Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

detect: allow rule which need both directions to match #12646

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

catenacyber
Copy link
Contributor

Link to redmine ticket:
https://redmine.openinfosecfoundation.org/issues/5665

Describe changes:

  • allows bidirectional signature matching !

SV_BRANCH=OISF/suricata-verify#2083

#12405 with improved doc after review and fix for new assertion BUG_ON(count_final_sm_list == 0);

Ongoing question : usage of new keyword bidir.toserver or tweaking flow: toserver(or something else) in the case of a bidirectional signature with direction-ambiguous keywords ?

Copy link

codecov bot commented Feb 21, 2025

Codecov Report

Attention: Patch coverage is 76.96335% with 44 lines in your changes missing coverage. Please review.

Project coverage is 80.75%. Comparing base (3bc2a14) to head (454c31d).

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #12646      +/-   ##
==========================================
- Coverage   80.77%   80.75%   -0.03%     
==========================================
  Files         932      932              
  Lines      259517   259699     +182     
==========================================
+ Hits       209629   209707      +78     
- Misses      49888    49992     +104     
Flag Coverage Δ
fuzzcorpus 56.98% <40.31%> (-0.01%) ⬇️
livemode 19.35% <10.47%> (-0.03%) ⬇️
pcap 44.14% <27.22%> (-0.02%) ⬇️
suricata-verify 63.48% <75.39%> (-0.03%) ⬇️
unittests 58.30% <31.41%> (-0.03%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

@catenacyber
Copy link
Contributor Author

Red CI because needs #12647

@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 24858

Ticket: 5665

This is done with `alert ip any any => any any`
The => operator means that we will need both directions
@catenacyber catenacyber force-pushed the detect-bidir-5665-v21 branch from 62192fc to 454c31d Compare February 23, 2025 20:18
@catenacyber
Copy link
Contributor Author

Rebased to get green CI

@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 24870

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants