ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/branches/8.2.x/src/server.c
(Generate patch)

Comparing:
ircd-hybrid-7.2/src/s_serv.c (file contents), Revision 889 by michael, Thu Nov 1 12:59:05 2007 UTC vs.
ircd-hybrid/trunk/src/s_serv.c (file contents), Revision 3215 by michael, Tue Mar 25 19:23:15 2014 UTC

# Line 1 | Line 1
1   /*
2 < *  ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd).
3 < *  s_serv.c: Server related functions.
2 > *  ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3   *
4 < *  Copyright (C) 2005 by the past and present ircd coders, and others.
4 > *  Copyright (c) 1997-2014 ircd-hybrid development team
5   *
6   *  This program is free software; you can redistribute it and/or modify
7   *  it under the terms of the GNU General Public License as published by
# Line 18 | Line 17
17   *  along with this program; if not, write to the Free Software
18   *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307
19   *  USA
20 < *
21 < *  $Id$
20 > */
21 >
22 > /*! \file s_serv.c
23 > * \brief Server related functions.
24 > * \version $Id$
25   */
26  
27   #include "stdinc.h"
# Line 27 | Line 29
29   #include <openssl/rsa.h>
30   #include "rsa.h"
31   #endif
32 < #include "tools.h"
32 > #include "list.h"
33   #include "channel.h"
34   #include "channel_mode.h"
35   #include "client.h"
34 #include "common.h"
35 #include "dbuf.h"
36   #include "event.h"
37   #include "fdlist.h"
38   #include "hash.h"
39   #include "irc_string.h"
40 #include "inet_misc.h"
41 #include "sprintf_irc.h"
40   #include "ircd.h"
41   #include "ircd_defs.h"
42   #include "s_bsd.h"
45 #include "irc_getnameinfo.h"
46 #include "list.h"
43   #include "numeric.h"
44   #include "packet.h"
45   #include "irc_res.h"
46 < #include "s_conf.h"
46 > #include "conf.h"
47   #include "s_serv.h"
48 < #include "s_log.h"
49 < #include "s_stats.h"
48 > #include "log.h"
49 > #include "s_misc.h"
50   #include "s_user.h"
51   #include "send.h"
52   #include "memory.h"
53 < #include "channel.h" /* chcap_usage_counts stuff...*/
53 > #include "channel.h"
54 > #include "parse.h"
55  
56   #define MIN_CONN_FREQ 300
57  
58 + dlink_list flatten_links;
59   static dlink_list cap_list = { NULL, NULL, 0 };
60   static void server_burst(struct Client *);
63 static int fork_server(struct Client *);
61   static void burst_all(struct Client *);
62   static void send_tb(struct Client *client_p, struct Channel *chptr);
63  
64   static CNCB serv_connect_callback;
65  
69 static void start_io(struct Client *);
66   static void burst_members(struct Client *, struct Channel *);
67  
72 static SlinkRplHnd slink_error;
73 static SlinkRplHnd slink_zipstats;
74
75
76 #ifdef HAVE_LIBCRYPTO
77 struct EncCapability CipherTable[] =
78 {
79 #ifdef HAVE_EVP_BF_CFB
80  { "BF/168",     CAP_ENC_BF_168,     24, CIPHER_BF     },
81  { "BF/128",     CAP_ENC_BF_128,     16, CIPHER_BF     },
82 #endif
83 #ifdef HAVE_EVP_CAST5_CFB
84  { "CAST/128",   CAP_ENC_CAST_128,   16, CIPHER_CAST   },
85 #endif
86 #ifdef HAVE_EVP_IDEA_CFB
87  { "IDEA/128",   CAP_ENC_IDEA_128,   16, CIPHER_IDEA   },
88 #endif
89 #ifdef HAVE_EVP_RC5_32_12_16_CFB
90  { "RC5.16/128", CAP_ENC_RC5_16_128, 16, CIPHER_RC5_16 },
91  { "RC5.12/128", CAP_ENC_RC5_12_128, 16, CIPHER_RC5_12 },
92  { "RC5.8/128",  CAP_ENC_RC5_8_128,  16, CIPHER_RC5_8  },
93 #endif
94 #ifdef HAVE_EVP_DES_EDE3_CFB
95  { "3DES/168",   CAP_ENC_3DES_168,   24, CIPHER_3DES   },
96 #endif
97 #ifdef HAVE_EVP_DES_CFB
98  { "DES/56",     CAP_ENC_DES_56,      8, CIPHER_DES    },
99 #endif
100  { 0,            0,                   0, 0             }
101 };
102 #endif
103
104 struct SlinkRplDef slinkrpltab[] = {
105  { SLINKRPL_ERROR,    slink_error,    SLINKRPL_FLAG_DATA },
106  { SLINKRPL_ZIPSTATS, slink_zipstats, SLINKRPL_FLAG_DATA },
107  { 0,                 0,              0 },
108 };
109
110
111 void
112 slink_error(unsigned int rpl, unsigned int len, unsigned char *data,
113            struct Client *server_p)
114 {
115  assert(rpl == SLINKRPL_ERROR);
116  assert(len < 256);
117
118  data[len-1] = '\0';
119
120  sendto_realops_flags(UMODE_ALL, L_ALL, "SlinkError for %s: %s",
121                       server_p->name, data);
122  /* XXX should this be exit_client? */
123  exit_client(server_p, &me, "servlink error -- terminating link");
124 }
125
126 void
127 slink_zipstats(unsigned int rpl, unsigned int len, unsigned char *data,
128               struct Client *server_p)
129 {
130  struct ZipStats zipstats;
131  unsigned long in = 0, in_wire = 0, out = 0, out_wire = 0;
132  int i = 0;
133
134  assert(rpl == SLINKRPL_ZIPSTATS);
135  assert(len == 16);
136  assert(IsCapable(server_p, CAP_ZIP));
137
138  /* Yes, it needs to be done this way, no we cannot let the compiler
139   * work with the pointer to the structure.  This works around a GCC
140   * bug on SPARC that affects all versions at the time of this writing.
141   * I will feed you to the creatures living in RMS's beard if you do
142   * not leave this as is, without being sure that you are not causing
143   * regression for most of our installed SPARC base.
144   * -jmallett, 04/27/2002
145   */
146  memcpy(&zipstats, &server_p->localClient->zipstats, sizeof(struct ZipStats));
147
148  in |= (data[i++] << 24);
149  in |= (data[i++] << 16);
150  in |= (data[i++] <<  8);
151  in |= (data[i++]      );
152
153  in_wire |= (data[i++] << 24);
154  in_wire |= (data[i++] << 16);
155  in_wire |= (data[i++] <<  8);
156  in_wire |= (data[i++]      );
157
158  out |= (data[i++] << 24);
159  out |= (data[i++] << 16);
160  out |= (data[i++] <<  8);
161  out |= (data[i++]      );
162
163  out_wire |= (data[i++] << 24);
164  out_wire |= (data[i++] << 16);
165  out_wire |= (data[i++] <<  8);
166  out_wire |= (data[i++]      );
167
168  /* This macro adds b to a if a plus b is not an overflow, and sets the
169   * value of a to b if it is.
170   * Add and Set if No Overflow.
171   */
172 #define ASNO(a, b) a = (a + b >= a ? a + b : b)
173
174  ASNO(zipstats.in, in);
175  ASNO(zipstats.out, out);
176  ASNO(zipstats.in_wire, in_wire);
177  ASNO(zipstats.out_wire, out_wire);
178
179  if (zipstats.in > 0)
180    zipstats.in_ratio = (((double)(zipstats.in - zipstats.in_wire) /
181                         (double)zipstats.in) * 100.00);
182  else
183    zipstats.in_ratio = 0;
184
185  if (zipstats.out > 0)
186    zipstats.out_ratio = (((double)(zipstats.out - zipstats.out_wire) /
187                          (double)zipstats.out) * 100.00);
188  else
189    zipstats.out_ratio = 0;
190
191  memcpy(&server_p->localClient->zipstats, &zipstats, sizeof (struct ZipStats));
192 }
193
194 void
195 collect_zipstats(void *unused)
196 {
197  dlink_node *ptr;
198  struct Client *target_p;
199
200  DLINK_FOREACH(ptr, serv_list.head)
201  {
202    target_p = ptr->data;
203
204    if (IsCapable(target_p, CAP_ZIP))
205    {
206      /* only bother if we haven't already got something queued... */
207      if (!target_p->localClient->slinkq)
208      {
209        target_p->localClient->slinkq     = MyMalloc(1); /* sigh.. */
210        target_p->localClient->slinkq[0]  = SLINKCMD_ZIPSTATS;
211        target_p->localClient->slinkq_ofs = 0;
212        target_p->localClient->slinkq_len = 1;
213        send_queued_slink_write(target_p);
214      }
215    }
216  }
217 }
218
219 #ifdef HAVE_LIBCRYPTO
220 struct EncCapability *
221 check_cipher(struct Client *client_p, struct AccessItem *aconf)
222 {
223  struct EncCapability *epref = NULL;
224
225  /* Use connect{} specific info if available */
226  if (aconf->cipher_preference)
227    epref = aconf->cipher_preference;
228  else if (ConfigFileEntry.default_cipher_preference)
229    epref = ConfigFileEntry.default_cipher_preference;
230
231  /*
232   * If the server supports the capability in hand, return the matching
233   * conf struct.  Otherwise, return NULL (an error).
234   */
235  if (epref && IsCapableEnc(client_p, epref->cap))
236    return epref;
237
238  return NULL;
239 }
240 #endif /* HAVE_LIBCRYPTO */
241
242 /* my_name_for_link()
243 * return wildcard name of my server name
244 * according to given config entry --Jto
245 */
246 const char *
247 my_name_for_link(struct ConfItem *conf)
248 {
249  struct AccessItem *aconf;
250
251  aconf = (struct AccessItem *)map_to_conf(conf);
252  if (aconf->fakename != NULL)
253    return aconf->fakename;
254  else
255    return me.name;
256 }
257
68   /*
69   * write_links_file
70   *
# Line 264 | Line 74 | my_name_for_link(struct ConfItem *conf)
74   *                but in no particular order.
75   */
76   void
77 < write_links_file(void* notused)
77 > write_links_file(void *notused)
78   {
79 <  MessageFileLine *next_mptr = 0;
80 <  MessageFileLine *mptr = 0;
81 <  MessageFileLine *currentMessageLine = 0;
272 <  MessageFileLine *newMessageLine = 0;
273 <  MessageFile *MessageFileptr;
274 <  const char *p;
275 <  FBFILE *file;
276 <  char buff[512];
277 <  dlink_node *ptr;
79 >  FILE *file = NULL;
80 >  dlink_node *ptr = NULL, *ptr_next = NULL;
81 >  char buff[IRCD_BUFSIZE] = "";
82  
83 <  MessageFileptr = &ConfigFileEntry.linksfile;
280 <
281 <  if ((file = fbopen(MessageFileptr->fileName, "w")) == NULL)
83 >  if ((file = fopen(LIPATH, "w")) == NULL)
84      return;
85  
86 <  for (mptr = MessageFileptr->contentsOfFile; mptr; mptr = next_mptr)
86 >  DLINK_FOREACH_SAFE(ptr, ptr_next, flatten_links.head)
87    {
88 <    next_mptr = mptr->next;
89 <    MyFree(mptr);
88 >    dlinkDelete(ptr, &flatten_links);
89 >    MyFree(ptr->data);
90 >    free_dlink_node(ptr);
91    }
92  
290  MessageFileptr->contentsOfFile = NULL;
291  currentMessageLine             = NULL;
292
93    DLINK_FOREACH(ptr, global_serv_list.head)
94    {
95 <    size_t nbytes = 0;
296 <    struct Client *target_p = ptr->data;
95 >    const struct Client *target_p = ptr->data;
96  
97 <    /* skip ourselves, we send ourselves in /links */
98 <    if (IsMe(target_p))
97 >    /*
98 >     * Skip hidden servers, aswell as ourselves, since we already send
99 >     * ourselves in /links
100 >     */
101 >    if (IsHidden(target_p) || IsMe(target_p))
102        continue;
103  
104 <    /* skip hidden servers */
303 <    if (IsHidden(target_p) && !ConfigServerHide.disable_hidden)
104 >    if (HasFlag(target_p, FLAGS_SERVICE) && ConfigServerHide.hide_services)
105        continue;
106  
107 <    if (target_p->info[0])
108 <      p = target_p->info;
308 <    else
309 <      p = "(Unknown Location)";
310 <
311 <    newMessageLine = MyMalloc(sizeof(MessageFileLine));
312 <
313 <    /* Attempt to format the file in such a way it follows the usual links output
107 >    /*
108 >     * Attempt to format the file in such a way it follows the usual links output
109       * ie  "servername uplink :hops info"
110       * Mostly for aesthetic reasons - makes it look pretty in mIRC ;)
111       * - madmax
112       */
113 +    snprintf(buff, sizeof(buff), "%s %s :1 %s",   target_p->name,
114 +             me.name, target_p->info);
115 +    dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
116 +    snprintf(buff, sizeof(buff), "%s %s :1 %s\n", target_p->name,
117 +             me.name, target_p->info);
118  
119 <    /*
120 <     * For now, check this ircsprintf wont overflow - it shouldnt on a
321 <     * default config but it is configurable..
322 <     * This should be changed to an snprintf at some point, but I'm wanting to
323 <     * know if this is a cause of a bug - cryogen
324 <     */
325 <    assert(strlen(target_p->name) + strlen(me.name) + 6 + strlen(p) <=
326 <            MESSAGELINELEN);
327 <    ircsprintf(newMessageLine->line, "%s %s :1 %s",
328 <               target_p->name, me.name, p);
329 <    newMessageLine->next = NULL;
119 >    fputs(buff, file);
120 >  }
121  
122 <    if (MessageFileptr->contentsOfFile)
123 <    {
124 <      if (currentMessageLine)
125 <        currentMessageLine->next = newMessageLine;
126 <      currentMessageLine = newMessageLine;
127 <    }
128 <    else
129 <    {
130 <      MessageFileptr->contentsOfFile = newMessageLine;
131 <      currentMessageLine = newMessageLine;
132 <    }
122 >  fclose(file);
123 > }
124 >
125 > void
126 > read_links_file(void)
127 > {
128 >  FILE *file = NULL;
129 >  char *p = NULL;
130 >  char buff[IRCD_BUFSIZE] = "";
131 >
132 >  if ((file = fopen(LIPATH, "r")) == NULL)
133 >    return;
134  
135 <    nbytes = ircsprintf(buff, "%s %s :1 %s\n", target_p->name, me.name, p);
136 <    fbputs(buff, file, nbytes);
135 >  while (fgets(buff, sizeof(buff), file))
136 >  {
137 >    if ((p = strchr(buff, '\n')) != NULL)
138 >      *p = '\0';
139 >
140 >    dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
141    }
142  
143 <  fbclose(file);
143 >  fclose(file);
144   }
145  
146   /* hunt_server()
# Line 367 | Line 163 | write_links_file(void* notused)
163   *      returns: (see #defines)
164   */
165   int
166 < hunt_server(struct Client *client_p, struct Client *source_p, const char *command,
167 <            int server, int parc, char *parv[])
166 > hunt_server(struct Client *source_p, const char *command,
167 >            const int server, const int parc, char *parv[])
168   {
169    struct Client *target_p = NULL;
170    struct Client *target_tmp = NULL;
171    dlink_node *ptr;
172    int wilds;
173  
174 <  /* Assume it's me, if no server
175 <   */
176 <  if (parc <= server || EmptyString(parv[server]) ||
177 <      match(me.name, parv[server]) ||
178 <      match(parv[server], me.name) ||
179 <      !strcmp(parv[server], me.id))
384 <    return(HUNTED_ISME);
174 >  /* Assume it's me, if no server */
175 >  if (parc <= server || EmptyString(parv[server]))
176 >    return HUNTED_ISME;
177 >
178 >  if (!strcmp(parv[server], me.id) || !match(parv[server], me.name))
179 >    return HUNTED_ISME;
180  
181    /* These are to pickup matches that would cause the following
182     * message to go in the wrong direction while doing quick fast
183     * non-matching lookups.
184     */
185    if (MyClient(source_p))
186 <    target_p = find_client(parv[server]);
186 >    target_p = hash_find_client(parv[server]);
187    else
188 <    target_p = find_person(client_p, parv[server]);
188 >    target_p = find_person(source_p, parv[server]);
189  
190    if (target_p)
191      if (target_p->from == source_p->from && !MyConnect(target_p))
192        target_p = NULL;
193  
194 <  if (target_p == NULL && (target_p = find_server(parv[server])))
194 >  if (target_p == NULL && (target_p = hash_find_server(parv[server])))
195      if (target_p->from == source_p->from && !MyConnect(target_p))
196        target_p = NULL;
197  
198 <  collapse(parv[server]);
404 <  wilds = (strchr(parv[server], '?') || strchr(parv[server], '*'));
198 >  wilds = has_wildcards(parv[server]);
199  
200    /* Again, if there are no wild cards involved in the server
201     * name, use the hash lookup
# Line 410 | Line 204 | hunt_server(struct Client *client_p, str
204    {
205      if (!wilds)
206      {
207 <      if (!(target_p = find_server(parv[server])))
207 >      if (!(target_p = hash_find_server(parv[server])))
208        {
209 <        sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
210 <                   me.name, parv[0], parv[server]);
417 <        return(HUNTED_NOSUCH);
209 >        sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
210 >        return HUNTED_NOSUCH;
211        }
212      }
213      else
# Line 423 | Line 216 | hunt_server(struct Client *client_p, str
216        {
217          target_tmp = ptr->data;
218  
219 <        if (match(parv[server], target_tmp->name))
219 >        if (!match(parv[server], target_tmp->name))
220          {
221            if (target_tmp->from == source_p->from && !MyConnect(target_tmp))
222              continue;
223            target_p = ptr->data;
224  
225 <          if (IsRegistered(target_p) && (target_p != client_p))
225 >          if (IsRegistered(target_p) && (target_p != source_p->from))
226              break;
227          }
228        }
# Line 440 | Line 233 | hunt_server(struct Client *client_p, str
233    {
234      if(!IsRegistered(target_p))
235      {
236 <      sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
444 <                 me.name, parv[0], parv[server]);
236 >      sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
237        return HUNTED_NOSUCH;
238      }
239  
240      if (IsMe(target_p) || MyClient(target_p))
241        return HUNTED_ISME;
242  
243 <    if (!match(target_p->name, parv[server]))
243 >    if (match(target_p->name, parv[server]))
244        parv[server] = target_p->name;
245  
246      /* This is a little kludgy but should work... */
247 <    if (IsClient(source_p) &&
456 <        ((MyConnect(target_p) && IsCapable(target_p, CAP_TS6)) ||
457 <         (!MyConnect(target_p) && IsCapable(target_p->from, CAP_TS6))))
458 <      parv[0] = ID(source_p);
459 <
460 <    sendto_one(target_p, command, parv[0],
247 >    sendto_one(target_p, command, ID_or_name(source_p, target_p),
248                 parv[1], parv[2], parv[3], parv[4],
249                 parv[5], parv[6], parv[7], parv[8]);
250 <    return(HUNTED_PASS);
251 <  }
250 >    return HUNTED_PASS;
251 >  }
252  
253 <  sendto_one(source_p, form_str(ERR_NOSUCHSERVER),
254 <             me.name, parv[0], parv[server]);
468 <  return(HUNTED_NOSUCH);
253 >  sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
254 >  return HUNTED_NOSUCH;
255   }
256  
257   /* try_connections()
# Line 481 | Line 267 | hunt_server(struct Client *client_p, str
267   void
268   try_connections(void *unused)
269   {
270 <  dlink_node *ptr;
271 <  struct ConfItem *conf;
486 <  struct AccessItem *aconf;
487 <  struct ClassItem *cltmp;
270 >  dlink_node *ptr = NULL;
271 >  struct MaskItem *conf;
272    int confrq;
273  
274    /* TODO: change this to set active flag to 0 when added to event! --Habeeb */
# Line 494 | Line 278 | try_connections(void *unused)
278    DLINK_FOREACH(ptr, server_items.head)
279    {
280      conf = ptr->data;
497    aconf = (struct AccessItem *)map_to_conf(conf);
281  
282 <    /* Also when already connecting! (update holdtimes) --SRB
282 >    assert(conf->type == CONF_SERVER);
283 >
284 >    /* Also when already connecting! (update holdtimes) --SRB
285       */
286 <    if (!(aconf->status & CONF_SERVER) || aconf->port <= 0 ||
502 <        !(IsConfAllowAutoConn(aconf)))
286 >    if (!conf->port ||!IsConfAllowAutoConn(conf))
287        continue;
288  
505    cltmp = (struct ClassItem *)map_to_conf(aconf->class_ptr);
289  
290      /* Skip this entry if the use of it is still on hold until
291       * future. Otherwise handle this entry (and set it on hold
# Line 510 | Line 293 | try_connections(void *unused)
293       * made one successfull connection... [this algorithm is
294       * a bit fuzzy... -- msa >;) ]
295       */
296 <    if (aconf->hold > CurrentTime)
296 >    if (conf->until > CurrentTime)
297        continue;
298  
299 <    if (cltmp == NULL)
299 >    if (conf->class == NULL)
300        confrq = DEFAULT_CONNECTFREQUENCY;
301      else
302      {
303 <      confrq = ConFreq(cltmp);
304 <      if (confrq < MIN_CONN_FREQ )
305 <        confrq = MIN_CONN_FREQ;
303 >      confrq = conf->class->con_freq;
304 >      if (confrq < MIN_CONN_FREQ)
305 >        confrq = MIN_CONN_FREQ;
306      }
307  
308 <    aconf->hold = CurrentTime + confrq;
308 >    conf->until = CurrentTime + confrq;
309  
310      /* Found a CONNECT config with port specified, scan clients
311       * and see if this server is already connected?
312       */
313 <    if (find_server(conf->name) != NULL)
313 >    if (hash_find_server(conf->name) != NULL)
314        continue;
315  
316 <    if (CurrUserCount(cltmp) < MaxTotal(cltmp))
316 >    if (conf->class->ref_count < conf->class->max_total)
317      {
318        /* Go to the end of the list, if not already last */
319        if (ptr->next != NULL)
# Line 551 | Line 334 | try_connections(void *unused)
334         *   -- adrian
335         */
336        if (ConfigServerHide.hide_server_ips)
337 <        sendto_realops_flags(UMODE_ALL, L_ALL, "Connection to %s activated.",
337 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
338 >                             "Connection to %s activated.",
339                               conf->name);
340        else
341 <        sendto_realops_flags(UMODE_ALL, L_ALL, "Connection to %s[%s] activated.",
342 <                             conf->name, aconf->host);
341 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
342 >                             "Connection to %s[%s] activated.",
343 >                             conf->name, conf->host);
344  
345 <      serv_connect(aconf, NULL);
345 >      serv_connect(conf, NULL);
346        /* We connect only one at time... */
347        return;
348      }
# Line 565 | Line 350 | try_connections(void *unused)
350   }
351  
352   int
353 < check_server(const char *name, struct Client *client_p, int cryptlink)
353 > valid_servname(const char *name)
354 > {
355 >  unsigned int length = 0;
356 >  unsigned int dots   = 0;
357 >  const char *p = name;
358 >
359 >  for (; *p; ++p)
360 >  {
361 >    if (!IsServChar(*p))
362 >      return 0;
363 >
364 >    ++length;
365 >
366 >    if (*p == '.')
367 >      ++dots;
368 >  }
369 >
370 >  return dots != 0 && length <= HOSTLEN;
371 > }
372 >
373 > int
374 > check_server(const char *name, struct Client *client_p)
375   {
376    dlink_node *ptr;
377 <  struct ConfItem *conf           = NULL;
378 <  struct ConfItem *server_conf    = NULL;
573 <  struct AccessItem *server_aconf = NULL;
574 <  struct AccessItem *aconf        = NULL;
377 >  struct MaskItem *conf        = NULL;
378 >  struct MaskItem *server_conf = NULL;
379    int error = -1;
380  
381    assert(client_p != NULL);
382  
579  if (client_p == NULL)
580    return(error);
581
582  if (strlen(name) > HOSTLEN)
583    return(-4);
584
383    /* loop through looking for all possible connect items that might work */
384    DLINK_FOREACH(ptr, server_items.head)
385    {
386      conf = ptr->data;
589    aconf = (struct AccessItem *)map_to_conf(conf);
387  
388 <    if (!match(name, conf->name))
388 >    if (match(name, conf->name))
389        continue;
390  
391      error = -3;
392  
393      /* XXX: Fix me for IPv6                    */
394      /* XXX sockhost is the IPv4 ip as a string */
395 <    if (match(aconf->host, client_p->host) ||
396 <        match(aconf->host, client_p->sockhost))
395 >    if (!match(conf->host, client_p->host) ||
396 >        !match(conf->host, client_p->sockhost))
397      {
398        error = -2;
602 #ifdef HAVE_LIBCRYPTO
603      if (cryptlink && IsConfCryptLink(aconf))
604      {
605        if (aconf->rsa_public_key)
606          server_conf = conf;
607      }
608      else if (!(cryptlink || IsConfCryptLink(aconf)))
609 #endif /* HAVE_LIBCRYPTO */
610      {
611        /* A NULL password is as good as a bad one */
612        if (EmptyString(client_p->localClient->passwd))
613          return(-2);
614
615        /* code in s_conf.c should not have allowed this to be NULL */
616        if (aconf->passwd == NULL)
617          return(-2);
399  
400 <        if (IsConfEncrypted(aconf))
401 <        {
402 <          if (strcmp(aconf->passwd,
403 <              (const char *)crypt(client_p->localClient->passwd,
404 <                                  aconf->passwd)) == 0)
405 <            server_conf = conf;
406 <        }
407 <        else
627 <        {
628 <          if (strcmp(aconf->passwd, client_p->localClient->passwd) == 0)
629 <            server_conf = conf;
630 <        }
631 <      }
400 >      if (!match_conf_password(client_p->localClient->passwd, conf))
401 >        return -2;
402 >
403 >      if (!EmptyString(conf->certfp))
404 >        if (EmptyString(client_p->certfp) || strcasecmp(client_p->certfp, conf->certfp))
405 >          return -4;
406 >
407 >      server_conf = conf;
408      }
409    }
410  
411    if (server_conf == NULL)
412 <    return(error);
412 >    return error;
413  
414    attach_conf(client_p, server_conf);
415  
640  /* Now find all leaf or hub config items for this server */
641  DLINK_FOREACH(ptr, hub_items.head)
642  {
643    conf = ptr->data;
644
645    if (!match(name, conf->name))
646      continue;
647    attach_conf(client_p, conf);
648  }
649
650  DLINK_FOREACH(ptr, leaf_items.head)
651  {
652    conf = ptr->data;
653
654    if (!match(name, conf->name))
655      continue;
656    attach_conf(client_p, conf);
657  }
658
659  server_aconf = map_to_conf(server_conf);
416  
417 < #ifdef HAVE_LIBZ /* otherwise, clear it unconditionally */
662 <  if (!IsConfCompressed(server_aconf))
663 < #endif
664 <    ClearCap(client_p, CAP_ZIP);
665 <  if (!IsConfCryptLink(server_aconf))
666 <    ClearCap(client_p, CAP_ENC);
667 <  if (!IsConfTopicBurst(server_aconf))
668 <  {
669 <    ClearCap(client_p, CAP_TB);
670 <    ClearCap(client_p, CAP_TBURST);
671 <  }
672 <
673 <  /* Don't unset CAP_HUB here even if the server isn't a hub,
674 <   * it only indicates if the server thinks it's lazylinks are
675 <   * leafs or not.. if you unset it, bad things will happen
676 <   */
677 <  if (aconf != NULL)
417 >  if (server_conf != NULL)
418    {
419      struct sockaddr_in *v4;
420   #ifdef IPV6
421      struct sockaddr_in6 *v6;
422   #endif
423 <    switch (aconf->aftype)
423 >    switch (server_conf->aftype)
424      {
425   #ifdef IPV6
426 <      case AF_INET6:
427 <        v6 = (struct sockaddr_in6 *)&aconf->ipnum;
426 >      case AF_INET6:
427 >        v6 = (struct sockaddr_in6 *)&server_conf->addr;
428  
429          if (IN6_IS_ADDR_UNSPECIFIED(&v6->sin6_addr))
430 <          memcpy(&aconf->ipnum, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
430 >          memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
431          break;
432   #endif
433        case AF_INET:
434 <        v4 = (struct sockaddr_in *)&aconf->ipnum;
434 >        v4 = (struct sockaddr_in *)&server_conf->addr;
435  
436          if (v4->sin_addr.s_addr == INADDR_NONE)
437 <          memcpy(&aconf->ipnum, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
437 >          memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
438          break;
439      }
440    }
441  
442 <  return(0);
442 >  return 0;
443   }
444  
445   /* add_capability()
# Line 716 | Line 456 | add_capability(const char *capab_name, i
456   {
457    struct Capability *cap = MyMalloc(sizeof(*cap));
458  
459 <  DupString(cap->name, capab_name);
459 >  cap->name = xstrdup(capab_name);
460    cap->cap = cap_flag;
461    dlinkAdd(cap, &cap->node, &cap_list);
462  
# Line 745 | Line 485 | delete_capability(const char *capab_name
485      {
486        if (irccmp(cap->name, capab_name) == 0)
487        {
488 <        default_server_capabs &= ~(cap->cap);
489 <        dlinkDelete(ptr, &cap_list);
490 <        MyFree(cap->name);
491 <        cap->name = NULL;
752 <        MyFree(cap);
488 >        default_server_capabs &= ~(cap->cap);
489 >        dlinkDelete(ptr, &cap_list);
490 >        MyFree(cap->name);
491 >        MyFree(cap);
492        }
493      }
494    }
495  
496 <  return(0);
496 >  return 0;
497   }
498  
499   /*
# Line 764 | Line 503 | delete_capability(const char *capab_name
503   * output       - 0 if not found CAPAB otherwise
504   * side effects - none
505   */
506 < int
506 > unsigned int
507   find_capability(const char *capab)
508   {
509 <  dlink_node *ptr;
771 <  struct Capability *cap;
509 >  const dlink_node *ptr = NULL;
510  
511    DLINK_FOREACH(ptr, cap_list.head)
512    {
513 <    cap = ptr->data;
513 >    const struct Capability *cap = ptr->data;
514  
515 <    if (cap->cap != 0)
516 <    {
779 <      if (irccmp(cap->name, capab) == 0)
780 <        return(cap->cap);
781 <    }
515 >    if (cap->cap && !irccmp(cap->name, capab))
516 >      return cap->cap;
517    }
518 <  return(0);
518 >
519 >  return 0;
520   }
521  
522   /* send_capabilities()
523   *
524   * inputs       - Client pointer to send to
789 *              - Pointer to AccessItem (for crypt)
525   *              - int flag of capabilities that this server can send
791 *              - int flag of encryption capabilities
526   * output       - NONE
527   * side effects - send the CAPAB line to a server  -orabidoo
528   *
529   */
530   void
531 < send_capabilities(struct Client *client_p, struct AccessItem *aconf,
798 <                  int cap_can_send, int enc_can_send)
531 > send_capabilities(struct Client *client_p, int cap_can_send)
532   {
533    struct Capability *cap=NULL;
534    char msgbuf[IRCD_BUFSIZE];
535    char *t;
536    int tl;
537    dlink_node *ptr;
805 #ifdef HAVE_LIBCRYPTO
806  const struct EncCapability *epref = NULL;
807  char *capend;
808  int sent_cipher = 0;
809 #endif
538  
539    t = msgbuf;
540  
# Line 816 | Line 544 | send_capabilities(struct Client *client_
544  
545      if (cap->cap & (cap_can_send|default_server_capabs))
546      {
547 <      tl = ircsprintf(t, "%s ", cap->name);
547 >      tl = sprintf(t, "%s ", cap->name);
548        t += tl;
549      }
550    }
823 #ifdef HAVE_LIBCRYPTO
824  if (enc_can_send)
825  {
826    capend = t;
827    strcpy(t, "ENC:");
828    t += 4;
829
830    /* use connect{} specific info if available */
831    if (aconf->cipher_preference)
832      epref = aconf->cipher_preference;
833    else if (ConfigFileEntry.default_cipher_preference)
834      epref = ConfigFileEntry.default_cipher_preference;
551  
836    if (epref && (epref->cap & enc_can_send))
837    {
838      /* Leave the space -- it is removed later. */
839      tl = ircsprintf(t, "%s ", epref->name);
840      t += tl;
841      sent_cipher = 1;
842    }
843
844    if (!sent_cipher)
845      t = capend; /* truncate string before ENC:, below */
846  }
847 #endif
552    *(t - 1) = '\0';
553    sendto_one(client_p, "CAPAB :%s", msgbuf);
554   }
555  
556   /* sendnick_TS()
557 < *
557 > *
558   * inputs       - client (server) to send nick towards
559   *          - client to send nick for
560   * output       - NONE
# Line 859 | Line 563 | send_capabilities(struct Client *client_
563   void
564   sendnick_TS(struct Client *client_p, struct Client *target_p)
565   {
566 <  static char ubuf[12];
566 >  char ubuf[IRCD_BUFSIZE];
567  
568    if (!IsClient(target_p))
569      return;
570  
571 <  send_umode(NULL, target_p, 0, IsOperHiddenAdmin(target_p) ?
868 <    SEND_UMODES & ~UMODE_ADMIN : SEND_UMODES, ubuf);
571 >  send_umode(NULL, target_p, 0, SEND_UMODES, ubuf);
572  
573    if (ubuf[0] == '\0')
574    {
# Line 873 | Line 576 | sendnick_TS(struct Client *client_p, str
576      ubuf[1] = '\0';
577    }
578  
579 <  /* XXX Both of these need to have a :me.name or :mySID!?!?! */
580 <  if (HasID(target_p) && IsCapable(client_p, CAP_TS6))
579 >  if (IsCapable(client_p, CAP_SVS))
580 >    sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s %s :%s",
581 >               target_p->servptr->id,
582 >               target_p->name, target_p->hopcount + 1,
583 >               (unsigned long) target_p->tsinfo,
584 >               ubuf, target_p->username, target_p->host,
585 >               (MyClient(target_p) && IsIPSpoof(target_p)) ?
586 >               "0" : target_p->sockhost, target_p->id,
587 >               target_p->svid, target_p->info);
588 >  else
589      sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s :%s",
590                 target_p->servptr->id,
591                 target_p->name, target_p->hopcount + 1,
# Line 882 | Line 593 | sendnick_TS(struct Client *client_p, str
593                 ubuf, target_p->username, target_p->host,
594                 (MyClient(target_p) && IsIPSpoof(target_p)) ?
595                 "0" : target_p->sockhost, target_p->id, target_p->info);
596 <  else
597 <    sendto_one(client_p, "NICK %s %d %lu %s %s %s %s :%s",
598 <               target_p->name, target_p->hopcount + 1,
599 <               (unsigned long) target_p->tsinfo,
600 <               ubuf, target_p->username, target_p->host,
601 <               target_p->servptr->name, target_p->info);
891 <
892 <  if (IsConfAwayBurst((struct AccessItem *)map_to_conf(client_p->serv->sconf)))
893 <    if (!EmptyString(target_p->away))
894 <      sendto_one(client_p, ":%s AWAY :%s", target_p->name,
895 <                 target_p->away);
596 >
597 >  if (!EmptyString(target_p->certfp))
598 >    sendto_one(client_p, ":%s CERTFP %s", target_p->id, target_p->certfp);
599 >
600 >  if (target_p->away[0])
601 >    sendto_one(client_p, ":%s AWAY :%s", target_p->id, target_p->away);
602  
603   }
604  
# Line 904 | Line 610 | sendnick_TS(struct Client *client_p, str
610   * side effects - build up string representing capabilities of server listed
611   */
612   const char *
613 < show_capabilities(struct Client *target_p)
613 > show_capabilities(const struct Client *target_p)
614   {
615 <  static char msgbuf[IRCD_BUFSIZE];
616 <  char *t = msgbuf;
911 <  dlink_node *ptr;
615 >  static char msgbuf[IRCD_BUFSIZE] = "";
616 >  const dlink_node *ptr = NULL;
617  
618 <  t += ircsprintf(msgbuf, "TS ");
618 >  strlcpy(msgbuf, "TS", sizeof(msgbuf));
619  
620    DLINK_FOREACH(ptr, cap_list.head)
621    {
622      const struct Capability *cap = ptr->data;
623  
624 <    if (IsCapable(target_p, cap->cap))
625 <      t += ircsprintf(t, "%s ", cap->name);
624 >    if (!IsCapable(target_p, cap->cap))
625 >      continue;
626 >
627 >    strlcat(msgbuf,       " ", sizeof(msgbuf));
628 >    strlcat(msgbuf, cap->name, sizeof(msgbuf));
629    }
922 #ifdef HAVE_LIBCRYPTO
923  if (IsCapable(target_p, CAP_ENC) &&
924      target_p->localClient->in_cipher &&
925      target_p->localClient->out_cipher)
926    t += ircsprintf(t, "ENC:%s ",
927                    target_p->localClient->in_cipher->name);
928 #endif
929  *(t - 1) = '\0';
630  
631 <  return(msgbuf);
631 >  return msgbuf;
632   }
633  
634   /* make_server()
# Line 956 | Line 656 | make_server(struct Client *client_p)
656   void
657   server_estab(struct Client *client_p)
658   {
659 <  struct Client *target_p;
960 <  struct ConfItem *conf;
961 <  struct AccessItem *aconf=NULL;
659 >  struct MaskItem *conf = NULL;
660    char *host;
661    const char *inpath;
662    static char inpath_ip[HOSTLEN * 2 + USERLEN + 6];
965  dlink_node *m;
663    dlink_node *ptr;
664 + #ifdef HAVE_LIBCRYPTO
665 +  const COMP_METHOD *compression = NULL, *expansion = NULL;
666 + #endif
667  
668    assert(client_p != NULL);
669  
# Line 972 | Line 672 | server_estab(struct Client *client_p)
672    inpath = get_client_name(client_p, MASK_IP); /* "refresh" inpath with host */
673    host   = client_p->name;
674  
675 <  if ((conf = find_conf_name(&client_p->localClient->confs, host, SERVER_TYPE))
675 >  if ((conf = find_conf_name(&client_p->localClient->confs, host, CONF_SERVER))
676        == NULL)
677    {
678      /* This shouldn't happen, better tell the ops... -A1kmm */
679 <    sendto_realops_flags(UMODE_ALL, L_ALL, "Warning: Lost connect{} block "
679 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
680 >                         "Warning: Lost connect{} block "
681                           "for server %s(this shouldn't happen)!", host);
682 <    exit_client(client_p, &me, "Lost connect{} block!");
682 >    exit_client(client_p, "Lost connect{} block!");
683      return;
684    }
685  
# Line 991 | Line 692 | server_estab(struct Client *client_p)
692    /* If there is something in the serv_list, it might be this
693     * connecting server..
694     */
695 <  if (!ServerInfo.hub && serv_list.head)  
695 >  if (!ServerInfo.hub && serv_list.head)
696    {
697      if (client_p != serv_list.head->data || serv_list.head->next)
698      {
699 <      ServerStats->is_ref++;
699 >      ++ServerStats.is_ref;
700        sendto_one(client_p, "ERROR :I'm a leaf not a hub");
701 <      exit_client(client_p, &me, "I'm a leaf");
701 >      exit_client(client_p, "I'm a leaf");
702        return;
703      }
704    }
705  
706 <  aconf = (struct AccessItem *)map_to_conf(conf);
1006 <
1007 <  if (IsUnknown(client_p) && !IsConfCryptLink(aconf))
706 >  if (IsUnknown(client_p))
707    {
708 <    /* jdc -- 1.  Use EmptyString(), not [0] index reference.
1010 <     *        2.  Check aconf->spasswd, not aconf->passwd.
1011 <     */
1012 <    if (!EmptyString(aconf->spasswd))
1013 <    {
1014 <      /* only send ts6 format PASS if we have ts6 enabled */
1015 <    if (me.id[0] != '\0')               /* Send TS 6 form only if id */
1016 <        sendto_one(client_p, "PASS %s TS %d %s",
1017 <                   aconf->spasswd, TS_CURRENT, me.id);
1018 <      else
1019 <        sendto_one(client_p, "PASS %s TS 5",
1020 <                   aconf->spasswd);
1021 <    }
708 >    sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
709  
710 <    /* Pass my info to the new server
1024 <     *
1025 <     * If this is a HUB, pass on CAP_HUB
1026 <     * Pass on ZIP if supported
1027 <     * Pass on TB if supported.
1028 <     * - Dianora
1029 <     */
710 >    send_capabilities(client_p, 0);
711  
1031    send_capabilities(client_p, aconf, (ServerInfo.hub ? CAP_HUB : 0)
1032      | (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1033      | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), 0);
1034
1035    /* SERVER is the last command sent before switching to ziplinks.
1036     * We set TCPNODELAY on the socket to make sure it gets sent out
1037     * on the wire immediately.  Otherwise, it could be sitting in
1038     * a kernel buffer when we start sending zipped data, and the
1039     * parser on the receiving side can't hand both unzipped and zipped
1040     * data in one packet. --Rodder
1041     *
1042     * currently we only need to call send_queued_write,
1043     * Nagle is already disabled at this point --adx
1044     */
712      sendto_one(client_p, "SERVER %s 1 :%s%s",
713 <               my_name_for_link(conf),
1047 <               ConfigServerHide.hidden ? "(H) " : "",
1048 <               (me.info[0]) ? (me.info) : "IRCers United");
1049 <    send_queued_write(client_p);
713 >               me.name, ConfigServerHide.hidden ? "(H) " : "", me.info);
714    }
715  
716 <  /* Hand the server off to servlink now */
1053 <  if (IsCapable(client_p, CAP_ENC) || IsCapable(client_p, CAP_ZIP))
1054 <  {
1055 <    if (fork_server(client_p) < 0)
1056 <    {
1057 <      sendto_realops_flags(UMODE_ALL, L_ADMIN,
1058 <                           "Warning: fork failed for server %s -- check servlink_path (%s)",
1059 <                           get_client_name(client_p, HIDE_IP), ConfigFileEntry.servlink_path);
1060 <      sendto_realops_flags(UMODE_ALL, L_OPER, "Warning: fork failed for server "
1061 <                           "%s -- check servlink_path (%s)",
1062 <                           get_client_name(client_p, MASK_IP),
1063 <                           ConfigFileEntry.servlink_path);
1064 <      exit_client(client_p, &me, "fork failed");
1065 <      return;
1066 <    }
1067 <
1068 <    start_io(client_p);
1069 <    SetServlink(client_p);
1070 <  }
1071 <
1072 <  /* only send ts6 format SVINFO if we have ts6 enabled */
1073 <  sendto_one(client_p, "SVINFO %d %d 0 :%lu",
1074 <             (me.id[0] ? TS_CURRENT : 5), TS_MIN,
716 >  sendto_one(client_p, "SVINFO %d %d 0 :%lu", TS_CURRENT, TS_MIN,
717               (unsigned long)CurrentTime);
718  
1077  /* assumption here is if they passed the correct TS version, they also passed an SID */
1078  if (IsCapable(client_p, CAP_TS6))
1079    hash_add_id(client_p);
1080
719    /* XXX Does this ever happen? I don't think so -db */
720 <  detach_conf(client_p, OPER_TYPE);
720 >  detach_conf(client_p, CONF_OPER);
721  
722    /* *WARNING*
723    **    In the following code in place of plain server's
# Line 1099 | Line 737 | server_estab(struct Client *client_p)
737  
738    SetServer(client_p);
739  
1102  /* Update the capability combination usage counts. -A1kmm */
1103  set_chcap_usage_counts(client_p);
1104
740    /* Some day, all these lists will be consolidated *sigh* */
741    dlinkAdd(client_p, &client_p->lnode, &me.serv->server_list);
742  
743 <  m = dlinkFind(&unknown_list, client_p);
1109 <  assert(NULL != m);
743 >  assert(dlinkFind(&unknown_list, client_p));
744  
745 <  dlinkDelete(m, &unknown_list);
746 <  dlinkAdd(client_p, m, &serv_list);
745 >  dlink_move_node(&client_p->localClient->lclient_node,
746 >                  &unknown_list, &serv_list);
747  
748    Count.myserver++;
749  
750    dlinkAdd(client_p, make_dlink_node(), &global_serv_list);
751    hash_add_client(client_p);
752 +  hash_add_id(client_p);
753  
754    /* doesnt duplicate client_p->serv if allocated this struct already */
755    make_server(client_p);
756  
757    /* fixing eob timings.. -gnp */
758 <  client_p->firsttime = CurrentTime;
1124 <
1125 <  /* Show the real host/IP to admins */
1126 <  sendto_realops_flags(UMODE_ALL, L_ADMIN,
1127 <                       "Link with %s established: (%s) link",
1128 <                       inpath_ip,show_capabilities(client_p));
1129 <  /* Now show the masked hostname/IP to opers */
1130 <  sendto_realops_flags(UMODE_ALL, L_OPER,
1131 <                       "Link with %s established: (%s) link",
1132 <                       inpath,show_capabilities(client_p));
1133 <  ilog(L_NOTICE, "Link with %s established: (%s) link",
1134 <       inpath_ip, show_capabilities(client_p));
758 >  client_p->localClient->firsttime = CurrentTime;
759  
760 <  client_p->serv->sconf = conf;
760 >  if (find_matching_name_conf(CONF_SERVICE, client_p->name, NULL, NULL, 0))
761 >    AddFlag(client_p, FLAGS_SERVICE);
762  
763 <  if (HasServlink(client_p))
763 >  /* Show the real host/IP to admins */
764 > #ifdef HAVE_LIBCRYPTO
765 >  if (client_p->localClient->fd.ssl)
766    {
767 <    /* we won't overflow FD_DESC_SZ here, as it can hold
768 <     * client_p->name + 64
769 <     */
770 <    fd_note(&client_p->localClient->fd, "slink data: %s", client_p->name);
771 <    fd_note(&client_p->localClient->ctrlfd, "slink ctrl: %s", client_p->name);
767 >    compression = SSL_get_current_compression(client_p->localClient->fd.ssl);
768 >    expansion   = SSL_get_current_expansion(client_p->localClient->fd.ssl);
769 >
770 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
771 >                         "Link with %s established: [SSL: %s, Compression/Expansion method: %s/%s] (Capabilities: %s)",
772 >                         inpath_ip, ssl_get_cipher(client_p->localClient->fd.ssl),
773 >                         compression ? SSL_COMP_get_name(compression) : "NONE",
774 >                         expansion ? SSL_COMP_get_name(expansion) : "NONE",
775 >                         show_capabilities(client_p));
776 >    /* Now show the masked hostname/IP to opers */
777 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
778 >                         "Link with %s established: [SSL: %s, Compression/Expansion method: %s/%s] (Capabilities: %s)",
779 >                         inpath, ssl_get_cipher(client_p->localClient->fd.ssl),
780 >                         compression ? SSL_COMP_get_name(compression) : "NONE",
781 >                         expansion ? SSL_COMP_get_name(expansion) : "NONE",
782 >                         show_capabilities(client_p));
783 >    ilog(LOG_TYPE_IRCD, "Link with %s established: [SSL: %s, Compression/Expansion method: %s/%s] (Capabilities: %s)",
784 >         inpath_ip, ssl_get_cipher(client_p->localClient->fd.ssl),
785 >         compression ? SSL_COMP_get_name(compression) : "NONE",
786 >         expansion ? SSL_COMP_get_name(expansion) : "NONE",
787 >         show_capabilities(client_p));
788    }
789    else
790 <    fd_note(&client_p->localClient->fd, "Server: %s", client_p->name);
1148 <
1149 <  /* Old sendto_serv_but_one() call removed because we now
1150 <  ** need to send different names to different servers
1151 <  ** (domain name matching) Send new server to other servers.
1152 <  */
1153 <  DLINK_FOREACH(ptr, serv_list.head)
790 > #endif
791    {
792 <    target_p = ptr->data;
793 <
794 <    if (target_p == client_p)
795 <      continue;
792 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
793 >                         "Link with %s established: (Capabilities: %s)",
794 >                         inpath_ip, show_capabilities(client_p));
795 >    /* Now show the masked hostname/IP to opers */
796 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
797 >                         "Link with %s established: (Capabilities: %s)",
798 >                         inpath, show_capabilities(client_p));
799 >    ilog(LOG_TYPE_IRCD, "Link with %s established: (Capabilities: %s)",
800 >         inpath_ip, show_capabilities(client_p));
801 >  }
802 >
803 >  fd_note(&client_p->localClient->fd, "Server: %s", client_p->name);
804 >
805 >  sendto_server(client_p, NOCAPS, NOCAPS, ":%s SID %s 2 %s :%s%s",
806 >                me.id, client_p->name, client_p->id,
807 >                IsHidden(client_p) ? "(H) " : "", client_p->info);
808  
809 <    if ((conf = target_p->serv->sconf) &&
810 <         match(my_name_for_link(conf), client_p->name))
811 <      continue;
812 <
813 <    if (IsCapable(target_p, CAP_TS6) && HasID(client_p))
814 <      sendto_one(target_p, ":%s SID %s 2 %s :%s%s",
815 <                 me.id, client_p->name, client_p->id,
816 <                 IsHidden(client_p) ? "(H) " : "",
817 <                 client_p->info);
818 <    else
819 <      sendto_one(target_p,":%s SERVER %s 2 :%s%s",
820 <                 me.name, client_p->name,
821 <                 IsHidden(client_p) ? "(H) " : "",
822 <                 client_p->info);
823 <  }
824 <
825 <  /* Pass on my client information to the new server
826 <  **
1178 <  ** First, pass only servers (idea is that if the link gets
1179 <  ** cancelled beacause the server was already there,
1180 <  ** there are no NICK's to be cancelled...). Of course,
1181 <  ** if cancellation occurs, all this info is sent anyway,
1182 <  ** and I guess the link dies when a read is attempted...? --msa
1183 <  **
1184 <  ** Note: Link cancellation to occur at this point means
1185 <  ** that at least two servers from my fragment are building
1186 <  ** up connection this other fragment at the same time, it's
1187 <  ** a race condition, not the normal way of operation...
1188 <  **
1189 <  ** ALSO NOTE: using the get_client_name for server names--
1190 <  **    see previous *WARNING*!!! (Also, original inpath
1191 <  **    is destroyed...)
1192 <  */
1193 <
1194 <  conf = client_p->serv->sconf;
809 >  /*
810 >   * Pass on my client information to the new server
811 >   *
812 >   * First, pass only servers (idea is that if the link gets
813 >   * cancelled beacause the server was already there,
814 >   * there are no NICK's to be cancelled...). Of course,
815 >   * if cancellation occurs, all this info is sent anyway,
816 >   * and I guess the link dies when a read is attempted...? --msa
817 >   *
818 >   * Note: Link cancellation to occur at this point means
819 >   * that at least two servers from my fragment are building
820 >   * up connection this other fragment at the same time, it's
821 >   * a race condition, not the normal way of operation...
822 >   *
823 >   * ALSO NOTE: using the get_client_name for server names--
824 >   *    see previous *WARNING*!!! (Also, original inpath
825 >   *    is destroyed...)
826 >   */
827  
828    DLINK_FOREACH_PREV(ptr, global_serv_list.tail)
829    {
830 <    target_p = ptr->data;
830 >    struct Client *target_p = ptr->data;
831  
832      /* target_p->from == target_p for target_p == client_p */
833 <    if (target_p->from == client_p)
833 >    if (IsMe(target_p) || target_p->from == client_p)
834        continue;
835  
836 <    if (match(my_name_for_link(conf), target_p->name))
837 <      continue;
836 >    sendto_one(client_p, ":%s SID %s %d %s :%s%s",
837 >               target_p->servptr->id, target_p->name, target_p->hopcount+1,
838 >               target_p->id, IsHidden(target_p) ? "(H) " : "",
839 >               target_p->info);
840  
841 <    if (IsCapable(client_p, CAP_TS6))
842 <    {
1209 <      if (HasID(target_p))
1210 <        sendto_one(client_p, ":%s SID %s %d %s :%s%s",
1211 <                   ID(target_p->servptr), target_p->name, target_p->hopcount+1,
1212 <                   target_p->id, IsHidden(target_p) ? "(H) " : "",
1213 <                   target_p->info);
1214 <      else  /* introducing non-ts6 server */
1215 <        sendto_one(client_p, ":%s SERVER %s %d :%s%s",
1216 <                   ID(target_p->servptr), target_p->name, target_p->hopcount+1,
1217 <                   IsHidden(target_p) ? "(H) " : "", target_p->info);
1218 <    }
1219 <    else
1220 <      sendto_one(client_p, ":%s SERVER %s %d :%s%s",
1221 <                 target_p->servptr->name, target_p->name, target_p->hopcount+1,
1222 <                 IsHidden(target_p) ? "(H) " : "", target_p->info);
841 >    if (HasFlag(target_p, FLAGS_EOB))
842 >      sendto_one(client_p, ":%s EOB", target_p->id, client_p);
843    }
844  
845    server_burst(client_p);
846   }
847  
1228 static void
1229 start_io(struct Client *server)
1230 {
1231  struct LocalUser *lserver = server->localClient;
1232  int alloclen = 1;
1233  char *buf;
1234  dlink_node *ptr;
1235  struct dbuf_block *block;
1236
1237  /* calculate how many bytes to allocate */
1238  if (IsCapable(server, CAP_ZIP))
1239    alloclen += 6;
1240 #ifdef HAVE_LIBCRYPTO
1241  if (IsCapable(server, CAP_ENC))
1242    alloclen += 16 + lserver->in_cipher->keylen + lserver->out_cipher->keylen;
1243 #endif
1244  alloclen += dbuf_length(&lserver->buf_recvq);
1245  alloclen += dlink_list_length(&lserver->buf_recvq.blocks) * 3;
1246  alloclen += dbuf_length(&lserver->buf_sendq);
1247  alloclen += dlink_list_length(&lserver->buf_sendq.blocks) * 3;
1248
1249  /* initialize servlink control sendq */
1250  lserver->slinkq = buf = MyMalloc(alloclen);
1251  lserver->slinkq_ofs = 0;
1252  lserver->slinkq_len = alloclen;
1253
1254  if (IsCapable(server, CAP_ZIP))
1255  {
1256    /* ziplink */
1257    *buf++ = SLINKCMD_SET_ZIP_OUT_LEVEL;
1258    *buf++ = 0; /* |          */
1259    *buf++ = 1; /* \ len is 1 */
1260    *buf++ = ConfigFileEntry.compression_level;
1261    *buf++ = SLINKCMD_START_ZIP_IN;
1262    *buf++ = SLINKCMD_START_ZIP_OUT;
1263  }
1264 #ifdef HAVE_LIBCRYPTO
1265  if (IsCapable(server, CAP_ENC))
1266  {
1267    /* Decryption settings */
1268    *buf++ = SLINKCMD_SET_CRYPT_IN_CIPHER;
1269    *buf++ = 0; /* /                     (upper 8-bits of len) */
1270    *buf++ = 1; /* \ cipher id is 1 byte (lower 8-bits of len) */
1271    *buf++ = lserver->in_cipher->cipherid;
1272    *buf++ = SLINKCMD_SET_CRYPT_IN_KEY;
1273    *buf++ = 0; /* keylen < 256 */
1274    *buf++ = lserver->in_cipher->keylen;
1275    memcpy(buf, lserver->in_key, lserver->in_cipher->keylen);
1276    buf += lserver->in_cipher->keylen;
1277    /* Encryption settings */
1278    *buf++ = SLINKCMD_SET_CRYPT_OUT_CIPHER;
1279    *buf++ = 0; /* /                     (upper 8-bits of len) */
1280    *buf++ = 1; /* \ cipher id is 1 byte (lower 8-bits of len) */
1281    *buf++ = lserver->out_cipher->cipherid;
1282    *buf++ = SLINKCMD_SET_CRYPT_OUT_KEY;
1283    *buf++ = 0; /* keylen < 256 */
1284    *buf++ = lserver->out_cipher->keylen;
1285    memcpy(buf, lserver->out_key, lserver->out_cipher->keylen);
1286    buf += lserver->out_cipher->keylen;
1287    *buf++ = SLINKCMD_START_CRYPT_IN;
1288    *buf++ = SLINKCMD_START_CRYPT_OUT;
1289  }
1290 #endif
1291
1292  /* pass the whole recvq to servlink */
1293  DLINK_FOREACH (ptr, lserver->buf_recvq.blocks.head)
1294  {
1295    block = ptr->data;
1296    *buf++ = SLINKCMD_INJECT_RECVQ;
1297    *buf++ = (block->size >> 8);
1298    *buf++ = (block->size & 0xff);
1299    memcpy(buf, &block->data[0], block->size);
1300    buf += block->size;
1301  }
1302
1303  dbuf_clear(&lserver->buf_recvq);
1304
1305  /* pass the whole sendq to servlink */
1306  DLINK_FOREACH (ptr, lserver->buf_sendq.blocks.head)
1307  {
1308    block = ptr->data;
1309    *buf++ = SLINKCMD_INJECT_SENDQ;
1310    *buf++ = (block->size >> 8);
1311    *buf++ = (block->size & 0xff);
1312    memcpy(buf, &block->data[0], block->size);
1313    buf += block->size;
1314  }
1315
1316  dbuf_clear(&lserver->buf_sendq);
1317
1318  /* start io */
1319  *buf++ = SLINKCMD_INIT;
1320
1321  /* schedule a write */
1322  send_queued_slink_write(server);
1323 }
1324
1325 /* fork_server()
1326 *
1327 * inputs       - struct Client *server
1328 * output       - success: 0 / failure: -1
1329 * side effect  - fork, and exec SERVLINK to handle this connection
1330 */
1331 static int
1332 fork_server(struct Client *server)
1333 {
1334 #ifndef HAVE_SOCKETPAIR
1335  return -1;
1336 #else
1337  int i;
1338  int slink_fds[2][2];
1339  /* 0? - ctrl  | 1? - data  
1340   * ?0 - child | ?1 - parent */
1341
1342  if (socketpair(AF_UNIX, SOCK_STREAM, 0, slink_fds[0]) < 0)
1343    return -1;
1344  if (socketpair(AF_UNIX, SOCK_STREAM, 0, slink_fds[1]) < 0)
1345    goto free_ctrl_fds;
1346
1347  if ((i = fork()) < 0)
1348  {
1349    close(slink_fds[1][0]);  close(slink_fds[1][1]);
1350    free_ctrl_fds:
1351    close(slink_fds[0][0]);  close(slink_fds[0][1]);
1352    return -1;
1353  }
1354
1355  if (i == 0)
1356  {
1357    char fd_str[3][6];   /* store 3x sizeof("65535") */
1358    char *kid_argv[7];
1359
1360 #ifdef O_ASYNC
1361    fcntl(server->localClient->fd.fd, F_SETFL,
1362          fcntl(server->localClient->fd.fd, F_GETFL, 0) & ~O_ASYNC);
1363 #endif
1364    close_fds(&server->localClient->fd);
1365    close(slink_fds[0][1]);
1366    close(slink_fds[1][1]);
1367
1368    sprintf(fd_str[0], "%d", slink_fds[0][0]);
1369    sprintf(fd_str[1], "%d", slink_fds[1][0]);
1370    sprintf(fd_str[2], "%d", server->localClient->fd.fd);
1371
1372    kid_argv[0] = "-slink";
1373    kid_argv[1] = kid_argv[2] = fd_str[0];  /* ctrl */
1374    kid_argv[3] = kid_argv[4] = fd_str[1];  /* data */
1375    kid_argv[5] = fd_str[2];    /* network */
1376    kid_argv[6] = NULL;
1377
1378    execv(ConfigFileEntry.servlink_path, kid_argv);
1379
1380    _exit(1);
1381  }
1382
1383  /* close the network fd and the child ends of the pipes */
1384  fd_close(&server->localClient->fd);
1385  close(slink_fds[0][0]);
1386  close(slink_fds[1][0]);
1387
1388  execute_callback(setup_socket_cb, slink_fds[0][1]);
1389  execute_callback(setup_socket_cb, slink_fds[1][1]);
1390
1391  fd_open(&server->localClient->ctrlfd, slink_fds[0][1], 1, "slink ctrl");
1392  fd_open(&server->localClient->fd, slink_fds[1][1], 1, "slink data");
1393
1394  read_ctrl_packet(&server->localClient->ctrlfd, server);
1395  read_packet(&server->localClient->fd, server);
1396
1397  return 0;
1398 #endif
1399 }
1400
848   /* server_burst()
849   *
850   * inputs       - struct Client pointer server
# Line 1423 | Line 870 | server_burst(struct Client *client_p)
870  
871    /* EOB stuff is now in burst_all */
872    /* Always send a PING after connect burst is done */
873 <  sendto_one(client_p, "PING :%s", ID_or_name(&me, client_p));
873 >  sendto_one(client_p, "PING :%s", me.id);
874   }
875  
876   /* burst_all()
877   *
878 < * inputs       - pointer to server to send burst to
878 > * inputs       - pointer to server to send burst to
879   * output       - NONE
880   * side effects - complete burst of channels/nicks is sent to client_p
881   */
# Line 1446 | Line 893 | burst_all(struct Client *client_p)
893        burst_members(client_p, chptr);
894        send_channel_modes(client_p, chptr);
895  
896 <      if (IsCapable(client_p, CAP_TBURST) ||
897 <          IsCapable(client_p, CAP_TB))
1451 <        send_tb(client_p, chptr);
896 >      if (IsCapable(client_p, CAP_TBURST))
897 >        send_tb(client_p, chptr);
898      }
899    }
900  
# Line 1458 | Line 904 | burst_all(struct Client *client_p)
904    {
905      struct Client *target_p = ptr->data;
906  
907 <    if (!IsBursted(target_p) && target_p->from != client_p)
907 >    if (!HasFlag(target_p, FLAGS_BURSTED) && target_p->from != client_p)
908        sendnick_TS(client_p, target_p);
909 <    
910 <    ClearBursted(target_p);
909 >
910 >    DelFlag(target_p, FLAGS_BURSTED);
911    }
912  
1467  /* We send the time we started the burst, and let the remote host determine an EOB time,
1468  ** as otherwise we end up sending a EOB of 0   Sending here means it gets sent last -- fl
1469  */
1470  /* Its simpler to just send EOB and use the time its been connected.. --fl_ */
913    if (IsCapable(client_p, CAP_EOB))
914 <    sendto_one(client_p, ":%s EOB", ID_or_name(&me, client_p));
914 >    sendto_one(client_p, ":%s EOB", me.id);
915   }
916  
917   /*
# Line 1479 | Line 921 | burst_all(struct Client *client_p)
921   *              - pointer to channel
922   * output       - NONE
923   * side effects - Called on a server burst when
924 < *                server is CAP_TB|CAP_TBURST capable
924 > *                server is CAP_TBURST capable
925   */
926   static void
927   send_tb(struct Client *client_p, struct Channel *chptr)
# Line 1498 | Line 940 | send_tb(struct Client *client_p, struct
940     * for further information   -Michael
941     */
942    if (chptr->topic_time != 0)
943 <  {
944 <    if (IsCapable(client_p, CAP_TBURST))
945 <      sendto_one(client_p, ":%s TBURST %lu %s %lu %s :%s",
946 <                 me.name, (unsigned long)chptr->channelts, chptr->chname,
947 <                 (unsigned long)chptr->topic_time,
1506 <                 chptr->topic_info ? chptr->topic_info : "",
1507 <                 chptr->topic ? chptr->topic : "");
1508 <    else if (IsCapable(client_p, CAP_TB))
1509 <    {
1510 <      if (ConfigChannel.burst_topicwho)
1511 <      {
1512 <        sendto_one(client_p, ":%s TB %s %lu %s :%s",
1513 <                   me.name, chptr->chname,
1514 <                   (unsigned long)chptr->topic_time,
1515 <                   chptr->topic_info, chptr->topic ? chptr->topic : "");
1516 <      }
1517 <      else
1518 <      {
1519 <        sendto_one(client_p, ":%s TB %s %lu :%s",
1520 <                   me.name, chptr->chname,
1521 <                   (unsigned long)chptr->topic_time,
1522 <                   chptr->topic ? chptr->topic : "");
1523 <      }
1524 <    }
1525 <  }
943 >    sendto_one(client_p, ":%s TBURST %lu %s %lu %s :%s", me.id,
944 >               (unsigned long)chptr->channelts, chptr->chname,
945 >               (unsigned long)chptr->topic_time,
946 >               chptr->topic_info,
947 >               chptr->topic);
948   }
949  
950   /* burst_members()
# Line 1544 | Line 966 | burst_members(struct Client *client_p, s
966      ms       = ptr->data;
967      target_p = ms->client_p;
968  
969 <    if (!IsBursted(target_p))
969 >    if (!HasFlag(target_p, FLAGS_BURSTED))
970      {
971 <      SetBursted(target_p);
971 >      AddFlag(target_p, FLAGS_BURSTED);
972  
973        if (target_p->from != client_p)
974          sendnick_TS(client_p, target_p);
# Line 1554 | Line 976 | burst_members(struct Client *client_p, s
976    }
977   }
978  
1557 /* set_autoconn()
1558 *
1559 * inputs       - struct Client pointer to oper requesting change
1560 * output       - none
1561 * side effects - set autoconnect mode
1562 */
1563 void
1564 set_autoconn(struct Client *source_p, const char *name, int newval)
1565 {
1566  struct ConfItem *conf;
1567  struct AccessItem *aconf;
1568
1569  if (name != NULL)
1570  {
1571    conf = find_exact_name_conf(SERVER_TYPE, name, NULL, NULL);
1572    if (conf != NULL)
1573    {
1574      aconf = (struct AccessItem *)map_to_conf(conf);
1575      if (newval)
1576        SetConfAllowAutoConn(aconf);
1577      else
1578        ClearConfAllowAutoConn(aconf);
1579
1580      sendto_realops_flags(UMODE_ALL, L_ALL,
1581                           "%s has changed AUTOCONN for %s to %i",
1582                           source_p->name, name, newval);
1583      sendto_one(source_p,
1584                 ":%s NOTICE %s :AUTOCONN for %s is now set to %i",
1585                 me.name, source_p->name, name, newval);
1586    }
1587    else
1588    {
1589      sendto_one(source_p, ":%s NOTICE %s :Can't find %s",
1590                 me.name, source_p->name, name);
1591    }
1592  }
1593  else
1594  {
1595    sendto_one(source_p, ":%s NOTICE %s :Please specify a server name!",
1596               me.name, source_p->name);
1597  }
1598 }
1599
979   /* New server connection code
980   * Based upon the stuff floating about in s_bsd.c
981   *   -- adrian
# Line 1604 | Line 983 | set_autoconn(struct Client *source_p, co
983  
984   /* serv_connect() - initiate a server connection
985   *
986 < * inputs       - pointer to conf
986 > * inputs       - pointer to conf
987   *              - pointer to client doing the connect
988   * output       -
989   * side effects -
# Line 1619 | Line 998 | set_autoconn(struct Client *source_p, co
998   * it suceeded or not, and 0 if it fails in here somewhere.
999   */
1000   int
1001 < serv_connect(struct AccessItem *aconf, struct Client *by)
1001 > serv_connect(struct MaskItem *conf, struct Client *by)
1002   {
1624  struct ConfItem *conf;
1003    struct Client *client_p;
1004 <  char buf[HOSTIPLEN];
1004 >  char buf[HOSTIPLEN + 1];
1005  
1006    /* conversion structs */
1007    struct sockaddr_in *v4;
1008 <  /* Make sure aconf is useful */
1009 <  assert(aconf != NULL);
1632 <
1633 <  if(aconf == NULL)
1634 <    return (0);
1008 >  /* Make sure conf is useful */
1009 >  assert(conf != NULL);
1010  
1636  /* XXX should be passing struct ConfItem in the first place */
1637  conf = unmap_conf_item(aconf);
1011  
1012 <  /* log */
1013 <  irc_getnameinfo((struct sockaddr*)&aconf->ipnum, aconf->ipnum.ss_len,
1014 <                  buf, HOSTIPLEN, NULL, 0, NI_NUMERICHOST);
1642 <  ilog(L_NOTICE, "Connect to %s[%s] @%s", aconf->user, aconf->host,
1012 >  getnameinfo((struct sockaddr *)&conf->addr, conf->addr.ss_len,
1013 >              buf, sizeof(buf), NULL, 0, NI_NUMERICHOST);
1014 >  ilog(LOG_TYPE_IRCD, "Connect to %s[%s] @%s", conf->name, conf->host,
1015         buf);
1016  
1017    /* Still processing a DNS lookup? -> exit */
1018 <  if (aconf->dns_query != NULL)
1018 >  if (conf->dns_pending)
1019    {
1020 <    sendto_realops_flags(UMODE_ALL, L_OPER,
1021 <                         "Error connecting to %s: Error during DNS lookup", conf->name);
1020 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1021 >                         "Error connecting to %s: DNS lookup for connect{} in progress.",
1022 >                         conf->name);
1023 >    return (0);
1024 >  }
1025 >
1026 >  if (conf->dns_failed)
1027 >  {
1028 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1029 >                         "Error connecting to %s: DNS lookup for connect{} failed.",
1030 >                         conf->name);
1031      return (0);
1032    }
1033  
1034    /* Make sure this server isn't already connected
1035 <   * Note: aconf should ALWAYS be a valid C: line
1035 >   * Note: conf should ALWAYS be a valid C: line
1036     */
1037 <  if ((client_p = find_server(conf->name)) != NULL)
1038 <  {
1039 <    sendto_realops_flags(UMODE_ALL, L_ADMIN,
1040 <                         "Server %s already present from %s",
1041 <                         conf->name, get_client_name(client_p, SHOW_IP));
1042 <    sendto_realops_flags(UMODE_ALL, L_OPER,
1043 <                         "Server %s already present from %s",
1044 <                         conf->name, get_client_name(client_p, MASK_IP));
1037 >  if ((client_p = hash_find_server(conf->name)) != NULL)
1038 >  {
1039 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1040 >                         "Server %s already present from %s",
1041 >                         conf->name, get_client_name(client_p, SHOW_IP));
1042 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1043 >                         "Server %s already present from %s",
1044 >                         conf->name, get_client_name(client_p, MASK_IP));
1045      if (by && IsClient(by) && !MyClient(by))
1046 <      sendto_one(by, ":%s NOTICE %s :Server %s already present from %s",
1047 <                 me.name, by->name, conf->name,
1048 <                 get_client_name(client_p, MASK_IP));
1668 <    return (0);
1046 >      sendto_one_notice(by, &me, ":Server %s already present from %s",
1047 >                        conf->name, get_client_name(client_p, MASK_IP));
1048 >    return 0;
1049    }
1050 <    
1050 >
1051    /* Create a local client */
1052    client_p = make_client(NULL);
1053  
1054    /* Copy in the server, hostname, fd */
1055    strlcpy(client_p->name, conf->name, sizeof(client_p->name));
1056 <  strlcpy(client_p->host, aconf->host, sizeof(client_p->host));
1056 >  strlcpy(client_p->host, conf->host, sizeof(client_p->host));
1057  
1058    /* We already converted the ip once, so lets use it - stu */
1059 <  strlcpy(client_p->sockhost, buf, HOSTIPLEN);
1059 >  strlcpy(client_p->sockhost, buf, sizeof(client_p->sockhost));
1060  
1061 <  /* create a socket for the server connection */
1062 <  if (comm_open(&client_p->localClient->fd, aconf->ipnum.ss.ss_family,
1061 >  /* create a socket for the server connection */
1062 >  if (comm_open(&client_p->localClient->fd, conf->addr.ss.ss_family,
1063                  SOCK_STREAM, 0, NULL) < 0)
1064    {
1065      /* Eek, failure to create the socket */
1066 <    report_error(L_ALL,
1067 <                 "opening stream socket to %s: %s", conf->name, errno);
1066 >    report_error(L_ALL, "opening stream socket to %s: %s",
1067 >                 conf->name, errno);
1068      SetDead(client_p);
1069 <    exit_client(client_p, &me, "Connection failed");
1070 <    return (0);
1069 >    exit_client(client_p, "Connection failed");
1070 >    return 0;
1071    }
1072  
1073    /* servernames are always guaranteed under HOSTLEN chars */
# Line 1696 | Line 1076 | serv_connect(struct AccessItem *aconf, s
1076    /* Attach config entries to client here rather than in
1077     * serv_connect_callback(). This to avoid null pointer references.
1078     */
1079 <  if (!attach_connect_block(client_p, conf->name, aconf->host))
1079 >  if (!attach_connect_block(client_p, conf->name, conf->host))
1080    {
1081 <    sendto_realops_flags(UMODE_ALL, L_ALL,
1082 <                         "Host %s is not enabled for connecting:no C/N-line",
1083 <                         conf->name);
1084 <    if (by && IsClient(by) && !MyClient(by))  
1085 <      sendto_one(by, ":%s NOTICE %s :Connect to host %s failed.",
1086 <                 me.name, by->name, client_p->name);
1081 >    sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1082 >                         "Host %s is not enabled for connecting: no connect{} block",
1083 >                         conf->name);
1084 >    if (by && IsClient(by) && !MyClient(by))
1085 >      sendto_one_notice(by, &me, ":Connect to host %s failed.", client_p->name);
1086 >
1087      SetDead(client_p);
1088 <    exit_client(client_p, client_p, "Connection failed");
1089 <    return (0);
1088 >    exit_client(client_p, "Connection failed");
1089 >    return 0;
1090    }
1091  
1092    /* at this point we have a connection in progress and C/N lines
# Line 1725 | Line 1105 | serv_connect(struct AccessItem *aconf, s
1105    SetConnecting(client_p);
1106    dlinkAdd(client_p, &client_p->node, &global_client_list);
1107    /* from def_fam */
1108 <  client_p->localClient->aftype = aconf->aftype;
1108 >  client_p->localClient->aftype = conf->aftype;
1109  
1110    /* Now, initiate the connection */
1111 <  /* XXX assume that a non 0 type means a specific bind address
1111 >  /* XXX assume that a non 0 type means a specific bind address
1112     * for this connect.
1113     */
1114 <  switch (aconf->aftype)
1114 >  switch (conf->aftype)
1115    {
1116      case AF_INET:
1117 <      v4 = (struct sockaddr_in*)&aconf->my_ipnum;
1117 >      v4 = (struct sockaddr_in*)&conf->bind;
1118        if (v4->sin_addr.s_addr != 0)
1119        {
1120          struct irc_ssaddr ipn;
1121          memset(&ipn, 0, sizeof(struct irc_ssaddr));
1122          ipn.ss.ss_family = AF_INET;
1123          ipn.ss_port = 0;
1124 <        memcpy(&ipn, &aconf->my_ipnum, sizeof(struct irc_ssaddr));
1125 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
1126 <                         (struct sockaddr *)&ipn, ipn.ss_len,
1127 <                         serv_connect_callback, client_p, aconf->aftype,
1128 <                         CONNECTTIMEOUT);
1124 >        memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
1125 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
1126 >                         (struct sockaddr *)&ipn, ipn.ss_len,
1127 >                         serv_connect_callback, client_p, conf->aftype,
1128 >                         CONNECTTIMEOUT);
1129        }
1130        else if (ServerInfo.specific_ipv4_vhost)
1131        {
# Line 1754 | Line 1134 | serv_connect(struct AccessItem *aconf, s
1134          ipn.ss.ss_family = AF_INET;
1135          ipn.ss_port = 0;
1136          memcpy(&ipn, &ServerInfo.ip, sizeof(struct irc_ssaddr));
1137 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
1137 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
1138                           (struct sockaddr *)&ipn, ipn.ss_len,
1139 <                         serv_connect_callback, client_p, aconf->aftype,
1140 <                         CONNECTTIMEOUT);
1139 >                         serv_connect_callback, client_p, conf->aftype,
1140 >                         CONNECTTIMEOUT);
1141        }
1142        else
1143 <        comm_connect_tcp(&client_p->localClient->fd, aconf->host, aconf->port,
1144 <                         NULL, 0, serv_connect_callback, client_p, aconf->aftype,
1143 >        comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
1144 >                         NULL, 0, serv_connect_callback, client_p, conf->aftype,
1145                           CONNECTTIMEOUT);
1146        break;
1147   #ifdef IPV6
1148      case AF_INET6:
1149        {
1150 <        struct irc_ssaddr ipn;
1151 <        struct sockaddr_in6 *v6;
1152 <        struct sockaddr_in6 *v6conf;
1153 <
1154 <        memset(&ipn, 0, sizeof(struct irc_ssaddr));
1155 <        v6conf = (struct sockaddr_in6 *)&aconf->my_ipnum;
1156 <        v6 = (struct sockaddr_in6 *)&ipn;
1157 <
1158 <        if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr,
1779 <                   sizeof(struct in6_addr)) != 0)
1780 <        {
1781 <          memcpy(&ipn, &aconf->my_ipnum, sizeof(struct irc_ssaddr));
1782 <          ipn.ss.ss_family = AF_INET6;
1783 <          ipn.ss_port = 0;
1784 <          comm_connect_tcp(&client_p->localClient->fd,
1785 <                           aconf->host, aconf->port,
1786 <                           (struct sockaddr *)&ipn, ipn.ss_len,
1787 <                           serv_connect_callback, client_p,
1788 <                           aconf->aftype, CONNECTTIMEOUT);
1789 <        }
1790 <        else if (ServerInfo.specific_ipv6_vhost)
1150 >        struct irc_ssaddr ipn;
1151 >        struct sockaddr_in6 *v6;
1152 >        struct sockaddr_in6 *v6conf;
1153 >
1154 >        memset(&ipn, 0, sizeof(struct irc_ssaddr));
1155 >        v6conf = (struct sockaddr_in6 *)&conf->bind;
1156 >        v6 = (struct sockaddr_in6 *)&ipn;
1157 >
1158 >        if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr, sizeof(struct in6_addr)) != 0)
1159          {
1160 <          memcpy(&ipn, &ServerInfo.ip6, sizeof(struct irc_ssaddr));
1161 <          ipn.ss.ss_family = AF_INET6;
1162 <          ipn.ss_port = 0;
1163 <          comm_connect_tcp(&client_p->localClient->fd,
1164 <                           aconf->host, aconf->port,
1165 <                           (struct sockaddr *)&ipn, ipn.ss_len,
1166 <                           serv_connect_callback, client_p,
1167 <                           aconf->aftype, CONNECTTIMEOUT);
1168 <        }
1169 <        else
1170 <          comm_connect_tcp(&client_p->localClient->fd,
1171 <                           aconf->host, aconf->port,
1172 <                           NULL, 0, serv_connect_callback, client_p,
1173 <                           aconf->aftype, CONNECTTIMEOUT);
1160 >          memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
1161 >          ipn.ss.ss_family = AF_INET6;
1162 >          ipn.ss_port = 0;
1163 >          comm_connect_tcp(&client_p->localClient->fd,
1164 >                           conf->host, conf->port,
1165 >                           (struct sockaddr *)&ipn, ipn.ss_len,
1166 >                           serv_connect_callback, client_p,
1167 >                           conf->aftype, CONNECTTIMEOUT);
1168 >        }
1169 >        else if (ServerInfo.specific_ipv6_vhost)
1170 >        {
1171 >          memcpy(&ipn, &ServerInfo.ip6, sizeof(struct irc_ssaddr));
1172 >          ipn.ss.ss_family = AF_INET6;
1173 >          ipn.ss_port = 0;
1174 >          comm_connect_tcp(&client_p->localClient->fd,
1175 >                           conf->host, conf->port,
1176 >                           (struct sockaddr *)&ipn, ipn.ss_len,
1177 >                           serv_connect_callback, client_p,
1178 >                           conf->aftype, CONNECTTIMEOUT);
1179 >        }
1180 >        else
1181 >          comm_connect_tcp(&client_p->localClient->fd,
1182 >                           conf->host, conf->port,
1183 >                           NULL, 0, serv_connect_callback, client_p,
1184 >                           conf->aftype, CONNECTTIMEOUT);
1185        }
1186   #endif
1187    }
1188 <  return (1);
1188 >  return 1;
1189 > }
1190 >
1191 > #ifdef HAVE_LIBCRYPTO
1192 > static void
1193 > finish_ssl_server_handshake(struct Client *client_p)
1194 > {
1195 >  struct MaskItem *conf = NULL;
1196 >
1197 >  conf = find_conf_name(&client_p->localClient->confs,
1198 >                        client_p->name, CONF_SERVER);
1199 >  if (conf == NULL)
1200 >  {
1201 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1202 >                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
1203 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1204 >                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
1205 >
1206 >    exit_client(client_p, "Lost connect{} block");
1207 >    return;
1208 >  }
1209 >
1210 >  sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
1211 >
1212 >  send_capabilities(client_p, 0);
1213 >
1214 >  sendto_one(client_p, "SERVER %s 1 :%s%s",
1215 >             me.name, ConfigServerHide.hidden ? "(H) " : "",
1216 >             me.info);
1217 >
1218 >  /* If we've been marked dead because a send failed, just exit
1219 >   * here now and save everyone the trouble of us ever existing.
1220 >   */
1221 >  if (IsDead(client_p))
1222 >  {
1223 >      sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1224 >                           "%s[%s] went dead during handshake",
1225 >                           client_p->name,
1226 >                           client_p->host);
1227 >      sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1228 >                           "%s went dead during handshake", client_p->name);
1229 >      return;
1230 >  }
1231 >
1232 >  /* don't move to serv_list yet -- we haven't sent a burst! */
1233 >  /* If we get here, we're ok, so lets start reading some data */
1234 >  comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ, read_packet, client_p, 0);
1235 > }
1236 >
1237 > static void
1238 > ssl_server_handshake(fde_t *fd, struct Client *client_p)
1239 > {
1240 >  X509 *cert = NULL;
1241 >  int ret = 0;
1242 >
1243 >  if ((ret = SSL_connect(client_p->localClient->fd.ssl)) <= 0)
1244 >  {
1245 >    switch (SSL_get_error(client_p->localClient->fd.ssl, ret))
1246 >    {
1247 >      case SSL_ERROR_WANT_WRITE:
1248 >        comm_setselect(&client_p->localClient->fd, COMM_SELECT_WRITE,
1249 >                       (PF *)ssl_server_handshake, client_p, 0);
1250 >        return;
1251 >      case SSL_ERROR_WANT_READ:
1252 >        comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ,
1253 >                       (PF *)ssl_server_handshake, client_p, 0);
1254 >        return;
1255 >      default:
1256 >      {
1257 >        const char *sslerr = ERR_error_string(ERR_get_error(), NULL);
1258 >        sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
1259 >                             "Error connecting to %s: %s", client_p->name,
1260 >                             sslerr ? sslerr : "unknown SSL error");
1261 >        exit_client(client_p, "Error during SSL handshake");
1262 >        return;
1263 >      }
1264 >    }
1265 >  }
1266 >
1267 >  if ((cert = SSL_get_peer_certificate(client_p->localClient->fd.ssl)))
1268 >  {
1269 >    int res = SSL_get_verify_result(client_p->localClient->fd.ssl);
1270 >    char buf[EVP_MAX_MD_SIZE * 2 + 1] = { '\0' };
1271 >    unsigned char md[EVP_MAX_MD_SIZE] = { '\0' };
1272 >
1273 >    if (res == X509_V_OK || res == X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN ||
1274 >        res == X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE ||
1275 >        res == X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT)
1276 >    {
1277 >      unsigned int i = 0, n = 0;
1278 >
1279 >      if (X509_digest(cert, EVP_sha256(), md, &n))
1280 >      {
1281 >        for (; i < n; ++i)
1282 >          snprintf(buf + 2 * i, 3, "%02X", md[i]);
1283 >        client_p->certfp = xstrdup(buf);
1284 >      }
1285 >    }
1286 >    else
1287 >      ilog(LOG_TYPE_IRCD, "Server %s!%s@%s gave bad SSL client certificate: %d",
1288 >           client_p->name, client_p->username, client_p->host, res);
1289 >    X509_free(cert);
1290 >  }
1291 >
1292 >  finish_ssl_server_handshake(client_p);
1293 > }
1294 >
1295 > static void
1296 > ssl_connect_init(struct Client *client_p, struct MaskItem *conf, fde_t *fd)
1297 > {
1298 >  if ((client_p->localClient->fd.ssl = SSL_new(ServerInfo.client_ctx)) == NULL)
1299 >  {
1300 >    ilog(LOG_TYPE_IRCD, "SSL_new() ERROR! -- %s",
1301 >         ERR_error_string(ERR_get_error(), NULL));
1302 >    SetDead(client_p);
1303 >    exit_client(client_p, "SSL_new failed");
1304 >    return;
1305 >  }
1306 >
1307 >  SSL_set_fd(fd->ssl, fd->fd);
1308 >
1309 >  if (!EmptyString(conf->cipher_list))
1310 >    SSL_set_cipher_list(client_p->localClient->fd.ssl, conf->cipher_list);
1311 >
1312 >  ssl_server_handshake(NULL, client_p);
1313   }
1314 + #endif
1315  
1316   /* serv_connect_callback() - complete a server connection.
1317 < *
1317 > *
1318   * This routine is called after the server connection attempt has
1319   * completed. If unsucessful, an error is sent to ops and the client
1320   * is closed. If sucessful, it goes through the initialisation/check
# Line 1821 | Line 1325 | static void
1325   serv_connect_callback(fde_t *fd, int status, void *data)
1326   {
1327    struct Client *client_p = data;
1328 <  struct ConfItem *conf=NULL;
1825 <  struct AccessItem *aconf=NULL;
1328 >  struct MaskItem *conf = NULL;
1329  
1330    /* First, make sure its a real client! */
1331    assert(client_p != NULL);
# Line 1838 | Line 1341 | serv_connect_callback(fde_t *fd, int sta
1341       * Admins get to see any IP, mere opers don't *sigh*
1342       */
1343       if (ConfigServerHide.hide_server_ips)
1344 <       sendto_realops_flags(UMODE_ALL, L_ADMIN,
1344 >       sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1345                              "Error connecting to %s: %s",
1346                              client_p->name, comm_errstr(status));
1347       else
1348 <       sendto_realops_flags(UMODE_ALL, L_ADMIN,
1349 <                            "Error connecting to %s[%s]: %s", client_p->name,
1350 <                            client_p->host, comm_errstr(status));
1351 <
1352 <     sendto_realops_flags(UMODE_ALL, L_OPER,
1353 <                          "Error connecting to %s: %s",
1354 <                          client_p->name, comm_errstr(status));
1348 >       sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1349 >                            "Error connecting to %s[%s]: %s", client_p->name,
1350 >                            client_p->host, comm_errstr(status));
1351 >
1352 >     sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1353 >                          "Error connecting to %s: %s",
1354 >                          client_p->name, comm_errstr(status));
1355  
1356       /* If a fd goes bad, call dead_link() the socket is no
1357        * longer valid for reading or writing.
# Line 1860 | Line 1363 | serv_connect_callback(fde_t *fd, int sta
1363    /* COMM_OK, so continue the connection procedure */
1364    /* Get the C/N lines */
1365    conf = find_conf_name(&client_p->localClient->confs,
1366 <                        client_p->name, SERVER_TYPE);
1366 >                        client_p->name, CONF_SERVER);
1367    if (conf == NULL)
1368    {
1369 <    sendto_realops_flags(UMODE_ALL, L_ADMIN,
1370 <                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
1371 <    sendto_realops_flags(UMODE_ALL, L_OPER,
1372 <                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
1369 >    sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1370 >                         "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
1371 >    sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1372 >                         "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
1373  
1374 <    exit_client(client_p, &me, "Lost connect{} block");
1374 >    exit_client(client_p, "Lost connect{} block");
1375      return;
1376    }
1377  
1875  aconf = (struct AccessItem *)map_to_conf(conf);
1378    /* Next, send the initial handshake */
1379    SetHandshake(client_p);
1380  
1381   #ifdef HAVE_LIBCRYPTO
1382 <  /* Handle all CRYPTLINK links in cryptlink_init */
1881 <  if (IsConfCryptLink(aconf))
1382 >  if (IsConfSSL(conf))
1383    {
1384 <    cryptlink_init(client_p, conf, fd);
1384 >    ssl_connect_init(client_p, conf, fd);
1385      return;
1386    }
1387   #endif
1388  
1389 <  /* jdc -- Check and send spasswd, not passwd. */
1889 <  if (!EmptyString(aconf->spasswd) && (me.id[0] != '\0'))
1890 <      /* Send TS 6 form only if id */
1891 <    sendto_one(client_p, "PASS %s TS %d %s",
1892 <               aconf->spasswd, TS_CURRENT, me.id);
1893 <  else
1894 <    sendto_one(client_p, "PASS %s TS 5",
1895 <               aconf->spasswd);
1389 >  sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
1390  
1391 <  /* Pass my info to the new server
1898 <   *
1899 <   * If this is a HUB, pass on CAP_HUB
1900 <   * Pass on ZIP if supported
1901 <   * Pass on TB if supported.
1902 <   * - Dianora
1903 <   */
1904 <  send_capabilities(client_p, aconf, (ServerInfo.hub ? CAP_HUB : 0)
1905 <                    | (IsConfCompressed(aconf) ? CAP_ZIP : 0)
1906 <                    | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), 0);
1391 >  send_capabilities(client_p, 0);
1392  
1393 <  sendto_one(client_p, "SERVER %s 1 :%s%s",
1394 <             my_name_for_link(conf),
1910 <             ConfigServerHide.hidden ? "(H) " : "",
1911 <             me.info);
1393 >  sendto_one(client_p, "SERVER %s 1 :%s%s", me.name,
1394 >             ConfigServerHide.hidden ? "(H) " : "", me.info);
1395  
1396    /* If we've been marked dead because a send failed, just exit
1397     * here now and save everyone the trouble of us ever existing.
1398     */
1399 <  if (IsDead(client_p))
1399 >  if (IsDead(client_p))
1400    {
1401 <      sendto_realops_flags(UMODE_ALL, L_ADMIN,
1402 <                           "%s[%s] went dead during handshake",
1401 >      sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
1402 >                           "%s[%s] went dead during handshake",
1403                             client_p->name,
1404 <                           client_p->host);
1405 <      sendto_realops_flags(UMODE_ALL, L_OPER,
1406 <                           "%s went dead during handshake", client_p->name);
1404 >                           client_p->host);
1405 >      sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1406 >                           "%s went dead during handshake", client_p->name);
1407        return;
1408    }
1409  
# Line 1940 | Line 1423 | find_servconn_in_progress(const char *na
1423      cptr = ptr->data;
1424  
1425      if (cptr && cptr->name[0])
1426 <      if (match(cptr->name, name) || match(name, cptr->name))
1426 >      if (!match(name, cptr->name))
1427          return cptr;
1428    }
1946  
1947  return NULL;
1948 }
1949
1950 #ifdef HAVE_LIBCRYPTO
1951 /*
1952 * sends a CRYPTLINK SERV command.
1953 */
1954 void
1955 cryptlink_init(struct Client *client_p, struct ConfItem *conf, fde_t *fd)
1956 {
1957  struct AccessItem *aconf;
1958  char *encrypted;
1959  unsigned char *key_to_send;
1960  char randkey[CIPHERKEYLEN];
1961  int enc_len;
1962
1963  /* get key */
1964  if ((!ServerInfo.rsa_private_key) ||
1965      (!RSA_check_key(ServerInfo.rsa_private_key)) )
1966  {
1967    cryptlink_error(client_p, "SERV", "Invalid RSA private key",
1968                                      "Invalid RSA private key");
1969    return;
1970  }
1971
1972  aconf = (struct AccessItem *)map_to_conf(conf);
1973
1974  if (aconf->rsa_public_key == NULL)
1975  {
1976    cryptlink_error(client_p, "SERV", "Invalid RSA public key",
1977                                      "Invalid RSA public key");
1978    return;
1979  }
1980
1981  if (get_randomness((unsigned char *)randkey, CIPHERKEYLEN) != 1)
1982  {
1983    cryptlink_error(client_p, "SERV", "Couldn't generate keyphrase",
1984                                      "Couldn't generate keyphrase");
1985    return;
1986  }
1987
1988  encrypted = MyMalloc(RSA_size(ServerInfo.rsa_private_key));
1989  enc_len   = RSA_public_encrypt(CIPHERKEYLEN,
1990                                 (unsigned char *)randkey,
1991                                 (unsigned char *)encrypted,
1992                                 aconf->rsa_public_key,
1993                                 RSA_PKCS1_PADDING);
1994
1995  memcpy(client_p->localClient->in_key, randkey, CIPHERKEYLEN);
1996
1997  if (enc_len <= 0)
1998  {
1999    report_crypto_errors();
2000    MyFree(encrypted);
2001    cryptlink_error(client_p, "SERV", "Couldn't encrypt data",
2002                                      "Couldn't encrypt data");
2003    return;
2004  }
2005
2006  if (!(base64_block(&key_to_send, encrypted, enc_len)))
2007  {
2008    MyFree(encrypted);
2009    cryptlink_error(client_p, "SERV", "Couldn't base64 encode key",
2010                                      "Couldn't base64 encode key");
2011    return;
2012  }
2013
2014  send_capabilities(client_p, aconf, (ServerInfo.hub ? CAP_HUB : 0)
2015                    | (IsConfCompressed(aconf) ? CAP_ZIP : 0)
2016                    | (IsConfTopicBurst(aconf) ? CAP_TBURST|CAP_TB : 0), CAP_ENC_MASK);
1429  
1430 <  if (me.id[0])
2019 <    sendto_one(client_p, "PASS . TS %d %s", TS_CURRENT, me.id);
2020 <
2021 <  sendto_one(client_p, "CRYPTLINK SERV %s %s :%s%s",
2022 <             my_name_for_link(conf), key_to_send,
2023 <             ConfigServerHide.hidden ? "(H) " : "", me.info);
2024 <
2025 <  SetHandshake(client_p);
2026 <  SetWaitAuth(client_p);
2027 <
2028 <  MyFree(encrypted);
2029 <  MyFree(key_to_send);
2030 <
2031 <  if (IsDead(client_p))
2032 <    cryptlink_error(client_p, "SERV", "Went dead during handshake",
2033 <                                      "Went dead during handshake");
2034 <  else if (fd != NULL)
2035 <    /* If we get here, we're ok, so lets start reading some data */
2036 <    comm_setselect(fd, COMM_SELECT_READ, read_packet, client_p, 0);
2037 < }
2038 <
2039 < void
2040 < cryptlink_error(struct Client *client_p, const char *type,
2041 <                const char *reason, const char *client_reason)
2042 < {
2043 <  sendto_realops_flags(UMODE_ALL, L_ADMIN, "%s: CRYPTLINK %s error - %s",
2044 <                       get_client_name(client_p, SHOW_IP), type, reason);
2045 <  sendto_realops_flags(UMODE_ALL, L_OPER,  "%s: CRYPTLINK %s error - %s",
2046 <                       get_client_name(client_p, MASK_IP), type, reason);
2047 <  ilog(L_ERROR, "%s: CRYPTLINK %s error - %s",
2048 <       get_client_name(client_p, SHOW_IP), type, reason);
2049 <
2050 <  /* If client_reason isn't NULL, then exit the client with the message
2051 <   * defined in the call.
2052 <   */
2053 <  if ((client_reason != NULL) && (!IsDead(client_p)))
2054 <    exit_client(client_p, &me, client_reason);
2055 < }
2056 <
2057 < static char base64_chars[] =
2058 <        "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=";
2059 <
2060 < static char base64_values[] =
2061 < {
2062 < /* 00-15   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2063 < /* 16-31   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2064 < /* 32-47   */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, 62, -1, -1, -1, 63,
2065 < /* 48-63   */ 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, -1, -1, -1,  0, -1, -1,
2066 < /* 64-79   */ -1,  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14,
2067 < /* 80-95   */ 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, -1, -1, -1, -1, -1,
2068 < /* 96-111  */ -1, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40,
2069 < /* 112-127 */ 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, -1, -1, -1, -1, -1,
2070 < /* 128-143 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2071 < /* 144-159 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2072 < /* 160-175 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2073 < /* 186-191 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2074 < /* 192-207 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2075 < /* 208-223 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2076 < /* 224-239 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
2077 < /* 240-255 */ -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1
2078 < };
2079 <
2080 < /*
2081 < * base64_block will allocate and return a new block of memory
2082 < * using MyMalloc().  It should be freed after use.
2083 < */
2084 < int
2085 < base64_block(unsigned char **output, char *data, int len)
2086 < {
2087 <  unsigned char *out;
2088 <  unsigned char *in = (unsigned char*)data;
2089 <  unsigned long int q_in;
2090 <  int i;
2091 <  int count = 0;
2092 <
2093 <  out = MyMalloc(((((len + 2) - ((len + 2) % 3)) / 3) * 4) + 1);
2094 <
2095 <  /* process 24 bits at a time */
2096 <  for( i = 0; i < len; i += 3)
2097 <  {
2098 <    q_in = 0;
2099 <
2100 <    if ( i + 2 < len )
2101 <    {
2102 <      q_in  = (in[i+2] & 0xc0) << 2;
2103 <      q_in |=  in[i+2];
2104 <    }
2105 <
2106 <    if ( i + 1 < len )
2107 <    {
2108 <      q_in |= (in[i+1] & 0x0f) << 10;
2109 <      q_in |= (in[i+1] & 0xf0) << 12;
2110 <    }
2111 <
2112 <    q_in |= (in[i]   & 0x03) << 20;
2113 <    q_in |=  in[i]           << 22;
2114 <
2115 <    q_in &= 0x3f3f3f3f;
2116 <
2117 <    out[count++] = base64_chars[((q_in >> 24)       )];
2118 <    out[count++] = base64_chars[((q_in >> 16) & 0xff)];
2119 <    out[count++] = base64_chars[((q_in >>  8) & 0xff)];
2120 <    out[count++] = base64_chars[((q_in      ) & 0xff)];
2121 <  }
2122 <  if ( (i - len) > 0 )
2123 <  {
2124 <    out[count-1] = '=';
2125 <    if ( (i - len) > 1 )
2126 <      out[count-2] = '=';
2127 <  }
2128 <
2129 <  out[count] = '\0';
2130 <  *output = out;
2131 <  return (count);
2132 < }
2133 <
2134 < /*
2135 < * unbase64_block will allocate and return a new block of memory
2136 < * using MyMalloc().  It should be freed after use.
2137 < */
2138 < int
2139 < unbase64_block(unsigned char **output, char *data, int len)
2140 < {
2141 <  unsigned char *out;
2142 <  unsigned char *in = (unsigned char*)data;
2143 <  unsigned long int q_in;
2144 <  int i;
2145 <  int count = 0;
2146 <
2147 <  if ((len % 4) != 0)
2148 <    return (0);
2149 <
2150 <  out = MyMalloc(((len / 4) * 3) + 1);
2151 <
2152 <  /* process 32 bits at a time */
2153 <  for( i = 0; (i + 3) < len; i+=4)
2154 <  {
2155 <    /* compress input (chars a, b, c and d) as follows:
2156 <     * (after converting ascii -> base64 value)
2157 <     *
2158 <     * |00000000aaaaaabbbbbbccccccdddddd|
2159 <     * |  765432  107654  321076  543210|
2160 <     */
2161 <
2162 <    q_in = 0;
2163 <
2164 <    if (base64_values[in[i+3]] > -1)
2165 <      q_in |= base64_values[in[i+3]]      ;
2166 <    if (base64_values[in[i+2]] > -1)
2167 <      q_in |= base64_values[in[i+2]] <<  6;
2168 <    if (base64_values[in[i+1]] > -1)
2169 <      q_in |= base64_values[in[i+1]] << 12;
2170 <    if (base64_values[in[i  ]] > -1)
2171 <      q_in |= base64_values[in[i  ]] << 18;
2172 <
2173 <    out[count++] = (q_in >> 16) & 0xff;
2174 <    out[count++] = (q_in >>  8) & 0xff;
2175 <    out[count++] = (q_in      ) & 0xff;
2176 <  }
2177 <
2178 <  if (in[i-1] == '=') count--;
2179 <  if (in[i-2] == '=') count--;
2180 <
2181 <  out[count] = '\0';
2182 <  *output = out;
2183 <  return (count);
1430 >  return NULL;
1431   }
2185
2186 #endif /* HAVE_LIBCRYPTO */
2187

Diff Legend

Removed lines
+ Added lines
< Changed lines (old)
> Changed lines (new)