feat!: universal redesign — drop Minecraft stack, single-crate architecture

- remove Java plugins (velocity/paper), dashboard, all MC-specific code
  (handshake, death_code, varint, hostname-HMAC); available in history pre-v0.2
- merge crates/* into one package with src/bin/{rampart,rampart-manager,rampart-cli}
- ProtocolHandler trait + registry (no implementations yet), universal PoW kept
- XDP: universal L3/L4 filter (xdp/core/) + pluggable hook API (xdp/hooks/),
  fix IPv6 saddr bug; clang build verified
- docs: bilingual knowledge base (docs/kb/: attacks x4, defense-levels,
  practice x3), rewrite README/architecture for universal concept
- TODO.md v4.0: <=300-line module limit, competitor benchmark section (ref/)
- deploy/CI/docs cleanup: no MC references, new binary names

cargo build/clippy(-D warnings)/test green (55 tests)
This commit is contained in:
loki5512344 2026-08-24 01:50:22 +02:00
parent 0b53ed720b
commit 15f474486a
Signed by: boba
GPG key ID: 253067914055423B
179 changed files with 5044 additions and 11519 deletions

View file

@ -48,8 +48,8 @@ run_flood_phase() {
local ba bb bp
ba=$(mget 'rampart_connections_total{result="allowed"}')
bb=$(mget 'rampart_connections_total{result="blocked"}')
bp=$(mget 'rampart_pow_challenges_total{result="failed"}')
echo "baseline: allowed=$ba blocked=$bb pow_fail=$bp"
bp=$(mget 'rampart_rate_limit_hits')
echo "baseline: allowed=$ba blocked=$bb rate_limit_hits=$bp"
docker exec rampart-attacker python3 /flood.py \
--target "$EDGE_IP" --port 25565 --mode "$mode" \
@ -68,10 +68,10 @@ run_flood_phase() {
local a bl p s cpu
a=$(mget 'rampart_connections_total{result="allowed"}')
bl=$(mget 'rampart_connections_total{result="blocked"}')
p=$(mget 'rampart_pow_challenges_total{result="failed"}')
p=$(mget 'rampart_rate_limit_hits')
s=$(mget 'rampart_attack_status ')
cpu=$(edge_cpu)
echo " [t=${i}x5s] status=$s cpu=$cpu allowed=+$((a - ba)) blocked=+$((bl - bb)) pow_fail=+$((p - bp))"
echo " [t=${i}x5s] status=$s cpu=$cpu allowed=+$((a - ba)) blocked=+$((bl - bb)) rate_limit_hits=+$((p - bp))"
done
wait "$flood_pid" || true
@ -80,14 +80,14 @@ run_flood_phase() {
local ea eb ep es ec
ea=$(mget 'rampart_connections_total{result="allowed"}')
eb=$(mget 'rampart_connections_total{result="blocked"}')
ep=$(mget 'rampart_pow_challenges_total{result="failed"}')
ep=$(mget 'rampart_rate_limit_hits')
es=$(mget 'rampart_attack_status ')
ec=$(edge_cpu)
echo "--- итог фазы $phase ---"
echo " attack_status=$es cpu=$ec"
echo " allowed: $((ea - ba)) (+$(( (ea - ba) / duration ))/s)"
echo " blocked: $((eb - bb)) (+$(( (eb - bb) / duration ))/s)"
echo " pow_fail: $((ep - bp))"
echo " rate_limit_hits: $((ep - bp))"
echo "--- легитимные клиенты во время фазы ---"
grep -E '^\[phase' /tmp/legit_$phase.log || true
echo ""
@ -101,12 +101,12 @@ docker network create --subnet "$SUB" "$NET" >/dev/null
# Подготовка контекстов: бинарь ищем в target/release репозитория
mkdir -p "$DIR/edge-ctx" "$DIR/attacker-ctx"
cp "$DIR/flood.py" "$DIR/attacker-ctx/flood.py" 2>/dev/null || true
if [ ! -f "$DIR/edge-ctx/rampart-core" ]; then
for p in "$DIR/rampart-core" "$DIR/repo/target/release/rampart-core" "$DIR/../target/release/rampart-core"; do
if [ -f "$p" ]; then cp "$p" "$DIR/edge-ctx/rampart-core"; break; fi
if [ ! -f "$DIR/edge-ctx/rampart" ]; then
for p in "$DIR/rampart" "$DIR/repo/target/release/rampart" "$DIR/../../target/release/rampart"; do
if [ -f "$p" ]; then cp "$p" "$DIR/edge-ctx/rampart"; break; fi
done
fi
[ -f "$DIR/edge-ctx/rampart-core" ] || { echo "ERROR: rampart-core не найден. Собери: cargo build --release --bin rampart-core" >&2; exit 1; }
[ -f "$DIR/edge-ctx/rampart" ] || { echo "ERROR: rampart не найден. Собери: cargo build --release --bin rampart" >&2; exit 1; }
docker build -q -f "$DIR/edge.Dockerfile" -t rampart-edge "$DIR/edge-ctx"
docker build -q -f "$DIR/attacker.Dockerfile" -t rampart-attacker "$DIR/attacker-ctx"
@ -124,34 +124,30 @@ docker exec rampart-attacker sh -c '
echo ""
echo "############### PHASE A: СЫРАЯ ПРОПУСКНАЯ СПОСОБНОСТЬ ###############"
echo "############### (лимиты сняты: 100k pps, 100 src IP, валидные handshake) ###############"
run_flood_phase A edge-high.toml 30 handshake 100 "$IPS_END" "raw throughput, 100 IP flood, valid handshake"
echo "############### (лимиты сняты: 100k conn/s, 100 src IP, TCP connect flood) ###############"
run_flood_phase A edge-high.toml 30 connect 100 "$IPS_END" "raw throughput, 100 IP TCP connect flood"
echo ""
echo "############### PHASE B: ЗАЩИТА (дефолтные лимиты 5 pps/IP) ###############"
echo "############### PHASE B: ЗАЩИТА (дефолтные лимиты 2 pps/IP) ###############"
echo "############### (та же атака, но теперь edge режет по IP; легитимные клиенты заходят) ###############"
run_flood_phase B edge-defense.toml 30 handshake 100 "$IPS_END" "defense, rate limit 5pps/IP + reputation bans"
run_flood_phase B edge-defense.toml 30 connect 100 "$IPS_END" "defense, rate limit + reputation bans"
echo ""
echo "############### PHASE C: SYN flood ###############"
echo "=============================================================="
echo "ФАЗА C: SYN flood hping3 (rand-source, 20s)"
echo "=============================================================="
ba=$(mget 'rampart_connections_total{result="allowed"}')
bb=$(mget 'rampart_connections_total{result="blocked"}')
timeout 20 docker exec rampart-attacker hping3 -S --flood --rand-source -p 25565 "$EDGE_IP" || true
sleep 2
ea=$(mget 'rampart_connections_total{result="allowed"}')
eb=$(mget 'rampart_connections_total{result="blocked"}')
es=$(mget 'rampart_attack_status ')
echo " attack_status=$es cpu=$(edge_cpu) allowed=+$((ea - ba)) blocked=+$((eb - bb))"
echo " attack_status=$es cpu=$(edge_cpu)"
echo " (SYN flood обрабатывается kernel'ом/XDP, L7 edge почти не задет)"
echo ""
echo ""
echo "############### PHASE D: активные соединения (keepalive) ###############"
echo "=============================================================="
echo "ФАЗА D: 300 keepalive коннектов (валидный handshake, держим открытым)"
echo "ФАЗА D: 300 keepalive коннектов (держим открытыми)"
echo "=============================================================="
start_edge edge-high.toml
ba=$(mget 'rampart_connections_total{result="allowed"}')
@ -166,7 +162,7 @@ echo ""
echo "=============================================================="
echo "ИТОГОВЫЙ СВОД"
echo "=============================================================="
edge_metrics | grep -E 'connections_total|pow_challenges|attack_status'
edge_metrics | grep -E 'connections_total|rate_limit_hits|attack_status'
echo ""
echo "CPU/память контейнеров:"
docker stats --no-stream --format 'table {{.Name}}\t{{.CPUPerc}}\t{{.MemUsage}}' rampart-edge rampart-attacker