feat!: universal redesign — drop Minecraft stack, single-crate architecture
- remove Java plugins (velocity/paper), dashboard, all MC-specific code
(handshake, death_code, varint, hostname-HMAC); available in history pre-v0.2
- merge crates/* into one package with src/bin/{rampart,rampart-manager,rampart-cli}
- ProtocolHandler trait + registry (no implementations yet), universal PoW kept
- XDP: universal L3/L4 filter (xdp/core/) + pluggable hook API (xdp/hooks/),
fix IPv6 saddr bug; clang build verified
- docs: bilingual knowledge base (docs/kb/: attacks x4, defense-levels,
practice x3), rewrite README/architecture for universal concept
- TODO.md v4.0: <=300-line module limit, competitor benchmark section (ref/)
- deploy/CI/docs cleanup: no MC references, new binary names
cargo build/clippy(-D warnings)/test green (55 tests)
This commit is contained in:
parent
0b53ed720b
commit
15f474486a
179 changed files with 5044 additions and 11519 deletions
63
tests/config_parse.rs
Normal file
63
tests/config_parse.rs
Normal file
|
|
@ -0,0 +1,63 @@
|
|||
use rampart::config::Config;
|
||||
|
||||
#[test]
|
||||
fn parses_minimal_config_with_defaults() {
|
||||
let config = Config::parse_str("").expect("empty config must parse with defaults");
|
||||
assert_eq!(config.bind.address, "0.0.0.0");
|
||||
assert_eq!(config.bind.port, 25565);
|
||||
assert_eq!(config.backend.upstreams, vec!["127.0.0.1:25566"]);
|
||||
assert_eq!(config.workers.count, 4);
|
||||
assert!(!config.pow.enabled);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_full_config() {
|
||||
let config = Config::parse_str(
|
||||
r#"
|
||||
[bind]
|
||||
port = 8443
|
||||
|
||||
[backend]
|
||||
upstreams = ["10.0.0.1:9000", "10.0.0.2:9000"]
|
||||
|
||||
[limits]
|
||||
rate_limit_pps = 50.0
|
||||
|
||||
[pow]
|
||||
enabled = true
|
||||
difficulty = 5
|
||||
|
||||
[store]
|
||||
redis_url = "redis://localhost:6379/1"
|
||||
clickhouse_url = "http://localhost:8123"
|
||||
|
||||
whitelist = ["203.0.113.7"]
|
||||
"#,
|
||||
)
|
||||
.expect("full config must parse");
|
||||
|
||||
assert_eq!(config.bind.port, 8443);
|
||||
assert_eq!(config.backend.upstreams.len(), 2);
|
||||
assert!((config.limits.rate_limit_pps - 50.0).abs() < f64::EPSILON);
|
||||
assert!(config.pow.enabled);
|
||||
assert_eq!(config.pow.difficulty, 5);
|
||||
assert_eq!(config.store.redis_url.as_deref(), Some("redis://localhost:6379/1"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_empty_upstreams() {
|
||||
let err = Config::parse_str("[backend]\nupstreams = []\n").expect_err("must reject empty upstream list");
|
||||
assert!(err.to_string().contains("upstreams"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_malformed_upstream_address() {
|
||||
let result = Config::parse_str("[backend]\nupstreams = [\"example.invalid\"]\n");
|
||||
assert!(result.is_err(), "hostname-only upstreams are not supported");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_invalid_whitelist_ip() {
|
||||
let result = Config::parse_str("whitelist = [\"10.0.0.999\"]");
|
||||
assert!(result.is_err());
|
||||
}
|
||||
56
tests/filter_logic.rs
Normal file
56
tests/filter_logic.rs
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
use std::net::{IpAddr, Ipv4Addr};
|
||||
use std::time::Duration;
|
||||
|
||||
use rampart::filter::blacklist::Blacklist;
|
||||
use rampart::filter::rate_limit::RateLimiter;
|
||||
|
||||
fn ip(octet: u8) -> IpAddr {
|
||||
IpAddr::V4(Ipv4Addr::new(192, 168, 0, octet))
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rate_limiter_allows_burst_then_blocks() {
|
||||
let limiter = RateLimiter::new(1.0, 3.0);
|
||||
for _ in 0..3 {
|
||||
assert!(limiter.check(ip(1)), "burst tokens must be available");
|
||||
}
|
||||
assert!(!limiter.check(ip(1)), "exhausted bucket must block");
|
||||
assert!(limiter.check(ip(2)), "other IPs are independent buckets");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rate_limiter_refills_over_time() {
|
||||
let limiter = RateLimiter::new(100.0, 1.0);
|
||||
assert!(limiter.check(ip(3)));
|
||||
assert!(!limiter.check(ip(3)));
|
||||
std::thread::sleep(Duration::from_millis(30));
|
||||
assert!(limiter.check(ip(3)), "tokens must refill at configured rate");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rate_limiter_buckets_are_independent() {
|
||||
let limiter = RateLimiter::new(1.0, 1.0);
|
||||
assert!(limiter.check(ip(4)));
|
||||
assert!(!limiter.check(ip(4)));
|
||||
assert!(limiter.check(ip(5)), "other IPs are independent buckets");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn blacklist_blocks_until_ttl_expires() {
|
||||
let blacklist = Blacklist::new();
|
||||
blacklist.add(ip(6), Duration::from_millis(30), "test");
|
||||
|
||||
assert!(blacklist.is_blocked(ip(6)), "fresh ban must block");
|
||||
assert_eq!(blacklist.len(), 1);
|
||||
std::thread::sleep(Duration::from_millis(40));
|
||||
assert!(!blacklist.is_blocked(ip(6)), "expired ban must not block");
|
||||
assert!(blacklist.is_empty(), "expired entry must be dropped on check");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn blacklist_remove_clears_ban() {
|
||||
let blacklist = Blacklist::new();
|
||||
blacklist.add(ip(7), Duration::from_secs(60), "test");
|
||||
blacklist.remove(ip(7));
|
||||
assert!(!blacklist.is_blocked(ip(7)));
|
||||
}
|
||||
18
tests/pow_roundtrip.rs
Normal file
18
tests/pow_roundtrip.rs
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
use rampart::engine::challenge::{Challenge, solve};
|
||||
|
||||
#[test]
|
||||
fn solver_output_passes_verifier() {
|
||||
let mut challenge = Challenge::generate(3);
|
||||
let nonce = solve(&challenge.challenge_string(), 3).expect("solver must find nonce for difficulty 3");
|
||||
assert!(challenge.verify(&nonce));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn verifier_rejects_garbage_and_replay() {
|
||||
let mut challenge = Challenge::generate(2);
|
||||
assert!(!challenge.verify("garbage"));
|
||||
|
||||
let nonce = solve(&challenge.challenge_string(), 2).expect("solved");
|
||||
assert!(challenge.verify(&nonce), "first use passes");
|
||||
assert!(!challenge.verify(&nonce), "replay is rejected");
|
||||
}
|
||||
38
tests/protocol_registry.rs
Normal file
38
tests/protocol_registry.rs
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
use std::future::Future;
|
||||
use std::pin::Pin;
|
||||
|
||||
use rampart::protocol::{ProtocolHandler, ProtocolRegistry, Upstream};
|
||||
use tokio::net::TcpStream;
|
||||
|
||||
struct NoopHandler;
|
||||
|
||||
impl ProtocolHandler for NoopHandler {
|
||||
fn name(&self) -> &'static str {
|
||||
"noop"
|
||||
}
|
||||
|
||||
fn handshake<'a>(
|
||||
&'a self,
|
||||
_stream: &'a mut TcpStream,
|
||||
) -> Pin<Box<dyn Future<Output = anyhow::Result<Upstream>> + Send + 'a>> {
|
||||
Box::pin(async { Ok(Upstream::new("127.0.0.1:9000")) })
|
||||
}
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn empty_registry_reports_missing_protocols() {
|
||||
let registry = ProtocolRegistry::new();
|
||||
assert!(registry.is_empty());
|
||||
let err = registry.primary().err().expect("empty registry must fail fast");
|
||||
assert!(err.to_string().contains("no protocol plugins compiled"));
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn registered_handler_resolves_by_name() {
|
||||
let mut registry = ProtocolRegistry::new();
|
||||
registry.register(Box::new(NoopHandler));
|
||||
|
||||
assert_eq!(registry.names(), vec!["noop"]);
|
||||
let handler = registry.primary().expect("registered handler must resolve");
|
||||
assert_eq!(handler.name(), "noop");
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue