2 * ngIRCd -- The Next Generation IRC Daemon
3 * Copyright (c)2001-2013 Alexander Barton (alex@barton.de) and Contributors.
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
9 * Please read the file COPYING, README and AUTHORS for more information.
16 * IRC command parser and validator.
28 #include "conn-func.h"
40 #include "irc-channel.h"
41 #include "irc-encoding.h"
43 #include "irc-login.h"
44 #include "irc-metadata.h"
48 #include "irc-server.h"
49 #include "irc-write.h"
57 bool (*function) PARAMS(( CLIENT *Client, REQUEST *Request ));
61 static COMMAND My_Commands[] =
63 #define _CMD(name, func, type, min, max, penalty) \
64 { (name), (func), (type), (min), (max), (penalty), 0, 0, 0 }
65 _CMD("ADMIN", IRC_ADMIN, CLIENT_USER|CLIENT_SERVER, 0, 1, 1),
66 _CMD("AWAY", IRC_AWAY, CLIENT_USER, 0, 1, 0),
67 _CMD("CAP", IRC_CAP, CLIENT_ANY, 1, 2, 0),
68 _CMD("CONNECT", IRC_CONNECT, CLIENT_USER|CLIENT_SERVER, 0, -1, 0),
70 _CMD("DIE", IRC_DIE, CLIENT_USER, 0, 0, 0),
72 _CMD("DIE", IRC_DIE, CLIENT_USER, 0, 1, 0),
74 _CMD("DISCONNECT", IRC_DISCONNECT, CLIENT_USER, 1, 1, 0),
75 _CMD("ERROR", IRC_ERROR, CLIENT_ANY, 0, -1, 0),
76 _CMD("GLINE", IRC_xLINE, CLIENT_USER|CLIENT_SERVER, 0, -1, 0),
77 _CMD("HELP", IRC_HELP, CLIENT_USER, 0, 1, 2),
78 _CMD("INFO", IRC_INFO, CLIENT_USER|CLIENT_SERVER, 0, 1, 2),
79 _CMD("INVITE", IRC_INVITE, CLIENT_USER|CLIENT_SERVER, 2, 2, 0),
80 _CMD("ISON", IRC_ISON, CLIENT_USER, 1, -1, 0),
81 _CMD("JOIN", IRC_JOIN, CLIENT_USER|CLIENT_SERVER, 1, 2, 0),
82 _CMD("KICK", IRC_KICK, CLIENT_USER|CLIENT_SERVER, 2, 3, 0),
83 _CMD("KILL", IRC_KILL, CLIENT_USER|CLIENT_SERVER, 2, 2, 0),
84 _CMD("KLINE", IRC_xLINE, CLIENT_USER|CLIENT_SERVER, 0, -1, 0),
85 _CMD("LINKS", IRC_LINKS, CLIENT_USER|CLIENT_SERVER, 0, 2, 1),
86 _CMD("LIST", IRC_LIST, CLIENT_USER|CLIENT_SERVER, 0, 2, 2),
87 _CMD("LUSERS", IRC_LUSERS, CLIENT_USER|CLIENT_SERVER, 0, 2, 1),
88 _CMD("METADATA", IRC_METADATA, CLIENT_SERVER, 3, 3, 0),
89 _CMD("MODE", IRC_MODE, CLIENT_USER|CLIENT_SERVER, 1, -1, 1),
90 _CMD("MOTD", IRC_MOTD, CLIENT_USER|CLIENT_SERVER, 0, 1, 3),
91 _CMD("NAMES", IRC_NAMES, CLIENT_USER|CLIENT_SERVER, 0, 2, 1),
92 _CMD("NICK", IRC_NICK, CLIENT_ANY, 0, -1, 0),
93 _CMD("NJOIN", IRC_NJOIN, CLIENT_SERVER, 2, 2, 0),
94 _CMD("NOTICE", IRC_NOTICE, CLIENT_ANY, 0, -1, 0),
95 _CMD("OPER", IRC_OPER, CLIENT_USER, 2, 2, 0),
96 _CMD("PART", IRC_PART, CLIENT_USER|CLIENT_SERVER, 1, 2, 0),
97 _CMD("PASS", IRC_PASS, CLIENT_ANY, 0, -1, 0),
98 _CMD("PING", IRC_PING, CLIENT_USER|CLIENT_SERVER, 0, -1, 0),
99 _CMD("PONG", IRC_PONG, CLIENT_ANY, 0, -1, 0),
100 _CMD("PRIVMSG", IRC_PRIVMSG, CLIENT_USER|CLIENT_SERVER, 0, 2, 0),
101 _CMD("QUIT", IRC_QUIT, CLIENT_ANY, 0, 1, 0),
102 _CMD("REHASH", IRC_REHASH, CLIENT_USER, 0, 0, 0),
103 _CMD("RESTART", IRC_RESTART, CLIENT_USER, 0, 0, 0),
104 _CMD("SERVER", IRC_SERVER, CLIENT_ANY, 0, -1, 0),
105 _CMD("SERVICE", IRC_SERVICE, CLIENT_ANY, 6, 6, 0),
106 _CMD("SERVLIST", IRC_SERVLIST, CLIENT_USER, 0, 2, 1),
107 _CMD("SQUERY", IRC_SQUERY, CLIENT_USER|CLIENT_SERVER, 0, 2, 0),
108 _CMD("SQUIT", IRC_SQUIT, CLIENT_USER|CLIENT_SERVER, 2, 2, 0),
109 _CMD("STATS", IRC_STATS, CLIENT_USER|CLIENT_SERVER, 0, 2, 2),
110 _CMD("SVSNICK", IRC_SVSNICK, CLIENT_SERVER, 2, 2, 0),
111 _CMD("SUMMON", IRC_SUMMON, CLIENT_USER|CLIENT_SERVER, 0, -1, 0),
112 _CMD("TIME", IRC_TIME, CLIENT_USER|CLIENT_SERVER, 0, 1, 1),
113 _CMD("TOPIC", IRC_TOPIC, CLIENT_USER|CLIENT_SERVER, 1, 2, 1),
114 _CMD("TRACE", IRC_TRACE, CLIENT_USER|CLIENT_SERVER, 0, 1, 3),
115 _CMD("USER", IRC_USER, CLIENT_ANY, 0, -1, 0),
116 _CMD("USERHOST", IRC_USERHOST, CLIENT_USER, 1, -1, 1),
117 _CMD("USERS", IRC_USERS, CLIENT_USER|CLIENT_SERVER, 0, -1, 0),
118 _CMD("VERSION", IRC_VERSION, CLIENT_USER|CLIENT_SERVER, 0, 1, 1),
119 _CMD("WALLOPS", IRC_WALLOPS, CLIENT_USER|CLIENT_SERVER, 1, 1, 0),
120 _CMD("WEBIRC", IRC_WEBIRC, CLIENT_UNKNOWN, 4, 4, 0),
121 _CMD("WHO", IRC_WHO, CLIENT_USER, 0, 2, 1),
122 _CMD("WHOIS", IRC_WHOIS, CLIENT_USER|CLIENT_SERVER, 0, -1, 1),
123 _CMD("WHOWAS", IRC_WHOWAS, CLIENT_USER|CLIENT_SERVER, 0, -1, 0),
126 _CMD("CHANINFO", IRC_CHANINFO, CLIENT_SERVER, 0, -1, 0),
128 _CMD("CHARCONV", IRC_CHARCONV, CLIENT_USER, 1, 1, 0),
133 _CMD("GET", IRC_QUIT_HTTP, CLIENT_UNKNOWN, 0, -1, 0),
134 _CMD("POST", IRC_QUIT_HTTP, CLIENT_UNKNOWN, 0, -1, 0),
136 _CMD(NULL, NULL, 0, 0, 0, 0) /* End-Mark */
140 static void Init_Request PARAMS(( REQUEST *Req ));
142 static bool Validate_Prefix PARAMS(( CONN_ID Idx, REQUEST *Req, bool *Closed ));
143 static bool Validate_Command PARAMS(( CONN_ID Idx, REQUEST *Req, bool *Closed ));
144 static bool Validate_Args PARAMS(( CONN_ID Idx, REQUEST *Req, bool *Closed ));
146 static bool Handle_Request PARAMS(( CONN_ID Idx, REQUEST *Req ));
148 static bool ScrubCTCP PARAMS((char *Request));
151 * Return the pointer to the global "IRC command structure".
152 * This structure, an array of type "COMMAND" describes all the IRC commands
153 * implemented by ngIRCd and how to handle them.
154 * @return Pointer to the global command structure.
157 Parse_GetCommandStruct( void )
160 } /* Parse_GetCommandStruct */
164 * Parse a command ("request") received from a client.
166 * This function is called after the connection layer received a valid CR+LF
167 * terminated line of text: we assume that this is a valid IRC command and
168 * try to do something useful with it :-)
170 * All errors are reported to the client from which the command has been
171 * received, and if the error is fatal this connection is closed down.
173 * This function is able to parse the syntax as described in RFC 2812,
176 * @param Idx Index of the connection from which the command has been received.
177 * @param Request NULL terminated line of text (the "command").
178 * @return true on success (valid command or "regular" error), false if a
179 * fatal error occurred and the connection has been shut down.
182 Parse_Request( CONN_ID Idx, char *Request )
189 assert( Request != NULL );
192 if( NGIRCd_Sniffer ) Log( LOG_DEBUG, " <- connection %d: '%s'.", Idx, Request );
195 Init_Request( &req );
197 /* remove leading & trailing whitespace */
198 ngt_TrimStr( Request );
200 if (Conf_ScrubCTCP && ScrubCTCP(Request))
203 if (Request[0] == ':') {
205 req.prefix = Request + 1;
206 ptr = strchr( Request, ' ' );
209 LogDebug("Connection %d: Parse error: prefix without command!?", Idx);
210 return Conn_WriteStr(Idx, "ERROR :Prefix without command");
214 /* ignore multiple spaces between prefix and command */
215 while( *(ptr + 1) == ' ' ) ptr++;
219 else start = Request;
221 ptr = strchr( start, ' ' );
226 /* ignore multiple spaces between parameters */
227 while( *(ptr + 1) == ' ' ) ptr++;
232 /* Arguments, Parameters */
238 if( start[0] == ':' )
240 req.argv[req.argc] = start + 1;
245 req.argv[req.argc] = start;
246 ptr = strchr( start, ' ' );
251 while( *(ptr + 1) == ' ' ) ptr++;
258 if( start[0] == ':' ) break;
259 if( req.argc > 14 ) break;
261 if( ptr ) start = ptr + 1;
266 if( ! Validate_Prefix( Idx, &req, &closed )) return ! closed;
267 if( ! Validate_Command( Idx, &req, &closed )) return ! closed;
268 if( ! Validate_Args( Idx, &req, &closed )) return ! closed;
270 return Handle_Request( Idx, &req );
271 } /* Parse_Request */
275 * Initialize request structure.
276 * @param Req Request structure to be initialized.
279 Init_Request( REQUEST *Req )
283 assert( Req != NULL );
287 for( i = 0; i < 15; Req->argv[i++] = NULL );
293 Validate_Prefix( CONN_ID Idx, REQUEST *Req, bool *Closed )
298 assert( Req != NULL );
302 client = Conn_GetClient( Idx );
303 assert( client != NULL );
305 if (!Req->prefix && Client_Type(client) == CLIENT_SERVER
306 && !(Conn_Options(Idx) & CONN_RFC1459)
307 && strcasecmp(Req->command, "ERROR") != 0
308 && strcasecmp(Req->command, "PING") != 0)
311 "Received command without prefix (connection %d, command \"%s\")!?",
313 if (!Conn_WriteStr(Idx, "ERROR :Prefix missing"))
321 /* only validate if this connection is already registered */
322 if (Client_Type(client) != CLIENT_USER
323 && Client_Type(client) != CLIENT_SERVER
324 && Client_Type(client) != CLIENT_SERVICE) {
325 /* not registered, ignore prefix */
330 /* check if client in prefix is known */
331 c = Client_Search(Req->prefix);
333 if (Client_Type(client) != CLIENT_SERVER) {
335 "Ignoring command with invalid prefix \"%s\" from \"%s\" (connection %d, command \"%s\")!",
336 Req->prefix, Client_ID(client), Idx, Req->command);
337 if (!Conn_WriteStr(Idx,
338 "ERROR :Invalid prefix \"%s\"",
341 IRC_SetPenalty(client, 2);
343 LogDebug("Ignoring command with invalid prefix \"%s\" from \"%s\" (connection %d, command \"%s\")!",
344 Req->prefix, Client_ID(client), Idx, Req->command);
348 /* check if the client named in the prefix is expected
349 * to come from that direction */
350 if (Client_NextHop(c) != client) {
351 if (Client_Type(c) != CLIENT_SERVER) {
353 "Spoofed prefix \"%s\" from \"%s\" (connection %d, command \"%s\"), closing connection!",
354 Req->prefix, Client_ID(client), Idx, Req->command);
355 Conn_Close(Idx, NULL, "Spoofed prefix", true);
359 "Ignoring command with spoofed prefix \"%s\" from \"%s\" (connection %d, command \"%s\")!",
360 Req->prefix, Client_ID(client), Idx, Req->command);
366 } /* Validate_Prefix */
370 Validate_Command( UNUSED CONN_ID Idx, UNUSED REQUEST *Req, bool *Closed )
373 assert( Req != NULL );
377 } /* Validate_Command */
382 Validate_Args(CONN_ID Idx, REQUEST *Req, bool *Closed)
384 Validate_Args(UNUSED CONN_ID Idx, UNUSED REQUEST *Req, bool *Closed)
395 assert( Req != NULL );
397 /* CR and LF are never allowed in command parameters.
398 * But since we do accept lines terminated only with CR or LF in
399 * "non-RFC-compliant mode" (besides the correct CR+LF combination),
400 * this check can only trigger in "strict RFC" mode; therefore we
401 * optimize it away otherwise ... */
402 for (i = 0; i < Req->argc; i++) {
403 if (strchr(Req->argv[i], '\r') || strchr(Req->argv[i], '\n')) {
405 "Invalid character(s) in parameter (connection %d, command %s)!?",
407 if (!Conn_WriteStr(Idx,
408 "ERROR :Invalid character(s) in parameter!"))
416 } /* Validate_Args */
419 /* Command is a status code ("numeric") from another server */
421 Handle_Numeric(CLIENT *client, REQUEST *Req)
423 static const struct _NUMERIC Numerics[] = {
424 { 5, IRC_Num_ISUPPORT },
426 { 376, IRC_Num_ENDOFMOTD }
429 char str[COMMAND_LEN];
430 CLIENT *prefix, *target = NULL;
432 /* Determine target */
434 if (strcmp(Req->argv[0], "*") != 0)
435 target = Client_Search(Req->argv[0]);
437 target = Client_ThisServer();
441 /* Status code without target!? */
444 "Unknown target for status code %s: \"%s\"",
445 Req->command, Req->argv[0]);
448 "Unknown target for status code %s!",
452 if (target == Client_ThisServer()) {
453 /* This server is the target of the numeric */
454 num = atoi(Req->command);
456 for (i = 0; i < (int) C_ARRAY_SIZE(Numerics); i++) {
457 if (num == Numerics[i].numeric) {
458 if (!Numerics[i].function)
460 return Numerics[i].function(client, Req);
464 LogDebug("Ignored status code %s from \"%s\".",
465 Req->command, Client_ID(client));
469 /* Determine source */
470 if (! Req->prefix[0]) {
471 /* Oops, no prefix!? */
472 Log(LOG_WARNING, "Got status code %s from \"%s\" without prefix!?",
473 Req->command, Client_ID(client));
477 prefix = Client_Search(Req->prefix);
478 if (! prefix) { /* Oops, unknown prefix!? */
479 Log(LOG_WARNING, "Got status code %s from unknown source: \"%s\"", Req->command, Req->prefix);
483 /* Forward status code */
484 strlcpy(str, Req->command, sizeof(str));
485 for (i = 0; i < Req->argc; i++) {
486 if (i < Req->argc - 1)
487 strlcat(str, " ", sizeof(str));
489 strlcat(str, " :", sizeof(str));
490 strlcat(str, Req->argv[i], sizeof(str));
492 return IRC_WriteStrClientPrefix(target, prefix, "%s", str);
496 Handle_Request( CONN_ID Idx, REQUEST *Req )
504 assert( Req != NULL );
505 assert( Req->command != NULL );
507 client = Conn_GetClient( Idx );
508 assert( client != NULL );
511 client_type = Client_Type(client);
512 if ((client_type == CLIENT_SERVER ||
513 client_type == CLIENT_UNKNOWNSERVER)
514 && strlen(Req->command) == 3 && atoi(Req->command) > 1)
515 return Handle_Numeric(client, Req);
519 if (strcasecmp(Req->command, cmd->name) != 0) {
524 if (!(client_type & cmd->type)) {
525 if (client_type == CLIENT_USER
526 && cmd->type & CLIENT_SERVER)
527 return IRC_WriteErrClient(client,
528 ERR_NOTREGISTEREDSERVER_MSG,
531 return IRC_WriteErrClient(client,
532 ERR_NOTREGISTERED_MSG,
537 IRC_SetPenalty(client, cmd->penalty);
539 if (Req->argc < cmd->min_argc ||
540 (cmd->max_argc != -1 && Req->argc > cmd->max_argc))
541 return IRC_WriteErrClient(client, ERR_NEEDMOREPARAMS_MSG,
542 Client_ID(client), Req->command);
544 /* Command is allowed for this client: call it and count
545 * generated bytes in output */
546 Conn_ResetWCounter();
547 result = (cmd->function)(client, Req);
548 cmd->bytes += Conn_WCounter();
550 /* Adjust counters */
551 if (client_type != CLIENT_SERVER)
558 if (client_type != CLIENT_USER &&
559 client_type != CLIENT_SERVER &&
560 client_type != CLIENT_SERVICE )
563 /* Unknown command and registered connection: generate error: */
564 LogDebug("Connection %d: Unknown command \"%s\", %d %s,%s prefix.",
565 Client_Conn( client ), Req->command, Req->argc,
566 Req->argc == 1 ? "parameter" : "parameters",
567 Req->prefix ? "" : " no" );
569 if (Client_Type(client) != CLIENT_SERVER)
570 result = IRC_WriteErrClient(client, ERR_UNKNOWNCOMMAND_MSG,
571 Client_ID(client), Req->command);
574 } /* Handle_Request */
578 * Check if incoming messages contains CTCP commands and should be dropped.
580 * @param Request NULL terminated incoming command.
581 * @returns true, when the message should be dropped.
584 ScrubCTCP(char *Request)
586 static const char me_cmd[] = "ACTION ";
587 static const char ctcp_char = 0x1;
588 bool dropCommand = false;
590 char *ptrEnd = strchr(Request, '\0');
592 if (Request[0] == ':' && ptrEnd > ptr)
595 while (ptr != ptrEnd && *ptr != ':')
598 if ((ptrEnd - ptr) > 1) {
600 if (*ptr == ctcp_char) {
603 /* allow /me commands */
604 if ((size_t)(ptrEnd - ptr) >= strlen(me_cmd)
605 && !strncmp(ptr, me_cmd, strlen(me_cmd)))