Permit a duplicate knock just from the previous stage#90
Open
bobrippling wants to merge 4 commits intojvinet:masterfrom
Open
Permit a duplicate knock just from the previous stage#90bobrippling wants to merge 4 commits intojvinet:masterfrom
bobrippling wants to merge 4 commits intojvinet:masterfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is similar to #72 (only spotted this after I'd written up my solution!), but without the same brute-force concerns.
The difference is that we permit (ignore) a duplicate packet only if it matches the previous stage of the current sequence. I've added more details in the docs:
knock/doc/knockd.1.in
Lines 199 to 204 in 474330a
This also allows for browser based knocking, or knocking on a server who will drop packets, where (if we're using something like netcat) we'll send multiple TCP SYNs.