Merge in SNORT/snort3 from ~JALIIMRA/snort3:sfcn_zw_block to master
Squashed commit of the following:
commit
f9831f17611dfbed4c4ff20717272e7ab26c66f9
Author: Juweria Ali Imran <jaliimra@cisco.com>
Date: Mon Sep 4 14:30:19 2023 -0400
stream_tcp: ensure all data segments after a zero window are blocked when NAP is inline
}
else
{
- listener->normalizer.trim_win_payload(tsd);
+ bool force = (tsd.is_nap_policy_inline() && listener->get_iss());
+ listener->normalizer.trim_win_payload(tsd, 0, force);
return STREAM_UNALIGNED;
}
}
if (tsd.get_len() == ZERO_WIN_PROBE_LEN)
tcpStats.zero_win_probes++;
- listener->normalizer.trim_win_payload(tsd);
+ bool force = (tsd.is_nap_policy_inline() && listener->get_iss());
+ listener->normalizer.trim_win_payload(tsd, 0, force);
return STREAM_UNALIGNED;
}
if ( tsd.is_data_segment() )