suricata
detect-config.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2020 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * Implements the config keyword
24  */
25 
26 #include "suricata-common.h"
27 #include "threads.h"
28 #include "decode.h"
29 
30 #include "detect.h"
31 #include "detect-parse.h"
32 
33 #include "detect-engine.h"
34 #include "detect-engine-mpm.h"
35 #include "detect-engine-state.h"
36 
37 #include "flow.h"
38 #include "flow-var.h"
39 #include "flow-util.h"
40 
41 #include "util-debug.h"
42 #include "util-spm-bm.h"
43 #include "util-unittest-helper.h"
44 
45 #include "app-layer.h"
46 #include "app-layer-parser.h"
47 #include "app-layer-htp.h"
48 
49 #include "stream-tcp.h"
50 
51 #include "detect-config.h"
52 
53 #include "output.h"
54 
55 /**
56  * \brief Regex for parsing our config keyword options
57  */
58 #define PARSE_REGEX "^\\s*([A-z_]+)\\s*\\s*([A-z_]+)\\s*(?:,\\s*([A-z_]+)\\s+([A-z_]+))?\\s*(?:,\\s*([A-z_]+)\\s+([A-z_]+))?$"
59 
60 static DetectParseRegex parse_regex;
61 
62 static int DetectConfigPostMatch (DetectEngineThreadCtx *det_ctx, Packet *p,
63  const Signature *s, const SigMatchCtx *ctx);
64 static int DetectConfigSetup (DetectEngineCtx *, Signature *, const char *);
65 static void DetectConfigFree(DetectEngineCtx *, void *);
66 #ifdef UNITTESTS
67 static void DetectConfigRegisterTests(void);
68 #endif
69 
70 /**
71  * \brief Registers the "config" keyword for detection.
72  */
74 {
75  sigmatch_table[DETECT_CONFIG].name = "config";
76  sigmatch_table[DETECT_CONFIG].Match = DetectConfigPostMatch;
77  sigmatch_table[DETECT_CONFIG].Setup = DetectConfigSetup;
78  sigmatch_table[DETECT_CONFIG].Free = DetectConfigFree;
80  "apply different configuration settings to a flow, packet or other unit";
81  sigmatch_table[DETECT_CONFIG].url = "/rules/config.html";
82 #ifdef UNITTESTS
83  sigmatch_table[DETECT_CONFIG].RegisterTests = DetectConfigRegisterTests;
84 #endif
86  DetectSetupParseRegexes(PARSE_REGEX, &parse_regex);
87 }
88 
89 /**
90  * \brief Apply configuration settings to a transaction based on the provided DetectConfigData.
91  *
92  * This function applies specific configurations to a transaction. The configurations are
93  * determined by the subsystems and types specified in the DetectConfigData structure.
94  *
95  * \param f Pointer to the Flow structure that will be configured.
96  * \param tx_id Transaction ID within the flow.
97  * \param config Pointer to the DetectConfigData structure containing configuration settings.
98  */
99 static void ConfigApplyTx(Flow *f,
100  const uint64_t tx_id, const DetectConfigData *config)
101 {
102  if (f->alstate == NULL) {
103  return;
104  }
105  void *tx = AppLayerParserGetTx(f->proto, f->alproto, f->alstate, tx_id);
106  if (tx) {
108  SCLogDebug("tx %p txd %p: log_flags %x", tx, txd, txd->config.log_flags);
109  txd->config.log_flags |= BIT_U8(config->type);
110 
111  const bool unidir =
112  (txd->flags & (APP_LAYER_TX_SKIP_INSPECT_TS | APP_LAYER_TX_SKIP_INSPECT_TC)) != 0;
113  if (unidir) {
114  SCLogDebug("handle unidir tx");
115  AppLayerTxConfig req;
116  memset(&req, 0, sizeof(req));
117  req.log_flags = BIT_U8(config->type);
119  f->proto, f->alproto, f->alstate, tx, CONFIG_ACTION_SET, req);
120  }
121  } else {
122  SCLogDebug("no tx");
123  }
124 }
125 
126 /**
127  * \brief Apply configuration settings to a packet based on the provided DetectConfigData.
128  *
129  * This function applies specific configurations to a packet. The configurations are
130  * determined by the subsystems and types specified in the DetectConfigData structure.
131  *
132  * \param p Pointer to the Packet structure that will be configured.
133  * \param config Pointer to the DetectConfigData structure containing configuration settings.
134  */
135 static void ConfigApplyPacket(Packet *p, const DetectConfigData *config)
136 {
138 
139  switch (config->subsys) {
141  switch (config->type) {
142  case CONFIG_TYPE_FLOW:
143  if (p->flags & PKT_WANTS_FLOW) {
144  p->flags &= ~PKT_WANTS_FLOW;
145  }
146  break;
147  case CONFIG_TYPE_TX:
148  break;
149  }
150  break;
152  break;
153  }
154 }
155 
156 /**
157  * \brief Apply configuration settings based on the scope.
158  *
159  * This function applies post-match configurations with options. It
160  * determines which logic to apply based on the scope of the configuration,
161  * whether it is packet, transaction (tx), or flow level.
162  *
163  * \param det_ctx Pointer to the detection engine thread context.
164  * \param p Pointer to the current packet being processed.
165  * \param config Pointer to the configuration data structure.
166  *
167  * \retval 0 on success.
168  */
169 static int ConfigApply(DetectEngineThreadCtx *det_ctx,
170  Packet *p, const DetectConfigData *config)
171 {
172  bool this_packet = false;
173  bool this_tx = false;
174  bool this_flow = false;
175 
176  switch (config->scope) {
177  case CONFIG_SCOPE_PACKET:
178  this_packet = true;
179  break;
180  case CONFIG_SCOPE_TX:
181  this_tx = true;
182  break;
183  case CONFIG_SCOPE_FLOW:
184  this_flow = true;
185  break;
186  }
187 
188  if (this_packet) {
189  SCLogDebug("packet logic here: %" PRIu64, PcapPacketCntGet(p));
190  ConfigApplyPacket(p, config);
191  } else if (this_tx) {
192  SCLogDebug("tx logic here: tx_id %"PRIu64, det_ctx->tx_id);
193  ConfigApplyTx(p->flow, det_ctx->tx_id, config);
194  } else if (this_flow) {
195  SCLogDebug("flow logic here");
196  }
197 
198  SCReturnInt(0);
199 }
200 
201 /**
202  * \brief Post-match configuration detection function.
203  *
204  * This function is called after a match has been detected. It applies the
205  * configuration settings to the packet and returns 1 indicating that the
206  * configuration was successfully applied.
207  *
208  * \param det_ctx Pointer to the detection engine thread context.
209  * \param p Pointer to the packet being processed.
210  * \param s Pointer to the signature that matched.
211  * \param ctx Pointer to the match context, which contains the configuration data.
212  * \return 1 indicating the configuration was successfully applied
213  */
214 static int DetectConfigPostMatch(DetectEngineThreadCtx *det_ctx,
215  Packet *p, const Signature *s, const SigMatchCtx *ctx)
216 {
217  SCEnter();
218  const DetectConfigData *config = (const DetectConfigData *)ctx;
219  ConfigApply(det_ctx, p, config);
220  SCReturnInt(1);
221 }
222 
224  char subsys[32];
225  char state[32];
226  char type[32];
227  char typeval[32];
228  char scope[32];
229  char scopeval[32];
230 };
231 
232 static int GetStrings(const char *str, struct ConfigStrings *p)
233 {
234  pcre2_match_data *match = NULL;
235 
236  if (str == NULL || strlen(str) == 0) {
237  SCLogError("config keywords need arguments");
238  return -1;
239  }
240  SCLogDebug("str %s", str);
241 
242  int ret = DetectParsePcreExec(&parse_regex, &match, str, 0, 0);
243  if (ret != 7) {
244  SCLogError("config is rather picky at this time");
245  goto error;
246  }
247  size_t pcre2len = sizeof(p->subsys);
248  int res = pcre2_substring_copy_bynumber(match, 1, (PCRE2_UCHAR8 *)p->subsys, &pcre2len);
249  if (res < 0) {
250  SCLogError("failed to copy subsys substring");
251  goto error;
252  }
253 
254  pcre2len = sizeof(p->state);
255  res = pcre2_substring_copy_bynumber(match, 2, (PCRE2_UCHAR8 *)p->state, &pcre2len);
256  if (res < 0) {
257  SCLogError("failed to copy state substring");
258  goto error;
259  }
260 
261  pcre2len = sizeof(p->type);
262  res = pcre2_substring_copy_bynumber(match, 3, (PCRE2_UCHAR8 *)p->type, &pcre2len);
263  if (res < 0) {
264  SCLogError("failed to copy type substring");
265  goto error;
266  }
267 
268  pcre2len = sizeof(p->typeval);
269  res = pcre2_substring_copy_bynumber(match, 4, (PCRE2_UCHAR8 *)p->typeval, &pcre2len);
270  if (res < 0) {
271  SCLogError("failed to copy typeval substring");
272  goto error;
273  }
274 
275  pcre2len = sizeof(p->scope);
276  res = pcre2_substring_copy_bynumber(match, 5, (PCRE2_UCHAR8 *)p->scope, &pcre2len);
277  if (res < 0) {
278  SCLogError("failed to copy scope substring");
279  goto error;
280  }
281 
282  pcre2len = sizeof(p->scopeval);
283  res = pcre2_substring_copy_bynumber(match, 6, (PCRE2_UCHAR8 *)p->scopeval, &pcre2len);
284  if (res < 0) {
285  SCLogError("failed to copy scopeval substring");
286  goto error;
287  }
288 
289  pcre2_match_data_free(match);
290  return 0;
291 error:
292  pcre2_match_data_free(match);
293  return -1;
294 }
295 
296 static bool ParseValues(const struct ConfigStrings *c, enum ConfigType *type,
297  enum ConfigSubsys *subsys, enum ConfigScope *scope)
298 {
299  SCLogDebug("subsys %s", c->subsys);
300  if (strcmp(c->subsys, "logging") == 0) {
301  *subsys = CONFIG_SUBSYS_LOGGING;
302  } else if (strcmp(c->subsys, "tracking") == 0) {
303  *subsys = CONFIG_SUBSYS_TRACKING;
304  } else {
305  SCLogError("invalid subsys '%s': only 'logging' and 'tracking' supported at this time",
306  c->subsys);
307  return false;
308  }
309 
310  SCLogDebug("state %s", c->state);
311  if (strcmp(c->state, "disable") != 0) {
312  SCLogError("only 'disable' supported at this time");
313  return false;
314  }
315 
316  SCLogDebug("type %s", c->type);
317  if (strcmp(c->type, "type") != 0) {
318  SCLogError("only 'type' supported at this time");
319  return false;
320  }
321 
322  SCLogDebug("typeval %s", c->typeval);
323  if (strcmp(c->typeval, "tx") == 0) {
324  *type = CONFIG_TYPE_TX;
325  } else if (strcmp(c->typeval, "flow") == 0) {
327  } else {
328  SCLogError("only 'tx' and 'flow' supported at this time");
329  return false;
330  }
331 
332  SCLogDebug("scope %s", c->scope);
333  if (strcmp(c->scope, "scope") != 0) {
334  SCLogError("only 'scope' supported at this time");
335  return false;
336  }
337 
338  if (strcmp(c->scopeval, "tx") == 0) {
339  *scope = CONFIG_SCOPE_TX;
340  } else if (strcmp(c->scopeval, "flow") == 0) {
341  *scope = CONFIG_SCOPE_FLOW;
342  } else if (strcmp(c->scopeval, "packet") == 0) {
343  *scope = CONFIG_SCOPE_PACKET;
344  } else {
345  SCLogError("invalid scope '%s': only 'tx', 'flow' and 'packet' supported at this time",
346  c->scopeval);
347  return false;
348  }
349  SCLogDebug("scopeval %s", c->scopeval);
350  return true;
351 }
352 
353 /**
354  * \brief this function is used to parse config option into the current signature
355  *
356  * \param de_ctx pointer to the Detection Engine Context
357  * \param s pointer to the Current Signature
358  * \param str pointer to the user provided "config" input option string
359  *
360  * \retval 0 on Success
361  * \retval -1 on Failure
362  */
363 static int DetectConfigSetup(DetectEngineCtx *de_ctx, Signature *s, const char *str)
364 {
365  SCEnter();
366 
367  struct ConfigStrings c;
368  memset(&c, 0, sizeof(c));
369 
370  if (GetStrings(str, &c) != 0) {
371  SCReturnInt(-1);
372  }
373 
374  enum ConfigType type;
375  enum ConfigSubsys subsys;
376  enum ConfigScope scope;
377 
378  if (ParseValues(&c, &type, &subsys, &scope) == false) {
379  SCReturnInt(-1);
380  }
381 
382  /* TODO table is not yet set here */
384  type == CONFIG_TYPE_FLOW) {
387  SCLogError("disabling flow tracking is only supported in 'pre_flow' hook");
388  SCReturnInt(-1);
389  }
390  }
391 
392  DetectConfigData *fd = SCCalloc(1, sizeof(DetectConfigData));
393  if (unlikely(fd == NULL))
394  return -1;
395 
396  fd->type = type;
397  fd->scope = scope;
398  fd->subsys = subsys;
399 
400  if (fd->scope == CONFIG_SCOPE_TX) {
401  s->flags |= SIG_FLAG_APPLAYER;
402  }
403 
406  return -1;
407  }
408 
409  return 0;
410 }
411 
412 static void DetectConfigFree(DetectEngineCtx *de_ctx, void *ptr)
413 {
414  if (ptr != NULL) {
415  SCFree(ptr);
416  }
417 }
418 
419 #ifdef UNITTESTS
420 static int DetectConfigTest01(void)
421 {
423  FAIL_IF(de_ctx == NULL);
424  de_ctx->flags |= DE_QUIET;
426  "config dns any any -> any any ("
427  "dns.query; content:\"common.domain.com\"; "
428  "config:logging disable, type tx, scope tx; "
429  "sid:1;)");
430  FAIL_IF_NULL(s);
432  PASS;
433 }
434 
435 void DetectConfigRegisterTests(void)
436 {
437  UtRegisterTest("DetectConfigTest01", DetectConfigTest01);
438 }
439 #endif /* UNITTESTS */
SigTableElmt_::url
const char * url
Definition: detect.h:1545
AppLayerTxConfig
Definition: app-layer-parser.h:165
AppLayerTxData::flags
uint8_t flags
Definition: app-layer-parser.h:182
detect-engine.h
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
CONFIG_SUBSYS_TRACKING
@ CONFIG_SUBSYS_TRACKING
Definition: util-config.h:33
ConfigStrings::type
char type[32]
Definition: detect-config.c:226
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
DetectConfigRegister
void DetectConfigRegister(void)
Registers the "config" keyword for detection.
Definition: detect-config.c:73
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
flow-util.h
ConfigStrings::scope
char scope[32]
Definition: detect-config.c:228
DetectParseRegex
Definition: detect-parse.h:94
SigTableElmt_::name
const char * name
Definition: detect.h:1542
CONFIG_TYPE_TX
@ CONFIG_TYPE_TX
Definition: util-config.h:37
stream-tcp.h
AppLayerParserApplyTxConfig
void AppLayerParserApplyTxConfig(uint8_t ipproto, AppProto alproto, void *state, void *tx, enum ConfigAction mode, AppLayerTxConfig config)
Definition: app-layer-parser.c:1438
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
PcapPacketCntGet
uint64_t PcapPacketCntGet(const Packet *p)
Definition: decode.c:1193
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
CONFIG_ACTION_SET
@ CONFIG_ACTION_SET
Definition: util-config.h:28
DetectConfigData_::subsys
enum ConfigSubsys subsys
Definition: detect-config.h:30
Flow_::proto
uint8_t proto
Definition: flow.h:381
DetectEngineThreadCtx_::tx_id
uint64_t tx_id
Definition: detect.h:1392
SignatureHook_::t
union SignatureHook_::@87 t
Packet_::flags
uint32_t flags
Definition: decode.h:562
type
uint8_t type
Definition: decode-sctp.h:0
threads.h
Flow_
Flow data structure.
Definition: flow.h:359
PARSE_REGEX
#define PARSE_REGEX
Regex for parsing our config keyword options.
Definition: detect-config.c:58
ctx
struct Thresholds ctx
ConfigScope
ConfigScope
Definition: util-config.h:49
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
PKT_WANTS_FLOW
#define PKT_WANTS_FLOW
Definition: decode.h:1341
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
CONFIG_SCOPE_TX
@ CONFIG_SCOPE_TX
Definition: util-config.h:50
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
p
Packet * p
Definition: fuzz_dataset.c:30
DetectParsePcreExec
int DetectParsePcreExec(DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options)
Definition: detect-parse.c:4019
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
ConfigSubsys
ConfigSubsys
Definition: util-config.h:31
util-unittest-helper.h
SIG_FLAG_APPLAYER
#define SIG_FLAG_APPLAYER
Definition: detect.h:252
ConfigStrings
Definition: detect-config.c:223
ConfigStrings::typeval
char typeval[32]
Definition: detect-config.c:227
DETECT_SM_LIST_POSTMATCH
@ DETECT_SM_LIST_POSTMATCH
Definition: detect.h:128
app-layer-htp.h
decode.h
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
AppLayerTxData
Definition: app-layer-parser.h:172
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
CONFIG_TYPE_FLOW
@ CONFIG_TYPE_FLOW
Definition: util-config.h:38
DetectConfigData_::scope
enum ConfigScope scope
Definition: detect-config.h:32
ConfigStrings::state
char state[32]
Definition: detect-config.c:225
DetectSetupParseRegexes
void DetectSetupParseRegexes(const char *parse_str, DetectParseRegex *detect_parse)
Definition: detect-parse.c:4145
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
detect-engine-mpm.h
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
SignatureHook_::pkt
struct SignatureHook_::@87::@89 pkt
app-layer-parser.h
SIGMATCH_BAN_TD_FIREWALL_MODE
#define SIGMATCH_BAN_TD_FIREWALL_MODE
Definition: detect-engine-register.h:364
SignatureInitData_::hook
SignatureHook hook
Definition: detect.h:604
Signature_::flags
uint32_t flags
Definition: detect.h:693
ConfigType
ConfigType
Definition: util-config.h:36
Packet_
Definition: decode.h:516
DetectConfigData_::type
enum ConfigType type
Definition: detect-config.h:31
DetectConfigData_
Definition: detect-config.h:29
ConfigStrings::subsys
char subsys[32]
Definition: detect-config.c:224
DETECT_CONFIG
@ DETECT_CONFIG
Definition: detect-engine-register.h:222
Signature_::init_data
SignatureInitData * init_data
Definition: detect.h:775
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
AppLayerParserGetTx
void * AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id)
Definition: app-layer-parser.c:1219
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
Packet_::flow
struct Flow_ * flow
Definition: decode.h:564
BIT_U8
#define BIT_U8(n)
Definition: suricata-common.h:420
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
suricata-common.h
SignatureHook_::type
enum SignatureHookType type
Definition: detect.h:584
SIGNATURE_HOOK_PKT_PRE_FLOW
@ SIGNATURE_HOOK_PKT_PRE_FLOW
Definition: detect.h:550
AppLayerParserGetTxData
AppLayerTxData * AppLayerParserGetTxData(uint8_t ipproto, AppProto alproto, void *tx)
Definition: app-layer-parser.c:1420
util-spm-bm.h
SIGNATURE_HOOK_TYPE_PKT
@ SIGNATURE_HOOK_TYPE_PKT
Definition: detect.h:557
ConfigStrings::scopeval
char scopeval[32]
Definition: detect-config.c:229
AppLayerTxConfig::log_flags
uint8_t log_flags
config: log flags
Definition: app-layer-parser.h:167
str
#define str(s)
Definition: suricata-common.h:313
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SCFree
#define SCFree(p)
Definition: util-mem.h:61
Flow_::alstate
void * alstate
Definition: flow.h:484
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
SIGMATCH_SUPPORT_FIREWALL
#define SIGMATCH_SUPPORT_FIREWALL
Definition: detect-engine-register.h:336
CONFIG_SCOPE_FLOW
@ CONFIG_SCOPE_FLOW
Definition: util-config.h:51
CONFIG_SCOPE_PACKET
@ CONFIG_SCOPE_PACKET
Definition: util-config.h:52
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
flow.h
Flow_::alproto
AppProto alproto
application level protocol
Definition: flow.h:455
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
detect-config.h
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
Packet_::type
uint8_t type
Definition: decode.h:526
flow-var.h
CONFIG_SUBSYS_LOGGING
@ CONFIG_SUBSYS_LOGGING
Definition: util-config.h:32
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
output.h
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
app-layer.h
AppLayerTxData::config
AppLayerTxConfig config
config: log flags
Definition: app-layer-parser.h:174
f
Flow f
Definition: fuzz_dataset.c:32