Skip to content

feat: per-host stats, flush toggle, and SNI/Host log redaction - #3

Merged
achoimet merged 2 commits into
mainfrom
feat/stats-flush-toggle-log-redaction
Sep 1, 2026
Merged

achoimet merged 2 commits into
mainfrom
feat/stats-flush-toggle-log-redaction

Conversation

@achoimet

Copy link
Copy Markdown
Member

What

Three additions driven by the extension-side dependency-fault feedback:

Per-hostname statistics on stdout

  • internal/metrics: per-hostname matched/faulted breakdown, plus LatencyApplied and HTTPResponsesInjected counters, exposed in Snapshot.
  • --metrics-stdout-interval prints JSON metrics snapshots to stdout at a fixed cadence (and once on exit). This is the channel the orchestrating extension scrapes: the proxy runs inside the target's netns (a container's, for container attacks), where its HTTP metrics endpoint is unreachable, but its stdout is always captured. The extension renders these as a Markdown statistics widget.

Flush toggle

  • --no-flush / Config.SkipFlush omits the SB_TP_FLUSH chain that resets already-ESTABLISHED connections, so an attack can choose to affect only new connections.

Log redaction

  • The identity value (TLS SNI / HTTP Host) is no longer attached to per-connection logs at info level — it is now debug-only, while still feeding the (operator-facing) per-host statistics. No header/body/URL content was ever logged.

Tests

go test ./... → 85 pass. New coverage for the per-host counters and the SkipFlush script omission.

- metrics: add per-hostname matched/faulted breakdown plus LatencyApplied and
  HTTPResponsesInjected counters; expose them in Snapshot.
- main: --metrics-stdout-interval prints JSON metrics snapshots to stdout (the
  cross-namespace channel the extension scrapes; the HTTP endpoint cannot be
  reached inside a container's netns) and a final snapshot on exit.
- interception: --no-flush / Config.SkipFlush omits the ESTABLISHED-reset flush
  chain, so an attack can choose to affect only new connections.
- server: stop logging the identity (TLS SNI / HTTP Host) at info level; it is
  now debug-only, while still feeding the per-host statistics. Wire the new
  counters into the fault paths.
- metrics: add ConnectionsFaulted, incremented once per faulted connection, so
  callers report an accurate "faulted" total instead of summing per-fault-type
  counters (which double-counts a latency+injected-response connection).
- server: record faulted at the point a fault actually applies (not
  speculatively from the Action), so per-host "faulted" no longer over-reports
  an HTTP rule on a non-cleartext connection that is forwarded untouched.
- interception: DeleteCommands omits the filter-chain deletes when SkipFlush, so
  a --no-flush attack does not emit failing iptables deletes on teardown.
@achoimet
achoimet merged commit bf9ef3d into main Sep 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant