suricata
app-layer-htp-range.c
Go to the documentation of this file.
1 /* Copyright (C) 2021 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Philippe Antoine <p.antoine@catenacyber.fr>
22  */
23 
24 #include "suricata-common.h"
25 #include "app-layer-htp-range.h"
26 #include "util-misc.h" //ParseSizeStringU64
27 #include "util-thash.h" //HashTable
28 #include "util-memcmp.h" //SCBufferCmp
29 #include "util-hash-string.h" //StringHashDjb2
30 #include "util-validate.h" //DEBUG_VALIDATE_BUG_ON
31 #include "util-byte.h" //StringParseUint32
32 
33 typedef struct ContainerTHashTable {
35  uint32_t timeout;
37 
38 // globals
40 
41 static void HttpRangeBlockDerefContainer(HttpRangeContainerBlock *b);
42 
43 #define CONTAINER_URLRANGE_HASH_SIZE 256
44 
46 {
47  // lexical order : start, buflen, offset
48  if (a->start > b->start)
49  return 1;
50  if (a->start < b->start)
51  return -1;
52  if (a->buflen > b->buflen)
53  return 1;
54  if (a->buflen < b->buflen)
55  return -1;
56  if (a->offset > b->offset)
57  return 1;
58  if (a->offset < b->offset)
59  return -1;
60  return 0;
61 }
62 
64 
65 static int ContainerUrlRangeSet(void *dst, void *src)
66 {
67  HttpRangeContainerFile *src_s = src;
68  HttpRangeContainerFile *dst_s = dst;
69  dst_s->len = src_s->len;
70  dst_s->key = SCMalloc(dst_s->len);
71  if (dst_s->key == NULL)
72  return -1;
73  memcpy(dst_s->key, src_s->key, dst_s->len);
74  dst_s->files = FileContainerAlloc();
75  if (dst_s->files == NULL) {
76  SCFree(dst_s->key);
77  return -1;
78  }
79  RB_INIT(&dst_s->fragment_tree);
80  dst_s->flags = 0;
81  dst_s->lastsize = 0;
82  dst_s->totalsize = 0;
83  dst_s->hdata = NULL;
84  dst_s->error = false;
85  return 0;
86 }
87 
88 static bool ContainerUrlRangeCompare(void *a, void *b)
89 {
90  const HttpRangeContainerFile *as = a;
91  const HttpRangeContainerFile *bs = b;
92 
93  /* ranges in the error state should not be found so they can
94  * be evicted */
95  if (as->error || bs->error) {
96  return false;
97  }
98 
99  if (SCBufferCmp(as->key, as->len, bs->key, bs->len) == 0) {
100  return true;
101  }
102  return false;
103 }
104 
105 static uint32_t ContainerUrlRangeHash(void *s)
106 {
107  HttpRangeContainerFile *cur = s;
108  uint32_t h = StringHashDjb2(cur->key, cur->len);
109  return h;
110 }
111 
112 // base data stays in hash
113 static void ContainerUrlRangeFree(void *s)
114 {
115  HttpRangeContainerBuffer *range = NULL, *tmp = NULL;
116 
117  HttpRangeContainerFile *cu = s;
118  SCFree(cu->key);
119  cu->key = NULL;
121  cu->files = NULL;
122  RB_FOREACH_SAFE (range, HTTP_RANGES, &cu->fragment_tree, tmp) {
123  RB_REMOVE(HTTP_RANGES, &cu->fragment_tree, range);
124  SCFree(range->buffer);
125  (void)SC_ATOMIC_SUB(ContainerUrlRangeList.ht->memuse, range->buflen);
126  SCFree(range);
127  }
128 }
129 
130 static inline bool ContainerValueRangeTimeout(HttpRangeContainerFile *cu, struct timeval *ts)
131 {
132  // we only timeout if we have no flow referencing us
133  if ((uint32_t)ts->tv_sec > cu->expire || cu->error) {
134  if (SC_ATOMIC_GET(cu->hdata->use_cnt) == 0) {
135  DEBUG_VALIDATE_BUG_ON(cu->files == NULL);
136  return true;
137  }
138  }
139  return false;
140 }
141 
142 static void ContainerUrlRangeUpdate(HttpRangeContainerFile *cu, uint32_t expire)
143 {
144  cu->expire = expire;
145 }
146 
147 #define HTTP_RANGE_DEFAULT_TIMEOUT 60
148 #define HTTP_RANGE_DEFAULT_MEMCAP 100 * 1024 * 1024
149 
151 {
152  SCLogDebug("containers start");
153  const char *str = NULL;
154  uint64_t memcap = HTTP_RANGE_DEFAULT_MEMCAP;
155  uint32_t timeout = HTTP_RANGE_DEFAULT_TIMEOUT;
156  if (ConfGetValue("app-layer.protocols.http.byterange.memcap", &str) == 1) {
157  if (ParseSizeStringU64(str, &memcap) < 0) {
159  "memcap value cannot be deduced: %s,"
160  " resetting to default",
161  str);
162  memcap = 0;
163  }
164  }
165  if (ConfGetValue("app-layer.protocols.http.byterange.timeout", &str) == 1) {
166  if (StringParseUint32(&timeout, 10, strlen(str), str) <= 0) {
168  "timeout value cannot be deduced: %s,"
169  " resetting to default",
170  str);
171  timeout = 0;
172  }
173  }
174 
176  THashInit("app-layer.protocols.http.byterange", sizeof(HttpRangeContainerFile),
177  ContainerUrlRangeSet, ContainerUrlRangeFree, ContainerUrlRangeHash,
178  ContainerUrlRangeCompare, false, memcap, CONTAINER_URLRANGE_HASH_SIZE);
179  ContainerUrlRangeList.timeout = timeout;
180 
181  SCLogDebug("containers started");
182 }
183 
185 {
187 }
188 
189 uint32_t HttpRangeContainersTimeoutHash(struct timeval *ts)
190 {
191  SCLogDebug("timeout: starting");
192  uint32_t cnt = 0;
193 
194  for (uint32_t i = 0; i < ContainerUrlRangeList.ht->config.hash_size; i++) {
195  THashHashRow *hb = &ContainerUrlRangeList.ht->array[i];
196 
197  if (HRLOCK_TRYLOCK(hb) != 0)
198  continue;
199  /* hash bucket is now locked */
200  THashData *h = hb->head;
201  while (h) {
202  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(h->use_cnt) > (uint32_t)INT_MAX);
203  THashData *n = h->next;
204  THashDataLock(h);
205  if (ContainerValueRangeTimeout(h->data, ts)) {
206  /* remove from the hash */
207  if (h->prev != NULL)
208  h->prev->next = h->next;
209  if (h->next != NULL)
210  h->next->prev = h->prev;
211  if (hb->head == h)
212  hb->head = h->next;
213  if (hb->tail == h)
214  hb->tail = h->prev;
215  h->next = NULL;
216  h->prev = NULL;
217  // we should log the timed out file somehow...
218  // but it does not belong to any flow...
219  SCLogDebug("timeout: removing range %p", h);
220  ContainerUrlRangeFree(h->data); // TODO do we need a "RECYCLE" func?
221  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(h->use_cnt) > (uint32_t)INT_MAX);
222  THashDataUnlock(h);
224  } else {
225  THashDataUnlock(h);
226  }
227  h = n;
228  }
229  HRLOCK_UNLOCK(hb);
230  }
231 
232  SCLogDebug("timeout: ending");
233  return cnt;
234 }
235 
236 /**
237  * \returns locked data
238  */
239 static void *HttpRangeContainerUrlGet(const uint8_t *key, uint32_t keylen, const Flow *f)
240 {
241  const struct timeval *ts = &f->lastts;
242  HttpRangeContainerFile lookup;
243  memset(&lookup, 0, sizeof(lookup));
244  // cast so as not to have const in the structure
245  lookup.key = (uint8_t *)key;
246  lookup.len = keylen;
248  if (res.data) {
249  // nothing more to do if (res.is_new)
250  ContainerUrlRangeUpdate(res.data->data, ts->tv_sec + ContainerUrlRangeList.timeout);
251  HttpRangeContainerFile *c = res.data->data;
252  c->hdata = res.data;
253  SCLogDebug("c %p", c);
254  return res.data->data;
255  }
256  return NULL;
257 }
258 
259 static HttpRangeContainerBlock *HttpRangeOpenFileAux(HttpRangeContainerFile *c, uint64_t start,
260  uint64_t end, uint64_t total, const StreamingBufferConfig *sbcfg, const uint8_t *name,
261  uint16_t name_len, uint16_t flags)
262 {
263  if (c->files != NULL && c->files->tail == NULL) {
264  /* this is the first request, we open a single file in the file container
265  * this could be part of ContainerUrlRangeSet if we could have
266  * all the arguments there
267  */
268  if (FileOpenFileWithId(c->files, sbcfg, 0, name, name_len, NULL, 0, flags) != 0) {
269  SCLogDebug("open file for range failed");
270  return NULL;
271  }
272  }
274  if (curf == NULL) {
275  c->error = true;
276  return NULL;
277  }
278  curf->files = NULL;
279  if (total > c->totalsize) {
280  // we grow to the maximum size indicated by different range requests
281  // we could add some warning/app-layer event in this case where
282  // different range requests indicate different total sizes
283  c->totalsize = total;
284  }
285  const uint64_t buflen = end - start + 1;
286 
287  /* The big part of this function is now to decide which kind of HttpRangeContainerBlock
288  * we will return :
289  * - skipping already processed data
290  * - storing out of order data for later use
291  * - directly appending to the file if we are at the right offset
292  */
293  if (start == c->lastsize && c->files != NULL) {
294  // easy case : append to current file
295  curf->container = c;
296  // If we see 2 duplicate range requests with the same range,
297  // the first one takes the ownership of the files container
298  // protected by the lock from caller HTPFileOpenWithRange
299  curf->files = c->files;
300  c->files = NULL;
301  return curf;
302  } else if (start < c->lastsize && c->lastsize - start >= buflen) {
303  // only overlap
304  // redundant to be explicit that this block is independent
305  curf->toskip = buflen;
306  return curf;
307  } else if (start < c->lastsize && c->lastsize - start < buflen && c->files != NULL) {
308  // some overlap, then some data to append to the file
309  curf->toskip = c->lastsize - start;
310  curf->files = c->files;
311  c->files = NULL;
312  curf->container = c;
313  return curf;
314  }
315  // Because we are not in the previous cases, we will store the data for later use
316 
317  // block/range to be inserted in ordered linked list
318  if (!(THASH_CHECK_MEMCAP(ContainerUrlRangeList.ht, buflen))) {
319  // skips this range
320  curf->toskip = buflen;
321  return curf;
322  }
323  curf->container = c;
324 
326  if (range == NULL) {
327  c->error = true;
328  SCFree(curf);
329  return NULL;
330  }
331 
332  (void)SC_ATOMIC_ADD(ContainerUrlRangeList.ht->memuse, buflen);
333  range->buffer = SCMalloc(buflen);
334  if (range->buffer == NULL) {
335  c->error = true;
336  SCFree(curf);
337  SCFree(range);
338  (void)SC_ATOMIC_SUB(ContainerUrlRangeList.ht->memuse, buflen);
339  return NULL;
340  }
341  range->buflen = buflen;
342  range->start = start;
343  range->offset = 0;
344  range->gap = 0;
345  curf->current = range;
346  return curf;
347 }
348 
349 static HttpRangeContainerBlock *HttpRangeOpenFile(HttpRangeContainerFile *c, uint64_t start,
350  uint64_t end, uint64_t total, const StreamingBufferConfig *sbcfg, const uint8_t *name,
351  uint16_t name_len, uint16_t flags, const uint8_t *data, uint32_t len)
352 {
354  HttpRangeOpenFileAux(c, start, end, total, sbcfg, name, name_len, flags);
355  if (HttpRangeAppendData(r, data, len) < 0) {
356  SCLogDebug("Failed to append data while openeing");
357  }
358  return r;
359 }
360 
361 HttpRangeContainerBlock *HttpRangeContainerOpenFile(const uint8_t *key, uint32_t keylen,
362  const Flow *f, const HTTPContentRange *crparsed, const StreamingBufferConfig *sbcfg,
363  const uint8_t *name, uint16_t name_len, uint16_t flags, const uint8_t *data,
364  uint32_t data_len)
365 {
366  HttpRangeContainerFile *file_range_container = HttpRangeContainerUrlGet(key, keylen, f);
367  if (file_range_container == NULL) {
368  // probably reached memcap
369  return NULL;
370  }
371  HttpRangeContainerBlock *r = HttpRangeOpenFile(file_range_container, crparsed->start,
372  crparsed->end, crparsed->size, sbcfg, name, name_len, flags, data, data_len);
373  SCLogDebug("s->file_range == %p", r);
374  if (r == NULL) {
375  THashDecrUsecnt(file_range_container->hdata);
377  SC_ATOMIC_GET(file_range_container->hdata->use_cnt) > (uint32_t)INT_MAX);
378  THashDataUnlock(file_range_container->hdata);
379 
380  // probably reached memcap
381  return NULL;
382  /* in some cases we don't take a reference, so decr use cnt */
383  } else if (r->container == NULL) {
384  THashDecrUsecnt(file_range_container->hdata);
385  } else {
386  SCLogDebug("container %p use_cnt %u", r, SC_ATOMIC_GET(r->container->hdata->use_cnt));
387  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(r->container->hdata->use_cnt) > (uint32_t)INT_MAX);
388  }
389 
390  /* we're done, so unlock. But since we have a reference in s->file_range keep use_cnt. */
391  THashDataUnlock(file_range_container->hdata);
392  return r;
393 }
394 
395 int HttpRangeAppendData(HttpRangeContainerBlock *c, const uint8_t *data, uint32_t len)
396 {
397  if (len == 0) {
398  return 0;
399  }
400  // first check if we need to skip all bytes
401  if (c->toskip >= len) {
402  c->toskip -= len;
403  return 0;
404  }
405  // then if we need to skip only some bytes
406  if (c->toskip > 0) {
407  int r = 0;
408  if (c->files) {
409  if (data == NULL) {
410  // gap overlaping already known data
411  r = FileAppendData(c->files, NULL, len - c->toskip);
412  } else {
413  r = FileAppendData(c->files, data + c->toskip, len - c->toskip);
414  }
415  }
416  c->toskip = 0;
417  return r;
418  }
419  // If we are owning the file to append to it, let's do it
420  if (c->files) {
421  SCLogDebug("update files (FileAppendData)");
422  return FileAppendData(c->files, data, len);
423  }
424  // Maybe we were in the skipping case,
425  // but we get more data than expected and had set c->toskip = 0
426  // so we need to check for last case with something to do
427  if (c->current) {
428  // So we have a current allocated buffer to copy to
429  // in the case of an unordered range being handled
430  SCLogDebug("update current: adding %u bytes to block %p", len, c);
431  // GAP "data"
432  if (data == NULL) {
433  // just save the length of the gap
434  c->current->gap += len;
435  // data, but we're not yet complete
436  } else if (c->current->offset + len < c->current->buflen) {
437  memcpy(c->current->buffer + c->current->offset, data, len);
438  c->current->offset += len;
439  // data, we're complete
440  } else if (c->current->offset + len == c->current->buflen) {
441  memcpy(c->current->buffer + c->current->offset, data, len);
442  c->current->offset += len;
443  // data, more than expected
444  } else {
445  memcpy(c->current->buffer + c->current->offset, data,
446  c->current->buflen - c->current->offset);
447  c->current->offset = c->current->buflen;
448  }
449  }
450  return 0;
451 }
452 
453 static void HttpRangeFileClose(HttpRangeContainerFile *c, uint16_t flags)
454 {
455  SCLogDebug("closing range %p flags %04x", c, flags);
456  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(c->hdata->use_cnt) == 0);
457  // move ownership of file c->files->head to caller
458  FileCloseFile(c->files, NULL, 0, c->flags | flags);
459  c->files->head = NULL;
460  c->files->tail = NULL;
461 }
462 
463 /**
464  * \note if `f` is non-NULL, the ownership of the file is transfered to the caller.
465  */
467 {
468  SCLogDebug("c %p c->container %p c->current %p", c, c->container, c->current);
469 
470  DEBUG_VALIDATE_BUG_ON(c->container == NULL);
471 
472  /* we're processing an OOO chunk, won't be able to get us a full file just yet */
473  if (c->current) {
474  SCLogDebug("processing ooo chunk as c->current is set %p", c->current);
475  // some out-or-order range is finished
476  if (c->container->lastsize >= c->current->start + c->current->offset) {
477  // if the range has become obsolete because we received the data already
478  // we just free it
480  SCFree(c->current->buffer);
481  SCFree(c->current);
482  c->current = NULL;
483  SCLogDebug("c->current was obsolete");
484  return NULL;
485  } else {
486  /* otherwise insert in red and black tree. If res != NULL, the insert
487  failed because its a dup. */
489  HTTP_RANGES_RB_INSERT(&c->container->fragment_tree, c->current);
490  if (res) {
491  SCLogDebug("duplicate range fragment");
493  SCFree(c->current->buffer);
494  SCFree(c->current);
495  }
496  SCLogDebug("inserted range fragment");
497  c->current = NULL;
498  if (c->container->files == NULL) {
499  // we have to wait for the flow owning the file
500  return NULL;
501  }
502  // keep on going, maybe this out of order chunk
503  // became the missing part between open and close
504  }
505  SCLogDebug("c->current was set, file incomplete so return NULL");
506  } else if (c->toskip > 0) {
507  // was only an overlapping range, truncated before new bytes
508  SCLogDebug("c->toskip %" PRIu64, c->toskip);
509  if (c->files) {
510  // if we expected new bytes after overlap
511  c->container->files = c->files;
512  c->files = NULL;
513  }
514  return NULL;
515  } else {
516  // we just finished an in-order block
517  DEBUG_VALIDATE_BUG_ON(c->files == NULL);
518  // move back the ownership of the file container to HttpRangeContainerFile
519  c->container->files = c->files;
520  c->files = NULL;
522  }
523 
524  File *f = c->container->files->tail;
525 
526  /* See if we can use our stored fragments to (partly) reconstruct the file */
527  HttpRangeContainerBuffer *range, *safe = NULL;
528  RB_FOREACH_SAFE (range, HTTP_RANGES, &c->container->fragment_tree, safe) {
529  if (f->size < range->start) {
530  // this next range is not reached yet
531  break;
532  }
533  if (f->size == range->start) {
534  // a new range just begins where we ended, append it
535  if (range->gap > 0) {
536  // if the range had a gap, begin by it
537  if (FileAppendData(c->container->files, NULL, range->gap) != 0) {
538  c->container->lastsize = f->size;
539  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
540  c->container->error = true;
541  return f;
542  }
543  }
544  if (FileAppendData(c->container->files, range->buffer, range->offset) != 0) {
545  c->container->lastsize = f->size;
546  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
547  c->container->error = true;
548  return f;
549  }
550  } else {
551  // the range starts before where we ended
552  uint64_t overlap = f->size - range->start;
553  if (overlap < range->offset) {
554  if (range->gap > 0) {
555  // if the range had a gap, begin by it
556  if (FileAppendData(c->container->files, NULL, range->gap) != 0) {
557  c->container->lastsize = f->size;
558  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
559  c->container->error = true;
560  return f;
561  }
562  }
563  // And the range ends beyond where we ended
564  // in this case of overlap, only add the extra data
565  if (FileAppendData(c->container->files, range->buffer + overlap,
566  range->offset - overlap) != 0) {
567  c->container->lastsize = f->size;
568  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
569  c->container->error = true;
570  return f;
571  }
572  }
573  }
574  /* Remove this range from the tree */
575  HTTP_RANGES_RB_REMOVE(&c->container->fragment_tree, range);
576  (void)SC_ATOMIC_SUB(ContainerUrlRangeList.ht->memuse, range->buflen);
577  SCFree(range->buffer);
578  SCFree(range);
579  }
580  // wait until we merged all the buffers to update known size
581  c->container->lastsize = f->size;
582 
583  if (f->size >= c->container->totalsize) {
584  // we finished the whole file
585  HttpRangeFileClose(c->container, flags);
586  } else {
587  // we are expecting more ranges
588  f = NULL;
589  SCLogDebug("expecting more use_cnt %u", SC_ATOMIC_GET(c->container->hdata->use_cnt));
590  }
591  SCLogDebug("returning f %p (c:%p container:%p)", f, c, c->container);
592  return f;
593 }
594 
595 static void HttpRangeBlockDerefContainer(HttpRangeContainerBlock *b)
596 {
597  if (b && b->container) {
600  b->container = NULL;
601  }
602 }
603 
605 {
606  if (b) {
607  HttpRangeBlockDerefContainer(b);
608 
609  if (b->current) {
611  SCFree(b->current->buffer);
612  SCFree(b->current);
613  }
614  // we did not move ownership of the file container back to HttpRangeContainerFile
615  DEBUG_VALIDATE_BUG_ON(b->files != NULL);
616  if (b->files != NULL) {
618  b->files = NULL;
619  }
620  SCFree(b);
621  }
622 }
HttpRangeContainerBuffer::gap
uint64_t gap
Definition: app-layer-htp-range.h:44
util-byte.h
HttpRangeContainerBuffer::buffer
uint8_t * buffer
Definition: app-layer-htp-range.h:36
FILE_TRUNCATED
#define FILE_TRUNCATED
Definition: util-file.h:45
util-hash-string.h
len
uint8_t len
Definition: app-layer-dnp3.h:2
ts
uint64_t ts
Definition: source-erf-file.c:54
app-layer-htp-range.h
HttpRangeContainerBuffer::buflen
uint64_t buflen
Definition: app-layer-htp-range.h:38
THashDataGetResult::data
THashData * data
Definition: util-thash.h:206
offset
uint64_t offset
Definition: util-streaming-buffer.h:0
SC_ERR_INVALID_VALUE
@ SC_ERR_INVALID_VALUE
Definition: util-error.h:160
FileContainerAlloc
FileContainer * FileContainerAlloc(void)
allocate a FileContainer
Definition: util-file.c:426
RB_REMOVE
#define RB_REMOVE(name, x, y)
Definition: tree.h:773
File_::size
uint64_t size
Definition: util-file.h:96
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:298
ParseSizeStringU64
int ParseSizeStringU64(const char *size, uint64_t *res)
Definition: util-misc.c:200
HttpRangeContainerFile::files
FileContainer * files
Definition: app-layer-htp-range.h:75
THashData_::prev
struct THashData_ * prev
Definition: util-thash.h:96
Flow_
Flow data structure.
Definition: flow.h:353
HTTP_RANGE_DEFAULT_MEMCAP
#define HTTP_RANGE_DEFAULT_MEMCAP
Definition: app-layer-htp-range.c:148
SC_ATOMIC_ADD
#define SC_ATOMIC_ADD(name, val)
add a value to our atomic variable
Definition: util-atomic.h:333
HttpRangeContainerBuffer::start
uint64_t start
Definition: app-layer-htp-range.h:40
HttpRangeContainerFile::error
bool error
Definition: app-layer-htp-range.h:81
THashData_::next
struct THashData_ * next
Definition: util-thash.h:95
HttpRangeContainerOpenFile
HttpRangeContainerBlock * HttpRangeContainerOpenFile(const uint8_t *key, uint32_t keylen, const Flow *f, const HTTPContentRange *crparsed, const StreamingBufferConfig *sbcfg, const uint8_t *name, uint16_t name_len, uint16_t flags, const uint8_t *data, uint32_t data_len)
Definition: app-layer-htp-range.c:361
StringHashDjb2
uint32_t StringHashDjb2(uint8_t *data, uint32_t datalen)
Definition: util-hash-string.c:22
FileContainer_::tail
File * tail
Definition: util-file.h:109
HttpRangeContainerBufferCompare
int HttpRangeContainerBufferCompare(HttpRangeContainerBuffer *a, HttpRangeContainerBuffer *b)
Definition: app-layer-htp-range.c:45
FileAppendData
int FileAppendData(FileContainer *ffc, const uint8_t *data, uint32_t data_len)
Store/handle a chunk of file data in the File structure The last file in the FileContainer will be us...
Definition: util-file.c:720
HttpRangeContainerBlock::toskip
uint64_t toskip
Definition: app-layer-htp-range.h:91
HttpRangeContainerFile::flags
uint16_t flags
Definition: app-layer-htp-range.h:79
util-memcmp.h
HttpRangeContainerBlock
Definition: app-layer-htp-range.h:89
HRLOCK_UNLOCK
#define HRLOCK_UNLOCK(fb)
Definition: host.h:53
HttpRangeContainerFile
Definition: app-layer-htp-range.h:61
THashDataConfig_::hash_size
uint32_t hash_size
Definition: util-thash.h:131
RB_INIT
#define RB_INIT(root)
Definition: tree.h:308
RB_GENERATE
RB_GENERATE(HTTP_RANGES, HttpRangeContainerBuffer, rb, HttpRangeContainerBufferCompare)
HttpRangeClose
File * HttpRangeClose(HttpRangeContainerBlock *c, uint16_t flags)
Definition: app-layer-htp-range.c:466
THashTableContext_
Definition: util-thash.h:143
HttpRangeContainerFile::lastsize
uint64_t lastsize
Definition: app-layer-htp-range.h:73
res
PoolThreadReserved res
Definition: stream-tcp-private.h:0
HttpRangeContainersInit
void HttpRangeContainersInit(void)
Definition: app-layer-htp-range.c:150
RB_FOREACH_SAFE
#define RB_FOREACH_SAFE(x, name, head, y)
Definition: tree.h:791
FileContainer_::head
File * head
Definition: util-file.h:108
HttpRangeContainerBlock::current
HttpRangeContainerBuffer * current
Definition: app-layer-htp-range.h:93
ContainerTHashTable
struct ContainerTHashTable ContainerTHashTable
THashInit
THashTableContext * THashInit(const char *cnf_prefix, size_t data_size, int(*DataSet)(void *, void *), void(*DataFree)(void *), uint32_t(*DataHash)(void *), bool(*DataCompare)(void *, void *), bool reset_memcap, uint64_t memcap, uint32_t hashsize)
Definition: util-thash.c:296
THashTableContext_::array
THashHashRow * array
Definition: util-thash.h:145
SC_ATOMIC_SUB
#define SC_ATOMIC_SUB(name, val)
sub a value from our atomic variable
Definition: util-atomic.h:342
THashDataGetResult
Definition: util-thash.h:205
ContainerTHashTable
Definition: app-layer-htp-range.c:33
FileOpenFileWithId
int FileOpenFileWithId(FileContainer *ffc, const StreamingBufferConfig *sbcfg, uint32_t track_id, const uint8_t *name, uint16_t name_len, const uint8_t *data, uint32_t data_len, uint16_t flags)
Open a new File.
Definition: util-file.c:920
HttpRangeContainerFile::expire
uint32_t expire
Definition: app-layer-htp-range.h:67
THashDataMoveToSpare
void THashDataMoveToSpare(THashTableContext *ctx, THashData *h)
Definition: util-thash.c:41
HttpRangeContainerFile::key
uint8_t * key
Definition: app-layer-htp-range.h:63
HttpRangeContainersTimeoutHash
uint32_t HttpRangeContainersTimeoutHash(struct timeval *ts)
Definition: app-layer-htp-range.c:189
HttpRangeContainerFile::hdata
THashData * hdata
Definition: app-layer-htp-range.h:69
Flow_::lastts
struct timeval lastts
Definition: flow.h:414
THashShutdown
void THashShutdown(THashTableContext *ctx)
shutdown the flow engine
Definition: util-thash.c:348
HttpRangeContainerBlock::container
HttpRangeContainerFile * container
Definition: app-layer-htp-range.h:95
HttpRangeContainerBuffer::offset
uint64_t offset
Definition: app-layer-htp-range.h:42
File_
Definition: util-file.h:72
StringParseUint32
int StringParseUint32(uint32_t *res, int base, uint16_t len, const char *str)
Definition: util-byte.c:313
THashData_::data
void * data
Definition: util-thash.h:93
THashData_
Definition: util-thash.h:86
flags
uint8_t flags
Definition: decode-gre.h:0
ContainerTHashTable::timeout
uint32_t timeout
Definition: app-layer-htp-range.c:35
suricata-common.h
CONTAINER_URLRANGE_HASH_SIZE
#define CONTAINER_URLRANGE_HASH_SIZE
Definition: app-layer-htp-range.c:43
HttpRangeContainerFile::totalsize
uint64_t totalsize
Definition: app-layer-htp-range.h:71
HttpRangeContainerFile::len
uint32_t len
Definition: app-layer-htp-range.h:65
ContainerUrlRangeList
ContainerTHashTable ContainerUrlRangeList
Definition: app-layer-htp-range.c:39
THashGetFromHash
struct THashDataGetResult THashGetFromHash(THashTableContext *ctx, void *data)
Definition: util-thash.c:532
THashDecrUsecnt
#define THashDecrUsecnt(h)
Definition: util-thash.h:171
util-validate.h
StreamingBufferConfig_
Definition: util-streaming-buffer.h:67
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
HttpRangeFreeBlock
void HttpRangeFreeBlock(HttpRangeContainerBlock *b)
Definition: app-layer-htp-range.c:604
str
#define str(s)
Definition: suricata-common.h:272
SCLogWarning
#define SCLogWarning(err_code,...)
Macro used to log WARNING messages.
Definition: util-debug.h:244
SCFree
#define SCFree(p)
Definition: util-mem.h:61
src
uint16_t src
Definition: app-layer-dnp3.h:5
HRLOCK_TRYLOCK
#define HRLOCK_TRYLOCK(fb)
Definition: host.h:52
HttpRangeAppendData
int HttpRangeAppendData(HttpRangeContainerBlock *c, const uint8_t *data, uint32_t len)
Definition: app-layer-htp-range.c:395
ConfGetValue
int ConfGetValue(const char *name, const char **vptr)
Retrieve the value of a configuration node.
Definition: conf.c:359
HttpRangeContainersDestroy
void HttpRangeContainersDestroy(void)
Definition: app-layer-htp-range.c:184
HttpRangeContainerFile::fragment_tree
struct HTTP_RANGES fragment_tree
Definition: app-layer-htp-range.h:77
ContainerTHashTable::ht
THashTableContext * ht
Definition: app-layer-htp-range.c:34
FileContainerFree
void FileContainerFree(FileContainer *ffc)
Free a FileContainer.
Definition: util-file.c:462
SC_ATOMIC_GET
#define SC_ATOMIC_GET(name)
Get the value from the atomic variable.
Definition: util-atomic.h:376
dst
uint16_t dst
Definition: app-layer-dnp3.h:4
util-misc.h
util-thash.h
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
FileCloseFile
int FileCloseFile(FileContainer *ffc, const uint8_t *data, uint32_t data_len, uint16_t flags)
Close a File.
Definition: util-file.c:1008
THASH_CHECK_MEMCAP
#define THASH_CHECK_MEMCAP(ctx, size)
check if a memory alloc would fit in the memcap
Definition: util-thash.h:166
HttpRangeContainerBlock::files
FileContainer * files
Definition: app-layer-htp-range.h:97
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:111
HTTP_RANGE_DEFAULT_TIMEOUT
#define HTTP_RANGE_DEFAULT_TIMEOUT
Definition: app-layer-htp-range.c:147
HttpRangeContainerBuffer
Definition: app-layer-htp-range.h:32
THashTableContext_::config
THashConfig config
Definition: util-thash.h:153