Some checks are pending
CI / Rust — check & clippy (push) Waiting to run
CI / Rust — test (push) Waiting to run
CI / Repo — module size & default secrets (push) Waiting to run
CI / Rust — cargo-deny (push) Waiting to run
CI / Docker — build edge image (push) Blocked by required conditions
- xdp: real 24-byte xdp_event parsing (fixes LE byte-swap of src IP), opt-in [xdp] auto_ban (RATE_LIMIT always, CONN_DROP at fails>=threshold; EVENT_BAN/POLICY_DROP excluded by design), rampart_xdp_autobans_total; wired in app before load(); 10 tests in tests/xdp_events.rs - build: --no-default-features compiles — redis paths cfg-gated behind store-redis, manager fail-fasts without it; CI gates the config now - app: RunExit enum replaces process::exit in lib; single exit site in main - tests: seed PoW roundtrip token (was ~1/16 flaky; 50 pre-fix fails -> 0) - docs: TODO statuses refreshed (round 2)
24 lines
1 KiB
Rust
24 lines
1 KiB
Rust
use rampart::engine::challenge::{Challenge, solve};
|
|
|
|
/// Fixed 32-byte token: sha256(hex(token) || "garbage") starts with "ebc1",
|
|
/// so "garbage" provably fails the difficulty-2 check (first two hex chars
|
|
/// must be in "0123"). A random token made this flaky with probability 1/16
|
|
/// per run, since any digest lands in the accepted prefix with p=(4/16)^2.
|
|
const FIXED_TOKEN: [u8; 32] = *b"rampart-pow-fixed-token-test-v1!";
|
|
|
|
#[test]
|
|
fn solver_output_passes_verifier() {
|
|
let mut challenge = Challenge::generate(3);
|
|
let nonce = solve(&challenge.challenge_string(), 3).expect("solver must find nonce for difficulty 3");
|
|
assert!(challenge.verify(&nonce));
|
|
}
|
|
|
|
#[test]
|
|
fn verifier_rejects_garbage_and_replay() {
|
|
let mut challenge = Challenge::with_token(FIXED_TOKEN, 2);
|
|
assert!(!challenge.verify("garbage"));
|
|
|
|
let nonce = solve(&challenge.challenge_string(), 2).expect("solved");
|
|
assert!(challenge.verify(&nonce), "first use passes");
|
|
assert!(!challenge.verify(&nonce), "replay is rejected");
|
|
}
|