suricata
app-layer.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2024 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  * \author Anoop Saldanha <anoopsaldanha@gmail.com>
23  *
24  * Generic App-layer functions
25  */
26 
27 #include "suricata-common.h"
28 #include "suricata.h"
29 #include "app-layer.h"
30 #include "app-layer-parser.h"
31 #include "app-layer-protos.h"
32 #include "app-layer-expectation.h"
33 #include "app-layer-ftp.h"
34 #include "app-layer-htp-range.h"
35 #include "app-layer-detect-proto.h"
36 #include "app-layer-frames.h"
37 #include "app-layer-events.h"
38 #include "stream-tcp-reassemble.h"
39 #include "stream-tcp-private.h"
40 #include "stream-tcp.h"
41 #include "flow.h"
42 #include "flow-util.h"
43 #include "flow-private.h"
44 #include "ippair.h"
45 #include "util-debug.h"
46 #include "util-print.h"
47 #include "util-profiling.h"
48 #include "util-validate.h"
49 #include "app-layer-htp-mem.h"
50 #include "util-exception-policy.h"
51 #include "counters.h"
52 #include "decode-tcp.h"
53 #include "host.h"
54 #include "packet-queue.h"
56 
58 /**
59  * \brief This is for the app layer in general and it contains per thread
60  * context relevant to both the alpd and alp.
61  */
63  /* App layer protocol detection thread context, from AppLayerProtoDetectGetCtxThread(). */
65  /* App layer parser thread context, from AppLayerParserThreadCtxAlloc(). */
67 
68 #ifdef PROFILING
69  uint64_t ticks_start;
70  uint64_t ticks_end;
71  uint64_t ticks_spent;
76 #endif
77 };
78 
79 #define FLOW_PROTO_CHANGE_MAX_DEPTH 4096
80 
81 #define MAX_COUNTER_SIZE 64
82 typedef struct AppLayerCounterNames_ {
91 
92 typedef struct AppLayerCounters_ {
101 
102 /* counter names. Only used at init. */
104 /* counter id's. Used that runtime. */
106 /* Exception policy global counters ids */
108 
109 /* Settings order as in the enum */
110 // clang-format off
112  .valid_settings_ids = {
113  /* EXCEPTION_POLICY_NOT_SET */ false,
114  /* EXCEPTION_POLICY_AUTO */ false,
115  /* EXCEPTION_POLICY_PASS_PACKET */ true,
116  /* EXCEPTION_POLICY_PASS_FLOW */ true,
117  /* EXCEPTION_POLICY_BYPASS_FLOW */ true,
118  /* EXCEPTION_POLICY_DROP_PACKET */ false,
119  /* EXCEPTION_POLICY_DROP_FLOW */ false,
120  /* EXCEPTION_POLICY_REJECT */ true,
121  /* EXCEPTION_POLICY_REJECT_BOTH */ true,
122  },
123  .valid_settings_ips = {
124  /* EXCEPTION_POLICY_NOT_SET */ false,
125  /* EXCEPTION_POLICY_AUTO */ false,
126  /* EXCEPTION_POLICY_PASS_PACKET */ true,
127  /* EXCEPTION_POLICY_PASS_FLOW */ true,
128  /* EXCEPTION_POLICY_BYPASS_FLOW */ true,
129  /* EXCEPTION_POLICY_DROP_PACKET */ true,
130  /* EXCEPTION_POLICY_DROP_FLOW */ true,
131  /* EXCEPTION_POLICY_REJECT */ true,
132  /* EXCEPTION_POLICY_REJECT_BOTH */ true,
133  },
134 };
135 // clang-format on
136 
137 void AppLayerSetupCounters(void);
138 void AppLayerDeSetupCounters(void);
139 
140 /***** L7 layer dispatchers *****/
141 
142 static inline int ProtoDetectDone(const Flow *f, const TcpSession *ssn, uint8_t direction) {
143  const TcpStream *stream = (direction & STREAM_TOSERVER) ? &ssn->client : &ssn->server;
145  (FLOW_IS_PM_DONE(f, direction) && FLOW_IS_PP_DONE(f, direction)));
146 }
147 
148 /**
149  * \note id can be 0 if protocol parser is disabled but detection
150  * is enabled.
151  */
152 static void AppLayerIncFlowCounter(ThreadVars *tv, Flow *f)
153 {
155  if (likely(tv && id.id > 0)) {
156  StatsCounterIncr(&tv->stats, id);
157  }
158 }
159 
160 void AppLayerIncTxCounter(ThreadVars *tv, Flow *f, int64_t step)
161 {
163  if (likely(tv && id.id > 0)) {
164  StatsCounterAddI64(&tv->stats, id, step);
165  }
166 }
167 
169 {
171  if (likely(tv && id.id > 0)) {
172  StatsCounterIncr(&tv->stats, id);
173  }
174 }
175 
177 {
179  if (likely(tv && id.id > 0)) {
180  StatsCounterIncr(&tv->stats, id);
181  }
182 }
183 
185 {
187  if (likely(tv && id.id > 0)) {
188  StatsCounterIncr(&tv->stats, id);
189  }
190 }
191 
193 {
195  if (likely(tv && id.id > 0)) {
196  StatsCounterIncr(&tv->stats, id);
197  }
198 }
199 
200 static void AppLayerIncrErrorExcPolicyCounter(ThreadVars *tv, Flow *f, enum ExceptionPolicy policy)
201 {
202 #ifdef UNITTESTS
203  if (tv == NULL) {
204  return;
205  }
206 #endif
208  /* for the summary values */
209  StatsCounterId g_id = eps_error_summary.eps_id[policy];
210 
211  if (likely(id.id > 0)) {
212  StatsCounterIncr(&tv->stats, id);
213  }
214  if (likely(g_id.id > 0)) {
215  StatsCounterIncr(&tv->stats, g_id);
216  }
217 }
218 
219 /* in IDS mode protocol detection is done in reverse order:
220  * when TCP data is ack'd. We want to flag the correct packet,
221  * so in this case we set a flag in the flow so that the first
222  * packet in the correct direction can be tagged.
223  *
224  * For IPS we update packet and flow. */
225 static inline void FlagPacketFlow(Packet *p, Flow *f, uint8_t flags)
226 {
227  if (p->proto != IPPROTO_TCP || EngineModeIsIPS()) {
228  if (flags & STREAM_TOSERVER) {
229  if (p->flowflags & FLOW_PKT_TOSERVER) {
232  } else {
234  }
235  } else {
236  if (p->flowflags & FLOW_PKT_TOCLIENT) {
239  } else {
241  }
242  }
243  } else {
244  if (flags & STREAM_TOSERVER) {
246  } else {
248  }
249  }
250 }
251 
252 static void DisableAppLayer(ThreadVars *tv, Flow *f, Packet *p)
253 {
254  SCLogDebug("disable app layer for flow %p alproto %u ts %u tc %u",
255  f, f->alproto, f->alproto_ts, f->alproto_tc);
258  TcpSession *ssn = f->protoctx;
261  AppLayerIncFlowCounter(tv, f);
262 
263  if (f->alproto_tc != ALPROTO_FAILED) {
264  if (f->alproto_tc == ALPROTO_UNKNOWN) {
266  }
267  FlagPacketFlow(p, f, STREAM_TOCLIENT);
268  }
269  if (f->alproto_ts != ALPROTO_FAILED) {
270  if (f->alproto_ts == ALPROTO_UNKNOWN) {
272  }
273  FlagPacketFlow(p, f, STREAM_TOSERVER);
274  }
275  SCLogDebug("disabled app layer for flow %p alproto %u ts %u tc %u",
276  f, f->alproto, f->alproto_ts, f->alproto_tc);
277 }
278 
279 /* See if we're going to have to give up:
280  *
281  * If we're getting a lot of data in one direction and the
282  * proto for this direction is unknown, proto detect will
283  * hold up segments in the segment list in the stream.
284  * They are held so that if we detect the protocol on the
285  * opposing stream, we can still parse this side of the stream
286  * as well. However, some sessions are very unbalanced. FTP
287  * data channels, large PUT/POST request and many others, can
288  * lead to cases where we would have to store many megabytes
289  * worth of segments before we see the opposing stream. This
290  * leads to risks of resource starvation.
291  *
292  * Here a cutoff point is enforced. If we've stored 100k in
293  * one direction and we've seen no data in the other direction,
294  * we give up.
295  *
296  * Giving up means we disable applayer an set an applayer event
297  */
298 static void TCPProtoDetectCheckBailConditions(ThreadVars *tv,
299  Flow *f, TcpSession *ssn, Packet *p)
300 {
301  if (ssn->state < TCP_ESTABLISHED) {
302  SCLogDebug("skip as long as TCP is not ESTABLISHED (TCP fast open)");
303  return;
304  }
305 
306  const uint32_t size_ts = StreamDataAvailableForProtoDetect(&ssn->client);
307  const uint32_t size_tc = StreamDataAvailableForProtoDetect(&ssn->server);
308  SCLogDebug("size_ts %" PRIu32 ", size_tc %" PRIu32, size_ts, size_tc);
309 
310  /* at least 100000 whatever the conditions
311  * and can be more if window is bigger and if configuration allows it */
312  const uint32_t size_tc_limit =
314  const uint32_t size_ts_limit =
316 
317  if (ProtoDetectDone(f, ssn, STREAM_TOSERVER) &&
318  ProtoDetectDone(f, ssn, STREAM_TOCLIENT))
319  {
320  goto failure;
321 
322  /* we bail out whatever the pp and pm states if
323  * we received too much data */
324  } else if (size_tc > 2 * size_tc_limit || size_ts > 2 * size_ts_limit) {
326  goto failure;
327 
328  } else if (FLOW_IS_PM_DONE(f, STREAM_TOSERVER) && FLOW_IS_PP_DONE(f, STREAM_TOSERVER) &&
329  size_ts > size_ts_limit && size_tc == 0) {
331  goto failure;
332 
333  } else if (FLOW_IS_PM_DONE(f, STREAM_TOCLIENT) && FLOW_IS_PP_DONE(f, STREAM_TOCLIENT) &&
334  size_tc > size_tc_limit && size_ts == 0) {
336  goto failure;
337 
338  /* little data in ts direction, pp done, pm not done (max
339  * depth not reached), ts direction done, lots of data in
340  * tc direction. */
341  } else if (size_tc > size_tc_limit && FLOW_IS_PP_DONE(f, STREAM_TOSERVER) &&
342  !(FLOW_IS_PM_DONE(f, STREAM_TOSERVER)) && FLOW_IS_PM_DONE(f, STREAM_TOCLIENT) &&
343  FLOW_IS_PP_DONE(f, STREAM_TOCLIENT)) {
345  goto failure;
346 
347  /* little data in tc direction, pp done, pm not done (max
348  * depth not reached), tc direction done, lots of data in
349  * ts direction. */
350  } else if (size_ts > size_ts_limit && FLOW_IS_PP_DONE(f, STREAM_TOCLIENT) &&
351  !(FLOW_IS_PM_DONE(f, STREAM_TOCLIENT)) && FLOW_IS_PM_DONE(f, STREAM_TOSERVER) &&
352  FLOW_IS_PP_DONE(f, STREAM_TOSERVER)) {
354  goto failure;
355  }
356  return;
357 
358 failure:
359  DisableAppLayer(tv, f, p);
360 }
361 
362 static int TCPProtoDetectTriggerOpposingSide(ThreadVars *tv, TcpReassemblyThreadCtx *ra_ctx,
363  Packet *p, TcpSession *ssn, const TcpStream *stream)
364 {
365  TcpStream *opposing_stream = NULL;
366  if (stream == &ssn->client) {
367  opposing_stream = &ssn->server;
368  } else {
369  opposing_stream = &ssn->client;
370  }
371 
372  /* if the opposing side is not going to work, then
373  * we just have to give up. */
374  if (opposing_stream->flags & STREAMTCP_STREAM_FLAG_NOREASSEMBLY) {
375  SCLogDebug("opposing dir has STREAMTCP_STREAM_FLAG_NOREASSEMBLY set");
376  return -1;
377  }
378 
379  enum StreamUpdateDir dir = StreamTcpInlineMode() ?
382  int ret = StreamTcpReassembleAppLayer(tv, ra_ctx, ssn,
383  opposing_stream, p, dir);
384  return ret;
385 }
386 
388 
389 /** \todo data const
390  * \retval int -1 error
391  * \retval int 0 ok
392  */
393 static int TCPProtoDetect(ThreadVars *tv, TcpReassemblyThreadCtx *ra_ctx,
394  AppLayerThreadCtx *app_tctx, Packet *p, Flow *f, TcpSession *ssn, TcpStream **stream,
395  uint8_t *data, uint32_t data_len, uint8_t flags, enum StreamUpdateDir app_update_dir)
396 {
397  AppProto *alproto;
398  AppProto *alproto_otherdir;
399  uint8_t direction = (flags & STREAM_TOSERVER) ? 0 : 1;
400 
401  if (flags & STREAM_TOSERVER) {
402  alproto = &f->alproto_ts;
403  alproto_otherdir = &f->alproto_tc;
404  } else {
405  alproto = &f->alproto_tc;
406  alproto_otherdir = &f->alproto_ts;
407  }
408 
409  SCLogDebug("Stream initializer (len %" PRIu32 ")", data_len);
410 #ifdef PRINT
411  if (data_len > 0) {
412  printf("=> Init Stream Data (app layer) -- start %s%s\n",
413  flags & STREAM_TOCLIENT ? "toclient" : "",
414  flags & STREAM_TOSERVER ? "toserver" : "");
415  PrintRawDataFp(stdout, data, data_len);
416  printf("=> Init Stream Data -- end\n");
417  }
418 #endif
419 
420  bool reverse_flow = false;
421  DEBUG_VALIDATE_BUG_ON(data == NULL && data_len > 0);
423  *alproto = AppLayerProtoDetectGetProto(app_tctx->alpd_tctx,
424  f, data, data_len,
425  IPPROTO_TCP, flags, &reverse_flow);
426  PACKET_PROFILING_APP_PD_END(app_tctx);
427  SCLogDebug("alproto %u rev %s", *alproto, reverse_flow ? "true" : "false");
428 
429  if (*alproto != ALPROTO_UNKNOWN) {
430  if (*alproto_otherdir != ALPROTO_UNKNOWN && *alproto_otherdir != *alproto) {
433 
435  /* if we already invoked the parser, we go with that proto */
436  f->alproto = *alproto_otherdir;
437  } else {
438  /* no data sent to parser yet, we can still choose
439  * we're trusting the server more. */
440  if (flags & STREAM_TOCLIENT)
441  f->alproto = *alproto;
442  else
443  f->alproto = *alproto_otherdir;
444  }
445  } else {
446  f->alproto = *alproto;
447  }
448 
452  FlagPacketFlow(p, f, flags);
453 
454  /* if protocol detection indicated that we need to reverse
455  * the direction of the flow, do it now. We flip the flow,
456  * packet and the direction flags */
457  if (reverse_flow &&
460  /* but only if we didn't already detect it on the other side. */
461  if (*alproto_otherdir == ALPROTO_UNKNOWN) {
462  SCLogDebug("reversing flow after proto detect told us so");
463  PacketSwap(p);
464  FlowSwap(f);
465  // Will reset signature groups in DetectRunSetup
466  f->de_ctx_version = UINT32_MAX;
467  SWAP_FLAGS(flags, STREAM_TOSERVER, STREAM_TOCLIENT);
468  if (*stream == &ssn->client) {
469  *stream = &ssn->server;
470  } else {
471  *stream = &ssn->client;
472  }
473  direction = 1 - direction;
474  } else {
475  // TODO event, error?
476  }
477  }
478 
479  /* account flow if we have both sides */
480  if (*alproto_otherdir != ALPROTO_UNKNOWN) {
481  AppLayerIncFlowCounter(tv, f);
482  }
483 
484  /* if we have seen data from the other direction first, send
485  * data for that direction first to the parser. This shouldn't
486  * be an issue, since each stream processing happens
487  * independently of the other stream direction. At this point of
488  * call, you need to know that this function's already being
489  * called by the very same StreamReassembly() function that we
490  * will now call shortly for the opposing direction. */
491  if ((ssn->data_first_seen_dir & (STREAM_TOSERVER | STREAM_TOCLIENT)) &&
493  {
494  SCLogDebug("protocol %s needs first data in other direction",
495  AppProtoToString(*alproto));
496 
497  if (TCPProtoDetectTriggerOpposingSide(tv, ra_ctx,
498  p, ssn, *stream) != 0)
499  {
500  goto detect_error;
501  }
502  if (FlowChangeProto(f)) {
503  /* We have the first data which requested a protocol change from P1 to P2
504  * even if it was not recognized at first as being P1
505  * As the second data was recognized as P1, the protocol did not change !
506  */
510  }
511  }
512 
513  /* if the parser operates such that it needs to see data from
514  * a particular direction first, we check if we have seen
515  * data from that direction first for the flow. IF it is not
516  * the same, we set an event and exit.
517  *
518  * \todo We need to figure out a more robust solution for this,
519  * as this can lead to easy evasion tactics, where the
520  * attacker can first send some dummy data in the wrong
521  * direction first to mislead our proto detection process.
522  * While doing this we need to update the parsers as well,
523  * since the parsers must be robust to see such wrong
524  * direction data.
525  * Either ways the moment we see the
526  * APPLAYER_WRONG_DIRECTION_FIRST_DATA event set for the
527  * flow, it shows something's fishy.
528  */
530  uint8_t first_data_dir;
531  first_data_dir = AppLayerParserGetFirstDataDir(f->proto, f->alproto);
532 
533  if (first_data_dir && !(first_data_dir & ssn->data_first_seen_dir)) {
536  goto detect_error;
537  }
538  /* This can happen if the current direction is not the
539  * right direction, and the data from the other(also
540  * the right direction) direction is available to be sent
541  * to the app layer, but it is not ack'ed yet and hence
542  * the forced call to STreamTcpAppLayerReassemble still
543  * hasn't managed to send data from the other direction
544  * to the app layer. */
545  if (first_data_dir && !(first_data_dir & flags)) {
551  SCReturnInt(-1);
552  }
553  }
554 
555  /* Set a value that is neither STREAM_TOSERVER, nor STREAM_TOCLIENT */
557 
558  /* finally, invoke the parser */
560  int r = AppLayerParserParse(tv, app_tctx->alp_tctx, f, f->alproto,
561  flags, data, data_len);
562  PACKET_PROFILING_APP_END(app_tctx);
563  p->app_update_direction = (uint8_t)app_update_dir;
564  if (r != 1) {
565  StreamTcpUpdateAppLayerProgress(ssn, direction, data_len);
566  }
567  if (r == 0) {
568  if (*alproto_otherdir == ALPROTO_UNKNOWN) {
569  TcpStream *opposing_stream;
570  if (*stream == &ssn->client) {
571  opposing_stream = &ssn->server;
572  } else {
573  opposing_stream = &ssn->client;
574  }
576  // can happen in detection-only
577  AppLayerIncFlowCounter(tv, f);
578  }
579  }
580  }
581  if (r < 0) {
582  goto parser_error;
583  }
584  } else {
585  /* if the ssn is midstream, we may end up with a case where the
586  * start of an HTTP request is missing. We won't detect HTTP based
587  * on the request. However, the reply is fine, so we detect
588  * HTTP anyway. This leads to passing the incomplete request to
589  * the htp parser.
590  *
591  * This has been observed, where the http parser then saw many
592  * bogus requests in the incomplete data.
593  *
594  * To counter this case, a midstream session MUST find it's
595  * protocol in the toserver direction. If not, we assume the
596  * start of the request/toserver is incomplete and no reliable
597  * detection and parsing is possible. So we give up.
598  */
601  {
602  if (FLOW_IS_PM_DONE(f, STREAM_TOSERVER) && FLOW_IS_PP_DONE(f, STREAM_TOSERVER)) {
603  SCLogDebug("midstream end pd %p", ssn);
604  /* midstream and toserver detection failed: give up */
605  DisableAppLayer(tv, f, p);
606  SCReturnInt(0);
607  }
608  }
609 
610  if (*alproto_otherdir != ALPROTO_UNKNOWN) {
611  uint8_t first_data_dir;
612  first_data_dir = AppLayerParserGetFirstDataDir(f->proto, *alproto_otherdir);
613 
614  /* this would handle this test case -
615  * http parser which says it wants to see toserver data first only.
616  * tcp handshake
617  * toclient data first received. - RUBBISH DATA which
618  * we don't detect as http
619  * toserver data next sent - we detect this as http.
620  * at this stage we see that toclient is the first data seen
621  * for this session and we try and redetect the app protocol,
622  * but we are unable to detect the app protocol like before.
623  * But since we have managed to detect the protocol for the
624  * other direction as http, we try to use that. At this
625  * stage we check if the direction of this stream matches
626  * to that acceptable by the app parser. If it is not the
627  * acceptable direction we error out.
628  */
630  (first_data_dir) && !(first_data_dir & flags))
631  {
632  goto detect_error;
633  }
634 
635  /* if protocol detection is marked done for our direction we
636  * pass our data on. We're only succeeded in finding one
637  * direction: the opposing stream
638  *
639  * If PD was not yet complete, we don't do anything.
640  */
642  if (data_len > 0)
644 
645  if (*alproto_otherdir != ALPROTO_FAILED) {
647  int r = AppLayerParserParse(tv, app_tctx->alp_tctx, f,
648  f->alproto, flags,
649  data, data_len);
650  PACKET_PROFILING_APP_END(app_tctx);
651  p->app_update_direction = (uint8_t)app_update_dir;
652  if (r != 1) {
653  StreamTcpUpdateAppLayerProgress(ssn, direction, data_len);
654  }
655 
660  AppLayerIncFlowCounter(tv, f);
661 
662  *alproto = *alproto_otherdir;
663  SCLogDebug("packet %" PRIu64 ": pd done(us %u them %u), parser called (r==%d), "
664  "APPLAYER_DETECT_PROTOCOL_ONLY_ONE_DIRECTION set",
665  PcapPacketCntGet(p), *alproto, *alproto_otherdir, r);
666  if (r < 0) {
667  goto parser_error;
668  }
669  }
670  *alproto = ALPROTO_FAILED;
672  FlagPacketFlow(p, f, flags);
673 
674  } else if (flags & STREAM_EOF) {
675  *alproto = f->alproto;
677  AppLayerIncFlowCounter(tv, f);
678  }
679  } else {
680  /* both sides unknown, let's see if we need to give up */
681  if (FlowChangeProto(f)) {
682  /* TCPProtoDetectCheckBailConditions does not work well because
683  * size_tc from STREAM_RIGHT_EDGE is not reset to zero
684  * so, we set a lower limit to the data we inspect
685  * We could instead have set ssn->server.sb.stream_offset = 0;
686  */
687  if (data_len >= FLOW_PROTO_CHANGE_MAX_DEPTH || (flags & STREAM_EOF)) {
688  DisableAppLayer(tv, f, p);
689  }
690  } else {
691  TCPProtoDetectCheckBailConditions(tv, f, ssn, p);
692  }
693  }
694  }
695  SCReturnInt(0);
696 parser_error:
698  AppLayerIncrErrorExcPolicyCounter(tv, f, g_applayerparser_error_policy);
699  SCReturnInt(-1);
700 detect_error:
701  DisableAppLayer(tv, f, p);
702  SCReturnInt(-2);
703 }
704 
705 /** \brief handle TCP data for the app-layer.
706  *
707  * First run protocol detection and then when the protocol is known invoke
708  * the app layer parser.
709  *
710  * \param stream ptr-to-ptr to stream object. Might change if flow dir is
711  * reversed.
712  */
714  TcpSession *ssn, TcpStream **stream, uint8_t *data, uint32_t data_len, uint8_t flags,
715  enum StreamUpdateDir app_update_dir)
716 {
717  SCEnter();
718 
720  DEBUG_VALIDATE_BUG_ON(data_len > (uint32_t)INT_MAX);
721 
722  AppLayerThreadCtx *app_tctx = ra_ctx->app_tctx;
723  AppProto alproto;
724  int r = 0;
725 
726  SCLogDebug("data_len %u flags %02X", data_len, flags);
728  SCLogDebug("STREAMTCP_FLAG_APP_LAYER_DISABLED is set");
729  goto end;
730  }
731 
732  const uint8_t direction = (flags & STREAM_TOSERVER) ? 0 : 1;
733 
734  if (flags & STREAM_TOSERVER) {
735  alproto = f->alproto_ts;
736  } else {
737  alproto = f->alproto_tc;
738  }
739 
740  /* If a gap notification, relay the notification on to the
741  * app-layer if known. */
742  if (flags & STREAM_GAP) {
743  SCLogDebug("GAP of size %u", data_len);
744  if (alproto == ALPROTO_UNKNOWN) {
746  SCLogDebug("ALPROTO_UNKNOWN flow %p, due to GAP in stream start", f);
747  /* if the other side didn't already find the proto, we're done */
748  if (f->alproto == ALPROTO_UNKNOWN) {
749  goto failure;
750  }
751  AppLayerIncFlowCounter(tv, f);
752  }
753  if (FlowChangeProto(f)) {
755  SCLogDebug("Cannot handle gap while changing protocol");
756  goto failure;
757  }
759  r = AppLayerParserParse(tv, app_tctx->alp_tctx, f, f->alproto,
760  flags, data, data_len);
761  PACKET_PROFILING_APP_END(app_tctx);
762  p->app_update_direction = (uint8_t)app_update_dir;
763  /* ignore parser result for gap */
764  StreamTcpUpdateAppLayerProgress(ssn, direction, data_len);
765  if (r < 0) {
767  AppLayerIncrErrorExcPolicyCounter(tv, f, g_applayerparser_error_policy);
768  SCReturnInt(-1);
769  }
770  goto end;
771  }
772 
773  /* if we don't know the proto yet and we have received a stream
774  * initializer message, we run proto detection.
775  * We receive 2 stream init msgs (one for each direction), we
776  * only run the proto detection for both and emit an event
777  * in the case protocols mismatch. */
778  if (alproto == ALPROTO_UNKNOWN && (flags & STREAM_START)) {
780  /* run protocol detection */
781  if (TCPProtoDetect(tv, ra_ctx, app_tctx, p, f, ssn, stream, data, data_len, flags,
782  app_update_dir) != 0) {
783  goto failure;
784  }
785  } else if (alproto != ALPROTO_UNKNOWN && FlowChangeProto(f)) {
786  SCLogDebug("protocol change, old %s", AppProtoToString(f->alproto_orig));
787  void *alstate_orig = f->alstate;
788  AppLayerParserState *alparser = f->alparser;
789  // we delay AppLayerParserStateCleanup because we may need previous parser state
793  /* rerun protocol detection */
794  int rd = TCPProtoDetect(
795  tv, ra_ctx, app_tctx, p, f, ssn, stream, data, data_len, flags, app_update_dir);
796  if (f->alproto == ALPROTO_UNKNOWN) {
797  DEBUG_VALIDATE_BUG_ON(alstate_orig != f->alstate);
798  // not enough data, revert AppLayerProtoDetectReset to rerun detection
799  f->alparser = alparser;
800  f->alproto = f->alproto_orig;
803  } else {
805  AppLayerParserStateProtoCleanup(f->protomap, f->alproto_orig, alstate_orig, alparser);
806  if (alstate_orig == f->alstate) {
807  // we just freed it
808  f->alstate = NULL;
809  }
810  }
811  if (rd != 0) {
812  SCLogDebug("proto detect failure");
813  goto failure;
814  }
815  SCLogDebug("protocol change, old %s, new %s",
817 
819  f->alproto != f->alproto_expect) {
821 
822  if (f->alproto_expect == ALPROTO_TLS && f->alproto != ALPROTO_TLS) {
825  }
826  }
827  } else {
828  SCLogDebug("stream data (len %" PRIu32 " alproto "
829  "%"PRIu16" (flow %p)", data_len, f->alproto, f);
830 #ifdef PRINT
831  if (data_len > 0) {
832  printf("=> Stream Data (app layer) -- start %s%s\n",
833  flags & STREAM_TOCLIENT ? "toclient" : "",
834  flags & STREAM_TOSERVER ? "toserver" : "");
835  PrintRawDataFp(stdout, data, data_len);
836  printf("=> Stream Data -- end\n");
837  }
838 #endif
839  /* if we don't have a data object here we are not getting it
840  * a start msg should have gotten us one */
841  if (f->alproto != ALPROTO_UNKNOWN) {
843  r = AppLayerParserParse(tv, app_tctx->alp_tctx, f, f->alproto,
844  flags, data, data_len);
845  PACKET_PROFILING_APP_END(app_tctx);
846  p->app_update_direction = (uint8_t)app_update_dir;
847  if (r != 1) {
848  StreamTcpUpdateAppLayerProgress(ssn, direction, data_len);
849  if (r < 0) {
852  AppLayerIncrErrorExcPolicyCounter(tv, f, g_applayerparser_error_policy);
853  SCReturnInt(-1);
854  }
855  }
856  }
857  }
858 
859  goto end;
860  failure:
861  r = -1;
862  end:
863  SCReturnInt(r);
864 }
865 
866 /**
867  * \brief Handle a app layer UDP message
868  *
869  * If the protocol is yet unknown, the proto detection code is run first.
870  *
871  * \param dp_ctx Thread app layer detect context
872  * \param f *locked* flow
873  * \param p UDP packet
874  *
875  * \retval 0 ok
876  * \retval -1 error
877  */
879 {
880  SCEnter();
881  AppProto *alproto;
882  AppProto *alproto_otherdir;
883 
885  SCReturnInt(0);
886  }
887 
888  int r = 0;
889  uint8_t flags = 0;
890  if (p->flowflags & FLOW_PKT_TOSERVER) {
891  flags |= STREAM_TOSERVER;
892  alproto = &f->alproto_ts;
893  alproto_otherdir = &f->alproto_tc;
894  } else {
895  flags |= STREAM_TOCLIENT;
896  alproto = &f->alproto_tc;
897  alproto_otherdir = &f->alproto_ts;
898  }
899 
901 
902  /* if the protocol is still unknown, run detection */
903  if (*alproto == ALPROTO_UNKNOWN) {
904  SCLogDebug("Detecting AL proto on udp mesg (len %" PRIu32 ")",
905  p->payload_len);
906 
907  bool reverse_flow = false;
909  *alproto = AppLayerProtoDetectGetProto(
910  tctx->alpd_tctx, f, p->payload, p->payload_len, IPPROTO_UDP, flags, &reverse_flow);
912 
913  switch (*alproto) {
914  case ALPROTO_UNKNOWN:
915  if (*alproto_otherdir != ALPROTO_UNKNOWN) {
916  // Use recognized side
917  f->alproto = *alproto_otherdir;
918  // do not keep ALPROTO_UNKNOWN for this side so as not to loop
919  *alproto = *alproto_otherdir;
920  if (*alproto_otherdir == ALPROTO_FAILED) {
921  SCLogDebug("ALPROTO_UNKNOWN flow %p", f);
922  }
923  } else {
924  // First side of protocol is unknown
925  *alproto = ALPROTO_FAILED;
926  }
927  break;
928  case ALPROTO_FAILED:
929  if (*alproto_otherdir != ALPROTO_UNKNOWN) {
930  // Use recognized side
931  f->alproto = *alproto_otherdir;
932  if (*alproto_otherdir == ALPROTO_FAILED) {
933  SCLogDebug("ALPROTO_UNKNOWN flow %p", f);
934  }
935  }
936  // else wait for second side of protocol
937  break;
938  default:
939  if (*alproto_otherdir != ALPROTO_UNKNOWN && *alproto_otherdir != ALPROTO_FAILED) {
940  if (*alproto_otherdir != *alproto) {
943  // data already sent to parser, we cannot change the protocol to use the one
944  // of the server
945  }
946  } else {
947  f->alproto = *alproto;
948  }
949  }
950  if (*alproto_otherdir == ALPROTO_UNKNOWN) {
951  if (f->alproto == ALPROTO_UNKNOWN) {
952  // so as to increase stat about .app_layer.flow.failed_udp
954  }
955  // If the other side is unknown, this is the first packet of the flow
956  AppLayerIncFlowCounter(tv, f);
957  }
958 
959  // parse the data if we recognized one protocol
960  if (f->alproto != ALPROTO_UNKNOWN && f->alproto != ALPROTO_FAILED) {
961  if (reverse_flow) {
962  SCLogDebug("reversing flow after proto detect told us so");
963  PacketSwap(p);
964  FlowSwap(f);
965  SWAP_FLAGS(flags, STREAM_TOSERVER, STREAM_TOCLIENT);
966  }
967 
969  r = AppLayerParserParse(tv, tctx->alp_tctx, f, f->alproto,
970  flags, p->payload, p->payload_len);
973  SCAppLayerParserStateIssetFlag(f->alparser, APP_LAYER_PARSER_BYPASS_READY)) {
975  }
977  }
979  /* we do only inspection in one direction, so flag both
980  * sides as done here */
981  FlagPacketFlow(p, f, STREAM_TOSERVER);
982  FlagPacketFlow(p, f, STREAM_TOCLIENT);
983  } else {
984  SCLogDebug("data (len %" PRIu32 " ), alproto "
985  "%"PRIu16" (flow %p)", p->payload_len, f->alproto, f);
986 
987  /* run the parser */
989  r = AppLayerParserParse(tv, tctx->alp_tctx, f, f->alproto,
990  flags, p->payload, p->payload_len);
992  SCAppLayerParserStateIssetFlag(f->alparser, APP_LAYER_PARSER_BYPASS_READY)) {
994  }
998  }
999  if (r < 0) {
1001  AppLayerIncrErrorExcPolicyCounter(tv, f, g_applayerparser_error_policy);
1002  SCReturnInt(-1);
1003  }
1004 
1005  SCReturnInt(r);
1006 }
1007 
1008 /***** Utility *****/
1009 
1010 AppProto AppLayerGetProtoByName(const char *alproto_name)
1011 {
1012  SCEnter();
1013  AppProto r = AppLayerProtoDetectGetProtoByName(alproto_name);
1014  SCReturnCT(r, "AppProto");
1015 }
1016 
1017 const char *AppLayerGetProtoName(AppProto alproto)
1018 {
1019  SCEnter();
1020  const char * r = AppLayerProtoDetectGetProtoName(alproto);
1021  SCReturnCT(r, "char *");
1022 }
1023 
1025 {
1026  SCEnter();
1027 
1028  AppProto alproto;
1029  AppProto alprotos[g_alproto_max];
1030 
1032 
1033  printf("=========Supported App Layer Protocols=========\n");
1034  for (alproto = 0; alproto < g_alproto_max; alproto++) {
1035  if (alprotos[alproto] == 1)
1036  printf("%s\n", AppLayerGetProtoName(alproto));
1037  }
1038 
1039  SCReturn;
1040 }
1041 
1042 /***** Setup/General Registration *****/
1043 static void AppLayerNamesSetup(void)
1044 {
1085 }
1086 
1087 int AppLayerSetup(void)
1088 {
1089  SCEnter();
1090 
1091  AppLayerNamesSetup();
1094 
1097 
1099  FrameConfigInit();
1100 
1101  SCReturnInt(0);
1102 }
1103 
1105 {
1106  SCEnter();
1107 
1110 
1113 
1114  SCReturnInt(0);
1115 }
1116 
1118 {
1119  SCEnter();
1120 
1121  AppLayerThreadCtx *app_tctx = SCCalloc(1, sizeof(*app_tctx));
1122  if (app_tctx == NULL)
1123  goto error;
1124 
1125  if ((app_tctx->alpd_tctx = AppLayerProtoDetectGetCtxThread()) == NULL)
1126  goto error;
1127  if ((app_tctx->alp_tctx = AppLayerParserThreadCtxAlloc()) == NULL)
1128  goto error;
1129 
1130  goto done;
1131  error:
1132  AppLayerDestroyCtxThread(app_tctx);
1133  app_tctx = NULL;
1134  done:
1135  SCReturnPtr(app_tctx, "void *");
1136 }
1137 
1139 {
1140  SCEnter();
1141 
1142  if (app_tctx == NULL)
1143  SCReturn;
1144 
1145  if (app_tctx->alpd_tctx != NULL)
1147  if (app_tctx->alp_tctx != NULL)
1149  SCFree(app_tctx);
1150 
1151  SCReturn;
1152 }
1153 
1154 #ifdef PROFILING
1156 {
1157  PACKET_PROFILING_APP_RESET(app_tctx);
1158 }
1159 
1161 {
1162  PACKET_PROFILING_APP_STORE(app_tctx, p);
1163 }
1164 #endif
1165 
1166 /** \brief HACK to work around our broken unix manager (re)init loop
1167  */
1169 {
1174  StatsRegisterGlobalCounter("app_layer.expectations", ExpectationGetCounter);
1177  StatsRegisterGlobalCounter("ippair.memuse", IPPairGetMemuse);
1178  StatsRegisterGlobalCounter("ippair.memcap", IPPairGetMemcap);
1179  StatsRegisterGlobalCounter("host.memuse", HostGetMemuse);
1180  StatsRegisterGlobalCounter("host.memcap", HostGetMemcap);
1181 }
1182 
1183 static bool IsAppLayerErrorExceptionPolicyStatsValid(enum ExceptionPolicy policy)
1184 {
1185  if (EngineModeIsIPS()) {
1187  }
1189 }
1190 
1191 static void AppLayerSetupExceptionPolicyPerProtoCounters(
1192  uint8_t ipproto_map, AppProto alproto, const char *alproto_str, const char *ipproto_suffix)
1193 {
1196  for (enum ExceptionPolicy i = EXCEPTION_POLICY_NOT_SET + 1; i < EXCEPTION_POLICY_MAX; i++) {
1197  if (IsAppLayerErrorExceptionPolicyStatsValid(i)) {
1198  snprintf(applayer_counter_names[alproto][ipproto_map].eps_name[i],
1199  sizeof(applayer_counter_names[alproto][ipproto_map].eps_name[i]),
1200  "app_layer.error.%s%s.exception_policy.%s", alproto_str, ipproto_suffix,
1201  ExceptionPolicyEnumToString(i, true));
1202  }
1203  }
1204  }
1205 }
1206 
1208 {
1209  const uint8_t ipprotos[] = { IPPROTO_TCP, IPPROTO_UDP };
1210  AppProto alprotos[g_alproto_max];
1211  const char *str = "app_layer.flow.";
1212  const char *estr = "app_layer.error.";
1213 
1216  if (unlikely(applayer_counter_names == NULL)) {
1217  FatalError("Unable to alloc applayer_counter_names.");
1218  }
1220  if (unlikely(applayer_counters == NULL)) {
1221  FatalError("Unable to alloc applayer_counters.");
1222  }
1223  /* We don't log stats counters if exception policy is `ignore`/`not set` */
1225  /* Register global counters for app layer error exception policy summary */
1226  const char *eps_default_str = "exception_policy.app_layer.error.";
1227  for (enum ExceptionPolicy i = EXCEPTION_POLICY_NOT_SET + 1; i < EXCEPTION_POLICY_MAX; i++) {
1228  if (IsAppLayerErrorExceptionPolicyStatsValid(i)) {
1229  snprintf(app_layer_error_eps_stats.eps_name[i],
1230  sizeof(app_layer_error_eps_stats.eps_name[i]), "%s%s", eps_default_str,
1231  ExceptionPolicyEnumToString(i, true));
1232  }
1233  }
1234  }
1235 
1237 
1238  for (uint8_t p = 0; p < FLOW_PROTO_APPLAYER_MAX; p++) {
1239  const uint8_t ipproto = ipprotos[p];
1240  const uint8_t ipproto_map = FlowGetProtoMapping(ipproto);
1241  const char *ipproto_suffix = (ipproto == IPPROTO_TCP) ? "_tcp" : "_udp";
1242  uint8_t ipprotos_all[256 / 8];
1243 
1244  for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
1245  if (alprotos[alproto] == 1) {
1246  const char *tx_str = "app_layer.tx.";
1247  const char *alproto_raw = AppLayerGetProtoName(alproto);
1248  char alproto_str[32];
1249  for (size_t i = 0; i < 32; i++) {
1250  alproto_str[i] = alproto_raw[i];
1251  if (alproto_str[i] == 0) {
1252  break;
1253  } else if (alproto_str[i] == '-') {
1254  alproto_str[i] = '_';
1255  }
1256  }
1257 
1258  memset(ipprotos_all, 0, sizeof(ipprotos_all));
1259  AppLayerProtoDetectSupportedIpprotos(alproto, ipprotos_all);
1260  if ((ipprotos_all[IPPROTO_TCP / 8] & (1 << (IPPROTO_TCP % 8))) &&
1261  (ipprotos_all[IPPROTO_UDP / 8] & (1 << (IPPROTO_UDP % 8)))) {
1262  snprintf(applayer_counter_names[alproto][ipproto_map].name,
1263  sizeof(applayer_counter_names[alproto][ipproto_map].name), "%s%s%s",
1264  str, alproto_str, ipproto_suffix);
1265  snprintf(applayer_counter_names[alproto][ipproto_map].tx_name,
1266  sizeof(applayer_counter_names[alproto][ipproto_map].tx_name), "%s%s%s",
1267  tx_str, alproto_str, ipproto_suffix);
1268 
1269  if (ipproto == IPPROTO_TCP) {
1270  snprintf(applayer_counter_names[alproto][ipproto_map].gap_error,
1271  sizeof(applayer_counter_names[alproto][ipproto_map].gap_error),
1272  "%s%s%s.gap", estr, alproto_str, ipproto_suffix);
1273  }
1274  snprintf(applayer_counter_names[alproto][ipproto_map].alloc_error,
1275  sizeof(applayer_counter_names[alproto][ipproto_map].alloc_error),
1276  "%s%s%s.alloc", estr, alproto_str, ipproto_suffix);
1277  snprintf(applayer_counter_names[alproto][ipproto_map].parser_error,
1278  sizeof(applayer_counter_names[alproto][ipproto_map].parser_error),
1279  "%s%s%s.parser", estr, alproto_str, ipproto_suffix);
1280  snprintf(applayer_counter_names[alproto][ipproto_map].internal_error,
1281  sizeof(applayer_counter_names[alproto][ipproto_map].internal_error),
1282  "%s%s%s.internal", estr, alproto_str, ipproto_suffix);
1283 
1284  AppLayerSetupExceptionPolicyPerProtoCounters(
1285  ipproto_map, alproto, alproto_str, ipproto_suffix);
1286  } else {
1287  snprintf(applayer_counter_names[alproto][ipproto_map].name,
1288  sizeof(applayer_counter_names[alproto][ipproto_map].name), "%s%s", str,
1289  alproto_str);
1290  snprintf(applayer_counter_names[alproto][ipproto_map].tx_name,
1291  sizeof(applayer_counter_names[alproto][ipproto_map].tx_name), "%s%s",
1292  tx_str, alproto_str);
1293 
1294  if (ipproto == IPPROTO_TCP) {
1295  snprintf(applayer_counter_names[alproto][ipproto_map].gap_error,
1296  sizeof(applayer_counter_names[alproto][ipproto_map].gap_error),
1297  "%s%s.gap", estr, alproto_str);
1298  }
1299  snprintf(applayer_counter_names[alproto][ipproto_map].alloc_error,
1300  sizeof(applayer_counter_names[alproto][ipproto_map].alloc_error),
1301  "%s%s.alloc", estr, alproto_str);
1302  snprintf(applayer_counter_names[alproto][ipproto_map].parser_error,
1303  sizeof(applayer_counter_names[alproto][ipproto_map].parser_error),
1304  "%s%s.parser", estr, alproto_str);
1305  snprintf(applayer_counter_names[alproto][ipproto_map].internal_error,
1306  sizeof(applayer_counter_names[alproto][ipproto_map].internal_error),
1307  "%s%s.internal", estr, alproto_str);
1308  AppLayerSetupExceptionPolicyPerProtoCounters(
1309  ipproto_map, alproto, alproto_str, "");
1310  }
1311  } else if (alproto == ALPROTO_FAILED) {
1312  snprintf(applayer_counter_names[alproto][ipproto_map].name,
1313  sizeof(applayer_counter_names[alproto][ipproto_map].name), "%s%s%s", str,
1314  "failed", ipproto_suffix);
1315  if (ipproto == IPPROTO_TCP) {
1316  snprintf(applayer_counter_names[alproto][ipproto_map].gap_error,
1317  sizeof(applayer_counter_names[alproto][ipproto_map].gap_error),
1318  "%sfailed%s.gap", estr, ipproto_suffix);
1319  }
1320  }
1321  }
1322  }
1323 }
1324 
1326 {
1327  const uint8_t ipprotos[] = { IPPROTO_TCP, IPPROTO_UDP };
1328  AppProto alprotos[g_alproto_max];
1330 
1331  /* We don't log stats counters if exception policy is `ignore`/`not set` */
1333  /* Register global counters for app layer error exception policy summary */
1334  for (enum ExceptionPolicy i = EXCEPTION_POLICY_NOT_SET + 1; i < EXCEPTION_POLICY_MAX; i++) {
1335  if (IsAppLayerErrorExceptionPolicyStatsValid(i)) {
1338  }
1339  }
1340  }
1341 
1342  for (uint8_t p = 0; p < FLOW_PROTO_APPLAYER_MAX; p++) {
1343  const uint8_t ipproto = ipprotos[p];
1344  const uint8_t ipproto_map = FlowGetProtoMapping(ipproto);
1345 
1346  for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
1347  if (alprotos[alproto] == 1) {
1348  applayer_counters[alproto][ipproto_map].counter_id = StatsRegisterCounter(
1349  applayer_counter_names[alproto][ipproto_map].name, &tv->stats);
1350 
1351  if (AppLayerParserProtoIsRegistered(ipproto, alproto) != 1)
1352  continue;
1353 
1354  applayer_counters[alproto][ipproto_map].counter_tx_id = StatsRegisterCounter(
1355  applayer_counter_names[alproto][ipproto_map].tx_name, &tv->stats);
1356 
1357  if (ipproto == IPPROTO_TCP) {
1358  applayer_counters[alproto][ipproto_map].gap_error_id = StatsRegisterCounter(
1359  applayer_counter_names[alproto][ipproto_map].gap_error, &tv->stats);
1360  }
1361  applayer_counters[alproto][ipproto_map].alloc_error_id = StatsRegisterCounter(
1362  applayer_counter_names[alproto][ipproto_map].alloc_error, &tv->stats);
1363  applayer_counters[alproto][ipproto_map].parser_error_id = StatsRegisterCounter(
1364  applayer_counter_names[alproto][ipproto_map].parser_error, &tv->stats);
1366  applayer_counter_names[alproto][ipproto_map].internal_error, &tv->stats);
1367  /* We don't log stats counters if exception policy is `ignore`/`not set` */
1370  for (enum ExceptionPolicy i = EXCEPTION_POLICY_NOT_SET + 1;
1371  i < EXCEPTION_POLICY_MAX; i++) {
1372  if (IsAppLayerErrorExceptionPolicyStatsValid(i)) {
1373  applayer_counters[alproto][ipproto_map]
1375  applayer_counter_names[alproto][ipproto_map].eps_name[i],
1376  &tv->stats);
1377  }
1378  }
1379  }
1380  } else if (alproto == ALPROTO_FAILED) {
1381  applayer_counters[alproto][ipproto_map].counter_id = StatsRegisterCounter(
1382  applayer_counter_names[alproto][ipproto_map].name, &tv->stats);
1383 
1384  if (ipproto == IPPROTO_TCP) {
1385  applayer_counters[alproto][ipproto_map].gap_error_id = StatsRegisterCounter(
1386  applayer_counter_names[alproto][ipproto_map].gap_error, &tv->stats);
1387  }
1388  }
1389  }
1390  }
1391 }
1392 
1394 {
1397 }
1398 
1399 /***** Unittests *****/
1400 
1401 #ifdef UNITTESTS
1402 
1403 #define TEST_START \
1404  Packet *p = PacketGetFromAlloc(); \
1405  FAIL_IF_NULL(p); \
1406  Flow f; \
1407  ThreadVars tv; \
1408  StreamTcpThread *stt = NULL; \
1409  TCPHdr tcph; \
1410  PacketQueueNoLock pq; \
1411  memset(&pq, 0, sizeof(PacketQueueNoLock)); \
1412  memset(&f, 0, sizeof(Flow)); \
1413  memset(&tv, 0, sizeof(ThreadVars)); \
1414  StatsThreadInit(&tv.stats); \
1415  memset(&tcph, 0, sizeof(TCPHdr)); \
1416  \
1417  FLOW_INITIALIZE(&f); \
1418  f.flags = FLOW_IPV4; \
1419  f.proto = IPPROTO_TCP; \
1420  p->flow = &f; \
1421  PacketSetTCP(p, (uint8_t *)&tcph); \
1422  \
1423  StreamTcpInitConfig(true); \
1424  IPPairInitConfig(true); \
1425  StreamTcpThreadInit(&tv, NULL, (void **)&stt); \
1426  \
1427  /* handshake */ \
1428  tcph.th_win = htons(5480); \
1429  tcph.th_flags = TH_SYN; \
1430  p->flowflags = FLOW_PKT_TOSERVER; \
1431  p->payload_len = 0; \
1432  p->payload = NULL; \
1433  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1); \
1434  TcpSession *ssn = (TcpSession *)f.protoctx; \
1435  \
1436  FAIL_IF(StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(&ssn->server)); \
1437  FAIL_IF(StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(&ssn->client)); \
1438  FAIL_IF(f.alproto != ALPROTO_UNKNOWN); \
1439  FAIL_IF(f.alproto_ts != ALPROTO_UNKNOWN); \
1440  FAIL_IF(f.alproto_tc != ALPROTO_UNKNOWN); \
1441  FAIL_IF(ssn->flags &STREAMTCP_FLAG_APP_LAYER_DISABLED); \
1442  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER)); \
1443  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER)); \
1444  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT)); \
1445  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT)); \
1446  FAIL_IF(ssn->data_first_seen_dir != 0); \
1447  \
1448  /* handshake */ \
1449  tcph.th_ack = htonl(1); \
1450  tcph.th_flags = TH_SYN | TH_ACK; \
1451  p->flowflags = FLOW_PKT_TOCLIENT; \
1452  p->payload_len = 0; \
1453  p->payload = NULL; \
1454  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1); \
1455  FAIL_IF(StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(&ssn->server)); \
1456  FAIL_IF(StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(&ssn->client)); \
1457  FAIL_IF(f.alproto != ALPROTO_UNKNOWN); \
1458  FAIL_IF(f.alproto_ts != ALPROTO_UNKNOWN); \
1459  FAIL_IF(f.alproto_tc != ALPROTO_UNKNOWN); \
1460  FAIL_IF(ssn->flags &STREAMTCP_FLAG_APP_LAYER_DISABLED); \
1461  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER)); \
1462  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER)); \
1463  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT)); \
1464  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT)); \
1465  FAIL_IF(ssn->data_first_seen_dir != 0); \
1466  \
1467  /* handshake */ \
1468  tcph.th_ack = htonl(1); \
1469  tcph.th_seq = htonl(1); \
1470  tcph.th_flags = TH_ACK; \
1471  p->flowflags = FLOW_PKT_TOSERVER; \
1472  p->payload_len = 0; \
1473  p->payload = NULL; \
1474  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1); \
1475  FAIL_IF(StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(&ssn->server)); \
1476  FAIL_IF(StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(&ssn->client)); \
1477  FAIL_IF(f.alproto != ALPROTO_UNKNOWN); \
1478  FAIL_IF(f.alproto_ts != ALPROTO_UNKNOWN); \
1479  FAIL_IF(f.alproto_tc != ALPROTO_UNKNOWN); \
1480  FAIL_IF(ssn->flags &STREAMTCP_FLAG_APP_LAYER_DISABLED); \
1481  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER)); \
1482  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER)); \
1483  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT)); \
1484  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT)); \
1485  FAIL_IF(ssn->data_first_seen_dir != 0);
1486 #define TEST_END \
1487  StreamTcpSessionClear(p->flow->protoctx); \
1488  StreamTcpThreadDeinit(&tv, (void *)stt); \
1489  StreamTcpFreeConfig(true); \
1490  PacketFree(p); \
1491  FLOW_DESTROY(&f); \
1492  IPPairShutdown(); \
1493  StatsThreadCleanup(&tv.stats);
1494 
1495 /**
1496  * \test GET -> HTTP/1.1
1497  */
1498 static int AppLayerTest01(void)
1499 {
1500  TEST_START;
1501 
1502  /* full request */
1503  uint8_t request[] = {
1504  0x47, 0x45, 0x54, 0x20, 0x2f, 0x69, 0x6e, 0x64,
1505  0x65, 0x78, 0x2e, 0x68, 0x74, 0x6d, 0x6c, 0x20,
1506  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x30,
1507  0x0d, 0x0a, 0x48, 0x6f, 0x73, 0x74, 0x3a, 0x20,
1508  0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73,
1509  0x74, 0x0d, 0x0a, 0x55, 0x73, 0x65, 0x72, 0x2d,
1510  0x41, 0x67, 0x65, 0x6e, 0x74, 0x3a, 0x20, 0x41,
1511  0x70, 0x61, 0x63, 0x68, 0x65, 0x42, 0x65, 0x6e,
1512  0x63, 0x68, 0x2f, 0x32, 0x2e, 0x33, 0x0d, 0x0a,
1513  0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x3a, 0x20,
1514  0x2a, 0x2f, 0x2a, 0x0d, 0x0a, 0x0d, 0x0a };
1515  tcph.th_ack = htonl(1);
1516  tcph.th_seq = htonl(1);
1517  tcph.th_flags = TH_PUSH | TH_ACK;
1519  p->payload_len = sizeof(request);
1520  p->payload = request;
1521  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1528  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1529  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1530  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1531  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1532  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
1533 
1534  /* full response - request ack */
1535  uint8_t response[] = {
1536  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x31,
1537  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
1538  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
1539  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
1540  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
1541  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
1542  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
1543  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
1544  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
1545  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
1546  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
1547  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
1548  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
1549  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
1550  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
1551  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
1552  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
1553  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
1554  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
1555  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
1556  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
1557  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
1558  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
1559  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
1560  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
1561  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
1562  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
1563  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
1564  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
1565  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
1566  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
1567  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
1568  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
1569  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
1570  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
1571  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
1572  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
1573  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
1574  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
1575  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
1576  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
1577  tcph.th_ack = htonl(88);
1578  tcph.th_seq = htonl(1);
1579  tcph.th_flags = TH_PUSH | TH_ACK;
1581  p->payload_len = sizeof(response);
1582  p->payload = response;
1583  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1590  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1591  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1592  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1593  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1595 
1596  /* response ack */
1597  tcph.th_ack = htonl(328);
1598  tcph.th_seq = htonl(88);
1599  tcph.th_flags = TH_ACK;
1601  p->payload_len = 0;
1602  p->payload = NULL;
1603  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1610  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1611  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1612  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1613  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1615 
1616  TEST_END;
1617  PASS;
1618 }
1619 
1620 /**
1621  * \test GE -> T -> HTTP/1.1
1622  */
1623 static int AppLayerTest02(void)
1624 {
1625  TEST_START;
1626 
1627  /* partial request */
1628  uint8_t request1[] = { 0x47, 0x45, };
1629  tcph.th_ack = htonl(1);
1630  tcph.th_seq = htonl(1);
1631  tcph.th_flags = TH_PUSH | TH_ACK;
1633  p->payload_len = sizeof(request1);
1634  p->payload = request1;
1635  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1642  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1643  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1644  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1645  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1646  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
1647 
1648  /* response ack against partial request */
1649  tcph.th_ack = htonl(3);
1650  tcph.th_seq = htonl(1);
1651  tcph.th_flags = TH_ACK;
1653  p->payload_len = 0;
1654  p->payload = NULL;
1655  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1662  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1663  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1664  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1665  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1666  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
1667 
1668  /* complete partial request */
1669  uint8_t request2[] = {
1670  0x54, 0x20, 0x2f, 0x69, 0x6e, 0x64,
1671  0x65, 0x78, 0x2e, 0x68, 0x74, 0x6d, 0x6c, 0x20,
1672  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x30,
1673  0x0d, 0x0a, 0x48, 0x6f, 0x73, 0x74, 0x3a, 0x20,
1674  0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73,
1675  0x74, 0x0d, 0x0a, 0x55, 0x73, 0x65, 0x72, 0x2d,
1676  0x41, 0x67, 0x65, 0x6e, 0x74, 0x3a, 0x20, 0x41,
1677  0x70, 0x61, 0x63, 0x68, 0x65, 0x42, 0x65, 0x6e,
1678  0x63, 0x68, 0x2f, 0x32, 0x2e, 0x33, 0x0d, 0x0a,
1679  0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x3a, 0x20,
1680  0x2a, 0x2f, 0x2a, 0x0d, 0x0a, 0x0d, 0x0a };
1681  tcph.th_ack = htonl(1);
1682  tcph.th_seq = htonl(3);
1683  tcph.th_flags = TH_PUSH | TH_ACK;
1685  p->payload_len = sizeof(request2);
1686  p->payload = request2;
1687  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1694  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1695  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1696  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1697  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1698  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
1699 
1700  /* response - request ack */
1701  uint8_t response[] = {
1702  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x31,
1703  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
1704  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
1705  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
1706  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
1707  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
1708  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
1709  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
1710  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
1711  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
1712  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
1713  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
1714  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
1715  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
1716  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
1717  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
1718  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
1719  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
1720  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
1721  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
1722  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
1723  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
1724  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
1725  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
1726  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
1727  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
1728  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
1729  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
1730  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
1731  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
1732  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
1733  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
1734  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
1735  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
1736  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
1737  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
1738  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
1739  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
1740  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
1741  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
1742  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
1743  tcph.th_ack = htonl(88);
1744  tcph.th_seq = htonl(1);
1745  tcph.th_flags = TH_PUSH | TH_ACK;
1747  p->payload_len = sizeof(response);
1748  p->payload = response;
1749  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1756  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1757  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1758  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1759  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1761 
1762  /* response ack */
1763  tcph.th_ack = htonl(328);
1764  tcph.th_seq = htonl(88);
1765  tcph.th_flags = TH_ACK;
1767  p->payload_len = 0;
1768  p->payload = NULL;
1769  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1776  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1777  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1778  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1779  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1781 
1782  TEST_END;
1783  PASS;
1784 }
1785 
1786 /**
1787  * \test GET -> RUBBISH(PM AND PP DONE IN ONE GO)
1788  */
1789 static int AppLayerTest03(void)
1790 {
1791  TEST_START;
1792 
1793  /* request */
1794  uint8_t request[] = {
1795  0x47, 0x45, 0x54, 0x20, 0x2f, 0x69, 0x6e, 0x64,
1796  0x65, 0x78, 0x2e, 0x68, 0x74, 0x6d, 0x6c, 0x20,
1797  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x30,
1798  0x0d, 0x0a, 0x48, 0x6f, 0x73, 0x74, 0x3a, 0x20,
1799  0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73,
1800  0x74, 0x0d, 0x0a, 0x55, 0x73, 0x65, 0x72, 0x2d,
1801  0x41, 0x67, 0x65, 0x6e, 0x74, 0x3a, 0x20, 0x41,
1802  0x70, 0x61, 0x63, 0x68, 0x65, 0x42, 0x65, 0x6e,
1803  0x63, 0x68, 0x2f, 0x32, 0x2e, 0x33, 0x0d, 0x0a,
1804  0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x3a, 0x20,
1805  0x2a, 0x2f, 0x2a, 0x0d, 0x0a, 0x0d, 0x0a };
1806  tcph.th_ack = htonl(1);
1807  tcph.th_seq = htonl(1);
1808  tcph.th_flags = TH_PUSH | TH_ACK;
1810  p->payload_len = sizeof(request);
1811  p->payload = request;
1812  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1819  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1820  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1821  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1822  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1823  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
1824 
1825  /* rubbish response */
1826  uint8_t response[] = {
1827  0x58, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x31,
1828  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
1829  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
1830  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
1831  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
1832  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
1833  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
1834  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
1835  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
1836  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
1837  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
1838  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
1839  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
1840  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
1841  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
1842  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
1843  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
1844  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
1845  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
1846  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
1847  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
1848  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
1849  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
1850  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
1851  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
1852  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
1853  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
1854  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
1855  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
1856  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
1857  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
1858  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
1859  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
1860  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
1861  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
1862  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
1863  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
1864  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
1865  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
1866  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
1867  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
1868  tcph.th_ack = htonl(88);
1869  tcph.th_seq = htonl(1);
1870  tcph.th_flags = TH_PUSH | TH_ACK;
1872  p->payload_len = sizeof(response);
1873  p->payload = response;
1874  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1881  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1882  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1883  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1884  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1886 
1887  /* response ack */
1888  tcph.th_ack = htonl(328);
1889  tcph.th_seq = htonl(88);
1890  tcph.th_flags = TH_ACK;
1892  p->payload_len = 0;
1893  p->payload = NULL;
1894  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1901  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1902  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1903  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1904  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1906 
1907  TEST_END;
1908  PASS;
1909 }
1910 
1911 /**
1912  * \test GE -> RUBBISH(TC - PM AND PP NOT DONE) -> RUBBISH(TC - PM AND PP DONE).
1913  */
1914 static int AppLayerTest04(void)
1915 {
1916  TEST_START;
1917 
1918  /* request */
1919  uint8_t request[] = {
1920  0x47, 0x45, 0x54, 0x20, 0x2f, 0x69, 0x6e, 0x64,
1921  0x65, 0x78, 0x2e, 0x68, 0x74, 0x6d, 0x6c, 0x20,
1922  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x30,
1923  0x0d, 0x0a, 0x48, 0x6f, 0x73, 0x74, 0x3a, 0x20,
1924  0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73,
1925  0x74, 0x0d, 0x0a, 0x55, 0x73, 0x65, 0x72, 0x2d,
1926  0x41, 0x67, 0x65, 0x6e, 0x74, 0x3a, 0x20, 0x41,
1927  0x70, 0x61, 0x63, 0x68, 0x65, 0x42, 0x65, 0x6e,
1928  0x63, 0x68, 0x2f, 0x32, 0x2e, 0x33, 0x0d, 0x0a,
1929  0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x3a, 0x20,
1930  0x2a, 0x2f, 0x2a, 0x0d, 0x0a, 0x0d, 0x0a };
1931  PrintRawDataFp(stdout, request, sizeof(request));
1932  tcph.th_ack = htonl(1);
1933  tcph.th_seq = htonl(1);
1934  tcph.th_flags = TH_PUSH | TH_ACK;
1936  p->payload_len = sizeof(request);
1937  p->payload = request;
1938  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1945  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1946  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1947  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1948  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1949  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER); // TOSERVER data now seen
1950 
1951  /* partial response */
1952  uint8_t response1[] = { 0x58, 0x54, 0x54, 0x50, };
1953  PrintRawDataFp(stdout, response1, sizeof(response1));
1954  tcph.th_ack = htonl(88);
1955  tcph.th_seq = htonl(1);
1956  tcph.th_flags = TH_PUSH | TH_ACK;
1958  p->payload_len = sizeof(response1);
1959  p->payload = response1;
1960  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1963  FAIL_IF(f.alproto != ALPROTO_HTTP1); // http based on ts
1964  FAIL_IF(f.alproto_ts != ALPROTO_HTTP1); // ts complete
1967  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1968  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1969  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1970  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
1971  FAIL_IF(ssn->data_first_seen_dir != APP_LAYER_DATA_ALREADY_SENT_TO_APP_LAYER); // first data sent to applayer
1972 
1973  /* partial response ack */
1974  tcph.th_ack = htonl(5);
1975  tcph.th_seq = htonl(88);
1976  tcph.th_flags = TH_ACK;
1978  p->payload_len = 0;
1979  p->payload = NULL;
1980  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
1983  FAIL_IF(f.alproto != ALPROTO_HTTP1); // http based on ts
1984  FAIL_IF(f.alproto_ts != ALPROTO_HTTP1); // ts complete
1987  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
1988  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
1989  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
1990  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT)); // to client pp got nothing
1991  FAIL_IF(ssn->data_first_seen_dir != APP_LAYER_DATA_ALREADY_SENT_TO_APP_LAYER); // first data sent to applayer
1992 
1993  /* remaining response */
1994  uint8_t response2[] = {
1995  0x2f, 0x31, 0x2e, 0x31,
1996  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
1997  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
1998  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
1999  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
2000  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
2001  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
2002  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
2003  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
2004  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
2005  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
2006  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
2007  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
2008  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
2009  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
2010  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
2011  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
2012  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
2013  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
2014  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
2015  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
2016  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
2017  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
2018  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
2019  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
2020  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
2021  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
2022  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
2023  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
2024  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
2025  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
2026  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
2027  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
2028  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
2029  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
2030  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
2031  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
2032  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
2033  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
2034  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
2035  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
2036  PrintRawDataFp(stdout, response2, sizeof(response2));
2037  tcph.th_ack = htonl(88);
2038  tcph.th_seq = htonl(5);
2039  tcph.th_flags = TH_PUSH | TH_ACK;
2041  p->payload_len = sizeof(response2);
2042  p->payload = response2;
2043  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2046  FAIL_IF(f.alproto != ALPROTO_HTTP1); // http based on ts
2047  FAIL_IF(f.alproto_ts != ALPROTO_HTTP1); // ts complete
2050  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2051  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2052  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2053  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT)); // to client pp got nothing
2054  FAIL_IF(ssn->data_first_seen_dir != APP_LAYER_DATA_ALREADY_SENT_TO_APP_LAYER); // first data sent to applayer
2055 
2056  /* response ack */
2057  tcph.th_ack = htonl(328);
2058  tcph.th_seq = htonl(88);
2059  tcph.th_flags = TH_ACK;
2061  p->payload_len = 0;
2062  p->payload = NULL;
2063  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2064  FAIL_IF(!StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(&ssn->server)); // toclient complete (failed)
2066  FAIL_IF(f.alproto != ALPROTO_HTTP1); // http based on ts
2067  FAIL_IF(f.alproto_ts != ALPROTO_HTTP1); // ts complete
2068  FAIL_IF(f.alproto_tc != ALPROTO_FAILED); // tc failed
2070  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2071  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2072  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2073  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT)); // to client pp got nothing
2074  FAIL_IF(ssn->data_first_seen_dir != APP_LAYER_DATA_ALREADY_SENT_TO_APP_LAYER); // first data sent to applayer
2075 
2076  TEST_END;
2077  PASS;
2078 }
2079 
2080 /**
2081  * \test RUBBISH -> HTTP/1.1
2082  */
2083 static int AppLayerTest05(void)
2084 {
2085  TEST_START;
2086 
2087  /* full request */
2088  uint8_t request[] = {
2089  0x48, 0x45, 0x54, 0x20, 0x2f, 0x69, 0x6e, 0x64,
2090  0x65, 0x78, 0x2e, 0x68, 0x74, 0x6d, 0x6c, 0x20,
2091  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x30,
2092  0x0d, 0x0a, 0x48, 0x6f, 0x73, 0x74, 0x3a, 0x20,
2093  0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73,
2094  0x74, 0x0d, 0x0a, 0x55, 0x73, 0x65, 0x72, 0x2d,
2095  0x41, 0x67, 0x65, 0x6e, 0x74, 0x3a, 0x20, 0x41,
2096  0x70, 0x61, 0x63, 0x68, 0x65, 0x42, 0x65, 0x6e,
2097  0x63, 0x68, 0x2f, 0x32, 0x2e, 0x33, 0x0d, 0x0a,
2098  0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x3a, 0x20,
2099  0x2a, 0x2f, 0x2a, 0x0d, 0x0a, 0x0d, 0x0a };
2100  PrintRawDataFp(stdout, request, sizeof(request));
2101  tcph.th_ack = htonl(1);
2102  tcph.th_seq = htonl(1);
2103  tcph.th_flags = TH_PUSH | TH_ACK;
2105  p->payload_len = sizeof(request);
2106  p->payload = request;
2107  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2114  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2115  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2116  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2117  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2118  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2119 
2120  /* full response - request ack */
2121  uint8_t response[] = {
2122  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x31,
2123  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
2124  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
2125  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
2126  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
2127  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
2128  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
2129  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
2130  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
2131  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
2132  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
2133  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
2134  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
2135  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
2136  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
2137  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
2138  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
2139  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
2140  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
2141  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
2142  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
2143  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
2144  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
2145  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
2146  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
2147  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
2148  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
2149  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
2150  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
2151  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
2152  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
2153  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
2154  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
2155  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
2156  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
2157  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
2158  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
2159  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
2160  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
2161  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
2162  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
2163  PrintRawDataFp(stdout, response, sizeof(response));
2164  tcph.th_ack = htonl(88);
2165  tcph.th_seq = htonl(1);
2166  tcph.th_flags = TH_PUSH | TH_ACK;
2168  p->payload_len = sizeof(response);
2169  p->payload = response;
2170  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2177  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2178  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2179  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2180  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2181  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2182 
2183  /* response ack */
2184  tcph.th_ack = htonl(328);
2185  tcph.th_seq = htonl(88);
2186  tcph.th_flags = TH_ACK;
2188  p->payload_len = 0;
2189  p->payload = NULL;
2190  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2197  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2198  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2199  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2200  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2202 
2203  TEST_END;
2204  PASS;
2205 }
2206 
2207 /**
2208  * \test HTTP/1.1 -> GET
2209  */
2210 static int AppLayerTest06(void)
2211 {
2212  TEST_START;
2213 
2214  /* full response - request ack */
2215  uint8_t response[] = {
2216  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x31,
2217  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
2218  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
2219  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
2220  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
2221  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
2222  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
2223  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
2224  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
2225  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
2226  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
2227  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
2228  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
2229  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
2230  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
2231  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
2232  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
2233  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
2234  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
2235  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
2236  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
2237  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
2238  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
2239  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
2240  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
2241  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
2242  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
2243  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
2244  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
2245  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
2246  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
2247  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
2248  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
2249  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
2250  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
2251  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
2252  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
2253  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
2254  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
2255  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
2256  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
2257  tcph.th_ack = htonl(1);
2258  tcph.th_seq = htonl(1);
2259  tcph.th_flags = TH_PUSH | TH_ACK;
2261  p->payload_len = sizeof(response);
2262  p->payload = response;
2263  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2270  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2271  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2272  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2273  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2274  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOCLIENT);
2275 
2276  /* full request - response ack*/
2277  uint8_t request[] = {
2278  0x47, 0x45, 0x54, 0x20, 0x2f, 0x69, 0x6e, 0x64,
2279  0x65, 0x78, 0x2e, 0x68, 0x74, 0x6d, 0x6c, 0x20,
2280  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x30,
2281  0x0d, 0x0a, 0x48, 0x6f, 0x73, 0x74, 0x3a, 0x20,
2282  0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73,
2283  0x74, 0x0d, 0x0a, 0x55, 0x73, 0x65, 0x72, 0x2d,
2284  0x41, 0x67, 0x65, 0x6e, 0x74, 0x3a, 0x20, 0x41,
2285  0x70, 0x61, 0x63, 0x68, 0x65, 0x42, 0x65, 0x6e,
2286  0x63, 0x68, 0x2f, 0x32, 0x2e, 0x33, 0x0d, 0x0a,
2287  0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x3a, 0x20,
2288  0x2a, 0x2f, 0x2a, 0x0d, 0x0a, 0x0d, 0x0a };
2289  tcph.th_ack = htonl(328);
2290  tcph.th_seq = htonl(1);
2291  tcph.th_flags = TH_PUSH | TH_ACK;
2293  p->payload_len = sizeof(request);
2294  p->payload = request;
2295  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2302  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2303  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2304  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2305  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2307 
2308  tcph.th_ack = htonl(1 + sizeof(request));
2309  tcph.th_seq = htonl(328);
2310  tcph.th_flags = TH_PUSH | TH_ACK;
2312  p->payload_len = 0;
2313  p->payload = NULL;
2314  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2321  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2322  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2323  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2324  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2326 
2327  TEST_END;
2328  PASS;
2329 }
2330 
2331 /**
2332  * \test GET -> DCERPC
2333  */
2334 static int AppLayerTest07(void)
2335 {
2336  TEST_START;
2337 
2338  /* full request */
2339  uint8_t request[] = {
2340  0x47, 0x45, 0x54, 0x20, 0x2f, 0x69, 0x6e, 0x64,
2341  0x65, 0x78, 0x2e, 0x68, 0x74, 0x6d, 0x6c, 0x20,
2342  0x48, 0x54, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x30,
2343  0x0d, 0x0a, 0x48, 0x6f, 0x73, 0x74, 0x3a, 0x20,
2344  0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73,
2345  0x74, 0x0d, 0x0a, 0x55, 0x73, 0x65, 0x72, 0x2d,
2346  0x41, 0x67, 0x65, 0x6e, 0x74, 0x3a, 0x20, 0x41,
2347  0x70, 0x61, 0x63, 0x68, 0x65, 0x42, 0x65, 0x6e,
2348  0x63, 0x68, 0x2f, 0x32, 0x2e, 0x33, 0x0d, 0x0a,
2349  0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x3a, 0x20,
2350  0x2a, 0x2f, 0x2a, 0x0d, 0x0a, 0x0d, 0x0a };
2351  tcph.th_ack = htonl(1);
2352  tcph.th_seq = htonl(1);
2353  tcph.th_flags = TH_PUSH | TH_ACK;
2355  p->payload_len = sizeof(request);
2356  p->payload = request;
2357  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2364  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2365  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2366  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2367  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2368  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2369 
2370  /* full response - request ack */
2371  uint8_t response[] = { 0x05, 0x00, 0x4d, 0x42, 0x00, 0x01, 0x2e, 0x31, 0x20, 0x32, 0x30, 0x30,
2372  0x20, 0x4f, 0x4b, 0x0d, 0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46, 0x72, 0x69, 0x2c,
2373  0x20, 0x32, 0x33, 0x20, 0x53, 0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20, 0x30, 0x36,
2374  0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65, 0x72,
2375  0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70, 0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
2376  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69, 0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f,
2377  0x32, 0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d, 0x6f, 0x64, 0x69, 0x66, 0x69, 0x65,
2378  0x64, 0x3a, 0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34, 0x20, 0x4e, 0x6f, 0x76, 0x20,
2379  0x32, 0x30, 0x31, 0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a, 0x34, 0x36, 0x20, 0x47,
2380  0x4d, 0x54, 0x0d, 0x0a, 0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61, 0x62, 0x38, 0x39,
2381  0x36, 0x35, 0x2d, 0x32, 0x63, 0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61, 0x37, 0x66,
2382  0x37, 0x66, 0x38, 0x30, 0x22, 0x0d, 0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d, 0x52,
2383  0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20, 0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
2384  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c, 0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20,
2385  0x34, 0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65, 0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a,
2386  0x20, 0x63, 0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74,
2387  0x2d, 0x54, 0x79, 0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74, 0x2f, 0x68, 0x74, 0x6d,
2388  0x6c, 0x0d, 0x0a, 0x58, 0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76, 0x6f, 0x69, 0x64,
2389  0x20, 0x62, 0x72, 0x6f, 0x77, 0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d, 0x0a, 0x0d,
2390  0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c, 0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c, 0x68,
2391  0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f, 0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
2392  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
2393  tcph.th_ack = htonl(88);
2394  tcph.th_seq = htonl(1);
2395  tcph.th_flags = TH_PUSH | TH_ACK;
2397  p->payload_len = sizeof(response);
2398  p->payload = response;
2399  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2406  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2407  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2408  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2409  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2411 
2412  /* response ack */
2413  tcph.th_ack = htonl(328);
2414  tcph.th_seq = htonl(88);
2415  tcph.th_flags = TH_ACK;
2417  p->payload_len = 0;
2418  p->payload = NULL;
2419  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2426  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2427  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2428  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2429  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2431 
2432  TEST_END;
2433  PASS;
2434 }
2435 
2436 /**
2437  * \test RUBBISH(TC - PM and PP NOT DONE) ->
2438  * RUBBISH(TC - PM and PP DONE) ->
2439  * RUBBISH(TS - PM and PP DONE)
2440  */
2441 static int AppLayerTest09(void)
2442 {
2443  TEST_START;
2444 
2445  /* full request */
2446  uint8_t request1[] = {
2447  0x47, 0x47, 0x49, 0x20, 0x2f, 0x69, 0x6e, 0x64 };
2448  tcph.th_ack = htonl(1);
2449  tcph.th_seq = htonl(1);
2450  tcph.th_flags = TH_PUSH | TH_ACK;
2452  p->payload_len = sizeof(request1);
2453  p->payload = request1;
2454  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2461  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2462  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2463  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2464  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2465  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2466 
2467  /* response - request ack */
2468  tcph.th_ack = htonl(9);
2469  tcph.th_seq = htonl(1);
2470  tcph.th_flags = TH_PUSH | TH_ACK;
2472  p->payload_len = 0;
2473  p->payload = NULL;
2474  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2481  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2482  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2483  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2484  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2485  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2486 
2487  /* full request */
2488  uint8_t request2[] = {
2489  0x44, 0x44, 0x45, 0x20, 0x2f, 0x69, 0x6e, 0x64, 0xff };
2490  tcph.th_ack = htonl(1);
2491  tcph.th_seq = htonl(9);
2492  tcph.th_flags = TH_PUSH | TH_ACK;
2494  p->payload_len = sizeof(request2);
2495  p->payload = request2;
2496  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2503  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2504  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2505  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2506  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2507  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2508 
2509  /* full response - request ack */
2510  uint8_t response[] = {
2511  0x55, 0x74, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x31,
2512  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
2513  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
2514  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
2515  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
2516  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
2517  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
2518  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
2519  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
2520  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
2521  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
2522  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
2523  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
2524  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
2525  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
2526  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
2527  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
2528  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
2529  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
2530  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
2531  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
2532  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
2533  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
2534  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
2535  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
2536  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
2537  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
2538  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
2539  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
2540  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
2541  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
2542  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
2543  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
2544  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
2545  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
2546  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
2547  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
2548  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
2549  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
2550  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
2551  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
2552  tcph.th_ack = htonl(18);
2553  tcph.th_seq = htonl(1);
2554  tcph.th_flags = TH_PUSH | TH_ACK;
2556  p->payload_len = sizeof(response);
2557  p->payload = response;
2558  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2565  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2566  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2567  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2568  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2569  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2570 
2571  /* response ack */
2572  tcph.th_ack = htonl(328);
2573  tcph.th_seq = htonl(18);
2574  tcph.th_flags = TH_ACK;
2576  p->payload_len = 0;
2577  p->payload = NULL;
2578  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2585  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2586  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2587  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2588  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2590 
2591  TEST_END;
2592  PASS;
2593 }
2594 
2595 /**
2596  * \test RUBBISH(TC - PM and PP DONE) ->
2597  * RUBBISH(TS - PM and PP DONE)
2598  */
2599 static int AppLayerTest10(void)
2600 {
2601  TEST_START;
2602 
2603  /* full request */
2604  uint8_t request1[] = {
2605  0x47, 0x47, 0x49, 0x20, 0x2f, 0x69, 0x6e, 0x64,
2606  0x47, 0x47, 0x49, 0x20, 0x2f, 0x69, 0x6e, 0x64, 0xff };
2607  tcph.th_ack = htonl(1);
2608  tcph.th_seq = htonl(1);
2609  tcph.th_flags = TH_PUSH | TH_ACK;
2611  p->payload_len = sizeof(request1);
2612  p->payload = request1;
2613  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2620  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2621  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2622  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2623  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2624  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2625 
2626  /* response - request ack */
2627  tcph.th_ack = htonl(18);
2628  tcph.th_seq = htonl(1);
2629  tcph.th_flags = TH_PUSH | TH_ACK;
2631  p->payload_len = 0;
2632  p->payload = NULL;
2633  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2640  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2641  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2642  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2643  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2644  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2645 
2646  /* full response - request ack */
2647  uint8_t response[] = {
2648  0x55, 0x74, 0x54, 0x50, 0x2f, 0x31, 0x2e, 0x31,
2649  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
2650  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
2651  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
2652  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
2653  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
2654  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
2655  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
2656  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
2657  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
2658  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
2659  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
2660  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
2661  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
2662  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
2663  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
2664  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
2665  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
2666  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
2667  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
2668  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
2669  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
2670  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
2671  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
2672  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
2673  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
2674  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
2675  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
2676  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
2677  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
2678  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
2679  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
2680  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
2681  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
2682  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
2683  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
2684  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
2685  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
2686  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
2687  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
2688  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
2689  tcph.th_ack = htonl(18);
2690  tcph.th_seq = htonl(1);
2691  tcph.th_flags = TH_PUSH | TH_ACK;
2693  p->payload_len = sizeof(response);
2694  p->payload = response;
2695  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2702  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2703  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2704  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2705  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2706  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2707 
2708  /* response ack */
2709  tcph.th_ack = htonl(328);
2710  tcph.th_seq = htonl(18);
2711  tcph.th_flags = TH_ACK;
2713  p->payload_len = 0;
2714  p->payload = NULL;
2715  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2722  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2723  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2724  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2725  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2727 
2728  TEST_END;
2729  PASS;
2730 }
2731 
2732 /**
2733  * \test RUBBISH(TC - PM and PP DONE) ->
2734  * RUBBISH(TS - PM and PP NOT DONE) ->
2735  * RUBBISH(TS - PM and PP DONE)
2736  */
2737 static int AppLayerTest11(void)
2738 {
2739  TEST_START;
2740 
2741  /* full request */
2742  uint8_t request1[] = {
2743  0x47, 0x47, 0x49, 0x20, 0x2f, 0x69, 0x6e, 0x64,
2744  0x47, 0x47, 0x49, 0x20, 0x2f, 0x69, 0x6e, 0x64, 0xff };
2745  tcph.th_ack = htonl(1);
2746  tcph.th_seq = htonl(1);
2747  tcph.th_flags = TH_PUSH | TH_ACK;
2749  p->payload_len = sizeof(request1);
2750  p->payload = request1;
2751  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2758  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2759  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2760  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2761  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2762  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2763 
2764  /* response - request ack */
2765  tcph.th_ack = htonl(18);
2766  tcph.th_seq = htonl(1);
2767  tcph.th_flags = TH_PUSH | TH_ACK;
2769  p->payload_len = 0;
2770  p->payload = NULL;
2771  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2778  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2779  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2780  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2781  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2782  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2783 
2784  /* full response - request ack */
2785  uint8_t response1[] = {
2786  0x55, 0x74, 0x54, 0x50, };
2787  tcph.th_ack = htonl(18);
2788  tcph.th_seq = htonl(1);
2789  tcph.th_flags = TH_PUSH | TH_ACK;
2791  p->payload_len = sizeof(response1);
2792  p->payload = response1;
2793  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2800  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2801  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2802  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2803  FAIL_IF(FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2804  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2805 
2806  /* response ack from request */
2807  tcph.th_ack = htonl(5);
2808  tcph.th_seq = htonl(18);
2809  tcph.th_flags = TH_ACK;
2811  p->payload_len = 0;
2812  p->payload = NULL;
2813  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2820  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2821  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2822  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2823  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2824  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2825 
2826  uint8_t response2[] = {
2827  0x2f, 0x31, 0x2e, 0x31,
2828  0x20, 0x32, 0x30, 0x30, 0x20, 0x4f, 0x4b, 0x0d,
2829  0x0a, 0x44, 0x61, 0x74, 0x65, 0x3a, 0x20, 0x46,
2830  0x72, 0x69, 0x2c, 0x20, 0x32, 0x33, 0x20, 0x53,
2831  0x65, 0x70, 0x20, 0x32, 0x30, 0x31, 0x31, 0x20,
2832  0x30, 0x36, 0x3a, 0x32, 0x39, 0x3a, 0x33, 0x39,
2833  0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a, 0x53, 0x65,
2834  0x72, 0x76, 0x65, 0x72, 0x3a, 0x20, 0x41, 0x70,
2835  0x61, 0x63, 0x68, 0x65, 0x2f, 0x32, 0x2e, 0x32,
2836  0x2e, 0x31, 0x35, 0x20, 0x28, 0x55, 0x6e, 0x69,
2837  0x78, 0x29, 0x20, 0x44, 0x41, 0x56, 0x2f, 0x32,
2838  0x0d, 0x0a, 0x4c, 0x61, 0x73, 0x74, 0x2d, 0x4d,
2839  0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x3a,
2840  0x20, 0x54, 0x68, 0x75, 0x2c, 0x20, 0x30, 0x34,
2841  0x20, 0x4e, 0x6f, 0x76, 0x20, 0x32, 0x30, 0x31,
2842  0x30, 0x20, 0x31, 0x35, 0x3a, 0x30, 0x34, 0x3a,
2843  0x34, 0x36, 0x20, 0x47, 0x4d, 0x54, 0x0d, 0x0a,
2844  0x45, 0x54, 0x61, 0x67, 0x3a, 0x20, 0x22, 0x61,
2845  0x62, 0x38, 0x39, 0x36, 0x35, 0x2d, 0x32, 0x63,
2846  0x2d, 0x34, 0x39, 0x34, 0x33, 0x62, 0x37, 0x61,
2847  0x37, 0x66, 0x37, 0x66, 0x38, 0x30, 0x22, 0x0d,
2848  0x0a, 0x41, 0x63, 0x63, 0x65, 0x70, 0x74, 0x2d,
2849  0x52, 0x61, 0x6e, 0x67, 0x65, 0x73, 0x3a, 0x20,
2850  0x62, 0x79, 0x74, 0x65, 0x73, 0x0d, 0x0a, 0x43,
2851  0x6f, 0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x4c,
2852  0x65, 0x6e, 0x67, 0x74, 0x68, 0x3a, 0x20, 0x34,
2853  0x34, 0x0d, 0x0a, 0x43, 0x6f, 0x6e, 0x6e, 0x65,
2854  0x63, 0x74, 0x69, 0x6f, 0x6e, 0x3a, 0x20, 0x63,
2855  0x6c, 0x6f, 0x73, 0x65, 0x0d, 0x0a, 0x43, 0x6f,
2856  0x6e, 0x74, 0x65, 0x6e, 0x74, 0x2d, 0x54, 0x79,
2857  0x70, 0x65, 0x3a, 0x20, 0x74, 0x65, 0x78, 0x74,
2858  0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x0d, 0x0a, 0x58,
2859  0x2d, 0x50, 0x61, 0x64, 0x3a, 0x20, 0x61, 0x76,
2860  0x6f, 0x69, 0x64, 0x20, 0x62, 0x72, 0x6f, 0x77,
2861  0x73, 0x65, 0x72, 0x20, 0x62, 0x75, 0x67, 0x0d,
2862  0x0a, 0x0d, 0x0a, 0x3c, 0x68, 0x74, 0x6d, 0x6c,
2863  0x3e, 0x3c, 0x62, 0x6f, 0x64, 0x79, 0x3e, 0x3c,
2864  0x68, 0x31, 0x3e, 0x49, 0x74, 0x20, 0x77, 0x6f,
2865  0x72, 0x6b, 0x73, 0x21, 0x3c, 0x2f, 0x68, 0x31,
2866  0x3e, 0x3c, 0x2f, 0x62, 0x6f, 0x64, 0x79, 0x3e,
2867  0x3c, 0x2f, 0x68, 0x74, 0x6d, 0x6c, 0x3e };
2868  tcph.th_ack = htonl(18);
2869  tcph.th_seq = htonl(5);
2870  tcph.th_flags = TH_PUSH | TH_ACK;
2872  p->payload_len = sizeof(response2);
2873  p->payload = response2;
2874  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2881  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2882  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2883  FAIL_IF(FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2884  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2885  FAIL_IF(ssn->data_first_seen_dir != STREAM_TOSERVER);
2886 
2887  /* response ack from request */
2888  tcph.th_ack = htonl(328);
2889  tcph.th_seq = htonl(18);
2890  tcph.th_flags = TH_ACK;
2892  p->payload_len = 0;
2893  p->payload = NULL;
2894  FAIL_IF(StreamTcpPacket(&tv, p, stt, &pq) == -1);
2901  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOSERVER));
2902  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOSERVER));
2903  FAIL_IF(!FLOW_IS_PM_DONE(&f, STREAM_TOCLIENT));
2904  FAIL_IF(!FLOW_IS_PP_DONE(&f, STREAM_TOCLIENT));
2906 
2907  TEST_END;
2908  PASS;
2909 }
2910 
2912 {
2913  SCEnter();
2914 
2915  UtRegisterTest("AppLayerTest01", AppLayerTest01);
2916  UtRegisterTest("AppLayerTest02", AppLayerTest02);
2917  UtRegisterTest("AppLayerTest03", AppLayerTest03);
2918  UtRegisterTest("AppLayerTest04", AppLayerTest04);
2919  UtRegisterTest("AppLayerTest05", AppLayerTest05);
2920  UtRegisterTest("AppLayerTest06", AppLayerTest06);
2921  UtRegisterTest("AppLayerTest07", AppLayerTest07);
2922  UtRegisterTest("AppLayerTest09", AppLayerTest09);
2923  UtRegisterTest("AppLayerTest10", AppLayerTest10);
2924  UtRegisterTest("AppLayerTest11", AppLayerTest11);
2925 
2926  SCReturn;
2927 }
2928 
2929 #endif /* UNITTESTS */
AppLayerCounters_::counter_tx_id
StatsCounterId counter_tx_id
Definition: app-layer.c:94
APP_LAYER_DATA_ALREADY_SENT_TO_APP_LAYER
#define APP_LAYER_DATA_ALREADY_SENT_TO_APP_LAYER
Definition: app-layer.h:40
FLOW_RESET_PP_DONE
#define FLOW_RESET_PP_DONE(f, dir)
Definition: flow.h:290
UPDATE_DIR_PACKET
@ UPDATE_DIR_PACKET
Definition: stream-tcp-reassemble.h:56
FlowUnsetChangeProtoFlag
void FlowUnsetChangeProtoFlag(Flow *f)
Unset flag to indicate to change proto for the flow.
Definition: flow.c:184
host.h
decode-tcp.h
StatsRegisterGlobalCounter
StatsCounterGlobalId StatsRegisterGlobalCounter(const char *name, uint64_t(*Func)(void))
Registers a counter, which represents a global value.
Definition: counters.c:1093
Packet_::proto
uint8_t proto
Definition: decode.h:538
AppLayerParserDeSetup
int AppLayerParserDeSetup(void)
Definition: app-layer-parser.c:310
TcpStream_
Definition: stream-tcp-private.h:106
APPLAYER_UNEXPECTED_PROTOCOL
@ APPLAYER_UNEXPECTED_PROTOCOL
Definition: app-layer-events.h:51
ExceptionPolicyApply
void ExceptionPolicyApply(Packet *p, enum ExceptionPolicy policy, enum PacketDropReason drop_reason)
Definition: util-exception-policy.c:138
AppLayerCounters_
Definition: app-layer.c:92
ippair.h
SCAppLayerParserStateIssetFlag
uint16_t SCAppLayerParserStateIssetFlag(AppLayerParserState *pstate, uint16_t flag)
Definition: app-layer-parser.c:2079
app-layer-htp-range.h
FlowCleanupAppLayer
void FlowCleanupAppLayer(Flow *f)
Definition: flow.c:137
AppLayerProtoDetectSetup
int AppLayerProtoDetectSetup(void)
The first function to be called. This initializes a global protocol detection context.
Definition: app-layer-detect-proto.c:1673
ALPROTO_IKE
@ ALPROTO_IKE
Definition: app-layer-protos.h:55
ExpectationGetCounter
uint64_t ExpectationGetCounter(void)
Definition: app-layer-expectation.c:140
AppLayerCounterNames_::eps_name
char eps_name[EXCEPTION_POLICY_MAX][MAX_COUNTER_SIZE]
Definition: app-layer.c:89
Flow_::flags
uint64_t flags
Definition: flow.h:408
AppLayerCounters
struct AppLayerCounters_ AppLayerCounters
ALPROTO_DCERPC
@ ALPROTO_DCERPC
Definition: app-layer-protos.h:44
flow-util.h
ALPROTO_DNS
@ ALPROTO_DNS
Definition: app-layer-protos.h:47
AppLayerCounters_::gap_error_id
StatsCounterId gap_error_id
Definition: app-layer.c:95
AppLayerCounters_::internal_error_id
StatsCounterId internal_error_id
Definition: app-layer.c:97
PacketBypassCallback
void PacketBypassCallback(Packet *p)
Definition: decode.c:549
stream-tcp.h
ALPROTO_ENIP
@ ALPROTO_ENIP
Definition: app-layer-protos.h:49
StreamTcpInlineMode
bool StreamTcpInlineMode(void)
See if stream engine is operating in inline mode.
Definition: stream-tcp.c:7299
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
AppLayerGetProtoByName
AppProto AppLayerGetProtoByName(const char *alproto_name)
Given a protocol string, returns the corresponding internal protocol id.
Definition: app-layer.c:1010
ALPROTO_TLS
@ ALPROTO_TLS
Definition: app-layer-protos.h:39
PcapPacketCntGet
uint64_t PcapPacketCntGet(const Packet *p)
Definition: decode.c:1193
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
StatsRegisterCounter
StatsCounterId StatsRegisterCounter(const char *name, StatsThreadContext *stats)
Registers a normal, unqualified counter.
Definition: counters.c:1038
AppLayerCounterNames_::parser_error
char parser_error[MAX_COUNTER_SIZE]
Definition: app-layer.c:86
name
const char * name
Definition: detect-engine-proto.c:47
ALPROTO_MODBUS
@ ALPROTO_MODBUS
Definition: app-layer-protos.h:48
AppLayerProfilingStoreInternal
void AppLayerProfilingStoreInternal(AppLayerThreadCtx *app_tctx, Packet *p)
Definition: app-layer.c:1160
Flow_::proto
uint8_t proto
Definition: flow.h:381
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
ALPROTO_QUIC
@ ALPROTO_QUIC
Definition: app-layer-protos.h:57
Packet_::payload
uint8_t * payload
Definition: decode.h:620
ALPROTO_POP3
@ ALPROTO_POP3
Definition: app-layer-protos.h:71
TcpReassemblyThreadCtx_::app_tctx
void * app_tctx
Definition: stream-tcp-reassemble.h:62
Packet_::flags
uint32_t flags
Definition: decode.h:562
AppLayerThreadCtx_::proto_detect_ticks_spent
uint64_t proto_detect_ticks_spent
Definition: app-layer.c:75
ssn
TcpSession ssn
Definition: fuzz_dataset.c:31
PACKET_PROFILING_APP_PD_END
#define PACKET_PROFILING_APP_PD_END(dp)
Definition: util-profiling.h:186
ALPROTO_JABBER
@ ALPROTO_JABBER
Definition: app-layer-protos.h:42
TcpStreamCnf_::reassembly_depth
uint32_t reassembly_depth
Definition: stream-tcp.h:75
AppLayerThreadCtx_::alp_tctx
AppLayerParserThreadCtx * alp_tctx
Definition: app-layer.c:66
flow-private.h
Flow_
Flow data structure.
Definition: flow.h:359
AppLayerIncGapErrorCounter
void AppLayerIncGapErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:168
Flow_::protomap
uint8_t protomap
Definition: flow.h:450
AppProtoToString
const char * AppProtoToString(AppProto alproto)
Maps the ALPROTO_*, to its normalized string equivalent.
Definition: app-layer-protos.c:53
AppLayerThreadCtx_::ticks_spent
uint64_t ticks_spent
Definition: app-layer.c:71
ALPROTO_IRC
@ ALPROTO_IRC
Definition: app-layer-protos.h:45
ExceptionPolicyStatsSetts_
Definition: util-exception-policy-types.h:59
AppLayerParserGetFirstDataDir
uint8_t AppLayerParserGetFirstDataDir(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1386
g_stats_eps_per_app_proto_errors
bool g_stats_eps_per_app_proto_errors
Definition: suricata.c:225
AppLayerParserProtoIsRegistered
int AppLayerParserProtoIsRegistered(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:253
StreamTcpReassembleAppLayer
int StreamTcpReassembleAppLayer(ThreadVars *tv, TcpReassemblyThreadCtx *ra_ctx, TcpSession *ssn, TcpStream *stream, Packet *p, enum StreamUpdateDir app_update_dir)
Update the stream reassembly upon receiving a packet.
Definition: stream-tcp-reassemble.c:1395
packet-queue.h
FLOW_NOPAYLOAD_INSPECTION
#define FLOW_NOPAYLOAD_INSPECTION
Definition: flow.h:66
StreamTcpResetStreamFlagAppProtoDetectionCompleted
#define StreamTcpResetStreamFlagAppProtoDetectionCompleted(stream)
Definition: stream-tcp-private.h:305
AppLayerRegisterThreadCounters
void AppLayerRegisterThreadCounters(ThreadVars *tv)
Registers per flow counters for all protocols.
Definition: app-layer.c:1325
Flow_::alproto_orig
AppProto alproto_orig
Definition: flow.h:461
AppLayerProtoDetectSupportedIpprotos
void AppLayerProtoDetectSupportedIpprotos(AppProto alproto, uint8_t *ipprotos)
Definition: app-layer-detect-proto.c:2073
FTPMemuseGlobalCounter
uint64_t FTPMemuseGlobalCounter(void)
Definition: app-layer-ftp.c:85
ALPROTO_SIP
@ ALPROTO_SIP
Definition: app-layer-protos.h:59
AppLayerProfilingResetInternal
void AppLayerProfilingResetInternal(AppLayerThreadCtx *app_tctx)
Definition: app-layer.c:1155
util-exception-policy-types.h
AppLayerCounterNames_
Definition: app-layer.c:82
AppLayerParserStateProtoCleanup
void AppLayerParserStateProtoCleanup(uint8_t protomap, AppProto alproto, void *alstate, AppLayerParserState *pstate)
Definition: app-layer-parser.c:1877
AppLayerParserThreadCtxFree
void AppLayerParserThreadCtxFree(AppLayerParserThreadCtx *tctx)
Destroys the app layer parser thread context obtained using AppLayerParserThreadCtxAlloc().
Definition: app-layer-parser.c:364
AppLayerHandleTCPData
int AppLayerHandleTCPData(ThreadVars *tv, TcpReassemblyThreadCtx *ra_ctx, Packet *p, Flow *f, TcpSession *ssn, TcpStream **stream, uint8_t *data, uint32_t data_len, uint8_t flags, enum StreamUpdateDir app_update_dir)
handle TCP data for the app-layer.
Definition: app-layer.c:713
FLOW_PKT_TOSERVER
#define FLOW_PKT_TOSERVER
Definition: flow.h:236
ALPROTO_LDAP
@ ALPROTO_LDAP
Definition: app-layer-protos.h:65
TCP_ESTABLISHED
@ TCP_ESTABLISHED
Definition: stream-tcp-private.h:155
MIN
#define MIN(x, y)
Definition: suricata-common.h:413
StreamTcpUpdateAppLayerProgress
void StreamTcpUpdateAppLayerProgress(TcpSession *ssn, char direction, const uint32_t progress)
update reassembly progress
Definition: stream-tcp.c:6874
ALPROTO_FTP
@ ALPROTO_FTP
Definition: app-layer-protos.h:37
app_layer_error_eps_stats
ExceptionPolicyStatsSetts app_layer_error_eps_stats
Definition: app-layer.c:111
stream-tcp-reassemble.h
AppLayerThreadCtx_::proto_detect_ticks_end
uint64_t proto_detect_ticks_end
Definition: app-layer.c:74
TcpStream_::flags
uint16_t flags
Definition: stream-tcp-private.h:107
p
Packet * p
Definition: fuzz_dataset.c:30
AppLayerUnittestsRegister
void AppLayerUnittestsRegister(void)
Definition: app-layer.c:2911
StatsCounterId
Definition: counters.h:30
APPLAYER_PROTO_DETECTION_SKIPPED
@ APPLAYER_PROTO_DETECTION_SKIPPED
Definition: app-layer-events.h:49
HTPMemuseGlobalCounter
uint64_t HTPMemuseGlobalCounter(void)
Definition: app-layer-htp-mem.c:81
AppLayerCounters_::counter_id
StatsCounterId counter_id
Definition: app-layer.c:93
AppLayerListSupportedProtocols
void AppLayerListSupportedProtocols(void)
Definition: app-layer.c:1024
AppLayerSetupCounters
void AppLayerSetupCounters(void)
Definition: app-layer.c:1207
ALPROTO_SSH
@ ALPROTO_SSH
Definition: app-layer-protos.h:40
app-layer-ftp.h
ALPROTO_DHCP
@ ALPROTO_DHCP
Definition: app-layer-protos.h:58
Packet_::flowflags
uint8_t flowflags
Definition: decode.h:547
AppLayerThreadCtx_::alproto
AppProto alproto
Definition: app-layer.c:72
stream_config
TcpStreamCnf stream_config
Definition: stream-tcp.c:227
MAX
#define MAX(x, y)
Definition: suricata-common.h:417
Flow_::protoctx
void * protoctx
Definition: flow.h:438
AppLayerCounterNames_::tx_name
char tx_name[MAX_COUNTER_SIZE]
Definition: app-layer.c:84
AppLayerIncAllocErrorCounter
void AppLayerIncAllocErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:176
EXCEPTION_POLICY_NOT_SET
@ EXCEPTION_POLICY_NOT_SET
Definition: util-exception-policy-types.h:27
Packet_::payload_len
uint16_t payload_len
Definition: decode.h:621
Packet_::app_layer_events
AppLayerDecoderEvents * app_layer_events
Definition: decode.h:645
PACKET_PROFILING_APP_PD_START
#define PACKET_PROFILING_APP_PD_START(dp)
Definition: util-profiling.h:181
AppLayerDeSetup
int AppLayerDeSetup(void)
De initializes the app layer.
Definition: app-layer.c:1104
HostGetMemcap
uint64_t HostGetMemcap(void)
Return memcap value.
Definition: host.c:83
SCAppLayerDecoderEventsSetEventRaw
void SCAppLayerDecoderEventsSetEventRaw(AppLayerDecoderEvents **sevents, uint8_t event)
Set an app layer decoder event.
Definition: app-layer-events.c:97
PKT_PROTO_DETECT_TS_DONE
#define PKT_PROTO_DETECT_TS_DONE
Definition: decode.h:1344
MAX_COUNTER_SIZE
#define MAX_COUNTER_SIZE
Definition: app-layer.c:81
ALPROTO_KRB5
@ ALPROTO_KRB5
Definition: app-layer-protos.h:56
STREAMTCP_FLAG_MIDSTREAM
#define STREAMTCP_FLAG_MIDSTREAM
Definition: stream-tcp-private.h:170
TcpSession_::flags
uint32_t flags
Definition: stream-tcp-private.h:294
FLOW_IS_PM_DONE
#define FLOW_IS_PM_DONE(f, dir)
Definition: flow.h:281
APPLAYER_NO_TLS_AFTER_STARTTLS
@ APPLAYER_NO_TLS_AFTER_STARTTLS
Definition: app-layer-events.h:50
Flow_::alparser
AppLayerParserState * alparser
Definition: flow.h:483
EXCEPTION_POLICY_MAX
#define EXCEPTION_POLICY_MAX
Definition: util-exception-policy-types.h:39
AppLayerParserRegisterProtocolParsers
void AppLayerParserRegisterProtocolParsers(void)
Definition: app-layer-parser.c:2017
AppLayerThreadCtx_::proto_detect_ticks_start
uint64_t proto_detect_ticks_start
Definition: app-layer.c:73
AppLayerSetup
int AppLayerSetup(void)
Setup the app layer.
Definition: app-layer.c:1087
counters.h
app-layer-expectation.h
app-layer-detect-proto.h
AppLayerProtoDetectThreadCtx_
The app layer protocol detection thread context.
Definition: app-layer-detect-proto.c:166
util-debug.h
AppLayerParserState_
Definition: app-layer-parser.c:160
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
ExceptionPolicyCounters_
Definition: util-exception-policy-types.h:54
APPLAYER_MISMATCH_PROTOCOL_BOTH_DIRECTIONS
@ APPLAYER_MISMATCH_PROTOCOL_BOTH_DIRECTIONS
Definition: app-layer-events.h:46
g_alproto_max
AppProto g_alproto_max
Definition: app-layer-protos.c:32
FLOW_IS_PP_DONE
#define FLOW_IS_PP_DONE(f, dir)
Definition: flow.h:282
AppLayerRegisterGlobalCounters
void AppLayerRegisterGlobalCounters(void)
HACK to work around our broken unix manager (re)init loop.
Definition: app-layer.c:1168
ALPROTO_DNP3
@ ALPROTO_DNP3
Definition: app-layer-protos.h:50
PKT_DROP_REASON_APPLAYER_ERROR
@ PKT_DROP_REASON_APPLAYER_ERROR
Definition: decode.h:391
AppLayerThreadCtx_::ticks_end
uint64_t ticks_end
Definition: app-layer.c:70
AppLayerIncTxCounter
void AppLayerIncTxCounter(ThreadVars *tv, Flow *f, int64_t step)
Definition: app-layer.c:160
PacketSwap
void PacketSwap(Packet *p)
switch direction of a packet
Definition: decode.c:596
util-exception-policy.h
ALPROTO_SMTP
@ ALPROTO_SMTP
Definition: app-layer-protos.h:38
AppProtoRegisterProtoString
void AppProtoRegisterProtoString(AppProto alproto, const char *proto_name)
Definition: app-layer-protos.c:93
HTPByteRangeMemuseGlobalCounter
uint64_t HTPByteRangeMemuseGlobalCounter(void)
Definition: app-layer-htp-range.c:64
AppLayerThreadCtx_
This is for the app layer in general and it contains per thread context relevant to both the alpd and...
Definition: app-layer.c:62
util-print.h
IPPairGetMemcap
uint64_t IPPairGetMemcap(void)
Return memcap value.
Definition: ippair.c:81
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
StreamTcpPacket
int StreamTcpPacket(ThreadVars *tv, Packet *p, StreamTcpThread *stt, PacketQueueNoLock *pq)
Definition: stream-tcp.c:5703
AppLayerProtoDetectReset
void AppLayerProtoDetectReset(Flow *f)
Reset proto detect for flow.
Definition: app-layer-detect-proto.c:1888
StatsCounterIncr
void StatsCounterIncr(StatsThreadContext *stats, StatsCounterId id)
Increments the local counter.
Definition: counters.c:163
TcpSession_::state
uint8_t state
Definition: stream-tcp-private.h:285
TEST_START
#define TEST_START
Definition: app-layer.c:1403
ExceptionPolicyStatsSetts_::valid_settings_ids
bool valid_settings_ids[EXCEPTION_POLICY_MAX]
Definition: util-exception-policy-types.h:61
TH_ACK
#define TH_ACK
Definition: decode-tcp.h:38
HostGetMemuse
uint64_t HostGetMemuse(void)
Return memuse value.
Definition: host.c:94
PACKET_PROFILING_APP_STORE
#define PACKET_PROFILING_APP_STORE(dp, p)
Definition: util-profiling.h:206
PrintRawDataFp
void PrintRawDataFp(FILE *fp, const uint8_t *buf, uint32_t buflen)
Definition: util-print.c:112
app-layer-parser.h
FLOW_PROTO_DETECT_TC_DONE
#define FLOW_PROTO_DETECT_TC_DONE
Definition: flow.h:104
AppLayerCounterNames
struct AppLayerCounterNames_ AppLayerCounterNames
util-profiling.h
AppLayerParserSetup
int AppLayerParserSetup(void)
Definition: app-layer-parser.c:284
SCReturn
#define SCReturn
Definition: util-debug.h:286
FLOW_RESET_PM_DONE
#define FLOW_RESET_PM_DONE(f, dir)
Definition: flow.h:289
FlowGetProtoMapping
uint8_t FlowGetProtoMapping(uint8_t proto)
Function to map the protocol to the defined FLOW_PROTO_* enumeration.
Definition: flow-util.c:100
StreamTcpIsSetStreamFlagAppProtoDetectionCompleted
#define StreamTcpIsSetStreamFlagAppProtoDetectionCompleted(stream)
Definition: stream-tcp-private.h:303
Packet_
Definition: decode.h:516
ALPROTO_IMAP
@ ALPROTO_IMAP
Definition: app-layer-protos.h:41
stream-tcp-private.h
ALPROTO_RDP
@ ALPROTO_RDP
Definition: app-layer-protos.h:68
FLOW_PROTO_APPLAYER_MAX
#define FLOW_PROTO_APPLAYER_MAX
Definition: flow-private.h:73
applayer_counters
AppLayerCounters(* applayer_counters)[FLOW_PROTO_APPLAYER_MAX]
Definition: app-layer.c:105
AppLayerHandleUdp
int AppLayerHandleUdp(ThreadVars *tv, AppLayerThreadCtx *tctx, Packet *p, Flow *f)
Handle a app layer UDP message.
Definition: app-layer.c:878
DEBUG_ASSERT_FLOW_LOCKED
#define DEBUG_ASSERT_FLOW_LOCKED(f)
Definition: util-validate.h:106
StreamTcpSetStreamFlagAppProtoDetectionCompleted
#define StreamTcpSetStreamFlagAppProtoDetectionCompleted(stream)
Definition: stream-tcp-private.h:301
PACKET_PROFILING_APP_END
#define PACKET_PROFILING_APP_END(dp)
Definition: util-profiling.h:173
TcpStream_::window
uint32_t window
Definition: stream-tcp-private.h:117
ALPROTO_TELNET
@ ALPROTO_TELNET
Definition: app-layer-protos.h:63
ALPROTO_DOH2
@ ALPROTO_DOH2
Definition: app-layer-protos.h:66
SCReturnPtr
#define SCReturnPtr(x, type)
Definition: util-debug.h:300
AppLayerThreadCtx_::alpd_tctx
AppLayerProtoDetectThreadCtx * alpd_tctx
Definition: app-layer.c:64
StreamDataAvailableForProtoDetect
uint32_t StreamDataAvailableForProtoDetect(TcpStream *stream)
Definition: stream-tcp-reassemble.c:726
AppLayerGetCtxThread
AppLayerThreadCtx * AppLayerGetCtxThread(void)
Creates a new app layer thread context.
Definition: app-layer.c:1117
ALPROTO_TFTP
@ ALPROTO_TFTP
Definition: app-layer-protos.h:54
AppLayerThreadCtx_::ticks_start
uint64_t ticks_start
Definition: app-layer.c:69
AppLayerIncParserErrorCounter
void AppLayerIncParserErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:184
ALPROTO_HTTP2
@ ALPROTO_HTTP2
Definition: app-layer-protos.h:69
FTPMemcapGlobalCounter
uint64_t FTPMemcapGlobalCounter(void)
Definition: app-layer-ftp.c:91
FLOW_PKT_TOCLIENT
#define FLOW_PKT_TOCLIENT
Definition: flow.h:237
Flow_::alproto_expect
AppProto alproto_expect
Definition: flow.h:464
UPDATE_DIR_OPPOSING
@ UPDATE_DIR_OPPOSING
Definition: stream-tcp-reassemble.h:57
AppLayerParserThreadCtxAlloc
AppLayerParserThreadCtx * AppLayerParserThreadCtxAlloc(void)
Gets a new app layer protocol's parser thread context.
Definition: app-layer-parser.c:337
TH_PUSH
#define TH_PUSH
Definition: decode-tcp.h:37
app-layer-frames.h
ALPROTO_LLMNR
@ ALPROTO_LLMNR
Definition: app-layer-protos.h:73
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
flags
uint8_t flags
Definition: decode-gre.h:0
AppLayerParserParse
int AppLayerParserParse(ThreadVars *tv, AppLayerParserThreadCtx *alp_tctx, Flow *f, AppProto alproto, uint8_t flags, const uint8_t *input, uint32_t input_len)
Definition: app-layer-parser.c:1528
StreamTcpDisableAppLayer
void StreamTcpDisableAppLayer(Flow *f)
Definition: stream-tcp-reassemble.c:444
suricata-common.h
FLOW_RESET_PE_DONE
#define FLOW_RESET_PE_DONE(f, dir)
Definition: flow.h:291
AppLayerProtoDetectDeSetup
int AppLayerProtoDetectDeSetup(void)
Cleans up the app layer protocol detection phase.
Definition: app-layer-detect-proto.c:1730
ALPROTO_HTTP1
@ ALPROTO_HTTP1
Definition: app-layer-protos.h:36
ALPROTO_PGSQL
@ ALPROTO_PGSQL
Definition: app-layer-protos.h:62
IPPairGetMemuse
uint64_t IPPairGetMemuse(void)
Return memuse value.
Definition: ippair.c:92
Packet_::app_update_direction
uint8_t app_update_direction
Definition: decode.h:550
FLOW_PROTO_DETECT_TS_DONE
#define FLOW_PROTO_DETECT_TS_DONE
Definition: flow.h:103
ALPROTO_FTPDATA
@ ALPROTO_FTPDATA
Definition: app-layer-protos.h:53
AppLayerIncInternalErrorCounter
void AppLayerIncInternalErrorCounter(ThreadVars *tv, Flow *f)
Definition: app-layer.c:192
eps_error_summary
ExceptionPolicyCounters eps_error_summary
Definition: app-layer.c:107
FatalError
#define FatalError(...)
Definition: util-debug.h:517
APPLAYER_DETECT_PROTOCOL_ONLY_ONE_DIRECTION
@ APPLAYER_DETECT_PROTOCOL_ONLY_ONE_DIRECTION
Definition: app-layer-events.h:48
STREAMTCP_FLAG_MIDSTREAM_SYNACK
#define STREAMTCP_FLAG_MIDSTREAM_SYNACK
Definition: stream-tcp-private.h:174
applayer_counter_names
AppLayerCounterNames(* applayer_counter_names)[FLOW_PROTO_APPLAYER_MAX]
Definition: app-layer.c:103
ALPROTO_WEBSOCKET
@ ALPROTO_WEBSOCKET
Definition: app-layer-protos.h:64
TcpSession_::client
TcpStream client
Definition: stream-tcp-private.h:297
PKT_PROTO_DETECT_TC_DONE
#define PKT_PROTO_DETECT_TC_DONE
Definition: decode.h:1345
FrameConfigInit
void FrameConfigInit(void)
Definition: app-layer-frames.c:41
AppLayerParserGetStreamDepth
uint32_t AppLayerParserGetStreamDepth(const Flow *f)
Definition: app-layer-parser.c:1809
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:34
app-layer-events.h
util-validate.h
FlowSwap
void FlowSwap(Flow *f)
swap the flow's direction
Definition: flow.c:243
AppLayerProtoDetectSupportedAppProtocols
void AppLayerProtoDetectSupportedAppProtocols(AppProto *alprotos)
Definition: app-layer-detect-proto.c:2135
AppLayerProtoDetectGetProto
AppProto AppLayerProtoDetectGetProto(AppLayerProtoDetectThreadCtx *tctx, Flow *f, const uint8_t *buf, uint32_t buflen, uint8_t ipproto, uint8_t flags, bool *reverse_flow)
Returns the app layer protocol given a buffer.
Definition: app-layer-detect-proto.c:1396
AppLayerProtoDetectGetCtxThread
AppLayerProtoDetectThreadCtx * AppLayerProtoDetectGetCtxThread(void)
Inits and returns an app layer protocol detection thread context.
Definition: app-layer-detect-proto.c:1994
TcpSession_::server
TcpStream server
Definition: stream-tcp-private.h:296
AppLayerProtoDetectGetProtoByName
AppProto AppLayerProtoDetectGetProtoByName(const char *alproto_name)
Definition: app-layer-detect-proto.c:2093
str
#define str(s)
Definition: suricata-common.h:313
SWAP_FLAGS
#define SWAP_FLAGS(flags, a, b)
Definition: suricata-common.h:439
ExceptionPolicyEnumToString
const char * ExceptionPolicyEnumToString(enum ExceptionPolicy policy, bool is_json)
Definition: util-exception-policy.c:39
SCFree
#define SCFree(p)
Definition: util-mem.h:61
AppLayerCounterNames_::gap_error
char gap_error[MAX_COUNTER_SIZE]
Definition: app-layer.c:85
Flow_::alproto_ts
AppProto alproto_ts
Definition: flow.h:456
AppLayerCounters_::alloc_error_id
StatsCounterId alloc_error_id
Definition: app-layer.c:98
ExceptionPolicyStatsSetts_::valid_settings_ips
bool valid_settings_ips[EXCEPTION_POLICY_MAX]
Definition: util-exception-policy-types.h:62
TcpSessionSetReassemblyDepth
void TcpSessionSetReassemblyDepth(TcpSession *ssn, uint32_t size)
Definition: stream-tcp.c:7305
Flow_::alstate
void * alstate
Definition: flow.h:484
AppLayerDestroyCtxThread
void AppLayerDestroyCtxThread(AppLayerThreadCtx *app_tctx)
Destroys the context created by AppLayerGetCtxThread().
Definition: app-layer.c:1138
PACKET_PROFILING_APP_START
#define PACKET_PROFILING_APP_START(dp, id)
Definition: util-profiling.h:167
HTPByteRangeMemcapGlobalCounter
uint64_t HTPByteRangeMemcapGlobalCounter(void)
Definition: app-layer-htp-range.c:58
ALPROTO_MDNS
@ ALPROTO_MDNS
Definition: app-layer-protos.h:72
StatsCounterId::id
uint16_t id
Definition: counters.h:31
HTPMemcapGlobalCounter
uint64_t HTPMemcapGlobalCounter(void)
Definition: app-layer-htp-mem.c:87
ALPROTO_MQTT
@ ALPROTO_MQTT
Definition: app-layer-protos.h:61
AppLayerGetProtoName
const char * AppLayerGetProtoName(AppProto alproto)
Given the internal protocol id, returns a string representation of the protocol.
Definition: app-layer.c:1017
g_applayerparser_error_policy
enum ExceptionPolicy g_applayerparser_error_policy
Definition: app-layer-parser.c:180
ALPROTO_HTTP
@ ALPROTO_HTTP
Definition: app-layer-protos.h:77
AppLayerCounters_::eps_error
ExceptionPolicyCounters eps_error
Definition: app-layer.c:99
ALPROTO_UNKNOWN
@ ALPROTO_UNKNOWN
Definition: app-layer-protos.h:29
ALPROTO_FAILED
@ ALPROTO_FAILED
Definition: app-layer-protos.h:33
ALPROTO_TEMPLATE
@ ALPROTO_TEMPLATE
Definition: app-layer-protos.h:67
AppLayerCounterNames_::internal_error
char internal_error[MAX_COUNTER_SIZE]
Definition: app-layer.c:87
TcpReassemblyThreadCtx_
Definition: stream-tcp-reassemble.h:61
SCReturnCT
#define SCReturnCT(x, type)
Definition: util-debug.h:298
app-layer-protos.h
AppLayerProfilingReset
#define AppLayerProfilingReset(app_tctx)
Definition: app-layer.h:127
app-layer-htp-mem.h
EngineModeIsIPS
int EngineModeIsIPS(void)
Definition: suricata.c:247
STREAMTCP_FLAG_APP_LAYER_DISABLED
#define STREAMTCP_FLAG_APP_LAYER_DISABLED
Definition: stream-tcp-private.h:201
STREAMTCP_STREAM_FLAG_NOREASSEMBLY
#define STREAMTCP_STREAM_FLAG_NOREASSEMBLY
Definition: stream-tcp-private.h:219
suricata.h
ALPROTO_RFB
@ ALPROTO_RFB
Definition: app-layer-protos.h:60
TEST_END
#define TEST_END
Definition: app-layer.c:1486
StreamUpdateDir
StreamUpdateDir
Definition: stream-tcp-reassemble.h:54
AppLayerProtoDetectDestroyCtxThread
void AppLayerProtoDetectDestroyCtxThread(AppLayerProtoDetectThreadCtx *alpd_tctx)
Destroys the app layer protocol detection thread context.
Definition: app-layer-detect-proto.c:2047
ALPROTO_BITTORRENT_DHT
@ ALPROTO_BITTORRENT_DHT
Definition: app-layer-protos.h:70
ALPROTO_NTP
@ ALPROTO_NTP
Definition: app-layer-protos.h:52
ALPROTO_SMB
@ ALPROTO_SMB
Definition: app-layer-protos.h:43
AppLayerCounters_::parser_error_id
StatsCounterId parser_error_id
Definition: app-layer.c:96
likely
#define likely(expr)
Definition: util-optimize.h:32
AppLayerParserThreadCtx_
Definition: app-layer-parser.c:72
AppLayerCounterNames_::name
char name[MAX_COUNTER_SIZE]
Definition: app-layer.c:83
FlowChangeProto
int FlowChangeProto(Flow *f)
Check if change proto flag is set for flow.
Definition: flow.c:194
TcpSession_
Definition: stream-tcp-private.h:283
FrameConfigDeInit
void FrameConfigDeInit(void)
Definition: app-layer-frames.c:52
TcpSession_::data_first_seen_dir
int8_t data_first_seen_dir
Definition: stream-tcp-private.h:288
flow.h
Flow_::alproto_tc
AppProto alproto_tc
Definition: flow.h:457
FLOW_PROTO_CHANGE_MAX_DEPTH
#define FLOW_PROTO_CHANGE_MAX_DEPTH
Definition: app-layer.c:79
AppLayerProtoDetectPrepareState
int AppLayerProtoDetectPrepareState(void)
Prepares the internal state for protocol detection. This needs to be called once all the patterns and...
Definition: app-layer-detect-proto.c:1484
Flow_::alproto
AppProto alproto
application level protocol
Definition: flow.h:455
ExceptionPolicy
ExceptionPolicy
Definition: util-exception-policy-types.h:26
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
AppLayerCounterNames_::alloc_error
char alloc_error[MAX_COUNTER_SIZE]
Definition: app-layer.c:88
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
PACKET_PROFILING_APP_RESET
#define PACKET_PROFILING_APP_RESET(dp)
Definition: util-profiling.h:195
StatsCounterAddI64
void StatsCounterAddI64(StatsThreadContext *stats, StatsCounterId id, int64_t x)
Adds a value of type uint64_t to the local counter.
Definition: counters.c:144
APPLAYER_WRONG_DIRECTION_FIRST_DATA
@ APPLAYER_WRONG_DIRECTION_FIRST_DATA
Definition: app-layer-events.h:47
AppLayerDeSetupCounters
void AppLayerDeSetupCounters(void)
Definition: app-layer.c:1393
ExceptionPolicyCounters_::eps_id
StatsCounterId eps_id[EXCEPTION_POLICY_MAX]
Definition: util-exception-policy-types.h:56
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
ALPROTO_NFS
@ ALPROTO_NFS
Definition: app-layer-protos.h:51
ExceptionPolicyStatsSetts_::eps_name
char eps_name[EXCEPTION_POLICY_MAX][EXCEPTION_POLICY_COUNTER_MAX_LEN]
Definition: util-exception-policy-types.h:60
STREAMTCP_STREAM_FLAG_APPPROTO_DETECTION_COMPLETED
#define STREAMTCP_STREAM_FLAG_APPPROTO_DETECTION_COMPLETED
Definition: stream-tcp-private.h:232
AppLayerProtoDetectGetProtoName
const char * AppLayerProtoDetectGetProtoName(AppProto alproto)
Definition: app-layer-detect-proto.c:2118
app-layer.h
f
Flow f
Definition: fuzz_dataset.c:32
Flow_::de_ctx_version
uint32_t de_ctx_version
Definition: flow.h:469