mirror of
https://github.com/falcosecurity/falco.git
synced 2025-07-01 09:02:18 +00:00
Finish moving token bucket impl from falco to libs
It took a while, but we remembered to finish moving the token_bucket from falco engine to libs. There were 2 copies for a while. This brings over one change to libs--to have an optional timer function. Co-authored-by: Leonardo Grasso <me@leonardograsso.com> Co-authored-by: Loris Degioanni <loris@sysdig.com> Signed-off-by: Mark Stemm <mark.stemm@gmail.com>
This commit is contained in:
parent
1313e77113
commit
6a4e4eaa4f
@ -17,7 +17,6 @@ set(FALCO_ENGINE_SOURCE_FILES
|
|||||||
falco_utils.cpp
|
falco_utils.cpp
|
||||||
json_evt.cpp
|
json_evt.cpp
|
||||||
ruleset.cpp
|
ruleset.cpp
|
||||||
token_bucket.cpp
|
|
||||||
formats.cpp)
|
formats.cpp)
|
||||||
|
|
||||||
add_library(falco_engine STATIC ${FALCO_ENGINE_SOURCE_FILES})
|
add_library(falco_engine STATIC ${FALCO_ENGINE_SOURCE_FILES})
|
||||||
|
@ -1,89 +0,0 @@
|
|||||||
/*
|
|
||||||
Copyright (C) 2019 The Falco Authors.
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#include <cstddef>
|
|
||||||
#include <functional>
|
|
||||||
#include <sys/time.h>
|
|
||||||
|
|
||||||
#include "token_bucket.h"
|
|
||||||
#include "utils.h"
|
|
||||||
#include "banned.h" // This raises a compilation error when certain functions are used
|
|
||||||
|
|
||||||
token_bucket::token_bucket():
|
|
||||||
token_bucket(sinsp_utils::get_current_time_ns)
|
|
||||||
{
|
|
||||||
}
|
|
||||||
|
|
||||||
token_bucket::token_bucket(std::function<uint64_t()> timer)
|
|
||||||
{
|
|
||||||
m_timer = timer;
|
|
||||||
init(1, 1);
|
|
||||||
}
|
|
||||||
|
|
||||||
token_bucket::~token_bucket()
|
|
||||||
{
|
|
||||||
}
|
|
||||||
|
|
||||||
void token_bucket::init(double rate, double max_tokens, uint64_t now)
|
|
||||||
{
|
|
||||||
m_rate = rate;
|
|
||||||
m_max_tokens = max_tokens;
|
|
||||||
m_tokens = max_tokens;
|
|
||||||
m_last_seen = now == 0 ? m_timer() : now;
|
|
||||||
}
|
|
||||||
|
|
||||||
bool token_bucket::claim()
|
|
||||||
{
|
|
||||||
return claim(1, m_timer());
|
|
||||||
}
|
|
||||||
|
|
||||||
bool token_bucket::claim(double tokens, uint64_t now)
|
|
||||||
{
|
|
||||||
double tokens_gained = m_rate * ((now - m_last_seen) / (1000000000.0));
|
|
||||||
m_last_seen = now;
|
|
||||||
|
|
||||||
m_tokens += tokens_gained;
|
|
||||||
|
|
||||||
//
|
|
||||||
// Cap at max_tokens
|
|
||||||
//
|
|
||||||
if(m_tokens > m_max_tokens)
|
|
||||||
{
|
|
||||||
m_tokens = m_max_tokens;
|
|
||||||
}
|
|
||||||
|
|
||||||
//
|
|
||||||
// If m_tokens is < tokens, can't claim.
|
|
||||||
//
|
|
||||||
if(m_tokens < tokens)
|
|
||||||
{
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
m_tokens -= tokens;
|
|
||||||
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
double token_bucket::get_tokens()
|
|
||||||
{
|
|
||||||
return m_tokens;
|
|
||||||
}
|
|
||||||
|
|
||||||
uint64_t token_bucket::get_last_seen()
|
|
||||||
{
|
|
||||||
return m_last_seen;
|
|
||||||
}
|
|
@ -1,77 +0,0 @@
|
|||||||
/*
|
|
||||||
Copyright (C) 2019 The Falco Authors.
|
|
||||||
|
|
||||||
Licensed under the Apache License, Version 2.0 (the "License");
|
|
||||||
you may not use this file except in compliance with the License.
|
|
||||||
You may obtain a copy of the License at
|
|
||||||
|
|
||||||
http://www.apache.org/licenses/LICENSE-2.0
|
|
||||||
|
|
||||||
Unless required by applicable law or agreed to in writing, software
|
|
||||||
distributed under the License is distributed on an "AS IS" BASIS,
|
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
||||||
See the License for the specific language governing permissions and
|
|
||||||
limitations under the License.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#pragma once
|
|
||||||
|
|
||||||
#include <cstdint>
|
|
||||||
#include <functional>
|
|
||||||
|
|
||||||
// A simple token bucket that accumulates tokens at a fixed rate and allows
|
|
||||||
// for limited bursting in the form of "banked" tokens.
|
|
||||||
class token_bucket
|
|
||||||
{
|
|
||||||
public:
|
|
||||||
token_bucket();
|
|
||||||
token_bucket(std::function<uint64_t()> timer);
|
|
||||||
virtual ~token_bucket();
|
|
||||||
|
|
||||||
//
|
|
||||||
// Initialize the token bucket and start accumulating tokens
|
|
||||||
//
|
|
||||||
void init(double rate, double max_tokens, uint64_t now = 0);
|
|
||||||
|
|
||||||
//
|
|
||||||
// Try to claim tokens tokens from the token bucket, using a
|
|
||||||
// timestamp of now. Returns true if the tokens could be
|
|
||||||
// claimed. Also updates internal metrics.
|
|
||||||
//
|
|
||||||
bool claim(double tokens, uint64_t now);
|
|
||||||
|
|
||||||
// Simpler version of claim that claims a single token and
|
|
||||||
// uses the current time for now
|
|
||||||
bool claim();
|
|
||||||
|
|
||||||
// Return the current number of tokens available
|
|
||||||
double get_tokens();
|
|
||||||
|
|
||||||
// Return the last time someone tried to claim a token.
|
|
||||||
uint64_t get_last_seen();
|
|
||||||
|
|
||||||
private:
|
|
||||||
std::function<uint64_t()> m_timer;
|
|
||||||
|
|
||||||
//
|
|
||||||
// The number of tokens generated per second.
|
|
||||||
//
|
|
||||||
double m_rate;
|
|
||||||
|
|
||||||
//
|
|
||||||
// The maximum number of tokens that can be banked for future
|
|
||||||
// claim()s.
|
|
||||||
//
|
|
||||||
double m_max_tokens;
|
|
||||||
|
|
||||||
//
|
|
||||||
// The current number of tokens
|
|
||||||
//
|
|
||||||
double m_tokens;
|
|
||||||
|
|
||||||
//
|
|
||||||
// The last time claim() was called (or the object was created).
|
|
||||||
// Nanoseconds since the epoch.
|
|
||||||
//
|
|
||||||
uint64_t m_last_seen;
|
|
||||||
};
|
|
Loading…
Reference in New Issue
Block a user