Commit graph

31 commits

Author SHA1 Message Date
b6ada854cc
brand: per-SNI server/network identity (welcome, ISUPPORT NETWORK, numeric source prefix) 2026-08-24 23:29:15 +00:00
8d48900ae3
config: derive Eq on the block-parser token enum 2026-08-23 13:01:05 +00:00
1166c49443
config: checkconfig CLI + Config::dump; tls block carries sni/handshake_timeout 2026-08-23 12:42:30 +00:00
b11382bc1e
config: block-format example documenting every option; cloak/uline block fields + example parse guard 2026-08-23 12:28:19 +00:00
2f6ce36af0
config: add brace/block format (translated to flat, both formats supported) 2026-08-23 12:18:10 +00:00
e8d16a1f96
config: accept oper password=<hash> named token; keep positional password back-compat 2026-08-23 03:11:32 +00:00
b693c5e5df
dnsbl: per-zone name/action/duration/reason with %ip%; XLINE notice shows duration + absolute expiry 2026-08-21 14:14:17 +00:00
01516d5fdc
opertypes: oper classes + types — reusable capability classes and named roles (WHOIS title, auto usermodes/snomasks/vhost + level on oper-up, per-type command enforcement via on_pre_command); ships 5 built-in (helpop/globop/admin/servadmin/netadmin); oper blocks gain type=<id>; a typeless oper keeps full access 2026-08-20 10:05:11 +00:00
235c747c03 refactor: WEBIRC gateways and +G censor rules are named structs (WebircGateway/CensorRule) instead of positional tuples — self-documenting field access, no (_, g, _) index guessing; extends the OperBlock pattern 2026-08-18 23:31:21 +00:00
c4456cf002 oper: TLS client-cert fingerprint login — oper block gains an optional fp=<sha256>; password=* means cert-only. Named OperBlock struct replaces the (name,pass,level) tuple. (Password login was never broken — verified live.) 2026-08-18 22:55:07 +00:00
20b49add0b perf: mimalloc global allocator + aHash maps + memchr line framer + LTO/codegen-units=1 — ~29% faster channel fanout; and drop the bogus openssl+mio dependency whitelist from the guard (any perf crate is welcome now) 2026-08-18 19:45:33 +00:00
0ace39c882 listeners: make bind/bind_tls/bind_server repeatable (multiple addresses/ports) and normalize IPv4-mapped IPv6 peers back to plain IPv4 — a single [::] bind now serves IPv4+IPv6 with clean v4 addresses 2026-08-15 01:12:37 +00:00
3b43abc88a operlevels: oper = <name> <pass> <level>; a lower-level oper can't KILL a higher-level one 2026-08-11 18:50:12 +00:00
1dd7f77ca8 operprefix + ojoin: server oper prefix (!/mode y, above owner) auto-granted to opers + OJOIN command 2026-08-10 13:01:07 +00:00
131471e245 modules: move all per-module state/config out of server.rs/config.rs into own files 2026-08-09 11:18:04 +00:00
0d4c9297b5 port whoisport, ircv3_network_icon, profileLink, hidewhois (all config-driven) 2026-08-09 08:33:56 +00:00
f6fbff5270 reputation: full parity port — CIDR ipv4/ipv6 masking, reputationexpire decay rules, whois visibility modes, config-driven db/bump/expire/save/minchanmembers/scorecap (no hardcoding) 2026-08-09 08:28:38 +00:00
eb121a75f8 reputation: full port — y: score extban (y:<N/y:>N), WHOIS score, +2 for accounts, bump interval/scorecap/minchanmembers config; conn_join/conn_umodes/connbanner/operjoin/opermodes/seenicks/chancreate 2026-08-09 08:19:32 +00:00
64dcbd8bf4 securitygroups: UnrealIRCd-style groups + g: extban + SECURITYGROUPS + WHOIS 2026-08-09 08:08:06 +00:00
d4ce5c008f connflood: refuse connection floods from a single IP 2026-08-09 01:28:09 +00:00
f4c01e1bf8 OPERMOTD, self-service VHOST, and command aliases (config-driven) 2026-08-09 01:19:24 +00:00
045e7d3ee7 Revert "ircv3 STS: advertise sts= (port on plaintext, duration/preload on tls) — the modern tls-upgrade cap"
This reverts commit e0b22a34d0.
2026-08-08 21:51:06 +00:00
6cf9f01ff8 ircv3 STS: advertise sts= (port on plaintext, duration/preload on tls) — the modern tls-upgrade cap 2026-08-08 21:48:05 +00:00
49a1bf08b9 webirc: restrict a gateway password to a source ip-mask; document webirc in the example config 2026-08-08 20:02:22 +00:00
81e9728cfa webirc: trusted web gateways can set the real client host/ip (webirc config blocks) 2026-08-08 19:42:10 +00:00
8d31feb4e7 sasl relay over s2s: authenticate plain forwarded to services (sasl_server), 900/903 on success; fails clean with no services 2026-08-08 19:28:53 +00:00
e736188378 dnsbl on connect (m_dnsbl-style, ipv4+ipv6, own module), cache + parallelize resolver, group connect notices before cap 2026-08-08 02:26:02 +00:00
fceafa8064 move rehash to its own coremod; reload-safe rehash (keeps running config on read failure) + snotice + servermask 2026-08-08 00:16:34 +00:00
dbdeb97392 configurable resolved hostname in the hostmask (use_resolved_host) 2026-08-08 00:09:28 +00:00
4fc26d13e9 reverse-dns clients on connect with pre-registration notices (checking ident / looking up your hostname) 2026-08-07 18:39:03 +00:00
9b12791774 import echoircd — from-scratch irc daemon in native rust 2026-08-05 16:10:31 +00:00