feat: traffic intel hot path, SYN RST-challenge, XDP environment diagnostics
Traffic Intel (was dead code, now wired): - TrafficHook in listener accept path: cps/pps windows -> AttackDetector - auto-ban IPs below reputation threshold under attack ([detect.autoban]) - AlertDispatcher: webhook on attack state transition only (dedup), metrics AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url XDP SYN RST-challenge (Oubliette pattern, off by default): - G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX, spoofed sources stay silent, live clients answer RST with secret echo -> challenge_verified (LRU, sliding TTL); brute-force of marker impossible - maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic in xdp/core/syn_challenge.h (221 lines) XDP diagnostics (src/xdp/diagnostics.rs): - EnvironmentReport: kernel version/BTF/driver->AttachMode verdict, fail-fast before load on unsupported kernels; wired into CLI - SystemProbe trait for kernel-less testing fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
This commit is contained in:
parent
40bfe956e2
commit
aa787a558c
25 changed files with 1825 additions and 28 deletions
|
|
@ -61,3 +61,31 @@ fn rejects_invalid_whitelist_ip() {
|
|||
let result = Config::parse_str("whitelist = [\"10.0.0.999\"]");
|
||||
assert!(result.is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn detect_autoban_defaults_disabled() {
|
||||
let config = Config::parse_str("").expect("empty config must parse");
|
||||
assert!(!config.detect.autoban.enabled);
|
||||
assert_eq!(config.detect.autoban.reputation_threshold, -50);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_detect_sections() {
|
||||
let config = Config::parse_str(
|
||||
r#"
|
||||
[detect.autoban]
|
||||
enabled = true
|
||||
reputation_threshold = -30
|
||||
|
||||
[detect.alert]
|
||||
webhook_url = "https://hooks.example.test/rampart"
|
||||
"#,
|
||||
)
|
||||
.expect("detect sections must parse");
|
||||
assert!(config.detect.autoban.enabled);
|
||||
assert_eq!(config.detect.autoban.reputation_threshold, -30);
|
||||
assert_eq!(
|
||||
config.detect.alert.webhook_url.as_deref(),
|
||||
Some("https://hooks.example.test/rampart")
|
||||
);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue