Skip to content

dnp3: preserve events when no current tx; better recoverty - v1 - #16168

Closed
jasonish wants to merge 2 commits into
OISF:mainfrom
jasonish:issue-8979-dnp3/v1
Closed

jasonish wants to merge 2 commits into
OISF:mainfrom
jasonish:issue-8979-dnp3/v1

Conversation

@jasonish

@jasonish jasonish commented Sep 2, 2026

Copy link
Copy Markdown
Member

Treat bad link-header CRCs and impossible link lengths as recoverable
errors and attempt to resynchronize.

Also consume a response frame whose trusted length is too short for the
required response headers, so later responses remain available.

Ticket: 8980
Create a TX to carry the event if needed.

Ticket: 8979
@suricata-review-bot

Copy link
Copy Markdown

AI-generated review posted automatically by Suricata ai-review.

Verdict: request changes

  • Medium — src/app-layer-dnp3.c:1112 (mirrored at src/app-layer-dnp3.c:1246): Input without a DNP3 start marker still returns a fatal parser error. The garbage-between-valid-frames reproducer from Redmine #8980 therefore still disables subsequent DNP3 transaction logging and transaction-aware inspection for the flow. suricata-verify PR #3347 covers bad-CRC and short frames but not this scenario. Resynchronize invalid-start input in both directions and add the ticket’s garbage-between-valid-frames regression with TCP segmentation coverage.

@codecov

codecov Bot commented Sep 2, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 94.87179% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 83.13%. Comparing base (cd7f775) to head (a4ebc6d).

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #16168      +/-   ##
==========================================
+ Coverage   83.11%   83.13%   +0.02%     
==========================================
  Files        1004     1004              
  Lines      277558   277577      +19     
==========================================
+ Hits       230692   230767      +75     
+ Misses      46866    46810      -56     
Flag Coverage Δ
fuzzcorpus 61.63% <73.68%> (+0.03%) ⬆️
livemode 18.41% <0.00%> (+<0.01%) ⬆️
netns 22.83% <0.00%> (+<0.01%) ⬆️
pcap 45.39% <0.00%> (-0.07%) ⬇️
suricata-verify 67.31% <71.05%> (-0.02%) ⬇️
unittests 58.53% <20.51%> (-0.02%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Comment thread src/app-layer-dnp3.c
}

/**
* \brief Set a directional event, allocating a transaction if necessary.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Event is not directional

Comment thread src/app-layer-dnp3.c
/**
* \brief Set a directional event, allocating a transaction if necessary.
*/
static void DNP3SetEventDirection(DNP3State *dnp3, bool request, uint8_t event)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is this named DNP3SetEventDirection ?
Direction looks like a leftover

Comment thread src/output-json-dnp3.c
Comment thread src/app-layer-dnp3.c
STREAM_TOCLIENT, packet_bytes, sizeof(packet_bytes));

FAIL_IF(r == 0);
FAIL_IF(r != 0);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could have moved this to a SV test ;-)

@jasonish jasonish Sep 2, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Covered by tests/dnp3/issue-8980-dnp3-framing-recovery, don't really see the need to remove a UT. Though with all that setup its a bit more than a UT.

@suricata-qa

Copy link
Copy Markdown

Information: QA ran without warnings.

Pipeline = 33705

@jasonish

jasonish commented Sep 2, 2026

Copy link
Copy Markdown
Member Author

Replaced by #16170

@jasonish jasonish closed this Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants