ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing:
ircd-hybrid-7.2/src/ircd_parser.y (file contents), Revision 601 by michael, Sat May 13 16:59:28 2006 UTC vs.
ircd-hybrid/trunk/src/conf_parser.y (file contents), Revision 3435 by michael, Thu May 1 13:57:39 2014 UTC

# Line 1 | Line 1
1   /*
2 < *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  ircd_parser.y: Parses the ircd configuration file.
2 > *  ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3   *
4 < *  Copyright (C) 2005 by the past and present ircd coders, and others.
4 > *  Copyright (c) 2000-2014 ircd-hybrid development team
5   *
6   *  This program is free software; you can redistribute it and/or modify
7   *  it under the terms of the GNU General Public License as published by
# Line 18 | Line 17
17   *  along with this program; if not, write to the Free Software
18   *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
19   *  USA
21 *
22 *  $Id$
20   */
21  
22 + /*! \file conf_parser.y
23 + * \brief Parses the ircd configuration file.
24 + * \version $Id$
25 + */
26 +
27 +
28   %{
29  
30   #define YY_NO_UNPUT
31   #include <sys/types.h>
32 + #include <string.h>
33  
34 + #include "config.h"
35   #include "stdinc.h"
36   #include "ircd.h"
32 #include "tools.h"
37   #include "list.h"
38 < #include "s_conf.h"
38 > #include "conf.h"
39 > #include "conf_class.h"
40   #include "event.h"
41 < #include "s_log.h"
41 > #include "log.h"
42   #include "client.h"     /* for UMODE_ALL only */
38 #include "pcre.h"
43   #include "irc_string.h"
40 #include "irc_getaddrinfo.h"
41 #include "sprintf_irc.h"
44   #include "memory.h"
45   #include "modules.h"
46 < #include "s_serv.h" /* for CAP_LL / IsCapable */
46 > #include "server.h"
47   #include "hostmask.h"
48   #include "send.h"
49   #include "listener.h"
50   #include "resv.h"
51   #include "numeric.h"
52 < #include "s_user.h"
52 > #include "user.h"
53 > #include "motd.h"
54  
55   #ifdef HAVE_LIBCRYPTO
56   #include <openssl/rsa.h>
57   #include <openssl/bio.h>
58   #include <openssl/pem.h>
59 + #include <openssl/dh.h>
60   #endif
61  
62 < static char *class_name = NULL;
59 < static struct ConfItem *yy_conf = NULL;
60 < static struct AccessItem *yy_aconf = NULL;
61 < static struct MatchItem *yy_match_item = NULL;
62 < static struct ClassItem *yy_class = NULL;
63 < static char *yy_class_name = NULL;
64 <
65 < static dlink_list col_conf_list  = { NULL, NULL, 0 };
66 < static dlink_list hub_conf_list  = { NULL, NULL, 0 };
67 < static dlink_list leaf_conf_list = { NULL, NULL, 0 };
68 < static unsigned int listener_flags = 0;
69 < static unsigned int regex_ban = 0;
70 < static char userbuf[IRCD_BUFSIZE];
71 < static char hostbuf[IRCD_BUFSIZE];
72 < static char reasonbuf[REASONLEN + 1];
73 < static char gecos_name[REALLEN * 4];
74 <
75 < extern dlink_list gdeny_items; /* XXX */
76 <
77 < static char *resv_reason = NULL;
78 < static char *listener_address = NULL;
79 < static int not_atom = 0;
80 <
81 < struct CollectItem
82 < {
83 <  dlink_node node;
84 <  char *name;
85 <  char *user;
86 <  char *host;
87 <  char *passwd;
88 <  int  port;
89 <  int  flags;
90 < #ifdef HAVE_LIBCRYPTO
91 <  char *rsa_public_key_file;
92 <  RSA *rsa_public_key;
93 < #endif
94 < };
62 > #include "rsa.h"
63  
64 < static void
65 < free_collect_item(struct CollectItem *item)
64 > int yylex(void);
65 >
66 > static struct
67   {
68 <  MyFree(item->name);
69 <  MyFree(item->user);
70 <  MyFree(item->host);
71 <  MyFree(item->passwd);
72 < #ifdef HAVE_LIBCRYPTO
73 <  MyFree(item->rsa_public_key_file);
74 < #endif
75 <  MyFree(item);
76 < }
68 >  struct {
69 >    dlink_list list;
70 >  } mask,
71 >    leaf,
72 >    hub;
73 >
74 >  struct {
75 >    char buf[IRCD_BUFSIZE];
76 >  } name,
77 >    user,
78 >    host,
79 >    addr,
80 >    bind,
81 >    file,
82 >    ciph,
83 >    cert,
84 >    rpass,
85 >    spass,
86 >    class;
87 >
88 >  struct {
89 >    unsigned int value;
90 >  } flags,
91 >    modes,
92 >    size,
93 >    type,
94 >    port,
95 >    aftype,
96 >    ping_freq,
97 >    max_perip,
98 >    con_freq,
99 >    min_idle,
100 >    max_idle,
101 >    max_total,
102 >    max_global,
103 >    max_local,
104 >    max_ident,
105 >    max_sendq,
106 >    max_recvq,
107 >    cidr_bitlen_ipv4,
108 >    cidr_bitlen_ipv6,
109 >    number_per_cidr;
110 > } block_state;
111  
112   static void
113 < unhook_hub_leaf_confs(void)
113 > reset_block_state(void)
114   {
115 <  dlink_node *ptr;
116 <  dlink_node *next_ptr;
117 <  struct CollectItem *yy_hconf;
118 <  struct CollectItem *yy_lconf;
115 >  dlink_node *ptr = NULL, *ptr_next = NULL;
116 >
117 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.mask.list.head)
118 >  {
119 >    MyFree(ptr->data);
120 >    dlinkDelete(ptr, &block_state.mask.list);
121 >    free_dlink_node(ptr);
122 >  }
123  
124 <  DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
124 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.leaf.list.head)
125    {
126 <    yy_hconf = ptr->data;
127 <    dlinkDelete(&yy_hconf->node, &hub_conf_list);
128 <    free_collect_item(yy_hconf);
126 >    MyFree(ptr->data);
127 >    dlinkDelete(ptr, &block_state.leaf.list);
128 >    free_dlink_node(ptr);
129    }
130  
131 <  DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
131 >  DLINK_FOREACH_SAFE(ptr, ptr_next, block_state.hub.list.head)
132    {
133 <    yy_lconf = ptr->data;
134 <    dlinkDelete(&yy_lconf->node, &leaf_conf_list);
135 <    free_collect_item(yy_lconf);
133 >    MyFree(ptr->data);
134 >    dlinkDelete(ptr, &block_state.hub.list);
135 >    free_dlink_node(ptr);
136    }
137 +
138 +  memset(&block_state, 0, sizeof(block_state));
139   }
140  
141   %}
# Line 137 | Line 146 | unhook_hub_leaf_confs(void)
146   }
147  
148   %token  ACCEPT_PASSWORD
140 %token  ACTION
149   %token  ADMIN
150   %token  AFTYPE
143 %token  T_ALLOW
151   %token  ANTI_NICK_FLOOD
152   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
153   %token  AUTOCONN
154 < %token  T_BLOCK
148 < %token  BURST_AWAY
149 < %token  BURST_TOPICWHO
150 < %token  BYTES KBYTES MBYTES GBYTES TBYTES
154 > %token  BYTES KBYTES MBYTES
155   %token  CALLER_ID_WAIT
156   %token  CAN_FLOOD
153 %token  CAN_IDLE
157   %token  CHANNEL
158 < %token  CIDR_BITLEN_IPV4
159 < %token  CIDR_BITLEN_IPV6
157 < %token  CIPHER_PREFERENCE
158 > %token  CIDR_BITLEN_IPV4
159 > %token  CIDR_BITLEN_IPV6
160   %token  CLASS
159 %token  COMPRESSED
160 %token  COMPRESSION_LEVEL
161   %token  CONNECT
162   %token  CONNECTFREQ
163 < %token  CRYPTLINK
164 < %token  DEFAULT_CIPHER_PREFERENCE
163 > %token  CYCLE_ON_HOST_CHANGE
164   %token  DEFAULT_FLOODCOUNT
165   %token  DEFAULT_SPLIT_SERVER_COUNT
166   %token  DEFAULT_SPLIT_USER_COUNT
# Line 169 | Line 168 | unhook_hub_leaf_confs(void)
168   %token  DESCRIPTION
169   %token  DIE
170   %token  DISABLE_AUTH
171 < %token  DISABLE_HIDDEN
173 < %token  DISABLE_LOCAL_CHANNELS
171 > %token  DISABLE_FAKE_CHANNELS
172   %token  DISABLE_REMOTE_COMMANDS
175 %token  DOT_IN_IP6_ADDR
173   %token  DOTS_IN_IDENT
177 %token  DURATION
174   %token  EGDPOOL_PATH
175   %token  EMAIL
180 %token  ENABLE
176   %token  ENCRYPTED
177   %token  EXCEED_LIMIT
178   %token  EXEMPT
179   %token  FAILED_OPER_NOTICE
185 %token  FAKENAME
186 %token  IRCD_FLAGS
180   %token  FLATTEN_LINKS
188 %token  FFAILED_OPERLOG
189 %token  FKILLLOG
190 %token  FKLINELOG
191 %token  FGLINELOG
192 %token  FIOERRLOG
193 %token  FOPERLOG
194 %token  FOPERSPYLOG
195 %token  FUSERLOG
181   %token  GECOS
182   %token  GENERAL
183   %token  GLINE
184 < %token  GLINES
184 > %token  GLINE_DURATION
185 > %token  GLINE_ENABLE
186   %token  GLINE_EXEMPT
201 %token  GLINE_LOG
202 %token  GLINE_TIME
187   %token  GLINE_MIN_CIDR
188   %token  GLINE_MIN_CIDR6
189 + %token  GLINE_REQUEST_DURATION
190   %token  GLOBAL_KILL
206 %token  IRCD_AUTH
207 %token  NEED_IDENT
191   %token  HAVENT_READ_CONF
192   %token  HIDDEN
193 < %token  HIDDEN_ADMIN
194 < %token  HIDDEN_NAME
212 < %token  HIDDEN_OPER
193 > %token  HIDDEN_NAME
194 > %token  HIDE_IDLE_FROM_OPERS
195   %token  HIDE_SERVER_IPS
196   %token  HIDE_SERVERS
197 < %token  HIDE_SPOOF_IPS
197 > %token  HIDE_SERVICES
198 > %token  HIDE_SPOOF_IPS
199   %token  HOST
200   %token  HUB
201   %token  HUB_MASK
219 %token  IDLETIME
202   %token  IGNORE_BOGUS_TS
203   %token  INVISIBLE_ON_CONNECT
204   %token  IP
205 + %token  IRCD_AUTH
206 + %token  IRCD_FLAGS
207 + %token  IRCD_SID
208 + %token  JOIN_FLOOD_COUNT
209 + %token  JOIN_FLOOD_TIME
210   %token  KILL
211 < %token  KILL_CHASE_TIME_LIMIT
211 > %token  KILL_CHASE_TIME_LIMIT
212   %token  KLINE
213   %token  KLINE_EXEMPT
227 %token  KLINE_REASON
228 %token  KLINE_WITH_REASON
214   %token  KNOCK_DELAY
215   %token  KNOCK_DELAY_CHANNEL
231 %token  LAZYLINK
216   %token  LEAF_MASK
217   %token  LINKS_DELAY
218   %token  LISTEN
219 < %token  T_LOG
236 < %token  LOGGING
237 < %token  LOG_LEVEL
219 > %token  MASK
220   %token  MAX_ACCEPT
221   %token  MAX_BANS
222 + %token  MAX_CHANS_PER_OPER
223   %token  MAX_CHANS_PER_USER
224   %token  MAX_GLOBAL
225   %token  MAX_IDENT
226 + %token  MAX_IDLE
227   %token  MAX_LOCAL
228   %token  MAX_NICK_CHANGES
229 + %token  MAX_NICK_LENGTH
230   %token  MAX_NICK_TIME
231   %token  MAX_NUMBER
232   %token  MAX_TARGETS
233 < %token  MESSAGE_LOCALE
233 > %token  MAX_TOPIC_LENGTH
234 > %token  MAX_WATCH
235 > %token  MIN_IDLE
236   %token  MIN_NONWILDCARD
237   %token  MIN_NONWILDCARD_SIMPLE
238   %token  MODULE
239   %token  MODULES
240 + %token  MOTD
241   %token  NAME
242 + %token  NEED_IDENT
243   %token  NEED_PASSWORD
244   %token  NETWORK_DESC
245   %token  NETWORK_NAME
246   %token  NICK
258 %token  NICK_CHANGES
247   %token  NO_CREATE_ON_SPLIT
248   %token  NO_JOIN_ON_SPLIT
249   %token  NO_OPER_FLOOD
250   %token  NO_TILDE
263 %token  NOT
251   %token  NUMBER
265 %token  NUMBER_PER_IDENT
252   %token  NUMBER_PER_CIDR
253   %token  NUMBER_PER_IP
268 %token  NUMBER_PER_IP_GLOBAL
269 %token  OPERATOR
270 %token  OPERS_BYPASS_CALLERID
271 %token  OPER_LOG
254   %token  OPER_ONLY_UMODES
255   %token  OPER_PASS_RESV
274 %token  OPER_SPY_T
256   %token  OPER_UMODES
257 < %token  JOIN_FLOOD_COUNT
258 < %token  JOIN_FLOOD_TIME
257 > %token  OPERATOR
258 > %token  OPERS_BYPASS_CALLERID
259   %token  PACE_WAIT
260   %token  PACE_WAIT_SIMPLE
261   %token  PASSWORD
262   %token  PATH
263   %token  PING_COOKIE
264   %token  PING_TIME
284 %token  PING_WARNING
265   %token  PORT
266   %token  QSTRING
267 < %token  QUIET_ON_BAN
267 > %token  RANDOM_IDLE
268   %token  REASON
269   %token  REDIRPORT
270   %token  REDIRSERV
291 %token  REGEX_T
271   %token  REHASH
293 %token  TREJECT_HOLD_TIME
272   %token  REMOTE
273   %token  REMOTEBAN
296 %token  RESTRICT_CHANNELS
297 %token  RESTRICTED
298 %token  RSA_PRIVATE_KEY_FILE
299 %token  RSA_PUBLIC_KEY_FILE
300 %token  SSL_CERTIFICATE_FILE
274   %token  RESV
275   %token  RESV_EXEMPT
276 < %token  SECONDS MINUTES HOURS DAYS WEEKS
277 < %token  SENDQ
276 > %token  RSA_PRIVATE_KEY_FILE
277 > %token  RSA_PUBLIC_KEY_FILE
278 > %token  SECONDS MINUTES HOURS DAYS WEEKS MONTHS YEARS
279   %token  SEND_PASSWORD
280 + %token  SENDQ
281   %token  SERVERHIDE
282   %token  SERVERINFO
308 %token  SERVLINK_PATH
309 %token  IRCD_SID
310 %token  TKLINE_EXPIRE_NOTICES
311 %token  T_SHARED
312 %token  T_CLUSTER
313 %token  TYPE
283   %token  SHORT_MOTD
315 %token  SILENT
284   %token  SPOOF
285   %token  SPOOF_NOTICE
286 + %token  SQUIT
287 + %token  SSL_CERTIFICATE_FILE
288 + %token  SSL_CERTIFICATE_FINGERPRINT
289 + %token  SSL_CONNECTION_REQUIRED
290 + %token  SSL_DH_PARAM_FILE
291   %token  STATS_E_DISABLED
292   %token  STATS_I_OPER_ONLY
293   %token  STATS_K_OPER_ONLY
294   %token  STATS_O_OPER_ONLY
295   %token  STATS_P_OPER_ONLY
296 < %token  TBOOL
324 < %token  TMASKED
325 < %token  T_REJECT
326 < %token  TS_MAX_DELTA
327 < %token  TS_WARN_DELTA
328 < %token  TWODOTS
296 > %token  STATS_U_OPER_ONLY
297   %token  T_ALL
298   %token  T_BOTS
331 %token  T_SOFTCALLERID
299   %token  T_CALLERID
300   %token  T_CCONN
301 < %token  T_CLIENT_FLOOD
301 > %token  T_CLUSTER
302   %token  T_DEAF
303   %token  T_DEBUG
304 < %token  T_DRONE
304 > %token  T_DLINE
305   %token  T_EXTERNAL
306 + %token  T_FARCONNECT
307 + %token  T_FILE
308   %token  T_FULL
309 + %token  T_GLOBOPS
310   %token  T_INVISIBLE
311   %token  T_IPV4
312   %token  T_IPV6
313   %token  T_LOCOPS
314 < %token  T_LOGPATH
345 < %token  T_L_CRIT
346 < %token  T_L_DEBUG
347 < %token  T_L_ERROR
348 < %token  T_L_INFO
349 < %token  T_L_NOTICE
350 < %token  T_L_TRACE
351 < %token  T_L_WARN
314 > %token  T_LOG
315   %token  T_MAX_CLIENTS
316   %token  T_NCHANGE
317 + %token  T_NONONREG
318   %token  T_OPERWALL
319 + %token  T_RECVQ
320   %token  T_REJ
321 + %token  T_RESTART
322 + %token  T_SERVER
323 + %token  T_SERVICE
324 + %token  T_SERVICES_NAME
325   %token  T_SERVNOTICE
326 + %token  T_SET
327 + %token  T_SHARED
328 + %token  T_SIZE
329   %token  T_SKILL
330 + %token  T_SOFTCALLERID
331   %token  T_SPY
332   %token  T_SSL
333 + %token  T_SSL_CIPHER_LIST
334 + %token  T_SSL_CLIENT_METHOD
335 + %token  T_SSL_SERVER_METHOD
336 + %token  T_SSLV3
337 + %token  T_TLSV1
338   %token  T_UMODES
339   %token  T_UNAUTH
340 + %token  T_UNDLINE
341 + %token  T_UNLIMITED
342   %token  T_UNRESV
343   %token  T_UNXLINE
344   %token  T_WALLOP
345 + %token  T_WALLOPS
346 + %token  T_WEBIRC
347 + %token  TBOOL
348   %token  THROTTLE_TIME
349 < %token  TOPICBURST
349 > %token  TKLINE_EXPIRE_NOTICES
350 > %token  TMASKED
351   %token  TRUE_NO_OPER_FLOOD
352 < %token  TKLINE
353 < %token  TXLINE
354 < %token  TRESV
352 > %token  TS_MAX_DELTA
353 > %token  TS_WARN_DELTA
354 > %token  TWODOTS
355 > %token  TYPE
356   %token  UNKLINE
372 %token  USER
357   %token  USE_EGD
374 %token  USE_EXCEPT
375 %token  USE_INVEX
376 %token  USE_KNOCK
358   %token  USE_LOGGING
359 < %token  USE_WHOIS_ACTUALLY
359 > %token  USER
360   %token  VHOST
361   %token  VHOST6
381 %token  XLINE
382 %token  WARN
362   %token  WARN_NO_NLINE
363 + %token  XLINE
364  
365 < %type <string> QSTRING
366 < %type <number> NUMBER
367 < %type <number> timespec
368 < %type <number> timespec_
369 < %type <number> sizespec
370 < %type <number> sizespec_
365 > %type  <string> QSTRING
366 > %type  <number> NUMBER
367 > %type  <number> timespec
368 > %type  <number> timespec_
369 > %type  <number> sizespec
370 > %type  <number> sizespec_
371  
372   %%
373 < conf:  
373 > conf:
374          | conf conf_item
375          ;
376  
# Line 398 | Line 378 | conf_item:        admin_entry
378                  | logging_entry
379                  | oper_entry
380                  | channel_entry
381 <                | class_entry
381 >                | class_entry
382                  | listen_entry
383                  | auth_entry
384                  | serverinfo_entry
385                  | serverhide_entry
386                  | resv_entry
387 +                | service_entry
388                  | shared_entry
389                  | cluster_entry
390                  | connect_entry
# Line 411 | Line 392 | conf_item:        admin_entry
392                  | deny_entry
393                  | exempt_entry
394                  | general_entry
414                | gline_entry
395                  | gecos_entry
396                  | modules_entry
397 +                | motd_entry
398                  | error ';'
399                  | error '}'
400          ;
# Line 444 | Line 425 | timespec:      NUMBER timespec_
425                  {
426                          $$ = $1 * 60 * 60 * 24 * 7 + $3;
427                  }
428 +                | NUMBER MONTHS timespec_
429 +                {
430 +                        $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3;
431 +                }
432 +                | NUMBER YEARS timespec_
433 +                {
434 +                        $$ = $1 * 60 * 60 * 24 * 365 + $3;
435 +                }
436                  ;
437  
438   sizespec_:      { $$ = 0; } | sizespec;
# Line 465 | Line 454 | modules_item:   modules_module | modules
454  
455   modules_module: MODULE '=' QSTRING ';'
456   {
457 < #ifndef STATIC_MODULES /* NOOP in the static case */
458 <  if (ypass == 2)
470 <  {
471 <    char *m_bn;
472 <
473 <    m_bn = basename(yylval.string);
474 <
475 <    /* I suppose we should just ignore it if it is already loaded(since
476 <     * otherwise we would flood the opers on rehash) -A1kmm.
477 <     */
478 <    add_conf_module(yylval.string);
479 <  }
480 < #endif
457 >  if (conf_parser_ctx.pass == 2)
458 >    add_conf_module(libio_basename(yylval.string));
459   };
460  
461   modules_path: PATH '=' QSTRING ';'
462   {
463 < #ifndef STATIC_MODULES
486 <  if (ypass == 2)
463 >  if (conf_parser_ctx.pass == 2)
464      mod_add_path(yylval.string);
488 #endif
465   };
466  
491 /***************************************************************************
492 *  section serverinfo
493 ***************************************************************************/
494 serverinfo_entry: SERVERINFO
495  '{' serverinfo_items '}' ';';
467  
468 < serverinfo_items:       serverinfo_items serverinfo_item |
469 <                        serverinfo_item ;
468 > serverinfo_entry: SERVERINFO '{' serverinfo_items '}' ';';
469 >
470 > serverinfo_items:       serverinfo_items serverinfo_item | serverinfo_item ;
471   serverinfo_item:        serverinfo_name | serverinfo_vhost |
472                          serverinfo_hub | serverinfo_description |
473                          serverinfo_network_name | serverinfo_network_desc |
474 <                        serverinfo_max_clients |
474 >                        serverinfo_max_clients | serverinfo_max_nick_length |
475 >                        serverinfo_max_topic_length | serverinfo_ssl_dh_param_file |
476                          serverinfo_rsa_private_key_file | serverinfo_vhost6 |
477                          serverinfo_sid | serverinfo_ssl_certificate_file |
478 +                        serverinfo_ssl_client_method | serverinfo_ssl_server_method |
479 +                        serverinfo_ssl_cipher_list |
480                          error ';' ;
481  
482 +
483 + serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
484 + serverinfo_ssl_server_method: T_SSL_SERVER_METHOD '=' server_method_types ';' ;
485 +
486 + client_method_types: client_method_types ',' client_method_type_item | client_method_type_item;
487 + client_method_type_item: T_SSLV3
488 + {
489 + #ifdef HAVE_LIBCRYPTO
490 +  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
491 +    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv3);
492 + #endif
493 + } | T_TLSV1
494 + {
495 + #ifdef HAVE_LIBCRYPTO
496 +  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
497 +    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_TLSv1);
498 + #endif
499 + };
500 +
501 + server_method_types: server_method_types ',' server_method_type_item | server_method_type_item;
502 + server_method_type_item: T_SSLV3
503 + {
504 + #ifdef HAVE_LIBCRYPTO
505 +  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
506 +    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
507 + #endif
508 + } | T_TLSV1
509 + {
510 + #ifdef HAVE_LIBCRYPTO
511 +  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
512 +    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
513 + #endif
514 + };
515 +
516   serverinfo_ssl_certificate_file: SSL_CERTIFICATE_FILE '=' QSTRING ';'
517   {
518   #ifdef HAVE_LIBCRYPTO
519 <  if (ypass == 2 && ServerInfo.ctx)
519 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
520    {
521      if (!ServerInfo.rsa_private_key_file)
522      {
523 <      yyerror("No rsa_private_key_file specified, SSL disabled");
523 >      conf_error_report("No rsa_private_key_file specified, SSL disabled");
524        break;
525      }
526  
527 <    if (SSL_CTX_use_certificate_file(ServerInfo.ctx,
528 <      yylval.string, SSL_FILETYPE_PEM) <= 0)
527 >    if (SSL_CTX_use_certificate_file(ServerInfo.server_ctx, yylval.string,
528 >                                     SSL_FILETYPE_PEM) <= 0 ||
529 >        SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
530 >                                     SSL_FILETYPE_PEM) <= 0)
531      {
532 <      yyerror(ERR_lib_error_string(ERR_get_error()));
532 >      report_crypto_errors();
533 >      conf_error_report("Could not open/read certificate file");
534        break;
535      }
536  
537 <    if (SSL_CTX_use_PrivateKey_file(ServerInfo.ctx,
538 <      ServerInfo.rsa_private_key_file, SSL_FILETYPE_PEM) <= 0)
537 >    if (SSL_CTX_use_PrivateKey_file(ServerInfo.server_ctx, ServerInfo.rsa_private_key_file,
538 >                                    SSL_FILETYPE_PEM) <= 0 ||
539 >        SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
540 >                                    SSL_FILETYPE_PEM) <= 0)
541      {
542 <      yyerror(ERR_lib_error_string(ERR_get_error()));
542 >      report_crypto_errors();
543 >      conf_error_report("Could not read RSA private key");
544        break;
545      }
546  
547 <    if (!SSL_CTX_check_private_key(ServerInfo.ctx))
547 >    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
548 >        !SSL_CTX_check_private_key(ServerInfo.client_ctx))
549      {
550 <      yyerror("RSA private key does not match the SSL certificate public key!");
550 >      report_crypto_errors();
551 >      conf_error_report("Could not read RSA private key");
552        break;
553      }
554    }
# Line 541 | Line 558 | serverinfo_ssl_certificate_file: SSL_CER
558   serverinfo_rsa_private_key_file: RSA_PRIVATE_KEY_FILE '=' QSTRING ';'
559   {
560   #ifdef HAVE_LIBCRYPTO
561 <  if (ypass == 1)
561 >  BIO *file = NULL;
562 >
563 >  if (conf_parser_ctx.pass != 1)
564 >    break;
565 >
566 >  if (ServerInfo.rsa_private_key)
567    {
568 <    BIO *file;
568 >    RSA_free(ServerInfo.rsa_private_key);
569 >    ServerInfo.rsa_private_key = NULL;
570 >  }
571  
572 <    if (ServerInfo.rsa_private_key)
573 <    {
574 <      RSA_free(ServerInfo.rsa_private_key);
575 <      ServerInfo.rsa_private_key = NULL;
576 <    }
572 >  if (ServerInfo.rsa_private_key_file)
573 >  {
574 >    MyFree(ServerInfo.rsa_private_key_file);
575 >    ServerInfo.rsa_private_key_file = NULL;
576 >  }
577  
578 <    if (ServerInfo.rsa_private_key_file)
555 <    {
556 <      MyFree(ServerInfo.rsa_private_key_file);
557 <      ServerInfo.rsa_private_key_file = NULL;
558 <    }
578 >  ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
579  
580 <    DupString(ServerInfo.rsa_private_key_file, yylval.string);
580 >  if ((file = BIO_new_file(yylval.string, "r")) == NULL)
581 >  {
582 >    conf_error_report("File open failed, ignoring");
583 >    break;
584 >  }
585  
586 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
563 <    {
564 <      yyerror("File open failed, ignoring");
565 <      break;
566 <    }
586 >  ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
587  
588 <    ServerInfo.rsa_private_key = (RSA *)PEM_read_bio_RSAPrivateKey(file, NULL,
589 <      0, NULL);
588 >  BIO_set_close(file, BIO_CLOSE);
589 >  BIO_free(file);
590  
591 <    BIO_set_close(file, BIO_CLOSE);
592 <    BIO_free(file);
591 >  if (ServerInfo.rsa_private_key == NULL)
592 >  {
593 >    conf_error_report("Couldn't extract key, ignoring");
594 >    break;
595 >  }
596  
597 <    if (ServerInfo.rsa_private_key == NULL)
598 <    {
599 <      yyerror("Couldn't extract key, ignoring");
600 <      break;
578 <    }
597 >  if (!RSA_check_key(ServerInfo.rsa_private_key))
598 >  {
599 >    RSA_free(ServerInfo.rsa_private_key);
600 >    ServerInfo.rsa_private_key = NULL;
601  
602 <    if (!RSA_check_key(ServerInfo.rsa_private_key))
603 <    {
604 <      RSA_free(ServerInfo.rsa_private_key);
583 <      ServerInfo.rsa_private_key = NULL;
602 >    conf_error_report("Invalid key, ignoring");
603 >    break;
604 >  }
605  
606 <      yyerror("Invalid key, ignoring");
607 <      break;
608 <    }
606 >  if (RSA_size(ServerInfo.rsa_private_key) < 128)
607 >  {
608 >    RSA_free(ServerInfo.rsa_private_key);
609 >    ServerInfo.rsa_private_key = NULL;
610  
611 <    /* require 2048 bit (256 byte) key */
612 <    if (RSA_size(ServerInfo.rsa_private_key) != 256)
611 >    conf_error_report("Ignoring serverinfo::rsa_private_key_file -- need at least a 1024 bit key size");
612 >  }
613 > #endif
614 > };
615 >
616 > serverinfo_ssl_dh_param_file: SSL_DH_PARAM_FILE '=' QSTRING ';'
617 > {
618 > /* TBD - XXX: error reporting */
619 > #ifdef HAVE_LIBCRYPTO
620 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
621 >  {
622 >    BIO *file = BIO_new_file(yylval.string, "r");
623 >
624 >    if (file)
625      {
626 <      RSA_free(ServerInfo.rsa_private_key);
627 <      ServerInfo.rsa_private_key = NULL;
626 >      DH *dh = PEM_read_bio_DHparams(file, NULL, NULL, NULL);
627 >
628 >      BIO_free(file);
629 >
630 >      if (dh)
631 >      {
632 >        if (DH_size(dh) < 128)
633 >          conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
634 >        else
635 >          SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
636  
637 <      yyerror("Not a 2048 bit key, ignoring");
637 >        DH_free(dh);
638 >      }
639      }
640    }
641   #endif
642   };
643  
644 < serverinfo_name: NAME '=' QSTRING ';'
644 > serverinfo_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
645 > {
646 > #ifdef HAVE_LIBCRYPTO
647 >  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
648 >    SSL_CTX_set_cipher_list(ServerInfo.server_ctx, yylval.string);
649 > #endif
650 > };
651 >
652 > serverinfo_name: NAME '=' QSTRING ';'
653   {
654    /* this isn't rehashable */
655 <  if (ypass == 2)
655 >  if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
656    {
657 <    if (ServerInfo.name == NULL)
657 >    if (valid_servname(yylval.string))
658 >      ServerInfo.name = xstrdup(yylval.string);
659 >    else
660      {
661 <      /* the ircd will exit() in main() if we dont set one */
662 <      if (strlen(yylval.string) <= HOSTLEN)
610 <        DupString(ServerInfo.name, yylval.string);
661 >      conf_error_report("Ignoring serverinfo::name -- invalid name. Aborting.");
662 >      exit(0);
663      }
664    }
665   };
666  
667 < serverinfo_sid: IRCD_SID '=' QSTRING ';'
667 > serverinfo_sid: IRCD_SID '=' QSTRING ';'
668   {
669    /* this isn't rehashable */
670 <  if (ypass == 2 && !ServerInfo.sid)
670 >  if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
671    {
672      if (valid_sid(yylval.string))
673 <      DupString(ServerInfo.sid, yylval.string);
673 >      ServerInfo.sid = xstrdup(yylval.string);
674      else
675      {
676 <      ilog(L_ERROR, "Ignoring config file entry SID -- invalid SID. Aborting.");
676 >      conf_error_report("Ignoring serverinfo::sid -- invalid SID. Aborting.");
677        exit(0);
678      }
679    }
# Line 629 | Line 681 | serverinfo_sid: IRCD_SID '=' QSTRING ';'
681  
682   serverinfo_description: DESCRIPTION '=' QSTRING ';'
683   {
684 <  if (ypass == 2)
684 >  if (conf_parser_ctx.pass == 2)
685    {
686      MyFree(ServerInfo.description);
687 <    DupString(ServerInfo.description,yylval.string);
687 >    ServerInfo.description = xstrdup(yylval.string);
688    }
689   };
690  
691   serverinfo_network_name: NETWORK_NAME '=' QSTRING ';'
692   {
693 <  if (ypass == 2)
693 >  if (conf_parser_ctx.pass == 2)
694    {
695      char *p;
696  
# Line 646 | Line 698 | serverinfo_network_name: NETWORK_NAME '=
698        p = '\0';
699  
700      MyFree(ServerInfo.network_name);
701 <    DupString(ServerInfo.network_name, yylval.string);
701 >    ServerInfo.network_name = xstrdup(yylval.string);
702    }
703   };
704  
705   serverinfo_network_desc: NETWORK_DESC '=' QSTRING ';'
706   {
707 <  if (ypass == 2)
708 <  {
709 <    MyFree(ServerInfo.network_desc);
710 <    DupString(ServerInfo.network_desc, yylval.string);
711 <  }
707 >  if (conf_parser_ctx.pass != 2)
708 >    break;
709 >
710 >  MyFree(ServerInfo.network_desc);
711 >  ServerInfo.network_desc = xstrdup(yylval.string);
712   };
713  
714   serverinfo_vhost: VHOST '=' QSTRING ';'
715   {
716 <  if (ypass == 2 && *yylval.string != '*')
716 >  if (conf_parser_ctx.pass == 2 && *yylval.string != '*')
717    {
718      struct addrinfo hints, *res;
719  
# Line 671 | Line 723 | serverinfo_vhost: VHOST '=' QSTRING ';'
723      hints.ai_socktype = SOCK_STREAM;
724      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
725  
726 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
727 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
726 >    if (getaddrinfo(yylval.string, NULL, &hints, &res))
727 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
728      else
729      {
730        assert(res != NULL);
# Line 680 | Line 732 | serverinfo_vhost: VHOST '=' QSTRING ';'
732        memcpy(&ServerInfo.ip, res->ai_addr, res->ai_addrlen);
733        ServerInfo.ip.ss.ss_family = res->ai_family;
734        ServerInfo.ip.ss_len = res->ai_addrlen;
735 <      irc_freeaddrinfo(res);
735 >      freeaddrinfo(res);
736  
737        ServerInfo.specific_ipv4_vhost = 1;
738      }
# Line 690 | Line 742 | serverinfo_vhost: VHOST '=' QSTRING ';'
742   serverinfo_vhost6: VHOST6 '=' QSTRING ';'
743   {
744   #ifdef IPV6
745 <  if (ypass == 2 && *yylval.string != '*')
745 >  if (conf_parser_ctx.pass == 2 && *yylval.string != '*')
746    {
747      struct addrinfo hints, *res;
748  
# Line 700 | Line 752 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
752      hints.ai_socktype = SOCK_STREAM;
753      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
754  
755 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
756 <      ilog(L_ERROR, "Invalid netmask for server vhost6(%s)", yylval.string);
755 >    if (getaddrinfo(yylval.string, NULL, &hints, &res))
756 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost6(%s)", yylval.string);
757      else
758      {
759        assert(res != NULL);
# Line 709 | Line 761 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
761        memcpy(&ServerInfo.ip6, res->ai_addr, res->ai_addrlen);
762        ServerInfo.ip6.ss.ss_family = res->ai_family;
763        ServerInfo.ip6.ss_len = res->ai_addrlen;
764 <      irc_freeaddrinfo(res);
764 >      freeaddrinfo(res);
765  
766        ServerInfo.specific_ipv6_vhost = 1;
767      }
# Line 719 | Line 771 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
771  
772   serverinfo_max_clients: T_MAX_CLIENTS '=' NUMBER ';'
773   {
774 <  if (ypass == 2)
774 >  if (conf_parser_ctx.pass != 2)
775 >    break;
776 >
777 >  if ($3 < MAXCLIENTS_MIN)
778    {
779 <    recalc_fdlimit(NULL);
779 >    char buf[IRCD_BUFSIZE];
780  
781 <    if ($3 < MAXCLIENTS_MIN)
782 <    {
783 <      char buf[IRCD_BUFSIZE];
784 <      ircsprintf(buf, "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
785 <      yyerror(buf);
786 <    }
787 <    else if ($3 > MAXCLIENTS_MAX)
788 <    {
789 <      char buf[IRCD_BUFSIZE];
790 <      ircsprintf(buf, "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
791 <      yyerror(buf);
737 <    }
738 <    else
739 <      ServerInfo.max_clients = $3;
781 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
782 >    conf_error_report(buf);
783 >    ServerInfo.max_clients = MAXCLIENTS_MIN;
784 >  }
785 >  else if ($3 > MAXCLIENTS_MAX)
786 >  {
787 >    char buf[IRCD_BUFSIZE];
788 >
789 >    snprintf(buf, sizeof(buf), "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
790 >    conf_error_report(buf);
791 >    ServerInfo.max_clients = MAXCLIENTS_MAX;
792    }
793 +  else
794 +    ServerInfo.max_clients = $3;
795   };
796  
797 < serverinfo_hub: HUB '=' TBOOL ';'
797 > serverinfo_max_nick_length: MAX_NICK_LENGTH '=' NUMBER ';'
798   {
799 <  if (ypass == 2)
799 >  if (conf_parser_ctx.pass != 2)
800 >    break;
801 >
802 >  if ($3 < 9)
803    {
804 <    if (yylval.number)
805 <    {
806 <      /* Don't become a hub if we have a lazylink active. */
807 <      if (!ServerInfo.hub && uplink && IsCapable(uplink, CAP_LL))
808 <      {
809 <        sendto_realops_flags(UMODE_ALL, L_ALL,
753 <                             "Ignoring config file line hub=yes; "
754 <                             "due to active LazyLink (%s)", uplink->name);
755 <      }
756 <      else
757 <      {
758 <        ServerInfo.hub = 1;
759 <        uplink = NULL;
760 <        delete_capability("HUB");
761 <        add_capability("HUB", CAP_HUB, 1);
762 <      }
763 <    }
764 <    else if (ServerInfo.hub)
765 <    {
766 <      dlink_node *ptr = NULL;
804 >    conf_error_report("max_nick_length too low, setting to 9");
805 >    ServerInfo.max_nick_length = 9;
806 >  }
807 >  else if ($3 > NICKLEN)
808 >  {
809 >    char buf[IRCD_BUFSIZE];
810  
811 <      ServerInfo.hub = 0;
812 <      delete_capability("HUB");
811 >    snprintf(buf, sizeof(buf), "max_nick_length too high, setting to %d", NICKLEN);
812 >    conf_error_report(buf);
813 >    ServerInfo.max_nick_length = NICKLEN;
814 >  }
815 >  else
816 >    ServerInfo.max_nick_length = $3;
817 > };
818  
819 <      /* Don't become a leaf if we have a lazylink active. */
820 <      DLINK_FOREACH(ptr, serv_list.head)
821 <      {
822 <        const struct Client *acptr = ptr->data;
823 <        if (MyConnect(acptr) && IsCapable(acptr, CAP_LL))
824 <        {
825 <          sendto_realops_flags(UMODE_ALL, L_ALL,
826 <                               "Ignoring config file line hub=no; "
827 <                               "due to active LazyLink (%s)",
780 <                               acptr->name);
781 <          add_capability("HUB", CAP_HUB, 1);
782 <          ServerInfo.hub = 1;
783 <          break;
784 <        }
785 <      }
786 <    }
819 > serverinfo_max_topic_length: MAX_TOPIC_LENGTH '=' NUMBER ';'
820 > {
821 >  if (conf_parser_ctx.pass != 2)
822 >    break;
823 >
824 >  if ($3 < 80)
825 >  {
826 >    conf_error_report("max_topic_length too low, setting to 80");
827 >    ServerInfo.max_topic_length = 80;
828    }
829 +  else if ($3 > TOPICLEN)
830 +  {
831 +    char buf[IRCD_BUFSIZE];
832 +
833 +    snprintf(buf, sizeof(buf), "max_topic_length too high, setting to %d", TOPICLEN);
834 +    conf_error_report(buf);
835 +    ServerInfo.max_topic_length = TOPICLEN;
836 +  }
837 +  else
838 +    ServerInfo.max_topic_length = $3;
839 + };
840 +
841 + serverinfo_hub: HUB '=' TBOOL ';'
842 + {
843 +  if (conf_parser_ctx.pass == 2)
844 +    ServerInfo.hub = yylval.number;
845   };
846  
847   /***************************************************************************
# Line 796 | Line 853 | admin_items: admin_items admin_item | ad
853   admin_item:  admin_name | admin_description |
854               admin_email | error ';' ;
855  
856 < admin_name: NAME '=' QSTRING ';'
856 > admin_name: NAME '=' QSTRING ';'
857   {
858 <  if (ypass == 2)
859 <  {
860 <    MyFree(AdminInfo.name);
861 <    DupString(AdminInfo.name, yylval.string);
862 <  }
858 >  if (conf_parser_ctx.pass != 2)
859 >    break;
860 >
861 >  MyFree(AdminInfo.name);
862 >  AdminInfo.name = xstrdup(yylval.string);
863   };
864  
865   admin_email: EMAIL '=' QSTRING ';'
866   {
867 <  if (ypass == 2)
868 <  {
869 <    MyFree(AdminInfo.email);
870 <    DupString(AdminInfo.email, yylval.string);
871 <  }
867 >  if (conf_parser_ctx.pass != 2)
868 >    break;
869 >
870 >  MyFree(AdminInfo.email);
871 >  AdminInfo.email = xstrdup(yylval.string);
872   };
873  
874   admin_description: DESCRIPTION '=' QSTRING ';'
875   {
876 <  if (ypass == 2)
877 <  {
878 <    MyFree(AdminInfo.description);
879 <    DupString(AdminInfo.description, yylval.string);
880 <  }
876 >  if (conf_parser_ctx.pass != 2)
877 >    break;
878 >
879 >  MyFree(AdminInfo.description);
880 >  AdminInfo.description = xstrdup(yylval.string);
881   };
882  
883   /***************************************************************************
884 < *  section logging
884 > * motd section
885   ***************************************************************************/
886 < /* XXX */
887 < logging_entry:          LOGGING  '{' logging_items '}' ';' ;
886 > motd_entry: MOTD
887 > {
888 >  if (conf_parser_ctx.pass == 2)
889 >    reset_block_state();
890 > } '{' motd_items '}' ';'
891 > {
892 >  dlink_node *ptr = NULL;
893  
894 < logging_items:          logging_items logging_item |
895 <                        logging_item ;
894 >  if (conf_parser_ctx.pass != 2)
895 >    break;
896  
897 < logging_item:           logging_path | logging_oper_log |
898 <                        logging_log_level |
837 <                        logging_use_logging | logging_fuserlog |
838 <                        logging_foperlog | logging_fglinelog |
839 <                        logging_fklinelog | logging_killlog |
840 <                        logging_foperspylog | logging_ioerrlog |
841 <                        logging_ffailed_operlog |
842 <                        error ';' ;
897 >  if (!block_state.file.buf[0])
898 >    break;
899  
900 < logging_path:           T_LOGPATH '=' QSTRING ';'
901 <                        {
902 <                        };
900 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
901 >    motd_add(ptr->data, block_state.file.buf);
902 > };
903  
904 < logging_oper_log:       OPER_LOG '=' QSTRING ';'
905 <                        {
850 <                        };
904 > motd_items: motd_items motd_item | motd_item;
905 > motd_item:  motd_mask | motd_file | error ';' ;
906  
907 < logging_fuserlog: FUSERLOG '=' QSTRING ';'
907 > motd_mask: MASK '=' QSTRING ';'
908   {
909 <  if (ypass == 2)
910 <    strlcpy(ConfigLoggingEntry.userlog, yylval.string,
856 <            sizeof(ConfigLoggingEntry.userlog));
909 >  if (conf_parser_ctx.pass == 2)
910 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
911   };
912  
913 < logging_ffailed_operlog: FFAILED_OPERLOG '=' QSTRING ';'
913 > motd_file: T_FILE '=' QSTRING ';'
914   {
915 <  if (ypass == 2)
916 <    strlcpy(ConfigLoggingEntry.failed_operlog, yylval.string,
863 <            sizeof(ConfigLoggingEntry.failed_operlog));
915 >  if (conf_parser_ctx.pass == 2)
916 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
917   };
918  
919 < logging_foperlog: FOPERLOG '=' QSTRING ';'
920 < {
921 <  if (ypass == 2)
922 <    strlcpy(ConfigLoggingEntry.operlog, yylval.string,
923 <            sizeof(ConfigLoggingEntry.operlog));
924 < };
919 > /***************************************************************************
920 > *  section logging
921 > ***************************************************************************/
922 > logging_entry:          T_LOG  '{' logging_items '}' ';' ;
923 > logging_items:          logging_items logging_item | logging_item ;
924 >
925 > logging_item:           logging_use_logging | logging_file_entry |
926 >                        error ';' ;
927  
928 < logging_foperspylog: FOPERSPYLOG '=' QSTRING ';'
928 > logging_use_logging: USE_LOGGING '=' TBOOL ';'
929   {
930 <  if (ypass == 2)
931 <    strlcpy(ConfigLoggingEntry.operspylog, yylval.string,
877 <            sizeof(ConfigLoggingEntry.operspylog));
930 >  if (conf_parser_ctx.pass == 2)
931 >    ConfigLoggingEntry.use_logging = yylval.number;
932   };
933  
934 < logging_fglinelog: FGLINELOG '=' QSTRING ';'
934 > logging_file_entry:
935   {
936 <  if (ypass == 2)
937 <    strlcpy(ConfigLoggingEntry.glinelog, yylval.string,
938 <            sizeof(ConfigLoggingEntry.glinelog));
936 >  if (conf_parser_ctx.pass == 2)
937 >    reset_block_state();
938 > } T_FILE  '{' logging_file_items '}' ';'
939 > {
940 >  if (conf_parser_ctx.pass != 2)
941 >    break;
942 >
943 >  if (block_state.type.value && block_state.file.buf[0])
944 >    log_set_file(block_state.type.value, block_state.size.value,
945 >                 block_state.file.buf);
946   };
947  
948 < logging_fklinelog: FKLINELOG '=' QSTRING ';'
948 > logging_file_items: logging_file_items logging_file_item |
949 >                    logging_file_item ;
950 >
951 > logging_file_item:  logging_file_name | logging_file_type |
952 >                    logging_file_size | error ';' ;
953 >
954 > logging_file_name: NAME '=' QSTRING ';'
955   {
956 <  if (ypass == 2)
957 <    strlcpy(ConfigLoggingEntry.klinelog, yylval.string,
958 <            sizeof(ConfigLoggingEntry.klinelog));
959 < };
956 >  if (conf_parser_ctx.pass != 2)
957 >    break;
958 >
959 >  strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
960 > }
961  
962 < logging_ioerrlog: FIOERRLOG '=' QSTRING ';'
962 > logging_file_size: T_SIZE '=' sizespec ';'
963   {
964 <  if (ypass == 2)
965 <    strlcpy(ConfigLoggingEntry.ioerrlog, yylval.string,
966 <            sizeof(ConfigLoggingEntry.ioerrlog));
964 >  block_state.size.value = $3;
965 > } | T_SIZE '=' T_UNLIMITED ';'
966 > {
967 >  block_state.size.value = 0;
968   };
969  
970 < logging_killlog: FKILLLOG '=' QSTRING ';'
970 > logging_file_type: TYPE
971   {
972 <  if (ypass == 2)
973 <    strlcpy(ConfigLoggingEntry.killlog, yylval.string,
974 <            sizeof(ConfigLoggingEntry.killlog));
906 < };
972 >  if (conf_parser_ctx.pass == 2)
973 >    block_state.type.value = 0;
974 > } '='  logging_file_type_items ';' ;
975  
976 < logging_log_level: LOG_LEVEL '=' T_L_CRIT ';'
977 < {
910 <  if (ypass == 2)
911 <    set_log_level(L_CRIT);
912 < } | LOG_LEVEL '=' T_L_ERROR ';'
976 > logging_file_type_items: logging_file_type_items ',' logging_file_type_item | logging_file_type_item;
977 > logging_file_type_item:  USER
978   {
979 <  if (ypass == 2)
980 <    set_log_level(L_ERROR);
981 < } | LOG_LEVEL '=' T_L_WARN ';'
979 >  if (conf_parser_ctx.pass == 2)
980 >    block_state.type.value = LOG_TYPE_USER;
981 > } | OPERATOR
982   {
983 <  if (ypass == 2)
984 <    set_log_level(L_WARN);
985 < } | LOG_LEVEL '=' T_L_NOTICE ';'
983 >  if (conf_parser_ctx.pass == 2)
984 >    block_state.type.value = LOG_TYPE_OPER;
985 > } | GLINE
986   {
987 <  if (ypass == 2)
988 <    set_log_level(L_NOTICE);
989 < } | LOG_LEVEL '=' T_L_TRACE ';'
987 >  if (conf_parser_ctx.pass == 2)
988 >    block_state.type.value = LOG_TYPE_GLINE;
989 > } | XLINE
990   {
991 <  if (ypass == 2)
992 <    set_log_level(L_TRACE);
993 < } | LOG_LEVEL '=' T_L_INFO ';'
991 >  if (conf_parser_ctx.pass == 2)
992 >    block_state.type.value = LOG_TYPE_XLINE;
993 > } | RESV
994   {
995 <  if (ypass == 2)
996 <    set_log_level(L_INFO);
997 < } | LOG_LEVEL '=' T_L_DEBUG ';'
995 >  if (conf_parser_ctx.pass == 2)
996 >    block_state.type.value = LOG_TYPE_RESV;
997 > } | T_DLINE
998   {
999 <  if (ypass == 2)
1000 <    set_log_level(L_DEBUG);
1001 < };
937 <
938 < logging_use_logging: USE_LOGGING '=' TBOOL ';'
999 >  if (conf_parser_ctx.pass == 2)
1000 >    block_state.type.value = LOG_TYPE_DLINE;
1001 > } | KLINE
1002   {
1003 <  if (ypass == 2)
1004 <    ConfigLoggingEntry.use_logging = yylval.number;
1003 >  if (conf_parser_ctx.pass == 2)
1004 >    block_state.type.value = LOG_TYPE_KLINE;
1005 > } | KILL
1006 > {
1007 >  if (conf_parser_ctx.pass == 2)
1008 >    block_state.type.value = LOG_TYPE_KILL;
1009 > } | T_DEBUG
1010 > {
1011 >  if (conf_parser_ctx.pass == 2)
1012 >    block_state.type.value = LOG_TYPE_DEBUG;
1013   };
1014  
1015 +
1016   /***************************************************************************
1017   * section oper
1018   ***************************************************************************/
1019 < oper_entry: OPERATOR
1019 > oper_entry: OPERATOR
1020   {
1021 <  if (ypass == 2)
1022 <  {
1023 <    yy_conf = make_conf_item(OPER_TYPE);
1024 <    yy_aconf = map_to_conf(yy_conf);
1025 <    SetConfEncrypted(yy_aconf); /* Yes, the default is encrypted */
1026 <  }
955 <  else
956 <  {
957 <    MyFree(class_name);
958 <    class_name = NULL;
959 <  }
960 < } oper_name_b '{' oper_items '}' ';'
1021 >  if (conf_parser_ctx.pass != 2)
1022 >    break;
1023 >
1024 >  reset_block_state();
1025 >  block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1026 > } '{' oper_items '}' ';'
1027   {
1028 <  if (ypass == 2)
963 <  {
964 <    struct CollectItem *yy_tmp;
965 <    dlink_node *ptr;
966 <    dlink_node *next_ptr;
1028 >  dlink_node *ptr = NULL;
1029  
1030 <    conf_add_class_to_conf(yy_conf, class_name);
1030 >  if (conf_parser_ctx.pass != 2)
1031 >    break;
1032  
1033 <    /* Now, make sure there is a copy of the "base" given oper
1034 <     * block in each of the collected copies
1035 <     */
1033 >  if (!block_state.name.buf[0])
1034 >    break;
1035 > #ifdef HAVE_LIBCRYPTO
1036 >  if (!block_state.file.buf[0] &&
1037 >      !block_state.rpass.buf[0])
1038 >    break;
1039 > #else
1040 >  if (!block_state.rpass.buf[0])
1041 >    break;
1042 > #endif
1043  
1044 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1045 <    {
1046 <      struct AccessItem *new_aconf;
1047 <      struct ConfItem *new_conf;
978 <      yy_tmp = ptr->data;
979 <
980 <      new_conf = make_conf_item(OPER_TYPE);
981 <      new_aconf = (struct AccessItem *)map_to_conf(new_conf);
982 <
983 <      new_aconf->flags = yy_aconf->flags;
984 <
985 <      if (yy_conf->name != NULL)
986 <        DupString(new_conf->name, yy_conf->name);
987 <      if (yy_tmp->user != NULL)
988 <        DupString(new_aconf->user, yy_tmp->user);
989 <      else
990 <        DupString(new_aconf->user, "*");
991 <      if (yy_tmp->host != NULL)
992 <        DupString(new_aconf->host, yy_tmp->host);
993 <      else
994 <        DupString(new_aconf->host, "*");
995 <      conf_add_class_to_conf(new_conf, class_name);
996 <      if (yy_aconf->passwd != NULL)
997 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1044 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1045 >  {
1046 >    struct MaskItem *conf = NULL;
1047 >    struct split_nuh_item nuh;
1048  
1049 <      new_aconf->port = yy_aconf->port;
1050 < #ifdef HAVE_LIBCRYPTO
1051 <      if (yy_aconf->rsa_public_key_file != NULL)
1052 <      {
1053 <        BIO *file;
1049 >    nuh.nuhmask  = ptr->data;
1050 >    nuh.nickptr  = NULL;
1051 >    nuh.userptr  = block_state.user.buf;
1052 >    nuh.hostptr  = block_state.host.buf;
1053 >    nuh.nicksize = 0;
1054 >    nuh.usersize = sizeof(block_state.user.buf);
1055 >    nuh.hostsize = sizeof(block_state.host.buf);
1056 >    split_nuh(&nuh);
1057  
1058 <        DupString(new_aconf->rsa_public_key_file,
1059 <                  yy_aconf->rsa_public_key_file);
1058 >    conf         = conf_make(CONF_OPER);
1059 >    conf->name   = xstrdup(block_state.name.buf);
1060 >    conf->user   = xstrdup(block_state.user.buf);
1061 >    conf->host   = xstrdup(block_state.host.buf);
1062 >
1063 >    if (block_state.cert.buf[0])
1064 >      conf->certfp = xstrdup(block_state.cert.buf);
1065 >
1066 >    if (block_state.rpass.buf[0])
1067 >      conf->passwd = xstrdup(block_state.rpass.buf);
1068 >
1069 >    conf->flags = block_state.flags.value;
1070 >    conf->modes = block_state.modes.value;
1071 >    conf->port  = block_state.port.value;
1072 >    conf->htype = parse_netmask(conf->host, &conf->addr, &conf->bits);
1073  
1074 <        file = BIO_new_file(yy_aconf->rsa_public_key_file, "r");
1009 <        new_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file,
1010 <                                                           NULL, 0, NULL);
1011 <        BIO_set_close(file, BIO_CLOSE);
1012 <        BIO_free(file);
1013 <      }
1014 < #endif
1074 >    conf_add_class_to_conf(conf, block_state.class.buf);
1075  
1076   #ifdef HAVE_LIBCRYPTO
1077 <      if (yy_tmp->name && (yy_tmp->passwd || yy_aconf->rsa_public_key)
1078 <          && yy_tmp->host)
1079 < #else
1080 <      if (yy_tmp->name && yy_tmp->passwd && yy_tmp->host)
1081 < #endif
1077 >    if (block_state.file.buf[0])
1078 >    {
1079 >      BIO *file = NULL;
1080 >      RSA *pkey = NULL;
1081 >
1082 >      if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
1083        {
1084 <        conf_add_class_to_conf(new_conf, class_name);
1085 <        if (yy_tmp->name != NULL)
1025 <          DupString(new_conf->name, yy_tmp->name);
1084 >        conf_error_report("Ignoring rsa_public_key_file -- file doesn't exist");
1085 >        break;
1086        }
1087  
1088 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1089 <      free_collect_item(yy_tmp);
1030 <    }
1031 <
1032 <    yy_conf = NULL;
1033 <    yy_aconf = NULL;
1088 >      if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
1089 >        conf_error_report("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1090  
1091 <
1092 <    MyFree(class_name);
1093 <    class_name = NULL;
1091 >      conf->rsa_public_key = pkey;
1092 >      BIO_set_close(file, BIO_CLOSE);
1093 >      BIO_free(file);
1094 >    }
1095 > #endif /* HAVE_LIBCRYPTO */
1096    }
1097 < };
1097 > };
1098  
1041 oper_name_b: | oper_name_t;
1099   oper_items:     oper_items oper_item | oper_item;
1100 < oper_item:      oper_name | oper_user | oper_password | oper_hidden_admin |
1101 <                oper_hidden_oper | oper_umodes |
1102 <                oper_class | oper_global_kill | oper_remote |
1103 <                oper_kline | oper_xline | oper_unkline |
1104 <                oper_gline | oper_nick_changes | oper_remoteban |
1048 <                oper_die | oper_rehash | oper_admin | oper_operwall |
1049 <                oper_encrypted | oper_rsa_public_key_file |
1050 <                oper_flags | error ';' ;
1100 > oper_item:      oper_name | oper_user | oper_password |
1101 >                oper_umodes | oper_class | oper_encrypted |
1102 >                oper_rsa_public_key_file | oper_ssl_certificate_fingerprint |
1103 >                oper_ssl_connection_required |
1104 >                oper_flags | error ';' ;
1105  
1106   oper_name: NAME '=' QSTRING ';'
1107   {
1108 <  if (ypass == 2)
1109 <  {
1056 <    if (strlen(yylval.string) > OPERNICKLEN)
1057 <      yylval.string[OPERNICKLEN] = '\0';
1058 <
1059 <    MyFree(yy_conf->name);
1060 <    DupString(yy_conf->name, yylval.string);
1061 <  }
1062 < };
1063 <
1064 < oper_name_t: QSTRING
1065 < {
1066 <  if (ypass == 2)
1067 <  {
1068 <    if (strlen(yylval.string) > OPERNICKLEN)
1069 <      yylval.string[OPERNICKLEN] = '\0';
1070 <
1071 <    MyFree(yy_conf->name);
1072 <    DupString(yy_conf->name, yylval.string);
1073 <  }
1108 >  if (conf_parser_ctx.pass == 2)
1109 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1110   };
1111  
1112   oper_user: USER '=' QSTRING ';'
1113   {
1114 <  if (ypass == 2)
1115 <  {
1080 <    struct split_nuh_item nuh;
1081 <
1082 <    nuh.nuhmask  = yylval.string;
1083 <    nuh.nickptr  = NULL;
1084 <    nuh.userptr  = userbuf;
1085 <    nuh.hostptr  = hostbuf;
1086 <
1087 <    nuh.nicksize = 0;
1088 <    nuh.usersize = sizeof(userbuf);
1089 <    nuh.hostsize = sizeof(hostbuf);
1090 <
1091 <    split_nuh(&nuh);
1092 <
1093 <    if (yy_aconf->user == NULL)
1094 <    {
1095 <      DupString(yy_aconf->user, userbuf);
1096 <      DupString(yy_aconf->host, hostbuf);
1097 <    }
1098 <    else
1099 <    {
1100 <      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
1101 <
1102 <      DupString(yy_tmp->user, userbuf);
1103 <      DupString(yy_tmp->host, hostbuf);
1104 <
1105 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1106 <    }
1107 <  }
1114 >  if (conf_parser_ctx.pass == 2)
1115 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1116   };
1117  
1118   oper_password: PASSWORD '=' QSTRING ';'
1119   {
1120 <  if (ypass == 2)
1121 <  {
1114 <    if (yy_aconf->passwd != NULL)
1115 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1116 <
1117 <    MyFree(yy_aconf->passwd);
1118 <    DupString(yy_aconf->passwd, yylval.string);
1119 <  }
1120 >  if (conf_parser_ctx.pass == 2)
1121 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1122   };
1123  
1124   oper_encrypted: ENCRYPTED '=' TBOOL ';'
1125   {
1126 <  if (ypass == 2)
1127 <  {
1128 <    if (yylval.number)
1129 <      SetConfEncrypted(yy_aconf);
1130 <    else
1131 <      ClearConfEncrypted(yy_aconf);
1132 <  }
1126 >  if (conf_parser_ctx.pass != 2)
1127 >    break;
1128 >
1129 >  if (yylval.number)
1130 >    block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1131 >  else
1132 >    block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1133   };
1134  
1135   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
1136   {
1137 < #ifdef HAVE_LIBCRYPTO
1138 <  if (ypass == 2)
1139 <  {
1138 <    BIO *file;
1139 <
1140 <    if (yy_aconf->rsa_public_key != NULL)
1141 <    {
1142 <      RSA_free(yy_aconf->rsa_public_key);
1143 <      yy_aconf->rsa_public_key = NULL;
1144 <    }
1145 <
1146 <    if (yy_aconf->rsa_public_key_file != NULL)
1147 <    {
1148 <      MyFree(yy_aconf->rsa_public_key_file);
1149 <      yy_aconf->rsa_public_key_file = NULL;
1150 <    }
1151 <
1152 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
1153 <    file = BIO_new_file(yylval.string, "r");
1154 <
1155 <    if (file == NULL)
1156 <    {
1157 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
1158 <      break;
1159 <    }
1137 >  if (conf_parser_ctx.pass == 2)
1138 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1139 > };
1140  
1141 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
1141 > oper_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
1142 > {
1143 >  if (conf_parser_ctx.pass == 2)
1144 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
1145 > };
1146  
1147 <    if (yy_aconf->rsa_public_key == NULL)
1148 <    {
1149 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1150 <      break;
1167 <    }
1147 > oper_ssl_connection_required: SSL_CONNECTION_REQUIRED '=' TBOOL ';'
1148 > {
1149 >  if (conf_parser_ctx.pass != 2)
1150 >    break;
1151  
1152 <    BIO_set_close(file, BIO_CLOSE);
1153 <    BIO_free(file);
1154 <  }
1155 < #endif /* HAVE_LIBCRYPTO */
1152 >  if (yylval.number)
1153 >    block_state.flags.value |= CONF_FLAGS_SSL;
1154 >  else
1155 >    block_state.flags.value &= ~CONF_FLAGS_SSL;
1156   };
1157  
1158   oper_class: CLASS '=' QSTRING ';'
1159   {
1160 <  if (ypass == 2)
1161 <  {
1179 <    MyFree(class_name);
1180 <    DupString(class_name, yylval.string);
1181 <  }
1160 >  if (conf_parser_ctx.pass == 2)
1161 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1162   };
1163  
1164   oper_umodes: T_UMODES
1165   {
1166 <  if (ypass == 2)
1167 <    yy_aconf->modes = 0;
1166 >  if (conf_parser_ctx.pass == 2)
1167 >    block_state.modes.value = 0;
1168   } '='  oper_umodes_items ';' ;
1169  
1170   oper_umodes_items: oper_umodes_items ',' oper_umodes_item | oper_umodes_item;
1171   oper_umodes_item:  T_BOTS
1172   {
1173 <  if (ypass == 2)
1174 <    yy_aconf->modes |= UMODE_BOTS;
1173 >  if (conf_parser_ctx.pass == 2)
1174 >    block_state.modes.value |= UMODE_BOTS;
1175   } | T_CCONN
1176   {
1177 <  if (ypass == 2)
1178 <    yy_aconf->modes |= UMODE_CCONN;
1177 >  if (conf_parser_ctx.pass == 2)
1178 >    block_state.modes.value |= UMODE_CCONN;
1179   } | T_DEAF
1180   {
1181 <  if (ypass == 2)
1182 <    yy_aconf->modes |= UMODE_DEAF;
1181 >  if (conf_parser_ctx.pass == 2)
1182 >    block_state.modes.value |= UMODE_DEAF;
1183   } | T_DEBUG
1184   {
1185 <  if (ypass == 2)
1186 <    yy_aconf->modes |= UMODE_DEBUG;
1185 >  if (conf_parser_ctx.pass == 2)
1186 >    block_state.modes.value |= UMODE_DEBUG;
1187   } | T_FULL
1188   {
1189 <  if (ypass == 2)
1190 <    yy_aconf->modes |= UMODE_FULL;
1189 >  if (conf_parser_ctx.pass == 2)
1190 >    block_state.modes.value |= UMODE_FULL;
1191 > } | HIDDEN
1192 > {
1193 >  if (conf_parser_ctx.pass == 2)
1194 >    block_state.modes.value |= UMODE_HIDDEN;
1195   } | T_SKILL
1196   {
1197 <  if (ypass == 2)
1198 <    yy_aconf->modes |= UMODE_SKILL;
1197 >  if (conf_parser_ctx.pass == 2)
1198 >    block_state.modes.value |= UMODE_SKILL;
1199   } | T_NCHANGE
1200   {
1201 <  if (ypass == 2)
1202 <    yy_aconf->modes |= UMODE_NCHANGE;
1201 >  if (conf_parser_ctx.pass == 2)
1202 >    block_state.modes.value |= UMODE_NCHANGE;
1203   } | T_REJ
1204   {
1205 <  if (ypass == 2)
1206 <    yy_aconf->modes |= UMODE_REJ;
1205 >  if (conf_parser_ctx.pass == 2)
1206 >    block_state.modes.value |= UMODE_REJ;
1207   } | T_UNAUTH
1208   {
1209 <  if (ypass == 2)
1210 <    yy_aconf->modes |= UMODE_UNAUTH;
1209 >  if (conf_parser_ctx.pass == 2)
1210 >    block_state.modes.value |= UMODE_UNAUTH;
1211   } | T_SPY
1212   {
1213 <  if (ypass == 2)
1214 <    yy_aconf->modes |= UMODE_SPY;
1213 >  if (conf_parser_ctx.pass == 2)
1214 >    block_state.modes.value |= UMODE_SPY;
1215   } | T_EXTERNAL
1216   {
1217 <  if (ypass == 2)
1218 <    yy_aconf->modes |= UMODE_EXTERNAL;
1217 >  if (conf_parser_ctx.pass == 2)
1218 >    block_state.modes.value |= UMODE_EXTERNAL;
1219   } | T_OPERWALL
1220   {
1221 <  if (ypass == 2)
1222 <    yy_aconf->modes |= UMODE_OPERWALL;
1221 >  if (conf_parser_ctx.pass == 2)
1222 >    block_state.modes.value |= UMODE_OPERWALL;
1223   } | T_SERVNOTICE
1224   {
1225 <  if (ypass == 2)
1226 <    yy_aconf->modes |= UMODE_SERVNOTICE;
1225 >  if (conf_parser_ctx.pass == 2)
1226 >    block_state.modes.value |= UMODE_SERVNOTICE;
1227   } | T_INVISIBLE
1228   {
1229 <  if (ypass == 2)
1230 <    yy_aconf->modes |= UMODE_INVISIBLE;
1229 >  if (conf_parser_ctx.pass == 2)
1230 >    block_state.modes.value |= UMODE_INVISIBLE;
1231   } | T_WALLOP
1232   {
1233 <  if (ypass == 2)
1234 <    yy_aconf->modes |= UMODE_WALLOP;
1233 >  if (conf_parser_ctx.pass == 2)
1234 >    block_state.modes.value |= UMODE_WALLOP;
1235   } | T_SOFTCALLERID
1236   {
1237 <  if (ypass == 2)
1238 <    yy_aconf->modes |= UMODE_SOFTCALLERID;
1237 >  if (conf_parser_ctx.pass == 2)
1238 >    block_state.modes.value |= UMODE_SOFTCALLERID;
1239   } | T_CALLERID
1240   {
1241 <  if (ypass == 2)
1242 <    yy_aconf->modes |= UMODE_CALLERID;
1241 >  if (conf_parser_ctx.pass == 2)
1242 >    block_state.modes.value |= UMODE_CALLERID;
1243   } | T_LOCOPS
1244   {
1245 <  if (ypass == 2)
1246 <    yy_aconf->modes |= UMODE_LOCOPS;
1247 < };
1248 <
1249 < oper_global_kill: GLOBAL_KILL '=' TBOOL ';'
1250 < {
1251 <  if (ypass == 2)
1268 <  {
1269 <    if (yylval.number)
1270 <      yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1271 <    else
1272 <      yy_aconf->port &= ~OPER_FLAG_GLOBAL_KILL;
1273 <  }
1274 < };
1275 <
1276 < oper_remote: REMOTE '=' TBOOL ';'
1277 < {
1278 <  if (ypass == 2)
1279 <  {
1280 <    if (yylval.number)
1281 <      yy_aconf->port |= OPER_FLAG_REMOTE;
1282 <    else
1283 <      yy_aconf->port &= ~OPER_FLAG_REMOTE;
1284 <  }
1285 < };
1286 <
1287 < oper_remoteban: REMOTEBAN '=' TBOOL ';'
1288 < {
1289 <  if (ypass == 2)
1290 <  {
1291 <    if (yylval.number)
1292 <      yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1293 <    else
1294 <      yy_aconf->port &= ~OPER_FLAG_REMOTEBAN;
1295 <  }
1296 < };
1297 <
1298 < oper_kline: KLINE '=' TBOOL ';'
1299 < {
1300 <  if (ypass == 2)
1301 <  {
1302 <    if (yylval.number)
1303 <      yy_aconf->port |= OPER_FLAG_K;
1304 <    else
1305 <      yy_aconf->port &= ~OPER_FLAG_K;
1306 <  }
1307 < };
1308 <
1309 < oper_xline: XLINE '=' TBOOL ';'
1310 < {
1311 <  if (ypass == 2)
1312 <  {
1313 <    if (yylval.number)
1314 <      yy_aconf->port |= OPER_FLAG_X;
1315 <    else
1316 <      yy_aconf->port &= ~OPER_FLAG_X;
1317 <  }
1318 < };
1319 <
1320 < oper_unkline: UNKLINE '=' TBOOL ';'
1321 < {
1322 <  if (ypass == 2)
1323 <  {
1324 <    if (yylval.number)
1325 <      yy_aconf->port |= OPER_FLAG_UNKLINE;
1326 <    else
1327 <      yy_aconf->port &= ~OPER_FLAG_UNKLINE;
1328 <  }
1329 < };
1330 <
1331 < oper_gline: GLINE '=' TBOOL ';'
1245 >  if (conf_parser_ctx.pass == 2)
1246 >    block_state.modes.value |= UMODE_LOCOPS;
1247 > } | T_NONONREG
1248 > {
1249 >  if (conf_parser_ctx.pass == 2)
1250 >    block_state.modes.value |= UMODE_REGONLY;
1251 > } | T_FARCONNECT
1252   {
1253 <  if (ypass == 2)
1254 <  {
1335 <    if (yylval.number)
1336 <      yy_aconf->port |= OPER_FLAG_GLINE;
1337 <    else
1338 <      yy_aconf->port &= ~OPER_FLAG_GLINE;
1339 <  }
1340 < };
1341 <
1342 < oper_nick_changes: NICK_CHANGES '=' TBOOL ';'
1343 < {
1344 <  if (ypass == 2)
1345 <  {
1346 <    if (yylval.number)
1347 <      yy_aconf->port |= OPER_FLAG_N;
1348 <    else
1349 <      yy_aconf->port &= ~OPER_FLAG_N;
1350 <  }
1351 < };
1352 <
1353 < oper_die: DIE '=' TBOOL ';'
1354 < {
1355 <  if (ypass == 2)
1356 <  {
1357 <    if (yylval.number)
1358 <      yy_aconf->port |= OPER_FLAG_DIE;
1359 <    else
1360 <      yy_aconf->port &= ~OPER_FLAG_DIE;
1361 <  }
1362 < };
1363 <
1364 < oper_rehash: REHASH '=' TBOOL ';'
1365 < {
1366 <  if (ypass == 2)
1367 <  {
1368 <    if (yylval.number)
1369 <      yy_aconf->port |= OPER_FLAG_REHASH;
1370 <    else
1371 <      yy_aconf->port &= ~OPER_FLAG_REHASH;
1372 <  }
1373 < };
1374 <
1375 < oper_admin: ADMIN '=' TBOOL ';'
1376 < {
1377 <  if (ypass == 2)
1378 <  {
1379 <    if (yylval.number)
1380 <      yy_aconf->port |= OPER_FLAG_ADMIN;
1381 <    else
1382 <      yy_aconf->port &= ~OPER_FLAG_ADMIN;
1383 <  }
1384 < };
1385 <
1386 < oper_hidden_admin: HIDDEN_ADMIN '=' TBOOL ';'
1387 < {
1388 <  if (ypass == 2)
1389 <  {
1390 <    if (yylval.number)
1391 <      yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1392 <    else
1393 <      yy_aconf->port &= ~OPER_FLAG_HIDDEN_ADMIN;
1394 <  }
1395 < };
1396 <
1397 < oper_hidden_oper: HIDDEN_OPER '=' TBOOL ';'
1398 < {
1399 <  if (ypass == 2)
1400 <  {
1401 <    if (yylval.number)
1402 <      yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1403 <    else
1404 <      yy_aconf->port &= ~OPER_FLAG_HIDDEN_OPER;
1405 <  }
1406 < };
1407 <
1408 < oper_operwall: T_OPERWALL '=' TBOOL ';'
1409 < {
1410 <  if (ypass == 2)
1411 <  {
1412 <    if (yylval.number)
1413 <      yy_aconf->port |= OPER_FLAG_OPERWALL;
1414 <    else
1415 <      yy_aconf->port &= ~OPER_FLAG_OPERWALL;
1416 <  }
1253 >  if (conf_parser_ctx.pass == 2)
1254 >    block_state.modes.value |= UMODE_FARCONNECT;
1255   };
1256  
1257   oper_flags: IRCD_FLAGS
1258   {
1259 +  if (conf_parser_ctx.pass == 2)
1260 +    block_state.port.value = 0;
1261   } '='  oper_flags_items ';';
1262  
1263   oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1264 < oper_flags_item: NOT { not_atom = 1; } oper_flags_item_atom
1425 <                | { not_atom = 0; } oper_flags_item_atom;
1426 <
1427 < oper_flags_item_atom: GLOBAL_KILL
1264 > oper_flags_item: KILL ':' REMOTE
1265   {
1266 <  if (ypass == 2)
1267 <  {
1268 <    if (not_atom)yy_aconf->port &= ~OPER_FLAG_GLOBAL_KILL;
1269 <    else yy_aconf->port |= OPER_FLAG_GLOBAL_KILL;
1270 <  }
1271 < } | REMOTE
1266 >  if (conf_parser_ctx.pass == 2)
1267 >    block_state.port.value |= OPER_FLAG_KILL_REMOTE;
1268 > } | KILL
1269 > {
1270 >  if (conf_parser_ctx.pass == 2)
1271 >    block_state.port.value |= OPER_FLAG_KILL;
1272 > } | CONNECT ':' REMOTE
1273 > {
1274 >  if (conf_parser_ctx.pass == 2)
1275 >    block_state.port.value |= OPER_FLAG_CONNECT_REMOTE;
1276 > } | CONNECT
1277 > {
1278 >  if (conf_parser_ctx.pass == 2)
1279 >    block_state.port.value |= OPER_FLAG_CONNECT;
1280 > } | SQUIT ':' REMOTE
1281 > {
1282 >  if (conf_parser_ctx.pass == 2)
1283 >    block_state.port.value |= OPER_FLAG_SQUIT_REMOTE;
1284 > } | SQUIT
1285   {
1286 <  if (ypass == 2)
1287 <  {
1438 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTE;
1439 <    else yy_aconf->port |= OPER_FLAG_REMOTE;
1440 <  }
1286 >  if (conf_parser_ctx.pass == 2)
1287 >    block_state.port.value |= OPER_FLAG_SQUIT;
1288   } | KLINE
1289   {
1290 <  if (ypass == 2)
1291 <  {
1445 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_K;
1446 <    else yy_aconf->port |= OPER_FLAG_K;
1447 <  }
1290 >  if (conf_parser_ctx.pass == 2)
1291 >    block_state.port.value |= OPER_FLAG_K;
1292   } | UNKLINE
1293   {
1294 <  if (ypass == 2)
1295 <  {
1296 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_UNKLINE;
1297 <    else yy_aconf->port |= OPER_FLAG_UNKLINE;
1298 <  }
1294 >  if (conf_parser_ctx.pass == 2)
1295 >    block_state.port.value |= OPER_FLAG_UNKLINE;
1296 > } | T_DLINE
1297 > {
1298 >  if (conf_parser_ctx.pass == 2)
1299 >    block_state.port.value |= OPER_FLAG_DLINE;
1300 > } | T_UNDLINE
1301 > {
1302 >  if (conf_parser_ctx.pass == 2)
1303 >    block_state.port.value |= OPER_FLAG_UNDLINE;
1304   } | XLINE
1305   {
1306 <  if (ypass == 2)
1307 <  {
1308 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_X;
1309 <    else yy_aconf->port |= OPER_FLAG_X;
1310 <  }
1306 >  if (conf_parser_ctx.pass == 2)
1307 >    block_state.port.value |= OPER_FLAG_XLINE;
1308 > } | T_UNXLINE
1309 > {
1310 >  if (conf_parser_ctx.pass == 2)
1311 >    block_state.port.value |= OPER_FLAG_UNXLINE;
1312   } | GLINE
1313   {
1314 <  if (ypass == 2)
1315 <  {
1466 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_GLINE;
1467 <    else yy_aconf->port |= OPER_FLAG_GLINE;
1468 <  }
1314 >  if (conf_parser_ctx.pass == 2)
1315 >    block_state.port.value |= OPER_FLAG_GLINE;
1316   } | DIE
1317   {
1318 <  if (ypass == 2)
1319 <  {
1320 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_DIE;
1321 <    else yy_aconf->port |= OPER_FLAG_DIE;
1322 <  }
1318 >  if (conf_parser_ctx.pass == 2)
1319 >    block_state.port.value |= OPER_FLAG_DIE;
1320 > } | T_RESTART
1321 > {
1322 >  if (conf_parser_ctx.pass == 2)
1323 >    block_state.port.value |= OPER_FLAG_RESTART;
1324   } | REHASH
1325   {
1326 <  if (ypass == 2)
1327 <  {
1480 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REHASH;
1481 <    else yy_aconf->port |= OPER_FLAG_REHASH;
1482 <  }
1326 >  if (conf_parser_ctx.pass == 2)
1327 >    block_state.port.value |= OPER_FLAG_REHASH;
1328   } | ADMIN
1329   {
1330 <  if (ypass == 2)
1331 <  {
1487 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_ADMIN;
1488 <    else yy_aconf->port |= OPER_FLAG_ADMIN;
1489 <  }
1490 < } | HIDDEN_ADMIN
1491 < {
1492 <  if (ypass == 2)
1493 <  {
1494 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_ADMIN;
1495 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_ADMIN;
1496 <  }
1497 < } | NICK_CHANGES
1498 < {
1499 <  if (ypass == 2)
1500 <  {
1501 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_N;
1502 <    else yy_aconf->port |= OPER_FLAG_N;
1503 <  }
1330 >  if (conf_parser_ctx.pass == 2)
1331 >    block_state.port.value |= OPER_FLAG_ADMIN;
1332   } | T_OPERWALL
1333   {
1334 <  if (ypass == 2)
1335 <  {
1336 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPERWALL;
1337 <    else yy_aconf->port |= OPER_FLAG_OPERWALL;
1338 <  }
1339 < } | OPER_SPY_T
1334 >  if (conf_parser_ctx.pass == 2)
1335 >    block_state.port.value |= OPER_FLAG_OPERWALL;
1336 > } | T_GLOBOPS
1337 > {
1338 >  if (conf_parser_ctx.pass == 2)
1339 >    block_state.port.value |= OPER_FLAG_GLOBOPS;
1340 > } | T_WALLOPS
1341   {
1342 <  if (ypass == 2)
1343 <  {
1344 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_OPER_SPY;
1516 <    else yy_aconf->port |= OPER_FLAG_OPER_SPY;
1517 <  }
1518 < } | HIDDEN_OPER
1342 >  if (conf_parser_ctx.pass == 2)
1343 >    block_state.port.value |= OPER_FLAG_WALLOPS;
1344 > } | T_LOCOPS
1345   {
1346 <  if (ypass == 2)
1347 <  {
1522 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_HIDDEN_OPER;
1523 <    else yy_aconf->port |= OPER_FLAG_HIDDEN_OPER;
1524 <  }
1346 >  if (conf_parser_ctx.pass == 2)
1347 >    block_state.port.value |= OPER_FLAG_LOCOPS;
1348   } | REMOTEBAN
1349   {
1350 <  if (ypass == 2)
1351 <  {
1352 <    if (not_atom) yy_aconf->port &= ~OPER_FLAG_REMOTEBAN;
1353 <    else yy_aconf->port |= OPER_FLAG_REMOTEBAN;
1354 <  }
1355 < } | ENCRYPTED
1350 >  if (conf_parser_ctx.pass == 2)
1351 >    block_state.port.value |= OPER_FLAG_REMOTEBAN;
1352 > } | T_SET
1353 > {
1354 >  if (conf_parser_ctx.pass == 2)
1355 >    block_state.port.value |= OPER_FLAG_SET;
1356 > } | MODULE
1357   {
1358 <  if (ypass == 2)
1359 <  {
1536 <    if (not_atom) ClearConfEncrypted(yy_aconf);
1537 <    else SetConfEncrypted(yy_aconf);
1538 <  }
1358 >  if (conf_parser_ctx.pass == 2)
1359 >    block_state.port.value |= OPER_FLAG_MODULE;
1360   };
1361  
1362  
# Line 1544 | Line 1365 | oper_flags_item_atom: GLOBAL_KILL
1365   ***************************************************************************/
1366   class_entry: CLASS
1367   {
1368 <  if (ypass == 1)
1369 <  {
1549 <    yy_conf = make_conf_item(CLASS_TYPE);
1550 <    yy_class = (struct ClassItem *)map_to_conf(yy_conf);
1551 <  }
1552 < } class_name_b '{' class_items '}' ';'
1553 < {
1554 <  if (ypass == 1)
1555 <  {
1556 <    struct ConfItem *cconf;
1557 <    struct ClassItem *class = NULL;
1558 <
1559 <    if (yy_class_name == NULL)
1560 <    {
1561 <      delete_conf_item(yy_conf);
1562 <    }
1563 <    else
1564 <    {
1565 <      cconf = find_exact_name_conf(CLASS_TYPE, yy_class_name, NULL, NULL);
1368 >  if (conf_parser_ctx.pass != 1)
1369 >    break;
1370  
1371 <      if (cconf != NULL)                /* The class existed already */
1568 <      {
1569 <        rebuild_cidr_class(cconf, yy_class);
1570 <        class = (struct ClassItem *) map_to_conf(cconf);
1571 <        *class = *yy_class;
1572 <        delete_conf_item(yy_conf);
1371 >  reset_block_state();
1372  
1373 <        MyFree(cconf->name);            /* Allows case change of class name */
1374 <        cconf->name = yy_class_name;
1375 <      }
1376 <      else      /* Brand new class */
1377 <      {
1378 <        MyFree(yy_conf->name);          /* just in case it was allocated */
1379 <        yy_conf->name = yy_class_name;
1380 <      }
1381 <    }
1382 <    yy_class_name = NULL;
1383 <  }
1373 >  block_state.ping_freq.value = DEFAULT_PINGFREQUENCY;
1374 >  block_state.con_freq.value  = DEFAULT_CONNECTFREQUENCY;
1375 >  block_state.max_total.value = MAXIMUM_LINKS_DEFAULT;
1376 >  block_state.max_sendq.value = DEFAULT_SENDQ;
1377 >  block_state.max_recvq.value = DEFAULT_RECVQ;
1378 > } '{' class_items '}' ';'
1379 > {
1380 >  struct ClassItem *class = NULL;
1381 >
1382 >  if (conf_parser_ctx.pass != 1)
1383 >    break;
1384 >
1385 >  if (!block_state.class.buf[0])
1386 >    break;
1387 >
1388 >  if (!(class = class_find(block_state.class.buf, 0)))
1389 >    class = class_make();
1390 >
1391 >  class->active = 1;
1392 >  MyFree(class->name);
1393 >  class->name = xstrdup(block_state.class.buf);
1394 >  class->ping_freq = block_state.ping_freq.value;
1395 >  class->max_perip = block_state.max_perip.value;
1396 >  class->con_freq = block_state.con_freq.value;
1397 >  class->max_total = block_state.max_total.value;
1398 >  class->max_global = block_state.max_global.value;
1399 >  class->max_local = block_state.max_local.value;
1400 >  class->max_ident = block_state.max_ident.value;
1401 >  class->max_sendq = block_state.max_sendq.value;
1402 >  class->max_recvq = block_state.max_recvq.value;
1403 >
1404 >  if (block_state.min_idle.value > block_state.max_idle.value)
1405 >  {
1406 >    block_state.min_idle.value = 0;
1407 >    block_state.max_idle.value = 0;
1408 >    block_state.flags.value &= ~CLASS_FLAGS_FAKE_IDLE;
1409 >  }
1410 >
1411 >  class->flags = block_state.flags.value;
1412 >  class->min_idle = block_state.min_idle.value;
1413 >  class->max_idle = block_state.max_idle.value;
1414 >
1415 >  if (class->number_per_cidr && block_state.number_per_cidr.value)
1416 >    if ((class->cidr_bitlen_ipv4 && block_state.cidr_bitlen_ipv4.value) ||
1417 >        (class->cidr_bitlen_ipv6 && block_state.cidr_bitlen_ipv6.value))
1418 >      if ((class->cidr_bitlen_ipv4 != block_state.cidr_bitlen_ipv4.value) ||
1419 >          (class->cidr_bitlen_ipv6 != block_state.cidr_bitlen_ipv6.value))
1420 >        rebuild_cidr_list(class);
1421 >
1422 >  class->cidr_bitlen_ipv4 = block_state.cidr_bitlen_ipv4.value;
1423 >  class->cidr_bitlen_ipv6 = block_state.cidr_bitlen_ipv6.value;
1424 >  class->number_per_cidr = block_state.number_per_cidr.value;
1425   };
1426  
1587 class_name_b: | class_name_t;
1588
1427   class_items:    class_items class_item | class_item;
1428   class_item:     class_name |
1429                  class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1430                  class_ping_time |
1593                class_ping_warning |
1431                  class_number_per_cidr |
1432                  class_number_per_ip |
1433                  class_connectfreq |
# Line 1598 | Line 1435 | class_item:     class_name |
1435                  class_max_global |
1436                  class_max_local |
1437                  class_max_ident |
1438 <                class_sendq |
1438 >                class_sendq | class_recvq |
1439 >                class_min_idle |
1440 >                class_max_idle |
1441 >                class_flags |
1442                  error ';' ;
1443  
1444 < class_name: NAME '=' QSTRING ';'
1444 > class_name: NAME '=' QSTRING ';'
1445   {
1446 <  if (ypass == 1)
1447 <  {
1608 <    MyFree(yy_class_name);
1609 <    DupString(yy_class_name, yylval.string);
1610 <  }
1611 < };
1612 <
1613 < class_name_t: QSTRING
1614 < {
1615 <  if (ypass == 1)
1616 <  {
1617 <    MyFree(yy_class_name);
1618 <    DupString(yy_class_name, yylval.string);
1619 <  }
1446 >  if (conf_parser_ctx.pass == 1)
1447 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1448   };
1449  
1450   class_ping_time: PING_TIME '=' timespec ';'
1451   {
1452 <  if (ypass == 1)
1453 <    PingFreq(yy_class) = $3;
1626 < };
1627 <
1628 < class_ping_warning: PING_WARNING '=' timespec ';'
1629 < {
1630 <  if (ypass == 1)
1631 <    PingWarning(yy_class) = $3;
1452 >  if (conf_parser_ctx.pass == 1)
1453 >    block_state.ping_freq.value = $3;
1454   };
1455  
1456   class_number_per_ip: NUMBER_PER_IP '=' NUMBER ';'
1457   {
1458 <  if (ypass == 1)
1459 <    MaxPerIp(yy_class) = $3;
1458 >  if (conf_parser_ctx.pass == 1)
1459 >    block_state.max_perip.value = $3;
1460   };
1461  
1462   class_connectfreq: CONNECTFREQ '=' timespec ';'
1463   {
1464 <  if (ypass == 1)
1465 <    ConFreq(yy_class) = $3;
1464 >  if (conf_parser_ctx.pass == 1)
1465 >    block_state.con_freq.value = $3;
1466   };
1467  
1468   class_max_number: MAX_NUMBER '=' NUMBER ';'
1469   {
1470 <  if (ypass == 1)
1471 <    MaxTotal(yy_class) = $3;
1470 >  if (conf_parser_ctx.pass == 1)
1471 >    block_state.max_total.value = $3;
1472   };
1473  
1474   class_max_global: MAX_GLOBAL '=' NUMBER ';'
1475   {
1476 <  if (ypass == 1)
1477 <    MaxGlobal(yy_class) = $3;
1476 >  if (conf_parser_ctx.pass == 1)
1477 >    block_state.max_global.value = $3;
1478   };
1479  
1480   class_max_local: MAX_LOCAL '=' NUMBER ';'
1481   {
1482 <  if (ypass == 1)
1483 <    MaxLocal(yy_class) = $3;
1482 >  if (conf_parser_ctx.pass == 1)
1483 >    block_state.max_local.value = $3;
1484   };
1485  
1486   class_max_ident: MAX_IDENT '=' NUMBER ';'
1487   {
1488 <  if (ypass == 1)
1489 <    MaxIdent(yy_class) = $3;
1488 >  if (conf_parser_ctx.pass == 1)
1489 >    block_state.max_ident.value = $3;
1490   };
1491  
1492   class_sendq: SENDQ '=' sizespec ';'
1493   {
1494 <  if (ypass == 1)
1495 <    MaxSendq(yy_class) = $3;
1494 >  if (conf_parser_ctx.pass == 1)
1495 >    block_state.max_sendq.value = $3;
1496 > };
1497 >
1498 > class_recvq: T_RECVQ '=' sizespec ';'
1499 > {
1500 >  if (conf_parser_ctx.pass == 1)
1501 >    if ($3 >= CLIENT_FLOOD_MIN && $3 <= CLIENT_FLOOD_MAX)
1502 >      block_state.max_recvq.value = $3;
1503   };
1504  
1505   class_cidr_bitlen_ipv4: CIDR_BITLEN_IPV4 '=' NUMBER ';'
1506   {
1507 <  if (ypass == 1)
1508 <    CidrBitlenIPV4(yy_class) = $3;
1507 >  if (conf_parser_ctx.pass == 1)
1508 >    block_state.cidr_bitlen_ipv4.value = $3 > 32 ? 32 : $3;
1509   };
1510  
1511   class_cidr_bitlen_ipv6: CIDR_BITLEN_IPV6 '=' NUMBER ';'
1512   {
1513 <  if (ypass == 1)
1514 <    CidrBitlenIPV6(yy_class) = $3;
1513 >  if (conf_parser_ctx.pass == 1)
1514 >    block_state.cidr_bitlen_ipv6.value = $3 > 128 ? 128 : $3;
1515   };
1516  
1517   class_number_per_cidr: NUMBER_PER_CIDR '=' NUMBER ';'
1518   {
1519 <  if (ypass == 1)
1520 <    NumberPerCidr(yy_class) = $3;
1519 >  if (conf_parser_ctx.pass == 1)
1520 >    block_state.number_per_cidr.value = $3;
1521 > };
1522 >
1523 > class_min_idle: MIN_IDLE '=' timespec ';'
1524 > {
1525 >  if (conf_parser_ctx.pass != 1)
1526 >    break;
1527 >
1528 >  block_state.min_idle.value = $3;
1529 >  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1530   };
1531  
1532 + class_max_idle: MAX_IDLE '=' timespec ';'
1533 + {
1534 +  if (conf_parser_ctx.pass != 1)
1535 +    break;
1536 +
1537 +  block_state.max_idle.value = $3;
1538 +  block_state.flags.value |= CLASS_FLAGS_FAKE_IDLE;
1539 + };
1540 +
1541 + class_flags: IRCD_FLAGS
1542 + {
1543 +  if (conf_parser_ctx.pass == 1)
1544 +    block_state.flags.value &= CLASS_FLAGS_FAKE_IDLE;
1545 + } '='  class_flags_items ';';
1546 +
1547 + class_flags_items: class_flags_items ',' class_flags_item | class_flags_item;
1548 + class_flags_item: RANDOM_IDLE
1549 + {
1550 +  if (conf_parser_ctx.pass == 1)
1551 +    block_state.flags.value |= CLASS_FLAGS_RANDOM_IDLE;
1552 + } | HIDE_IDLE_FROM_OPERS
1553 + {
1554 +  if (conf_parser_ctx.pass == 1)
1555 +    block_state.flags.value |= CLASS_FLAGS_HIDE_IDLE_FROM_OPERS;
1556 + };
1557 +
1558 +
1559   /***************************************************************************
1560   *  section listen
1561   ***************************************************************************/
1562   listen_entry: LISTEN
1563   {
1564 <  if (ypass == 2)
1565 <  {
1566 <    listener_address = NULL;
1702 <    listener_flags = 0;
1703 <  }
1704 < } '{' listen_items '}' ';'
1705 < {
1706 <  if (ypass == 2)
1707 <  {
1708 <    MyFree(listener_address);
1709 <    listener_address = NULL;
1710 <  }
1711 < };
1564 >  if (conf_parser_ctx.pass == 2)
1565 >    reset_block_state();
1566 > } '{' listen_items '}' ';';
1567  
1568   listen_flags: IRCD_FLAGS
1569   {
1570 <  listener_flags = 0;
1570 >  block_state.flags.value = 0;
1571   } '='  listen_flags_items ';';
1572  
1573   listen_flags_items: listen_flags_items ',' listen_flags_item | listen_flags_item;
1574   listen_flags_item: T_SSL
1575   {
1576 <  if (ypass == 2)
1577 <    listener_flags |= LISTENER_SSL;
1576 >  if (conf_parser_ctx.pass == 2)
1577 >    block_state.flags.value |= LISTENER_SSL;
1578   } | HIDDEN
1579   {
1580 <  if (ypass == 2)
1581 <    listener_flags |= LISTENER_HIDDEN;
1580 >  if (conf_parser_ctx.pass == 2)
1581 >    block_state.flags.value |= LISTENER_HIDDEN;
1582 > } | T_SERVER
1583 > {
1584 >  if (conf_parser_ctx.pass == 2)
1585 >   block_state.flags.value |= LISTENER_SERVER;
1586   };
1587  
1588   listen_items:   listen_items listen_item | listen_item;
1589   listen_item:    listen_port | listen_flags | listen_address | listen_host | error ';';
1590  
1591 < listen_port: PORT '=' port_items { listener_flags = 0; } ';';
1591 > listen_port: PORT '=' port_items { block_state.flags.value = 0; } ';';
1592  
1593   port_items: port_items ',' port_item | port_item;
1594  
1595   port_item: NUMBER
1596   {
1597 <  if (ypass == 2)
1597 >  if (conf_parser_ctx.pass == 2)
1598    {
1599 <    if ((listener_flags & LISTENER_SSL))
1599 >    if (block_state.flags.value & LISTENER_SSL)
1600   #ifdef HAVE_LIBCRYPTO
1601 <      if (!ServerInfo.ctx)
1601 >      if (!ServerInfo.server_ctx)
1602   #endif
1603        {
1604 <        yyerror("SSL not available - port closed");
1604 >        conf_error_report("SSL not available - port closed");
1605          break;
1606        }
1607 <    add_listener($1, listener_address, listener_flags);
1607 >    add_listener($1, block_state.addr.buf, block_state.flags.value);
1608    }
1609   } | NUMBER TWODOTS NUMBER
1610   {
1611 <  if (ypass == 2)
1611 >  if (conf_parser_ctx.pass == 2)
1612    {
1613      int i;
1614  
1615 <    if ((listener_flags & LISTENER_SSL))
1615 >    if (block_state.flags.value & LISTENER_SSL)
1616   #ifdef HAVE_LIBCRYPTO
1617 <      if (!ServerInfo.ctx)
1617 >      if (!ServerInfo.server_ctx)
1618   #endif
1619        {
1620 <        yyerror("SSL not available - port closed");
1620 >        conf_error_report("SSL not available - port closed");
1621          break;
1622        }
1623  
1624      for (i = $1; i <= $3; ++i)
1625 <      add_listener(i, listener_address, listener_flags);
1625 >      add_listener(i, block_state.addr.buf, block_state.flags.value);
1626    }
1627   };
1628  
1629   listen_address: IP '=' QSTRING ';'
1630   {
1631 <  if (ypass == 2)
1632 <  {
1774 <    MyFree(listener_address);
1775 <    DupString(listener_address, yylval.string);
1776 <  }
1631 >  if (conf_parser_ctx.pass == 2)
1632 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1633   };
1634  
1635   listen_host: HOST '=' QSTRING ';'
1636   {
1637 <  if (ypass == 2)
1638 <  {
1783 <    MyFree(listener_address);
1784 <    DupString(listener_address, yylval.string);
1785 <  }
1637 >  if (conf_parser_ctx.pass == 2)
1638 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
1639   };
1640  
1641   /***************************************************************************
# Line 1790 | Line 1643 | listen_host: HOST '=' QSTRING ';'
1643   ***************************************************************************/
1644   auth_entry: IRCD_AUTH
1645   {
1646 <  if (ypass == 2)
1647 <  {
1795 <    yy_conf = make_conf_item(CLIENT_TYPE);
1796 <    yy_aconf = map_to_conf(yy_conf);
1797 <  }
1798 <  else
1799 <  {
1800 <    MyFree(class_name);
1801 <    class_name = NULL;
1802 <  }
1646 >  if (conf_parser_ctx.pass == 2)
1647 >    reset_block_state();
1648   } '{' auth_items '}' ';'
1649   {
1650 <  if (ypass == 2)
1806 <  {
1807 <    struct CollectItem *yy_tmp = NULL;
1808 <    dlink_node *ptr = NULL, *next_ptr = NULL;
1809 <
1810 <    if (yy_aconf->user && yy_aconf->host)
1811 <    {
1812 <      conf_add_class_to_conf(yy_conf, class_name);
1813 <      add_conf_by_address(CONF_CLIENT, yy_aconf);
1814 <    }
1815 <    else
1816 <      delete_conf_item(yy_conf);
1817 <
1818 <    /* copy over settings from first struct */
1819 <    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
1820 <    {
1821 <      struct AccessItem *new_aconf;
1822 <      struct ConfItem *new_conf;
1823 <
1824 <      new_conf = make_conf_item(CLIENT_TYPE);
1825 <      new_aconf = map_to_conf(new_conf);
1650 >  dlink_node *ptr = NULL;
1651  
1652 <      yy_tmp = ptr->data;
1652 >  if (conf_parser_ctx.pass != 2)
1653 >    break;
1654  
1655 <      assert(yy_tmp->user && yy_tmp->host);
1830 <
1831 <      if (yy_aconf->passwd != NULL)
1832 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1833 <      if (yy_conf->name != NULL)
1834 <        DupString(new_conf->name, yy_conf->name);
1835 <      if (yy_aconf->passwd != NULL)
1836 <        DupString(new_aconf->passwd, yy_aconf->passwd);
1837 <
1838 <      new_aconf->flags = yy_aconf->flags;
1839 <      new_aconf->port  = yy_aconf->port;
1840 <
1841 <      DupString(new_aconf->user, yy_tmp->user);
1842 <      collapse(new_aconf->user);
1843 <
1844 <      DupString(new_aconf->host, yy_tmp->host);
1845 <      collapse(new_aconf->host);
1846 <
1847 <      conf_add_class_to_conf(new_conf, class_name);
1848 <      add_conf_by_address(CONF_CLIENT, new_aconf);
1849 <      dlinkDelete(&yy_tmp->node, &col_conf_list);
1850 <      free_collect_item(yy_tmp);
1851 <    }
1852 <
1853 <    MyFree(class_name);
1854 <    class_name = NULL;
1855 <    yy_conf = NULL;
1856 <    yy_aconf = NULL;
1857 <  }
1858 < };
1859 <
1860 < auth_items:     auth_items auth_item | auth_item;
1861 < auth_item:      auth_user | auth_passwd | auth_class | auth_flags |
1862 <                auth_kline_exempt | auth_need_ident |
1863 <                auth_exceed_limit | auth_no_tilde | auth_gline_exempt |
1864 <                auth_spoof | auth_spoof_notice |
1865 <                auth_redir_serv | auth_redir_port | auth_can_flood |
1866 <                auth_need_password | auth_encrypted | error ';' ;
1867 <
1868 < auth_user: USER '=' QSTRING ';'
1869 < {
1870 <  if (ypass == 2)
1655 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
1656    {
1657 <    struct CollectItem *yy_tmp = NULL;
1657 >    struct MaskItem *conf = NULL;
1658      struct split_nuh_item nuh;
1659  
1660 <    nuh.nuhmask  = yylval.string;
1660 >    nuh.nuhmask  = ptr->data;
1661      nuh.nickptr  = NULL;
1662 <    nuh.userptr  = userbuf;
1663 <    nuh.hostptr  = hostbuf;
1879 <
1662 >    nuh.userptr  = block_state.user.buf;
1663 >    nuh.hostptr  = block_state.host.buf;
1664      nuh.nicksize = 0;
1665 <    nuh.usersize = sizeof(userbuf);
1666 <    nuh.hostsize = sizeof(hostbuf);
1883 <
1665 >    nuh.usersize = sizeof(block_state.user.buf);
1666 >    nuh.hostsize = sizeof(block_state.host.buf);
1667      split_nuh(&nuh);
1668  
1669 <    if (yy_aconf->user == NULL)
1670 <    {
1671 <      DupString(yy_aconf->user, userbuf);
1672 <      DupString(yy_aconf->host, hostbuf);
1673 <    }
1674 <    else
1675 <    {
1676 <      yy_tmp = MyMalloc(sizeof(struct CollectItem));
1669 >    conf        = conf_make(CONF_CLIENT);
1670 >    conf->user  = xstrdup(block_state.user.buf);
1671 >    conf->host  = xstrdup(block_state.host.buf);
1672 >
1673 >    if (block_state.rpass.buf[0])
1674 >      conf->passwd = xstrdup(block_state.rpass.buf);
1675 >    if (block_state.name.buf[0])
1676 >      conf->name = xstrdup(block_state.name.buf);
1677  
1678 <      DupString(yy_tmp->user, userbuf);
1679 <      DupString(yy_tmp->host, hostbuf);
1678 >    conf->flags = block_state.flags.value;
1679 >    conf->port  = block_state.port.value;
1680  
1681 <      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
1682 <    }
1681 >    conf_add_class_to_conf(conf, block_state.class.buf);
1682 >    add_conf_by_address(CONF_CLIENT, conf);
1683    }
1684   };
1685  
1686 < /* XXX - IP/IPV6 tags don't exist anymore - put IP/IPV6 into user. */
1686 > auth_items:     auth_items auth_item | auth_item;
1687 > auth_item:      auth_user | auth_passwd | auth_class | auth_flags |
1688 >                auth_spoof | auth_redir_serv | auth_redir_port |
1689 >                auth_encrypted | error ';' ;
1690  
1691 < auth_passwd: PASSWORD '=' QSTRING ';'
1691 > auth_user: USER '=' QSTRING ';'
1692   {
1693 <  if (ypass == 2)
1694 <  {
1909 <    /* be paranoid */
1910 <    if (yy_aconf->passwd != NULL)
1911 <      memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
1912 <
1913 <    MyFree(yy_aconf->passwd);
1914 <    DupString(yy_aconf->passwd, yylval.string);
1915 <  }
1693 >  if (conf_parser_ctx.pass == 2)
1694 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1695   };
1696  
1697 < auth_spoof_notice: SPOOF_NOTICE '=' TBOOL ';'
1697 > auth_passwd: PASSWORD '=' QSTRING ';'
1698   {
1699 <  if (ypass == 2)
1700 <  {
1922 <    if (yylval.number)
1923 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1924 <    else
1925 <      yy_aconf->flags &= ~CONF_FLAGS_SPOOF_NOTICE;
1926 <  }
1699 >  if (conf_parser_ctx.pass == 2)
1700 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1701   };
1702  
1703   auth_class: CLASS '=' QSTRING ';'
1704   {
1705 <  if (ypass == 2)
1706 <  {
1933 <    MyFree(class_name);
1934 <    DupString(class_name, yylval.string);
1935 <  }
1705 >  if (conf_parser_ctx.pass == 2)
1706 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
1707   };
1708  
1709   auth_encrypted: ENCRYPTED '=' TBOOL ';'
1710   {
1711 <  if (ypass == 2)
1711 >  if (conf_parser_ctx.pass == 2)
1712    {
1713      if (yylval.number)
1714 <      SetConfEncrypted(yy_aconf);
1714 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1715      else
1716 <      ClearConfEncrypted(yy_aconf);
1716 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1717    }
1718   };
1719  
1720   auth_flags: IRCD_FLAGS
1721   {
1722 +  if (conf_parser_ctx.pass == 2)
1723 +    block_state.flags.value &= (CONF_FLAGS_ENCRYPTED | CONF_FLAGS_SPOOF_IP);
1724   } '='  auth_flags_items ';';
1725  
1726   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
1727 < auth_flags_item: NOT { not_atom = 1; } auth_flags_item_atom
1955 <                | { not_atom = 0; } auth_flags_item_atom;
1956 <
1957 < auth_flags_item_atom: SPOOF_NOTICE
1727 > auth_flags_item: SPOOF_NOTICE
1728   {
1729 <  if (ypass == 2)
1730 <  {
1961 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_SPOOF_NOTICE;
1962 <    else yy_aconf->flags |= CONF_FLAGS_SPOOF_NOTICE;
1963 <  }
1964 <
1729 >  if (conf_parser_ctx.pass == 2)
1730 >    block_state.flags.value |= CONF_FLAGS_SPOOF_NOTICE;
1731   } | EXCEED_LIMIT
1732   {
1733 <  if (ypass == 2)
1734 <  {
1969 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NOLIMIT;
1970 <    else yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
1971 <  }
1733 >  if (conf_parser_ctx.pass == 2)
1734 >    block_state.flags.value |= CONF_FLAGS_NOLIMIT;
1735   } | KLINE_EXEMPT
1736   {
1737 <  if (ypass == 2)
1738 <  {
1976 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTKLINE;
1977 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
1978 <  }
1737 >  if (conf_parser_ctx.pass == 2)
1738 >    block_state.flags.value |= CONF_FLAGS_EXEMPTKLINE;
1739   } | NEED_IDENT
1740   {
1741 <  if (ypass == 2)
1742 <  {
1983 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_IDENTD;
1984 <    else yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
1985 <  }
1741 >  if (conf_parser_ctx.pass == 2)
1742 >    block_state.flags.value |= CONF_FLAGS_NEED_IDENTD;
1743   } | CAN_FLOOD
1744   {
1745 <  if (ypass == 2)
1746 <  {
1990 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_CAN_FLOOD;
1991 <    else yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
1992 <  }
1993 < } | CAN_IDLE
1994 < {
1995 <  if (ypass == 2)
1996 <  {
1997 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_IDLE_LINED;
1998 <    else yy_aconf->flags |= CONF_FLAGS_IDLE_LINED;
1999 <  }
1745 >  if (conf_parser_ctx.pass == 2)
1746 >    block_state.flags.value |= CONF_FLAGS_CAN_FLOOD;
1747   } | NO_TILDE
1748   {
1749 <  if (ypass == 2)
1750 <  {
2004 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NO_TILDE;
2005 <    else yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
2006 <  }
1749 >  if (conf_parser_ctx.pass == 2)
1750 >    block_state.flags.value |= CONF_FLAGS_NO_TILDE;
1751   } | GLINE_EXEMPT
1752   {
1753 <  if (ypass == 2)
1754 <  {
2011 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTGLINE;
2012 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
2013 <  }
1753 >  if (conf_parser_ctx.pass == 2)
1754 >    block_state.flags.value |= CONF_FLAGS_EXEMPTGLINE;
1755   } | RESV_EXEMPT
1756   {
1757 <  if (ypass == 2)
1758 <  {
1759 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_EXEMPTRESV;
2019 <    else yy_aconf->flags |= CONF_FLAGS_EXEMPTRESV;
2020 <  }
2021 < } | NEED_PASSWORD
2022 < {
2023 <  if (ypass == 2)
2024 <  {
2025 <    if (not_atom) yy_aconf->flags &= ~CONF_FLAGS_NEED_PASSWORD;
2026 <    else yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
2027 <  }
2028 < };
2029 <
2030 < auth_kline_exempt: KLINE_EXEMPT '=' TBOOL ';'
2031 < {
2032 <  if (ypass == 2)
2033 <  {
2034 <    if (yylval.number)
2035 <      yy_aconf->flags |= CONF_FLAGS_EXEMPTKLINE;
2036 <    else
2037 <      yy_aconf->flags &= ~CONF_FLAGS_EXEMPTKLINE;
2038 <  }
2039 < };
2040 <
2041 < auth_need_ident: NEED_IDENT '=' TBOOL ';'
1757 >  if (conf_parser_ctx.pass == 2)
1758 >    block_state.flags.value |= CONF_FLAGS_EXEMPTRESV;
1759 > } | T_WEBIRC
1760   {
1761 <  if (ypass == 2)
1762 <  {
1763 <    if (yylval.number)
2046 <      yy_aconf->flags |= CONF_FLAGS_NEED_IDENTD;
2047 <    else
2048 <      yy_aconf->flags &= ~CONF_FLAGS_NEED_IDENTD;
2049 <  }
2050 < };
2051 <
2052 < auth_exceed_limit: EXCEED_LIMIT '=' TBOOL ';'
2053 < {
2054 <  if (ypass == 2)
2055 <  {
2056 <    if (yylval.number)
2057 <      yy_aconf->flags |= CONF_FLAGS_NOLIMIT;
2058 <    else
2059 <      yy_aconf->flags &= ~CONF_FLAGS_NOLIMIT;
2060 <  }
2061 < };
2062 <
2063 < auth_can_flood: CAN_FLOOD '=' TBOOL ';'
2064 < {
2065 <  if (ypass == 2)
2066 <  {
2067 <    if (yylval.number)
2068 <      yy_aconf->flags |= CONF_FLAGS_CAN_FLOOD;
2069 <    else
2070 <      yy_aconf->flags &= ~CONF_FLAGS_CAN_FLOOD;
2071 <  }
2072 < };
2073 <
2074 < auth_no_tilde: NO_TILDE '=' TBOOL ';'
1761 >  if (conf_parser_ctx.pass == 2)
1762 >    block_state.flags.value |= CONF_FLAGS_WEBIRC;
1763 > } | NEED_PASSWORD
1764   {
1765 <  if (ypass == 2)
1766 <  {
2078 <    if (yylval.number)
2079 <      yy_aconf->flags |= CONF_FLAGS_NO_TILDE;
2080 <    else
2081 <      yy_aconf->flags &= ~CONF_FLAGS_NO_TILDE;
2082 <  }
1765 >  if (conf_parser_ctx.pass == 2)
1766 >    block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1767   };
1768  
1769 < auth_gline_exempt: GLINE_EXEMPT '=' TBOOL ';'
1769 > auth_spoof: SPOOF '=' QSTRING ';'
1770   {
1771 <  if (ypass == 2)
1772 <  {
2089 <    if (yylval.number)
2090 <      yy_aconf->flags |= CONF_FLAGS_EXEMPTGLINE;
2091 <    else
2092 <      yy_aconf->flags &= ~CONF_FLAGS_EXEMPTGLINE;
2093 <  }
2094 < };
1771 >  if (conf_parser_ctx.pass != 2)
1772 >    break;
1773  
1774 < /* XXX - need check for illegal hostnames here */
2097 < auth_spoof: SPOOF '=' QSTRING ';'
2098 < {
2099 <  if (ypass == 2)
1774 >  if (strlen(yylval.string) <= HOSTLEN && valid_hostname(yylval.string))
1775    {
1776 <    MyFree(yy_conf->name);
1777 <
2103 <    if (strlen(yylval.string) < HOSTLEN)
2104 <    {    
2105 <      DupString(yy_conf->name, yylval.string);
2106 <      yy_aconf->flags |= CONF_FLAGS_SPOOF_IP;
2107 <    }
2108 <    else
2109 <    {
2110 <      ilog(L_ERROR, "Spoofs must be less than %d..ignoring it", HOSTLEN);
2111 <      yy_conf->name = NULL;
2112 <    }
1776 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1777 >    block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
1778    }
1779 +  else
1780 +    ilog(LOG_TYPE_IRCD, "Spoof either is too long or contains invalid characters. Ignoring it.");
1781   };
1782  
1783   auth_redir_serv: REDIRSERV '=' QSTRING ';'
1784   {
1785 <  if (ypass == 2)
1786 <  {
1787 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
1788 <    MyFree(yy_conf->name);
1789 <    DupString(yy_conf->name, yylval.string);
2123 <  }
1785 >  if (conf_parser_ctx.pass != 2)
1786 >    break;
1787 >
1788 >  strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1789 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1790   };
1791  
1792   auth_redir_port: REDIRPORT '=' NUMBER ';'
1793   {
1794 <  if (ypass == 2)
1795 <  {
2130 <    yy_aconf->flags |= CONF_FLAGS_REDIR;
2131 <    yy_aconf->port = $3;
2132 <  }
2133 < };
1794 >  if (conf_parser_ctx.pass != 2)
1795 >    break;
1796  
1797 < auth_need_password: NEED_PASSWORD '=' TBOOL ';'
1798 < {
2137 <  if (ypass == 2)
2138 <  {
2139 <    if (yylval.number)
2140 <      yy_aconf->flags |= CONF_FLAGS_NEED_PASSWORD;
2141 <    else
2142 <      yy_aconf->flags &= ~CONF_FLAGS_NEED_PASSWORD;
2143 <  }
1797 >  block_state.flags.value |= CONF_FLAGS_REDIR;
1798 >  block_state.port.value = $3;
1799   };
1800  
1801  
# Line 2149 | Line 1804 | auth_need_password: NEED_PASSWORD '=' TB
1804   ***************************************************************************/
1805   resv_entry: RESV
1806   {
1807 <  if (ypass == 2)
1808 <  {
1809 <    MyFree(resv_reason);
1810 <    resv_reason = NULL;
1811 <  }
1807 >  if (conf_parser_ctx.pass != 2)
1808 >    break;
1809 >
1810 >  reset_block_state();
1811 >  strlcpy(block_state.rpass.buf, CONF_NOREASON, sizeof(block_state.rpass.buf));
1812   } '{' resv_items '}' ';'
1813   {
1814 <  if (ypass == 2)
1815 <  {
1816 <    MyFree(resv_reason);
1817 <    resv_reason = NULL;
2163 <  }
1814 >  if (conf_parser_ctx.pass != 2)
1815 >    break;
1816 >
1817 >  create_resv(block_state.name.buf, block_state.rpass.buf, &block_state.mask.list);
1818   };
1819  
1820   resv_items:     resv_items resv_item | resv_item;
1821 < resv_item:      resv_creason | resv_channel | resv_nick | error ';' ;
1821 > resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1822  
1823 < resv_creason: REASON '=' QSTRING ';'
1823 > resv_mask: MASK '=' QSTRING ';'
1824   {
1825 <  if (ypass == 2)
1826 <  {
2173 <    MyFree(resv_reason);
2174 <    DupString(resv_reason, yylval.string);
2175 <  }
1825 >  if (conf_parser_ctx.pass == 2)
1826 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1827   };
1828  
1829 < resv_channel: CHANNEL '=' QSTRING ';'
1829 > resv_reason: REASON '=' QSTRING ';'
1830   {
1831 <  if (ypass == 2)
1832 <  {
1833 <    if (IsChanPrefix(*yylval.string))
2183 <    {
2184 <      char def_reason[] = "No reason";
1831 >  if (conf_parser_ctx.pass == 2)
1832 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
1833 > };
1834  
1835 <      create_channel_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1836 <    }
1837 <  }
1838 <  /* ignore it for now.. but we really should make a warning if
2190 <   * its an erroneous name --fl_ */
1835 > resv_exempt: EXEMPT '=' QSTRING ';'
1836 > {
1837 >  if (conf_parser_ctx.pass == 2)
1838 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
1839   };
1840  
1841 < resv_nick: NICK '=' QSTRING ';'
1841 >
1842 > /***************************************************************************
1843 > *  section service
1844 > ***************************************************************************/
1845 > service_entry: T_SERVICE '{' service_items '}' ';';
1846 >
1847 > service_items:     service_items service_item | service_item;
1848 > service_item:      service_name | error;
1849 >
1850 > service_name: NAME '=' QSTRING ';'
1851   {
1852 <  if (ypass == 2)
1853 <  {
2197 <    char def_reason[] = "No reason";
1852 >  if (conf_parser_ctx.pass != 2)
1853 >    break;
1854  
1855 <    create_nick_resv(yylval.string, resv_reason != NULL ? resv_reason : def_reason, 1);
1855 >  if (valid_servname(yylval.string))
1856 >  {
1857 >    struct MaskItem *conf = conf_make(CONF_SERVICE);
1858 >    conf->name = xstrdup(yylval.string);
1859    }
1860   };
1861  
# Line 2205 | Line 1864 | resv_nick: NICK '=' QSTRING ';'
1864   ***************************************************************************/
1865   shared_entry: T_SHARED
1866   {
1867 <  if (ypass == 2)
1868 <  {
1869 <    yy_conf = make_conf_item(ULINE_TYPE);
1870 <    yy_match_item = map_to_conf(yy_conf);
1871 <    yy_match_item->action = SHARED_ALL;
1872 <  }
1867 >  if (conf_parser_ctx.pass != 2)
1868 >    break;
1869 >
1870 >  reset_block_state();
1871 >
1872 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1873 >  strlcpy(block_state.user.buf, "*", sizeof(block_state.user.buf));
1874 >  strlcpy(block_state.host.buf, "*", sizeof(block_state.host.buf));
1875 >  block_state.flags.value = SHARED_ALL;
1876   } '{' shared_items '}' ';'
1877   {
1878 <  if (ypass == 2)
1879 <  {
1880 <    yy_conf = NULL;
1881 <  }
1878 >  struct MaskItem *conf = NULL;
1879 >
1880 >  if (conf_parser_ctx.pass != 2)
1881 >    break;
1882 >
1883 >  conf = conf_make(CONF_ULINE);
1884 >  conf->flags = block_state.flags.value;
1885 >  conf->name = xstrdup(block_state.name.buf);
1886 >  conf->user = xstrdup(block_state.user.buf);
1887 >  conf->host = xstrdup(block_state.host.buf);
1888   };
1889  
1890   shared_items: shared_items shared_item | shared_item;
# Line 2224 | Line 1892 | shared_item:  shared_name | shared_user
1892  
1893   shared_name: NAME '=' QSTRING ';'
1894   {
1895 <  if (ypass == 2)
1896 <  {
2229 <    MyFree(yy_conf->name);
2230 <    DupString(yy_conf->name, yylval.string);
2231 <  }
1895 >  if (conf_parser_ctx.pass == 2)
1896 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1897   };
1898  
1899   shared_user: USER '=' QSTRING ';'
1900   {
1901 <  if (ypass == 2)
1901 >  if (conf_parser_ctx.pass == 2)
1902    {
1903      struct split_nuh_item nuh;
1904  
1905      nuh.nuhmask  = yylval.string;
1906      nuh.nickptr  = NULL;
1907 <    nuh.userptr  = userbuf;
1908 <    nuh.hostptr  = hostbuf;
1907 >    nuh.userptr  = block_state.user.buf;
1908 >    nuh.hostptr  = block_state.host.buf;
1909  
1910      nuh.nicksize = 0;
1911 <    nuh.usersize = sizeof(userbuf);
1912 <    nuh.hostsize = sizeof(hostbuf);
1911 >    nuh.usersize = sizeof(block_state.user.buf);
1912 >    nuh.hostsize = sizeof(block_state.host.buf);
1913  
1914      split_nuh(&nuh);
2250
2251    DupString(yy_match_item->user, userbuf);
2252    DupString(yy_match_item->host, hostbuf);
1915    }
1916   };
1917  
1918   shared_type: TYPE
1919   {
1920 <  if (ypass == 2)
1921 <    yy_match_item->action = 0;
1920 >  if (conf_parser_ctx.pass == 2)
1921 >    block_state.flags.value = 0;
1922   } '=' shared_types ';' ;
1923  
1924   shared_types: shared_types ',' shared_type_item | shared_type_item;
1925   shared_type_item: KLINE
1926   {
1927 <  if (ypass == 2)
1928 <    yy_match_item->action |= SHARED_KLINE;
2267 < } | TKLINE
2268 < {
2269 <  if (ypass == 2)
2270 <    yy_match_item->action |= SHARED_TKLINE;
1927 >  if (conf_parser_ctx.pass == 2)
1928 >    block_state.flags.value |= SHARED_KLINE;
1929   } | UNKLINE
1930   {
1931 <  if (ypass == 2)
1932 <    yy_match_item->action |= SHARED_UNKLINE;
1933 < } | XLINE
1931 >  if (conf_parser_ctx.pass == 2)
1932 >    block_state.flags.value |= SHARED_UNKLINE;
1933 > } | T_DLINE
1934 > {
1935 >  if (conf_parser_ctx.pass == 2)
1936 >    block_state.flags.value |= SHARED_DLINE;
1937 > } | T_UNDLINE
1938   {
1939 <  if (ypass == 2)
1940 <    yy_match_item->action |= SHARED_XLINE;
1941 < } | TXLINE
1939 >  if (conf_parser_ctx.pass == 2)
1940 >    block_state.flags.value |= SHARED_UNDLINE;
1941 > } | XLINE
1942   {
1943 <  if (ypass == 2)
1944 <    yy_match_item->action |= SHARED_TXLINE;
1943 >  if (conf_parser_ctx.pass == 2)
1944 >    block_state.flags.value |= SHARED_XLINE;
1945   } | T_UNXLINE
1946   {
1947 <  if (ypass == 2)
1948 <    yy_match_item->action |= SHARED_UNXLINE;
1947 >  if (conf_parser_ctx.pass == 2)
1948 >    block_state.flags.value |= SHARED_UNXLINE;
1949   } | RESV
1950   {
1951 <  if (ypass == 2)
1952 <    yy_match_item->action |= SHARED_RESV;
2291 < } | TRESV
2292 < {
2293 <  if (ypass == 2)
2294 <    yy_match_item->action |= SHARED_TRESV;
1951 >  if (conf_parser_ctx.pass == 2)
1952 >    block_state.flags.value |= SHARED_RESV;
1953   } | T_UNRESV
1954   {
1955 <  if (ypass == 2)
1956 <    yy_match_item->action |= SHARED_UNRESV;
1955 >  if (conf_parser_ctx.pass == 2)
1956 >    block_state.flags.value |= SHARED_UNRESV;
1957   } | T_LOCOPS
1958   {
1959 <  if (ypass == 2)
1960 <    yy_match_item->action |= SHARED_LOCOPS;
1959 >  if (conf_parser_ctx.pass == 2)
1960 >    block_state.flags.value |= SHARED_LOCOPS;
1961   } | T_ALL
1962   {
1963 <  if (ypass == 2)
1964 <    yy_match_item->action = SHARED_ALL;
1963 >  if (conf_parser_ctx.pass == 2)
1964 >    block_state.flags.value = SHARED_ALL;
1965   };
1966  
1967   /***************************************************************************
# Line 2311 | Line 1969 | shared_type_item: KLINE
1969   ***************************************************************************/
1970   cluster_entry: T_CLUSTER
1971   {
1972 <  if (ypass == 2)
1973 <  {
1974 <    yy_conf = make_conf_item(CLUSTER_TYPE);
1975 <    yy_conf->flags = SHARED_ALL;
1976 <  }
1972 >  if (conf_parser_ctx.pass != 2)
1973 >    break;
1974 >
1975 >  reset_block_state();
1976 >
1977 >  strlcpy(block_state.name.buf, "*", sizeof(block_state.name.buf));
1978 >  block_state.flags.value = SHARED_ALL;
1979   } '{' cluster_items '}' ';'
1980   {
1981 <  if (ypass == 2)
1982 <  {
1983 <    if (yy_conf->name == NULL)
1984 <      DupString(yy_conf->name, "*");
1985 <    yy_conf = NULL;
1986 <  }
1981 >  struct MaskItem *conf = NULL;
1982 >
1983 >  if (conf_parser_ctx.pass != 2)
1984 >    break;
1985 >
1986 >  conf = conf_make(CONF_CLUSTER);
1987 >  conf->flags = block_state.flags.value;
1988 >  conf->name = xstrdup(block_state.name.buf);
1989   };
1990  
1991   cluster_items:  cluster_items cluster_item | cluster_item;
# Line 2331 | Line 1993 | cluster_item:  cluster_name | cluster_typ
1993  
1994   cluster_name: NAME '=' QSTRING ';'
1995   {
1996 <  if (ypass == 2)
1997 <    DupString(yy_conf->name, yylval.string);
1996 >  if (conf_parser_ctx.pass == 2)
1997 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1998   };
1999  
2000   cluster_type: TYPE
2001   {
2002 <  if (ypass == 2)
2003 <    yy_conf->flags = 0;
2002 >  if (conf_parser_ctx.pass == 2)
2003 >    block_state.flags.value = 0;
2004   } '=' cluster_types ';' ;
2005  
2006   cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2007   cluster_type_item: KLINE
2008   {
2009 <  if (ypass == 2)
2010 <    yy_conf->flags |= SHARED_KLINE;
2349 < } | TKLINE
2350 < {
2351 <  if (ypass == 2)
2352 <    yy_conf->flags |= SHARED_TKLINE;
2009 >  if (conf_parser_ctx.pass == 2)
2010 >    block_state.flags.value |= SHARED_KLINE;
2011   } | UNKLINE
2012   {
2013 <  if (ypass == 2)
2014 <    yy_conf->flags |= SHARED_UNKLINE;
2015 < } | XLINE
2013 >  if (conf_parser_ctx.pass == 2)
2014 >    block_state.flags.value |= SHARED_UNKLINE;
2015 > } | T_DLINE
2016 > {
2017 >  if (conf_parser_ctx.pass == 2)
2018 >    block_state.flags.value |= SHARED_DLINE;
2019 > } | T_UNDLINE
2020   {
2021 <  if (ypass == 2)
2022 <    yy_conf->flags |= SHARED_XLINE;
2023 < } | TXLINE
2021 >  if (conf_parser_ctx.pass == 2)
2022 >    block_state.flags.value |= SHARED_UNDLINE;
2023 > } | XLINE
2024   {
2025 <  if (ypass == 2)
2026 <    yy_conf->flags |= SHARED_TXLINE;
2025 >  if (conf_parser_ctx.pass == 2)
2026 >    block_state.flags.value |= SHARED_XLINE;
2027   } | T_UNXLINE
2028   {
2029 <  if (ypass == 2)
2030 <    yy_conf->flags |= SHARED_UNXLINE;
2029 >  if (conf_parser_ctx.pass == 2)
2030 >    block_state.flags.value |= SHARED_UNXLINE;
2031   } | RESV
2032   {
2033 <  if (ypass == 2)
2034 <    yy_conf->flags |= SHARED_RESV;
2373 < } | TRESV
2374 < {
2375 <  if (ypass == 2)
2376 <    yy_conf->flags |= SHARED_TRESV;
2033 >  if (conf_parser_ctx.pass == 2)
2034 >    block_state.flags.value |= SHARED_RESV;
2035   } | T_UNRESV
2036   {
2037 <  if (ypass == 2)
2038 <    yy_conf->flags |= SHARED_UNRESV;
2037 >  if (conf_parser_ctx.pass == 2)
2038 >    block_state.flags.value |= SHARED_UNRESV;
2039   } | T_LOCOPS
2040   {
2041 <  if (ypass == 2)
2042 <    yy_conf->flags |= SHARED_LOCOPS;
2041 >  if (conf_parser_ctx.pass == 2)
2042 >    block_state.flags.value |= SHARED_LOCOPS;
2043   } | T_ALL
2044   {
2045 <  if (ypass == 2)
2046 <    yy_conf->flags = SHARED_ALL;
2045 >  if (conf_parser_ctx.pass == 2)
2046 >    block_state.flags.value = SHARED_ALL;
2047   };
2048  
2049   /***************************************************************************
2050   *  section connect
2051   ***************************************************************************/
2052 < connect_entry: CONNECT  
2052 > connect_entry: CONNECT
2053   {
2396  if (ypass == 2)
2397  {
2398    yy_conf = make_conf_item(SERVER_TYPE);
2399    yy_aconf = (struct AccessItem *)map_to_conf(yy_conf);
2400    yy_aconf->passwd = NULL;
2401    /* defaults */
2402    yy_aconf->port = PORTNUM;
2054  
2055 <    if (ConfigFileEntry.burst_away)
2056 <      yy_aconf->flags = CONF_FLAGS_BURST_AWAY;
2057 <  }
2058 <  else
2059 <  {
2060 <    MyFree(class_name);
2061 <    class_name = NULL;
2411 <  }
2412 < } connect_name_b '{' connect_items '}' ';'
2055 >  if (conf_parser_ctx.pass != 2)
2056 >    break;
2057 >
2058 >  reset_block_state();
2059 >  block_state.aftype.value = AF_INET;
2060 >  block_state.port.value = PORTNUM;
2061 > } '{' connect_items '}' ';'
2062   {
2063 <  if (ypass == 2)
2064 <  {
2416 <    struct CollectItem *yy_hconf=NULL;
2417 <    struct CollectItem *yy_lconf=NULL;
2418 <    dlink_node *ptr;
2419 <    dlink_node *next_ptr;
2420 < #ifdef HAVE_LIBCRYPTO
2421 <    if (yy_aconf->host &&
2422 <        ((yy_aconf->passwd && yy_aconf->spasswd) ||
2423 <         (yy_aconf->rsa_public_key && IsConfCryptLink(yy_aconf))))
2424 < #else /* !HAVE_LIBCRYPTO */
2425 <      if (yy_aconf->host && !IsConfCryptLink(yy_aconf) &&
2426 <          yy_aconf->passwd && yy_aconf->spasswd)
2427 < #endif /* !HAVE_LIBCRYPTO */
2428 <        {
2429 <          if (conf_add_server(yy_conf, class_name) == -1)
2430 <          {
2431 <            delete_conf_item(yy_conf);
2432 <            yy_conf = NULL;
2433 <            yy_aconf = NULL;
2434 <          }
2435 <        }
2436 <        else
2437 <        {
2438 <          /* Even if yy_conf ->name is NULL
2439 <           * should still unhook any hub/leaf confs still pending
2440 <           */
2441 <          unhook_hub_leaf_confs();
2442 <
2443 <          if (yy_conf->name != NULL)
2444 <          {
2445 < #ifndef HAVE_LIBCRYPTO
2446 <            if (IsConfCryptLink(yy_aconf))
2447 <              yyerror("Ignoring connect block -- no OpenSSL support");
2448 < #else
2449 <            if (IsConfCryptLink(yy_aconf) && !yy_aconf->rsa_public_key)
2450 <              yyerror("Ignoring connect block -- missing key");
2451 < #endif
2452 <            if (yy_aconf->host == NULL)
2453 <              yyerror("Ignoring connect block -- missing host");
2454 <            else if (!IsConfCryptLink(yy_aconf) &&
2455 <                    (!yy_aconf->passwd || !yy_aconf->spasswd))
2456 <              yyerror("Ignoring connect block -- missing password");
2457 <          }
2458 <
2459 <
2460 <          /* XXX
2461 <           * This fixes a try_connections() core (caused by invalid class_ptr
2462 <           * pointers) reported by metalrock. That's an ugly fix, but there
2463 <           * is currently no better way. The entire config subsystem needs an
2464 <           * rewrite ASAP. make_conf_item() shouldn't really add things onto
2465 <           * a doubly linked list immediately without any sanity checks!  -Michael
2466 <           */
2467 <          delete_conf_item(yy_conf);
2468 <
2469 <          yy_aconf = NULL;
2470 <          yy_conf = NULL;
2471 <        }
2472 <
2473 <      /*
2474 <       * yy_conf is still pointing at the server that is having
2475 <       * a connect block built for it. This means, y_aconf->name
2476 <       * points to the actual irc name this server will be known as.
2477 <       * Now this new server has a set or even just one hub_mask (or leaf_mask)
2478 <       * given in the link list at yy_hconf. Fill in the HUB confs
2479 <       * from this link list now.
2480 <       */        
2481 <      DLINK_FOREACH_SAFE(ptr, next_ptr, hub_conf_list.head)
2482 <      {
2483 <        struct ConfItem *new_hub_conf;
2484 <        struct MatchItem *match_item;
2063 >  struct MaskItem *conf = NULL;
2064 >  struct addrinfo hints, *res;
2065  
2066 <        yy_hconf = ptr->data;
2066 >  if (conf_parser_ctx.pass != 2)
2067 >    break;
2068  
2069 <        /* yy_conf == NULL is a fatal error for this connect block! */
2070 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2071 <        {
2491 <          new_hub_conf = make_conf_item(HUB_TYPE);
2492 <          match_item = (struct MatchItem *)map_to_conf(new_hub_conf);
2493 <          DupString(new_hub_conf->name, yy_conf->name);
2494 <          if (yy_hconf->user != NULL)
2495 <            DupString(match_item->user, yy_hconf->user);
2496 <          else
2497 <            DupString(match_item->user, "*");
2498 <          if (yy_hconf->host != NULL)
2499 <            DupString(match_item->host, yy_hconf->host);
2500 <          else
2501 <            DupString(match_item->host, "*");
2502 <        }
2503 <        dlinkDelete(&yy_hconf->node, &hub_conf_list);
2504 <        free_collect_item(yy_hconf);
2505 <      }
2069 >  if (!block_state.name.buf[0] ||
2070 >      !block_state.host.buf[0])
2071 >    break;
2072  
2073 <      /* Ditto for the LEAF confs */
2073 >  if (!block_state.rpass.buf[0] ||
2074 >      !block_state.spass.buf[0])
2075 >    break;
2076  
2077 <      DLINK_FOREACH_SAFE(ptr, next_ptr, leaf_conf_list.head)
2078 <      {
2079 <        struct ConfItem *new_leaf_conf;
2512 <        struct MatchItem *match_item;
2077 >  if (has_wildcards(block_state.name.buf) ||
2078 >      has_wildcards(block_state.host.buf))
2079 >    break;
2080  
2081 <        yy_lconf = ptr->data;
2081 >  conf = conf_make(CONF_SERVER);
2082 >  conf->port = block_state.port.value;
2083 >  conf->flags = block_state.flags.value;
2084 >  conf->aftype = block_state.aftype.value;
2085 >  conf->host = xstrdup(block_state.host.buf);
2086 >  conf->name = xstrdup(block_state.name.buf);
2087 >  conf->passwd = xstrdup(block_state.rpass.buf);
2088 >  conf->spasswd = xstrdup(block_state.spass.buf);
2089  
2090 <        if ((yy_conf != NULL) && (yy_conf->name != NULL))
2091 <        {
2518 <          new_leaf_conf = make_conf_item(LEAF_TYPE);
2519 <          match_item = (struct MatchItem *)map_to_conf(new_leaf_conf);
2520 <          DupString(new_leaf_conf->name, yy_conf->name);
2521 <          if (yy_lconf->user != NULL)
2522 <            DupString(match_item->user, yy_lconf->user);
2523 <          else
2524 <            DupString(match_item->user, "*");
2525 <          if (yy_lconf->host != NULL)
2526 <            DupString(match_item->host, yy_lconf->host);
2527 <          else
2528 <            DupString(match_item->host, "*");
2529 <        }
2530 <        dlinkDelete(&yy_lconf->node, &leaf_conf_list);
2531 <        free_collect_item(yy_lconf);
2532 <      }
2533 <      MyFree(class_name);
2534 <      class_name = NULL;
2535 <      yy_conf = NULL;
2536 <      yy_aconf = NULL;
2537 <  }
2538 < };
2090 >  if (block_state.cert.buf[0])
2091 >    conf->certfp = xstrdup(block_state.cert.buf);
2092  
2093 < connect_name_b: | connect_name_t;
2094 < connect_items:  connect_items connect_item | connect_item;
2542 < connect_item:   connect_name | connect_host | connect_vhost |
2543 <                connect_send_password | connect_accept_password |
2544 <                connect_aftype | connect_port |
2545 <                connect_fakename | connect_flags | connect_hub_mask |
2546 <                connect_leaf_mask | connect_class | connect_auto |
2547 <                connect_encrypted | connect_compressed | connect_cryptlink |
2548 <                connect_rsa_public_key_file | connect_cipher_preference |
2549 <                connect_topicburst | error ';' ;
2093 >  if (block_state.ciph.buf[0])
2094 >    conf->cipher_list = xstrdup(block_state.ciph.buf);
2095  
2096 < connect_name: NAME '=' QSTRING ';'
2097 < {
2553 <  if (ypass == 2)
2554 <  {
2555 <    if (yy_conf->name != NULL)
2556 <      yyerror("Multiple connect name entry");
2096 >  dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
2097 >  dlinkMoveList(&block_state.hub.list, &conf->hub_list);
2098  
2099 <    MyFree(yy_conf->name);
2559 <    DupString(yy_conf->name, yylval.string);
2560 <  }
2561 < };
2562 <
2563 < connect_name_t: QSTRING
2564 < {
2565 <  if (ypass == 2)
2099 >  if (block_state.bind.buf[0])
2100    {
2567    if (yy_conf->name != NULL)
2568      yyerror("Multiple connect name entry");
2569
2570    MyFree(yy_conf->name);
2571    DupString(yy_conf->name, yylval.string);
2572  }
2573 };
2574
2575 connect_host: HOST '=' QSTRING ';'
2576 {
2577  if (ypass == 2)
2578  {
2579    MyFree(yy_aconf->host);
2580    DupString(yy_aconf->host, yylval.string);
2581  }
2582 };
2583
2584 connect_vhost: VHOST '=' QSTRING ';'
2585 {
2586  if (ypass == 2)
2587  {
2588    struct addrinfo hints, *res;
2589
2101      memset(&hints, 0, sizeof(hints));
2102  
2103      hints.ai_family   = AF_UNSPEC;
2104      hints.ai_socktype = SOCK_STREAM;
2105      hints.ai_flags    = AI_PASSIVE | AI_NUMERICHOST;
2106  
2107 <    if (irc_getaddrinfo(yylval.string, NULL, &hints, &res))
2108 <      ilog(L_ERROR, "Invalid netmask for server vhost(%s)", yylval.string);
2107 >    if (getaddrinfo(block_state.bind.buf, NULL, &hints, &res))
2108 >      ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
2109      else
2110      {
2111        assert(res != NULL);
2112  
2113 <      memcpy(&yy_aconf->my_ipnum, res->ai_addr, res->ai_addrlen);
2114 <      yy_aconf->my_ipnum.ss.ss_family = res->ai_family;
2115 <      yy_aconf->my_ipnum.ss_len = res->ai_addrlen;
2116 <      irc_freeaddrinfo(res);
2113 >      memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
2114 >      conf->bind.ss.ss_family = res->ai_family;
2115 >      conf->bind.ss_len = res->ai_addrlen;
2116 >      freeaddrinfo(res);
2117      }
2118    }
2608 };
2609
2610 connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2611 {
2612  if (ypass == 2)
2613  {
2614    if ($3[0] == ':')
2615      yyerror("Server passwords cannot begin with a colon");
2616    else if (strchr($3, ' ') != NULL)
2617      yyerror("Server passwords cannot contain spaces");
2618    else {
2619      if (yy_aconf->spasswd != NULL)
2620        memset(yy_aconf->spasswd, 0, strlen(yy_aconf->spasswd));
2119  
2120 <      MyFree(yy_aconf->spasswd);
2121 <      DupString(yy_aconf->spasswd, yylval.string);
2624 <    }
2625 <  }
2120 >  conf_add_class_to_conf(conf, block_state.class.buf);
2121 >  lookup_confhost(conf);
2122   };
2123  
2124 < connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2125 < {
2126 <  if (ypass == 2)
2127 <  {
2128 <    if ($3[0] == ':')
2129 <      yyerror("Server passwords cannot begin with a colon");
2130 <    else if (strchr($3, ' ') != NULL)
2131 <      yyerror("Server passwords cannot contain spaces");
2636 <    else {
2637 <      if (yy_aconf->passwd != NULL)
2638 <        memset(yy_aconf->passwd, 0, strlen(yy_aconf->passwd));
2639 <
2640 <      MyFree(yy_aconf->passwd);
2641 <      DupString(yy_aconf->passwd, yylval.string);
2642 <    }
2643 <  }
2644 < };
2124 > connect_items:  connect_items connect_item | connect_item;
2125 > connect_item:   connect_name | connect_host | connect_vhost |
2126 >                connect_send_password | connect_accept_password |
2127 >                connect_ssl_certificate_fingerprint |
2128 >                connect_aftype | connect_port | connect_ssl_cipher_list |
2129 >                connect_flags | connect_hub_mask | connect_leaf_mask |
2130 >                connect_class | connect_encrypted |
2131 >                error ';' ;
2132  
2133 < connect_port: PORT '=' NUMBER ';'
2133 > connect_name: NAME '=' QSTRING ';'
2134   {
2135 <  if (ypass == 2)
2136 <    yy_aconf->port = $3;
2135 >  if (conf_parser_ctx.pass == 2)
2136 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2137   };
2138  
2139 < connect_aftype: AFTYPE '=' T_IPV4 ';'
2139 > connect_host: HOST '=' QSTRING ';'
2140   {
2141 <  if (ypass == 2)
2142 <    yy_aconf->aftype = AF_INET;
2656 < } | AFTYPE '=' T_IPV6 ';'
2657 < {
2658 < #ifdef IPV6
2659 <  if (ypass == 2)
2660 <    yy_aconf->aftype = AF_INET6;
2661 < #endif
2141 >  if (conf_parser_ctx.pass == 2)
2142 >    strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
2143   };
2144  
2145 < connect_fakename: FAKENAME '=' QSTRING ';'
2145 > connect_vhost: VHOST '=' QSTRING ';'
2146   {
2147 <  if (ypass == 2)
2148 <  {
2668 <    MyFree(yy_aconf->fakename);
2669 <    DupString(yy_aconf->fakename, yylval.string);
2670 <  }
2147 >  if (conf_parser_ctx.pass == 2)
2148 >    strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
2149   };
2150  
2151 < connect_flags: IRCD_FLAGS
2151 > connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2152   {
2153 < } '='  connect_flags_items ';';
2153 >  if (conf_parser_ctx.pass != 2)
2154 >    break;
2155  
2156 < connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
2157 < connect_flags_item: NOT  { not_atom = 1; } connect_flags_item_atom
2158 <                        |  { not_atom = 0; } connect_flags_item_atom;
2159 <
2160 < connect_flags_item_atom: LAZYLINK
2161 < {
2162 <  if (ypass == 2)
2684 <  {
2685 <    if (not_atom)ClearConfLazyLink(yy_aconf);
2686 <    else SetConfLazyLink(yy_aconf);
2687 <  }
2688 < } | COMPRESSED
2689 < {
2690 <  if (ypass == 2)
2691 < #ifndef HAVE_LIBZ
2692 <    yyerror("Ignoring flags = compressed; -- no zlib support");
2693 < #else
2694 < {
2695 <   if (not_atom)ClearConfCompressed(yy_aconf);
2696 <   else SetConfCompressed(yy_aconf);
2697 < }
2698 < #endif
2699 < } | CRYPTLINK
2700 < {
2701 <  if (ypass == 2)
2702 <  {
2703 <    if (not_atom)ClearConfCryptLink(yy_aconf);
2704 <    else SetConfCryptLink(yy_aconf);
2705 <  }
2706 < } | AUTOCONN
2707 < {
2708 <  if (ypass == 2)
2709 <  {
2710 <    if (not_atom)ClearConfAllowAutoConn(yy_aconf);
2711 <    else SetConfAllowAutoConn(yy_aconf);
2712 <  }
2713 < } | BURST_AWAY
2714 < {
2715 <  if (ypass == 2)
2716 <  {
2717 <    if (not_atom)ClearConfAwayBurst(yy_aconf);
2718 <    else SetConfAwayBurst(yy_aconf);
2719 <  }
2720 < } | TOPICBURST
2721 < {
2722 <  if (ypass == 2)
2723 <  {
2724 <    if (not_atom)ClearConfTopicBurst(yy_aconf);
2725 <    else SetConfTopicBurst(yy_aconf);
2726 <  }
2727 < }
2728 < ;
2156 >  if ($3[0] == ':')
2157 >    conf_error_report("Server passwords cannot begin with a colon");
2158 >  else if (strchr($3, ' ') != NULL)
2159 >    conf_error_report("Server passwords cannot contain spaces");
2160 >  else
2161 >    strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
2162 > };
2163  
2164 < connect_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
2164 > connect_accept_password: ACCEPT_PASSWORD '=' QSTRING ';'
2165   {
2166 < #ifdef HAVE_LIBCRYPTO
2167 <  if (ypass == 2)
2734 <  {
2735 <    BIO *file;
2736 <
2737 <    if (yy_aconf->rsa_public_key != NULL)
2738 <    {
2739 <      RSA_free(yy_aconf->rsa_public_key);
2740 <      yy_aconf->rsa_public_key = NULL;
2741 <    }
2742 <
2743 <    if (yy_aconf->rsa_public_key_file != NULL)
2744 <    {
2745 <      MyFree(yy_aconf->rsa_public_key_file);
2746 <      yy_aconf->rsa_public_key_file = NULL;
2747 <    }
2748 <
2749 <    DupString(yy_aconf->rsa_public_key_file, yylval.string);
2750 <
2751 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
2752 <    {
2753 <      yyerror("Ignoring rsa_public_key_file -- file doesn't exist");
2754 <      break;
2755 <    }
2166 >  if (conf_parser_ctx.pass != 2)
2167 >    break;
2168  
2169 <    yy_aconf->rsa_public_key = (RSA *)PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL);
2170 <
2171 <    if (yy_aconf->rsa_public_key == NULL)
2172 <    {
2173 <      yyerror("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
2174 <      break;
2763 <    }
2764 <      
2765 <    BIO_set_close(file, BIO_CLOSE);
2766 <    BIO_free(file);
2767 <  }
2768 < #endif /* HAVE_LIBCRYPTO */
2169 >  if ($3[0] == ':')
2170 >    conf_error_report("Server passwords cannot begin with a colon");
2171 >  else if (strchr($3, ' ') != NULL)
2172 >    conf_error_report("Server passwords cannot contain spaces");
2173 >  else
2174 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2175   };
2176  
2177 < connect_encrypted: ENCRYPTED '=' TBOOL ';'
2177 > connect_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
2178   {
2179 <  if (ypass == 2)
2180 <  {
2775 <    if (yylval.number)
2776 <      yy_aconf->flags |= CONF_FLAGS_ENCRYPTED;
2777 <    else
2778 <      yy_aconf->flags &= ~CONF_FLAGS_ENCRYPTED;
2779 <  }
2179 >  if (conf_parser_ctx.pass == 2)
2180 >    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
2181   };
2182  
2183 < connect_cryptlink: CRYPTLINK '=' TBOOL ';'
2183 > connect_port: PORT '=' NUMBER ';'
2184   {
2185 <  if (ypass == 2)
2186 <  {
2786 <    if (yylval.number)
2787 <      yy_aconf->flags |= CONF_FLAGS_CRYPTLINK;
2788 <    else
2789 <      yy_aconf->flags &= ~CONF_FLAGS_CRYPTLINK;
2790 <  }
2185 >  if (conf_parser_ctx.pass == 2)
2186 >    block_state.port.value = $3;
2187   };
2188  
2189 < connect_compressed: COMPRESSED '=' TBOOL ';'
2189 > connect_aftype: AFTYPE '=' T_IPV4 ';'
2190   {
2191 <  if (ypass == 2)
2192 <  {
2193 <    if (yylval.number)
2194 < #ifndef HAVE_LIBZ
2195 <      yyerror("Ignoring compressed=yes; -- no zlib support");
2196 < #else
2197 <      yy_aconf->flags |= CONF_FLAGS_COMPRESSED;
2191 >  if (conf_parser_ctx.pass == 2)
2192 >    block_state.aftype.value = AF_INET;
2193 > } | AFTYPE '=' T_IPV6 ';'
2194 > {
2195 > #ifdef IPV6
2196 >  if (conf_parser_ctx.pass == 2)
2197 >    block_state.aftype.value = AF_INET6;
2198   #endif
2803    else
2804      yy_aconf->flags &= ~CONF_FLAGS_COMPRESSED;
2805  }
2199   };
2200  
2201 < connect_auto: AUTOCONN '=' TBOOL ';'
2201 > connect_flags: IRCD_FLAGS
2202   {
2203 <  if (ypass == 2)
2204 <  {
2205 <    if (yylval.number)
2206 <      yy_aconf->flags |= CONF_FLAGS_ALLOW_AUTO_CONN;
2207 <    else
2208 <      yy_aconf->flags &= ~CONF_FLAGS_ALLOW_AUTO_CONN;
2209 <  }
2203 >  block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
2204 > } '='  connect_flags_items ';';
2205 >
2206 > connect_flags_items: connect_flags_items ',' connect_flags_item | connect_flags_item;
2207 > connect_flags_item: AUTOCONN
2208 > {
2209 >  if (conf_parser_ctx.pass == 2)
2210 >    block_state.flags.value |= CONF_FLAGS_ALLOW_AUTO_CONN;
2211 > } | T_SSL
2212 > {
2213 >  if (conf_parser_ctx.pass == 2)
2214 >    block_state.flags.value |= CONF_FLAGS_SSL;
2215   };
2216  
2217 < connect_topicburst: TOPICBURST '=' TBOOL ';'
2217 > connect_encrypted: ENCRYPTED '=' TBOOL ';'
2218   {
2219 <  if (ypass == 2)
2219 >  if (conf_parser_ctx.pass == 2)
2220    {
2221      if (yylval.number)
2222 <      SetConfTopicBurst(yy_aconf);
2222 >      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
2223      else
2224 <      ClearConfTopicBurst(yy_aconf);
2224 >      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
2225    }
2226   };
2227  
2228 < connect_hub_mask: HUB_MASK '=' QSTRING ';'
2228 > connect_hub_mask: HUB_MASK '=' QSTRING ';'
2229   {
2230 <  if (ypass == 2)
2231 <  {
2834 <    struct CollectItem *yy_tmp;
2835 <
2836 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2837 <    DupString(yy_tmp->host, yylval.string);
2838 <    DupString(yy_tmp->user, "*");
2839 <    dlinkAdd(yy_tmp, &yy_tmp->node, &hub_conf_list);
2840 <  }
2230 >  if (conf_parser_ctx.pass == 2)
2231 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
2232   };
2233  
2234 < connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2234 > connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2235   {
2236 <  if (ypass == 2)
2237 <  {
2847 <    struct CollectItem *yy_tmp;
2848 <
2849 <    yy_tmp = (struct CollectItem *)MyMalloc(sizeof(struct CollectItem));
2850 <    DupString(yy_tmp->host, yylval.string);
2851 <    DupString(yy_tmp->user, "*");
2852 <    dlinkAdd(yy_tmp, &yy_tmp->node, &leaf_conf_list);
2853 <  }
2236 >  if (conf_parser_ctx.pass == 2)
2237 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
2238   };
2239  
2240   connect_class: CLASS '=' QSTRING ';'
2241   {
2242 <  if (ypass == 2)
2243 <  {
2860 <    MyFree(class_name);
2861 <    DupString(class_name, yylval.string);
2862 <  }
2242 >  if (conf_parser_ctx.pass == 2)
2243 >    strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
2244   };
2245  
2246 < connect_cipher_preference: CIPHER_PREFERENCE '=' QSTRING ';'
2246 > connect_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
2247   {
2248   #ifdef HAVE_LIBCRYPTO
2249 <  if (ypass == 2)
2250 <  {
2870 <    struct EncCapability *ecap;
2871 <    const char *cipher_name;
2872 <    int found = 0;
2873 <
2874 <    yy_aconf->cipher_preference = NULL;
2875 <    cipher_name = yylval.string;
2876 <
2877 <    for (ecap = CipherTable; ecap->name; ecap++)
2878 <    {
2879 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
2880 <          (ecap->cap & CAP_ENC_MASK))
2881 <      {
2882 <        yy_aconf->cipher_preference = ecap;
2883 <        found = 1;
2884 <        break;
2885 <      }
2886 <    }
2887 <
2888 <    if (!found)
2889 <      yyerror("Invalid cipher");
2890 <  }
2249 >  if (conf_parser_ctx.pass == 2)
2250 >    strlcpy(block_state.ciph.buf, yylval.string, sizeof(block_state.ciph.buf));
2251   #else
2252 <  if (ypass == 2)
2253 <    yyerror("Ignoring cipher_preference -- no OpenSSL support");
2252 >  if (conf_parser_ctx.pass == 2)
2253 >    conf_error_report("Ignoring connect::ciphers -- no OpenSSL support");
2254   #endif
2255   };
2256  
2257 +
2258   /***************************************************************************
2259   *  section kill
2260   ***************************************************************************/
2261   kill_entry: KILL
2262   {
2263 <  if (ypass == 2)
2264 <  {
2904 <    userbuf[0] = hostbuf[0] = reasonbuf[0] = '\0';
2905 <    regex_ban = 0;
2906 <  }
2263 >  if (conf_parser_ctx.pass == 2)
2264 >    reset_block_state();
2265   } '{' kill_items '}' ';'
2266   {
2267 <  if (ypass == 2)
2910 <  {
2911 <    if (userbuf[0] && hostbuf[0])
2912 <    {
2913 <      if (regex_ban)
2914 <      {
2915 <        pcre *exp_user = NULL;
2916 <        pcre *exp_host = NULL;
2917 <        const char *errptr = NULL;
2918 <
2919 <        if (!(exp_user = ircd_pcre_compile(userbuf, &errptr)) ||
2920 <            !(exp_host = ircd_pcre_compile(hostbuf, &errptr)))
2921 <        {
2922 <          ilog(L_ERROR, "Failed to add regular expression based K-Line: %s",
2923 <               errptr);
2924 <          break;
2925 <        }
2926 <
2927 <        yy_conf = make_conf_item(RKLINE_TYPE);
2928 <        yy_aconf = map_to_conf(yy_conf);
2267 >  struct MaskItem *conf = NULL;
2268  
2269 <        yy_aconf->regexuser = exp_user;
2270 <        yy_aconf->regexhost = exp_host;
2269 >  if (conf_parser_ctx.pass != 2)
2270 >    break;
2271  
2272 <        DupString(yy_aconf->user, userbuf);
2273 <        DupString(yy_aconf->host, hostbuf);
2274 <
2936 <        if (reasonbuf[0])
2937 <          DupString(yy_aconf->reason, reasonbuf);
2938 <        else
2939 <          DupString(yy_aconf->reason, "No reason");
2940 <      }
2941 <      else
2942 <      {
2943 <        yy_conf = make_conf_item(KLINE_TYPE);
2944 <        yy_aconf = map_to_conf(yy_conf);
2272 >  if (!block_state.user.buf[0] ||
2273 >      !block_state.host.buf[0])
2274 >    break;
2275  
2276 <        DupString(yy_aconf->user, userbuf);
2277 <        DupString(yy_aconf->host, hostbuf);
2276 >  conf = conf_make(CONF_KLINE);
2277 >  conf->user = xstrdup(block_state.user.buf);
2278 >  conf->host = xstrdup(block_state.host.buf);
2279  
2280 <        if (reasonbuf[0])
2281 <          DupString(yy_aconf->reason, reasonbuf);
2282 <        else
2283 <          DupString(yy_aconf->reason, "No reason");
2284 <        add_conf_by_address(CONF_KILL, yy_aconf);
2954 <      }
2955 <    }
2956 <    else
2957 <      delete_conf_item(yy_conf);
2958 <
2959 <    yy_conf = NULL;
2960 <    yy_aconf = NULL;
2961 <  }
2962 < };
2963 <
2964 < kill_type: TYPE
2965 < {
2966 < } '='  kill_type_items ';';
2967 <
2968 < kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2969 < kill_type_item: REGEX_T
2970 < {
2971 <  if (ypass == 2)
2972 <    regex_ban = 1;
2280 >  if (block_state.rpass.buf[0])
2281 >    conf->reason = xstrdup(block_state.rpass.buf);
2282 >  else
2283 >    conf->reason = xstrdup(CONF_NOREASON);
2284 >  add_conf_by_address(CONF_KLINE, conf);
2285   };
2286  
2287   kill_items:     kill_items kill_item | kill_item;
2288 < kill_item:      kill_user | kill_reason | kill_type | error;
2288 > kill_item:      kill_user | kill_reason | error;
2289  
2290   kill_user: USER '=' QSTRING ';'
2291   {
2292 <  if (ypass == 2)
2292 >
2293 >  if (conf_parser_ctx.pass == 2)
2294    {
2295      struct split_nuh_item nuh;
2296  
2297      nuh.nuhmask  = yylval.string;
2298      nuh.nickptr  = NULL;
2299 <    nuh.userptr  = userbuf;
2300 <    nuh.hostptr  = hostbuf;
2299 >    nuh.userptr  = block_state.user.buf;
2300 >    nuh.hostptr  = block_state.host.buf;
2301  
2302      nuh.nicksize = 0;
2303 <    nuh.usersize = sizeof(userbuf);
2304 <    nuh.hostsize = sizeof(hostbuf);
2303 >    nuh.usersize = sizeof(block_state.user.buf);
2304 >    nuh.hostsize = sizeof(block_state.host.buf);
2305  
2306      split_nuh(&nuh);
2307    }
2308   };
2309  
2310 < kill_reason: REASON '=' QSTRING ';'
2310 > kill_reason: REASON '=' QSTRING ';'
2311   {
2312 <  if (ypass == 2)
2313 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2312 >  if (conf_parser_ctx.pass == 2)
2313 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2314   };
2315  
2316   /***************************************************************************
2317   *  section deny
2318   ***************************************************************************/
2319 < deny_entry: DENY
2319 > deny_entry: DENY
2320   {
2321 <  if (ypass == 2)
2322 <  {
3010 <    yy_conf = make_conf_item(DLINE_TYPE);
3011 <    yy_aconf = map_to_conf(yy_conf);
3012 <    /* default reason */
3013 <    DupString(yy_aconf->reason, "No reason");
3014 <  }
2321 >  if (conf_parser_ctx.pass == 2)
2322 >    reset_block_state();
2323   } '{' deny_items '}' ';'
2324   {
2325 <  if (ypass == 2)
2325 >  struct MaskItem *conf = NULL;
2326 >
2327 >  if (conf_parser_ctx.pass != 2)
2328 >    break;
2329 >
2330 >  if (!block_state.addr.buf[0])
2331 >    break;
2332 >
2333 >  if (parse_netmask(block_state.addr.buf, NULL, NULL) != HM_HOST)
2334    {
2335 <    if (yy_aconf->host && parse_netmask(yy_aconf->host, NULL, NULL) != HM_HOST)
2336 <      add_conf_by_address(CONF_DLINE, yy_aconf);
2335 >    conf = conf_make(CONF_DLINE);
2336 >    conf->host = xstrdup(block_state.addr.buf);
2337 >
2338 >    if (block_state.rpass.buf[0])
2339 >      conf->reason = xstrdup(block_state.rpass.buf);
2340      else
2341 <      delete_conf_item(yy_conf);
2342 <    yy_conf = NULL;
3024 <    yy_aconf = NULL;
2341 >      conf->reason = xstrdup(CONF_NOREASON);
2342 >    add_conf_by_address(CONF_DLINE, conf);
2343    }
2344 < };
2344 > };
2345  
2346   deny_items:     deny_items deny_item | deny_item;
2347   deny_item:      deny_ip | deny_reason | error;
2348  
2349   deny_ip: IP '=' QSTRING ';'
2350   {
2351 <  if (ypass == 2)
2352 <  {
3035 <    MyFree(yy_aconf->host);
3036 <    DupString(yy_aconf->host, yylval.string);
3037 <  }
2351 >  if (conf_parser_ctx.pass == 2)
2352 >    strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2353   };
2354  
2355 < deny_reason: REASON '=' QSTRING ';'
2355 > deny_reason: REASON '=' QSTRING ';'
2356   {
2357 <  if (ypass == 2)
2358 <  {
3044 <    MyFree(yy_aconf->reason);
3045 <    DupString(yy_aconf->reason, yylval.string);
3046 <  }
2357 >  if (conf_parser_ctx.pass == 2)
2358 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2359   };
2360  
2361   /***************************************************************************
# Line 3056 | Line 2368 | exempt_item:      exempt_ip | error;
2368  
2369   exempt_ip: IP '=' QSTRING ';'
2370   {
2371 <  if (ypass == 2)
2371 >  if (conf_parser_ctx.pass == 2)
2372    {
2373      if (yylval.string[0] && parse_netmask(yylval.string, NULL, NULL) != HM_HOST)
2374      {
2375 <      yy_conf = make_conf_item(EXEMPTDLINE_TYPE);
2376 <      yy_aconf = map_to_conf(yy_conf);
3065 <      DupString(yy_aconf->host, yylval.string);
2375 >      struct MaskItem *conf = conf_make(CONF_EXEMPT);
2376 >      conf->host = xstrdup(yylval.string);
2377  
2378 <      add_conf_by_address(CONF_EXEMPTDLINE, yy_aconf);
3068 <
3069 <      yy_conf = NULL;
3070 <      yy_aconf = NULL;
2378 >      add_conf_by_address(CONF_EXEMPT, conf);
2379      }
2380    }
2381   };
# Line 3077 | Line 2385 | exempt_ip: IP '=' QSTRING ';'
2385   ***************************************************************************/
2386   gecos_entry: GECOS
2387   {
2388 <  if (ypass == 2)
2389 <  {
3082 <    regex_ban = 0;
3083 <    reasonbuf[0] = gecos_name[0] = '\0';
3084 <  }
2388 >  if (conf_parser_ctx.pass == 2)
2389 >    reset_block_state();
2390   } '{' gecos_items '}' ';'
2391   {
2392 <  if (ypass == 2)
3088 <  {
3089 <    if (gecos_name[0])
3090 <    {
3091 <      if (regex_ban)
3092 <      {
3093 <        pcre *exp_p = NULL;
3094 <        const char *errptr = NULL;
3095 <
3096 <        if (!(exp_p = ircd_pcre_compile(gecos_name, &errptr)))
3097 <        {
3098 <          ilog(L_ERROR, "Failed to add regular expression based X-Line: %s",
3099 <               errptr);
3100 <          break;
3101 <        }
3102 <
3103 <        yy_conf = make_conf_item(RXLINE_TYPE);
3104 <        yy_conf->regexpname = exp_p;
3105 <      }
3106 <      else
3107 <        yy_conf = make_conf_item(XLINE_TYPE);
2392 >  struct MaskItem *conf = NULL;
2393  
2394 <      yy_match_item = map_to_conf(yy_conf);
2395 <      DupString(yy_conf->name, gecos_name);
2394 >  if (conf_parser_ctx.pass != 2)
2395 >    break;
2396  
2397 <      if (reasonbuf[0])
2398 <        DupString(yy_match_item->reason, reasonbuf);
3114 <      else
3115 <        DupString(yy_match_item->reason, "No reason");
3116 <    }
3117 <  }
3118 < };
2397 >  if (!block_state.name.buf[0])
2398 >    break;
2399  
2400 < gecos_flags: TYPE
2401 < {
3122 < } '='  gecos_flags_items ';';
2400 >  conf = conf_make(CONF_XLINE);
2401 >  conf->name = xstrdup(block_state.name.buf);
2402  
2403 < gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2404 < gecos_flags_item: REGEX_T
2405 < {
2406 <  if (ypass == 2)
3128 <    regex_ban = 1;
2403 >  if (block_state.rpass.buf[0])
2404 >    conf->reason = xstrdup(block_state.rpass.buf);
2405 >  else
2406 >    conf->reason = xstrdup(CONF_NOREASON);
2407   };
2408  
2409   gecos_items: gecos_items gecos_item | gecos_item;
2410 < gecos_item:  gecos_name | gecos_reason | gecos_flags | error;
2410 > gecos_item:  gecos_name | gecos_reason | error;
2411  
2412 < gecos_name: NAME '=' QSTRING ';'
2412 > gecos_name: NAME '=' QSTRING ';'
2413   {
2414 <  if (ypass == 2)
2415 <    strlcpy(gecos_name, yylval.string, sizeof(gecos_name));
2414 >  if (conf_parser_ctx.pass == 2)
2415 >    strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2416   };
2417  
2418 < gecos_reason: REASON '=' QSTRING ';'
2418 > gecos_reason: REASON '=' QSTRING ';'
2419   {
2420 <  if (ypass == 2)
2421 <    strlcpy(reasonbuf, yylval.string, sizeof(reasonbuf));
2420 >  if (conf_parser_ctx.pass == 2)
2421 >    strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2422   };
2423  
2424   /***************************************************************************
# Line 3155 | Line 2433 | general_item:       general_hide_spoof_i
2433                      general_max_nick_time | general_max_nick_changes |
2434                      general_max_accept | general_anti_spam_exit_message_time |
2435                      general_ts_warn_delta | general_ts_max_delta |
2436 <                    general_kill_chase_time_limit | general_kline_with_reason |
2437 <                    general_kline_reason | general_invisible_on_connect |
2436 >                    general_kill_chase_time_limit |
2437 >                    general_invisible_on_connect |
2438                      general_warn_no_nline | general_dots_in_ident |
2439                      general_stats_o_oper_only | general_stats_k_oper_only |
2440                      general_pace_wait | general_stats_i_oper_only |
2441                      general_pace_wait_simple | general_stats_P_oper_only |
2442 +                    general_stats_u_oper_only |
2443                      general_short_motd | general_no_oper_flood |
2444                      general_true_no_oper_flood | general_oper_pass_resv |
3166                    general_idletime | general_message_locale |
2445                      general_oper_only_umodes | general_max_targets |
2446                      general_use_egd | general_egdpool_path |
2447                      general_oper_umodes | general_caller_id_wait |
2448                      general_opers_bypass_callerid | general_default_floodcount |
2449                      general_min_nonwildcard | general_min_nonwildcard_simple |
3172                    general_servlink_path | general_disable_remote_commands |
3173                    general_default_cipher_preference |
3174                    general_compression_level | general_client_flood |
2450                      general_throttle_time | general_havent_read_conf |
2451 <                    general_dot_in_ip6_addr | general_ping_cookie |
2452 <                    general_disable_auth | general_burst_away |
2453 <                    general_tkline_expire_notices | general_gline_min_cidr |
2454 <                    general_gline_min_cidr6 | general_use_whois_actually |
2455 <                    general_reject_hold_time | general_stats_e_disabled |
2451 >                    general_ping_cookie |
2452 >                    general_disable_auth |
2453 >                    general_tkline_expire_notices | general_gline_enable |
2454 >                    general_gline_duration | general_gline_request_duration |
2455 >                    general_gline_min_cidr |
2456 >                    general_gline_min_cidr6 |
2457 >                    general_stats_e_disabled |
2458 >                    general_max_watch | general_services_name |
2459 >                    general_cycle_on_host_change |
2460                      error;
2461  
2462  
2463 + general_max_watch: MAX_WATCH '=' NUMBER ';'
2464 + {
2465 +  ConfigFileEntry.max_watch = $3;
2466 + };
2467  
2468 < general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2468 > general_cycle_on_host_change: CYCLE_ON_HOST_CHANGE '=' TBOOL ';'
2469   {
2470 <  ConfigFileEntry.gline_min_cidr = $3;
2470 >  if (conf_parser_ctx.pass == 2)
2471 >    ConfigFileEntry.cycle_on_host_change = yylval.number;
2472   };
2473  
2474 < general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2474 > general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2475   {
2476 <  ConfigFileEntry.gline_min_cidr6 = $3;
2476 >  if (conf_parser_ctx.pass == 2)
2477 >    ConfigFileEntry.glines = yylval.number;
2478   };
2479  
2480 < general_burst_away: BURST_AWAY '=' TBOOL ';'
2480 > general_gline_duration: GLINE_DURATION '=' timespec ';'
2481   {
2482 <  ConfigFileEntry.burst_away = yylval.number;
2482 >  if (conf_parser_ctx.pass == 2)
2483 >    ConfigFileEntry.gline_time = $3;
2484   };
2485  
2486 < general_use_whois_actually: USE_WHOIS_ACTUALLY '=' TBOOL ';'
2486 > general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2487   {
2488 <  ConfigFileEntry.use_whois_actually = yylval.number;
2488 >  if (conf_parser_ctx.pass == 2)
2489 >    ConfigFileEntry.gline_request_time = $3;
2490   };
2491  
2492 < general_reject_hold_time: TREJECT_HOLD_TIME '=' timespec ';'
2492 > general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2493   {
2494 <  GlobalSetOptions.rejecttime = yylval.number;
2494 >  ConfigFileEntry.gline_min_cidr = $3;
2495 > };
2496 >
2497 > general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2498 > {
2499 >  ConfigFileEntry.gline_min_cidr6 = $3;
2500   };
2501  
2502   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
# Line 3212 | Line 2504 | general_tkline_expire_notices: TKLINE_EX
2504    ConfigFileEntry.tkline_expire_notices = yylval.number;
2505   };
2506  
2507 < general_kill_chase_time_limit: KILL_CHASE_TIME_LIMIT '=' NUMBER ';'
2507 > general_kill_chase_time_limit: KILL_CHASE_TIME_LIMIT '=' timespec ';'
2508   {
2509    ConfigFileEntry.kill_chase_time_limit = $3;
2510   };
# Line 3227 | Line 2519 | general_ignore_bogus_ts: IGNORE_BOGUS_TS
2519    ConfigFileEntry.ignore_bogus_ts = yylval.number;
2520   };
2521  
3230 general_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
3231 {
3232  ConfigFileEntry.disable_remote = yylval.number;
3233 };
3234
2522   general_failed_oper_notice: FAILED_OPER_NOTICE '=' TBOOL ';'
2523   {
2524    ConfigFileEntry.failed_oper_notice = yylval.number;
# Line 3244 | Line 2531 | general_anti_nick_flood: ANTI_NICK_FLOOD
2531  
2532   general_max_nick_time: MAX_NICK_TIME '=' timespec ';'
2533   {
2534 <  ConfigFileEntry.max_nick_time = $3;
2534 >  ConfigFileEntry.max_nick_time = $3;
2535   };
2536  
2537   general_max_nick_changes: MAX_NICK_CHANGES '=' NUMBER ';'
# Line 3269 | Line 2556 | general_ts_warn_delta: TS_WARN_DELTA '='
2556  
2557   general_ts_max_delta: TS_MAX_DELTA '=' timespec ';'
2558   {
2559 <  if (ypass == 2)
2559 >  if (conf_parser_ctx.pass == 2)
2560      ConfigFileEntry.ts_max_delta = $3;
2561   };
2562  
2563   general_havent_read_conf: HAVENT_READ_CONF '=' NUMBER ';'
2564   {
2565 <  if (($3 > 0) && ypass == 1)
2565 >  if (($3 > 0) && conf_parser_ctx.pass == 1)
2566    {
2567 <    ilog(L_CRIT, "You haven't read your config file properly.");
2568 <    ilog(L_CRIT, "There is a line in the example conf that will kill your server if not removed.");
2569 <    ilog(L_CRIT, "Consider actually reading/editing the conf file, and removing this line.");
2567 >    ilog(LOG_TYPE_IRCD, "You haven't read your config file properly.");
2568 >    ilog(LOG_TYPE_IRCD, "There is a line in the example conf that will kill your server if not removed.");
2569 >    ilog(LOG_TYPE_IRCD, "Consider actually reading/editing the conf file, and removing this line.");
2570      exit(0);
2571    }
2572   };
2573  
3287 general_kline_with_reason: KLINE_WITH_REASON '=' TBOOL ';'
3288 {
3289  ConfigFileEntry.kline_with_reason = yylval.number;
3290 };
3291
3292 general_kline_reason: KLINE_REASON '=' QSTRING ';'
3293 {
3294  if (ypass == 2)
3295  {
3296    MyFree(ConfigFileEntry.kline_reason);
3297    DupString(ConfigFileEntry.kline_reason, yylval.string);
3298  }
3299 };
3300
2574   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2575   {
2576    ConfigFileEntry.invisible_on_connect = yylval.number;
# Line 3323 | Line 2596 | general_stats_P_oper_only: STATS_P_OPER_
2596    ConfigFileEntry.stats_P_oper_only = yylval.number;
2597   };
2598  
2599 + general_stats_u_oper_only: STATS_U_OPER_ONLY '=' TBOOL ';'
2600 + {
2601 +  ConfigFileEntry.stats_u_oper_only = yylval.number;
2602 + };
2603 +
2604   general_stats_k_oper_only: STATS_K_OPER_ONLY '=' TBOOL ';'
2605   {
2606    ConfigFileEntry.stats_k_oper_only = 2 * yylval.number;
# Line 3363 | Line 2641 | general_short_motd: SHORT_MOTD '=' TBOOL
2641   {
2642    ConfigFileEntry.short_motd = yylval.number;
2643   };
2644 <  
2644 >
2645   general_no_oper_flood: NO_OPER_FLOOD '=' TBOOL ';'
2646   {
2647    ConfigFileEntry.no_oper_flood = yylval.number;
# Line 3379 | Line 2657 | general_oper_pass_resv: OPER_PASS_RESV '
2657    ConfigFileEntry.oper_pass_resv = yylval.number;
2658   };
2659  
3382 general_message_locale: MESSAGE_LOCALE '=' QSTRING ';'
3383 {
3384  if (ypass == 2)
3385  {
3386    if (strlen(yylval.string) > LOCALE_LENGTH-2)
3387      yylval.string[LOCALE_LENGTH-1] = '\0';
3388
3389    set_locale(yylval.string);
3390  }
3391 };
3392
3393 general_idletime: IDLETIME '=' timespec ';'
3394 {
3395  ConfigFileEntry.idletime = $3;
3396 };
3397
2660   general_dots_in_ident: DOTS_IN_IDENT '=' NUMBER ';'
2661   {
2662    ConfigFileEntry.dots_in_ident = $3;
# Line 3405 | Line 2667 | general_max_targets: MAX_TARGETS '=' NUM
2667    ConfigFileEntry.max_targets = $3;
2668   };
2669  
2670 < general_servlink_path: SERVLINK_PATH '=' QSTRING ';'
3409 < {
3410 <  if (ypass == 2)
3411 <  {
3412 <    MyFree(ConfigFileEntry.servlink_path);
3413 <    DupString(ConfigFileEntry.servlink_path, yylval.string);
3414 <  }
3415 < };
3416 <
3417 < general_default_cipher_preference: DEFAULT_CIPHER_PREFERENCE '=' QSTRING ';'
2670 > general_use_egd: USE_EGD '=' TBOOL ';'
2671   {
2672 < #ifdef HAVE_LIBCRYPTO
3420 <  if (ypass == 2)
3421 <  {
3422 <    struct EncCapability *ecap;
3423 <    const char *cipher_name;
3424 <    int found = 0;
3425 <
3426 <    ConfigFileEntry.default_cipher_preference = NULL;
3427 <    cipher_name = yylval.string;
3428 <
3429 <    for (ecap = CipherTable; ecap->name; ecap++)
3430 <    {
3431 <      if ((irccmp(ecap->name, cipher_name) == 0) &&
3432 <          (ecap->cap & CAP_ENC_MASK))
3433 <      {
3434 <        ConfigFileEntry.default_cipher_preference = ecap;
3435 <        found = 1;
3436 <        break;
3437 <      }
3438 <    }
3439 <
3440 <    if (!found)
3441 <      yyerror("Invalid cipher");
3442 <  }
3443 < #else
3444 <  if (ypass == 2)
3445 <    yyerror("Ignoring default_cipher_preference -- no OpenSSL support");
3446 < #endif
2672 >  ConfigFileEntry.use_egd = yylval.number;
2673   };
2674  
2675 < general_compression_level: COMPRESSION_LEVEL '=' NUMBER ';'
2675 > general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
2676   {
2677 <  if (ypass == 2)
2677 >  if (conf_parser_ctx.pass == 2)
2678    {
2679 <    ConfigFileEntry.compression_level = $3;
2680 < #ifndef HAVE_LIBZ
3455 <    yyerror("Ignoring compression_level -- no zlib support");
3456 < #else
3457 <    if ((ConfigFileEntry.compression_level < 1) ||
3458 <        (ConfigFileEntry.compression_level > 9))
3459 <    {
3460 <      yyerror("Ignoring invalid compression_level, using default");
3461 <      ConfigFileEntry.compression_level = 0;
3462 <    }
3463 < #endif
2679 >    MyFree(ConfigFileEntry.egdpool_path);
2680 >    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2681    }
2682   };
2683  
2684 < general_use_egd: USE_EGD '=' TBOOL ';'
2684 > general_services_name: T_SERVICES_NAME '=' QSTRING ';'
2685   {
2686 <  ConfigFileEntry.use_egd = yylval.number;
3470 < };
3471 <
3472 < general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
3473 < {
3474 <  if (ypass == 2)
2686 >  if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2687    {
2688 <    MyFree(ConfigFileEntry.egdpool_path);
2689 <    DupString(ConfigFileEntry.egdpool_path, yylval.string);
2688 >    MyFree(ConfigFileEntry.service_name);
2689 >    ConfigFileEntry.service_name = xstrdup(yylval.string);
2690    }
2691   };
2692  
# Line 3490 | Line 2702 | general_disable_auth: DISABLE_AUTH '=' T
2702  
2703   general_throttle_time: THROTTLE_TIME '=' timespec ';'
2704   {
2705 <  ConfigFileEntry.throttle_time = yylval.number;
2705 >  ConfigFileEntry.throttle_time = $3;
2706   };
2707  
2708   general_oper_umodes: OPER_UMODES
# Line 3514 | Line 2726 | umode_oitem:     T_BOTS
2726   } | T_FULL
2727   {
2728    ConfigFileEntry.oper_umodes |= UMODE_FULL;
2729 + } | HIDDEN
2730 + {
2731 +  ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2732   } | T_SKILL
2733   {
2734    ConfigFileEntry.oper_umodes |= UMODE_SKILL;
# Line 3553 | Line 2768 | umode_oitem:     T_BOTS
2768   } | T_LOCOPS
2769   {
2770    ConfigFileEntry.oper_umodes |= UMODE_LOCOPS;
2771 + } | T_NONONREG
2772 + {
2773 +  ConfigFileEntry.oper_umodes |= UMODE_REGONLY;
2774 + } | T_FARCONNECT
2775 + {
2776 +  ConfigFileEntry.oper_umodes |= UMODE_FARCONNECT;
2777   };
2778  
2779 < general_oper_only_umodes: OPER_ONLY_UMODES
2779 > general_oper_only_umodes: OPER_ONLY_UMODES
2780   {
2781    ConfigFileEntry.oper_only_umodes = 0;
2782   } '='  umode_items ';' ;
2783  
2784   umode_items:    umode_items ',' umode_item | umode_item;
2785 < umode_item:     T_BOTS
2785 > umode_item:     T_BOTS
2786   {
2787    ConfigFileEntry.oper_only_umodes |= UMODE_BOTS;
2788   } | T_CCONN
# Line 3574 | Line 2795 | umode_item:    T_BOTS
2795   {
2796    ConfigFileEntry.oper_only_umodes |= UMODE_DEBUG;
2797   } | T_FULL
2798 < {
2798 > {
2799    ConfigFileEntry.oper_only_umodes |= UMODE_FULL;
2800   } | T_SKILL
2801   {
2802    ConfigFileEntry.oper_only_umodes |= UMODE_SKILL;
2803 + } | HIDDEN
2804 + {
2805 +  ConfigFileEntry.oper_only_umodes |= UMODE_HIDDEN;
2806   } | T_NCHANGE
2807   {
2808    ConfigFileEntry.oper_only_umodes |= UMODE_NCHANGE;
# Line 3615 | Line 2839 | umode_item:    T_BOTS
2839   } | T_LOCOPS
2840   {
2841    ConfigFileEntry.oper_only_umodes |= UMODE_LOCOPS;
2842 + } | T_NONONREG
2843 + {
2844 +  ConfigFileEntry.oper_only_umodes |= UMODE_REGONLY;
2845 + } | T_FARCONNECT
2846 + {
2847 +  ConfigFileEntry.oper_only_umodes |= UMODE_FARCONNECT;
2848   };
2849  
2850   general_min_nonwildcard: MIN_NONWILDCARD '=' NUMBER ';'
# Line 3632 | Line 2862 | general_default_floodcount: DEFAULT_FLOO
2862    ConfigFileEntry.default_floodcount = $3;
2863   };
2864  
3635 general_client_flood: T_CLIENT_FLOOD '=' sizespec ';'
3636 {
3637  ConfigFileEntry.client_flood = $3;
3638 };
3639
3640 general_dot_in_ip6_addr: DOT_IN_IP6_ADDR '=' TBOOL ';'
3641 {
3642  ConfigFileEntry.dot_in_ip6_addr = yylval.number;
3643 };
3644
3645 /***************************************************************************
3646 *  section glines
3647 ***************************************************************************/
3648 gline_entry: GLINES
3649 {
3650  if (ypass == 2)
3651  {
3652    yy_conf = make_conf_item(GDENY_TYPE);
3653    yy_aconf = map_to_conf(yy_conf);
3654  }
3655 } '{' gline_items '}' ';'
3656 {
3657  if (ypass == 2)
3658  {
3659    /*
3660     * since we re-allocate yy_conf/yy_aconf after the end of action=, at the
3661     * end we will have one extra, so we should free it.
3662     */
3663    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3664    {
3665      delete_conf_item(yy_conf);
3666      yy_conf = NULL;
3667      yy_aconf = NULL;
3668    }
3669  }
3670 };
3671
3672 gline_items:        gline_items gline_item | gline_item;
3673 gline_item:         gline_enable |
3674                    gline_duration |
3675                    gline_logging |
3676                    gline_user |
3677                    gline_server |
3678                    gline_action |
3679                    error;
3680
3681 gline_enable: ENABLE '=' TBOOL ';'
3682 {
3683  if (ypass == 2)
3684    ConfigFileEntry.glines = yylval.number;
3685 };
3686
3687 gline_duration: DURATION '=' timespec ';'
3688 {
3689  if (ypass == 2)
3690    ConfigFileEntry.gline_time = $3;
3691 };
3692
3693 gline_logging: LOGGING
3694 {
3695  if (ypass == 2)
3696    ConfigFileEntry.gline_logging = 0;
3697 } '=' gline_logging_types ';';
3698 gline_logging_types:     gline_logging_types ',' gline_logging_type_item | gline_logging_type_item;
3699 gline_logging_type_item: T_REJECT
3700 {
3701  if (ypass == 2)
3702    ConfigFileEntry.gline_logging |= GDENY_REJECT;
3703 } | T_BLOCK
3704 {
3705  if (ypass == 2)
3706    ConfigFileEntry.gline_logging |= GDENY_BLOCK;
3707 };
3708
3709 gline_user: USER '=' QSTRING ';'
3710 {
3711  if (ypass == 2)
3712  {
3713    struct split_nuh_item nuh;
3714
3715    nuh.nuhmask  = yylval.string;
3716    nuh.nickptr  = NULL;
3717    nuh.userptr  = userbuf;
3718    nuh.hostptr  = hostbuf;
3719
3720    nuh.nicksize = 0;
3721    nuh.usersize = sizeof(userbuf);
3722    nuh.hostsize = sizeof(hostbuf);
3723
3724    split_nuh(&nuh);
3725
3726    if (yy_aconf->user == NULL)
3727    {
3728      DupString(yy_aconf->user, userbuf);
3729      DupString(yy_aconf->host, hostbuf);
3730    }
3731    else
3732    {
3733      struct CollectItem *yy_tmp = MyMalloc(sizeof(struct CollectItem));
3734
3735      DupString(yy_tmp->user, userbuf);
3736      DupString(yy_tmp->host, hostbuf);
3737
3738      dlinkAdd(yy_tmp, &yy_tmp->node, &col_conf_list);
3739    }
3740  }
3741 };
3742
3743 gline_server: NAME '=' QSTRING ';'
3744 {
3745  if (ypass == 2)  
3746  {
3747    MyFree(yy_conf->name);
3748    DupString(yy_conf->name, yylval.string);
3749  }
3750 };
3751
3752 gline_action: ACTION
3753 {
3754  if (ypass == 2)
3755    yy_aconf->flags = 0;
3756 } '=' gdeny_types ';'
3757 {
3758  if (ypass == 2)
3759  {
3760    struct CollectItem *yy_tmp = NULL;
3761    dlink_node *ptr, *next_ptr;
3762
3763    DLINK_FOREACH_SAFE(ptr, next_ptr, col_conf_list.head)
3764    {
3765      struct AccessItem *new_aconf;
3766      struct ConfItem *new_conf;
3767
3768      yy_tmp = ptr->data;
3769      new_conf = make_conf_item(GDENY_TYPE);
3770      new_aconf = map_to_conf(new_conf);
3771
3772      new_aconf->flags = yy_aconf->flags;
3773
3774      if (yy_conf->name != NULL)
3775        DupString(new_conf->name, yy_conf->name);
3776      else
3777        DupString(new_conf->name, "*");
3778      if (yy_aconf->user != NULL)
3779         DupString(new_aconf->user, yy_tmp->user);
3780      else  
3781        DupString(new_aconf->user, "*");
3782      if (yy_aconf->host != NULL)
3783        DupString(new_aconf->host, yy_tmp->host);
3784      else
3785        DupString(new_aconf->host, "*");
3786
3787      dlinkDelete(&yy_tmp->node, &col_conf_list);
3788    }
3789
3790    /*
3791     * In case someone has fed us with more than one action= after user/name
3792     * which would leak memory  -Michael
3793     */
3794    if (yy_conf->name == NULL || yy_aconf->user == NULL)
3795      delete_conf_item(yy_conf);
3796
3797    yy_conf = make_conf_item(GDENY_TYPE);
3798    yy_aconf = map_to_conf(yy_conf);
3799  }
3800 };
3801
3802 gdeny_types: gdeny_types ',' gdeny_type_item | gdeny_type_item;
3803 gdeny_type_item: T_REJECT
3804 {
3805  if (ypass == 2)
3806    yy_aconf->flags |= GDENY_REJECT;
3807 } | T_BLOCK
3808 {
3809  if (ypass == 2)
3810    yy_aconf->flags |= GDENY_BLOCK;
3811 };
2865  
2866   /***************************************************************************
2867   *  section channel
# Line 3817 | Line 2870 | channel_entry: CHANNEL
2870    '{' channel_items '}' ';';
2871  
2872   channel_items:      channel_items channel_item | channel_item;
2873 < channel_item:       channel_disable_local_channels | channel_use_except |
2874 <                    channel_use_invex | channel_use_knock |
2875 <                    channel_max_bans | channel_knock_delay |
2876 <                    channel_knock_delay_channel | channel_max_chans_per_user |
3824 <                    channel_quiet_on_ban | channel_default_split_user_count |
2873 > channel_item:       channel_max_bans |
2874 >                    channel_knock_delay | channel_knock_delay_channel |
2875 >                    channel_max_chans_per_user | channel_max_chans_per_oper |
2876 >                    channel_default_split_user_count |
2877                      channel_default_split_server_count |
2878 <                    channel_no_create_on_split | channel_restrict_channels |
2879 <                    channel_no_join_on_split | channel_burst_topicwho |
2878 >                    channel_no_create_on_split |
2879 >                    channel_no_join_on_split |
2880                      channel_jflood_count | channel_jflood_time |
2881 <                    error;
2881 >                    channel_disable_fake_channels | error;
2882  
2883 < channel_restrict_channels: RESTRICT_CHANNELS '=' TBOOL ';'
2883 > channel_disable_fake_channels: DISABLE_FAKE_CHANNELS '=' TBOOL ';'
2884   {
2885 <  ConfigChannel.restrict_channels = yylval.number;
3834 < };
3835 <
3836 < channel_disable_local_channels: DISABLE_LOCAL_CHANNELS '=' TBOOL ';'
3837 < {
3838 <  ConfigChannel.disable_local_channels = yylval.number;
3839 < };
3840 <
3841 < channel_use_except: USE_EXCEPT '=' TBOOL ';'
3842 < {
3843 <  ConfigChannel.use_except = yylval.number;
3844 < };
3845 <
3846 < channel_use_invex: USE_INVEX '=' TBOOL ';'
3847 < {
3848 <  ConfigChannel.use_invex = yylval.number;
3849 < };
3850 <
3851 < channel_use_knock: USE_KNOCK '=' TBOOL ';'
3852 < {
3853 <  ConfigChannel.use_knock = yylval.number;
2885 >  ConfigChannel.disable_fake_channels = yylval.number;
2886   };
2887  
2888   channel_knock_delay: KNOCK_DELAY '=' timespec ';'
# Line 3868 | Line 2900 | channel_max_chans_per_user: MAX_CHANS_PE
2900    ConfigChannel.max_chans_per_user = $3;
2901   };
2902  
2903 < channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
2903 > channel_max_chans_per_oper: MAX_CHANS_PER_OPER '=' NUMBER ';'
2904   {
2905 <  ConfigChannel.quiet_on_ban = yylval.number;
2905 >  ConfigChannel.max_chans_per_oper = $3;
2906   };
2907  
2908   channel_max_bans: MAX_BANS '=' NUMBER ';'
# Line 3898 | Line 2930 | channel_no_join_on_split: NO_JOIN_ON_SPL
2930    ConfigChannel.no_join_on_split = yylval.number;
2931   };
2932  
3901 channel_burst_topicwho: BURST_TOPICWHO '=' TBOOL ';'
3902 {
3903  ConfigChannel.burst_topicwho = yylval.number;
3904 };
3905
2933   channel_jflood_count: JOIN_FLOOD_COUNT '=' NUMBER ';'
2934   {
2935    GlobalSetOptions.joinfloodcount = yylval.number;
# Line 3910 | Line 2937 | channel_jflood_count: JOIN_FLOOD_COUNT '
2937  
2938   channel_jflood_time: JOIN_FLOOD_TIME '=' timespec ';'
2939   {
2940 <  GlobalSetOptions.joinfloodtime = yylval.number;
2940 >  GlobalSetOptions.joinfloodtime = $3;
2941   };
2942  
2943   /***************************************************************************
# Line 3920 | Line 2947 | serverhide_entry: SERVERHIDE
2947    '{' serverhide_items '}' ';';
2948  
2949   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
2950 < serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
2950 > serverhide_item:    serverhide_flatten_links | serverhide_disable_remote_commands |
2951 >                    serverhide_hide_servers |
2952 >                    serverhide_hide_services |
2953                      serverhide_links_delay |
3925                    serverhide_disable_hidden |
2954                      serverhide_hidden | serverhide_hidden_name |
2955                      serverhide_hide_server_ips |
2956                      error;
2957  
2958   serverhide_flatten_links: FLATTEN_LINKS '=' TBOOL ';'
2959   {
2960 <  if (ypass == 2)
2960 >  if (conf_parser_ctx.pass == 2)
2961      ConfigServerHide.flatten_links = yylval.number;
2962   };
2963  
2964 + serverhide_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2965 + {
2966 +  if (conf_parser_ctx.pass == 2)
2967 +    ConfigServerHide.disable_remote_commands = yylval.number;
2968 + };
2969 +
2970   serverhide_hide_servers: HIDE_SERVERS '=' TBOOL ';'
2971   {
2972 <  if (ypass == 2)
2972 >  if (conf_parser_ctx.pass == 2)
2973      ConfigServerHide.hide_servers = yylval.number;
2974   };
2975  
2976 + serverhide_hide_services: HIDE_SERVICES '=' TBOOL ';'
2977 + {
2978 +  if (conf_parser_ctx.pass == 2)
2979 +    ConfigServerHide.hide_services = yylval.number;
2980 + };
2981 +
2982   serverhide_hidden_name: HIDDEN_NAME '=' QSTRING ';'
2983   {
2984 <  if (ypass == 2)
2984 >  if (conf_parser_ctx.pass == 2)
2985    {
2986      MyFree(ConfigServerHide.hidden_name);
2987 <    DupString(ConfigServerHide.hidden_name, yylval.string);
2987 >    ConfigServerHide.hidden_name = xstrdup(yylval.string);
2988    }
2989   };
2990  
2991   serverhide_links_delay: LINKS_DELAY '=' timespec ';'
2992   {
2993 <  if (ypass == 2)
2993 >  if (conf_parser_ctx.pass == 2)
2994    {
2995      if (($3 > 0) && ConfigServerHide.links_disabled == 1)
2996      {
# Line 3964 | Line 3004 | serverhide_links_delay: LINKS_DELAY '='
3004  
3005   serverhide_hidden: HIDDEN '=' TBOOL ';'
3006   {
3007 <  if (ypass == 2)
3007 >  if (conf_parser_ctx.pass == 2)
3008      ConfigServerHide.hidden = yylval.number;
3009   };
3010  
3971 serverhide_disable_hidden: DISABLE_HIDDEN '=' TBOOL ';'
3972 {
3973  if (ypass == 2)
3974    ConfigServerHide.disable_hidden = yylval.number;
3975 };
3976
3011   serverhide_hide_server_ips: HIDE_SERVER_IPS '=' TBOOL ';'
3012   {
3013 <  if (ypass == 2)
3013 >  if (conf_parser_ctx.pass == 2)
3014      ConfigServerHide.hide_server_ips = yylval.number;
3015   };

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)