suricata
app-layer-htp-file.h File Reference
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Functions

int HTPFileOpen (HtpState *, const uint8_t *, uint16_t, const uint8_t *, uint32_t, uint64_t, uint8_t)
 Open the file with "filename" and pass the first chunk of data if any. More...
 
int HTPFileStoreChunk (HtpState *, const uint8_t *, uint32_t, uint8_t)
 Store a chunk of data in the flow. More...
 
int HTPFileClose (HtpState *, const uint8_t *, uint32_t, uint8_t, uint8_t)
 Close the file in the flow. More...
 
void HTPFileParserRegisterTests (void)
 

Detailed Description

Function Documentation

int HTPFileClose ( HtpState s,
const uint8_t *  data,
uint32_t  data_len,
uint8_t  flags,
uint8_t  direction 
)

Close the file in the flow.

Parameters
shttp state
datadata chunk if any
data_lenlength of the data portion
flagsflags to indicate events
directionflow direction

Currently on the FLOW_FILE_TRUNCATED flag is implemented, indicating that the file isn't complete but we're stopping storing it.

Return values
0ok
-1error
-2not storing files on this flow/tx

Definition at line 219 of file app-layer-htp-file.c.

References Flow_::alproto, ALPROTO_HTTP, Flow_::alstate, AppLayerParserGetEventsByTx(), AppLayerParserGetTx(), AppLayerParserParse(), AppLayerParserThreadCtxAlloc(), AppLayerParserThreadCtxFree(), AppLayerDecoderEvents_::cnt, FILE_STATE_CLOSED, FileCloseFile(), FileDataSize(), FilePrune(), HtpState_::files_tc, HtpState_::files_ts, FLOWLOCK_UNLOCK, FLOWLOCK_WRLOCK, FileContainer_::head, File_::next, Flow_::proto, Flow_::protoctx, File_::sb, SCEnter, SCLogDebug, SCReturnInt, File_::state, STREAM_EOF, STREAM_START, STREAM_TOCLIENT, STREAM_TOSERVER, StreamingBufferCompareRawData(), StreamTcpFreeConfig(), StreamTcpInitConfig(), FileContainer_::tail, TRUE, UTHBuildFlow(), and UTHFreeFlow().

Referenced by HTPFreeConfig().

Here is the call graph for this function:

Here is the caller graph for this function:

int HTPFileOpen ( HtpState s,
const uint8_t *  filename,
uint16_t  filename_len,
const uint8_t *  data,
uint32_t  data_len,
uint64_t  txid,
uint8_t  direction 
)

Open the file with "filename" and pass the first chunk of data if any.

Parameters
shttp state
filenamename of the file
filename_lenlength of the name
datadata chunk (if any)
data_lenlength of the data portion
directionflow direction
Return values
0ok
-1error
-2not handling files on this flow

Definition at line 79 of file app-layer-htp-file.c.

References HtpState_::cfg, HtpState_::f, Flow_::file_flags, FILE_NOSTORE, FILE_STORE, FileContainerAlloc(), FileFlowToFlags(), FileOpenFile(), FilePrune(), HtpState_::files_tc, HtpState_::files_ts, FileSetTx(), flags, HtpState_::flags, FLOWFILE_NO_STORE_TC, FLOWFILE_NO_STORE_TS, HTP_FLAG_STORE_FILES_TC, HTP_FLAG_STORE_FILES_TS, HTP_FLAG_STORE_FILES_TX_TC, HTP_FLAG_STORE_FILES_TX_TS, HTPCfgRec_::request, HTPCfgRec_::response, HTPCfgDir_::sbcfg, SCLogDebug, SCReturnInt, HtpState_::store_tx_id, STREAM_TOCLIENT, STREAM_TOSERVER, and FileContainer_::tail.

Here is the call graph for this function:

void HTPFileParserRegisterTests ( void  )

Definition at line 1583 of file app-layer-htp-file.c.

References UtRegisterTest().

Referenced by HTPParserRegisterTests().

Here is the call graph for this function:

Here is the caller graph for this function:

int HTPFileStoreChunk ( HtpState s,
const uint8_t *  data,
uint32_t  data_len,
uint8_t  direction 
)

Store a chunk of data in the flow.

Parameters
shttp state
datadata chunk (if any)
data_lenlength of the data portion
directionflow direction
Return values
0ok
-1error
-2file doesn't need storing

Definition at line 165 of file app-layer-htp-file.c.

References FileAppendData(), FilePrune(), HtpState_::files_tc, HtpState_::files_ts, SCEnter, SCLogDebug, SCReturnInt, and STREAM_TOCLIENT.

Here is the call graph for this function: