5 FUTURE: natural (sort of) language parsing
8 PPA: if multiple users match the same user@host or *@host it'll send multiple glines?!
11 #include "regexgline.h"
12 #include "../lib/version.h"
13 #include "../dbapi/dbapi.h"
14 #include "../lib/stringbuf.h"
15 #include "../core/hooks.h"
16 #include "../server/server.h"
17 #include "../lib/strlfunc.h"
20 #define INSTANT_IDENT_GLINE 1
21 #define INSTANT_HOST_GLINE 2
22 #define INSTANT_KILL 3
23 #define DELAYED_IDENT_GLINE 4
24 #define DELAYED_HOST_GLINE 5
25 #define DELAYED_KILL 6
27 MODULE_VERSION("1.43");
29 typedef struct rg_glinenode
{
31 struct rg_struct
*reason
;
33 struct rg_glinenode
*next
;
36 typedef struct rg_glinelist
{
37 struct rg_glinenode
*start
;
38 struct rg_glinenode
*end
;
41 typedef struct rg_delay
{
44 struct rg_struct
*reason
;
46 struct rg_delay
*next
;
49 #define GLINE_HEADER " ID Expires Set by Class Type Last seen (ago) Hits(p) Hits Reason"
53 void rg_setdelay(nick
*np
, struct rg_struct
*reason
, short punish
);
54 void rg_deletedelay(rg_delay
*delay
);
55 void rg_dodelay(void *arg
);
57 void rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
);
58 void rg_flush_schedule(void *arg
);
60 static DBModuleIdentifier dbid
;
61 static unsigned long highestid
= 0;
62 static int attached
= 0, started
= 0;
64 static unsigned int getrgmarker(void);
66 /* shadowserver only reports classes[0] */
67 static const char *classes
[] = { "drone", "proxy", "spam", "fakeauth", "other", (char *)0 };
70 sstring
*max_casualties
, *max_spew
, *expiry_time
, *max_per_gline
;
72 max_casualties
= getcopyconfigitem("regexgline", "maxcasualties", RGStringise(RG_MAX_CASUALTIES_DEFAULT
), 8);
73 if(!protectedatoi(max_casualties
->content
, &rg_max_casualties
))
74 rg_max_casualties
= RG_MAX_CASUALTIES_DEFAULT
;
76 freesstring(max_casualties
);
78 max_spew
= getcopyconfigitem("regexgline", "maxspew", RGStringise(RG_MAX_SPEW_DEFAULT
), 8);
79 if(!protectedatoi(max_spew
->content
, &rg_max_spew
))
80 rg_max_spew
= RG_MAX_SPEW_DEFAULT
;
82 freesstring(max_spew
);
84 expiry_time
= getcopyconfigitem("regexgline", "expirytime", RGStringise(RG_EXPIRY_TIME_DEFAULT
), 8);
85 if(!protectedatoi(expiry_time
->content
, &rg_expiry_time
))
86 rg_expiry_time
= RG_EXPIRY_TIME_DEFAULT
;
88 freesstring(expiry_time
);
90 max_per_gline
= getcopyconfigitem("regexgline", "maxpergline", RGStringise(RG_MAX_PER_GLINE_DEFAULT
), 8);
91 if(!protectedatoi(max_per_gline
->content
, &rg_max_per_gline
))
92 rg_max_per_gline
= RG_MAX_PER_GLINE_DEFAULT
;
94 freesstring(max_per_gline
);
103 Error("regexgline", ERR_STOP
, "Could not connect to database.");
108 struct rg_struct
*gp
= rg_list
, *oldgp
;
109 rg_delay
*delay
, *delaynext
;
112 deregisterhook(HOOK_NICK_NEWNICK
, &rg_nick
);
113 deregisterhook(HOOK_NICK_RENAME
, &rg_nick
);
114 deregisterhook(HOOK_NICK_LOSTNICK
, &rg_lostnick
);
115 deregistercontrolcmd("regexspew", rg_spew
);
116 deregistercontrolcmd("regexglist", rg_glist
);
117 deregistercontrolcmd("regexdelgline", rg_delgline
);
118 deregistercontrolcmd("regexgline", rg_gline
);
119 deregistercontrolcmd("regexidlookup", rg_idlist
);
123 for(delay
=rg_delays
;delay
;delay
=delaynext
) {
124 delaynext
=delay
->next
;
125 deleteschedule(delay
->sch
, rg_dodelay
, delay
);
131 deleteschedule(rg_schedule
, &rg_checkexpiry
, NULL
);
135 deleteallschedules(rg_flush_schedule
);
136 rg_flush_schedule(NULL
);
138 for(gp
=rg_list
;gp
;) {
141 rg_freestruct(oldgp
);
145 dbdetach("regexgline");
150 void rg_checkexpiry(void *arg
) {
151 struct rg_struct
*rp
= rg_list
, *lp
= NULL
;
152 time_t current
= time(NULL
);
155 if (current
>= rp
->expires
) {
156 dbquery("DELETE FROM regexglines WHERE id = %d", rp
->id
);
173 void rg_setdelay(nick
*np
, rg_struct
*reason
, short punish
) {
175 delay
= (rg_delay
*)malloc(sizeof(rg_delay
));
179 killuser(NULL
, np
, "%s (ID: %08lx)", reason
->reason
->content
, reason
->glineid
);
184 delay
->reason
= reason
;
185 delay
->punish
= punish
;
186 delay
->next
= rg_delays
;
189 delay
->sch
= scheduleoneshot(time(NULL
) + (RG_MINIMUM_DELAY_TIME
+ (rand() % RG_MAXIMUM_RAND_TIME
)), rg_dodelay
, delay
);
192 static void rg_shadowserver(nick
*np
, struct rg_struct
*reason
, int type
) {
195 if(reason
->class != classes
[0]) /* drone */
198 snprintf(buf
, sizeof(buf
), "regex-ban %lu %s!%s@%s %s %s", time(NULL
), np
->nick
, np
->ident
, np
->host
->name
->content
, reason
->mask
->content
, serverlist
[homeserver(np
->numeric
)].name
->content
);
200 triggerhook(HOOK_SHADOW_SERVER
, (void *)buf
);
203 void rg_deletedelay(rg_delay
*delay
) {
204 rg_delay
*temp
, *prev
;
206 for (temp
=rg_delays
;temp
;temp
=temp
->next
) {
209 rg_delays
= temp
->next
;
211 prev
->next
= temp
->next
;
221 void rg_dodelay(void *arg
) {
222 rg_delay
*delay
= (rg_delay
*)arg
;
223 char hostname
[RG_MASKLEN
];
224 int hostlen
, usercount
= 0;
226 /* User or regex gline no longer exists */
227 if((!delay
->np
) || (!delay
->reason
)) {
228 rg_deletedelay(delay
);
232 hostlen
= RGBuildHostname(hostname
, delay
->np
);
234 /* User has wisely changed nicknames */
235 if(pcre_exec(delay
->reason
->regex
, delay
->reason
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) < 0) {
236 rg_deletedelay(delay
);
240 if (delay
->reason
->type
== DELAYED_HOST_GLINE
) {
241 usercount
= delay
->np
->host
->clonecount
;
242 snprintf(hostname
, sizeof(hostname
), "*@%s", IPtostr(delay
->np
->p_ipaddr
));
245 if((delay
->reason
->type
== DELAYED_IDENT_GLINE
) || (usercount
> rg_max_per_gline
)) {
248 for(usercount
=0,tnp
=delay
->np
->host
->nicks
;tnp
;tnp
=tnp
->nextbyhost
)
249 if(!ircd_strcmp(delay
->np
->ident
, tnp
->ident
))
252 snprintf(hostname
, sizeof(hostname
), "%s@%s", delay
->np
->ident
, IPtostr(delay
->np
->p_ipaddr
));
255 if ((delay
->reason
->type
== DELAYED_KILL
) || (usercount
> rg_max_per_gline
)) {
256 if (IsAccount(delay
->np
)) {
257 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched delayed kill regex %08lx (class: %s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->np
->authname
, delay
->reason
->glineid
, delay
->reason
->class);
259 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched delayed kill regex %08lx (class: %s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->reason
->glineid
, delay
->reason
->class);
262 rg_shadowserver(delay
->np
, delay
->reason
, DELAYED_KILL
);
263 killuser(NULL
, delay
->np
, "%s (ID: %08lx)", delay
->reason
->reason
->content
, delay
->reason
->glineid
);
267 if (delay
->reason
->type
== DELAYED_IDENT_GLINE
) {
268 if (IsAccount(delay
->np
)) {
269 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched delayed user@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->np
->authname
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
271 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched delayed user@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
273 } else if (delay
->reason
->type
== DELAYED_HOST_GLINE
) {
274 if (IsAccount(delay
->np
)) {
275 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched delayed *@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->np
->authname
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
277 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched delayed *@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
283 rg_shadowserver(delay
->np
, delay
->reason
, delay
->reason
->type
);
284 irc_send("%s GL * +%s %d %jd :AUTO: %s (ID: %08lx)\r\n", mynumeric
->content
, hostname
, rg_expiry_time
, (intmax_t)time(NULL
), delay
->reason
->reason
->content
, delay
->reason
->glineid
);
285 rg_deletedelay(delay
);
288 void rg_initglinelist(struct rg_glinelist
*gll
) {
293 void rg_flushglines(struct rg_glinelist
*gll
) {
294 struct rg_glinenode
*nn
, *pn
;
295 for(nn
=gll
->start
;nn
;nn
=pn
) {
297 if(nn
->punish
== INSTANT_KILL
) {
298 if ( IsAccount(nn
->np
) ) {
299 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched kill regex %08lx (class: %s)", nn
->np
->nick
, nn
->np
->ident
, nn
->np
->host
->name
->content
, nn
->np
->authname
, nn
->reason
->glineid
, nn
->reason
->class);
301 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched kill regex %08lx (class: %s)", nn
->np
->nick
, nn
->np
->ident
, nn
->np
->host
->name
->content
, nn
->reason
->glineid
, nn
->reason
->class);
304 rg_shadowserver(nn
->np
, nn
->reason
, nn
->punish
);
305 killuser(NULL
, nn
->np
, "%s (ID: %08lx)", nn
->reason
->reason
->content
, nn
->reason
->glineid
);
306 } else if ((nn
->punish
== DELAYED_IDENT_GLINE
) || (nn
->punish
== DELAYED_HOST_GLINE
) || (nn
->punish
== DELAYED_KILL
)) {
307 rg_setdelay(nn
->np
, nn
->reason
, nn
->punish
);
312 rg_initglinelist(gll
);
315 static void dbloaddata(DBConn
*dbconn
, void *arg
) {
316 DBResult
*dbres
= dbgetresult(dbconn
);
318 if(!dbquerysuccessful(dbres
)) {
319 Error("chanserv", ERR_ERROR
, "Error loading DB");
323 if (dbnumfields(dbres
) != 9) {
324 Error("regexgline", ERR_ERROR
, "DB format error");
328 while(dbfetchrow(dbres
)) {
329 unsigned long id
, hitssaved
;
331 char *gline
, *setby
, *reason
, *expires
, *type
, *class;
333 id
= strtoul(dbgetvalue(dbres
, 0), NULL
, 10);
337 gline
= dbgetvalue(dbres
, 1);
338 setby
= dbgetvalue(dbres
, 2);
339 reason
= dbgetvalue(dbres
, 3);
340 expires
= dbgetvalue(dbres
, 4);
341 type
= dbgetvalue(dbres
, 5);
342 class = dbgetvalue(dbres
, 6);
344 lastseen
= strtoul(dbgetvalue(dbres
, 7), NULL
, 10);
345 hitssaved
= strtoul(dbgetvalue(dbres
, 8), NULL
, 10);
347 if (!rg_newsstruct(id
, gline
, setby
, reason
, expires
, type
, 0, class, lastseen
, hitssaved
))
348 dbquery("DELETE FROM regexgline.glines WHERE id = %lu", id
);
354 static void dbloadfini(DBConn
*dbconn
, void *arg
) {
358 char helpbuf
[8192 * 2], allclasses
[8192];
360 sbinit(&b
, (char *)allclasses
, sizeof(allclasses
));
361 for(p
=classes
;*p
;p
++) {
362 sbaddstr(&b
, (char *)*p
);
367 snprintf(helpbuf
, sizeof(helpbuf
),
368 "Usage: regexgline <regex> <duration> <type> <class> <reason>\n"
369 "Adds a new regular expression pattern.\n"
370 "Duration is represented as 3d, 3M etc.\n"
371 "Class is one of the following: %s\n"
372 "Type is an integer which represents the following:\n"
373 "1 - Instant USER@IP GLINE (igu)\n"
374 "2 - Instant *@IP GLINE (igh)\n"
375 "3 - Instant KILL (ik)\n"
376 "4 - Delayed USER@IP GLINE (dgu)\n"
377 "5 - Delayed *@IP GLINE (dgh)\n"
378 "6 - Delayed KILL (dk)",
381 registercontrolhelpcmd("regexgline", NO_OPER
, 5, &rg_gline
, helpbuf
);
382 registercontrolhelpcmd("regexdelgline", NO_OPER
, 1, &rg_delgline
, "Usage: regexdelgline <pattern>\nDeletes a regular expression pattern.");
383 registercontrolhelpcmd("regexglist", NO_OPER
, 1, &rg_glist
, "Usage: regexglist <pattern>\nLists regular expression patterns.");
384 registercontrolhelpcmd("regexspew", NO_OPER
, 1, &rg_spew
, "Usage: regexspew <pattern>\nLists users currently on the network which match the given pattern.");
385 registercontrolhelpcmd("regexidlookup", NO_OPER
, 1, &rg_idlist
, "Usage: regexidlookup <id>\nFinds a regular expression pattern by it's ID number.");
387 registerhook(HOOK_NICK_NEWNICK
, &rg_nick
);
388 registerhook(HOOK_NICK_RENAME
, &rg_nick
);
389 registerhook(HOOK_NICK_LOSTNICK
, &rg_lostnick
);
392 rg_schedule
= schedulerecurring(time(NULL
) + 1, 0, 1, rg_checkexpiry
, NULL
);
393 schedulerecurring(time(NULL
) + 60, 0, 60, rg_flush_schedule
, NULL
);
396 void rg_dbload(void) {
397 dbattach("regexgline");
398 dbcreatequery("CREATE TABLE regexgline.glines (id INT NOT NULL PRIMARY KEY, gline TEXT NOT NULL, setby VARCHAR(%d) NOT NULL, reason VARCHAR(%d) NOT NULL, expires INT NOT NULL, type INT NOT NULL DEFAULT 1, class TEXT NOT NULL, lastseen INT DEFAULT 0, hits INT DEFAULT 0)", ACCOUNTLEN
, RG_REASON_MAX
);
399 dbcreatequery("CREATE TABLE regexgline.clog (host VARCHAR(%d) NOT NULL, account VARCHAR(%d) NOT NULL, event TEXT NOT NULL, arg TEXT NOT NULL, ts TIMESTAMP)", RG_MASKLEN
- 1, ACCOUNTLEN
);
400 dbcreatequery("CREATE TABLE regexgline.glog (glineid INT NOT NULL, ts TIMESTAMP, nickname VARCHAR(%d) NOT NULL, username VARCHAR(%d) NOT NULL, hostname VARCHAR(%d) NOT NULL, realname VARCHAR(%d))", NICKLEN
, USERLEN
, HOSTLEN
, REALLEN
);
402 dbloadtable("regexgline.glines", NULL
, dbloaddata
, dbloadfini
);
405 void rg_nick(int hooknum
, void *arg
) {
406 nick
*np
= (nick
*)arg
;
407 struct rg_struct
*rp
;
408 char hostname
[RG_MASKLEN
];
410 struct rg_glinelist gll
;
412 rg_initglinelist(&gll
);
414 hostlen
= RGBuildHostname(hostname
, np
);
416 if(IsOper(np
) || IsService(np
) || IsXOper(np
))
419 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
420 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
421 rg_dogline(&gll
, np
, rp
, hostname
);
426 rg_flushglines(&gll
);
429 void rg_lostnick(int hooknum
, void *arg
) {
430 nick
*np
= (nick
*)arg
;
433 /* Cleanup the delays */
434 for(delay
=rg_delays
;delay
;delay
=delay
->next
)
439 int rg_gline(void *source
, int cargc
, char **cargv
) {
440 nick
*np
= (nick
*)source
, *tnp
;
442 const char *expirybuf
;
443 int expiry
, count
, j
, hostlen
;
444 struct rg_struct
*rp
;
445 struct rg_glinelist gll
;
448 char eemask
[RG_QUERY_BUF_SIZE
], eesetby
[RG_QUERY_BUF_SIZE
], eereason
[RG_QUERY_BUF_SIZE
], eeclass
[RG_QUERY_BUF_SIZE
];
449 char hostname
[RG_MASKLEN
], *class, *reason
, *regex
, type
;
455 if ((strlen(cargv
[2]) != 1) || ((type
!= '1') && (type
!= '2') && (type
!= '3') && (type
!= '4') && (type
!= '5') && (type
!= '6'))) {
456 controlreply(np
, "Invalid type specified!");
464 for(p
=classes
;*p
;p
++)
465 if(!strcasecmp(class, *p
))
469 controlreply(np
, "Bad class supplied.");
473 if (!(expiry
= durationtolong(cargv
[1]))) {
474 controlreply(np
, "Invalid duration specified!");
478 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
479 if (RGMasksEqual(rp
->mask
->content
, regex
)) {
480 controlreply(np
, "That regexgline already exists!");
485 if (rg_sanitycheck(regex
, &count
)) {
486 controlreply(np
, "Error in expression.");
488 } else if (count
< 0) {
489 controlreply(np
, "That expression would hit too many users (%d)!", -count
);
493 realexpiry
= expiry
+ time(NULL
);
495 dbescapestring(eemask
, regex
, strlen(regex
));
496 dbescapestring(eesetby
, np
->nick
, strlen(np
->nick
));
497 dbescapestring(eeclass
, class, strlen(class));
498 dbescapestring(eereason
, reason
, strlen(reason
));
500 highestid
= highestid
+ 1;
501 dbquery("INSERT INTO regexgline.glines (id, gline, setby, reason, expires, type, class, lastseen, hits) VALUES (%lu, '%s', '%s', '%s', %lu, %c, '%s', 0, 0)", highestid
, eemask
, eesetby
, eereason
, realexpiry
, type
, eeclass
);
502 rp
= rg_newsstruct(highestid
, regex
, np
->nick
, reason
, "", cargv
[2], realexpiry
, class, 0, 0);
504 rg_initglinelist(&gll
);
506 for(j
=0;j
<NICKHASHSIZE
;j
++) {
507 for(tnp
=nicktable
[j
];tnp
;tnp
=tnp
->next
) {
508 if(IsOper(tnp
) || IsService(tnp
) || IsXOper(tnp
))
511 hostlen
= RGBuildHostname(hostname
, tnp
);
512 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0)
513 rg_dogline(&gll
, tnp
, rp
, hostname
);
517 rg_flushglines(&gll
);
519 expirybuf
= longtoduration(expiry
, 0);
521 rg_logevent(np
, "regexgline", "%s %d %d %s %s", regex
, expiry
, count
, class, reason
);
522 controlreply(np
, "Added regexgline: %s (class: %s, expires in: %s, hit %d user%s): %s", regex
, class, expirybuf
, count
, (count
!=1)?"s":"", reason
);
523 /* If we are using NO, can we safely assume the user is authed here and use ->authname? */
524 controlwall(NO_OPER
, NL_GLINES
, "%s!%s@%s/%s added regexgline: %s (class: %s, expires in: %s, hit %d user%s): %s", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, regex
, class, expirybuf
, count
, (count
!=1)?"s":"", reason
);
529 int rg_sanitycheck(char *mask
, int *count
) {
531 char hostname
[RG_MASKLEN
];
532 int erroroffset
, hostlen
, j
, masklen
= strlen(mask
);
537 if((masklen
< RG_MIN_MASK_LEN
) || (masklen
> RG_REGEXGLINE_MAX
))
540 if(!(regex
= pcre_compile(mask
, RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
541 Error("regexgline", ERR_WARNING
, "Error compiling expression %s at offset %d: %s", mask
, erroroffset
, error
);
544 hint
= pcre_study(regex
, 0, &error
);
546 Error("regexgline", ERR_WARNING
, "Error studying expression %s: %s", mask
, error
);
553 for(j
=0;j
<NICKHASHSIZE
;j
++) {
554 for(np
=nicktable
[j
];np
;np
=np
->next
) {
555 hostlen
= RGBuildHostname(hostname
, np
);
556 if(pcre_exec(regex
, hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
566 if(*count
>= rg_max_casualties
)
572 int rg_delgline(void *source
, int cargc
, char **cargv
) {
573 nick
*np
= (nick
*)source
;
575 struct rg_struct
*rp
= rg_list
, *last
= NULL
;
581 rg_logevent(np
, "regexdelgline", "%s", cargv
[0]);
583 if(RGMasksEqual(rp
->mask
->content
, cargv
[0])) {
586 /* Cleanup the delays */
587 for(delay
=rg_delays
;delay
;delay
=delay
->next
)
588 if(delay
->reason
==rp
)
589 delay
->reason
= NULL
;
591 dbquery("DELETE FROM regexgline.glines WHERE id = %d", rp
->id
);
593 last
->next
= rp
->next
;
607 controlreply(np
, "Deleted (matched: %d).", count
);
608 /* If we are using NO, can we safely assume the user is authed here and use ->authname? */
609 controlwall(NO_OPER
, NL_GLINES
, "%s!%s@%s/%s removed regexgline: %s", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, cargv
[0]);
611 controlreply(np
, "No glines matched: %s", cargv
[0]);
616 int rg_idlist(void *source
, int cargc
, char **cargv
) {
617 nick
*np
= (nick
*)source
;
621 } else if (strlen(cargv
[0]) != 8) {
622 controlreply(np
, "Invalid gline id!");
625 struct rg_struct
*rp
;
626 unsigned long id
= 0;
631 if(0xff == rc_hexlookup
[(int)cargv
[0][i
]]) {
632 controlreply(np
, "Invalid gline id!");
635 id
= (id
<< 4) | rc_hexlookup
[(int)cargv
[0][i
]];
640 controlreply(np
, GLINE_HEADER
);
641 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
642 if(id
== rp
->glineid
) {
644 if(rp
->mask
->length
> longest
)
645 longest
= rp
->mask
->length
;
649 for(rp
=rg_list
;rp
;rp
=rp
->next
)
651 rg_displaygline(np
, rp
, longest
);
652 controlreply(np
, "Done.");
658 int rg_glist(void *source
, int cargc
, char **cargv
) {
659 nick
*np
= (nick
*)source
;
660 struct rg_struct
*rp
;
670 if(!(regex
= pcre_compile(cargv
[0], RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
671 controlreply(np
, "Error compiling expression %s at offset %d: %s", cargv
[0], erroroffset
, error
);
674 hint
= pcre_study(regex
, 0, &error
);
676 controlreply(np
, "Error studying expression %s: %s", cargv
[0], error
);
683 rg_logevent(np
, "regexglist", "%s", cargv
[0]);
684 controlreply(np
, GLINE_HEADER
);
685 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
686 if(pcre_exec(regex
, hint
, rp
->mask
->content
, rp
->mask
->length
, 0, 0, NULL
, 0) >= 0) {
688 if(rp
->mask
->length
> longest
)
689 longest
= rp
->mask
->length
;
693 for(rp
=rg_list
;rp
;rp
=rp
->next
)
695 rg_displaygline(np
, rp
, longest
);
702 rg_logevent(np
, "regexglist", "%s", "");
703 controlreply(np
, GLINE_HEADER
);
704 for(rp
=rg_list
;rp
;rp
=rp
->next
)
705 if(rp
->mask
->length
> longest
)
706 longest
= rp
->mask
->length
;
708 for(rp
=rg_list
;rp
;rp
=rp
->next
)
709 rg_displaygline(np
, rp
, longest
);
712 controlreply(np
, "Done.");
716 char *displaytype(int type
) {
718 static char ctypebuf
[10];
743 snprintf(ctypebuf
, sizeof(ctype
), "%1d:%s", type
, ctype
);
747 char *getsep(int longest
) {
748 static int lastlongest
= -1;
749 static char lenbuf
[1024];
756 if(longest >= sizeof(lenbuf) - 20)
757 longest = sizeof(lenbuf) - 20;
760 if(lastlongest
== -1) {
763 for(i
=0;i
<sizeof(lenbuf
)-1;i
++)
765 lenbuf
[sizeof(lenbuf
)-1] = '\0';
769 if(lastlongest
!= longest
) {
770 lenbuf
[lastlongest
] = '-';
771 lenbuf
[longest
] = '\0';
772 lastlongest
= longest
;
778 void rg_displaygline(nick
*np
, struct rg_struct
*rp
, int longest
) { /* could be a macro? I'll assume the C compiler inlines it */
779 char *sep
= getsep(longest
);
780 /* 12345678 12345678901234567890 123456789012345 12345678 12345 12345678901234567890 1234567 1234567 123456
781 ID Expires Set by Class Type Last seen (ago) Hits(s) Hits Reason
785 time_t t
= time(NULL
);
787 if(rp
->lastseen
== 0) {
788 strlcpy(d
, "(never)", sizeof(d
));
790 strlcpy(d
, longtoduration(t
- rp
->lastseen
, 2), sizeof(d
));
793 controlreply(np
, "%s", rp
->mask
->content
);
794 controlreply(np
, " %08lx %-20s %-15s %-8s %-5s %-20s %-7lu %-7lu %s", rp
->glineid
, longtoduration(rp
->expires
- t
, 2), rp
->setby
->content
, rp
->class, displaytype(rp
->type
), d
, rp
->hitssaved
, rp
->hits
, rp
->reason
->content
);
795 controlreply(np
, "%s", sep
);
798 int rg_spew(void *source
, int cargc
, char **cargv
) {
799 nick
*np
= (nick
*)source
, *tnp
;
800 int counter
= 0, erroroffset
, hostlen
, j
;
804 char hostname
[RG_MASKLEN
];
811 if(!(regex
= pcre_compile(cargv
[0], RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
812 controlreply(np
, "Error compiling expression %s at offset %d: %s", cargv
[0], erroroffset
, error
);
815 hint
= pcre_study(regex
, 0, &error
);
817 controlreply(np
, "Error studying expression %s: %s", cargv
[0], error
);
823 rg_logevent(np
, "regexspew", "%s", cargv
[0]);
825 for(j
=0;j
<NICKHASHSIZE
;j
++) {
826 for(tnp
=nicktable
[j
];tnp
;tnp
=tnp
->next
) {
827 hostlen
= RGBuildHostname(hostname
, tnp
);
828 pcreret
= pcre_exec(regex
, hint
, hostname
, hostlen
, 0, 0, ovector
, sizeof(ovector
) / sizeof(int));
830 if(counter
== rg_max_spew
) {
831 controlreply(np
, "Reached maximum spew count (%d) - aborting display.", rg_max_spew
);
832 } else if (counter
< rg_max_spew
) {
833 /* 15 should be number of bolds */
834 char boldbuf
[RG_MASKLEN
+ 15], *tp
, *fp
, *realname
= NULL
;
836 for(tp
=hostname
,fp
=boldbuf
;*tp
;) {
837 if(tp
- hostname
== ovector
[0]) {
841 if(tp
- hostname
== ovector
[1]) {
860 controlreply(np
, "%s (%s) (%dc)", boldbuf
, realname
, tnp
->channels
->cursi
);
866 controlreply(np
, "Done - %d matches.", counter
);
875 void rg_startup(void) {
878 struct rg_struct
*rp
;
879 struct rg_glinelist gll
;
880 char hostname
[RG_MASKLEN
];
882 rg_initglinelist(&gll
);
884 for(j
=0;j
<NICKHASHSIZE
;j
++) {
885 for(np
=nicktable
[j
];np
;np
=np
->next
) {
886 if(IsOper(np
) || IsService(np
) || IsXOper(np
))
888 hostlen
= RGBuildHostname(hostname
, np
);
889 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
890 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
891 rg_dogline(&gll
, np
, rp
, hostname
);
898 rg_flushglines(&gll
);
901 void rg_freestruct(struct rg_struct
*rp
) {
902 freesstring(rp
->mask
);
903 freesstring(rp
->setby
);
904 freesstring(rp
->reason
);
905 pcre_free(rp
->regex
);
911 struct rg_struct
*rg_newstruct(time_t expires
) {
912 struct rg_struct
*rp
;
914 if (time(NULL
) >= expires
)
917 rp
= (struct rg_struct
*)malloc(sizeof(struct rg_struct
));
919 struct rg_struct
*tp
, *lp
;
921 memset(rp
, 0, sizeof(rg_struct
));
922 rp
->expires
= expires
;
924 for(lp
=NULL
,tp
=rg_list
;tp
;lp
=tp
,tp
=tp
->next
) {
925 if (expires
<= tp
->expires
) { /* <= possible, slight speed increase */
948 struct rg_struct
*rg_newsstruct(unsigned long id
, char *mask
, char *setby
, char *reason
, char *expires
, char *type
, time_t iexpires
, char *class, time_t lastseen
, unsigned int hitssaved
) {
949 struct rg_struct
*newrow
, *lp
, *cp
;
951 char glineiddata
[1024];
956 if(!protectedatoi(expires
, &qexpires
))
958 rexpires
= (time_t)qexpires
;
963 newrow
= rg_newstruct(rexpires
);
969 for(p
=classes
;*p
;p
++) {
970 if(!strcasecmp(class, *p
)) {
977 newrow
->class = "unknown";
979 if(!(newrow
->regex
= pcre_compile(mask
, RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
980 Error("regexgline", ERR_WARNING
, "Error compiling expression %s at offset %d: %s", mask
, erroroffset
, error
);
983 newrow
->hint
= pcre_study(newrow
->regex
, 0, &error
);
985 Error("regexgline", ERR_WARNING
, "Error studying expression %s: %s", mask
, error
);
986 pcre_free(newrow
->regex
);
992 newrow
->hitssaved
= hitssaved
;
993 newrow
->lastseen
= lastseen
;
995 newrow
->mask
= getsstring(mask
, RG_REGEXGLINE_MAX
);
997 Error("regexgline", ERR_WARNING
, "Error allocating memory for mask!");
1001 newrow
->setby
= getsstring(setby
, ACCOUNTLEN
);
1002 if(!newrow
->setby
) {
1003 Error("regexgline", ERR_WARNING
, "Error allocating memory for setby!");
1007 newrow
->reason
= getsstring(reason
, RG_REASON_MAX
);
1008 if(!newrow
->reason
) {
1009 Error("regexgline", ERR_WARNING
, "Error allocating memory for reason!");
1013 if(!protectedatoi(type
, &newrow
->type
))
1014 newrow
->type
= 0; /* just in case */
1016 snprintf(glineiddata
, sizeof(glineiddata
), "%s regexgline %s %s %s %d %d", mynumeric
->content
, mask
, setby
, reason
, (int)iexpires
, newrow
->type
);
1017 newrow
->glineid
= crc32(glineiddata
);
1024 freesstring(newrow
->mask
);
1026 freesstring(newrow
->setby
);
1028 freesstring(newrow
->reason
);
1029 pcre_free(newrow
->regex
);
1031 pcre_free(newrow
->hint
);
1034 for(lp
=NULL
,cp
=rg_list
;cp
;lp
=cp
,cp
=cp
->next
) {
1037 lp
->next
= cp
->next
;
1048 int __rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
) { /* PPA: if multiple users match the same user@host or *@host it'll send multiple glines?! */
1049 char hostname
[RG_MASKLEN
];
1053 rg_loggline(rp
, np
);
1055 if (rp
->type
== INSTANT_HOST_GLINE
) {
1056 usercount
= np
->host
->clonecount
;
1057 snprintf(hostname
, sizeof(hostname
), "*@%s", IPtostr(np
->p_ipaddr
));
1060 if ((rp
->type
== INSTANT_IDENT_GLINE
) || (usercount
> rg_max_per_gline
)) {
1063 for(usercount
=0,tnp
=np
->host
->nicks
;tnp
;tnp
=tnp
->nextbyhost
)
1064 if(!ircd_strcmp(np
->ident
, tnp
->ident
))
1067 snprintf(hostname
, sizeof(hostname
), "%s@%s", np
->ident
, IPtostr(np
->p_ipaddr
));
1070 validdelay
= (rp
->type
== INSTANT_KILL
) || (rp
->type
== DELAYED_IDENT_GLINE
) || (rp
->type
== DELAYED_HOST_GLINE
) || (rp
->type
== DELAYED_KILL
);
1071 if (validdelay
|| (usercount
> rg_max_per_gline
)) {
1072 struct rg_glinenode
*nn
= (struct rg_glinenode
*)malloc(sizeof(struct rg_glinenode
));
1076 gll
->end
->next
= nn
;
1086 nn
->punish
= INSTANT_KILL
;
1088 nn
->punish
= rp
->type
;
1094 if (rp
->type
== INSTANT_IDENT_GLINE
) {
1095 if (IsAccount(np
)) {
1096 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched user@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1098 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched user@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1100 } else if(rp
->type
== INSTANT_HOST_GLINE
) {
1101 if (IsAccount(np
)) {
1102 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched *@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1104 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched *@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1110 rg_shadowserver(np
, rp
, rp
->type
);
1111 irc_send("%s GL * +%s %d %jd :AUTO: %s (ID: %08lx)\r\n", mynumeric
->content
, hostname
, rg_expiry_time
, (intmax_t)time(NULL
), rp
->reason
->content
, rp
->glineid
);
1115 static int floodprotection
= 0;
1116 static int lastfloodspam
= 0;
1118 void rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
) {
1121 if(t
> floodprotection
) {
1122 floodprotection
= t
;
1123 } else if((floodprotection
- t
) / 8 > RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
) {
1124 if(t
> lastfloodspam
+ 3600) {
1125 channel
*cp
= findchannel("#twilightzone");
1127 controlchanmsg(cp
, "WARNING! REGEXGLINE DISABLED FOR AN HOUR DUE TO NETWORK WIDE LOOKING GLINE!: %d exceeded %d", (floodprotection
- t
) / 8, RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
);
1128 controlwall(NO_OPER
, NL_MANAGEMENT
, "WARNING! REGEXGLINE DISABLED FOR AN HOUR DUE TO NETWORK WIDE LOOKING GLINE!");
1130 floodprotection
= t
+ RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
* 3600 * 8;
1135 floodprotection
+=__rg_dogline(gll
, np
, rp
, matched
);
1138 void rg_logevent(nick
*np
, char *event
, char *details
, ...) {
1139 char eeevent
[RG_QUERY_BUF_SIZE
], eedetails
[RG_QUERY_BUF_SIZE
], eemask
[RG_QUERY_BUF_SIZE
], eeaccount
[RG_QUERY_BUF_SIZE
];
1140 char buf
[513], account
[ACCOUNTLEN
+ 1], mask
[RG_MASKLEN
];
1146 va_start(va
, details
);
1147 vsnprintf(buf
, sizeof(buf
), details
, va
);
1154 if (IsAccount(np
)) {
1155 strncpy(account
, np
->authname
, sizeof(account
) - 1);
1156 account
[sizeof(account
) - 1] = '\0';
1160 masklen
= RGBuildHostname(mask
, np
);
1166 dbescapestring(eeevent
, event
, strlen(event
));
1167 dbescapestring(eedetails
, buf
, strlen(buf
));
1168 dbescapestring(eeaccount
, account
, strlen(account
));
1169 dbescapestring(eemask
, mask
, masklen
);
1171 dbquery("INSERT INTO regexgline.clog (host, account, event, arg, ts) VALUES ('%s', '%s', '%s', '%s', NOW())", eemask
, eeaccount
, eeevent
, eedetails
);
1174 void rg_loggline(struct rg_struct
*rg
, nick
*np
) {
1175 char eenick
[RG_QUERY_BUF_SIZE
], eeuser
[RG_QUERY_BUF_SIZE
], eehost
[RG_QUERY_BUF_SIZE
], eereal
[RG_QUERY_BUF_SIZE
];
1179 rg
->lastseen
= time(NULL
);
1182 /* @paul: disabled */
1185 dbescapestring(eenick
, np
->nick
, strlen(np
->nick
));
1186 dbescapestring(eeuser
, np
->ident
, strlen(np
->ident
));
1187 dbescapestring(eehost
, np
->host
->name
->content
, strlen(np
->host
->name
->content
));
1188 dbescapestring(eereal
, np
->realname
->name
->content
, strlen(np
->realname
->name
->content
));
1190 dbquery("INSERT INTO regexgline.glog (glineid, nickname, username, hostname, realname, ts) VALUES (%d, '%s', '%s', '%s', '%s', NOW())", rg
->id
, eenick
, eeuser
, eehost
, eereal
);
1193 static unsigned int getrgmarker(void) {
1194 static unsigned int marker
= 0;
1198 struct rg_struct
*l
;
1200 /* If we wrapped to zero, zap the marker on all hosts */
1201 for(l
=rg_list
;l
;l
=l
->next
)
1209 void rg_flush_schedule(void *arg
) {
1210 struct rg_struct
*l
;
1212 for(l
=rg_list
;l
;l
=l
->next
) {
1216 dbquery("UPDATE regexgline.glines SET lastseen = %jd, hits = %lu WHERE id = %d", (intmax_t)l
->lastseen
, l
->hitssaved
, l
->id
);