feat(xdp): auto-ban from ringbuf events; fix feature gating, exit path, pow flake
Some checks are pending
CI / Rust — check & clippy (push) Waiting to run
CI / Rust — test (push) Waiting to run
CI / Repo — module size & default secrets (push) Waiting to run
CI / Rust — cargo-deny (push) Waiting to run
CI / Docker — build edge image (push) Blocked by required conditions
Some checks are pending
CI / Rust — check & clippy (push) Waiting to run
CI / Rust — test (push) Waiting to run
CI / Repo — module size & default secrets (push) Waiting to run
CI / Rust — cargo-deny (push) Waiting to run
CI / Docker — build edge image (push) Blocked by required conditions
- xdp: real 24-byte xdp_event parsing (fixes LE byte-swap of src IP), opt-in [xdp] auto_ban (RATE_LIMIT always, CONN_DROP at fails>=threshold; EVENT_BAN/POLICY_DROP excluded by design), rampart_xdp_autobans_total; wired in app before load(); 10 tests in tests/xdp_events.rs - build: --no-default-features compiles — redis paths cfg-gated behind store-redis, manager fail-fasts without it; CI gates the config now - app: RunExit enum replaces process::exit in lib; single exit site in main - tests: seed PoW roundtrip token (was ~1/16 flaky; 50 pre-fix fails -> 0) - docs: TODO statuses refreshed (round 2)
This commit is contained in:
parent
aa615a1141
commit
bd40a44980
23 changed files with 714 additions and 50 deletions
|
|
@ -1,6 +1,9 @@
|
|||
#[cfg(feature = "store-redis")]
|
||||
use crate::manager::AppState;
|
||||
#[cfg(feature = "store-redis")]
|
||||
use axum::{Json, extract::State};
|
||||
use serde::{Deserialize, Serialize};
|
||||
#[cfg(feature = "store-redis")]
|
||||
use std::sync::Arc;
|
||||
|
||||
#[derive(Debug, Serialize, Deserialize)]
|
||||
|
|
@ -29,6 +32,7 @@ pub struct AddBlacklistRequest {
|
|||
pub duration_secs: Option<u64>,
|
||||
}
|
||||
|
||||
#[cfg(feature = "store-redis")]
|
||||
pub async fn list_blacklist(State(state): State<Arc<AppState>>) -> Json<BlacklistResponse> {
|
||||
let mut conn = match state.redis_client.get_multiplexed_async_connection().await {
|
||||
Ok(c) => c,
|
||||
|
|
@ -69,6 +73,7 @@ pub async fn list_blacklist(State(state): State<Arc<AppState>>) -> Json<Blacklis
|
|||
Json(BlacklistResponse { items, total })
|
||||
}
|
||||
|
||||
#[cfg(feature = "store-redis")]
|
||||
pub async fn add_blacklist(
|
||||
State(state): State<Arc<AppState>>,
|
||||
Json(req): Json<AddBlacklistRequest>,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue