You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

server.go 35KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000
  1. // Copyright (c) 2012-2014 Jeremy Latt
  2. // Copyright (c) 2014-2015 Edmund Huber
  3. // Copyright (c) 2016-2017 Daniel Oaks <daniel@danieloaks.net>
  4. // released under the MIT license
  5. package irc
  6. import (
  7. "fmt"
  8. "net"
  9. "net/http"
  10. _ "net/http/pprof"
  11. "os"
  12. "os/signal"
  13. "strconv"
  14. "strings"
  15. "sync"
  16. "syscall"
  17. "time"
  18. "unsafe"
  19. "github.com/goshuirc/irc-go/ircfmt"
  20. "github.com/oragono/oragono/irc/caps"
  21. "github.com/oragono/oragono/irc/connection_limits"
  22. "github.com/oragono/oragono/irc/history"
  23. "github.com/oragono/oragono/irc/logger"
  24. "github.com/oragono/oragono/irc/modes"
  25. "github.com/oragono/oragono/irc/mysql"
  26. "github.com/oragono/oragono/irc/sno"
  27. "github.com/oragono/oragono/irc/utils"
  28. "github.com/tidwall/buntdb"
  29. )
  30. var (
  31. // common error line to sub values into
  32. errorMsg = "ERROR :%s\r\n"
  33. // three final parameters of 004 RPL_MYINFO, enumerating our supported modes
  34. rplMyInfo1, rplMyInfo2, rplMyInfo3 = modes.RplMyInfo()
  35. // CHANMODES isupport token
  36. chanmodesToken = modes.ChanmodesToken()
  37. // whitelist of caps to serve on the STS-only listener. In particular,
  38. // never advertise SASL, to discourage people from sending their passwords:
  39. stsOnlyCaps = caps.NewSet(caps.STS, caps.MessageTags, caps.ServerTime, caps.Batch, caps.LabeledResponse, caps.EchoMessage, caps.Nope)
  40. // we only have standard channels for now. TODO: any updates to this
  41. // will also need to be reflected in CasefoldChannel
  42. chanTypes = "#"
  43. throttleMessage = "You have attempted to connect too many times within a short duration. Wait a while, and you will be able to connect."
  44. )
  45. // Server is the main Oragono server.
  46. type Server struct {
  47. accounts AccountManager
  48. channels ChannelManager
  49. channelRegistry ChannelRegistry
  50. clients ClientManager
  51. config unsafe.Pointer
  52. configFilename string
  53. connectionLimiter connection_limits.Limiter
  54. ctime time.Time
  55. dlines *DLineManager
  56. helpIndexManager HelpIndexManager
  57. klines *KLineManager
  58. listeners map[string]IRCListener
  59. logger *logger.Manager
  60. monitorManager MonitorManager
  61. name string
  62. nameCasefolded string
  63. rehashMutex sync.Mutex // tier 4
  64. rehashSignal chan os.Signal
  65. pprofServer *http.Server
  66. resumeManager ResumeManager
  67. signals chan os.Signal
  68. snomasks SnoManager
  69. store *buntdb.DB
  70. historyDB mysql.MySQL
  71. torLimiter connection_limits.TorLimiter
  72. whoWas WhoWasList
  73. stats Stats
  74. semaphores ServerSemaphores
  75. defcon uint32
  76. }
  77. // NewServer returns a new Oragono server.
  78. func NewServer(config *Config, logger *logger.Manager) (*Server, error) {
  79. // initialize data structures
  80. server := &Server{
  81. ctime: time.Now().UTC(),
  82. listeners: make(map[string]IRCListener),
  83. logger: logger,
  84. rehashSignal: make(chan os.Signal, 1),
  85. signals: make(chan os.Signal, len(ServerExitSignals)),
  86. defcon: 5,
  87. }
  88. server.clients.Initialize()
  89. server.semaphores.Initialize()
  90. server.resumeManager.Initialize(server)
  91. server.whoWas.Initialize(config.Limits.WhowasEntries)
  92. server.monitorManager.Initialize()
  93. server.snomasks.Initialize()
  94. if err := server.applyConfig(config); err != nil {
  95. return nil, err
  96. }
  97. // Attempt to clean up when receiving these signals.
  98. signal.Notify(server.signals, ServerExitSignals...)
  99. signal.Notify(server.rehashSignal, syscall.SIGHUP)
  100. return server, nil
  101. }
  102. // Shutdown shuts down the server.
  103. func (server *Server) Shutdown() {
  104. //TODO(dan): Make sure we disallow new nicks
  105. for _, client := range server.clients.AllClients() {
  106. client.Notice("Server is shutting down")
  107. if client.AlwaysOn() {
  108. client.Store(IncludeLastSeen)
  109. }
  110. }
  111. if err := server.store.Close(); err != nil {
  112. server.logger.Error("shutdown", fmt.Sprintln("Could not close datastore:", err))
  113. }
  114. server.historyDB.Close()
  115. }
  116. // Run starts the server.
  117. func (server *Server) Run() {
  118. // defer closing db/store
  119. defer server.store.Close()
  120. for {
  121. select {
  122. case <-server.signals:
  123. server.Shutdown()
  124. return
  125. case <-server.rehashSignal:
  126. go func() {
  127. server.logger.Info("server", "Rehashing due to SIGHUP")
  128. server.rehash()
  129. }()
  130. }
  131. }
  132. }
  133. func (server *Server) checkBans(config *Config, ipaddr net.IP, checkScripts bool) (banned bool, requireSASL bool, message string) {
  134. if server.Defcon() == 1 {
  135. if !(ipaddr.IsLoopback() || utils.IPInNets(ipaddr, server.Config().Server.secureNets)) {
  136. return true, false, "New connections to this server are temporarily restricted"
  137. }
  138. }
  139. // check DLINEs
  140. isBanned, info := server.dlines.CheckIP(ipaddr)
  141. if isBanned {
  142. server.logger.Info("connect-ip", fmt.Sprintf("Client from %v rejected by d-line", ipaddr))
  143. return true, false, info.BanMessage("You are banned from this server (%s)")
  144. }
  145. // check connection limits
  146. err := server.connectionLimiter.AddClient(ipaddr)
  147. if err == connection_limits.ErrLimitExceeded {
  148. // too many connections from one client, tell the client and close the connection
  149. server.logger.Info("connect-ip", fmt.Sprintf("Client from %v rejected for connection limit", ipaddr))
  150. return true, false, "Too many clients from your network"
  151. } else if err == connection_limits.ErrThrottleExceeded {
  152. duration := config.Server.IPLimits.BanDuration
  153. if duration != 0 {
  154. server.dlines.AddIP(ipaddr, duration, throttleMessage,
  155. "Exceeded automated connection throttle", "auto.connection.throttler")
  156. // they're DLINE'd for 15 minutes or whatever, so we can reset the connection throttle now,
  157. // and once their temporary DLINE is finished they can fill up the throttler again
  158. server.connectionLimiter.ResetThrottle(ipaddr)
  159. }
  160. server.logger.Info(
  161. "connect-ip",
  162. fmt.Sprintf("Client from %v exceeded connection throttle, d-lining for %v", ipaddr, duration))
  163. return true, false, throttleMessage
  164. } else if err != nil {
  165. server.logger.Warning("internal", "unexpected ban result", err.Error())
  166. }
  167. if checkScripts && config.Server.IPCheckScript.Enabled {
  168. output, err := CheckIPBan(server.semaphores.IPCheckScript, config.Server.IPCheckScript, ipaddr)
  169. if err != nil {
  170. server.logger.Error("internal", "couldn't check IP ban script", ipaddr.String(), err.Error())
  171. return false, false, ""
  172. }
  173. // TODO: currently no way to cache results other than IPBanned
  174. if output.Result == IPBanned && output.CacheSeconds != 0 {
  175. network, err := utils.NormalizedNetFromString(output.CacheNet)
  176. if err != nil {
  177. server.logger.Error("internal", "invalid dline net from IP ban script", ipaddr.String(), output.CacheNet)
  178. } else {
  179. dlineDuration := time.Duration(output.CacheSeconds) * time.Second
  180. err := server.dlines.AddNetwork(network, dlineDuration, output.BanMessage, "", "")
  181. if err != nil {
  182. server.logger.Error("internal", "couldn't set dline from IP ban script", ipaddr.String(), err.Error())
  183. }
  184. }
  185. }
  186. if output.Result == IPBanned {
  187. // XXX roll back IP connection/throttling addition for the IP
  188. server.connectionLimiter.RemoveClient(ipaddr)
  189. server.logger.Info("connect-ip", "Rejected client due to ip-check-script", ipaddr.String())
  190. return true, false, output.BanMessage
  191. } else if output.Result == IPRequireSASL {
  192. server.logger.Info("connect-ip", "Requiring SASL from client due to ip-check-script", ipaddr.String())
  193. return false, true, output.BanMessage
  194. }
  195. }
  196. return false, false, ""
  197. }
  198. func (server *Server) checkTorLimits() (banned bool, message string) {
  199. switch server.torLimiter.AddClient() {
  200. case connection_limits.ErrLimitExceeded:
  201. return true, "Too many clients from the Tor network"
  202. case connection_limits.ErrThrottleExceeded:
  203. return true, "Exceeded connection throttle for the Tor network"
  204. default:
  205. return false, ""
  206. }
  207. }
  208. //
  209. // server functionality
  210. //
  211. func (server *Server) tryRegister(c *Client, session *Session) (exiting bool) {
  212. // if the session just sent us a RESUME line, try to resume
  213. if session.resumeDetails != nil {
  214. session.tryResume()
  215. return // whether we succeeded or failed, either way `c` is not getting registered
  216. }
  217. // XXX PROXY or WEBIRC MUST be sent as the first line of the session;
  218. // if we are here at all that means we have the final value of the IP
  219. if session.rawHostname == "" {
  220. session.client.lookupHostname(session, false)
  221. }
  222. // try to complete registration normally
  223. // XXX(#1057) username can be filled in by an ident query without the client
  224. // having sent USER: check for both username and realname to ensure they did
  225. if c.preregNick == "" || c.username == "" || c.realname == "" || session.capState == caps.NegotiatingState {
  226. return
  227. }
  228. if c.isSTSOnly {
  229. server.playSTSBurst(session)
  230. return true
  231. }
  232. // client MUST send PASS if necessary, or authenticate with SASL if necessary,
  233. // before completing the other registration commands
  234. config := server.Config()
  235. authOutcome := c.isAuthorized(server, config, session, c.requireSASL)
  236. var quitMessage string
  237. switch authOutcome {
  238. case authFailPass:
  239. quitMessage = c.t("Password incorrect")
  240. c.Send(nil, server.name, ERR_PASSWDMISMATCH, "*", quitMessage)
  241. case authFailSaslRequired, authFailTorSaslRequired:
  242. quitMessage = c.requireSASLMessage
  243. if quitMessage == "" {
  244. quitMessage = c.t("You must log in with SASL to join this server")
  245. }
  246. c.Send(nil, c.server.name, "FAIL", "*", "ACCOUNT_REQUIRED", quitMessage)
  247. }
  248. if authOutcome != authSuccess {
  249. c.Quit(quitMessage, nil)
  250. return true
  251. }
  252. c.requireSASLMessage = ""
  253. rb := NewResponseBuffer(session)
  254. nickError := performNickChange(server, c, c, session, c.preregNick, rb)
  255. rb.Send(true)
  256. if nickError == errInsecureReattach {
  257. c.Quit(c.t("You can't mix secure and insecure connections to this account"), nil)
  258. return true
  259. } else if nickError != nil {
  260. c.preregNick = ""
  261. return false
  262. }
  263. if session.client != c {
  264. // reattached, bail out.
  265. // we'll play the reg burst later, on the new goroutine associated with
  266. // (thisSession, otherClient). This is to avoid having to transfer state
  267. // like nickname, hostname, etc. to show the correct values in the reg burst.
  268. return false
  269. }
  270. // Apply default user modes (without updating the invisible counter)
  271. // The number of invisible users will be updated by server.stats.Register
  272. // if we're using default user mode +i.
  273. for _, defaultMode := range config.Accounts.defaultUserModes {
  274. c.SetMode(defaultMode, true)
  275. }
  276. // count new user in statistics (before checking KLINEs, see #1303)
  277. server.stats.Register(c.HasMode(modes.Invisible))
  278. // check KLINEs
  279. isBanned, info := server.klines.CheckMasks(c.AllNickmasks()...)
  280. if isBanned {
  281. c.Quit(info.BanMessage(c.t("You are banned from this server (%s)")), nil)
  282. return true
  283. }
  284. server.playRegistrationBurst(session)
  285. return false
  286. }
  287. func (server *Server) playSTSBurst(session *Session) {
  288. nick := utils.SafeErrorParam(session.client.preregNick)
  289. session.Send(nil, server.name, RPL_WELCOME, nick, fmt.Sprintf("Welcome to the Internet Relay Network %s", nick))
  290. session.Send(nil, server.name, RPL_YOURHOST, nick, fmt.Sprintf("Your host is %[1]s, running version %[2]s", server.name, "oragono"))
  291. session.Send(nil, server.name, RPL_CREATED, nick, fmt.Sprintf("This server was created %s", time.Time{}.Format(time.RFC1123)))
  292. session.Send(nil, server.name, RPL_MYINFO, nick, server.name, "oragono", "o", "o", "o")
  293. session.Send(nil, server.name, RPL_ISUPPORT, nick, "CASEMAPPING=ascii", "are supported by this server")
  294. session.Send(nil, server.name, ERR_NOMOTD, nick, "MOTD is unavailable")
  295. for _, line := range server.Config().Server.STS.bannerLines {
  296. session.Send(nil, server.name, "NOTICE", nick, line)
  297. }
  298. }
  299. func (server *Server) playRegistrationBurst(session *Session) {
  300. c := session.client
  301. // continue registration
  302. d := c.Details()
  303. server.logger.Info("connect", fmt.Sprintf("Client connected [%s] [u:%s] [r:%s]", d.nick, d.username, d.realname))
  304. server.snomasks.Send(sno.LocalConnects, fmt.Sprintf("Client connected [%s] [u:%s] [h:%s] [ip:%s] [r:%s]", d.nick, d.username, session.rawHostname, session.IP().String(), d.realname))
  305. // send welcome text
  306. //NOTE(dan): we specifically use the NICK here instead of the nickmask
  307. // see http://modern.ircdocs.horse/#rplwelcome-001 for details on why we avoid using the nickmask
  308. session.Send(nil, server.name, RPL_WELCOME, d.nick, fmt.Sprintf(c.t("Welcome to the Internet Relay Network %s"), d.nick))
  309. session.Send(nil, server.name, RPL_YOURHOST, d.nick, fmt.Sprintf(c.t("Your host is %[1]s, running version %[2]s"), server.name, Ver))
  310. session.Send(nil, server.name, RPL_CREATED, d.nick, fmt.Sprintf(c.t("This server was created %s"), server.ctime.Format(time.RFC1123)))
  311. session.Send(nil, server.name, RPL_MYINFO, d.nick, server.name, Ver, rplMyInfo1, rplMyInfo2, rplMyInfo3)
  312. rb := NewResponseBuffer(session)
  313. server.RplISupport(c, rb)
  314. server.Lusers(c, rb)
  315. server.MOTD(c, rb)
  316. rb.Send(true)
  317. modestring := c.ModeString()
  318. if modestring != "+" {
  319. session.Send(nil, server.name, RPL_UMODEIS, d.nick, modestring)
  320. }
  321. c.attemptAutoOper(session)
  322. if server.logger.IsLoggingRawIO() {
  323. session.Send(nil, c.server.name, "NOTICE", d.nick, c.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  324. }
  325. }
  326. // RplISupport outputs our ISUPPORT lines to the client. This is used on connection and in VERSION responses.
  327. func (server *Server) RplISupport(client *Client, rb *ResponseBuffer) {
  328. translatedISupport := client.t("are supported by this server")
  329. nick := client.Nick()
  330. config := server.Config()
  331. for _, cachedTokenLine := range config.Server.isupport.CachedReply {
  332. length := len(cachedTokenLine) + 2
  333. tokenline := make([]string, length)
  334. tokenline[0] = nick
  335. copy(tokenline[1:], cachedTokenLine)
  336. tokenline[length-1] = translatedISupport
  337. rb.Add(nil, server.name, RPL_ISUPPORT, tokenline...)
  338. }
  339. }
  340. func (server *Server) Lusers(client *Client, rb *ResponseBuffer) {
  341. nick := client.Nick()
  342. stats := server.stats.GetValues()
  343. rb.Add(nil, server.name, RPL_LUSERCLIENT, nick, fmt.Sprintf(client.t("There are %[1]d users and %[2]d invisible on %[3]d server(s)"), stats.Total-stats.Invisible, stats.Invisible, 1))
  344. rb.Add(nil, server.name, RPL_LUSEROP, nick, strconv.Itoa(stats.Operators), client.t("IRC Operators online"))
  345. rb.Add(nil, server.name, RPL_LUSERUNKNOWN, nick, strconv.Itoa(stats.Unknown), client.t("unregistered connections"))
  346. rb.Add(nil, server.name, RPL_LUSERCHANNELS, nick, strconv.Itoa(server.channels.Len()), client.t("channels formed"))
  347. rb.Add(nil, server.name, RPL_LUSERME, nick, fmt.Sprintf(client.t("I have %[1]d clients and %[2]d servers"), stats.Total, 0))
  348. total := strconv.Itoa(stats.Total)
  349. max := strconv.Itoa(stats.Max)
  350. rb.Add(nil, server.name, RPL_LOCALUSERS, nick, total, max, fmt.Sprintf(client.t("Current local users %[1]s, max %[2]s"), total, max))
  351. rb.Add(nil, server.name, RPL_GLOBALUSERS, nick, total, max, fmt.Sprintf(client.t("Current global users %[1]s, max %[2]s"), total, max))
  352. }
  353. // MOTD serves the Message of the Day.
  354. func (server *Server) MOTD(client *Client, rb *ResponseBuffer) {
  355. motdLines := server.Config().Server.motdLines
  356. if len(motdLines) < 1 {
  357. rb.Add(nil, server.name, ERR_NOMOTD, client.nick, client.t("MOTD File is missing"))
  358. return
  359. }
  360. rb.Add(nil, server.name, RPL_MOTDSTART, client.nick, fmt.Sprintf(client.t("- %s Message of the day - "), server.name))
  361. for _, line := range motdLines {
  362. rb.Add(nil, server.name, RPL_MOTD, client.nick, line)
  363. }
  364. rb.Add(nil, server.name, RPL_ENDOFMOTD, client.nick, client.t("End of MOTD command"))
  365. }
  366. // WhoisChannelsNames returns the common channel names between two users.
  367. func (client *Client) WhoisChannelsNames(target *Client, multiPrefix bool) []string {
  368. var chstrs []string
  369. for _, channel := range target.Channels() {
  370. // channel is secret and the target can't see it
  371. if !client.HasMode(modes.Operator) {
  372. if (target.HasMode(modes.Invisible) || channel.flags.HasMode(modes.Secret)) && !channel.hasClient(client) {
  373. continue
  374. }
  375. }
  376. chstrs = append(chstrs, channel.ClientPrefixes(target, multiPrefix)+channel.name)
  377. }
  378. return chstrs
  379. }
  380. func (client *Client) getWhoisOf(target *Client, hasPrivs bool, rb *ResponseBuffer) {
  381. cnick := client.Nick()
  382. targetInfo := target.Details()
  383. rb.Add(nil, client.server.name, RPL_WHOISUSER, cnick, targetInfo.nick, targetInfo.username, targetInfo.hostname, "*", targetInfo.realname)
  384. tnick := targetInfo.nick
  385. whoischannels := client.WhoisChannelsNames(target, rb.session.capabilities.Has(caps.MultiPrefix))
  386. if whoischannels != nil {
  387. rb.Add(nil, client.server.name, RPL_WHOISCHANNELS, cnick, tnick, strings.Join(whoischannels, " "))
  388. }
  389. if target.HasMode(modes.Operator) && operStatusVisible(client, target, hasPrivs) {
  390. tOper := target.Oper()
  391. if tOper != nil {
  392. rb.Add(nil, client.server.name, RPL_WHOISOPERATOR, cnick, tnick, tOper.WhoisLine)
  393. }
  394. }
  395. if client == target || hasPrivs {
  396. rb.Add(nil, client.server.name, RPL_WHOISACTUALLY, cnick, tnick, fmt.Sprintf("%s@%s", targetInfo.username, target.RawHostname()), target.IPString(), client.t("Actual user@host, Actual IP"))
  397. rb.Add(nil, client.server.name, RPL_WHOISMODES, cnick, tnick, fmt.Sprintf(client.t("is using modes +%s"), target.modes.String()))
  398. }
  399. if target.HasMode(modes.TLS) {
  400. rb.Add(nil, client.server.name, RPL_WHOISSECURE, cnick, tnick, client.t("is using a secure connection"))
  401. }
  402. if targetInfo.accountName != "*" {
  403. rb.Add(nil, client.server.name, RPL_WHOISACCOUNT, cnick, tnick, targetInfo.accountName, client.t("is logged in as"))
  404. }
  405. if target.HasMode(modes.Bot) {
  406. rb.Add(nil, client.server.name, RPL_WHOISBOT, cnick, tnick, ircfmt.Unescape(fmt.Sprintf(client.t("is a $bBot$b on %s"), client.server.Config().Network.Name)))
  407. }
  408. if client == target || hasPrivs {
  409. for _, session := range target.Sessions() {
  410. if session.certfp != "" {
  411. rb.Add(nil, client.server.name, RPL_WHOISCERTFP, cnick, tnick, fmt.Sprintf(client.t("has client certificate fingerprint %s"), session.certfp))
  412. }
  413. }
  414. }
  415. rb.Add(nil, client.server.name, RPL_WHOISIDLE, cnick, tnick, strconv.FormatUint(target.IdleSeconds(), 10), strconv.FormatInt(target.SignonTime(), 10), client.t("seconds idle, signon time"))
  416. if away, awayMessage := target.Away(); away {
  417. rb.Add(nil, client.server.name, RPL_AWAY, cnick, tnick, awayMessage)
  418. }
  419. }
  420. // rehash reloads the config and applies the changes from the config file.
  421. func (server *Server) rehash() error {
  422. server.logger.Info("server", "Attempting rehash")
  423. // only let one REHASH go on at a time
  424. server.rehashMutex.Lock()
  425. defer server.rehashMutex.Unlock()
  426. server.logger.Debug("server", "Got rehash lock")
  427. config, err := LoadConfig(server.configFilename)
  428. if err != nil {
  429. server.logger.Error("server", "failed to load config file", err.Error())
  430. return err
  431. }
  432. err = server.applyConfig(config)
  433. if err != nil {
  434. server.logger.Error("server", "Failed to rehash", err.Error())
  435. return err
  436. }
  437. server.logger.Info("server", "Rehash completed successfully")
  438. return nil
  439. }
  440. func (server *Server) applyConfig(config *Config) (err error) {
  441. oldConfig := server.Config()
  442. initial := oldConfig == nil
  443. if initial {
  444. server.configFilename = config.Filename
  445. server.name = config.Server.Name
  446. server.nameCasefolded = config.Server.nameCasefolded
  447. globalCasemappingSetting = config.Server.Casemapping
  448. globalUtf8EnforcementSetting = config.Server.EnforceUtf8
  449. } else {
  450. // enforce configs that can't be changed after launch:
  451. if server.name != config.Server.Name {
  452. return fmt.Errorf("Server name cannot be changed after launching the server, rehash aborted")
  453. } else if oldConfig.Datastore.Path != config.Datastore.Path {
  454. return fmt.Errorf("Datastore path cannot be changed after launching the server, rehash aborted")
  455. } else if globalCasemappingSetting != config.Server.Casemapping {
  456. return fmt.Errorf("Casemapping cannot be changed after launching the server, rehash aborted")
  457. } else if globalUtf8EnforcementSetting != config.Server.EnforceUtf8 {
  458. return fmt.Errorf("UTF-8 enforcement cannot be changed after launching the server, rehash aborted")
  459. } else if oldConfig.Accounts.Multiclient.AlwaysOn != config.Accounts.Multiclient.AlwaysOn {
  460. return fmt.Errorf("Default always-on setting cannot be changed after launching the server, rehash aborted")
  461. } else if oldConfig.Server.Relaymsg.Enabled != config.Server.Relaymsg.Enabled {
  462. return fmt.Errorf("Cannot enable or disable relaying after launching the server, rehash aborted")
  463. } else if oldConfig.Server.Relaymsg.Separators != config.Server.Relaymsg.Separators {
  464. return fmt.Errorf("Cannot change relaying separators after launching the server, rehash aborted")
  465. } else if oldConfig.Server.IPCheckScript.MaxConcurrency != config.Server.IPCheckScript.MaxConcurrency ||
  466. oldConfig.Accounts.AuthScript.MaxConcurrency != config.Accounts.AuthScript.MaxConcurrency {
  467. return fmt.Errorf("Cannot change max-concurrency for scripts after launching the server, rehash aborted")
  468. } else if oldConfig.Server.OverrideServicesHostname != config.Server.OverrideServicesHostname {
  469. return fmt.Errorf("Cannot change override-services-hostname after launching the server, rehash aborted")
  470. }
  471. }
  472. server.logger.Info("server", "Using config file", server.configFilename)
  473. // first, reload config sections for functionality implemented in subpackages:
  474. wasLoggingRawIO := !initial && server.logger.IsLoggingRawIO()
  475. err = server.logger.ApplyConfig(config.Logging)
  476. if err != nil {
  477. return err
  478. }
  479. nowLoggingRawIO := server.logger.IsLoggingRawIO()
  480. // notify existing clients if raw i/o logging was enabled by a rehash
  481. sendRawOutputNotice := !wasLoggingRawIO && nowLoggingRawIO
  482. server.connectionLimiter.ApplyConfig(&config.Server.IPLimits)
  483. tlConf := &config.Server.TorListeners
  484. server.torLimiter.Configure(tlConf.MaxConnections, tlConf.ThrottleDuration, tlConf.MaxConnectionsPerDuration)
  485. // Translations
  486. server.logger.Debug("server", "Regenerating HELP indexes for new languages")
  487. server.helpIndexManager.GenerateIndices(config.languageManager)
  488. if initial {
  489. maxIPConc := int(config.Server.IPCheckScript.MaxConcurrency)
  490. if maxIPConc != 0 {
  491. server.semaphores.IPCheckScript.Initialize(maxIPConc)
  492. }
  493. maxAuthConc := int(config.Accounts.AuthScript.MaxConcurrency)
  494. if maxAuthConc != 0 {
  495. server.semaphores.AuthScript.Initialize(maxAuthConc)
  496. }
  497. if err := overrideServicePrefixes(config.Server.OverrideServicesHostname); err != nil {
  498. return err
  499. }
  500. }
  501. if oldConfig != nil {
  502. // if certain features were enabled by rehash, we need to load the corresponding data
  503. // from the store
  504. if !oldConfig.Accounts.NickReservation.Enabled {
  505. server.accounts.buildNickToAccountIndex(config)
  506. }
  507. if !oldConfig.Channels.Registration.Enabled {
  508. server.channels.loadRegisteredChannels(config)
  509. }
  510. // resize history buffers as needed
  511. if config.historyChangedFrom(oldConfig) {
  512. for _, channel := range server.channels.Channels() {
  513. channel.resizeHistory(config)
  514. }
  515. for _, client := range server.clients.AllClients() {
  516. client.resizeHistory(config)
  517. }
  518. }
  519. if oldConfig.Accounts.Registration.Throttling != config.Accounts.Registration.Throttling {
  520. server.accounts.resetRegisterThrottle(config)
  521. }
  522. }
  523. server.logger.Info("server", "Using datastore", config.Datastore.Path)
  524. if initial {
  525. if err := server.loadDatastore(config); err != nil {
  526. return err
  527. }
  528. } else {
  529. if config.Datastore.MySQL.Enabled && config.Datastore.MySQL != oldConfig.Datastore.MySQL {
  530. server.historyDB.SetConfig(config.Datastore.MySQL)
  531. }
  532. }
  533. // now that the datastore is initialized, we can load the cloak secret from it
  534. // XXX this modifies config after the initial load, which is naughty,
  535. // but there's no data race because we haven't done SetConfig yet
  536. config.Server.Cloaks.SetSecret(LoadCloakSecret(server.store))
  537. // activate the new config
  538. server.SetConfig(config)
  539. // load [dk]-lines, registered users and channels, etc.
  540. if initial {
  541. if err := server.loadFromDatastore(config); err != nil {
  542. return err
  543. }
  544. }
  545. // burst new and removed caps
  546. addedCaps, removedCaps := config.Diff(oldConfig)
  547. var capBurstSessions []*Session
  548. added := make(map[caps.Version][]string)
  549. var removed []string
  550. if !addedCaps.Empty() || !removedCaps.Empty() {
  551. capBurstSessions = server.clients.AllWithCapsNotify()
  552. added[caps.Cap301] = addedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  553. added[caps.Cap302] = addedCaps.Strings(caps.Cap302, config.Server.capValues, 0)
  554. // removed never has values, so we leave it as Cap301
  555. removed = removedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  556. }
  557. for _, sSession := range capBurstSessions {
  558. // DEL caps and then send NEW ones so that updated caps get removed/added correctly
  559. if !removedCaps.Empty() {
  560. for _, capStr := range removed {
  561. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "DEL", capStr)
  562. }
  563. }
  564. if !addedCaps.Empty() {
  565. for _, capStr := range added[sSession.capVersion] {
  566. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "NEW", capStr)
  567. }
  568. }
  569. }
  570. server.setupPprofListener(config)
  571. // set RPL_ISUPPORT
  572. var newISupportReplies [][]string
  573. if oldConfig != nil {
  574. newISupportReplies = oldConfig.Server.isupport.GetDifference(&config.Server.isupport)
  575. }
  576. if len(config.Server.ProxyAllowedFrom) != 0 {
  577. server.logger.Info("server", "Proxied IPs will be accepted from", strings.Join(config.Server.ProxyAllowedFrom, ", "))
  578. }
  579. // we are now open for business
  580. err = server.setupListeners(config)
  581. if !initial {
  582. // push new info to all of our clients
  583. for _, sClient := range server.clients.AllClients() {
  584. for _, tokenline := range newISupportReplies {
  585. sClient.Send(nil, server.name, RPL_ISUPPORT, append([]string{sClient.nick}, tokenline...)...)
  586. }
  587. if sendRawOutputNotice {
  588. sClient.Notice(sClient.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  589. }
  590. }
  591. }
  592. return err
  593. }
  594. func (server *Server) setupPprofListener(config *Config) {
  595. pprofListener := ""
  596. if config.Debug.PprofListener != nil {
  597. pprofListener = *config.Debug.PprofListener
  598. }
  599. if server.pprofServer != nil {
  600. if pprofListener == "" || (pprofListener != server.pprofServer.Addr) {
  601. server.logger.Info("server", "Stopping pprof listener", server.pprofServer.Addr)
  602. server.pprofServer.Close()
  603. server.pprofServer = nil
  604. }
  605. }
  606. if pprofListener != "" && server.pprofServer == nil {
  607. ps := http.Server{
  608. Addr: pprofListener,
  609. }
  610. go func() {
  611. if err := ps.ListenAndServe(); err != nil {
  612. server.logger.Error("server", "pprof listener failed", err.Error())
  613. }
  614. }()
  615. server.pprofServer = &ps
  616. server.logger.Info("server", "Started pprof listener", server.pprofServer.Addr)
  617. }
  618. }
  619. func (server *Server) loadDatastore(config *Config) error {
  620. // open the datastore and load server state for which it (rather than config)
  621. // is the source of truth
  622. _, err := os.Stat(config.Datastore.Path)
  623. if os.IsNotExist(err) {
  624. server.logger.Warning("server", "database does not exist, creating it", config.Datastore.Path)
  625. err = initializeDB(config.Datastore.Path)
  626. if err != nil {
  627. return err
  628. }
  629. }
  630. db, err := OpenDatabase(config)
  631. if err == nil {
  632. server.store = db
  633. return nil
  634. } else {
  635. return fmt.Errorf("Failed to open datastore: %s", err.Error())
  636. }
  637. }
  638. func (server *Server) loadFromDatastore(config *Config) (err error) {
  639. // load *lines (from the datastores)
  640. server.logger.Debug("server", "Loading D/Klines")
  641. server.loadDLines()
  642. server.loadKLines()
  643. server.channelRegistry.Initialize(server)
  644. server.channels.Initialize(server)
  645. server.accounts.Initialize(server)
  646. if config.Datastore.MySQL.Enabled {
  647. server.historyDB.Initialize(server.logger, config.Datastore.MySQL)
  648. err = server.historyDB.Open()
  649. if err != nil {
  650. server.logger.Error("internal", "could not connect to mysql", err.Error())
  651. return err
  652. }
  653. }
  654. return nil
  655. }
  656. func (server *Server) setupListeners(config *Config) (err error) {
  657. logListener := func(addr string, config utils.ListenerConfig) {
  658. server.logger.Info("listeners",
  659. fmt.Sprintf("now listening on %s, tls=%t, proxy=%t, tor=%t, websocket=%t.", addr, (config.TLSConfig != nil), config.RequireProxy, config.Tor, config.WebSocket),
  660. )
  661. }
  662. // update or destroy all existing listeners
  663. for addr := range server.listeners {
  664. currentListener := server.listeners[addr]
  665. newConfig, stillConfigured := config.Server.trueListeners[addr]
  666. if stillConfigured {
  667. if reloadErr := currentListener.Reload(newConfig); reloadErr == nil {
  668. logListener(addr, newConfig)
  669. } else {
  670. // stop the listener; we will attempt to replace it below
  671. currentListener.Stop()
  672. delete(server.listeners, addr)
  673. }
  674. } else {
  675. currentListener.Stop()
  676. delete(server.listeners, addr)
  677. server.logger.Info("listeners", fmt.Sprintf("stopped listening on %s.", addr))
  678. }
  679. }
  680. publicPlaintextListener := ""
  681. // create new listeners that were not previously configured,
  682. // or that couldn't be reloaded above:
  683. for newAddr, newConfig := range config.Server.trueListeners {
  684. if strings.HasPrefix(newAddr, ":") && !newConfig.Tor && !newConfig.STSOnly && newConfig.TLSConfig == nil {
  685. publicPlaintextListener = newAddr
  686. }
  687. _, exists := server.listeners[newAddr]
  688. if !exists {
  689. // make a new listener
  690. newListener, newErr := NewListener(server, newAddr, newConfig, config.Server.UnixBindMode)
  691. if newErr == nil {
  692. server.listeners[newAddr] = newListener
  693. logListener(newAddr, newConfig)
  694. } else {
  695. server.logger.Error("server", "couldn't listen on", newAddr, newErr.Error())
  696. err = newErr
  697. }
  698. }
  699. }
  700. if publicPlaintextListener != "" {
  701. server.logger.Warning("listeners", fmt.Sprintf("Your server is configured with public plaintext listener %s. Consider disabling it for improved security and privacy.", publicPlaintextListener))
  702. }
  703. return
  704. }
  705. // Gets the abstract sequence from which we're going to query history;
  706. // we may already know the channel we're querying, or we may have
  707. // to look it up via a string query. This function is responsible for
  708. // privilege checking.
  709. func (server *Server) GetHistorySequence(providedChannel *Channel, client *Client, query string) (channel *Channel, sequence history.Sequence, err error) {
  710. config := server.Config()
  711. // 4 cases: {persistent, ephemeral} x {normal, conversation}
  712. // with ephemeral history, target is implicit in the choice of `hist`,
  713. // and correspondent is "" if we're retrieving a channel or *, and the correspondent's name
  714. // if we're retrieving a DM conversation ("query buffer"). with persistent history,
  715. // target is always nonempty, and correspondent is either empty or nonempty as before.
  716. var status HistoryStatus
  717. var target, correspondent string
  718. var hist *history.Buffer
  719. channel = providedChannel
  720. if channel == nil {
  721. if strings.HasPrefix(query, "#") {
  722. channel = server.channels.Get(query)
  723. if channel == nil {
  724. return
  725. }
  726. }
  727. }
  728. if channel != nil {
  729. if !channel.hasClient(client) {
  730. err = errInsufficientPrivs
  731. return
  732. }
  733. status, target = channel.historyStatus(config)
  734. switch status {
  735. case HistoryEphemeral:
  736. hist = &channel.history
  737. case HistoryPersistent:
  738. // already set `target`
  739. default:
  740. return
  741. }
  742. } else {
  743. status, target = client.historyStatus(config)
  744. if query != "*" {
  745. correspondent, err = CasefoldName(query)
  746. if err != nil {
  747. return
  748. }
  749. }
  750. switch status {
  751. case HistoryEphemeral:
  752. hist = &client.history
  753. case HistoryPersistent:
  754. // already set `target`, and `correspondent` if necessary
  755. default:
  756. return
  757. }
  758. }
  759. var cutoff time.Time
  760. if config.History.Restrictions.ExpireTime != 0 {
  761. cutoff = time.Now().UTC().Add(-time.Duration(config.History.Restrictions.ExpireTime))
  762. }
  763. // #836: registration date cutoff is always enforced for DMs
  764. if config.History.Restrictions.EnforceRegistrationDate || channel == nil {
  765. regCutoff := client.historyCutoff()
  766. // take the later of the two cutoffs
  767. if regCutoff.After(cutoff) {
  768. cutoff = regCutoff
  769. }
  770. }
  771. // #836 again: grace period is never applied to DMs
  772. if !cutoff.IsZero() && channel != nil {
  773. cutoff = cutoff.Add(-time.Duration(config.History.Restrictions.GracePeriod))
  774. }
  775. if hist != nil {
  776. sequence = hist.MakeSequence(correspondent, cutoff)
  777. } else if target != "" {
  778. sequence = server.historyDB.MakeSequence(target, correspondent, cutoff)
  779. }
  780. return
  781. }
  782. func (server *Server) ForgetHistory(accountName string) {
  783. // sanity check
  784. if accountName == "*" {
  785. return
  786. }
  787. config := server.Config()
  788. if !config.History.Enabled {
  789. return
  790. }
  791. if cfAccount, err := CasefoldName(accountName); err == nil {
  792. server.historyDB.Forget(cfAccount)
  793. }
  794. persistent := config.History.Persistent
  795. if persistent.Enabled && persistent.UnregisteredChannels && persistent.RegisteredChannels == PersistentMandatory && persistent.DirectMessages == PersistentMandatory {
  796. return
  797. }
  798. predicate := func(item *history.Item) bool { return item.AccountName == accountName }
  799. for _, channel := range server.channels.Channels() {
  800. channel.history.Delete(predicate)
  801. }
  802. for _, client := range server.clients.AllClients() {
  803. client.history.Delete(predicate)
  804. }
  805. }
  806. // deletes a message. target is a hint about what buffer it's in (not required for
  807. // persistent history, where all the msgids are indexed together). if accountName
  808. // is anything other than "*", it must match the recorded AccountName of the message
  809. func (server *Server) DeleteMessage(target, msgid, accountName string) (err error) {
  810. config := server.Config()
  811. var hist *history.Buffer
  812. if target != "" {
  813. if target[0] == '#' {
  814. channel := server.channels.Get(target)
  815. if channel != nil {
  816. if status, _ := channel.historyStatus(config); status == HistoryEphemeral {
  817. hist = &channel.history
  818. }
  819. }
  820. } else {
  821. client := server.clients.Get(target)
  822. if client != nil {
  823. if status, _ := client.historyStatus(config); status == HistoryEphemeral {
  824. hist = &client.history
  825. }
  826. }
  827. }
  828. }
  829. if hist == nil {
  830. err = server.historyDB.DeleteMsgid(msgid, accountName)
  831. } else {
  832. count := hist.Delete(func(item *history.Item) bool {
  833. return item.Message.Msgid == msgid && (accountName == "*" || item.AccountName == accountName)
  834. })
  835. if count == 0 {
  836. err = errNoop
  837. }
  838. }
  839. return
  840. }
  841. // elistMatcher takes and matches ELIST conditions
  842. type elistMatcher struct {
  843. MinClientsActive bool
  844. MinClients int
  845. MaxClientsActive bool
  846. MaxClients int
  847. }
  848. // Matches checks whether the given channel matches our matches.
  849. func (matcher *elistMatcher) Matches(channel *Channel) bool {
  850. if matcher.MinClientsActive {
  851. if len(channel.Members()) < matcher.MinClients {
  852. return false
  853. }
  854. }
  855. if matcher.MaxClientsActive {
  856. if len(channel.Members()) < len(channel.members) {
  857. return false
  858. }
  859. }
  860. return true
  861. }
  862. var (
  863. infoString1 = strings.Split(` ▄▄▄ ▄▄▄· ▄▄ • ▐ ▄
  864. ▪ ▀▄ █·▐█ ▀█ ▐█ ▀ ▪▪ •█▌▐█▪
  865. ▄█▀▄ ▐▀▀▄ ▄█▀▀█ ▄█ ▀█▄ ▄█▀▄▪▐█▐▐▌ ▄█▀▄
  866. ▐█▌.▐▌▐█•█▌▐█ ▪▐▌▐█▄▪▐█▐█▌ ▐▌██▐█▌▐█▌.▐▌
  867. ▀█▄▀▪.▀ ▀ ▀ ▀ ·▀▀▀▀ ▀█▄▀ ▀▀ █▪ ▀█▄▀▪
  868. https://oragono.io/
  869. https://github.com/oragono/oragono
  870. https://crowdin.com/project/oragono
  871. `, "\n")
  872. infoString2 = strings.Split(` Daniel Oakley, DanielOaks, <daniel@danieloaks.net>
  873. Shivaram Lingamneni, slingamn, <slingamn@cs.stanford.edu>
  874. `, "\n")
  875. infoString3 = strings.Split(` Jeremy Latt, jlatt
  876. Edmund Huber, edmund-huber
  877. `, "\n")
  878. )