WIP: feat: Port room takeover and shutdown commands from continuwuity.rocks #1375

Draft
nex wants to merge 4 commits from nex/feat/room-shutdown into main
Owner

This pull request ports over the !admin rooms moderation takeover and !admin rooms moderation shutdown commands from continuwuity.rocks: nex/continuwuity@8754479e96

The first command works by finding any local user in the target room that can modify the m.room.power_levels event, and uses their account to increase the invoking admin's power level to match their own. For rooms where we have local creators or admin users, this can allow server admins to commandeer a room and do whatever with it, such as assigning new moderators to an abandoned room. This is similar in behaviour to Synapse's "assign admin" function.

The second command does the following:

  1. If --force is passed, join the privileged user to the room so they can send events
  2. If the power levels have not yet been restricted, set the user_default level to -2^53-1 (as low as it can go) and raise the requirement of every specified event, ban, kick, events_default, and state_default to admin_user_pl, and remove all other users with a power level below the admin user's own
  3. If the join rules have not yet been changed, change them to the custom rule org.continuwuity.shutdown. This prevents people joining in the future, even if they have been invited, as the unrecognised rule prevents any further join authorisation.
  4. If the history visibility has not yet been changed, the history visibility is set to joined
  5. All users in the room, excluding server admins, are banned, or if the admin user being puppetted cannot ban, kicked. The MSC4293 redact_events flag is set on these events if --redact is passed, preventing clients from rendering sent messages afterwards.
  6. Finally, an m.room.tombstone event is sent, preventing most clients from allowing the room to be used again, even in the event of a state reset.

This is a very powerful command designed to be used to disband offensive/illegal rooms. It is not uncommon for bad users to sign up on public or restricted homeservers, create or join rooms with illegal content, and then assign a power level to their accounts on other servers in order to retain control over said rooms when their accounts get banned from other servers. This feature takes advantage of this trend to ruin their day.
It is worth mentioning: the shutdown command performs exactly the same functions any user with an elevated power level can do, meaning even if this command was ultimately dropped, you could still perform these actions manually after takeover. And without takeover, you could always just !admin users reset-password and log in to the target user.

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
This pull request ports over the `!admin rooms moderation takeover` and `!admin rooms moderation shutdown` commands from continuwuity.rocks: https://forgejo.ellis.link/nex/continuwuity/commit/8754479e96df93c1a23bbd9dc9171be8a154238f The first command works by finding any local user in the target room that can modify the `m.room.power_levels` event, and uses their account to increase the invoking admin's power level to match their own. For rooms where we have local creators or admin users, this can allow server admins to commandeer a room and do whatever with it, such as assigning new moderators to an abandoned room. This is similar in behaviour to [Synapse's "assign admin" function](https://element-hq.github.io/synapse/latest/admin_api/rooms.html#make-room-admin-api). The second command does the following: 1. If `--force` is passed, join the privileged user to the room so they can send events 2. If the power levels have not yet been restricted, set the `user_default` level to -2^53-1 (as low as it can go) and raise the requirement of every specified event, `ban`, `kick`, `events_default`, and `state_default` to `admin_user_pl`, and remove all other users with a power level below the admin user's own 3. If the join rules have not yet been changed, change them to the custom rule `org.continuwuity.shutdown`. This prevents people joining in the future, even if they have been invited, as the unrecognised rule prevents any further join authorisation. 4. If the history visibility has not yet been changed, the history visibility is set to `joined` 5. All users in the room, excluding server admins, are banned, or if the admin user being puppetted cannot ban, kicked. The MSC4293 `redact_events` flag is set on these events if `--redact` is passed, preventing clients from rendering sent messages afterwards. 6. Finally, an `m.room.tombstone` event is sent, preventing most clients from allowing the room to be used again, even in the event of a state reset. This is a very powerful command designed to be used to disband offensive/illegal rooms. It is not uncommon for bad users to sign up on public or restricted homeservers, create or join rooms with illegal content, and then assign a power level to their accounts on other servers in order to retain control over said rooms when their accounts get banned from other servers. This feature takes advantage of this trend to ruin their day. It is worth mentioning: the `shutdown` command performs exactly the same functions any user with an elevated power level can do, meaning even if this command was ultimately dropped, you could still perform these actions manually after `takeover`. And without takeover, you could always just `!admin users reset-password` and log in to the target user. **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [ ] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. - [ ] I have written a [news fragment][n1] for this PR, if applicable<!--(can be done after hitting open!)-->. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages [n1]: https://towncrier.readthedocs.io/en/stable/tutorial.html#creating-news-fragments
feat: Port room takeover and shutdown commands from continuwuity.rocks
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Successful in 22s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m34s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m54s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
c9d9ed0a90
nex self-assigned this 2026-02-14 14:13:43 +00:00
chore: Add double-lock flag
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m25s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m38s
Update flake hashes / update-flake-hashes (pull_request) Successful in 20s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 25m31s
2919c8e636
fix: Unreliability in kicks & bans
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Successful in 29s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m24s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m13s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 19m28s
93b9007e1d
Some checks failed
Update flake hashes / update-flake-hashes (pull_request) Successful in 29s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m24s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m13s
Required
Details
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 19m28s
Required
Details
This pull request is marked as a work in progress.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin nex/feat/room-shutdown:nex/feat/room-shutdown
git switch nex/feat/room-shutdown
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!1375
No description provided.