mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
The tun device will be closed only after the disconnect script has been called.
This allows gathering statistics from it. In addition, changed behavior of script calling, and now will always contain the IP information.
This commit is contained in:
@@ -2,6 +2,9 @@
|
||||
|
||||
- Execute disconnect script for users that their IP was hijacked by a
|
||||
cookie reconnection.
|
||||
- If a disconnect script is set, the tun device will be closed only after
|
||||
the disconnect script has been called. This allows gathering statistics
|
||||
from it.
|
||||
|
||||
|
||||
* Version 0.3.3 (released 2014-04-08)
|
||||
|
||||
+1
-1
@@ -415,7 +415,7 @@ unsigned int entries = 1; /* that one */
|
||||
/* steal its leases */
|
||||
proc->ipv4 = ctmp->ipv4;
|
||||
proc->ipv6 = ctmp->ipv6;
|
||||
ctmp->ipv4 = ctmp->ipv6 = NULL;
|
||||
ctmp->leases_in_use = 1;
|
||||
|
||||
kill(ctmp->pid, SIGTERM);
|
||||
} else if (strcmp(proc->username, ctmp->username) == 0) {
|
||||
|
||||
+4
-2
@@ -312,8 +312,10 @@ void remove_proc(main_server_st * s, struct proc_st *proc, unsigned k)
|
||||
if (proc->auth_ctx != NULL)
|
||||
proc_auth_deinit(s, proc);
|
||||
|
||||
if (proc->ipv4 || proc->ipv6)
|
||||
remove_ip_leases(s, proc);
|
||||
if (!proc->leases_in_use) {
|
||||
if (proc->ipv4 || proc->ipv6)
|
||||
remove_ip_leases(s, proc);
|
||||
}
|
||||
|
||||
if (proc->tun_lease.fd >= 0)
|
||||
close(proc->tun_lease.fd);
|
||||
|
||||
@@ -87,6 +87,7 @@ struct proc_st {
|
||||
struct tun_lease_st tun_lease;
|
||||
struct ip_lease_st *ipv4;
|
||||
struct ip_lease_st *ipv6;
|
||||
unsigned leases_in_use; /* someone else got our IP leases */
|
||||
|
||||
struct sockaddr_storage remote_addr; /* peer address */
|
||||
socklen_t remote_addr_len;
|
||||
|
||||
@@ -225,10 +225,6 @@ rekey-method = ssl
|
||||
# IPV6_LOCAL (the IPv6 local address if there are both IPv4 and IPv6
|
||||
# assigned), IPV6_REMOVE (the IPv6 remote address), and
|
||||
# ID (a unique numeric ID); REASON may be "connect" or "disconnect".
|
||||
#
|
||||
# Note that a "disconnect" call will not contain the IP information
|
||||
# of the client, if the client has reconnected with a cookie (and thus
|
||||
# re-used its IP addresses).
|
||||
|
||||
#connect-script = /usr/bin/myscript
|
||||
#disconnect-script = /usr/bin/myscript
|
||||
|
||||
Reference in New Issue
Block a user