Feature/bypass lastpktts v5 - #16205
Aboussejra wants to merge 2 commits into
Conversation
When a flow is bypassed by the capture method, the packets and bytes counted by the bypass are stored in the flow's FlowBypassInfo storage and not in the Flow counters. The netflow logger only read the Flow counters, so netflow.pkts and netflow.bytes only reported what Suricata saw before the bypass was installed, which disagreed with the flow event logged for the same flow. Add the bypassed counters to the reported values and expose the bypassed part alone in a netflow.bypassed object, mirroring what the flow event already does in flow.bypassed. Ticket: OISF#8918
EBPFBypassUpdate() set the flow's lastts from the timestamp of the flow manager pass that noticed a counter change, not from the time of the last packet, which was not available: the eBPF bypass map only carried packet and byte counters. Stamp every counted packet with bpf_ktime_get_ns() in a new field of struct pair, in both the bypass_filter and xdp_filter programs, and take the most recent stamp over the per CPU values when reading the map. Ticket: OISF#8919
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #16205 +/- ##
==========================================
- Coverage 83.15% 83.11% -0.05%
==========================================
Files 1004 1004
Lines 277688 277707 +19
==========================================
- Hits 230918 230803 -115
- Misses 46770 46904 +134
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
My bot flags an issue with flows that are evicted from the ebpf table:
|
EBPFBypassUpdate() set the flow's lastts from the timestamp of the flow manager pass that noticed a counter change, not from the time of the last packet, which was not available: the eBPF bypass map only carried packet and byte counters.
Stamp every counted packet with bpf_ktime_get_ns() in a new field of struct pair, in both the bypass_filter and xdp_filter programs, and take the most recent stamp over the per CPU values when reading the map.
Link to ticket: https://redmine.openinfosecfoundation.org/issues/8919
Provide values to any of the below to override the defaults.
link to the pull request in the respective
_BRANCHvariable.SV_REPO=
SV_BRANCH=
SU_REPO=
SU_BRANCH=