Commit graph

260 commits

Author SHA1 Message Date
54c2a733fe password_hash: reject a PBKDF2 credential with an absurd iteration count (>10M) instead of running it — the count is read straight from the stored string, so a corrupt/hostile credential (e.g. via a compromised accounts backend) could pin a worker thread for a very long time; legitimate work factors are far below the cap 2026-08-19 01:02:36 +00:00
4248cc0479 oper: gate the client-facing SVSLOGIN/SVSLOGOUT behind oper_svslogin (default off) — they were a pre-S2S stopgap that let any oper forge an arbitrary account login (set_login) and thus +r/account-gated access; the live path is S2S link_svslogin (source_is_service-gated), so services are unaffected — only the obsolete oper backdoor is closed 2026-08-19 01:01:33 +00:00
a80b86b50d perf: S2S channel-message fanout shares the line by Arc across members (relay_channel_message) instead of cloning a String per recipient — mirrors the client PRIVMSG fanout; builds at most three variants (plain / server-time / echo-services-tagged) whatever the channel size, behaviour unchanged 2026-08-19 00:47:32 +00:00
910422199b perf: glob_match takes a zero-allocation byte-wise path for ASCII operands (the norm for hostmasks/IPs/cloaks) instead of collecting two Vec<char> per call — it runs per-message (filter), per-user (extbans/tline) and per-channel (channelban); non-ASCII still uses the Unicode-lowercased fallback, and a proptest pins the two paths equal on ASCII 2026-08-19 00:45:14 +00:00
35bb901455 whoisport: report the port the user actually connected to (User.port, set at accept) instead of conf("bind")/conf("bind_tls") — those are Vec-valued so conf() returned only the LAST configured listener, giving every user the same wrong port on a multi-listener server 2026-08-19 00:43:03 +00:00
25702c9541 syslog: strip control chars (CR/LF) from the message before framing — a snotice carrying user-influenced text (nick/realname/quit reason) with an embedded newline could inject a forged syslog record; matches the CR/LF care the JSON log path already takes 2026-08-19 00:42:30 +00:00
d9d5bd069b filehost: refuse to sign upload tokens when filehost_jwt_secret is unset/empty/"changeme" — the default fell open, signing with a world-known key so anyone could forge a server-trusted upload authorization; now it fails closed and tells the user to fix the config 2026-08-19 00:42:10 +00:00
a09dfc74df auth: constant-time compare for VHOST and WEBIRC secrets — both used plain == on the config password, unlike oper/RPC/JWT secrets which already route through ct_eq; expose password_hash::ct_eq as the shared comparator and use it (usernames stay plain == — not secret) 2026-08-19 00:41:47 +00:00
c72b966e0a mode: cap mode changes per MODE command (modes=, default 20) and advertise it as the MODES= ISUPPORT token — an uncapped modestring like MODE #c +bbbb… dispatched a handler per letter, each fanning out to the whole channel and every S2S link (amplification DoS); matches InspIRCd's MODES limit 2026-08-19 00:40:58 +00:00
11cec9fc36 s2s/xline: reject a malformed ADDLINE duration instead of coercing it to 0 (= a silent permanent ban), and make add_xline expiry saturating (n.saturating_add) so a peer sending duration=u64::MAX can't overflow-panic the debug build or wrap in release 2026-08-19 00:39:40 +00:00
bbe4ee4567 http: bound spawn_http concurrency (http_max_concurrent, default 32) like spawn_crypto — it spawned one unbounded OS thread per call, so a pre-auth VERIFY/REGISTER flood could exhaust threads and hammer the accounts backend; at capacity the command now fails with TEMPORARILY_UNAVAILABLE instead 2026-08-19 00:39:01 +00:00
801614605f http: verify TLS certs by default + cap the response body — set_verify(NONE) unconditionally let a MITM read/forge the account-registration & captcha traffic (usernames, emails, plaintext passwords) POSTed to operator-configured https URLs; now the connector's cert+hostname check stays on (opt out with http_tls_verify=no), and read_to_end is bounded to 4 MiB so a hostile endpoint can't OOM the worker 2026-08-19 00:37:50 +00:00
6682227f81 denychans: bound redirect recursion — a badchan redirect re-enters Server::join (which re-runs denychans), so a redirect loop (#a->#b->#a) or a redirect into a broad badchan glob recursed until the single-threaded daemon stack-overflowed from one JOIN; cap the chain at 8 hops via a RedirDepth guard in ext 2026-08-19 00:36:29 +00:00
a4f4c29a8a connectban: clamp the IPv6 keep-hextets to >=1 — connectban_ipv6cidr between 1 and 15 made keep==0, so the z-line glob became "*" and banned every IPv6 address on the internet (and bucketed all v6 clients into one key); mirrors the v4 clamp(1,4) 2026-08-19 00:34:53 +00:00
c99f16f3e0 webirc: require a non-empty source-IP mask on a webirc block — an empty ipmask meant "any IP", so a maskless webirc=<password> block turned one shared secret into a full host/IP spoof (bypassing z-lines, DNSBL, GeoIP, cloak) for anyone who learned it; now the gateway's connecting IP must match the block's ipmask 2026-08-19 00:34:25 +00:00
f56b68d6f5 resolver: close an off-path DNS spoof — connect() the UDP socket so the kernel drops replies from any IP but the nameserver, and use a CSPRNG per-query transaction id instead of the hardcoded 0x4543/0x4544 (which were in the public source, so rDNS/DNSBL answers could be forged with no guessing) 2026-08-19 00:33:18 +00:00
1763a95985 s2s: validate a message source actually lives behind the link it arrived on (source_behind) before applying remote JOIN/IJOIN/KICK/TOPIC/MODE/KILL/PRIVMSG — else a peer could forge ops/kicks/bans/topics/service-badged messages for users behind another link; NICK/QUIT/PART already guarded this, now the channel-state handlers do too 2026-08-19 00:32:09 +00:00
235c747c03 refactor: WEBIRC gateways and +G censor rules are named structs (WebircGateway/CensorRule) instead of positional tuples — self-documenting field access, no (_, g, _) index guessing; extends the OperBlock pattern 2026-08-18 23:31:21 +00:00
c4456cf002 oper: TLS client-cert fingerprint login — oper block gains an optional fp=<sha256>; password=* means cert-only. Named OperBlock struct replaces the (name,pass,level) tuple. (Password login was never broken — verified live.) 2026-08-18 22:55:07 +00:00
853be58d18 perf: channel PRIVMSG/NOTICE fanout builds at most one line per capability profile (server-time/account-tag/message-tags) and shares it by Arc, instead of formatting a String per member — a big channel now allocates <=8 lines, not N 2026-08-18 22:37:50 +00:00
d4dadf33e6 metrics: optional OpenMetrics/Prometheus endpoint (metrics_bind, off by default) — commands/messages/connects counters bumped inline via shared atomics, users/channels/servers/links gauges republished each tick; no event round-trip on the hot path 2026-08-18 22:34:36 +00:00
30754f08b5 refactor: define caps from one token=>field list via a macro that generates SUPPORTED_CAPS + the Caps struct + has/set — an advertised-but-unwired cap (or an unwired field) no longer compiles 2026-08-18 22:29:47 +00:00
a3dc7b521f test: deterministic two-node S2S convergence simulator — real handshake + join/part/rejoin/FJOIN-TS-arbitration driven through actual code paths, proptest-randomised churn asserts both sides always converge; extract Server::part so the sim and the PART command share one path 2026-08-18 22:24:19 +00:00
621f06448d test: property-based fuzzing (proptest) for every untrusted-input parser — message line, PROXY header, WebSocket frame, regex engine, ban-mask, duration; asserts no-panic + round-trip/idempotence/bounds invariants 2026-08-18 22:17:17 +00:00
cf2b157842 perf: to_channel shares one Arc<str> across all broadcast recipients instead of cloning the line per member (server-time members share a single time-tagged variant); single-recipient sends unchanged 2026-08-18 20:30:07 +00:00
fc58113db9 tls: add opt-in pure-Rust rustls backend behind the TlsBackend trait (tls_backend = rustls; default stays openssl) — TLS1.3, CertFP via handshake-sig verify, SNI, REHASH reload; bump integration timeouts for loaded-host robustness 2026-08-18 20:20:21 +00:00
2565089666 gitignore runtime *.db state (reputation.db/permchannels.db) — untrack; they must never be committed 2026-08-18 19:55:11 +00:00
20b49add0b perf: mimalloc global allocator + aHash maps + memchr line framer + LTO/codegen-units=1 — ~29% faster channel fanout; and drop the bogus openssl+mio dependency whitelist from the guard (any perf crate is welcome now) 2026-08-18 19:45:33 +00:00
687c91638b remove some stupid text. 2026-08-18 19:26:22 +00:00
33a18b81cc channelban: leave the a: (account) extban mask verbatim — normalize_ban_mask was appending !*@* and breaking account matching 2026-08-18 15:59:00 +00:00
bcd958d2d3 ircv3: close server-support-table gaps — BOT=B ISUPPORT, account-extban (a: matcher + ACCOUNTEXTBAN=a), draft/read-marker cap (gates MARKREAD sync), and no-implicit-names (suppress the post-JOIN NAMES burst) 2026-08-18 15:56:59 +00:00
c9bd8e7492 channel-rename: implement IRCv3 draft/channel-rename — RENAME command + cap, in-place rename (RENAME for cap clients, PART/JOIN fallback for the rest), and S2S propagation 2026-08-17 23:45:02 +00:00
755e835baf snoop: only announce a client's exit if it registered — an unregistered liveness/health probe was spamming the +q snomask (regression from firing on_user_quit for all users) 2026-08-17 22:49:29 +00:00
244feb9f45 reactor: bound the blocking TLS handshake (proxied-TLS path) with tls_handshake_timeout so a stalled handshake can't pin a thread/socket 2026-08-17 22:13:37 +00:00
7563daf3a3 account_registration: GC the per-IP rate-limit table on the tick (an entry per distinct registering IP was never dropped) 2026-08-17 22:13:37 +00:00
e28efb03e6 callerid: cap the auto-accept list like the explicit ACCEPT command 2026-08-17 21:37:19 +00:00
fad66eaac2 chathistory: GC conversation keys idle past chathistory_maxage (default 7d) — the key set never shrank 2026-08-17 21:37:19 +00:00
5522e36125 reactor: reap proxy-pending connections that never send their PROXY header (were never timed out) 2026-08-17 21:37:18 +00:00
de4cf9866d channel: scrub a departed user from every +i invite list (invited-then-quit leaked a Uid on persistent channels) 2026-08-17 21:37:18 +00:00
0da0906dc9 core: fire on_user_quit for unregistered users too — pre-registration module state (captcha Challenged/Verified) leaked one Uid per held-then-dropped bot 2026-08-17 21:37:18 +00:00
f2e23fffa9 captcha: issue the challenge once per held client, not on every command they send 2026-08-17 20:37:51 +00:00
d6cc813aad channel: reclaim departed-member +f flood counters and expired +J entries on the tick (slow high-churn leak) 2026-08-17 20:37:51 +00:00
92a3f5ba86 s2s: propagate CHGHOST/CHGIDENT host/ident changes to links (were applied locally only); inbound path uses a non-propagating variant to avoid a loop 2026-08-17 19:38:58 +00:00
73f8ff58ed s2s: enforce servprotect on a remote KILL and rank-vs-victim on a remote KICK (matching the local paths) 2026-08-17 19:38:58 +00:00
da36d5c32a s2s: FJOIN TS arbitration wipes list modes+topic on loss and merges on equal TS; arbitrate remote-remote nick collisions (rewrite forward); IJOIN/FTOPIC channel-TS handling 2026-08-17 19:32:18 +00:00
4b86de3b62 registration: add a Hold verdict so captcha/challenge modules pend the client for the challenge instead of tearing the link down 2026-08-17 19:06:17 +00:00
99eb9c74f3 relaymsg: gate RELAYMSG on oper (it spoofs an arbitrary source nick), matching InspIRCd 2026-08-17 19:06:17 +00:00
d6f27ac56c securitygroups: honor tls=no/account=no/etc. instead of inverting them to require 2026-08-17 15:05:13 +00:00
edb10a6607 connectban: never collapse the ban mask to * on a sub-/8 CIDR (would z-line the whole network) 2026-08-17 15:05:13 +00:00
58d5a0e5a5 message: keep +U opmoderated messages out of CHATHISTORY/+H replay, and subject TAGMSG to the same PM gates (+c/+R/+z/+g/SILENCE) 2026-08-17 15:05:13 +00:00