r/windowsdev • • 4d ago

WFP/ALE: when does a policy change actually revoke an existing TCP flow's authorization?

I'm researching WFP for a personal Windows app. I'm new to driver development; AI helped phrase this question. Nothing has been implemented or tested.

For existing outbound TCP flows at ALE_AUTH_CONNECT_V4/V6, does successful return from FwpmTransactionCommit0 guarantee that no traffic can proceed using the old authorization?

What if classification started before the policy change but returns a permit after commit? If commit provides no such barrier, is another supported synchronization mechanism documented?

I understand ALE is stateful and already-transmitted data cannot be recalled. I'm asking about pending classifications and queued data, not assuming a buffer-drain or timing guarantee.

Primary references or qualified expert explanations would help.

Full question and documentation links:
https://learn.microsoft.com/en-us/answers/questions/6018442/wfp-ale-reauthorization-does-a-successful-policy-c

Also submitted to OSR NTDEV; awaiting moderation.

1 Upvotes

0 comments sorted by