]>
git.ipfire.org Git - thirdparty/snort3.git/log
Priyanka Bangalore Gurudev (prbg) [Tue, 1 Jul 2025 17:20:33 +0000 (17:20 +0000)]
Pull request #4792: build: generate and tag 3.9.1.0
Merge in SNORT/snort3 from ~PRBG/snort3:build_3.9.1.0 to master
Squashed commit of the following:
commit
3fd3bfd2a978c0995229d023f45d2f16fdc33802
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Sun Jun 29 23:15:14 2025 -0400
build: generate and tag 3.9.1.0
Pull request #4781: ssl: fix integer underflow in certificate parsing
Merge in SNORT/snort3 from ~BHRYNIV/snort3:ssl_underflow_fix to master
Squashed commit of the following:
commit
bc9af6fa1edf78e998f5ea9b8259b7c9c892e08b
Author: Bohdan Hryniv <bhryniv@cisco>
Date: Fri Jun 20 08:38:08 2025 -0400
ssl: fix integer underflow in certificate parsing
Adrian Mamolea (admamole) [Wed, 25 Jun 2025 17:46:35 +0000 (17:46 +0000)]
Pull request #4765: http_inspect: add support for partial_depth configuration option
Merge in SNORT/snort3 from ~ADMAMOLE/snort3:cl to master
Squashed commit of the following:
commit
3e9cdd52035184e38416581e4d5ffb6fd4df0bd1
Author: Adrian Mamolea <admamole@cisco.com>
Date: Fri May 23 15:48:16 2025 -0400
http_inspect: add support for partial_depth configuration option
Pull request #4780: appid: appid_debug_test fix
Merge in SNORT/snort3 from ~DKOLOMII/snort3:appid_debug_test_fix to master
Squashed commit of the following:
commit
9c69c77176fe2aa6334e424617636d319d72f54c
Author: Daniil Kolomiiets <dkolomii@cisco.com>
Date: Mon Jun 23 10:50:07 2025 -0400
appid: appid_debug_test and critical log fix
Pull request #4778: extractor: add context logging event for notice
Merge in SNORT/snort3 from ~ANOROKH/snort3:extr_notice_event to master
Squashed commit of the following:
commit
da9709af1b8edb7090a783471a78181ad880af28
Author: anorokh <anorokh@cisco.com>
Date: Tue Jun 10 12:59:25 2025 +0300
extractor: add context logging event for notice
Pull request #4767: Extractor Buffered Printout
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:ring2 to master
Squashed commit of the following:
commit
180fa2a60a25000ed386dafd98db053c018a1630
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Jun 18 12:13:52 2025 +0300
connectors: set affinity for flusher thread
commit
e8ab7c14455dd9678fc5cce5e4f1a43e544a3604
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Mon Jun 16 12:44:27 2025 +0300
connectors: give name to flusher thread
commit
ba153a5662ae767d68c06d98a2b4a870965d4758
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Tue May 27 18:23:44 2025 +0300
extractor: add benchmark tests
commit
1b990e23946fd36b21035f92c8c7d8c16562102e
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed May 14 16:50:37 2025 +0300
connectors: add redirect option to print to a file
commit
9860640b438d9741480382958d6ed2c2207ab271
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Tue May 13 17:41:49 2025 +0300
connectors: rename text log field
commit
bd4f4cd4d5a6b34b1eff92d53f5238bde30b494e
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed May 7 18:01:49 2025 +0300
connectors: rebuild readers as they might be outdated at exit
commit
74b8a422ba86c8b76c6a83ef396558a497d3fe7e
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed May 7 17:26:17 2025 +0300
connectors: guarantee writes for std connector
commit
d268bc8b55171a6d7dfd3cd9499f84cb0aff8caa
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Fri Apr 25 18:01:56 2025 +0300
connectors: add buffered output to std_connector
New buffer_size option in std_connector.
commit
86e30b13424263c4c29c98e5bce06c0c0cc1c3a0
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Mon Apr 14 10:45:01 2025 +0300
helpers: add 1-reader-1-writer ring buffer
Thread safe.
Supports variable record size.
Overflow on write drops the new record.
Benchmark tests added.
Umang Sharma (umasharm) [Mon, 23 Jun 2025 13:08:08 +0000 (13:08 +0000)]
Pull request #4775: appid: fixed stash issue by fixing publishing shadow traffic
Merge in SNORT/snort3 from ~UMASHARM/snort3:stash_fix_shadowtraffic to master
Squashed commit of the following:
commit
51998042ed5f314e18f32ebad0eb37638371cef2
Author: Umang Sharma <umasharm@cisco.com>
Date: Mon Jun 16 09:38:41 2025 -0400
appid: fixed stash issue by fixing publishing shadow traffic
Pull request #4779: unixdomain_connector: explicit include of select.h
Merge in SNORT/snort3 from ~OSTEPANO/snort3:alpine_header to master
Squashed commit of the following:
commit
120e4dce6c9d2f340462a48c32b75844bd195167
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Wed Jun 18 07:24:19 2025 -0400
unixdomain_connector: explicit include of select.h
Pull request #4764: appid: fix APPID_LOG macro for correct usage of log_level
Merge in SNORT/snort3 from ~DKOLOMII/snort3:APPID_LOG_macro_fix to master
Squashed commit of the following:
commit
09023c0f0cb9cc0b625fde8236b0067369a55702
Author: Daniil Kolomiiets <dkolomii@cisco.com>
Date: Mon Jun 16 04:41:20 2025 -0400
appid: fixed APPID_LOG macro for correct usage of log_level
Wei Wang (weiwa) [Tue, 17 Jun 2025 13:36:03 +0000 (13:36 +0000)]
Pull request #4776: dns: handle multi DNS transactions one TCP connection
Merge in SNORT/snort3 from ~WEIWA/snort3:weiwa-master-dns-tcp-multi-tx to master
Squashed commit of the following:
commit
4cf7e30aa9a06bed678b723eeeb645a73d851b2c
Author: Wei Wang <weiwa@cisco.com>
Date: Tue Jun 17 03:21:13 2025 +0530
dns: handle multi DNS transactions one TCP connection
Pull request #4739: appid: sync flow service on protocol based detection
Merge in SNORT/snort3 from ~OSTEPANO/snort3:proto_detection_sync to master
Squashed commit of the following:
commit
727b13d446aa485de0d0f6b5fc4016b065a8fa3c
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Wed Apr 16 06:22:46 2025 -0400
appid: sync flow service with protocol based detection
Ashik Thomas (ashiktho) [Fri, 13 Jun 2025 06:14:18 +0000 (06:14 +0000)]
Pull request #4772: binder, flow, framework: add a facility to block binding based on a do_not_decrypt flow flag and inspector can_decrypt method
Merge in SNORT/snort3 from ~ASHIKTHO/snort3:CSCwo40673_tot_1 to master
Squashed commit of the following:
commit
61177c5e2c7690f33dca5b67dc0bb29dbeece64a
Author: bjandhya <bjandhya@cisco.com>
Date: Tue Mar 25 10:16:35 2025 -0400
binder, flow, framework: add a facility to block binding based on a do_not_decrypt flow flag and inspector can_decrypt method
Rishabh Choudhary (rishacho) [Mon, 9 Jun 2025 06:37:27 +0000 (06:37 +0000)]
Pull request #4770: profiler: add note for total percentage for profiler_dump
Merge in SNORT/snort3 from ~RISHACHO/snort3:cpu_profiler_warn_msg to master
Squashed commit of the following:
commit
d23e9ce41dae05647dab0221969e20399660a91e
Author: Rishabh Choudhary <rishacho@cisco.com>
Date: Thu Jun 5 15:01:01 2025 +0530
profiler: add note for total percentage for profiler_dump
Pull request #4747: mime: fix unfolding processing
Merge in SNORT/snort3 from ~OFATIEIE/snort3:mime_crlf_crash to master
Squashed commit of the following:
commit
a796d6bc8e41ed2b3ef78bba3888aba97c6d9859
Author: Oleksandr Fatieiev <ofatieie@cisco.com>
Date: Tue Jun 3 23:12:21 2025 +0300
mime: fix eol search and add unit tests
commit
61ba86bd99038a77174ae3a87b7ef6f426f08ede
Author: Oleksandr Fatieiev <ofatieie@cisco.com>
Date: Mon Jun 2 22:08:07 2025 +0300
mime: fix crash in folding right after colon
Pull request #4754: build: address coverity warnings
Merge in SNORT/snort3 from ~OFATIEIE/snort3:ips_rule_engine_coverity_fix to master
Squashed commit of the following:
commit
ea1a4897fd80585fc6ebf9b2c163f87f433ef39f
Author: Oleksandr Fatieiev <ofatieie@cisco.com>
Date: Tue May 20 17:55:38 2025 +0300
build: address coverity warnings
Andres Avila Segura (aavilase) [Wed, 4 Jun 2025 20:06:26 +0000 (20:06 +0000)]
Pull request #4731: appid: fix AppIdInspector hanging during tterm
Merge in SNORT/snort3 from ~AAVILASE/snort3:tp_fini_hanging_fix to master
Squashed commit of the following:
commit
5bab58a64439c65206c860a38e7d0bd13583a79d
Author: Andres Avila <aavilase@cisco.com>
Date: Tue Jun 3 16:49:19 2025 -0400
appid: broadcast command for third party tfini during tterm rather than doing it sequentially
Pull request #4766: helpers: fix JSON stream flags ater escaping
Merge in SNORT/snort3 from ~VHORBATO/snort3:json_escape_ios to master
Squashed commit of the following:
commit
4eb098766a157f0572e55be1195693ccea139df7
Author: vhorbato <vhorbato@cisco.com>
Date: Fri May 30 18:49:37 2025 +0300
helpers: fix JSON stream flags after escaping
Pull request #4757: mp_unix_transport: added reset stats handling
Merge in SNORT/snort3 from ~OSTEPANO/snort3:transport_opt to master
Squashed commit of the following:
commit
85abeddb909fee7f7107f6ff049004c5713840d6
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Mon May 12 05:50:44 2025 -0400
mp_unix_transport: use shared mutex in message processing
Andres Avila Segura (aavilase) [Tue, 3 Jun 2025 20:32:21 +0000 (20:32 +0000)]
Pull request #4735: appid: fix AppIdInspector hanging during tinit on startup and reload third party
Merge in SNORT/snort3 from ~AAVILASE/snort3:tp_tinit_hanging_fix to master
Squashed commit of the following:
commit
383d11a617737c3d1a9c29d9811cd530a393fb44
Author: Andres Avila <aavilase@cisco.com>
Date: Thu May 8 18:42:23 2025 -0400
appid: queue analyzer command for third party setup during appid id tinit and stagger packet threads during third party tinit
Pull request #4749: main: DAQ verdict changes
Merge in SNORT/snort3 from ~NIRMVENK/snort3:daq_verdict to master
Squashed commit of the following:
commit
a711df5547eb10f15e8ba654504824b962a1d7ec
Author: Nirmala Subbaiah <nirmvenk@cisco.com>
Date: Wed May 14 11:53:50 2025 -0400
main: clarify the DAQ verdict for inject
Ron Dempster (rdempste) [Sat, 31 May 2025 15:40:34 +0000 (15:40 +0000)]
Pull request #4743: appid: fix tcp dns multiple transaction support
Merge in SNORT/snort3 from ~RDEMPSTE/snort3:dns_logging to master
Squashed commit of the following:
commit
ee1088e727a5c83e68e05829bc082cddc9bbf45c
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Wed May 14 13:28:31 2025 -0400
appid: differentiate between request and response DNS host
commit
a8454a7feb16cf966ec3d00c30d984caffbe1f5e
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Fri May 9 09:27:02 2025 -0400
appid: fix tcp dns multiple transaction support
Pull request #4760: mp_unix_transport: refactored socket reconnect
Merge in SNORT/snort3 from ~OSTEPANO/snort3:transport_asan to master
Squashed commit of the following:
commit
e87ec546921a79a5e92e2c7dc59806768d1ea074
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Mon May 26 12:12:00 2025 -0400
mp_unix_transport: refactored socket reconnect
Pull request #4762: mp_dbus: transfer ownership of MPDataBus to new config during reload
Merge in SNORT/snort3 from ~OSTEPANO/snort3:transport_reload to master
Squashed commit of the following:
commit
e56c55c2eddeb7b41107f79ca5a78ce1e3c96a35
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Tue May 27 12:52:08 2025 -0400
mp_dbus: transfer ownership of MPDataBus to new config during reload
Priyanka Bangalore Gurudev (prbg) [Thu, 29 May 2025 00:57:55 +0000 (00:57 +0000)]
Pull request #4763: build: generate and tag 3.9.0.0
Merge in SNORT/snort3 from ~PRBG/snort3:build_3.9.0.0 to master
Squashed commit of the following:
commit
e7f05b621609a272b9ea977b1b3c8798671b82e9
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Wed May 28 14:29:03 2025 -0400
build: generate and tag 3.9.0.0
Ron Dempster (rdempste) [Wed, 28 May 2025 17:18:57 +0000 (17:18 +0000)]
Pull request #4594: flow: change to vector with binary search for flow data and stash
Merge in SNORT/snort3 from ~RDEMPSTE/snort3:flow to master
Squashed commit of the following:
commit
0c905b7a6905b54a449a87882ac1e3316bc81c3c
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Tue Dec 10 13:14:09 2024 -0500
managers, profiler, stream: fix glibc debug and assertion issues
commit
1df7595917fb9f6094733b65c624c80833676422
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Wed Mar 19 13:31:37 2025 -0400
codec, flow: make mpls layers in flow pointers to save memory
commit
e65aafd4add8969db80b353bbd4868d52b65e085
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Wed Nov 27 11:51:19 2024 -0500
flow: use vector and binary search for flow data and stash
Priyanka Bangalore Gurudev (prbg) [Tue, 27 May 2025 16:48:22 +0000 (16:48 +0000)]
Pull request #4761: build: generate and tag 3.8.1.0
Merge in SNORT/snort3 from ~PRBG/snort3:build_3.8.1.0 to master
Squashed commit of the following:
commit
04fcb95f47537de9076f4f0143dfbbef3dc27ecf
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Mon May 26 18:26:33 2025 -0400
build: generate and tag 3.8.1.0
Pull request #4759: Fixup for unit tests.
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:fix2 to master
Squashed commit of the following:
commit
0e3ce31ea59ac3b3d45928ec1adffb6ac1d6e5c4
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Mon May 26 13:42:53 2025 +0300
http2_inspect: rid of removed base template in unit tests
Juweria Ali Imran (jaliimra) [Fri, 23 May 2025 14:46:27 +0000 (14:46 +0000)]
Pull request #4711: stream_tcp: do not purge seglist data on held packet retransmit
Merge in SNORT/snort3 from ~JALIIMRA/snort3:held_packet_retransmit to master
Squashed commit of the following:
commit
2fba7b400772dec79ab54a19bc52897d949e35d3
Author: Juweria Ali Imran <jaliimra@cisco.com>
Date: Thu Apr 24 20:36:30 2025 -0400
stream_tcp: do not purge seglist data on held packet retransmit
Ashutosh Gupta (ashugup3) [Thu, 22 May 2025 08:14:38 +0000 (08:14 +0000)]
Pull request #4756: file_api: introduced atomicity for is_file_service_enabled
Merge in SNORT/snort3 from ~ASHUGUP3/snort3:bug_CSCwn79296 to master
Squashed commit of the following:
commit
e3162b2fbcb9f865c9a423e0aa4a1ff22892b12e
Author: ashutosh <ashugup3@cisco.com>
Date: Thu May 22 10:42:28 2025 +0530
file_api: introduced atomicity for is_file_service_enabled
Akhilesh MY (amuttuva) [Thu, 22 May 2025 05:43:40 +0000 (05:43 +0000)]
Pull request #4740: telnet: handle ayt commands in splitter
Merge in SNORT/snort3 from ~AMUTTUVA/snort3:telnet_block to master
Squashed commit of the following:
commit
e862f9ad8ae83f116d57eb74bb8ebeef0566d7d8
Author: Akhilesh MY <amuttuva@cisco.com>
Date: Mon May 12 07:45:34 2025 -0400
telnet: handle ayt commands in splitter
Pull request #4751: Rid of removed base template
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:fix_base_template to master
Squashed commit of the following:
commit
834b202ae4ea196e643df15403e7e86759dc1f3f
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Mon May 19 18:22:41 2025 +0300
http2_inspect: rid of removed base template
The base template for std::char_traits has been removed.
Rishabh Choudhary (rishacho) [Tue, 20 May 2025 07:42:15 +0000 (07:42 +0000)]
Pull request #4745: main: remove snort cpu command output from log
Merge in SNORT/snort3 from ~RISHACHO/snort3:snort_cpu_fix to master
Squashed commit of the following:
commit
cf8bac4f2becbda0fcc84205d868758e59665f2f
Author: Rishabh Choudhary <rishacho@cisco.com>
Date: Tue May 13 23:40:36 2025 +0530
main: remove snort cpu command output from log
Raza Shafiq (rshafiq) [Mon, 19 May 2025 17:29:22 +0000 (17:29 +0000)]
Pull request #4742: rna: coverity fixes
Merge in SNORT/snort3 from ~RSHAFIQ/snort3:cov_rna to master
Squashed commit of the following:
commit
54f9ee7379d39560e4085b72b5860aa98d4610b4
Author: rshafiq <rshafiq@cisco.com>
Date: Fri May 2 10:28:27 2025 -0400
rna: coverity fixes
Pull request #4750: Bump CMake minimal version to 3.5
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:cmake_version to master
Squashed commit of the following:
commit
cfe82ae54302258082adf115f54efd879ee7782d
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Tue Apr 29 09:19:46 2025 +0300
build: set CMake minimal version to 3.5
Pull request #4733: protocol: add ESP to valid next headers in IPv6
Merge in SNORT/snort3 from ~JAIMEACA/snort3:protocols_add_esp_to_valid_next_header_ipv6 to master
Squashed commit of the following:
commit
13e35df9fe6281202db320b1e98662d1da705638
Author: Jaime Andres Castillo Leon -X (jaimeaca - SOFTSERVE INC at Cisco) <jaimeaca@cisco.com>
Date: Thu May 8 15:24:32 2025 -0400
protocol: add ESP to valid next headers in IPv6
Pull request #4702: flow: add id_offset to filenames created by stream.dump_flows()
Merge in SNORT/snort3 from ~DZIKRATY/snort3:change_file_names_for_dump_flows to master
Squashed commit of the following:
commit
c92caed95d6a071f7fdcc2d2809b35d48994b622
Author: Denys Zikratyi -X (dzikraty - SOFTSERVE INC at Cisco) <dzikraty@cisco.com>
Date: Tue Apr 15 09:48:06 2025 -0400
flow: add id_offset to filenames created by stream.dump_flows()
Michael Matirko (mmatirko) [Tue, 13 May 2025 20:12:43 +0000 (20:12 +0000)]
Pull request #4737: main: change process_id to a global var such that we don't require constant access to the SnortConfig
Merge in SNORT/snort3 from ~MMATIRKO/snort3:proc_id_2 to master
Squashed commit of the following:
commit
90a78ea8f5c0ac0247e0e48fe1e288568b9e053f
Author: Michael Matirko <mmatirko@cisco.com>
Date: Fri May 2 14:57:04 2025 -0400
main: change process_id to a global var such that we don't require constant access to the SnortConfig
Maya Dagon (mdagon) [Tue, 13 May 2025 14:44:04 +0000 (14:44 +0000)]
Pull request #4728: extractor: support conn.log history field
Merge in SNORT/snort3 from ~MDAGON/snort3:conn_state to master
Squashed commit of the following:
commit
dbce4ec8618a4d3e0ecda6fa4d4375de06eee9c0
Author: maya dagon <mdagon@cisco.com>
Date: Wed Apr 30 13:56:59 2025 -0400
extractor: support conn.log history field
Raza Shafiq (rshafiq) [Mon, 12 May 2025 22:48:01 +0000 (22:48 +0000)]
Pull request #4698: flow: excess flows to allowlist
Merge in SNORT/snort3 from ~RSHAFIQ/snort3:flow_limit to master
Squashed commit of the following:
commit
4caf75c4bc3857e7588f823ef89035f97e518d8f
Author: rshafiq <rshafiq@cisco.com>
Date: Mon Apr 7 18:31:23 2025 -0400
flow: add option to move excess flows to allowlist
Pull request #4609: stream_tcp: detection of gaps in packet stream
Merge in SNORT/snort3 from ~NIRMVENK/snort3:seglist_hole to master
Squashed commit of the following:
commit
067ed3b736175cad013725eba8393a26d0a2944c
Author: Nirmala Subbaiah <nirmvenk@cisco.com>
Date: Fri Feb 7 13:42:24 2025 -0500
stream: detection of gaps in packet stream
Steve Chew (stechew) [Mon, 12 May 2025 20:37:27 +0000 (20:37 +0000)]
Pull request #4738: pub_sub: Can now get all headers, response str and method from HttpEvent.
Merge in SNORT/snort3 from ~STECHEW/snort3:update_http_event to master
Squashed commit of the following:
commit
0e25d6025597408baa71bb7b0396c2affc7f746b
Author: Steve Chew <stechew@cisco.com>
Date: Sat May 10 15:58:00 2025 -0400
pub_sub: Can now get all headers, response str and method from HttpEvent.
Pull request #4723: Include input file name to DAQ error message
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:daq_err_message to master
Squashed commit of the following:
commit
885f662a13d1cb47d10cc4556690429d84ae06d2
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Tue May 6 13:52:33 2025 +0300
analyzer: print DAQ input specification next to its message
Juweria Ali Imran (jaliimra) [Fri, 9 May 2025 20:46:43 +0000 (20:46 +0000)]
Pull request #4729: stream_tcp: print stream_tcp state upon hitting queue_limits
Merge in SNORT/snort3 from ~JALIIMRA/snort3:print_stream_state to master
Squashed commit of the following:
commit
552960385a7655eb84fb7c44704aa07c160a5800
Author: Juweria Ali Imran <jaliimra@cisco.com>
Date: Tue Apr 22 12:41:13 2025 -0400
stream_tcp: print stream_tcp state upon hitting queue_limits
Pull request #4726: stream_tcp: deprecate the reassemble_async configuration option
Merge in SNORT/snort3 from ~DAVMCPHE/snort3:deprecate_reassemble_async to master
Squashed commit of the following:
commit
18400e7d9fda158c3fc59d73060312b70795f93f
Author: davis mcpherson <davmcphe@cisco.com>
Date: Tue May 6 08:29:46 2025 -0400
stream_tcp: deprecate the reassemble_async configuration option
commit
a5a8fe2fb28ee6cc33391f1453b5599c3e0928e0
Author: davis mcpherson <davmcphe@cisco.com>
Date: Mon May 5 23:18:17 2025 -0400
snort2lua: add include for cstdint to provide standard c++ integer types
Pull request #4719: flow: implement a per flow check of the packet timestamp and drop packets if the timestamp is earlier than the timestamp of the previous packet
Merge in SNORT/snort3 from ~DAVMCPHE/snort3:drop_stale_packets to master
Squashed commit of the following:
commit
27a0456758a6713b2c5cdc94f3d2c59eaa9aa9dc
Author: davis mcpherson <davmcphe@cisco.com>
Date: Mon May 5 23:18:17 2025 -0400
snort2lua: add include for cstdint to provide standard c++ integer types
commit
63de2df3d4e5c871a0069b646c0a5c06588d9aa7
Author: davis mcpherson <davmcphe@cisco.com>
Date: Fri Apr 4 14:45:29 2025 -0400
flow: implement a per flow check of the packet timestamp and drop packets if the timestamp is earlier than the timestamp of the previous packet
flow: always count stale packets, only drop if that is enabled by config, set default value for drop_stale_packets to false (disabled)
Priyanka Bangalore Gurudev (prbg) [Fri, 9 May 2025 17:17:23 +0000 (17:17 +0000)]
Pull request #4736: build: generate and tag 3.8.0.0
Merge in SNORT/snort3 from ~PRBG/snort3:build_3.8.0.0 to master
Squashed commit of the following:
commit
a191b6ffeda07cc2431c0a197d86e81e80ee1772
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Thu May 8 20:44:30 2025 -0400
build: generate and tag 3.8.0.0
Steve Chew (stechew) [Fri, 9 May 2025 00:26:40 +0000 (00:26 +0000)]
Pull request #4683: packet_io: add trace logs when injecting packets.
Merge in SNORT/snort3 from ~STECHEW/snort3:inject_trace_logs to master
Squashed commit of the following:
commit
4aee3268aab234a62231870a3ff8764b463b7948
Author: Steve Chew <stechew@cisco.com>
Date: Wed Apr 2 00:50:04 2025 -0400
packet_io: add trace logs when injecting packets.
Steve Chew (stechew) [Fri, 9 May 2025 00:05:53 +0000 (00:05 +0000)]
Pull request #4732: Fix alias name
Merge in SNORT/snort3 from ~STECHEW/snort3:oleksii_alias_fix to master
Squashed commit of the following:
commit
e14bdcd2196c9151048a2afb8559a64ab6fb4358
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Apr 2 15:54:45 2025 +0300
framework: make alias name internal to inspector instance
commit
32450f01541938b7e3b80d1b52df3ad172bf56c3
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Apr 2 14:07:16 2025 +0300
managers: update formatting
Priyanka Bangalore Gurudev (prbg) [Thu, 8 May 2025 18:26:14 +0000 (18:26 +0000)]
Pull request #4722: build: generate and tag 3.7.4.0
Merge in SNORT/snort3 from ~PRBG/snort3:build_3.7.4.0 to master
Squashed commit of the following:
commit
6f6d275e11180e523aa96f991908a07d960d8d72
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Mon May 5 22:24:20 2025 -0400
build: generate and tag 3.7.4.0
Pull request #4725: mp_data_bus: standartize data types
Merge in SNORT/snort3 from ~OSTEPANO/snort3:mp_transport_types to master
Squashed commit of the following:
commit
f8c03a985161f9c8b3963064d136fd364936e74e
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Tue May 6 10:19:37 2025 -0400
mp_data_bus: standartize data types
Pull request #4657: extractor: add ips events logging
Merge in SNORT/snort3 from ~ANOROKH/snort3:extr_detection to master
Squashed commit of the following:
commit
582e912a61e0993915ed83d84e77f1841f4e3423
Author: anorokh <anorokh@cisco.com>
Date: Thu Feb 20 02:28:16 2025 +0200
extractor: add weird and notice logging
Umang Sharma (umasharm) [Sun, 4 May 2025 16:19:14 +0000 (16:19 +0000)]
Pull request #4721: AppID Third party sync events for Multiprocess
Merge in SNORT/snort3 from ~UMASHARM/snort3:appid_tp_syncevents to master
Squashed commit of the following:
commit
e9776d26a8d485b85ba3d99c37f8a841f8c960ee
Author: Umang Sharma <umasharm@cisco.com>
Date: Fri May 2 17:28:07 2025 -0400
appid: multiprocess init for appid tp syncevents
Pull request #4718: mp_data_bus: Adding stats and CLI commands to MPDataBus
Merge in SNORT/snort3 from ~OSTEPANO/snort3:cli_stats_mp to master
Squashed commit of the following:
commit
8160a86149c4b0030e74b6a04a6919ce55bf3913
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Mon Apr 28 06:02:08 2025 -0400
mp_data_bus: Adding peg stats and socket commands for MPDataBus
Pull request #4699: http_inspect: add dynamic length-limited publishing of request and response body
Merge in SNORT/snort3 from ~VTRON/snort3:publish_http_body to master
Squashed commit of the following:
commit
2dba6d67d600da2f03621ce84dd10bda0486b926
Author: Vitalii Tron <vtron@cisco.com>
Date: Tue Oct 22 13:17:54 2024 -0400
http_inspect: add dynamic length-limited publishing of request and response body
Pull request #4717: Fix build for newer LuaJIT
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:build_fix to master
Squashed commit of the following:
commit
7fa3b137336f512a60351e5462050e09d3931897
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Tue Apr 29 10:34:02 2025 +0300
build: apply workaround only for lower versions of LuaJIT
Thanks to Michael Cho for reporting the issue.
Bhumika Sachdeva (bsachdev) [Mon, 28 Apr 2025 20:04:17 +0000 (20:04 +0000)]
Pull request #4708: appid: fixed crash while printing appid debug
Merge in SNORT/snort3 from ~BSACHDEV/snort3:crash_shadow_traffic_fix to master
Squashed commit of the following:
commit
565bd492cad3143672f4d3c6cd4ab425dfe81305
Author: bsachdev <bsachdev@cisco.com>
Date: Mon Apr 21 12:53:15 2025 -0400
appid: fixed crash while printing appid debug
Adrian Mamolea (admamole) [Mon, 28 Apr 2025 18:39:39 +0000 (18:39 +0000)]
Pull request #4705: extractor: extend dns support
Merge in SNORT/snort3 from ~ADMAMOLE/snort3:dns3 to master
Squashed commit of the following:
commit
a66400442cc0567df4607d23f5a070e670b6d76a
Author: Adrian Mamolea <admamole@cisco.com>
Date: Tue Apr 15 13:55:28 2025 -0400
extractor: extend dns support
Michael Matirko (mmatirko) [Mon, 28 Apr 2025 15:13:22 +0000 (15:13 +0000)]
Pull request #4703: flow: don't offset flow instance number by 1 when printing flows
Merge in SNORT/snort3 from ~MMATIRKO/snort3:flow_off_by_one to master
Squashed commit of the following:
commit
3a644db3963d2fef5638e7b30a792d85fd9abe30
Author: Michael Matirko <mmatirko@cisco.com>
Date: Tue Apr 15 12:46:20 2025 -0400
flow: don't offset flow instance number by 1 when printing flows
Umang Sharma (umasharm) [Sat, 26 Apr 2025 00:34:17 +0000 (00:34 +0000)]
Pull request #4692: mp_data_bus: core logic for mp databus
Merge in SNORT/snort3 from ~UMASHARM/snort3:mp_dbus to master
Squashed commit of the following:
commit
7fc8f62dac71aea14203346fe12d2d3bc9605f9c
Author: Umang Sharma <umasharm@cisco.com>
Date: Thu Apr 24 15:29:53 2025 -0400
mp_data_bus: core logic for mp databus
Pull request #4712: mp_unix_transport: clang compilation fix
Merge in SNORT/snort3 from ~OSTEPANO/snort3:crunch_fix to master
Squashed commit of the following:
commit
2a9ddee769279b2a03d32ac93d84e9369bc7463e
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Fri Apr 25 07:08:40 2025 -0400
mp_unix_transport: clang compilation fix
Pull request #4695: mp_unix_transport: mp_transport plugin type, implementation of unix domain name based mp transport
Merge in SNORT/snort3 from ~OSTEPANO/snort3:mp_transport_layer to master
Squashed commit of the following:
commit
edb3158929808ca911049623f5e676554134eab7
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Thu Mar 27 16:06:10 2025 -0400
mp_unix_transport: mp_transport plugin type, implementation of unix domain name based mp transport
Maya Dagon (mdagon) [Wed, 23 Apr 2025 18:38:15 +0000 (18:38 +0000)]
Pull request #4709: extractor: support conn.log orig_bytes, resp_bytes
Merge in SNORT/snort3 from ~MDAGON/snort3:conn_bytes_final to master
Squashed commit of the following:
commit
ee59534a98148aaed8a16339ced286afbe3d1e80
Author: maya dagon <mdagon@cisco.com>
Date: Fri Aug 30 12:54:48 2024 -0400
extractor: support conn.log orig_bytes, resp_bytes
Priyanka Bangalore Gurudev (prbg) [Mon, 21 Apr 2025 15:29:07 +0000 (15:29 +0000)]
Pull request #4706: build: generate and tag 3.7.3.0
Merge in SNORT/snort3 from ~PRBG/snort3:build_3.7.3.0 to master
Squashed commit of the following:
commit
f76d18521571fb953de123b540e13d0082937a73
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Sun Apr 20 11:49:44 2025 -0400
build: generate and tag 3.7.3.0
Abhishek Rawat (abhrawat) [Wed, 16 Apr 2025 12:54:28 +0000 (12:54 +0000)]
Pull request #4650: main: added show snort latency data cli support
Merge in SNORT/snort3 from ~ABHRAWAT/snort3:snort_latency_dioctl to master
Squashed commit of the following:
commit
2f8aec88f4b3e329f931ada996bb272ff2a0716b
Author: abhrawat <abhrawat@cisco.com>
Date: Mon Sep 9 09:17:38 2024 +0000
main: added show snort latency data cli support
Pull request #4700: Handle utility Shell calls
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:ha_fix to master
Squashed commit of the following:
commit
6e62646b481c53a5b0d54acee0a2adc570c5c003
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Sat Apr 12 00:32:33 2025 +0300
main: do not collect configurations for utility shells
This fixes null pointer de-reference.
Pull request #4694: packet_capture: rename pcaps and change max_packet_count default value
Merge in SNORT/snort3 from ~NIRMVENK/snort3:limit_pcap to master
Squashed commit of the following:
commit
ff811e9a73ec19d4408d83715ab2a8e32ca445cd
Author: Nirmala Subbaiah <nirmvenk@cisco.com>
Date: Mon Apr 7 15:58:00 2025 -0400
packet_capture: fix unit test
commit
52d5c0094cdfa7d0c7d72cad5552936ccfce8553
Author: Nirmala Subbaiah <nirmvenk@cisco.com>
Date: Mon Apr 7 13:06:46 2025 -0400
packet_capture: max_packet_count default value modification
commit
dc033ddad141a77f519a2ad1d6f34efb17ea6bd1
Author: Nirmala Subbaiah <nirmvenk@cisco.com>
Date: Mon Apr 7 12:59:18 2025 -0400
packet_capture: rename pcaps and change default value
Pull request #4649: appid: Caching for tcp dns packets.
Merge in SNORT/snort3 from ~VIIZHYK/snort3:dns_caching_appid to master
Squashed commit of the following:
commit
2845f901f9c45b7e284f84378f3cae66ed677ba3
Author: viizhyk <viizhyk@cisco.com>
Date: Wed Apr 2 14:16:49 2025 -0400
appid: Added caching for dns detector.
Pull request #4690: Static checker warning
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:fixup to master
Squashed commit of the following:
commit
de0d2c021f3d2d6de648e5b92121635cf368649b
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Mon Apr 7 09:18:50 2025 +0300
extractor: fix static checker warning
Adrian Mamolea (admamole) [Fri, 4 Apr 2025 14:06:39 +0000 (14:06 +0000)]
Pull request #4675: extractor: extend dns logging
Merge in SNORT/snort3 from ~ADMAMOLE/snort3:extractor_dns2 to master
Squashed commit of the following:
commit
92b7e2c0ab8f1b0fba620f80a2882dea301cbc8c
Author: Adrian Mamolea <admamole@cisco.com>
Date: Mon Mar 24 17:03:25 2025 -0400
extractor: extend dns logging
Pull request #4687: TSV formatting
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:extr_tsv to master
Squashed commit of the following:
commit
7139b13db0f2864f003d18e7e1e1ba00398e7883
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Thu Apr 3 11:56:48 2025 +0300
control: fix types in comparison
commit
7c3600f896b812b7dbb5ca262207789bf37ad598
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Thu Apr 3 11:14:01 2025 +0300
extractor: enable TSV formatting
commit
e7dde81c4dc9ee3772ea3cea7470ae36b0ade1b9
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Apr 2 18:03:10 2025 +0300
extractor: add escaping for TSV
commit
85df6b89ed7427f0ac72028b56a5cf820a9e0dbc
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Apr 2 18:01:46 2025 +0300
extractor: add configurable delimiter in CSV logger
commit
56382b7d389a132523ba183323dc217ebe884031
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Apr 2 17:12:07 2025 +0300
extractor: simplify CSV logger implementation
Pull request #4688: Extractor Parser
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:extr_parse_warning to master
Squashed commit of the following:
commit
1fff5b9cb510f73b7696a76261b618986622c8a9
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Thu Apr 3 15:21:30 2025 +0300
extractor: make parsing more strict
Wei Wang (weiwa) [Thu, 3 Apr 2025 18:56:15 +0000 (18:56 +0000)]
Pull request #4679: DNS: Handle multi trans_IDs in single DNS-UDP flow
Merge in SNORT/snort3 from ~WEIWA/snort3:weiwa-dns-udp-flow-multi-tx to master
Squashed commit of the following:
commit
bd686ccda796712e9545afa72fbcce4e31e50af1
Author: Wei Wang <weiwa@cisco.com>
Date: Thu Apr 3 22:33:06 2025 +0530
DNS: Handle multi trans_IDs in single DNS-UDP flow
Bhumika Sachdeva (bsachdev) [Wed, 2 Apr 2025 14:11:31 +0000 (14:11 +0000)]
Pull request #4673: appid: fixed unknown payload case for domain fronting
Merge in SNORT/snort3 from ~BSACHDEV/snort3:domain_fronting_payload_unknown to master
Squashed commit of the following:
commit
ca35caad3f65496e8ca02cdbca4f39f599a287db
Author: bsachdev <bsachdev@cisco.com>
Date: Fri Mar 21 17:28:28 2025 -0400
appid: fixed unknown payload case for domain fronting
Pull request #4654: snort3: resolve issues reported by Coverity static analysis
Merge in SNORT/snort3 from ~DAVMCPHE/snort3:resolve_coverity_issues to master
Squashed commit of the following:
commit
dbbb96a44df54ec5d8074befd0b2be937950ace8
Author: davis mcpherson <davmcphe@cisco.com>
Date: Sat Mar 15 17:16:36 2025 -0400
main: redirect stdin, stdout, stderr to /dev/null with the freopen system call
main: check return code on mkdir system call and FatalError if it fails
main: refactor signal handling switch statement to eliminate unreachable code
commit
975bae48e44d038495e4649384dcf847dadf253d
Author: davis mcpherson <davmcphe@cisco.com>
Date: Tue Mar 11 09:40:47 2025 -0400
loggers: allocate large buffer for writing unified2 extra data from heap instead of stack
snort: in for loops that use auto keyword add & so the iterator assign a reference for each container element instead of doing a copy. coverity issue: AUTO_CAUSES_COPY
filters: initialize struct fields when instance is defined
unified2: use uint64_t to hold time values to eliminate Y2K38 time rollover issues
managers: use std::move to pass shared ptr to new owner to avoid a copy
commit
77bd1f1b7fc21d6fecf0d51682866bfa08149cf5
Author: davis mcpherson <davmcphe@cisco.com>
Date: Thu Mar 6 14:19:47 2025 -0500
flow: fix coverity SWAPPED ARGUMENTS and Y2K38_SAFETY issues
helpers: validate input from conf file to verify port number string is valid digits
host_tracker: recode while loop to avoid bogus coverity infinite loop warning
ips_options: allocate large buffer for base64 decode from heap instead of on stack
http: initialize class member variables in the ctor
Pull request #4682: control: data race in ControlConn touch method fix
Merge in SNORT/snort3 from ~VSHPYRKA/snort3:ctrl_connn_dr_fix to master
Squashed commit of the following:
commit
6efb3d5acac88957a17886969ae9145fb21b0222
Author: Volodymyr Shpyrka <vshpyrka@cisco.com>
Date: Mon Mar 31 03:24:58 2025 -0400
control: fix data race in ControlConn touch method
Pull request #4659: http2_inspect: builtin rule for large settings max frame size
Merge in SNORT/snort3 from ~JCANOGOM/snort3:http2_rule_large_settings_max_frame_size to master
Squashed commit of the following:
commit
c0a3a471ecdc029bee8984bed2e38edea6e00531
Author: Jose Cano <jcanogom@cisco.com>
Date: Tue Mar 11 11:52:25 2025 -0400
http2_inspect: added settings_max_frame_size parameter and built-in rule 121:44 to check for max frame size
Priyanka Bangalore Gurudev (prbg) [Mon, 31 Mar 2025 17:29:53 +0000 (17:29 +0000)]
Pull request #4681: build: generate and tag 3.7.2.0
Merge in SNORT/snort3 from ~PRBG/snort3:build_3.7.2.0 to master
Squashed commit of the following:
commit
7efd9bbf77cdcb9923acb17a0214ed8e48689a51
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Sun Mar 30 22:19:53 2025 -0400
build: generate and tag 3.7.2.0
Sumit Kumar (sumikum7) [Thu, 27 Mar 2025 06:04:19 +0000 (06:04 +0000)]
Pull request #4662: dce_rpc: fixing coverity in dce_rpc code
Merge in SNORT/snort3 from ~SUMIKUM7/snort3:coverity_CSCwo16686_snort to master
Squashed commit of the following:
commit
92afd8abbce3613447019c469eb0f7f02eb7ffc3
Author: Sumit Kumar <sumikum7@cisco.com>
Date: Mon Mar 24 15:16:03 2025 +0530
dce_rpc: ignoring false positives and fixing spell checks
Sumit Kumar (sumikum7) [Wed, 26 Mar 2025 09:35:39 +0000 (09:35 +0000)]
Pull request #4651: file_api: making current_context as nullptr before it gets the value of ctx
Merge in SNORT/snort3 from ~SUMIKUM7/snort3:coverity_CSCwo20068_snort to master
Squashed commit of the following:
commit
4004df617faf5598c181ae672b1b304e3e440c1b
Author: Sumit Kumar <sumikum7@cisco.com>
Date: Wed Mar 5 15:31:53 2025 +0530
file_api: making current_context as nullptr before it gets the value of ctx
file_api: since current_context would never be file_got hence removing this style check
file_api: making current_context as nullptr before it gets the value of ctx and removing redundant part of if check
Shijin Bose (shibose) [Wed, 26 Mar 2025 06:36:31 +0000 (06:36 +0000)]
Pull request #4665: unified2 : add packet dump to unified event with reassembled udp packet
Merge in SNORT/snort3 from ~SHIBOSE/snort3:unified_udp_data to master
Squashed commit of the following:
commit
e351244d1ffb8e22a6bf706f217d434101604931
Author: shibose <shibose@cisco.com>
Date: Wed Mar 12 15:15:41 2025 +0000
unified2 : add packet dump to unified event with reassembled udp packet
Pull request #4674: PID into dump file name
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:cfg_dump_pid to master
Squashed commit of the following:
commit
818389e207fe57ac24e3095dbc42f4cf9eeeff35
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Mon Mar 24 15:45:24 2025 +0200
dump_config: include PID into dump file name
Brian Morris (bmorris2) [Mon, 24 Mar 2025 19:36:33 +0000 (19:36 +0000)]
Pull request #4671: main: initialize openssl at startup
Merge in SNORT/snort3 from ~BMORRIS2/snort3:init_ssl to master
Squashed commit of the following:
commit
88f0d54f906864cee226dff4e994b2303444237a
Author: Brian Morris <bmorris2@cisco.com>
Date: Wed Mar 19 16:48:26 2025 -0500
main: initialize openssl at startup
Pull request #4672: packet_capture: use existing util function to check directory path
Merge in SNORT/snort3 from ~NIRMVENK/snort3:fix_error to master
Squashed commit of the following:
commit
47e879770de81b34013c58c66f73713bbb2dcb42
Author: Nirmala Subbaiah <nirmvenk@cisco.com>
Date: Fri Mar 21 13:24:01 2025 -0400
packet_capture: use existing util function to check directory path
Juweria Ali Imran (jaliimra) [Mon, 24 Mar 2025 17:15:42 +0000 (17:15 +0000)]
Pull request #4670: stream_tcp: rename OS policy names to prevent conflict with existing macros
Merge in SNORT/snort3 from ~JALIIMRA/snort3:bsd_identifier to master
Squashed commit of the following:
commit
b12a29259c3e9a0fea148e841d4cdb91686fcb27
Author: Juweria Ali Imran <jaliimra@cisco.com>
Date: Fri Mar 21 11:48:21 2025 -0400
stream_tcp: rename OS policy names to prevent conflict with existing macros
Umang Sharma (umasharm) [Sat, 22 Mar 2025 14:44:08 +0000 (14:44 +0000)]
Pull request #4645: connectors: new Unix Domain Connector
Merge in SNORT/snort3 from ~UMASHARM/snort3:unixdomain_connector to master
Squashed commit of the following:
commit
2efb114f729caa16f9044e06789d1ebff6c44321
Author: Umang Sharma <umasharm@cisco.com>
Date: Sun Mar 2 20:36:19 2025 -0500
connectors: new unix domain connector
Umang Sharma (umasharm) [Fri, 21 Mar 2025 23:31:28 +0000 (23:31 +0000)]
Pull request #4664: Multiprocess DataBus Framework
Merge in SNORT/snort3 from ~UMASHARM/snort3:mpubsub_dbus to master
Squashed commit of the following:
commit
e5e650f62e17bb9529b5c7d05cfd27234261613d
Author: Umang Sharma <umasharm@cisco.com>
Date: Thu Mar 13 08:25:05 2025 -0400
mp_data_bus: basic framework with skeleton APIs
Wei Wang (weiwa) [Wed, 19 Mar 2025 14:30:20 +0000 (14:30 +0000)]
Pull request #4610: dns-bee-message: add tenant-fqdn as key in bee-messages
Merge in SNORT/snort3 from ~WEIWA/snort3:weiwa-master-fqdn-bee-compaction-key to master
Squashed commit of the following:
commit
745433c3a261d0dded615b83c89a65785bcb102d
Author: Wei Wang <weiwa@cisco.com>
Date: Tue Mar 18 22:13:56 2025 +0530
dns: pass packet in DnsResponseEvent
Pull request #4547: stream_tcp: refactor tcp normalizer initialization to eliminate duplicate initializations
Merge in SNORT/snort3 from ~DAVMCPHE/snort3:stream_tcp_norm_init to master
Squashed commit of the following:
commit
e8a5e275d89b22f5eb9d3b688a2b84650cb5e209
Author: davis mcpherson <davmcphe@cisco.com>
Date: Tue Sep 24 15:57:10 2024 -0400
imap:pop: delete if expression that compared session flag to the packet_flag filed
commit
395f937f5ec39f22e735cdc094fc34008c0ce359
Author: davis mcpherson <davmcphe@cisco.com>
Date: Thu Jan 30 09:51:01 2025 -0500
stream_tcp: make member variables private to improve tracker class encapsulation
commit
3934da1fee6f5f0c72bfa55cf2c5a02d9f651cc0
Author: davis mcpherson <davmcphe@cisco.com>
Date: Thu Mar 13 10:41:54 2025 -0400
stream_tcp: reduce verbosity of packet tracer log messages for normalizer initialization actions
stream_tcp: split StreamPolicy enum into enums specific to normalization and to overlap resolution
commit
a3e4777c89136f3de3bcc67d365626dca7563b51
Author: davis mcpherson <davmcphe@cisco.com>
Date: Thu Sep 12 11:03:06 2024 -0400
stream_tcp: eliminate redundant calls to initialize the normalizer policy
stream_tcp: only allow legacy OS and FIRST normalizer policies to be configurable. Proxy and missed 3whs modes are determined dynamically per flow
stream_tcp: initialize each tracker's normalizer for missed 3whs behavior invidually when the initial packet is processed by the tracker
Pull request #4623: appid: added flag to enable inspection of ooo packets
Merge in SNORT/snort3 from ~OSTEPANO/snort3:ssl_ooo_ch to master
Squashed commit of the following:
commit
ec43974fa2a3ddc6acf1716f6c1bec0fb5dad657
Author: Oleksandr Stepanov <ostepano@cisco.com>
Date: Mon Feb 17 07:34:48 2025 -0500
appid: added flag to inspect ooo packets
Pull request #4635: packet_capture: support packet capture limit and location
Merge in SNORT/snort3 from ~NIRMVENK/snort3:pcap_limit to master
Squashed commit of the following:
commit
397c78f1e44a6e9e6ba976b7387182377739e87f
Author: Nirmala Subbaiah <nirmvenk@cisco.com>
Date: Mon Feb 24 17:56:54 2025 -0500
packet_capture: support packet capture limit and location
Bhumika Sachdeva (bsachdev) [Wed, 12 Mar 2025 20:27:06 +0000 (20:27 +0000)]
Pull request #4658: appid: Modified shadow traffic status to default
Merge in SNORT/snort3 from ~BSACHDEV/snort3:status_shadow_traffic_default to master
Squashed commit of the following:
commit
752c252429c631f756fcbe0bcae670067f9e83a5
Author: bsachdev <bsachdev@cisco.com>
Date: Tue Mar 11 10:23:44 2025 -0400
appid: Modified shadow traffic status to default
Priyanka Bangalore Gurudev (prbg) [Wed, 12 Mar 2025 19:20:10 +0000 (19:20 +0000)]
Pull request #4661: build: generate and tag 3.7.1.0
Merge in SNORT/snort3 from ~PRBG/snort3:build__3.7.1.0 to master
Squashed commit of the following:
commit
69333ea7033b53c5bf730daba90f8a04ecb9e62a
Author: Priyanka Gurudev <prbg@cisco.com>
Date: Wed Mar 12 00:30:17 2025 -0400
build: generate and tag 3.7.1.0
Ron Dempster (rdempste) [Tue, 11 Mar 2025 18:31:25 +0000 (18:31 +0000)]
Pull request #4626: Appid flow data
Merge in SNORT/snort3 from ~RDEMPSTE/snort3:appid_flow_data to master
Squashed commit of the following:
commit
17d3c097c366d0624f25424a0d1f5d4705ec686a
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Thu Jan 30 10:22:48 2025 -0500
appid: fixes for coverity and cppcheck issues
commit
e5932f8567cbd7eef6ca8569691328b101803734
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Tue Feb 18 10:25:11 2025 -0500
appid: change get_appid_session_api to use the stash
commit
fb1fe44bbe2e8204cff7d84d4d6ab7e29df6375e
Author: Ron Dempster (rdempste) <rdempste@cisco.com>
Date: Wed Nov 27 11:57:09 2024 -0500
appid: convert appid flow data to use objects
Pull request #4653: file_api: add log message for reset ctx
Merge in SNORT/snort3 from ~OTORUBAR/snort3:improve_logging to master
Squashed commit of the following:
commit
e60995fd30f3b16162f9d4f1a5618f5bca5a8bb7
Author: otorubar <otorubar@cisco.com>
Date: Tue Mar 4 04:48:58 2025 -0800
file_api: add log message for reset ctx
Pull request #4656: extractor: add tenant id as common field
Merge in SNORT/snort3 from ~ANOROKH/snort3:extr_add_tenant_field to master
Squashed commit of the following:
commit
2a414abe67d6ffd4bc4d94171a595031a3fa1a89
Author: anorokh <anorokh@cisco.com>
Date: Tue Mar 4 14:21:32 2025 +0200
extractor: add tenant id as common field
Pull request #4655: Extractor timestamp field
Merge in SNORT/snort3 from ~OSHUMEIK/snort3:extr_field_types to master
Squashed commit of the following:
commit
22aae83d1edfaa22a7145501068a29954370d38d
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Thu Mar 6 17:37:52 2025 +0200
extractor: add time formatting in loggers
commit
bdd2f2ac6ccf9f7aa2984bc22455a5959bc6745c
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Mar 5 17:36:14 2025 +0200
extractor: add configuration option for time formatting
commit
df147998fd47b5e3813e909328748e85e254c8b0
Author: Oleksii Shumeiko <oshumeik@cisco.com>
Date: Wed Mar 5 17:10:53 2025 +0200
extractor: remove obsolete includes
Adrian Mamolea (admamole) [Fri, 7 Mar 2025 18:57:44 +0000 (18:57 +0000)]
Pull request #4634: Extractor dns
Merge in SNORT/snort3 from ~ADMAMOLE/snort3:extractor_dns to master
Squashed commit of the following:
commit
eff76203471fb2129af3d0e1ecd04b6b946f88a6
Author: Adrian Mamolea <admamole@cisco.com>
Date: Fri Feb 14 12:28:13 2025 -0500
extractor: dns support
Andres Avila Segura (aavilase) [Thu, 6 Mar 2025 13:44:04 +0000 (13:44 +0000)]
Pull request #4618: appid: adding logs while creating third party context to monitor hanging
Merge in SNORT/snort3 from ~AAVILASE/snort3:third_party_reload_logging to master
Squashed commit of the following:
commit
fd570b5fc85d6b700a4f30ab5ae406e661b84328
Author: Andres Avila <aavilase@cisco.com>
Date: Thu Feb 13 08:40:19 2025 -0500
appid: Adding log while creating third party context to monitor hanging
Pull request #4638: build: add version check for numactl library
Merge in SNORT/snort3 from ~DZIKRATY/snort3:add_version_check_for_numactl to master
Squashed commit of the following:
commit
3bdbc66908dce164db28ec693021224e38d8263d
Author: Denys Zikratyi -X (dzikraty - SOFTSERVE INC at Cisco) <dzikraty@cisco.com>
Date: Wed Feb 26 07:13:27 2025 -0500
build: add version check for numactl
Sumit Kumar (sumikum7) [Wed, 5 Mar 2025 13:14:09 +0000 (13:14 +0000)]
Pull request #4646: config_parser : fixing unchecked return in snort_config
Merge in SNORT/snort3 from ~SUMIKUM7/snort3:coverity_CSCwo20129 to master
Squashed commit of the following:
commit
14a2c51a860fde5116dcd22d153b94acbad38c2c
Author: Sumit Kumar <sumikum7@cisco.com>
Date: Wed Mar 5 11:48:26 2025 +0530
config_parser : fixing the no return check warning rather than supressing it
commit
55404aa73c8ef2cbd06c1d39044816222b644066
Author: Sumit Kumar <sumikum7@cisco.com>
Date: Tue Mar 4 19:58:50 2025 +0530
config_parser : turning down false positive warnings
commit
9b72c801eedcf5109044ff620b314fb04ab9e481
Author: Sumit Kumar <sumikum7@cisco.com>
Date: Tue Mar 4 11:23:56 2025 +0530
config_parser : turning down false positive warnings