v0.3: 6-layer architecture complete

Layers:
  Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf
  Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify
  Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing)
  Layer 4: Velocity — Physics check, CAPTCHA, protocol verification
  Layer 5: Paper — Heartbeat, auto-registration (existing)
  Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts

Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose
Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report
Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup
Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
This commit is contained in:
loki5512344 2026-07-21 15:47:36 +02:00
parent 78fc6e00c7
commit 269daa071f
Signed by: boba
GPG key ID: 253067914055423B
66 changed files with 4529 additions and 1003 deletions

View file

@ -4,8 +4,11 @@ use crate::filter::blacklist::Blacklist;
use crate::filter::death_code;
use crate::filter::rate_limit::RateLimiter;
use crate::metrics;
use crate::pow::difficulty::DifficultyAdjuster;
use crate::proxy::handshake::{McHandshake, read_varint};
use std::sync::Arc;
use crate::proxy::pow::handle_pow;
use std::net::Ipv4Addr;
use std::sync::{Arc, Mutex};
use std::time::Duration;
use tokio::io::{AsyncReadExt, AsyncWriteExt};
use tokio::net::TcpStream;
@ -14,14 +17,21 @@ pub struct ConnectionHandler {
config: Arc<Config>,
rate_limiter: Arc<RateLimiter>,
blacklist: Arc<Blacklist>,
adjuster: Arc<Mutex<DifficultyAdjuster>>,
}
impl ConnectionHandler {
pub fn new(config: Arc<Config>, rate_limiter: Arc<RateLimiter>, blacklist: Arc<Blacklist>) -> Self {
pub fn new(
config: Arc<Config>,
rate_limiter: Arc<RateLimiter>,
blacklist: Arc<Blacklist>,
adjuster: Arc<Mutex<DifficultyAdjuster>>,
) -> Self {
Self {
config,
rate_limiter,
blacklist,
adjuster,
}
}
@ -40,6 +50,31 @@ impl ConnectionHandler {
return Ok(());
}
let pow_config = &self.config.pow;
let peer_ip = Ipv4Addr::from_bits(ip_u32);
if pow_config.enabled && pow_config.difficulty > 0 && !self.config.whitelist.contains(&peer_ip.to_string()) {
self.adjuster
.lock()
.expect("adjuster lock poisoned")
.record_connection();
let diff = self
.adjuster
.lock()
.expect("adjuster lock poisoned")
.current_difficulty();
let result = handle_pow(&mut client, peer_ip, diff).await?;
if !result {
metrics::POW_CHALLENGES_TOTAL.with_label_values(&["failed"]).inc();
tracing::debug!("pow: failed for {peer_ip}, dropping connection");
return Ok(());
}
metrics::POW_CHALLENGES_TOTAL.with_label_values(&["passed"]).inc();
metrics::POW_CURRENT_DIFFICULTY.set(diff as i64);
} else if pow_config.enabled && pow_config.difficulty > 0 {
metrics::POW_CHALLENGES_TOTAL.with_label_values(&["skipped"]).inc();
metrics::POW_CURRENT_DIFFICULTY.set(pow_config.difficulty as i64);
}
if !self.rate_limiter.check(ip_u32) {
metrics::RATE_LIMIT_HITS.with_label_values(&["hit"]).inc();
metrics::CONNECTIONS_TOTAL.with_label_values(&["blocked"]).inc();