Traffic Intel (was dead code, now wired): - TrafficHook in listener accept path: cps/pps windows -> AttackDetector - auto-ban IPs below reputation threshold under attack ([detect.autoban]) - AlertDispatcher: webhook on attack state transition only (dedup), metrics AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url XDP SYN RST-challenge (Oubliette pattern, off by default): - G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX, spoofed sources stay silent, live clients answer RST with secret echo -> challenge_verified (LRU, sliding TTL); brute-force of marker impossible - maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic in xdp/core/syn_challenge.h (221 lines) XDP diagnostics (src/xdp/diagnostics.rs): - EnvironmentReport: kernel version/BTF/driver->AttachMode verdict, fail-fast before load on unsupported kernels; wired into CLI - SystemProbe trait for kernel-less testing fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
44 lines
2 KiB
C
44 lines
2 KiB
C
#ifndef RAMPART_CONFIG_H
|
|
#define RAMPART_CONFIG_H
|
|
|
|
// ⚙️ Runtime configurable globals (patched by Rust loader)
|
|
// These are volatile const — compiler replaces reads with immediate values
|
|
// after loader writes to .rodata section
|
|
|
|
// ── Port range ──
|
|
static volatile const __u16 G_START_PORT = 25565;
|
|
static volatile const __u16 G_END_PORT = 25570;
|
|
|
|
// ── SYN throttle ──
|
|
static volatile const __u32 G_SYN_HIT_COUNT = 10; // max SYNs / window
|
|
static volatile const __u64 G_SYN_WINDOW_NS = 3000000000ULL; // 3 sec
|
|
static volatile const __u64 G_SYN_BAN_DURATION_NS = 60000000000ULL; // 60 sec
|
|
|
|
// ── Idle timeouts ──
|
|
static volatile const __u64 G_CONNTRACK_IDLE_NS = 30000000000ULL; // 30 sec
|
|
static volatile const __u64 G_PLAYER_IDLE_NS = 120000000000ULL; // 120 sec
|
|
|
|
// ── Blacklist default ban duration ──
|
|
static volatile const __u64 G_BAN_DURATION_NS = 300000000000ULL; // 5 min
|
|
|
|
// ── Max out-of-order packets before dropping connection ──
|
|
static volatile const __u8 G_MAX_OUT_OF_ORDER = 4;
|
|
|
|
// ── UDP policy ──
|
|
static volatile const __u8 G_UDP_POLICY = 0; // 0 = pass, 1 = drop, 2 = rate-limit
|
|
static volatile const __u32 G_UDP_HIT_COUNT = 100; // max packets / window
|
|
static volatile const __u64 G_UDP_WINDOW_NS = 1000000000ULL; // 1 sec
|
|
|
|
// ── Feature flags ──
|
|
static volatile const __u8 G_FEATURE_SYN_THROTTLE = 1;
|
|
static volatile const __u8 G_FEATURE_EVENTS = 1;
|
|
|
|
// ── RST-challenge (Oubliette liveness proof) ──
|
|
// 0 = disabled: single branch, zero cost for legitimate traffic.
|
|
// Secret is patched by the loader at attach time (default is a placeholder).
|
|
static volatile const __u8 G_SYN_CHALLENGE_ENABLED = 0;
|
|
static volatile const __u64 G_CHALLENGE_SECRET = 0xA5A55A5A5A5AA5A5ULL;
|
|
static volatile const __u32 G_CHALLENGE_TIMEOUT_MS = 3000; // pending TTL
|
|
static volatile const __u64 G_CHALLENGE_VERIFIED_TTL_NS = 300000000000ULL; // 5 min
|
|
|
|
#endif /* RAMPART_CONFIG_H */
|