Layers: Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing) Layer 4: Velocity — Physics check, CAPTCHA, protocol verification Layer 5: Paper — Heartbeat, auto-registration (existing) Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
106 lines
1.7 KiB
Makefile
106 lines
1.7 KiB
Makefile
# Rampart — Build System
|
|
|
|
CARGO = cargo
|
|
TARGET_DIR = target
|
|
GRADLE = ./gradlew
|
|
|
|
.PHONY: all build test check fmt clippy clean release
|
|
.PHONY: deny audit ebpf
|
|
.PHONY: plugins paper velocity
|
|
.PHONY: docker docker-build docker-up docker-down docker-logs
|
|
.PHONY: dash dash-dev dash-build
|
|
.PHONY: ci ci-full
|
|
|
|
all: check test build
|
|
|
|
# --- Rust ---
|
|
|
|
build:
|
|
$(CARGO) build
|
|
|
|
release:
|
|
$(CARGO) build --release
|
|
|
|
check:
|
|
$(CARGO) check
|
|
|
|
check-all:
|
|
$(CARGO) check --all-features
|
|
|
|
test:
|
|
$(CARGO) test
|
|
|
|
fmt:
|
|
$(CARGO) fmt --all
|
|
|
|
fmt-check:
|
|
$(CARGO) fmt --all --check
|
|
|
|
clippy:
|
|
$(CARGO) clippy --all-targets --all-features -- -D warnings
|
|
|
|
clean:
|
|
$(CARGO) clean
|
|
|
|
deny:
|
|
cargo deny check
|
|
|
|
audit:
|
|
cargo audit
|
|
|
|
# --- eBPF / XDP ---
|
|
|
|
ebpf:
|
|
@echo "Building XDP/eBPF filter..."
|
|
cd xdp && clang -O2 -target bpf -c xdp_filter.c -o xdp_filter.o 2>/dev/null || \
|
|
echo "WARNING: clang+bpf not installed, skipping eBPF build"
|
|
|
|
ebpf-clean:
|
|
rm -f xdp/xdp_filter.o
|
|
|
|
# --- Java Plugins ---
|
|
|
|
plugins:
|
|
cd plugins && $(GRADLE) build
|
|
|
|
paper:
|
|
cd plugins && $(GRADLE) :paper:build
|
|
|
|
velocity:
|
|
cd plugins && $(GRADLE) :velocity:build
|
|
|
|
# --- Dashboard ---
|
|
|
|
dash-install:
|
|
cd dashboard && npm ci
|
|
|
|
dash-dev:
|
|
cd dashboard && npm run dev
|
|
|
|
dash-build:
|
|
cd dashboard && npm run build
|
|
|
|
# --- Docker ---
|
|
|
|
docker-build: plugins
|
|
docker compose -f deploy/docker-compose.yml build
|
|
|
|
docker-up: docker-build
|
|
docker compose -f deploy/docker-compose.yml up -d
|
|
|
|
docker-down:
|
|
docker compose -f deploy/docker-compose.yml down
|
|
|
|
docker-logs:
|
|
docker compose -f deploy/docker-compose.yml logs -f
|
|
|
|
# --- Convenience ---
|
|
|
|
checkstyle: fmt-check clippy
|
|
@echo "✓ Checkstyle passed (rustfmt + clippy)"
|
|
|
|
ci: checkstyle test build deny
|
|
@echo "✓ CI passed"
|
|
|
|
ci-full: ci plugins dash-build
|
|
@echo "✓ Full CI passed"
|