Skip to content

Feature/bypass lastpktts v5 - #16205

Open
Aboussejra wants to merge 2 commits into
OISF:mainfrom
Aboussejra:feature/bypass-lastpktts-v5
Open

Aboussejra wants to merge 2 commits into
OISF:mainfrom
Aboussejra:feature/bypass-lastpktts-v5

Conversation

@Aboussejra

Copy link
Copy Markdown

EBPFBypassUpdate() set the flow's lastts from the timestamp of the flow manager pass that noticed a counter change, not from the time of the last packet, which was not available: the eBPF bypass map only carried packet and byte counters.

Stamp every counted packet with bpf_ktime_get_ns() in a new field of struct pair, in both the bypass_filter and xdp_filter programs, and take the most recent stamp over the per CPU values when reading the map.

Link to ticket: https://redmine.openinfosecfoundation.org/issues/8919

Provide values to any of the below to override the defaults.

  • To use a Suricata-Verify or Suricata-Update pull request,
    link to the pull request in the respective _BRANCH variable.
  • Leave unused overrides blank or remove.

SV_REPO=
SV_BRANCH=
SU_REPO=
SU_BRANCH=

Amir Boussejra added 2 commits September 9, 2026 15:34
When a flow is bypassed by the capture method, the packets and bytes
counted by the bypass are stored in the flow's FlowBypassInfo storage and
not in the Flow counters. The netflow logger only read the Flow counters,
so netflow.pkts and netflow.bytes only reported what Suricata saw before
the bypass was installed, which disagreed with the flow event logged for
the same flow.

Add the bypassed counters to the reported values and expose the bypassed
part alone in a netflow.bypassed object, mirroring what the flow event
already does in flow.bypassed.

Ticket: OISF#8918
EBPFBypassUpdate() set the flow's lastts from the timestamp of the flow
manager pass that noticed a counter change, not from the time of the last
packet, which was not available: the eBPF bypass map only carried packet
and byte counters.

Stamp every counted packet with bpf_ktime_get_ns() in a new field of
struct pair, in both the bypass_filter and xdp_filter programs, and take
the most recent stamp over the per CPU values when reading the map.

Ticket: OISF#8919
@codecov

codecov Bot commented Sep 10, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 62.85714% with 13 lines in your changes missing coverage. Please review.
✅ Project coverage is 83.11%. Comparing base (928ac01) to head (9591361).

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #16205      +/-   ##
==========================================
- Coverage   83.15%   83.11%   -0.05%     
==========================================
  Files        1004     1004              
  Lines      277688   277707      +19     
==========================================
- Hits       230918   230803     -115     
- Misses      46770    46904     +134     
Flag Coverage Δ
fuzzcorpus 61.79% <63.63%> (-0.01%) ⬇️
livemode 18.43% <15.15%> (-0.02%) ⬇️
netns 22.82% <17.14%> (-0.03%) ⬇️
pcap 45.40% <15.15%> (-0.05%) ⬇️
suricata-verify 67.30% <63.63%> (-0.03%) ⬇️
unittests 58.52% <0.00%> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@victorjulien

Copy link
Copy Markdown
Member

My bot flags an issue with flows that are evicted from the ebpf table:

Main finding (must fix): stale lastpktts. A capture-bypassed flow that goes quiet (FM deletes the eBPF map entry) and resumes traffic gets downgraded to FLOW_STATE_LOCAL_BYPASSED (flow.c, gap > bypassed_timeout/2 = 50s). fc->lastpktts stays non-zero
but stale, and the new output code
lastts = (fc && SCTIME_SECS(fc->lastpktts)) ? fc->lastpktts : f->lastts (output-json-flow.c, output-json-netflow.c ×2) then reports end/age as the last bypassed packet time instead of the true last packet — understated by the idle gap. Fix: take max of
f->lastts and fc->lastpktts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants