Skip to content

Lua http2 6409 v2 - #16104

Draft
catenacyber wants to merge 3 commits into
OISF:mainfrom
catenacyber:lua-http2-6409-v2
Draft

catenacyber wants to merge 3 commits into
OISF:mainfrom
catenacyber:lua-http2-6409-v2

Conversation

@catenacyber

Copy link
Copy Markdown
Contributor

Link to ticket: https://redmine.openinfosecfoundation.org/issues/6409

Describe changes:

  • lua : begin support for HTTP2

SV_BRANCH=OISF/suricata-verify#3315

DRAFT :
Does the syntax look good so far ?
If it is ok, I can complete the commits to support all lua functions for HTTP2

but restrict lua further functions to http1 for now
Next commits will add http2 compatibility function by function

Ticket: 6409
get_h1_tx for HTTP1 and get_h2_tx for HTTP2

Ticket: 6409
@catenacyber catenacyber mentioned this pull request Aug 25, 2026
@catenacyber

Copy link
Copy Markdown
Contributor Author

Medium — src/util-lua-http.c:64,90,124: get_tx() and get_h2_tx() reject ALPROTO_DOH2, although HTTP/2 signature engines intentionally inspect the outer HTTP/2 transaction on DoH2 flows. Lua rules therefore miss DoH2 URI matches or abort on a nil transaction. Treat DoH2 as HTTP/2 in both getter checks and URI dispatch, and add DoH2 coverage to suricata-verify PR #3315, whose capture contains only HTTP/1 and plain HTTP/2.

To fix, but I guess I will wait on the syntax validation first

@codecov

codecov Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 60.65574% with 24 lines in your changes missing coverage. Please review.
✅ Project coverage is 83.04%. Comparing base (7c66954) to head (14a26df).

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #16104      +/-   ##
==========================================
- Coverage   83.06%   83.04%   -0.02%     
==========================================
  Files        1004     1004              
  Lines      277376   277434      +58     
==========================================
- Hits       230389   230382       -7     
- Misses      46987    47052      +65     
Flag Coverage Δ
fuzzcorpus 61.48% <8.19%> (-0.02%) ⬇️
livemode 18.44% <8.19%> (+0.02%) ⬆️
netns 22.84% <8.19%> (-0.04%) ⬇️
pcap 45.40% <8.19%> (-0.02%) ⬇️
suricata-verify 67.12% <60.65%> (-0.04%) ⬇️
unittests 58.51% <13.11%> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@suricata-qa

Copy link
Copy Markdown

Information: QA ran without warnings.

Pipeline = 33323

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants