Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 363769 - net-analyzer/snort 2.9.4.6 needs explicit parameter to find daq
Summary: net-analyzer/snort 2.9.4.6 needs explicit parameter to find daq
Status: CONFIRMED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All All
: Normal minor (vote)
Assignee: Patrick Lauer
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-04-15 21:43 UTC by mike
Modified: 2018-01-25 23:17 UTC (History)
7 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description mike 2011-04-15 21:43:08 UTC
starting up snort results in:

Running in packet dump mode

        --== Initializing Snort ==--
Initializing Output Plugins!
ERROR: Can't find pcap DAQ!
Fatal Error, Quitting..

This can be fixed by explicitly giving the daq-directory with
"--daq-dir /usr/lib/daq/". Cant this be set at installation
via configuration?

Reproducible: Always

Steps to Reproduce:
1. startup snort
Actual Results:  
snort reports:
ERROR: Can't find pcap DAQ!

Expected Results:  
no errors

Portage 2.1.9.42 (default/linux/x86/10.0, gcc-4.4.5, glibc-2.11.3-r0, 2.6.36-gentoo-r8 i686)
=================================================================
System uname: Linux-2.6.36-gentoo-r8-i686-Intel-R-_Core-TM-2_Duo_CPU_L9400_@_1.86GHz-with-gentoo-1.12.14
Timestamp of tree: Fri, 15 Apr 2011 12:45:01 +0000
ccache version 2.4 [enabled]
app-shells/bash:     4.1_p9
dev-java/java-config: 2.1.11-r3
dev-lang/python:     2.6.6-r2, 3.1.3-r1
dev-util/ccache:     2.4-r9
dev-util/cmake:      2.8.1-r2
sys-apps/baselayout: 1.12.14-r1
sys-apps/sandbox:    2.4
sys-devel/autoconf:  2.13, 2.65-r1
sys-devel/automake:  1.9.6-r3, 1.10.3, 1.11.1
sys-devel/binutils:  2.20.1-r1
sys-devel/gcc:       4.4.5
sys-devel/gcc-config: 1.4.1
sys-devel/libtool:   2.2.10
sys-devel/make:      3.81-r2
sys-kernel/linux-headers: 2.6.36.1
virtual/os-headers:  0
ACCEPT_KEYWORDS="x86"
ACCEPT_LICENSE="* -@EULA"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=native -pipe"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt /usr/share/maven-bin-3.0/conf /usr/share/openvpn/easy-rsa /var/lib/hsqldb"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/php/apache2-php5.3/ext-active/ /etc/php/cgi-php5.3/ext-active/ /etc/php/cli-php5.3/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c"
CXXFLAGS="-O2 -march=native -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="assume-digests binpkg-logs ccache distlocks fixlafiles fixpackages news parallel-fetch protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch"
FFLAGS=""
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j3"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/var/lib/layman/fordfrog"
SYNC="rsync://rsync1.de.gentoo.org/gentoo-portage"
USE="X acl acpi alsa bash-completion berkdb bzip2 cli cracklib crypt cups cxx dri dri2 fortran gdbm gpm iconv ipv6 libv4l2 mmx modules mudflap ncurses nls nptl nptlonly opengl openmp pam pcre perl pppd python qt3support qt4 readline sdl session sse sse2 sse3 ssl ssse3 sysfs tcpd threads unicode v4l v4l2 x86 xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" PHP_TARGETS="php5-3" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="intel" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account" 
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LINGUAS, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 1 Jason Wallace 2011-04-18 12:23:54 UTC
Per the post install message...

    elog "The core DQA libraries are installed in /usr/$(get_libdir)/. The libraries"
    elog "for the individual DAQ modules (afpacket,pcap,dump) are installed in"
    elog "/usr/$(get_libdir)/daq. To use these you will need to add the following"
    elog "lines to your snort.conf:"
    elog
    elog "config daq: <DAQ module>"
    elog "config daq_mode: <mode>"
    elog "config daq_dir: /usr/$(get_libdir)/daq"

You need to include the "config daq_dir:" in your config file or edit the conf.d file and include --daq-dir in SNORT_OPTS. Most of the options in the current conf.d file will be included by default in the snort.conf that ships with snort (in the next version I believe). When they are included in snort.conf they will be removed from conf.d.
Comment 2 mike 2011-04-18 16:27:26 UTC
(In reply to comment #1)
> Per the post install message...
> 
>     elog "The core DQA libraries are installed in /usr/$(get_libdir)/. The
> libraries"
>     elog "for the individual DAQ modules (afpacket,pcap,dump) are installed in"
>     elog "/usr/$(get_libdir)/daq. To use these you will need to add the
> following"
>     elog "lines to your snort.conf:"

hm k this was a little confusing because there is no snort.conf but a
snort.conf.distrib..I suppose this is the one.
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2012-11-20 18:17:47 UTC
This is not fixed IMHO.

I've got this in /etc/snort.conf:
config daq: afpacket
config daq_dir: /usr/lib64/daq
config daq_mode: passive

This fails:
# /etc/init.d/snort start
 * Caching service dependencies ...                                                                                                                                                                           [ ok ]
 * Use of the opts variable is deprecated and will be
 * removed in the future.
 * Please use extra_commands, extra_started_commands or extra_stopped_commands.
 * Starting snort ...                                                                                                                                                                                         [ !! ]
 * ERROR: snort failed to start
# snort 
Running in packet dump mode

        --== Initializing Snort ==--
Initializing Output Plugins!
ERROR: Can't find pcap DAQ!
Fatal Error, Quitting..

But This works:
snort --daq-dir /usr/lib/daq/
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2012-11-20 18:21:01 UTC
The same problem exists with 2.9.1, 2.9.2.3
Comment 5 Thomas Kahle (RETIRED) gentoo-dev 2013-11-26 18:27:29 UTC
Same in 2.9.4.6 and while we are at it: The dependency is too low, 0.6.2 is not enough:

# snort -v --daq-dir /usr/lib/daq
Running in packet dump mode

        --== Initializing Snort ==--
Initializing Output Plugins!
pcap DAQ configured to passive.
The DAQ version does not support reload.
Comment 6 Oleh 2014-02-01 13:30:26 UTC
this still happens with daq-2.0.0 version.
Comment 7 Joshua Kinard gentoo-dev 2014-02-03 05:26:03 UTC
Does this happen only when running Snort via the /etc/init.d route, or also when running as an unprivileged user?

Cause I checked my local user copy of my snort conf, and with all three daq config lines present, Snort can find and run daq w/o issues.  I use these three for reading in local libpcap files:

config daq: pcap
config daq_mode: read-file
config daq_dir: /home/<user>/snort/lib/daq/

I'll try to fix the daq version dep as well.
Comment 8 Joshua Kinard gentoo-dev 2014-02-03 08:33:31 UTC
daq has been updated to 2.0.2, and newer Snort ebuilds have been added to the tree.  Please check to see if this problem still exists or not.  If it is, please attach your Snort configuration file.
Comment 9 three sixes 2014-02-22 19:29:51 UTC
bump, still an issue, i solved and resolved this on my own.....  see notes

https://forums.gentoo.org/viewtopic-t-984762-highlight-.html

snort fails to pull in net-libs/libnetfilter_queue

on top of that, its 'all' interface monitoring is not working.
Comment 10 Joshua Kinard gentoo-dev 2014-02-22 23:46:16 UTC
(In reply to three sixes from comment #9)
> bump, still an issue, i solved and resolved this on my own.....  see notes
> 
> https://forums.gentoo.org/viewtopic-t-984762-highlight-.html
> 
> snort fails to pull in net-libs/libnetfilter_queue
> 
> on top of that, its 'all' interface monitoring is not working.

It looks like Snort isn't itself responsible for pulling in the net-libs/libnetfilter_queue library.  You have to make sure to set 'nfq' in your USE flags and re-merge net-libs/daq, which contains the libnetfilter_queue dependency.

I am not sure about the use of the "all" interface not working.  That sounds like a problem upstream (possibly with the upstream-provided configuration), so you may have to ask on the snort-users ML for more info on that.

If you feel this is a problem with the ebuild, please open a new bug specific to this issue.

Additionally, Snort-2.9.6.0 is in the tree, so test against that, too, if you can.