Repository navigation
feat: add Suricata configuration - #927
Merged
Merged
Conversation
VyOS 1.5 exposes service suricata. 1.4 does not. Ship the mapper, builder, capabilities, and a guided UI together, and reject the paths on devices that do not have the node.
A bare log eve node is logging, not off. Do not mark the page dirty by filling filename defaults the user did not change. Reject ports above 65535 and scoped IPv6. Drop the search entry that called this IPS.
Clearing a custom log file now saves eve.json. Turning logging off and back on no longer writes filename or filetype the user did not change. Port checks reject non-ASCII digits.
Logging edits made while the service is off no longer look unsaved. Interface, group, and file-name checks use an end anchor and ASCII digits so a newline or a non-ASCII digit cannot reach the device.
A bare log eve node already records alerts. Choosing alerts only must not mark the page dirty or save a no-op.
useSearchParams needs a Suspense boundary or the production build fails while prerendering the page.
The setup form accepted 2001:db8::1/32 and the device then rejected the save. Check host bits before the value is sent.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
VyManager had no Suricata page. VyOS 1.5 exposes service suricata (interfaces, address groups, port groups, EVE logging). VyOS 1.4 does not have that node, and a direct API call still has to be rejected.
The change adds the mapper, builder, capabilities, RBAC, and a guided UI. Setup creates the network variables rules expect and the three capture port groups the generated config references. The page does not show version numbers. Rule download is not in the device API, so the page says to run update suricata or schedule the existing update script.
Tests: python -m pytest tests/test_suricata_builder_paths.py (52 passed). npx tsx --test src/lib/suricata-model.test.ts (11 passed). npx tsc --noEmit. eslint on the new UI. validateTmplPath on 1.5 accepted the emitted paths; 1.4 rejected service suricata.
Closes #926