Project

General

Profile

Actions

Bug #5458

closed

Reject action is no longer working

Added by tug tugtug over 2 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport to 6.0

Description

This is a pretty significant regression that got slipped away during any testing (if any) before the release.

As of bf5d9d542bc31f8d5eb856484a2336ab8a240825 below, the ACTION_REJECT set by all signatures are essentially no longer set to the packet. i.e. the RespondReject module that filters the action on rejections are no longer functional.

detect-parse.c

    } else if (strcasecmp(action, "reject") == 0 ||
               strcasecmp(action, "rejectsrc") == 0)
    {
        if (!(SigParseActionRejectValidate(action)))
            return -1;
        s->action = ACTION_REJECT|ACTION_DROP;

detect-engine-alert.c

@@ -178,9 +178,10 @@ static void PacketApplySignatureActions(Packet *p, const Signature *s, const uin
 {
     SCLogDebug("packet %" PRIu64 " sid %u action %02x alert_flags %02x", p->pcap_cnt, s->id,
             s->action, alert_flags);
-    PACKET_UPDATE_ACTION(p, s->action);

     if (s->action & ACTION_DROP) {
+        PacketDrop(p, PKT_DROP_REASON_RULES);
+
         if (p->alerts.drop.action == 0) {
             p->alerts.drop.num = s->num;
             p->alerts.drop.action = s->action;
@@ -189,8 +190,11 @@ static void PacketApplySignatureActions(Packet *p, const Signature *s, const uin
         if ((p->flow != NULL) && (alert_flags & PACKET_ALERT_FLAG_APPLY_ACTION_TO_FLOW)) {
             RuleActionToFlow(s->action, p->flow);
         }
-    } else if (s->action & ACTION_PASS) {
-        if ((p->flow != NULL) && (alert_flags & PACKET_ALERT_FLAG_APPLY_ACTION_TO_FLOW)) {
+    } else {
+        PACKET_UPDATE_ACTION(p, s->action);
+
+        if ((s->action & ACTION_PASS) && (p->flow != NULL) &&
+                (alert_flags & PACKET_ALERT_FLAG_APPLY_ACTION_TO_FLOW)) {
             RuleActionToFlow(s->action, p->flow);
         }
     }


Subtasks 1 (0 open1 closed)

Bug #5471: Reject action is no longer working (6.0.x backport)ClosedJuliana Fajardini ReichowActions

Related issues 1 (0 open1 closed)

Copied to Suricata - Bug #5471: Reject action is no longer working (6.0.x backport)ClosedJuliana Fajardini ReichowActions
Actions #1

Updated by Juliana Fajardini Reichow over 2 years ago

  • Assignee changed from OISF Dev to Juliana Fajardini Reichow
Actions #2

Updated by Juliana Fajardini Reichow over 2 years ago

  • Status changed from New to In Review
Actions #3

Updated by Victor Julien over 2 years ago

  • Priority changed from Urgent to High
  • Target version changed from TBD to 7.0.0-beta1
  • Label Needs backport to 6.0 added
Actions #4

Updated by Juliana Fajardini Reichow over 2 years ago

  • Copied to Bug #5471: Reject action is no longer working (6.0.x backport) added
Actions #5

Updated by Juliana Fajardini Reichow over 2 years ago

  • Subtask #5471 added
Actions #7

Updated by Juliana Fajardini Reichow over 2 years ago

  • Status changed from In Review to Resolved
Actions #8

Updated by Juliana Fajardini Reichow over 2 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF