From d8d60bc73c0e8a4a1eb74b6e2e0bd21e05dcb2fe Mon Sep 17 00:00:00 2001 From: Lukas Sismis Date: Wed, 26 Aug 2026 16:11:22 +0200 Subject: [PATCH 1/2] fw: validate scope inheritance in policies and rules A secondary action given without an explicit scope inherits the scope of the primary action, but was never validated against the scopes it supports itself. `pass` only supports packet and flow scope but the inheritance was never verified. Ticket: 8954 --- src/detect-parse.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/src/detect-parse.c b/src/detect-parse.c index 44d546984c19..a34276eca6ef 100644 --- a/src/detect-parse.c +++ b/src/detect-parse.c @@ -1873,6 +1873,14 @@ static int SigParseActionDo(const char *action_in, const int idx, const bool fw_ return -1; } *scope_out = scope_flags; + } else if (*scope_out != 0 && (flags & ACTION_PASS)) { + /* No scope given, this action inherits the scope set by the preceding + * actions of a multi-action rule. */ + if (*scope_out != ACTION_SCOPE_PACKET && *scope_out != ACTION_SCOPE_FLOW) { + SCLogError("invalid action scope '%s' in action '%s': only 'packet' and 'flow' allowed", + ActionScopeToString((enum ActionScope) * scope_out), action_in); + return -1; + } } /* require explicit action scope for fw rules */ From f32a565bda5fb019696976561ace844231da7165 Mon Sep 17 00:00:00 2001 From: Lukas Sismis Date: Thu, 27 Aug 2026 16:32:13 +0200 Subject: [PATCH 2/2] fw: allow pass as a secondary action only for accept Previously, hook sequences in both rules and default policies allowed `pass` to be combined with incompatible hooks (e.g. reject or drop). This commit clamps pass to accept only. Ticket: 8954 --- src/detect-parse.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/detect-parse.c b/src/detect-parse.c index a34276eca6ef..74502ba6f2df 100644 --- a/src/detect-parse.c +++ b/src/detect-parse.c @@ -1822,6 +1822,10 @@ static int SigParseActionDo(const char *action_in, const int idx, const bool fw_ "rules"); return -1; } + if (idx > 0 && (flags & ACTION_PASS) && !(*action_out & ACTION_ACCEPT)) { + SCLogError("'pass' is only supported as a secondary action for 'accept'"); + return -1; + } } /* parse scope, if any */