suricata
app-layer-htp-range.c
Go to the documentation of this file.
1 /* Copyright (C) 2021 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Philippe Antoine <p.antoine@catenacyber.fr>
22  */
23 
24 #include "suricata-common.h"
25 #include "app-layer-htp-range.h"
26 #include "util-misc.h" //ParseSizeStringU64
27 #include "util-thash.h" //HashTable
28 #include "util-memcmp.h" //SCBufferCmp
29 #include "util-hash-string.h" //StringHashDjb2
30 #include "util-validate.h" //DEBUG_VALIDATE_BUG_ON
31 #include "util-byte.h" //StringParseUint32
32 
33 typedef struct ContainerTHashTable {
35  uint32_t timeout;
37 
38 // globals
40 
41 static void HttpRangeBlockDerefContainer(HttpRangeContainerBlock *b);
42 
43 #define CONTAINER_URLRANGE_HASH_SIZE 256
44 
46 {
47  // lexical order : start, buflen, offset
48  if (a->start > b->start)
49  return 1;
50  if (a->start < b->start)
51  return -1;
52  if (a->buflen > b->buflen)
53  return 1;
54  if (a->buflen < b->buflen)
55  return -1;
56  if (a->offset > b->offset)
57  return 1;
58  if (a->offset < b->offset)
59  return -1;
60  return 0;
61 }
62 
64 
65 static int ContainerUrlRangeSet(void *dst, void *src)
66 {
67  HttpRangeContainerFile *src_s = src;
68  HttpRangeContainerFile *dst_s = dst;
69  dst_s->len = src_s->len;
70  dst_s->key = SCMalloc(dst_s->len);
71  if (dst_s->key == NULL)
72  return -1;
73  memcpy(dst_s->key, src_s->key, dst_s->len);
74  dst_s->files = FileContainerAlloc();
75  if (dst_s->files == NULL) {
76  SCFree(dst_s->key);
77  return -1;
78  }
79  RB_INIT(&dst_s->fragment_tree);
80  dst_s->flags = 0;
81  dst_s->lastsize = 0;
82  dst_s->totalsize = 0;
83  dst_s->hdata = NULL;
84  dst_s->error = false;
85  return 0;
86 }
87 
88 static bool ContainerUrlRangeCompare(void *a, void *b)
89 {
90  const HttpRangeContainerFile *as = a;
91  const HttpRangeContainerFile *bs = b;
92 
93  /* ranges in the error state should not be found so they can
94  * be evicted */
95  if (as->error || bs->error) {
96  return false;
97  }
98 
99  if (SCBufferCmp(as->key, as->len, bs->key, bs->len) == 0) {
100  return true;
101  }
102  return false;
103 }
104 
105 static uint32_t ContainerUrlRangeHash(void *s)
106 {
107  HttpRangeContainerFile *cur = s;
108  uint32_t h = StringHashDjb2(cur->key, cur->len);
109  return h;
110 }
111 
112 // base data stays in hash
113 static void ContainerUrlRangeFree(void *s)
114 {
115  HttpRangeContainerBuffer *range = NULL, *tmp = NULL;
116 
117  HttpRangeContainerFile *cu = s;
118  SCFree(cu->key);
119  cu->key = NULL;
121  cu->files = NULL;
122  RB_FOREACH_SAFE (range, HTTP_RANGES, &cu->fragment_tree, tmp) {
123  RB_REMOVE(HTTP_RANGES, &cu->fragment_tree, range);
124  SCFree(range->buffer);
125  (void)SC_ATOMIC_SUB(ContainerUrlRangeList.ht->memuse, range->buflen);
126  SCFree(range);
127  }
128 }
129 
130 static inline bool ContainerValueRangeTimeout(HttpRangeContainerFile *cu, struct timeval *ts)
131 {
132  // we only timeout if we have no flow referencing us
133  if ((uint32_t)ts->tv_sec > cu->expire || cu->error) {
134  if (SC_ATOMIC_GET(cu->hdata->use_cnt) == 0) {
135  DEBUG_VALIDATE_BUG_ON(cu->files == NULL);
136  return true;
137  }
138  }
139  return false;
140 }
141 
142 static void ContainerUrlRangeUpdate(HttpRangeContainerFile *cu, uint32_t expire)
143 {
144  cu->expire = expire;
145 }
146 
147 #define HTTP_RANGE_DEFAULT_TIMEOUT 60
148 #define HTTP_RANGE_DEFAULT_MEMCAP 100 * 1024 * 1024
149 
151 {
152  SCLogDebug("containers start");
153  const char *str = NULL;
154  uint64_t memcap = HTTP_RANGE_DEFAULT_MEMCAP;
155  uint32_t timeout = HTTP_RANGE_DEFAULT_TIMEOUT;
156  if (ConfGet("app-layer.protocols.http.byterange.memcap", &str) == 1) {
157  if (ParseSizeStringU64(str, &memcap) < 0) {
159  "memcap value cannot be deduced: %s,"
160  " resetting to default",
161  str);
162  memcap = 0;
163  }
164  }
165  if (ConfGet("app-layer.protocols.http.byterange.timeout", &str) == 1) {
166  size_t slen = strlen(str);
167  if (slen > UINT16_MAX || StringParseUint32(&timeout, 10, (uint16_t)slen, str) <= 0) {
169  "timeout value cannot be deduced: %s,"
170  " resetting to default",
171  str);
172  timeout = 0;
173  }
174  }
175 
177  THashInit("app-layer.protocols.http.byterange", sizeof(HttpRangeContainerFile),
178  ContainerUrlRangeSet, ContainerUrlRangeFree, ContainerUrlRangeHash,
179  ContainerUrlRangeCompare, false, memcap, CONTAINER_URLRANGE_HASH_SIZE);
180  ContainerUrlRangeList.timeout = timeout;
181 
182  SCLogDebug("containers started");
183 }
184 
186 {
188 }
189 
190 uint32_t HttpRangeContainersTimeoutHash(struct timeval *ts)
191 {
192  SCLogDebug("timeout: starting");
193  uint32_t cnt = 0;
194 
195  for (uint32_t i = 0; i < ContainerUrlRangeList.ht->config.hash_size; i++) {
196  THashHashRow *hb = &ContainerUrlRangeList.ht->array[i];
197 
198  if (HRLOCK_TRYLOCK(hb) != 0)
199  continue;
200  /* hash bucket is now locked */
201  THashData *h = hb->head;
202  while (h) {
203  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(h->use_cnt) > (uint32_t)INT_MAX);
204  THashData *n = h->next;
205  THashDataLock(h);
206  if (ContainerValueRangeTimeout(h->data, ts)) {
207  /* remove from the hash */
208  if (h->prev != NULL)
209  h->prev->next = h->next;
210  if (h->next != NULL)
211  h->next->prev = h->prev;
212  if (hb->head == h)
213  hb->head = h->next;
214  if (hb->tail == h)
215  hb->tail = h->prev;
216  h->next = NULL;
217  h->prev = NULL;
218  // we should log the timed out file somehow...
219  // but it does not belong to any flow...
220  SCLogDebug("timeout: removing range %p", h);
221  ContainerUrlRangeFree(h->data); // TODO do we need a "RECYCLE" func?
222  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(h->use_cnt) > (uint32_t)INT_MAX);
223  THashDataUnlock(h);
225  } else {
226  THashDataUnlock(h);
227  }
228  h = n;
229  }
230  HRLOCK_UNLOCK(hb);
231  }
232 
233  SCLogDebug("timeout: ending");
234  return cnt;
235 }
236 
237 /**
238  * \returns locked data
239  */
240 static void *HttpRangeContainerUrlGet(const uint8_t *key, uint32_t keylen, const Flow *f)
241 {
242  const struct timeval *ts = &f->lastts;
243  HttpRangeContainerFile lookup;
244  memset(&lookup, 0, sizeof(lookup));
245  // cast so as not to have const in the structure
246  lookup.key = (uint8_t *)key;
247  lookup.len = keylen;
249  if (res.data) {
250  // nothing more to do if (res.is_new)
251  ContainerUrlRangeUpdate(res.data->data, ts->tv_sec + ContainerUrlRangeList.timeout);
252  HttpRangeContainerFile *c = res.data->data;
253  c->hdata = res.data;
254  SCLogDebug("c %p", c);
255  return res.data->data;
256  }
257  return NULL;
258 }
259 
260 static HttpRangeContainerBlock *HttpRangeOpenFileAux(HttpRangeContainerFile *c, uint64_t start,
261  uint64_t end, uint64_t total, const StreamingBufferConfig *sbcfg, const uint8_t *name,
262  uint16_t name_len, uint16_t flags)
263 {
264  if (c->files != NULL && c->files->tail == NULL) {
265  /* this is the first request, we open a single file in the file container
266  * this could be part of ContainerUrlRangeSet if we could have
267  * all the arguments there
268  */
269  if (FileOpenFileWithId(c->files, sbcfg, 0, name, name_len, NULL, 0, flags) != 0) {
270  SCLogDebug("open file for range failed");
271  return NULL;
272  }
273  }
275  if (curf == NULL) {
276  c->error = true;
277  return NULL;
278  }
279  curf->files = NULL;
280  if (total > c->totalsize) {
281  // we grow to the maximum size indicated by different range requests
282  // we could add some warning/app-layer event in this case where
283  // different range requests indicate different total sizes
284  c->totalsize = total;
285  }
286  const uint64_t buflen = end - start + 1;
287 
288  /* The big part of this function is now to decide which kind of HttpRangeContainerBlock
289  * we will return :
290  * - skipping already processed data
291  * - storing out of order data for later use
292  * - directly appending to the file if we are at the right offset
293  */
294  if (start == c->lastsize && c->files != NULL) {
295  // easy case : append to current file
296  curf->container = c;
297  // If we see 2 duplicate range requests with the same range,
298  // the first one takes the ownership of the files container
299  // protected by the lock from caller HTPFileOpenWithRange
300  curf->files = c->files;
301  c->files = NULL;
302  return curf;
303  } else if (start < c->lastsize && c->lastsize - start >= buflen) {
304  // only overlap
305  // redundant to be explicit that this block is independent
306  curf->toskip = buflen;
307  return curf;
308  } else if (start < c->lastsize && c->lastsize - start < buflen && c->files != NULL) {
309  // some overlap, then some data to append to the file
310  curf->toskip = c->lastsize - start;
311  curf->files = c->files;
312  c->files = NULL;
313  curf->container = c;
314  return curf;
315  }
316  // Because we are not in the previous cases, we will store the data for later use
317 
318  // block/range to be inserted in ordered linked list
319  if (!(THASH_CHECK_MEMCAP(ContainerUrlRangeList.ht, buflen))) {
320  // skips this range
321  curf->toskip = buflen;
322  return curf;
323  }
324  curf->container = c;
325 
327  if (range == NULL) {
328  c->error = true;
329  SCFree(curf);
330  return NULL;
331  }
332 
333  (void)SC_ATOMIC_ADD(ContainerUrlRangeList.ht->memuse, buflen);
334  range->buffer = SCMalloc(buflen);
335  if (range->buffer == NULL) {
336  c->error = true;
337  SCFree(curf);
338  SCFree(range);
339  (void)SC_ATOMIC_SUB(ContainerUrlRangeList.ht->memuse, buflen);
340  return NULL;
341  }
342  range->buflen = buflen;
343  range->start = start;
344  range->offset = 0;
345  range->gap = 0;
346  curf->current = range;
347  return curf;
348 }
349 
350 static HttpRangeContainerBlock *HttpRangeOpenFile(HttpRangeContainerFile *c, uint64_t start,
351  uint64_t end, uint64_t total, const StreamingBufferConfig *sbcfg, const uint8_t *name,
352  uint16_t name_len, uint16_t flags, const uint8_t *data, uint32_t len)
353 {
355  HttpRangeOpenFileAux(c, start, end, total, sbcfg, name, name_len, flags);
356  if (HttpRangeAppendData(r, data, len) < 0) {
357  SCLogDebug("Failed to append data while openeing");
358  }
359  return r;
360 }
361 
362 HttpRangeContainerBlock *HttpRangeContainerOpenFile(const uint8_t *key, uint32_t keylen,
363  const Flow *f, const HTTPContentRange *crparsed, const StreamingBufferConfig *sbcfg,
364  const uint8_t *name, uint16_t name_len, uint16_t flags, const uint8_t *data,
365  uint32_t data_len)
366 {
367  HttpRangeContainerFile *file_range_container = HttpRangeContainerUrlGet(key, keylen, f);
368  if (file_range_container == NULL) {
369  // probably reached memcap
370  return NULL;
371  }
372  HttpRangeContainerBlock *r = HttpRangeOpenFile(file_range_container, crparsed->start,
373  crparsed->end, crparsed->size, sbcfg, name, name_len, flags, data, data_len);
374  SCLogDebug("s->file_range == %p", r);
375  if (r == NULL) {
376  THashDecrUsecnt(file_range_container->hdata);
378  SC_ATOMIC_GET(file_range_container->hdata->use_cnt) > (uint32_t)INT_MAX);
379  THashDataUnlock(file_range_container->hdata);
380 
381  // probably reached memcap
382  return NULL;
383  /* in some cases we don't take a reference, so decr use cnt */
384  } else if (r->container == NULL) {
385  THashDecrUsecnt(file_range_container->hdata);
386  } else {
387  SCLogDebug("container %p use_cnt %u", r, SC_ATOMIC_GET(r->container->hdata->use_cnt));
388  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(r->container->hdata->use_cnt) > (uint32_t)INT_MAX);
389  }
390 
391  /* we're done, so unlock. But since we have a reference in s->file_range keep use_cnt. */
392  THashDataUnlock(file_range_container->hdata);
393  return r;
394 }
395 
396 int HttpRangeAppendData(HttpRangeContainerBlock *c, const uint8_t *data, uint32_t len)
397 {
398  if (len == 0) {
399  return 0;
400  }
401  // first check if we need to skip all bytes
402  if (c->toskip >= len) {
403  c->toskip -= len;
404  return 0;
405  }
406  // then if we need to skip only some bytes
407  if (c->toskip > 0) {
408  int r = 0;
409  if (c->files) {
410  if (data == NULL) {
411  // gap overlaping already known data
412  r = FileAppendData(c->files, NULL, len - c->toskip);
413  } else {
414  r = FileAppendData(c->files, data + c->toskip, len - c->toskip);
415  }
416  }
417  c->toskip = 0;
418  return r;
419  }
420  // If we are owning the file to append to it, let's do it
421  if (c->files) {
422  SCLogDebug("update files (FileAppendData)");
423  return FileAppendData(c->files, data, len);
424  }
425  // Maybe we were in the skipping case,
426  // but we get more data than expected and had set c->toskip = 0
427  // so we need to check for last case with something to do
428  if (c->current) {
429  // So we have a current allocated buffer to copy to
430  // in the case of an unordered range being handled
431  SCLogDebug("update current: adding %u bytes to block %p", len, c);
432  // GAP "data"
433  if (data == NULL) {
434  // just save the length of the gap
435  c->current->gap += len;
436  // data, but we're not yet complete
437  } else if (c->current->offset + len < c->current->buflen) {
438  memcpy(c->current->buffer + c->current->offset, data, len);
439  c->current->offset += len;
440  // data, we're complete
441  } else if (c->current->offset + len == c->current->buflen) {
442  memcpy(c->current->buffer + c->current->offset, data, len);
443  c->current->offset += len;
444  // data, more than expected
445  } else {
446  memcpy(c->current->buffer + c->current->offset, data,
447  c->current->buflen - c->current->offset);
448  c->current->offset = c->current->buflen;
449  }
450  }
451  return 0;
452 }
453 
454 static void HttpRangeFileClose(HttpRangeContainerFile *c, uint16_t flags)
455 {
456  SCLogDebug("closing range %p flags %04x", c, flags);
457  DEBUG_VALIDATE_BUG_ON(SC_ATOMIC_GET(c->hdata->use_cnt) == 0);
458  // move ownership of file c->files->head to caller
459  FileCloseFile(c->files, NULL, 0, c->flags | flags);
460  c->files->head = NULL;
461  c->files->tail = NULL;
462 }
463 
464 /**
465  * \note if `f` is non-NULL, the ownership of the file is transfered to the caller.
466  */
468 {
469  SCLogDebug("c %p c->container %p c->current %p", c, c->container, c->current);
470 
471  DEBUG_VALIDATE_BUG_ON(c->container == NULL);
472 
473  /* we're processing an OOO chunk, won't be able to get us a full file just yet */
474  if (c->current) {
475  SCLogDebug("processing ooo chunk as c->current is set %p", c->current);
476  // some out-or-order range is finished
477  if (c->container->lastsize >= c->current->start + c->current->offset) {
478  // if the range has become obsolete because we received the data already
479  // we just free it
481  SCFree(c->current->buffer);
482  SCFree(c->current);
483  c->current = NULL;
484  SCLogDebug("c->current was obsolete");
485  return NULL;
486  } else {
487  /* otherwise insert in red and black tree. If res != NULL, the insert
488  failed because its a dup. */
490  HTTP_RANGES_RB_INSERT(&c->container->fragment_tree, c->current);
491  if (res) {
492  SCLogDebug("duplicate range fragment");
494  SCFree(c->current->buffer);
495  SCFree(c->current);
496  c->current = NULL;
497  return NULL;
498  }
499  SCLogDebug("inserted range fragment");
500  c->current = NULL;
501  if (c->container->files == NULL) {
502  // we have to wait for the flow owning the file
503  return NULL;
504  }
505  if (c->container->files->tail == NULL) {
506  // file has already been closed meanwhile
507  return NULL;
508  }
509  // keep on going, maybe this out of order chunk
510  // became the missing part between open and close
511  }
512  SCLogDebug("c->current was set, file incomplete so return NULL");
513  } else if (c->toskip > 0) {
514  // was only an overlapping range, truncated before new bytes
515  SCLogDebug("c->toskip %" PRIu64, c->toskip);
516  if (c->files) {
517  // if we expected new bytes after overlap
518  c->container->files = c->files;
519  c->files = NULL;
520  }
521  return NULL;
522  } else {
523  // we just finished an in-order block
524  DEBUG_VALIDATE_BUG_ON(c->files == NULL);
525  // move back the ownership of the file container to HttpRangeContainerFile
526  c->container->files = c->files;
527  c->files = NULL;
529  }
530 
531  File *f = c->container->files->tail;
532 
533  /* See if we can use our stored fragments to (partly) reconstruct the file */
534  HttpRangeContainerBuffer *range, *safe = NULL;
535  RB_FOREACH_SAFE (range, HTTP_RANGES, &c->container->fragment_tree, safe) {
536  if (f->size < range->start) {
537  // this next range is not reached yet
538  break;
539  }
540  if (f->size == range->start) {
541  // a new range just begins where we ended, append it
542  if (range->gap > 0) {
543  // if the range had a gap, begin by it
544  if (FileAppendData(c->container->files, NULL, range->gap) != 0) {
545  c->container->lastsize = f->size;
546  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
547  c->container->error = true;
548  return f;
549  }
550  }
551  if (FileAppendData(c->container->files, range->buffer, range->offset) != 0) {
552  c->container->lastsize = f->size;
553  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
554  c->container->error = true;
555  return f;
556  }
557  } else {
558  // the range starts before where we ended
559  uint64_t overlap = f->size - range->start;
560  if (overlap < range->offset) {
561  if (range->gap > 0) {
562  // if the range had a gap, begin by it
563  if (FileAppendData(c->container->files, NULL, range->gap) != 0) {
564  c->container->lastsize = f->size;
565  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
566  c->container->error = true;
567  return f;
568  }
569  }
570  // And the range ends beyond where we ended
571  // in this case of overlap, only add the extra data
572  if (FileAppendData(c->container->files, range->buffer + overlap,
573  range->offset - overlap) != 0) {
574  c->container->lastsize = f->size;
575  HttpRangeFileClose(c->container, flags | FILE_TRUNCATED);
576  c->container->error = true;
577  return f;
578  }
579  }
580  }
581  /* Remove this range from the tree */
582  HTTP_RANGES_RB_REMOVE(&c->container->fragment_tree, range);
583  (void)SC_ATOMIC_SUB(ContainerUrlRangeList.ht->memuse, range->buflen);
584  SCFree(range->buffer);
585  SCFree(range);
586  }
587  // wait until we merged all the buffers to update known size
588  c->container->lastsize = f->size;
589 
590  if (f->size >= c->container->totalsize) {
591  // we finished the whole file
592  HttpRangeFileClose(c->container, flags);
593  } else {
594  // we are expecting more ranges
595  f = NULL;
596  SCLogDebug("expecting more use_cnt %u", SC_ATOMIC_GET(c->container->hdata->use_cnt));
597  }
598  SCLogDebug("returning f %p (c:%p container:%p)", f, c, c->container);
599  return f;
600 }
601 
602 static void HttpRangeBlockDerefContainer(HttpRangeContainerBlock *b)
603 {
604  if (b && b->container) {
607  b->container = NULL;
608  }
609 }
610 
612 {
613  if (b) {
614  HttpRangeBlockDerefContainer(b);
615 
616  if (b->current) {
618  SCFree(b->current->buffer);
619  SCFree(b->current);
620  }
621  // we did not move ownership of the file container back to HttpRangeContainerFile
622  DEBUG_VALIDATE_BUG_ON(b->files != NULL);
623  if (b->files != NULL) {
625  b->files = NULL;
626  }
627  SCFree(b);
628  }
629 }
HttpRangeContainerBuffer::gap
uint64_t gap
Definition: app-layer-htp-range.h:43
util-byte.h
HttpRangeContainerBuffer::buffer
uint8_t * buffer
Definition: app-layer-htp-range.h:35
FILE_TRUNCATED
#define FILE_TRUNCATED
Definition: util-file.h:45
util-hash-string.h
len
uint8_t len
Definition: app-layer-dnp3.h:2
ts
uint64_t ts
Definition: source-erf-file.c:55
app-layer-htp-range.h
HttpRangeContainerBuffer::buflen
uint64_t buflen
Definition: app-layer-htp-range.h:37
THashDataGetResult::data
THashData * data
Definition: util-thash.h:205
offset
uint64_t offset
Definition: util-streaming-buffer.h:0
SC_ERR_INVALID_VALUE
@ SC_ERR_INVALID_VALUE
Definition: util-error.h:160
FileContainerAlloc
FileContainer * FileContainerAlloc(void)
allocate a FileContainer
Definition: util-file.c:490
RB_REMOVE
#define RB_REMOVE(name, x, y)
Definition: tree.h:773
File_::size
uint64_t size
Definition: util-file.h:102
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:296
ParseSizeStringU64
int ParseSizeStringU64(const char *size, uint64_t *res)
Definition: util-misc.c:200
HttpRangeContainerFile::files
FileContainer * files
Definition: app-layer-htp-range.h:74
THashData_::prev
struct THashData_ * prev
Definition: util-thash.h:95
Flow_
Flow data structure.
Definition: flow.h:356
HTTP_RANGE_DEFAULT_MEMCAP
#define HTTP_RANGE_DEFAULT_MEMCAP
Definition: app-layer-htp-range.c:148
SC_ATOMIC_ADD
#define SC_ATOMIC_ADD(name, val)
add a value to our atomic variable
Definition: util-atomic.h:333
HttpRangeContainerBuffer::start
uint64_t start
Definition: app-layer-htp-range.h:39
HttpRangeContainerFile::error
bool error
Definition: app-layer-htp-range.h:80
THashData_::next
struct THashData_ * next
Definition: util-thash.h:94
HttpRangeContainerOpenFile
HttpRangeContainerBlock * HttpRangeContainerOpenFile(const uint8_t *key, uint32_t keylen, const Flow *f, const HTTPContentRange *crparsed, const StreamingBufferConfig *sbcfg, const uint8_t *name, uint16_t name_len, uint16_t flags, const uint8_t *data, uint32_t data_len)
Definition: app-layer-htp-range.c:362
FileContainer_::tail
File * tail
Definition: util-file.h:115
HttpRangeContainerBufferCompare
int HttpRangeContainerBufferCompare(HttpRangeContainerBuffer *a, HttpRangeContainerBuffer *b)
Definition: app-layer-htp-range.c:45
FileAppendData
int FileAppendData(FileContainer *ffc, const uint8_t *data, uint32_t data_len)
Store/handle a chunk of file data in the File structure The last file in the FileContainer will be us...
Definition: util-file.c:774
HttpRangeContainerBlock::toskip
uint64_t toskip
Definition: app-layer-htp-range.h:90
HttpRangeContainerFile::flags
uint16_t flags
Definition: app-layer-htp-range.h:78
util-memcmp.h
HttpRangeContainerBlock
Definition: app-layer-htp-range.h:88
ConfGet
int ConfGet(const char *name, const char **vptr)
Retrieve the value of a configuration node.
Definition: conf.c:331
HRLOCK_UNLOCK
#define HRLOCK_UNLOCK(fb)
Definition: host.h:53
HttpRangeContainerFile
Definition: app-layer-htp-range.h:60
THashDataConfig_::hash_size
uint32_t hash_size
Definition: util-thash.h:130
RB_INIT
#define RB_INIT(root)
Definition: tree.h:308
RB_GENERATE
RB_GENERATE(HTTP_RANGES, HttpRangeContainerBuffer, rb, HttpRangeContainerBufferCompare)
HttpRangeClose
File * HttpRangeClose(HttpRangeContainerBlock *c, uint16_t flags)
Definition: app-layer-htp-range.c:467
THashTableContext_
Definition: util-thash.h:142
HttpRangeContainerFile::lastsize
uint64_t lastsize
Definition: app-layer-htp-range.h:72
HttpRangeContainersInit
void HttpRangeContainersInit(void)
Definition: app-layer-htp-range.c:150
RB_FOREACH_SAFE
#define RB_FOREACH_SAFE(x, name, head, y)
Definition: tree.h:791
FileContainer_::head
File * head
Definition: util-file.h:114
HttpRangeContainerBlock::current
HttpRangeContainerBuffer * current
Definition: app-layer-htp-range.h:92
ContainerTHashTable
struct ContainerTHashTable ContainerTHashTable
StringParseUint32
int StringParseUint32(uint32_t *res, int base, size_t len, const char *str)
Definition: util-byte.c:313
THashInit
THashTableContext * THashInit(const char *cnf_prefix, size_t data_size, int(*DataSet)(void *, void *), void(*DataFree)(void *), uint32_t(*DataHash)(void *), bool(*DataCompare)(void *, void *), bool reset_memcap, uint64_t memcap, uint32_t hashsize)
Definition: util-thash.c:294
THashTableContext_::array
THashHashRow * array
Definition: util-thash.h:144
SC_ATOMIC_SUB
#define SC_ATOMIC_SUB(name, val)
sub a value from our atomic variable
Definition: util-atomic.h:342
THashDataGetResult
Definition: util-thash.h:204
ContainerTHashTable
Definition: app-layer-htp-range.c:33
FileOpenFileWithId
int FileOpenFileWithId(FileContainer *ffc, const StreamingBufferConfig *sbcfg, uint32_t track_id, const uint8_t *name, uint16_t name_len, const uint8_t *data, uint32_t data_len, uint16_t flags)
Open a new File.
Definition: util-file.c:978
HttpRangeContainerFile::expire
uint32_t expire
Definition: app-layer-htp-range.h:66
THashDataMoveToSpare
void THashDataMoveToSpare(THashTableContext *ctx, THashData *h)
Definition: util-thash.c:41
HttpRangeContainerFile::key
uint8_t * key
Definition: app-layer-htp-range.h:62
HttpRangeContainersTimeoutHash
uint32_t HttpRangeContainersTimeoutHash(struct timeval *ts)
Definition: app-layer-htp-range.c:190
HttpRangeContainerFile::hdata
THashData * hdata
Definition: app-layer-htp-range.h:68
Flow_::lastts
struct timeval lastts
Definition: flow.h:417
THashShutdown
void THashShutdown(THashTableContext *ctx)
shutdown the flow engine
Definition: util-thash.c:346
HttpRangeContainerBlock::container
HttpRangeContainerFile * container
Definition: app-layer-htp-range.h:94
HttpRangeContainerBuffer::offset
uint64_t offset
Definition: app-layer-htp-range.h:41
File_
Definition: util-file.h:79
THashData_::data
void * data
Definition: util-thash.h:92
THashData_
Definition: util-thash.h:85
flags
uint8_t flags
Definition: decode-gre.h:0
ContainerTHashTable::timeout
uint32_t timeout
Definition: app-layer-htp-range.c:35
suricata-common.h
CONTAINER_URLRANGE_HASH_SIZE
#define CONTAINER_URLRANGE_HASH_SIZE
Definition: app-layer-htp-range.c:43
HttpRangeContainerFile::totalsize
uint64_t totalsize
Definition: app-layer-htp-range.h:70
HttpRangeContainerFile::len
uint32_t len
Definition: app-layer-htp-range.h:64
ContainerUrlRangeList
ContainerTHashTable ContainerUrlRangeList
Definition: app-layer-htp-range.c:39
THashGetFromHash
struct THashDataGetResult THashGetFromHash(THashTableContext *ctx, void *data)
Definition: util-thash.c:529
THashDecrUsecnt
#define THashDecrUsecnt(h)
Definition: util-thash.h:170
util-validate.h
StreamingBufferConfig_
Definition: util-streaming-buffer.h:64
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
HttpRangeFreeBlock
void HttpRangeFreeBlock(HttpRangeContainerBlock *b)
Definition: app-layer-htp-range.c:611
str
#define str(s)
Definition: suricata-common.h:280
SCLogWarning
#define SCLogWarning(err_code,...)
Macro used to log WARNING messages.
Definition: util-debug.h:242
SCFree
#define SCFree(p)
Definition: util-mem.h:61
src
uint16_t src
Definition: app-layer-dnp3.h:5
HRLOCK_TRYLOCK
#define HRLOCK_TRYLOCK(fb)
Definition: host.h:52
HttpRangeAppendData
int HttpRangeAppendData(HttpRangeContainerBlock *c, const uint8_t *data, uint32_t len)
Definition: app-layer-htp-range.c:396
HttpRangeContainersDestroy
void HttpRangeContainersDestroy(void)
Definition: app-layer-htp-range.c:185
HttpRangeContainerFile::fragment_tree
struct HTTP_RANGES fragment_tree
Definition: app-layer-htp-range.h:76
ContainerTHashTable::ht
THashTableContext * ht
Definition: app-layer-htp-range.c:34
FileContainerFree
void FileContainerFree(FileContainer *ffc)
Free a FileContainer.
Definition: util-file.c:527
SC_ATOMIC_GET
#define SC_ATOMIC_GET(name)
Get the value from the atomic variable.
Definition: util-atomic.h:376
dst
uint16_t dst
Definition: app-layer-dnp3.h:4
util-misc.h
util-thash.h
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
FileCloseFile
int FileCloseFile(FileContainer *ffc, const uint8_t *data, uint32_t data_len, uint16_t flags)
Close a File.
Definition: util-file.c:1074
THASH_CHECK_MEMCAP
#define THASH_CHECK_MEMCAP(ctx, size)
check if a memory alloc would fit in the memcap
Definition: util-thash.h:165
HttpRangeContainerBlock::files
FileContainer * files
Definition: app-layer-htp-range.h:96
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:111
HTTP_RANGE_DEFAULT_TIMEOUT
#define HTTP_RANGE_DEFAULT_TIMEOUT
Definition: app-layer-htp-range.c:147
HttpRangeContainerBuffer
Definition: app-layer-htp-range.h:31
StringHashDjb2
uint32_t StringHashDjb2(const uint8_t *data, uint32_t datalen)
Definition: util-hash-string.c:22
THashTableContext_::config
THashConfig config
Definition: util-thash.h:152