]> git.netwichtig.de Git - user/henk/code/inspircd.git/blobdiff - src/modules/m_spanningtree/utils.cpp
Improve SSL fingerprint on link message
[user/henk/code/inspircd.git] / src / modules / m_spanningtree / utils.cpp
index 10a8888334ff0eae1076a652877bb7a97c4aa924..ab057570a3a2f32655d3a25fd60882e556d0c48b 100644 (file)
@@ -2,7 +2,7 @@
  *       | Inspire Internet Relay Chat Daemon |
  *       +------------------------------------+
  *
- *  InspIRCd: (C) 2002-2009 InspIRCd Development Team
+ *  InspIRCd: (C) 2002-2010 InspIRCd Development Team
  * See: http://wiki.inspircd.org/Credits
  *
  * This program is free but copyrighted software; see
 #include "resolvers.h"
 
 /* Create server sockets off a listener. */
-void ServerSocketListener::OnAcceptReady(int newsock)
+ModResult ModuleSpanningTree::OnAcceptConnection(int newsock, ListenSocket* from, irc::sockets::sockaddrs* client, irc::sockets::sockaddrs* server)
 {
-       bool found = false;
-       int port;
-       std::string incomingip;
-       irc::sockets::satoap(&client, incomingip, port);
+       if (from->bind_tag->getString("type") != "servers")
+               return MOD_RES_PASSTHRU;
 
-       found = (std::find(Utils->ValidIPs.begin(), Utils->ValidIPs.end(), incomingip) != Utils->ValidIPs.end());
-       if (!found)
-       {
-               for (std::vector<std::string>::iterator i = Utils->ValidIPs.begin(); i != Utils->ValidIPs.end(); i++)
-               {
-                       if (*i == "*" || irc::sockets::MatchCIDR(incomingip, *i))
-                       {
-                               found = true;
-                               break;
-                       }
-               }
+       std::string incomingip = client->addr();
 
-               if (!found)
+       for (std::vector<std::string>::iterator i = Utils->ValidIPs.begin(); i != Utils->ValidIPs.end(); i++)
+       {
+               if (*i == "*" || *i == incomingip || irc::sockets::cidr_mask(*i).match(*client))
                {
-                       ServerInstance->SNO->WriteToSnoMask('l', "Server connection from %s denied (no link blocks with that IP address)", incomingip.c_str());
-                       ServerInstance->SE->Close(newsock);
-                       return;
+                       /* we don't need to do anything with the pointer, creating it stores it in the necessary places */
+                       new TreeSocket(Utils, newsock, from, client, server);
+                       return MOD_RES_ALLOW;
                }
        }
-
-       /* we don't need to do anything with the pointer, creating it stores it in the necessary places */
-
-       new TreeSocket(Utils, newsock, this, &client, &server);
+       ServerInstance->SNO->WriteToSnoMask('l', "Server connection from %s denied (no link blocks with that IP address)", incomingip.c_str());
+       return MOD_RES_DENY;
 }
 
 /** Yay for fast searches!
@@ -144,19 +132,11 @@ SpanningTreeUtilities::SpanningTreeUtilities(ModuleSpanningTree* C) : Creator(C)
        ServerInstance->Logs->Log("m_spanningtree",DEBUG,"***** Using SID for hash: %s *****", ServerInstance->Config->GetSID().c_str());
 
        this->TreeRoot = new TreeServer(this, ServerInstance->Config->ServerName, ServerInstance->Config->ServerDesc, ServerInstance->Config->GetSID());
-       ServerUser = new FakeUser(TreeRoot->GetID());
-
-       this->ReadConfiguration(true);
+       this->ReadConfiguration();
 }
 
 CullResult SpanningTreeUtilities::cull()
 {
-       for (unsigned int i = 0; i < ServerInstance->ports.size(); i++)
-       {
-               if (ServerInstance->ports[i]->type == "servers")
-                       ServerInstance->ports[i]->cull();
-       }
-
        while (TreeRoot->ChildCount())
        {
                TreeServer* child_server = TreeRoot->GetChild(0);
@@ -168,20 +148,18 @@ CullResult SpanningTreeUtilities::cull()
                }
        }
 
-       ServerUser->uuid = TreeRoot->GetID();
-       ServerUser->cull();
-       delete ServerUser;
+       for(std::map<TreeSocket*, std::pair<std::string, int> >::iterator i = timeoutlist.begin(); i != timeoutlist.end(); ++i)
+       {
+               TreeSocket* s = i->first;
+               ServerInstance->GlobalCulls.AddItem(s);
+       }
+       TreeRoot->cull();
+
        return classbase::cull();
 }
 
 SpanningTreeUtilities::~SpanningTreeUtilities()
 {
-       for (unsigned int i = 0; i < ServerInstance->ports.size(); i++)
-       {
-               if (ServerInstance->ports[i]->type == "servers")
-                       delete ServerInstance->ports[i];
-       }
-
        delete TreeRoot;
 }
 
@@ -344,7 +322,7 @@ void SpanningTreeUtilities::RefreshIPCache()
                        ValidIPs.push_back(L->AllowMask);
 
                irc::sockets::sockaddrs dummy;
-               bool ipvalid = irc::sockets::aptosa(L->IPAddr, L->Port, &dummy);
+               bool ipvalid = irc::sockets::aptosa(L->IPAddr, L->Port, dummy);
                if (ipvalid)
                        ValidIPs.push_back(L->IPAddr);
                else
@@ -362,42 +340,10 @@ void SpanningTreeUtilities::RefreshIPCache()
        }
 }
 
-void SpanningTreeUtilities::ReadConfiguration(bool rebind)
+void SpanningTreeUtilities::ReadConfiguration()
 {
        ConfigReader Conf;
 
-       if (rebind)
-       {
-               ConfigTagList tags = ServerInstance->Config->ConfTags("bind");
-               for(ConfigIter i = tags.first; i != tags.second; ++i)
-               {
-                       ConfigTag* tag = i->second;
-                       std::string Type = tag->getString("type");
-                       std::string IP = tag->getString("address");
-                       std::string Port = tag->getString("port");
-                       std::string ssl = tag->getString("ssl");
-                       if (Type == "servers")
-                       {
-                               irc::portparser portrange(Port, false);
-                               int portno = -1;
-
-                               if (IP == "*")
-                                       IP.clear();
-
-                               while ((portno = portrange.GetToken()))
-                               {
-                                       ServerSocketListener *listener = new ServerSocketListener(this, portno, IP, ssl);
-                                       if (listener->GetFd() == -1)
-                                       {
-                                               delete listener;
-                                               continue;
-                                       }
-
-                                       ServerInstance->ports.push_back(listener);
-                               }
-                       }
-               }
-       }
        FlatLinks = Conf.ReadFlag("security","flatlinks",0);
        HideULines = Conf.ReadFlag("security","hideulines",0);
        AnnounceTSChange = Conf.ReadFlag("options","announcets",0);
@@ -425,8 +371,8 @@ void SpanningTreeUtilities::ReadConfiguration(bool rebind)
                L->AllowMask = tag->getString("allowmask");
                L->IPAddr = tag->getString("ipaddr");
                L->Port = tag->getInt("port");
-               L->SendPass = tag->getString("sendpass");
-               L->RecvPass = tag->getString("recvpass");
+               L->SendPass = tag->getString("sendpass", tag->getString("password"));
+               L->RecvPass = tag->getString("recvpass", tag->getString("password"));
                L->Fingerprint = tag->getString("fingerprint");
                L->HiddenFromStats = tag->getBool("statshidden");
                L->Timeout = tag->getInt("timeout");
@@ -440,6 +386,15 @@ void SpanningTreeUtilities::ReadConfiguration(bool rebind)
                if (L->Name.length() > 64)
                        throw CoreException("The link name '"+assign(L->Name)+"' is longer than 64 characters!");
 
+               if (L->Fingerprint.find(':') != std::string::npos)
+               {
+                       std::string tmp = L->Fingerprint;
+                       L->Fingerprint.clear();
+                       for(unsigned int j=0; j < tmp.length(); j++)
+                               if (tmp[j] != ':')
+                                       L->Fingerprint.push_back(tmp[j]);
+               }
+
                if ((!L->IPAddr.empty()) && (!L->RecvPass.empty()) && (!L->SendPass.empty()) && (!L->Name.empty()) && (L->Port))
                {
                        ValidIPs.push_back(L->IPAddr);