20 Commits

Author SHA1 Message Date
fauno be75ab83f2 v0.6.1 2025-11-01 02:25:09 -03:00
fauno ccd54a93f0 ci: build ip2asn_server 2025-11-01 02:24:39 -03:00
fauno 81a7426e51 fix: update average intensity data 2025-11-01 02:23:01 -03:00
fauno ee40371272 feat: example ip2asn nginx config 2025-11-01 01:18:37 -03:00
fauno 838f9e970a fix: log not implemented command 2025-11-01 01:16:05 -03:00
fauno b1b0757e0d fix: don't cache status 2025-11-01 01:15:52 -03:00
fauno 4a062a4dae feat: asns can be blocked 2025-11-01 01:08:45 -03:00
fauno 857c39fdbb fix: rename 2025-11-01 00:33:15 -03:00
fauno 0326c60f90 feat: configurable 2025-11-01 00:32:50 -03:00
fauno f8a00dec1b refactor: reusable redis server 2025-11-01 00:24:55 -03:00
fauno ef975d1b98 feat: small redis server for nginx keyval 2025-10-31 23:29:29 -03:00
fauno d51d43d8a7 feat: http3 module 2025-10-30 18:48:31 -03:00
fauno b69e68b04b fix: tests 2025-07-24 12:34:57 -03:00
fauno cfdf9083ef v0.6.0 2025-07-24 12:29:15 -03:00
fauno 8c6c0e6aa2 fix: update intensity data
https://github.com/thegreenwebfoundation/co2.js/commit/b0a65fe073c8a4d7fc2adbafb1844e4cae3ee6c2
2025-07-24 11:41:40 -03:00
fauno 8440ba4cf8 feat: asn database 2025-07-24 11:35:05 -03:00
fauno 28f91eeecb fix: remove socket before start 2025-07-05 19:13:30 -03:00
fauno 61652d1e85 refactor: socket removal 2025-07-05 19:13:11 -03:00
fauno 4218f8b5bf fix: don't recalculate reading buffer 2025-07-05 18:42:03 -03:00
fauno 1aae89ed08 fix: match the internal version 2025-07-05 18:41:37 -03:00
14 changed files with 332 additions and 63 deletions
+3 -1
View File
@@ -25,9 +25,11 @@ build:
- "apk add sqlite-static"
- "shards install"
- "crystal build --release --static src/access_log.cr"
- "strip --strip-all access_log"
- "crystal build --release --static src/ip2asn_server.cr"
- "strip --strip-all access_log ip2asn_server"
- "install -Dm 644 LICENSE ${RELEASE_DIRECTORY}/LICENSE"
- "install -Dm 755 access_log ${RELEASE_DIRECTORY}/access_log"
- "install -Dm 755 ip2asn_server ${RELEASE_DIRECTORY}/ip2asn_server"
- "tar -cf ${RELEASE_TARBALL} ${RELEASE_DIRECTORY}"
artifacts:
paths:
+12
View File
@@ -195,6 +195,18 @@ Then run the program with the required flags enabled:
access_log --swd --device-country
```
## ASN database
If you want to keep track of ASN for each visitor, for instance for
grouping possible attacks or IA crawls, create a database based on
<https://iptoasn.com/>:
```bash
./contrib/asn_database.sh
```
And start the server with the `--asn-database=` flag.
## Crawler user agents
Download the [crawler user agents
+11
View File
@@ -0,0 +1,11 @@
#!/bin/sh
set -e
db="${1:-$PWD/asn.sqlite3}"
sqlite3 "$db" "CREATE TABLE IF NOT EXISTS asn (range_start INTEGER, range_end INTEGER, id INTEGER, country STRING, description TEXT);"
sqlite3 "$db" "CREATE INDEX IF NOT EXISTS asn_id_idx ON asn (id);"
sqlite3 "$db" "CREATE TABLE IF NOT EXISTS status (id INTEGER PRIMARY KEY, blocked BOOLEAN DEFAULT FALSE);"
sqlite3 "$db" "DELETE from asn;"
wget https://iptoasn.com/data/ip2asn-v4-u32.tsv.gz -O - | gunzip | sqlite3 -tabs "$db" ".import '|cat -' asn"
echo "ASN database created/updated at $db"
+4 -1
View File
@@ -53,7 +53,10 @@ CREATE TABLE IF NOT EXISTS "access_logs" (
"network_co2" float DEFAULT NULL,
"consumer_device_co2" float DEFAULT NULL,
"production_co2" float DEFAULT NULL,
"total_co2" float DEFAULT NULL
"total_co2" float DEFAULT NULL,
"node" varchar DEFAULT NULL,
"asn" integer DEFAULT NULL,
"http3" varchar(2) DEFAULT NULL
);
CREATE INDEX IF NOT EXISTS "index_access_logs_on_host" ON "access_logs" ("host");
+19
View File
@@ -0,0 +1,19 @@
keyval_zone_redis zone=ip2asn hostname=::1;
keyval "$remote_addr:id" $asn zone=ip2asn;
keyval "$remote_addr:blocked" $asn_blocked zone=ip2asn;
limit_conn_zone $asn zone=asn_conn:10m;
limit_req_zone $asn zone=asn_req:10m rate=10r/s;
server {
server_name _;
listen 80 default_server;
if ($asn_blocked) {
return 444;
}
limit_conn asn_conn 1;
limit_req zone=asn_req nodelay;
}
+1 -1
View File
@@ -1,5 +1,5 @@
name: "access_log"
version: "0.5.12"
version: "0.6.1"
authors:
- "f <f@sutty.nl>"
targets:
+5 -5
View File
@@ -111,31 +111,31 @@ describe SWD do
describe "#consumer_device_co2" do
it "should extract the consumer device co2 emissions" do
swd.consumer_device_co2.should(eq 0.6343432152938272)
swd.consumer_device_co2.should(eq 0.6854924454444445)
end
end
describe "#production_co2" do
it "should extract the production co2 emissions" do
swd.production_co2.should(eq 0.2317792517419753)
swd.production_co2.should(eq 0.2504683935277778)
end
end
describe "#network_co2" do
it "should extract the network co2 emissions" do
swd.network_co2.should(eq 0.1707847118098766)
swd.network_co2.should(eq 0.1845556583888889)
end
end
describe "#datacenter_co2" do
it "should extract the datacenter co2 emissions" do
swd.datacenter_co2.should(eq 0.1829836197962963)
swd.datacenter_co2.should(eq 0.19773820541666665)
end
end
describe "#total_co2" do
it "should extract the total co2 emissions" do
swd.total_co2.should(eq 1.2198907986419754)
swd.total_co2.should(eq 1.3182547027777778)
end
end
end
+37 -11
View File
@@ -10,8 +10,9 @@ require "system"
require "./models/access_log"
require "./models/crawler"
require "./swd"
require "./asn"
VERSION = "0.5.8"
VERSION = "0.6.1"
Log.setup_from_env
@@ -19,13 +20,15 @@ Log.setup_from_env
socket = "/tmp/access_log.socket"
# The default database URI
database = "sqlite3://./development.sqlite3"
# ASN database
asn_database = ""
# Detect web crawlers
crawler = false
# Parse the crawlers repository
crawlers = [] of Crawler
# Fields in database
# TODO: Obtain them from AccessLog
fields = %w[id remote_user host msec server_protocol request_method request_completion uri request_uri query_string status sent_http_content_type sent_http_content_encoding sent_http_etag sent_http_last_modified http_accept http_accept_encoding http_accept_language http_pragma http_cache_control http_if_none_match http_dnt http_user_agent http_origin http_referer request_time bytes_sent body_bytes_sent request_length http_connection pipe connection_requests geoip2_data_country_name geoip2_data_city_name ssl_server_name ssl_protocol ssl_early_data ssl_session_reused ssl_curves ssl_ciphers ssl_cipher sent_http_x_xss_protection sent_http_x_frame_options sent_http_x_content_type_options sent_http_strict_transport_security nginx_version pid crawler datacenter_co2 network_co2 consumer_device_co2 production_co2 total_co2 node]
fields = %w[id remote_user host msec server_protocol request_method request_completion uri request_uri query_string status sent_http_content_type sent_http_content_encoding sent_http_etag sent_http_last_modified http_accept http_accept_encoding http_accept_language http_pragma http_cache_control http_if_none_match http_dnt http_user_agent http_origin http_referer request_time bytes_sent body_bytes_sent request_length http_connection pipe connection_requests geoip2_data_country_name geoip2_data_city_name ssl_server_name ssl_protocol ssl_early_data ssl_session_reused ssl_curves ssl_ciphers ssl_cipher sent_http_x_xss_protection sent_http_x_frame_options sent_http_x_content_type_options sent_http_strict_transport_security nginx_version pid crawler datacenter_co2 network_co2 consumer_device_co2 production_co2 total_co2 node asn http3]
# Params for the query
params = [] of String
# SWD
@@ -56,6 +59,10 @@ OptionParser.parse do |p|
database = d
end
p.on "-I DATABASE", "--asn-database=DATABASE", "ASN Database URI" do |d|
asn_database = d
end
p.on "-c crawler-user-agents.json", "--crawlers crawler-user-agents.json", "Crawlers repository" do |c|
crawler = true
crawlers = Array(Crawler).from_json File.read(c)
@@ -110,26 +117,41 @@ if crawler
crawler_re = Regex.union(crawlers.map { |c| c.pattern })
end
def remove_socket!(socket)
FileUtils.rm(socket) if File.exists? socket
end
remove_socket!(socket)
asn = ASN.new(asn_database) unless asn_database.empty?
server = Socket.unix(Socket::Type::DGRAM)
server.bind Socket::UNIXAddress.new(socket)
def close_server!(server, asn)
server.try(&.close)
asn.try(&.close)
end
Signal::INT.trap do
server.close
FileUtils.rm(socket) if File.exists? socket
remove_socket!(socket)
close_server!(server, asn)
exit
end
Signal::KILL.trap do
server.close
FileUtils.rm(socket) if File.exists? socket
remove_socket!(socket)
close_server!(server, asn)
exit
end
MAX_SIZE = 1024 * 64 # 64K
# Open the database and wait for JSONL input.
db = DB.open database do |db|
DB.open database do |db|
while true
begin
msg, _ = server.receive(1024 * 64) # 64K
msg, _ = server.receive(MAX_SIZE)
# TODO: is this the best method?
_, json = msg.split("{", 2)
json = "{#{json}"
@@ -137,6 +159,8 @@ db = DB.open database do |db|
access_log = AccessLog.from_json(json || "{}")
d = device_country ? access_log.geoip2_data_country_iso_code : nil
s = SWD.new(access_log.bytes_sent, renewable, datacenter, d, intensity) if swd
i = access_log.remote_addr
a = asn.try(&.query(i)) if i
# Execute query, detect crawler if enabled.
# TODO: Does Crystal support splats? It does but we need to cast
@@ -195,14 +219,16 @@ db = DB.open database do |db|
(swd ? s.try(&.consumer_device_co2) : nil),
(swd ? s.try(&.production_co2) : nil),
(swd ? s.try(&.total_co2) : nil),
(node ? System.hostname : nil)
(node ? System.hostname : nil),
a.try(&.id),
access_log.http3
# Ignore parsing errors
rescue e : JSON::ParseException
Log.warn &.emit("Parse exception", error: e.message)
rescue IO::Error
server.close
FileUtils.rm(socket) if File.exists? socket
remove_socket!(socket)
close_server!(server, asn)
exit
end
end
+45
View File
@@ -0,0 +1,45 @@
require "db"
require "sqlite3"
class AsnResult
include DB::Serializable
property id : Int64?
property country : String?
property description : String?
property blocked : Bool?
end
class ASN
QUERY = "select id, country, description from asn where ? between range_start and range_end limit 1;"
STATUS = "select blocked from status where id = ? limit 1;"
property db : DB::Database
def initialize(database : String)
@db = DB.open(database)
@cache = Hash(UInt32, AsnResult).new
end
# Binary representation of an IPv4 address
def to_binary(address : String) : UInt32
(address.split(".").map(&.to_u32).reduce(0.to_u32) { |t, v| (t << 8) + v })
end
# Lookups an address and returns the ASN for it
def query(address : String)
query(to_binary(address))
end
def query(binary_address : UInt32) : AsnResult?
(@cache[binary_address] ||= @db.query_one(QUERY, binary_address.to_i64, &.read(AsnResult))).tap do |result|
result.blocked = @db.query_one(STATUS, result.id, &.read(Bool))
end
rescue DB::NoResultsError
nil
end
def close
@db.close
end
end
+90
View File
@@ -0,0 +1,90 @@
# This is a very minimal Redis server that works with Nginx keyval
# module. When set like this:
#
# keyval_zone_redis zone=redis hostname=::1;
# keyval "$remote_addr:id" $asn_id zone=redis;
#
# We can query the ASN id from a database and use it on Nginx config to
# rate limit entire subnets.
require "log"
require "option_parser"
require "./asn"
require "./redis_server"
Log.setup_from_env
VERSION = "0.2.0"
ASN_ID = "id"
ASN_DESCRIPTION = "description"
ASN_COUNTRY = "country"
ASN_BLOCKED = "blocked"
asn_database = "sqlite3://./asn.sqlite3"
interface = "localhost"
port = 6379
OptionParser.parse do |p|
p.banner = "IP to ASN Redis server"
p.on "-v", "--version", "Show version" do
puts VERSION
exit
end
p.on "-h", "--help", "Show help" do
puts p
exit
end
p.on "-d #{asn_database}", "--asn-database=#{asn_database}", "ASN Database URI" do |d|
asn_database = d
end
p.on "-i #{interface}", "--interface=#{interface}", "Listening interface" do |i|
interface = i
end
p.on "-p #{port}", "--port=#{port}", "Listening port" do |p|
port = p.to_i
end
end
asn = ASN.new(asn_database)
# The client can be a long lived connection sending commands. We only
# answer to GET commands.
RedisServer.new(interface, port) do |client, _, key|
begin
_, ip, field = key.split(":", 3)
rescue
Log.warn &.emit("Error parsing key", key: key)
next
end
# This is cached in memory
result = asn.query(ip)
next if result.nil?
# XXX: Are we going to use the other fields?
response =
case field
when ASN_ID then result.try(&.id).try(&.to_s)
when ASN_COUNTRY then result.try(&.country)
when ASN_DESCRIPTION then result.try(&.description)
when ASN_BLOCKED then
if result.try(&.blocked)
"1"
else
"0"
end
else nil
end
next if response.nil?
# Reply
RedisServer.bulk_string(client, response)
end
asn.close
+2
View File
@@ -58,4 +58,6 @@ class AccessLog
property sent_http_strict_transport_security : String
property nginx_version : String
property pid : String
property remote_addr : String?
property http3 : String?
end
+59
View File
@@ -0,0 +1,59 @@
require "log"
require "socket"
class RedisServer
BULK_STRING = "$"
CRLF = "\r\n"
NOT_IMPLEMENTED = "-Not implemented#{CRLF}"
QUIT_COMMAND = "quit"
GET_COMMAND = "get"
property server : TCPServer
def initialize(interface : String = "localhost", port : Int = 6379, &block : TCPSocket, String, String -> _)
@server = TCPServer.new(interface, port)
while (client = server.accept?)
spawn handle_client(client, block)
end
ensure
server.close
end
def handle_client(client : TCPSocket, block : Proc)
next_is_key = false
last_command = ""
while (line = client.gets)
# We're not a compliant RESP
next if line.starts_with?("*")
next if line.starts_with?("$")
# Execute the query when we get the key
if next_is_key
next_is_key = false
# Do something with the key
block.call(client, last_command, line)
# First we get the Redis command and we only support a small subset.
else
case (last_command = line.downcase)
when QUIT_COMMAND then client.close
when GET_COMMAND then next_is_key = true
else
client.print NOT_IMPLEMENTED
raise last_command
end
end
end
rescue ex
Log.warn &.emit("Error", exception: ex.class.name, error: ex.message)
ensure
client.close
end
def self.bulk_string(client : TCPSocket, string : String)
client.print(BULK_STRING, string.size, CRLF, string, CRLF)
end
end
+1 -1
View File
@@ -27,7 +27,7 @@ class SWD
NETWORK_ENERGY = 0.14
DATACENTER_ENERGY = 0.15
PRODUCTION_ENERGY = 0.19
GLOBAL_GRID_INTENSITY = 437.66
GLOBAL_GRID_INTENSITY = 472.95
RENEWABLES_GRID_INTENSITY = 50.0
@transfered_bytes_to_gb : Float32? | Float64? = nil
+43 -43
View File
@@ -2,19 +2,19 @@ class SWD
module IntensityData
# @see {co2.js/data/output/average-intensities.json}
AVERAGE_INTENSITY_BY_ISO_CODE = {
"AE": 467.51,
"AF": 123.71,
"AE": 492.7,
"AG": 611.11,
"AL": 24.42,
"AM": 244.34,
"AM": 243.52,
"AO": 167.22,
"AR": 358.95,
"AR": 344.83,
"AS": 647.06,
"AT": 102.62,
"AU": 551.59,
"AU": 553.76,
"AW": 550.0,
"AZ": 633.07,
"BA": 637.76,
"AZ": 632.89,
"BA": 638.05,
"BB": 600.0,
"BD": 694.63,
"BE": 117.58,
@@ -25,37 +25,37 @@ class SWD
"BJ": 590.0,
"BN": 892.67,
"BO": 468.02,
"BR": 103.21,
"BR": 106.06,
"BS": 653.66,
"BT": 24.19,
"BW": 849.42,
"BY": 313.62,
"BY": 323.63,
"BZ": 155.56,
"CA": 174.81,
"CA": 184.99,
"CD": 27.04,
"CF": 0.0,
"CG": 713.73,
"CH": 36.6,
"CH": 36.72,
"CI": 393.53,
"CK": 250.0,
"CL": 265.52,
"CM": 285.71,
"CN": 559.55,
"CN": 557.5,
"CO": 285.8,
"CR": 63.01,
"CU": 638.98,
"CV": 480.0,
"CY": 512.24,
"CZ": 413.86,
"DE": 344.14,
"DE": 342.06,
"DJ": 450.0,
"DK": 143.3,
"DM": 600.0,
"DO": 566.05,
"DO": 565.97,
"DZ": 633.65,
"EC": 209.7,
"EE": 341.02,
"EG": 571.92,
"EG": 574.5,
"ER": 590.91,
"ES": 146.15,
"ET": 23.55,
@@ -65,7 +65,7 @@ class SWD
"FO": 354.17,
"FR": 44.18,
"GA": 429.47,
"GB": 210.89,
"GB": 215.79,
"GD": 666.67,
"GE": 143.06,
"GF": 204.08,
@@ -86,27 +86,27 @@ class SWD
"HT": 534.65,
"HU": 182.82,
"ID": 682.43,
"IE": 279.7,
"IE": 279.79,
"IL": 567.26,
"IN": 708.32,
"IN": 708.96,
"IQ": 689.4,
"IR": 641.94,
"IR": 648.68,
"IS": 28.33,
"IT": 287.53,
"IT": 287.75,
"JM": 561.25,
"JO": 539.21,
"JP": 482.32,
"KE": 88.79,
"KG": 162.71,
"JP": 483.73,
"KE": 84.83,
"KG": 152.65,
"KH": 497.46,
"KI": 500.0,
"KM": 642.86,
"KN": 636.36,
"KP": 344.26,
"KR": 414.27,
"KR": 415.65,
"KW": 637.24,
"KY": 642.86,
"KZ": 801.95,
"KZ": 801.79,
"LA": 232.12,
"LB": 369.47,
"LC": 650.0,
@@ -118,12 +118,12 @@ class SWD
"LV": 136.22,
"LY": 830.53,
"MA": 577.65,
"MD": 631.68,
"MD": 629.56,
"ME": 413.51,
"MG": 477.27,
"MK": 568.97,
"ML": 394.5,
"MM": 578.82,
"MM": 569.69,
"MN": 784.01,
"MO": 448.98,
"MQ": 516.78,
@@ -133,20 +133,20 @@ class SWD
"MU": 633.03,
"MV": 611.77,
"MW": 54.65,
"MX": 484.83,
"MY": 609.85,
"MX": 483.14,
"MY": 604.43,
"MZ": 127.81,
"NA": 47.62,
"NC": 585.76,
"NE": 687.5,
"NG": 507.85,
"NI": 288.33,
"NL": 253.31,
"NL": 252.7,
"NO": 30.75,
"NP": 23.36,
"NR": 750.0,
"NZ": 120.11,
"OM": 545.25,
"OM": 545.33,
"PA": 258.74,
"PE": 263.27,
"PF": 436.62,
@@ -157,21 +157,21 @@ class SWD
"PM": 600.0,
"PR": 664.53,
"PS": 460.78,
"PT": 112.29,
"PT": 111.8,
"PY": 24.86,
"QA": 602.83,
"RE": 525.22,
"RO": 245.55,
"RS": 673.16,
"RU": 449.2,
"RS": 670.8,
"RU": 446.17,
"RW": 301.89,
"SA": 696.31,
"SA": 691.95,
"SB": 636.36,
"SC": 571.43,
"SD": 214.33,
"SE": 35.82,
"SE": 35.89,
"SG": 498.74,
"SI": 227.65,
"SI": 227.11,
"SK": 96.49,
"SL": 47.62,
"SN": 535.4,
@@ -179,22 +179,22 @@ class SWD
"SR": 383.18,
"SS": 610.17,
"ST": 555.56,
"SV": 103.13,
"SV": 99.29,
"SY": 682.27,
"SZ": 142.86,
"TC": 653.85,
"TD": 615.39,
"TG": 478.26,
"TH": 554.5,
"TJ": 112.79,
"TH": 555.43,
"TJ": 98.7,
"TM": 1306.3,
"TN": 560.25,
"TO": 571.43,
"TR": 469.7,
"TT": 682.11,
"TW": 635.65,
"TW": 635.15,
"TZ": 371.59,
"UA": 256.21,
"UA": 250.47,
"UG": 57.39,
"US": 383.55,
"UY": 96.7,
@@ -203,12 +203,12 @@ class SWD
"VE": 180.25,
"VG": 647.06,
"VI": 641.79,
"VN": 471.16,
"VN": 486.13,
"VU": 500.0,
"WS": 400.0,
"XK": 958.72,
"YE": 586.32,
"ZA": 708.88,
"ZA": 713.9,
"ZM": 111.0,
"ZW": 298.44
}