Re: Error in registered TalosLightSPD ruleset released on 2026-03-24?
Dheeraj Gupta via Snort-users <[email protected]> Mon, 30 Mar 2026 10:46:43 +0530
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAOsL98PaxhAqY53ppkL8p6Du+X-0bXXS6UAQQ4E=0VrbseGnfg__18256.863292639$1774848482$gmane$org@mail.gmail.com> |
--===============7576572413803025626== Content-Type: multipart/alternative; boundary="0000000000007f6f3d064e36f548" --0000000000007f6f3d064e36f548 Content-Type: text/plain; charset="UTF-8" Following up on this, The new ruleset released on 2026-03-26 also causes the same error. Although the reference in load_ips.lua has been removed, there is now a reference to 3.1.25.0 in policies/common/ruledirs.conf.lua With the latest ruleset, that line needs to be commented or the sensor will not start. Once again I am requesting the signature release admins to let us know if there is something missing in the registered ruleset (The directory for rules/3.1.25.0) which we need to manually account for or is this a bug at Snort's end? Thanks, Dheeraj On Thu, 26 Mar 2026 at 13:56, Dheeraj Gupta <[email protected]> wrote: > Hi, > > We are using registered ruleset for Snort. After downloading the latest > LightSPD ruleset released on 2026-03-24, our sensor failed to start up with > an error > > ERROR: ips.rules:6 can't open ../../rules/3.1.25.0/includes.rules > ERROR: ips.states:6 can't open ../../rules/ > 3.1.25.0/rulestates-security-ips.states > > Looking at the the file lightspd/policies/common/load_ips.lua in the > release, there is a reference to 3.1.25 (which was not there in older > release) > > if TALOS.functions.minsnortver_str("3.1.25.0-0") then > table.insert(ruleDirs, "../../rules/3.1.25.0") > end > > while there is no 3.1.25.0 subdirectory in the rules/ > > Commenting out the above 3 lines allows sensor to start. Is this a problem > with only the registered ruleset? > > I initially posted this in snort-sigs list but cross-posting here as no > response was received on that list > > Thanks, > Dheeraj > > --0000000000007f6f3d064e36f548 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Following up on this,</div><div><br></div><div>The ne= w ruleset released on 2026-03-26 also causes the same error. Although the r= eference=C2=A0in load_ips.lua has been removed, there is now a reference to= 3.1.25.0 in</div><div><br></div><div>policies/common/ruledirs.conf.lua</di= v><div><br></div><div>With the latest ruleset, that line needs to be commen= ted=C2=A0or the sensor will not start.</div><div><br></div><div>Once again = I am requesting the signature release admins to let us know if there is som= ething missing in the registered ruleset (The directory for rules/<a href= =3D"http://3.1.25.0">3.1.25.0</a>) which we need to manually account for or= is this a bug at Snort's end?</div><div><br></div><div>Thanks,</div><d= iv>Dheeraj</div><br><div class=3D"gmail_quote gmail_quote_container"><div d= ir=3D"ltr" class=3D"gmail_attr">On Thu, 26 Mar 2026 at 13:56, Dheeraj Gupta= <<a href=3D"mailto:[email protected]">[email protected]</= a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0p= x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><d= iv dir=3D"ltr"><div class=3D"gmail_quote"><div dir=3D"ltr"><div dir=3D"ltr"= ><div>Hi,</div><div><br></div><div>We are using registered ruleset for Snort. After downloading the latest LightSPD ruleset=20 released on 2026-03-24, our sensor failed to start up with an error</div><d= iv><br></div><div>ERROR: ips.rules:6 can't open ../../rules/<a href=3D"= http://3.1.25.0/includes.rules" target=3D"_blank">3.1.25.0/includes.rules</= a><br>ERROR: ips.states:6 can't open ../../rules/<a href=3D"http://3.1.= 25.0/rulestates-security-ips.states" target=3D"_blank">3.1.25.0/rulestates-= security-ips.states</a></div><div><br></div><div>Looking at the the file=C2= =A0lightspd/policies/common/load_ips.lua in the release, there is a referen= ce to 3.1.25 (which was not there in older release)</div><div><br></div><di= v>if TALOS.functions.minsnortver_str("3.1.25.0-0") then<br>=C2=A0= =C2=A0table.insert(ruleDirs, "../../rules/<a href=3D"http://3.1.25.0"= target=3D"_blank">3.1.25.0</a>")<br>end</div><div><br></div><div>whil= e there is no 3.1.25.0 subdirectory in the rules/</div><div><br></div><div>= Commenting out the above 3 lines allows sensor to start. Is this a problem = with only the registered ruleset?</div><div><br></div><div>I initially post= ed this in snort-sigs list but cross-posting here as no response was receiv= ed on that list</div><div><br></div><div>Thanks,</div><div>Dheeraj</div></d= iv><br></div> </div></div> </blockquote></div></div> --0000000000007f6f3d064e36f548-- --===============7576572413803025626== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============7576572413803025626==--