Project

General

Profile

Actions

Bug #7886

open

firewall: --firewall-rules-exclusive loads generic td rules as well

Added by Shivani Bhardwaj 2 months ago. Updated 7 days ago.

Status:
Assigned
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs Suricata-Verify test

Description

when it should only load the firewall rules.


Subtasks 1 (1 open0 closed)

Bug #7912: firewall: --firewall-rules-exclusive loads generic td rules as well (8.0.x backport)AssignedShivani BhardwajActions
Actions #1

Updated by Philippe Antoine about 2 months ago

  • Label Needs Suricata-Verify test added
Actions #2

Updated by Philippe Antoine about 2 months ago

  • Affected Versions 8.0.0 added
Actions #3

Updated by Victor Julien about 2 months ago

  • Target version changed from 8.0.1 to 8.0.2
Actions #4

Updated by Philippe Antoine about 2 months ago

Is the only problem the fact that we can use -S ?

see

 if (!sig_file_exclusive && de_ctx->firewall_rule_file_exclusive) {

Actions #5

Updated by Philippe Antoine about 2 months ago

  • Status changed from New to Feedback
Actions #6

Updated by Victor Julien about 2 months ago

  • Target version changed from 8.0.2 to 9.0.0-beta1
  • Label Needs backport to 8.0 added
Actions #7

Updated by OISF Ticketbot about 2 months ago

  • Subtask #7912 added
Actions #8

Updated by OISF Ticketbot about 2 months ago

  • Label deleted (Needs backport to 8.0)
Actions #9

Updated by Shivani Bhardwaj 8 days ago

  • Status changed from Feedback to Assigned
  • Assignee changed from OISF Dev to Shivani Bhardwaj

Think this is simple enough to tackle for the upcoming release. Self assigned

Actions #10

Updated by Shivani Bhardwaj 7 days ago

Philippe Antoine wrote in #note-4:

Is the only problem the fact that we can use -S ?

see
[...]

No idea. I spent some time trying to understand what I meant here but either I tested it wrong or it happened in a special combination of config and cmdline options. But, for now, I'm unable to reproduce this and what I've written here seems impossible by looking at the code.
Should have done a better job at ticket description.

Actions

Also available in: Atom PDF