--- ircd-hybrid/trunk/NEWS 2018/04/04 22:02:58 8491 +++ ircd-hybrid/trunk/NEWS 2020/10/09 21:52:26 9656 @@ -1,808 +1,922 @@ -####################################################################### -Reminder for package maintainers of ircd-hybrid: ircd-hybrid now has -GnuTLS support as of version 8.2.13 -####################################################################### +-- Noteworthy changes in version 8.2.33 (2020-09-07) +* Added `client` option to `listener::flags` +* Added `defer` option to `listener::flags` +* IRC operators may now use CIDR notation in `WHO` +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.32 (2020-08-16) +* `RESV` couldn't be issued in case no reason has been supplied. This has been fixed. +* Fixed possible `RPL_WHOISCHANNELS` line truncation of remote replies +* Extban $t of type `matching` has been implemented. This extban allows matching + based on TLS protocol version and/or cipher suite +* Implemented channel mode `K`. `KNOCK` cannot be used on channels with that mode set +* `STATS ?` is now oper-only +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.31 (2020-05-03) +* macOS compatibility fixes +* Removed `spoof_notice` from `auth::flags`. With vhosts now this notice doesn't make + much sense anymore +* Fixed issue where ban masks might become malformed if set by remote clients/servers +* Fixed issue with channel mode +c where high ascii characters can be erroneously + detected as control characters +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.30 (2020-03-01) +* `QUOTE HELP extban` didn't work because the extban help file hasn't been + installed properly during `make install` +* Fixed broken libcrypto detection which caused the ircd not to work with + openssl under certain circumstances +* Extban $n of type `acting` has been implemented. This extban prevents + matching users from changing their nick while in the channel. Users + with voice or above are not affected. +* Channel mode +N has been changed so channel members with +v can change + their nick name as well +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.29 (2020-02-19) +* Extbans have been implemented. Currently supported extbans: + + Matching: + + $a: Matches users logged into a matching account. + $c: Matches users that are on the given channel. An additional + prefix of either @, %, or + can be specified to test for + certain channel privileges. + $o: Matches IRC operators that have joined a class + matching the mask. + $r: Matches users with a matching realname. + $s: Matches users that are connected to a server matching the mask. + $u: Matches users having the specified user modes set or not set. + $z: Matches users having the given TLS certificate fingerprint. + + Acting: + + $j: Prevents matching users from joining the channel. + $m: Blocks messages from matching users. Users with voice + or above are not affected. + + For more details, see help/extban. +* Added `channel::enable_extbans` configuration option. See doc/reference.conf + for more information. +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.28 (2020-01-26) +* Fixed issue with topics set by `TBURST` not being propagated properly to clients +* Allow IRC operators to search for real hosts in `WHO` +* Ban/exempt/invex masks are now also tested against realhosts to prevent clients + from bypassing channel bans by activating a fakehost +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.27 (2020-01-22) +* Experimental support for wolfSSL has been implemented. Minimum supported version is 4.3.0 +* The `--enable-openssl`, `--enable-gnutls` switches, and their disabling counterparts + `--disable-openssl` and `--disable-gnutls`, have been replaced with the `--with-tls` + switch which takes one of the following options: `openssl`, `wolfssl`, `gnutls`, + and `none`. + If nothing has been specified, configure tries to autodetect in the following order: + openssl/libressl -> gnutls -> wolfssl. +* Fixed segfault with GnuTLS/libgmp in case there's no DH parameters file + defined in `serverinfo::ssl_dh_param_file` or if that file is missing +* The connection timeout for connect{} blocks can now be configured via + the `connect::timeout` configuration directive +* Minimum supported OpenSSL version is 1.1.1 now +* Minimum supported GnuTLS version is 3.6.5 now +* Supported TLSv1.3 cipher suites can now be configured explicitely via the + new `serverinfo::tls_cipher_suites` configuration directive +* In the serverinfo {} block, the following configuration directives have been renamed: + `ssl_certificate_file` -> `tls_certificate_file` + `ssl_dh_param_file` -> `tls_dh_param_file` + `ssl_dh_elliptic_curve` -> `tls_supported_groups` + `ssl_cipher_list` -> `tls_cipher_list` + `ssl_message_digest_algorithm` -> `tls_message_digest_algorithm` +* In the operator {} block, the following configuration directives have been renamed: + `ssl_certificate_fingerprint -> `tls_certificate_fingerprint` + `ssl_connection_required -> `tls_connection_required` +* In the connect {} block, the following configuration directives have been renamed: + `ssl_cipher_list -> `tls_cipher_list` + `ssl_certificate_fingerprint -> `tls_certificate_fingerprint` +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.26 (2019-05-31) +* The `general::tkline_expire_notices` configuration directive has been + replaced with user mode `X`. *LINE expiration notices are sent to IRC + operators with that mode set +* Fixed issue with `/rehash conf` creating duplicated class entries + instead of updating existing ones that are already in use +* For a full list of all changes in this release, see + + +-- Noteworthy changes in version 8.2.25 (2019-04-24) +* The `class::number_per_ip`, `class::max_local` and `class::max_global` + configuration directives have been replaced with just `class::number_per_ip_local` + and `class::number_per_ip_global`. The `class::max_local` basically was + redundant as it had the same functionality as `class::number_per_ip` +* Adding RESVs with wildcards no longer requires administrator privileges +* The `general::ignore_bogus_ts` configuration option has been deprecated +* TLSv1.1 and TLSv1.0 are no longer supported and have been disabled in + the openssl and gnutls module +* Minimum supported OpenSSL version is 1.0.1f now +* Minimum supported GnuTLS version is 3.5.8 now +* The `serverinfo::vhost` and `serverinfo:vhost6` configuration directives have + been deprecated. If you need to bind() a specific address you can specify one + in the connect {} block +* The `connect::vhost` configuration directive has been renamed to `connect::bind` +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.24 (2018-04-05) -o) Added "STATS s" to show configured pseudo {} blocks -o) Implemented channel mode 'N' which prevents users from changing their - nick while in a channel with that mode set -o) Services clients are now shown with 'is a Network Service' in "WHOIS" +* Added `STATS s` to show configured pseudo {} blocks +* Implemented channel mode `N` which prevents users from changing their + nick while in a channel with that mode set +* Services clients are now shown with `is a Network Service` in `WHOIS` +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.23 (2018-03-26) -o) irc-operators are now able to see a user's resolved hostname in /whowas, - and /whois even if the user has a fakehost/vhost -o) RPL_WELCOME now does use the rfc2812 style nick!user@host format -o) Removed rudimentary libgeoip support -o) Added --enable-efence switch to allow easy linking with the - electric fence memory debugger library -o) "JOIN 0" is no longer supported -o) Fixed bug where ircd would not remove RPL_WHOISOPERATOR based svstags - when deoppering -o) Fixed 'unknown closes' statistic in "STATS t" showing invalid values sometimes +* irc-operators are now able to see a user's resolved hostname in /whowas, + and /whois even if the user has a fakehost/vhost +* `RPL_WELCOME` now does use the rfc2812 style nick!user@host format +* Removed rudimentary libgeoip support +* Added `--enable-efence` switch to allow easy linking with the + electric fence memory debugger library +* `JOIN 0` is no longer supported +* Fixed bug where ircd would not remove `RPL_WHOISOPERATOR` based svstags + when deoppering +* Fixed `unknown closes` statistic in `STATS t` showing invalid values sometimes +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.22 (2017-03-26) -o) Implemented channel mode 'L'. Channels with that mode set can make use of an - extended ban list size specified with the new 'channel::max_bans_large' - configuraton option. This mode can be set only by irc-operators or servers. -o) Implemented channel mode 'u' which hides bmask (+b/+e/+I) lists and mode changes - to non-chanops everywhere -o) Fixed an issue with "TRACE" where remote servers would reply with RPL_TRACEUSER - numerics containing UIDs -o) "STATS z" now shows simple memory stats of servers linked to the network -o) Added support for remote "ETRACE" +* Implemented channel mode `L`. Channels with that mode set can make use of an + extended ban list size specified with the new `channel::max_bans_large` + configuraton option. This mode can be set only by irc-operators or servers. +* Implemented channel mode `u` which hides bmask (+b/+e/+I) lists and mode changes + to non-chanops everywhere +* Fixed an issue with `TRACE` where remote servers would reply with `RPL_TRACEUSER` + numerics containing UIDs +* `STATS z` now shows simple memory stats of servers linked to the network +* Added support for remote `ETRACE` +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.21 (2016-11-27) -o) The 'general::default_floodtime' configuration option has been added - along with the "SET FLOODTIME" command. These allow to fine-tune the - message throttling better -o) Fixed an issue with /invite not showing the list of channels the - sender is invited to +* The `general::default_floodtime` configuration option has been added + along with the `SET FLOODTIME` command. These allow to fine-tune the + message throttling better +* Fixed an issue with `INVITE` not showing the list of channels the + sender is invited to +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.20 (2016-11-05) -o) "INFO" now shows GnuTLS/OpenSSL library/header versions -o) Added 'channel::max_invites' configuration option. See doc/reference.conf - for more information. -o) INVITE expirations have been implemented. Expire time can be adjusted with - the 'channel::invite_expire_time' configuration directive -o) /whois notices to operators have been re-added. User mode +y is required - to see them -o) The maximum line length for motd files has been increased to 320 bytes - to support multibyte encodings better +* `INFO` now shows GnuTLS/OpenSSL library/header versions +* Added `channel::max_invites` configuration option. See doc/reference.conf + for more information. +* `INVITE` expirations have been implemented. Expire time can be adjusted with + the `channel::invite_expire_time` configuration directive +* `WHOIS` notices to operators have been re-added. User mode +y is required + to see them +* The maximum line length for motd files has been increased to 320 bytes + to support multibyte encodings better +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.19 (2016-08-21) -o) Fixed a possible server name leak in "WHO" with server hiding enabled -o) "WHO" now allows opers to search by IP address -o) Admins no longer can see IP addresses in "STATS P" with - 'serverhide::hide_server_ips' enabled -o) User mode 'n' now shows nick name changes from remote clients, too +* Fixed a possible server name leak in `WHO` with server hiding enabled +* `WHO` now allows opers to search by IP address +* Admins no longer can see IP addresses in `STATS P` with + `serverhide::hide_server_ips` enabled +* User mode `n` now shows nick name changes from remote clients, too +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.18 (2016-06-22) -o) Fixed an assert when a client sends invalid LIST options -o) Fixed invalid memory stats of channel invites in "STATS z" +* Fixed an assert when a client sends invalid `LIST` options +* Fixed invalid memory stats of channel invites in `STATS z` +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.17 (2016-04-21) -o) Fixed core on "REHASH CONF" with 'general::whowas_history_length' - set to 0 -o) Fixed possible core on "INVITE" with 'channel::max_channels' set to 0 +* Fixed core on `REHASH CONF` with `general::whowas_history_length` + set to 0 +* Fixed possible core on `INVITE` with `channel::max_channels` set to 0 +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.16 (2016-03-20) -o) Added 'general::whowas_history_length' configuration option which - allows to define the maximum length of the WHOWAS nickname history -o) Services are now allowed to override 'general::min_nonwildcard', - and 'general::min_nonwildcard_simple' settings -o) Minor updates to help files +* Added `general::whowas_history_length` configuration option which + allows to define the maximum length of the `WHOWAS` nickname history +* Services are now allowed to override `general::min_nonwildcard`, + and `general::min_nonwildcard_simple` settings +* Minor updates to help files +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.15 (2016-02-24) -o) Added proper support for Raspbian/ARM. Gracias to Beave/2600.net - for providing a box for testing purposes. -o) Fixed an assert with empty user = "" directives in auth {} blocks -o) "STATS z" now shows allocated listeners -o) Fixed bug where 'can_flood' auth {} flags did not work on channels +* Added proper support for Raspbian/ARM. Gracias to Beave/2600.net + for providing a box for testing purposes. +* Fixed an assert with empty `user = ""` directives in auth {} blocks +* `STATS z` now shows allocated listeners +* Fixed bug where `can_flood` auth {} flags did not work on channels +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.14 (2016-02-09) -o) Fixed server clustering -o) Major cleanups to the configuration subsystem -o) Improvements to libGeoIP support: - - Works now with IPv6 addresses - - Added 'libgeoip_database_options', 'libgeoip_ipv4_database_file', - and 'libgeoip_ipv6_database_file' configuration directives to the - serverinfo {} block -o) Further improvements to GnuTLS support +* Fixed server clustering +* Major cleanups to the configuration subsystem +* Improvements to libGeoIP support: + - Works now with IPv6 addresses + - Added `libgeoip_database_options`, `libgeoip_ipv4_database_file`, + and `libgeoip_ipv6_database_file` configuration directives to the + serverinfo {} block +* Further improvements to GnuTLS support +* For a full list of all changes in this release, see -- Noteworthy changes in version 8.2.13 (2016-02-02) -o) Implemented support for GnuTLS. Currently ./configure's autodetection - intentionally prefers OpenSSL over GnuTLS, so OpenSSL detection needs - to be disabled explicitely by using the --disable-openssl switch. -o) Minimum supported GnuTLS version is 3.3.8 now -o) Minimum supported OpenSSL version is 1.0.1d now -o) Added support for remote REHASH: REHASH