suricata
detect-asn1.c
Go to the documentation of this file.
1 /* Copyright (C) 2020-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file detect-asn1.c
20  *
21  * Implements "asn1" keyword
22  */
23 
24 #include "suricata-common.h"
25 #include "decode.h"
26 #include "rust.h"
27 
28 #include "detect.h"
29 #include "detect-parse.h"
30 
31 #include "flow.h"
32 #include "detect-asn1.h"
33 
34 #include "util-unittest-helper.h"
35 #include "util-byte.h"
36 #include "util-debug.h"
37 
38 static int DetectAsn1Setup (DetectEngineCtx *, Signature *, const char *);
39 #ifdef UNITTESTS
40 static void DetectAsn1RegisterTests(void);
41 #endif
42 static void DetectAsn1Free(DetectEngineCtx *, void *);
43 
44 /**
45  * \brief Registration function for asn1
46  */
48 {
50  sigmatch_table[DETECT_ASN1].Setup = DetectAsn1Setup;
51  sigmatch_table[DETECT_ASN1].Free = DetectAsn1Free;
52 #ifdef UNITTESTS
53  sigmatch_table[DETECT_ASN1].RegisterTests = DetectAsn1RegisterTests;
54 #endif
55 }
56 
57 bool DetectAsn1Match(const SigMatchData *smd, const uint8_t *buffer, const uint32_t buffer_len,
58  const uint32_t offset)
59 {
60  const DetectAsn1Data *ad = (const DetectAsn1Data *)smd->ctx;
61  Asn1 *asn1 = SCAsn1Decode(buffer, buffer_len, offset, ad);
62  uint8_t ret = SCAsn1Checks(asn1, ad);
63  SCAsn1Free(asn1);
64  return ret == 1;
65 }
66 
67 /**
68  * \brief This function is used to parse asn1 options passed via asn1: keyword
69  *
70  * \param asn1str pointer to the user provided asn1 options
71  *
72  * \retval pointer to `DetectAsn1Data` on success
73  * \retval NULL on failure
74  */
75 static DetectAsn1Data *DetectAsn1Parse(const char *asn1str)
76 {
77  DetectAsn1Data *ad = SCAsn1DetectParse(asn1str);
78 
79  if (ad == NULL) {
80  SCLogError("Malformed asn1 argument: %s", asn1str);
81  }
82 
83  return ad;
84 }
85 
86 /**
87  * \brief this function is used to add the parsed asn1 data into
88  * the current signature
89  *
90  * \param de_ctx pointer to the detection engine context
91  * \param s pointer to the current signature
92  * \param asn1str pointer to the user provided asn1 options
93  *
94  * \retval 0 on success
95  * \retval -1 on failure
96  */
97 static int DetectAsn1Setup(DetectEngineCtx *de_ctx, Signature *s, const char *asn1str)
98 {
99  DetectAsn1Data *ad = DetectAsn1Parse(asn1str);
100  if (ad == NULL)
101  return -1;
102 
104  de_ctx, s, DETECT_ASN1, (SigMatchCtx *)ad, DETECT_SM_LIST_PMATCH) == NULL) {
105  DetectAsn1Free(de_ctx, ad);
106  return -1;
107  }
108 
110  return 0;
111 }
112 
113 /**
114  * \brief this function will free memory associated with `DetectAsn1Data`
115  *
116  * \param de_ctx pointer to the detection engine context
117  * \param ptr point to `DetectAsn1Data`
118  */
119 static void DetectAsn1Free(DetectEngineCtx *de_ctx, void *ptr)
120 {
121  DetectAsn1Data *ad = (DetectAsn1Data *)ptr;
122  SCAsn1DetectFree(ad);
123 }
124 
125 #ifdef UNITTESTS
126 
127 /**
128  * \test DetectAsn1TestReal01 Ensure that all works together
129  */
130 static int DetectAsn1TestReal01(void)
131 {
132  uint8_t *buf = (uint8_t *) "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
133  "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
134  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
135  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
136  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
137  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
138  "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
139  "Jones""\xA0\x0A\x43\x08""19590717"
140  "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
141  "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
142  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
143  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
144  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
145  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
146  "\x61\x11\x1A\x05""Pablo""\x1A\x01""B""\x1A\x05""Jones"
147  "\xA0\x0A\x43\x08""19590717";
148 
149  uint16_t buflen = strlen((char *)buf) - 1;
150 
151  /* Check the start with AA (this is to test the relative_offset keyword) */
152  uint8_t *buf2 = (uint8_t *) "AA\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
153  "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
154  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
155  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
156  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
157  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
158  "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
159  "Jones""\xA0\x0A\x43\x08""19590717"
160  "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
161  "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
162  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
163  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
164  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
165  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
166  "\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05""Jones"
167  "\xA0\x0A\x43\x08""19590717";
168 
169  uint16_t buflen2 = strlen((char *)buf2) - 1;
170 
171  Packet *p[2];
172 
173  p[0] = UTHBuildPacket((uint8_t *)buf, buflen, IPPROTO_TCP);
174  FAIL_IF_NULL(p[0]);
175  p[1] = UTHBuildPacket((uint8_t *)buf2, buflen2, IPPROTO_TCP);
176  FAIL_IF_NULL(p[1]);
177 
178  const char *sigs[3];
179  sigs[0]= "alert ip any any -> any any (msg:\"Testing id 1\"; "
180  "content:\"Pablo\"; asn1:absolute_offset 0, "
181  "oversize_length 130; sid:1;)";
182  sigs[1]= "alert ip any any -> any any (msg:\"Testing id 2\"; "
183  "content:\"AA\"; asn1:relative_offset 0, "
184  "oversize_length 130; sid:2;)";
185  sigs[2]= "alert ip any any -> any any (msg:\"Testing id 3\"; "
186  "content:\"lalala\"; asn1: oversize_length 2000; sid:3;)";
187 
188  uint32_t sid[3] = {1, 2, 3};
189  uint32_t results[2][3] = {
190  /* packet 0 match sid 1 */
191  {1, 0, 0},
192  /* packet 1 match sid 2 */
193  {0, 1, 0}};
194  /* None of the packets should match sid 3 */
195  FAIL_IF_NOT(UTHGenericTest(p, 2, sigs, sid, (uint32_t *)results, 3) == 1);
196 
197  UTHFreePackets(p, 2);
198  PASS;
199 }
200 
201 /**
202  * \test DetectAsn1TestReal02 Ensure that all works together
203  */
204 static int DetectAsn1TestReal02(void)
205 {
206  int result = 0;
207  uint8_t *buf = (uint8_t *) "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
208  "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
209  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
210  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
211  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
212  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
213  "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
214  "Jones""\xA0\x0A\x43\x08""19590717"
215  "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
216  "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
217  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
218  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
219  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
220  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
221  "\x61\x11\x1A\x05""Pablo""\x1A\x01""B""\x1A\x05""Jones"
222  "\xA0\x0A\x43\x08""19590717";
223 
224  uint16_t buflen = strlen((char *)buf) - 1;
225 
226  /* Check the start with AA (this is to test the relative_offset keyword) */
227  uint8_t *buf2 = (uint8_t *) "AA\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
228  "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
229  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
230  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
231  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
232  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
233  "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
234  "Jones""\xA0\x0A\x43\x08""19590717"
235  "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
236  "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
237  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
238  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
239  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
240  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
241  "\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05""Jones"
242  "\xA0\x0A\x43\x08""19590717";
243 
244  uint16_t buflen2 = strlen((char *)buf2) - 1;
245 
246  Packet *p[2];
247 
248  p[0] = UTHBuildPacket((uint8_t *)buf, buflen, IPPROTO_TCP);
249  p[1] = UTHBuildPacket((uint8_t *)buf2, buflen2, IPPROTO_TCP);
250 
251  if (p[0] == NULL || p[1] == NULL)
252  goto end;
253 
254  const char *sigs[3];
255  sigs[0]= "alert ip any any -> any any (msg:\"Testing id 1\"; "
256  "content:\"Pablo\"; asn1:absolute_offset 0, "
257  "oversize_length 140; sid:1;)";
258  sigs[1]= "alert ip any any -> any any (msg:\"Testing id 2\"; "
259  "content:\"AA\"; asn1:relative_offset 0, "
260  "oversize_length 140; sid:2;)";
261  sigs[2]= "alert ip any any -> any any (msg:\"Testing id 3\"; "
262  "content:\"lalala\"; asn1: oversize_length 2000; sid:3;)";
263 
264  uint32_t sid[3] = {1, 2, 3};
265 
266  uint32_t results[2][3] = {
267  {0, 0, 0},
268  {0, 0, 0}};
269  /* None of the packets should match */
270 
271  result = UTHGenericTest(p, 2, sigs, sid, (uint32_t *) results, 3);
272 
273  UTHFreePackets(p, 2);
274 end:
275  return result;
276 }
277 
278 /**
279  * \test DetectAsn1TestReal03 Ensure that all works together
280  */
281 static int DetectAsn1TestReal03(void)
282 {
283  int result = 0;
284  uint8_t buf[261] = "";
285  /* universal class, primitive type, tag_num = 9 (Data type Real) */
286  buf[0] = '\x09';
287  /* length, definite form, 2 octets */
288  buf[1] = '\x82';
289  /* length is the sum of the following octets (257): */
290  buf[2] = '\x01';
291  buf[3] = '\x01';
292 
293  /* Fill the content of the number */
294  uint16_t i = 4;
295  for (; i < 257;i++)
296  buf[i] = '\x05';
297 
298  uint16_t buflen = 261;
299 
300  /* Check the start with AA (this is to test the relative_offset keyword) */
301  uint8_t *buf2 = (uint8_t *) "AA\x03\x01\xFF";
302 
303  uint16_t buflen2 = 5;
304 
305  Packet *p[2] = { NULL, NULL };
306 
307  p[0] = UTHBuildPacket((uint8_t *)buf, buflen, IPPROTO_TCP);
308  p[1] = UTHBuildPacket((uint8_t *)buf2, buflen2, IPPROTO_TCP);
309 
310  if (p[0] == NULL || p[1] == NULL)
311  goto end;
312 
313  const char *sigs[3];
314  /* This should match the first packet */
315  sigs[0]= "alert ip any any -> any any (msg:\"Testing id 1\"; "
316  "asn1:absolute_offset 0, double_overflow; sid:1;)";
317  /* This should match the second packet */
318  sigs[1]= "alert ip any any -> any any (msg:\"Testing id 2\"; "
319  "asn1:relative_offset 2, bitstring_overflow,"
320  "oversize_length 140; sid:2;)";
321  /* This should match no packet */
322  sigs[2]= "alert ip any any -> any any (msg:\"Testing id 3\"; "
323  "asn1: oversize_length 2000; sid:3;)";
324 
325  uint32_t sid[3] = {1, 2, 3};
326 
327  uint32_t results[2][3] = {{1, 0, 0},
328  {0, 1, 0}};
329 
330  result = UTHGenericTest(p, 2, sigs, sid, (uint32_t *) results, 3);
331 
332  UTHFreePackets(p, 2);
333 end:
334  return result;
335 }
336 
337 /**
338  * \test DetectAsn1TestReal04 like the real test 02, but modified the
339  * relative offset to check negative offset values, in this case
340  * start decoding from -7 bytes respect the content match "John"
341  */
342 static int DetectAsn1TestReal04(void)
343 {
344  int result = 0;
345  uint8_t *buf = (uint8_t *) "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
346  "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
347  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
348  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
349  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
350  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
351  "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
352  "Jones""\xA0\x0A\x43\x08""19590717"
353  "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
354  "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
355  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
356  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
357  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
358  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
359  "\x61\x11\x1A\x05""Pablo""\x1A\x01""B""\x1A\x05""Jones"
360  "\xA0\x0A\x43\x08""19590717";
361 
362  uint16_t buflen = strlen((char *)buf) - 1;
363 
364  /* Check the start with AA (this is to test the relative_offset keyword) */
365  uint8_t *buf2 = (uint8_t *) "AA\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01"
366  "P""\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
367  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
368  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
369  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
370  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111"
371  "\x31\x1F\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05"
372  "Jones""\xA0\x0A\x43\x08""19590717"
373  "\x60\x81\x85\x61\x10\x1A\x04""John""\x1A\x01""P"
374  "\x1A\x05""Smith""\xA0\x0A\x1A\x08""Director"
375  "\x42\x01\x33\xA1\x0A\x43\x08""19710917"
376  "\xA2\x12\x61\x10\x1A\x04""Mary""\x1A\x01""T""\x1A\x05"
377  "Smith""\xA3\x42\x31\x1F\x61\x11\x1A\x05""Ralph""\x1A\x01"
378  "T""\x1A\x05""Smith""\xA0\x0A\x43\x08""19571111""\x31\x1F"
379  "\x61\x11\x1A\x05""Susan""\x1A\x01""B""\x1A\x05""Jones"
380  "\xA0\x0A\x43\x08""19590717";
381 
382  uint16_t buflen2 = strlen((char *)buf2) - 1;
383 
384  Packet *p[2];
385 
386  p[0] = UTHBuildPacket((uint8_t *)buf, buflen, IPPROTO_TCP);
387  p[1] = UTHBuildPacket((uint8_t *)buf2, buflen2, IPPROTO_TCP);
388 
389  if (p[0] == NULL || p[1] == NULL)
390  goto end;
391 
392  const char *sigs[3];
393  sigs[0]= "alert ip any any -> any any (msg:\"Testing id 1\"; "
394  "content:\"Pablo\"; asn1:absolute_offset 0, "
395  "oversize_length 140; sid:1;)";
396  sigs[1]= "alert ip any any -> any any (msg:\"Testing id 2\"; "
397  "content:\"John\"; asn1:relative_offset -11, "
398  "oversize_length 140; sid:2;)";
399  sigs[2]= "alert ip any any -> any any (msg:\"Testing id 3\"; "
400  "content:\"lalala\"; asn1: oversize_length 2000; sid:3;)";
401 
402  uint32_t sid[3] = {1, 2, 3};
403 
404  uint32_t results[2][3] = {
405  {0, 0, 0},
406  {0, 0, 0}};
407  /* None of the packets should match */
408 
409  result = UTHGenericTest(p, 2, sigs, sid, (uint32_t *) results, 3);
410 
411  UTHFreePackets(p, 2);
412 end:
413  return result;
414 }
415 
416 /**
417  * \brief this function registers unit tests for DetectAsn1
418  */
419 static void DetectAsn1RegisterTests(void)
420 {
421  UtRegisterTest("DetectAsn1TestReal01", DetectAsn1TestReal01);
422  UtRegisterTest("DetectAsn1TestReal02", DetectAsn1TestReal02);
423  UtRegisterTest("DetectAsn1TestReal03", DetectAsn1TestReal03);
424  UtRegisterTest("DetectAsn1TestReal04", DetectAsn1TestReal04);
425 }
426 #endif /* UNITTESTS */
DetectAsn1Match
bool DetectAsn1Match(const SigMatchData *smd, const uint8_t *buffer, const uint32_t buffer_len, const uint32_t offset)
Definition: detect-asn1.c:57
util-byte.h
DETECT_SM_LIST_PMATCH
@ DETECT_SM_LIST_PMATCH
Definition: detect.h:120
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
offset
uint64_t offset
Definition: util-streaming-buffer.h:0
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
SigTableElmt_::name
const char * name
Definition: detect.h:1542
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
SigMatchData_::ctx
SigMatchCtx * ctx
Definition: detect.h:372
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
rust.h
UTHBuildPacket
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
Definition: util-unittest-helper.c:241
p
Packet * p
Definition: fuzz_dataset.c:30
SigMatchData_
Data needed for Match()
Definition: detect.h:369
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
DETECT_ASN1
@ DETECT_ASN1
Definition: detect-engine-register.h:100
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
detect-asn1.h
DetectAsn1Register
void DetectAsn1Register(void)
Registration function for asn1.
Definition: detect-asn1.c:47
decode.h
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
Signature_::flags
uint32_t flags
Definition: detect.h:693
Packet_
Definition: decode.h:516
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
suricata-common.h
UTHGenericTest
int UTHGenericTest(Packet **pkt, int numpkts, const char *sigs[], uint32_t sids[], uint32_t *results, int numsigs)
UTHGenericTest: function that perform a generic check taking care of as maximum common unittest eleme...
Definition: util-unittest-helper.c:578
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
flow.h
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
SIG_FLAG_REQUIRE_PACKET
#define SIG_FLAG_REQUIRE_PACKET
Definition: detect.h:257
UTHFreePackets
void UTHFreePackets(Packet **p, int numpkts)
UTHFreePackets: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:453