You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

server.go 37KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053
  1. // Copyright (c) 2012-2014 Jeremy Latt
  2. // Copyright (c) 2014-2015 Edmund Huber
  3. // Copyright (c) 2016-2017 Daniel Oaks <daniel@danieloaks.net>
  4. // released under the MIT license
  5. package irc
  6. import (
  7. "fmt"
  8. "net"
  9. "net/http"
  10. _ "net/http/pprof"
  11. "os"
  12. "os/signal"
  13. "runtime/debug"
  14. "strconv"
  15. "strings"
  16. "sync"
  17. "syscall"
  18. "time"
  19. "unsafe"
  20. "github.com/goshuirc/irc-go/ircfmt"
  21. "github.com/oragono/oragono/irc/caps"
  22. "github.com/oragono/oragono/irc/connection_limits"
  23. "github.com/oragono/oragono/irc/flatip"
  24. "github.com/oragono/oragono/irc/history"
  25. "github.com/oragono/oragono/irc/logger"
  26. "github.com/oragono/oragono/irc/modes"
  27. "github.com/oragono/oragono/irc/mysql"
  28. "github.com/oragono/oragono/irc/sno"
  29. "github.com/oragono/oragono/irc/utils"
  30. "github.com/tidwall/buntdb"
  31. )
  32. const (
  33. alwaysOnExpirationPollPeriod = time.Hour
  34. )
  35. var (
  36. // common error line to sub values into
  37. errorMsg = "ERROR :%s\r\n"
  38. // three final parameters of 004 RPL_MYINFO, enumerating our supported modes
  39. rplMyInfo1, rplMyInfo2, rplMyInfo3 = modes.RplMyInfo()
  40. // CHANMODES isupport token
  41. chanmodesToken = modes.ChanmodesToken()
  42. // whitelist of caps to serve on the STS-only listener. In particular,
  43. // never advertise SASL, to discourage people from sending their passwords:
  44. stsOnlyCaps = caps.NewSet(caps.STS, caps.MessageTags, caps.ServerTime, caps.Batch, caps.LabeledResponse, caps.EchoMessage, caps.Nope)
  45. // we only have standard channels for now. TODO: any updates to this
  46. // will also need to be reflected in CasefoldChannel
  47. chanTypes = "#"
  48. throttleMessage = "You have attempted to connect too many times within a short duration. Wait a while, and you will be able to connect."
  49. )
  50. // Server is the main Oragono server.
  51. type Server struct {
  52. accounts AccountManager
  53. channels ChannelManager
  54. channelRegistry ChannelRegistry
  55. clients ClientManager
  56. config unsafe.Pointer
  57. configFilename string
  58. connectionLimiter connection_limits.Limiter
  59. ctime time.Time
  60. dlines *DLineManager
  61. helpIndexManager HelpIndexManager
  62. klines *KLineManager
  63. listeners map[string]IRCListener
  64. logger *logger.Manager
  65. monitorManager MonitorManager
  66. name string
  67. nameCasefolded string
  68. rehashMutex sync.Mutex // tier 4
  69. rehashSignal chan os.Signal
  70. pprofServer *http.Server
  71. resumeManager ResumeManager
  72. signals chan os.Signal
  73. snomasks SnoManager
  74. store *buntdb.DB
  75. historyDB mysql.MySQL
  76. torLimiter connection_limits.TorLimiter
  77. whoWas WhoWasList
  78. stats Stats
  79. semaphores ServerSemaphores
  80. defcon uint32
  81. }
  82. // NewServer returns a new Oragono server.
  83. func NewServer(config *Config, logger *logger.Manager) (*Server, error) {
  84. // initialize data structures
  85. server := &Server{
  86. ctime: time.Now().UTC(),
  87. listeners: make(map[string]IRCListener),
  88. logger: logger,
  89. rehashSignal: make(chan os.Signal, 1),
  90. signals: make(chan os.Signal, len(ServerExitSignals)),
  91. defcon: 5,
  92. }
  93. server.clients.Initialize()
  94. server.semaphores.Initialize()
  95. server.resumeManager.Initialize(server)
  96. server.whoWas.Initialize(config.Limits.WhowasEntries)
  97. server.monitorManager.Initialize()
  98. server.snomasks.Initialize()
  99. if err := server.applyConfig(config); err != nil {
  100. return nil, err
  101. }
  102. // Attempt to clean up when receiving these signals.
  103. signal.Notify(server.signals, ServerExitSignals...)
  104. signal.Notify(server.rehashSignal, syscall.SIGHUP)
  105. time.AfterFunc(alwaysOnExpirationPollPeriod, server.handleAlwaysOnExpirations)
  106. return server, nil
  107. }
  108. // Shutdown shuts down the server.
  109. func (server *Server) Shutdown() {
  110. //TODO(dan): Make sure we disallow new nicks
  111. for _, client := range server.clients.AllClients() {
  112. client.Notice("Server is shutting down")
  113. if client.AlwaysOn() {
  114. client.Store(IncludeLastSeen)
  115. }
  116. }
  117. if err := server.store.Close(); err != nil {
  118. server.logger.Error("shutdown", fmt.Sprintln("Could not close datastore:", err))
  119. }
  120. server.historyDB.Close()
  121. }
  122. // Run starts the server.
  123. func (server *Server) Run() {
  124. // defer closing db/store
  125. defer server.store.Close()
  126. for {
  127. select {
  128. case <-server.signals:
  129. server.Shutdown()
  130. return
  131. case <-server.rehashSignal:
  132. go func() {
  133. server.logger.Info("server", "Rehashing due to SIGHUP")
  134. server.rehash()
  135. }()
  136. }
  137. }
  138. }
  139. func (server *Server) checkBans(config *Config, ipaddr net.IP, checkScripts bool) (banned bool, requireSASL bool, message string) {
  140. // #671: do not enforce bans against loopback, as a failsafe
  141. // note that this function is not used for Tor connections (checkTorLimits is used instead)
  142. if ipaddr.IsLoopback() {
  143. return
  144. }
  145. if server.Defcon() == 1 {
  146. if !utils.IPInNets(ipaddr, server.Config().Server.secureNets) {
  147. return true, false, "New connections to this server are temporarily restricted"
  148. }
  149. }
  150. flat := flatip.FromNetIP(ipaddr)
  151. // check DLINEs
  152. isBanned, info := server.dlines.CheckIP(flat)
  153. if isBanned {
  154. if info.RequireSASL {
  155. server.logger.Info("connect-ip", "Requiring SASL from client due to d-line", ipaddr.String())
  156. return false, true, info.BanMessage("You must authenticate with SASL to connect from this IP (%s)")
  157. } else {
  158. server.logger.Info("connect-ip", "Client rejected by d-line", ipaddr.String())
  159. return true, false, info.BanMessage("You are banned from this server (%s)")
  160. }
  161. }
  162. // check connection limits
  163. err := server.connectionLimiter.AddClient(flat)
  164. if err == connection_limits.ErrLimitExceeded {
  165. // too many connections from one client, tell the client and close the connection
  166. server.logger.Info("connect-ip", "Client rejected for connection limit", ipaddr.String())
  167. return true, false, "Too many clients from your network"
  168. } else if err == connection_limits.ErrThrottleExceeded {
  169. server.logger.Info("connect-ip", "Client exceeded connection throttle", ipaddr.String())
  170. return true, false, throttleMessage
  171. } else if err != nil {
  172. server.logger.Warning("internal", "unexpected ban result", err.Error())
  173. }
  174. if checkScripts && config.Server.IPCheckScript.Enabled {
  175. output, err := CheckIPBan(server.semaphores.IPCheckScript, config.Server.IPCheckScript, ipaddr)
  176. if err != nil {
  177. server.logger.Error("internal", "couldn't check IP ban script", ipaddr.String(), err.Error())
  178. return false, false, ""
  179. }
  180. // TODO: currently no way to cache IPAccepted
  181. if (output.Result == IPBanned || output.Result == IPRequireSASL) && output.CacheSeconds != 0 {
  182. network, err := flatip.ParseToNormalizedNet(output.CacheNet)
  183. if err != nil {
  184. server.logger.Error("internal", "invalid dline net from IP ban script", ipaddr.String(), output.CacheNet)
  185. } else {
  186. dlineDuration := time.Duration(output.CacheSeconds) * time.Second
  187. err := server.dlines.AddNetwork(network, dlineDuration, output.Result == IPRequireSASL, output.BanMessage, "", "")
  188. if err != nil {
  189. server.logger.Error("internal", "couldn't set dline from IP ban script", ipaddr.String(), err.Error())
  190. }
  191. }
  192. }
  193. if output.Result == IPBanned {
  194. // XXX roll back IP connection/throttling addition for the IP
  195. server.connectionLimiter.RemoveClient(flat)
  196. server.logger.Info("connect-ip", "Rejected client due to ip-check-script", ipaddr.String())
  197. return true, false, output.BanMessage
  198. } else if output.Result == IPRequireSASL {
  199. server.logger.Info("connect-ip", "Requiring SASL from client due to ip-check-script", ipaddr.String())
  200. return false, true, output.BanMessage
  201. }
  202. }
  203. return false, false, ""
  204. }
  205. func (server *Server) checkTorLimits() (banned bool, message string) {
  206. switch server.torLimiter.AddClient() {
  207. case connection_limits.ErrLimitExceeded:
  208. return true, "Too many clients from the Tor network"
  209. case connection_limits.ErrThrottleExceeded:
  210. return true, "Exceeded connection throttle for the Tor network"
  211. default:
  212. return false, ""
  213. }
  214. }
  215. func (server *Server) handleAlwaysOnExpirations() {
  216. defer func() {
  217. if r := recover(); r != nil {
  218. server.logger.Error("internal",
  219. fmt.Sprintf("Panic in always-on cleanup: %v\n%s", r, debug.Stack()))
  220. }
  221. // either way, reschedule
  222. time.AfterFunc(alwaysOnExpirationPollPeriod, server.handleAlwaysOnExpirations)
  223. }()
  224. config := server.Config()
  225. deadline := time.Duration(config.Accounts.Multiclient.AlwaysOnExpiration)
  226. if deadline == 0 {
  227. return
  228. }
  229. server.logger.Info("accounts", "Checking always-on clients for expiration")
  230. for _, client := range server.clients.AllClients() {
  231. if client.IsExpiredAlwaysOn(config) {
  232. // TODO save the channels list, use it for autojoin if/when they return?
  233. server.logger.Info("accounts", "Expiring always-on client", client.AccountName())
  234. client.destroy(nil)
  235. }
  236. }
  237. }
  238. //
  239. // server functionality
  240. //
  241. func (server *Server) tryRegister(c *Client, session *Session) (exiting bool) {
  242. // if the session just sent us a RESUME line, try to resume
  243. if session.resumeDetails != nil {
  244. session.tryResume()
  245. return // whether we succeeded or failed, either way `c` is not getting registered
  246. }
  247. // XXX PROXY or WEBIRC MUST be sent as the first line of the session;
  248. // if we are here at all that means we have the final value of the IP
  249. if session.rawHostname == "" {
  250. session.client.lookupHostname(session, false)
  251. }
  252. // try to complete registration normally
  253. // XXX(#1057) username can be filled in by an ident query without the client
  254. // having sent USER: check for both username and realname to ensure they did
  255. if c.preregNick == "" || c.username == "" || c.realname == "" || session.capState == caps.NegotiatingState {
  256. return
  257. }
  258. if c.isSTSOnly {
  259. server.playSTSBurst(session)
  260. return true
  261. }
  262. // client MUST send PASS if necessary, or authenticate with SASL if necessary,
  263. // before completing the other registration commands
  264. config := server.Config()
  265. authOutcome := c.isAuthorized(server, config, session, c.requireSASL)
  266. var quitMessage string
  267. switch authOutcome {
  268. case authFailPass:
  269. quitMessage = c.t("Password incorrect")
  270. c.Send(nil, server.name, ERR_PASSWDMISMATCH, "*", quitMessage)
  271. case authFailSaslRequired, authFailTorSaslRequired:
  272. quitMessage = c.requireSASLMessage
  273. if quitMessage == "" {
  274. quitMessage = c.t("You must log in with SASL to join this server")
  275. }
  276. c.Send(nil, c.server.name, "FAIL", "*", "ACCOUNT_REQUIRED", quitMessage)
  277. }
  278. if authOutcome != authSuccess {
  279. c.Quit(quitMessage, nil)
  280. return true
  281. }
  282. c.requireSASLMessage = ""
  283. rb := NewResponseBuffer(session)
  284. nickError := performNickChange(server, c, c, session, c.preregNick, rb)
  285. rb.Send(true)
  286. if nickError == errInsecureReattach {
  287. c.Quit(c.t("You can't mix secure and insecure connections to this account"), nil)
  288. return true
  289. } else if nickError != nil {
  290. c.preregNick = ""
  291. return false
  292. }
  293. if session.client != c {
  294. // reattached, bail out.
  295. // we'll play the reg burst later, on the new goroutine associated with
  296. // (thisSession, otherClient). This is to avoid having to transfer state
  297. // like nickname, hostname, etc. to show the correct values in the reg burst.
  298. return false
  299. }
  300. // Apply default user modes (without updating the invisible counter)
  301. // The number of invisible users will be updated by server.stats.Register
  302. // if we're using default user mode +i.
  303. for _, defaultMode := range config.Accounts.defaultUserModes {
  304. c.SetMode(defaultMode, true)
  305. }
  306. // count new user in statistics (before checking KLINEs, see #1303)
  307. server.stats.Register(c.HasMode(modes.Invisible))
  308. // check KLINEs (#671: ignore KLINEs for loopback connections)
  309. if !session.IP().IsLoopback() || session.isTor {
  310. isBanned, info := server.klines.CheckMasks(c.AllNickmasks()...)
  311. if isBanned {
  312. c.Quit(info.BanMessage(c.t("You are banned from this server (%s)")), nil)
  313. return true
  314. }
  315. }
  316. server.playRegistrationBurst(session)
  317. return false
  318. }
  319. func (server *Server) playSTSBurst(session *Session) {
  320. nick := utils.SafeErrorParam(session.client.preregNick)
  321. session.Send(nil, server.name, RPL_WELCOME, nick, fmt.Sprintf("Welcome to the Internet Relay Network %s", nick))
  322. session.Send(nil, server.name, RPL_YOURHOST, nick, fmt.Sprintf("Your host is %[1]s, running version %[2]s", server.name, "oragono"))
  323. session.Send(nil, server.name, RPL_CREATED, nick, fmt.Sprintf("This server was created %s", time.Time{}.Format(time.RFC1123)))
  324. session.Send(nil, server.name, RPL_MYINFO, nick, server.name, "oragono", "o", "o", "o")
  325. session.Send(nil, server.name, RPL_ISUPPORT, nick, "CASEMAPPING=ascii", "are supported by this server")
  326. session.Send(nil, server.name, ERR_NOMOTD, nick, "MOTD is unavailable")
  327. for _, line := range server.Config().Server.STS.bannerLines {
  328. session.Send(nil, server.name, "NOTICE", nick, line)
  329. }
  330. }
  331. func (server *Server) playRegistrationBurst(session *Session) {
  332. c := session.client
  333. // continue registration
  334. d := c.Details()
  335. server.logger.Info("connect", fmt.Sprintf("Client connected [%s] [u:%s] [r:%s]", d.nick, d.username, d.realname))
  336. server.snomasks.Send(sno.LocalConnects, fmt.Sprintf("Client connected [%s] [u:%s] [h:%s] [ip:%s] [r:%s]", d.nick, d.username, session.rawHostname, session.IP().String(), d.realname))
  337. if d.account != "" {
  338. server.sendLoginSnomask(d.nickMask, d.accountName)
  339. }
  340. // send welcome text
  341. //NOTE(dan): we specifically use the NICK here instead of the nickmask
  342. // see http://modern.ircdocs.horse/#rplwelcome-001 for details on why we avoid using the nickmask
  343. config := server.Config()
  344. session.Send(nil, server.name, RPL_WELCOME, d.nick, fmt.Sprintf(c.t("Welcome to the %s IRC Network %s"), config.Network.Name, d.nick))
  345. session.Send(nil, server.name, RPL_YOURHOST, d.nick, fmt.Sprintf(c.t("Your host is %[1]s, running version %[2]s"), server.name, Ver))
  346. session.Send(nil, server.name, RPL_CREATED, d.nick, fmt.Sprintf(c.t("This server was created %s"), server.ctime.Format(time.RFC1123)))
  347. session.Send(nil, server.name, RPL_MYINFO, d.nick, server.name, Ver, rplMyInfo1, rplMyInfo2, rplMyInfo3)
  348. rb := NewResponseBuffer(session)
  349. server.RplISupport(c, rb)
  350. server.Lusers(c, rb)
  351. server.MOTD(c, rb)
  352. rb.Send(true)
  353. modestring := c.ModeString()
  354. if modestring != "+" {
  355. session.Send(nil, server.name, RPL_UMODEIS, d.nick, modestring)
  356. }
  357. c.attemptAutoOper(session)
  358. if server.logger.IsLoggingRawIO() {
  359. session.Send(nil, c.server.name, "NOTICE", d.nick, c.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  360. }
  361. }
  362. // RplISupport outputs our ISUPPORT lines to the client. This is used on connection and in VERSION responses.
  363. func (server *Server) RplISupport(client *Client, rb *ResponseBuffer) {
  364. translatedISupport := client.t("are supported by this server")
  365. nick := client.Nick()
  366. config := server.Config()
  367. for _, cachedTokenLine := range config.Server.isupport.CachedReply {
  368. length := len(cachedTokenLine) + 2
  369. tokenline := make([]string, length)
  370. tokenline[0] = nick
  371. copy(tokenline[1:], cachedTokenLine)
  372. tokenline[length-1] = translatedISupport
  373. rb.Add(nil, server.name, RPL_ISUPPORT, tokenline...)
  374. }
  375. }
  376. func (server *Server) Lusers(client *Client, rb *ResponseBuffer) {
  377. nick := client.Nick()
  378. stats := server.stats.GetValues()
  379. rb.Add(nil, server.name, RPL_LUSERCLIENT, nick, fmt.Sprintf(client.t("There are %[1]d users and %[2]d invisible on %[3]d server(s)"), stats.Total-stats.Invisible, stats.Invisible, 1))
  380. rb.Add(nil, server.name, RPL_LUSEROP, nick, strconv.Itoa(stats.Operators), client.t("IRC Operators online"))
  381. rb.Add(nil, server.name, RPL_LUSERUNKNOWN, nick, strconv.Itoa(stats.Unknown), client.t("unregistered connections"))
  382. rb.Add(nil, server.name, RPL_LUSERCHANNELS, nick, strconv.Itoa(server.channels.Len()), client.t("channels formed"))
  383. rb.Add(nil, server.name, RPL_LUSERME, nick, fmt.Sprintf(client.t("I have %[1]d clients and %[2]d servers"), stats.Total, 0))
  384. total := strconv.Itoa(stats.Total)
  385. max := strconv.Itoa(stats.Max)
  386. rb.Add(nil, server.name, RPL_LOCALUSERS, nick, total, max, fmt.Sprintf(client.t("Current local users %[1]s, max %[2]s"), total, max))
  387. rb.Add(nil, server.name, RPL_GLOBALUSERS, nick, total, max, fmt.Sprintf(client.t("Current global users %[1]s, max %[2]s"), total, max))
  388. }
  389. // MOTD serves the Message of the Day.
  390. func (server *Server) MOTD(client *Client, rb *ResponseBuffer) {
  391. motdLines := server.Config().Server.motdLines
  392. if len(motdLines) < 1 {
  393. rb.Add(nil, server.name, ERR_NOMOTD, client.nick, client.t("MOTD File is missing"))
  394. return
  395. }
  396. rb.Add(nil, server.name, RPL_MOTDSTART, client.nick, fmt.Sprintf(client.t("- %s Message of the day - "), server.name))
  397. for _, line := range motdLines {
  398. rb.Add(nil, server.name, RPL_MOTD, client.nick, line)
  399. }
  400. rb.Add(nil, server.name, RPL_ENDOFMOTD, client.nick, client.t("End of MOTD command"))
  401. }
  402. // WhoisChannelsNames returns the common channel names between two users.
  403. func (client *Client) WhoisChannelsNames(target *Client, multiPrefix bool) []string {
  404. var chstrs []string
  405. for _, channel := range target.Channels() {
  406. // channel is secret and the target can't see it
  407. if !client.HasMode(modes.Operator) {
  408. if (target.HasMode(modes.Invisible) || channel.flags.HasMode(modes.Secret)) && !channel.hasClient(client) {
  409. continue
  410. }
  411. }
  412. chstrs = append(chstrs, channel.ClientPrefixes(target, multiPrefix)+channel.name)
  413. }
  414. return chstrs
  415. }
  416. func (client *Client) getWhoisOf(target *Client, hasPrivs bool, rb *ResponseBuffer) {
  417. cnick := client.Nick()
  418. targetInfo := target.Details()
  419. rb.Add(nil, client.server.name, RPL_WHOISUSER, cnick, targetInfo.nick, targetInfo.username, targetInfo.hostname, "*", targetInfo.realname)
  420. tnick := targetInfo.nick
  421. whoischannels := client.WhoisChannelsNames(target, rb.session.capabilities.Has(caps.MultiPrefix))
  422. if whoischannels != nil {
  423. rb.Add(nil, client.server.name, RPL_WHOISCHANNELS, cnick, tnick, strings.Join(whoischannels, " "))
  424. }
  425. if target.HasMode(modes.Operator) && operStatusVisible(client, target, hasPrivs) {
  426. tOper := target.Oper()
  427. if tOper != nil {
  428. rb.Add(nil, client.server.name, RPL_WHOISOPERATOR, cnick, tnick, tOper.WhoisLine)
  429. }
  430. }
  431. if client == target || hasPrivs {
  432. rb.Add(nil, client.server.name, RPL_WHOISACTUALLY, cnick, tnick, fmt.Sprintf("%s@%s", targetInfo.username, target.RawHostname()), target.IPString(), client.t("Actual user@host, Actual IP"))
  433. rb.Add(nil, client.server.name, RPL_WHOISMODES, cnick, tnick, fmt.Sprintf(client.t("is using modes +%s"), target.modes.String()))
  434. }
  435. if target.HasMode(modes.TLS) {
  436. rb.Add(nil, client.server.name, RPL_WHOISSECURE, cnick, tnick, client.t("is using a secure connection"))
  437. }
  438. if targetInfo.accountName != "*" {
  439. rb.Add(nil, client.server.name, RPL_WHOISACCOUNT, cnick, tnick, targetInfo.accountName, client.t("is logged in as"))
  440. }
  441. if target.HasMode(modes.Bot) {
  442. rb.Add(nil, client.server.name, RPL_WHOISBOT, cnick, tnick, fmt.Sprintf(ircfmt.Unescape(client.t("is a $bBot$b on %s")), client.server.Config().Network.Name))
  443. }
  444. if client == target || hasPrivs {
  445. for _, session := range target.Sessions() {
  446. if session.certfp != "" {
  447. rb.Add(nil, client.server.name, RPL_WHOISCERTFP, cnick, tnick, fmt.Sprintf(client.t("has client certificate fingerprint %s"), session.certfp))
  448. }
  449. }
  450. }
  451. rb.Add(nil, client.server.name, RPL_WHOISIDLE, cnick, tnick, strconv.FormatUint(target.IdleSeconds(), 10), strconv.FormatInt(target.SignonTime(), 10), client.t("seconds idle, signon time"))
  452. if away, awayMessage := target.Away(); away {
  453. rb.Add(nil, client.server.name, RPL_AWAY, cnick, tnick, awayMessage)
  454. }
  455. }
  456. // rehash reloads the config and applies the changes from the config file.
  457. func (server *Server) rehash() error {
  458. server.logger.Info("server", "Attempting rehash")
  459. // only let one REHASH go on at a time
  460. server.rehashMutex.Lock()
  461. defer server.rehashMutex.Unlock()
  462. server.logger.Debug("server", "Got rehash lock")
  463. config, err := LoadConfig(server.configFilename)
  464. if err != nil {
  465. server.logger.Error("server", "failed to load config file", err.Error())
  466. return err
  467. }
  468. err = server.applyConfig(config)
  469. if err != nil {
  470. server.logger.Error("server", "Failed to rehash", err.Error())
  471. return err
  472. }
  473. server.logger.Info("server", "Rehash completed successfully")
  474. return nil
  475. }
  476. func (server *Server) applyConfig(config *Config) (err error) {
  477. oldConfig := server.Config()
  478. initial := oldConfig == nil
  479. if initial {
  480. server.configFilename = config.Filename
  481. server.name = config.Server.Name
  482. server.nameCasefolded = config.Server.nameCasefolded
  483. globalCasemappingSetting = config.Server.Casemapping
  484. globalUtf8EnforcementSetting = config.Server.EnforceUtf8
  485. } else {
  486. // enforce configs that can't be changed after launch:
  487. if server.name != config.Server.Name {
  488. return fmt.Errorf("Server name cannot be changed after launching the server, rehash aborted")
  489. } else if oldConfig.Datastore.Path != config.Datastore.Path {
  490. return fmt.Errorf("Datastore path cannot be changed after launching the server, rehash aborted")
  491. } else if globalCasemappingSetting != config.Server.Casemapping {
  492. return fmt.Errorf("Casemapping cannot be changed after launching the server, rehash aborted")
  493. } else if globalUtf8EnforcementSetting != config.Server.EnforceUtf8 {
  494. return fmt.Errorf("UTF-8 enforcement cannot be changed after launching the server, rehash aborted")
  495. } else if oldConfig.Accounts.Multiclient.AlwaysOn != config.Accounts.Multiclient.AlwaysOn {
  496. return fmt.Errorf("Default always-on setting cannot be changed after launching the server, rehash aborted")
  497. } else if oldConfig.Server.Relaymsg.Enabled != config.Server.Relaymsg.Enabled {
  498. return fmt.Errorf("Cannot enable or disable relaying after launching the server, rehash aborted")
  499. } else if oldConfig.Server.Relaymsg.Separators != config.Server.Relaymsg.Separators {
  500. return fmt.Errorf("Cannot change relaying separators after launching the server, rehash aborted")
  501. } else if oldConfig.Server.IPCheckScript.MaxConcurrency != config.Server.IPCheckScript.MaxConcurrency ||
  502. oldConfig.Accounts.AuthScript.MaxConcurrency != config.Accounts.AuthScript.MaxConcurrency {
  503. return fmt.Errorf("Cannot change max-concurrency for scripts after launching the server, rehash aborted")
  504. } else if oldConfig.Server.OverrideServicesHostname != config.Server.OverrideServicesHostname {
  505. return fmt.Errorf("Cannot change override-services-hostname after launching the server, rehash aborted")
  506. } else if !oldConfig.Datastore.MySQL.Enabled && config.Datastore.MySQL.Enabled {
  507. return fmt.Errorf("Cannot enable MySQL after launching the server, rehash aborted")
  508. }
  509. }
  510. server.logger.Info("server", "Using config file", server.configFilename)
  511. // first, reload config sections for functionality implemented in subpackages:
  512. wasLoggingRawIO := !initial && server.logger.IsLoggingRawIO()
  513. err = server.logger.ApplyConfig(config.Logging)
  514. if err != nil {
  515. return err
  516. }
  517. nowLoggingRawIO := server.logger.IsLoggingRawIO()
  518. // notify existing clients if raw i/o logging was enabled by a rehash
  519. sendRawOutputNotice := !wasLoggingRawIO && nowLoggingRawIO
  520. server.connectionLimiter.ApplyConfig(&config.Server.IPLimits)
  521. tlConf := &config.Server.TorListeners
  522. server.torLimiter.Configure(tlConf.MaxConnections, tlConf.ThrottleDuration, tlConf.MaxConnectionsPerDuration)
  523. // Translations
  524. server.logger.Debug("server", "Regenerating HELP indexes for new languages")
  525. server.helpIndexManager.GenerateIndices(config.languageManager)
  526. if initial {
  527. maxIPConc := int(config.Server.IPCheckScript.MaxConcurrency)
  528. if maxIPConc != 0 {
  529. server.semaphores.IPCheckScript.Initialize(maxIPConc)
  530. }
  531. maxAuthConc := int(config.Accounts.AuthScript.MaxConcurrency)
  532. if maxAuthConc != 0 {
  533. server.semaphores.AuthScript.Initialize(maxAuthConc)
  534. }
  535. if err := overrideServicePrefixes(config.Server.OverrideServicesHostname); err != nil {
  536. return err
  537. }
  538. }
  539. if oldConfig != nil {
  540. // if certain features were enabled by rehash, we need to load the corresponding data
  541. // from the store
  542. if !oldConfig.Accounts.NickReservation.Enabled {
  543. server.accounts.buildNickToAccountIndex(config)
  544. }
  545. if !oldConfig.Channels.Registration.Enabled {
  546. server.channels.loadRegisteredChannels(config)
  547. }
  548. // resize history buffers as needed
  549. if config.historyChangedFrom(oldConfig) {
  550. for _, channel := range server.channels.Channels() {
  551. channel.resizeHistory(config)
  552. }
  553. for _, client := range server.clients.AllClients() {
  554. client.resizeHistory(config)
  555. }
  556. }
  557. if oldConfig.Accounts.Registration.Throttling != config.Accounts.Registration.Throttling {
  558. server.accounts.resetRegisterThrottle(config)
  559. }
  560. }
  561. server.logger.Info("server", "Using datastore", config.Datastore.Path)
  562. if initial {
  563. if err := server.loadDatastore(config); err != nil {
  564. return err
  565. }
  566. } else {
  567. if config.Datastore.MySQL.Enabled && config.Datastore.MySQL != oldConfig.Datastore.MySQL {
  568. server.historyDB.SetConfig(config.Datastore.MySQL)
  569. }
  570. }
  571. // now that the datastore is initialized, we can load the cloak secret from it
  572. // XXX this modifies config after the initial load, which is naughty,
  573. // but there's no data race because we haven't done SetConfig yet
  574. config.Server.Cloaks.SetSecret(LoadCloakSecret(server.store))
  575. // activate the new config
  576. server.SetConfig(config)
  577. // load [dk]-lines, registered users and channels, etc.
  578. if initial {
  579. if err := server.loadFromDatastore(config); err != nil {
  580. return err
  581. }
  582. }
  583. // burst new and removed caps
  584. addedCaps, removedCaps := config.Diff(oldConfig)
  585. var capBurstSessions []*Session
  586. added := make(map[caps.Version][]string)
  587. var removed []string
  588. if !addedCaps.Empty() || !removedCaps.Empty() {
  589. capBurstSessions = server.clients.AllWithCapsNotify()
  590. added[caps.Cap301] = addedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  591. added[caps.Cap302] = addedCaps.Strings(caps.Cap302, config.Server.capValues, 0)
  592. // removed never has values, so we leave it as Cap301
  593. removed = removedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  594. }
  595. for _, sSession := range capBurstSessions {
  596. // DEL caps and then send NEW ones so that updated caps get removed/added correctly
  597. if !removedCaps.Empty() {
  598. for _, capStr := range removed {
  599. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "DEL", capStr)
  600. }
  601. }
  602. if !addedCaps.Empty() {
  603. for _, capStr := range added[sSession.capVersion] {
  604. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "NEW", capStr)
  605. }
  606. }
  607. }
  608. server.setupPprofListener(config)
  609. // set RPL_ISUPPORT
  610. var newISupportReplies [][]string
  611. if oldConfig != nil {
  612. newISupportReplies = oldConfig.Server.isupport.GetDifference(&config.Server.isupport)
  613. }
  614. if len(config.Server.ProxyAllowedFrom) != 0 {
  615. server.logger.Info("server", "Proxied IPs will be accepted from", strings.Join(config.Server.ProxyAllowedFrom, ", "))
  616. }
  617. // we are now open for business
  618. err = server.setupListeners(config)
  619. if !initial {
  620. // push new info to all of our clients
  621. for _, sClient := range server.clients.AllClients() {
  622. for _, tokenline := range newISupportReplies {
  623. sClient.Send(nil, server.name, RPL_ISUPPORT, append([]string{sClient.nick}, tokenline...)...)
  624. }
  625. if sendRawOutputNotice {
  626. sClient.Notice(sClient.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  627. }
  628. }
  629. }
  630. return err
  631. }
  632. func (server *Server) setupPprofListener(config *Config) {
  633. pprofListener := ""
  634. if config.Debug.PprofListener != nil {
  635. pprofListener = *config.Debug.PprofListener
  636. }
  637. if server.pprofServer != nil {
  638. if pprofListener == "" || (pprofListener != server.pprofServer.Addr) {
  639. server.logger.Info("server", "Stopping pprof listener", server.pprofServer.Addr)
  640. server.pprofServer.Close()
  641. server.pprofServer = nil
  642. }
  643. }
  644. if pprofListener != "" && server.pprofServer == nil {
  645. ps := http.Server{
  646. Addr: pprofListener,
  647. }
  648. go func() {
  649. if err := ps.ListenAndServe(); err != nil {
  650. server.logger.Error("server", "pprof listener failed", err.Error())
  651. }
  652. }()
  653. server.pprofServer = &ps
  654. server.logger.Info("server", "Started pprof listener", server.pprofServer.Addr)
  655. }
  656. }
  657. func (server *Server) loadDatastore(config *Config) error {
  658. // open the datastore and load server state for which it (rather than config)
  659. // is the source of truth
  660. _, err := os.Stat(config.Datastore.Path)
  661. if os.IsNotExist(err) {
  662. server.logger.Warning("server", "database does not exist, creating it", config.Datastore.Path)
  663. err = initializeDB(config.Datastore.Path)
  664. if err != nil {
  665. return err
  666. }
  667. }
  668. db, err := OpenDatabase(config)
  669. if err == nil {
  670. server.store = db
  671. return nil
  672. } else {
  673. return fmt.Errorf("Failed to open datastore: %s", err.Error())
  674. }
  675. }
  676. func (server *Server) loadFromDatastore(config *Config) (err error) {
  677. // load *lines (from the datastores)
  678. server.logger.Debug("server", "Loading D/Klines")
  679. server.loadDLines()
  680. server.loadKLines()
  681. server.channelRegistry.Initialize(server)
  682. server.channels.Initialize(server)
  683. server.accounts.Initialize(server)
  684. if config.Datastore.MySQL.Enabled {
  685. server.historyDB.Initialize(server.logger, config.Datastore.MySQL)
  686. err = server.historyDB.Open()
  687. if err != nil {
  688. server.logger.Error("internal", "could not connect to mysql", err.Error())
  689. return err
  690. }
  691. }
  692. return nil
  693. }
  694. func (server *Server) setupListeners(config *Config) (err error) {
  695. logListener := func(addr string, config utils.ListenerConfig) {
  696. server.logger.Info("listeners",
  697. fmt.Sprintf("now listening on %s, tls=%t, proxy=%t, tor=%t, websocket=%t.", addr, (config.TLSConfig != nil), config.RequireProxy, config.Tor, config.WebSocket),
  698. )
  699. }
  700. // update or destroy all existing listeners
  701. for addr := range server.listeners {
  702. currentListener := server.listeners[addr]
  703. newConfig, stillConfigured := config.Server.trueListeners[addr]
  704. if stillConfigured {
  705. if reloadErr := currentListener.Reload(newConfig); reloadErr == nil {
  706. logListener(addr, newConfig)
  707. } else {
  708. // stop the listener; we will attempt to replace it below
  709. currentListener.Stop()
  710. delete(server.listeners, addr)
  711. }
  712. } else {
  713. currentListener.Stop()
  714. delete(server.listeners, addr)
  715. server.logger.Info("listeners", fmt.Sprintf("stopped listening on %s.", addr))
  716. }
  717. }
  718. publicPlaintextListener := ""
  719. // create new listeners that were not previously configured,
  720. // or that couldn't be reloaded above:
  721. for newAddr, newConfig := range config.Server.trueListeners {
  722. if strings.HasPrefix(newAddr, ":") && !newConfig.Tor && !newConfig.STSOnly && newConfig.TLSConfig == nil {
  723. publicPlaintextListener = newAddr
  724. }
  725. _, exists := server.listeners[newAddr]
  726. if !exists {
  727. // make a new listener
  728. newListener, newErr := NewListener(server, newAddr, newConfig, config.Server.UnixBindMode)
  729. if newErr == nil {
  730. server.listeners[newAddr] = newListener
  731. logListener(newAddr, newConfig)
  732. } else {
  733. server.logger.Error("server", "couldn't listen on", newAddr, newErr.Error())
  734. err = newErr
  735. }
  736. }
  737. }
  738. if publicPlaintextListener != "" {
  739. server.logger.Warning("listeners", fmt.Sprintf("Your server is configured with public plaintext listener %s. Consider disabling it for improved security and privacy.", publicPlaintextListener))
  740. }
  741. return
  742. }
  743. // Gets the abstract sequence from which we're going to query history;
  744. // we may already know the channel we're querying, or we may have
  745. // to look it up via a string query. This function is responsible for
  746. // privilege checking.
  747. func (server *Server) GetHistorySequence(providedChannel *Channel, client *Client, query string) (channel *Channel, sequence history.Sequence, err error) {
  748. config := server.Config()
  749. // 4 cases: {persistent, ephemeral} x {normal, conversation}
  750. // with ephemeral history, target is implicit in the choice of `hist`,
  751. // and correspondent is "" if we're retrieving a channel or *, and the correspondent's name
  752. // if we're retrieving a DM conversation ("query buffer"). with persistent history,
  753. // target is always nonempty, and correspondent is either empty or nonempty as before.
  754. var status HistoryStatus
  755. var target, correspondent string
  756. var hist *history.Buffer
  757. restriction := HistoryCutoffNone
  758. channel = providedChannel
  759. if channel == nil {
  760. if strings.HasPrefix(query, "#") {
  761. channel = server.channels.Get(query)
  762. if channel == nil {
  763. return
  764. }
  765. }
  766. }
  767. var joinTimeCutoff time.Time
  768. if channel != nil {
  769. if present, cutoff := channel.joinTimeCutoff(client); present {
  770. joinTimeCutoff = cutoff
  771. } else {
  772. err = errInsufficientPrivs
  773. return
  774. }
  775. status, target, restriction = channel.historyStatus(config)
  776. switch status {
  777. case HistoryEphemeral:
  778. hist = &channel.history
  779. case HistoryPersistent:
  780. // already set `target`
  781. default:
  782. return
  783. }
  784. } else {
  785. status, target = client.historyStatus(config)
  786. if query != "*" {
  787. correspondent, err = CasefoldName(query)
  788. if err != nil {
  789. return
  790. }
  791. }
  792. switch status {
  793. case HistoryEphemeral:
  794. hist = &client.history
  795. case HistoryPersistent:
  796. // already set `target`, and `correspondent` if necessary
  797. default:
  798. return
  799. }
  800. }
  801. var cutoff time.Time
  802. if config.History.Restrictions.ExpireTime != 0 {
  803. cutoff = time.Now().UTC().Add(-time.Duration(config.History.Restrictions.ExpireTime))
  804. }
  805. // #836: registration date cutoff is always enforced for DMs
  806. // either way, take the later of the two cutoffs
  807. if restriction == HistoryCutoffRegistrationTime || channel == nil {
  808. regCutoff := client.historyCutoff()
  809. if regCutoff.After(cutoff) {
  810. cutoff = regCutoff
  811. }
  812. } else if restriction == HistoryCutoffJoinTime {
  813. if joinTimeCutoff.After(cutoff) {
  814. cutoff = joinTimeCutoff
  815. }
  816. }
  817. // #836 again: grace period is never applied to DMs
  818. if !cutoff.IsZero() && channel != nil && restriction != HistoryCutoffJoinTime {
  819. cutoff = cutoff.Add(-time.Duration(config.History.Restrictions.GracePeriod))
  820. }
  821. if hist != nil {
  822. sequence = hist.MakeSequence(correspondent, cutoff)
  823. } else if target != "" {
  824. sequence = server.historyDB.MakeSequence(target, correspondent, cutoff)
  825. }
  826. return
  827. }
  828. func (server *Server) ForgetHistory(accountName string) {
  829. // sanity check
  830. if accountName == "*" {
  831. return
  832. }
  833. config := server.Config()
  834. if !config.History.Enabled {
  835. return
  836. }
  837. if cfAccount, err := CasefoldName(accountName); err == nil {
  838. server.historyDB.Forget(cfAccount)
  839. }
  840. persistent := config.History.Persistent
  841. if persistent.Enabled && persistent.UnregisteredChannels && persistent.RegisteredChannels == PersistentMandatory && persistent.DirectMessages == PersistentMandatory {
  842. return
  843. }
  844. predicate := func(item *history.Item) bool { return item.AccountName == accountName }
  845. for _, channel := range server.channels.Channels() {
  846. channel.history.Delete(predicate)
  847. }
  848. for _, client := range server.clients.AllClients() {
  849. client.history.Delete(predicate)
  850. }
  851. }
  852. // deletes a message. target is a hint about what buffer it's in (not required for
  853. // persistent history, where all the msgids are indexed together). if accountName
  854. // is anything other than "*", it must match the recorded AccountName of the message
  855. func (server *Server) DeleteMessage(target, msgid, accountName string) (err error) {
  856. config := server.Config()
  857. var hist *history.Buffer
  858. if target != "" {
  859. if target[0] == '#' {
  860. channel := server.channels.Get(target)
  861. if channel != nil {
  862. if status, _, _ := channel.historyStatus(config); status == HistoryEphemeral {
  863. hist = &channel.history
  864. }
  865. }
  866. } else {
  867. client := server.clients.Get(target)
  868. if client != nil {
  869. if status, _ := client.historyStatus(config); status == HistoryEphemeral {
  870. hist = &client.history
  871. }
  872. }
  873. }
  874. }
  875. if hist == nil {
  876. err = server.historyDB.DeleteMsgid(msgid, accountName)
  877. } else {
  878. count := hist.Delete(func(item *history.Item) bool {
  879. return item.Message.Msgid == msgid && (accountName == "*" || item.AccountName == accountName)
  880. })
  881. if count == 0 {
  882. err = errNoop
  883. }
  884. }
  885. return
  886. }
  887. // elistMatcher takes and matches ELIST conditions
  888. type elistMatcher struct {
  889. MinClientsActive bool
  890. MinClients int
  891. MaxClientsActive bool
  892. MaxClients int
  893. }
  894. // Matches checks whether the given channel matches our matches.
  895. func (matcher *elistMatcher) Matches(channel *Channel) bool {
  896. if matcher.MinClientsActive {
  897. if len(channel.Members()) < matcher.MinClients {
  898. return false
  899. }
  900. }
  901. if matcher.MaxClientsActive {
  902. if len(channel.Members()) < len(channel.members) {
  903. return false
  904. }
  905. }
  906. return true
  907. }
  908. var (
  909. infoString1 = strings.Split(` ▄▄▄ ▄▄▄· ▄▄ • ▐ ▄
  910. ▪ ▀▄ █·▐█ ▀█ ▐█ ▀ ▪▪ •█▌▐█▪
  911. ▄█▀▄ ▐▀▀▄ ▄█▀▀█ ▄█ ▀█▄ ▄█▀▄▪▐█▐▐▌ ▄█▀▄
  912. ▐█▌.▐▌▐█•█▌▐█ ▪▐▌▐█▄▪▐█▐█▌ ▐▌██▐█▌▐█▌.▐▌
  913. ▀█▄▀▪.▀ ▀ ▀ ▀ ·▀▀▀▀ ▀█▄▀ ▀▀ █▪ ▀█▄▀▪
  914. https://oragono.io/
  915. https://github.com/oragono/oragono
  916. https://crowdin.com/project/oragono
  917. `, "\n")
  918. infoString2 = strings.Split(` Daniel Oakley, DanielOaks, <daniel@danieloaks.net>
  919. Shivaram Lingamneni, slingamn, <slingamn@cs.stanford.edu>
  920. `, "\n")
  921. infoString3 = strings.Split(` Jeremy Latt, jlatt
  922. Edmund Huber, edmund-huber
  923. `, "\n")
  924. )