protocol-http (compile-time feature): - HttpHandler: incremental HTTP/1.1 request parse (fragment-safe), header size/timeout limits, method whitelist, Host required, blocked_paths, optional User-Agent requirement - [protocol.http] config section; registry wiring behind feature XDP globals: - src/xdp/globals.rs: XdpGlobals + build_rodata_image() mirroring xdp/core/config.h layout; set via OpenMapMut::set_initial_value() before load ([xdp] section: ports, udp policy, throttle, challenge) - wire set_globals into rampart binary startup fix: gate preflight() behind xdp feature (dead code without it)
73 lines
2.2 KiB
TOML
73 lines
2.2 KiB
TOML
[package]
|
|
name = "rampart"
|
|
version = "0.3.0-dev"
|
|
edition = "2024"
|
|
license = "GPL-3.0-only"
|
|
authors = ["loki"]
|
|
description = "Universal L3/L4/L7 network protection platform"
|
|
|
|
[[bin]]
|
|
name = "rampart"
|
|
path = "src/bin/rampart.rs"
|
|
|
|
[[bin]]
|
|
name = "rampart-manager"
|
|
path = "src/bin/rampart-manager.rs"
|
|
|
|
[[bin]]
|
|
name = "rampart-cli"
|
|
path = "src/bin/rampart-cli.rs"
|
|
|
|
[lints.clippy]
|
|
# Deny — критически важные для безопасности и стабильности
|
|
type_complexity = "allow"
|
|
unwrap_used = "deny"
|
|
panic = "deny"
|
|
dbg_macro = "deny"
|
|
print_stdout = "deny"
|
|
print_stderr = "deny"
|
|
wildcard_imports = "deny"
|
|
exit = "deny"
|
|
# expect разрешён — используется в prometheus метриках при старте
|
|
# cast разрешён — неизбежен в сетевых протоколах
|
|
|
|
[features]
|
|
default = ["store-redis"]
|
|
store-redis = ["dep:redis"]
|
|
geoip = ["dep:maxminddb"]
|
|
xdp = ["dep:libbpf-rs", "dep:libc"]
|
|
io-uring = ["dep:tokio-splice"]
|
|
# HTTP/1.1 protocol handler: парсинг request-head, verdict Allow/Reject,
|
|
# туннелирование на upstream (см. src/protocol/http/ и [protocol.http] в конфиге).
|
|
protocol-http = []
|
|
|
|
[dependencies]
|
|
tokio = { version = "1", features = ["full"] }
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["json", "env-filter"] }
|
|
thiserror = "2"
|
|
anyhow = "1"
|
|
dashmap = "6"
|
|
hex = "0.4"
|
|
sha2 = "0.10"
|
|
subtle = "2"
|
|
socket2 = { version = "0.5", features = ["all"] }
|
|
futures = "0.3"
|
|
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls"] }
|
|
prometheus = { version = "0.14", features = ["process"] }
|
|
toml = "0.8"
|
|
rand = { version = "0.8", default-features = false, features = ["std", "std_rng"] }
|
|
clap = { version = "4", features = ["derive"] }
|
|
chrono = { version = "0.4", features = ["serde"] }
|
|
|
|
axum = "0.8"
|
|
tower-http = { version = "0.6", features = ["cors"] }
|
|
jsonwebtoken = "9"
|
|
|
|
redis = { version = "0.27", optional = true, features = ["tokio-comp", "connection-manager"] }
|
|
maxminddb = { version = "0.30", optional = true }
|
|
tokio-splice = { version = "0.2", optional = true }
|
|
libbpf-rs = { version = "0.24", optional = true }
|
|
libc = { version = "0.2", optional = true }
|