feat(xdp): auto-ban from ringbuf events; fix feature gating, exit path, pow flake
Some checks are pending
CI / Rust — check & clippy (push) Waiting to run
CI / Rust — test (push) Waiting to run
CI / Repo — module size & default secrets (push) Waiting to run
CI / Rust — cargo-deny (push) Waiting to run
CI / Docker — build edge image (push) Blocked by required conditions

- xdp: real 24-byte xdp_event parsing (fixes LE byte-swap of src IP),
  opt-in [xdp] auto_ban (RATE_LIMIT always, CONN_DROP at fails>=threshold;
  EVENT_BAN/POLICY_DROP excluded by design), rampart_xdp_autobans_total;
  wired in app before load(); 10 tests in tests/xdp_events.rs
- build: --no-default-features compiles — redis paths cfg-gated behind
  store-redis, manager fail-fasts without it; CI gates the config now
- app: RunExit enum replaces process::exit in lib; single exit site in main
- tests: seed PoW roundtrip token (was ~1/16 flaky; 50 pre-fix fails -> 0)
- docs: TODO statuses refreshed (round 2)
This commit is contained in:
loki5512344 2026-09-16 00:49:41 +02:00
parent aa615a1141
commit bd40a44980
Signed by: boba
GPG key ID: 253067914055423B
23 changed files with 714 additions and 50 deletions

View file

@ -1,5 +1,11 @@
use rampart::engine::challenge::{Challenge, solve};
/// Fixed 32-byte token: sha256(hex(token) || "garbage") starts with "ebc1",
/// so "garbage" provably fails the difficulty-2 check (first two hex chars
/// must be in "0123"). A random token made this flaky with probability 1/16
/// per run, since any digest lands in the accepted prefix with p=(4/16)^2.
const FIXED_TOKEN: [u8; 32] = *b"rampart-pow-fixed-token-test-v1!";
#[test]
fn solver_output_passes_verifier() {
let mut challenge = Challenge::generate(3);
@ -9,7 +15,7 @@ fn solver_output_passes_verifier() {
#[test]
fn verifier_rejects_garbage_and_replay() {
let mut challenge = Challenge::generate(2);
let mut challenge = Challenge::with_token(FIXED_TOKEN, 2);
assert!(!challenge.verify("garbage"));
let nonce = solve(&challenge.challenge_string(), 2).expect("solved");