|
|
3ad67c6b52
|
xline: broadcast the XLINE notice on remove and expire too, so it covers every x-line's whole lifecycle
|
2026-08-21 15:03:36 +00:00 |
|
|
|
6301b64509
|
server: extract civil() so iso_time and long_date share one date conversion instead of duplicating it
|
2026-08-21 14:52:49 +00:00 |
|
|
|
b693c5e5df
|
dnsbl: per-zone name/action/duration/reason with %ip%; XLINE notice shows duration + absolute expiry
|
2026-08-21 14:14:17 +00:00 |
|
|
|
1824af5d90
|
signore: persist per-account via services metadata — push on edit, replay on login
|
2026-08-20 15:40:19 +00:00 |
|
|
|
6c5f330746
|
add SIGNORE: personal mutual server-side ignore across channels and PMs
|
2026-08-20 14:48:17 +00:00 |
|
|
|
2c9ce18cd7
|
whois: render the oper-type title line in bold + colour (per-type color=<name|0-15|none>, default red) so it stands out
|
2026-08-20 14:26:17 +00:00 |
|
|
|
bc520d59a5
|
whois: a typed oper gets its own 320 special line with the type title (e.g. 'is a Network Administrator'), separate from the generic 313 operator line
|
2026-08-20 14:17:15 +00:00 |
|
|
|
8f9e60c8e2
|
whois: 313 shows the generic 'is an IRC Operator' again — the oper type gates capabilities, and a custom title comes from the SWHOIS line (320)
|
2026-08-20 14:05:46 +00:00 |
|
|
|
5a9825ee61
|
comments: strip stray reference-implementation names from a handful of module/inline comments
|
2026-08-20 10:11:07 +00:00 |
|
|
|
81e013f053
|
docs: document oper classes/types + the five built-in types (operators.md, example config)
|
2026-08-20 10:06:38 +00:00 |
|
|
|
01516d5fdc
|
opertypes: oper classes + types — reusable capability classes and named roles (WHOIS title, auto usermodes/snomasks/vhost + level on oper-up, per-type command enforcement via on_pre_command); ships 5 built-in (helpop/globop/admin/servadmin/netadmin); oper blocks gain type=<id>; a typeless oper keeps full access
|
2026-08-20 10:05:11 +00:00 |
|
|
|
f3ce0e61ef
|
s2s: accept a swhois metadata key from services — set (or clear, when empty) the user's SWHOIS ext, shown in WHOIS 320
|
2026-08-20 00:02:02 +00:00 |
|
|
|
f1ddb878af
|
rustls: offer TLS 1.2 only, matching the openssl backend (mozilla_intermediate) — advertising 1.3 as well pushed every client onto a 1.3 handshake openssl never served, so a client fine on 1.2 could fail to connect; a drop-in backend must negotiate the same protocol
|
2026-08-19 17:55:31 +00:00 |
|
|
|
598a019620
|
rustls: keep WRITABLE and drain buffered ciphertext when the socket backs up, and bound the plaintext buffer at 256KiB — rustls accepts all plaintext and buffers ciphertext internally on WouldBlock (unlike openssl, which surfaces backpressure through write); expose wants_write()/flush() so the reactor drains it and the sendq caps govern a slow reader. no-op for the openssl and plaintext paths
|
2026-08-19 17:19:15 +00:00 |
|
|
|
ebd6e29589
|
docs: rework README + manual — refresh the feature set (services interface, rustls TLS backend, WebSocket, PROXY v1/v2, metrics + JSON-RPC endpoints), correct command/module/cap counts, and document the tls_backend/metrics_bind/rpc/sts config keys in configuration.md and the example
|
2026-08-19 14:37:22 +00:00 |
|
|
|
b106b66de5
|
s2s: validate source_behind on ADDLINE/DELLINE/INVITE too — these apply network state (x-lines, invite bypass) from msg.source with no check the source sits behind the arriving link; a legit source (incl. a services SID/uuid) always is, so echo's akills still propagate
|
2026-08-19 04:57:39 +00:00 |
|
|
|
78a6574d64
|
hardening: bracket a bare IPv6 nameserver literal (was unparseable -> rDNS/DNSBL silently degraded on v6-only hosts); saturating chunk-size advance in the RPC dechunker (a 16-hex-digit size could overflow-panic the worker); connclass hash= is now last-wins to match password= under parent= inheritance
|
2026-08-19 04:45:07 +00:00 |
|
|
|
1a5c41871c
|
password_hash: reject an empty PBKDF2 hash/salt — a stored 'pbkdf2:iters:salt:' (empty hash) made ct_eq(&[],&[]) return true, verifying ANY password; refuse empty want/salt before computing
|
2026-08-19 04:45:07 +00:00 |
|
|
|
6bc299f286
|
socketengine: re-drain a read-capped socket via a pending_reads queue, not an epoll re-arm — the MAX_READ_PER_TURN re-arm relied on kernel readiness, but a TLS socket drains all ciphertext and buffers decrypted plaintext INSIDE the session, so complete lines past 64KB stranded until the next TCP segment; the reactor now re-reads queued sockets each turn (covers kernel- and TLS-buffered leftover)
|
2026-08-19 04:45:07 +00:00 |
|
|
|
9eda8cbd4f
|
server: carry accepted_nicks count across a nick change — set_nick rewrites ACCEPT entries old->new in place (bypassing accept_add/remove) so the reverse count desynced; the count-gated quit scrub could then skip a reused nick, letting it inherit +g acceptance. move the count old->new (also fixes a slow map leak)
|
2026-08-19 04:45:07 +00:00 |
|
|
|
155e804779
|
s2s: extend source_behind to FTOPIC/RENAME/UID/OPERTYPE/REDACT — the guard was on plain TOPIC but not its S2S twin FTOPIC (a peer could forge a network-wide topic overwrite), nor channel RENAME, UID (SID announce unchecked), OPERTYPE, or REDACT; all now validate the source lives behind the arriving link
|
2026-08-19 04:45:06 +00:00 |
|
|
|
9c5719fd7c
|
socketengine: cap bytes drained from one socket per readable event (MAX_READ_PER_TURN=64KiB), then re-arm epoll and yield — bounds the per-turn line buffer and stops one flooding client from monopolising the reactor; the leftover waits in the kernel buffer and is re-delivered next turn (verified: a 133KB single-write burst gets every reply back)
|
2026-08-19 03:28:51 +00:00 |
|
|
|
fc9ae4faad
|
message: parse the IRCv3 tag block in a single pass instead of four separate split(';') scans plus an intermediate Vec for ctags
|
2026-08-19 02:54:24 +00:00 |
|
|
|
1aa02a08b9
|
channels: replace Member's six parallel prefix bools (oprefix/owner/admin/op/halfop/voice) with a single u8 bitfield (PFX_*) + inline bool accessors/mutators — same semantics, one byte instead of six, no more risk of the flags drifting out of sync; all call sites go through op()/set_op()-style methods
|
2026-08-19 02:47:04 +00:00 |
|
|
|
16fae5b23c
|
watch: notify WATCH/MONITOR via nick->watchers reverse indexes (watch_by/monitor_by) instead of scanning every user on each online/offline/nick-change flip — O(watchers) not O(users); maintained through centralized watch_index_*/monitor_index_* helpers + quit cleanup
|
2026-08-19 02:34:22 +00:00 |
|
|
|
16ea4b5a23
|
core_message: compute the sender's channel rank once per message (mrank) instead of recomputing s.rank(uid,&key) up to 7x in the channel PRIVMSG/NOTICE gate and once more in TAGMSG — rank is fixed for a single message
|
2026-08-19 02:29:59 +00:00 |
|
|
|
fb1a9f3d70
|
server: skip the O(users) callerid ACCEPT scrub on quit unless the departing nick is actually accepted by someone — a reverse count (accepted_nicks) maintained through centralized accept_add/accept_remove helpers avoids scanning every user's accept list on each quit (O(users*quits) on a netsplit); the full scrub still runs when the count is nonzero, so the nick-reuse protection is unchanged
|
2026-08-19 02:21:38 +00:00 |
|
|
|
ab0ccae71f
|
server: scrub a departed user's pending invites via a User.invited reverse index instead of scanning every channel on the network per quit — the old O(channels)-per-quit path was O(channels*quits) on a netsplit; the index is maintained at the 4 invite add/remove sites (INVITE cmd, S2S INVITE, join-consume, UNINVITE)
|
2026-08-19 02:09:36 +00:00 |
|
|
|
5101b1361d
|
whois: build the target snapshot as a named WhoisInfo struct instead of a 17-field positional tuple — field-named construction can't silently transpose two same-typed fields; destructured into the same locals so the reply code is unchanged
|
2026-08-19 01:58:01 +00:00 |
|
|
|
ea3e879068
|
connclass: cache resolved connect classes in a config_gen-tagged thread_local — all()/named() (and thus pick/assign and every per-ping/per-message getter) re-parsed the connectclass config and re-resolved parent inheritance on each call; now rebuilt only on rehash
|
2026-08-19 01:56:22 +00:00 |
|
|
|
d4d3886379
|
restrictcommands: cache the parsed restriction list (config_gen-tagged) instead of re-tokenizing every restrictcommand line on every command; clone only the one matched rule so the ext borrow drops before the server is used mutably
|
2026-08-19 01:54:45 +00:00 |
|
|
|
cd46cfc49f
|
securitygroups: cache parsed groups in a config_gen-tagged thread_local instead of re-parsing all securitygroup lines on every g: extban match and WHOIS — safe on the single-threaded core, re-parses only on rehash
|
2026-08-19 01:53:41 +00:00 |
|
|
|
1da913a249
|
autodrop: cache the autodrop-command set (config_gen-tagged) instead of re-splitting autodrop_commands on every packet from an unregistered socket — the path runs hottest under the scanner flood it defends against
|
2026-08-19 01:51:57 +00:00 |
|
|
|
09b4adabbf
|
disable: cache the disabled-command set (config_gen-tagged HashSet) instead of re-splitting disabled_commands on every non-oper command — the hottest hook in the server; re-parses only on rehash
|
2026-08-19 01:51:31 +00:00 |
|
|
|
78be7279b0
|
server: add a config_gen counter bumped on every rehash — lets modules cache config parsed into a hot-path structure and invalidate it correctly (a REHASH can't leave a stale cache), unblocking the per-message/per-command config re-parse in disable/autodrop/securitygroups/restrictcommands/connclass
|
2026-08-19 01:51:08 +00:00 |
|
|
|
11852332dc
|
message: parse on space (0x20) only per RFC — trim_start() also ate tabs, so a param containing a tab (e.g. a trailing ':\t') didn't round-trip through to_wire/parse; the parser fuzz proptest found it. trim_start_matches(' ') makes tabs ordinary param content; regression case pinned
|
2026-08-19 01:41:22 +00:00 |
|
|
|
98e5cf4d20
|
relaymsg/showfile: reject whitespace/control chars in a RELAYMSG spoofed nick (defence-in-depth on top of the denylist), and cap the showfile read at 256 KiB so a large /RULES-style file can't stall the core loop
|
2026-08-19 01:35:25 +00:00 |
|
|
|
c47fb9a80a
|
syslog: keep the UDP socket cached across send errors instead of dropping it (which re-bound + re-resolved a socket on every notice when the target was unreachable); the Unix datagram path still reopens on failure
|
2026-08-19 01:34:24 +00:00 |
|
|
|
b3f66ec310
|
customtitle: return Fail (not Ok) when the crypto pool is at capacity and the TITLE auth is denied, matching the synchronous verify path
|
2026-08-19 01:33:34 +00:00 |
|
|
|
55174ec017
|
profilelink/hidelist: unify the WHOIS label to English "Profile:" (was "Profil:" for logged-in users) and make hidelist honour the last matching config line (conf last-wins semantics) instead of the first
|
2026-08-19 01:33:05 +00:00 |
|
|
|
303fc0c8dc
|
filehost: use only the final path segment of the URL as the displayed filename tag — the trailing part was taken verbatim (path separators, ../), and while json_esc/escape_tag block injection, a client rendering filename could be misled by traversal; take the basename
|
2026-08-19 01:32:17 +00:00 |
|
|
|
c532828aab
|
jwt: match claim_num only against a top-level object key (depth-aware scan), not any substring — a claim whose string value contained "exp": could otherwise spoof the exp an external verifier reads; added nested + string-value regression tests
|
2026-08-19 01:31:22 +00:00 |
|
|
|
c32fbee905
|
chanlog: fan the mirrored notice via to_channel (Arc-shared line, per-recipient server-time) instead of collecting a members Vec and cloning the String per member
|
2026-08-19 01:29:48 +00:00 |
|
|
|
2851c0a7ab
|
rmode: send a usage NOTICE when the list-mode arg has no mode letter (e.g. RMODE #c 3) instead of failing silently
|
2026-08-19 01:29:14 +00:00 |
|
|
|
b557c9887f
|
log_json: cache an open failure so a misconfigured path doesn't re-issue an open() syscall (and silently drop) on every notice — the error is now surfaced once via stderr and not retried until the path changes; the write-failure reopen (for logrotate) is preserved
|
2026-08-19 01:28:42 +00:00 |
|
|
|
65bedaf417
|
hidemode: resolve each changed mode's hidden-rank once and each member's rank once, instead of re-scanning the hidemode config for every (member x change) pair on the MODE broadcast hot path
|
2026-08-19 01:23:33 +00:00 |
|
|
|
b59fe70537
|
operlevels: use Extensible::set instead of get_or_insert_with(0)-then-overwrite
|
2026-08-19 01:22:54 +00:00 |
|
|
|
d495fd0f30
|
channel: cap the per-channel invite set (maxinvites, default 100) — it only shrank when the invitee joined, so an op could grow it unboundedly; re-inviting an already-listed nick still works
|
2026-08-19 01:22:32 +00:00 |
|
|
|
8f5b37bf8d
|
dnsbl: cap the number of blocklist zones checked per client at 16 — each zone is a serial blocking DNS lookup, so a long (mis)configured zone list could stall a connecting client's registration for zones.len()*timeout
|
2026-08-19 01:21:40 +00:00 |
|
|
|
b63458816e
|
metrics: set read/write timeouts on each scrape connection — the single-threaded accept loop did an untimed read, so one client that connected and never sent blocked every future scrape (slowloris)
|
2026-08-19 01:21:21 +00:00 |
|