USERHOST, VERSION, ADMIN, INFO, TIME, KILL and WALLOPS on both the HTTP API and the IRC listener, and user mode +w. Model: opus-5-5
This commit is contained in:
+119
-6
@@ -22,6 +22,7 @@ const (
|
||||
maxLineLen = 512
|
||||
readTimeout = 5 * time.Minute
|
||||
writeTimeout = 30 * time.Second
|
||||
killWriteWindow = 2 * time.Second
|
||||
dnsTimeout = 3 * time.Second
|
||||
pollInterval = 100 * time.Millisecond
|
||||
pingInterval = 90 * time.Second
|
||||
@@ -46,6 +47,12 @@ type Conn struct {
|
||||
serverSfx string
|
||||
commands map[string]cmdHandler
|
||||
|
||||
// writeMu serializes writes to conn. A connection is
|
||||
// written to by its own read loop, by its relay
|
||||
// goroutine, and — when an operator KILLs it — by
|
||||
// another client's goroutine.
|
||||
writeMu sync.Mutex
|
||||
|
||||
mu sync.Mutex
|
||||
nick string
|
||||
username string
|
||||
@@ -62,6 +69,7 @@ type Conn struct {
|
||||
|
||||
lastQueueID int64
|
||||
closed bool
|
||||
killed bool
|
||||
}
|
||||
|
||||
func newConn(
|
||||
@@ -97,6 +105,57 @@ func newConn(
|
||||
return conn
|
||||
}
|
||||
|
||||
// Disconnect ends the connection for an operator KILL from
|
||||
// either transport: the victim is sent KILL and ERROR, then
|
||||
// its socket is closed, which ends serve() and with it the
|
||||
// relay goroutine. It is called from the killer's goroutine
|
||||
// and does not wait for the writes, so a victim that has
|
||||
// stopped reading cannot stall the killer.
|
||||
func (c *Conn) Disconnect(reason string) {
|
||||
c.mu.Lock()
|
||||
|
||||
if c.closed {
|
||||
c.mu.Unlock()
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
c.closed = true
|
||||
c.killed = true
|
||||
nick := c.nick
|
||||
host := c.hostname
|
||||
c.mu.Unlock()
|
||||
|
||||
if nick == "" {
|
||||
nick = "*"
|
||||
}
|
||||
|
||||
go func() {
|
||||
c.notifyKilledAndClose(nick, host, reason)
|
||||
}()
|
||||
}
|
||||
|
||||
// notifyKilledAndClose sends a killed victim the KILL and
|
||||
// ERROR lines, each bounded by killWriteWindow, and then
|
||||
// closes its socket.
|
||||
func (c *Conn) notifyKilledAndClose(
|
||||
nick, host, reason string,
|
||||
) {
|
||||
defer c.conn.Close() //nolint:errcheck
|
||||
|
||||
c.sendWithin(
|
||||
killWriteWindow,
|
||||
FormatMessage(
|
||||
c.serverSfx, irc.CmdKill, nick, reason,
|
||||
),
|
||||
)
|
||||
c.sendWithin(
|
||||
killWriteWindow,
|
||||
"ERROR :Closing Link: "+host+
|
||||
" ("+reason+")",
|
||||
)
|
||||
}
|
||||
|
||||
// buildCommandMap returns a map from IRC command strings
|
||||
// to handler functions.
|
||||
func (c *Conn) buildCommandMap() map[string]cmdHandler {
|
||||
@@ -129,7 +188,13 @@ func (c *Conn) buildCommandMap() map[string]cmdHandler {
|
||||
"CAP": func(_ context.Context, msg *Message) {
|
||||
c.handleCAP(msg)
|
||||
},
|
||||
"USERHOST": c.handleUserhost,
|
||||
"USERHOST": c.handleUserhost,
|
||||
irc.CmdVersion: func(context.Context, *Message) { c.handleVersion() },
|
||||
irc.CmdAdmin: func(context.Context, *Message) { c.handleAdmin() },
|
||||
irc.CmdInfo: func(context.Context, *Message) { c.handleInfo() },
|
||||
irc.CmdTime: func(context.Context, *Message) { c.handleTime() },
|
||||
irc.CmdKill: c.handleKillCmd,
|
||||
irc.CmdWallops: c.handleWallopsCmd,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -180,7 +245,7 @@ func (c *Conn) serve(ctx context.Context) {
|
||||
|
||||
c.handleMessage(ctx, msg)
|
||||
|
||||
if c.closed {
|
||||
if c.isClosed() {
|
||||
return
|
||||
}
|
||||
}
|
||||
@@ -189,24 +254,65 @@ func (c *Conn) serve(ctx context.Context) {
|
||||
func (c *Conn) cleanup(ctx context.Context) {
|
||||
c.mu.Lock()
|
||||
wasRegistered := c.registered
|
||||
wasKilled := c.killed
|
||||
sessID := c.sessionID
|
||||
nick := c.nick
|
||||
c.closed = true
|
||||
c.mu.Unlock()
|
||||
|
||||
if wasRegistered && sessID > 0 {
|
||||
c.svc.BroadcastQuit(
|
||||
ctx, sessID, nick, "Connection closed",
|
||||
)
|
||||
c.svc.UnregisterWireConn(sessID, c)
|
||||
|
||||
// A KILLed session has already been broadcast and
|
||||
// deleted by the killer; broadcasting again would
|
||||
// fan out a QUIT for a session row that is gone.
|
||||
if !wasKilled {
|
||||
c.svc.BroadcastQuit(
|
||||
ctx, sessID, nick, "Connection closed",
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
c.conn.Close() //nolint:errcheck,gosec
|
||||
}
|
||||
|
||||
// isClosed reports whether the connection has been marked
|
||||
// for teardown, either by QUIT or by an operator KILL.
|
||||
func (c *Conn) isClosed() bool {
|
||||
c.mu.Lock()
|
||||
defer c.mu.Unlock()
|
||||
|
||||
return c.closed
|
||||
}
|
||||
|
||||
// currentNick returns the connection's registered nick.
|
||||
// c.nick is written under c.mu during registration and
|
||||
// NICK changes, so every read must take the mutex.
|
||||
func (c *Conn) currentNick() string {
|
||||
c.mu.Lock()
|
||||
defer c.mu.Unlock()
|
||||
|
||||
return c.nick
|
||||
}
|
||||
|
||||
// send writes a formatted IRC line to the connection.
|
||||
func (c *Conn) send(line string) {
|
||||
c.sendWithin(writeTimeout, line)
|
||||
}
|
||||
|
||||
// sendWithin writes a formatted IRC line to the connection
|
||||
// under the given write deadline. Callers that must not be
|
||||
// held hostage by an unresponsive peer pass a shorter window
|
||||
// than writeTimeout.
|
||||
func (c *Conn) sendWithin(
|
||||
timeout time.Duration,
|
||||
line string,
|
||||
) {
|
||||
c.writeMu.Lock()
|
||||
defer c.writeMu.Unlock()
|
||||
|
||||
_ = c.conn.SetWriteDeadline(
|
||||
time.Now().Add(writeTimeout),
|
||||
time.Now().Add(timeout),
|
||||
)
|
||||
|
||||
_, _ = fmt.Fprintf(c.conn, "%s\r\n", line)
|
||||
@@ -387,7 +493,10 @@ func (c *Conn) completeRegistration(ctx context.Context) {
|
||||
"failed to create session", "error", err,
|
||||
)
|
||||
c.send("ERROR :Internal server error")
|
||||
|
||||
c.mu.Lock()
|
||||
c.closed = true
|
||||
c.mu.Unlock()
|
||||
|
||||
return
|
||||
}
|
||||
@@ -398,6 +507,10 @@ func (c *Conn) completeRegistration(ctx context.Context) {
|
||||
c.registered = true
|
||||
c.mu.Unlock()
|
||||
|
||||
// Make this connection reachable by session ID so that
|
||||
// KILL from either transport can disconnect it.
|
||||
c.svc.RegisterWireConn(sessionID, c)
|
||||
|
||||
// If PASS was provided before registration, set the
|
||||
// session password.
|
||||
if c.passWord != "" && len(c.passWord) >= minPasswordLen {
|
||||
|
||||
Reference in New Issue
Block a user