mirror of
https://github.com/ScuroNeko/mtg.git
synced 2026-09-01 05:14:02 +03:00
Move cert noise calibration into doppelganger scout
Instead of a separate cert_probe.go that duplicates the scout's TLS connection logic, measure the cert chain size directly from the same HTTPS connections the scout already makes. Changes: - Extend ScoutConnResult with payloadLen field - Add Write interception to ScoutConn for handshake boundary detection - Scout.learn() now computes cert size (sum of ApplicationData between CCS and first client Write) alongside inter-record durations - Ganger aggregates cert sizes across raids and exposes NoiseParams() via atomic pointer for lock-free reads from proxy goroutines - Proxy reads NoiseParams from Ganger on each handshake instead of probing at startup - Remove cert_probe.go, disk cache, and related config options (noise-cache-path, noise-cache-ttl, noise-probe-count) Falls back to legacy 2500-4700 range until the first scout raid completes (typically within 1-2 seconds of startup).
This commit is contained in:
@@ -267,10 +267,6 @@ func runProxy(conf *config.Config, version string) error { //nolint: funlen
|
||||
DoppelGangerPerRaid: conf.Defense.Doppelganger.Repeats.Get(mtglib.DoppelGangerPerRaid),
|
||||
DoppelGangerEach: conf.Defense.Doppelganger.UpdateEach.Get(mtglib.DoppelGangerEach),
|
||||
DoppelGangerDRS: conf.Defense.Doppelganger.DRS.Get(false),
|
||||
|
||||
NoiseProbeCount: conf.Defense.Doppelganger.NoiseProbeCount.Get(0),
|
||||
NoiseCacheTTL: conf.Defense.Doppelganger.NoiseCacheTTL.Get(0),
|
||||
NoiseCachePath: conf.Defense.Doppelganger.NoiseCachePath,
|
||||
}
|
||||
|
||||
proxy, err := mtglib.NewProxy(opts)
|
||||
|
||||
Reference in New Issue
Block a user