ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf.c
Revision: 9234
Committed: Fri Jan 31 17:38:34 2020 UTC (4 years, 1 month ago) by michael
Content type: text/x-csrc
File size: 38977 byte(s)
Log Message:
- Extbans have been implemented. Main implementation done by Adam for p4.
  Currently supported extbans:

  Matching:

   $a:<account>   Matches users logged into a matching account.
   $c:<channel>   Matches users that are on the given channel. An additional
                  prefix of either @, %, or + can be specified to test for
                  certain channel privileges.
   $o:<class>     Matches IRC operators that have joined a class
                  matching the mask.
   $r:<realname>  Matches users with a matching realname.
   $s:<server>    Matches users that are connected to a server matching the mask.
   $u:<modes>     Matches users having the specified user modes set or not set.
   $z:<certfp>    Matches users having the given TLS certificate fingerprint.

  Acting:

   $j:<banmask>   Prevents matching users from joining the channel.
   $m:<banmask>   Blocks messages from matching users. Users with voice
                  or above are not affected.

File Contents

# User Rev Content
1 adx 30 /*
2 michael 2916 * ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3 adx 30 *
4 michael 9101 * Copyright (c) 1997-2020 ircd-hybrid development team
5 adx 30 *
6     * This program is free software; you can redistribute it and/or modify
7     * it under the terms of the GNU General Public License as published by
8     * the Free Software Foundation; either version 2 of the License, or
9     * (at your option) any later version.
10     *
11     * This program is distributed in the hope that it will be useful,
12     * but WITHOUT ANY WARRANTY; without even the implied warranty of
13     * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14     * GNU General Public License for more details.
15     *
16     * You should have received a copy of the GNU General Public License
17     * along with this program; if not, write to the Free Software
18 michael 4565 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301
19 adx 30 * USA
20     */
21    
22 michael 2916 /*! \file conf.c
23     * \brief Configuration file functions.
24     * \version $Id$
25     */
26    
27 adx 30 #include "stdinc.h"
28 michael 1011 #include "list.h"
29 adx 30 #include "ircd_defs.h"
30 michael 8458 #include "parse.h"
31 michael 1309 #include "conf.h"
32 michael 7217 #include "conf_cluster.h"
33 michael 7304 #include "conf_gecos.h"
34 michael 4545 #include "conf_pseudo.h"
35 michael 7234 #include "conf_resv.h"
36 michael 7248 #include "conf_service.h"
37 michael 7209 #include "conf_shared.h"
38 michael 3347 #include "server.h"
39 adx 30 #include "channel.h"
40     #include "client.h"
41     #include "event.h"
42     #include "irc_string.h"
43     #include "s_bsd.h"
44     #include "ircd.h"
45     #include "listener.h"
46     #include "hostmask.h"
47     #include "modules.h"
48     #include "numeric.h"
49     #include "fdlist.h"
50 michael 1309 #include "log.h"
51 adx 30 #include "send.h"
52     #include "memory.h"
53 michael 3322 #include "res.h"
54 michael 3347 #include "user.h"
55 adx 30 #include "channel_mode.h"
56 michael 3347 #include "misc.h"
57 michael 1622 #include "conf_db.h"
58 michael 1632 #include "conf_class.h"
59 michael 2150 #include "motd.h"
60 michael 4325 #include "ipcache.h"
61 michael 6185 #include "isupport.h"
62 michael 7437 #include "whowas.h"
63 adx 30
64 michael 2872
65 michael 5602 struct config_channel_entry ConfigChannel;
66 michael 5644 struct config_serverhide_entry ConfigServerHide;
67 michael 5602 struct config_general_entry ConfigGeneral;
68 michael 5644 struct config_log_entry ConfigLog = { .use_logging = 1 };
69     struct config_serverinfo_entry ConfigServerInfo;
70     struct config_admin_entry ConfigAdminInfo;
71 michael 5602 struct conf_parser_context conf_parser_ctx;
72    
73 adx 30 /* general conf items link list root, other than k lines etc. */
74 michael 7401 dlink_list connect_items;
75 michael 6628 dlink_list operator_items;
76 adx 30
77     extern unsigned int lineno;
78     extern char linebuf[];
79     extern char conffilebuf[IRCD_BUFSIZE];
80     extern int yyparse(); /* defined in y.tab.c */
81    
82    
83     /* conf_dns_callback()
84     *
85 michael 1632 * inputs - pointer to struct MaskItem
86 adx 30 * - pointer to DNSReply reply
87     * output - none
88     * side effects - called when resolver query finishes
89     * if the query resulted in a successful search, hp will contain
90     * a non-null pointer, otherwise hp will be null.
91     * if successful save hp in the conf item it was called with
92     */
93     static void
94 michael 4408 conf_dns_callback(void *vptr, const struct irc_ssaddr *addr, const char *name, size_t namelength)
95 adx 30 {
96 michael 4874 struct MaskItem *const conf = vptr;
97 adx 30
98 michael 8658 conf->dns_pending = false;
99 adx 30
100 michael 3235 if (addr)
101 michael 9116 *conf->addr = *addr;
102 michael 992 else
103 michael 8658 conf->dns_failed = true;
104 adx 30 }
105    
106 michael 9114 /* conf_resolve_host()
107 adx 30 *
108 michael 9114 * start DNS lookups of all hostnames in the conf
109     * line and convert an IP addresses in a.b.c.d number for to IP#s.
110 adx 30 */
111 michael 9114 void
112 michael 1632 conf_dns_lookup(struct MaskItem *conf)
113 adx 30 {
114 michael 9114 struct addrinfo hints, *res;
115    
116     /*
117     * Do name lookup now on hostnames given and store the
118     * ip numbers in conf structure.
119     */
120     memset(&hints, 0, sizeof(hints));
121    
122     hints.ai_family = AF_UNSPEC;
123     hints.ai_socktype = SOCK_STREAM;
124    
125     /* Get us ready for a bind() and don't bother doing dns lookup */
126     hints.ai_flags = AI_PASSIVE | AI_NUMERICHOST;
127    
128     if (getaddrinfo(conf->host, NULL, &hints, &res))
129     {
130     /*
131     * By this point conf->host possibly is not a numerical network address. Do a nameserver
132     * lookup of the conf host. If the conf entry is currently doing a ns lookup do nothing.
133     */
134     if (conf->dns_pending == true)
135     return;
136    
137     conf->dns_pending = true;
138    
139     if (conf->aftype == AF_INET)
140     gethost_byname_type(conf_dns_callback, conf, conf->host, T_A);
141     else
142     gethost_byname_type(conf_dns_callback, conf, conf->host, T_AAAA);
143 michael 4982 return;
144 michael 9114 }
145 michael 4982
146 michael 9114 assert(res);
147 michael 4982
148 michael 9114 memcpy(conf->addr, res->ai_addr, res->ai_addrlen);
149     conf->addr->ss_len = res->ai_addrlen;
150    
151     freeaddrinfo(res);
152 michael 4982 }
153    
154     /* map_to_list()
155     *
156     * inputs - ConfType conf
157     * output - pointer to dlink_list to use
158     * side effects - none
159     */
160     static dlink_list *
161     map_to_list(enum maskitem_type type)
162     {
163     switch (type)
164 adx 30 {
165 michael 4982 case CONF_OPER:
166 michael 6628 return &operator_items;
167 michael 4982 break;
168     case CONF_SERVER:
169 michael 7401 return &connect_items;
170 michael 4982 break;
171     default:
172     return NULL;
173 adx 30 }
174     }
175    
176 michael 1632 struct MaskItem *
177     conf_make(enum maskitem_type type)
178     {
179 michael 7032 struct MaskItem *const conf = xcalloc(sizeof(*conf));
180 michael 1632 dlink_list *list = NULL;
181    
182     conf->type = type;
183 michael 8658 conf->active = true;
184 michael 1632 conf->aftype = AF_INET;
185    
186     if ((list = map_to_list(type)))
187     dlinkAdd(conf, &conf->node, list);
188     return conf;
189     }
190    
191     void
192     conf_free(struct MaskItem *conf)
193     {
194 michael 4815 dlink_node *node = NULL, *node_next = NULL;
195 michael 1636 dlink_list *list = NULL;
196    
197 michael 4511 if ((list = map_to_list(conf->type)))
198 michael 4523 dlinkFindDelete(list, conf);
199 michael 4511
200 michael 7032 xfree(conf->name);
201 michael 1632
202 michael 8658 if (conf->dns_pending == true)
203 michael 1632 delete_resolver_queries(conf);
204 michael 3235 if (conf->passwd)
205 michael 1632 memset(conf->passwd, 0, strlen(conf->passwd));
206 michael 3235 if (conf->spasswd)
207 michael 1632 memset(conf->spasswd, 0, strlen(conf->spasswd));
208    
209     conf->class = NULL;
210    
211 michael 7032 xfree(conf->passwd);
212     xfree(conf->spasswd);
213     xfree(conf->reason);
214     xfree(conf->certfp);
215     xfree(conf->whois);
216     xfree(conf->user);
217     xfree(conf->host);
218 michael 8872 xfree(conf->addr);
219     xfree(conf->bind);
220 michael 7032 xfree(conf->cipher_list);
221 michael 1632
222 michael 4815 DLINK_FOREACH_SAFE(node, node_next, conf->hub_list.head)
223 michael 1632 {
224 michael 7032 xfree(node->data);
225 michael 4815 dlinkDelete(node, &conf->hub_list);
226     free_dlink_node(node);
227 michael 1632 }
228    
229 michael 4815 DLINK_FOREACH_SAFE(node, node_next, conf->leaf_list.head)
230 michael 1632 {
231 michael 7032 xfree(node->data);
232 michael 4815 dlinkDelete(node, &conf->leaf_list);
233     free_dlink_node(node);
234 michael 1632 }
235 adx 30
236 michael 7032 xfree(conf);
237 adx 30 }
238    
239 michael 4982 /* attach_iline()
240 adx 30 *
241 michael 4982 * inputs - client pointer
242     * - conf pointer
243     * output -
244     * side effects - do actual attach
245 adx 30 */
246 michael 4982 static int
247     attach_iline(struct Client *client_p, struct MaskItem *conf)
248 adx 30 {
249 michael 4982 const struct ClassItem *const class = conf->class;
250 michael 8658 bool a_limit_reached = false;
251 michael 2916
252 michael 8593 struct ip_entry *ipcache = ipcache_record_find_or_add(&client_p->ip);
253 michael 8496 ++ipcache->count_local;
254 michael 4982 AddFlag(client_p, FLAGS_IPHASH);
255 adx 30
256 michael 4982 if (class->max_total && class->ref_count >= class->max_total)
257 michael 8658 a_limit_reached = true;
258 michael 8496 else if (class->max_perip_local && ipcache->count_local > class->max_perip_local)
259 michael 8658 a_limit_reached = true;
260 michael 8496 else if (class->max_perip_global &&
261     (ipcache->count_local + ipcache->count_remote) > class->max_perip_global)
262 michael 8658 a_limit_reached = true;
263 adx 30
264 michael 8658 if (a_limit_reached == true)
265 michael 4982 {
266     if (!IsConfExemptLimits(conf))
267     return TOO_MANY; /* Already at maximum allowed */
268 adx 30
269 michael 4982 sendto_one_notice(client_p, &me, ":*** Your connection class is full, "
270     "but you have exceed_limit = yes;");
271 adx 30 }
272    
273 michael 8395 return conf_attach(client_p, conf);
274 adx 30 }
275    
276     /* verify_access()
277     *
278 michael 4982 * inputs - pointer to client to verify
279     * output - 0 if success -'ve if not
280     * side effect - find the first (best) I line to attach.
281 adx 30 */
282     static int
283 michael 1644 verify_access(struct Client *client_p)
284 adx 30 {
285 michael 8727 struct MaskItem *conf;
286 adx 30
287 michael 6313 if (HasFlag(client_p, FLAGS_GOTID))
288 michael 8727 conf = find_address_conf(client_p->host, client_p->username, &client_p->ip,
289 michael 4588 client_p->connection->password);
290 adx 30 else
291     {
292 michael 5583 char non_ident[USERLEN + 1] = "~";
293    
294 michael 2182 strlcpy(non_ident + 1, client_p->username, sizeof(non_ident) - 1);
295 michael 8727 conf = find_address_conf(client_p->host, non_ident, &client_p->ip,
296 michael 4588 client_p->connection->password);
297 adx 30 }
298    
299 michael 8727 if (conf == NULL)
300 michael 5805 return NOT_AUTHORIZED;
301    
302     assert(IsConfClient(conf) || IsConfKill(conf));
303    
304 michael 8727 if (IsConfKill(conf))
305 adx 30 {
306 michael 8727 sendto_one_notice(client_p, &me, ":*** Banned: %s", conf->reason);
307     return BANNED_CLIENT;
308     }
309 adx 30
310 michael 8727 if (IsConfRedir(conf))
311     {
312     sendto_one_numeric(client_p, &me, RPL_REDIR,
313     conf->name ? conf->name : "",
314     conf->port);
315     return NOT_AUTHORIZED;
316     }
317 michael 4982
318 michael 8727 if (IsConfDoSpoofIp(conf))
319     {
320     if (IsConfSpoofNotice(conf))
321     sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE, "%s spoofing: %s as %s",
322     client_p->name, client_p->host, conf->name);
323 michael 4982
324 michael 8727 strlcpy(client_p->host, conf->name, sizeof(client_p->host));
325 adx 30 }
326    
327 michael 8727 return attach_iline(client_p, conf);
328 adx 30 }
329    
330 michael 4982 /* check_client()
331 adx 30 *
332 michael 4982 * inputs - pointer to client
333     * output - 0 = Success
334     * NOT_AUTHORIZED (-1) = Access denied (no I line match)
335     * IRCD_SOCKET_ERROR (-2) = Bad socket.
336     * I_LINE_FULL (-3) = I-line is full
337     * TOO_MANY (-4) = Too many connections from hostname
338     * BANNED_CLIENT (-5) = K-lined
339     * side effects - Ordinary client access check.
340     * Look for conf lines which have the same
341     * status as the flags passed.
342 adx 30 */
343 michael 9107 bool
344 michael 9110 conf_check_client(struct Client *source_p)
345 adx 30 {
346 michael 4982 int i;
347 adx 30
348 michael 4982 if ((i = verify_access(source_p)))
349     ilog(LOG_TYPE_IRCD, "Access denied: %s[%s]",
350     source_p->name, source_p->sockhost);
351 adx 30
352 michael 4982 switch (i)
353     {
354     case TOO_MANY:
355     sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE,
356     "Too many on IP for %s (%s).",
357 michael 7997 client_get_name(source_p, SHOW_IP),
358 michael 4982 source_p->sockhost);
359     ilog(LOG_TYPE_IRCD, "Too many connections on IP from %s.",
360 michael 7997 client_get_name(source_p, SHOW_IP));
361 michael 4982 ++ServerStats.is_ref;
362     exit_client(source_p, "No more connections allowed on that IP");
363     break;
364 adx 30
365 michael 4982 case I_LINE_FULL:
366     sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE,
367     "auth {} block is full for %s (%s).",
368 michael 7997 client_get_name(source_p, SHOW_IP),
369 michael 4982 source_p->sockhost);
370     ilog(LOG_TYPE_IRCD, "Too many connections from %s.",
371 michael 7997 client_get_name(source_p, SHOW_IP));
372 michael 4982 ++ServerStats.is_ref;
373     exit_client(source_p, "No more connections allowed in your connection class");
374     break;
375 adx 30
376 michael 4982 case NOT_AUTHORIZED:
377     /* jdc - lists server name & port connections are on */
378     /* a purely cosmetical change */
379     sendto_realops_flags(UMODE_UNAUTH, L_ALL, SEND_NOTICE,
380 michael 7537 "Unauthorized client connection from %s on [%s/%u].",
381 michael 7997 client_get_name(source_p, SHOW_IP),
382 michael 4982 source_p->connection->listener->name,
383     source_p->connection->listener->port);
384     ilog(LOG_TYPE_IRCD, "Unauthorized client connection from %s on [%s/%u].",
385 michael 7997 client_get_name(source_p, SHOW_IP),
386 michael 4982 source_p->connection->listener->name,
387     source_p->connection->listener->port);
388 adx 30
389 michael 4982 ++ServerStats.is_ref;
390     exit_client(source_p, "You are not authorized to use this server");
391     break;
392    
393     case BANNED_CLIENT:
394     ++ServerStats.is_ref;
395     exit_client(source_p, "Banned");
396     break;
397    
398     case 0:
399     default:
400     break;
401 adx 30 }
402    
403 michael 9107 if (i < 0)
404     return false;
405     return true;
406 adx 30 }
407    
408 michael 8395 /*! \brief Disassociate configuration from the client. Also removes a class
409     * from the list if marked for deleting.
410     * \param client_p Client to operate on
411     * \param type Type of conf to detach
412 adx 30 */
413 michael 1632 void
414 michael 8395 conf_detach(struct Client *client_p, enum maskitem_type type)
415 adx 30 {
416 michael 8395 dlink_node *node, *node_next;
417 adx 30
418 michael 4815 DLINK_FOREACH_SAFE(node, node_next, client_p->connection->confs.head)
419 adx 30 {
420 michael 4815 struct MaskItem *conf = node->data;
421 adx 30
422 michael 1645 assert(conf->type & (CONF_CLIENT | CONF_OPER | CONF_SERVER));
423     assert(conf->ref_count > 0);
424     assert(conf->class->ref_count > 0);
425 adx 30
426 michael 1645 if (!(conf->type & type))
427     continue;
428 michael 671
429 michael 4815 dlinkDelete(node, &client_p->connection->confs);
430     free_dlink_node(node);
431 michael 1644
432 michael 2278 if (conf->type == CONF_CLIENT)
433 michael 8608 class_ip_limit_remove(conf->class, &client_p->ip);
434 adx 30
435 michael 8658 if (--conf->class->ref_count == 0 && conf->class->active == false)
436 michael 1645 {
437     class_free(conf->class);
438     conf->class = NULL;
439 adx 30 }
440 michael 1645
441 michael 8658 if (--conf->ref_count == 0 && conf->active == false)
442 michael 1645 conf_free(conf);
443 adx 30 }
444     }
445    
446 michael 8395 /*! \brief Associate a specific configuration entry to a *local* client (this
447     * is the one which used in accepting the connection). Note, that this
448     * automatically changes the attachment if there was an old one.
449     * \param client_p Client to attach the conf to
450     * \param conf Configuration record to attach
451 adx 30 */
452     int
453 michael 8395 conf_attach(struct Client *client_p, struct MaskItem *conf)
454 adx 30 {
455 michael 4588 if (dlinkFind(&client_p->connection->confs, conf))
456 adx 30 return 1;
457    
458 michael 1632 if (conf->type == CONF_CLIENT)
459 michael 8658 if (class_ip_limit_add(conf->class, &client_p->ip, IsConfExemptLimits(conf)) == true)
460 michael 1394 return TOO_MANY; /* Already at maximum allowed */
461 adx 30
462 michael 1632 conf->class->ref_count++;
463 michael 1644 conf->ref_count++;
464 adx 30
465 michael 4588 dlinkAdd(conf, make_dlink_node(), &client_p->connection->confs);
466 adx 30
467     return 0;
468     }
469    
470     /* find_conf_name()
471     *
472     * inputs - pointer to conf link list to search
473     * - pointer to name to find
474     * - int mask of type of conf to find
475     * output - NULL or pointer to conf found
476     * side effects - find a conf entry which matches the name
477     * and has the given mask.
478     */
479 michael 1632 struct MaskItem *
480     find_conf_name(dlink_list *list, const char *name, enum maskitem_type type)
481 adx 30 {
482 michael 4815 dlink_node *node = NULL;
483 adx 30
484 michael 4815 DLINK_FOREACH(node, list->head)
485 adx 30 {
486 michael 4815 struct MaskItem *conf = node->data;
487 michael 2916
488 adx 30 if (conf->type == type)
489     {
490 michael 4596 if (conf->name && !irccmp(conf->name, name))
491     return conf;
492 adx 30 }
493     }
494    
495     return NULL;
496     }
497    
498 michael 8391 /*! \brief Find a connect {} conf that has a name that matches \a name.
499     * \param name Name to match
500     * \param compare Pointer to function to be used for string matching
501 adx 30 */
502 michael 1632 struct MaskItem *
503 michael 8391 connect_find(const char *name, int (*compare)(const char *, const char *))
504 adx 30 {
505 michael 8391 dlink_node *node;
506 adx 30
507 michael 7401 DLINK_FOREACH(node, connect_items.head)
508 adx 30 {
509 michael 7401 struct MaskItem *conf = node->data;
510 adx 30
511 michael 9202 if (compare(name, conf->name) == 0)
512 michael 7401 return conf;
513     }
514 michael 2916
515 adx 30 return NULL;
516     }
517    
518     /* find_exact_name_conf()
519     *
520     * inputs - type of link list to look in
521     * - pointer to name string to find
522     * - pointer to user
523     * - pointer to host
524 michael 1632 * output - NULL or pointer to found struct MaskItem
525 adx 30 * side effects - looks for an exact match on name field
526     */
527 michael 1632 struct MaskItem *
528 michael 7403 operator_find(const struct Client *who, const char *name)
529 adx 30 {
530 michael 9202 dlink_node *node;
531 adx 30
532 michael 7401 DLINK_FOREACH(node, operator_items.head)
533 adx 30 {
534 michael 7401 struct MaskItem *conf = node->data;
535    
536 michael 9202 if (irccmp(conf->name, name) == 0)
537 adx 30 {
538 michael 9202 if (who == NULL)
539 michael 7401 return conf;
540 michael 1285
541 michael 9202 if (match(conf->user, who->username) == 0)
542 adx 30 {
543 michael 7401 switch (conf->htype)
544 michael 1285 {
545 michael 7401 case HM_HOST:
546 michael 9202 if (match(conf->host, who->host) == 0 || match(conf->host, who->sockhost) == 0)
547     if (conf->class->max_total == 0 || conf->class->ref_count < conf->class->max_total)
548 michael 7401 return conf;
549     break;
550     case HM_IPV4:
551 michael 8500 if (who->ip.ss.ss_family == AF_INET)
552 michael 8872 if (match_ipv4(&who->ip, conf->addr, conf->bits))
553 michael 9202 if (conf->class->max_total == 0 || conf->class->ref_count < conf->class->max_total)
554 michael 1637 return conf;
555 michael 7401 break;
556     case HM_IPV6:
557 michael 8500 if (who->ip.ss.ss_family == AF_INET6)
558 michael 8872 if (match_ipv6(&who->ip, conf->addr, conf->bits))
559 michael 9202 if (conf->class->max_total == 0 || conf->class->ref_count < conf->class->max_total)
560 michael 7401 return conf;
561     break;
562     default:
563     assert(0);
564 michael 1285 }
565 adx 30 }
566     }
567     }
568 michael 2182
569     return NULL;
570 adx 30 }
571    
572 michael 9110 /* conf_set_defaults()
573 adx 30 *
574     * inputs - NONE
575     * output - NONE
576     * side effects - Set default values here.
577     * This is called **PRIOR** to parsing the
578     * configuration file. If you want to do some validation
579     * of values later, put them in validate_conf().
580     */
581     static void
582 michael 9110 conf_set_defaults(void)
583 adx 30 {
584 michael 9202 /*
585     * Verify init_class() ran, this should be an unnecessary check
586     * but it's not much work.
587 adx 30 */
588 michael 1644 assert(class_default == class_get_list()->tail->data);
589 adx 30
590 michael 4340 ConfigServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT);
591     ConfigServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT);
592 michael 5489 ConfigServerInfo.default_max_clients = MAXCLIENTS_MAX;
593 michael 4340 ConfigServerInfo.max_nick_length = 9;
594     ConfigServerInfo.max_topic_length = 80;
595     ConfigServerInfo.hub = 0;
596 michael 4313
597 michael 8510 log_iterate(log_free);
598 michael 1247
599 michael 4340 ConfigLog.use_logging = 1;
600 adx 30
601 michael 9234 ConfigChannel.enable_extbans = 0;
602 michael 1243 ConfigChannel.disable_fake_channels = 0;
603 michael 3860 ConfigChannel.invite_client_count = 10;
604     ConfigChannel.invite_client_time = 300;
605 michael 6792 ConfigChannel.invite_delay_channel = 5;
606 michael 7793 ConfigChannel.invite_expire_time = 1800;
607 michael 3860 ConfigChannel.knock_client_count = 1;
608     ConfigChannel.knock_client_time = 300;
609 adx 30 ConfigChannel.knock_delay_channel = 60;
610 michael 3933 ConfigChannel.max_channels = 25;
611 michael 7766 ConfigChannel.max_invites = 20;
612 michael 8046 ConfigChannel.max_bans = 100;
613     ConfigChannel.max_bans_large = 500;
614 michael 5489 ConfigChannel.default_join_flood_count = 18;
615     ConfigChannel.default_join_flood_time = 6;
616 adx 30
617 michael 1243 ConfigServerHide.flatten_links = 0;
618 michael 6597 ConfigServerHide.flatten_links_delay = 300;
619 michael 1243 ConfigServerHide.hidden = 0;
620     ConfigServerHide.hide_servers = 0;
621 michael 1851 ConfigServerHide.hide_services = 0;
622 michael 1646 ConfigServerHide.hidden_name = xstrdup(NETWORK_NAME_DEFAULT);
623 michael 1243 ConfigServerHide.hide_server_ips = 0;
624 michael 2196 ConfigServerHide.disable_remote_commands = 0;
625 adx 30
626 michael 4340 ConfigGeneral.away_count = 2;
627     ConfigGeneral.away_time = 10;
628 michael 6740 ConfigGeneral.max_watch = 50;
629 michael 7437 ConfigGeneral.whowas_history_length = 15000;
630 michael 4340 ConfigGeneral.cycle_on_host_change = 1;
631 michael 5805 ConfigGeneral.dline_min_cidr = 16;
632     ConfigGeneral.dline_min_cidr6 = 48;
633     ConfigGeneral.kline_min_cidr = 16;
634     ConfigGeneral.kline_min_cidr6 = 48;
635 michael 4340 ConfigGeneral.invisible_on_connect = 1;
636     ConfigGeneral.disable_auth = 0;
637     ConfigGeneral.kill_chase_time_limit = 90;
638     ConfigGeneral.default_floodcount = 8;
639 michael 7858 ConfigGeneral.default_floodtime = 1;
640 michael 4340 ConfigGeneral.failed_oper_notice = 1;
641     ConfigGeneral.dots_in_ident = 0;
642     ConfigGeneral.min_nonwildcard = 4;
643     ConfigGeneral.min_nonwildcard_simple = 3;
644 michael 6740 ConfigGeneral.max_accept = 50;
645 michael 4340 ConfigGeneral.anti_nick_flood = 0;
646     ConfigGeneral.max_nick_time = 20;
647     ConfigGeneral.max_nick_changes = 5;
648     ConfigGeneral.anti_spam_exit_message_time = 0;
649 michael 6956 ConfigGeneral.ts_warn_delta = 30;
650     ConfigGeneral.ts_max_delta = 600;
651 michael 4340 ConfigGeneral.warn_no_connect_block = 1;
652     ConfigGeneral.stats_e_disabled = 0;
653 michael 5025 ConfigGeneral.stats_i_oper_only = 1; /* 1 = masked */
654 michael 4340 ConfigGeneral.stats_k_oper_only = 1; /* 1 = masked */
655 michael 5025 ConfigGeneral.stats_o_oper_only = 1;
656     ConfigGeneral.stats_m_oper_only = 1;
657 michael 4340 ConfigGeneral.stats_P_oper_only = 0;
658     ConfigGeneral.stats_u_oper_only = 0;
659     ConfigGeneral.caller_id_wait = 60;
660 michael 7949 ConfigGeneral.opers_bypass_callerid = 1;
661 michael 4340 ConfigGeneral.pace_wait = 10;
662     ConfigGeneral.pace_wait_simple = 1;
663     ConfigGeneral.short_motd = 0;
664     ConfigGeneral.ping_cookie = 0;
665     ConfigGeneral.no_oper_flood = 0;
666     ConfigGeneral.max_targets = MAX_TARGETS_DEFAULT;
667 michael 5506 ConfigGeneral.oper_only_umodes = UMODE_DEBUG | UMODE_LOCOPS | UMODE_HIDDEN | UMODE_FARCONNECT |
668     UMODE_UNAUTH | UMODE_EXTERNAL | UMODE_BOTS | UMODE_NCHANGE |
669     UMODE_SPY | UMODE_FULL | UMODE_SKILL | UMODE_REJ | UMODE_CCONN;
670 michael 4340 ConfigGeneral.oper_umodes = UMODE_BOTS | UMODE_LOCOPS | UMODE_SERVNOTICE | UMODE_WALLOP;
671     ConfigGeneral.throttle_count = 1;
672     ConfigGeneral.throttle_time = 1;
673 adx 30 }
674    
675     static void
676 michael 9110 conf_validate(void)
677 adx 30 {
678 michael 5039 if (EmptyString(ConfigServerInfo.network_name))
679 michael 4340 ConfigServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT);
680 adx 30
681 michael 5039 if (EmptyString(ConfigServerInfo.network_desc))
682 michael 4340 ConfigServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT);
683 adx 30 }
684    
685 michael 9110 /* conf_read()
686 michael 1363 *
687     * inputs - file descriptor pointing to config file to use
688     * output - None
689     * side effects - Read configuration file.
690     */
691     static void
692 michael 9110 conf_read(FILE *file)
693 michael 1363 {
694 michael 7746 lineno = 1;
695 michael 1363
696 michael 9110 conf_set_defaults(); /* Set default values prior to conf parsing */
697 michael 1363 conf_parser_ctx.pass = 1;
698 michael 3375 yyparse(); /* Pick up the classes first */
699 michael 1363
700     rewind(file);
701    
702     conf_parser_ctx.pass = 2;
703 michael 3375 yyparse(); /* Load the values from the conf */
704 michael 9110 conf_validate(); /* Check to make sure some values are still okay. */
705 michael 3375 /* Some global values are also loaded here. */
706 michael 7437 whowas_trim(); /* Attempt to trim whowas list if necessary */
707 michael 3375 class_delete_marked(); /* Delete unused classes that are marked for deletion */
708 michael 1363 }
709    
710 michael 4982 /* conf_rehash()
711     *
712     * Actual REHASH service routine. Called with sig == 0 if it has been called
713     * as a result of an operator issuing this command, else assume it has been
714     * called as a result of the server receiving a HUP signal.
715     */
716 michael 5776 void
717 michael 8658 conf_rehash(bool sig)
718 michael 4982 {
719 michael 8658 if (sig == true)
720 michael 7639 {
721 michael 6318 sendto_realops_flags(UMODE_SERVNOTICE, L_ALL, SEND_NOTICE,
722 michael 4982 "Got signal SIGHUP, reloading configuration file(s)");
723 michael 7639 ilog(LOG_TYPE_IRCD, "Got signal SIGHUP, reloading configuration file(s)");
724     }
725 michael 4982
726     restart_resolver();
727    
728     /* don't close listeners until we know we can go ahead with the rehash */
729    
730 michael 9110 conf_read_files(false);
731 michael 4982
732     load_conf_modules();
733     check_conf_klines();
734     }
735    
736 adx 30 /* conf_connect_allowed()
737     *
738     * inputs - pointer to inaddr
739     * - int type ipv4 or ipv6
740     * output - BANNED or accepted
741     * side effects - none
742     */
743     int
744 michael 8829 conf_connect_allowed(struct irc_ssaddr *addr)
745 adx 30 {
746 michael 8829 const struct MaskItem *conf = find_dline_conf(addr);
747 adx 30
748 michael 3235 if (conf)
749 michael 6549 {
750     /* DLINE exempt also gets you out of static limits/pacing... */
751     if (conf->type == CONF_EXEMPT)
752     return 0;
753 adx 30 return BANNED_CLIENT;
754 michael 6549 }
755 adx 30
756 michael 9202 struct ip_entry *ip_found = ipcache_record_find_or_add(addr);
757 michael 8903 if ((event_base->time.sec_monotonic - ip_found->last_attempt) < ConfigGeneral.throttle_time)
758 adx 30 {
759 michael 4340 if (ip_found->connection_count >= ConfigGeneral.throttle_count)
760 michael 3877 return TOO_FAST;
761 michael 4055
762     ++ip_found->connection_count;
763 adx 30 }
764 michael 3877 else
765     ip_found->connection_count = 1;
766 adx 30
767 michael 8903 ip_found->last_attempt = event_base->time.sec_monotonic;
768 adx 30 return 0;
769     }
770    
771 michael 4982 /* cleanup_tklines()
772     *
773     * inputs - NONE
774     * output - NONE
775     * side effects - call function to expire temporary k/d lines
776     * This is an event started off in ircd.c
777     */
778     void
779     cleanup_tklines(void *unused)
780     {
781     hostmask_expire_temporary();
782 michael 7304 gecos_expire();
783 michael 7282 resv_expire();
784 michael 4982 }
785    
786 adx 30 /*
787 michael 4298 * Input: A client to find the active operator {} name for.
788 adx 30 * Output: The nick!user@host{oper} of the oper.
789     * "oper" is server name for remote opers
790     * Side effects: None.
791     */
792 michael 1364 const char *
793 adx 30 get_oper_name(const struct Client *client_p)
794     {
795 michael 5514 static char buffer[IRCD_BUFSIZE];
796 adx 30
797 michael 4628 if (IsServer(client_p))
798     return client_p->name;
799    
800 adx 30 if (MyConnect(client_p))
801     {
802 michael 4977 const dlink_node *const node = client_p->connection->confs.head;
803    
804     if (node)
805 adx 30 {
806 michael 4937 const struct MaskItem *const conf = node->data;
807 adx 30
808 michael 4937 if (conf->type == CONF_OPER)
809 adx 30 {
810 michael 2182 snprintf(buffer, sizeof(buffer), "%s!%s@%s{%s}", client_p->name,
811 michael 1147 client_p->username, client_p->host, conf->name);
812 michael 2182 return buffer;
813 adx 30 }
814     }
815    
816 michael 4298 /*
817     * Probably should assert here for now. If there is an oper out there
818     * with no operator {} conf attached, it would be good for us to know...
819 adx 30 */
820 michael 4298 assert(0); /* Oper without oper conf! */
821 adx 30 }
822    
823 michael 1147 snprintf(buffer, sizeof(buffer), "%s!%s@%s{%s}", client_p->name,
824 michael 2182 client_p->username, client_p->host, client_p->servptr->name);
825 adx 30 return buffer;
826     }
827    
828 michael 9110 /* conf_clear()
829 adx 30 *
830     * inputs - none
831     * output - none
832     * side effects - Clear out the old configuration
833     */
834     static void
835 michael 9110 conf_clear(void)
836 adx 30 {
837 michael 4815 dlink_node *node = NULL, *node_next = NULL;
838 adx 30 dlink_list *free_items [] = {
839 michael 7401 &connect_items, &operator_items, NULL
840 adx 30 };
841    
842     dlink_list ** iterator = free_items; /* C is dumb */
843    
844     /* We only need to free anything allocated by yyparse() here.
845 michael 9110 * Resetting structs, etc, is taken care of by conf_set_defaults().
846 adx 30 */
847 michael 2916
848 michael 5003 for (; *iterator; iterator++)
849 adx 30 {
850 michael 4815 DLINK_FOREACH_SAFE(node, node_next, (*iterator)->head)
851 adx 30 {
852 michael 4815 struct MaskItem *conf = node->data;
853 michael 1632
854 michael 8658 conf->active = false;
855 michael 7304 dlinkDelete(&conf->node, *iterator);
856 michael 1632
857 michael 7304 if (!conf->ref_count)
858     conf_free(conf);
859 adx 30 }
860     }
861    
862 michael 671 /*
863 michael 5583 * Don't delete the class table, rather mark all entries for deletion.
864     * The table is cleaned up by class_delete_marked. - avalon
865 adx 30 */
866 michael 1632 class_mark_for_deletion();
867 michael 671
868 adx 30 clear_out_address_conf();
869    
870 michael 7245 modules_conf_clear(); /* Clear modules {} items */
871 adx 30
872 michael 7229 motd_clear(); /* Clear motd {} items and re-cache default motd */
873    
874 michael 7217 cluster_clear(); /* Clear cluster {} items */
875 michael 4545
876 michael 7304 gecos_clear(); /* Clear gecos {} items */
877    
878 michael 7282 resv_clear(); /* Clear resv {} items */
879    
880 michael 7248 service_clear(); /* Clear service {} items */
881    
882 michael 7209 shared_clear(); /* Clear shared {} items */
883    
884 michael 7217 pseudo_clear(); /* Clear pseudo {} items */
885    
886 michael 5583 /* Clean out ConfigServerInfo */
887 michael 7032 xfree(ConfigServerInfo.description);
888 michael 4340 ConfigServerInfo.description = NULL;
889 michael 7032 xfree(ConfigServerInfo.network_name);
890 michael 4340 ConfigServerInfo.network_name = NULL;
891 michael 7032 xfree(ConfigServerInfo.network_desc);
892 michael 4340 ConfigServerInfo.network_desc = NULL;
893 michael 7032 xfree(ConfigServerInfo.rsa_private_key_file);
894 michael 4340 ConfigServerInfo.rsa_private_key_file = NULL;
895 michael 9145 xfree(ConfigServerInfo.tls_certificate_file);
896     ConfigServerInfo.tls_certificate_file = NULL;
897     xfree(ConfigServerInfo.tls_dh_param_file);
898     ConfigServerInfo.tls_dh_param_file = NULL;
899     xfree(ConfigServerInfo.tls_supported_groups);
900     ConfigServerInfo.tls_supported_groups = NULL;
901     xfree(ConfigServerInfo.tls_cipher_list);
902     ConfigServerInfo.tls_cipher_list = NULL;
903 michael 9139 xfree(ConfigServerInfo.tls_cipher_suites);
904     ConfigServerInfo.tls_cipher_suites = NULL;
905 michael 9145 xfree(ConfigServerInfo.tls_message_digest_algorithm);
906     ConfigServerInfo.tls_message_digest_algorithm = NULL;
907 adx 30
908 michael 5583 /* Clean out ConfigAdminInfo */
909 michael 7032 xfree(ConfigAdminInfo.name);
910 michael 4340 ConfigAdminInfo.name = NULL;
911 michael 7032 xfree(ConfigAdminInfo.email);
912 michael 4340 ConfigAdminInfo.email = NULL;
913 michael 7032 xfree(ConfigAdminInfo.description);
914 michael 4340 ConfigAdminInfo.description = NULL;
915 adx 30
916 michael 8451 /* Clean out ConfigServerHide */
917 michael 7032 xfree(ConfigServerHide.flatten_links_file);
918 michael 6599 ConfigServerHide.flatten_links_file = NULL;
919 michael 8451 xfree(ConfigServerHide.hidden_name);
920     ConfigServerHide.hidden_name = NULL;
921 michael 6599
922 michael 5583 /* Clean out listeners */
923 michael 6367 listener_close_marked();
924 adx 30 }
925    
926 michael 7105 static void
927 michael 8656 conf_handle_tls(bool cold)
928 michael 7105 {
929 michael 9224 if (tls_new_credentials() == false)
930 michael 7105 {
931 michael 8656 if (cold == true)
932 michael 7105 {
933     ilog(LOG_TYPE_IRCD, "Error while initializing TLS");
934 michael 7230 exit(EXIT_FAILURE);
935 michael 7105 }
936     else
937     {
938     /* Failed to load new settings/certs, old ones remain active */
939     sendto_realops_flags(UMODE_SERVNOTICE, L_ALL, SEND_NOTICE,
940     "Error reloading TLS settings, check the ircd log"); // report_crypto_errors logs this
941     }
942     }
943     }
944    
945 michael 4982 /* read_conf_files()
946     *
947     * inputs - cold start YES or NO
948     * output - none
949     * side effects - read all conf files needed, ircd.conf kline.conf etc.
950     */
951     void
952 michael 9110 conf_read_files(bool cold)
953 michael 4982 {
954 michael 9220 char buf[IRCD_BUFSIZE];
955 michael 4982
956     conf_parser_ctx.boot = cold;
957 michael 9222 conf_parser_ctx.conf_file = fopen(ConfigGeneral.configfile, "r");
958 michael 4982
959 michael 9222 if (conf_parser_ctx.conf_file == NULL)
960 michael 4982 {
961 michael 8656 if (cold == true)
962 michael 4982 {
963     ilog(LOG_TYPE_IRCD, "Unable to read configuration file '%s': %s",
964 michael 9222 ConfigGeneral.configfile, strerror(errno));
965 michael 6645 exit(EXIT_FAILURE);
966 michael 4982 }
967     else
968     {
969 michael 6318 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
970 michael 4982 "Unable to read configuration file '%s': %s",
971 michael 9222 ConfigGeneral.configfile, strerror(errno));
972 michael 4982 return;
973     }
974     }
975    
976 michael 9222 /*
977     * We need to know the initial filename for the yyerror() to report
978     *
979     * FIXME: The full path is in conffilenamebuf first time since we
980     * don't know anything else
981     *
982     * - Gozem 2002-07-21
983     */
984     strlcpy(conffilebuf, ConfigGeneral.configfile, sizeof(conffilebuf));
985    
986 michael 8656 if (cold == false)
987 michael 9110 conf_clear();
988 michael 4982
989 michael 9110 conf_read(conf_parser_ctx.conf_file);
990 michael 4982 fclose(conf_parser_ctx.conf_file);
991    
992 michael 8510 log_iterate(log_reopen);
993 michael 7105 conf_handle_tls(cold);
994 michael 4982
995 michael 6185 isupport_add("NICKLEN", NULL, ConfigServerInfo.max_nick_length);
996     isupport_add("NETWORK", ConfigServerInfo.network_name, -1);
997 michael 4982
998 michael 9220 snprintf(buf, sizeof(buf), "beI:%u", ConfigChannel.max_bans);
999     isupport_add("MAXLIST", buf, -1);
1000 michael 9202
1001 michael 6185 isupport_add("MAXTARGETS", NULL, ConfigGeneral.max_targets);
1002     isupport_add("CHANTYPES", "#", -1);
1003 michael 4982
1004 michael 9220 snprintf(buf, sizeof(buf), "#:%u", ConfigChannel.max_channels);
1005     isupport_add("CHANLIMIT", buf, -1);
1006 michael 9202
1007 michael 6185 isupport_add("CHANNELLEN", NULL, CHANNELLEN);
1008     isupport_add("TOPICLEN", NULL, ConfigServerInfo.max_topic_length);
1009 michael 9202
1010 michael 9220 snprintf(buf, sizeof(buf), "%s", "beI,k,l,cimnprstuCLMNORST");
1011     isupport_add("CHANMODES", buf, -1);
1012 michael 4982 }
1013    
1014 adx 30 /* conf_add_class_to_conf()
1015     *
1016     * inputs - pointer to config item
1017     * output - NONE
1018 michael 2916 * side effects - Add a class pointer to a conf
1019 adx 30 */
1020     void
1021 michael 5797 conf_add_class_to_conf(struct MaskItem *conf, const char *name)
1022 adx 30 {
1023 michael 8660 if (EmptyString(name) || (conf->class = class_find(name, true)) == NULL)
1024 adx 30 {
1025 michael 1632 conf->class = class_default;
1026 michael 671
1027 michael 4941 if (conf->type == CONF_CLIENT || conf->type == CONF_OPER)
1028 michael 6318 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1029 michael 2182 "Warning *** Defaulting to default class for %s@%s",
1030     conf->user, conf->host);
1031 adx 30 else
1032 michael 6318 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1033 michael 2182 "Warning *** Defaulting to default class for %s",
1034     conf->name);
1035 adx 30 }
1036     }
1037    
1038     /* yyerror()
1039     *
1040     * inputs - message from parser
1041     * output - NONE
1042     * side effects - message to opers and log file entry is made
1043     */
1044     void
1045     yyerror(const char *msg)
1046     {
1047 michael 967 if (conf_parser_ctx.pass != 1)
1048 adx 30 return;
1049    
1050 michael 7789 const char *p = stripws(linebuf);
1051 michael 6318 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1052 michael 1618 "\"%s\", line %u: %s: %s",
1053 michael 7746 conffilebuf, lineno, msg, p);
1054 michael 1247 ilog(LOG_TYPE_IRCD, "\"%s\", line %u: %s: %s",
1055 michael 7746 conffilebuf, lineno, msg, p);
1056 adx 30 }
1057    
1058 michael 1751 void
1059     conf_error_report(const char *msg)
1060     {
1061 michael 7789 const char *p = stripws(linebuf);
1062 michael 6318 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1063 michael 1751 "\"%s\", line %u: %s: %s",
1064 michael 7777 conffilebuf, lineno, msg, p);
1065 michael 1751 ilog(LOG_TYPE_IRCD, "\"%s\", line %u: %s: %s",
1066 michael 7777 conffilebuf, lineno, msg, p);
1067 michael 1751 }
1068    
1069 adx 30 /*
1070     * valid_tkline()
1071 michael 2916 *
1072 adx 30 * inputs - pointer to ascii string to check
1073     * - whether the specified time is in seconds or minutes
1074     * output - -1 not enough parameters
1075     * - 0 if not an integer number, else the number
1076     * side effects - none
1077     * Originally written by Dianora (Diane, db@db.net)
1078     */
1079 michael 7330 uintmax_t
1080 michael 2313 valid_tkline(const char *data, const int minutes)
1081 adx 30 {
1082 michael 2313 const unsigned char *p = (const unsigned char *)data;
1083     unsigned char tmpch = '\0';
1084 michael 7330 uintmax_t result = 0;
1085 adx 30
1086 michael 2313 while ((tmpch = *p++))
1087 adx 30 {
1088 michael 2313 if (!IsDigit(tmpch))
1089 michael 1121 return 0;
1090 michael 1120
1091     result *= 10;
1092 michael 2313 result += (tmpch & 0xF);
1093 adx 30 }
1094    
1095 michael 1120 /*
1096 michael 2916 * In the degenerate case where oper does a /quote kline 0 user@host :reason
1097 michael 5583 * i.e. they specifically use 0, I am going to return 1 instead as a return
1098     * value of non-zero is used to flag it as a temporary kline
1099 adx 30 */
1100     if (result == 0)
1101     result = 1;
1102    
1103 michael 2916 /*
1104 adx 30 * If the incoming time is in seconds convert it to minutes for the purpose
1105     * of this calculation
1106     */
1107 michael 8522 if (minutes == 0)
1108 michael 2916 result = result / 60;
1109 adx 30
1110     if (result > MAX_TDKLINE_TIME)
1111     result = MAX_TDKLINE_TIME;
1112    
1113 michael 5583 result = result * 60; /* Turn it into seconds */
1114 adx 30
1115     return result;
1116     }
1117    
1118 michael 2130 /* valid_wild_card_simple()
1119     *
1120     * inputs - data to check for sufficient non-wildcard characters
1121     * outputs - 1 if valid, else 0
1122     * side effects - none
1123     */
1124 michael 8660 bool
1125 michael 2130 valid_wild_card_simple(const char *data)
1126     {
1127     const unsigned char *p = (const unsigned char *)data;
1128     unsigned char tmpch = '\0';
1129 michael 6332 unsigned int nonwild = 0, wild = 0;
1130 michael 2130
1131     while ((tmpch = *p++))
1132     {
1133 michael 4265 if (tmpch == '\\' && *p)
1134 michael 2130 {
1135     ++p;
1136 michael 4340 if (++nonwild >= ConfigGeneral.min_nonwildcard_simple)
1137 michael 8660 return true;
1138 michael 2130 }
1139     else if (!IsMWildChar(tmpch))
1140     {
1141 michael 4340 if (++nonwild >= ConfigGeneral.min_nonwildcard_simple)
1142 michael 8660 return true;
1143 michael 2130 }
1144 michael 6332 else
1145     ++wild;
1146 michael 2130 }
1147    
1148 michael 8660 return wild == 0;
1149 michael 2130 }
1150    
1151 adx 30 /* valid_wild_card()
1152     *
1153     * input - pointer to client
1154     * - int flag, 0 for no warning oper 1 for warning oper
1155     * - count of following varargs to check
1156     * output - 0 if not valid, 1 if valid
1157     * side effects - NOTICE is given to source_p if warn is 1
1158     */
1159 michael 8660 bool
1160 michael 7429 valid_wild_card(int count, ...)
1161 adx 30 {
1162 michael 3931 unsigned char tmpch = '\0';
1163 michael 3870 unsigned int nonwild = 0;
1164 adx 30 va_list args;
1165    
1166     /*
1167     * Now we must check the user and host to make sure there
1168     * are at least NONWILDCHARS non-wildcard characters in
1169     * them, otherwise assume they are attempting to kline
1170     * *@* or some variant of that. This code will also catch
1171     * people attempting to kline *@*.tld, as long as NONWILDCHARS
1172     * is greater than 3. In that case, there are only 3 non-wild
1173     * characters (tld), so if NONWILDCHARS is 4, the kline will
1174     * be disallowed.
1175     * -wnder
1176     */
1177    
1178     va_start(args, count);
1179    
1180     while (count--)
1181     {
1182 michael 3931 const unsigned char *p = va_arg(args, const unsigned char *);
1183 adx 30 if (p == NULL)
1184     continue;
1185    
1186     while ((tmpch = *p++))
1187     {
1188     if (!IsKWildChar(tmpch))
1189     {
1190     /*
1191     * If we find enough non-wild characters, we can
1192     * break - no point in searching further.
1193     */
1194 michael 4340 if (++nonwild >= ConfigGeneral.min_nonwildcard)
1195 michael 2659 {
1196     va_end(args);
1197 michael 8660 return true;
1198 michael 2659 }
1199 adx 30 }
1200     }
1201     }
1202    
1203 michael 2659 va_end(args);
1204 michael 8660 return false;
1205 adx 30 }
1206    
1207     /* XXX should this go into a separate file ? -Dianora */
1208     /* parse_aline
1209     *
1210     * input - pointer to cmd name being used
1211     * - pointer to client using cmd
1212     * - parc parameter count
1213     * - parv[] list of parameters to parse
1214     * - parse_flags bit map of things to test
1215     * - pointer to user or string to parse into
1216     * - pointer to host or NULL to parse into if non NULL
1217 michael 2916 * - pointer to optional tkline time or NULL
1218 adx 30 * - pointer to target_server to parse into if non NULL
1219     * - pointer to reason to parse into
1220     *
1221 michael 5776 * output - 1 if valid, 0 if not valid
1222 adx 30 * side effects - A generalised k/d/x etc. line parser,
1223     * "ALINE [time] user@host|string [ON] target :reason"
1224     * will parse returning a parsed user, host if
1225     * h_p pointer is non NULL, string otherwise.
1226     * if tkline_time pointer is non NULL a tk line will be set
1227     * to non zero if found.
1228     * if tkline_time pointer is NULL and tk line is found,
1229     * error is reported.
1230     * if target_server is NULL and an "ON" is found error
1231     * is reported.
1232     * if reason pointer is NULL ignore pointer,
1233 db 936 * this allows use of parse_a_line in unkline etc.
1234 adx 30 *
1235     * - Dianora
1236     */
1237 michael 8664 bool
1238 michael 8670 parse_aline(const char *cmd, struct Client *source_p, int parc, char **parv, struct aline_ctx *aline)
1239 adx 30 {
1240 michael 5823 static char default_reason[] = CONF_NOREASON;
1241 michael 8676 static char user[USERLEN * 2 + 1];
1242     static char host[HOSTLEN * 2 + 1];
1243 adx 30
1244 michael 8670 ++parv;
1245     --parc;
1246 adx 30
1247 michael 8670 if (aline->add == true && (aline->duration = valid_tkline(*parv, TK_MINUTES)))
1248 adx 30 {
1249 michael 8670 ++parv;
1250     --parc;
1251 adx 30 }
1252    
1253     if (parc == 0)
1254     {
1255 michael 3109 sendto_one_numeric(source_p, &me, ERR_NEEDMOREPARAMS, cmd);
1256 michael 8664 return false;
1257 adx 30 }
1258    
1259 michael 8680 if (aline->simple_mask == true)
1260     {
1261     aline->mask = *parv;
1262     aline->user = NULL;
1263     aline->host = NULL;
1264     }
1265 adx 30 else
1266     {
1267 michael 8676 struct split_nuh_item nuh;
1268 michael 8682
1269 michael 8676 nuh.nuhmask = *parv;
1270 michael 8682 nuh.nickptr = NULL;
1271 michael 8676 nuh.userptr = user;
1272     nuh.hostptr = host;
1273 adx 30
1274 michael 8682 nuh.nicksize = 0;
1275 michael 8676 nuh.usersize = sizeof(user);
1276     nuh.hostsize = sizeof(host);
1277    
1278     split_nuh(&nuh);
1279    
1280 michael 8680 aline->mask = NULL;
1281 michael 8670 aline->user = user;
1282     aline->host = host;
1283 adx 30 }
1284 michael 2916
1285 michael 8670 ++parv;
1286     --parc;
1287 adx 30
1288 michael 4982 if (parc)
1289 adx 30 {
1290     if (irccmp(*parv, "ON") == 0)
1291     {
1292 michael 8670 ++parv;
1293     --parc;
1294 adx 30
1295 michael 1219 if (!HasOFlag(source_p, OPER_FLAG_REMOTEBAN))
1296 adx 30 {
1297 michael 3109 sendto_one_numeric(source_p, &me, ERR_NOPRIVS, "remoteban");
1298 michael 8664 return false;
1299 adx 30 }
1300    
1301     if (parc == 0 || EmptyString(*parv))
1302     {
1303 michael 3109 sendto_one_numeric(source_p, &me, ERR_NEEDMOREPARAMS, cmd);
1304 michael 8664 return false;
1305 adx 30 }
1306    
1307 michael 8670 aline->server = *parv;
1308     ++parv;
1309     --parc;
1310 adx 30 }
1311     else
1312 michael 8670 aline->server = NULL;
1313 adx 30 }
1314    
1315 michael 8670 if (aline->add == true)
1316 adx 30 {
1317 michael 8676 if (parc == 0 || EmptyString(*parv))
1318     aline->reason = default_reason;
1319     else
1320 michael 8670 aline->reason = *parv;
1321 adx 30 }
1322    
1323 michael 8664 return true;
1324 adx 30 }
1325    
1326     /* match_conf_password()
1327     *
1328     * inputs - pointer to given password
1329     * - pointer to Conf
1330     * output - 1 or 0 if match
1331     * side effects - none
1332     */
1333 michael 8660 bool
1334 michael 1632 match_conf_password(const char *password, const struct MaskItem *conf)
1335 adx 30 {
1336     const char *encr = NULL;
1337    
1338 michael 1632 if (EmptyString(password) || EmptyString(conf->passwd))
1339 michael 8660 return false;
1340 adx 30
1341 michael 1632 if (conf->flags & CONF_FLAGS_ENCRYPTED)
1342     encr = crypt(password, conf->passwd);
1343 adx 30 else
1344     encr = password;
1345    
1346 michael 8660 return encr && strcmp(encr, conf->passwd) == 0;
1347 adx 30 }
1348    
1349     /*
1350     * split_nuh
1351     *
1352     * inputs - pointer to original mask (modified in place)
1353     * - pointer to pointer where nick should go
1354     * - pointer to pointer where user should go
1355     * - pointer to pointer where host should go
1356     * output - NONE
1357     * side effects - mask is modified in place
1358     * If nick pointer is NULL, ignore writing to it
1359     * this allows us to use this function elsewhere.
1360     *
1361     * mask nick user host
1362     * ---------------------- ------- ------- ------
1363     * Dianora!db@db.net Dianora db db.net
1364     * Dianora Dianora * *
1365     * db.net * * db.net
1366     * OR if nick pointer is NULL
1367     * Dianora - * Dianora
1368     * Dianora! Dianora * *
1369     * Dianora!@ Dianora * *
1370     * Dianora!db Dianora db *
1371     * Dianora!@db.net Dianora * db.net
1372     * db@db.net * db db.net
1373     * !@ * * *
1374     * @ * * *
1375     * ! * * *
1376     */
1377     void
1378 michael 593 split_nuh(struct split_nuh_item *const iptr)
1379 adx 30 {
1380     char *p = NULL, *q = NULL;
1381    
1382 michael 593 if (iptr->nickptr)
1383     strlcpy(iptr->nickptr, "*", iptr->nicksize);
1384 michael 4982
1385 michael 593 if (iptr->userptr)
1386     strlcpy(iptr->userptr, "*", iptr->usersize);
1387 michael 4982
1388 michael 593 if (iptr->hostptr)
1389     strlcpy(iptr->hostptr, "*", iptr->hostsize);
1390    
1391     if ((p = strchr(iptr->nuhmask, '!')))
1392 adx 30 {
1393     *p = '\0';
1394    
1395 michael 3375 if (iptr->nickptr && *iptr->nuhmask)
1396 michael 593 strlcpy(iptr->nickptr, iptr->nuhmask, iptr->nicksize);
1397 adx 30
1398 michael 2525 if ((q = strchr(++p, '@')))
1399     {
1400 michael 593 *q++ = '\0';
1401    
1402 michael 3375 if (*p)
1403 michael 593 strlcpy(iptr->userptr, p, iptr->usersize);
1404 adx 30
1405 michael 3375 if (*q)
1406 michael 593 strlcpy(iptr->hostptr, q, iptr->hostsize);
1407 adx 30 }
1408     else
1409     {
1410 michael 3375 if (*p)
1411 michael 593 strlcpy(iptr->userptr, p, iptr->usersize);
1412 adx 30 }
1413     }
1414 michael 593 else
1415 adx 30 {
1416 michael 593 /* No ! found so lets look for a user@host */
1417     if ((p = strchr(iptr->nuhmask, '@')))
1418 adx 30 {
1419 michael 593 /* if found a @ */
1420     *p++ = '\0';
1421 adx 30
1422 michael 3375 if (*iptr->nuhmask)
1423 michael 593 strlcpy(iptr->userptr, iptr->nuhmask, iptr->usersize);
1424 adx 30
1425 michael 3375 if (*p)
1426 michael 593 strlcpy(iptr->hostptr, p, iptr->hostsize);
1427 adx 30 }
1428 michael 593 else
1429 adx 30 {
1430 michael 5583 /* No @ found */
1431 michael 8702 if (iptr->nickptr == NULL || strpbrk(iptr->nuhmask, ".:"))
1432 michael 593 strlcpy(iptr->hostptr, iptr->nuhmask, iptr->hostsize);
1433 adx 30 else
1434 michael 593 strlcpy(iptr->nickptr, iptr->nuhmask, iptr->nicksize);
1435 adx 30 }
1436     }
1437     }

Properties

Name Value
svn:eol-style native
svn:keywords Id