unix-socket: reset to ready state on startup

As part of commit ea15282f47,
some initialization was moved to happen even in unix socket mode,
however, this initialization does setup some loggers that can only have
one instance enabled (anomaly, drop, file-store).

This will cause these loggers to error out on the first pcap, but work
on subsequent runs of the pcap as some deinitialization is done after
each pcap.

This fix just runs the post pcap-file deinitialization routine to
reset some of the initialization done on startup, like is done after
running each pcap in unix socket mode.

Redmine issue:
https://redmine.openinfosecfoundation.org/issues/4225

Additionally this prevents alerts from being logged two times
on the first run of a pcap through the unix socket:

Redmine issue:
https://redmine.openinfosecfoundation.org/issues/4434
pull/6101/head
Jason Ish 6 years ago committed by Victor Julien
parent 0f0cb5169f
commit 488d5fb342

@ -2027,8 +2027,14 @@ void PreRunPostPrivsDropInit(const int runmode)
StatsSetupPostConfigPreOutput();
RunModeInitializeOutputs();
if (runmode == RUNMODE_UNIX_SOCKET)
if (runmode == RUNMODE_UNIX_SOCKET) {
/* As the above did some necessary startup initialization, it
* also setup some outputs where only one is allowed, so
* deinitialize to the state that unix-mode does after every
* pcap. */
PostRunDeinit(RUNMODE_PCAP_FILE, NULL);
return;
}
StatsSetupPostConfigPostOutput();
}

Loading…
Cancel
Save