You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

server.go 33KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007
  1. // Copyright (c) 2012-2014 Jeremy Latt
  2. // Copyright (c) 2014-2015 Edmund Huber
  3. // Copyright (c) 2016-2017 Daniel Oaks <daniel@danieloaks.net>
  4. // released under the MIT license
  5. package irc
  6. import (
  7. "bufio"
  8. "fmt"
  9. "net"
  10. "net/http"
  11. _ "net/http/pprof"
  12. "os"
  13. "os/signal"
  14. "strconv"
  15. "strings"
  16. "sync"
  17. "syscall"
  18. "time"
  19. "unsafe"
  20. "github.com/goshuirc/irc-go/ircfmt"
  21. "github.com/oragono/oragono/irc/caps"
  22. "github.com/oragono/oragono/irc/connection_limits"
  23. "github.com/oragono/oragono/irc/history"
  24. "github.com/oragono/oragono/irc/logger"
  25. "github.com/oragono/oragono/irc/modes"
  26. "github.com/oragono/oragono/irc/mysql"
  27. "github.com/oragono/oragono/irc/sno"
  28. "github.com/oragono/oragono/irc/utils"
  29. "github.com/tidwall/buntdb"
  30. )
  31. var (
  32. // common error line to sub values into
  33. errorMsg = "ERROR :%s\r\n"
  34. // three final parameters of 004 RPL_MYINFO, enumerating our supported modes
  35. rplMyInfo1, rplMyInfo2, rplMyInfo3 = modes.RplMyInfo()
  36. // whitelist of caps to serve on the STS-only listener. In particular,
  37. // never advertise SASL, to discourage people from sending their passwords:
  38. stsOnlyCaps = caps.NewSet(caps.STS, caps.MessageTags, caps.ServerTime, caps.LabeledResponse, caps.Nope)
  39. // we only have standard channels for now. TODO: any updates to this
  40. // will also need to be reflected in CasefoldChannel
  41. chanTypes = "#"
  42. throttleMessage = "You have attempted to connect too many times within a short duration. Wait a while, and you will be able to connect."
  43. )
  44. // Server is the main Oragono server.
  45. type Server struct {
  46. accounts AccountManager
  47. channels ChannelManager
  48. channelRegistry ChannelRegistry
  49. clients ClientManager
  50. config unsafe.Pointer
  51. configFilename string
  52. connectionLimiter connection_limits.Limiter
  53. ctime time.Time
  54. dlines *DLineManager
  55. helpIndexManager HelpIndexManager
  56. klines *KLineManager
  57. listeners map[string]IRCListener
  58. logger *logger.Manager
  59. monitorManager MonitorManager
  60. name string
  61. nameCasefolded string
  62. rehashMutex sync.Mutex // tier 4
  63. rehashSignal chan os.Signal
  64. pprofServer *http.Server
  65. resumeManager ResumeManager
  66. signals chan os.Signal
  67. snomasks SnoManager
  68. store *buntdb.DB
  69. historyDB mysql.MySQL
  70. torLimiter connection_limits.TorLimiter
  71. whoWas WhoWasList
  72. stats Stats
  73. semaphores ServerSemaphores
  74. }
  75. // NewServer returns a new Oragono server.
  76. func NewServer(config *Config, logger *logger.Manager) (*Server, error) {
  77. // initialize data structures
  78. server := &Server{
  79. ctime: time.Now().UTC(),
  80. listeners: make(map[string]IRCListener),
  81. logger: logger,
  82. rehashSignal: make(chan os.Signal, 1),
  83. signals: make(chan os.Signal, len(ServerExitSignals)),
  84. }
  85. server.clients.Initialize()
  86. server.semaphores.Initialize()
  87. server.resumeManager.Initialize(server)
  88. server.whoWas.Initialize(config.Limits.WhowasEntries)
  89. server.monitorManager.Initialize()
  90. server.snomasks.Initialize()
  91. if err := server.applyConfig(config); err != nil {
  92. return nil, err
  93. }
  94. // Attempt to clean up when receiving these signals.
  95. signal.Notify(server.signals, ServerExitSignals...)
  96. signal.Notify(server.rehashSignal, syscall.SIGHUP)
  97. return server, nil
  98. }
  99. // Shutdown shuts down the server.
  100. func (server *Server) Shutdown() {
  101. //TODO(dan): Make sure we disallow new nicks
  102. for _, client := range server.clients.AllClients() {
  103. client.Notice("Server is shutting down")
  104. }
  105. if err := server.store.Close(); err != nil {
  106. server.logger.Error("shutdown", fmt.Sprintln("Could not close datastore:", err))
  107. }
  108. server.historyDB.Close()
  109. }
  110. // Run starts the server.
  111. func (server *Server) Run() {
  112. // defer closing db/store
  113. defer server.store.Close()
  114. for {
  115. select {
  116. case <-server.signals:
  117. server.Shutdown()
  118. return
  119. case <-server.rehashSignal:
  120. go func() {
  121. server.logger.Info("server", "Rehashing due to SIGHUP")
  122. server.rehash()
  123. }()
  124. }
  125. }
  126. }
  127. func (server *Server) checkBans(ipaddr net.IP) (banned bool, message string) {
  128. // check DLINEs
  129. isBanned, info := server.dlines.CheckIP(ipaddr)
  130. if isBanned {
  131. server.logger.Info("connect-ip", fmt.Sprintf("Client from %v rejected by d-line", ipaddr))
  132. return true, info.BanMessage("You are banned from this server (%s)")
  133. }
  134. // check connection limits
  135. err := server.connectionLimiter.AddClient(ipaddr)
  136. if err == connection_limits.ErrLimitExceeded {
  137. // too many connections from one client, tell the client and close the connection
  138. server.logger.Info("connect-ip", fmt.Sprintf("Client from %v rejected for connection limit", ipaddr))
  139. return true, "Too many clients from your network"
  140. } else if err == connection_limits.ErrThrottleExceeded {
  141. duration := server.Config().Server.IPLimits.BanDuration
  142. if duration == 0 {
  143. return false, ""
  144. }
  145. server.dlines.AddIP(ipaddr, duration, throttleMessage, "Exceeded automated connection throttle", "auto.connection.throttler")
  146. // they're DLINE'd for 15 minutes or whatever, so we can reset the connection throttle now,
  147. // and once their temporary DLINE is finished they can fill up the throttler again
  148. server.connectionLimiter.ResetThrottle(ipaddr)
  149. // this might not show up properly on some clients, but our objective here is just to close it out before it has a load impact on us
  150. server.logger.Info(
  151. "connect-ip",
  152. fmt.Sprintf("Client from %v exceeded connection throttle, d-lining for %v", ipaddr, duration))
  153. return true, throttleMessage
  154. } else if err != nil {
  155. server.logger.Warning("internal", "unexpected ban result", err.Error())
  156. }
  157. return false, ""
  158. }
  159. func (server *Server) checkTorLimits() (banned bool, message string) {
  160. switch server.torLimiter.AddClient() {
  161. case connection_limits.ErrLimitExceeded:
  162. return true, "Too many clients from the Tor network"
  163. case connection_limits.ErrThrottleExceeded:
  164. return true, "Exceeded connection throttle for the Tor network"
  165. default:
  166. return false, ""
  167. }
  168. }
  169. //
  170. // server functionality
  171. //
  172. func (server *Server) tryRegister(c *Client, session *Session) (exiting bool) {
  173. // if the session just sent us a RESUME line, try to resume
  174. if session.resumeDetails != nil {
  175. session.tryResume()
  176. return // whether we succeeded or failed, either way `c` is not getting registered
  177. }
  178. // try to complete registration normally
  179. // XXX(#1057) username can be filled in by an ident query without the client
  180. // having sent USER: check for both username and realname to ensure they did
  181. if c.preregNick == "" || c.username == "" || c.realname == "" || session.capState == caps.NegotiatingState {
  182. return
  183. }
  184. if c.isSTSOnly {
  185. server.playRegistrationBurst(session)
  186. return true
  187. }
  188. // client MUST send PASS if necessary, or authenticate with SASL if necessary,
  189. // before completing the other registration commands
  190. authOutcome := c.isAuthorized(server.Config(), session)
  191. var quitMessage string
  192. switch authOutcome {
  193. case authFailPass:
  194. quitMessage = c.t("Password incorrect")
  195. c.Send(nil, server.name, ERR_PASSWDMISMATCH, "*", quitMessage)
  196. case authFailSaslRequired, authFailTorSaslRequired:
  197. quitMessage = c.t("You must log in with SASL to join this server")
  198. c.Send(nil, c.server.name, "FAIL", "*", "ACCOUNT_REQUIRED", quitMessage)
  199. }
  200. if authOutcome != authSuccess {
  201. c.Quit(quitMessage, nil)
  202. return true
  203. }
  204. // we have the final value of the IP address: do the hostname lookup
  205. // (nickmask will be set below once nickname assignment succeeds)
  206. if session.rawHostname == "" {
  207. session.client.lookupHostname(session, false)
  208. }
  209. rb := NewResponseBuffer(session)
  210. nickError := performNickChange(server, c, c, session, c.preregNick, rb)
  211. rb.Send(true)
  212. if nickError == errInsecureReattach {
  213. c.Quit(c.t("You can't mix secure and insecure connections to this account"), nil)
  214. return true
  215. } else if nickError != nil {
  216. c.preregNick = ""
  217. return false
  218. }
  219. if session.client != c {
  220. // reattached, bail out.
  221. // we'll play the reg burst later, on the new goroutine associated with
  222. // (thisSession, otherClient). This is to avoid having to transfer state
  223. // like nickname, hostname, etc. to show the correct values in the reg burst.
  224. return false
  225. }
  226. // check KLINEs
  227. isBanned, info := server.klines.CheckMasks(c.AllNickmasks()...)
  228. if isBanned {
  229. c.Quit(info.BanMessage(c.t("You are banned from this server (%s)")), nil)
  230. return true
  231. }
  232. // Apply default user modes (without updating the invisible counter)
  233. // The number of invisible users will be updated by server.stats.Register
  234. // if we're using default user mode +i.
  235. for _, defaultMode := range server.Config().Accounts.defaultUserModes {
  236. c.SetMode(defaultMode, true)
  237. }
  238. // registration has succeeded:
  239. c.SetRegistered()
  240. // count new user in statistics
  241. server.stats.Register(c.HasMode(modes.Invisible))
  242. server.monitorManager.AlertAbout(c.Nick(), c.NickCasefolded(), true)
  243. server.playRegistrationBurst(session)
  244. return false
  245. }
  246. func (server *Server) playRegistrationBurst(session *Session) {
  247. c := session.client
  248. // continue registration
  249. d := c.Details()
  250. server.logger.Info("connect", fmt.Sprintf("Client connected [%s] [u:%s] [r:%s]", d.nick, d.username, d.realname))
  251. server.snomasks.Send(sno.LocalConnects, fmt.Sprintf("Client connected [%s] [u:%s] [h:%s] [ip:%s] [r:%s]", d.nick, d.username, session.rawHostname, session.IP().String(), d.realname))
  252. // send welcome text
  253. //NOTE(dan): we specifically use the NICK here instead of the nickmask
  254. // see http://modern.ircdocs.horse/#rplwelcome-001 for details on why we avoid using the nickmask
  255. session.Send(nil, server.name, RPL_WELCOME, d.nick, fmt.Sprintf(c.t("Welcome to the Internet Relay Network %s"), d.nick))
  256. session.Send(nil, server.name, RPL_YOURHOST, d.nick, fmt.Sprintf(c.t("Your host is %[1]s, running version %[2]s"), server.name, Ver))
  257. session.Send(nil, server.name, RPL_CREATED, d.nick, fmt.Sprintf(c.t("This server was created %s"), server.ctime.Format(time.RFC1123)))
  258. session.Send(nil, server.name, RPL_MYINFO, d.nick, server.name, Ver, rplMyInfo1, rplMyInfo2, rplMyInfo3)
  259. if c.isSTSOnly {
  260. for _, line := range server.Config().Server.STS.bannerLines {
  261. c.Notice(line)
  262. }
  263. return
  264. }
  265. rb := NewResponseBuffer(session)
  266. server.RplISupport(c, rb)
  267. server.Lusers(c, rb)
  268. server.MOTD(c, rb)
  269. rb.Send(true)
  270. modestring := c.ModeString()
  271. if modestring != "+" {
  272. session.Send(nil, server.name, RPL_UMODEIS, d.nick, modestring)
  273. }
  274. c.attemptAutoOper(session)
  275. if server.logger.IsLoggingRawIO() {
  276. session.Send(nil, c.server.name, "NOTICE", d.nick, c.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  277. }
  278. }
  279. // RplISupport outputs our ISUPPORT lines to the client. This is used on connection and in VERSION responses.
  280. func (server *Server) RplISupport(client *Client, rb *ResponseBuffer) {
  281. translatedISupport := client.t("are supported by this server")
  282. nick := client.Nick()
  283. config := server.Config()
  284. for _, cachedTokenLine := range config.Server.isupport.CachedReply {
  285. length := len(cachedTokenLine) + 2
  286. tokenline := make([]string, length)
  287. tokenline[0] = nick
  288. copy(tokenline[1:], cachedTokenLine)
  289. tokenline[length-1] = translatedISupport
  290. rb.Add(nil, server.name, RPL_ISUPPORT, tokenline...)
  291. }
  292. }
  293. func (server *Server) Lusers(client *Client, rb *ResponseBuffer) {
  294. nick := client.Nick()
  295. stats := server.stats.GetValues()
  296. rb.Add(nil, server.name, RPL_LUSERCLIENT, nick, fmt.Sprintf(client.t("There are %[1]d users and %[2]d invisible on %[3]d server(s)"), stats.Total-stats.Invisible, stats.Invisible, 1))
  297. rb.Add(nil, server.name, RPL_LUSEROP, nick, strconv.Itoa(stats.Operators), client.t("IRC Operators online"))
  298. rb.Add(nil, server.name, RPL_LUSERUNKNOWN, nick, strconv.Itoa(stats.Unknown), client.t("unregistered connections"))
  299. rb.Add(nil, server.name, RPL_LUSERCHANNELS, nick, strconv.Itoa(server.channels.Len()), client.t("channels formed"))
  300. rb.Add(nil, server.name, RPL_LUSERME, nick, fmt.Sprintf(client.t("I have %[1]d clients and %[2]d servers"), stats.Total, 0))
  301. total := strconv.Itoa(stats.Total)
  302. max := strconv.Itoa(stats.Max)
  303. rb.Add(nil, server.name, RPL_LOCALUSERS, nick, total, max, fmt.Sprintf(client.t("Current local users %[1]s, max %[2]s"), total, max))
  304. rb.Add(nil, server.name, RPL_GLOBALUSERS, nick, total, max, fmt.Sprintf(client.t("Current global users %[1]s, max %[2]s"), total, max))
  305. }
  306. // MOTD serves the Message of the Day.
  307. func (server *Server) MOTD(client *Client, rb *ResponseBuffer) {
  308. motdLines := server.Config().Server.motdLines
  309. if len(motdLines) < 1 {
  310. rb.Add(nil, server.name, ERR_NOMOTD, client.nick, client.t("MOTD File is missing"))
  311. return
  312. }
  313. rb.Add(nil, server.name, RPL_MOTDSTART, client.nick, fmt.Sprintf(client.t("- %s Message of the day - "), server.name))
  314. for _, line := range motdLines {
  315. rb.Add(nil, server.name, RPL_MOTD, client.nick, line)
  316. }
  317. rb.Add(nil, server.name, RPL_ENDOFMOTD, client.nick, client.t("End of MOTD command"))
  318. }
  319. // WhoisChannelsNames returns the common channel names between two users.
  320. func (client *Client) WhoisChannelsNames(target *Client, multiPrefix bool) []string {
  321. var chstrs []string
  322. for _, channel := range target.Channels() {
  323. // channel is secret and the target can't see it
  324. if !client.HasMode(modes.Operator) {
  325. if (target.HasMode(modes.Invisible) || channel.flags.HasMode(modes.Secret)) && !channel.hasClient(client) {
  326. continue
  327. }
  328. }
  329. chstrs = append(chstrs, channel.ClientPrefixes(target, multiPrefix)+channel.name)
  330. }
  331. return chstrs
  332. }
  333. func (client *Client) getWhoisOf(target *Client, rb *ResponseBuffer) {
  334. cnick := client.Nick()
  335. targetInfo := target.Details()
  336. rb.Add(nil, client.server.name, RPL_WHOISUSER, cnick, targetInfo.nick, targetInfo.username, targetInfo.hostname, "*", targetInfo.realname)
  337. tnick := targetInfo.nick
  338. whoischannels := client.WhoisChannelsNames(target, rb.session.capabilities.Has(caps.MultiPrefix))
  339. if whoischannels != nil {
  340. rb.Add(nil, client.server.name, RPL_WHOISCHANNELS, cnick, tnick, strings.Join(whoischannels, " "))
  341. }
  342. tOper := target.Oper()
  343. if tOper != nil {
  344. rb.Add(nil, client.server.name, RPL_WHOISOPERATOR, cnick, tnick, tOper.WhoisLine)
  345. }
  346. if client.HasMode(modes.Operator) || client == target {
  347. rb.Add(nil, client.server.name, RPL_WHOISACTUALLY, cnick, tnick, fmt.Sprintf("%s@%s", targetInfo.username, target.RawHostname()), target.IPString(), client.t("Actual user@host, Actual IP"))
  348. }
  349. if target.HasMode(modes.TLS) {
  350. rb.Add(nil, client.server.name, RPL_WHOISSECURE, cnick, tnick, client.t("is using a secure connection"))
  351. }
  352. if targetInfo.accountName != "*" {
  353. rb.Add(nil, client.server.name, RPL_WHOISACCOUNT, cnick, tnick, targetInfo.accountName, client.t("is logged in as"))
  354. }
  355. if target.HasMode(modes.Bot) {
  356. rb.Add(nil, client.server.name, RPL_WHOISBOT, cnick, tnick, ircfmt.Unescape(fmt.Sprintf(client.t("is a $bBot$b on %s"), client.server.Config().Network.Name)))
  357. }
  358. if client == target || client.HasMode(modes.Operator) {
  359. for _, session := range target.Sessions() {
  360. if session.certfp != "" {
  361. rb.Add(nil, client.server.name, RPL_WHOISCERTFP, cnick, tnick, fmt.Sprintf(client.t("has client certificate fingerprint %s"), session.certfp))
  362. }
  363. }
  364. }
  365. rb.Add(nil, client.server.name, RPL_WHOISIDLE, cnick, tnick, strconv.FormatUint(target.IdleSeconds(), 10), strconv.FormatInt(target.SignonTime(), 10), client.t("seconds idle, signon time"))
  366. if target.Away() {
  367. rb.Add(nil, client.server.name, RPL_AWAY, cnick, tnick, target.AwayMessage())
  368. }
  369. }
  370. // rplWhoReply returns the WHO reply between one user and another channel/user.
  371. // <channel> <user> <host> <server> <nick> ( "H" / "G" ) ["*"] [ ( "@" / "+" ) ]
  372. // :<hopcount> <real name>
  373. func (client *Client) rplWhoReply(channel *Channel, target *Client, rb *ResponseBuffer) {
  374. channelName := "*"
  375. flags := ""
  376. if target.Away() {
  377. flags = "G"
  378. } else {
  379. flags = "H"
  380. }
  381. if target.HasMode(modes.Operator) {
  382. flags += "*"
  383. }
  384. if channel != nil {
  385. // TODO is this right?
  386. flags += channel.ClientPrefixes(target, rb.session.capabilities.Has(caps.MultiPrefix))
  387. channelName = channel.name
  388. }
  389. if target.HasMode(modes.Bot) {
  390. flags += "B"
  391. }
  392. details := target.Details()
  393. // hardcode a hopcount of 0 for now
  394. rb.Add(nil, client.server.name, RPL_WHOREPLY, client.Nick(), channelName, details.username, details.hostname, client.server.name, details.nick, flags, "0 "+details.realname)
  395. }
  396. // rehash reloads the config and applies the changes from the config file.
  397. func (server *Server) rehash() error {
  398. server.logger.Info("server", "Attempting rehash")
  399. // only let one REHASH go on at a time
  400. server.rehashMutex.Lock()
  401. defer server.rehashMutex.Unlock()
  402. server.logger.Debug("server", "Got rehash lock")
  403. config, err := LoadConfig(server.configFilename)
  404. if err != nil {
  405. server.logger.Error("server", "failed to load config file", err.Error())
  406. return err
  407. }
  408. err = server.applyConfig(config)
  409. if err != nil {
  410. server.logger.Error("server", "Failed to rehash", err.Error())
  411. return err
  412. }
  413. server.logger.Info("server", "Rehash completed successfully")
  414. return nil
  415. }
  416. func (server *Server) applyConfig(config *Config) (err error) {
  417. oldConfig := server.Config()
  418. initial := oldConfig == nil
  419. if initial {
  420. server.configFilename = config.Filename
  421. server.name = config.Server.Name
  422. server.nameCasefolded = config.Server.nameCasefolded
  423. globalCasemappingSetting = config.Server.Casemapping
  424. globalUtf8EnforcementSetting = config.Server.EnforceUtf8
  425. } else {
  426. // enforce configs that can't be changed after launch:
  427. if server.name != config.Server.Name {
  428. return fmt.Errorf("Server name cannot be changed after launching the server, rehash aborted")
  429. } else if oldConfig.Datastore.Path != config.Datastore.Path {
  430. return fmt.Errorf("Datastore path cannot be changed after launching the server, rehash aborted")
  431. } else if globalCasemappingSetting != config.Server.Casemapping {
  432. return fmt.Errorf("Casemapping cannot be changed after launching the server, rehash aborted")
  433. } else if globalUtf8EnforcementSetting != config.Server.EnforceUtf8 {
  434. return fmt.Errorf("UTF-8 enforcement cannot be changed after launching the server, rehash aborted")
  435. } else if oldConfig.Accounts.Multiclient.AlwaysOn != config.Accounts.Multiclient.AlwaysOn {
  436. return fmt.Errorf("Default always-on setting cannot be changed after launching the server, rehash aborted")
  437. }
  438. }
  439. server.logger.Info("server", "Using config file", server.configFilename)
  440. // first, reload config sections for functionality implemented in subpackages:
  441. wasLoggingRawIO := !initial && server.logger.IsLoggingRawIO()
  442. err = server.logger.ApplyConfig(config.Logging)
  443. if err != nil {
  444. return err
  445. }
  446. nowLoggingRawIO := server.logger.IsLoggingRawIO()
  447. // notify existing clients if raw i/o logging was enabled by a rehash
  448. sendRawOutputNotice := !wasLoggingRawIO && nowLoggingRawIO
  449. server.connectionLimiter.ApplyConfig(&config.Server.IPLimits)
  450. tlConf := &config.Server.TorListeners
  451. server.torLimiter.Configure(tlConf.MaxConnections, tlConf.ThrottleDuration, tlConf.MaxConnectionsPerDuration)
  452. // Translations
  453. server.logger.Debug("server", "Regenerating HELP indexes for new languages")
  454. server.helpIndexManager.GenerateIndices(config.languageManager)
  455. if oldConfig != nil {
  456. // if certain features were enabled by rehash, we need to load the corresponding data
  457. // from the store
  458. if !oldConfig.Accounts.NickReservation.Enabled {
  459. server.accounts.buildNickToAccountIndex(config)
  460. }
  461. if !oldConfig.Accounts.VHosts.Enabled {
  462. server.accounts.initVHostRequestQueue(config)
  463. }
  464. if !oldConfig.Channels.Registration.Enabled {
  465. server.channels.loadRegisteredChannels(config)
  466. }
  467. // resize history buffers as needed
  468. if oldConfig.History != config.History {
  469. for _, channel := range server.channels.Channels() {
  470. channel.resizeHistory(config)
  471. }
  472. for _, client := range server.clients.AllClients() {
  473. client.resizeHistory(config)
  474. }
  475. }
  476. if oldConfig.Accounts.Registration.Throttling != config.Accounts.Registration.Throttling {
  477. server.accounts.resetRegisterThrottle(config)
  478. }
  479. }
  480. server.logger.Info("server", "Using datastore", config.Datastore.Path)
  481. if initial {
  482. if err := server.loadDatastore(config); err != nil {
  483. return err
  484. }
  485. } else {
  486. if config.Datastore.MySQL.Enabled && config.Datastore.MySQL != oldConfig.Datastore.MySQL {
  487. server.historyDB.SetConfig(config.Datastore.MySQL)
  488. }
  489. }
  490. // now that the datastore is initialized, we can load the cloak secret from it
  491. // XXX this modifies config after the initial load, which is naughty,
  492. // but there's no data race because we haven't done SetConfig yet
  493. if config.Server.Cloaks.Enabled {
  494. config.Server.Cloaks.SetSecret(LoadCloakSecret(server.store))
  495. }
  496. // activate the new config
  497. server.SetConfig(config)
  498. // load [dk]-lines, registered users and channels, etc.
  499. if initial {
  500. if err := server.loadFromDatastore(config); err != nil {
  501. return err
  502. }
  503. }
  504. // burst new and removed caps
  505. addedCaps, removedCaps := config.Diff(oldConfig)
  506. var capBurstSessions []*Session
  507. added := make(map[caps.Version][]string)
  508. var removed []string
  509. if !addedCaps.Empty() || !removedCaps.Empty() {
  510. capBurstSessions = server.clients.AllWithCapsNotify()
  511. added[caps.Cap301] = addedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  512. added[caps.Cap302] = addedCaps.Strings(caps.Cap302, config.Server.capValues, 0)
  513. // removed never has values, so we leave it as Cap301
  514. removed = removedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  515. }
  516. for _, sSession := range capBurstSessions {
  517. // DEL caps and then send NEW ones so that updated caps get removed/added correctly
  518. if !removedCaps.Empty() {
  519. for _, capStr := range removed {
  520. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "DEL", capStr)
  521. }
  522. }
  523. if !addedCaps.Empty() {
  524. for _, capStr := range added[sSession.capVersion] {
  525. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "NEW", capStr)
  526. }
  527. }
  528. }
  529. server.setupPprofListener(config)
  530. // set RPL_ISUPPORT
  531. var newISupportReplies [][]string
  532. if oldConfig != nil {
  533. newISupportReplies = oldConfig.Server.isupport.GetDifference(&config.Server.isupport)
  534. }
  535. if len(config.Server.ProxyAllowedFrom) != 0 {
  536. server.logger.Info("server", "Proxied IPs will be accepted from", strings.Join(config.Server.ProxyAllowedFrom, ", "))
  537. }
  538. // we are now open for business
  539. err = server.setupListeners(config)
  540. if !initial {
  541. // push new info to all of our clients
  542. for _, sClient := range server.clients.AllClients() {
  543. for _, tokenline := range newISupportReplies {
  544. sClient.Send(nil, server.name, RPL_ISUPPORT, append([]string{sClient.nick}, tokenline...)...)
  545. }
  546. if sendRawOutputNotice {
  547. sClient.Notice(sClient.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  548. }
  549. }
  550. }
  551. return err
  552. }
  553. func (server *Server) setupPprofListener(config *Config) {
  554. pprofListener := ""
  555. if config.Debug.PprofListener != nil {
  556. pprofListener = *config.Debug.PprofListener
  557. }
  558. if server.pprofServer != nil {
  559. if pprofListener == "" || (pprofListener != server.pprofServer.Addr) {
  560. server.logger.Info("server", "Stopping pprof listener", server.pprofServer.Addr)
  561. server.pprofServer.Close()
  562. server.pprofServer = nil
  563. }
  564. }
  565. if pprofListener != "" && server.pprofServer == nil {
  566. ps := http.Server{
  567. Addr: pprofListener,
  568. }
  569. go func() {
  570. if err := ps.ListenAndServe(); err != nil {
  571. server.logger.Error("server", "pprof listener failed", err.Error())
  572. }
  573. }()
  574. server.pprofServer = &ps
  575. server.logger.Info("server", "Started pprof listener", server.pprofServer.Addr)
  576. }
  577. }
  578. func (config *Config) loadMOTD() (err error) {
  579. if config.Server.MOTD != "" {
  580. file, err := os.Open(config.Server.MOTD)
  581. if err == nil {
  582. defer file.Close()
  583. reader := bufio.NewReader(file)
  584. for {
  585. line, err := reader.ReadString('\n')
  586. if err != nil {
  587. break
  588. }
  589. line = strings.TrimRight(line, "\r\n")
  590. if config.Server.MOTDFormatting {
  591. line = ircfmt.Unescape(line)
  592. }
  593. // "- " is the required prefix for MOTD, we just add it here to make
  594. // bursting it out to clients easier
  595. line = fmt.Sprintf("- %s", line)
  596. config.Server.motdLines = append(config.Server.motdLines, line)
  597. }
  598. }
  599. }
  600. return
  601. }
  602. func (server *Server) loadDatastore(config *Config) error {
  603. // open the datastore and load server state for which it (rather than config)
  604. // is the source of truth
  605. _, err := os.Stat(config.Datastore.Path)
  606. if os.IsNotExist(err) {
  607. server.logger.Warning("server", "database does not exist, creating it", config.Datastore.Path)
  608. err = initializeDB(config.Datastore.Path)
  609. if err != nil {
  610. return err
  611. }
  612. }
  613. db, err := OpenDatabase(config)
  614. if err == nil {
  615. server.store = db
  616. return nil
  617. } else {
  618. return fmt.Errorf("Failed to open datastore: %s", err.Error())
  619. }
  620. }
  621. func (server *Server) loadFromDatastore(config *Config) (err error) {
  622. // load *lines (from the datastores)
  623. server.logger.Debug("server", "Loading D/Klines")
  624. server.loadDLines()
  625. server.loadKLines()
  626. server.channelRegistry.Initialize(server)
  627. server.channels.Initialize(server)
  628. server.accounts.Initialize(server)
  629. if config.Datastore.MySQL.Enabled {
  630. server.historyDB.Initialize(server.logger, config.Datastore.MySQL)
  631. err = server.historyDB.Open()
  632. if err != nil {
  633. server.logger.Error("internal", "could not connect to mysql", err.Error())
  634. return err
  635. }
  636. }
  637. return nil
  638. }
  639. func (server *Server) setupListeners(config *Config) (err error) {
  640. logListener := func(addr string, config utils.ListenerConfig) {
  641. server.logger.Info("listeners",
  642. fmt.Sprintf("now listening on %s, tls=%t, tlsproxy=%t, tor=%t, websocket=%t.", addr, (config.TLSConfig != nil), config.RequireProxy, config.Tor, config.WebSocket),
  643. )
  644. }
  645. // update or destroy all existing listeners
  646. for addr := range server.listeners {
  647. currentListener := server.listeners[addr]
  648. newConfig, stillConfigured := config.Server.trueListeners[addr]
  649. if stillConfigured {
  650. if reloadErr := currentListener.Reload(newConfig); reloadErr == nil {
  651. logListener(addr, newConfig)
  652. } else {
  653. // stop the listener; we will attempt to replace it below
  654. currentListener.Stop()
  655. delete(server.listeners, addr)
  656. }
  657. } else {
  658. currentListener.Stop()
  659. delete(server.listeners, addr)
  660. server.logger.Info("listeners", fmt.Sprintf("stopped listening on %s.", addr))
  661. }
  662. }
  663. publicPlaintextListener := ""
  664. // create new listeners that were not previously configured,
  665. // or that couldn't be reloaded above:
  666. for newAddr, newConfig := range config.Server.trueListeners {
  667. if strings.HasPrefix(newAddr, ":") && !newConfig.Tor && !newConfig.STSOnly && newConfig.TLSConfig == nil {
  668. publicPlaintextListener = newAddr
  669. }
  670. _, exists := server.listeners[newAddr]
  671. if !exists {
  672. // make a new listener
  673. newListener, newErr := NewListener(server, newAddr, newConfig, config.Server.UnixBindMode)
  674. if newErr == nil {
  675. server.listeners[newAddr] = newListener
  676. logListener(newAddr, newConfig)
  677. } else {
  678. server.logger.Error("server", "couldn't listen on", newAddr, newErr.Error())
  679. err = newErr
  680. }
  681. }
  682. }
  683. if publicPlaintextListener != "" {
  684. server.logger.Warning("listeners", fmt.Sprintf("Your server is configured with public plaintext listener %s. Consider disabling it for improved security and privacy.", publicPlaintextListener))
  685. }
  686. return
  687. }
  688. // Gets the abstract sequence from which we're going to query history;
  689. // we may already know the channel we're querying, or we may have
  690. // to look it up via a string query. This function is responsible for
  691. // privilege checking.
  692. func (server *Server) GetHistorySequence(providedChannel *Channel, client *Client, query string) (channel *Channel, sequence history.Sequence, err error) {
  693. config := server.Config()
  694. // 4 cases: {persistent, ephemeral} x {normal, conversation}
  695. // with ephemeral history, target is implicit in the choice of `hist`,
  696. // and correspondent is "" if we're retrieving a channel or *, and the correspondent's name
  697. // if we're retrieving a DM conversation ("query buffer"). with persistent history,
  698. // target is always nonempty, and correspondent is either empty or nonempty as before.
  699. var status HistoryStatus
  700. var target, correspondent string
  701. var hist *history.Buffer
  702. channel = providedChannel
  703. if channel == nil {
  704. if strings.HasPrefix(query, "#") {
  705. channel = server.channels.Get(query)
  706. if channel == nil {
  707. return
  708. }
  709. }
  710. }
  711. if channel != nil {
  712. if !channel.hasClient(client) {
  713. err = errInsufficientPrivs
  714. return
  715. }
  716. status, target = channel.historyStatus(config)
  717. switch status {
  718. case HistoryEphemeral:
  719. hist = &channel.history
  720. case HistoryPersistent:
  721. // already set `target`
  722. default:
  723. return
  724. }
  725. } else {
  726. status, target = client.historyStatus(config)
  727. if query != "*" {
  728. correspondent, err = CasefoldName(query)
  729. if err != nil {
  730. return
  731. }
  732. }
  733. switch status {
  734. case HistoryEphemeral:
  735. hist = &client.history
  736. case HistoryPersistent:
  737. // already set `target`, and `correspondent` if necessary
  738. default:
  739. return
  740. }
  741. }
  742. var cutoff time.Time
  743. if config.History.Restrictions.ExpireTime != 0 {
  744. cutoff = time.Now().UTC().Add(-time.Duration(config.History.Restrictions.ExpireTime))
  745. }
  746. // #836: registration date cutoff is always enforced for DMs
  747. if config.History.Restrictions.EnforceRegistrationDate || channel == nil {
  748. regCutoff := client.historyCutoff()
  749. // take the later of the two cutoffs
  750. if regCutoff.After(cutoff) {
  751. cutoff = regCutoff
  752. }
  753. }
  754. // #836 again: grace period is never applied to DMs
  755. if !cutoff.IsZero() && channel != nil {
  756. cutoff = cutoff.Add(-time.Duration(config.History.Restrictions.GracePeriod))
  757. }
  758. if hist != nil {
  759. sequence = hist.MakeSequence(correspondent, cutoff)
  760. } else if target != "" {
  761. sequence = server.historyDB.MakeSequence(target, correspondent, cutoff)
  762. }
  763. return
  764. }
  765. func (server *Server) ForgetHistory(accountName string) {
  766. // sanity check
  767. if accountName == "*" {
  768. return
  769. }
  770. config := server.Config()
  771. if !config.History.Enabled {
  772. return
  773. }
  774. if cfAccount, err := CasefoldName(accountName); err == nil {
  775. server.historyDB.Forget(cfAccount)
  776. }
  777. persistent := config.History.Persistent
  778. if persistent.Enabled && persistent.UnregisteredChannels && persistent.RegisteredChannels == PersistentMandatory && persistent.DirectMessages == PersistentMandatory {
  779. return
  780. }
  781. predicate := func(item *history.Item) bool { return item.AccountName == accountName }
  782. for _, channel := range server.channels.Channels() {
  783. channel.history.Delete(predicate)
  784. }
  785. for _, client := range server.clients.AllClients() {
  786. client.history.Delete(predicate)
  787. }
  788. }
  789. // deletes a message. target is a hint about what buffer it's in (not required for
  790. // persistent history, where all the msgids are indexed together). if accountName
  791. // is anything other than "*", it must match the recorded AccountName of the message
  792. func (server *Server) DeleteMessage(target, msgid, accountName string) (err error) {
  793. config := server.Config()
  794. var hist *history.Buffer
  795. if target != "" {
  796. if target[0] == '#' {
  797. channel := server.channels.Get(target)
  798. if channel != nil {
  799. if status, _ := channel.historyStatus(config); status == HistoryEphemeral {
  800. hist = &channel.history
  801. }
  802. }
  803. } else {
  804. client := server.clients.Get(target)
  805. if client != nil {
  806. if status, _ := client.historyStatus(config); status == HistoryEphemeral {
  807. hist = &client.history
  808. }
  809. }
  810. }
  811. }
  812. if hist == nil {
  813. err = server.historyDB.DeleteMsgid(msgid, accountName)
  814. } else {
  815. count := hist.Delete(func(item *history.Item) bool {
  816. return item.Message.Msgid == msgid && (accountName == "*" || item.AccountName == accountName)
  817. })
  818. if count == 0 {
  819. err = errNoop
  820. }
  821. }
  822. return
  823. }
  824. // elistMatcher takes and matches ELIST conditions
  825. type elistMatcher struct {
  826. MinClientsActive bool
  827. MinClients int
  828. MaxClientsActive bool
  829. MaxClients int
  830. }
  831. // Matches checks whether the given channel matches our matches.
  832. func (matcher *elistMatcher) Matches(channel *Channel) bool {
  833. if matcher.MinClientsActive {
  834. if len(channel.Members()) < matcher.MinClients {
  835. return false
  836. }
  837. }
  838. if matcher.MaxClientsActive {
  839. if len(channel.Members()) < len(channel.members) {
  840. return false
  841. }
  842. }
  843. return true
  844. }
  845. // RplList returns the RPL_LIST numeric for the given channel.
  846. func (target *Client) RplList(channel *Channel, rb *ResponseBuffer) {
  847. // get the correct number of channel members
  848. var memberCount int
  849. if target.HasMode(modes.Operator) || channel.hasClient(target) {
  850. memberCount = len(channel.Members())
  851. } else {
  852. for _, member := range channel.Members() {
  853. if !member.HasMode(modes.Invisible) {
  854. memberCount++
  855. }
  856. }
  857. }
  858. // #704: some channels are kept around even with no members
  859. if memberCount != 0 {
  860. rb.Add(nil, target.server.name, RPL_LIST, target.nick, channel.name, strconv.Itoa(memberCount), channel.topic)
  861. }
  862. }
  863. var (
  864. infoString1 = strings.Split(` ▄▄▄ ▄▄▄· ▄▄ • ▐ ▄
  865. ▪ ▀▄ █·▐█ ▀█ ▐█ ▀ ▪▪ •█▌▐█▪
  866. ▄█▀▄ ▐▀▀▄ ▄█▀▀█ ▄█ ▀█▄ ▄█▀▄▪▐█▐▐▌ ▄█▀▄
  867. ▐█▌.▐▌▐█•█▌▐█ ▪▐▌▐█▄▪▐█▐█▌ ▐▌██▐█▌▐█▌.▐▌
  868. ▀█▄▀▪.▀ ▀ ▀ ▀ ·▀▀▀▀ ▀█▄▀ ▀▀ █▪ ▀█▄▀▪
  869. https://oragono.io/
  870. https://github.com/oragono/oragono
  871. https://crowdin.com/project/oragono
  872. `, "\n")
  873. infoString2 = strings.Split(` Daniel Oakley, DanielOaks, <daniel@danieloaks.net>
  874. Shivaram Lingamneni, slingamn, <slingamn@cs.stanford.edu>
  875. `, "\n")
  876. infoString3 = strings.Split(` Jeremy Latt, jlatt
  877. Edmund Huber, edmund-huber
  878. `, "\n")
  879. )