diff --git a/NEWS b/NEWS index 63b84456..1dc2aa52 100644 --- a/NEWS +++ b/NEWS @@ -2,6 +2,9 @@ - Execute disconnect script for users that their IP was hijacked by a cookie reconnection. +- If a disconnect script is set, the tun device will be closed only after + the disconnect script has been called. This allows gathering statistics + from it. * Version 0.3.3 (released 2014-04-08) diff --git a/src/main-auth.c b/src/main-auth.c index a3fba50f..07a19c24 100644 --- a/src/main-auth.c +++ b/src/main-auth.c @@ -415,7 +415,7 @@ unsigned int entries = 1; /* that one */ /* steal its leases */ proc->ipv4 = ctmp->ipv4; proc->ipv6 = ctmp->ipv6; - ctmp->ipv4 = ctmp->ipv6 = NULL; + ctmp->leases_in_use = 1; kill(ctmp->pid, SIGTERM); } else if (strcmp(proc->username, ctmp->username) == 0) { diff --git a/src/main-misc.c b/src/main-misc.c index 85948c85..f6cfaa5b 100644 --- a/src/main-misc.c +++ b/src/main-misc.c @@ -312,8 +312,10 @@ void remove_proc(main_server_st * s, struct proc_st *proc, unsigned k) if (proc->auth_ctx != NULL) proc_auth_deinit(s, proc); - if (proc->ipv4 || proc->ipv6) - remove_ip_leases(s, proc); + if (!proc->leases_in_use) { + if (proc->ipv4 || proc->ipv6) + remove_ip_leases(s, proc); + } if (proc->tun_lease.fd >= 0) close(proc->tun_lease.fd); diff --git a/src/main.h b/src/main.h index 8065e1b3..55da3369 100644 --- a/src/main.h +++ b/src/main.h @@ -87,6 +87,7 @@ struct proc_st { struct tun_lease_st tun_lease; struct ip_lease_st *ipv4; struct ip_lease_st *ipv6; + unsigned leases_in_use; /* someone else got our IP leases */ struct sockaddr_storage remote_addr; /* peer address */ socklen_t remote_addr_len; diff --git a/src/ocserv-args.def b/src/ocserv-args.def index a3146b5f..e11dfc93 100644 --- a/src/ocserv-args.def +++ b/src/ocserv-args.def @@ -225,10 +225,6 @@ rekey-method = ssl # IPV6_LOCAL (the IPv6 local address if there are both IPv4 and IPv6 # assigned), IPV6_REMOVE (the IPv6 remote address), and # ID (a unique numeric ID); REASON may be "connect" or "disconnect". -# -# Note that a "disconnect" call will not contain the IP information -# of the client, if the client has reconnected with a cookie (and thus -# re-used its IP addresses). #connect-script = /usr/bin/myscript #disconnect-script = /usr/bin/myscript