General

Profile

LS Lukas Sismis

  • Login: lukas.sismis
  • Registered on: 06/02/2021
  • Last sign in: 08/28/2026

Issues

open closed Total
Assigned issues 40 153 193
Reported issues 39 92 131

Projects

Project Roles Registered on
Suricata Developer, OISF Team 12/15/2021
Suricata-Update Developer, OISF Team 12/15/2021

Activity

09/14/2026

LS 01:06 PM Suricata Feature #8334: firewall: allow matching on packet layers
Would it be ok to have the format such as:
accept:hook eth/vlan/tcp:all ...
accept:hook eth/vlan/tcp/tls:request_started ...
where the last element is what is currently used in the rules?
---
The second idea, potentially ...
Lukas Sismis

09/10/2026

LS 02:36 PM Suricata Feature #8334: firewall: allow matching on packet layers
Intermediary questions:
Is the goal here to match only on layers itself or do we also want to match on fields of individual layers?
Also, is the goal here to match on the specific layers using a single rule?
Lukas Sismis
LS 11:39 AM Suricata Task #9034 (Triaged): firewall: add PGSQL hooks
Lukas Sismis
LS 11:38 AM Suricata Task #9034 (Triaged): firewall: add PGSQL hooks
Currently PostgreSQL has no named hooks and therefore cannot be practically used in FW rules.
The ticket aims to evaluate and design sensible hook names and later implement them.
Lukas Sismis

09/07/2026

LS 02:15 PM Suricata Bug #8952 (In Review): engine-analysis: packet:filter policy is hardcoded to drop:packet (8.0.x backport)
https://github.com/OISF/suricata/pull/16199 Lukas Sismis
LS 02:14 PM Suricata Bug #8955 (In Review): firewall: action scope not validated when inherited in multi-action rules (8.0.x backport)
https://github.com/OISF/suricata/pull/16199 Lukas Sismis
LS 02:14 PM Suricata Bug #9018 (In Review): output: Double-free of prefix/sensor_name in threaded LogFileCtx teardown (8.0.x backport)
https://github.com/OISF/suricata/pull/16199 Lukas Sismis
LS 09:32 AM Suricata Bug #8861 (Resolved): output: Double-free of prefix/sensor_name in threaded LogFileCtx teardown
https://github.com/OISF/suricata/pull/16137
Will need to evaluate if the bug is present in 8 (likely).
Lukas Sismis
LS 09:27 AM Suricata Bug #8968: firewall: tighten scopes available to pre_flow packet hook (8.0.x backport)
we'll give it a chance Lukas Sismis
LS 09:27 AM Suricata Bug #8970: firewall: flow scope not applied to drop default policy on packet level (8.0.x backport)
we'll give it a chance Lukas Sismis

Also available in: Atom