OperServ: DEFCON network defence levels
DEFCON [1-5] reads or sets a network-wide defence posture, each level
adding a restriction the engine and services enforce:
- 4: channel registrations frozen (ChanServ REGISTER)
- 3: all registrations frozen (the pre_register_check choke-point, covering
NickServ and the IRCv3 relay, plus channels)
- 2: sessions additionally capped to one per host
- 1: full lockdown — new connections are turned away on connect
Setting a level announces it to the whole network. Node-local level on the
db so services can read the derived freezes; admin-only.
This commit is contained in:
parent
85d01b3ebf
commit
4c899d80b0
6 changed files with 165 additions and 4 deletions
40
operserv/src/defcon.rs
Normal file
40
operserv/src/defcon.rs
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
use fedserv_api::{Priv, Sender, ServiceCtx, Store};
|
||||
|
||||
// DEFCON [1-5]: read or set the network defence level. 5 is normal; each lower
|
||||
// level adds a restriction — 4 freezes channel registrations, 3 freezes all
|
||||
// registrations, 2 also caps everyone to one session, 1 is a full lockdown that
|
||||
// turns away new connections. Changing it announces the level to the network.
|
||||
// Admin-only.
|
||||
pub fn handle(me: &str, from: &Sender, args: &[&str], ctx: &mut ServiceCtx, db: &mut dyn Store) {
|
||||
if !from.privs.has(Priv::Admin) {
|
||||
ctx.notice(me, from.uid, "Access denied — DEFCON needs the \x02admin\x02 privilege.");
|
||||
return;
|
||||
}
|
||||
match args.get(1) {
|
||||
None => ctx.notice(me, from.uid, format!("The network is at \x02DEFCON {}\x02 — {}.", db.defcon(), describe(db.defcon()))),
|
||||
Some(&arg) => match arg.parse::<u8>() {
|
||||
Ok(level) if (1..=5).contains(&level) => {
|
||||
db.set_defcon(level);
|
||||
ctx.notice(me, from.uid, format!("DEFCON set to \x02{level}\x02 — {}.", describe(level)));
|
||||
// Let everyone know the posture changed.
|
||||
let msg = if level == 5 {
|
||||
"The network is back to normal operations (DEFCON 5).".to_string()
|
||||
} else {
|
||||
format!("Network defence level is now \x02DEFCON {level}\x02: {}.", describe(level))
|
||||
};
|
||||
ctx.global(me, msg);
|
||||
}
|
||||
_ => ctx.notice(me, from.uid, "Syntax: DEFCON [1-5] (5 = normal, 1 = lockdown)"),
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
fn describe(level: u8) -> &'static str {
|
||||
match level {
|
||||
5 => "normal operations",
|
||||
4 => "channel registrations frozen",
|
||||
3 => "all registrations frozen",
|
||||
2 => "registrations frozen and sessions capped to one per host",
|
||||
_ => "full lockdown, no new connections",
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue