Feature #1504
closedlua: better notification in verbose mode on script errors
Description
Using - Suricata version 2.1dev (rev b5e1df2)
On a lua script err/failure - if not possible to err - we should at least relay a warning as compared to "Info" msg.
[9156] 12/7/2015 -- 13:51:42 - (tmqh-packetpool.c:373) <Info> (PacketPoolInit) -- preallocated 1024 packets. Total memory 3598336 [9157] 12/7/2015 -- 13:51:42 - (detect-lua.c:578) <Info> (DetectLuaAppMatch) -- failed to run script: /etc/suricata/rules/self-signed-cert.lua:21: attempt to call global 'format' (a nil value) [9156] 12/7/2015 -- 13:51:42 - (suricata.c:1088) <Info> (SCPrintElapsedTime) -- time elapsed 0.026s
It comes really handy when using the color output in verbose mode.
VJ Updated by Victor Julien about 11 years ago
- Status changed from New to Assigned
- Assignee set to Victor Julien
- Target version set to 3.0RC1
VJ Updated by Victor Julien almost 11 years ago
- Target version changed from 3.0RC1 to 70
VJ Updated by Victor Julien over 9 years ago
- Status changed from Assigned to New
- Assignee changed from Victor Julien to OISF Dev
- Target version changed from 70 to TBD
AH Updated by Andreas Herz about 7 years ago
- Tracker changed from Bug to Feature
VJ Updated by Victor Julien almost 7 years ago
This should probably be combined with some form of rate limiting. In theory every call to a script could generate this output.
VJ Updated by Victor Julien almost 5 years ago
- Subject changed from better notification in verbose mode on luascript err to lua: better notification in verbose mode on script errors
VJ Updated by Victor Julien almost 5 years ago
- Related to Feature #4775: lua: overhaul lua support added
JI Updated by Jason Ish 7 days ago · Edited
- Status changed from New to Closed
At packet-time, a Lua rule runtime failure now logs a Warning:
<Warning> (DetectLuaRunMatch) -- Lua script failed to run successfully: <filename>:<line>: <Lua error>
Behavior in `src/detect-lua.c:176-205`:
- Logged once per Lua thread context and error category.
- Every occurrence increments `detect.lua.errors`.
- Blocked-function, instruction-limit, and memory-limit failures also have dedicated counters.
- The rule is treated as not matched, including negated Lua rules.
This was implemented for Redmine #6940 and shipped in Suricata 8.0.0-beta1, so #1504’s warning and rate-limiting requirements appear satisfied.