Hello,
I am preparing a personal application and am not an experienced Windows driver developer. I have used AI assistance to organize this question, but I am seeking an expert explanation supported by documentation. No WFP implementation or tests have been performed.
The application needs to revoke permission for outbound network activity. I am trying to understand the supported enforcement boundary for existing outbound TCP connections at ALE_AUTH_CONNECT_V4/V6.
Microsoft documents that, once an ALE policy change is detected, the first packet traversing an affected flow triggers reauthorization:
FwpmTransactionCommit0 documents commitment of the management transaction:
Does successful return from FwpmTransactionCommit0 establish a synchronization point after which traffic cannot proceed using the old ALE authorization?
In particular, what happens if classification started before the policy change but returns a permit after the commit? If commit is not such a synchronization point, is there another supported mechanism with documented ordering semantics?
I understand that ALE is stateful rather than necessarily classifying every packet, and that bytes already transmitted cannot be recalled. I am asking where the guarantee ends for pending classifications and data already queued downstream—not assuming that a policy update drains the transport or guarantees a particular stopping time.
An explanation of the supported contract, its limitations, and any applicable Windows-version differences would be very helpful.
I also posted the question on Microsoft Q&A. At the time of writing, I have only received an automated response restating the documentation gap: