5 FUTURE: natural (sort of) language parsing
8 PPA: if multiple users match the same user@host or *@host it'll send multiple glines?!
11 #include "regexgline.h"
12 #include "../lib/version.h"
13 #include "../dbapi/dbapi.h"
14 #include "../lib/stringbuf.h"
15 #include "../core/hooks.h"
16 #include "../server/server.h"
17 #include "../lib/strlfunc.h"
19 #define INSTANT_IDENT_GLINE 1
20 #define INSTANT_HOST_GLINE 2
21 #define INSTANT_KILL 3
22 #define DELAYED_IDENT_GLINE 4
23 #define DELAYED_HOST_GLINE 5
24 #define DELAYED_KILL 6
26 MODULE_VERSION("1.43");
28 typedef struct rg_glinenode
{
30 struct rg_struct
*reason
;
32 struct rg_glinenode
*next
;
35 typedef struct rg_glinelist
{
36 struct rg_glinenode
*start
;
37 struct rg_glinenode
*end
;
40 typedef struct rg_delay
{
43 struct rg_struct
*reason
;
45 struct rg_delay
*next
;
48 #define GLINE_HEADER " ID Expires Set by Class Type Last seen (ago) Hits(p) Hits Reason"
52 void rg_setdelay(nick
*np
, struct rg_struct
*reason
, short punish
);
53 void rg_deletedelay(rg_delay
*delay
);
54 void rg_dodelay(void *arg
);
56 void rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
);
57 void rg_flush_schedule(void *arg
);
59 static DBModuleIdentifier dbid
;
60 static unsigned long highestid
= 0;
61 static int attached
= 0, started
= 0;
63 static unsigned int getrgmarker(void);
65 /* shadowserver only reports classes[0] */
66 static const char *classes
[] = { "drone", "proxy", "spam", "fakeauth", "other", (char *)0 };
69 sstring
*max_casualties
, *max_spew
, *expiry_time
, *max_per_gline
;
71 max_casualties
= getcopyconfigitem("regexgline", "maxcasualties", RGStringise(RG_MAX_CASUALTIES_DEFAULT
), 8);
72 if(!protectedatoi(max_casualties
->content
, &rg_max_casualties
))
73 rg_max_casualties
= RG_MAX_CASUALTIES_DEFAULT
;
75 freesstring(max_casualties
);
77 max_spew
= getcopyconfigitem("regexgline", "maxspew", RGStringise(RG_MAX_SPEW_DEFAULT
), 8);
78 if(!protectedatoi(max_spew
->content
, &rg_max_spew
))
79 rg_max_spew
= RG_MAX_SPEW_DEFAULT
;
81 freesstring(max_spew
);
83 expiry_time
= getcopyconfigitem("regexgline", "expirytime", RGStringise(RG_EXPIRY_TIME_DEFAULT
), 8);
84 if(!protectedatoi(expiry_time
->content
, &rg_expiry_time
))
85 rg_expiry_time
= RG_EXPIRY_TIME_DEFAULT
;
87 freesstring(expiry_time
);
89 max_per_gline
= getcopyconfigitem("regexgline", "maxpergline", RGStringise(RG_MAX_PER_GLINE_DEFAULT
), 8);
90 if(!protectedatoi(max_per_gline
->content
, &rg_max_per_gline
))
91 rg_max_per_gline
= RG_MAX_PER_GLINE_DEFAULT
;
93 freesstring(max_per_gline
);
102 Error("regexgline", ERR_STOP
, "Could not connect to database.");
107 struct rg_struct
*gp
= rg_list
, *oldgp
;
108 rg_delay
*delay
, *delaynext
;
111 deregisterhook(HOOK_NICK_NEWNICK
, &rg_nick
);
112 deregisterhook(HOOK_NICK_RENAME
, &rg_nick
);
113 deregisterhook(HOOK_NICK_LOSTNICK
, &rg_lostnick
);
114 deregistercontrolcmd("regexspew", rg_spew
);
115 deregistercontrolcmd("regexglist", rg_glist
);
116 deregistercontrolcmd("regexdelgline", rg_delgline
);
117 deregistercontrolcmd("regexgline", rg_gline
);
118 deregistercontrolcmd("regexidlookup", rg_idlist
);
122 for(delay
=rg_delays
;delay
;delay
=delaynext
) {
123 delaynext
=delay
->next
;
124 deleteschedule(delay
->sch
, rg_dodelay
, delay
);
130 deleteschedule(rg_schedule
, &rg_checkexpiry
, NULL
);
134 deleteallschedules(rg_flush_schedule
);
135 rg_flush_schedule(NULL
);
137 for(gp
=rg_list
;gp
;) {
140 rg_freestruct(oldgp
);
144 dbdetach("regexgline");
149 void rg_checkexpiry(void *arg
) {
150 struct rg_struct
*rp
= rg_list
, *lp
= NULL
;
151 time_t current
= time(NULL
);
154 if (current
>= rp
->expires
) {
171 void rg_setdelay(nick
*np
, rg_struct
*reason
, short punish
) {
173 delay
= (rg_delay
*)malloc(sizeof(rg_delay
));
177 killuser(NULL
, np
, "%s (ID: %08lx)", reason
->reason
->content
, reason
->glineid
);
182 delay
->reason
= reason
;
183 delay
->punish
= punish
;
184 delay
->next
= rg_delays
;
187 delay
->sch
= scheduleoneshot(time(NULL
) + (RG_MINIMUM_DELAY_TIME
+ (rand() % RG_MAXIMUM_RAND_TIME
)), rg_dodelay
, delay
);
190 static void rg_shadowserver(nick
*np
, struct rg_struct
*reason
, int type
) {
193 if(reason
->class != classes
[0]) /* drone */
196 snprintf(buf
, sizeof(buf
), "regex-ban %lu %s!%s@%s %s %s", time(NULL
), np
->nick
, np
->ident
, np
->host
->name
->content
, reason
->mask
->content
, serverlist
[homeserver(np
->numeric
)].name
->content
);
198 triggerhook(HOOK_SHADOW_SERVER
, (void *)buf
);
201 void rg_deletedelay(rg_delay
*delay
) {
202 rg_delay
*temp
, *prev
;
204 for (temp
=rg_delays
;temp
;temp
=temp
->next
) {
207 rg_delays
= temp
->next
;
209 prev
->next
= temp
->next
;
219 void rg_dodelay(void *arg
) {
220 rg_delay
*delay
= (rg_delay
*)arg
;
221 char hostname
[RG_MASKLEN
];
222 int hostlen
, usercount
= 0;
224 /* User or regex gline no longer exists */
225 if((!delay
->np
) || (!delay
->reason
)) {
226 rg_deletedelay(delay
);
230 hostlen
= RGBuildHostname(hostname
, delay
->np
);
232 /* User has wisely changed nicknames */
233 if(pcre_exec(delay
->reason
->regex
, delay
->reason
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) < 0) {
234 rg_deletedelay(delay
);
238 if (delay
->reason
->type
== DELAYED_HOST_GLINE
) {
239 usercount
= delay
->np
->host
->clonecount
;
240 snprintf(hostname
, sizeof(hostname
), "*@%s", IPtostr(delay
->np
->p_ipaddr
));
243 if((delay
->reason
->type
== DELAYED_IDENT_GLINE
) || (usercount
> rg_max_per_gline
)) {
246 for(usercount
=0,tnp
=delay
->np
->host
->nicks
;tnp
;tnp
=tnp
->nextbyhost
)
247 if(!ircd_strcmp(delay
->np
->ident
, tnp
->ident
))
250 snprintf(hostname
, sizeof(hostname
), "%s@%s", delay
->np
->ident
, IPtostr(delay
->np
->p_ipaddr
));
253 if ((delay
->reason
->type
== DELAYED_KILL
) || (usercount
> rg_max_per_gline
)) {
254 if (IsAccount(delay
->np
)) {
255 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched delayed kill regex %08lx (class: %s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->np
->authname
, delay
->reason
->glineid
, delay
->reason
->class);
257 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched delayed kill regex %08lx (class: %s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->reason
->glineid
, delay
->reason
->class);
260 rg_shadowserver(delay
->np
, delay
->reason
, DELAYED_KILL
);
261 killuser(NULL
, delay
->np
, "%s (ID: %08lx)", delay
->reason
->reason
->content
, delay
->reason
->glineid
);
265 if (delay
->reason
->type
== DELAYED_IDENT_GLINE
) {
266 if (IsAccount(delay
->np
)) {
267 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched delayed user@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->np
->authname
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
269 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched delayed user@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
271 } else if (delay
->reason
->type
== DELAYED_HOST_GLINE
) {
272 if (IsAccount(delay
->np
)) {
273 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched delayed *@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->np
->authname
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
275 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched delayed *@host gline regex %08lx (class: %s, hit %d user%s)", delay
->np
->nick
, delay
->np
->ident
, delay
->np
->host
->name
->content
, delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
281 rg_shadowserver(delay
->np
, delay
->reason
, delay
->reason
->type
);
282 irc_send("%s GL * +%s %d %zu :AUTO: %s (ID: %08lx)\r\n", mynumeric
->content
, hostname
, rg_expiry_time
, time(NULL
), delay
->reason
->reason
->content
, delay
->reason
->glineid
);
283 rg_deletedelay(delay
);
286 void rg_initglinelist(struct rg_glinelist
*gll
) {
291 void rg_flushglines(struct rg_glinelist
*gll
) {
292 struct rg_glinenode
*nn
, *pn
;
293 for(nn
=gll
->start
;nn
;nn
=pn
) {
295 if(nn
->punish
== INSTANT_KILL
) {
296 if ( IsAccount(nn
->np
) ) {
297 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched kill regex %08lx (class: %s)", nn
->np
->nick
, nn
->np
->ident
, nn
->np
->host
->name
->content
, nn
->np
->authname
, nn
->reason
->glineid
, nn
->reason
->class);
299 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched kill regex %08lx (class: %s)", nn
->np
->nick
, nn
->np
->ident
, nn
->np
->host
->name
->content
, nn
->reason
->glineid
, nn
->reason
->class);
302 rg_shadowserver(nn
->np
, nn
->reason
, nn
->punish
);
303 killuser(NULL
, nn
->np
, "%s (ID: %08lx)", nn
->reason
->reason
->content
, nn
->reason
->glineid
);
304 } else if ((nn
->punish
== DELAYED_IDENT_GLINE
) || (nn
->punish
== DELAYED_HOST_GLINE
) || (nn
->punish
== DELAYED_KILL
)) {
305 rg_setdelay(nn
->np
, nn
->reason
, nn
->punish
);
310 rg_initglinelist(gll
);
313 static void dbloaddata(DBConn
*dbconn
, void *arg
) {
314 DBResult
*dbres
= dbgetresult(dbconn
);
316 if(!dbquerysuccessful(dbres
)) {
317 Error("chanserv", ERR_ERROR
, "Error loading DB");
321 if (dbnumfields(dbres
) != 9) {
322 Error("regexgline", ERR_ERROR
, "DB format error");
326 while(dbfetchrow(dbres
)) {
327 unsigned long id
, hitssaved
;
329 char *gline
, *setby
, *reason
, *expires
, *type
, *class;
331 id
= strtoul(dbgetvalue(dbres
, 0), NULL
, 10);
335 gline
= dbgetvalue(dbres
, 1);
336 setby
= dbgetvalue(dbres
, 2);
337 reason
= dbgetvalue(dbres
, 3);
338 expires
= dbgetvalue(dbres
, 4);
339 type
= dbgetvalue(dbres
, 5);
340 class = dbgetvalue(dbres
, 6);
342 lastseen
= strtoul(dbgetvalue(dbres
, 7), NULL
, 10);
343 hitssaved
= strtoul(dbgetvalue(dbres
, 8), NULL
, 10);
345 if (!rg_newsstruct(id
, gline
, setby
, reason
, expires
, type
, 0, class, lastseen
, hitssaved
))
346 dbquery("DELETE FROM regexgline.glines WHERE id = %lu", id
);
352 static void dbloadfini(DBConn
*dbconn
, void *arg
) {
356 char helpbuf
[8192 * 2], allclasses
[8192];
358 sbinit(&b
, (char *)allclasses
, sizeof(allclasses
));
359 for(p
=classes
;*p
;p
++) {
360 sbaddstr(&b
, (char *)*p
);
365 snprintf(helpbuf
, sizeof(helpbuf
),
366 "Usage: regexgline <regex> <duration> <type> <class> <reason>\n"
367 "Adds a new regular expression pattern.\n"
368 "Duration is represented as 3d, 3M etc.\n"
369 "Class is one of the following: %s\n"
370 "Type is an integer which represents the following:\n"
371 "1 - Instant USER@IP GLINE (igu)\n"
372 "2 - Instant *@IP GLINE (igh)\n"
373 "3 - Instant KILL (ik)\n"
374 "4 - Delayed USER@IP GLINE (dgu)\n"
375 "5 - Delayed *@IP GLINE (dgh)\n"
376 "6 - Delayed KILL (dk)",
379 registercontrolhelpcmd("regexgline", NO_OPER
, 5, &rg_gline
, helpbuf
);
380 registercontrolhelpcmd("regexdelgline", NO_OPER
, 1, &rg_delgline
, "Usage: regexdelgline <pattern>\nDeletes a regular expression pattern.");
381 registercontrolhelpcmd("regexglist", NO_OPER
, 1, &rg_glist
, "Usage: regexglist <pattern>\nLists regular expression patterns.");
382 registercontrolhelpcmd("regexspew", NO_OPER
, 1, &rg_spew
, "Usage: regexspew <pattern>\nLists users currently on the network which match the given pattern.");
383 registercontrolhelpcmd("regexidlookup", NO_OPER
, 1, &rg_idlist
, "Usage: regexidlookup <id>\nFinds a regular expression pattern by it's ID number.");
385 registerhook(HOOK_NICK_NEWNICK
, &rg_nick
);
386 registerhook(HOOK_NICK_RENAME
, &rg_nick
);
387 registerhook(HOOK_NICK_LOSTNICK
, &rg_lostnick
);
390 rg_schedule
= schedulerecurring(time(NULL
) + 1, 0, 1, rg_checkexpiry
, NULL
);
391 schedulerecurring(time(NULL
) + 60, 0, 60, rg_flush_schedule
, NULL
);
394 void rg_dbload(void) {
395 dbattach("regexgline");
396 dbcreatequery("CREATE TABLE regexgline.glines (id INT NOT NULL PRIMARY KEY, gline TEXT NOT NULL, setby VARCHAR(%d) NOT NULL, reason VARCHAR(%d) NOT NULL, expires INT NOT NULL, type INT NOT NULL DEFAULT 1, class TEXT NOT NULL, lastseen INT DEFAULT 0, hits INT DEFAULT 0)", ACCOUNTLEN
, RG_REASON_MAX
);
397 dbcreatequery("CREATE TABLE regexgline.clog (host VARCHAR(%d) NOT NULL, account VARCHAR(%d) NOT NULL, event TEXT NOT NULL, arg TEXT NOT NULL, ts TIMESTAMP)", RG_MASKLEN
- 1, ACCOUNTLEN
);
398 dbcreatequery("CREATE TABLE regexgline.glog (glineid INT NOT NULL, ts TIMESTAMP, nickname VARCHAR(%d) NOT NULL, username VARCHAR(%d) NOT NULL, hostname VARCHAR(%d) NOT NULL, realname VARCHAR(%d))", NICKLEN
, USERLEN
, HOSTLEN
, REALLEN
);
400 dbloadtable("regexgline.glines", NULL
, dbloaddata
, dbloadfini
);
403 void rg_nick(int hooknum
, void *arg
) {
404 nick
*np
= (nick
*)arg
;
405 struct rg_struct
*rp
;
406 char hostname
[RG_MASKLEN
];
408 struct rg_glinelist gll
;
410 rg_initglinelist(&gll
);
412 hostlen
= RGBuildHostname(hostname
, np
);
414 if(IsOper(np
) || IsService(np
) || IsXOper(np
))
417 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
418 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
419 rg_dogline(&gll
, np
, rp
, hostname
);
424 rg_flushglines(&gll
);
427 void rg_lostnick(int hooknum
, void *arg
) {
428 nick
*np
= (nick
*)arg
;
431 /* Cleanup the delays */
432 for(delay
=rg_delays
;delay
;delay
=delay
->next
)
437 int rg_gline(void *source
, int cargc
, char **cargv
) {
438 nick
*np
= (nick
*)source
, *tnp
;
440 const char *expirybuf
;
441 int expiry
, count
, j
, hostlen
;
442 struct rg_struct
*rp
;
443 struct rg_glinelist gll
;
446 char eemask
[RG_QUERY_BUF_SIZE
], eesetby
[RG_QUERY_BUF_SIZE
], eereason
[RG_QUERY_BUF_SIZE
], eeclass
[RG_QUERY_BUF_SIZE
];
447 char hostname
[RG_MASKLEN
], *class, *reason
, *regex
, type
;
453 if ((strlen(cargv
[2]) != 1) || ((type
!= '1') && (type
!= '2') && (type
!= '3') && (type
!= '4') && (type
!= '5') && (type
!= '6'))) {
454 controlreply(np
, "Invalid type specified!");
462 for(p
=classes
;*p
;p
++)
463 if(!strcasecmp(class, *p
))
467 controlreply(np
, "Bad class supplied.");
471 if (!(expiry
= durationtolong(cargv
[1]))) {
472 controlreply(np
, "Invalid duration specified!");
476 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
477 if (RGMasksEqual(rp
->mask
->content
, regex
)) {
478 controlreply(np
, "That regexgline already exists!");
483 if (rg_sanitycheck(regex
, &count
)) {
484 controlreply(np
, "Error in expression.");
486 } else if (count
< 0) {
487 controlreply(np
, "That expression would hit too many users (%d)!", -count
);
491 realexpiry
= expiry
+ time(NULL
);
493 dbescapestring(eemask
, regex
, strlen(regex
));
494 dbescapestring(eesetby
, np
->nick
, strlen(np
->nick
));
495 dbescapestring(eeclass
, class, strlen(class));
496 dbescapestring(eereason
, reason
, strlen(reason
));
498 highestid
= highestid
+ 1;
499 dbquery("INSERT INTO regexgline.glines (id, gline, setby, reason, expires, type, class, lastseen, hits) VALUES (%lu, '%s', '%s', '%s', %lu, %c, '%s', 0, 0)", highestid
, eemask
, eesetby
, eereason
, realexpiry
, type
, eeclass
);
500 rp
= rg_newsstruct(highestid
, regex
, np
->nick
, reason
, "", cargv
[2], realexpiry
, class, 0, 0);
502 rg_initglinelist(&gll
);
504 for(j
=0;j
<NICKHASHSIZE
;j
++) {
505 for(tnp
=nicktable
[j
];tnp
;tnp
=tnp
->next
) {
506 if(IsOper(tnp
) || IsService(tnp
) || IsXOper(tnp
))
509 hostlen
= RGBuildHostname(hostname
, tnp
);
510 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0)
511 rg_dogline(&gll
, tnp
, rp
, hostname
);
515 rg_flushglines(&gll
);
517 expirybuf
= longtoduration(expiry
, 0);
519 rg_logevent(np
, "regexgline", "%s %d %d %s %s", regex
, expiry
, count
, class, reason
);
520 controlreply(np
, "Added regexgline: %s (class: %s, expires in: %s, hit %d user%s): %s", regex
, class, expirybuf
, count
, (count
!=1)?"s":"", reason
);
521 /* If we are using NO, can we safely assume the user is authed here and use ->authname? */
522 controlwall(NO_OPER
, NL_GLINES
, "%s!%s@%s/%s added regexgline: %s (class: %s, expires in: %s, hit %d user%s): %s", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, regex
, class, expirybuf
, count
, (count
!=1)?"s":"", reason
);
527 int rg_sanitycheck(char *mask
, int *count
) {
529 char hostname
[RG_MASKLEN
];
530 int erroroffset
, hostlen
, j
, masklen
= strlen(mask
);
535 if((masklen
< RG_MIN_MASK_LEN
) || (masklen
> RG_REGEXGLINE_MAX
))
538 if(!(regex
= pcre_compile(mask
, RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
539 Error("regexgline", ERR_WARNING
, "Error compiling expression %s at offset %d: %s", mask
, erroroffset
, error
);
542 hint
= pcre_study(regex
, 0, &error
);
544 Error("regexgline", ERR_WARNING
, "Error studying expression %s: %s", mask
, error
);
551 for(j
=0;j
<NICKHASHSIZE
;j
++) {
552 for(np
=nicktable
[j
];np
;np
=np
->next
) {
553 hostlen
= RGBuildHostname(hostname
, np
);
554 if(pcre_exec(regex
, hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
564 if(*count
>= rg_max_casualties
)
570 int rg_delgline(void *source
, int cargc
, char **cargv
) {
571 nick
*np
= (nick
*)source
;
573 struct rg_struct
*rp
= rg_list
, *last
= NULL
;
579 rg_logevent(np
, "regexdelgline", "%s", cargv
[0]);
581 if(RGMasksEqual(rp
->mask
->content
, cargv
[0])) {
584 /* Cleanup the delays */
585 for(delay
=rg_delays
;delay
;delay
=delay
->next
)
586 if(delay
->reason
==rp
)
587 delay
->reason
= NULL
;
589 dbquery("DELETE FROM regexgline.glines WHERE id = %d", rp
->id
);
591 last
->next
= rp
->next
;
605 controlreply(np
, "Deleted (matched: %d).", count
);
606 /* If we are using NO, can we safely assume the user is authed here and use ->authname? */
607 controlwall(NO_OPER
, NL_GLINES
, "%s!%s@%s/%s removed regexgline: %s", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, cargv
[0]);
609 controlreply(np
, "No glines matched: %s", cargv
[0]);
614 int rg_idlist(void *source
, int cargc
, char **cargv
) {
615 nick
*np
= (nick
*)source
;
619 } else if (strlen(cargv
[0]) != 8) {
620 controlreply(np
, "Invalid gline id!");
623 struct rg_struct
*rp
;
624 unsigned long id
= 0;
629 if(0xff == rc_hexlookup
[(int)cargv
[0][i
]]) {
630 controlreply(np
, "Invalid gline id!");
633 id
= (id
<< 4) | rc_hexlookup
[(int)cargv
[0][i
]];
638 controlreply(np
, GLINE_HEADER
);
639 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
640 if(id
== rp
->glineid
) {
642 if(rp
->mask
->length
> longest
)
643 longest
= rp
->mask
->length
;
647 for(rp
=rg_list
;rp
;rp
=rp
->next
)
649 rg_displaygline(np
, rp
, longest
);
650 controlreply(np
, "Done.");
656 int rg_glist(void *source
, int cargc
, char **cargv
) {
657 nick
*np
= (nick
*)source
;
658 struct rg_struct
*rp
;
668 if(!(regex
= pcre_compile(cargv
[0], RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
669 controlreply(np
, "Error compiling expression %s at offset %d: %s", cargv
[0], erroroffset
, error
);
672 hint
= pcre_study(regex
, 0, &error
);
674 controlreply(np
, "Error studying expression %s: %s", cargv
[0], error
);
681 rg_logevent(np
, "regexglist", "%s", cargv
[0]);
682 controlreply(np
, GLINE_HEADER
);
683 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
684 if(pcre_exec(regex
, hint
, rp
->mask
->content
, rp
->mask
->length
, 0, 0, NULL
, 0) >= 0) {
686 if(rp
->mask
->length
> longest
)
687 longest
= rp
->mask
->length
;
691 for(rp
=rg_list
;rp
;rp
=rp
->next
)
693 rg_displaygline(np
, rp
, longest
);
700 rg_logevent(np
, "regexglist", NULL
);
701 controlreply(np
, GLINE_HEADER
);
702 for(rp
=rg_list
;rp
;rp
=rp
->next
)
703 if(rp
->mask
->length
> longest
)
704 longest
= rp
->mask
->length
;
706 for(rp
=rg_list
;rp
;rp
=rp
->next
)
707 rg_displaygline(np
, rp
, longest
);
710 controlreply(np
, "Done.");
714 char *displaytype(int type
) {
716 static char ctypebuf
[10];
741 snprintf(ctypebuf
, sizeof(ctype
), "%1d:%s", type
, ctype
);
745 char *getsep(int longest
) {
746 static int lastlongest
= -1;
747 static char lenbuf
[1024];
754 if(longest >= sizeof(lenbuf) - 20)
755 longest = sizeof(lenbuf) - 20;
758 if(lastlongest
== -1) {
761 for(i
=0;i
<sizeof(lenbuf
)-1;i
++)
763 lenbuf
[sizeof(lenbuf
)-1] = '\0';
767 if(lastlongest
!= longest
) {
768 lenbuf
[lastlongest
] = '-';
769 lenbuf
[longest
] = '\0';
770 lastlongest
= longest
;
776 void rg_displaygline(nick
*np
, struct rg_struct
*rp
, int longest
) { /* could be a macro? I'll assume the C compiler inlines it */
777 char *sep
= getsep(longest
);
778 /* 12345678 12345678901234567890 123456789012345 12345678 12345 12345678901234567890 1234567 1234567 123456
779 ID Expires Set by Class Type Last seen (ago) Hits(s) Hits Reason
783 time_t t
= time(NULL
);
785 if(rp
->lastseen
== 0) {
786 strlcpy(d
, "(never)", sizeof(d
));
788 strlcpy(d
, longtoduration(t
- rp
->lastseen
, 2), sizeof(d
));
791 controlreply(np
, "%s", rp
->mask
->content
);
792 controlreply(np
, " %08lx %-20s %-15s %-8s %-5s %-20s %-7lu %-7lu %s", rp
->glineid
, longtoduration(rp
->expires
- t
, 2), rp
->setby
->content
, rp
->class, displaytype(rp
->type
), d
, rp
->hitssaved
, rp
->hits
, rp
->reason
->content
);
793 controlreply(np
, "%s", sep
);
796 int rg_spew(void *source
, int cargc
, char **cargv
) {
797 nick
*np
= (nick
*)source
, *tnp
;
798 int counter
= 0, erroroffset
, hostlen
, j
;
802 char hostname
[RG_MASKLEN
];
809 if(!(regex
= pcre_compile(cargv
[0], RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
810 controlreply(np
, "Error compiling expression %s at offset %d: %s", cargv
[0], erroroffset
, error
);
813 hint
= pcre_study(regex
, 0, &error
);
815 controlreply(np
, "Error studying expression %s: %s", cargv
[0], error
);
821 rg_logevent(np
, "regexspew", "%s", cargv
[0]);
823 for(j
=0;j
<NICKHASHSIZE
;j
++) {
824 for(tnp
=nicktable
[j
];tnp
;tnp
=tnp
->next
) {
825 hostlen
= RGBuildHostname(hostname
, tnp
);
826 pcreret
= pcre_exec(regex
, hint
, hostname
, hostlen
, 0, 0, ovector
, sizeof(ovector
) / sizeof(int));
828 if(counter
== rg_max_spew
) {
829 controlreply(np
, "Reached maximum spew count (%d) - aborting display.", rg_max_spew
);
830 } else if (counter
< rg_max_spew
) {
831 /* 15 should be number of bolds */
832 char boldbuf
[RG_MASKLEN
+ 15], *tp
, *fp
, *realname
= NULL
;
834 for(tp
=hostname
,fp
=boldbuf
;*tp
;) {
835 if(tp
- hostname
== ovector
[0]) {
839 if(tp
- hostname
== ovector
[1]) {
858 controlreply(np
, "%s (%s) (%dc)", boldbuf
, realname
, tnp
->channels
->cursi
);
864 controlreply(np
, "Done - %d matches.", counter
);
873 void rg_startup(void) {
876 struct rg_struct
*rp
;
877 struct rg_glinelist gll
;
878 char hostname
[RG_MASKLEN
];
880 rg_initglinelist(&gll
);
882 for(j
=0;j
<NICKHASHSIZE
;j
++) {
883 for(np
=nicktable
[j
];np
;np
=np
->next
) {
884 if(IsOper(np
) || IsService(np
) || IsXOper(np
))
886 hostlen
= RGBuildHostname(hostname
, np
);
887 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
888 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
889 rg_dogline(&gll
, np
, rp
, hostname
);
896 rg_flushglines(&gll
);
899 void rg_freestruct(struct rg_struct
*rp
) {
900 freesstring(rp
->mask
);
901 freesstring(rp
->setby
);
902 freesstring(rp
->reason
);
903 pcre_free(rp
->regex
);
909 struct rg_struct
*rg_newstruct(time_t expires
) {
910 struct rg_struct
*rp
;
912 if (time(NULL
) >= expires
)
915 rp
= (struct rg_struct
*)malloc(sizeof(struct rg_struct
));
917 struct rg_struct
*tp
, *lp
;
919 memset(rp
, 0, sizeof(rg_struct
));
920 rp
->expires
= expires
;
922 for(lp
=NULL
,tp
=rg_list
;tp
;lp
=tp
,tp
=tp
->next
) {
923 if (expires
<= tp
->expires
) { /* <= possible, slight speed increase */
946 struct rg_struct
*rg_newsstruct(unsigned long id
, char *mask
, char *setby
, char *reason
, char *expires
, char *type
, time_t iexpires
, char *class, time_t lastseen
, unsigned int hitssaved
) {
947 struct rg_struct
*newrow
, *lp
, *cp
;
949 char glineiddata
[1024];
954 if(!protectedatoi(expires
, &qexpires
))
956 rexpires
= (time_t)qexpires
;
961 newrow
= rg_newstruct(rexpires
);
967 for(p
=classes
;*p
;p
++) {
968 if(!strcasecmp(class, *p
)) {
975 newrow
->class = "unknown";
977 if(!(newrow
->regex
= pcre_compile(mask
, RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
978 Error("regexgline", ERR_WARNING
, "Error compiling expression %s at offset %d: %s", mask
, erroroffset
, error
);
981 newrow
->hint
= pcre_study(newrow
->regex
, 0, &error
);
983 Error("regexgline", ERR_WARNING
, "Error studying expression %s: %s", mask
, error
);
984 pcre_free(newrow
->regex
);
990 newrow
->hitssaved
= hitssaved
;
991 newrow
->lastseen
= lastseen
;
993 newrow
->mask
= getsstring(mask
, RG_REGEXGLINE_MAX
);
995 Error("regexgline", ERR_WARNING
, "Error allocating memory for mask!");
999 newrow
->setby
= getsstring(setby
, ACCOUNTLEN
);
1000 if(!newrow
->setby
) {
1001 Error("regexgline", ERR_WARNING
, "Error allocating memory for setby!");
1005 newrow
->reason
= getsstring(reason
, RG_REASON_MAX
);
1006 if(!newrow
->reason
) {
1007 Error("regexgline", ERR_WARNING
, "Error allocating memory for reason!");
1011 if(!protectedatoi(type
, &newrow
->type
))
1012 newrow
->type
= 0; /* just in case */
1014 snprintf(glineiddata
, sizeof(glineiddata
), "%s regexgline %s %s %s %d %d", mynumeric
->content
, mask
, setby
, reason
, (int)iexpires
, newrow
->type
);
1015 newrow
->glineid
= crc32(glineiddata
);
1022 freesstring(newrow
->mask
);
1024 freesstring(newrow
->setby
);
1026 freesstring(newrow
->reason
);
1027 pcre_free(newrow
->regex
);
1029 pcre_free(newrow
->hint
);
1032 for(lp
=NULL
,cp
=rg_list
;cp
;lp
=cp
,cp
=cp
->next
) {
1035 lp
->next
= cp
->next
;
1046 int __rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
) { /* PPA: if multiple users match the same user@host or *@host it'll send multiple glines?! */
1047 char hostname
[RG_MASKLEN
];
1051 rg_loggline(rp
, np
);
1053 if (rp
->type
== INSTANT_HOST_GLINE
) {
1054 usercount
= np
->host
->clonecount
;
1055 snprintf(hostname
, sizeof(hostname
), "*@%s", IPtostr(np
->p_ipaddr
));
1058 if ((rp
->type
== INSTANT_IDENT_GLINE
) || (usercount
> rg_max_per_gline
)) {
1061 for(usercount
=0,tnp
=np
->host
->nicks
;tnp
;tnp
=tnp
->nextbyhost
)
1062 if(!ircd_strcmp(np
->ident
, tnp
->ident
))
1065 snprintf(hostname
, sizeof(hostname
), "%s@%s", np
->ident
, IPtostr(np
->p_ipaddr
));
1068 validdelay
= (rp
->type
== INSTANT_KILL
) || (rp
->type
== DELAYED_IDENT_GLINE
) || (rp
->type
== DELAYED_HOST_GLINE
) || (rp
->type
== DELAYED_KILL
);
1069 if (validdelay
|| (usercount
> rg_max_per_gline
)) {
1070 struct rg_glinenode
*nn
= (struct rg_glinenode
*)malloc(sizeof(struct rg_glinenode
));
1074 gll
->end
->next
= nn
;
1084 nn
->punish
= INSTANT_KILL
;
1086 nn
->punish
= rp
->type
;
1092 if (rp
->type
== INSTANT_IDENT_GLINE
) {
1093 if (IsAccount(np
)) {
1094 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched user@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1096 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched user@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1098 } else if(rp
->type
== INSTANT_HOST_GLINE
) {
1099 if (IsAccount(np
)) {
1100 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s/%s matched *@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1102 controlwall(NO_OPER
, NL_HITS
, "%s!%s@%s matched *@host gline regex %08lx (class: %s, hit %d user%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1108 rg_shadowserver(np
, rp
, rp
->type
);
1109 irc_send("%s GL * +%s %d %zu :AUTO: %s (ID: %08lx)\r\n", mynumeric
->content
, hostname
, rg_expiry_time
, time(NULL
), rp
->reason
->content
, rp
->glineid
);
1113 static int floodprotection
= 0;
1114 static int lastfloodspam
= 0;
1116 void rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
) {
1119 if(t
> floodprotection
) {
1120 floodprotection
= t
;
1121 } else if((floodprotection
- t
) / 8 > RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
) {
1122 if(t
> lastfloodspam
+ 3600) {
1123 channel
*cp
= findchannel("#twilightzone");
1125 controlchanmsg(cp
, "WARNING! REGEXGLINE DISABLED FOR AN HOUR DUE TO NETWORK WIDE LOOKING GLINE!: %d exceeded %d", (floodprotection
- t
) / 8, RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
);
1126 controlwall(NO_OPER
, NL_MANAGEMENT
, "WARNING! REGEXGLINE DISABLED FOR AN HOUR DUE TO NETWORK WIDE LOOKING GLINE!");
1128 floodprotection
= t
+ RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
* 3600 * 8;
1133 floodprotection
+=__rg_dogline(gll
, np
, rp
, matched
);
1136 void rg_logevent(nick
*np
, char *event
, char *details
, ...) {
1137 char eeevent
[RG_QUERY_BUF_SIZE
], eedetails
[RG_QUERY_BUF_SIZE
], eemask
[RG_QUERY_BUF_SIZE
], eeaccount
[RG_QUERY_BUF_SIZE
];
1138 char buf
[513], account
[ACCOUNTLEN
+ 1], mask
[RG_MASKLEN
];
1144 va_start(va
, details
);
1145 vsnprintf(buf
, sizeof(buf
), details
, va
);
1152 if (IsAccount(np
)) {
1153 strncpy(account
, np
->authname
, sizeof(account
) - 1);
1154 account
[sizeof(account
) - 1] = '\0';
1158 masklen
= RGBuildHostname(mask
, np
);
1164 dbescapestring(eeevent
, event
, strlen(event
));
1165 dbescapestring(eedetails
, buf
, strlen(buf
));
1166 dbescapestring(eeaccount
, account
, strlen(account
));
1167 dbescapestring(eemask
, mask
, masklen
);
1169 dbquery("INSERT INTO regexgline.clog (host, account, event, arg, ts) VALUES ('%s', '%s', '%s', '%s', NOW())", eemask
, eeaccount
, eeevent
, eedetails
);
1172 void rg_loggline(struct rg_struct
*rg
, nick
*np
) {
1173 char eenick
[RG_QUERY_BUF_SIZE
], eeuser
[RG_QUERY_BUF_SIZE
], eehost
[RG_QUERY_BUF_SIZE
], eereal
[RG_QUERY_BUF_SIZE
];
1177 rg
->lastseen
= time(NULL
);
1180 /* @paul: disabled */
1183 dbescapestring(eenick
, np
->nick
, strlen(np
->nick
));
1184 dbescapestring(eeuser
, np
->ident
, strlen(np
->ident
));
1185 dbescapestring(eehost
, np
->host
->name
->content
, strlen(np
->host
->name
->content
));
1186 dbescapestring(eereal
, np
->realname
->name
->content
, strlen(np
->realname
->name
->content
));
1188 dbquery("INSERT INTO regexgline.glog (glineid, nickname, username, hostname, realname, ts) VALUES (%d, '%s', '%s', '%s', '%s', NOW())", rg
->id
, eenick
, eeuser
, eehost
, eereal
);
1191 static unsigned int getrgmarker(void) {
1192 static unsigned int marker
= 0;
1196 struct rg_struct
*l
;
1198 /* If we wrapped to zero, zap the marker on all hosts */
1199 for(l
=rg_list
;l
;l
=l
->next
)
1207 void rg_flush_schedule(void *arg
) {
1208 struct rg_struct
*l
;
1210 for(l
=rg_list
;l
;l
=l
->next
) {
1214 dbquery("UPDATE regexgline.glines SET lastseen = %zu, hits = %lu WHERE id = %d", l
->lastseen
, l
->hitssaved
, l
->id
);