ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/branches/8.2.x/src/server.c
Revision: 4738
Committed: Sun Oct 12 12:06:42 2014 UTC (9 years, 6 months ago) by michael
Content type: text/x-csrc
File size: 28963 byte(s)
Log Message:
- s_bsd.c:ssl_handshake(): use CONNECTTIMEOUT instead of hardcoded value
- server.c:ssl_server_handshake(): use CONNECTTIMEOUT instead of hardcoded value

File Contents

# Content
1 /*
2 * ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3 *
4 * Copyright (c) 1997-2014 ircd-hybrid development team
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301
19 * USA
20 */
21
22 /*! \file s_serv.c
23 * \brief Server related functions.
24 * \version $Id$
25 */
26
27 #include "stdinc.h"
28 #ifdef HAVE_LIBCRYPTO
29 #include <openssl/rsa.h>
30 #include "rsa.h"
31 #endif
32 #include "list.h"
33 #include "client.h"
34 #include "event.h"
35 #include "hash.h"
36 #include "irc_string.h"
37 #include "ircd.h"
38 #include "ircd_defs.h"
39 #include "s_bsd.h"
40 #include "numeric.h"
41 #include "packet.h"
42 #include "conf.h"
43 #include "server.h"
44 #include "log.h"
45 #include "user.h"
46 #include "send.h"
47 #include "memory.h"
48 #include "channel.h"
49 #include "parse.h"
50
51 #define MIN_CONN_FREQ 300
52
53 dlink_list flatten_links;
54 static dlink_list cap_list = { NULL, NULL, 0 };
55 static void serv_connect_callback(fde_t *, int, void *);
56
57
58 /*
59 * write_links_file
60 *
61 * inputs - void pointer which is not used
62 * output - NONE
63 * side effects - called from an event, write out list of linked servers
64 * but in no particular order.
65 */
66 void
67 write_links_file(void *unused)
68 {
69 FILE *file = NULL;
70 dlink_node *ptr = NULL, *ptr_next = NULL;
71 char buff[IRCD_BUFSIZE] = "";
72
73 if ((file = fopen(LIPATH, "w")) == NULL)
74 return;
75
76 DLINK_FOREACH_SAFE(ptr, ptr_next, flatten_links.head)
77 {
78 dlinkDelete(ptr, &flatten_links);
79 MyFree(ptr->data);
80 free_dlink_node(ptr);
81 }
82
83 DLINK_FOREACH(ptr, global_server_list.head)
84 {
85 const struct Client *target_p = ptr->data;
86
87 /*
88 * Skip hidden servers, aswell as ourselves, since we already send
89 * ourselves in /links
90 */
91 if (IsHidden(target_p) || IsMe(target_p))
92 continue;
93
94 if (HasFlag(target_p, FLAGS_SERVICE) && ConfigServerHide.hide_services)
95 continue;
96
97 /*
98 * Attempt to format the file in such a way it follows the usual links output
99 * ie "servername uplink :hops info"
100 * Mostly for aesthetic reasons - makes it look pretty in mIRC ;)
101 * - madmax
102 */
103 snprintf(buff, sizeof(buff), "%s %s :1 %s", target_p->name,
104 me.name, target_p->info);
105 dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
106 snprintf(buff, sizeof(buff), "%s %s :1 %s\n", target_p->name,
107 me.name, target_p->info);
108
109 fputs(buff, file);
110 }
111
112 fclose(file);
113 }
114
115 void
116 read_links_file(void)
117 {
118 FILE *file = NULL;
119 char *p = NULL;
120 char buff[IRCD_BUFSIZE] = "";
121
122 if ((file = fopen(LIPATH, "r")) == NULL)
123 return;
124
125 while (fgets(buff, sizeof(buff), file))
126 {
127 if ((p = strchr(buff, '\n')))
128 *p = '\0';
129
130 dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
131 }
132
133 fclose(file);
134 }
135
136 /* hunt_server()
137 * Do the basic thing in delivering the message (command)
138 * across the relays to the specific server (server) for
139 * actions.
140 *
141 * Note: The command is a format string and *MUST* be
142 * of prefixed style (e.g. ":%s COMMAND %s ...").
143 * Command can have only max 8 parameters.
144 *
145 * server parv[server] is the parameter identifying the
146 * target server.
147 *
148 * *WARNING*
149 * parv[server] is replaced with the pointer to the
150 * real servername from the matched client (I'm lazy
151 * now --msa).
152 *
153 * returns: (see #defines)
154 */
155 int
156 hunt_server(struct Client *source_p, const char *command,
157 const int server, const int parc, char *parv[])
158 {
159 struct Client *target_p = NULL;
160 dlink_node *ptr = NULL;
161
162 /* Assume it's me, if no server */
163 if (parc <= server || EmptyString(parv[server]))
164 return HUNTED_ISME;
165
166 if ((target_p = find_person(source_p, parv[server])) == NULL)
167 target_p = hash_find_server(parv[server]);
168
169 /*
170 * These are to pickup matches that would cause the following
171 * message to go in the wrong direction while doing quick fast
172 * non-matching lookups.
173 */
174 if (target_p)
175 if (target_p->from == source_p->from && !MyConnect(target_p))
176 target_p = NULL;
177
178 if (!target_p && has_wildcards(parv[server]))
179 {
180 DLINK_FOREACH(ptr, global_client_list.head)
181 {
182 struct Client *tmp = ptr->data;
183
184 assert(IsMe(tmp) || IsServer(tmp) || IsClient(tmp));
185 if (!match(parv[server], tmp->name))
186 {
187 if (tmp->from == source_p->from && !MyConnect(tmp))
188 continue;
189
190 target_p = ptr->data;
191 break;
192 }
193 }
194 }
195
196 if (target_p)
197 {
198 assert(IsMe(target_p) || IsServer(target_p) || IsClient(target_p));
199 if (IsMe(target_p) || MyClient(target_p))
200 return HUNTED_ISME;
201
202 parv[server] = target_p->id;
203 sendto_one(target_p, command, source_p->id,
204 parv[1], parv[2], parv[3], parv[4],
205 parv[5], parv[6], parv[7], parv[8]);
206 return HUNTED_PASS;
207 }
208
209 sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
210 return HUNTED_NOSUCH;
211 }
212
213 /* try_connections()
214 *
215 * inputs - void pointer which is not used
216 * output - NONE
217 * side effects -
218 * scan through configuration and try new connections.
219 * Returns the calendar time when the next call to this
220 * function should be made latest. (No harm done if this
221 * is called earlier or later...)
222 */
223 void
224 try_connections(void *unused)
225 {
226 dlink_node *ptr = NULL;
227 int confrq = 0;
228
229 /* TODO: change this to set active flag to 0 when added to event! --Habeeb */
230 if (GlobalSetOptions.autoconn == 0)
231 return;
232
233 DLINK_FOREACH(ptr, server_items.head)
234 {
235 struct MaskItem *conf = ptr->data;
236
237 assert(conf->type == CONF_SERVER);
238
239 /* Also when already connecting! (update holdtimes) --SRB
240 */
241 if (!conf->port || !IsConfAllowAutoConn(conf))
242 continue;
243
244
245 /* Skip this entry if the use of it is still on hold until
246 * future. Otherwise handle this entry (and set it on hold
247 * until next time). Will reset only hold times, if already
248 * made one successfull connection... [this algorithm is
249 * a bit fuzzy... -- msa >;) ]
250 */
251 if (conf->until > CurrentTime)
252 continue;
253
254 assert(conf->class);
255
256 confrq = conf->class->con_freq;
257 if (confrq < MIN_CONN_FREQ)
258 confrq = MIN_CONN_FREQ;
259
260 conf->until = CurrentTime + confrq;
261
262 /*
263 * Found a CONNECT config with port specified, scan clients
264 * and see if this server is already connected?
265 */
266 if (hash_find_server(conf->name))
267 continue;
268
269 if (conf->class->ref_count < conf->class->max_total)
270 {
271 /* Go to the end of the list, if not already last */
272 if (ptr->next)
273 {
274 dlinkDelete(ptr, &server_items);
275 dlinkAddTail(conf, &conf->node, &server_items);
276 }
277
278 if (find_servconn_in_progress(conf->name))
279 return;
280
281 /*
282 * We used to only print this if serv_connect() actually
283 * succeeded, but since comm_tcp_connect() can call the callback
284 * immediately if there is an error, we were getting error messages
285 * in the wrong order. SO, we just print out the activated line,
286 * and let serv_connect() / serv_connect_callback() print an
287 * error afterwards if it fails.
288 * -- adrian
289 */
290 if (ConfigServerHide.hide_server_ips)
291 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
292 "Connection to %s activated.",
293 conf->name);
294 else
295 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
296 "Connection to %s[%s] activated.",
297 conf->name, conf->host);
298
299 serv_connect(conf, NULL);
300 /* We connect only one at time... */
301 return;
302 }
303 }
304 }
305
306 int
307 valid_servname(const char *name)
308 {
309 unsigned int dots = 0;
310 const char *p = name;
311
312 for (; *p; ++p)
313 {
314 if (!IsServChar(*p))
315 return 0;
316
317 if (*p == '.')
318 ++dots;
319 }
320
321 return dots && (p - name) <= HOSTLEN;
322 }
323
324 int
325 check_server(const char *name, struct Client *client_p)
326 {
327 dlink_node *ptr;
328 struct MaskItem *conf = NULL;
329 struct MaskItem *server_conf = NULL;
330 int error = -1;
331
332 assert(client_p);
333
334 /* loop through looking for all possible connect items that might work */
335 DLINK_FOREACH(ptr, server_items.head)
336 {
337 conf = ptr->data;
338
339 if (match(name, conf->name))
340 continue;
341
342 error = -3;
343
344 /* XXX: Fix me for IPv6 */
345 /* XXX sockhost is the IPv4 ip as a string */
346 if (!match(conf->host, client_p->host) ||
347 !match(conf->host, client_p->sockhost))
348 {
349 error = -2;
350
351 if (!match_conf_password(client_p->connection->password, conf))
352 return -2;
353
354 if (!EmptyString(conf->certfp))
355 if (EmptyString(client_p->certfp) || strcasecmp(client_p->certfp, conf->certfp))
356 return -4;
357
358 server_conf = conf;
359 }
360 }
361
362 if (server_conf == NULL)
363 return error;
364
365 attach_conf(client_p, server_conf);
366
367
368 if (server_conf)
369 {
370 struct sockaddr_in *v4;
371 struct sockaddr_in6 *v6;
372
373 switch (server_conf->aftype)
374 {
375 case AF_INET6:
376 v6 = (struct sockaddr_in6 *)&server_conf->addr;
377
378 if (IN6_IS_ADDR_UNSPECIFIED(&v6->sin6_addr))
379 memcpy(&server_conf->addr, &client_p->connection->ip, sizeof(struct irc_ssaddr));
380 break;
381 case AF_INET:
382 v4 = (struct sockaddr_in *)&server_conf->addr;
383
384 if (v4->sin_addr.s_addr == INADDR_NONE)
385 memcpy(&server_conf->addr, &client_p->connection->ip, sizeof(struct irc_ssaddr));
386 break;
387 }
388 }
389
390 return 0;
391 }
392
393 /* add_capability()
394 *
395 * inputs - string name of CAPAB
396 * - int flag of capability
397 * output - NONE
398 * side effects - Adds given capability name and bit mask to
399 * current supported capabilities. This allows
400 * modules to dynamically add or subtract their capability.
401 */
402 void
403 add_capability(const char *capab_name, int cap_flag, int add_to_default)
404 {
405 struct Capability *cap = MyCalloc(sizeof(*cap));
406
407 cap->name = xstrdup(capab_name);
408 cap->cap = cap_flag;
409 dlinkAdd(cap, &cap->node, &cap_list);
410
411 if (add_to_default)
412 default_server_capabs |= cap_flag;
413 }
414
415 /* delete_capability()
416 *
417 * inputs - string name of CAPAB
418 * output - NONE
419 * side effects - delete given capability from ones known.
420 */
421 int
422 delete_capability(const char *capab_name)
423 {
424 dlink_node *ptr = NULL, *ptr_next = NULL;
425
426 DLINK_FOREACH_SAFE(ptr, ptr_next, cap_list.head)
427 {
428 struct Capability *cap = ptr->data;
429
430 if (cap->cap)
431 {
432 if (!irccmp(cap->name, capab_name))
433 {
434 default_server_capabs &= ~(cap->cap);
435 dlinkDelete(ptr, &cap_list);
436 MyFree(cap->name);
437 MyFree(cap);
438 }
439 }
440 }
441
442 return 0;
443 }
444
445 /*
446 * find_capability()
447 *
448 * inputs - string name of capab to find
449 * output - 0 if not found CAPAB otherwise
450 * side effects - none
451 */
452 unsigned int
453 find_capability(const char *capab)
454 {
455 const dlink_node *ptr = NULL;
456
457 DLINK_FOREACH(ptr, cap_list.head)
458 {
459 const struct Capability *cap = ptr->data;
460
461 if (cap->cap && !irccmp(cap->name, capab))
462 return cap->cap;
463 }
464
465 return 0;
466 }
467
468 /* send_capabilities()
469 *
470 * inputs - Client pointer to send to
471 * - int flag of capabilities that this server can send
472 * output - NONE
473 * side effects - send the CAPAB line to a server -orabidoo
474 *
475 */
476 void
477 send_capabilities(struct Client *client_p, int cap_can_send)
478 {
479 char buf[IRCD_BUFSIZE] = "";
480 const dlink_node *ptr = NULL;
481
482 DLINK_FOREACH(ptr, cap_list.head)
483 {
484 const struct Capability *cap = ptr->data;
485
486 if (cap->cap & (cap_can_send|default_server_capabs))
487 {
488 strlcat(buf, cap->name, sizeof(buf));
489 if (ptr->next)
490 strlcat(buf, " ", sizeof(buf));
491 }
492 }
493
494 sendto_one(client_p, "CAPAB :%s", buf);
495 }
496
497 /*
498 * show_capabilities - show current server capabilities
499 *
500 * inputs - pointer to a struct Client
501 * output - pointer to static string
502 * side effects - build up string representing capabilities of server listed
503 */
504 const char *
505 show_capabilities(const struct Client *target_p)
506 {
507 static char msgbuf[IRCD_BUFSIZE] = "";
508 const dlink_node *ptr = NULL;
509
510 strlcpy(msgbuf, "TS", sizeof(msgbuf));
511
512 DLINK_FOREACH(ptr, cap_list.head)
513 {
514 const struct Capability *cap = ptr->data;
515
516 if (!IsCapable(target_p, cap->cap))
517 continue;
518
519 strlcat(msgbuf, " ", sizeof(msgbuf));
520 strlcat(msgbuf, cap->name, sizeof(msgbuf));
521 }
522
523 return msgbuf;
524 }
525
526 /* make_server()
527 *
528 * inputs - pointer to client struct
529 * output - pointer to struct Server
530 * side effects - add's an Server information block to a client
531 * if it was not previously allocated.
532 */
533 struct Server *
534 make_server(struct Client *client_p)
535 {
536 if (client_p->serv == NULL)
537 client_p->serv = MyCalloc(sizeof(struct Server));
538
539 return client_p->serv;
540 }
541
542 /* New server connection code
543 * Based upon the stuff floating about in s_bsd.c
544 * -- adrian
545 */
546
547 /* serv_connect() - initiate a server connection
548 *
549 * inputs - pointer to conf
550 * - pointer to client doing the connect
551 * output -
552 * side effects -
553 *
554 * This code initiates a connection to a server. It first checks to make
555 * sure the given server exists. If this is the case, it creates a socket,
556 * creates a client, saves the socket information in the client, and
557 * initiates a connection to the server through comm_connect_tcp(). The
558 * completion of this goes through serv_completed_connection().
559 *
560 * We return 1 if the connection is attempted, since we don't know whether
561 * it suceeded or not, and 0 if it fails in here somewhere.
562 */
563 int
564 serv_connect(struct MaskItem *conf, struct Client *by)
565 {
566 struct Client *client_p = NULL;
567 char buf[HOSTIPLEN + 1] = "";
568
569 /* conversion structs */
570 struct sockaddr_in *v4;
571
572 /* Make sure conf is useful */
573 assert(conf);
574
575 getnameinfo((struct sockaddr *)&conf->addr, conf->addr.ss_len,
576 buf, sizeof(buf), NULL, 0, NI_NUMERICHOST);
577 ilog(LOG_TYPE_IRCD, "Connect to %s[%s] @%s", conf->name, conf->host,
578 buf);
579
580 /* Still processing a DNS lookup? -> exit */
581 if (conf->dns_pending)
582 {
583 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
584 "Error connecting to %s: DNS lookup for connect{} in progress.",
585 conf->name);
586 return 0;
587 }
588
589 if (conf->dns_failed)
590 {
591 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
592 "Error connecting to %s: DNS lookup for connect{} failed.",
593 conf->name);
594 return 0;
595 }
596
597 /* Make sure this server isn't already connected
598 * Note: conf should ALWAYS be a valid C: line
599 */
600 if ((client_p = hash_find_server(conf->name)))
601 {
602 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
603 "Server %s already present from %s",
604 conf->name, get_client_name(client_p, SHOW_IP));
605 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
606 "Server %s already present from %s",
607 conf->name, get_client_name(client_p, MASK_IP));
608 if (by && IsClient(by) && !MyClient(by))
609 sendto_one_notice(by, &me, ":Server %s already present from %s",
610 conf->name, get_client_name(client_p, MASK_IP));
611 return 0;
612 }
613
614 /* Create a local client */
615 client_p = make_client(NULL);
616
617 /* Copy in the server, hostname, fd */
618 strlcpy(client_p->name, conf->name, sizeof(client_p->name));
619 strlcpy(client_p->host, conf->host, sizeof(client_p->host));
620
621 /* We already converted the ip once, so lets use it - stu */
622 strlcpy(client_p->sockhost, buf, sizeof(client_p->sockhost));
623
624 /* create a socket for the server connection */
625 if (comm_open(&client_p->connection->fd, conf->addr.ss.ss_family, SOCK_STREAM, 0, NULL) < 0)
626 {
627 /* Eek, failure to create the socket */
628 report_error(L_ALL, "opening stream socket to %s: %s", conf->name, errno);
629
630 SetDead(client_p);
631 exit_client(client_p, "Connection failed");
632 return 0;
633 }
634
635 /* servernames are always guaranteed under HOSTLEN chars */
636 fd_note(&client_p->connection->fd, "Server: %s", conf->name);
637
638 /* Attach config entries to client here rather than in
639 * serv_connect_callback(). This to avoid null pointer references.
640 */
641 if (!attach_connect_block(client_p, conf->name, conf->host))
642 {
643 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
644 "Host %s is not enabled for connecting: no connect {} block",
645 conf->name);
646 if (by && IsClient(by) && !MyClient(by))
647 sendto_one_notice(by, &me, ":Connect to host %s failed: no connect {} block", client_p->name);
648
649 SetDead(client_p);
650 exit_client(client_p, "Connection failed");
651 return 0;
652 }
653
654 /* at this point we have a connection in progress and C/N lines
655 * attached to the client, the socket info should be saved in the
656 * client and it should either be resolved or have a valid address.
657 *
658 * The socket has been connected or connect is in progress.
659 */
660 make_server(client_p);
661
662 if (by && IsClient(by))
663 strlcpy(client_p->serv->by, by->name, sizeof(client_p->serv->by));
664 else
665 strlcpy(client_p->serv->by, "AutoConn.", sizeof(client_p->serv->by));
666
667 SetConnecting(client_p);
668 client_p->connection->aftype = conf->aftype;
669
670 /* Now, initiate the connection */
671 /* XXX assume that a non 0 type means a specific bind address
672 * for this connect.
673 */
674 switch (conf->aftype)
675 {
676 case AF_INET:
677 v4 = (struct sockaddr_in*)&conf->bind;
678 if (v4->sin_addr.s_addr)
679 {
680 struct irc_ssaddr ipn;
681 memset(&ipn, 0, sizeof(struct irc_ssaddr));
682 ipn.ss.ss_family = AF_INET;
683 ipn.ss_port = 0;
684 memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
685 comm_connect_tcp(&client_p->connection->fd, conf->host, conf->port,
686 (struct sockaddr *)&ipn, ipn.ss_len,
687 serv_connect_callback, client_p, conf->aftype,
688 CONNECTTIMEOUT);
689 }
690 else if (ConfigServerInfo.specific_ipv4_vhost)
691 {
692 struct irc_ssaddr ipn;
693 memset(&ipn, 0, sizeof(struct irc_ssaddr));
694 ipn.ss.ss_family = AF_INET;
695 ipn.ss_port = 0;
696 memcpy(&ipn, &ConfigServerInfo.ip, sizeof(struct irc_ssaddr));
697 comm_connect_tcp(&client_p->connection->fd, conf->host, conf->port,
698 (struct sockaddr *)&ipn, ipn.ss_len,
699 serv_connect_callback, client_p, conf->aftype,
700 CONNECTTIMEOUT);
701 }
702 else
703 comm_connect_tcp(&client_p->connection->fd, conf->host, conf->port,
704 NULL, 0, serv_connect_callback, client_p, conf->aftype,
705 CONNECTTIMEOUT);
706 break;
707 case AF_INET6:
708 {
709 struct irc_ssaddr ipn;
710 struct sockaddr_in6 *v6;
711 struct sockaddr_in6 *v6conf;
712
713 memset(&ipn, 0, sizeof(struct irc_ssaddr));
714 v6conf = (struct sockaddr_in6 *)&conf->bind;
715 v6 = (struct sockaddr_in6 *)&ipn;
716
717 if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr, sizeof(struct in6_addr)))
718 {
719 memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
720 ipn.ss.ss_family = AF_INET6;
721 ipn.ss_port = 0;
722 comm_connect_tcp(&client_p->connection->fd,
723 conf->host, conf->port,
724 (struct sockaddr *)&ipn, ipn.ss_len,
725 serv_connect_callback, client_p,
726 conf->aftype, CONNECTTIMEOUT);
727 }
728 else if (ConfigServerInfo.specific_ipv6_vhost)
729 {
730 memcpy(&ipn, &ConfigServerInfo.ip6, sizeof(struct irc_ssaddr));
731 ipn.ss.ss_family = AF_INET6;
732 ipn.ss_port = 0;
733 comm_connect_tcp(&client_p->connection->fd,
734 conf->host, conf->port,
735 (struct sockaddr *)&ipn, ipn.ss_len,
736 serv_connect_callback, client_p,
737 conf->aftype, CONNECTTIMEOUT);
738 }
739 else
740 comm_connect_tcp(&client_p->connection->fd,
741 conf->host, conf->port,
742 NULL, 0, serv_connect_callback, client_p,
743 conf->aftype, CONNECTTIMEOUT);
744 }
745 }
746
747 return 1;
748 }
749
750 #ifdef HAVE_LIBCRYPTO
751 static void
752 finish_ssl_server_handshake(struct Client *client_p)
753 {
754 struct MaskItem *conf = NULL;
755
756 conf = find_conf_name(&client_p->connection->confs,
757 client_p->name, CONF_SERVER);
758 if (conf == NULL)
759 {
760 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
761 "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
762 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
763 "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
764
765 exit_client(client_p, "Lost connect{} block");
766 return;
767 }
768
769 sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
770
771 send_capabilities(client_p, 0);
772
773 sendto_one(client_p, "SERVER %s 1 :%s%s",
774 me.name, ConfigServerHide.hidden ? "(H) " : "",
775 me.info);
776
777 /* If we've been marked dead because a send failed, just exit
778 * here now and save everyone the trouble of us ever existing.
779 */
780 if (IsDead(client_p))
781 {
782 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
783 "%s[%s] went dead during handshake",
784 client_p->name,
785 client_p->host);
786 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
787 "%s went dead during handshake", client_p->name);
788 return;
789 }
790
791 /* don't move to serv_list yet -- we haven't sent a burst! */
792 /* If we get here, we're ok, so lets start reading some data */
793 comm_setselect(&client_p->connection->fd, COMM_SELECT_READ, read_packet, client_p, 0);
794 }
795
796 static void
797 ssl_server_handshake(fde_t *fd, void *data)
798 {
799 struct Client *client_p = data;
800 X509 *cert = NULL;
801 int ret = 0;
802
803 if ((ret = SSL_connect(client_p->connection->fd.ssl)) <= 0)
804 {
805 if ((CurrentTime - client_p->connection->firsttime) > CONNECTTIMEOUT)
806 {
807 exit_client(client_p, "Timeout during SSL handshake");
808 return;
809 }
810
811 switch (SSL_get_error(client_p->connection->fd.ssl, ret))
812 {
813 case SSL_ERROR_WANT_WRITE:
814 comm_setselect(&client_p->connection->fd, COMM_SELECT_WRITE,
815 ssl_server_handshake, client_p, CONNECTTIMEOUT);
816 return;
817 case SSL_ERROR_WANT_READ:
818 comm_setselect(&client_p->connection->fd, COMM_SELECT_READ,
819 ssl_server_handshake, client_p, CONNECTTIMEOUT);
820 return;
821 default:
822 {
823 const char *sslerr = ERR_error_string(ERR_get_error(), NULL);
824 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
825 "Error connecting to %s: %s", client_p->name,
826 sslerr ? sslerr : "unknown SSL error");
827 exit_client(client_p, "Error during SSL handshake");
828 return;
829 }
830 }
831 }
832
833 comm_settimeout(&client_p->connection->fd, 0, NULL, NULL);
834
835 if ((cert = SSL_get_peer_certificate(client_p->connection->fd.ssl)))
836 {
837 int res = SSL_get_verify_result(client_p->connection->fd.ssl);
838 char buf[EVP_MAX_MD_SIZE * 2 + 1] = "";
839 unsigned char md[EVP_MAX_MD_SIZE] = "";
840
841 if (res == X509_V_OK || res == X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN ||
842 res == X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE ||
843 res == X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT)
844 {
845 unsigned int n = 0;
846
847 if (X509_digest(cert, ConfigServerInfo.message_digest_algorithm, md, &n))
848 {
849 binary_to_hex(md, buf, n);
850 client_p->certfp = xstrdup(buf);
851 }
852 }
853 else
854 ilog(LOG_TYPE_IRCD, "Server %s!%s@%s gave bad SSL client certificate: %d",
855 client_p->name, client_p->username, client_p->host, res);
856 X509_free(cert);
857 }
858
859 finish_ssl_server_handshake(client_p);
860 }
861
862 static void
863 ssl_connect_init(struct Client *client_p, struct MaskItem *conf, fde_t *fd)
864 {
865 if ((client_p->connection->fd.ssl = SSL_new(ConfigServerInfo.client_ctx)) == NULL)
866 {
867 ilog(LOG_TYPE_IRCD, "SSL_new() ERROR! -- %s",
868 ERR_error_string(ERR_get_error(), NULL));
869 SetDead(client_p);
870 exit_client(client_p, "SSL_new failed");
871 return;
872 }
873
874 SSL_set_fd(fd->ssl, fd->fd);
875
876 if (!EmptyString(conf->cipher_list))
877 SSL_set_cipher_list(client_p->connection->fd.ssl, conf->cipher_list);
878
879 ssl_server_handshake(NULL, client_p);
880 }
881 #endif
882
883 /* serv_connect_callback() - complete a server connection.
884 *
885 * This routine is called after the server connection attempt has
886 * completed. If unsucessful, an error is sent to ops and the client
887 * is closed. If sucessful, it goes through the initialisation/check
888 * procedures, the capabilities are sent, and the socket is then
889 * marked for reading.
890 */
891 static void
892 serv_connect_callback(fde_t *fd, int status, void *data)
893 {
894 struct Client *client_p = data;
895 struct MaskItem *conf = NULL;
896
897 /* First, make sure it's a real client! */
898 assert(client_p);
899 assert(&client_p->connection->fd == fd);
900
901 /* Next, for backward purposes, record the ip of the server */
902 memcpy(&client_p->connection->ip, &fd->connect.hostaddr,
903 sizeof(struct irc_ssaddr));
904
905 /* Check the status */
906 if (status != COMM_OK)
907 {
908 /* We have an error, so report it and quit
909 * Admins get to see any IP, mere opers don't *sigh*
910 */
911 if (ConfigServerHide.hide_server_ips)
912 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
913 "Error connecting to %s: %s",
914 client_p->name, comm_errstr(status));
915 else
916 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
917 "Error connecting to %s[%s]: %s", client_p->name,
918 client_p->host, comm_errstr(status));
919
920 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
921 "Error connecting to %s: %s",
922 client_p->name, comm_errstr(status));
923
924 /* If a fd goes bad, call dead_link() the socket is no
925 * longer valid for reading or writing.
926 */
927 dead_link_on_write(client_p, 0);
928 return;
929 }
930
931 /* COMM_OK, so continue the connection procedure */
932 /* Get the C/N lines */
933 conf = find_conf_name(&client_p->connection->confs,
934 client_p->name, CONF_SERVER);
935 if (conf == NULL)
936 {
937 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
938 "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
939 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
940 "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
941
942 exit_client(client_p, "Lost connect{} block");
943 return;
944 }
945
946 /* Next, send the initial handshake */
947 SetHandshake(client_p);
948
949 #ifdef HAVE_LIBCRYPTO
950 if (IsConfSSL(conf))
951 {
952 ssl_connect_init(client_p, conf, fd);
953 return;
954 }
955 #endif
956
957 sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
958
959 send_capabilities(client_p, 0);
960
961 sendto_one(client_p, "SERVER %s 1 :%s%s", me.name,
962 ConfigServerHide.hidden ? "(H) " : "", me.info);
963
964 /* If we've been marked dead because a send failed, just exit
965 * here now and save everyone the trouble of us ever existing.
966 */
967 if (IsDead(client_p))
968 {
969 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
970 "%s[%s] went dead during handshake",
971 client_p->name,
972 client_p->host);
973 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
974 "%s went dead during handshake", client_p->name);
975 return;
976 }
977
978 /* don't move to serv_list yet -- we haven't sent a burst! */
979 /* If we get here, we're ok, so lets start reading some data */
980 comm_setselect(fd, COMM_SELECT_READ, read_packet, client_p, 0);
981 }
982
983 struct Client *
984 find_servconn_in_progress(const char *name)
985 {
986 dlink_node *ptr;
987 struct Client *cptr;
988
989 DLINK_FOREACH(ptr, unknown_list.head)
990 {
991 cptr = ptr->data;
992
993 if (cptr && cptr->name[0])
994 if (!match(name, cptr->name))
995 return cptr;
996 }
997
998 return NULL;
999 }

Properties

Name Value
svn:eol-style native
svn:keywords Id Revision