feat: per-host stats, flush toggle, and SNI/Host log redaction - #3
Merged
Merged
Conversation
- metrics: add per-hostname matched/faulted breakdown plus LatencyApplied and HTTPResponsesInjected counters; expose them in Snapshot. - main: --metrics-stdout-interval prints JSON metrics snapshots to stdout (the cross-namespace channel the extension scrapes; the HTTP endpoint cannot be reached inside a container's netns) and a final snapshot on exit. - interception: --no-flush / Config.SkipFlush omits the ESTABLISHED-reset flush chain, so an attack can choose to affect only new connections. - server: stop logging the identity (TLS SNI / HTTP Host) at info level; it is now debug-only, while still feeding the per-host statistics. Wire the new counters into the fault paths.
- metrics: add ConnectionsFaulted, incremented once per faulted connection, so callers report an accurate "faulted" total instead of summing per-fault-type counters (which double-counts a latency+injected-response connection). - server: record faulted at the point a fault actually applies (not speculatively from the Action), so per-host "faulted" no longer over-reports an HTTP rule on a non-cleartext connection that is forwarded untouched. - interception: DeleteCommands omits the filter-chain deletes when SkipFlush, so a --no-flush attack does not emit failing iptables deletes on teardown.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Three additions driven by the extension-side dependency-fault feedback:
Per-hostname statistics on stdout
internal/metrics: per-hostnamematched/faultedbreakdown, plusLatencyAppliedandHTTPResponsesInjectedcounters, exposed inSnapshot.--metrics-stdout-intervalprints JSON metrics snapshots to stdout at a fixed cadence (and once on exit). This is the channel the orchestrating extension scrapes: the proxy runs inside the target's netns (a container's, for container attacks), where its HTTP metrics endpoint is unreachable, but its stdout is always captured. The extension renders these as a Markdown statistics widget.Flush toggle
--no-flush/Config.SkipFlushomits theSB_TP_FLUSHchain that resets already-ESTABLISHED connections, so an attack can choose to affect only new connections.Log redaction
identityvalue (TLS SNI / HTTP Host) is no longer attached to per-connection logs at info level — it is now debug-only, while still feeding the (operator-facing) per-host statistics. No header/body/URL content was ever logged.Tests
go test ./...→ 85 pass. New coverage for the per-host counters and theSkipFlushscript omission.