v0.3: 6-layer architecture complete
Layers: Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing) Layer 4: Velocity — Physics check, CAPTCHA, protocol verification Layer 5: Paper — Heartbeat, auto-registration (existing) Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
This commit is contained in:
parent
78fc6e00c7
commit
269daa071f
66 changed files with 4529 additions and 1003 deletions
|
|
@ -4,8 +4,11 @@ use crate::filter::blacklist::Blacklist;
|
|||
use crate::filter::death_code;
|
||||
use crate::filter::rate_limit::RateLimiter;
|
||||
use crate::metrics;
|
||||
use crate::pow::difficulty::DifficultyAdjuster;
|
||||
use crate::proxy::handshake::{McHandshake, read_varint};
|
||||
use std::sync::Arc;
|
||||
use crate::proxy::pow::handle_pow;
|
||||
use std::net::Ipv4Addr;
|
||||
use std::sync::{Arc, Mutex};
|
||||
use std::time::Duration;
|
||||
use tokio::io::{AsyncReadExt, AsyncWriteExt};
|
||||
use tokio::net::TcpStream;
|
||||
|
|
@ -14,14 +17,21 @@ pub struct ConnectionHandler {
|
|||
config: Arc<Config>,
|
||||
rate_limiter: Arc<RateLimiter>,
|
||||
blacklist: Arc<Blacklist>,
|
||||
adjuster: Arc<Mutex<DifficultyAdjuster>>,
|
||||
}
|
||||
|
||||
impl ConnectionHandler {
|
||||
pub fn new(config: Arc<Config>, rate_limiter: Arc<RateLimiter>, blacklist: Arc<Blacklist>) -> Self {
|
||||
pub fn new(
|
||||
config: Arc<Config>,
|
||||
rate_limiter: Arc<RateLimiter>,
|
||||
blacklist: Arc<Blacklist>,
|
||||
adjuster: Arc<Mutex<DifficultyAdjuster>>,
|
||||
) -> Self {
|
||||
Self {
|
||||
config,
|
||||
rate_limiter,
|
||||
blacklist,
|
||||
adjuster,
|
||||
}
|
||||
}
|
||||
|
||||
|
|
@ -40,6 +50,31 @@ impl ConnectionHandler {
|
|||
return Ok(());
|
||||
}
|
||||
|
||||
let pow_config = &self.config.pow;
|
||||
let peer_ip = Ipv4Addr::from_bits(ip_u32);
|
||||
if pow_config.enabled && pow_config.difficulty > 0 && !self.config.whitelist.contains(&peer_ip.to_string()) {
|
||||
self.adjuster
|
||||
.lock()
|
||||
.expect("adjuster lock poisoned")
|
||||
.record_connection();
|
||||
let diff = self
|
||||
.adjuster
|
||||
.lock()
|
||||
.expect("adjuster lock poisoned")
|
||||
.current_difficulty();
|
||||
let result = handle_pow(&mut client, peer_ip, diff).await?;
|
||||
if !result {
|
||||
metrics::POW_CHALLENGES_TOTAL.with_label_values(&["failed"]).inc();
|
||||
tracing::debug!("pow: failed for {peer_ip}, dropping connection");
|
||||
return Ok(());
|
||||
}
|
||||
metrics::POW_CHALLENGES_TOTAL.with_label_values(&["passed"]).inc();
|
||||
metrics::POW_CURRENT_DIFFICULTY.set(diff as i64);
|
||||
} else if pow_config.enabled && pow_config.difficulty > 0 {
|
||||
metrics::POW_CHALLENGES_TOTAL.with_label_values(&["skipped"]).inc();
|
||||
metrics::POW_CURRENT_DIFFICULTY.set(pow_config.difficulty as i64);
|
||||
}
|
||||
|
||||
if !self.rate_limiter.check(ip_u32) {
|
||||
metrics::RATE_LIMIT_HITS.with_label_values(&["hit"]).inc();
|
||||
metrics::CONNECTIONS_TOTAL.with_label_values(&["blocked"]).inc();
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue