suricata
app-layer-parser.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2026 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * Generic App-layer parsing functions.
24  */
25 
26 #include "suricata-common.h"
27 #include "app-layer-parser.h"
28 
29 #include "flow.h"
30 #include "flow-private.h"
31 #include "flow-util.h"
32 
33 #include "app-layer-frames.h"
34 #include "app-layer-events.h"
35 
36 #include "stream-tcp.h"
37 
38 #include "util-validate.h"
39 #include "util-config.h"
40 
41 #include "app-layer.h"
42 #include "app-layer-detect-proto.h"
43 
44 #include "app-layer-ftp.h"
45 #include "app-layer-smtp.h"
46 
47 #include "app-layer-smb.h"
48 #include "app-layer-htp.h"
49 #include "app-layer-ssl.h"
50 #include "app-layer-ssh.h"
51 #include "app-layer-modbus.h"
52 #include "app-layer-dnp3.h"
53 #include "app-layer-nfs-tcp.h"
54 #include "app-layer-nfs-udp.h"
55 #include "app-layer-tftp.h"
56 #include "app-layer-ike.h"
57 #include "app-layer-http2.h"
58 #include "app-layer-imap.h"
59 #include "conf.h"
60 #include "decode.h"
61 #include "detect.h"
62 #include "rust-bindings.h"
63 #include "rust.h"
64 #include "stream-tcp-reassemble.h"
65 #include "suricata.h"
66 #include "threadvars.h"
67 #include "util-debug.h"
68 #include "util-exception-policy.h"
69 #include "util-file.h"
70 #include "util-var.h"
71 
73  void *(*alproto_local_storage)[FLOW_PROTO_MAX];
74 };
75 
77  uint8_t sub_state;
81 };
82 
83 /**
84  * \brief App layer protocol parser context.
85  */
87 {
88  /* 0 - to_server, 1 - to_client. */
90 
91  bool logger;
92 
93  /* Indicates the direction the parser is ready to see the data
94  * the first time for a flow. Values accepted -
95  * STREAM_TOSERVER, STREAM_TOCLIENT */
96  uint8_t first_data_dir;
97 
98  uint32_t logger_bits; /**< registered loggers for this proto */
99 
100  void *(*StateAlloc)(void *, AppProto);
101  void (*StateFree)(void *);
102  void (*StateTransactionFree)(void *, uint64_t);
103  void *(*LocalStorageAlloc)(void);
104  void (*LocalStorageFree)(void *);
105 
106  /** get FileContainer reference from the TX. MUST return a non-NULL reference if the TX
107  * has or may have files in the requested direction at some point. */
108  AppLayerGetFileState (*GetTxFiles)(void *, uint8_t);
109 
110  int (*StateGetProgress)(void *alstate, uint8_t direction);
111  uint64_t (*StateGetTxCnt)(void *alstate);
112  void *(*StateGetTx)(void *alstate, uint64_t tx_id);
117  uint8_t event_id, const char **event_name, AppLayerEventType *event_type);
119  const char *event_name, uint8_t *event_id, AppLayerEventType *event_type);
120 
121  AppLayerStateData *(*GetStateData)(void *state);
122  AppLayerTxData *(*GetTxData)(void *tx);
123  void (*ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig);
124 
125  void (*SetStreamDepthFlag)(void *tx, uint8_t flags);
126 
129 
132 
133  /* each app-layer has its own value */
134  uint32_t stream_depth;
135 
136  /* Option flags such as supporting gaps or not. */
137  uint32_t option_flags;
138  /* coccinelle: AppLayerParserProtoCtx:option_flags:APP_LAYER_PARSER_OPT_ */
139 
140  uint32_t internal_flags;
141  /* coccinelle: AppLayerParserProtoCtx:internal_flags:APP_LAYER_PARSER_INT_ */
142 
143 #ifdef UNITTESTS
144  void (*RegisterUnittests)(void);
145 #endif
146 
147  /* list of mappings per sub state
148  * only set for FLOW_PROTO_DEFAULT */
150  /* max value of a sub state
151  * only set for FLOW_PROTO_DEFAULT */
152  uint8_t max_sub_state;
154 
155 typedef struct AppLayerParserCtx_ {
157  size_t ctxs_len;
159 
161  /* coccinelle: AppLayerParserState:flags:APP_LAYER_PARSER_ */
162  uint16_t flags;
163 
164  /* Indicates the current transaction that is being inspected.
165  * We have a var per direction. */
166  uint64_t inspect_id[2];
167  /* Indicates the current transaction being logged. Unlike inspect_id,
168  * we don't need a var per direction since we don't log a transaction
169  * unless we have the entire transaction. */
170  uint64_t log_id;
171 
172  uint64_t min_id;
173 
174  /* Used to store decoder events. */
176 
178 };
179 
181 
182 static void AppLayerConfig(void)
183 {
184  g_applayerparser_error_policy = ExceptionPolicyParse("app-layer.error-policy", true);
185 }
186 
188 {
190 }
191 
192 static void AppLayerParserFramesFreeContainer(FramesContainer *frames)
193 {
194  if (frames != NULL) {
195  FramesFree(&frames->toserver);
196  FramesFree(&frames->toclient);
197  SCFree(frames);
198  }
199 }
200 
202 {
203  if (f == NULL || f->alparser == NULL || f->alparser->frames == NULL)
204  return;
205  AppLayerParserFramesFreeContainer(f->alparser->frames);
206  f->alparser->frames = NULL;
207 }
208 
210 {
211  if (f == NULL || f->alparser == NULL)
212  return NULL;
213  return f->alparser->frames;
214 }
215 
217 {
218 #ifdef UNITTESTS
219  if (f == NULL || f->alparser == NULL || (f->proto == IPPROTO_TCP && f->protoctx == NULL))
220  return NULL;
221 #endif
222  DEBUG_VALIDATE_BUG_ON(f == NULL || f->alparser == NULL);
223  if (f->alparser->frames == NULL) {
224  f->alparser->frames = SCCalloc(1, sizeof(FramesContainer));
225  if (f->alparser->frames == NULL) {
226  return NULL;
227  }
228 #ifdef DEBUG
229  f->alparser->frames->toserver.ipproto = f->proto;
230  f->alparser->frames->toserver.alproto = f->alproto;
231  f->alparser->frames->toclient.ipproto = f->proto;
232  f->alparser->frames->toclient.alproto = f->alproto;
233 #endif
234  }
235  return f->alparser->frames;
236 }
237 
238 #ifdef UNITTESTS
239 void UTHAppLayerParserStateGetIds(void *ptr, uint64_t *i1, uint64_t *i2, uint64_t *log, uint64_t *min)
240 {
241  struct AppLayerParserState_ *s = ptr;
242  *i1 = s->inspect_id[0];
243  *i2 = s->inspect_id[1];
244  *log = s->log_id;
245  *min = s->min_id;
246 }
247 #endif
248 
249 /* Static global version of the parser context.
250  * Post 2.0 let's look at changing this to move it out to app-layer.c. */
251 static AppLayerParserCtx alp_ctx;
252 
253 int AppLayerParserProtoIsRegistered(uint8_t ipproto, AppProto alproto)
254 {
255  uint8_t ipproto_map = FlowGetProtoMapping(ipproto);
256 
257  return (alp_ctx.ctxs[alproto][ipproto_map].StateAlloc != NULL) ? 1 : 0;
258 }
259 
261 {
262  SCEnter();
263 
264  AppLayerParserState *pstate = (AppLayerParserState *)SCCalloc(1, sizeof(*pstate));
265  if (pstate == NULL)
266  goto end;
267 
268  end:
269  SCReturnPtr(pstate, "AppLayerParserState");
270 }
271 
273 {
274  SCEnter();
275 
276  if (pstate->decoder_events != NULL)
278  AppLayerParserFramesFreeContainer(pstate->frames);
279  SCFree(pstate);
280 
281  SCReturn;
282 }
283 
285 {
286  SCEnter();
287  // initial allocation that will later be grown using realloc,
288  // when new protocols register themselves and make g_alproto_max grow
290  if (unlikely(alp_ctx.ctxs == NULL)) {
291  FatalError("Unable to alloc alp_ctx.ctxs.");
292  }
293  alp_ctx.ctxs_len = g_alproto_max;
294  SCReturnInt(0);
295 }
296 
298 {
299  /* lets set a default value for stream_depth */
300  for (int flow_proto = 0; flow_proto < FLOW_PROTO_DEFAULT; flow_proto++) {
301  for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
302  if (!(alp_ctx.ctxs[alproto][flow_proto].internal_flags &
304  alp_ctx.ctxs[alproto][flow_proto].stream_depth = stream_config.reassembly_depth;
305  }
306  }
307  }
308 }
309 
311 {
312  SCEnter();
313 
314  /* inclusive loop as some parsers use FLOW_PROTO_DEFAULT */
315  for (int flow_proto = 0; flow_proto <= FLOW_PROTO_DEFAULT; flow_proto++) {
316  for (AppProto a = 0; a < g_alproto_max; a++) {
317  if (alp_ctx.ctxs[a][flow_proto].sub_state_mappings == NULL)
318  continue;
319 
320  while (alp_ctx.ctxs[a][flow_proto].sub_state_mappings) {
322  alp_ctx.ctxs[a][flow_proto].sub_state_mappings->next;
323  SCFree(alp_ctx.ctxs[a][flow_proto].sub_state_mappings);
324  alp_ctx.ctxs[a][flow_proto].sub_state_mappings = next;
325  }
326  }
327  }
328 
329  SCFree(alp_ctx.ctxs);
330 
333 
334  SCReturnInt(0);
335 }
336 
338 {
339  SCEnter();
340 
341  AppLayerParserThreadCtx *tctx = SCCalloc(1, sizeof(*tctx));
342  if (tctx == NULL)
343  goto end;
344 
346  if (unlikely(tctx->alproto_local_storage == NULL)) {
347  SCFree(tctx);
348  tctx = NULL;
349  goto end;
350  }
351  for (uint8_t flow_proto = 0; flow_proto < FLOW_PROTO_DEFAULT; flow_proto++) {
352  for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
353  uint8_t ipproto = FlowGetReverseProtoMapping(flow_proto);
354 
355  tctx->alproto_local_storage[alproto][flow_proto] =
357  }
358  }
359 
360  end:
361  SCReturnPtr(tctx, "void *");
362 }
363 
365 {
366  SCEnter();
367 
368  for (uint8_t flow_proto = 0; flow_proto < FLOW_PROTO_DEFAULT; flow_proto++) {
369  for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
370  uint8_t ipproto = FlowGetReverseProtoMapping(flow_proto);
371 
373  ipproto, alproto, tctx->alproto_local_storage[alproto][flow_proto]);
374  }
375  }
376 
378  SCFree(tctx);
379  SCReturn;
380 }
381 
382 /** \brief check if a parser is enabled in the config
383  * Returns enabled always if: were running unittests
384  */
385 int SCAppLayerParserConfParserEnabled(const char *ipproto, const char *alproto_name)
386 {
387  SCEnter();
388 
389  char param[100];
390  SCConfNode *g_proto, *i_proto;
391  bool g_enabled = false;
392  bool i_enabled = false;
393  int r;
394 
395  if (RunmodeIsUnittests())
396  SCReturnInt(1);
397 
398  r = snprintf(param, sizeof(param), "%s%s%s%s%s", "app-layer.protocols.", alproto_name, ".",
399  ipproto, ".enabled");
400  if (r < 0) {
401  FatalError("snprintf failure.");
402  } else if (r > (int)sizeof(param)) {
403  FatalError("buffer not big enough to write param.");
404  }
405  SCLogDebug("Looking for %s", param);
406 
407  i_proto = SCConfGetNode(param);
408  if (i_proto && i_proto->val) {
409  if (SCConfValIsTrue(i_proto->val)) {
410  i_enabled = true;
411  } else if (SCConfValIsFalse(i_proto->val)) {
412  i_enabled = false;
413  } else if (strcasecmp(i_proto->val, "detection-only") == 0) {
414  i_enabled = false;
415  } else {
416  FatalError("Invalid value found for %s.", param);
417  }
418  }
419 
420  r = snprintf(param, sizeof(param), "%s%s%s", "app-layer.protocols.", alproto_name, ".enabled");
421  if (r < 0) {
422  FatalError("snprintf failure.");
423  } else if (r > (int)sizeof(param)) {
424  FatalError("buffer not big enough to write param.");
425  }
426 
427  SCLogDebug("Looking for %s", param);
428  g_proto = SCConfGetNode(param);
429  if (g_proto && g_proto->val) {
430  if (SCConfValIsTrue(g_proto->val)) {
431  g_enabled = true;
432  } else if (SCConfValIsFalse(g_proto->val)) {
433  g_enabled = false;
434  } else if (strcasecmp(g_proto->val, "detection-only") == 0) {
435  g_enabled = false;
436  } else {
437  FatalError("Invalid value found for %s", param);
438  }
439  }
440 
441  if ((i_proto && g_proto) && (i_enabled ^ g_enabled)) {
442  /* these checks are also performed for detection-only, no need to issue double warning */
443  SCLogDebug("Inconsistent global (%s) and respective ipproto (%s) settings found for "
444  "alproto %s and ipproto %s",
445  g_enabled ? "TRUE" : "FALSE", i_enabled ? "TRUE" : "FALSE", alproto_name, ipproto);
446  }
447 
448  if (i_proto) {
449  SCReturnInt(i_enabled);
450  }
451  if (g_proto) {
452  SCReturnInt(g_enabled);
453  }
454 
455  SCReturnInt(1);
456 }
457 
458 /***** Parser related registration *****/
459 
460 int AppLayerParserRegisterParser(uint8_t ipproto, AppProto alproto,
461  uint8_t direction,
462  AppLayerParserFPtr Parser)
463 {
464  SCEnter();
465 
466  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)]
467  .Parser[(direction & STREAM_TOSERVER) ? 0 : 1] = Parser;
468 
469  SCReturnInt(0);
470 }
471 
473  uint8_t ipproto, AppProto alproto, uint8_t direction)
474 {
475  SCEnter();
476 
477  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].first_data_dir |=
478  (direction & (STREAM_TOSERVER | STREAM_TOCLIENT));
479 
480  SCReturn;
481 }
482 
483 void AppLayerParserRegisterOptionFlags(uint8_t ipproto, AppProto alproto,
484  uint32_t flags)
485 {
486  SCEnter();
487 
488  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].option_flags |= flags;
489 
490  SCReturn;
491 }
492 
493 void AppLayerParserRegisterStateFuncs(uint8_t ipproto, AppProto alproto,
494  void *(*StateAlloc)(void *, AppProto), void (*StateFree)(void *))
495 {
496  SCEnter();
497 
498  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateAlloc = StateAlloc;
499  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateFree = StateFree;
500 
501  SCReturn;
502 }
503 
504 void AppLayerParserRegisterLocalStorageFunc(uint8_t ipproto, AppProto alproto,
505  void *(*LocalStorageAlloc)(void),
506  void (*LocalStorageFree)(void *))
507 {
508  SCEnter();
509 
510  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageAlloc = LocalStorageAlloc;
511  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageFree = LocalStorageFree;
512 
513  SCReturn;
514 }
515 
517  uint8_t ipproto, AppProto alproto, AppLayerGetFileState (*GetTxFiles)(void *, uint8_t))
518 {
519  SCEnter();
520 
521  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxFiles = GetTxFiles;
522 
523  SCReturn;
524 }
525 
526 void AppLayerParserRegisterLoggerBits(uint8_t ipproto, AppProto alproto, LoggerId bits)
527 {
528  SCEnter();
529 
530  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].logger_bits = bits;
531 
532  SCReturn;
533 }
534 
535 void SCAppLayerParserRegisterLogger(uint8_t ipproto, AppProto alproto)
536 {
537  SCEnter();
538 
539  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].logger = true;
540 
541  SCReturn;
542 }
543 
545  int (*StateGetProgress)(void *alstate, uint8_t direction))
546 {
547  SCEnter();
548 
549  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetProgress = StateGetProgress;
550 
551  SCReturn;
552 }
553 
554 void AppLayerParserRegisterTxFreeFunc(uint8_t ipproto, AppProto alproto,
555  void (*StateTransactionFree)(void *, uint64_t))
556 {
557  SCEnter();
558 
559  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateTransactionFree = StateTransactionFree;
560 
561  SCReturn;
562 }
563 
564 void AppLayerParserRegisterGetTxCnt(uint8_t ipproto, AppProto alproto,
565  uint64_t (*StateGetTxCnt)(void *alstate))
566 {
567  SCEnter();
568 
569  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTxCnt = StateGetTxCnt;
570 
571  SCReturn;
572 }
573 
574 void AppLayerParserRegisterGetTx(uint8_t ipproto, AppProto alproto,
575  void *(StateGetTx)(void *alstate, uint64_t tx_id))
576 {
577  SCEnter();
578 
579  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTx = StateGetTx;
580 
581  SCReturn;
582 }
583 
584 void AppLayerParserRegisterGetTxIterator(uint8_t ipproto, AppProto alproto,
586 {
587  SCEnter();
588  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTxIterator = Func;
589  SCReturn;
590 }
591 
593  AppProto alproto, const int ts, const int tc)
594 {
595  BUG_ON(ts == 0);
596  BUG_ON(tc == 0);
597  BUG_ON(!AppProtoIsValid(alproto));
598  BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts != 0 &&
599  alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts != ts);
600  BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc != 0 &&
601  alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc != tc);
602 
603  alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts = ts;
604  alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc = tc;
605 }
606 
607 void AppLayerParserRegisterGetEventInfoById(uint8_t ipproto, AppProto alproto,
608  int (*StateGetEventInfoById)(
609  uint8_t event_id, const char **event_name, AppLayerEventType *event_type))
610 {
611  SCEnter();
612 
613  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetEventInfoById =
614  StateGetEventInfoById;
615 
616  SCReturn;
617 }
618 
620  AppLayerParserGetStateIdByNameFn GetIdByNameFunc,
621  AppLayerParserGetStateNameByIdFn GetNameByIdFunc)
622 {
623  SCEnter();
624  /* validate input */
625  BUG_ON(sub_state == 0);
626  BUG_ON(GetIdByNameFunc == NULL);
627  BUG_ON(GetNameByIdFunc == NULL);
628 
629  AppLayerParserProtoCtx *p = &alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT];
630  /* double registration not allowed */
631  for (struct AppLayerParserSubStateMapping *m = p->sub_state_mappings; m != NULL; m = m->next) {
632  BUG_ON(sub_state == m->sub_state);
633  }
634  struct AppLayerParserSubStateMapping *m = SCCalloc(1, sizeof(*m));
635  if (m == NULL)
636  FatalError("failed to register substate");
637 
638  m->sub_state = sub_state;
639  m->GetStateIdByName = GetIdByNameFunc;
640  m->GetStateNameById = GetNameByIdFunc;
641  m->next = p->sub_state_mappings;
642  p->sub_state_mappings = m;
643 
644  p->max_sub_state = MAX(p->max_sub_state, sub_state);
645  SCLogDebug("alproto %u:%s, sub_state:%u max:%u %p:%p", alproto, AppProtoToString(alproto),
646  sub_state, p->max_sub_state, m->GetStateIdByName, m->GetStateNameById);
647 
648  SCReturn;
649 }
650 
651 void AppLayerParserRegisterGetStateFuncs(uint8_t ipproto, AppProto alproto,
652  AppLayerParserGetStateIdByNameFn GetIdByNameFunc,
653  AppLayerParserGetStateNameByIdFn GetNameByIdFunc)
654 {
655  SCEnter();
656  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateIdByName = GetIdByNameFunc;
657  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateNameById = GetNameByIdFunc;
658  SCReturn;
659 }
660 
661 void AppLayerParserRegisterGetFrameFuncs(uint8_t ipproto, AppProto alproto,
662  AppLayerParserGetFrameIdByNameFn GetIdByNameFunc,
663  AppLayerParserGetFrameNameByIdFn GetNameByIdFunc)
664 {
665  SCEnter();
666  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameIdByName = GetIdByNameFunc;
667  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameNameById = GetNameByIdFunc;
668  SCReturn;
669 }
670 
671 void AppLayerParserRegisterGetEventInfo(uint8_t ipproto, AppProto alproto,
672  int (*StateGetEventInfo)(
673  const char *event_name, uint8_t *event_id, AppLayerEventType *event_type))
674 {
675  SCEnter();
676 
677  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetEventInfo = StateGetEventInfo;
678 
679  SCReturn;
680 }
681 
682 void AppLayerParserRegisterTxDataFunc(uint8_t ipproto, AppProto alproto,
683  AppLayerTxData *(*GetTxData)(void *tx))
684 {
685  SCEnter();
686 
687  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxData = GetTxData;
688 
689  SCReturn;
690 }
691 
693  uint8_t ipproto, AppProto alproto, AppLayerStateData *(*GetStateData)(void *state))
694 {
695  SCEnter();
696 
697  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateData = GetStateData;
698 
699  SCReturn;
700 }
701 
702 void AppLayerParserRegisterApplyTxConfigFunc(uint8_t ipproto, AppProto alproto,
703  void (*ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig))
704 {
705  SCEnter();
706 
707  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].ApplyTxConfig = ApplyTxConfig;
708 
709  SCReturn;
710 }
711 
713  void (*SetStreamDepthFlag)(void *tx, uint8_t flags))
714 {
715  SCEnter();
716 
717  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].SetStreamDepthFlag = SetStreamDepthFlag;
718 
719  SCReturn;
720 }
721 
722 /***** Get and transaction functions *****/
723 
725 {
726  SCEnter();
727  void * r = NULL;
728 
729  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageAlloc != NULL) {
730  r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageAlloc();
731  }
732 
733  SCReturnPtr(r, "void *");
734 }
735 
737  void *local_data)
738 {
739  SCEnter();
740 
741  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageFree != NULL) {
742  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageFree(local_data);
743  }
744 
745  SCReturn;
746 }
747 
748 /** \brief default tx iterator
749  *
750  * Used if the app layer parser doesn't register its own iterator.
751  * Simply walks the tx_id space until it finds a tx. Uses 'state' to
752  * keep track of where it left off.
753  *
754  * \retval txptr or NULL if no more txs in list
755  */
756 static AppLayerGetTxIterTuple AppLayerDefaultGetTxIterator(
757  const uint8_t ipproto, const AppProto alproto,
758  void *alstate, uint64_t min_tx_id, uint64_t max_tx_id,
759  AppLayerGetTxIterState *state)
760 {
761  uint64_t ustate = *(uint64_t *)state;
762  uint64_t tx_id = MAX(min_tx_id, ustate);
763  for ( ; tx_id < max_tx_id; tx_id++) {
764  void *tx_ptr = AppLayerParserGetTx(ipproto, alproto, alstate, tx_id);
765  if (tx_ptr != NULL) {
766  ustate = tx_id + 1;
767  *state = *(AppLayerGetTxIterState *)&ustate;
768  AppLayerGetTxIterTuple tuple = {
769  .tx_ptr = tx_ptr,
770  .tx_id = tx_id,
771  .has_next = (tx_id + 1 < max_tx_id),
772  };
773  SCLogDebug("tuple: %p/%"PRIu64"/%s", tuple.tx_ptr, tuple.tx_id,
774  tuple.has_next ? "true" : "false");
775  return tuple;
776  }
777  }
778 
779  AppLayerGetTxIterTuple no_tuple = { NULL, 0, false };
780  return no_tuple;
781 }
782 
784  const AppProto alproto)
785 {
787  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTxIterator;
788  return Func ? Func : AppLayerDefaultGetTxIterator;
789 }
790 
792 {
793  SCEnter();
794  DEBUG_VALIDATE_BUG_ON(pstate == NULL);
795  SCReturnCT(pstate->log_id, "uint64_t");
796 }
797 
799 {
800  SCEnter();
801  DEBUG_VALIDATE_BUG_ON(pstate == NULL);
802  SCReturnCT(pstate->min_id, "uint64_t");
803 }
804 
806 {
807  SCEnter();
808  DEBUG_VALIDATE_BUG_ON(pstate == NULL);
809  pstate->log_id = tx_id;
810  SCReturn;
811 }
812 
813 uint64_t AppLayerParserGetTransactionInspectId(AppLayerParserState *pstate, uint8_t direction)
814 {
815  SCEnter();
816  DEBUG_VALIDATE_BUG_ON(pstate == NULL);
817  SCReturnCT(pstate->inspect_id[(direction & STREAM_TOSERVER) ? 0 : 1], "uint64_t");
818 }
819 
820 inline uint8_t AppLayerParserGetTxDetectProgress(AppLayerTxData *txd, const uint8_t dir)
821 {
822  uint8_t p = (dir & STREAM_TOSERVER) ? txd->detect_progress_ts : txd->detect_progress_tc;
823  return p;
824 }
825 
826 static inline uint32_t GetTxLogged(AppLayerTxData *txd)
827 {
828  return txd->logged;
829 }
830 
832 {
833  if (txd->de_state) {
835  }
836  if (txd->events) {
838  }
839  if (txd->txbits) {
840  SCGenericVarFree(txd->txbits);
841  }
842 }
843 
845  void *alstate, const uint8_t flags,
846  bool tag_txs_as_inspected)
847 {
848  SCEnter();
849 
850  const int direction = (flags & STREAM_TOSERVER) ? 0 : 1;
851  const uint64_t total_txs = AppLayerParserGetTxCnt(f, alstate);
852  uint64_t idx = AppLayerParserGetTransactionInspectId(pstate, flags);
853  const uint8_t ipproto = f->proto;
854  const AppProto alproto = f->alproto;
855 
856  AppLayerGetTxIteratorFunc IterFunc = AppLayerGetTxIterator(ipproto, alproto);
857  AppLayerGetTxIterState state = { 0 };
858 
859  SCLogDebug("called: %s, tag_txs_as_inspected %s",direction==0?"toserver":"toclient",
860  tag_txs_as_inspected?"true":"false");
861 
862  /* mark all txs as inspected if the applayer progress is
863  * at the 'end state'. */
864  while (1) {
865  AppLayerGetTxIterTuple ires = IterFunc(ipproto, alproto, alstate, idx, total_txs, &state);
866  if (ires.tx_ptr == NULL)
867  break;
868 
869  void *tx = ires.tx_ptr;
870  idx = ires.tx_id;
871 
872  AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
873  const int tx_end_state = AppLayerParserGetTxEndState(ipproto, alproto, tx, flags);
874  int state_progress = AppLayerParserGetStateProgress(ipproto, alproto, tx, flags);
875  if (state_progress < tx_end_state)
876  break;
877 
878  if (tag_txs_as_inspected) {
879  const uint8_t inspected_flag = (flags & STREAM_TOSERVER) ? APP_LAYER_TX_INSPECTED_TS
881  if (!(txd->flags & inspected_flag)) {
882  txd->flags |= inspected_flag;
883  SCLogDebug("%p/%" PRIu64 " in-order tx is done for direction %s. Flags %02x", tx,
884  idx, flags & STREAM_TOSERVER ? "toserver" : "toclient", txd->flags);
885  }
886  }
887  idx++;
888  if (!ires.has_next)
889  break;
890  }
891  pstate->inspect_id[direction] = idx;
892  SCLogDebug("inspect_id now %"PRIu64, pstate->inspect_id[direction]);
893 
894  /* if necessary we flag all txs that are complete as 'inspected'
895  * also move inspect_id forward. */
896  if (tag_txs_as_inspected) {
897  /* continue at idx */
898  while (1) {
899  AppLayerGetTxIterTuple ires = IterFunc(ipproto, alproto, alstate, idx, total_txs, &state);
900  if (ires.tx_ptr == NULL)
901  break;
902 
903  void *tx = ires.tx_ptr;
904  /* if we got a higher id than the minimum we requested, we
905  * skipped a bunch of 'null-txs'. Lets see if we can up the
906  * inspect tracker */
907  if (ires.tx_id > idx && pstate->inspect_id[direction] == idx) {
908  pstate->inspect_id[direction] = ires.tx_id;
909  }
910  idx = ires.tx_id;
911 
912  AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
913  const int tx_end_state = AppLayerParserGetTxEndState(ipproto, alproto, tx, flags);
914  const int state_progress = AppLayerParserGetStateProgress(ipproto, alproto, tx, flags);
915  if (state_progress < tx_end_state)
916  break;
917 
918  const uint8_t inspected_flag = (flags & STREAM_TOSERVER) ? APP_LAYER_TX_INSPECTED_TS
920  if (!(txd->flags & inspected_flag)) {
921  txd->flags |= inspected_flag;
922  SCLogDebug("%p/%" PRIu64 " out of order tx is done for direction %s. Flag %02x", tx,
923  idx, flags & STREAM_TOSERVER ? "toserver" : "toclient", txd->flags);
924 
925  SCLogDebug("%p/%" PRIu64 " out of order tx. Update inspect_id? %" PRIu64, tx, idx,
926  pstate->inspect_id[direction]);
927  if (pstate->inspect_id[direction] + 1 == idx)
928  pstate->inspect_id[direction] = idx;
929  }
930  if (!ires.has_next)
931  break;
932  idx++;
933  }
934  }
935 
936  SCReturn;
937 }
938 
940 {
941  SCEnter();
942 
943  SCReturnPtr(pstate->decoder_events,
944  "AppLayerDecoderEvents *");
945 }
946 
948  void *tx)
949 {
950  SCEnter();
951 
952  AppLayerDecoderEvents *ptr = NULL;
953 
954  /* Access events via the tx_data. */
955  AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
956  if (txd->events != NULL) {
957  ptr = txd->events;
958  }
959 
960  SCReturnPtr(ptr, "AppLayerDecoderEvents *");
961 }
962 
963 AppLayerGetFileState AppLayerParserGetTxFiles(const Flow *f, void *tx, const uint8_t direction)
964 {
965  SCEnter();
966 
967  if (alp_ctx.ctxs[f->alproto][f->protomap].GetTxFiles != NULL) {
968  return alp_ctx.ctxs[f->alproto][f->protomap].GetTxFiles(tx, direction);
969  }
970 
971  AppLayerGetFileState files = { .fc = NULL, .cfg = NULL };
972  return files;
973 }
974 
975 static void AppLayerParserFileTxHousekeeping(
976  const Flow *f, void *tx, const uint8_t pkt_dir, const bool trunc)
977 {
978  AppLayerGetFileState files = AppLayerParserGetTxFiles(f, tx, pkt_dir);
979  if (files.fc) {
980  FilesPrune(files.fc, files.cfg, trunc);
981  }
982 }
983 
984 #define IS_DISRUPTED(flags) ((flags) & (STREAM_DEPTH | STREAM_GAP | STREAM_ASYNC))
985 
986 extern int g_detect_disabled;
987 extern bool g_file_logger_enabled;
988 extern bool g_filedata_logger_enabled;
989 
990 /**
991  * \brief remove obsolete (inspected and logged) transactions
992  */
993 void AppLayerParserTransactionsCleanup(Flow *f, const uint8_t pkt_dir)
994 {
995  SCEnter();
997 
998  AppLayerParserProtoCtx *p = &alp_ctx.ctxs[f->alproto][f->protomap];
999  if (unlikely(p->StateTransactionFree == NULL))
1000  SCReturn;
1001 
1002  const bool has_tx_detect_flags = !g_detect_disabled;
1003  const uint8_t ipproto = f->proto;
1004  const AppProto alproto = f->alproto;
1005  void * const alstate = f->alstate;
1006  AppLayerParserState * const alparser = f->alparser;
1007 
1008  if (alstate == NULL || alparser == NULL)
1009  SCReturn;
1010 
1011  const uint64_t min = alparser->min_id;
1012  const uint64_t total_txs = AppLayerParserGetTxCnt(f, alstate);
1013  const LoggerId logger_expectation = AppLayerParserProtocolGetLoggerBits(ipproto, alproto);
1014  const uint8_t ts_disrupt_flags = FlowGetDisruptionFlags(f, STREAM_TOSERVER);
1015  const uint8_t tc_disrupt_flags = FlowGetDisruptionFlags(f, STREAM_TOCLIENT);
1016 
1017  int pkt_dir_trunc = -1;
1018 
1019  AppLayerGetTxIteratorFunc IterFunc = AppLayerGetTxIterator(ipproto, alproto);
1020  AppLayerGetTxIterState state;
1021  memset(&state, 0, sizeof(state));
1022  uint64_t i = min;
1023  uint64_t new_min = min;
1024  SCLogDebug("start min %"PRIu64, min);
1025  bool skipped = false;
1026  // const bool support_files = AppLayerParserSupportsFiles(f->proto, f->alproto);
1027 
1028  while (1) {
1029  AppLayerGetTxIterTuple ires = IterFunc(ipproto, alproto, alstate, i, total_txs, &state);
1030  if (ires.tx_ptr == NULL)
1031  break;
1032 
1033  bool tx_skipped = false;
1034  void *tx = ires.tx_ptr;
1035  i = ires.tx_id; // actual tx id for the tx the IterFunc returned
1036 
1037  SCLogDebug("%p/%"PRIu64" checking", tx, i);
1038  AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
1039  if (AppLayerParserHasFilesInDir(txd, pkt_dir)) {
1040  if (pkt_dir_trunc == -1)
1041  pkt_dir_trunc = IS_DISRUPTED(
1042  (pkt_dir == STREAM_TOSERVER) ? ts_disrupt_flags : tc_disrupt_flags);
1043  AppLayerParserFileTxHousekeeping(f, tx, pkt_dir, (bool)pkt_dir_trunc);
1044  }
1045  // should be reset by parser next time it updates the tx
1046  if (pkt_dir & STREAM_TOSERVER) {
1047  txd->updated_ts = false;
1048  } else {
1049  txd->updated_tc = false;
1050  }
1051  const int tx_progress_tc =
1052  AppLayerParserGetStateProgress(ipproto, alproto, tx, tc_disrupt_flags);
1053  const int end_state_tc = AppLayerParserGetTxEndState(ipproto, alproto, tx, STREAM_TOCLIENT);
1054  if (tx_progress_tc < end_state_tc) {
1055  SCLogDebug("%p/%"PRIu64" skipping: tc parser not done", tx, i);
1056  skipped = true;
1057  goto next;
1058  }
1059  const int end_state_ts = AppLayerParserGetTxEndState(ipproto, alproto, tx, STREAM_TOSERVER);
1060  const int tx_progress_ts =
1061  AppLayerParserGetStateProgress(ipproto, alproto, tx, ts_disrupt_flags);
1062  if (tx_progress_ts < end_state_ts) {
1063  SCLogDebug("%p/%"PRIu64" skipping: ts parser not done", tx, i);
1064  skipped = true;
1065  goto next;
1066  }
1067 
1068  if (has_tx_detect_flags) {
1069  if (!IS_DISRUPTED(ts_disrupt_flags) &&
1070  (f->sgh_toserver != NULL || (f->flags & FLOW_SGH_TOSERVER) == 0)) {
1071  if ((txd->flags & (APP_LAYER_TX_INSPECTED_TS | APP_LAYER_TX_SKIP_INSPECT_TS)) ==
1072  0) {
1073  SCLogDebug("%p/%" PRIu64 " skipping: TS inspect not done: ts:%02x", tx, i,
1074  txd->flags);
1075  tx_skipped = true;
1076  }
1077  }
1078  if (!IS_DISRUPTED(tc_disrupt_flags) &&
1079  (f->sgh_toclient != NULL || (f->flags & FLOW_SGH_TOCLIENT) == 0)) {
1080  if ((txd->flags & (APP_LAYER_TX_INSPECTED_TC | APP_LAYER_TX_SKIP_INSPECT_TC)) ==
1081  0) {
1082  SCLogDebug("%p/%" PRIu64 " skipping: TC inspect not done: ts:%02x", tx, i,
1083  txd->flags);
1084  tx_skipped = true;
1085  }
1086  }
1087  }
1088 
1089  if (tx_skipped) {
1090  SCLogDebug("%p/%" PRIu64 " tx_skipped", tx, i);
1091  skipped = true;
1092  goto next;
1093  }
1094 
1095  if (logger_expectation != 0) {
1096  LoggerId tx_logged = GetTxLogged(txd);
1097  if (tx_logged != logger_expectation) {
1098  SCLogDebug("%p/%"PRIu64" skipping: logging not done: want:%"PRIx32", have:%"PRIx32,
1099  tx, i, logger_expectation, tx_logged);
1100  skipped = true;
1101  goto next;
1102  }
1103  }
1104 
1105  /* if file logging is enabled, we keep a tx active while some of the files aren't
1106  * logged yet. */
1107  SCLogDebug("files_opened %u files_logged %u files_stored %u", txd->files_opened,
1108  txd->files_logged, txd->files_stored);
1109 
1110  if (txd->files_opened) {
1111  if (g_file_logger_enabled && txd->files_opened != txd->files_logged) {
1112  skipped = true;
1113  goto next;
1114  }
1115  if (g_filedata_logger_enabled && txd->files_opened != txd->files_stored) {
1116  skipped = true;
1117  goto next;
1118  }
1119  }
1120 
1121  /* if we are here, the tx can be freed. */
1122  p->StateTransactionFree(alstate, i);
1123  SCLogDebug("%p/%"PRIu64" freed", tx, i);
1124 
1125  /* if we didn't skip any tx so far, up the minimum */
1126  SCLogDebug("skipped? %s i %"PRIu64", new_min %"PRIu64, skipped ? "true" : "false", i, new_min);
1127  if (!skipped)
1128  new_min = i + 1;
1129  SCLogDebug("final i %"PRIu64", new_min %"PRIu64, i, new_min);
1130 
1131 next:
1132  if (!ires.has_next) {
1133  /* this was the last tx. See if we skipped any. If not
1134  * we removed all and can update the minimum to the max
1135  * id. */
1136  SCLogDebug("no next: cur tx i %"PRIu64", total %"PRIu64, i, total_txs);
1137  if (!skipped) {
1138  new_min = total_txs;
1139  SCLogDebug("no next: cur tx i %"PRIu64", total %"PRIu64": "
1140  "new_min updated to %"PRIu64, i, total_txs, new_min);
1141  }
1142  break;
1143  }
1144  i++;
1145  }
1146 
1147  /* see if we need to bring all trackers up to date. */
1148  SCLogDebug("update f->alparser->min_id? %"PRIu64" vs %"PRIu64, new_min, alparser->min_id);
1149  if (new_min > alparser->min_id) {
1150  const uint64_t next_id = new_min;
1151  alparser->min_id = next_id;
1152  alparser->inspect_id[0] = MAX(alparser->inspect_id[0], next_id);
1153  alparser->inspect_id[1] = MAX(alparser->inspect_id[1], next_id);
1154  alparser->log_id = MAX(alparser->log_id, next_id);
1155  SCLogDebug("updated f->alparser->min_id %"PRIu64, alparser->min_id);
1156  }
1157  SCReturn;
1158 }
1159 
1160 static inline int StateGetProgressCompletionStatus(const AppProto alproto, const uint8_t flags)
1161 {
1162  if (flags & STREAM_TOSERVER) {
1163  return alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts;
1164  } else if (flags & STREAM_TOCLIENT) {
1165  return alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc;
1166  } else {
1168  return 0;
1169  }
1170 }
1171 
1172 /** \internal
1173  * \brief get the end state (progress) for a TX
1174  * If the TX is supporting sub-states, return the value from the txd.
1175  * \param tx pointer to the transaction
1176  */
1177 uint8_t AppLayerParserGetTxEndState(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
1178 {
1179  const AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
1180  if (txd == NULL || txd->tx_type == 0) {
1181  return (uint8_t)AppLayerParserGetStateProgressCompletionStatus(alproto, flags);
1182  }
1183  const uint8_t eop = (flags & STREAM_TOSERVER) ? txd->tx_type_eop_ts : txd->tx_type_eop_tc;
1184  if (unlikely(eop == 0)) {
1185  /* a parser with tx types must fill both end-of-phase fields; without
1186  * the fallback 0 would make the first state look final in release
1187  * builds */
1189  return (uint8_t)AppLayerParserGetStateProgressCompletionStatus(alproto, flags);
1190  }
1191  return eop;
1192 }
1193 
1194 /**
1195  * \brief get the progress value for a tx/protocol
1196  *
1197  * If the stream is disrupted, we return the 'completion' value.
1198  */
1199 int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
1200 {
1201  SCEnter();
1202  int r;
1203  if (unlikely(IS_DISRUPTED(flags))) {
1204  r = (int)AppLayerParserGetTxEndState(ipproto, alproto, tx, flags);
1205  } else {
1206  const uint8_t direction = flags & (STREAM_TOCLIENT | STREAM_TOSERVER);
1207  r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetProgress(tx, direction);
1208  }
1209  SCReturnInt(r);
1210 }
1211 
1212 uint64_t AppLayerParserGetTxCnt(const Flow *f, void *alstate)
1213 {
1214  SCEnter();
1215  uint64_t r = alp_ctx.ctxs[f->alproto][f->protomap].StateGetTxCnt(alstate);
1216  SCReturnCT(r, "uint64_t");
1217 }
1218 
1219 void *AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id)
1220 {
1221  SCEnter();
1222  void *r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTx(alstate, tx_id);
1223  SCReturnPtr(r, "void *");
1224 }
1225 
1227 {
1228  SCEnter();
1229  int r = StateGetProgressCompletionStatus(alproto, direction);
1230  // TODO convert StateGetProgressCompletionStatus and more to uint8_t
1231  return (uint8_t)r;
1232 }
1233 
1234 /**
1235  * \brief
1236  *
1237  * Translate name to progress value for a substate `sub_state`. Calls the
1238  * registered callbacks.
1239  *
1240  * \retval -1 not found
1241  * \retval -2 parser is not enabled
1242  * \retval id value belonging to the state name
1243  */
1245  const AppProto alproto, const uint8_t sub_state, const char *state, const uint8_t dir_flag)
1246 {
1247  if (!AppLayerParserIsEnabled(alproto))
1248  return -2;
1249 
1250  if (alproto == ALPROTO_DOH2)
1252 
1253  BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].max_sub_state == 0);
1254  BUG_ON(dir_flag != STREAM_TOSERVER && dir_flag != STREAM_TOCLIENT);
1255 
1256  for (struct AppLayerParserSubStateMapping *m =
1257  alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].sub_state_mappings;
1258  m != NULL; m = m->next) {
1259  if (m->sub_state == sub_state) {
1260  BUG_ON(m->GetStateNameById == NULL);
1261  BUG_ON(m->GetStateIdByName == NULL);
1262 
1263  int v = m->GetStateIdByName(state, dir_flag);
1264  if (v < 0) {
1265  /* name not found */
1266  return -1;
1267  }
1268  SCLogDebug("state:%s v:%u", state, v);
1270  return (int8_t)v;
1271  }
1272  }
1273 
1274  return -1;
1275 }
1276 
1277 const char *AppLayerParserGetSubStateProgressName(const AppProto alproto, const uint8_t sub_state,
1278  const uint8_t state, const uint8_t dir_flag)
1279 {
1280  if (!AppLayerParserIsEnabled(alproto))
1281  return NULL;
1282 
1283  if (alproto == ALPROTO_DOH2)
1285 
1286  BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].max_sub_state == 0);
1287  BUG_ON(dir_flag != STREAM_TOSERVER && dir_flag != STREAM_TOCLIENT);
1288 
1289  for (struct AppLayerParserSubStateMapping *m =
1290  alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].sub_state_mappings;
1291  m != NULL; m = m->next) {
1292  if (m->sub_state == sub_state) {
1293  BUG_ON(m->GetStateNameById == NULL);
1294  BUG_ON(m->GetStateIdByName == NULL);
1295 
1296  return m->GetStateNameById(state, dir_flag);
1297  }
1298  }
1299 
1300  return NULL;
1301 }
1302 
1303 uint8_t AppLayerParserGetSubStateCompletion(const AppProto alproto, const uint8_t sub_state)
1304 {
1305  if (!AppLayerParserIsEnabled(alproto))
1306  return 0;
1307 
1308  if (alproto == ALPROTO_DOH2)
1310 
1311  BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].max_sub_state == 0);
1312 
1313  /* TODO hard coded for now */
1314  BUG_ON(alproto != ALPROTO_HTTP2);
1315 
1316  if (sub_state == 1) {
1317  return 4;
1318  } else if (sub_state == 2) {
1319  return 1;
1320  } else {
1321  BUG_ON(1);
1322  }
1323  return 0;
1324 }
1325 
1326 const char *AppLayerParserGetSubStateName(const AppProto alproto, const uint8_t sub_state)
1327 {
1328  if (!AppLayerParserIsEnabled(alproto))
1329  return NULL;
1330 
1331  if (alproto == ALPROTO_DOH2)
1333 
1334  BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].max_sub_state == 0);
1335 
1336  /* TODO hard coded for now */
1337  BUG_ON(alproto != ALPROTO_HTTP2);
1338 
1339  if (sub_state == 1) {
1340  return "stream";
1341  } else if (sub_state == 2) {
1342  return "global";
1343  } else {
1344  BUG_ON(1);
1345  }
1346  return NULL;
1347 }
1348 
1350 {
1351  if (alproto == ALPROTO_DOH2)
1353  return alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].max_sub_state;
1354 }
1355 
1357 {
1358  return AppLayerParserGetMaxSubState(alproto) != 0;
1359 }
1360 
1361 int AppLayerParserGetEventInfo(uint8_t ipproto, AppProto alproto, const char *event_name,
1362  uint8_t *event_id, AppLayerEventType *event_type)
1363 {
1364  SCEnter();
1365  const int ipproto_map = FlowGetProtoMapping(ipproto);
1366  int r = (alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfo == NULL)
1367  ? -1
1368  : alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfo(
1369  event_name, event_id, event_type);
1370  SCReturnInt(r);
1371 }
1372 
1373 int AppLayerParserGetEventInfoById(uint8_t ipproto, AppProto alproto, uint8_t event_id,
1374  const char **event_name, AppLayerEventType *event_type)
1375 {
1376  SCEnter();
1377  const int ipproto_map = FlowGetProtoMapping(ipproto);
1378  *event_name = (const char *)NULL;
1379  int r = (alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfoById == NULL)
1380  ? -1
1381  : alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfoById(
1382  event_id, event_name, event_type);
1383  SCReturnInt(r);
1384 }
1385 
1386 uint8_t AppLayerParserGetFirstDataDir(uint8_t ipproto, AppProto alproto)
1387 {
1388  SCEnter();
1389  uint8_t r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].first_data_dir;
1390  SCReturnCT(r, "uint8_t");
1391 }
1392 
1394  AppLayerParserState *pstate, uint8_t direction)
1395 {
1396  SCEnter();
1397 
1398  uint64_t active_id;
1399  uint64_t log_id = pstate->log_id;
1400  uint64_t inspect_id = pstate->inspect_id[(direction & STREAM_TOSERVER) ? 0 : 1];
1401  if (alp_ctx.ctxs[f->alproto][f->protomap].logger) {
1402  active_id = MIN(log_id, inspect_id);
1403  } else {
1404  active_id = inspect_id;
1405  }
1406 
1407  SCReturnCT(active_id, "uint64_t");
1408 }
1409 
1410 bool AppLayerParserSupportsFiles(uint8_t ipproto, AppProto alproto)
1411 {
1412  // Custom case for only signature-only protocol so far
1413  if (alproto == ALPROTO_HTTP) {
1414  return AppLayerParserSupportsFiles(ipproto, ALPROTO_HTTP1) ||
1416  }
1417  return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxFiles != NULL;
1418 }
1419 
1420 AppLayerTxData *AppLayerParserGetTxData(uint8_t ipproto, AppProto alproto, void *tx)
1421 {
1422  SCEnter();
1423  AppLayerTxData *d = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxData(tx);
1424  SCReturnPtr(d, "AppLayerTxData");
1425 }
1426 
1427 AppLayerStateData *AppLayerParserGetStateData(uint8_t ipproto, AppProto alproto, void *state)
1428 {
1429  SCEnter();
1430  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateData) {
1431  AppLayerStateData *d =
1432  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateData(state);
1433  SCReturnPtr(d, "AppLayerStateData");
1434  }
1435  SCReturnPtr(NULL, "AppLayerStateData");
1436 }
1437 
1438 void AppLayerParserApplyTxConfig(uint8_t ipproto, AppProto alproto,
1439  void *state, void *tx, enum ConfigAction mode, AppLayerTxConfig config)
1440 {
1441  SCEnter();
1442  const int ipproto_map = FlowGetProtoMapping(ipproto);
1443  if (alp_ctx.ctxs[alproto][ipproto_map].ApplyTxConfig) {
1444  alp_ctx.ctxs[alproto][ipproto_map].ApplyTxConfig(state, tx, mode, config);
1445  }
1446  SCReturn;
1447 }
1448 
1449 /***** General *****/
1450 
1451 static inline void SetEOFFlags(AppLayerParserState *pstate, const uint8_t flags)
1452 {
1453  if ((flags & (STREAM_EOF|STREAM_TOSERVER)) == (STREAM_EOF|STREAM_TOSERVER)) {
1454  SCLogDebug("setting APP_LAYER_PARSER_EOF_TS");
1455  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_EOF_TS);
1456  } else if ((flags & (STREAM_EOF|STREAM_TOCLIENT)) == (STREAM_EOF|STREAM_TOCLIENT)) {
1457  SCLogDebug("setting APP_LAYER_PARSER_EOF_TC");
1458  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_EOF_TC);
1459  }
1460 }
1461 
1462 /** \internal
1463  * \brief create/close stream frames
1464  * On first invocation of TCP parser in a direction, create a <alproto>.stream frame.
1465  * On STREAM_EOF, set the final length. */
1466 static void HandleStreamFrames(Flow *f, StreamSlice stream_slice, const uint8_t *input,
1467  const uint32_t input_len, const uint8_t flags)
1468 {
1469  const uint8_t direction = (flags & STREAM_TOSERVER) ? 0 : 1;
1470  AppLayerParserState *pstate = f->alparser;
1471 
1472  /* setup the generic stream frame */
1473  if (((direction == 0 && (pstate->flags & APP_LAYER_PARSER_SFRAME_TS) == 0) ||
1474  (direction == 1 && (pstate->flags & APP_LAYER_PARSER_SFRAME_TC) == 0)) &&
1475  input != NULL && f->proto == IPPROTO_TCP) {
1477  if (frame == NULL) {
1478  int64_t frame_len = -1;
1479  if (flags & STREAM_EOF)
1480  frame_len = input_len;
1481 
1483  f, &stream_slice, stream_slice.offset, frame_len, direction, FRAME_STREAM_TYPE);
1484  if (frame) {
1485  SCLogDebug("opened: frame %p id %" PRIi64, frame, frame->id);
1486  frame->flags = FRAME_FLAG_ENDS_AT_EOF; // TODO logic is not yet implemented
1488  frame->id != 1); // should always be the first frame that is created
1489  }
1490  if (direction == 0) {
1491  pstate->flags |= APP_LAYER_PARSER_SFRAME_TS;
1492  } else {
1493  pstate->flags |= APP_LAYER_PARSER_SFRAME_TC;
1494  }
1495  }
1496  } else if (flags & STREAM_EOF) {
1498  SCLogDebug("EOF closing: frame %p", frame);
1499  if (frame) {
1500  /* calculate final frame length */
1501  int64_t slice_o = (int64_t)stream_slice.offset - (int64_t)frame->offset;
1502  int64_t frame_len = slice_o + (int64_t)input_len;
1503  SCLogDebug("%s: EOF frame->offset %" PRIu64 " -> %" PRIi64 ": o %" PRIi64,
1504  AppProtoToString(f->alproto), frame->offset, frame_len, slice_o);
1505  frame->len = frame_len;
1506  }
1507  }
1508 }
1509 
1510 static void Setup(Flow *f, const uint8_t direction, const uint8_t *input, uint32_t input_len,
1511  const uint8_t flags, StreamSlice *as)
1512 {
1513  memset(as, 0, sizeof(*as));
1514  as->input = input;
1515  as->input_len = input_len;
1516  as->flags = flags;
1517 
1518  if (f->proto == IPPROTO_TCP && f->protoctx != NULL) {
1519  TcpSession *ssn = f->protoctx;
1520  TcpStream *stream = (direction & STREAM_TOSERVER) ? &ssn->client : &ssn->server;
1521  as->offset = STREAM_APP_PROGRESS(stream);
1522  }
1523 }
1524 
1525 /** \retval int -1 in case of unrecoverable error. App-layer tracking stops for this flow.
1526  * \retval int 0 ok: we did not update app_progress
1527  * \retval int 1 ok: we updated app_progress */
1529  uint8_t flags, const uint8_t *input, uint32_t input_len)
1530 {
1531  SCEnter();
1532 #ifdef DEBUG_VALIDATION
1534 #endif
1535  AppLayerParserState *pstate = f->alparser;
1536  AppLayerParserProtoCtx *p = &alp_ctx.ctxs[alproto][f->protomap];
1537  StreamSlice stream_slice;
1538  void *alstate = NULL;
1539  uint64_t p_tx_cnt = 0;
1540  uint32_t consumed = input_len;
1541  const uint8_t direction = (flags & STREAM_TOSERVER) ? 0 : 1;
1542 
1543  /* we don't have the parser registered for this protocol */
1544  if (p->StateAlloc == NULL) {
1545  if (f->proto == IPPROTO_TCP) {
1547  }
1548  goto end;
1549  }
1550 
1551  if (flags & STREAM_GAP) {
1552  if (!(p->option_flags & APP_LAYER_PARSER_OPT_ACCEPT_GAPS)) {
1553  SCLogDebug("app-layer parser does not accept gaps");
1554  if (f->alstate != NULL && !FlowChangeProto(f)) {
1556  }
1558  goto error;
1559  }
1560  }
1561 
1562  /* Get the parser state (if any) */
1563  if (pstate == NULL) {
1564  f->alparser = pstate = AppLayerParserStateAlloc();
1565  if (pstate == NULL) {
1567  goto error;
1568  }
1569  }
1570 
1571  SetEOFFlags(pstate, flags);
1572 
1573  alstate = f->alstate;
1574  if (alstate == NULL || FlowChangeProto(f)) {
1575  f->alstate = alstate = p->StateAlloc(alstate, f->alproto_orig);
1576  if (alstate == NULL) {
1578  goto error;
1579  }
1580  SCLogDebug("alloced new app layer state %p (name %s)",
1581  alstate, AppLayerGetProtoName(f->alproto));
1582 
1583  /* set flow flags to state */
1584  if (f->file_flags != 0) {
1586  if (sd != NULL) {
1587  if ((sd->file_flags & f->file_flags) != f->file_flags) {
1588  SCLogDebug("state data: updating file_flags %04x with flow file_flags %04x",
1589  sd->file_flags, f->file_flags);
1590  sd->file_flags |= f->file_flags;
1591  }
1592  }
1593  }
1594  } else {
1595  SCLogDebug("using existing app layer state %p (name %s))",
1596  alstate, AppLayerGetProtoName(f->alproto));
1597  }
1598 
1599  p_tx_cnt = AppLayerParserGetTxCnt(f, f->alstate);
1600 
1601  /* invoke the recursive parser, but only on data. We may get empty msgs on EOF */
1602  if (input_len > 0 || (flags & STREAM_EOF)) {
1603  Setup(f, flags & (STREAM_TOSERVER | STREAM_TOCLIENT), input, input_len, flags,
1604  &stream_slice);
1605  HandleStreamFrames(f, stream_slice, input, input_len, flags);
1606 
1607 #ifdef QA_SIMULATION
1608  if (((stream_slice.flags & STREAM_TOSERVER) &&
1609  stream_slice.offset >= g_eps_applayer_error_offset_ts)) {
1610  SCLogNotice("putting parser %s into an error state from toserver offset %" PRIu64,
1611  AppProtoToString(alproto), g_eps_applayer_error_offset_ts);
1613  goto error;
1614  }
1615  if (((stream_slice.flags & STREAM_TOCLIENT) &&
1616  stream_slice.offset >= g_eps_applayer_error_offset_tc)) {
1617  SCLogNotice("putting parser %s into an error state from toclient offset %" PRIu64,
1618  AppProtoToString(alproto), g_eps_applayer_error_offset_tc);
1620  goto error;
1621  }
1622 #endif
1623  /* invoke the parser */
1624  AppLayerResult res = p->Parser[direction](f, alstate, pstate, stream_slice,
1626  if (res.status < 0) {
1628  goto error;
1629  } else if (res.status > 0) {
1630  DEBUG_VALIDATE_BUG_ON(res.consumed > input_len);
1631  DEBUG_VALIDATE_BUG_ON(res.needed < input_len - res.consumed);
1632  DEBUG_VALIDATE_BUG_ON(res.needed == 0);
1633  /* incomplete is only supported for TCP */
1634  DEBUG_VALIDATE_BUG_ON(f->proto != IPPROTO_TCP);
1635 
1636  /* put protocol in error state on improper use of the
1637  * return codes. */
1638  if (res.consumed > input_len || res.needed + res.consumed < input_len) {
1640  goto error;
1641  }
1642 
1643  if (f->proto == IPPROTO_TCP && f->protoctx != NULL) {
1644  TcpSession *ssn = f->protoctx;
1645  SCLogDebug("direction %d/%s", direction,
1646  (flags & STREAM_TOSERVER) ? "toserver" : "toclient");
1647  if (direction == 0) {
1648  /* parser told us how much data it needs on top of what it
1649  * consumed. So we need tell stream engine how much we need
1650  * before the next call */
1651  ssn->client.data_required = res.needed;
1652  SCLogDebug("setting data_required %u", ssn->client.data_required);
1653  } else {
1654  /* parser told us how much data it needs on top of what it
1655  * consumed. So we need tell stream engine how much we need
1656  * before the next call */
1657  ssn->server.data_required = res.needed;
1658  SCLogDebug("setting data_required %u", ssn->server.data_required);
1659  }
1660  }
1661  consumed = res.consumed;
1662  }
1663  }
1664 
1665  /* set the packets to no inspection and reassembly if required */
1666  if (pstate->flags & APP_LAYER_PARSER_NO_INSPECTION) {
1667  AppLayerParserSetEOF(pstate);
1668 
1669  if (f->proto == IPPROTO_TCP) {
1671 
1672  /* Set the no reassembly flag for both the stream in this TcpSession */
1673  if (pstate->flags & APP_LAYER_PARSER_NO_REASSEMBLY) {
1674  /* Used only if it's TCP */
1675  TcpSession *ssn = f->protoctx;
1676  if (ssn != NULL) {
1679  }
1680  }
1681  /* Set the bypass flag for both the stream in this TcpSession */
1682  if (pstate->flags & APP_LAYER_PARSER_BYPASS_READY) {
1683  /* Used only if it's TCP */
1684  TcpSession *ssn = f->protoctx;
1685  if (ssn != NULL) {
1687  }
1688  }
1689  } else {
1690  // for TCP, this is set after flushing
1691  FlowSetNoPayloadInspectionFlag(f);
1692  }
1693  }
1694 
1695  /* In cases like HeartBleed for TLS we need to inspect AppLayer but not Payload */
1696  if (!(f->flags & FLOW_NOPAYLOAD_INSPECTION) && pstate->flags & APP_LAYER_PARSER_NO_INSPECTION_PAYLOAD) {
1697  FlowSetNoPayloadInspectionFlag(f);
1698  /* Set the no reassembly flag for both the stream in this TcpSession */
1699  if (f->proto == IPPROTO_TCP) {
1700  /* Used only if it's TCP */
1701  TcpSession *ssn = f->protoctx;
1702  if (ssn != NULL) {
1705  }
1706  }
1707  }
1708 
1709  /* get the diff in tx cnt for stats keeping */
1710  uint64_t cur_tx_cnt = AppLayerParserGetTxCnt(f, f->alstate);
1711  if (cur_tx_cnt > p_tx_cnt && tv) {
1712  AppLayerIncTxCounter(tv, f, cur_tx_cnt - p_tx_cnt);
1713  }
1714 
1715  end:
1716  /* update app progress */
1717  if (consumed != input_len && f->proto == IPPROTO_TCP && f->protoctx != NULL) {
1718  TcpSession *ssn = f->protoctx;
1719  StreamTcpUpdateAppLayerProgress(ssn, direction, consumed);
1720  SCReturnInt(1);
1721  }
1722 
1723  SCReturnInt(0);
1724  error:
1725  /* Set the no app layer inspection flag for both
1726  * the stream in this Flow */
1727  if (f->proto == IPPROTO_TCP) {
1729  }
1730  if (pstate != NULL) {
1731  AppLayerParserSetEOF(pstate);
1732  }
1733  SCReturnInt(-1);
1734 }
1735 
1737 {
1738  SCEnter();
1739  DEBUG_VALIDATE_BUG_ON(pstate == NULL);
1740  SCLogDebug("setting APP_LAYER_PARSER_EOF_TC and APP_LAYER_PARSER_EOF_TS");
1741  SCAppLayerParserStateSetFlag(pstate, (APP_LAYER_PARSER_EOF_TS | APP_LAYER_PARSER_EOF_TC));
1742  SCReturn;
1743 }
1744 
1745 /* return true if there are app parser decoder events. These are
1746  * only the ones that are set during protocol detection. */
1748 {
1749  SCEnter();
1750  if (pstate != NULL) {
1751  const AppLayerDecoderEvents *decoder_events = AppLayerParserGetDecoderEvents(pstate);
1752  return (decoder_events && decoder_events->cnt);
1753  }
1754  /* if we have reached here, we don't have events */
1755  return false;
1756 }
1757 
1758 /** \brief simple way to globally test if a alproto is registered
1759  * and fully enabled in the configuration.
1760  */
1762 {
1763  for (int i = 0; i < FLOW_PROTO_APPLAYER_MAX; i++) {
1764  if (alp_ctx.ctxs[alproto][i].StateGetProgress != NULL) {
1765  return 1;
1766  }
1767  }
1768  return 0;
1769 }
1770 
1771 int AppLayerParserProtocolHasLogger(uint8_t ipproto, AppProto alproto)
1772 {
1773  SCEnter();
1774  int ipproto_map = FlowGetProtoMapping(ipproto);
1775  int r = (!alp_ctx.ctxs[alproto][ipproto_map].logger) ? 0 : 1;
1776  SCReturnInt(r);
1777 }
1778 
1780 {
1781  SCEnter();
1782  const int ipproto_map = FlowGetProtoMapping(ipproto);
1783  LoggerId r = alp_ctx.ctxs[alproto][ipproto_map].logger_bits;
1784  SCReturnUInt(r);
1785 }
1786 
1788 {
1789  SCEnter();
1790 
1791  SCLogDebug("f %p tcp %p direction %d", f, f ? f->protoctx : NULL, direction);
1792  if (f != NULL && f->protoctx != NULL)
1794 
1795  SCReturn;
1796 }
1797 
1798 void SCAppLayerParserSetStreamDepth(uint8_t ipproto, AppProto alproto, uint32_t stream_depth)
1799 {
1800  SCEnter();
1801 
1802  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].stream_depth = stream_depth;
1803  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].internal_flags |=
1805 
1806  SCReturn;
1807 }
1808 
1810 {
1812 }
1813 
1814 void AppLayerParserSetStreamDepthFlag(uint8_t ipproto, AppProto alproto, void *state, uint64_t tx_id, uint8_t flags)
1815 {
1816  SCEnter();
1817  void *tx = NULL;
1818  if (state != NULL) {
1819  if ((tx = AppLayerParserGetTx(ipproto, alproto, state, tx_id)) != NULL) {
1820  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].SetStreamDepthFlag != NULL) {
1821  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].SetStreamDepthFlag(tx, flags);
1822  }
1823  }
1824  }
1825  SCReturn;
1826 }
1827 
1828 /**
1829  * \param id progress value id to get the name for
1830  * \param direction STREAM_TOSERVER/STREAM_TOCLIENT
1831  */
1833  uint8_t ipproto, AppProto alproto, const char *name, const uint8_t direction)
1834 {
1835  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateIdByName != NULL) {
1836  return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateIdByName(
1837  name, direction);
1838  } else {
1839  return -1;
1840  }
1841 }
1842 
1843 /**
1844  * \param id progress value id to get the name for
1845  * \param direction STREAM_TOSERVER/STREAM_TOCLIENT
1846  */
1848  uint8_t ipproto, AppProto alproto, const int id, const uint8_t direction)
1849 {
1850  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateNameById != NULL) {
1851  return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateNameById(id, direction);
1852  } else {
1853  return NULL;
1854  }
1855 }
1856 
1857 int AppLayerParserGetFrameIdByName(uint8_t ipproto, AppProto alproto, const char *name)
1858 {
1859  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameIdByName != NULL) {
1860  return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameIdByName(name);
1861  } else {
1862  return -1;
1863  }
1864 }
1865 
1866 const char *AppLayerParserGetFrameNameById(uint8_t ipproto, AppProto alproto, const uint8_t id)
1867 {
1868  if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameNameById != NULL) {
1869  return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameNameById(id);
1870  } else {
1871  return NULL;
1872  }
1873 }
1874 
1875 /***** Cleanup *****/
1876 
1878  uint8_t protomap, AppProto alproto, void *alstate, AppLayerParserState *pstate)
1879 {
1880  SCEnter();
1881 
1882  AppLayerParserProtoCtx *ctx = &alp_ctx.ctxs[alproto][protomap];
1883 
1884  if (ctx->StateFree != NULL && alstate != NULL)
1885  ctx->StateFree(alstate);
1886 
1887  /* free the app layer parser api state */
1888  if (pstate != NULL)
1889  AppLayerParserStateFree(pstate);
1890 
1891  SCReturn;
1892 }
1893 
1894 void AppLayerParserStateCleanup(const Flow *f, void *alstate, AppLayerParserState *pstate)
1895 {
1896  AppLayerParserStateProtoCleanup(f->protomap, f->alproto, alstate, pstate);
1897 }
1898 
1899 static void ValidateParserProtoDump(AppProto alproto, uint8_t ipproto)
1900 {
1901  uint8_t map = FlowGetProtoMapping(ipproto);
1902  const AppLayerParserProtoCtx *ctx = &alp_ctx.ctxs[alproto][map];
1903  printf("ERROR: incomplete app-layer registration\n");
1904  printf("AppLayer protocol %s ipproto %u\n", AppProtoToString(alproto), ipproto);
1905  printf("- option flags %"PRIx32"\n", ctx->option_flags);
1906  printf("- first_data_dir %"PRIx8"\n", ctx->first_data_dir);
1907  printf("Mandatory:\n");
1908  printf("- Parser[0] %p Parser[1] %p\n", ctx->Parser[0], ctx->Parser[1]);
1909  printf("- StateAlloc %p StateFree %p\n", ctx->StateAlloc, ctx->StateFree);
1910  printf("- StateGetTx %p StateGetTxCnt %p StateTransactionFree %p\n",
1911  ctx->StateGetTx, ctx->StateGetTxCnt, ctx->StateTransactionFree);
1912  printf("- GetTxData %p\n", ctx->GetTxData);
1913  printf("- GetStateData %p\n", ctx->GetStateData);
1914  printf("- StateGetProgress %p\n", ctx->StateGetProgress);
1915  printf("Optional:\n");
1916  printf("- LocalStorageAlloc %p LocalStorageFree %p\n", ctx->LocalStorageAlloc, ctx->LocalStorageFree);
1917  printf("- StateGetEventInfo %p StateGetEventInfoById %p\n", ctx->StateGetEventInfo,
1918  ctx->StateGetEventInfoById);
1919 }
1920 
1921 #define BOTH_SET(a, b) ((a) != NULL && (b) != NULL)
1922 #define BOTH_SET_OR_BOTH_UNSET(a, b) (((a) == NULL && (b) == NULL) || ((a) != NULL && (b) != NULL))
1923 #define THREE_SET(a, b, c) ((a) != NULL && (b) != NULL && (c) != NULL)
1925 static void ValidateParserProto(AppProto alproto, uint8_t ipproto)
1926 {
1927  uint8_t map = FlowGetProtoMapping(ipproto);
1928  const AppLayerParserProtoCtx *ctx = &alp_ctx.ctxs[alproto][map];
1929 
1930  if (ctx->Parser[0] == NULL && ctx->Parser[1] == NULL)
1931  return;
1932 
1933  if (!(BOTH_SET(ctx->Parser[0], ctx->Parser[1]))) {
1934  goto bad;
1935  }
1936  if (!(BOTH_SET(ctx->StateFree, ctx->StateAlloc))) {
1937  goto bad;
1938  }
1939  if (!(THREE_SET(ctx->StateGetTx, ctx->StateGetTxCnt, ctx->StateTransactionFree))) {
1940  goto bad;
1941  }
1942  if (ctx->StateGetProgress == NULL) {
1943  goto bad;
1944  }
1945  /* local storage is optional, but needs both set if used */
1946  if (!(BOTH_SET_OR_BOTH_UNSET(ctx->LocalStorageAlloc, ctx->LocalStorageFree))) {
1947  goto bad;
1948  }
1949  if (ctx->GetTxData == NULL) {
1950  goto bad;
1951  }
1952  if (ctx->GetStateData == NULL) {
1953  goto bad;
1954  }
1955  return;
1956 bad:
1957  ValidateParserProtoDump(alproto, ipproto);
1958  exit(EXIT_FAILURE);
1959 }
1960 #undef BOTH_SET
1961 #undef BOTH_SET_OR_BOTH_UNSET
1962 #undef THREE_SET
1963 
1964 static void ValidateParser(AppProto alproto)
1965 {
1966  ValidateParserProto(alproto, IPPROTO_TCP);
1967  ValidateParserProto(alproto, IPPROTO_UDP);
1968 }
1969 
1970 static void ValidateParsers(void)
1971 {
1972  AppProto p = 0;
1973  for (; p < g_alproto_max; p++) {
1974  ValidateParser(p);
1975  }
1976 }
1977 
1978 #define ARRAY_CAP_STEP 16
1979 static void (**PreRegisteredCallbacks)(void) = NULL;
1980 static size_t preregistered_callbacks_nb = 0;
1981 static size_t preregistered_callbacks_cap = 0;
1982 
1984 {
1985  if (alp_ctx.ctxs_len <= alproto && alproto < g_alproto_max) {
1986  /* Realloc alp_ctx.ctxs, so that dynamic alproto can be treated as real/normal ones.
1987  * In case we need to turn off dynamic alproto. */
1988  void *tmp = SCRealloc(alp_ctx.ctxs, sizeof(AppLayerParserProtoCtx[FLOW_PROTO_MAX]) *
1989  (alp_ctx.ctxs_len + ARRAY_CAP_STEP));
1990  if (unlikely(tmp == NULL)) {
1991  FatalError("Unable to realloc alp_ctx.ctxs.");
1992  }
1993  alp_ctx.ctxs = tmp;
1994  memset(&alp_ctx.ctxs[alp_ctx.ctxs_len], 0,
1996  alp_ctx.ctxs_len += ARRAY_CAP_STEP;
1997  }
1998  return 0;
1999 }
2000 
2001 int AppLayerParserPreRegister(void (*Register)(void))
2002 {
2003  if (preregistered_callbacks_nb == preregistered_callbacks_cap) {
2004  void *tmp = SCRealloc(PreRegisteredCallbacks,
2005  sizeof(void *) * (preregistered_callbacks_cap + ARRAY_CAP_STEP));
2006  if (tmp == NULL) {
2007  return 1;
2008  }
2009  preregistered_callbacks_cap += ARRAY_CAP_STEP;
2010  PreRegisteredCallbacks = tmp;
2011  }
2012  PreRegisteredCallbacks[preregistered_callbacks_nb] = Register;
2013  preregistered_callbacks_nb++;
2014  return 0;
2015 }
2016 
2018 {
2019  SCEnter();
2020 
2021  AppLayerConfig();
2022 
2025  SCRegisterDcerpcParser();
2026  SCRegisterDcerpcUdpParser();
2031  SCRegisterDnsUdpParser();
2032  SCRegisterDnsTcpParser();
2033  SCRegisterBittorrentDhtUdpParser();
2035  SCEnipRegisterParsers();
2039  SCRegisterNtpParser();
2042  SCRegisterKrb5Parser();
2043  SCRegisterDhcpParser();
2044  SCRegisterSnmpParser();
2045  SCRegisterSipParser();
2046  SCRegisterQuicParser();
2047  SCRegisterWebSocketParser();
2048  SCRegisterLdapTcpParser();
2049  SCRegisterLdapUdpParser();
2050  SCRegisterMdnsParser();
2051  SCRegisterTemplateParser();
2052  SCRfbRegisterParser();
2053  SCMqttRegisterParser();
2054  SCRegisterPgsqlParser();
2055  SCRegisterPop3Parser();
2056  SCRegisterRdpParser();
2058  SCRegisterTelnetParser();
2060  SCRegisterLLMNRUdpParser();
2061  SCRegisterLLMNRTcpParser();
2062 
2063  for (size_t i = 0; i < preregistered_callbacks_nb; i++) {
2064  PreRegisteredCallbacks[i]();
2065  }
2066 
2067  ValidateParsers();
2068 }
2069 
2070 /* coccinelle: SCAppLayerParserStateSetFlag():2,2:APP_LAYER_PARSER_ */
2072 {
2073  SCEnter();
2074  pstate->flags |= flag;
2075  SCReturn;
2076 }
2077 
2078 /* coccinelle: SCAppLayerParserStateIssetFlag():2,2:APP_LAYER_PARSER_ */
2079 uint16_t SCAppLayerParserStateIssetFlag(AppLayerParserState *pstate, uint16_t flag)
2080 {
2081  SCEnter();
2082  SCReturnUInt(pstate->flags & flag);
2083 }
2084 
2085 /***** Unittests *****/
2086 
2087 #ifdef UNITTESTS
2088 #include "util-unittest-helper.h"
2089 
2091  void (*RegisterUnittests)(void))
2092 {
2093  SCEnter();
2094  alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].RegisterUnittests = RegisterUnittests;
2095  SCReturn;
2096 }
2097 
2099 {
2100  SCEnter();
2101 
2102  int ip;
2103  AppProto alproto;
2105 
2106  for (ip = 0; ip < FLOW_PROTO_DEFAULT; ip++) {
2107  for (alproto = 0; alproto < g_alproto_max; alproto++) {
2108  ctx = &alp_ctx.ctxs[alproto][ip];
2109  if (ctx->RegisterUnittests == NULL)
2110  continue;
2111  ctx->RegisterUnittests();
2112  }
2113  }
2114 
2115  SCReturn;
2116 }
2117 
2118 #endif
AppLayerParserHasFilesInDir
#define AppLayerParserHasFilesInDir(txd, direction)
check if tx (possibly) has files in this tx for the direction
Definition: app-layer-parser.h:368
StreamSlice
Definition: app-layer-parser.h:126
app-layer-nfs-udp.h
AppLayerParserRegisterGetStateProgressFunc
void AppLayerParserRegisterGetStateProgressFunc(uint8_t ipproto, AppProto alproto, int(*StateGetProgress)(void *alstate, uint8_t direction))
Definition: app-layer-parser.c:544
AppLayerParserDeSetup
int AppLayerParserDeSetup(void)
Definition: app-layer-parser.c:310
TcpStream_
Definition: stream-tcp-private.h:106
AppLayerTxConfig
Definition: app-layer-parser.h:165
AppLayerParserProtoCtx_::GetStateData
AppLayerStateData *(* GetStateData)(void *state)
Definition: app-layer-parser.c:121
ts
uint64_t ts
Definition: source-erf-file.c:68
AppLayerTxData::flags
uint8_t flags
Definition: app-layer-parser.h:182
AppLayerParserProtoCtx_::StateGetTxCnt
uint64_t(* StateGetTxCnt)(void *alstate)
Definition: app-layer-parser.c:111
g_applayerparser_error_policy
enum ExceptionPolicy g_applayerparser_error_policy
Definition: app-layer-parser.c:180
SCAppLayerParserStateIssetFlag
uint16_t SCAppLayerParserStateIssetFlag(AppLayerParserState *pstate, uint16_t flag)
Definition: app-layer-parser.c:2079
SCConfValIsTrue
int SCConfValIsTrue(const char *val)
Check if a value is true.
Definition: conf.c:578
AppLayerParserProtoCtx_::logger_bits
uint32_t logger_bits
Definition: app-layer-parser.c:98
AppLayerParserProtoCtx_::complete_tc
int complete_tc
Definition: app-layer-parser.c:115
AppLayerParserProtoCtx_::GetTxData
AppLayerTxData *(* GetTxData)(void *tx)
Definition: app-layer-parser.c:122
app-layer-tftp.h
AppLayerParserState_::log_id
uint64_t log_id
Definition: app-layer-parser.c:170
RegisterSMBParsers
void RegisterSMBParsers(void)
Definition: app-layer-smb.c:48
app-layer-ssh.h
RegisterIKEParsers
void RegisterIKEParsers(void)
Definition: app-layer-ike.c:43
Flow_::flags
uint64_t flags
Definition: flow.h:409
AppLayerParserIsEnabled
int AppLayerParserIsEnabled(AppProto alproto)
simple way to globally test if a alproto is registered and fully enabled in the configuration.
Definition: app-layer-parser.c:1761
AppLayerParserRegisterLocalStorageFunc
void AppLayerParserRegisterLocalStorageFunc(uint8_t ipproto, AppProto alproto, void *(*LocalStorageAlloc)(void), void(*LocalStorageFree)(void *))
Definition: app-layer-parser.c:504
BOTH_SET
#define BOTH_SET(a, b)
Definition: app-layer-parser.c:1921
AppLayerParserProtocolHasLogger
int AppLayerParserProtocolHasLogger(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1771
AppLayerParserRegisterOptionFlags
void AppLayerParserRegisterOptionFlags(uint8_t ipproto, AppProto alproto, uint32_t flags)
Definition: app-layer-parser.c:483
AppLayerParserGetStateNameById
const char * AppLayerParserGetStateNameById(uint8_t ipproto, AppProto alproto, const int id, const uint8_t direction)
Definition: app-layer-parser.c:1847
flow-util.h
FramesFree
void FramesFree(Frames *frames)
Definition: app-layer-frames.c:456
AppLayerParserSetStreamDepthFlag
void AppLayerParserSetStreamDepthFlag(uint8_t ipproto, AppProto alproto, void *state, uint64_t tx_id, uint8_t flags)
Definition: app-layer-parser.c:1814
AppLayerParserSetTransactionLogId
void AppLayerParserSetTransactionLogId(AppLayerParserState *pstate, uint64_t tx_id)
Definition: app-layer-parser.c:805
g_filedata_logger_enabled
bool g_filedata_logger_enabled
Definition: output-filedata.c:37
stream-tcp.h
AppLayerParserCtx_::ctxs_len
size_t ctxs_len
Definition: app-layer-parser.c:157
AppLayerParserApplyTxConfig
void AppLayerParserApplyTxConfig(uint8_t ipproto, AppProto alproto, void *state, void *tx, enum ConfigAction mode, AppLayerTxConfig config)
Definition: app-layer-parser.c:1438
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
AppLayerTxData::tx_type
uint8_t tx_type
Definition: app-layer-parser.h:215
AppLayerParserTransactionsCleanup
void AppLayerParserTransactionsCleanup(Flow *f, const uint8_t pkt_dir)
remove obsolete (inspected and logged) transactions
Definition: app-layer-parser.c:993
AppLayerParserGetProtocolParserLocalStorage
void * AppLayerParserGetProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:724
AppLayerParserProtoCtx_::LocalStorageFree
void(* LocalStorageFree)(void *)
Definition: app-layer-parser.c:104
AppLayerParserProtoCtx_
App layer protocol parser context.
Definition: app-layer-parser.c:87
RegisterSSHParsers
void RegisterSSHParsers(void)
Function to register the SSH protocol parsers and other functions.
Definition: app-layer-ssh.c:87
AppLayerParserProtoCtx_::StateGetTx
void *(* StateGetTx)(void *alstate, uint64_t tx_id)
Definition: app-layer-parser.c:112
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
FLOW_SGH_TOCLIENT
#define FLOW_SGH_TOCLIENT
Definition: flow.h:75
AppLayerParserSetTransactionInspectId
void AppLayerParserSetTransactionInspectId(const Flow *f, AppLayerParserState *pstate, void *alstate, const uint8_t flags, bool tag_txs_as_inspected)
Definition: app-layer-parser.c:844
SCAppLayerTxDataCleanup
void SCAppLayerTxDataCleanup(AppLayerTxData *txd)
Definition: app-layer-parser.c:831
FLOW_PROTO_MAX
@ FLOW_PROTO_MAX
Definition: flow-private.h:72
AppLayerParserProtoCtx_::ApplyTxConfig
void(* ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig)
Definition: app-layer-parser.c:123
AppLayerParserGetEventsByTx
AppLayerDecoderEvents * AppLayerParserGetEventsByTx(uint8_t ipproto, AppProto alproto, void *tx)
Definition: app-layer-parser.c:947
AppLayerGetTxIterator
AppLayerGetTxIteratorFunc AppLayerGetTxIterator(const uint8_t ipproto, const AppProto alproto)
Definition: app-layer-parser.c:783
next
struct HtpBodyChunk_ * next
Definition: app-layer-htp.h:0
AppLayerTxData::de_state
DetectEngineState * de_state
Definition: app-layer-parser.h:223
RegisterModbusParsers
void RegisterModbusParsers(void)
Function to register the Modbus protocol parser.
Definition: app-layer-modbus.c:72
name
const char * name
Definition: detect-engine-proto.c:48
AppLayerParserGetTxDetectProgress
uint8_t AppLayerParserGetTxDetectProgress(AppLayerTxData *txd, const uint8_t dir)
Definition: app-layer-parser.c:820
Flow_::proto
uint8_t proto
Definition: flow.h:382
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
StreamTcpSetDisableRawReassemblyFlag
void StreamTcpSetDisableRawReassemblyFlag(TcpSession *, char)
Set the No reassembly flag for the given direction in given TCP session.
Definition: stream-tcp.c:6883
AppLayerFramesSetupContainer
FramesContainer * AppLayerFramesSetupContainer(Flow *f)
Definition: app-layer-parser.c:216
AppLayerParserGetStateProgressCompletionStatus
uint8_t AppLayerParserGetStateProgressCompletionStatus(AppProto alproto, uint8_t direction)
Definition: app-layer-parser.c:1226
FramesContainer::toserver
Frames toserver
Definition: app-layer-frames.h:74
SCAppLayerParserStateSetFlag
void SCAppLayerParserStateSetFlag(AppLayerParserState *pstate, uint16_t flag)
Definition: app-layer-parser.c:2071
ssn
TcpSession ssn
Definition: fuzz_dataset.c:31
AppLayerStateData
Definition: app-layer-parser.h:155
Frame::offset
uint64_t offset
Definition: app-layer-frames.h:51
TcpStreamCnf_::reassembly_depth
uint32_t reassembly_depth
Definition: stream-tcp.h:75
Frame
Definition: app-layer-frames.h:45
flow-private.h
Flow_
Flow data structure.
Definition: flow.h:360
FLOW_PROTO_DEFAULT
@ FLOW_PROTO_DEFAULT
Definition: flow-private.h:69
AppLayerParserProtoCtx_::GetStateNameById
AppLayerParserGetStateNameByIdFn GetStateNameById
Definition: app-layer-parser.c:131
AppLayerIncGapErrorCounter
void AppLayerIncGapErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:168
APP_LAYER_PARSER_INT_STREAM_DEPTH_SET
#define APP_LAYER_PARSER_INT_STREAM_DEPTH_SET
Definition: app-layer-parser.h:42
SCAppLayerParserSetStreamDepth
void SCAppLayerParserSetStreamDepth(uint8_t ipproto, AppProto alproto, uint32_t stream_depth)
Definition: app-layer-parser.c:1798
LoggerId
LoggerId
Definition: suricata-common.h:491
Flow_::protomap
uint8_t protomap
Definition: flow.h:451
AppLayerParserGetTransactionLogId
uint64_t AppLayerParserGetTransactionLogId(AppLayerParserState *pstate)
Definition: app-layer-parser.c:791
AppProtoToString
const char * AppProtoToString(AppProto alproto)
Maps the ALPROTO_*, to its normalized string equivalent.
Definition: app-layer-protos.c:53
ctx
struct Thresholds ctx
AppLayerParserSupportsFiles
bool AppLayerParserSupportsFiles(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1410
AppLayerParserRegisterStateProgressCompletionStatus
void AppLayerParserRegisterStateProgressCompletionStatus(AppProto alproto, const int ts, const int tc)
Definition: app-layer-parser.c:592
AppLayerParserGetFirstDataDir
uint8_t AppLayerParserGetFirstDataDir(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1386
AppLayerParserGetSubStateProgressId
int8_t AppLayerParserGetSubStateProgressId(const AppProto alproto, const uint8_t sub_state, const char *state, const uint8_t dir_flag)
Translate name to progress value for a substate sub_state. Calls the registered callbacks.
Definition: app-layer-parser.c:1244
AppLayerParserProtoIsRegistered
int AppLayerParserProtoIsRegistered(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:253
AppLayerParserRegisterTxFreeFunc
void AppLayerParserRegisterTxFreeFunc(uint8_t ipproto, AppProto alproto, void(*StateTransactionFree)(void *, uint64_t))
Definition: app-layer-parser.c:554
FLOW_NOPAYLOAD_INSPECTION
#define FLOW_NOPAYLOAD_INSPECTION
Definition: flow.h:67
Frame::id
int64_t id
Definition: app-layer-frames.h:53
AppLayerParserGetStateIdByName
int AppLayerParserGetStateIdByName(uint8_t ipproto, AppProto alproto, const char *name, const uint8_t direction)
Definition: app-layer-parser.c:1832
Flow_::alproto_orig
AppProto alproto_orig
Definition: flow.h:462
AppLayerTxData::files_stored
uint32_t files_stored
Definition: app-layer-parser.h:190
AppLayerParserStateProtoCleanup
void AppLayerParserStateProtoCleanup(uint8_t protomap, AppProto alproto, void *alstate, AppLayerParserState *pstate)
Definition: app-layer-parser.c:1877
AppLayerParserProtoCtx_::StateGetTxIterator
AppLayerGetTxIteratorFunc StateGetTxIterator
Definition: app-layer-parser.c:113
AppLayerParserThreadCtxFree
void AppLayerParserThreadCtxFree(AppLayerParserThreadCtx *tctx)
Destroys the app layer parser thread context obtained using AppLayerParserThreadCtxAlloc().
Definition: app-layer-parser.c:364
AppLayerResult::needed
uint32_t needed
Definition: app-layer-parser.h:123
rust.h
MIN
#define MIN(x, y)
Definition: suricata-common.h:422
StreamTcpUpdateAppLayerProgress
void StreamTcpUpdateAppLayerProgress(TcpSession *ssn, char direction, const uint32_t progress)
update reassembly progress
Definition: stream-tcp.c:6851
AppLayerParserRegisterGetStateFuncs
void AppLayerParserRegisterGetStateFuncs(uint8_t ipproto, AppProto alproto, AppLayerParserGetStateIdByNameFn GetIdByNameFunc, AppLayerParserGetStateNameByIdFn GetNameByIdFunc)
Definition: app-layer-parser.c:651
FramesContainer
Definition: app-layer-frames.h:73
SCConfValIsFalse
int SCConfValIsFalse(const char *val)
Check if a value is false.
Definition: conf.c:603
stream-tcp-reassemble.h
p
Packet * p
Definition: fuzz_dataset.c:30
m
SCMutex m
Definition: flow-hash.h:6
AppLayerParserGetStateData
AppLayerStateData * AppLayerParserGetStateData(uint8_t ipproto, AppProto alproto, void *state)
Definition: app-layer-parser.c:1427
app-layer-http2.h
app-layer-ftp.h
AppLayerFrameNewByAbsoluteOffset
Frame * AppLayerFrameNewByAbsoluteOffset(Flow *f, const StreamSlice *stream_slice, const uint64_t frame_start, const int64_t len, int dir, uint8_t frame_type)
create new frame using the absolute offset from the start of the stream
Definition: app-layer-frames.c:611
AppLayerFrameGetLastOpenByType
Frame * AppLayerFrameGetLastOpenByType(Flow *f, const int dir, const uint8_t frame_type)
Definition: app-layer-frames.c:716
stream_config
TcpStreamCnf stream_config
Definition: stream-tcp.c:229
MAX
#define MAX(x, y)
Definition: suricata-common.h:426
Flow_::protoctx
void * protoctx
Definition: flow.h:439
AppLayerGetTxIterTuple::tx_ptr
void * tx_ptr
Definition: app-layer-parser.h:160
TcpStream_::data_required
uint32_t data_required
Definition: stream-tcp-private.h:133
AppLayerIncAllocErrorCounter
void AppLayerIncAllocErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:176
AppLayerTxData::tx_type_eop_ts
uint8_t tx_type_eop_ts
Definition: app-layer-parser.h:219
EXCEPTION_POLICY_NOT_SET
@ EXCEPTION_POLICY_NOT_SET
Definition: util-exception-policy-types.h:27
ExceptionPolicyParse
enum ExceptionPolicy ExceptionPolicyParse(const char *option, bool support_flow)
Definition: util-exception-policy.c:312
AppLayerParserRegisterUnittests
void AppLayerParserRegisterUnittests(void)
Definition: app-layer-parser.c:2098
util-var.h
AppLayerParserGetTransactionInspectId
uint64_t AppLayerParserGetTransactionInspectId(AppLayerParserState *pstate, uint8_t direction)
Definition: app-layer-parser.c:813
AppLayerParserRegisterApplyTxConfigFunc
void AppLayerParserRegisterApplyTxConfigFunc(uint8_t ipproto, AppProto alproto, void(*ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig))
Definition: app-layer-parser.c:702
StreamSlice::flags
uint8_t flags
STREAM_* flags.
Definition: app-layer-parser.h:130
AppLayerDecoderEvents_
Data structure to store app layer decoder events.
Definition: app-layer-events.h:33
AppLayerTxConfig
struct AppLayerTxConfig AppLayerTxConfig
FlowGetReverseProtoMapping
uint8_t FlowGetReverseProtoMapping(uint8_t rproto)
Definition: flow-util.c:114
RegisterDNP3Parsers
void RegisterDNP3Parsers(void)
Register the DNP3 application protocol parser.
Definition: app-layer-dnp3.c:1607
util-unittest-helper.h
AppLayerParserProtoCtx_::StateGetEventInfoById
int(* StateGetEventInfoById)(uint8_t event_id, const char **event_name, AppLayerEventType *event_type)
Definition: app-layer-parser.c:116
FTPParserCleanup
void FTPParserCleanup(void)
Free memory allocated for global FTP parser state.
Definition: app-layer-ftp.c:1530
AppLayerParserGetTxFiles
AppLayerGetFileState AppLayerParserGetTxFiles(const Flow *f, void *tx, const uint8_t direction)
Definition: app-layer-parser.c:963
AppLayerParserState_::flags
uint16_t flags
Definition: app-layer-parser.c:162
Flow_::sgh_toserver
const struct SigGroupHead_ * sgh_toserver
Definition: flow.h:492
StreamTcpReassembleTriggerRawInspection
void StreamTcpReassembleTriggerRawInspection(TcpSession *ssn, int direction)
Trigger RAW stream inspection.
Definition: stream-tcp-reassemble.c:2164
AppLayerParserState_::inspect_id
uint64_t inspect_id[2]
Definition: app-layer-parser.c:166
AppLayerResult
Definition: app-layer-parser.h:120
AppLayerParserFPtr
AppLayerResult(* AppLayerParserFPtr)(Flow *f, void *protocol_state, AppLayerParserState *pstate, StreamSlice stream_slice, void *local_storage)
Prototype for parsing functions.
Definition: app-layer-parser.h:145
AppLayerParserCtx
struct AppLayerParserCtx_ AppLayerParserCtx
Flow_::alparser
AppLayerParserState * alparser
Definition: flow.h:484
AppLayerParserRegisterProtocolParsers
void AppLayerParserRegisterProtocolParsers(void)
Definition: app-layer-parser.c:2017
SCAppLayerParserTriggerRawStreamInspection
void SCAppLayerParserTriggerRawStreamInspection(Flow *f, int direction)
Definition: app-layer-parser.c:1787
app-layer-detect-proto.h
AppLayerParserSubStateMapping::next
struct AppLayerParserSubStateMapping * next
Definition: app-layer-parser.c:80
app-layer-htp.h
FramesContainer::toclient
Frames toclient
Definition: app-layer-frames.h:75
AppLayerParserProtoCtx_::stream_depth
uint32_t stream_depth
Definition: app-layer-parser.c:134
decode.h
AppLayerParserGetSubStateCompletion
uint8_t AppLayerParserGetSubStateCompletion(const AppProto alproto, const uint8_t sub_state)
Definition: app-layer-parser.c:1303
StreamSlice::input_len
uint32_t input_len
Definition: app-layer-parser.h:128
util-debug.h
AppLayerParserState_
Definition: app-layer-parser.c:160
StreamSlice::offset
uint64_t offset
Definition: app-layer-parser.h:131
AppLayerTxData
Definition: app-layer-parser.h:172
AppLayerParserGetEventInfoById
int AppLayerParserGetEventInfoById(uint8_t ipproto, AppProto alproto, uint8_t event_id, const char **event_name, AppLayerEventType *event_type)
Definition: app-layer-parser.c:1373
AppLayerParserProtoCtx_::GetFrameIdByName
AppLayerParserGetFrameIdByNameFn GetFrameIdByName
Definition: app-layer-parser.c:127
AppLayerParserGetFrameNameById
const char * AppLayerParserGetFrameNameById(uint8_t ipproto, AppProto alproto, const uint8_t id)
Definition: app-layer-parser.c:1866
g_alproto_max
AppProto g_alproto_max
Definition: app-layer-protos.c:32
AppLayerParserGetTransactionActive
uint64_t AppLayerParserGetTransactionActive(const Flow *f, AppLayerParserState *pstate, uint8_t direction)
Definition: app-layer-parser.c:1393
SCAppLayerParserConfParserEnabled
int SCAppLayerParserConfParserEnabled(const char *ipproto, const char *alproto_name)
check if a parser is enabled in the config Returns enabled always if: were running unittests
Definition: app-layer-parser.c:385
AppLayerParserProtoCtx_::logger
bool logger
Definition: app-layer-parser.c:91
app-layer-ike.h
AppLayerFramesFreeContainer
void AppLayerFramesFreeContainer(Flow *f)
Definition: app-layer-parser.c:201
SCAppLayerParserRegisterLogger
void SCAppLayerParserRegisterLogger(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:535
app-layer-dnp3.h
AppLayerEventType
AppLayerEventType
Definition: app-layer-events.h:54
AppLayerIncTxCounter
void AppLayerIncTxCounter(ThreadVars *tv, Flow *f, int64_t step)
Definition: app-layer.c:160
AppLayerParserThreadCtx_::alproto_local_storage
void *(* alproto_local_storage)[FLOW_PROTO_MAX]
Definition: app-layer-parser.c:73
util-exception-policy.h
AppLayerGetFileState
struct AppLayerGetFileState AppLayerGetFileState
Definition: app-layer-parser.h:40
AppLayerParserProtoCtx_::StateGetEventInfo
int(* StateGetEventInfo)(const char *event_name, uint8_t *event_id, AppLayerEventType *event_type)
Definition: app-layer-parser.c:118
alp_tctx
AppLayerParserThreadCtx * alp_tctx
Definition: fuzz_applayerparserparse.c:24
SCDetectEngineStateFree
void SCDetectEngineStateFree(DetectEngineState *state)
Frees a DetectEngineState object.
Definition: detect-engine-state.c:168
AppLayerParserRegisterGetFrameFuncs
void AppLayerParserRegisterGetFrameFuncs(uint8_t ipproto, AppProto alproto, AppLayerParserGetFrameIdByNameFn GetIdByNameFunc, AppLayerParserGetFrameNameByIdFn GetNameByIdFunc)
Definition: app-layer-parser.c:661
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
AppLayerParserProtoCtx_::SetStreamDepthFlag
void(* SetStreamDepthFlag)(void *tx, uint8_t flags)
Definition: app-layer-parser.c:125
AppLayerFramesGetContainer
FramesContainer * AppLayerFramesGetContainer(const Flow *f)
Definition: app-layer-parser.c:209
AppLayerParserState_::min_id
uint64_t min_id
Definition: app-layer-parser.c:172
AppLayerGetTxIterTuple::tx_id
uint64_t tx_id
Definition: app-layer-parser.h:161
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:58
AppLayerParserRegisterLoggerBits
void AppLayerParserRegisterLoggerBits(uint8_t ipproto, AppProto alproto, LoggerId bits)
Definition: app-layer-parser.c:526
AppLayerParserRegisterStateFuncs
void AppLayerParserRegisterStateFuncs(uint8_t ipproto, AppProto alproto, void *(*StateAlloc)(void *, AppProto), void(*StateFree)(void *))
Definition: app-layer-parser.c:493
AppLayerResult::consumed
uint32_t consumed
Definition: app-layer-parser.h:122
AppLayerParserSubStateMapping::GetStateIdByName
AppLayerParserGetStateIdByNameFn GetStateIdByName
Definition: app-layer-parser.c:78
IS_DISRUPTED
#define IS_DISRUPTED(flags)
Definition: app-layer-parser.c:984
AppLayerParserSetEOF
void AppLayerParserSetEOF(AppLayerParserState *pstate)
Definition: app-layer-parser.c:1736
AppLayerParserProtoCtx_::RegisterUnittests
void(* RegisterUnittests)(void)
Definition: app-layer-parser.c:144
AppLayerParserStateFree
void AppLayerParserStateFree(AppLayerParserState *pstate)
Definition: app-layer-parser.c:272
app-layer-parser.h
AppLayerParserStateCleanup
void AppLayerParserStateCleanup(const Flow *f, void *alstate, AppLayerParserState *pstate)
Definition: app-layer-parser.c:1894
AppLayerParserGetStateProgress
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the progress value for a tx/protocol
Definition: app-layer-parser.c:1199
AppLayerParserSubStateMapping
Definition: app-layer-parser.c:76
BUG_ON
#define BUG_ON(x)
Definition: suricata-common.h:331
AppLayerDecoderEvents_::cnt
uint8_t cnt
Definition: app-layer-events.h:37
Flow_::sgh_toclient
const struct SigGroupHead_ * sgh_toclient
Definition: flow.h:489
RegisterNFSTCPParsers
void RegisterNFSTCPParsers(void)
Definition: app-layer-nfs-tcp.c:44
AppLayerParserRegisterGetEventInfo
void AppLayerParserRegisterGetEventInfo(uint8_t ipproto, AppProto alproto, int(*StateGetEventInfo)(const char *event_name, uint8_t *event_id, AppLayerEventType *event_type))
Definition: app-layer-parser.c:671
AppLayerParserProtoCtx_::GetFrameNameById
AppLayerParserGetFrameNameByIdFn GetFrameNameById
Definition: app-layer-parser.c:128
AppLayerParserProtoCtx
struct AppLayerParserProtoCtx_ AppLayerParserProtoCtx
App layer protocol parser context.
AppLayerParserSetup
int AppLayerParserSetup(void)
Definition: app-layer-parser.c:284
SCReturn
#define SCReturn
Definition: util-debug.h:286
RegisterFTPParsers
void RegisterFTPParsers(void)
Definition: app-layer-ftp.c:1379
AppLayerParserRegisterProtocolUnittests
void AppLayerParserRegisterProtocolUnittests(uint8_t ipproto, AppProto alproto, void(*RegisterUnittests)(void))
Definition: app-layer-parser.c:2090
AppLayerGetTxIterState
Definition: app-layer-parser.h:148
AppLayerParserProtoCtx_::StateAlloc
void *(* StateAlloc)(void *, AppProto)
Definition: app-layer-parser.c:100
FlowGetProtoMapping
uint8_t FlowGetProtoMapping(uint8_t proto)
Function to map the protocol to the defined FLOW_PROTO_* enumeration.
Definition: flow-util.c:100
RegisterTFTPParsers
void RegisterTFTPParsers(void)
Definition: app-layer-tftp.c:157
StreamSlice::input
const uint8_t * input
Definition: app-layer-parser.h:127
FLOW_PROTO_APPLAYER_MAX
#define FLOW_PROTO_APPLAYER_MAX
Definition: flow-private.h:75
SCReturnUInt
#define SCReturnUInt(x)
Definition: util-debug.h:290
conf.h
DEBUG_ASSERT_FLOW_LOCKED
#define DEBUG_ASSERT_FLOW_LOCKED(f)
Definition: util-validate.h:106
SCAppLayerParserRegisterGetTxSubStateFuncs
void SCAppLayerParserRegisterGetTxSubStateFuncs(AppProto alproto, const uint8_t sub_state, AppLayerParserGetStateIdByNameFn GetIdByNameFunc, AppLayerParserGetStateNameByIdFn GetNameByIdFunc)
register state<>name funcs for a substate
Definition: app-layer-parser.c:619
AppLayerTxData::txbits
GenericVar * txbits
Definition: app-layer-parser.h:225
BOTH_SET_OR_BOTH_UNSET
#define BOTH_SET_OR_BOTH_UNSET(a, b)
Definition: app-layer-parser.c:1922
Frame::len
int64_t len
Definition: app-layer-frames.h:52
ALPROTO_DOH2
@ ALPROTO_DOH2
Definition: app-layer-protos.h:66
SCReturnPtr
#define SCReturnPtr(x, type)
Definition: util-debug.h:300
AppLayerParserProtoCtx_::StateFree
void(* StateFree)(void *)
Definition: app-layer-parser.c:101
AppLayerParserRegisterGetTxFilesFunc
void AppLayerParserRegisterGetTxFilesFunc(uint8_t ipproto, AppProto alproto, AppLayerGetFileState(*GetTxFiles)(void *, uint8_t))
Definition: app-layer-parser.c:516
AppLayerParserRegisterSetStreamDepthFlag
void AppLayerParserRegisterSetStreamDepthFlag(uint8_t ipproto, AppProto alproto, void(*SetStreamDepthFlag)(void *tx, uint8_t flags))
Definition: app-layer-parser.c:712
AppLayerGetTxIterTuple
Definition: app-layer-parser.h:159
AppLayerIncParserErrorCounter
void AppLayerIncParserErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:184
ALPROTO_HTTP2
@ ALPROTO_HTTP2
Definition: app-layer-protos.h:69
AppLayerTxData::detect_progress_ts
uint8_t detect_progress_ts
Definition: app-layer-parser.h:210
AppLayerTxData::logged
uint32_t logged
logger flags for tx logging api
Definition: app-layer-parser.h:185
RunmodeIsUnittests
int RunmodeIsUnittests(void)
Definition: suricata.c:292
AppLayerParserGetTx
void * AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id)
Definition: app-layer-parser.c:1219
g_detect_disabled
int g_detect_disabled
Definition: suricata.c:190
AppLayerParserRegisterParser
int AppLayerParserRegisterParser(uint8_t ipproto, AppProto alproto, uint8_t direction, AppLayerParserFPtr Parser)
Register app layer parser for the protocol.
Definition: app-layer-parser.c:460
app-layer-imap.h
Frame::flags
uint8_t flags
Definition: app-layer-frames.h:47
SCRealloc
#define SCRealloc(ptr, sz)
Definition: util-mem.h:50
AppLayerParserThreadCtxAlloc
AppLayerParserThreadCtx * AppLayerParserThreadCtxAlloc(void)
Gets a new app layer protocol's parser thread context.
Definition: app-layer-parser.c:337
AppLayerParserRegisterGetTx
void AppLayerParserRegisterGetTx(uint8_t ipproto, AppProto alproto, void *(StateGetTx)(void *alstate, uint64_t tx_id))
Definition: app-layer-parser.c:574
ConfigAction
ConfigAction
Definition: util-config.h:27
AppLayerErrorGetExceptionPolicy
enum ExceptionPolicy AppLayerErrorGetExceptionPolicy(void)
Definition: app-layer-parser.c:187
util-file.h
AppLayerParserProtoCtx_::Parser
AppLayerParserFPtr Parser[2]
Definition: app-layer-parser.c:89
app-layer-modbus.h
APP_LAYER_MAX_PROGRESS
#define APP_LAYER_MAX_PROGRESS
Definition: app-layer-parser.h:81
AppLayerParserProtoCtx_::StateTransactionFree
void(* StateTransactionFree)(void *, uint64_t)
Definition: app-layer-parser.c:102
app-layer-frames.h
AppLayerParserPreRegister
int AppLayerParserPreRegister(void(*Register)(void))
Definition: app-layer-parser.c:2001
RegisterSSLParsers
void RegisterSSLParsers(void)
Definition: app-layer-ssl.c:3436
AppLayerParserProtoCtx_::option_flags
uint32_t option_flags
Definition: app-layer-parser.c:137
StreamTcpSetSessionNoReassemblyFlag
void StreamTcpSetSessionNoReassemblyFlag(TcpSession *, char)
disable reassembly
Definition: stream-tcp.c:6871
flags
uint8_t flags
Definition: decode-gre.h:0
SCGenericVarFree
void SCGenericVarFree(GenericVar *gv)
Definition: util-var.c:48
AppLayerParserParse
int AppLayerParserParse(ThreadVars *tv, AppLayerParserThreadCtx *alp_tctx, Flow *f, AppProto alproto, uint8_t flags, const uint8_t *input, uint32_t input_len)
Definition: app-layer-parser.c:1528
AppLayerGetFileState
Definition: util-file.h:44
AppLayerParserGetFrameNameByIdFn
const char *(* AppLayerParserGetFrameNameByIdFn)(const uint8_t id)
Definition: app-layer-parser.h:250
StreamTcpDisableAppLayer
void StreamTcpDisableAppLayer(Flow *f)
Definition: stream-tcp-reassemble.c:445
suricata-common.h
AppLayerGetFileState::fc
FileContainer * fc
Definition: util-file.h:45
AppLayerTxData::updated_tc
bool updated_tc
Definition: app-layer-parser.h:179
AppLayerParserCtx_::ctxs
AppLayerParserProtoCtx(* ctxs)[FLOW_PROTO_MAX]
Definition: app-layer-parser.c:156
AppLayerParserProtoCtx_::max_sub_state
uint8_t max_sub_state
Definition: app-layer-parser.c:152
AppLayerParserGetFrameIdByName
int AppLayerParserGetFrameIdByName(uint8_t ipproto, AppProto alproto, const char *name)
Definition: app-layer-parser.c:1857
ALPROTO_HTTP1
@ ALPROTO_HTTP1
Definition: app-layer-protos.h:36
SCAppLayerParserRegisterParserAcceptableDataDirection
void SCAppLayerParserRegisterParserAcceptableDataDirection(uint8_t ipproto, AppProto alproto, uint8_t direction)
Definition: app-layer-parser.c:472
AppLayerParserProtoCtx_::internal_flags
uint32_t internal_flags
Definition: app-layer-parser.c:140
AppLayerTxData::files_opened
uint32_t files_opened
track file open/logs so we can know how long to keep the tx
Definition: app-layer-parser.h:188
AppLayerParserRegisterStateDataFunc
void AppLayerParserRegisterStateDataFunc(uint8_t ipproto, AppProto alproto, AppLayerStateData *(*GetStateData)(void *state))
Definition: app-layer-parser.c:692
FilesPrune
void FilesPrune(FileContainer *fc, const StreamingBufferConfig *sbcfg, const bool trunc)
Definition: util-file.c:1175
AppLayerIncInternalErrorCounter
void AppLayerIncInternalErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:192
AppLayerParserGetStateNameByIdFn
const char *(* AppLayerParserGetStateNameByIdFn)(const int id, const uint8_t direction)
Definition: app-layer-parser.h:247
AppLayerParserGetSubStateProgressName
const char * AppLayerParserGetSubStateProgressName(const AppProto alproto, const uint8_t sub_state, const uint8_t state, const uint8_t dir_flag)
Definition: app-layer-parser.c:1277
AppLayerParserGetTxData
AppLayerTxData * AppLayerParserGetTxData(uint8_t ipproto, AppProto alproto, void *tx)
Definition: app-layer-parser.c:1420
FatalError
#define FatalError(...)
Definition: util-debug.h:517
AppLayerParserRegisterTxDataFunc
void AppLayerParserRegisterTxDataFunc(uint8_t ipproto, AppProto alproto, AppLayerTxData *(*GetTxData)(void *tx))
Definition: app-layer-parser.c:682
AppLayerTxData::tx_type_eop_tc
uint8_t tx_type_eop_tc
toclient end of tx progress value
Definition: app-layer-parser.h:221
AppLayerTxData::detect_progress_tc
uint8_t detect_progress_tc
Definition: app-layer-parser.h:211
SCAppLayerDecoderEventsFreeEvents
void SCAppLayerDecoderEventsFreeEvents(AppLayerDecoderEvents **events)
Definition: app-layer-events.c:138
TcpSession_::client
TcpStream client
Definition: stream-tcp-private.h:297
AppLayerParserGetStreamDepth
uint32_t AppLayerParserGetStreamDepth(const Flow *f)
Definition: app-layer-parser.c:1809
RegisterIMAPParsers
void RegisterIMAPParsers(void)
Definition: app-layer-imap.c:121
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:34
AppLayerParserProtoCtx_::GetTxFiles
AppLayerGetFileState(* GetTxFiles)(void *, uint8_t)
Definition: app-layer-parser.c:108
AppLayerParserProtoCtx_::GetStateIdByName
AppLayerParserGetStateIdByNameFn GetStateIdByName
Definition: app-layer-parser.c:130
app-layer-events.h
threadvars.h
util-validate.h
AppLayerGetFileState::cfg
const StreamingBufferConfig * cfg
Definition: util-file.h:46
FRAME_STREAM_TYPE
#define FRAME_STREAM_TYPE
Definition: app-layer-frames.h:32
APP_LAYER_TX_INSPECTED_TS
#define APP_LAYER_TX_INSPECTED_TS
Definition: app-layer-parser.h:51
TcpSession_::server
TcpStream server
Definition: stream-tcp-private.h:296
AppLayerParserRegisterGetTxIterator
void AppLayerParserRegisterGetTxIterator(uint8_t ipproto, AppProto alproto, AppLayerGetTxIteratorFunc Func)
Definition: app-layer-parser.c:584
SCConfGetNode
SCConfNode * SCConfGetNode(const char *name)
Get a SCConfNode by name.
Definition: conf.c:184
AppLayerParserProtoCtx_::complete_ts
int complete_ts
Definition: app-layer-parser.c:114
FLOW_SGH_TOSERVER
#define FLOW_SGH_TOSERVER
Definition: flow.h:73
AppLayerResult::status
int32_t status
Definition: app-layer-parser.h:121
SCFree
#define SCFree(p)
Definition: util-mem.h:61
AppLayerParserGetSubStateName
const char * AppLayerParserGetSubStateName(const AppProto alproto, const uint8_t sub_state)
Definition: app-layer-parser.c:1326
AppLayerTxData::files_logged
uint32_t files_logged
Definition: app-layer-parser.h:189
Flow_::alstate
void * alstate
Definition: flow.h:485
AppLayerParserPostStreamSetup
void AppLayerParserPostStreamSetup(void)
Definition: app-layer-parser.c:297
util-config.h
AppLayerParserGetDecoderEvents
AppLayerDecoderEvents * AppLayerParserGetDecoderEvents(AppLayerParserState *pstate)
Definition: app-layer-parser.c:939
THREE_SET
#define THREE_SET(a, b, c)
Definition: app-layer-parser.c:1923
AppLayerGetProtoName
const char * AppLayerGetProtoName(AppProto alproto)
Given the internal protocol id, returns a string representation of the protocol.
Definition: app-layer.c:1017
UTHAppLayerParserStateGetIds
void UTHAppLayerParserStateGetIds(void *ptr, uint64_t *i1, uint64_t *i2, uint64_t *log, uint64_t *min)
Definition: app-layer-parser.c:239
AppLayerGetTxIterTuple::has_next
bool has_next
Definition: app-layer-parser.h:162
RegisterHTPParsers
void RegisterHTPParsers(void)
Register the HTTP protocol and state handling functions to APP layer of the engine.
Definition: app-layer-htp.c:2626
AppLayerParserGetStateIdByNameFn
int(* AppLayerParserGetStateIdByNameFn)(const char *name, const uint8_t direction)
Definition: app-layer-parser.h:242
ALPROTO_HTTP
@ ALPROTO_HTTP
Definition: app-layer-protos.h:77
AppLayerParserGetTxEndState
uint8_t AppLayerParserGetTxEndState(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the end state (progress) for a transaction.
Definition: app-layer-parser.c:1177
FRAME_FLAG_ENDS_AT_EOF
#define FRAME_FLAG_ENDS_AT_EOF
Definition: app-layer-frames.h:40
RegisterSMTPParsers
void RegisterSMTPParsers(void)
Register the SMTP Protocol parser.
Definition: app-layer-smtp.c:2125
AppLayerParserStateAlloc
AppLayerParserState * AppLayerParserStateAlloc(void)
Definition: app-layer-parser.c:260
SCReturnCT
#define SCReturnCT(x, type)
Definition: util-debug.h:298
AppLayerParserState_::decoder_events
AppLayerDecoderEvents * decoder_events
Definition: app-layer-parser.c:175
suricata.h
AppLayerParserRegisterGetTxCnt
void AppLayerParserRegisterGetTxCnt(uint8_t ipproto, AppProto alproto, uint64_t(*StateGetTxCnt)(void *alstate))
Definition: app-layer-parser.c:564
app-layer-smb.h
AppLayerParserProtoCtx_::StateGetProgress
int(* StateGetProgress)(void *alstate, uint8_t direction)
Definition: app-layer-parser.c:110
AppLayerParserGetMaxSubState
uint8_t AppLayerParserGetMaxSubState(const AppProto alproto)
Definition: app-layer-parser.c:1349
AppLayerParserProtocolGetLoggerBits
LoggerId AppLayerParserProtocolGetLoggerBits(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1779
AppLayerTxData::events
AppLayerDecoderEvents * events
Definition: app-layer-parser.h:224
AppLayerParserCtx_
Definition: app-layer-parser.c:155
AppLayerParserRegisterGetEventInfoById
void AppLayerParserRegisterGetEventInfoById(uint8_t ipproto, AppProto alproto, int(*StateGetEventInfoById)(uint8_t event_id, const char **event_name, AppLayerEventType *event_type))
Definition: app-layer-parser.c:607
AppLayerGetTxIteratorFunc
AppLayerGetTxIterTuple(* AppLayerGetTxIteratorFunc)(const uint8_t ipproto, const AppProto alproto, void *alstate, uint64_t min_tx_id, uint64_t max_tx_id, AppLayerGetTxIterState *state)
tx iterator prototype
Definition: app-layer-parser.h:232
g_file_logger_enabled
bool g_file_logger_enabled
Definition: output-file.c:39
RegisterHTTP2Parsers
void RegisterHTTP2Parsers(void)
Definition: app-layer-http2.c:55
AppLayerParserSupportsSubStates
bool AppLayerParserSupportsSubStates(const AppProto alproto)
Definition: app-layer-parser.c:1356
STREAM_APP_PROGRESS
#define STREAM_APP_PROGRESS(stream)
Definition: stream-tcp-private.h:145
AppLayerParserThreadCtx_
Definition: app-layer-parser.c:72
app-layer-smtp.h
FlowChangeProto
int FlowChangeProto(Flow *f)
Check if change proto flag is set for flow.
Definition: flow.c:196
FlowGetDisruptionFlags
uint8_t FlowGetDisruptionFlags(const Flow *f, uint8_t flags)
get 'disruption' flags: GAP/DEPTH/PASS
Definition: flow.c:1170
TcpSession_
Definition: stream-tcp-private.h:283
flow.h
AppLayerParserProtoCtx_::sub_state_mappings
struct AppLayerParserSubStateMapping * sub_state_mappings
Definition: app-layer-parser.c:149
SCAppLayerParserReallocCtx
int SCAppLayerParserReallocCtx(AppProto alproto)
Definition: app-layer-parser.c:1983
SCLogNotice
#define SCLogNotice(...)
Macro used to log NOTICE messages.
Definition: util-debug.h:250
RegisterNFSUDPParsers
void RegisterNFSUDPParsers(void)
Definition: app-layer-nfs-udp.c:61
AppLayerParserGetMinId
uint64_t AppLayerParserGetMinId(AppLayerParserState *pstate)
Definition: app-layer-parser.c:798
Flow_::file_flags
uint16_t file_flags
Definition: flow.h:411
Flow_::alproto
AppProto alproto
application level protocol
Definition: flow.h:456
ExceptionPolicy
ExceptionPolicy
Definition: util-exception-policy-types.h:26
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
AppLayerParserDestroyProtocolParserLocalStorage
void AppLayerParserDestroyProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto, void *local_data)
Definition: app-layer-parser.c:736
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
SCConfNode_
Definition: conf.h:37
AppLayerParserSubStateMapping::sub_state
uint8_t sub_state
Definition: app-layer-parser.c:77
SCConfNode_::val
char * val
Definition: conf.h:39
AppLayerParserGetTxCnt
uint64_t AppLayerParserGetTxCnt(const Flow *f, void *alstate)
Definition: app-layer-parser.c:1212
SMTPParserCleanup
void SMTPParserCleanup(void)
Free memory allocated for global SMTP parser state.
Definition: app-layer-smtp.c:2183
AppLayerParserHasDecoderEvents
bool AppLayerParserHasDecoderEvents(AppLayerParserState *pstate)
Definition: app-layer-parser.c:1747
AppLayerParserGetFrameIdByNameFn
int(* AppLayerParserGetFrameIdByNameFn)(const char *frame_name)
Definition: app-layer-parser.h:249
AppLayerParserState_::frames
FramesContainer * frames
Definition: app-layer-parser.c:177
StreamTcpSetSessionBypassFlag
void StreamTcpSetSessionBypassFlag(TcpSession *)
enable bypass
Definition: stream-tcp.c:6894
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
app-layer-ssl.h
AppLayerStateData::file_flags
uint16_t file_flags
Definition: app-layer-parser.h:156
ARRAY_CAP_STEP
#define ARRAY_CAP_STEP
Definition: app-layer-parser.c:1978
APP_LAYER_TX_INSPECTED_TC
#define APP_LAYER_TX_INSPECTED_TC
Definition: app-layer-parser.h:52
AppLayerParserProtoCtx_::LocalStorageAlloc
void *(* LocalStorageAlloc)(void)
Definition: app-layer-parser.c:103
AppLayerParserGetEventInfo
int AppLayerParserGetEventInfo(uint8_t ipproto, AppProto alproto, const char *event_name, uint8_t *event_id, AppLayerEventType *event_type)
Definition: app-layer-parser.c:1361
app-layer-nfs-tcp.h
AppLayerTxData::updated_ts
bool updated_ts
Definition: app-layer-parser.h:180
app-layer.h
AppLayerParserSubStateMapping::GetStateNameById
AppLayerParserGetStateNameByIdFn GetStateNameById
Definition: app-layer-parser.c:79
AppLayerParserProtoCtx_::first_data_dir
uint8_t first_data_dir
Definition: app-layer-parser.c:96
f
Flow f
Definition: fuzz_dataset.c:32