1 /* 2 * Copyright (c) 2020 Darren Tucker <dtucker@openbsd.org> 3 * 4 * Permission to use, copy, modify, and distribute this software for any 5 * purpose with or without fee is hereby granted, provided that the above 6 * copyright notice and this permission notice appear in all copies. 7 * 8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 15 */ 16 struct xaddr; 17 18 struct per_source_penalty; 19 20 void srclimit_init(int, int, int, int, 21 struct per_source_penalty *, const char *); 22 int srclimit_check_allow(int, int); 23 void srclimit_done(int); 24 25 #define SRCLIMIT_PENALTY_NONE 0 26 #define SRCLIMIT_PENALTY_CRASH 1 27 #define SRCLIMIT_PENALTY_AUTHFAIL 2 28 #define SRCLIMIT_PENALTY_GRACE_EXCEEDED 3 29 #define SRCLIMIT_PENALTY_NOAUTH 4 30 #define SRCLIMIT_PENALTY_REFUSECONNECTION 5 31 32 /* meaningful exit values, used by sshd listener for penalties */ 33 #define EXIT_LOGIN_GRACE 3 /* login grace period exceeded */ 34 #define EXIT_CHILD_CRASH 4 /* preauth child crashed */ 35 #define EXIT_AUTH_ATTEMPTED 5 /* at least one auth attempt made */ 36 #define EXIT_CONFIG_REFUSED 6 /* sshd_config RefuseConnection */ 37 38 void srclimit_penalise(struct xaddr *, int); 39 int srclimit_penalty_check_allow(int, const char **); 40 void srclimit_penalty_info(void); 41