LS Lukas Sismis
- Login: lukas.sismis
- Registered on: 06/02/2021
- Last sign in: 08/28/2026
Issues
| open | closed | Total | |
|---|---|---|---|
| Assigned issues | 40 | 153 | 193 |
| Reported issues | 39 | 92 | 131 |
Projects
| Project | Roles | Registered on |
|---|---|---|
| Suricata | Developer, OISF Team | 12/15/2021 |
| Suricata-Update | Developer, OISF Team | 12/15/2021 |
Activity
09/14/2026
- LS 01:06 PM Suricata Feature #8334: firewall: allow matching on packet layers
- Would it be ok to have the format such as:
accept:hook eth/vlan/tcp:all ...
accept:hook eth/vlan/tcp/tls:request_started ...
where the last element is what is currently used in the rules?
---
The second idea, potentially ...
09/10/2026
- LS 02:36 PM Suricata Feature #8334: firewall: allow matching on packet layers
- Intermediary questions:
Is the goal here to match only on layers itself or do we also want to match on fields of individual layers?
Also, is the goal here to match on the specific layers using a single rule? - LS 11:39 AM Suricata Task #9034 (Triaged): firewall: add PGSQL hooks
- LS 11:38 AM Suricata Task #9034 (Triaged): firewall: add PGSQL hooks
- Currently PostgreSQL has no named hooks and therefore cannot be practically used in FW rules.
The ticket aims to evaluate and design sensible hook names and later implement them.
09/07/2026
- LS 02:15 PM Suricata Bug #8952 (In Review): engine-analysis: packet:filter policy is hardcoded to drop:packet (8.0.x backport)
- https://github.com/OISF/suricata/pull/16199
- LS 02:14 PM Suricata Bug #8955 (In Review): firewall: action scope not validated when inherited in multi-action rules (8.0.x backport)
- https://github.com/OISF/suricata/pull/16199
- LS 02:14 PM Suricata Bug #9018 (In Review): output: Double-free of prefix/sensor_name in threaded LogFileCtx teardown (8.0.x backport)
- https://github.com/OISF/suricata/pull/16199
- LS 09:32 AM Suricata Bug #8861 (Resolved): output: Double-free of prefix/sensor_name in threaded LogFileCtx teardown
- https://github.com/OISF/suricata/pull/16137
Will need to evaluate if the bug is present in 8 (likely). - LS 09:27 AM Suricata Bug #8968: firewall: tighten scopes available to pre_flow packet hook (8.0.x backport)
- we'll give it a chance
- LS 09:27 AM Suricata Bug #8970: firewall: flow scope not applied to drop default policy on packet level (8.0.x backport)
- we'll give it a chance