Commit Graph

17574 Commits (0e18048ef0569322d6f4761253228bbf907bddbd)
 

Author SHA1 Message Date
Victor Julien 19e3a70ca3 detect/byte_test: suppress scan-build warning
detect-bytetest.c:523:14: warning: 2nd function call argument is an uninitialized value [core.CallAndMessage]
  523 |         if (!DetectBytetestValidateNbytes(data, nbytes, optstr)) {
      |              ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
1 year ago
Victor Julien 159bacb268 github-ci: bump scan-build to 20 on Ubuntu 25.04 1 year ago
Eric Leblond f342ae9e8c misc: add git-clang-format to shell.nix 1 year ago
Eric Leblond 96962536a7 misc: add python support to shell.nix
This allows to run suricata-verify from the shell environment.

Ticket: #7669
1 year ago
Eric Leblond 649a032ba9 github-ci: add a nix build
This will test that shell.nix is working properly and also
test compile-commands Makefile target.

Ticket: #7669
1 year ago
Eric Leblond 2a2f38ff88 build: add compile-commands target
It generates a `compile_commands.json` suitable for clangd.
This is almost mandatory to have a command like this one for NixOs
users as tool like bear are not able to intercept correctly the
clang calls due to the usage of a wrapper.

Ticket: #7669
1 year ago
Eric Leblond 20371dbdf6 build: add EXTRA_CFLAGS
This can be used from command line to add some build options without
running a full configure. This is convenient for single run build.
1 year ago
Eric Leblond 90a08ecfc3 misc: add a shell.nix file
By adding a `shell.nix` file in the root directory of the source,
NixOs (https://nixos.org/) users can get a ready for development
environment by simply running `nix-shell` from the source tree.

This is really convenient as the installation of needed packages
is just done as user and transparently for the user/developer.

Ticket: #7669
1 year ago
Jason Ish 97eaeef7d8 lua: convert SMTP functions to lib: suricata.smtp
Ticket: #7606
1 year ago
Eric Leblond e499a98ba9 datasets: fix set with ip sets
It can get an IPv6 or an IPv4 so we need to handle both length.

Ticket: #7689
1 year ago
Victor Julien ee59d9a894 flow: fix unittests for ThreadVars requirement 1 year ago
Victor Julien c648abad0d flow: fix time handling for non-TCP
Track per flow thread id for UDP and other non-TCP protocols. This
improves the timeout handling as the per thread timestamp is used in
offline mode.

Fixes: ada2bfe009 ("flow/worker: improve flow timeout time accuracy")
Fixes: ef396f7509 ("flow/manager: in offline mode, use owning threads time")

Bug #7687.
1 year ago
Jeff Lucovsky 44d6886dc1 detect/ftp: Use helper functions with ftp.command
Refactor ftp.command handling to use helper functions from
detect-engine-helper.[ch] for reduced code duplication.
1 year ago
Philippe Antoine 7e78ad944c lua: convert ja3 function into suricata.ja3 lib
Ticket: 7605
1 year ago
Philippe Antoine c578015edf lua: remove unused code
Since hooks, we do not need a specific SMTP buffer list id.
1 year ago
Philippe Antoine 06ad72e83e quic: ja3 getter function uses direction
so that future lua code can specify a direction
1 year ago
Philippe Antoine d1bca4a9b9 util/lua: fix new -Wshorten-64-to-32 warning
Ticket: 6186
1 year ago
Philippe Antoine 4463fbac15 output/ftp: fix new -Wshorten-64-to-32 warning
Ticket: 6186

Fixes d674ce2510 ("app/ftp: Use Rust FTP response line handling")
1 year ago
Philippe Antoine 41fcf3b356 detect: fix some -Wshorten-64-to-32 warnings
Ticket: #6186
1 year ago
Philippe Antoine 527b05b6b8 datasets: fix new -Wshorten-64-to-32 warning
Ticket: #6186
1 year ago
Philippe Antoine 8545ef2e56 detect: factorize code for DetectSetupDirection
Ticket: 7665

Instead of each keyword calling DetectSetupDirection, use a
new flag SIGMATCH_SUPPORT_DIR so that DetectSetupDirection gets
called, before parsing the rest of the keyword.

Allows to support filesize keyword in transactional signatures
1 year ago
Jason Ish 14864d49ac examples/altemplate: remove rs_ naming 1 year ago
Jason Ish e8d7d3d83d scripts/setup-app-layer: fixes for name changes 1 year ago
Jason Ish bf427c69cd rust: remaining rs_ to SC conversions 1 year ago
Jason Ish d16c014641 rust/x509: replace rs_ naming with SC 1 year ago
Jason Ish afce53c8b7 rust/websocket: replace rs_ naming with SC 1 year ago
Jason Ish 7321d7c7db rust/applayertemplate: replace rs_ naming with SC 1 year ago
Jason Ish 2c98ee73ce rust/rfb: replace rs_ naming with SC 1 year ago
Jason Ish e74b4177ac rust/nfs: rust format 1 year ago
Jason Ish 8c1bd60ab1 rust/nfs: replace rs_ naming with SC 1 year ago
Jason Ish 01ce0f92e8 rust/modbus: replace rs_ naming to SC
This was missed in the previous round.
1 year ago
Victor Julien 2cbec43b98 mpm/ac-ks: allow cppcheck to inspect included file directly 1 year ago
Victor Julien a8b342a07b debug: suppress cppcheck warning
src/util-debug.c:1562:5: warning: Either the condition 'sc_lid!=NULL' is redundant or there is possible null pointer dereference: sc_lid. [nullPointerRedundantCheck]
    sc_lid->global_log_level = MAX(sc_lid->global_log_level, max_level);
    ^
src/util-debug.c:1569:16: note: Assuming that condition 'sc_lid!=NULL' is not redundant
    if (sc_lid != NULL)
               ^
src/util-debug.c:1562:5: note: Null pointer dereference
    sc_lid->global_log_level = MAX(sc_lid->global_log_level, max_level);
    ^
1 year ago
Victor Julien 223c568701 lua/flowvarlib: check malloc result
src/util-lua-flowvarlib.c:110:12: warning: If memory allocation fails, then there is a possible null pointer dereference: buf [nullPointerOutOfMemory]
    memcpy(buf, value, len);
           ^
src/util-lua-flowvarlib.c:109:28: note: Assuming allocation function fails
    uint8_t *buf = SCMalloc(len + 1);
                           ^
src/util-lua-flowvarlib.c:109:28: note: Assignment 'buf=malloc(len+1)', assigned value is 0
    uint8_t *buf = SCMalloc(len + 1);
                           ^
src/util-lua-flowvarlib.c:110:12: note: Null pointer dereference
    memcpy(buf, value, len);
           ^
src/util-lua-flowvarlib.c:111:5: warning: If memory allocation fails, then there is a possible null pointer dereference: buf [nullPointerOutOfMemory]
    buf[len] = '\0';
    ^
src/util-lua-flowvarlib.c:109:28: note: Assuming allocation function fails
    uint8_t *buf = SCMalloc(len + 1);
                           ^
src/util-lua-flowvarlib.c:109:28: note: Assignment 'buf=malloc(len+1)', assigned value is 0
    uint8_t *buf = SCMalloc(len + 1);
                           ^
src/util-lua-flowvarlib.c:111:5: note: Null pointer dereference
    buf[len] = '\0';
1 year ago
Jason Ish 4e2f1de308 rust/quic: replace rs_ naming with SC 1 year ago
Jason Ish bfa0acf278 rust/ike: replace rs_ naming with SC 1 year ago
Jason Ish 717e06e351 rust/http2: replace rs_ naming with SC 1 year ago
Jason Ish af15986d41 rust/modbus: replace rs_ naming with SC 1 year ago
Jason Ish c994cfb615 rust/sip: replace rs_ naming with SC 1 year ago
Jason Ish 9b830c92dc rust/tftp: replace rs_ naming with SC 1 year ago
Jason Ish aa24276999 rust/telnet: replace rs_ naming with SC 1 year ago
Jason Ish 1c580f9001 rust/detect: replace rs_ naming with SC 1 year ago
Jason Ish 713034d0dd rust/asn1: replace rs_ naming with SC naming 1 year ago
Jason Ish 90116827fe rust/krb: rust format 1 year ago
Jason Ish 8ba0a5c8ec rust/krb: remove rs_ prefix; visibility fixes
- remove pub/no_mangle where not needed
- replace rs_ naming with SC naming
1 year ago
Jason Ish 1f30746e07 rust/dns: rs_ prefix name cleanup 1 year ago
Victor Julien 3fe9bd7cbb detect/flow: don't overwrite hook direction 1 year ago
Victor Julien 6ee32cba3b firewall: apply action again for stateful matches
For "stateful rules", don't drop packets after the initial match as long
as the tx state doesn't change.

An example of how this could happen was:

        accept:hook ssh:request_started any any -> any any (alert; sid:2000;)
        accept:hook ssh:request_banner_wait_eol any any -> any any (alert; sid:2001;)
        accept:hook ssh:request_banner_done any any -> any any (        \
                ssh.software; content:"OpenSSH_8.2p1"; alert; sid:2002;)

As the ssh session reached the request_banner_done state, it would
remain in this state. So additional packets would again review the rules
for this state. The rule 2002 is stored in the tx state as fully
matched, and would be skipped for the additional packets. This meant
that the `accept:hook` action was not applied and the default drop
policy was triggered.

This is addressed by updating the stateful logic:

If an accept rule has the DE_STATE_FLAG_FULL_INSPECT flag set, and the
tx progress is not progressed beyond the rule, apply the rule accept
acction.
1 year ago
Victor Julien b1f955ef5a firewall: move app action setting into helper func
In preparation of adding another callsite.
1 year ago
dependabot[bot] 4b89dafb44 github-actions: bump actions/download-artifact from 4.2.1 to 4.3.0
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.2.1 to 4.3.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](95815c38cf...d3f86a106a)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
1 year ago