Commit Graph

18767 Commits (98469b0f564595e2eefc9c59da1b3d577862fcad)
 

Author SHA1 Message Date
Jason Ish 98469b0f56 rust/ffi: fix clippy warnings
Remove the unneeded return.

The other option would be to allow it, but so far in the ffi crate we
don't have any non-default allows.
4 months ago
Jason Ish ecffd6cd54 github-ci: deny warnings in clippy check
We currently have some clippy warnings in the ffi crate. They output to
to the terminal but clippy exits with a success code. Typically we want
to fix this, so deny warnings which will cause clippy to exit with an
error code, failing ci.
4 months ago
Jason Ish 70994426d3 github-ci: add --workspace to cargo clippy --fix
--fix doesn't appear to apply to all sub-crates unless --workspace is
provided.
4 months ago
Jason Ish 336b50ae9e storage: prefix core API with SC 4 months ago
Jason Ish 3722477319 device/storage: prefix API with SC 4 months ago
Jason Ish 41fd80aa46 ippair/storage: prefix API with SC 4 months ago
Jason Ish 279aa88956 host/storage: prefix API with SC 4 months ago
Jason Ish 67bd09ba2c thread/storage: prefix API with SC
In preparation for Rust bindings.
4 months ago
Jason Ish 137f59f542 flow/storage: prefix API with SC
In preparation for adding Rust bindings.
4 months ago
dependabot[bot] bf6824cb49 github-actions: bump codecov/codecov-action from 5.5.2 to 6.0.0
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 5.5.2 to 6.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](671740ac38...57e3a136b7)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
4 months ago
dependabot[bot] b9fac32bbd github-actions: bump github/codeql-action from 4.32.4 to 4.35.1
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.32.4 to 4.35.1.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Commits](https://github.com/github/codeql-action/compare/v4.32.4...v4.35.1)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.35.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
4 months ago
dependabot[bot] 5ff0ed977c github-actions: bump actions/download-artifact from 8.0.0 to 8.0.1
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 8.0.0 to 8.0.1.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](70fc10c6e5...3e5f45b2cf)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
4 months ago
Philippe Antoine c53b9df5a2 rust/ffi: move detection helpers to ffi crate
Ticket: 7666
4 months ago
Philippe Antoine 4f4912c042 rust: bindgen SIGMATCH_ constants 4 months ago
Shivani Bhardwaj 4ec5f22951 ftp: trigger raw stream inspection
Internals
---------
Suricata's stream engine returns data for inspection to the detection
engine from the stream when the chunk size is reached.

Bug
---
Inspection triggered only in the specified chunk sizes may be too late
when it comes to inspection of smaller protocol specific data which
could result in delayed inspection, incorrect data logged with a transaction
and logs misindicating the pkt that triggered an alert.

Fix
---
Fix this by making an explicit call from all respective applayer parsers to
trigger raw stream inspection which shall make the data available for inspection
in the following call of the stream engine. This needs to happen per direction
on the completion of an entity like a request or a response.

Important notes
---------------
1. The above mentioned behavior with and without this patch is
affected internally by the following conditions.
- inspection depth
- stream depth
In these special cases, the inspection window will be affected and
Suricata may not consider all the data that could be expected to be
inspected.
2. This only applies to applayer protocols running over TCP.
3. The inspection window is only considered up to the ACK'd data.
4. This entire issue is about IDS mode only.

FTP parser can handle multiple command lines per direction. Appropriate calls
to trigger raw stream inspection have been added on succesful parsing of each
request line and response line.

Bug 7742
4 months ago
Philippe Antoine 2fa10052cf websocket: check pdu opcode for reassembly
Ticket: 8413

RFC 6455 Section 5.4 states

Control frames (see Section 5.5) MAY be injected in the middle of
a fragmented message.

Control frames are identified by opcodes where the most significant
bit of the opcode is 1.
4 months ago
Philippe Antoine 7b0528d85f http2: set response_frame_size
Ticket: 8410

Do not set only request_frame_size whatever the direction
4 months ago
Victor Julien 6c3169cee0 doc/userguide: add ether and arp to intro 4 months ago
Victor Julien 6298c47145 doc/userguide: improve protocol docs 4 months ago
Victor Julien e6381a3c22 doc/userguide: add note on rule reloads
Cannot be combined with --firewall-rules-exclusive
4 months ago
Victor Julien f99b86beab doc/userguide: document L2 firewall handling of ARP 4 months ago
Victor Julien facbb04915 detect: enable pcre and urilen for firewall mode
Ticket: #8397.
4 months ago
Victor Julien 49b1382a8b qa: add nfq based firewall test with live reload 4 months ago
Victor Julien 7ac32910c9 qa: add rule reload step to firewall test
Additionally, use bsize, pcre and urilen.

Ticket: #8204.
Ticket: #8397.
4 months ago
Victor Julien 1c66eec656 qa: add script to test firewall bridge mode 4 months ago
Victor Julien 2e2132a16f doc/userguide: improve pkthdr docs 4 months ago
Victor Julien 6fbd7483d6 detect/parse: limit pkthdr proto to decoder event rules
`alert pkthdr` was initially just an alias for `alert ip`, as that was
really just a way of stating that "any" should be matched. However with
the Ethernet matching in place, it no long makes sense to treat `alert
ip` as "any". Since `pkthdr` is used to match on decoder events, also
for packets that completely failed to parse, it should no longer be
treated as `alert ip` but rather as it's own distinct logic.
4 months ago
Victor Julien b983ce64ef detect: add track pkthdr as any l2 protocol
To indicate it's not just like `alert ip`.
4 months ago
Victor Julien 61a7f47a69 detect: add ether.hdr keyword
Sticky buffer to inspect the ethernet header.

Example rule:

        alert ether any any -> any any ( \
                ether.hdr; content:"|08 06|"; offset:12; depth:2; \
                sid:1;)

Ticket: #8327.
4 months ago
Victor Julien 232276ac19 detect: ethernet/arp matching
Support `alert ether` for matching all ethernet packets.

Add `alert arp` for matching ARP packets.

Ticket: #8313.
4 months ago
Victor Julien d4f005933a detect/proto: reduce size for common sigs
Make `Signature::proto` an optional member, meaning that if it is
NULL we can skip the check. This can be done for `alert ip`, as no check
is needed, and for `alert tcp` and `alert udp` as having a rule in a sgh
for those means that the protocol matches.

Some exceptions are rules that require:
- ipv4/ipv6 specific matching
- frames, due to sharing prefilter between tcp and udp
- ip-only rules, due to those not being per sgh
4 months ago
Victor Julien dc814aa595 detect/frame: set frame flag during init
Allows for quickly checking if sig operates on frames during parsing.
4 months ago
Jason Ish cd9993c568 storage: remove the size registration parameter
With the Alloc callback gone, the size is no longer needed.
4 months ago
Jason Ish f337cd573b storage: remove alloc callback as its unused
Remove the "Alloc" callback from the storage API, it was only being
used in tests without any real usage.
4 months ago
Jason Ish 332f47d557 host/storage: use fail/pass api in unit tests 4 months ago
Jason Ish 31a4381d30 flow/storage: use fail/pass api in unit tests 4 months ago
Eric Leblond e4e5413478 etc/schema: add http_request_body
Ticket: 8161
4 months ago
Eric Leblond 97a0ad342b etc/schema: match on http response body
Matching on the HTTP response body is not really possible as it is
a transformed version that can not be accessed via the signature
language.
4 months ago
Juliana Fajardini 41834f0a05 configure/qa-simulation: explicitly declare default
This is needed to generate the `--build-info` report.

Related to
Ticket #7885
4 months ago
Juliana Fajardini 6f0bb39aaa workflows: add qa-simulation mode
As build flag to (some of the) checks that run suricata-verify:
- AlmaLinux 10 (schema, plugins)
- CentOS Stream 9
- Fedora 43 (Suricata Verify codecov)
- Fedora 43 (clang, debug, asan, wshadow, rust-strict, systemd)
- Fedora 43 (gcc, debug, flto, asan, wshadow, rust-strict)
- Fedora (non-root, debug, clang, asan, wshadow, rust-strict, no-ja)
- Ubuntu 22.04 (Debug Validation)
- Debian 12 (xdp)
- Debian 13 (xdp)
- Debian 12 MSRV
- PF_RING

Related to
Ticket #7885
4 months ago
Juliana Fajardini 17cd814911 workflows: fix minor typo 4 months ago
Philippe Antoine f61247e846 plugin: remove one small suricata crate dependency 4 months ago
Philippe Antoine 267c3baff7 rust/ffi: move STREAM_ constants to ffi crate
Ticket: 7666

reexport them in suricata crate
cbindgen them to C
4 months ago
Philippe Antoine 61c667400b rust: remove obsolete inclusions from cbindgen.toml 4 months ago
Philippe Antoine fd4c6d4e06 rust: remove obsolete struct exclusions in cbindgen
As these structs are now in suricata_sys crate
4 months ago
Philippe Antoine a10a818792 rust: remove obsolete constants exclusion from cbindgen.toml
Completes commit 71b59f6dbe

These const are no longer defined in rust suricata crate
4 months ago
Philippe Antoine efcc7f9dfc ftp: remove PASS pattern for protocol detection
As FTP must have USER before PASS command
unlike IRC which can begin by PASS command

Ticket: 2978
4 months ago
Jason Ish dce2deee5e rust: pin unicode-segmentation crate to 1.12.0
unicode-segmentation (used by rustyline) was updated from 1.12.0 to
1.13.1 earlier and requires a newer version of Rust. Pin to 1.12.0 which
works with Rust 1.75.0.
5 months ago
Jason Ish 3e9c726aa8 etc/schema: remove "optional" field
The optional field has not been valid JSON schema field since we started
using it, so remove it.

All fields are optional unless marked as required.
5 months ago
Philippe Antoine 34ed8958a6 dcerpc: only log the tx interfaces
Not all the state ones

Ticket: 8378
5 months ago