Project

General

Profile

Actions

Bug #7197

open

detect/flowvars: persist if the inspection happens on multiple packets

Added by Philippe Antoine 5 months ago. Updated 5 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
high
Difficulty:
Label:

Description

At the end of the run of each detection (frame, transaction..) the flowvar varlist in the DetectEngineThreadCtx gets reset by DetectVarProcessList

This prevents the flow variable to persist if the rule inspection happens on multiple packets ( as stored in a DetectEngineState )

SV test coming when I will get the ticket number


Related issues 1 (1 open0 closed)

Related to Suricata - Bug #5576: Dataset is setting data despite the signature being a complete matchIn ReviewPhilippe AntoineActions
Actions

Also available in: Atom PDF