]> git.ipfire.org Git - thirdparty/suricata.git/log
thirdparty/suricata.git
8 years agoqa: add -Wshadow to appveyor builds 2433/head
Victor Julien [Mon, 28 Nov 2016 13:40:20 +0000 (14:40 +0100)] 
qa: add -Wshadow to appveyor builds

8 years agoproto detect: fix -Wshadow warning 2432/head
Victor Julien [Mon, 28 Nov 2016 12:03:34 +0000 (13:03 +0100)] 
proto detect: fix -Wshadow warning

8 years agodcerpc: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 11:54:16 +0000 (12:54 +0100)] 
dcerpc: fix -Wshadow warnings

8 years agocommandline: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 11:51:52 +0000 (12:51 +0100)] 
commandline: fix -Wshadow warnings

8 years agodetect-address: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 11:36:41 +0000 (12:36 +0100)] 
detect-address: fix -Wshadow warnings

8 years agoasn1: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 11:36:26 +0000 (12:36 +0100)] 
asn1: fix -Wshadow warnings

8 years agoasn1: modernize test
Victor Julien [Mon, 28 Nov 2016 11:24:35 +0000 (12:24 +0100)] 
asn1: modernize test

8 years agoyaml: fix tests for -Wshadow
Victor Julien [Mon, 28 Nov 2016 11:24:19 +0000 (12:24 +0100)] 
yaml: fix tests for -Wshadow

8 years agodnp3: fix test for -Wshadow
Victor Julien [Mon, 28 Nov 2016 11:24:03 +0000 (12:24 +0100)] 
dnp3: fix test for -Wshadow

8 years agorunmodes: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:29:25 +0000 (10:29 +0100)] 
runmodes: fix -Wshadow warnings

8 years agompm ac-bs: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:27:34 +0000 (10:27 +0100)] 
mpm ac-bs: fix -Wshadow warnings

8 years agothreads: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:27:18 +0000 (10:27 +0100)] 
threads: fix -Wshadow warnings

8 years agocommandline: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:21:53 +0000 (10:21 +0100)] 
commandline: fix -Wshadow warnings

8 years agonfq: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:18:03 +0000 (10:18 +0100)] 
nfq: fix -Wshadow warnings

Rename globals to make sure it's clear they are globals.

8 years agoreputation: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:11:44 +0000 (10:11 +0100)] 
reputation: fix -Wshadow warnings

8 years agoeve-flow: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:10:40 +0000 (10:10 +0100)] 
eve-flow: fix -Wshadow warning

8 years agoeve-file: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:09:16 +0000 (10:09 +0100)] 
eve-file: fix -Wshadow warnings

8 years agoippair: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:07:39 +0000 (10:07 +0100)] 
ippair: fix -Wshadow warning

8 years agohost: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:07:25 +0000 (10:07 +0100)] 
host: fix -Wshadow warning

8 years agoflow: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:07:09 +0000 (10:07 +0100)] 
flow: fix -Wshadow warning

8 years agowithin: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:06:42 +0000 (10:06 +0100)] 
within: fix -Wshadow warning

8 years agoprefilter: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 09:05:51 +0000 (10:05 +0100)] 
prefilter: fix -Wshadow warnings

8 years agodetect: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:04:25 +0000 (10:04 +0100)] 
detect: fix -Wshadow warning

8 years agoapp engines: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:03:11 +0000 (10:03 +0100)] 
app engines: fix -Wshadow warning

8 years agoaddress: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:01:52 +0000 (10:01 +0100)] 
address: fix -Wshadow warning

8 years agodistance: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 09:00:35 +0000 (10:00 +0100)] 
distance: fix -Wshadow warning

8 years agocontent: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 08:59:05 +0000 (09:59 +0100)] 
content: fix -Wshadow warning

8 years agomem: fix SCStrdup -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 08:58:44 +0000 (09:58 +0100)] 
mem: fix SCStrdup -Wshadow warning

8 years agodns: fix -Wshadow warnings
Victor Julien [Mon, 28 Nov 2016 08:55:17 +0000 (09:55 +0100)] 
dns: fix -Wshadow warnings

8 years agoapp-layer-proto-detect: fix -Wshadow warning
Victor Julien [Mon, 28 Nov 2016 08:48:22 +0000 (09:48 +0100)] 
app-layer-proto-detect: fix -Wshadow warning

8 years agodnp3: fix coverity CID 1374300
Victor Julien [Mon, 28 Nov 2016 08:44:23 +0000 (09:44 +0100)] 
dnp3: fix coverity CID 1374300

8 years agoflow: suppress coverity CID 400600
Victor Julien [Mon, 28 Nov 2016 12:53:57 +0000 (13:53 +0100)] 
flow: suppress coverity CID 400600

8 years agostat: suppress CID 1293508 and 1312013
Victor Julien [Mon, 28 Nov 2016 08:39:02 +0000 (09:39 +0100)] 
stat: suppress CID 1293508 and 1312013

8 years agonfq: suppress CID 1374302 and 1374303
Victor Julien [Mon, 28 Nov 2016 08:34:43 +0000 (09:34 +0100)] 
nfq: suppress CID 1374302 and 1374303

8 years agohost-info: coverity 1298890
Victor Julien [Mon, 28 Nov 2016 08:20:01 +0000 (09:20 +0100)] 
host-info: coverity 1298890

8 years agottl: coverity 400560 + minor cleanups
Victor Julien [Mon, 28 Nov 2016 08:16:05 +0000 (09:16 +0100)] 
ttl: coverity 400560 + minor cleanups

8 years agotos: coverity 400559
Victor Julien [Mon, 28 Nov 2016 08:12:23 +0000 (09:12 +0100)] 
tos: coverity 400559

8 years agossl-state: coverity 400558
Victor Julien [Mon, 28 Nov 2016 08:11:42 +0000 (09:11 +0100)] 
ssl-state: coverity 400558

8 years agoissue 1961: depth: fail if numeric value has trailing text
Jason Ish [Thu, 24 Nov 2016 17:21:48 +0000 (11:21 -0600)] 
issue 1961: depth: fail if numeric value has trailing text

Catches the case where the depth is not terminated with a
semicolon (eg: "depth:17 classtype:trojan-activity") which
is usually a sign the rule has a missing semi-colon.

8 years agolog-pcap.c: cleanup scan-build warning
Jason Ish [Thu, 24 Nov 2016 16:59:15 +0000 (10:59 -0600)] 
log-pcap.c: cleanup scan-build warning

Don't initialize value to a value that is never used.

8 years agolog-pcap.c: fix resource leak found by coverity
Jason Ish [Thu, 24 Nov 2016 16:36:27 +0000 (10:36 -0600)] 
log-pcap.c: fix resource leak found by coverity

Goto the failure label instead of returning which will allow the open
directory to get cleaned up.

Fixes:

*** CID 1394675:  Resource leaks  (RESOURCE_LEAK)
/src/log-pcap.c: 615 in PcapLogInitRingBuffer()
609                  * failure as the file might just not be a pcap log file. */
610                 continue;
611             }
612
613             PcapFileName *pf = SCCalloc(sizeof(*pf), 1);
614             if (unlikely(pf == NULL)) {
>>>     CID 1394675:  Resource leaks  (RESOURCE_LEAK)
>>>     Variable "dir" going out of scope leaks the storage it points to.
615                 return TM_ECODE_FAILED;
616             }
617             char path[PATH_MAX];
618             snprintf(path, PATH_MAX - 1, "%s/%s", pattern, entry->d_name);
619             if ((pf->filename = SCStrdup(path)) == NULL) {
620                 goto fail;

This also means that pf can be NULL which should clear up CID
1394676 (REVERSE_INULL).

8 years agodoc: document that that ;, \, " need to be escaped in rules
Jason Ish [Wed, 23 Nov 2016 21:59:28 +0000 (15:59 -0600)] 
doc: document that that ;, \, " need to be escaped in rules

8 years agoqa: appveyor support 2421/head
Victor Julien [Wed, 23 Nov 2016 14:27:28 +0000 (15:27 +0100)] 
qa: appveyor support

8 years agoqa: update url in libhtp script
Victor Julien [Thu, 24 Nov 2016 12:31:05 +0000 (13:31 +0100)] 
qa: update url in libhtp script

8 years agopcap-log: seed ring buffer on start up 2414/head
Jason Ish [Sat, 24 Sep 2016 02:46:06 +0000 (20:46 -0600)] 
pcap-log: seed ring buffer on start up

On start, look for existing pcap log files and add them to
the ring buffer. This makes pcap-log self maintaining over
restarts removing the need for external tools to clear
orphaned files.

8 years agodocumentation: fix list keywords URLs
Eric Leblond [Wed, 9 Nov 2016 19:08:07 +0000 (14:08 -0500)] 
documentation: fix list keywords URLs

Update URLs in keyword definition to point to sphinx documentation.

8 years agologging: hook the application log file into rotation
Jason Ish [Tue, 8 Nov 2016 17:02:23 +0000 (12:02 -0500)] 
logging: hook the application log file into rotation

8 years agologging: open application log file in append mode
Jason Ish [Tue, 8 Nov 2016 15:13:01 +0000 (10:13 -0500)] 
logging: open application log file in append mode

It was being open in read/write mode, which was likely
a mistake with append mode being the intention.

8 years agodns: accept a data length of 0 without marking as malformed
Jason Ish [Mon, 7 Nov 2016 15:46:45 +0000 (10:46 -0500)] 
dns: accept a data length of 0 without marking as malformed

Addresses issue:
https://redmine.openinfosecfoundation.org/issues/1924

8 years agodns-events: fix direction of malformed events + typo
Jason Ish [Mon, 7 Nov 2016 15:02:18 +0000 (10:02 -0500)] 
dns-events: fix direction of malformed events + typo

8 years agoipfw: disable more code to suppress compiler warnings
Jason Ish [Mon, 21 Nov 2016 16:24:17 +0000 (10:24 -0600)] 
ipfw: disable more code to suppress compiler warnings

Disabled code lead to unused variable warnings, so disable the
variable code as well.

8 years agocompiler warnings: fix compiler warnings in format strings
Jason Ish [Mon, 21 Nov 2016 16:16:14 +0000 (10:16 -0600)] 
compiler warnings: fix compiler warnings in format strings

8 years agodetect-lua: unify on using 'lua' name vs 'luajit'
Victor Julien [Fri, 18 Nov 2016 10:18:57 +0000 (11:18 +0100)] 
detect-lua: unify on using 'lua' name vs 'luajit'

8 years agoluajit: remove unused instance counter
Victor Julien [Fri, 18 Nov 2016 10:18:33 +0000 (11:18 +0100)] 
luajit: remove unused instance counter

8 years agoluajit: update default yaml and doc for 'states'
Victor Julien [Thu, 17 Nov 2016 13:27:41 +0000 (14:27 +0100)] 
luajit: update default yaml and doc for 'states'

8 years agolua: luajit improvements
Victor Julien [Thu, 17 Nov 2016 07:54:44 +0000 (08:54 +0100)] 
lua: luajit improvements

Luajit has a strange memory requirement, it's 'states' need to be in the
first 2G of the process' memory.

This patch improves the pool approach by moving it to the front of the
start up.

A new config option 'luajit.states' is added to control how many states
are preallocated. It defaults to 128.

Add a warning when more states are used then preallocated. This may fail
if flow/stream/detect engines use a lot of memory. Add hint at exit that
gives the max states in use if it's higher than the default.

8 years agodoc: only build pdf on dist if pdflatex is installed
Jason Ish [Fri, 18 Nov 2016 17:50:02 +0000 (11:50 -0600)] 
doc: only build pdf on dist if pdflatex is installed

8 years agodoc: fix build pdf on non gnu make platforms
Jason Ish [Fri, 18 Nov 2016 17:41:11 +0000 (11:41 -0600)] 
doc: fix build pdf on non gnu make platforms

The Makefile generated by sphinx-build is GNU Make specific
causing the PDF phase to fail. Instead call pdflatex directly
based on how the generated Makefile was doing it.

8 years agopcap-file: minor cleanup
Victor Julien [Wed, 23 Nov 2016 09:35:42 +0000 (10:35 +0100)] 
pcap-file: minor cleanup

8 years agochangelog: update for 3.2RC1 release suricata-3.2RC1
Victor Julien [Tue, 1 Nov 2016 12:11:18 +0000 (13:11 +0100)] 
changelog: update for 3.2RC1 release

8 years agoyaml: group ICS protocols together 2393/head
Victor Julien [Mon, 31 Oct 2016 13:11:57 +0000 (14:11 +0100)] 
yaml: group ICS protocols together

8 years agoENIP: add default ports to yaml
Victor Julien [Mon, 31 Oct 2016 13:10:53 +0000 (14:10 +0100)] 
ENIP: add default ports to yaml

8 years agoENIP: disable parser if no config found
Victor Julien [Mon, 31 Oct 2016 12:41:46 +0000 (13:41 +0100)] 
ENIP: disable parser if no config found

8 years agoDNP3: disable in case of no dnp3 config
Victor Julien [Mon, 31 Oct 2016 12:40:19 +0000 (13:40 +0100)] 
DNP3: disable in case of no dnp3 config

8 years agoreadme: Fix markdown header levels
Priit Laes [Thu, 27 Oct 2016 11:41:00 +0000 (14:41 +0300)] 
readme: Fix markdown header levels

8 years agoreadme: reformat some key points about possible security issues
Priit Laes [Thu, 27 Oct 2016 11:38:28 +0000 (14:38 +0300)] 
readme: reformat some key points about possible security issues

8 years agoreadme: Add link to up-to-date user guide and mark wiki as deprecated.
Priit Laes [Thu, 27 Oct 2016 11:37:56 +0000 (14:37 +0300)] 
readme: Add link to up-to-date user guide and mark wiki as deprecated.

8 years agodnp3: fix coverity checks; return value not checked
Jason Ish [Thu, 27 Oct 2016 17:19:05 +0000 (11:19 -0600)] 
dnp3: fix coverity checks; return value not checked

8 years agodetect: add missing break (CID 1374301)
Victor Julien [Mon, 31 Oct 2016 10:30:26 +0000 (11:30 +0100)] 
detect: add missing break (CID 1374301)

8 years agoeve: make payload printing in alerts more robust
Victor Julien [Mon, 31 Oct 2016 10:14:41 +0000 (11:14 +0100)] 
eve: make payload printing in alerts more robust

8 years agoflowint: allow / in name
Victor Julien [Fri, 28 Oct 2016 10:23:23 +0000 (12:23 +0200)] 
flowint: allow / in name

8 years agohostbits: test fixes
Victor Julien [Tue, 25 Oct 2016 19:15:44 +0000 (21:15 +0200)] 
hostbits: test fixes

8 years agopkt-var: const name
Victor Julien [Thu, 27 Oct 2016 12:56:21 +0000 (14:56 +0200)] 
pkt-var: const name

8 years agoDNP3: minor cleanup 2391/head
Victor Julien [Thu, 27 Oct 2016 09:55:28 +0000 (11:55 +0200)] 
DNP3: minor cleanup

8 years agoDNP3: don't leak memory on dnp3_obj parsing
Victor Julien [Thu, 27 Oct 2016 09:55:17 +0000 (11:55 +0200)] 
DNP3: don't leak memory on dnp3_obj parsing

8 years agoDNP3: Use directional logging.
Jason Ish [Wed, 13 Jul 2016 15:04:15 +0000 (09:04 -0600)] 
DNP3: Use directional logging.

Instead of waiting for a transaction complete, log the
request as soon as it is completes which will give it a
more accurate timestamp.

8 years agoDNP3: --afl-dnp3 entry point
Jason Ish [Fri, 15 Apr 2016 22:49:28 +0000 (16:49 -0600)] 
DNP3: --afl-dnp3 entry point

8 years agoDNP3: Lua detect support.
Jason Ish [Thu, 10 Dec 2015 17:59:48 +0000 (11:59 -0600)] 
DNP3: Lua detect support.

Adds support for access the DNP3 transaction in Lua rules.

8 years agoDNP3: Log DNP3 info with DNP3 alert.
Jason Ish [Mon, 28 Sep 2015 22:33:48 +0000 (16:33 -0600)] 
DNP3: Log DNP3 info with DNP3 alert.

8 years agoDNP3: Log DNP3 transactions.
Jason Ish [Thu, 7 May 2015 17:53:39 +0000 (11:53 -0600)] 
DNP3: Log DNP3 transactions.

8 years agoDNP3: dnp3_data, dnp3_func, dnp3_ind, dnp3_obj rule keywords
Jason Ish [Fri, 10 Apr 2015 16:22:25 +0000 (10:22 -0600)] 
DNP3: dnp3_data, dnp3_func, dnp3_ind, dnp3_obj rule keywords

8 years agoDNP3: Application layer decoder.
Jason Ish [Fri, 10 Apr 2015 15:33:20 +0000 (09:33 -0600)] 
DNP3: Application layer decoder.

Decodes TCP DNP3 and raises some DNP3 decoder alerts.

8 years agoDNP3: dnp3-gen: code generator for repetitive DNP3 code
Jason Ish [Mon, 8 Feb 2016 21:16:01 +0000 (15:16 -0600)] 
DNP3: dnp3-gen: code generator for repetitive DNP3 code

8 years agocommon: define json_boolean when not defined
Jason Ish [Mon, 25 Apr 2016 06:17:58 +0000 (00:17 -0600)] 
common: define json_boolean when not defined

Older versions of jansson in current use don't have this
macro defined.

8 years agoeve: check redis reply in non pipeline mode
fooinha [Mon, 24 Oct 2016 15:52:06 +0000 (15:52 +0000)] 
eve: check redis reply in non pipeline mode

We may lose the reply if disconnection happens.
Reconnection is needed.

8 years agoflowvar: cleanups
Victor Julien [Wed, 26 Oct 2016 14:19:13 +0000 (16:19 +0200)] 
flowvar: cleanups

8 years agofast-pattern: fix tls_sni
Jason Ish [Wed, 26 Oct 2016 21:34:43 +0000 (15:34 -0600)] 
fast-pattern: fix tls_sni

Use all 38 arguments in call to SigMatchGetLastSMFromLists

Was preventing fast_pattern from being applied to tls_sni:
https://redmine.openinfosecfoundation.org/issues/1936

8 years agodns: use new unittest macros 2386/head
Jason Ish [Tue, 25 Oct 2016 20:56:09 +0000 (14:56 -0600)] 
dns: use new unittest macros

8 years agodns: support back to back requests without a response
Jason Ish [Tue, 25 Oct 2016 06:13:07 +0000 (00:13 -0600)] 
dns: support back to back requests without a response

Address the issue where a DNS response would not be logged when
the traffic is like:
- Request 1
- Request 2
- Response 1
- Response 2
which can happen on dual stack machines where the request for A
and AAAA are sent out at the same time on the same UDP "session".

A "window" is used to set the maximum number of outstanding
responses before considering the olders lost.

8 years agotcp dns: unit test for multi-request buffer
Jason Ish [Wed, 26 Oct 2016 15:48:42 +0000 (09:48 -0600)] 
tcp dns: unit test for multi-request buffer

8 years agotcp dns: fix advancement to next request in buffer
Jason Ish [Tue, 25 Oct 2016 20:13:31 +0000 (14:13 -0600)] 
tcp dns: fix advancement to next request in buffer

The advancement through the buffer was not taking into account
the size of the length field resulting in the second request
being detected as bad data.

8 years agomulti-tenant: make less verbose 2384/head
Victor Julien [Wed, 26 Oct 2016 08:33:55 +0000 (10:33 +0200)] 
multi-tenant: make less verbose

8 years agomulti-tenants: fix minor memleak
Victor Julien [Tue, 25 Oct 2016 18:58:53 +0000 (20:58 +0200)] 
multi-tenants: fix minor memleak

8 years agodetect: suppress debug message for reloads
Victor Julien [Wed, 26 Oct 2016 08:34:28 +0000 (10:34 +0200)] 
detect: suppress debug message for reloads

8 years agovars: small cleanups
Victor Julien [Thu, 20 Oct 2016 12:21:53 +0000 (14:21 +0200)] 
vars: small cleanups

8 years agonfq: support bypass for rebuilt fragment packets 2383/head
Victor Julien [Tue, 25 Oct 2016 12:31:41 +0000 (14:31 +0200)] 
nfq: support bypass for rebuilt fragment packets

8 years agonfq_set_mask: set mark on root pkt for tunnels
Victor Julien [Tue, 25 Oct 2016 12:25:55 +0000 (14:25 +0200)] 
nfq_set_mask: set mark on root pkt for tunnels

8 years agosource-nfq: document bypass function
Eric Leblond [Wed, 19 Oct 2016 20:05:25 +0000 (22:05 +0200)] 
source-nfq: document bypass function

8 years agosource-nfq: fix tunnel mark callback algorithm
Eric Leblond [Wed, 12 Oct 2016 20:18:12 +0000 (22:18 +0200)] 
source-nfq: fix tunnel mark callback algorithm

In case of a tunnel packet, adding a mark to the root packet will have
for consequence to bypass all the flows that are hosted in this tunnel.
This is not the attended behavior and as initial fix let's simply warn
suricata that bypass for NFQ is not possible for this kind of packets.

This patch also fixes a segfault. The root packet was accessed even if it is
NULL causing a NULL dereference:

ASAN:SIGSEGV
=================================================================
==24408==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000060 (pc 0x00000076f948 bp 0x7f435c000240 sp 0x7f435c000220 T5)
ASAN:SIGSEGV
==24408==AddressSanitizer: while reporting a bug found another one. Ignoring.
    #0 0x76f947 in NFQBypassCallback /home/victor/dev/suricata/src/source-nfq.c:510
    #1 0x4d0f02 in PacketBypassCallback /home/victor/dev/suricata/src/decode.c:395
    #2 0x7b8a95 in StreamTcpPacket /home/victor/dev/suricata/src/stream-tcp.c:4661
    #3 0x7b9ddd in StreamTcp /home/victor/dev/suricata/src/stream-tcp.c:4913
    #4 0x68fa50 in FlowWorker /home/victor/dev/suricata/src/flow-worker.c:194
    #5 0x7f0abd in TmThreadsSlotVarRun /home/victor/dev/suricata/src/tm-threads.c:128
    #6 0x7f2958 in TmThreadsSlotVar /home/victor/dev/suricata/src/tm-threads.c:585
    #7 0x7f436368e6f9 in start_thread (/lib/x86_64-linux-gnu/libpthread.so.0+0x76f9)
    #8 0x7f4362802b5c in clone (/lib/x86_64-linux-gnu/libc.so.6+0x106b5c)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /home/victor/dev/suricata/src/source-nfq.c:510 NFQBypassCallback
Thread T5 (W#04) created by T0 (Suricata-Main) here:
    #0 0x7f4364ff2253 in pthread_create (/usr/lib/x86_64-linux-gnu/libasan.so.2+0x36253)
    #1 0x7f9c48 in TmThreadSpawn /home/victor/dev/suricata/src/tm-threads.c:1843
    #2 0x8da7c0 in RunModeSetIPSAutoFp /home/victor/dev/suricata/src/util-runmodes.c:519
    #3 0x73e3ff in RunModeIpsNFQAutoFp /home/victor/dev/suricata/src/runmode-nfq.c:74
    #4 0x7503fa in RunModeDispatch /home/victor/dev/suricata/src/runmodes.c:382
    #5 0x7e5cb3 in main /home/victor/dev/suricata/src/suricata.c:2547
    #6 0x7f436271c82f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)

8 years agotls-rules: install on 'make install-full' 2381/head
Victor Julien [Tue, 25 Oct 2016 06:58:32 +0000 (08:58 +0200)] 
tls-rules: install on 'make install-full'