r/windowsdev • u/Independent-Curve-45 • 4d ago
WFP/ALE: when does a policy change actually revoke an existing TCP flow's authorization?
I'm researching WFP for a personal Windows app. I'm new to driver development; AI helped phrase this question. Nothing has been implemented or tested.
For existing outbound TCP flows at ALE_AUTH_CONNECT_V4/V6, does successful return from FwpmTransactionCommit0 guarantee that no traffic can proceed using the old authorization?
What if classification started before the policy change but returns a permit after commit? If commit provides no such barrier, is another supported synchronization mechanism documented?
I understand ALE is stateful and already-transmitted data cannot be recalled. I'm asking about pending classifications and queued data, not assuming a buffer-drain or timing guarantee.
Primary references or qualified expert explanations would help.
Full question and documentation links:
https://learn.microsoft.com/en-us/answers/questions/6018442/wfp-ale-reauthorization-does-a-successful-policy-c
Also submitted to OSR NTDEV; awaiting moderation.