ruleset: try to fix reloader

This commit is contained in:
2026-02-12 13:27:53 +05:30
parent a8f8b43f3e
commit beaaddad2b
3 changed files with 194 additions and 12 deletions

View File

@@ -60,9 +60,7 @@ func (f *tcpStreamFactory) New(ipFlow, tcpFlow gopacket.Flow, tcp *layers.TCP, a
Props: make(analyzer.CombinedPropMap),
}
f.Logger.TCPStreamNew(f.WorkerID, info)
f.RulesetMutex.RLock()
rs := f.Ruleset
f.RulesetMutex.RUnlock()
rs := f.currentRuleset()
ans := analyzersToTCPAnalyzers(rs.Analyzers(info))
// Create entries for each analyzer
entries := make([]*tcpStreamEntry, 0, len(ans))
@@ -87,7 +85,7 @@ func (f *tcpStreamFactory) New(ipFlow, tcpFlow gopacket.Flow, tcp *layers.TCP, a
info: info,
virgin: true,
logger: f.Logger,
ruleset: rs,
rulesetSource: f.currentRuleset,
activeEntries: entries,
}
}
@@ -99,11 +97,17 @@ func (f *tcpStreamFactory) UpdateRuleset(r ruleset.Ruleset) error {
return nil
}
func (f *tcpStreamFactory) currentRuleset() ruleset.Ruleset {
f.RulesetMutex.RLock()
defer f.RulesetMutex.RUnlock()
return f.Ruleset
}
type tcpStream struct {
info ruleset.StreamInfo
virgin bool // true if no packets have been processed
logger Logger
ruleset ruleset.Ruleset
rulesetSource func() ruleset.Ruleset
activeEntries []*tcpStreamEntry
doneEntries []*tcpStreamEntry
lastVerdict tcpVerdict
@@ -152,7 +156,10 @@ func (s *tcpStream) ReassembledSG(sg reassembly.ScatterGather, ac reassembly.Ass
s.virgin = false
s.logger.TCPStreamPropUpdate(s.info, false)
// Match properties against ruleset
result := s.ruleset.Match(s.info)
result := ruleset.MatchResult{Action: ruleset.ActionMaybe}
if rs := s.currentRuleset(); rs != nil {
result = rs.Match(s.info)
}
action := result.Action
if action != ruleset.ActionMaybe && action != ruleset.ActionModify {
verdict := actionToTCPVerdict(action)
@@ -171,6 +178,13 @@ func (s *tcpStream) ReassembledSG(sg reassembly.ScatterGather, ac reassembly.Ass
}
}
func (s *tcpStream) currentRuleset() ruleset.Ruleset {
if s.rulesetSource == nil {
return nil
}
return s.rulesetSource()
}
func (s *tcpStream) ReassemblyComplete(ac reassembly.AssemblerContext) bool {
s.closeActiveEntries()
return true