You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

server.go 37KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073
  1. // Copyright (c) 2012-2014 Jeremy Latt
  2. // Copyright (c) 2014-2015 Edmund Huber
  3. // Copyright (c) 2016-2017 Daniel Oaks <daniel@danieloaks.net>
  4. // released under the MIT license
  5. package irc
  6. import (
  7. "fmt"
  8. "net"
  9. "net/http"
  10. _ "net/http/pprof"
  11. "os"
  12. "os/signal"
  13. "runtime/debug"
  14. "strconv"
  15. "strings"
  16. "sync"
  17. "syscall"
  18. "time"
  19. "unsafe"
  20. "github.com/goshuirc/irc-go/ircfmt"
  21. "github.com/ergochat/ergo/irc/caps"
  22. "github.com/ergochat/ergo/irc/connection_limits"
  23. "github.com/ergochat/ergo/irc/flatip"
  24. "github.com/ergochat/ergo/irc/history"
  25. "github.com/ergochat/ergo/irc/logger"
  26. "github.com/ergochat/ergo/irc/modes"
  27. "github.com/ergochat/ergo/irc/mysql"
  28. "github.com/ergochat/ergo/irc/sno"
  29. "github.com/ergochat/ergo/irc/utils"
  30. "github.com/tidwall/buntdb"
  31. )
  32. const (
  33. alwaysOnExpirationPollPeriod = time.Hour
  34. )
  35. var (
  36. // common error line to sub values into
  37. errorMsg = "ERROR :%s\r\n"
  38. // three final parameters of 004 RPL_MYINFO, enumerating our supported modes
  39. rplMyInfo1, rplMyInfo2, rplMyInfo3 = modes.RplMyInfo()
  40. // CHANMODES isupport token
  41. chanmodesToken = modes.ChanmodesToken()
  42. // whitelist of caps to serve on the STS-only listener. In particular,
  43. // never advertise SASL, to discourage people from sending their passwords:
  44. stsOnlyCaps = caps.NewSet(caps.STS, caps.MessageTags, caps.ServerTime, caps.Batch, caps.LabeledResponse, caps.EchoMessage, caps.Nope)
  45. // we only have standard channels for now. TODO: any updates to this
  46. // will also need to be reflected in CasefoldChannel
  47. chanTypes = "#"
  48. throttleMessage = "You have attempted to connect too many times within a short duration. Wait a while, and you will be able to connect."
  49. )
  50. // Server is the main Oragono server.
  51. type Server struct {
  52. accounts AccountManager
  53. channels ChannelManager
  54. channelRegistry ChannelRegistry
  55. clients ClientManager
  56. config unsafe.Pointer
  57. configFilename string
  58. connectionLimiter connection_limits.Limiter
  59. ctime time.Time
  60. dlines *DLineManager
  61. helpIndexManager HelpIndexManager
  62. klines *KLineManager
  63. listeners map[string]IRCListener
  64. logger *logger.Manager
  65. monitorManager MonitorManager
  66. name string
  67. nameCasefolded string
  68. rehashMutex sync.Mutex // tier 4
  69. rehashSignal chan os.Signal
  70. pprofServer *http.Server
  71. signals chan os.Signal
  72. snomasks SnoManager
  73. store *buntdb.DB
  74. historyDB mysql.MySQL
  75. torLimiter connection_limits.TorLimiter
  76. whoWas WhoWasList
  77. stats Stats
  78. semaphores ServerSemaphores
  79. defcon uint32
  80. }
  81. // NewServer returns a new Oragono server.
  82. func NewServer(config *Config, logger *logger.Manager) (*Server, error) {
  83. // initialize data structures
  84. server := &Server{
  85. ctime: time.Now().UTC(),
  86. listeners: make(map[string]IRCListener),
  87. logger: logger,
  88. rehashSignal: make(chan os.Signal, 1),
  89. signals: make(chan os.Signal, len(ServerExitSignals)),
  90. defcon: 5,
  91. }
  92. server.clients.Initialize()
  93. server.semaphores.Initialize()
  94. server.whoWas.Initialize(config.Limits.WhowasEntries)
  95. server.monitorManager.Initialize()
  96. server.snomasks.Initialize()
  97. if err := server.applyConfig(config); err != nil {
  98. return nil, err
  99. }
  100. // Attempt to clean up when receiving these signals.
  101. signal.Notify(server.signals, ServerExitSignals...)
  102. signal.Notify(server.rehashSignal, syscall.SIGHUP)
  103. time.AfterFunc(alwaysOnExpirationPollPeriod, server.handleAlwaysOnExpirations)
  104. return server, nil
  105. }
  106. // Shutdown shuts down the server.
  107. func (server *Server) Shutdown() {
  108. //TODO(dan): Make sure we disallow new nicks
  109. for _, client := range server.clients.AllClients() {
  110. client.Notice("Server is shutting down")
  111. if client.AlwaysOn() {
  112. client.Store(IncludeLastSeen)
  113. }
  114. }
  115. if err := server.store.Close(); err != nil {
  116. server.logger.Error("shutdown", fmt.Sprintln("Could not close datastore:", err))
  117. }
  118. server.historyDB.Close()
  119. }
  120. // Run starts the server.
  121. func (server *Server) Run() {
  122. // defer closing db/store
  123. defer server.store.Close()
  124. for {
  125. select {
  126. case <-server.signals:
  127. server.Shutdown()
  128. return
  129. case <-server.rehashSignal:
  130. server.logger.Info("server", "Rehashing due to SIGHUP")
  131. go server.rehash()
  132. }
  133. }
  134. }
  135. func (server *Server) checkBans(config *Config, ipaddr net.IP, checkScripts bool) (banned bool, requireSASL bool, message string) {
  136. // #671: do not enforce bans against loopback, as a failsafe
  137. // note that this function is not used for Tor connections (checkTorLimits is used instead)
  138. if ipaddr.IsLoopback() {
  139. return
  140. }
  141. if server.Defcon() == 1 {
  142. if !utils.IPInNets(ipaddr, server.Config().Server.secureNets) {
  143. return true, false, "New connections to this server are temporarily restricted"
  144. }
  145. }
  146. flat := flatip.FromNetIP(ipaddr)
  147. // check DLINEs
  148. isBanned, info := server.dlines.CheckIP(flat)
  149. if isBanned {
  150. if info.RequireSASL {
  151. server.logger.Info("connect-ip", "Requiring SASL from client due to d-line", ipaddr.String())
  152. return false, true, info.BanMessage("You must authenticate with SASL to connect from this IP (%s)")
  153. } else {
  154. server.logger.Info("connect-ip", "Client rejected by d-line", ipaddr.String())
  155. return true, false, info.BanMessage("You are banned from this server (%s)")
  156. }
  157. }
  158. // check connection limits
  159. err := server.connectionLimiter.AddClient(flat)
  160. if err == connection_limits.ErrLimitExceeded {
  161. // too many connections from one client, tell the client and close the connection
  162. server.logger.Info("connect-ip", "Client rejected for connection limit", ipaddr.String())
  163. return true, false, "Too many clients from your network"
  164. } else if err == connection_limits.ErrThrottleExceeded {
  165. server.logger.Info("connect-ip", "Client exceeded connection throttle", ipaddr.String())
  166. return true, false, throttleMessage
  167. } else if err != nil {
  168. server.logger.Warning("internal", "unexpected ban result", err.Error())
  169. }
  170. if checkScripts && config.Server.IPCheckScript.Enabled {
  171. output, err := CheckIPBan(server.semaphores.IPCheckScript, config.Server.IPCheckScript, ipaddr)
  172. if err != nil {
  173. server.logger.Error("internal", "couldn't check IP ban script", ipaddr.String(), err.Error())
  174. return false, false, ""
  175. }
  176. // TODO: currently no way to cache IPAccepted
  177. if (output.Result == IPBanned || output.Result == IPRequireSASL) && output.CacheSeconds != 0 {
  178. network, err := flatip.ParseToNormalizedNet(output.CacheNet)
  179. if err != nil {
  180. server.logger.Error("internal", "invalid dline net from IP ban script", ipaddr.String(), output.CacheNet)
  181. } else {
  182. dlineDuration := time.Duration(output.CacheSeconds) * time.Second
  183. err := server.dlines.AddNetwork(network, dlineDuration, output.Result == IPRequireSASL, output.BanMessage, "", "")
  184. if err != nil {
  185. server.logger.Error("internal", "couldn't set dline from IP ban script", ipaddr.String(), err.Error())
  186. }
  187. }
  188. }
  189. if output.Result == IPBanned {
  190. // XXX roll back IP connection/throttling addition for the IP
  191. server.connectionLimiter.RemoveClient(flat)
  192. server.logger.Info("connect-ip", "Rejected client due to ip-check-script", ipaddr.String())
  193. return true, false, output.BanMessage
  194. } else if output.Result == IPRequireSASL {
  195. server.logger.Info("connect-ip", "Requiring SASL from client due to ip-check-script", ipaddr.String())
  196. return false, true, output.BanMessage
  197. }
  198. }
  199. return false, false, ""
  200. }
  201. func (server *Server) checkTorLimits() (banned bool, message string) {
  202. switch server.torLimiter.AddClient() {
  203. case connection_limits.ErrLimitExceeded:
  204. return true, "Too many clients from the Tor network"
  205. case connection_limits.ErrThrottleExceeded:
  206. return true, "Exceeded connection throttle for the Tor network"
  207. default:
  208. return false, ""
  209. }
  210. }
  211. func (server *Server) handleAlwaysOnExpirations() {
  212. defer func() {
  213. if r := recover(); r != nil {
  214. server.logger.Error("internal",
  215. fmt.Sprintf("Panic in always-on cleanup: %v\n%s", r, debug.Stack()))
  216. }
  217. // either way, reschedule
  218. time.AfterFunc(alwaysOnExpirationPollPeriod, server.handleAlwaysOnExpirations)
  219. }()
  220. config := server.Config()
  221. deadline := time.Duration(config.Accounts.Multiclient.AlwaysOnExpiration)
  222. if deadline == 0 {
  223. return
  224. }
  225. server.logger.Info("accounts", "Checking always-on clients for expiration")
  226. for _, client := range server.clients.AllClients() {
  227. if client.IsExpiredAlwaysOn(config) {
  228. // TODO save the channels list, use it for autojoin if/when they return?
  229. server.logger.Info("accounts", "Expiring always-on client", client.AccountName())
  230. client.destroy(nil)
  231. }
  232. }
  233. }
  234. //
  235. // server functionality
  236. //
  237. func (server *Server) tryRegister(c *Client, session *Session) (exiting bool) {
  238. // XXX PROXY or WEBIRC MUST be sent as the first line of the session;
  239. // if we are here at all that means we have the final value of the IP
  240. if session.rawHostname == "" {
  241. session.client.lookupHostname(session, false)
  242. }
  243. // try to complete registration normally
  244. // XXX(#1057) username can be filled in by an ident query without the client
  245. // having sent USER: check for both username and realname to ensure they did
  246. if c.preregNick == "" || c.username == "" || c.realname == "" || session.capState == caps.NegotiatingState {
  247. return
  248. }
  249. if c.isSTSOnly {
  250. server.playSTSBurst(session)
  251. return true
  252. }
  253. // client MUST send PASS if necessary, or authenticate with SASL if necessary,
  254. // before completing the other registration commands
  255. config := server.Config()
  256. authOutcome := c.isAuthorized(server, config, session, c.requireSASL)
  257. var quitMessage string
  258. switch authOutcome {
  259. case authFailPass:
  260. quitMessage = c.t("Password incorrect")
  261. c.Send(nil, server.name, ERR_PASSWDMISMATCH, "*", quitMessage)
  262. case authFailSaslRequired, authFailTorSaslRequired:
  263. quitMessage = c.requireSASLMessage
  264. if quitMessage == "" {
  265. quitMessage = c.t("You must log in with SASL to join this server")
  266. }
  267. c.Send(nil, c.server.name, "FAIL", "*", "ACCOUNT_REQUIRED", quitMessage)
  268. }
  269. if authOutcome != authSuccess {
  270. c.Quit(quitMessage, nil)
  271. return true
  272. }
  273. c.requireSASLMessage = ""
  274. rb := NewResponseBuffer(session)
  275. nickError := performNickChange(server, c, c, session, c.preregNick, rb)
  276. rb.Send(true)
  277. if nickError == errInsecureReattach {
  278. c.Quit(c.t("You can't mix secure and insecure connections to this account"), nil)
  279. return true
  280. } else if nickError != nil {
  281. c.preregNick = ""
  282. return false
  283. }
  284. if session.client != c {
  285. // reattached, bail out.
  286. // we'll play the reg burst later, on the new goroutine associated with
  287. // (thisSession, otherClient). This is to avoid having to transfer state
  288. // like nickname, hostname, etc. to show the correct values in the reg burst.
  289. return false
  290. }
  291. // Apply default user modes (without updating the invisible counter)
  292. // The number of invisible users will be updated by server.stats.Register
  293. // if we're using default user mode +i.
  294. for _, defaultMode := range config.Accounts.defaultUserModes {
  295. c.SetMode(defaultMode, true)
  296. }
  297. // count new user in statistics (before checking KLINEs, see #1303)
  298. server.stats.Register(c.HasMode(modes.Invisible))
  299. // check KLINEs (#671: ignore KLINEs for loopback connections)
  300. if !session.IP().IsLoopback() || session.isTor {
  301. isBanned, info := server.klines.CheckMasks(c.AllNickmasks()...)
  302. if isBanned {
  303. c.Quit(info.BanMessage(c.t("You are banned from this server (%s)")), nil)
  304. return true
  305. }
  306. }
  307. server.playRegistrationBurst(session)
  308. return false
  309. }
  310. func (server *Server) playSTSBurst(session *Session) {
  311. nick := utils.SafeErrorParam(session.client.preregNick)
  312. session.Send(nil, server.name, RPL_WELCOME, nick, fmt.Sprintf("Welcome to the Internet Relay Network %s", nick))
  313. session.Send(nil, server.name, RPL_YOURHOST, nick, fmt.Sprintf("Your host is %[1]s, running version %[2]s", server.name, "ergo"))
  314. session.Send(nil, server.name, RPL_CREATED, nick, fmt.Sprintf("This server was created %s", time.Time{}.Format(time.RFC1123)))
  315. session.Send(nil, server.name, RPL_MYINFO, nick, server.name, "ergo", "o", "o", "o")
  316. session.Send(nil, server.name, RPL_ISUPPORT, nick, "CASEMAPPING=ascii", "are supported by this server")
  317. session.Send(nil, server.name, ERR_NOMOTD, nick, "MOTD is unavailable")
  318. for _, line := range server.Config().Server.STS.bannerLines {
  319. session.Send(nil, server.name, "NOTICE", nick, line)
  320. }
  321. }
  322. func (server *Server) playRegistrationBurst(session *Session) {
  323. c := session.client
  324. // continue registration
  325. d := c.Details()
  326. server.logger.Info("connect", fmt.Sprintf("Client connected [%s] [u:%s] [r:%s]", d.nick, d.username, d.realname))
  327. server.snomasks.Send(sno.LocalConnects, fmt.Sprintf("Client connected [%s] [u:%s] [h:%s] [ip:%s] [r:%s]", d.nick, d.username, session.rawHostname, session.IP().String(), d.realname))
  328. if d.account != "" {
  329. server.sendLoginSnomask(d.nickMask, d.accountName)
  330. }
  331. // send welcome text
  332. //NOTE(dan): we specifically use the NICK here instead of the nickmask
  333. // see http://modern.ircdocs.horse/#rplwelcome-001 for details on why we avoid using the nickmask
  334. config := server.Config()
  335. session.Send(nil, server.name, RPL_WELCOME, d.nick, fmt.Sprintf(c.t("Welcome to the %s IRC Network %s"), config.Network.Name, d.nick))
  336. session.Send(nil, server.name, RPL_YOURHOST, d.nick, fmt.Sprintf(c.t("Your host is %[1]s, running version %[2]s"), server.name, Ver))
  337. session.Send(nil, server.name, RPL_CREATED, d.nick, fmt.Sprintf(c.t("This server was created %s"), server.ctime.Format(time.RFC1123)))
  338. session.Send(nil, server.name, RPL_MYINFO, d.nick, server.name, Ver, rplMyInfo1, rplMyInfo2, rplMyInfo3)
  339. rb := NewResponseBuffer(session)
  340. server.RplISupport(c, rb)
  341. server.Lusers(c, rb)
  342. server.MOTD(c, rb)
  343. rb.Send(true)
  344. modestring := c.ModeString()
  345. if modestring != "+" {
  346. session.Send(nil, server.name, RPL_UMODEIS, d.nick, modestring)
  347. }
  348. c.attemptAutoOper(session)
  349. if server.logger.IsLoggingRawIO() {
  350. session.Send(nil, c.server.name, "NOTICE", d.nick, c.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  351. }
  352. }
  353. // RplISupport outputs our ISUPPORT lines to the client. This is used on connection and in VERSION responses.
  354. func (server *Server) RplISupport(client *Client, rb *ResponseBuffer) {
  355. translatedISupport := client.t("are supported by this server")
  356. nick := client.Nick()
  357. config := server.Config()
  358. for _, cachedTokenLine := range config.Server.isupport.CachedReply {
  359. length := len(cachedTokenLine) + 2
  360. tokenline := make([]string, length)
  361. tokenline[0] = nick
  362. copy(tokenline[1:], cachedTokenLine)
  363. tokenline[length-1] = translatedISupport
  364. rb.Add(nil, server.name, RPL_ISUPPORT, tokenline...)
  365. }
  366. }
  367. func (server *Server) Lusers(client *Client, rb *ResponseBuffer) {
  368. nick := client.Nick()
  369. stats := server.stats.GetValues()
  370. rb.Add(nil, server.name, RPL_LUSERCLIENT, nick, fmt.Sprintf(client.t("There are %[1]d users and %[2]d invisible on %[3]d server(s)"), stats.Total-stats.Invisible, stats.Invisible, 1))
  371. rb.Add(nil, server.name, RPL_LUSEROP, nick, strconv.Itoa(stats.Operators), client.t("IRC Operators online"))
  372. rb.Add(nil, server.name, RPL_LUSERUNKNOWN, nick, strconv.Itoa(stats.Unknown), client.t("unregistered connections"))
  373. rb.Add(nil, server.name, RPL_LUSERCHANNELS, nick, strconv.Itoa(server.channels.Len()), client.t("channels formed"))
  374. rb.Add(nil, server.name, RPL_LUSERME, nick, fmt.Sprintf(client.t("I have %[1]d clients and %[2]d servers"), stats.Total, 0))
  375. total := strconv.Itoa(stats.Total)
  376. max := strconv.Itoa(stats.Max)
  377. rb.Add(nil, server.name, RPL_LOCALUSERS, nick, total, max, fmt.Sprintf(client.t("Current local users %[1]s, max %[2]s"), total, max))
  378. rb.Add(nil, server.name, RPL_GLOBALUSERS, nick, total, max, fmt.Sprintf(client.t("Current global users %[1]s, max %[2]s"), total, max))
  379. }
  380. // MOTD serves the Message of the Day.
  381. func (server *Server) MOTD(client *Client, rb *ResponseBuffer) {
  382. motdLines := server.Config().Server.motdLines
  383. if len(motdLines) < 1 {
  384. rb.Add(nil, server.name, ERR_NOMOTD, client.nick, client.t("MOTD File is missing"))
  385. return
  386. }
  387. rb.Add(nil, server.name, RPL_MOTDSTART, client.nick, fmt.Sprintf(client.t("- %s Message of the day - "), server.name))
  388. for _, line := range motdLines {
  389. rb.Add(nil, server.name, RPL_MOTD, client.nick, line)
  390. }
  391. rb.Add(nil, server.name, RPL_ENDOFMOTD, client.nick, client.t("End of MOTD command"))
  392. }
  393. func (client *Client) whoisChannelsNames(target *Client, multiPrefix bool, hasPrivs bool) []string {
  394. var chstrs []string
  395. targetInvis := target.HasMode(modes.Invisible)
  396. for _, channel := range target.Channels() {
  397. if !hasPrivs && (targetInvis || channel.flags.HasMode(modes.Secret)) && !channel.hasClient(client) {
  398. // client can't see *this* channel membership
  399. continue
  400. }
  401. chstrs = append(chstrs, channel.ClientPrefixes(target, multiPrefix)+channel.name)
  402. }
  403. return chstrs
  404. }
  405. func (client *Client) getWhoisOf(target *Client, hasPrivs bool, rb *ResponseBuffer) {
  406. oper := client.Oper()
  407. cnick := client.Nick()
  408. targetInfo := target.Details()
  409. rb.Add(nil, client.server.name, RPL_WHOISUSER, cnick, targetInfo.nick, targetInfo.username, targetInfo.hostname, "*", targetInfo.realname)
  410. tnick := targetInfo.nick
  411. whoischannels := client.whoisChannelsNames(target, rb.session.capabilities.Has(caps.MultiPrefix), oper.HasRoleCapab("sajoin"))
  412. if whoischannels != nil {
  413. rb.Add(nil, client.server.name, RPL_WHOISCHANNELS, cnick, tnick, strings.Join(whoischannels, " "))
  414. }
  415. if target.HasMode(modes.Operator) && operStatusVisible(client, target, oper != nil) {
  416. tOper := target.Oper()
  417. if tOper != nil {
  418. rb.Add(nil, client.server.name, RPL_WHOISOPERATOR, cnick, tnick, tOper.WhoisLine)
  419. }
  420. }
  421. if client == target || oper.HasRoleCapab("ban") {
  422. rb.Add(nil, client.server.name, RPL_WHOISACTUALLY, cnick, tnick, fmt.Sprintf("%s@%s", targetInfo.username, target.RawHostname()), target.IPString(), client.t("Actual user@host, Actual IP"))
  423. }
  424. if client == target || oper.HasRoleCapab("samode") {
  425. rb.Add(nil, client.server.name, RPL_WHOISMODES, cnick, tnick, fmt.Sprintf(client.t("is using modes +%s"), target.modes.String()))
  426. }
  427. if target.HasMode(modes.TLS) {
  428. rb.Add(nil, client.server.name, RPL_WHOISSECURE, cnick, tnick, client.t("is using a secure connection"))
  429. }
  430. if targetInfo.accountName != "*" {
  431. rb.Add(nil, client.server.name, RPL_WHOISACCOUNT, cnick, tnick, targetInfo.accountName, client.t("is logged in as"))
  432. }
  433. if target.HasMode(modes.Bot) {
  434. rb.Add(nil, client.server.name, RPL_WHOISBOT, cnick, tnick, fmt.Sprintf(ircfmt.Unescape(client.t("is a $bBot$b on %s")), client.server.Config().Network.Name))
  435. }
  436. if client == target || oper.HasRoleCapab("ban") {
  437. for _, session := range target.Sessions() {
  438. if session.certfp != "" {
  439. rb.Add(nil, client.server.name, RPL_WHOISCERTFP, cnick, tnick, fmt.Sprintf(client.t("has client certificate fingerprint %s"), session.certfp))
  440. }
  441. }
  442. }
  443. rb.Add(nil, client.server.name, RPL_WHOISIDLE, cnick, tnick, strconv.FormatUint(target.IdleSeconds(), 10), strconv.FormatInt(target.SignonTime(), 10), client.t("seconds idle, signon time"))
  444. if away, awayMessage := target.Away(); away {
  445. rb.Add(nil, client.server.name, RPL_AWAY, cnick, tnick, awayMessage)
  446. }
  447. }
  448. // rehash reloads the config and applies the changes from the config file.
  449. func (server *Server) rehash() error {
  450. // #1570; this needs its own panic handling because it can be invoked via SIGHUP
  451. defer func() {
  452. if r := recover(); r != nil {
  453. if server.Config().Debug.recoverFromErrors {
  454. server.logger.Error("internal",
  455. fmt.Sprintf("Panic during rehash: %v\n%s", r, debug.Stack()))
  456. } else {
  457. panic(r)
  458. }
  459. }
  460. }()
  461. server.logger.Info("server", "Attempting rehash")
  462. // only let one REHASH go on at a time
  463. server.rehashMutex.Lock()
  464. defer server.rehashMutex.Unlock()
  465. config, err := LoadConfig(server.configFilename)
  466. if err != nil {
  467. server.logger.Error("server", "failed to load config file", err.Error())
  468. return err
  469. }
  470. err = server.applyConfig(config)
  471. if err != nil {
  472. server.logger.Error("server", "Failed to rehash", err.Error())
  473. return err
  474. }
  475. server.logger.Info("server", "Rehash completed successfully")
  476. return nil
  477. }
  478. func (server *Server) applyConfig(config *Config) (err error) {
  479. oldConfig := server.Config()
  480. initial := oldConfig == nil
  481. if initial {
  482. server.configFilename = config.Filename
  483. server.name = config.Server.Name
  484. server.nameCasefolded = config.Server.nameCasefolded
  485. globalCasemappingSetting = config.Server.Casemapping
  486. globalUtf8EnforcementSetting = config.Server.EnforceUtf8
  487. MaxLineLen = config.Server.MaxLineLen
  488. } else {
  489. // enforce configs that can't be changed after launch:
  490. if server.name != config.Server.Name {
  491. return fmt.Errorf("Server name cannot be changed after launching the server, rehash aborted")
  492. } else if oldConfig.Datastore.Path != config.Datastore.Path {
  493. return fmt.Errorf("Datastore path cannot be changed after launching the server, rehash aborted")
  494. } else if globalCasemappingSetting != config.Server.Casemapping {
  495. return fmt.Errorf("Casemapping cannot be changed after launching the server, rehash aborted")
  496. } else if globalUtf8EnforcementSetting != config.Server.EnforceUtf8 {
  497. return fmt.Errorf("UTF-8 enforcement cannot be changed after launching the server, rehash aborted")
  498. } else if oldConfig.Accounts.Multiclient.AlwaysOn != config.Accounts.Multiclient.AlwaysOn {
  499. return fmt.Errorf("Default always-on setting cannot be changed after launching the server, rehash aborted")
  500. } else if oldConfig.Server.Relaymsg.Enabled != config.Server.Relaymsg.Enabled {
  501. return fmt.Errorf("Cannot enable or disable relaying after launching the server, rehash aborted")
  502. } else if oldConfig.Server.Relaymsg.Separators != config.Server.Relaymsg.Separators {
  503. return fmt.Errorf("Cannot change relaying separators after launching the server, rehash aborted")
  504. } else if oldConfig.Server.IPCheckScript.MaxConcurrency != config.Server.IPCheckScript.MaxConcurrency ||
  505. oldConfig.Accounts.AuthScript.MaxConcurrency != config.Accounts.AuthScript.MaxConcurrency {
  506. return fmt.Errorf("Cannot change max-concurrency for scripts after launching the server, rehash aborted")
  507. } else if oldConfig.Server.OverrideServicesHostname != config.Server.OverrideServicesHostname {
  508. return fmt.Errorf("Cannot change override-services-hostname after launching the server, rehash aborted")
  509. } else if !oldConfig.Datastore.MySQL.Enabled && config.Datastore.MySQL.Enabled {
  510. return fmt.Errorf("Cannot enable MySQL after launching the server, rehash aborted")
  511. } else if oldConfig.Server.MaxLineLen != config.Server.MaxLineLen {
  512. return fmt.Errorf("Cannot change max-line-len after launching the server, rehash aborted")
  513. }
  514. }
  515. server.logger.Info("server", "Using config file", server.configFilename)
  516. // first, reload config sections for functionality implemented in subpackages:
  517. wasLoggingRawIO := !initial && server.logger.IsLoggingRawIO()
  518. err = server.logger.ApplyConfig(config.Logging)
  519. if err != nil {
  520. return err
  521. }
  522. nowLoggingRawIO := server.logger.IsLoggingRawIO()
  523. // notify existing clients if raw i/o logging was enabled by a rehash
  524. sendRawOutputNotice := !wasLoggingRawIO && nowLoggingRawIO
  525. server.connectionLimiter.ApplyConfig(&config.Server.IPLimits)
  526. tlConf := &config.Server.TorListeners
  527. server.torLimiter.Configure(tlConf.MaxConnections, tlConf.ThrottleDuration, tlConf.MaxConnectionsPerDuration)
  528. // Translations
  529. server.logger.Debug("server", "Regenerating HELP indexes for new languages")
  530. server.helpIndexManager.GenerateIndices(config.languageManager)
  531. if initial {
  532. maxIPConc := int(config.Server.IPCheckScript.MaxConcurrency)
  533. if maxIPConc != 0 {
  534. server.semaphores.IPCheckScript = utils.NewSemaphore(maxIPConc)
  535. }
  536. maxAuthConc := int(config.Accounts.AuthScript.MaxConcurrency)
  537. if maxAuthConc != 0 {
  538. server.semaphores.AuthScript = utils.NewSemaphore(maxAuthConc)
  539. }
  540. if err := overrideServicePrefixes(config.Server.OverrideServicesHostname); err != nil {
  541. return err
  542. }
  543. }
  544. if oldConfig != nil {
  545. // if certain features were enabled by rehash, we need to load the corresponding data
  546. // from the store
  547. if !oldConfig.Accounts.NickReservation.Enabled {
  548. server.accounts.buildNickToAccountIndex(config)
  549. }
  550. if !oldConfig.Channels.Registration.Enabled {
  551. server.channels.loadRegisteredChannels(config)
  552. }
  553. // resize history buffers as needed
  554. if config.historyChangedFrom(oldConfig) {
  555. for _, channel := range server.channels.Channels() {
  556. channel.resizeHistory(config)
  557. }
  558. for _, client := range server.clients.AllClients() {
  559. client.resizeHistory(config)
  560. }
  561. }
  562. if oldConfig.Accounts.Registration.Throttling != config.Accounts.Registration.Throttling {
  563. server.accounts.resetRegisterThrottle(config)
  564. }
  565. }
  566. server.logger.Info("server", "Using datastore", config.Datastore.Path)
  567. if initial {
  568. if err := server.loadDatastore(config); err != nil {
  569. return err
  570. }
  571. } else {
  572. if config.Datastore.MySQL.Enabled && config.Datastore.MySQL != oldConfig.Datastore.MySQL {
  573. server.historyDB.SetConfig(config.Datastore.MySQL)
  574. }
  575. }
  576. // now that the datastore is initialized, we can load the cloak secret from it
  577. // XXX this modifies config after the initial load, which is naughty,
  578. // but there's no data race because we haven't done SetConfig yet
  579. config.Server.Cloaks.SetSecret(LoadCloakSecret(server.store))
  580. // activate the new config
  581. server.SetConfig(config)
  582. // load [dk]-lines, registered users and channels, etc.
  583. if initial {
  584. if err := server.loadFromDatastore(config); err != nil {
  585. return err
  586. }
  587. }
  588. // burst new and removed caps
  589. addedCaps, removedCaps := config.Diff(oldConfig)
  590. var capBurstSessions []*Session
  591. added := make(map[caps.Version][]string)
  592. var removed []string
  593. if !addedCaps.Empty() || !removedCaps.Empty() {
  594. capBurstSessions = server.clients.AllWithCapsNotify()
  595. added[caps.Cap301] = addedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  596. added[caps.Cap302] = addedCaps.Strings(caps.Cap302, config.Server.capValues, 0)
  597. // removed never has values, so we leave it as Cap301
  598. removed = removedCaps.Strings(caps.Cap301, config.Server.capValues, 0)
  599. }
  600. for _, sSession := range capBurstSessions {
  601. // DEL caps and then send NEW ones so that updated caps get removed/added correctly
  602. if !removedCaps.Empty() {
  603. for _, capStr := range removed {
  604. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "DEL", capStr)
  605. }
  606. }
  607. if !addedCaps.Empty() {
  608. for _, capStr := range added[sSession.capVersion] {
  609. sSession.Send(nil, server.name, "CAP", sSession.client.Nick(), "NEW", capStr)
  610. }
  611. }
  612. }
  613. server.setupPprofListener(config)
  614. // set RPL_ISUPPORT
  615. var newISupportReplies [][]string
  616. if oldConfig != nil {
  617. newISupportReplies = oldConfig.Server.isupport.GetDifference(&config.Server.isupport)
  618. }
  619. if len(config.Server.ProxyAllowedFrom) != 0 {
  620. server.logger.Info("server", "Proxied IPs will be accepted from", strings.Join(config.Server.ProxyAllowedFrom, ", "))
  621. }
  622. // we are now open for business
  623. err = server.setupListeners(config)
  624. // send other config warnings
  625. if config.Accounts.RequireSasl.Enabled && config.Accounts.Registration.Enabled {
  626. server.logger.Warning("server", "Warning: although require-sasl is enabled, users can still register accounts. If your server is not intended to be public, you must set accounts.registration.enabled to false.")
  627. }
  628. if !initial {
  629. // push new info to all of our clients
  630. for _, sClient := range server.clients.AllClients() {
  631. for _, tokenline := range newISupportReplies {
  632. sClient.Send(nil, server.name, RPL_ISUPPORT, append([]string{sClient.nick}, tokenline...)...)
  633. }
  634. if sendRawOutputNotice {
  635. sClient.Notice(sClient.t("This server is in debug mode and is logging all user I/O. If you do not wish for everything you send to be readable by the server owner(s), please disconnect."))
  636. }
  637. }
  638. }
  639. return err
  640. }
  641. func (server *Server) setupPprofListener(config *Config) {
  642. pprofListener := ""
  643. if config.Debug.PprofListener != nil {
  644. pprofListener = *config.Debug.PprofListener
  645. }
  646. if server.pprofServer != nil {
  647. if pprofListener == "" || (pprofListener != server.pprofServer.Addr) {
  648. server.logger.Info("server", "Stopping pprof listener", server.pprofServer.Addr)
  649. server.pprofServer.Close()
  650. server.pprofServer = nil
  651. }
  652. }
  653. if pprofListener != "" && server.pprofServer == nil {
  654. ps := http.Server{
  655. Addr: pprofListener,
  656. }
  657. go func() {
  658. if err := ps.ListenAndServe(); err != nil {
  659. server.logger.Error("server", "pprof listener failed", err.Error())
  660. }
  661. }()
  662. server.pprofServer = &ps
  663. server.logger.Info("server", "Started pprof listener", server.pprofServer.Addr)
  664. }
  665. }
  666. func (server *Server) loadDatastore(config *Config) error {
  667. // open the datastore and load server state for which it (rather than config)
  668. // is the source of truth
  669. _, err := os.Stat(config.Datastore.Path)
  670. if os.IsNotExist(err) {
  671. server.logger.Warning("server", "database does not exist, creating it", config.Datastore.Path)
  672. err = initializeDB(config.Datastore.Path)
  673. if err != nil {
  674. return err
  675. }
  676. }
  677. db, err := OpenDatabase(config)
  678. if err == nil {
  679. server.store = db
  680. return nil
  681. } else {
  682. return fmt.Errorf("Failed to open datastore: %s", err.Error())
  683. }
  684. }
  685. func (server *Server) loadFromDatastore(config *Config) (err error) {
  686. // load *lines (from the datastores)
  687. server.logger.Debug("server", "Loading D/Klines")
  688. server.loadDLines()
  689. server.loadKLines()
  690. server.channelRegistry.Initialize(server)
  691. server.channels.Initialize(server)
  692. server.accounts.Initialize(server)
  693. if config.Datastore.MySQL.Enabled {
  694. server.historyDB.Initialize(server.logger, config.Datastore.MySQL)
  695. err = server.historyDB.Open()
  696. if err != nil {
  697. server.logger.Error("internal", "could not connect to mysql", err.Error())
  698. return err
  699. }
  700. }
  701. return nil
  702. }
  703. func (server *Server) setupListeners(config *Config) (err error) {
  704. logListener := func(addr string, config utils.ListenerConfig) {
  705. server.logger.Info("listeners",
  706. fmt.Sprintf("now listening on %s, tls=%t, proxy=%t, tor=%t, websocket=%t.", addr, (config.TLSConfig != nil), config.RequireProxy, config.Tor, config.WebSocket),
  707. )
  708. }
  709. // update or destroy all existing listeners
  710. for addr := range server.listeners {
  711. currentListener := server.listeners[addr]
  712. newConfig, stillConfigured := config.Server.trueListeners[addr]
  713. if stillConfigured {
  714. if reloadErr := currentListener.Reload(newConfig); reloadErr == nil {
  715. logListener(addr, newConfig)
  716. } else {
  717. // stop the listener; we will attempt to replace it below
  718. currentListener.Stop()
  719. delete(server.listeners, addr)
  720. }
  721. } else {
  722. currentListener.Stop()
  723. delete(server.listeners, addr)
  724. server.logger.Info("listeners", fmt.Sprintf("stopped listening on %s.", addr))
  725. }
  726. }
  727. publicPlaintextListener := ""
  728. // create new listeners that were not previously configured,
  729. // or that couldn't be reloaded above:
  730. for newAddr, newConfig := range config.Server.trueListeners {
  731. if strings.HasPrefix(newAddr, ":") && !newConfig.Tor && !newConfig.STSOnly && newConfig.TLSConfig == nil {
  732. publicPlaintextListener = newAddr
  733. }
  734. _, exists := server.listeners[newAddr]
  735. if !exists {
  736. // make a new listener
  737. newListener, newErr := NewListener(server, newAddr, newConfig, config.Server.UnixBindMode)
  738. if newErr == nil {
  739. server.listeners[newAddr] = newListener
  740. logListener(newAddr, newConfig)
  741. } else {
  742. server.logger.Error("server", "couldn't listen on", newAddr, newErr.Error())
  743. err = newErr
  744. }
  745. }
  746. }
  747. if publicPlaintextListener != "" {
  748. server.logger.Warning("listeners", fmt.Sprintf("Warning: your server is configured with public plaintext listener %s. Consider disabling it for improved security and privacy.", publicPlaintextListener))
  749. }
  750. return
  751. }
  752. // Gets the abstract sequence from which we're going to query history;
  753. // we may already know the channel we're querying, or we may have
  754. // to look it up via a string query. This function is responsible for
  755. // privilege checking.
  756. // XXX: call this with providedChannel==nil and query=="" to get a sequence
  757. // suitable for ListCorrespondents (i.e., this function is still used to
  758. // decide whether the ringbuf or mysql is authoritative about the client's
  759. // message history).
  760. func (server *Server) GetHistorySequence(providedChannel *Channel, client *Client, query string) (channel *Channel, sequence history.Sequence, err error) {
  761. config := server.Config()
  762. // 4 cases: {persistent, ephemeral} x {normal, conversation}
  763. // with ephemeral history, target is implicit in the choice of `hist`,
  764. // and correspondent is "" if we're retrieving a channel or *, and the correspondent's name
  765. // if we're retrieving a DM conversation ("query buffer"). with persistent history,
  766. // target is always nonempty, and correspondent is either empty or nonempty as before.
  767. var status HistoryStatus
  768. var target, correspondent string
  769. var hist *history.Buffer
  770. restriction := HistoryCutoffNone
  771. channel = providedChannel
  772. if channel == nil {
  773. if strings.HasPrefix(query, "#") {
  774. channel = server.channels.Get(query)
  775. if channel == nil {
  776. return
  777. }
  778. }
  779. }
  780. var joinTimeCutoff time.Time
  781. if channel != nil {
  782. if present, cutoff := channel.joinTimeCutoff(client); present {
  783. joinTimeCutoff = cutoff
  784. } else {
  785. err = errInsufficientPrivs
  786. return
  787. }
  788. status, target, restriction = channel.historyStatus(config)
  789. switch status {
  790. case HistoryEphemeral:
  791. hist = &channel.history
  792. case HistoryPersistent:
  793. // already set `target`
  794. default:
  795. return
  796. }
  797. } else {
  798. status, target = client.historyStatus(config)
  799. if query != "" {
  800. correspondent, err = CasefoldName(query)
  801. if err != nil {
  802. return
  803. }
  804. }
  805. switch status {
  806. case HistoryEphemeral:
  807. hist = &client.history
  808. case HistoryPersistent:
  809. // already set `target`, and `correspondent` if necessary
  810. default:
  811. return
  812. }
  813. }
  814. var cutoff time.Time
  815. if config.History.Restrictions.ExpireTime != 0 {
  816. cutoff = time.Now().UTC().Add(-time.Duration(config.History.Restrictions.ExpireTime))
  817. }
  818. // #836: registration date cutoff is always enforced for DMs
  819. // either way, take the later of the two cutoffs
  820. if restriction == HistoryCutoffRegistrationTime || channel == nil {
  821. regCutoff := client.historyCutoff()
  822. if regCutoff.After(cutoff) {
  823. cutoff = regCutoff
  824. }
  825. } else if restriction == HistoryCutoffJoinTime {
  826. if joinTimeCutoff.After(cutoff) {
  827. cutoff = joinTimeCutoff
  828. }
  829. }
  830. // #836 again: grace period is never applied to DMs
  831. if !cutoff.IsZero() && channel != nil && restriction != HistoryCutoffJoinTime {
  832. cutoff = cutoff.Add(-time.Duration(config.History.Restrictions.GracePeriod))
  833. }
  834. if hist != nil {
  835. sequence = hist.MakeSequence(correspondent, cutoff)
  836. } else if target != "" {
  837. sequence = server.historyDB.MakeSequence(target, correspondent, cutoff)
  838. }
  839. return
  840. }
  841. func (server *Server) ForgetHistory(accountName string) {
  842. // sanity check
  843. if accountName == "*" {
  844. return
  845. }
  846. config := server.Config()
  847. if !config.History.Enabled {
  848. return
  849. }
  850. if cfAccount, err := CasefoldName(accountName); err == nil {
  851. server.historyDB.Forget(cfAccount)
  852. }
  853. persistent := config.History.Persistent
  854. if persistent.Enabled && persistent.UnregisteredChannels && persistent.RegisteredChannels == PersistentMandatory && persistent.DirectMessages == PersistentMandatory {
  855. return
  856. }
  857. predicate := func(item *history.Item) bool { return item.AccountName == accountName }
  858. for _, channel := range server.channels.Channels() {
  859. channel.history.Delete(predicate)
  860. }
  861. for _, client := range server.clients.AllClients() {
  862. client.history.Delete(predicate)
  863. }
  864. }
  865. // deletes a message. target is a hint about what buffer it's in (not required for
  866. // persistent history, where all the msgids are indexed together). if accountName
  867. // is anything other than "*", it must match the recorded AccountName of the message
  868. func (server *Server) DeleteMessage(target, msgid, accountName string) (err error) {
  869. config := server.Config()
  870. var hist *history.Buffer
  871. if target != "" {
  872. if target[0] == '#' {
  873. channel := server.channels.Get(target)
  874. if channel != nil {
  875. if status, _, _ := channel.historyStatus(config); status == HistoryEphemeral {
  876. hist = &channel.history
  877. }
  878. }
  879. } else {
  880. client := server.clients.Get(target)
  881. if client != nil {
  882. if status, _ := client.historyStatus(config); status == HistoryEphemeral {
  883. hist = &client.history
  884. }
  885. }
  886. }
  887. }
  888. if hist == nil {
  889. err = server.historyDB.DeleteMsgid(msgid, accountName)
  890. } else {
  891. count := hist.Delete(func(item *history.Item) bool {
  892. return item.Message.Msgid == msgid && (accountName == "*" || item.AccountName == accountName)
  893. })
  894. if count == 0 {
  895. err = errNoop
  896. }
  897. }
  898. return
  899. }
  900. func (server *Server) UnfoldName(cfname string) (name string) {
  901. if strings.HasPrefix(cfname, "#") {
  902. return server.channels.UnfoldName(cfname)
  903. }
  904. return server.clients.UnfoldNick(cfname)
  905. }
  906. // elistMatcher takes and matches ELIST conditions
  907. type elistMatcher struct {
  908. MinClientsActive bool
  909. MinClients int
  910. MaxClientsActive bool
  911. MaxClients int
  912. }
  913. // Matches checks whether the given channel matches our matches.
  914. func (matcher *elistMatcher) Matches(channel *Channel) bool {
  915. if matcher.MinClientsActive {
  916. if len(channel.Members()) < matcher.MinClients {
  917. return false
  918. }
  919. }
  920. if matcher.MaxClientsActive {
  921. if len(channel.Members()) < len(channel.members) {
  922. return false
  923. }
  924. }
  925. return true
  926. }
  927. var (
  928. infoString1 = []string{
  929. " ___ _ __ __ _ ___ ",
  930. " / _ \\ '__/ _` |/ _ \\ ",
  931. " | __/ | | (_| | (_) |",
  932. ` \___|_| \__, |\___/ `,
  933. " __/ | ",
  934. " |___/ ",
  935. "",
  936. " https://ergo.chat/",
  937. "https://github.com/ergochat/ergo ",
  938. }
  939. infoString2 = strings.Split(` Daniel Oakley, DanielOaks, <daniel@danieloaks.net>
  940. Shivaram Lingamneni, slingamn, <slingamn@cs.stanford.edu>
  941. `, "\n")
  942. infoString3 = strings.Split(` Jeremy Latt, jlatt
  943. Edmund Huber, edmund-huber
  944. `, "\n")
  945. )