v0.3: 6-layer architecture complete
Layers: Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing) Layer 4: Velocity — Physics check, CAPTCHA, protocol verification Layer 5: Paper — Heartbeat, auto-registration (existing) Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
This commit is contained in:
parent
78fc6e00c7
commit
269daa071f
66 changed files with 4529 additions and 1003 deletions
64
Makefile
64
Makefile
|
|
@ -2,12 +2,19 @@
|
|||
|
||||
CARGO = cargo
|
||||
TARGET_DIR = target
|
||||
GRADLE = gradle
|
||||
GRADLE = ./gradlew
|
||||
|
||||
.PHONY: all build test check fmt clippy clean release plugins
|
||||
.PHONY: all build test check fmt clippy clean release
|
||||
.PHONY: deny audit ebpf
|
||||
.PHONY: plugins paper velocity
|
||||
.PHONY: docker docker-build docker-up docker-down docker-logs
|
||||
.PHONY: dash dash-dev dash-build
|
||||
.PHONY: ci ci-full
|
||||
|
||||
all: check test build
|
||||
|
||||
# --- Rust ---
|
||||
|
||||
build:
|
||||
$(CARGO) build
|
||||
|
||||
|
|
@ -17,6 +24,9 @@ release:
|
|||
check:
|
||||
$(CARGO) check
|
||||
|
||||
check-all:
|
||||
$(CARGO) check --all-features
|
||||
|
||||
test:
|
||||
$(CARGO) test
|
||||
|
||||
|
|
@ -27,13 +37,50 @@ fmt-check:
|
|||
$(CARGO) fmt --all --check
|
||||
|
||||
clippy:
|
||||
$(CARGO) clippy -- -D warnings
|
||||
$(CARGO) clippy --all-targets --all-features -- -D warnings
|
||||
|
||||
clean:
|
||||
$(CARGO) clean
|
||||
|
||||
deny:
|
||||
cargo deny check
|
||||
|
||||
audit:
|
||||
cargo audit
|
||||
|
||||
# --- eBPF / XDP ---
|
||||
|
||||
ebpf:
|
||||
@echo "Building XDP/eBPF filter..."
|
||||
cd xdp && clang -O2 -target bpf -c xdp_filter.c -o xdp_filter.o 2>/dev/null || \
|
||||
echo "WARNING: clang+bpf not installed, skipping eBPF build"
|
||||
|
||||
ebpf-clean:
|
||||
rm -f xdp/xdp_filter.o
|
||||
|
||||
# --- Java Plugins ---
|
||||
|
||||
plugins:
|
||||
cd plugins && ./gradlew build
|
||||
cd plugins && $(GRADLE) build
|
||||
|
||||
paper:
|
||||
cd plugins && $(GRADLE) :paper:build
|
||||
|
||||
velocity:
|
||||
cd plugins && $(GRADLE) :velocity:build
|
||||
|
||||
# --- Dashboard ---
|
||||
|
||||
dash-install:
|
||||
cd dashboard && npm ci
|
||||
|
||||
dash-dev:
|
||||
cd dashboard && npm run dev
|
||||
|
||||
dash-build:
|
||||
cd dashboard && npm run build
|
||||
|
||||
# --- Docker ---
|
||||
|
||||
docker-build: plugins
|
||||
docker compose -f deploy/docker-compose.yml build
|
||||
|
|
@ -47,8 +94,13 @@ docker-down:
|
|||
docker-logs:
|
||||
docker compose -f deploy/docker-compose.yml logs -f
|
||||
|
||||
# Full checkstyle (analog of Java's checkstyle + PMD + spotbugs)
|
||||
# --- Convenience ---
|
||||
|
||||
checkstyle: fmt-check clippy
|
||||
@echo "✓ Checkstyle passed (rustfmt + clippy)"
|
||||
|
||||
ci: checkstyle test build
|
||||
ci: checkstyle test build deny
|
||||
@echo "✓ CI passed"
|
||||
|
||||
ci-full: ci plugins dash-build
|
||||
@echo "✓ Full CI passed"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue