v1.2.27 - Permanent ban escalation: ban_count never resets, IPs with history always get 24h ban on next failure

This commit is contained in:
Your Name
2026-02-23 18:18:55 -04:00
parent f8ec4ae924
commit c96736fa6a
2 changed files with 9 additions and 7 deletions
+7 -5
View File
@@ -350,18 +350,20 @@ void ip_ban_cleanup(void) {
int last_ban_expired_long_ago = (entry->banned_until == 0 ||
(now - entry->banned_until) > retain_sec);
if (last_ban_expired_long_ago && !entry->has_authed_successfully) {
// Fully clean — no ban history and never authenticated
if (last_ban_expired_long_ago && !entry->has_authed_successfully &&
entry->ban_count == 0 && entry->total_connections <= 1) {
// Fully clean — never banned, never authenticated, only seen once
memset(entry, 0, sizeof(ip_ban_entry_t));
cleaned++;
} else {
// Keep entry — either has ban history or has authenticated before
// Keep entry permanently — preserve ban_count for escalation.
// An IP that has been banned before will always get at least a 24-hour ban
// if it fails auth again, regardless of how long it has been away.
entry->failure_count = 0;
entry->first_failure = 0;
if (last_ban_expired_long_ago) {
entry->banned_until = 0;
// Reset ban_count after 24 hours of inactivity
entry->ban_count = 0;
// ban_count intentionally NOT reset — permanent escalation
}
}
}
+2 -2
View File
@@ -13,8 +13,8 @@
// Using CRELAY_ prefix to avoid conflicts with nostr_core_lib VERSION macros
#define CRELAY_VERSION_MAJOR 1
#define CRELAY_VERSION_MINOR 2
#define CRELAY_VERSION_PATCH 26
#define CRELAY_VERSION "v1.2.26"
#define CRELAY_VERSION_PATCH 27
#define CRELAY_VERSION "v1.2.27"
// Relay metadata (authoritative source for NIP-11 information)
#define RELAY_NAME "C-Relay"