Commit graph

2 commits

Author SHA1 Message Date
d6bcae54c8
fix(xdp): two RST-challenge bugs found by live kernel testing
Found on real kernel 5.15 (netns+veth, challenge enabled):
1. truncated IP: after bpf_xdp_adjust_tail the IPv4 tot_len / IPv6
   payload_len still claimed the original SYN size — peer silently
   dropped the malformed SYN-ACK, challenge never seen
2. endianness: marker/bad_ack written as raw host-order halfwords into
   network-order tcpw[] — client echoed swap16halves(bad_ack) in its
   RST.seq, verification always failed (CHAL_FAILED == CHAL_SENT)

Post-fix e2e: SYN -> bad-ACK SYN-ACK (XDP_TX) -> client RST ->
verified -> retry connects transparently; counters SENT=1 VERIFIED=1
FAILED=0
2026-08-24 13:06:10 +02:00
aa787a558c
feat: traffic intel hot path, SYN RST-challenge, XDP environment diagnostics
Traffic Intel (was dead code, now wired):
- TrafficHook in listener accept path: cps/pps windows -> AttackDetector
- auto-ban IPs below reputation threshold under attack ([detect.autoban])
- AlertDispatcher: webhook on attack state transition only (dedup), metrics
  AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url

XDP SYN RST-challenge (Oubliette pattern, off by default):
- G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX,
  spoofed sources stay silent, live clients answer RST with secret echo ->
  challenge_verified (LRU, sliding TTL); brute-force of marker impossible
- maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic
  in xdp/core/syn_challenge.h (221 lines)

XDP diagnostics (src/xdp/diagnostics.rs):
- EnvironmentReport: kernel version/BTF/driver->AttachMode verdict,
  fail-fast before load on unsupported kernels; wired into  CLI
- SystemProbe trait for kernel-less testing

fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed

cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
2026-08-24 10:11:10 +02:00