Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

exception/policy: use pkt action if no flow support (60x backports) - v1 #8646

Merged

Conversation

jufajardini
Copy link
Contributor

#8631

backports

ink to redmine ticket:
https://redmine.openinfosecfoundation.org/issues/5942

suricata-verify-pr: 1155

Defrag memcap and flow memcap do not support flow action for the
exception policies, as there is no flow when the exception condition is
hit. In such cases, the exception policy must be considered for the
packet only, when that makes sense, or should be ignored, in case of
`bypass`.

Bug OISF#5940

(cherry picked from commit d4333fb)
As flow.memcap-policy and defrag.memcap-policy do not support flow
actions, clarify that in the documentation. Also fix some typos, and
add missing values in some places where the exception policies were
explained.

Related to
Bug OISF#5940

(cherry picked from commit 31066c7)
@jufajardini jufajardini requested review from norg and a team as code owners March 29, 2023 14:54
@suricata-qa
Copy link

Information:

ERROR: QA failed on SURI_TLPW1_files_sha256.

field baseline test %
SURI_TLPW1_stats_chk
.tcp.overlap 23728 32191 135.67%

Pipeline 12908

@victorjulien victorjulien merged commit 35b2756 into OISF:master-6.0.x Mar 30, 2023
22 checks passed
@jufajardini jufajardini deleted the 60x-backports-eps-flow-action/v1 branch March 30, 2023 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants