detect: allow rule which need both directions to match #10242
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Link to redmine ticket:
https://redmine.openinfosecfoundation.org/issues/5665
Describe changes:
OISF/suricata-verify#1603
Not so much a draft anymore...
But I still expect to see next iterations...
TODO :
to_client
andto_server
keywords that are not inflow
keyword, but only apply to a previous keyword). Here, it is a documented limitation...#10231 with
DetectEngineStateDirection dir_state[]
so as to have efficient CPU-time (even if more memory) storage and retrieval of inspect_flags