]>
Commit | Line | Data |
---|---|---|
d1e348cf A |
1 | /* $NetBSD: throttle.c,v 1.4 2006/09/09 16:22:10 manu Exp $ */ |
2 | ||
3 | /* Id: throttle.c,v 1.5 2006/04/05 20:54:50 manubsd Exp */ | |
52b7d2ce A |
4 | |
5 | /* | |
6 | * Copyright (C) 2004 Emmanuel Dreyfus | |
7 | * All rights reserved. | |
8 | * | |
9 | * Redistribution and use in source and binary forms, with or without | |
10 | * modification, are permitted provided that the following conditions | |
11 | * are met: | |
12 | * 1. Redistributions of source code must retain the above copyright | |
13 | * notice, this list of conditions and the following disclaimer. | |
14 | * 2. Redistributions in binary form must reproduce the above copyright | |
15 | * notice, this list of conditions and the following disclaimer in the | |
16 | * documentation and/or other materials provided with the distribution. | |
17 | * 3. Neither the name of the project nor the names of its contributors | |
18 | * may be used to endorse or promote products derived from this software | |
19 | * without specific prior written permission. | |
20 | * | |
21 | * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND | |
22 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | |
23 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE | |
24 | * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE | |
25 | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL | |
26 | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS | |
27 | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) | |
28 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT | |
29 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY | |
30 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF | |
31 | * SUCH DAMAGE. | |
32 | */ | |
33 | ||
34 | #include "config.h" | |
35 | ||
36 | #include <stdio.h> | |
37 | #include <stdlib.h> | |
38 | #include <string.h> | |
39 | #if TIME_WITH_SYS_TIME | |
40 | # include <sys/time.h> | |
41 | # include <time.h> | |
42 | #else | |
43 | # if HAVE_SYS_TIME_H | |
44 | # include <sys/time.h> | |
45 | # else | |
46 | # include <time.h> | |
47 | # endif | |
48 | #endif | |
49 | #include <sys/param.h> | |
50 | #include <sys/queue.h> | |
51 | #include <sys/socket.h> | |
52 | ||
53 | #include <netinet/in.h> | |
54 | ||
55 | #include "vmbuf.h" | |
56 | #include "misc.h" | |
57 | #include "plog.h" | |
58 | #include "throttle.h" | |
59 | #include "sockmisc.h" | |
60 | #include "libpfkey.h" | |
61 | #include "isakmp_var.h" | |
62 | #include "isakmp.h" | |
63 | #include "isakmp_xauth.h" | |
64 | #include "isakmp_cfg.h" | |
65 | #include "gcmalloc.h" | |
66 | ||
67 | struct throttle_list throttle_list = TAILQ_HEAD_INITIALIZER(throttle_list); | |
68 | ||
69 | ||
70 | struct throttle_entry * | |
71 | throttle_add(addr) | |
85f41bec | 72 | struct sockaddr_storage *addr; |
52b7d2ce A |
73 | { |
74 | struct throttle_entry *te; | |
75 | size_t len; | |
76 | ||
77 | len = sizeof(*te) | |
78 | - sizeof(struct sockaddr_storage) | |
85f41bec | 79 | + sysdep_sa_len((struct sockaddr *)addr); |
52b7d2ce A |
80 | |
81 | if ((te = racoon_malloc(len)) == NULL) | |
82 | return NULL; | |
83 | ||
84 | te->penalty = time(NULL) + isakmp_cfg_config.auth_throttle; | |
85f41bec | 85 | memcpy(&te->host, addr, sysdep_sa_len((struct sockaddr *)addr)); |
52b7d2ce A |
86 | TAILQ_INSERT_HEAD(&throttle_list, te, next); |
87 | ||
88 | return te; | |
89 | } | |
90 | ||
91 | int | |
92 | throttle_host(addr, authfail) | |
85f41bec | 93 | struct sockaddr_storage *addr; |
52b7d2ce A |
94 | int authfail; |
95 | { | |
96 | struct throttle_entry *te; | |
97 | int found = 0; | |
98 | time_t now; | |
99 | ||
100 | if (isakmp_cfg_config.auth_throttle == 0) | |
101 | return 0; | |
102 | ||
103 | now = time(NULL); | |
104 | ||
d1e348cf | 105 | restart: |
52b7d2ce | 106 | TAILQ_FOREACH_REVERSE(te, &throttle_list, throttle_list, next) { |
d1e348cf A |
107 | /* |
108 | * Remove outdated entries | |
109 | */ | |
52b7d2ce A |
110 | if (te->penalty < now) { |
111 | TAILQ_REMOVE(&throttle_list, te, next); | |
112 | racoon_free(te); | |
d1e348cf | 113 | goto restart; |
52b7d2ce A |
114 | } |
115 | ||
85f41bec | 116 | if (cmpsaddrwop(addr, (struct sockaddr_storage *)&te->host) == 0) { |
52b7d2ce A |
117 | found = 1; |
118 | break; | |
119 | } | |
120 | } | |
121 | ||
122 | /* | |
123 | * No match, if auth failed, allocate a new throttle entry | |
124 | * give no penalty even on error: this is the first time | |
125 | * and we are indulgent. | |
126 | */ | |
127 | if (!found) { | |
128 | if (authfail) { | |
129 | if ((te = throttle_add(addr)) == NULL) { | |
65c25746 | 130 | plog(ASL_LEVEL_ERR, |
52b7d2ce A |
131 | "Throttle insertion failed\n"); |
132 | return (time(NULL) | |
133 | + isakmp_cfg_config.auth_throttle); | |
134 | } | |
135 | } | |
136 | return 0; | |
137 | } else { | |
138 | /* | |
139 | * We had a match and auth failed, increase penalty. | |
140 | */ | |
141 | if (authfail) { | |
142 | time_t remaining; | |
143 | time_t new; | |
144 | ||
145 | remaining = te->penalty - now; | |
146 | new = remaining + isakmp_cfg_config.auth_throttle; | |
147 | ||
148 | if (new > THROTTLE_PENALTY_MAX) | |
149 | new = THROTTLE_PENALTY_MAX; | |
150 | ||
151 | te->penalty = now + new; | |
152 | } | |
153 | } | |
154 | ||
155 | return te->penalty; | |
156 | } | |
157 |