oz icon indicating copy to clipboard operation
oz copied to clipboard

ProxyPair structure should save socket inodes

Open dma opened this issue 7 years ago • 0 comments

Current procsnitch lookup works, but subject to losing information about short lived connections.

  • The socket inode #s should be saved when oz TCP port forward clients connect, and removed when disconnect, though there may be reason to keep the information longer than the life of the connection, perhaps a ring buffer
  • This ensures that every connection is recorded by oz-daemon, even if it is lost immediately.
  • The procsnitch lookup should rely on the inode first. Inodes for sockets can be retrieved via INET_DIAG.
  • This will result in a more efficient lookup by fw-daemon, the connection monitor, and elsewhere (see https://github.com/subgraph/go-procsnitch/issues/6)

dma avatar Oct 01 '17 15:10 dma