fix: XDP unsafe loader + Redis sync; enforce 250-line/4-file layout limits

- xdp: CString for if_nametoindex (was UB), real detach via prog fd
  (fabricated borrow_raw(-1) silently never detached), SAFETY comments,
  saturating expiry math; +5 unit tests
- redis: real pubsub reconnect with exponential backoff (was sleep+return);
  KEYS -> SCAN in heartbeat sweep
- ci: cargo test --all-features, repo-gates job — module size gate
  (scripts/check_module_size.sh, ratchet baseline) + default-secrets grep
- refactor src/ to <=250 LOC/file, <=4 .rs/dir without behavior change;
  thin bins (rampart.rs 330 -> 6 LOC), new app/, subnet/, intel/,
  profile/, prefix/, challenge/, filter/, probe/, inventory/, metrics/, node/
- docs: TODO v5.0 (status refresh, new rules, findings backlog),
  README quickstart now matches real binaries
- verify: fmt/clippy -D warnings/test --all-features (164 tests)/clang XDP green
This commit is contained in:
loki5512344 2026-09-15 23:55:17 +02:00
parent d6bcae54c8
commit aa615a1141
Signed by: boba
GPG key ID: 253067914055423B
64 changed files with 2052 additions and 1408 deletions

View file

@ -0,0 +1,63 @@
#!/usr/bin/env bash
#
# check_default_secrets.sh — reject the placeholder secret "changeme"
# committed as a real value in code, deploy configs, or docs.
#
# Intentional occurrences are whitelisted in two layers:
# 1. File level — the validation code itself:
# src/bin/rampart-manager.rs (startup guard rejecting the default)
# src/manager/api/auth.rs (test constant)
# 2. Line level — only lines that *use* "changeme" as a value are reported.
# A matching line is skipped when it contains "must not be" or "test"
# (case-insensitive), states the prohibition ("запр" root: запрет /
# запрещено / запрещён — the project docs are partly Russian), or is a
# comment / markdown table row (starts with '#', '//', '*', '|', '--').
#
# Any remaining occurrence is an offender -> exit 1, offending lines listed.
set -u
PATTERN="changeme"
SCAN_DIRS="src deploy docs"
FILE_WHITELIST="src/bin/rampart-manager.rs src/manager/api/auth.rs"
cd "$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)" || exit 1
found=0
for dir in $SCAN_DIRS; do
[ -d "$dir" ] || continue
while IFS= read -r match; do
file="${match%%:*}"
rest="${match#*:}"
lineno="${rest%%:*}"
content="${rest#*:}"
skip=0
for whitelisted in $FILE_WHITELIST; do
[ "$file" = "$whitelisted" ] && skip=1
done
if printf '%s' "$content" | grep -qiE 'must not be|test|запр'; then
skip=1
fi
trimmed="${content#"${content%%[![:space:]]*}"}"
if [ "${trimmed:0:2}" = "//" ] || [ "${trimmed:0:2}" = "--" ]; then
skip=1
fi
case "${trimmed:0:1}" in
'#'|'*'|'|') skip=1 ;;
esac
if [ "$skip" -eq 0 ]; then
found=1
printf 'FAIL %s:%s: %s\n' "$file" "$lineno" "$trimmed" >&2
fi
done < <(grep -rn --binary-files=without-match "$PATTERN" "$dir" 2>/dev/null)
done
if [ "$found" -ne 0 ]; then
echo "secrets gate: FAIL — 'changeme' used as a value (see lines above)" >&2
exit 1
fi
echo "secrets gate: PASS — no unexpected '$PATTERN' occurrences in: $SCAN_DIRS"
exit 0