Commit Graph

154 Commits

Author SHA1 Message Date
ali_rajabpour 721b75c687 perf/deploy: optimize hot-path allocs (cut per-session ad_tag allocations), split metrics module, and add ENV config support
Three independent changes bundled here — performance, maintainability, and
deployment DX.

1. Hot-path Allocations (ad_tag caching):
Every middle-relay session was doing a hex::decode of the user's ad_tag (plus a fallback to the global one) on every single connection. That's two string allocations and two hex decodes per session for data that only changes on config reload. Moved the decoding into ProxyConfig load/hot-reload into a precomputed runtime_ad_tags cache (same #[serde(skip)] pattern as runtime_user_auth). The session path now does a single O(1) lookup via config.effective_ad_tag(&user). Falls back to on-demand decode if the cache isn't built (e.g. in tests), so existing behavior is preserved. This eliminates two useless allocations and hex decodes per connection.

2. Metrics Monolith Split(structural refactor):
Broke up the massive 4,200-line `metrics.rs` into a proper `metrics/` directory module (`mod.rs`, `tls_front.rs`, `tests.rs`). I isolated the giant `render_metrics` function into its own `render.rs` file. This was a purely structural move—no locks or function bodies were changed, keeping things build-safe while making the crate significantly easier to navigate. The /metrics endpoint output is byte-identical.

3. GitOps / Dokploy Auto-Deployment Support (deployment DX):
Added `figment` to `Cargo.toml` to seamlessly merge TOML config files with Environment Variables. You can now configure the proxy entirely using `TELEMT_` prefixed ENV variables (e.g., `TELEMT_GENERAL__PORT=443`) without needing to manually mount a physical `config.toml` via Docker volumes. The Dockerfile and compose setups now gracefully handle missing config files by generating an empty placeholder, making stateless auto-deployments on platforms like Dokploy frictionless.
2026-08-03 18:41:24 +04:00
Alexey 5b5cd952c8 Bump -> 3.4.25 2026-07-19 18:36:04 +03:00
Alexey feb51cbf57 Fix RustCrypto zeroize feature wiring 2026-07-12 09:27:15 +03:00
Alexey a51e58009b Update Cargo.toml 2026-07-10 11:46:33 +03:00
Alexey 88d161a5e9 Bump -> 3.4.22 2026-06-29 16:38:09 +03:00
Alexey 22627b498d Bump -> 3.4.21 2026-06-29 12:44:03 +03:00
Alexey f56895feac Bump -> 3.4.19 2026-06-24 00:53:01 +03:00
Alexey 2d02fbe548 Bump 2026-06-12 15:06:14 +03:00
Alexey 52a1b66ad7 Syntactic key shares for TLS-F
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com>
2026-06-11 23:13:21 +03:00
Alexey 1edd63bfb1 Rustfmt + Bump 2026-06-11 16:36:33 +03:00
Alexey 62af515504 Generate Valid X25519MLKEM768 ServerHello key shares
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com>
2026-06-11 14:14:09 +03:00
Mirotin Artem d7e16f5b26 feat(api): config-edit endpoints PATCH/GET /v1/config 2026-06-09 12:03:28 +03:00
Alexey 27a5f5a4ec MSS Tuning with config
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com>
2026-06-06 12:11:05 +03:00
Alexey 44be585ee3 Update Cargo.toml 2026-06-05 14:24:27 +03:00
Alexey c4e522a16d Bump -> 3.4.14
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com>
2026-06-05 14:21:29 +03:00
Aleksei K 752a2f5012 Bump -> 3.4.13 2026-05-29 14:05:19 +03:00
Alexey 231f04a810 Bump 2026-05-22 11:00:41 +03:00
Alexey 57b2aa0453 Rustfmt 2026-05-10 14:14:52 +03:00
Alexey 2a694470d5 Update Cargo.toml 2026-04-30 11:37:18 +03:00
Alexey cfe01dced2 Bump
Signed-off-by: Alexey <247128645+axkurcom@users.noreply.github.com>
2026-04-29 15:54:22 +03:00
Alexey 8ab9405dca Bump 2026-04-25 18:05:22 +03:00
Alexey e217371dc8 Bump 2026-04-25 14:36:51 +03:00
Alexey 8960fad8cd Сlassified Bad Connections and Handshake Failures in API
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com>
2026-04-24 10:56:30 +03:00
Alexey 30e73adaac Bump 2026-04-21 13:38:38 +03:00
Alexey 2a7303c129 Bump 2026-04-19 19:10:19 +03:00
Alexey b447f60a72 Rustfmt + Bump 2026-04-17 19:08:57 +03:00
Alexey a858dd799e Bump 2026-04-17 12:43:41 +03:00
Alexey 5c99cd8eb7 Backpressure-driven Fairness
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com>
2026-04-17 10:33:37 +03:00
uncle Sam 3bff4fbfcd Merge branch 'main' into security-tls-front-fidelity 2026-04-15 19:45:35 +05:00
astronaut808 f5b5ea3bbf Improve FakeTLS server-flight fidelity and macOS portability 2026-04-15 19:35:09 +05:00
Alexey 32d5cee01c Bump 2026-04-15 02:18:44 +03:00
Alexey bc691539a1 Bump 2026-04-07 19:28:05 +03:00
Alexey e630ea0045 Bump 2026-04-05 17:31:48 +03:00
Alexey 486e439ae6 Update Cargo.toml + Cargo.lock 2026-04-05 12:19:24 +03:00
Alexey 8ac1a0017d Update Cargo.toml 2026-03-31 23:17:30 +03:00
Alexey 5f5a046710 Update Cargo.toml + Cargo.lock 2026-03-31 13:04:24 +03:00
Alexey 6c850e4150 Update Cargo.toml 2026-03-31 11:15:31 +03:00
Alexey 5bf56b6dd8 Update Cargo.toml 2026-03-30 23:36:45 +03:00
Alexey 01c3d0a707 Merge branch 'flow' into daemonize 2026-03-27 11:35:52 +03:00
Alexey 70479c4094 Unexpected-only Quarantine
Co-Authored-By: brekotis <93345790+brekotis@users.noreply.github.com>
2026-03-25 22:25:39 +03:00
Alexey 08684bcbd2 Update Cargo.toml 2026-03-24 22:03:12 +03:00
Alexey 80cb1bc221 Merge branch 'main' into flow 2026-03-24 22:00:51 +03:00
Alexey cfd516edf3 Update Cargo.toml 2026-03-24 21:41:14 +03:00
Alexey dc61d300ab Bump 2026-03-24 21:02:43 +03:00
Vladislav Yaroslavlev 4426082c17 Update release profile settings for better optimization 2026-03-24 14:01:49 +03:00
David Osipov 91be148b72 Security hardening, concurrency fixes, and expanded test coverage
This commit introduces a comprehensive set of improvements to enhance
the security, reliability, and configurability of the proxy server,
specifically targeting adversarial resilience and high-load concurrency.

Security & Cryptography:
- Zeroize MTProto cryptographic key material (`dec_key`, `enc_key`)
  immediately after use to prevent memory leakage on early returns.
- Move TLS handshake replay tracking after full policy/ALPN validation
  to prevent cache poisoning by unauthenticated probes.
- Add `proxy_protocol_trusted_cidrs` configuration to restrict PROXY
  protocol headers to trusted networks, rejecting spoofed IPs.

Adversarial Resilience & DoS Mitigation:
- Implement "Tiny Frame Debt" tracking in the middle-relay to prevent
  CPU exhaustion from malicious 0-byte or 1-byte frame floods.
- Add `mask_relay_max_bytes` to strictly bound unauthenticated fallback
  connections, preventing the proxy from being abused as an open relay.
- Add a 5ms prefetch window (`mask_classifier_prefetch_timeout_ms`) to
  correctly assemble and classify fragmented HTTP/1.1 and HTTP/2 probes
  (e.g., `PRI * HTTP/2.0`) before routing them to masking heuristics.
- Prevent recursive masking loops (FD exhaustion) by verifying the mask
  target is not the proxy's own listener via local interface enumeration.

Concurrency & Reliability:
- Eliminate executor waker storms during quota lock contention by replacing
  the spin-waker task with inline `Sleep` and exponential backoff.
- Roll back user quota reservations (`rollback_me2c_quota_reservation`)
  if a network write fails, preventing Head-of-Line (HoL) blocking from
  permanently burning data quotas.
- Recover gracefully from idle-registry `Mutex` poisoning instead of
  panicking, ensuring isolated thread failures do not break the proxy.
- Fix `auth_probe_scan_start_offset` modulo logic to ensure bounds safety.

Testing:
- Add extensive adversarial, timing, fuzzing, and invariant test suites
  for both the client and handshake modules.
2026-03-22 23:09:49 +04:00
Vladimir Krivopalov 95685adba7 Add multi-destination logging: syslog and file support
Implement logging infrastructure for non-systemd platforms:

- Add src/logging.rs with syslog and file logging support
- New CLI flags: --syslog, --log-file, --log-file-daily
- Syslog uses libc directly with LOG_DAEMON facility
- File logging via tracing-appender with optional daily rotation

Update service scripts:
- OpenRC and FreeBSD rc.d now use --syslog by default
- Ensures logs are captured on platforms without journald

Default (stderr) behavior unchanged for systemd compatibility.
Log destination is selected at startup based on CLI flags.

Signed-off-by: Vladimir Krivopalov <argenet@yandex.ru>
2026-03-21 21:09:29 +02:00
Vladimir Krivopalov 2ea7813ed4 Add Unix daemon mode with PID file and privilege dropping
Implement core daemon infrastructure for running telemt as a background
  service on Unix platforms (Linux, FreeBSD, etc.):

  - Add src/daemon module with classic double-fork daemonization
  - Implement flock-based PID file management to prevent duplicate instances
  - Add privilege dropping (setuid/setgid) after socket binding
  - New CLI flags: --daemon, --foreground, --pid-file, --run-as-user,
    --run-as-group, --working-dir

  Daemonization occurs before tokio runtime starts to ensure clean fork.
  PID file uses exclusive locking to detect already-running instances.
  Privilege dropping happens after bind_listeners() to allow binding
  to privileged ports (< 1024) before switching to unprivileged user.

Signed-off-by: Vladimir Krivopalov <argenet@yandex.ru>
2026-03-21 21:09:29 +02:00
David Osipov 4c32370b25 Refactor proxy and transport modules for improved safety and performance
- Enhanced linting rules in `src/proxy/mod.rs` to enforce stricter code quality checks in production.
- Updated hash functions in `src/proxy/middle_relay.rs` for better efficiency.
- Added new security tests in `src/proxy/tests/middle_relay_stub_completion_security_tests.rs` to validate desynchronization behavior.
- Removed ignored test stubs in `src/proxy/tests/middle_relay_security_tests.rs` to clean up the test suite.
- Improved error handling and code readability in various transport modules, including `src/transport/middle_proxy/config_updater.rs` and `src/transport/middle_proxy/pool.rs`.
- Introduced new padding functions in `src/stream/frame_stream_padding_security_tests.rs` to ensure consistent behavior across different implementations.
- Adjusted TLS stream validation in `src/stream/tls_stream.rs` for better boundary checking.
- General code cleanup and dead code elimination across multiple files to enhance maintainability.
2026-03-21 20:05:07 +04:00
Alexey f2e6dc1774 Update Cargo.toml 2026-03-21 15:27:21 +03:00