|
|
b6ada854cc
|
brand: per-SNI server/network identity (welcome, ISUPPORT NETWORK, numeric source prefix)
|
2026-08-24 23:29:15 +00:00 |
|
|
|
f36f803d42
|
whois: show client-cert fingerprint (276) to everyone, not just opers/self
|
2026-08-24 22:25:08 +00:00 |
|
|
|
009bea734a
|
whois: show negotiated TLS version/group/cipher in 671; sslgroup crate reads the KEX group
|
2026-08-24 21:45:46 +00:00 |
|
|
|
85eb8218f0
|
tls: openssl backend offers TLS 1.3 via mozilla_intermediate_v5 (was capped at 1.2)
|
2026-08-24 20:38:58 +00:00 |
|
|
|
51602737e2
|
tls: rustls backend offers TLS 1.3 (was TLS 1.2 only), preferred over 1.2
|
2026-08-24 20:30:54 +00:00 |
|
|
|
d0fdb2e8be
|
docs: add Community section (irc.devtronic.pro #echoiRCd support channel) to README
|
2026-08-24 19:47:06 +00:00 |
|
|
|
f066fa0b5a
|
docs: document the block config format + mkpasswd/checkconfig/rehash CLIs in README and configuration.md
|
2026-08-24 19:13:45 +00:00 |
|
|
|
8d48900ae3
|
config: derive Eq on the block-parser token enum
|
2026-08-23 13:01:05 +00:00 |
|
|
|
1166c49443
|
config: checkconfig CLI + Config::dump; tls block carries sni/handshake_timeout
|
2026-08-23 12:42:30 +00:00 |
|
|
|
b11382bc1e
|
config: block-format example documenting every option; cloak/uline block fields + example parse guard
|
2026-08-23 12:28:19 +00:00 |
|
|
|
2f6ce36af0
|
config: add brace/block format (translated to flat, both formats supported)
|
2026-08-23 12:18:10 +00:00 |
|
|
|
e8d16a1f96
|
config: accept oper password=<hash> named token; keep positional password back-compat
|
2026-08-23 03:11:32 +00:00 |
|
|
|
c2e0a9eeb4
|
mkpasswd: 'echoircd mkpasswd [cost]' CLI hashes a stdin password with bcrypt for oper blocks
|
2026-08-23 02:55:14 +00:00 |
|
|
|
12a4ddb749
|
rehash: fall back to a /proc scan for the running server when the pidfile is stale, and self-heal it
|
2026-08-23 02:40:53 +00:00 |
|
|
|
3052e47212
|
docs: document the pidfile option in the example config
|
2026-08-23 02:35:32 +00:00 |
|
|
|
34342e110f
|
rehash: write the pidfile only when configured + CLI verifies a live echoircd, so a stale/clobbered pid can't misfire
|
2026-08-23 02:17:44 +00:00 |
|
|
|
a7ae0d86a9
|
rehash: 'echoircd rehash' CLI + SIGHUP reload the running config in place via a pidfile
|
2026-08-23 02:10:41 +00:00 |
|
|
|
42fe82556b
|
version: show echoircd-<major> (5) in 002/004/351 and enrich RPL_VERSION with build/toolchain provenance
|
2026-08-23 01:24:45 +00:00 |
|
|
|
5c286a94cb
|
conn_waitpong: exempt loopback (per ipv4/ipv6) and per-class from the registration ping cookie
|
2026-08-22 23:49:46 +00:00 |
|
|
|
70a4ecb0a0
|
core: add oper MODULES command (702/703) listing loaded modules; module.list RPC already existed
|
2026-08-22 17:36:46 +00:00 |
|
|
|
4357a59c7a
|
filter: pluggable pattern engine (glob|regex) selected by filter_engine config; regex/glob backends behind a Matcher trait
|
2026-08-22 17:36:46 +00:00 |
|
|
|
73817eddde
|
whois: show a remote user's actual server description in 312, not the literal "remote user"
|
2026-08-21 23:43:51 +00:00 |
|
|
|
ddb6214b47
|
chanlog: post log lines as a channel PRIVMSG from the server, not a NOTICE
|
2026-08-21 17:41:00 +00:00 |
|
|
|
b8e24e2071
|
chanlog: filter each log channel by snomask category; repeatable so different snomasks route to different channels
|
2026-08-21 17:11:27 +00:00 |
|
|
|
7cb9256ff5
|
xline: tell a banned user when the ban expires, not just why
|
2026-08-21 15:18:23 +00:00 |
|
|
|
745ddd540e
|
xline: show a timed ban's remaining time in the removal notice
|
2026-08-21 15:10:27 +00:00 |
|
|
|
3ad67c6b52
|
xline: broadcast the XLINE notice on remove and expire too, so it covers every x-line's whole lifecycle
|
2026-08-21 15:03:36 +00:00 |
|
|
|
6301b64509
|
server: extract civil() so iso_time and long_date share one date conversion instead of duplicating it
|
2026-08-21 14:52:49 +00:00 |
|
|
|
b693c5e5df
|
dnsbl: per-zone name/action/duration/reason with %ip%; XLINE notice shows duration + absolute expiry
|
2026-08-21 14:14:17 +00:00 |
|
|
|
1824af5d90
|
signore: persist per-account via services metadata — push on edit, replay on login
|
2026-08-20 15:40:19 +00:00 |
|
|
|
6c5f330746
|
add SIGNORE: personal mutual server-side ignore across channels and PMs
|
2026-08-20 14:48:17 +00:00 |
|
|
|
2c9ce18cd7
|
whois: render the oper-type title line in bold + colour (per-type color=<name|0-15|none>, default red) so it stands out
|
2026-08-20 14:26:17 +00:00 |
|
|
|
bc520d59a5
|
whois: a typed oper gets its own 320 special line with the type title (e.g. 'is a Network Administrator'), separate from the generic 313 operator line
|
2026-08-20 14:17:15 +00:00 |
|
|
|
8f9e60c8e2
|
whois: 313 shows the generic 'is an IRC Operator' again — the oper type gates capabilities, and a custom title comes from the SWHOIS line (320)
|
2026-08-20 14:05:46 +00:00 |
|
|
|
5a9825ee61
|
comments: strip stray reference-implementation names from a handful of module/inline comments
|
2026-08-20 10:11:07 +00:00 |
|
|
|
81e013f053
|
docs: document oper classes/types + the five built-in types (operators.md, example config)
|
2026-08-20 10:06:38 +00:00 |
|
|
|
01516d5fdc
|
opertypes: oper classes + types — reusable capability classes and named roles (WHOIS title, auto usermodes/snomasks/vhost + level on oper-up, per-type command enforcement via on_pre_command); ships 5 built-in (helpop/globop/admin/servadmin/netadmin); oper blocks gain type=<id>; a typeless oper keeps full access
|
2026-08-20 10:05:11 +00:00 |
|
|
|
f3ce0e61ef
|
s2s: accept a swhois metadata key from services — set (or clear, when empty) the user's SWHOIS ext, shown in WHOIS 320
|
2026-08-20 00:02:02 +00:00 |
|
|
|
f1ddb878af
|
rustls: offer TLS 1.2 only, matching the openssl backend (mozilla_intermediate) — advertising 1.3 as well pushed every client onto a 1.3 handshake openssl never served, so a client fine on 1.2 could fail to connect; a drop-in backend must negotiate the same protocol
|
2026-08-19 17:55:31 +00:00 |
|
|
|
598a019620
|
rustls: keep WRITABLE and drain buffered ciphertext when the socket backs up, and bound the plaintext buffer at 256KiB — rustls accepts all plaintext and buffers ciphertext internally on WouldBlock (unlike openssl, which surfaces backpressure through write); expose wants_write()/flush() so the reactor drains it and the sendq caps govern a slow reader. no-op for the openssl and plaintext paths
|
2026-08-19 17:19:15 +00:00 |
|
|
|
ebd6e29589
|
docs: rework README + manual — refresh the feature set (services interface, rustls TLS backend, WebSocket, PROXY v1/v2, metrics + JSON-RPC endpoints), correct command/module/cap counts, and document the tls_backend/metrics_bind/rpc/sts config keys in configuration.md and the example
|
2026-08-19 14:37:22 +00:00 |
|
|
|
b106b66de5
|
s2s: validate source_behind on ADDLINE/DELLINE/INVITE too — these apply network state (x-lines, invite bypass) from msg.source with no check the source sits behind the arriving link; a legit source (incl. a services SID/uuid) always is, so echo's akills still propagate
|
2026-08-19 04:57:39 +00:00 |
|
|
|
78a6574d64
|
hardening: bracket a bare IPv6 nameserver literal (was unparseable -> rDNS/DNSBL silently degraded on v6-only hosts); saturating chunk-size advance in the RPC dechunker (a 16-hex-digit size could overflow-panic the worker); connclass hash= is now last-wins to match password= under parent= inheritance
|
2026-08-19 04:45:07 +00:00 |
|
|
|
1a5c41871c
|
password_hash: reject an empty PBKDF2 hash/salt — a stored 'pbkdf2:iters:salt:' (empty hash) made ct_eq(&[],&[]) return true, verifying ANY password; refuse empty want/salt before computing
|
2026-08-19 04:45:07 +00:00 |
|
|
|
6bc299f286
|
socketengine: re-drain a read-capped socket via a pending_reads queue, not an epoll re-arm — the MAX_READ_PER_TURN re-arm relied on kernel readiness, but a TLS socket drains all ciphertext and buffers decrypted plaintext INSIDE the session, so complete lines past 64KB stranded until the next TCP segment; the reactor now re-reads queued sockets each turn (covers kernel- and TLS-buffered leftover)
|
2026-08-19 04:45:07 +00:00 |
|
|
|
9eda8cbd4f
|
server: carry accepted_nicks count across a nick change — set_nick rewrites ACCEPT entries old->new in place (bypassing accept_add/remove) so the reverse count desynced; the count-gated quit scrub could then skip a reused nick, letting it inherit +g acceptance. move the count old->new (also fixes a slow map leak)
|
2026-08-19 04:45:07 +00:00 |
|
|
|
155e804779
|
s2s: extend source_behind to FTOPIC/RENAME/UID/OPERTYPE/REDACT — the guard was on plain TOPIC but not its S2S twin FTOPIC (a peer could forge a network-wide topic overwrite), nor channel RENAME, UID (SID announce unchecked), OPERTYPE, or REDACT; all now validate the source lives behind the arriving link
|
2026-08-19 04:45:06 +00:00 |
|
|
|
9c5719fd7c
|
socketengine: cap bytes drained from one socket per readable event (MAX_READ_PER_TURN=64KiB), then re-arm epoll and yield — bounds the per-turn line buffer and stops one flooding client from monopolising the reactor; the leftover waits in the kernel buffer and is re-delivered next turn (verified: a 133KB single-write burst gets every reply back)
|
2026-08-19 03:28:51 +00:00 |
|
|
|
fc9ae4faad
|
message: parse the IRCv3 tag block in a single pass instead of four separate split(';') scans plus an intermediate Vec for ctags
|
2026-08-19 02:54:24 +00:00 |
|
|
|
1aa02a08b9
|
channels: replace Member's six parallel prefix bools (oprefix/owner/admin/op/halfop/voice) with a single u8 bitfield (PFX_*) + inline bool accessors/mutators — same semantics, one byte instead of six, no more risk of the flags drifting out of sync; all call sites go through op()/set_op()-style methods
|
2026-08-19 02:47:04 +00:00 |
|