]> git.xonotic.org Git - xonotic/darkplaces.git/blob - netconn.c
added sv_threaded cvar, the server can now be moved to another thread
[xonotic/darkplaces.git] / netconn.c
1 /*
2 Copyright (C) 1996-1997 Id Software, Inc.
3 Copyright (C) 2002 Mathieu Olivier
4 Copyright (C) 2003 Forest Hale
5
6 This program is free software; you can redistribute it and/or
7 modify it under the terms of the GNU General Public License
8 as published by the Free Software Foundation; either version 2
9 of the License, or (at your option) any later version.
10
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
14
15 See the GNU General Public License for more details.
16
17 You should have received a copy of the GNU General Public License
18 along with this program; if not, write to the Free Software
19 Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307, USA.
20
21 */
22
23 #include "quakedef.h"
24 #include "thread.h"
25 #include "lhnet.h"
26
27 // for secure rcon authentication
28 #include "hmac.h"
29 #include "mdfour.h"
30 #include <time.h>
31
32 #define QWMASTER_PORT 27000
33 #define DPMASTER_PORT 27950
34
35 // note this defaults on for dedicated servers, off for listen servers
36 cvar_t sv_public = {0, "sv_public", "0", "1: advertises this server on the master server (so that players can find it in the server browser); 0: allow direct queries only; -1: do not respond to direct queries; -2: do not allow anyone to connect; -3: already block at getchallenge level"};
37 cvar_t sv_public_rejectreason = {0, "sv_public_rejectreason", "The server is closing.", "Rejection reason for connects when sv_public is -2"};
38 static cvar_t sv_heartbeatperiod = {CVAR_SAVE, "sv_heartbeatperiod", "120", "how often to send heartbeat in seconds (only used if sv_public is 1)"};
39 extern cvar_t sv_status_privacy;
40
41 static cvar_t sv_masters [] =
42 {
43         {CVAR_SAVE, "sv_master1", "", "user-chosen master server 1"},
44         {CVAR_SAVE, "sv_master2", "", "user-chosen master server 2"},
45         {CVAR_SAVE, "sv_master3", "", "user-chosen master server 3"},
46         {CVAR_SAVE, "sv_master4", "", "user-chosen master server 4"},
47         {0, "sv_masterextra1", "69.59.212.88", "ghdigital.com - default master server 1 (admin: LordHavoc)"}, // admin: LordHavoc
48         {0, "sv_masterextra2", "64.22.107.125", "dpmaster.deathmask.net - default master server 2 (admin: Willis)"}, // admin: Willis
49         {0, "sv_masterextra3", "92.62.40.73", "dpmaster.tchr.no - default master server 3 (admin: tChr)"}, // admin: tChr
50 #ifdef SUPPORTIPV6
51         {0, "sv_masterextra4", "[2001:41d0:2:1628::4450]:27950", "dpmaster.div0.qc.to - default master server 4 (admin: divVerent)"}, // admin: divVerent
52 #endif
53         {0, NULL, NULL, NULL}
54 };
55
56 static cvar_t sv_qwmasters [] =
57 {
58         {CVAR_SAVE, "sv_qwmaster1", "", "user-chosen qwmaster server 1"},
59         {CVAR_SAVE, "sv_qwmaster2", "", "user-chosen qwmaster server 2"},
60         {CVAR_SAVE, "sv_qwmaster3", "", "user-chosen qwmaster server 3"},
61         {CVAR_SAVE, "sv_qwmaster4", "", "user-chosen qwmaster server 4"},
62         {0, "sv_qwmasterextra1", "master.quakeservers.net:27000", "Global master server. (admin: unknown)"},
63         {0, "sv_qwmasterextra2", "asgaard.morphos-team.net:27000", "Global master server. (admin: unknown)"},
64         {0, "sv_qwmasterextra3", "qwmaster.ocrana.de:27000", "German master server. (admin: unknown)"},
65         {0, "sv_qwmasterextra4", "masterserver.exhale.de:27000", "German master server. (admin: unknown)"},
66         {0, "sv_qwmasterextra5", "qwmaster.fodquake.net:27000", "Global master server. (admin: unknown)"},
67         {0, NULL, NULL, NULL}
68 };
69
70 static double nextheartbeattime = 0;
71
72 sizebuf_t net_message;
73 static unsigned char net_message_buf[NET_MAXMESSAGE];
74
75 cvar_t net_messagetimeout = {0, "net_messagetimeout","300", "drops players who have not sent any packets for this many seconds"};
76 cvar_t net_connecttimeout = {0, "net_connecttimeout","15", "after requesting a connection, the client must reply within this many seconds or be dropped (cuts down on connect floods). Must be above 10 seconds."};
77 cvar_t net_connectfloodblockingtimeout = {0, "net_connectfloodblockingtimeout", "5", "when a connection packet is received, it will block all future connect packets from that IP address for this many seconds (cuts down on connect floods)"};
78 cvar_t hostname = {CVAR_SAVE, "hostname", "UNNAMED", "server message to show in server browser"};
79 cvar_t developer_networking = {0, "developer_networking", "0", "prints all received and sent packets (recommended only for debugging)"};
80
81 cvar_t cl_netlocalping = {0, "cl_netlocalping","0", "lags local loopback connection by this much ping time (useful to play more fairly on your own server with people with higher pings)"};
82 static cvar_t cl_netpacketloss_send = {0, "cl_netpacketloss_send","0", "drops this percentage of outgoing packets, useful for testing network protocol robustness (jerky movement, prediction errors, etc)"};
83 static cvar_t cl_netpacketloss_receive = {0, "cl_netpacketloss_receive","0", "drops this percentage of incoming packets, useful for testing network protocol robustness (jerky movement, effects failing to start, sounds failing to play, etc)"};
84 static cvar_t net_slist_queriespersecond = {0, "net_slist_queriespersecond", "20", "how many server information requests to send per second"};
85 static cvar_t net_slist_queriesperframe = {0, "net_slist_queriesperframe", "4", "maximum number of server information requests to send each rendered frame (guards against low framerates causing problems)"};
86 static cvar_t net_slist_timeout = {0, "net_slist_timeout", "4", "how long to listen for a server information response before giving up"};
87 static cvar_t net_slist_pause = {0, "net_slist_pause", "0", "when set to 1, the server list won't update until it is set back to 0"};
88 static cvar_t net_slist_maxtries = {0, "net_slist_maxtries", "3", "how many times to ask the same server for information (more times gives better ping reports but takes longer)"};
89 static cvar_t net_slist_favorites = {CVAR_SAVE | CVAR_NQUSERINFOHACK, "net_slist_favorites", "", "contains a list of IP addresses and ports to always query explicitly"};
90 static cvar_t gameversion = {0, "gameversion", "0", "version of game data (mod-specific) to be sent to querying clients"};
91 static cvar_t gameversion_min = {0, "gameversion_min", "-1", "minimum version of game data (mod-specific), when client and server gameversion mismatch in the server browser the server is shown as incompatible; if -1, gameversion is used alone"};
92 static cvar_t gameversion_max = {0, "gameversion_max", "-1", "maximum version of game data (mod-specific), when client and server gameversion mismatch in the server browser the server is shown as incompatible; if -1, gameversion is used alone"};
93 static cvar_t rcon_restricted_password = {CVAR_PRIVATE, "rcon_restricted_password", "", "password to authenticate rcon commands in restricted mode; may be set to a string of the form user1:pass1 user2:pass2 user3:pass3 to allow multiple user accounts - the client then has to specify ONE of these combinations"};
94 static cvar_t rcon_restricted_commands = {0, "rcon_restricted_commands", "", "allowed commands for rcon when the restricted mode password was used"};
95 static cvar_t rcon_secure_maxdiff = {0, "rcon_secure_maxdiff", "5", "maximum time difference between rcon request and server system clock (to protect against replay attack)"};
96 extern cvar_t rcon_secure;
97 extern cvar_t rcon_secure_challengetimeout;
98
99 /* statistic counters */
100 static int packetsSent = 0;
101 static int packetsReSent = 0;
102 static int packetsReceived = 0;
103 static int receivedDuplicateCount = 0;
104 static int droppedDatagrams = 0;
105
106 static int unreliableMessagesSent = 0;
107 static int unreliableMessagesReceived = 0;
108 static int reliableMessagesSent = 0;
109 static int reliableMessagesReceived = 0;
110
111 double masterquerytime = -1000;
112 int masterquerycount = 0;
113 int masterreplycount = 0;
114 int serverquerycount = 0;
115 int serverreplycount = 0;
116
117 challenge_t challenge[MAX_CHALLENGES];
118
119 /// this is only false if there are still servers left to query
120 static qboolean serverlist_querysleep = true;
121 static qboolean serverlist_paused = false;
122 /// this is pushed a second or two ahead of realtime whenever a master server
123 /// reply is received, to avoid issuing queries while master replies are still
124 /// flooding in (which would make a mess of the ping times)
125 static double serverlist_querywaittime = 0;
126
127 static unsigned char sendbuffer[NET_HEADERSIZE+NET_MAXMESSAGE];
128 static unsigned char readbuffer[NET_HEADERSIZE+NET_MAXMESSAGE];
129 static unsigned char cryptosendbuffer[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
130 static unsigned char cryptoreadbuffer[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
131
132 static int cl_numsockets;
133 static lhnetsocket_t *cl_sockets[16];
134 static int sv_numsockets;
135 static lhnetsocket_t *sv_sockets[16];
136
137 netconn_t *netconn_list = NULL;
138 mempool_t *netconn_mempool = NULL;
139 void *netconn_mutex = NULL;
140
141 cvar_t cl_netport = {0, "cl_port", "0", "forces client to use chosen port number if not 0"};
142 cvar_t sv_netport = {0, "port", "26000", "server port for players to connect to"};
143 cvar_t net_address = {0, "net_address", "", "network address to open ipv4 ports on (if empty, use default interfaces)"};
144 cvar_t net_address_ipv6 = {0, "net_address_ipv6", "", "network address to open ipv6 ports on (if empty, use default interfaces)"};
145
146 char cl_net_extresponse[NET_EXTRESPONSE_MAX][1400];
147 int cl_net_extresponse_count = 0;
148 int cl_net_extresponse_last = 0;
149
150 char sv_net_extresponse[NET_EXTRESPONSE_MAX][1400];
151 int sv_net_extresponse_count = 0;
152 int sv_net_extresponse_last = 0;
153
154 // ServerList interface
155 serverlist_mask_t serverlist_andmasks[SERVERLIST_ANDMASKCOUNT];
156 serverlist_mask_t serverlist_ormasks[SERVERLIST_ORMASKCOUNT];
157
158 serverlist_infofield_t serverlist_sortbyfield;
159 int serverlist_sortflags;
160
161 int serverlist_viewcount = 0;
162 unsigned short serverlist_viewlist[SERVERLIST_VIEWLISTSIZE];
163
164 int serverlist_maxcachecount = 0;
165 int serverlist_cachecount = 0;
166 serverlist_entry_t *serverlist_cache = NULL;
167
168 qboolean serverlist_consoleoutput;
169
170 static int nFavorites = 0;
171 static lhnetaddress_t favorites[MAX_FAVORITESERVERS];
172 static int nFavorites_idfp = 0;
173 static char favorites_idfp[MAX_FAVORITESERVERS][FP64_SIZE+1];
174
175 void NetConn_UpdateFavorites(void)
176 {
177         const char *p;
178         nFavorites = 0;
179         nFavorites_idfp = 0;
180         p = net_slist_favorites.string;
181         while((size_t) nFavorites < sizeof(favorites) / sizeof(*favorites) && COM_ParseToken_Console(&p))
182         {
183                 if(com_token[0] != '[' && strlen(com_token) == FP64_SIZE && !strchr(com_token, '.'))
184                 // currently 44 bytes, longest possible IPv6 address: 39 bytes, so this works
185                 // (if v6 address contains port, it must start with '[')
186                 {
187                         strlcpy(favorites_idfp[nFavorites_idfp], com_token, sizeof(favorites_idfp[nFavorites_idfp]));
188                         ++nFavorites_idfp;
189                 }
190                 else 
191                 {
192                         if(LHNETADDRESS_FromString(&favorites[nFavorites], com_token, 26000))
193                                 ++nFavorites;
194                 }
195         }
196 }
197
198 /// helper function to insert a value into the viewset
199 /// spare entries will be removed
200 static void _ServerList_ViewList_Helper_InsertBefore( int index, serverlist_entry_t *entry )
201 {
202     int i;
203         if( serverlist_viewcount < SERVERLIST_VIEWLISTSIZE ) {
204                 i = serverlist_viewcount++;
205         } else {
206                 i = SERVERLIST_VIEWLISTSIZE - 1;
207         }
208
209         for( ; i > index ; i-- )
210                 serverlist_viewlist[ i ] = serverlist_viewlist[ i - 1 ];
211
212         serverlist_viewlist[index] = (int)(entry - serverlist_cache);
213 }
214
215 /// we suppose serverlist_viewcount to be valid, ie > 0
216 static void _ServerList_ViewList_Helper_Remove( int index )
217 {
218         serverlist_viewcount--;
219         for( ; index < serverlist_viewcount ; index++ )
220                 serverlist_viewlist[index] = serverlist_viewlist[index + 1];
221 }
222
223 /// \returns true if A should be inserted before B
224 static qboolean _ServerList_Entry_Compare( serverlist_entry_t *A, serverlist_entry_t *B )
225 {
226         int result = 0; // > 0 if for numbers A > B and for text if A < B
227
228         if( serverlist_sortflags & SLSF_FAVORITESFIRST )
229         {
230                 if(A->info.isfavorite != B->info.isfavorite)
231                         return A->info.isfavorite;
232         }
233
234         switch( serverlist_sortbyfield ) {
235                 case SLIF_PING:
236                         result = A->info.ping - B->info.ping;
237                         break;
238                 case SLIF_MAXPLAYERS:
239                         result = A->info.maxplayers - B->info.maxplayers;
240                         break;
241                 case SLIF_NUMPLAYERS:
242                         result = A->info.numplayers - B->info.numplayers;
243                         break;
244                 case SLIF_NUMBOTS:
245                         result = A->info.numbots - B->info.numbots;
246                         break;
247                 case SLIF_NUMHUMANS:
248                         result = A->info.numhumans - B->info.numhumans;
249                         break;
250                 case SLIF_FREESLOTS:
251                         result = A->info.freeslots - B->info.freeslots;
252                         break;
253                 case SLIF_PROTOCOL:
254                         result = A->info.protocol - B->info.protocol;
255                         break;
256                 case SLIF_CNAME:
257                         result = strcmp( B->info.cname, A->info.cname );
258                         break;
259                 case SLIF_GAME:
260                         result = strcasecmp( B->info.game, A->info.game );
261                         break;
262                 case SLIF_MAP:
263                         result = strcasecmp( B->info.map, A->info.map );
264                         break;
265                 case SLIF_MOD:
266                         result = strcasecmp( B->info.mod, A->info.mod );
267                         break;
268                 case SLIF_NAME:
269                         result = strcasecmp( B->info.name, A->info.name );
270                         break;
271                 case SLIF_QCSTATUS:
272                         result = strcasecmp( B->info.qcstatus, A->info.qcstatus ); // not really THAT useful, though
273                         break;
274                 case SLIF_ISFAVORITE:
275                         result = !!B->info.isfavorite - !!A->info.isfavorite;
276                         break;
277                 default:
278                         Con_DPrint( "_ServerList_Entry_Compare: Bad serverlist_sortbyfield!\n" );
279                         break;
280         }
281
282         if (result != 0)
283         {
284                 if( serverlist_sortflags & SLSF_DESCENDING )
285                         return result > 0;
286                 else
287                         return result < 0;
288         }
289
290         // if the chosen sort key is identical, sort by index
291         // (makes this a stable sort, so that later replies from servers won't
292         //  shuffle the servers around when they have the same ping)
293         return A < B;
294 }
295
296 static qboolean _ServerList_CompareInt( int A, serverlist_maskop_t op, int B )
297 {
298         // This should actually be done with some intermediate and end-of-function return
299         switch( op ) {
300                 case SLMO_LESS:
301                         return A < B;
302                 case SLMO_LESSEQUAL:
303                         return A <= B;
304                 case SLMO_EQUAL:
305                         return A == B;
306                 case SLMO_GREATER:
307                         return A > B;
308                 case SLMO_NOTEQUAL:
309                         return A != B;
310                 case SLMO_GREATEREQUAL:
311                 case SLMO_CONTAINS:
312                 case SLMO_NOTCONTAIN:
313                 case SLMO_STARTSWITH:
314                 case SLMO_NOTSTARTSWITH:
315                         return A >= B;
316                 default:
317                         Con_DPrint( "_ServerList_CompareInt: Bad op!\n" );
318                         return false;
319         }
320 }
321
322 static qboolean _ServerList_CompareStr( const char *A, serverlist_maskop_t op, const char *B )
323 {
324         int i;
325         char bufferA[ 1400 ], bufferB[ 1400 ]; // should be more than enough
326         COM_StringDecolorize(A, 0, bufferA, sizeof(bufferA), false);
327         for (i = 0;i < (int)sizeof(bufferA)-1 && bufferA[i];i++)
328                 bufferA[i] = (bufferA[i] >= 'A' && bufferA[i] <= 'Z') ? (bufferA[i] + 'a' - 'A') : bufferA[i];
329         bufferA[i] = 0;
330         for (i = 0;i < (int)sizeof(bufferB)-1 && B[i];i++)
331                 bufferB[i] = (B[i] >= 'A' && B[i] <= 'Z') ? (B[i] + 'a' - 'A') : B[i];
332         bufferB[i] = 0;
333
334         // Same here, also using an intermediate & final return would be more appropriate
335         // A info B mask
336         switch( op ) {
337                 case SLMO_CONTAINS:
338                         return *bufferB && !!strstr( bufferA, bufferB ); // we want a real bool
339                 case SLMO_NOTCONTAIN:
340                         return !*bufferB || !strstr( bufferA, bufferB );
341                 case SLMO_STARTSWITH:
342                         //Con_Printf("startsWith: %s %s\n", bufferA, bufferB);
343                         return *bufferB && !memcmp(bufferA, bufferB, strlen(bufferB));
344                 case SLMO_NOTSTARTSWITH:
345                         return !*bufferB || memcmp(bufferA, bufferB, strlen(bufferB));
346                 case SLMO_LESS:
347                         return strcmp( bufferA, bufferB ) < 0;
348                 case SLMO_LESSEQUAL:
349                         return strcmp( bufferA, bufferB ) <= 0;
350                 case SLMO_EQUAL:
351                         return strcmp( bufferA, bufferB ) == 0;
352                 case SLMO_GREATER:
353                         return strcmp( bufferA, bufferB ) > 0;
354                 case SLMO_NOTEQUAL:
355                         return strcmp( bufferA, bufferB ) != 0;
356                 case SLMO_GREATEREQUAL:
357                         return strcmp( bufferA, bufferB ) >= 0;
358                 default:
359                         Con_DPrint( "_ServerList_CompareStr: Bad op!\n" );
360                         return false;
361         }
362 }
363
364 static qboolean _ServerList_Entry_Mask( serverlist_mask_t *mask, serverlist_info_t *info )
365 {
366         if( !_ServerList_CompareInt( info->ping, mask->tests[SLIF_PING], mask->info.ping ) )
367                 return false;
368         if( !_ServerList_CompareInt( info->maxplayers, mask->tests[SLIF_MAXPLAYERS], mask->info.maxplayers ) )
369                 return false;
370         if( !_ServerList_CompareInt( info->numplayers, mask->tests[SLIF_NUMPLAYERS], mask->info.numplayers ) )
371                 return false;
372         if( !_ServerList_CompareInt( info->numbots, mask->tests[SLIF_NUMBOTS], mask->info.numbots ) )
373                 return false;
374         if( !_ServerList_CompareInt( info->numhumans, mask->tests[SLIF_NUMHUMANS], mask->info.numhumans ) )
375                 return false;
376         if( !_ServerList_CompareInt( info->freeslots, mask->tests[SLIF_FREESLOTS], mask->info.freeslots ) )
377                 return false;
378         if( !_ServerList_CompareInt( info->protocol, mask->tests[SLIF_PROTOCOL], mask->info.protocol ))
379                 return false;
380         if( *mask->info.cname
381                 && !_ServerList_CompareStr( info->cname, mask->tests[SLIF_CNAME], mask->info.cname ) )
382                 return false;
383         if( *mask->info.game
384                 && !_ServerList_CompareStr( info->game, mask->tests[SLIF_GAME], mask->info.game ) )
385                 return false;
386         if( *mask->info.mod
387                 && !_ServerList_CompareStr( info->mod, mask->tests[SLIF_MOD], mask->info.mod ) )
388                 return false;
389         if( *mask->info.map
390                 && !_ServerList_CompareStr( info->map, mask->tests[SLIF_MAP], mask->info.map ) )
391                 return false;
392         if( *mask->info.name
393                 && !_ServerList_CompareStr( info->name, mask->tests[SLIF_NAME], mask->info.name ) )
394                 return false;
395         if( *mask->info.qcstatus
396                 && !_ServerList_CompareStr( info->qcstatus, mask->tests[SLIF_QCSTATUS], mask->info.qcstatus ) )
397                 return false;
398         if( *mask->info.players
399                 && !_ServerList_CompareStr( info->players, mask->tests[SLIF_PLAYERS], mask->info.players ) )
400                 return false;
401         if( !_ServerList_CompareInt( info->isfavorite, mask->tests[SLIF_ISFAVORITE], mask->info.isfavorite ))
402                 return false;
403         return true;
404 }
405
406 static void ServerList_ViewList_Insert( serverlist_entry_t *entry )
407 {
408         int start, end, mid, i;
409         lhnetaddress_t addr;
410
411         // reject incompatible servers
412         if(
413                 entry->info.gameversion != gameversion.integer
414                 &&
415                 !(
416                            gameversion_min.integer >= 0 // min/max range set by user/mod?
417                         && gameversion_max.integer >= 0
418                         && gameversion_min.integer <= entry->info.gameversion // version of server in min/max range?
419                         && gameversion_max.integer >= entry->info.gameversion
420                  )
421         )
422                 return;
423
424         // refresh the "favorite" status
425         entry->info.isfavorite = false;
426         if(LHNETADDRESS_FromString(&addr, entry->info.cname, 26000))
427         {
428                 char idfp[FP64_SIZE+1];
429                 for(i = 0; i < nFavorites; ++i)
430                 {
431                         if(LHNETADDRESS_Compare(&addr, &favorites[i]) == 0)
432                         {
433                                 entry->info.isfavorite = true;
434                                 break;
435                         }
436                 }
437                 if(Crypto_RetrieveHostKey(&addr, 0, NULL, 0, idfp, sizeof(idfp), NULL))
438                 {
439                         for(i = 0; i < nFavorites_idfp; ++i)
440                         {
441                                 if(!strcmp(idfp, favorites_idfp[i]))
442                                 {
443                                         entry->info.isfavorite = true;
444                                         break;
445                                 }
446                         }
447                 }
448         }
449
450         // FIXME: change this to be more readable (...)
451         // now check whether it passes through the masks
452         for( start = 0 ; start < SERVERLIST_ANDMASKCOUNT && serverlist_andmasks[start].active; start++ )
453                 if( !_ServerList_Entry_Mask( &serverlist_andmasks[start], &entry->info ) )
454                         return;
455
456         for( start = 0 ; start < SERVERLIST_ORMASKCOUNT && serverlist_ormasks[start].active ; start++ )
457                 if( _ServerList_Entry_Mask( &serverlist_ormasks[start], &entry->info ) )
458                         break;
459         if( start == SERVERLIST_ORMASKCOUNT || (start > 0 && !serverlist_ormasks[start].active) )
460                 return;
461
462         if( !serverlist_viewcount ) {
463                 _ServerList_ViewList_Helper_InsertBefore( 0, entry );
464                 return;
465         }
466         // ok, insert it, we just need to find out where exactly:
467
468         // two special cases
469         // check whether to insert it as new first item
470         if( _ServerList_Entry_Compare( entry, ServerList_GetViewEntry(0) ) ) {
471                 _ServerList_ViewList_Helper_InsertBefore( 0, entry );
472                 return;
473         } // check whether to insert it as new last item
474         else if( !_ServerList_Entry_Compare( entry, ServerList_GetViewEntry(serverlist_viewcount - 1) ) ) {
475                 _ServerList_ViewList_Helper_InsertBefore( serverlist_viewcount, entry );
476                 return;
477         }
478         start = 0;
479         end = serverlist_viewcount - 1;
480         while( end > start + 1 )
481         {
482                 mid = (start + end) / 2;
483                 // test the item that lies in the middle between start and end
484                 if( _ServerList_Entry_Compare( entry, ServerList_GetViewEntry(mid) ) )
485                         // the item has to be in the upper half
486                         end = mid;
487                 else
488                         // the item has to be in the lower half
489                         start = mid;
490         }
491         _ServerList_ViewList_Helper_InsertBefore( start + 1, entry );
492 }
493
494 static void ServerList_ViewList_Remove( serverlist_entry_t *entry )
495 {
496         int i;
497         for( i = 0; i < serverlist_viewcount; i++ )
498         {
499                 if (ServerList_GetViewEntry(i) == entry)
500                 {
501                         _ServerList_ViewList_Helper_Remove(i);
502                         break;
503                 }
504         }
505 }
506
507 void ServerList_RebuildViewList(void)
508 {
509         int i;
510
511         serverlist_viewcount = 0;
512         for( i = 0 ; i < serverlist_cachecount ; i++ ) {
513                 serverlist_entry_t *entry = &serverlist_cache[i];
514                 // also display entries that are currently being refreshed [11/8/2007 Black]
515                 if( entry->query == SQS_QUERIED || entry->query == SQS_REFRESHING )
516                         ServerList_ViewList_Insert( entry );
517         }
518 }
519
520 void ServerList_ResetMasks(void)
521 {
522         int i;
523
524         memset( &serverlist_andmasks, 0, sizeof( serverlist_andmasks ) );
525         memset( &serverlist_ormasks, 0, sizeof( serverlist_ormasks ) );
526         // numbots needs to be compared to -1 to always succeed
527         for(i = 0; i < SERVERLIST_ANDMASKCOUNT; ++i)
528                 serverlist_andmasks[i].info.numbots = -1;
529         for(i = 0; i < SERVERLIST_ORMASKCOUNT; ++i)
530                 serverlist_ormasks[i].info.numbots = -1;
531 }
532
533 void ServerList_GetPlayerStatistics(int *numplayerspointer, int *maxplayerspointer)
534 {
535         int i;
536         int numplayers = 0, maxplayers = 0;
537         for (i = 0;i < serverlist_cachecount;i++)
538         {
539                 if (serverlist_cache[i].query == SQS_QUERIED)
540                 {
541                         numplayers += serverlist_cache[i].info.numhumans;
542                         maxplayers += serverlist_cache[i].info.maxplayers;
543                 }
544         }
545         *numplayerspointer = numplayers;
546         *maxplayerspointer = maxplayers;
547 }
548
549 #if 0
550 static void _ServerList_Test(void)
551 {
552         int i;
553         if (serverlist_maxcachecount <= 1024)
554         {
555                 serverlist_maxcachecount = 1024;
556                 serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
557         }
558         for( i = 0 ; i < 1024 ; i++ ) {
559                 memset( &serverlist_cache[serverlist_cachecount], 0, sizeof( serverlist_entry_t ) );
560                 serverlist_cache[serverlist_cachecount].info.ping = 1000 + 1024 - i;
561                 dpsnprintf( serverlist_cache[serverlist_cachecount].info.name, sizeof(serverlist_cache[serverlist_cachecount].info.name), "Black's ServerList Test %i", i );
562                 serverlist_cache[serverlist_cachecount].finished = true;
563                 dpsnprintf( serverlist_cache[serverlist_cachecount].line1, sizeof(serverlist_cache[serverlist_cachecount].info.line1), "%i %s", serverlist_cache[serverlist_cachecount].info.ping, serverlist_cache[serverlist_cachecount].info.name );
564                 ServerList_ViewList_Insert( &serverlist_cache[serverlist_cachecount] );
565                 serverlist_cachecount++;
566         }
567 }
568 #endif
569
570 void ServerList_QueryList(qboolean resetcache, qboolean querydp, qboolean queryqw, qboolean consoleoutput)
571 {
572         masterquerytime = realtime;
573         masterquerycount = 0;
574         masterreplycount = 0;
575         if( resetcache ) {
576                 serverquerycount = 0;
577                 serverreplycount = 0;
578                 serverlist_cachecount = 0;
579                 serverlist_viewcount = 0;
580                 serverlist_maxcachecount = 0;
581                 serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
582         } else {
583                 // refresh all entries
584                 int n;
585                 for( n = 0 ; n < serverlist_cachecount ; n++ ) {
586                         serverlist_entry_t *entry = &serverlist_cache[ n ];
587                         entry->query = SQS_REFRESHING;
588                         entry->querycounter = 0;
589                 }
590         }
591         serverlist_consoleoutput = consoleoutput;
592
593         //_ServerList_Test();
594
595         NetConn_QueryMasters(querydp, queryqw);
596 }
597
598 // rest
599
600 int NetConn_Read(lhnetsocket_t *mysocket, void *data, int maxlength, lhnetaddress_t *peeraddress)
601 {
602         int length;
603         int i;
604         if (mysocket->address.addresstype == LHNETADDRESSTYPE_LOOP && netconn_mutex)
605                 Thread_LockMutex(netconn_mutex);
606         length = LHNET_Read(mysocket, data, maxlength, peeraddress);
607         if (mysocket->address.addresstype == LHNETADDRESSTYPE_LOOP && netconn_mutex)
608                 Thread_UnlockMutex(netconn_mutex);
609         if (length == 0)
610                 return 0;
611         if (cl_netpacketloss_receive.integer)
612                 for (i = 0;i < cl_numsockets;i++)
613                         if (cl_sockets[i] == mysocket && (rand() % 100) < cl_netpacketloss_receive.integer)
614                                 return 0;
615         if (developer_networking.integer)
616         {
617                 char addressstring[128], addressstring2[128];
618                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(mysocket), addressstring, sizeof(addressstring), true);
619                 if (length > 0)
620                 {
621                         LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
622                         Con_Printf("LHNET_Read(%p (%s), %p, %i, %p) = %i from %s:\n", (void *)mysocket, addressstring, (void *)data, maxlength, (void *)peeraddress, length, addressstring2);
623                         Com_HexDumpToConsole((unsigned char *)data, length);
624                 }
625                 else
626                         Con_Printf("LHNET_Read(%p (%s), %p, %i, %p) = %i\n", (void *)mysocket, addressstring, (void *)data, maxlength, (void *)peeraddress, length);
627         }
628         return length;
629 }
630
631 int NetConn_Write(lhnetsocket_t *mysocket, const void *data, int length, const lhnetaddress_t *peeraddress)
632 {
633         int ret;
634         int i;
635         if (cl_netpacketloss_send.integer)
636                 for (i = 0;i < cl_numsockets;i++)
637                         if (cl_sockets[i] == mysocket && (rand() % 100) < cl_netpacketloss_send.integer)
638                                 return length;
639         if (mysocket->address.addresstype == LHNETADDRESSTYPE_LOOP && netconn_mutex)
640                 Thread_LockMutex(netconn_mutex);
641         ret = LHNET_Write(mysocket, data, length, peeraddress);
642         if (mysocket->address.addresstype == LHNETADDRESSTYPE_LOOP && netconn_mutex)
643                 Thread_UnlockMutex(netconn_mutex);
644         if (developer_networking.integer)
645         {
646                 char addressstring[128], addressstring2[128];
647                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(mysocket), addressstring, sizeof(addressstring), true);
648                 LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
649                 Con_Printf("LHNET_Write(%p (%s), %p, %i, %p (%s)) = %i%s\n", (void *)mysocket, addressstring, (void *)data, length, (void *)peeraddress, addressstring2, length, ret == length ? "" : " (ERROR)");
650                 Com_HexDumpToConsole((unsigned char *)data, length);
651         }
652         return ret;
653 }
654
655 int NetConn_WriteString(lhnetsocket_t *mysocket, const char *string, const lhnetaddress_t *peeraddress)
656 {
657         // note this does not include the trailing NULL because we add that in the parser
658         return NetConn_Write(mysocket, string, (int)strlen(string), peeraddress);
659 }
660
661 qboolean NetConn_CanSend(netconn_t *conn)
662 {
663         conn->outgoing_packetcounter = (conn->outgoing_packetcounter + 1) % NETGRAPH_PACKETS;
664         conn->outgoing_netgraph[conn->outgoing_packetcounter].time            = realtime;
665         conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes = NETGRAPH_NOPACKET;
666         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
667         conn->outgoing_netgraph[conn->outgoing_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
668         if (realtime > conn->cleartime)
669                 return true;
670         else
671         {
672                 conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes = NETGRAPH_CHOKEDPACKET;
673                 return false;
674         }
675 }
676
677 int NetConn_SendUnreliableMessage(netconn_t *conn, sizebuf_t *data, protocolversion_t protocol, int rate, qboolean quakesignon_suppressreliables)
678 {
679         int totallen = 0;
680
681         // if this packet was supposedly choked, but we find ourselves sending one
682         // anyway, make sure the size counting starts at zero
683         // (this mostly happens on level changes and disconnects and such)
684         if (conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes == NETGRAPH_CHOKEDPACKET)
685                 conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes = NETGRAPH_NOPACKET;
686
687         if (protocol == PROTOCOL_QUAKEWORLD)
688         {
689                 int packetLen;
690                 qboolean sendreliable;
691
692                 // note that it is ok to send empty messages to the qw server,
693                 // otherwise it won't respond to us at all
694
695                 sendreliable = false;
696                 // if the remote side dropped the last reliable message, resend it
697                 if (conn->qw.incoming_acknowledged > conn->qw.last_reliable_sequence && conn->qw.incoming_reliable_acknowledged != conn->qw.reliable_sequence)
698                         sendreliable = true;
699                 // if the reliable transmit buffer is empty, copy the current message out
700                 if (!conn->sendMessageLength && conn->message.cursize)
701                 {
702                         memcpy (conn->sendMessage, conn->message.data, conn->message.cursize);
703                         conn->sendMessageLength = conn->message.cursize;
704                         SZ_Clear(&conn->message); // clear the message buffer
705                         conn->qw.reliable_sequence ^= 1;
706                         sendreliable = true;
707                 }
708                 // outgoing unreliable packet number, and outgoing reliable packet number (0 or 1)
709                 StoreLittleLong(sendbuffer, (unsigned int)conn->outgoing_unreliable_sequence | ((unsigned int)sendreliable<<31));
710                 // last received unreliable packet number, and last received reliable packet number (0 or 1)
711                 StoreLittleLong(sendbuffer + 4, (unsigned int)conn->qw.incoming_sequence | ((unsigned int)conn->qw.incoming_reliable_sequence<<31));
712                 packetLen = 8;
713                 conn->outgoing_unreliable_sequence++;
714                 // client sends qport in every packet
715                 if (conn == cls.netcon)
716                 {
717                         *((short *)(sendbuffer + 8)) = LittleShort(cls.qw_qport);
718                         packetLen += 2;
719                         // also update cls.qw_outgoing_sequence
720                         cls.qw_outgoing_sequence = conn->outgoing_unreliable_sequence;
721                 }
722                 if (packetLen + (sendreliable ? conn->sendMessageLength : 0) > 1400)
723                 {
724                         Con_Printf ("NetConn_SendUnreliableMessage: reliable message too big %u\n", data->cursize);
725                         return -1;
726                 }
727
728                 conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes += packetLen + 28;
729
730                 // add the reliable message if there is one
731                 if (sendreliable)
732                 {
733                         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes += conn->sendMessageLength + 28;
734                         memcpy(sendbuffer + packetLen, conn->sendMessage, conn->sendMessageLength);
735                         packetLen += conn->sendMessageLength;
736                         conn->qw.last_reliable_sequence = conn->outgoing_unreliable_sequence;
737                 }
738
739                 // add the unreliable message if possible
740                 if (packetLen + data->cursize <= 1400)
741                 {
742                         conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes += data->cursize + 28;
743                         memcpy(sendbuffer + packetLen, data->data, data->cursize);
744                         packetLen += data->cursize;
745                 }
746
747                 NetConn_Write(conn->mysocket, (void *)&sendbuffer, packetLen, &conn->peeraddress);
748
749                 packetsSent++;
750                 unreliableMessagesSent++;
751
752                 totallen += packetLen + 28;
753         }
754         else
755         {
756                 unsigned int packetLen;
757                 unsigned int dataLen;
758                 unsigned int eom;
759                 const void *sendme;
760                 size_t sendmelen;
761
762                 // if a reliable message fragment has been lost, send it again
763                 if (conn->sendMessageLength && (realtime - conn->lastSendTime) > 1.0)
764                 {
765                         if (conn->sendMessageLength <= MAX_PACKETFRAGMENT)
766                         {
767                                 dataLen = conn->sendMessageLength;
768                                 eom = NETFLAG_EOM;
769                         }
770                         else
771                         {
772                                 dataLen = MAX_PACKETFRAGMENT;
773                                 eom = 0;
774                         }
775
776                         packetLen = NET_HEADERSIZE + dataLen;
777
778                         StoreBigLong(sendbuffer, packetLen | (NETFLAG_DATA | eom));
779                         StoreBigLong(sendbuffer + 4, conn->nq.sendSequence - 1);
780                         memcpy(sendbuffer + NET_HEADERSIZE, conn->sendMessage, dataLen);
781
782                         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes += packetLen + 28;
783
784                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
785                         if (sendme && NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress) == (int)sendmelen)
786                         {
787                                 conn->lastSendTime = realtime;
788                                 packetsReSent++;
789                         }
790
791                         totallen += sendmelen + 28;
792                 }
793
794                 // if we have a new reliable message to send, do so
795                 if (!conn->sendMessageLength && conn->message.cursize && !quakesignon_suppressreliables)
796                 {
797                         if (conn->message.cursize > (int)sizeof(conn->sendMessage))
798                         {
799                                 Con_Printf("NetConn_SendUnreliableMessage: reliable message too big (%u > %u)\n", conn->message.cursize, (int)sizeof(conn->sendMessage));
800                                 conn->message.overflowed = true;
801                                 return -1;
802                         }
803
804                         if (developer_networking.integer && conn == cls.netcon)
805                         {
806                                 Con_Print("client sending reliable message to server:\n");
807                                 SZ_HexDumpToConsole(&conn->message);
808                         }
809
810                         memcpy(conn->sendMessage, conn->message.data, conn->message.cursize);
811                         conn->sendMessageLength = conn->message.cursize;
812                         SZ_Clear(&conn->message);
813
814                         if (conn->sendMessageLength <= MAX_PACKETFRAGMENT)
815                         {
816                                 dataLen = conn->sendMessageLength;
817                                 eom = NETFLAG_EOM;
818                         }
819                         else
820                         {
821                                 dataLen = MAX_PACKETFRAGMENT;
822                                 eom = 0;
823                         }
824
825                         packetLen = NET_HEADERSIZE + dataLen;
826
827                         StoreBigLong(sendbuffer, packetLen | (NETFLAG_DATA | eom));
828                         StoreBigLong(sendbuffer + 4, conn->nq.sendSequence);
829                         memcpy(sendbuffer + NET_HEADERSIZE, conn->sendMessage, dataLen);
830
831                         conn->nq.sendSequence++;
832
833                         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes += packetLen + 28;
834
835                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
836                         if(sendme)
837                                 NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress);
838
839                         conn->lastSendTime = realtime;
840                         packetsSent++;
841                         reliableMessagesSent++;
842
843                         totallen += sendmelen + 28;
844                 }
845
846                 // if we have an unreliable message to send, do so
847                 if (data->cursize)
848                 {
849                         packetLen = NET_HEADERSIZE + data->cursize;
850
851                         if (packetLen > (int)sizeof(sendbuffer))
852                         {
853                                 Con_Printf("NetConn_SendUnreliableMessage: message too big %u\n", data->cursize);
854                                 return -1;
855                         }
856
857                         StoreBigLong(sendbuffer, packetLen | NETFLAG_UNRELIABLE);
858                         StoreBigLong(sendbuffer + 4, conn->outgoing_unreliable_sequence);
859                         memcpy(sendbuffer + NET_HEADERSIZE, data->data, data->cursize);
860
861                         conn->outgoing_unreliable_sequence++;
862
863                         conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes += packetLen + 28;
864
865                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
866                         if(sendme)
867                                 NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress);
868
869                         packetsSent++;
870                         unreliableMessagesSent++;
871
872                         totallen += sendmelen + 28;
873                 }
874         }
875
876         // delay later packets to obey rate limit
877         if (conn->cleartime < realtime - 0.1)
878                 conn->cleartime = realtime - 0.1;
879         conn->cleartime = conn->cleartime + (double)totallen / (double)rate;
880         if (conn->cleartime < realtime)
881                 conn->cleartime = realtime;
882
883         return 0;
884 }
885
886 qboolean NetConn_HaveClientPorts(void)
887 {
888         return !!cl_numsockets;
889 }
890
891 qboolean NetConn_HaveServerPorts(void)
892 {
893         return !!sv_numsockets;
894 }
895
896 void NetConn_CloseClientPorts(void)
897 {
898         for (;cl_numsockets > 0;cl_numsockets--)
899                 if (cl_sockets[cl_numsockets - 1])
900                         LHNET_CloseSocket(cl_sockets[cl_numsockets - 1]);
901 }
902
903 void NetConn_OpenClientPort(const char *addressstring, lhnetaddresstype_t addresstype, int defaultport)
904 {
905         lhnetaddress_t address;
906         lhnetsocket_t *s;
907         int success;
908         char addressstring2[1024];
909         if (addressstring && addressstring[0])
910                 success = LHNETADDRESS_FromString(&address, addressstring, defaultport);
911         else
912                 success = LHNETADDRESS_FromPort(&address, addresstype, defaultport);
913         if (success)
914         {
915                 if ((s = LHNET_OpenSocket_Connectionless(&address)))
916                 {
917                         cl_sockets[cl_numsockets++] = s;
918                         LHNETADDRESS_ToString(LHNET_AddressFromSocket(s), addressstring2, sizeof(addressstring2), true);
919                         if (addresstype != LHNETADDRESSTYPE_LOOP)
920                                 Con_Printf("Client opened a socket on address %s\n", addressstring2);
921                 }
922                 else
923                 {
924                         LHNETADDRESS_ToString(&address, addressstring2, sizeof(addressstring2), true);
925                         Con_Printf("Client failed to open a socket on address %s\n", addressstring2);
926                 }
927         }
928         else
929                 Con_Printf("Client unable to parse address %s\n", addressstring);
930 }
931
932 void NetConn_OpenClientPorts(void)
933 {
934         int port;
935         NetConn_CloseClientPorts();
936         port = bound(0, cl_netport.integer, 65535);
937         if (cl_netport.integer != port)
938                 Cvar_SetValueQuick(&cl_netport, port);
939         if(port == 0)
940                 Con_Printf("Client using an automatically assigned port\n");
941         else
942                 Con_Printf("Client using port %i\n", port);
943         NetConn_OpenClientPort(NULL, LHNETADDRESSTYPE_LOOP, 2);
944         NetConn_OpenClientPort(net_address.string, LHNETADDRESSTYPE_INET4, port);
945 #ifdef SUPPORTIPV6
946         NetConn_OpenClientPort(net_address_ipv6.string, LHNETADDRESSTYPE_INET6, port);
947 #endif
948 }
949
950 void NetConn_CloseServerPorts(void)
951 {
952         for (;sv_numsockets > 0;sv_numsockets--)
953                 if (sv_sockets[sv_numsockets - 1])
954                         LHNET_CloseSocket(sv_sockets[sv_numsockets - 1]);
955 }
956
957 qboolean NetConn_OpenServerPort(const char *addressstring, lhnetaddresstype_t addresstype, int defaultport, int range)
958 {
959         lhnetaddress_t address;
960         lhnetsocket_t *s;
961         int port;
962         char addressstring2[1024];
963         int success;
964
965         for (port = defaultport; port <= defaultport + range; port++)
966         {
967                 if (addressstring && addressstring[0])
968                         success = LHNETADDRESS_FromString(&address, addressstring, port);
969                 else
970                         success = LHNETADDRESS_FromPort(&address, addresstype, port);
971                 if (success)
972                 {
973                         if ((s = LHNET_OpenSocket_Connectionless(&address)))
974                         {
975                                 sv_sockets[sv_numsockets++] = s;
976                                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(s), addressstring2, sizeof(addressstring2), true);
977                                 if (addresstype != LHNETADDRESSTYPE_LOOP)
978                                         Con_Printf("Server listening on address %s\n", addressstring2);
979                                 return true;
980                         }
981                         else
982                         {
983                                 LHNETADDRESS_ToString(&address, addressstring2, sizeof(addressstring2), true);
984                                 Con_Printf("Server failed to open socket on address %s\n", addressstring2);
985                         }
986                 }
987                 else
988                 {
989                         Con_Printf("Server unable to parse address %s\n", addressstring);
990                         // if it cant parse one address, it wont be able to parse another for sure
991                         return false;
992                 }
993         }
994         return false;
995 }
996
997 void NetConn_OpenServerPorts(int opennetports)
998 {
999         int port;
1000         NetConn_CloseServerPorts();
1001         NetConn_UpdateSockets();
1002         port = bound(0, sv_netport.integer, 65535);
1003         if (port == 0)
1004                 port = 26000;
1005         Con_Printf("Server using port %i\n", port);
1006         if (sv_netport.integer != port)
1007                 Cvar_SetValueQuick(&sv_netport, port);
1008         if (cls.state != ca_dedicated)
1009                 NetConn_OpenServerPort(NULL, LHNETADDRESSTYPE_LOOP, 1, 1);
1010         if (opennetports)
1011         {
1012 #ifdef SUPPORTIPV6
1013                 qboolean ip4success = NetConn_OpenServerPort(net_address.string, LHNETADDRESSTYPE_INET4, port, 100);
1014                 NetConn_OpenServerPort(net_address_ipv6.string, LHNETADDRESSTYPE_INET6, port, ip4success ? 1 : 100);
1015 #else
1016                 NetConn_OpenServerPort(net_address.string, LHNETADDRESSTYPE_INET4, port, 100);
1017 #endif
1018         }
1019         if (sv_numsockets == 0)
1020                 Host_Error("NetConn_OpenServerPorts: unable to open any ports!");
1021 }
1022
1023 lhnetsocket_t *NetConn_ChooseClientSocketForAddress(lhnetaddress_t *address)
1024 {
1025         int i, a = LHNETADDRESS_GetAddressType(address);
1026         for (i = 0;i < cl_numsockets;i++)
1027                 if (cl_sockets[i] && LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i])) == a)
1028                         return cl_sockets[i];
1029         return NULL;
1030 }
1031
1032 lhnetsocket_t *NetConn_ChooseServerSocketForAddress(lhnetaddress_t *address)
1033 {
1034         int i, a = LHNETADDRESS_GetAddressType(address);
1035         for (i = 0;i < sv_numsockets;i++)
1036                 if (sv_sockets[i] && LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(sv_sockets[i])) == a)
1037                         return sv_sockets[i];
1038         return NULL;
1039 }
1040
1041 netconn_t *NetConn_Open(lhnetsocket_t *mysocket, lhnetaddress_t *peeraddress)
1042 {
1043         netconn_t *conn;
1044         conn = (netconn_t *)Mem_Alloc(netconn_mempool, sizeof(*conn));
1045         conn->mysocket = mysocket;
1046         conn->peeraddress = *peeraddress;
1047         conn->lastMessageTime = realtime;
1048         conn->message.data = conn->messagedata;
1049         conn->message.maxsize = sizeof(conn->messagedata);
1050         conn->message.cursize = 0;
1051         // LordHavoc: (inspired by ProQuake) use a short connect timeout to
1052         // reduce effectiveness of connection request floods
1053         conn->timeout = realtime + net_connecttimeout.value;
1054         LHNETADDRESS_ToString(&conn->peeraddress, conn->address, sizeof(conn->address), true);
1055         conn->next = netconn_list;
1056         netconn_list = conn;
1057         return conn;
1058 }
1059
1060 void NetConn_ClearConnectFlood(lhnetaddress_t *peeraddress);
1061 void NetConn_Close(netconn_t *conn)
1062 {
1063         netconn_t *c;
1064         // remove connection from list
1065
1066         // allow the client to reconnect immediately
1067         NetConn_ClearConnectFlood(&(conn->peeraddress));
1068
1069         if (conn == netconn_list)
1070                 netconn_list = conn->next;
1071         else
1072         {
1073                 for (c = netconn_list;c;c = c->next)
1074                 {
1075                         if (c->next == conn)
1076                         {
1077                                 c->next = conn->next;
1078                                 break;
1079                         }
1080                 }
1081                 // not found in list, we'll avoid crashing here...
1082                 if (!c)
1083                         return;
1084         }
1085         // free connection
1086         Mem_Free(conn);
1087 }
1088
1089 static int clientport = -1;
1090 static int clientport2 = -1;
1091 static int hostport = -1;
1092 void NetConn_UpdateSockets(void)
1093 {
1094         int i, j;
1095
1096         if (cls.state != ca_dedicated)
1097         {
1098                 if (clientport2 != cl_netport.integer)
1099                 {
1100                         clientport2 = cl_netport.integer;
1101                         if (cls.state == ca_connected)
1102                                 Con_Print("Changing \"cl_port\" will not take effect until you reconnect.\n");
1103                 }
1104                 if (cls.state == ca_disconnected && clientport != clientport2)
1105                 {
1106                         clientport = clientport2;
1107                         NetConn_CloseClientPorts();
1108                 }
1109                 if (cl_numsockets == 0)
1110                         NetConn_OpenClientPorts();
1111         }
1112
1113         if (hostport != sv_netport.integer)
1114         {
1115                 hostport = sv_netport.integer;
1116                 if (sv.active)
1117                         Con_Print("Changing \"port\" will not take effect until \"map\" command is executed.\n");
1118         }
1119
1120         for (j = 0;j < MAX_RCONS;j++)
1121         {
1122                 i = (cls.rcon_ringpos + j + 1) % MAX_RCONS;
1123                 if(cls.rcon_commands[i][0])
1124                 {
1125                         if(realtime > cls.rcon_timeout[i])
1126                         {
1127                                 char s[128];
1128                                 LHNETADDRESS_ToString(&cls.rcon_addresses[i], s, sizeof(s), true);
1129                                 Con_Printf("rcon to %s (for command %s) failed: challenge request timed out\n", s, cls.rcon_commands[i]);
1130                                 cls.rcon_commands[i][0] = 0;
1131                                 --cls.rcon_trying;
1132                                 break;
1133                         }
1134                 }
1135         }
1136 }
1137
1138 static int NetConn_ReceivedMessage(netconn_t *conn, const unsigned char *data, size_t length, protocolversion_t protocol, double newtimeout)
1139 {
1140         int originallength = length;
1141         if (length < 8)
1142                 return 0;
1143
1144         if (protocol == PROTOCOL_QUAKEWORLD)
1145         {
1146                 int sequence, sequence_ack;
1147                 int reliable_ack, reliable_message;
1148                 int count;
1149                 //int qport;
1150
1151                 sequence = LittleLong(*((int *)(data + 0)));
1152                 sequence_ack = LittleLong(*((int *)(data + 4)));
1153                 data += 8;
1154                 length -= 8;
1155
1156                 if (conn != cls.netcon)
1157                 {
1158                         // server only
1159                         if (length < 2)
1160                                 return 0;
1161                         // TODO: use qport to identify that this client really is who they say they are?  (and elsewhere in the code to identify the connection without a port match?)
1162                         //qport = LittleShort(*((int *)(data + 8)));
1163                         data += 2;
1164                         length -= 2;
1165                 }
1166
1167                 packetsReceived++;
1168                 reliable_message = (sequence >> 31) & 1;
1169                 reliable_ack = (sequence_ack >> 31) & 1;
1170                 sequence &= ~(1<<31);
1171                 sequence_ack &= ~(1<<31);
1172                 if (sequence <= conn->qw.incoming_sequence)
1173                 {
1174                         //Con_DPrint("Got a stale datagram\n");
1175                         return 0;
1176                 }
1177                 count = sequence - (conn->qw.incoming_sequence + 1);
1178                 if (count > 0)
1179                 {
1180                         droppedDatagrams += count;
1181                         //Con_DPrintf("Dropped %u datagram(s)\n", count);
1182                         while (count--)
1183                         {
1184                                 conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1185                                 conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1186                                 conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = NETGRAPH_LOSTPACKET;
1187                                 conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1188                                 conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1189                         }
1190                 }
1191                 conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1192                 conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1193                 conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = originallength + 28;
1194                 conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1195                 conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1196                 if (reliable_ack == conn->qw.reliable_sequence)
1197                 {
1198                         // received, now we will be able to send another reliable message
1199                         conn->sendMessageLength = 0;
1200                         reliableMessagesReceived++;
1201                 }
1202                 conn->qw.incoming_sequence = sequence;
1203                 if (conn == cls.netcon)
1204                         cls.qw_incoming_sequence = conn->qw.incoming_sequence;
1205                 conn->qw.incoming_acknowledged = sequence_ack;
1206                 conn->qw.incoming_reliable_acknowledged = reliable_ack;
1207                 if (reliable_message)
1208                         conn->qw.incoming_reliable_sequence ^= 1;
1209                 conn->lastMessageTime = realtime;
1210                 conn->timeout = realtime + newtimeout;
1211                 unreliableMessagesReceived++;
1212                 SZ_Clear(&net_message);
1213                 SZ_Write(&net_message, data, length);
1214                 MSG_BeginReading();
1215                 return 2;
1216         }
1217         else
1218         {
1219                 unsigned int count;
1220                 unsigned int flags;
1221                 unsigned int sequence;
1222                 size_t qlength;
1223                 const void *sendme;
1224                 size_t sendmelen;
1225
1226                 originallength = length;
1227                 data = (const unsigned char *) Crypto_DecryptPacket(&conn->crypto, data, length, cryptoreadbuffer, &length, sizeof(cryptoreadbuffer));
1228                 if(!data)
1229                         return 0;
1230                 if(length < 8)
1231                         return 0;
1232
1233                 qlength = (unsigned int)BuffBigLong(data);
1234                 flags = qlength & ~NETFLAG_LENGTH_MASK;
1235                 qlength &= NETFLAG_LENGTH_MASK;
1236                 // control packets were already handled
1237                 if (!(flags & NETFLAG_CTL) && qlength == length)
1238                 {
1239                         sequence = BuffBigLong(data + 4);
1240                         packetsReceived++;
1241                         data += 8;
1242                         length -= 8;
1243                         if (flags & NETFLAG_UNRELIABLE)
1244                         {
1245                                 if (sequence >= conn->nq.unreliableReceiveSequence)
1246                                 {
1247                                         if (sequence > conn->nq.unreliableReceiveSequence)
1248                                         {
1249                                                 count = sequence - conn->nq.unreliableReceiveSequence;
1250                                                 droppedDatagrams += count;
1251                                                 //Con_DPrintf("Dropped %u datagram(s)\n", count);
1252                                                 while (count--)
1253                                                 {
1254                                                         conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1255                                                         conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1256                                                         conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = NETGRAPH_LOSTPACKET;
1257                                                         conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1258                                                         conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1259                                                 }
1260                                         }
1261                                         conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1262                                         conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1263                                         conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = originallength + 28;
1264                                         conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1265                                         conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1266                                         conn->nq.unreliableReceiveSequence = sequence + 1;
1267                                         conn->lastMessageTime = realtime;
1268                                         conn->timeout = realtime + newtimeout;
1269                                         unreliableMessagesReceived++;
1270                                         if (length > 0)
1271                                         {
1272                                                 SZ_Clear(&net_message);
1273                                                 SZ_Write(&net_message, data, length);
1274                                                 MSG_BeginReading();
1275                                                 return 2;
1276                                         }
1277                                 }
1278                                 //else
1279                                 //      Con_DPrint("Got a stale datagram\n");
1280                                 return 1;
1281                         }
1282                         else if (flags & NETFLAG_ACK)
1283                         {
1284                                 conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes += originallength + 28;
1285                                 if (sequence == (conn->nq.sendSequence - 1))
1286                                 {
1287                                         if (sequence == conn->nq.ackSequence)
1288                                         {
1289                                                 conn->nq.ackSequence++;
1290                                                 if (conn->nq.ackSequence != conn->nq.sendSequence)
1291                                                         Con_DPrint("ack sequencing error\n");
1292                                                 conn->lastMessageTime = realtime;
1293                                                 conn->timeout = realtime + newtimeout;
1294                                                 if (conn->sendMessageLength > MAX_PACKETFRAGMENT)
1295                                                 {
1296                                                         unsigned int packetLen;
1297                                                         unsigned int dataLen;
1298                                                         unsigned int eom;
1299
1300                                                         conn->sendMessageLength -= MAX_PACKETFRAGMENT;
1301                                                         memmove(conn->sendMessage, conn->sendMessage+MAX_PACKETFRAGMENT, conn->sendMessageLength);
1302
1303                                                         if (conn->sendMessageLength <= MAX_PACKETFRAGMENT)
1304                                                         {
1305                                                                 dataLen = conn->sendMessageLength;
1306                                                                 eom = NETFLAG_EOM;
1307                                                         }
1308                                                         else
1309                                                         {
1310                                                                 dataLen = MAX_PACKETFRAGMENT;
1311                                                                 eom = 0;
1312                                                         }
1313
1314                                                         packetLen = NET_HEADERSIZE + dataLen;
1315
1316                                                         StoreBigLong(sendbuffer, packetLen | (NETFLAG_DATA | eom));
1317                                                         StoreBigLong(sendbuffer + 4, conn->nq.sendSequence);
1318                                                         memcpy(sendbuffer + NET_HEADERSIZE, conn->sendMessage, dataLen);
1319
1320                                                         conn->nq.sendSequence++;
1321
1322                                                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
1323                                                         if (sendme && NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress) == (int)sendmelen)
1324                                                         {
1325                                                                 conn->lastSendTime = realtime;
1326                                                                 packetsSent++;
1327                                                         }
1328                                                 }
1329                                                 else
1330                                                         conn->sendMessageLength = 0;
1331                                         }
1332                                         //else
1333                                         //      Con_DPrint("Duplicate ACK received\n");
1334                                 }
1335                                 //else
1336                                 //      Con_DPrint("Stale ACK received\n");
1337                                 return 1;
1338                         }
1339                         else if (flags & NETFLAG_DATA)
1340                         {
1341                                 unsigned char temppacket[8];
1342                                 conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   += originallength + 28;
1343                                 conn->outgoing_netgraph[conn->outgoing_packetcounter].ackbytes        += 8 + 28;
1344                                 StoreBigLong(temppacket, 8 | NETFLAG_ACK);
1345                                 StoreBigLong(temppacket + 4, sequence);
1346                                 sendme = Crypto_EncryptPacket(&conn->crypto, temppacket, 8, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
1347                                 if(sendme)
1348                                         NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress);
1349                                 if (sequence == conn->nq.receiveSequence)
1350                                 {
1351                                         conn->lastMessageTime = realtime;
1352                                         conn->timeout = realtime + newtimeout;
1353                                         conn->nq.receiveSequence++;
1354                                         if( conn->receiveMessageLength + length <= (int)sizeof( conn->receiveMessage ) ) {
1355                                                 memcpy(conn->receiveMessage + conn->receiveMessageLength, data, length);
1356                                                 conn->receiveMessageLength += length;
1357                                         } else {
1358                                                 Con_Printf( "Reliable message (seq: %i) too big for message buffer!\n"
1359                                                                         "Dropping the message!\n", sequence );
1360                                                 conn->receiveMessageLength = 0;
1361                                                 return 1;
1362                                         }
1363                                         if (flags & NETFLAG_EOM)
1364                                         {
1365                                                 reliableMessagesReceived++;
1366                                                 length = conn->receiveMessageLength;
1367                                                 conn->receiveMessageLength = 0;
1368                                                 if (length > 0)
1369                                                 {
1370                                                         SZ_Clear(&net_message);
1371                                                         SZ_Write(&net_message, conn->receiveMessage, length);
1372                                                         MSG_BeginReading();
1373                                                         return 2;
1374                                                 }
1375                                         }
1376                                 }
1377                                 else
1378                                         receivedDuplicateCount++;
1379                                 return 1;
1380                         }
1381                 }
1382         }
1383         return 0;
1384 }
1385
1386 void NetConn_ConnectionEstablished(lhnetsocket_t *mysocket, lhnetaddress_t *peeraddress, protocolversion_t initialprotocol)
1387 {
1388         crypto_t *crypto;
1389         cls.connect_trying = false;
1390         M_Update_Return_Reason("");
1391         // the connection request succeeded, stop current connection and set up a new connection
1392         CL_Disconnect();
1393         // if we're connecting to a remote server, shut down any local server
1394         if (LHNETADDRESS_GetAddressType(peeraddress) != LHNETADDRESSTYPE_LOOP && sv.active)
1395                 Host_ShutdownServer ();
1396         // allocate a net connection to keep track of things
1397         cls.netcon = NetConn_Open(mysocket, peeraddress);
1398         crypto = &cls.crypto;
1399         if(crypto && crypto->authenticated)
1400         {
1401                 Crypto_ServerFinishInstance(&cls.netcon->crypto, crypto);
1402                 Con_Printf("%s connection to %s has been established: server is %s@%.*s, I am %.*s@%.*s\n",
1403                                 crypto->use_aes ? "Encrypted" : "Authenticated",
1404                                 cls.netcon->address,
1405                                 crypto->server_idfp[0] ? crypto->server_idfp : "-",
1406                                 crypto_keyfp_recommended_length, crypto->server_keyfp[0] ? crypto->server_keyfp : "-",
1407                                 crypto_keyfp_recommended_length, crypto->client_idfp[0] ? crypto->client_idfp : "-",
1408                                 crypto_keyfp_recommended_length, crypto->client_keyfp[0] ? crypto->client_keyfp : "-"
1409                                 );
1410         }
1411         Con_Printf("Connection accepted to %s\n", cls.netcon->address);
1412         key_dest = key_game;
1413         m_state = m_none;
1414         cls.demonum = -1;                       // not in the demo loop now
1415         cls.state = ca_connected;
1416         cls.signon = 0;                         // need all the signon messages before playing
1417         cls.protocol = initialprotocol;
1418         // reset move sequence numbering on this new connection
1419         cls.servermovesequence = 0;
1420         if (cls.protocol == PROTOCOL_QUAKEWORLD)
1421                 Cmd_ForwardStringToServer("new");
1422         if (cls.protocol == PROTOCOL_QUAKE)
1423         {
1424                 // write a keepalive (clc_nop) as it seems to greatly improve the
1425                 // chances of connecting to a netquake server
1426                 sizebuf_t msg;
1427                 unsigned char buf[4];
1428                 memset(&msg, 0, sizeof(msg));
1429                 msg.data = buf;
1430                 msg.maxsize = sizeof(buf);
1431                 MSG_WriteChar(&msg, clc_nop);
1432                 NetConn_SendUnreliableMessage(cls.netcon, &msg, cls.protocol, 10000, false);
1433         }
1434 }
1435
1436 int NetConn_IsLocalGame(void)
1437 {
1438         if (cls.state == ca_connected && sv.active && cl.maxclients == 1)
1439                 return true;
1440         return false;
1441 }
1442
1443 static int NetConn_ClientParsePacket_ServerList_ProcessReply(const char *addressstring)
1444 {
1445         int n;
1446         int pingtime;
1447         serverlist_entry_t *entry = NULL;
1448
1449         // search the cache for this server and update it
1450         for (n = 0;n < serverlist_cachecount;n++) {
1451                 entry = &serverlist_cache[ n ];
1452                 if (!strcmp(addressstring, entry->info.cname))
1453                         break;
1454         }
1455
1456         if (n == serverlist_cachecount)
1457         {
1458                 // LAN search doesnt require an answer from the master server so we wont
1459                 // know the ping nor will it be initialized already...
1460
1461                 // find a slot
1462                 if (serverlist_cachecount == SERVERLIST_TOTALSIZE)
1463                         return -1;
1464
1465                 if (serverlist_maxcachecount <= serverlist_cachecount)
1466                 {
1467                         serverlist_maxcachecount += 64;
1468                         serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
1469                 }
1470                 entry = &serverlist_cache[n];
1471
1472                 memset(entry, 0, sizeof(*entry));
1473                 // store the data the engine cares about (address and ping)
1474                 strlcpy(entry->info.cname, addressstring, sizeof(entry->info.cname));
1475                 entry->info.ping = 100000;
1476                 entry->querytime = realtime;
1477                 // if not in the slist menu we should print the server to console
1478                 if (serverlist_consoleoutput)
1479                         Con_Printf("querying %s\n", addressstring);
1480                 ++serverlist_cachecount;
1481         }
1482         // if this is the first reply from this server, count it as having replied
1483         pingtime = (int)((realtime - entry->querytime) * 1000.0 + 0.5);
1484         pingtime = bound(0, pingtime, 9999);
1485         if (entry->query == SQS_REFRESHING) {
1486                 entry->info.ping = pingtime;
1487                 entry->query = SQS_QUERIED;
1488         } else {
1489                 // convert to unsigned to catch the -1
1490                 // I still dont like this but its better than the old 10000 magic ping number - as in easier to type and read :( [11/8/2007 Black]
1491                 entry->info.ping = min((unsigned) entry->info.ping, (unsigned) pingtime);
1492                 serverreplycount++;
1493         }
1494         
1495         // other server info is updated by the caller
1496         return n;
1497 }
1498
1499 static void NetConn_ClientParsePacket_ServerList_UpdateCache(int n)
1500 {
1501         serverlist_entry_t *entry = &serverlist_cache[n];
1502         serverlist_info_t *info = &entry->info;
1503         // update description strings for engine menu and console output
1504         dpsnprintf(entry->line1, sizeof(serverlist_cache[n].line1), "^%c%5d^7 ^%c%3u^7/%3u %-65.65s", info->ping >= 300 ? '1' : (info->ping >= 200 ? '3' : '7'), (int)info->ping, ((info->numhumans > 0 && info->numhumans < info->maxplayers) ? (info->numhumans >= 4 ? '7' : '3') : '1'), info->numplayers, info->maxplayers, info->name);
1505         dpsnprintf(entry->line2, sizeof(serverlist_cache[n].line2), "^4%-21.21s %-19.19s ^%c%-17.17s^4 %-20.20s", info->cname, info->game,
1506                         (
1507                          info->gameversion != gameversion.integer
1508                          &&
1509                          !(
1510                                     gameversion_min.integer >= 0 // min/max range set by user/mod?
1511                                  && gameversion_max.integer >= 0
1512                                  && gameversion_min.integer <= info->gameversion // version of server in min/max range?
1513                                  && gameversion_max.integer >= info->gameversion
1514                           )
1515                         ) ? '1' : '4',
1516                         info->mod, info->map);
1517         if (entry->query == SQS_QUERIED)
1518         {
1519                 if(!serverlist_paused)
1520                         ServerList_ViewList_Remove(entry);
1521         }
1522         // if not in the slist menu we should print the server to console (if wanted)
1523         else if( serverlist_consoleoutput )
1524                 Con_Printf("%s\n%s\n", serverlist_cache[n].line1, serverlist_cache[n].line2);
1525         // and finally, update the view set
1526         if(!serverlist_paused)
1527                 ServerList_ViewList_Insert( entry );
1528         //      update the entry's state
1529         serverlist_cache[n].query = SQS_QUERIED;
1530 }
1531
1532 // returns true, if it's sensible to continue the processing
1533 static qboolean NetConn_ClientParsePacket_ServerList_PrepareQuery( int protocol, const char *ipstring, qboolean isfavorite ) {
1534         int n;
1535         serverlist_entry_t *entry;
1536
1537         //      ignore the rest of the message if the serverlist is full
1538         if( serverlist_cachecount == SERVERLIST_TOTALSIZE )
1539                 return false;
1540         //      also ignore     it      if      we      have already queried    it      (other master server    response)
1541         for( n =        0 ; n   < serverlist_cachecount ; n++   )
1542                 if( !strcmp( ipstring, serverlist_cache[ n ].info.cname ) )
1543                         break;
1544
1545         if( n < serverlist_cachecount ) {
1546                 // the entry has already been queried once or 
1547                 return true;
1548         }
1549
1550         if (serverlist_maxcachecount <= n)
1551         {
1552                 serverlist_maxcachecount += 64;
1553                 serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
1554         }
1555
1556         entry = &serverlist_cache[n];
1557
1558         memset(entry, 0, sizeof(entry));
1559         entry->protocol =       protocol;
1560         //      store   the data        the engine cares about (address and     ping)
1561         strlcpy (entry->info.cname, ipstring, sizeof(entry->info.cname));
1562
1563         entry->info.isfavorite = isfavorite;
1564         
1565         // no, then reset the ping right away
1566         entry->info.ping = -1;
1567         // we also want to increase the serverlist_cachecount then
1568         serverlist_cachecount++;
1569         serverquerycount++;
1570
1571         entry->query =  SQS_QUERYING;
1572
1573         return true;
1574 }
1575
1576 static void NetConn_ClientParsePacket_ServerList_ParseDPList(lhnetaddress_t *senderaddress, const unsigned char *data, int length, qboolean isextended)
1577 {
1578         masterreplycount++;
1579         if (serverlist_consoleoutput)
1580                 Con_Printf("received DarkPlaces %sserver list...\n", isextended ? "extended " : "");
1581         while (length >= 7)
1582         {
1583                 char ipstring [128];
1584
1585                 // IPv4 address
1586                 if (data[0] == '\\')
1587                 {
1588                         unsigned short port = data[5] * 256 + data[6];
1589
1590                         if (port != 0 && (data[1] != 0xFF || data[2] != 0xFF || data[3] != 0xFF || data[4] != 0xFF))
1591                                 dpsnprintf (ipstring, sizeof (ipstring), "%u.%u.%u.%u:%hu", data[1], data[2], data[3], data[4], port);
1592
1593                         // move on to next address in packet
1594                         data += 7;
1595                         length -= 7;
1596                 }
1597                 // IPv6 address
1598                 else if (data[0] == '/' && isextended && length >= 19)
1599                 {
1600                         unsigned short port = data[17] * 256 + data[18];
1601
1602                         if (port != 0)
1603                         {
1604 #ifdef WHY_JUST_WHY
1605                                 const char *ifname;
1606
1607                                 /// \TODO: make some basic checks of the IP address (broadcast, ...)
1608
1609                                 ifname = LHNETADDRESS_GetInterfaceName(senderaddress);
1610                                 if (ifname != NULL)
1611                                 {
1612                                         dpsnprintf (ipstring, sizeof (ipstring), "[%x:%x:%x:%x:%x:%x:%x:%x%%%s]:%hu",
1613                                                                 (data[1] << 8) | data[2], (data[3] << 8) | data[4], (data[5] << 8) | data[6], (data[7] << 8) | data[8],
1614                                                                 (data[9] << 8) | data[10], (data[11] << 8) | data[12], (data[13] << 8) | data[14], (data[15] << 8) | data[16],
1615                                                                 ifname, port);
1616                                 }
1617                                 else
1618 #endif
1619                                 {
1620                                         dpsnprintf (ipstring, sizeof (ipstring), "[%x:%x:%x:%x:%x:%x:%x:%x]:%hu",
1621                                                                 (data[1] << 8) | data[2], (data[3] << 8) | data[4], (data[5] << 8) | data[6], (data[7] << 8) | data[8],
1622                                                                 (data[9] << 8) | data[10], (data[11] << 8) | data[12], (data[13] << 8) | data[14], (data[15] << 8) | data[16],
1623                                                                 port);
1624                                 }
1625                         }
1626
1627                         // move on to next address in packet
1628                         data += 19;
1629                         length -= 19;
1630                 }
1631                 else
1632                 {
1633                         Con_Print("Error while parsing the server list\n");
1634                         break;
1635                 }
1636
1637                 if (serverlist_consoleoutput && developer_networking.integer)
1638                         Con_Printf("Requesting info from DarkPlaces server %s\n", ipstring);
1639                 
1640                 if( !NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_DARKPLACES7, ipstring, false ) ) {
1641                         break;
1642                 }
1643
1644         }
1645
1646         // begin or resume serverlist queries
1647         serverlist_querysleep = false;
1648         serverlist_querywaittime = realtime + 3;
1649 }
1650
1651 static int NetConn_ClientParsePacket(lhnetsocket_t *mysocket, unsigned char *data, int length, lhnetaddress_t *peeraddress)
1652 {
1653         qboolean fromserver;
1654         int ret, c, control;
1655         const char *s;
1656         char *string, addressstring2[128], ipstring[32];
1657         char stringbuf[16384];
1658         char senddata[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
1659         size_t sendlength;
1660
1661         // quakeworld ingame packet
1662         fromserver = cls.netcon && mysocket == cls.netcon->mysocket && !LHNETADDRESS_Compare(&cls.netcon->peeraddress, peeraddress);
1663
1664         // convert the address to a string incase we need it
1665         LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
1666
1667         if (length >= 5 && data[0] == 255 && data[1] == 255 && data[2] == 255 && data[3] == 255)
1668         {
1669                 // received a command string - strip off the packaging and put it
1670                 // into our string buffer with NULL termination
1671                 data += 4;
1672                 length -= 4;
1673                 length = min(length, (int)sizeof(stringbuf) - 1);
1674                 memcpy(stringbuf, data, length);
1675                 stringbuf[length] = 0;
1676                 string = stringbuf;
1677
1678                 if (developer_networking.integer)
1679                 {
1680                         Con_Printf("NetConn_ClientParsePacket: %s sent us a command:\n", addressstring2);
1681                         Com_HexDumpToConsole(data, length);
1682                 }
1683
1684                 sendlength = sizeof(senddata) - 4;
1685                 switch(Crypto_ClientParsePacket(string, length, senddata+4, &sendlength, peeraddress))
1686                 {
1687                         case CRYPTO_NOMATCH:
1688                                 // nothing to do
1689                                 break;
1690                         case CRYPTO_MATCH:
1691                                 if(sendlength)
1692                                 {
1693                                         memcpy(senddata, "\377\377\377\377", 4);
1694                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
1695                                 }
1696                                 break;
1697                         case CRYPTO_DISCARD:
1698                                 if(sendlength)
1699                                 {
1700                                         memcpy(senddata, "\377\377\377\377", 4);
1701                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
1702                                 }
1703                                 return true;
1704                                 break;
1705                         case CRYPTO_REPLACE:
1706                                 string = senddata+4;
1707                                 length = sendlength;
1708                                 break;
1709                 }
1710
1711                 if (length >= 10 && !memcmp(string, "challenge ", 10) && cls.rcon_trying)
1712                 {
1713                         int i = 0, j;
1714                         for (j = 0;j < MAX_RCONS;j++)
1715                         {
1716                                 // note: this value from i is used outside the loop too...
1717                                 i = (cls.rcon_ringpos + j) % MAX_RCONS;
1718                                 if(cls.rcon_commands[i][0])
1719                                         if (!LHNETADDRESS_Compare(peeraddress, &cls.rcon_addresses[i]))
1720                                                 break;
1721                         }
1722                         if (j < MAX_RCONS)
1723                         {
1724                                 char buf[1500];
1725                                 char argbuf[1500];
1726                                 const char *e;
1727                                 int n;
1728                                 dpsnprintf(argbuf, sizeof(argbuf), "%s %s", string + 10, cls.rcon_commands[i]);
1729                                 memcpy(buf, "\377\377\377\377srcon HMAC-MD4 CHALLENGE ", 29);
1730
1731                                 e = strchr(rcon_password.string, ' ');
1732                                 n = e ? e-rcon_password.string : (int)strlen(rcon_password.string);
1733
1734                                 if(HMAC_MDFOUR_16BYTES((unsigned char *) (buf + 29), (unsigned char *) argbuf, strlen(argbuf), (unsigned char *) rcon_password.string, n))
1735                                 {
1736                                         int k;
1737                                         buf[45] = ' ';
1738                                         strlcpy(buf + 46, argbuf, sizeof(buf) - 46);
1739                                         NetConn_Write(mysocket, buf, 46 + strlen(buf + 46), peeraddress);
1740                                         cls.rcon_commands[i][0] = 0;
1741                                         --cls.rcon_trying;
1742
1743                                         for (k = 0;k < MAX_RCONS;k++)
1744                                                 if(cls.rcon_commands[k][0])
1745                                                         if (!LHNETADDRESS_Compare(peeraddress, &cls.rcon_addresses[k]))
1746                                                                 break;
1747                                         if(k < MAX_RCONS)
1748                                         {
1749                                                 int l;
1750                                                 NetConn_WriteString(mysocket, "\377\377\377\377getchallenge", peeraddress);
1751                                                 // extend the timeout on other requests as we asked for a challenge
1752                                                 for (l = 0;l < MAX_RCONS;l++)
1753                                                         if(cls.rcon_commands[l][0])
1754                                                                 if (!LHNETADDRESS_Compare(peeraddress, &cls.rcon_addresses[l]))
1755                                                                         cls.rcon_timeout[l] = realtime + rcon_secure_challengetimeout.value;
1756                                         }
1757
1758                                         return true; // we used up the challenge, so we can't use this oen for connecting now anyway
1759                                 }
1760                         }
1761                 }
1762                 if (length >= 10 && !memcmp(string, "challenge ", 10) && cls.connect_trying)
1763                 {
1764                         // darkplaces or quake3
1765                         char protocolnames[1400];
1766                         Protocol_Names(protocolnames, sizeof(protocolnames));
1767                         Con_DPrintf("\"%s\" received, sending connect request back to %s\n", string, addressstring2);
1768                         M_Update_Return_Reason("Got challenge response");
1769                         // update the server IP in the userinfo (QW servers expect this, and it is used by the reconnect command)
1770                         InfoString_SetValue(cls.userinfo, sizeof(cls.userinfo), "*ip", addressstring2);
1771                         // TODO: add userinfo stuff here instead of using NQ commands?
1772                         NetConn_WriteString(mysocket, va("\377\377\377\377connect\\protocol\\darkplaces 3\\protocols\\%s%s\\challenge\\%s", protocolnames, cls.connect_userinfo, string + 10), peeraddress);
1773                         return true;
1774                 }
1775                 if (length == 6 && !memcmp(string, "accept", 6) && cls.connect_trying)
1776                 {
1777                         // darkplaces or quake3
1778                         M_Update_Return_Reason("Accepted");
1779                         NetConn_ConnectionEstablished(mysocket, peeraddress, PROTOCOL_DARKPLACES3);
1780                         return true;
1781                 }
1782                 if (length > 7 && !memcmp(string, "reject ", 7) && cls.connect_trying)
1783                 {
1784                         char rejectreason[128];
1785                         cls.connect_trying = false;
1786                         string += 7;
1787                         length = min(length - 7, (int)sizeof(rejectreason) - 1);
1788                         memcpy(rejectreason, string, length);
1789                         rejectreason[length] = 0;
1790                         M_Update_Return_Reason(rejectreason);
1791                         return true;
1792                 }
1793                 if (length >= 15 && !memcmp(string, "statusResponse\x0A", 15))
1794                 {
1795                         serverlist_info_t *info;
1796                         char *p;
1797                         int n;
1798
1799                         string += 15;
1800                         // search the cache for this server and update it
1801                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
1802                         if (n < 0)
1803                                 return true;
1804
1805                         info = &serverlist_cache[n].info;
1806                         info->game[0] = 0;
1807                         info->mod[0]  = 0;
1808                         info->map[0]  = 0;
1809                         info->name[0] = 0;
1810                         info->qcstatus[0] = 0;
1811                         info->players[0] = 0;
1812                         info->protocol = -1;
1813                         info->numplayers = 0;
1814                         info->numbots = -1;
1815                         info->maxplayers  = 0;
1816                         info->gameversion = 0;
1817
1818                         p = strchr(string, '\n');
1819                         if(p)
1820                         {
1821                                 *p = 0; // cut off the string there
1822                                 ++p;
1823                         }
1824                         else
1825                                 Con_Printf("statusResponse without players block?\n");
1826
1827                         if ((s = SearchInfostring(string, "gamename"     )) != NULL) strlcpy(info->game, s, sizeof (info->game));
1828                         if ((s = SearchInfostring(string, "modname"      )) != NULL) strlcpy(info->mod , s, sizeof (info->mod ));
1829                         if ((s = SearchInfostring(string, "mapname"      )) != NULL) strlcpy(info->map , s, sizeof (info->map ));
1830                         if ((s = SearchInfostring(string, "hostname"     )) != NULL) strlcpy(info->name, s, sizeof (info->name));
1831                         if ((s = SearchInfostring(string, "protocol"     )) != NULL) info->protocol = atoi(s);
1832                         if ((s = SearchInfostring(string, "clients"      )) != NULL) info->numplayers = atoi(s);
1833                         if ((s = SearchInfostring(string, "bots"         )) != NULL) info->numbots = atoi(s);
1834                         if ((s = SearchInfostring(string, "sv_maxclients")) != NULL) info->maxplayers = atoi(s);
1835                         if ((s = SearchInfostring(string, "gameversion"  )) != NULL) info->gameversion = atoi(s);
1836                         if ((s = SearchInfostring(string, "qcstatus"     )) != NULL) strlcpy(info->qcstatus, s, sizeof(info->qcstatus));
1837                         if (p                                               != NULL) strlcpy(info->players, p, sizeof(info->players));
1838                         info->numhumans = info->numplayers - max(0, info->numbots);
1839                         info->freeslots = info->maxplayers - info->numplayers;
1840
1841                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
1842
1843                         return true;
1844                 }
1845                 if (length >= 13 && !memcmp(string, "infoResponse\x0A", 13))
1846                 {
1847                         serverlist_info_t *info;
1848                         int n;
1849
1850                         string += 13;
1851                         // search the cache for this server and update it
1852                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
1853                         if (n < 0)
1854                                 return true;
1855
1856                         info = &serverlist_cache[n].info;
1857                         info->game[0] = 0;
1858                         info->mod[0]  = 0;
1859                         info->map[0]  = 0;
1860                         info->name[0] = 0;
1861                         info->qcstatus[0] = 0;
1862                         info->players[0] = 0;
1863                         info->protocol = -1;
1864                         info->numplayers = 0;
1865                         info->numbots = -1;
1866                         info->maxplayers  = 0;
1867                         info->gameversion = 0;
1868
1869                         if ((s = SearchInfostring(string, "gamename"     )) != NULL) strlcpy(info->game, s, sizeof (info->game));
1870                         if ((s = SearchInfostring(string, "modname"      )) != NULL) strlcpy(info->mod , s, sizeof (info->mod ));
1871                         if ((s = SearchInfostring(string, "mapname"      )) != NULL) strlcpy(info->map , s, sizeof (info->map ));
1872                         if ((s = SearchInfostring(string, "hostname"     )) != NULL) strlcpy(info->name, s, sizeof (info->name));
1873                         if ((s = SearchInfostring(string, "protocol"     )) != NULL) info->protocol = atoi(s);
1874                         if ((s = SearchInfostring(string, "clients"      )) != NULL) info->numplayers = atoi(s);
1875                         if ((s = SearchInfostring(string, "bots"         )) != NULL) info->numbots = atoi(s);
1876                         if ((s = SearchInfostring(string, "sv_maxclients")) != NULL) info->maxplayers = atoi(s);
1877                         if ((s = SearchInfostring(string, "gameversion"  )) != NULL) info->gameversion = atoi(s);
1878                         if ((s = SearchInfostring(string, "qcstatus"     )) != NULL) strlcpy(info->qcstatus, s, sizeof(info->qcstatus));
1879                         info->numhumans = info->numplayers - max(0, info->numbots);
1880                         info->freeslots = info->maxplayers - info->numplayers;
1881
1882                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
1883
1884                         return true;
1885                 }
1886                 if (!strncmp(string, "getserversResponse\\", 19) && serverlist_cachecount < SERVERLIST_TOTALSIZE)
1887                 {
1888                         // Extract the IP addresses
1889                         data += 18;
1890                         length -= 18;
1891                         NetConn_ClientParsePacket_ServerList_ParseDPList(peeraddress, data, length, false);
1892                         return true;
1893                 }
1894                 if (!strncmp(string, "getserversExtResponse", 21) && serverlist_cachecount < SERVERLIST_TOTALSIZE)
1895                 {
1896                         // Extract the IP addresses
1897                         data += 21;
1898                         length -= 21;
1899                         NetConn_ClientParsePacket_ServerList_ParseDPList(peeraddress, data, length, true);
1900                         return true;
1901                 }
1902                 if (!memcmp(string, "d\n", 2) && serverlist_cachecount < SERVERLIST_TOTALSIZE)
1903                 {
1904                         // Extract the IP addresses
1905                         data += 2;
1906                         length -= 2;
1907                         masterreplycount++;
1908                         if (serverlist_consoleoutput)
1909                                 Con_Printf("received QuakeWorld server list from %s...\n", addressstring2);
1910                         while (length >= 6 && (data[0] != 0xFF || data[1] != 0xFF || data[2] != 0xFF || data[3] != 0xFF) && data[4] * 256 + data[5] != 0)
1911                         {
1912                                 dpsnprintf (ipstring, sizeof (ipstring), "%u.%u.%u.%u:%u", data[0], data[1], data[2], data[3], data[4] * 256 + data[5]);
1913                                 if (serverlist_consoleoutput && developer_networking.integer)
1914                                         Con_Printf("Requesting info from QuakeWorld server %s\n", ipstring);
1915                                 
1916                                 if( !NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_QUAKEWORLD, ipstring, false ) ) {
1917                                         break;
1918                                 }
1919
1920                                 // move on to next address in packet
1921                                 data += 6;
1922                                 length -= 6;
1923                         }
1924                         // begin or resume serverlist queries
1925                         serverlist_querysleep = false;
1926                         serverlist_querywaittime = realtime + 3;
1927                         return true;
1928                 }
1929                 if (!strncmp(string, "extResponse ", 12))
1930                 {
1931                         ++cl_net_extresponse_count;
1932                         if(cl_net_extresponse_count > NET_EXTRESPONSE_MAX)
1933                                 cl_net_extresponse_count = NET_EXTRESPONSE_MAX;
1934                         cl_net_extresponse_last = (cl_net_extresponse_last + 1) % NET_EXTRESPONSE_MAX;
1935                         dpsnprintf(cl_net_extresponse[cl_net_extresponse_last], sizeof(cl_net_extresponse[cl_net_extresponse_last]), "\"%s\" %s", addressstring2, string + 12);
1936                         return true;
1937                 }
1938                 if (!strncmp(string, "ping", 4))
1939                 {
1940                         if (developer_extra.integer)
1941                                 Con_DPrintf("Received ping from %s, sending ack\n", addressstring2);
1942                         NetConn_WriteString(mysocket, "\377\377\377\377ack", peeraddress);
1943                         return true;
1944                 }
1945                 if (!strncmp(string, "ack", 3))
1946                         return true;
1947                 // QuakeWorld compatibility
1948                 if (length > 1 && string[0] == 'c' && (string[1] == '-' || (string[1] >= '0' && string[1] <= '9')) && cls.connect_trying)
1949                 {
1950                         // challenge message
1951                         Con_Printf("challenge %s received, sending QuakeWorld connect request back to %s\n", string + 1, addressstring2);
1952                         M_Update_Return_Reason("Got QuakeWorld challenge response");
1953                         cls.qw_qport = qport.integer;
1954                         // update the server IP in the userinfo (QW servers expect this, and it is used by the reconnect command)
1955                         InfoString_SetValue(cls.userinfo, sizeof(cls.userinfo), "*ip", addressstring2);
1956                         NetConn_WriteString(mysocket, va("\377\377\377\377connect %i %i %i \"%s%s\"\n", 28, cls.qw_qport, atoi(string + 1), cls.userinfo, cls.connect_userinfo), peeraddress);
1957                         return true;
1958                 }
1959                 if (length >= 1 && string[0] == 'j' && cls.connect_trying)
1960                 {
1961                         // accept message
1962                         M_Update_Return_Reason("QuakeWorld Accepted");
1963                         NetConn_ConnectionEstablished(mysocket, peeraddress, PROTOCOL_QUAKEWORLD);
1964                         return true;
1965                 }
1966                 if (length > 2 && !memcmp(string, "n\\", 2))
1967                 {
1968                         serverlist_info_t *info;
1969                         int n;
1970
1971                         // qw server status
1972                         if (serverlist_consoleoutput && developer_networking.integer >= 2)
1973                                 Con_Printf("QW server status from server at %s:\n%s\n", addressstring2, string + 1);
1974
1975                         string += 1;
1976                         // search the cache for this server and update it
1977                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
1978                         if (n < 0)
1979                                 return true;
1980
1981                         info = &serverlist_cache[n].info;
1982                         strlcpy(info->game, "QuakeWorld", sizeof(info->game));
1983                         if ((s = SearchInfostring(string, "*gamedir"     )) != NULL) strlcpy(info->mod , s, sizeof (info->mod ));else info->mod[0]  = 0;
1984                         if ((s = SearchInfostring(string, "map"          )) != NULL) strlcpy(info->map , s, sizeof (info->map ));else info->map[0]  = 0;
1985                         if ((s = SearchInfostring(string, "hostname"     )) != NULL) strlcpy(info->name, s, sizeof (info->name));else info->name[0] = 0;
1986                         info->protocol = 0;
1987                         info->numplayers = 0; // updated below
1988                         info->numhumans = 0; // updated below
1989                         if ((s = SearchInfostring(string, "maxclients"   )) != NULL) info->maxplayers = atoi(s);else info->maxplayers  = 0;
1990                         if ((s = SearchInfostring(string, "gameversion"  )) != NULL) info->gameversion = atoi(s);else info->gameversion = 0;
1991
1992                         // count active players on server
1993                         // (we could gather more info, but we're just after the number)
1994                         s = strchr(string, '\n');
1995                         if (s)
1996                         {
1997                                 s++;
1998                                 while (s < string + length)
1999                                 {
2000                                         for (;s < string + length && *s != '\n';s++)
2001                                                 ;
2002                                         if (s >= string + length)
2003                                                 break;
2004                                         info->numplayers++;
2005                                         info->numhumans++;
2006                                         s++;
2007                                 }
2008                         }
2009
2010                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
2011
2012                         return true;
2013                 }
2014                 if (string[0] == 'n')
2015                 {
2016                         // qw print command
2017                         Con_Printf("QW print command from server at %s:\n%s\n", addressstring2, string + 1);
2018                 }
2019                 // we may not have liked the packet, but it was a command packet, so
2020                 // we're done processing this packet now
2021                 return true;
2022         }
2023         // quakeworld ingame packet
2024         if (fromserver && cls.protocol == PROTOCOL_QUAKEWORLD && length >= 8 && (ret = NetConn_ReceivedMessage(cls.netcon, data, length, cls.protocol, net_messagetimeout.value)) == 2)
2025         {
2026                 ret = 0;
2027                 CL_ParseServerMessage();
2028                 return ret;
2029         }
2030         // netquake control packets, supported for compatibility only
2031         if (length >= 5 && (control = BuffBigLong(data)) && (control & (~NETFLAG_LENGTH_MASK)) == (int)NETFLAG_CTL && (control & NETFLAG_LENGTH_MASK) == length && !ENCRYPTION_REQUIRED)
2032         {
2033                 int n;
2034                 serverlist_info_t *info;
2035
2036                 data += 4;
2037                 length -= 4;
2038                 SZ_Clear(&net_message);
2039                 SZ_Write(&net_message, data, length);
2040                 MSG_BeginReading();
2041                 c = MSG_ReadByte();
2042                 switch (c)
2043                 {
2044                 case CCREP_ACCEPT:
2045                         if (developer_extra.integer)
2046                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_ACCEPT from %s.\n", addressstring2);
2047                         if (cls.connect_trying)
2048                         {
2049                                 lhnetaddress_t clientportaddress;
2050                                 clientportaddress = *peeraddress;
2051                                 LHNETADDRESS_SetPort(&clientportaddress, MSG_ReadLong());
2052                                 // extra ProQuake stuff
2053                                 if (length >= 6)
2054                                         cls.proquake_servermod = MSG_ReadByte(); // MOD_PROQUAKE
2055                                 else
2056                                         cls.proquake_servermod = 0;
2057                                 if (length >= 7)
2058                                         cls.proquake_serverversion = MSG_ReadByte(); // version * 10
2059                                 else
2060                                         cls.proquake_serverversion = 0;
2061                                 if (length >= 8)
2062                                         cls.proquake_serverflags = MSG_ReadByte(); // flags (mainly PQF_CHEATFREE)
2063                                 else
2064                                         cls.proquake_serverflags = 0;
2065                                 if (cls.proquake_servermod == 1)
2066                                         Con_Printf("Connected to ProQuake %.1f server, enabling precise aim\n", cls.proquake_serverversion / 10.0f);
2067                                 // update the server IP in the userinfo (QW servers expect this, and it is used by the reconnect command)
2068                                 InfoString_SetValue(cls.userinfo, sizeof(cls.userinfo), "*ip", addressstring2);
2069                                 M_Update_Return_Reason("Accepted");
2070                                 NetConn_ConnectionEstablished(mysocket, &clientportaddress, PROTOCOL_QUAKE);
2071                         }
2072                         break;
2073                 case CCREP_REJECT:
2074                         if (developer_extra.integer)
2075                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_REJECT from %s.\n", addressstring2);
2076                         cls.connect_trying = false;
2077                         M_Update_Return_Reason((char *)MSG_ReadString());
2078                         break;
2079                 case CCREP_SERVER_INFO:
2080                         if (developer_extra.integer)
2081                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_SERVER_INFO from %s.\n", addressstring2);
2082                         // LordHavoc: because the quake server may report weird addresses
2083                         // we just ignore it and keep the real address
2084                         MSG_ReadString();
2085                         // search the cache for this server and update it
2086                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
2087                         if (n < 0)
2088                                 break;
2089
2090                         info = &serverlist_cache[n].info;
2091                         strlcpy(info->game, "Quake", sizeof(info->game));
2092                         strlcpy(info->mod , "", sizeof(info->mod)); // mod name is not specified
2093                         strlcpy(info->name, MSG_ReadString(), sizeof(info->name));
2094                         strlcpy(info->map , MSG_ReadString(), sizeof(info->map));
2095                         info->numplayers = MSG_ReadByte();
2096                         info->maxplayers = MSG_ReadByte();
2097                         info->protocol = MSG_ReadByte();
2098
2099                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
2100
2101                         break;
2102                 case CCREP_RCON: // RocketGuy: ProQuake rcon support
2103                         if (developer_extra.integer)
2104                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_RCON from %s.\n", addressstring2);
2105
2106                         Con_Printf("%s\n", MSG_ReadString());
2107                         break;
2108                 case CCREP_PLAYER_INFO:
2109                         // we got a CCREP_PLAYER_INFO??
2110                         //if (developer_extra.integer)
2111                                 Con_Printf("Datagram_ParseConnectionless: received CCREP_PLAYER_INFO from %s.\n", addressstring2);
2112                         break;
2113                 case CCREP_RULE_INFO:
2114                         // we got a CCREP_RULE_INFO??
2115                         //if (developer_extra.integer)
2116                                 Con_Printf("Datagram_ParseConnectionless: received CCREP_RULE_INFO from %s.\n", addressstring2);
2117                         break;
2118                 default:
2119                         break;
2120                 }
2121                 SZ_Clear(&net_message);
2122                 // we may not have liked the packet, but it was a valid control
2123                 // packet, so we're done processing this packet now
2124                 return true;
2125         }
2126         ret = 0;
2127         if (fromserver && length >= (int)NET_HEADERSIZE && (ret = NetConn_ReceivedMessage(cls.netcon, data, length, cls.protocol, net_messagetimeout.value)) == 2)
2128                 CL_ParseServerMessage();
2129         return ret;
2130 }
2131
2132 void NetConn_QueryQueueFrame(void)
2133 {
2134         int index;
2135         int queries;
2136         int maxqueries;
2137         double timeouttime;
2138         static double querycounter = 0;
2139
2140         if(!net_slist_pause.integer && serverlist_paused)
2141                 ServerList_RebuildViewList();
2142         serverlist_paused = net_slist_pause.integer != 0;
2143
2144         if (serverlist_querysleep)
2145                 return;
2146
2147         // apply a cool down time after master server replies,
2148         // to avoid messing up the ping times on the servers
2149         if (serverlist_querywaittime > realtime)
2150                 return;
2151
2152         // each time querycounter reaches 1.0 issue a query
2153         querycounter += cl.realframetime * net_slist_queriespersecond.value;
2154         maxqueries = (int)querycounter;
2155         maxqueries = bound(0, maxqueries, net_slist_queriesperframe.integer);
2156         querycounter -= maxqueries;
2157
2158         if( maxqueries == 0 ) {
2159                 return;
2160         }
2161
2162         //      scan serverlist and issue queries as needed
2163         serverlist_querysleep = true;
2164
2165         timeouttime     = realtime - net_slist_timeout.value;
2166         for( index = 0, queries = 0 ;   index   < serverlist_cachecount &&      queries < maxqueries    ; index++ )
2167         {
2168                 serverlist_entry_t *entry = &serverlist_cache[ index ];
2169                 if( entry->query != SQS_QUERYING && entry->query != SQS_REFRESHING )
2170                 {
2171                         continue;
2172                 }
2173
2174                 serverlist_querysleep   = false;
2175                 if( entry->querycounter !=      0 && entry->querytime > timeouttime     )
2176                 {
2177                         continue;
2178                 }
2179
2180                 if( entry->querycounter !=      (unsigned) net_slist_maxtries.integer )
2181                 {
2182                         lhnetaddress_t  address;
2183                         int socket;
2184
2185                         LHNETADDRESS_FromString(&address, entry->info.cname, 0);
2186                         if      (entry->protocol == PROTOCOL_QUAKEWORLD)
2187                         {
2188                                 for (socket     = 0; socket     < cl_numsockets ;       socket++)
2189                                         NetConn_WriteString(cl_sockets[socket], "\377\377\377\377status\n", &address);
2190                         }
2191                         else
2192                         {
2193                                 for (socket     = 0; socket     < cl_numsockets ;       socket++)
2194                                         NetConn_WriteString(cl_sockets[socket], "\377\377\377\377getstatus", &address);
2195                         }
2196
2197                         //      update the entry fields
2198                         entry->querytime = realtime;
2199                         entry->querycounter++;
2200
2201                         // if not in the slist menu we should print the server to console
2202                         if (serverlist_consoleoutput)
2203                                 Con_Printf("querying %25s (%i. try)\n", entry->info.cname, entry->querycounter);
2204
2205                         queries++;
2206                 }
2207                 else
2208                 {
2209                         // have we tried to refresh this server?
2210                         if( entry->query == SQS_REFRESHING ) {
2211                                 // yes, so update the reply count (since its not responding anymore)
2212                                 serverreplycount--;
2213                                 if(!serverlist_paused)
2214                                         ServerList_ViewList_Remove(entry);
2215                         }
2216                         entry->query = SQS_TIMEDOUT;
2217                 }
2218         }
2219 }
2220
2221 void NetConn_ClientFrame(void)
2222 {
2223         int i, length;
2224         lhnetaddress_t peeraddress;
2225         NetConn_UpdateSockets();
2226         if (cls.connect_trying && cls.connect_nextsendtime < realtime)
2227         {
2228                 if (cls.connect_remainingtries == 0)
2229                         M_Update_Return_Reason("Connect: Waiting 10 seconds for reply");
2230                 cls.connect_nextsendtime = realtime + 1;
2231                 cls.connect_remainingtries--;
2232                 if (cls.connect_remainingtries <= -10)
2233                 {
2234                         cls.connect_trying = false;
2235                         M_Update_Return_Reason("Connect: Failed");
2236                         return;
2237                 }
2238                 // try challenge first (newer DP server or QW)
2239                 NetConn_WriteString(cls.connect_mysocket, "\377\377\377\377getchallenge", &cls.connect_address);
2240                 // then try netquake as a fallback (old server, or netquake)
2241                 SZ_Clear(&net_message);
2242                 // save space for the header, filled in later
2243                 MSG_WriteLong(&net_message, 0);
2244                 MSG_WriteByte(&net_message, CCREQ_CONNECT);
2245                 MSG_WriteString(&net_message, "QUAKE");
2246                 MSG_WriteByte(&net_message, NET_PROTOCOL_VERSION);
2247                 // extended proquake stuff
2248                 MSG_WriteByte(&net_message, 1); // mod = MOD_PROQUAKE
2249                 // this version matches ProQuake 3.40, the first version to support
2250                 // the NAT fix, and it only supports the NAT fix for ProQuake 3.40 or
2251                 // higher clients, so we pretend we are that version...
2252                 MSG_WriteByte(&net_message, 34); // version * 10
2253                 MSG_WriteByte(&net_message, 0); // flags
2254                 MSG_WriteLong(&net_message, 0); // password
2255                 // write the packetsize now...
2256                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
2257                 NetConn_Write(cls.connect_mysocket, net_message.data, net_message.cursize, &cls.connect_address);
2258                 SZ_Clear(&net_message);
2259         }
2260         for (i = 0;i < cl_numsockets;i++)
2261         {
2262                 while (cl_sockets[i] && (length = NetConn_Read(cl_sockets[i], readbuffer, sizeof(readbuffer), &peeraddress)) > 0)
2263                 {
2264 //                      R_TimeReport("clientreadnetwork");
2265                         NetConn_ClientParsePacket(cl_sockets[i], readbuffer, length, &peeraddress);
2266 //                      R_TimeReport("clientparsepacket");
2267                 }
2268         }
2269         NetConn_QueryQueueFrame();
2270         if (cls.netcon && realtime > cls.netcon->timeout && !sv.active)
2271         {
2272                 Con_Print("Connection timed out\n");
2273                 CL_Disconnect();
2274                 Host_ShutdownServer ();
2275         }
2276 }
2277
2278 static void NetConn_BuildChallengeString(char *buffer, int bufferlength)
2279 {
2280         int i;
2281         char c;
2282         for (i = 0;i < bufferlength - 1;i++)
2283         {
2284                 do
2285                 {
2286                         c = rand () % (127 - 33) + 33;
2287                 } while (c == '\\' || c == ';' || c == '"' || c == '%' || c == '/');
2288                 buffer[i] = c;
2289         }
2290         buffer[i] = 0;
2291 }
2292
2293 /// (div0) build the full response only if possible; better a getinfo response than no response at all if getstatus won't fit
2294 static qboolean NetConn_BuildStatusResponse(const char* challenge, char* out_msg, size_t out_size, qboolean fullstatus)
2295 {
2296         char qcstatus[256];
2297         unsigned int nb_clients = 0, nb_bots = 0, i;
2298         int length;
2299         char teambuf[3];
2300         const char *crypto_idstring;
2301         const char *str;
2302
2303         SV_VM_Begin();
2304
2305         // How many clients are there?
2306         for (i = 0;i < (unsigned int)svs.maxclients;i++)
2307         {
2308                 if (svs.clients[i].active)
2309                 {
2310                         nb_clients++;
2311                         if (!svs.clients[i].netconnection)
2312                                 nb_bots++;
2313                 }
2314         }
2315
2316         *qcstatus = 0;
2317         str = PRVM_GetString(PRVM_serverglobalstring(worldstatus));
2318         if(str && *str)
2319         {
2320                 char *p;
2321                 const char *q;
2322                 p = qcstatus;
2323                 for(q = str; *q && (size_t)(p - qcstatus) < (sizeof(qcstatus) - 1); ++q)
2324                         if(*q != '\\' && *q != '\n')
2325                                 *p++ = *q;
2326                 *p = 0;
2327         }
2328
2329         /// \TODO: we should add more information for the full status string
2330         crypto_idstring = Crypto_GetInfoResponseDataString();
2331         length = dpsnprintf(out_msg, out_size,
2332                                                 "\377\377\377\377%s\x0A"
2333                                                 "\\gamename\\%s\\modname\\%s\\gameversion\\%d\\sv_maxclients\\%d"
2334                                                 "\\clients\\%d\\bots\\%d\\mapname\\%s\\hostname\\%s\\protocol\\%d"
2335                                                 "%s%s"
2336                                                 "%s%s"
2337                                                 "%s%s"
2338                                                 "%s",
2339                                                 fullstatus ? "statusResponse" : "infoResponse",
2340                                                 gamename, com_modname, gameversion.integer, svs.maxclients,
2341                                                 nb_clients, nb_bots, sv.worldbasename, hostname.string, NET_PROTOCOL_VERSION,
2342                                                 *qcstatus ? "\\qcstatus\\" : "", qcstatus,
2343                                                 challenge ? "\\challenge\\" : "", challenge ? challenge : "",
2344                                                 crypto_idstring ? "\\d0_blind_id\\" : "", crypto_idstring ? crypto_idstring : "",
2345                                                 fullstatus ? "\n" : "");
2346
2347         // Make sure it fits in the buffer
2348         if (length < 0)
2349                 goto bad;
2350
2351         if (fullstatus)
2352         {
2353                 char *ptr;
2354                 int left;
2355                 int savelength;
2356
2357                 savelength = length;
2358
2359                 ptr = out_msg + length;
2360                 left = (int)out_size - length;
2361
2362                 for (i = 0;i < (unsigned int)svs.maxclients;i++)
2363                 {
2364                         client_t *cl = &svs.clients[i];
2365                         if (cl->active)
2366                         {
2367                                 int nameind, cleanind, pingvalue;
2368                                 char curchar;
2369                                 char cleanname [sizeof(cl->name)];
2370                                 const char *str;
2371                                 prvm_edict_t *ed;
2372
2373                                 // Remove all characters '"' and '\' in the player name
2374                                 nameind = 0;
2375                                 cleanind = 0;
2376                                 do
2377                                 {
2378                                         curchar = cl->name[nameind++];
2379                                         if (curchar != '"' && curchar != '\\')
2380                                         {
2381                                                 cleanname[cleanind++] = curchar;
2382                                                 if (cleanind == sizeof(cleanname) - 1)
2383                                                         break;
2384                                         }
2385                                 } while (curchar != '\0');
2386                                 cleanname[cleanind] = 0; // cleanind is always a valid index even at this point
2387
2388                                 pingvalue = (int)(cl->ping * 1000.0f);
2389                                 if(cl->netconnection)
2390                                         pingvalue = bound(1, pingvalue, 9999);
2391                                 else
2392                                         pingvalue = 0;
2393
2394                                 *qcstatus = 0;
2395                                 ed = PRVM_EDICT_NUM(i + 1);
2396                                 str = PRVM_GetString(PRVM_serveredictstring(ed, clientstatus));
2397                                 if(str && *str)
2398                                 {
2399                                         char *p;
2400                                         const char *q;
2401                                         p = qcstatus;
2402                                         for(q = str; *q && p != qcstatus + sizeof(qcstatus) - 1; ++q)
2403                                                 if(*q != '\\' && *q != '"' && !ISWHITESPACE(*q))
2404                                                         *p++ = *q;
2405                                         *p = 0;
2406                                 }
2407
2408                                 if ((gamemode == GAME_NEXUIZ || gamemode == GAME_XONOTIC) && (teamplay.integer > 0))
2409                                 {
2410                                         if(cl->frags == -666) // spectator
2411                                                 strlcpy(teambuf, " 0", sizeof(teambuf));
2412                                         else if(cl->colors == 0x44) // red team
2413                                                 strlcpy(teambuf, " 1", sizeof(teambuf));
2414                                         else if(cl->colors == 0xDD) // blue team
2415                                                 strlcpy(teambuf, " 2", sizeof(teambuf));
2416                                         else if(cl->colors == 0xCC) // yellow team
2417                                                 strlcpy(teambuf, " 3", sizeof(teambuf));
2418                                         else if(cl->colors == 0x99) // pink team
2419                                                 strlcpy(teambuf, " 4", sizeof(teambuf));
2420                                         else
2421                                                 strlcpy(teambuf, " 0", sizeof(teambuf));
2422                                 }
2423                                 else
2424                                         *teambuf = 0;
2425
2426                                 // note: team number is inserted according to SoF2 protocol
2427                                 if(*qcstatus)
2428                                         length = dpsnprintf(ptr, left, "%s %d%s \"%s\"\n",
2429                                                                                 qcstatus,
2430                                                                                 pingvalue,
2431                                                                                 teambuf,
2432                                                                                 cleanname);
2433                                 else
2434                                         length = dpsnprintf(ptr, left, "%d %d%s \"%s\"\n",
2435                                                                                 cl->frags,
2436                                                                                 pingvalue,
2437                                                                                 teambuf,
2438                                                                                 cleanname);
2439
2440                                 if(length < 0)
2441                                 {
2442                                         // out of space?
2443                                         // turn it into an infoResponse!
2444                                         out_msg[savelength] = 0;
2445                                         memcpy(out_msg + 4, "infoResponse\x0A", 13);
2446                                         memmove(out_msg + 17, out_msg + 19, savelength - 19);
2447                                         break;
2448                                 }
2449                                 left -= length;
2450                                 ptr += length;
2451                         }
2452                 }
2453         }
2454
2455         SV_VM_End();
2456         return true;
2457
2458 bad:
2459         SV_VM_End();
2460         return false;
2461 }
2462
2463 static qboolean NetConn_PreventConnectFlood(lhnetaddress_t *peeraddress)
2464 {
2465         int floodslotnum, bestfloodslotnum;
2466         double bestfloodtime;
2467         lhnetaddress_t noportpeeraddress;
2468         // see if this is a connect flood
2469         noportpeeraddress = *peeraddress;
2470         LHNETADDRESS_SetPort(&noportpeeraddress, 0);
2471         bestfloodslotnum = 0;
2472         bestfloodtime = sv.connectfloodaddresses[bestfloodslotnum].lasttime;
2473         for (floodslotnum = 0;floodslotnum < MAX_CONNECTFLOODADDRESSES;floodslotnum++)
2474         {
2475                 if (bestfloodtime >= sv.connectfloodaddresses[floodslotnum].lasttime)
2476                 {
2477                         bestfloodtime = sv.connectfloodaddresses[floodslotnum].lasttime;
2478                         bestfloodslotnum = floodslotnum;
2479                 }
2480                 if (sv.connectfloodaddresses[floodslotnum].lasttime && LHNETADDRESS_Compare(&noportpeeraddress, &sv.connectfloodaddresses[floodslotnum].address) == 0)
2481                 {
2482                         // this address matches an ongoing flood address
2483                         if (realtime < sv.connectfloodaddresses[floodslotnum].lasttime + net_connectfloodblockingtimeout.value)
2484                         {
2485                                 // renew the ban on this address so it does not expire
2486                                 // until the flood has subsided
2487                                 sv.connectfloodaddresses[floodslotnum].lasttime = realtime;
2488                                 //Con_Printf("Flood detected!\n");
2489                                 return true;
2490                         }
2491                         // the flood appears to have subsided, so allow this
2492                         bestfloodslotnum = floodslotnum; // reuse the same slot
2493                         break;
2494                 }
2495         }
2496         // begin a new timeout on this address
2497         sv.connectfloodaddresses[bestfloodslotnum].address = noportpeeraddress;
2498         sv.connectfloodaddresses[bestfloodslotnum].lasttime = realtime;
2499         //Con_Printf("Flood detection initiated!\n");
2500         return false;
2501 }
2502
2503 void NetConn_ClearConnectFlood(lhnetaddress_t *peeraddress)
2504 {
2505         int floodslotnum;
2506         lhnetaddress_t noportpeeraddress;
2507         // see if this is a connect flood
2508         noportpeeraddress = *peeraddress;
2509         LHNETADDRESS_SetPort(&noportpeeraddress, 0);
2510         for (floodslotnum = 0;floodslotnum < MAX_CONNECTFLOODADDRESSES;floodslotnum++)
2511         {
2512                 if (sv.connectfloodaddresses[floodslotnum].lasttime && LHNETADDRESS_Compare(&noportpeeraddress, &sv.connectfloodaddresses[floodslotnum].address) == 0)
2513                 {
2514                         // this address matches an ongoing flood address
2515                         // remove the ban
2516                         sv.connectfloodaddresses[floodslotnum].address.addresstype = LHNETADDRESSTYPE_NONE;
2517                         sv.connectfloodaddresses[floodslotnum].lasttime = 0;
2518                         //Con_Printf("Flood cleared!\n");
2519                 }
2520         }
2521 }
2522
2523 typedef qboolean (*rcon_matchfunc_t) (lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen);
2524
2525 qboolean hmac_mdfour_time_matching(lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen)
2526 {
2527         char mdfourbuf[16];
2528         long t1, t2;
2529
2530         t1 = (long) time(NULL);
2531         t2 = strtol(s, NULL, 0);
2532         if(abs(t1 - t2) > rcon_secure_maxdiff.integer)
2533                 return false;
2534
2535         if(!HMAC_MDFOUR_16BYTES((unsigned char *) mdfourbuf, (unsigned char *) s, slen, (unsigned char *) password, strlen(password)))
2536                 return false;
2537
2538         return !memcmp(mdfourbuf, hash, 16);
2539 }
2540
2541 qboolean hmac_mdfour_challenge_matching(lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen)
2542 {
2543         char mdfourbuf[16];
2544         int i;
2545
2546         if(slen < (int)(sizeof(challenge[0].string)) - 1)
2547                 return false;
2548
2549         // validate the challenge
2550         for (i = 0;i < MAX_CHALLENGES;i++)
2551                 if(challenge[i].time > 0)
2552                         if (!LHNETADDRESS_Compare(peeraddress, &challenge[i].address) && !strncmp(challenge[i].string, s, sizeof(challenge[0].string) - 1))
2553                                 break;
2554         // if the challenge is not recognized, drop the packet
2555         if (i == MAX_CHALLENGES)
2556                 return false;
2557
2558         if(!HMAC_MDFOUR_16BYTES((unsigned char *) mdfourbuf, (unsigned char *) s, slen, (unsigned char *) password, strlen(password)))
2559                 return false;
2560
2561         if(memcmp(mdfourbuf, hash, 16))
2562                 return false;
2563
2564         // unmark challenge to prevent replay attacks
2565         challenge[i].time = 0;
2566
2567         return true;
2568 }
2569
2570 qboolean plaintext_matching(lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen)
2571 {
2572         return !strcmp(password, hash);
2573 }
2574
2575 /// returns a string describing the user level, or NULL for auth failure
2576 const char *RCon_Authenticate(lhnetaddress_t *peeraddress, const char *password, const char *s, const char *endpos, rcon_matchfunc_t comparator, const char *cs, int cslen)
2577 {
2578         const char *text, *userpass_start, *userpass_end, *userpass_startpass;
2579         static char buf[MAX_INPUTLINE];
2580         qboolean hasquotes;
2581         qboolean restricted = false;
2582         qboolean have_usernames = false;
2583
2584         userpass_start = rcon_password.string;
2585         while((userpass_end = strchr(userpass_start, ' ')))
2586         {
2587                 have_usernames = true;
2588                 strlcpy(buf, userpass_start, ((size_t)(userpass_end-userpass_start) >= sizeof(buf)) ? (int)(sizeof(buf)) : (int)(userpass_end-userpass_start+1));
2589                 if(buf[0])
2590                         if(comparator(peeraddress, buf, password, cs, cslen))
2591                                 goto allow;
2592                 userpass_start = userpass_end + 1;
2593         }
2594         if(userpass_start[0])
2595         {
2596                 userpass_end = userpass_start + strlen(userpass_start);
2597                 if(comparator(peeraddress, userpass_start, password, cs, cslen))
2598                         goto allow;
2599         }
2600
2601         restricted = true;
2602         have_usernames = false;
2603         userpass_start = rcon_restricted_password.string;
2604         while((userpass_end = strchr(userpass_start, ' ')))
2605         {
2606                 have_usernames = true;
2607                 strlcpy(buf, userpass_start, ((size_t)(userpass_end-userpass_start) >= sizeof(buf)) ? (int)(sizeof(buf)) : (int)(userpass_end-userpass_start+1));
2608                 if(buf[0])
2609                         if(comparator(peeraddress, buf, password, cs, cslen))
2610                                 goto check;
2611                 userpass_start = userpass_end + 1;
2612         }
2613         if(userpass_start[0])
2614         {
2615                 userpass_end = userpass_start + strlen(userpass_start);
2616                 if(comparator(peeraddress, userpass_start, password, cs, cslen))
2617                         goto check;
2618         }
2619         
2620         return NULL; // DENIED
2621
2622 check:
2623         for(text = s; text != endpos; ++text)
2624                 if((signed char) *text > 0 && ((signed char) *text < (signed char) ' ' || *text == ';'))
2625                         return NULL; // block possible exploits against the parser/alias expansion
2626
2627         while(s != endpos)
2628         {
2629                 size_t l = strlen(s);
2630                 if(l)
2631                 {
2632                         hasquotes = (strchr(s, '"') != NULL);
2633                         // sorry, we can't allow these substrings in wildcard expressions,
2634                         // as they can mess with the argument counts
2635                         text = rcon_restricted_commands.string;
2636                         while(COM_ParseToken_Console(&text))
2637                         {
2638                                 // com_token now contains a pattern to check for...
2639                                 if(strchr(com_token, '*') || strchr(com_token, '?')) // wildcard expression, * can only match a SINGLE argument
2640                                 {
2641                                         if(!hasquotes)
2642                                                 if(matchpattern_with_separator(s, com_token, true, " ", true)) // note how we excluded tab, newline etc. above
2643                                                         goto match;
2644                                 }
2645                                 else if(strchr(com_token, ' ')) // multi-arg expression? must match in whole
2646                                 {
2647                                         if(!strcmp(com_token, s))
2648                                                 goto match;
2649                                 }
2650                                 else // single-arg expression? must match the beginning of the command
2651                                 {
2652                                         if(!strcmp(com_token, s))
2653                                                 goto match;
2654                                         if(!memcmp(va("%s ", com_token), s, strlen(com_token) + 1))
2655                                                 goto match;
2656                                 }
2657                         }
2658                         // if we got here, nothing matched!
2659                         return NULL;
2660                 }
2661 match:
2662                 s += l + 1;
2663         }
2664
2665 allow:
2666         userpass_startpass = strchr(userpass_start, ':');
2667         if(have_usernames && userpass_startpass && userpass_startpass < userpass_end)
2668                 return va("%srcon (username %.*s)", restricted ? "restricted " : "", (int)(userpass_startpass-userpass_start), userpass_start);
2669
2670         return va("%srcon", restricted ? "restricted " : "");
2671 }
2672
2673 void RCon_Execute(lhnetsocket_t *mysocket, lhnetaddress_t *peeraddress, const char *addressstring2, const char *userlevel, const char *s, const char *endpos, qboolean proquakeprotocol)
2674 {
2675         if(userlevel)
2676         {
2677                 // looks like a legitimate rcon command with the correct password
2678                 const char *s_ptr = s;
2679                 Con_Printf("server received %s command from %s: ", userlevel, host_client ? host_client->name : addressstring2);
2680                 while(s_ptr != endpos)
2681                 {
2682                         size_t l = strlen(s_ptr);
2683                         if(l)
2684                                 Con_Printf(" %s;", s_ptr);
2685                         s_ptr += l + 1;
2686                 }
2687                 Con_Printf("\n");
2688
2689                 if (!host_client || !host_client->netconnection || LHNETADDRESS_GetAddressType(&host_client->netconnection->peeraddress) != LHNETADDRESSTYPE_LOOP)
2690                         Con_Rcon_Redirect_Init(mysocket, peeraddress, proquakeprotocol);
2691                 while(s != endpos)
2692                 {
2693                         size_t l = strlen(s);
2694                         if(l)
2695                         {
2696                                 client_t *host_client_save = host_client;
2697                                 Cmd_ExecuteString(s, src_command, true);
2698                                 host_client = host_client_save;
2699                                 // in case it is a command that changes host_client (like restart)
2700                         }
2701                         s += l + 1;
2702                 }
2703                 Con_Rcon_Redirect_End();
2704         }
2705         else
2706         {
2707                 Con_Printf("server denied rcon access to %s\n", host_client ? host_client->name : addressstring2);
2708         }
2709 }
2710
2711 extern void SV_SendServerinfo (client_t *client);
2712 static int NetConn_ServerParsePacket(lhnetsocket_t *mysocket, unsigned char *data, int length, lhnetaddress_t *peeraddress)
2713 {
2714         int i, ret, clientnum, best;
2715         double besttime;
2716         client_t *client;
2717         char *s, *string, response[1400], addressstring2[128];
2718         static char stringbuf[16384];
2719         qboolean islocal = (LHNETADDRESS_GetAddressType(peeraddress) == LHNETADDRESSTYPE_LOOP);
2720         char senddata[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
2721         size_t sendlength, response_len;
2722
2723         if (!sv.active)
2724                 return false;
2725
2726         // convert the address to a string incase we need it
2727         LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
2728
2729         // see if we can identify the sender as a local player
2730         // (this is necessary for rcon to send a reliable reply if the client is
2731         //  actually on the server, not sending remotely)
2732         for (i = 0, host_client = svs.clients;i < svs.maxclients;i++, host_client++)
2733                 if (host_client->netconnection && host_client->netconnection->mysocket == mysocket && !LHNETADDRESS_Compare(&host_client->netconnection->peeraddress, peeraddress))
2734                         break;
2735         if (i == svs.maxclients)
2736                 host_client = NULL;
2737
2738         if (length >= 5 && data[0] == 255 && data[1] == 255 && data[2] == 255 && data[3] == 255)
2739         {
2740                 // received a command string - strip off the packaging and put it
2741                 // into our string buffer with NULL termination
2742                 data += 4;
2743                 length -= 4;
2744                 length = min(length, (int)sizeof(stringbuf) - 1);
2745                 memcpy(stringbuf, data, length);
2746                 stringbuf[length] = 0;
2747                 string = stringbuf;
2748
2749                 if (developer_extra.integer)
2750                 {
2751                         Con_Printf("NetConn_ServerParsePacket: %s sent us a command:\n", addressstring2);
2752                         Com_HexDumpToConsole(data, length);
2753                 }
2754
2755                 sendlength = sizeof(senddata) - 4;
2756                 switch(Crypto_ServerParsePacket(string, length, senddata+4, &sendlength, peeraddress))
2757                 {
2758                         case CRYPTO_NOMATCH:
2759                                 // nothing to do
2760                                 break;
2761                         case CRYPTO_MATCH:
2762                                 if(sendlength)
2763                                 {
2764                                         memcpy(senddata, "\377\377\377\377", 4);
2765                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
2766                                 }
2767                                 break;
2768                         case CRYPTO_DISCARD:
2769                                 if(sendlength)
2770                                 {
2771                                         memcpy(senddata, "\377\377\377\377", 4);
2772                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
2773                                 }
2774                                 return true;
2775                                 break;
2776                         case CRYPTO_REPLACE:
2777                                 string = senddata+4;
2778                                 length = sendlength;
2779                                 break;
2780                 }
2781
2782                 if (length >= 12 && !memcmp(string, "getchallenge", 12) && (islocal || sv_public.integer > -3))
2783                 {
2784                         for (i = 0, best = 0, besttime = realtime;i < MAX_CHALLENGES;i++)
2785                         {
2786                                 if(challenge[i].time > 0)
2787                                         if (!LHNETADDRESS_Compare(peeraddress, &challenge[i].address))
2788                                                 break;
2789                                 if (besttime > challenge[i].time)
2790                                         besttime = challenge[best = i].time;
2791                         }
2792                         // if we did not find an exact match, choose the oldest and
2793                         // update address and string
2794                         if (i == MAX_CHALLENGES)
2795                         {
2796                                 i = best;
2797                                 challenge[i].address = *peeraddress;
2798                                 NetConn_BuildChallengeString(challenge[i].string, sizeof(challenge[i].string));
2799                         }
2800                         challenge[i].time = realtime;
2801                         // send the challenge
2802                         dpsnprintf(response, sizeof(response), "\377\377\377\377challenge %s", challenge[i].string);
2803                         response_len = strlen(response) + 1;
2804                         Crypto_ServerAppendToChallenge(string, length, response, &response_len, sizeof(response));
2805                         NetConn_Write(mysocket, response, response_len, peeraddress);
2806                         return true;
2807                 }
2808                 if (length > 8 && !memcmp(string, "connect\\", 8))
2809                 {
2810                         crypto_t *crypto = Crypto_ServerGetInstance(peeraddress);
2811                         string += 7;
2812                         length -= 7;
2813
2814                         if(crypto && crypto->authenticated)
2815                         {
2816                                 // no need to check challenge
2817                                 if(crypto_developer.integer)
2818                                 {
2819                                         Con_Printf("%s connection to %s is being established: client is %s@%.*s, I am %.*s@%.*s\n",
2820                                                         crypto->use_aes ? "Encrypted" : "Authenticated",
2821                                                         addressstring2,
2822                                                         crypto->client_idfp[0] ? crypto->client_idfp : "-",
2823                                                         crypto_keyfp_recommended_length, crypto->client_keyfp[0] ? crypto->client_keyfp : "-",
2824                                                         crypto_keyfp_recommended_length, crypto->server_idfp[0] ? crypto->server_idfp : "-",
2825                                                         crypto_keyfp_recommended_length, crypto->server_keyfp[0] ? crypto->server_keyfp : "-"
2826                                                   );
2827                                 }
2828                         }
2829                         else
2830                         {
2831                                 if ((s = SearchInfostring(string, "challenge")))
2832                                 {
2833                                         // validate the challenge
2834                                         for (i = 0;i < MAX_CHALLENGES;i++)
2835                                                 if(challenge[i].time > 0)
2836                                                         if (!LHNETADDRESS_Compare(peeraddress, &challenge[i].address) && !strcmp(challenge[i].string, s))
2837                                                                 break;
2838                                         // if the challenge is not recognized, drop the packet
2839                                         if (i == MAX_CHALLENGES)
2840                                                 return true;
2841                                 }
2842                         }
2843
2844                         if((s = SearchInfostring(string, "message")))
2845                                 Con_DPrintf("Connecting client %s sent us the message: %s\n", addressstring2, s);
2846
2847                         if(!(islocal || sv_public.integer > -2))
2848                         {
2849                                 if (developer_extra.integer)
2850                                         Con_Printf("Datagram_ParseConnectionless: sending \"reject %s\" to %s.\n", sv_public_rejectreason.string, addressstring2);
2851                                 NetConn_WriteString(mysocket, va("\377\377\377\377reject %s", sv_public_rejectreason.string), peeraddress);
2852                                 return true;
2853                         }
2854
2855                         // check engine protocol
2856                         if(!(s = SearchInfostring(string, "protocol")) || strcmp(s, "darkplaces 3"))
2857                         {
2858                                 if (developer_extra.integer)
2859                                         Con_Printf("Datagram_ParseConnectionless: sending \"reject Wrong game protocol.\" to %s.\n", addressstring2);
2860                                 NetConn_WriteString(mysocket, "\377\377\377\377reject Wrong game protocol.", peeraddress);
2861                                 return true;
2862                         }
2863
2864                         // see if this is a duplicate connection request or a disconnected
2865                         // client who is rejoining to the same client slot
2866                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
2867                         {
2868                                 if (client->netconnection && LHNETADDRESS_Compare(peeraddress, &client->netconnection->peeraddress) == 0)
2869                                 {
2870                                         // this is a known client...
2871                                         if(crypto && crypto->authenticated)
2872                                         {
2873                                                 // reject if changing key!
2874                                                 if(client->netconnection->crypto.authenticated)
2875                                                 {
2876                                                         if(
2877                                                                         strcmp(client->netconnection->crypto.client_idfp, crypto->client_idfp)
2878                                                                         ||
2879                                                                         strcmp(client->netconnection->crypto.server_idfp, crypto->server_idfp)
2880                                                                         ||
2881                                                                         strcmp(client->netconnection->crypto.client_keyfp, crypto->client_keyfp)
2882                                                                         ||
2883                                                                         strcmp(client->netconnection->crypto.server_keyfp, crypto->server_keyfp)
2884                                                           )
2885                                                         {
2886                                                                 if (developer_extra.integer)
2887                                                                         Con_Printf("Datagram_ParseConnectionless: sending \"reject Attempt to change key of crypto.\" to %s.\n", addressstring2);
2888                                                                 NetConn_WriteString(mysocket, "\377\377\377\377reject Attempt to change key of crypto.", peeraddress);
2889                                                                 return true;
2890                                                         }
2891                                                 }
2892                                         }
2893                                         else
2894                                         {
2895                                                 // reject if downgrading!
2896                                                 if(client->netconnection->crypto.authenticated)
2897                                                 {
2898                                                         if (developer_extra.integer)
2899                                                                 Con_Printf("Datagram_ParseConnectionless: sending \"reject Attempt to downgrade crypto.\" to %s.\n", addressstring2);
2900                                                         NetConn_WriteString(mysocket, "\377\377\377\377reject Attempt to downgrade crypto.", peeraddress);
2901                                                         return true;
2902                                                 }
2903                                         }
2904                                         if (client->spawned)
2905                                         {
2906                                                 // client crashed and is coming back,
2907                                                 // keep their stuff intact
2908                                                 if (developer_extra.integer)
2909                                                         Con_Printf("Datagram_ParseConnectionless: sending \"accept\" to %s.\n", addressstring2);
2910                                                 NetConn_WriteString(mysocket, "\377\377\377\377accept", peeraddress);
2911                                                 if(crypto && crypto->authenticated)
2912                                                         Crypto_ServerFinishInstance(&client->netconnection->crypto, crypto);
2913                                                 SV_VM_Begin();
2914                                                 SV_SendServerinfo(client);
2915                                                 SV_VM_End();
2916                                         }
2917                                         else
2918                                         {
2919                                                 // client is still trying to connect,
2920                                                 // so we send a duplicate reply
2921                                                 if (developer_extra.integer)
2922                                                         Con_Printf("Datagram_ParseConnectionless: sending duplicate accept to %s.\n", addressstring2);
2923                                                 if(crypto && crypto->authenticated)
2924                                                         Crypto_ServerFinishInstance(&client->netconnection->crypto, crypto);
2925                                                 NetConn_WriteString(mysocket, "\377\377\377\377accept", peeraddress);
2926                                         }
2927                                         return true;
2928                                 }
2929                         }
2930
2931                         if (NetConn_PreventConnectFlood(peeraddress))
2932                                 return true;
2933
2934                         // find an empty client slot for this new client
2935                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
2936                         {
2937                                 netconn_t *conn;
2938                                 if (!client->active && (conn = NetConn_Open(mysocket, peeraddress)))
2939                                 {
2940                                         // allocated connection
2941                                         if (developer_extra.integer)
2942                                                 Con_Printf("Datagram_ParseConnectionless: sending \"accept\" to %s.\n", conn->address);
2943                                         NetConn_WriteString(mysocket, "\377\377\377\377accept", peeraddress);
2944                                         // now set up the client
2945                                         if(crypto && crypto->authenticated)
2946                                                 Crypto_ServerFinishInstance(&conn->crypto, crypto);
2947                                         SV_VM_Begin();
2948                                         SV_ConnectClient(clientnum, conn);
2949                                         SV_VM_End();
2950                                         NetConn_Heartbeat(1);
2951                                         return true;
2952                                 }
2953                         }
2954
2955                         // no empty slots found - server is full
2956                         if (developer_extra.integer)
2957                                 Con_Printf("Datagram_ParseConnectionless: sending \"reject Server is full.\" to %s.\n", addressstring2);
2958                         NetConn_WriteString(mysocket, "\377\377\377\377reject Server is full.", peeraddress);
2959
2960                         return true;
2961                 }
2962                 if (length >= 7 && !memcmp(string, "getinfo", 7) && (islocal || sv_public.integer > -1))
2963                 {
2964                         const char *challenge = NULL;
2965
2966                         // If there was a challenge in the getinfo message
2967                         if (length > 8 && string[7] == ' ')
2968                                 challenge = string + 8;
2969
2970                         if (NetConn_BuildStatusResponse(challenge, response, sizeof(response), false))
2971                         {
2972                                 if (developer_extra.integer)
2973                                         Con_DPrintf("Sending reply to master %s - %s\n", addressstring2, response);
2974                                 NetConn_WriteString(mysocket, response, peeraddress);
2975                         }
2976                         return true;
2977                 }
2978                 if (length >= 9 && !memcmp(string, "getstatus", 9) && (islocal || sv_public.integer > -1))
2979                 {
2980                         const char *challenge = NULL;
2981
2982                         // If there was a challenge in the getinfo message
2983                         if (length > 10 && string[9] == ' ')
2984                                 challenge = string + 10;
2985
2986                         if (NetConn_BuildStatusResponse(challenge, response, sizeof(response), true))
2987                         {
2988                                 if (developer_extra.integer)
2989                                         Con_DPrintf("Sending reply to client %s - %s\n", addressstring2, response);
2990                                 NetConn_WriteString(mysocket, response, peeraddress);
2991                         }
2992                         return true;
2993                 }
2994                 if (length >= 37 && !memcmp(string, "srcon HMAC-MD4 TIME ", 20))
2995                 {
2996                         char *password = string + 20;
2997                         char *timeval = string + 37;
2998                         char *s = strchr(timeval, ' ');
2999                         char *endpos = string + length + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
3000                         const char *userlevel;
3001
3002                         if(rcon_secure.integer > 1)
3003                                 return true;
3004
3005                         if(!s)
3006                                 return true; // invalid packet
3007                         ++s;
3008
3009                         userlevel = RCon_Authenticate(peeraddress, password, s, endpos, hmac_mdfour_time_matching, timeval, endpos - timeval - 1); // not including the appended \0 into the HMAC
3010                         RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, false);
3011                         return true;
3012                 }
3013                 if (length >= 42 && !memcmp(string, "srcon HMAC-MD4 CHALLENGE ", 25))
3014                 {
3015                         char *password = string + 25;
3016                         char *challenge = string + 42;
3017                         char *s = strchr(challenge, ' ');
3018                         char *endpos = string + length + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
3019                         const char *userlevel;
3020                         if(!s)
3021                                 return true; // invalid packet
3022                         ++s;
3023
3024                         userlevel = RCon_Authenticate(peeraddress, password, s, endpos, hmac_mdfour_challenge_matching, challenge, endpos - challenge - 1); // not including the appended \0 into the HMAC
3025                         RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, false);
3026                         return true;
3027                 }
3028                 if (length >= 5 && !memcmp(string, "rcon ", 5))
3029                 {
3030                         int i;
3031                         char *s = string + 5;
3032                         char *endpos = string + length + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
3033                         char password[64];
3034
3035                         if(rcon_secure.integer > 0)
3036                                 return true;
3037
3038                         for (i = 0;!ISWHITESPACE(*s);s++)
3039                                 if (i < (int)sizeof(password) - 1)
3040                                         password[i++] = *s;
3041                         if(ISWHITESPACE(*s) && s != endpos) // skip leading ugly space
3042                                 ++s;
3043                         password[i] = 0;
3044                         if (!ISWHITESPACE(password[0]))
3045                         {
3046                                 const char *userlevel = RCon_Authenticate(peeraddress, password, s, endpos, plaintext_matching, NULL, 0);
3047                                 RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, false);
3048                         }
3049                         return true;
3050                 }
3051                 if (!strncmp(string, "extResponse ", 12))
3052                 {
3053                         ++sv_net_extresponse_count;
3054                         if(sv_net_extresponse_count > NET_EXTRESPONSE_MAX)
3055                                 sv_net_extresponse_count = NET_EXTRESPONSE_MAX;
3056                         sv_net_extresponse_last = (sv_net_extresponse_last + 1) % NET_EXTRESPONSE_MAX;
3057                         dpsnprintf(sv_net_extresponse[sv_net_extresponse_last], sizeof(sv_net_extresponse[sv_net_extresponse_last]), "'%s' %s", addressstring2, string + 12);
3058                         return true;
3059                 }
3060                 if (!strncmp(string, "ping", 4))
3061                 {
3062                         if (developer_extra.integer)
3063                                 Con_DPrintf("Received ping from %s, sending ack\n", addressstring2);
3064                         NetConn_WriteString(mysocket, "\377\377\377\377ack", peeraddress);
3065                         return true;
3066                 }
3067                 if (!strncmp(string, "ack", 3))
3068                         return true;
3069                 // we may not have liked the packet, but it was a command packet, so
3070                 // we're done processing this packet now
3071                 return true;
3072         }
3073         // netquake control packets, supported for compatibility only, and only
3074         // when running game protocols that are normally served via this connection
3075         // protocol
3076         // (this protects more modern protocols against being used for
3077         //  Quake packet flood Denial Of Service attacks)
3078         if (length >= 5 && (i = BuffBigLong(data)) && (i & (~NETFLAG_LENGTH_MASK)) == (int)NETFLAG_CTL && (i & NETFLAG_LENGTH_MASK) == length && (sv.protocol == PROTOCOL_QUAKE || sv.protocol == PROTOCOL_QUAKEDP || sv.protocol == PROTOCOL_NEHAHRAMOVIE || sv.protocol == PROTOCOL_NEHAHRABJP || sv.protocol == PROTOCOL_NEHAHRABJP2 || sv.protocol == PROTOCOL_NEHAHRABJP3 || sv.protocol == PROTOCOL_DARKPLACES1 || sv.protocol == PROTOCOL_DARKPLACES2 || sv.protocol == PROTOCOL_DARKPLACES3) && !ENCRYPTION_REQUIRED)
3079         {
3080                 int c;
3081                 int protocolnumber;
3082                 const char *protocolname;
3083                 data += 4;
3084                 length -= 4;
3085                 SZ_Clear(&net_message);
3086                 SZ_Write(&net_message, data, length);
3087                 MSG_BeginReading();
3088                 c = MSG_ReadByte();
3089                 switch (c)
3090                 {
3091                 case CCREQ_CONNECT:
3092                         if (developer_extra.integer)
3093                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_CONNECT from %s.\n", addressstring2);
3094                         if(!(islocal || sv_public.integer > -2))
3095                         {
3096                                 if (developer_extra.integer)
3097                                         Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_REJECT \"%s\" to %s.\n", sv_public_rejectreason.string, addressstring2);
3098                                 SZ_Clear(&net_message);
3099                                 // save space for the header, filled in later
3100                                 MSG_WriteLong(&net_message, 0);
3101                                 MSG_WriteByte(&net_message, CCREP_REJECT);
3102                                 MSG_WriteString(&net_message, va("%s\n", sv_public_rejectreason.string));
3103                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3104                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3105                                 SZ_Clear(&net_message);
3106                                 break;
3107                         }
3108
3109                         protocolname = MSG_ReadString();
3110                         protocolnumber = MSG_ReadByte();
3111                         if (strcmp(protocolname, "QUAKE") || protocolnumber != NET_PROTOCOL_VERSION)
3112                         {
3113                                 if (developer_extra.integer)
3114                                         Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_REJECT \"Incompatible version.\" to %s.\n", addressstring2);
3115                                 SZ_Clear(&net_message);
3116                                 // save space for the header, filled in later
3117                                 MSG_WriteLong(&net_message, 0);
3118                                 MSG_WriteByte(&net_message, CCREP_REJECT);
3119                                 MSG_WriteString(&net_message, "Incompatible version.\n");
3120                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3121                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3122                                 SZ_Clear(&net_message);
3123                                 break;
3124                         }
3125
3126                         // see if this connect request comes from a known client
3127                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
3128                         {
3129                                 if (client->netconnection && LHNETADDRESS_Compare(peeraddress, &client->netconnection->peeraddress) == 0)
3130                                 {
3131                                         // this is either a duplicate connection request
3132                                         // or coming back from a timeout
3133                                         // (if so, keep their stuff intact)
3134
3135                                         // send a reply
3136                                         if (developer_extra.integer)
3137                                                 Con_DPrintf("Datagram_ParseConnectionless: sending duplicate CCREP_ACCEPT to %s.\n", addressstring2);
3138                                         SZ_Clear(&net_message);
3139                                         // save space for the header, filled in later
3140                                         MSG_WriteLong(&net_message, 0);
3141                                         MSG_WriteByte(&net_message, CCREP_ACCEPT);
3142                                         MSG_WriteLong(&net_message, LHNETADDRESS_GetPort(LHNET_AddressFromSocket(client->netconnection->mysocket)));
3143                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3144                                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3145                                         SZ_Clear(&net_message);
3146
3147                                         // if client is already spawned, re-send the
3148                                         // serverinfo message as they'll need it to play
3149                                         if (client->spawned)
3150                                         {
3151                                                 SV_VM_Begin();
3152                                                 SV_SendServerinfo(client);
3153                                                 SV_VM_End();
3154                                         }
3155                                         return true;
3156                                 }
3157                         }
3158
3159                         // this is a new client, check for connection flood
3160                         if (NetConn_PreventConnectFlood(peeraddress))
3161                                 break;
3162
3163                         // find a slot for the new client
3164                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
3165                         {
3166                                 netconn_t *conn;
3167                                 if (!client->active && (client->netconnection = conn = NetConn_Open(mysocket, peeraddress)) != NULL)
3168                                 {
3169                                         // connect to the client
3170                                         // everything is allocated, just fill in the details
3171                                         strlcpy (conn->address, addressstring2, sizeof (conn->address));
3172                                         if (developer_extra.integer)
3173                                                 Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_ACCEPT to %s.\n", addressstring2);
3174                                         // send back the info about the server connection
3175                                         SZ_Clear(&net_message);
3176                                         // save space for the header, filled in later
3177                                         MSG_WriteLong(&net_message, 0);
3178                                         MSG_WriteByte(&net_message, CCREP_ACCEPT);
3179                                         MSG_WriteLong(&net_message, LHNETADDRESS_GetPort(LHNET_AddressFromSocket(conn->mysocket)));
3180                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3181                                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3182                                         SZ_Clear(&net_message);
3183                                         // now set up the client struct
3184                                         SV_VM_Begin();
3185                                         SV_ConnectClient(clientnum, conn);
3186                                         SV_VM_End();
3187                                         NetConn_Heartbeat(1);
3188                                         return true;
3189                                 }
3190                         }
3191
3192                         if (developer_extra.integer)
3193                                 Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_REJECT \"Server is full.\" to %s.\n", addressstring2);
3194                         // no room; try to let player know
3195                         SZ_Clear(&net_message);
3196                         // save space for the header, filled in later
3197                         MSG_WriteLong(&net_message, 0);
3198                         MSG_WriteByte(&net_message, CCREP_REJECT);
3199                         MSG_WriteString(&net_message, "Server is full.\n");
3200                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3201                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3202                         SZ_Clear(&net_message);
3203                         break;
3204                 case CCREQ_SERVER_INFO:
3205                         if (developer_extra.integer)
3206                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_SERVER_INFO from %s.\n", addressstring2);
3207                         if(!(islocal || sv_public.integer > -1))
3208                                 break;
3209                         if (sv.active && !strcmp(MSG_ReadString(), "QUAKE"))
3210                         {
3211                                 int numclients;
3212                                 char myaddressstring[128];
3213                                 if (developer_extra.integer)
3214                                         Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_SERVER_INFO to %s.\n", addressstring2);
3215                                 SZ_Clear(&net_message);
3216                                 // save space for the header, filled in later
3217                                 MSG_WriteLong(&net_message, 0);
3218                                 MSG_WriteByte(&net_message, CCREP_SERVER_INFO);
3219                                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(mysocket), myaddressstring, sizeof(myaddressstring), true);
3220                                 MSG_WriteString(&net_message, myaddressstring);
3221                                 MSG_WriteString(&net_message, hostname.string);
3222                                 MSG_WriteString(&net_message, sv.name);
3223                                 // How many clients are there?
3224                                 for (i = 0, numclients = 0;i < svs.maxclients;i++)
3225                                         if (svs.clients[i].active)
3226                                                 numclients++;
3227                                 MSG_WriteByte(&net_message, numclients);
3228                                 MSG_WriteByte(&net_message, svs.maxclients);
3229                                 MSG_WriteByte(&net_message, NET_PROTOCOL_VERSION);
3230                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3231                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3232                                 SZ_Clear(&net_message);
3233                         }
3234                         break;
3235                 case CCREQ_PLAYER_INFO:
3236                         if (developer_extra.integer)
3237                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_PLAYER_INFO from %s.\n", addressstring2);
3238                         if(!(islocal || sv_public.integer > -1))
3239                                 break;
3240                         if (sv.active)
3241                         {
3242                                 int playerNumber, activeNumber, clientNumber;
3243                                 client_t *client;
3244
3245                                 playerNumber = MSG_ReadByte();
3246                                 activeNumber = -1;
3247                                 for (clientNumber = 0, client = svs.clients; clientNumber < svs.maxclients; clientNumber++, client++)
3248                                         if (client->active && ++activeNumber == playerNumber)
3249                                                 break;
3250                                 if (clientNumber != svs.maxclients)
3251                                 {
3252                                         SZ_Clear(&net_message);
3253                                         // save space for the header, filled in later
3254                                         MSG_WriteLong(&net_message, 0);
3255                                         MSG_WriteByte(&net_message, CCREP_PLAYER_INFO);
3256                                         MSG_WriteByte(&net_message, playerNumber);
3257                                         MSG_WriteString(&net_message, client->name);
3258                                         MSG_WriteLong(&net_message, client->colors);
3259                                         MSG_WriteLong(&net_message, client->frags);
3260                                         MSG_WriteLong(&net_message, (int)(realtime - client->connecttime));
3261                                         if(sv_status_privacy.integer)
3262                                                 MSG_WriteString(&net_message, client->netconnection ? "hidden" : "botclient");
3263                                         else
3264                                                 MSG_WriteString(&net_message, client->netconnection ? client->netconnection->address : "botclient");
3265                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3266                                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3267                                         SZ_Clear(&net_message);
3268                                 }
3269                         }
3270                         break;
3271                 case CCREQ_RULE_INFO:
3272                         if (developer_extra.integer)
3273                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_RULE_INFO from %s.\n", addressstring2);
3274                         if(!(islocal || sv_public.integer > -1))
3275                                 break;
3276                         if (sv.active)
3277                         {
3278                                 char *prevCvarName;
3279                                 cvar_t *var;
3280
3281                                 // find the search start location
3282                                 prevCvarName = MSG_ReadString();
3283                                 var = Cvar_FindVarAfter(prevCvarName, CVAR_NOTIFY);
3284
3285                                 // send the response
3286                                 SZ_Clear(&net_message);
3287                                 // save space for the header, filled in later
3288                                 MSG_WriteLong(&net_message, 0);
3289                                 MSG_WriteByte(&net_message, CCREP_RULE_INFO);
3290                                 if (var)
3291                                 {
3292                                         MSG_WriteString(&net_message, var->name);
3293                                         MSG_WriteString(&net_message, var->string);
3294                                 }
3295                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3296                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3297                                 SZ_Clear(&net_message);
3298                         }
3299                         break;
3300                 case CCREQ_RCON:
3301                         if (developer_extra.integer)
3302                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_RCON from %s.\n", addressstring2);
3303                         if (sv.active && !rcon_secure.integer)
3304                         {
3305                                 char password[2048];
3306                                 char cmd[2048];
3307                                 char *s;
3308                                 char *endpos;
3309                                 const char *userlevel;
3310                                 strlcpy(password, MSG_ReadString(), sizeof(password));
3311                                 strlcpy(cmd, MSG_ReadString(), sizeof(cmd));
3312                                 s = cmd;
3313                                 endpos = cmd + strlen(cmd) + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
3314                                 userlevel = RCon_Authenticate(peeraddress, password, s, endpos, plaintext_matching, NULL, 0);
3315                                 RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, true);
3316                                 return true;
3317                         }
3318                         break;
3319                 default:
3320                         break;
3321                 }
3322                 SZ_Clear(&net_message);
3323                 // we may not have liked the packet, but it was a valid control
3324                 // packet, so we're done processing this packet now
3325                 return true;
3326         }
3327         if (host_client)
3328         {
3329                 if ((ret = NetConn_ReceivedMessage(host_client->netconnection, data, length, sv.protocol, host_client->spawned ? net_messagetimeout.value : net_connecttimeout.value)) == 2)
3330                 {
3331                         SV_VM_Begin();
3332                         SV_ReadClientMessage();
3333                         SV_VM_End();
3334                         return ret;
3335                 }
3336         }
3337         return 0;
3338 }
3339
3340 void NetConn_ServerFrame(void)
3341 {
3342         int i, length;
3343         lhnetaddress_t peeraddress;
3344         for (i = 0;i < sv_numsockets;i++)
3345                 while (sv_sockets[i] && (length = NetConn_Read(sv_sockets[i], readbuffer, sizeof(readbuffer), &peeraddress)) > 0)
3346                         NetConn_ServerParsePacket(sv_sockets[i], readbuffer, length, &peeraddress);
3347         for (i = 0, host_client = svs.clients;i < svs.maxclients;i++, host_client++)
3348         {
3349                 // never timeout loopback connections
3350                 if (host_client->netconnection && realtime > host_client->netconnection->timeout && LHNETADDRESS_GetAddressType(&host_client->netconnection->peeraddress) != LHNETADDRESSTYPE_LOOP)
3351                 {
3352                         Con_Printf("Client \"%s\" connection timed out\n", host_client->name);
3353                         SV_VM_Begin();
3354                         SV_DropClient(false);
3355                         SV_VM_End();
3356                 }
3357         }
3358 }
3359
3360 void NetConn_SleepMicroseconds(int microseconds)
3361 {
3362         LHNET_SleepUntilPacket_Microseconds(microseconds);
3363 }
3364
3365 void NetConn_QueryMasters(qboolean querydp, qboolean queryqw)
3366 {
3367         int i, j;
3368         int masternum;
3369         lhnetaddress_t masteraddress;
3370         lhnetaddress_t broadcastaddress;
3371         char request[256];
3372
3373         if (serverlist_cachecount >= SERVERLIST_TOTALSIZE)
3374                 return;
3375
3376         // 26000 is the default quake server port, servers on other ports will not
3377         // be found
3378         // note this is IPv4-only, I doubt there are IPv6-only LANs out there
3379         LHNETADDRESS_FromString(&broadcastaddress, "255.255.255.255", 26000);
3380
3381         if (querydp)
3382         {
3383                 for (i = 0;i < cl_numsockets;i++)
3384                 {
3385                         if (cl_sockets[i])
3386                         {
3387                                 const char *cmdname, *extraoptions;
3388                                 int af = LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i]));
3389
3390                                 if(LHNETADDRESS_GetAddressType(&broadcastaddress) == af)
3391                                 {
3392                                         // search LAN for Quake servers
3393                                         SZ_Clear(&net_message);
3394                                         // save space for the header, filled in later
3395                                         MSG_WriteLong(&net_message, 0);
3396                                         MSG_WriteByte(&net_message, CCREQ_SERVER_INFO);
3397                                         MSG_WriteString(&net_message, "QUAKE");
3398                                         MSG_WriteByte(&net_message, NET_PROTOCOL_VERSION);
3399                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3400                                         NetConn_Write(cl_sockets[i], net_message.data, net_message.cursize, &broadcastaddress);
3401                                         SZ_Clear(&net_message);
3402
3403                                         // search LAN for DarkPlaces servers
3404                                         NetConn_WriteString(cl_sockets[i], "\377\377\377\377getstatus", &broadcastaddress);
3405                                 }
3406
3407                                 // build the getservers message to send to the dpmaster master servers
3408                                 if (LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i])) == LHNETADDRESSTYPE_INET6)
3409                                 {
3410                                         cmdname = "getserversExt";
3411                                         extraoptions = " ipv4 ipv6";  // ask for IPv4 and IPv6 servers
3412                                 }
3413                                 else
3414                                 {
3415                                         cmdname = "getservers";
3416                                         extraoptions = "";
3417                                 }
3418                                 dpsnprintf(request, sizeof(request), "\377\377\377\377%s %s %u empty full%s", cmdname, gamename, NET_PROTOCOL_VERSION, extraoptions);
3419
3420                                 // search internet
3421                                 for (masternum = 0;sv_masters[masternum].name;masternum++)
3422                                 {
3423                                         if (sv_masters[masternum].string && sv_masters[masternum].string[0] && LHNETADDRESS_FromString(&masteraddress, sv_masters[masternum].string, DPMASTER_PORT) && LHNETADDRESS_GetAddressType(&masteraddress) == af)
3424                                         {
3425                                                 masterquerycount++;
3426                                                 NetConn_WriteString(cl_sockets[i], request, &masteraddress);
3427                                         }
3428                                 }
3429
3430                                 // search favorite servers
3431                                 for(j = 0; j < nFavorites; ++j)
3432                                 {
3433                                         if(LHNETADDRESS_GetAddressType(&favorites[j]) == af)
3434                                         {
3435                                                 if(LHNETADDRESS_ToString(&favorites[j], request, sizeof(request), true))
3436                                                         NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_DARKPLACES7, request, true );
3437                                         }
3438                                 }
3439                         }
3440                 }
3441         }
3442
3443         // only query QuakeWorld servers when the user wants to
3444         if (queryqw)
3445         {
3446                 for (i = 0;i < cl_numsockets;i++)
3447                 {
3448                         if (cl_sockets[i])
3449                         {
3450                                 int af = LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i]));
3451
3452                                 if(LHNETADDRESS_GetAddressType(&broadcastaddress) == af)
3453                                 {
3454                                         // search LAN for QuakeWorld servers
3455                                         NetConn_WriteString(cl_sockets[i], "\377\377\377\377status\n", &broadcastaddress);
3456
3457                                         // build the getservers message to send to the qwmaster master servers
3458                                         // note this has no -1 prefix, and the trailing nul byte is sent
3459                                         dpsnprintf(request, sizeof(request), "c\n");
3460                                 }
3461
3462                                 // search internet
3463                                 for (masternum = 0;sv_qwmasters[masternum].name;masternum++)
3464                                 {
3465                                         if (sv_qwmasters[masternum].string && LHNETADDRESS_FromString(&masteraddress, sv_qwmasters[masternum].string, QWMASTER_PORT) && LHNETADDRESS_GetAddressType(&masteraddress) == LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i])))
3466                                         {
3467                                                 if (m_state != m_slist)
3468                                                 {
3469                                                         char lookupstring[128];
3470                                                         LHNETADDRESS_ToString(&masteraddress, lookupstring, sizeof(lookupstring), true);
3471                                                         Con_Printf("Querying master %s (resolved from %s)\n", lookupstring, sv_qwmasters[masternum].string);
3472                                                 }
3473                                                 masterquerycount++;
3474                                                 NetConn_Write(cl_sockets[i], request, (int)strlen(request) + 1, &masteraddress);
3475                                         }
3476                                 }
3477
3478                                 // search favorite servers
3479                                 for(j = 0; j < nFavorites; ++j)
3480                                 {
3481                                         if(LHNETADDRESS_GetAddressType(&favorites[j]) == af)
3482                                         {
3483                                                 if(LHNETADDRESS_ToString(&favorites[j], request, sizeof(request), true))
3484                                                 {
3485                                                         NetConn_WriteString(cl_sockets[i], "\377\377\377\377status\n", &favorites[j]);
3486                                                         NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_QUAKEWORLD, request, true );
3487                                                 }
3488                                         }
3489                                 }
3490                         }
3491                 }
3492         }
3493         if (!masterquerycount)
3494         {
3495                 Con_Print("Unable to query master servers, no suitable network sockets active.\n");
3496                 M_Update_Return_Reason("No network");
3497         }
3498 }
3499
3500 void NetConn_Heartbeat(int priority)
3501 {
3502         lhnetaddress_t masteraddress;
3503         int masternum;
3504         lhnetsocket_t *mysocket;
3505
3506         // if it's a state change (client connected), limit next heartbeat to no
3507         // more than 30 sec in the future
3508         if (priority == 1 && nextheartbeattime > realtime + 30.0)
3509                 nextheartbeattime = realtime + 30.0;
3510
3511         // limit heartbeatperiod to 30 to 270 second range,
3512         // lower limit is to avoid abusing master servers with excess traffic,
3513         // upper limit is to avoid timing out on the master server (which uses
3514         // 300 sec timeout)
3515         if (sv_heartbeatperiod.value < 30)
3516                 Cvar_SetValueQuick(&sv_heartbeatperiod, 30);
3517         if (sv_heartbeatperiod.value > 270)
3518                 Cvar_SetValueQuick(&sv_heartbeatperiod, 270);
3519
3520         // make advertising optional and don't advertise singleplayer games, and
3521         // only send a heartbeat as often as the admin wants
3522         if (sv.active && sv_public.integer > 0 && svs.maxclients >= 2 && (priority > 1 || realtime > nextheartbeattime))
3523         {
3524                 nextheartbeattime = realtime + sv_heartbeatperiod.value;
3525                 for (masternum = 0;sv_masters[masternum].name;masternum++)
3526                         if (sv_masters[masternum].string && sv_masters[masternum].string[0] && LHNETADDRESS_FromString(&masteraddress, sv_masters[masternum].string, DPMASTER_PORT) && (mysocket = NetConn_ChooseServerSocketForAddress(&masteraddress)))
3527                                 NetConn_WriteString(mysocket, "\377\377\377\377heartbeat DarkPlaces\x0A", &masteraddress);
3528         }
3529 }
3530
3531 static void Net_Heartbeat_f(void)
3532 {
3533         if (sv.active)
3534                 NetConn_Heartbeat(2);
3535         else
3536                 Con_Print("No server running, can not heartbeat to master server.\n");
3537 }
3538
3539 void PrintStats(netconn_t *conn)
3540 {
3541         if ((cls.state == ca_connected && cls.protocol == PROTOCOL_QUAKEWORLD) || (sv.active && sv.protocol == PROTOCOL_QUAKEWORLD))
3542                 Con_Printf("address=%21s canSend=%u sendSeq=%6u recvSeq=%6u\n", conn->address, !conn->sendMessageLength, conn->outgoing_unreliable_sequence, conn->qw.incoming_sequence);
3543         else
3544                 Con_Printf("address=%21s canSend=%u sendSeq=%6u recvSeq=%6u\n", conn->address, !conn->sendMessageLength, conn->nq.sendSequence, conn->nq.receiveSequence);
3545 }
3546
3547 void Net_Stats_f(void)
3548 {
3549         netconn_t *conn;
3550         Con_Printf("unreliable messages sent   = %i\n", unreliableMessagesSent);
3551         Con_Printf("unreliable messages recv   = %i\n", unreliableMessagesReceived);
3552         Con_Printf("reliable messages sent     = %i\n", reliableMessagesSent);
3553         Con_Printf("reliable messages received = %i\n", reliableMessagesReceived);
3554         Con_Printf("packetsSent                = %i\n", packetsSent);
3555         Con_Printf("packetsReSent              = %i\n", packetsReSent);
3556         Con_Printf("packetsReceived            = %i\n", packetsReceived);
3557         Con_Printf("receivedDuplicateCount     = %i\n", receivedDuplicateCount);
3558         Con_Printf("droppedDatagrams           = %i\n", droppedDatagrams);
3559         Con_Print("connections                =\n");
3560         for (conn = netconn_list;conn;conn = conn->next)
3561                 PrintStats(conn);
3562 }
3563
3564 void Net_Refresh_f(void)
3565 {
3566         if (m_state != m_slist) {
3567                 Con_Print("Sending new requests to master servers\n");
3568                 ServerList_QueryList(false, true, false, true);
3569                 Con_Print("Listening for replies...\n");
3570         } else
3571                 ServerList_QueryList(false, true, false, false);
3572 }
3573
3574 void Net_Slist_f(void)
3575 {
3576         ServerList_ResetMasks();
3577         serverlist_sortbyfield = SLIF_PING;
3578         serverlist_sortflags = 0;
3579     if (m_state != m_slist) {
3580                 Con_Print("Sending requests to master servers\n");
3581                 ServerList_QueryList(true, true, false, true);
3582                 Con_Print("Listening for replies...\n");
3583         } else
3584                 ServerList_QueryList(true, true, false, false);
3585 }
3586
3587 void Net_SlistQW_f(void)
3588 {
3589         ServerList_ResetMasks();
3590         serverlist_sortbyfield = SLIF_PING;
3591         serverlist_sortflags = 0;
3592     if (m_state != m_slist) {
3593                 Con_Print("Sending requests to master servers\n");
3594                 ServerList_QueryList(true, false, true, true);
3595                 serverlist_consoleoutput = true;
3596                 Con_Print("Listening for replies...\n");
3597         } else
3598                 ServerList_QueryList(true, false, true, false);
3599 }
3600
3601 void NetConn_Init(void)
3602 {
3603         int i;
3604         lhnetaddress_t tempaddress;
3605         netconn_mempool = Mem_AllocPool("network connections", 0, NULL);
3606         Cmd_AddCommand("net_stats", Net_Stats_f, "print network statistics");
3607         Cmd_AddCommand("net_slist", Net_Slist_f, "query dp master servers and print all server information");
3608         Cmd_AddCommand("net_slistqw", Net_SlistQW_f, "query qw master servers and print all server information");
3609         Cmd_AddCommand("net_refresh", Net_Refresh_f, "query dp master servers and refresh all server information");
3610         Cmd_AddCommand("heartbeat", Net_Heartbeat_f, "send a heartbeat to the master server (updates your server information)");
3611         Cvar_RegisterVariable(&rcon_restricted_password);
3612         Cvar_RegisterVariable(&rcon_restricted_commands);
3613         Cvar_RegisterVariable(&rcon_secure_maxdiff);
3614         Cvar_RegisterVariable(&net_slist_queriespersecond);
3615         Cvar_RegisterVariable(&net_slist_queriesperframe);
3616         Cvar_RegisterVariable(&net_slist_timeout);
3617         Cvar_RegisterVariable(&net_slist_maxtries);
3618         Cvar_RegisterVariable(&net_slist_favorites);
3619         Cvar_RegisterVariable(&net_slist_pause);
3620         Cvar_RegisterVariable(&net_messagetimeout);
3621         Cvar_RegisterVariable(&net_connecttimeout);
3622         Cvar_RegisterVariable(&net_connectfloodblockingtimeout);
3623         Cvar_RegisterVariable(&cl_netlocalping);
3624         Cvar_RegisterVariable(&cl_netpacketloss_send);
3625         Cvar_RegisterVariable(&cl_netpacketloss_receive);
3626         Cvar_RegisterVariable(&hostname);
3627         Cvar_RegisterVariable(&developer_networking);
3628         Cvar_RegisterVariable(&cl_netport);
3629         Cvar_RegisterVariable(&sv_netport);
3630         Cvar_RegisterVariable(&net_address);
3631         Cvar_RegisterVariable(&net_address_ipv6);
3632         Cvar_RegisterVariable(&sv_public);
3633         Cvar_RegisterVariable(&sv_public_rejectreason);
3634         Cvar_RegisterVariable(&sv_heartbeatperiod);
3635         for (i = 0;sv_masters[i].name;i++)
3636                 Cvar_RegisterVariable(&sv_masters[i]);
3637         Cvar_RegisterVariable(&gameversion);
3638         Cvar_RegisterVariable(&gameversion_min);
3639         Cvar_RegisterVariable(&gameversion_max);
3640 // COMMANDLINEOPTION: Server: -ip <ipaddress> sets the ip address of this machine for purposes of networking (default 0.0.0.0 also known as INADDR_ANY), use only if you have multiple network adapters and need to choose one specifically.
3641         if ((i = COM_CheckParm("-ip")) && i + 1 < com_argc)
3642         {
3643                 if (LHNETADDRESS_FromString(&tempaddress, com_argv[i + 1], 0) == 1)
3644                 {
3645                         Con_Printf("-ip option used, setting net_address to \"%s\"\n", com_argv[i + 1]);
3646                         Cvar_SetQuick(&net_address, com_argv[i + 1]);
3647                 }
3648                 else
3649                         Con_Printf("-ip option used, but unable to parse the address \"%s\"\n", com_argv[i + 1]);
3650         }
3651 // COMMANDLINEOPTION: Server: -port <portnumber> sets the port to use for a server (default 26000, the same port as QUAKE itself), useful if you host multiple servers on your machine
3652         if (((i = COM_CheckParm("-port")) || (i = COM_CheckParm("-ipport")) || (i = COM_CheckParm("-udpport"))) && i + 1 < com_argc)
3653         {
3654                 i = atoi(com_argv[i + 1]);
3655                 if (i >= 0 && i < 65536)
3656                 {
3657                         Con_Printf("-port option used, setting port cvar to %i\n", i);
3658                         Cvar_SetValueQuick(&sv_netport, i);
3659                 }
3660                 else
3661                         Con_Printf("-port option used, but %i is not a valid port number\n", i);
3662         }
3663         cl_numsockets = 0;
3664         sv_numsockets = 0;
3665         net_message.data = net_message_buf;
3666         net_message.maxsize = sizeof(net_message_buf);
3667         net_message.cursize = 0;
3668         LHNET_Init();
3669         if (Thread_HasThreads())
3670                 netconn_mutex = Thread_CreateMutex();
3671 }
3672
3673 void NetConn_Shutdown(void)
3674 {
3675         NetConn_CloseClientPorts();
3676         NetConn_CloseServerPorts();
3677         LHNET_Shutdown();
3678         if (netconn_mutex)
3679                 Thread_DestroyMutex(netconn_mutex);
3680         netconn_mutex = NULL;
3681 }
3682