ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/conf.c
Revision: 7105
Committed: Sat Jan 23 20:11:27 2016 UTC (9 years, 7 months ago) by michael
Content type: text/x-csrc
File size: 49935 byte(s)
Log Message:
- Incorporate gnutls support by Adam & Attila

File Contents

# Content
1 /*
2 * ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3 *
4 * Copyright (c) 1997-2016 ircd-hybrid development team
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301
19 * USA
20 */
21
22 /*! \file conf.c
23 * \brief Configuration file functions.
24 * \version $Id$
25 */
26
27 #include "stdinc.h"
28 #include "list.h"
29 #include "ircd_defs.h"
30 #include "conf.h"
31 #include "conf_pseudo.h"
32 #include "server.h"
33 #include "resv.h"
34 #include "channel.h"
35 #include "client.h"
36 #include "event.h"
37 #include "irc_string.h"
38 #include "s_bsd.h"
39 #include "ircd.h"
40 #include "listener.h"
41 #include "hostmask.h"
42 #include "modules.h"
43 #include "numeric.h"
44 #include "fdlist.h"
45 #include "log.h"
46 #include "send.h"
47 #include "memory.h"
48 #include "res.h"
49 #include "userhost.h"
50 #include "user.h"
51 #include "channel_mode.h"
52 #include "parse.h"
53 #include "misc.h"
54 #include "conf_db.h"
55 #include "conf_class.h"
56 #include "motd.h"
57 #include "ipcache.h"
58 #include "isupport.h"
59
60
61 struct config_channel_entry ConfigChannel;
62 struct config_serverhide_entry ConfigServerHide;
63 struct config_general_entry ConfigGeneral;
64 struct config_log_entry ConfigLog = { .use_logging = 1 };
65 struct config_serverinfo_entry ConfigServerInfo;
66 struct config_admin_entry ConfigAdminInfo;
67 struct conf_parser_context conf_parser_ctx;
68
69 /* general conf items link list root, other than k lines etc. */
70 dlink_list service_items;
71 dlink_list server_items;
72 dlink_list cluster_items;
73 dlink_list operator_items;
74 dlink_list shared_items;
75 dlink_list gecos_items;
76 dlink_list nresv_items;
77 dlink_list cresv_items;
78
79 extern unsigned int lineno;
80 extern char linebuf[];
81 extern char conffilebuf[IRCD_BUFSIZE];
82 extern int yyparse(); /* defined in y.tab.c */
83
84
85 /* conf_dns_callback()
86 *
87 * inputs - pointer to struct MaskItem
88 * - pointer to DNSReply reply
89 * output - none
90 * side effects - called when resolver query finishes
91 * if the query resulted in a successful search, hp will contain
92 * a non-null pointer, otherwise hp will be null.
93 * if successful save hp in the conf item it was called with
94 */
95 static void
96 conf_dns_callback(void *vptr, const struct irc_ssaddr *addr, const char *name, size_t namelength)
97 {
98 struct MaskItem *const conf = vptr;
99
100 conf->dns_pending = 0;
101
102 if (addr)
103 memcpy(&conf->addr, addr, sizeof(conf->addr));
104 else
105 conf->dns_failed = 1;
106 }
107
108 /* conf_dns_lookup()
109 *
110 * do a nameserver lookup of the conf host
111 * if the conf entry is currently doing a ns lookup do nothing, otherwise
112 * allocate a dns_query and start ns lookup.
113 */
114 static void
115 conf_dns_lookup(struct MaskItem *conf)
116 {
117 if (conf->dns_pending)
118 return;
119
120 conf->dns_pending = 1;
121
122 if (conf->aftype == AF_INET)
123 gethost_byname_type(conf_dns_callback, conf, conf->host, T_A);
124 else
125 gethost_byname_type(conf_dns_callback, conf, conf->host, T_AAAA);
126 }
127
128 /* map_to_list()
129 *
130 * inputs - ConfType conf
131 * output - pointer to dlink_list to use
132 * side effects - none
133 */
134 static dlink_list *
135 map_to_list(enum maskitem_type type)
136 {
137 switch (type)
138 {
139 case CONF_XLINE:
140 return &gecos_items;
141 break;
142 case CONF_SHARED:
143 return &shared_items;
144 break;
145 case CONF_NRESV:
146 return &nresv_items;
147 break;
148 case CONF_CRESV:
149 return &cresv_items;
150 break;
151 case CONF_OPER:
152 return &operator_items;
153 break;
154 case CONF_SERVER:
155 return &server_items;
156 break;
157 case CONF_SERVICE:
158 return &service_items;
159 break;
160 case CONF_CLUSTER:
161 return &cluster_items;
162 break;
163 default:
164 return NULL;
165 }
166 }
167
168 struct MaskItem *
169 conf_make(enum maskitem_type type)
170 {
171 struct MaskItem *const conf = xcalloc(sizeof(*conf));
172 dlink_list *list = NULL;
173
174 conf->type = type;
175 conf->active = 1;
176 conf->aftype = AF_INET;
177
178 if ((list = map_to_list(type)))
179 dlinkAdd(conf, &conf->node, list);
180 return conf;
181 }
182
183 void
184 conf_free(struct MaskItem *conf)
185 {
186 dlink_node *node = NULL, *node_next = NULL;
187 dlink_list *list = NULL;
188
189 if ((list = map_to_list(conf->type)))
190 dlinkFindDelete(list, conf);
191
192 xfree(conf->name);
193
194 if (conf->dns_pending)
195 delete_resolver_queries(conf);
196 if (conf->passwd)
197 memset(conf->passwd, 0, strlen(conf->passwd));
198 if (conf->spasswd)
199 memset(conf->spasswd, 0, strlen(conf->spasswd));
200
201 conf->class = NULL;
202
203 xfree(conf->passwd);
204 xfree(conf->spasswd);
205 xfree(conf->reason);
206 xfree(conf->certfp);
207 xfree(conf->whois);
208 xfree(conf->user);
209 xfree(conf->host);
210 xfree(conf->cipher_list);
211
212 DLINK_FOREACH_SAFE(node, node_next, conf->hub_list.head)
213 {
214 xfree(node->data);
215 dlinkDelete(node, &conf->hub_list);
216 free_dlink_node(node);
217 }
218
219 DLINK_FOREACH_SAFE(node, node_next, conf->leaf_list.head)
220 {
221 xfree(node->data);
222 dlinkDelete(node, &conf->leaf_list);
223 free_dlink_node(node);
224 }
225
226 DLINK_FOREACH_SAFE(node, node_next, conf->exempt_list.head)
227 {
228 struct exempt *exptr = node->data;
229
230 dlinkDelete(node, &conf->exempt_list);
231 xfree(exptr->name);
232 xfree(exptr->user);
233 xfree(exptr->host);
234 xfree(exptr);
235 }
236
237 xfree(conf);
238 }
239
240 /* attach_iline()
241 *
242 * inputs - client pointer
243 * - conf pointer
244 * output -
245 * side effects - do actual attach
246 */
247 static int
248 attach_iline(struct Client *client_p, struct MaskItem *conf)
249 {
250 const struct ClassItem *const class = conf->class;
251 struct ip_entry *ip_found;
252 int a_limit_reached = 0;
253 unsigned int local = 0, global = 0, ident = 0;
254
255 ip_found = ipcache_find_or_add_address(&client_p->connection->ip);
256 ip_found->count++;
257 AddFlag(client_p, FLAGS_IPHASH);
258
259 userhost_count(client_p->username, client_p->host,
260 &global, &local, &ident);
261
262 /* XXX blah. go down checking the various silly limits
263 * setting a_limit_reached if any limit is reached.
264 * - Dianora
265 */
266 if (class->max_total && class->ref_count >= class->max_total)
267 a_limit_reached = 1;
268 else if (class->max_perip && ip_found->count > class->max_perip)
269 a_limit_reached = 1;
270 else if (class->max_local && local >= class->max_local)
271 a_limit_reached = 1;
272 else if (class->max_global && global >= class->max_global)
273 a_limit_reached = 1;
274 else if (class->max_ident && ident >= class->max_ident &&
275 client_p->username[0] != '~')
276 a_limit_reached = 1;
277
278 if (a_limit_reached)
279 {
280 if (!IsConfExemptLimits(conf))
281 return TOO_MANY; /* Already at maximum allowed */
282
283 sendto_one_notice(client_p, &me, ":*** Your connection class is full, "
284 "but you have exceed_limit = yes;");
285 }
286
287 return attach_conf(client_p, conf);
288 }
289
290 /* verify_access()
291 *
292 * inputs - pointer to client to verify
293 * output - 0 if success -'ve if not
294 * side effect - find the first (best) I line to attach.
295 */
296 static int
297 verify_access(struct Client *client_p)
298 {
299 struct MaskItem *conf = NULL;
300
301 if (HasFlag(client_p, FLAGS_GOTID))
302 {
303 conf = find_address_conf(client_p->host, client_p->username,
304 &client_p->connection->ip,
305 client_p->connection->aftype,
306 client_p->connection->password);
307 }
308 else
309 {
310 char non_ident[USERLEN + 1] = "~";
311
312 strlcpy(non_ident + 1, client_p->username, sizeof(non_ident) - 1);
313 conf = find_address_conf(client_p->host, non_ident,
314 &client_p->connection->ip,
315 client_p->connection->aftype,
316 client_p->connection->password);
317 }
318
319 if (!conf)
320 return NOT_AUTHORIZED;
321
322 assert(IsConfClient(conf) || IsConfKill(conf));
323
324 if (IsConfClient(conf))
325 {
326 if (IsConfRedir(conf))
327 {
328 sendto_one_numeric(client_p, &me, RPL_REDIR,
329 conf->name ? conf->name : "",
330 conf->port);
331 return NOT_AUTHORIZED;
332 }
333
334 if (IsConfDoSpoofIp(conf))
335 {
336 if (IsConfSpoofNotice(conf))
337 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE, "%s spoofing: %s as %s",
338 client_p->name, client_p->host, conf->name);
339
340 strlcpy(client_p->host, conf->name, sizeof(client_p->host));
341 }
342
343 return attach_iline(client_p, conf);
344 }
345
346 sendto_one_notice(client_p, &me, ":*** Banned: %s", conf->reason);
347 return BANNED_CLIENT;
348 }
349
350 /* check_client()
351 *
352 * inputs - pointer to client
353 * output - 0 = Success
354 * NOT_AUTHORIZED (-1) = Access denied (no I line match)
355 * IRCD_SOCKET_ERROR (-2) = Bad socket.
356 * I_LINE_FULL (-3) = I-line is full
357 * TOO_MANY (-4) = Too many connections from hostname
358 * BANNED_CLIENT (-5) = K-lined
359 * side effects - Ordinary client access check.
360 * Look for conf lines which have the same
361 * status as the flags passed.
362 */
363 int
364 check_client(struct Client *source_p)
365 {
366 int i;
367
368 if ((i = verify_access(source_p)))
369 ilog(LOG_TYPE_IRCD, "Access denied: %s[%s]",
370 source_p->name, source_p->sockhost);
371
372 switch (i)
373 {
374 case TOO_MANY:
375 sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE,
376 "Too many on IP for %s (%s).",
377 get_client_name(source_p, SHOW_IP),
378 source_p->sockhost);
379 ilog(LOG_TYPE_IRCD, "Too many connections on IP from %s.",
380 get_client_name(source_p, SHOW_IP));
381 ++ServerStats.is_ref;
382 exit_client(source_p, "No more connections allowed on that IP");
383 break;
384
385 case I_LINE_FULL:
386 sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE,
387 "auth {} block is full for %s (%s).",
388 get_client_name(source_p, SHOW_IP),
389 source_p->sockhost);
390 ilog(LOG_TYPE_IRCD, "Too many connections from %s.",
391 get_client_name(source_p, SHOW_IP));
392 ++ServerStats.is_ref;
393 exit_client(source_p, "No more connections allowed in your connection class");
394 break;
395
396 case NOT_AUTHORIZED:
397 /* jdc - lists server name & port connections are on */
398 /* a purely cosmetical change */
399 sendto_realops_flags(UMODE_UNAUTH, L_ALL, SEND_NOTICE,
400 "Unauthorized client connection from %s [%s] on [%s/%u].",
401 get_client_name(source_p, SHOW_IP),
402 source_p->sockhost,
403 source_p->connection->listener->name,
404 source_p->connection->listener->port);
405 ilog(LOG_TYPE_IRCD, "Unauthorized client connection from %s on [%s/%u].",
406 get_client_name(source_p, SHOW_IP),
407 source_p->connection->listener->name,
408 source_p->connection->listener->port);
409
410 ++ServerStats.is_ref;
411 exit_client(source_p, "You are not authorized to use this server");
412 break;
413
414 case BANNED_CLIENT:
415 ++ServerStats.is_ref;
416 exit_client(source_p, "Banned");
417 break;
418
419 case 0:
420 default:
421 break;
422 }
423
424 return !(i < 0);
425 }
426
427 /* detach_conf()
428 *
429 * inputs - pointer to client to detach
430 * - type of conf to detach
431 * output - 0 for success, -1 for failure
432 * side effects - Disassociate configuration from the client.
433 * Also removes a class from the list if marked for deleting.
434 */
435 void
436 detach_conf(struct Client *client_p, enum maskitem_type type)
437 {
438 dlink_node *node = NULL, *node_next = NULL;
439
440 DLINK_FOREACH_SAFE(node, node_next, client_p->connection->confs.head)
441 {
442 struct MaskItem *conf = node->data;
443
444 assert(conf->type & (CONF_CLIENT | CONF_OPER | CONF_SERVER));
445 assert(conf->ref_count > 0);
446 assert(conf->class->ref_count > 0);
447
448 if (!(conf->type & type))
449 continue;
450
451 dlinkDelete(node, &client_p->connection->confs);
452 free_dlink_node(node);
453
454 if (conf->type == CONF_CLIENT)
455 remove_from_cidr_check(&client_p->connection->ip, conf->class);
456
457 if (--conf->class->ref_count == 0 && conf->class->active == 0)
458 {
459 class_free(conf->class);
460 conf->class = NULL;
461 }
462
463 if (--conf->ref_count == 0 && conf->active == 0)
464 conf_free(conf);
465 }
466 }
467
468 /* attach_conf()
469 *
470 * inputs - client pointer
471 * - conf pointer
472 * output -
473 * side effects - Associate a specific configuration entry to a *local*
474 * client (this is the one which used in accepting the
475 * connection). Note, that this automatically changes the
476 * attachment if there was an old one...
477 */
478 int
479 attach_conf(struct Client *client_p, struct MaskItem *conf)
480 {
481 if (dlinkFind(&client_p->connection->confs, conf))
482 return 1;
483
484 if (conf->type == CONF_CLIENT)
485 if (cidr_limit_reached(IsConfExemptLimits(conf),
486 &client_p->connection->ip, conf->class))
487 return TOO_MANY; /* Already at maximum allowed */
488
489 conf->class->ref_count++;
490 conf->ref_count++;
491
492 dlinkAdd(conf, make_dlink_node(), &client_p->connection->confs);
493
494 return 0;
495 }
496
497 /* attach_connect_block()
498 *
499 * inputs - pointer to server to attach
500 * - name of server
501 * - hostname of server
502 * output - true (1) if both are found, otherwise return false (0)
503 * side effects - find connect block and attach them to connecting client
504 */
505 int
506 attach_connect_block(struct Client *client_p, const char *name,
507 const char *host)
508 {
509 dlink_node *node = NULL;
510
511 assert(host);
512
513 DLINK_FOREACH(node, server_items.head)
514 {
515 struct MaskItem *conf = node->data;
516
517 if (match(conf->name, name) || match(conf->host, host))
518 continue;
519
520 attach_conf(client_p, conf);
521 return 1;
522 }
523
524 return 0;
525 }
526
527 /* find_conf_name()
528 *
529 * inputs - pointer to conf link list to search
530 * - pointer to name to find
531 * - int mask of type of conf to find
532 * output - NULL or pointer to conf found
533 * side effects - find a conf entry which matches the name
534 * and has the given mask.
535 */
536 struct MaskItem *
537 find_conf_name(dlink_list *list, const char *name, enum maskitem_type type)
538 {
539 dlink_node *node = NULL;
540
541 DLINK_FOREACH(node, list->head)
542 {
543 struct MaskItem *conf = node->data;
544
545 if (conf->type == type)
546 {
547 if (conf->name && !irccmp(conf->name, name))
548 return conf;
549 }
550 }
551
552 return NULL;
553 }
554
555 /* find_matching_name_conf()
556 *
557 * inputs - type of link list to look in
558 * - pointer to name string to find
559 * - pointer to user
560 * - pointer to host
561 * - optional flags to match on as well
562 * output - NULL or pointer to found struct MaskItem
563 * side effects - looks for a match on name field
564 */
565 struct MaskItem *
566 find_matching_name_conf(enum maskitem_type type, const char *name, const char *user,
567 const char *host, unsigned int flags)
568 {
569 dlink_node *node = NULL;
570 dlink_list *list = map_to_list(type);
571 struct MaskItem *conf = NULL;
572
573 switch (type)
574 {
575 case CONF_SERVICE:
576 DLINK_FOREACH(node, list->head)
577 {
578 conf = node->data;
579
580 if (EmptyString(conf->name))
581 continue;
582 if (name && !irccmp(name, conf->name))
583 return conf;
584 }
585 break;
586
587 case CONF_XLINE:
588 case CONF_SHARED:
589 case CONF_NRESV:
590 case CONF_CRESV:
591 DLINK_FOREACH(node, list->head)
592 {
593 conf = node->data;
594
595 if (EmptyString(conf->name))
596 continue;
597 if (name && !match(conf->name, name))
598 {
599 if ((user == NULL && (host == NULL)))
600 return conf;
601 if ((conf->flags & flags) != flags)
602 continue;
603 if (EmptyString(conf->user) || EmptyString(conf->host))
604 return conf;
605 if (!match(conf->user, user) && !match(conf->host, host))
606 return conf;
607 }
608 }
609 break;
610
611 case CONF_SERVER:
612 DLINK_FOREACH(node, list->head)
613 {
614 conf = node->data;
615
616 if (name && !match(name, conf->name))
617 return conf;
618 if (host && !match(host, conf->host))
619 return conf;
620 }
621 break;
622
623 default:
624 break;
625 }
626 return NULL;
627 }
628
629 /* find_exact_name_conf()
630 *
631 * inputs - type of link list to look in
632 * - pointer to name string to find
633 * - pointer to user
634 * - pointer to host
635 * output - NULL or pointer to found struct MaskItem
636 * side effects - looks for an exact match on name field
637 */
638 struct MaskItem *
639 find_exact_name_conf(enum maskitem_type type, const struct Client *who, const char *name,
640 const char *user, const char *host)
641 {
642 dlink_node *node = NULL;
643 dlink_list *list = map_to_list(type);
644 struct MaskItem *conf = NULL;
645
646 switch(type)
647 {
648 case CONF_XLINE:
649 case CONF_SHARED:
650 case CONF_NRESV:
651 case CONF_CRESV:
652
653 DLINK_FOREACH(node, list->head)
654 {
655 conf = node->data;
656
657 if (EmptyString(conf->name))
658 continue;
659
660 if (irccmp(conf->name, name) == 0)
661 {
662 if ((user == NULL && (host == NULL)))
663 return conf;
664 if (EmptyString(conf->user) || EmptyString(conf->host))
665 return conf;
666 if (!match(conf->user, user) && !match(conf->host, host))
667 return conf;
668 }
669 }
670 break;
671
672 case CONF_OPER:
673 DLINK_FOREACH(node, list->head)
674 {
675 conf = node->data;
676
677 if (EmptyString(conf->name))
678 continue;
679
680 if (!irccmp(conf->name, name))
681 {
682 if (!who)
683 return conf;
684 if (EmptyString(conf->user) || EmptyString(conf->host))
685 return NULL;
686 if (!match(conf->user, who->username))
687 {
688 switch (conf->htype)
689 {
690 case HM_HOST:
691 if (!match(conf->host, who->host) || !match(conf->host, who->sockhost))
692 if (!conf->class->max_total || conf->class->ref_count < conf->class->max_total)
693 return conf;
694 break;
695 case HM_IPV4:
696 if (who->connection->aftype == AF_INET)
697 if (match_ipv4(&who->connection->ip, &conf->addr, conf->bits))
698 if (!conf->class->max_total || conf->class->ref_count < conf->class->max_total)
699 return conf;
700 break;
701 case HM_IPV6:
702 if (who->connection->aftype == AF_INET6)
703 if (match_ipv6(&who->connection->ip, &conf->addr, conf->bits))
704 if (!conf->class->max_total || conf->class->ref_count < conf->class->max_total)
705 return conf;
706 break;
707 default:
708 assert(0);
709 }
710 }
711 }
712 }
713
714 break;
715
716 case CONF_SERVER:
717 DLINK_FOREACH(node, list->head)
718 {
719 conf = node->data;
720
721 if (EmptyString(conf->name))
722 continue;
723
724 if (name == NULL)
725 {
726 if (EmptyString(conf->host))
727 continue;
728 if (irccmp(conf->host, host) == 0)
729 return conf;
730 }
731 else if (irccmp(conf->name, name) == 0)
732 return conf;
733 }
734
735 break;
736
737 default:
738 break;
739 }
740
741 return NULL;
742 }
743
744 /* set_default_conf()
745 *
746 * inputs - NONE
747 * output - NONE
748 * side effects - Set default values here.
749 * This is called **PRIOR** to parsing the
750 * configuration file. If you want to do some validation
751 * of values later, put them in validate_conf().
752 */
753 static void
754 set_default_conf(void)
755 {
756 /* verify init_class() ran, this should be an unnecessary check
757 * but its not much work.
758 */
759 assert(class_default == class_get_list()->tail->data);
760
761 ConfigServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT);
762 ConfigServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT);
763
764 memset(&ConfigServerInfo.ip, 0, sizeof(ConfigServerInfo.ip));
765 ConfigServerInfo.specific_ipv4_vhost = 0;
766 memset(&ConfigServerInfo.ip6, 0, sizeof(ConfigServerInfo.ip6));
767 ConfigServerInfo.specific_ipv6_vhost = 0;
768
769 ConfigServerInfo.default_max_clients = MAXCLIENTS_MAX;
770 ConfigServerInfo.max_nick_length = 9;
771 ConfigServerInfo.max_topic_length = 80;
772 ConfigServerInfo.hub = 0;
773
774 log_del_all();
775
776 ConfigLog.use_logging = 1;
777
778 ConfigChannel.disable_fake_channels = 0;
779 ConfigChannel.invite_client_count = 10;
780 ConfigChannel.invite_client_time = 300;
781 ConfigChannel.invite_delay_channel = 5;
782 ConfigChannel.knock_client_count = 1;
783 ConfigChannel.knock_client_time = 300;
784 ConfigChannel.knock_delay_channel = 60;
785 ConfigChannel.max_channels = 25;
786 ConfigChannel.max_bans = 25;
787 ConfigChannel.default_join_flood_count = 18;
788 ConfigChannel.default_join_flood_time = 6;
789
790 ConfigServerHide.flatten_links = 0;
791 ConfigServerHide.flatten_links_delay = 300;
792 ConfigServerHide.hidden = 0;
793 ConfigServerHide.hide_servers = 0;
794 ConfigServerHide.hide_services = 0;
795 ConfigServerHide.hidden_name = xstrdup(NETWORK_NAME_DEFAULT);
796 ConfigServerHide.hide_server_ips = 0;
797 ConfigServerHide.disable_remote_commands = 0;
798
799 ConfigGeneral.away_count = 2;
800 ConfigGeneral.away_time = 10;
801 ConfigGeneral.max_watch = 50;
802 ConfigGeneral.cycle_on_host_change = 1;
803 ConfigGeneral.dline_min_cidr = 16;
804 ConfigGeneral.dline_min_cidr6 = 48;
805 ConfigGeneral.kline_min_cidr = 16;
806 ConfigGeneral.kline_min_cidr6 = 48;
807 ConfigGeneral.invisible_on_connect = 1;
808 ConfigGeneral.tkline_expire_notices = 1;
809 ConfigGeneral.ignore_bogus_ts = 0;
810 ConfigGeneral.disable_auth = 0;
811 ConfigGeneral.kill_chase_time_limit = 90;
812 ConfigGeneral.default_floodcount = 8;
813 ConfigGeneral.failed_oper_notice = 1;
814 ConfigGeneral.dots_in_ident = 0;
815 ConfigGeneral.min_nonwildcard = 4;
816 ConfigGeneral.min_nonwildcard_simple = 3;
817 ConfigGeneral.max_accept = 50;
818 ConfigGeneral.anti_nick_flood = 0;
819 ConfigGeneral.max_nick_time = 20;
820 ConfigGeneral.max_nick_changes = 5;
821 ConfigGeneral.anti_spam_exit_message_time = 0;
822 ConfigGeneral.ts_warn_delta = 30;
823 ConfigGeneral.ts_max_delta = 600;
824 ConfigGeneral.warn_no_connect_block = 1;
825 ConfigGeneral.stats_e_disabled = 0;
826 ConfigGeneral.stats_i_oper_only = 1; /* 1 = masked */
827 ConfigGeneral.stats_k_oper_only = 1; /* 1 = masked */
828 ConfigGeneral.stats_o_oper_only = 1;
829 ConfigGeneral.stats_m_oper_only = 1;
830 ConfigGeneral.stats_P_oper_only = 0;
831 ConfigGeneral.stats_u_oper_only = 0;
832 ConfigGeneral.caller_id_wait = 60;
833 ConfigGeneral.opers_bypass_callerid = 0;
834 ConfigGeneral.pace_wait = 10;
835 ConfigGeneral.pace_wait_simple = 1;
836 ConfigGeneral.short_motd = 0;
837 ConfigGeneral.ping_cookie = 0;
838 ConfigGeneral.no_oper_flood = 0;
839 ConfigGeneral.max_targets = MAX_TARGETS_DEFAULT;
840 ConfigGeneral.oper_only_umodes = UMODE_DEBUG | UMODE_LOCOPS | UMODE_HIDDEN | UMODE_FARCONNECT |
841 UMODE_UNAUTH | UMODE_EXTERNAL | UMODE_BOTS | UMODE_NCHANGE |
842 UMODE_SPY | UMODE_FULL | UMODE_SKILL | UMODE_REJ | UMODE_CCONN;
843 ConfigGeneral.oper_umodes = UMODE_BOTS | UMODE_LOCOPS | UMODE_SERVNOTICE | UMODE_WALLOP;
844 ConfigGeneral.throttle_count = 1;
845 ConfigGeneral.throttle_time = 1;
846 }
847
848 static void
849 validate_conf(void)
850 {
851 if (EmptyString(ConfigServerInfo.network_name))
852 ConfigServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT);
853
854 if (EmptyString(ConfigServerInfo.network_desc))
855 ConfigServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT);
856 }
857
858 /* read_conf()
859 *
860 * inputs - file descriptor pointing to config file to use
861 * output - None
862 * side effects - Read configuration file.
863 */
864 static void
865 read_conf(FILE *file)
866 {
867 lineno = 0;
868
869 set_default_conf(); /* Set default values prior to conf parsing */
870 conf_parser_ctx.pass = 1;
871 yyparse(); /* Pick up the classes first */
872
873 rewind(file);
874
875 conf_parser_ctx.pass = 2;
876 yyparse(); /* Load the values from the conf */
877 validate_conf(); /* Check to make sure some values are still okay. */
878 /* Some global values are also loaded here. */
879 class_delete_marked(); /* Delete unused classes that are marked for deletion */
880 }
881
882 /* conf_rehash()
883 *
884 * Actual REHASH service routine. Called with sig == 0 if it has been called
885 * as a result of an operator issuing this command, else assume it has been
886 * called as a result of the server receiving a HUP signal.
887 */
888 void
889 conf_rehash(int sig)
890 {
891 if (sig)
892 sendto_realops_flags(UMODE_SERVNOTICE, L_ALL, SEND_NOTICE,
893 "Got signal SIGHUP, reloading configuration file(s)");
894
895 restart_resolver();
896
897 /* don't close listeners until we know we can go ahead with the rehash */
898
899 read_conf_files(0);
900
901 load_conf_modules();
902 check_conf_klines();
903 }
904
905 /* lookup_confhost()
906 *
907 * start DNS lookups of all hostnames in the conf
908 * line and convert an IP addresses in a.b.c.d number for to IP#s.
909 */
910 void
911 lookup_confhost(struct MaskItem *conf)
912 {
913 struct addrinfo hints, *res;
914
915 /*
916 * Do name lookup now on hostnames given and store the
917 * ip numbers in conf structure.
918 */
919 memset(&hints, 0, sizeof(hints));
920
921 hints.ai_family = AF_UNSPEC;
922 hints.ai_socktype = SOCK_STREAM;
923
924 /* Get us ready for a bind() and don't bother doing dns lookup */
925 hints.ai_flags = AI_PASSIVE | AI_NUMERICHOST;
926
927 if (getaddrinfo(conf->host, NULL, &hints, &res))
928 {
929 conf_dns_lookup(conf);
930 return;
931 }
932
933 assert(res);
934
935 memcpy(&conf->addr, res->ai_addr, res->ai_addrlen);
936 conf->addr.ss_len = res->ai_addrlen;
937 conf->addr.ss.ss_family = res->ai_family;
938
939 freeaddrinfo(res);
940 }
941
942 /* conf_connect_allowed()
943 *
944 * inputs - pointer to inaddr
945 * - int type ipv4 or ipv6
946 * output - BANNED or accepted
947 * side effects - none
948 */
949 int
950 conf_connect_allowed(struct irc_ssaddr *addr, int aftype)
951 {
952 struct ip_entry *ip_found = NULL;
953 const struct MaskItem *conf = find_dline_conf(addr, aftype);
954
955 if (conf)
956 {
957 /* DLINE exempt also gets you out of static limits/pacing... */
958 if (conf->type == CONF_EXEMPT)
959 return 0;
960 return BANNED_CLIENT;
961 }
962
963 ip_found = ipcache_find_or_add_address(addr);
964
965 if ((CurrentTime - ip_found->last_attempt) < ConfigGeneral.throttle_time)
966 {
967 if (ip_found->connection_count >= ConfigGeneral.throttle_count)
968 return TOO_FAST;
969
970 ++ip_found->connection_count;
971 }
972 else
973 ip_found->connection_count = 1;
974
975 ip_found->last_attempt = CurrentTime;
976 return 0;
977 }
978
979 /* expire_tklines()
980 *
981 * inputs - tkline list pointer
982 * output - NONE
983 * side effects - expire tklines
984 */
985 static void
986 expire_tklines(dlink_list *list)
987 {
988 dlink_node *node = NULL, *node_next = NULL;
989
990 DLINK_FOREACH_SAFE(node, node_next, list->head)
991 {
992 struct MaskItem *conf = node->data;
993
994 if (!conf->until || conf->until > CurrentTime)
995 continue;
996
997 if (ConfigGeneral.tkline_expire_notices)
998 sendto_realops_flags(UMODE_SERVNOTICE, L_ALL, SEND_NOTICE, "Temporary %s for [%s] expired",
999 (conf->type == CONF_XLINE) ? "X-line" : "RESV", conf->name);
1000 conf_free(conf);
1001 }
1002 }
1003
1004 /* cleanup_tklines()
1005 *
1006 * inputs - NONE
1007 * output - NONE
1008 * side effects - call function to expire temporary k/d lines
1009 * This is an event started off in ircd.c
1010 */
1011 void
1012 cleanup_tklines(void *unused)
1013 {
1014 hostmask_expire_temporary();
1015 expire_tklines(&gecos_items);
1016 expire_tklines(&nresv_items);
1017 expire_tklines(&cresv_items);
1018 }
1019
1020 /* oper_privs_as_string()
1021 *
1022 * inputs - pointer to client_p
1023 * output - pointer to static string showing oper privs
1024 * side effects - return as string, the oper privs as derived from port
1025 */
1026 static const struct oper_privs
1027 {
1028 const unsigned int flag;
1029 const unsigned char c;
1030 } flag_list[] = {
1031 { OPER_FLAG_ADMIN, 'A' },
1032 { OPER_FLAG_CLOSE, 'B' },
1033 { OPER_FLAG_CONNECT, 'C' },
1034 { OPER_FLAG_CONNECT_REMOTE, 'D' },
1035 { OPER_FLAG_DIE, 'E' },
1036 { OPER_FLAG_DLINE, 'F' },
1037 { OPER_FLAG_GLOBOPS, 'G' },
1038 { OPER_FLAG_JOIN_RESV, 'H' },
1039 { OPER_FLAG_KILL, 'I' },
1040 { OPER_FLAG_KILL_REMOTE, 'J' },
1041 { OPER_FLAG_KLINE, 'K' },
1042 { OPER_FLAG_LOCOPS, 'L' },
1043 { OPER_FLAG_MODULE, 'M' },
1044 { OPER_FLAG_NICK_RESV, 'N' },
1045 { OPER_FLAG_OPME, 'O' },
1046 { OPER_FLAG_REHASH, 'P' },
1047 { OPER_FLAG_REMOTEBAN, 'Q' },
1048 { OPER_FLAG_RESTART, 'R' },
1049 { OPER_FLAG_RESV, 'S' },
1050 { OPER_FLAG_SET, 'T' },
1051 { OPER_FLAG_SQUIT, 'U' },
1052 { OPER_FLAG_SQUIT_REMOTE, 'V' },
1053 { OPER_FLAG_UNDLINE, 'W' },
1054 { OPER_FLAG_UNKLINE, 'X' },
1055 { OPER_FLAG_UNRESV, 'Y' },
1056 { OPER_FLAG_UNXLINE, 'Z' },
1057 { OPER_FLAG_WALLOPS, 'a' },
1058 { OPER_FLAG_XLINE, 'b' },
1059 { 0, '\0' }
1060 };
1061
1062 const char *
1063 oper_privs_as_string(const unsigned int port)
1064 {
1065 static char privs_out[IRCD_BUFSIZE];
1066 char *privs_ptr = privs_out;
1067
1068 for (const struct oper_privs *opriv = flag_list; opriv->flag; ++opriv)
1069 if (port & opriv->flag)
1070 *privs_ptr++ = opriv->c;
1071
1072 if (privs_ptr == privs_out)
1073 *privs_ptr++ = '0';
1074
1075 *privs_ptr = '\0';
1076
1077 return privs_out;
1078 }
1079
1080 /*
1081 * Input: A client to find the active operator {} name for.
1082 * Output: The nick!user@host{oper} of the oper.
1083 * "oper" is server name for remote opers
1084 * Side effects: None.
1085 */
1086 const char *
1087 get_oper_name(const struct Client *client_p)
1088 {
1089 static char buffer[IRCD_BUFSIZE];
1090
1091 if (IsServer(client_p))
1092 return client_p->name;
1093
1094 if (MyConnect(client_p))
1095 {
1096 const dlink_node *const node = client_p->connection->confs.head;
1097
1098 if (node)
1099 {
1100 const struct MaskItem *const conf = node->data;
1101
1102 if (conf->type == CONF_OPER)
1103 {
1104 snprintf(buffer, sizeof(buffer), "%s!%s@%s{%s}", client_p->name,
1105 client_p->username, client_p->host, conf->name);
1106 return buffer;
1107 }
1108 }
1109
1110 /*
1111 * Probably should assert here for now. If there is an oper out there
1112 * with no operator {} conf attached, it would be good for us to know...
1113 */
1114 assert(0); /* Oper without oper conf! */
1115 }
1116
1117 snprintf(buffer, sizeof(buffer), "%s!%s@%s{%s}", client_p->name,
1118 client_p->username, client_p->host, client_p->servptr->name);
1119 return buffer;
1120 }
1121
1122 /* clear_out_old_conf()
1123 *
1124 * inputs - none
1125 * output - none
1126 * side effects - Clear out the old configuration
1127 */
1128 static void
1129 clear_out_old_conf(void)
1130 {
1131 dlink_node *node = NULL, *node_next = NULL;
1132 dlink_list *free_items [] = {
1133 &server_items, &operator_items,
1134 &shared_items, &gecos_items,
1135 &nresv_items, &cluster_items, &service_items, &cresv_items, NULL
1136 };
1137
1138 dlink_list ** iterator = free_items; /* C is dumb */
1139
1140 /* We only need to free anything allocated by yyparse() here.
1141 * Resetting structs, etc, is taken care of by set_default_conf().
1142 */
1143
1144 for (; *iterator; iterator++)
1145 {
1146 DLINK_FOREACH_SAFE(node, node_next, (*iterator)->head)
1147 {
1148 struct MaskItem *conf = node->data;
1149
1150 conf->active = 0;
1151
1152 if (!IsConfDatabase(conf))
1153 {
1154 dlinkDelete(&conf->node, *iterator);
1155
1156 if (!conf->ref_count)
1157 conf_free(conf);
1158 }
1159 }
1160 }
1161
1162 motd_clear();
1163
1164 /*
1165 * Don't delete the class table, rather mark all entries for deletion.
1166 * The table is cleaned up by class_delete_marked. - avalon
1167 */
1168 class_mark_for_deletion();
1169
1170 clear_out_address_conf();
1171
1172 /* Clean out module paths */
1173 mod_clear_paths();
1174
1175 pseudo_clear();
1176
1177 /* Clean out ConfigServerInfo */
1178 xfree(ConfigServerInfo.description);
1179 ConfigServerInfo.description = NULL;
1180 xfree(ConfigServerInfo.network_name);
1181 ConfigServerInfo.network_name = NULL;
1182 xfree(ConfigServerInfo.network_desc);
1183 ConfigServerInfo.network_desc = NULL;
1184 #ifdef HAVE_LIBCRYPTO
1185 if (ConfigServerInfo.rsa_private_key)
1186 {
1187 RSA_free(ConfigServerInfo.rsa_private_key);
1188 ConfigServerInfo.rsa_private_key = NULL;
1189 }
1190 #endif
1191
1192 xfree(ConfigServerInfo.rsa_private_key_file);
1193 ConfigServerInfo.rsa_private_key_file = NULL;
1194 xfree(ConfigServerInfo.ssl_certificate_file);
1195 ConfigServerInfo.ssl_certificate_file = NULL;
1196 xfree(ConfigServerInfo.ssl_dh_param_file);
1197 ConfigServerInfo.ssl_dh_param_file = NULL;
1198 xfree(ConfigServerInfo.ssl_dh_elliptic_curve);
1199 ConfigServerInfo.ssl_dh_elliptic_curve = NULL;
1200 xfree(ConfigServerInfo.ssl_cipher_list);
1201 ConfigServerInfo.ssl_cipher_list = NULL;
1202 xfree(ConfigServerInfo.ssl_message_digest_algorithm);
1203 ConfigServerInfo.ssl_message_digest_algorithm = NULL;
1204
1205 /* Clean out ConfigAdminInfo */
1206 xfree(ConfigAdminInfo.name);
1207 ConfigAdminInfo.name = NULL;
1208 xfree(ConfigAdminInfo.email);
1209 ConfigAdminInfo.email = NULL;
1210 xfree(ConfigAdminInfo.description);
1211 ConfigAdminInfo.description = NULL;
1212
1213 xfree(ConfigServerHide.flatten_links_file);
1214 ConfigServerHide.flatten_links_file = NULL;
1215
1216 /* Clean out listeners */
1217 listener_close_marked();
1218 }
1219
1220 static void
1221 conf_handle_tls(int cold)
1222 {
1223 if (!tls_new_cred())
1224 {
1225 if (cold)
1226 {
1227 ilog(LOG_TYPE_IRCD, "Error while initializing TLS");
1228 exit(-1);
1229 }
1230 else
1231 {
1232 /* Failed to load new settings/certs, old ones remain active */
1233 sendto_realops_flags(UMODE_SERVNOTICE, L_ALL, SEND_NOTICE,
1234 "Error reloading TLS settings, check the ircd log"); // report_crypto_errors logs this
1235 }
1236 }
1237 }
1238
1239 /* read_conf_files()
1240 *
1241 * inputs - cold start YES or NO
1242 * output - none
1243 * side effects - read all conf files needed, ircd.conf kline.conf etc.
1244 */
1245 void
1246 read_conf_files(int cold)
1247 {
1248 const char *filename = NULL;
1249 char chanmodes[IRCD_BUFSIZE] = "";
1250 char chanlimit[IRCD_BUFSIZE] = "";
1251
1252 conf_parser_ctx.boot = cold;
1253 filename = ConfigGeneral.configfile;
1254
1255 /* We need to know the initial filename for the yyerror() to report
1256 FIXME: The full path is in conffilenamebuf first time since we
1257 don't know anything else
1258
1259 - Gozem 2002-07-21
1260 */
1261 strlcpy(conffilebuf, filename, sizeof(conffilebuf));
1262
1263 if ((conf_parser_ctx.conf_file = fopen(filename, "r")) == NULL)
1264 {
1265 if (cold)
1266 {
1267 ilog(LOG_TYPE_IRCD, "Unable to read configuration file '%s': %s",
1268 filename, strerror(errno));
1269 exit(EXIT_FAILURE);
1270 }
1271 else
1272 {
1273 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1274 "Unable to read configuration file '%s': %s",
1275 filename, strerror(errno));
1276 return;
1277 }
1278 }
1279
1280 if (!cold)
1281 clear_out_old_conf();
1282
1283 read_conf(conf_parser_ctx.conf_file);
1284 fclose(conf_parser_ctx.conf_file);
1285
1286 log_reopen_all();
1287 conf_handle_tls(cold);
1288
1289 isupport_add("NICKLEN", NULL, ConfigServerInfo.max_nick_length);
1290 isupport_add("NETWORK", ConfigServerInfo.network_name, -1);
1291
1292 snprintf(chanmodes, sizeof(chanmodes), "beI:%u", ConfigChannel.max_bans);
1293 isupport_add("MAXLIST", chanmodes, -1);
1294 isupport_add("MAXTARGETS", NULL, ConfigGeneral.max_targets);
1295 isupport_add("CHANTYPES", "#", -1);
1296
1297 snprintf(chanlimit, sizeof(chanlimit), "#:%u",
1298 ConfigChannel.max_channels);
1299 isupport_add("CHANLIMIT", chanlimit, -1);
1300 snprintf(chanmodes, sizeof(chanmodes), "%s", "beI,k,l,cimnprstCMORST");
1301 isupport_add("CHANNELLEN", NULL, CHANNELLEN);
1302 isupport_add("TOPICLEN", NULL, ConfigServerInfo.max_topic_length);
1303 isupport_add("CHANMODES", chanmodes, -1);
1304
1305 /*
1306 * message_locale may have changed. rebuild isupport since it relies
1307 * on strlen(form_str(RPL_ISUPPORT))
1308 */
1309 isupport_rebuild();
1310 }
1311
1312 /* conf_add_class_to_conf()
1313 *
1314 * inputs - pointer to config item
1315 * output - NONE
1316 * side effects - Add a class pointer to a conf
1317 */
1318 void
1319 conf_add_class_to_conf(struct MaskItem *conf, const char *name)
1320 {
1321 if (EmptyString(name) || (conf->class = class_find(name, 1)) == NULL)
1322 {
1323 conf->class = class_default;
1324
1325 if (conf->type == CONF_CLIENT || conf->type == CONF_OPER)
1326 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1327 "Warning *** Defaulting to default class for %s@%s",
1328 conf->user, conf->host);
1329 else
1330 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1331 "Warning *** Defaulting to default class for %s",
1332 conf->name);
1333 }
1334 }
1335
1336 /* yyerror()
1337 *
1338 * inputs - message from parser
1339 * output - NONE
1340 * side effects - message to opers and log file entry is made
1341 */
1342 void
1343 yyerror(const char *msg)
1344 {
1345 char newlinebuf[IRCD_BUFSIZE];
1346
1347 if (conf_parser_ctx.pass != 1)
1348 return;
1349
1350 strip_tabs(newlinebuf, linebuf, sizeof(newlinebuf));
1351 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1352 "\"%s\", line %u: %s: %s",
1353 conffilebuf, lineno + 1, msg, newlinebuf);
1354 ilog(LOG_TYPE_IRCD, "\"%s\", line %u: %s: %s",
1355 conffilebuf, lineno + 1, msg, newlinebuf);
1356 }
1357
1358 void
1359 conf_error_report(const char *msg)
1360 {
1361 char newlinebuf[IRCD_BUFSIZE];
1362
1363 strip_tabs(newlinebuf, linebuf, sizeof(newlinebuf));
1364 sendto_realops_flags(UMODE_SERVNOTICE, L_ADMIN, SEND_NOTICE,
1365 "\"%s\", line %u: %s: %s",
1366 conffilebuf, lineno + 1, msg, newlinebuf);
1367 ilog(LOG_TYPE_IRCD, "\"%s\", line %u: %s: %s",
1368 conffilebuf, lineno + 1, msg, newlinebuf);
1369 }
1370
1371 /*
1372 * valid_tkline()
1373 *
1374 * inputs - pointer to ascii string to check
1375 * - whether the specified time is in seconds or minutes
1376 * output - -1 not enough parameters
1377 * - 0 if not an integer number, else the number
1378 * side effects - none
1379 * Originally written by Dianora (Diane, db@db.net)
1380 */
1381 time_t
1382 valid_tkline(const char *data, const int minutes)
1383 {
1384 const unsigned char *p = (const unsigned char *)data;
1385 unsigned char tmpch = '\0';
1386 time_t result = 0;
1387
1388 while ((tmpch = *p++))
1389 {
1390 if (!IsDigit(tmpch))
1391 return 0;
1392
1393 result *= 10;
1394 result += (tmpch & 0xF);
1395 }
1396
1397 /*
1398 * In the degenerate case where oper does a /quote kline 0 user@host :reason
1399 * i.e. they specifically use 0, I am going to return 1 instead as a return
1400 * value of non-zero is used to flag it as a temporary kline
1401 */
1402 if (result == 0)
1403 result = 1;
1404
1405 /*
1406 * If the incoming time is in seconds convert it to minutes for the purpose
1407 * of this calculation
1408 */
1409 if (!minutes)
1410 result = result / 60;
1411
1412 if (result > MAX_TDKLINE_TIME)
1413 result = MAX_TDKLINE_TIME;
1414
1415 result = result * 60; /* Turn it into seconds */
1416
1417 return result;
1418 }
1419
1420 /* valid_wild_card_simple()
1421 *
1422 * inputs - data to check for sufficient non-wildcard characters
1423 * outputs - 1 if valid, else 0
1424 * side effects - none
1425 */
1426 int
1427 valid_wild_card_simple(const char *data)
1428 {
1429 const unsigned char *p = (const unsigned char *)data;
1430 unsigned char tmpch = '\0';
1431 unsigned int nonwild = 0, wild = 0;
1432
1433 while ((tmpch = *p++))
1434 {
1435 if (tmpch == '\\' && *p)
1436 {
1437 ++p;
1438 if (++nonwild >= ConfigGeneral.min_nonwildcard_simple)
1439 return 1;
1440 }
1441 else if (!IsMWildChar(tmpch))
1442 {
1443 if (++nonwild >= ConfigGeneral.min_nonwildcard_simple)
1444 return 1;
1445 }
1446 else
1447 ++wild;
1448 }
1449
1450 return !wild;
1451 }
1452
1453 /* valid_wild_card()
1454 *
1455 * input - pointer to client
1456 * - int flag, 0 for no warning oper 1 for warning oper
1457 * - count of following varargs to check
1458 * output - 0 if not valid, 1 if valid
1459 * side effects - NOTICE is given to source_p if warn is 1
1460 */
1461 int
1462 valid_wild_card(struct Client *source_p, int count, ...)
1463 {
1464 unsigned char tmpch = '\0';
1465 unsigned int nonwild = 0;
1466 va_list args;
1467
1468 /*
1469 * Now we must check the user and host to make sure there
1470 * are at least NONWILDCHARS non-wildcard characters in
1471 * them, otherwise assume they are attempting to kline
1472 * *@* or some variant of that. This code will also catch
1473 * people attempting to kline *@*.tld, as long as NONWILDCHARS
1474 * is greater than 3. In that case, there are only 3 non-wild
1475 * characters (tld), so if NONWILDCHARS is 4, the kline will
1476 * be disallowed.
1477 * -wnder
1478 */
1479
1480 va_start(args, count);
1481
1482 while (count--)
1483 {
1484 const unsigned char *p = va_arg(args, const unsigned char *);
1485 if (p == NULL)
1486 continue;
1487
1488 while ((tmpch = *p++))
1489 {
1490 if (!IsKWildChar(tmpch))
1491 {
1492 /*
1493 * If we find enough non-wild characters, we can
1494 * break - no point in searching further.
1495 */
1496 if (++nonwild >= ConfigGeneral.min_nonwildcard)
1497 {
1498 va_end(args);
1499 return 1;
1500 }
1501 }
1502 }
1503 }
1504
1505 if (IsClient(source_p))
1506 sendto_one_notice(source_p, &me,
1507 ":Please include at least %u non-wildcard characters with the mask",
1508 ConfigGeneral.min_nonwildcard);
1509 va_end(args);
1510 return 0;
1511 }
1512
1513 /* find_user_host()
1514 *
1515 * inputs - pointer to client placing kline
1516 * - pointer to user_host_or_nick
1517 * - pointer to user buffer
1518 * - pointer to host buffer
1519 * output - 0 if not ok to kline, 1 to kline i.e. if valid user host
1520 * side effects -
1521 */
1522 static int
1523 find_user_host(struct Client *source_p, char *user_host_or_nick,
1524 char *luser, char *lhost)
1525 {
1526 struct Client *target_p = NULL;
1527 char *hostp = NULL;
1528
1529 if (lhost == NULL)
1530 {
1531 strlcpy(luser, user_host_or_nick, USERLEN*4 + 1);
1532 return 1;
1533 }
1534
1535 if ((hostp = strchr(user_host_or_nick, '@')) || *user_host_or_nick == '*')
1536 {
1537 /* Explicit user@host mask given */
1538 if (hostp) /* I'm a little user@host */
1539 {
1540 *(hostp++) = '\0'; /* short and squat */
1541
1542 if (*user_host_or_nick)
1543 strlcpy(luser, user_host_or_nick, USERLEN*4 + 1); /* here is my user */
1544 else
1545 strcpy(luser, "*");
1546
1547 if (*hostp)
1548 strlcpy(lhost, hostp, HOSTLEN + 1); /* here is my host */
1549 else
1550 strcpy(lhost, "*");
1551 }
1552 else
1553 {
1554 luser[0] = '*'; /* no @ found, assume its *@somehost */
1555 luser[1] = '\0';
1556 strlcpy(lhost, user_host_or_nick, HOSTLEN*4 + 1);
1557 }
1558
1559 return 1;
1560 }
1561 else
1562 {
1563 /* Try to find user@host mask from nick */
1564 /* Okay to use source_p as the first param, because source_p == client_p */
1565 if ((target_p =
1566 find_chasing(source_p, user_host_or_nick)) == NULL)
1567 return 0; /* find_chasing sends ERR_NOSUCHNICK */
1568
1569 if (HasFlag(target_p, FLAGS_EXEMPTKLINE))
1570 {
1571 if (IsClient(source_p))
1572 sendto_one_notice(source_p, &me, ":%s is E-lined", target_p->name);
1573 return 0;
1574 }
1575
1576 /*
1577 * Turn the "user" bit into "*user", blow away '~'
1578 * if found in original user name (non-idented)
1579 */
1580 strlcpy(luser, target_p->username, USERLEN*4 + 1);
1581
1582 if (target_p->username[0] == '~')
1583 luser[0] = '*';
1584
1585 strlcpy(lhost, target_p->sockhost, HOSTLEN*4 + 1);
1586 return 1;
1587 }
1588
1589 return 0;
1590 }
1591
1592 /* XXX should this go into a separate file ? -Dianora */
1593 /* parse_aline
1594 *
1595 * input - pointer to cmd name being used
1596 * - pointer to client using cmd
1597 * - parc parameter count
1598 * - parv[] list of parameters to parse
1599 * - parse_flags bit map of things to test
1600 * - pointer to user or string to parse into
1601 * - pointer to host or NULL to parse into if non NULL
1602 * - pointer to optional tkline time or NULL
1603 * - pointer to target_server to parse into if non NULL
1604 * - pointer to reason to parse into
1605 *
1606 * output - 1 if valid, 0 if not valid
1607 * side effects - A generalised k/d/x etc. line parser,
1608 * "ALINE [time] user@host|string [ON] target :reason"
1609 * will parse returning a parsed user, host if
1610 * h_p pointer is non NULL, string otherwise.
1611 * if tkline_time pointer is non NULL a tk line will be set
1612 * to non zero if found.
1613 * if tkline_time pointer is NULL and tk line is found,
1614 * error is reported.
1615 * if target_server is NULL and an "ON" is found error
1616 * is reported.
1617 * if reason pointer is NULL ignore pointer,
1618 * this allows use of parse_a_line in unkline etc.
1619 *
1620 * - Dianora
1621 */
1622 int
1623 parse_aline(const char *cmd, struct Client *source_p,
1624 int parc, char **parv,
1625 int parse_flags, char **up_p, char **h_p, time_t *tkline_time,
1626 char **target_server, char **reason)
1627 {
1628 int found_tkline_time=0;
1629 static char default_reason[] = CONF_NOREASON;
1630 static char user[USERLEN*4+1];
1631 static char host[HOSTLEN*4+1];
1632
1633 parv++;
1634 parc--;
1635
1636 found_tkline_time = valid_tkline(*parv, TK_MINUTES);
1637
1638 if (found_tkline_time)
1639 {
1640 parv++;
1641 parc--;
1642
1643 if (tkline_time)
1644 *tkline_time = found_tkline_time;
1645 else
1646 {
1647 sendto_one_notice(source_p, &me, ":temp_line not supported by %s", cmd);
1648 return 0;
1649 }
1650 }
1651
1652 if (parc == 0)
1653 {
1654 sendto_one_numeric(source_p, &me, ERR_NEEDMOREPARAMS, cmd);
1655 return 0;
1656 }
1657
1658 if (h_p == NULL)
1659 *up_p = *parv;
1660 else
1661 {
1662 if (find_user_host(source_p, *parv, user, host) == 0)
1663 return 0;
1664
1665 *up_p = user;
1666 *h_p = host;
1667 }
1668
1669 parc--;
1670 parv++;
1671
1672 if (parc)
1673 {
1674 if (irccmp(*parv, "ON") == 0)
1675 {
1676 parc--;
1677 parv++;
1678
1679 if (!HasOFlag(source_p, OPER_FLAG_REMOTEBAN))
1680 {
1681 sendto_one_numeric(source_p, &me, ERR_NOPRIVS, "remoteban");
1682 return 0;
1683 }
1684
1685 if (parc == 0 || EmptyString(*parv))
1686 {
1687 sendto_one_numeric(source_p, &me, ERR_NEEDMOREPARAMS, cmd);
1688 return 0;
1689 }
1690
1691 *target_server = *parv;
1692 parc--;
1693 parv++;
1694 }
1695 else
1696 {
1697 /* Make sure target_server *is* NULL if no ON server found
1698 * caller probably NULL'd it first, but no harm to do it again -db
1699 */
1700 if (target_server)
1701 *target_server = NULL;
1702 }
1703 }
1704
1705 if (h_p)
1706 {
1707 if (strchr(user, '!'))
1708 {
1709 sendto_one_notice(source_p, &me, ":Invalid character '!' in kline");
1710 return 0;
1711 }
1712
1713 if ((parse_flags & AWILD) && !valid_wild_card(source_p, 2, *up_p, *h_p))
1714 return 0;
1715 }
1716 else
1717 if ((parse_flags & AWILD) && !valid_wild_card(source_p, 1, *up_p))
1718 return 0;
1719
1720 if (reason)
1721 {
1722 if (parc && !EmptyString(*parv))
1723 *reason = *parv;
1724 else
1725 *reason = default_reason;
1726 }
1727
1728 return 1;
1729 }
1730
1731 /* match_conf_password()
1732 *
1733 * inputs - pointer to given password
1734 * - pointer to Conf
1735 * output - 1 or 0 if match
1736 * side effects - none
1737 */
1738 int
1739 match_conf_password(const char *password, const struct MaskItem *conf)
1740 {
1741 const char *encr = NULL;
1742
1743 if (EmptyString(password) || EmptyString(conf->passwd))
1744 return 0;
1745
1746 if (conf->flags & CONF_FLAGS_ENCRYPTED)
1747 encr = crypt(password, conf->passwd);
1748 else
1749 encr = password;
1750
1751 return encr && !strcmp(encr, conf->passwd);
1752 }
1753
1754 /*
1755 * cluster_a_line
1756 *
1757 * inputs - client sending the cluster
1758 * - command name "KLINE" "XLINE" etc.
1759 * - capab -- CAPAB_KLN etc. from server.h
1760 * - cluster type -- CLUSTER_KLINE etc. from conf.h
1761 * - pattern and args to send along
1762 * output - none
1763 * side effects - Take source_p send the pattern with args given
1764 * along to all servers that match capab and cluster type
1765 */
1766 void
1767 cluster_a_line(struct Client *source_p, const char *command, unsigned int capab,
1768 unsigned int cluster_type, const char *pattern, ...)
1769 {
1770 va_list args;
1771 char buffer[IRCD_BUFSIZE] = "";
1772 const dlink_node *node = NULL;
1773
1774 va_start(args, pattern);
1775 vsnprintf(buffer, sizeof(buffer), pattern, args);
1776 va_end(args);
1777
1778 DLINK_FOREACH(node, cluster_items.head)
1779 {
1780 const struct MaskItem *conf = node->data;
1781
1782 if (conf->flags & cluster_type)
1783 sendto_match_servs(source_p, conf->name, CAPAB_CLUSTER | capab,
1784 "%s %s %s", command, conf->name, buffer);
1785 }
1786 }
1787
1788 /*
1789 * split_nuh
1790 *
1791 * inputs - pointer to original mask (modified in place)
1792 * - pointer to pointer where nick should go
1793 * - pointer to pointer where user should go
1794 * - pointer to pointer where host should go
1795 * output - NONE
1796 * side effects - mask is modified in place
1797 * If nick pointer is NULL, ignore writing to it
1798 * this allows us to use this function elsewhere.
1799 *
1800 * mask nick user host
1801 * ---------------------- ------- ------- ------
1802 * Dianora!db@db.net Dianora db db.net
1803 * Dianora Dianora * *
1804 * db.net * * db.net
1805 * OR if nick pointer is NULL
1806 * Dianora - * Dianora
1807 * Dianora! Dianora * *
1808 * Dianora!@ Dianora * *
1809 * Dianora!db Dianora db *
1810 * Dianora!@db.net Dianora * db.net
1811 * db@db.net * db db.net
1812 * !@ * * *
1813 * @ * * *
1814 * ! * * *
1815 */
1816 void
1817 split_nuh(struct split_nuh_item *const iptr)
1818 {
1819 char *p = NULL, *q = NULL;
1820
1821 if (iptr->nickptr)
1822 strlcpy(iptr->nickptr, "*", iptr->nicksize);
1823
1824 if (iptr->userptr)
1825 strlcpy(iptr->userptr, "*", iptr->usersize);
1826
1827 if (iptr->hostptr)
1828 strlcpy(iptr->hostptr, "*", iptr->hostsize);
1829
1830 if ((p = strchr(iptr->nuhmask, '!')))
1831 {
1832 *p = '\0';
1833
1834 if (iptr->nickptr && *iptr->nuhmask)
1835 strlcpy(iptr->nickptr, iptr->nuhmask, iptr->nicksize);
1836
1837 if ((q = strchr(++p, '@')))
1838 {
1839 *q++ = '\0';
1840
1841 if (*p)
1842 strlcpy(iptr->userptr, p, iptr->usersize);
1843
1844 if (*q)
1845 strlcpy(iptr->hostptr, q, iptr->hostsize);
1846 }
1847 else
1848 {
1849 if (*p)
1850 strlcpy(iptr->userptr, p, iptr->usersize);
1851 }
1852 }
1853 else
1854 {
1855 /* No ! found so lets look for a user@host */
1856 if ((p = strchr(iptr->nuhmask, '@')))
1857 {
1858 /* if found a @ */
1859 *p++ = '\0';
1860
1861 if (*iptr->nuhmask)
1862 strlcpy(iptr->userptr, iptr->nuhmask, iptr->usersize);
1863
1864 if (*p)
1865 strlcpy(iptr->hostptr, p, iptr->hostsize);
1866 }
1867 else
1868 {
1869 /* No @ found */
1870 if (!iptr->nickptr || strpbrk(iptr->nuhmask, ".:"))
1871 strlcpy(iptr->hostptr, iptr->nuhmask, iptr->hostsize);
1872 else
1873 strlcpy(iptr->nickptr, iptr->nuhmask, iptr->nicksize);
1874 }
1875 }
1876 }

Properties

Name Value
svn:eol-style native
svn:keywords Id Revision