Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
31187c4c4f | ||
|
|
55f862b879 | ||
|
|
76c9b3fcf0 | ||
|
|
929bd09164 |
@@ -85,7 +85,7 @@ static const struct {
|
||||
|
||||
// Debug Level (0=none, 1=errors, 2=warnings, 3=info, 4=debug, 5=trace)
|
||||
// Can be changed at runtime without restart via config_set admin command
|
||||
{"debug_level", "0"},
|
||||
{"debug_level", "3"},
|
||||
|
||||
// IP Auth Failure Ban Settings
|
||||
// Ban IPs that repeatedly fail NIP-42 authentication
|
||||
@@ -103,8 +103,8 @@ static const struct {
|
||||
// Ban IPs that connect but never send REQ or EVENT (idle or early disconnect)
|
||||
{"idle_connection_timeout_sec", "30"}, // Seconds before idle connection is closed (0 = disabled)
|
||||
{"idle_ban_enabled", "true"}, // Whether to ban IPs with idle failures
|
||||
{"idle_ban_threshold", "3"}, // Idle failures before ban
|
||||
{"idle_ban_window_sec", "60"}, // Window to count idle failures in
|
||||
{"idle_ban_threshold", "1"}, // Idle failures before ban (1 = ban on first offense)
|
||||
{"idle_ban_window_sec", "30"}, // Window to count idle failures in
|
||||
{"idle_ban_duration_sec", "300"}, // Initial ban duration (doubles each time, max 24h)
|
||||
|
||||
// SQLite Performance Tuning
|
||||
|
||||
File diff suppressed because one or more lines are too long
+2
-2
@@ -360,8 +360,8 @@ void ip_ban_record_idle_failure(const char* ip) {
|
||||
if (!ip || !g_initialized) return;
|
||||
if (!get_config_bool("idle_ban_enabled", 1)) return;
|
||||
|
||||
int threshold = get_config_int("idle_ban_threshold", 3);
|
||||
int window_sec = get_config_int("idle_ban_window_sec", 60);
|
||||
int threshold = get_config_int("idle_ban_threshold", 1);
|
||||
int window_sec = get_config_int("idle_ban_window_sec", 30);
|
||||
int ban_duration = get_config_int("idle_ban_duration_sec", 300);
|
||||
|
||||
pthread_mutex_lock(&g_ban_mutex);
|
||||
|
||||
+2
-2
@@ -13,8 +13,8 @@
|
||||
// Using CRELAY_ prefix to avoid conflicts with nostr_core_lib VERSION macros
|
||||
#define CRELAY_VERSION_MAJOR 1
|
||||
#define CRELAY_VERSION_MINOR 2
|
||||
#define CRELAY_VERSION_PATCH 30
|
||||
#define CRELAY_VERSION "v1.2.30"
|
||||
#define CRELAY_VERSION_PATCH 34
|
||||
#define CRELAY_VERSION "v1.2.34"
|
||||
|
||||
// Relay metadata (authoritative source for NIP-11 information)
|
||||
#define RELAY_NAME "C-Relay"
|
||||
|
||||
+98
-1
@@ -116,6 +116,81 @@ extern struct lws_context *ws_context;
|
||||
// Global subscription manager
|
||||
struct subscription_manager g_subscription_manager;
|
||||
|
||||
// Global connection list for idle connection tracking
|
||||
// Tracks ALL WebSocket connections (not just subscribed ones)
|
||||
// so the periodic timer can find and close idle connections
|
||||
#define MAX_TRACKED_CONNECTIONS 4096
|
||||
|
||||
typedef struct {
|
||||
struct lws* wsi;
|
||||
struct per_session_data* pss;
|
||||
} tracked_connection_t;
|
||||
|
||||
static tracked_connection_t g_connections[MAX_TRACKED_CONNECTIONS];
|
||||
static int g_connection_count = 0;
|
||||
static pthread_mutex_t g_connections_lock = PTHREAD_MUTEX_INITIALIZER;
|
||||
|
||||
static void connection_list_add(struct lws* wsi, struct per_session_data* pss) {
|
||||
pthread_mutex_lock(&g_connections_lock);
|
||||
for (int i = 0; i < MAX_TRACKED_CONNECTIONS; i++) {
|
||||
if (g_connections[i].wsi == NULL) {
|
||||
g_connections[i].wsi = wsi;
|
||||
g_connections[i].pss = pss;
|
||||
g_connection_count++;
|
||||
break;
|
||||
}
|
||||
}
|
||||
pthread_mutex_unlock(&g_connections_lock);
|
||||
}
|
||||
|
||||
static void connection_list_remove(struct lws* wsi) {
|
||||
pthread_mutex_lock(&g_connections_lock);
|
||||
for (int i = 0; i < MAX_TRACKED_CONNECTIONS; i++) {
|
||||
if (g_connections[i].wsi == wsi) {
|
||||
g_connections[i].wsi = NULL;
|
||||
g_connections[i].pss = NULL;
|
||||
g_connection_count--;
|
||||
break;
|
||||
}
|
||||
}
|
||||
pthread_mutex_unlock(&g_connections_lock);
|
||||
}
|
||||
|
||||
// Check all tracked connections for idle timeout and close them
|
||||
// Called from the periodic maintenance timer (every 60 seconds)
|
||||
static void check_idle_connections(int idle_timeout_sec) {
|
||||
if (idle_timeout_sec <= 0) return;
|
||||
|
||||
time_t now = time(NULL);
|
||||
|
||||
// Collect WSIs to close outside the lock to avoid deadlock
|
||||
struct lws* to_close[MAX_TRACKED_CONNECTIONS];
|
||||
int close_count = 0;
|
||||
|
||||
pthread_mutex_lock(&g_connections_lock);
|
||||
for (int i = 0; i < MAX_TRACKED_CONNECTIONS; i++) {
|
||||
if (g_connections[i].wsi == NULL || g_connections[i].pss == NULL) continue;
|
||||
struct per_session_data* pss = g_connections[i].pss;
|
||||
if (pss->session_active) continue; // Already active — skip
|
||||
if (pss->connection_established <= 0) continue;
|
||||
time_t age = now - pss->connection_established;
|
||||
if (age >= idle_timeout_sec) {
|
||||
to_close[close_count++] = g_connections[i].wsi;
|
||||
}
|
||||
}
|
||||
pthread_mutex_unlock(&g_connections_lock);
|
||||
|
||||
for (int i = 0; i < close_count; i++) {
|
||||
// Get pss again safely — it may have been freed if connection closed between lock release and here
|
||||
struct per_session_data* pss = (struct per_session_data*)lws_wsi_user(to_close[i]);
|
||||
if (!pss) continue;
|
||||
DEBUG_LOG("Closing idle connection from %s (no REQ/EVENT after %d seconds)",
|
||||
pss->client_ip, idle_timeout_sec);
|
||||
lws_close_reason(to_close[i], LWS_CLOSE_STATUS_POLICY_VIOLATION,
|
||||
(unsigned char*)"Idle connection timeout", 23);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
|
||||
// Message queue functions for proper libwebsockets pattern
|
||||
@@ -330,6 +405,12 @@ static int nostr_relay_callback(struct lws *wsi, enum lws_callback_reasons reaso
|
||||
switch (reason) {
|
||||
case LWS_CALLBACK_HTTP:
|
||||
// Handle HTTP requests
|
||||
// Mark session as active so HTTP requests don't trigger idle ban
|
||||
if (pss) {
|
||||
pthread_mutex_lock(&pss->session_lock);
|
||||
pss->session_active = 1;
|
||||
pthread_mutex_unlock(&pss->session_lock);
|
||||
}
|
||||
{
|
||||
char *requested_uri = (char *)in;
|
||||
|
||||
@@ -383,6 +464,12 @@ static int nostr_relay_callback(struct lws *wsi, enum lws_callback_reasons reaso
|
||||
int is_nip11_request = (strstr(accept_header, "application/nostr+json") != NULL);
|
||||
|
||||
if (is_nip11_request) {
|
||||
// Mark session as active so HTTP requests don't trigger idle ban
|
||||
if (pss) {
|
||||
pthread_mutex_lock(&pss->session_lock);
|
||||
pss->session_active = 1;
|
||||
pthread_mutex_unlock(&pss->session_lock);
|
||||
}
|
||||
// Handle NIP-11 request
|
||||
if (handle_nip11_http_request(wsi, accept_header) == 0) {
|
||||
return 0; // Successfully handled
|
||||
@@ -547,6 +634,9 @@ static int nostr_relay_callback(struct lws *wsi, enum lws_callback_reasons reaso
|
||||
pss->challenge_created = 0;
|
||||
pss->challenge_expires = 0;
|
||||
|
||||
// Register in global connection list for idle tracking
|
||||
connection_list_add(wsi, pss);
|
||||
|
||||
// Record connection for stats tracking
|
||||
ip_ban_record_connection(pss->client_ip);
|
||||
|
||||
@@ -2149,7 +2239,10 @@ static int nostr_relay_callback(struct lws *wsi, enum lws_callback_reasons reaso
|
||||
|
||||
case LWS_CALLBACK_CLOSED:
|
||||
DEBUG_TRACE("WebSocket connection closed");
|
||||
|
||||
|
||||
// Remove from global connection list (must happen before pss cleanup)
|
||||
connection_list_remove(wsi);
|
||||
|
||||
// Enhanced closure logging with detailed diagnostics
|
||||
if (pss) {
|
||||
// Calculate connection duration
|
||||
@@ -2560,6 +2653,10 @@ int start_websocket_relay(int port_override, int strict_port) {
|
||||
DEBUG_WARN("Debug level changed: %d -> %d", g_debug_level, config_debug_level);
|
||||
g_debug_level = config_debug_level;
|
||||
}
|
||||
// Check and close idle connections (no REQ/EVENT sent within timeout)
|
||||
int idle_timeout_sec = get_config_int("idle_connection_timeout_sec", 30);
|
||||
check_idle_connections(idle_timeout_sec);
|
||||
|
||||
if (max_connection_seconds > 0) {
|
||||
check_connection_age(max_connection_seconds);
|
||||
} else {
|
||||
|
||||
Reference in New Issue
Block a user