diff --git a/.github/workflows/always.yml b/.github/workflows/always.yml new file mode 100644 index 0000000..23067ba --- /dev/null +++ b/.github/workflows/always.yml @@ -0,0 +1,19 @@ +name: always +on: [push] + +env: + CARGO_TERM_COLOR: always + +jobs: + build: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + - name: Run CI + run: make ci + + - name: Install Cross + run: cargo install cross --git https://github.com/cross-rs/cross + + - name: Build all artifacts + run: make build-all diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 0000000..c2f5a45 --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,32 @@ +name: deploy + +on: + push: + tags: + - '*' + +jobs: + build: + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Run tests + run: make ci + + - name: Install Cross + run: cargo install cross --git https://github.com/cross-rs/cross + + - name: Build all artifacts + run: make build-all + + - name: "Release gh release latest" + uses: ncipollo/release-action@v1 + with: + tag: latest + name: Latest + allowUpdates: true + artifacts: "builds/*" + bodyFile: "builds/buildout" + token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml deleted file mode 100644 index 40cbc19..0000000 --- a/.github/workflows/rust.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: Rust - -on: - push: - branches: [ main ] - pull_request: - branches: [ main ] - -env: - CARGO_TERM_COLOR: always - -jobs: - build: - - runs-on: ubuntu-latest - - steps: - - uses: actions/checkout@v2 - - name: Run CI - run: make ci diff --git a/.gitignore b/.gitignore index ea8c4bf..486967d 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,2 @@ /target +builds/** diff --git a/Cargo.lock b/Cargo.lock index 040405c..635a498 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -12,36 +12,66 @@ dependencies = [ ] [[package]] -name = "ansi_term" -version = "0.11.0" +name = "anstream" +version = "0.6.18" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ee49baf6cb617b853aa8d93bf420db2383fab46d314482ca2803b40d5fde979b" +checksum = "8acc5369981196006228e28809f761875c0327210a891e941f4c683b3a99529b" dependencies = [ - "winapi", + "anstyle", + "anstyle-parse", + "anstyle-query", + "anstyle-wincon", + "colorchoice", + "is_terminal_polyfill", + "utf8parse", +] + +[[package]] +name = "anstyle" +version = "1.0.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "55cc3b69f167a1ef2e161439aa98aed94e6028e5f9a59be9a6ffb47aef1651f9" + +[[package]] +name = "anstyle-parse" +version = "0.2.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3b2d16507662817a6a20a9ea92df6652ee4f94f914589377d69f3b21bc5798a9" +dependencies = [ + "utf8parse", +] + +[[package]] +name = "anstyle-query" +version = "1.1.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "79947af37f4177cfead1110013d678905c37501914fba0efea834c3fe9a8d60c" +dependencies = [ + "windows-sys 0.59.0", +] + +[[package]] +name = "anstyle-wincon" +version = "3.0.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ca3534e77181a9cc07539ad51f2141fe32f6c3ffd4df76db8ad92346b003ae4e" +dependencies = [ + "anstyle", + "once_cell", + "windows-sys 0.59.0", ] [[package]] name = "anyhow" -version = "1.0.44" +version = "1.0.62" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "61604a8f862e1d5c3229fdd78f8b02c68dcf73a4c4b05fd636d12240aaa242c1" - -[[package]] -name = "atty" -version = "0.2.14" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d9b39be18770d11421cdb1b9947a45dd3f37e93092cbf377614828a319d5fee8" -dependencies = [ - "hermit-abi", - "libc", - "winapi", -] +checksum = "1485d4d2cc45e7b201ee3767015c96faa5904387c9d87c6efdd0fb511f12d305" [[package]] name = "autocfg" -version = "1.0.1" +version = "1.1.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "cdb031dd78e28731d87d56cc8ffef4a8f36ca26c38fe2de700543e627f8a464a" +checksum = "d468802bab17cbc0cc575e9b053f41e72aa36bfa6b7f55e3529ffa43161b97fa" [[package]] name = "bitflags" @@ -51,21 +81,22 @@ checksum = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a" [[package]] name = "blockfast" -version = "0.1.0" +version = "0.2.0" dependencies = [ "anyhow", "clap", "lazy_static", "linemux", "regex", + "serde_json", "tokio", ] [[package]] name = "bytes" -version = "1.1.0" +version = "1.2.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c4872d67bab6358e59559027aa3b9157c53d9358c51423c17554809a8858e0f8" +checksum = "ec8a7b6a70fde80372154c65702f00a0f56f3e1c36abbc6c440484be248856db" [[package]] name = "cfg-if" @@ -75,24 +106,55 @@ checksum = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40fd" [[package]] name = "clap" -version = "2.33.3" +version = "4.5.27" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "37e58ac78573c40708d45522f0d80fa2f01cc4f9b4e2bf749807255454312002" +checksum = "769b0145982b4b48713e01ec42d61614425f27b7058bda7180a3a41f30104796" dependencies = [ - "ansi_term", - "atty", - "bitflags", - "strsim", - "textwrap", - "unicode-width", - "vec_map", + "clap_builder", + "clap_derive", ] [[package]] -name = "crossbeam-channel" -version = "0.5.1" +name = "clap_builder" +version = "4.5.27" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "06ed27e177f16d65f0f0c22a213e17c696ace5dd64b14258b52f9417ccb52db4" +checksum = "1b26884eb4b57140e4d2d93652abfa49498b938b3c9179f9fc487b0acc3edad7" +dependencies = [ + "anstream", + "anstyle", + "clap_lex", + "strsim", +] + +[[package]] +name = "clap_derive" +version = "4.5.24" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "54b755194d6389280185988721fffba69495eed5ee9feeee9a599b53db80318c" +dependencies = [ + "heck", + "proc-macro2", + "quote", + "syn 2.0.96", +] + +[[package]] +name = "clap_lex" +version = "0.7.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f46ad14479a25103f283c0f10005961cf086d8dc42205bb44c46ac563475dca6" + +[[package]] +name = "colorchoice" +version = "1.0.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5b63caa9aa9397e2d9480a9b13673856c78d8ac123288526c37d7839f2a86990" + +[[package]] +name = "crossbeam-channel" +version = "0.5.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c2dd04ddaf88237dc3b8d8f9a3c1004b506b54b3313403944054d23c0870c521" dependencies = [ "cfg-if", "crossbeam-utils", @@ -100,61 +162,63 @@ dependencies = [ [[package]] name = "crossbeam-utils" -version = "0.8.5" +version = "0.8.11" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d82cfc11ce7f2c3faef78d8a684447b40d503d9681acebed6cb728d45940c4db" +checksum = "51887d4adc7b564537b15adcfb307936f8075dfcd5f00dde9a9f1d29383682bc" dependencies = [ "cfg-if", - "lazy_static", + "once_cell", ] [[package]] -name = "filetime" -version = "0.2.15" +name = "dtoa" +version = "0.4.8" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "975ccf83d8d9d0d84682850a38c8169027be83368805971cc4f238c2b245bc98" +checksum = "56899898ce76aaf4a0f24d914c97ea6ed976d42fec6ad33fcbb0a1103e07b2b0" + +[[package]] +name = "filetime" +version = "0.2.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e94a7bbaa59354bc20dd75b67f23e2797b4490e9d6928203fb105c79e448c86c" dependencies = [ "cfg-if", "libc", "redox_syscall", - "winapi", -] - -[[package]] -name = "fsevent-sys" -version = "4.0.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5c0e564d24da983c053beff1bb7178e237501206840a3e6bf4e267b9e8ae734a" -dependencies = [ - "libc", + "windows-sys 0.36.1", ] [[package]] name = "futures-core" -version = "0.3.17" +version = "0.3.23" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "88d1c26957f23603395cd326b0ffe64124b818f4449552f960d815cfba83a53d" +checksum = "d2acedae88d38235936c3922476b10fced7b2b68136f5e3c03c2d5be348a1115" [[package]] name = "futures-task" -version = "0.3.17" +version = "0.3.23" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1d3d00f4eddb73e498a54394f228cd55853bdf059259e8e7bc6e69d408892e99" +checksum = "842fc63b931f4056a24d59de13fb1272134ce261816e063e634ad0c15cdc5306" [[package]] name = "futures-util" -version = "0.3.17" +version = "0.3.23" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "36568465210a3a6ee45e1f165136d68671471a501e632e9a98d96872222b5481" +checksum = "f0828a5471e340229c11c77ca80017937ce3c58cb788a17e5f1c2d5c485a9577" dependencies = [ - "autocfg", "futures-core", "futures-task", - "pin-project-lite 0.2.7", + "pin-project-lite", "pin-utils", "slab", ] +[[package]] +name = "heck" +version = "0.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea" + [[package]] name = "hermit-abi" version = "0.1.19" @@ -166,9 +230,9 @@ dependencies = [ [[package]] name = "inotify" -version = "0.9.4" +version = "0.9.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d88ed757e516714cd8736e65b84ed901f72458512111871f20c1d377abdfbf5e" +checksum = "f8069d3ec154eb856955c1c0fbffefbf5f3c40a104ec912d4797314c1801abff" dependencies = [ "bitflags", "inotify-sys", @@ -185,10 +249,22 @@ dependencies = [ ] [[package]] -name = "kqueue" -version = "1.0.4" +name = "is_terminal_polyfill" +version = "1.70.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "058a107a784f8be94c7d35c1300f4facced2e93d2fbe5b1452b44e905ddca4a9" +checksum = "7943c866cc5cd64cbc25b2e01621d07fa8eb2a1a23160ee81ce38704e97b8ecf" + +[[package]] +name = "itoa" +version = "0.3.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8324a32baf01e2ae060e9de58ed0bc2320c9a2833491ee36cd3b4c414de4db8c" + +[[package]] +name = "kqueue" +version = "1.0.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4d6112e8f37b59803ac47a42d14f1f3a59bbf72fc6857ffc5be455e28a691f8e" dependencies = [ "kqueue-sys", "libc", @@ -212,69 +288,58 @@ checksum = "e2abad23fbc42b3700f2f279844dc832adb2b2eb069b2df918f455c4e18cc646" [[package]] name = "libc" -version = "0.2.103" +version = "0.2.132" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "dd8f7255a17a627354f321ef0055d63b898c6fb27eff628af4d1b66b7331edf6" +checksum = "8371e4e5341c3a96db127eb2465ac681ced4c433e01dd0e938adbef26ba93ba5" [[package]] name = "linemux" -version = "0.2.3" +version = "0.2.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "faffd44046d5dcc8b31e76840fa2a9e975b3b6e6ad2db576cf71dca8c27945b9" +checksum = "51157eba73f3dae3b17ae3ea5b29a8ad0346bdff3881e9a00646b827db066a83" dependencies = [ "futures-util", "notify", - "pin-project-lite 0.1.12", + "pin-project-lite", "tokio", ] [[package]] name = "log" -version = "0.4.14" +version = "0.4.17" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "51b9bbe6c47d51fc3e1a9b945965946b4c44142ab8792c50835a980d362c2710" +checksum = "abb12e687cfb44aa40f41fc3978ef76448f9b6038cad6aef4259d3c095a2382e" dependencies = [ "cfg-if", ] [[package]] name = "memchr" -version = "2.4.1" +version = "2.5.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "308cc39be01b73d0d18f82a0e7b2a3df85245f84af96fdddc5d202d27e47b86a" +checksum = "2dffe52ecf27772e601905b7522cb4ef790d2cc203488bbd0e2fe85fcb74566d" [[package]] name = "mio" -version = "0.7.13" +version = "0.8.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8c2bdb6314ec10835cd3293dd268473a835c02b7b352e788be788b3c6ca6bb16" +checksum = "57ee1c23c7c63b0c9250c339ffdc69255f110b298b901b9f6c82547b7b87caaf" dependencies = [ "libc", "log", - "miow", - "ntapi", - "winapi", -] - -[[package]] -name = "miow" -version = "0.3.7" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b9f1c5b025cda876f66ef43a113f91ebc9f4ccef34843000e0adf6ebbab84e21" -dependencies = [ - "winapi", + "wasi", + "windows-sys 0.36.1", ] [[package]] name = "notify" -version = "5.0.0-pre.13" +version = "5.0.0-pre.16" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "245d358380e2352c2d020e8ee62baac09b3420f1f6c012a31326cfced4ad487d" +checksum = "530f6314d6904508082f4ea424a0275cf62d341e118b313663f266429cb19693" dependencies = [ "bitflags", "crossbeam-channel", "filetime", - "fsevent-sys", "inotify", "kqueue", "libc", @@ -284,35 +349,44 @@ dependencies = [ ] [[package]] -name = "ntapi" -version = "0.3.6" +name = "num-traits" +version = "0.1.43" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "3f6bb902e437b6d86e03cce10a7e2af662292c5dfef23b65899ea3ac9354ad44" +checksum = "92e5113e9fd4cc14ded8e499429f396a20f98c772a47cc8622a736e1ec843c31" dependencies = [ - "winapi", + "num-traits 0.2.19", +] + +[[package]] +name = "num-traits" +version = "0.2.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841" +dependencies = [ + "autocfg", ] [[package]] name = "num_cpus" -version = "1.13.0" +version = "1.13.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "05499f3756671c15885fee9034446956fff3f243d6077b91e5767df161f766b3" +checksum = "19e64526ebdee182341572e50e9ad03965aa510cd94427a4549448f285e957a1" dependencies = [ "hermit-abi", "libc", ] [[package]] -name = "pin-project-lite" -version = "0.1.12" +name = "once_cell" +version = "1.20.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "257b64915a082f7811703966789728173279bdebb956b143dbcd23f6f970a777" +checksum = "1261fe7e33c73b354eab43b1273a57c8f967d0391e80353e51f764ac02cf6775" [[package]] name = "pin-project-lite" -version = "0.2.7" +version = "0.2.9" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8d31d11c69a6b52a174b42bdc0c30e5e11670f90788b2c471c31c1d17d449443" +checksum = "e0a7ae3ac2f1173085d398531c705756c94a4c56843785df85a60c1a0afac116" [[package]] name = "pin-utils" @@ -322,36 +396,36 @@ checksum = "8b870d8c151b6f2fb93e84a13146138f05d02ed11c7e7c54f8826aaaf7c9f184" [[package]] name = "proc-macro2" -version = "1.0.29" +version = "1.0.93" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b9f5105d4fdaab20335ca9565e106a5d9b82b6219b5ba735731124ac6711d23d" +checksum = "60946a68e5f9d28b0dc1c21bb8a97ee7d018a8b322fa57838ba31cc878e22d99" dependencies = [ - "unicode-xid", + "unicode-ident", ] [[package]] name = "quote" -version = "1.0.9" +version = "1.0.38" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c3d0b9745dc2debf507c8422de05d7226cc1f0644216dfdfead988f9b1ab32a7" +checksum = "0e4dccaaaf89514f546c693ddc140f729f958c247918a13380cccc6078391acc" dependencies = [ "proc-macro2", ] [[package]] name = "redox_syscall" -version = "0.2.10" +version = "0.2.16" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8383f39639269cde97d255a32bdb68c047337295414940c68bdd30c2e13203ff" +checksum = "fb5a58c1855b4b6819d59012155603f0b22ad30cad752600aadfcb695265519a" dependencies = [ "bitflags", ] [[package]] name = "regex" -version = "1.5.4" +version = "1.6.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d07a8629359eb56f1e2fb1652bb04212c072a87ba68546a04065d525673ac461" +checksum = "4c4eb3267174b8c6c2f654116623910a0fef09c4753f8dd83db29c48a0df988b" dependencies = [ "aho-corasick", "memchr", @@ -360,9 +434,9 @@ dependencies = [ [[package]] name = "regex-syntax" -version = "0.6.25" +version = "0.6.27" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f497285884f3fcff424ffc933e56d7cbca511def0c9831a7f9b5f6153e3cc89b" +checksum = "a3f87b73ce11b1619a3c6332f45341e0047173771e8b8b73f87bfeefb7b56244" [[package]] name = "same-file" @@ -374,79 +448,97 @@ dependencies = [ ] [[package]] -name = "slab" -version = "0.4.4" +name = "serde" +version = "1.0.185" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c307a32c1c5c437f38c7fd45d753050587732ba8628319fbdf12a7e289ccc590" +checksum = "be9b6f69f1dfd54c3b568ffa45c310d6973a5e5148fd40cf515acaf38cf5bc31" [[package]] -name = "strsim" -version = "0.8.0" +name = "serde_json" +version = "1.0.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8ea5119cdb4c55b55d432abb513a0429384878c15dde60cc77b1c99de1a95a6a" - -[[package]] -name = "syn" -version = "1.0.78" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a4eac2e6c19f5c3abc0c229bea31ff0b9b091c7b14990e8924b92902a303a0c0" +checksum = "1c62115693d0a9ed8c32d1c760f0fdbe7d4b05cb13c135b9b54137ac0d59fccb" dependencies = [ - "proc-macro2", - "quote", - "unicode-xid", + "dtoa", + "itoa", + "num-traits 0.1.43", + "serde", ] [[package]] -name = "textwrap" -version = "0.11.0" +name = "slab" +version = "0.4.7" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d326610f408c7a4eb6f51c37c330e496b08506c9457c9d34287ecc38809fb060" +checksum = "4614a76b2a8be0058caa9dbbaf66d988527d86d003c11a94fbd335d7661edcef" dependencies = [ - "unicode-width", + "autocfg", +] + +[[package]] +name = "strsim" +version = "0.11.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f" + +[[package]] +name = "syn" +version = "1.0.99" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "58dbef6ec655055e20b86b15a8cc6d439cca19b667537ac6a1369572d151ab13" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "syn" +version = "2.0.96" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d5d0adab1ae378d7f53bdebc67a39f1f151407ef230f0ce2883572f5d8985c80" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", ] [[package]] name = "tokio" -version = "1.12.0" +version = "1.20.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c2c2416fdedca8443ae44b4527de1ea633af61d8f7169ffa6e72c5b53d24efcc" +checksum = "7a8325f63a7d4774dd041e363b2409ed1c5cbbd0f867795e661df066b2b0a581" dependencies = [ "autocfg", "bytes", "memchr", "num_cpus", - "pin-project-lite 0.2.7", + "once_cell", + "pin-project-lite", "tokio-macros", ] [[package]] name = "tokio-macros" -version = "1.4.1" +version = "1.8.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "154794c8f499c2619acd19e839294703e9e32e7630ef5f46ea80d4ef0fbee5eb" +checksum = "9724f9a975fb987ef7a3cd9be0350edcbe130698af5b8f7a631e23d42d052484" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 1.0.99", ] [[package]] -name = "unicode-width" -version = "0.1.9" +name = "unicode-ident" +version = "1.0.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "3ed742d4ea2bd1176e236172c8429aaf54486e7ac098db29ffe6529e0ce50973" +checksum = "c4f5b37a154999a8f3f98cc23a628d850e154479cd94decf3414696e12e31aaf" [[package]] -name = "unicode-xid" +name = "utf8parse" version = "0.2.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8ccb82d61f80a663efe1f787a51b16b5a51e3314d6ac365b08639f52387b33f3" - -[[package]] -name = "vec_map" -version = "0.8.2" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f1bddf1187be692e79c5ffeab891132dfb0f236ed36a43c7ed39f1165ee20191" +checksum = "06abde3611657adf66d383f00b093d7faecc7fa57071cce2578660c9f1010821" [[package]] name = "walkdir" @@ -459,6 +551,12 @@ dependencies = [ "winapi-util", ] +[[package]] +name = "wasi" +version = "0.11.0+wasi-snapshot-preview1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423" + [[package]] name = "winapi" version = "0.3.9" @@ -489,3 +587,119 @@ name = "winapi-x86_64-pc-windows-gnu" version = "0.4.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "712e227841d057c1ee1cd2fb22fa7e5a5461ae8e48fa2ca79ec42cfc1931183f" + +[[package]] +name = "windows-sys" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ea04155a16a59f9eab786fe12a4a450e75cdb175f9e0d80da1e17db09f55b8d2" +dependencies = [ + "windows_aarch64_msvc 0.36.1", + "windows_i686_gnu 0.36.1", + "windows_i686_msvc 0.36.1", + "windows_x86_64_gnu 0.36.1", + "windows_x86_64_msvc 0.36.1", +] + +[[package]] +name = "windows-sys" +version = "0.59.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1e38bc4d79ed67fd075bcc251a1c39b32a1776bbe92e5bef1f0bf1f8c531853b" +dependencies = [ + "windows-targets", +] + +[[package]] +name = "windows-targets" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9b724f72796e036ab90c1021d4780d4d3d648aca59e491e6b98e725b84e99973" +dependencies = [ + "windows_aarch64_gnullvm", + "windows_aarch64_msvc 0.52.6", + "windows_i686_gnu 0.52.6", + "windows_i686_gnullvm", + "windows_i686_msvc 0.52.6", + "windows_x86_64_gnu 0.52.6", + "windows_x86_64_gnullvm", + "windows_x86_64_msvc 0.52.6", +] + +[[package]] +name = "windows_aarch64_gnullvm" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "32a4622180e7a0ec044bb555404c800bc9fd9ec262ec147edd5989ccd0c02cd3" + +[[package]] +name = "windows_aarch64_msvc" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9bb8c3fd39ade2d67e9874ac4f3db21f0d710bee00fe7cab16949ec184eeaa47" + +[[package]] +name = "windows_aarch64_msvc" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "09ec2a7bb152e2252b53fa7803150007879548bc709c039df7627cabbd05d469" + +[[package]] +name = "windows_i686_gnu" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "180e6ccf01daf4c426b846dfc66db1fc518f074baa793aa7d9b9aaeffad6a3b6" + +[[package]] +name = "windows_i686_gnu" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8e9b5ad5ab802e97eb8e295ac6720e509ee4c243f69d781394014ebfe8bbfa0b" + +[[package]] +name = "windows_i686_gnullvm" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0eee52d38c090b3caa76c563b86c3a4bd71ef1a819287c19d586d7334ae8ed66" + +[[package]] +name = "windows_i686_msvc" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e2e7917148b2812d1eeafaeb22a97e4813dfa60a3f8f78ebe204bcc88f12f024" + +[[package]] +name = "windows_i686_msvc" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "240948bc05c5e7c6dabba28bf89d89ffce3e303022809e73deaefe4f6ec56c66" + +[[package]] +name = "windows_x86_64_gnu" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4dcd171b8776c41b97521e5da127a2d86ad280114807d0b2ab1e462bc764d9e1" + +[[package]] +name = "windows_x86_64_gnu" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "147a5c80aabfbf0c7d901cb5895d1de30ef2907eb21fbbab29ca94c5b08b1a78" + +[[package]] +name = "windows_x86_64_gnullvm" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "24d5b23dc417412679681396f2b49f3de8c1473deb516bd34410872eff51ed0d" + +[[package]] +name = "windows_x86_64_msvc" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c811ca4a8c853ef420abd8592ba53ddbbac90410fab6903b3e79972a631f7680" + +[[package]] +name = "windows_x86_64_msvc" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "589f6da84c646204747d1270a2a5661ea66ed1cced2631d546fdfb155959f9ec" diff --git a/Cargo.toml b/Cargo.toml index 25f875d..5ae063d 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "blockfast" -version = "0.1.0" +version = "0.2.0" authors = ["Pierre Dubouilh "] edition = "2018" @@ -11,5 +11,6 @@ linemux = "0.2" tokio = { version = "1", features = ["rt-multi-thread", "macros"] } lazy_static = "1.4.0" regex = "1.5.4" -clap = "2.33.3" anyhow = "1.0.44" +serde_json = "=1.0.1" +clap = { version = "4.5.27", features = ["derive"] } diff --git a/Makefile b/Makefile index 077aef0..40320ca 100644 --- a/Makefile +++ b/Makefile @@ -1,23 +1,61 @@ -build: +build:: cargo build - cargo clippy - cargo fmt + cargo clippy --all + cargo fmt --all -run: - cargo run -- -s=/tmp/sshdtest -c=/tmp/clftest +run:: + touch /tmp/sshdtest + touch /tmp/clftest + touch /tmp/jsontest + touch /tmp/generictest + cargo build + sudo target/debug/blockfast -v -s=/tmp/sshdtest -c=/tmp/clftest -j=/tmp/jsontest --generic-logpath=/tmp/generictest --generic-ip='from ([0-9a-fA-F:.]+) port' --generic-positive='Failed password' -watch: +ci:: test + cargo fmt --all -- --check + cargo clippy -- -D warnings + +build-all:: + mkdir -p builds + rustc --version > builds/buildout + cross build --release --target x86_64-unknown-linux-musl + cross build --release --target aarch64-unknown-linux-musl + cross build --release --target armv7-unknown-linux-musleabihf + cp target/x86_64-unknown-linux-musl/release/blockfast builds/blockfast-x86_64-linux + cp target/aarch64-unknown-linux-musl/release/blockfast builds/blockfast-aarch64-linux + cp target/armv7-unknown-linux-musleabihf/release/blockfast builds/blockfast-arm7-linux + sha256sum builds/* >> builds/buildout + +watch:: ls src/*.rs | entr -rc -- make run -test: +test:: cargo test -watch-test: - ls src/*.rs | entr -rc -- make test - -release: +release:: cargo build --target x86_64-unknown-linux-musl --release -ci: test - cargo fmt --all -- --check - cargo clippy -- -D warnings \ No newline at end of file +hit-sshd:: + echo "Sep 26 06:25:32 livecompute sshd[23254]: Invalid user neal from 9.124.36.195" >> /tmp/sshdtest + +ok-sshd:: + echo "Sep 26 06:25:19 livecompute sshd[23246]: successful login 8.124.36.195 port 41883 ssh2" >> /tmp/sshdtest + +hit-generic:: + echo "Sep 26 06:25:19 livecompute sshd[23246]: Failed password for root from 179.124.36.195 port 41883 ssh2" >> /tmp/generictest + +ok-generic:: + echo "Sep 26 06:25:19 livecompute sshd[23246]: Successful login for root from 179.124.36.195 port 41883 ssh2" >> /tmp/generictest + +hit-clf:: + echo "1.124.36.195 - p [25/Sep/2021:13:49:56 +0200] \"POST /some/rpc HTTP/2.0\" 401 923" >> /tmp/clftest + +ok-clf:: + echo "2.124.36.195 - p [25/Sep/2021:13:49:56 +0200] \"POST /some/rpc HTTP/2.0\" 200 23012" >> /tmp/clftest + +hit-json:: + echo "{\"request\":{\"remote_ip\":\"1.124.36.19\"}, \"status\": 400}" >> /tmp/jsontest + +ok-json:: + echo "{\"request\":{\"remote_ip\":\"2.124.36.19\"}, \"status\": 200}" >> /tmp/jsontest + diff --git a/README.md b/README.md index 762f924..5e872cc 100644 --- a/README.md +++ b/README.md @@ -1,13 +1,78 @@ # blockfast -block ssh and http scanners fast +Block internets scanners fast 🍶 -features: - - generic SSH log parser - - generic Common Log Format parser (apache logs, caddy logs, etc...) - - sane defaults - - fast ip ban with `ipset` - - libmusl static release builds, no libc dependency - - lighter alternative to fail2ban +Features: + - SSH log parser + - Common Log Format parser (apache logs, etc...) + - JSON log parser (caddy logs) + - Generic log parser + - Sane defaults + - Fast ip ban with `ipset` + - Static release builds, no libc dependency + - Lighter alternative to fail2ban -Todo: more granular CLI args to filter HTTP Status codes (e.g. 5 401 leads to a block, but 30 404 before a block) ? +## example +```txt +$ ./blockfast -s=/var/log/auth.log -j=/caddy/logs +1737927469 - starting with sshd parsing at "/tmp/sshdtest" +1737927469 - starting with json parsing at "/tmp/jsontest" +1737927469 - jail setup, allowance 5, time 21600s +1737927477 - sshd logged offence for 9.124.36.195 +1737927478 - sshd logged offence for 9.124.36.195 +1737927479 - sshd logged offence for 9.124.36.195 +1737927479 - sshd logged offence for 9.124.36.195 +1737927480 - sshd logged offence for 9.124.36.195 +1737927480 - sshd jailtime for 9.124.36.195 +``` + +## build +see `Makefile` + +## usage +```txt +$ target/debug/blockfast +Blockfast - block internets scanners fast 🍶 +Author: pierre dubouilh + +Blockfast reads logs from various sources and blocks the offending IPs using iptables and ipset. +It supports logs from sshd, Common-Log-Format (Apache, etc..), JSON (Caddy) and a generic logs parser. + +Example: + # block invalid sshd attempts & invalid http statuses from caddy + ./blockfast -s=/var/log/auth.log -j=/caddy/logs + + # generic log parser example with a log text to flag, and a regex to parse the offending IP. + ./blockfast --generic-logpath=/tmp/generictest --generic-positive='Failed password' --generic-ip='from ([0-9a-fA-F:.]+) port' + +Usage: blockfast [OPTIONS] +Usage: blockfast [OPTIONS] + +Options: + --jailtime + jail time (seconds) [default: 21600] + --allowance + how many offences allowed (max 255) [default: 5] + -v, --verbose + log all offences + -s, --sshd-logpath + path of sshd logfile + -c, --clf-logpath + path of Common-Log-Format logfile (Apache, etc..) + -j, --json-logpath + path of JSON HTTP logfile (Caddy) + --generic-logpath + generic parser log file path + --generic-ip + generic parser ip regex + --generic-positive + generic parser positive - if a logline contains this, it is considered bad, the rest is good + --generic-negative + generic parser negative - if a logline contains this, it is considered good, the rest is bad + --valid-http-statuses + valid http statuses (for CLF and JSON logs) [default: 200 101] + -h, --help + Print help + -V, --version + Print version +``` diff --git a/rust-toolchain.toml b/rust-toolchain.toml new file mode 100644 index 0000000..3cf2110 --- /dev/null +++ b/rust-toolchain.toml @@ -0,0 +1,2 @@ +[toolchain] +channel = "1.81.0" \ No newline at end of file diff --git a/src/clf.rs b/src/clf.rs index 63453ad..36760c9 100644 --- a/src/clf.rs +++ b/src/clf.rs @@ -1,28 +1,33 @@ use crate::utils::ParsingStatus; -use anyhow::Result; +use anyhow::*; use lazy_static::lazy_static; -use std::net::IpAddr; +use regex::Regex; +use std::{net::IpAddr, str::FromStr}; -// TODO: allow user-provided list -// TODO: match different error-levels (10 404, but only 5 401, etc...) lazy_static! { - static ref BAD_STATUSES: [u32; 2] = [401, 429]; + static ref RE_IP: Regex = Regex::new(r"^(\S+)\s").unwrap(); + static ref RE_STATUS: Regex = Regex::new(r"(\d+)\s(\w+)$").unwrap(); } -pub fn parse(line: &str) -> Result { - // TODO: Use a proper parser ? - let elts: Vec<&str> = line.split_whitespace().collect(); +#[allow(clippy::bind_instead_of_map)] +pub fn parse(line: &str, valid_statuses: &[u32]) -> Result { + let ip = RE_IP + .captures(line) + .and_then(|c| c.get(1)) + .and_then(|g| Some(g.as_str())) + .and_then(|e| IpAddr::from_str(e).ok()) + .ok_or_else(|| anyhow!("cant parse clf line - ip"))?; - let ip_str = elts[0]; - let ip = ip_str.parse::()?; + let status = RE_STATUS + .captures(line) + .and_then(|c| c.get(1)) + .and_then(|g| Some(g.as_str())) + .and_then(|e| e.parse::().ok()) + .ok_or_else(|| anyhow!("cant parse clf line - status"))?; - let http_code_str = elts[elts.len() - 2] as &str; - let http_code = http_code_str.parse::()?; - - for status in BAD_STATUSES.iter() { - if *status == http_code { - return Ok(ParsingStatus::BadEntry(ip)); - } + let is_good_status = valid_statuses.iter().any(|s| s == &status); + if !is_good_status { + return Ok(ParsingStatus::BadEntry(ip)); } Ok(ParsingStatus::OkEntry) @@ -40,7 +45,7 @@ mod tests { ]; vectors.iter().for_each(|e| { - let ret = parse(*e).unwrap(); + let ret = parse(*e, &vec![200, 404]).unwrap(); match ret { ParsingStatus::BadEntry(_) => {} _ => panic!("bad parsing"), @@ -56,7 +61,7 @@ mod tests { ]; vectors.iter().for_each(|e| { - let ret = parse(*e).unwrap(); + let ret = parse(*e, &vec![200, 404]).unwrap(); match ret { ParsingStatus::OkEntry => {} _ => panic!("bad parsing"), @@ -72,7 +77,7 @@ mod tests { ]; vectors.iter().for_each(|e| { - let ret = parse(*e); + let ret = parse(*e, &vec![200, 404]); assert!(ret.is_err()); }) } diff --git a/src/generic.rs b/src/generic.rs new file mode 100644 index 0000000..86da75a --- /dev/null +++ b/src/generic.rs @@ -0,0 +1,83 @@ +use crate::utils::ParsingStatus; +use anyhow::*; +use regex::Regex; +use std::{net::IpAddr, str::FromStr}; + +#[allow(clippy::bind_instead_of_map)] +pub fn parse( + line: &str, + ip: Option<&Regex>, + positive: Option<&String>, + negative: Option<&String>, +) -> Result { + if let Some(ne) = negative { + if line.contains(ne) { + return Ok(ParsingStatus::OkEntry); + } + } + + if let Some(po) = positive { + if !line.contains(po) { + return Ok(ParsingStatus::OkEntry); + } + } + + let ip = ip.unwrap().captures(line); + + let ip = ip + .and_then(|c| c.get(1)) + .and_then(|g| Some(g.as_str())) + .and_then(|e| IpAddr::from_str(e).ok()) + .ok_or_else(|| anyhow!("cant parse clf line - ip"))?; + + Ok(ParsingStatus::BadEntry(ip)) +} + +#[cfg(test)] +mod tests { + use super::*; + + const FAILED: &str = + "Sep 26 06:25:19 livecompute sshd[23246]: Failed password for root from 179.124.36.195 port 41883 ssh2"; + + const SUCCESS: &str = + "Sep 26 06:25:19 livecompute sshd[23246]: Successful login for root from 179.124.36.195 port 41883 ssh2"; + + // generic log positive regex - what's that's flagged by this is considered bad, the rest is good + #[test] + fn positive() { + let positive = "Failed password".to_string(); + let ip = Regex::new(r"from ([0-9a-fA-F:.]+) port").unwrap(); + + let ret = parse(FAILED, Some(&ip), Some(&positive), None).unwrap(); + match ret { + ParsingStatus::BadEntry(_) => {} + _ => panic!("bad parsing"), + } + + let ret = parse(SUCCESS, Some(&ip), Some(&positive), None).unwrap(); + match ret { + ParsingStatus::OkEntry => {} + _ => panic!("bad parsing"), + } + } + + // generic log negative regex - what's that's flagged by this is considered good, the rest is bad + #[test] + fn negative() { + let negative = "Successful login".to_string(); + let ip = Regex::new(r"from ([0-9a-fA-F:.]+) port").unwrap(); + + let ret = parse(SUCCESS, Some(&ip), None, Some(&negative)).unwrap(); + match ret { + ParsingStatus::OkEntry => {} + _ => panic!("bad parsing"), + } + + let ret = parse(FAILED, Some(&ip), None, Some(&negative)).unwrap(); + match ret { + ParsingStatus::BadEntry(_) => {} + _ => panic!("bad parsing"), + } + } +} diff --git a/src/jail.rs b/src/jail.rs index 1038c09..c7d3916 100644 --- a/src/jail.rs +++ b/src/jail.rs @@ -5,114 +5,81 @@ use std::sync::Mutex; use anyhow::*; -use crate::utils::JailStatus; +use crate::utils::{get_epoch, log}; pub struct Jail { - jailtime: u32, + name: String, allowance: u8, - remand: Mutex>, + jailtime: u32, + remand: Mutex>, } -const JAIL_NAME: &str = "blockfast_jail"; - -const ERR_MSG: &str = - "error using ipset/iptables, maybe it's not installed, this program isn't running as root ?"; - -fn ipset_init() -> Result<()> { - let init0 = format!("ipset create {} hash:ip timeout 0", JAIL_NAME); - let init1 = format!( - "iptables -I INPUT 1 -m set -j DROP --match-set {} src", - JAIL_NAME - ); - let init2 = format!( - "iptables -I FORWARD 1 -m set -j DROP --match-set {} src", - JAIL_NAME - ); - - let args0: Vec<&str> = init0.split_whitespace().collect(); - let args1: Vec<&str> = init1.split_whitespace().collect(); - let args2: Vec<&str> = init2.split_whitespace().collect(); - - // create - let out = Command::new("sudo").args(args0).output()?; - if out.status.code() != Some(0) { - let already_exists = - std::str::from_utf8(&out.stderr)?.contains("set with the same name already exists"); - - if already_exists { - return Ok(()); - } else { - eprintln!("{:?}", out); - bail!(ERR_MSG); - } - } - - // setup input - let out = Command::new("sudo").args(args1).output()?; - if out.status.code() != Some(0) { - eprintln!("{:?}", out); - bail!(ERR_MSG); - } - - // setup fwd - let out = Command::new("sudo").args(args2).output()?; - if out.status.code() != Some(0) { - eprintln!("{:?}", out); - bail!(ERR_MSG); - } - - Ok(()) -} - -fn ipset_block(jailtime: u32, ip: IpAddr) -> Result<()> { - let sentence = format!( - "ipset add {} {} timeout {}", - JAIL_NAME, - ip.to_string(), - jailtime - ); - let sentence_sl: Vec<&str> = sentence.split_whitespace().collect(); - - let out = Command::new("sudo").args(sentence_sl).output()?; - if out.status.code() != Some(0) { - eprintln!("{:?}", out); - bail!("error executing ipset ban"); - } - +fn exec(program: &str, cmd: &str, err: &str) -> Result<(), Error> { + let sentence_sl: Vec<&str> = cmd.split_whitespace().collect(); + let out = Command::new(program).args(sentence_sl).output()?; + let sc = out.status.code(); + ensure!(sc == Some(0), "err exec {}, {:?}\n{}", cmd, out, err); Ok(()) } impl Jail { pub fn new(allowance: u8, jailtime: u32) -> Result { - ipset_init()?; + const ERR_MSG: &str = "error using ipset/iptables, maybe it's not installed, or this program isn't running as root ?"; + let n = format!("blockfast_jail_{}", jailtime); + // create + let cmd = format!("create -exist {} hash:ip timeout {}", n, jailtime); + exec("ipset", &cmd, ERR_MSG)?; + + // setup input + let cmd = format!("-I INPUT 1 -m set -j DROP --match-set {} src", n); + exec("iptables", &cmd, ERR_MSG)?; + + // setup fwd + let cmd = format!("-I FORWARD 1 -m set -j DROP --match-set {} src", n); + exec("iptables", &cmd, ERR_MSG)?; + + log!("jail setup, allowance {}, time {}s", allowance, jailtime); Ok(Jail { + name: n, allowance, jailtime, remand: Mutex::new(HashMap::new()), }) } - pub fn probe(&self, ip: IpAddr) -> Result { + pub fn sentence(&self, ip: IpAddr) -> Result { + let now = get_epoch(); + let should_ban = { let mut locked_map = self.remand.lock().map_err(|_| anyhow!("cant lock"))?; - // TODO: set time of last offence, and add grace - let hits = *locked_map.entry(ip).and_modify(|e| *e += 1).or_insert(1); - + let (hits, _ts) = *locked_map + .entry(ip) + .and_modify(|(hits, ts)| { + if now > *ts + self.jailtime as u64 { + // reset if we have a hit, but past the defined jailtime + *ts = now; + *hits = 1; + } else { + *hits += 1; // bump + } + }) + .or_insert((1, now)); if hits < self.allowance { false } else { - locked_map.remove_entry(&ip); // preserve space + locked_map.remove_entry(&ip); true } }; if should_ban { - ipset_block(self.jailtime, ip)?; - Ok(JailStatus::Jailed(ip)) - } else { - Ok(JailStatus::Remand) + let cmd = format!("add -exist {} {}", self.name, ip); + exec("ipset", &cmd, "")?; + return Ok(true); } + + Ok(false) } } diff --git a/src/json.rs b/src/json.rs new file mode 100644 index 0000000..5752fb9 --- /dev/null +++ b/src/json.rs @@ -0,0 +1,75 @@ +use crate::utils::ParsingStatus; +use anyhow::*; +use std::{net::IpAddr, str::FromStr}; + +pub fn parse(line: &str, valid_statuses: &[u32]) -> Result { + let json: serde_json::Value = serde_json::from_str(line)?; + + let remote_ip = json + .get("request") + .and_then(|r| r.get("remote_ip")) + .and_then(|r| r.as_str()) + .and_then(|r| IpAddr::from_str(r).ok()) + .ok_or_else(|| anyhow!("cant parse json line - remote_ip"))?; + + let status = json + .get("status") + .and_then(|r| r.as_u64()) + .ok_or_else(|| anyhow!("cant parse json line - status"))?; + + let is_good_status = valid_statuses.iter().any(|s| s == &(status as u32)); + if !is_good_status { + return Ok(ParsingStatus::BadEntry(remote_ip)); + } + + Ok(ParsingStatus::OkEntry) +} + +#[cfg(test)] +mod tests { + use super::*; + + #[test] + fn positive() { + let vectors = [ + r#"{"level":"info","ts":1738064403.2176833,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"127.0.0.1","remote_port":"46884","client_ip":"127.0.0.1","proto":"HTTP/1.1","method":"GET","host":"127.0.0.1:8009","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Mode":["navigate"],"Accept-Language":["en-US,en;q=0.5"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Connection":["keep-alive"],"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Site":["cross-site"],"Priority":["u=0, i"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"]}},"bytes_read":0,"user_id":"","duration":0.002135063,"size":35133,"status":429,"resp_headers":{"Vary":["Accept, Accept-Encoding"],"Last-Modified":["Tue, 28 Jan 2025 12:40:02 GMT"],"Content-Type":["text/html; charset=utf-8"],"Server":["Caddy"]}}"#, + r#"{"level":"info","ts":1738064403.2176833,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"127.0.0.1","remote_port":"46884","client_ip":"127.0.0.1","proto":"HTTP/1.1","method":"GET","host":"127.0.0.1:8009","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Mode":["navigate"],"Accept-Language":["en-US,en;q=0.5"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Connection":["keep-alive"],"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Site":["cross-site"],"Priority":["u=0, i"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"]}},"bytes_read":0,"user_id":"","duration":0.002135063,"size":35133,"status":401,"resp_headers":{"Vary":["Accept, Accept-Encoding"],"Last-Modified":["Tue, 28 Jan 2025 12:40:02 GMT"],"Content-Type":["text/html; charset=utf-8"],"Server":["Caddy"]}}"#, + ]; + + vectors.iter().for_each(|e| { + let ret = parse(*e, &vec![200, 404]).unwrap(); + match ret { + ParsingStatus::BadEntry(_) => {} + _ => panic!("bad parsing"), + } + }) + } + + #[test] + fn negative() { + let vectors = [ + r#"{"level":"info","ts":1738064403.2176833,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"127.0.0.1","remote_port":"46884","client_ip":"127.0.0.1","proto":"HTTP/1.1","method":"GET","host":"127.0.0.1:8009","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Mode":["navigate"],"Accept-Language":["en-US,en;q=0.5"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Connection":["keep-alive"],"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Site":["cross-site"],"Priority":["u=0, i"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"]}},"bytes_read":0,"user_id":"","duration":0.002135063,"size":35133,"status":200,"resp_headers":{"Vary":["Accept, Accept-Encoding"],"Last-Modified":["Tue, 28 Jan 2025 12:40:02 GMT"],"Content-Type":["text/html; charset=utf-8"],"Server":["Caddy"]}}"#, + r#"{"level":"info","ts":1738064403.2176833,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"127.0.0.1","remote_port":"46884","client_ip":"127.0.0.1","proto":"HTTP/1.1","method":"GET","host":"127.0.0.1:8009","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Mode":["navigate"],"Accept-Language":["en-US,en;q=0.5"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Connection":["keep-alive"],"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Site":["cross-site"],"Priority":["u=0, i"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"]}},"bytes_read":0,"user_id":"","duration":0.002135063,"size":35133,"status":404,"resp_headers":{"Vary":["Accept, Accept-Encoding"],"Last-Modified":["Tue, 28 Jan 2025 12:40:02 GMT"],"Content-Type":["text/html; charset=utf-8"],"Server":["Caddy"]}}"#, + ]; + + vectors.iter().for_each(|e| { + let ret = parse(*e, &vec![200, 404]).unwrap(); + match ret { + ParsingStatus::OkEntry => {} + _ => panic!("bad parsing"), + } + }) + } + + #[test] + fn malformed() { + let vectors = [ + r#"{"level":"info","ts":1738064403.2176833,"logger":"http.log.access.log0","msg":"handled request","requeto":"HTTP/1 x86_64; rv:133.0)"],"Server":["Caddy"]}}"#, + ]; + + vectors.iter().for_each(|e| { + let ret = parse(*e, &vec![200, 404]); + assert!(ret.is_err()); + }) + } +} diff --git a/src/main.rs b/src/main.rs index 17a4800..82fc09f 100644 --- a/src/main.rs +++ b/src/main.rs @@ -1,7 +1,12 @@ +use std::result::Result::Ok; + use anyhow::*; -use linemux::MuxedLines; +use clap::Parser; +use linemux::{Line, MuxedLines}; mod clf; +mod generic; +mod json; mod sshd; mod utils; @@ -9,91 +14,110 @@ mod jail; use crate::jail::Jail; use crate::utils::*; -fn judge( - path_sshd: &str, - path_clf: &str, - payload: &str, - path: &str, - jail: &Jail, -) -> Result { - let do_sshd = !path_sshd.is_empty(); - let do_clf = !path_clf.is_empty(); - let mut target = ""; - - let ret_parse = if do_sshd && path.ends_with(path_sshd) { - target = "sshd"; - sshd::parse(payload) - } else if do_clf && path.ends_with(path_clf) { - target = "clf "; - clf::parse(payload) - } else { - Err(anyhow!("cant locate file !")) - }; - - let ip = match ret_parse? { - ParsingStatus::OkEntry => return Ok(Judgment::Good), - ParsingStatus::BadEntry(ip) => ip, - }; - - match jail.probe(ip)? { - JailStatus::Remand => Ok(Judgment::Remand), - JailStatus::Jailed(ip) => Ok(Judgment::Bad(target, ip)), - } -} - async fn run() -> Result<()> { - let args = utils::cli().get_matches(); - let mut lines = MuxedLines::new()?; + let args = utils::Args::parse(); + let mut ml = MuxedLines::new()?; - // jail - let jailtime_str = args.value_of("jailtime").unwrap_or(""); - let jailtime = jailtime_str.parse().context("parsing jailtime")?; + // HTTP statuses + let ok_statuses = args.valid_http_statuses.clone(); + let ok_statuses_parsed = parse_statuses(&ok_statuses)?; + let ok_statuses_ref = ok_statuses_parsed.as_ref(); - let allowance_str = args.value_of("allowance").unwrap_or(""); - let allowance = allowance_str.parse().context("parsing allowance")?; - - let jail = Jail::new(allowance, jailtime)?; - eprintln!( - "+ jail setup, offences allowed: {}, jailtime {}s", - allowance, jailtime - ); + // generic parser + let generic_path = args.generic_logpath.as_ref(); + let generic_ip_re = args.generic_ip.as_ref(); + let generic_positive = args.generic_positive.as_ref(); + let generic_negative = args.generic_negative.as_ref(); + if args.generic_ip.is_some() + || args.generic_logpath.is_some() + || args.generic_positive.is_some() + || args.generic_negative.is_some() + { + if args.generic_ip.is_none() || args.generic_logpath.is_none() { + bail!("generic parser needs both ip regex and log file path"); + } + if !(args.generic_positive.is_some() ^ args.generic_negative.is_some()) { + bail!("generic parser requires either a positive or a negative regex"); + } + if let Some(p) = generic_path.as_ref() { + ml.add_file(&p).await?; + log!("starting with generic parsing at {:?}", &p); + } + } // sshd - let path_sshd = args.value_of("sshd_logpath").unwrap_or(""); - if !path_sshd.is_empty() { - lines.add_file(path_sshd).await?; - eprintln!("+ starting with sshd parsing at {}", path_sshd); + let sshd_logpath = args.sshd_logpath.as_ref(); + if let Some(p) = sshd_logpath { + ml.add_file(&p).await?; + log!("starting with sshd parsing at {:?}", &p); } // common log format - let path_clf = args.value_of("clf_logpath").unwrap_or(""); - if !path_clf.is_empty() { - lines.add_file(path_clf).await?; - eprintln!("+ starting with clf parsing at {}", path_clf); + let clf_logpath = args.clf_logpath.as_ref(); + if let Some(p) = clf_logpath { + ml.add_file(&p).await?; + log!("starting with clf parsing at {:?}", &p); } - while let Ok(Some(line)) = lines.next_line().await { - let payload = line.line(); - let path = line.source().display().to_string(); + // json + let json_logpath = args.json_logpath.as_ref(); + if let Some(p) = json_logpath { + ml.add_file(&p).await?; + log!("starting with json parsing at {:?}", &p); + } - match judge(path_sshd, path_clf, payload, &path, &jail) { - Err(err) => eprintln!("! ERR {:?} - file {}", err, path), - Ok(Judgment::Good) => {} - Ok(Judgment::Remand) => {} - Ok(Judgment::Bad(target, ip)) => { - eprintln!("~ too many infraction, {} jailtime for: {}", target, ip) - } + if json_logpath.is_none() && clf_logpath.is_none() && sshd_logpath.is_none() { + bail!("no log files to parse, see --help"); + } + + // jail + let jail = Jail::new(args.allowance, args.jailtime)?; + + let assess_line = |line: Line| { + let payload = line.line(); + let path_buf = Some(line.source().to_path_buf()); + let path = path_buf.as_ref(); + + let (target, ret) = if path == sshd_logpath { + ("sshd", sshd::parse(payload)?) + } else if path == clf_logpath { + ("clf", clf::parse(payload, ok_statuses_ref)?) + } else if path == json_logpath { + ("json", json::parse(payload, ok_statuses_ref)?) + } else if path == generic_path { + ( + "generic", + generic::parse(payload, generic_ip_re, generic_positive, generic_negative)?, + ) + } else { + bail!("file {:?} unknown ?", path) }; + + if let ParsingStatus::BadEntry(ip) = ret { + if args.verbose { + log!("{} logged offence for {}", target, ip); + } + let banned = jail.sentence(ip)?; + if banned { + log!("{} jailtime for {}", target, ip); + } + } + + Ok(()) + }; + + while let Ok(Some(line)) = ml.next_line().await { + if let Err(e) = assess_line(line) { + log!("ERR: {:?}", e); + } } Ok(()) } #[tokio::main] -async fn main() -> std::io::Result<()> { - let ret = run().await; - let _ = ret.map_err(|e| eprintln!("! ERROR {:?}", e)); +async fn main() -> Result<()> { + run().await?; eprintln!("\n"); - let _ = utils::cli().print_help(); Ok(()) } diff --git a/src/sshd.rs b/src/sshd.rs index 17a93aa..44311ca 100644 --- a/src/sshd.rs +++ b/src/sshd.rs @@ -1,8 +1,7 @@ use anyhow::*; use lazy_static::lazy_static; use regex::Regex; -use std::net::IpAddr; -use std::str::FromStr; +use std::{net::IpAddr, str::FromStr}; use crate::utils::ParsingStatus; @@ -15,27 +14,24 @@ lazy_static! { static ref SSHD_BAD: [Rule; 3] = [ Rule { matcher: "Failed password".to_string(), - extractor: Regex::new(r"(from.)(.*)(.port)").unwrap(), + extractor: Regex::new(r"(from.)(\S+)").unwrap(), }, Rule { matcher: "Invalid user ".to_string(), - extractor: Regex::new(r"(from.)(.*)").unwrap(), + extractor: Regex::new(r"(from.)(\S+)").unwrap(), }, Rule { matcher: "authentication failure".to_string(), - extractor: Regex::new(r"(rhost=)(.*)").unwrap() + extractor: Regex::new(r"(rhost=)(\S+)").unwrap() }, ]; } pub fn parse(line: &str) -> Result { - let hits = SSHD_BAD.iter().find_map(|rule| { - if line.contains(&rule.matcher) { - rule.extractor.captures(line) - } else { - None - } - }); + let hits = SSHD_BAD + .iter() + .find(|rule| line.contains(&rule.matcher)) + .and_then(|r| r.extractor.captures(line)); if hits.is_none() { return Ok(ParsingStatus::OkEntry); @@ -43,12 +39,10 @@ pub fn parse(line: &str) -> Result { let ip = hits .and_then(|c| c.get(2)) - .and_then(|m| IpAddr::from_str(m.as_str()).ok()); + .and_then(|m| IpAddr::from_str(m.as_str()).ok()) + .ok_or_else(|| anyhow!("cant parse sshd line"))?; - match ip { - Some(ip) => Ok(ParsingStatus::BadEntry(ip)), - None => Err(anyhow!("cant parse sshd entry")), - } + Ok(ParsingStatus::BadEntry(ip)) } #[cfg(test)] @@ -93,12 +87,10 @@ mod tests { fn malformed() { let vectors = [ "Sep 26 06:25:19 livecompute sshd[23246]: Failed password for root from 179.124.36.195.232 port 41883 ssh2", - "Sep 26 06:26:14 livecompute sshd[23292]: pam_unix(sshd:auth): authentication failure; logname= u =0 tty=ssh ruser= rhost=", ]; vectors.iter().for_each(|e| { - let ret = parse(*e); - assert!(ret.is_err()); + parse(*e).expect_err(""); }) } } diff --git a/src/utils.rs b/src/utils.rs index afd98a8..601f4a4 100644 --- a/src/utils.rs +++ b/src/utils.rs @@ -1,61 +1,142 @@ -use clap::{App, Arg}; -use std::net::IpAddr; +use anyhow::{anyhow, Context, Result}; +use clap::Parser; +use regex::Regex; +use std::{ + net::IpAddr, + path::{Path, PathBuf}, +}; +#[derive(Debug)] pub enum ParsingStatus { OkEntry, BadEntry(IpAddr), } -pub enum Judgment { - Good, - Remand, - Bad(&'static str, IpAddr), + +pub fn get_epoch() -> u64 { + let e = std::time::SystemTime::now().duration_since(std::time::UNIX_EPOCH); + e.map(|e| e.as_secs()).unwrap_or(0) } -pub enum JailStatus { - Remand, - Jailed(IpAddr), +macro_rules! log{ + ($first:expr) => { + let ts = crate::utils::get_epoch(); + eprintln!("{} - {}", ts, $first); + }; + ($first:expr, $($others:expr),+) => { + let ts = crate::utils::get_epoch(); + let formatted = format!($first, $($others), *); + eprintln!("{} - {}", ts, formatted); + }; } -pub fn cli() -> App<'static, 'static> { - App::new("ban internets scanner fast 🍶") - .version("v0.0.1") - .author("pierre dubouilh ") - // .arg(Arg::with_name("prune") - // .short("prune") - // .help("prune current logfiles to prefill banlist") - // .default_value("false") - // .takes_value(true)) - .arg( - Arg::with_name("jailtime") - .short("j") - .help("jail time (seconds)") - .default_value("3600") - .takes_value(true), - ) - .arg( - Arg::with_name("allowance") - .short("a") - .help("how many offences allowed (max 255") - .default_value("5") - .takes_value(true), - ) - .arg( - Arg::with_name("sshd_logpath") - .short("sshd_logpath") - .help("path of sshd logfile (disable with empty path)") - .default_value("/var/log/auth.log") - .takes_value(true), - ) - .arg( - Arg::with_name("clf_logpath") - .short("clf_logpath") - .help("path of Common-Log-Format (Apache, etc..) logfile") - .default_value("") - .takes_value(true), - ) - // .arg(Arg::with_name("clf_bad_http_codes") - // .short("cb") - // .help("bad CLF http codes") - // .default_value("{401, 429}") - // .takes_value(true)) +pub fn resolve_path(a: &str) -> Result { + let p = Path::new(a); + if !p.exists() { + return Err(anyhow!("path {:?} does not exist", p)); + } + let p = std::fs::canonicalize(p)?; + Ok(p) +} + +pub fn parse_regex(a: &str) -> Result { + let r: Regex = Regex::new(a).context("invalid regexp for generic parser")?; + Ok(r) +} + +pub fn parse_statuses(a: &str) -> Result> { + let mut statuses = vec![]; + for s in a.split(',') { + if s.contains("xx") { + let range = s.replace("xx", ""); + let range = range.parse::().context("invalid range")?; + let range = range * 100; + for i in 0..100 { + let status = range + i; + statuses.push(status); + } + } else if s.contains("x") { + let range = s.replace("x", ""); + let range = range.parse::().context("invalid range")?; + let range = range * 10; + for i in 0..10 { + let status = range + i; + statuses.push(status); + } + } else { + let status = s.parse::().context("invalid status")?; + statuses.push(status); + } + } + Ok(statuses) +} + +pub(crate) use log; + +#[derive(Parser, Debug)] +#[command( + name = "Blockfast", + author = "pierre dubouilh ", + arg_required_else_help = true, + version, + long_about = None, + about = " +Blockfast - block internets scanners fast 🍶 +Author: pierre dubouilh + +Blockfast reads logs from various sources and blocks the offending IPs using iptables and ipset. +It supports logs from sshd, Common-Log-Format (Apache, etc..), JSON (Caddy) and a generic logs parser. + +Example: + # block invalid sshd attempts & invalid http statuses from caddy + ./blockfast -s=/var/log/auth.log -j=/caddy/logs + + # generic log parser example with a log text to flag, and a regex to parse the offending IP. + ./blockfast --generic-logpath=/tmp/generictest --generic-positive='Failed password' --generic-ip='from ([0-9a-fA-F:.]+) port'", + verbatim_doc_comment, +)] + +pub struct Args { + /// jail time (seconds) + #[clap(long, default_value = "21600")] + pub jailtime: u32, + + /// how many offences allowed (max 255) + #[clap(long, default_value = "5")] + pub allowance: u8, + + /// log all offences + #[clap(short, long)] + pub verbose: bool, + + /// path of sshd logfile + #[clap(short, long, value_parser = resolve_path)] + pub sshd_logpath: Option, + + /// path of Common-Log-Format logfile (Apache, etc..) + #[clap(short, long, value_parser = resolve_path)] + pub clf_logpath: Option, + + /// path of JSON logfile (works with Caddy) + #[clap(short, long, value_parser = resolve_path)] + pub json_logpath: Option, + + /// generic parser log file path + #[clap(long, value_parser = resolve_path)] + pub generic_logpath: Option, + + /// generic parser ip regex + #[clap(long , value_parser = parse_regex)] + pub generic_ip: Option, + + /// generic parser positive - if a logline contains this, it is considered bad, the rest is good + #[clap(long)] + pub generic_positive: Option, + + /// generic parser negative - if a logline contains this, it is considered good, the rest is bad + #[clap(long)] + pub generic_negative: Option, + + /// valid http statuses (for CLF and JSON logs). Coma separated list, accepts ranges with XX. + #[clap(long, default_value = "10x,20x,30x,404,408")] + pub valid_http_statuses: String, }