26.7(.1): Suricata configuration causes crashes
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 505
- Forks
- 202
- PR merge metrics
- No merged PRs in 30d
Description
Important notices
Before you add a new report, we ask you kindly to acknowledge the following:
- [ x ] I have read the contributing guidelines at https://github.com/opnsense/core/blob/master/CONTRIBUTING.md
- [ x ] I am convinced that my issue is new after having checked both open and closed issues at https://github.com/opnsense/core/issues?q=is%3Aissue
- AI tools were used to create at least part of the text submitted herewith.
Describe the bug
Prior to 26.7, Suricata was fine. Updating to 26.7 caused crashes where OPNSense would boot, and within a minute or two, a cascade of text would fill the screen, then the host miniPC for OPNSense would reboot and the cycle would restart.
Utilizing option 4 on the shell to reset to default configuration eliminates the issue.
During Suricata configuration process for 26.7.1, the bug returned, forcing another reset to default configuration.
To Reproduce
Steps to reproduce the behavior (upgrade):
- Have Suricata installed on pre-26.7 OPNSense.
- Complete update process to 26.7
- Have hardware running OPNSense connected to monitor
- Load into shell
- Wait ~1-2 minutes
- Cascade of text
- Crash
- System reboots
- Wait ~1-2 minutes
- Crash loop continues
Steps to reproduce the behavior (Suricata config on 26.7 - speculative):
- Enable Suricata IPS
- Set capture mode to Netmap
- Press "Download & Update Rules"
- Crashing begins sometime afterwards
Expected behavior
Suricata on 26.7(.1) to function normally and not interfere with OPNSense functionality.
Describe alternatives you considered
Setting Suricata to Divert mode might prevent the issue, but I haven't tried it.
Additional context
OPNSense is configured as a transparent filtering bridge.
Environment
OPNsense 26.7(.1) (amd64).
Intel® N100
Network Intel® WiFi 6 AX101
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Suricata IPS and Netmap configuration described in the reproduction steps, using shell option 4 to compare the default configuration with the failing one. Capture the cascade of text before the reboot and narrow the failure to the 26.7(.1) upgrade or configuration process. Done means Suricata runs without crashes or reboot loops on the stated bridge setup.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c
- Domain
- networking, operating-systems, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100