 < %token  HIDE_SPOOF_IPS
194 > %token  HIDE_SERVICES
195 > %token  HIDE_SPOOF_IPS
196   %token  HOST
197   %token  HUB
198   %token  HUB_MASK
199   %token  IGNORE_BOGUS_TS
200   %token  INVISIBLE_ON_CONNECT
201   %token  IP
202 + %token  IRCD_AUTH
203 + %token  IRCD_FLAGS
204 + %token  IRCD_SID
205 + %token  JOIN_FLOOD_COUNT
206 + %token  JOIN_FLOOD_TIME
207   %token  KILL
208 < %token  KILL_CHASE_TIME_LIMIT
208 > %token  KILL_CHASE_TIME_LIMIT
209   %token  KLINE
210   %token  KLINE_EXEMPT
213 %token  KLINE_REASON
214 %token  KLINE_WITH_REASON
211   %token  KNOCK_DELAY
212   %token  KNOCK_DELAY_CHANNEL
213   %token  LEAF_MASK
214   %token  LINKS_DELAY
215   %token  LISTEN
216 < %token  T_LOG
216 > %token  MASK
217   %token  MAX_ACCEPT
218   %token  MAX_BANS
219 + %token  MAX_CHANS_PER_OPER
220   %token  MAX_CHANS_PER_USER
221   %token  MAX_GLOBAL
222   %token  MAX_IDENT
223 + %token  MAX_IDLE
224   %token  MAX_LOCAL
225   %token  MAX_NICK_CHANGES
226 + %token  MAX_NICK_LENGTH
227   %token  MAX_NICK_TIME
228   %token  MAX_NUMBER
229   %token  MAX_TARGETS
230 + %token  MAX_TOPIC_LENGTH
231   %token  MAX_WATCH
232 < %token  MESSAGE_LOCALE
232 > %token  MIN_IDLE
233   %token  MIN_NONWILDCARD
234   %token  MIN_NONWILDCARD_SIMPLE
235   %token  MODULE
236   %token  MODULES
237 + %token  MOTD
238   %token  NAME
239 + %token  NEED_IDENT
240   %token  NEED_PASSWORD
241   %token  NETWORK_DESC
242   %token  NETWORK_NAME
243   %token  NICK
242 %token  NICK_CHANGES
244   %token  NO_CREATE_ON_SPLIT
245   %token  NO_JOIN_ON_SPLIT
246   %token  NO_OPER_FLOOD
247   %token  NO_TILDE
248   %token  NUMBER
248 %token  NUMBER_PER_IDENT
249   %token  NUMBER_PER_CIDR
250   %token  NUMBER_PER_IP
251 %token  NUMBER_PER_IP_GLOBAL
252 %token  OPERATOR
253 %token  OPERS_BYPASS_CALLERID
251   %token  OPER_ONLY_UMODES
252   %token  OPER_PASS_RESV
256 %token  OPER_SPY_T
253   %token  OPER_UMODES
254 < %token  JOIN_FLOOD_COUNT
255 < %token  JOIN_FLOOD_TIME
254 > %token  OPERATOR
255 > %token  OPERS_BYPASS_CALLERID
256   %token  PACE_WAIT
257   %token  PACE_WAIT_SIMPLE
258   %token  PASSWORD
259   %token  PATH
260   %token  PING_COOKIE
261   %token  PING_TIME
266 %token  PING_WARNING
262   %token  PORT
263   %token  QSTRING
264 < %token  QUIET_ON_BAN
264 > %token  RANDOM_IDLE
265   %token  REASON
266   %token  REDIRPORT
267   %token  REDIRSERV
273 %token  REGEX_T
268   %token  REHASH
275 %token  TREJECT_HOLD_TIME
269   %token  REMOTE
270   %token  REMOTEBAN
278 %token  RESTRICT_CHANNELS
279 %token  RESTRICTED
280 %token  RSA_PRIVATE_KEY_FILE
281 %token  RSA_PUBLIC_KEY_FILE
282 %token  SSL_CERTIFICATE_FILE
283 %token  T_SSL_CONNECTION_METHOD
284 %token  T_SSLV3
285 %token  T_TLSV1
271   %token  RESV
272   %token  RESV_EXEMPT
273 < %token  SECONDS MINUTES HOURS DAYS WEEKS
274 < %token  SENDQ
273 > %token  RSA_PRIVATE_KEY_FILE
274 > %token  RSA_PUBLIC_KEY_FILE
275 > %token  SECONDS MINUTES HOURS DAYS WEEKS MONTHS YEARS
276   %token  SEND_PASSWORD
277 + %token  SENDQ
278   %token  SERVERHIDE
279   %token  SERVERINFO
293 %token  SERVLINK_PATH
294 %token  IRCD_SID
295 %token  TKLINE_EXPIRE_NOTICES
296 %token  T_SHARED
297 %token  T_CLUSTER
298 %token  TYPE
280   %token  SHORT_MOTD
300 %token  SILENT
281   %token  SPOOF
282   %token  SPOOF_NOTICE
283 + %token  SQUIT
284 + %token  SSL_CERTIFICATE_FILE
285 + %token  SSL_CERTIFICATE_FINGERPRINT
286 + %token  SSL_CONNECTION_REQUIRED
287 + %token  SSL_DH_PARAM_FILE
288   %token  STATS_E_DISABLED
289   %token  STATS_I_OPER_ONLY
290   %token  STATS_K_OPER_ONLY
291   %token  STATS_O_OPER_ONLY
292   %token  STATS_P_OPER_ONLY
293 < %token  TBOOL
309 < %token  TMASKED
310 < %token  T_REJECT
311 < %token  TS_MAX_DELTA
312 < %token  TS_WARN_DELTA
313 < %token  TWODOTS
293 > %token  STATS_U_OPER_ONLY
294   %token  T_ALL
295   %token  T_BOTS
316 %token  T_SOFTCALLERID
296   %token  T_CALLERID
297   %token  T_CCONN
298 < %token  T_CCONN_FULL
320 < %token  T_CLIENT_FLOOD
298 > %token  T_CLUSTER
299   %token  T_DEAF
300   %token  T_DEBUG
301   %token  T_DLINE
324 %token  T_DRONE
302   %token  T_EXTERNAL
303 + %token  T_FARCONNECT
304 + %token  T_FILE
305   %token  T_FULL
306 + %token  T_GLOBOPS
307   %token  T_INVISIBLE
308   %token  T_IPV4
309   %token  T_IPV6
310   %token  T_LOCOPS
311 + %token  T_LOG
312   %token  T_MAX_CLIENTS
313   %token  T_NCHANGE
314 + %token  T_NONONREG
315   %token  T_OPERWALL
316 + %token  T_RECVQ
317   %token  T_REJ
318 + %token  T_RESTART
319   %token  T_SERVER
320 + %token  T_SERVICE
321 + %token  T_SERVICES_NAME
322   %token  T_SERVNOTICE
323 + %token  T_SET
324 + %token  T_SHARED
325 + %token  T_SIZE
326   %token  T_SKILL
327 + %token  T_SOFTCALLERID
328   %token  T_SPY
329   %token  T_SSL
330 + %token  T_SSL_CIPHER_LIST
331 + %token  T_SSL_CLIENT_METHOD
332 + %token  T_SSL_SERVER_METHOD
333 + %token  T_SSLV3
334 + %token  T_TLSV1
335   %token  T_UMODES
336   %token  T_UNAUTH
337 + %token  T_UNDLINE
338   %token  T_UNLIMITED
339   %token  T_UNRESV
340   %token  T_UNXLINE
345 %token  T_GLOBOPS
341   %token  T_WALLOP
342 < %token  T_RESTART
343 < %token  T_SERVICE
344 < %token  T_SERVICES_NAME
350 < %token  T_TIMESTAMP
342 > %token  T_WALLOPS
343 > %token  T_WEBIRC
344 > %token  TBOOL
345   %token  THROTTLE_TIME
346 < %token  TOPICBURST
346 > %token  TKLINE_EXPIRE_NOTICES
347 > %token  TMASKED
348   %token  TRUE_NO_OPER_FLOOD
349 < %token  TKLINE
350 < %token  TXLINE
351 < %token  TRESV
349 > %token  TS_MAX_DELTA
350 > %token  TS_WARN_DELTA
351 > %token  TWODOTS
352 > %token  TYPE
353   %token  UNKLINE
358 %token  USER
354   %token  USE_EGD
360 %token  USE_EXCEPT
361 %token  USE_INVEX
362 %token  USE_KNOCK
355   %token  USE_LOGGING
356 < %token  USE_WHOIS_ACTUALLY
356 > %token  USER
357   %token  VHOST
358   %token  VHOST6
367 %token  XLINE
368 %token  WARN
359   %token  WARN_NO_NLINE
360 < %token  T_SIZE
371 < %token  T_FILE
360 > %token  XLINE
361  
362 < %type <string> QSTRING
363 < %type <number> NUMBER
364 < %type <number> timespec
365 < %type <number> timespec_
366 < %type <number> sizespec
367 < %type <number> sizespec_
362 > %type  <string> QSTRING
363 > %type  <number> NUMBER
364 > %type  <number> timespec
365 > %type  <number> timespec_
366 > %type  <number> sizespec
367 > %type  <number> sizespec_
368  
369   %%
370   conf:  
# Line 400 | Line 389 | conf_item:        admin_entry
389                  | deny_entry
390                  | exempt_entry
391                  | general_entry
403                | gline_entry
392                  | gecos_entry
393                  | modules_entry
394 +                | motd_entry
395                  | error ';'
396                  | error '}'
397          ;
# Line 433 | Line 422 | timespec:      NUMBER timespec_
422                  {
423                          $$ = $1 * 60 * 60 * 24 * 7 + $3;
424                  }
425 +                | NUMBER MONTHS timespec_
426 +                {
427 +                        $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3;
428 +                }
429 +                | NUMBER YEARS timespec_
430 +                {
431 +                        $$ = $1 * 60 * 60 * 24 * 365 + $3;
432 +                }
433                  ;
434  
435   sizespec_:      { $$ = 0; } | sizespec;
# Line 471 | Line 468 | serverinfo_items:       serverinfo_items
468   serverinfo_item:        serverinfo_name | serverinfo_vhost |
469                          serverinfo_hub | serverinfo_description |
470                          serverinfo_network_name | serverinfo_network_desc |
471 <                        serverinfo_max_clients |
471 >                        serverinfo_max_clients | serverinfo_max_nick_length |
472 >                        serverinfo_max_topic_length | serverinfo_ssl_dh_param_file |
473                          serverinfo_rsa_private_key_file | serverinfo_vhost6 |
474                          serverinfo_sid | serverinfo_ssl_certificate_file |
475 <                        serverinfo_ssl_connection_method |
475 >                        serverinfo_ssl_client_method | serverinfo_ssl_server_method |
476 >                        serverinfo_ssl_cipher_list |
477                          error ';' ;
478  
479  
480 < serverinfo_ssl_connection_method: T_SSL_CONNECTION_METHOD
480 > serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
481 > serverinfo_ssl_server_method: T_SSL_SERVER_METHOD '=' server_method_types ';' ;
482 >
483 > client_method_types: client_method_types ',' client_method_type_item | client_method_type_item;
484 > client_method_type_item: T_SSLV3
485   {
486   #ifdef HAVE_LIBCRYPTO
487 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
488 <    ServerInfo.tls_version = 0;
487 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
488 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv3);
489   #endif
490 < } '=' method_types ';'
490 > } | T_TLSV1
491   {
492   #ifdef HAVE_LIBCRYPTO
493 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
494 <  {
492 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_SSLV3))
493 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
494 <    if (!(ServerInfo.tls_version & CONF_SERVER_INFO_TLS_VERSION_TLSV1))
495 <      SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
496 <  }
493 >  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
494 >    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_TLSv1);
495   #endif
496   };
497  
498 < method_types: method_types ',' method_type_item | method_type_item;
499 < method_type_item: T_SSLV3
498 > server_method_types: server_method_types ',' server_method_type_item | server_method_type_item;
499 > server_method_type_item: T_SSLV3
500   {
501   #ifdef HAVE_LIBCRYPTO
502 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
503 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_SSLV3;
502 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
503 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
504   #endif
505   } | T_TLSV1
506   {
507   #ifdef HAVE_LIBCRYPTO
508 <  if (conf_parser_ctx.boot && conf_parser_ctx.pass == 2)
509 <    ServerInfo.tls_version |= CONF_SERVER_INFO_TLS_VERSION_TLSV1;
508 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
509 >    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
510   #endif
511   };
512  
# Line 519 | Line 517 | serverinfo_ssl_certificate_file: SSL_CER
517    {
518      if (!ServerInfo.rsa_private_key_file)
519      {
520 <      yyerror("No rsa_private_key_file specified, SSL disabled");
520 >      conf_error_report("No rsa_private_key_file specified, SSL disabled");
521        break;
522      }
523  
524      if (SSL_CTX_use_certificate_file(ServerInfo.server_ctx, yylval.string,
525 +                                     SSL_FILETYPE_PEM) <= 0 ||
526 +        SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
527                                       SSL_FILETYPE_PEM) <= 0)
528      {
529 <      yyerror(ERR_lib_error_string(ERR_get_error()));
529 >      report_crypto_errors();
530 >      conf_error_report("Could not open/read certificate file");
531        break;
532      }
533  
534      if (SSL_CTX_use_PrivateKey_file(ServerInfo.server_ctx, ServerInfo.rsa_private_key_file,
535 +                                    SSL_FILETYPE_PEM) <= 0 ||
536 +        SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
537                                      SSL_FILETYPE_PEM) <= 0)
538      {
539 <      yyerror(ERR_lib_error_string(ERR_get_error()));
539 >      report_crypto_errors();
540 >      conf_error_report("Could not read RSA private key");
541        break;
542      }
543  
544 <    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx))
544 >    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
545 >        !SSL_CTX_check_private_key(ServerInfo.client_ctx))
546      {
547 <      yyerror(ERR_lib_error_string(ERR_get_error()));
547 >      report_crypto_errors();
548 >      conf_error_report("Could not read RSA private key");
549        break;
550      }
551    }
# Line 549 | Line 555 | serverinfo_ssl_certificate_file: SSL_CER
555   serverinfo_rsa_private_key_file: RSA_PRIVATE_KEY_FILE '=' QSTRING ';'
556   {
557   #ifdef HAVE_LIBCRYPTO
558 <  if (conf_parser_ctx.pass == 1)
558 >  BIO *file = NULL;
559 >
560 >  if (conf_parser_ctx.pass != 1)
561 >    break;
562 >
563 >  if (ServerInfo.rsa_private_key)
564 >  {
565 >    RSA_free(ServerInfo.rsa_private_key);
566 >    ServerInfo.rsa_private_key = NULL;
567 >  }
568 >
569 >  if (ServerInfo.rsa_private_key_file)
570    {
571 <    BIO *file;
571 >    MyFree(ServerInfo.rsa_private_key_file);
572 >    ServerInfo.rsa_private_key_file = NULL;
573 >  }
574  
575 <    if (ServerInfo.rsa_private_key)
557 <    {
558 <      RSA_free(ServerInfo.rsa_private_key);
559 <      ServerInfo.rsa_private_key = NULL;
560 <    }
575 >  ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
576  
577 <    if (ServerInfo.rsa_private_key_file)
578 <    {
579 <      MyFree(ServerInfo.rsa_private_key_file);
580 <      ServerInfo.rsa_private_key_file = NULL;
581 <    }
577 >  if ((file = BIO_new_file(yylval.string, "r")) == NULL)
578 >  {
579 >    conf_error_report("File open failed, ignoring");
580 >    break;
581 >  }
582  
583 <    DupString(ServerInfo.rsa_private_key_file, yylval.string);
583 >  ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
584  
585 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
586 <    {
587 <      yyerror("File open failed, ignoring");
588 <      break;
589 <    }
585 >  BIO_set_close(file, BIO_CLOSE);
586 >  BIO_free(file);
587 >
588 >  if (ServerInfo.rsa_private_key == NULL)
589 >  {
590 >    conf_error_report("Couldn't extract key, ignoring");
591 >    break;
592 >  }
593  
594 <    ServerInfo.rsa_private_key = (RSA *)PEM_read_bio_RSAPrivateKey(file, NULL,
595 <      0, NULL);
594 >  if (!RSA_check_key(ServerInfo.rsa_private_key))
595 >  {
596 >    RSA_free(ServerInfo.rsa_private_key);
597 >    ServerInfo.rsa_private_key = NULL;
598  
599 <    BIO_set_close(file, BIO_CLOSE);
600 <    BIO_free(file);
599 >    conf_error_report("Invalid key, ignoring");
600 >    break;
601 >  }
602  
603 <    if (ServerInfo.rsa_private_key == NULL)
604 <    {
605 <      yyerror("Couldn't extract key, ignoring");
606 <      break;
607 <    }
603 >  /* require 2048 bit (256 byte) key */
604 >  if (RSA_size(ServerInfo.rsa_private_key) != 256)
605 >  {
606 >    RSA_free(ServerInfo.rsa_private_key);
607 >    ServerInfo.rsa_private_key = NULL;
608  
609 <    if (!RSA_check_key(ServerInfo.rsa_private_key))
610 <    {
611 <      RSA_free(ServerInfo.rsa_private_key);
612 <      ServerInfo.rsa_private_key = NULL;
609 >    conf_error_report("Not a 2048 bit key, ignoring");
610 >  }
611 > #endif
612 > };
613  
614 <      yyerror("Invalid key, ignoring");
615 <      break;
616 <    }
614 > serverinfo_ssl_dh_param_file: SSL_DH_PARAM_FILE '=' QSTRING ';'
615 > {
616 > /* TBD - XXX: error reporting */
617 > #ifdef HAVE_LIBCRYPTO
618 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
619 >  {
620 >    BIO *file = BIO_new_file(yylval.string, "r");
621  
622 <    /* require 2048 bit (256 byte) key */
598 <    if (RSA_size(ServerInfo.rsa_private_key) != 256)
622 >    if (file)
623      {
624 <      RSA_free(ServerInfo.rsa_private_key);
601 <      ServerInfo.rsa_private_key = NULL;
624 >      DH *dh = PEM_read_bio_DHparams(file, NULL, NULL, NULL);
625  
626 <      yyerror("Not a 2048 bit key, ignoring");
626 >      BIO_free(file);
627 >
628 >      if (dh)
629 >      {
630 >        if (DH_size(dh) < 128)
631 >          conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
632 >        else
633 >          SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
634 >
635 >        DH_free(dh);
636 >      }
637      }
638    }
639   #endif
640   };
641  
642 + serverinfo_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
643 + {
644 + #ifdef HAVE_LIBCRYPTO
645 +  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
646 +    SSL_CTX_set_cipher_list(ServerInfo.server_ctx, yylval.string);
647 + #endif
648 + };
649 +
650   serverinfo_name: NAME '=' QSTRING ';'
651   {
652    /* this isn't rehashable */
653    if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
654    {
655      if (valid_servname(yylval.string))
656 <      DupString(ServerInfo.name, yylval.string);
656 >      ServerInfo.name = xstrdup(yylval.string);
657      else
658      {
659 <      ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::name -- invalid name. Aborting.");
659 >      conf_error_report("Ignoring serverinfo::name -- invalid name. Aborting.");
660        exit(0);
661      }
662    }
# Line 627 | Line 668 | serverinfo_sid: IRCD_SID '=' QSTRING ';'
668    if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
669    {
670      if (valid_sid(yylval.string))
671 <      DupString(ServerInfo.sid, yylval.string);
671 >      ServerInfo.sid = xstrdup(yylval.string);
672      else
673      {
674 <      ilog(LOG_TYPE_IRCD, "Ignoring serverinfo::sid -- invalid SID. Aborting.");
674 >      conf_error_report("Ignoring serverinfo::sid -- invalid SID. Aborting.");
675        exit(0);
676      }
677    }
# Line 641 | Line 682 | serverinfo_description: DESCRIPTION '='
682    if (conf_parser_ctx.pass == 2)
683    {
684      MyFree(ServerInfo.description);
685 <    DupString(ServerInfo.description,yylval.string);
685 >    ServerInfo.description = xstrdup(yylval.string);
686    }
687   };
688  
# Line 655 | Line 696 | serverinfo_network_name: NETWORK_NAME '=
696        p = '\0';
697  
698      MyFree(ServerInfo.network_name);
699 <    DupString(ServerInfo.network_name, yylval.string);
699 >    ServerInfo.network_name = xstrdup(yylval.string);
700    }
701   };
702  
703   serverinfo_network_desc: NETWORK_DESC '=' QSTRING ';'
704   {
705 <  if (conf_parser_ctx.pass == 2)
706 <  {
707 <    MyFree(ServerInfo.network_desc);
708 <    DupString(ServerInfo.network_desc, yylval.string);
709 <  }
705 >  if (conf_parser_ctx.pass != 2)
706 >    break;
707 >
708 >  MyFree(ServerInfo.network_desc);
709 >  ServerInfo.network_desc = xstrdup(yylval.string);
710   };
711  
712   serverinfo_vhost: VHOST '=' QSTRING ';'
# Line 728 | Line 769 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
769  
770   serverinfo_max_clients: T_MAX_CLIENTS '=' NUMBER ';'
771   {
772 <  if (conf_parser_ctx.pass == 2)
772 >  if (conf_parser_ctx.pass != 2)
773 >    break;
774 >
775 >  if ($3 < MAXCLIENTS_MIN)
776    {
777 <    recalc_fdlimit(NULL);
777 >    char buf[IRCD_BUFSIZE];
778  
779 <    if ($3 < MAXCLIENTS_MIN)
780 <    {
781 <      char buf[IRCD_BUFSIZE];
782 <      ircsprintf(buf, "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
783 <      yyerror(buf);
784 <    }
785 <    else if ($3 > MAXCLIENTS_MAX)
786 <    {
787 <      char buf[IRCD_BUFSIZE];
788 <      ircsprintf(buf, "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
789 <      yyerror(buf);
790 <    }
791 <    else
792 <      ServerInfo.max_clients = $3;
779 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
780 >    conf_error_report(buf);
781 >    ServerInfo.max_clients = MAXCLIENTS_MIN;
782 >  }
783 >  else if ($3 > MAXCLIENTS_MAX)
784 >  {
785 >    char buf[IRCD_BUFSIZE];
786 >
787 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
788 >    conf_error_report(buf);
789 >    ServerInfo.max_clients = MAXCLIENTS_MAX;
790 >  }
791 >  else
792 >    ServerInfo.max_clients = $3;
793 > };
794 >
795 > serverinfo_max_nick_length: MAX_NICK_LENGTH '=' NUMBER ';'
796 > {
797 >  if (conf_parser_ctx.pass != 2)
798 >    break;
799 >
800 >  if ($3 < 9)
801 >  {
802 >    conf_error_report("max_nick_length too low, setting to 9");
803 >    ServerInfo.max_nick_length = 9;
804 >  }
805 >  else if ($3 > NICKLEN)
806 >  {
807 >    char buf[IRCD_BUFSIZE];
808 >
809 >    snprintf(buf, sizeof(buf), "max_nick_length too high, setting to %d", NICKLEN);
810 >    conf_error_report(buf);
811 >    ServerInfo.max_nick_length = NICKLEN;
812 >  }
813 >  else
814 >    ServerInfo.max_nick_length = $3;
815 > };
816 >
817 > serverinfo_max_topic_length: MAX_TOPIC_LENGTH '=' NUMBER ';'
818 > {
819 >  if (conf_parser_ctx.pass != 2)
820 >    break;
821 >
822 >  if ($3 < 80)
823 >  {
824 >    conf_error_report("max_topic_length too low, setting to 80");
825 >    ServerInfo.max_topic_length = 80;
826 >  }
827 >  else if ($3 > TOPICLEN)
828 >  {
829 >    char buf[IRCD_BUFSIZE];
830 >
831 >    snprintf(buf, sizeof(buf), "max_topic_length too high, setting to %d", TOPICLEN);
832 >    conf_error_report(buf);
833 >    ServerInfo.max_topic_length = TOPICLEN;
834    }
835 +  else
836 +    ServerInfo.max_topic_length = $3;
837   };
838  
839   serverinfo_hub: HUB '=' TBOOL ';'
# Line 766 | Line 853 | admin_item:  admin_name | admin_descript
853  
854   admin_name: NAME '=' QSTRING ';'
855   {
856 <  if (conf_parser_ctx.pass == 2)
857 <  {
858 <    MyFree(AdminInfo.name);
859 <    DupString(AdminInfo.name, yylval.string);
860 <  }
856 >  if (conf_parser_ctx.pass != 2)
857 >    break;
858 >
859 >  MyFree(AdminInfo.name);
860 >  AdminInfo.name = xstrdup(yylval.string);
861   };
862  
863   admin_email: EMAIL '=' QSTRING ';'
864   {
865 <  if (conf_parser_ctx.pass == 2)
866 <  {
867 <    MyFree(AdminInfo.email);
868 <    DupString(AdminInfo.email, yylval.string);
869 <  }
865 >  if (conf_parser_ctx.pass != 2)
866 >    break;
867 >
868 >  MyFree(AdminInfo.email);
869 >  AdminInfo.email = xstrdup(yylval.string);
870   };
871  
872   admin_description: DESCRIPTION '=' QSTRING ';'
873   {
874 +  if (conf_parser_ctx.pass != 2)
875 +    break;
876 +
877 +  MyFree(AdminInfo.description);
878 +  AdminInfo.description = xstrdup(yylval.string);
879 + };
880 +
881 + /***************************************************************************
882 + * motd section
883 + ***************************************************************************/
884 + motd_entry: MOTD
885 + {
886    if (conf_parser_ctx.pass == 2)
887 <  {
888 <    MyFree(AdminInfo.description);
889 <    DupString(AdminInfo.description, yylval.string);
890 <  }
887 >    reset_block_state();
888 > } '{' motd_items '}' ';'
889 > {
890 >  dlink_node *ptr = NULL;
891 >
892 >  if (conf_parser_ctx.pass != 2)
893 >    break;
894 >
895 >  if (!block_state.file.buf[0])
896 >    break;
897 >
898 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
899 >    motd_add(ptr->data, block_state.file.buf);
900 > };
901 >
902 > motd_items: motd_items motd_item | motd_item;
903 > motd_item:  motd_mask | motd_file | error ';' ;
904 >
905 > motd_mask: MASK '=' QSTRING ';'
906 > {
907 >  if (conf_parser_ctx.pass == 2)
908 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
909 > };
910 >
911 > motd_file: T_FILE '=' QSTRING ';'
912 > {
913 >  if (conf_parser_ctx.pass == 2)
914 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
915   };
916  
917   /***************************************************************************
# Line 797 | Line 920 | admin_description: DESCRIPTION '=' QSTRI
920   logging_entry:          T_LOG  '{' logging_items '}' ';' ;
921   logging_items:          logging_items logging_item | logging_item ;
922  
923 < logging_item:           logging_use_logging | logging_timestamp | logging_file_entry |
923 > logging_item:           logging_use_logging | logging_file_entry |
924                          error ';' ;
925  
926   logging_use_logging: USE_LOGGING '=' TBOOL ';'
# Line 806 | Line 929 | logging_use_logging: USE_LOGGING '=' TBO
929      ConfigLoggingEntry.use_logging = yylval.number;
930   };
931  
809 logging_timestamp: T_TIMESTAMP '=' TBOOL ';'
810 {
811  if (conf_parser_ctx.pass == 2)
812    ConfigLoggingEntry.timestamp = yylval.number;
813 };
814
932   logging_file_entry:
933   {
934 <  lfile[0] = '\0';
935 <  ltype = 0;
819 <  lsize = 0;
934 >  if (conf_parser_ctx.pass == 2)
935 >    reset_block_state();
936   } T_FILE  '{' logging_file_items '}' ';'
937   {
938 <  if (conf_parser_ctx.pass == 2 && ltype > 0)
939 <    log_add_file(ltype, lsize, lfile);
938 >  if (conf_parser_ctx.pass != 2)
939 >    break;
940 >
941 >  if (block_state.type.value && block_state.file.buf[0])
942 >    log_set_file(block_state.type.value, block_state.size.value,
943 >                 block_state.file.buf);
944   };
945  
946   logging_file_items: logging_file_items logging_file_item |
# Line 831 | Line 951 | logging_file_item:  logging_file_name |
951  
952   logging_file_name: NAME '=' QSTRING ';'
953   {
954 <  strlcpy(lfile, yylval.string, sizeof(lfile));
954 >  if (conf_parser_ctx.pass != 2)
955 >    break;
956 >
957 >  strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
958   }
959  
960   logging_file_size: T_SIZE '=' sizespec ';'
961   {
962 <  lsize = $3;
962 >  block_state.size.value = $3;
963   } | T_SIZE '=' T_UNLIMITED ';'
964   {
965 <  lsize = 0;
965 >  block_state.size.value = 0;
966   };
967  
968   logging_file_type: TYPE
969   {
970    if (conf_parser_ctx.pass == 2)
971 <    ltype = 0;
971 >    block_state.type.value = 0;
972   } '='  logging_file_type_items ';' ;
973  
974   logging_file_type_items: logging_file_type_items ',' logging_file_type_item | logging_file_type_item;
975   logging_file_type_item:  USER
976   {
977    if (conf_parser_ctx.pass == 2)
978 <    ltype = LOG_TYPE_USER;
978 >    block_state.type.value = LOG_TYPE_USER;
979   } | OPERATOR
980   {
981    if (conf_parser_ctx.pass == 2)
982 <    ltype = LOG_TYPE_OPER;
982 >    block_state.type.value = LOG_TYPE_OPER;
983   } | GLINE
984   {
985    if (conf_parser_ctx.pass == 2)
986 <    ltype = LOG_TYPE_GLINE;
986 >    block_state.type.value = LOG_TYPE_GLINE;
987 > } | XLINE
988 > {
989 >  if (conf_parser_ctx.pass == 2)
990 >    block_state.type.value = LOG_TYPE_XLINE;
991 > } | RESV
992 > {
993 >  if (conf_parser_ctx.pass == 2)
994 >    block_state.type.value = LOG_TYPE_RESV;
995   } | T_DLINE
996   {
997    if (conf_parser_ctx.pass == 2)
998 <    ltype = LOG_TYPE_DLINE;
998 >    block_state.type.value = LOG_TYPE_DLINE;
999   } | KLINE
1000   {
1001    if (conf_parser_ctx.pass == 2)
1002 <    ltype = LOG_TYPE_KLINE;
1002 >    block_state.type.value = LOG_TYPE_KLINE;
1003   } | KILL
1004   {
1005    if (conf_parser_ctx.pass == 2)
1006 <    ltype = LOG_TYPE_KILL;
1006 >    block_state.type.value = LOG_TYPE_KILL;
1007   } | T_DEBUG
1008   {
1009    if (conf_parser_ctx.pass == 2)
1010 <    ltype = LOG_TYPE_DEBUG;
1010 >    block_state.type.value = LOG_TYPE_DEBUG;
1011   };
1012  
1013  
# Line 885 | Line 1016 | logging_file_type_item:  USER
1016   ***************************************************************************/
1017   oper_entry: OPERATOR
1018   {
1019 <  if (conf_parser_ctx.pass == 2)
1020 <  {
1021 <    yy_conf = make_conf_item(OPER_TYPE);
1022 <    yy_aconf = map_to_conf(yy_conf);
1023 <    SetConfEncrypted(yy_aconf); /* Yes, the default is encrypted */
1024 <  }
894 <  else
895 <  {
896 <    MyFree(class_name);
897 <    class_name = NULL;
898 <  }
899 < } oper_name_b '{' oper_items '}' ';'
1019 >  if (conf_parser_ctx.pass != 2)
1020 >    break;
1021 >
1022 >  reset_block_state();
1023 >  block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1024 > } '{' oper_items '}' ';'
1025   {
1026 <  if (conf_parser_ctx.pass == 2)
902 <  {
903 <    struct CollectItem *yy_tmp;
904 <    dlink_node *ptr;
905 <    dlink_node *next_ptr;
1026 >  dlink_node *ptr = NULL;
1027  
1028 <    conf_add_class_to_conf(yy_conf, class_name);
1028 >  if (conf_parser_ctx.pass != 2)
1029 >    break;
1030  
1031 <    /* Now, make sure there is a copy of the "base" given oper
1032 <     * block in each of the collected copies
1033 <     */
1031 >  if (!block_state.name.buf[0])
1032 >    break;
1033 > #ifdef HAVE_LIBCRYPTO
1034 >  if (!block_state.file.buf[0] &&
1035 >      !block_state.rpass.buf[0])
1036 >    break;
1037 > #else
1038 >  if (!block_state.rpass.buf[0])
1039 >    break;
1040 > #endif
1041  
1042 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1043 <    {
1044 <      struct AccessItem *new_aconf;
1045 <      struct ConfItem *new_conf;
917 <      yy_tmp = ptr->data;
918 <
919 <      new_conf = make_conf_item(OPER_TYPE);
920 <      new_aconf = (struct AccessItem *)map_to_conf(new_conf);
921 <
922 <      new_aconf->flags = yy_aconf->flags;
923 <
924 <      if (yy_conf->name != NULL)
925 <        DupString(new_conf->name, yy_conf->name);
926 <      if (yy_tmp->user != NULL)
927 <        DupString(new_aconf->user, yy_tmp->user);
928 <      else
929 <        DupString(new_aconf->user, "*");
930 <      if (yy_tmp->host != NULL)
931 <        DupString(new_aconf->host, yy_tmp->host);
932 <      else
933 <        DupString(new_aconf->host, "*");
934 <      conf_add_class_to_conf(new_conf, class_name);
935 <      if (yy_aconf->passwd != NULL)
936 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1042 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1043 >  {
1044 >    struct MaskItem *conf = NULL;
1045 >    struct split_nuh_item nuh;
1046  
1047 <      new_aconf->port = yy_aconf->port;
1048 < #ifdef HAVE_LIBCRYPTO
1049 <      if (yy_aconf->rsa_public_key_file != NULL)
1050 <      {
1051 <        BIO *file;
1047 >    nuh.nuhmask  = ptr->data;
1048 >    nuh.nickptr  = NULL;
1049 >    nuh.userptr  = block_state.user.buf;
1050 >    nuh.hostptr  = block_state.host.buf;
1051 >    nuh.nicksize = 0;
1052 >    nuh.usersize = sizeof(block_state.user.buf);
1053 >    nuh.hostsize = sizeof(block_state.host.buf);
1054 >    split_nuh(&nuh);
1055  
1056 <        DupString(new_aconf->rsa_public_key_file,
1057 <                  yy_aconf->rsa_public_key_file);
1056 >    conf         = conf_make(CONF_OPER);
1057 >    conf->name   = xstrdup(block_state.name.buf);
1058 >    conf->user   = xstrdup(block_state.user.buf);
1059 >    conf->host   = xstrdup(block_state.host.buf);
1060 >
1061 >    if (block_state.cert.buf[0])
1062 >      conf->certfp = xstrdup(block_state.cert.buf);
1063 >
1064 >    if (block_state.rpass.buf[0])
1065 >      conf->passwd = xstrdup(block_state.rpass.buf);
1066 >
1067 >    conf->flags = block_state.flags.value;
1068 >    conf->modes = block_state.modes.value;
1069 >    conf->port  = block_state.port.value;
1070 >    conf->htype = parse_netmask(conf->host, &conf->addr, &conf->bits);
1071  
1072 <        file = BIO_new_file(yy_aconf->rsa_public_key_file, "r");
948 <        new_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file,
949 <                                                           NULL, 0, NULL);
950 <        BIO_set_close(file, BIO_CLOSE);
951 <        BIO_free(file);
952 <      }
953 < #endif
1072 >    conf_add_class_to_conf(conf, block_state.class.buf);
1073  
1074   #ifdef HAVE_LIBCRYPTO
1075 <      if (yy_tmp->name && (yy_tmp->passwd || yy_aconf->rsa_public_key)
1076 <          && yy_tmp->host)
1077 < #else
1078 <      if (yy_tmp->name && yy_tmp->passwd && yy_tmp->host)
1079 < #endif
1075 >    if (block_state.file.buf[0])
1076 >    {
1077 >      BIO *file = NULL;
1078 >      RSA *pkey = NULL;
1079 >
1080 >      if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
1081        {
1082 <        conf_add_class_to_conf(new_conf, class_name);
1083 <        if (yy_tmp->name != NULL)
964 <          DupString(new_conf->name, yy_tmp->name);
1082 >        conf_error_report("Ignoring rsa_public_key_file -- file doesn't exist");
1083 >        break;
1084        }
1085  
1086 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1087 <      free_collect_item(yy_tmp);
969 <    }
970 <
971 <    yy_conf = NULL;
972 <    yy_aconf = NULL;
973 <
1086 >      if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
1087 >        conf_error_report("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1088  
1089 <    MyFree(class_name);
1090 <    class_name = NULL;
1089 >      conf->rsa_public_key = pkey;
1090 >      BIO_set_close(file, BIO_CLOSE);
1091 >      BIO_free(file);
1092 >    }
1093 > #endif /* HAVE_LIBCRYPTO */
1094    }
1095 < };
1095 > };
1096  
980 oper_name_b: | oper_name_t;
1097   oper_items:     oper_items oper_item | oper_item;
1098   oper_item:      oper_name | oper_user | oper_password |
1099                  oper_umodes | oper_class | oper_encrypted |
1100 <                oper_rsa_public_key_file | oper_flags | error ';' ;
1100 >                oper_rsa_public_key_file | oper_ssl_certificate_fingerprint |
1101 >                oper_ssl_connection_required |
1102 >                oper_flags | error ';' ;
1103  
1104   oper_name: NAME '=' QSTRING ';'
1105   {
1106    if (conf_parser_ctx.pass == 2)
1107 <  {
990 <    if (strlen(yylval.string) > OPERNICKLEN)
991 <      yylval.string[OPERNICKLEN] = '\0';
992 <
993 <    MyFree(yy_conf->name);
994 <    DupString(yy_conf->name, yylval.string);
995 <  }
996 < };
997 <
998 < oper_name_t: QSTRING
999 < {
1000 <  if (conf_parser_ctx.pass == 2)
1001 <  {
1002 <    if (strlen(yylval.string) > OPERNICKLEN)
1003 <      yylval.string[OPERNICKLEN] = '\0';
1004 <
1005 <    MyFree(yy_conf->name);
1006 <    DupString(yy_conf->name, yylval.string);
1007 <  }
1107 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1108   };
1109  
1110   oper_user: USER '=' QSTRING ';'
1111   {
1112    if (conf_parser_ctx.pass == 2)
1113 <  {
1014 <    struct split_nuh_item nuh;
1015 <
1016 <    nuh.nuhmask  = yylval.string;
1017 <    nuh.nickptr  = NULL;
1018 <    nuh.userptr  = userbuf;
1019 <    nuh.hostptr  = hostbuf;
1020 <
1021 <    nuh.nicksize = 0;
1022 <    nuh.usersize = sizeof(userbuf);
1023 <    nuh.hostsize = sizeof(hostbuf);
1024 <
1025 <    split_nuh(&nuh);
1026 <
1027 <    if (yy_aconf->user == NULL)
1028 <    {
1029 <      DupString(yy_aconf->user, userbuf);
1030 <      DupString(yy_aconf->host, hostbuf);
1031 <    }
1032 <    else
1033 <    {
1034 <      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
1035 <
1036 <      DupString(yy_tmp->user, userbuf);
1037 <      DupString(yy_tmp->host, hostbuf);
1038 <
1039 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1040 <    }
1041 <  }
1113 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1114   };
1115  
1116   oper_password: PASSWORD '=' QSTRING ';'
1117   {
1118    if (conf_parser_ctx.pass == 2)
1119 <  {
1048 <    if (yy_aconf->passwd != NULL)
1049 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1050 <
1051 <    MyFree(yy_aconf->passwd);
1052 <    DupString(yy_aconf->passwd, yylval.string);
1053 <  }
1119 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1120   };
1121  
1122   oper_encrypted: ENCRYPTED '=' TBOOL ';'
1123   {
1124 <  if (conf_parser_ctx.pass == 2)
1125 <  {
1126 <    if (yylval.number)
1127 <      SetConfEncrypted(yy_aconf);
1128 <    else
1129 <      ClearConfEncrypted(yy_aconf);
1130 <  }
1124 >  if (conf_parser_ctx.pass != 2)
1125 >    break;
1126 >
1127 >  if (yylval.number)
1128 >    block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1129 >  else
1130 >    block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1131   };
1132  
1133   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
1134   {
1069 #ifdef HAVE_LIBCRYPTO
1135    if (conf_parser_ctx.pass == 2)
1136 <  {
1137 <    BIO *file;
1073 <
1074 <    if (yy_aconf->rsa_public_key != NULL)
1075 <    {
1076 <      RSA_free(yy_aconf->rsa_public_key);
1077 <      yy_aconf->rsa_public_key = NULL;
1078 <    }
1079 <
1080 <    if (yy_aconf->rsa_public_key_file != NULL)
1081 <    {
1082 <      MyFree(yy_aconf->rsa_public_key_file);
1083 <      yy_aconf->rsa_public_key_file = NULL;
1084 <    }
1085 <
1086 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
1087 <    file = BIO_new_file(yylval.string, "r");
1088 <
1089 <    if (file == NULL)
1090 <    {
1091 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
1092 <      break;
1093 <    }
1136 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1137 > };
1138  
1139 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
1139 > oper_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
1140 > {
1141 >  if (conf_parser_ctx.pass == 2)
1142 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
1143 > };
1144  
1145 <    if (yy_aconf->rsa_public_key == NULL)
1146 <    {
1147 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1148 <      break;
1101 <    }
1145 > oper_ssl_connection_required: SSL_CONNECTION_REQUIRED '=' TBOOL ';'
1146 > {
1147 >  if (conf_parser_ctx.pass != 2)
1148 >    break;
1149  
1150 <    BIO_set_close(file, BIO_CLOSE);
1151 <    BIO_free(file);
1152 <  }
1153 < #endif /* HAVE_LIBCRYPTO */
1150 >  if (yylval.number)
1151 >    block_state.flags.value |= CONF_FLAGS_SSL;
1152 >  else
1153 >    block_state.flags.value &= ~CONF_FLAGS_SSL;
1154   };
1155  
1156   oper_class: CLASS '=' QSTRING ';'
1157   {
1158    if (conf_parser_ctx.pass == 2)
1159 <  {
1113 <    MyFree(class_name);
1114 <    DupString(class_name, yylval.string);
1115 <  }
1159 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1160   };
1161  
1162   oper_umodes: T_UMODES
1163   {
1164    if (conf_parser_ctx.pass == 2)
1165 <    yy_aconf->modes = 0;
1165 >    block_state.modes.value = 0;
1166   } '='  oper_umodes_items ';' ;
1167  
1168   oper_umodes_items: oper_umodes_items ',' oper_umodes_item | oper_umodes_item;
1169   oper_umodes_item:  T_BOTS
1170   {
1171    if (conf_parser_ctx.pass == 2)
1172 <    yy_aconf->modes |= UMODE_BOTS;
1172 >    block_state.modes.value |= UMODE_BOTS;
1173   } | T_CCONN
1174   {
1175    if (conf_parser_ctx.pass == 2)
1176 <    yy_aconf->modes |= UMODE_CCONN;
1133 < } | T_CCONN_FULL
1134 < {
1135 <  if (conf_parser_ctx.pass == 2)
1136 <    yy_aconf->modes |= UMODE_CCONN_FULL;
1176 >    block_state.modes.value |= UMODE_CCONN;
1177   } | T_DEAF
1178   {
1179    if (conf_parser_ctx.pass == 2)
1180 <    yy_aconf->modes |= UMODE_DEAF;
1180 >    block_state.modes.value |= UMODE_DEAF;
1181   } | T_DEBUG
1182   {
1183    if (conf_parser_ctx.pass == 2)
1184 <    yy_aconf->modes |= UMODE_DEBUG;
1184 >    block_state.modes.value |= UMODE_DEBUG;
1185   } | T_FULL
1186   {
1187    if (conf_parser_ctx.pass == 2)
1188 <    yy_aconf->modes |= UMODE_FULL;
1188 >    block_state.modes.value |= UMODE_FULL;
1189 > } | HIDDEN
1190 > {
1191 >  if (conf_parser_ctx.pass == 2)
1192 >    block_state.modes.value |= UMODE_HIDDEN;
1193   } | T_SKILL
1194   {
1195    if (conf_parser_ctx.pass == 2)
1196 <    yy_aconf->modes |= UMODE_SKILL;
1196 >    block_state.modes.value |= UMODE_SKILL;
1197   } | T_NCHANGE
1198   {
1199    if (conf_parser_ctx.pass == 2)
1200 <    yy_aconf->modes |= UMODE_NCHANGE;
1200 >    block_state.modes.value |= UMODE_NCHANGE;
1201   } | T_REJ
1202   {
1203    if (conf_parser_ctx.pass == 2)
1204 <    yy_aconf->modes |= UMODE_REJ;
1204 >    block_state.modes.value |= UMODE_REJ;
1205   } | T_UNAUTH
1206   {
1207    if (conf_parser_ctx.pass == 2)
1208 <    yy_aconf->modes |= UMODE_UNAUTH;
1208 >    block_state.modes.value |= UMODE_UNAUTH;
1209   } | T_SPY
1210   {
1211    if (conf_parser_ctx.pass == 2)
1212 <    yy_aconf->modes |= UMODE_SPY;
1212 >    block_state.modes.value |= UMODE_SPY;
1213   } | T_EXTERNAL
1214   {
1215    if (conf_parser_ctx.pass == 2)
1216 <    yy_aconf->modes |= UMODE_EXTERNAL;
1216 >    block_state.modes.value |= UMODE_EXTERNAL;
1217   } | T_OPERWALL
1218   {
1219    if (conf_parser_ctx.pass == 2)
1220 <    yy_aconf->modes |= UMODE_OPERWALL;
1220 >    block_state.modes.value |= UMODE_OPERWALL;
1221   } | T_SERVNOTICE
1222   {
1223    if (conf_parser_ctx.pass == 2)
1224 <    yy_aconf->modes |= UMODE_SERVNOTICE;
1224 >    block_state.modes.value |= UMODE_SERVNOTICE;
1225   } | T_INVISIBLE
1226   {
1227    if (conf_parser_ctx.pass == 2)
1228 <    yy_aconf->modes |= UMODE_INVISIBLE;
1228 >    block_state.modes.value |= UMODE_INVISIBLE;
1229   } | T_WALLOP
1230   {
1231    if (conf_parser_ctx.pass == 2)
1232 <    yy_aconf->modes |= UMODE_WALLOP;
1232 >    block_state.modes.value |= UMODE_WALLOP;
1233   } | T_SOFTCALLERID
1234   {
1235    if (conf_parser_ctx.pass == 2)
1236 <    yy_aconf->modes |= UMODE_SOFTCALLERID;
1236 >    block_state.modes.value |= UMODE_SOFTCALLERID;
1237   } | T_CALLERID
1238   {
1239    if (conf_parser_ctx.pass == 2)
1240 <    yy_aconf->modes |= UMODE_CALLERID;
1240 >    block_state.modes.value |= UMODE_CALLERID;
1241   } | T_LOCOPS
1242   {
1243    if (conf_parser_ctx.pass == 2)
1244 <    yy_aconf->modes |= UMODE_LOCOPS;
1244 >    block_state.modes.value |= UMODE_LOCOPS;
1245 > } | T_NONONREG
1246 > {
1247 >  if (conf_parser_ctx.pass == 2)
1248 >    block_state.modes.value |= UMODE_REGONLY;
1249 > } | T_FARCONNECT
1250 > {
1251 >  if (conf_parser_ctx.pass == 2)
1252 >    block_state.modes.value |= UMODE_FARCONNECT;
1253   };
1254  
1255   oper_flags: IRCD_FLAGS
1256   {
1257    if (conf_parser_ctx.pass == 2)
1258 <    yy_aconf->port = 0;
1258 >    block_state.port.value = 0;
1259   } '='  oper_flags_items ';';
1260  
1261   oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1262 < oper_flags_item: GLOBAL_KILL
1262 > oper_flags_item: KILL ':' REMOTE
1263   {
1264    if (conf_parser_ctx.pass == 2)
1265 <    yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1266 < } | REMOTE
1265 >    block_state.port.value |= OPER_FLAG_KILL_REMOTE;
1266 > } | KILL
1267 > {
1268 >  if (conf_parser_ctx.pass == 2)
1269 >    block_state.port.value |= OPER_FLAG_KILL;
1270 > } | CONNECT ':' REMOTE
1271 > {
1272 >  if (conf_parser_ctx.pass == 2)
1273 >    block_state.port.value |= OPER_FLAG_CONNECT_REMOTE;
1274 > } | CONNECT
1275 > {
1276 >  if (conf_parser_ctx.pass == 2)
1277 >    block_state.port.value |= OPER_FLAG_CONNECT;
1278 > } | SQUIT ':' REMOTE
1279   {
1280    if (conf_parser_ctx.pass == 2)
1281 <    yy_aconf->port |= OPER_FLAG_REMOTE;
1281 >    block_state.port.value |= OPER_FLAG_SQUIT_REMOTE;
1282 > } | SQUIT
1283 > {
1284 >  if (conf_parser_ctx.pass == 2)
1285 >    block_state.port.value |= OPER_FLAG_SQUIT;
1286   } | KLINE
1287   {
1288    if (conf_parser_ctx.pass == 2)
1289 <    yy_aconf->port |= OPER_FLAG_K;
1289 >    block_state.port.value |= OPER_FLAG_K;
1290   } | UNKLINE
1291   {
1292    if (conf_parser_ctx.pass == 2)
1293 <    yy_aconf->port |= OPER_FLAG_UNKLINE;
1293 >    block_state.port.value |= OPER_FLAG_UNKLINE;
1294 > } | T_DLINE
1295 > {
1296 >  if (conf_parser_ctx.pass == 2)
1297 >    block_state.port.value |= OPER_FLAG_DLINE;
1298 > } | T_UNDLINE
1299 > {
1300 >  if (conf_parser_ctx.pass == 2)
1301 >    block_state.port.value |= OPER_FLAG_UNDLINE;
1302   } | XLINE
1303   {
1304    if (conf_parser_ctx.pass == 2)
1305 <    yy_aconf->port |= OPER_FLAG_X;
1305 >    block_state.port.value |= OPER_FLAG_X;
1306   } | GLINE
1307   {
1308    if (conf_parser_ctx.pass == 2)
1309 <    yy_aconf->port |= OPER_FLAG_GLINE;
1309 >    block_state.port.value |= OPER_FLAG_GLINE;
1310   } | DIE
1311   {
1312    if (conf_parser_ctx.pass == 2)
1313 <    yy_aconf->port |= OPER_FLAG_DIE;
1313 >    block_state.port.value |= OPER_FLAG_DIE;
1314   } | T_RESTART
1315   {
1316    if (conf_parser_ctx.pass == 2)
1317 <    yy_aconf->port |= OPER_FLAG_RESTART;
1317 >    block_state.port.value |= OPER_FLAG_RESTART;
1318   } | REHASH
1319   {
1320    if (conf_parser_ctx.pass == 2)
1321 <    yy_aconf->port |= OPER_FLAG_REHASH;
1321 >    block_state.port.value |= OPER_FLAG_REHASH;
1322   } | ADMIN
1323   {
1324    if (conf_parser_ctx.pass == 2)
1325 <    yy_aconf->port |= OPER_FLAG_ADMIN;
1250 < } | HIDDEN_ADMIN
1251 < {
1252 <  if (conf_parser_ctx.pass == 2)
1253 <    yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1254 < } | NICK_CHANGES
1255 < {
1256 <  if (conf_parser_ctx.pass == 2)
1257 <    yy_aconf->port |= OPER_FLAG_N;
1325 >    block_state.port.value |= OPER_FLAG_ADMIN;
1326   } | T_OPERWALL
1327   {
1328    if (conf_parser_ctx.pass == 2)
1329 <    yy_aconf->port |= OPER_FLAG_OPERWALL;
1329 >    block_state.port.value |= OPER_FLAG_OPERWALL;
1330   } | T_GLOBOPS
1331   {
1332    if (conf_parser_ctx.pass == 2)
1333 <    yy_aconf->port |= OPER_FLAG_GLOBOPS;
1334 < } | OPER_SPY_T
1333 >    block_state.port.value |= OPER_FLAG_GLOBOPS;
1334 > } | T_WALLOPS
1335   {
1336    if (conf_parser_ctx.pass == 2)
1337 <    yy_aconf->port |= OPER_FLAG_OPER_SPY;
1338 < } | HIDDEN_OPER
1337 >    block_state.port.value |= OPER_FLAG_WALLOPS;
1338 > } | T_LOCOPS
1339   {
1340    if (conf_parser_ctx.pass == 2)
1341 <    yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1341 >    block_state.port.value |= OPER_FLAG_LOCOPS;
1342   } | REMOTEBAN
1343   {
1344    if (conf_parser_ctx.pass == 2)
1345 <    yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1345 >    block_state.port.value |= OPER_FLAG_REMOTEBAN;
1346 > } | T_SET
1347 > {
1348 >  if (conf_parser_ctx.pass == 2)
1349 >    block_state.port.value |= OPER_FLAG_SET;
1350   } | MODULE
1351   {
1352    if (conf_parser_ctx.pass == 2)
1353 <    yy_aconf->port |= OPER_FLAG_MODULE;
1353 >    block_state.port.value |= OPER_FLAG_MODULE;
1354   };
1355  
1356  
# Line 1287 | Line 1359 | oper_flags_item: GLOBAL_KILL
1359   ***************************************************************************/
1360   class_entry: CLASS
1361   {
1362 <  if (conf_parser_ctx.pass == 1)
1363 <  {
1292 <    yy_conf = make_conf_item(CLASS_TYPE);
1293 <    yy_class = map_to_conf(yy_conf);
1294 <  }
1295 < } class_name_b '{' class_items '}' ';'
1296 < {
1297 <  if (conf_parser_ctx.pass == 1)
1298 <  {
1299 <    struct ConfItem *cconf = NULL;
1300 <    struct ClassItem *class = NULL;
1301 <
1302 <    if (yy_class_name == NULL)
1303 <      delete_conf_item(yy_conf);
1304 <    else
1305 <    {
1306 <      cconf = find_exact_name_conf(CLASS_TYPE, yy_class_name, NULL, NULL);
1307 <
1308 <      if (cconf != NULL)                /* The class existed already */
1309 <      {
1310 <        int user_count = 0;
1311 <
1312 <        rebuild_cidr_class(cconf, yy_class);
1313 <
1314 <        class = map_to_conf(cconf);
1315 <
1316 <        user_count = class->curr_user_count;
1317 <        memcpy(class, yy_class, sizeof(*class));
1318 <        class->curr_user_count = user_count;
1319 <        class->active = 1;
1362 >  if (conf_parser_ctx.pass != 1)
1363 >    break;
1364  
1365 <        delete_conf_item(yy_conf);
1365 >  reset_block_state();
1366  
1367 <        MyFree(cconf->name);            /* Allows case change of class name */
1368 <        cconf->name = yy_class_name;
1369 <      }
1370 <      else      /* Brand new class */
1371 <      {
1372 <        MyFree(yy_conf->name);          /* just in case it was allocated */
1373 <        yy_conf->name = yy_class_name;
1374 <        yy_class->active = 1;
1375 <      }
1376 <    }
1377 <
1378 <    yy_class_name = NULL;
1379 <  }
1367 >  block_state.ping_freq.value = DEFAULT_PINGFREQUENCY;
1368 >  block_state.con_freq.value  = DEFAULT_CONNECTFREQUENCY;
1369 >  block_state.max_total.value = MAXIMUM_LINKS_DEFAULT;
1370 >  block_state.max_sendq.value = DEFAULT_SENDQ;
1371 >  block_state.max_recvq.value = DEFAULT_RECVQ;
1372 > } '{' class_items '}' ';'
1373 > {
1374 >  struct ClassItem *class = NULL;
1375 >
1376 >  if (conf_parser_ctx.pass != 1)
1377 >    break;
1378 >
1379 >  if (!block_state.class.buf[0])
1380 >    break;
1381 >
1382 >  if (!(class = class_find(block_state.class.buf, 0)))
1383 >    class = class_make();
1384 >
1385 >  class->active = 1;
1386 >  MyFree(class->name);
1387 >  class->name = xstrdup(block_state.class.buf);
1388 >  class->ping_freq = block_state.ping_freq.value;
1389 >  class->max_perip = block_state.max_perip.value;
1390 >  class->con_freq = block_state.con_freq.value;
1391 >  class->max_total = block_state.max_total.value;
1392 >  class->max_global = block_state.max_global.value;
1393 >  class->max_local = block_state.max_local.value;
1394 >  class->max_ident = block_state.max_ident.value;
1395 >  class->max_sendq = block_state.max_sendq.value;
1396 >  class->max_recvq = block_state.max_recvq.value;
1397 >
1398 >  if (block_state.min_idle.value > block_state.max_idle.value)
1399 >  {
1400 >    block_state.min_idle.value = 0;
1401 >    block_state.max_idle.value = 0;
1402 >    block_state.flags.value &= ~CLASS_FLAGS_FAKE_IDLE;
1403 >  }
1404 >
1405 >  class->flags = block_state.flags.value;
1406 >  class->min_idle = block_state.min_idle.value;
1407 >  class->max_idle = block_state.max_idle.value;
1408 >
1409 >  if (class->number_per_cidr && block_state.number_per_cidr.value)
1410 >    if ((class->cidr_bitlen_ipv4 && block_state.cidr_bitlen_ipv4.value) ||
1411 >        (class->cidr_bitlen_ipv6 && block_state.cidr_bitlen_ipv6.value))
1412 >      if ((class->cidr_bitlen_ipv4 != block_state.cidr_bitlen_ipv4.value) ||
1413 >          (class->cidr_bitlen_ipv6 != block_state.cidr_bitlen_ipv6.value))
1414 >        rebuild_cidr_list(class);
1415 >
1416 >  class->cidr_bitlen_ipv4 = block_state.cidr_bitlen_ipv4.value;
1417 >  class->cidr_bitlen_ipv6 = block_state.cidr_bitlen_ipv6.value;
1418 >  class->number_per_cidr = block_state.number_per_cidr.value;
1419   };
1420  
1338 class_name_b: | class_name_t;
1339
1421   class_items:    class_items class_item | class_item;
1422   class_item:     class_name |
1423                  class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1424                  class_ping_time |
1344                class_ping_warning |
1425                  class_number_per_cidr |
1426                  class_number_per_ip |
1427                  class_connectfreq |
# Line 1349 | Line 1429 | class_item:     class_name |
1429                  class_max_global |
1430                  class_max_local |
1431                  class_max_ident |
1432 <                class_sendq |
1432 >                class_sendq | class_recvq |
1433 >                class_min_idle |
1434 >                class_max_idle |
1435 >                class_flags |
1436                  error ';' ;
1437  
1438   class_name: NAME '=' QSTRING ';'
1439   {
1440    if (conf_parser_ctx.pass == 1)
1441 <  {
1359 <    MyFree(yy_class_name);
1360 <    DupString(yy_class_name, yylval.string);
1361 <  }
1362 < };
1363 <
1364 < class_name_t: QSTRING
1365 < {
1366 <  if (conf_parser_ctx.pass == 1)
1367 <  {
1368 <    MyFree(yy_class_name);
1369 <    DupString(yy_class_name, yylval.string);
1370 <  }
1441 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1442   };
1443  
1444   class_ping_time: PING_TIME '=' timespec ';'
1445   {
1446    if (conf_parser_ctx.pass == 1)
1447 <    PingFreq(yy_class) = $3;
1377 < };
1378 <
1379 < class_ping_warning: PING_WARNING '=' timespec ';'
1380 < {
1381 <  if (conf_parser_ctx.pass == 1)
1382 <    PingWarning(yy_class) = $3;
1447 >    block_state.ping_freq.value = $3;
1448   };
1449  
1450   class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1451   {
1452    if (conf_parser_ctx.pass == 1)
1453 <    MaxPerIp(yy_class) = $3;
1453 >    block_state.max_perip.value = $3;
1454   };
1455  
1456   class_connectfreq: CONNECTFREQ '=' timespec ';'
1457   {
1458    if (conf_parser_ctx.pass == 1)
1459 <    ConFreq(yy_class) = $3;
1459 >    block_state.con_freq.value = $3;
1460   };
1461  
1462   class_max_number: MAX_NUMBER '=' NUMBER ';'
1463   {
1464    if (conf_parser_ctx.pass == 1)
1465 <    MaxTotal(yy_class) = $3;
1465 >    block_state.max_total.value = $3;
1466   };
1467  
1468   class_max_global: MAX_GLOBAL '=' NUMBER ';'
1469   {
1470    if (conf_parser_ctx.pass == 1)
1471 <    MaxGlobal(yy_class) = $3;
1471 >    block_state.max_global.value = $3;
1472   };
1473  
1474   class_max_local: MAX_LOCAL '=' NUMBER ';'
1475   {
1476    if (conf_parser_ctx.pass == 1)
1477 <    MaxLocal(yy_class) = $3;
1477 >    block_state.max_local.value = $3;
1478   };
1479  
1480   class_max_ident: MAX_IDENT '=' NUMBER ';'
1481   {
1482    if (conf_parser_ctx.pass == 1)
1483 <    MaxIdent(yy_class) = $3;
1483 >    block_state.max_ident.value = $3;
1484   };
1485  
1486   class_sendq: SENDQ '=' sizespec ';'
1487   {
1488    if (conf_parser_ctx.pass == 1)
1489 <    MaxSendq(yy_class) = $3;
1489 >    block_state.max_sendq.value = $3;
1490 > };
1491 >
1492 > class_recvq: T_RECVQ '=' sizespec ';'
1493 > {
1494 >  if (conf_parser_ctx.pass == 1)
1495 >    if ($3 >= CLIENT_FLOOD_MIN && $3 <= CLIENT_FLOOD_MAX)
1496 >      block_state.max_recvq.value = $3;
1497   };
1498  
1499   class_cidr_bitlen_ipv4: CIDR_BITLEN_IPV4 '=' NUMBER ';'
1500   {
1501    if (conf_parser_ctx.pass == 1)
1502 <    CidrBitlenIPV4(yy_class) = $3;
1502 >    block_state.cidr_bitlen_ipv4.value = $3 > 32 ? 32 : $3;
1503   };
1504  
1505   class_cidr_bitlen_ipv6: CIDR_BITLEN_IPV6 '=' NUMBER ';'
1506   {
1507    if (conf_parser_ctx.pass == 1)
1508 <    CidrBitlenIPV6(yy_class) = $3;
1508 >    block_state.cidr_bitlen_ipv6.value = $3 > 128 ? 128 : $3;
1509   };
1510  
1511   class_number_per_cidr: NUMBER_PER_CIDR '=' NUMBER ';'
1512   {
1513    if (conf_parser_ctx.pass == 1)
1514 <    NumberPerCidr(yy_class) = $3;
1514 >    block_state.number_per_cidr.value = $3;
1515 > };
1516 >
1517 > class_min_idle: MIN_IDLE '=' timespec ';'
1518 > {
1519 >  if (conf_parser_ctx.pass != 1)
1520 >    break;
1521 >
1522 >  block_state.min_idle.value = $3;
1523 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1524 > };
1525 >
1526 > class_max_idle: MAX_IDLE '=' timespec ';'
1527 > {
1528 >  if (conf_parser_ctx.pass != 1)
1529 >    break;
1530 >
1531 >  block_state.max_idle.value = $3;
1532 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1533 > };
1534 >
1535 > class_flags: IRCD_FLAGS
1536 > {
1537 >  if (conf_parser_ctx.pass == 1)
1538 >    block_state.flags.value &= CLASS_FLAGS_FAKE_IDLE;
1539 > } '='  class_flags_items ';';
1540 >
1541 > class_flags_items: class_flags_items ',' class_flags_item | class_flags_item;
1542 > class_flags_item: RANDOM_IDLE
1543 > {
1544 >  if (conf_parser_ctx.pass == 1)
1545 >    block_state.flags.value |= CLASS_FLAGS_RANDOM_IDLE;
1546 > } | HIDE_IDLE_FROM_OPERS
1547 > {
1548 >  if (conf_parser_ctx.pass == 1)
1549 >    block_state.flags.value |= CLASS_FLAGS_HIDE_IDLE_FROM_OPERS;
1550   };
1551  
1552 +
1553   /***************************************************************************
1554   *  section listen
1555   ***************************************************************************/
1556   listen_entry: LISTEN
1557   {
1558    if (conf_parser_ctx.pass == 2)
1559 <  {
1560 <    listener_address = NULL;
1453 <    listener_flags = 0;
1454 <  }
1455 < } '{' listen_items '}' ';'
1456 < {
1457 <  if (conf_parser_ctx.pass == 2)
1458 <  {
1459 <    MyFree(listener_address);
1460 <    listener_address = NULL;
1461 <  }
1462 < };
1559 >    reset_block_state();
1560 > } '{' listen_items '}' ';';
1561  
1562   listen_flags: IRCD_FLAGS
1563   {
1564 <  listener_flags = 0;
1564 >  block_state.flags.value = 0;
1565   } '='  listen_flags_items ';';
1566  
1567   listen_flags_items: listen_flags_items ',' listen_flags_item | listen_flags_item;
1568   listen_flags_item: T_SSL
1569   {
1570    if (conf_parser_ctx.pass == 2)
1571 <    listener_flags |= LISTENER_SSL;
1571 >    block_state.flags.value |= LISTENER_SSL;
1572   } | HIDDEN
1573   {
1574    if (conf_parser_ctx.pass == 2)
1575 <    listener_flags |= LISTENER_HIDDEN;
1575 >    block_state.flags.value |= LISTENER_HIDDEN;
1576   } | T_SERVER
1577   {
1578    if (conf_parser_ctx.pass == 2)
1579 <    listener_flags |= LISTENER_SERVER;
1579 >   block_state.flags.value |= LISTENER_SERVER;
1580   };
1581  
1484
1485
1582   listen_items:   listen_items listen_item | listen_item;
1583   listen_item:    listen_port | listen_flags | listen_address | listen_host | error ';';
1584  
1585 < listen_port: PORT '=' port_items { listener_flags = 0; } ';';
1585 > listen_port: PORT '=' port_items { block_state.flags.value = 0; } ';';
1586  
1587   port_items: port_items ',' port_item | port_item;
1588  
# Line 1494 | Line 1590 | port_item: NUMBER
1590   {
1591    if (conf_parser_ctx.pass == 2)
1592    {
1593 <    if ((listener_flags & LISTENER_SSL))
1593 >    if (block_state.flags.value & LISTENER_SSL)
1594   #ifdef HAVE_LIBCRYPTO
1595        if (!ServerInfo.server_ctx)
1596   #endif
1597        {
1598 <        yyerror("SSL not available - port closed");
1598 >        conf_error_report("SSL not available - port closed");
1599          break;
1600        }
1601 <    add_listener($1, listener_address, listener_flags);
1601 >    add_listener($1, block_state.addr.buf, block_state.flags.value);
1602    }
1603   } | NUMBER TWODOTS NUMBER
1604   {
# Line 1510 | Line 1606 | port_item: NUMBER
1606    {
1607      int i;
1608  
1609 <    if ((listener_flags & LISTENER_SSL))
1609 >    if (block_state.flags.value & LISTENER_SSL)
1610   #ifdef HAVE_LIBCRYPTO
1611        if (!ServerInfo.server_ctx)
1612   #endif
1613        {
1614 <        yyerror("SSL not available - port closed");
1614 >        conf_error_report("SSL not available - port closed");
1615          break;
1616        }
1617  
1618      for (i = $1; i <= $3; ++i)
1619 <      add_listener(i, listener_address, listener_flags);
1619 >      add_listener(i, block_state.addr.buf, block_state.flags.value);
1620    }
1621   };
1622  
1623   listen_address: IP '=' QSTRING ';'
1624   {
1625    if (conf_parser_ctx.pass == 2)
1626 <  {
1531 <    MyFree(listener_address);
1532 <    DupString(listener_address, yylval.string);
1533 <  }
1626 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1627   };
1628  
1629   listen_host: HOST '=' QSTRING ';'
1630   {
1631    if (conf_parser_ctx.pass == 2)
1632 <  {
1540 <    MyFree(listener_address);
1541 <    DupString(listener_address, yylval.string);
1542 <  }
1632 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1633   };
1634  
1635   /***************************************************************************
# Line 1548 | Line 1638 | listen_host: HOST '=' QSTRING ';'
1638   auth_entry: IRCD_AUTH
1639   {
1640    if (conf_parser_ctx.pass == 2)
1641 <  {
1552 <    yy_conf = make_conf_item(CLIENT_TYPE);
1553 <    yy_aconf = map_to_conf(yy_conf);
1554 <  }
1555 <  else
1556 <  {
1557 <    MyFree(class_name);
1558 <    class_name = NULL;
1559 <  }
1641 >    reset_block_state();
1642   } '{' auth_items '}' ';'
1643   {
1644 <  if (conf_parser_ctx.pass == 2)
1563 <  {
1564 <    struct CollectItem *yy_tmp = NULL;
1565 <    dlink_node *ptr = NULL, *next_ptr = NULL;
1566 <
1567 <    if (yy_aconf->user && yy_aconf->host)
1568 <    {
1569 <      conf_add_class_to_conf(yy_conf, class_name);
1570 <      add_conf_by_address(CONF_CLIENT, yy_aconf);
1571 <    }
1572 <    else
1573 <      delete_conf_item(yy_conf);
1574 <
1575 <    /* copy over settings from first struct */
1576 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1577 <    {
1578 <      struct AccessItem *new_aconf;
1579 <      struct ConfItem *new_conf;
1580 <
1581 <      new_conf = make_conf_item(CLIENT_TYPE);
1582 <      new_aconf = map_to_conf(new_conf);
1583 <
1584 <      yy_tmp = ptr->data;
1585 <
1586 <      assert(yy_tmp->user && yy_tmp->host);
1644 >  dlink_node *ptr = NULL;
1645  
1646 <      if (yy_aconf->passwd != NULL)
1647 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1590 <      if (yy_conf->name != NULL)
1591 <        DupString(new_conf->name, yy_conf->name);
1592 <      if (yy_aconf->passwd != NULL)
1593 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1646 >  if (conf_parser_ctx.pass != 2)
1647 >    break;
1648  
1649 <      new_aconf->flags = yy_aconf->flags;
1650 <      new_aconf->port  = yy_aconf->port;
1649 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1650 >  {
1651 >    struct MaskItem *conf = NULL;
1652 >    struct split_nuh_item nuh;
1653  
1654 <      DupString(new_aconf->user, yy_tmp->user);
1655 <      collapse(new_aconf->user);
1654 >    nuh.nuhmask  = ptr->data;
1655 >    nuh.nickptr  = NULL;
1656 >    nuh.userptr  = block_state.user.buf;
1657 >    nuh.hostptr  = block_state.host.buf;
1658 >    nuh.nicksize = 0;
1659 >    nuh.usersize = sizeof(block_state.user.buf);
1660 >    nuh.hostsize = sizeof(block_state.host.buf);
1661 >    split_nuh(&nuh);
1662  
1663 <      DupString(new_aconf->host, yy_tmp->host);
1664 <      collapse(new_aconf->host);
1663 >    conf        = conf_make(CONF_CLIENT);
1664 >    conf->user  = xstrdup(block_state.user.buf);
1665 >    conf->host  = xstrdup(block_state.host.buf);
1666 >
1667 >    if (block_state.rpass.buf[0])
1668 >      conf->passwd = xstrdup(block_state.rpass.buf);
1669 >    if (block_state.name.buf[0])
1670 >      conf->name = xstrdup(block_state.name.buf);
1671  
1672 <      conf_add_class_to_conf(new_conf, class_name);
1673 <      add_conf_by_address(CONF_CLIENT, new_aconf);
1606 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1607 <      free_collect_item(yy_tmp);
1608 <    }
1672 >    conf->flags = block_state.flags.value;
1673 >    conf->port  = block_state.port.value;
1674  
1675 <    MyFree(class_name);
1676 <    class_name = NULL;
1612 <    yy_conf = NULL;
1613 <    yy_aconf = NULL;
1675 >    conf_add_class_to_conf(conf, block_state.class.buf);
1676 >    add_conf_by_address(CONF_CLIENT, conf);
1677    }
1678   };
1679  
# Line 1622 | Line 1685 | auth_item:      auth_user | auth_passwd
1685   auth_user: USER '=' QSTRING ';'
1686   {
1687    if (conf_parser_ctx.pass == 2)
1688 <  {
1626 <    struct CollectItem *yy_tmp = NULL;
1627 <    struct split_nuh_item nuh;
1628 <
1629 <    nuh.nuhmask  = yylval.string;
1630 <    nuh.nickptr  = NULL;
1631 <    nuh.userptr  = userbuf;
1632 <    nuh.hostptr  = hostbuf;
1633 <
1634 <    nuh.nicksize = 0;
1635 <    nuh.usersize = sizeof(userbuf);
1636 <    nuh.hostsize = sizeof(hostbuf);
1637 <
1638 <    split_nuh(&nuh);
1639 <
1640 <    if (yy_aconf->user == NULL)
1641 <    {
1642 <      DupString(yy_aconf->user, userbuf);
1643 <      DupString(yy_aconf->host, hostbuf);
1644 <    }
1645 <    else
1646 <    {
1647 <      yy_tmp = MyMalloc(sizeof(struct CollectItem));
1648 <
1649 <      DupString(yy_tmp->user, userbuf);
1650 <      DupString(yy_tmp->host, hostbuf);
1651 <
1652 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1653 <    }
1654 <  }
1688 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1689   };
1690  
1657 /* XXX - IP/IPV6 tags don't exist anymore - put IP/IPV6 into user. */
1658
1691   auth_passwd: PASSWORD '=' QSTRING ';'
1692   {
1693    if (conf_parser_ctx.pass == 2)
1694 <  {
1663 <    /* be paranoid */
1664 <    if (yy_aconf->passwd != NULL)
1665 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1666 <
1667 <    MyFree(yy_aconf->passwd);
1668 <    DupString(yy_aconf->passwd, yylval.string);
1669 <  }
1694 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1695   };
1696  
1697   auth_class: CLASS '=' QSTRING ';'
1698   {
1699    if (conf_parser_ctx.pass == 2)
1700 <  {
1676 <    MyFree(class_name);
1677 <    DupString(class_name, yylval.string);
1678 <  }
1700 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1701   };
1702  
1703   auth_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 1683 | Line 1705 | auth_encrypted: ENCRYPTED '=' TBOOL ';'
1705    if (conf_parser_ctx.pass == 2)
1706    {
1707      if (yylval.number)
1708 <      SetConfEncrypted(yy_aconf);
1708 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1709      else
1710 <      ClearConfEncrypted(yy_aconf);
1710 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1711    }
1712   };
1713  
1714   auth_flags: IRCD_FLAGS
1715   {
1716 +  if (conf_parser_ctx.pass == 2)
1717 +    block_state.flags.value &= (CONF_FLAGS_ENCRYPTED | CONF_FLAGS_SPOOF_IP);
1718   } '='  auth_flags_items ';';
1719  
1720   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
1721   auth_flags_item: SPOOF_NOTICE
1722   {
1723    if (conf_parser_ctx.pass == 2)
1724 <    yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1724 >    block_state.flags.value |= CONF_FLAGS_SPOOF_NOTICE;
1725   } | EXCEED_LIMIT
1726   {
1727    if (conf_parser_ctx.pass == 2)
1728 <    yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
1728 >    block_state.flags.value |= CONF_FLAGS_NOLIMIT;
1729   } | KLINE_EXEMPT
1730   {
1731    if (conf_parser_ctx.pass == 2)
1732 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
1732 >    block_state.flags.value |= CONF_FLAGS_EXEMPTKLINE;
1733   } | NEED_IDENT
1734   {
1735    if (conf_parser_ctx.pass == 2)
1736 <    yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
1736 >    block_state.flags.value |= CONF_FLAGS_NEED_IDENTD;
1737   } | CAN_FLOOD
1738   {
1739    if (conf_parser_ctx.pass == 2)
1740 <    yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
1740 >    block_state.flags.value |= CONF_FLAGS_CAN_FLOOD;
1741   } | NO_TILDE
1742   {
1743    if (conf_parser_ctx.pass == 2)
1744 <    yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
1744 >    block_state.flags.value |= CONF_FLAGS_NO_TILDE;
1745   } | GLINE_EXEMPT
1746   {
1747    if (conf_parser_ctx.pass == 2)
1748 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
1748 >    block_state.flags.value |= CONF_FLAGS_EXEMPTGLINE;
1749   } | RESV_EXEMPT
1750   {
1751    if (conf_parser_ctx.pass == 2)
1752 <    yy_aconf->flags |= CONF_FLAGS_EXEMPTRESV;
1752 >    block_state.flags.value |= CONF_FLAGS_EXEMPTRESV;
1753 > } | T_WEBIRC
1754 > {
1755 >  if (conf_parser_ctx.pass == 2)
1756 >    block_state.flags.value |= CONF_FLAGS_WEBIRC;
1757   } | NEED_PASSWORD
1758   {
1759    if (conf_parser_ctx.pass == 2)
1760 <    yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
1760 >    block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1761   };
1762  
1735 /* XXX - need check for illegal hostnames here */
1763   auth_spoof: SPOOF '=' QSTRING ';'
1764   {
1765 <  if (conf_parser_ctx.pass == 2)
1766 <  {
1740 <    MyFree(yy_conf->name);
1765 >  if (conf_parser_ctx.pass != 2)
1766 >    break;
1767  
1768 <    if (strlen(yylval.string) < HOSTLEN)
1769 <    {    
1770 <      DupString(yy_conf->name, yylval.string);
1771 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_IP;
1746 <    }
1747 <    else
1748 <    {
1749 <      ilog(LOG_TYPE_IRCD, "Spoofs must be less than %d..ignoring it", HOSTLEN);
1750 <      yy_conf->name = NULL;
1751 <    }
1768 >  if (strlen(yylval.string) <= HOSTLEN && valid_hostname(yylval.string))
1769 >  {
1770 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1771 >    block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
1772    }
1773 +  else
1774 +    ilog(LOG_TYPE_IRCD, "Spoof either is too long or contains invalid characters. Ignoring it.");
1775   };
1776  
1777   auth_redir_serv: REDIRSERV '=' QSTRING ';'
1778   {
1779 <  if (conf_parser_ctx.pass == 2)
1780 <  {
1781 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1782 <    MyFree(yy_conf->name);
1783 <    DupString(yy_conf->name, yylval.string);
1762 <  }
1779 >  if (conf_parser_ctx.pass != 2)
1780 >    break;
1781 >
1782 >  strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1783 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1784   };
1785  
1786   auth_redir_port: REDIRPORT '=' NUMBER ';'
1787   {
1788 <  if (conf_parser_ctx.pass == 2)
1789 <  {
1790 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1791 <    yy_aconf->port = $3;
1792 <  }
1788 >  if (conf_parser_ctx.pass != 2)
1789 >    break;
1790 >
1791 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1792 >  block_state.port.value = $3;
1793   };
1794  
1795  
# Line 1777 | Line 1798 | auth_redir_port: REDIRPORT '=' NUMBER ';
1798   ***************************************************************************/
1799   resv_entry: RESV
1800   {
1801 <  if (conf_parser_ctx.pass == 2)
1802 <  {
1803 <    MyFree(resv_reason);
1804 <    resv_reason = NULL;
1805 <  }
1801 >  if (conf_parser_ctx.pass != 2)
1802 >    break;
1803 >
1804 >  reset_block_state();
1805 >  strlcpy(block_state.rpass.buf, CONF_NOREASON, sizeof(block_state.rpass.buf));
1806   } '{' resv_items '}' ';'
1807   {
1808 <  if (conf_parser_ctx.pass == 2)
1809 <  {
1810 <    MyFree(resv_reason);
1811 <    resv_reason = NULL;
1791 <  }
1808 >  if (conf_parser_ctx.pass != 2)
1809 >    break;
1810 >
1811 >  create_resv(block_state.name.buf, block_state.rpass.buf, &block_state.mask.list);
1812   };
1813  
1814   resv_items:     resv_items resv_item | resv_item;
1815 < resv_item:      resv_creason | resv_channel | resv_nick | error ';' ;
1815 > resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1816  
1817 < resv_creason: REASON '=' QSTRING ';'
1817 > resv_mask: MASK '=' QSTRING ';'
1818   {
1819    if (conf_parser_ctx.pass == 2)
1820 <  {
1801 <    MyFree(resv_reason);
1802 <    DupString(resv_reason, yylval.string);
1803 <  }
1820 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1821   };
1822  
1823 < resv_channel: CHANNEL '=' QSTRING ';'
1823 > resv_reason: REASON '=' QSTRING ';'
1824   {
1825    if (conf_parser_ctx.pass == 2)
1826 <  {
1810 <    if (IsChanPrefix(*yylval.string))
1811 <    {
1812 <      char def_reason[] = "No reason";
1813 <
1814 <      create_channel_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1815 <    }
1816 <  }
1817 <  /* ignore it for now.. but we really should make a warning if
1818 <   * its an erroneous name --fl_ */
1826 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1827   };
1828  
1829 < resv_nick: NICK '=' QSTRING ';'
1829 > resv_exempt: EXEMPT '=' QSTRING ';'
1830   {
1831    if (conf_parser_ctx.pass == 2)
1832 <  {
1825 <    char def_reason[] = "No reason";
1826 <
1827 <    create_nick_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1828 <  }
1832 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1833   };
1834  
1835 +
1836   /***************************************************************************
1837   *  section service
1838   ***************************************************************************/
# Line 1838 | Line 1843 | service_item:      service_name | error;
1843  
1844   service_name: NAME '=' QSTRING ';'
1845   {
1846 <  if (conf_parser_ctx.pass == 2)
1846 >  if (conf_parser_ctx.pass != 2)
1847 >    break;
1848 >
1849 >  if (valid_servname(yylval.string))
1850    {
1851 <    if (valid_servname(yylval.string))
1852 <    {
1845 <      yy_conf = make_conf_item(SERVICE_TYPE);
1846 <      DupString(yy_conf->name, yylval.string);
1847 <    }
1851 >    struct MaskItem *conf = conf_make(CONF_SERVICE);
1852 >    conf->name = xstrdup(yylval.string);
1853    }
1854   };
1855  
# Line 1853 | Line 1858 | service_name: NAME '=' QSTRING ';'
1858   ***************************************************************************/
1859   shared_entry: T_SHARED
1860   {
1861 <  if (conf_parser_ctx.pass == 2)
1862 <  {
1863 <    yy_conf = make_conf_item(ULINE_TYPE);
1864 <    yy_match_item = map_to_conf(yy_conf);
1865 <    yy_match_item->action = SHARED_ALL;
1866 <  }
1861 >  if (conf_parser_ctx.pass != 2)
1862 >    break;
1863 >
1864 >  reset_block_state();
1865 >
1866 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1867 >  strlcpy(block_state.user.buf, "*", sizeof(block_state.user.buf));
1868 >  strlcpy(block_state.host.buf, "*", sizeof(block_state.host.buf));
1869 >  block_state.flags.value = SHARED_ALL;
1870   } '{' shared_items '}' ';'
1871   {
1872 <  if (conf_parser_ctx.pass == 2)
1873 <  {
1874 <    yy_conf = NULL;
1875 <  }
1872 >  struct MaskItem *conf = NULL;
1873 >
1874 >  if (conf_parser_ctx.pass != 2)
1875 >    break;
1876 >
1877 >  conf = conf_make(CONF_ULINE);
1878 >  conf->flags = block_state.flags.value;
1879 >  conf->name = xstrdup(block_state.name.buf);
1880 >  conf->user = xstrdup(block_state.user.buf);
1881 >  conf->host = xstrdup(block_state.host.buf);
1882   };
1883  
1884   shared_items: shared_items shared_item | shared_item;
# Line 1873 | Line 1887 | shared_item:  shared_name | shared_user
1887   shared_name: NAME '=' QSTRING ';'
1888   {
1889    if (conf_parser_ctx.pass == 2)
1890 <  {
1877 <    MyFree(yy_conf->name);
1878 <    DupString(yy_conf->name, yylval.string);
1879 <  }
1890 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1891   };
1892  
1893   shared_user: USER '=' QSTRING ';'
# Line 1887 | Line 1898 | shared_user: USER '=' QSTRING ';'
1898  
1899      nuh.nuhmask  = yylval.string;
1900      nuh.nickptr  = NULL;
1901 <    nuh.userptr  = userbuf;
1902 <    nuh.hostptr  = hostbuf;
1901 >    nuh.userptr  = block_state.user.buf;
1902 >    nuh.hostptr  = block_state.host.buf;
1903  
1904      nuh.nicksize = 0;
1905 <    nuh.usersize = sizeof(userbuf);
1906 <    nuh.hostsize = sizeof(hostbuf);
1905 >    nuh.usersize = sizeof(block_state.user.buf);
1906 >    nuh.hostsize = sizeof(block_state.host.buf);
1907  
1908      split_nuh(&nuh);
1898
1899    DupString(yy_match_item->user, userbuf);
1900    DupString(yy_match_item->host, hostbuf);
1909    }
1910   };
1911  
1912   shared_type: TYPE
1913   {
1914    if (conf_parser_ctx.pass == 2)
1915 <    yy_match_item->action = 0;
1915 >    block_state.flags.value = 0;
1916   } '=' shared_types ';' ;
1917  
1918   shared_types: shared_types ',' shared_type_item | shared_type_item;
1919   shared_type_item: KLINE
1920   {
1921    if (conf_parser_ctx.pass == 2)
1922 <    yy_match_item->action |= SHARED_KLINE;
1923 < } | TKLINE
1922 >    block_state.flags.value |= SHARED_KLINE;
1923 > } | UNKLINE
1924   {
1925    if (conf_parser_ctx.pass == 2)
1926 <    yy_match_item->action |= SHARED_TKLINE;
1927 < } | UNKLINE
1926 >    block_state.flags.value |= SHARED_UNKLINE;
1927 > } | T_DLINE
1928   {
1929    if (conf_parser_ctx.pass == 2)
1930 <    yy_match_item->action |= SHARED_UNKLINE;
1931 < } | XLINE
1930 >    block_state.flags.value |= SHARED_DLINE;
1931 > } | T_UNDLINE
1932   {
1933    if (conf_parser_ctx.pass == 2)
1934 <    yy_match_item->action |= SHARED_XLINE;
1935 < } | TXLINE
1934 >    block_state.flags.value |= SHARED_UNDLINE;
1935 > } | XLINE
1936   {
1937    if (conf_parser_ctx.pass == 2)
1938 <    yy_match_item->action |= SHARED_TXLINE;
1938 >    block_state.flags.value |= SHARED_XLINE;
1939   } | T_UNXLINE
1940   {
1941    if (conf_parser_ctx.pass == 2)
1942 <    yy_match_item->action |= SHARED_UNXLINE;
1942 >    block_state.flags.value |= SHARED_UNXLINE;
1943   } | RESV
1944   {
1945    if (conf_parser_ctx.pass == 2)
1946 <    yy_match_item->action |= SHARED_RESV;
1939 < } | TRESV
1940 < {
1941 <  if (conf_parser_ctx.pass == 2)
1942 <    yy_match_item->action |= SHARED_TRESV;
1946 >    block_state.flags.value |= SHARED_RESV;
1947   } | T_UNRESV
1948   {
1949    if (conf_parser_ctx.pass == 2)
1950 <    yy_match_item->action |= SHARED_UNRESV;
1950 >    block_state.flags.value |= SHARED_UNRESV;
1951   } | T_LOCOPS
1952   {
1953    if (conf_parser_ctx.pass == 2)
1954 <    yy_match_item->action |= SHARED_LOCOPS;
1954 >    block_state.flags.value |= SHARED_LOCOPS;
1955   } | T_ALL
1956   {
1957    if (conf_parser_ctx.pass == 2)
1958 <    yy_match_item->action = SHARED_ALL;
1958 >    block_state.flags.value = SHARED_ALL;
1959   };
1960  
1961   /***************************************************************************
# Line 1959 | Line 1963 | shared_type_item: KLINE
1963   ***************************************************************************/
1964   cluster_entry: T_CLUSTER
1965   {
1966 <  if (conf_parser_ctx.pass == 2)
1967 <  {
1968 <    yy_conf = make_conf_item(CLUSTER_TYPE);
1969 <    yy_conf->flags = SHARED_ALL;
1970 <  }
1966 >  if (conf_parser_ctx.pass != 2)
1967 >    break;
1968 >
1969 >  reset_block_state();
1970 >
1971 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1972 >  block_state.flags.value = SHARED_ALL;
1973   } '{' cluster_items '}' ';'
1974   {
1975 <  if (conf_parser_ctx.pass == 2)
1976 <  {
1977 <    if (yy_conf->name == NULL)
1978 <      DupString(yy_conf->name, "*");
1979 <    yy_conf = NULL;
1980 <  }
1975 >  struct MaskItem *conf = NULL;
1976 >
1977 >  if (conf_parser_ctx.pass != 2)
1978 >    break;
1979 >
1980 >  conf = conf_make(CONF_CLUSTER);
1981 >  conf->flags = block_state.flags.value;
1982 >  conf->name = xstrdup(block_state.name.buf);
1983   };
1984  
1985   cluster_items:  cluster_items cluster_item | cluster_item;
# Line 1980 | Line 1988 | cluster_item:  cluster_name | cluster_typ
1988   cluster_name: NAME '=' QSTRING ';'
1989   {
1990    if (conf_parser_ctx.pass == 2)
1991 <    DupString(yy_conf->name, yylval.string);
1991 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1992   };
1993  
1994   cluster_type: TYPE
1995   {
1996    if (conf_parser_ctx.pass == 2)
1997 <    yy_conf->flags = 0;
1997 >    block_state.flags.value = 0;
1998   } '=' cluster_types ';' ;
1999  
2000   cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2001   cluster_type_item: KLINE
2002   {
2003    if (conf_parser_ctx.pass == 2)
2004 <    yy_conf->flags |= SHARED_KLINE;
2005 < } | TKLINE
2004 >    block_state.flags.value |= SHARED_KLINE;
2005 > } | UNKLINE
2006   {
2007    if (conf_parser_ctx.pass == 2)
2008 <    yy_conf->flags |= SHARED_TKLINE;
2009 < } | UNKLINE
2008 >    block_state.flags.value |= SHARED_UNKLINE;
2009 > } | T_DLINE
2010   {
2011    if (conf_parser_ctx.pass == 2)
2012 <    yy_conf->flags |= SHARED_UNKLINE;
2013 < } | XLINE
2012 >    block_state.flags.value |= SHARED_DLINE;
2013 > } | T_UNDLINE
2014   {
2015    if (conf_parser_ctx.pass == 2)
2016 <    yy_conf->flags |= SHARED_XLINE;
2017 < } | TXLINE
2016 >    block_state.flags.value |= SHARED_UNDLINE;
2017 > } | XLINE
2018   {
2019    if (conf_parser_ctx.pass == 2)
2020 <    yy_conf->flags |= SHARED_TXLINE;
2020 >    block_state.flags.value |= SHARED_XLINE;
2021   } | T_UNXLINE
2022   {
2023    if (conf_parser_ctx.pass == 2)
2024 <    yy_conf->flags |= SHARED_UNXLINE;
2024 >    block_state.flags.value |= SHARED_UNXLINE;
2025   } | RESV
2026   {
2027    if (conf_parser_ctx.pass == 2)
2028 <    yy_conf->flags |= SHARED_RESV;
2021 < } | TRESV
2022 < {
2023 <  if (conf_parser_ctx.pass == 2)
2024 <    yy_conf->flags |= SHARED_TRESV;
2028 >    block_state.flags.value |= SHARED_RESV;
2029   } | T_UNRESV
2030   {
2031    if (conf_parser_ctx.pass == 2)
2032 <    yy_conf->flags |= SHARED_UNRESV;
2032 >    block_state.flags.value |= SHARED_UNRESV;
2033   } | T_LOCOPS
2034   {
2035    if (conf_parser_ctx.pass == 2)
2036 <    yy_conf->flags |= SHARED_LOCOPS;
2036 >    block_state.flags.value |= SHARED_LOCOPS;
2037   } | T_ALL
2038   {
2039    if (conf_parser_ctx.pass == 2)
2040 <    yy_conf->flags = SHARED_ALL;
2040 >    block_state.flags.value = SHARED_ALL;
2041   };
2042  
2043   /***************************************************************************
# Line 2041 | Line 2045 | cluster_type_item: KLINE
2045   ***************************************************************************/
2046   connect_entry: CONNECT  
2047   {
2044  if (conf_parser_ctx.pass == 2)
2045  {
2046    yy_conf = make_conf_item(SERVER_TYPE);
2047    yy_aconf = map_to_conf(yy_conf);
2048  
2049 <    /* defaults */
2050 <    yy_aconf->port = PORTNUM;
2051 <  }
2052 <  else
2053 <  {
2054 <    MyFree(class_name);
2055 <    class_name = NULL;
2056 <  }
2057 < } connect_name_b '{' connect_items '}' ';'
2058 < {
2059 <  if (conf_parser_ctx.pass == 2)
2060 <  {
2061 <    struct CollectItem *yy_hconf=NULL;
2062 <    struct CollectItem *yy_lconf=NULL;
2063 <    dlink_node *ptr;
2064 <    dlink_node *next_ptr;
2065 < #ifdef HAVE_LIBCRYPTO
2066 <    if (yy_aconf->host &&
2067 <        ((yy_aconf->passwd && yy_aconf->spasswd) ||
2068 <         (yy_aconf->rsa_public_key && IsConfCryptLink(yy_aconf))))
2069 < #else /* !HAVE_LIBCRYPTO */
2070 <      if (yy_aconf->host && !IsConfCryptLink(yy_aconf) &&
2071 <          yy_aconf->passwd && yy_aconf->spasswd)
2072 < #endif /* !HAVE_LIBCRYPTO */
2073 <        {
2074 <          if (conf_add_server(yy_conf, class_name) == -1)
2075 <          {
2076 <            delete_conf_item(yy_conf);
2077 <            yy_conf = NULL;
2078 <            yy_aconf = NULL;
2079 <          }
2080 <        }
2081 <        else
2082 <        {
2083 <          /* Even if yy_conf ->name is NULL
2084 <           * should still unhook any hub/leaf confs still pending
2085 <           */
2086 <          unhook_hub_leaf_confs();
2087 <
2088 <          if (yy_conf->name != NULL)
2089 <          {
2090 < #ifndef HAVE_LIBCRYPTO
2091 <            if (IsConfCryptLink(yy_aconf))
2092 <              yyerror("Ignoring connect block -- no OpenSSL support");
2093 < #else
2094 <            if (IsConfCryptLink(yy_aconf) && !yy_aconf->rsa_public_key)
2095 <              yyerror("Ignoring connect block -- missing key");
2096 < #endif
2097 <            if (yy_aconf->host == NULL)
2098 <              yyerror("Ignoring connect block -- missing host");
2099 <            else if (!IsConfCryptLink(yy_aconf) &&
2100 <                    (!yy_aconf->passwd || !yy_aconf->spasswd))
2101 <              yyerror("Ignoring connect block -- missing password");
2102 <          }
2103 <
2104 <
2105 <          /* XXX
2106 <           * This fixes a try_connections() core (caused by invalid class_ptr
2107 <           * pointers) reported by metalrock. That's an ugly fix, but there
2108 <           * is currently no better way. The entire config subsystem needs an
2109 <           * rewrite ASAP. make_conf_item() shouldn't really add things onto
2110 <           * a doubly linked list immediately without any sanity checks!  -Michael
2111 <           */
2112 <          delete_conf_item(yy_conf);
2113 <
2114 <          yy_aconf = NULL;
2115 <          yy_conf = NULL;
2116 <        }
2117 <
2118 <      /*
2119 <       * yy_conf is still pointing at the server that is having
2120 <       * a connect block built for it. This means, y_aconf->name
2121 <       * points to the actual irc name this server will be known as.
2122 <       * Now this new server has a set or even just one hub_mask (or leaf_mask)
2123 <       * given in the link list at yy_hconf. Fill in the HUB confs
2124 <       * from this link list now.
2125 <       */        
2126 <      DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
2127 <      {
2128 <        struct ConfItem *new_hub_conf;
2129 <        struct MatchItem *match_item;
2049 >  if (conf_parser_ctx.pass != 2)
2050 >    break;
2051  
2052 <        yy_hconf = ptr->data;
2052 >  reset_block_state();
2053 >  block_state.port.value = PORTNUM;
2054 > } '{' connect_items '}' ';'
2055 > {
2056 >  struct MaskItem *conf = NULL;
2057 >  struct addrinfo hints, *res;
2058 >
2059 >  if (conf_parser_ctx.pass != 2)
2060 >    break;
2061 >
2062 >  if (!block_state.name.buf[0] ||
2063 >      !block_state.host.buf[0])
2064 >    break;
2065 >
2066 >  if (!block_state.rpass.buf[0] ||
2067 >      !block_state.spass.buf[0])
2068 >    break;
2069 >
2070 >  if (has_wildcards(block_state.name.buf) ||
2071 >      has_wildcards(block_state.host.buf))
2072 >    break;
2073 >
2074 >  conf = conf_make(CONF_SERVER);
2075 >  conf->port = block_state.port.value;
2076 >  conf->flags = block_state.flags.value;
2077 >  conf->aftype = block_state.aftype.value;
2078 >  conf->host = xstrdup(block_state.host.buf);
2079 >  conf->name = xstrdup(block_state.name.buf);
2080 >  conf->passwd = xstrdup(block_state.rpass.buf);
2081 >  conf->spasswd = xstrdup(block_state.spass.buf);
2082 >
2083 >  if (block_state.cert.buf[0])
2084 >    conf->certfp = xstrdup(block_state.cert.buf);
2085  
2086 <        /* yy_conf == NULL is a fatal error for this connect block! */
2087 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2135 <        {
2136 <          new_hub_conf = make_conf_item(HUB_TYPE);
2137 <          match_item = (struct MatchItem *)map_to_conf(new_hub_conf);
2138 <          DupString(new_hub_conf->name, yy_conf->name);
2139 <          if (yy_hconf->user != NULL)
2140 <            DupString(match_item->user, yy_hconf->user);
2141 <          else
2142 <            DupString(match_item->user, "*");
2143 <          if (yy_hconf->host != NULL)
2144 <            DupString(match_item->host, yy_hconf->host);
2145 <          else
2146 <            DupString(match_item->host, "*");
2147 <        }
2148 <        dlinkDelete(&yy_hconf->node, &hub_conf_list);
2149 <        free_collect_item(yy_hconf);
2150 <      }
2086 >  if (block_state.ciph.buf[0])
2087 >    conf->cipher_list = xstrdup(block_state.ciph.buf);
2088  
2089 <      /* Ditto for the LEAF confs */
2089 >  dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
2090 >  dlinkMoveList(&block_state.hub.list, &conf->hub_list);
2091  
2092 <      DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
2093 <      {
2094 <        struct ConfItem *new_leaf_conf;
2157 <        struct MatchItem *match_item;
2092 >  if (block_state.bind.buf[0])
2093 >  {
2094 >    memset(&hints, 0, sizeof(hints));
2095  
2096 <        yy_lconf = ptr->data;
2096 >    hints.ai_family   = AF_UNSPEC;
2097 >    hints.ai_socktype = SOCK_STREAM;
2098 >    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2099  
2100 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2101 <        {
2102 <          new_leaf_conf = make_conf_item(LEAF_TYPE);
2103 <          match_item = (struct MatchItem *)map_to_conf(new_leaf_conf);
2104 <          DupString(new_leaf_conf->name, yy_conf->name);
2105 <          if (yy_lconf->user != NULL)
2106 <            DupString(match_item->user, yy_lconf->user);
2107 <          else
2108 <            DupString(match_item->user, "*");
2109 <          if (yy_lconf->host != NULL)
2110 <            DupString(match_item->host, yy_lconf->host);
2172 <          else
2173 <            DupString(match_item->host, "*");
2174 <        }
2175 <        dlinkDelete(&yy_lconf->node, &leaf_conf_list);
2176 <        free_collect_item(yy_lconf);
2177 <      }
2178 <      MyFree(class_name);
2179 <      class_name = NULL;
2180 <      yy_conf = NULL;
2181 <      yy_aconf = NULL;
2100 >    if (getaddrinfo(block_state.bind.buf, NULL, &hints, &res))
2101 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
2102 >    else
2103 >    {
2104 >      assert(res != NULL);
2105 >
2106 >      memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
2107 >      conf->bind.ss.ss_family = res->ai_family;
2108 >      conf->bind.ss_len = res->ai_addrlen;
2109 >      freeaddrinfo(res);
2110 >    }
2111    }
2112 +
2113 +  conf_add_class_to_conf(conf, block_state.class.buf);
2114 +  lookup_confhost(conf);
2115   };
2116  
2185 connect_name_b: | connect_name_t;
2117   connect_items:  connect_items connect_item | connect_item;
2118   connect_item:   connect_name | connect_host | connect_vhost |
2119                  connect_send_password | connect_accept_password |
2120 <                connect_aftype | connect_port |
2120 >                connect_ssl_certificate_fingerprint |
2121 >                connect_aftype | connect_port | connect_ssl_cipher_list |
2122                  connect_flags | connect_hub_mask | connect_leaf_mask |
2123 <                connect_class | connect_encrypted |
2192 <                connect_rsa_public_key_file | connect_cipher_preference |
2123 >                connect_class | connect_encrypted |
2124                  error ';' ;
2125  
2126   connect_name: NAME '=' QSTRING ';'
2127   {
2128    if (conf_parser_ctx.pass == 2)
2129 <  {
2199 <    if (yy_conf->name != NULL)
2200 <      yyerror("Multiple connect name entry");
2201 <
2202 <    MyFree(yy_conf->name);
2203 <    DupString(yy_conf->name, yylval.string);
2204 <  }
2205 < };
2206 <
2207 < connect_name_t: QSTRING
2208 < {
2209 <  if (conf_parser_ctx.pass == 2)
2210 <  {
2211 <    if (yy_conf->name != NULL)
2212 <      yyerror("Multiple connect name entry");
2213 <
2214 <    MyFree(yy_conf->name);
2215 <    DupString(yy_conf->name, yylval.string);
2216 <  }
2129 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2130   };
2131  
2132   connect_host: HOST '=' QSTRING ';'
2133   {
2134    if (conf_parser_ctx.pass == 2)
2135 <  {
2223 <    MyFree(yy_aconf->host);
2224 <    DupString(yy_aconf->host, yylval.string);
2225 <  }
2135 >    strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
2136   };
2137  
2138   connect_vhost: VHOST '=' QSTRING ';'
2139   {
2140    if (conf_parser_ctx.pass == 2)
2141 <  {
2232 <    struct addrinfo hints, *res;
2233 <
2234 <    memset(&hints, 0, sizeof(hints));
2235 <
2236 <    hints.ai_family   = AF_UNSPEC;
2237 <    hints.ai_socktype = SOCK_STREAM;
2238 <    hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2239 <
2240 <    if (getaddrinfo(yylval.string, NULL, &hints, &res))
2241 <      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
2242 <    else
2243 <    {
2244 <      assert(res != NULL);
2245 <
2246 <      memcpy(&yy_aconf->my_ipnum, res->ai_addr, res->ai_addrlen);
2247 <      yy_aconf->my_ipnum.ss.ss_family = res->ai_family;
2248 <      yy_aconf->my_ipnum.ss_len = res->ai_addrlen;
2249 <      freeaddrinfo(res);
2250 <    }
2251 <  }
2141 >    strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
2142   };
2143  
2144   connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2145   {
2146 <  if (conf_parser_ctx.pass == 2)
2147 <  {
2258 <    if ($3[0] == ':')
2259 <      yyerror("Server passwords cannot begin with a colon");
2260 <    else if (strchr($3, ' ') != NULL)
2261 <      yyerror("Server passwords cannot contain spaces");
2262 <    else {
2263 <      if (yy_aconf->spasswd != NULL)
2264 <        memset(yy_aconf->spasswd, 0, strlen(yy_aconf->spasswd));
2146 >  if (conf_parser_ctx.pass != 2)
2147 >    break;
2148  
2149 <      MyFree(yy_aconf->spasswd);
2150 <      DupString(yy_aconf->spasswd, yylval.string);
2151 <    }
2152 <  }
2149 >  if ($3[0] == ':')
2150 >    conf_error_report("Server passwords cannot begin with a colon");
2151 >  else if (strchr($3, ' ') != NULL)
2152 >    conf_error_report("Server passwords cannot contain spaces");
2153 >  else
2154 >    strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
2155   };
2156  
2157   connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2158   {
2159 <  if (conf_parser_ctx.pass == 2)
2160 <  {
2276 <    if ($3[0] == ':')
2277 <      yyerror("Server passwords cannot begin with a colon");
2278 <    else if (strchr($3, ' ') != NULL)
2279 <      yyerror("Server passwords cannot contain spaces");
2280 <    else {
2281 <      if (yy_aconf->passwd != NULL)
2282 <        memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
2159 >  if (conf_parser_ctx.pass != 2)
2160 >    break;
2161  
2162 <      MyFree(yy_aconf->passwd);
2163 <      DupString(yy_aconf->passwd, yylval.string);
2164 <    }
2165 <  }
2162 >  if ($3[0] == ':')
2163 >    conf_error_report("Server passwords cannot begin with a colon");
2164 >  else if (strchr($3, ' ') != NULL)
2165 >    conf_error_report("Server passwords cannot contain spaces");
2166 >  else
2167 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2168 > };
2169 >
2170 > connect_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
2171 > {
2172 >  if (conf_parser_ctx.pass == 2)
2173 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
2174   };
2175  
2176   connect_port: PORT '=' NUMBER ';'
2177   {
2178    if (conf_parser_ctx.pass == 2)
2179 <    yy_aconf->port = $3;
2179 >    block_state.port.value = $3;
2180   };
2181  
2182   connect_aftype: AFTYPE '=' T_IPV4 ';'
2183   {
2184    if (conf_parser_ctx.pass == 2)
2185 <    yy_aconf->aftype = AF_INET;
2185 >    block_state.aftype.value = AF_INET;
2186   } | AFTYPE '=' T_IPV6 ';'
2187   {
2188   #ifdef IPV6
2189    if (conf_parser_ctx.pass == 2)
2190 <    yy_aconf->aftype = AF_INET6;
2190 >    block_state.aftype.value = AF_INET6;
2191   #endif
2192   };
2193  
2194   connect_flags: IRCD_FLAGS
2195   {
2196 +  block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
2197   } '='  connect_flags_items ';';
2198  
2199   connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
2200 < connect_flags_item: COMPRESSED
2314 < {
2315 <  if (conf_parser_ctx.pass == 2)
2316 < #ifndef HAVE_LIBZ
2317 <    yyerror("Ignoring flags = compressed; -- no zlib support");
2318 < #else
2319 < {
2320 <   SetConfCompressed(yy_aconf);
2321 < }
2322 < #endif
2323 < } | CRYPTLINK
2324 < {
2325 <  if (conf_parser_ctx.pass == 2)
2326 <    SetConfCryptLink(yy_aconf);
2327 < } | AUTOCONN
2328 < {
2329 <  if (conf_parser_ctx.pass == 2)
2330 <    SetConfAllowAutoConn(yy_aconf);
2331 < } | BURST_AWAY
2200 > connect_flags_item: AUTOCONN
2201   {
2202    if (conf_parser_ctx.pass == 2)
2203 <    SetConfAwayBurst(yy_aconf);
2204 < } | TOPICBURST
2203 >    block_state.flags.value |= CONF_FLAGS_ALLOW_AUTO_CONN;
2204 > } | T_SSL
2205   {
2206    if (conf_parser_ctx.pass == 2)
2207 <    SetConfTopicBurst(yy_aconf);
2339 < };
2340 <
2341 < connect_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
2342 < {
2343 < #ifdef HAVE_LIBCRYPTO
2344 <  if (conf_parser_ctx.pass == 2)
2345 <  {
2346 <    BIO *file;
2347 <
2348 <    if (yy_aconf->rsa_public_key != NULL)
2349 <    {
2350 <      RSA_free(yy_aconf->rsa_public_key);
2351 <      yy_aconf->rsa_public_key = NULL;
2352 <    }
2353 <
2354 <    if (yy_aconf->rsa_public_key_file != NULL)
2355 <    {
2356 <      MyFree(yy_aconf->rsa_public_key_file);
2357 <      yy_aconf->rsa_public_key_file = NULL;
2358 <    }
2359 <
2360 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
2361 <
2362 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
2363 <    {
2364 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
2365 <      break;
2366 <    }
2367 <
2368 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
2369 <
2370 <    if (yy_aconf->rsa_public_key == NULL)
2371 <    {
2372 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
2373 <      break;
2374 <    }
2375 <      
2376 <    BIO_set_close(file, BIO_CLOSE);
2377 <    BIO_free(file);
2378 <  }
2379 < #endif /* HAVE_LIBCRYPTO */
2207 >    block_state.flags.value |= CONF_FLAGS_SSL;
2208   };
2209  
2210   connect_encrypted: ENCRYPTED '=' TBOOL ';'
# Line 2384 | Line 2212 | connect_encrypted: ENCRYPTED '=' TBOOL '
2212    if (conf_parser_ctx.pass == 2)
2213    {
2214      if (yylval.number)
2215 <      yy_aconf->flags |= CONF_FLAGS_ENCRYPTED;
2215 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
2216      else
2217 <      yy_aconf->flags &= ~CONF_FLAGS_ENCRYPTED;
2217 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
2218    }
2219   };
2220  
2221   connect_hub_mask: HUB_MASK '=' QSTRING ';'
2222   {
2223    if (conf_parser_ctx.pass == 2)
2224 <  {
2397 <    struct CollectItem *yy_tmp;
2398 <
2399 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2400 <    DupString(yy_tmp->host, yylval.string);
2401 <    DupString(yy_tmp->user, "*");
2402 <    dlinkAdd(yy_tmp, &yy_tmp->node, &hub_conf_list);
2403 <  }
2224 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
2225   };
2226  
2227   connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2228   {
2229    if (conf_parser_ctx.pass == 2)
2230 <  {
2410 <    struct CollectItem *yy_tmp;
2411 <
2412 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2413 <    DupString(yy_tmp->host, yylval.string);
2414 <    DupString(yy_tmp->user, "*");
2415 <    dlinkAdd(yy_tmp, &yy_tmp->node, &leaf_conf_list);
2416 <  }
2230 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
2231   };
2232  
2233   connect_class: CLASS '=' QSTRING ';'
2234   {
2235    if (conf_parser_ctx.pass == 2)
2236 <  {
2423 <    MyFree(class_name);
2424 <    DupString(class_name, yylval.string);
2425 <  }
2236 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
2237   };
2238  
2239 < connect_cipher_preference: CIPHER_PREFERENCE '=' QSTRING ';'
2239 > connect_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
2240   {
2241   #ifdef HAVE_LIBCRYPTO
2242    if (conf_parser_ctx.pass == 2)
2243 <  {
2433 <    struct EncCapability *ecap;
2434 <    const char *cipher_name;
2435 <    int found = 0;
2436 <
2437 <    yy_aconf->cipher_preference = NULL;
2438 <    cipher_name = yylval.string;
2439 <
2440 <    for (ecap = CipherTable; ecap->name; ecap++)
2441 <    {
2442 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
2443 <          (ecap->cap & CAP_ENC_MASK))
2444 <      {
2445 <        yy_aconf->cipher_preference = ecap;
2446 <        found = 1;
2447 <        break;
2448 <      }
2449 <    }
2450 <
2451 <    if (!found)
2452 <      yyerror("Invalid cipher");
2453 <  }
2243 >    strlcpy(block_state.ciph.buf, yylval.string, sizeof(block_state.ciph.buf));
2244   #else
2245    if (conf_parser_ctx.pass == 2)
2246 <    yyerror("Ignoring cipher_preference -- no OpenSSL support");
2246 >    conf_error_report("Ignoring connect::ciphers -- no OpenSSL support");
2247   #endif
2248   };
2249  
2250 +
2251   /***************************************************************************
2252   *  section kill
2253   ***************************************************************************/
2254   kill_entry: KILL
2255   {
2256    if (conf_parser_ctx.pass == 2)
2257 <  {
2467 <    userbuf[0] = hostbuf[0] = reasonbuf[0] = '\0';
2468 <    regex_ban = 0;
2469 <  }
2257 >    reset_block_state();
2258   } '{' kill_items '}' ';'
2259   {
2260 <  if (conf_parser_ctx.pass == 2)
2473 <  {
2474 <    if (userbuf[0] && hostbuf[0])
2475 <    {
2476 <      if (regex_ban)
2477 <      {
2478 < #ifdef HAVE_LIBPCRE
2479 <        void *exp_user = NULL;
2480 <        void *exp_host = NULL;
2481 <        const char *errptr = NULL;
2482 <
2483 <        if (!(exp_user = ircd_pcre_compile(userbuf, &errptr)) ||
2484 <            !(exp_host = ircd_pcre_compile(hostbuf, &errptr)))
2485 <        {
2486 <          ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: %s",
2487 <               errptr);
2488 <          break;
2489 <        }
2490 <
2491 <        yy_aconf = map_to_conf(make_conf_item(RKLINE_TYPE));
2492 <        yy_aconf->regexuser = exp_user;
2493 <        yy_aconf->regexhost = exp_host;
2494 <
2495 <        DupString(yy_aconf->user, userbuf);
2496 <        DupString(yy_aconf->host, hostbuf);
2260 >  struct MaskItem *conf = NULL;
2261  
2262 <        if (reasonbuf[0])
2263 <          DupString(yy_aconf->reason, reasonbuf);
2500 <        else
2501 <          DupString(yy_aconf->reason, "No reason");
2502 < #else
2503 <        ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: no PCRE support");
2504 <        break;
2505 < #endif
2506 <      }
2507 <      else
2508 <      {
2509 <        yy_aconf = map_to_conf(make_conf_item(KLINE_TYPE));
2262 >  if (conf_parser_ctx.pass != 2)
2263 >    break;
2264  
2265 <        DupString(yy_aconf->user, userbuf);
2266 <        DupString(yy_aconf->host, hostbuf);
2265 >  if (!block_state.user.buf[0] ||
2266 >      !block_state.host.buf[0])
2267 >    break;
2268  
2269 <        if (reasonbuf[0])
2270 <          DupString(yy_aconf->reason, reasonbuf);
2271 <        else
2517 <          DupString(yy_aconf->reason, "No reason");
2518 <        add_conf_by_address(CONF_KILL, yy_aconf);
2519 <      }
2520 <    }
2269 >  conf = conf_make(CONF_KLINE);
2270 >  conf->user = xstrdup(block_state.user.buf);
2271 >  conf->host = xstrdup(block_state.host.buf);
2272  
2273 <    yy_aconf = NULL;
2274 <  }
2273 >  if (block_state.rpass.buf[0])
2274 >    conf->reason = xstrdup(block_state.rpass.buf);
2275 >  else
2276 >    conf->reason = xstrdup(CONF_NOREASON);
2277 >  add_conf_by_address(CONF_KLINE, conf);
2278   };
2279  
2526 kill_type: TYPE
2527 {
2528 } '='  kill_type_items ';';
2529
2530 kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2531 kill_type_item: REGEX_T
2532 {
2533  if (conf_parser_ctx.pass == 2)
2534    regex_ban = 1;
2535 };
2536
2280   kill_items:     kill_items kill_item | kill_item;
2281 < kill_item:      kill_user | kill_reason | kill_type | error;
2281 > kill_item:      kill_user | kill_reason | error;
2282  
2283   kill_user: USER '=' QSTRING ';'
2284   {
2285 +
2286    if (conf_parser_ctx.pass == 2)
2287    {
2288      struct split_nuh_item nuh;
2289  
2290      nuh.nuhmask  = yylval.string;
2291      nuh.nickptr  = NULL;
2292 <    nuh.userptr  = userbuf;
2293 <    nuh.hostptr  = hostbuf;
2292 >    nuh.userptr  = block_state.user.buf;
2293 >    nuh.hostptr  = block_state.host.buf;
2294  
2295      nuh.nicksize = 0;
2296 <    nuh.usersize = sizeof(userbuf);
2297 <    nuh.hostsize = sizeof(hostbuf);
2296 >    nuh.usersize = sizeof(block_state.user.buf);
2297 >    nuh.hostsize = sizeof(block_state.host.buf);
2298  
2299      split_nuh(&nuh);
2300    }
# Line 2559 | Line 2303 | kill_user: USER '=' QSTRING ';'
2303   kill_reason: REASON '=' QSTRING ';'
2304   {
2305    if (conf_parser_ctx.pass == 2)
2306 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2306 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2307   };
2308  
2309   /***************************************************************************
# Line 2568 | Line 2312 | kill_reason: REASON '=' QSTRING ';'
2312   deny_entry: DENY
2313   {
2314    if (conf_parser_ctx.pass == 2)
2315 <    hostbuf[0] = reasonbuf[0] = '\0';
2315 >    reset_block_state();
2316   } '{' deny_items '}' ';'
2317   {
2318 <  if (conf_parser_ctx.pass == 2)
2318 >  struct MaskItem *conf = NULL;
2319 >
2320 >  if (conf_parser_ctx.pass != 2)
2321 >    break;
2322 >
2323 >  if (!block_state.addr.buf[0])
2324 >    break;
2325 >
2326 >  if (parse_netmask(block_state.addr.buf, NULL, NULL) != HM_HOST)
2327    {
2328 <    if (hostbuf[0] && parse_netmask(hostbuf, NULL, NULL) != HM_HOST)
2329 <    {
2578 <      yy_aconf = map_to_conf(make_conf_item(DLINE_TYPE));
2579 <      DupString(yy_aconf->host, hostbuf);
2328 >    conf = conf_make(CONF_DLINE);
2329 >    conf->host = xstrdup(block_state.addr.buf);
2330  
2331 <      if (reasonbuf[0])
2332 <        DupString(yy_aconf->reason, reasonbuf);
2333 <      else
2334 <        DupString(yy_aconf->reason, "No reason");
2335 <      add_conf_by_address(CONF_DLINE, yy_aconf);
2586 <      yy_aconf = NULL;
2587 <    }
2331 >    if (block_state.rpass.buf[0])
2332 >      conf->reason = xstrdup(block_state.rpass.buf);
2333 >    else
2334 >      conf->reason = xstrdup(CONF_NOREASON);
2335 >    add_conf_by_address(CONF_DLINE, conf);
2336    }
2337   };
2338  
# Line 2594 | Line 2342 | deny_item:      deny_ip | deny_reason |
2342   deny_ip: IP '=' QSTRING ';'
2343   {
2344    if (conf_parser_ctx.pass == 2)
2345 <    strlcpy(hostbuf, yylval.string, sizeof(hostbuf));
2345 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2346   };
2347  
2348   deny_reason: REASON '=' QSTRING ';'
2349   {
2350    if (conf_parser_ctx.pass == 2)
2351 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2351 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2352   };
2353  
2354   /***************************************************************************
# Line 2617 | Line 2365 | exempt_ip: IP '=' QSTRING ';'
2365    {
2366      if (yylval.string[0] && parse_netmask(yylval.string, NULL, NULL) != HM_HOST)
2367      {
2368 <      yy_aconf = map_to_conf(make_conf_item(EXEMPTDLINE_TYPE));
2369 <      DupString(yy_aconf->host, yylval.string);
2368 >      struct MaskItem *conf = conf_make(CONF_EXEMPT);
2369 >      conf->host = xstrdup(yylval.string);
2370  
2371 <      add_conf_by_address(CONF_EXEMPTDLINE, yy_aconf);
2624 <      yy_aconf = NULL;
2371 >      add_conf_by_address(CONF_EXEMPT, conf);
2372      }
2373    }
2374   };
# Line 2632 | Line 2379 | exempt_ip: IP '=' QSTRING ';'
2379   gecos_entry: GECOS
2380   {
2381    if (conf_parser_ctx.pass == 2)
2382 <  {
2636 <    regex_ban = 0;
2637 <    reasonbuf[0] = gecos_name[0] = '\0';
2638 <  }
2382 >    reset_block_state();
2383   } '{' gecos_items '}' ';'
2384   {
2385 <  if (conf_parser_ctx.pass == 2)
2642 <  {
2643 <    if (gecos_name[0])
2644 <    {
2645 <      if (regex_ban)
2646 <      {
2647 < #ifdef HAVE_LIBPCRE
2648 <        void *exp_p = NULL;
2649 <        const char *errptr = NULL;
2650 <
2651 <        if (!(exp_p = ircd_pcre_compile(gecos_name, &errptr)))
2652 <        {
2653 <          ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: %s",
2654 <               errptr);
2655 <          break;
2656 <        }
2657 <
2658 <        yy_conf = make_conf_item(RXLINE_TYPE);
2659 <        yy_conf->regexpname = exp_p;
2660 < #else
2661 <        ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: no PCRE support");
2662 <        break;
2663 < #endif
2664 <      }
2665 <      else
2666 <        yy_conf = make_conf_item(XLINE_TYPE);
2385 >  struct MaskItem *conf = NULL;
2386  
2387 <      yy_match_item = map_to_conf(yy_conf);
2388 <      DupString(yy_conf->name, gecos_name);
2387 >  if (conf_parser_ctx.pass != 2)
2388 >    break;
2389  
2390 <      if (reasonbuf[0])
2391 <        DupString(yy_match_item->reason, reasonbuf);
2673 <      else
2674 <        DupString(yy_match_item->reason, "No reason");
2675 <    }
2676 <  }
2677 < };
2390 >  if (!block_state.name.buf[0])
2391 >    break;
2392  
2393 < gecos_flags: TYPE
2394 < {
2681 < } '='  gecos_flags_items ';';
2393 >  conf = conf_make(CONF_XLINE);
2394 >  conf->name = xstrdup(block_state.name.buf);
2395  
2396 < gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2397 < gecos_flags_item: REGEX_T
2398 < {
2399 <  if (conf_parser_ctx.pass == 2)
2687 <    regex_ban = 1;
2396 >  if (block_state.rpass.buf[0])
2397 >    conf->reason = xstrdup(block_state.rpass.buf);
2398 >  else
2399 >    conf->reason = xstrdup(CONF_NOREASON);
2400   };
2401  
2402   gecos_items: gecos_items gecos_item | gecos_item;
2403 < gecos_item:  gecos_name | gecos_reason | gecos_flags | error;
2403 > gecos_item:  gecos_name | gecos_reason | error;
2404  
2405   gecos_name: NAME '=' QSTRING ';'
2406   {
2407    if (conf_parser_ctx.pass == 2)
2408 <    strlcpy(gecos_name, yylval.string, sizeof(gecos_name));
2408 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2409   };
2410  
2411   gecos_reason: REASON '=' QSTRING ';'
2412   {
2413    if (conf_parser_ctx.pass == 2)
2414 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2414 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2415   };
2416  
2417   /***************************************************************************
# Line 2714 | Line 2426 | general_item:       general_hide_spoof_i
2426                      general_max_nick_time | general_max_nick_changes |
2427                      general_max_accept | general_anti_spam_exit_message_time |
2428                      general_ts_warn_delta | general_ts_max_delta |
2429 <                    general_kill_chase_time_limit | general_kline_with_reason |
2430 <                    general_kline_reason | general_invisible_on_connect |
2429 >                    general_kill_chase_time_limit |
2430 >                    general_invisible_on_connect |
2431                      general_warn_no_nline | general_dots_in_ident |
2432                      general_stats_o_oper_only | general_stats_k_oper_only |
2433                      general_pace_wait | general_stats_i_oper_only |
2434                      general_pace_wait_simple | general_stats_P_oper_only |
2435 +                    general_stats_u_oper_only |
2436                      general_short_motd | general_no_oper_flood |
2437                      general_true_no_oper_flood | general_oper_pass_resv |
2725                    general_message_locale |
2438                      general_oper_only_umodes | general_max_targets |
2439                      general_use_egd | general_egdpool_path |
2440                      general_oper_umodes | general_caller_id_wait |
2441                      general_opers_bypass_callerid | general_default_floodcount |
2442                      general_min_nonwildcard | general_min_nonwildcard_simple |
2731                    general_servlink_path | general_disable_remote_commands |
2732                    general_default_cipher_preference |
2733                    general_compression_level | general_client_flood |
2443                      general_throttle_time | general_havent_read_conf |
2444                      general_ping_cookie |
2445                      general_disable_auth |
2446 <                    general_tkline_expire_notices | general_gline_min_cidr |
2447 <                    general_gline_min_cidr6 | general_use_whois_actually |
2448 <                    general_reject_hold_time | general_stats_e_disabled |
2446 >                    general_tkline_expire_notices | general_gline_enable |
2447 >                    general_gline_duration | general_gline_request_duration |
2448 >                    general_gline_min_cidr |
2449 >                    general_gline_min_cidr6 |
2450 >                    general_stats_e_disabled |
2451                      general_max_watch | general_services_name |
2452 +                    general_cycle_on_host_change |
2453                      error;
2454  
2455  
# Line 2746 | Line 2458 | general_max_watch: MAX_WATCH '=' NUMBER
2458    ConfigFileEntry.max_watch = $3;
2459   };
2460  
2461 < general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2461 > general_cycle_on_host_change: CYCLE_ON_HOST_CHANGE '=' TBOOL ';'
2462   {
2463 <  ConfigFileEntry.gline_min_cidr = $3;
2463 >  if (conf_parser_ctx.pass == 2)
2464 >    ConfigFileEntry.cycle_on_host_change = yylval.number;
2465   };
2466  
2467 < general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2467 > general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2468   {
2469 <  ConfigFileEntry.gline_min_cidr6 = $3;
2469 >  if (conf_parser_ctx.pass == 2)
2470 >    ConfigFileEntry.glines = yylval.number;
2471 > };
2472 >
2473 > general_gline_duration: GLINE_DURATION '=' timespec ';'
2474 > {
2475 >  if (conf_parser_ctx.pass == 2)
2476 >    ConfigFileEntry.gline_time = $3;
2477   };
2478  
2479 < general_use_whois_actually: USE_WHOIS_ACTUALLY '=' TBOOL ';'
2479 > general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2480   {
2481 <  ConfigFileEntry.use_whois_actually = yylval.number;
2481 >  if (conf_parser_ctx.pass == 2)
2482 >    ConfigFileEntry.gline_request_time = $3;
2483 > };
2484 >
2485 > general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2486 > {
2487 >  ConfigFileEntry.gline_min_cidr = $3;
2488   };
2489  
2490 < general_reject_hold_time: TREJECT_HOLD_TIME '=' timespec ';'
2490 > general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2491   {
2492 <  GlobalSetOptions.rejecttime = yylval.number;
2492 >  ConfigFileEntry.gline_min_cidr6 = $3;
2493   };
2494  
2495   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
# Line 2786 | Line 2512 | general_ignore_bogus_ts: IGNORE_BOGUS_TS
2512    ConfigFileEntry.ignore_bogus_ts = yylval.number;
2513   };
2514  
2789 general_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2790 {
2791  ConfigFileEntry.disable_remote = yylval.number;
2792 };
2793
2515   general_failed_oper_notice: FAILED_OPER_NOTICE '=' TBOOL ';'
2516   {
2517    ConfigFileEntry.failed_oper_notice = yylval.number;
# Line 2843 | Line 2564 | general_havent_read_conf: HAVENT_READ_CO
2564    }
2565   };
2566  
2846 general_kline_with_reason: KLINE_WITH_REASON '=' TBOOL ';'
2847 {
2848  ConfigFileEntry.kline_with_reason = yylval.number;
2849 };
2850
2851 general_kline_reason: KLINE_REASON '=' QSTRING ';'
2852 {
2853  if (conf_parser_ctx.pass == 2)
2854  {
2855    MyFree(ConfigFileEntry.kline_reason);
2856    DupString(ConfigFileEntry.kline_reason, yylval.string);
2857  }
2858 };
2859
2567   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2568   {
2569    ConfigFileEntry.invisible_on_connect = yylval.number;
# Line 2882 | Line 2589 | general_stats_P_oper_only: STATS_P_OPER_
2589    ConfigFileEntry.stats_P_oper_only = yylval.number;
2590   };
2591  
2592 + general_stats_u_oper_only: STATS_U_OPER_ONLY '=' TBOOL ';'
2593 + {
2594 +  ConfigFileEntry.stats_u_oper_only = yylval.number;
2595 + };
2596 +
2597   general_stats_k_oper_only: STATS_K_OPER_ONLY '=' TBOOL ';'
2598   {
2599    ConfigFileEntry.stats_k_oper_only = 2 * yylval.number;
# Line 2938 | Line 2650 | general_oper_pass_resv: OPER_PASS_RESV '
2650    ConfigFileEntry.oper_pass_resv = yylval.number;
2651   };
2652  
2941 general_message_locale: MESSAGE_LOCALE '=' QSTRING ';'
2942 {
2943  if (conf_parser_ctx.pass == 2)
2944  {
2945    if (strlen(yylval.string) > LOCALE_LENGTH-2)
2946      yylval.string[LOCALE_LENGTH-1] = '\0';
2947
2948    set_locale(yylval.string);
2949  }
2950 };
2951
2653   general_dots_in_ident: DOTS_IN_IDENT '=' NUMBER ';'
2654   {
2655    ConfigFileEntry.dots_in_ident = $3;
# Line 2959 | Line 2660 | general_max_targets: MAX_TARGETS '=' NUM
2660    ConfigFileEntry.max_targets = $3;
2661   };
2662  
2962 general_servlink_path: SERVLINK_PATH '=' QSTRING ';'
2963 {
2964  if (conf_parser_ctx.pass == 2)
2965  {
2966    MyFree(ConfigFileEntry.servlink_path);
2967    DupString(ConfigFileEntry.servlink_path, yylval.string);
2968  }
2969 };
2970
2971 general_default_cipher_preference: DEFAULT_CIPHER_PREFERENCE '=' QSTRING ';'
2972 {
2973 #ifdef HAVE_LIBCRYPTO
2974  if (conf_parser_ctx.pass == 2)
2975  {
2976    struct EncCapability *ecap;
2977    const char *cipher_name;
2978    int found = 0;
2979
2980    ConfigFileEntry.default_cipher_preference = NULL;
2981    cipher_name = yylval.string;
2982
2983    for (ecap = CipherTable; ecap->name; ecap++)
2984    {
2985      if ((irccmp(ecap->name, cipher_name) == 0) &&
2986          (ecap->cap & CAP_ENC_MASK))
2987      {
2988        ConfigFileEntry.default_cipher_preference = ecap;
2989        found = 1;
2990        break;
2991      }
2992    }
2993
2994    if (!found)
2995      yyerror("Invalid cipher");
2996  }
2997 #else
2998  if (conf_parser_ctx.pass == 2)
2999    yyerror("Ignoring default_cipher_preference -- no OpenSSL support");
3000 #endif
3001 };
3002
3003 general_compression_level: COMPRESSION_LEVEL '=' NUMBER ';'
3004 {
3005  if (conf_parser_ctx.pass == 2)
3006  {
3007    ConfigFileEntry.compression_level = $3;
3008 #ifndef HAVE_LIBZ
3009    yyerror("Ignoring compression_level -- no zlib support");
3010 #else
3011    if ((ConfigFileEntry.compression_level < 1) ||
3012        (ConfigFileEntry.compression_level > 9))
3013    {
3014      yyerror("Ignoring invalid compression_level, using default");
3015      ConfigFileEntry.compression_level = 0;
3016    }
3017 #endif
3018  }
3019 };
3020
2663   general_use_egd: USE_EGD '=' TBOOL ';'
2664   {
2665    ConfigFileEntry.use_egd = yylval.number;
# Line 3028 | Line 2670 | general_egdpool_path: EGDPOOL_PATH '=' Q
2670    if (conf_parser_ctx.pass == 2)
2671    {
2672      MyFree(ConfigFileEntry.egdpool_path);
2673 <    DupString(ConfigFileEntry.egdpool_path, yylval.string);
2673 >    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2674    }
2675   };
2676  
# Line 3037 | Line 2679 | general_services_name: T_SERVICES_NAME '
2679    if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2680    {
2681      MyFree(ConfigFileEntry.service_name);
2682 <    DupString(ConfigFileEntry.service_name, yylval.string);
2682 >    ConfigFileEntry.service_name = xstrdup(yylval.string);
2683    }
2684   };
2685  
# Line 3068 | Line 2710 | umode_oitem:     T_BOTS
2710   } | T_CCONN
2711   {
2712    ConfigFileEntry.oper_umodes |= UMODE_CCONN;
3071 } | T_CCONN_FULL
3072 {
3073  ConfigFileEntry.oper_umodes |= UMODE_CCONN_FULL;
2713   } | T_DEAF
2714   {
2715    ConfigFileEntry.oper_umodes |= UMODE_DEAF;
# Line 3080 | Line 2719 | umode_oitem:     T_BOTS
2719   } | T_FULL
2720   {
2721    ConfigFileEntry.oper_umodes |= UMODE_FULL;
2722 + } | HIDDEN
2723 + {
2724 +  ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2725   } | T_SKILL
2726   {
2727    ConfigFileEntry.oper_umodes |= UMODE_SKILL;
# Line 3119 | Line 2761 | umode_oitem:     T_BOTS
2761   } | T_LOCOPS
2762   {
2763    ConfigFileEntry.oper_umodes |= UMODE_LOCOPS;
2764 + } | T_NONONREG
2765 + {
2766 +  ConfigFileEntry.oper_umodes |= UMODE_REGONLY;
2767 + } | T_FARCONNECT
2768 + {
2769 +  ConfigFileEntry.oper_umodes |= UMODE_FARCONNECT;
2770   };
2771  
2772   general_oper_only_umodes: OPER_ONLY_UMODES
# Line 3133 | Line 2781 | umode_item:    T_BOTS
2781   } | T_CCONN
2782   {
2783    ConfigFileEntry.oper_only_umodes |= UMODE_CCONN;
3136 } | T_CCONN_FULL
3137 {
3138  ConfigFileEntry.oper_only_umodes |= UMODE_CCONN_FULL;
2784   } | T_DEAF
2785   {
2786    ConfigFileEntry.oper_only_umodes |= UMODE_DEAF;
# Line 3148 | Line 2793 | umode_item:    T_BOTS
2793   } | T_SKILL
2794   {
2795    ConfigFileEntry.oper_only_umodes |= UMODE_SKILL;
2796 + } | HIDDEN
2797 + {
2798 +  ConfigFileEntry.oper_only_umodes |= UMODE_HIDDEN;
2799   } | T_NCHANGE
2800   {
2801    ConfigFileEntry.oper_only_umodes |= UMODE_NCHANGE;
# Line 3184 | Line 2832 | umode_item:    T_BOTS
2832   } | T_LOCOPS
2833   {
2834    ConfigFileEntry.oper_only_umodes |= UMODE_LOCOPS;
2835 + } | T_NONONREG
2836 + {
2837 +  ConfigFileEntry.oper_only_umodes |= UMODE_REGONLY;
2838 + } | T_FARCONNECT
2839 + {
2840 +  ConfigFileEntry.oper_only_umodes |= UMODE_FARCONNECT;
2841   };
2842  
2843   general_min_nonwildcard: MIN_NONWILDCARD '=' NUMBER ';'
# Line 3201 | Line 2855 | general_default_floodcount: DEFAULT_FLOO
2855    ConfigFileEntry.default_floodcount = $3;
2856   };
2857  
3204 general_client_flood: T_CLIENT_FLOOD '=' sizespec ';'
3205 {
3206  ConfigFileEntry.client_flood = $3;
3207 };
3208
3209
3210 /***************************************************************************
3211 *  section glines
3212 ***************************************************************************/
3213 gline_entry: GLINES
3214 {
3215  if (conf_parser_ctx.pass == 2)
3216  {
3217    yy_conf = make_conf_item(GDENY_TYPE);
3218    yy_aconf = map_to_conf(yy_conf);
3219  }
3220 } '{' gline_items '}' ';'
3221 {
3222  if (conf_parser_ctx.pass == 2)
3223  {
3224    /*
3225     * since we re-allocate yy_conf/yy_aconf after the end of action=, at the
3226     * end we will have one extra, so we should free it.
3227     */
3228    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3229    {
3230      delete_conf_item(yy_conf);
3231      yy_conf = NULL;
3232      yy_aconf = NULL;
3233    }
3234  }
3235 };
3236
3237 gline_items:        gline_items gline_item | gline_item;
3238 gline_item:         gline_enable |
3239                    gline_duration |
3240                    gline_logging |
3241                    gline_user |
3242                    gline_server |
3243                    gline_action |
3244                    error;
3245
3246 gline_enable: ENABLE '=' TBOOL ';'
3247 {
3248  if (conf_parser_ctx.pass == 2)
3249    ConfigFileEntry.glines = yylval.number;
3250 };
3251
3252 gline_duration: DURATION '=' timespec ';'
3253 {
3254  if (conf_parser_ctx.pass == 2)
3255    ConfigFileEntry.gline_time = $3;
3256 };
3257
3258 gline_logging: T_LOG
3259 {
3260  if (conf_parser_ctx.pass == 2)
3261    ConfigFileEntry.gline_logging = 0;
3262 } '=' gline_logging_types ';';
3263 gline_logging_types:     gline_logging_types ',' gline_logging_type_item | gline_logging_type_item;
3264 gline_logging_type_item: T_REJECT
3265 {
3266  if (conf_parser_ctx.pass == 2)
3267    ConfigFileEntry.gline_logging |= GDENY_REJECT;
3268 } | T_BLOCK
3269 {
3270  if (conf_parser_ctx.pass == 2)
3271    ConfigFileEntry.gline_logging |= GDENY_BLOCK;
3272 };
3273
3274 gline_user: USER '=' QSTRING ';'
3275 {
3276  if (conf_parser_ctx.pass == 2)
3277  {
3278    struct split_nuh_item nuh;
3279
3280    nuh.nuhmask  = yylval.string;
3281    nuh.nickptr  = NULL;
3282    nuh.userptr  = userbuf;
3283    nuh.hostptr  = hostbuf;
3284
3285    nuh.nicksize = 0;
3286    nuh.usersize = sizeof(userbuf);
3287    nuh.hostsize = sizeof(hostbuf);
3288
3289    split_nuh(&nuh);
3290
3291    if (yy_aconf->user == NULL)
3292    {
3293      DupString(yy_aconf->user, userbuf);
3294      DupString(yy_aconf->host, hostbuf);
3295    }
3296    else
3297    {
3298      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
3299
3300      DupString(yy_tmp->user, userbuf);
3301      DupString(yy_tmp->host, hostbuf);
3302
3303      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
3304    }
3305  }
3306 };
3307
3308 gline_server: NAME '=' QSTRING ';'
3309 {
3310  if (conf_parser_ctx.pass == 2)  
3311  {
3312    MyFree(yy_conf->name);
3313    DupString(yy_conf->name, yylval.string);
3314  }
3315 };
3316
3317 gline_action: ACTION
3318 {
3319  if (conf_parser_ctx.pass == 2)
3320    yy_aconf->flags = 0;
3321 } '=' gdeny_types ';'
3322 {
3323  if (conf_parser_ctx.pass == 2)
3324  {
3325    struct CollectItem *yy_tmp = NULL;
3326    dlink_node *ptr, *next_ptr;
3327
3328    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
3329    {
3330      struct AccessItem *new_aconf;
3331      struct ConfItem *new_conf;
3332
3333      yy_tmp = ptr->data;
3334      new_conf = make_conf_item(GDENY_TYPE);
3335      new_aconf = map_to_conf(new_conf);
3336
3337      new_aconf->flags = yy_aconf->flags;
3338
3339      if (yy_conf->name != NULL)
3340        DupString(new_conf->name, yy_conf->name);
3341      else
3342        DupString(new_conf->name, "*");
3343      if (yy_aconf->user != NULL)
3344         DupString(new_aconf->user, yy_tmp->user);
3345      else  
3346        DupString(new_aconf->user, "*");
3347      if (yy_aconf->host != NULL)
3348        DupString(new_aconf->host, yy_tmp->host);
3349      else
3350        DupString(new_aconf->host, "*");
3351
3352      dlinkDelete(&yy_tmp->node, &col_conf_list);
3353    }
3354
3355    /*
3356     * In case someone has fed us with more than one action= after user/name
3357     * which would leak memory  -Michael
3358     */
3359    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3360      delete_conf_item(yy_conf);
3361
3362    yy_conf = make_conf_item(GDENY_TYPE);
3363    yy_aconf = map_to_conf(yy_conf);
3364  }
3365 };
3366
3367 gdeny_types: gdeny_types ',' gdeny_type_item | gdeny_type_item;
3368 gdeny_type_item: T_REJECT
3369 {
3370  if (conf_parser_ctx.pass == 2)
3371    yy_aconf->flags |= GDENY_REJECT;
3372 } | T_BLOCK
3373 {
3374  if (conf_parser_ctx.pass == 2)
3375    yy_aconf->flags |= GDENY_BLOCK;
3376 };
2858  
2859   /***************************************************************************
2860   *  section channel
# Line 3382 | Line 2863 | channel_entry: CHANNEL
2863    '{' channel_items '}' ';';
2864  
2865   channel_items:      channel_items channel_item | channel_item;
2866 < channel_item:       channel_disable_local_channels | channel_use_except |
2867 <                    channel_use_invex | channel_use_knock |
2868 <                    channel_max_bans | channel_knock_delay |
2869 <                    channel_knock_delay_channel | channel_max_chans_per_user |
3389 <                    channel_quiet_on_ban | channel_default_split_user_count |
2866 > channel_item:       channel_max_bans |
2867 >                    channel_knock_delay | channel_knock_delay_channel |
2868 >                    channel_max_chans_per_user | channel_max_chans_per_oper |
2869 >                    channel_default_split_user_count |
2870                      channel_default_split_server_count |
2871 <                    channel_no_create_on_split | channel_restrict_channels |
2872 <                    channel_no_join_on_split | channel_burst_topicwho |
2871 >                    channel_no_create_on_split |
2872 >                    channel_no_join_on_split |
2873                      channel_jflood_count | channel_jflood_time |
2874                      channel_disable_fake_channels | error;
2875  
# Line 3398 | Line 2878 | channel_disable_fake_channels: DISABLE_F
2878    ConfigChannel.disable_fake_channels = yylval.number;
2879   };
2880  
3401 channel_restrict_channels: RESTRICT_CHANNELS '=' TBOOL ';'
3402 {
3403  ConfigChannel.restrict_channels = yylval.number;
3404 };
3405
3406 channel_disable_local_channels: DISABLE_LOCAL_CHANNELS '=' TBOOL ';'
3407 {
3408  ConfigChannel.disable_local_channels = yylval.number;
3409 };
3410
3411 channel_use_except: USE_EXCEPT '=' TBOOL ';'
3412 {
3413  ConfigChannel.use_except = yylval.number;
3414 };
3415
3416 channel_use_invex: USE_INVEX '=' TBOOL ';'
3417 {
3418  ConfigChannel.use_invex = yylval.number;
3419 };
3420
3421 channel_use_knock: USE_KNOCK '=' TBOOL ';'
3422 {
3423  ConfigChannel.use_knock = yylval.number;
3424 };
3425
2881   channel_knock_delay: KNOCK_DELAY '=' timespec ';'
2882   {
2883    ConfigChannel.knock_delay = $3;
# Line 3438 | Line 2893 | channel_max_chans_per_user: MAX_CHANS_PE
2893    ConfigChannel.max_chans_per_user = $3;
2894   };
2895  
2896 < channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
2896 > channel_max_chans_per_oper: MAX_CHANS_PER_OPER '=' NUMBER ';'
2897   {
2898 <  ConfigChannel.quiet_on_ban = yylval.number;
2898 >  ConfigChannel.max_chans_per_oper = $3;
2899   };
2900  
2901   channel_max_bans: MAX_BANS '=' NUMBER ';'
# Line 3468 | Line 2923 | channel_no_join_on_split: NO_JOIN_ON_SPL
2923    ConfigChannel.no_join_on_split = yylval.number;
2924   };
2925  
3471 channel_burst_topicwho: BURST_TOPICWHO '=' TBOOL ';'
3472 {
3473  ConfigChannel.burst_topicwho = yylval.number;
3474 };
3475
2926   channel_jflood_count: JOIN_FLOOD_COUNT '=' NUMBER ';'
2927   {
2928    GlobalSetOptions.joinfloodcount = yylval.number;
# Line 3490 | Line 2940 | serverhide_entry: SERVERHIDE
2940    '{' serverhide_items '}' ';';
2941  
2942   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
2943 < serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
2943 > serverhide_item:    serverhide_flatten_links | serverhide_disable_remote_commands |
2944 >                    serverhide_hide_servers |
2945 >                    serverhide_hide_services |
2946                      serverhide_links_delay |
3495                    serverhide_disable_hidden |
2947                      serverhide_hidden | serverhide_hidden_name |
2948                      serverhide_hide_server_ips |
2949                      error;
# Line 3503 | Line 2954 | serverhide_flatten_links: FLATTEN_LINKS
2954      ConfigServerHide.flatten_links = yylval.number;
2955   };
2956  
2957 + serverhide_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2958 + {
2959 +  if (conf_parser_ctx.pass == 2)
2960 +    ConfigServerHide.disable_remote_commands = yylval.number;
2961 + };
2962 +
2963   serverhide_hide_servers: HIDE_SERVERS '=' TBOOL ';'
2964   {
2965    if (conf_parser_ctx.pass == 2)
2966      ConfigServerHide.hide_servers = yylval.number;
2967   };
2968  
2969 + serverhide_hide_services: HIDE_SERVICES '=' TBOOL ';'
2970 + {
2971 +  if (conf_parser_ctx.pass == 2)
2972 +    ConfigServerHide.hide_services = yylval.number;
2973 + };
2974 +
2975   serverhide_hidden_name: HIDDEN_NAME '=' QSTRING ';'
2976   {
2977    if (conf_parser_ctx.pass == 2)
2978    {
2979      MyFree(ConfigServerHide.hidden_name);
2980 <    DupString(ConfigServerHide.hidden_name, yylval.string);
2980 >    ConfigServerHide.hidden_name = xstrdup(yylval.string);
2981    }
2982   };
2983  
# Line 3538 | Line 3001 | serverhide_hidden: HIDDEN '=' TBOOL ';'
3001      ConfigServerHide.hidden = yylval.number;
3002   };
3003  
3541 serverhide_disable_hidden: DISABLE_HIDDEN '=' TBOOL ';'
3542 {
3543  if (conf_parser_ctx.pass == 2)
3544    ConfigServerHide.disable_hidden = yylval.number;
3545 };
3546
3004   serverhide_hide_server_ips: HIDE_SERVER_IPS '=' TBOOL ';'
3005   {
3006    if (conf_parser_ctx.pass == 2)

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)