|
|
5c286a94cb
|
conn_waitpong: exempt loopback (per ipv4/ipv6) and per-class from the registration ping cookie
|
2026-08-22 23:49:46 +00:00 |
|
|
|
4357a59c7a
|
filter: pluggable pattern engine (glob|regex) selected by filter_engine config; regex/glob backends behind a Matcher trait
|
2026-08-22 17:36:46 +00:00 |
|
|
|
ddb6214b47
|
chanlog: post log lines as a channel PRIVMSG from the server, not a NOTICE
|
2026-08-21 17:41:00 +00:00 |
|
|
|
b8e24e2071
|
chanlog: filter each log channel by snomask category; repeatable so different snomasks route to different channels
|
2026-08-21 17:11:27 +00:00 |
|
|
|
3ad67c6b52
|
xline: broadcast the XLINE notice on remove and expire too, so it covers every x-line's whole lifecycle
|
2026-08-21 15:03:36 +00:00 |
|
|
|
b693c5e5df
|
dnsbl: per-zone name/action/duration/reason with %ip%; XLINE notice shows duration + absolute expiry
|
2026-08-21 14:14:17 +00:00 |
|
|
|
1824af5d90
|
signore: persist per-account via services metadata — push on edit, replay on login
|
2026-08-20 15:40:19 +00:00 |
|
|
|
2c9ce18cd7
|
whois: render the oper-type title line in bold + colour (per-type color=<name|0-15|none>, default red) so it stands out
|
2026-08-20 14:26:17 +00:00 |
|
|
|
5a9825ee61
|
comments: strip stray reference-implementation names from a handful of module/inline comments
|
2026-08-20 10:11:07 +00:00 |
|
|
|
01516d5fdc
|
opertypes: oper classes + types — reusable capability classes and named roles (WHOIS title, auto usermodes/snomasks/vhost + level on oper-up, per-type command enforcement via on_pre_command); ships 5 built-in (helpop/globop/admin/servadmin/netadmin); oper blocks gain type=<id>; a typeless oper keeps full access
|
2026-08-20 10:05:11 +00:00 |
|
|
|
78a6574d64
|
hardening: bracket a bare IPv6 nameserver literal (was unparseable -> rDNS/DNSBL silently degraded on v6-only hosts); saturating chunk-size advance in the RPC dechunker (a 16-hex-digit size could overflow-panic the worker); connclass hash= is now last-wins to match password= under parent= inheritance
|
2026-08-19 04:45:07 +00:00 |
|
|
|
1a5c41871c
|
password_hash: reject an empty PBKDF2 hash/salt — a stored 'pbkdf2:iters:salt:' (empty hash) made ct_eq(&[],&[]) return true, verifying ANY password; refuse empty want/salt before computing
|
2026-08-19 04:45:07 +00:00 |
|
|
|
1aa02a08b9
|
channels: replace Member's six parallel prefix bools (oprefix/owner/admin/op/halfop/voice) with a single u8 bitfield (PFX_*) + inline bool accessors/mutators — same semantics, one byte instead of six, no more risk of the flags drifting out of sync; all call sites go through op()/set_op()-style methods
|
2026-08-19 02:47:04 +00:00 |
|
|
|
ab0ccae71f
|
server: scrub a departed user's pending invites via a User.invited reverse index instead of scanning every channel on the network per quit — the old O(channels)-per-quit path was O(channels*quits) on a netsplit; the index is maintained at the 4 invite add/remove sites (INVITE cmd, S2S INVITE, join-consume, UNINVITE)
|
2026-08-19 02:09:36 +00:00 |
|
|
|
ea3e879068
|
connclass: cache resolved connect classes in a config_gen-tagged thread_local — all()/named() (and thus pick/assign and every per-ping/per-message getter) re-parsed the connectclass config and re-resolved parent inheritance on each call; now rebuilt only on rehash
|
2026-08-19 01:56:22 +00:00 |
|
|
|
d4d3886379
|
restrictcommands: cache the parsed restriction list (config_gen-tagged) instead of re-tokenizing every restrictcommand line on every command; clone only the one matched rule so the ext borrow drops before the server is used mutably
|
2026-08-19 01:54:45 +00:00 |
|
|
|
cd46cfc49f
|
securitygroups: cache parsed groups in a config_gen-tagged thread_local instead of re-parsing all securitygroup lines on every g: extban match and WHOIS — safe on the single-threaded core, re-parses only on rehash
|
2026-08-19 01:53:41 +00:00 |
|
|
|
1da913a249
|
autodrop: cache the autodrop-command set (config_gen-tagged) instead of re-splitting autodrop_commands on every packet from an unregistered socket — the path runs hottest under the scanner flood it defends against
|
2026-08-19 01:51:57 +00:00 |
|
|
|
09b4adabbf
|
disable: cache the disabled-command set (config_gen-tagged HashSet) instead of re-splitting disabled_commands on every non-oper command — the hottest hook in the server; re-parses only on rehash
|
2026-08-19 01:51:31 +00:00 |
|
|
|
98e5cf4d20
|
relaymsg/showfile: reject whitespace/control chars in a RELAYMSG spoofed nick (defence-in-depth on top of the denylist), and cap the showfile read at 256 KiB so a large /RULES-style file can't stall the core loop
|
2026-08-19 01:35:25 +00:00 |
|
|
|
c47fb9a80a
|
syslog: keep the UDP socket cached across send errors instead of dropping it (which re-bound + re-resolved a socket on every notice when the target was unreachable); the Unix datagram path still reopens on failure
|
2026-08-19 01:34:24 +00:00 |
|
|
|
b3f66ec310
|
customtitle: return Fail (not Ok) when the crypto pool is at capacity and the TITLE auth is denied, matching the synchronous verify path
|
2026-08-19 01:33:34 +00:00 |
|
|
|
55174ec017
|
profilelink/hidelist: unify the WHOIS label to English "Profile:" (was "Profil:" for logged-in users) and make hidelist honour the last matching config line (conf last-wins semantics) instead of the first
|
2026-08-19 01:33:05 +00:00 |
|
|
|
303fc0c8dc
|
filehost: use only the final path segment of the URL as the displayed filename tag — the trailing part was taken verbatim (path separators, ../), and while json_esc/escape_tag block injection, a client rendering filename could be misled by traversal; take the basename
|
2026-08-19 01:32:17 +00:00 |
|
|
|
c532828aab
|
jwt: match claim_num only against a top-level object key (depth-aware scan), not any substring — a claim whose string value contained "exp": could otherwise spoof the exp an external verifier reads; added nested + string-value regression tests
|
2026-08-19 01:31:22 +00:00 |
|
|
|
c32fbee905
|
chanlog: fan the mirrored notice via to_channel (Arc-shared line, per-recipient server-time) instead of collecting a members Vec and cloning the String per member
|
2026-08-19 01:29:48 +00:00 |
|
|
|
2851c0a7ab
|
rmode: send a usage NOTICE when the list-mode arg has no mode letter (e.g. RMODE #c 3) instead of failing silently
|
2026-08-19 01:29:14 +00:00 |
|
|
|
b557c9887f
|
log_json: cache an open failure so a misconfigured path doesn't re-issue an open() syscall (and silently drop) on every notice — the error is now surfaced once via stderr and not retried until the path changes; the write-failure reopen (for logrotate) is preserved
|
2026-08-19 01:28:42 +00:00 |
|
|
|
65bedaf417
|
hidemode: resolve each changed mode's hidden-rank once and each member's rank once, instead of re-scanning the hidemode config for every (member x change) pair on the MODE broadcast hot path
|
2026-08-19 01:23:33 +00:00 |
|
|
|
b59fe70537
|
operlevels: use Extensible::set instead of get_or_insert_with(0)-then-overwrite
|
2026-08-19 01:22:54 +00:00 |
|
|
|
8f5b37bf8d
|
dnsbl: cap the number of blocklist zones checked per client at 16 — each zone is a serial blocking DNS lookup, so a long (mis)configured zone list could stall a connecting client's registration for zones.len()*timeout
|
2026-08-19 01:21:40 +00:00 |
|
|
|
b63458816e
|
metrics: set read/write timeouts on each scrape connection — the single-threaded accept loop did an untimed read, so one client that connected and never sent blocked every future scrape (slowloris)
|
2026-08-19 01:21:21 +00:00 |
|
|
|
ac3e66e9e0
|
metadata: prune a channel's metadata once the channel no longer exists (tick GC) — #channel entries were never freed (unlike user entries on quit), so setting metadata on a channel that later empties leaked memory and kept re-persisting to disk forever; +P channels stay live so keep theirs
|
2026-08-19 01:20:23 +00:00 |
|
|
|
a7f6c264d1
|
snoop: gate the per-connect/join/quit eprintln! behind snoop_stderr (default off) — it wrote to stderr (journald) on every client event in the reactor thread, unbounded under a connect flood; the +c/+q snotices already carry the operator-facing signal
|
2026-08-19 01:18:58 +00:00 |
|
|
|
924141683c
|
extbanbanlist: identify extbans by the real rule (<letter>:...) instead of "2nd byte is a colon" — the old heuristic wrongly skipped a plain hostmask whose second char happened to be ':', mis-listing it
|
2026-08-19 01:18:27 +00:00 |
|
|
|
6f9d11f83e
|
captcha: clamp recaptcha/cloudflare token TTL to [60s, 86400s] — an unclamped conf value could set exp in the past (every token instantly invalid, self-DoS) or absurdly far out
|
2026-08-19 01:18:13 +00:00 |
|
|
|
ee3c5e761e
|
geoip: bound recursion + require forward progress in the .mmdb value decoder — value_len/map_get recursed into nested maps/arrays with no depth limit (unlike resolve), so a crafted database could overflow the stack or spin on a zero-advance value; cap nesting at 32 and bail on a malformed (0-length) sub-value
|
2026-08-19 01:17:32 +00:00 |
|
|
|
e200779d27
|
connclass: resolve hash= independently of token order — the fold only ran if password= had already been parsed, so "hash=sha256 password=<hex>" (hash first) stored the digest as a plaintext password and every login to that class failed; build() now combines <algo>:<digest> after the full token pass
|
2026-08-19 01:15:26 +00:00 |
|
|
|
928026c49e
|
permchannels: isolate the load-time mode applier in catch_unwind so a panicking mode handler can't leave mode_sudo stuck true — which would silently disable rank/oper gating for every subsequent MODE; the flag is now always reset
|
2026-08-19 01:14:34 +00:00 |
|
|
|
14eb982db5
|
multiline: reject an over-limit batch with a FAIL instead of silently dropping the overflowing lines — accumulate() dropped a line that exceeded multiline_maxbytes/maxlines but still returned buffered=true, so the client believed a truncated message was sent whole; now overflow flags the batch and close() drops it with a standard FAIL
|
2026-08-19 01:13:39 +00:00 |
|
|
|
83cdce17c5
|
connflood: bound the per-IP connection-history map (prune stale buckets past 65536 tracked IPs) — it only shrank on the tick GC, so a wide source-IP spread could grow it unbounded between ticks (memory DoS)
|
2026-08-19 01:12:39 +00:00 |
|
|
|
a218d65371
|
rpc: authenticate on the header block before buffering the request body — the httpd read up to MAX_REQUEST (256 KiB) and only then checked the Authorization header, so an unauthenticated peer reaching rpc_bind could make each connection consume memory + a worker thread; now POST+auth are validated as soon as headers are complete, before any body is read
|
2026-08-19 01:05:29 +00:00 |
|
|
|
5b33786a46
|
rpc: refuse an all-wildcard x-line via ban.add — the mask went unvalidated, so an authenticated RPC call with "mask":"" or "*@*" installed a K/G/Z-line matching the entire network; require at least one literal host/ip/nick char
|
2026-08-19 01:03:27 +00:00 |
|
|
|
54c2a733fe
|
password_hash: reject a PBKDF2 credential with an absurd iteration count (>10M) instead of running it — the count is read straight from the stored string, so a corrupt/hostile credential (e.g. via a compromised accounts backend) could pin a worker thread for a very long time; legitimate work factors are far below the cap
|
2026-08-19 01:02:36 +00:00 |
|
|
|
35bb901455
|
whoisport: report the port the user actually connected to (User.port, set at accept) instead of conf("bind")/conf("bind_tls") — those are Vec-valued so conf() returned only the LAST configured listener, giving every user the same wrong port on a multi-listener server
|
2026-08-19 00:43:03 +00:00 |
|
|
|
25702c9541
|
syslog: strip control chars (CR/LF) from the message before framing — a snotice carrying user-influenced text (nick/realname/quit reason) with an embedded newline could inject a forged syslog record; matches the CR/LF care the JSON log path already takes
|
2026-08-19 00:42:30 +00:00 |
|
|
|
d9d5bd069b
|
filehost: refuse to sign upload tokens when filehost_jwt_secret is unset/empty/"changeme" — the default fell open, signing with a world-known key so anyone could forge a server-trusted upload authorization; now it fails closed and tells the user to fix the config
|
2026-08-19 00:42:10 +00:00 |
|
|
|
a09dfc74df
|
auth: constant-time compare for VHOST and WEBIRC secrets — both used plain == on the config password, unlike oper/RPC/JWT secrets which already route through ct_eq; expose password_hash::ct_eq as the shared comparator and use it (usernames stay plain == — not secret)
|
2026-08-19 00:41:47 +00:00 |
|
|
|
bbe4ee4567
|
http: bound spawn_http concurrency (http_max_concurrent, default 32) like spawn_crypto — it spawned one unbounded OS thread per call, so a pre-auth VERIFY/REGISTER flood could exhaust threads and hammer the accounts backend; at capacity the command now fails with TEMPORARILY_UNAVAILABLE instead
|
2026-08-19 00:39:01 +00:00 |
|
|
|
6682227f81
|
denychans: bound redirect recursion — a badchan redirect re-enters Server::join (which re-runs denychans), so a redirect loop (#a->#b->#a) or a redirect into a broad badchan glob recursed until the single-threaded daemon stack-overflowed from one JOIN; cap the chain at 8 hops via a RedirDepth guard in ext
|
2026-08-19 00:36:29 +00:00 |
|