analysis: report rule state altered by other rule - v1 #12286
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Flowbits can make a rule such as a packet rule be treated as a stateful rule, without actually changing the rule type.
Add a flag to allow report such cases via the engine analysis.
Task #7456
Link to ticket: https://redmine.openinfosecfoundation.org/issues/
https://redmine.openinfosecfoundation.org/issues/7456
Describe changes:
Wasn't sure about using this as another
SIG_INIT_FLAG
or even as flag that could have other values, so decided to go with this as a proof of concept, sort of.The output will also be tested with SV tests that should accompany the rule types doc.
Moved on with this work before the rule types documentation as this should also be present in the
engine-analysis
examples seen there.Output example: