feat: multiple verdicts (#83)

* feat: multiple verdicts

* chore: bump version
This commit is contained in:
LowderPlay
2026-08-18 19:57:56 +05:00
committed by GitHub
parent a233cff58c
commit 4d05f18c4c
6 changed files with 130 additions and 97 deletions
Generated
+1 -1
View File
@@ -4706,7 +4706,7 @@ dependencies = [
[[package]] [[package]]
name = "website" name = "website"
version = "1.2.0" version = "1.2.1"
dependencies = [ dependencies = [
"dotenvy", "dotenvy",
"env_logger", "env_logger",
+3 -2
View File
@@ -32,13 +32,14 @@ export type ProbeResult = {
region?: string | null; region?: string | null;
provider?: string | null; provider?: string | null;
asn?: string | null; asn?: string | null;
verdict: verdicts: (
| "uncertain" | "uncertain"
| "dns_spoofing" | "dns_spoofing"
| "sni_block" | "sni_block"
| "tspu_block" | "tspu_block"
| "whitelist" | "whitelist"
| "ok"; | "ok"
)[];
host_results: ProbeHostResult[] | null; host_results: ProbeHostResult[] | null;
target_hop: number | null; target_hop: number | null;
dns: { dns: {
@@ -110,6 +110,19 @@ const verdictStyles = {
border: "border-neutral-400/20", border: "border-neutral-400/20",
}, },
}; };
type VerdictStyle = keyof typeof verdictStyles;
function probeVerdicts(
probe: ProbeResult,
isStaticBlocked: boolean,
): VerdictStyle[] {
return probe.verdicts.map((verdict) =>
isStaticBlocked && probe.host_results?.length !== 0 && verdict === "ok"
? "cdn_block"
: verdict,
);
}
</script> </script>
<div class="mt-8 space-y-4"> <div class="mt-8 space-y-4">
@@ -169,7 +182,7 @@ const verdictStyles = {
</thead> </thead>
<tbody> <tbody>
{#each probes as probe (probe.probe_id)} {#each probes as probe (probe.probe_id)}
{@const style = verdictStyles[(isStaticBlocked && probe.host_results?.length !== 0 && probe.verdict === "ok") ? "cdn_block" : probe.verdict]} {@const verdicts = probeVerdicts(probe, isStaticBlocked)}
{@const isExpanded = !!expandedRows[probe.probe_id]} {@const isExpanded = !!expandedRows[probe.probe_id]}
<tr <tr
class="border-b border-neutral-800/50 hover:bg-neutral-800/20 transition-colors cursor-pointer select-none" class="border-b border-neutral-800/50 hover:bg-neutral-800/20 transition-colors cursor-pointer select-none"
@@ -187,23 +200,28 @@ const verdictStyles = {
<div class="text-xs text-neutral-500">{probe.asn || ""}</div> <div class="text-xs text-neutral-500">{probe.asn || ""}</div>
</td> </td>
<td class="p-3"> <td class="p-3">
{#if probe.verdict === "whitelist"} <div class="flex flex-wrap gap-1.5">
<a {#each verdicts as verdict}
href="/kb/whitelist" {@const style = verdictStyles[verdict]}
onclick={(event) => event.stopPropagation()} {#if verdict === "whitelist"}
class={`inline-flex items-center gap-1.5 px-2 py-1 rounded border ${style.bg} ${style.border} ${style.class} text-xs font-bold transition-colors hover:bg-amber-500/20 hover:border-amber-500/50 hover:text-amber-400`} <a
> href="/kb/whitelist"
<style.icon size={14} /> onclick={(event) => event.stopPropagation()}
{style.text} class={`inline-flex items-center gap-1.5 px-2 py-1 rounded border ${style.bg} ${style.border} ${style.class} text-xs font-bold transition-colors hover:bg-amber-500/20 hover:border-amber-500/50 hover:text-amber-400`}
</a> >
{:else} <style.icon size={14} />
<div {style.text}
class={`inline-flex items-center gap-1.5 px-2 py-1 rounded border ${style.bg} ${style.border} ${style.class} text-xs font-bold`} </a>
> {:else}
<style.icon size={14} /> <div
{style.text} class={`inline-flex items-center gap-1.5 px-2 py-1 rounded border ${style.bg} ${style.border} ${style.class} text-xs font-bold`}
</div> >
{/if} <style.icon size={14} />
{style.text}
</div>
{/if}
{/each}
</div>
</td> </td>
<td class="p-3 text-right"> <td class="p-3 text-right">
{#if isExpanded} {#if isExpanded}
@@ -216,7 +234,7 @@ const verdictStyles = {
{#if isExpanded} {#if isExpanded}
<tr class="bg-neutral-900/30"> <tr class="bg-neutral-900/30">
<td colspan="4" class="p-4 border-b border-neutral-800/50"> <td colspan="4" class="p-4 border-b border-neutral-800/50">
<!-- {#if probe.verdict === "tspu_block"} <!-- {#if probe.verdicts.includes("tspu_block")}
<div <div
class="mb-3 flex items-center gap-2 rounded-md border border-red-500/50 bg-red-500/15 px-3 py-2 text-red-200" class="mb-3 flex items-center gap-2 rounded-md border border-red-500/50 bg-red-500/15 px-3 py-2 text-red-200"
> >
+1 -1
View File
@@ -1,6 +1,6 @@
[package] [package]
name = "website" name = "website"
version = "1.2.0" version = "1.2.1"
edition = "2024" edition = "2024"
[dependencies] [dependencies]
@@ -0,0 +1,9 @@
ALTER TABLE probe_reports
RENAME COLUMN verdict TO verdicts;
ALTER TABLE probe_reports
ALTER COLUMN verdicts TYPE VARCHAR(32)[]
USING ARRAY[verdicts];
UPDATE probe_reports
SET result = (result - 'verdict') || jsonb_build_object('verdicts', to_jsonb(verdicts));
+79 -74
View File
@@ -153,7 +153,7 @@ pub fn build_probe_response(
reporter_info: Option<ProbeReporterInfo>, reporter_info: Option<ProbeReporterInfo>,
) -> Value { ) -> Value {
let hosts: HashMap<&String, &Host> = config.hosts.iter().map(|h| (&h.id, h)).collect(); let hosts: HashMap<&String, &Host> = config.hosts.iter().map(|h| (&h.id, h)).collect();
let verdict = build_probe_verdict( let verdicts = build_probe_verdicts(
&raw.host_results, &raw.host_results,
config, config,
raw.target_traceroute.as_ref(), raw.target_traceroute.as_ref(),
@@ -194,7 +194,7 @@ pub fn build_probe_response(
"region": region, "region": region,
"provider": provider, "provider": provider,
"asn": asn, "asn": asn,
"verdict": verdict, "verdicts": verdicts,
"host_results": host_results, "host_results": host_results,
"target_hop": target_hop, "target_hop": target_hop,
"dns": raw.dns, "dns": raw.dns,
@@ -212,10 +212,16 @@ async fn insert_probe_report(
.get("probe_id") .get("probe_id")
.and_then(Value::as_str) .and_then(Value::as_str)
.and_then(|probe_id| probe_id.parse::<i32>().ok()); .and_then(|probe_id| probe_id.parse::<i32>().ok());
let verdict = response let verdicts = response
.get("verdict") .get("verdicts")
.and_then(Value::as_str) .and_then(Value::as_array)
.unwrap_or("uncertain"); .map(|verdicts| {
verdicts
.iter()
.filter_map(Value::as_str)
.collect::<Vec<_>>()
})
.unwrap_or_else(|| vec!["uncertain"]);
let (target_hop_count, target_trace_result) = traceroute_columns(target_traceroute); let (target_hop_count, target_trace_result) = traceroute_columns(target_traceroute);
let (control_hop_count, control_trace_result) = traceroute_columns(control_traceroute); let (control_hop_count, control_trace_result) = traceroute_columns(control_traceroute);
@@ -229,7 +235,7 @@ async fn insert_probe_report(
INSERT INTO probe_reports ( INSERT INTO probe_reports (
query_id, query_id,
probe_id, probe_id,
verdict, verdicts,
result, result,
target_hop_count, target_hop_count,
target_trace_result, target_trace_result,
@@ -240,7 +246,7 @@ async fn insert_probe_report(
ON CONFLICT (query_id, probe_id) ON CONFLICT (query_id, probe_id)
DO UPDATE SET DO UPDATE SET
date = NOW(), date = NOW(),
verdict = EXCLUDED.verdict, verdicts = EXCLUDED.verdicts,
result = EXCLUDED.result, result = EXCLUDED.result,
target_hop_count = EXCLUDED.target_hop_count, target_hop_count = EXCLUDED.target_hop_count,
target_trace_result = EXCLUDED.target_trace_result, target_trace_result = EXCLUDED.target_trace_result,
@@ -250,7 +256,7 @@ async fn insert_probe_report(
) )
.bind(query_id) .bind(query_id)
.bind(probe_id) .bind(probe_id)
.bind(verdict) .bind(verdicts)
.bind(response) .bind(response)
.bind(target_hop_count) .bind(target_hop_count)
.bind(target_trace_result) .bind(target_trace_result)
@@ -289,13 +295,14 @@ async fn fetch_probe_reporter_info(
.await .await
} }
fn build_probe_verdict( fn build_probe_verdicts(
results: &[HostProbeResult], results: &[HostProbeResult],
config: &ProbeConfig, config: &ProbeConfig,
target_traceroute: Option<&TcpTracerouteResult>, target_traceroute: Option<&TcpTracerouteResult>,
control_traceroute: Option<&TcpTracerouteResult>, control_traceroute: Option<&TcpTracerouteResult>,
dns: Option<&reports::probe::DnsProbeResult>, dns: Option<&reports::probe::DnsProbeResult>,
) -> &'static str { ) -> Vec<&'static str> {
let mut verdicts = Vec::new();
let dns_spoofing = dns.is_some_and(|result| result.spoofing_detected); let dns_spoofing = dns.is_some_and(|result| result.spoofing_detected);
if let ( if let (
Some(TcpTracerouteResult { Some(TcpTracerouteResult {
@@ -309,11 +316,7 @@ fn build_probe_verdict(
) = (target_traceroute, control_traceroute) ) = (target_traceroute, control_traceroute)
&& target_hop < control_hop && target_hop < control_hop
{ {
return "tspu_block"; verdicts.push("tspu_block");
}
if results.is_empty() {
return if dns_spoofing { "dns_spoofing" } else { "ok" };
} }
let matched = results let matched = results
@@ -327,69 +330,71 @@ fn build_probe_verdict(
}) })
.collect::<Vec<_>>(); .collect::<Vec<_>>();
if matched.is_empty() { let host_verdict = if results.is_empty() {
return if dns_spoofing { "ok"
"dns_spoofing" } else if matched.is_empty() {
} else { "uncertain"
"uncertain" } else if is_strict_majority(
};
}
if is_strict_majority(
matched.len(), matched.len(),
matched matched
.iter() .iter()
.filter(|(_, evidence)| matches!(evidence, ProbeEvidence::ClientHello)) .filter(|(_, evidence)| matches!(evidence, ProbeEvidence::ClientHello))
.count(), .count(),
) { ) {
return "sni_block"; "sni_block"
} } else if is_strict_majority(
if dns_spoofing {
return "dns_spoofing";
}
if is_strict_majority(
matched.len(), matched.len(),
matched matched
.iter() .iter()
.filter(|(_, evidence)| matches!(evidence, ProbeEvidence::Good)) .filter(|(_, evidence)| matches!(evidence, ProbeEvidence::Good))
.count(), .count(),
) { ) {
return "whitelist"; "whitelist"
}
let blacklist = matched
.iter()
.filter(|(host, _)| matches!(host.host_type, HostType::Blacklist))
.collect::<Vec<_>>();
let whitelist = matched
.iter()
.filter(|(host, _)| matches!(host.host_type, HostType::Whitelist))
.collect::<Vec<_>>();
let most_blacklist_timed_out = !blacklist.is_empty()
&& is_strict_majority(
blacklist.len(),
blacklist
.iter()
.filter(|(_, evidence)| matches!(evidence, ProbeEvidence::DataTimeout { .. }))
.count(),
);
let most_whitelist_good = !whitelist.is_empty()
&& is_strict_majority(
whitelist.len(),
whitelist
.iter()
.filter(|(_, evidence)| matches!(evidence, ProbeEvidence::Good))
.count(),
);
if most_blacklist_timed_out && most_whitelist_good {
"ok"
} else { } else {
"uncertain" let blacklist = matched
.iter()
.filter(|(host, _)| matches!(host.host_type, HostType::Blacklist))
.collect::<Vec<_>>();
let whitelist = matched
.iter()
.filter(|(host, _)| matches!(host.host_type, HostType::Whitelist))
.collect::<Vec<_>>();
let most_blacklist_timed_out = !blacklist.is_empty()
&& is_strict_majority(
blacklist.len(),
blacklist
.iter()
.filter(|(_, evidence)| matches!(evidence, ProbeEvidence::DataTimeout { .. }))
.count(),
);
let most_whitelist_good = !whitelist.is_empty()
&& is_strict_majority(
whitelist.len(),
whitelist
.iter()
.filter(|(_, evidence)| matches!(evidence, ProbeEvidence::Good))
.count(),
);
if most_blacklist_timed_out && most_whitelist_good {
"ok"
} else {
"uncertain"
}
};
if !matches!(host_verdict, "ok" | "uncertain") {
verdicts.push(host_verdict);
} }
if dns_spoofing {
verdicts.push("dns_spoofing");
}
if verdicts.is_empty() {
verdicts.push(host_verdict);
}
verdicts
} }
fn publish_error_status(error: PublishError) -> Status { fn publish_error_status(error: PublishError) -> Status {
@@ -436,14 +441,14 @@ mod tests {
let target = icmp_trace(3); let target = icmp_trace(3);
let control = icmp_trace(5); let control = icmp_trace(5);
assert_eq!( assert_eq!(
build_probe_verdict(&[], &empty_config(), Some(&target), Some(&control), None), build_probe_verdicts(&[], &empty_config(), Some(&target), Some(&control), None),
"tspu_block" vec!["tspu_block"]
); );
let target = icmp_trace(5); let target = icmp_trace(5);
assert_eq!( assert_eq!(
build_probe_verdict(&[], &empty_config(), Some(&target), Some(&control), None), build_probe_verdicts(&[], &empty_config(), Some(&target), Some(&control), None),
"ok" vec!["ok"]
); );
} }
@@ -455,13 +460,13 @@ mod tests {
}; };
let control = icmp_trace(5); let control = icmp_trace(5);
assert_eq!( assert_eq!(
build_probe_verdict(&[], &empty_config(), Some(&target), Some(&control), None), build_probe_verdicts(&[], &empty_config(), Some(&target), Some(&control), None),
"ok" vec!["ok"]
); );
} }
#[test] #[test]
fn sni_block_takes_priority_over_dns_spoofing() { fn reports_sni_block_and_dns_spoofing_together() {
let mut config = empty_config(); let mut config = empty_config();
config.hosts.push(Host { config.hosts.push(Host {
id: "test".to_string(), id: "test".to_string(),
@@ -484,8 +489,8 @@ mod tests {
}; };
assert_eq!( assert_eq!(
build_probe_verdict(&results, &config, None, None, Some(&dns)), build_probe_verdicts(&results, &config, None, None, Some(&dns)),
"sni_block" vec!["sni_block", "dns_spoofing"]
); );
} }