ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/server.c
(Generate patch)

Comparing:
ircd-hybrid-7.2/src/s_serv.c (file contents), Revision 992 by michael, Mon Aug 17 19:19:16 2009 UTC vs.
ircd-hybrid/trunk/src/s_serv.c (file contents), Revision 3274 by michael, Sun Apr 6 12:22:23 2014 UTC

# Line 1 | Line 1
1   /*
2 < *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  s_serv.c: Server related functions.
2 > *  ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3   *
4 < *  Copyright (C) 2005 by the past and present ircd coders, and others.
4 > *  Copyright (c) 1997-2014 ircd-hybrid development team
5   *
6   *  This program is free software; you can redistribute it and/or modify
7   *  it under the terms of the GNU General Public License as published by
# Line 18 | Line 17
17   *  along with this program; if not, write to the Free Software
18   *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
19   *  USA
20 < *
21 < *  $Id$
20 > */
21 >
22 > /*! \file s_serv.c
23 > * \brief Server related functions.
24 > * \version $Id$
25   */
26  
27   #include "stdinc.h"
# Line 27 | Line 29
29   #include <openssl/rsa.h>
30   #include "rsa.h"
31   #endif
32 < #include "tools.h"
31 < #include "channel.h"
32 < #include "channel_mode.h"
32 > #include "list.h"
33   #include "client.h"
34 – #include "common.h"
35 – #include "dbuf.h"
34   #include "event.h"
37 – #include "fdlist.h"
35   #include "hash.h"
36   #include "irc_string.h"
40 – #include "inet_misc.h"
41 – #include "sprintf_irc.h"
37   #include "ircd.h"
38   #include "ircd_defs.h"
39   #include "s_bsd.h"
45 – #include "irc_getnameinfo.h"
46 – #include "list.h"
40   #include "numeric.h"
41   #include "packet.h"
42 < #include "irc_res.h"
50 < #include "s_conf.h"
42 > #include "conf.h"
43   #include "s_serv.h"
44 < #include "s_log.h"
44 > #include "log.h"
45 > #include "s_misc.h"
46   #include "s_user.h"
47   #include "send.h"
48   #include "memory.h"
49 < #include "channel.h" /* chcap_usage_counts stuff...*/
49 > #include "channel.h"
50 > #include "parse.h"
51  
52   #define MIN_CONN_FREQ 300
53  
54 + dlink_list flatten_links;
55   static dlink_list cap_list = { NULL, NULL, 0 };
56   static void server_burst(struct Client *);
62 – static int fork_server(struct Client *);
57   static void burst_all(struct Client *);
58   static void send_tb(struct Client *client_p, struct Channel *chptr);
59  
60   static CNCB serv_connect_callback;
61  
68 – static void start_io(struct Client *);
62   static void burst_members(struct Client *, struct Channel *);
63  
71 – static SlinkRplHnd slink_error;
72 – static SlinkRplHnd slink_zipstats;
73 –
74 –
75 – #ifdef HAVE_LIBCRYPTO
76 – struct EncCapability CipherTable[] =
77 – {
78 – #ifdef HAVE_EVP_BF_CFB
79 –  { "BF/168",     CAP_ENC_BF_168,     24, CIPHER_BF     },
80 –  { "BF/128",     CAP_ENC_BF_128,     16, CIPHER_BF     },
81 – #endif
82 – #ifdef HAVE_EVP_CAST5_CFB
83 –  { "CAST/128",   CAP_ENC_CAST_128,   16, CIPHER_CAST   },
84 – #endif
85 – #ifdef HAVE_EVP_IDEA_CFB
86 –  { "IDEA/128",   CAP_ENC_IDEA_128,   16, CIPHER_IDEA   },
87 – #endif
88 – #ifdef HAVE_EVP_RC5_32_12_16_CFB
89 –  { "RC5.16/128", CAP_ENC_RC5_16_128, 16, CIPHER_RC5_16 },
90 –  { "RC5.12/128", CAP_ENC_RC5_12_128, 16, CIPHER_RC5_12 },
91 –  { "RC5.8/128",  CAP_ENC_RC5_8_128,  16, CIPHER_RC5_8  },
92 – #endif
93 – #ifdef HAVE_EVP_DES_EDE3_CFB
94 –  { "3DES/168",   CAP_ENC_3DES_168,   24, CIPHER_3DES   },
95 – #endif
96 – #ifdef HAVE_EVP_DES_CFB
97 –  { "DES/56",     CAP_ENC_DES_56,      8, CIPHER_DES    },
98 – #endif
99 –  { 0,            0,                   0, 0             }
100 – };
101 – #endif
102 –
103 – struct SlinkRplDef slinkrpltab[] = {
104 –  { SLINKRPL_ERROR,    slink_error,    SLINKRPL_FLAG_DATA },
105 –  { SLINKRPL_ZIPSTATS, slink_zipstats, SLINKRPL_FLAG_DATA },
106 –  { 0,                 0,              0 },
107 – };
108 –
109 –
110 – void
111 – slink_error(unsigned int rpl, unsigned int len, unsigned char *data,
112 –            struct Client *server_p)
113 – {
114 –  assert(rpl == SLINKRPL_ERROR);
115 –  assert(len < 256);
116 –
117 –  data[len-1] = '\0';
118 –
119 –  sendto_realops_flags(UMODE_ALL, L_ALL, "SlinkError for %s: %s",
120 –                       server_p->name, data);
121 –  /* XXX should this be exit_client? */
122 –  exit_client(server_p, &me, "servlink error -- terminating link");
123 – }
124 –
125 – void
126 – slink_zipstats(unsigned int rpl, unsigned int len, unsigned char *data,
127 –               struct Client *server_p)
128 – {
129 –  struct ZipStats zipstats;
130 –  uint64_t in = 0, in_wire = 0, out = 0, out_wire = 0;
131 –  int i = 0;
132 –
133 –  assert(rpl == SLINKRPL_ZIPSTATS);
134 –  assert(len == 16);
135 –  assert(IsCapable(server_p, CAP_ZIP));
136 –
137 –  /* Yes, it needs to be done this way, no we cannot let the compiler
138 –   * work with the pointer to the structure.  This works around a GCC
139 –   * bug on SPARC that affects all versions at the time of this writing.
140 –   * I will feed you to the creatures living in RMS's beard if you do
141 –   * not leave this as is, without being sure that you are not causing
142 –   * regression for most of our installed SPARC base.
143 –   * -jmallett, 04/27/2002
144 –   */
145 –  memcpy(&zipstats, &server_p->localClient->zipstats, sizeof(struct ZipStats));
146 –
147 –  in |= (data[i++] << 24);
148 –  in |= (data[i++] << 16);
149 –  in |= (data[i++] <<  8);
150 –  in |= (data[i++]      );
151 –
152 –  in_wire |= (data[i++] << 24);
153 –  in_wire |= (data[i++] << 16);
154 –  in_wire |= (data[i++] <<  8);
155 –  in_wire |= (data[i++]      );
156 –
157 –  out |= (data[i++] << 24);
158 –  out |= (data[i++] << 16);
159 –  out |= (data[i++] <<  8);
160 –  out |= (data[i++]      );
161 –
162 –  out_wire |= (data[i++] << 24);
163 –  out_wire |= (data[i++] << 16);
164 –  out_wire |= (data[i++] <<  8);
165 –  out_wire |= (data[i++]      );
166 –
167 –  /* This macro adds b to a if a plus b is not an overflow, and sets the
168 –   * value of a to b if it is.
169 –   * Add and Set if No Overflow.
170 –   */
171 – #define ASNO(a, b) a = (a + b >= a ? a + b : b)
172 –
173 –  ASNO(zipstats.in, in);
174 –  ASNO(zipstats.out, out);
175 –  ASNO(zipstats.in_wire, in_wire);
176 –  ASNO(zipstats.out_wire, out_wire);
177 –
178 –  if (zipstats.in > 0)
179 –    zipstats.in_ratio = (((double)(zipstats.in - zipstats.in_wire) /
180 –                         (double)zipstats.in) * 100.00);
181 –  else
182 –    zipstats.in_ratio = 0;
183 –
184 –  if (zipstats.out > 0)
185 –    zipstats.out_ratio = (((double)(zipstats.out - zipstats.out_wire) /
186 –                          (double)zipstats.out) * 100.00);
187 –  else
188 –    zipstats.out_ratio = 0;
189 –
190 –  memcpy(&server_p->localClient->zipstats, &zipstats, sizeof(struct ZipStats));
191 – }
192 –
193 – void
194 – collect_zipstats(void *unused)
195 – {
196 –  dlink_node *ptr = NULL;
197 –
198 –  DLINK_FOREACH(ptr, serv_list.head)
199 –  {
200 –    struct Client *target_p = ptr->data;
201 –
202 –    if (IsCapable(target_p, CAP_ZIP))
203 –    {
204 –      /* only bother if we haven't already got something queued... */
205 –      if (!target_p->localClient->slinkq)
206 –      {
207 –        target_p->localClient->slinkq     = MyMalloc(1); /* sigh.. */
208 –        target_p->localClient->slinkq[0]  = SLINKCMD_ZIPSTATS;
209 –        target_p->localClient->slinkq_ofs = 0;
210 –        target_p->localClient->slinkq_len = 1;
211 –        send_queued_slink_write(target_p);
212 –      }
213 –    }
214 –  }
215 – }
216 –
217 – #ifdef HAVE_LIBCRYPTO
218 – struct EncCapability *
219 – check_cipher(struct Client *client_p, struct AccessItem *aconf)
220 – {
221 –  struct EncCapability *epref = NULL;
222 –
223 –  /* Use connect{} specific info if available */
224 –  if (aconf->cipher_preference)
225 –    epref = aconf->cipher_preference;
226 –  else if (ConfigFileEntry.default_cipher_preference)
227 –    epref = ConfigFileEntry.default_cipher_preference;
228 –
229 –  /*
230 –   * If the server supports the capability in hand, return the matching
231 –   * conf struct.  Otherwise, return NULL (an error).
232 –   */
233 –  if (epref && IsCapableEnc(client_p, epref->cap))
234 –    return epref;
235 –
236 –  return NULL;
237 – }
238 – #endif /* HAVE_LIBCRYPTO */
239 –
240 – /* my_name_for_link()
241 – * return wildcard name of my server name
242 – * according to given config entry --Jto
243 – */
244 – const char *
245 – my_name_for_link(struct ConfItem *conf)
246 – {
247 –  struct AccessItem *aconf;
248 –
249 –  aconf = (struct AccessItem *)map_to_conf(conf);
250 –  if (aconf->fakename != NULL)
251 –    return aconf->fakename;
252 –  else
253 –    return me.name;
254 – }
255 –
64   /*
65   * write_links_file
66   *
# Line 262 | Line 70 | my_name_for_link(struct ConfItem *conf)
70   *                but in no particular order.
71   */
72   void
73 < write_links_file(void* notused)
73 > write_links_file(void *notused)
74   {
75 <  MessageFileLine *next_mptr = 0;
76 <  MessageFileLine *mptr = 0;
77 <  MessageFileLine *currentMessageLine = 0;
270 <  MessageFileLine *newMessageLine = 0;
271 <  MessageFile *MessageFileptr;
272 <  const char *p;
273 <  FBFILE *file;
274 <  char buff[512];
275 <  dlink_node *ptr;
276 <
277 <  MessageFileptr = &ConfigFileEntry.linksfile;
75 >  FILE *file = NULL;
76 >  dlink_node *ptr = NULL, *ptr_next = NULL;
77 >  char buff[IRCD_BUFSIZE] = "";
78  
79 <  if ((file = fbopen(MessageFileptr->fileName, "w")) == NULL)
79 >  if ((file = fopen(LIPATH, "w")) == NULL)
80      return;
81  
82 <  for (mptr = MessageFileptr->contentsOfFile; mptr; mptr = next_mptr)
82 >  DLINK_FOREACH_SAFE(ptr, ptr_next, flatten_links.head)
83    {
84 <    next_mptr = mptr->next;
85 <    MyFree(mptr);
84 >    dlinkDelete(ptr, &flatten_links);
85 >    MyFree(ptr->data);
86 >    free_dlink_node(ptr);
87    }
88  
288 –  MessageFileptr->contentsOfFile = NULL;
289 –  currentMessageLine             = NULL;
290 –
89    DLINK_FOREACH(ptr, global_serv_list.head)
90    {
91 <    size_t nbytes = 0;
294 <    struct Client *target_p = ptr->data;
91 >    const struct Client *target_p = ptr->data;
92  
93 <    /* skip ourselves, we send ourselves in /links */
94 <    if (IsMe(target_p))
93 >    /*
94 >     * Skip hidden servers, aswell as ourselves, since we already send
95 >     * ourselves in /links
96 >     */
97 >    if (IsHidden(target_p) || IsMe(target_p))
98        continue;
99  
100 <    /* skip hidden servers */
301 <    if (IsHidden(target_p) && !ConfigServerHide.disable_hidden)
100 >    if (HasFlag(target_p, FLAGS_SERVICE) && ConfigServerHide.hide_services)
101        continue;
102  
103 <    if (target_p->info[0])
104 <      p = target_p->info;
306 <    else
307 <      p = "(Unknown Location)";
308 <
309 <    newMessageLine = MyMalloc(sizeof(MessageFileLine));
310 <
311 <    /* Attempt to format the file in such a way it follows the usual links output
103 >    /*
104 >     * Attempt to format the file in such a way it follows the usual links output
105       * ie  "servername uplink :hops info"
106       * Mostly for aesthetic reasons - makes it look pretty in mIRC ;)
107       * - madmax
108       */
109 +    snprintf(buff, sizeof(buff), "%s %s :1 %s",   target_p->name,
110 +             me.name, target_p->info);
111 +    dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
112 +    snprintf(buff, sizeof(buff), "%s %s :1 %s\n", target_p->name,
113 +             me.name, target_p->info);
114  
115 <    /*
116 <     * For now, check this ircsprintf wont overflow - it shouldnt on a
319 <     * default config but it is configurable..
320 <     * This should be changed to an snprintf at some point, but I'm wanting to
321 <     * know if this is a cause of a bug - cryogen
322 <     */
323 <    assert(strlen(target_p->name) + strlen(me.name) + 6 + strlen(p) <=
324 <            MESSAGELINELEN);
325 <    ircsprintf(newMessageLine->line, "%s %s :1 %s",
326 <               target_p->name, me.name, p);
327 <    newMessageLine->next = NULL;
115 >    fputs(buff, file);
116 >  }
117  
118 <    if (MessageFileptr->contentsOfFile)
119 <    {
120 <      if (currentMessageLine)
121 <        currentMessageLine->next = newMessageLine;
122 <      currentMessageLine = newMessageLine;
123 <    }
124 <    else
125 <    {
126 <      MessageFileptr->contentsOfFile = newMessageLine;
127 <      currentMessageLine = newMessageLine;
128 <    }
118 >  fclose(file);
119 > }
120 >
121 > void
122 > read_links_file(void)
123 > {
124 >  FILE *file = NULL;
125 >  char *p = NULL;
126 >  char buff[IRCD_BUFSIZE] = "";
127 >
128 >  if ((file = fopen(LIPATH, "r")) == NULL)
129 >    return;
130  
131 <    nbytes = ircsprintf(buff, "%s %s :1 %s\n", target_p->name, me.name, p);
132 <    fbputs(buff, file, nbytes);
131 >  while (fgets(buff, sizeof(buff), file))
132 >  {
133 >    if ((p = strchr(buff, '\n')))
134 >      *p = '\0';
135 >
136 >    dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
137    }
138  
139 <  fbclose(file);
139 >  fclose(file);
140   }
141  
142   /* hunt_server()
# Line 365 | Line 159 | write_links_file(void* notused)
159   *      returns: (see #defines)
160   */
161   int
162 < hunt_server(struct Client *client_p, struct Client *source_p, const char *command,
163 <            int server, int parc, char *parv[])
162 > hunt_server(struct Client *source_p, const char *command,
163 >            const int server, const int parc, char *parv[])
164   {
165    struct Client *target_p = NULL;
166    struct Client *target_tmp = NULL;
167    dlink_node *ptr;
168    int wilds;
169  
170 <  /* Assume it's me, if no server
171 <   */
172 <  if (parc <= server || EmptyString(parv[server]) ||
173 <      match(me.name, parv[server]) ||
174 <      match(parv[server], me.name) ||
175 <      !strcmp(parv[server], me.id))
382 <    return(HUNTED_ISME);
170 >  /* Assume it's me, if no server */
171 >  if (parc <= server || EmptyString(parv[server]))
172 >    return HUNTED_ISME;
173 >
174 >  if (!strcmp(parv[server], me.id) || !match(parv[server], me.name))
175 >    return HUNTED_ISME;
176  
177    /* These are to pickup matches that would cause the following
178     * message to go in the wrong direction while doing quick fast
179     * non-matching lookups.
180     */
181    if (MyClient(source_p))
182 <    target_p = find_client(parv[server]);
182 >    target_p = hash_find_client(parv[server]);
183    else
184 <    target_p = find_person(client_p, parv[server]);
184 >    target_p = find_person(source_p, parv[server]);
185  
186    if (target_p)
187      if (target_p->from == source_p->from && !MyConnect(target_p))
188        target_p = NULL;
189  
190 <  if (target_p == NULL && (target_p = find_server(parv[server])))
190 >  if (target_p == NULL && (target_p = hash_find_server(parv[server])))
191      if (target_p->from == source_p->from && !MyConnect(target_p))
192        target_p = NULL;
193  
194 <  collapse(parv[server]);
402 <  wilds = (strchr(parv[server], '?') || strchr(parv[server], '*'));
194 >  wilds = has_wildcards(parv[server]);
195  
196    /* Again, if there are no wild cards involved in the server
197     * name, use the hash lookup
# Line 408 | Line 200 | hunt_server(struct Client *client_p, str
200    {
201      if (!wilds)
202      {
203 <      if (!(target_p = find_server(parv[server])))
203 >      if (!(target_p = hash_find_server(parv[server])))
204        {
205 <        sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
206 <                   me.name, parv[0], parv[server]);
415 <        return(HUNTED_NOSUCH);
205 >        sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
206 >        return HUNTED_NOSUCH;
207        }
208      }
209      else
# Line 421 | Line 212 | hunt_server(struct Client *client_p, str
212        {
213          target_tmp = ptr->data;
214  
215 <        if (match(parv[server], target_tmp->name))
215 >        if (!match(parv[server], target_tmp->name))
216          {
217            if (target_tmp->from == source_p->from && !MyConnect(target_tmp))
218              continue;
219            target_p = ptr->data;
220  
221 <          if (IsRegistered(target_p) && (target_p != client_p))
221 >          if (IsRegistered(target_p) && (target_p != source_p->from))
222              break;
223          }
224        }
225      }
226    }
227  
228 <  if (target_p != NULL)
228 >  if (target_p)
229    {
230 <    if(!IsRegistered(target_p))
230 >    if (!IsRegistered(target_p))
231      {
232 <      sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
442 <                 me.name, parv[0], parv[server]);
232 >      sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
233        return HUNTED_NOSUCH;
234      }
235  
236      if (IsMe(target_p) || MyClient(target_p))
237        return HUNTED_ISME;
238  
239 <    if (!match(target_p->name, parv[server]))
239 >    if (match(target_p->name, parv[server]))
240        parv[server] = target_p->name;
241  
242      /* This is a little kludgy but should work... */
243 <    if (IsClient(source_p) &&
454 <        ((MyConnect(target_p) && IsCapable(target_p, CAP_TS6)) ||
455 <         (!MyConnect(target_p) && IsCapable(target_p->from, CAP_TS6))))
456 <      parv[0] = ID(source_p);
457 <
458 <    sendto_one(target_p, command, parv[0],
243 >    sendto_one(target_p, command, ID_or_name(source_p, target_p),
244                 parv[1], parv[2], parv[3], parv[4],
245                 parv[5], parv[6], parv[7], parv[8]);
246 <    return(HUNTED_PASS);
247 <  }
246 >    return HUNTED_PASS;
247 >  }
248  
249 <  sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
250 <             me.name, parv[0], parv[server]);
466 <  return(HUNTED_NOSUCH);
249 >  sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
250 >  return HUNTED_NOSUCH;
251   }
252  
253   /* try_connections()
# Line 479 | Line 263 | hunt_server(struct Client *client_p, str
263   void
264   try_connections(void *unused)
265   {
266 <  dlink_node *ptr;
267 <  struct ConfItem *conf;
484 <  struct AccessItem *aconf;
485 <  struct ClassItem *cltmp;
266 >  dlink_node *ptr = NULL;
267 >  struct MaskItem *conf;
268    int confrq;
269  
270    /* TODO: change this to set active flag to 0 when added to event! --Habeeb */
# Line 492 | Line 274 | try_connections(void *unused)
274    DLINK_FOREACH(ptr, server_items.head)
275    {
276      conf = ptr->data;
495 –    aconf = (struct AccessItem *)map_to_conf(conf);
277  
278 <    /* Also when already connecting! (update holdtimes) --SRB
278 >    assert(conf->type == CONF_SERVER);
279 >
280 >    /* Also when already connecting! (update holdtimes) --SRB
281       */
282 <    if (!(aconf->status & CONF_SERVER) || aconf->port <= 0 ||
500 <        !(IsConfAllowAutoConn(aconf)))
282 >    if (!conf->port ||!IsConfAllowAutoConn(conf))
283        continue;
284  
503 –    cltmp = (struct ClassItem *)map_to_conf(aconf->class_ptr);
285  
286      /* Skip this entry if the use of it is still on hold until
287       * future. Otherwise handle this entry (and set it on hold
# Line 508 | Line 289 | try_connections(void *unused)
289       * made one successfull connection... [this algorithm is
290       * a bit fuzzy... -- msa >;) ]
291       */
292 <    if (aconf->hold > CurrentTime)
292 >    if (conf->until > CurrentTime)
293        continue;
294  
295 <    if (cltmp == NULL)
295 >    if (conf->class == NULL)
296        confrq = DEFAULT_CONNECTFREQUENCY;
297      else
298      {
299 <      confrq = ConFreq(cltmp);
300 <      if (confrq < MIN_CONN_FREQ )
301 <        confrq = MIN_CONN_FREQ;
299 >      confrq = conf->class->con_freq;
300 >      if (confrq < MIN_CONN_FREQ)
301 >        confrq = MIN_CONN_FREQ;
302      }
303  
304 <    aconf->hold = CurrentTime + confrq;
304 >    conf->until = CurrentTime + confrq;
305  
306 <    /* Found a CONNECT config with port specified, scan clients
306 >    /*
307 >     * Found a CONNECT config with port specified, scan clients
308       * and see if this server is already connected?
309       */
310 <    if (find_server(conf->name) != NULL)
310 >    if (hash_find_server(conf->name))
311        continue;
312  
313 <    if (CurrUserCount(cltmp) < MaxTotal(cltmp))
313 >    if (conf->class->ref_count < conf->class->max_total)
314      {
315        /* Go to the end of the list, if not already last */
316 <      if (ptr->next != NULL)
316 >      if (ptr->next)
317        {
318          dlinkDelete(ptr, &server_items);
319          dlinkAddTail(conf, &conf->node, &server_items);
# Line 540 | Line 322 | try_connections(void *unused)
322        if (find_servconn_in_progress(conf->name))
323          return;
324  
325 <      /* We used to only print this if serv_connect() actually
325 >      /*
326 >       * We used to only print this if serv_connect() actually
327         * succeeded, but since comm_tcp_connect() can call the callback
328         * immediately if there is an error, we were getting error messages
329         * in the wrong order. SO, we just print out the activated line,
# Line 549 | Line 332 | try_connections(void *unused)
332         *   -- adrian
333         */
334        if (ConfigServerHide.hide_server_ips)
335 <        sendto_realops_flags(UMODE_ALL, L_ALL, "Connection to %s activated.",
335 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
336 >                             "Connection to %s activated.",
337                               conf->name);
338        else
339 <        sendto_realops_flags(UMODE_ALL, L_ALL, "Connection to %s[%s] activated.",
340 <                             conf->name, aconf->host);
339 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
340 >                             "Connection to %s[%s] activated.",
341 >                             conf->name, conf->host);
342  
343 <      serv_connect(aconf, NULL);
343 >      serv_connect(conf, NULL);
344        /* We connect only one at time... */
345        return;
346      }
# Line 563 | Line 348 | try_connections(void *unused)
348   }
349  
350   int
351 < check_server(const char *name, struct Client *client_p, int cryptlink)
351 > valid_servname(const char *name)
352   {
353 <  dlink_node *ptr;
354 <  struct ConfItem *conf           = NULL;
355 <  struct ConfItem *server_conf    = NULL;
356 <  struct AccessItem *server_aconf = NULL;
357 <  struct AccessItem *aconf        = NULL;
358 <  int error = -1;
353 >  unsigned int length = 0;
354 >  unsigned int dots   = 0;
355 >  const char *p = name;
356 >
357 >  for (; *p; ++p)
358 >  {
359 >    if (!IsServChar(*p))
360 >      return 0;
361  
362 <  assert(client_p != NULL);
362 >    ++length;
363  
364 <  if (client_p == NULL)
365 <    return(error);
364 >    if (*p == '.')
365 >      ++dots;
366 >  }
367 >
368 >  return dots && length <= HOSTLEN;
369 > }
370  
371 <  if (strlen(name) > HOSTLEN)
372 <    return(-4);
371 > int
372 > check_server(const char *name, struct Client *client_p)
373 > {
374 >  dlink_node *ptr;
375 >  struct MaskItem *conf        = NULL;
376 >  struct MaskItem *server_conf = NULL;
377 >  int error = -1;
378 >
379 >  assert(client_p);
380  
381    /* loop through looking for all possible connect items that might work */
382    DLINK_FOREACH(ptr, server_items.head)
383    {
384      conf = ptr->data;
587 –    aconf = (struct AccessItem *)map_to_conf(conf);
385  
386 <    if (!match(name, conf->name))
386 >    if (match(name, conf->name))
387        continue;
388  
389      error = -3;
390  
391      /* XXX: Fix me for IPv6                    */
392      /* XXX sockhost is the IPv4 ip as a string */
393 <    if (match(aconf->host, client_p->host) ||
394 <        match(aconf->host, client_p->sockhost))
393 >    if (!match(conf->host, client_p->host) ||
394 >        !match(conf->host, client_p->sockhost))
395      {
396        error = -2;
600 – #ifdef HAVE_LIBCRYPTO
601 –      if (cryptlink && IsConfCryptLink(aconf))
602 –      {
603 –        if (aconf->rsa_public_key)
604 –          server_conf = conf;
605 –      }
606 –      else if (!(cryptlink || IsConfCryptLink(aconf)))
607 – #endif /* HAVE_LIBCRYPTO */
608 –      {
609 –        /* A NULL password is as good as a bad one */
610 –        if (EmptyString(client_p->localClient->passwd))
611 –          return(-2);
612 –
613 –        /* code in s_conf.c should not have allowed this to be NULL */
614 –        if (aconf->passwd == NULL)
615 –          return(-2);
397  
398 <        if (IsConfEncrypted(aconf))
399 <        {
400 <          if (strcmp(aconf->passwd,
401 <              (const char *)crypt(client_p->localClient->passwd,
402 <                                  aconf->passwd)) == 0)
403 <            server_conf = conf;
404 <        }
405 <        else
625 <        {
626 <          if (strcmp(aconf->passwd, client_p->localClient->passwd) == 0)
627 <            server_conf = conf;
628 <        }
629 <      }
398 >      if (!match_conf_password(client_p->localClient->passwd, conf))
399 >        return -2;
400 >
401 >      if (!EmptyString(conf->certfp))
402 >        if (EmptyString(client_p->certfp) || strcasecmp(client_p->certfp, conf->certfp))
403 >          return -4;
404 >
405 >      server_conf = conf;
406      }
407    }
408  
409    if (server_conf == NULL)
410 <    return(error);
410 >    return error;
411  
412    attach_conf(client_p, server_conf);
413  
638 –  /* Now find all leaf or hub config items for this server */
639 –  DLINK_FOREACH(ptr, hub_items.head)
640 –  {
641 –    conf = ptr->data;
642 –
643 –    if (!match(name, conf->name))
644 –      continue;
645 –    attach_conf(client_p, conf);
646 –  }
647 –
648 –  DLINK_FOREACH(ptr, leaf_items.head)
649 –  {
650 –    conf = ptr->data;
651 –
652 –    if (!match(name, conf->name))
653 –      continue;
654 –    attach_conf(client_p, conf);
655 –  }
656 –
657 –  server_aconf = map_to_conf(server_conf);
658 –
659 – #ifdef HAVE_LIBZ /* otherwise, clear it unconditionally */
660 –  if (!IsConfCompressed(server_aconf))
661 – #endif
662 –    ClearCap(client_p, CAP_ZIP);
663 –  if (!IsConfCryptLink(server_aconf))
664 –    ClearCap(client_p, CAP_ENC);
665 –  if (!IsConfTopicBurst(server_aconf))
666 –  {
667 –    ClearCap(client_p, CAP_TB);
668 –    ClearCap(client_p, CAP_TBURST);
669 –  }
414  
415 <  /* Don't unset CAP_HUB here even if the server isn't a hub,
672 <   * it only indicates if the server thinks it's lazylinks are
673 <   * leafs or not.. if you unset it, bad things will happen
674 <   */
675 <  if (aconf != NULL)
415 >  if (server_conf)
416    {
417      struct sockaddr_in *v4;
418   #ifdef IPV6
419      struct sockaddr_in6 *v6;
420   #endif
421 <    switch (aconf->aftype)
421 >    switch (server_conf->aftype)
422      {
423   #ifdef IPV6
424 <      case AF_INET6:
425 <        v6 = (struct sockaddr_in6 *)&aconf->ipnum;
424 >      case AF_INET6:
425 >        v6 = (struct sockaddr_in6 *)&server_conf->addr;
426  
427          if (IN6_IS_ADDR_UNSPECIFIED(&v6->sin6_addr))
428 <          memcpy(&aconf->ipnum, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
428 >          memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
429          break;
430   #endif
431        case AF_INET:
432 <        v4 = (struct sockaddr_in *)&aconf->ipnum;
432 >        v4 = (struct sockaddr_in *)&server_conf->addr;
433  
434          if (v4->sin_addr.s_addr == INADDR_NONE)
435 <          memcpy(&aconf->ipnum, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
435 >          memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
436          break;
437      }
438    }
439  
440 <  return(0);
440 >  return 0;
441   }
442  
443   /* add_capability()
# Line 714 | Line 454 | add_capability(const char *capab_name, i
454   {
455    struct Capability *cap = MyMalloc(sizeof(*cap));
456  
457 <  DupString(cap->name, capab_name);
457 >  cap->name = xstrdup(capab_name);
458    cap->cap = cap_flag;
459    dlinkAdd(cap, &cap->node, &cap_list);
460  
# Line 743 | Line 483 | delete_capability(const char *capab_name
483      {
484        if (irccmp(cap->name, capab_name) == 0)
485        {
486 <        default_server_capabs &= ~(cap->cap);
487 <        dlinkDelete(ptr, &cap_list);
488 <        MyFree(cap->name);
489 <        cap->name = NULL;
750 <        MyFree(cap);
486 >        default_server_capabs &= ~(cap->cap);
487 >        dlinkDelete(ptr, &cap_list);
488 >        MyFree(cap->name);
489 >        MyFree(cap);
490        }
491      }
492    }
# Line 762 | Line 501 | delete_capability(const char *capab_name
501   * output       - 0 if not found CAPAB otherwise
502   * side effects - none
503   */
504 < int
504 > unsigned int
505   find_capability(const char *capab)
506   {
507    const dlink_node *ptr = NULL;
# Line 781 | Line 520 | find_capability(const char *capab)
520   /* send_capabilities()
521   *
522   * inputs       - Client pointer to send to
784 – *              - Pointer to AccessItem (for crypt)
523   *              - int flag of capabilities that this server can send
786 – *              - int flag of encryption capabilities
524   * output       - NONE
525   * side effects - send the CAPAB line to a server  -orabidoo
526   *
527   */
528   void
529 < send_capabilities(struct Client *client_p, struct AccessItem *aconf,
793 <                  int cap_can_send, int enc_can_send)
529 > send_capabilities(struct Client *client_p, int cap_can_send)
530   {
531 <  struct Capability *cap=NULL;
532 <  char msgbuf[IRCD_BUFSIZE];
797 <  char *t;
531 >  char msgbuf[IRCD_BUFSIZE] = "";
532 >  char *t = msgbuf;
533    int tl;
534 <  dlink_node *ptr;
800 < #ifdef HAVE_LIBCRYPTO
801 <  const struct EncCapability *epref = NULL;
802 <  char *capend;
803 <  int sent_cipher = 0;
804 < #endif
805 <
806 <  t = msgbuf;
534 >  dlink_node *ptr = NULL;
535  
536    DLINK_FOREACH(ptr, cap_list.head)
537    {
538 <    cap = ptr->data;
538 >    struct Capability *cap = ptr->data;
539  
540      if (cap->cap & (cap_can_send|default_server_capabs))
541      {
542 <      tl = ircsprintf(t, "%s ", cap->name);
542 >      tl = sprintf(t, "%s ", cap->name);
543        t += tl;
544      }
545    }
818 – #ifdef HAVE_LIBCRYPTO
819 –  if (enc_can_send)
820 –  {
821 –    capend = t;
822 –    strcpy(t, "ENC:");
823 –    t += 4;
824 –
825 –    /* use connect{} specific info if available */
826 –    if (aconf->cipher_preference)
827 –      epref = aconf->cipher_preference;
828 –    else if (ConfigFileEntry.default_cipher_preference)
829 –      epref = ConfigFileEntry.default_cipher_preference;
830 –
831 –    if (epref && (epref->cap & enc_can_send))
832 –    {
833 –      /* Leave the space -- it is removed later. */
834 –      tl = ircsprintf(t, "%s ", epref->name);
835 –      t += tl;
836 –      sent_cipher = 1;
837 –    }
546  
839 –    if (!sent_cipher)
840 –      t = capend; /* truncate string before ENC:, below */
841 –  }
842 – #endif
547    *(t - 1) = '\0';
548    sendto_one(client_p, "CAPAB :%s", msgbuf);
549   }
550  
551   /* sendnick_TS()
552 < *
552 > *
553   * inputs       - client (server) to send nick towards
554   *          - client to send nick for
555   * output       - NONE
# Line 854 | Line 558 | send_capabilities(struct Client *client_
558   void
559   sendnick_TS(struct Client *client_p, struct Client *target_p)
560   {
561 <  static char ubuf[12];
561 >  char ubuf[IRCD_BUFSIZE] = "";
562  
563    if (!IsClient(target_p))
564      return;
565  
566 <  send_umode(NULL, target_p, 0, IsOperHiddenAdmin(target_p) ?
863 <    SEND_UMODES & ~UMODE_ADMIN : SEND_UMODES, ubuf);
566 >  send_umode(NULL, target_p, 0, SEND_UMODES, ubuf);
567  
568    if (ubuf[0] == '\0')
569    {
# Line 868 | Line 571 | sendnick_TS(struct Client *client_p, str
571      ubuf[1] = '\0';
572    }
573  
574 <  /* XXX Both of these need to have a :me.name or :mySID!?!?! */
575 <  if (HasID(target_p) && IsCapable(client_p, CAP_TS6))
574 >  if (IsCapable(client_p, CAP_SVS))
575 >    sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s %s :%s",
576 >               target_p->servptr->id,
577 >               target_p->name, target_p->hopcount + 1,
578 >               (unsigned long) target_p->tsinfo,
579 >               ubuf, target_p->username, target_p->host,
580 >               (MyClient(target_p) && IsIPSpoof(target_p)) ?
581 >               "0" : target_p->sockhost, target_p->id,
582 >               target_p->svid, target_p->info);
583 >  else
584      sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s :%s",
585                 target_p->servptr->id,
586                 target_p->name, target_p->hopcount + 1,
# Line 877 | Line 588 | sendnick_TS(struct Client *client_p, str
588                 ubuf, target_p->username, target_p->host,
589                 (MyClient(target_p) && IsIPSpoof(target_p)) ?
590                 "0" : target_p->sockhost, target_p->id, target_p->info);
591 <  else
592 <    sendto_one(client_p, "NICK %s %d %lu %s %s %s %s :%s",
593 <               target_p->name, target_p->hopcount + 1,
594 <               (unsigned long) target_p->tsinfo,
595 <               ubuf, target_p->username, target_p->host,
596 <               target_p->servptr->name, target_p->info);
886 <
887 <  if (IsConfAwayBurst((struct AccessItem *)map_to_conf(client_p->serv->sconf)))
888 <    if (!EmptyString(target_p->away))
889 <      sendto_one(client_p, ":%s AWAY :%s", target_p->name,
890 <                 target_p->away);
591 >
592 >  if (!EmptyString(target_p->certfp))
593 >    sendto_one(client_p, ":%s CERTFP %s", target_p->id, target_p->certfp);
594 >
595 >  if (target_p->away[0])
596 >    sendto_one(client_p, ":%s AWAY :%s", target_p->id, target_p->away);
597  
598   }
599  
# Line 899 | Line 605 | sendnick_TS(struct Client *client_p, str
605   * side effects - build up string representing capabilities of server listed
606   */
607   const char *
608 < show_capabilities(struct Client *target_p)
608 > show_capabilities(const struct Client *target_p)
609   {
610 <  static char msgbuf[IRCD_BUFSIZE];
611 <  char *t = msgbuf;
906 <  dlink_node *ptr;
610 >  static char msgbuf[IRCD_BUFSIZE] = "";
611 >  const dlink_node *ptr = NULL;
612  
613 <  t += ircsprintf(msgbuf, "TS ");
613 >  strlcpy(msgbuf, "TS", sizeof(msgbuf));
614  
615    DLINK_FOREACH(ptr, cap_list.head)
616    {
617      const struct Capability *cap = ptr->data;
618  
619 <    if (IsCapable(target_p, cap->cap))
620 <      t += ircsprintf(t, "%s ", cap->name);
619 >    if (!IsCapable(target_p, cap->cap))
620 >      continue;
621 >
622 >    strlcat(msgbuf,       " ", sizeof(msgbuf));
623 >    strlcat(msgbuf, cap->name, sizeof(msgbuf));
624    }
917 – #ifdef HAVE_LIBCRYPTO
918 –  if (IsCapable(target_p, CAP_ENC) &&
919 –      target_p->localClient->in_cipher &&
920 –      target_p->localClient->out_cipher)
921 –    t += ircsprintf(t, "ENC:%s ",
922 –                    target_p->localClient->in_cipher->name);
923 – #endif
924 –  *(t - 1) = '\0';
625  
626 <  return(msgbuf);
626 >  return msgbuf;
627   }
628  
629   /* make_server()
# Line 951 | Line 651 | make_server(struct Client *client_p)
651   void
652   server_estab(struct Client *client_p)
653   {
654 <  struct Client *target_p;
955 <  struct ConfItem *conf;
956 <  struct AccessItem *aconf=NULL;
654 >  struct MaskItem *conf = NULL;
655    char *host;
656    const char *inpath;
657    static char inpath_ip[HOSTLEN * 2 + USERLEN + 6];
960 –  dlink_node *m;
658    dlink_node *ptr;
659 + #ifdef HAVE_LIBCRYPTO
660 +  const COMP_METHOD *compression = NULL, *expansion = NULL;
661 + #endif
662  
663 <  assert(client_p != NULL);
663 >  assert(client_p);
664  
665    strlcpy(inpath_ip, get_client_name(client_p, SHOW_IP), sizeof(inpath_ip));
666  
667    inpath = get_client_name(client_p, MASK_IP); /* "refresh" inpath with host */
668    host   = client_p->name;
669  
670 <  if ((conf = find_conf_name(&client_p->localClient->confs, host, SERVER_TYPE))
670 >  if ((conf = find_conf_name(&client_p->localClient->confs, host, CONF_SERVER))
671        == NULL)
672    {
673      /* This shouldn't happen, better tell the ops... -A1kmm */
674 <    sendto_realops_flags(UMODE_ALL, L_ALL, "Warning: Lost connect{} block "
674 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
675 >                         "Warning: Lost connect{} block "
676                           "for server %s(this shouldn't happen)!", host);
677 <    exit_client(client_p, &me, "Lost connect{} block!");
677 >    exit_client(client_p, "Lost connect{} block!");
678      return;
679    }
680  
# Line 986 | Line 687 | server_estab(struct Client *client_p)
687    /* If there is something in the serv_list, it might be this
688     * connecting server..
689     */
690 <  if (!ServerInfo.hub && serv_list.head)  
690 >  if (!ServerInfo.hub && serv_list.head)
691    {
692      if (client_p != serv_list.head->data || serv_list.head->next)
693      {
694        ++ServerStats.is_ref;
695        sendto_one(client_p, "ERROR :I'm a leaf not a hub");
696 <      exit_client(client_p, &me, "I'm a leaf");
696 >      exit_client(client_p, "I'm a leaf");
697        return;
698      }
699    }
700  
701 <  aconf = (struct AccessItem *)map_to_conf(conf);
1001 <
1002 <  if (IsUnknown(client_p) && !IsConfCryptLink(aconf))
701 >  if (IsUnknown(client_p))
702    {
703 <    /* jdc -- 1.  Use EmptyString(), not [0] index reference.
1005 <     *        2.  Check aconf->spasswd, not aconf->passwd.
1006 <     */
1007 <    if (!EmptyString(aconf->spasswd))
1008 <    {
1009 <      /* only send ts6 format PASS if we have ts6 enabled */
1010 <    if (me.id[0] != '\0')               /* Send TS 6 form only if id */
1011 <        sendto_one(client_p, "PASS %s TS %d %s",
1012 <                   aconf->spasswd, TS_CURRENT, me.id);
1013 <      else
1014 <        sendto_one(client_p, "PASS %s TS 5",
1015 <                   aconf->spasswd);
1016 <    }
703 >    sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
704  
705 <    /* Pass my info to the new server
1019 <     *
1020 <     * If this is a HUB, pass on CAP_HUB
1021 <     * Pass on ZIP if supported
1022 <     * Pass on TB if supported.
1023 <     * - Dianora
1024 <     */
705 >    send_capabilities(client_p, 0);
706  
1026 –    send_capabilities(client_p, aconf, (ServerInfo.hub ? CAP_HUB : 0)
1027 –      | (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1028 –      | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), 0);
1029 –
1030 –    /* SERVER is the last command sent before switching to ziplinks.
1031 –     * We set TCPNODELAY on the socket to make sure it gets sent out
1032 –     * on the wire immediately.  Otherwise, it could be sitting in
1033 –     * a kernel buffer when we start sending zipped data, and the
1034 –     * parser on the receiving side can't hand both unzipped and zipped
1035 –     * data in one packet. --Rodder
1036 –     *
1037 –     * currently we only need to call send_queued_write,
1038 –     * Nagle is already disabled at this point --adx
1039 –     */
707      sendto_one(client_p, "SERVER %s 1 :%s%s",
708 <               my_name_for_link(conf),
1042 <               ConfigServerHide.hidden ? "(H) " : "",
1043 <               (me.info[0]) ? (me.info) : "IRCers United");
1044 <    send_queued_write(client_p);
1045 <  }
1046 <
1047 <  /* Hand the server off to servlink now */
1048 <  if (IsCapable(client_p, CAP_ENC) || IsCapable(client_p, CAP_ZIP))
1049 <  {
1050 <    if (fork_server(client_p) < 0)
1051 <    {
1052 <      sendto_realops_flags(UMODE_ALL, L_ADMIN,
1053 <                           "Warning: fork failed for server %s -- check servlink_path (%s)",
1054 <                           get_client_name(client_p, HIDE_IP), ConfigFileEntry.servlink_path);
1055 <      sendto_realops_flags(UMODE_ALL, L_OPER, "Warning: fork failed for server "
1056 <                           "%s -- check servlink_path (%s)",
1057 <                           get_client_name(client_p, MASK_IP),
1058 <                           ConfigFileEntry.servlink_path);
1059 <      exit_client(client_p, &me, "fork failed");
1060 <      return;
1061 <    }
1062 <
1063 <    start_io(client_p);
1064 <    SetServlink(client_p);
708 >               me.name, ConfigServerHide.hidden ? "(H) " : "", me.info);
709    }
710  
711 <  /* only send ts6 format SVINFO if we have ts6 enabled */
1068 <  sendto_one(client_p, "SVINFO %d %d 0 :%lu",
1069 <             (me.id[0] ? TS_CURRENT : 5), TS_MIN,
711 >  sendto_one(client_p, "SVINFO %d %d 0 :%lu", TS_CURRENT, TS_MIN,
712               (unsigned long)CurrentTime);
713  
1072 –  /* assumption here is if they passed the correct TS version, they also passed an SID */
1073 –  if (IsCapable(client_p, CAP_TS6))
1074 –    hash_add_id(client_p);
1075 –
714    /* XXX Does this ever happen? I don't think so -db */
715 <  detach_conf(client_p, OPER_TYPE);
715 >  detach_conf(client_p, CONF_OPER);
716  
717    /* *WARNING*
718    **    In the following code in place of plain server's
# Line 1094 | Line 732 | server_estab(struct Client *client_p)
732  
733    SetServer(client_p);
734  
1097 –  /* Update the capability combination usage counts. -A1kmm */
1098 –  set_chcap_usage_counts(client_p);
1099 –
735    /* Some day, all these lists will be consolidated *sigh* */
736    dlinkAdd(client_p, &client_p->lnode, &me.serv->server_list);
737  
738 <  m = dlinkFind(&unknown_list, client_p);
1104 <  assert(NULL != m);
738 >  assert(dlinkFind(&unknown_list, client_p));
739  
740 <  dlinkDelete(m, &unknown_list);
741 <  dlinkAdd(client_p, m, &serv_list);
740 >  dlink_move_node(&client_p->localClient->lclient_node,
741 >                  &unknown_list, &serv_list);
742  
743    Count.myserver++;
744  
745    dlinkAdd(client_p, make_dlink_node(), &global_serv_list);
746    hash_add_client(client_p);
747 +  hash_add_id(client_p);
748  
749    /* doesnt duplicate client_p->serv if allocated this struct already */
750    make_server(client_p);
751  
752    /* fixing eob timings.. -gnp */
753 <  client_p->firsttime = CurrentTime;
753 >  client_p->localClient->firsttime = CurrentTime;
754  
755 <  /* Show the real host/IP to admins */
756 <  sendto_realops_flags(UMODE_ALL, L_ADMIN,
1122 <                       "Link with %s established: (%s) link",
1123 <                       inpath_ip,show_capabilities(client_p));
1124 <  /* Now show the masked hostname/IP to opers */
1125 <  sendto_realops_flags(UMODE_ALL, L_OPER,
1126 <                       "Link with %s established: (%s) link",
1127 <                       inpath,show_capabilities(client_p));
1128 <  ilog(L_NOTICE, "Link with %s established: (%s) link",
1129 <       inpath_ip, show_capabilities(client_p));
755 >  if (find_matching_name_conf(CONF_SERVICE, client_p->name, NULL, NULL, 0))
756 >    AddFlag(client_p, FLAGS_SERVICE);
757  
758 <  client_p->serv->sconf = conf;
759 <
760 <  if (HasServlink(client_p))
758 >  /* Show the real host/IP to admins */
759 > #ifdef HAVE_LIBCRYPTO
760 >  if (client_p->localClient->fd.ssl)
761    {
762 <    /* we won't overflow FD_DESC_SZ here, as it can hold
763 <     * client_p->name + 64
764 <     */
765 <    fd_note(&client_p->localClient->fd, "slink data: %s", client_p->name);
766 <    fd_note(&client_p->localClient->ctrlfd, "slink ctrl: %s", client_p->name);
762 >    compression = SSL_get_current_compression(client_p->localClient->fd.ssl);
763 >    expansion   = SSL_get_current_expansion(client_p->localClient->fd.ssl);
764 >
765 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
766 >                         "Link with %s established: [SSL: %s, Compression/Expansion method: %s/%s] (Capabilities: %s)",
767 >                         inpath_ip, ssl_get_cipher(client_p->localClient->fd.ssl),
768 >                         compression ? SSL_COMP_get_name(compression) : "NONE",
769 >                         expansion ? SSL_COMP_get_name(expansion) : "NONE",
770 >                         show_capabilities(client_p));
771 >    /* Now show the masked hostname/IP to opers */
772 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
773 >                         "Link with %s established: [SSL: %s, Compression/Expansion method: %s/%s] (Capabilities: %s)",
774 >                         inpath, ssl_get_cipher(client_p->localClient->fd.ssl),
775 >                         compression ? SSL_COMP_get_name(compression) : "NONE",
776 >                         expansion ? SSL_COMP_get_name(expansion) : "NONE",
777 >                         show_capabilities(client_p));
778 >    ilog(LOG_TYPE_IRCD, "Link with %s established: [SSL: %s, Compression/Expansion method: %s/%s] (Capabilities: %s)",
779 >         inpath_ip, ssl_get_cipher(client_p->localClient->fd.ssl),
780 >         compression ? SSL_COMP_get_name(compression) : "NONE",
781 >         expansion ? SSL_COMP_get_name(expansion) : "NONE",
782 >         show_capabilities(client_p));
783    }
784    else
785 <    fd_note(&client_p->localClient->fd, "Server: %s", client_p->name);
1143 <
1144 <  /* Old sendto_serv_but_one() call removed because we now
1145 <  ** need to send different names to different servers
1146 <  ** (domain name matching) Send new server to other servers.
1147 <  */
1148 <  DLINK_FOREACH(ptr, serv_list.head)
785 > #endif
786    {
787 <    target_p = ptr->data;
788 <
789 <    if (target_p == client_p)
790 <      continue;
787 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
788 >                         "Link with %s established: (Capabilities: %s)",
789 >                         inpath_ip, show_capabilities(client_p));
790 >    /* Now show the masked hostname/IP to opers */
791 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
792 >                         "Link with %s established: (Capabilities: %s)",
793 >                         inpath, show_capabilities(client_p));
794 >    ilog(LOG_TYPE_IRCD, "Link with %s established: (Capabilities: %s)",
795 >         inpath_ip, show_capabilities(client_p));
796 >  }
797 >
798 >  fd_note(&client_p->localClient->fd, "Server: %s", client_p->name);
799 >
800 >  sendto_server(client_p, NOCAPS, NOCAPS, ":%s SID %s 2 %s :%s%s",
801 >                me.id, client_p->name, client_p->id,
802 >                IsHidden(client_p) ? "(H) " : "", client_p->info);
803  
804 <    if ((conf = target_p->serv->sconf) &&
805 <         match(my_name_for_link(conf), client_p->name))
806 <      continue;
807 <
808 <    if (IsCapable(target_p, CAP_TS6) && HasID(client_p))
809 <      sendto_one(target_p, ":%s SID %s 2 %s :%s%s",
810 <                 me.id, client_p->name, client_p->id,
811 <                 IsHidden(client_p) ? "(H) " : "",
812 <                 client_p->info);
813 <    else
814 <      sendto_one(target_p,":%s SERVER %s 2 :%s%s",
815 <                 me.name, client_p->name,
816 <                 IsHidden(client_p) ? "(H) " : "",
817 <                 client_p->info);
818 <  }
819 <
820 <  /* Pass on my client information to the new server
821 <  **
1173 <  ** First, pass only servers (idea is that if the link gets
1174 <  ** cancelled beacause the server was already there,
1175 <  ** there are no NICK's to be cancelled...). Of course,
1176 <  ** if cancellation occurs, all this info is sent anyway,
1177 <  ** and I guess the link dies when a read is attempted...? --msa
1178 <  **
1179 <  ** Note: Link cancellation to occur at this point means
1180 <  ** that at least two servers from my fragment are building
1181 <  ** up connection this other fragment at the same time, it's
1182 <  ** a race condition, not the normal way of operation...
1183 <  **
1184 <  ** ALSO NOTE: using the get_client_name for server names--
1185 <  **    see previous *WARNING*!!! (Also, original inpath
1186 <  **    is destroyed...)
1187 <  */
1188 <
1189 <  conf = client_p->serv->sconf;
804 >  /*
805 >   * Pass on my client information to the new server
806 >   *
807 >   * First, pass only servers (idea is that if the link gets
808 >   * cancelled beacause the server was already there,
809 >   * there are no NICK's to be cancelled...). Of course,
810 >   * if cancellation occurs, all this info is sent anyway,
811 >   * and I guess the link dies when a read is attempted...? --msa
812 >   *
813 >   * Note: Link cancellation to occur at this point means
814 >   * that at least two servers from my fragment are building
815 >   * up connection this other fragment at the same time, it's
816 >   * a race condition, not the normal way of operation...
817 >   *
818 >   * ALSO NOTE: using the get_client_name for server names--
819 >   *    see previous *WARNING*!!! (Also, original inpath
820 >   *    is destroyed...)
821 >   */
822  
823    DLINK_FOREACH_PREV(ptr, global_serv_list.tail)
824    {
825 <    target_p = ptr->data;
825 >    struct Client *target_p = ptr->data;
826  
827      /* target_p->from == target_p for target_p == client_p */
828 <    if (target_p->from == client_p)
828 >    if (IsMe(target_p) || target_p->from == client_p)
829        continue;
830  
831 <    if (match(my_name_for_link(conf), target_p->name))
832 <      continue;
831 >    sendto_one(client_p, ":%s SID %s %d %s :%s%s",
832 >               target_p->servptr->id, target_p->name, target_p->hopcount+1,
833 >               target_p->id, IsHidden(target_p) ? "(H) " : "",
834 >               target_p->info);
835  
836 <    if (IsCapable(client_p, CAP_TS6))
837 <    {
1204 <      if (HasID(target_p))
1205 <        sendto_one(client_p, ":%s SID %s %d %s :%s%s",
1206 <                   ID(target_p->servptr), target_p->name, target_p->hopcount+1,
1207 <                   target_p->id, IsHidden(target_p) ? "(H) " : "",
1208 <                   target_p->info);
1209 <      else  /* introducing non-ts6 server */
1210 <        sendto_one(client_p, ":%s SERVER %s %d :%s%s",
1211 <                   ID(target_p->servptr), target_p->name, target_p->hopcount+1,
1212 <                   IsHidden(target_p) ? "(H) " : "", target_p->info);
1213 <    }
1214 <    else
1215 <      sendto_one(client_p, ":%s SERVER %s %d :%s%s",
1216 <                 target_p->servptr->name, target_p->name, target_p->hopcount+1,
1217 <                 IsHidden(target_p) ? "(H) " : "", target_p->info);
836 >    if (HasFlag(target_p, FLAGS_EOB))
837 >      sendto_one(client_p, ":%s EOB", target_p->id, client_p);
838    }
839  
840    server_burst(client_p);
841   }
842  
1223 – static void
1224 – start_io(struct Client *server)
1225 – {
1226 –  struct LocalUser *lserver = server->localClient;
1227 –  int alloclen = 1;
1228 –  char *buf;
1229 –  dlink_node *ptr;
1230 –  struct dbuf_block *block;
1231 –
1232 –  /* calculate how many bytes to allocate */
1233 –  if (IsCapable(server, CAP_ZIP))
1234 –    alloclen += 6;
1235 – #ifdef HAVE_LIBCRYPTO
1236 –  if (IsCapable(server, CAP_ENC))
1237 –    alloclen += 16 + lserver->in_cipher->keylen + lserver->out_cipher->keylen;
1238 – #endif
1239 –  alloclen += dbuf_length(&lserver->buf_recvq);
1240 –  alloclen += dlink_list_length(&lserver->buf_recvq.blocks) * 3;
1241 –  alloclen += dbuf_length(&lserver->buf_sendq);
1242 –  alloclen += dlink_list_length(&lserver->buf_sendq.blocks) * 3;
1243 –
1244 –  /* initialize servlink control sendq */
1245 –  lserver->slinkq = buf = MyMalloc(alloclen);
1246 –  lserver->slinkq_ofs = 0;
1247 –  lserver->slinkq_len = alloclen;
1248 –
1249 –  if (IsCapable(server, CAP_ZIP))
1250 –  {
1251 –    /* ziplink */
1252 –    *buf++ = SLINKCMD_SET_ZIP_OUT_LEVEL;
1253 –    *buf++ = 0; /* |          */
1254 –    *buf++ = 1; /* \ len is 1 */
1255 –    *buf++ = ConfigFileEntry.compression_level;
1256 –    *buf++ = SLINKCMD_START_ZIP_IN;
1257 –    *buf++ = SLINKCMD_START_ZIP_OUT;
1258 –  }
1259 – #ifdef HAVE_LIBCRYPTO
1260 –  if (IsCapable(server, CAP_ENC))
1261 –  {
1262 –    /* Decryption settings */
1263 –    *buf++ = SLINKCMD_SET_CRYPT_IN_CIPHER;
1264 –    *buf++ = 0; /* /                     (upper 8-bits of len) */
1265 –    *buf++ = 1; /* \ cipher id is 1 byte (lower 8-bits of len) */
1266 –    *buf++ = lserver->in_cipher->cipherid;
1267 –    *buf++ = SLINKCMD_SET_CRYPT_IN_KEY;
1268 –    *buf++ = 0; /* keylen < 256 */
1269 –    *buf++ = lserver->in_cipher->keylen;
1270 –    memcpy(buf, lserver->in_key, lserver->in_cipher->keylen);
1271 –    buf += lserver->in_cipher->keylen;
1272 –    /* Encryption settings */
1273 –    *buf++ = SLINKCMD_SET_CRYPT_OUT_CIPHER;
1274 –    *buf++ = 0; /* /                     (upper 8-bits of len) */
1275 –    *buf++ = 1; /* \ cipher id is 1 byte (lower 8-bits of len) */
1276 –    *buf++ = lserver->out_cipher->cipherid;
1277 –    *buf++ = SLINKCMD_SET_CRYPT_OUT_KEY;
1278 –    *buf++ = 0; /* keylen < 256 */
1279 –    *buf++ = lserver->out_cipher->keylen;
1280 –    memcpy(buf, lserver->out_key, lserver->out_cipher->keylen);
1281 –    buf += lserver->out_cipher->keylen;
1282 –    *buf++ = SLINKCMD_START_CRYPT_IN;
1283 –    *buf++ = SLINKCMD_START_CRYPT_OUT;
1284 –  }
1285 – #endif
1286 –
1287 –  /* pass the whole recvq to servlink */
1288 –  DLINK_FOREACH (ptr, lserver->buf_recvq.blocks.head)
1289 –  {
1290 –    block = ptr->data;
1291 –    *buf++ = SLINKCMD_INJECT_RECVQ;
1292 –    *buf++ = (block->size >> 8);
1293 –    *buf++ = (block->size & 0xff);
1294 –    memcpy(buf, &block->data[0], block->size);
1295 –    buf += block->size;
1296 –  }
1297 –
1298 –  dbuf_clear(&lserver->buf_recvq);
1299 –
1300 –  /* pass the whole sendq to servlink */
1301 –  DLINK_FOREACH (ptr, lserver->buf_sendq.blocks.head)
1302 –  {
1303 –    block = ptr->data;
1304 –    *buf++ = SLINKCMD_INJECT_SENDQ;
1305 –    *buf++ = (block->size >> 8);
1306 –    *buf++ = (block->size & 0xff);
1307 –    memcpy(buf, &block->data[0], block->size);
1308 –    buf += block->size;
1309 –  }
1310 –
1311 –  dbuf_clear(&lserver->buf_sendq);
1312 –
1313 –  /* start io */
1314 –  *buf++ = SLINKCMD_INIT;
1315 –
1316 –  /* schedule a write */
1317 –  send_queued_slink_write(server);
1318 – }
1319 –
1320 – /* fork_server()
1321 – *
1322 – * inputs       - struct Client *server
1323 – * output       - success: 0 / failure: -1
1324 – * side effect  - fork, and exec SERVLINK to handle this connection
1325 – */
1326 – static int
1327 – fork_server(struct Client *server)
1328 – {
1329 – #ifndef HAVE_SOCKETPAIR
1330 –  return -1;
1331 – #else
1332 –  int i;
1333 –  int slink_fds[2][2];
1334 –  /* 0? - ctrl  | 1? - data  
1335 –   * ?0 - child | ?1 - parent */
1336 –
1337 –  if (socketpair(AF_UNIX, SOCK_STREAM, 0, slink_fds[0]) < 0)
1338 –    return -1;
1339 –  if (socketpair(AF_UNIX, SOCK_STREAM, 0, slink_fds[1]) < 0)
1340 –    goto free_ctrl_fds;
1341 –
1342 –  if ((i = fork()) < 0)
1343 –  {
1344 –    close(slink_fds[1][0]);  close(slink_fds[1][1]);
1345 –    free_ctrl_fds:
1346 –    close(slink_fds[0][0]);  close(slink_fds[0][1]);
1347 –    return -1;
1348 –  }
1349 –
1350 –  if (i == 0)
1351 –  {
1352 –    char fd_str[3][6];   /* store 3x sizeof("65535") */
1353 –    char *kid_argv[7];
1354 –
1355 – #ifdef O_ASYNC
1356 –    fcntl(server->localClient->fd.fd, F_SETFL,
1357 –          fcntl(server->localClient->fd.fd, F_GETFL, 0) & ~O_ASYNC);
1358 – #endif
1359 –    close_fds(&server->localClient->fd);
1360 –    close(slink_fds[0][1]);
1361 –    close(slink_fds[1][1]);
1362 –
1363 –    sprintf(fd_str[0], "%d", slink_fds[0][0]);
1364 –    sprintf(fd_str[1], "%d", slink_fds[1][0]);
1365 –    sprintf(fd_str[2], "%d", server->localClient->fd.fd);
1366 –
1367 –    kid_argv[0] = "-slink";
1368 –    kid_argv[1] = kid_argv[2] = fd_str[0];  /* ctrl */
1369 –    kid_argv[3] = kid_argv[4] = fd_str[1];  /* data */
1370 –    kid_argv[5] = fd_str[2];    /* network */
1371 –    kid_argv[6] = NULL;
1372 –
1373 –    execv(ConfigFileEntry.servlink_path, kid_argv);
1374 –
1375 –    _exit(1);
1376 –  }
1377 –
1378 –  /* close the network fd and the child ends of the pipes */
1379 –  fd_close(&server->localClient->fd);
1380 –  close(slink_fds[0][0]);
1381 –  close(slink_fds[1][0]);
1382 –
1383 –  execute_callback(setup_socket_cb, slink_fds[0][1]);
1384 –  execute_callback(setup_socket_cb, slink_fds[1][1]);
1385 –
1386 –  fd_open(&server->localClient->ctrlfd, slink_fds[0][1], 1, "slink ctrl");
1387 –  fd_open(&server->localClient->fd, slink_fds[1][1], 1, "slink data");
1388 –
1389 –  read_ctrl_packet(&server->localClient->ctrlfd, server);
1390 –  read_packet(&server->localClient->fd, server);
1391 –
1392 –  return 0;
1393 – #endif
1394 – }
1395 –
843   /* server_burst()
844   *
845   * inputs       - struct Client pointer server
# Line 1418 | Line 865 | server_burst(struct Client *client_p)
865  
866    /* EOB stuff is now in burst_all */
867    /* Always send a PING after connect burst is done */
868 <  sendto_one(client_p, "PING :%s", ID_or_name(&me, client_p));
868 >  sendto_one(client_p, "PING :%s", me.id);
869   }
870  
871   /* burst_all()
872   *
873 < * inputs       - pointer to server to send burst to
873 > * inputs       - pointer to server to send burst to
874   * output       - NONE
875   * side effects - complete burst of channels/nicks is sent to client_p
876   */
# Line 1436 | Line 883 | burst_all(struct Client *client_p)
883    {
884      struct Channel *chptr = ptr->data;
885  
886 <    if (dlink_list_length(&chptr->members) != 0)
886 >    if (dlink_list_length(&chptr->members))
887      {
888        burst_members(client_p, chptr);
889        send_channel_modes(client_p, chptr);
890  
891 <      if (IsCapable(client_p, CAP_TBURST) ||
892 <          IsCapable(client_p, CAP_TB))
1446 <        send_tb(client_p, chptr);
891 >      if (IsCapable(client_p, CAP_TBURST))
892 >        send_tb(client_p, chptr);
893      }
894    }
895  
# Line 1453 | Line 899 | burst_all(struct Client *client_p)
899    {
900      struct Client *target_p = ptr->data;
901  
902 <    if (!IsBursted(target_p) && target_p->from != client_p)
902 >    if (!HasFlag(target_p, FLAGS_BURSTED) && target_p->from != client_p)
903        sendnick_TS(client_p, target_p);
904 <    
905 <    ClearBursted(target_p);
904 >
905 >    DelFlag(target_p, FLAGS_BURSTED);
906    }
907  
1462 –  /* We send the time we started the burst, and let the remote host determine an EOB time,
1463 –  ** as otherwise we end up sending a EOB of 0   Sending here means it gets sent last -- fl
1464 –  */
1465 –  /* Its simpler to just send EOB and use the time its been connected.. --fl_ */
908    if (IsCapable(client_p, CAP_EOB))
909 <    sendto_one(client_p, ":%s EOB", ID_or_name(&me, client_p));
909 >    sendto_one(client_p, ":%s EOB", me.id);
910   }
911  
912   /*
# Line 1474 | Line 916 | burst_all(struct Client *client_p)
916   *              - pointer to channel
917   * output       - NONE
918   * side effects - Called on a server burst when
919 < *                server is CAP_TB|CAP_TBURST capable
919 > *                server is CAP_TBURST capable
920   */
921   static void
922   send_tb(struct Client *client_p, struct Channel *chptr)
# Line 1492 | Line 934 | send_tb(struct Client *client_p, struct
934     * it to their old topic they had before.  Read m_tburst.c:ms_tburst
935     * for further information   -Michael
936     */
937 <  if (chptr->topic_time != 0)
938 <  {
939 <    if (IsCapable(client_p, CAP_TBURST))
940 <      sendto_one(client_p, ":%s TBURST %lu %s %lu %s :%s",
941 <                 me.name, (unsigned long)chptr->channelts, chptr->chname,
942 <                 (unsigned long)chptr->topic_time,
1501 <                 chptr->topic_info ? chptr->topic_info : "",
1502 <                 chptr->topic ? chptr->topic : "");
1503 <    else if (IsCapable(client_p, CAP_TB))
1504 <    {
1505 <      if (ConfigChannel.burst_topicwho)
1506 <      {
1507 <        sendto_one(client_p, ":%s TB %s %lu %s :%s",
1508 <                   me.name, chptr->chname,
1509 <                   (unsigned long)chptr->topic_time,
1510 <                   chptr->topic_info, chptr->topic ? chptr->topic : "");
1511 <      }
1512 <      else
1513 <      {
1514 <        sendto_one(client_p, ":%s TB %s %lu :%s",
1515 <                   me.name, chptr->chname,
1516 <                   (unsigned long)chptr->topic_time,
1517 <                   chptr->topic ? chptr->topic : "");
1518 <      }
1519 <    }
1520 <  }
937 >  if (chptr->topic_time)
938 >    sendto_one(client_p, ":%s TBURST %lu %s %lu %s :%s", me.id,
939 >               (unsigned long)chptr->channelts, chptr->chname,
940 >               (unsigned long)chptr->topic_time,
941 >               chptr->topic_info,
942 >               chptr->topic);
943   }
944  
945   /* burst_members()
# Line 1539 | Line 961 | burst_members(struct Client *client_p, s
961      ms       = ptr->data;
962      target_p = ms->client_p;
963  
964 <    if (!IsBursted(target_p))
964 >    if (!HasFlag(target_p, FLAGS_BURSTED))
965      {
966 <      SetBursted(target_p);
966 >      AddFlag(target_p, FLAGS_BURSTED);
967  
968        if (target_p->from != client_p)
969          sendnick_TS(client_p, target_p);
# Line 1556 | Line 978 | burst_members(struct Client *client_p, s
978  
979   /* serv_connect() - initiate a server connection
980   *
981 < * inputs       - pointer to conf
981 > * inputs       - pointer to conf
982   *              - pointer to client doing the connect
983   * output       -
984   * side effects -
# Line 1571 | Line 993 | burst_members(struct Client *client_p, s
993   * it suceeded or not, and 0 if it fails in here somewhere.
994   */
995   int
996 < serv_connect(struct AccessItem *aconf, struct Client *by)
996 > serv_connect(struct MaskItem *conf, struct Client *by)
997   {
998 <  struct ConfItem *conf;
999 <  struct Client *client_p;
1578 <  char buf[HOSTIPLEN];
998 >  struct Client *client_p = NULL;
999 >  char buf[HOSTIPLEN + 1] = "";
1000  
1001    /* conversion structs */
1002    struct sockaddr_in *v4;
1582 –  /* Make sure aconf is useful */
1583 –  assert(aconf != NULL);
1584 –
1585 –  if(aconf == NULL)
1586 –    return (0);
1003  
1004 <  /* XXX should be passing struct ConfItem in the first place */
1005 <  conf = unmap_conf_item(aconf);
1004 >  /* Make sure conf is useful */
1005 >  assert(conf);
1006  
1007 <  /* log */
1008 <  irc_getnameinfo((struct sockaddr*)&aconf->ipnum, aconf->ipnum.ss_len,
1009 <                  buf, HOSTIPLEN, NULL, 0, NI_NUMERICHOST);
1594 <  ilog(L_NOTICE, "Connect to %s[%s] @%s", aconf->user, aconf->host,
1007 >  getnameinfo((struct sockaddr *)&conf->addr, conf->addr.ss_len,
1008 >              buf, sizeof(buf), NULL, 0, NI_NUMERICHOST);
1009 >  ilog(LOG_TYPE_IRCD, "Connect to %s[%s] @%s", conf->name, conf->host,
1010         buf);
1011  
1012    /* Still processing a DNS lookup? -> exit */
1013 <  if (aconf->dns_pending)
1013 >  if (conf->dns_pending)
1014    {
1015 <    sendto_realops_flags(UMODE_ALL, L_ALL,
1015 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1016                           "Error connecting to %s: DNS lookup for connect{} in progress.",
1017                           conf->name);
1018 <    return (0);
1018 >    return 0;
1019    }
1020  
1021 <  if (aconf->dns_failed)
1021 >  if (conf->dns_failed)
1022    {
1023 <    sendto_realops_flags(UMODE_ALL, L_ALL,
1023 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1024                           "Error connecting to %s: DNS lookup for connect{} failed.",
1025                           conf->name);
1026 <    return (0);
1026 >    return 0;
1027    }
1028  
1029    /* Make sure this server isn't already connected
1030 <   * Note: aconf should ALWAYS be a valid C: line
1030 >   * Note: conf should ALWAYS be a valid C: line
1031     */
1032 <  if ((client_p = find_server(conf->name)) != NULL)
1033 <  {
1034 <    sendto_realops_flags(UMODE_ALL, L_ADMIN,
1035 <                         "Server %s already present from %s",
1036 <                         conf->name, get_client_name(client_p, SHOW_IP));
1037 <    sendto_realops_flags(UMODE_ALL, L_OPER,
1038 <                         "Server %s already present from %s",
1039 <                         conf->name, get_client_name(client_p, MASK_IP));
1032 >  if ((client_p = hash_find_server(conf->name)))
1033 >  {
1034 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1035 >                         "Server %s already present from %s",
1036 >                         conf->name, get_client_name(client_p, SHOW_IP));
1037 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1038 >                         "Server %s already present from %s",
1039 >                         conf->name, get_client_name(client_p, MASK_IP));
1040      if (by && IsClient(by) && !MyClient(by))
1041 <      sendto_one(by, ":%s NOTICE %s :Server %s already present from %s",
1042 <                 me.name, by->name, conf->name,
1043 <                 get_client_name(client_p, MASK_IP));
1629 <    return (0);
1041 >      sendto_one_notice(by, &me, ":Server %s already present from %s",
1042 >                        conf->name, get_client_name(client_p, MASK_IP));
1043 >    return 0;
1044    }
1045 <    
1045 >
1046    /* Create a local client */
1047    client_p = make_client(NULL);
1048  
1049    /* Copy in the server, hostname, fd */
1050    strlcpy(client_p->name, conf->name, sizeof(client_p->name));
1051 <  strlcpy(client_p->host, aconf->host, sizeof(client_p->host));
1051 >  strlcpy(client_p->host, conf->host, sizeof(client_p->host));
1052  
1053    /* We already converted the ip once, so lets use it - stu */
1054 <  strlcpy(client_p->sockhost, buf, HOSTIPLEN);
1054 >  strlcpy(client_p->sockhost, buf, sizeof(client_p->sockhost));
1055  
1056 <  /* create a socket for the server connection */
1057 <  if (comm_open(&client_p->localClient->fd, aconf->ipnum.ss.ss_family,
1056 >  /* create a socket for the server connection */
1057 >  if (comm_open(&client_p->localClient->fd, conf->addr.ss.ss_family,
1058                  SOCK_STREAM, 0, NULL) < 0)
1059    {
1060      /* Eek, failure to create the socket */
1061 <    report_error(L_ALL,
1062 <                 "opening stream socket to %s: %s", conf->name, errno);
1061 >    report_error(L_ALL, "opening stream socket to %s: %s",
1062 >                 conf->name, errno);
1063      SetDead(client_p);
1064 <    exit_client(client_p, &me, "Connection failed");
1065 <    return (0);
1064 >    exit_client(client_p, "Connection failed");
1065 >    return 0;
1066    }
1067  
1068    /* servernames are always guaranteed under HOSTLEN chars */
# Line 1657 | Line 1071 | serv_connect(struct AccessItem *aconf, s
1071    /* Attach config entries to client here rather than in
1072     * serv_connect_callback(). This to avoid null pointer references.
1073     */
1074 <  if (!attach_connect_block(client_p, conf->name, aconf->host))
1074 >  if (!attach_connect_block(client_p, conf->name, conf->host))
1075    {
1076 <    sendto_realops_flags(UMODE_ALL, L_ALL,
1077 <                         "Host %s is not enabled for connecting:no C/N-line",
1078 <                         conf->name);
1079 <    if (by && IsClient(by) && !MyClient(by))  
1080 <      sendto_one(by, ":%s NOTICE %s :Connect to host %s failed.",
1081 <                 me.name, by->name, client_p->name);
1076 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1077 >                         "Host %s is not enabled for connecting: no connect{} block",
1078 >                         conf->name);
1079 >    if (by && IsClient(by) && !MyClient(by))
1080 >      sendto_one_notice(by, &me, ":Connect to host %s failed.", client_p->name);
1081 >
1082      SetDead(client_p);
1083 <    exit_client(client_p, client_p, "Connection failed");
1084 <    return (0);
1083 >    exit_client(client_p, "Connection failed");
1084 >    return 0;
1085    }
1086  
1087    /* at this point we have a connection in progress and C/N lines
# Line 1686 | Line 1100 | serv_connect(struct AccessItem *aconf, s
1100    SetConnecting(client_p);
1101    dlinkAdd(client_p, &client_p->node, &global_client_list);
1102    /* from def_fam */
1103 <  client_p->localClient->aftype = aconf->aftype;
1103 >  client_p->localClient->aftype = conf->aftype;
1104  
1105    /* Now, initiate the connection */
1106 <  /* XXX assume that a non 0 type means a specific bind address
1106 >  /* XXX assume that a non 0 type means a specific bind address
1107     * for this connect.
1108     */
1109 <  switch (aconf->aftype)
1109 >  switch (conf->aftype)
1110    {
1111      case AF_INET:
1112 <      v4 = (struct sockaddr_in*)&aconf->my_ipnum;
1113 <      if (v4->sin_addr.s_addr != 0)
1112 >      v4 = (struct sockaddr_in*)&conf->bind;
1113 >      if (v4->sin_addr.s_addr)
1114        {
1115          struct irc_ssaddr ipn;
1116          memset(&ipn, 0, sizeof(struct irc_ssaddr));
1117          ipn.ss.ss_family = AF_INET;
1118          ipn.ss_port = 0;
1119 <        memcpy(&ipn, &aconf->my_ipnum, sizeof(struct irc_ssaddr));
1120 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
1121 <                         (struct sockaddr *)&ipn, ipn.ss_len,
1122 <                         serv_connect_callback, client_p, aconf->aftype,
1123 <                         CONNECTTIMEOUT);
1119 >        memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
1120 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
1121 >                         (struct sockaddr *)&ipn, ipn.ss_len,
1122 >                         serv_connect_callback, client_p, conf->aftype,
1123 >                         CONNECTTIMEOUT);
1124        }
1125        else if (ServerInfo.specific_ipv4_vhost)
1126        {
# Line 1715 | Line 1129 | serv_connect(struct AccessItem *aconf, s
1129          ipn.ss.ss_family = AF_INET;
1130          ipn.ss_port = 0;
1131          memcpy(&ipn, &ServerInfo.ip, sizeof(struct irc_ssaddr));
1132 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
1132 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
1133                           (struct sockaddr *)&ipn, ipn.ss_len,
1134 <                         serv_connect_callback, client_p, aconf->aftype,
1135 <                         CONNECTTIMEOUT);
1134 >                         serv_connect_callback, client_p, conf->aftype,
1135 >                         CONNECTTIMEOUT);
1136        }
1137        else
1138 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
1139 <                         NULL, 0, serv_connect_callback, client_p, aconf->aftype,
1138 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
1139 >                         NULL, 0, serv_connect_callback, client_p, conf->aftype,
1140                           CONNECTTIMEOUT);
1141        break;
1142   #ifdef IPV6
1143      case AF_INET6:
1144        {
1145 <        struct irc_ssaddr ipn;
1146 <        struct sockaddr_in6 *v6;
1147 <        struct sockaddr_in6 *v6conf;
1148 <
1149 <        memset(&ipn, 0, sizeof(struct irc_ssaddr));
1150 <        v6conf = (struct sockaddr_in6 *)&aconf->my_ipnum;
1151 <        v6 = (struct sockaddr_in6 *)&ipn;
1152 <
1153 <        if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr,
1740 <                   sizeof(struct in6_addr)) != 0)
1741 <        {
1742 <          memcpy(&ipn, &aconf->my_ipnum, sizeof(struct irc_ssaddr));
1743 <          ipn.ss.ss_family = AF_INET6;
1744 <          ipn.ss_port = 0;
1745 <          comm_connect_tcp(&client_p->localClient->fd,
1746 <                           aconf->host, aconf->port,
1747 <                           (struct sockaddr *)&ipn, ipn.ss_len,
1748 <                           serv_connect_callback, client_p,
1749 <                           aconf->aftype, CONNECTTIMEOUT);
1750 <        }
1751 <        else if (ServerInfo.specific_ipv6_vhost)
1145 >        struct irc_ssaddr ipn;
1146 >        struct sockaddr_in6 *v6;
1147 >        struct sockaddr_in6 *v6conf;
1148 >
1149 >        memset(&ipn, 0, sizeof(struct irc_ssaddr));
1150 >        v6conf = (struct sockaddr_in6 *)&conf->bind;
1151 >        v6 = (struct sockaddr_in6 *)&ipn;
1152 >
1153 >        if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr, sizeof(struct in6_addr)))
1154          {
1155 <          memcpy(&ipn, &ServerInfo.ip6, sizeof(struct irc_ssaddr));
1156 <          ipn.ss.ss_family = AF_INET6;
1157 <          ipn.ss_port = 0;
1158 <          comm_connect_tcp(&client_p->localClient->fd,
1159 <                           aconf->host, aconf->port,
1160 <                           (struct sockaddr *)&ipn, ipn.ss_len,
1161 <                           serv_connect_callback, client_p,
1162 <                           aconf->aftype, CONNECTTIMEOUT);
1163 <        }
1164 <        else
1165 <          comm_connect_tcp(&client_p->localClient->fd,
1166 <                           aconf->host, aconf->port,
1167 <                           NULL, 0, serv_connect_callback, client_p,
1168 <                           aconf->aftype, CONNECTTIMEOUT);
1155 >          memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
1156 >          ipn.ss.ss_family = AF_INET6;
1157 >          ipn.ss_port = 0;
1158 >          comm_connect_tcp(&client_p->localClient->fd,
1159 >                           conf->host, conf->port,
1160 >                           (struct sockaddr *)&ipn, ipn.ss_len,
1161 >                           serv_connect_callback, client_p,
1162 >                           conf->aftype, CONNECTTIMEOUT);
1163 >        }
1164 >        else if (ServerInfo.specific_ipv6_vhost)
1165 >        {
1166 >          memcpy(&ipn, &ServerInfo.ip6, sizeof(struct irc_ssaddr));
1167 >          ipn.ss.ss_family = AF_INET6;
1168 >          ipn.ss_port = 0;
1169 >          comm_connect_tcp(&client_p->localClient->fd,
1170 >                           conf->host, conf->port,
1171 >                           (struct sockaddr *)&ipn, ipn.ss_len,
1172 >                           serv_connect_callback, client_p,
1173 >                           conf->aftype, CONNECTTIMEOUT);
1174 >        }
1175 >        else
1176 >          comm_connect_tcp(&client_p->localClient->fd,
1177 >                           conf->host, conf->port,
1178 >                           NULL, 0, serv_connect_callback, client_p,
1179 >                           conf->aftype, CONNECTTIMEOUT);
1180        }
1181   #endif
1182    }
1183 <  return (1);
1183 >  return 1;
1184 > }
1185 >
1186 > #ifdef HAVE_LIBCRYPTO
1187 > static void
1188 > finish_ssl_server_handshake(struct Client *client_p)
1189 > {
1190 >  struct MaskItem *conf = NULL;
1191 >
1192 >  conf = find_conf_name(&client_p->localClient->confs,
1193 >                        client_p->name, CONF_SERVER);
1194 >  if (conf == NULL)
1195 >  {
1196 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1197 >                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
1198 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1199 >                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
1200 >
1201 >    exit_client(client_p, "Lost connect{} block");
1202 >    return;
1203 >  }
1204 >
1205 >  sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
1206 >
1207 >  send_capabilities(client_p, 0);
1208 >
1209 >  sendto_one(client_p, "SERVER %s 1 :%s%s",
1210 >             me.name, ConfigServerHide.hidden ? "(H) " : "",
1211 >             me.info);
1212 >
1213 >  /* If we've been marked dead because a send failed, just exit
1214 >   * here now and save everyone the trouble of us ever existing.
1215 >   */
1216 >  if (IsDead(client_p))
1217 >  {
1218 >      sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1219 >                           "%s[%s] went dead during handshake",
1220 >                           client_p->name,
1221 >                           client_p->host);
1222 >      sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1223 >                           "%s went dead during handshake", client_p->name);
1224 >      return;
1225 >  }
1226 >
1227 >  /* don't move to serv_list yet -- we haven't sent a burst! */
1228 >  /* If we get here, we're ok, so lets start reading some data */
1229 >  comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ, read_packet, client_p, 0);
1230 > }
1231 >
1232 > static void
1233 > ssl_server_handshake(fde_t *fd, struct Client *client_p)
1234 > {
1235 >  X509 *cert = NULL;
1236 >  int ret = 0;
1237 >
1238 >  if ((ret = SSL_connect(client_p->localClient->fd.ssl)) <= 0)
1239 >  {
1240 >    switch (SSL_get_error(client_p->localClient->fd.ssl, ret))
1241 >    {
1242 >      case SSL_ERROR_WANT_WRITE:
1243 >        comm_setselect(&client_p->localClient->fd, COMM_SELECT_WRITE,
1244 >                       (PF *)ssl_server_handshake, client_p, 0);
1245 >        return;
1246 >      case SSL_ERROR_WANT_READ:
1247 >        comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ,
1248 >                       (PF *)ssl_server_handshake, client_p, 0);
1249 >        return;
1250 >      default:
1251 >      {
1252 >        const char *sslerr = ERR_error_string(ERR_get_error(), NULL);
1253 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1254 >                             "Error connecting to %s: %s", client_p->name,
1255 >                             sslerr ? sslerr : "unknown SSL error");
1256 >        exit_client(client_p, "Error during SSL handshake");
1257 >        return;
1258 >      }
1259 >    }
1260 >  }
1261 >
1262 >  if ((cert = SSL_get_peer_certificate(client_p->localClient->fd.ssl)))
1263 >  {
1264 >    int res = SSL_get_verify_result(client_p->localClient->fd.ssl);
1265 >    char buf[EVP_MAX_MD_SIZE * 2 + 1] = { '\0' };
1266 >    unsigned char md[EVP_MAX_MD_SIZE] = { '\0' };
1267 >
1268 >    if (res == X509_V_OK || res == X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN ||
1269 >        res == X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE ||
1270 >        res == X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT)
1271 >    {
1272 >      unsigned int i = 0, n = 0;
1273 >
1274 >      if (X509_digest(cert, EVP_sha256(), md, &n))
1275 >      {
1276 >        for (; i < n; ++i)
1277 >          snprintf(buf + 2 * i, 3, "%02X", md[i]);
1278 >        client_p->certfp = xstrdup(buf);
1279 >      }
1280 >    }
1281 >    else
1282 >      ilog(LOG_TYPE_IRCD, "Server %s!%s@%s gave bad SSL client certificate: %d",
1283 >           client_p->name, client_p->username, client_p->host, res);
1284 >    X509_free(cert);
1285 >  }
1286 >
1287 >  finish_ssl_server_handshake(client_p);
1288 > }
1289 >
1290 > static void
1291 > ssl_connect_init(struct Client *client_p, struct MaskItem *conf, fde_t *fd)
1292 > {
1293 >  if ((client_p->localClient->fd.ssl = SSL_new(ServerInfo.client_ctx)) == NULL)
1294 >  {
1295 >    ilog(LOG_TYPE_IRCD, "SSL_new() ERROR! -- %s",
1296 >         ERR_error_string(ERR_get_error(), NULL));
1297 >    SetDead(client_p);
1298 >    exit_client(client_p, "SSL_new failed");
1299 >    return;
1300 >  }
1301 >
1302 >  SSL_set_fd(fd->ssl, fd->fd);
1303 >
1304 >  if (!EmptyString(conf->cipher_list))
1305 >    SSL_set_cipher_list(client_p->localClient->fd.ssl, conf->cipher_list);
1306 >
1307 >  ssl_server_handshake(NULL, client_p);
1308   }
1309 + #endif
1310  
1311   /* serv_connect_callback() - complete a server connection.
1312 < *
1312 > *
1313   * This routine is called after the server connection attempt has
1314   * completed. If unsucessful, an error is sent to ops and the client
1315   * is closed. If sucessful, it goes through the initialisation/check
# Line 1782 | Line 1320 | static void
1320   serv_connect_callback(fde_t *fd, int status, void *data)
1321   {
1322    struct Client *client_p = data;
1323 <  struct ConfItem *conf=NULL;
1786 <  struct AccessItem *aconf=NULL;
1323 >  struct MaskItem *conf = NULL;
1324  
1325    /* First, make sure its a real client! */
1326 <  assert(client_p != NULL);
1326 >  assert(client_p);
1327    assert(&client_p->localClient->fd == fd);
1328  
1329    /* Next, for backward purposes, record the ip of the server */
1330    memcpy(&client_p->localClient->ip, &fd->connect.hostaddr,
1331           sizeof(struct irc_ssaddr));
1332 +
1333    /* Check the status */
1334    if (status != COMM_OK)
1335    {
# Line 1799 | Line 1337 | serv_connect_callback(fde_t *fd, int sta
1337       * Admins get to see any IP, mere opers don't *sigh*
1338       */
1339       if (ConfigServerHide.hide_server_ips)
1340 <       sendto_realops_flags(UMODE_ALL, L_ADMIN,
1340 >       sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1341                              "Error connecting to %s: %s",
1342                              client_p->name, comm_errstr(status));
1343       else
1344 <       sendto_realops_flags(UMODE_ALL, L_ADMIN,
1345 <                            "Error connecting to %s[%s]: %s", client_p->name,
1346 <                            client_p->host, comm_errstr(status));
1347 <
1348 <     sendto_realops_flags(UMODE_ALL, L_OPER,
1349 <                          "Error connecting to %s: %s",
1350 <                          client_p->name, comm_errstr(status));
1344 >       sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1345 >                            "Error connecting to %s[%s]: %s", client_p->name,
1346 >                            client_p->host, comm_errstr(status));
1347 >
1348 >     sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1349 >                          "Error connecting to %s: %s",
1350 >                          client_p->name, comm_errstr(status));
1351  
1352       /* If a fd goes bad, call dead_link() the socket is no
1353        * longer valid for reading or writing.
# Line 1821 | Line 1359 | serv_connect_callback(fde_t *fd, int sta
1359    /* COMM_OK, so continue the connection procedure */
1360    /* Get the C/N lines */
1361    conf = find_conf_name(&client_p->localClient->confs,
1362 <                        client_p->name, SERVER_TYPE);
1362 >                        client_p->name, CONF_SERVER);
1363    if (conf == NULL)
1364    {
1365 <    sendto_realops_flags(UMODE_ALL, L_ADMIN,
1366 <                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
1367 <    sendto_realops_flags(UMODE_ALL, L_OPER,
1368 <                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
1365 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1366 >                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
1367 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1368 >                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
1369  
1370 <    exit_client(client_p, &me, "Lost connect{} block");
1370 >    exit_client(client_p, "Lost connect{} block");
1371      return;
1372    }
1373  
1836 –  aconf = (struct AccessItem *)map_to_conf(conf);
1374    /* Next, send the initial handshake */
1375    SetHandshake(client_p);
1376  
1377   #ifdef HAVE_LIBCRYPTO
1378 <  /* Handle all CRYPTLINK links in cryptlink_init */
1842 <  if (IsConfCryptLink(aconf))
1378 >  if (IsConfSSL(conf))
1379    {
1380 <    cryptlink_init(client_p, conf, fd);
1380 >    ssl_connect_init(client_p, conf, fd);
1381      return;
1382    }
1383   #endif
1384  
1385 <  /* jdc -- Check and send spasswd, not passwd. */
1850 <  if (!EmptyString(aconf->spasswd) && (me.id[0] != '\0'))
1851 <      /* Send TS 6 form only if id */
1852 <    sendto_one(client_p, "PASS %s TS %d %s",
1853 <               aconf->spasswd, TS_CURRENT, me.id);
1854 <  else
1855 <    sendto_one(client_p, "PASS %s TS 5",
1856 <               aconf->spasswd);
1385 >  sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
1386  
1387 <  /* Pass my info to the new server
1859 <   *
1860 <   * If this is a HUB, pass on CAP_HUB
1861 <   * Pass on ZIP if supported
1862 <   * Pass on TB if supported.
1863 <   * - Dianora
1864 <   */
1865 <  send_capabilities(client_p, aconf, (ServerInfo.hub ? CAP_HUB : 0)
1866 <                    | (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1867 <                    | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), 0);
1387 >  send_capabilities(client_p, 0);
1388  
1389 <  sendto_one(client_p, "SERVER %s 1 :%s%s",
1390 <             my_name_for_link(conf),
1871 <             ConfigServerHide.hidden ? "(H) " : "",
1872 <             me.info);
1389 >  sendto_one(client_p, "SERVER %s 1 :%s%s", me.name,
1390 >             ConfigServerHide.hidden ? "(H) " : "", me.info);
1391  
1392    /* If we've been marked dead because a send failed, just exit
1393     * here now and save everyone the trouble of us ever existing.
1394     */
1395 <  if (IsDead(client_p))
1395 >  if (IsDead(client_p))
1396    {
1397 <      sendto_realops_flags(UMODE_ALL, L_ADMIN,
1398 <                           "%s[%s] went dead during handshake",
1397 >      sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1398 >                           "%s[%s] went dead during handshake",
1399                             client_p->name,
1400 <                           client_p->host);
1401 <      sendto_realops_flags(UMODE_ALL, L_OPER,
1402 <                           "%s went dead during handshake", client_p->name);
1400 >                           client_p->host);
1401 >      sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1402 >                           "%s went dead during handshake", client_p->name);
1403        return;
1404    }
1405  
# Line 1901 | Line 1419 | find_servconn_in_progress(const char *na
1419      cptr = ptr->data;
1420  
1421      if (cptr && cptr->name[0])
1422 <      if (match(cptr->name, name) || match(name, cptr->name))
1422 >      if (!match(name, cptr->name))
1423          return cptr;
1424    }
1907 –  
1908 –  return NULL;
1909 – }
1910 –
1911 – #ifdef HAVE_LIBCRYPTO
1912 – /*
1913 – * sends a CRYPTLINK SERV command.
1914 – */
1915 – void
1916 – cryptlink_init(struct Client *client_p, struct ConfItem *conf, fde_t *fd)
1917 – {
1918 –  struct AccessItem *aconf;
1919 –  char *encrypted;
1920 –  unsigned char *key_to_send;
1921 –  char randkey[CIPHERKEYLEN];
1922 –  int enc_len;
1923 –
1924 –  /* get key */
1925 –  if ((!ServerInfo.rsa_private_key) ||
1926 –      (!RSA_check_key(ServerInfo.rsa_private_key)) )
1927 –  {
1928 –    cryptlink_error(client_p, "SERV", "Invalid RSA private key",
1929 –                                      "Invalid RSA private key");
1930 –    return;
1931 –  }
1932 –
1933 –  aconf = (struct AccessItem *)map_to_conf(conf);
1934 –
1935 –  if (aconf->rsa_public_key == NULL)
1936 –  {
1937 –    cryptlink_error(client_p, "SERV", "Invalid RSA public key",
1938 –                                      "Invalid RSA public key");
1939 –    return;
1940 –  }
1941 –
1942 –  if (get_randomness((unsigned char *)randkey, CIPHERKEYLEN) != 1)
1943 –  {
1944 –    cryptlink_error(client_p, "SERV", "Couldn't generate keyphrase",
1945 –                                      "Couldn't generate keyphrase");
1946 –    return;
1947 –  }
1948 –
1949 –  encrypted = MyMalloc(RSA_size(ServerInfo.rsa_private_key));
1950 –  enc_len   = RSA_public_encrypt(CIPHERKEYLEN,
1951 –                                 (unsigned char *)randkey,
1952 –                                 (unsigned char *)encrypted,
1953 –                                 aconf->rsa_public_key,
1954 –                                 RSA_PKCS1_PADDING);
1955 –
1956 –  memcpy(client_p->localClient->in_key, randkey, CIPHERKEYLEN);
1957 –
1958 –  if (enc_len <= 0)
1959 –  {
1960 –    report_crypto_errors();
1961 –    MyFree(encrypted);
1962 –    cryptlink_error(client_p, "SERV", "Couldn't encrypt data",
1963 –                                      "Couldn't encrypt data");
1964 –    return;
1965 –  }
1966 –
1967 –  if (!(base64_block(&key_to_send, encrypted, enc_len)))
1968 –  {
1969 –    MyFree(encrypted);
1970 –    cryptlink_error(client_p, "SERV", "Couldn't base64 encode key",
1971 –                                      "Couldn't base64 encode key");
1972 –    return;
1973 –  }
1425  
1426 <  send_capabilities(client_p, aconf, (ServerInfo.hub ? CAP_HUB : 0)
1976 <                    | (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1977 <                    | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), CAP_ENC_MASK);
1978 <
1979 <  if (me.id[0])
1980 <    sendto_one(client_p, "PASS . TS %d %s", TS_CURRENT, me.id);
1981 <
1982 <  sendto_one(client_p, "CRYPTLINK SERV %s %s :%s%s",
1983 <             my_name_for_link(conf), key_to_send,
1984 <             ConfigServerHide.hidden ? "(H) " : "", me.info);
1985 <
1986 <  SetHandshake(client_p);
1987 <  SetWaitAuth(client_p);
1988 <
1989 <  MyFree(encrypted);
1990 <  MyFree(key_to_send);
1991 <
1992 <  if (IsDead(client_p))
1993 <    cryptlink_error(client_p, "SERV", "Went dead during handshake",
1994 <                                      "Went dead during handshake");
1995 <  else if (fd != NULL)
1996 <    /* If we get here, we're ok, so lets start reading some data */
1997 <    comm_setselect(fd, COMM_SELECT_READ, read_packet, client_p, 0);
1998 < }
1999 <
2000 < void
2001 < cryptlink_error(struct Client *client_p, const char *type,
2002 <                const char *reason, const char *client_reason)
2003 < {
2004 <  sendto_realops_flags(UMODE_ALL, L_ADMIN, "%s: CRYPTLINK %s error - %s",
2005 <                       get_client_name(client_p, SHOW_IP), type, reason);
2006 <  sendto_realops_flags(UMODE_ALL, L_OPER,  "%s: CRYPTLINK %s error - %s",
2007 <                       get_client_name(client_p, MASK_IP), type, reason);
2008 <  ilog(L_ERROR, "%s: CRYPTLINK %s error - %s",
2009 <       get_client_name(client_p, SHOW_IP), type, reason);
2010 <
2011 <  /* If client_reason isn't NULL, then exit the client with the message
2012 <   * defined in the call.
2013 <   */
2014 <  if ((client_reason != NULL) && (!IsDead(client_p)))
2015 <    exit_client(client_p, &me, client_reason);
2016 < }
2017 <
2018 < static char base64_chars[] =
2019 <        "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=";
2020 <
2021 < static char base64_values[] =
2022 < {
2023 < /* 00-15   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2024 < /* 16-31   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2025 < /* 32-47   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, 62, -1, -1, -1, 63,
2026 < /* 48-63   */ 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, -1, -1, -1,  0, -1, -1,
2027 < /* 64-79   */ -1,  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14,
2028 < /* 80-95   */ 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, -1, -1, -1, -1, -1,
2029 < /* 96-111  */ -1, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40,
2030 < /* 112-127 */ 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, -1, -1, -1, -1, -1,
2031 < /* 128-143 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2032 < /* 144-159 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2033 < /* 160-175 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2034 < /* 186-191 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2035 < /* 192-207 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2036 < /* 208-223 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2037 < /* 224-239 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2038 < /* 240-255 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1
2039 < };
2040 <
2041 < /*
2042 < * base64_block will allocate and return a new block of memory
2043 < * using MyMalloc().  It should be freed after use.
2044 < */
2045 < int
2046 < base64_block(unsigned char **output, char *data, int len)
2047 < {
2048 <  unsigned char *out;
2049 <  unsigned char *in = (unsigned char*)data;
2050 <  unsigned long int q_in;
2051 <  int i;
2052 <  int count = 0;
2053 <
2054 <  out = MyMalloc(((((len + 2) - ((len + 2) % 3)) / 3) * 4) + 1);
2055 <
2056 <  /* process 24 bits at a time */
2057 <  for( i = 0; i < len; i += 3)
2058 <  {
2059 <    q_in = 0;
2060 <
2061 <    if ( i + 2 < len )
2062 <    {
2063 <      q_in  = (in[i+2] & 0xc0) << 2;
2064 <      q_in |=  in[i+2];
2065 <    }
2066 <
2067 <    if ( i + 1 < len )
2068 <    {
2069 <      q_in |= (in[i+1] & 0x0f) << 10;
2070 <      q_in |= (in[i+1] & 0xf0) << 12;
2071 <    }
2072 <
2073 <    q_in |= (in[i]   & 0x03) << 20;
2074 <    q_in |=  in[i]           << 22;
2075 <
2076 <    q_in &= 0x3f3f3f3f;
2077 <
2078 <    out[count++] = base64_chars[((q_in >> 24)       )];
2079 <    out[count++] = base64_chars[((q_in >> 16) & 0xff)];
2080 <    out[count++] = base64_chars[((q_in >>  8) & 0xff)];
2081 <    out[count++] = base64_chars[((q_in      ) & 0xff)];
2082 <  }
2083 <  if ( (i - len) > 0 )
2084 <  {
2085 <    out[count-1] = '=';
2086 <    if ( (i - len) > 1 )
2087 <      out[count-2] = '=';
2088 <  }
2089 <
2090 <  out[count] = '\0';
2091 <  *output = out;
2092 <  return (count);
2093 < }
2094 <
2095 < /*
2096 < * unbase64_block will allocate and return a new block of memory
2097 < * using MyMalloc().  It should be freed after use.
2098 < */
2099 < int
2100 < unbase64_block(unsigned char **output, char *data, int len)
2101 < {
2102 <  unsigned char *out;
2103 <  unsigned char *in = (unsigned char*)data;
2104 <  unsigned long int q_in;
2105 <  int i;
2106 <  int count = 0;
2107 <
2108 <  if ((len % 4) != 0)
2109 <    return (0);
2110 <
2111 <  out = MyMalloc(((len / 4) * 3) + 1);
2112 <
2113 <  /* process 32 bits at a time */
2114 <  for( i = 0; (i + 3) < len; i+=4)
2115 <  {
2116 <    /* compress input (chars a, b, c and d) as follows:
2117 <     * (after converting ascii -> base64 value)
2118 <     *
2119 <     * |00000000aaaaaabbbbbbccccccdddddd|
2120 <     * |  765432  107654  321076  543210|
2121 <     */
2122 <
2123 <    q_in = 0;
2124 <
2125 <    if (base64_values[in[i+3]] > -1)
2126 <      q_in |= base64_values[in[i+3]]      ;
2127 <    if (base64_values[in[i+2]] > -1)
2128 <      q_in |= base64_values[in[i+2]] <<  6;
2129 <    if (base64_values[in[i+1]] > -1)
2130 <      q_in |= base64_values[in[i+1]] << 12;
2131 <    if (base64_values[in[i  ]] > -1)
2132 <      q_in |= base64_values[in[i  ]] << 18;
2133 <
2134 <    out[count++] = (q_in >> 16) & 0xff;
2135 <    out[count++] = (q_in >>  8) & 0xff;
2136 <    out[count++] = (q_in      ) & 0xff;
2137 <  }
2138 <
2139 <  if (in[i-1] == '=') count--;
2140 <  if (in[i-2] == '=') count--;
2141 <
2142 <  out[count] = '\0';
2143 <  *output = out;
2144 <  return (count);
1426 >  return NULL;
1427   }
2146 –
2147 – #endif /* HAVE_LIBCRYPTO */
2148 –

Diff Legend

– Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)