test tshark fix
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 9s
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 9s
This commit is contained in:
@@ -90,7 +90,7 @@ def load_settings() -> BackendSettings:
|
|||||||
tshark_enabled=_env_bool("BACKEND_TSHARK_ENABLED", True),
|
tshark_enabled=_env_bool("BACKEND_TSHARK_ENABLED", True),
|
||||||
tshark_display_filter=_env_str("BACKEND_TSHARK_DISPLAY_FILTER", "http or tls or dns"),
|
tshark_display_filter=_env_str("BACKEND_TSHARK_DISPLAY_FILTER", "http or tls or dns"),
|
||||||
tshark_cache_ttl_seconds=_env_float("BACKEND_TSHARK_CACHE_TTL_SECONDS", 5.0),
|
tshark_cache_ttl_seconds=_env_float("BACKEND_TSHARK_CACHE_TTL_SECONDS", 5.0),
|
||||||
tshark_match_window_ms=_env_int("BACKEND_TSHARK_MATCH_WINDOW_MS", 1_500),
|
tshark_match_window_ms=_env_int("BACKEND_TSHARK_MATCH_WINDOW_MS", 5_000),
|
||||||
tshark_reader_join_timeout_seconds=_env_float("BACKEND_TSHARK_READER_JOIN_TIMEOUT_SECONDS", 2.0),
|
tshark_reader_join_timeout_seconds=_env_float("BACKEND_TSHARK_READER_JOIN_TIMEOUT_SECONDS", 2.0),
|
||||||
tshark_process_stop_timeout_seconds=_env_float("BACKEND_TSHARK_PROCESS_STOP_TIMEOUT_SECONDS", 3.0),
|
tshark_process_stop_timeout_seconds=_env_float("BACKEND_TSHARK_PROCESS_STOP_TIMEOUT_SECONDS", 3.0),
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -281,6 +281,13 @@ class TsharkManager:
|
|||||||
self._workers: Dict[str, Dict[str, Any]] = {}
|
self._workers: Dict[str, Dict[str, Any]] = {}
|
||||||
self._cache: Dict[Tuple[str, int, str, str, int, int, int], List[Dict[str, Any]]] = {}
|
self._cache: Dict[Tuple[str, int, str, str, int, int, int], List[Dict[str, Any]]] = {}
|
||||||
self._last_error_by_iface: Dict[str, str] = {}
|
self._last_error_by_iface: Dict[str, str] = {}
|
||||||
|
self._stats: Dict[str, Any] = {
|
||||||
|
"events_total": 0,
|
||||||
|
"events_useful": 0,
|
||||||
|
"lookup_hits": 0,
|
||||||
|
"backfill_updates_total": 0,
|
||||||
|
"last_event_by_iface": {},
|
||||||
|
}
|
||||||
self._lock = threading.Lock()
|
self._lock = threading.Lock()
|
||||||
|
|
||||||
@property
|
@property
|
||||||
@@ -338,6 +345,7 @@ class TsharkManager:
|
|||||||
event = entries.pop(best_index)
|
event = entries.pop(best_index)
|
||||||
if not entries:
|
if not entries:
|
||||||
self._cache.pop(signature, None)
|
self._cache.pop(signature, None)
|
||||||
|
self._stats["lookup_hits"] += 1
|
||||||
|
|
||||||
return _build_enrichment(event)
|
return _build_enrichment(event)
|
||||||
|
|
||||||
@@ -356,6 +364,7 @@ class TsharkManager:
|
|||||||
},
|
},
|
||||||
"cache_entries": sum(len(entries) for entries in self._cache.values()),
|
"cache_entries": sum(len(entries) for entries in self._cache.values()),
|
||||||
"last_error_by_iface": dict(self._last_error_by_iface),
|
"last_error_by_iface": dict(self._last_error_by_iface),
|
||||||
|
"stats": dict(self._stats),
|
||||||
}
|
}
|
||||||
|
|
||||||
def _start_worker_locked(self, iface: str) -> None:
|
def _start_worker_locked(self, iface: str) -> None:
|
||||||
@@ -465,10 +474,25 @@ class TsharkManager:
|
|||||||
with self._lock:
|
with self._lock:
|
||||||
entries = self._cache.setdefault(signature, [])
|
entries = self._cache.setdefault(signature, [])
|
||||||
entries.append(event)
|
entries.append(event)
|
||||||
|
self._stats["events_total"] += 1
|
||||||
|
self._stats["last_event_by_iface"][iface] = {
|
||||||
|
"observed_at_ms": event.get("observed_at_ms"),
|
||||||
|
"protocol": event.get("protocol"),
|
||||||
|
"src_ip": event.get("src_ip"),
|
||||||
|
"dst_ip": event.get("dst_ip"),
|
||||||
|
"src_port": event.get("src_port"),
|
||||||
|
"dst_port": event.get("dst_port"),
|
||||||
|
"frame_protocols": event.get("frame_protocols"),
|
||||||
|
"http": event.get("http"),
|
||||||
|
"tls": event.get("tls"),
|
||||||
|
"dns": event.get("dns"),
|
||||||
|
}
|
||||||
self._purge_cache_locked(now_ms=int(event["observed_at_ms"]))
|
self._purge_cache_locked(now_ms=int(event["observed_at_ms"]))
|
||||||
|
|
||||||
enrichment = _build_enrichment(event)
|
enrichment = _build_enrichment(event)
|
||||||
if _has_useful_enrichment(enrichment):
|
if _has_useful_enrichment(enrichment):
|
||||||
|
with self._lock:
|
||||||
|
self._stats["events_useful"] += 1
|
||||||
self._schedule_backfill(event, enrichment)
|
self._schedule_backfill(event, enrichment)
|
||||||
|
|
||||||
rc = process.poll()
|
rc = process.poll()
|
||||||
@@ -495,6 +519,8 @@ class TsharkManager:
|
|||||||
window_ms=settings.tshark_match_window_ms,
|
window_ms=settings.tshark_match_window_ms,
|
||||||
)
|
)
|
||||||
if updated:
|
if updated:
|
||||||
|
with self._lock:
|
||||||
|
self._stats["backfill_updates_total"] += updated
|
||||||
logger.debug(
|
logger.debug(
|
||||||
"Backfilled tshark metadata for %s packets on %s %s:%s -> %s:%s",
|
"Backfilled tshark metadata for %s packets on %s %s:%s -> %s:%s",
|
||||||
updated,
|
updated,
|
||||||
|
|||||||
@@ -79,7 +79,7 @@ cat >"$BACKEND_ENV_FILE" <<EOL
|
|||||||
BACKEND_TSHARK_ENABLED=true
|
BACKEND_TSHARK_ENABLED=true
|
||||||
BACKEND_TSHARK_DISPLAY_FILTER=http or tls or dns
|
BACKEND_TSHARK_DISPLAY_FILTER=http or tls or dns
|
||||||
BACKEND_TSHARK_CACHE_TTL_SECONDS=5.0
|
BACKEND_TSHARK_CACHE_TTL_SECONDS=5.0
|
||||||
BACKEND_TSHARK_MATCH_WINDOW_MS=1500
|
BACKEND_TSHARK_MATCH_WINDOW_MS=5000
|
||||||
BACKEND_TSHARK_READER_JOIN_TIMEOUT_SECONDS=2.0
|
BACKEND_TSHARK_READER_JOIN_TIMEOUT_SECONDS=2.0
|
||||||
BACKEND_TSHARK_PROCESS_STOP_TIMEOUT_SECONDS=3.0
|
BACKEND_TSHARK_PROCESS_STOP_TIMEOUT_SECONDS=3.0
|
||||||
EOL
|
EOL
|
||||||
|
|||||||
Reference in New Issue
Block a user