564613b82d
feat: rampart-tui — live metrics terminal dashboard
...
- ratatui + crossterm; separate bin reading Prometheus exposition format
- counter table (xdp stats, auto-bans, intel), pps/drops history chart,
status panel with error banner, q/quit r/refresh
- prometheus text parser (labels, escapes, NaN/Inf), Fetcher trait for tests
- 152 tests green
2026-08-24 12:35:09 +02:00
6863249ad4
feat: HTTP protocol plugin + XDP globals patching from config
...
protocol-http (compile-time feature):
- HttpHandler: incremental HTTP/1.1 request parse (fragment-safe),
header size/timeout limits, method whitelist, Host required,
blocked_paths, optional User-Agent requirement
- [protocol.http] config section; registry wiring behind feature
XDP globals:
- src/xdp/globals.rs: XdpGlobals + build_rodata_image() mirroring
xdp/core/config.h layout; set via OpenMapMut::set_initial_value()
before load ([xdp] section: ports, udp policy, throttle, challenge)
- wire set_globals into rampart binary startup
fix: gate preflight() behind xdp feature (dead code without it)
2026-08-24 12:18:22 +02:00
8b35ac693c
fix: universal default protected port range (was Minecraft 25565-25570)
...
Verified on real kernel 5.15.0-186 (VDS, netns+veth, generic XDP):
- verifier accepts program, all maps created (BTF ok)
- legit TCP passes end-to-end; conntrack entry cleaned on close
- stats counters increment correctly; prefix_stats /24 key populated
- LPM blacklist ban blocks traffic with retransmit drops
2026-08-24 11:18:57 +02:00
aa787a558c
feat: traffic intel hot path, SYN RST-challenge, XDP environment diagnostics
...
Traffic Intel (was dead code, now wired):
- TrafficHook in listener accept path: cps/pps windows -> AttackDetector
- auto-ban IPs below reputation threshold under attack ([detect.autoban])
- AlertDispatcher: webhook on attack state transition only (dedup), metrics
AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url
XDP SYN RST-challenge (Oubliette pattern, off by default):
- G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX,
spoofed sources stay silent, live clients answer RST with secret echo ->
challenge_verified (LRU, sliding TTL); brute-force of marker impossible
- maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic
in xdp/core/syn_challenge.h (221 lines)
XDP diagnostics (src/xdp/diagnostics.rs):
- EnvironmentReport: kernel version/BTF/driver->AttachMode verdict,
fail-fast before load on unsupported kernels; wired into CLI
- SystemProbe trait for kernel-less testing
fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed
cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
2026-08-24 10:11:10 +02:00
40bfe956e2
feat: subnet-level attack detection (prefix_stats)
...
- XDP: prefix_stats LRU map, per-/24 (v4) and /64 (v6) SYN/packet counters,
incremented post-blacklist/throttle (xdp/core/prefix_stats.h)
- userspace: SubnetDetector escalation ladder Monitor->StrictLimit->Challenge->Block
with spoof-gate (Block requires >= min_unique_sources, CGNAT-safe)
- config: [detect.prefix] section (enabled=false by default)
- fallback without XDP: engine SubnetTracker aggregates connections per-prefix
- fix: PrefixStatsVal::from_bytes for xdp feature build; prefix_len 24 vs 64
cargo build/clippy(-D warnings, all features)/test green: 83 tests
2026-08-24 09:47:21 +02:00
15f474486a
feat!: universal redesign — drop Minecraft stack, single-crate architecture
...
- remove Java plugins (velocity/paper), dashboard, all MC-specific code
(handshake, death_code, varint, hostname-HMAC); available in history pre-v0.2
- merge crates/* into one package with src/bin/{rampart,rampart-manager,rampart-cli}
- ProtocolHandler trait + registry (no implementations yet), universal PoW kept
- XDP: universal L3/L4 filter (xdp/core/) + pluggable hook API (xdp/hooks/),
fix IPv6 saddr bug; clang build verified
- docs: bilingual knowledge base (docs/kb/: attacks x4, defense-levels,
practice x3), rewrite README/architecture for universal concept
- TODO.md v4.0: <=300-line module limit, competitor benchmark section (ref/)
- deploy/CI/docs cleanup: no MC references, new binary names
cargo build/clippy(-D warnings)/test green (55 tests)
2026-08-24 01:50:22 +02:00
0b53ed720b
feat: VDS stress test harness (edge-only) and load-test results
...
- deploy/test/stress/: multi-IP masked handshake flood (flood.py), legit client
during attack (legit.py), full orchestration (run-stress.sh), edge Dockerfile
with socat stub backend and high/defense configs
- docs/research/load-test-report.md: v3 VDS loopback results (2026-08-04)
- README.md: performance table update (4k conn/s raw, 99.6% blocked in defense,
legit clients RTT 2-6ms during attack)
- docs/testing.md: multi-IP masked stress-test procedure
2026-08-04 19:16:27 +02:00
d41bd6e815
fix: download Paper jar on CI runner and COPY into image
2026-08-03 12:13:45 +02:00
0db4fd867b
fix: force identity encoding for PaperMC API and download in Dockerfile.paper
2026-08-03 12:08:47 +02:00
2e4c50ab4a
fix: request compressed JSON from PaperMC v3 API in Dockerfile.paper
2026-08-03 12:02:13 +02:00
b446fd4f7b
fix: allow too_many_arguments in ProxyListener::new, add make to edge Dockerfile
2026-08-03 11:51:53 +02:00
29ce6fb8e9
feat: velocity routing, server registry and RampartVelocity tests
2026-08-03 10:54:28 +02:00
fa6de281fb
fix: restore download-artifact path plugins/ (artifact strips root dir)
2026-07-21 16:42:08 +02:00
35d20e97db
fix: clippy byte_char_slices lint, Docker java artifact path
2026-07-21 16:34:30 +02:00
997da7fbd3
fix: add libbpf-dev for xdp clang headers, update papermc download API to fill.papermc.io/v3
2026-07-21 16:20:49 +02:00
c828915560
fix: cargo-deny CDLA-Permissive-2.0, build.rs asm include path, eclipse-temurin noble tag
2026-07-21 16:16:07 +02:00
e7631f918a
fix: update Dockerfile to rust:slim-bookworm, install libelf-dev in CI
2026-07-21 16:08:33 +02:00
705521ade9
fix: remove deploy/ from .dockerignore (Dockerfiles need deploy/config)
2026-07-21 15:56:58 +02:00
95be20abd3
fix: track Cargo.lock (required for Docker build)
2026-07-21 15:56:40 +02:00
269daa071f
v0.3: 6-layer architecture complete
...
Layers:
Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf
Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify
Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing)
Layer 4: Velocity — Physics check, CAPTCHA, protocol verification
Layer 5: Paper — Heartbeat, auto-registration (existing)
Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts
Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose
Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report
Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup
Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
2026-07-21 15:47:36 +02:00
78fc6e00c7
Add yellow warning banner (dev/disclaimer) and clean .gitignore
2026-07-20 20:56:13 +02:00
cf9608ce5d
Initial commit: Rampart v0.2.0
...
Multi-layer DDoS protection for Minecraft servers.
- rampart-core: Edge node with XDP/eBPF + Rust L7 filtering
- rampart-manager: REST API with JWT auth, Redis sync
- rampart-cli: CLI tool for operators
- velocity-plugin: Domain check, HMAC verify, server registry, load balancer
- paper-plugin: Auto-registration, heartbeat, HMAC verify
- dashboard: React + Vite web UI for management
2026-07-20 20:53:32 +02:00