View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0001115 | unreal | ircd | public | 2003-07-13 11:56 | 2003-11-20 19:43 |
| Reporter | capitaine | Assigned To | syzop | ||
| Priority | normal | Severity | tweak | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Summary | 0001115: Allow blocks does not work for localhost | ||||
| Description | sample from my conf (Unreal3.2-beta17): class clients { pingfreq 90; maxclients 350; sendq 100000; }; allow { ip *@*; hostname *@*; class clients; maxperip 4; }; allow { ip *@127.0.0.1; hostname *@localhost; class clients; password "toto"; maxperip 20; }; Localhost is limited to 4 connections and does not have a required password. I also suppressed the 1st *@* allow block, and no connexion ever was possible from localhost. I also tried swapping the 2 blocks : same pb. Replaced localhost/127.0.0.1 with another public ip address, then the restrictions apply properly. | ||||
| 3rd party modules | |||||
|
|
Can you give a little more info, such as your OS, also if, after connecting to the server you type /userhost your_nick_here what does it say? The reason I ask is I just added: allow { ip *@127.0.0.1; hostname *@localhost; class clients; maxperip 5; }; to my unrealircd.conf under Windows XP (thats the only allow block in the conf) and it works perfectly. |
|
|
I have an IPv6 enabled server and I experience a problem similar to capitaine's. I used capitaine's allow blocks with one change, so the class is "opers" in the second allow block. /Stats output: 218 Y:vodafone:8:0:1000:100000 218 Y:servers:90:100:10:1000000 218 Y:opers:120:0:1000:100000 218 Y:clients:120:0:1000:100000 218 Y:default:120:0:100:3000000 219 Y : End of /STATS report 215 I:*@127.0.0.1:*:*@localhost:20:opers 215 I:*@*:*:*@*:4:clients 219 I : End of /STATS report If I try to connect (by sending the correct password of course), I don't belong to class opers. *** Notice -- Client connecting on port 6667: wolf (~wolf@localhost) [clients] 302 wolf is ~wolf@localhost And after removing the *@* allow block, I can't connect any more: ERROR :Closing Link: wolf[0:0:0:0:0:0:0:1] (You are not authorized to connect to this server) I tested codemastr's allow block too, and I got the same error as above. Oh, forgot to say: SuSE Linux 8.1 Linux ip1 2.4.18-4GB #1 Fri Apr 5 15:14:39 UTC 2002 i686 unknown gcc version 2.95.3 20010315 (SuSE) edited on: 07-13-03 18:41 |
|
|
umm no kidding... ERROR :Closing Link: wolf[___0:0:0:0:0:0:0:1___] (You are not authorized to connect to this server) See that IP there? Does that look like 127.0.0.1? Cause it doesn't to me. Thats why you can't connect. Change it to *@0:0:0:0:0:0:1 and then you can connect. |
|
|
Well, no, allow { ip *@0:0:0:0:0:0:0:1; hostname *@localhost; class opers; #password "toto"; maxperip 20; }; *** * Closing Link: localhost[0:0:0:0:0:0:0:1] (You are not authorized to connect to this server) And... can I quote a part from unrealircd.conf? "About matching The access control works like this: ip matches OR host matches" Why is that my host doesn't match? |
|
|
I run it under Debian : Linux noname 2.4.18 #1 Tue Dec 17 11:49:53 CET 2002 i686 unknown Netstat report only tcp & udp, so I guess IPv6 is not setup (I'm not root) userhost says : userhost test :Cool.chat 302 test :test=+user@localhost At the moment, I have 4 bots from 127.0.01, I tried to override by user@* mask : allow { ip *@*; hostname *@*; class clients; maxperip 4; }; allow { ip localtest@*; hostname localtest@*; class clients; maxperip 1000; }; telneting : telnet localhost 6667 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'. :Cool.chat NOTICE AUTH :*** Looking up your hostname... :Cool.chat NOTICE AUTH :*** Found your hostname (cached) user localtest 0 0 :0 nick tttt ERROR :Closing Link: tttt[localhost] (Too many connections from your IP) Connection closed by foreign host. |
|
|
Known bug to me (null struct somewhere in auth check, don't remember it fully), the weird workaround is to use 'ip "*@localhost";' [yes, localhost in ip, that's correct]. |
|
|
thanks you, it works, I need this access control. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2003-07-13 11:56 | capitaine | New Issue | |
| 2003-07-13 16:49 |
|
Note Added: 0003222 | |
| 2003-07-13 18:26 | AngryWolf | Note Added: 0003223 | |
| 2003-07-13 18:41 | AngryWolf | Note Edited: 0003223 | |
| 2003-07-13 18:41 |
|
Note Added: 0003224 | |
| 2003-07-13 19:05 | AngryWolf | Note Added: 0003226 | |
| 2003-07-13 19:20 | capitaine | Note Added: 0003227 | |
| 2003-07-17 22:06 | syzop | Note Added: 0003258 | |
| 2003-07-17 22:07 | syzop | Status | new => acknowledged |
| 2003-07-19 00:57 | capitaine | Note Added: 0003286 | |
| 2003-09-05 21:01 | syzop | Status | acknowledged => resolved |
| 2003-09-05 21:01 | syzop | Resolution | open => fixed |
| 2003-09-05 21:01 | syzop | Assigned To | => syzop |
| 2003-11-20 19:43 | syzop | Status | resolved => closed |