fix: XDP unsafe loader + Redis sync; enforce 250-line/4-file layout limits

- xdp: CString for if_nametoindex (was UB), real detach via prog fd
  (fabricated borrow_raw(-1) silently never detached), SAFETY comments,
  saturating expiry math; +5 unit tests
- redis: real pubsub reconnect with exponential backoff (was sleep+return);
  KEYS -> SCAN in heartbeat sweep
- ci: cargo test --all-features, repo-gates job — module size gate
  (scripts/check_module_size.sh, ratchet baseline) + default-secrets grep
- refactor src/ to <=250 LOC/file, <=4 .rs/dir without behavior change;
  thin bins (rampart.rs 330 -> 6 LOC), new app/, subnet/, intel/,
  profile/, prefix/, challenge/, filter/, probe/, inventory/, metrics/, node/
- docs: TODO v5.0 (status refresh, new rules, findings backlog),
  README quickstart now matches real binaries
- verify: fmt/clippy -D warnings/test --all-features (164 tests)/clang XDP green
This commit is contained in:
loki5512344 2026-09-15 23:55:17 +02:00
parent d6bcae54c8
commit aa615a1141
Signed by: boba
GPG key ID: 253067914055423B
64 changed files with 2052 additions and 1408 deletions

View file

@ -3,10 +3,10 @@
CARGO = cargo
TARGET_DIR = target
.PHONY: all build release test check check-all fmt fmt-check clippy clean deny audit
.PHONY: all build release test test-all check check-all fmt fmt-check clippy clean deny audit
.PHONY: ebpf ebpf-clean
.PHONY: docker docker-build docker-up docker-down docker-logs
.PHONY: ci ci-full
.PHONY: ci ci-full repo-gates
all: check test build
@ -27,6 +27,9 @@ check-all:
test:
$(CARGO) test
test-all:
$(CARGO) test --all-features
fmt:
$(CARGO) fmt --all
@ -75,7 +78,11 @@ docker-logs:
checkstyle: fmt-check clippy
@echo "✓ Checkstyle passed (rustfmt + clippy)"
ci: checkstyle test build deny
repo-gates:
bash scripts/check_module_size.sh
bash scripts/check_default_secrets.sh
ci: checkstyle test-all build deny repo-gates
@echo "✓ CI passed"
ci-full: ci ebpf