fix: avoid useless "Failed authentication attempt" logs (#39602)

This commit is contained in:
wxiaoguang
2026-10-05 16:45:50 +08:00
committed by GitHub
parent fc44404843
commit b71967b254
4 changed files with 20 additions and 18 deletions
+14 -7
View File
@@ -84,23 +84,30 @@ func (srv *sshServer) serve(listener net.Listener) error {
}
func (srv *sshServer) handleConn(netConn net.Conn) {
ctx, cancel := context.WithCancel(graceful.GetManager().HammerContext())
defer cancel()
defer netConn.Close()
conn, chans, reqs, err := gossh.NewServerConn(netConn, srv.newServerConfig(ctx))
ctx, cancel := context.WithCancel(graceful.GetManager().HammerContext())
defer cancel()
sshConn, sshChannels, sshReqs, err := gossh.NewServerConn(netConn, srv.newServerConfig(ctx))
if err != nil {
sshConnectionFailed(netConn, err)
// OpenSSH's logs are something like:
// * disconnect without sending anything: "Connection closed by 1.2.3.4 port 5678"
// * send invalid bytes: "banner exchange: Connection from 1.2.3.4 port 5678: invalid format"
// * preauth failed: "Connection closed by authenticating user SYSOP 1.2.3.4 port 5678 [preauth]"
// * successfully logon and disconnect: "Disconnected from user SYSOP 1.2.3.4 port 5678"
log.Warn("Failed connection from %s with error: %v", netConn.RemoteAddr(), err)
return
}
defer sshConn.Close()
go gossh.DiscardRequests(reqs)
for newChan := range chans {
go gossh.DiscardRequests(sshReqs)
for newChan := range sshChannels {
if newChan.ChannelType() != "session" {
_ = newChan.Reject(gossh.UnknownChannelType, "unsupported channel type")
continue
}
go handleSessionChannel(ctx, conn, newChan)
go handleSessionChannel(ctx, sshConn, newChan)
}
}
-9
View File
@@ -250,15 +250,6 @@ func publicKeyHandler(ctx context.Context, conn gossh.ConnMetadata, key gossh.Pu
return keyPermissions(pkey.ID), nil
}
// sshConnectionFailed logs a failed connection
// - this mainly exists to give a nice function name in logging
func sshConnectionFailed(conn net.Conn, err error) {
// Log the underlying error with a specific message
log.Warn("Failed connection from %s with error: %v", conn.RemoteAddr(), err)
// Log with the standard failed authentication from message for simpler fail2ban configuration
log.Warn("Failed authentication attempt from %s", conn.RemoteAddr())
}
// Listen starts an SSH server listening on given port.
func Listen(host string, port int, ciphers, keyExchanges, macs []string) {
hostKeyFiles := make([]string, 0, len(setting.SSH.ServerHostKeys))