ViewVC Help
View File | Revision Log | Show Annotations | View Changeset | Root Listing
root/svn/ircd-hybrid/trunk/src/server.c
Revision: 4113
Committed: Tue Jul 1 16:02:52 2014 UTC (11 years, 1 month ago) by michael
Content type: text/x-csrc
File size: 29601 byte(s)
Log Message:
- Make use of binary_to_hex() in ssl_handshake() and ssl_server_handshake()

File Contents

# User Rev Content
1 adx 30 /*
2 michael 2916 * ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd)
3 adx 30 *
4 michael 2916 * Copyright (c) 1997-2014 ircd-hybrid development team
5 adx 30 *
6     * This program is free software; you can redistribute it and/or modify
7     * it under the terms of the GNU General Public License as published by
8     * the Free Software Foundation; either version 2 of the License, or
9     * (at your option) any later version.
10     *
11     * This program is distributed in the hope that it will be useful,
12     * but WITHOUT ANY WARRANTY; without even the implied warranty of
13     * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14     * GNU General Public License for more details.
15     *
16     * You should have received a copy of the GNU General Public License
17     * along with this program; if not, write to the Free Software
18     * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307
19     * USA
20     */
21    
22 michael 2916 /*! \file s_serv.c
23     * \brief Server related functions.
24     * \version $Id$
25     */
26    
27 adx 30 #include "stdinc.h"
28     #ifdef HAVE_LIBCRYPTO
29     #include <openssl/rsa.h>
30     #include "rsa.h"
31     #endif
32 michael 1011 #include "list.h"
33 adx 30 #include "client.h"
34     #include "event.h"
35     #include "hash.h"
36     #include "irc_string.h"
37     #include "ircd.h"
38     #include "ircd_defs.h"
39     #include "s_bsd.h"
40     #include "numeric.h"
41     #include "packet.h"
42 michael 1309 #include "conf.h"
43 michael 3347 #include "server.h"
44 michael 1309 #include "log.h"
45 michael 3347 #include "user.h"
46 adx 30 #include "send.h"
47     #include "memory.h"
48 michael 2916 #include "channel.h"
49 michael 1243 #include "parse.h"
50 adx 30
51     #define MIN_CONN_FREQ 300
52    
53 michael 2156 dlink_list flatten_links;
54 adx 30 static dlink_list cap_list = { NULL, NULL, 0 };
55     static CNCB serv_connect_callback;
56    
57    
58     /*
59     * write_links_file
60     *
61     * inputs - void pointer which is not used
62     * output - NONE
63     * side effects - called from an event, write out list of linked servers
64     * but in no particular order.
65     */
66     void
67 michael 2156 write_links_file(void *notused)
68 adx 30 {
69 michael 2156 FILE *file = NULL;
70 michael 2216 dlink_node *ptr = NULL, *ptr_next = NULL;
71 michael 3215 char buff[IRCD_BUFSIZE] = "";
72 adx 30
73 michael 2156 if ((file = fopen(LIPATH, "w")) == NULL)
74 adx 30 return;
75    
76 michael 2156 DLINK_FOREACH_SAFE(ptr, ptr_next, flatten_links.head)
77 adx 30 {
78 michael 2156 dlinkDelete(ptr, &flatten_links);
79     MyFree(ptr->data);
80     free_dlink_node(ptr);
81 adx 30 }
82    
83     DLINK_FOREACH(ptr, global_serv_list.head)
84     {
85 michael 1325 const struct Client *target_p = ptr->data;
86 adx 30
87 michael 2156 /*
88     * Skip hidden servers, aswell as ourselves, since we already send
89     * ourselves in /links
90     */
91     if (IsHidden(target_p) || IsMe(target_p))
92 adx 30 continue;
93    
94 michael 1851 if (HasFlag(target_p, FLAGS_SERVICE) && ConfigServerHide.hide_services)
95     continue;
96    
97 michael 1545 /*
98     * Attempt to format the file in such a way it follows the usual links output
99 adx 30 * ie "servername uplink :hops info"
100     * Mostly for aesthetic reasons - makes it look pretty in mIRC ;)
101     * - madmax
102     */
103 michael 2156 snprintf(buff, sizeof(buff), "%s %s :1 %s", target_p->name,
104     me.name, target_p->info);
105 michael 2212 dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
106 michael 2156 snprintf(buff, sizeof(buff), "%s %s :1 %s\n", target_p->name,
107     me.name, target_p->info);
108 adx 30
109 michael 1325 fputs(buff, file);
110 adx 30 }
111    
112 michael 1325 fclose(file);
113 adx 30 }
114    
115 michael 2216 void
116     read_links_file(void)
117     {
118     FILE *file = NULL;
119     char *p = NULL;
120 michael 3215 char buff[IRCD_BUFSIZE] = "";
121 michael 2216
122     if ((file = fopen(LIPATH, "r")) == NULL)
123     return;
124    
125     while (fgets(buff, sizeof(buff), file))
126     {
127 michael 3246 if ((p = strchr(buff, '\n')))
128 michael 2216 *p = '\0';
129    
130     dlinkAddTail(xstrdup(buff), make_dlink_node(), &flatten_links);
131     }
132    
133     fclose(file);
134     }
135    
136 adx 30 /* hunt_server()
137     * Do the basic thing in delivering the message (command)
138     * across the relays to the specific server (server) for
139     * actions.
140     *
141     * Note: The command is a format string and *MUST* be
142     * of prefixed style (e.g. ":%s COMMAND %s ...").
143     * Command can have only max 8 parameters.
144     *
145     * server parv[server] is the parameter identifying the
146     * target server.
147     *
148     * *WARNING*
149     * parv[server] is replaced with the pointer to the
150     * real servername from the matched client (I'm lazy
151     * now --msa).
152     *
153     * returns: (see #defines)
154     */
155     int
156 michael 3156 hunt_server(struct Client *source_p, const char *command,
157 michael 1857 const int server, const int parc, char *parv[])
158 adx 30 {
159     struct Client *target_p = NULL;
160     struct Client *target_tmp = NULL;
161     dlink_node *ptr;
162    
163 michael 1344 /* Assume it's me, if no server */
164     if (parc <= server || EmptyString(parv[server]))
165     return HUNTED_ISME;
166 adx 30
167 michael 1652 if (!strcmp(parv[server], me.id) || !match(parv[server], me.name))
168 michael 1344 return HUNTED_ISME;
169    
170 adx 30 /* These are to pickup matches that would cause the following
171     * message to go in the wrong direction while doing quick fast
172     * non-matching lookups.
173     */
174     if (MyClient(source_p))
175 michael 1169 target_p = hash_find_client(parv[server]);
176 adx 30 else
177 michael 3156 target_p = find_person(source_p, parv[server]);
178 adx 30
179     if (target_p)
180     if (target_p->from == source_p->from && !MyConnect(target_p))
181     target_p = NULL;
182    
183 michael 1169 if (target_p == NULL && (target_p = hash_find_server(parv[server])))
184 adx 30 if (target_p->from == source_p->from && !MyConnect(target_p))
185     target_p = NULL;
186    
187     /* Again, if there are no wild cards involved in the server
188     * name, use the hash lookup
189     */
190     if (target_p == NULL)
191     {
192 michael 3449 if (!has_wildcards(parv[server]))
193 adx 30 {
194 michael 1169 if (!(target_p = hash_find_server(parv[server])))
195 adx 30 {
196 michael 3109 sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
197 michael 2182 return HUNTED_NOSUCH;
198 adx 30 }
199     }
200     else
201     {
202     DLINK_FOREACH(ptr, global_client_list.head)
203     {
204     target_tmp = ptr->data;
205    
206 michael 1652 if (!match(parv[server], target_tmp->name))
207 adx 30 {
208     if (target_tmp->from == source_p->from && !MyConnect(target_tmp))
209     continue;
210     target_p = ptr->data;
211    
212 michael 3156 if (IsRegistered(target_p) && (target_p != source_p->from))
213 adx 30 break;
214     }
215     }
216     }
217     }
218    
219 michael 3246 if (target_p)
220 adx 30 {
221 michael 3246 if (!IsRegistered(target_p))
222 adx 30 {
223 michael 3109 sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
224 adx 30 return HUNTED_NOSUCH;
225     }
226    
227     if (IsMe(target_p) || MyClient(target_p))
228     return HUNTED_ISME;
229    
230 michael 1652 if (match(target_p->name, parv[server]))
231 adx 30 parv[server] = target_p->name;
232    
233 michael 3136 /* This is a little kludgy but should work... */
234 michael 3096 sendto_one(target_p, command, ID_or_name(source_p, target_p),
235 adx 30 parv[1], parv[2], parv[3], parv[4],
236     parv[5], parv[6], parv[7], parv[8]);
237 michael 2134 return HUNTED_PASS;
238 michael 2345 }
239 adx 30
240 michael 3109 sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]);
241 michael 2134 return HUNTED_NOSUCH;
242 adx 30 }
243    
244     /* try_connections()
245     *
246     * inputs - void pointer which is not used
247     * output - NONE
248     * side effects -
249     * scan through configuration and try new connections.
250     * Returns the calendar time when the next call to this
251     * function should be made latest. (No harm done if this
252     * is called earlier or later...)
253     */
254     void
255     try_connections(void *unused)
256     {
257 michael 1632 dlink_node *ptr = NULL;
258 michael 3335 int confrq = 0;
259 adx 30
260     /* TODO: change this to set active flag to 0 when added to event! --Habeeb */
261     if (GlobalSetOptions.autoconn == 0)
262     return;
263    
264     DLINK_FOREACH(ptr, server_items.head)
265     {
266 michael 3335 struct MaskItem *conf = ptr->data;
267 adx 30
268 michael 1636 assert(conf->type == CONF_SERVER);
269 michael 1632
270 michael 2345 /* Also when already connecting! (update holdtimes) --SRB
271 adx 30 */
272 michael 1632 if (!conf->port ||!IsConfAllowAutoConn(conf))
273 adx 30 continue;
274    
275    
276     /* Skip this entry if the use of it is still on hold until
277     * future. Otherwise handle this entry (and set it on hold
278     * until next time). Will reset only hold times, if already
279     * made one successfull connection... [this algorithm is
280     * a bit fuzzy... -- msa >;) ]
281     */
282 michael 1649 if (conf->until > CurrentTime)
283 adx 30 continue;
284    
285 michael 4028 assert(conf->class);
286 adx 30
287 michael 4028 confrq = conf->class->con_freq;
288     if (confrq < MIN_CONN_FREQ)
289     confrq = MIN_CONN_FREQ;
290    
291 michael 1649 conf->until = CurrentTime + confrq;
292 adx 30
293 michael 3246 /*
294     * Found a CONNECT config with port specified, scan clients
295 adx 30 * and see if this server is already connected?
296     */
297 michael 3246 if (hash_find_server(conf->name))
298 adx 30 continue;
299    
300 michael 1632 if (conf->class->ref_count < conf->class->max_total)
301 adx 30 {
302     /* Go to the end of the list, if not already last */
303 michael 3246 if (ptr->next)
304 adx 30 {
305     dlinkDelete(ptr, &server_items);
306     dlinkAddTail(conf, &conf->node, &server_items);
307     }
308    
309     if (find_servconn_in_progress(conf->name))
310     return;
311    
312 michael 3246 /*
313     * We used to only print this if serv_connect() actually
314 adx 30 * succeeded, but since comm_tcp_connect() can call the callback
315     * immediately if there is an error, we were getting error messages
316     * in the wrong order. SO, we just print out the activated line,
317     * and let serv_connect() / serv_connect_callback() print an
318     * error afterwards if it fails.
319     * -- adrian
320     */
321     if (ConfigServerHide.hide_server_ips)
322 michael 1618 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
323     "Connection to %s activated.",
324 adx 30 conf->name);
325     else
326 michael 1618 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
327     "Connection to %s[%s] activated.",
328 michael 1632 conf->name, conf->host);
329 adx 30
330 michael 1632 serv_connect(conf, NULL);
331 adx 30 /* We connect only one at time... */
332     return;
333     }
334     }
335     }
336    
337     int
338 michael 1115 valid_servname(const char *name)
339     {
340 michael 3451 unsigned int dots = 0;
341 michael 1115 const char *p = name;
342    
343     for (; *p; ++p)
344     {
345     if (!IsServChar(*p))
346 michael 1118 return 0;
347 michael 1115
348     if (*p == '.')
349     ++dots;
350     }
351    
352 michael 3451 return dots && (p - name) <= HOSTLEN;
353 michael 1115 }
354    
355     int
356 michael 1302 check_server(const char *name, struct Client *client_p)
357 adx 30 {
358     dlink_node *ptr;
359 michael 1632 struct MaskItem *conf = NULL;
360     struct MaskItem *server_conf = NULL;
361 adx 30 int error = -1;
362    
363 michael 3246 assert(client_p);
364 adx 30
365     /* loop through looking for all possible connect items that might work */
366     DLINK_FOREACH(ptr, server_items.head)
367     {
368     conf = ptr->data;
369    
370 michael 1652 if (match(name, conf->name))
371 adx 30 continue;
372    
373     error = -3;
374    
375     /* XXX: Fix me for IPv6 */
376     /* XXX sockhost is the IPv4 ip as a string */
377 michael 2345 if (!match(conf->host, client_p->host) ||
378 michael 1652 !match(conf->host, client_p->sockhost))
379 adx 30 {
380     error = -2;
381    
382 michael 1632 if (!match_conf_password(client_p->localClient->passwd, conf))
383 michael 1414 return -2;
384 adx 30
385 michael 2228 if (!EmptyString(conf->certfp))
386 michael 2229 if (EmptyString(client_p->certfp) || strcasecmp(client_p->certfp, conf->certfp))
387 michael 2228 return -4;
388    
389 michael 1414 server_conf = conf;
390 adx 30 }
391     }
392    
393     if (server_conf == NULL)
394 michael 2182 return error;
395 adx 30
396     attach_conf(client_p, server_conf);
397    
398    
399 michael 3246 if (server_conf)
400 adx 30 {
401     struct sockaddr_in *v4;
402     #ifdef IPV6
403     struct sockaddr_in6 *v6;
404     #endif
405 michael 1632 switch (server_conf->aftype)
406 adx 30 {
407     #ifdef IPV6
408 michael 2345 case AF_INET6:
409 michael 1632 v6 = (struct sockaddr_in6 *)&server_conf->addr;
410 adx 30
411     if (IN6_IS_ADDR_UNSPECIFIED(&v6->sin6_addr))
412 michael 1632 memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
413 adx 30 break;
414     #endif
415     case AF_INET:
416 michael 1632 v4 = (struct sockaddr_in *)&server_conf->addr;
417 adx 30
418     if (v4->sin_addr.s_addr == INADDR_NONE)
419 michael 2345 memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr));
420 adx 30 break;
421     }
422     }
423    
424 michael 2182 return 0;
425 adx 30 }
426    
427     /* add_capability()
428     *
429     * inputs - string name of CAPAB
430     * - int flag of capability
431     * output - NONE
432     * side effects - Adds given capability name and bit mask to
433     * current supported capabilities. This allows
434     * modules to dynamically add or subtract their capability.
435     */
436     void
437     add_capability(const char *capab_name, int cap_flag, int add_to_default)
438     {
439 michael 3504 struct Capability *cap = MyCalloc(sizeof(*cap));
440 adx 30
441 michael 1646 cap->name = xstrdup(capab_name);
442 adx 30 cap->cap = cap_flag;
443     dlinkAdd(cap, &cap->node, &cap_list);
444 michael 885
445 adx 30 if (add_to_default)
446     default_server_capabs |= cap_flag;
447     }
448    
449     /* delete_capability()
450     *
451     * inputs - string name of CAPAB
452     * output - NONE
453     * side effects - delete given capability from ones known.
454     */
455     int
456     delete_capability(const char *capab_name)
457     {
458 michael 3335 dlink_node *ptr = NULL, *ptr_next = NULL;
459 adx 30
460 michael 3335 DLINK_FOREACH_SAFE(ptr, ptr_next, cap_list.head)
461 adx 30 {
462 michael 3335 struct Capability *cap = ptr->data;
463 adx 30
464 michael 3335 if (cap->cap)
465 adx 30 {
466 michael 3335 if (!irccmp(cap->name, capab_name))
467 adx 30 {
468 michael 2134 default_server_capabs &= ~(cap->cap);
469     dlinkDelete(ptr, &cap_list);
470     MyFree(cap->name);
471     MyFree(cap);
472 adx 30 }
473     }
474     }
475    
476 michael 896 return 0;
477 adx 30 }
478    
479     /*
480     * find_capability()
481     *
482     * inputs - string name of capab to find
483     * output - 0 if not found CAPAB otherwise
484     * side effects - none
485     */
486 michael 1877 unsigned int
487 adx 30 find_capability(const char *capab)
488     {
489 michael 896 const dlink_node *ptr = NULL;
490 adx 30
491     DLINK_FOREACH(ptr, cap_list.head)
492     {
493 michael 896 const struct Capability *cap = ptr->data;
494 adx 30
495 michael 896 if (cap->cap && !irccmp(cap->name, capab))
496     return cap->cap;
497 adx 30 }
498 michael 896
499     return 0;
500 adx 30 }
501    
502     /* send_capabilities()
503     *
504     * inputs - Client pointer to send to
505     * - int flag of capabilities that this server can send
506     * output - NONE
507     * side effects - send the CAPAB line to a server -orabidoo
508     *
509     */
510     void
511 michael 1632 send_capabilities(struct Client *client_p, int cap_can_send)
512 adx 30 {
513 michael 3746 char buf[IRCD_BUFSIZE] = "";
514     const dlink_node *ptr = NULL;
515 adx 30
516     DLINK_FOREACH(ptr, cap_list.head)
517     {
518 michael 3746 const struct Capability *cap = ptr->data;
519 adx 30
520     if (cap->cap & (cap_can_send|default_server_capabs))
521     {
522 michael 3746 strlcat(buf, cap->name, sizeof(buf));
523     if (ptr->next)
524     strlcat(buf, " ", sizeof(buf));
525 adx 30 }
526     }
527    
528 michael 3746 sendto_one(client_p, "CAPAB :%s", buf);
529 adx 30 }
530    
531     /*
532     * show_capabilities - show current server capabilities
533     *
534     * inputs - pointer to a struct Client
535     * output - pointer to static string
536     * side effects - build up string representing capabilities of server listed
537     */
538     const char *
539 michael 2282 show_capabilities(const struct Client *target_p)
540 adx 30 {
541 michael 2309 static char msgbuf[IRCD_BUFSIZE] = "";
542 michael 2282 const dlink_node *ptr = NULL;
543 adx 30
544 michael 2309 strlcpy(msgbuf, "TS", sizeof(msgbuf));
545    
546 adx 30 DLINK_FOREACH(ptr, cap_list.head)
547     {
548     const struct Capability *cap = ptr->data;
549    
550 michael 2282 if (!IsCapable(target_p, cap->cap))
551     continue;
552    
553     strlcat(msgbuf, " ", sizeof(msgbuf));
554     strlcat(msgbuf, cap->name, sizeof(msgbuf));
555 adx 30 }
556 michael 1302
557     return msgbuf;
558 adx 30 }
559    
560     /* make_server()
561     *
562     * inputs - pointer to client struct
563     * output - pointer to struct Server
564     * side effects - add's an Server information block to a client
565     * if it was not previously allocated.
566     */
567     struct Server *
568     make_server(struct Client *client_p)
569     {
570     if (client_p->serv == NULL)
571 michael 3504 client_p->serv = MyCalloc(sizeof(struct Server));
572 adx 30
573     return client_p->serv;
574     }
575    
576     /* New server connection code
577     * Based upon the stuff floating about in s_bsd.c
578     * -- adrian
579     */
580    
581     /* serv_connect() - initiate a server connection
582     *
583 michael 2345 * inputs - pointer to conf
584 adx 30 * - pointer to client doing the connect
585     * output -
586     * side effects -
587     *
588     * This code initiates a connection to a server. It first checks to make
589     * sure the given server exists. If this is the case, it creates a socket,
590     * creates a client, saves the socket information in the client, and
591     * initiates a connection to the server through comm_connect_tcp(). The
592     * completion of this goes through serv_completed_connection().
593     *
594     * We return 1 if the connection is attempted, since we don't know whether
595     * it suceeded or not, and 0 if it fails in here somewhere.
596     */
597     int
598 michael 1632 serv_connect(struct MaskItem *conf, struct Client *by)
599 adx 30 {
600 michael 3246 struct Client *client_p = NULL;
601     char buf[HOSTIPLEN + 1] = "";
602 adx 30
603     /* conversion structs */
604     struct sockaddr_in *v4;
605 michael 3246
606 michael 1632 /* Make sure conf is useful */
607 michael 3246 assert(conf);
608 adx 30
609 michael 1632 getnameinfo((struct sockaddr *)&conf->addr, conf->addr.ss_len,
610 michael 1123 buf, sizeof(buf), NULL, 0, NI_NUMERICHOST);
611 michael 1632 ilog(LOG_TYPE_IRCD, "Connect to %s[%s] @%s", conf->name, conf->host,
612 adx 30 buf);
613    
614     /* Still processing a DNS lookup? -> exit */
615 michael 1632 if (conf->dns_pending)
616 adx 30 {
617 michael 1618 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
618 michael 992 "Error connecting to %s: DNS lookup for connect{} in progress.",
619     conf->name);
620 michael 3246 return 0;
621 adx 30 }
622    
623 michael 1632 if (conf->dns_failed)
624 michael 992 {
625 michael 1618 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
626 michael 992 "Error connecting to %s: DNS lookup for connect{} failed.",
627     conf->name);
628 michael 3246 return 0;
629 michael 992 }
630    
631 adx 30 /* Make sure this server isn't already connected
632 michael 1632 * Note: conf should ALWAYS be a valid C: line
633 adx 30 */
634 michael 3246 if ((client_p = hash_find_server(conf->name)))
635 michael 2345 {
636 michael 1618 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
637 michael 2134 "Server %s already present from %s",
638     conf->name, get_client_name(client_p, SHOW_IP));
639 michael 1618 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
640 michael 2134 "Server %s already present from %s",
641     conf->name, get_client_name(client_p, MASK_IP));
642 adx 30 if (by && IsClient(by) && !MyClient(by))
643 michael 3110 sendto_one_notice(by, &me, ":Server %s already present from %s",
644     conf->name, get_client_name(client_p, MASK_IP));
645 michael 2134 return 0;
646 adx 30 }
647 michael 2345
648 adx 30 /* Create a local client */
649     client_p = make_client(NULL);
650    
651     /* Copy in the server, hostname, fd */
652     strlcpy(client_p->name, conf->name, sizeof(client_p->name));
653 michael 1632 strlcpy(client_p->host, conf->host, sizeof(client_p->host));
654 adx 30
655     /* We already converted the ip once, so lets use it - stu */
656 michael 1115 strlcpy(client_p->sockhost, buf, sizeof(client_p->sockhost));
657 adx 30
658 michael 2345 /* create a socket for the server connection */
659 michael 3335 if (comm_open(&client_p->localClient->fd, conf->addr.ss.ss_family, SOCK_STREAM, 0, NULL) < 0)
660 adx 30 {
661     /* Eek, failure to create the socket */
662 michael 3335 report_error(L_ALL, "opening stream socket to %s: %s", conf->name, errno);
663    
664 adx 30 SetDead(client_p);
665 michael 3171 exit_client(client_p, "Connection failed");
666 michael 2134 return 0;
667 adx 30 }
668    
669     /* servernames are always guaranteed under HOSTLEN chars */
670     fd_note(&client_p->localClient->fd, "Server: %s", conf->name);
671    
672     /* Attach config entries to client here rather than in
673     * serv_connect_callback(). This to avoid null pointer references.
674     */
675 michael 1632 if (!attach_connect_block(client_p, conf->name, conf->host))
676 adx 30 {
677 michael 1618 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
678 michael 2134 "Host %s is not enabled for connecting: no connect{} block",
679     conf->name);
680 michael 2345 if (by && IsClient(by) && !MyClient(by))
681 michael 3110 sendto_one_notice(by, &me, ":Connect to host %s failed.", client_p->name);
682    
683 adx 30 SetDead(client_p);
684 michael 3171 exit_client(client_p, "Connection failed");
685 michael 2134 return 0;
686 adx 30 }
687    
688     /* at this point we have a connection in progress and C/N lines
689     * attached to the client, the socket info should be saved in the
690     * client and it should either be resolved or have a valid address.
691     *
692     * The socket has been connected or connect is in progress.
693     */
694     make_server(client_p);
695    
696     if (by && IsClient(by))
697     strlcpy(client_p->serv->by, by->name, sizeof(client_p->serv->by));
698     else
699     strlcpy(client_p->serv->by, "AutoConn.", sizeof(client_p->serv->by));
700    
701     SetConnecting(client_p);
702     dlinkAdd(client_p, &client_p->node, &global_client_list);
703 michael 3335
704 michael 1632 client_p->localClient->aftype = conf->aftype;
705 adx 30
706     /* Now, initiate the connection */
707 michael 2345 /* XXX assume that a non 0 type means a specific bind address
708 adx 30 * for this connect.
709     */
710 michael 1632 switch (conf->aftype)
711 adx 30 {
712     case AF_INET:
713 michael 1632 v4 = (struct sockaddr_in*)&conf->bind;
714 michael 3246 if (v4->sin_addr.s_addr)
715 adx 30 {
716     struct irc_ssaddr ipn;
717     memset(&ipn, 0, sizeof(struct irc_ssaddr));
718     ipn.ss.ss_family = AF_INET;
719     ipn.ss_port = 0;
720 michael 1632 memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
721 michael 2134 comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
722 michael 2345 (struct sockaddr *)&ipn, ipn.ss_len,
723 michael 2134 serv_connect_callback, client_p, conf->aftype,
724     CONNECTTIMEOUT);
725 adx 30 }
726     else if (ServerInfo.specific_ipv4_vhost)
727     {
728     struct irc_ssaddr ipn;
729     memset(&ipn, 0, sizeof(struct irc_ssaddr));
730     ipn.ss.ss_family = AF_INET;
731     ipn.ss_port = 0;
732     memcpy(&ipn, &ServerInfo.ip, sizeof(struct irc_ssaddr));
733 michael 1632 comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
734 adx 30 (struct sockaddr *)&ipn, ipn.ss_len,
735 michael 1632 serv_connect_callback, client_p, conf->aftype,
736 michael 2134 CONNECTTIMEOUT);
737 adx 30 }
738     else
739 michael 2345 comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port,
740     NULL, 0, serv_connect_callback, client_p, conf->aftype,
741 adx 30 CONNECTTIMEOUT);
742     break;
743     #ifdef IPV6
744     case AF_INET6:
745     {
746 michael 2182 struct irc_ssaddr ipn;
747     struct sockaddr_in6 *v6;
748     struct sockaddr_in6 *v6conf;
749 adx 30
750 michael 2182 memset(&ipn, 0, sizeof(struct irc_ssaddr));
751     v6conf = (struct sockaddr_in6 *)&conf->bind;
752     v6 = (struct sockaddr_in6 *)&ipn;
753 adx 30
754 michael 3246 if (memcmp(&v6conf->sin6_addr, &v6->sin6_addr, sizeof(struct in6_addr)))
755 adx 30 {
756 michael 2182 memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr));
757     ipn.ss.ss_family = AF_INET6;
758     ipn.ss_port = 0;
759     comm_connect_tcp(&client_p->localClient->fd,
760     conf->host, conf->port,
761 michael 2345 (struct sockaddr *)&ipn, ipn.ss_len,
762 michael 2182 serv_connect_callback, client_p,
763     conf->aftype, CONNECTTIMEOUT);
764     }
765     else if (ServerInfo.specific_ipv6_vhost)
766     {
767     memcpy(&ipn, &ServerInfo.ip6, sizeof(struct irc_ssaddr));
768     ipn.ss.ss_family = AF_INET6;
769     ipn.ss_port = 0;
770     comm_connect_tcp(&client_p->localClient->fd,
771     conf->host, conf->port,
772     (struct sockaddr *)&ipn, ipn.ss_len,
773     serv_connect_callback, client_p,
774     conf->aftype, CONNECTTIMEOUT);
775     }
776     else
777     comm_connect_tcp(&client_p->localClient->fd,
778 michael 2345 conf->host, conf->port,
779 michael 2182 NULL, 0, serv_connect_callback, client_p,
780     conf->aftype, CONNECTTIMEOUT);
781 adx 30 }
782     #endif
783     }
784 michael 2182 return 1;
785 adx 30 }
786    
787 michael 1303 #ifdef HAVE_LIBCRYPTO
788     static void
789     finish_ssl_server_handshake(struct Client *client_p)
790     {
791 michael 1632 struct MaskItem *conf = NULL;
792 michael 1303
793     conf = find_conf_name(&client_p->localClient->confs,
794 michael 1632 client_p->name, CONF_SERVER);
795 michael 1303 if (conf == NULL)
796     {
797 michael 1618 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
798 michael 1303 "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
799 michael 1618 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
800 michael 1303 "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
801    
802 michael 3171 exit_client(client_p, "Lost connect{} block");
803 michael 1303 return;
804     }
805    
806 michael 2134 sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
807 michael 1303
808 michael 1632 send_capabilities(client_p, 0);
809 michael 1303
810     sendto_one(client_p, "SERVER %s 1 :%s%s",
811     me.name, ConfigServerHide.hidden ? "(H) " : "",
812     me.info);
813    
814     /* If we've been marked dead because a send failed, just exit
815     * here now and save everyone the trouble of us ever existing.
816     */
817     if (IsDead(client_p))
818     {
819 michael 1618 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
820 michael 1303 "%s[%s] went dead during handshake",
821     client_p->name,
822     client_p->host);
823 michael 1618 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
824 michael 1303 "%s went dead during handshake", client_p->name);
825     return;
826     }
827    
828     /* don't move to serv_list yet -- we haven't sent a burst! */
829     /* If we get here, we're ok, so lets start reading some data */
830     comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ, read_packet, client_p, 0);
831     }
832    
833     static void
834 michael 1306 ssl_server_handshake(fde_t *fd, struct Client *client_p)
835 michael 1303 {
836 michael 2463 X509 *cert = NULL;
837     int ret = 0;
838 michael 1303
839 michael 2463 if ((ret = SSL_connect(client_p->localClient->fd.ssl)) <= 0)
840 michael 1303 {
841 michael 2463 switch (SSL_get_error(client_p->localClient->fd.ssl, ret))
842 michael 1303 {
843     case SSL_ERROR_WANT_WRITE:
844     comm_setselect(&client_p->localClient->fd, COMM_SELECT_WRITE,
845 michael 1308 (PF *)ssl_server_handshake, client_p, 0);
846 michael 1303 return;
847     case SSL_ERROR_WANT_READ:
848     comm_setselect(&client_p->localClient->fd, COMM_SELECT_READ,
849 michael 1308 (PF *)ssl_server_handshake, client_p, 0);
850 michael 1303 return;
851     default:
852 michael 1308 {
853     const char *sslerr = ERR_error_string(ERR_get_error(), NULL);
854 michael 1618 sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE,
855 michael 1308 "Error connecting to %s: %s", client_p->name,
856     sslerr ? sslerr : "unknown SSL error");
857 michael 3171 exit_client(client_p, "Error during SSL handshake");
858 michael 1303 return;
859 michael 1308 }
860 michael 1303 }
861     }
862    
863 michael 2463 if ((cert = SSL_get_peer_certificate(client_p->localClient->fd.ssl)))
864     {
865     int res = SSL_get_verify_result(client_p->localClient->fd.ssl);
866 michael 3375 char buf[EVP_MAX_MD_SIZE * 2 + 1] = "";
867     unsigned char md[EVP_MAX_MD_SIZE] = "";
868 michael 2463
869     if (res == X509_V_OK || res == X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN ||
870     res == X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE ||
871     res == X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT)
872     {
873 michael 3375 unsigned int n = 0;
874 michael 2463
875     if (X509_digest(cert, EVP_sha256(), md, &n))
876     {
877 michael 4113 binary_to_hex(md, buf, n);
878 michael 2463 client_p->certfp = xstrdup(buf);
879     }
880     }
881     else
882     ilog(LOG_TYPE_IRCD, "Server %s!%s@%s gave bad SSL client certificate: %d",
883     client_p->name, client_p->username, client_p->host, res);
884     X509_free(cert);
885     }
886    
887 michael 1303 finish_ssl_server_handshake(client_p);
888     }
889    
890     static void
891 michael 1632 ssl_connect_init(struct Client *client_p, struct MaskItem *conf, fde_t *fd)
892 michael 1303 {
893     if ((client_p->localClient->fd.ssl = SSL_new(ServerInfo.client_ctx)) == NULL)
894     {
895     ilog(LOG_TYPE_IRCD, "SSL_new() ERROR! -- %s",
896     ERR_error_string(ERR_get_error(), NULL));
897     SetDead(client_p);
898 michael 3171 exit_client(client_p, "SSL_new failed");
899 michael 1303 return;
900     }
901    
902     SSL_set_fd(fd->ssl, fd->fd);
903 michael 1306
904 michael 1632 if (!EmptyString(conf->cipher_list))
905     SSL_set_cipher_list(client_p->localClient->fd.ssl, conf->cipher_list);
906 michael 1306
907     ssl_server_handshake(NULL, client_p);
908 michael 1303 }
909     #endif
910    
911 adx 30 /* serv_connect_callback() - complete a server connection.
912 michael 2345 *
913 adx 30 * This routine is called after the server connection attempt has
914     * completed. If unsucessful, an error is sent to ops and the client
915     * is closed. If sucessful, it goes through the initialisation/check
916     * procedures, the capabilities are sent, and the socket is then
917     * marked for reading.
918     */
919     static void
920     serv_connect_callback(fde_t *fd, int status, void *data)
921     {
922     struct Client *client_p = data;
923 michael 1632 struct MaskItem *conf = NULL;
924 adx 30
925     /* First, make sure its a real client! */
926 michael 3246 assert(client_p);
927 adx 30 assert(&client_p->localClient->fd == fd);
928    
929     /* Next, for backward purposes, record the ip of the server */
930     memcpy(&client_p->localClient->ip, &fd->connect.hostaddr,
931     sizeof(struct irc_ssaddr));
932 michael 3246
933 adx 30 /* Check the status */
934     if (status != COMM_OK)
935     {
936     /* We have an error, so report it and quit
937     * Admins get to see any IP, mere opers don't *sigh*
938     */
939     if (ConfigServerHide.hide_server_ips)
940 michael 1618 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
941 adx 30 "Error connecting to %s: %s",
942     client_p->name, comm_errstr(status));
943     else
944 michael 1618 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
945 michael 2134 "Error connecting to %s[%s]: %s", client_p->name,
946     client_p->host, comm_errstr(status));
947 adx 30
948 michael 1618 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
949 michael 2134 "Error connecting to %s: %s",
950     client_p->name, comm_errstr(status));
951 adx 30
952     /* If a fd goes bad, call dead_link() the socket is no
953     * longer valid for reading or writing.
954     */
955     dead_link_on_write(client_p, 0);
956     return;
957     }
958    
959     /* COMM_OK, so continue the connection procedure */
960     /* Get the C/N lines */
961     conf = find_conf_name(&client_p->localClient->confs,
962 michael 2134 client_p->name, CONF_SERVER);
963 adx 30 if (conf == NULL)
964     {
965 michael 1618 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
966 michael 2134 "Lost connect{} block for %s", get_client_name(client_p, HIDE_IP));
967 michael 1618 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
968 michael 2134 "Lost connect{} block for %s", get_client_name(client_p, MASK_IP));
969 adx 30
970 michael 3171 exit_client(client_p, "Lost connect{} block");
971 adx 30 return;
972     }
973    
974     /* Next, send the initial handshake */
975     SetHandshake(client_p);
976    
977     #ifdef HAVE_LIBCRYPTO
978 michael 1632 if (IsConfSSL(conf))
979 michael 1303 {
980 michael 1632 ssl_connect_init(client_p, conf, fd);
981 michael 1303 return;
982     }
983 adx 30 #endif
984    
985 michael 2134 sendto_one(client_p, "PASS %s TS %d %s", conf->spasswd, TS_CURRENT, me.id);
986 adx 30
987 michael 1632 send_capabilities(client_p, 0);
988 adx 30
989 michael 2134 sendto_one(client_p, "SERVER %s 1 :%s%s", me.name,
990     ConfigServerHide.hidden ? "(H) " : "", me.info);
991 adx 30
992     /* If we've been marked dead because a send failed, just exit
993     * here now and save everyone the trouble of us ever existing.
994     */
995 michael 2345 if (IsDead(client_p))
996 adx 30 {
997 michael 1618 sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE,
998 michael 2134 "%s[%s] went dead during handshake",
999 adx 30 client_p->name,
1000 michael 2134 client_p->host);
1001 michael 1618 sendto_realops_flags(UMODE_ALL, L_OPER, SEND_NOTICE,
1002 michael 2134 "%s went dead during handshake", client_p->name);
1003 adx 30 return;
1004     }
1005    
1006     /* don't move to serv_list yet -- we haven't sent a burst! */
1007     /* If we get here, we're ok, so lets start reading some data */
1008     comm_setselect(fd, COMM_SELECT_READ, read_packet, client_p, 0);
1009     }
1010    
1011     struct Client *
1012     find_servconn_in_progress(const char *name)
1013     {
1014     dlink_node *ptr;
1015     struct Client *cptr;
1016    
1017     DLINK_FOREACH(ptr, unknown_list.head)
1018     {
1019     cptr = ptr->data;
1020    
1021     if (cptr && cptr->name[0])
1022 michael 1652 if (!match(name, cptr->name))
1023 adx 30 return cptr;
1024     }
1025 michael 2345
1026 adx 30 return NULL;
1027     }

Properties

Name Value
svn:eol-style native
svn:keywords Id Revision