1 |
|
/* |
2 |
|
* ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd) |
3 |
|
* |
4 |
< |
* Copyright (c) 1997-2014 ircd-hybrid development team |
4 |
> |
* Copyright (c) 1997-2015 ircd-hybrid development team |
5 |
|
* |
6 |
|
* This program is free software; you can redistribute it and/or modify |
7 |
|
* it under the terms of the GNU General Public License as published by |
15 |
|
* |
16 |
|
* You should have received a copy of the GNU General Public License |
17 |
|
* along with this program; if not, write to the Free Software |
18 |
< |
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 |
18 |
> |
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 |
19 |
|
* USA |
20 |
|
*/ |
21 |
|
|
28 |
|
#include "list.h" |
29 |
|
#include "ircd_defs.h" |
30 |
|
#include "conf.h" |
31 |
< |
#include "s_serv.h" |
31 |
> |
#include "conf_pseudo.h" |
32 |
> |
#include "server.h" |
33 |
|
#include "resv.h" |
34 |
|
#include "channel.h" |
35 |
|
#include "client.h" |
36 |
|
#include "event.h" |
36 |
– |
#include "hook.h" |
37 |
|
#include "irc_string.h" |
38 |
|
#include "s_bsd.h" |
39 |
|
#include "ircd.h" |
44 |
|
#include "fdlist.h" |
45 |
|
#include "log.h" |
46 |
|
#include "send.h" |
47 |
– |
#include "s_gline.h" |
47 |
|
#include "memory.h" |
48 |
< |
#include "mempool.h" |
50 |
< |
#include "irc_res.h" |
48 |
> |
#include "res.h" |
49 |
|
#include "userhost.h" |
50 |
< |
#include "s_user.h" |
50 |
> |
#include "user.h" |
51 |
|
#include "channel_mode.h" |
52 |
|
#include "parse.h" |
53 |
< |
#include "s_misc.h" |
53 |
> |
#include "misc.h" |
54 |
|
#include "conf_db.h" |
55 |
|
#include "conf_class.h" |
56 |
|
#include "motd.h" |
57 |
+ |
#include "ipcache.h" |
58 |
|
|
59 |
|
|
60 |
|
struct config_channel_entry ConfigChannel; |
61 |
< |
struct config_server_hide ConfigServerHide; |
62 |
< |
struct config_file_entry ConfigFileEntry; |
63 |
< |
struct logging_entry ConfigLoggingEntry = { .use_logging = 1 }; |
64 |
< |
struct server_info ServerInfo; |
65 |
< |
struct admin_info AdminInfo; |
61 |
> |
struct config_serverhide_entry ConfigServerHide; |
62 |
> |
struct config_general_entry ConfigGeneral; |
63 |
> |
struct config_log_entry ConfigLog = { .use_logging = 1 }; |
64 |
> |
struct config_serverinfo_entry ConfigServerInfo; |
65 |
> |
struct config_admin_entry ConfigAdminInfo; |
66 |
> |
struct conf_parser_context conf_parser_ctx; |
67 |
|
|
68 |
|
/* general conf items link list root, other than k lines etc. */ |
69 |
< |
dlink_list service_items = { NULL, NULL, 0 }; |
70 |
< |
dlink_list server_items = { NULL, NULL, 0 }; |
71 |
< |
dlink_list cluster_items = { NULL, NULL, 0 }; |
72 |
< |
dlink_list oconf_items = { NULL, NULL, 0 }; |
73 |
< |
dlink_list uconf_items = { NULL, NULL, 0 }; |
74 |
< |
dlink_list xconf_items = { NULL, NULL, 0 }; |
75 |
< |
dlink_list nresv_items = { NULL, NULL, 0 }; |
76 |
< |
dlink_list cresv_items = { NULL, NULL, 0 }; |
69 |
> |
dlink_list service_items; |
70 |
> |
dlink_list server_items; |
71 |
> |
dlink_list cluster_items; |
72 |
> |
dlink_list oconf_items; |
73 |
> |
dlink_list uconf_items; |
74 |
> |
dlink_list xconf_items; |
75 |
> |
dlink_list nresv_items; |
76 |
> |
dlink_list cresv_items; |
77 |
|
|
78 |
|
extern unsigned int lineno; |
79 |
|
extern char linebuf[]; |
80 |
|
extern char conffilebuf[IRCD_BUFSIZE]; |
81 |
|
extern int yyparse(); /* defined in y.tab.c */ |
82 |
|
|
83 |
– |
struct conf_parser_context conf_parser_ctx = { 0, 0, NULL }; |
84 |
– |
|
85 |
– |
/* internally defined functions */ |
86 |
– |
static void read_conf(FILE *); |
87 |
– |
static void clear_out_old_conf(void); |
88 |
– |
static void expire_tklines(dlink_list *); |
89 |
– |
static void garbage_collect_ip_entries(void); |
90 |
– |
static int hash_ip(struct irc_ssaddr *); |
91 |
– |
static int verify_access(struct Client *); |
92 |
– |
static int attach_iline(struct Client *, struct MaskItem *); |
93 |
– |
static struct ip_entry *find_or_add_ip(struct irc_ssaddr *); |
94 |
– |
static dlink_list *map_to_list(enum maskitem_type); |
95 |
– |
static int find_user_host(struct Client *, char *, char *, char *, unsigned int); |
96 |
– |
|
97 |
– |
|
98 |
– |
/* usually, with hash tables, you use a prime number... |
99 |
– |
* but in this case I am dealing with ip addresses, |
100 |
– |
* not ascii strings. |
101 |
– |
*/ |
102 |
– |
#define IP_HASH_SIZE 0x1000 |
103 |
– |
|
104 |
– |
struct ip_entry |
105 |
– |
{ |
106 |
– |
struct irc_ssaddr ip; |
107 |
– |
unsigned int count; |
108 |
– |
time_t last_attempt; |
109 |
– |
struct ip_entry *next; |
110 |
– |
}; |
111 |
– |
|
112 |
– |
static struct ip_entry *ip_hash_table[IP_HASH_SIZE]; |
113 |
– |
static mp_pool_t *ip_entry_pool = NULL; |
114 |
– |
static int ip_entries_count = 0; |
115 |
– |
|
83 |
|
|
84 |
|
/* conf_dns_callback() |
85 |
|
* |
92 |
|
* if successful save hp in the conf item it was called with |
93 |
|
*/ |
94 |
|
static void |
95 |
< |
conf_dns_callback(void *vptr, const struct irc_ssaddr *addr, const char *name) |
95 |
> |
conf_dns_callback(void *vptr, const struct irc_ssaddr *addr, const char *name, size_t namelength) |
96 |
|
{ |
97 |
< |
struct MaskItem *conf = vptr; |
97 |
> |
struct MaskItem *const conf = vptr; |
98 |
|
|
99 |
|
conf->dns_pending = 0; |
100 |
|
|
101 |
< |
if (addr != NULL) |
101 |
> |
if (addr) |
102 |
|
memcpy(&conf->addr, addr, sizeof(conf->addr)); |
103 |
|
else |
104 |
|
conf->dns_failed = 1; |
113 |
|
static void |
114 |
|
conf_dns_lookup(struct MaskItem *conf) |
115 |
|
{ |
116 |
< |
if (!conf->dns_pending) |
116 |
> |
if (conf->dns_pending) |
117 |
> |
return; |
118 |
> |
|
119 |
> |
conf->dns_pending = 1; |
120 |
> |
|
121 |
> |
if (conf->aftype == AF_INET) |
122 |
> |
gethost_byname_type(conf_dns_callback, conf, conf->host, T_A); |
123 |
> |
else |
124 |
> |
gethost_byname_type(conf_dns_callback, conf, conf->host, T_AAAA); |
125 |
> |
} |
126 |
> |
|
127 |
> |
/* map_to_list() |
128 |
> |
* |
129 |
> |
* inputs - ConfType conf |
130 |
> |
* output - pointer to dlink_list to use |
131 |
> |
* side effects - none |
132 |
> |
*/ |
133 |
> |
static dlink_list * |
134 |
> |
map_to_list(enum maskitem_type type) |
135 |
> |
{ |
136 |
> |
switch (type) |
137 |
|
{ |
138 |
< |
conf->dns_pending = 1; |
139 |
< |
gethost_byname(conf_dns_callback, conf, conf->host); |
138 |
> |
case CONF_XLINE: |
139 |
> |
return &xconf_items; |
140 |
> |
break; |
141 |
> |
case CONF_ULINE: |
142 |
> |
return &uconf_items; |
143 |
> |
break; |
144 |
> |
case CONF_NRESV: |
145 |
> |
return &nresv_items; |
146 |
> |
break; |
147 |
> |
case CONF_CRESV: |
148 |
> |
return &cresv_items; |
149 |
> |
break; |
150 |
> |
case CONF_OPER: |
151 |
> |
return &oconf_items; |
152 |
> |
break; |
153 |
> |
case CONF_SERVER: |
154 |
> |
return &server_items; |
155 |
> |
break; |
156 |
> |
case CONF_SERVICE: |
157 |
> |
return &service_items; |
158 |
> |
break; |
159 |
> |
case CONF_CLUSTER: |
160 |
> |
return &cluster_items; |
161 |
> |
break; |
162 |
> |
default: |
163 |
> |
return NULL; |
164 |
|
} |
165 |
|
} |
166 |
|
|
167 |
|
struct MaskItem * |
168 |
|
conf_make(enum maskitem_type type) |
169 |
|
{ |
170 |
< |
struct MaskItem *conf = MyMalloc(sizeof(*conf)); |
170 |
> |
struct MaskItem *const conf = MyCalloc(sizeof(*conf)); |
171 |
|
dlink_list *list = NULL; |
172 |
|
|
173 |
|
conf->type = type; |
182 |
|
void |
183 |
|
conf_free(struct MaskItem *conf) |
184 |
|
{ |
185 |
< |
dlink_node *ptr = NULL, *ptr_next = NULL; |
185 |
> |
dlink_node *node = NULL, *node_next = NULL; |
186 |
|
dlink_list *list = NULL; |
187 |
|
|
188 |
< |
if (conf->node.next) |
189 |
< |
if ((list = map_to_list(conf->type))) |
179 |
< |
dlinkDelete(&conf->node, list); |
188 |
> |
if ((list = map_to_list(conf->type))) |
189 |
> |
dlinkFindDelete(list, conf); |
190 |
|
|
191 |
|
MyFree(conf->name); |
192 |
|
|
193 |
|
if (conf->dns_pending) |
194 |
|
delete_resolver_queries(conf); |
195 |
< |
if (conf->passwd != NULL) |
195 |
> |
if (conf->passwd) |
196 |
|
memset(conf->passwd, 0, strlen(conf->passwd)); |
197 |
< |
if (conf->spasswd != NULL) |
197 |
> |
if (conf->spasswd) |
198 |
|
memset(conf->spasswd, 0, strlen(conf->spasswd)); |
199 |
|
|
200 |
|
conf->class = NULL; |
203 |
|
MyFree(conf->spasswd); |
204 |
|
MyFree(conf->reason); |
205 |
|
MyFree(conf->certfp); |
206 |
+ |
MyFree(conf->whois); |
207 |
|
MyFree(conf->user); |
208 |
|
MyFree(conf->host); |
209 |
|
#ifdef HAVE_LIBCRYPTO |
212 |
|
if (conf->rsa_public_key) |
213 |
|
RSA_free(conf->rsa_public_key); |
214 |
|
#endif |
215 |
< |
DLINK_FOREACH_SAFE(ptr, ptr_next, conf->hub_list.head) |
215 |
> |
DLINK_FOREACH_SAFE(node, node_next, conf->hub_list.head) |
216 |
|
{ |
217 |
< |
MyFree(ptr->data); |
218 |
< |
dlinkDelete(ptr, &conf->hub_list); |
219 |
< |
free_dlink_node(ptr); |
217 |
> |
MyFree(node->data); |
218 |
> |
dlinkDelete(node, &conf->hub_list); |
219 |
> |
free_dlink_node(node); |
220 |
|
} |
221 |
|
|
222 |
< |
DLINK_FOREACH_SAFE(ptr, ptr_next, conf->leaf_list.head) |
222 |
> |
DLINK_FOREACH_SAFE(node, node_next, conf->leaf_list.head) |
223 |
|
{ |
224 |
< |
MyFree(ptr->data); |
225 |
< |
dlinkDelete(ptr, &conf->leaf_list); |
226 |
< |
free_dlink_node(ptr); |
224 |
> |
MyFree(node->data); |
225 |
> |
dlinkDelete(node, &conf->leaf_list); |
226 |
> |
free_dlink_node(node); |
227 |
|
} |
228 |
|
|
229 |
< |
DLINK_FOREACH_SAFE(ptr, ptr_next, conf->exempt_list.head) |
229 |
> |
DLINK_FOREACH_SAFE(node, node_next, conf->exempt_list.head) |
230 |
|
{ |
231 |
< |
struct exempt *exptr = ptr->data; |
231 |
> |
struct exempt *exptr = node->data; |
232 |
|
|
233 |
< |
dlinkDelete(ptr, &conf->exempt_list); |
233 |
> |
dlinkDelete(node, &conf->exempt_list); |
234 |
|
MyFree(exptr->name); |
235 |
|
MyFree(exptr->user); |
236 |
|
MyFree(exptr->host); |
240 |
|
MyFree(conf); |
241 |
|
} |
242 |
|
|
243 |
< |
/* check_client() |
243 |
> |
/* attach_iline() |
244 |
|
* |
245 |
< |
* inputs - pointer to client |
246 |
< |
* output - 0 = Success |
247 |
< |
* NOT_AUTHORIZED (-1) = Access denied (no I line match) |
248 |
< |
* IRCD_SOCKET_ERROR (-2) = Bad socket. |
238 |
< |
* I_LINE_FULL (-3) = I-line is full |
239 |
< |
* TOO_MANY (-4) = Too many connections from hostname |
240 |
< |
* BANNED_CLIENT (-5) = K-lined |
241 |
< |
* side effects - Ordinary client access check. |
242 |
< |
* Look for conf lines which have the same |
243 |
< |
* status as the flags passed. |
245 |
> |
* inputs - client pointer |
246 |
> |
* - conf pointer |
247 |
> |
* output - |
248 |
> |
* side effects - do actual attach |
249 |
|
*/ |
250 |
< |
int |
251 |
< |
check_client(struct Client *source_p) |
250 |
> |
static int |
251 |
> |
attach_iline(struct Client *client_p, struct MaskItem *conf) |
252 |
|
{ |
253 |
< |
int i; |
254 |
< |
|
255 |
< |
if ((i = verify_access(source_p))) |
256 |
< |
ilog(LOG_TYPE_IRCD, "Access denied: %s[%s]", |
252 |
< |
source_p->name, source_p->sockhost); |
253 |
< |
|
254 |
< |
switch (i) |
255 |
< |
{ |
256 |
< |
case TOO_MANY: |
257 |
< |
sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE, |
258 |
< |
"Too many on IP for %s (%s).", |
259 |
< |
get_client_name(source_p, SHOW_IP), |
260 |
< |
source_p->sockhost); |
261 |
< |
ilog(LOG_TYPE_IRCD, "Too many connections on IP from %s.", |
262 |
< |
get_client_name(source_p, SHOW_IP)); |
263 |
< |
++ServerStats.is_ref; |
264 |
< |
exit_client(source_p, "No more connections allowed on that IP"); |
265 |
< |
break; |
253 |
> |
const struct ClassItem *const class = conf->class; |
254 |
> |
struct ip_entry *ip_found; |
255 |
> |
int a_limit_reached = 0; |
256 |
> |
unsigned int local = 0, global = 0, ident = 0; |
257 |
|
|
258 |
< |
case I_LINE_FULL: |
259 |
< |
sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE, |
260 |
< |
"auth{} block is full for %s (%s).", |
270 |
< |
get_client_name(source_p, SHOW_IP), |
271 |
< |
source_p->sockhost); |
272 |
< |
ilog(LOG_TYPE_IRCD, "Too many connections from %s.", |
273 |
< |
get_client_name(source_p, SHOW_IP)); |
274 |
< |
++ServerStats.is_ref; |
275 |
< |
exit_client(source_p, "No more connections allowed in your connection class"); |
276 |
< |
break; |
258 |
> |
ip_found = ipcache_find_or_add_address(&client_p->connection->ip); |
259 |
> |
ip_found->count++; |
260 |
> |
AddFlag(client_p, FLAGS_IPHASH); |
261 |
|
|
262 |
< |
case NOT_AUTHORIZED: |
263 |
< |
++ServerStats.is_ref; |
280 |
< |
/* jdc - lists server name & port connections are on */ |
281 |
< |
/* a purely cosmetical change */ |
282 |
< |
sendto_realops_flags(UMODE_UNAUTH, L_ALL, SEND_NOTICE, |
283 |
< |
"Unauthorized client connection from %s [%s] on [%s/%u].", |
284 |
< |
get_client_name(source_p, SHOW_IP), |
285 |
< |
source_p->sockhost, |
286 |
< |
source_p->localClient->listener->name, |
287 |
< |
source_p->localClient->listener->port); |
288 |
< |
ilog(LOG_TYPE_IRCD, |
289 |
< |
"Unauthorized client connection from %s on [%s/%u].", |
290 |
< |
get_client_name(source_p, SHOW_IP), |
291 |
< |
source_p->localClient->listener->name, |
292 |
< |
source_p->localClient->listener->port); |
262 |
> |
count_user_host(client_p->username, client_p->host, |
263 |
> |
&global, &local, &ident); |
264 |
|
|
265 |
< |
exit_client(source_p, "You are not authorized to use this server"); |
266 |
< |
break; |
265 |
> |
/* XXX blah. go down checking the various silly limits |
266 |
> |
* setting a_limit_reached if any limit is reached. |
267 |
> |
* - Dianora |
268 |
> |
*/ |
269 |
> |
if (class->max_total && class->ref_count >= class->max_total) |
270 |
> |
a_limit_reached = 1; |
271 |
> |
else if (class->max_perip && ip_found->count > class->max_perip) |
272 |
> |
a_limit_reached = 1; |
273 |
> |
else if (class->max_local && local >= class->max_local) |
274 |
> |
a_limit_reached = 1; |
275 |
> |
else if (class->max_global && global >= class->max_global) |
276 |
> |
a_limit_reached = 1; |
277 |
> |
else if (class->max_ident && ident >= class->max_ident && |
278 |
> |
client_p->username[0] != '~') |
279 |
> |
a_limit_reached = 1; |
280 |
|
|
281 |
< |
case BANNED_CLIENT: |
282 |
< |
exit_client(source_p, "Banned"); |
283 |
< |
++ServerStats.is_ref; |
284 |
< |
break; |
281 |
> |
if (a_limit_reached) |
282 |
> |
{ |
283 |
> |
if (!IsConfExemptLimits(conf)) |
284 |
> |
return TOO_MANY; /* Already at maximum allowed */ |
285 |
|
|
286 |
< |
case 0: |
287 |
< |
default: |
304 |
< |
break; |
286 |
> |
sendto_one_notice(client_p, &me, ":*** Your connection class is full, " |
287 |
> |
"but you have exceed_limit = yes;"); |
288 |
|
} |
289 |
|
|
290 |
< |
return (i < 0 ? 0 : 1); |
290 |
> |
return attach_conf(client_p, conf); |
291 |
|
} |
292 |
|
|
293 |
|
/* verify_access() |
294 |
|
* |
295 |
< |
* inputs - pointer to client to verify |
296 |
< |
* output - 0 if success -'ve if not |
297 |
< |
* side effect - find the first (best) I line to attach. |
295 |
> |
* inputs - pointer to client to verify |
296 |
> |
* output - 0 if success -'ve if not |
297 |
> |
* side effect - find the first (best) I line to attach. |
298 |
|
*/ |
299 |
|
static int |
300 |
|
verify_access(struct Client *client_p) |
301 |
|
{ |
302 |
|
struct MaskItem *conf = NULL; |
320 |
– |
char non_ident[USERLEN + 1] = "~"; |
303 |
|
|
304 |
|
if (IsGotId(client_p)) |
305 |
|
{ |
306 |
|
conf = find_address_conf(client_p->host, client_p->username, |
307 |
< |
&client_p->localClient->ip, |
308 |
< |
client_p->localClient->aftype, |
309 |
< |
client_p->localClient->passwd); |
307 |
> |
&client_p->connection->ip, |
308 |
> |
client_p->connection->aftype, |
309 |
> |
client_p->connection->password); |
310 |
|
} |
311 |
|
else |
312 |
|
{ |
313 |
+ |
char non_ident[USERLEN + 1] = "~"; |
314 |
+ |
|
315 |
|
strlcpy(non_ident + 1, client_p->username, sizeof(non_ident) - 1); |
316 |
< |
conf = find_address_conf(client_p->host,non_ident, |
317 |
< |
&client_p->localClient->ip, |
318 |
< |
client_p->localClient->aftype, |
319 |
< |
client_p->localClient->passwd); |
316 |
> |
conf = find_address_conf(client_p->host, non_ident, |
317 |
> |
&client_p->connection->ip, |
318 |
> |
client_p->connection->aftype, |
319 |
> |
client_p->connection->password); |
320 |
|
} |
321 |
|
|
322 |
|
if (conf) |
331 |
|
return NOT_AUTHORIZED; |
332 |
|
} |
333 |
|
|
350 |
– |
if (IsConfDoIdentd(conf)) |
351 |
– |
SetNeedId(client_p); |
352 |
– |
|
334 |
|
/* Thanks for spoof idea amm */ |
335 |
|
if (IsConfDoSpoofIp(conf)) |
336 |
|
{ |
337 |
< |
if (!ConfigFileEntry.hide_spoof_ips && IsConfSpoofNotice(conf)) |
338 |
< |
sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE, |
358 |
< |
"%s spoofing: %s as %s", |
337 |
> |
if (IsConfSpoofNotice(conf)) |
338 |
> |
sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE, "%s spoofing: %s as %s", |
339 |
|
client_p->name, client_p->host, conf->name); |
340 |
+ |
|
341 |
|
strlcpy(client_p->host, conf->name, sizeof(client_p->host)); |
361 |
– |
AddFlag(client_p, FLAGS_IP_SPOOFING | FLAGS_AUTH_SPOOF); |
342 |
|
} |
343 |
|
|
344 |
|
return attach_iline(client_p, conf); |
345 |
|
} |
346 |
< |
else if (IsConfKill(conf) || (ConfigFileEntry.glines && IsConfGline(conf))) |
346 |
> |
else if (IsConfKill(conf) || (ConfigGeneral.glines && IsConfGline(conf))) |
347 |
|
{ |
348 |
|
if (IsConfGline(conf)) |
349 |
|
sendto_one_notice(client_p, &me, ":*** G-lined"); |
350 |
+ |
|
351 |
|
sendto_one_notice(client_p, &me, ":*** Banned: %s", conf->reason); |
352 |
|
return BANNED_CLIENT; |
353 |
|
} |
356 |
|
return NOT_AUTHORIZED; |
357 |
|
} |
358 |
|
|
359 |
< |
/* attach_iline() |
379 |
< |
* |
380 |
< |
* inputs - client pointer |
381 |
< |
* - conf pointer |
382 |
< |
* output - |
383 |
< |
* side effects - do actual attach |
384 |
< |
*/ |
385 |
< |
static int |
386 |
< |
attach_iline(struct Client *client_p, struct MaskItem *conf) |
387 |
< |
{ |
388 |
< |
struct ClassItem *class = NULL; |
389 |
< |
struct ip_entry *ip_found; |
390 |
< |
int a_limit_reached = 0; |
391 |
< |
unsigned int local = 0, global = 0, ident = 0; |
392 |
< |
|
393 |
< |
assert(conf->class); |
394 |
< |
|
395 |
< |
ip_found = find_or_add_ip(&client_p->localClient->ip); |
396 |
< |
ip_found->count++; |
397 |
< |
SetIpHash(client_p); |
398 |
< |
|
399 |
< |
class = conf->class; |
400 |
< |
|
401 |
< |
count_user_host(client_p->username, client_p->host, |
402 |
< |
&global, &local, &ident); |
403 |
< |
|
404 |
< |
/* XXX blah. go down checking the various silly limits |
405 |
< |
* setting a_limit_reached if any limit is reached. |
406 |
< |
* - Dianora |
407 |
< |
*/ |
408 |
< |
if (class->max_total != 0 && class->ref_count >= class->max_total) |
409 |
< |
a_limit_reached = 1; |
410 |
< |
else if (class->max_perip != 0 && ip_found->count > class->max_perip) |
411 |
< |
a_limit_reached = 1; |
412 |
< |
else if (class->max_local != 0 && local >= class->max_local) |
413 |
< |
a_limit_reached = 1; |
414 |
< |
else if (class->max_global != 0 && global >= class->max_global) |
415 |
< |
a_limit_reached = 1; |
416 |
< |
else if (class->max_ident != 0 && ident >= class->max_ident && |
417 |
< |
client_p->username[0] != '~') |
418 |
< |
a_limit_reached = 1; |
419 |
< |
|
420 |
< |
if (a_limit_reached) |
421 |
< |
{ |
422 |
< |
if (!IsConfExemptLimits(conf)) |
423 |
< |
return TOO_MANY; /* Already at maximum allowed */ |
424 |
< |
|
425 |
< |
sendto_one_notice(client_p, &me, ":*** Your connection class is full, " |
426 |
< |
"but you have exceed_limit = yes;"); |
427 |
< |
} |
428 |
< |
|
429 |
< |
return attach_conf(client_p, conf); |
430 |
< |
} |
431 |
< |
|
432 |
< |
/* init_ip_hash_table() |
433 |
< |
* |
434 |
< |
* inputs - NONE |
435 |
< |
* output - NONE |
436 |
< |
* side effects - allocate memory for ip_entry(s) |
437 |
< |
* - clear the ip hash table |
438 |
< |
*/ |
439 |
< |
void |
440 |
< |
init_ip_hash_table(void) |
441 |
< |
{ |
442 |
< |
ip_entry_pool = mp_pool_new(sizeof(struct ip_entry), MP_CHUNK_SIZE_IP_ENTRY); |
443 |
< |
memset(ip_hash_table, 0, sizeof(ip_hash_table)); |
444 |
< |
} |
445 |
< |
|
446 |
< |
/* find_or_add_ip() |
447 |
< |
* |
448 |
< |
* inputs - pointer to struct irc_ssaddr |
449 |
< |
* output - pointer to a struct ip_entry |
450 |
< |
* side effects - |
359 |
> |
/* check_client() |
360 |
|
* |
361 |
< |
* If the ip # was not found, a new struct ip_entry is created, and the ip |
362 |
< |
* count set to 0. |
361 |
> |
* inputs - pointer to client |
362 |
> |
* output - 0 = Success |
363 |
> |
* NOT_AUTHORIZED (-1) = Access denied (no I line match) |
364 |
> |
* IRCD_SOCKET_ERROR (-2) = Bad socket. |
365 |
> |
* I_LINE_FULL (-3) = I-line is full |
366 |
> |
* TOO_MANY (-4) = Too many connections from hostname |
367 |
> |
* BANNED_CLIENT (-5) = K-lined |
368 |
> |
* side effects - Ordinary client access check. |
369 |
> |
* Look for conf lines which have the same |
370 |
> |
* status as the flags passed. |
371 |
|
*/ |
372 |
< |
static struct ip_entry * |
373 |
< |
find_or_add_ip(struct irc_ssaddr *ip_in) |
372 |
> |
int |
373 |
> |
check_client(struct Client *source_p) |
374 |
|
{ |
375 |
< |
struct ip_entry *ptr, *newptr; |
459 |
< |
int hash_index = hash_ip(ip_in), res; |
460 |
< |
struct sockaddr_in *v4 = (struct sockaddr_in *)ip_in, *ptr_v4; |
461 |
< |
#ifdef IPV6 |
462 |
< |
struct sockaddr_in6 *v6 = (struct sockaddr_in6 *)ip_in, *ptr_v6; |
463 |
< |
#endif |
464 |
< |
|
465 |
< |
for (ptr = ip_hash_table[hash_index]; ptr; ptr = ptr->next) |
466 |
< |
{ |
467 |
< |
#ifdef IPV6 |
468 |
< |
if (ptr->ip.ss.ss_family != ip_in->ss.ss_family) |
469 |
< |
continue; |
470 |
< |
if (ip_in->ss.ss_family == AF_INET6) |
471 |
< |
{ |
472 |
< |
ptr_v6 = (struct sockaddr_in6 *)&ptr->ip; |
473 |
< |
res = memcmp(&v6->sin6_addr, &ptr_v6->sin6_addr, sizeof(struct in6_addr)); |
474 |
< |
} |
475 |
< |
else |
476 |
< |
#endif |
477 |
< |
{ |
478 |
< |
ptr_v4 = (struct sockaddr_in *)&ptr->ip; |
479 |
< |
res = memcmp(&v4->sin_addr, &ptr_v4->sin_addr, sizeof(struct in_addr)); |
480 |
< |
} |
481 |
< |
if (res == 0) |
482 |
< |
{ |
483 |
< |
/* Found entry already in hash, return it. */ |
484 |
< |
return ptr; |
485 |
< |
} |
486 |
< |
} |
487 |
< |
|
488 |
< |
if (ip_entries_count >= 2 * hard_fdlimit) |
489 |
< |
garbage_collect_ip_entries(); |
490 |
< |
|
491 |
< |
newptr = mp_pool_get(ip_entry_pool); |
492 |
< |
memset(newptr, 0, sizeof(*newptr)); |
493 |
< |
ip_entries_count++; |
494 |
< |
memcpy(&newptr->ip, ip_in, sizeof(struct irc_ssaddr)); |
495 |
< |
|
496 |
< |
newptr->next = ip_hash_table[hash_index]; |
497 |
< |
ip_hash_table[hash_index] = newptr; |
498 |
< |
|
499 |
< |
return newptr; |
500 |
< |
} |
375 |
> |
int i; |
376 |
|
|
377 |
< |
/* remove_one_ip() |
378 |
< |
* |
379 |
< |
* inputs - unsigned long IP address value |
505 |
< |
* output - NONE |
506 |
< |
* side effects - The ip address given, is looked up in ip hash table |
507 |
< |
* and number of ip#'s for that ip decremented. |
508 |
< |
* If ip # count reaches 0 and has expired, |
509 |
< |
* the struct ip_entry is returned to the ip_entry_heap |
510 |
< |
*/ |
511 |
< |
void |
512 |
< |
remove_one_ip(struct irc_ssaddr *ip_in) |
513 |
< |
{ |
514 |
< |
struct ip_entry *ptr; |
515 |
< |
struct ip_entry *last_ptr = NULL; |
516 |
< |
int hash_index = hash_ip(ip_in), res; |
517 |
< |
struct sockaddr_in *v4 = (struct sockaddr_in *)ip_in, *ptr_v4; |
518 |
< |
#ifdef IPV6 |
519 |
< |
struct sockaddr_in6 *v6 = (struct sockaddr_in6 *)ip_in, *ptr_v6; |
520 |
< |
#endif |
377 |
> |
if ((i = verify_access(source_p))) |
378 |
> |
ilog(LOG_TYPE_IRCD, "Access denied: %s[%s]", |
379 |
> |
source_p->name, source_p->sockhost); |
380 |
|
|
381 |
< |
for (ptr = ip_hash_table[hash_index]; ptr; ptr = ptr->next) |
381 |
> |
switch (i) |
382 |
|
{ |
383 |
< |
#ifdef IPV6 |
384 |
< |
if (ptr->ip.ss.ss_family != ip_in->ss.ss_family) |
385 |
< |
continue; |
386 |
< |
if (ip_in->ss.ss_family == AF_INET6) |
387 |
< |
{ |
388 |
< |
ptr_v6 = (struct sockaddr_in6 *)&ptr->ip; |
389 |
< |
res = memcmp(&v6->sin6_addr, &ptr_v6->sin6_addr, sizeof(struct in6_addr)); |
390 |
< |
} |
391 |
< |
else |
392 |
< |
#endif |
534 |
< |
{ |
535 |
< |
ptr_v4 = (struct sockaddr_in *)&ptr->ip; |
536 |
< |
res = memcmp(&v4->sin_addr, &ptr_v4->sin_addr, sizeof(struct in_addr)); |
537 |
< |
} |
538 |
< |
if (res) |
539 |
< |
continue; |
540 |
< |
if (ptr->count > 0) |
541 |
< |
ptr->count--; |
542 |
< |
if (ptr->count == 0 && |
543 |
< |
(CurrentTime-ptr->last_attempt) >= ConfigFileEntry.throttle_time) |
544 |
< |
{ |
545 |
< |
if (last_ptr != NULL) |
546 |
< |
last_ptr->next = ptr->next; |
547 |
< |
else |
548 |
< |
ip_hash_table[hash_index] = ptr->next; |
549 |
< |
|
550 |
< |
mp_pool_release(ptr); |
551 |
< |
ip_entries_count--; |
552 |
< |
return; |
553 |
< |
} |
554 |
< |
last_ptr = ptr; |
555 |
< |
} |
556 |
< |
} |
383 |
> |
case TOO_MANY: |
384 |
> |
sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE, |
385 |
> |
"Too many on IP for %s (%s).", |
386 |
> |
get_client_name(source_p, SHOW_IP), |
387 |
> |
source_p->sockhost); |
388 |
> |
ilog(LOG_TYPE_IRCD, "Too many connections on IP from %s.", |
389 |
> |
get_client_name(source_p, SHOW_IP)); |
390 |
> |
++ServerStats.is_ref; |
391 |
> |
exit_client(source_p, "No more connections allowed on that IP"); |
392 |
> |
break; |
393 |
|
|
394 |
< |
/* hash_ip() |
395 |
< |
* |
396 |
< |
* input - pointer to an irc_inaddr |
397 |
< |
* output - integer value used as index into hash table |
398 |
< |
* side effects - hopefully, none |
399 |
< |
*/ |
400 |
< |
static int |
401 |
< |
hash_ip(struct irc_ssaddr *addr) |
402 |
< |
{ |
403 |
< |
if (addr->ss.ss_family == AF_INET) |
568 |
< |
{ |
569 |
< |
struct sockaddr_in *v4 = (struct sockaddr_in *)addr; |
570 |
< |
int hash; |
571 |
< |
uint32_t ip; |
394 |
> |
case I_LINE_FULL: |
395 |
> |
sendto_realops_flags(UMODE_FULL, L_ALL, SEND_NOTICE, |
396 |
> |
"auth {} block is full for %s (%s).", |
397 |
> |
get_client_name(source_p, SHOW_IP), |
398 |
> |
source_p->sockhost); |
399 |
> |
ilog(LOG_TYPE_IRCD, "Too many connections from %s.", |
400 |
> |
get_client_name(source_p, SHOW_IP)); |
401 |
> |
++ServerStats.is_ref; |
402 |
> |
exit_client(source_p, "No more connections allowed in your connection class"); |
403 |
> |
break; |
404 |
|
|
405 |
< |
ip = ntohl(v4->sin_addr.s_addr); |
406 |
< |
hash = ((ip >> 12) + ip) & (IP_HASH_SIZE-1); |
407 |
< |
return hash; |
408 |
< |
} |
409 |
< |
#ifdef IPV6 |
410 |
< |
else |
411 |
< |
{ |
412 |
< |
int hash; |
413 |
< |
struct sockaddr_in6 *v6 = (struct sockaddr_in6 *)addr; |
414 |
< |
uint32_t *ip = (uint32_t *)&v6->sin6_addr.s6_addr; |
415 |
< |
|
416 |
< |
hash = ip[0] ^ ip[3]; |
417 |
< |
hash ^= hash >> 16; |
586 |
< |
hash ^= hash >> 8; |
587 |
< |
hash = hash & (IP_HASH_SIZE - 1); |
588 |
< |
return hash; |
589 |
< |
} |
590 |
< |
#else |
591 |
< |
return 0; |
592 |
< |
#endif |
593 |
< |
} |
405 |
> |
case NOT_AUTHORIZED: |
406 |
> |
/* jdc - lists server name & port connections are on */ |
407 |
> |
/* a purely cosmetical change */ |
408 |
> |
sendto_realops_flags(UMODE_UNAUTH, L_ALL, SEND_NOTICE, |
409 |
> |
"Unauthorized client connection from %s [%s] on [%s/%u].", |
410 |
> |
get_client_name(source_p, SHOW_IP), |
411 |
> |
source_p->sockhost, |
412 |
> |
source_p->connection->listener->name, |
413 |
> |
source_p->connection->listener->port); |
414 |
> |
ilog(LOG_TYPE_IRCD, "Unauthorized client connection from %s on [%s/%u].", |
415 |
> |
get_client_name(source_p, SHOW_IP), |
416 |
> |
source_p->connection->listener->name, |
417 |
> |
source_p->connection->listener->port); |
418 |
|
|
419 |
< |
/* count_ip_hash() |
420 |
< |
* |
421 |
< |
* inputs - pointer to counter of number of ips hashed |
598 |
< |
* - pointer to memory used for ip hash |
599 |
< |
* output - returned via pointers input |
600 |
< |
* side effects - NONE |
601 |
< |
* |
602 |
< |
* number of hashed ip #'s is counted up, plus the amount of memory |
603 |
< |
* used in the hash. |
604 |
< |
*/ |
605 |
< |
void |
606 |
< |
count_ip_hash(unsigned int *number_ips_stored, uint64_t *mem_ips_stored) |
607 |
< |
{ |
608 |
< |
struct ip_entry *ptr; |
609 |
< |
int i; |
419 |
> |
++ServerStats.is_ref; |
420 |
> |
exit_client(source_p, "You are not authorized to use this server"); |
421 |
> |
break; |
422 |
|
|
423 |
< |
*number_ips_stored = 0; |
424 |
< |
*mem_ips_stored = 0; |
423 |
> |
case BANNED_CLIENT: |
424 |
> |
++ServerStats.is_ref; |
425 |
> |
exit_client(source_p, "Banned"); |
426 |
> |
break; |
427 |
|
|
428 |
< |
for (i = 0; i < IP_HASH_SIZE; i++) |
429 |
< |
{ |
430 |
< |
for (ptr = ip_hash_table[i]; ptr; ptr = ptr->next) |
617 |
< |
{ |
618 |
< |
*number_ips_stored += 1; |
619 |
< |
*mem_ips_stored += sizeof(struct ip_entry); |
620 |
< |
} |
428 |
> |
case 0: |
429 |
> |
default: |
430 |
> |
break; |
431 |
|
} |
622 |
– |
} |
623 |
– |
|
624 |
– |
/* garbage_collect_ip_entries() |
625 |
– |
* |
626 |
– |
* input - NONE |
627 |
– |
* output - NONE |
628 |
– |
* side effects - free up all ip entries with no connections |
629 |
– |
*/ |
630 |
– |
static void |
631 |
– |
garbage_collect_ip_entries(void) |
632 |
– |
{ |
633 |
– |
struct ip_entry *ptr; |
634 |
– |
struct ip_entry *last_ptr; |
635 |
– |
struct ip_entry *next_ptr; |
636 |
– |
int i; |
637 |
– |
|
638 |
– |
for (i = 0; i < IP_HASH_SIZE; i++) |
639 |
– |
{ |
640 |
– |
last_ptr = NULL; |
432 |
|
|
433 |
< |
for (ptr = ip_hash_table[i]; ptr; ptr = next_ptr) |
643 |
< |
{ |
644 |
< |
next_ptr = ptr->next; |
645 |
< |
|
646 |
< |
if (ptr->count == 0 && |
647 |
< |
(CurrentTime - ptr->last_attempt) >= ConfigFileEntry.throttle_time) |
648 |
< |
{ |
649 |
< |
if (last_ptr != NULL) |
650 |
< |
last_ptr->next = ptr->next; |
651 |
< |
else |
652 |
< |
ip_hash_table[i] = ptr->next; |
653 |
< |
mp_pool_release(ptr); |
654 |
< |
ip_entries_count--; |
655 |
< |
} |
656 |
< |
else |
657 |
< |
last_ptr = ptr; |
658 |
< |
} |
659 |
< |
} |
433 |
> |
return !(i < 0); |
434 |
|
} |
435 |
|
|
436 |
|
/* detach_conf() |
444 |
|
void |
445 |
|
detach_conf(struct Client *client_p, enum maskitem_type type) |
446 |
|
{ |
447 |
< |
dlink_node *ptr = NULL, *next_ptr = NULL; |
447 |
> |
dlink_node *node = NULL, *node_next = NULL; |
448 |
|
|
449 |
< |
DLINK_FOREACH_SAFE(ptr, next_ptr, client_p->localClient->confs.head) |
449 |
> |
DLINK_FOREACH_SAFE(node, node_next, client_p->connection->confs.head) |
450 |
|
{ |
451 |
< |
struct MaskItem *conf = ptr->data; |
451 |
> |
struct MaskItem *conf = node->data; |
452 |
|
|
453 |
|
assert(conf->type & (CONF_CLIENT | CONF_OPER | CONF_SERVER)); |
454 |
|
assert(conf->ref_count > 0); |
457 |
|
if (!(conf->type & type)) |
458 |
|
continue; |
459 |
|
|
460 |
< |
dlinkDelete(ptr, &client_p->localClient->confs); |
461 |
< |
free_dlink_node(ptr); |
460 |
> |
dlinkDelete(node, &client_p->connection->confs); |
461 |
> |
free_dlink_node(node); |
462 |
|
|
463 |
|
if (conf->type == CONF_CLIENT) |
464 |
< |
remove_from_cidr_check(&client_p->localClient->ip, conf->class); |
464 |
> |
remove_from_cidr_check(&client_p->connection->ip, conf->class); |
465 |
|
|
466 |
|
if (--conf->class->ref_count == 0 && conf->class->active == 0) |
467 |
|
{ |
487 |
|
int |
488 |
|
attach_conf(struct Client *client_p, struct MaskItem *conf) |
489 |
|
{ |
490 |
< |
if (dlinkFind(&client_p->localClient->confs, conf) != NULL) |
490 |
> |
if (dlinkFind(&client_p->connection->confs, conf)) |
491 |
|
return 1; |
492 |
|
|
493 |
|
if (conf->type == CONF_CLIENT) |
494 |
|
if (cidr_limit_reached(IsConfExemptLimits(conf), |
495 |
< |
&client_p->localClient->ip, conf->class)) |
495 |
> |
&client_p->connection->ip, conf->class)) |
496 |
|
return TOO_MANY; /* Already at maximum allowed */ |
497 |
|
|
498 |
|
conf->class->ref_count++; |
499 |
|
conf->ref_count++; |
500 |
|
|
501 |
< |
dlinkAdd(conf, make_dlink_node(), &client_p->localClient->confs); |
501 |
> |
dlinkAdd(conf, make_dlink_node(), &client_p->connection->confs); |
502 |
|
|
503 |
|
return 0; |
504 |
|
} |
515 |
|
attach_connect_block(struct Client *client_p, const char *name, |
516 |
|
const char *host) |
517 |
|
{ |
518 |
< |
dlink_node *ptr; |
745 |
< |
struct MaskItem *conf = NULL; |
518 |
> |
dlink_node *node = NULL; |
519 |
|
|
520 |
< |
assert(client_p != NULL); |
748 |
< |
assert(host != NULL); |
520 |
> |
assert(host); |
521 |
|
|
522 |
< |
if (client_p == NULL || host == NULL) |
751 |
< |
return 0; |
752 |
< |
|
753 |
< |
DLINK_FOREACH(ptr, server_items.head) |
522 |
> |
DLINK_FOREACH(node, server_items.head) |
523 |
|
{ |
524 |
< |
conf = ptr->data; |
524 |
> |
struct MaskItem *conf = node->data; |
525 |
|
|
526 |
|
if (match(conf->name, name) || match(conf->host, host)) |
527 |
|
continue; |
528 |
|
|
529 |
|
attach_conf(client_p, conf); |
530 |
< |
return -1; |
530 |
> |
return 1; |
531 |
|
} |
532 |
|
|
533 |
|
return 0; |
545 |
|
struct MaskItem * |
546 |
|
find_conf_name(dlink_list *list, const char *name, enum maskitem_type type) |
547 |
|
{ |
548 |
< |
dlink_node *ptr; |
780 |
< |
struct MaskItem* conf; |
548 |
> |
dlink_node *node = NULL; |
549 |
|
|
550 |
< |
DLINK_FOREACH(ptr, list->head) |
550 |
> |
DLINK_FOREACH(node, list->head) |
551 |
|
{ |
552 |
< |
conf = ptr->data; |
552 |
> |
struct MaskItem *conf = node->data; |
553 |
|
|
554 |
|
if (conf->type == type) |
555 |
|
{ |
556 |
< |
if (conf->name && (irccmp(conf->name, name) == 0 || |
557 |
< |
!match(conf->name, name))) |
790 |
< |
return conf; |
556 |
> |
if (conf->name && !irccmp(conf->name, name)) |
557 |
> |
return conf; |
558 |
|
} |
559 |
|
} |
560 |
|
|
561 |
|
return NULL; |
562 |
|
} |
563 |
|
|
797 |
– |
/* map_to_list() |
798 |
– |
* |
799 |
– |
* inputs - ConfType conf |
800 |
– |
* output - pointer to dlink_list to use |
801 |
– |
* side effects - none |
802 |
– |
*/ |
803 |
– |
static dlink_list * |
804 |
– |
map_to_list(enum maskitem_type type) |
805 |
– |
{ |
806 |
– |
switch(type) |
807 |
– |
{ |
808 |
– |
case CONF_XLINE: |
809 |
– |
return(&xconf_items); |
810 |
– |
break; |
811 |
– |
case CONF_ULINE: |
812 |
– |
return(&uconf_items); |
813 |
– |
break; |
814 |
– |
case CONF_NRESV: |
815 |
– |
return(&nresv_items); |
816 |
– |
break; |
817 |
– |
case CONF_CRESV: |
818 |
– |
return(&cresv_items); |
819 |
– |
case CONF_OPER: |
820 |
– |
return(&oconf_items); |
821 |
– |
break; |
822 |
– |
case CONF_SERVER: |
823 |
– |
return(&server_items); |
824 |
– |
break; |
825 |
– |
case CONF_SERVICE: |
826 |
– |
return(&service_items); |
827 |
– |
break; |
828 |
– |
case CONF_CLUSTER: |
829 |
– |
return(&cluster_items); |
830 |
– |
break; |
831 |
– |
default: |
832 |
– |
return NULL; |
833 |
– |
} |
834 |
– |
} |
835 |
– |
|
564 |
|
/* find_matching_name_conf() |
565 |
|
* |
566 |
|
* inputs - type of link list to look in |
575 |
|
find_matching_name_conf(enum maskitem_type type, const char *name, const char *user, |
576 |
|
const char *host, unsigned int flags) |
577 |
|
{ |
578 |
< |
dlink_node *ptr=NULL; |
579 |
< |
struct MaskItem *conf=NULL; |
580 |
< |
dlink_list *list_p = map_to_list(type); |
578 |
> |
dlink_node *node = NULL; |
579 |
> |
dlink_list *list = map_to_list(type); |
580 |
> |
struct MaskItem *conf = NULL; |
581 |
|
|
582 |
|
switch (type) |
583 |
|
{ |
584 |
|
case CONF_SERVICE: |
585 |
< |
DLINK_FOREACH(ptr, list_p->head) |
585 |
> |
DLINK_FOREACH(node, list->head) |
586 |
|
{ |
587 |
< |
conf = ptr->data; |
587 |
> |
conf = node->data; |
588 |
|
|
589 |
|
if (EmptyString(conf->name)) |
590 |
|
continue; |
591 |
< |
if ((name != NULL) && !irccmp(name, conf->name)) |
591 |
> |
if (name && !irccmp(name, conf->name)) |
592 |
|
return conf; |
593 |
|
} |
594 |
|
break; |
597 |
|
case CONF_ULINE: |
598 |
|
case CONF_NRESV: |
599 |
|
case CONF_CRESV: |
600 |
< |
DLINK_FOREACH(ptr, list_p->head) |
600 |
> |
DLINK_FOREACH(node, list->head) |
601 |
|
{ |
602 |
< |
conf = ptr->data; |
602 |
> |
conf = node->data; |
603 |
|
|
604 |
|
if (EmptyString(conf->name)) |
605 |
|
continue; |
606 |
< |
if ((name != NULL) && !match(conf->name, name)) |
606 |
> |
if (name && !match(conf->name, name)) |
607 |
|
{ |
608 |
|
if ((user == NULL && (host == NULL))) |
609 |
|
return conf; |
618 |
|
break; |
619 |
|
|
620 |
|
case CONF_SERVER: |
621 |
< |
DLINK_FOREACH(ptr, list_p->head) |
621 |
> |
DLINK_FOREACH(node, list->head) |
622 |
|
{ |
623 |
< |
conf = ptr->data; |
623 |
> |
conf = node->data; |
624 |
|
|
625 |
< |
if ((name != NULL) && !match(name, conf->name)) |
625 |
> |
if (name && !match(name, conf->name)) |
626 |
|
return conf; |
627 |
< |
else if ((host != NULL) && !match(host, conf->host)) |
627 |
> |
if (host && !match(host, conf->host)) |
628 |
|
return conf; |
629 |
|
} |
630 |
|
break; |
648 |
|
find_exact_name_conf(enum maskitem_type type, const struct Client *who, const char *name, |
649 |
|
const char *user, const char *host) |
650 |
|
{ |
651 |
< |
dlink_node *ptr = NULL; |
652 |
< |
struct MaskItem *conf; |
653 |
< |
dlink_list *list_p = map_to_list(type); |
651 |
> |
dlink_node *node = NULL; |
652 |
> |
dlink_list *list = map_to_list(type); |
653 |
> |
struct MaskItem *conf = NULL; |
654 |
|
|
655 |
|
switch(type) |
656 |
|
{ |
659 |
|
case CONF_NRESV: |
660 |
|
case CONF_CRESV: |
661 |
|
|
662 |
< |
DLINK_FOREACH(ptr, list_p->head) |
662 |
> |
DLINK_FOREACH(node, list->head) |
663 |
|
{ |
664 |
< |
conf = ptr->data; |
664 |
> |
conf = node->data; |
665 |
|
|
666 |
|
if (EmptyString(conf->name)) |
667 |
|
continue; |
679 |
|
break; |
680 |
|
|
681 |
|
case CONF_OPER: |
682 |
< |
DLINK_FOREACH(ptr, list_p->head) |
682 |
> |
DLINK_FOREACH(node, list->head) |
683 |
|
{ |
684 |
< |
conf = ptr->data; |
684 |
> |
conf = node->data; |
685 |
|
|
686 |
|
if (EmptyString(conf->name)) |
687 |
|
continue; |
702 |
|
return conf; |
703 |
|
break; |
704 |
|
case HM_IPV4: |
705 |
< |
if (who->localClient->aftype == AF_INET) |
706 |
< |
if (match_ipv4(&who->localClient->ip, &conf->addr, conf->bits)) |
705 |
> |
if (who->connection->aftype == AF_INET) |
706 |
> |
if (match_ipv4(&who->connection->ip, &conf->addr, conf->bits)) |
707 |
|
if (!conf->class->max_total || conf->class->ref_count < conf->class->max_total) |
708 |
|
return conf; |
709 |
|
break; |
982 |
– |
#ifdef IPV6 |
710 |
|
case HM_IPV6: |
711 |
< |
if (who->localClient->aftype == AF_INET6) |
712 |
< |
if (match_ipv6(&who->localClient->ip, &conf->addr, conf->bits)) |
711 |
> |
if (who->connection->aftype == AF_INET6) |
712 |
> |
if (match_ipv6(&who->connection->ip, &conf->addr, conf->bits)) |
713 |
|
if (!conf->class->max_total || conf->class->ref_count < conf->class->max_total) |
714 |
|
return conf; |
715 |
|
break; |
989 |
– |
#endif |
716 |
|
default: |
717 |
|
assert(0); |
718 |
|
} |
723 |
|
break; |
724 |
|
|
725 |
|
case CONF_SERVER: |
726 |
< |
DLINK_FOREACH(ptr, list_p->head) |
726 |
> |
DLINK_FOREACH(node, list->head) |
727 |
|
{ |
728 |
< |
conf = ptr->data; |
728 |
> |
conf = node->data; |
729 |
|
|
730 |
|
if (EmptyString(conf->name)) |
731 |
|
continue; |
750 |
|
return NULL; |
751 |
|
} |
752 |
|
|
1027 |
– |
/* rehash() |
1028 |
– |
* |
1029 |
– |
* Actual REHASH service routine. Called with sig == 0 if it has been called |
1030 |
– |
* as a result of an operator issuing this command, else assume it has been |
1031 |
– |
* called as a result of the server receiving a HUP signal. |
1032 |
– |
*/ |
1033 |
– |
int |
1034 |
– |
rehash(int sig) |
1035 |
– |
{ |
1036 |
– |
if (sig != 0) |
1037 |
– |
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1038 |
– |
"Got signal SIGHUP, reloading configuration file(s)"); |
1039 |
– |
|
1040 |
– |
restart_resolver(); |
1041 |
– |
|
1042 |
– |
/* don't close listeners until we know we can go ahead with the rehash */ |
1043 |
– |
|
1044 |
– |
/* Check to see if we magically got(or lost) IPv6 support */ |
1045 |
– |
check_can_use_v6(); |
1046 |
– |
|
1047 |
– |
read_conf_files(0); |
1048 |
– |
|
1049 |
– |
if (ServerInfo.description != NULL) |
1050 |
– |
strlcpy(me.info, ServerInfo.description, sizeof(me.info)); |
1051 |
– |
|
1052 |
– |
load_conf_modules(); |
1053 |
– |
|
1054 |
– |
rehashed_klines = 1; |
1055 |
– |
|
1056 |
– |
return 0; |
1057 |
– |
} |
1058 |
– |
|
753 |
|
/* set_default_conf() |
754 |
|
* |
755 |
|
* inputs - NONE |
768 |
|
assert(class_default == class_get_list()->tail->data); |
769 |
|
|
770 |
|
#ifdef HAVE_LIBCRYPTO |
771 |
< |
ServerInfo.rsa_private_key = NULL; |
772 |
< |
ServerInfo.rsa_private_key_file = NULL; |
771 |
> |
#if OPENSSL_VERSION_NUMBER >= 0x009080FFL && !defined(OPENSSL_NO_ECDH) |
772 |
> |
{ |
773 |
> |
EC_KEY *key = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1); |
774 |
> |
|
775 |
> |
if (key) |
776 |
> |
{ |
777 |
> |
SSL_CTX_set_tmp_ecdh(ConfigServerInfo.server_ctx, key); |
778 |
> |
EC_KEY_free(key); |
779 |
> |
} |
780 |
> |
} |
781 |
> |
|
782 |
> |
SSL_CTX_set_options(ConfigServerInfo.server_ctx, SSL_OP_SINGLE_ECDH_USE); |
783 |
|
#endif |
784 |
|
|
785 |
< |
/* ServerInfo.name is not rehashable */ |
786 |
< |
/* ServerInfo.name = ServerInfo.name; */ |
787 |
< |
ServerInfo.description = NULL; |
788 |
< |
ServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT); |
789 |
< |
ServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT); |
790 |
< |
|
791 |
< |
memset(&ServerInfo.ip, 0, sizeof(ServerInfo.ip)); |
792 |
< |
ServerInfo.specific_ipv4_vhost = 0; |
793 |
< |
memset(&ServerInfo.ip6, 0, sizeof(ServerInfo.ip6)); |
794 |
< |
ServerInfo.specific_ipv6_vhost = 0; |
795 |
< |
|
796 |
< |
ServerInfo.max_clients = MAXCLIENTS_MAX; |
797 |
< |
ServerInfo.max_nick_length = 9; |
798 |
< |
ServerInfo.max_topic_length = 80; |
799 |
< |
|
800 |
< |
ServerInfo.hub = 0; |
801 |
< |
ServerInfo.dns_host.sin_addr.s_addr = 0; |
802 |
< |
ServerInfo.dns_host.sin_port = 0; |
803 |
< |
AdminInfo.name = NULL; |
804 |
< |
AdminInfo.email = NULL; |
805 |
< |
AdminInfo.description = NULL; |
785 |
> |
SSL_CTX_set_cipher_list(ConfigServerInfo.server_ctx, "EECDH+HIGH:EDH+HIGH:HIGH:!aNULL"); |
786 |
> |
ConfigServerInfo.message_digest_algorithm = EVP_sha256(); |
787 |
> |
ConfigServerInfo.rsa_private_key = NULL; |
788 |
> |
ConfigServerInfo.rsa_private_key_file = NULL; |
789 |
> |
#endif |
790 |
> |
|
791 |
> |
/* ConfigServerInfo.name is not rehashable */ |
792 |
> |
/* ConfigServerInfo.name = ConfigServerInfo.name; */ |
793 |
> |
ConfigServerInfo.description = NULL; |
794 |
> |
ConfigServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT); |
795 |
> |
ConfigServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT); |
796 |
> |
|
797 |
> |
memset(&ConfigServerInfo.ip, 0, sizeof(ConfigServerInfo.ip)); |
798 |
> |
ConfigServerInfo.specific_ipv4_vhost = 0; |
799 |
> |
memset(&ConfigServerInfo.ip6, 0, sizeof(ConfigServerInfo.ip6)); |
800 |
> |
ConfigServerInfo.specific_ipv6_vhost = 0; |
801 |
> |
|
802 |
> |
ConfigServerInfo.default_max_clients = MAXCLIENTS_MAX; |
803 |
> |
ConfigServerInfo.max_nick_length = 9; |
804 |
> |
ConfigServerInfo.max_topic_length = 80; |
805 |
> |
ConfigServerInfo.hub = 0; |
806 |
> |
|
807 |
> |
ConfigAdminInfo.name = NULL; |
808 |
> |
ConfigAdminInfo.email = NULL; |
809 |
> |
ConfigAdminInfo.description = NULL; |
810 |
|
|
811 |
|
log_del_all(); |
812 |
|
|
813 |
< |
ConfigLoggingEntry.use_logging = 1; |
813 |
> |
ConfigLog.use_logging = 1; |
814 |
|
|
815 |
|
ConfigChannel.disable_fake_channels = 0; |
816 |
< |
ConfigChannel.knock_delay = 300; |
816 |
> |
ConfigChannel.invite_client_count = 10; |
817 |
> |
ConfigChannel.invite_client_time = 300; |
818 |
> |
ConfigChannel.knock_client_count = 1; |
819 |
> |
ConfigChannel.knock_client_time = 300; |
820 |
|
ConfigChannel.knock_delay_channel = 60; |
821 |
< |
ConfigChannel.max_chans_per_user = 25; |
1111 |
< |
ConfigChannel.max_chans_per_oper = 50; |
821 |
> |
ConfigChannel.max_channels = 25; |
822 |
|
ConfigChannel.max_bans = 25; |
823 |
+ |
ConfigChannel.default_join_flood_count = 18; |
824 |
+ |
ConfigChannel.default_join_flood_time = 6; |
825 |
|
ConfigChannel.default_split_user_count = 0; |
826 |
|
ConfigChannel.default_split_server_count = 0; |
827 |
|
ConfigChannel.no_join_on_split = 0; |
836 |
|
ConfigServerHide.hide_server_ips = 0; |
837 |
|
ConfigServerHide.disable_remote_commands = 0; |
838 |
|
|
839 |
< |
ConfigFileEntry.service_name = xstrdup(SERVICE_NAME_DEFAULT); |
840 |
< |
ConfigFileEntry.max_watch = WATCHSIZE_DEFAULT; |
841 |
< |
ConfigFileEntry.cycle_on_host_change = 1; |
842 |
< |
ConfigFileEntry.glines = 0; |
843 |
< |
ConfigFileEntry.gline_time = 12 * 3600; |
844 |
< |
ConfigFileEntry.gline_request_time = GLINE_REQUEST_EXPIRE_DEFAULT; |
845 |
< |
ConfigFileEntry.gline_min_cidr = 16; |
846 |
< |
ConfigFileEntry.gline_min_cidr6 = 48; |
847 |
< |
ConfigFileEntry.invisible_on_connect = 1; |
848 |
< |
ConfigFileEntry.tkline_expire_notices = 1; |
849 |
< |
ConfigFileEntry.hide_spoof_ips = 1; |
850 |
< |
ConfigFileEntry.ignore_bogus_ts = 0; |
851 |
< |
ConfigFileEntry.disable_auth = 0; |
852 |
< |
ConfigFileEntry.kill_chase_time_limit = 90; |
853 |
< |
ConfigFileEntry.default_floodcount = 8; |
854 |
< |
ConfigFileEntry.failed_oper_notice = 1; |
855 |
< |
ConfigFileEntry.dots_in_ident = 0; |
856 |
< |
ConfigFileEntry.min_nonwildcard = 4; |
857 |
< |
ConfigFileEntry.min_nonwildcard_simple = 3; |
858 |
< |
ConfigFileEntry.max_accept = 20; |
859 |
< |
ConfigFileEntry.anti_nick_flood = 0; |
860 |
< |
ConfigFileEntry.max_nick_time = 20; |
861 |
< |
ConfigFileEntry.max_nick_changes = 5; |
862 |
< |
ConfigFileEntry.anti_spam_exit_message_time = 0; |
863 |
< |
ConfigFileEntry.ts_warn_delta = TS_WARN_DELTA_DEFAULT; |
864 |
< |
ConfigFileEntry.ts_max_delta = TS_MAX_DELTA_DEFAULT; |
865 |
< |
ConfigFileEntry.warn_no_nline = 1; |
866 |
< |
ConfigFileEntry.stats_o_oper_only = 0; |
867 |
< |
ConfigFileEntry.stats_k_oper_only = 1; /* masked */ |
868 |
< |
ConfigFileEntry.stats_i_oper_only = 1; /* masked */ |
869 |
< |
ConfigFileEntry.stats_P_oper_only = 0; |
870 |
< |
ConfigFileEntry.stats_u_oper_only = 0; |
871 |
< |
ConfigFileEntry.caller_id_wait = 60; |
872 |
< |
ConfigFileEntry.opers_bypass_callerid = 0; |
873 |
< |
ConfigFileEntry.pace_wait = 10; |
874 |
< |
ConfigFileEntry.pace_wait_simple = 1; |
875 |
< |
ConfigFileEntry.short_motd = 0; |
876 |
< |
ConfigFileEntry.ping_cookie = 0; |
877 |
< |
ConfigFileEntry.no_oper_flood = 0; |
878 |
< |
ConfigFileEntry.true_no_oper_flood = 0; |
879 |
< |
ConfigFileEntry.oper_pass_resv = 1; |
880 |
< |
ConfigFileEntry.max_targets = MAX_TARGETS_DEFAULT; |
881 |
< |
ConfigFileEntry.oper_only_umodes = UMODE_DEBUG; |
882 |
< |
ConfigFileEntry.oper_umodes = UMODE_BOTS | UMODE_LOCOPS | UMODE_SERVNOTICE | |
883 |
< |
UMODE_OPERWALL | UMODE_WALLOP; |
884 |
< |
ConfigFileEntry.use_egd = 0; |
885 |
< |
ConfigFileEntry.egdpool_path = NULL; |
886 |
< |
ConfigFileEntry.throttle_time = 10; |
839 |
> |
ConfigGeneral.away_count = 2; |
840 |
> |
ConfigGeneral.away_time = 10; |
841 |
> |
ConfigGeneral.max_watch = WATCHSIZE_DEFAULT; |
842 |
> |
ConfigGeneral.cycle_on_host_change = 1; |
843 |
> |
ConfigGeneral.glines = 0; |
844 |
> |
ConfigGeneral.gline_time = 12 * 3600; |
845 |
> |
ConfigGeneral.gline_request_time = GLINE_REQUEST_EXPIRE_DEFAULT; |
846 |
> |
ConfigGeneral.gline_min_cidr = 16; |
847 |
> |
ConfigGeneral.gline_min_cidr6 = 48; |
848 |
> |
ConfigGeneral.invisible_on_connect = 1; |
849 |
> |
ConfigGeneral.tkline_expire_notices = 1; |
850 |
> |
ConfigGeneral.ignore_bogus_ts = 0; |
851 |
> |
ConfigGeneral.disable_auth = 0; |
852 |
> |
ConfigGeneral.kill_chase_time_limit = 90; |
853 |
> |
ConfigGeneral.default_floodcount = 8; |
854 |
> |
ConfigGeneral.failed_oper_notice = 1; |
855 |
> |
ConfigGeneral.dots_in_ident = 0; |
856 |
> |
ConfigGeneral.min_nonwildcard = 4; |
857 |
> |
ConfigGeneral.min_nonwildcard_simple = 3; |
858 |
> |
ConfigGeneral.max_accept = 20; |
859 |
> |
ConfigGeneral.anti_nick_flood = 0; |
860 |
> |
ConfigGeneral.max_nick_time = 20; |
861 |
> |
ConfigGeneral.max_nick_changes = 5; |
862 |
> |
ConfigGeneral.anti_spam_exit_message_time = 0; |
863 |
> |
ConfigGeneral.ts_warn_delta = TS_WARN_DELTA_DEFAULT; |
864 |
> |
ConfigGeneral.ts_max_delta = TS_MAX_DELTA_DEFAULT; |
865 |
> |
ConfigGeneral.warn_no_connect_block = 1; |
866 |
> |
ConfigGeneral.stats_e_disabled = 0; |
867 |
> |
ConfigGeneral.stats_i_oper_only = 1; /* 1 = masked */ |
868 |
> |
ConfigGeneral.stats_k_oper_only = 1; /* 1 = masked */ |
869 |
> |
ConfigGeneral.stats_o_oper_only = 1; |
870 |
> |
ConfigGeneral.stats_m_oper_only = 1; |
871 |
> |
ConfigGeneral.stats_P_oper_only = 0; |
872 |
> |
ConfigGeneral.stats_u_oper_only = 0; |
873 |
> |
ConfigGeneral.caller_id_wait = 60; |
874 |
> |
ConfigGeneral.opers_bypass_callerid = 0; |
875 |
> |
ConfigGeneral.pace_wait = 10; |
876 |
> |
ConfigGeneral.pace_wait_simple = 1; |
877 |
> |
ConfigGeneral.short_motd = 0; |
878 |
> |
ConfigGeneral.ping_cookie = 0; |
879 |
> |
ConfigGeneral.no_oper_flood = 0; |
880 |
> |
ConfigGeneral.oper_pass_resv = 1; |
881 |
> |
ConfigGeneral.max_targets = MAX_TARGETS_DEFAULT; |
882 |
> |
ConfigGeneral.oper_only_umodes = UMODE_DEBUG | UMODE_LOCOPS | UMODE_HIDDEN | UMODE_FARCONNECT | |
883 |
> |
UMODE_UNAUTH | UMODE_EXTERNAL | UMODE_BOTS | UMODE_NCHANGE | |
884 |
> |
UMODE_SPY | UMODE_FULL | UMODE_SKILL | UMODE_REJ | UMODE_CCONN; |
885 |
> |
ConfigGeneral.oper_umodes = UMODE_BOTS | UMODE_LOCOPS | UMODE_SERVNOTICE | UMODE_WALLOP; |
886 |
> |
ConfigGeneral.throttle_count = 1; |
887 |
> |
ConfigGeneral.throttle_time = 1; |
888 |
|
} |
889 |
|
|
890 |
|
static void |
891 |
|
validate_conf(void) |
892 |
|
{ |
893 |
< |
if (ConfigFileEntry.ts_warn_delta < TS_WARN_DELTA_MIN) |
894 |
< |
ConfigFileEntry.ts_warn_delta = TS_WARN_DELTA_DEFAULT; |
1182 |
< |
|
1183 |
< |
if (ConfigFileEntry.ts_max_delta < TS_MAX_DELTA_MIN) |
1184 |
< |
ConfigFileEntry.ts_max_delta = TS_MAX_DELTA_DEFAULT; |
893 |
> |
if (ConfigGeneral.ts_warn_delta < TS_WARN_DELTA_MIN) |
894 |
> |
ConfigGeneral.ts_warn_delta = TS_WARN_DELTA_DEFAULT; |
895 |
|
|
896 |
< |
if (ServerInfo.network_name == NULL) |
897 |
< |
ServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT); |
896 |
> |
if (ConfigGeneral.ts_max_delta < TS_MAX_DELTA_MIN) |
897 |
> |
ConfigGeneral.ts_max_delta = TS_MAX_DELTA_DEFAULT; |
898 |
|
|
899 |
< |
if (ServerInfo.network_desc == NULL) |
900 |
< |
ServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT); |
899 |
> |
if (EmptyString(ConfigServerInfo.network_name)) |
900 |
> |
ConfigServerInfo.network_name = xstrdup(NETWORK_NAME_DEFAULT); |
901 |
|
|
902 |
< |
if (ConfigFileEntry.service_name == NULL) |
903 |
< |
ConfigFileEntry.service_name = xstrdup(SERVICE_NAME_DEFAULT); |
902 |
> |
if (EmptyString(ConfigServerInfo.network_desc)) |
903 |
> |
ConfigServerInfo.network_desc = xstrdup(NETWORK_DESC_DEFAULT); |
904 |
|
|
905 |
< |
ConfigFileEntry.max_watch = IRCD_MAX(ConfigFileEntry.max_watch, WATCHSIZE_MIN); |
905 |
> |
ConfigGeneral.max_watch = IRCD_MAX(ConfigGeneral.max_watch, WATCHSIZE_MIN); |
906 |
|
} |
907 |
|
|
908 |
|
/* read_conf() |
916 |
|
{ |
917 |
|
lineno = 0; |
918 |
|
|
919 |
< |
set_default_conf(); /* Set default values prior to conf parsing */ |
919 |
> |
set_default_conf(); /* Set default values prior to conf parsing */ |
920 |
|
conf_parser_ctx.pass = 1; |
921 |
< |
yyparse(); /* pick up the classes first */ |
921 |
> |
yyparse(); /* Pick up the classes first */ |
922 |
|
|
923 |
|
rewind(file); |
924 |
|
|
925 |
|
conf_parser_ctx.pass = 2; |
926 |
< |
yyparse(); /* Load the values from the conf */ |
927 |
< |
validate_conf(); /* Check to make sure some values are still okay. */ |
928 |
< |
/* Some global values are also loaded here. */ |
929 |
< |
class_delete_marked(); /* Make sure classes are valid */ |
926 |
> |
yyparse(); /* Load the values from the conf */ |
927 |
> |
validate_conf(); /* Check to make sure some values are still okay. */ |
928 |
> |
/* Some global values are also loaded here. */ |
929 |
> |
class_delete_marked(); /* Delete unused classes that are marked for deletion */ |
930 |
> |
} |
931 |
> |
|
932 |
> |
/* conf_rehash() |
933 |
> |
* |
934 |
> |
* Actual REHASH service routine. Called with sig == 0 if it has been called |
935 |
> |
* as a result of an operator issuing this command, else assume it has been |
936 |
> |
* called as a result of the server receiving a HUP signal. |
937 |
> |
*/ |
938 |
> |
void |
939 |
> |
conf_rehash(int sig) |
940 |
> |
{ |
941 |
> |
if (sig) |
942 |
> |
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
943 |
> |
"Got signal SIGHUP, reloading configuration file(s)"); |
944 |
> |
|
945 |
> |
restart_resolver(); |
946 |
> |
|
947 |
> |
/* don't close listeners until we know we can go ahead with the rehash */ |
948 |
> |
|
949 |
> |
read_conf_files(0); |
950 |
> |
|
951 |
> |
load_conf_modules(); |
952 |
> |
check_conf_klines(); |
953 |
|
} |
954 |
|
|
955 |
|
/* lookup_confhost() |
962 |
|
{ |
963 |
|
struct addrinfo hints, *res; |
964 |
|
|
965 |
< |
/* Do name lookup now on hostnames given and store the |
965 |
> |
/* |
966 |
> |
* Do name lookup now on hostnames given and store the |
967 |
|
* ip numbers in conf structure. |
968 |
|
*/ |
969 |
|
memset(&hints, 0, sizeof(hints)); |
980 |
|
return; |
981 |
|
} |
982 |
|
|
983 |
< |
assert(res != NULL); |
983 |
> |
assert(res); |
984 |
|
|
985 |
|
memcpy(&conf->addr, res->ai_addr, res->ai_addrlen); |
986 |
|
conf->addr.ss_len = res->ai_addrlen; |
999 |
|
int |
1000 |
|
conf_connect_allowed(struct irc_ssaddr *addr, int aftype) |
1001 |
|
{ |
1002 |
< |
struct ip_entry *ip_found; |
1003 |
< |
struct MaskItem *conf = find_dline_conf(addr, aftype); |
1002 |
> |
struct ip_entry *ip_found = NULL; |
1003 |
> |
struct MaskItem *const conf = find_dline_conf(addr, aftype); |
1004 |
|
|
1005 |
|
/* DLINE exempt also gets you out of static limits/pacing... */ |
1006 |
|
if (conf && (conf->type == CONF_EXEMPT)) |
1007 |
|
return 0; |
1008 |
|
|
1009 |
< |
if (conf != NULL) |
1009 |
> |
if (conf) |
1010 |
|
return BANNED_CLIENT; |
1011 |
|
|
1012 |
< |
ip_found = find_or_add_ip(addr); |
1012 |
> |
ip_found = ipcache_find_or_add_address(addr); |
1013 |
|
|
1014 |
< |
if ((CurrentTime - ip_found->last_attempt) < |
1281 |
< |
ConfigFileEntry.throttle_time) |
1014 |
> |
if ((CurrentTime - ip_found->last_attempt) < ConfigGeneral.throttle_time) |
1015 |
|
{ |
1016 |
< |
ip_found->last_attempt = CurrentTime; |
1017 |
< |
return TOO_FAST; |
1016 |
> |
if (ip_found->connection_count >= ConfigGeneral.throttle_count) |
1017 |
> |
return TOO_FAST; |
1018 |
> |
|
1019 |
> |
++ip_found->connection_count; |
1020 |
|
} |
1021 |
+ |
else |
1022 |
+ |
ip_found->connection_count = 1; |
1023 |
|
|
1024 |
|
ip_found->last_attempt = CurrentTime; |
1025 |
|
return 0; |
1026 |
|
} |
1027 |
|
|
1291 |
– |
/* cleanup_tklines() |
1292 |
– |
* |
1293 |
– |
* inputs - NONE |
1294 |
– |
* output - NONE |
1295 |
– |
* side effects - call function to expire temporary k/d lines |
1296 |
– |
* This is an event started off in ircd.c |
1297 |
– |
*/ |
1298 |
– |
void |
1299 |
– |
cleanup_tklines(void *notused) |
1300 |
– |
{ |
1301 |
– |
hostmask_expire_temporary(); |
1302 |
– |
expire_tklines(&xconf_items); |
1303 |
– |
expire_tklines(&nresv_items); |
1304 |
– |
expire_tklines(&cresv_items); |
1305 |
– |
} |
1306 |
– |
|
1028 |
|
/* expire_tklines() |
1029 |
|
* |
1030 |
|
* inputs - tkline list pointer |
1032 |
|
* side effects - expire tklines |
1033 |
|
*/ |
1034 |
|
static void |
1035 |
< |
expire_tklines(dlink_list *tklist) |
1035 |
> |
expire_tklines(dlink_list *list) |
1036 |
|
{ |
1037 |
< |
dlink_node *ptr; |
1317 |
< |
dlink_node *next_ptr; |
1318 |
< |
struct MaskItem *conf; |
1037 |
> |
dlink_node *node = NULL, *node_next = NULL; |
1038 |
|
|
1039 |
< |
DLINK_FOREACH_SAFE(ptr, next_ptr, tklist->head) |
1039 |
> |
DLINK_FOREACH_SAFE(node, node_next, list->head) |
1040 |
|
{ |
1041 |
< |
conf = ptr->data; |
1041 |
> |
struct MaskItem *conf = node->data; |
1042 |
|
|
1043 |
|
if (!conf->until || conf->until > CurrentTime) |
1044 |
|
continue; |
1045 |
|
|
1046 |
|
if (conf->type == CONF_XLINE) |
1047 |
|
{ |
1048 |
< |
if (ConfigFileEntry.tkline_expire_notices) |
1048 |
> |
if (ConfigGeneral.tkline_expire_notices) |
1049 |
|
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1050 |
< |
"Temporary X-line for [%s] expired", conf->name); |
1050 |
> |
"Temporary X-line for [%s] expired", conf->name); |
1051 |
|
conf_free(conf); |
1052 |
|
} |
1053 |
|
else if (conf->type == CONF_NRESV || conf->type == CONF_CRESV) |
1054 |
|
{ |
1055 |
< |
if (ConfigFileEntry.tkline_expire_notices) |
1055 |
> |
if (ConfigGeneral.tkline_expire_notices) |
1056 |
|
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1057 |
< |
"Temporary RESV for [%s] expired", conf->name); |
1057 |
> |
"Temporary RESV for [%s] expired", conf->name); |
1058 |
|
conf_free(conf); |
1059 |
|
} |
1060 |
|
} |
1061 |
|
} |
1062 |
|
|
1063 |
+ |
/* cleanup_tklines() |
1064 |
+ |
* |
1065 |
+ |
* inputs - NONE |
1066 |
+ |
* output - NONE |
1067 |
+ |
* side effects - call function to expire temporary k/d lines |
1068 |
+ |
* This is an event started off in ircd.c |
1069 |
+ |
*/ |
1070 |
+ |
void |
1071 |
+ |
cleanup_tklines(void *unused) |
1072 |
+ |
{ |
1073 |
+ |
hostmask_expire_temporary(); |
1074 |
+ |
expire_tklines(&xconf_items); |
1075 |
+ |
expire_tklines(&nresv_items); |
1076 |
+ |
expire_tklines(&cresv_items); |
1077 |
+ |
} |
1078 |
+ |
|
1079 |
|
/* oper_privs_as_string() |
1080 |
|
* |
1081 |
|
* inputs - pointer to client_p |
1092 |
|
{ OPER_FLAG_DIE, 'D' }, |
1093 |
|
{ OPER_FLAG_GLINE, 'G' }, |
1094 |
|
{ OPER_FLAG_REHASH, 'H' }, |
1095 |
< |
{ OPER_FLAG_K, 'K' }, |
1361 |
< |
{ OPER_FLAG_OPERWALL, 'L' }, |
1095 |
> |
{ OPER_FLAG_KLINE, 'K' }, |
1096 |
|
{ OPER_FLAG_KILL, 'N' }, |
1097 |
|
{ OPER_FLAG_KILL_REMOTE, 'O' }, |
1098 |
|
{ OPER_FLAG_CONNECT, 'P' }, |
1104 |
|
{ 0, '\0' } |
1105 |
|
}; |
1106 |
|
|
1107 |
< |
char * |
1107 |
> |
const char * |
1108 |
|
oper_privs_as_string(const unsigned int port) |
1109 |
|
{ |
1110 |
|
static char privs_out[IRCD_BUFSIZE]; |
1111 |
|
char *privs_ptr = privs_out; |
1378 |
– |
const struct oper_privs *opriv = flag_list; |
1112 |
|
|
1113 |
< |
for (; opriv->flag; ++opriv) |
1113 |
> |
for (const struct oper_privs *opriv = flag_list; opriv->flag; ++opriv) |
1114 |
|
{ |
1115 |
|
if (port & opriv->flag) |
1116 |
|
*privs_ptr++ = opriv->c; |
1124 |
|
} |
1125 |
|
|
1126 |
|
/* |
1127 |
< |
* Input: A client to find the active oper{} name for. |
1127 |
> |
* Input: A client to find the active operator {} name for. |
1128 |
|
* Output: The nick!user@host{oper} of the oper. |
1129 |
|
* "oper" is server name for remote opers |
1130 |
|
* Side effects: None. |
1132 |
|
const char * |
1133 |
|
get_oper_name(const struct Client *client_p) |
1134 |
|
{ |
1135 |
< |
const dlink_node *cnode = NULL; |
1136 |
< |
/* +5 for !,@,{,} and null */ |
1137 |
< |
static char buffer[NICKLEN + USERLEN + HOSTLEN + HOSTLEN + 5]; |
1135 |
> |
static char buffer[IRCD_BUFSIZE]; |
1136 |
> |
|
1137 |
> |
if (IsServer(client_p)) |
1138 |
> |
return client_p->name; |
1139 |
|
|
1140 |
|
if (MyConnect(client_p)) |
1141 |
|
{ |
1142 |
< |
if ((cnode = client_p->localClient->confs.head)) |
1142 |
> |
const dlink_node *const node = client_p->connection->confs.head; |
1143 |
> |
|
1144 |
> |
if (node) |
1145 |
|
{ |
1146 |
< |
const struct MaskItem *conf = cnode->data; |
1146 |
> |
const struct MaskItem *const conf = node->data; |
1147 |
|
|
1148 |
< |
if (IsConfOperator(conf)) |
1148 |
> |
if (conf->type == CONF_OPER) |
1149 |
|
{ |
1150 |
|
snprintf(buffer, sizeof(buffer), "%s!%s@%s{%s}", client_p->name, |
1151 |
|
client_p->username, client_p->host, conf->name); |
1153 |
|
} |
1154 |
|
} |
1155 |
|
|
1156 |
< |
/* Probably should assert here for now. If there is an oper out there |
1157 |
< |
* with no oper{} conf attached, it would be good for us to know... |
1156 |
> |
/* |
1157 |
> |
* Probably should assert here for now. If there is an oper out there |
1158 |
> |
* with no operator {} conf attached, it would be good for us to know... |
1159 |
|
*/ |
1160 |
< |
assert(0); /* Oper without oper conf! */ |
1160 |
> |
assert(0); /* Oper without oper conf! */ |
1161 |
|
} |
1162 |
|
|
1163 |
|
snprintf(buffer, sizeof(buffer), "%s!%s@%s{%s}", client_p->name, |
1165 |
|
return buffer; |
1166 |
|
} |
1167 |
|
|
1431 |
– |
/* read_conf_files() |
1432 |
– |
* |
1433 |
– |
* inputs - cold start YES or NO |
1434 |
– |
* output - none |
1435 |
– |
* side effects - read all conf files needed, ircd.conf kline.conf etc. |
1436 |
– |
*/ |
1437 |
– |
void |
1438 |
– |
read_conf_files(int cold) |
1439 |
– |
{ |
1440 |
– |
const char *filename; |
1441 |
– |
char chanmodes[IRCD_BUFSIZE]; |
1442 |
– |
char chanlimit[IRCD_BUFSIZE]; |
1443 |
– |
|
1444 |
– |
conf_parser_ctx.boot = cold; |
1445 |
– |
filename = ConfigFileEntry.configfile; |
1446 |
– |
|
1447 |
– |
/* We need to know the initial filename for the yyerror() to report |
1448 |
– |
FIXME: The full path is in conffilenamebuf first time since we |
1449 |
– |
dont know anything else |
1450 |
– |
|
1451 |
– |
- Gozem 2002-07-21 |
1452 |
– |
*/ |
1453 |
– |
strlcpy(conffilebuf, filename, sizeof(conffilebuf)); |
1454 |
– |
|
1455 |
– |
if ((conf_parser_ctx.conf_file = fopen(filename, "r")) == NULL) |
1456 |
– |
{ |
1457 |
– |
if (cold) |
1458 |
– |
{ |
1459 |
– |
ilog(LOG_TYPE_IRCD, "Unable to read configuration file '%s': %s", |
1460 |
– |
filename, strerror(errno)); |
1461 |
– |
exit(-1); |
1462 |
– |
} |
1463 |
– |
else |
1464 |
– |
{ |
1465 |
– |
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1466 |
– |
"Unable to read configuration file '%s': %s", |
1467 |
– |
filename, strerror(errno)); |
1468 |
– |
return; |
1469 |
– |
} |
1470 |
– |
} |
1471 |
– |
|
1472 |
– |
if (!cold) |
1473 |
– |
clear_out_old_conf(); |
1474 |
– |
|
1475 |
– |
read_conf(conf_parser_ctx.conf_file); |
1476 |
– |
fclose(conf_parser_ctx.conf_file); |
1477 |
– |
|
1478 |
– |
log_reopen_all(); |
1479 |
– |
|
1480 |
– |
add_isupport("NICKLEN", NULL, ServerInfo.max_nick_length); |
1481 |
– |
add_isupport("NETWORK", ServerInfo.network_name, -1); |
1482 |
– |
|
1483 |
– |
snprintf(chanmodes, sizeof(chanmodes), "beI:%d", ConfigChannel.max_bans); |
1484 |
– |
add_isupport("MAXLIST", chanmodes, -1); |
1485 |
– |
add_isupport("MAXTARGETS", NULL, ConfigFileEntry.max_targets); |
1486 |
– |
add_isupport("CHANTYPES", "#", -1); |
1487 |
– |
|
1488 |
– |
snprintf(chanlimit, sizeof(chanlimit), "#:%d", |
1489 |
– |
ConfigChannel.max_chans_per_user); |
1490 |
– |
add_isupport("CHANLIMIT", chanlimit, -1); |
1491 |
– |
snprintf(chanmodes, sizeof(chanmodes), "%s", "beI,k,l,imnprstORS"); |
1492 |
– |
add_isupport("CHANNELLEN", NULL, LOCAL_CHANNELLEN); |
1493 |
– |
add_isupport("TOPICLEN", NULL, ServerInfo.max_topic_length); |
1494 |
– |
add_isupport("CHANMODES", chanmodes, -1); |
1495 |
– |
|
1496 |
– |
/* |
1497 |
– |
* message_locale may have changed. rebuild isupport since it relies |
1498 |
– |
* on strlen(form_str(RPL_ISUPPORT)) |
1499 |
– |
*/ |
1500 |
– |
rebuild_isupport_message_line(); |
1501 |
– |
} |
1502 |
– |
|
1168 |
|
/* clear_out_old_conf() |
1169 |
|
* |
1170 |
|
* inputs - none |
1174 |
|
static void |
1175 |
|
clear_out_old_conf(void) |
1176 |
|
{ |
1177 |
< |
dlink_node *ptr = NULL, *next_ptr = NULL; |
1513 |
< |
struct MaskItem *conf; |
1177 |
> |
dlink_node *node = NULL, *node_next = NULL; |
1178 |
|
dlink_list *free_items [] = { |
1179 |
|
&server_items, &oconf_items, |
1180 |
|
&uconf_items, &xconf_items, |
1187 |
|
* Resetting structs, etc, is taken care of by set_default_conf(). |
1188 |
|
*/ |
1189 |
|
|
1190 |
< |
for (; *iterator != NULL; iterator++) |
1190 |
> |
for (; *iterator; iterator++) |
1191 |
|
{ |
1192 |
< |
DLINK_FOREACH_SAFE(ptr, next_ptr, (*iterator)->head) |
1192 |
> |
DLINK_FOREACH_SAFE(node, node_next, (*iterator)->head) |
1193 |
|
{ |
1194 |
< |
conf = ptr->data; |
1194 |
> |
struct MaskItem *conf = node->data; |
1195 |
|
|
1196 |
< |
dlinkDelete(&conf->node, map_to_list(conf->type)); |
1196 |
> |
conf->active = 0; |
1197 |
> |
dlinkDelete(&conf->node, *iterator); |
1198 |
|
|
1199 |
|
/* XXX This is less than pretty */ |
1200 |
|
if (conf->type == CONF_SERVER || conf->type == CONF_OPER) |
1215 |
|
motd_clear(); |
1216 |
|
|
1217 |
|
/* |
1218 |
< |
* don't delete the class table, rather mark all entries |
1219 |
< |
* for deletion. The table is cleaned up by class_delete_marked. - avalon |
1218 |
> |
* Don't delete the class table, rather mark all entries for deletion. |
1219 |
> |
* The table is cleaned up by class_delete_marked. - avalon |
1220 |
|
*/ |
1221 |
|
class_mark_for_deletion(); |
1222 |
|
|
1223 |
|
clear_out_address_conf(); |
1224 |
|
|
1225 |
< |
/* clean out module paths */ |
1225 |
> |
/* Clean out module paths */ |
1226 |
|
mod_clear_paths(); |
1227 |
|
|
1228 |
< |
/* clean out ServerInfo */ |
1229 |
< |
MyFree(ServerInfo.description); |
1230 |
< |
ServerInfo.description = NULL; |
1231 |
< |
MyFree(ServerInfo.network_name); |
1232 |
< |
ServerInfo.network_name = NULL; |
1233 |
< |
MyFree(ServerInfo.network_desc); |
1234 |
< |
ServerInfo.network_desc = NULL; |
1235 |
< |
MyFree(ConfigFileEntry.egdpool_path); |
1236 |
< |
ConfigFileEntry.egdpool_path = NULL; |
1228 |
> |
pseudo_clear(); |
1229 |
> |
|
1230 |
> |
/* Clean out ConfigServerInfo */ |
1231 |
> |
MyFree(ConfigServerInfo.description); |
1232 |
> |
ConfigServerInfo.description = NULL; |
1233 |
> |
MyFree(ConfigServerInfo.network_name); |
1234 |
> |
ConfigServerInfo.network_name = NULL; |
1235 |
> |
MyFree(ConfigServerInfo.network_desc); |
1236 |
> |
ConfigServerInfo.network_desc = NULL; |
1237 |
|
#ifdef HAVE_LIBCRYPTO |
1238 |
< |
if (ServerInfo.rsa_private_key != NULL) |
1238 |
> |
if (ConfigServerInfo.rsa_private_key) |
1239 |
|
{ |
1240 |
< |
RSA_free(ServerInfo.rsa_private_key); |
1241 |
< |
ServerInfo.rsa_private_key = NULL; |
1240 |
> |
RSA_free(ConfigServerInfo.rsa_private_key); |
1241 |
> |
ConfigServerInfo.rsa_private_key = NULL; |
1242 |
|
} |
1243 |
|
|
1244 |
< |
MyFree(ServerInfo.rsa_private_key_file); |
1245 |
< |
ServerInfo.rsa_private_key_file = NULL; |
1581 |
< |
|
1582 |
< |
if (ServerInfo.server_ctx) |
1583 |
< |
SSL_CTX_set_options(ServerInfo.server_ctx, SSL_OP_NO_SSLv2| |
1584 |
< |
SSL_OP_NO_SSLv3| |
1585 |
< |
SSL_OP_NO_TLSv1); |
1586 |
< |
if (ServerInfo.client_ctx) |
1587 |
< |
SSL_CTX_set_options(ServerInfo.client_ctx, SSL_OP_NO_SSLv2| |
1588 |
< |
SSL_OP_NO_SSLv3| |
1589 |
< |
SSL_OP_NO_TLSv1); |
1244 |
> |
MyFree(ConfigServerInfo.rsa_private_key_file); |
1245 |
> |
ConfigServerInfo.rsa_private_key_file = NULL; |
1246 |
|
#endif |
1247 |
|
|
1248 |
< |
/* clean out AdminInfo */ |
1249 |
< |
MyFree(AdminInfo.name); |
1250 |
< |
AdminInfo.name = NULL; |
1251 |
< |
MyFree(AdminInfo.email); |
1252 |
< |
AdminInfo.email = NULL; |
1253 |
< |
MyFree(AdminInfo.description); |
1254 |
< |
AdminInfo.description = NULL; |
1248 |
> |
/* Clean out ConfigAdminInfo */ |
1249 |
> |
MyFree(ConfigAdminInfo.name); |
1250 |
> |
ConfigAdminInfo.name = NULL; |
1251 |
> |
MyFree(ConfigAdminInfo.email); |
1252 |
> |
ConfigAdminInfo.email = NULL; |
1253 |
> |
MyFree(ConfigAdminInfo.description); |
1254 |
> |
ConfigAdminInfo.description = NULL; |
1255 |
|
|
1256 |
< |
/* clean out listeners */ |
1256 |
> |
/* Clean out listeners */ |
1257 |
|
close_listeners(); |
1258 |
+ |
} |
1259 |
+ |
|
1260 |
+ |
/* read_conf_files() |
1261 |
+ |
* |
1262 |
+ |
* inputs - cold start YES or NO |
1263 |
+ |
* output - none |
1264 |
+ |
* side effects - read all conf files needed, ircd.conf kline.conf etc. |
1265 |
+ |
*/ |
1266 |
+ |
void |
1267 |
+ |
read_conf_files(int cold) |
1268 |
+ |
{ |
1269 |
+ |
const char *filename = NULL; |
1270 |
+ |
char chanmodes[IRCD_BUFSIZE] = ""; |
1271 |
+ |
char chanlimit[IRCD_BUFSIZE] = ""; |
1272 |
+ |
|
1273 |
+ |
conf_parser_ctx.boot = cold; |
1274 |
+ |
filename = ConfigGeneral.configfile; |
1275 |
+ |
|
1276 |
+ |
/* We need to know the initial filename for the yyerror() to report |
1277 |
+ |
FIXME: The full path is in conffilenamebuf first time since we |
1278 |
+ |
don't know anything else |
1279 |
+ |
|
1280 |
+ |
- Gozem 2002-07-21 |
1281 |
+ |
*/ |
1282 |
+ |
strlcpy(conffilebuf, filename, sizeof(conffilebuf)); |
1283 |
+ |
|
1284 |
+ |
if ((conf_parser_ctx.conf_file = fopen(filename, "r")) == NULL) |
1285 |
+ |
{ |
1286 |
+ |
if (cold) |
1287 |
+ |
{ |
1288 |
+ |
ilog(LOG_TYPE_IRCD, "Unable to read configuration file '%s': %s", |
1289 |
+ |
filename, strerror(errno)); |
1290 |
+ |
exit(-1); |
1291 |
+ |
} |
1292 |
+ |
else |
1293 |
+ |
{ |
1294 |
+ |
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1295 |
+ |
"Unable to read configuration file '%s': %s", |
1296 |
+ |
filename, strerror(errno)); |
1297 |
+ |
return; |
1298 |
+ |
} |
1299 |
+ |
} |
1300 |
+ |
|
1301 |
+ |
if (!cold) |
1302 |
+ |
clear_out_old_conf(); |
1303 |
+ |
|
1304 |
+ |
read_conf(conf_parser_ctx.conf_file); |
1305 |
+ |
fclose(conf_parser_ctx.conf_file); |
1306 |
+ |
|
1307 |
+ |
log_reopen_all(); |
1308 |
+ |
|
1309 |
+ |
add_isupport("NICKLEN", NULL, ConfigServerInfo.max_nick_length); |
1310 |
+ |
add_isupport("NETWORK", ConfigServerInfo.network_name, -1); |
1311 |
+ |
|
1312 |
+ |
snprintf(chanmodes, sizeof(chanmodes), "beI:%d", ConfigChannel.max_bans); |
1313 |
+ |
add_isupport("MAXLIST", chanmodes, -1); |
1314 |
+ |
add_isupport("MAXTARGETS", NULL, ConfigGeneral.max_targets); |
1315 |
+ |
add_isupport("CHANTYPES", "#", -1); |
1316 |
|
|
1317 |
< |
/* clean out general */ |
1318 |
< |
MyFree(ConfigFileEntry.service_name); |
1319 |
< |
ConfigFileEntry.service_name = NULL; |
1317 |
> |
snprintf(chanlimit, sizeof(chanlimit), "#:%d", |
1318 |
> |
ConfigChannel.max_channels); |
1319 |
> |
add_isupport("CHANLIMIT", chanlimit, -1); |
1320 |
> |
snprintf(chanmodes, sizeof(chanmodes), "%s", "beI,k,l,cimnprstCMORS"); |
1321 |
> |
add_isupport("CHANNELLEN", NULL, CHANNELLEN); |
1322 |
> |
add_isupport("TOPICLEN", NULL, ConfigServerInfo.max_topic_length); |
1323 |
> |
add_isupport("CHANMODES", chanmodes, -1); |
1324 |
> |
|
1325 |
> |
/* |
1326 |
> |
* message_locale may have changed. rebuild isupport since it relies |
1327 |
> |
* on strlen(form_str(RPL_ISUPPORT)) |
1328 |
> |
*/ |
1329 |
> |
rebuild_isupport_message_line(); |
1330 |
|
} |
1331 |
|
|
1332 |
|
/* conf_add_class_to_conf() |
1342 |
|
{ |
1343 |
|
conf->class = class_default; |
1344 |
|
|
1345 |
< |
if (conf->type == CONF_CLIENT) |
1345 |
> |
if (conf->type == CONF_CLIENT || conf->type == CONF_OPER) |
1346 |
|
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1347 |
|
"Warning *** Defaulting to default class for %s@%s", |
1348 |
|
conf->user, conf->host); |
1356 |
|
|
1357 |
|
if (conf->class == NULL) |
1358 |
|
{ |
1359 |
< |
if (conf->type == CONF_CLIENT) |
1359 |
> |
if (conf->type == CONF_CLIENT || conf->type == CONF_OPER) |
1360 |
|
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1361 |
|
"Warning *** Defaulting to default class for %s@%s", |
1362 |
|
conf->user, conf->host); |
1431 |
|
|
1432 |
|
/* |
1433 |
|
* In the degenerate case where oper does a /quote kline 0 user@host :reason |
1434 |
< |
* i.e. they specifically use 0, I am going to return 1 instead |
1435 |
< |
* as a return value of non-zero is used to flag it as a temporary kline |
1434 |
> |
* i.e. they specifically use 0, I am going to return 1 instead as a return |
1435 |
> |
* value of non-zero is used to flag it as a temporary kline |
1436 |
|
*/ |
1437 |
|
if (result == 0) |
1438 |
|
result = 1; |
1447 |
|
if (result > MAX_TDKLINE_TIME) |
1448 |
|
result = MAX_TDKLINE_TIME; |
1449 |
|
|
1450 |
< |
result = result * 60; /* turn it into seconds */ |
1450 |
> |
result = result * 60; /* Turn it into seconds */ |
1451 |
|
|
1452 |
|
return result; |
1453 |
|
} |
1463 |
|
{ |
1464 |
|
const unsigned char *p = (const unsigned char *)data; |
1465 |
|
unsigned char tmpch = '\0'; |
1466 |
< |
int nonwild = 0; |
1466 |
> |
unsigned int nonwild = 0; |
1467 |
|
|
1468 |
|
while ((tmpch = *p++)) |
1469 |
|
{ |
1470 |
< |
if (tmpch == '\\') |
1470 |
> |
if (tmpch == '\\' && *p) |
1471 |
|
{ |
1472 |
|
++p; |
1473 |
< |
if (++nonwild >= ConfigFileEntry.min_nonwildcard_simple) |
1473 |
> |
if (++nonwild >= ConfigGeneral.min_nonwildcard_simple) |
1474 |
|
return 1; |
1475 |
|
} |
1476 |
|
else if (!IsMWildChar(tmpch)) |
1477 |
|
{ |
1478 |
< |
if (++nonwild >= ConfigFileEntry.min_nonwildcard_simple) |
1478 |
> |
if (++nonwild >= ConfigGeneral.min_nonwildcard_simple) |
1479 |
|
return 1; |
1480 |
|
} |
1481 |
|
} |
1494 |
|
int |
1495 |
|
valid_wild_card(struct Client *source_p, int warn, int count, ...) |
1496 |
|
{ |
1497 |
< |
char tmpch; |
1498 |
< |
int nonwild = 0; |
1497 |
> |
unsigned char tmpch = '\0'; |
1498 |
> |
unsigned int nonwild = 0; |
1499 |
|
va_list args; |
1500 |
|
|
1501 |
|
/* |
1514 |
|
|
1515 |
|
while (count--) |
1516 |
|
{ |
1517 |
< |
const char *p = va_arg(args, const char *); |
1517 |
> |
const unsigned char *p = va_arg(args, const unsigned char *); |
1518 |
|
if (p == NULL) |
1519 |
|
continue; |
1520 |
|
|
1526 |
|
* If we find enough non-wild characters, we can |
1527 |
|
* break - no point in searching further. |
1528 |
|
*/ |
1529 |
< |
if (++nonwild >= ConfigFileEntry.min_nonwildcard) |
1529 |
> |
if (++nonwild >= ConfigGeneral.min_nonwildcard) |
1530 |
|
{ |
1531 |
|
va_end(args); |
1532 |
|
return 1; |
1537 |
|
|
1538 |
|
if (warn) |
1539 |
|
sendto_one_notice(source_p, &me, |
1540 |
< |
":Please include at least %d non-wildcard characters with the mask", |
1541 |
< |
ConfigFileEntry.min_nonwildcard); |
1540 |
> |
":Please include at least %u non-wildcard characters with the mask", |
1541 |
> |
ConfigGeneral.min_nonwildcard); |
1542 |
|
va_end(args); |
1543 |
|
return 0; |
1544 |
|
} |
1545 |
|
|
1546 |
+ |
/* find_user_host() |
1547 |
+ |
* |
1548 |
+ |
* inputs - pointer to client placing kline |
1549 |
+ |
* - pointer to user_host_or_nick |
1550 |
+ |
* - pointer to user buffer |
1551 |
+ |
* - pointer to host buffer |
1552 |
+ |
* output - 0 if not ok to kline, 1 to kline i.e. if valid user host |
1553 |
+ |
* side effects - |
1554 |
+ |
*/ |
1555 |
+ |
static int |
1556 |
+ |
find_user_host(struct Client *source_p, char *user_host_or_nick, |
1557 |
+ |
char *luser, char *lhost) |
1558 |
+ |
{ |
1559 |
+ |
struct Client *target_p = NULL; |
1560 |
+ |
char *hostp = NULL; |
1561 |
+ |
|
1562 |
+ |
if (lhost == NULL) |
1563 |
+ |
{ |
1564 |
+ |
strlcpy(luser, user_host_or_nick, USERLEN*4 + 1); |
1565 |
+ |
return 1; |
1566 |
+ |
} |
1567 |
+ |
|
1568 |
+ |
if ((hostp = strchr(user_host_or_nick, '@')) || *user_host_or_nick == '*') |
1569 |
+ |
{ |
1570 |
+ |
/* Explicit user@host mask given */ |
1571 |
+ |
if (hostp) /* I'm a little user@host */ |
1572 |
+ |
{ |
1573 |
+ |
*(hostp++) = '\0'; /* short and squat */ |
1574 |
+ |
|
1575 |
+ |
if (*user_host_or_nick) |
1576 |
+ |
strlcpy(luser, user_host_or_nick, USERLEN*4 + 1); /* here is my user */ |
1577 |
+ |
else |
1578 |
+ |
strcpy(luser, "*"); |
1579 |
+ |
|
1580 |
+ |
if (*hostp) |
1581 |
+ |
strlcpy(lhost, hostp, HOSTLEN + 1); /* here is my host */ |
1582 |
+ |
else |
1583 |
+ |
strcpy(lhost, "*"); |
1584 |
+ |
} |
1585 |
+ |
else |
1586 |
+ |
{ |
1587 |
+ |
luser[0] = '*'; /* no @ found, assume its *@somehost */ |
1588 |
+ |
luser[1] = '\0'; |
1589 |
+ |
strlcpy(lhost, user_host_or_nick, HOSTLEN*4 + 1); |
1590 |
+ |
} |
1591 |
+ |
|
1592 |
+ |
return 1; |
1593 |
+ |
} |
1594 |
+ |
else |
1595 |
+ |
{ |
1596 |
+ |
/* Try to find user@host mask from nick */ |
1597 |
+ |
/* Okay to use source_p as the first param, because source_p == client_p */ |
1598 |
+ |
if ((target_p = |
1599 |
+ |
find_chasing(source_p, user_host_or_nick)) == NULL) |
1600 |
+ |
return 0; /* find_chasing sends ERR_NOSUCHNICK */ |
1601 |
+ |
|
1602 |
+ |
if (IsExemptKline(target_p)) |
1603 |
+ |
{ |
1604 |
+ |
if (IsClient(source_p)) |
1605 |
+ |
sendto_one_notice(source_p, &me, ":%s is E-lined", target_p->name); |
1606 |
+ |
return 0; |
1607 |
+ |
} |
1608 |
+ |
|
1609 |
+ |
/* |
1610 |
+ |
* Turn the "user" bit into "*user", blow away '~' |
1611 |
+ |
* if found in original user name (non-idented) |
1612 |
+ |
*/ |
1613 |
+ |
strlcpy(luser, target_p->username, USERLEN*4 + 1); |
1614 |
+ |
|
1615 |
+ |
if (target_p->username[0] == '~') |
1616 |
+ |
luser[0] = '*'; |
1617 |
+ |
|
1618 |
+ |
if (!strcmp(target_p->sockhost, "0")) |
1619 |
+ |
strlcpy(lhost, target_p->host, HOSTLEN*4 + 1); |
1620 |
+ |
else |
1621 |
+ |
strlcpy(lhost, target_p->sockhost, HOSTLEN*4 + 1); |
1622 |
+ |
return 1; |
1623 |
+ |
} |
1624 |
+ |
|
1625 |
+ |
return 0; |
1626 |
+ |
} |
1627 |
+ |
|
1628 |
|
/* XXX should this go into a separate file ? -Dianora */ |
1629 |
|
/* parse_aline |
1630 |
|
* |
1639 |
|
* - pointer to target_server to parse into if non NULL |
1640 |
|
* - pointer to reason to parse into |
1641 |
|
* |
1642 |
< |
* output - 1 if valid, -1 if not valid |
1642 |
> |
* output - 1 if valid, 0 if not valid |
1643 |
|
* side effects - A generalised k/d/x etc. line parser, |
1644 |
|
* "ALINE [time] user@host|string [ON] target :reason" |
1645 |
|
* will parse returning a parsed user, host if |
1662 |
|
char **target_server, char **reason) |
1663 |
|
{ |
1664 |
|
int found_tkline_time=0; |
1665 |
< |
static char def_reason[] = "No Reason"; |
1665 |
> |
static char def_reason[] = CONF_NOREASON; |
1666 |
|
static char user[USERLEN*4+1]; |
1667 |
|
static char host[HOSTLEN*4+1]; |
1668 |
|
|
1671 |
|
|
1672 |
|
found_tkline_time = valid_tkline(*parv, TK_MINUTES); |
1673 |
|
|
1674 |
< |
if (found_tkline_time != 0) |
1674 |
> |
if (found_tkline_time) |
1675 |
|
{ |
1676 |
|
parv++; |
1677 |
|
parc--; |
1678 |
|
|
1679 |
< |
if (tkline_time != NULL) |
1679 |
> |
if (tkline_time) |
1680 |
|
*tkline_time = found_tkline_time; |
1681 |
|
else |
1682 |
|
{ |
1683 |
|
sendto_one_notice(source_p, &me, ":temp_line not supported by %s", cmd); |
1684 |
< |
return -1; |
1684 |
> |
return 0; |
1685 |
|
} |
1686 |
|
} |
1687 |
|
|
1688 |
|
if (parc == 0) |
1689 |
|
{ |
1690 |
|
sendto_one_numeric(source_p, &me, ERR_NEEDMOREPARAMS, cmd); |
1691 |
< |
return -1; |
1691 |
> |
return 0; |
1692 |
|
} |
1693 |
|
|
1694 |
|
if (h_p == NULL) |
1695 |
|
*up_p = *parv; |
1696 |
|
else |
1697 |
|
{ |
1698 |
< |
if (find_user_host(source_p, *parv, user, host, parse_flags) == 0) |
1699 |
< |
return -1; |
1698 |
> |
if (find_user_host(source_p, *parv, user, host) == 0) |
1699 |
> |
return 0; |
1700 |
|
|
1701 |
|
*up_p = user; |
1702 |
|
*h_p = host; |
1705 |
|
parc--; |
1706 |
|
parv++; |
1707 |
|
|
1708 |
< |
if (parc != 0) |
1708 |
> |
if (parc) |
1709 |
|
{ |
1710 |
|
if (irccmp(*parv, "ON") == 0) |
1711 |
|
{ |
1715 |
|
if (target_server == NULL) |
1716 |
|
{ |
1717 |
|
sendto_one_notice(source_p, &me, ":ON server not supported by %s", cmd); |
1718 |
< |
return -1; |
1718 |
> |
return 0; |
1719 |
|
} |
1720 |
|
|
1721 |
|
if (!HasOFlag(source_p, OPER_FLAG_REMOTEBAN)) |
1722 |
|
{ |
1723 |
|
sendto_one_numeric(source_p, &me, ERR_NOPRIVS, "remoteban"); |
1724 |
< |
return -1; |
1724 |
> |
return 0; |
1725 |
|
} |
1726 |
|
|
1727 |
|
if (parc == 0 || EmptyString(*parv)) |
1728 |
|
{ |
1729 |
|
sendto_one_numeric(source_p, &me, ERR_NEEDMOREPARAMS, cmd); |
1730 |
< |
return -1; |
1730 |
> |
return 0; |
1731 |
|
} |
1732 |
|
|
1733 |
|
*target_server = *parv; |
1739 |
|
/* Make sure target_server *is* NULL if no ON server found |
1740 |
|
* caller probably NULL'd it first, but no harm to do it again -db |
1741 |
|
*/ |
1742 |
< |
if (target_server != NULL) |
1742 |
> |
if (target_server) |
1743 |
|
*target_server = NULL; |
1744 |
|
} |
1745 |
|
} |
1746 |
|
|
1747 |
< |
if (h_p != NULL) |
1747 |
> |
if (h_p) |
1748 |
|
{ |
1749 |
< |
if (strchr(user, '!') != NULL) |
1749 |
> |
if (strchr(user, '!')) |
1750 |
|
{ |
1751 |
|
sendto_one_notice(source_p, &me, ":Invalid character '!' in kline"); |
1752 |
< |
return -1; |
1752 |
> |
return 0; |
1753 |
|
} |
1754 |
|
|
1755 |
|
if ((parse_flags & AWILD) && !valid_wild_card(source_p, 1, 2, *up_p, *h_p)) |
1756 |
< |
return -1; |
1756 |
> |
return 0; |
1757 |
|
} |
1758 |
|
else |
1759 |
|
if ((parse_flags & AWILD) && !valid_wild_card(source_p, 1, 1, *up_p)) |
1760 |
< |
return -1; |
1760 |
> |
return 0; |
1761 |
|
|
1762 |
< |
if (reason != NULL) |
1762 |
> |
if (reason) |
1763 |
|
{ |
1764 |
< |
if (parc != 0 && !EmptyString(*parv)) |
1764 |
> |
if (parc && !EmptyString(*parv)) |
1765 |
|
{ |
1766 |
|
*reason = *parv; |
1767 |
+ |
|
1768 |
|
if (!valid_comment(source_p, *reason, 1)) |
1769 |
< |
return -1; |
1769 |
> |
return 0; |
1770 |
|
} |
1771 |
|
else |
1772 |
|
*reason = def_reason; |
1775 |
|
return 1; |
1776 |
|
} |
1777 |
|
|
1971 |
– |
/* find_user_host() |
1972 |
– |
* |
1973 |
– |
* inputs - pointer to client placing kline |
1974 |
– |
* - pointer to user_host_or_nick |
1975 |
– |
* - pointer to user buffer |
1976 |
– |
* - pointer to host buffer |
1977 |
– |
* output - 0 if not ok to kline, 1 to kline i.e. if valid user host |
1978 |
– |
* side effects - |
1979 |
– |
*/ |
1980 |
– |
static int |
1981 |
– |
find_user_host(struct Client *source_p, char *user_host_or_nick, |
1982 |
– |
char *luser, char *lhost, unsigned int flags) |
1983 |
– |
{ |
1984 |
– |
struct Client *target_p = NULL; |
1985 |
– |
char *hostp = NULL; |
1986 |
– |
|
1987 |
– |
if (lhost == NULL) |
1988 |
– |
{ |
1989 |
– |
strlcpy(luser, user_host_or_nick, USERLEN*4 + 1); |
1990 |
– |
return 1; |
1991 |
– |
} |
1992 |
– |
|
1993 |
– |
if ((hostp = strchr(user_host_or_nick, '@')) || *user_host_or_nick == '*') |
1994 |
– |
{ |
1995 |
– |
/* Explicit user@host mask given */ |
1996 |
– |
|
1997 |
– |
if (hostp != NULL) /* I'm a little user@host */ |
1998 |
– |
{ |
1999 |
– |
*(hostp++) = '\0'; /* short and squat */ |
2000 |
– |
if (*user_host_or_nick) |
2001 |
– |
strlcpy(luser, user_host_or_nick, USERLEN*4 + 1); /* here is my user */ |
2002 |
– |
else |
2003 |
– |
strcpy(luser, "*"); |
2004 |
– |
|
2005 |
– |
if (*hostp) |
2006 |
– |
strlcpy(lhost, hostp, HOSTLEN + 1); /* here is my host */ |
2007 |
– |
else |
2008 |
– |
strcpy(lhost, "*"); |
2009 |
– |
} |
2010 |
– |
else |
2011 |
– |
{ |
2012 |
– |
luser[0] = '*'; /* no @ found, assume its *@somehost */ |
2013 |
– |
luser[1] = '\0'; |
2014 |
– |
strlcpy(lhost, user_host_or_nick, HOSTLEN*4 + 1); |
2015 |
– |
} |
2016 |
– |
|
2017 |
– |
return 1; |
2018 |
– |
} |
2019 |
– |
else |
2020 |
– |
{ |
2021 |
– |
/* Try to find user@host mask from nick */ |
2022 |
– |
/* Okay to use source_p as the first param, because source_p == client_p */ |
2023 |
– |
if ((target_p = |
2024 |
– |
find_chasing(source_p, user_host_or_nick)) == NULL) |
2025 |
– |
return 0; |
2026 |
– |
|
2027 |
– |
if (IsExemptKline(target_p)) |
2028 |
– |
{ |
2029 |
– |
if (!IsServer(source_p)) |
2030 |
– |
sendto_one_notice(source_p, &me, ":%s is E-lined", target_p->name); |
2031 |
– |
return 0; |
2032 |
– |
} |
2033 |
– |
|
2034 |
– |
/* |
2035 |
– |
* turn the "user" bit into "*user", blow away '~' |
2036 |
– |
* if found in original user name (non-idented) |
2037 |
– |
*/ |
2038 |
– |
strlcpy(luser, target_p->username, USERLEN*4 + 1); |
2039 |
– |
|
2040 |
– |
if (target_p->username[0] == '~') |
2041 |
– |
luser[0] = '*'; |
2042 |
– |
|
2043 |
– |
if (target_p->sockhost[0] == '\0' || |
2044 |
– |
(target_p->sockhost[0] == '0' && target_p->sockhost[1] == '\0')) |
2045 |
– |
strlcpy(lhost, target_p->host, HOSTLEN*4 + 1); |
2046 |
– |
else |
2047 |
– |
strlcpy(lhost, target_p->sockhost, HOSTLEN*4 + 1); |
2048 |
– |
return 1; |
2049 |
– |
} |
2050 |
– |
|
2051 |
– |
return 0; |
2052 |
– |
} |
2053 |
– |
|
1778 |
|
/* valid_comment() |
1779 |
|
* |
1780 |
|
* inputs - pointer to client |
1812 |
|
else |
1813 |
|
encr = password; |
1814 |
|
|
1815 |
< |
return !strcmp(encr, conf->passwd); |
1815 |
> |
return encr && !strcmp(encr, conf->passwd); |
1816 |
|
} |
1817 |
|
|
1818 |
|
/* |
1820 |
|
* |
1821 |
|
* inputs - client sending the cluster |
1822 |
|
* - command name "KLINE" "XLINE" etc. |
1823 |
< |
* - capab -- CAP_KLN etc. from s_serv.h |
1823 |
> |
* - capab -- CAP_KLN etc. from server.h |
1824 |
|
* - cluster type -- CLUSTER_KLINE etc. from conf.h |
1825 |
|
* - pattern and args to send along |
1826 |
|
* output - none |
1828 |
|
* along to all servers that match capab and cluster type |
1829 |
|
*/ |
1830 |
|
void |
1831 |
< |
cluster_a_line(struct Client *source_p, const char *command, |
1832 |
< |
int capab, int cluster_type, const char *pattern, ...) |
1831 |
> |
cluster_a_line(struct Client *source_p, const char *command, unsigned int capab, |
1832 |
> |
unsigned int cluster_type, const char *pattern, ...) |
1833 |
|
{ |
1834 |
|
va_list args; |
1835 |
< |
char buffer[IRCD_BUFSIZE]; |
1836 |
< |
const dlink_node *ptr = NULL; |
1835 |
> |
char buffer[IRCD_BUFSIZE] = ""; |
1836 |
> |
const dlink_node *node = NULL; |
1837 |
|
|
1838 |
|
va_start(args, pattern); |
1839 |
|
vsnprintf(buffer, sizeof(buffer), pattern, args); |
1840 |
|
va_end(args); |
1841 |
|
|
1842 |
< |
DLINK_FOREACH(ptr, cluster_items.head) |
1842 |
> |
DLINK_FOREACH(node, cluster_items.head) |
1843 |
|
{ |
1844 |
< |
const struct MaskItem *conf = ptr->data; |
1844 |
> |
const struct MaskItem *conf = node->data; |
1845 |
|
|
1846 |
|
if (conf->flags & cluster_type) |
1847 |
< |
sendto_match_servs(source_p, conf->name, CAP_CLUSTER|capab, |
1847 |
> |
sendto_match_servs(source_p, conf->name, CAP_CLUSTER | capab, |
1848 |
|
"%s %s %s", command, conf->name, buffer); |
1849 |
|
} |
1850 |
|
} |
1884 |
|
|
1885 |
|
if (iptr->nickptr) |
1886 |
|
strlcpy(iptr->nickptr, "*", iptr->nicksize); |
1887 |
+ |
|
1888 |
|
if (iptr->userptr) |
1889 |
|
strlcpy(iptr->userptr, "*", iptr->usersize); |
1890 |
+ |
|
1891 |
|
if (iptr->hostptr) |
1892 |
|
strlcpy(iptr->hostptr, "*", iptr->hostsize); |
1893 |
|
|
1895 |
|
{ |
1896 |
|
*p = '\0'; |
1897 |
|
|
1898 |
< |
if (iptr->nickptr && *iptr->nuhmask != '\0') |
1898 |
> |
if (iptr->nickptr && *iptr->nuhmask) |
1899 |
|
strlcpy(iptr->nickptr, iptr->nuhmask, iptr->nicksize); |
1900 |
|
|
1901 |
|
if ((q = strchr(++p, '@'))) |
1902 |
|
{ |
1903 |
|
*q++ = '\0'; |
1904 |
|
|
1905 |
< |
if (*p != '\0') |
1905 |
> |
if (*p) |
1906 |
|
strlcpy(iptr->userptr, p, iptr->usersize); |
1907 |
|
|
1908 |
< |
if (*q != '\0') |
1908 |
> |
if (*q) |
1909 |
|
strlcpy(iptr->hostptr, q, iptr->hostsize); |
1910 |
|
} |
1911 |
|
else |
1912 |
|
{ |
1913 |
< |
if (*p != '\0') |
1913 |
> |
if (*p) |
1914 |
|
strlcpy(iptr->userptr, p, iptr->usersize); |
1915 |
|
} |
1916 |
|
} |
1922 |
|
/* if found a @ */ |
1923 |
|
*p++ = '\0'; |
1924 |
|
|
1925 |
< |
if (*iptr->nuhmask != '\0') |
1925 |
> |
if (*iptr->nuhmask) |
1926 |
|
strlcpy(iptr->userptr, iptr->nuhmask, iptr->usersize); |
1927 |
|
|
1928 |
< |
if (*p != '\0') |
1928 |
> |
if (*p) |
1929 |
|
strlcpy(iptr->hostptr, p, iptr->hostsize); |
1930 |
|
} |
1931 |
|
else |
1932 |
|
{ |
1933 |
< |
/* no @ found */ |
1933 |
> |
/* No @ found */ |
1934 |
|
if (!iptr->nickptr || strpbrk(iptr->nuhmask, ".:")) |
1935 |
|
strlcpy(iptr->hostptr, iptr->nuhmask, iptr->hostsize); |
1936 |
|
else |