5 FUTURE: natural (sort of) language parsing
8 PPA: if multiple users match the same user@host or *@host it'll send multiple glines?!
11 #include "regexgline.h"
12 #include "../lib/version.h"
13 #include "../dbapi/dbapi.h"
14 #include "../lib/stringbuf.h"
15 #include "../core/hooks.h"
16 #include "../server/server.h"
17 #include "../lib/strlfunc.h"
20 #define INSTANT_IDENT_GLINE 1
21 #define INSTANT_HOST_GLINE 2
22 #define INSTANT_KILL 3
23 #define DELAYED_IDENT_GLINE 4
24 #define DELAYED_HOST_GLINE 5
25 #define DELAYED_KILL 6
27 MODULE_VERSION("1.43");
29 typedef struct rg_glinenode
{
31 struct rg_struct
*reason
;
33 struct rg_glinenode
*next
;
36 typedef struct rg_glinelist
{
37 struct rg_glinenode
*start
;
38 struct rg_glinenode
*end
;
41 typedef struct rg_delay
{
44 struct rg_struct
*reason
;
46 struct rg_delay
*next
;
49 #define GLINE_HEADER " ID Expires Set by Class Type Last seen (ago) Hits(p) Hits Reason"
53 void rg_setdelay(nick
*np
, struct rg_struct
*reason
, short punish
);
54 void rg_deletedelay(rg_delay
*delay
);
55 void rg_dodelay(void *arg
);
57 void rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
);
58 void rg_flush_schedule(void *arg
);
60 static char *gvhost(nick
*np
);
62 static DBModuleIdentifier dbid
;
63 static unsigned long highestid
= 0;
64 static int attached
= 0, started
= 0;
66 static unsigned int getrgmarker(void);
68 /* shadowserver only reports classes[0] */
69 static const char *classes
[] = { "drone", "proxy", "spam", "fakeauth", "other", (char *)0 };
72 sstring
*max_casualties
, *max_spew
, *expiry_time
, *max_per_gline
;
74 max_casualties
= getcopyconfigitem("regexgline", "maxcasualties", RGStringise(RG_MAX_CASUALTIES_DEFAULT
), 8);
75 if(!protectedatoi(max_casualties
->content
, &rg_max_casualties
))
76 rg_max_casualties
= RG_MAX_CASUALTIES_DEFAULT
;
78 freesstring(max_casualties
);
80 max_spew
= getcopyconfigitem("regexgline", "maxspew", RGStringise(RG_MAX_SPEW_DEFAULT
), 8);
81 if(!protectedatoi(max_spew
->content
, &rg_max_spew
))
82 rg_max_spew
= RG_MAX_SPEW_DEFAULT
;
84 freesstring(max_spew
);
86 expiry_time
= getcopyconfigitem("regexgline", "expirytime", RGStringise(RG_EXPIRY_TIME_DEFAULT
), 8);
87 if(!protectedatoi(expiry_time
->content
, &rg_expiry_time
))
88 rg_expiry_time
= RG_EXPIRY_TIME_DEFAULT
;
90 freesstring(expiry_time
);
92 max_per_gline
= getcopyconfigitem("regexgline", "maxpergline", RGStringise(RG_MAX_PER_GLINE_DEFAULT
), 8);
93 if(!protectedatoi(max_per_gline
->content
, &rg_max_per_gline
))
94 rg_max_per_gline
= RG_MAX_PER_GLINE_DEFAULT
;
96 freesstring(max_per_gline
);
105 Error("regexgline", ERR_STOP
, "Could not connect to database.");
110 struct rg_struct
*gp
= rg_list
, *oldgp
;
111 rg_delay
*delay
, *delaynext
;
114 deregisterhook(HOOK_NICK_NEWNICK
, &rg_nick
);
115 deregisterhook(HOOK_NICK_RENAME
, &rg_nick
);
116 deregisterhook(HOOK_NICK_LOSTNICK
, &rg_lostnick
);
117 deregistercontrolcmd("regexspew", rg_spew
);
118 deregistercontrolcmd("regexglist", rg_glist
);
119 deregistercontrolcmd("regexdelgline", rg_delgline
);
120 deregistercontrolcmd("regexgline", rg_gline
);
121 deregistercontrolcmd("regexidlookup", rg_idlist
);
125 for(delay
=rg_delays
;delay
;delay
=delaynext
) {
126 delaynext
=delay
->next
;
127 deleteschedule(delay
->sch
, rg_dodelay
, delay
);
133 deleteschedule(rg_schedule
, &rg_checkexpiry
, NULL
);
137 deleteallschedules(rg_flush_schedule
);
138 rg_flush_schedule(NULL
);
140 for(gp
=rg_list
;gp
;) {
143 rg_freestruct(oldgp
);
147 dbdetach("regexgline");
152 static int ignorable_nick(nick
*np
) {
153 if(IsOper(np
) || IsService(np
) || IsXOper(np
) || SIsService(&serverlist
[homeserver(np
->numeric
)]))
158 void rg_checkexpiry(void *arg
) {
159 struct rg_struct
*rp
= rg_list
, *lp
= NULL
;
160 time_t current
= time(NULL
);
163 if (current
>= rp
->expires
) {
164 dbquery("DELETE FROM regexglines WHERE id = %d", rp
->id
);
181 void rg_setdelay(nick
*np
, rg_struct
*reason
, short punish
) {
183 delay
= (rg_delay
*)malloc(sizeof(rg_delay
));
187 killuser(NULL
, np
, "%s (ID: %08lx)", reason
->reason
->content
, reason
->glineid
);
192 delay
->reason
= reason
;
193 delay
->punish
= punish
;
194 delay
->next
= rg_delays
;
197 delay
->sch
= scheduleoneshot(time(NULL
) + (RG_MINIMUM_DELAY_TIME
+ (rand() % RG_MAXIMUM_RAND_TIME
)), rg_dodelay
, delay
);
200 static void rg_shadowserver(nick
*np
, struct rg_struct
*reason
, int type
) {
203 if(reason
->class != classes
[0]) /* drone */
206 snprintf(buf
, sizeof(buf
), "regex-ban %lu %s!%s@%s %s %s", time(NULL
), np
->nick
, np
->ident
, np
->host
->name
->content
, reason
->mask
->content
, serverlist
[homeserver(np
->numeric
)].name
->content
);
208 triggerhook(HOOK_SHADOW_SERVER
, (void *)buf
);
211 void rg_deletedelay(rg_delay
*delay
) {
212 rg_delay
*temp
, *prev
;
214 for (temp
=rg_delays
;temp
;temp
=temp
->next
) {
217 rg_delays
= temp
->next
;
219 prev
->next
= temp
->next
;
229 void rg_dodelay(void *arg
) {
230 rg_delay
*delay
= (rg_delay
*)arg
;
231 char hostname
[RG_MASKLEN
];
232 int hostlen
, usercount
= 0;
234 /* User or regex gline no longer exists */
235 if((!delay
->np
) || (!delay
->reason
)) {
236 rg_deletedelay(delay
);
240 hostlen
= RGBuildHostname(hostname
, delay
->np
);
242 /* User has wisely changed nicknames */
243 if(pcre_exec(delay
->reason
->regex
, delay
->reason
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) < 0) {
244 rg_deletedelay(delay
);
248 if (delay
->reason
->type
== DELAYED_HOST_GLINE
) {
249 usercount
= delay
->np
->host
->clonecount
;
250 snprintf(hostname
, sizeof(hostname
), "*@%s", IPtostr(delay
->np
->p_ipaddr
));
253 if((delay
->reason
->type
== DELAYED_IDENT_GLINE
) || (usercount
> rg_max_per_gline
)) {
256 for(usercount
=0,tnp
=delay
->np
->host
->nicks
;tnp
;tnp
=tnp
->nextbyhost
)
257 if(!ircd_strcmp(delay
->np
->ident
, tnp
->ident
))
260 snprintf(hostname
, sizeof(hostname
), "%s@%s", delay
->np
->ident
, IPtostr(delay
->np
->p_ipaddr
));
263 if ((delay
->reason
->type
== DELAYED_KILL
) || (usercount
> rg_max_per_gline
)) {
264 controlwall(NO_OPER
, NL_HITS
, "%s matched delayed kill regex %08lx (class: %s)", gvhost(delay
->np
), delay
->reason
->glineid
, delay
->reason
->class);
266 rg_shadowserver(delay
->np
, delay
->reason
, DELAYED_KILL
);
267 killuser(NULL
, delay
->np
, "%s (ID: %08lx)", delay
->reason
->reason
->content
, delay
->reason
->glineid
);
271 if (delay
->reason
->type
== DELAYED_IDENT_GLINE
) {
272 controlwall(NO_OPER
, NL_HITS
, "%s matched delayed user@host gline regex %08lx (class: %s, hit %d user%s)", gvhost(delay
->np
), delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
273 } else if (delay
->reason
->type
== DELAYED_HOST_GLINE
) {
274 controlwall(NO_OPER
, NL_HITS
, "%s matched delayed *@host gline regex %08lx (class: %s, hit %d user%s)", gvhost(delay
->np
), delay
->reason
->glineid
, delay
->reason
->class, usercount
, (usercount
!=1)?"s":"");
279 rg_shadowserver(delay
->np
, delay
->reason
, delay
->reason
->type
);
280 irc_send("%s GL * +%s %d %jd :AUTO: %s (ID: %08lx)\r\n", mynumeric
->content
, hostname
, rg_expiry_time
, (intmax_t)time(NULL
), delay
->reason
->reason
->content
, delay
->reason
->glineid
);
281 rg_deletedelay(delay
);
284 void rg_initglinelist(struct rg_glinelist
*gll
) {
289 void rg_flushglines(struct rg_glinelist
*gll
) {
290 struct rg_glinenode
*nn
, *pn
;
291 for(nn
=gll
->start
;nn
;nn
=pn
) {
293 if(nn
->punish
== INSTANT_KILL
) {
294 controlwall(NO_OPER
, NL_HITS
, "%s matched kill regex %08lx (class: %s)", gvhost(nn
->np
), nn
->reason
->glineid
, nn
->reason
->class);
296 rg_shadowserver(nn
->np
, nn
->reason
, nn
->punish
);
297 killuser(NULL
, nn
->np
, "%s (ID: %08lx)", nn
->reason
->reason
->content
, nn
->reason
->glineid
);
298 } else if ((nn
->punish
== DELAYED_IDENT_GLINE
) || (nn
->punish
== DELAYED_HOST_GLINE
) || (nn
->punish
== DELAYED_KILL
)) {
299 rg_setdelay(nn
->np
, nn
->reason
, nn
->punish
);
304 rg_initglinelist(gll
);
307 static void dbloaddata(DBConn
*dbconn
, void *arg
) {
308 DBResult
*dbres
= dbgetresult(dbconn
);
310 if(!dbquerysuccessful(dbres
)) {
311 Error("chanserv", ERR_ERROR
, "Error loading DB");
315 if (dbnumfields(dbres
) != 9) {
316 Error("regexgline", ERR_ERROR
, "DB format error");
320 while(dbfetchrow(dbres
)) {
321 unsigned long id
, hitssaved
;
323 char *gline
, *setby
, *reason
, *expires
, *type
, *class;
325 id
= strtoul(dbgetvalue(dbres
, 0), NULL
, 10);
329 gline
= dbgetvalue(dbres
, 1);
330 setby
= dbgetvalue(dbres
, 2);
331 reason
= dbgetvalue(dbres
, 3);
332 expires
= dbgetvalue(dbres
, 4);
333 type
= dbgetvalue(dbres
, 5);
334 class = dbgetvalue(dbres
, 6);
336 lastseen
= strtoul(dbgetvalue(dbres
, 7), NULL
, 10);
337 hitssaved
= strtoul(dbgetvalue(dbres
, 8), NULL
, 10);
339 if (!rg_newsstruct(id
, gline
, setby
, reason
, expires
, type
, 0, class, lastseen
, hitssaved
))
340 dbquery("DELETE FROM regexgline.glines WHERE id = %lu", id
);
346 static void dbloadfini(DBConn
*dbconn
, void *arg
) {
350 char helpbuf
[8192 * 2], allclasses
[8192];
352 sbinit(&b
, (char *)allclasses
, sizeof(allclasses
));
353 for(p
=classes
;*p
;p
++) {
354 sbaddstr(&b
, (char *)*p
);
359 snprintf(helpbuf
, sizeof(helpbuf
),
360 "Usage: regexgline <regex> <duration> <type> <class> <reason>\n"
361 "Adds a new regular expression pattern.\n"
362 "Duration is represented as 3d, 3M etc.\n"
363 "Class is one of the following: %s\n"
364 "Type is an integer which represents the following:\n"
365 "1 - Instant USER@IP GLINE (igu)\n"
366 "2 - Instant *@IP GLINE (igh)\n"
367 "3 - Instant KILL (ik)\n"
368 "4 - Delayed USER@IP GLINE (dgu)\n"
369 "5 - Delayed *@IP GLINE (dgh)\n"
370 "6 - Delayed KILL (dk)",
373 registercontrolhelpcmd("regexgline", NO_OPER
, 5, &rg_gline
, helpbuf
);
374 registercontrolhelpcmd("regexdelgline", NO_OPER
, 1, &rg_delgline
, "Usage: regexdelgline <pattern>\nDeletes a regular expression pattern.");
375 registercontrolhelpcmd("regexglist", NO_OPER
, 1, &rg_glist
, "Usage: regexglist <pattern>\nLists regular expression patterns.");
376 registercontrolhelpcmd("regexspew", NO_OPER
, 1, &rg_spew
, "Usage: regexspew <pattern>\nLists users currently on the network which match the given pattern.");
377 registercontrolhelpcmd("regexidlookup", NO_OPER
, 1, &rg_idlist
, "Usage: regexidlookup <id>\nFinds a regular expression pattern by it's ID number.");
379 registerhook(HOOK_NICK_NEWNICK
, &rg_nick
);
380 registerhook(HOOK_NICK_RENAME
, &rg_nick
);
381 registerhook(HOOK_NICK_LOSTNICK
, &rg_lostnick
);
384 rg_schedule
= schedulerecurring(time(NULL
) + 1, 0, 1, rg_checkexpiry
, NULL
);
385 schedulerecurring(time(NULL
) + 60, 0, 60, rg_flush_schedule
, NULL
);
388 void rg_dbload(void) {
389 dbattach("regexgline");
390 dbcreatequery("CREATE TABLE regexgline.glines (id INT NOT NULL PRIMARY KEY, gline TEXT NOT NULL, setby VARCHAR(%d) NOT NULL, reason VARCHAR(%d) NOT NULL, expires INT NOT NULL, type INT NOT NULL DEFAULT 1, class TEXT NOT NULL, lastseen INT DEFAULT 0, hits INT DEFAULT 0)", ACCOUNTLEN
, RG_REASON_MAX
);
391 dbcreatequery("CREATE TABLE regexgline.clog (host VARCHAR(%d) NOT NULL, account VARCHAR(%d) NOT NULL, event TEXT NOT NULL, arg TEXT NOT NULL, ts TIMESTAMP)", RG_MASKLEN
- 1, ACCOUNTLEN
);
392 dbcreatequery("CREATE TABLE regexgline.glog (glineid INT NOT NULL, ts TIMESTAMP, nickname VARCHAR(%d) NOT NULL, username VARCHAR(%d) NOT NULL, hostname VARCHAR(%d) NOT NULL, realname VARCHAR(%d))", NICKLEN
, USERLEN
, HOSTLEN
, REALLEN
);
394 dbloadtable("regexgline.glines", NULL
, dbloaddata
, dbloadfini
);
397 void rg_nick(int hooknum
, void *arg
) {
398 nick
*np
= (nick
*)arg
;
399 struct rg_struct
*rp
;
400 char hostname
[RG_MASKLEN
];
402 struct rg_glinelist gll
;
404 rg_initglinelist(&gll
);
406 hostlen
= RGBuildHostname(hostname
, np
);
408 if(ignorable_nick(np
))
411 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
412 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
413 rg_dogline(&gll
, np
, rp
, hostname
);
418 rg_flushglines(&gll
);
421 void rg_lostnick(int hooknum
, void *arg
) {
422 nick
*np
= (nick
*)arg
;
425 /* Cleanup the delays */
426 for(delay
=rg_delays
;delay
;delay
=delay
->next
)
431 int rg_gline(void *source
, int cargc
, char **cargv
) {
432 nick
*np
= (nick
*)source
, *tnp
;
434 const char *expirybuf
;
435 int expiry
, count
, j
, hostlen
;
436 struct rg_struct
*rp
;
437 struct rg_glinelist gll
;
440 char eemask
[RG_QUERY_BUF_SIZE
], eesetby
[RG_QUERY_BUF_SIZE
], eereason
[RG_QUERY_BUF_SIZE
], eeclass
[RG_QUERY_BUF_SIZE
];
441 char hostname
[RG_MASKLEN
], *class, *reason
, *regex
, type
;
447 if ((strlen(cargv
[2]) != 1) || ((type
!= '1') && (type
!= '2') && (type
!= '3') && (type
!= '4') && (type
!= '5') && (type
!= '6'))) {
448 controlreply(np
, "Invalid type specified!");
456 for(p
=classes
;*p
;p
++)
457 if(!strcasecmp(class, *p
))
461 controlreply(np
, "Bad class supplied.");
465 if (!(expiry
= durationtolong(cargv
[1]))) {
466 controlreply(np
, "Invalid duration specified!");
470 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
471 if (RGMasksEqual(rp
->mask
->content
, regex
)) {
472 controlreply(np
, "That regexgline already exists!");
477 if (rg_sanitycheck(regex
, &count
)) {
478 controlreply(np
, "Error in expression.");
480 } else if (count
< 0) {
481 controlreply(np
, "That expression would hit too many users (%d)!", -count
);
485 realexpiry
= expiry
+ time(NULL
);
487 dbescapestring(eemask
, regex
, strlen(regex
));
488 dbescapestring(eesetby
, np
->nick
, strlen(np
->nick
));
489 dbescapestring(eeclass
, class, strlen(class));
490 dbescapestring(eereason
, reason
, strlen(reason
));
492 highestid
= highestid
+ 1;
493 dbquery("INSERT INTO regexgline.glines (id, gline, setby, reason, expires, type, class, lastseen, hits) VALUES (%lu, '%s', '%s', '%s', %lu, %c, '%s', 0, 0)", highestid
, eemask
, eesetby
, eereason
, realexpiry
, type
, eeclass
);
494 rp
= rg_newsstruct(highestid
, regex
, np
->nick
, reason
, "", cargv
[2], realexpiry
, class, 0, 0);
496 rg_initglinelist(&gll
);
498 for(j
=0;j
<NICKHASHSIZE
;j
++) {
499 for(tnp
=nicktable
[j
];tnp
;tnp
=tnp
->next
) {
500 if(ignorable_nick(tnp
))
503 hostlen
= RGBuildHostname(hostname
, tnp
);
504 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0)
505 rg_dogline(&gll
, tnp
, rp
, hostname
);
509 rg_flushglines(&gll
);
511 expirybuf
= longtoduration(expiry
, 0);
513 rg_logevent(np
, "regexgline", "%s %d %d %s %s", regex
, expiry
, count
, class, reason
);
514 controlreply(np
, "Added regexgline: %s (class: %s, expires in: %s, hit %d user%s): %s", regex
, class, expirybuf
, count
, (count
!=1)?"s":"", reason
);
515 /* If we are using NO, can we safely assume the user is authed here and use ->authname? */
516 controlwall(NO_OPER
, NL_GLINES
, "%s!%s@%s/%s added regexgline: %s (class: %s, expires in: %s, hit %d user%s): %s", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, regex
, class, expirybuf
, count
, (count
!=1)?"s":"", reason
);
521 int rg_sanitycheck(char *mask
, int *count
) {
523 char hostname
[RG_MASKLEN
];
524 int erroroffset
, hostlen
, j
, masklen
= strlen(mask
);
529 if((masklen
< RG_MIN_MASK_LEN
) || (masklen
> RG_REGEXGLINE_MAX
))
532 if(!(regex
= pcre_compile(mask
, RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
533 Error("regexgline", ERR_WARNING
, "Error compiling expression %s at offset %d: %s", mask
, erroroffset
, error
);
536 hint
= pcre_study(regex
, 0, &error
);
538 Error("regexgline", ERR_WARNING
, "Error studying expression %s: %s", mask
, error
);
545 for(j
=0;j
<NICKHASHSIZE
;j
++) {
546 for(np
=nicktable
[j
];np
;np
=np
->next
) {
547 hostlen
= RGBuildHostname(hostname
, np
);
548 if(pcre_exec(regex
, hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
558 if(*count
>= rg_max_casualties
)
564 int rg_delgline(void *source
, int cargc
, char **cargv
) {
565 nick
*np
= (nick
*)source
;
567 struct rg_struct
*rp
= rg_list
, *last
= NULL
;
573 rg_logevent(np
, "regexdelgline", "%s", cargv
[0]);
575 if(RGMasksEqual(rp
->mask
->content
, cargv
[0])) {
578 /* Cleanup the delays */
579 for(delay
=rg_delays
;delay
;delay
=delay
->next
)
580 if(delay
->reason
==rp
)
581 delay
->reason
= NULL
;
583 dbquery("DELETE FROM regexgline.glines WHERE id = %d", rp
->id
);
585 last
->next
= rp
->next
;
599 controlreply(np
, "Deleted (matched: %d).", count
);
600 /* If we are using NO, can we safely assume the user is authed here and use ->authname? */
601 controlwall(NO_OPER
, NL_GLINES
, "%s!%s@%s/%s removed regexgline: %s", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, cargv
[0]);
603 controlreply(np
, "No glines matched: %s", cargv
[0]);
608 int rg_idlist(void *source
, int cargc
, char **cargv
) {
609 nick
*np
= (nick
*)source
;
613 } else if (strlen(cargv
[0]) != 8) {
614 controlreply(np
, "Invalid gline id!");
617 struct rg_struct
*rp
;
618 unsigned long id
= 0;
623 if(0xff == rc_hexlookup
[(int)cargv
[0][i
]]) {
624 controlreply(np
, "Invalid gline id!");
627 id
= (id
<< 4) | rc_hexlookup
[(int)cargv
[0][i
]];
632 controlreply(np
, GLINE_HEADER
);
633 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
634 if(id
== rp
->glineid
) {
636 if(rp
->mask
->length
> longest
)
637 longest
= rp
->mask
->length
;
641 for(rp
=rg_list
;rp
;rp
=rp
->next
)
643 rg_displaygline(np
, rp
, longest
);
644 controlreply(np
, "Done.");
650 int rg_glist(void *source
, int cargc
, char **cargv
) {
651 nick
*np
= (nick
*)source
;
652 struct rg_struct
*rp
;
662 if(!(regex
= pcre_compile(cargv
[0], RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
663 controlreply(np
, "Error compiling expression %s at offset %d: %s", cargv
[0], erroroffset
, error
);
666 hint
= pcre_study(regex
, 0, &error
);
668 controlreply(np
, "Error studying expression %s: %s", cargv
[0], error
);
675 rg_logevent(np
, "regexglist", "%s", cargv
[0]);
676 controlreply(np
, GLINE_HEADER
);
677 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
678 if(pcre_exec(regex
, hint
, rp
->mask
->content
, rp
->mask
->length
, 0, 0, NULL
, 0) >= 0) {
680 if(rp
->mask
->length
> longest
)
681 longest
= rp
->mask
->length
;
685 for(rp
=rg_list
;rp
;rp
=rp
->next
)
687 rg_displaygline(np
, rp
, longest
);
694 rg_logevent(np
, "regexglist", "%s", "");
695 controlreply(np
, GLINE_HEADER
);
696 for(rp
=rg_list
;rp
;rp
=rp
->next
)
697 if(rp
->mask
->length
> longest
)
698 longest
= rp
->mask
->length
;
700 for(rp
=rg_list
;rp
;rp
=rp
->next
)
701 rg_displaygline(np
, rp
, longest
);
704 controlreply(np
, "Done.");
708 char *displaytype(int type
) {
710 static char ctypebuf
[10];
735 snprintf(ctypebuf
, sizeof(ctype
), "%1d:%s", type
, ctype
);
739 char *getsep(int longest
) {
740 static int lastlongest
= -1;
741 static char lenbuf
[1024];
748 if(longest >= sizeof(lenbuf) - 20)
749 longest = sizeof(lenbuf) - 20;
752 if(lastlongest
== -1) {
755 for(i
=0;i
<sizeof(lenbuf
)-1;i
++)
757 lenbuf
[sizeof(lenbuf
)-1] = '\0';
761 if(lastlongest
!= longest
) {
762 lenbuf
[lastlongest
] = '-';
763 lenbuf
[longest
] = '\0';
764 lastlongest
= longest
;
770 void rg_displaygline(nick
*np
, struct rg_struct
*rp
, int longest
) { /* could be a macro? I'll assume the C compiler inlines it */
771 char *sep
= getsep(longest
);
772 /* 12345678 12345678901234567890 123456789012345 12345678 12345 12345678901234567890 1234567 1234567 123456
773 ID Expires Set by Class Type Last seen (ago) Hits(s) Hits Reason
777 time_t t
= time(NULL
);
779 if(rp
->lastseen
== 0) {
780 strlcpy(d
, "(never)", sizeof(d
));
782 strlcpy(d
, longtoduration(t
- rp
->lastseen
, 2), sizeof(d
));
785 controlreply(np
, "%s", rp
->mask
->content
);
786 controlreply(np
, " %08lx %-20s %-15s %-8s %-5s %-20s %-7lu %-7lu %s", rp
->glineid
, longtoduration(rp
->expires
- t
, 2), rp
->setby
->content
, rp
->class, displaytype(rp
->type
), d
, rp
->hitssaved
, rp
->hits
, rp
->reason
->content
);
787 controlreply(np
, "%s", sep
);
790 int rg_spew(void *source
, int cargc
, char **cargv
) {
791 nick
*np
= (nick
*)source
, *tnp
;
792 int counter
= 0, erroroffset
, hostlen
, j
;
796 char hostname
[RG_MASKLEN
];
803 if(!(regex
= pcre_compile(cargv
[0], RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
804 controlreply(np
, "Error compiling expression %s at offset %d: %s", cargv
[0], erroroffset
, error
);
807 hint
= pcre_study(regex
, 0, &error
);
809 controlreply(np
, "Error studying expression %s: %s", cargv
[0], error
);
815 rg_logevent(np
, "regexspew", "%s", cargv
[0]);
817 for(j
=0;j
<NICKHASHSIZE
;j
++) {
818 for(tnp
=nicktable
[j
];tnp
;tnp
=tnp
->next
) {
819 hostlen
= RGBuildHostname(hostname
, tnp
);
820 pcreret
= pcre_exec(regex
, hint
, hostname
, hostlen
, 0, 0, ovector
, sizeof(ovector
) / sizeof(int));
822 if(counter
== rg_max_spew
) {
823 controlreply(np
, "Reached maximum spew count (%d) - aborting display.", rg_max_spew
);
824 } else if (counter
< rg_max_spew
) {
825 /* 15 should be number of bolds */
826 char boldbuf
[RG_MASKLEN
+ 15], *tp
, *fp
, *realname
= NULL
;
828 for(tp
=hostname
,fp
=boldbuf
;*tp
;) {
829 if(tp
- hostname
== ovector
[0]) {
833 if(tp
- hostname
== ovector
[1]) {
852 controlreply(np
, "%s (%s) (%dc)", boldbuf
, realname
, tnp
->channels
->cursi
);
858 controlreply(np
, "Done - %d matches.", counter
);
867 void rg_startup(void) {
870 struct rg_struct
*rp
;
871 struct rg_glinelist gll
;
872 char hostname
[RG_MASKLEN
];
874 rg_initglinelist(&gll
);
876 for(j
=0;j
<NICKHASHSIZE
;j
++) {
877 for(np
=nicktable
[j
];np
;np
=np
->next
) {
878 if(ignorable_nick(np
))
880 hostlen
= RGBuildHostname(hostname
, np
);
881 for(rp
=rg_list
;rp
;rp
=rp
->next
) {
882 if(pcre_exec(rp
->regex
, rp
->hint
, hostname
, hostlen
, 0, 0, NULL
, 0) >= 0) {
883 rg_dogline(&gll
, np
, rp
, hostname
);
890 rg_flushglines(&gll
);
893 void rg_freestruct(struct rg_struct
*rp
) {
894 freesstring(rp
->mask
);
895 freesstring(rp
->setby
);
896 freesstring(rp
->reason
);
897 pcre_free(rp
->regex
);
903 struct rg_struct
*rg_newstruct(time_t expires
) {
904 struct rg_struct
*rp
;
906 if (time(NULL
) >= expires
)
909 rp
= (struct rg_struct
*)malloc(sizeof(struct rg_struct
));
911 struct rg_struct
*tp
, *lp
;
913 memset(rp
, 0, sizeof(rg_struct
));
914 rp
->expires
= expires
;
916 for(lp
=NULL
,tp
=rg_list
;tp
;lp
=tp
,tp
=tp
->next
) {
917 if (expires
<= tp
->expires
) { /* <= possible, slight speed increase */
940 struct rg_struct
*rg_newsstruct(unsigned long id
, char *mask
, char *setby
, char *reason
, char *expires
, char *type
, time_t iexpires
, char *class, time_t lastseen
, unsigned int hitssaved
) {
941 struct rg_struct
*newrow
, *lp
, *cp
;
943 char glineiddata
[1024];
948 if(!protectedatoi(expires
, &qexpires
))
950 rexpires
= (time_t)qexpires
;
955 newrow
= rg_newstruct(rexpires
);
961 for(p
=classes
;*p
;p
++) {
962 if(!strcasecmp(class, *p
)) {
969 newrow
->class = "unknown";
971 if(!(newrow
->regex
= pcre_compile(mask
, RG_PCREFLAGS
, &error
, &erroroffset
, NULL
))) {
972 Error("regexgline", ERR_WARNING
, "Error compiling expression %s at offset %d: %s", mask
, erroroffset
, error
);
975 newrow
->hint
= pcre_study(newrow
->regex
, 0, &error
);
977 Error("regexgline", ERR_WARNING
, "Error studying expression %s: %s", mask
, error
);
978 pcre_free(newrow
->regex
);
984 newrow
->hitssaved
= hitssaved
;
985 newrow
->lastseen
= lastseen
;
987 newrow
->mask
= getsstring(mask
, RG_REGEXGLINE_MAX
);
989 Error("regexgline", ERR_WARNING
, "Error allocating memory for mask!");
993 newrow
->setby
= getsstring(setby
, ACCOUNTLEN
);
995 Error("regexgline", ERR_WARNING
, "Error allocating memory for setby!");
999 newrow
->reason
= getsstring(reason
, RG_REASON_MAX
);
1000 if(!newrow
->reason
) {
1001 Error("regexgline", ERR_WARNING
, "Error allocating memory for reason!");
1005 if(!protectedatoi(type
, &newrow
->type
))
1006 newrow
->type
= 0; /* just in case */
1008 snprintf(glineiddata
, sizeof(glineiddata
), "%s regexgline %s %s %s %d %d", mynumeric
->content
, mask
, setby
, reason
, (int)iexpires
, newrow
->type
);
1009 newrow
->glineid
= crc32(glineiddata
);
1016 freesstring(newrow
->mask
);
1018 freesstring(newrow
->setby
);
1020 freesstring(newrow
->reason
);
1021 pcre_free(newrow
->regex
);
1023 pcre_free(newrow
->hint
);
1026 for(lp
=NULL
,cp
=rg_list
;cp
;lp
=cp
,cp
=cp
->next
) {
1029 lp
->next
= cp
->next
;
1040 int __rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
) { /* PPA: if multiple users match the same user@host or *@host it'll send multiple glines?! */
1041 char hostname
[RG_MASKLEN
];
1045 rg_loggline(rp
, np
);
1047 if (rp
->type
== INSTANT_HOST_GLINE
) {
1048 usercount
= np
->host
->clonecount
;
1049 snprintf(hostname
, sizeof(hostname
), "*@%s", IPtostr(np
->p_ipaddr
));
1052 if ((rp
->type
== INSTANT_IDENT_GLINE
) || (usercount
> rg_max_per_gline
)) {
1055 for(usercount
=0,tnp
=np
->host
->nicks
;tnp
;tnp
=tnp
->nextbyhost
)
1056 if(!ircd_strcmp(np
->ident
, tnp
->ident
))
1059 snprintf(hostname
, sizeof(hostname
), "%s@%s", np
->ident
, IPtostr(np
->p_ipaddr
));
1062 validdelay
= (rp
->type
== INSTANT_KILL
) || (rp
->type
== DELAYED_IDENT_GLINE
) || (rp
->type
== DELAYED_HOST_GLINE
) || (rp
->type
== DELAYED_KILL
);
1063 if (validdelay
|| (usercount
> rg_max_per_gline
)) {
1064 struct rg_glinenode
*nn
= (struct rg_glinenode
*)malloc(sizeof(struct rg_glinenode
));
1068 gll
->end
->next
= nn
;
1078 nn
->punish
= INSTANT_KILL
;
1080 nn
->punish
= rp
->type
;
1086 if (rp
->type
== INSTANT_IDENT_GLINE
) {
1087 controlwall(NO_OPER
, NL_HITS
, "%s matched user@host gline regex %08lx (class: %s, hit %d user%s)", gvhost(np
), rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1088 } else if(rp
->type
== INSTANT_HOST_GLINE
) {
1089 controlwall(NO_OPER
, NL_HITS
, "%s matched *@host gline regex %08lx (class: %s, hit %d user%s)", gvhost(np
), rp
->glineid
, rp
->class, usercount
, (usercount
!=1)?"s":"");
1094 rg_shadowserver(np
, rp
, rp
->type
);
1095 irc_send("%s GL * +%s %d %jd :AUTO: %s (ID: %08lx)\r\n", mynumeric
->content
, hostname
, rg_expiry_time
, (intmax_t)time(NULL
), rp
->reason
->content
, rp
->glineid
);
1099 static char *gvhost(nick
*np
) {
1100 static char buf
[NICKLEN
+1+USERLEN
+1+HOSTLEN
+1+ACCOUNTLEN
+4+REALLEN
+1+10];
1103 snprintf(buf
, sizeof(buf
), "%s!%s@%s/%s r(%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->authname
, np
->realname
->name
->content
);
1105 snprintf(buf
, sizeof(buf
), "%s!%s@%s r(%s)", np
->nick
, np
->ident
, np
->host
->name
->content
, np
->realname
->name
->content
);
1111 static int floodprotection
= 0;
1112 static int lastfloodspam
= 0;
1114 void rg_dogline(struct rg_glinelist
*gll
, nick
*np
, struct rg_struct
*rp
, char *matched
) {
1117 if(t
> floodprotection
) {
1118 floodprotection
= t
;
1119 } else if((floodprotection
- t
) / 8 > RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
) {
1120 if(t
> lastfloodspam
+ 3600) {
1121 channel
*cp
= findchannel("#twilightzone");
1123 controlchanmsg(cp
, "WARNING! REGEXGLINE DISABLED FOR AN HOUR DUE TO NETWORK WIDE LOOKING GLINE!: %d exceeded %d", (floodprotection
- t
) / 8, RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
);
1124 controlwall(NO_OPER
, NL_MANAGEMENT
, "WARNING! REGEXGLINE DISABLED FOR AN HOUR DUE TO NETWORK WIDE LOOKING GLINE!");
1126 floodprotection
= t
+ RG_NETWORK_WIDE_MAX_GLINES_PER_8_SEC
* 3600 * 8;
1131 floodprotection
+=__rg_dogline(gll
, np
, rp
, matched
);
1134 void rg_logevent(nick
*np
, char *event
, char *details
, ...) {
1135 char eeevent
[RG_QUERY_BUF_SIZE
], eedetails
[RG_QUERY_BUF_SIZE
], eemask
[RG_QUERY_BUF_SIZE
], eeaccount
[RG_QUERY_BUF_SIZE
];
1136 char buf
[513], account
[ACCOUNTLEN
+ 1], mask
[RG_MASKLEN
];
1142 va_start(va
, details
);
1143 vsnprintf(buf
, sizeof(buf
), details
, va
);
1150 if (IsAccount(np
)) {
1151 strncpy(account
, np
->authname
, sizeof(account
) - 1);
1152 account
[sizeof(account
) - 1] = '\0';
1156 masklen
= RGBuildHostname(mask
, np
);
1162 dbescapestring(eeevent
, event
, strlen(event
));
1163 dbescapestring(eedetails
, buf
, strlen(buf
));
1164 dbescapestring(eeaccount
, account
, strlen(account
));
1165 dbescapestring(eemask
, mask
, masklen
);
1167 dbquery("INSERT INTO regexgline.clog (host, account, event, arg, ts) VALUES ('%s', '%s', '%s', '%s', NOW())", eemask
, eeaccount
, eeevent
, eedetails
);
1170 void rg_loggline(struct rg_struct
*rg
, nick
*np
) {
1171 char eenick
[RG_QUERY_BUF_SIZE
], eeuser
[RG_QUERY_BUF_SIZE
], eehost
[RG_QUERY_BUF_SIZE
], eereal
[RG_QUERY_BUF_SIZE
];
1175 rg
->lastseen
= time(NULL
);
1178 /* @paul: disabled */
1181 dbescapestring(eenick
, np
->nick
, strlen(np
->nick
));
1182 dbescapestring(eeuser
, np
->ident
, strlen(np
->ident
));
1183 dbescapestring(eehost
, np
->host
->name
->content
, strlen(np
->host
->name
->content
));
1184 dbescapestring(eereal
, np
->realname
->name
->content
, strlen(np
->realname
->name
->content
));
1186 dbquery("INSERT INTO regexgline.glog (glineid, nickname, username, hostname, realname, ts) VALUES (%d, '%s', '%s', '%s', '%s', NOW())", rg
->id
, eenick
, eeuser
, eehost
, eereal
);
1189 static unsigned int getrgmarker(void) {
1190 static unsigned int marker
= 0;
1194 struct rg_struct
*l
;
1196 /* If we wrapped to zero, zap the marker on all hosts */
1197 for(l
=rg_list
;l
;l
=l
->next
)
1205 void rg_flush_schedule(void *arg
) {
1206 struct rg_struct
*l
;
1208 for(l
=rg_list
;l
;l
=l
->next
) {
1212 dbquery("UPDATE regexgline.glines SET lastseen = %jd, hits = %lu WHERE id = %d", (intmax_t)l
->lastseen
, l
->hitssaved
, l
->id
);