v1.2.27 - Permanent ban escalation: ban_count never resets, IPs with history always get 24h ban on next failure
This commit is contained in:
+7
-5
@@ -350,18 +350,20 @@ void ip_ban_cleanup(void) {
|
||||
int last_ban_expired_long_ago = (entry->banned_until == 0 ||
|
||||
(now - entry->banned_until) > retain_sec);
|
||||
|
||||
if (last_ban_expired_long_ago && !entry->has_authed_successfully) {
|
||||
// Fully clean — no ban history and never authenticated
|
||||
if (last_ban_expired_long_ago && !entry->has_authed_successfully &&
|
||||
entry->ban_count == 0 && entry->total_connections <= 1) {
|
||||
// Fully clean — never banned, never authenticated, only seen once
|
||||
memset(entry, 0, sizeof(ip_ban_entry_t));
|
||||
cleaned++;
|
||||
} else {
|
||||
// Keep entry — either has ban history or has authenticated before
|
||||
// Keep entry permanently — preserve ban_count for escalation.
|
||||
// An IP that has been banned before will always get at least a 24-hour ban
|
||||
// if it fails auth again, regardless of how long it has been away.
|
||||
entry->failure_count = 0;
|
||||
entry->first_failure = 0;
|
||||
if (last_ban_expired_long_ago) {
|
||||
entry->banned_until = 0;
|
||||
// Reset ban_count after 24 hours of inactivity
|
||||
entry->ban_count = 0;
|
||||
// ban_count intentionally NOT reset — permanent escalation
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+2
-2
@@ -13,8 +13,8 @@
|
||||
// Using CRELAY_ prefix to avoid conflicts with nostr_core_lib VERSION macros
|
||||
#define CRELAY_VERSION_MAJOR 1
|
||||
#define CRELAY_VERSION_MINOR 2
|
||||
#define CRELAY_VERSION_PATCH 26
|
||||
#define CRELAY_VERSION "v1.2.26"
|
||||
#define CRELAY_VERSION_PATCH 27
|
||||
#define CRELAY_VERSION "v1.2.27"
|
||||
|
||||
// Relay metadata (authoritative source for NIP-11 information)
|
||||
#define RELAY_NAME "C-Relay"
|
||||
|
||||
Reference in New Issue
Block a user