-
Notifications
You must be signed in to change notification settings - Fork 51
/
processor.go
116 lines (96 loc) · 3.54 KB
/
processor.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
// +build windows
package windowsmonitor
import (
"context"
"fmt"
"regexp"
"go.aporeto.io/enforcerd/trireme-lib/common"
"go.aporeto.io/enforcerd/trireme-lib/monitor/config"
"go.aporeto.io/enforcerd/trireme-lib/monitor/extractors"
"go.aporeto.io/enforcerd/trireme-lib/policy"
"go.uber.org/zap"
)
type windowsProcessor struct {
regStart *regexp.Regexp
metadataExtractor extractors.EventMetadataExtractor
config *config.ProcessorConfig
host bool
}
// Start processes PU start events
func (w *windowsProcessor) Start(ctx context.Context, eventInfo *common.EventInfo) error {
// Validate the PUID format. Additional validations TODO
if !w.regStart.Match([]byte(eventInfo.PUID)) {
return fmt.Errorf("invalid pu id: %s", eventInfo.PUID)
}
// Normalize to a nativeID context. This will become key for any recoveries
// and it's an one way function.
nativeID := w.generateContextID(eventInfo)
// Extract the metadata and create the runtime
runtime, err := w.metadataExtractor(eventInfo)
if err != nil {
return err
}
// We need to send a create event to the policy engine.
if err = w.config.Policy.HandlePUEvent(ctx, nativeID, common.EventCreate, runtime); err != nil {
return fmt.Errorf("Unable to create PU: %s", err)
}
// We can now send a start event to the policy engine
if err = w.config.Policy.HandlePUEvent(ctx, nativeID, common.EventStart, runtime); err != nil {
return fmt.Errorf("Unable to start PU: %s", err)
}
return nil
}
// Event processes PU stop events
func (w *windowsProcessor) Stop(ctx context.Context, eventInfo *common.EventInfo) error {
puID := w.generateContextID(eventInfo)
runtime := policy.NewPURuntimeWithDefaults()
runtime.SetPUType(eventInfo.PUType)
return w.config.Policy.HandlePUEvent(ctx, puID, common.EventStop, runtime)
}
// Create process a PU create event
func (w *windowsProcessor) Create(ctx context.Context, eventInfo *common.EventInfo) error {
return fmt.Errorf("Use start directly for windows processes. Create not supported")
}
// Event process a PU destroy event
func (w *windowsProcessor) Destroy(ctx context.Context, eventInfo *common.EventInfo) error {
puID := w.generateContextID(eventInfo)
runtime := policy.NewPURuntimeWithDefaults()
runtime.SetPUType(eventInfo.PUType)
// Send the event upstream
if err := w.config.Policy.HandlePUEvent(ctx, puID, common.EventDestroy, runtime); err != nil {
zap.L().Warn("Unable to clean trireme ",
zap.String("puID", puID),
zap.Error(err),
)
}
return nil
}
// Event processes a pause event
func (w *windowsProcessor) Pause(ctx context.Context, eventInfo *common.EventInfo) error {
return fmt.Errorf("Use start directly for windows processes. Pause not supported")
}
// Resync resyncs all PUs handled by this processor
func (w *windowsProcessor) Resync(ctx context.Context, eventInfo *common.EventInfo) error {
if eventInfo != nil {
// If its a host service then use pu from eventInfo
if eventInfo.HostService {
runtime, err := w.metadataExtractor(eventInfo)
if err != nil {
return err
}
nativeID := w.generateContextID(eventInfo)
if err = w.config.Policy.HandlePUEvent(ctx, nativeID, common.EventStart, runtime); err != nil {
return fmt.Errorf("Unable to start PU: %s", err)
}
return nil
}
}
// TODO(windows): handle resync of windows process PU later?
zap.L().Debug("Resync not handled")
return nil
}
func (w *windowsProcessor) generateContextID(eventInfo *common.EventInfo) string {
puID := eventInfo.PUID
// TODO(windows): regStop may be used here somewhere in the future?
return puID
}