]>
git.ipfire.org Git - thirdparty/suricata-update.git/log
summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Jason Ish [Mon, 4 Dec 2017 22:15:01 +0000 (16:15 -0600)]
add-source: don't use flags for options
Instead making name and url positional args.
We can add a flag to change the meaning of the URL
later.
Jason Ish [Mon, 4 Dec 2017 20:01:29 +0000 (14:01 -0600)]
remove sources that an enabled one replaces
For example, when enabling et/pro, if et/open is enabled,
remove it, as its replaced by et/pro
Jason Ish [Mon, 4 Dec 2017 19:50:52 +0000 (13:50 -0600)]
doc: reorg index
Jason Ish [Mon, 4 Dec 2017 19:48:54 +0000 (13:48 -0600)]
doc: remove-source
Jason Ish [Mon, 4 Dec 2017 19:44:41 +0000 (13:44 -0600)]
doc: disable-source
Jason Ish [Mon, 4 Dec 2017 19:40:34 +0000 (13:40 -0600)]
remove-source - move code to its own file
Jason Ish [Mon, 4 Dec 2017 19:35:00 +0000 (13:35 -0600)]
disable-source: move command to own source file
Jason Ish [Mon, 4 Dec 2017 19:28:31 +0000 (13:28 -0600)]
doc: add page for enable-source
Jason Ish [Mon, 4 Dec 2017 19:22:52 +0000 (13:22 -0600)]
quickstart: remove bit about re-enabling et/open
Jason Ish [Mon, 4 Dec 2017 19:20:55 +0000 (13:20 -0600)]
list-sources: show parameters (if any)
Jason Ish [Mon, 4 Dec 2017 19:18:01 +0000 (13:18 -0600)]
When enabling source, also enable et/open...
But only if the source being enabled is not et/open, or the
source being enabled does not replace et/open.
This is also only done on creation of the directory:
/var/lib/suricata/update/sources
Jason Ish [Mon, 4 Dec 2017 13:40:09 +0000 (07:40 -0600)]
enable-source: move to own source files
Jason Ish [Mon, 4 Dec 2017 13:10:15 +0000 (07:10 -0600)]
list-sources: show replaces info
Jason Ish [Mon, 4 Dec 2017 02:40:59 +0000 (20:40 -0600)]
doc: add doc for update-sources
Also introduce a common-options file for options that are
common to all commands.
Jason Ish [Sun, 3 Dec 2017 20:57:20 +0000 (14:57 -0600)]
update-sources: move to own source file
Also make the verbose logging info.
Jason Ish [Sun, 3 Dec 2017 17:12:18 +0000 (11:12 -0600)]
doc: re-org into commands
Jason Ish [Sat, 2 Dec 2017 16:39:35 +0000 (10:39 -0600)]
python 3 fix for parsing suricata config output
Jason Ish [Fri, 1 Dec 2017 21:18:51 +0000 (15:18 -0600)]
include suricata version in user agent
Jason Ish [Fri, 1 Dec 2017 20:31:18 +0000 (14:31 -0600)]
doc: add quickstart
Jason Ish [Fri, 1 Dec 2017 20:31:01 +0000 (14:31 -0600)]
doc: fix pulling in version
Jason Ish [Fri, 1 Dec 2017 19:52:32 +0000 (13:52 -0600)]
use a custom user agent
Includes Suricata-Update version, Suricata version, OS name
and processor architecture.
Jason Ish [Fri, 1 Dec 2017 18:10:41 +0000 (12:10 -0600)]
changelog: update
Jason Ish [Fri, 1 Dec 2017 13:25:02 +0000 (07:25 -0600)]
list-sources: colourize
Jason Ish [Thu, 30 Nov 2017 23:07:20 +0000 (17:07 -0600)]
disable rules with proto's not enabled in suricata config
Jason Ish [Thu, 30 Nov 2017 21:57:22 +0000 (15:57 -0600)]
include git revision in version output
Jason Ish [Thu, 30 Nov 2017 19:27:12 +0000 (13:27 -0600)]
env var SOURCE_DIRECTORY to override default...
So tests won't pick up enabled sources...
Jason Ish [Thu, 30 Nov 2017 18:51:51 +0000 (12:51 -0600)]
add --now to skip the timebased check.
Jason Ish [Thu, 30 Nov 2017 17:25:47 +0000 (11:25 -0600)]
doc: rework heading levels
Jason Ish [Wed, 29 Nov 2017 22:40:53 +0000 (16:40 -0600)]
readme: update files and directories
Jason Ish [Thu, 30 Nov 2017 17:26:32 +0000 (11:26 -0600)]
don't require index for url sources
Also logs some exceptions in a more friendly way.
Jason Ish [Wed, 29 Nov 2017 22:38:24 +0000 (16:38 -0600)]
update.yaml: sources is now just a URL list
Jason Ish [Wed, 29 Nov 2017 12:33:55 +0000 (06:33 -0600)]
new commands: add-source, list-sources, list-enabled-sources
Jason Ish [Tue, 28 Nov 2017 22:45:27 +0000 (16:45 -0600)]
sources: resolve urls from index
Jason Ish [Tue, 28 Nov 2017 04:21:52 +0000 (22:21 -0600)]
update-sources: new command to download source index
Jason Ish [Tue, 28 Nov 2017 22:50:17 +0000 (16:50 -0600)]
et pro: mask the secret code
Jason Ish [Tue, 28 Nov 2017 22:44:47 +0000 (16:44 -0600)]
logging: add secret masking
Allows strings to be registered that will be masked
in the log output.
Jason Ish [Mon, 20 Nov 2017 21:15:54 +0000 (15:15 -0600)]
rule parsing: fix infinite loop on missing ;
If the last rule option was missing a ";" the parser would
enter an infinite loop. Instead error out with an exception
that can be logged.
Test case added.
From an reported on the idstools rule parser.
Jason Ish [Mon, 20 Nov 2017 21:11:20 +0000 (15:11 -0600)]
tests: remove BSD license.
All code has been assigned to the OISF under the GPLv2.
Breaker [Fri, 3 Nov 2017 03:29:14 +0000 (11:29 +0800)]
change --post-hook to --reload-command
Jason Ish [Tue, 14 Nov 2017 11:04:51 +0000 (12:04 +0100)]
doc: --cache-dir command line argument removed
Jason Ish [Tue, 14 Nov 2017 10:57:29 +0000 (11:57 +0100)]
Ingore cache directory when backing up rules.
Jason Ish [Tue, 14 Nov 2017 10:42:21 +0000 (11:42 +0100)]
Put cache directory under the rules directory.
One less directory to manage permissions on.
Jason Ish [Mon, 13 Nov 2017 08:57:23 +0000 (09:57 +0100)]
fix restoration permission issue after update fail
First attempt to just copy back the data of the files. Then
attempt to copy the mode, as the mode may fail if the user
running suricata-update doesn't own the files, but has permissions
to write to them with group permissions.
Jason Ish [Mon, 6 Nov 2017 04:27:01 +0000 (22:27 -0600)]
fix ET Open by default logic...
Somewhere along the line the behaviour of loading ET Open
if no other URLs were present was lost. Re-add this default
behaviour.
Loading ET-Open by default will happen if:
- no --urls passed on the command line
- no sources provided in the configuration
- no etpro code given
Victor Julien [Fri, 3 Nov 2017 14:19:11 +0000 (15:19 +0100)]
github/codeowners: add OISF/core-team
Add core team so all PRs get a reviewer assigned. When it's @jasonish
it will be just OISF/core-team, otherwise it'll be both. Then
@jasonish can approve in name of core-team as well.
Jason Ish [Fri, 3 Nov 2017 13:36:14 +0000 (07:36 -0600)]
rule parsing: don't warn if no msg present
Jason Ish [Fri, 3 Nov 2017 13:34:51 +0000 (07:34 -0600)]
issue 2261: don't fail on empty "local"
If local existed, but was empty, YAML would make it a None
value instead of the default empty list.
For local and sources, make sure they are an empty list after
loading instead of None.
Victor Julien [Thu, 2 Nov 2017 14:20:26 +0000 (15:20 +0100)]
rule testing: don't fail because of ASAN leak warnings
Jason Ish [Thu, 2 Nov 2017 13:46:07 +0000 (07:46 -0600)]
Fix Oinkmaster modifysid with group name.
Make the group name matcher the last matcher to be parsed,
and accept the match spec if it ends with .rules and not
prefixed with group.
This was broken while fixing up other issues in group name
parsing to make it more predictable.
Jason Ish [Thu, 2 Nov 2017 13:03:16 +0000 (07:03 -0600)]
Initial import of Suricata-Update.
Suricata-Update is a tool for updating Suricata rules. Based
on idstools-rulecat, but relicensed under the GPL and contributed
to the OISF.