Re: Error in registered TalosLightSPD ruleset released on 2026-03-24?

Dheeraj Gupta via Snort-users <[email protected]> Mon, 30 Mar 2026 10:46:43 +0530
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAOsL98PaxhAqY53ppkL8p6Du+X-0bXXS6UAQQ4E=0VrbseGnfg__18256.863292639$1774848482$gmane$org@mail.gmail.com>
--===============7576572413803025626==
Content-Type: multipart/alternative; boundary="0000000000007f6f3d064e36f548"

--0000000000007f6f3d064e36f548
Content-Type: text/plain; charset="UTF-8"

Following up on this,

The new ruleset released on 2026-03-26 also causes the same error. Although
the reference in load_ips.lua has been removed, there is now a reference to
3.1.25.0 in

policies/common/ruledirs.conf.lua

With the latest ruleset, that line needs to be commented or the sensor will
not start.

Once again I am requesting the signature release admins to let us know if
there is something missing in the registered ruleset (The directory for
rules/3.1.25.0) which we need to manually account for or is this a bug at
Snort's end?

Thanks,
Dheeraj

On Thu, 26 Mar 2026 at 13:56, Dheeraj Gupta <[email protected]>
wrote:

> Hi,
>
> We are using registered ruleset for Snort. After downloading the latest
> LightSPD ruleset released on 2026-03-24, our sensor failed to start up with
> an error
>
> ERROR: ips.rules:6 can't open ../../rules/3.1.25.0/includes.rules
> ERROR: ips.states:6 can't open ../../rules/
> 3.1.25.0/rulestates-security-ips.states
>
> Looking at the the file lightspd/policies/common/load_ips.lua in the
> release, there is a reference to 3.1.25 (which was not there in older
> release)
>
> if TALOS.functions.minsnortver_str("3.1.25.0-0") then
>    table.insert(ruleDirs, "../../rules/3.1.25.0")
> end
>
> while there is no 3.1.25.0 subdirectory in the rules/
>
> Commenting out the above 3 lines allows sensor to start. Is this a problem
> with only the registered ruleset?
>
> I initially posted this in snort-sigs list but cross-posting here as no
> response was received on that list
>
> Thanks,
> Dheeraj
>
>

--0000000000007f6f3d064e36f548
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Following up on this,</div><div><br></div><div>The ne=
w ruleset released on 2026-03-26 also causes the same error. Although the r=
eference=C2=A0in load_ips.lua has been removed, there is now a reference to=
 3.1.25.0 in</div><div><br></div><div>policies/common/ruledirs.conf.lua</di=
v><div><br></div><div>With the latest ruleset, that line needs to be commen=
ted=C2=A0or the sensor will not start.</div><div><br></div><div>Once again =
I am requesting the signature release admins to let us know if there is som=
ething missing in the registered ruleset (The directory for rules/<a href=
=3D"http://3.1.25.0">3.1.25.0</a>) which we need to manually account for or=
 is this a bug at Snort&#39;s end?</div><div><br></div><div>Thanks,</div><d=
iv>Dheeraj</div><br><div class=3D"gmail_quote gmail_quote_container"><div d=
ir=3D"ltr" class=3D"gmail_attr">On Thu, 26 Mar 2026 at 13:56, Dheeraj Gupta=
 &lt;<a href=3D"mailto:[email protected]">[email protected]</=
a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0p=
x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><d=
iv dir=3D"ltr"><div class=3D"gmail_quote"><div dir=3D"ltr"><div dir=3D"ltr"=
><div>Hi,</div><div><br></div><div>We are using registered
 ruleset for Snort. After downloading the latest LightSPD ruleset=20
released on 2026-03-24, our sensor failed to start up with an error</div><d=
iv><br></div><div>ERROR: ips.rules:6 can&#39;t open ../../rules/<a href=3D"=
http://3.1.25.0/includes.rules" target=3D"_blank">3.1.25.0/includes.rules</=
a><br>ERROR: ips.states:6 can&#39;t open ../../rules/<a href=3D"http://3.1.=
25.0/rulestates-security-ips.states" target=3D"_blank">3.1.25.0/rulestates-=
security-ips.states</a></div><div><br></div><div>Looking at the the file=C2=
=A0lightspd/policies/common/load_ips.lua in the release, there is a referen=
ce to 3.1.25 (which was not there in older release)</div><div><br></div><di=
v>if TALOS.functions.minsnortver_str(&quot;3.1.25.0-0&quot;) then<br>=C2=A0=
 =C2=A0table.insert(ruleDirs, &quot;../../rules/<a href=3D"http://3.1.25.0"=
 target=3D"_blank">3.1.25.0</a>&quot;)<br>end</div><div><br></div><div>whil=
e there is no 3.1.25.0 subdirectory in the rules/</div><div><br></div><div>=
Commenting out the above 3 lines allows sensor to start. Is this a problem =
with only the registered ruleset?</div><div><br></div><div>I initially post=
ed this in snort-sigs list but cross-posting here as no response was receiv=
ed on that list</div><div><br></div><div>Thanks,</div><div>Dheeraj</div></d=
iv><br></div>
</div></div>
</blockquote></div></div>

--0000000000007f6f3d064e36f548--

--===============7576572413803025626==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============7576572413803025626==--