From c96736fa6a0c42cdd9b752ad66d337c703c84c14 Mon Sep 17 00:00:00 2001 From: Your Name Date: Mon, 23 Feb 2026 18:18:55 -0400 Subject: [PATCH] v1.2.27 - Permanent ban escalation: ban_count never resets, IPs with history always get 24h ban on next failure --- src/ip_ban.c | 12 +++++++----- src/main.h | 4 ++-- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/src/ip_ban.c b/src/ip_ban.c index 77960c5..883c1df 100644 --- a/src/ip_ban.c +++ b/src/ip_ban.c @@ -350,18 +350,20 @@ void ip_ban_cleanup(void) { int last_ban_expired_long_ago = (entry->banned_until == 0 || (now - entry->banned_until) > retain_sec); - if (last_ban_expired_long_ago && !entry->has_authed_successfully) { - // Fully clean — no ban history and never authenticated + if (last_ban_expired_long_ago && !entry->has_authed_successfully && + entry->ban_count == 0 && entry->total_connections <= 1) { + // Fully clean — never banned, never authenticated, only seen once memset(entry, 0, sizeof(ip_ban_entry_t)); cleaned++; } else { - // Keep entry — either has ban history or has authenticated before + // Keep entry permanently — preserve ban_count for escalation. + // An IP that has been banned before will always get at least a 24-hour ban + // if it fails auth again, regardless of how long it has been away. entry->failure_count = 0; entry->first_failure = 0; if (last_ban_expired_long_ago) { entry->banned_until = 0; - // Reset ban_count after 24 hours of inactivity - entry->ban_count = 0; + // ban_count intentionally NOT reset — permanent escalation } } } diff --git a/src/main.h b/src/main.h index cffe177..5f109c0 100644 --- a/src/main.h +++ b/src/main.h @@ -13,8 +13,8 @@ // Using CRELAY_ prefix to avoid conflicts with nostr_core_lib VERSION macros #define CRELAY_VERSION_MAJOR 1 #define CRELAY_VERSION_MINOR 2 -#define CRELAY_VERSION_PATCH 26 -#define CRELAY_VERSION "v1.2.26" +#define CRELAY_VERSION_PATCH 27 +#define CRELAY_VERSION "v1.2.27" // Relay metadata (authoritative source for NIP-11 information) #define RELAY_NAME "C-Relay"