|
|
2aaa5ac091
|
deploy: persistent systemd unit running a pinned release binary with Restart=on-failure + boot enable, plus a liveness timer that restarts the daemon if a register round-trip stops answering
|
2026-08-12 16:01:58 +00:00 |
|
|
|
b022189fa5
|
core: write persisted snapshots atomically (temp + rename) so a crash mid-write can't leave a truncated reputation/metadata/xline file
|
2026-08-12 15:57:43 +00:00 |
|
|
|
859450fb6c
|
tests: add end-to-end integration suite (spawns the binary on ephemeral ports; kills by PID, never by name) covering reactor-pool cross-worker delivery, TLS-in-reactor handshake + cross-transport + secure marker, stalled-handshake reap, and nick collision
|
2026-08-12 15:56:42 +00:00 |
|
|
|
d8d57511ab
|
tls: send a close_notify on close for established TLS sessions instead of just dropping the socket, so clients see a clean shutdown not a truncation error
|
2026-08-12 15:53:10 +00:00 |
|
|
|
59e18b0205
|
socketengine: reap TLS conns that stall mid-handshake (tls_handshake_timeout, default 15s) — a connection that opens the TLS port but never negotiates no longer leaks a slot
|
2026-08-12 15:51:45 +00:00 |
|
|
|
e74763619b
|
docs: document the io_threads reactor-pool knob in the example config
|
2026-08-12 14:03:24 +00:00 |
|
|
|
02ae92e16d
|
socketengine: run direct TLS in the reactor pool — non-blocking handshake + crypto in the worker threads (Sock::Tls, TlsSession), unifying the client I/O model and spreading TLS work across cores; proxied TLS + links keep the thread path
|
2026-08-12 14:03:00 +00:00 |
|
|
|
7c166e3aae
|
socketengine: plaintext reactor pool — an acceptor round-robins connections across N worker reactors (io_threads, auto=cores) feeding the single lock-free core, so per-connection I/O scales across cores
|
2026-08-12 13:42:08 +00:00 |
|
|
|
4ba8d5bce6
|
xline: persist server bans via the off-core disk writer too, so a KLINE/GLINE burst can't stall the event loop on a slow disk
|
2026-08-12 13:20:16 +00:00 |
|
|
|
e91b64a4db
|
resilience: isolate per-connection panics in the plaintext reactor (catch_unwind read/write -> drop just that conn) and log worker-thread panics instead of vanishing silently
|
2026-08-12 13:19:25 +00:00 |
|
|
|
145a01b2c2
|
core: Server::disk_write — coalescing off-core snapshot writer; reputation/metadata saves no longer block the event loop on a slow disk
|
2026-08-12 13:16:15 +00:00 |
|
|
|
c231c6b8ef
|
connclass: verify a KDF class password off the core thread with a registration hold (auth_pending + Event::ConnclassAuth) — connect floods can't freeze the server
|
2026-08-12 13:13:27 +00:00 |
|
|
|
2b3495be65
|
customtitle: verify a KDF /TITLE password off the core thread (Event::TitleAuth) — /TITLE spam can't freeze the server
|
2026-08-12 13:07:28 +00:00 |
|
|
|
7cb58586b4
|
core: generic spawn_crypto helper; offload all slow KDF hashing (OPER pbkdf2 too, and MKPASSWD) off the core thread
|
2026-08-12 13:05:29 +00:00 |
|
|
|
e246699fef
|
oper: verify bcrypt passwords on a worker thread (Event::OperAuth), bounded — a bcrypt OPER no longer freezes the core, closing the OPER-spam DoS; fast hashes stay inline
|
2026-08-12 12:46:52 +00:00 |
|
|
|
6795243d5f
|
core: slow-command snotice (slow_command_ms) + a watchdog thread (watchdog_ms) so a blocked core thread is visible instead of a silent freeze
|
2026-08-12 12:43:41 +00:00 |
|
|
|
8309b851f2
|
core: wrap each event handler in catch_unwind so one panicking command can't take the whole single-threaded server down
|
2026-08-12 12:41:16 +00:00 |
|
|
|
b40c523b87
|
customprefix: data-driven prefix engine — define arbitrary new prefix modes (letter/prefix/rank/ranktoset/ranktounset/depriv), ranks re-spaced x10; built-in tiers + defaults unchanged
|
2026-08-11 19:46:07 +00:00 |
|
|
|
d35a2071a6
|
docs: document abbreviation + customprefix in the config example
|
2026-08-11 19:21:17 +00:00 |
|
|
|
9f3081cb38
|
customprefix: add ranktoset/ranktounset/depriv per tier (InspIRCd change= parity for existing prefixes)
|
2026-08-11 19:20:27 +00:00 |
|
|
|
749a1c3b69
|
customprefix: config-override channel-prefix sigils per tier (customprefix = <tier> <sigil>); PREFIX/NAMES/FJOIN consistent
|
2026-08-11 19:01:45 +00:00 |
|
|
|
b4186ae08d
|
namedmodes: PROP command sets/queries channel modes by long name (op, moderated, limit, ...)
|
2026-08-11 18:55:14 +00:00 |
|
|
|
3b43abc88a
|
operlevels: oper = <name> <pass> <level>; a lower-level oper can't KILL a higher-level one
|
2026-08-11 18:50:12 +00:00 |
|
|
|
3b2f30965a
|
abbreviation: a unique command-prefix resolves to its full command (abbreviation = yes)
|
2026-08-11 18:46:16 +00:00 |
|
|
|
72ca89af26
|
log_json: append the server-notice/log stream to a file as JSONL (log_json = <path>)
|
2026-08-11 18:44:48 +00:00 |
|
|
|
6ffd6a57bc
|
proxy: forward v2 TLS TLVs (PP2_TYPE_SSL/CERTFP) so plaintext clients behind a TLS-terminating proxy show secure+certfp; restore ws_trust_proxy to the config example
|
2026-08-11 17:13:32 +00:00 |
|
|
|
4f6c0ded48
|
websocket: add ws_defaultmode (text/binary/reject), ws_proxyranges (glob/CIDR X-Real-IP/XFF trust), ws_allowmissingorigin, ws_nativeping
|
2026-08-11 16:10:09 +00:00 |
|
|
|
87a683dbd2
|
proxy: HAProxy PROXY protocol v1+v2 on the plaintext (reactor) and TLS listeners; trusted via proxy=<glob>, rewrites the client IP before connect checks
|
2026-08-11 11:43:08 +00:00 |
|
|
|
d68f3ce97e
|
bcrypt: native $2b$ hashing (blowfish + eksblowfish; pi constants via exact fixed-point machin) wired into password_hash + MKPASSWD
|
2026-08-11 11:32:35 +00:00 |
|
|
|
5ea543188d
|
syslog: tee the server-notice/log stream to syslog (native /dev/log unix datagram or udp host:port)
|
2026-08-11 11:21:09 +00:00 |
|
|
|
56d3774647
|
rline: native regex engine (thompson nfa, no backtracking) + RLINE regex bans (registration/enforce/stats R/matchonnickchange)
|
2026-08-10 21:48:52 +00:00 |
|
|
|
b76fbfdb79
|
services: SVSHOLD nick reservation, SVSTOPIC, SVSOPER, SVSCMODE over s2s (+ stats S)
|
2026-08-10 21:00:23 +00:00 |
|
|
|
f371ed0a18
|
connclass: cidr/parent/port/limit/globalmax + hashed/trusted-cert passwords, per-class recvq/sendq + fakelag, and rfc1413 ident
|
2026-08-10 18:46:42 +00:00 |
|
|
|
f5f888dbaa
|
connectclass: per-class connection policy (allow/deny, localmax, password, maxchans, pingfreq, timeout, modes) + PASS
|
2026-08-10 17:49:12 +00:00 |
|
|
|
02b2061561
|
readme: polished front-page layout — badges, about, grouped features, quick start, links
|
2026-08-10 13:01:08 +00:00 |
|
|
|
75de56f532
|
readme: cover the full feature set (modes, ircv3, services, s2s, geoip, rpc, transports)
|
2026-08-10 13:01:07 +00:00 |
|
|
|
1dd7f77ca8
|
operprefix + ojoin: server oper prefix (!/mode y, above owner) auto-granted to opers + OJOIN command
|
2026-08-10 13:01:07 +00:00 |
|
|
|
8ebb106f97
|
hidemode: hide configured mode changes from members below a rank (per-recipient MODE)
|
2026-08-10 09:41:20 +00:00 |
|
|
|
06883ced9f
|
extbanbanlist: matching extban b:#chan (share another channel's ban list)
|
2026-08-10 09:37:51 +00:00 |
|
|
|
0d5717c585
|
relaymsg: RELAYMSG + draft/relaymsg cap for bridge-style spoofed-nick channel messages
|
2026-08-10 09:06:30 +00:00 |
|
|
|
71d6e7441b
|
helpmode: oper-settable user mode +h (helpop) shown in whois
|
2026-08-10 09:01:38 +00:00 |
|
|
|
512185d6df
|
globops + autodrop: /GLOBOPS oper broadcast and pre-registration scanner drop
|
2026-08-10 08:58:15 +00:00 |
|
|
|
ab4d87488b
|
hidelist: restrict list-mode viewing by rank; allow members to view lists by default (parity)
|
2026-08-10 08:24:37 +00:00 |
|
|
|
9d84a66437
|
autoop: +w <prefix>:<mask> channel list mode grants status on join
|
2026-08-10 08:18:07 +00:00 |
|
|
|
87e3d5436d
|
chanlog: mirror the oper server-notice stream into a configured channel
|
2026-08-09 23:19:29 +00:00 |
|
|
|
1a53c5ae5a
|
banredirect: +b mask$#chan bounces a banned user to another channel (loop-guarded)
|
2026-08-09 23:17:32 +00:00 |
|
|
|
349200d695
|
solvemsg: arithmetic challenge before an un-vouched user's PMs deliver (anti-spam)
|
2026-08-09 23:11:57 +00:00 |
|
|
|
0bf6992d8a
|
dccallow: block unwanted DCC sends/chat + DCCALLOW +/-/LIST allow-list command
|
2026-08-09 23:08:25 +00:00 |
|
|
|
61954f6c5c
|
conn_waitpong: optionally require a PONG cookie before registration (anti-bot)
|
2026-08-09 23:04:14 +00:00 |
|
|
|
e0d849b4c9
|
showfile: serve a text file as its own command (e.g. /RULES), config-driven like aliases
|
2026-08-09 23:00:07 +00:00 |
|