This commit is contained in:
Alexey
2026-08-22 16:22:07 +03:00
parent bb0d3ba927
commit fb47ad149c
57 changed files with 675 additions and 710 deletions
+1 -3
View File
@@ -78,9 +78,7 @@ pub(crate) async fn clear_synlimit_rules_all_backends() -> Result<bool, String>
async fn clear_synlimit_rules_for_namespace(namespace: &SynLimitNamespace) -> Result<bool, String> {
if !has_firewall_privileges() {
return Err(
"SYN limiter cleanup requires root or CAP_NET_ADMIN privileges".to_string(),
);
return Err("SYN limiter cleanup requires root or CAP_NET_ADMIN privileges".to_string());
}
let mut errors = Vec::new();
+10 -2
View File
@@ -31,7 +31,12 @@ pub(super) async fn apply_synlimit_rules(
}
let script = pf_synlimit_script(targets);
run_command("pfctl", &["-a", namespace.pf_anchor.as_str(), "-f", "-"], Some(script)).await
run_command(
"pfctl",
&["-a", namespace.pf_anchor.as_str(), "-f", "-"],
Some(script),
)
.await
}
async fn has_pf_anchor_hook() -> Result<bool, String> {
@@ -98,7 +103,10 @@ mod tests {
#[test]
fn pf_script_uses_native_rate_limited_pass() {
let mut targets = SynLimitTargets::default();
targets.pf_v4 = vec![test_rule(Some(IpAddr::V4(Ipv4Addr::new(203, 0, 113, 7))), 443)];
targets.pf_v4 = vec![test_rule(
Some(IpAddr::V4(Ipv4Addr::new(203, 0, 113, 7))),
443,
)];
let script = pf_synlimit_script(&targets);
assert!(script.contains(
+1 -4
View File
@@ -29,10 +29,7 @@ fn targets(low_family: &str) -> SynLimitTargets {
_ => panic!("TELEMT_PF_LOW_FAMILY must be v4 or v6"),
};
SynLimitTargets {
pf_v4: vec![rule(
IpAddr::V4(Ipv4Addr::new(198, 18, 1, 1)),
v4_rate,
)],
pf_v4: vec![rule(IpAddr::V4(Ipv4Addr::new(198, 18, 1, 1)), v4_rate)],
pf_v6: vec![rule(
IpAddr::V6("fd00:18:1::1".parse::<Ipv6Addr>().unwrap()),
v6_rate,