Snort on openwrt (23.05.3)

Whats up with the snort package(s)? Seems only snort 2 is available.

Wiki states

Packages for both Snort 2.x as well as Snort 3.x are currently available. This page is focused exclusively on the 3.x series.

Makes things quite confusing. packages for snort3 are not available in 23.05.3.

1 Like

[heavily edited reply now]

snort v2 was deprecated from snapshot in January '24, leaving only snort3. But you're right, snort3 isn't in 23.05.3 - and that is confusing!

1 Like

snort3 is built in 22.x and earlier, but not in the 23 series. I have no idea why, as the package and makefile look fine when you switch to the v23.05.3 branch.

I think something is broken in the build config, make menuconfig on shows no snort entries, but if you look for it in 22.x or main, it's there and can be configured and built.

Let's see if the devs can shed some light on this:

1 Like

Source code is your friend...

My two cents are on the backport of the HAS_LUAJIT_ARCH dependency.

Main/master shows that definition:

.config - OpenWrt Configuration
 > Search (LUAJIT) ────────────────────────────────────────────────────────────
  ┌──────────────────────────── Search Results ─────────────────────────────┐
  │ Symbol: HAS_LUAJIT_ARCH [=y]                                            │  
  │ Type  : bool                                                            │  
  │ Defined at tmp/                                 │  
  │                                                                         │  

But 23.05 has no idea about that:

.config - OpenWrt Configuration
 > Search (LUAJIT) ───────────────────────────────────────────────────────────────
  ┌────────────────────────────── Search Results ──────────────────────────────┐
  │                                                                            │  
  │ Symbol: HAS_LUAJIT_ARCH [=HAS_LUAJIT_ARCH]                                 │  
  │ Type  : unknown                                                            │  
  │                                                                            │  

And that symbol is a hard dependency since this in master:

That requirement in snort3 has been backported into 23.05 by thuis commit

Probably @ansuel @bkpepe know more about HAS_LUAJIT_ARCH

I guess the commit has to be backported as well?

No idea, I just stumbled into the "disappearing package" and looked for reasons why snort3 does show up in menuconfig. Never used or compiled snort3 (or luajit) by myself.

1 Like

One thing solved and another pops up...

@hnyman, good sleuthing. Turns out that HAS_LUAJIT_ARCH only appears in the backported snort3/Makefile. Editing the make file to remove the reference now shows snort3 in menuconfig.


When I include the package in .config, the snort3 package build fails miserably, lots of missing symbols. Reported here

[10/819] Building CXX object src/main/CMakeFiles/main.dir/
FAILED: src/main/CMakeFiles/main.dir/
/home/efahlgren/openwrt/openwrt/staging_dir/toolchain-x86_64_gcc-12.3.0_musl/bin/x86_64-openwrt-linux-musl-g++ -DHAVE_CONFIG_H -Dinline=inline -Drestrict=__restrict -I/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- -I/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- -I/home/efahlgren/openwrt/openwrt/staging_dir/target-x86_64_musl/usr/include/luajit-2.1 -I/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- -I/home/efahlgren/openwrt/openwrt/staging_dir/host/include -I/home/efahlgren/openwrt/openwrt/staging_dir/target-x86_64_musl/usr/include/hs -I/home/efahlgren/openwrt/openwrt/staging_dir/target-x86_64_musl/usr/include/uuid -I/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- -Os -pipe -fno-caller-saves -fno-plt -fhonour-copts -fmacro-prefix-map=/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- -Wformat -Werror=format-security -fstack-protector -D_FORTIFY_SOURCE=1 -Wl,-z,now -Wl,-z,relro -I/home/efahlgren/openwrt/openwrt/staging_dir/target-x86_64_musl/usr/include/daq3 -I/home/efahlgren/openwrt/openwrt/staging_dir/target-x86_64_musl/usr/include/tirpc  -fvisibility=hidden   -DNDEBUG  -fno-builtin-malloc -fno-builtin-calloc -fno-builtin-realloc -fno-builtin-free  -DNDEBUG -std=c++17 -MD -MT src/main/CMakeFiles/main.dir/ -MF src/main/CMakeFiles/main.dir/ -o src/main/CMakeFiles/main.dir/ -c /home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3-
/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- In member function 'void OopsHandler::set_current_message(DAQ_Msg_h, snort::SFDAQInstance*)':
/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- error: 'DIOCTL_GetPrivDataLen' was not declared in this scope
   61 |         DIOCTL_GetPrivDataLen ioctl_data = {cur_msg,  0};
      |         ^~~~~~~~~~~~~~~~~~~~~
/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- error: 'DIOCTL_GET_PRIV_DATA_LEN' was not declared in this scope
   62 |         if (DAQ_SUCCESS == daq_instance->ioctl(DIOCTL_GET_PRIV_DATA_LEN, &ioctl_data, sizeof(ioctl_data)))
      |                                                ^~~~~~~~~~~~~~~~~~~~~~~~
/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- error: 'ioctl_data' was not declared in this scope
   62 |         if (DAQ_SUCCESS == daq_instance->ioctl(DIOCTL_GET_PRIV_DATA_LEN, &ioctl_data, sizeof(ioctl_data)))
      |                                                                           ^~~~~~~~~~
/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- In member function 'void OopsHandler::eternalize(int)':
/home/efahlgren/openwrt/openwrt/build_dir/target-x86_64_musl/snort3- error: 'daq_msg_get_priv_data' was not declared in this scope; did you mean 'daq_msg_get_data'?
   97 |         memcpy(priv_data, daq_msg_get_priv_data(msg), std::min<size_t>(priv_data_len, sizeof(priv_data)));
      |                           ^~~~~~~~~~~~~~~~~~~~~
      |                           daq_msg_get_data
ninja: build stopped: subcommand failed.

I'll carry on over on the -devel list, and stop posting on this thread, at least until something is resolved (no sense in posting everything twice).

Belay that, discussion will be continued at

1 Like

Snort3 has just appeared in the 23.05.3 release branch (at least for x86/64):

(@kimboslice, you should probably mark this thread as "solved".)


Thanks for opening that issue and getting this resolved!


Don't know if I'm jumping onto correct thread, but I have installed snort3 today with opkg and tried to follow wiki, but snort-rules and snort-mgr utilities seem to not be present:

# snort-rules
-ash: snort-rules: not found
# snort-mgr
-ash: snort-mgr: not found
1 Like

Correct, they are only present in snapshot, and don't appear in 23.05 or earlier.

All of the new stuff is just scripts (sh and ucode), so probably works on 23.05... Look in (the Makefile can tell you how its layed out, and files/ contains the scripts and supporting files).

1 Like

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.