## OISF/suricata — suricata-8.0.5…suricata-8.0.6

_125 commits._

### Features
- **ftp: support STOU data transfers** (0e65076)
- **ftp: support APPE data transfers** (c729bdd)
- **ftp: support LIST and MLSD data channels** (c95c99b)
- **ftp: support nlst on the data channel** (032a81c)
- **flowbits: add deprecation notice for toggle command** (36fb9ae)
- **conf: introduce SCConfGetNonNull** (8192998)
- **detect/firewall: support hook LTE mode for built-in hooks** (46b98c9)
- **detect: add helper for getting hook name** (fd51eb2)
- **github-ci: add --enable-qa-simulation to debug validation job** (8923605)
- **qa: add rule reload step to firewall test** (1c4a1a2)
- **clang-format: support clang 17** (497a69c)
- **doc/userguide: add new constructs to firewall examples** (48ab24c)
- **doc/userguide: document firewall lte rule support** (05b9fd6)
- **detect/firewall: support alert in packet default policy** (2b09cb8)
- **detect/firewall: support alert in default app policy** (6440d44)
- **detect/firewall: implement initial state range support** (85f2685)
- **qa: add script to test firewall bridge mode** (a0382a9)
- **exceptions: add dedicated flow drop reason** (6f6d184)
- **detect: add flow drop by firewall as drop reason** (a261229)
- **detect/firewall: add dedicated stats counters** (e3a6f29)
- **flow: add aux flags** (b7b9720)
- **docs/configuration: add firewall mode settings** (1664b09)
- **firewall: support multi-action statements in rules** (1fb2f0b)
- **detect/firewall: add single call for applying app default policy** (430bca6)

### Fixes
- **rdp: fix tx id handling** (6be7484)
- **http1: fix transaction iterator** (1f1db89)
- **dhcp: mark transactions single-directional to fix tx leak** (bac8a69)
- **app-layer: fix inverted tx inspected flag check** (60a83c6)
- **mpm/hs: fix compile warnings** (ae3655f)
- **doc/userguide: fix default policies for pre_* hooks** (166707f)
- **detect/firewall: fix accept:tx,alert in default policy** (fa5ecdd)
- **detect/alert: fix suppressed drop handling** (f5ee931)
- **detect/firewall: fix TD drop:flow after FW accept:flow** (ca79a30)
- **detect/firewall: fix last for progress handling** (c82e5dd)
- **firewall: fix hooks getting skipped in some rulesets** (a32e97a)

### Backend
- **release: 8.0.6; update changelog** (4c28cc1)
- **ftp: do not create more than max-tx transactions** (15bf91c)
- **ippair: check ip family when comparing** (c92e270)
- **http1: limit the number of compression bombs per flow** (e369bf2)
- **doh2: clear the buffer after processing it** (26c26de)
- **stream: disrupt never seen direction with async-oneside** (9a54a04)
- **smb: fail transaction creation once the limit is reached** (755d6c3)
- **flow: check ip family when comparing** (4e2f23d)
- **mqtt: bounds number of messages per tx** (c03666d)
- **smtp/mime: consolidate a MimeStateSMTP restart function** (c0215c7)
- **sip: store frame lens as u32 to avoid body truncation** (6f87930)
- **detect: use only one non-prefilter frame for prefilter** (5449ae1)
- **flow/manager: no flow timeout when hash-size < 10** (ae85a04)
- **detect/firewall: apply accept if last tx was skipped** (088b765)
- **detect: use next tx info from iterator** (a6d97b7)
- **ftp: don't match unset ftp.dynamic_port** (dc8160b)
- **ftp: mark ftp.reply as firewall supported** (42332e5)
- **ftp: mark ftp.command_data as firewall supported** (89b6cda)
- **ftp: mark ftpbounce as firewall supported** (a535c01)
- **ftp: mark ftp.reply_received as firewall supported** (1281bc0)
- **ftp: register ftp.mode at response_complete** (0dc49ab)
- **ftp: register ftp.completion_code at response_complete** (d1da970)
- **ftp: mark ftpdata_command as firewall supported** (9893bf5)
- **ftp: mark ftp.dynamic_port as firewall supported** (9146d47)
- **ftp: register ftp.dynamic_port at response completion** (9ad221d)
- **ftp: mark ftp.command as firewall supported** (e9e491d)
- **ftp: register ftp.command_data at request completion** (f1845f0)
- **ftp: register ftp.command buffer at request completion** (90aef2d)
- **psl: update to latest version** (8cdff89)
- **ftp: do not error the flow on file before port** (feb0ff9)
- **swf: prevents overflow with bad config value** (b632248)
- **rdp: mark transactions single-directional** (ef035c7)
- **detect: revert 3adadde** (f234d15)
- **ftpdata: ignore direction in ftpdata_command** (f2ef8e0)
- **ftp: skip ts inspection on tc only transactions** (dace9ec)
- **detect/datajson: check json objects are string as expected** (bd3293a)
- **pcap-file: skip setvbuf on non-seekable streams** (6bcf958)
- **fuzz: forbid usage of pcre with \X** (f45b8f7)
- **windows: always quote path for windows functions needing it** (2b924d4)
- **Revert "af-packet: speed up thread sync during startup"** (5560c7e)
- **conf: uses SCConfGetNonNull** (078ab2f)
- **doc: improve manpage of suricatasc** (3e4bc39)
- **decode/vlan: implement max layers for IEEE8021ah** (2d17c31)
- **defrag: decrement memuse on alloc failure** (94a82f8)
- **rust: exclude DETECT_BYTEMATH_ENDIAN_DEFAULT from bindings** (69c777d)
- **github-actions: bump codecov/codecov-action from 6.0.1 to 7.0.0** (aedc0ed)
- **detect: propagate inspect engine setup failures** (0ea62b4)
- **detect: don't register unrelated inspect engines** (fe14bc8)
- **qa/live: update tests for fw stats counters** (a90ef60)
- **detect: cleanup last tx logic** (c1dbdad)
- **detect: make progress values uint8_t** (eddff49)
- **detect/firewall: minor code cleanup** (28f1b6b)
- **detect/firewall: clean up apply accept logic** (4a75eb9)
- **detect/firewall: refactor per tx rule result handling** (af8e861)
- **detect/firewall: further simplify flow control** (d095860)
- **doc: update firewall design** (b0004fb)
- **detect/firewall: clean up per rule run check** (b9aedae)
- **detect/firewall: minor flow control cleanup** (a1e3f90)
- **detect/firewall: simplify pre-check flow** (c23e028)
- **detect/firewall: clean up tx inspection loop** (d74f953)
- **detect/firewall: consolidate action handling** (a97aa1a)
- **detect/firewall: clean up pre-check policy logic** (a39e36c)
- **detect/firewall: inject alert before default policy** (22c3fb2)
- **detect/firewall: update discarded logic** (08376ae)
- **detect/firewall: drop in fw mode does not include alert** (8c94f10)
- **detect/firewall: log alert for app default with alert** (816e700)
- **detect/firewall: improve handle fw alert handling** (ea66602)
- **detect: minor action handling cleanup** (9bd0ce7)
- **detect/firewall: fixup debug message** (3670b36)
- **detect/firewall: minor code cleanup** (24736ed)
- **eve/alert: firewall default policy logging improvements** (5868e54)
- **detect/analyzer: log firewall lte rule for prior states as well** (97e774b)
- **detect/firewall: limit auto accept notation** (74c2233)
- **detect/parse: convert Notice Log into Debug** (a68bc82)
- **schema: expand stats.ips.replaced explanation** (680b54f)
- **detect/tx: minor debug additions and fixes** (314dce8)
- **firewall/analyzer: include all hooks** (bac8ebf)
- **detect/analyzer: log actual policy for app firewall** (017a28b)
- **detect/firewall: configurable default policies** (1444de0)
- **firewall: accept:flow no longer implies pass:flow** (c17728c)
- **detect/firewall: rename flow control variable** (a08d4d7)
- **detect/firewall: apply default policy in no rules case** (a0ebecc)
- **firewall: limit action scope packet for app-hooks** (f08a748)
- **detect: clean up firewall rule match handling** (8ee91f8)
- **detect: clean up of last_tx check** (ee766f6)
- **detect: minor code cleanup** (b13c890)
- **detect/firewall: clean up flow control** (e39128f)
- **detect: clean app-layer txs when we pass the flow** (3adadde)
- **version: start development towards 8.0.6** (dd5888c)

### Docs
- **docs: add firewall stats doc** (d950432)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/OISF/suricata?utm_source=github-action)._