+ case IO_FAILURE:
+ iauth_disconnect(iauth);
+ return;
+ }
+ }
+ /* We were able to flush all events, so remove notification. */
+ socket_events(i_socket(iauth), SOCK_ACTION_DEL | SOCK_EVENT_WRITABLE);
+}
+
+/** Send a message to iauth.
+ * @param[in] cptr Optional client context for message.
+ * @param[in] format Format string for message.
+ * @return Non-zero on successful send or buffering, zero on failure.
+ */
+static int sendto_iauth(struct Client *cptr, const char *format, ...)
+{
+ struct VarData vd;
+ struct MsgBuf *mb;
+
+ /* Do not send requests when we have no iauth. */
+ if (!i_GetConnected(iauth))
+ return 0;
+ /* Do not send for clients in the NORMAL state. */
+ if (cptr
+ && (format[0] != 'D')
+ && (!cli_auth(cptr) || !FlagHas(&cli_auth(cptr)->flags, AR_IAUTH_PENDING)))
+ return 0;
+
+ /* Build the message buffer. */
+ vd.vd_format = format;
+ va_start(vd.vd_args, format);
+ if (0 == cptr)
+ mb = msgq_make(NULL, "-1 %v", &vd);
+ else
+ mb = msgq_make(NULL, "%d %v", cli_fd(cptr), &vd);
+ va_end(vd.vd_args);
+
+ /* Tack it onto the iauth sendq and try to write it. */
+ ++iauth->i_sendM;
+ msgq_add(i_sendQ(iauth), mb, 0);
+ msgq_clean(mb);
+ iauth_write(iauth);
+ return 1;
+}
+
+/** Send text to interested operators (SNO_AUTH server notice).
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params Text to send.
+ * @return Zero.
+ */
+static int iauth_cmd_snotice(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ sendto_opmask_butone(NULL, SNO_AUTH, "%s", params[0]);
+ return 0;
+}
+
+/** Set the debug level for the session.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params String starting with an integer.
+ * @return Zero.
+ */
+static int iauth_cmd_debuglevel(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ int new_level;
+
+ new_level = parc > 0 ? atoi(params[0]) : 0;
+ if (i_debug(iauth) > 0 || new_level > 0) {
+ /* The "ia_dbg" name is borrowed from (IRCnet) ircd. */
+ sendto_opmask_butone(NULL, SNO_AUTH, "ia_dbg = %d", new_level);
+ }
+ i_debug(iauth) = new_level;
+ return 0;
+}
+
+/** Set policy options for the session.
+ * Old policy is forgotten, and any of the following characters in \a
+ * params enable the corresponding policy:
+ * \li A IAUTH_ADDLINFO
+ * \li R IAUTH_REQUIRED
+ * \li T IAUTH_TIMEOUT
+ * \li W IAUTH_EXTRAWAIT
+ * \li U IAUTH_UNDERNET
+ *
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params Zero or more policy options.
+ * @return Zero.
+ */
+static int iauth_cmd_policy(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ enum IAuthFlag flag;
+ char *p;
+
+ /* Erase old policy first. */
+ for (flag = IAUTH_FIRST_OPTION; flag < IAUTH_LAST_FLAG; ++flag)
+ IAuthClr(iauth, flag);
+
+ if (parc > 0) /* only try to parse if we were given a policy string */
+ /* Parse new policy set. */
+ for (p = params[0]; *p; p++) switch (*p) {
+ case 'A': IAuthSet(iauth, IAUTH_ADDLINFO); break;
+ case 'R': IAuthSet(iauth, IAUTH_REQUIRED); break;
+ case 'T': IAuthSet(iauth, IAUTH_TIMEOUT); break;
+ case 'W': IAuthSet(iauth, IAUTH_EXTRAWAIT); break;
+ case 'U': IAuthSet(iauth, IAUTH_UNDERNET); break;
+ }
+
+ /* Optionally notify operators. */
+ if (i_debug(iauth) > 0)
+ sendto_opmask_butone(NULL, SNO_AUTH, "iauth options: %s", params[0]);
+ return 0;
+}
+
+/** Set the iauth program version number.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params Version number or name.
+ * @return Zero.
+ */
+static int iauth_cmd_version(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ MyFree(iauth->i_version);
+ DupString(iauth->i_version, parc > 0 ? params[0] : "<NONE>");
+ sendto_opmask_butone(NULL, SNO_AUTH, "iauth version %s running.",
+ iauth->i_version);
+ return 0;
+}
+
+/** Paste a parameter list together into a single string.
+ * @param[in] parc Number of parameters.
+ * @param[in] params Parameter list to paste together.
+ * @return Pasted parameter list.
+ */
+static char *paste_params(int parc, char **params)
+{
+ char *str, *tmp;
+ int len = 0, lengths[MAXPARA], i;
+
+ /* Compute the length... */
+ for (i = 0; i < parc; i++)
+ len += lengths[i] = strlen(params[i]);
+
+ /* Allocate memory, accounting for string lengths, spaces (parc - 1), a
+ * sentinel, and the trailing \0
+ */
+ str = MyMalloc(len + parc + 1);
+
+ /* Build the pasted string */
+ for (tmp = str, i = 0; i < parc; i++) {
+ if (i) /* add space separator... */
+ *(tmp++) = ' ';
+ if (i == parc - 1) /* add colon sentinel */
+ *(tmp++) = ':';
+
+ /* Copy string component... */
+ memcpy(tmp, params[i], lengths[i]);
+ tmp += lengths[i]; /* move to end of string */
+ }
+
+ /* terminate the string... */
+ *tmp = '\0';
+
+ return str; /* return the pasted string */
+}
+
+/** Clear cached iauth configuration information.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (0).
+ * @param[in] params Parameter list (ignored).
+ * @return Zero.
+ */
+static int iauth_cmd_newconfig(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ struct SLink *head;
+ struct SLink *next;
+
+ head = iauth->i_config;
+ iauth->i_config = NULL;
+ for (; head; head = next) {
+ next = head->next;
+ MyFree(head->value.cp);
+ free_link(head);
+ }
+ sendto_opmask_butone(NULL, SNO_AUTH, "New iauth configuration.");
+ return 0;
+}
+
+/** Append iauth configuration information.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters.
+ * @param[in] params Description of configuration element.
+ * @return Zero.
+ */
+static int iauth_cmd_config(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ struct SLink *node;
+
+ if (iauth->i_config) {
+ for (node = iauth->i_config; node->next; node = node->next) ;
+ node = node->next = make_link();
+ } else {
+ node = iauth->i_config = make_link();
+ }
+ node->value.cp = paste_params(parc, params);
+ node->next = 0; /* must be explicitly cleared */
+ return 0;
+}
+
+/** Clear cached iauth configuration information.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (0).
+ * @param[in] params Parameter list (ignored).
+ * @return Zero.
+ */
+static int iauth_cmd_newstats(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ struct SLink *head;
+ struct SLink *next;
+
+ head = iauth->i_stats;
+ iauth->i_stats = NULL;
+ for (; head; head = next) {
+ next = head->next;
+ MyFree(head->value.cp);
+ free_link(head);
+ }
+ sendto_opmask_butone(NULL, SNO_AUTH, "New iauth statistics.");
+ return 0;
+}
+
+/** Append iauth statistics information.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters.
+ * @param[in] params Statistics element.
+ * @return Zero.
+ */
+static int iauth_cmd_stats(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ struct SLink *node;
+ if (iauth->i_stats) {
+ for (node = iauth->i_stats; node->next; node = node->next) ;
+ node = node->next = make_link();
+ } else {
+ node = iauth->i_stats = make_link();
+ }
+ node->value.cp = paste_params(parc, params);
+ node->next = 0; /* must be explicitly cleared */
+ return 0;
+}
+
+/** Set client's username to a trusted string even if it breaks the rules.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params Forced username.
+ * @return One.
+ */
+static int iauth_cmd_username_forced(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ assert(cli_auth(cli) != NULL);
+ FlagClr(&cli_auth(cli)->flags, AR_AUTH_PENDING);
+ if (!EmptyString(params[0])) {
+ ircd_strncpy(cli_username(cli), params[0], USERLEN);
+ SetGotId(cli);
+ FlagSet(&cli_auth(cli)->flags, AR_IAUTH_USERNAME);
+ FlagSet(&cli_auth(cli)->flags, AR_IAUTH_FUSERNAME);
+ }
+ return 1;
+}
+
+/** Set client's username to a trusted string.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params Trusted username.
+ * @return One.
+ */
+static int iauth_cmd_username_good(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ assert(cli_auth(cli) != NULL);
+ FlagClr(&cli_auth(cli)->flags, AR_AUTH_PENDING);
+ if (!EmptyString(params[0])) {
+ ircd_strncpy(cli_username(cli), params[0], USERLEN);
+ SetGotId(cli);
+ FlagSet(&cli_auth(cli)->flags, AR_IAUTH_USERNAME);
+ }
+ return 1;
+}
+
+/** Set client's username to an untrusted string.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params Untrusted username.
+ * @return One.
+ */
+static int iauth_cmd_username_bad(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ assert(cli_auth(cli) != NULL);
+ FlagClr(&cli_auth(cli)->flags, AR_AUTH_PENDING);
+ if (!EmptyString(params[0]))
+ ircd_strncpy(cli_user(cli)->username, params[0], USERLEN);
+ return 1;
+}
+
+/** Set client's hostname.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params New hostname for client.
+ * @return Non-zero if \a cli authorization should be checked for completion.
+ */
+static int iauth_cmd_hostname(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ struct AuthRequest *auth;
+
+ if (EmptyString(params[0])) {
+ sendto_iauth(cli, "E Missing :Missing hostname parameter");
+ return 0;
+ }
+
+ auth = cli_auth(cli);
+ assert(auth != NULL);
+
+ /* If a DNS request is pending, abort it. */
+ if (FlagHas(&auth->flags, AR_DNS_PENDING)) {
+ FlagClr(&auth->flags, AR_DNS_PENDING);
+ delete_resolver_queries(auth);
+ if (IsUserPort(cli))
+ sendheader(cli, REPORT_FIN_DNS);
+ }
+ /* Set hostname from params. */
+ ircd_strncpy(cli_sockhost(cli), params[0], HOSTLEN);
+ /* If we have gotten here, the user is in a "hurry" state and has
+ * been pre-registered. Their hostname was set during that, and
+ * needs to be overwritten now.
+ */
+ if (FlagHas(&auth->flags, AR_IAUTH_HURRY)) {
+ ircd_strncpy(cli_user(cli)->host, cli_sockhost(cli), HOSTLEN);
+ ircd_strncpy(cli_user(cli)->realhost, cli_sockhost(cli), HOSTLEN);
+ }
+ return 1;
+}
+
+/** Set client's IP address.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params New IP address for client in dotted quad or
+ * standard IPv6 format.
+ * @return Zero.
+ */
+static int iauth_cmd_ip_address(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ struct irc_in_addr addr;
+ struct AuthRequest *auth;
+
+ if (EmptyString(params[0])) {
+ sendto_iauth(cli, "E Missing :Missing IP address parameter");
+ return 0;
+ }
+
+ /* Get AuthRequest for client. */
+ auth = cli_auth(cli);
+ assert(auth != NULL);
+
+ /* Parse the client's new IP address. */
+ if (!ircd_aton(&addr, params[0])) {
+ sendto_iauth(cli, "E Invalid :Unable to parse IP address [%s]", params[0]);
+ return 0;
+ }
+
+ /* If this is the first IP override, save the client's original
+ * address in case we get a DNS response later.
+ */
+ if (!irc_in_addr_valid(&auth->original))
+ memcpy(&auth->original, &cli_ip(cli), sizeof(auth->original));
+
+ /* Undo original IP connection in IPcheck. */
+ IPcheck_connect_fail(cli);
+ ClearIPChecked(cli);
+
+ /* Update the IP and charge them as a remote connect. */
+ memcpy(&cli_ip(cli), &addr, sizeof(cli_ip(cli)));
+ IPcheck_remote_connect(cli, 0);
+
+ return 0;
+}
+
+/** Find a ConfItem structure for a named connection class.
+ * @param[in] class_name Name of configuration class to find.
+ * @return A ConfItem of type CONF_CLIENT for the class, or NULL on failure.
+ */
+static struct ConfItem *auth_find_class_conf(const char *class_name)
+{
+ static struct ConfItem *aconf_list;
+ struct ConnectionClass *class;
+ struct ConfItem *aconf;
+
+ /* Make sure the configuration class is valid. */
+ class = find_class(class_name);
+ if (!class || !class->valid)
+ return NULL;
+
+ /* Look for an existing ConfItem for the class. */
+ for (aconf = aconf_list; aconf; aconf = aconf->next)
+ if (aconf->conn_class == class)
+ break;
+
+ /* If no ConfItem, create one. */
+ if (!aconf) {
+ aconf = make_conf(CONF_CLIENT);
+ if (!aconf) {
+ sendto_opmask_butone(NULL, SNO_AUTH,
+ "Unable to allocate ConfItem for class %s!",
+ ConClass(class));
+ return NULL;
+ }
+ /* make_conf() "helpfully" links the conf into GlobalConfList,
+ * which we do not want, so undo that. (Ugh.)
+ */
+ if (aconf == GlobalConfList) {
+ GlobalConfList = aconf->next;
+ }
+ /* Back to business as usual. */
+ aconf->conn_class = class;
+ aconf->next = aconf_list;
+ aconf_list = aconf;
+ }
+
+ return aconf;
+}
+
+/** Accept a client in IAuth.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters.
+ * @param[in] params Optional class name for client.
+ * @return Negative (CPTR_KILLED) if the connection is refused, one otherwise.
+ */
+static int iauth_cmd_done_client(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ static time_t warn_time;
+
+ /* Clear iauth pending flag. */
+ assert(cli_auth(cli) != NULL);
+ FlagClr(&cli_auth(cli)->flags, AR_IAUTH_PENDING);
+
+ /* If a connection class was specified (and usable), assign the client to it. */
+ if (!EmptyString(params[0])) {
+ struct ConfItem *aconf;
+
+ aconf = auth_find_class_conf(params[0]);
+ if (aconf) {
+ enum AuthorizationCheckResult acr;
+
+ acr = attach_conf(cli, aconf);
+ switch (acr) {
+ case ACR_OK:
+ /* There should maybe be some way to set FLAG_DOID here.. */
+ break;
+ case ACR_TOO_MANY_IN_CLASS:
+ ++ServerStats->is_ref;
+ return exit_client(cli, cli, &me,
+ "Sorry, your connection class is full - try "
+ "again later or try another server");
+ default:
+ log_write(LS_IAUTH, L_ERROR, 0, "IAuth: Unexpected AuthorizationCheckResult %d from attach_conf()", acr);
+ break;
+ }
+ } else
+ sendto_opmask_butone_ratelimited(NULL, SNO_AUTH, &warn_time,
+ "iauth tried to use undefined class [%s]",
+ params[0]);
+ }
+
+ return 1;
+}
+
+/** Accept a client in IAuth and assign them to an account.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters.
+ * @param[in] params Account name and optional class name for client.
+ * @return Negative if the connection is refused, otherwise non-zero
+ * if \a cli authorization should be checked for completion.
+ */
+static int iauth_cmd_done_account(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ size_t len;
+
+ /* Sanity check. */
+ if (EmptyString(params[0])) {
+ sendto_iauth(cli, "E Missing :Missing account parameter");
+ return 0;
+ }
+ /* Check length of account name. */
+ len = strcspn(params[0], ": ");
+ if (len > ACCOUNTLEN) {
+ sendto_iauth(cli, "E Invalid :Account parameter too long");
+ return 0;
+ }
+ /* If account has a creation timestamp, use it. */
+ assert(cli_user(cli) != NULL);
+ if (params[0][len] == ':')
+ cli_user(cli)->acc_create = strtoul(params[0] + len + 1, NULL, 10);
+
+ /* Copy account name to User structure. */
+ ircd_strncpy(cli_user(cli)->account, params[0], ACCOUNTLEN);
+ SetAccount(cli);
+
+ /* Fall through to the normal "done" handler. */
+ return iauth_cmd_done_client(iauth, cli, parc - 1, params + 1);
+}
+
+/** Reject a client's connection.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (1).
+ * @param[in] params Optional kill message.
+ * @return Zero.
+ */
+static int iauth_cmd_kill(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ if (cli_auth(cli))
+ FlagClr(&cli_auth(cli)->flags, AR_IAUTH_PENDING);
+ if (EmptyString(params[0]))
+ params[0] = "Access denied";
+ exit_client(cli, cli, &me, params[0]);
+ return 0;
+}
+
+/** Change a client's usermode.
+ * @param[in] iauth Active IAuth session.
+ * @param[in] cli Client referenced by command.
+ * @param[in] parc Number of parameters (at least one).
+ * @param[in] params Usermode arguments for client (with the first
+ * starting with '+').
+ * @return Zero.
+ */
+static int iauth_cmd_usermode(struct IAuth *iauth, struct Client *cli,
+ int parc, char **params)
+{
+ if (params[0][0] == '+')