ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/branches/8.2.x/src/server.c
(Generate patch)

Comparing:
ircd-hybrid-8/src/s_serv.c (file contents), Revision 1241 by michael, Thu Sep 29 20:26:09 2011 UTC vs.
ircd-hybrid/trunk/src/s_serv.c (file contents), Revision 3303 by michael, Sun Apr 13 11:19:36 2014 UTC

# Line 1 | Line 1
1   /*
2 < *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  s_serv.c: Server related functions.
2 > *  ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3   *
4 < *  Copyright (C) 2005 by the past and present ircd coders, and others.
4 > *  Copyright (c) 1997-2014 ircd-hybrid development team
5   *
6   *  This program is free software; you can redistribute it and/or modify
7   *  it under the terms of the GNU General Public License as published by
# Line 18 | Line 17
17   *  along with this program; if not, write to the Free Software
18   *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
19   *  USA
20 < *
21 < *  $Id$
20 > */
21 >
22 > /*! \file s_serv.c
23 > * \brief Server related functions.
24 > * \version $Id$
25   */
26  
27   #include "stdinc.h"
# Line 28 | Line 30
30   #include "rsa.h"
31   #endif
32   #include "list.h"
31 #include "channel.h"
32 #include "channel_mode.h"
33   #include "client.h"
34 #include "common.h"
35 #include "dbuf.h"
34   #include "event.h"
37 #include "fdlist.h"
35   #include "hash.h"
36   #include "irc_string.h"
40 #include "sprintf_irc.h"
37   #include "ircd.h"
38   #include "ircd_defs.h"
39   #include "s_bsd.h"
40   #include "numeric.h"
41   #include "packet.h"
42 < #include "irc_res.h"
47 < #include "s_conf.h"
42 > #include "conf.h"
43   #include "s_serv.h"
44 < #include "s_log.h"
44 > #include "log.h"
45 > #include "s_misc.h"
46   #include "s_user.h"
47   #include "send.h"
48   #include "memory.h"
49 < #include "channel.h" /* chcap_usage_counts stuff...*/
49 > #include "channel.h"
50 > #include "parse.h"
51  
52   #define MIN_CONN_FREQ 300
53  
54 + dlink_list flatten_links;
55   static dlink_list cap_list = { NULL, NULL, 0 };
58 static void server_burst(struct Client *);
59 static int fork_server(struct Client *);
60 static void burst_all(struct Client *);
61 static void send_tb(struct Client *client_p, struct Channel *chptr);
62
56   static CNCB serv_connect_callback;
57  
65 static void start_io(struct Client *);
66 static void burst_members(struct Client *, struct Channel *);
67
68 static SlinkRplHnd slink_error;
69 static SlinkRplHnd slink_zipstats;
70
71
72 #ifdef HAVE_LIBCRYPTO
73 struct EncCapability CipherTable[] =
74 {
75 #ifdef HAVE_EVP_BF_CFB
76  { "BF/168",     CAP_ENC_BF_168,     24, CIPHER_BF     },
77  { "BF/128",     CAP_ENC_BF_128,     16, CIPHER_BF     },
78 #endif
79 #ifdef HAVE_EVP_CAST5_CFB
80  { "CAST/128",   CAP_ENC_CAST_128,   16, CIPHER_CAST   },
81 #endif
82 #ifdef HAVE_EVP_IDEA_CFB
83  { "IDEA/128",   CAP_ENC_IDEA_128,   16, CIPHER_IDEA   },
84 #endif
85 #ifdef HAVE_EVP_RC5_32_12_16_CFB
86  { "RC5.16/128", CAP_ENC_RC5_16_128, 16, CIPHER_RC5_16 },
87  { "RC5.12/128", CAP_ENC_RC5_12_128, 16, CIPHER_RC5_12 },
88  { "RC5.8/128",  CAP_ENC_RC5_8_128,  16, CIPHER_RC5_8  },
89 #endif
90 #ifdef HAVE_EVP_DES_EDE3_CFB
91  { "3DES/168",   CAP_ENC_3DES_168,   24, CIPHER_3DES   },
92 #endif
93 #ifdef HAVE_EVP_DES_CFB
94  { "DES/56",     CAP_ENC_DES_56,      8, CIPHER_DES    },
95 #endif
96  { 0,            0,                   0, 0             }
97 };
98 #endif
99
100 struct SlinkRplDef slinkrpltab[] = {
101  { SLINKRPL_ERROR,    slink_error,    SLINKRPL_FLAG_DATA },
102  { SLINKRPL_ZIPSTATS, slink_zipstats, SLINKRPL_FLAG_DATA },
103  { 0,                 0,              0 },
104 };
105
106
107 void
108 slink_error(unsigned int rpl, unsigned int len, unsigned char *data,
109            struct Client *server_p)
110 {
111  assert(rpl == SLINKRPL_ERROR);
112  assert(len < 256);
113
114  data[len-1] = '\0';
115
116  sendto_realops_flags(UMODE_ALL, L_ALL, "SlinkError for %s: %s",
117                       server_p->name, data);
118  /* XXX should this be exit_client? */
119  exit_client(server_p, &me, "servlink error -- terminating link");
120 }
121
122 void
123 slink_zipstats(unsigned int rpl, unsigned int len, unsigned char *data,
124               struct Client *server_p)
125 {
126  struct ZipStats zipstats;
127  uint64_t in = 0, in_wire = 0, out = 0, out_wire = 0;
128  int i = 0;
129
130  assert(rpl == SLINKRPL_ZIPSTATS);
131  assert(len == 16);
132  assert(IsCapable(server_p, CAP_ZIP));
133
134  /* Yes, it needs to be done this way, no we cannot let the compiler
135   * work with the pointer to the structure.  This works around a GCC
136   * bug on SPARC that affects all versions at the time of this writing.
137   * I will feed you to the creatures living in RMS's beard if you do
138   * not leave this as is, without being sure that you are not causing
139   * regression for most of our installed SPARC base.
140   * -jmallett, 04/27/2002
141   */
142  memcpy(&zipstats, &server_p->localClient->zipstats, sizeof(struct ZipStats));
143
144  in |= (data[i++] << 24);
145  in |= (data[i++] << 16);
146  in |= (data[i++] <<  8);
147  in |= (data[i++]      );
148
149  in_wire |= (data[i++] << 24);
150  in_wire |= (data[i++] << 16);
151  in_wire |= (data[i++] <<  8);
152  in_wire |= (data[i++]      );
153
154  out |= (data[i++] << 24);
155  out |= (data[i++] << 16);
156  out |= (data[i++] <<  8);
157  out |= (data[i++]      );
158
159  out_wire |= (data[i++] << 24);
160  out_wire |= (data[i++] << 16);
161  out_wire |= (data[i++] <<  8);
162  out_wire |= (data[i++]      );
163
164  /* This macro adds b to a if a plus b is not an overflow, and sets the
165   * value of a to b if it is.
166   * Add and Set if No Overflow.
167   */
168 #define ASNO(a, b) a = (a + b >= a ? a + b : b)
169
170  ASNO(zipstats.in, in);
171  ASNO(zipstats.out, out);
172  ASNO(zipstats.in_wire, in_wire);
173  ASNO(zipstats.out_wire, out_wire);
174
175  if (zipstats.in > 0)
176    zipstats.in_ratio = (((double)(zipstats.in - zipstats.in_wire) /
177                         (double)zipstats.in) * 100.00);
178  else
179    zipstats.in_ratio = 0;
180
181  if (zipstats.out > 0)
182    zipstats.out_ratio = (((double)(zipstats.out - zipstats.out_wire) /
183                          (double)zipstats.out) * 100.00);
184  else
185    zipstats.out_ratio = 0;
186
187  memcpy(&server_p->localClient->zipstats, &zipstats, sizeof(struct ZipStats));
188 }
189
190 void
191 collect_zipstats(void *unused)
192 {
193  dlink_node *ptr = NULL;
194
195  DLINK_FOREACH(ptr, serv_list.head)
196  {
197    struct Client *target_p = ptr->data;
198
199    if (IsCapable(target_p, CAP_ZIP))
200    {
201      /* only bother if we haven't already got something queued... */
202      if (!target_p->localClient->slinkq)
203      {
204        target_p->localClient->slinkq     = MyMalloc(1); /* sigh.. */
205        target_p->localClient->slinkq[0]  = SLINKCMD_ZIPSTATS;
206        target_p->localClient->slinkq_ofs = 0;
207        target_p->localClient->slinkq_len = 1;
208        send_queued_slink_write(target_p);
209      }
210    }
211  }
212 }
213
214 #ifdef HAVE_LIBCRYPTO
215 struct EncCapability *
216 check_cipher(struct Client *client_p, struct AccessItem *aconf)
217 {
218  struct EncCapability *epref = NULL;
219
220  /* Use connect{} specific info if available */
221  if (aconf->cipher_preference)
222    epref = aconf->cipher_preference;
223  else if (ConfigFileEntry.default_cipher_preference)
224    epref = ConfigFileEntry.default_cipher_preference;
225
226  /*
227   * If the server supports the capability in hand, return the matching
228   * conf struct.  Otherwise, return NULL (an error).
229   */
230  if (epref && IsCapableEnc(client_p, epref->cap))
231    return epref;
232
233  return NULL;
234 }
235 #endif /* HAVE_LIBCRYPTO */
58  
59   /*
60   * write_links_file
# Line 243 | Line 65 | check_cipher(struct Client *client_p, st
65   *                but in no particular order.
66   */
67   void
68 < write_links_file(void* notused)
68 > write_links_file(void *notused)
69   {
70 <  MessageFileLine *next_mptr = 0;
71 <  MessageFileLine *mptr = 0;
72 <  MessageFileLine *currentMessageLine = 0;
251 <  MessageFileLine *newMessageLine = 0;
252 <  MessageFile *MessageFileptr;
253 <  const char *p;
254 <  FBFILE *file;
255 <  char buff[512];
256 <  dlink_node *ptr;
70 >  FILE *file = NULL;
71 >  dlink_node *ptr = NULL, *ptr_next = NULL;
72 >  char buff[IRCD_BUFSIZE] = "";
73  
74 <  MessageFileptr = &ConfigFileEntry.linksfile;
259 <
260 <  if ((file = fbopen(MessageFileptr->fileName, "w")) == NULL)
74 >  if ((file = fopen(LIPATH, "w")) == NULL)
75      return;
76  
77 <  for (mptr = MessageFileptr->contentsOfFile; mptr; mptr = next_mptr)
77 >  DLINK_FOREACH_SAFE(ptr, ptr_next, flatten_links.head)
78    {
79 <    next_mptr = mptr->next;
80 <    MyFree(mptr);
79 >    dlinkDelete(ptr, &flatten_links);
80 >    MyFree(ptr->data);
81 >    free_dlink_node(ptr);
82    }
83  
269  MessageFileptr->contentsOfFile = NULL;
270  currentMessageLine             = NULL;
271
84    DLINK_FOREACH(ptr, global_serv_list.head)
85    {
86 <    size_t nbytes = 0;
275 <    struct Client *target_p = ptr->data;
86 >    const struct Client *target_p = ptr->data;
87  
88 <    /* skip ourselves, we send ourselves in /links */
89 <    if (IsMe(target_p))
88 >    /*
89 >     * Skip hidden servers, aswell as ourselves, since we already send
90 >     * ourselves in /links
91 >     */
92 >    if (IsHidden(target_p) || IsMe(target_p))
93        continue;
94  
95 <    /* skip hidden servers */
282 <    if (IsHidden(target_p) && !ConfigServerHide.disable_hidden)
95 >    if (HasFlag(target_p, FLAGS_SERVICE) && ConfigServerHide.hide_services)
96        continue;
97  
98 <    if (target_p->info[0])
99 <      p = target_p->info;
287 <    else
288 <      p = "(Unknown Location)";
289 <
290 <    newMessageLine = MyMalloc(sizeof(MessageFileLine));
291 <
292 <    /* Attempt to format the file in such a way it follows the usual links output
98 >    /*
99 >     * Attempt to format the file in such a way it follows the usual links output
100       * ie  "servername uplink :hops info"
101       * Mostly for aesthetic reasons - makes it look pretty in mIRC ;)
102       * - madmax
103       */
104 +    snprintf(buff, sizeof(buff), "%s %s :1 %s",   target_p->name,
105 +             me.name, target_p->info);
106 +    dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
107 +    snprintf(buff, sizeof(buff), "%s %s :1 %s\n", target_p->name,
108 +             me.name, target_p->info);
109  
110 <    /*
111 <     * For now, check this ircsprintf wont overflow - it shouldnt on a
300 <     * default config but it is configurable..
301 <     * This should be changed to an snprintf at some point, but I'm wanting to
302 <     * know if this is a cause of a bug - cryogen
303 <     */
304 <    assert(strlen(target_p->name) + strlen(me.name) + 6 + strlen(p) <=
305 <            MESSAGELINELEN);
306 <    ircsprintf(newMessageLine->line, "%s %s :1 %s",
307 <               target_p->name, me.name, p);
308 <    newMessageLine->next = NULL;
110 >    fputs(buff, file);
111 >  }
112  
113 <    if (MessageFileptr->contentsOfFile)
114 <    {
115 <      if (currentMessageLine)
116 <        currentMessageLine->next = newMessageLine;
117 <      currentMessageLine = newMessageLine;
118 <    }
119 <    else
120 <    {
121 <      MessageFileptr->contentsOfFile = newMessageLine;
122 <      currentMessageLine = newMessageLine;
123 <    }
113 >  fclose(file);
114 > }
115 >
116 > void
117 > read_links_file(void)
118 > {
119 >  FILE *file = NULL;
120 >  char *p = NULL;
121 >  char buff[IRCD_BUFSIZE] = "";
122 >
123 >  if ((file = fopen(LIPATH, "r")) == NULL)
124 >    return;
125 >
126 >  while (fgets(buff, sizeof(buff), file))
127 >  {
128 >    if ((p = strchr(buff, '\n')))
129 >      *p = '\0';
130  
131 <    nbytes = ircsprintf(buff, "%s %s :1 %s\n", target_p->name, me.name, p);
323 <    fbputs(buff, file, nbytes);
131 >    dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
132    }
133  
134 <  fbclose(file);
134 >  fclose(file);
135   }
136  
137   /* hunt_server()
# Line 346 | Line 154 | write_links_file(void* notused)
154   *      returns: (see #defines)
155   */
156   int
157 < hunt_server(struct Client *client_p, struct Client *source_p, const char *command,
158 <            int server, int parc, char *parv[])
157 > hunt_server(struct Client *source_p, const char *command,
158 >            const int server, const int parc, char *parv[])
159   {
160    struct Client *target_p = NULL;
161    struct Client *target_tmp = NULL;
162    dlink_node *ptr;
163    int wilds;
164  
165 <  /* Assume it's me, if no server
166 <   */
167 <  if (parc <= server || EmptyString(parv[server]) ||
168 <      match(me.name, parv[server]) ||
169 <      match(parv[server], me.name) ||
170 <      !strcmp(parv[server], me.id))
363 <    return(HUNTED_ISME);
165 >  /* Assume it's me, if no server */
166 >  if (parc <= server || EmptyString(parv[server]))
167 >    return HUNTED_ISME;
168 >
169 >  if (!strcmp(parv[server], me.id) || !match(parv[server], me.name))
170 >    return HUNTED_ISME;
171  
172    /* These are to pickup matches that would cause the following
173     * message to go in the wrong direction while doing quick fast
# Line 369 | Line 176 | hunt_server(struct Client *client_p, str
176    if (MyClient(source_p))
177      target_p = hash_find_client(parv[server]);
178    else
179 <    target_p = find_person(client_p, parv[server]);
179 >    target_p = find_person(source_p, parv[server]);
180  
181    if (target_p)
182      if (target_p->from == source_p->from && !MyConnect(target_p))
# Line 379 | Line 186 | hunt_server(struct Client *client_p, str
186      if (target_p->from == source_p->from && !MyConnect(target_p))
187        target_p = NULL;
188  
189 <  collapse(parv[server]);
383 <  wilds = (strchr(parv[server], '?') || strchr(parv[server], '*'));
189 >  wilds = has_wildcards(parv[server]);
190  
191    /* Again, if there are no wild cards involved in the server
192     * name, use the hash lookup
# Line 391 | Line 197 | hunt_server(struct Client *client_p, str
197      {
198        if (!(target_p = hash_find_server(parv[server])))
199        {
200 <        sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
201 <                   me.name, source_p->name, parv[server]);
396 <        return(HUNTED_NOSUCH);
200 >        sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
201 >        return HUNTED_NOSUCH;
202        }
203      }
204      else
# Line 402 | Line 207 | hunt_server(struct Client *client_p, str
207        {
208          target_tmp = ptr->data;
209  
210 <        if (match(parv[server], target_tmp->name))
210 >        if (!match(parv[server], target_tmp->name))
211          {
212            if (target_tmp->from == source_p->from && !MyConnect(target_tmp))
213              continue;
214            target_p = ptr->data;
215  
216 <          if (IsRegistered(target_p) && (target_p != client_p))
216 >          if (IsRegistered(target_p) && (target_p != source_p->from))
217              break;
218          }
219        }
220      }
221    }
222  
223 <  if (target_p != NULL)
223 >  if (target_p)
224    {
225 <    if(!IsRegistered(target_p))
225 >    if (!IsRegistered(target_p))
226      {
227 <      sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
423 <                 me.name, source_p->name, parv[server]);
227 >      sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
228        return HUNTED_NOSUCH;
229      }
230  
231      if (IsMe(target_p) || MyClient(target_p))
232        return HUNTED_ISME;
233  
234 <    if (!match(target_p->name, parv[server]))
234 >    if (match(target_p->name, parv[server]))
235        parv[server] = target_p->name;
236  
237      /* This is a little kludgy but should work... */
238 <    if (IsClient(source_p) &&
435 <        ((MyConnect(target_p) && IsCapable(target_p, CAP_TS6)) ||
436 <         (!MyConnect(target_p) && IsCapable(target_p->from, CAP_TS6))))
437 <      parv[0] = ID(source_p);
438 <
439 <    sendto_one(target_p, command, parv[0],
238 >    sendto_one(target_p, command, ID_or_name(source_p, target_p),
239                 parv[1], parv[2], parv[3], parv[4],
240                 parv[5], parv[6], parv[7], parv[8]);
241 <    return(HUNTED_PASS);
242 <  }
241 >    return HUNTED_PASS;
242 >  }
243  
244 <  sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
245 <             me.name, source_p->name, parv[server]);
447 <  return(HUNTED_NOSUCH);
244 >  sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
245 >  return HUNTED_NOSUCH;
246   }
247  
248   /* try_connections()
# Line 460 | Line 258 | hunt_server(struct Client *client_p, str
258   void
259   try_connections(void *unused)
260   {
261 <  dlink_node *ptr;
262 <  struct ConfItem *conf;
465 <  struct AccessItem *aconf;
466 <  struct ClassItem *cltmp;
261 >  dlink_node *ptr = NULL;
262 >  struct MaskItem *conf;
263    int confrq;
264  
265    /* TODO: change this to set active flag to 0 when added to event! --Habeeb */
# Line 473 | Line 269 | try_connections(void *unused)
269    DLINK_FOREACH(ptr, server_items.head)
270    {
271      conf = ptr->data;
476    aconf = map_to_conf(conf);
272  
273 <    /* Also when already connecting! (update holdtimes) --SRB
273 >    assert(conf->type == CONF_SERVER);
274 >
275 >    /* Also when already connecting! (update holdtimes) --SRB
276       */
277 <    if (!(aconf->status & CONF_SERVER) || !aconf->port ||
481 <        !(IsConfAllowAutoConn(aconf)))
277 >    if (!conf->port ||!IsConfAllowAutoConn(conf))
278        continue;
279  
484    cltmp = map_to_conf(aconf->class_ptr);
280  
281      /* Skip this entry if the use of it is still on hold until
282       * future. Otherwise handle this entry (and set it on hold
# Line 489 | Line 284 | try_connections(void *unused)
284       * made one successfull connection... [this algorithm is
285       * a bit fuzzy... -- msa >;) ]
286       */
287 <    if (aconf->hold > CurrentTime)
287 >    if (conf->until > CurrentTime)
288        continue;
289  
290 <    if (cltmp == NULL)
290 >    if (conf->class == NULL)
291        confrq = DEFAULT_CONNECTFREQUENCY;
292      else
293      {
294 <      confrq = ConFreq(cltmp);
295 <      if (confrq < MIN_CONN_FREQ )
296 <        confrq = MIN_CONN_FREQ;
294 >      confrq = conf->class->con_freq;
295 >      if (confrq < MIN_CONN_FREQ)
296 >        confrq = MIN_CONN_FREQ;
297      }
298  
299 <    aconf->hold = CurrentTime + confrq;
299 >    conf->until = CurrentTime + confrq;
300  
301 <    /* Found a CONNECT config with port specified, scan clients
301 >    /*
302 >     * Found a CONNECT config with port specified, scan clients
303       * and see if this server is already connected?
304       */
305 <    if (hash_find_server(conf->name) != NULL)
305 >    if (hash_find_server(conf->name))
306        continue;
307  
308 <    if (CurrUserCount(cltmp) < MaxTotal(cltmp))
308 >    if (conf->class->ref_count < conf->class->max_total)
309      {
310        /* Go to the end of the list, if not already last */
311 <      if (ptr->next != NULL)
311 >      if (ptr->next)
312        {
313          dlinkDelete(ptr, &server_items);
314          dlinkAddTail(conf, &conf->node, &server_items);
# Line 521 | Line 317 | try_connections(void *unused)
317        if (find_servconn_in_progress(conf->name))
318          return;
319  
320 <      /* We used to only print this if serv_connect() actually
320 >      /*
321 >       * We used to only print this if serv_connect() actually
322         * succeeded, but since comm_tcp_connect() can call the callback
323         * immediately if there is an error, we were getting error messages
324         * in the wrong order. SO, we just print out the activated line,
# Line 530 | Line 327 | try_connections(void *unused)
327         *   -- adrian
328         */
329        if (ConfigServerHide.hide_server_ips)
330 <        sendto_realops_flags(UMODE_ALL, L_ALL, "Connection to %s activated.",
330 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
331 >                             "Connection to %s activated.",
332                               conf->name);
333        else
334 <        sendto_realops_flags(UMODE_ALL, L_ALL, "Connection to %s[%s] activated.",
335 <                             conf->name, aconf->host);
334 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
335 >                             "Connection to %s[%s] activated.",
336 >                             conf->name, conf->host);
337  
338 <      serv_connect(aconf, NULL);
338 >      serv_connect(conf, NULL);
339        /* We connect only one at time... */
340        return;
341      }
# Line 561 | Line 360 | valid_servname(const char *name)
360        ++dots;
361    }
362  
363 <  return dots != 0 && length <= HOSTLEN;
363 >  return dots && length <= HOSTLEN;
364   }
365  
366   int
367 < check_server(const char *name, struct Client *client_p, int cryptlink)
367 > check_server(const char *name, struct Client *client_p)
368   {
369    dlink_node *ptr;
370 <  struct ConfItem *conf           = NULL;
371 <  struct ConfItem *server_conf    = NULL;
573 <  struct AccessItem *server_aconf = NULL;
574 <  struct AccessItem *aconf        = NULL;
370 >  struct MaskItem *conf        = NULL;
371 >  struct MaskItem *server_conf = NULL;
372    int error = -1;
373  
374 <  assert(client_p != NULL);
578 <
579 <  if (client_p == NULL)
580 <    return(error);
581 <
582 <  if (strlen(name) > HOSTLEN)
583 <    return(-4);
374 >  assert(client_p);
375  
376    /* loop through looking for all possible connect items that might work */
377    DLINK_FOREACH(ptr, server_items.head)
378    {
379      conf = ptr->data;
589    aconf = map_to_conf(conf);
380  
381 <    if (!match(name, conf->name))
381 >    if (match(name, conf->name))
382        continue;
383  
384      error = -3;
385  
386      /* XXX: Fix me for IPv6                    */
387      /* XXX sockhost is the IPv4 ip as a string */
388 <    if (match(aconf->host, client_p->host) ||
389 <        match(aconf->host, client_p->sockhost))
388 >    if (!match(conf->host, client_p->host) ||
389 >        !match(conf->host, client_p->sockhost))
390      {
391        error = -2;
602 #ifdef HAVE_LIBCRYPTO
603      if (cryptlink && IsConfCryptLink(aconf))
604      {
605        if (aconf->rsa_public_key)
606          server_conf = conf;
607      }
608      else if (!(cryptlink || IsConfCryptLink(aconf)))
609 #endif /* HAVE_LIBCRYPTO */
610      {
611        /* A NULL password is as good as a bad one */
612        if (EmptyString(client_p->localClient->passwd))
613          return(-2);
614
615        /* code in s_conf.c should not have allowed this to be NULL */
616        if (aconf->passwd == NULL)
617          return(-2);
392  
393 <        if (IsConfEncrypted(aconf))
394 <        {
395 <          if (strcmp(aconf->passwd,
396 <              (const char *)crypt(client_p->localClient->passwd,
397 <                                  aconf->passwd)) == 0)
398 <            server_conf = conf;
399 <        }
400 <        else
627 <        {
628 <          if (strcmp(aconf->passwd, client_p->localClient->passwd) == 0)
629 <            server_conf = conf;
630 <        }
631 <      }
393 >      if (!match_conf_password(client_p->localClient->passwd, conf))
394 >        return -2;
395 >
396 >      if (!EmptyString(conf->certfp))
397 >        if (EmptyString(client_p->certfp) || strcasecmp(client_p->certfp, conf->certfp))
398 >          return -4;
399 >
400 >      server_conf = conf;
401      }
402    }
403  
404    if (server_conf == NULL)
405 <    return(error);
405 >    return error;
406  
407    attach_conf(client_p, server_conf);
408  
640  /* Now find all leaf or hub config items for this server */
641  DLINK_FOREACH(ptr, hub_items.head)
642  {
643    conf = ptr->data;
644
645    if (!match(name, conf->name))
646      continue;
647    attach_conf(client_p, conf);
648  }
409  
410 <  DLINK_FOREACH(ptr, leaf_items.head)
651 <  {
652 <    conf = ptr->data;
653 <
654 <    if (!match(name, conf->name))
655 <      continue;
656 <    attach_conf(client_p, conf);
657 <  }
658 <
659 <  server_aconf = map_to_conf(server_conf);
660 <
661 < #ifdef HAVE_LIBZ /* otherwise, clear it unconditionally */
662 <  if (!IsConfCompressed(server_aconf))
663 < #endif
664 <    ClearCap(client_p, CAP_ZIP);
665 <  if (!IsConfCryptLink(server_aconf))
666 <    ClearCap(client_p, CAP_ENC);
667 <  if (!IsConfTopicBurst(server_aconf))
668 <  {
669 <    ClearCap(client_p, CAP_TB);
670 <    ClearCap(client_p, CAP_TBURST);
671 <  }
672 <
673 <  if (aconf != NULL)
410 >  if (server_conf)
411    {
412      struct sockaddr_in *v4;
413   #ifdef IPV6
414      struct sockaddr_in6 *v6;
415   #endif
416 <    switch (aconf->aftype)
416 >    switch (server_conf->aftype)
417      {
418   #ifdef IPV6
419 <      case AF_INET6:
420 <        v6 = (struct sockaddr_in6 *)&aconf->ipnum;
419 >      case AF_INET6:
420 >        v6 = (struct sockaddr_in6 *)&server_conf->addr;
421  
422          if (IN6_IS_ADDR_UNSPECIFIED(&v6->sin6_addr))
423 <          memcpy(&aconf->ipnum, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
423 >          memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
424          break;
425   #endif
426        case AF_INET:
427 <        v4 = (struct sockaddr_in *)&aconf->ipnum;
427 >        v4 = (struct sockaddr_in *)&server_conf->addr;
428  
429          if (v4->sin_addr.s_addr == INADDR_NONE)
430 <          memcpy(&aconf->ipnum, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
430 >          memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
431          break;
432      }
433    }
434  
435 <  return(0);
435 >  return 0;
436   }
437  
438   /* add_capability()
# Line 712 | Line 449 | add_capability(const char *capab_name, i
449   {
450    struct Capability *cap = MyMalloc(sizeof(*cap));
451  
452 <  DupString(cap->name, capab_name);
452 >  cap->name = xstrdup(capab_name);
453    cap->cap = cap_flag;
454    dlinkAdd(cap, &cap->node, &cap_list);
455  
# Line 741 | Line 478 | delete_capability(const char *capab_name
478      {
479        if (irccmp(cap->name, capab_name) == 0)
480        {
481 <        default_server_capabs &= ~(cap->cap);
482 <        dlinkDelete(ptr, &cap_list);
483 <        MyFree(cap->name);
484 <        cap->name = NULL;
748 <        MyFree(cap);
481 >        default_server_capabs &= ~(cap->cap);
482 >        dlinkDelete(ptr, &cap_list);
483 >        MyFree(cap->name);
484 >        MyFree(cap);
485        }
486      }
487    }
# Line 760 | Line 496 | delete_capability(const char *capab_name
496   * output       - 0 if not found CAPAB otherwise
497   * side effects - none
498   */
499 < int
499 > unsigned int
500   find_capability(const char *capab)
501   {
502    const dlink_node *ptr = NULL;
# Line 779 | Line 515 | find_capability(const char *capab)
515   /* send_capabilities()
516   *
517   * inputs       - Client pointer to send to
782 *              - Pointer to AccessItem (for crypt)
518   *              - int flag of capabilities that this server can send
784 *              - int flag of encryption capabilities
519   * output       - NONE
520   * side effects - send the CAPAB line to a server  -orabidoo
521   *
522   */
523   void
524 < send_capabilities(struct Client *client_p, struct AccessItem *aconf,
791 <                  int cap_can_send, int enc_can_send)
524 > send_capabilities(struct Client *client_p, int cap_can_send)
525   {
526 <  struct Capability *cap=NULL;
527 <  char msgbuf[IRCD_BUFSIZE];
795 <  char *t;
526 >  char msgbuf[IRCD_BUFSIZE] = "";
527 >  char *t = msgbuf;
528    int tl;
529 <  dlink_node *ptr;
798 < #ifdef HAVE_LIBCRYPTO
799 <  const struct EncCapability *epref = NULL;
800 <  char *capend;
801 <  int sent_cipher = 0;
802 < #endif
803 <
804 <  t = msgbuf;
529 >  dlink_node *ptr = NULL;
530  
531    DLINK_FOREACH(ptr, cap_list.head)
532    {
533 <    cap = ptr->data;
533 >    struct Capability *cap = ptr->data;
534  
535      if (cap->cap & (cap_can_send|default_server_capabs))
536      {
537 <      tl = ircsprintf(t, "%s ", cap->name);
537 >      tl = sprintf(t, "%s ", cap->name);
538        t += tl;
539      }
540    }
816 #ifdef HAVE_LIBCRYPTO
817  if (enc_can_send)
818  {
819    capend = t;
820    strcpy(t, "ENC:");
821    t += 4;
822
823    /* use connect{} specific info if available */
824    if (aconf->cipher_preference)
825      epref = aconf->cipher_preference;
826    else if (ConfigFileEntry.default_cipher_preference)
827      epref = ConfigFileEntry.default_cipher_preference;
828
829    if (epref && (epref->cap & enc_can_send))
830    {
831      /* Leave the space -- it is removed later. */
832      tl = ircsprintf(t, "%s ", epref->name);
833      t += tl;
834      sent_cipher = 1;
835    }
541  
837    if (!sent_cipher)
838      t = capend; /* truncate string before ENC:, below */
839  }
840 #endif
542    *(t - 1) = '\0';
543    sendto_one(client_p, "CAPAB :%s", msgbuf);
544   }
545  
845 /* sendnick_TS()
846 *
847 * inputs       - client (server) to send nick towards
848 *          - client to send nick for
849 * output       - NONE
850 * side effects - NICK message is sent towards given client_p
851 */
852 void
853 sendnick_TS(struct Client *client_p, struct Client *target_p)
854 {
855  static char ubuf[12];
856
857  if (!IsClient(target_p))
858    return;
859
860  send_umode(NULL, target_p, 0, HasOFlag(target_p, OPER_FLAG_HIDDEN_ADMIN) ?
861    SEND_UMODES & ~UMODE_ADMIN : SEND_UMODES, ubuf);
862
863  if (ubuf[0] == '\0')
864  {
865    ubuf[0] = '+';
866    ubuf[1] = '\0';
867  }
868
869  /* XXX Both of these need to have a :me.name or :mySID!?!?! */
870  if (IsCapable(client_p, CAP_SVS))
871  {
872    if (HasID(target_p) && IsCapable(client_p, CAP_TS6))
873      sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s %lu :%s",
874                 target_p->servptr->id,
875                 target_p->name, target_p->hopcount + 1,
876                 (unsigned long) target_p->tsinfo,
877                 ubuf, target_p->username, target_p->host,
878                 (MyClient(target_p) && IsIPSpoof(target_p)) ?
879                 "0" : target_p->sockhost, target_p->id,
880                 (unsigned long)target_p->servicestamp, target_p->info);
881    else
882      sendto_one(client_p, "NICK %s %d %lu %s %s %s %s %lu :%s",
883                 target_p->name, target_p->hopcount + 1,
884                 (unsigned long) target_p->tsinfo,
885                 ubuf, target_p->username, target_p->host,
886                 target_p->servptr->name, (unsigned long)target_p->servicestamp,
887                 target_p->info);
888  }
889  else
890  {
891    if (HasID(target_p) && IsCapable(client_p, CAP_TS6))
892      sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s :%s",
893                 target_p->servptr->id,
894                 target_p->name, target_p->hopcount + 1,
895                 (unsigned long) target_p->tsinfo,
896                 ubuf, target_p->username, target_p->host,
897                 (MyClient(target_p) && IsIPSpoof(target_p)) ?
898                 "0" : target_p->sockhost, target_p->id, target_p->info);
899    else
900      sendto_one(client_p, "NICK %s %d %lu %s %s %s %s :%s",
901                 target_p->name, target_p->hopcount + 1,
902                 (unsigned long) target_p->tsinfo,
903                 ubuf, target_p->username, target_p->host,
904                 target_p->servptr->name, target_p->info);
905  }
906
907  if (IsConfAwayBurst((struct AccessItem *)map_to_conf(client_p->serv->sconf)))
908    if (!EmptyString(target_p->away))
909      sendto_one(client_p, ":%s AWAY :%s", target_p->name,
910                 target_p->away);
911
912 }
913
546   /*
547   * show_capabilities - show current server capabilities
548   *
# Line 919 | Line 551 | sendnick_TS(struct Client *client_p, str
551   * side effects - build up string representing capabilities of server listed
552   */
553   const char *
554 < show_capabilities(struct Client *target_p)
554 > show_capabilities(const struct Client *target_p)
555   {
556 <  static char msgbuf[IRCD_BUFSIZE];
557 <  char *t = msgbuf;
926 <  dlink_node *ptr;
556 >  static char msgbuf[IRCD_BUFSIZE] = "";
557 >  const dlink_node *ptr = NULL;
558  
559 <  t += ircsprintf(msgbuf, "TS ");
559 >  strlcpy(msgbuf, "TS", sizeof(msgbuf));
560  
561    DLINK_FOREACH(ptr, cap_list.head)
562    {
563      const struct Capability *cap = ptr->data;
564  
565 <    if (IsCapable(target_p, cap->cap))
566 <      t += ircsprintf(t, "%s ", cap->name);
565 >    if (!IsCapable(target_p, cap->cap))
566 >      continue;
567 >
568 >    strlcat(msgbuf,       " ", sizeof(msgbuf));
569 >    strlcat(msgbuf, cap->name, sizeof(msgbuf));
570    }
937 #ifdef HAVE_LIBCRYPTO
938  if (IsCapable(target_p, CAP_ENC) &&
939      target_p->localClient->in_cipher &&
940      target_p->localClient->out_cipher)
941    t += ircsprintf(t, "ENC:%s ",
942                    target_p->localClient->in_cipher->name);
943 #endif
944  *(t - 1) = '\0';
571  
572 <  return(msgbuf);
572 >  return msgbuf;
573   }
574  
575   /* make_server()
# Line 962 | Line 588 | make_server(struct Client *client_p)
588    return client_p->serv;
589   }
590  
965 /* server_estab()
966 *
967 * inputs       - pointer to a struct Client
968 * output       -
969 * side effects -
970 */
971 void
972 server_estab(struct Client *client_p)
973 {
974  struct Client *target_p;
975  struct ConfItem *conf;
976  struct AccessItem *aconf=NULL;
977  char *host;
978  const char *inpath;
979  static char inpath_ip[HOSTLEN * 2 + USERLEN + 6];
980  dlink_node *ptr;
981
982  assert(client_p != NULL);
983
984  strlcpy(inpath_ip, get_client_name(client_p, SHOW_IP), sizeof(inpath_ip));
985
986  inpath = get_client_name(client_p, MASK_IP); /* "refresh" inpath with host */
987  host   = client_p->name;
988
989  if ((conf = find_conf_name(&client_p->localClient->confs, host, SERVER_TYPE))
990      == NULL)
991  {
992    /* This shouldn't happen, better tell the ops... -A1kmm */
993    sendto_realops_flags(UMODE_ALL, L_ALL, "Warning: Lost connect{} block "
994                         "for server %s(this shouldn't happen)!", host);
995    exit_client(client_p, &me, "Lost connect{} block!");
996    return;
997  }
998
999  MyFree(client_p->localClient->passwd);
1000  client_p->localClient->passwd = NULL;
1001
1002  /* Its got identd, since its a server */
1003  SetGotId(client_p);
1004
1005  /* If there is something in the serv_list, it might be this
1006   * connecting server..
1007   */
1008  if (!ServerInfo.hub && serv_list.head)  
1009  {
1010    if (client_p != serv_list.head->data || serv_list.head->next)
1011    {
1012      ++ServerStats.is_ref;
1013      sendto_one(client_p, "ERROR :I'm a leaf not a hub");
1014      exit_client(client_p, &me, "I'm a leaf");
1015      return;
1016    }
1017  }
1018
1019  aconf = map_to_conf(conf);
1020
1021  if (IsUnknown(client_p) && !IsConfCryptLink(aconf))
1022  {
1023    /* jdc -- 1.  Use EmptyString(), not [0] index reference.
1024     *        2.  Check aconf->spasswd, not aconf->passwd.
1025     */
1026    if (!EmptyString(aconf->spasswd))
1027      sendto_one(client_p, "PASS %s TS %d %s",
1028                 aconf->spasswd, TS_CURRENT, me.id);
1029
1030    /* Pass my info to the new server
1031     *
1032     * Pass on ZIP if supported
1033     * Pass on TB if supported.
1034     * - Dianora
1035     */
1036
1037    send_capabilities(client_p, aconf,
1038      (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1039      | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), 0);
1040
1041    /* SERVER is the last command sent before switching to ziplinks.
1042     * We set TCPNODELAY on the socket to make sure it gets sent out
1043     * on the wire immediately.  Otherwise, it could be sitting in
1044     * a kernel buffer when we start sending zipped data, and the
1045     * parser on the receiving side can't hand both unzipped and zipped
1046     * data in one packet. --Rodder
1047     *
1048     * currently we only need to call send_queued_write,
1049     * Nagle is already disabled at this point --adx
1050     */
1051    sendto_one(client_p, "SERVER %s 1 :%s%s",
1052               me.name, ConfigServerHide.hidden ? "(H) " : "", me.info);
1053    send_queued_write(client_p);
1054  }
1055
1056  /* Hand the server off to servlink now */
1057  if (IsCapable(client_p, CAP_ENC) || IsCapable(client_p, CAP_ZIP))
1058  {
1059    if (fork_server(client_p) < 0)
1060    {
1061      sendto_realops_flags(UMODE_ALL, L_ADMIN,
1062                           "Warning: fork failed for server %s -- check servlink_path (%s)",
1063                           get_client_name(client_p, HIDE_IP), ConfigFileEntry.servlink_path);
1064      sendto_realops_flags(UMODE_ALL, L_OPER, "Warning: fork failed for server "
1065                           "%s -- check servlink_path (%s)",
1066                           get_client_name(client_p, MASK_IP),
1067                           ConfigFileEntry.servlink_path);
1068      exit_client(client_p, &me, "fork failed");
1069      return;
1070    }
1071
1072    start_io(client_p);
1073    SetServlink(client_p);
1074  }
1075
1076  sendto_one(client_p, "SVINFO %d %d 0 :%lu", TS_CURRENT, TS_MIN,
1077             (unsigned long)CurrentTime);
1078
1079  /* assumption here is if they passed the correct TS version, they also passed an SID */
1080  if (IsCapable(client_p, CAP_TS6))
1081    hash_add_id(client_p);
1082
1083  /* XXX Does this ever happen? I don't think so -db */
1084  detach_conf(client_p, OPER_TYPE);
1085
1086  /* *WARNING*
1087  **    In the following code in place of plain server's
1088  **    name we send what is returned by get_client_name
1089  **    which may add the "sockhost" after the name. It's
1090  **    *very* *important* that there is a SPACE between
1091  **    the name and sockhost (if present). The receiving
1092  **    server will start the information field from this
1093  **    first blank and thus puts the sockhost into info.
1094  **    ...a bit tricky, but you have been warned, besides
1095  **    code is more neat this way...  --msa
1096  */
1097  client_p->servptr = &me;
1098
1099  if (IsClosing(client_p))
1100    return;
1101
1102  SetServer(client_p);
1103
1104  /* Update the capability combination usage counts. -A1kmm */
1105  set_chcap_usage_counts(client_p);
1106
1107  /* Some day, all these lists will be consolidated *sigh* */
1108  dlinkAdd(client_p, &client_p->lnode, &me.serv->server_list);
1109
1110  assert(dlinkFind(&unknown_list, client_p));
1111
1112  dlink_move_node(&client_p->localClient->lclient_node,
1113                  &unknown_list, &serv_list);
1114
1115  Count.myserver++;
1116
1117  dlinkAdd(client_p, make_dlink_node(), &global_serv_list);
1118  hash_add_client(client_p);
1119
1120  /* doesnt duplicate client_p->serv if allocated this struct already */
1121  make_server(client_p);
1122
1123  /* fixing eob timings.. -gnp */
1124  client_p->localClient->firsttime = CurrentTime;
1125
1126
1127  if (find_matching_name_conf(SERVICE_TYPE, client_p->name, NULL, NULL, 0))
1128    AddFlag(client_p, FLAGS_SERVICE);
1129
1130  /* Show the real host/IP to admins */
1131  sendto_realops_flags(UMODE_ALL, L_ADMIN,
1132                       "Link with %s established: (%s) link",
1133                       inpath_ip,show_capabilities(client_p));
1134  /* Now show the masked hostname/IP to opers */
1135  sendto_realops_flags(UMODE_ALL, L_OPER,
1136                       "Link with %s established: (%s) link",
1137                       inpath,show_capabilities(client_p));
1138  ilog(L_NOTICE, "Link with %s established: (%s) link",
1139       inpath_ip, show_capabilities(client_p));
1140
1141  client_p->serv->sconf = conf;
1142
1143  if (HasServlink(client_p))
1144  {
1145    /* we won't overflow FD_DESC_SZ here, as it can hold
1146     * client_p->name + 64
1147     */
1148    fd_note(&client_p->localClient->fd, "slink data: %s", client_p->name);
1149    fd_note(&client_p->localClient->ctrlfd, "slink ctrl: %s", client_p->name);
1150  }
1151  else
1152    fd_note(&client_p->localClient->fd, "Server: %s", client_p->name);
1153
1154  /* Old sendto_serv_but_one() call removed because we now
1155  ** need to send different names to different servers
1156  ** (domain name matching) Send new server to other servers.
1157  */
1158  DLINK_FOREACH(ptr, serv_list.head)
1159  {
1160    target_p = ptr->data;
1161
1162    if (target_p == client_p)
1163      continue;
1164
1165    if (IsCapable(target_p, CAP_TS6) && HasID(client_p))
1166      sendto_one(target_p, ":%s SID %s 2 %s :%s%s",
1167                 me.id, client_p->name, client_p->id,
1168                 IsHidden(client_p) ? "(H) " : "",
1169                 client_p->info);
1170    else
1171      sendto_one(target_p,":%s SERVER %s 2 :%s%s",
1172                 me.name, client_p->name,
1173                 IsHidden(client_p) ? "(H) " : "",
1174                 client_p->info);
1175  }
1176
1177  /* Pass on my client information to the new server
1178  **
1179  ** First, pass only servers (idea is that if the link gets
1180  ** cancelled beacause the server was already there,
1181  ** there are no NICK's to be cancelled...). Of course,
1182  ** if cancellation occurs, all this info is sent anyway,
1183  ** and I guess the link dies when a read is attempted...? --msa
1184  **
1185  ** Note: Link cancellation to occur at this point means
1186  ** that at least two servers from my fragment are building
1187  ** up connection this other fragment at the same time, it's
1188  ** a race condition, not the normal way of operation...
1189  **
1190  ** ALSO NOTE: using the get_client_name for server names--
1191  **    see previous *WARNING*!!! (Also, original inpath
1192  **    is destroyed...)
1193  */
1194
1195  DLINK_FOREACH_PREV(ptr, global_serv_list.tail)
1196  {
1197    target_p = ptr->data;
1198
1199    /* target_p->from == target_p for target_p == client_p */
1200    if (IsMe(target_p) || target_p->from == client_p)
1201      continue;
1202
1203    if (IsCapable(client_p, CAP_TS6))
1204    {
1205      if (HasID(target_p))
1206        sendto_one(client_p, ":%s SID %s %d %s :%s%s",
1207                   ID(target_p->servptr), target_p->name, target_p->hopcount+1,
1208                   target_p->id, IsHidden(target_p) ? "(H) " : "",
1209                   target_p->info);
1210      else  /* introducing non-ts6 server */
1211        sendto_one(client_p, ":%s SERVER %s %d :%s%s",
1212                   ID(target_p->servptr), target_p->name, target_p->hopcount+1,
1213                   IsHidden(target_p) ? "(H) " : "", target_p->info);
1214    }
1215    else
1216      sendto_one(client_p, ":%s SERVER %s %d :%s%s",
1217                 target_p->servptr->name, target_p->name, target_p->hopcount+1,
1218                 IsHidden(target_p) ? "(H) " : "", target_p->info);
1219  }
1220
1221  server_burst(client_p);
1222 }
1223
1224 static void
1225 start_io(struct Client *server)
1226 {
1227  struct LocalUser *lserver = server->localClient;
1228  int alloclen = 1;
1229  char *buf;
1230  dlink_node *ptr;
1231  struct dbuf_block *block;
1232
1233  /* calculate how many bytes to allocate */
1234  if (IsCapable(server, CAP_ZIP))
1235    alloclen += 6;
1236 #ifdef HAVE_LIBCRYPTO
1237  if (IsCapable(server, CAP_ENC))
1238    alloclen += 16 + lserver->in_cipher->keylen + lserver->out_cipher->keylen;
1239 #endif
1240  alloclen += dbuf_length(&lserver->buf_recvq);
1241  alloclen += dlink_list_length(&lserver->buf_recvq.blocks) * 3;
1242  alloclen += dbuf_length(&lserver->buf_sendq);
1243  alloclen += dlink_list_length(&lserver->buf_sendq.blocks) * 3;
1244
1245  /* initialize servlink control sendq */
1246  lserver->slinkq = buf = MyMalloc(alloclen);
1247  lserver->slinkq_ofs = 0;
1248  lserver->slinkq_len = alloclen;
1249
1250  if (IsCapable(server, CAP_ZIP))
1251  {
1252    /* ziplink */
1253    *buf++ = SLINKCMD_SET_ZIP_OUT_LEVEL;
1254    *buf++ = 0; /* |          */
1255    *buf++ = 1; /* \ len is 1 */
1256    *buf++ = ConfigFileEntry.compression_level;
1257    *buf++ = SLINKCMD_START_ZIP_IN;
1258    *buf++ = SLINKCMD_START_ZIP_OUT;
1259  }
1260 #ifdef HAVE_LIBCRYPTO
1261  if (IsCapable(server, CAP_ENC))
1262  {
1263    /* Decryption settings */
1264    *buf++ = SLINKCMD_SET_CRYPT_IN_CIPHER;
1265    *buf++ = 0; /* /                     (upper 8-bits of len) */
1266    *buf++ = 1; /* \ cipher id is 1 byte (lower 8-bits of len) */
1267    *buf++ = lserver->in_cipher->cipherid;
1268    *buf++ = SLINKCMD_SET_CRYPT_IN_KEY;
1269    *buf++ = 0; /* keylen < 256 */
1270    *buf++ = lserver->in_cipher->keylen;
1271    memcpy(buf, lserver->in_key, lserver->in_cipher->keylen);
1272    buf += lserver->in_cipher->keylen;
1273    /* Encryption settings */
1274    *buf++ = SLINKCMD_SET_CRYPT_OUT_CIPHER;
1275    *buf++ = 0; /* /                     (upper 8-bits of len) */
1276    *buf++ = 1; /* \ cipher id is 1 byte (lower 8-bits of len) */
1277    *buf++ = lserver->out_cipher->cipherid;
1278    *buf++ = SLINKCMD_SET_CRYPT_OUT_KEY;
1279    *buf++ = 0; /* keylen < 256 */
1280    *buf++ = lserver->out_cipher->keylen;
1281    memcpy(buf, lserver->out_key, lserver->out_cipher->keylen);
1282    buf += lserver->out_cipher->keylen;
1283    *buf++ = SLINKCMD_START_CRYPT_IN;
1284    *buf++ = SLINKCMD_START_CRYPT_OUT;
1285  }
1286 #endif
1287
1288  /* pass the whole recvq to servlink */
1289  DLINK_FOREACH (ptr, lserver->buf_recvq.blocks.head)
1290  {
1291    block = ptr->data;
1292    *buf++ = SLINKCMD_INJECT_RECVQ;
1293    *buf++ = (block->size >> 8);
1294    *buf++ = (block->size & 0xff);
1295    memcpy(buf, &block->data[0], block->size);
1296    buf += block->size;
1297  }
1298
1299  dbuf_clear(&lserver->buf_recvq);
1300
1301  /* pass the whole sendq to servlink */
1302  DLINK_FOREACH (ptr, lserver->buf_sendq.blocks.head)
1303  {
1304    block = ptr->data;
1305    *buf++ = SLINKCMD_INJECT_SENDQ;
1306    *buf++ = (block->size >> 8);
1307    *buf++ = (block->size & 0xff);
1308    memcpy(buf, &block->data[0], block->size);
1309    buf += block->size;
1310  }
1311
1312  dbuf_clear(&lserver->buf_sendq);
1313
1314  /* start io */
1315  *buf++ = SLINKCMD_INIT;
1316
1317  /* schedule a write */
1318  send_queued_slink_write(server);
1319 }
1320
1321 /* fork_server()
1322 *
1323 * inputs       - struct Client *server
1324 * output       - success: 0 / failure: -1
1325 * side effect  - fork, and exec SERVLINK to handle this connection
1326 */
1327 static int
1328 fork_server(struct Client *server)
1329 {
1330 #ifndef HAVE_SOCKETPAIR
1331  return -1;
1332 #else
1333  int i;
1334  int slink_fds[2][2];
1335  /* 0? - ctrl  | 1? - data  
1336   * ?0 - child | ?1 - parent */
1337
1338  if (socketpair(AF_UNIX, SOCK_STREAM, 0, slink_fds[0]) < 0)
1339    return -1;
1340  if (socketpair(AF_UNIX, SOCK_STREAM, 0, slink_fds[1]) < 0)
1341    goto free_ctrl_fds;
1342
1343  if ((i = fork()) < 0)
1344  {
1345    close(slink_fds[1][0]);  close(slink_fds[1][1]);
1346    free_ctrl_fds:
1347    close(slink_fds[0][0]);  close(slink_fds[0][1]);
1348    return -1;
1349  }
1350
1351  if (i == 0)
1352  {
1353    char fd_str[3][6];   /* store 3x sizeof("65535") */
1354    char *kid_argv[7];
1355
1356 #ifdef O_ASYNC
1357    fcntl(server->localClient->fd.fd, F_SETFL,
1358          fcntl(server->localClient->fd.fd, F_GETFL, 0) & ~O_ASYNC);
1359 #endif
1360    close_fds(&server->localClient->fd);
1361    close(slink_fds[0][1]);
1362    close(slink_fds[1][1]);
1363
1364    sprintf(fd_str[0], "%d", slink_fds[0][0]);
1365    sprintf(fd_str[1], "%d", slink_fds[1][0]);
1366    sprintf(fd_str[2], "%d", server->localClient->fd.fd);
1367
1368    kid_argv[0] = "-slink";
1369    kid_argv[1] = kid_argv[2] = fd_str[0];  /* ctrl */
1370    kid_argv[3] = kid_argv[4] = fd_str[1];  /* data */
1371    kid_argv[5] = fd_str[2];    /* network */
1372    kid_argv[6] = NULL;
1373
1374    execv(ConfigFileEntry.servlink_path, kid_argv);
1375
1376    _exit(1);
1377  }
1378
1379  /* close the network fd and the child ends of the pipes */
1380  fd_close(&server->localClient->fd);
1381  close(slink_fds[0][0]);
1382  close(slink_fds[1][0]);
1383
1384  execute_callback(setup_socket_cb, slink_fds[0][1]);
1385  execute_callback(setup_socket_cb, slink_fds[1][1]);
1386
1387  fd_open(&server->localClient->ctrlfd, slink_fds[0][1], 1, "slink ctrl");
1388  fd_open(&server->localClient->fd, slink_fds[1][1], 1, "slink data");
1389
1390  read_ctrl_packet(&server->localClient->ctrlfd, server);
1391  read_packet(&server->localClient->fd, server);
1392
1393  return 0;
1394 #endif
1395 }
1396
1397 /* server_burst()
1398 *
1399 * inputs       - struct Client pointer server
1400 *              -
1401 * output       - none
1402 * side effects - send a server burst
1403 * bugs         - still too long
1404 */
1405 static void
1406 server_burst(struct Client *client_p)
1407 {
1408  /* Send it in the shortened format with the TS, if
1409  ** it's a TS server; walk the list of channels, sending
1410  ** all the nicks that haven't been sent yet for each
1411  ** channel, then send the channel itself -- it's less
1412  ** obvious than sending all nicks first, but on the
1413  ** receiving side memory will be allocated more nicely
1414  ** saving a few seconds in the handling of a split
1415  ** -orabidoo
1416  */
1417
1418  burst_all(client_p);
1419
1420  /* EOB stuff is now in burst_all */
1421  /* Always send a PING after connect burst is done */
1422  sendto_one(client_p, "PING :%s", ID_or_name(&me, client_p));
1423 }
1424
1425 /* burst_all()
1426 *
1427 * inputs       - pointer to server to send burst to
1428 * output       - NONE
1429 * side effects - complete burst of channels/nicks is sent to client_p
1430 */
1431 static void
1432 burst_all(struct Client *client_p)
1433 {
1434  dlink_node *ptr = NULL;
1435
1436  DLINK_FOREACH(ptr, global_channel_list.head)
1437  {
1438    struct Channel *chptr = ptr->data;
1439
1440    if (dlink_list_length(&chptr->members) != 0)
1441    {
1442      burst_members(client_p, chptr);
1443      send_channel_modes(client_p, chptr);
1444
1445      if (IsCapable(client_p, CAP_TBURST) ||
1446          IsCapable(client_p, CAP_TB))
1447        send_tb(client_p, chptr);
1448    }
1449  }
1450
1451  /* also send out those that are not on any channel
1452   */
1453  DLINK_FOREACH(ptr, global_client_list.head)
1454  {
1455    struct Client *target_p = ptr->data;
1456
1457    if (!HasFlag(target_p, FLAGS_BURSTED) && target_p->from != client_p)
1458      sendnick_TS(client_p, target_p);
1459    
1460    DelFlag(target_p, FLAGS_BURSTED);
1461  }
1462
1463  /* We send the time we started the burst, and let the remote host determine an EOB time,
1464  ** as otherwise we end up sending a EOB of 0   Sending here means it gets sent last -- fl
1465  */
1466  /* Its simpler to just send EOB and use the time its been connected.. --fl_ */
1467  if (IsCapable(client_p, CAP_EOB))
1468    sendto_one(client_p, ":%s EOB", ID_or_name(&me, client_p));
1469 }
1470
1471 /*
1472 * send_tb
1473 *
1474 * inputs       - pointer to Client
1475 *              - pointer to channel
1476 * output       - NONE
1477 * side effects - Called on a server burst when
1478 *                server is CAP_TB|CAP_TBURST capable
1479 */
1480 static void
1481 send_tb(struct Client *client_p, struct Channel *chptr)
1482 {
1483  /*
1484   * We may also send an empty topic here, but only if topic_time isn't 0,
1485   * i.e. if we had a topic that got unset.  This is required for syncing
1486   * topics properly.
1487   *
1488   * Imagine the following scenario: Our downlink introduces a channel
1489   * to us with a TS that is equal to ours, but the channel topic on
1490   * their side got unset while the servers were in splitmode, which means
1491   * their 'topic' is newer.  They simply wanted to unset it, so we have to
1492   * deal with it in a more sophisticated fashion instead of just resetting
1493   * it to their old topic they had before.  Read m_tburst.c:ms_tburst
1494   * for further information   -Michael
1495   */
1496  if (chptr->topic_time != 0)
1497  {
1498    if (IsCapable(client_p, CAP_TBURST))
1499      sendto_one(client_p, ":%s TBURST %lu %s %lu %s :%s",
1500                 me.name, (unsigned long)chptr->channelts, chptr->chname,
1501                 (unsigned long)chptr->topic_time,
1502                 chptr->topic_info,
1503                 chptr->topic);
1504    else if (IsCapable(client_p, CAP_TB))
1505    {
1506      if (ConfigChannel.burst_topicwho)
1507      {
1508        sendto_one(client_p, ":%s TB %s %lu %s :%s",
1509                   me.name, chptr->chname,
1510                   (unsigned long)chptr->topic_time,
1511                   chptr->topic_info, chptr->topic);
1512      }
1513      else
1514      {
1515        sendto_one(client_p, ":%s TB %s %lu :%s",
1516                   me.name, chptr->chname,
1517                   (unsigned long)chptr->topic_time,
1518                   chptr->topic);
1519      }
1520    }
1521  }
1522 }
1523
1524 /* burst_members()
1525 *
1526 * inputs       - pointer to server to send members to
1527 *              - dlink_list pointer to membership list to send
1528 * output       - NONE
1529 * side effects -
1530 */
1531 static void
1532 burst_members(struct Client *client_p, struct Channel *chptr)
1533 {
1534  struct Client *target_p;
1535  struct Membership *ms;
1536  dlink_node *ptr;
1537
1538  DLINK_FOREACH(ptr, chptr->members.head)
1539  {
1540    ms       = ptr->data;
1541    target_p = ms->client_p;
1542
1543    if (!HasFlag(target_p, FLAGS_BURSTED))
1544    {
1545      AddFlag(target_p, FLAGS_BURSTED);
1546
1547      if (target_p->from != client_p)
1548        sendnick_TS(client_p, target_p);
1549    }
1550  }
1551 }
1552
591   /* New server connection code
592   * Based upon the stuff floating about in s_bsd.c
593   *   -- adrian
# Line 1557 | Line 595 | burst_members(struct Client *client_p, s
595  
596   /* serv_connect() - initiate a server connection
597   *
598 < * inputs       - pointer to conf
598 > * inputs       - pointer to conf
599   *              - pointer to client doing the connect
600   * output       -
601   * side effects -
# Line 1572 | Line 610 | burst_members(struct Client *client_p, s
610   * it suceeded or not, and 0 if it fails in here somewhere.
611   */
612   int
613 < serv_connect(struct AccessItem *aconf, struct Client *by)
613 > serv_connect(struct MaskItem *conf, struct Client *by)
614   {
615 <  struct ConfItem *conf;
616 <  struct Client *client_p;
1579 <  char buf[HOSTIPLEN];
615 >  struct Client *client_p = NULL;
616 >  char buf[HOSTIPLEN + 1] = "";
617  
618    /* conversion structs */
619    struct sockaddr_in *v4;
1583  /* Make sure aconf is useful */
1584  assert(aconf != NULL);
1585
1586  if(aconf == NULL)
1587    return (0);
620  
621 <  /* XXX should be passing struct ConfItem in the first place */
622 <  conf = unmap_conf_item(aconf);
621 >  /* Make sure conf is useful */
622 >  assert(conf);
623  
624 <  /* log */
1593 <  getnameinfo((struct sockaddr *)&aconf->ipnum, aconf->ipnum.ss_len,
624 >  getnameinfo((struct sockaddr *)&conf->addr, conf->addr.ss_len,
625                buf, sizeof(buf), NULL, 0, NI_NUMERICHOST);
626 <  ilog(L_NOTICE, "Connect to %s[%s] @%s", aconf->user, aconf->host,
626 >  ilog(LOG_TYPE_IRCD, "Connect to %s[%s] @%s", conf->name, conf->host,
627         buf);
628  
629    /* Still processing a DNS lookup? -> exit */
630 <  if (aconf->dns_pending)
630 >  if (conf->dns_pending)
631    {
632 <    sendto_realops_flags(UMODE_ALL, L_ALL,
632 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
633                           "Error connecting to %s: DNS lookup for connect{} in progress.",
634                           conf->name);
635 <    return (0);
635 >    return 0;
636    }
637  
638 <  if (aconf->dns_failed)
638 >  if (conf->dns_failed)
639    {
640 <    sendto_realops_flags(UMODE_ALL, L_ALL,
640 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
641                           "Error connecting to %s: DNS lookup for connect{} failed.",
642                           conf->name);
643 <    return (0);
643 >    return 0;
644    }
645  
646    /* Make sure this server isn't already connected
647 <   * Note: aconf should ALWAYS be a valid C: line
647 >   * Note: conf should ALWAYS be a valid C: line
648     */
649 <  if ((client_p = hash_find_server(conf->name)) != NULL)
650 <  {
651 <    sendto_realops_flags(UMODE_ALL, L_ADMIN,
652 <                         "Server %s already present from %s",
653 <                         conf->name, get_client_name(client_p, SHOW_IP));
654 <    sendto_realops_flags(UMODE_ALL, L_OPER,
655 <                         "Server %s already present from %s",
656 <                         conf->name, get_client_name(client_p, MASK_IP));
649 >  if ((client_p = hash_find_server(conf->name)))
650 >  {
651 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
652 >                         "Server %s already present from %s",
653 >                         conf->name, get_client_name(client_p, SHOW_IP));
654 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
655 >                         "Server %s already present from %s",
656 >                         conf->name, get_client_name(client_p, MASK_IP));
657      if (by && IsClient(by) && !MyClient(by))
658 <      sendto_one(by, ":%s NOTICE %s :Server %s already present from %s",
659 <                 me.name, by->name, conf->name,
660 <                 get_client_name(client_p, MASK_IP));
1630 <    return (0);
658 >      sendto_one_notice(by, &me, ":Server %s already present from %s",
659 >                        conf->name, get_client_name(client_p, MASK_IP));
660 >    return 0;
661    }
662 <    
662 >
663    /* Create a local client */
664    client_p = make_client(NULL);
665  
666    /* Copy in the server, hostname, fd */
667    strlcpy(client_p->name, conf->name, sizeof(client_p->name));
668 <  strlcpy(client_p->host, aconf->host, sizeof(client_p->host));
668 >  strlcpy(client_p->host, conf->host, sizeof(client_p->host));
669  
670    /* We already converted the ip once, so lets use it - stu */
671    strlcpy(client_p->sockhost, buf, sizeof(client_p->sockhost));
672  
673 <  /* create a socket for the server connection */
674 <  if (comm_open(&client_p->localClient->fd, aconf->ipnum.ss.ss_family,
673 >  /* create a socket for the server connection */
674 >  if (comm_open(&client_p->localClient->fd, conf->addr.ss.ss_family,
675                  SOCK_STREAM, 0, NULL) < 0)
676    {
677      /* Eek, failure to create the socket */
678 <    report_error(L_ALL,
679 <                 "opening stream socket to %s: %s", conf->name, errno);
678 >    report_error(L_ALL, "opening stream socket to %s: %s",
679 >                 conf->name, errno);
680      SetDead(client_p);
681 <    exit_client(client_p, &me, "Connection failed");
682 <    return (0);
681 >    exit_client(client_p, "Connection failed");
682 >    return 0;
683    }
684  
685    /* servernames are always guaranteed under HOSTLEN chars */
# Line 1658 | Line 688 | serv_connect(struct AccessItem *aconf, s
688    /* Attach config entries to client here rather than in
689     * serv_connect_callback(). This to avoid null pointer references.
690     */
691 <  if (!attach_connect_block(client_p, conf->name, aconf->host))
691 >  if (!attach_connect_block(client_p, conf->name, conf->host))
692    {
693 <    sendto_realops_flags(UMODE_ALL, L_ALL,
694 <                         "Host %s is not enabled for connecting:no C/N-line",
695 <                         conf->name);
696 <    if (by && IsClient(by) && !MyClient(by))  
697 <      sendto_one(by, ":%s NOTICE %s :Connect to host %s failed.",
698 <                 me.name, by->name, client_p->name);
693 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
694 >                         "Host %s is not enabled for connecting: no connect{} block",
695 >                         conf->name);
696 >    if (by && IsClient(by) && !MyClient(by))
697 >      sendto_one_notice(by, &me, ":Connect to host %s failed.", client_p->name);
698 >
699      SetDead(client_p);
700 <    exit_client(client_p, client_p, "Connection failed");
701 <    return (0);
700 >    exit_client(client_p, "Connection failed");
701 >    return 0;
702    }
703  
704    /* at this point we have a connection in progress and C/N lines
# Line 1687 | Line 717 | serv_connect(struct AccessItem *aconf, s
717    SetConnecting(client_p);
718    dlinkAdd(client_p, &client_p->node, &global_client_list);
719    /* from def_fam */
720 <  client_p->localClient->aftype = aconf->aftype;
720 >  client_p->localClient->aftype = conf->aftype;
721  
722    /* Now, initiate the connection */
723 <  /* XXX assume that a non 0 type means a specific bind address
723 >  /* XXX assume that a non 0 type means a specific bind address
724     * for this connect.
725     */
726 <  switch (aconf->aftype)
726 >  switch (conf->aftype)
727    {
728      case AF_INET:
729 <      v4 = (struct sockaddr_in*)&aconf->my_ipnum;
730 <      if (v4->sin_addr.s_addr != 0)
729 >      v4 = (struct sockaddr_in*)&conf->bind;
730 >      if (v4->sin_addr.s_addr)
731        {
732          struct irc_ssaddr ipn;
733          memset(&ipn, 0, sizeof(struct irc_ssaddr));
734          ipn.ss.ss_family = AF_INET;
735          ipn.ss_port = 0;
736 <        memcpy(&ipn, &aconf->my_ipnum, sizeof(struct irc_ssaddr));
737 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
738 <                         (struct sockaddr *)&ipn, ipn.ss_len,
739 <                         serv_connect_callback, client_p, aconf->aftype,
740 <                         CONNECTTIMEOUT);
736 >        memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
737 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
738 >                         (struct sockaddr *)&ipn, ipn.ss_len,
739 >                         serv_connect_callback, client_p, conf->aftype,
740 >                         CONNECTTIMEOUT);
741        }
742        else if (ServerInfo.specific_ipv4_vhost)
743        {
# Line 1716 | Line 746 | serv_connect(struct AccessItem *aconf, s
746          ipn.ss.ss_family = AF_INET;
747          ipn.ss_port = 0;
748          memcpy(&ipn, &ServerInfo.ip, sizeof(struct irc_ssaddr));
749 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
749 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
750                           (struct sockaddr *)&ipn, ipn.ss_len,
751 <                         serv_connect_callback, client_p, aconf->aftype,
752 <                         CONNECTTIMEOUT);
751 >                         serv_connect_callback, client_p, conf->aftype,
752 >                         CONNECTTIMEOUT);
753        }
754        else
755 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
756 <                         NULL, 0, serv_connect_callback, client_p, aconf->aftype,
755 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
756 >                         NULL, 0, serv_connect_callback, client_p, conf->aftype,
757                           CONNECTTIMEOUT);
758        break;
759   #ifdef IPV6
760      case AF_INET6:
761        {
762 <        struct irc_ssaddr ipn;
763 <        struct sockaddr_in6 *v6;
764 <        struct sockaddr_in6 *v6conf;
765 <
766 <        memset(&ipn, 0, sizeof(struct irc_ssaddr));
767 <        v6conf = (struct sockaddr_in6 *)&aconf->my_ipnum;
768 <        v6 = (struct sockaddr_in6 *)&ipn;
769 <
770 <        if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr,
771 <                   sizeof(struct in6_addr)) != 0)
772 <        {
773 <          memcpy(&ipn, &aconf->my_ipnum, sizeof(struct irc_ssaddr));
774 <          ipn.ss.ss_family = AF_INET6;
775 <          ipn.ss_port = 0;
776 <          comm_connect_tcp(&client_p->localClient->fd,
777 <                           aconf->host, aconf->port,
778 <                           (struct sockaddr *)&ipn, ipn.ss_len,
779 <                           serv_connect_callback, client_p,
780 <                           aconf->aftype, CONNECTTIMEOUT);
781 <        }
1752 <        else if (ServerInfo.specific_ipv6_vhost)
762 >        struct irc_ssaddr ipn;
763 >        struct sockaddr_in6 *v6;
764 >        struct sockaddr_in6 *v6conf;
765 >
766 >        memset(&ipn, 0, sizeof(struct irc_ssaddr));
767 >        v6conf = (struct sockaddr_in6 *)&conf->bind;
768 >        v6 = (struct sockaddr_in6 *)&ipn;
769 >
770 >        if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr, sizeof(struct in6_addr)))
771 >        {
772 >          memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
773 >          ipn.ss.ss_family = AF_INET6;
774 >          ipn.ss_port = 0;
775 >          comm_connect_tcp(&client_p->localClient->fd,
776 >                           conf->host, conf->port,
777 >                           (struct sockaddr *)&ipn, ipn.ss_len,
778 >                           serv_connect_callback, client_p,
779 >                           conf->aftype, CONNECTTIMEOUT);
780 >        }
781 >        else if (ServerInfo.specific_ipv6_vhost)
782          {
783 <          memcpy(&ipn, &ServerInfo.ip6, sizeof(struct irc_ssaddr));
784 <          ipn.ss.ss_family = AF_INET6;
785 <          ipn.ss_port = 0;
786 <          comm_connect_tcp(&client_p->localClient->fd,
787 <                           aconf->host, aconf->port,
788 <                           (struct sockaddr *)&ipn, ipn.ss_len,
789 <                           serv_connect_callback, client_p,
790 <                           aconf->aftype, CONNECTTIMEOUT);
791 <        }
792 <        else
793 <          comm_connect_tcp(&client_p->localClient->fd,
794 <                           aconf->host, aconf->port,
795 <                           NULL, 0, serv_connect_callback, client_p,
796 <                           aconf->aftype, CONNECTTIMEOUT);
783 >          memcpy(&ipn, &ServerInfo.ip6, sizeof(struct irc_ssaddr));
784 >          ipn.ss.ss_family = AF_INET6;
785 >          ipn.ss_port = 0;
786 >          comm_connect_tcp(&client_p->localClient->fd,
787 >                           conf->host, conf->port,
788 >                           (struct sockaddr *)&ipn, ipn.ss_len,
789 >                           serv_connect_callback, client_p,
790 >                           conf->aftype, CONNECTTIMEOUT);
791 >        }
792 >        else
793 >          comm_connect_tcp(&client_p->localClient->fd,
794 >                           conf->host, conf->port,
795 >                           NULL, 0, serv_connect_callback, client_p,
796 >                           conf->aftype, CONNECTTIMEOUT);
797        }
798   #endif
799    }
800 <  return (1);
800 >  return 1;
801 > }
802 >
803 > #ifdef HAVE_LIBCRYPTO
804 > static void
805 > finish_ssl_server_handshake(struct Client *client_p)
806 > {
807 >  struct MaskItem *conf = NULL;
808 >
809 >  conf = find_conf_name(&client_p->localClient->confs,
810 >                        client_p->name, CONF_SERVER);
811 >  if (conf == NULL)
812 >  {
813 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
814 >                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
815 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
816 >                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
817 >
818 >    exit_client(client_p, "Lost connect{} block");
819 >    return;
820 >  }
821 >
822 >  sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
823 >
824 >  send_capabilities(client_p, 0);
825 >
826 >  sendto_one(client_p, "SERVER %s 1 :%s%s",
827 >             me.name, ConfigServerHide.hidden ? "(H) " : "",
828 >             me.info);
829 >
830 >  /* If we've been marked dead because a send failed, just exit
831 >   * here now and save everyone the trouble of us ever existing.
832 >   */
833 >  if (IsDead(client_p))
834 >  {
835 >      sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
836 >                           "%s[%s] went dead during handshake",
837 >                           client_p->name,
838 >                           client_p->host);
839 >      sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
840 >                           "%s went dead during handshake", client_p->name);
841 >      return;
842 >  }
843 >
844 >  /* don't move to serv_list yet -- we haven't sent a burst! */
845 >  /* If we get here, we're ok, so lets start reading some data */
846 >  comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ, read_packet, client_p, 0);
847 > }
848 >
849 > static void
850 > ssl_server_handshake(fde_t *fd, struct Client *client_p)
851 > {
852 >  X509 *cert = NULL;
853 >  int ret = 0;
854 >
855 >  if ((ret = SSL_connect(client_p->localClient->fd.ssl)) <= 0)
856 >  {
857 >    switch (SSL_get_error(client_p->localClient->fd.ssl, ret))
858 >    {
859 >      case SSL_ERROR_WANT_WRITE:
860 >        comm_setselect(&client_p->localClient->fd, COMM_SELECT_WRITE,
861 >                       (PF *)ssl_server_handshake, client_p, 0);
862 >        return;
863 >      case SSL_ERROR_WANT_READ:
864 >        comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ,
865 >                       (PF *)ssl_server_handshake, client_p, 0);
866 >        return;
867 >      default:
868 >      {
869 >        const char *sslerr = ERR_error_string(ERR_get_error(), NULL);
870 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
871 >                             "Error connecting to %s: %s", client_p->name,
872 >                             sslerr ? sslerr : "unknown SSL error");
873 >        exit_client(client_p, "Error during SSL handshake");
874 >        return;
875 >      }
876 >    }
877 >  }
878 >
879 >  if ((cert = SSL_get_peer_certificate(client_p->localClient->fd.ssl)))
880 >  {
881 >    int res = SSL_get_verify_result(client_p->localClient->fd.ssl);
882 >    char buf[EVP_MAX_MD_SIZE * 2 + 1] = { '\0' };
883 >    unsigned char md[EVP_MAX_MD_SIZE] = { '\0' };
884 >
885 >    if (res == X509_V_OK || res == X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN ||
886 >        res == X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE ||
887 >        res == X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT)
888 >    {
889 >      unsigned int i = 0, n = 0;
890 >
891 >      if (X509_digest(cert, EVP_sha256(), md, &n))
892 >      {
893 >        for (; i < n; ++i)
894 >          snprintf(buf + 2 * i, 3, "%02X", md[i]);
895 >        client_p->certfp = xstrdup(buf);
896 >      }
897 >    }
898 >    else
899 >      ilog(LOG_TYPE_IRCD, "Server %s!%s@%s gave bad SSL client certificate: %d",
900 >           client_p->name, client_p->username, client_p->host, res);
901 >    X509_free(cert);
902 >  }
903 >
904 >  finish_ssl_server_handshake(client_p);
905 > }
906 >
907 > static void
908 > ssl_connect_init(struct Client *client_p, struct MaskItem *conf, fde_t *fd)
909 > {
910 >  if ((client_p->localClient->fd.ssl = SSL_new(ServerInfo.client_ctx)) == NULL)
911 >  {
912 >    ilog(LOG_TYPE_IRCD, "SSL_new() ERROR! -- %s",
913 >         ERR_error_string(ERR_get_error(), NULL));
914 >    SetDead(client_p);
915 >    exit_client(client_p, "SSL_new failed");
916 >    return;
917 >  }
918 >
919 >  SSL_set_fd(fd->ssl, fd->fd);
920 >
921 >  if (!EmptyString(conf->cipher_list))
922 >    SSL_set_cipher_list(client_p->localClient->fd.ssl, conf->cipher_list);
923 >
924 >  ssl_server_handshake(NULL, client_p);
925   }
926 + #endif
927  
928   /* serv_connect_callback() - complete a server connection.
929 < *
929 > *
930   * This routine is called after the server connection attempt has
931   * completed. If unsucessful, an error is sent to ops and the client
932   * is closed. If sucessful, it goes through the initialisation/check
# Line 1783 | Line 937 | static void
937   serv_connect_callback(fde_t *fd, int status, void *data)
938   {
939    struct Client *client_p = data;
940 <  struct ConfItem *conf=NULL;
1787 <  struct AccessItem *aconf=NULL;
940 >  struct MaskItem *conf = NULL;
941  
942    /* First, make sure its a real client! */
943 <  assert(client_p != NULL);
943 >  assert(client_p);
944    assert(&client_p->localClient->fd == fd);
945  
946    /* Next, for backward purposes, record the ip of the server */
947    memcpy(&client_p->localClient->ip, &fd->connect.hostaddr,
948           sizeof(struct irc_ssaddr));
949 +
950    /* Check the status */
951    if (status != COMM_OK)
952    {
# Line 1800 | Line 954 | serv_connect_callback(fde_t *fd, int sta
954       * Admins get to see any IP, mere opers don't *sigh*
955       */
956       if (ConfigServerHide.hide_server_ips)
957 <       sendto_realops_flags(UMODE_ALL, L_ADMIN,
957 >       sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
958                              "Error connecting to %s: %s",
959                              client_p->name, comm_errstr(status));
960       else
961 <       sendto_realops_flags(UMODE_ALL, L_ADMIN,
962 <                            "Error connecting to %s[%s]: %s", client_p->name,
963 <                            client_p->host, comm_errstr(status));
964 <
965 <     sendto_realops_flags(UMODE_ALL, L_OPER,
966 <                          "Error connecting to %s: %s",
967 <                          client_p->name, comm_errstr(status));
961 >       sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
962 >                            "Error connecting to %s[%s]: %s", client_p->name,
963 >                            client_p->host, comm_errstr(status));
964 >
965 >     sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
966 >                          "Error connecting to %s: %s",
967 >                          client_p->name, comm_errstr(status));
968  
969       /* If a fd goes bad, call dead_link() the socket is no
970        * longer valid for reading or writing.
# Line 1822 | Line 976 | serv_connect_callback(fde_t *fd, int sta
976    /* COMM_OK, so continue the connection procedure */
977    /* Get the C/N lines */
978    conf = find_conf_name(&client_p->localClient->confs,
979 <                        client_p->name, SERVER_TYPE);
979 >                        client_p->name, CONF_SERVER);
980    if (conf == NULL)
981    {
982 <    sendto_realops_flags(UMODE_ALL, L_ADMIN,
983 <                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
984 <    sendto_realops_flags(UMODE_ALL, L_OPER,
985 <                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
982 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
983 >                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
984 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
985 >                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
986  
987 <    exit_client(client_p, &me, "Lost connect{} block");
987 >    exit_client(client_p, "Lost connect{} block");
988      return;
989    }
990  
1837  aconf = (struct AccessItem *)map_to_conf(conf);
991    /* Next, send the initial handshake */
992    SetHandshake(client_p);
993  
994   #ifdef HAVE_LIBCRYPTO
995 <  /* Handle all CRYPTLINK links in cryptlink_init */
1843 <  if (IsConfCryptLink(aconf))
995 >  if (IsConfSSL(conf))
996    {
997 <    cryptlink_init(client_p, conf, fd);
997 >    ssl_connect_init(client_p, conf, fd);
998      return;
999    }
1000   #endif
1001  
1002 <  /* jdc -- Check and send spasswd, not passwd. */
1851 <  if (!EmptyString(aconf->spasswd))
1852 <      /* Send TS 6 form only if id */
1853 <    sendto_one(client_p, "PASS %s TS %d %s",
1854 <               aconf->spasswd, TS_CURRENT, me.id);
1002 >  sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
1003  
1004 <  /* Pass my info to the new server
1857 <   *
1858 <   * Pass on ZIP if supported
1859 <   * Pass on TB if supported.
1860 <   * - Dianora
1861 <   */
1862 <  send_capabilities(client_p, aconf,
1863 <                    (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1864 <                    | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), 0);
1004 >  send_capabilities(client_p, 0);
1005  
1006 <  sendto_one(client_p, "SERVER %s 1 :%s%s",
1007 <             me.name, ConfigServerHide.hidden ? "(H) " : "",
1868 <             me.info);
1006 >  sendto_one(client_p, "SERVER %s 1 :%s%s", me.name,
1007 >             ConfigServerHide.hidden ? "(H) " : "", me.info);
1008  
1009    /* If we've been marked dead because a send failed, just exit
1010     * here now and save everyone the trouble of us ever existing.
1011     */
1012 <  if (IsDead(client_p))
1012 >  if (IsDead(client_p))
1013    {
1014 <      sendto_realops_flags(UMODE_ALL, L_ADMIN,
1015 <                           "%s[%s] went dead during handshake",
1014 >      sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1015 >                           "%s[%s] went dead during handshake",
1016                             client_p->name,
1017 <                           client_p->host);
1018 <      sendto_realops_flags(UMODE_ALL, L_OPER,
1019 <                           "%s went dead during handshake", client_p->name);
1017 >                           client_p->host);
1018 >      sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1019 >                           "%s went dead during handshake", client_p->name);
1020        return;
1021    }
1022  
# Line 1897 | Line 1036 | find_servconn_in_progress(const char *na
1036      cptr = ptr->data;
1037  
1038      if (cptr && cptr->name[0])
1039 <      if (match(name, cptr->name))
1039 >      if (!match(name, cptr->name))
1040          return cptr;
1041    }
1903  
1904  return NULL;
1905 }
1906
1907 #ifdef HAVE_LIBCRYPTO
1908 /*
1909 * sends a CRYPTLINK SERV command.
1910 */
1911 void
1912 cryptlink_init(struct Client *client_p, struct ConfItem *conf, fde_t *fd)
1913 {
1914  struct AccessItem *aconf;
1915  char *encrypted;
1916  unsigned char *key_to_send;
1917  char randkey[CIPHERKEYLEN];
1918  int enc_len;
1919
1920  /* get key */
1921  if ((!ServerInfo.rsa_private_key) ||
1922      (!RSA_check_key(ServerInfo.rsa_private_key)) )
1923  {
1924    cryptlink_error(client_p, "SERV", "Invalid RSA private key",
1925                                      "Invalid RSA private key");
1926    return;
1927  }
1042  
1043 <  aconf = (struct AccessItem *)map_to_conf(conf);
1930 <
1931 <  if (aconf->rsa_public_key == NULL)
1932 <  {
1933 <    cryptlink_error(client_p, "SERV", "Invalid RSA public key",
1934 <                                      "Invalid RSA public key");
1935 <    return;
1936 <  }
1937 <
1938 <  if (get_randomness((unsigned char *)randkey, CIPHERKEYLEN) != 1)
1939 <  {
1940 <    cryptlink_error(client_p, "SERV", "Couldn't generate keyphrase",
1941 <                                      "Couldn't generate keyphrase");
1942 <    return;
1943 <  }
1944 <
1945 <  encrypted = MyMalloc(RSA_size(ServerInfo.rsa_private_key));
1946 <  enc_len   = RSA_public_encrypt(CIPHERKEYLEN,
1947 <                                 (unsigned char *)randkey,
1948 <                                 (unsigned char *)encrypted,
1949 <                                 aconf->rsa_public_key,
1950 <                                 RSA_PKCS1_PADDING);
1951 <
1952 <  memcpy(client_p->localClient->in_key, randkey, CIPHERKEYLEN);
1953 <
1954 <  if (enc_len <= 0)
1955 <  {
1956 <    report_crypto_errors();
1957 <    MyFree(encrypted);
1958 <    cryptlink_error(client_p, "SERV", "Couldn't encrypt data",
1959 <                                      "Couldn't encrypt data");
1960 <    return;
1961 <  }
1962 <
1963 <  if (!(base64_block(&key_to_send, encrypted, enc_len)))
1964 <  {
1965 <    MyFree(encrypted);
1966 <    cryptlink_error(client_p, "SERV", "Couldn't base64 encode key",
1967 <                                      "Couldn't base64 encode key");
1968 <    return;
1969 <  }
1970 <
1971 <  send_capabilities(client_p, aconf,
1972 <                    (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1973 <                    | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), CAP_ENC_MASK);
1974 <
1975 <  sendto_one(client_p, "PASS . TS %d %s", TS_CURRENT, me.id);
1976 <  sendto_one(client_p, "CRYPTLINK SERV %s %s :%s%s",
1977 <             me.name, key_to_send,
1978 <             ConfigServerHide.hidden ? "(H) " : "", me.info);
1979 <
1980 <  SetHandshake(client_p);
1981 <  SetWaitAuth(client_p);
1982 <
1983 <  MyFree(encrypted);
1984 <  MyFree(key_to_send);
1985 <
1986 <  if (IsDead(client_p))
1987 <    cryptlink_error(client_p, "SERV", "Went dead during handshake",
1988 <                                      "Went dead during handshake");
1989 <  else if (fd != NULL)
1990 <    /* If we get here, we're ok, so lets start reading some data */
1991 <    comm_setselect(fd, COMM_SELECT_READ, read_packet, client_p, 0);
1992 < }
1993 <
1994 < void
1995 < cryptlink_error(struct Client *client_p, const char *type,
1996 <                const char *reason, const char *client_reason)
1997 < {
1998 <  sendto_realops_flags(UMODE_ALL, L_ADMIN, "%s: CRYPTLINK %s error - %s",
1999 <                       get_client_name(client_p, SHOW_IP), type, reason);
2000 <  sendto_realops_flags(UMODE_ALL, L_OPER,  "%s: CRYPTLINK %s error - %s",
2001 <                       get_client_name(client_p, MASK_IP), type, reason);
2002 <  ilog(L_ERROR, "%s: CRYPTLINK %s error - %s",
2003 <       get_client_name(client_p, SHOW_IP), type, reason);
2004 <
2005 <  /* If client_reason isn't NULL, then exit the client with the message
2006 <   * defined in the call.
2007 <   */
2008 <  if ((client_reason != NULL) && (!IsDead(client_p)))
2009 <    exit_client(client_p, &me, client_reason);
2010 < }
2011 <
2012 < static char base64_chars[] =
2013 <        "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=";
2014 <
2015 < static char base64_values[] =
2016 < {
2017 < /* 00-15   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2018 < /* 16-31   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2019 < /* 32-47   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, 62, -1, -1, -1, 63,
2020 < /* 48-63   */ 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, -1, -1, -1,  0, -1, -1,
2021 < /* 64-79   */ -1,  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14,
2022 < /* 80-95   */ 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, -1, -1, -1, -1, -1,
2023 < /* 96-111  */ -1, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40,
2024 < /* 112-127 */ 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, -1, -1, -1, -1, -1,
2025 < /* 128-143 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2026 < /* 144-159 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2027 < /* 160-175 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2028 < /* 186-191 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2029 < /* 192-207 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2030 < /* 208-223 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2031 < /* 224-239 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2032 < /* 240-255 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1
2033 < };
2034 <
2035 < /*
2036 < * base64_block will allocate and return a new block of memory
2037 < * using MyMalloc().  It should be freed after use.
2038 < */
2039 < int
2040 < base64_block(unsigned char **output, char *data, int len)
2041 < {
2042 <  unsigned char *out;
2043 <  unsigned char *in = (unsigned char*)data;
2044 <  unsigned long int q_in;
2045 <  int i;
2046 <  int count = 0;
2047 <
2048 <  out = MyMalloc(((((len + 2) - ((len + 2) % 3)) / 3) * 4) + 1);
2049 <
2050 <  /* process 24 bits at a time */
2051 <  for( i = 0; i < len; i += 3)
2052 <  {
2053 <    q_in = 0;
2054 <
2055 <    if ( i + 2 < len )
2056 <    {
2057 <      q_in  = (in[i+2] & 0xc0) << 2;
2058 <      q_in |=  in[i+2];
2059 <    }
2060 <
2061 <    if ( i + 1 < len )
2062 <    {
2063 <      q_in |= (in[i+1] & 0x0f) << 10;
2064 <      q_in |= (in[i+1] & 0xf0) << 12;
2065 <    }
2066 <
2067 <    q_in |= (in[i]   & 0x03) << 20;
2068 <    q_in |=  in[i]           << 22;
2069 <
2070 <    q_in &= 0x3f3f3f3f;
2071 <
2072 <    out[count++] = base64_chars[((q_in >> 24)       )];
2073 <    out[count++] = base64_chars[((q_in >> 16) & 0xff)];
2074 <    out[count++] = base64_chars[((q_in >>  8) & 0xff)];
2075 <    out[count++] = base64_chars[((q_in      ) & 0xff)];
2076 <  }
2077 <  if ( (i - len) > 0 )
2078 <  {
2079 <    out[count-1] = '=';
2080 <    if ( (i - len) > 1 )
2081 <      out[count-2] = '=';
2082 <  }
2083 <
2084 <  out[count] = '\0';
2085 <  *output = out;
2086 <  return (count);
2087 < }
2088 <
2089 < /*
2090 < * unbase64_block will allocate and return a new block of memory
2091 < * using MyMalloc().  It should be freed after use.
2092 < */
2093 < int
2094 < unbase64_block(unsigned char **output, char *data, int len)
2095 < {
2096 <  unsigned char *out;
2097 <  unsigned char *in = (unsigned char*)data;
2098 <  unsigned long int q_in;
2099 <  int i;
2100 <  int count = 0;
2101 <
2102 <  if ((len % 4) != 0)
2103 <    return (0);
2104 <
2105 <  out = MyMalloc(((len / 4) * 3) + 1);
2106 <
2107 <  /* process 32 bits at a time */
2108 <  for( i = 0; (i + 3) < len; i+=4)
2109 <  {
2110 <    /* compress input (chars a, b, c and d) as follows:
2111 <     * (after converting ascii -> base64 value)
2112 <     *
2113 <     * |00000000aaaaaabbbbbbccccccdddddd|
2114 <     * |  765432  107654  321076  543210|
2115 <     */
2116 <
2117 <    q_in = 0;
2118 <
2119 <    if (base64_values[in[i+3]] > -1)
2120 <      q_in |= base64_values[in[i+3]]      ;
2121 <    if (base64_values[in[i+2]] > -1)
2122 <      q_in |= base64_values[in[i+2]] <<  6;
2123 <    if (base64_values[in[i+1]] > -1)
2124 <      q_in |= base64_values[in[i+1]] << 12;
2125 <    if (base64_values[in[i  ]] > -1)
2126 <      q_in |= base64_values[in[i  ]] << 18;
2127 <
2128 <    out[count++] = (q_in >> 16) & 0xff;
2129 <    out[count++] = (q_in >>  8) & 0xff;
2130 <    out[count++] = (q_in      ) & 0xff;
2131 <  }
2132 <
2133 <  if (in[i-1] == '=') count--;
2134 <  if (in[i-2] == '=') count--;
2135 <
2136 <  out[count] = '\0';
2137 <  *output = out;
2138 <  return (count);
1043 >  return NULL;
1044   }
2140
2141 #endif /* HAVE_LIBCRYPTO */
2142

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)