ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf_parser.y
(Generate patch)

Comparing ircd-hybrid/trunk/src/conf_parser.y (file contents):
Revision 1904 by michael, Sat Apr 27 21:16:22 2013 UTC vs.
Revision 4499 by michael, Sat Aug 16 18:29:23 2014 UTC

# Line 1 | Line 1
1   /*
2 < *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  conf_parser.y: Parses the ircd configuration file.
2 > *  ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3   *
4 < *  Copyright (C) 2005 by the past and present ircd coders, and others.
4 > *  Copyright (c) 2000-2014 ircd-hybrid development team
5   *
6   *  This program is free software; you can redistribute it and/or modify
7   *  it under the terms of the GNU General Public License as published by
# Line 18 | Line 17
17   *  along with this program; if not, write to the Free Software
18   *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
19   *  USA
21 *
22 *  $Id$
20   */
21  
22 + /*! \file conf_parser.y
23 + * \brief Parses the ircd configuration file.
24 + * \version $Id$
25 + */
26 +
27 +
28   %{
29  
30   #define YY_NO_UNPUT
# Line 40 | Line 43
43   #include "irc_string.h"
44   #include "memory.h"
45   #include "modules.h"
46 < #include "s_serv.h"
46 > #include "server.h"
47   #include "hostmask.h"
48   #include "send.h"
49   #include "listener.h"
50   #include "resv.h"
51   #include "numeric.h"
52 < #include "s_user.h"
52 > #include "user.h"
53 > #include "motd.h"
54  
55   #ifdef HAVE_LIBCRYPTO
56   #include <openssl/rsa.h>
# Line 61 | Line 65 | int yylex(void);
65  
66   static struct
67   {
68 <  struct {
68 >  struct
69 >  {
70      dlink_list list;
71    } mask,
72      leaf,
73      hub;
74  
75 <  struct {
75 >  struct
76 >  {
77      char buf[IRCD_BUFSIZE];
78    } name,
79      user,
# Line 76 | Line 82 | static struct
82      bind,
83      file,
84      ciph,
85 +    cert,
86      rpass,
87      spass,
88      class;
89  
90 <  struct {
90 >  struct
91 >  {
92      unsigned int value;
93    } flags,
94      modes,
# Line 99 | Line 107 | static struct
107      max_ident,
108      max_sendq,
109      max_recvq,
110 +    max_channels,
111      cidr_bitlen_ipv4,
112      cidr_bitlen_ipv6,
113      number_per_cidr;
# Line 146 | Line 155 | reset_block_state(void)
155   %token  ANTI_NICK_FLOOD
156   %token  ANTI_SPAM_EXIT_MESSAGE_TIME
157   %token  AUTOCONN
158 + %token  AWAY_COUNT
159 + %token  AWAY_TIME
160   %token  BYTES KBYTES MBYTES
161   %token  CALLER_ID_WAIT
162   %token  CAN_FLOOD
163   %token  CHANNEL
164 < %token  CIDR_BITLEN_IPV4
165 < %token  CIDR_BITLEN_IPV6
164 > %token  CIDR_BITLEN_IPV4
165 > %token  CIDR_BITLEN_IPV6
166   %token  CLASS
167   %token  CONNECT
168   %token  CONNECTFREQ
169 + %token  CYCLE_ON_HOST_CHANGE
170   %token  DEFAULT_FLOODCOUNT
171   %token  DEFAULT_SPLIT_SERVER_COUNT
172   %token  DEFAULT_SPLIT_USER_COUNT
# Line 171 | Line 183 | reset_block_state(void)
183   %token  EXCEED_LIMIT
184   %token  EXEMPT
185   %token  FAILED_OPER_NOTICE
174 %token  IRCD_FLAGS
186   %token  FLATTEN_LINKS
187   %token  GECOS
188   %token  GENERAL
# Line 179 | Line 190 | reset_block_state(void)
190   %token  GLINE_DURATION
191   %token  GLINE_ENABLE
192   %token  GLINE_EXEMPT
182 %token  GLINE_REQUEST_DURATION
193   %token  GLINE_MIN_CIDR
194   %token  GLINE_MIN_CIDR6
195 + %token  GLINE_REQUEST_DURATION
196   %token  GLOBAL_KILL
186 %token  IRCD_AUTH
187 %token  NEED_IDENT
197   %token  HAVENT_READ_CONF
198   %token  HIDDEN
199 < %token  HIDDEN_NAME
199 > %token  HIDDEN_NAME
200 > %token  HIDE_CHANS
201 > %token  HIDE_IDLE
202 > %token  HIDE_IDLE_FROM_OPERS
203   %token  HIDE_SERVER_IPS
204   %token  HIDE_SERVERS
205   %token  HIDE_SERVICES
206 < %token  HIDE_SPOOF_IPS
206 > %token  HIDE_SPOOF_IPS
207   %token  HOST
208   %token  HUB
209   %token  HUB_MASK
210   %token  IGNORE_BOGUS_TS
211   %token  INVISIBLE_ON_CONNECT
212 + %token  INVITE_CLIENT_COUNT
213 + %token  INVITE_CLIENT_TIME
214   %token  IP
215 + %token  IRCD_AUTH
216 + %token  IRCD_FLAGS
217 + %token  IRCD_SID
218 + %token  JOIN_FLOOD_COUNT
219 + %token  JOIN_FLOOD_TIME
220   %token  KILL
221 < %token  KILL_CHASE_TIME_LIMIT
221 > %token  KILL_CHASE_TIME_LIMIT
222   %token  KLINE
223   %token  KLINE_EXEMPT
224 < %token  KNOCK_DELAY
224 > %token  KNOCK_CLIENT_COUNT
225 > %token  KNOCK_CLIENT_TIME
226   %token  KNOCK_DELAY_CHANNEL
227   %token  LEAF_MASK
228   %token  LINKS_DELAY
229   %token  LISTEN
210 %token  T_LOG
230   %token  MASK
231   %token  MAX_ACCEPT
232   %token  MAX_BANS
233 < %token  MAX_CHANS_PER_OPER
215 < %token  MAX_CHANS_PER_USER
233 > %token  MAX_CHANNELS
234   %token  MAX_GLOBAL
235   %token  MAX_IDENT
236 + %token  MAX_IDLE
237   %token  MAX_LOCAL
238   %token  MAX_NICK_CHANGES
239   %token  MAX_NICK_LENGTH
# Line 223 | Line 242 | reset_block_state(void)
242   %token  MAX_TARGETS
243   %token  MAX_TOPIC_LENGTH
244   %token  MAX_WATCH
245 + %token  MIN_IDLE
246   %token  MIN_NONWILDCARD
247   %token  MIN_NONWILDCARD_SIMPLE
228 %token  MIN_IDLE
229 %token  MAX_IDLE
230 %token  RANDOM_IDLE
231 %token  HIDE_IDLE_FROM_OPERS
248   %token  MODULE
249   %token  MODULES
250 + %token  MOTD
251   %token  NAME
252 + %token  NEED_IDENT
253   %token  NEED_PASSWORD
254   %token  NETWORK_DESC
255   %token  NETWORK_NAME
# Line 243 | Line 261 | reset_block_state(void)
261   %token  NUMBER
262   %token  NUMBER_PER_CIDR
263   %token  NUMBER_PER_IP
246 %token  OPERATOR
247 %token  OPERS_BYPASS_CALLERID
264   %token  OPER_ONLY_UMODES
265   %token  OPER_PASS_RESV
250 %token  OPER_SPY_T
266   %token  OPER_UMODES
267 < %token  JOIN_FLOOD_COUNT
268 < %token  JOIN_FLOOD_TIME
267 > %token  OPERATOR
268 > %token  OPERS_BYPASS_CALLERID
269   %token  PACE_WAIT
270   %token  PACE_WAIT_SIMPLE
271   %token  PASSWORD
# Line 259 | Line 274 | reset_block_state(void)
274   %token  PING_TIME
275   %token  PORT
276   %token  QSTRING
277 < %token  QUIET_ON_BAN
277 > %token  RANDOM_IDLE
278   %token  REASON
279   %token  REDIRPORT
280   %token  REDIRSERV
266 %token  REGEX_T
281   %token  REHASH
282   %token  REMOTE
283   %token  REMOTEBAN
270 %token  RSA_PRIVATE_KEY_FILE
271 %token  RSA_PUBLIC_KEY_FILE
272 %token  SSL_CERTIFICATE_FILE
273 %token  SSL_DH_PARAM_FILE
274 %token  T_SSL_CLIENT_METHOD
275 %token  T_SSL_SERVER_METHOD
276 %token  T_SSLV3
277 %token  T_TLSV1
284   %token  RESV
285   %token  RESV_EXEMPT
286 + %token  RSA_PRIVATE_KEY_FILE
287 + %token  RSA_PUBLIC_KEY_FILE
288   %token  SECONDS MINUTES HOURS DAYS WEEKS MONTHS YEARS
281 %token  SENDQ
289   %token  SEND_PASSWORD
290 + %token  SENDQ
291   %token  SERVERHIDE
292   %token  SERVERINFO
285 %token  IRCD_SID
286 %token  TKLINE_EXPIRE_NOTICES
287 %token  T_SHARED
288 %token  T_CLUSTER
289 %token  TYPE
293   %token  SHORT_MOTD
294   %token  SPOOF
295   %token  SPOOF_NOTICE
296 + %token  SQUIT
297 + %token  SSL_CERTIFICATE_FILE
298 + %token  SSL_CERTIFICATE_FINGERPRINT
299 + %token  SSL_CONNECTION_REQUIRED
300 + %token  SSL_DH_ELLIPTIC_CURVE
301 + %token  SSL_DH_PARAM_FILE
302 + %token  SSL_MESSAGE_DIGEST_ALGORITHM
303   %token  STATS_E_DISABLED
304   %token  STATS_I_OPER_ONLY
305   %token  STATS_K_OPER_ONLY
306   %token  STATS_O_OPER_ONLY
307   %token  STATS_P_OPER_ONLY
308 < %token  TBOOL
299 < %token  TMASKED
300 < %token  TS_MAX_DELTA
301 < %token  TS_WARN_DELTA
302 < %token  TWODOTS
308 > %token  STATS_U_OPER_ONLY
309   %token  T_ALL
310   %token  T_BOTS
305 %token  T_SOFTCALLERID
311   %token  T_CALLERID
312   %token  T_CCONN
313 < %token  T_CCONN_FULL
309 < %token  T_SSL_CIPHER_LIST
313 > %token  T_CLUSTER
314   %token  T_DEAF
315   %token  T_DEBUG
316   %token  T_DLINE
317   %token  T_EXTERNAL
318 + %token  T_FARCONNECT
319 + %token  T_FILE
320   %token  T_FULL
321 + %token  T_GLOBOPS
322   %token  T_INVISIBLE
323   %token  T_IPV4
324   %token  T_IPV6
325   %token  T_LOCOPS
326 + %token  T_LOG
327   %token  T_MAX_CLIENTS
328   %token  T_NCHANGE
329   %token  T_NONONREG
322 %token  T_OPERWALL
330   %token  T_RECVQ
331   %token  T_REJ
332 + %token  T_RESTART
333   %token  T_SERVER
334 + %token  T_SERVICE
335 + %token  T_SERVICES_NAME
336   %token  T_SERVNOTICE
337   %token  T_SET
338 + %token  T_SHARED
339 + %token  T_SIZE
340   %token  T_SKILL
341 + %token  T_SOFTCALLERID
342   %token  T_SPY
343   %token  T_SSL
344 + %token  T_SSL_CIPHER_LIST
345   %token  T_UMODES
346   %token  T_UNAUTH
347   %token  T_UNDLINE
348   %token  T_UNLIMITED
349   %token  T_UNRESV
350   %token  T_UNXLINE
337 %token  T_GLOBOPS
351   %token  T_WALLOP
352 + %token  T_WALLOPS
353   %token  T_WEBIRC
354 < %token  T_RESTART
355 < %token  T_SERVICE
342 < %token  T_SERVICES_NAME
354 > %token  TBOOL
355 > %token  THROTTLE_COUNT
356   %token  THROTTLE_TIME
357 + %token  TKLINE_EXPIRE_NOTICES
358 + %token  TMASKED
359   %token  TRUE_NO_OPER_FLOOD
360 + %token  TS_MAX_DELTA
361 + %token  TS_WARN_DELTA
362 + %token  TWODOTS
363 + %token  TYPE
364   %token  UNKLINE
346 %token  USER
365   %token  USE_EGD
366   %token  USE_LOGGING
367 + %token  USER
368   %token  VHOST
369   %token  VHOST6
370 + %token  WARN_NO_CONNECT_BLOCK
371   %token  XLINE
352 %token  WARN_NO_NLINE
353 %token  T_SIZE
354 %token  T_FILE
372  
373 < %type <string> QSTRING
374 < %type <number> NUMBER
375 < %type <number> timespec
376 < %type <number> timespec_
377 < %type <number> sizespec
378 < %type <number> sizespec_
373 > %type  <string> QSTRING
374 > %type  <number> NUMBER
375 > %type  <number> timespec
376 > %type  <number> timespec_
377 > %type  <number> sizespec
378 > %type  <number> sizespec_
379  
380   %%
381 < conf:  
381 > conf:
382          | conf conf_item
383          ;
384  
385   conf_item:        admin_entry
386                  | logging_entry
387                  | oper_entry
388 <                | channel_entry
389 <                | class_entry
388 >                | channel_entry
389 >                | class_entry
390                  | listen_entry
391                  | auth_entry
392                  | serverinfo_entry
393 <                | serverhide_entry
393 >                | serverhide_entry
394                  | resv_entry
395                  | service_entry
396                  | shared_entry
397 <                | cluster_entry
397 >                | cluster_entry
398                  | connect_entry
399                  | kill_entry
400                  | deny_entry
401 <                | exempt_entry
402 <                | general_entry
401 >                | exempt_entry
402 >                | general_entry
403                  | gecos_entry
404                  | modules_entry
405 +                | motd_entry
406                  | error ';'
407                  | error '}'
408          ;
409  
410  
411   timespec_: { $$ = 0; } | timespec;
412 < timespec:       NUMBER timespec_
413 <                {
414 <                        $$ = $1 + $2;
415 <                }
416 <                | NUMBER SECONDS timespec_
417 <                {
418 <                        $$ = $1 + $3;
419 <                }
420 <                | NUMBER MINUTES timespec_
421 <                {
422 <                        $$ = $1 * 60 + $3;
423 <                }
424 <                | NUMBER HOURS timespec_
425 <                {
426 <                        $$ = $1 * 60 * 60 + $3;
427 <                }
410 <                | NUMBER DAYS timespec_
411 <                {
412 <                        $$ = $1 * 60 * 60 * 24 + $3;
413 <                }
414 <                | NUMBER WEEKS timespec_
415 <                {
416 <                        $$ = $1 * 60 * 60 * 24 * 7 + $3;
417 <                }
418 <                | NUMBER MONTHS timespec_
419 <                {
420 <                        $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3;
421 <                }
422 <                | NUMBER YEARS timespec_
423 <                {
424 <                        $$ = $1 * 60 * 60 * 24 * 365 + $3;
425 <                }
426 <                ;
427 <
428 < sizespec_:      { $$ = 0; } | sizespec;
429 < sizespec:       NUMBER sizespec_ { $$ = $1 + $2; }
430 <                | NUMBER BYTES sizespec_ { $$ = $1 + $3; }
431 <                | NUMBER KBYTES sizespec_ { $$ = $1 * 1024 + $3; }
432 <                | NUMBER MBYTES sizespec_ { $$ = $1 * 1024 * 1024 + $3; }
433 <                ;
412 > timespec:  NUMBER timespec_         { $$ = $1 + $2; } |
413 >           NUMBER SECONDS timespec_ { $$ = $1 + $3; } |
414 >           NUMBER MINUTES timespec_ { $$ = $1 * 60 + $3; } |
415 >           NUMBER HOURS timespec_   { $$ = $1 * 60 * 60 + $3; } |
416 >           NUMBER DAYS timespec_    { $$ = $1 * 60 * 60 * 24 + $3; } |
417 >           NUMBER WEEKS timespec_   { $$ = $1 * 60 * 60 * 24 * 7 + $3; } |
418 >           NUMBER MONTHS timespec_  { $$ = $1 * 60 * 60 * 24 * 7 * 4 + $3; } |
419 >           NUMBER YEARS timespec_   { $$ = $1 * 60 * 60 * 24 * 365 + $3; }
420 >           ;
421 >
422 > sizespec_:  { $$ = 0; } | sizespec;
423 > sizespec:   NUMBER sizespec_ { $$ = $1 + $2; } |
424 >            NUMBER BYTES sizespec_ { $$ = $1 + $3; } |
425 >            NUMBER KBYTES sizespec_ { $$ = $1 * 1024 + $3; } |
426 >            NUMBER MBYTES sizespec_ { $$ = $1 * 1024 * 1024 + $3; }
427 >            ;
428  
429  
430   /***************************************************************************
# Line 458 | Line 452 | modules_path: PATH '=' QSTRING ';'
452   serverinfo_entry: SERVERINFO '{' serverinfo_items '}' ';';
453  
454   serverinfo_items:       serverinfo_items serverinfo_item | serverinfo_item ;
455 < serverinfo_item:        serverinfo_name | serverinfo_vhost |
456 <                        serverinfo_hub | serverinfo_description |
457 <                        serverinfo_network_name | serverinfo_network_desc |
458 <                        serverinfo_max_clients | serverinfo_max_nick_length |
459 <                        serverinfo_max_topic_length | serverinfo_ssl_dh_param_file |
460 <                        serverinfo_rsa_private_key_file | serverinfo_vhost6 |
461 <                        serverinfo_sid | serverinfo_ssl_certificate_file |
462 <                        serverinfo_ssl_client_method | serverinfo_ssl_server_method |
455 > serverinfo_item:        serverinfo_name |
456 >                        serverinfo_vhost |
457 >                        serverinfo_hub |
458 >                        serverinfo_description |
459 >                        serverinfo_network_name |
460 >                        serverinfo_network_desc |
461 >                        serverinfo_max_clients |
462 >                        serverinfo_max_nick_length |
463 >                        serverinfo_max_topic_length |
464 >                        serverinfo_ssl_dh_param_file |
465 >                        serverinfo_ssl_dh_elliptic_curve |
466 >                        serverinfo_rsa_private_key_file |
467 >                        serverinfo_vhost6 |
468 >                        serverinfo_sid |
469 >                        serverinfo_ssl_certificate_file |
470                          serverinfo_ssl_cipher_list |
471 <                        error ';' ;
472 <
471 >                        serverinfo_ssl_message_digest_algorithm |
472 >                        error ';' ;
473  
473 serverinfo_ssl_client_method: T_SSL_CLIENT_METHOD '=' client_method_types ';' ;
474 serverinfo_ssl_server_method: T_SSL_SERVER_METHOD '=' server_method_types ';' ;
475
476 client_method_types: client_method_types ',' client_method_type_item | client_method_type_item;
477 client_method_type_item: T_SSLV3
478 {
479 #ifdef HAVE_LIBCRYPTO
480  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
481    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv3);
482 #endif
483 } | T_TLSV1
484 {
485 #ifdef HAVE_LIBCRYPTO
486  if (conf_parser_ctx.pass == 2 && ServerInfo.client_ctx)
487    SSL_CTX_clear_options(ServerInfo.client_ctx, SSL_OP_NO_TLSv1);
488 #endif
489 };
490
491 server_method_types: server_method_types ',' server_method_type_item | server_method_type_item;
492 server_method_type_item: T_SSLV3
493 {
494 #ifdef HAVE_LIBCRYPTO
495  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
496    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv3);
497 #endif
498 } | T_TLSV1
499 {
500 #ifdef HAVE_LIBCRYPTO
501  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
502    SSL_CTX_clear_options(ServerInfo.server_ctx, SSL_OP_NO_TLSv1);
503 #endif
504 };
474  
475   serverinfo_ssl_certificate_file: SSL_CERTIFICATE_FILE '=' QSTRING ';'
476   {
477   #ifdef HAVE_LIBCRYPTO
478 <  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
478 >  if (conf_parser_ctx.pass == 2)
479    {
480 <    if (!ServerInfo.rsa_private_key_file)
480 >    if (!ConfigServerInfo.rsa_private_key_file)
481      {
482        conf_error_report("No rsa_private_key_file specified, SSL disabled");
483        break;
484      }
485  
486 <    if (SSL_CTX_use_certificate_file(ServerInfo.server_ctx, yylval.string,
486 >    if (SSL_CTX_use_certificate_file(ConfigServerInfo.server_ctx, yylval.string,
487                                       SSL_FILETYPE_PEM) <= 0 ||
488 <        SSL_CTX_use_certificate_file(ServerInfo.client_ctx, yylval.string,
488 >        SSL_CTX_use_certificate_file(ConfigServerInfo.client_ctx, yylval.string,
489                                       SSL_FILETYPE_PEM) <= 0)
490      {
491        report_crypto_errors();
# Line 524 | Line 493 | serverinfo_ssl_certificate_file: SSL_CER
493        break;
494      }
495  
496 <    if (SSL_CTX_use_PrivateKey_file(ServerInfo.server_ctx, ServerInfo.rsa_private_key_file,
496 >    if (SSL_CTX_use_PrivateKey_file(ConfigServerInfo.server_ctx, ConfigServerInfo.rsa_private_key_file,
497                                      SSL_FILETYPE_PEM) <= 0 ||
498 <        SSL_CTX_use_PrivateKey_file(ServerInfo.client_ctx, ServerInfo.rsa_private_key_file,
498 >        SSL_CTX_use_PrivateKey_file(ConfigServerInfo.client_ctx, ConfigServerInfo.rsa_private_key_file,
499                                      SSL_FILETYPE_PEM) <= 0)
500      {
501        report_crypto_errors();
# Line 534 | Line 503 | serverinfo_ssl_certificate_file: SSL_CER
503        break;
504      }
505  
506 <    if (!SSL_CTX_check_private_key(ServerInfo.server_ctx) ||
507 <        !SSL_CTX_check_private_key(ServerInfo.client_ctx))
506 >    if (!SSL_CTX_check_private_key(ConfigServerInfo.server_ctx) ||
507 >        !SSL_CTX_check_private_key(ConfigServerInfo.client_ctx))
508      {
509        report_crypto_errors();
510        conf_error_report("Could not read RSA private key");
# Line 548 | Line 517 | serverinfo_ssl_certificate_file: SSL_CER
517   serverinfo_rsa_private_key_file: RSA_PRIVATE_KEY_FILE '=' QSTRING ';'
518   {
519   #ifdef HAVE_LIBCRYPTO
520 <  if (conf_parser_ctx.pass == 1)
552 <  {
553 <    BIO *file;
520 >  BIO *file = NULL;
521  
522 <    if (ServerInfo.rsa_private_key)
523 <    {
557 <      RSA_free(ServerInfo.rsa_private_key);
558 <      ServerInfo.rsa_private_key = NULL;
559 <    }
522 >  if (conf_parser_ctx.pass != 1)
523 >    break;
524  
525 <    if (ServerInfo.rsa_private_key_file)
526 <    {
527 <      MyFree(ServerInfo.rsa_private_key_file);
528 <      ServerInfo.rsa_private_key_file = NULL;
529 <    }
525 >  if (ConfigServerInfo.rsa_private_key)
526 >  {
527 >    RSA_free(ConfigServerInfo.rsa_private_key);
528 >    ConfigServerInfo.rsa_private_key = NULL;
529 >  }
530  
531 <    ServerInfo.rsa_private_key_file = xstrdup(yylval.string);
531 >  if (ConfigServerInfo.rsa_private_key_file)
532 >  {
533 >    MyFree(ConfigServerInfo.rsa_private_key_file);
534 >    ConfigServerInfo.rsa_private_key_file = NULL;
535 >  }
536  
537 <    if ((file = BIO_new_file(yylval.string, "r")) == NULL)
570 <    {
571 <      conf_error_report("File open failed, ignoring");
572 <      break;
573 <    }
537 >  ConfigServerInfo.rsa_private_key_file = xstrdup(yylval.string);
538  
539 <    ServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
539 >  if ((file = BIO_new_file(yylval.string, "r")) == NULL)
540 >  {
541 >    conf_error_report("File open failed, ignoring");
542 >    break;
543 >  }
544  
545 <    BIO_set_close(file, BIO_CLOSE);
578 <    BIO_free(file);
545 >  ConfigServerInfo.rsa_private_key = PEM_read_bio_RSAPrivateKey(file, NULL, 0, NULL);
546  
547 <    if (ServerInfo.rsa_private_key == NULL)
548 <    {
582 <      conf_error_report("Couldn't extract key, ignoring");
583 <      break;
584 <    }
547 >  BIO_set_close(file, BIO_CLOSE);
548 >  BIO_free(file);
549  
550 <    if (!RSA_check_key(ServerInfo.rsa_private_key))
551 <    {
552 <      RSA_free(ServerInfo.rsa_private_key);
553 <      ServerInfo.rsa_private_key = NULL;
550 >  if (ConfigServerInfo.rsa_private_key == NULL)
551 >  {
552 >    conf_error_report("Couldn't extract key, ignoring");
553 >    break;
554 >  }
555  
556 <      conf_error_report("Invalid key, ignoring");
557 <      break;
558 <    }
556 >  if (!RSA_check_key(ConfigServerInfo.rsa_private_key))
557 >  {
558 >    RSA_free(ConfigServerInfo.rsa_private_key);
559 >    ConfigServerInfo.rsa_private_key = NULL;
560  
561 <    /* require 2048 bit (256 byte) key */
562 <    if (RSA_size(ServerInfo.rsa_private_key) != 256)
563 <    {
598 <      RSA_free(ServerInfo.rsa_private_key);
599 <      ServerInfo.rsa_private_key = NULL;
561 >    conf_error_report("Invalid key, ignoring");
562 >    break;
563 >  }
564  
565 <      conf_error_report("Not a 2048 bit key, ignoring");
566 <    }
565 >  if (RSA_size(ConfigServerInfo.rsa_private_key) < 128)
566 >  {
567 >    RSA_free(ConfigServerInfo.rsa_private_key);
568 >    ConfigServerInfo.rsa_private_key = NULL;
569 >
570 >    conf_error_report("Ignoring serverinfo::rsa_private_key_file -- need at least a 1024 bit key size");
571    }
572   #endif
573   };
574  
575   serverinfo_ssl_dh_param_file: SSL_DH_PARAM_FILE '=' QSTRING ';'
576   {
609 /* TBD - XXX: error reporting */
577   #ifdef HAVE_LIBCRYPTO
578 <  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
578 >  if (conf_parser_ctx.pass == 2)
579    {
580      BIO *file = BIO_new_file(yylval.string, "r");
581  
# Line 623 | Line 590 | serverinfo_ssl_dh_param_file: SSL_DH_PAR
590          if (DH_size(dh) < 128)
591            conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- need at least a 1024 bit DH prime size");
592          else
593 <          SSL_CTX_set_tmp_dh(ServerInfo.server_ctx, dh);
593 >          SSL_CTX_set_tmp_dh(ConfigServerInfo.server_ctx, dh);
594  
595          DH_free(dh);
596        }
597      }
598 +    else
599 +      conf_error_report("Ignoring serverinfo::ssl_dh_param_file -- could not open/read Diffie-Hellman parameter file");
600    }
601   #endif
602   };
# Line 635 | Line 604 | serverinfo_ssl_dh_param_file: SSL_DH_PAR
604   serverinfo_ssl_cipher_list: T_SSL_CIPHER_LIST '=' QSTRING ';'
605   {
606   #ifdef HAVE_LIBCRYPTO
607 <  if (conf_parser_ctx.pass == 2 && ServerInfo.server_ctx)
608 <    SSL_CTX_set_cipher_list(ServerInfo.server_ctx, yylval.string);
607 >  if (conf_parser_ctx.pass == 2)
608 >    SSL_CTX_set_cipher_list(ConfigServerInfo.server_ctx, yylval.string);
609 > #endif
610 > };
611 >
612 > serverinfo_ssl_message_digest_algorithm: SSL_MESSAGE_DIGEST_ALGORITHM '=' QSTRING ';'
613 > {
614 > #ifdef HAVE_LIBCRYPTO
615 >  if (conf_parser_ctx.pass == 2)
616 >  {
617 >    if ((ConfigServerInfo.message_digest_algorithm = EVP_get_digestbyname(yylval.string)) == NULL)
618 >    {
619 >      ConfigServerInfo.message_digest_algorithm = EVP_sha256();
620 >      conf_error_report("Ignoring serverinfo::ssl_message_digest_algorithm -- unknown message digest algorithm");
621 >    }
622 >  }
623 > #endif
624 > }
625 >
626 > serverinfo_ssl_dh_elliptic_curve: SSL_DH_ELLIPTIC_CURVE '=' QSTRING ';'
627 > {
628 > #ifdef HAVE_LIBCRYPTO
629 > #if OPENSSL_VERSION_NUMBER >= 0x1000005FL && !defined(OPENSSL_NO_ECDH)
630 >  int nid = 0;
631 >  EC_KEY *key = NULL;
632 >
633 >  if (conf_parser_ctx.pass == 2)
634 >  {
635 >    if ((nid = OBJ_sn2nid(yylval.string)) == 0)
636 >    {
637 >        conf_error_report("Ignoring serverinfo::serverinfo_ssl_dh_elliptic_curve -- unknown curve name");
638 >        break;
639 >    }
640 >
641 >    if ((key = EC_KEY_new_by_curve_name(nid)) == NULL)
642 >    {
643 >      conf_error_report("Ignoring serverinfo::serverinfo_ssl_dh_elliptic_curve -- could not create curve");
644 >      break;
645 >    }
646 >
647 >    SSL_CTX_set_tmp_ecdh(ConfigServerInfo.server_ctx, key);
648 >    EC_KEY_free(key);
649 > }
650 > #endif
651   #endif
652   };
653  
654 < serverinfo_name: NAME '=' QSTRING ';'
654 > serverinfo_name: NAME '=' QSTRING ';'
655   {
656    /* this isn't rehashable */
657 <  if (conf_parser_ctx.pass == 2 && !ServerInfo.name)
657 >  if (conf_parser_ctx.pass == 2 && !ConfigServerInfo.name)
658    {
659      if (valid_servname(yylval.string))
660 <      ServerInfo.name = xstrdup(yylval.string);
660 >      ConfigServerInfo.name = xstrdup(yylval.string);
661      else
662      {
663        conf_error_report("Ignoring serverinfo::name -- invalid name. Aborting.");
# Line 655 | Line 666 | serverinfo_name: NAME '=' QSTRING ';'
666    }
667   };
668  
669 < serverinfo_sid: IRCD_SID '=' QSTRING ';'
669 > serverinfo_sid: IRCD_SID '=' QSTRING ';'
670   {
671    /* this isn't rehashable */
672 <  if (conf_parser_ctx.pass == 2 && !ServerInfo.sid)
672 >  if (conf_parser_ctx.pass == 2 && !ConfigServerInfo.sid)
673    {
674      if (valid_sid(yylval.string))
675 <      ServerInfo.sid = xstrdup(yylval.string);
675 >      ConfigServerInfo.sid = xstrdup(yylval.string);
676      else
677      {
678        conf_error_report("Ignoring serverinfo::sid -- invalid SID. Aborting.");
# Line 674 | Line 685 | serverinfo_description: DESCRIPTION '='
685   {
686    if (conf_parser_ctx.pass == 2)
687    {
688 <    MyFree(ServerInfo.description);
689 <    ServerInfo.description = xstrdup(yylval.string);
688 >    MyFree(ConfigServerInfo.description);
689 >    ConfigServerInfo.description = xstrdup(yylval.string);
690    }
691   };
692  
# Line 685 | Line 696 | serverinfo_network_name: NETWORK_NAME '=
696    {
697      char *p;
698  
699 <    if ((p = strchr(yylval.string, ' ')) != NULL)
700 <      p = '\0';
699 >    if ((p = strchr(yylval.string, ' ')))
700 >      *p = '\0';
701  
702 <    MyFree(ServerInfo.network_name);
703 <    ServerInfo.network_name = xstrdup(yylval.string);
702 >    MyFree(ConfigServerInfo.network_name);
703 >    ConfigServerInfo.network_name = xstrdup(yylval.string);
704    }
705   };
706  
707   serverinfo_network_desc: NETWORK_DESC '=' QSTRING ';'
708   {
709 <  if (conf_parser_ctx.pass == 2)
710 <  {
711 <    MyFree(ServerInfo.network_desc);
712 <    ServerInfo.network_desc = xstrdup(yylval.string);
713 <  }
709 >  if (conf_parser_ctx.pass != 2)
710 >    break;
711 >
712 >  MyFree(ConfigServerInfo.network_desc);
713 >  ConfigServerInfo.network_desc = xstrdup(yylval.string);
714   };
715  
716   serverinfo_vhost: VHOST '=' QSTRING ';'
# Line 718 | Line 729 | serverinfo_vhost: VHOST '=' QSTRING ';'
729        ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", yylval.string);
730      else
731      {
732 <      assert(res != NULL);
732 >      assert(res);
733  
734 <      memcpy(&ServerInfo.ip, res->ai_addr, res->ai_addrlen);
735 <      ServerInfo.ip.ss.ss_family = res->ai_family;
736 <      ServerInfo.ip.ss_len = res->ai_addrlen;
734 >      memcpy(&ConfigServerInfo.ip, res->ai_addr, res->ai_addrlen);
735 >      ConfigServerInfo.ip.ss.ss_family = res->ai_family;
736 >      ConfigServerInfo.ip.ss_len = res->ai_addrlen;
737        freeaddrinfo(res);
738  
739 <      ServerInfo.specific_ipv4_vhost = 1;
739 >      ConfigServerInfo.specific_ipv4_vhost = 1;
740      }
741    }
742   };
743  
744   serverinfo_vhost6: VHOST6 '=' QSTRING ';'
745   {
735 #ifdef IPV6
746    if (conf_parser_ctx.pass == 2 && *yylval.string != '*')
747    {
748      struct addrinfo hints, *res;
# Line 747 | Line 757 | serverinfo_vhost6: VHOST6 '=' QSTRING ';
757        ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost6(%s)", yylval.string);
758      else
759      {
760 <      assert(res != NULL);
760 >      assert(res);
761  
762 <      memcpy(&ServerInfo.ip6, res->ai_addr, res->ai_addrlen);
763 <      ServerInfo.ip6.ss.ss_family = res->ai_family;
764 <      ServerInfo.ip6.ss_len = res->ai_addrlen;
762 >      memcpy(&ConfigServerInfo.ip6, res->ai_addr, res->ai_addrlen);
763 >      ConfigServerInfo.ip6.ss.ss_family = res->ai_family;
764 >      ConfigServerInfo.ip6.ss_len = res->ai_addrlen;
765        freeaddrinfo(res);
766  
767 <      ServerInfo.specific_ipv6_vhost = 1;
767 >      ConfigServerInfo.specific_ipv6_vhost = 1;
768      }
769    }
760 #endif
770   };
771  
772   serverinfo_max_clients: T_MAX_CLIENTS '=' NUMBER ';'
# Line 767 | Line 776 | serverinfo_max_clients: T_MAX_CLIENTS '=
776  
777    if ($3 < MAXCLIENTS_MIN)
778    {
779 <    char buf[IRCD_BUFSIZE];
779 >    char buf[IRCD_BUFSIZE] = "";
780  
781      snprintf(buf, sizeof(buf), "MAXCLIENTS too low, setting to %d", MAXCLIENTS_MIN);
782      conf_error_report(buf);
783 <    ServerInfo.max_clients = MAXCLIENTS_MIN;
783 >    ConfigServerInfo.max_clients = MAXCLIENTS_MIN;
784    }
785    else if ($3 > MAXCLIENTS_MAX)
786    {
787 <    char buf[IRCD_BUFSIZE];
787 >    char buf[IRCD_BUFSIZE] = "";
788  
789      snprintf(buf, sizeof(buf), "MAXCLIENTS too high, setting to %d", MAXCLIENTS_MAX);
790      conf_error_report(buf);
791 <    ServerInfo.max_clients = MAXCLIENTS_MAX;
791 >    ConfigServerInfo.max_clients = MAXCLIENTS_MAX;
792    }
793    else
794 <    ServerInfo.max_clients = $3;
794 >    ConfigServerInfo.max_clients = $3;
795   };
796  
797   serverinfo_max_nick_length: MAX_NICK_LENGTH '=' NUMBER ';'
# Line 793 | Line 802 | serverinfo_max_nick_length: MAX_NICK_LEN
802    if ($3 < 9)
803    {
804      conf_error_report("max_nick_length too low, setting to 9");
805 <    ServerInfo.max_nick_length = 9;
805 >    ConfigServerInfo.max_nick_length = 9;
806    }
807    else if ($3 > NICKLEN)
808    {
809 <    char buf[IRCD_BUFSIZE];
809 >    char buf[IRCD_BUFSIZE] = "";
810  
811      snprintf(buf, sizeof(buf), "max_nick_length too high, setting to %d", NICKLEN);
812      conf_error_report(buf);
813 <    ServerInfo.max_nick_length = NICKLEN;
813 >    ConfigServerInfo.max_nick_length = NICKLEN;
814    }
815    else
816 <    ServerInfo.max_nick_length = $3;
816 >    ConfigServerInfo.max_nick_length = $3;
817   };
818  
819   serverinfo_max_topic_length: MAX_TOPIC_LENGTH '=' NUMBER ';'
# Line 815 | Line 824 | serverinfo_max_topic_length: MAX_TOPIC_L
824    if ($3 < 80)
825    {
826      conf_error_report("max_topic_length too low, setting to 80");
827 <    ServerInfo.max_topic_length = 80;
827 >    ConfigServerInfo.max_topic_length = 80;
828    }
829    else if ($3 > TOPICLEN)
830    {
831 <    char buf[IRCD_BUFSIZE];
831 >    char buf[IRCD_BUFSIZE] = "";
832  
833      snprintf(buf, sizeof(buf), "max_topic_length too high, setting to %d", TOPICLEN);
834      conf_error_report(buf);
835 <    ServerInfo.max_topic_length = TOPICLEN;
835 >    ConfigServerInfo.max_topic_length = TOPICLEN;
836    }
837    else
838 <    ServerInfo.max_topic_length = $3;
838 >    ConfigServerInfo.max_topic_length = $3;
839   };
840  
841 < serverinfo_hub: HUB '=' TBOOL ';'
841 > serverinfo_hub: HUB '=' TBOOL ';'
842   {
843    if (conf_parser_ctx.pass == 2)
844 <    ServerInfo.hub = yylval.number;
844 >    ConfigServerInfo.hub = yylval.number;
845   };
846  
847   /***************************************************************************
# Line 841 | Line 850 | serverinfo_hub: HUB '=' TBOOL ';'
850   admin_entry: ADMIN  '{' admin_items '}' ';' ;
851  
852   admin_items: admin_items admin_item | admin_item;
853 < admin_item:  admin_name | admin_description |
854 <             admin_email | error ';' ;
853 > admin_item:  admin_name |
854 >             admin_description |
855 >             admin_email |
856 >             error ';' ;
857  
858 < admin_name: NAME '=' QSTRING ';'
858 > admin_name: NAME '=' QSTRING ';'
859   {
860 <  if (conf_parser_ctx.pass == 2)
861 <  {
862 <    MyFree(AdminInfo.name);
863 <    AdminInfo.name = xstrdup(yylval.string);
864 <  }
860 >  if (conf_parser_ctx.pass != 2)
861 >    break;
862 >
863 >  MyFree(ConfigAdminInfo.name);
864 >  ConfigAdminInfo.name = xstrdup(yylval.string);
865   };
866  
867   admin_email: EMAIL '=' QSTRING ';'
868   {
869 <  if (conf_parser_ctx.pass == 2)
870 <  {
871 <    MyFree(AdminInfo.email);
872 <    AdminInfo.email = xstrdup(yylval.string);
873 <  }
869 >  if (conf_parser_ctx.pass != 2)
870 >    break;
871 >
872 >  MyFree(ConfigAdminInfo.email);
873 >  ConfigAdminInfo.email = xstrdup(yylval.string);
874   };
875  
876   admin_description: DESCRIPTION '=' QSTRING ';'
877   {
878 +  if (conf_parser_ctx.pass != 2)
879 +    break;
880 +
881 +  MyFree(ConfigAdminInfo.description);
882 +  ConfigAdminInfo.description = xstrdup(yylval.string);
883 + };
884 +
885 + /***************************************************************************
886 + * motd section
887 + ***************************************************************************/
888 + motd_entry: MOTD
889 + {
890    if (conf_parser_ctx.pass == 2)
891 <  {
892 <    MyFree(AdminInfo.description);
893 <    AdminInfo.description = xstrdup(yylval.string);
894 <  }
891 >    reset_block_state();
892 > } '{' motd_items '}' ';'
893 > {
894 >  dlink_node *ptr = NULL;
895 >
896 >  if (conf_parser_ctx.pass != 2)
897 >    break;
898 >
899 >  if (!block_state.file.buf[0])
900 >    break;
901 >
902 >  DLINK_FOREACH(ptr, block_state.mask.list.head)
903 >    motd_add(ptr->data, block_state.file.buf);
904 > };
905 >
906 > motd_items: motd_items motd_item | motd_item;
907 > motd_item:  motd_mask | motd_file | error ';' ;
908 >
909 > motd_mask: MASK '=' QSTRING ';'
910 > {
911 >  if (conf_parser_ctx.pass == 2)
912 >    dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.mask.list);
913 > };
914 >
915 > motd_file: T_FILE '=' QSTRING ';'
916 > {
917 >  if (conf_parser_ctx.pass == 2)
918 >    strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
919   };
920  
921   /***************************************************************************
# Line 877 | Line 924 | admin_description: DESCRIPTION '=' QSTRI
924   logging_entry:          T_LOG  '{' logging_items '}' ';' ;
925   logging_items:          logging_items logging_item | logging_item ;
926  
927 < logging_item:           logging_use_logging | logging_file_entry |
928 <                        error ';' ;
927 > logging_item:           logging_use_logging | logging_file_entry |
928 >                        error ';' ;
929  
930   logging_use_logging: USE_LOGGING '=' TBOOL ';'
931   {
932    if (conf_parser_ctx.pass == 2)
933 <    ConfigLoggingEntry.use_logging = yylval.number;
933 >    ConfigLog.use_logging = yylval.number;
934   };
935  
936   logging_file_entry:
# Line 941 | Line 988 | logging_file_type_item:  USER
988   {
989    if (conf_parser_ctx.pass == 2)
990      block_state.type.value = LOG_TYPE_GLINE;
991 + } | XLINE
992 + {
993 +  if (conf_parser_ctx.pass == 2)
994 +    block_state.type.value = LOG_TYPE_XLINE;
995 + } | RESV
996 + {
997 +  if (conf_parser_ctx.pass == 2)
998 +    block_state.type.value = LOG_TYPE_RESV;
999   } | T_DLINE
1000   {
1001    if (conf_parser_ctx.pass == 2)
# Line 963 | Line 1018 | logging_file_type_item:  USER
1018   /***************************************************************************
1019   * section oper
1020   ***************************************************************************/
1021 < oper_entry: OPERATOR
1021 > oper_entry: OPERATOR
1022   {
1023    if (conf_parser_ctx.pass != 2)
1024      break;
# Line 980 | Line 1035 | oper_entry: OPERATOR
1035    if (!block_state.name.buf[0])
1036      break;
1037   #ifdef HAVE_LIBCRYPTO
1038 <  if (!(block_state.file.buf[0] ||
1039 <        block_state.rpass.buf[0]))
1038 >  if (!block_state.file.buf[0] &&
1039 >      !block_state.rpass.buf[0])
1040      break;
1041   #else
1042    if (!block_state.rpass.buf[0])
# Line 1002 | Line 1057 | oper_entry: OPERATOR
1057      nuh.hostsize = sizeof(block_state.host.buf);
1058      split_nuh(&nuh);
1059  
1060 <    conf        = conf_make(CONF_OPER);
1061 <    conf->name  = xstrdup(block_state.name.buf);
1062 <    conf->user  = xstrdup(block_state.user.buf);
1063 <    conf->host  = xstrdup(block_state.host.buf);
1060 >    conf         = conf_make(CONF_OPER);
1061 >    conf->name   = xstrdup(block_state.name.buf);
1062 >    conf->user   = xstrdup(block_state.user.buf);
1063 >    conf->host   = xstrdup(block_state.host.buf);
1064 >
1065 >    if (block_state.cert.buf[0])
1066 >      conf->certfp = xstrdup(block_state.cert.buf);
1067  
1068      if (block_state.rpass.buf[0])
1069        conf->passwd = xstrdup(block_state.rpass.buf);
# Line 1025 | Line 1083 | oper_entry: OPERATOR
1083  
1084        if ((file = BIO_new_file(block_state.file.buf, "r")) == NULL)
1085        {
1086 <        conf_error_report("Ignoring rsa_public_key_file -- file doesn't exist");
1086 >        ilog(LOG_TYPE_IRCD, "Ignoring rsa_public_key_file -- file doesn't exist");
1087          break;
1088        }
1089  
1090        if ((pkey = PEM_read_bio_RSA_PUBKEY(file, NULL, 0, NULL)) == NULL)
1091 <        conf_error_report("Ignoring rsa_public_key_file -- Key invalid; check key syntax.");
1091 >        ilog(LOG_TYPE_IRCD, "Ignoring rsa_public_key_file -- key invalid; check key syntax");
1092 >      else
1093 >      {
1094 >        if (RSA_size(pkey) > 128)
1095 >          ilog(LOG_TYPE_IRCD, "Ignoring rsa_public_key_file -- key size must be 1024 or below");
1096 >        else
1097 >          conf->rsa_public_key = pkey;
1098 >      }
1099  
1035      conf->rsa_public_key = pkey;
1100        BIO_set_close(file, BIO_CLOSE);
1101        BIO_free(file);
1102      }
# Line 1041 | Line 1105 | oper_entry: OPERATOR
1105   };
1106  
1107   oper_items:     oper_items oper_item | oper_item;
1108 < oper_item:      oper_name | oper_user | oper_password |
1109 <                oper_umodes | oper_class | oper_encrypted |
1110 <                oper_rsa_public_key_file | oper_flags | error ';' ;
1108 > oper_item:      oper_name |
1109 >                oper_user |
1110 >                oper_password |
1111 >                oper_umodes |
1112 >                oper_class |
1113 >                oper_encrypted |
1114 >                oper_rsa_public_key_file |
1115 >                oper_ssl_certificate_fingerprint |
1116 >                oper_ssl_connection_required |
1117 >                oper_flags |
1118 >                error ';' ;
1119  
1120   oper_name: NAME '=' QSTRING ';'
1121   {
# Line 1065 | Line 1137 | oper_password: PASSWORD '=' QSTRING ';'
1137  
1138   oper_encrypted: ENCRYPTED '=' TBOOL ';'
1139   {
1140 <  if (conf_parser_ctx.pass == 2)
1141 <  {
1142 <    if (yylval.number)
1143 <      block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1144 <    else
1145 <      block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1146 <  }
1140 >  if (conf_parser_ctx.pass != 2)
1141 >    break;
1142 >
1143 >  if (yylval.number)
1144 >    block_state.flags.value |= CONF_FLAGS_ENCRYPTED;
1145 >  else
1146 >    block_state.flags.value &= ~CONF_FLAGS_ENCRYPTED;
1147   };
1148  
1149   oper_rsa_public_key_file: RSA_PUBLIC_KEY_FILE '=' QSTRING ';'
# Line 1080 | Line 1152 | oper_rsa_public_key_file: RSA_PUBLIC_KEY
1152      strlcpy(block_state.file.buf, yylval.string, sizeof(block_state.file.buf));
1153   };
1154  
1155 + oper_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
1156 + {
1157 +  if (conf_parser_ctx.pass == 2)
1158 +    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
1159 + };
1160 +
1161 + oper_ssl_connection_required: SSL_CONNECTION_REQUIRED '=' TBOOL ';'
1162 + {
1163 +  if (conf_parser_ctx.pass != 2)
1164 +    break;
1165 +
1166 +  if (yylval.number)
1167 +    block_state.flags.value |= CONF_FLAGS_SSL;
1168 +  else
1169 +    block_state.flags.value &= ~CONF_FLAGS_SSL;
1170 + };
1171 +
1172   oper_class: CLASS '=' QSTRING ';'
1173   {
1174    if (conf_parser_ctx.pass == 2)
# Line 1101 | Line 1190 | oper_umodes_item:  T_BOTS
1190   {
1191    if (conf_parser_ctx.pass == 2)
1192      block_state.modes.value |= UMODE_CCONN;
1104 } | T_CCONN_FULL
1105 {
1106  if (conf_parser_ctx.pass == 2)
1107    block_state.modes.value |= UMODE_CCONN_FULL;
1193   } | T_DEAF
1194   {
1195    if (conf_parser_ctx.pass == 2)
# Line 1121 | Line 1206 | oper_umodes_item:  T_BOTS
1206   {
1207    if (conf_parser_ctx.pass == 2)
1208      block_state.modes.value |= UMODE_HIDDEN;
1209 + } | HIDE_CHANS
1210 + {
1211 +  if (conf_parser_ctx.pass == 2)
1212 +    block_state.modes.value |= UMODE_HIDECHANS;
1213 + } | HIDE_IDLE
1214 + {
1215 +  if (conf_parser_ctx.pass == 2)
1216 +    block_state.modes.value |= UMODE_HIDEIDLE;
1217   } | T_SKILL
1218   {
1219    if (conf_parser_ctx.pass == 2)
# Line 1145 | Line 1238 | oper_umodes_item:  T_BOTS
1238   {
1239    if (conf_parser_ctx.pass == 2)
1240      block_state.modes.value |= UMODE_EXTERNAL;
1148 } | T_OPERWALL
1149 {
1150  if (conf_parser_ctx.pass == 2)
1151    block_state.modes.value |= UMODE_OPERWALL;
1241   } | T_SERVNOTICE
1242   {
1243    if (conf_parser_ctx.pass == 2)
# Line 1177 | Line 1266 | oper_umodes_item:  T_BOTS
1266   {
1267    if (conf_parser_ctx.pass == 2)
1268      block_state.modes.value |= UMODE_REGONLY;
1269 + } | T_FARCONNECT
1270 + {
1271 +  if (conf_parser_ctx.pass == 2)
1272 +    block_state.modes.value |= UMODE_FARCONNECT;
1273   };
1274  
1275   oper_flags: IRCD_FLAGS
# Line 1186 | Line 1279 | oper_flags: IRCD_FLAGS
1279   } '='  oper_flags_items ';';
1280  
1281   oper_flags_items: oper_flags_items ',' oper_flags_item | oper_flags_item;
1282 < oper_flags_item: GLOBAL_KILL
1282 > oper_flags_item: KILL ':' REMOTE
1283 > {
1284 >  if (conf_parser_ctx.pass == 2)
1285 >    block_state.port.value |= OPER_FLAG_KILL_REMOTE;
1286 > } | KILL
1287 > {
1288 >  if (conf_parser_ctx.pass == 2)
1289 >    block_state.port.value |= OPER_FLAG_KILL;
1290 > } | CONNECT ':' REMOTE
1291   {
1292    if (conf_parser_ctx.pass == 2)
1293 <    block_state.port.value |= OPER_FLAG_GLOBAL_KILL;
1294 < } | REMOTE
1293 >    block_state.port.value |= OPER_FLAG_CONNECT_REMOTE;
1294 > } | CONNECT
1295   {
1296    if (conf_parser_ctx.pass == 2)
1297 <    block_state.port.value |= OPER_FLAG_REMOTE;
1297 >    block_state.port.value |= OPER_FLAG_CONNECT;
1298 > } | SQUIT ':' REMOTE
1299 > {
1300 >  if (conf_parser_ctx.pass == 2)
1301 >    block_state.port.value |= OPER_FLAG_SQUIT_REMOTE;
1302 > } | SQUIT
1303 > {
1304 >  if (conf_parser_ctx.pass == 2)
1305 >    block_state.port.value |= OPER_FLAG_SQUIT;
1306   } | KLINE
1307   {
1308    if (conf_parser_ctx.pass == 2)
1309 <    block_state.port.value |= OPER_FLAG_K;
1309 >    block_state.port.value |= OPER_FLAG_KLINE;
1310   } | UNKLINE
1311   {
1312    if (conf_parser_ctx.pass == 2)
# Line 1213 | Line 1322 | oper_flags_item: GLOBAL_KILL
1322   } | XLINE
1323   {
1324    if (conf_parser_ctx.pass == 2)
1325 <    block_state.port.value |= OPER_FLAG_X;
1325 >    block_state.port.value |= OPER_FLAG_XLINE;
1326 > } | T_UNXLINE
1327 > {
1328 >  if (conf_parser_ctx.pass == 2)
1329 >    block_state.port.value |= OPER_FLAG_UNXLINE;
1330   } | GLINE
1331   {
1332    if (conf_parser_ctx.pass == 2)
# Line 1234 | Line 1347 | oper_flags_item: GLOBAL_KILL
1347   {
1348    if (conf_parser_ctx.pass == 2)
1349      block_state.port.value |= OPER_FLAG_ADMIN;
1237 } | T_OPERWALL
1238 {
1239  if (conf_parser_ctx.pass == 2)
1240    block_state.port.value |= OPER_FLAG_OPERWALL;
1350   } | T_GLOBOPS
1351   {
1352    if (conf_parser_ctx.pass == 2)
1353      block_state.port.value |= OPER_FLAG_GLOBOPS;
1354 < } | OPER_SPY_T
1354 > } | T_WALLOPS
1355   {
1356    if (conf_parser_ctx.pass == 2)
1357 <    block_state.port.value |= OPER_FLAG_OPER_SPY;
1357 >    block_state.port.value |= OPER_FLAG_WALLOPS;
1358 > } | T_LOCOPS
1359 > {
1360 >  if (conf_parser_ctx.pass == 2)
1361 >    block_state.port.value |= OPER_FLAG_LOCOPS;
1362   } | REMOTEBAN
1363   {
1364    if (conf_parser_ctx.pass == 2)
# Line 1301 | Line 1414 | class_entry: CLASS
1414    class->max_ident = block_state.max_ident.value;
1415    class->max_sendq = block_state.max_sendq.value;
1416    class->max_recvq = block_state.max_recvq.value;
1417 +  class->max_channels = block_state.max_channels.value;
1418  
1419    if (block_state.min_idle.value > block_state.max_idle.value)
1420    {
# Line 1327 | Line 1441 | class_entry: CLASS
1441  
1442   class_items:    class_items class_item | class_item;
1443   class_item:     class_name |
1444 <                class_cidr_bitlen_ipv4 | class_cidr_bitlen_ipv6 |
1444 >                class_cidr_bitlen_ipv4 |
1445 >                class_cidr_bitlen_ipv6 |
1446                  class_ping_time |
1447 <                class_number_per_cidr |
1447 >                class_number_per_cidr |
1448                  class_number_per_ip |
1449                  class_connectfreq |
1450 +                class_max_channels |
1451                  class_max_number |
1452 <                class_max_global |
1453 <                class_max_local |
1454 <                class_max_ident |
1452 >                class_max_global |
1453 >                class_max_local |
1454 >                class_max_ident |
1455                  class_sendq | class_recvq |
1456                  class_min_idle |
1457                  class_max_idle |
1458                  class_flags |
1459 <                error ';' ;
1459 >                error ';' ;
1460  
1461 < class_name: NAME '=' QSTRING ';'
1461 > class_name: NAME '=' QSTRING ';'
1462   {
1463    if (conf_parser_ctx.pass == 1)
1464      strlcpy(block_state.class.buf, yylval.string, sizeof(block_state.class.buf));
# Line 1366 | Line 1482 | class_connectfreq: CONNECTFREQ '=' times
1482      block_state.con_freq.value = $3;
1483   };
1484  
1485 + class_max_channels: MAX_CHANNELS '=' NUMBER ';'
1486 + {
1487 +  if (conf_parser_ctx.pass == 1)
1488 +    block_state.max_channels.value = $3;
1489 + };
1490 +
1491   class_max_number: MAX_NUMBER '=' NUMBER ';'
1492   {
1493    if (conf_parser_ctx.pass == 1)
# Line 1497 | Line 1619 | port_item: NUMBER
1619   {
1620    if (conf_parser_ctx.pass == 2)
1621    {
1622 + #ifndef HAVE_LIBCRYPTO
1623      if (block_state.flags.value & LISTENER_SSL)
1624 < #ifdef HAVE_LIBCRYPTO
1625 <      if (!ServerInfo.server_ctx)
1624 >    {
1625 >      conf_error_report("SSL not available - port closed");
1626 >      break;
1627 >    }
1628   #endif
1504      {
1505        conf_error_report("SSL not available - port closed");
1506        break;
1507      }
1629      add_listener($1, block_state.addr.buf, block_state.flags.value);
1630    }
1631   } | NUMBER TWODOTS NUMBER
1632   {
1633    if (conf_parser_ctx.pass == 2)
1634    {
1635 <    int i;
1515 <
1635 > #ifndef HAVE_LIBCRYPTO
1636      if (block_state.flags.value & LISTENER_SSL)
1637 < #ifdef HAVE_LIBCRYPTO
1638 <      if (!ServerInfo.server_ctx)
1637 >    {
1638 >      conf_error_report("SSL not available - port closed");
1639 >      break;
1640 >    }
1641   #endif
1520      {
1521        conf_error_report("SSL not available - port closed");
1522        break;
1523      }
1642  
1643 <    for (i = $1; i <= $3; ++i)
1643 >    for (int i = $1; i <= $3; ++i)
1644        add_listener(i, block_state.addr.buf, block_state.flags.value);
1645    }
1646   };
# Line 1568 | Line 1686 | auth_entry: IRCD_AUTH
1686      split_nuh(&nuh);
1687  
1688      conf        = conf_make(CONF_CLIENT);
1689 <    conf->user  = xstrdup(collapse(block_state.user.buf));
1690 <    conf->host  = xstrdup(collapse(block_state.host.buf));
1689 >    conf->user  = xstrdup(block_state.user.buf);
1690 >    conf->host  = xstrdup(block_state.host.buf);
1691  
1692      if (block_state.rpass.buf[0])
1693        conf->passwd = xstrdup(block_state.rpass.buf);
1694      if (block_state.name.buf[0])
1695 <      conf->passwd = xstrdup(block_state.name.buf);
1695 >      conf->name = xstrdup(block_state.name.buf);
1696  
1697      conf->flags = block_state.flags.value;
1698      conf->port  = block_state.port.value;
# Line 1582 | Line 1700 | auth_entry: IRCD_AUTH
1700      conf_add_class_to_conf(conf, block_state.class.buf);
1701      add_conf_by_address(CONF_CLIENT, conf);
1702    }
1703 < };
1703 > };
1704  
1705   auth_items:     auth_items auth_item | auth_item;
1706 < auth_item:      auth_user | auth_passwd | auth_class | auth_flags |
1707 <                auth_spoof | auth_redir_serv | auth_redir_port |
1708 <                auth_encrypted | error ';' ;
1706 > auth_item:      auth_user |
1707 >                auth_passwd |
1708 >                auth_class |
1709 >                auth_flags |
1710 >                auth_spoof |
1711 >                auth_redir_serv |
1712 >                auth_redir_port |
1713 >                auth_encrypted |
1714 >                error ';' ;
1715  
1716   auth_user: USER '=' QSTRING ';'
1717   {
# Line 1621 | Line 1745 | auth_encrypted: ENCRYPTED '=' TBOOL ';'
1745   auth_flags: IRCD_FLAGS
1746   {
1747    if (conf_parser_ctx.pass == 2)
1748 <    block_state.flags.value &= CONF_FLAGS_ENCRYPTED;
1748 >    block_state.flags.value &= (CONF_FLAGS_ENCRYPTED | CONF_FLAGS_SPOOF_IP);
1749   } '='  auth_flags_items ';';
1750  
1751   auth_flags_items: auth_flags_items ',' auth_flags_item | auth_flags_item;
# Line 1667 | Line 1791 | auth_flags_item: SPOOF_NOTICE
1791      block_state.flags.value |= CONF_FLAGS_NEED_PASSWORD;
1792   };
1793  
1794 < auth_spoof: SPOOF '=' QSTRING ';'
1794 > auth_spoof: SPOOF '=' QSTRING ';'
1795   {
1796    if (conf_parser_ctx.pass != 2)
1797      break;
1798  
1799 <  if (strlen(yylval.string) <= HOSTLEN && valid_hostname(yylval.string))
1799 >  if (valid_hostname(yylval.string))
1800    {
1801      strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
1802      block_state.flags.value |= CONF_FLAGS_SPOOF_IP;
# Line 1718 | Line 1842 | resv_entry: RESV
1842    create_resv(block_state.name.buf, block_state.rpass.buf, &block_state.mask.list);
1843   };
1844  
1845 < resv_items:     resv_items resv_item | resv_item;
1846 < resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1845 > resv_items:     resv_items resv_item | resv_item;
1846 > resv_item:      resv_mask | resv_reason | resv_exempt | error ';' ;
1847  
1848   resv_mask: MASK '=' QSTRING ';'
1849   {
# Line 1750 | Line 1874 | service_item:      service_name | error;
1874  
1875   service_name: NAME '=' QSTRING ';'
1876   {
1877 <  if (conf_parser_ctx.pass == 2)
1877 >  if (conf_parser_ctx.pass != 2)
1878 >    break;
1879 >
1880 >  if (valid_servname(yylval.string))
1881    {
1882 <    if (valid_servname(yylval.string))
1883 <    {
1757 <      struct MaskItem *conf = conf_make(CONF_SERVICE);
1758 <      conf->name = xstrdup(yylval.string);
1759 <    }
1882 >    struct MaskItem *conf = conf_make(CONF_SERVICE);
1883 >    conf->name = xstrdup(yylval.string);
1884    }
1885   };
1886  
# Line 1785 | Line 1909 | shared_entry: T_SHARED
1909    conf->flags = block_state.flags.value;
1910    conf->name = xstrdup(block_state.name.buf);
1911    conf->user = xstrdup(block_state.user.buf);
1912 <  conf->user = xstrdup(block_state.host.buf);
1912 >  conf->host = xstrdup(block_state.host.buf);
1913   };
1914  
1915   shared_items: shared_items shared_item | shared_item;
# Line 1889 | Line 2013 | cluster_entry: T_CLUSTER
2013    conf->name = xstrdup(block_state.name.buf);
2014   };
2015  
2016 < cluster_items:  cluster_items cluster_item | cluster_item;
2017 < cluster_item:   cluster_name | cluster_type | error ';' ;
2016 > cluster_items:  cluster_items cluster_item | cluster_item;
2017 > cluster_item:   cluster_name | cluster_type | error ';' ;
2018  
2019   cluster_name: NAME '=' QSTRING ';'
2020   {
# Line 1904 | Line 2028 | cluster_type: TYPE
2028      block_state.flags.value = 0;
2029   } '=' cluster_types ';' ;
2030  
2031 < cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2031 > cluster_types:  cluster_types ',' cluster_type_item | cluster_type_item;
2032   cluster_type_item: KLINE
2033   {
2034    if (conf_parser_ctx.pass == 2)
# Line 1950 | Line 2074 | cluster_type_item: KLINE
2074   /***************************************************************************
2075   *  section connect
2076   ***************************************************************************/
2077 < connect_entry: CONNECT  
2077 > connect_entry: CONNECT
2078   {
2079  
2080    if (conf_parser_ctx.pass != 2)
2081      break;
2082  
2083    reset_block_state();
2084 +  block_state.aftype.value = AF_INET;
2085    block_state.port.value = PORTNUM;
2086   } '{' connect_items '}' ';'
2087   {
# Line 1970 | Line 2095 | connect_entry: CONNECT
2095        !block_state.host.buf[0])
2096      break;
2097  
2098 <  if (!(block_state.rpass.buf[0] ||
2099 <        block_state.spass.buf[0]))
2098 >  if (!block_state.rpass.buf[0] ||
2099 >      !block_state.spass.buf[0])
2100      break;
2101  
2102    if (has_wildcards(block_state.name.buf) ||
# Line 1986 | Line 2111 | connect_entry: CONNECT
2111    conf->name = xstrdup(block_state.name.buf);
2112    conf->passwd = xstrdup(block_state.rpass.buf);
2113    conf->spasswd = xstrdup(block_state.spass.buf);
2114 <  conf->cipher_list = xstrdup(block_state.ciph.buf);
2114 >
2115 >  if (block_state.cert.buf[0])
2116 >    conf->certfp = xstrdup(block_state.cert.buf);
2117 >
2118 >  if (block_state.ciph.buf[0])
2119 >    conf->cipher_list = xstrdup(block_state.ciph.buf);
2120  
2121    dlinkMoveList(&block_state.leaf.list, &conf->leaf_list);
2122    dlinkMoveList(&block_state.hub.list, &conf->hub_list);
# Line 2003 | Line 2133 | connect_entry: CONNECT
2133        ilog(LOG_TYPE_IRCD, "Invalid netmask for server vhost(%s)", block_state.bind.buf);
2134      else
2135      {
2136 <      assert(res != NULL);
2136 >      assert(res);
2137  
2138        memcpy(&conf->bind, res->ai_addr, res->ai_addrlen);
2139        conf->bind.ss.ss_family = res->ai_family;
# Line 2017 | Line 2147 | connect_entry: CONNECT
2147   };
2148  
2149   connect_items:  connect_items connect_item | connect_item;
2150 < connect_item:   connect_name | connect_host | connect_vhost |
2151 <                connect_send_password | connect_accept_password |
2152 <                connect_aftype | connect_port | connect_ssl_cipher_list |
2153 <                connect_flags | connect_hub_mask | connect_leaf_mask |
2154 <                connect_class | connect_encrypted |
2150 > connect_item:   connect_name |
2151 >                connect_host |
2152 >                connect_vhost |
2153 >                connect_send_password |
2154 >                connect_accept_password |
2155 >                connect_ssl_certificate_fingerprint |
2156 >                connect_aftype |
2157 >                connect_port |
2158 >                connect_ssl_cipher_list |
2159 >                connect_flags |
2160 >                connect_hub_mask |
2161 >                connect_leaf_mask |
2162 >                connect_class |
2163 >                connect_encrypted |
2164                  error ';' ;
2165  
2166   connect_name: NAME '=' QSTRING ';'
# Line 2030 | Line 2169 | connect_name: NAME '=' QSTRING ';'
2169      strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2170   };
2171  
2172 < connect_host: HOST '=' QSTRING ';'
2172 > connect_host: HOST '=' QSTRING ';'
2173   {
2174    if (conf_parser_ctx.pass == 2)
2175      strlcpy(block_state.host.buf, yylval.string, sizeof(block_state.host.buf));
2176   };
2177  
2178 < connect_vhost: VHOST '=' QSTRING ';'
2178 > connect_vhost: VHOST '=' QSTRING ';'
2179   {
2180    if (conf_parser_ctx.pass == 2)
2181      strlcpy(block_state.bind.buf, yylval.string, sizeof(block_state.bind.buf));
2182   };
2183 <
2183 >
2184   connect_send_password: SEND_PASSWORD '=' QSTRING ';'
2185   {
2186    if (conf_parser_ctx.pass != 2)
# Line 2049 | Line 2188 | connect_send_password: SEND_PASSWORD '='
2188  
2189    if ($3[0] == ':')
2190      conf_error_report("Server passwords cannot begin with a colon");
2191 <  else if (strchr($3, ' ') != NULL)
2191 >  else if (strchr($3, ' '))
2192      conf_error_report("Server passwords cannot contain spaces");
2193    else
2194      strlcpy(block_state.spass.buf, yylval.string, sizeof(block_state.spass.buf));
# Line 2062 | Line 2201 | connect_accept_password: ACCEPT_PASSWORD
2201  
2202    if ($3[0] == ':')
2203      conf_error_report("Server passwords cannot begin with a colon");
2204 <  else if (strchr($3, ' ') != NULL)
2204 >  else if (strchr($3, ' '))
2205      conf_error_report("Server passwords cannot contain spaces");
2206    else
2207      strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
2208   };
2209  
2210 + connect_ssl_certificate_fingerprint: SSL_CERTIFICATE_FINGERPRINT '=' QSTRING ';'
2211 + {
2212 +  if (conf_parser_ctx.pass == 2)
2213 +    strlcpy(block_state.cert.buf, yylval.string, sizeof(block_state.cert.buf));
2214 + };
2215 +
2216   connect_port: PORT '=' NUMBER ';'
2217   {
2218    if (conf_parser_ctx.pass == 2)
# Line 2080 | Line 2225 | connect_aftype: AFTYPE '=' T_IPV4 ';'
2225      block_state.aftype.value = AF_INET;
2226   } | AFTYPE '=' T_IPV6 ';'
2227   {
2083 #ifdef IPV6
2228    if (conf_parser_ctx.pass == 2)
2229      block_state.aftype.value = AF_INET6;
2086 #endif
2230   };
2231  
2232   connect_flags: IRCD_FLAGS
# Line 2113 | Line 2256 | connect_encrypted: ENCRYPTED '=' TBOOL '
2256    }
2257   };
2258  
2259 < connect_hub_mask: HUB_MASK '=' QSTRING ';'
2259 > connect_hub_mask: HUB_MASK '=' QSTRING ';'
2260   {
2261    if (conf_parser_ctx.pass == 2)
2262      dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.hub.list);
2263   };
2264  
2265 < connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2265 > connect_leaf_mask: LEAF_MASK '=' QSTRING ';'
2266   {
2267    if (conf_parser_ctx.pass == 2)
2268      dlinkAdd(xstrdup(yylval.string), make_dlink_node(), &block_state.leaf.list);
# Line 2161 | Line 2304 | kill_entry: KILL
2304        !block_state.host.buf[0])
2305      break;
2306  
2307 +  conf = conf_make(CONF_KLINE);
2308 +  conf->user = xstrdup(block_state.user.buf);
2309 +  conf->host = xstrdup(block_state.host.buf);
2310  
2311 <  if (block_state.port.value == 1)
2312 <  {
2167 < #ifdef HAVE_LIBPCRE
2168 <    void *exp_user = NULL;
2169 <    void *exp_host = NULL;
2170 <    const char *errptr = NULL;
2171 <
2172 <    if (!(exp_user = ircd_pcre_compile(block_state.user.buf, &errptr)) ||
2173 <        !(exp_host = ircd_pcre_compile(block_state.host.buf, &errptr)))
2174 <    {
2175 <      ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: %s",
2176 <           errptr);
2177 <      break;
2178 <    }
2179 <
2180 <    conf = conf_make(CONF_RKLINE);
2181 <    conf->regexuser = exp_user;
2182 <    conf->regexhost = exp_host;
2183 <
2184 <    conf->user = xstrdup(block_state.user.buf);
2185 <    conf->host = xstrdup(block_state.host.buf);
2186 <
2187 <    if (block_state.rpass.buf[0])
2188 <      conf->reason = xstrdup(block_state.rpass.buf);
2189 <    else
2190 <      conf->reason = xstrdup(CONF_NOREASON);
2191 < #else
2192 <    ilog(LOG_TYPE_IRCD, "Failed to add regular expression based K-Line: no PCRE support");
2193 <    break;
2194 < #endif
2195 <  }
2311 >  if (block_state.rpass.buf[0])
2312 >    conf->reason = xstrdup(block_state.rpass.buf);
2313    else
2314 <  {
2315 <    conf = conf_make(CONF_KLINE);
2199 <
2200 <    conf->user = xstrdup(block_state.user.buf);
2201 <    conf->host = xstrdup(block_state.host.buf);
2202 <
2203 <    if (block_state.rpass.buf[0])
2204 <      conf->reason = xstrdup(block_state.rpass.buf);
2205 <    else
2206 <      conf->reason = xstrdup(CONF_NOREASON);
2207 <    add_conf_by_address(CONF_KLINE, conf);
2208 <  }
2209 < };
2210 <
2211 < kill_type: TYPE
2212 < {
2213 <  if (conf_parser_ctx.pass == 2)
2214 <    block_state.port.value = 0;
2215 < } '='  kill_type_items ';';
2216 <
2217 < kill_type_items: kill_type_items ',' kill_type_item | kill_type_item;
2218 < kill_type_item: REGEX_T
2219 < {
2220 <  if (conf_parser_ctx.pass == 2)
2221 <    block_state.port.value = 1;
2314 >    conf->reason = xstrdup(CONF_NOREASON);
2315 >  add_conf_by_address(CONF_KLINE, conf);
2316   };
2317  
2318   kill_items:     kill_items kill_item | kill_item;
2319 < kill_item:      kill_user | kill_reason | kill_type | error;
2319 > kill_item:      kill_user | kill_reason | error;
2320  
2321   kill_user: USER '=' QSTRING ';'
2322   {
# Line 2244 | Line 2338 | kill_user: USER '=' QSTRING ';'
2338    }
2339   };
2340  
2341 < kill_reason: REASON '=' QSTRING ';'
2341 > kill_reason: REASON '=' QSTRING ';'
2342   {
2343    if (conf_parser_ctx.pass == 2)
2344      strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
# Line 2253 | Line 2347 | kill_reason: REASON '=' QSTRING ';'
2347   /***************************************************************************
2348   *  section deny
2349   ***************************************************************************/
2350 < deny_entry: DENY
2350 > deny_entry: DENY
2351   {
2352    if (conf_parser_ctx.pass == 2)
2353      reset_block_state();
# Line 2278 | Line 2372 | deny_entry: DENY
2372        conf->reason = xstrdup(CONF_NOREASON);
2373      add_conf_by_address(CONF_DLINE, conf);
2374    }
2375 < };
2375 > };
2376  
2377   deny_items:     deny_items deny_item | deny_item;
2378   deny_item:      deny_ip | deny_reason | error;
# Line 2289 | Line 2383 | deny_ip: IP '=' QSTRING ';'
2383      strlcpy(block_state.addr.buf, yylval.string, sizeof(block_state.addr.buf));
2384   };
2385  
2386 < deny_reason: REASON '=' QSTRING ';'
2386 > deny_reason: REASON '=' QSTRING ';'
2387   {
2388    if (conf_parser_ctx.pass == 2)
2389      strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
# Line 2334 | Line 2428 | gecos_entry: GECOS
2428    if (!block_state.name.buf[0])
2429      break;
2430  
2431 <  if (block_state.port.value == 1)
2338 <  {
2339 < #ifdef HAVE_LIBPCRE
2340 <    void *exp_p = NULL;
2341 <    const char *errptr = NULL;
2342 <
2343 <    if (!(exp_p = ircd_pcre_compile(block_state.name.buf, &errptr)))
2344 <    {
2345 <      ilog(LOG_TYPE_IRCD, "Failed to add regular expression based X-Line: %s",
2346 <           errptr);
2347 <      break;
2348 <    }
2349 <
2350 <    conf = conf_make(CONF_RXLINE);
2351 <    conf->regexuser = exp_p;
2352 < #else
2353 <    conf_error_report("Failed to add regular expression based X-Line: no PCRE support");
2354 <    break;
2355 < #endif
2356 <  }
2357 <  else
2358 <    conf = conf_make(CONF_XLINE);
2359 <
2431 >  conf = conf_make(CONF_XLINE);
2432    conf->name = xstrdup(block_state.name.buf);
2433  
2434    if (block_state.rpass.buf[0])
# Line 2365 | Line 2437 | gecos_entry: GECOS
2437      conf->reason = xstrdup(CONF_NOREASON);
2438   };
2439  
2368 gecos_flags: TYPE
2369 {
2370  if (conf_parser_ctx.pass == 2)
2371    block_state.port.value = 0;
2372 } '='  gecos_flags_items ';';
2373
2374 gecos_flags_items: gecos_flags_items ',' gecos_flags_item | gecos_flags_item;
2375 gecos_flags_item: REGEX_T
2376 {
2377  if (conf_parser_ctx.pass == 2)
2378    block_state.port.value = 1;
2379 };
2380
2440   gecos_items: gecos_items gecos_item | gecos_item;
2441 < gecos_item:  gecos_name | gecos_reason | gecos_flags | error;
2441 > gecos_item:  gecos_name | gecos_reason | error;
2442  
2443 < gecos_name: NAME '=' QSTRING ';'
2443 > gecos_name: NAME '=' QSTRING ';'
2444   {
2445    if (conf_parser_ctx.pass == 2)
2446      strlcpy(block_state.name.buf, yylval.string, sizeof(block_state.name.buf));
2447   };
2448  
2449 < gecos_reason: REASON '=' QSTRING ';'
2449 > gecos_reason: REASON '=' QSTRING ';'
2450   {
2451    if (conf_parser_ctx.pass == 2)
2452      strlcpy(block_state.rpass.buf, yylval.string, sizeof(block_state.rpass.buf));
# Line 2400 | Line 2459 | general_entry: GENERAL
2459    '{' general_items '}' ';';
2460  
2461   general_items:      general_items general_item | general_item;
2462 < general_item:       general_hide_spoof_ips | general_ignore_bogus_ts |
2463 <                    general_failed_oper_notice | general_anti_nick_flood |
2464 <                    general_max_nick_time | general_max_nick_changes |
2465 <                    general_max_accept | general_anti_spam_exit_message_time |
2466 <                    general_ts_warn_delta | general_ts_max_delta |
2462 > general_item:       general_away_count |
2463 >                    general_away_time |
2464 >                    general_hide_spoof_ips |
2465 >                    general_ignore_bogus_ts |
2466 >                    general_failed_oper_notice |
2467 >                    general_anti_nick_flood |
2468 >                    general_max_nick_time |
2469 >                    general_max_nick_changes |
2470 >                    general_max_accept |
2471 >                    general_anti_spam_exit_message_time |
2472 >                    general_ts_warn_delta |
2473 >                    general_ts_max_delta |
2474                      general_kill_chase_time_limit |
2475                      general_invisible_on_connect |
2476 <                    general_warn_no_nline | general_dots_in_ident |
2477 <                    general_stats_o_oper_only | general_stats_k_oper_only |
2478 <                    general_pace_wait | general_stats_i_oper_only |
2479 <                    general_pace_wait_simple | general_stats_P_oper_only |
2480 <                    general_short_motd | general_no_oper_flood |
2481 <                    general_true_no_oper_flood | general_oper_pass_resv |
2482 <                    general_oper_only_umodes | general_max_targets |
2483 <                    general_use_egd | general_egdpool_path |
2484 <                    general_oper_umodes | general_caller_id_wait |
2485 <                    general_opers_bypass_callerid | general_default_floodcount |
2486 <                    general_min_nonwildcard | general_min_nonwildcard_simple |
2487 <                    general_disable_remote_commands |
2488 <                    general_throttle_time | general_havent_read_conf |
2476 >                    general_warn_no_connect_block |
2477 >                    general_dots_in_ident |
2478 >                    general_stats_o_oper_only |
2479 >                    general_stats_k_oper_only |
2480 >                    general_pace_wait |
2481 >                    general_stats_i_oper_only |
2482 >                    general_pace_wait_simple |
2483 >                    general_stats_P_oper_only |
2484 >                    general_stats_u_oper_only |
2485 >                    general_short_motd |
2486 >                    general_no_oper_flood |
2487 >                    general_true_no_oper_flood |
2488 >                    general_oper_pass_resv |
2489 >                    general_oper_only_umodes |
2490 >                    general_max_targets |
2491 >                    general_oper_umodes |
2492 >                    general_caller_id_wait |
2493 >                    general_opers_bypass_callerid |
2494 >                    general_default_floodcount |
2495 >                    general_min_nonwildcard |
2496 >                    general_min_nonwildcard_simple |
2497 >                    general_throttle_count |
2498 >                    general_throttle_time |
2499 >                    general_havent_read_conf |
2500                      general_ping_cookie |
2501 <                    general_disable_auth |
2502 <                    general_tkline_expire_notices | general_gline_enable |
2503 <                    general_gline_duration | general_gline_request_duration |
2501 >                    general_disable_auth |
2502 >                    general_tkline_expire_notices |
2503 >                    general_gline_enable |
2504 >                    general_gline_duration |
2505 >                    general_gline_request_duration |
2506                      general_gline_min_cidr |
2507                      general_gline_min_cidr6 |
2508 <                    general_stats_e_disabled |
2509 <                    general_max_watch | general_services_name |
2510 <                    error;
2508 >                    general_stats_e_disabled |
2509 >                    general_max_watch |
2510 >                    general_services_name |
2511 >                    general_cycle_on_host_change |
2512 >                    error;
2513 >
2514  
2515 + general_away_count: AWAY_COUNT '=' NUMBER ';'
2516 + {
2517 +  ConfigGeneral.away_count = $3;
2518 + };
2519 +
2520 + general_away_time: AWAY_TIME '=' timespec ';'
2521 + {
2522 +  ConfigGeneral.away_time = $3;
2523 + };
2524  
2525   general_max_watch: MAX_WATCH '=' NUMBER ';'
2526   {
2527 <  ConfigFileEntry.max_watch = $3;
2527 >  ConfigGeneral.max_watch = $3;
2528 > };
2529 >
2530 > general_cycle_on_host_change: CYCLE_ON_HOST_CHANGE '=' TBOOL ';'
2531 > {
2532 >  if (conf_parser_ctx.pass == 2)
2533 >    ConfigGeneral.cycle_on_host_change = yylval.number;
2534   };
2535  
2536   general_gline_enable: GLINE_ENABLE '=' TBOOL ';'
2537   {
2538    if (conf_parser_ctx.pass == 2)
2539 <    ConfigFileEntry.glines = yylval.number;
2539 >    ConfigGeneral.glines = yylval.number;
2540   };
2541  
2542   general_gline_duration: GLINE_DURATION '=' timespec ';'
2543   {
2544    if (conf_parser_ctx.pass == 2)
2545 <    ConfigFileEntry.gline_time = $3;
2545 >    ConfigGeneral.gline_time = $3;
2546   };
2547  
2548   general_gline_request_duration: GLINE_REQUEST_DURATION '=' timespec ';'
2549   {
2550    if (conf_parser_ctx.pass == 2)
2551 <    ConfigFileEntry.gline_request_time = $3;
2551 >    ConfigGeneral.gline_request_time = $3;
2552   };
2553  
2554   general_gline_min_cidr: GLINE_MIN_CIDR '=' NUMBER ';'
2555   {
2556 <  ConfigFileEntry.gline_min_cidr = $3;
2556 >  ConfigGeneral.gline_min_cidr = $3;
2557   };
2558  
2559   general_gline_min_cidr6: GLINE_MIN_CIDR6 '=' NUMBER ';'
2560   {
2561 <  ConfigFileEntry.gline_min_cidr6 = $3;
2561 >  ConfigGeneral.gline_min_cidr6 = $3;
2562   };
2563  
2564   general_tkline_expire_notices: TKLINE_EXPIRE_NOTICES '=' TBOOL ';'
2565   {
2566 <  ConfigFileEntry.tkline_expire_notices = yylval.number;
2566 >  ConfigGeneral.tkline_expire_notices = yylval.number;
2567   };
2568  
2569   general_kill_chase_time_limit: KILL_CHASE_TIME_LIMIT '=' timespec ';'
2570   {
2571 <  ConfigFileEntry.kill_chase_time_limit = $3;
2571 >  ConfigGeneral.kill_chase_time_limit = $3;
2572   };
2573  
2574   general_hide_spoof_ips: HIDE_SPOOF_IPS '=' TBOOL ';'
2575   {
2576 <  ConfigFileEntry.hide_spoof_ips = yylval.number;
2576 >  ConfigGeneral.hide_spoof_ips = yylval.number;
2577   };
2578  
2579   general_ignore_bogus_ts: IGNORE_BOGUS_TS '=' TBOOL ';'
2580   {
2581 <  ConfigFileEntry.ignore_bogus_ts = yylval.number;
2485 < };
2486 <
2487 < general_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
2488 < {
2489 <  ConfigFileEntry.disable_remote = yylval.number;
2581 >  ConfigGeneral.ignore_bogus_ts = yylval.number;
2582   };
2583  
2584   general_failed_oper_notice: FAILED_OPER_NOTICE '=' TBOOL ';'
2585   {
2586 <  ConfigFileEntry.failed_oper_notice = yylval.number;
2586 >  ConfigGeneral.failed_oper_notice = yylval.number;
2587   };
2588  
2589   general_anti_nick_flood: ANTI_NICK_FLOOD '=' TBOOL ';'
2590   {
2591 <  ConfigFileEntry.anti_nick_flood = yylval.number;
2591 >  ConfigGeneral.anti_nick_flood = yylval.number;
2592   };
2593  
2594   general_max_nick_time: MAX_NICK_TIME '=' timespec ';'
2595   {
2596 <  ConfigFileEntry.max_nick_time = $3;
2596 >  ConfigGeneral.max_nick_time = $3;
2597   };
2598  
2599   general_max_nick_changes: MAX_NICK_CHANGES '=' NUMBER ';'
2600   {
2601 <  ConfigFileEntry.max_nick_changes = $3;
2601 >  ConfigGeneral.max_nick_changes = $3;
2602   };
2603  
2604   general_max_accept: MAX_ACCEPT '=' NUMBER ';'
2605   {
2606 <  ConfigFileEntry.max_accept = $3;
2606 >  ConfigGeneral.max_accept = $3;
2607   };
2608  
2609   general_anti_spam_exit_message_time: ANTI_SPAM_EXIT_MESSAGE_TIME '=' timespec ';'
2610   {
2611 <  ConfigFileEntry.anti_spam_exit_message_time = $3;
2611 >  ConfigGeneral.anti_spam_exit_message_time = $3;
2612   };
2613  
2614   general_ts_warn_delta: TS_WARN_DELTA '=' timespec ';'
2615   {
2616 <  ConfigFileEntry.ts_warn_delta = $3;
2616 >  ConfigGeneral.ts_warn_delta = $3;
2617   };
2618  
2619   general_ts_max_delta: TS_MAX_DELTA '=' timespec ';'
2620   {
2621    if (conf_parser_ctx.pass == 2)
2622 <    ConfigFileEntry.ts_max_delta = $3;
2622 >    ConfigGeneral.ts_max_delta = $3;
2623   };
2624  
2625   general_havent_read_conf: HAVENT_READ_CONF '=' NUMBER ';'
# Line 2543 | Line 2635 | general_havent_read_conf: HAVENT_READ_CO
2635  
2636   general_invisible_on_connect: INVISIBLE_ON_CONNECT '=' TBOOL ';'
2637   {
2638 <  ConfigFileEntry.invisible_on_connect = yylval.number;
2638 >  ConfigGeneral.invisible_on_connect = yylval.number;
2639   };
2640  
2641 < general_warn_no_nline: WARN_NO_NLINE '=' TBOOL ';'
2641 > general_warn_no_connect_block: WARN_NO_CONNECT_BLOCK '=' TBOOL ';'
2642   {
2643 <  ConfigFileEntry.warn_no_nline = yylval.number;
2643 >  ConfigGeneral.warn_no_connect_block = yylval.number;
2644   };
2645  
2646   general_stats_e_disabled: STATS_E_DISABLED '=' TBOOL ';'
2647   {
2648 <  ConfigFileEntry.stats_e_disabled = yylval.number;
2648 >  ConfigGeneral.stats_e_disabled = yylval.number;
2649   };
2650  
2651   general_stats_o_oper_only: STATS_O_OPER_ONLY '=' TBOOL ';'
2652   {
2653 <  ConfigFileEntry.stats_o_oper_only = yylval.number;
2653 >  ConfigGeneral.stats_o_oper_only = yylval.number;
2654   };
2655  
2656   general_stats_P_oper_only: STATS_P_OPER_ONLY '=' TBOOL ';'
2657   {
2658 <  ConfigFileEntry.stats_P_oper_only = yylval.number;
2658 >  ConfigGeneral.stats_P_oper_only = yylval.number;
2659 > };
2660 >
2661 > general_stats_u_oper_only: STATS_U_OPER_ONLY '=' TBOOL ';'
2662 > {
2663 >  ConfigGeneral.stats_u_oper_only = yylval.number;
2664   };
2665  
2666   general_stats_k_oper_only: STATS_K_OPER_ONLY '=' TBOOL ';'
2667   {
2668 <  ConfigFileEntry.stats_k_oper_only = 2 * yylval.number;
2668 >  ConfigGeneral.stats_k_oper_only = 2 * yylval.number;
2669   } | STATS_K_OPER_ONLY '=' TMASKED ';'
2670   {
2671 <  ConfigFileEntry.stats_k_oper_only = 1;
2671 >  ConfigGeneral.stats_k_oper_only = 1;
2672   };
2673  
2674   general_stats_i_oper_only: STATS_I_OPER_ONLY '=' TBOOL ';'
2675   {
2676 <  ConfigFileEntry.stats_i_oper_only = 2 * yylval.number;
2676 >  ConfigGeneral.stats_i_oper_only = 2 * yylval.number;
2677   } | STATS_I_OPER_ONLY '=' TMASKED ';'
2678   {
2679 <  ConfigFileEntry.stats_i_oper_only = 1;
2679 >  ConfigGeneral.stats_i_oper_only = 1;
2680   };
2681  
2682   general_pace_wait: PACE_WAIT '=' timespec ';'
2683   {
2684 <  ConfigFileEntry.pace_wait = $3;
2684 >  ConfigGeneral.pace_wait = $3;
2685   };
2686  
2687   general_caller_id_wait: CALLER_ID_WAIT '=' timespec ';'
2688   {
2689 <  ConfigFileEntry.caller_id_wait = $3;
2689 >  ConfigGeneral.caller_id_wait = $3;
2690   };
2691  
2692   general_opers_bypass_callerid: OPERS_BYPASS_CALLERID '=' TBOOL ';'
2693   {
2694 <  ConfigFileEntry.opers_bypass_callerid = yylval.number;
2694 >  ConfigGeneral.opers_bypass_callerid = yylval.number;
2695   };
2696  
2697   general_pace_wait_simple: PACE_WAIT_SIMPLE '=' timespec ';'
2698   {
2699 <  ConfigFileEntry.pace_wait_simple = $3;
2699 >  ConfigGeneral.pace_wait_simple = $3;
2700   };
2701  
2702   general_short_motd: SHORT_MOTD '=' TBOOL ';'
2703   {
2704 <  ConfigFileEntry.short_motd = yylval.number;
2704 >  ConfigGeneral.short_motd = yylval.number;
2705   };
2706 <  
2706 >
2707   general_no_oper_flood: NO_OPER_FLOOD '=' TBOOL ';'
2708   {
2709 <  ConfigFileEntry.no_oper_flood = yylval.number;
2709 >  ConfigGeneral.no_oper_flood = yylval.number;
2710   };
2711  
2712   general_true_no_oper_flood: TRUE_NO_OPER_FLOOD '=' TBOOL ';'
2713   {
2714 <  ConfigFileEntry.true_no_oper_flood = yylval.number;
2714 >  ConfigGeneral.true_no_oper_flood = yylval.number;
2715   };
2716  
2717   general_oper_pass_resv: OPER_PASS_RESV '=' TBOOL ';'
2718   {
2719 <  ConfigFileEntry.oper_pass_resv = yylval.number;
2719 >  ConfigGeneral.oper_pass_resv = yylval.number;
2720   };
2721  
2722   general_dots_in_ident: DOTS_IN_IDENT '=' NUMBER ';'
2723   {
2724 <  ConfigFileEntry.dots_in_ident = $3;
2724 >  ConfigGeneral.dots_in_ident = $3;
2725   };
2726  
2727   general_max_targets: MAX_TARGETS '=' NUMBER ';'
2728   {
2729 <  ConfigFileEntry.max_targets = $3;
2633 < };
2634 <
2635 < general_use_egd: USE_EGD '=' TBOOL ';'
2636 < {
2637 <  ConfigFileEntry.use_egd = yylval.number;
2638 < };
2639 <
2640 < general_egdpool_path: EGDPOOL_PATH '=' QSTRING ';'
2641 < {
2642 <  if (conf_parser_ctx.pass == 2)
2643 <  {
2644 <    MyFree(ConfigFileEntry.egdpool_path);
2645 <    ConfigFileEntry.egdpool_path = xstrdup(yylval.string);
2646 <  }
2729 >  ConfigGeneral.max_targets = $3;
2730   };
2731  
2732   general_services_name: T_SERVICES_NAME '=' QSTRING ';'
2733   {
2734    if (conf_parser_ctx.pass == 2 && valid_servname(yylval.string))
2735    {
2736 <    MyFree(ConfigFileEntry.service_name);
2737 <    ConfigFileEntry.service_name = xstrdup(yylval.string);
2736 >    MyFree(ConfigGeneral.service_name);
2737 >    ConfigGeneral.service_name = xstrdup(yylval.string);
2738    }
2739   };
2740  
2741   general_ping_cookie: PING_COOKIE '=' TBOOL ';'
2742   {
2743 <  ConfigFileEntry.ping_cookie = yylval.number;
2743 >  ConfigGeneral.ping_cookie = yylval.number;
2744   };
2745  
2746   general_disable_auth: DISABLE_AUTH '=' TBOOL ';'
2747   {
2748 <  ConfigFileEntry.disable_auth = yylval.number;
2748 >  ConfigGeneral.disable_auth = yylval.number;
2749 > };
2750 >
2751 > general_throttle_count: THROTTLE_COUNT '=' NUMBER ';'
2752 > {
2753 >  ConfigGeneral.throttle_count = $3;
2754   };
2755  
2756   general_throttle_time: THROTTLE_TIME '=' timespec ';'
2757   {
2758 <  ConfigFileEntry.throttle_time = yylval.number;
2758 >  ConfigGeneral.throttle_time = $3;
2759   };
2760  
2761   general_oper_umodes: OPER_UMODES
2762   {
2763 <  ConfigFileEntry.oper_umodes = 0;
2763 >  ConfigGeneral.oper_umodes = 0;
2764   } '='  umode_oitems ';' ;
2765  
2766   umode_oitems:    umode_oitems ',' umode_oitem | umode_oitem;
2767   umode_oitem:     T_BOTS
2768   {
2769 <  ConfigFileEntry.oper_umodes |= UMODE_BOTS;
2769 >  ConfigGeneral.oper_umodes |= UMODE_BOTS;
2770   } | T_CCONN
2771   {
2772 <  ConfigFileEntry.oper_umodes |= UMODE_CCONN;
2685 < } | T_CCONN_FULL
2686 < {
2687 <  ConfigFileEntry.oper_umodes |= UMODE_CCONN_FULL;
2772 >  ConfigGeneral.oper_umodes |= UMODE_CCONN;
2773   } | T_DEAF
2774   {
2775 <  ConfigFileEntry.oper_umodes |= UMODE_DEAF;
2775 >  ConfigGeneral.oper_umodes |= UMODE_DEAF;
2776   } | T_DEBUG
2777   {
2778 <  ConfigFileEntry.oper_umodes |= UMODE_DEBUG;
2778 >  ConfigGeneral.oper_umodes |= UMODE_DEBUG;
2779   } | T_FULL
2780   {
2781 <  ConfigFileEntry.oper_umodes |= UMODE_FULL;
2781 >  ConfigGeneral.oper_umodes |= UMODE_FULL;
2782   } | HIDDEN
2783   {
2784 <  ConfigFileEntry.oper_umodes |= UMODE_HIDDEN;
2784 >  ConfigGeneral.oper_umodes |= UMODE_HIDDEN;
2785 > } | HIDE_CHANS
2786 > {
2787 >  ConfigGeneral.oper_umodes |= UMODE_HIDECHANS;
2788 > } | HIDE_IDLE
2789 > {
2790 >  ConfigGeneral.oper_umodes |= UMODE_HIDEIDLE;
2791   } | T_SKILL
2792   {
2793 <  ConfigFileEntry.oper_umodes |= UMODE_SKILL;
2793 >  ConfigGeneral.oper_umodes |= UMODE_SKILL;
2794   } | T_NCHANGE
2795   {
2796 <  ConfigFileEntry.oper_umodes |= UMODE_NCHANGE;
2796 >  ConfigGeneral.oper_umodes |= UMODE_NCHANGE;
2797   } | T_REJ
2798   {
2799 <  ConfigFileEntry.oper_umodes |= UMODE_REJ;
2799 >  ConfigGeneral.oper_umodes |= UMODE_REJ;
2800   } | T_UNAUTH
2801   {
2802 <  ConfigFileEntry.oper_umodes |= UMODE_UNAUTH;
2802 >  ConfigGeneral.oper_umodes |= UMODE_UNAUTH;
2803   } | T_SPY
2804   {
2805 <  ConfigFileEntry.oper_umodes |= UMODE_SPY;
2805 >  ConfigGeneral.oper_umodes |= UMODE_SPY;
2806   } | T_EXTERNAL
2807   {
2808 <  ConfigFileEntry.oper_umodes |= UMODE_EXTERNAL;
2718 < } | T_OPERWALL
2719 < {
2720 <  ConfigFileEntry.oper_umodes |= UMODE_OPERWALL;
2808 >  ConfigGeneral.oper_umodes |= UMODE_EXTERNAL;
2809   } | T_SERVNOTICE
2810   {
2811 <  ConfigFileEntry.oper_umodes |= UMODE_SERVNOTICE;
2811 >  ConfigGeneral.oper_umodes |= UMODE_SERVNOTICE;
2812   } | T_INVISIBLE
2813   {
2814 <  ConfigFileEntry.oper_umodes |= UMODE_INVISIBLE;
2814 >  ConfigGeneral.oper_umodes |= UMODE_INVISIBLE;
2815   } | T_WALLOP
2816   {
2817 <  ConfigFileEntry.oper_umodes |= UMODE_WALLOP;
2817 >  ConfigGeneral.oper_umodes |= UMODE_WALLOP;
2818   } | T_SOFTCALLERID
2819   {
2820 <  ConfigFileEntry.oper_umodes |= UMODE_SOFTCALLERID;
2820 >  ConfigGeneral.oper_umodes |= UMODE_SOFTCALLERID;
2821   } | T_CALLERID
2822   {
2823 <  ConfigFileEntry.oper_umodes |= UMODE_CALLERID;
2823 >  ConfigGeneral.oper_umodes |= UMODE_CALLERID;
2824   } | T_LOCOPS
2825   {
2826 <  ConfigFileEntry.oper_umodes |= UMODE_LOCOPS;
2826 >  ConfigGeneral.oper_umodes |= UMODE_LOCOPS;
2827 > } | T_NONONREG
2828 > {
2829 >  ConfigGeneral.oper_umodes |= UMODE_REGONLY;
2830 > } | T_FARCONNECT
2831 > {
2832 >  ConfigGeneral.oper_umodes |= UMODE_FARCONNECT;
2833   };
2834  
2835 < general_oper_only_umodes: OPER_ONLY_UMODES
2835 > general_oper_only_umodes: OPER_ONLY_UMODES
2836   {
2837 <  ConfigFileEntry.oper_only_umodes = 0;
2837 >  ConfigGeneral.oper_only_umodes = 0;
2838   } '='  umode_items ';' ;
2839  
2840 < umode_items:    umode_items ',' umode_item | umode_item;
2841 < umode_item:     T_BOTS
2840 > umode_items:  umode_items ',' umode_item | umode_item;
2841 > umode_item:   T_BOTS
2842   {
2843 <  ConfigFileEntry.oper_only_umodes |= UMODE_BOTS;
2843 >  ConfigGeneral.oper_only_umodes |= UMODE_BOTS;
2844   } | T_CCONN
2845   {
2846 <  ConfigFileEntry.oper_only_umodes |= UMODE_CCONN;
2753 < } | T_CCONN_FULL
2754 < {
2755 <  ConfigFileEntry.oper_only_umodes |= UMODE_CCONN_FULL;
2846 >  ConfigGeneral.oper_only_umodes |= UMODE_CCONN;
2847   } | T_DEAF
2848   {
2849 <  ConfigFileEntry.oper_only_umodes |= UMODE_DEAF;
2849 >  ConfigGeneral.oper_only_umodes |= UMODE_DEAF;
2850   } | T_DEBUG
2851   {
2852 <  ConfigFileEntry.oper_only_umodes |= UMODE_DEBUG;
2852 >  ConfigGeneral.oper_only_umodes |= UMODE_DEBUG;
2853   } | T_FULL
2854 < {
2855 <  ConfigFileEntry.oper_only_umodes |= UMODE_FULL;
2854 > {
2855 >  ConfigGeneral.oper_only_umodes |= UMODE_FULL;
2856   } | T_SKILL
2857   {
2858 <  ConfigFileEntry.oper_only_umodes |= UMODE_SKILL;
2858 >  ConfigGeneral.oper_only_umodes |= UMODE_SKILL;
2859   } | HIDDEN
2860   {
2861 <  ConfigFileEntry.oper_only_umodes |= UMODE_HIDDEN;
2861 >  ConfigGeneral.oper_only_umodes |= UMODE_HIDDEN;
2862   } | T_NCHANGE
2863   {
2864 <  ConfigFileEntry.oper_only_umodes |= UMODE_NCHANGE;
2864 >  ConfigGeneral.oper_only_umodes |= UMODE_NCHANGE;
2865   } | T_REJ
2866   {
2867 <  ConfigFileEntry.oper_only_umodes |= UMODE_REJ;
2867 >  ConfigGeneral.oper_only_umodes |= UMODE_REJ;
2868   } | T_UNAUTH
2869   {
2870 <  ConfigFileEntry.oper_only_umodes |= UMODE_UNAUTH;
2870 >  ConfigGeneral.oper_only_umodes |= UMODE_UNAUTH;
2871   } | T_SPY
2872   {
2873 <  ConfigFileEntry.oper_only_umodes |= UMODE_SPY;
2873 >  ConfigGeneral.oper_only_umodes |= UMODE_SPY;
2874   } | T_EXTERNAL
2875   {
2876 <  ConfigFileEntry.oper_only_umodes |= UMODE_EXTERNAL;
2786 < } | T_OPERWALL
2787 < {
2788 <  ConfigFileEntry.oper_only_umodes |= UMODE_OPERWALL;
2876 >  ConfigGeneral.oper_only_umodes |= UMODE_EXTERNAL;
2877   } | T_SERVNOTICE
2878   {
2879 <  ConfigFileEntry.oper_only_umodes |= UMODE_SERVNOTICE;
2879 >  ConfigGeneral.oper_only_umodes |= UMODE_SERVNOTICE;
2880   } | T_INVISIBLE
2881   {
2882 <  ConfigFileEntry.oper_only_umodes |= UMODE_INVISIBLE;
2882 >  ConfigGeneral.oper_only_umodes |= UMODE_INVISIBLE;
2883   } | T_WALLOP
2884   {
2885 <  ConfigFileEntry.oper_only_umodes |= UMODE_WALLOP;
2885 >  ConfigGeneral.oper_only_umodes |= UMODE_WALLOP;
2886   } | T_SOFTCALLERID
2887   {
2888 <  ConfigFileEntry.oper_only_umodes |= UMODE_SOFTCALLERID;
2888 >  ConfigGeneral.oper_only_umodes |= UMODE_SOFTCALLERID;
2889   } | T_CALLERID
2890   {
2891 <  ConfigFileEntry.oper_only_umodes |= UMODE_CALLERID;
2891 >  ConfigGeneral.oper_only_umodes |= UMODE_CALLERID;
2892   } | T_LOCOPS
2893   {
2894 <  ConfigFileEntry.oper_only_umodes |= UMODE_LOCOPS;
2894 >  ConfigGeneral.oper_only_umodes |= UMODE_LOCOPS;
2895   } | T_NONONREG
2896   {
2897 <  ConfigFileEntry.oper_only_umodes |= UMODE_REGONLY;
2897 >  ConfigGeneral.oper_only_umodes |= UMODE_REGONLY;
2898 > } | T_FARCONNECT
2899 > {
2900 >  ConfigGeneral.oper_only_umodes |= UMODE_FARCONNECT;
2901   };
2902  
2903   general_min_nonwildcard: MIN_NONWILDCARD '=' NUMBER ';'
2904   {
2905 <  ConfigFileEntry.min_nonwildcard = $3;
2905 >  ConfigGeneral.min_nonwildcard = $3;
2906   };
2907  
2908   general_min_nonwildcard_simple: MIN_NONWILDCARD_SIMPLE '=' NUMBER ';'
2909   {
2910 <  ConfigFileEntry.min_nonwildcard_simple = $3;
2910 >  ConfigGeneral.min_nonwildcard_simple = $3;
2911   };
2912  
2913   general_default_floodcount: DEFAULT_FLOODCOUNT '=' NUMBER ';'
2914   {
2915 <  ConfigFileEntry.default_floodcount = $3;
2915 >  ConfigGeneral.default_floodcount = $3;
2916   };
2917  
2918  
# Line 2833 | Line 2924 | channel_entry: CHANNEL
2924  
2925   channel_items:      channel_items channel_item | channel_item;
2926   channel_item:       channel_max_bans |
2927 <                    channel_knock_delay | channel_knock_delay_channel |
2928 <                    channel_max_chans_per_user | channel_max_chans_per_oper |
2929 <                    channel_quiet_on_ban | channel_default_split_user_count |
2927 >                    channel_invite_client_count |
2928 >                    channel_invite_client_time |
2929 >                    channel_knock_client_count |
2930 >                    channel_knock_client_time |
2931 >                    channel_knock_delay_channel |
2932 >                    channel_max_channels |
2933 >                    channel_default_split_user_count |
2934                      channel_default_split_server_count |
2935                      channel_no_create_on_split |
2936                      channel_no_join_on_split |
2937 <                    channel_jflood_count | channel_jflood_time |
2938 <                    channel_disable_fake_channels | error;
2937 >                    channel_jflood_count |
2938 >                    channel_jflood_time |
2939 >                    channel_disable_fake_channels |
2940 >                    error;
2941  
2942   channel_disable_fake_channels: DISABLE_FAKE_CHANNELS '=' TBOOL ';'
2943   {
2944    ConfigChannel.disable_fake_channels = yylval.number;
2945   };
2946  
2947 < channel_knock_delay: KNOCK_DELAY '=' timespec ';'
2947 > channel_invite_client_count: INVITE_CLIENT_COUNT '=' NUMBER ';'
2948   {
2949 <  ConfigChannel.knock_delay = $3;
2949 >  ConfigChannel.invite_client_count = $3;
2950   };
2951  
2952 < channel_knock_delay_channel: KNOCK_DELAY_CHANNEL '=' timespec ';'
2952 > channel_invite_client_time: INVITE_CLIENT_TIME '=' timespec ';'
2953   {
2954 <  ConfigChannel.knock_delay_channel = $3;
2954 >  ConfigChannel.invite_client_time = $3;
2955   };
2956  
2957 < channel_max_chans_per_user: MAX_CHANS_PER_USER '=' NUMBER ';'
2957 > channel_knock_client_count: KNOCK_CLIENT_COUNT '=' NUMBER ';'
2958   {
2959 <  ConfigChannel.max_chans_per_user = $3;
2959 >  ConfigChannel.knock_client_count = $3;
2960   };
2961  
2962 < channel_max_chans_per_oper: MAX_CHANS_PER_OPER '=' NUMBER ';'
2962 > channel_knock_client_time: KNOCK_CLIENT_TIME '=' timespec ';'
2963   {
2964 <  ConfigChannel.max_chans_per_oper = $3;
2964 >  ConfigChannel.knock_client_time = $3;
2965   };
2966  
2967 < channel_quiet_on_ban: QUIET_ON_BAN '=' TBOOL ';'
2967 > channel_knock_delay_channel: KNOCK_DELAY_CHANNEL '=' timespec ';'
2968   {
2969 <  ConfigChannel.quiet_on_ban = yylval.number;
2969 >  ConfigChannel.knock_delay_channel = $3;
2970 > };
2971 >
2972 > channel_max_channels: MAX_CHANNELS '=' NUMBER ';'
2973 > {
2974 >  ConfigChannel.max_channels = $3;
2975   };
2976  
2977   channel_max_bans: MAX_BANS '=' NUMBER ';'
# Line 2904 | Line 3006 | channel_jflood_count: JOIN_FLOOD_COUNT '
3006  
3007   channel_jflood_time: JOIN_FLOOD_TIME '=' timespec ';'
3008   {
3009 <  GlobalSetOptions.joinfloodtime = yylval.number;
3009 >  GlobalSetOptions.joinfloodtime = $3;
3010   };
3011  
3012   /***************************************************************************
# Line 2914 | Line 3016 | serverhide_entry: SERVERHIDE
3016    '{' serverhide_items '}' ';';
3017  
3018   serverhide_items:   serverhide_items serverhide_item | serverhide_item;
3019 < serverhide_item:    serverhide_flatten_links | serverhide_hide_servers |
3020 <                    serverhide_hide_services |
3021 <                    serverhide_links_delay |
3022 <                    serverhide_hidden | serverhide_hidden_name |
3023 <                    serverhide_hide_server_ips |
3019 > serverhide_item:    serverhide_flatten_links |
3020 >                    serverhide_disable_remote_commands |
3021 >                    serverhide_hide_servers |
3022 >                    serverhide_hide_services |
3023 >                    serverhide_links_delay |
3024 >                    serverhide_hidden |
3025 >                    serverhide_hidden_name |
3026 >                    serverhide_hide_server_ips |
3027                      error;
3028  
3029   serverhide_flatten_links: FLATTEN_LINKS '=' TBOOL ';'
# Line 2927 | Line 3032 | serverhide_flatten_links: FLATTEN_LINKS
3032      ConfigServerHide.flatten_links = yylval.number;
3033   };
3034  
3035 + serverhide_disable_remote_commands: DISABLE_REMOTE_COMMANDS '=' TBOOL ';'
3036 + {
3037 +  if (conf_parser_ctx.pass == 2)
3038 +    ConfigServerHide.disable_remote_commands = yylval.number;
3039 + };
3040 +
3041   serverhide_hide_servers: HIDE_SERVERS '=' TBOOL ';'
3042   {
3043    if (conf_parser_ctx.pass == 2)
# Line 2954 | Line 3065 | serverhide_links_delay: LINKS_DELAY '='
3065    {
3066      if (($3 > 0) && ConfigServerHide.links_disabled == 1)
3067      {
3068 <      eventAddIsh("write_links_file", write_links_file, NULL, $3);
3068 >      event_write_links_file.when = $3;
3069 >      event_addish(&event_write_links_file, NULL);
3070        ConfigServerHide.links_disabled = 0;
3071      }
3072  

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)