suricata
app-layer-parser.h
Go to the documentation of this file.
1 /* Copyright (C) 2007-2025 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  * \author Anoop Saldanha <anoopsaldanha@gmail.com>
23  */
24 
25 #ifndef SURICATA_APP_LAYER_PARSER_H
26 #define SURICATA_APP_LAYER_PARSER_H
27 
28 #include "app-layer-protos.h"
29 #include "app-layer-events.h"
30 #include "detect-engine-state.h"
31 // Forward declarations for bindgen
32 enum ConfigAction;
33 typedef struct Flow_ Flow;
36 typedef struct ThreadVars_ ThreadVars;
37 typedef struct File_ File;
38 typedef enum LoggerId LoggerId;
39 // Forward declarations from util-file.h
41 
42 #define APP_LAYER_PARSER_INT_STREAM_DEPTH_SET BIT_U32(0)
43 
44 /* for use with the detect_progress_ts|detect_progress_tc fields */
45 
46 /** should inspection be skipped in that direction */
47 // defined in rust
48 // #define APP_LAYER_TX_SKIP_INSPECT_TS BIT_U8(0)
49 // #define APP_LAYER_TX_SKIP_INSPECT_TC BIT_U8(1)
50 /** is tx fully inspected? */
51 #define APP_LAYER_TX_INSPECTED_TS BIT_U8(2)
52 #define APP_LAYER_TX_INSPECTED_TC BIT_U8(3)
53 /** accept is applied to entire tx */
54 #define APP_LAYER_TX_ACCEPT BIT_U8(4)
55 
56 /** parser has successfully processed in the input, and has consumed
57  * all of it. */
58 #define APP_LAYER_OK (AppLayerResult) { 0, 0, 0 }
59 
60 /** parser has hit an unrecoverable error. Returning this to the API
61  * leads to no further calls to the parser. */
62 #define APP_LAYER_ERROR (AppLayerResult) { -1, 0, 0 }
63 
64 /** parser needs more data. Through 'c' it will indicate how many
65  * of the input bytes it has consumed. Through 'n' it will indicate
66  * how many more bytes it needs before getting called again.
67  * \note consumed (c) should never be more than the input len
68  * needed (n) + consumed (c) should be more than the input len
69  */
70 #define APP_LAYER_INCOMPLETE(c,n) (AppLayerResult) { 1, (c), (n) }
71 
72 int AppLayerParserProtoIsRegistered(uint8_t ipproto, AppProto alproto);
73 
74 /** \brief get the end state (progress) for a transaction.
75  *
76  * Uses the transaction type specific end state when the parser provides one,
77  * else the protocol completion status. Tolerates a NULL tx data pointer. */
78 uint8_t AppLayerParserGetTxEndState(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags);
79 
80 /** progress values need to stay under this. */
81 #define APP_LAYER_MAX_PROGRESS 48
82 
83 /***** transaction handling *****/
84 
85 int AppLayerParserSetup(void);
88 
90 
91 /**
92  * \brief Gets a new app layer protocol's parser thread context.
93  *
94  * \retval Non-NULL pointer on success.
95  * NULL pointer on failure.
96  */
98 
99 /**
100  * \brief Destroys the app layer parser thread context obtained
101  * using AppLayerParserThreadCtxAlloc().
102  *
103  * \param tctx Pointer to the thread context to be destroyed.
104  */
106 
107 /**
108  * \brief Given a protocol name, checks if the parser is enabled in
109  * the conf file.
110  *
111  * \param alproto_name Name of the app layer protocol.
112  *
113  * \retval 1 If enabled.
114  * \retval 0 If disabled.
115  */
116 int SCAppLayerParserConfParserEnabled(const char *ipproto, const char *alproto_name);
117 
119 
120 typedef struct AppLayerResult {
121  int32_t status;
122  uint32_t consumed;
123  uint32_t needed;
125 
126 typedef struct StreamSlice {
127  const uint8_t *input;
128  uint32_t input_len;
129  /// STREAM_* flags
130  uint8_t flags;
131  uint64_t offset;
133 
134 static inline const uint8_t *StreamSliceGetData(const StreamSlice *stream_slice)
135 {
136  return stream_slice->input;
137 }
138 
139 static inline uint32_t StreamSliceGetDataLen(const StreamSlice *stream_slice)
140 {
141  return stream_slice->input_len;
142 }
143 
144 /** \brief Prototype for parsing functions */
145 typedef AppLayerResult (*AppLayerParserFPtr)(Flow *f, void *protocol_state,
146  AppLayerParserState *pstate, StreamSlice stream_slice, void *local_storage);
147 
148 typedef struct AppLayerGetTxIterState {
149  union {
150  void *ptr;
151  uint64_t u64;
152  } un;
154 
155 typedef struct AppLayerStateData {
156  uint16_t file_flags;
158 
159 typedef struct AppLayerGetTxIterTuple {
160  void *tx_ptr;
161  uint64_t tx_id;
162  bool has_next;
164 
165 typedef struct AppLayerTxConfig {
166  /// config: log flags
167  uint8_t log_flags;
169 
170 typedef struct GenericVar_ GenericVar;
171 
172 typedef struct AppLayerTxData {
173  /// config: log flags
175 
176  /// The tx has been updated and needs to be processed : detection, logging, cleaning
177  /// It can then be skipped until new data arrives.
178  /// There is a boolean for both directions : to server and to client
181 
182  uint8_t flags;
183 
184  /// logger flags for tx logging api
185  uint32_t logged;
186 
187  /// track file open/logs so we can know how long to keep the tx
188  uint32_t files_opened;
189  uint32_t files_logged;
190  uint32_t files_stored;
191 
192  uint16_t file_flags;
193 
194  /// Indicated if a file tracking tx, and if so in which direction:
195  /// 0: not a file tx
196  /// STREAM_TOSERVER: file tx, files only in toserver dir
197  /// STREAM_TOCLIENT: file tx , files only in toclient dir
198  /// STREAM_TOSERVER|STREAM_TOCLIENT: files possible in both dirs
199  uint8_t file_tx;
200  /// Number of times this tx data has already been logged for signatures
201  /// not using application layer keywords
203 
204  /// detection engine progress tracking for use by detection engine
205  /// Reflects the "progress" of prefilter engines into this TX, where
206  /// the value is offset by 1. So if for progress state 0 the engines
207  /// are done, the value here will be 1. So a value of 0 means, no
208  /// progress tracked yet.
209  ///
212 
213  /// Type of transaction. Meaning is defined by the parser. Used to
214  /// select a state machine. 0 means it is not used.
215  uint8_t tx_type;
216  /// End of TX progress values
217  ///
218  /// toserver end of tx progress value
219  uint8_t tx_type_eop_ts;
220  /// toclient end of tx progress value
221  uint8_t tx_type_eop_tc;
222 
227 
229 
230 /** \brief tx iterator prototype */
232  (const uint8_t ipproto, const AppProto alproto,
233  void *alstate, uint64_t min_tx_id, uint64_t max_tx_id,
234  AppLayerGetTxIterState *state);
235 
236 /***** Parser related registration *****/
237 
238 /**
239  * \param name progress name to get the id for
240  * \param direction STREAM_TOSERVER/STREAM_TOCLIENT
241  */
242 typedef int (*AppLayerParserGetStateIdByNameFn)(const char *name, const uint8_t direction);
243 /**
244  * \param id progress value id to get the name for
245  * \param direction STREAM_TOSERVER/STREAM_TOCLIENT
246  */
247 typedef const char *(*AppLayerParserGetStateNameByIdFn)(const int id, const uint8_t direction);
248 
249 typedef int (*AppLayerParserGetFrameIdByNameFn)(const char *frame_name);
250 typedef const char *(*AppLayerParserGetFrameNameByIdFn)(const uint8_t id);
251 
253 int AppLayerParserPreRegister(void (*Register)(void));
254 /**
255  * \brief Register app layer parser for the protocol.
256  *
257  * \retval 0 On success.
258  * \retval -1 On failure.
259  */
260 int AppLayerParserRegisterParser(uint8_t ipproto, AppProto alproto,
261  uint8_t direction,
262  AppLayerParserFPtr Parser);
264  uint8_t ipproto, AppProto alproto, uint8_t direction);
265 void AppLayerParserRegisterOptionFlags(uint8_t ipproto, AppProto alproto,
266  uint32_t flags);
267 void AppLayerParserRegisterStateFuncs(uint8_t ipproto, AppProto alproto,
268  void *(*StateAlloc)(void *, AppProto), void (*StateFree)(void *));
270  void *(*LocalStorageAlloc)(void), void (*LocalStorageFree)(void *));
271 // void AppLayerParserRegisterGetEventsFunc(uint8_t ipproto, AppProto proto,
272 // AppLayerDecoderEvents *(*StateGetEvents)(void *) __attribute__((nonnull)));
274  uint8_t ipproto, AppProto alproto, AppLayerGetFileState (*GetTxFiles)(void *, uint8_t));
275 void SCAppLayerParserRegisterLogger(uint8_t ipproto, AppProto alproto);
276 void AppLayerParserRegisterLoggerBits(uint8_t ipproto, AppProto alproto, LoggerId bits);
277 void AppLayerParserRegisterGetStateProgressFunc(uint8_t ipproto, AppProto alproto,
278  int (*StateGetStateProgress)(void *alstate, uint8_t direction));
279 void AppLayerParserRegisterTxFreeFunc(uint8_t ipproto, AppProto alproto,
280  void (*StateTransactionFree)(void *, uint64_t));
281 void AppLayerParserRegisterGetTxCnt(uint8_t ipproto, AppProto alproto,
282  uint64_t (*StateGetTxCnt)(void *alstate));
283 void AppLayerParserRegisterGetTx(uint8_t ipproto, AppProto alproto,
284  void *(StateGetTx)(void *alstate, uint64_t tx_id));
285 void AppLayerParserRegisterGetTxIterator(uint8_t ipproto, AppProto alproto,
288  AppProto alproto, const int ts, const int tc);
289 void AppLayerParserRegisterGetEventInfo(uint8_t ipproto, AppProto alproto,
290  int (*StateGetEventInfo)(
291  const char *event_name, uint8_t *event_id, AppLayerEventType *event_type));
292 void AppLayerParserRegisterGetEventInfoById(uint8_t ipproto, AppProto alproto,
293  int (*StateGetEventInfoById)(
294  uint8_t event_id, const char **event_name, AppLayerEventType *event_type));
295 void AppLayerParserRegisterGetFrameFuncs(uint8_t ipproto, AppProto alproto,
296  AppLayerParserGetFrameIdByNameFn GetFrameIdByName,
297  AppLayerParserGetFrameNameByIdFn GetFrameNameById);
298 void AppLayerParserRegisterSetStreamDepthFlag(uint8_t ipproto, AppProto alproto,
299  void (*SetStreamDepthFlag)(void *tx, uint8_t flags));
300 void AppLayerParserRegisterGetStateFuncs(uint8_t ipproto, AppProto alproto,
301  AppLayerParserGetStateIdByNameFn GetStateIdByName,
302  AppLayerParserGetStateNameByIdFn GetStateNameById);
303 
304 /** \brief register state<>name funcs for a substate */
305 void SCAppLayerParserRegisterGetTxSubStateFuncs(AppProto alproto, const uint8_t sub_state,
306  AppLayerParserGetStateIdByNameFn GetIdByNameFunc,
307  AppLayerParserGetStateNameByIdFn GetNameByIdFunc);
308 
309 void AppLayerParserRegisterTxDataFunc(uint8_t ipproto, AppProto alproto,
310  AppLayerTxData *(*GetTxData)(void *tx));
311 void AppLayerParserRegisterApplyTxConfigFunc(uint8_t ipproto, AppProto alproto,
312  void (*ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig));
314  uint8_t ipproto, AppProto alproto, AppLayerStateData *(*GetStateData)(void *state));
315 
316 /***** Get and transaction functions *****/
317 
319  const AppProto alproto);
320 
321 void *AppLayerParserGetProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto);
322 void AppLayerParserDestroyProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto,
323  void *local_data);
324 
325 
328 void AppLayerParserSetTransactionLogId(AppLayerParserState *pstate, uint64_t tx_id);
329 
330 uint64_t AppLayerParserGetTransactionInspectId(AppLayerParserState *pstate, uint8_t direction);
332  void *alstate, const uint8_t flags, bool tag_txs_as_inspected);
333 
335 AppLayerDecoderEvents *AppLayerParserGetEventsByTx(uint8_t ipproto, AppProto alproto, void *tx);
336 AppLayerGetFileState AppLayerParserGetTxFiles(const Flow *f, void *tx, const uint8_t direction);
337 int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto,
338  void *alstate, uint8_t direction);
339 uint64_t AppLayerParserGetTxCnt(const Flow *, void *alstate);
340 void *AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id);
342  const AppProto alproto, const uint8_t sub_state, const char *state, const uint8_t dir_flag);
343 const char *AppLayerParserGetSubStateProgressName(const AppProto alproto, const uint8_t sub_state,
344  const uint8_t state, const uint8_t dir_flag);
345 uint8_t AppLayerParserGetSubStateCompletion(const AppProto alproto, const uint8_t sub_state);
346 uint8_t AppLayerParserGetStateProgressCompletionStatus(AppProto alproto, uint8_t direction);
347 const char *AppLayerParserGetSubStateName(const AppProto alproto, const uint8_t sub_state);
348 uint8_t AppLayerParserGetMaxSubState(const AppProto alproto);
349 bool AppLayerParserSupportsSubStates(const AppProto alproto);
350 int AppLayerParserGetEventInfo(uint8_t ipproto, AppProto alproto, const char *event_name,
351  uint8_t *event_id, AppLayerEventType *event_type);
352 int AppLayerParserGetEventInfoById(uint8_t ipproto, AppProto alproto, uint8_t event_id,
353  const char **event_name, AppLayerEventType *event_type);
354 
355 uint64_t AppLayerParserGetTransactionActive(const Flow *f, AppLayerParserState *pstate, uint8_t direction);
356 
357 uint8_t AppLayerParserGetFirstDataDir(uint8_t ipproto, AppProto alproto);
358 
359 bool AppLayerParserSupportsFiles(uint8_t ipproto, AppProto alproto);
360 
361 AppLayerTxData *AppLayerParserGetTxData(uint8_t ipproto, AppProto alproto, void *tx);
362 uint8_t AppLayerParserGetTxDetectProgress(AppLayerTxData *txd, const uint8_t dir);
363 AppLayerStateData *AppLayerParserGetStateData(uint8_t ipproto, AppProto alproto, void *state);
364 void AppLayerParserApplyTxConfig(uint8_t ipproto, AppProto alproto,
365  void *state, void *tx, enum ConfigAction mode, AppLayerTxConfig);
366 
367 /** \brief check if tx (possibly) has files in this tx for the direction */
368 #define AppLayerParserHasFilesInDir(txd, direction) \
369  ((txd)->files_opened && ((txd)->file_tx & (direction)) != 0)
370 
371 /***** General *****/
372 
374  uint8_t flags, const uint8_t *input, uint32_t input_len);
377 int AppLayerParserProtocolHasLogger(uint8_t ipproto, AppProto alproto);
378 LoggerId AppLayerParserProtocolGetLoggerBits(uint8_t ipproto, AppProto alproto);
380 void SCAppLayerParserSetStreamDepth(uint8_t ipproto, AppProto alproto, uint32_t stream_depth);
381 uint32_t AppLayerParserGetStreamDepth(const Flow *f);
382 void AppLayerParserSetStreamDepthFlag(uint8_t ipproto, AppProto alproto, void *state, uint64_t tx_id, uint8_t flags);
383 int AppLayerParserIsEnabled(AppProto alproto);
384 int AppLayerParserGetFrameIdByName(uint8_t ipproto, AppProto alproto, const char *name);
385 const char *AppLayerParserGetFrameNameById(uint8_t ipproto, AppProto alproto, const uint8_t id);
386 /**
387  * \param name progress name to get the id for
388  * \param direction STREAM_TOSERVER/STREAM_TOCLIENT
389  */
391  uint8_t ipproto, AppProto alproto, const char *name, uint8_t direction);
392 /**
393  * \param id progress value id to get the name for
394  * \param direction STREAM_TOSERVER/STREAM_TOCLIENT
395  */
397  uint8_t ipproto, AppProto alproto, const int id, uint8_t direction);
398 
399 /***** Cleanup *****/
400 
402  uint8_t protomap, AppProto alproto, void *alstate, AppLayerParserState *pstate);
403 void AppLayerParserStateCleanup(const Flow *f, void *alstate, AppLayerParserState *pstate);
404 
406 
407 void SCAppLayerParserStateSetFlag(AppLayerParserState *pstate, uint16_t flag);
408 uint16_t SCAppLayerParserStateIssetFlag(AppLayerParserState *pstate, uint16_t flag);
409 
412 
413 void AppLayerParserTransactionsCleanup(Flow *f, const uint8_t pkt_dir);
414 
415 /***** Unittests *****/
416 
417 #ifdef UNITTESTS
418 void AppLayerParserRegisterProtocolUnittests(uint8_t ipproto, AppProto alproto,
419  void (*RegisterUnittests)(void));
421 void UTHAppLayerParserStateGetIds(void *ptr, uint64_t *i1, uint64_t *i2, uint64_t *log, uint64_t *min);
422 #endif
423 
425 void FileApplyTxFlags(const AppLayerTxData *txd, const uint8_t direction, File *file);
426 
427 #endif /* SURICATA_APP_LAYER_PARSER_H */
AppLayerParserGetStateProgress
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *alstate, uint8_t direction)
get the progress value for a tx/protocol
Definition: app-layer-parser.c:1199
AppLayerParserThreadCtxFree
void AppLayerParserThreadCtxFree(AppLayerParserThreadCtx *tctx)
Destroys the app layer parser thread context obtained using AppLayerParserThreadCtxAlloc().
Definition: app-layer-parser.c:364
AppLayerParserGetTx
void * AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id)
Definition: app-layer-parser.c:1219
StreamSlice
Definition: app-layer-parser.h:126
AppLayerParserPostStreamSetup
void AppLayerParserPostStreamSetup(void)
Definition: app-layer-parser.c:297
AppLayerParserGetDecoderEvents
AppLayerDecoderEvents * AppLayerParserGetDecoderEvents(AppLayerParserState *pstate)
Definition: app-layer-parser.c:939
AppLayerTxConfig
Definition: app-layer-parser.h:165
AppLayerParserRegisterGetTx
void AppLayerParserRegisterGetTx(uint8_t ipproto, AppProto alproto, void *(StateGetTx)(void *alstate, uint64_t tx_id))
Definition: app-layer-parser.c:574
ts
uint64_t ts
Definition: source-erf-file.c:68
AppLayerTxData::flags
uint8_t flags
Definition: app-layer-parser.h:182
AppLayerParserRegisterLoggerBits
void AppLayerParserRegisterLoggerBits(uint8_t ipproto, AppProto alproto, LoggerId bits)
Definition: app-layer-parser.c:526
AppLayerGetTxIterState::ptr
void * ptr
Definition: app-layer-parser.h:150
AppLayerParserStateAlloc
AppLayerParserState * AppLayerParserStateAlloc(void)
Definition: app-layer-parser.c:260
AppLayerParserRegisterApplyTxConfigFunc
void AppLayerParserRegisterApplyTxConfigFunc(uint8_t ipproto, AppProto alproto, void(*ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig))
Definition: app-layer-parser.c:702
AppLayerParserSetEOF
void AppLayerParserSetEOF(AppLayerParserState *pstate)
Definition: app-layer-parser.c:1736
AppLayerParserRegisterGetTxCnt
void AppLayerParserRegisterGetTxCnt(uint8_t ipproto, AppProto alproto, uint64_t(*StateGetTxCnt)(void *alstate))
Definition: app-layer-parser.c:564
DetectEngineState_
Definition: detect-engine-state.h:95
StreamSlice
struct StreamSlice StreamSlice
AppLayerParserGetMaxSubState
uint8_t AppLayerParserGetMaxSubState(const AppProto alproto)
Definition: app-layer-parser.c:1349
AppLayerTxData::tx_type
uint8_t tx_type
Definition: app-layer-parser.h:215
AppLayerParserSupportsSubStates
bool AppLayerParserSupportsSubStates(const AppProto alproto)
Definition: app-layer-parser.c:1356
AppLayerParserRegisterGetFrameFuncs
void AppLayerParserRegisterGetFrameFuncs(uint8_t ipproto, AppProto alproto, AppLayerParserGetFrameIdByNameFn GetFrameIdByName, AppLayerParserGetFrameNameByIdFn GetFrameNameById)
Definition: app-layer-parser.c:661
AppLayerTxData::de_state
DetectEngineState * de_state
Definition: app-layer-parser.h:223
AppLayerParserGetStreamDepth
uint32_t AppLayerParserGetStreamDepth(const Flow *f)
Definition: app-layer-parser.c:1809
SCAppLayerParserReallocCtx
int SCAppLayerParserReallocCtx(AppProto alproto)
Definition: app-layer-parser.c:1983
name
const char * name
Definition: detect-engine-proto.c:48
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
AppLayerParserGetSubStateCompletion
uint8_t AppLayerParserGetSubStateCompletion(const AppProto alproto, const uint8_t sub_state)
Definition: app-layer-parser.c:1303
AppLayerParserRegisterSetStreamDepthFlag
void AppLayerParserRegisterSetStreamDepthFlag(uint8_t ipproto, AppProto alproto, void(*SetStreamDepthFlag)(void *tx, uint8_t flags))
Definition: app-layer-parser.c:712
AppLayerStateData
Definition: app-layer-parser.h:155
Flow_
Flow data structure.
Definition: flow.h:360
LoggerId
LoggerId
Definition: suricata-common.h:491
SCAppLayerParserConfParserEnabled
int SCAppLayerParserConfParserEnabled(const char *ipproto, const char *alproto_name)
Given a protocol name, checks if the parser is enabled in the conf file.
Definition: app-layer-parser.c:385
UTHAppLayerParserStateGetIds
void UTHAppLayerParserStateGetIds(void *ptr, uint64_t *i1, uint64_t *i2, uint64_t *log, uint64_t *min)
Definition: app-layer-parser.c:239
AppLayerTxData::files_stored
uint32_t files_stored
Definition: app-layer-parser.h:190
AppLayerErrorGetExceptionPolicy
enum ExceptionPolicy AppLayerErrorGetExceptionPolicy(void)
Definition: app-layer-parser.c:187
AppLayerResult::needed
uint32_t needed
Definition: app-layer-parser.h:123
AppLayerTxData
struct AppLayerTxData AppLayerTxData
proto
uint8_t proto
Definition: decode-template.h:0
AppLayerParserProtocolGetLoggerBits
LoggerId AppLayerParserProtocolGetLoggerBits(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1779
AppLayerParserGetFrameIdByName
int AppLayerParserGetFrameIdByName(uint8_t ipproto, AppProto alproto, const char *name)
Definition: app-layer-parser.c:1857
AppLayerParserRegisterGetEventInfoById
void AppLayerParserRegisterGetEventInfoById(uint8_t ipproto, AppProto alproto, int(*StateGetEventInfoById)(uint8_t event_id, const char **event_name, AppLayerEventType *event_type))
Definition: app-layer-parser.c:607
AppLayerGetTxIterTuple::tx_ptr
void * tx_ptr
Definition: app-layer-parser.h:160
AppLayerGetTxIterState::u64
uint64_t u64
Definition: app-layer-parser.h:151
AppLayerParserSetup
int AppLayerParserSetup(void)
Definition: app-layer-parser.c:284
AppLayerTxData::tx_type_eop_ts
uint8_t tx_type_eop_ts
Definition: app-layer-parser.h:219
AppLayerParserRegisterProtocolUnittests
void AppLayerParserRegisterProtocolUnittests(uint8_t ipproto, AppProto alproto, void(*RegisterUnittests)(void))
Definition: app-layer-parser.c:2090
StreamSlice::flags
uint8_t flags
STREAM_* flags.
Definition: app-layer-parser.h:130
LoggerId
enum LoggerId LoggerId
Definition: app-layer-parser.h:38
AppLayerDecoderEvents_
Data structure to store app layer decoder events.
Definition: app-layer-events.h:33
AppLayerTxConfig
struct AppLayerTxConfig AppLayerTxConfig
SCAppLayerParserRegisterGetTxSubStateFuncs
void SCAppLayerParserRegisterGetTxSubStateFuncs(AppProto alproto, const uint8_t sub_state, AppLayerParserGetStateIdByNameFn GetIdByNameFunc, AppLayerParserGetStateNameByIdFn GetNameByIdFunc)
register state<>name funcs for a substate
Definition: app-layer-parser.c:619
AppLayerParserGetProtocolParserLocalStorage
void * AppLayerParserGetProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:724
AppLayerParserRegisterGetTxFilesFunc
void AppLayerParserRegisterGetTxFilesFunc(uint8_t ipproto, AppProto alproto, AppLayerGetFileState(*GetTxFiles)(void *, uint8_t))
Definition: app-layer-parser.c:516
AppLayerResult
Definition: app-layer-parser.h:120
AppLayerParserFPtr
AppLayerResult(* AppLayerParserFPtr)(Flow *f, void *protocol_state, AppLayerParserState *pstate, StreamSlice stream_slice, void *local_storage)
Prototype for parsing functions.
Definition: app-layer-parser.h:145
AppLayerParserGetTxDetectProgress
uint8_t AppLayerParserGetTxDetectProgress(AppLayerTxData *txd, const uint8_t dir)
Definition: app-layer-parser.c:820
FileApplyTxFlags
void FileApplyTxFlags(const AppLayerTxData *txd, const uint8_t direction, File *file)
Definition: util-file.c:277
AppLayerResult
struct AppLayerResult AppLayerResult
AppLayerParserGetStateProgressCompletionStatus
uint8_t AppLayerParserGetStateProgressCompletionStatus(AppProto alproto, uint8_t direction)
Definition: app-layer-parser.c:1226
SCAppLayerParserStateSetFlag
void SCAppLayerParserStateSetFlag(AppLayerParserState *pstate, uint16_t flag)
Definition: app-layer-parser.c:2071
StreamSlice::input_len
uint32_t input_len
Definition: app-layer-parser.h:128
AppLayerParserState_
Definition: app-layer-parser.c:160
StreamSlice::offset
uint64_t offset
Definition: app-layer-parser.h:131
AppLayerTxData
Definition: app-layer-parser.h:172
AppLayerParserGetTransactionLogId
uint64_t AppLayerParserGetTransactionLogId(AppLayerParserState *pstate)
Definition: app-layer-parser.c:791
AppLayerParserRegisterLocalStorageFunc
void AppLayerParserRegisterLocalStorageFunc(uint8_t ipproto, AppProto proto, void *(*LocalStorageAlloc)(void), void(*LocalStorageFree)(void *))
Definition: app-layer-parser.c:504
AppLayerParserGetTxEndState
uint8_t AppLayerParserGetTxEndState(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the end state (progress) for a transaction.
Definition: app-layer-parser.c:1177
AppLayerParserRegisterStateProgressCompletionStatus
void AppLayerParserRegisterStateProgressCompletionStatus(AppProto alproto, const int ts, const int tc)
Definition: app-layer-parser.c:592
AppLayerGetTxIterTuple
struct AppLayerGetTxIterTuple AppLayerGetTxIterTuple
AppLayerParserProtoIsRegistered
int AppLayerParserProtoIsRegistered(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:253
AppLayerEventType
AppLayerEventType
Definition: app-layer-events.h:54
AppLayerParserRegisterGetStateFuncs
void AppLayerParserRegisterGetStateFuncs(uint8_t ipproto, AppProto alproto, AppLayerParserGetStateIdByNameFn GetStateIdByName, AppLayerParserGetStateNameByIdFn GetStateNameById)
Definition: app-layer-parser.c:651
SCAppLayerParserStateIssetFlag
uint16_t SCAppLayerParserStateIssetFlag(AppLayerParserState *pstate, uint16_t flag)
Definition: app-layer-parser.c:2079
AppLayerGetTxIterTuple::tx_id
uint64_t tx_id
Definition: app-layer-parser.h:161
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:58
SCAppLayerParserRegisterParserAcceptableDataDirection
void SCAppLayerParserRegisterParserAcceptableDataDirection(uint8_t ipproto, AppProto alproto, uint8_t direction)
Definition: app-layer-parser.c:472
AppLayerResult::consumed
uint32_t consumed
Definition: app-layer-parser.h:122
AppLayerParserRegisterOptionFlags
void AppLayerParserRegisterOptionFlags(uint8_t ipproto, AppProto alproto, uint32_t flags)
Definition: app-layer-parser.c:483
AppLayerParserRegisterStateDataFunc
void AppLayerParserRegisterStateDataFunc(uint8_t ipproto, AppProto alproto, AppLayerStateData *(*GetStateData)(void *state))
Definition: app-layer-parser.c:692
AppLayerParserGetSubStateProgressName
const char * AppLayerParserGetSubStateProgressName(const AppProto alproto, const uint8_t sub_state, const uint8_t state, const uint8_t dir_flag)
Definition: app-layer-parser.c:1277
AppLayerParserGetTxData
AppLayerTxData * AppLayerParserGetTxData(uint8_t ipproto, AppProto alproto, void *tx)
Definition: app-layer-parser.c:1420
AppLayerParserRegisterTxDataFunc
void AppLayerParserRegisterTxDataFunc(uint8_t ipproto, AppProto alproto, AppLayerTxData *(*GetTxData)(void *tx))
Definition: app-layer-parser.c:682
AppLayerParserGetMinId
uint64_t AppLayerParserGetMinId(AppLayerParserState *pstate)
Definition: app-layer-parser.c:798
AppLayerParserTransactionsCleanup
void AppLayerParserTransactionsCleanup(Flow *f, const uint8_t pkt_dir)
remove obsolete (inspected and logged) transactions
Definition: app-layer-parser.c:993
AppLayerParserDestroyProtocolParserLocalStorage
void AppLayerParserDestroyProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto, void *local_data)
Definition: app-layer-parser.c:736
AppLayerGetTxIterState
Definition: app-layer-parser.h:148
AppLayerParserGetTransactionInspectId
uint64_t AppLayerParserGetTransactionInspectId(AppLayerParserState *pstate, uint8_t direction)
Definition: app-layer-parser.c:813
AppLayerParserHasDecoderEvents
bool AppLayerParserHasDecoderEvents(AppLayerParserState *pstate)
Definition: app-layer-parser.c:1747
AppLayerParserSetTransactionInspectId
void AppLayerParserSetTransactionInspectId(const Flow *f, AppLayerParserState *pstate, void *alstate, const uint8_t flags, bool tag_txs_as_inspected)
Definition: app-layer-parser.c:844
StreamSlice::input
const uint8_t * input
Definition: app-layer-parser.h:127
AppLayerParserRegisterGetTxIterator
void AppLayerParserRegisterGetTxIterator(uint8_t ipproto, AppProto alproto, AppLayerGetTxIteratorFunc Func)
Definition: app-layer-parser.c:584
AppLayerGetTxIterator
AppLayerGetTxIteratorFunc AppLayerGetTxIterator(const uint8_t ipproto, const AppProto alproto)
Definition: app-layer-parser.c:783
AppLayerTxData::guessed_applayer_logged
uint8_t guessed_applayer_logged
Definition: app-layer-parser.h:202
AppLayerParserGetStateNameById
const char * AppLayerParserGetStateNameById(uint8_t ipproto, AppProto alproto, const int id, uint8_t direction)
Definition: app-layer-parser.c:1847
AppLayerParserGetSubStateName
const char * AppLayerParserGetSubStateName(const AppProto alproto, const uint8_t sub_state)
Definition: app-layer-parser.c:1326
AppLayerTxData::txbits
GenericVar * txbits
Definition: app-layer-parser.h:225
AppLayerParserGetTxFiles
AppLayerGetFileState AppLayerParserGetTxFiles(const Flow *f, void *tx, const uint8_t direction)
Definition: app-layer-parser.c:963
AppLayerParserGetEventInfo
int AppLayerParserGetEventInfo(uint8_t ipproto, AppProto alproto, const char *event_name, uint8_t *event_id, AppLayerEventType *event_type)
Definition: app-layer-parser.c:1361
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
AppLayerGetTxIterTuple
Definition: app-layer-parser.h:159
SCAppLayerParserSetStreamDepth
void SCAppLayerParserSetStreamDepth(uint8_t ipproto, AppProto alproto, uint32_t stream_depth)
Definition: app-layer-parser.c:1798
AppLayerTxData::detect_progress_ts
uint8_t detect_progress_ts
Definition: app-layer-parser.h:210
AppLayerTxData::logged
uint32_t logged
logger flags for tx logging api
Definition: app-layer-parser.h:185
AppLayerGetTxIterState
struct AppLayerGetTxIterState AppLayerGetTxIterState
AppLayerParserRegisterTxFreeFunc
void AppLayerParserRegisterTxFreeFunc(uint8_t ipproto, AppProto alproto, void(*StateTransactionFree)(void *, uint64_t))
Definition: app-layer-parser.c:554
AppLayerParserDeSetup
int AppLayerParserDeSetup(void)
Definition: app-layer-parser.c:310
ConfigAction
ConfigAction
Definition: util-config.h:27
AppLayerParserGetFrameNameById
const char * AppLayerParserGetFrameNameById(uint8_t ipproto, AppProto alproto, const uint8_t id)
Definition: app-layer-parser.c:1866
AppLayerFramesFreeContainer
void AppLayerFramesFreeContainer(Flow *f)
Definition: app-layer-parser.c:201
File_
Definition: util-file.h:146
AppLayerParserIsEnabled
int AppLayerParserIsEnabled(AppProto alproto)
simple way to globally test if a alproto is registered and fully enabled in the configuration.
Definition: app-layer-parser.c:1761
flags
uint8_t flags
Definition: decode-gre.h:0
AppLayerGetFileState
Definition: util-file.h:44
AppLayerParserGetFrameNameByIdFn
const char *(* AppLayerParserGetFrameNameByIdFn)(const uint8_t id)
Definition: app-layer-parser.h:250
AppLayerParserGetStateData
AppLayerStateData * AppLayerParserGetStateData(uint8_t ipproto, AppProto alproto, void *state)
Definition: app-layer-parser.c:1427
AppLayerParserApplyTxConfig
void AppLayerParserApplyTxConfig(uint8_t ipproto, AppProto alproto, void *state, void *tx, enum ConfigAction mode, AppLayerTxConfig)
Definition: app-layer-parser.c:1438
AppLayerParserSetTransactionLogId
void AppLayerParserSetTransactionLogId(AppLayerParserState *pstate, uint64_t tx_id)
Definition: app-layer-parser.c:805
GenericVar_
Definition: util-var.h:53
AppLayerTxData::updated_tc
bool updated_tc
Definition: app-layer-parser.h:179
AppLayerTxData::files_opened
uint32_t files_opened
track file open/logs so we can know how long to keep the tx
Definition: app-layer-parser.h:188
AppLayerParserRegisterStateFuncs
void AppLayerParserRegisterStateFuncs(uint8_t ipproto, AppProto alproto, void *(*StateAlloc)(void *, AppProto), void(*StateFree)(void *))
Definition: app-layer-parser.c:493
AppLayerParserRegisterUnittests
void AppLayerParserRegisterUnittests(void)
Definition: app-layer-parser.c:2098
AppLayerParserGetStateNameByIdFn
const char *(* AppLayerParserGetStateNameByIdFn)(const int id, const uint8_t direction)
Definition: app-layer-parser.h:247
AppLayerParserStateCleanup
void AppLayerParserStateCleanup(const Flow *f, void *alstate, AppLayerParserState *pstate)
Definition: app-layer-parser.c:1894
AppLayerTxData::tx_type_eop_tc
uint8_t tx_type_eop_tc
toclient end of tx progress value
Definition: app-layer-parser.h:221
AppLayerTxData::detect_progress_tc
uint8_t detect_progress_tc
Definition: app-layer-parser.h:211
AppLayerParserRegisterGetStateProgressFunc
void AppLayerParserRegisterGetStateProgressFunc(uint8_t ipproto, AppProto alproto, int(*StateGetStateProgress)(void *alstate, uint8_t direction))
Definition: app-layer-parser.c:544
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:34
AppLayerStateData
struct AppLayerStateData AppLayerStateData
app-layer-events.h
AppLayerTxConfig::log_flags
uint8_t log_flags
config: log flags
Definition: app-layer-parser.h:167
AppLayerParserRegisterProtocolParsers
void AppLayerParserRegisterProtocolParsers(void)
Definition: app-layer-parser.c:2017
AppLayerResult::status
int32_t status
Definition: app-layer-parser.h:121
AppLayerParserGetFirstDataDir
uint8_t AppLayerParserGetFirstDataDir(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1386
AppLayerParserGetSubStateProgressId
int8_t AppLayerParserGetSubStateProgressId(const AppProto alproto, const uint8_t sub_state, const char *state, const uint8_t dir_flag)
Translate name to progress value for a substate sub_state. Calls the registered callbacks.
Definition: app-layer-parser.c:1244
AppLayerTxData::files_logged
uint32_t files_logged
Definition: app-layer-parser.h:189
AppLayerGetTxIterTuple::has_next
bool has_next
Definition: app-layer-parser.h:162
AppLayerParserGetStateIdByNameFn
int(* AppLayerParserGetStateIdByNameFn)(const char *name, const uint8_t direction)
Definition: app-layer-parser.h:242
AppLayerParserGetTxCnt
uint64_t AppLayerParserGetTxCnt(const Flow *, void *alstate)
Definition: app-layer-parser.c:1212
SCAppLayerParserRegisterLogger
void SCAppLayerParserRegisterLogger(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:535
AppLayerParserRegisterParser
int AppLayerParserRegisterParser(uint8_t ipproto, AppProto alproto, uint8_t direction, AppLayerParserFPtr Parser)
Register app layer parser for the protocol.
Definition: app-layer-parser.c:460
AppLayerParserGetStateIdByName
int AppLayerParserGetStateIdByName(uint8_t ipproto, AppProto alproto, const char *name, uint8_t direction)
Definition: app-layer-parser.c:1832
AppLayerParserProtocolHasLogger
int AppLayerParserProtocolHasLogger(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1771
app-layer-protos.h
AppLayerParserThreadCtxAlloc
AppLayerParserThreadCtx * AppLayerParserThreadCtxAlloc(void)
Gets a new app layer protocol's parser thread context.
Definition: app-layer-parser.c:337
AppLayerParserSetStreamDepthFlag
void AppLayerParserSetStreamDepthFlag(uint8_t ipproto, AppProto alproto, void *state, uint64_t tx_id, uint8_t flags)
Definition: app-layer-parser.c:1814
AppLayerTxData::events
AppLayerDecoderEvents * events
Definition: app-layer-parser.h:224
AppLayerGetTxIteratorFunc
AppLayerGetTxIterTuple(* AppLayerGetTxIteratorFunc)(const uint8_t ipproto, const AppProto alproto, void *alstate, uint64_t min_tx_id, uint64_t max_tx_id, AppLayerGetTxIterState *state)
tx iterator prototype
Definition: app-layer-parser.h:232
AppLayerParserPreRegister
int AppLayerParserPreRegister(void(*Register)(void))
Definition: app-layer-parser.c:2001
AppLayerParserThreadCtx_
Definition: app-layer-parser.c:72
SCAppLayerTxDataCleanup
void SCAppLayerTxDataCleanup(AppLayerTxData *txd)
Definition: app-layer-parser.c:831
AppLayerParserStateFree
void AppLayerParserStateFree(AppLayerParserState *pstate)
Definition: app-layer-parser.c:272
AppLayerParserGetEventsByTx
AppLayerDecoderEvents * AppLayerParserGetEventsByTx(uint8_t ipproto, AppProto alproto, void *tx)
Definition: app-layer-parser.c:947
AppLayerTxData::file_flags
uint16_t file_flags
Definition: app-layer-parser.h:192
AppLayerParserRegisterGetEventInfo
void AppLayerParserRegisterGetEventInfo(uint8_t ipproto, AppProto alproto, int(*StateGetEventInfo)(const char *event_name, uint8_t *event_id, AppLayerEventType *event_type))
Definition: app-layer-parser.c:671
ExceptionPolicy
ExceptionPolicy
Definition: util-exception-policy-types.h:26
AppLayerParserParse
int AppLayerParserParse(ThreadVars *tv, AppLayerParserThreadCtx *tctx, Flow *f, AppProto alproto, uint8_t flags, const uint8_t *input, uint32_t input_len)
Definition: app-layer-parser.c:1528
AppLayerParserGetFrameIdByNameFn
int(* AppLayerParserGetFrameIdByNameFn)(const char *frame_name)
Definition: app-layer-parser.h:249
SCAppLayerParserTriggerRawStreamInspection
void SCAppLayerParserTriggerRawStreamInspection(Flow *f, int direction)
Definition: app-layer-parser.c:1787
AppLayerParserSupportsFiles
bool AppLayerParserSupportsFiles(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1410
AppLayerStateData::file_flags
uint16_t file_flags
Definition: app-layer-parser.h:156
AppLayerGetTxIterState::un
union AppLayerGetTxIterState::@7 un
AppLayerTxData::file_tx
uint8_t file_tx
Definition: app-layer-parser.h:199
AppLayerTxData::updated_ts
bool updated_ts
Definition: app-layer-parser.h:180
AppLayerTxData::config
AppLayerTxConfig config
config: log flags
Definition: app-layer-parser.h:174
f
Flow f
Definition: fuzz_dataset.c:32
AppLayerParserGetEventInfoById
int AppLayerParserGetEventInfoById(uint8_t ipproto, AppProto alproto, uint8_t event_id, const char **event_name, AppLayerEventType *event_type)
Definition: app-layer-parser.c:1373
AppLayerParserStateProtoCleanup
void AppLayerParserStateProtoCleanup(uint8_t protomap, AppProto alproto, void *alstate, AppLayerParserState *pstate)
Definition: app-layer-parser.c:1877
AppLayerParserGetTransactionActive
uint64_t AppLayerParserGetTransactionActive(const Flow *f, AppLayerParserState *pstate, uint8_t direction)
Definition: app-layer-parser.c:1393