guard/xdp/core/stats.h
loki5512344 aa787a558c
feat: traffic intel hot path, SYN RST-challenge, XDP environment diagnostics
Traffic Intel (was dead code, now wired):
- TrafficHook in listener accept path: cps/pps windows -> AttackDetector
- auto-ban IPs below reputation threshold under attack ([detect.autoban])
- AlertDispatcher: webhook on attack state transition only (dedup), metrics
  AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url

XDP SYN RST-challenge (Oubliette pattern, off by default):
- G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX,
  spoofed sources stay silent, live clients answer RST with secret echo ->
  challenge_verified (LRU, sliding TTL); brute-force of marker impossible
- maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic
  in xdp/core/syn_challenge.h (221 lines)

XDP diagnostics (src/xdp/diagnostics.rs):
- EnvironmentReport: kernel version/BTF/driver->AttachMode verdict,
  fail-fast before load on unsupported kernels; wired into  CLI
- SystemProbe trait for kernel-less testing

fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed

cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
2026-08-24 10:11:10 +02:00

29 lines
1.3 KiB
C

#ifndef RAMPART_STATS_H
#define RAMPART_STATS_H
#include "common.h"
#include "maps.h"
// ── Per-CPU stat increment ──
static __always_inline void inc_stat(__u32 idx)
{
__u64 *val = bpf_map_lookup_elem(&stats_map, &idx);
if (val)
__sync_fetch_and_add(val, 1);
}
// ── Convenience wrappers ──
static __always_inline void inc_total(void) { inc_stat(STAT_TOTAL); }
static __always_inline void inc_tcp(void) { inc_stat(STAT_TCP); }
static __always_inline void inc_udp(void) { inc_stat(STAT_UDP); }
static __always_inline void inc_whitelist(void) { inc_stat(STAT_WHITELIST); }
static __always_inline void inc_blacklist(void) { inc_stat(STAT_BLACKLIST); }
static __always_inline void inc_syn_throttle(void) { inc_stat(STAT_SYN_THROTTLE); }
static __always_inline void inc_rate_limit(void) { inc_stat(STAT_RATE_LIMIT); }
static __always_inline void inc_chal_sent(void) { inc_stat(STAT_CHALLENGE_SENT); }
static __always_inline void inc_chal_verified(void) { inc_stat(STAT_CHALLENGE_VERIFIED); }
static __always_inline void inc_chal_failed(void) { inc_stat(STAT_CHALLENGE_FAILED); }
static __always_inline void inc_pass(void) { inc_stat(STAT_PASS); }
static __always_inline void inc_drop(void) { inc_stat(STAT_DROP); }
#endif /* RAMPART_STATS_H */