Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-22 Thread Robin Sommer


On Thu, Aug 22, 2013 at 13:31 -0400, you wrote:

> Could we do the ticket that moves uid values to 92 to 96 bits?  I
> forget what we agreed on.  Also, I'd like to see uid values prepended
> with either 'F' or 'C' for file uids and connection uids.  It would
> help me keep them straight in mind, especially with the designator
> being part of the uid.

Yeah, both make sense. Any volunteers to take the lead on
implemtentation and baseline updates?

Robin


-- 
Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org
ICSI/LBNL* Fax   +1 (510) 666-2956 * www.icir.org/robin
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-22 Thread Robin Sommer

On Thu, Aug 22, 2013 at 17:50 +, you wrote:

> Yeah, sorry about that. Getting SumStats working again was a big
> priority for CMU, so I've been focusing on that. I hope to work on
> those this weekend.

No worries, sumstats clearly had priority, just wanted to update the
list. :)

Robin

-- 
Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org
ICSI/LBNL* Fax   +1 (510) 666-2956 * www.icir.org/robin
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-22 Thread Vlad Grigorescu

On Aug 22, 2013, at 12:58 PM, Robin Sommer  wrote:

>>- DHCP script cleanup (Seth/Vlad; see BIT-1050)
> 
> Pending. 
> 
>>- SIP analyzer (Vlad; going to happen?)
> 
> Pending.

Yeah, sorry about that. Getting SumStats working again was a big priority for 
CMU, so I've been focusing on that. I hope to work on those this weekend.

  --Vlad
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-22 Thread Seth Hall
On Aug 22, 2013, at 12:58 PM, Robin Sommer  wrote:

> Plus potentially the packet-filter.log fix.
> 
> Anything else?


I would like two relatively small changes that will result in some massive 
headache in test baseline updates.  Sorry I hadn't been pushing on this harder 
until now.

Could we do the ticket that moves uid values to 92 to 96 bits?  I forget what 
we agreed on.  Also, I'd like to see uid values prepended with either 'F' or 
'C' for file uids and connection uids.  It would help me keep them straight in 
mind, especially with the designator being part of the uid.

  .Seth

--
Seth Hall
International Computer Science Institute
(Bro) because everyone has a network
http://www.bro.org/




signature.asc
Description: Message signed with OpenPGP using GPGMail
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-22 Thread Robin Sommer
Let me update this:

On Mon, Aug 12, 2013 at 09:04 -0700, I wrote:

> - Fix sumstats framework (Seth; or is it done already now?)

Done I believe.

> - HyperLogLog (Bernhard)

Waiting for Bernhard but I believe it's now ready for merging as the
memory leak was likely related to the when problem.

> - DHCP script cleanup (Seth/Vlad; see BIT-1050)

Pending. 

> - DNP3 finalizing (Robin, Hui)

Done, except that one unit tests fails on some platform.

> - Windows executable analyzer (Seth; going to happen?)

Pending.

> - SIP analyzer (Vlad; going to happen?)

Pending.

> - Bloomfilter test failures (Matthias)

Done.

> - Input framework test failures (Bernhard)

Done.

> - X509 extensions (going to happen? can somebody remind we what this is 
> about?)

We'll skip these.


Plus potentially the packet-filter.log fix.

Anything else?

Robin

-- 
Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org
ICSI/LBNL* Fax   +1 (510) 666-2956 * www.icir.org/robin
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-12 Thread Vlad Grigorescu

On Aug 12, 2013, at 12:04 PM, Robin Sommer  wrote:

>- DHCP script cleanup (Seth/Vlad; see BIT-1050)

Yep, I'll work on this with Seth.

>- SIP analyzer (Vlad; going to happen?)

I just have one issue to figure out in BinPAC, to implement this correctly. 
Right now I'm relying on is_orig, but due to some weird SIP proxying, that 
doesn't work correctly in a small number of cases (as seen in the real world by 
Aashish).

I'm going to try to get this done by the end of the week, but if I don't get to 
it I'm fine pushing it to 2.3.

  --Vlad
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-12 Thread Siwek, Jonathan Luke
>- Input framework test failures (Bernhard)

I've also started looking in to the executestdin one which is still showing 
some real problems and was planning to look at others too.

> Anything I'm missing? 

I want to add something to the file extraction analyzer to make it easier to 
impose limits.  Should just be a minor change to do.

- Jon
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


Re: [Bro-Dev] Planing for a 2.2 beta

2013-08-12 Thread Seth Hall
On Aug 12, 2013, at 12:04 PM, Robin Sommer  wrote:

>- Fix sumstats framework (Seth; or is it done already now?)

Not done yet.  It's broken on clusters at the moment, but I'm trying to get it 
done this week.

>- Windows executable analyzer (Seth; going to happen?)

Yes, I hope so.  I'll have some stuff out on this soon.

> Can we aim to have this all in by the end of this week? Then we could
> target a 2.2 beta by the end of next.


I'll try my best on my stuff. :)

  .Seth


--
Seth Hall
International Computer Science Institute
(Bro) because everyone has a network
http://www.bro.org/




signature.asc
Description: Message signed with OpenPGP using GPGMail
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev


[Bro-Dev] Planing for a 2.2 beta

2013-08-12 Thread Robin Sommer
This is what I have on my list as remaining for a 2.2 beta:

- Fix sumstats framework (Seth; or is it done already now?)
- HyperLogLog (Bernhard)
- DHCP script cleanup (Seth/Vlad; see BIT-1050)
- DNP3 finalizing (Robin, Hui)
- Windows executable analyzer (Seth; going to happen?)
- SIP analyzer (Vlad; going to happen?)
- Bloomfilter test failures (Matthias)
- Input framework test failures (Bernhard)
- X509 extensions (going to happen? can somebody remind we what this is 
about?)

Anything I'm missing? I'd like put a feature freeze in place.

Can we aim to have this all in by the end of this week? Then we could
target a 2.2 beta by the end of next.

Robin

-- 
Robin Sommer * Phone +1 (510) 722-6541 * ro...@icir.org
ICSI/LBNL* Fax   +1 (510) 666-2956 * www.icir.org/robin
___
bro-dev mailing list
bro-dev@bro.org
http://mailman.icsi.berkeley.edu/mailman/listinfo/bro-dev