]> git.xonotic.org Git - xonotic/darkplaces.git/blob - netconn.c
Command line: -sessionid, cvars: locksession, (R/O) sessionid
[xonotic/darkplaces.git] / netconn.c
1 /*
2 Copyright (C) 1996-1997 Id Software, Inc.
3 Copyright (C) 2002 Mathieu Olivier
4 Copyright (C) 2003 Forest Hale
5
6 This program is free software; you can redistribute it and/or
7 modify it under the terms of the GNU General Public License
8 as published by the Free Software Foundation; either version 2
9 of the License, or (at your option) any later version.
10
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
14
15 See the GNU General Public License for more details.
16
17 You should have received a copy of the GNU General Public License
18 along with this program; if not, write to the Free Software
19 Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307, USA.
20
21 */
22
23 #include "quakedef.h"
24 #include "lhnet.h"
25
26 // for secure rcon authentication
27 #include "hmac.h"
28 #include "mdfour.h"
29 #include <time.h>
30
31 #define QWMASTER_PORT 27000
32 #define DPMASTER_PORT 27950
33
34 // note this defaults on for dedicated servers, off for listen servers
35 cvar_t sv_public = {0, "sv_public", "0", "1: advertises this server on the master server (so that players can find it in the server browser); 0: allow direct queries only; -1: do not respond to direct queries; -2: do not allow anyone to connect; -3: already block at getchallenge level"};
36 cvar_t sv_public_rejectreason = {0, "sv_public_rejectreason", "The server is closing.", "Rejection reason for connects when sv_public is -2"};
37 static cvar_t sv_heartbeatperiod = {CVAR_SAVE, "sv_heartbeatperiod", "120", "how often to send heartbeat in seconds (only used if sv_public is 1)"};
38 extern cvar_t sv_status_privacy;
39
40 static cvar_t sv_masters [] =
41 {
42         {CVAR_SAVE, "sv_master1", "", "user-chosen master server 1"},
43         {CVAR_SAVE, "sv_master2", "", "user-chosen master server 2"},
44         {CVAR_SAVE, "sv_master3", "", "user-chosen master server 3"},
45         {CVAR_SAVE, "sv_master4", "", "user-chosen master server 4"},
46         {0, "sv_masterextra1", "69.59.212.88", "ghdigital.com - default master server 1 (admin: LordHavoc)"}, // admin: LordHavoc
47         {0, "sv_masterextra2", "64.22.107.125", "dpmaster.deathmask.net - default master server 2 (admin: Willis)"}, // admin: Willis
48         {0, "sv_masterextra3", "92.62.40.73", "dpmaster.tchr.no - default master server 3 (admin: tChr)"}, // admin: tChr
49 #ifdef SUPPORTIPV6
50         {0, "sv_masterextra4", "[2001:41d0:2:1628::4450]:27950", "dpmaster.div0.qc.to - default master server 4 (admin: divVerent)"}, // admin: divVerent
51 #endif
52         {0, NULL, NULL, NULL}
53 };
54
55 static cvar_t sv_qwmasters [] =
56 {
57         {CVAR_SAVE, "sv_qwmaster1", "", "user-chosen qwmaster server 1"},
58         {CVAR_SAVE, "sv_qwmaster2", "", "user-chosen qwmaster server 2"},
59         {CVAR_SAVE, "sv_qwmaster3", "", "user-chosen qwmaster server 3"},
60         {CVAR_SAVE, "sv_qwmaster4", "", "user-chosen qwmaster server 4"},
61         {0, "sv_qwmasterextra1", "master.quakeservers.net:27000", "Global master server. (admin: unknown)"},
62         {0, "sv_qwmasterextra2", "asgaard.morphos-team.net:27000", "Global master server. (admin: unknown)"},
63         {0, "sv_qwmasterextra3", "qwmaster.ocrana.de:27000", "German master server. (admin: unknown)"},
64         {0, "sv_qwmasterextra4", "masterserver.exhale.de:27000", "German master server. (admin: unknown)"},
65         {0, "sv_qwmasterextra5", "qwmaster.fodquake.net:27000", "Global master server. (admin: unknown)"},
66         {0, NULL, NULL, NULL}
67 };
68
69 static double nextheartbeattime = 0;
70
71 sizebuf_t net_message;
72 static unsigned char net_message_buf[NET_MAXMESSAGE];
73
74 cvar_t net_messagetimeout = {0, "net_messagetimeout","300", "drops players who have not sent any packets for this many seconds"};
75 cvar_t net_connecttimeout = {0, "net_connecttimeout","15", "after requesting a connection, the client must reply within this many seconds or be dropped (cuts down on connect floods). Must be above 10 seconds."};
76 cvar_t net_connectfloodblockingtimeout = {0, "net_connectfloodblockingtimeout", "5", "when a connection packet is received, it will block all future connect packets from that IP address for this many seconds (cuts down on connect floods)"};
77 cvar_t hostname = {CVAR_SAVE, "hostname", "UNNAMED", "server message to show in server browser"};
78 cvar_t developer_networking = {0, "developer_networking", "0", "prints all received and sent packets (recommended only for debugging)"};
79
80 cvar_t cl_netlocalping = {0, "cl_netlocalping","0", "lags local loopback connection by this much ping time (useful to play more fairly on your own server with people with higher pings)"};
81 static cvar_t cl_netpacketloss_send = {0, "cl_netpacketloss_send","0", "drops this percentage of outgoing packets, useful for testing network protocol robustness (jerky movement, prediction errors, etc)"};
82 static cvar_t cl_netpacketloss_receive = {0, "cl_netpacketloss_receive","0", "drops this percentage of incoming packets, useful for testing network protocol robustness (jerky movement, effects failing to start, sounds failing to play, etc)"};
83 static cvar_t net_slist_queriespersecond = {0, "net_slist_queriespersecond", "20", "how many server information requests to send per second"};
84 static cvar_t net_slist_queriesperframe = {0, "net_slist_queriesperframe", "4", "maximum number of server information requests to send each rendered frame (guards against low framerates causing problems)"};
85 static cvar_t net_slist_timeout = {0, "net_slist_timeout", "4", "how long to listen for a server information response before giving up"};
86 static cvar_t net_slist_pause = {0, "net_slist_pause", "0", "when set to 1, the server list won't update until it is set back to 0"};
87 static cvar_t net_slist_maxtries = {0, "net_slist_maxtries", "3", "how many times to ask the same server for information (more times gives better ping reports but takes longer)"};
88 static cvar_t net_slist_favorites = {CVAR_SAVE | CVAR_NQUSERINFOHACK, "net_slist_favorites", "", "contains a list of IP addresses and ports to always query explicitly"};
89 static cvar_t gameversion = {0, "gameversion", "0", "version of game data (mod-specific) to be sent to querying clients"};
90 static cvar_t gameversion_min = {0, "gameversion_min", "-1", "minimum version of game data (mod-specific), when client and server gameversion mismatch in the server browser the server is shown as incompatible; if -1, gameversion is used alone"};
91 static cvar_t gameversion_max = {0, "gameversion_max", "-1", "maximum version of game data (mod-specific), when client and server gameversion mismatch in the server browser the server is shown as incompatible; if -1, gameversion is used alone"};
92 static cvar_t rcon_restricted_password = {CVAR_PRIVATE, "rcon_restricted_password", "", "password to authenticate rcon commands in restricted mode; may be set to a string of the form user1:pass1 user2:pass2 user3:pass3 to allow multiple user accounts - the client then has to specify ONE of these combinations"};
93 static cvar_t rcon_restricted_commands = {0, "rcon_restricted_commands", "", "allowed commands for rcon when the restricted mode password was used"};
94 static cvar_t rcon_secure_maxdiff = {0, "rcon_secure_maxdiff", "5", "maximum time difference between rcon request and server system clock (to protect against replay attack)"};
95 extern cvar_t rcon_secure;
96 extern cvar_t rcon_secure_challengetimeout;
97
98 /* statistic counters */
99 static int packetsSent = 0;
100 static int packetsReSent = 0;
101 static int packetsReceived = 0;
102 static int receivedDuplicateCount = 0;
103 static int droppedDatagrams = 0;
104
105 static int unreliableMessagesSent = 0;
106 static int unreliableMessagesReceived = 0;
107 static int reliableMessagesSent = 0;
108 static int reliableMessagesReceived = 0;
109
110 double masterquerytime = -1000;
111 int masterquerycount = 0;
112 int masterreplycount = 0;
113 int serverquerycount = 0;
114 int serverreplycount = 0;
115
116 challenge_t challenge[MAX_CHALLENGES];
117
118 /// this is only false if there are still servers left to query
119 static qboolean serverlist_querysleep = true;
120 static qboolean serverlist_paused = false;
121 /// this is pushed a second or two ahead of realtime whenever a master server
122 /// reply is received, to avoid issuing queries while master replies are still
123 /// flooding in (which would make a mess of the ping times)
124 static double serverlist_querywaittime = 0;
125
126 static unsigned char sendbuffer[NET_HEADERSIZE+NET_MAXMESSAGE];
127 static unsigned char readbuffer[NET_HEADERSIZE+NET_MAXMESSAGE];
128 static unsigned char cryptosendbuffer[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
129 static unsigned char cryptoreadbuffer[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
130
131 static int cl_numsockets;
132 static lhnetsocket_t *cl_sockets[16];
133 static int sv_numsockets;
134 static lhnetsocket_t *sv_sockets[16];
135
136 netconn_t *netconn_list = NULL;
137 mempool_t *netconn_mempool = NULL;
138
139 cvar_t cl_netport = {0, "cl_port", "0", "forces client to use chosen port number if not 0"};
140 cvar_t sv_netport = {0, "port", "26000", "server port for players to connect to"};
141 cvar_t net_address = {0, "net_address", "", "network address to open ipv4 ports on (if empty, use default interfaces)"};
142 cvar_t net_address_ipv6 = {0, "net_address_ipv6", "", "network address to open ipv6 ports on (if empty, use default interfaces)"};
143
144 char cl_net_extresponse[NET_EXTRESPONSE_MAX][1400];
145 int cl_net_extresponse_count = 0;
146 int cl_net_extresponse_last = 0;
147
148 char sv_net_extresponse[NET_EXTRESPONSE_MAX][1400];
149 int sv_net_extresponse_count = 0;
150 int sv_net_extresponse_last = 0;
151
152 // ServerList interface
153 serverlist_mask_t serverlist_andmasks[SERVERLIST_ANDMASKCOUNT];
154 serverlist_mask_t serverlist_ormasks[SERVERLIST_ORMASKCOUNT];
155
156 serverlist_infofield_t serverlist_sortbyfield;
157 int serverlist_sortflags;
158
159 int serverlist_viewcount = 0;
160 unsigned short serverlist_viewlist[SERVERLIST_VIEWLISTSIZE];
161
162 int serverlist_maxcachecount = 0;
163 int serverlist_cachecount = 0;
164 serverlist_entry_t *serverlist_cache = NULL;
165
166 qboolean serverlist_consoleoutput;
167
168 static int nFavorites = 0;
169 static lhnetaddress_t favorites[MAX_FAVORITESERVERS];
170 static int nFavorites_idfp = 0;
171 static char favorites_idfp[MAX_FAVORITESERVERS][FP64_SIZE+1];
172
173 void NetConn_UpdateFavorites(void)
174 {
175         const char *p;
176         nFavorites = 0;
177         nFavorites_idfp = 0;
178         p = net_slist_favorites.string;
179         while((size_t) nFavorites < sizeof(favorites) / sizeof(*favorites) && COM_ParseToken_Console(&p))
180         {
181                 if(com_token[0] != '[' && strlen(com_token) == FP64_SIZE && !strchr(com_token, '.'))
182                 // currently 44 bytes, longest possible IPv6 address: 39 bytes, so this works
183                 // (if v6 address contains port, it must start with '[')
184                 {
185                         strlcpy(favorites_idfp[nFavorites_idfp], com_token, sizeof(favorites_idfp[nFavorites_idfp]));
186                         ++nFavorites_idfp;
187                 }
188                 else 
189                 {
190                         if(LHNETADDRESS_FromString(&favorites[nFavorites], com_token, 26000))
191                                 ++nFavorites;
192                 }
193         }
194 }
195
196 /// helper function to insert a value into the viewset
197 /// spare entries will be removed
198 static void _ServerList_ViewList_Helper_InsertBefore( int index, serverlist_entry_t *entry )
199 {
200     int i;
201         if( serverlist_viewcount < SERVERLIST_VIEWLISTSIZE ) {
202                 i = serverlist_viewcount++;
203         } else {
204                 i = SERVERLIST_VIEWLISTSIZE - 1;
205         }
206
207         for( ; i > index ; i-- )
208                 serverlist_viewlist[ i ] = serverlist_viewlist[ i - 1 ];
209
210         serverlist_viewlist[index] = (int)(entry - serverlist_cache);
211 }
212
213 /// we suppose serverlist_viewcount to be valid, ie > 0
214 static void _ServerList_ViewList_Helper_Remove( int index )
215 {
216         serverlist_viewcount--;
217         for( ; index < serverlist_viewcount ; index++ )
218                 serverlist_viewlist[index] = serverlist_viewlist[index + 1];
219 }
220
221 /// \returns true if A should be inserted before B
222 static qboolean _ServerList_Entry_Compare( serverlist_entry_t *A, serverlist_entry_t *B )
223 {
224         int result = 0; // > 0 if for numbers A > B and for text if A < B
225
226         if( serverlist_sortflags & SLSF_FAVORITESFIRST )
227         {
228                 if(A->info.isfavorite != B->info.isfavorite)
229                         return A->info.isfavorite;
230         }
231
232         switch( serverlist_sortbyfield ) {
233                 case SLIF_PING:
234                         result = A->info.ping - B->info.ping;
235                         break;
236                 case SLIF_MAXPLAYERS:
237                         result = A->info.maxplayers - B->info.maxplayers;
238                         break;
239                 case SLIF_NUMPLAYERS:
240                         result = A->info.numplayers - B->info.numplayers;
241                         break;
242                 case SLIF_NUMBOTS:
243                         result = A->info.numbots - B->info.numbots;
244                         break;
245                 case SLIF_NUMHUMANS:
246                         result = A->info.numhumans - B->info.numhumans;
247                         break;
248                 case SLIF_FREESLOTS:
249                         result = A->info.freeslots - B->info.freeslots;
250                         break;
251                 case SLIF_PROTOCOL:
252                         result = A->info.protocol - B->info.protocol;
253                         break;
254                 case SLIF_CNAME:
255                         result = strcmp( B->info.cname, A->info.cname );
256                         break;
257                 case SLIF_GAME:
258                         result = strcasecmp( B->info.game, A->info.game );
259                         break;
260                 case SLIF_MAP:
261                         result = strcasecmp( B->info.map, A->info.map );
262                         break;
263                 case SLIF_MOD:
264                         result = strcasecmp( B->info.mod, A->info.mod );
265                         break;
266                 case SLIF_NAME:
267                         result = strcasecmp( B->info.name, A->info.name );
268                         break;
269                 case SLIF_QCSTATUS:
270                         result = strcasecmp( B->info.qcstatus, A->info.qcstatus ); // not really THAT useful, though
271                         break;
272                 case SLIF_ISFAVORITE:
273                         result = !!B->info.isfavorite - !!A->info.isfavorite;
274                         break;
275                 default:
276                         Con_DPrint( "_ServerList_Entry_Compare: Bad serverlist_sortbyfield!\n" );
277                         break;
278         }
279
280         if (result != 0)
281         {
282                 if( serverlist_sortflags & SLSF_DESCENDING )
283                         return result > 0;
284                 else
285                         return result < 0;
286         }
287
288         // if the chosen sort key is identical, sort by index
289         // (makes this a stable sort, so that later replies from servers won't
290         //  shuffle the servers around when they have the same ping)
291         return A < B;
292 }
293
294 static qboolean _ServerList_CompareInt( int A, serverlist_maskop_t op, int B )
295 {
296         // This should actually be done with some intermediate and end-of-function return
297         switch( op ) {
298                 case SLMO_LESS:
299                         return A < B;
300                 case SLMO_LESSEQUAL:
301                         return A <= B;
302                 case SLMO_EQUAL:
303                         return A == B;
304                 case SLMO_GREATER:
305                         return A > B;
306                 case SLMO_NOTEQUAL:
307                         return A != B;
308                 case SLMO_GREATEREQUAL:
309                 case SLMO_CONTAINS:
310                 case SLMO_NOTCONTAIN:
311                 case SLMO_STARTSWITH:
312                 case SLMO_NOTSTARTSWITH:
313                         return A >= B;
314                 default:
315                         Con_DPrint( "_ServerList_CompareInt: Bad op!\n" );
316                         return false;
317         }
318 }
319
320 static qboolean _ServerList_CompareStr( const char *A, serverlist_maskop_t op, const char *B )
321 {
322         int i;
323         char bufferA[ 1400 ], bufferB[ 1400 ]; // should be more than enough
324         COM_StringDecolorize(A, 0, bufferA, sizeof(bufferA), false);
325         for (i = 0;i < (int)sizeof(bufferA)-1 && bufferA[i];i++)
326                 bufferA[i] = (bufferA[i] >= 'A' && bufferA[i] <= 'Z') ? (bufferA[i] + 'a' - 'A') : bufferA[i];
327         bufferA[i] = 0;
328         for (i = 0;i < (int)sizeof(bufferB)-1 && B[i];i++)
329                 bufferB[i] = (B[i] >= 'A' && B[i] <= 'Z') ? (B[i] + 'a' - 'A') : B[i];
330         bufferB[i] = 0;
331
332         // Same here, also using an intermediate & final return would be more appropriate
333         // A info B mask
334         switch( op ) {
335                 case SLMO_CONTAINS:
336                         return *bufferB && !!strstr( bufferA, bufferB ); // we want a real bool
337                 case SLMO_NOTCONTAIN:
338                         return !*bufferB || !strstr( bufferA, bufferB );
339                 case SLMO_STARTSWITH:
340                         //Con_Printf("startsWith: %s %s\n", bufferA, bufferB);
341                         return *bufferB && !memcmp(bufferA, bufferB, strlen(bufferB));
342                 case SLMO_NOTSTARTSWITH:
343                         return !*bufferB || memcmp(bufferA, bufferB, strlen(bufferB));
344                 case SLMO_LESS:
345                         return strcmp( bufferA, bufferB ) < 0;
346                 case SLMO_LESSEQUAL:
347                         return strcmp( bufferA, bufferB ) <= 0;
348                 case SLMO_EQUAL:
349                         return strcmp( bufferA, bufferB ) == 0;
350                 case SLMO_GREATER:
351                         return strcmp( bufferA, bufferB ) > 0;
352                 case SLMO_NOTEQUAL:
353                         return strcmp( bufferA, bufferB ) != 0;
354                 case SLMO_GREATEREQUAL:
355                         return strcmp( bufferA, bufferB ) >= 0;
356                 default:
357                         Con_DPrint( "_ServerList_CompareStr: Bad op!\n" );
358                         return false;
359         }
360 }
361
362 static qboolean _ServerList_Entry_Mask( serverlist_mask_t *mask, serverlist_info_t *info )
363 {
364         if( !_ServerList_CompareInt( info->ping, mask->tests[SLIF_PING], mask->info.ping ) )
365                 return false;
366         if( !_ServerList_CompareInt( info->maxplayers, mask->tests[SLIF_MAXPLAYERS], mask->info.maxplayers ) )
367                 return false;
368         if( !_ServerList_CompareInt( info->numplayers, mask->tests[SLIF_NUMPLAYERS], mask->info.numplayers ) )
369                 return false;
370         if( !_ServerList_CompareInt( info->numbots, mask->tests[SLIF_NUMBOTS], mask->info.numbots ) )
371                 return false;
372         if( !_ServerList_CompareInt( info->numhumans, mask->tests[SLIF_NUMHUMANS], mask->info.numhumans ) )
373                 return false;
374         if( !_ServerList_CompareInt( info->freeslots, mask->tests[SLIF_FREESLOTS], mask->info.freeslots ) )
375                 return false;
376         if( !_ServerList_CompareInt( info->protocol, mask->tests[SLIF_PROTOCOL], mask->info.protocol ))
377                 return false;
378         if( *mask->info.cname
379                 && !_ServerList_CompareStr( info->cname, mask->tests[SLIF_CNAME], mask->info.cname ) )
380                 return false;
381         if( *mask->info.game
382                 && !_ServerList_CompareStr( info->game, mask->tests[SLIF_GAME], mask->info.game ) )
383                 return false;
384         if( *mask->info.mod
385                 && !_ServerList_CompareStr( info->mod, mask->tests[SLIF_MOD], mask->info.mod ) )
386                 return false;
387         if( *mask->info.map
388                 && !_ServerList_CompareStr( info->map, mask->tests[SLIF_MAP], mask->info.map ) )
389                 return false;
390         if( *mask->info.name
391                 && !_ServerList_CompareStr( info->name, mask->tests[SLIF_NAME], mask->info.name ) )
392                 return false;
393         if( *mask->info.qcstatus
394                 && !_ServerList_CompareStr( info->qcstatus, mask->tests[SLIF_QCSTATUS], mask->info.qcstatus ) )
395                 return false;
396         if( *mask->info.players
397                 && !_ServerList_CompareStr( info->players, mask->tests[SLIF_PLAYERS], mask->info.players ) )
398                 return false;
399         if( !_ServerList_CompareInt( info->isfavorite, mask->tests[SLIF_ISFAVORITE], mask->info.isfavorite ))
400                 return false;
401         return true;
402 }
403
404 static void ServerList_ViewList_Insert( serverlist_entry_t *entry )
405 {
406         int start, end, mid, i;
407         lhnetaddress_t addr;
408
409         // reject incompatible servers
410         if(
411                 entry->info.gameversion != gameversion.integer
412                 &&
413                 !(
414                            gameversion_min.integer >= 0 // min/max range set by user/mod?
415                         && gameversion_max.integer >= 0
416                         && gameversion_min.integer <= entry->info.gameversion // version of server in min/max range?
417                         && gameversion_max.integer >= entry->info.gameversion
418                  )
419         )
420                 return;
421
422         // refresh the "favorite" status
423         entry->info.isfavorite = false;
424         if(LHNETADDRESS_FromString(&addr, entry->info.cname, 26000))
425         {
426                 char idfp[FP64_SIZE+1];
427                 for(i = 0; i < nFavorites; ++i)
428                 {
429                         if(LHNETADDRESS_Compare(&addr, &favorites[i]) == 0)
430                         {
431                                 entry->info.isfavorite = true;
432                                 break;
433                         }
434                 }
435                 if(Crypto_RetrieveHostKey(&addr, 0, NULL, 0, idfp, sizeof(idfp), NULL))
436                 {
437                         for(i = 0; i < nFavorites_idfp; ++i)
438                         {
439                                 if(!strcmp(idfp, favorites_idfp[i]))
440                                 {
441                                         entry->info.isfavorite = true;
442                                         break;
443                                 }
444                         }
445                 }
446         }
447
448         // FIXME: change this to be more readable (...)
449         // now check whether it passes through the masks
450         for( start = 0 ; start < SERVERLIST_ANDMASKCOUNT && serverlist_andmasks[start].active; start++ )
451                 if( !_ServerList_Entry_Mask( &serverlist_andmasks[start], &entry->info ) )
452                         return;
453
454         for( start = 0 ; start < SERVERLIST_ORMASKCOUNT && serverlist_ormasks[start].active ; start++ )
455                 if( _ServerList_Entry_Mask( &serverlist_ormasks[start], &entry->info ) )
456                         break;
457         if( start == SERVERLIST_ORMASKCOUNT || (start > 0 && !serverlist_ormasks[start].active) )
458                 return;
459
460         if( !serverlist_viewcount ) {
461                 _ServerList_ViewList_Helper_InsertBefore( 0, entry );
462                 return;
463         }
464         // ok, insert it, we just need to find out where exactly:
465
466         // two special cases
467         // check whether to insert it as new first item
468         if( _ServerList_Entry_Compare( entry, ServerList_GetViewEntry(0) ) ) {
469                 _ServerList_ViewList_Helper_InsertBefore( 0, entry );
470                 return;
471         } // check whether to insert it as new last item
472         else if( !_ServerList_Entry_Compare( entry, ServerList_GetViewEntry(serverlist_viewcount - 1) ) ) {
473                 _ServerList_ViewList_Helper_InsertBefore( serverlist_viewcount, entry );
474                 return;
475         }
476         start = 0;
477         end = serverlist_viewcount - 1;
478         while( end > start + 1 )
479         {
480                 mid = (start + end) / 2;
481                 // test the item that lies in the middle between start and end
482                 if( _ServerList_Entry_Compare( entry, ServerList_GetViewEntry(mid) ) )
483                         // the item has to be in the upper half
484                         end = mid;
485                 else
486                         // the item has to be in the lower half
487                         start = mid;
488         }
489         _ServerList_ViewList_Helper_InsertBefore( start + 1, entry );
490 }
491
492 static void ServerList_ViewList_Remove( serverlist_entry_t *entry )
493 {
494         int i;
495         for( i = 0; i < serverlist_viewcount; i++ )
496         {
497                 if (ServerList_GetViewEntry(i) == entry)
498                 {
499                         _ServerList_ViewList_Helper_Remove(i);
500                         break;
501                 }
502         }
503 }
504
505 void ServerList_RebuildViewList(void)
506 {
507         int i;
508
509         serverlist_viewcount = 0;
510         for( i = 0 ; i < serverlist_cachecount ; i++ ) {
511                 serverlist_entry_t *entry = &serverlist_cache[i];
512                 // also display entries that are currently being refreshed [11/8/2007 Black]
513                 if( entry->query == SQS_QUERIED || entry->query == SQS_REFRESHING )
514                         ServerList_ViewList_Insert( entry );
515         }
516 }
517
518 void ServerList_ResetMasks(void)
519 {
520         int i;
521
522         memset( &serverlist_andmasks, 0, sizeof( serverlist_andmasks ) );
523         memset( &serverlist_ormasks, 0, sizeof( serverlist_ormasks ) );
524         // numbots needs to be compared to -1 to always succeed
525         for(i = 0; i < SERVERLIST_ANDMASKCOUNT; ++i)
526                 serverlist_andmasks[i].info.numbots = -1;
527         for(i = 0; i < SERVERLIST_ORMASKCOUNT; ++i)
528                 serverlist_ormasks[i].info.numbots = -1;
529 }
530
531 void ServerList_GetPlayerStatistics(int *numplayerspointer, int *maxplayerspointer)
532 {
533         int i;
534         int numplayers = 0, maxplayers = 0;
535         for (i = 0;i < serverlist_cachecount;i++)
536         {
537                 if (serverlist_cache[i].query == SQS_QUERIED)
538                 {
539                         numplayers += serverlist_cache[i].info.numhumans;
540                         maxplayers += serverlist_cache[i].info.maxplayers;
541                 }
542         }
543         *numplayerspointer = numplayers;
544         *maxplayerspointer = maxplayers;
545 }
546
547 #if 0
548 static void _ServerList_Test(void)
549 {
550         int i;
551         if (serverlist_maxcachecount <= 1024)
552         {
553                 serverlist_maxcachecount = 1024;
554                 serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
555         }
556         for( i = 0 ; i < 1024 ; i++ ) {
557                 memset( &serverlist_cache[serverlist_cachecount], 0, sizeof( serverlist_entry_t ) );
558                 serverlist_cache[serverlist_cachecount].info.ping = 1000 + 1024 - i;
559                 dpsnprintf( serverlist_cache[serverlist_cachecount].info.name, sizeof(serverlist_cache[serverlist_cachecount].info.name), "Black's ServerList Test %i", i );
560                 serverlist_cache[serverlist_cachecount].finished = true;
561                 dpsnprintf( serverlist_cache[serverlist_cachecount].line1, sizeof(serverlist_cache[serverlist_cachecount].info.line1), "%i %s", serverlist_cache[serverlist_cachecount].info.ping, serverlist_cache[serverlist_cachecount].info.name );
562                 ServerList_ViewList_Insert( &serverlist_cache[serverlist_cachecount] );
563                 serverlist_cachecount++;
564         }
565 }
566 #endif
567
568 void ServerList_QueryList(qboolean resetcache, qboolean querydp, qboolean queryqw, qboolean consoleoutput)
569 {
570         masterquerytime = realtime;
571         masterquerycount = 0;
572         masterreplycount = 0;
573         if( resetcache ) {
574                 serverquerycount = 0;
575                 serverreplycount = 0;
576                 serverlist_cachecount = 0;
577                 serverlist_viewcount = 0;
578                 serverlist_maxcachecount = 0;
579                 serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
580         } else {
581                 // refresh all entries
582                 int n;
583                 for( n = 0 ; n < serverlist_cachecount ; n++ ) {
584                         serverlist_entry_t *entry = &serverlist_cache[ n ];
585                         entry->query = SQS_REFRESHING;
586                         entry->querycounter = 0;
587                 }
588         }
589         serverlist_consoleoutput = consoleoutput;
590
591         //_ServerList_Test();
592
593         NetConn_QueryMasters(querydp, queryqw);
594 }
595
596 // rest
597
598 int NetConn_Read(lhnetsocket_t *mysocket, void *data, int maxlength, lhnetaddress_t *peeraddress)
599 {
600         int length = LHNET_Read(mysocket, data, maxlength, peeraddress);
601         int i;
602         if (length == 0)
603                 return 0;
604         if (cl_netpacketloss_receive.integer)
605                 for (i = 0;i < cl_numsockets;i++)
606                         if (cl_sockets[i] == mysocket && (rand() % 100) < cl_netpacketloss_receive.integer)
607                                 return 0;
608         if (developer_networking.integer)
609         {
610                 char addressstring[128], addressstring2[128];
611                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(mysocket), addressstring, sizeof(addressstring), true);
612                 if (length > 0)
613                 {
614                         LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
615                         Con_Printf("LHNET_Read(%p (%s), %p, %i, %p) = %i from %s:\n", (void *)mysocket, addressstring, (void *)data, maxlength, (void *)peeraddress, length, addressstring2);
616                         Com_HexDumpToConsole((unsigned char *)data, length);
617                 }
618                 else
619                         Con_Printf("LHNET_Read(%p (%s), %p, %i, %p) = %i\n", (void *)mysocket, addressstring, (void *)data, maxlength, (void *)peeraddress, length);
620         }
621         return length;
622 }
623
624 int NetConn_Write(lhnetsocket_t *mysocket, const void *data, int length, const lhnetaddress_t *peeraddress)
625 {
626         int ret;
627         int i;
628         if (cl_netpacketloss_send.integer)
629                 for (i = 0;i < cl_numsockets;i++)
630                         if (cl_sockets[i] == mysocket && (rand() % 100) < cl_netpacketloss_send.integer)
631                                 return length;
632         ret = LHNET_Write(mysocket, data, length, peeraddress);
633         if (developer_networking.integer)
634         {
635                 char addressstring[128], addressstring2[128];
636                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(mysocket), addressstring, sizeof(addressstring), true);
637                 LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
638                 Con_Printf("LHNET_Write(%p (%s), %p, %i, %p (%s)) = %i%s\n", (void *)mysocket, addressstring, (void *)data, length, (void *)peeraddress, addressstring2, length, ret == length ? "" : " (ERROR)");
639                 Com_HexDumpToConsole((unsigned char *)data, length);
640         }
641         return ret;
642 }
643
644 int NetConn_WriteString(lhnetsocket_t *mysocket, const char *string, const lhnetaddress_t *peeraddress)
645 {
646         // note this does not include the trailing NULL because we add that in the parser
647         return NetConn_Write(mysocket, string, (int)strlen(string), peeraddress);
648 }
649
650 qboolean NetConn_CanSend(netconn_t *conn)
651 {
652         conn->outgoing_packetcounter = (conn->outgoing_packetcounter + 1) % NETGRAPH_PACKETS;
653         conn->outgoing_netgraph[conn->outgoing_packetcounter].time            = realtime;
654         conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes = NETGRAPH_NOPACKET;
655         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
656         conn->outgoing_netgraph[conn->outgoing_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
657         if (realtime > conn->cleartime)
658                 return true;
659         else
660         {
661                 conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes = NETGRAPH_CHOKEDPACKET;
662                 return false;
663         }
664 }
665
666 int NetConn_SendUnreliableMessage(netconn_t *conn, sizebuf_t *data, protocolversion_t protocol, int rate, qboolean quakesignon_suppressreliables)
667 {
668         int totallen = 0;
669
670         // if this packet was supposedly choked, but we find ourselves sending one
671         // anyway, make sure the size counting starts at zero
672         // (this mostly happens on level changes and disconnects and such)
673         if (conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes == NETGRAPH_CHOKEDPACKET)
674                 conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes = NETGRAPH_NOPACKET;
675
676         if (protocol == PROTOCOL_QUAKEWORLD)
677         {
678                 int packetLen;
679                 qboolean sendreliable;
680
681                 // note that it is ok to send empty messages to the qw server,
682                 // otherwise it won't respond to us at all
683
684                 sendreliable = false;
685                 // if the remote side dropped the last reliable message, resend it
686                 if (conn->qw.incoming_acknowledged > conn->qw.last_reliable_sequence && conn->qw.incoming_reliable_acknowledged != conn->qw.reliable_sequence)
687                         sendreliable = true;
688                 // if the reliable transmit buffer is empty, copy the current message out
689                 if (!conn->sendMessageLength && conn->message.cursize)
690                 {
691                         memcpy (conn->sendMessage, conn->message.data, conn->message.cursize);
692                         conn->sendMessageLength = conn->message.cursize;
693                         SZ_Clear(&conn->message); // clear the message buffer
694                         conn->qw.reliable_sequence ^= 1;
695                         sendreliable = true;
696                 }
697                 // outgoing unreliable packet number, and outgoing reliable packet number (0 or 1)
698                 StoreLittleLong(sendbuffer, (unsigned int)conn->outgoing_unreliable_sequence | ((unsigned int)sendreliable<<31));
699                 // last received unreliable packet number, and last received reliable packet number (0 or 1)
700                 StoreLittleLong(sendbuffer + 4, (unsigned int)conn->qw.incoming_sequence | ((unsigned int)conn->qw.incoming_reliable_sequence<<31));
701                 packetLen = 8;
702                 conn->outgoing_unreliable_sequence++;
703                 // client sends qport in every packet
704                 if (conn == cls.netcon)
705                 {
706                         *((short *)(sendbuffer + 8)) = LittleShort(cls.qw_qport);
707                         packetLen += 2;
708                         // also update cls.qw_outgoing_sequence
709                         cls.qw_outgoing_sequence = conn->outgoing_unreliable_sequence;
710                 }
711                 if (packetLen + (sendreliable ? conn->sendMessageLength : 0) > 1400)
712                 {
713                         Con_Printf ("NetConn_SendUnreliableMessage: reliable message too big %u\n", data->cursize);
714                         return -1;
715                 }
716
717                 conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes += packetLen + 28;
718
719                 // add the reliable message if there is one
720                 if (sendreliable)
721                 {
722                         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes += conn->sendMessageLength + 28;
723                         memcpy(sendbuffer + packetLen, conn->sendMessage, conn->sendMessageLength);
724                         packetLen += conn->sendMessageLength;
725                         conn->qw.last_reliable_sequence = conn->outgoing_unreliable_sequence;
726                 }
727
728                 // add the unreliable message if possible
729                 if (packetLen + data->cursize <= 1400)
730                 {
731                         conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes += data->cursize + 28;
732                         memcpy(sendbuffer + packetLen, data->data, data->cursize);
733                         packetLen += data->cursize;
734                 }
735
736                 NetConn_Write(conn->mysocket, (void *)&sendbuffer, packetLen, &conn->peeraddress);
737
738                 packetsSent++;
739                 unreliableMessagesSent++;
740
741                 totallen += packetLen + 28;
742         }
743         else
744         {
745                 unsigned int packetLen;
746                 unsigned int dataLen;
747                 unsigned int eom;
748                 const void *sendme;
749                 size_t sendmelen;
750
751                 // if a reliable message fragment has been lost, send it again
752                 if (conn->sendMessageLength && (realtime - conn->lastSendTime) > 1.0)
753                 {
754                         if (conn->sendMessageLength <= MAX_PACKETFRAGMENT)
755                         {
756                                 dataLen = conn->sendMessageLength;
757                                 eom = NETFLAG_EOM;
758                         }
759                         else
760                         {
761                                 dataLen = MAX_PACKETFRAGMENT;
762                                 eom = 0;
763                         }
764
765                         packetLen = NET_HEADERSIZE + dataLen;
766
767                         StoreBigLong(sendbuffer, packetLen | (NETFLAG_DATA | eom));
768                         StoreBigLong(sendbuffer + 4, conn->nq.sendSequence - 1);
769                         memcpy(sendbuffer + NET_HEADERSIZE, conn->sendMessage, dataLen);
770
771                         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes += packetLen + 28;
772
773                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
774                         if (sendme && NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress) == (int)sendmelen)
775                         {
776                                 conn->lastSendTime = realtime;
777                                 packetsReSent++;
778                         }
779
780                         totallen += sendmelen + 28;
781                 }
782
783                 // if we have a new reliable message to send, do so
784                 if (!conn->sendMessageLength && conn->message.cursize && !quakesignon_suppressreliables)
785                 {
786                         if (conn->message.cursize > (int)sizeof(conn->sendMessage))
787                         {
788                                 Con_Printf("NetConn_SendUnreliableMessage: reliable message too big (%u > %u)\n", conn->message.cursize, (int)sizeof(conn->sendMessage));
789                                 conn->message.overflowed = true;
790                                 return -1;
791                         }
792
793                         if (developer_networking.integer && conn == cls.netcon)
794                         {
795                                 Con_Print("client sending reliable message to server:\n");
796                                 SZ_HexDumpToConsole(&conn->message);
797                         }
798
799                         memcpy(conn->sendMessage, conn->message.data, conn->message.cursize);
800                         conn->sendMessageLength = conn->message.cursize;
801                         SZ_Clear(&conn->message);
802
803                         if (conn->sendMessageLength <= MAX_PACKETFRAGMENT)
804                         {
805                                 dataLen = conn->sendMessageLength;
806                                 eom = NETFLAG_EOM;
807                         }
808                         else
809                         {
810                                 dataLen = MAX_PACKETFRAGMENT;
811                                 eom = 0;
812                         }
813
814                         packetLen = NET_HEADERSIZE + dataLen;
815
816                         StoreBigLong(sendbuffer, packetLen | (NETFLAG_DATA | eom));
817                         StoreBigLong(sendbuffer + 4, conn->nq.sendSequence);
818                         memcpy(sendbuffer + NET_HEADERSIZE, conn->sendMessage, dataLen);
819
820                         conn->nq.sendSequence++;
821
822                         conn->outgoing_netgraph[conn->outgoing_packetcounter].reliablebytes += packetLen + 28;
823
824                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
825                         if(sendme)
826                                 NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress);
827
828                         conn->lastSendTime = realtime;
829                         packetsSent++;
830                         reliableMessagesSent++;
831
832                         totallen += sendmelen + 28;
833                 }
834
835                 // if we have an unreliable message to send, do so
836                 if (data->cursize)
837                 {
838                         packetLen = NET_HEADERSIZE + data->cursize;
839
840                         if (packetLen > (int)sizeof(sendbuffer))
841                         {
842                                 Con_Printf("NetConn_SendUnreliableMessage: message too big %u\n", data->cursize);
843                                 return -1;
844                         }
845
846                         StoreBigLong(sendbuffer, packetLen | NETFLAG_UNRELIABLE);
847                         StoreBigLong(sendbuffer + 4, conn->outgoing_unreliable_sequence);
848                         memcpy(sendbuffer + NET_HEADERSIZE, data->data, data->cursize);
849
850                         conn->outgoing_unreliable_sequence++;
851
852                         conn->outgoing_netgraph[conn->outgoing_packetcounter].unreliablebytes += packetLen + 28;
853
854                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
855                         if(sendme)
856                                 NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress);
857
858                         packetsSent++;
859                         unreliableMessagesSent++;
860
861                         totallen += sendmelen + 28;
862                 }
863         }
864
865         // delay later packets to obey rate limit
866         if (conn->cleartime < realtime - 0.1)
867                 conn->cleartime = realtime - 0.1;
868         conn->cleartime = conn->cleartime + (double)totallen / (double)rate;
869         if (conn->cleartime < realtime)
870                 conn->cleartime = realtime;
871
872         return 0;
873 }
874
875 qboolean NetConn_HaveClientPorts(void)
876 {
877         return !!cl_numsockets;
878 }
879
880 qboolean NetConn_HaveServerPorts(void)
881 {
882         return !!sv_numsockets;
883 }
884
885 void NetConn_CloseClientPorts(void)
886 {
887         for (;cl_numsockets > 0;cl_numsockets--)
888                 if (cl_sockets[cl_numsockets - 1])
889                         LHNET_CloseSocket(cl_sockets[cl_numsockets - 1]);
890 }
891
892 void NetConn_OpenClientPort(const char *addressstring, lhnetaddresstype_t addresstype, int defaultport)
893 {
894         lhnetaddress_t address;
895         lhnetsocket_t *s;
896         int success;
897         char addressstring2[1024];
898         if (addressstring && addressstring[0])
899                 success = LHNETADDRESS_FromString(&address, addressstring, defaultport);
900         else
901                 success = LHNETADDRESS_FromPort(&address, addresstype, defaultport);
902         if (success)
903         {
904                 if ((s = LHNET_OpenSocket_Connectionless(&address)))
905                 {
906                         cl_sockets[cl_numsockets++] = s;
907                         LHNETADDRESS_ToString(LHNET_AddressFromSocket(s), addressstring2, sizeof(addressstring2), true);
908                         if (addresstype != LHNETADDRESSTYPE_LOOP)
909                                 Con_Printf("Client opened a socket on address %s\n", addressstring2);
910                 }
911                 else
912                 {
913                         LHNETADDRESS_ToString(&address, addressstring2, sizeof(addressstring2), true);
914                         Con_Printf("Client failed to open a socket on address %s\n", addressstring2);
915                 }
916         }
917         else
918                 Con_Printf("Client unable to parse address %s\n", addressstring);
919 }
920
921 void NetConn_OpenClientPorts(void)
922 {
923         int port;
924         NetConn_CloseClientPorts();
925
926         Crypto_LoadKeys(); // client sockets
927
928         port = bound(0, cl_netport.integer, 65535);
929         if (cl_netport.integer != port)
930                 Cvar_SetValueQuick(&cl_netport, port);
931         if(port == 0)
932                 Con_Printf("Client using an automatically assigned port\n");
933         else
934                 Con_Printf("Client using port %i\n", port);
935         NetConn_OpenClientPort(NULL, LHNETADDRESSTYPE_LOOP, 2);
936         NetConn_OpenClientPort(net_address.string, LHNETADDRESSTYPE_INET4, port);
937 #ifdef SUPPORTIPV6
938         NetConn_OpenClientPort(net_address_ipv6.string, LHNETADDRESSTYPE_INET6, port);
939 #endif
940 }
941
942 void NetConn_CloseServerPorts(void)
943 {
944         for (;sv_numsockets > 0;sv_numsockets--)
945                 if (sv_sockets[sv_numsockets - 1])
946                         LHNET_CloseSocket(sv_sockets[sv_numsockets - 1]);
947 }
948
949 qboolean NetConn_OpenServerPort(const char *addressstring, lhnetaddresstype_t addresstype, int defaultport, int range)
950 {
951         lhnetaddress_t address;
952         lhnetsocket_t *s;
953         int port;
954         char addressstring2[1024];
955         int success;
956
957         for (port = defaultport; port <= defaultport + range; port++)
958         {
959                 if (addressstring && addressstring[0])
960                         success = LHNETADDRESS_FromString(&address, addressstring, port);
961                 else
962                         success = LHNETADDRESS_FromPort(&address, addresstype, port);
963                 if (success)
964                 {
965                         if ((s = LHNET_OpenSocket_Connectionless(&address)))
966                         {
967                                 sv_sockets[sv_numsockets++] = s;
968                                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(s), addressstring2, sizeof(addressstring2), true);
969                                 if (addresstype != LHNETADDRESSTYPE_LOOP)
970                                         Con_Printf("Server listening on address %s\n", addressstring2);
971                                 return true;
972                         }
973                         else
974                         {
975                                 LHNETADDRESS_ToString(&address, addressstring2, sizeof(addressstring2), true);
976                                 Con_Printf("Server failed to open socket on address %s\n", addressstring2);
977                         }
978                 }
979                 else
980                 {
981                         Con_Printf("Server unable to parse address %s\n", addressstring);
982                         // if it cant parse one address, it wont be able to parse another for sure
983                         return false;
984                 }
985         }
986         return false;
987 }
988
989 void NetConn_OpenServerPorts(int opennetports)
990 {
991         int port;
992         NetConn_CloseServerPorts();
993
994         Crypto_LoadKeys(); // server sockets
995
996         NetConn_UpdateSockets();
997         port = bound(0, sv_netport.integer, 65535);
998         if (port == 0)
999                 port = 26000;
1000         Con_Printf("Server using port %i\n", port);
1001         if (sv_netport.integer != port)
1002                 Cvar_SetValueQuick(&sv_netport, port);
1003         if (cls.state != ca_dedicated)
1004                 NetConn_OpenServerPort(NULL, LHNETADDRESSTYPE_LOOP, 1, 1);
1005         if (opennetports)
1006         {
1007 #ifdef SUPPORTIPV6
1008                 qboolean ip4success = NetConn_OpenServerPort(net_address.string, LHNETADDRESSTYPE_INET4, port, 100);
1009                 NetConn_OpenServerPort(net_address_ipv6.string, LHNETADDRESSTYPE_INET6, port, ip4success ? 1 : 100);
1010 #else
1011                 NetConn_OpenServerPort(net_address.string, LHNETADDRESSTYPE_INET4, port, 100);
1012 #endif
1013         }
1014         if (sv_numsockets == 0)
1015                 Host_Error("NetConn_OpenServerPorts: unable to open any ports!");
1016 }
1017
1018 lhnetsocket_t *NetConn_ChooseClientSocketForAddress(lhnetaddress_t *address)
1019 {
1020         int i, a = LHNETADDRESS_GetAddressType(address);
1021         for (i = 0;i < cl_numsockets;i++)
1022                 if (cl_sockets[i] && LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i])) == a)
1023                         return cl_sockets[i];
1024         return NULL;
1025 }
1026
1027 lhnetsocket_t *NetConn_ChooseServerSocketForAddress(lhnetaddress_t *address)
1028 {
1029         int i, a = LHNETADDRESS_GetAddressType(address);
1030         for (i = 0;i < sv_numsockets;i++)
1031                 if (sv_sockets[i] && LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(sv_sockets[i])) == a)
1032                         return sv_sockets[i];
1033         return NULL;
1034 }
1035
1036 netconn_t *NetConn_Open(lhnetsocket_t *mysocket, lhnetaddress_t *peeraddress)
1037 {
1038         netconn_t *conn;
1039         conn = (netconn_t *)Mem_Alloc(netconn_mempool, sizeof(*conn));
1040         conn->mysocket = mysocket;
1041         conn->peeraddress = *peeraddress;
1042         conn->lastMessageTime = realtime;
1043         conn->message.data = conn->messagedata;
1044         conn->message.maxsize = sizeof(conn->messagedata);
1045         conn->message.cursize = 0;
1046         // LordHavoc: (inspired by ProQuake) use a short connect timeout to
1047         // reduce effectiveness of connection request floods
1048         conn->timeout = realtime + net_connecttimeout.value;
1049         LHNETADDRESS_ToString(&conn->peeraddress, conn->address, sizeof(conn->address), true);
1050         conn->next = netconn_list;
1051         netconn_list = conn;
1052         return conn;
1053 }
1054
1055 void NetConn_ClearConnectFlood(lhnetaddress_t *peeraddress);
1056 void NetConn_Close(netconn_t *conn)
1057 {
1058         netconn_t *c;
1059         // remove connection from list
1060
1061         // allow the client to reconnect immediately
1062         NetConn_ClearConnectFlood(&(conn->peeraddress));
1063
1064         if (conn == netconn_list)
1065                 netconn_list = conn->next;
1066         else
1067         {
1068                 for (c = netconn_list;c;c = c->next)
1069                 {
1070                         if (c->next == conn)
1071                         {
1072                                 c->next = conn->next;
1073                                 break;
1074                         }
1075                 }
1076                 // not found in list, we'll avoid crashing here...
1077                 if (!c)
1078                         return;
1079         }
1080         // free connection
1081         Mem_Free(conn);
1082 }
1083
1084 static int clientport = -1;
1085 static int clientport2 = -1;
1086 static int hostport = -1;
1087 void NetConn_UpdateSockets(void)
1088 {
1089         int i, j;
1090
1091         if (cls.state != ca_dedicated)
1092         {
1093                 if (clientport2 != cl_netport.integer)
1094                 {
1095                         clientport2 = cl_netport.integer;
1096                         if (cls.state == ca_connected)
1097                                 Con_Print("Changing \"cl_port\" will not take effect until you reconnect.\n");
1098                 }
1099                 if (cls.state == ca_disconnected && clientport != clientport2)
1100                 {
1101                         clientport = clientport2;
1102                         NetConn_CloseClientPorts();
1103                 }
1104                 if (cl_numsockets == 0)
1105                         NetConn_OpenClientPorts();
1106         }
1107
1108         if (hostport != sv_netport.integer)
1109         {
1110                 hostport = sv_netport.integer;
1111                 if (sv.active)
1112                         Con_Print("Changing \"port\" will not take effect until \"map\" command is executed.\n");
1113         }
1114
1115         for (j = 0;j < MAX_RCONS;j++)
1116         {
1117                 i = (cls.rcon_ringpos + j + 1) % MAX_RCONS;
1118                 if(cls.rcon_commands[i][0])
1119                 {
1120                         if(realtime > cls.rcon_timeout[i])
1121                         {
1122                                 char s[128];
1123                                 LHNETADDRESS_ToString(&cls.rcon_addresses[i], s, sizeof(s), true);
1124                                 Con_Printf("rcon to %s (for command %s) failed: challenge request timed out\n", s, cls.rcon_commands[i]);
1125                                 cls.rcon_commands[i][0] = 0;
1126                                 --cls.rcon_trying;
1127                                 break;
1128                         }
1129                 }
1130         }
1131 }
1132
1133 static int NetConn_ReceivedMessage(netconn_t *conn, const unsigned char *data, size_t length, protocolversion_t protocol, double newtimeout)
1134 {
1135         int originallength = length;
1136         if (length < 8)
1137                 return 0;
1138
1139         if (protocol == PROTOCOL_QUAKEWORLD)
1140         {
1141                 int sequence, sequence_ack;
1142                 int reliable_ack, reliable_message;
1143                 int count;
1144                 //int qport;
1145
1146                 sequence = LittleLong(*((int *)(data + 0)));
1147                 sequence_ack = LittleLong(*((int *)(data + 4)));
1148                 data += 8;
1149                 length -= 8;
1150
1151                 if (conn != cls.netcon)
1152                 {
1153                         // server only
1154                         if (length < 2)
1155                                 return 0;
1156                         // TODO: use qport to identify that this client really is who they say they are?  (and elsewhere in the code to identify the connection without a port match?)
1157                         //qport = LittleShort(*((int *)(data + 8)));
1158                         data += 2;
1159                         length -= 2;
1160                 }
1161
1162                 packetsReceived++;
1163                 reliable_message = (sequence >> 31) & 1;
1164                 reliable_ack = (sequence_ack >> 31) & 1;
1165                 sequence &= ~(1<<31);
1166                 sequence_ack &= ~(1<<31);
1167                 if (sequence <= conn->qw.incoming_sequence)
1168                 {
1169                         //Con_DPrint("Got a stale datagram\n");
1170                         return 0;
1171                 }
1172                 count = sequence - (conn->qw.incoming_sequence + 1);
1173                 if (count > 0)
1174                 {
1175                         droppedDatagrams += count;
1176                         //Con_DPrintf("Dropped %u datagram(s)\n", count);
1177                         while (count--)
1178                         {
1179                                 conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1180                                 conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1181                                 conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = NETGRAPH_LOSTPACKET;
1182                                 conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1183                                 conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1184                         }
1185                 }
1186                 conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1187                 conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1188                 conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = originallength + 28;
1189                 conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1190                 conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1191                 if (reliable_ack == conn->qw.reliable_sequence)
1192                 {
1193                         // received, now we will be able to send another reliable message
1194                         conn->sendMessageLength = 0;
1195                         reliableMessagesReceived++;
1196                 }
1197                 conn->qw.incoming_sequence = sequence;
1198                 if (conn == cls.netcon)
1199                         cls.qw_incoming_sequence = conn->qw.incoming_sequence;
1200                 conn->qw.incoming_acknowledged = sequence_ack;
1201                 conn->qw.incoming_reliable_acknowledged = reliable_ack;
1202                 if (reliable_message)
1203                         conn->qw.incoming_reliable_sequence ^= 1;
1204                 conn->lastMessageTime = realtime;
1205                 conn->timeout = realtime + newtimeout;
1206                 unreliableMessagesReceived++;
1207                 SZ_Clear(&net_message);
1208                 SZ_Write(&net_message, data, length);
1209                 MSG_BeginReading();
1210                 return 2;
1211         }
1212         else
1213         {
1214                 unsigned int count;
1215                 unsigned int flags;
1216                 unsigned int sequence;
1217                 size_t qlength;
1218                 const void *sendme;
1219                 size_t sendmelen;
1220
1221                 originallength = length;
1222                 data = (const unsigned char *) Crypto_DecryptPacket(&conn->crypto, data, length, cryptoreadbuffer, &length, sizeof(cryptoreadbuffer));
1223                 if(!data)
1224                         return 0;
1225                 if(length < 8)
1226                         return 0;
1227
1228                 qlength = (unsigned int)BuffBigLong(data);
1229                 flags = qlength & ~NETFLAG_LENGTH_MASK;
1230                 qlength &= NETFLAG_LENGTH_MASK;
1231                 // control packets were already handled
1232                 if (!(flags & NETFLAG_CTL) && qlength == length)
1233                 {
1234                         sequence = BuffBigLong(data + 4);
1235                         packetsReceived++;
1236                         data += 8;
1237                         length -= 8;
1238                         if (flags & NETFLAG_UNRELIABLE)
1239                         {
1240                                 if (sequence >= conn->nq.unreliableReceiveSequence)
1241                                 {
1242                                         if (sequence > conn->nq.unreliableReceiveSequence)
1243                                         {
1244                                                 count = sequence - conn->nq.unreliableReceiveSequence;
1245                                                 droppedDatagrams += count;
1246                                                 //Con_DPrintf("Dropped %u datagram(s)\n", count);
1247                                                 while (count--)
1248                                                 {
1249                                                         conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1250                                                         conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1251                                                         conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = NETGRAPH_LOSTPACKET;
1252                                                         conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1253                                                         conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1254                                                 }
1255                                         }
1256                                         conn->incoming_packetcounter = (conn->incoming_packetcounter + 1) % NETGRAPH_PACKETS;
1257                                         conn->incoming_netgraph[conn->incoming_packetcounter].time            = realtime;
1258                                         conn->incoming_netgraph[conn->incoming_packetcounter].unreliablebytes = originallength + 28;
1259                                         conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   = NETGRAPH_NOPACKET;
1260                                         conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes        = NETGRAPH_NOPACKET;
1261                                         conn->nq.unreliableReceiveSequence = sequence + 1;
1262                                         conn->lastMessageTime = realtime;
1263                                         conn->timeout = realtime + newtimeout;
1264                                         unreliableMessagesReceived++;
1265                                         if (length > 0)
1266                                         {
1267                                                 SZ_Clear(&net_message);
1268                                                 SZ_Write(&net_message, data, length);
1269                                                 MSG_BeginReading();
1270                                                 return 2;
1271                                         }
1272                                 }
1273                                 //else
1274                                 //      Con_DPrint("Got a stale datagram\n");
1275                                 return 1;
1276                         }
1277                         else if (flags & NETFLAG_ACK)
1278                         {
1279                                 conn->incoming_netgraph[conn->incoming_packetcounter].ackbytes += originallength + 28;
1280                                 if (sequence == (conn->nq.sendSequence - 1))
1281                                 {
1282                                         if (sequence == conn->nq.ackSequence)
1283                                         {
1284                                                 conn->nq.ackSequence++;
1285                                                 if (conn->nq.ackSequence != conn->nq.sendSequence)
1286                                                         Con_DPrint("ack sequencing error\n");
1287                                                 conn->lastMessageTime = realtime;
1288                                                 conn->timeout = realtime + newtimeout;
1289                                                 if (conn->sendMessageLength > MAX_PACKETFRAGMENT)
1290                                                 {
1291                                                         unsigned int packetLen;
1292                                                         unsigned int dataLen;
1293                                                         unsigned int eom;
1294
1295                                                         conn->sendMessageLength -= MAX_PACKETFRAGMENT;
1296                                                         memmove(conn->sendMessage, conn->sendMessage+MAX_PACKETFRAGMENT, conn->sendMessageLength);
1297
1298                                                         if (conn->sendMessageLength <= MAX_PACKETFRAGMENT)
1299                                                         {
1300                                                                 dataLen = conn->sendMessageLength;
1301                                                                 eom = NETFLAG_EOM;
1302                                                         }
1303                                                         else
1304                                                         {
1305                                                                 dataLen = MAX_PACKETFRAGMENT;
1306                                                                 eom = 0;
1307                                                         }
1308
1309                                                         packetLen = NET_HEADERSIZE + dataLen;
1310
1311                                                         StoreBigLong(sendbuffer, packetLen | (NETFLAG_DATA | eom));
1312                                                         StoreBigLong(sendbuffer + 4, conn->nq.sendSequence);
1313                                                         memcpy(sendbuffer + NET_HEADERSIZE, conn->sendMessage, dataLen);
1314
1315                                                         conn->nq.sendSequence++;
1316
1317                                                         sendme = Crypto_EncryptPacket(&conn->crypto, &sendbuffer, packetLen, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
1318                                                         if (sendme && NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress) == (int)sendmelen)
1319                                                         {
1320                                                                 conn->lastSendTime = realtime;
1321                                                                 packetsSent++;
1322                                                         }
1323                                                 }
1324                                                 else
1325                                                         conn->sendMessageLength = 0;
1326                                         }
1327                                         //else
1328                                         //      Con_DPrint("Duplicate ACK received\n");
1329                                 }
1330                                 //else
1331                                 //      Con_DPrint("Stale ACK received\n");
1332                                 return 1;
1333                         }
1334                         else if (flags & NETFLAG_DATA)
1335                         {
1336                                 unsigned char temppacket[8];
1337                                 conn->incoming_netgraph[conn->incoming_packetcounter].reliablebytes   += originallength + 28;
1338                                 conn->outgoing_netgraph[conn->outgoing_packetcounter].ackbytes        += 8 + 28;
1339                                 StoreBigLong(temppacket, 8 | NETFLAG_ACK);
1340                                 StoreBigLong(temppacket + 4, sequence);
1341                                 sendme = Crypto_EncryptPacket(&conn->crypto, temppacket, 8, &cryptosendbuffer, &sendmelen, sizeof(cryptosendbuffer));
1342                                 if(sendme)
1343                                         NetConn_Write(conn->mysocket, sendme, sendmelen, &conn->peeraddress);
1344                                 if (sequence == conn->nq.receiveSequence)
1345                                 {
1346                                         conn->lastMessageTime = realtime;
1347                                         conn->timeout = realtime + newtimeout;
1348                                         conn->nq.receiveSequence++;
1349                                         if( conn->receiveMessageLength + length <= (int)sizeof( conn->receiveMessage ) ) {
1350                                                 memcpy(conn->receiveMessage + conn->receiveMessageLength, data, length);
1351                                                 conn->receiveMessageLength += length;
1352                                         } else {
1353                                                 Con_Printf( "Reliable message (seq: %i) too big for message buffer!\n"
1354                                                                         "Dropping the message!\n", sequence );
1355                                                 conn->receiveMessageLength = 0;
1356                                                 return 1;
1357                                         }
1358                                         if (flags & NETFLAG_EOM)
1359                                         {
1360                                                 reliableMessagesReceived++;
1361                                                 length = conn->receiveMessageLength;
1362                                                 conn->receiveMessageLength = 0;
1363                                                 if (length > 0)
1364                                                 {
1365                                                         SZ_Clear(&net_message);
1366                                                         SZ_Write(&net_message, conn->receiveMessage, length);
1367                                                         MSG_BeginReading();
1368                                                         return 2;
1369                                                 }
1370                                         }
1371                                 }
1372                                 else
1373                                         receivedDuplicateCount++;
1374                                 return 1;
1375                         }
1376                 }
1377         }
1378         return 0;
1379 }
1380
1381 void NetConn_ConnectionEstablished(lhnetsocket_t *mysocket, lhnetaddress_t *peeraddress, protocolversion_t initialprotocol)
1382 {
1383         crypto_t *crypto;
1384         cls.connect_trying = false;
1385         M_Update_Return_Reason("");
1386         // the connection request succeeded, stop current connection and set up a new connection
1387         CL_Disconnect();
1388         // if we're connecting to a remote server, shut down any local server
1389         if (LHNETADDRESS_GetAddressType(peeraddress) != LHNETADDRESSTYPE_LOOP && sv.active)
1390                 Host_ShutdownServer ();
1391         // allocate a net connection to keep track of things
1392         cls.netcon = NetConn_Open(mysocket, peeraddress);
1393         crypto = &cls.crypto;
1394         if(crypto && crypto->authenticated)
1395         {
1396                 Crypto_ServerFinishInstance(&cls.netcon->crypto, crypto);
1397                 Con_Printf("%s connection to %s has been established: server is %s@%.*s, I am %.*s@%.*s\n",
1398                                 crypto->use_aes ? "Encrypted" : "Authenticated",
1399                                 cls.netcon->address,
1400                                 crypto->server_idfp[0] ? crypto->server_idfp : "-",
1401                                 crypto_keyfp_recommended_length, crypto->server_keyfp[0] ? crypto->server_keyfp : "-",
1402                                 crypto_keyfp_recommended_length, crypto->client_idfp[0] ? crypto->client_idfp : "-",
1403                                 crypto_keyfp_recommended_length, crypto->client_keyfp[0] ? crypto->client_keyfp : "-"
1404                                 );
1405         }
1406         Con_Printf("Connection accepted to %s\n", cls.netcon->address);
1407         key_dest = key_game;
1408         m_state = m_none;
1409         cls.demonum = -1;                       // not in the demo loop now
1410         cls.state = ca_connected;
1411         cls.signon = 0;                         // need all the signon messages before playing
1412         cls.protocol = initialprotocol;
1413         // reset move sequence numbering on this new connection
1414         cls.servermovesequence = 0;
1415         if (cls.protocol == PROTOCOL_QUAKEWORLD)
1416                 Cmd_ForwardStringToServer("new");
1417         if (cls.protocol == PROTOCOL_QUAKE)
1418         {
1419                 // write a keepalive (clc_nop) as it seems to greatly improve the
1420                 // chances of connecting to a netquake server
1421                 sizebuf_t msg;
1422                 unsigned char buf[4];
1423                 memset(&msg, 0, sizeof(msg));
1424                 msg.data = buf;
1425                 msg.maxsize = sizeof(buf);
1426                 MSG_WriteChar(&msg, clc_nop);
1427                 NetConn_SendUnreliableMessage(cls.netcon, &msg, cls.protocol, 10000, false);
1428         }
1429 }
1430
1431 int NetConn_IsLocalGame(void)
1432 {
1433         if (cls.state == ca_connected && sv.active && cl.maxclients == 1)
1434                 return true;
1435         return false;
1436 }
1437
1438 static int NetConn_ClientParsePacket_ServerList_ProcessReply(const char *addressstring)
1439 {
1440         int n;
1441         int pingtime;
1442         serverlist_entry_t *entry = NULL;
1443
1444         // search the cache for this server and update it
1445         for (n = 0;n < serverlist_cachecount;n++) {
1446                 entry = &serverlist_cache[ n ];
1447                 if (!strcmp(addressstring, entry->info.cname))
1448                         break;
1449         }
1450
1451         if (n == serverlist_cachecount)
1452         {
1453                 // LAN search doesnt require an answer from the master server so we wont
1454                 // know the ping nor will it be initialized already...
1455
1456                 // find a slot
1457                 if (serverlist_cachecount == SERVERLIST_TOTALSIZE)
1458                         return -1;
1459
1460                 if (serverlist_maxcachecount <= serverlist_cachecount)
1461                 {
1462                         serverlist_maxcachecount += 64;
1463                         serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
1464                 }
1465                 entry = &serverlist_cache[n];
1466
1467                 memset(entry, 0, sizeof(*entry));
1468                 // store the data the engine cares about (address and ping)
1469                 strlcpy(entry->info.cname, addressstring, sizeof(entry->info.cname));
1470                 entry->info.ping = 100000;
1471                 entry->querytime = realtime;
1472                 // if not in the slist menu we should print the server to console
1473                 if (serverlist_consoleoutput)
1474                         Con_Printf("querying %s\n", addressstring);
1475                 ++serverlist_cachecount;
1476         }
1477         // if this is the first reply from this server, count it as having replied
1478         pingtime = (int)((realtime - entry->querytime) * 1000.0 + 0.5);
1479         pingtime = bound(0, pingtime, 9999);
1480         if (entry->query == SQS_REFRESHING) {
1481                 entry->info.ping = pingtime;
1482                 entry->query = SQS_QUERIED;
1483         } else {
1484                 // convert to unsigned to catch the -1
1485                 // I still dont like this but its better than the old 10000 magic ping number - as in easier to type and read :( [11/8/2007 Black]
1486                 entry->info.ping = min((unsigned) entry->info.ping, (unsigned) pingtime);
1487                 serverreplycount++;
1488         }
1489         
1490         // other server info is updated by the caller
1491         return n;
1492 }
1493
1494 static void NetConn_ClientParsePacket_ServerList_UpdateCache(int n)
1495 {
1496         serverlist_entry_t *entry = &serverlist_cache[n];
1497         serverlist_info_t *info = &entry->info;
1498         // update description strings for engine menu and console output
1499         dpsnprintf(entry->line1, sizeof(serverlist_cache[n].line1), "^%c%5d^7 ^%c%3u^7/%3u %-65.65s", info->ping >= 300 ? '1' : (info->ping >= 200 ? '3' : '7'), (int)info->ping, ((info->numhumans > 0 && info->numhumans < info->maxplayers) ? (info->numhumans >= 4 ? '7' : '3') : '1'), info->numplayers, info->maxplayers, info->name);
1500         dpsnprintf(entry->line2, sizeof(serverlist_cache[n].line2), "^4%-21.21s %-19.19s ^%c%-17.17s^4 %-20.20s", info->cname, info->game,
1501                         (
1502                          info->gameversion != gameversion.integer
1503                          &&
1504                          !(
1505                                     gameversion_min.integer >= 0 // min/max range set by user/mod?
1506                                  && gameversion_max.integer >= 0
1507                                  && gameversion_min.integer <= info->gameversion // version of server in min/max range?
1508                                  && gameversion_max.integer >= info->gameversion
1509                           )
1510                         ) ? '1' : '4',
1511                         info->mod, info->map);
1512         if (entry->query == SQS_QUERIED)
1513         {
1514                 if(!serverlist_paused)
1515                         ServerList_ViewList_Remove(entry);
1516         }
1517         // if not in the slist menu we should print the server to console (if wanted)
1518         else if( serverlist_consoleoutput )
1519                 Con_Printf("%s\n%s\n", serverlist_cache[n].line1, serverlist_cache[n].line2);
1520         // and finally, update the view set
1521         if(!serverlist_paused)
1522                 ServerList_ViewList_Insert( entry );
1523         //      update the entry's state
1524         serverlist_cache[n].query = SQS_QUERIED;
1525 }
1526
1527 // returns true, if it's sensible to continue the processing
1528 static qboolean NetConn_ClientParsePacket_ServerList_PrepareQuery( int protocol, const char *ipstring, qboolean isfavorite ) {
1529         int n;
1530         serverlist_entry_t *entry;
1531
1532         //      ignore the rest of the message if the serverlist is full
1533         if( serverlist_cachecount == SERVERLIST_TOTALSIZE )
1534                 return false;
1535         //      also ignore     it      if      we      have already queried    it      (other master server    response)
1536         for( n =        0 ; n   < serverlist_cachecount ; n++   )
1537                 if( !strcmp( ipstring, serverlist_cache[ n ].info.cname ) )
1538                         break;
1539
1540         if( n < serverlist_cachecount ) {
1541                 // the entry has already been queried once or 
1542                 return true;
1543         }
1544
1545         if (serverlist_maxcachecount <= n)
1546         {
1547                 serverlist_maxcachecount += 64;
1548                 serverlist_cache = (serverlist_entry_t *)Mem_Realloc(netconn_mempool, (void *)serverlist_cache, sizeof(serverlist_entry_t) * serverlist_maxcachecount);
1549         }
1550
1551         entry = &serverlist_cache[n];
1552
1553         memset(entry, 0, sizeof(entry));
1554         entry->protocol =       protocol;
1555         //      store   the data        the engine cares about (address and     ping)
1556         strlcpy (entry->info.cname, ipstring, sizeof(entry->info.cname));
1557
1558         entry->info.isfavorite = isfavorite;
1559         
1560         // no, then reset the ping right away
1561         entry->info.ping = -1;
1562         // we also want to increase the serverlist_cachecount then
1563         serverlist_cachecount++;
1564         serverquerycount++;
1565
1566         entry->query =  SQS_QUERYING;
1567
1568         return true;
1569 }
1570
1571 static void NetConn_ClientParsePacket_ServerList_ParseDPList(lhnetaddress_t *senderaddress, const unsigned char *data, int length, qboolean isextended)
1572 {
1573         masterreplycount++;
1574         if (serverlist_consoleoutput)
1575                 Con_Printf("received DarkPlaces %sserver list...\n", isextended ? "extended " : "");
1576         while (length >= 7)
1577         {
1578                 char ipstring [128];
1579
1580                 // IPv4 address
1581                 if (data[0] == '\\')
1582                 {
1583                         unsigned short port = data[5] * 256 + data[6];
1584
1585                         if (port != 0 && (data[1] != 0xFF || data[2] != 0xFF || data[3] != 0xFF || data[4] != 0xFF))
1586                                 dpsnprintf (ipstring, sizeof (ipstring), "%u.%u.%u.%u:%hu", data[1], data[2], data[3], data[4], port);
1587
1588                         // move on to next address in packet
1589                         data += 7;
1590                         length -= 7;
1591                 }
1592                 // IPv6 address
1593                 else if (data[0] == '/' && isextended && length >= 19)
1594                 {
1595                         unsigned short port = data[17] * 256 + data[18];
1596
1597                         if (port != 0)
1598                         {
1599 #ifdef WHY_JUST_WHY
1600                                 const char *ifname;
1601
1602                                 /// \TODO: make some basic checks of the IP address (broadcast, ...)
1603
1604                                 ifname = LHNETADDRESS_GetInterfaceName(senderaddress);
1605                                 if (ifname != NULL)
1606                                 {
1607                                         dpsnprintf (ipstring, sizeof (ipstring), "[%x:%x:%x:%x:%x:%x:%x:%x%%%s]:%hu",
1608                                                                 (data[1] << 8) | data[2], (data[3] << 8) | data[4], (data[5] << 8) | data[6], (data[7] << 8) | data[8],
1609                                                                 (data[9] << 8) | data[10], (data[11] << 8) | data[12], (data[13] << 8) | data[14], (data[15] << 8) | data[16],
1610                                                                 ifname, port);
1611                                 }
1612                                 else
1613 #endif
1614                                 {
1615                                         dpsnprintf (ipstring, sizeof (ipstring), "[%x:%x:%x:%x:%x:%x:%x:%x]:%hu",
1616                                                                 (data[1] << 8) | data[2], (data[3] << 8) | data[4], (data[5] << 8) | data[6], (data[7] << 8) | data[8],
1617                                                                 (data[9] << 8) | data[10], (data[11] << 8) | data[12], (data[13] << 8) | data[14], (data[15] << 8) | data[16],
1618                                                                 port);
1619                                 }
1620                         }
1621
1622                         // move on to next address in packet
1623                         data += 19;
1624                         length -= 19;
1625                 }
1626                 else
1627                 {
1628                         Con_Print("Error while parsing the server list\n");
1629                         break;
1630                 }
1631
1632                 if (serverlist_consoleoutput && developer_networking.integer)
1633                         Con_Printf("Requesting info from DarkPlaces server %s\n", ipstring);
1634                 
1635                 if( !NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_DARKPLACES7, ipstring, false ) ) {
1636                         break;
1637                 }
1638
1639         }
1640
1641         // begin or resume serverlist queries
1642         serverlist_querysleep = false;
1643         serverlist_querywaittime = realtime + 3;
1644 }
1645
1646 static int NetConn_ClientParsePacket(lhnetsocket_t *mysocket, unsigned char *data, int length, lhnetaddress_t *peeraddress)
1647 {
1648         qboolean fromserver;
1649         int ret, c, control;
1650         const char *s;
1651         char *string, addressstring2[128], ipstring[32];
1652         char stringbuf[16384];
1653         char senddata[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
1654         size_t sendlength;
1655
1656         // quakeworld ingame packet
1657         fromserver = cls.netcon && mysocket == cls.netcon->mysocket && !LHNETADDRESS_Compare(&cls.netcon->peeraddress, peeraddress);
1658
1659         // convert the address to a string incase we need it
1660         LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
1661
1662         if (length >= 5 && data[0] == 255 && data[1] == 255 && data[2] == 255 && data[3] == 255)
1663         {
1664                 // received a command string - strip off the packaging and put it
1665                 // into our string buffer with NULL termination
1666                 data += 4;
1667                 length -= 4;
1668                 length = min(length, (int)sizeof(stringbuf) - 1);
1669                 memcpy(stringbuf, data, length);
1670                 stringbuf[length] = 0;
1671                 string = stringbuf;
1672
1673                 if (developer_networking.integer)
1674                 {
1675                         Con_Printf("NetConn_ClientParsePacket: %s sent us a command:\n", addressstring2);
1676                         Com_HexDumpToConsole(data, length);
1677                 }
1678
1679                 sendlength = sizeof(senddata) - 4;
1680                 switch(Crypto_ClientParsePacket(string, length, senddata+4, &sendlength, peeraddress))
1681                 {
1682                         case CRYPTO_NOMATCH:
1683                                 // nothing to do
1684                                 break;
1685                         case CRYPTO_MATCH:
1686                                 if(sendlength)
1687                                 {
1688                                         memcpy(senddata, "\377\377\377\377", 4);
1689                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
1690                                 }
1691                                 break;
1692                         case CRYPTO_DISCARD:
1693                                 if(sendlength)
1694                                 {
1695                                         memcpy(senddata, "\377\377\377\377", 4);
1696                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
1697                                 }
1698                                 return true;
1699                                 break;
1700                         case CRYPTO_REPLACE:
1701                                 string = senddata+4;
1702                                 length = sendlength;
1703                                 break;
1704                 }
1705
1706                 if (length >= 10 && !memcmp(string, "challenge ", 10) && cls.rcon_trying)
1707                 {
1708                         int i = 0, j;
1709                         for (j = 0;j < MAX_RCONS;j++)
1710                         {
1711                                 // note: this value from i is used outside the loop too...
1712                                 i = (cls.rcon_ringpos + j) % MAX_RCONS;
1713                                 if(cls.rcon_commands[i][0])
1714                                         if (!LHNETADDRESS_Compare(peeraddress, &cls.rcon_addresses[i]))
1715                                                 break;
1716                         }
1717                         if (j < MAX_RCONS)
1718                         {
1719                                 char buf[1500];
1720                                 char argbuf[1500];
1721                                 const char *e;
1722                                 int n;
1723                                 dpsnprintf(argbuf, sizeof(argbuf), "%s %s", string + 10, cls.rcon_commands[i]);
1724                                 memcpy(buf, "\377\377\377\377srcon HMAC-MD4 CHALLENGE ", 29);
1725
1726                                 e = strchr(rcon_password.string, ' ');
1727                                 n = e ? e-rcon_password.string : (int)strlen(rcon_password.string);
1728
1729                                 if(HMAC_MDFOUR_16BYTES((unsigned char *) (buf + 29), (unsigned char *) argbuf, strlen(argbuf), (unsigned char *) rcon_password.string, n))
1730                                 {
1731                                         int k;
1732                                         buf[45] = ' ';
1733                                         strlcpy(buf + 46, argbuf, sizeof(buf) - 46);
1734                                         NetConn_Write(mysocket, buf, 46 + strlen(buf + 46), peeraddress);
1735                                         cls.rcon_commands[i][0] = 0;
1736                                         --cls.rcon_trying;
1737
1738                                         for (k = 0;k < MAX_RCONS;k++)
1739                                                 if(cls.rcon_commands[k][0])
1740                                                         if (!LHNETADDRESS_Compare(peeraddress, &cls.rcon_addresses[k]))
1741                                                                 break;
1742                                         if(k < MAX_RCONS)
1743                                         {
1744                                                 int l;
1745                                                 NetConn_WriteString(mysocket, "\377\377\377\377getchallenge", peeraddress);
1746                                                 // extend the timeout on other requests as we asked for a challenge
1747                                                 for (l = 0;l < MAX_RCONS;l++)
1748                                                         if(cls.rcon_commands[l][0])
1749                                                                 if (!LHNETADDRESS_Compare(peeraddress, &cls.rcon_addresses[l]))
1750                                                                         cls.rcon_timeout[l] = realtime + rcon_secure_challengetimeout.value;
1751                                         }
1752
1753                                         return true; // we used up the challenge, so we can't use this oen for connecting now anyway
1754                                 }
1755                         }
1756                 }
1757                 if (length >= 10 && !memcmp(string, "challenge ", 10) && cls.connect_trying)
1758                 {
1759                         // darkplaces or quake3
1760                         char protocolnames[1400];
1761                         Protocol_Names(protocolnames, sizeof(protocolnames));
1762                         Con_DPrintf("\"%s\" received, sending connect request back to %s\n", string, addressstring2);
1763                         M_Update_Return_Reason("Got challenge response");
1764                         // update the server IP in the userinfo (QW servers expect this, and it is used by the reconnect command)
1765                         InfoString_SetValue(cls.userinfo, sizeof(cls.userinfo), "*ip", addressstring2);
1766                         // TODO: add userinfo stuff here instead of using NQ commands?
1767                         NetConn_WriteString(mysocket, va("\377\377\377\377connect\\protocol\\darkplaces 3\\protocols\\%s%s\\challenge\\%s", protocolnames, cls.connect_userinfo, string + 10), peeraddress);
1768                         return true;
1769                 }
1770                 if (length == 6 && !memcmp(string, "accept", 6) && cls.connect_trying)
1771                 {
1772                         // darkplaces or quake3
1773                         M_Update_Return_Reason("Accepted");
1774                         NetConn_ConnectionEstablished(mysocket, peeraddress, PROTOCOL_DARKPLACES3);
1775                         return true;
1776                 }
1777                 if (length > 7 && !memcmp(string, "reject ", 7) && cls.connect_trying)
1778                 {
1779                         char rejectreason[128];
1780                         cls.connect_trying = false;
1781                         string += 7;
1782                         length = min(length - 7, (int)sizeof(rejectreason) - 1);
1783                         memcpy(rejectreason, string, length);
1784                         rejectreason[length] = 0;
1785                         M_Update_Return_Reason(rejectreason);
1786                         return true;
1787                 }
1788                 if (length >= 15 && !memcmp(string, "statusResponse\x0A", 15))
1789                 {
1790                         serverlist_info_t *info;
1791                         char *p;
1792                         int n;
1793
1794                         string += 15;
1795                         // search the cache for this server and update it
1796                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
1797                         if (n < 0)
1798                                 return true;
1799
1800                         info = &serverlist_cache[n].info;
1801                         info->game[0] = 0;
1802                         info->mod[0]  = 0;
1803                         info->map[0]  = 0;
1804                         info->name[0] = 0;
1805                         info->qcstatus[0] = 0;
1806                         info->players[0] = 0;
1807                         info->protocol = -1;
1808                         info->numplayers = 0;
1809                         info->numbots = -1;
1810                         info->maxplayers  = 0;
1811                         info->gameversion = 0;
1812
1813                         p = strchr(string, '\n');
1814                         if(p)
1815                         {
1816                                 *p = 0; // cut off the string there
1817                                 ++p;
1818                         }
1819                         else
1820                                 Con_Printf("statusResponse without players block?\n");
1821
1822                         if ((s = SearchInfostring(string, "gamename"     )) != NULL) strlcpy(info->game, s, sizeof (info->game));
1823                         if ((s = SearchInfostring(string, "modname"      )) != NULL) strlcpy(info->mod , s, sizeof (info->mod ));
1824                         if ((s = SearchInfostring(string, "mapname"      )) != NULL) strlcpy(info->map , s, sizeof (info->map ));
1825                         if ((s = SearchInfostring(string, "hostname"     )) != NULL) strlcpy(info->name, s, sizeof (info->name));
1826                         if ((s = SearchInfostring(string, "protocol"     )) != NULL) info->protocol = atoi(s);
1827                         if ((s = SearchInfostring(string, "clients"      )) != NULL) info->numplayers = atoi(s);
1828                         if ((s = SearchInfostring(string, "bots"         )) != NULL) info->numbots = atoi(s);
1829                         if ((s = SearchInfostring(string, "sv_maxclients")) != NULL) info->maxplayers = atoi(s);
1830                         if ((s = SearchInfostring(string, "gameversion"  )) != NULL) info->gameversion = atoi(s);
1831                         if ((s = SearchInfostring(string, "qcstatus"     )) != NULL) strlcpy(info->qcstatus, s, sizeof(info->qcstatus));
1832                         if (p                                               != NULL) strlcpy(info->players, p, sizeof(info->players));
1833                         info->numhumans = info->numplayers - max(0, info->numbots);
1834                         info->freeslots = info->maxplayers - info->numplayers;
1835
1836                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
1837
1838                         return true;
1839                 }
1840                 if (length >= 13 && !memcmp(string, "infoResponse\x0A", 13))
1841                 {
1842                         serverlist_info_t *info;
1843                         int n;
1844
1845                         string += 13;
1846                         // search the cache for this server and update it
1847                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
1848                         if (n < 0)
1849                                 return true;
1850
1851                         info = &serverlist_cache[n].info;
1852                         info->game[0] = 0;
1853                         info->mod[0]  = 0;
1854                         info->map[0]  = 0;
1855                         info->name[0] = 0;
1856                         info->qcstatus[0] = 0;
1857                         info->players[0] = 0;
1858                         info->protocol = -1;
1859                         info->numplayers = 0;
1860                         info->numbots = -1;
1861                         info->maxplayers  = 0;
1862                         info->gameversion = 0;
1863
1864                         if ((s = SearchInfostring(string, "gamename"     )) != NULL) strlcpy(info->game, s, sizeof (info->game));
1865                         if ((s = SearchInfostring(string, "modname"      )) != NULL) strlcpy(info->mod , s, sizeof (info->mod ));
1866                         if ((s = SearchInfostring(string, "mapname"      )) != NULL) strlcpy(info->map , s, sizeof (info->map ));
1867                         if ((s = SearchInfostring(string, "hostname"     )) != NULL) strlcpy(info->name, s, sizeof (info->name));
1868                         if ((s = SearchInfostring(string, "protocol"     )) != NULL) info->protocol = atoi(s);
1869                         if ((s = SearchInfostring(string, "clients"      )) != NULL) info->numplayers = atoi(s);
1870                         if ((s = SearchInfostring(string, "bots"         )) != NULL) info->numbots = atoi(s);
1871                         if ((s = SearchInfostring(string, "sv_maxclients")) != NULL) info->maxplayers = atoi(s);
1872                         if ((s = SearchInfostring(string, "gameversion"  )) != NULL) info->gameversion = atoi(s);
1873                         if ((s = SearchInfostring(string, "qcstatus"     )) != NULL) strlcpy(info->qcstatus, s, sizeof(info->qcstatus));
1874                         info->numhumans = info->numplayers - max(0, info->numbots);
1875                         info->freeslots = info->maxplayers - info->numplayers;
1876
1877                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
1878
1879                         return true;
1880                 }
1881                 if (!strncmp(string, "getserversResponse\\", 19) && serverlist_cachecount < SERVERLIST_TOTALSIZE)
1882                 {
1883                         // Extract the IP addresses
1884                         data += 18;
1885                         length -= 18;
1886                         NetConn_ClientParsePacket_ServerList_ParseDPList(peeraddress, data, length, false);
1887                         return true;
1888                 }
1889                 if (!strncmp(string, "getserversExtResponse", 21) && serverlist_cachecount < SERVERLIST_TOTALSIZE)
1890                 {
1891                         // Extract the IP addresses
1892                         data += 21;
1893                         length -= 21;
1894                         NetConn_ClientParsePacket_ServerList_ParseDPList(peeraddress, data, length, true);
1895                         return true;
1896                 }
1897                 if (!memcmp(string, "d\n", 2) && serverlist_cachecount < SERVERLIST_TOTALSIZE)
1898                 {
1899                         // Extract the IP addresses
1900                         data += 2;
1901                         length -= 2;
1902                         masterreplycount++;
1903                         if (serverlist_consoleoutput)
1904                                 Con_Printf("received QuakeWorld server list from %s...\n", addressstring2);
1905                         while (length >= 6 && (data[0] != 0xFF || data[1] != 0xFF || data[2] != 0xFF || data[3] != 0xFF) && data[4] * 256 + data[5] != 0)
1906                         {
1907                                 dpsnprintf (ipstring, sizeof (ipstring), "%u.%u.%u.%u:%u", data[0], data[1], data[2], data[3], data[4] * 256 + data[5]);
1908                                 if (serverlist_consoleoutput && developer_networking.integer)
1909                                         Con_Printf("Requesting info from QuakeWorld server %s\n", ipstring);
1910                                 
1911                                 if( !NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_QUAKEWORLD, ipstring, false ) ) {
1912                                         break;
1913                                 }
1914
1915                                 // move on to next address in packet
1916                                 data += 6;
1917                                 length -= 6;
1918                         }
1919                         // begin or resume serverlist queries
1920                         serverlist_querysleep = false;
1921                         serverlist_querywaittime = realtime + 3;
1922                         return true;
1923                 }
1924                 if (!strncmp(string, "extResponse ", 12))
1925                 {
1926                         ++cl_net_extresponse_count;
1927                         if(cl_net_extresponse_count > NET_EXTRESPONSE_MAX)
1928                                 cl_net_extresponse_count = NET_EXTRESPONSE_MAX;
1929                         cl_net_extresponse_last = (cl_net_extresponse_last + 1) % NET_EXTRESPONSE_MAX;
1930                         dpsnprintf(cl_net_extresponse[cl_net_extresponse_last], sizeof(cl_net_extresponse[cl_net_extresponse_last]), "\"%s\" %s", addressstring2, string + 12);
1931                         return true;
1932                 }
1933                 if (!strncmp(string, "ping", 4))
1934                 {
1935                         if (developer_extra.integer)
1936                                 Con_DPrintf("Received ping from %s, sending ack\n", addressstring2);
1937                         NetConn_WriteString(mysocket, "\377\377\377\377ack", peeraddress);
1938                         return true;
1939                 }
1940                 if (!strncmp(string, "ack", 3))
1941                         return true;
1942                 // QuakeWorld compatibility
1943                 if (length > 1 && string[0] == 'c' && (string[1] == '-' || (string[1] >= '0' && string[1] <= '9')) && cls.connect_trying)
1944                 {
1945                         // challenge message
1946                         Con_Printf("challenge %s received, sending QuakeWorld connect request back to %s\n", string + 1, addressstring2);
1947                         M_Update_Return_Reason("Got QuakeWorld challenge response");
1948                         cls.qw_qport = qport.integer;
1949                         // update the server IP in the userinfo (QW servers expect this, and it is used by the reconnect command)
1950                         InfoString_SetValue(cls.userinfo, sizeof(cls.userinfo), "*ip", addressstring2);
1951                         NetConn_WriteString(mysocket, va("\377\377\377\377connect %i %i %i \"%s%s\"\n", 28, cls.qw_qport, atoi(string + 1), cls.userinfo, cls.connect_userinfo), peeraddress);
1952                         return true;
1953                 }
1954                 if (length >= 1 && string[0] == 'j' && cls.connect_trying)
1955                 {
1956                         // accept message
1957                         M_Update_Return_Reason("QuakeWorld Accepted");
1958                         NetConn_ConnectionEstablished(mysocket, peeraddress, PROTOCOL_QUAKEWORLD);
1959                         return true;
1960                 }
1961                 if (length > 2 && !memcmp(string, "n\\", 2))
1962                 {
1963                         serverlist_info_t *info;
1964                         int n;
1965
1966                         // qw server status
1967                         if (serverlist_consoleoutput && developer_networking.integer >= 2)
1968                                 Con_Printf("QW server status from server at %s:\n%s\n", addressstring2, string + 1);
1969
1970                         string += 1;
1971                         // search the cache for this server and update it
1972                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
1973                         if (n < 0)
1974                                 return true;
1975
1976                         info = &serverlist_cache[n].info;
1977                         strlcpy(info->game, "QuakeWorld", sizeof(info->game));
1978                         if ((s = SearchInfostring(string, "*gamedir"     )) != NULL) strlcpy(info->mod , s, sizeof (info->mod ));else info->mod[0]  = 0;
1979                         if ((s = SearchInfostring(string, "map"          )) != NULL) strlcpy(info->map , s, sizeof (info->map ));else info->map[0]  = 0;
1980                         if ((s = SearchInfostring(string, "hostname"     )) != NULL) strlcpy(info->name, s, sizeof (info->name));else info->name[0] = 0;
1981                         info->protocol = 0;
1982                         info->numplayers = 0; // updated below
1983                         info->numhumans = 0; // updated below
1984                         if ((s = SearchInfostring(string, "maxclients"   )) != NULL) info->maxplayers = atoi(s);else info->maxplayers  = 0;
1985                         if ((s = SearchInfostring(string, "gameversion"  )) != NULL) info->gameversion = atoi(s);else info->gameversion = 0;
1986
1987                         // count active players on server
1988                         // (we could gather more info, but we're just after the number)
1989                         s = strchr(string, '\n');
1990                         if (s)
1991                         {
1992                                 s++;
1993                                 while (s < string + length)
1994                                 {
1995                                         for (;s < string + length && *s != '\n';s++)
1996                                                 ;
1997                                         if (s >= string + length)
1998                                                 break;
1999                                         info->numplayers++;
2000                                         info->numhumans++;
2001                                         s++;
2002                                 }
2003                         }
2004
2005                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
2006
2007                         return true;
2008                 }
2009                 if (string[0] == 'n')
2010                 {
2011                         // qw print command
2012                         Con_Printf("QW print command from server at %s:\n%s\n", addressstring2, string + 1);
2013                 }
2014                 // we may not have liked the packet, but it was a command packet, so
2015                 // we're done processing this packet now
2016                 return true;
2017         }
2018         // quakeworld ingame packet
2019         if (fromserver && cls.protocol == PROTOCOL_QUAKEWORLD && length >= 8 && (ret = NetConn_ReceivedMessage(cls.netcon, data, length, cls.protocol, net_messagetimeout.value)) == 2)
2020         {
2021                 ret = 0;
2022                 CL_ParseServerMessage();
2023                 return ret;
2024         }
2025         // netquake control packets, supported for compatibility only
2026         if (length >= 5 && (control = BuffBigLong(data)) && (control & (~NETFLAG_LENGTH_MASK)) == (int)NETFLAG_CTL && (control & NETFLAG_LENGTH_MASK) == length && !ENCRYPTION_REQUIRED)
2027         {
2028                 int n;
2029                 serverlist_info_t *info;
2030
2031                 data += 4;
2032                 length -= 4;
2033                 SZ_Clear(&net_message);
2034                 SZ_Write(&net_message, data, length);
2035                 MSG_BeginReading();
2036                 c = MSG_ReadByte();
2037                 switch (c)
2038                 {
2039                 case CCREP_ACCEPT:
2040                         if (developer_extra.integer)
2041                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_ACCEPT from %s.\n", addressstring2);
2042                         if (cls.connect_trying)
2043                         {
2044                                 lhnetaddress_t clientportaddress;
2045                                 clientportaddress = *peeraddress;
2046                                 LHNETADDRESS_SetPort(&clientportaddress, MSG_ReadLong());
2047                                 // extra ProQuake stuff
2048                                 if (length >= 6)
2049                                         cls.proquake_servermod = MSG_ReadByte(); // MOD_PROQUAKE
2050                                 else
2051                                         cls.proquake_servermod = 0;
2052                                 if (length >= 7)
2053                                         cls.proquake_serverversion = MSG_ReadByte(); // version * 10
2054                                 else
2055                                         cls.proquake_serverversion = 0;
2056                                 if (length >= 8)
2057                                         cls.proquake_serverflags = MSG_ReadByte(); // flags (mainly PQF_CHEATFREE)
2058                                 else
2059                                         cls.proquake_serverflags = 0;
2060                                 if (cls.proquake_servermod == 1)
2061                                         Con_Printf("Connected to ProQuake %.1f server, enabling precise aim\n", cls.proquake_serverversion / 10.0f);
2062                                 // update the server IP in the userinfo (QW servers expect this, and it is used by the reconnect command)
2063                                 InfoString_SetValue(cls.userinfo, sizeof(cls.userinfo), "*ip", addressstring2);
2064                                 M_Update_Return_Reason("Accepted");
2065                                 NetConn_ConnectionEstablished(mysocket, &clientportaddress, PROTOCOL_QUAKE);
2066                         }
2067                         break;
2068                 case CCREP_REJECT:
2069                         if (developer_extra.integer)
2070                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_REJECT from %s.\n", addressstring2);
2071                         cls.connect_trying = false;
2072                         M_Update_Return_Reason((char *)MSG_ReadString());
2073                         break;
2074                 case CCREP_SERVER_INFO:
2075                         if (developer_extra.integer)
2076                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_SERVER_INFO from %s.\n", addressstring2);
2077                         // LordHavoc: because the quake server may report weird addresses
2078                         // we just ignore it and keep the real address
2079                         MSG_ReadString();
2080                         // search the cache for this server and update it
2081                         n = NetConn_ClientParsePacket_ServerList_ProcessReply(addressstring2);
2082                         if (n < 0)
2083                                 break;
2084
2085                         info = &serverlist_cache[n].info;
2086                         strlcpy(info->game, "Quake", sizeof(info->game));
2087                         strlcpy(info->mod , "", sizeof(info->mod)); // mod name is not specified
2088                         strlcpy(info->name, MSG_ReadString(), sizeof(info->name));
2089                         strlcpy(info->map , MSG_ReadString(), sizeof(info->map));
2090                         info->numplayers = MSG_ReadByte();
2091                         info->maxplayers = MSG_ReadByte();
2092                         info->protocol = MSG_ReadByte();
2093
2094                         NetConn_ClientParsePacket_ServerList_UpdateCache(n);
2095
2096                         break;
2097                 case CCREP_RCON: // RocketGuy: ProQuake rcon support
2098                         if (developer_extra.integer)
2099                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREP_RCON from %s.\n", addressstring2);
2100
2101                         Con_Printf("%s\n", MSG_ReadString());
2102                         break;
2103                 case CCREP_PLAYER_INFO:
2104                         // we got a CCREP_PLAYER_INFO??
2105                         //if (developer_extra.integer)
2106                                 Con_Printf("Datagram_ParseConnectionless: received CCREP_PLAYER_INFO from %s.\n", addressstring2);
2107                         break;
2108                 case CCREP_RULE_INFO:
2109                         // we got a CCREP_RULE_INFO??
2110                         //if (developer_extra.integer)
2111                                 Con_Printf("Datagram_ParseConnectionless: received CCREP_RULE_INFO from %s.\n", addressstring2);
2112                         break;
2113                 default:
2114                         break;
2115                 }
2116                 SZ_Clear(&net_message);
2117                 // we may not have liked the packet, but it was a valid control
2118                 // packet, so we're done processing this packet now
2119                 return true;
2120         }
2121         ret = 0;
2122         if (fromserver && length >= (int)NET_HEADERSIZE && (ret = NetConn_ReceivedMessage(cls.netcon, data, length, cls.protocol, net_messagetimeout.value)) == 2)
2123                 CL_ParseServerMessage();
2124         return ret;
2125 }
2126
2127 void NetConn_QueryQueueFrame(void)
2128 {
2129         int index;
2130         int queries;
2131         int maxqueries;
2132         double timeouttime;
2133         static double querycounter = 0;
2134
2135         if(!net_slist_pause.integer && serverlist_paused)
2136                 ServerList_RebuildViewList();
2137         serverlist_paused = net_slist_pause.integer != 0;
2138
2139         if (serverlist_querysleep)
2140                 return;
2141
2142         // apply a cool down time after master server replies,
2143         // to avoid messing up the ping times on the servers
2144         if (serverlist_querywaittime > realtime)
2145                 return;
2146
2147         // each time querycounter reaches 1.0 issue a query
2148         querycounter += cl.realframetime * net_slist_queriespersecond.value;
2149         maxqueries = (int)querycounter;
2150         maxqueries = bound(0, maxqueries, net_slist_queriesperframe.integer);
2151         querycounter -= maxqueries;
2152
2153         if( maxqueries == 0 ) {
2154                 return;
2155         }
2156
2157         //      scan serverlist and issue queries as needed
2158         serverlist_querysleep = true;
2159
2160         timeouttime     = realtime - net_slist_timeout.value;
2161         for( index = 0, queries = 0 ;   index   < serverlist_cachecount &&      queries < maxqueries    ; index++ )
2162         {
2163                 serverlist_entry_t *entry = &serverlist_cache[ index ];
2164                 if( entry->query != SQS_QUERYING && entry->query != SQS_REFRESHING )
2165                 {
2166                         continue;
2167                 }
2168
2169                 serverlist_querysleep   = false;
2170                 if( entry->querycounter !=      0 && entry->querytime > timeouttime     )
2171                 {
2172                         continue;
2173                 }
2174
2175                 if( entry->querycounter !=      (unsigned) net_slist_maxtries.integer )
2176                 {
2177                         lhnetaddress_t  address;
2178                         int socket;
2179
2180                         LHNETADDRESS_FromString(&address, entry->info.cname, 0);
2181                         if      (entry->protocol == PROTOCOL_QUAKEWORLD)
2182                         {
2183                                 for (socket     = 0; socket     < cl_numsockets ;       socket++)
2184                                         NetConn_WriteString(cl_sockets[socket], "\377\377\377\377status\n", &address);
2185                         }
2186                         else
2187                         {
2188                                 for (socket     = 0; socket     < cl_numsockets ;       socket++)
2189                                         NetConn_WriteString(cl_sockets[socket], "\377\377\377\377getstatus", &address);
2190                         }
2191
2192                         //      update the entry fields
2193                         entry->querytime = realtime;
2194                         entry->querycounter++;
2195
2196                         // if not in the slist menu we should print the server to console
2197                         if (serverlist_consoleoutput)
2198                                 Con_Printf("querying %25s (%i. try)\n", entry->info.cname, entry->querycounter);
2199
2200                         queries++;
2201                 }
2202                 else
2203                 {
2204                         // have we tried to refresh this server?
2205                         if( entry->query == SQS_REFRESHING ) {
2206                                 // yes, so update the reply count (since its not responding anymore)
2207                                 serverreplycount--;
2208                                 if(!serverlist_paused)
2209                                         ServerList_ViewList_Remove(entry);
2210                         }
2211                         entry->query = SQS_TIMEDOUT;
2212                 }
2213         }
2214 }
2215
2216 void NetConn_ClientFrame(void)
2217 {
2218         int i, length;
2219         lhnetaddress_t peeraddress;
2220         NetConn_UpdateSockets();
2221         if (cls.connect_trying && cls.connect_nextsendtime < realtime)
2222         {
2223                 if (cls.connect_remainingtries == 0)
2224                         M_Update_Return_Reason("Connect: Waiting 10 seconds for reply");
2225                 cls.connect_nextsendtime = realtime + 1;
2226                 cls.connect_remainingtries--;
2227                 if (cls.connect_remainingtries <= -10)
2228                 {
2229                         cls.connect_trying = false;
2230                         M_Update_Return_Reason("Connect: Failed");
2231                         return;
2232                 }
2233                 // try challenge first (newer DP server or QW)
2234                 NetConn_WriteString(cls.connect_mysocket, "\377\377\377\377getchallenge", &cls.connect_address);
2235                 // then try netquake as a fallback (old server, or netquake)
2236                 SZ_Clear(&net_message);
2237                 // save space for the header, filled in later
2238                 MSG_WriteLong(&net_message, 0);
2239                 MSG_WriteByte(&net_message, CCREQ_CONNECT);
2240                 MSG_WriteString(&net_message, "QUAKE");
2241                 MSG_WriteByte(&net_message, NET_PROTOCOL_VERSION);
2242                 // extended proquake stuff
2243                 MSG_WriteByte(&net_message, 1); // mod = MOD_PROQUAKE
2244                 // this version matches ProQuake 3.40, the first version to support
2245                 // the NAT fix, and it only supports the NAT fix for ProQuake 3.40 or
2246                 // higher clients, so we pretend we are that version...
2247                 MSG_WriteByte(&net_message, 34); // version * 10
2248                 MSG_WriteByte(&net_message, 0); // flags
2249                 MSG_WriteLong(&net_message, 0); // password
2250                 // write the packetsize now...
2251                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
2252                 NetConn_Write(cls.connect_mysocket, net_message.data, net_message.cursize, &cls.connect_address);
2253                 SZ_Clear(&net_message);
2254         }
2255         for (i = 0;i < cl_numsockets;i++)
2256         {
2257                 while (cl_sockets[i] && (length = NetConn_Read(cl_sockets[i], readbuffer, sizeof(readbuffer), &peeraddress)) > 0)
2258                 {
2259 //                      R_TimeReport("clientreadnetwork");
2260                         NetConn_ClientParsePacket(cl_sockets[i], readbuffer, length, &peeraddress);
2261 //                      R_TimeReport("clientparsepacket");
2262                 }
2263         }
2264         NetConn_QueryQueueFrame();
2265         if (cls.netcon && realtime > cls.netcon->timeout && !sv.active)
2266         {
2267                 Con_Print("Connection timed out\n");
2268                 CL_Disconnect();
2269                 Host_ShutdownServer ();
2270         }
2271 }
2272
2273 static void NetConn_BuildChallengeString(char *buffer, int bufferlength)
2274 {
2275         int i;
2276         char c;
2277         for (i = 0;i < bufferlength - 1;i++)
2278         {
2279                 do
2280                 {
2281                         c = rand () % (127 - 33) + 33;
2282                 } while (c == '\\' || c == ';' || c == '"' || c == '%' || c == '/');
2283                 buffer[i] = c;
2284         }
2285         buffer[i] = 0;
2286 }
2287
2288 /// (div0) build the full response only if possible; better a getinfo response than no response at all if getstatus won't fit
2289 static qboolean NetConn_BuildStatusResponse(const char* challenge, char* out_msg, size_t out_size, qboolean fullstatus)
2290 {
2291         char qcstatus[256];
2292         unsigned int nb_clients = 0, nb_bots = 0, i;
2293         int length;
2294         char teambuf[3];
2295         const char *crypto_idstring;
2296         const char *str;
2297
2298         SV_VM_Begin();
2299
2300         // How many clients are there?
2301         for (i = 0;i < (unsigned int)svs.maxclients;i++)
2302         {
2303                 if (svs.clients[i].active)
2304                 {
2305                         nb_clients++;
2306                         if (!svs.clients[i].netconnection)
2307                                 nb_bots++;
2308                 }
2309         }
2310
2311         *qcstatus = 0;
2312         str = PRVM_GetString(PRVM_serverglobalstring(worldstatus));
2313         if(str && *str)
2314         {
2315                 char *p;
2316                 const char *q;
2317                 p = qcstatus;
2318                 for(q = str; *q && (size_t)(p - qcstatus) < (sizeof(qcstatus) - 1); ++q)
2319                         if(*q != '\\' && *q != '\n')
2320                                 *p++ = *q;
2321                 *p = 0;
2322         }
2323
2324         /// \TODO: we should add more information for the full status string
2325         crypto_idstring = Crypto_GetInfoResponseDataString();
2326         length = dpsnprintf(out_msg, out_size,
2327                                                 "\377\377\377\377%s\x0A"
2328                                                 "\\gamename\\%s\\modname\\%s\\gameversion\\%d\\sv_maxclients\\%d"
2329                                                 "\\clients\\%d\\bots\\%d\\mapname\\%s\\hostname\\%s\\protocol\\%d"
2330                                                 "%s%s"
2331                                                 "%s%s"
2332                                                 "%s%s"
2333                                                 "%s",
2334                                                 fullstatus ? "statusResponse" : "infoResponse",
2335                                                 gamename, com_modname, gameversion.integer, svs.maxclients,
2336                                                 nb_clients, nb_bots, sv.worldbasename, hostname.string, NET_PROTOCOL_VERSION,
2337                                                 *qcstatus ? "\\qcstatus\\" : "", qcstatus,
2338                                                 challenge ? "\\challenge\\" : "", challenge ? challenge : "",
2339                                                 crypto_idstring ? "\\d0_blind_id\\" : "", crypto_idstring ? crypto_idstring : "",
2340                                                 fullstatus ? "\n" : "");
2341
2342         // Make sure it fits in the buffer
2343         if (length < 0)
2344                 goto bad;
2345
2346         if (fullstatus)
2347         {
2348                 char *ptr;
2349                 int left;
2350                 int savelength;
2351
2352                 savelength = length;
2353
2354                 ptr = out_msg + length;
2355                 left = (int)out_size - length;
2356
2357                 for (i = 0;i < (unsigned int)svs.maxclients;i++)
2358                 {
2359                         client_t *cl = &svs.clients[i];
2360                         if (cl->active)
2361                         {
2362                                 int nameind, cleanind, pingvalue;
2363                                 char curchar;
2364                                 char cleanname [sizeof(cl->name)];
2365                                 const char *str;
2366                                 prvm_edict_t *ed;
2367
2368                                 // Remove all characters '"' and '\' in the player name
2369                                 nameind = 0;
2370                                 cleanind = 0;
2371                                 do
2372                                 {
2373                                         curchar = cl->name[nameind++];
2374                                         if (curchar != '"' && curchar != '\\')
2375                                         {
2376                                                 cleanname[cleanind++] = curchar;
2377                                                 if (cleanind == sizeof(cleanname) - 1)
2378                                                         break;
2379                                         }
2380                                 } while (curchar != '\0');
2381                                 cleanname[cleanind] = 0; // cleanind is always a valid index even at this point
2382
2383                                 pingvalue = (int)(cl->ping * 1000.0f);
2384                                 if(cl->netconnection)
2385                                         pingvalue = bound(1, pingvalue, 9999);
2386                                 else
2387                                         pingvalue = 0;
2388
2389                                 *qcstatus = 0;
2390                                 ed = PRVM_EDICT_NUM(i + 1);
2391                                 str = PRVM_GetString(PRVM_serveredictstring(ed, clientstatus));
2392                                 if(str && *str)
2393                                 {
2394                                         char *p;
2395                                         const char *q;
2396                                         p = qcstatus;
2397                                         for(q = str; *q && p != qcstatus + sizeof(qcstatus) - 1; ++q)
2398                                                 if(*q != '\\' && *q != '"' && !ISWHITESPACE(*q))
2399                                                         *p++ = *q;
2400                                         *p = 0;
2401                                 }
2402
2403                                 if ((gamemode == GAME_NEXUIZ || gamemode == GAME_XONOTIC) && (teamplay.integer > 0))
2404                                 {
2405                                         if(cl->frags == -666) // spectator
2406                                                 strlcpy(teambuf, " 0", sizeof(teambuf));
2407                                         else if(cl->colors == 0x44) // red team
2408                                                 strlcpy(teambuf, " 1", sizeof(teambuf));
2409                                         else if(cl->colors == 0xDD) // blue team
2410                                                 strlcpy(teambuf, " 2", sizeof(teambuf));
2411                                         else if(cl->colors == 0xCC) // yellow team
2412                                                 strlcpy(teambuf, " 3", sizeof(teambuf));
2413                                         else if(cl->colors == 0x99) // pink team
2414                                                 strlcpy(teambuf, " 4", sizeof(teambuf));
2415                                         else
2416                                                 strlcpy(teambuf, " 0", sizeof(teambuf));
2417                                 }
2418                                 else
2419                                         *teambuf = 0;
2420
2421                                 // note: team number is inserted according to SoF2 protocol
2422                                 if(*qcstatus)
2423                                         length = dpsnprintf(ptr, left, "%s %d%s \"%s\"\n",
2424                                                                                 qcstatus,
2425                                                                                 pingvalue,
2426                                                                                 teambuf,
2427                                                                                 cleanname);
2428                                 else
2429                                         length = dpsnprintf(ptr, left, "%d %d%s \"%s\"\n",
2430                                                                                 cl->frags,
2431                                                                                 pingvalue,
2432                                                                                 teambuf,
2433                                                                                 cleanname);
2434
2435                                 if(length < 0)
2436                                 {
2437                                         // out of space?
2438                                         // turn it into an infoResponse!
2439                                         out_msg[savelength] = 0;
2440                                         memcpy(out_msg + 4, "infoResponse\x0A", 13);
2441                                         memmove(out_msg + 17, out_msg + 19, savelength - 19);
2442                                         break;
2443                                 }
2444                                 left -= length;
2445                                 ptr += length;
2446                         }
2447                 }
2448         }
2449
2450         SV_VM_End();
2451         return true;
2452
2453 bad:
2454         SV_VM_End();
2455         return false;
2456 }
2457
2458 static qboolean NetConn_PreventConnectFlood(lhnetaddress_t *peeraddress)
2459 {
2460         int floodslotnum, bestfloodslotnum;
2461         double bestfloodtime;
2462         lhnetaddress_t noportpeeraddress;
2463         // see if this is a connect flood
2464         noportpeeraddress = *peeraddress;
2465         LHNETADDRESS_SetPort(&noportpeeraddress, 0);
2466         bestfloodslotnum = 0;
2467         bestfloodtime = sv.connectfloodaddresses[bestfloodslotnum].lasttime;
2468         for (floodslotnum = 0;floodslotnum < MAX_CONNECTFLOODADDRESSES;floodslotnum++)
2469         {
2470                 if (bestfloodtime >= sv.connectfloodaddresses[floodslotnum].lasttime)
2471                 {
2472                         bestfloodtime = sv.connectfloodaddresses[floodslotnum].lasttime;
2473                         bestfloodslotnum = floodslotnum;
2474                 }
2475                 if (sv.connectfloodaddresses[floodslotnum].lasttime && LHNETADDRESS_Compare(&noportpeeraddress, &sv.connectfloodaddresses[floodslotnum].address) == 0)
2476                 {
2477                         // this address matches an ongoing flood address
2478                         if (realtime < sv.connectfloodaddresses[floodslotnum].lasttime + net_connectfloodblockingtimeout.value)
2479                         {
2480                                 // renew the ban on this address so it does not expire
2481                                 // until the flood has subsided
2482                                 sv.connectfloodaddresses[floodslotnum].lasttime = realtime;
2483                                 //Con_Printf("Flood detected!\n");
2484                                 return true;
2485                         }
2486                         // the flood appears to have subsided, so allow this
2487                         bestfloodslotnum = floodslotnum; // reuse the same slot
2488                         break;
2489                 }
2490         }
2491         // begin a new timeout on this address
2492         sv.connectfloodaddresses[bestfloodslotnum].address = noportpeeraddress;
2493         sv.connectfloodaddresses[bestfloodslotnum].lasttime = realtime;
2494         //Con_Printf("Flood detection initiated!\n");
2495         return false;
2496 }
2497
2498 void NetConn_ClearConnectFlood(lhnetaddress_t *peeraddress)
2499 {
2500         int floodslotnum;
2501         lhnetaddress_t noportpeeraddress;
2502         // see if this is a connect flood
2503         noportpeeraddress = *peeraddress;
2504         LHNETADDRESS_SetPort(&noportpeeraddress, 0);
2505         for (floodslotnum = 0;floodslotnum < MAX_CONNECTFLOODADDRESSES;floodslotnum++)
2506         {
2507                 if (sv.connectfloodaddresses[floodslotnum].lasttime && LHNETADDRESS_Compare(&noportpeeraddress, &sv.connectfloodaddresses[floodslotnum].address) == 0)
2508                 {
2509                         // this address matches an ongoing flood address
2510                         // remove the ban
2511                         sv.connectfloodaddresses[floodslotnum].address.addresstype = LHNETADDRESSTYPE_NONE;
2512                         sv.connectfloodaddresses[floodslotnum].lasttime = 0;
2513                         //Con_Printf("Flood cleared!\n");
2514                 }
2515         }
2516 }
2517
2518 typedef qboolean (*rcon_matchfunc_t) (lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen);
2519
2520 qboolean hmac_mdfour_time_matching(lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen)
2521 {
2522         char mdfourbuf[16];
2523         long t1, t2;
2524
2525         t1 = (long) time(NULL);
2526         t2 = strtol(s, NULL, 0);
2527         if(abs(t1 - t2) > rcon_secure_maxdiff.integer)
2528                 return false;
2529
2530         if(!HMAC_MDFOUR_16BYTES((unsigned char *) mdfourbuf, (unsigned char *) s, slen, (unsigned char *) password, strlen(password)))
2531                 return false;
2532
2533         return !memcmp(mdfourbuf, hash, 16);
2534 }
2535
2536 qboolean hmac_mdfour_challenge_matching(lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen)
2537 {
2538         char mdfourbuf[16];
2539         int i;
2540
2541         if(slen < (int)(sizeof(challenge[0].string)) - 1)
2542                 return false;
2543
2544         // validate the challenge
2545         for (i = 0;i < MAX_CHALLENGES;i++)
2546                 if(challenge[i].time > 0)
2547                         if (!LHNETADDRESS_Compare(peeraddress, &challenge[i].address) && !strncmp(challenge[i].string, s, sizeof(challenge[0].string) - 1))
2548                                 break;
2549         // if the challenge is not recognized, drop the packet
2550         if (i == MAX_CHALLENGES)
2551                 return false;
2552
2553         if(!HMAC_MDFOUR_16BYTES((unsigned char *) mdfourbuf, (unsigned char *) s, slen, (unsigned char *) password, strlen(password)))
2554                 return false;
2555
2556         if(memcmp(mdfourbuf, hash, 16))
2557                 return false;
2558
2559         // unmark challenge to prevent replay attacks
2560         challenge[i].time = 0;
2561
2562         return true;
2563 }
2564
2565 qboolean plaintext_matching(lhnetaddress_t *peeraddress, const char *password, const char *hash, const char *s, int slen)
2566 {
2567         return !strcmp(password, hash);
2568 }
2569
2570 /// returns a string describing the user level, or NULL for auth failure
2571 const char *RCon_Authenticate(lhnetaddress_t *peeraddress, const char *password, const char *s, const char *endpos, rcon_matchfunc_t comparator, const char *cs, int cslen)
2572 {
2573         const char *text, *userpass_start, *userpass_end, *userpass_startpass;
2574         static char buf[MAX_INPUTLINE];
2575         qboolean hasquotes;
2576         qboolean restricted = false;
2577         qboolean have_usernames = false;
2578
2579         userpass_start = rcon_password.string;
2580         while((userpass_end = strchr(userpass_start, ' ')))
2581         {
2582                 have_usernames = true;
2583                 strlcpy(buf, userpass_start, ((size_t)(userpass_end-userpass_start) >= sizeof(buf)) ? (int)(sizeof(buf)) : (int)(userpass_end-userpass_start+1));
2584                 if(buf[0])
2585                         if(comparator(peeraddress, buf, password, cs, cslen))
2586                                 goto allow;
2587                 userpass_start = userpass_end + 1;
2588         }
2589         if(userpass_start[0])
2590         {
2591                 userpass_end = userpass_start + strlen(userpass_start);
2592                 if(comparator(peeraddress, userpass_start, password, cs, cslen))
2593                         goto allow;
2594         }
2595
2596         restricted = true;
2597         have_usernames = false;
2598         userpass_start = rcon_restricted_password.string;
2599         while((userpass_end = strchr(userpass_start, ' ')))
2600         {
2601                 have_usernames = true;
2602                 strlcpy(buf, userpass_start, ((size_t)(userpass_end-userpass_start) >= sizeof(buf)) ? (int)(sizeof(buf)) : (int)(userpass_end-userpass_start+1));
2603                 if(buf[0])
2604                         if(comparator(peeraddress, buf, password, cs, cslen))
2605                                 goto check;
2606                 userpass_start = userpass_end + 1;
2607         }
2608         if(userpass_start[0])
2609         {
2610                 userpass_end = userpass_start + strlen(userpass_start);
2611                 if(comparator(peeraddress, userpass_start, password, cs, cslen))
2612                         goto check;
2613         }
2614         
2615         return NULL; // DENIED
2616
2617 check:
2618         for(text = s; text != endpos; ++text)
2619                 if((signed char) *text > 0 && ((signed char) *text < (signed char) ' ' || *text == ';'))
2620                         return NULL; // block possible exploits against the parser/alias expansion
2621
2622         while(s != endpos)
2623         {
2624                 size_t l = strlen(s);
2625                 if(l)
2626                 {
2627                         hasquotes = (strchr(s, '"') != NULL);
2628                         // sorry, we can't allow these substrings in wildcard expressions,
2629                         // as they can mess with the argument counts
2630                         text = rcon_restricted_commands.string;
2631                         while(COM_ParseToken_Console(&text))
2632                         {
2633                                 // com_token now contains a pattern to check for...
2634                                 if(strchr(com_token, '*') || strchr(com_token, '?')) // wildcard expression, * can only match a SINGLE argument
2635                                 {
2636                                         if(!hasquotes)
2637                                                 if(matchpattern_with_separator(s, com_token, true, " ", true)) // note how we excluded tab, newline etc. above
2638                                                         goto match;
2639                                 }
2640                                 else if(strchr(com_token, ' ')) // multi-arg expression? must match in whole
2641                                 {
2642                                         if(!strcmp(com_token, s))
2643                                                 goto match;
2644                                 }
2645                                 else // single-arg expression? must match the beginning of the command
2646                                 {
2647                                         if(!strcmp(com_token, s))
2648                                                 goto match;
2649                                         if(!memcmp(va("%s ", com_token), s, strlen(com_token) + 1))
2650                                                 goto match;
2651                                 }
2652                         }
2653                         // if we got here, nothing matched!
2654                         return NULL;
2655                 }
2656 match:
2657                 s += l + 1;
2658         }
2659
2660 allow:
2661         userpass_startpass = strchr(userpass_start, ':');
2662         if(have_usernames && userpass_startpass && userpass_startpass < userpass_end)
2663                 return va("%srcon (username %.*s)", restricted ? "restricted " : "", (int)(userpass_startpass-userpass_start), userpass_start);
2664
2665         return va("%srcon", restricted ? "restricted " : "");
2666 }
2667
2668 void RCon_Execute(lhnetsocket_t *mysocket, lhnetaddress_t *peeraddress, const char *addressstring2, const char *userlevel, const char *s, const char *endpos, qboolean proquakeprotocol)
2669 {
2670         if(userlevel)
2671         {
2672                 // looks like a legitimate rcon command with the correct password
2673                 const char *s_ptr = s;
2674                 Con_Printf("server received %s command from %s: ", userlevel, host_client ? host_client->name : addressstring2);
2675                 while(s_ptr != endpos)
2676                 {
2677                         size_t l = strlen(s_ptr);
2678                         if(l)
2679                                 Con_Printf(" %s;", s_ptr);
2680                         s_ptr += l + 1;
2681                 }
2682                 Con_Printf("\n");
2683
2684                 if (!host_client || !host_client->netconnection || LHNETADDRESS_GetAddressType(&host_client->netconnection->peeraddress) != LHNETADDRESSTYPE_LOOP)
2685                         Con_Rcon_Redirect_Init(mysocket, peeraddress, proquakeprotocol);
2686                 while(s != endpos)
2687                 {
2688                         size_t l = strlen(s);
2689                         if(l)
2690                         {
2691                                 client_t *host_client_save = host_client;
2692                                 Cmd_ExecuteString(s, src_command);
2693                                 host_client = host_client_save;
2694                                 // in case it is a command that changes host_client (like restart)
2695                         }
2696                         s += l + 1;
2697                 }
2698                 Con_Rcon_Redirect_End();
2699         }
2700         else
2701         {
2702                 Con_Printf("server denied rcon access to %s\n", host_client ? host_client->name : addressstring2);
2703         }
2704 }
2705
2706 extern void SV_SendServerinfo (client_t *client);
2707 static int NetConn_ServerParsePacket(lhnetsocket_t *mysocket, unsigned char *data, int length, lhnetaddress_t *peeraddress)
2708 {
2709         int i, ret, clientnum, best;
2710         double besttime;
2711         client_t *client;
2712         char *s, *string, response[1400], addressstring2[128];
2713         static char stringbuf[16384];
2714         qboolean islocal = (LHNETADDRESS_GetAddressType(peeraddress) == LHNETADDRESSTYPE_LOOP);
2715         char senddata[NET_HEADERSIZE+NET_MAXMESSAGE+CRYPTO_HEADERSIZE];
2716         size_t sendlength, response_len;
2717
2718         if (!sv.active)
2719                 return false;
2720
2721         // convert the address to a string incase we need it
2722         LHNETADDRESS_ToString(peeraddress, addressstring2, sizeof(addressstring2), true);
2723
2724         // see if we can identify the sender as a local player
2725         // (this is necessary for rcon to send a reliable reply if the client is
2726         //  actually on the server, not sending remotely)
2727         for (i = 0, host_client = svs.clients;i < svs.maxclients;i++, host_client++)
2728                 if (host_client->netconnection && host_client->netconnection->mysocket == mysocket && !LHNETADDRESS_Compare(&host_client->netconnection->peeraddress, peeraddress))
2729                         break;
2730         if (i == svs.maxclients)
2731                 host_client = NULL;
2732
2733         if (length >= 5 && data[0] == 255 && data[1] == 255 && data[2] == 255 && data[3] == 255)
2734         {
2735                 // received a command string - strip off the packaging and put it
2736                 // into our string buffer with NULL termination
2737                 data += 4;
2738                 length -= 4;
2739                 length = min(length, (int)sizeof(stringbuf) - 1);
2740                 memcpy(stringbuf, data, length);
2741                 stringbuf[length] = 0;
2742                 string = stringbuf;
2743
2744                 if (developer_extra.integer)
2745                 {
2746                         Con_Printf("NetConn_ServerParsePacket: %s sent us a command:\n", addressstring2);
2747                         Com_HexDumpToConsole(data, length);
2748                 }
2749
2750                 sendlength = sizeof(senddata) - 4;
2751                 switch(Crypto_ServerParsePacket(string, length, senddata+4, &sendlength, peeraddress))
2752                 {
2753                         case CRYPTO_NOMATCH:
2754                                 // nothing to do
2755                                 break;
2756                         case CRYPTO_MATCH:
2757                                 if(sendlength)
2758                                 {
2759                                         memcpy(senddata, "\377\377\377\377", 4);
2760                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
2761                                 }
2762                                 break;
2763                         case CRYPTO_DISCARD:
2764                                 if(sendlength)
2765                                 {
2766                                         memcpy(senddata, "\377\377\377\377", 4);
2767                                         NetConn_Write(mysocket, senddata, sendlength+4, peeraddress);
2768                                 }
2769                                 return true;
2770                                 break;
2771                         case CRYPTO_REPLACE:
2772                                 string = senddata+4;
2773                                 length = sendlength;
2774                                 break;
2775                 }
2776
2777                 if (length >= 12 && !memcmp(string, "getchallenge", 12) && (islocal || sv_public.integer > -3))
2778                 {
2779                         for (i = 0, best = 0, besttime = realtime;i < MAX_CHALLENGES;i++)
2780                         {
2781                                 if(challenge[i].time > 0)
2782                                         if (!LHNETADDRESS_Compare(peeraddress, &challenge[i].address))
2783                                                 break;
2784                                 if (besttime > challenge[i].time)
2785                                         besttime = challenge[best = i].time;
2786                         }
2787                         // if we did not find an exact match, choose the oldest and
2788                         // update address and string
2789                         if (i == MAX_CHALLENGES)
2790                         {
2791                                 i = best;
2792                                 challenge[i].address = *peeraddress;
2793                                 NetConn_BuildChallengeString(challenge[i].string, sizeof(challenge[i].string));
2794                         }
2795                         challenge[i].time = realtime;
2796                         // send the challenge
2797                         dpsnprintf(response, sizeof(response), "\377\377\377\377challenge %s", challenge[i].string);
2798                         response_len = strlen(response) + 1;
2799                         Crypto_ServerAppendToChallenge(string, length, response, &response_len, sizeof(response));
2800                         NetConn_Write(mysocket, response, response_len, peeraddress);
2801                         return true;
2802                 }
2803                 if (length > 8 && !memcmp(string, "connect\\", 8))
2804                 {
2805                         crypto_t *crypto = Crypto_ServerGetInstance(peeraddress);
2806                         string += 7;
2807                         length -= 7;
2808
2809                         if(crypto && crypto->authenticated)
2810                         {
2811                                 // no need to check challenge
2812                                 if(crypto_developer.integer)
2813                                 {
2814                                         Con_Printf("%s connection to %s is being established: client is %s@%.*s, I am %.*s@%.*s\n",
2815                                                         crypto->use_aes ? "Encrypted" : "Authenticated",
2816                                                         addressstring2,
2817                                                         crypto->client_idfp[0] ? crypto->client_idfp : "-",
2818                                                         crypto_keyfp_recommended_length, crypto->client_keyfp[0] ? crypto->client_keyfp : "-",
2819                                                         crypto_keyfp_recommended_length, crypto->server_idfp[0] ? crypto->server_idfp : "-",
2820                                                         crypto_keyfp_recommended_length, crypto->server_keyfp[0] ? crypto->server_keyfp : "-"
2821                                                   );
2822                                 }
2823                         }
2824                         else
2825                         {
2826                                 if ((s = SearchInfostring(string, "challenge")))
2827                                 {
2828                                         // validate the challenge
2829                                         for (i = 0;i < MAX_CHALLENGES;i++)
2830                                                 if(challenge[i].time > 0)
2831                                                         if (!LHNETADDRESS_Compare(peeraddress, &challenge[i].address) && !strcmp(challenge[i].string, s))
2832                                                                 break;
2833                                         // if the challenge is not recognized, drop the packet
2834                                         if (i == MAX_CHALLENGES)
2835                                                 return true;
2836                                 }
2837                         }
2838
2839                         if((s = SearchInfostring(string, "message")))
2840                                 Con_DPrintf("Connecting client %s sent us the message: %s\n", addressstring2, s);
2841
2842                         if(!(islocal || sv_public.integer > -2))
2843                         {
2844                                 if (developer_extra.integer)
2845                                         Con_Printf("Datagram_ParseConnectionless: sending \"reject %s\" to %s.\n", sv_public_rejectreason.string, addressstring2);
2846                                 NetConn_WriteString(mysocket, va("\377\377\377\377reject %s", sv_public_rejectreason.string), peeraddress);
2847                                 return true;
2848                         }
2849
2850                         // check engine protocol
2851                         if(!(s = SearchInfostring(string, "protocol")) || strcmp(s, "darkplaces 3"))
2852                         {
2853                                 if (developer_extra.integer)
2854                                         Con_Printf("Datagram_ParseConnectionless: sending \"reject Wrong game protocol.\" to %s.\n", addressstring2);
2855                                 NetConn_WriteString(mysocket, "\377\377\377\377reject Wrong game protocol.", peeraddress);
2856                                 return true;
2857                         }
2858
2859                         // see if this is a duplicate connection request or a disconnected
2860                         // client who is rejoining to the same client slot
2861                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
2862                         {
2863                                 if (client->netconnection && LHNETADDRESS_Compare(peeraddress, &client->netconnection->peeraddress) == 0)
2864                                 {
2865                                         // this is a known client...
2866                                         if(crypto && crypto->authenticated)
2867                                         {
2868                                                 // reject if changing key!
2869                                                 if(client->netconnection->crypto.authenticated)
2870                                                 {
2871                                                         if(
2872                                                                         strcmp(client->netconnection->crypto.client_idfp, crypto->client_idfp)
2873                                                                         ||
2874                                                                         strcmp(client->netconnection->crypto.server_idfp, crypto->server_idfp)
2875                                                                         ||
2876                                                                         strcmp(client->netconnection->crypto.client_keyfp, crypto->client_keyfp)
2877                                                                         ||
2878                                                                         strcmp(client->netconnection->crypto.server_keyfp, crypto->server_keyfp)
2879                                                           )
2880                                                         {
2881                                                                 if (developer_extra.integer)
2882                                                                         Con_Printf("Datagram_ParseConnectionless: sending \"reject Attempt to change key of crypto.\" to %s.\n", addressstring2);
2883                                                                 NetConn_WriteString(mysocket, "\377\377\377\377reject Attempt to change key of crypto.", peeraddress);
2884                                                                 return true;
2885                                                         }
2886                                                 }
2887                                         }
2888                                         else
2889                                         {
2890                                                 // reject if downgrading!
2891                                                 if(client->netconnection->crypto.authenticated)
2892                                                 {
2893                                                         if (developer_extra.integer)
2894                                                                 Con_Printf("Datagram_ParseConnectionless: sending \"reject Attempt to downgrade crypto.\" to %s.\n", addressstring2);
2895                                                         NetConn_WriteString(mysocket, "\377\377\377\377reject Attempt to downgrade crypto.", peeraddress);
2896                                                         return true;
2897                                                 }
2898                                         }
2899                                         if (client->spawned)
2900                                         {
2901                                                 // client crashed and is coming back,
2902                                                 // keep their stuff intact
2903                                                 if (developer_extra.integer)
2904                                                         Con_Printf("Datagram_ParseConnectionless: sending \"accept\" to %s.\n", addressstring2);
2905                                                 NetConn_WriteString(mysocket, "\377\377\377\377accept", peeraddress);
2906                                                 if(crypto && crypto->authenticated)
2907                                                         Crypto_ServerFinishInstance(&client->netconnection->crypto, crypto);
2908                                                 SV_VM_Begin();
2909                                                 SV_SendServerinfo(client);
2910                                                 SV_VM_End();
2911                                         }
2912                                         else
2913                                         {
2914                                                 // client is still trying to connect,
2915                                                 // so we send a duplicate reply
2916                                                 if (developer_extra.integer)
2917                                                         Con_Printf("Datagram_ParseConnectionless: sending duplicate accept to %s.\n", addressstring2);
2918                                                 if(crypto && crypto->authenticated)
2919                                                         Crypto_ServerFinishInstance(&client->netconnection->crypto, crypto);
2920                                                 NetConn_WriteString(mysocket, "\377\377\377\377accept", peeraddress);
2921                                         }
2922                                         return true;
2923                                 }
2924                         }
2925
2926                         if (NetConn_PreventConnectFlood(peeraddress))
2927                                 return true;
2928
2929                         // find an empty client slot for this new client
2930                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
2931                         {
2932                                 netconn_t *conn;
2933                                 if (!client->active && (conn = NetConn_Open(mysocket, peeraddress)))
2934                                 {
2935                                         // allocated connection
2936                                         if (developer_extra.integer)
2937                                                 Con_Printf("Datagram_ParseConnectionless: sending \"accept\" to %s.\n", conn->address);
2938                                         NetConn_WriteString(mysocket, "\377\377\377\377accept", peeraddress);
2939                                         // now set up the client
2940                                         if(crypto && crypto->authenticated)
2941                                                 Crypto_ServerFinishInstance(&conn->crypto, crypto);
2942                                         SV_VM_Begin();
2943                                         SV_ConnectClient(clientnum, conn);
2944                                         SV_VM_End();
2945                                         NetConn_Heartbeat(1);
2946                                         return true;
2947                                 }
2948                         }
2949
2950                         // no empty slots found - server is full
2951                         if (developer_extra.integer)
2952                                 Con_Printf("Datagram_ParseConnectionless: sending \"reject Server is full.\" to %s.\n", addressstring2);
2953                         NetConn_WriteString(mysocket, "\377\377\377\377reject Server is full.", peeraddress);
2954
2955                         return true;
2956                 }
2957                 if (length >= 7 && !memcmp(string, "getinfo", 7) && (islocal || sv_public.integer > -1))
2958                 {
2959                         const char *challenge = NULL;
2960
2961                         // If there was a challenge in the getinfo message
2962                         if (length > 8 && string[7] == ' ')
2963                                 challenge = string + 8;
2964
2965                         if (NetConn_BuildStatusResponse(challenge, response, sizeof(response), false))
2966                         {
2967                                 if (developer_extra.integer)
2968                                         Con_DPrintf("Sending reply to master %s - %s\n", addressstring2, response);
2969                                 NetConn_WriteString(mysocket, response, peeraddress);
2970                         }
2971                         return true;
2972                 }
2973                 if (length >= 9 && !memcmp(string, "getstatus", 9) && (islocal || sv_public.integer > -1))
2974                 {
2975                         const char *challenge = NULL;
2976
2977                         // If there was a challenge in the getinfo message
2978                         if (length > 10 && string[9] == ' ')
2979                                 challenge = string + 10;
2980
2981                         if (NetConn_BuildStatusResponse(challenge, response, sizeof(response), true))
2982                         {
2983                                 if (developer_extra.integer)
2984                                         Con_DPrintf("Sending reply to client %s - %s\n", addressstring2, response);
2985                                 NetConn_WriteString(mysocket, response, peeraddress);
2986                         }
2987                         return true;
2988                 }
2989                 if (length >= 37 && !memcmp(string, "srcon HMAC-MD4 TIME ", 20))
2990                 {
2991                         char *password = string + 20;
2992                         char *timeval = string + 37;
2993                         char *s = strchr(timeval, ' ');
2994                         char *endpos = string + length + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
2995                         const char *userlevel;
2996
2997                         if(rcon_secure.integer > 1)
2998                                 return true;
2999
3000                         if(!s)
3001                                 return true; // invalid packet
3002                         ++s;
3003
3004                         userlevel = RCon_Authenticate(peeraddress, password, s, endpos, hmac_mdfour_time_matching, timeval, endpos - timeval - 1); // not including the appended \0 into the HMAC
3005                         RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, false);
3006                         return true;
3007                 }
3008                 if (length >= 42 && !memcmp(string, "srcon HMAC-MD4 CHALLENGE ", 25))
3009                 {
3010                         char *password = string + 25;
3011                         char *challenge = string + 42;
3012                         char *s = strchr(challenge, ' ');
3013                         char *endpos = string + length + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
3014                         const char *userlevel;
3015                         if(!s)
3016                                 return true; // invalid packet
3017                         ++s;
3018
3019                         userlevel = RCon_Authenticate(peeraddress, password, s, endpos, hmac_mdfour_challenge_matching, challenge, endpos - challenge - 1); // not including the appended \0 into the HMAC
3020                         RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, false);
3021                         return true;
3022                 }
3023                 if (length >= 5 && !memcmp(string, "rcon ", 5))
3024                 {
3025                         int i;
3026                         char *s = string + 5;
3027                         char *endpos = string + length + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
3028                         char password[64];
3029
3030                         if(rcon_secure.integer > 0)
3031                                 return true;
3032
3033                         for (i = 0;!ISWHITESPACE(*s);s++)
3034                                 if (i < (int)sizeof(password) - 1)
3035                                         password[i++] = *s;
3036                         if(ISWHITESPACE(*s) && s != endpos) // skip leading ugly space
3037                                 ++s;
3038                         password[i] = 0;
3039                         if (!ISWHITESPACE(password[0]))
3040                         {
3041                                 const char *userlevel = RCon_Authenticate(peeraddress, password, s, endpos, plaintext_matching, NULL, 0);
3042                                 RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, false);
3043                         }
3044                         return true;
3045                 }
3046                 if (!strncmp(string, "extResponse ", 12))
3047                 {
3048                         ++sv_net_extresponse_count;
3049                         if(sv_net_extresponse_count > NET_EXTRESPONSE_MAX)
3050                                 sv_net_extresponse_count = NET_EXTRESPONSE_MAX;
3051                         sv_net_extresponse_last = (sv_net_extresponse_last + 1) % NET_EXTRESPONSE_MAX;
3052                         dpsnprintf(sv_net_extresponse[sv_net_extresponse_last], sizeof(sv_net_extresponse[sv_net_extresponse_last]), "'%s' %s", addressstring2, string + 12);
3053                         return true;
3054                 }
3055                 if (!strncmp(string, "ping", 4))
3056                 {
3057                         if (developer_extra.integer)
3058                                 Con_DPrintf("Received ping from %s, sending ack\n", addressstring2);
3059                         NetConn_WriteString(mysocket, "\377\377\377\377ack", peeraddress);
3060                         return true;
3061                 }
3062                 if (!strncmp(string, "ack", 3))
3063                         return true;
3064                 // we may not have liked the packet, but it was a command packet, so
3065                 // we're done processing this packet now
3066                 return true;
3067         }
3068         // netquake control packets, supported for compatibility only, and only
3069         // when running game protocols that are normally served via this connection
3070         // protocol
3071         // (this protects more modern protocols against being used for
3072         //  Quake packet flood Denial Of Service attacks)
3073         if (length >= 5 && (i = BuffBigLong(data)) && (i & (~NETFLAG_LENGTH_MASK)) == (int)NETFLAG_CTL && (i & NETFLAG_LENGTH_MASK) == length && (sv.protocol == PROTOCOL_QUAKE || sv.protocol == PROTOCOL_QUAKEDP || sv.protocol == PROTOCOL_NEHAHRAMOVIE || sv.protocol == PROTOCOL_NEHAHRABJP || sv.protocol == PROTOCOL_NEHAHRABJP2 || sv.protocol == PROTOCOL_NEHAHRABJP3 || sv.protocol == PROTOCOL_DARKPLACES1 || sv.protocol == PROTOCOL_DARKPLACES2 || sv.protocol == PROTOCOL_DARKPLACES3) && !ENCRYPTION_REQUIRED)
3074         {
3075                 int c;
3076                 int protocolnumber;
3077                 const char *protocolname;
3078                 data += 4;
3079                 length -= 4;
3080                 SZ_Clear(&net_message);
3081                 SZ_Write(&net_message, data, length);
3082                 MSG_BeginReading();
3083                 c = MSG_ReadByte();
3084                 switch (c)
3085                 {
3086                 case CCREQ_CONNECT:
3087                         if (developer_extra.integer)
3088                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_CONNECT from %s.\n", addressstring2);
3089                         if(!(islocal || sv_public.integer > -2))
3090                         {
3091                                 if (developer_extra.integer)
3092                                         Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_REJECT \"%s\" to %s.\n", sv_public_rejectreason.string, addressstring2);
3093                                 SZ_Clear(&net_message);
3094                                 // save space for the header, filled in later
3095                                 MSG_WriteLong(&net_message, 0);
3096                                 MSG_WriteByte(&net_message, CCREP_REJECT);
3097                                 MSG_WriteString(&net_message, va("%s\n", sv_public_rejectreason.string));
3098                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3099                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3100                                 SZ_Clear(&net_message);
3101                                 break;
3102                         }
3103
3104                         protocolname = MSG_ReadString();
3105                         protocolnumber = MSG_ReadByte();
3106                         if (strcmp(protocolname, "QUAKE") || protocolnumber != NET_PROTOCOL_VERSION)
3107                         {
3108                                 if (developer_extra.integer)
3109                                         Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_REJECT \"Incompatible version.\" to %s.\n", addressstring2);
3110                                 SZ_Clear(&net_message);
3111                                 // save space for the header, filled in later
3112                                 MSG_WriteLong(&net_message, 0);
3113                                 MSG_WriteByte(&net_message, CCREP_REJECT);
3114                                 MSG_WriteString(&net_message, "Incompatible version.\n");
3115                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3116                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3117                                 SZ_Clear(&net_message);
3118                                 break;
3119                         }
3120
3121                         // see if this connect request comes from a known client
3122                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
3123                         {
3124                                 if (client->netconnection && LHNETADDRESS_Compare(peeraddress, &client->netconnection->peeraddress) == 0)
3125                                 {
3126                                         // this is either a duplicate connection request
3127                                         // or coming back from a timeout
3128                                         // (if so, keep their stuff intact)
3129
3130                                         // send a reply
3131                                         if (developer_extra.integer)
3132                                                 Con_DPrintf("Datagram_ParseConnectionless: sending duplicate CCREP_ACCEPT to %s.\n", addressstring2);
3133                                         SZ_Clear(&net_message);
3134                                         // save space for the header, filled in later
3135                                         MSG_WriteLong(&net_message, 0);
3136                                         MSG_WriteByte(&net_message, CCREP_ACCEPT);
3137                                         MSG_WriteLong(&net_message, LHNETADDRESS_GetPort(LHNET_AddressFromSocket(client->netconnection->mysocket)));
3138                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3139                                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3140                                         SZ_Clear(&net_message);
3141
3142                                         // if client is already spawned, re-send the
3143                                         // serverinfo message as they'll need it to play
3144                                         if (client->spawned)
3145                                         {
3146                                                 SV_VM_Begin();
3147                                                 SV_SendServerinfo(client);
3148                                                 SV_VM_End();
3149                                         }
3150                                         return true;
3151                                 }
3152                         }
3153
3154                         // this is a new client, check for connection flood
3155                         if (NetConn_PreventConnectFlood(peeraddress))
3156                                 break;
3157
3158                         // find a slot for the new client
3159                         for (clientnum = 0, client = svs.clients;clientnum < svs.maxclients;clientnum++, client++)
3160                         {
3161                                 netconn_t *conn;
3162                                 if (!client->active && (client->netconnection = conn = NetConn_Open(mysocket, peeraddress)) != NULL)
3163                                 {
3164                                         // connect to the client
3165                                         // everything is allocated, just fill in the details
3166                                         strlcpy (conn->address, addressstring2, sizeof (conn->address));
3167                                         if (developer_extra.integer)
3168                                                 Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_ACCEPT to %s.\n", addressstring2);
3169                                         // send back the info about the server connection
3170                                         SZ_Clear(&net_message);
3171                                         // save space for the header, filled in later
3172                                         MSG_WriteLong(&net_message, 0);
3173                                         MSG_WriteByte(&net_message, CCREP_ACCEPT);
3174                                         MSG_WriteLong(&net_message, LHNETADDRESS_GetPort(LHNET_AddressFromSocket(conn->mysocket)));
3175                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3176                                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3177                                         SZ_Clear(&net_message);
3178                                         // now set up the client struct
3179                                         SV_VM_Begin();
3180                                         SV_ConnectClient(clientnum, conn);
3181                                         SV_VM_End();
3182                                         NetConn_Heartbeat(1);
3183                                         return true;
3184                                 }
3185                         }
3186
3187                         if (developer_extra.integer)
3188                                 Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_REJECT \"Server is full.\" to %s.\n", addressstring2);
3189                         // no room; try to let player know
3190                         SZ_Clear(&net_message);
3191                         // save space for the header, filled in later
3192                         MSG_WriteLong(&net_message, 0);
3193                         MSG_WriteByte(&net_message, CCREP_REJECT);
3194                         MSG_WriteString(&net_message, "Server is full.\n");
3195                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3196                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3197                         SZ_Clear(&net_message);
3198                         break;
3199                 case CCREQ_SERVER_INFO:
3200                         if (developer_extra.integer)
3201                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_SERVER_INFO from %s.\n", addressstring2);
3202                         if(!(islocal || sv_public.integer > -1))
3203                                 break;
3204                         if (sv.active && !strcmp(MSG_ReadString(), "QUAKE"))
3205                         {
3206                                 int numclients;
3207                                 char myaddressstring[128];
3208                                 if (developer_extra.integer)
3209                                         Con_DPrintf("Datagram_ParseConnectionless: sending CCREP_SERVER_INFO to %s.\n", addressstring2);
3210                                 SZ_Clear(&net_message);
3211                                 // save space for the header, filled in later
3212                                 MSG_WriteLong(&net_message, 0);
3213                                 MSG_WriteByte(&net_message, CCREP_SERVER_INFO);
3214                                 LHNETADDRESS_ToString(LHNET_AddressFromSocket(mysocket), myaddressstring, sizeof(myaddressstring), true);
3215                                 MSG_WriteString(&net_message, myaddressstring);
3216                                 MSG_WriteString(&net_message, hostname.string);
3217                                 MSG_WriteString(&net_message, sv.name);
3218                                 // How many clients are there?
3219                                 for (i = 0, numclients = 0;i < svs.maxclients;i++)
3220                                         if (svs.clients[i].active)
3221                                                 numclients++;
3222                                 MSG_WriteByte(&net_message, numclients);
3223                                 MSG_WriteByte(&net_message, svs.maxclients);
3224                                 MSG_WriteByte(&net_message, NET_PROTOCOL_VERSION);
3225                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3226                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3227                                 SZ_Clear(&net_message);
3228                         }
3229                         break;
3230                 case CCREQ_PLAYER_INFO:
3231                         if (developer_extra.integer)
3232                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_PLAYER_INFO from %s.\n", addressstring2);
3233                         if(!(islocal || sv_public.integer > -1))
3234                                 break;
3235                         if (sv.active)
3236                         {
3237                                 int playerNumber, activeNumber, clientNumber;
3238                                 client_t *client;
3239
3240                                 playerNumber = MSG_ReadByte();
3241                                 activeNumber = -1;
3242                                 for (clientNumber = 0, client = svs.clients; clientNumber < svs.maxclients; clientNumber++, client++)
3243                                         if (client->active && ++activeNumber == playerNumber)
3244                                                 break;
3245                                 if (clientNumber != svs.maxclients)
3246                                 {
3247                                         SZ_Clear(&net_message);
3248                                         // save space for the header, filled in later
3249                                         MSG_WriteLong(&net_message, 0);
3250                                         MSG_WriteByte(&net_message, CCREP_PLAYER_INFO);
3251                                         MSG_WriteByte(&net_message, playerNumber);
3252                                         MSG_WriteString(&net_message, client->name);
3253                                         MSG_WriteLong(&net_message, client->colors);
3254                                         MSG_WriteLong(&net_message, client->frags);
3255                                         MSG_WriteLong(&net_message, (int)(realtime - client->connecttime));
3256                                         if(sv_status_privacy.integer)
3257                                                 MSG_WriteString(&net_message, client->netconnection ? "hidden" : "botclient");
3258                                         else
3259                                                 MSG_WriteString(&net_message, client->netconnection ? client->netconnection->address : "botclient");
3260                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3261                                         NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3262                                         SZ_Clear(&net_message);
3263                                 }
3264                         }
3265                         break;
3266                 case CCREQ_RULE_INFO:
3267                         if (developer_extra.integer)
3268                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_RULE_INFO from %s.\n", addressstring2);
3269                         if(!(islocal || sv_public.integer > -1))
3270                                 break;
3271                         if (sv.active)
3272                         {
3273                                 char *prevCvarName;
3274                                 cvar_t *var;
3275
3276                                 // find the search start location
3277                                 prevCvarName = MSG_ReadString();
3278                                 var = Cvar_FindVarAfter(prevCvarName, CVAR_NOTIFY);
3279
3280                                 // send the response
3281                                 SZ_Clear(&net_message);
3282                                 // save space for the header, filled in later
3283                                 MSG_WriteLong(&net_message, 0);
3284                                 MSG_WriteByte(&net_message, CCREP_RULE_INFO);
3285                                 if (var)
3286                                 {
3287                                         MSG_WriteString(&net_message, var->name);
3288                                         MSG_WriteString(&net_message, var->string);
3289                                 }
3290                                 StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3291                                 NetConn_Write(mysocket, net_message.data, net_message.cursize, peeraddress);
3292                                 SZ_Clear(&net_message);
3293                         }
3294                         break;
3295                 case CCREQ_RCON:
3296                         if (developer_extra.integer)
3297                                 Con_DPrintf("Datagram_ParseConnectionless: received CCREQ_RCON from %s.\n", addressstring2);
3298                         if (sv.active && !rcon_secure.integer)
3299                         {
3300                                 char password[2048];
3301                                 char cmd[2048];
3302                                 char *s;
3303                                 char *endpos;
3304                                 const char *userlevel;
3305                                 strlcpy(password, MSG_ReadString(), sizeof(password));
3306                                 strlcpy(cmd, MSG_ReadString(), sizeof(cmd));
3307                                 s = cmd;
3308                                 endpos = cmd + strlen(cmd) + 1; // one behind the NUL, so adding strlen+1 will eventually reach it
3309                                 userlevel = RCon_Authenticate(peeraddress, password, s, endpos, plaintext_matching, NULL, 0);
3310                                 RCon_Execute(mysocket, peeraddress, addressstring2, userlevel, s, endpos, true);
3311                                 return true;
3312                         }
3313                         break;
3314                 default:
3315                         break;
3316                 }
3317                 SZ_Clear(&net_message);
3318                 // we may not have liked the packet, but it was a valid control
3319                 // packet, so we're done processing this packet now
3320                 return true;
3321         }
3322         if (host_client)
3323         {
3324                 if ((ret = NetConn_ReceivedMessage(host_client->netconnection, data, length, sv.protocol, host_client->spawned ? net_messagetimeout.value : net_connecttimeout.value)) == 2)
3325                 {
3326                         SV_VM_Begin();
3327                         SV_ReadClientMessage();
3328                         SV_VM_End();
3329                         return ret;
3330                 }
3331         }
3332         return 0;
3333 }
3334
3335 void NetConn_ServerFrame(void)
3336 {
3337         int i, length;
3338         lhnetaddress_t peeraddress;
3339         for (i = 0;i < sv_numsockets;i++)
3340                 while (sv_sockets[i] && (length = NetConn_Read(sv_sockets[i], readbuffer, sizeof(readbuffer), &peeraddress)) > 0)
3341                         NetConn_ServerParsePacket(sv_sockets[i], readbuffer, length, &peeraddress);
3342         for (i = 0, host_client = svs.clients;i < svs.maxclients;i++, host_client++)
3343         {
3344                 // never timeout loopback connections
3345                 if (host_client->netconnection && realtime > host_client->netconnection->timeout && LHNETADDRESS_GetAddressType(&host_client->netconnection->peeraddress) != LHNETADDRESSTYPE_LOOP)
3346                 {
3347                         Con_Printf("Client \"%s\" connection timed out\n", host_client->name);
3348                         SV_VM_Begin();
3349                         SV_DropClient(false);
3350                         SV_VM_End();
3351                 }
3352         }
3353 }
3354
3355 void NetConn_SleepMicroseconds(int microseconds)
3356 {
3357         LHNET_SleepUntilPacket_Microseconds(microseconds);
3358 }
3359
3360 void NetConn_QueryMasters(qboolean querydp, qboolean queryqw)
3361 {
3362         int i, j;
3363         int masternum;
3364         lhnetaddress_t masteraddress;
3365         lhnetaddress_t broadcastaddress;
3366         char request[256];
3367
3368         if (serverlist_cachecount >= SERVERLIST_TOTALSIZE)
3369                 return;
3370
3371         // 26000 is the default quake server port, servers on other ports will not
3372         // be found
3373         // note this is IPv4-only, I doubt there are IPv6-only LANs out there
3374         LHNETADDRESS_FromString(&broadcastaddress, "255.255.255.255", 26000);
3375
3376         if (querydp)
3377         {
3378                 for (i = 0;i < cl_numsockets;i++)
3379                 {
3380                         if (cl_sockets[i])
3381                         {
3382                                 const char *cmdname, *extraoptions;
3383                                 int af = LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i]));
3384
3385                                 if(LHNETADDRESS_GetAddressType(&broadcastaddress) == af)
3386                                 {
3387                                         // search LAN for Quake servers
3388                                         SZ_Clear(&net_message);
3389                                         // save space for the header, filled in later
3390                                         MSG_WriteLong(&net_message, 0);
3391                                         MSG_WriteByte(&net_message, CCREQ_SERVER_INFO);
3392                                         MSG_WriteString(&net_message, "QUAKE");
3393                                         MSG_WriteByte(&net_message, NET_PROTOCOL_VERSION);
3394                                         StoreBigLong(net_message.data, NETFLAG_CTL | (net_message.cursize & NETFLAG_LENGTH_MASK));
3395                                         NetConn_Write(cl_sockets[i], net_message.data, net_message.cursize, &broadcastaddress);
3396                                         SZ_Clear(&net_message);
3397
3398                                         // search LAN for DarkPlaces servers
3399                                         NetConn_WriteString(cl_sockets[i], "\377\377\377\377getstatus", &broadcastaddress);
3400                                 }
3401
3402                                 // build the getservers message to send to the dpmaster master servers
3403                                 if (LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i])) == LHNETADDRESSTYPE_INET6)
3404                                 {
3405                                         cmdname = "getserversExt";
3406                                         extraoptions = " ipv4 ipv6";  // ask for IPv4 and IPv6 servers
3407                                 }
3408                                 else
3409                                 {
3410                                         cmdname = "getservers";
3411                                         extraoptions = "";
3412                                 }
3413                                 dpsnprintf(request, sizeof(request), "\377\377\377\377%s %s %u empty full%s", cmdname, gamename, NET_PROTOCOL_VERSION, extraoptions);
3414
3415                                 // search internet
3416                                 for (masternum = 0;sv_masters[masternum].name;masternum++)
3417                                 {
3418                                         if (sv_masters[masternum].string && sv_masters[masternum].string[0] && LHNETADDRESS_FromString(&masteraddress, sv_masters[masternum].string, DPMASTER_PORT) && LHNETADDRESS_GetAddressType(&masteraddress) == af)
3419                                         {
3420                                                 masterquerycount++;
3421                                                 NetConn_WriteString(cl_sockets[i], request, &masteraddress);
3422                                         }
3423                                 }
3424
3425                                 // search favorite servers
3426                                 for(j = 0; j < nFavorites; ++j)
3427                                 {
3428                                         if(LHNETADDRESS_GetAddressType(&favorites[j]) == af)
3429                                         {
3430                                                 if(LHNETADDRESS_ToString(&favorites[j], request, sizeof(request), true))
3431                                                         NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_DARKPLACES7, request, true );
3432                                         }
3433                                 }
3434                         }
3435                 }
3436         }
3437
3438         // only query QuakeWorld servers when the user wants to
3439         if (queryqw)
3440         {
3441                 for (i = 0;i < cl_numsockets;i++)
3442                 {
3443                         if (cl_sockets[i])
3444                         {
3445                                 int af = LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i]));
3446
3447                                 if(LHNETADDRESS_GetAddressType(&broadcastaddress) == af)
3448                                 {
3449                                         // search LAN for QuakeWorld servers
3450                                         NetConn_WriteString(cl_sockets[i], "\377\377\377\377status\n", &broadcastaddress);
3451
3452                                         // build the getservers message to send to the qwmaster master servers
3453                                         // note this has no -1 prefix, and the trailing nul byte is sent
3454                                         dpsnprintf(request, sizeof(request), "c\n");
3455                                 }
3456
3457                                 // search internet
3458                                 for (masternum = 0;sv_qwmasters[masternum].name;masternum++)
3459                                 {
3460                                         if (sv_qwmasters[masternum].string && LHNETADDRESS_FromString(&masteraddress, sv_qwmasters[masternum].string, QWMASTER_PORT) && LHNETADDRESS_GetAddressType(&masteraddress) == LHNETADDRESS_GetAddressType(LHNET_AddressFromSocket(cl_sockets[i])))
3461                                         {
3462                                                 if (m_state != m_slist)
3463                                                 {
3464                                                         char lookupstring[128];
3465                                                         LHNETADDRESS_ToString(&masteraddress, lookupstring, sizeof(lookupstring), true);
3466                                                         Con_Printf("Querying master %s (resolved from %s)\n", lookupstring, sv_qwmasters[masternum].string);
3467                                                 }
3468                                                 masterquerycount++;
3469                                                 NetConn_Write(cl_sockets[i], request, (int)strlen(request) + 1, &masteraddress);
3470                                         }
3471                                 }
3472
3473                                 // search favorite servers
3474                                 for(j = 0; j < nFavorites; ++j)
3475                                 {
3476                                         if(LHNETADDRESS_GetAddressType(&favorites[j]) == af)
3477                                         {
3478                                                 if(LHNETADDRESS_ToString(&favorites[j], request, sizeof(request), true))
3479                                                 {
3480                                                         NetConn_WriteString(cl_sockets[i], "\377\377\377\377status\n", &favorites[j]);
3481                                                         NetConn_ClientParsePacket_ServerList_PrepareQuery( PROTOCOL_QUAKEWORLD, request, true );
3482                                                 }
3483                                         }
3484                                 }
3485                         }
3486                 }
3487         }
3488         if (!masterquerycount)
3489         {
3490                 Con_Print("Unable to query master servers, no suitable network sockets active.\n");
3491                 M_Update_Return_Reason("No network");
3492         }
3493 }
3494
3495 void NetConn_Heartbeat(int priority)
3496 {
3497         lhnetaddress_t masteraddress;
3498         int masternum;
3499         lhnetsocket_t *mysocket;
3500
3501         // if it's a state change (client connected), limit next heartbeat to no
3502         // more than 30 sec in the future
3503         if (priority == 1 && nextheartbeattime > realtime + 30.0)
3504                 nextheartbeattime = realtime + 30.0;
3505
3506         // limit heartbeatperiod to 30 to 270 second range,
3507         // lower limit is to avoid abusing master servers with excess traffic,
3508         // upper limit is to avoid timing out on the master server (which uses
3509         // 300 sec timeout)
3510         if (sv_heartbeatperiod.value < 30)
3511                 Cvar_SetValueQuick(&sv_heartbeatperiod, 30);
3512         if (sv_heartbeatperiod.value > 270)
3513                 Cvar_SetValueQuick(&sv_heartbeatperiod, 270);
3514
3515         // make advertising optional and don't advertise singleplayer games, and
3516         // only send a heartbeat as often as the admin wants
3517         if (sv.active && sv_public.integer > 0 && svs.maxclients >= 2 && (priority > 1 || realtime > nextheartbeattime))
3518         {
3519                 nextheartbeattime = realtime + sv_heartbeatperiod.value;
3520                 for (masternum = 0;sv_masters[masternum].name;masternum++)
3521                         if (sv_masters[masternum].string && sv_masters[masternum].string[0] && LHNETADDRESS_FromString(&masteraddress, sv_masters[masternum].string, DPMASTER_PORT) && (mysocket = NetConn_ChooseServerSocketForAddress(&masteraddress)))
3522                                 NetConn_WriteString(mysocket, "\377\377\377\377heartbeat DarkPlaces\x0A", &masteraddress);
3523         }
3524 }
3525
3526 static void Net_Heartbeat_f(void)
3527 {
3528         if (sv.active)
3529                 NetConn_Heartbeat(2);
3530         else
3531                 Con_Print("No server running, can not heartbeat to master server.\n");
3532 }
3533
3534 void PrintStats(netconn_t *conn)
3535 {
3536         if ((cls.state == ca_connected && cls.protocol == PROTOCOL_QUAKEWORLD) || (sv.active && sv.protocol == PROTOCOL_QUAKEWORLD))
3537                 Con_Printf("address=%21s canSend=%u sendSeq=%6u recvSeq=%6u\n", conn->address, !conn->sendMessageLength, conn->outgoing_unreliable_sequence, conn->qw.incoming_sequence);
3538         else
3539                 Con_Printf("address=%21s canSend=%u sendSeq=%6u recvSeq=%6u\n", conn->address, !conn->sendMessageLength, conn->nq.sendSequence, conn->nq.receiveSequence);
3540 }
3541
3542 void Net_Stats_f(void)
3543 {
3544         netconn_t *conn;
3545         Con_Printf("unreliable messages sent   = %i\n", unreliableMessagesSent);
3546         Con_Printf("unreliable messages recv   = %i\n", unreliableMessagesReceived);
3547         Con_Printf("reliable messages sent     = %i\n", reliableMessagesSent);
3548         Con_Printf("reliable messages received = %i\n", reliableMessagesReceived);
3549         Con_Printf("packetsSent                = %i\n", packetsSent);
3550         Con_Printf("packetsReSent              = %i\n", packetsReSent);
3551         Con_Printf("packetsReceived            = %i\n", packetsReceived);
3552         Con_Printf("receivedDuplicateCount     = %i\n", receivedDuplicateCount);
3553         Con_Printf("droppedDatagrams           = %i\n", droppedDatagrams);
3554         Con_Print("connections                =\n");
3555         for (conn = netconn_list;conn;conn = conn->next)
3556                 PrintStats(conn);
3557 }
3558
3559 void Net_Refresh_f(void)
3560 {
3561         if (m_state != m_slist) {
3562                 Con_Print("Sending new requests to master servers\n");
3563                 ServerList_QueryList(false, true, false, true);
3564                 Con_Print("Listening for replies...\n");
3565         } else
3566                 ServerList_QueryList(false, true, false, false);
3567 }
3568
3569 void Net_Slist_f(void)
3570 {
3571         ServerList_ResetMasks();
3572         serverlist_sortbyfield = SLIF_PING;
3573         serverlist_sortflags = 0;
3574     if (m_state != m_slist) {
3575                 Con_Print("Sending requests to master servers\n");
3576                 ServerList_QueryList(true, true, false, true);
3577                 Con_Print("Listening for replies...\n");
3578         } else
3579                 ServerList_QueryList(true, true, false, false);
3580 }
3581
3582 void Net_SlistQW_f(void)
3583 {
3584         ServerList_ResetMasks();
3585         serverlist_sortbyfield = SLIF_PING;
3586         serverlist_sortflags = 0;
3587     if (m_state != m_slist) {
3588                 Con_Print("Sending requests to master servers\n");
3589                 ServerList_QueryList(true, false, true, true);
3590                 serverlist_consoleoutput = true;
3591                 Con_Print("Listening for replies...\n");
3592         } else
3593                 ServerList_QueryList(true, false, true, false);
3594 }
3595
3596 void NetConn_Init(void)
3597 {
3598         int i;
3599         lhnetaddress_t tempaddress;
3600         netconn_mempool = Mem_AllocPool("network connections", 0, NULL);
3601         Cmd_AddCommand("net_stats", Net_Stats_f, "print network statistics");
3602         Cmd_AddCommand("net_slist", Net_Slist_f, "query dp master servers and print all server information");
3603         Cmd_AddCommand("net_slistqw", Net_SlistQW_f, "query qw master servers and print all server information");
3604         Cmd_AddCommand("net_refresh", Net_Refresh_f, "query dp master servers and refresh all server information");
3605         Cmd_AddCommand("heartbeat", Net_Heartbeat_f, "send a heartbeat to the master server (updates your server information)");
3606         Cvar_RegisterVariable(&rcon_restricted_password);
3607         Cvar_RegisterVariable(&rcon_restricted_commands);
3608         Cvar_RegisterVariable(&rcon_secure_maxdiff);
3609         Cvar_RegisterVariable(&net_slist_queriespersecond);
3610         Cvar_RegisterVariable(&net_slist_queriesperframe);
3611         Cvar_RegisterVariable(&net_slist_timeout);
3612         Cvar_RegisterVariable(&net_slist_maxtries);
3613         Cvar_RegisterVariable(&net_slist_favorites);
3614         Cvar_RegisterVariable(&net_slist_pause);
3615         Cvar_RegisterVariable(&net_messagetimeout);
3616         Cvar_RegisterVariable(&net_connecttimeout);
3617         Cvar_RegisterVariable(&net_connectfloodblockingtimeout);
3618         Cvar_RegisterVariable(&cl_netlocalping);
3619         Cvar_RegisterVariable(&cl_netpacketloss_send);
3620         Cvar_RegisterVariable(&cl_netpacketloss_receive);
3621         Cvar_RegisterVariable(&hostname);
3622         Cvar_RegisterVariable(&developer_networking);
3623         Cvar_RegisterVariable(&cl_netport);
3624         Cvar_RegisterVariable(&sv_netport);
3625         Cvar_RegisterVariable(&net_address);
3626         Cvar_RegisterVariable(&net_address_ipv6);
3627         Cvar_RegisterVariable(&sv_public);
3628         Cvar_RegisterVariable(&sv_public_rejectreason);
3629         Cvar_RegisterVariable(&sv_heartbeatperiod);
3630         for (i = 0;sv_masters[i].name;i++)
3631                 Cvar_RegisterVariable(&sv_masters[i]);
3632         Cvar_RegisterVariable(&gameversion);
3633         Cvar_RegisterVariable(&gameversion_min);
3634         Cvar_RegisterVariable(&gameversion_max);
3635 // COMMANDLINEOPTION: Server: -ip <ipaddress> sets the ip address of this machine for purposes of networking (default 0.0.0.0 also known as INADDR_ANY), use only if you have multiple network adapters and need to choose one specifically.
3636         if ((i = COM_CheckParm("-ip")) && i + 1 < com_argc)
3637         {
3638                 if (LHNETADDRESS_FromString(&tempaddress, com_argv[i + 1], 0) == 1)
3639                 {
3640                         Con_Printf("-ip option used, setting net_address to \"%s\"\n", com_argv[i + 1]);
3641                         Cvar_SetQuick(&net_address, com_argv[i + 1]);
3642                 }
3643                 else
3644                         Con_Printf("-ip option used, but unable to parse the address \"%s\"\n", com_argv[i + 1]);
3645         }
3646 // COMMANDLINEOPTION: Server: -port <portnumber> sets the port to use for a server (default 26000, the same port as QUAKE itself), useful if you host multiple servers on your machine
3647         if (((i = COM_CheckParm("-port")) || (i = COM_CheckParm("-ipport")) || (i = COM_CheckParm("-udpport"))) && i + 1 < com_argc)
3648         {
3649                 i = atoi(com_argv[i + 1]);
3650                 if (i >= 0 && i < 65536)
3651                 {
3652                         Con_Printf("-port option used, setting port cvar to %i\n", i);
3653                         Cvar_SetValueQuick(&sv_netport, i);
3654                 }
3655                 else
3656                         Con_Printf("-port option used, but %i is not a valid port number\n", i);
3657         }
3658         cl_numsockets = 0;
3659         sv_numsockets = 0;
3660         net_message.data = net_message_buf;
3661         net_message.maxsize = sizeof(net_message_buf);
3662         net_message.cursize = 0;
3663         LHNET_Init();
3664 }
3665
3666 void NetConn_Shutdown(void)
3667 {
3668         NetConn_CloseClientPorts();
3669         NetConn_CloseServerPorts();
3670         LHNET_Shutdown();
3671 }
3672