Commit graph

21 commits

Author SHA1 Message Date
6863249ad4
feat: HTTP protocol plugin + XDP globals patching from config
protocol-http (compile-time feature):
- HttpHandler: incremental HTTP/1.1 request parse (fragment-safe),
  header size/timeout limits, method whitelist, Host required,
  blocked_paths, optional User-Agent requirement
- [protocol.http] config section; registry wiring behind feature

XDP globals:
- src/xdp/globals.rs: XdpGlobals + build_rodata_image() mirroring
  xdp/core/config.h layout; set via OpenMapMut::set_initial_value()
  before load ([xdp] section: ports, udp policy, throttle, challenge)
- wire set_globals into rampart binary startup

fix: gate preflight() behind xdp feature (dead code without it)
2026-08-24 12:18:22 +02:00
8b35ac693c
fix: universal default protected port range (was Minecraft 25565-25570)
Verified on real kernel 5.15.0-186 (VDS, netns+veth, generic XDP):
- verifier accepts program, all maps created (BTF ok)
- legit TCP passes end-to-end; conntrack entry cleaned on close
- stats counters increment correctly; prefix_stats /24 key populated
- LPM blacklist ban blocks traffic with retransmit drops
2026-08-24 11:18:57 +02:00
aa787a558c
feat: traffic intel hot path, SYN RST-challenge, XDP environment diagnostics
Traffic Intel (was dead code, now wired):
- TrafficHook in listener accept path: cps/pps windows -> AttackDetector
- auto-ban IPs below reputation threshold under attack ([detect.autoban])
- AlertDispatcher: webhook on attack state transition only (dedup), metrics
  AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url

XDP SYN RST-challenge (Oubliette pattern, off by default):
- G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX,
  spoofed sources stay silent, live clients answer RST with secret echo ->
  challenge_verified (LRU, sliding TTL); brute-force of marker impossible
- maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic
  in xdp/core/syn_challenge.h (221 lines)

XDP diagnostics (src/xdp/diagnostics.rs):
- EnvironmentReport: kernel version/BTF/driver->AttachMode verdict,
  fail-fast before load on unsupported kernels; wired into  CLI
- SystemProbe trait for kernel-less testing

fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed

cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
2026-08-24 10:11:10 +02:00
40bfe956e2
feat: subnet-level attack detection (prefix_stats)
- XDP: prefix_stats LRU map, per-/24 (v4) and /64 (v6) SYN/packet counters,
  incremented post-blacklist/throttle (xdp/core/prefix_stats.h)
- userspace: SubnetDetector escalation ladder Monitor->StrictLimit->Challenge->Block
  with spoof-gate (Block requires >= min_unique_sources, CGNAT-safe)
- config: [detect.prefix] section (enabled=false by default)
- fallback without XDP: engine SubnetTracker aggregates connections per-prefix
- fix: PrefixStatsVal::from_bytes for xdp feature build; prefix_len 24 vs 64

cargo build/clippy(-D warnings, all features)/test green: 83 tests
2026-08-24 09:47:21 +02:00
15f474486a
feat!: universal redesign — drop Minecraft stack, single-crate architecture
- remove Java plugins (velocity/paper), dashboard, all MC-specific code
  (handshake, death_code, varint, hostname-HMAC); available in history pre-v0.2
- merge crates/* into one package with src/bin/{rampart,rampart-manager,rampart-cli}
- ProtocolHandler trait + registry (no implementations yet), universal PoW kept
- XDP: universal L3/L4 filter (xdp/core/) + pluggable hook API (xdp/hooks/),
  fix IPv6 saddr bug; clang build verified
- docs: bilingual knowledge base (docs/kb/: attacks x4, defense-levels,
  practice x3), rewrite README/architecture for universal concept
- TODO.md v4.0: <=300-line module limit, competitor benchmark section (ref/)
- deploy/CI/docs cleanup: no MC references, new binary names

cargo build/clippy(-D warnings)/test green (55 tests)
2026-08-24 01:50:22 +02:00
0b53ed720b
feat: VDS stress test harness (edge-only) and load-test results
- deploy/test/stress/: multi-IP masked handshake flood (flood.py), legit client
  during attack (legit.py), full orchestration (run-stress.sh), edge Dockerfile
  with socat stub backend and high/defense configs
- docs/research/load-test-report.md: v3 VDS loopback results (2026-08-04)
- README.md: performance table update (4k conn/s raw, 99.6% blocked in defense,
  legit clients RTT 2-6ms during attack)
- docs/testing.md: multi-IP masked stress-test procedure
2026-08-04 19:16:27 +02:00
d41bd6e815
fix: download Paper jar on CI runner and COPY into image 2026-08-03 12:13:45 +02:00
0db4fd867b
fix: force identity encoding for PaperMC API and download in Dockerfile.paper 2026-08-03 12:08:47 +02:00
2e4c50ab4a
fix: request compressed JSON from PaperMC v3 API in Dockerfile.paper 2026-08-03 12:02:13 +02:00
b446fd4f7b
fix: allow too_many_arguments in ProxyListener::new, add make to edge Dockerfile 2026-08-03 11:51:53 +02:00
29ce6fb8e9
feat: velocity routing, server registry and RampartVelocity tests 2026-08-03 10:54:28 +02:00
fa6de281fb
fix: restore download-artifact path plugins/ (artifact strips root dir) 2026-07-21 16:42:08 +02:00
35d20e97db
fix: clippy byte_char_slices lint, Docker java artifact path 2026-07-21 16:34:30 +02:00
997da7fbd3
fix: add libbpf-dev for xdp clang headers, update papermc download API to fill.papermc.io/v3 2026-07-21 16:20:49 +02:00
c828915560
fix: cargo-deny CDLA-Permissive-2.0, build.rs asm include path, eclipse-temurin noble tag 2026-07-21 16:16:07 +02:00
e7631f918a
fix: update Dockerfile to rust:slim-bookworm, install libelf-dev in CI 2026-07-21 16:08:33 +02:00
705521ade9
fix: remove deploy/ from .dockerignore (Dockerfiles need deploy/config) 2026-07-21 15:56:58 +02:00
95be20abd3
fix: track Cargo.lock (required for Docker build) 2026-07-21 15:56:40 +02:00
269daa071f
v0.3: 6-layer architecture complete
Layers:
  Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf
  Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify
  Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing)
  Layer 4: Velocity — Physics check, CAPTCHA, protocol verification
  Layer 5: Paper — Heartbeat, auto-registration (existing)
  Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts

Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose
Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report
Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup
Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
2026-07-21 15:47:36 +02:00
78fc6e00c7
Add yellow warning banner (dev/disclaimer) and clean .gitignore 2026-07-20 20:56:13 +02:00
cf9608ce5d
Initial commit: Rampart v0.2.0
Multi-layer DDoS protection for Minecraft servers.

- rampart-core: Edge node with XDP/eBPF + Rust L7 filtering
- rampart-manager: REST API with JWT auth, Redis sync
- rampart-cli: CLI tool for operators
- velocity-plugin: Domain check, HMAC verify, server registry, load balancer
- paper-plugin: Auto-registration, heartbeat, HMAC verify
- dashboard: React + Vite web UI for management
2026-07-20 20:53:32 +02:00