|
|
aa615a1141
|
fix: XDP unsafe loader + Redis sync; enforce 250-line/4-file layout limits
- xdp: CString for if_nametoindex (was UB), real detach via prog fd
(fabricated borrow_raw(-1) silently never detached), SAFETY comments,
saturating expiry math; +5 unit tests
- redis: real pubsub reconnect with exponential backoff (was sleep+return);
KEYS -> SCAN in heartbeat sweep
- ci: cargo test --all-features, repo-gates job — module size gate
(scripts/check_module_size.sh, ratchet baseline) + default-secrets grep
- refactor src/ to <=250 LOC/file, <=4 .rs/dir without behavior change;
thin bins (rampart.rs 330 -> 6 LOC), new app/, subnet/, intel/,
profile/, prefix/, challenge/, filter/, probe/, inventory/, metrics/, node/
- docs: TODO v5.0 (status refresh, new rules, findings backlog),
README quickstart now matches real binaries
- verify: fmt/clippy -D warnings/test --all-features (164 tests)/clang XDP green
|
2026-09-15 23:55:17 +02:00 |
|
|
|
15f474486a
|
feat!: universal redesign — drop Minecraft stack, single-crate architecture
- remove Java plugins (velocity/paper), dashboard, all MC-specific code
(handshake, death_code, varint, hostname-HMAC); available in history pre-v0.2
- merge crates/* into one package with src/bin/{rampart,rampart-manager,rampart-cli}
- ProtocolHandler trait + registry (no implementations yet), universal PoW kept
- XDP: universal L3/L4 filter (xdp/core/) + pluggable hook API (xdp/hooks/),
fix IPv6 saddr bug; clang build verified
- docs: bilingual knowledge base (docs/kb/: attacks x4, defense-levels,
practice x3), rewrite README/architecture for universal concept
- TODO.md v4.0: <=300-line module limit, competitor benchmark section (ref/)
- deploy/CI/docs cleanup: no MC references, new binary names
cargo build/clippy(-D warnings)/test green (55 tests)
|
2026-08-24 01:50:22 +02:00 |
|
|
|
269daa071f
|
v0.3: 6-layer architecture complete
Layers:
Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf
Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify
Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing)
Layer 4: Velocity — Physics check, CAPTCHA, protocol verification
Layer 5: Paper — Heartbeat, auto-registration (existing)
Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts
Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose
Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report
Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup
Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
|
2026-07-21 15:47:36 +02:00 |
|
|
|
cf9608ce5d
|
Initial commit: Rampart v0.2.0
Multi-layer DDoS protection for Minecraft servers.
- rampart-core: Edge node with XDP/eBPF + Rust L7 filtering
- rampart-manager: REST API with JWT auth, Redis sync
- rampart-cli: CLI tool for operators
- velocity-plugin: Domain check, HMAC verify, server registry, load balancer
- paper-plugin: Auto-registration, heartbeat, HMAC verify
- dashboard: React + Vite web UI for management
|
2026-07-20 20:53:32 +02:00 |
|