]> git.ipfire.org Git - thirdparty/suricata.git/commitdiff
flowworker: simplify pseudo packet use 8888/head
authorVictor Julien <vjulien@oisf.net>
Mon, 15 May 2023 08:02:26 +0000 (10:02 +0200)
committerVictor Julien <vjulien@oisf.net>
Tue, 16 May 2023 09:56:08 +0000 (11:56 +0200)
Pseudo packets originating in the flow worker do not need to leave the
flow worker. Putting those in the ThreadVars::decode_pq will make them
be evaluated by the next steps in the pipeline, but those will all
ignore pseudo packets.

Instead, this patch returns them to the packet pool, while still honoring
the IPS verdict logic.

src/flow-worker.c

index 9ecfe65f299ad46e24c7ee4197ef9693e302788c..ffdd2defdc07bc41fe71abe0f3dd671aaf975e12 100644 (file)
@@ -407,12 +407,13 @@ static inline void FlowWorkerStreamTCPUpdate(ThreadVars *tv, FlowWorkerThreadDat
         /* no need to keep a flow ref beyond this point */
         FlowDeReference(&x->flow);
 
+        /* no further work to do for this pseudo packet, so we can return
+         * it to the pool immediately. */
         if (timeout) {
             PacketPoolReturnPacket(x);
         } else {
-            /* put these packets in the decode queue so that they are processed
-             * by the other thread modules before packet 'p'. */
-            PacketEnqueueNoLock(&tv->decode_pq, x);
+            /* to support IPS verdict logic, in the non-timeout case we need to do a bit more */
+            TmqhOutputPacketpool(tv, x);
         }
     }
 }