New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Backports 5.0.x V2 Batched backports of several issues #4723
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This function returns the individual components of the timeval in output pointers making it suitable for use over Rust FFI.
After a GAP all normal transactions are closed. File transactions are left open as they can handle GAPs in principle. However, the GAP might have contained the closing of a file and therefore it may remain active until the end of the flow. This patch introduces a time based heuristic for these transactions. After the GAP all file transactions are stamped with the current timestamp. If 60 seconds later a file has seen no update, its marked as closed. This is meant to fix resource starvation issues observed in long running SMB sessions where packet loss was causing GAPs.
(cherry picked from commit f05c12b)
Using the run-as configuration option with the nflog capture method results in the following error during the startup of suricata: [ERRCODE: SC_ERR_NFLOG_BIND(248)] - nflog_bind_pf() for AF_INET failed This is because SCDropMainThreadCaps does not have any capabilities defined for the nflog runmode (unlike other runmodes). Therefore, apply the same capabilities to the nflog runmode that are already defined for the nfqueue runmode. This has been confirmed to allow suricata start and drop its privileges in the nflog runmode. Fixes redmine issue OISF#3265. Signed-off-by: Timo Sigurdsson <public_timo.s@silentcreek.de> (cherry picked from commit 1262ecb)
Close all prior transactions in the direction of the GAP, except the file xfers. Those use their own logic described below. After a GAP all normal transactions are closed. File transactions are left open as they can handle GAPs in principle. However, the GAP might have contained the closing of a file and therefore it may remain active until the end of the flow. This patch introduces a time based heuristic for these transactions. After the GAP all file transactions are stamped with the current timestamp. If 60 seconds later a file has seen no update, its marked as closed. This is meant to fix resource starvation issues observed in long running SMB sessions where packet loss was causing GAPs. Due to the similarity of the NFS and SMB parsers, this issue is fixed for NFS as well in this patch. Bug OISF#3424. Bug OISF#3425. (cherry picked from commit f68c255)
Fix function CheckOverlap bug. (cherry picked from commit 2456f27)
When a TCP DNS flow would start with a GAP on the TS side, the successful protocol detection on the TC side would trigger 'opposing side' reassembly and app-layer processing. In this case the stream flags would indicate the wrong direction and the wrong parser would be called. (cherry picked from commit efee458)
Suricata generates an error on unrecognised ERF types. Suricata should ignore ERF 'Provenance' records with ERF_TYPE_META. (cherry picked from commit 47082dd)
This commit places restrictions on the length of the file name specified in attachments (`name=` or `filename=`) to `NAME_MAX`. Names exceeding these limits will be truncated and processing will continue with the truncated name. (cherry picked from commit d0d20bd)
(cherry picked from commit 130b8d2)
(cherry picked from commit 9a33b5d)
(cherry picked from commit c92975e)
(cherry picked from commit bcea730)
(cherry picked from commit 6d94b09)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit 6c35039)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit 9fe51a8)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit c2071e1)
Corrects misplaced backticks preventing proper formatting of `mpm-algo` section. (cherry picked from commit 8c132c0)
For the backport, ERSPAN TypeI decode is 1. Disabled by default 2. Configurable: `decoder.erspan_typeI.enabled` (cherry picked from commit ae6beed)
Switch to isspace() as well. (cherry picked from commit 52970d8)
(cherry picked from commit 0715e13)
This commit removes documentation for the never-implemented bitmask option for the `byte_jump` and `byte_test` keywords.
jlucovsky
requested review from
jasonish,
norg,
victorjulien and
a team
as code owners
March 24, 2020 11:32
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
TEST: This PR includes use of v2 of the github checkouts action for centos-8 only.
Continuation of #4620, #4625, #4635, #4658, #4694, #4703
Backports of: