1 |
|
/* |
2 |
< |
* ircd-hybrid: an advanced Internet Relay Chat Daemon(ircd). |
3 |
< |
* s_serv.c: Server related functions. |
2 |
> |
* ircd-hybrid: an advanced, lightweight Internet Relay Chat Daemon (ircd) |
3 |
|
* |
4 |
< |
* Copyright (C) 2005 by the past and present ircd coders, and others. |
4 |
> |
* Copyright (c) 1997-2014 ircd-hybrid development team |
5 |
|
* |
6 |
|
* This program is free software; you can redistribute it and/or modify |
7 |
|
* it under the terms of the GNU General Public License as published by |
17 |
|
* along with this program; if not, write to the Free Software |
18 |
|
* Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 |
19 |
|
* USA |
20 |
< |
* |
21 |
< |
* $Id$ |
20 |
> |
*/ |
21 |
> |
|
22 |
> |
/*! \file s_serv.c |
23 |
> |
* \brief Server related functions. |
24 |
> |
* \version $Id$ |
25 |
|
*/ |
26 |
|
|
27 |
|
#include "stdinc.h" |
33 |
|
#include "channel.h" |
34 |
|
#include "channel_mode.h" |
35 |
|
#include "client.h" |
34 |
– |
#include "dbuf.h" |
36 |
|
#include "event.h" |
37 |
|
#include "fdlist.h" |
38 |
|
#include "hash.h" |
50 |
|
#include "s_user.h" |
51 |
|
#include "send.h" |
52 |
|
#include "memory.h" |
53 |
< |
#include "channel.h" /* chcap_usage_counts stuff...*/ |
53 |
> |
#include "channel.h" |
54 |
|
#include "parse.h" |
55 |
|
|
56 |
|
#define MIN_CONN_FREQ 300 |
206 |
|
{ |
207 |
|
if (!(target_p = hash_find_server(parv[server]))) |
208 |
|
{ |
209 |
< |
sendto_one(source_p, form_str(ERR_NOSUCHSERVER), |
209 |
< |
me.name, source_p->name, parv[server]); |
209 |
> |
sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]); |
210 |
|
return HUNTED_NOSUCH; |
211 |
|
} |
212 |
|
} |
233 |
|
{ |
234 |
|
if(!IsRegistered(target_p)) |
235 |
|
{ |
236 |
< |
sendto_one(source_p, form_str(ERR_NOSUCHSERVER), |
237 |
< |
me.name, source_p->name, parv[server]); |
236 |
> |
sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]); |
237 |
|
return HUNTED_NOSUCH; |
238 |
|
} |
239 |
|
|
244 |
|
parv[server] = target_p->name; |
245 |
|
|
246 |
|
/* This is a little kludgy but should work... */ |
247 |
< |
if (IsClient(source_p) && |
249 |
< |
((MyConnect(target_p) && IsCapable(target_p, CAP_TS6)) || |
250 |
< |
(!MyConnect(target_p) && IsCapable(target_p->from, CAP_TS6)))) |
251 |
< |
parv[0] = ID(source_p); |
252 |
< |
|
253 |
< |
sendto_one(target_p, command, parv[0], |
247 |
> |
sendto_one(target_p, command, ID_or_name(source_p, target_p), |
248 |
|
parv[1], parv[2], parv[3], parv[4], |
249 |
|
parv[5], parv[6], parv[7], parv[8]); |
250 |
|
return HUNTED_PASS; |
251 |
< |
} |
251 |
> |
} |
252 |
|
|
253 |
< |
sendto_one(source_p, form_str(ERR_NOSUCHSERVER), |
260 |
< |
me.name, source_p->name, parv[server]); |
253 |
> |
sendto_one_numeric(source_p, &me, ERR_NOSUCHSERVER, parv[server]); |
254 |
|
return HUNTED_NOSUCH; |
255 |
|
} |
256 |
|
|
281 |
|
|
282 |
|
assert(conf->type == CONF_SERVER); |
283 |
|
|
284 |
< |
/* Also when already connecting! (update holdtimes) --SRB |
284 |
> |
/* Also when already connecting! (update holdtimes) --SRB |
285 |
|
*/ |
286 |
|
if (!conf->port ||!IsConfAllowAutoConn(conf)) |
287 |
|
continue; |
392 |
|
|
393 |
|
/* XXX: Fix me for IPv6 */ |
394 |
|
/* XXX sockhost is the IPv4 ip as a string */ |
395 |
< |
if (!match(conf->host, client_p->host) || |
395 |
> |
if (!match(conf->host, client_p->host) || |
396 |
|
!match(conf->host, client_p->sockhost)) |
397 |
|
{ |
398 |
|
error = -2; |
400 |
|
if (!match_conf_password(client_p->localClient->passwd, conf)) |
401 |
|
return -2; |
402 |
|
|
403 |
+ |
if (!EmptyString(conf->certfp)) |
404 |
+ |
if (EmptyString(client_p->certfp) || strcasecmp(client_p->certfp, conf->certfp)) |
405 |
+ |
return -4; |
406 |
+ |
|
407 |
|
server_conf = conf; |
408 |
|
} |
409 |
|
} |
423 |
|
switch (server_conf->aftype) |
424 |
|
{ |
425 |
|
#ifdef IPV6 |
426 |
< |
case AF_INET6: |
426 |
> |
case AF_INET6: |
427 |
|
v6 = (struct sockaddr_in6 *)&server_conf->addr; |
428 |
|
|
429 |
|
if (IN6_IS_ADDR_UNSPECIFIED(&v6->sin6_addr)) |
434 |
|
v4 = (struct sockaddr_in *)&server_conf->addr; |
435 |
|
|
436 |
|
if (v4->sin_addr.s_addr == INADDR_NONE) |
437 |
< |
memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr)); |
437 |
> |
memcpy(&server_conf->addr, &client_p->localClient->ip, sizeof(struct irc_ssaddr)); |
438 |
|
break; |
439 |
|
} |
440 |
|
} |
554 |
|
} |
555 |
|
|
556 |
|
/* sendnick_TS() |
557 |
< |
* |
557 |
> |
* |
558 |
|
* inputs - client (server) to send nick towards |
559 |
|
* - client to send nick for |
560 |
|
* output - NONE |
563 |
|
void |
564 |
|
sendnick_TS(struct Client *client_p, struct Client *target_p) |
565 |
|
{ |
566 |
< |
static char ubuf[12]; |
566 |
> |
char ubuf[IRCD_BUFSIZE]; |
567 |
|
|
568 |
|
if (!IsClient(target_p)) |
569 |
|
return; |
577 |
|
} |
578 |
|
|
579 |
|
if (IsCapable(client_p, CAP_SVS)) |
580 |
< |
{ |
581 |
< |
if (HasID(target_p) && IsCapable(client_p, CAP_TS6)) |
582 |
< |
sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s %s :%s", |
583 |
< |
target_p->servptr->id, |
584 |
< |
target_p->name, target_p->hopcount + 1, |
585 |
< |
(unsigned long) target_p->tsinfo, |
586 |
< |
ubuf, target_p->username, target_p->host, |
587 |
< |
(MyClient(target_p) && IsIPSpoof(target_p)) ? |
591 |
< |
"0" : target_p->sockhost, target_p->id, |
592 |
< |
target_p->svid, target_p->info); |
593 |
< |
else |
594 |
< |
sendto_one(client_p, "NICK %s %d %lu %s %s %s %s %s :%s", |
595 |
< |
target_p->name, target_p->hopcount + 1, |
596 |
< |
(unsigned long) target_p->tsinfo, |
597 |
< |
ubuf, target_p->username, target_p->host, |
598 |
< |
target_p->servptr->name, target_p->svid, |
599 |
< |
target_p->info); |
600 |
< |
} |
580 |
> |
sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s %s :%s", |
581 |
> |
target_p->servptr->id, |
582 |
> |
target_p->name, target_p->hopcount + 1, |
583 |
> |
(unsigned long) target_p->tsinfo, |
584 |
> |
ubuf, target_p->username, target_p->host, |
585 |
> |
(MyClient(target_p) && IsIPSpoof(target_p)) ? |
586 |
> |
"0" : target_p->sockhost, target_p->id, |
587 |
> |
target_p->svid, target_p->info); |
588 |
|
else |
589 |
< |
{ |
590 |
< |
if (HasID(target_p) && IsCapable(client_p, CAP_TS6)) |
591 |
< |
sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s :%s", |
592 |
< |
target_p->servptr->id, |
593 |
< |
target_p->name, target_p->hopcount + 1, |
594 |
< |
(unsigned long) target_p->tsinfo, |
595 |
< |
ubuf, target_p->username, target_p->host, |
596 |
< |
(MyClient(target_p) && IsIPSpoof(target_p)) ? |
597 |
< |
"0" : target_p->sockhost, target_p->id, target_p->info); |
598 |
< |
else |
599 |
< |
sendto_one(client_p, "NICK %s %d %lu %s %s %s %s :%s", |
613 |
< |
target_p->name, target_p->hopcount + 1, |
614 |
< |
(unsigned long) target_p->tsinfo, |
615 |
< |
ubuf, target_p->username, target_p->host, |
616 |
< |
target_p->servptr->name, target_p->info); |
617 |
< |
} |
589 |
> |
sendto_one(client_p, ":%s UID %s %d %lu %s %s %s %s %s :%s", |
590 |
> |
target_p->servptr->id, |
591 |
> |
target_p->name, target_p->hopcount + 1, |
592 |
> |
(unsigned long) target_p->tsinfo, |
593 |
> |
ubuf, target_p->username, target_p->host, |
594 |
> |
(MyClient(target_p) && IsIPSpoof(target_p)) ? |
595 |
> |
"0" : target_p->sockhost, target_p->id, target_p->info); |
596 |
> |
|
597 |
> |
if (!EmptyString(target_p->certfp)) |
598 |
> |
sendto_one(client_p, ":%s CERTFP %s", |
599 |
> |
ID_or_name(target_p, client_p), target_p->certfp); |
600 |
|
|
601 |
|
if (target_p->away[0]) |
602 |
|
sendto_one(client_p, ":%s AWAY :%s", ID_or_name(target_p, client_p), |
612 |
|
* side effects - build up string representing capabilities of server listed |
613 |
|
*/ |
614 |
|
const char * |
615 |
< |
show_capabilities(struct Client *target_p) |
615 |
> |
show_capabilities(const struct Client *target_p) |
616 |
|
{ |
617 |
< |
static char msgbuf[IRCD_BUFSIZE]; |
618 |
< |
char *t = msgbuf; |
637 |
< |
dlink_node *ptr; |
617 |
> |
static char msgbuf[IRCD_BUFSIZE] = ""; |
618 |
> |
const dlink_node *ptr = NULL; |
619 |
|
|
620 |
< |
t += sprintf(msgbuf, "TS "); |
620 |
> |
strlcpy(msgbuf, "TS", sizeof(msgbuf)); |
621 |
|
|
622 |
|
DLINK_FOREACH(ptr, cap_list.head) |
623 |
|
{ |
624 |
|
const struct Capability *cap = ptr->data; |
625 |
|
|
626 |
< |
if (IsCapable(target_p, cap->cap)) |
627 |
< |
t += sprintf(t, "%s ", cap->name); |
626 |
> |
if (!IsCapable(target_p, cap->cap)) |
627 |
> |
continue; |
628 |
> |
|
629 |
> |
strlcat(msgbuf, " ", sizeof(msgbuf)); |
630 |
> |
strlcat(msgbuf, cap->name, sizeof(msgbuf)); |
631 |
|
} |
632 |
|
|
649 |
– |
*(t - 1) = '\0'; |
633 |
|
return msgbuf; |
634 |
|
} |
635 |
|
|
695 |
|
/* If there is something in the serv_list, it might be this |
696 |
|
* connecting server.. |
697 |
|
*/ |
698 |
< |
if (!ServerInfo.hub && serv_list.head) |
698 |
> |
if (!ServerInfo.hub && serv_list.head) |
699 |
|
{ |
700 |
|
if (client_p != serv_list.head->data || serv_list.head->next) |
701 |
|
{ |
719 |
|
sendto_one(client_p, "SVINFO %d %d 0 :%lu", TS_CURRENT, TS_MIN, |
720 |
|
(unsigned long)CurrentTime); |
721 |
|
|
722 |
< |
/* assumption here is if they passed the correct TS version, they also passed an SID */ |
740 |
< |
if (IsCapable(client_p, CAP_TS6)) |
722 |
> |
if (HasID(client_p)) |
723 |
|
hash_add_id(client_p); |
724 |
|
|
725 |
|
/* XXX Does this ever happen? I don't think so -db */ |
810 |
|
|
811 |
|
fd_note(&client_p->localClient->fd, "Server: %s", client_p->name); |
812 |
|
|
813 |
< |
/* Old sendto_serv_but_one() call removed because we now |
814 |
< |
** need to send different names to different servers |
815 |
< |
** (domain name matching) Send new server to other servers. |
834 |
< |
*/ |
835 |
< |
DLINK_FOREACH(ptr, serv_list.head) |
836 |
< |
{ |
837 |
< |
target_p = ptr->data; |
838 |
< |
|
839 |
< |
if (target_p == client_p) |
840 |
< |
continue; |
813 |
> |
sendto_server(client_p, NOCAPS, NOCAPS, ":%s SID %s 2 %s :%s%s", |
814 |
> |
me.id, client_p->name, client_p->id, |
815 |
> |
IsHidden(client_p) ? "(H) " : "", client_p->info); |
816 |
|
|
817 |
< |
if (IsCapable(target_p, CAP_TS6) && HasID(client_p)) |
818 |
< |
sendto_one(target_p, ":%s SID %s 2 %s :%s%s", |
819 |
< |
me.id, client_p->name, client_p->id, |
820 |
< |
IsHidden(client_p) ? "(H) " : "", |
821 |
< |
client_p->info); |
822 |
< |
else |
823 |
< |
sendto_one(target_p,":%s SERVER %s 2 :%s%s", |
824 |
< |
me.name, client_p->name, |
825 |
< |
IsHidden(client_p) ? "(H) " : "", |
826 |
< |
client_p->info); |
827 |
< |
} |
828 |
< |
|
829 |
< |
/* Pass on my client information to the new server |
830 |
< |
** |
831 |
< |
** First, pass only servers (idea is that if the link gets |
832 |
< |
** cancelled beacause the server was already there, |
833 |
< |
** there are no NICK's to be cancelled...). Of course, |
834 |
< |
** if cancellation occurs, all this info is sent anyway, |
860 |
< |
** and I guess the link dies when a read is attempted...? --msa |
861 |
< |
** |
862 |
< |
** Note: Link cancellation to occur at this point means |
863 |
< |
** that at least two servers from my fragment are building |
864 |
< |
** up connection this other fragment at the same time, it's |
865 |
< |
** a race condition, not the normal way of operation... |
866 |
< |
** |
867 |
< |
** ALSO NOTE: using the get_client_name for server names-- |
868 |
< |
** see previous *WARNING*!!! (Also, original inpath |
869 |
< |
** is destroyed...) |
870 |
< |
*/ |
817 |
> |
/* |
818 |
> |
* Pass on my client information to the new server |
819 |
> |
* |
820 |
> |
* First, pass only servers (idea is that if the link gets |
821 |
> |
* cancelled beacause the server was already there, |
822 |
> |
* there are no NICK's to be cancelled...). Of course, |
823 |
> |
* if cancellation occurs, all this info is sent anyway, |
824 |
> |
* and I guess the link dies when a read is attempted...? --msa |
825 |
> |
* |
826 |
> |
* Note: Link cancellation to occur at this point means |
827 |
> |
* that at least two servers from my fragment are building |
828 |
> |
* up connection this other fragment at the same time, it's |
829 |
> |
* a race condition, not the normal way of operation... |
830 |
> |
* |
831 |
> |
* ALSO NOTE: using the get_client_name for server names-- |
832 |
> |
* see previous *WARNING*!!! (Also, original inpath |
833 |
> |
* is destroyed...) |
834 |
> |
*/ |
835 |
|
|
836 |
|
DLINK_FOREACH_PREV(ptr, global_serv_list.tail) |
837 |
|
{ |
841 |
|
if (IsMe(target_p) || target_p->from == client_p) |
842 |
|
continue; |
843 |
|
|
844 |
< |
if (IsCapable(client_p, CAP_TS6)) |
845 |
< |
{ |
846 |
< |
if (HasID(target_p)) |
847 |
< |
sendto_one(client_p, ":%s SID %s %d %s :%s%s", |
884 |
< |
ID(target_p->servptr), target_p->name, target_p->hopcount+1, |
885 |
< |
target_p->id, IsHidden(target_p) ? "(H) " : "", |
886 |
< |
target_p->info); |
887 |
< |
else /* introducing non-ts6 server */ |
888 |
< |
sendto_one(client_p, ":%s SERVER %s %d :%s%s", |
889 |
< |
ID(target_p->servptr), target_p->name, target_p->hopcount+1, |
890 |
< |
IsHidden(target_p) ? "(H) " : "", target_p->info); |
891 |
< |
} |
892 |
< |
else |
893 |
< |
sendto_one(client_p, ":%s SERVER %s %d :%s%s", |
894 |
< |
target_p->servptr->name, target_p->name, target_p->hopcount+1, |
895 |
< |
IsHidden(target_p) ? "(H) " : "", target_p->info); |
844 |
> |
sendto_one(client_p, ":%s SID %s %d %s :%s%s", |
845 |
> |
ID(target_p->servptr), target_p->name, target_p->hopcount+1, |
846 |
> |
target_p->id, IsHidden(target_p) ? "(H) " : "", |
847 |
> |
target_p->info); |
848 |
|
|
849 |
|
if (HasFlag(target_p, FLAGS_EOB)) |
850 |
< |
sendto_one(client_p, ":%s EOB", ID_or_name(client_p, target_p)); |
850 |
> |
sendto_one(client_p, ":%s EOB", ID_or_name(target_p, client_p)); |
851 |
|
} |
852 |
|
|
853 |
|
server_burst(client_p); |
883 |
|
|
884 |
|
/* burst_all() |
885 |
|
* |
886 |
< |
* inputs - pointer to server to send burst to |
886 |
> |
* inputs - pointer to server to send burst to |
887 |
|
* output - NONE |
888 |
|
* side effects - complete burst of channels/nicks is sent to client_p |
889 |
|
*/ |
914 |
|
|
915 |
|
if (!HasFlag(target_p, FLAGS_BURSTED) && target_p->from != client_p) |
916 |
|
sendnick_TS(client_p, target_p); |
917 |
< |
|
917 |
> |
|
918 |
|
DelFlag(target_p, FLAGS_BURSTED); |
919 |
|
} |
920 |
|
|
992 |
|
|
993 |
|
/* serv_connect() - initiate a server connection |
994 |
|
* |
995 |
< |
* inputs - pointer to conf |
995 |
> |
* inputs - pointer to conf |
996 |
|
* - pointer to client doing the connect |
997 |
|
* output - |
998 |
|
* side effects - |
1044 |
|
* Note: conf should ALWAYS be a valid C: line |
1045 |
|
*/ |
1046 |
|
if ((client_p = hash_find_server(conf->name)) != NULL) |
1047 |
< |
{ |
1047 |
> |
{ |
1048 |
|
sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE, |
1049 |
|
"Server %s already present from %s", |
1050 |
|
conf->name, get_client_name(client_p, SHOW_IP)); |
1052 |
|
"Server %s already present from %s", |
1053 |
|
conf->name, get_client_name(client_p, MASK_IP)); |
1054 |
|
if (by && IsClient(by) && !MyClient(by)) |
1055 |
< |
sendto_one(by, ":%s NOTICE %s :Server %s already present from %s", |
1056 |
< |
me.name, by->name, conf->name, |
1105 |
< |
get_client_name(client_p, MASK_IP)); |
1055 |
> |
sendto_one_notice(by, &me, ":Server %s already present from %s", |
1056 |
> |
conf->name, get_client_name(client_p, MASK_IP)); |
1057 |
|
return 0; |
1058 |
|
} |
1059 |
< |
|
1059 |
> |
|
1060 |
|
/* Create a local client */ |
1061 |
|
client_p = make_client(NULL); |
1062 |
|
|
1067 |
|
/* We already converted the ip once, so lets use it - stu */ |
1068 |
|
strlcpy(client_p->sockhost, buf, sizeof(client_p->sockhost)); |
1069 |
|
|
1070 |
< |
/* create a socket for the server connection */ |
1070 |
> |
/* create a socket for the server connection */ |
1071 |
|
if (comm_open(&client_p->localClient->fd, conf->addr.ss.ss_family, |
1072 |
|
SOCK_STREAM, 0, NULL) < 0) |
1073 |
|
{ |
1090 |
|
sendto_realops_flags(UMODE_ALL, L_ALL, SEND_NOTICE, |
1091 |
|
"Host %s is not enabled for connecting: no connect{} block", |
1092 |
|
conf->name); |
1093 |
< |
if (by && IsClient(by) && !MyClient(by)) |
1094 |
< |
sendto_one(by, ":%s NOTICE %s :Connect to host %s failed.", |
1095 |
< |
me.name, by->name, client_p->name); |
1093 |
> |
if (by && IsClient(by) && !MyClient(by)) |
1094 |
> |
sendto_one_notice(by, &me, ":Connect to host %s failed.", client_p->name); |
1095 |
> |
|
1096 |
|
SetDead(client_p); |
1097 |
|
exit_client(client_p, client_p, "Connection failed"); |
1098 |
|
return 0; |
1117 |
|
client_p->localClient->aftype = conf->aftype; |
1118 |
|
|
1119 |
|
/* Now, initiate the connection */ |
1120 |
< |
/* XXX assume that a non 0 type means a specific bind address |
1120 |
> |
/* XXX assume that a non 0 type means a specific bind address |
1121 |
|
* for this connect. |
1122 |
|
*/ |
1123 |
|
switch (conf->aftype) |
1132 |
|
ipn.ss_port = 0; |
1133 |
|
memcpy(&ipn, &conf->bind, sizeof(struct irc_ssaddr)); |
1134 |
|
comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port, |
1135 |
< |
(struct sockaddr *)&ipn, ipn.ss_len, |
1135 |
> |
(struct sockaddr *)&ipn, ipn.ss_len, |
1136 |
|
serv_connect_callback, client_p, conf->aftype, |
1137 |
|
CONNECTTIMEOUT); |
1138 |
|
} |
1149 |
|
CONNECTTIMEOUT); |
1150 |
|
} |
1151 |
|
else |
1152 |
< |
comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port, |
1153 |
< |
NULL, 0, serv_connect_callback, client_p, conf->aftype, |
1152 |
> |
comm_connect_tcp(&client_p->localClient->fd, conf->host, conf->port, |
1153 |
> |
NULL, 0, serv_connect_callback, client_p, conf->aftype, |
1154 |
|
CONNECTTIMEOUT); |
1155 |
|
break; |
1156 |
|
#ifdef IPV6 |
1171 |
|
ipn.ss_port = 0; |
1172 |
|
comm_connect_tcp(&client_p->localClient->fd, |
1173 |
|
conf->host, conf->port, |
1174 |
< |
(struct sockaddr *)&ipn, ipn.ss_len, |
1174 |
> |
(struct sockaddr *)&ipn, ipn.ss_len, |
1175 |
|
serv_connect_callback, client_p, |
1176 |
|
conf->aftype, CONNECTTIMEOUT); |
1177 |
|
} |
1188 |
|
} |
1189 |
|
else |
1190 |
|
comm_connect_tcp(&client_p->localClient->fd, |
1191 |
< |
conf->host, conf->port, |
1191 |
> |
conf->host, conf->port, |
1192 |
|
NULL, 0, serv_connect_callback, client_p, |
1193 |
|
conf->aftype, CONNECTTIMEOUT); |
1194 |
|
} |
1246 |
|
static void |
1247 |
|
ssl_server_handshake(fde_t *fd, struct Client *client_p) |
1248 |
|
{ |
1249 |
< |
int ret; |
1250 |
< |
int err; |
1300 |
< |
|
1301 |
< |
ret = SSL_connect(client_p->localClient->fd.ssl); |
1249 |
> |
X509 *cert = NULL; |
1250 |
> |
int ret = 0; |
1251 |
|
|
1252 |
< |
if (ret <= 0) |
1252 |
> |
if ((ret = SSL_connect(client_p->localClient->fd.ssl)) <= 0) |
1253 |
|
{ |
1254 |
< |
switch ((err = SSL_get_error(client_p->localClient->fd.ssl, ret))) |
1254 |
> |
switch (SSL_get_error(client_p->localClient->fd.ssl, ret)) |
1255 |
|
{ |
1256 |
|
case SSL_ERROR_WANT_WRITE: |
1257 |
|
comm_setselect(&client_p->localClient->fd, COMM_SELECT_WRITE, |
1273 |
|
} |
1274 |
|
} |
1275 |
|
|
1276 |
+ |
if ((cert = SSL_get_peer_certificate(client_p->localClient->fd.ssl))) |
1277 |
+ |
{ |
1278 |
+ |
int res = SSL_get_verify_result(client_p->localClient->fd.ssl); |
1279 |
+ |
char buf[EVP_MAX_MD_SIZE * 2 + 1] = { '\0' }; |
1280 |
+ |
unsigned char md[EVP_MAX_MD_SIZE] = { '\0' }; |
1281 |
+ |
|
1282 |
+ |
if (res == X509_V_OK || res == X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN || |
1283 |
+ |
res == X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE || |
1284 |
+ |
res == X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT) |
1285 |
+ |
{ |
1286 |
+ |
unsigned int i = 0, n = 0; |
1287 |
+ |
|
1288 |
+ |
if (X509_digest(cert, EVP_sha256(), md, &n)) |
1289 |
+ |
{ |
1290 |
+ |
for (; i < n; ++i) |
1291 |
+ |
snprintf(buf + 2 * i, 3, "%02X", md[i]); |
1292 |
+ |
client_p->certfp = xstrdup(buf); |
1293 |
+ |
} |
1294 |
+ |
} |
1295 |
+ |
else |
1296 |
+ |
ilog(LOG_TYPE_IRCD, "Server %s!%s@%s gave bad SSL client certificate: %d", |
1297 |
+ |
client_p->name, client_p->username, client_p->host, res); |
1298 |
+ |
X509_free(cert); |
1299 |
+ |
} |
1300 |
+ |
|
1301 |
|
finish_ssl_server_handshake(client_p); |
1302 |
|
} |
1303 |
|
|
1323 |
|
#endif |
1324 |
|
|
1325 |
|
/* serv_connect_callback() - complete a server connection. |
1326 |
< |
* |
1326 |
> |
* |
1327 |
|
* This routine is called after the server connection attempt has |
1328 |
|
* completed. If unsucessful, an error is sent to ops and the client |
1329 |
|
* is closed. If sucessful, it goes through the initialisation/check |
1405 |
|
/* If we've been marked dead because a send failed, just exit |
1406 |
|
* here now and save everyone the trouble of us ever existing. |
1407 |
|
*/ |
1408 |
< |
if (IsDead(client_p)) |
1408 |
> |
if (IsDead(client_p)) |
1409 |
|
{ |
1410 |
|
sendto_realops_flags(UMODE_ALL, L_ADMIN, SEND_NOTICE, |
1411 |
|
"%s[%s] went dead during handshake", |
1435 |
|
if (!match(name, cptr->name)) |
1436 |
|
return cptr; |
1437 |
|
} |
1438 |
< |
|
1438 |
> |
|
1439 |
|
return NULL; |
1440 |
|
} |