Refactor: Remove NFStream and flow identity utilities; introduce Tshark manager
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 11s

- Deleted flow_identity.py and nfstream_flow_worker.py as they are no longer needed.
- Removed nfstream_manager.py and its associated logic for managing NFStream workers.
- Added tshark_manager.py to manage tshark packet enrichment and matching.
- Updated setup_build_server.sh to include default environment variables for tshark.
- Implemented packet signature generation and enrichment logic in the new TsharkManager class.
This commit is contained in:
2026-03-07 19:51:29 +01:00
parent dfad09fa21
commit 22bb6b8526
11 changed files with 603 additions and 695 deletions

View File

@@ -33,9 +33,9 @@ from src.utilities.interface_bridge_helpers import (
)
from src.config import settings
from src.utilities.bridge_telemetry import bridge_telemetry_manager
from src.utilities.nfstream_manager import nfstream_manager
from src.utilities.packet_identity import build_packet_uid
from src.utilities.packet_tracker import packet_tracker
from src.utilities.tshark_manager import tshark_manager
from src.Models.etherType import EtherTypeEnum, ethertype_from_int
from src.Models.ip_protocol import IPProtocolEnum, protocol_from_number
@@ -371,13 +371,13 @@ def parse_packet(pkt, bridge_label: str, capture_metadata: Optional[Dict[str, An
if Raw in pkt and not pkt_info.get("protocol_name"):
pkt_info["protocol_name"] = "RAW"
# Flow-level enrichment using NFStream, if available.
# Packet-level enrichment using tshark, if available.
try:
flow_info = nfstream_manager.lookup_packet(pkt, pkt_iface)
if flow_info:
_merge_enrichment(pkt_info, flow_info)
packet_info = tshark_manager.lookup_packet(pkt, pkt_iface)
if packet_info:
_merge_enrichment(pkt_info, packet_info)
except Exception:
logger.exception("NFStream enrichment failed")
logger.exception("tshark enrichment failed")
if ICMP in pkt:
inner = pkt[ICMP].payload
@@ -536,9 +536,9 @@ def _sync_bridge_telemetry() -> None:
}
)
try:
nfstream_manager.update_interfaces(active_enrichment_ifaces)
tshark_manager.update_interfaces(active_enrichment_ifaces)
except Exception:
logger.exception("Failed to update NFStream enrichment workers")
logger.exception("Failed to update tshark enrichment workers")
# -------------------------
@@ -839,6 +839,6 @@ def get_internal_debug_state() -> dict:
"buffer_len": len(_PACKET_BUFFER),
"bridge_capture_mode": "tc_ingress_raw" if any(s.get("is_bridge") for s in sessions.values()) else "af_packet",
"telemetry_ports": sorted({iface for session in sessions.values() for iface in session.get("ports", [])}),
"nfstream": nfstream_manager.get_debug_snapshot(),
"tshark": tshark_manager.get_debug_snapshot(),
"packet_tracker": packet_tracker.get_debug_snapshot(),
}