From 717e2b0248c45c3d911bdd5704218e31e79de4ec Mon Sep 17 00:00:00 2001 From: Jason Ish Date: Wed, 25 Jan 2023 11:53:08 -0600 Subject: [PATCH] smb: fix duplicate interface logging An array of interfaces was being logged without creating an array, resulting in duplicate "interface" objects being logged. Instead put these interfaces into an array like already done elsewhere. Issue: 5814 --- rust/src/smb/log.rs | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/rust/src/smb/log.rs b/rust/src/smb/log.rs index b06d8d1d78..84965749ba 100644 --- a/rust/src/smb/log.rs +++ b/rust/src/smb/log.rs @@ -337,9 +337,18 @@ fn smb_common_header(jsb: &mut JsonBuilder, state: &SMBState, tx: &SMBTransactio jsb.set_uint("stub_data_size", x.stub_data_ts.len() as u64)?; jsb.close()?; if let Some(ref ifaces) = state.dcerpc_ifaces { - for i in ifaces { - if i.context_id == x.context_id { - jsb.open_object("interface")?; + // First filter the interfaces to those + // with the context_id we want to log to + // avoid creating an empty "interfaces" + // array. + let mut ifaces = ifaces + .iter() + .filter(|i| i.context_id == x.context_id) + .peekable(); + if ifaces.peek().is_some() { + jsb.open_array("interfaces")?; + for i in ifaces { + jsb.start_object()?; let ifstr = uuid::Uuid::from_slice(&i.uuid); let ifstr = ifstr.map(|ifstr| ifstr.to_hyphenated().to_string()).unwrap(); jsb.set_string("uuid", &ifstr)?; @@ -347,6 +356,7 @@ fn smb_common_header(jsb: &mut JsonBuilder, state: &SMBState, tx: &SMBTransactio jsb.set_string("version", &vstr)?; jsb.close()?; } + jsb.close()?; } } },