feat: HTTP protocol plugin + XDP globals patching from config
protocol-http (compile-time feature): - HttpHandler: incremental HTTP/1.1 request parse (fragment-safe), header size/timeout limits, method whitelist, Host required, blocked_paths, optional User-Agent requirement - [protocol.http] config section; registry wiring behind feature XDP globals: - src/xdp/globals.rs: XdpGlobals + build_rodata_image() mirroring xdp/core/config.h layout; set via OpenMapMut::set_initial_value() before load ([xdp] section: ports, udp policy, throttle, challenge) - wire set_globals into rampart binary startup fix: gate preflight() behind xdp feature (dead code without it)
This commit is contained in:
parent
8b35ac693c
commit
6863249ad4
14 changed files with 972 additions and 22 deletions
|
|
@ -89,3 +89,54 @@ webhook_url = "https://hooks.example.test/rampart"
|
|||
Some("https://hooks.example.test/rampart")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn xdp_section_defaults() {
|
||||
let config = Config::parse_str("").expect("empty config must parse");
|
||||
let xdp = &config.xdp;
|
||||
assert_eq!(xdp.protected_port_start, 1);
|
||||
assert_eq!(xdp.protected_port_end, 65535);
|
||||
assert_eq!(xdp.udp_policy, "pass");
|
||||
assert_eq!(xdp.udp_rate_hit_count, 100);
|
||||
assert_eq!(xdp.udp_rate_window_ms, 1000);
|
||||
assert!(!xdp.syn_challenge_enabled);
|
||||
assert!(xdp.challenge_secret_hex.is_none());
|
||||
assert_eq!(xdp.challenge_timeout_ms, 3000);
|
||||
assert!(xdp.throttle_enabled);
|
||||
assert!(xdp.events_enabled);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_xdp_section() {
|
||||
let config = Config::parse_str(
|
||||
r#"
|
||||
[xdp]
|
||||
enabled = true
|
||||
interface = "ens3"
|
||||
protected_port_start = 25560
|
||||
protected_port_end = 25600
|
||||
udp_policy = "drop"
|
||||
udp_rate_hit_count = 250
|
||||
udp_rate_window_ms = 500
|
||||
syn_challenge_enabled = true
|
||||
challenge_secret_hex = "dead_beef_dead_beef"
|
||||
challenge_timeout_ms = 1500
|
||||
throttle_enabled = false
|
||||
events_enabled = false
|
||||
"#,
|
||||
)
|
||||
.expect("[xdp] section must parse");
|
||||
let xdp = &config.xdp;
|
||||
assert!(xdp.enabled);
|
||||
assert_eq!(xdp.interface, "ens3");
|
||||
assert_eq!(xdp.protected_port_start, 25560);
|
||||
assert_eq!(xdp.protected_port_end, 25600);
|
||||
assert_eq!(xdp.udp_policy, "drop");
|
||||
assert_eq!(xdp.udp_rate_hit_count, 250);
|
||||
assert_eq!(xdp.udp_rate_window_ms, 500);
|
||||
assert!(xdp.syn_challenge_enabled);
|
||||
assert_eq!(xdp.challenge_secret_hex.as_deref(), Some("dead_beef_dead_beef"));
|
||||
assert_eq!(xdp.challenge_timeout_ms, 1500);
|
||||
assert!(!xdp.throttle_enabled);
|
||||
assert!(!xdp.events_enabled);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue