Actions
Optimization #569
open
VJ
CT
display syntax requirement on keyword parsing error
Optimization #569:
display syntax requirement on keyword parsing error
Added by Victor Julien almost 14 years ago. Updated 26 days ago.
Effort:
high
Difficulty:
low
Label:
Description
Currently if the syntax of a rule keyword is wrong we print just a pcre error most of the times.
It would be good to have a string per keyword that is displayed on error.
Format:
threshold: type <threshold|limit|both>, track <by_src|by_dst>, count <N>, seconds <T>
VJ Updated by Victor Julien almost 14 years ago Actions #1
- Priority changed from Normal to Low
VJ Updated by Victor Julien almost 14 years ago Actions #2
- Target version changed from 1.4beta3 to 1.4rc1
VJ Updated by Victor Julien over 13 years ago Actions #3
- Target version changed from 1.4rc1 to 2.0rc2
VJ Updated by Victor Julien over 12 years ago Actions #4
- Target version changed from 2.0rc2 to 3.0RC2
VJ Updated by Victor Julien over 11 years ago Actions #5
- Target version changed from 3.0RC2 to 70
VJ Updated by Victor Julien over 10 years ago Actions #6
- Priority changed from Low to Normal
- Target version changed from 70 to TBD
VJ Updated by Victor Julien about 8 years ago Actions #7
- Assignee changed from OISF Dev to Anonymous
- Effort set to high
- Difficulty set to low
AH Updated by Andreas Herz over 7 years ago Actions #8
- Assignee set to Community Ticket
JT Updated by Jason Taylor almost 7 years ago Actions #9
- Assignee changed from Community Ticket to Jason Taylor
JT Updated by Jason Taylor almost 5 years ago Actions #10
It looks like the last discussion that was had around this was in https://github.com/OISF/suricata/pull/4251. Are there any update thoughts or ideas around this? I was going to take another look at this but wanted to see if anyone else had or was.
JT Updated by Jason Taylor over 4 years ago Actions #11
- Assignee changed from Jason Taylor to Community Ticket
PA Updated by Philippe Antoine about 3 years ago Actions #12
Side-note: We want to move away from pcre for keywords, and we still need meaningful error messages
PA Updated by Philippe Antoine about 3 years ago Actions #13
- Tracker changed from Bug to Optimization
PA Updated by Philippe Antoine 26 days ago Actions #14
- Status changed from New to Triaged
Actions