New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Multiple Alerts After Blocking PID #525
Comments
I am investigating this scenario. To simulate this behavior I created a simple Swift application that has a 10 sec timeout and tries to make a connection to a domain that has multiple IP records (because What I observed:
In the scenario I simulated here, the first PID showed in alert window is from the current process, but the following are from a previous version of the process. I ask this because I suspect there is a problem with consuming flows that are Can you check in the scenario you brought if the first PID shown is different from the others? |
Thank you for this bug report, and @mdjunior thanks for the detailed repo steps! 🙏🏽 |
@mdjunior : Thanks for the investigation.
I'll try to take note of the original IP next time it occurs. |
Here is an example where I'm looking to allow the process. You'll note the PID doesn't change, though the remote address changes: Screen.Recording.2024-01-22.at.5.21.18.PM.movRepro / command being run: Issue: Expected: |
After selecting temporary, and blocking that PID, additional alerts continue for different IP addresses.
Note the same process id keeps popping up with different remote IP addresses.
Expected behavior:
Since I am blocking the PID (even temporarily), I would expect there to be no more alerts for that PID, including if the remote IP address changes.
Possible cause:
Perhaps LuLu isn't checking the newly set rules before each alert?
Config:
The text was updated successfully, but these errors were encountered: