detect/proto: check ipproto enabled setting first#14754
Open
detect/proto: check ipproto enabled setting first#14754
Conversation
4d34b7f to
907d397
Compare
So far, suricata.yaml was probed by default for `app-layer.protocols.PROTOCOL.enabled`. If this was not found, then, an attempt was made to look for `app-layer.protocols.PROTOCOL.IPPROTO.enabled`. This is not ideal behavior and restricts user to explicitly disable a carrier proto specific protocol. By default, check for carrier proto specific setting. If it is not found, then fall back to the generic setting. Issue a warning in case an inconsistent combination of global and ipproto specific setting is found. Bug 8205
907d397 to
c1c8d71
Compare
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #14754 +/- ##
=======================================
Coverage 82.15% 82.16%
=======================================
Files 1003 1003
Lines 263643 263664 +21
=======================================
+ Hits 216586 216627 +41
+ Misses 47057 47037 -20
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
Information: QA ran without warnings. Pipeline = 29448 |
catenacyber
reviewed
Feb 5, 2026
| SCLogError("Invalid value found for %s.", param); | ||
| exit(EXIT_FAILURE); | ||
| if ((i_proto && g_proto) && (i_enabled ^ g_enabled)) { | ||
| /* these checks are also performed by app-layer-parser, no need to issue double warning */ |
Contributor
There was a problem hiding this comment.
These checks are not performed by app-layer-parser if this is detection-only, so the warning should happen here, right ?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previous PR: #14743
Link to ticket: https://redmine.openinfosecfoundation.org/issues/8205
Changes since v5:
detection-onlyin applayer parserSV_BRANCH=OISF/suricata-verify#2893