Commit graph

310 commits

Author SHA1 Message Date
99df7baf10
engine: apply gossiped network bans to the ircd immediately
All checks were successful
CI / check (push) Successful in 3m47s
A local AKILL/SQLINE/etc. pushes an ADDLINE to the ircd at once, but a ban
arriving by gossip was only held for the next netburst — so a user banned on
one network could keep hopping to peers until their next relink. ingest now
signals BanAdded/BanLifted (all xline kinds), and gossip_ingest pushes the
ADDLINE/DELLINE. Renamed AccountChange to IngestEffect to match its broader
role.
2026-07-16 09:28:56 +00:00
886fe65e4d
engine: log out local sessions on a gossiped account suspension
All checks were successful
CI / check (push) Successful in 3m43s
A local SUSPEND logs out the account's active sessions, but a suspension
arriving by gossip only set the flag — a session already identified on a
remote node stayed logged in despite the network-wide suspension. ingest
now signals AccountChange::Suspended, and gossip_ingest ends those sessions
(the account and its channels are kept). Factors the per-session logout into
a shared logout_uid helper.
2026-07-16 09:13:53 +00:00
58af1187fc
engine: part orphaned-channel bots on a gossiped account removal
All checks were successful
CI / check (push) Successful in 3m46s
When a peer's gossiped entry drops or takes over an account, the local node
releases the channels that account founded locally (Local-scope channels can
be founded by a Global, gossiped account). That cleanup runs outside the
dispatch path, so a bot assigned to a released channel lingered until the
next netburst. gossip_ingest now reconciles bots after an account is removed,
matching the expiry sweep.
2026-07-16 08:57:38 +00:00
bbea17e848
engine: part a bot when its channel expires
All checks were successful
CI / check (push) Successful in 3m47s
Command-driven channel drops reconcile bots via the dispatch path, but the
inactivity-expiry sweep runs outside it — so a bot assigned to an expired
(or expired-founder-orphaned) channel lingered there until the next
netburst. The sweep now reconciles at the end, parting any stranded bot.
2026-07-16 08:27:59 +00:00
fa55bc3e3a
db: purge all references to a dropped account
All checks were successful
CI / check (push) Successful in 3m45s
Dropping (or expiring) an account left its channel access, channel
successorship, and group membership/foundership behind, keyed by name — so
re-registering the same nick silently inherited the old privileges. The
AccountDropped fold and the live drop_account path now share one helper
that erases every reference (founder channels are still handled by
handle_account_gone's successor transfer). Closes a privilege-inheritance
hole; especially relevant to inactivity expiry.
2026-07-16 03:51:01 +00:00
dc23a44f57
engine: apply auto-join, vhost and memo notice on SASL connect
All checks were successful
CI / check (push) Successful in 3m44s
A user authenticated via SASL during registration never runs the NickServ
IDENTIFY path, so they silently missed their auto-join channels, vhost, and
waiting-memo notice. The UserConnect handler now applies these login
side-effects when the arriving user is already authenticated, mirroring
identify.rs. Non-SASL connections are unaffected (no account set yet).
2026-07-16 03:35:32 +00:00
dabb18abd4
HostServ: re-check the forbidden list when activating a vhost request
REQUEST rejected a forbidden host, but ACTIVATE never re-checked, so a
pattern forbidden after a request was filed was granted on approval. The
activate path now re-reads the forbidden list. Operator SET stays an
intentional override (unchanged), so the check lives in approve, not the
shared prepare_vhost.
2026-07-16 03:25:27 +00:00
b749cd2969
OperServ: enforce FORBID EMAIL at registration and SET EMAIL
FORBID accepted and stored EMAIL patterns, but nothing ever checked them:
a forbidden address still registered and could be set via NickServ SET
EMAIL. Both paths now reject a matching address (new ForbiddenEmail
outcome), matching how NICK and CHAN forbids already gate registration.
2026-07-16 03:11:57 +00:00
01ea0fa95e
ChanServ: add SET EMAIL channel contact address
Founders can attach a contact email to a channel, shown in INFO and
cleared when set empty. Mirrors SET URL exactly; Local-scope channel
metadata. Completes the channel DESC/URL/EMAIL trio.
2026-07-16 03:06:08 +00:00
7eb1adce5e
ChanServ: add SET URL channel homepage
Founders can attach a homepage URL to a channel; it shows in INFO and
clears when set empty, mirroring SET DESC. Local-scope (channel metadata),
not gossiped, consistent with the entrymsg/description events.
2026-07-16 02:58:44 +00:00
053f8cf832
NickServ: add SET HIDE STATUS for last-seen privacy
Lets an account keep its last-seen/online line in INFO visible only to
itself and to opers. Default stays public (Anope's default). Accepts
STATUS (with USERMASK as an alias) per Anope's SET HIDE <field> grammar.
2026-07-16 02:33:55 +00:00
39d7421c06
NickServ: show last-seen (and online status) in INFO
The account's last-active time was tracked but never surfaced. INFO now
reports it, reading 'now (online)' when the account has a live session.
Threads NetView into the INFO handler for the session lookup and carries
last_seen on AccountView.
2026-07-16 01:56:51 +00:00
2c4bc9079c
NickServ: add SET KILL to toggle nick protection
Nick protection was unconditional. SET KILL OFF lets an account opt out —
an unidentified user keeping one of its nicks is no longer prompted or
renamed to a guest. Stored inverted (no_protect) so protection stays the
default. Accepts Anope's ON/QUICK/IMMED/OFF; grace is a fixed interval
here, so the finer variants simply enable protection like ON.
2026-07-16 01:43:10 +00:00
87e21ff85f
NickServ: add SET AUTOOP per-account auto-op opt-out
A user with SET AUTOOP OFF is never auto-opped on join, even where they
hold channel access — they op themselves via ChanServ UP. Stored inverted
(no_autoop) so the default stays auto-op. Join gates on both the channel
setting and the account preference; either can opt out.
2026-07-16 01:37:31 +00:00
0027decdb7
OperServ: add SET READONLY lockdown
All checks were successful
CI / check (push) Successful in 3m31s
2026-07-16 01:05:48 +00:00
b2442f85e6
OperServ: add SHUTDOWN and RESTART
All checks were successful
CI / check (push) Successful in 3m31s
2026-07-16 01:02:10 +00:00
dd43b9a331
BotServ: add BOTLIST and AUTOASSIGN default bot
All checks were successful
CI / check (push) Successful in 3m33s
2026-07-16 00:57:06 +00:00
cd6d8b1b93
ChanServ: add SYNC as an alias for ENFORCE
All checks were successful
CI / check (push) Successful in 3m33s
2026-07-16 00:50:42 +00:00
961dc870da
MemoServ: add STAFF to memo all operators
Some checks failed
CI / check (push) Has been cancelled
2026-07-16 00:48:50 +00:00
c646ccc0ec
NickServ: add SASET for operator account edits
Some checks failed
CI / check (push) Has been cancelled
2026-07-16 00:45:18 +00:00
d819b2c75f
MemoServ: add RSEND read receipts
Some checks failed
CI / check (push) Has been cancelled
2026-07-16 00:43:01 +00:00
2850620be1
ChanServ: add SET AUTOOP
All checks were successful
CI / check (push) Successful in 3m35s
SET AUTOOP {ON|OFF} controls whether access members are auto-opped/voiced
on join (on by default). Stored inverted as a settings flag so the
default stays on, and gated in the join handler.
2026-07-16 00:36:19 +00:00
2c282d036f
MemoServ: add SET NOTIFY and SET LIMIT
All checks were successful
CI / check (push) Successful in 3m35s
SET NOTIFY {ON|OFF} controls whether you're told about new memos on login;
SET LIMIT <n>|NONE sets your mailbox cap (honoured on SEND, NONE = the
network default). New memo_notify/memo_limit account fields + one
MemoPrefsSet event.
2026-07-16 00:29:33 +00:00
125b8c7701
NickServ: RECOVER regains your nick
All checks were successful
CI / check (push) Successful in 3m41s
Split RECOVER from GHOST: GHOST just frees a session off a nick you own,
while RECOVER also puts you back onto it (frees the ghost if present, then
SVSNICKs you to the nick). RECOVER works on an already-free nick too.
2026-07-16 00:21:07 +00:00
b5e08c33cf
MemoServ: add IGNORE
All checks were successful
CI / check (push) Successful in 3m34s
IGNORE ADD/DEL/LIST manages a per-account memo-ignore list; a memo from
an ignored account is silently dropped, and the sender is still told it
was sent so the ignore isn't revealed. New memo_ignore account field +
events, and a check in SEND.
2026-07-16 00:10:34 +00:00
ccbbb91fda
OperServ: add SVSPART
All checks were successful
CI / check (push) Successful in 3m36s
SVSPART <nick> <#channel> [reason] forces a user out of a channel
(admin-only), completing the SVS command family alongside SVSNICK and
SVSJOIN. New ForcePart action rendered as the ircd SVSPART command.
2026-07-16 00:00:18 +00:00
53d3d63464
NickServ GETEMAIL + ChanServ SET RESTRICTED
All checks were successful
CI / check (push) Successful in 3m51s
GETEMAIL (auspex) lists accounts whose email matches a glob. SET
RESTRICTED makes a channel kick anyone without access (or oper) as they
join, mirroring the SECUREOPS on-join enforcement.
2026-07-15 19:25:41 +00:00
be4860c9a8
OperServ: add FORBID (nick/channel/email registration bans)
All checks were successful
CI / check (push) Successful in 3m56s
FORBID ADD/DEL/LIST bans a NICK, CHAN, or EMAIL glob from being
registered — a network-wide policy that gossips like an AKILL and every
node enforces. Nick registration is blocked in pre_register_check (both
NickServ REGISTER and the account-registration relay), and channel
registration in ChanServ REGISTER. New Forbid store + events, mirroring
the akill subsystem.
2026-07-15 19:14:07 +00:00
ac50af92fc
ChanServ: add SET SUCCESSOR with founder inheritance
All checks were successful
CI / check (push) Successful in 3m59s
SET <#channel> SUCCESSOR <account>|OFF names an account that inherits the
channel if the founder's account is dropped or expires, instead of the
channel being released. Adds a ChannelInfo.successor field + event, and
centralises the founder-gone channel release into a single
release_founded_channels store method used by DROP, expiry, and the
gossip account-gone path so all three transfer consistently.
2026-07-15 18:58:08 +00:00
6e3a758cc1
ChanServ: add OWNER/PROTECT/HALFOP status commands
All checks were successful
CI / check (push) Successful in 3m47s
OWNER/DEOWNER (+q), PROTECT/DEPROTECT (+a, alias ADMIN), and
HALFOP/DEHALFOP (+h) set the higher channel-status modes. They reuse the
OP handler's target resolution and PEACE check; OWNER is founder-only,
the rest need op access.
2026-07-15 18:40:19 +00:00
30e91bb295
MemoServ SENDALL + ChanServ AKICK CLEAR
All checks were successful
CI / check (push) Successful in 3m46s
SENDALL (admin) leaves a memo on every registered account for a
network-wide announcement that persists until read. AKICK CLEAR empties a
channel's auto-kick list in one command.
2026-07-15 18:32:46 +00:00
21efbd32c1
NickServ: add UPDATE and LIST
All checks were successful
CI / check (push) Successful in 3m46s
UPDATE re-applies your auto-joins and vhost and re-checks for waiting
memos without re-identifying. LIST (auspex-gated) shows registered
accounts matching a glob, capped at 100. Adds an accounts_matching store
method.
2026-07-15 18:24:52 +00:00
959d085e7a
ChanServ: add UP and DOWN
All checks were successful
CI / check (push) Successful in 3m47s
UP re-applies the op/voice status your channel access entitles you to;
DOWN removes your status. Mirrors the OP/VOICE command's access check and
mode emission, and requires you to actually be in the channel.
2026-07-15 18:14:39 +00:00
98ecbca414
MemoServ: add CANCEL, CHECK, and INFO
All checks were successful
CI / check (push) Successful in 3m49s
CANCEL recalls the sender's most recent unread memo to a target (one the
recipient already read can't be recalled); CHECK reports whether the last
memo you sent someone has been read; INFO summarises your mailbox. Adds
memo_cancel/memo_check store methods and shares MAX_MEMOS from the module
root instead of duplicating it in send.rs.
2026-07-15 18:09:33 +00:00
a26ee722d1
Add nick-protection enforcement: prompt then rename an unidentified user on a registered nick
All checks were successful
CI / check (push) Successful in 3m51s
On connect or nick-change to a registered nick the user isn't identified
to, NickServ prompts them to IDENTIFY and schedules a rename; a short
enforcement sweep renames them to a guest nick after a grace period if
they still haven't. Gated on the uplink's initial burst so a relink does
not enforce every already-online user, and cancelled the moment they
identify (via IDENTIFY or SASL) or leave the nick.
2026-07-15 17:41:33 +00:00
54ad013e49
Wire account registration to the ircd's ENCAP SWACCTREG/SWACCTRES relay
All checks were successful
CI / check (push) Successful in 3m53s
Echo is the authority the ircd account module forwards to: parse
ENCAP <us> SWACCTREG <reqid> <origin> <kind> <account> <p2> :<p3> into an
account request, and answer the origin server with
ENCAP <origin> SWACCTRES <reqid> <kind> <account> <status> <code> :<message>.
Thread the origin through the reply so responses route back to the
requesting server. Replaces the placeholder ACCTREGISTER/ACCTREGRESULT
names that nothing on the wire actually spoke.
2026-07-15 16:34:20 +00:00
994e8c7347
Make the SCRAM verifier the sole password credential; finish the account-registration relay
All checks were successful
CI / check (push) Successful in 4m1s
Credentials: the SCRAM-SHA-256 verifier is now the only password
credential. PLAIN and IDENTIFY verify the plaintext against it via
scram::verify_plain, exactly as a SCRAM login proves knowledge of it, so
an account provisioned from a verifier alone (external authority) works
over every mechanism, not only SCRAM. Removed the redundant argon2 hash
entirely: the field, the Credentials member, the AccountPasswordSet
field, hash_password/verify_password, and the argon2 crate. SASL SCRAM
already forces a PBKDF2 verifier into the store, so the hash never raised
the at-rest floor. OS RNG now comes from rand_core.

Registration: finished draft/account-registration over the ircd relay.
VERIFY confirms the emailed code, RESEND reissues it, STATUS reports
state, and REGISTER now emails the code and replies verification_required
on the relay path too, not only through NickServ.
2026-07-15 15:47:41 +00:00
9ed40a2e7f
License (AGPL-3.0) and graceful shutdown
All checks were successful
CI / check (push) Successful in 3m48s
Add the AGPL-3.0 license (matching Orbit) and set it in Cargo.toml so
the crate metadata is complete. Handle SIGTERM/Ctrl-C: the run loop now
selects against a shutdown signal and exits cleanly, so systemctl stop
returns promptly instead of waiting out the kill timeout (every event is
already fsync'd, so nothing is lost either way). Verified: on SIGTERM the
daemon logs and exits 0.
2026-07-15 12:05:39 +00:00
e551a01cbf
Harden for production: fsync writes, deployment + backup tooling
All checks were successful
CI / check (push) Successful in 3m55s
The event log is the account/channel authority, so make it durable:
persist() now fsyncs every committed event before reporting success, and
a serialisation failure is an error instead of a silently-dropped blank
line. Add a hardened systemd unit (scripts/echo.service), an atomic
gzip backup script with retention (scripts/backup.sh), and a Deployment
wiki page (install, durability, backup/restore, upgrade, monitoring).
2026-07-15 11:45:50 +00:00
7d1edefb70
CI: install cmake for aws-lc-sys (rustls crypto backend)
All checks were successful
CI / check (push) Successful in 3m54s
rustls 0.23 pulls aws-lc-sys, which compiles AWS-LC via cmake; the node
image has gcc/make but not cmake, so add it (plus clang) before the
build.
2026-07-15 00:12:57 +00:00
23fac5eb39
Vendor protoc so the build needs no system protobuf compiler
Some checks failed
CI / check (push) Has been cancelled
The gRPC build script required a system protoc, which a fresh clone and
the CI container lack (build failed with 'Could not find protoc'). Set
PROTOC from protoc-bin-vendored in build.rs (unless one is already set),
so cargo build works out of the box everywhere.
2026-07-15 00:11:26 +00:00
2994cbbfea
CI: run on a Node image and install Rust on top
Some checks failed
CI / check (push) Failing after 1m30s
actions/checkout is a Node action and the rust:* container has no node,
so its post-step failed with 'node: not found'. Use node:20-bookworm
(node present for checkout) and install Rust via rustup, running build,
clippy, and test in one shell.
2026-07-15 00:04:44 +00:00
0ed6684522
Validate config on load; document the SDK's core traits
Some checks failed
CI / check (push) Failing after 53s
Config::load now checks the SID is 3 alphanumeric chars and that
server.name and uplink.host are set, failing with a clear message
instead of a cryptic link-time error. Give the Service and Protocol
traits and ServiceCtx proper rustdoc so cargo doc is useful to module
authors.
2026-07-14 23:31:44 +00:00
955e55d47f
Add per-service integration tests
The service crates had almost no tests. Exercise each one's core path
through a real Engine: MemoServ delivery, GroupServ register/add,
ReportServ file/close, InfoServ post (admin-gated), HostServ
request/activate, OperServ akill add/remove, BotServ bot add (oper),
StatServ SERVER gating, and ChanFix/DiceServ basics. +9 tests.
2026-07-14 23:28:08 +00:00
d9c0878b00
Log store write failures at the source; share the oper guard
The store's map_err(|_| Internal) discarded the real IO error, so a
disk-full or permissions failure was invisible; log it once in the log
append path where it happens. Add echo_api::require_oper (parameterised
by the required privilege) and route the three copied per-service guards
through it, keeping each service's own wording and policy.
2026-07-14 23:19:00 +00:00
081d90ad68
Add CI: build, clippy (-D warnings), and test on push
Push-to-deploy had no automated gate. This Forgejo Actions workflow
builds the workspace, runs clippy as an error gate, and runs the tests
on every push and PR. Adjust runs-on to match the runner's label.
2026-07-14 23:14:52 +00:00
fcca8e4e3b
Front the whole network's help through HelpServ
Each service now exposes its help catalog via Service::help_topics; the
engine collects them into a network-wide index on Network, reachable
through two new NetView methods. HelpServ uses it: HELP <service>
[command] (or a bare service name) serves any service's per-command
help, bare HELP lists the services, and its own ticket commands still
work. No cross-crate dependency: the catalog flows through the SDK's
NetView, keeping every module dependent only on echo-api.
2026-07-14 18:37:45 +00:00
69a93198ff
Wire centralized HELP into the remaining services
ChanServ, BotServ, HostServ, MemoServ, OperServ, and StatServ now route
HELP through the shared renderer with per-command topic tables, so every
service supports HELP <command>. The renderer matches slash-grouped
names (OP/DEOP/VOICE/DEVOICE) so a paired command resolves as one topic.
Adds unit tests for the renderer.
2026-07-14 17:23:40 +00:00
c9e392630b
Add centralized HELP with per-command subcommands
New echo-api primitive: a HelpEntry table plus a shared help() renderer.
HELP lists a service's commands; HELP <command> prints that command's
detail. Every service routes its HELP arm through the one renderer, so
the shape is identical across the network. Wired into NickServ and the
six newer services so far.
2026-07-14 17:12:14 +00:00
973d2826de
Rework the README and move the guides to the wiki
Turn the README into a lean landing page: what Echo is, highlights, a
quick start, the service suite, a three-layer architecture summary, and
links into the wiki for the detail. The extended docs (architecture,
federation, services, configuration, the directory API, and the
module-writing guide) now live as wiki pages, so MODULES.md is retired.
2026-07-14 16:15:28 +00:00