3 Commits
v8 ... v11

Author SHA1 Message Date
Auke Kok 5503ff0b20 Possibly handle journald restarts better.
I've encountered two runaway tallow daemons now that seem to
coincide with journald restarts that send it spinning tight
on the `continue` statement and hitting the same _get_data()
error (ENOENT).

I'm unsure if the `break` will fix it, but the `continue`
is definitely broken here. Hopefully the `sd_journal_wait()`
will properly reassess the journal state and notify us of
rotations or other issues.
2018-06-25 12:13:30 -07:00
Auke Kok 8655223248 Remove HUP/TERM/INT sighandler, shield USR1 sighandler.
We remove, by default, all signal handlers. The USR1 handler
remains, but is shielded behind `#ifdef DEBUG`.
2018-03-28 09:44:06 -07:00
Auke Kok 76a59df0f1 Fine-tune blocking rules one notch down.
Before, most rules would block on the 3rd rule hit, with this,
it's 4, which means 1 extra failure before a 1hr block is started
and this is a bit more sympathetic towards `typo` failures.
2018-03-23 16:17:34 -07:00
4 changed files with 21 additions and 35 deletions
+1 -1
View File
@@ -2,7 +2,7 @@
# Process this file with autoconf to produce a configure script. # Process this file with autoconf to produce a configure script.
AC_PREREQ([2.64]) AC_PREREQ([2.64])
AC_INIT([tallow], [8], [auke-jan.h.kok@intel.com]) AC_INIT([tallow], [11], [auke-jan.h.kok@intel.com])
AM_INIT_AUTOMAKE([foreign]) AM_INIT_AUTOMAKE([foreign])
AC_CONFIG_FILES([Makefile]) AC_CONFIG_FILES([Makefile])
+2 -2
View File
@@ -1,7 +1,7 @@
.\" generated with Ronn/v0.7.3 .\" generated with Ronn/v0.7.3
.\" http://github.com/rtomayko/ronn/tree/0.7.3 .\" http://github.com/rtomayko/ronn/tree/0.7.3
. .
.TH "TALLOW" "1" "January 2018" "" "" .TH "TALLOW" "1" "March 2018" "" ""
. .
.SH "NAME" .SH "NAME"
\fBtallow\fR \fBtallow\fR
@@ -28,7 +28,7 @@ Care should be taken to assure that legitimate users are not blocked inadvertent
The \fBtallow\fR daemon itself has no runtime configuration\. All configuration is done through the tallow\.conf(5) config file\. The \fBtallow\fR daemon itself has no runtime configuration\. All configuration is done through the tallow\.conf(5) config file\.
. .
.SH "SIGNALS" .SH "SIGNALS"
The \fBUSR1\fR signal causes \fBtallow\fR to print out it\'s internal tracking table of IP addresses\. The \fBUSR1\fR signal causes \fBtallow\fR to print out it\'s internal tracking table of IP addresses\. This requires that tallow is compiled with the \fB\-DDEBUG=1\fR symbol passed to the compiler\.
. .
.SH "SEE ALSO" .SH "SEE ALSO"
systemd\-journald(1), iptables(1), ipset(1), tallow\.conf(5) systemd\-journald(1), iptables(1), ipset(1), tallow\.conf(5)
+2 -1
View File
@@ -43,7 +43,8 @@ configuration is done through the tallow.conf(5) config file.
## SIGNALS ## SIGNALS
The `USR1` signal causes `tallow` to print out it's internal tracking The `USR1` signal causes `tallow` to print out it's internal tracking
table of IP addresses. table of IP addresses. This requires that tallow is compiled with
the `-DDEBUG=1` symbol passed to the compiler.
## SEE ALSO ## SEE ALSO
+16 -31
View File
@@ -58,15 +58,15 @@ struct pattern_struct {
#define PATTERN_COUNT 10 #define PATTERN_COUNT 10
static struct pattern_struct patterns[PATTERN_COUNT] = { static struct pattern_struct patterns[PATTERN_COUNT] = {
{ 0, 0.4, "MESSAGE=Failed .* for .* from ([0-9a-z:.]+) port \\d+ ssh2", NULL}, { 0, 0.3, "MESSAGE=Failed .* for .* from ([0-9a-z:.]+) port \\d+ ssh2", NULL},
{ 0, 0.4, "MESSAGE=error: PAM: Authentication failure for .* from ([0-9a-z:.]+)", NULL}, { 0, 0.3, "MESSAGE=error: PAM: Authentication failure for .* from ([0-9a-z:.]+)", NULL},
{15, 0.3, "MESSAGE=Invalid user .* from ([0-9a-z:.]+) port \\d+", NULL}, {15, 0.3, "MESSAGE=Invalid user .* from ([0-9a-z:.]+) port \\d+", NULL},
{15, 0.3, "MESSAGE=Did not receive identification string from ([0-9a-z:.]+) port \\d+", NULL}, {15, 0.3, "MESSAGE=Did not receive identification string from ([0-9a-z:.]+) port \\d+", NULL},
{30, 0.3, "MESSAGE=Failed .* for root from ([0-9a-z:.]+) port \\d+ ssh2", NULL}, {15, 0.4, "MESSAGE=Bad protocol version identification .* from ([0-9a-z:.]+)", NULL},
{15, 0.6, "MESSAGE=Bad protocol version identification .* from ([0-9a-z:.]+)", NULL}, {15, 0.4, "MESSAGE=Connection closed by authenticating user .* ([0-9a-z:.]+) port \\d+", NULL},
{15, 0.6, "MESSAGE=Connection closed by authenticating user .* ([0-9a-z:.]+) port \\d+", NULL}, {15, 0.4, "MESSAGE=Received disconnect from ([0-9a-z:.]+) port .*\\[preauth\\]", NULL},
{15, 0.6, "MESSAGE=Received disconnect from ([0-9a-z:.]+) port .*\\[preauth\\]", NULL}, {15, 0.4, "MESSAGE=Connection closed by ([0-9a-z:.]+) port .*\\[preauth\\]", NULL},
{15, 0.6, "MESSAGE=Connection closed by ([0-9a-z:.]+) port .*\\[preauth\\]", NULL}, {30, 0.5, "MESSAGE=Failed .* for root from ([0-9a-z:.]+) port \\d+ ssh2", NULL},
{60, 0.6, "MESSAGE=Unable to negotiate with ([0-9a-z:.]+) port \\d+: no matching key exchange method found.", NULL} {60, 0.6, "MESSAGE=Unable to negotiate with ([0-9a-z:.]+) port \\d+: no matching key exchange method found.", NULL}
}; };
@@ -284,23 +284,7 @@ static void find(const char *ip, float weight, int instant_block)
return; return;
} }
static void sig(int u __attribute__ ((unused))) #ifdef DEBUG
{
fprintf(stderr, "Exiting on request.\n");
sd_journal_close(j);
struct tallow_struct *s = head;
while (s) {
struct tallow_struct *n = NULL;
free(s->ip);
n = s;
s = s->next;
free(n);
}
exit(EXIT_SUCCESS);
}
static void sigusr1(int u __attribute__ ((unused))) static void sigusr1(int u __attribute__ ((unused)))
{ {
fprintf(stderr, "Dumping score list on request:\n"); fprintf(stderr, "Dumping score list on request:\n");
@@ -310,6 +294,7 @@ static void sigusr1(int u __attribute__ ((unused)))
s = s->next; s = s->next;
} }
} }
#endif
static void prune(void) static void prune(void)
{ {
@@ -354,20 +339,17 @@ int main(void)
{ {
int r; int r;
FILE *f; FILE *f;
struct sigaction s;
int timeout = 60; int timeout = 60;
strcpy(ipt_path, "/usr/sbin"); strcpy(ipt_path, "/usr/sbin");
memset(&s, 0, sizeof(struct sigaction)); #ifdef DEBUG
s.sa_handler = sig; struct sigaction s;
sigaction(SIGHUP, &s, NULL);
sigaction(SIGTERM, &s, NULL);
sigaction(SIGINT, &s, NULL);
memset(&s, 0, sizeof(struct sigaction)); memset(&s, 0, sizeof(struct sigaction));
s.sa_handler = sigusr1; s.sa_handler = sigusr1;
sigaction(SIGUSR1, &s, NULL); sigaction(SIGUSR1, &s, NULL);
#endif
if (access("/proc/sys/net/ipv6", R_OK | X_OK) == 0) if (access("/proc/sys/net/ipv6", R_OK | X_OK) == 0)
has_ipv6 = 1; has_ipv6 = 1;
@@ -452,6 +434,9 @@ int main(void)
if (r == SD_JOURNAL_INVALIDATE) { if (r == SD_JOURNAL_INVALIDATE) {
fprintf(stderr, "Journal was rotated, resetting\n"); fprintf(stderr, "Journal was rotated, resetting\n");
sd_journal_seek_tail(j); sd_journal_seek_tail(j);
} else if (r == SD_JOURNAL_NOP) {
dbg("Timeout reached, waiting again\n");
continue;
} }
while (sd_journal_next(j) != 0) { while (sd_journal_next(j) != 0) {
@@ -459,7 +444,7 @@ int main(void)
if (sd_journal_get_data(j, "MESSAGE", &d, &l) < 0) { if (sd_journal_get_data(j, "MESSAGE", &d, &l) < 0) {
fprintf(stderr, "Failed to read message field: %s\n", strerror(-r)); fprintf(stderr, "Failed to read message field: %s\n", strerror(-r));
continue; break;
} }
m = strndup(d, l+1); m = strndup(d, l+1);