suricata
detect-csum.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2024 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Anoop Saldanha <anoopsaldanha@gmail.com>
22  *
23  * Implements checksum keyword.
24  */
25 
26 #include "suricata-common.h"
27 #include "decode.h"
28 
29 #include "detect.h"
30 #include "detect-parse.h"
31 
32 #include "detect-csum.h"
33 
34 #include "util-debug.h"
35 
36 #include "pkt-var.h"
37 #include "host.h"
38 #include "util-profiling.h"
39 #include "detect-engine-build.h"
40 
41 #define DETECT_CSUM_VALID "valid"
42 #define DETECT_CSUM_INVALID "invalid"
43 
44 typedef struct DetectCsumData_ {
45  /* Indicates if the csum-<protocol> keyword in a rule holds the
46  keyvalue "valid" or "invalid" */
47  int16_t valid;
49 
50 /* prototypes for the "ipv4-csum" rule keyword */
51 static int DetectIPV4CsumMatch(DetectEngineThreadCtx *,
52  Packet *, const Signature *, const SigMatchCtx *);
53 static int DetectIPV4CsumSetup(DetectEngineCtx *, Signature *, const char *);
54 static void DetectIPV4CsumFree(DetectEngineCtx *, void *);
55 
56 /* prototypes for the "tcpv4-csum" rule keyword */
57 static int DetectTCPV4CsumMatch(DetectEngineThreadCtx *,
58  Packet *, const Signature *, const SigMatchCtx *);
59 static int DetectTCPV4CsumSetup(DetectEngineCtx *, Signature *, const char *);
60 static void DetectTCPV4CsumFree(DetectEngineCtx *, void *);
61 
62 /* prototypes for the "tcpv6-csum" rule keyword */
63 static int DetectTCPV6CsumMatch(DetectEngineThreadCtx *,
64  Packet *, const Signature *, const SigMatchCtx *);
65 static int DetectTCPV6CsumSetup(DetectEngineCtx *, Signature *, const char *);
66 static void DetectTCPV6CsumFree(DetectEngineCtx *, void *);
67 
68 /* prototypes for the "udpv4-csum" rule keyword */
69 static int DetectUDPV4CsumMatch(DetectEngineThreadCtx *,
70  Packet *, const Signature *, const SigMatchCtx *);
71 static int DetectUDPV4CsumSetup(DetectEngineCtx *, Signature *, const char *);
72 static void DetectUDPV4CsumFree(DetectEngineCtx *, void *);
73 
74 /* prototypes for the "udpv6-csum" rule keyword */
75 static int DetectUDPV6CsumMatch(DetectEngineThreadCtx *,
76  Packet *, const Signature *, const SigMatchCtx *);
77 static int DetectUDPV6CsumSetup(DetectEngineCtx *, Signature *, const char *);
78 static void DetectUDPV6CsumFree(DetectEngineCtx *de_ctx, void *);
79 
80 /* prototypes for the "icmpv4-csum" rule keyword */
81 static int DetectICMPV4CsumMatch(DetectEngineThreadCtx *,
82  Packet *, const Signature *, const SigMatchCtx *);
83 static int DetectICMPV4CsumSetup(DetectEngineCtx *, Signature *, const char *);
84 static void DetectICMPV4CsumFree(DetectEngineCtx *, void *);
85 
86 /* prototypes for the "icmpv6-csum" rule keyword */
87 static int DetectICMPV6CsumMatch(DetectEngineThreadCtx *,
88  Packet *, const Signature *, const SigMatchCtx *);
89 static int DetectICMPV6CsumSetup(DetectEngineCtx *, Signature *, const char *);
90 static void DetectICMPV6CsumFree(DetectEngineCtx *, void *);
91 
92 /* prototypes for the "igmp-csum" rule keyword */
93 static int DetectIGMPCsumMatch(
94  DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *);
95 static int DetectIGMPCsumSetup(DetectEngineCtx *, Signature *, const char *);
96 static void DetectIGMPCsumFree(DetectEngineCtx *, void *);
97 
98 #ifdef UNITTESTS
99 static void DetectCsumRegisterTests(void);
100 #endif
101 
102 /**
103  * \brief Registers handlers for all the checksum keywords. The checksum
104  * keywords that are registered are ipv4-sum, tcpv4-csum, tcpv6-csum,
105  * udpv4-csum, udpv6-csum, icmpv4-csum and icmpv6-csum.
106  *
107  * Each of the checksum keywords implemented here takes 2 arguments -
108  * "valid" or "invalid". If the rule keyword in the signature is
109  * specified as "valid", the Match function would return TRUE if the
110  * checksum for that particular packet and protocol is valid. Similarly
111  * for "invalid".
112  *
113  * The Setup functions takes 4 arguments -
114  *
115  * DetectEngineCtx * (de_ctx) - A pointer to the detection engine context
116  * Signature *(s) - Pointer to signature for the current Signature being
117  * parsed from the rules
118  * SigMatchCtx * (m) - Pointer to the head of the SigMatchs added to the
119  * current Signature being parsed
120  * char * (csum_str) - Pointer to a string holding the keyword value
121  *
122  * The Setup function returns 0 if it successfully parses the keyword
123  * value, and -1 otherwise.
124  *
125  * The Match function takes 5 arguments -
126  *
127  * ThreadVars * (t) - Pointer to the tv for the detection module instance
128  * DetectEngineThreadCtx * (det_ctx) - Pointer to the detection engine
129  * thread context
130  * Packet * (p) - Pointer to the Packet currently being handled
131  * Signature * (s) - Pointer to the Signature, the packet is being
132  * currently matched with
133  * SigMatchCtx * (m) - Pointer to the keyword structure from the above
134  * Signature, the Packet is being currently matched
135  * with
136  *
137  * The Match function returns 1 if the Packet contents match the keyword,
138  * and 0 otherwise
139  *
140  * The Free function takes a single argument -
141  *
142  * void * (ptr) - Pointer to the DetectCsumData for a keyword
143  */
145 {
146  sigmatch_table[DETECT_IPV4_CSUM].name = "ipv4-csum";
147  sigmatch_table[DETECT_IPV4_CSUM].Match = DetectIPV4CsumMatch;
148  sigmatch_table[DETECT_IPV4_CSUM].Setup = DetectIPV4CsumSetup;
149  sigmatch_table[DETECT_IPV4_CSUM].Free = DetectIPV4CsumFree;
150  sigmatch_table[DETECT_IPV4_CSUM].desc = "match on IPv4 checksum";
151 #ifdef UNITTESTS
152  sigmatch_table[DETECT_IPV4_CSUM].RegisterTests = DetectCsumRegisterTests;
153 #endif
154 
155  sigmatch_table[DETECT_TCPV4_CSUM].name = "tcpv4-csum";
156  sigmatch_table[DETECT_TCPV4_CSUM].Match = DetectTCPV4CsumMatch;
157  sigmatch_table[DETECT_TCPV4_CSUM].Setup = DetectTCPV4CsumSetup;
158  sigmatch_table[DETECT_TCPV4_CSUM].Free = DetectTCPV4CsumFree;
159  sigmatch_table[DETECT_TCPV4_CSUM].desc = "match on IPv4/TCP checksum";
160 
161  sigmatch_table[DETECT_TCPV6_CSUM].name = "tcpv6-csum";
162  sigmatch_table[DETECT_TCPV6_CSUM].Match = DetectTCPV6CsumMatch;
163  sigmatch_table[DETECT_TCPV6_CSUM].Setup = DetectTCPV6CsumSetup;
164  sigmatch_table[DETECT_TCPV6_CSUM].Free = DetectTCPV6CsumFree;
165  sigmatch_table[DETECT_TCPV6_CSUM].desc = "match on IPv6/TCP checksum";
166 
167  sigmatch_table[DETECT_UDPV4_CSUM].name = "udpv4-csum";
168  sigmatch_table[DETECT_UDPV4_CSUM].Match = DetectUDPV4CsumMatch;
169  sigmatch_table[DETECT_UDPV4_CSUM].Setup = DetectUDPV4CsumSetup;
170  sigmatch_table[DETECT_UDPV4_CSUM].Free = DetectUDPV4CsumFree;
171  sigmatch_table[DETECT_UDPV4_CSUM].desc = "match on IPv4/UDP checksum";
172 
173  sigmatch_table[DETECT_UDPV6_CSUM].name = "udpv6-csum";
174  sigmatch_table[DETECT_UDPV6_CSUM].Match = DetectUDPV6CsumMatch;
175  sigmatch_table[DETECT_UDPV6_CSUM].Setup = DetectUDPV6CsumSetup;
176  sigmatch_table[DETECT_UDPV6_CSUM].Free = DetectUDPV6CsumFree;
177  sigmatch_table[DETECT_UDPV6_CSUM].desc = "match on IPv6/UDP checksum";
178 
179  sigmatch_table[DETECT_ICMPV4_CSUM].name = "icmpv4-csum";
180  sigmatch_table[DETECT_ICMPV4_CSUM].Match = DetectICMPV4CsumMatch;
181  sigmatch_table[DETECT_ICMPV4_CSUM].Setup = DetectICMPV4CsumSetup;
182  sigmatch_table[DETECT_ICMPV4_CSUM].Free = DetectICMPV4CsumFree;
183  sigmatch_table[DETECT_ICMPV4_CSUM].desc = "match on IPv4/ICMP checksum";
184 
185  sigmatch_table[DETECT_ICMPV6_CSUM].name = "icmpv6-csum";
186  sigmatch_table[DETECT_ICMPV6_CSUM].Match = DetectICMPV6CsumMatch;
187  sigmatch_table[DETECT_ICMPV6_CSUM].Setup = DetectICMPV6CsumSetup;
188  sigmatch_table[DETECT_ICMPV6_CSUM].Free = DetectICMPV6CsumFree;
189  sigmatch_table[DETECT_ICMPV6_CSUM].desc = "match on IPv6/ICMPv6 checksum";
190 
191  sigmatch_table[DETECT_IGMP_CSUM].name = "igmp-csum";
192  sigmatch_table[DETECT_IGMP_CSUM].Match = DetectIGMPCsumMatch;
193  sigmatch_table[DETECT_IGMP_CSUM].Setup = DetectIGMPCsumSetup;
194  sigmatch_table[DETECT_IGMP_CSUM].Free = DetectIGMPCsumFree;
195  sigmatch_table[DETECT_IGMP_CSUM].desc = "match on IPv4/IGMP checksum";
196 }
197 
198 /**
199  * \brief Validates and parses the argument supplied with the checksum keyword.
200  * Accepts strings both with and without quotes, i.e. valid, \"valid\",
201  * invalid and \"invalid\"
202  *
203  * \param key Pointer to a const character string holding the csum keyword value
204  * \param cd Pointer to the DetectCsumData structure that holds the keyword
205  * value sent as argument
206  *
207  * \retval 1 the keyvalue has been parsed successfully
208  * \retval 0 error
209  */
210 static int DetectCsumParseArg(const char *key, DetectCsumData *cd)
211 {
212  char *str;
213 
214  if (key[0] == '\"' && key[strlen(key) - 1] == '\"') {
215  str = SCStrdup(key + 1);
216  if (unlikely(str == NULL)) {
217  return 0;
218  }
219  str[strlen(key) - 2] = '\0';
220  } else {
221  str = SCStrdup(key);
222  if (unlikely(str == NULL)) {
223  return 0;
224  }
225  }
226 
227  if (strcasecmp(str, DETECT_CSUM_VALID) == 0 ||
228  strcasecmp(str, DETECT_CSUM_INVALID) == 0) {
229  cd->valid = (strcasecmp(key, DETECT_CSUM_VALID) == 0);
230  SCFree(str);
231  return 1;
232  }
233 
234  SCFree(str);
235  return 0;
236 }
237 
238 /**
239  * \brief Checks if the packet sent as the argument, has a valid or invalid
240  * ipv4 checksum, based on whether ipv4-csum option for this rule
241  * has been supplied with "valid" or "invalid" argument
242  *
243  * \param t Pointer to the tv for this detection module instance
244  * \param det_ctx Pointer to the detection engine thread context
245  * \param p Pointer to the Packet currently being matched
246  * \param s Pointer to the Signature, the packet is being currently
247  * matched with
248  * \param m Pointer to the keyword_structure(SigMatch) from the above
249  * Signature, the Packet is being currently matched with
250  *
251  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
252  */
253 static int DetectIPV4CsumMatch(DetectEngineThreadCtx *det_ctx,
254  Packet *p, const Signature *s, const SigMatchCtx *ctx)
255 {
256  const DetectCsumData *cd = (const DetectCsumData *)ctx;
257 
258  if (!PacketIsIPv4(p))
259  return 0;
260 
261  if (p->flags & PKT_IGNORE_CHECKSUM) {
262  return cd->valid;
263  }
264 
265  if (!p->l3.csum_set) {
266  const IPV4Hdr *ip4h = PacketGetIPv4(p);
267  p->l3.csum = IPV4Checksum((uint16_t *)ip4h, IPV4_GET_RAW_HLEN(ip4h), ip4h->ip_csum);
268  p->l3.csum_set = true;
269  }
270 
271  if (p->l3.csum == 0 && cd->valid == 1)
272  return 1;
273  else if (p->l3.csum != 0 && cd->valid == 0)
274  return 1;
275  else
276  return 0;
277 }
278 
279 /**
280  * \brief Creates a SigMatch for the ipv4-csum keyword being sent as argument,
281  * and appends it to the Signature(s). Accepts 2 values for the
282  * keyword - "valid" and "invalid", both with and without quotes
283  *
284  * \param de_ctx Pointer to the detection engine context
285  * \param s Pointer to signature for the current Signature being parsed
286  * from the rules
287  * \param csum_str Pointer to the string holding the keyword value
288  *
289  * \retval 0 on success, -1 on failure
290  */
291 static int DetectIPV4CsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
292 {
293  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
294  if (cd == NULL)
295  return -1;
296 
297  if (DetectCsumParseArg(csum_str, cd) == 0)
298  goto error;
299 
302  goto error;
303  }
304 
305  return 0;
306 
307 error:
308  DetectIPV4CsumFree(de_ctx, cd);
309  return -1;
310 }
311 
312 static void DetectIPV4CsumFree(DetectEngineCtx *de_ctx, void *ptr)
313 {
314  SCFree(ptr);
315 }
316 
317 /**
318  * \brief Checks if the packet sent as the argument, has a valid or invalid
319  * tcpv4 checksum, based on whether tcpv4-csum option for this rule
320  * has been supplied with "valid" or "invalid" argument
321  *
322  * \param t Pointer to the tv for this detection module instance
323  * \param det_ctx Pointer to the detection engine thread context
324  * \param p Pointer to the Packet currently being matched
325  * \param s Pointer to the Signature, the packet is being currently
326  * matched with
327  * \param m Pointer to the keyword_structure(SigMatch) from the above
328  * Signature, the Packet is being currently matched with
329  *
330  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
331  */
332 static int DetectTCPV4CsumMatch(DetectEngineThreadCtx *det_ctx,
333  Packet *p, const Signature *s, const SigMatchCtx *ctx)
334 {
335  const DetectCsumData *cd = (const DetectCsumData *)ctx;
336 
337  if (!PacketIsIPv4(p) || !PacketIsTCP(p) || p->proto != IPPROTO_TCP)
338  return 0;
339 
340  if (p->flags & PKT_IGNORE_CHECKSUM) {
341  return cd->valid;
342  }
343 
344  if (!p->l4.csum_set) {
345  const IPV4Hdr *ip4h = PacketGetIPv4(p);
346  const TCPHdr *tcph = PacketGetTCP(p);
347  p->l4.csum = TCPChecksum(ip4h->s_ip_addrs, (uint16_t *)tcph,
348  (p->payload_len + TCP_GET_RAW_HLEN(tcph)), tcph->th_sum);
349  p->l4.csum_set = true;
350  }
351  if (p->l4.csum == 0 && cd->valid == 1)
352  return 1;
353  else if (p->l4.csum != 0 && cd->valid == 0)
354  return 1;
355  else
356  return 0;
357 }
358 
359 /**
360  * \brief Creates a SigMatch for the tcpv4-csum keyword being sent as argument,
361  * and appends it to the Signature(s). Accepts 2 values for the
362  * keyword - "valid" and "invalid", both with and without quotes
363  *
364  * \param de_ctx Pointer to the detection engine context
365  * \param s Pointer to signature for the current Signature being parsed
366  * from the rules
367  * \param csum_str Pointer to the string holding the keyword value
368  *
369  * \retval 0 on success, -1 on failure
370  */
371 static int DetectTCPV4CsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
372 {
373  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
374  if (cd == NULL)
375  return -1;
376 
377  if (DetectCsumParseArg(csum_str, cd) == 0)
378  goto error;
379 
382  goto error;
383  }
384 
385  return 0;
386 
387 error:
388  DetectTCPV4CsumFree(de_ctx, cd);
389  return -1;
390 }
391 
392 static void DetectTCPV4CsumFree(DetectEngineCtx *de_ctx, void *ptr)
393 {
394  SCFree(ptr);
395 }
396 
397 /**
398  * \brief Checks if the packet sent as the argument, has a valid or invalid
399  * tcpv6 checksum, based on whether tcpv6-csum option for this rule
400  * has been supplied with "valid" or "invalid" argument
401  *
402  * \param t Pointer to the tv for this detection module instance
403  * \param det_ctx Pointer to the detection engine thread context
404  * \param p Pointer to the Packet currently being matched
405  * \param s Pointer to the Signature, the packet is being currently
406  * matched with
407  * \param m Pointer to the keyword_structure(SigMatch) from the above
408  * Signature, the Packet is being currently matched with
409  *
410  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
411  */
412 static int DetectTCPV6CsumMatch(DetectEngineThreadCtx *det_ctx,
413  Packet *p, const Signature *s, const SigMatchCtx *ctx)
414 {
415  const DetectCsumData *cd = (const DetectCsumData *)ctx;
416 
417  if (!PacketIsIPv6(p) || !PacketIsTCP(p) || p->proto != IPPROTO_TCP)
418  return 0;
419 
420  if (p->flags & PKT_IGNORE_CHECKSUM) {
421  return cd->valid;
422  }
423 
424  if (!p->l4.csum_set) {
425  const IPV6Hdr *ip6h = PacketGetIPv6(p);
426  const TCPHdr *tcph = PacketGetTCP(p);
427  p->l4.csum = TCPV6Checksum(ip6h->s_ip6_addrs, (uint16_t *)tcph,
428  (p->payload_len + TCP_GET_RAW_HLEN(tcph)), tcph->th_sum);
429  p->l4.csum_set = true;
430  }
431 
432  if (p->l4.csum == 0 && cd->valid == 1)
433  return 1;
434  else if (p->l4.csum != 0 && cd->valid == 0)
435  return 1;
436  else
437  return 0;
438 }
439 
440 /**
441  * \brief Creates a SigMatch for the tcpv6-csum keyword being sent as argument,
442  * and appends it to the Signature(s). Accepts 2 values for the
443  * keyword - "valid" and "invalid", both with and without quotes
444  *
445  * \param de_ctx Pointer to the detection engine context
446  * \param s Pointer to signature for the current Signature being parsed
447  * from the rules
448  * \param csum_str Pointer to the string holding the keyword value
449  *
450  * \retval 0 on success, -1 on failure
451  */
452 static int DetectTCPV6CsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
453 {
454  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
455  if (cd == NULL)
456  return -1;
457 
458  if (DetectCsumParseArg(csum_str, cd) == 0)
459  goto error;
460 
463  goto error;
464  }
465 
466  return 0;
467 
468 error:
469  DetectTCPV6CsumFree(de_ctx, cd);
470  return -1;
471 }
472 
473 static void DetectTCPV6CsumFree(DetectEngineCtx *de_ctx, void *ptr)
474 {
475  SCFree(ptr);
476 }
477 
478 /**
479  * \brief Checks if the packet sent as the argument, has a valid or invalid
480  * udpv4 checksum, based on whether udpv4-csum option for this rule
481  * has been supplied with "valid" or "invalid" argument
482  *
483  * \param t Pointer to the tv for this detection module instance
484  * \param det_ctx Pointer to the detection engine thread context
485  * \param p Pointer to the Packet currently being matched
486  * \param s Pointer to the Signature, the packet is being currently
487  * matched with
488  * \param m Pointer to the keyword_structure(SigMatch) from the above
489  * Signature, the Packet is being currently matched with
490  *
491  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
492  */
493 static int DetectUDPV4CsumMatch(DetectEngineThreadCtx *det_ctx,
494  Packet *p, const Signature *s, const SigMatchCtx *ctx)
495 {
496  const DetectCsumData *cd = (const DetectCsumData *)ctx;
497 
498  if (!PacketIsIPv4(p) || !PacketIsUDP(p) || p->proto != IPPROTO_UDP)
499  return 0;
500 
501  const UDPHdr *udph = PacketGetUDP(p);
502  if (udph->uh_sum == 0)
503  return 0;
504 
505  if (p->flags & PKT_IGNORE_CHECKSUM) {
506  return cd->valid;
507  }
508 
509  if (!p->l4.csum_set) {
510  const IPV4Hdr *ip4h = PacketGetIPv4(p);
511  p->l4.csum = UDPV4Checksum(ip4h->s_ip_addrs, (uint16_t *)udph,
512  (p->payload_len + UDP_HEADER_LEN), udph->uh_sum);
513  p->l4.csum_set = true;
514  }
515  if (p->l4.csum == 0 && cd->valid == 1)
516  return 1;
517  else if (p->l4.csum != 0 && cd->valid == 0)
518  return 1;
519  else
520  return 0;
521 }
522 
523 /**
524  * \brief Creates a SigMatch for the udpv4-csum keyword being sent as argument,
525  * and appends it to the Signature(s). Accepts 2 values for the
526  * keyword - "valid" and "invalid", both with and without quotes
527  *
528  * \param de_ctx Pointer to the detection engine context
529  * \param s Pointer to signature for the current Signature being parsed
530  * from the rules
531  * \param csum_str Pointer to the string holding the keyword value
532  *
533  * \retval 0 on success, -1 on failure
534  */
535 static int DetectUDPV4CsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
536 {
537  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
538  if (cd == NULL)
539  return -1;
540 
541  if (DetectCsumParseArg(csum_str, cd) == 0)
542  goto error;
543 
546  goto error;
547  }
548 
549  return 0;
550 
551 error:
552  DetectUDPV4CsumFree(de_ctx, cd);
553  return -1;
554 }
555 
556 static void DetectUDPV4CsumFree(DetectEngineCtx *de_ctx, void *ptr)
557 {
558  SCFree(ptr);
559 }
560 
561 /**
562  * \brief Checks if the packet sent as the argument, has a valid or invalid
563  * udpv6 checksum, based on whether udpv6-csum option for this rule
564  * has been supplied with "valid" or "invalid" argument
565  *
566  * \param t Pointer to the tv for this detection module instance
567  * \param det_ctx Pointer to the detection engine thread context
568  * \param p Pointer to the Packet currently being matched
569  * \param s Pointer to the Signature, the packet is being currently
570  * matched with
571  * \param m Pointer to the keyword_structure(SigMatch) from the above
572  * Signature, the Packet is being currently matched with
573  *
574  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
575  */
576 static int DetectUDPV6CsumMatch(DetectEngineThreadCtx *det_ctx,
577  Packet *p, const Signature *s, const SigMatchCtx *ctx)
578 {
579  const DetectCsumData *cd = (const DetectCsumData *)ctx;
580 
581  if (!PacketIsIPv6(p) || !PacketIsUDP(p) || p->proto != IPPROTO_UDP)
582  return 0;
583 
584  if (p->flags & PKT_IGNORE_CHECKSUM) {
585  return cd->valid;
586  }
587 
588  if (!p->l4.csum_set) {
589  const IPV6Hdr *ip6h = PacketGetIPv6(p);
590  const UDPHdr *udph = PacketGetUDP(p);
591  p->l4.csum = UDPV6Checksum(ip6h->s_ip6_addrs, (uint16_t *)udph,
592  (p->payload_len + UDP_HEADER_LEN), udph->uh_sum);
593  p->l4.csum_set = true;
594  }
595  if (p->l4.csum == 0 && cd->valid == 1)
596  return 1;
597  else if (p->l4.csum != 0 && cd->valid == 0)
598  return 1;
599  else
600  return 0;
601 }
602 
603 /**
604  * \brief Creates a SigMatch for the udpv6-csum keyword being sent as argument,
605  * and appends it to the Signature(s). Accepts 2 values for the
606  * keyword - "valid" and "invalid", both with and without quotes
607  *
608  * \param de_ctx Pointer to the detection engine context
609  * \param s Pointer to signature for the current Signature being parsed
610  * from the rules
611  * \param csum_str Pointer to the string holding the keyword value
612  *
613  * \retval 0 on success, -1 on failure
614  */
615 static int DetectUDPV6CsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
616 {
617  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
618  if (cd == NULL)
619  return -1;
620 
621  if (DetectCsumParseArg(csum_str, cd) == 0)
622  goto error;
623 
626  goto error;
627  }
628 
629  return 0;
630 
631 error:
632  DetectUDPV6CsumFree(de_ctx, cd);
633  return -1;
634 }
635 
636 static void DetectUDPV6CsumFree(DetectEngineCtx *de_ctx, void *ptr)
637 {
638  DetectCsumData *cd = (DetectCsumData *)ptr;
639 
640  if (cd != NULL)
641  SCFree(cd);
642 }
643 
644 /**
645  * \brief Checks if the packet sent as the argument, has a valid or invalid
646  * icmpv4 checksum, based on whether icmpv4-csum option for this rule
647  * has been supplied with "valid" or "invalid" argument
648  *
649  * \param t Pointer to the tv for this detection module instance
650  * \param det_ctx Pointer to the detection engine thread context
651  * \param p Pointer to the Packet currently being matched
652  * \param s Pointer to the Signature, the packet is being currently
653  * matched with
654  * \param m Pointer to the keyword_structure(SigMatch) from the above
655  * Signature, the Packet is being currently matched with
656  *
657  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
658  */
659 static int DetectICMPV4CsumMatch(DetectEngineThreadCtx *det_ctx,
660  Packet *p, const Signature *s, const SigMatchCtx *ctx)
661 {
662  const DetectCsumData *cd = (const DetectCsumData *)ctx;
663 
664  if (!PacketIsIPv4(p) || !PacketIsICMPv4(p) || p->proto != IPPROTO_ICMP)
665  return 0;
666 
667  if (p->flags & PKT_IGNORE_CHECKSUM) {
668  return cd->valid;
669  }
670 
671  const ICMPV4Hdr *icmpv4h = PacketGetICMPv4(p);
672  if (!p->l4.csum_set) {
673  const IPV4Hdr *ip4h = PacketGetIPv4(p);
674  p->l4.csum = ICMPV4CalculateChecksum(
675  (uint16_t *)icmpv4h, IPV4_GET_RAW_IPLEN(ip4h) - IPV4_GET_RAW_HLEN(ip4h));
676  p->l4.csum_set = true;
677  }
678  if (p->l4.csum == icmpv4h->checksum && cd->valid == 1)
679  return 1;
680  else if (p->l4.csum != icmpv4h->checksum && cd->valid == 0)
681  return 1;
682  else
683  return 0;
684 }
685 
686 /**
687  * \brief Creates a SigMatch for the icmpv4-csum keyword being sent as argument,
688  * and appends it to the Signature(s). Accepts 2 values for the
689  * keyword - "valid" and "invalid", both with and without quotes
690  *
691  * \param de_ctx Pointer to the detection engine context
692  * \param s Pointer to signature for the current Signature being parsed
693  * from the rules
694  * \param csum_str Pointer to the string holding the keyword value
695  *
696  * \retval 0 on success, -1 on failure
697  */
698 static int DetectICMPV4CsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
699 {
700  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
701  if (cd == NULL)
702  return -1;
703 
704  if (DetectCsumParseArg(csum_str, cd) == 0)
705  goto error;
706 
709  goto error;
710  }
711 
712  return 0;
713 
714 error:
715  DetectICMPV4CsumFree(de_ctx, cd);
716  return -1;
717 }
718 
719 static void DetectICMPV4CsumFree(DetectEngineCtx *de_ctx, void *ptr)
720 {
721  SCFree(ptr);
722 }
723 
724 /**
725  * \brief Checks if the packet sent as the argument, has a valid or invalid
726  * icmpv6 checksum, based on whether icmpv6-csum option for this rule
727  * has been supplied with "valid" or "invalid" argument
728  *
729  * \param t Pointer to the tv for this detection module instance
730  * \param det_ctx Pointer to the detection engine thread context
731  * \param p Pointer to the Packet currently being matched
732  * \param s Pointer to the Signature, the packet is being currently
733  * matched with
734  * \param m Pointer to the keyword_structure(SigMatch) from the above
735  * Signature, the Packet is being currently matched with
736  *
737  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
738  */
739 static int DetectICMPV6CsumMatch(DetectEngineThreadCtx *det_ctx,
740  Packet *p, const Signature *s, const SigMatchCtx *ctx)
741 {
742  const DetectCsumData *cd = (const DetectCsumData *)ctx;
743 
744  if (!PacketIsIPv6(p) || !PacketIsICMPv6(p) || p->proto != IPPROTO_ICMPV6) {
745  return 0;
746  }
747  const ICMPV6Hdr *icmpv6h = PacketGetICMPv6(p);
748  if ((GET_PKT_LEN(p) - ((uint8_t *)icmpv6h - GET_PKT_DATA(p))) <= 0) {
749  return 0;
750  }
751 
752  if (p->flags & PKT_IGNORE_CHECKSUM) {
753  return cd->valid;
754  }
755 
756  if (!p->l4.csum_set) {
757  const IPV6Hdr *ip6h = PacketGetIPv6(p);
758  uint16_t len = IPV6_GET_RAW_PLEN(ip6h) -
759  (uint16_t)((uint8_t *)icmpv6h - (uint8_t *)ip6h - IPV6_HEADER_LEN);
760  p->l4.csum = ICMPV6CalculateChecksum(ip6h->s_ip6_addrs, (uint16_t *)icmpv6h, len);
761  p->l4.csum_set = true;
762  }
763 
764  if (p->l4.csum == icmpv6h->csum && cd->valid == 1)
765  return 1;
766  else if (p->l4.csum != icmpv6h->csum && cd->valid == 0)
767  return 1;
768  else
769  return 0;
770 }
771 
772 /**
773  * \brief Creates a SigMatch for the icmpv6-csum keyword being sent as argument,
774  * and appends it to the Signature(s). Accepts 2 values for the
775  * keyword - "valid" and "invalid", both with and without quotes
776  *
777  * \param de_ctx Pointer to the detection engine context
778  * \param s Pointer to signature for the current Signature being parsed
779  * from the rules
780  * \param csum_str Pointer to the string holding the keyword value
781  *
782  * \retval 0 on success, -1 on failure
783  */
784 static int DetectICMPV6CsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
785 {
786  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
787  if (cd == NULL)
788  return -1;
789 
790  if (DetectCsumParseArg(csum_str, cd) == 0)
791  goto error;
792 
795  goto error;
796  }
797 
798  return 0;
799 
800 error:
801  DetectICMPV6CsumFree(de_ctx, cd);
802  return -1;
803 }
804 
805 static void DetectICMPV6CsumFree(DetectEngineCtx *de_ctx, void *ptr)
806 {
807  SCFree(ptr);
808 }
809 
810 /**
811  * \brief Checks if the packet sent as the argument, has a valid or invalid
812  * igmp checksum, based on whether igmp-csum option for this rule
813  * has been supplied with "valid" or "invalid" argument
814  *
815  * \param t Pointer to the tv for this detection module instance
816  * \param det_ctx Pointer to the detection engine thread context
817  * \param p Pointer to the Packet currently being matched
818  * \param s Pointer to the Signature, the packet is being currently
819  * matched with
820  * \param m Pointer to the keyword_structure(SigMatch) from the above
821  * Signature, the Packet is being currently matched with
822  *
823  * \retval 1 if the Packet contents match the keyword option; 0 otherwise
824  */
825 static int DetectIGMPCsumMatch(
826  DetectEngineThreadCtx *det_ctx, Packet *p, const Signature *s, const SigMatchCtx *ctx)
827 {
828  const DetectCsumData *cd = (const DetectCsumData *)ctx;
829 
830  if (!PacketIsIPv4(p) || !PacketIsIGMP(p) || p->proto != IPPROTO_IGMP)
831  return 0;
832 
833  if (p->flags & PKT_IGNORE_CHECKSUM) {
834  return cd->valid;
835  }
836 
837  const IGMPHdr *igmph = PacketGetIGMP(p);
838  if (!p->l4.csum_set) {
839  const IPV4Hdr *ip4h = PacketGetIPv4(p);
840  p->l4.csum = ICMPV4CalculateChecksum(
841  (uint16_t *)igmph, IPV4_GET_RAW_IPLEN(ip4h) - IPV4_GET_RAW_HLEN(ip4h));
842  p->l4.csum_set = true;
843  }
844  if (p->l4.csum == igmph->checksum && cd->valid == 1)
845  return 1;
846  else if (p->l4.csum != igmph->checksum && cd->valid == 0)
847  return 1;
848  else
849  return 0;
850 }
851 
852 /**
853  * \brief Creates a SigMatch for the icmpv4-csum keyword being sent as argument,
854  * and appends it to the Signature(s). Accepts 2 values for the
855  * keyword - "valid" and "invalid", both with and without quotes
856  *
857  * \param de_ctx Pointer to the detection engine context
858  * \param s Pointer to signature for the current Signature being parsed
859  * from the rules
860  * \param csum_str Pointer to the string holding the keyword value
861  *
862  * \retval 0 on success, -1 on failure
863  */
864 static int DetectIGMPCsumSetup(DetectEngineCtx *de_ctx, Signature *s, const char *csum_str)
865 {
866  DetectCsumData *cd = SCCalloc(1, sizeof(DetectCsumData));
867  if (cd == NULL)
868  return -1;
869 
870  if (DetectCsumParseArg(csum_str, cd) == 0)
871  goto error;
872 
875  goto error;
876  }
877 
878  return 0;
879 
880 error:
881  DetectIGMPCsumFree(de_ctx, cd);
882  return -1;
883 }
884 
885 static void DetectIGMPCsumFree(DetectEngineCtx *de_ctx, void *ptr)
886 {
887  SCFree(ptr);
888 }
889 
890 /* ---------------------------------- Unit Tests --------------------------- */
891 
892 #ifdef UNITTESTS
893 #include "util-unittest-helper.h"
894 #include "detect-engine.h"
895 #include "detect-engine-alert.h"
896 #include "packet.h"
897 
898 #define mystr(s) #s
899 #define TEST1(kwstr) {\
900  DetectEngineCtx *de_ctx = DetectEngineCtxInit();\
901  FAIL_IF_NULL(de_ctx);\
902  de_ctx->flags = DE_QUIET;\
903  \
904  Signature *s = DetectEngineAppendSig(de_ctx, "alert ip any any -> any any ("mystr(kwstr)"-csum:valid; sid:1;)");\
905  FAIL_IF_NULL(s);\
906  s = DetectEngineAppendSig(de_ctx, "alert ip any any -> any any ("mystr(kwstr)"-csum:invalid; sid:2;)");\
907  FAIL_IF_NULL(s);\
908  s = DetectEngineAppendSig(de_ctx, "alert ip any any -> any any ("mystr(kwstr)"-csum:vaLid; sid:3;)");\
909  FAIL_IF_NULL(s);\
910  s = DetectEngineAppendSig(de_ctx, "alert ip any any -> any any ("mystr(kwstr)"-csum:VALID; sid:4;)");\
911  FAIL_IF_NULL(s);\
912  s = DetectEngineAppendSig(de_ctx, "alert ip any any -> any any ("mystr(kwstr)"-csum:iNvaLid; sid:5;)");\
913  FAIL_IF_NULL(s);\
914  DetectEngineCtxFree(de_ctx);\
915 }
916 
917 
918 static int DetectCsumValidArgsTestParse01(void)
919 {
920  TEST1(ipv4);
921  TEST1(tcpv4);
922  TEST1(tcpv6);
923  TEST1(udpv4);
924  TEST1(udpv6);
925  TEST1(icmpv4);
926  TEST1(icmpv6);
927  PASS;
928 }
929 #undef TEST1
930 
931 #define TEST2(kwstr) \
932  { \
933  DetectEngineCtx *de_ctx = DetectEngineCtxInit(); \
934  FAIL_IF_NULL(de_ctx); \
935  Signature *s = DetectEngineAppendSig( \
936  de_ctx, "alert ip any any -> any any (" mystr(kwstr) "-csum:xxxx; sid:1;)"); \
937  FAIL_IF(s); \
938  s = DetectEngineAppendSig( \
939  de_ctx, "alert ip any any -> any any (" mystr(kwstr) "-csum:xxxxxxxx; sid:2;)"); \
940  FAIL_IF(s); \
941  s = DetectEngineAppendSig( \
942  de_ctx, "alert ip any any -> any any (" mystr(kwstr) "-csum:xxxxxx; sid:3;)"); \
943  FAIL_IF(s); \
944  s = DetectEngineAppendSig( \
945  de_ctx, "alert ip any any -> any any (" mystr(kwstr) "-csum:XXXXXX; sid:4;)"); \
946  FAIL_IF(s); \
947  s = DetectEngineAppendSig( \
948  de_ctx, "alert ip any any -> any any (" mystr(kwstr) "-csum:XxXxXxX; sid:5;)"); \
949  FAIL_IF(s); \
950  DetectEngineCtxFree(de_ctx); \
951  }
952 
953 static int DetectCsumInvalidArgsTestParse02(void)
954 {
955  TEST2(ipv4);
956  TEST2(tcpv4);
957  TEST2(tcpv6);
958  TEST2(udpv4);
959  TEST2(udpv6);
960  TEST2(icmpv4);
961  TEST2(icmpv6);
962  PASS;
963 }
964 #undef TEST2
965 
966 #define TEST3(kwstr, kwtype) \
967  { \
968  DetectEngineCtx *de_ctx = DetectEngineCtxInit(); \
969  FAIL_IF_NULL(de_ctx); \
970  Signature *s = DetectEngineAppendSig( \
971  de_ctx, "alert ip any any -> any any (" mystr(kwstr) "-csum:valid; sid:1;)"); \
972  FAIL_IF_NULL(s); \
973  SigMatch *sm = SCDetectGetLastSMFromLists(s, (kwtype), -1); \
974  FAIL_IF_NULL(sm); \
975  FAIL_IF_NULL(sm->ctx); \
976  FAIL_IF_NOT(((DetectCsumData *)sm->ctx)->valid == 1); \
977  s = DetectEngineAppendSig( \
978  de_ctx, "alert ip any any -> any any (" mystr(kwstr) "-csum:INVALID; sid:2;)"); \
979  FAIL_IF_NULL(s); \
980  sm = SCDetectGetLastSMFromLists(s, (kwtype), -1); \
981  FAIL_IF_NULL(sm); \
982  FAIL_IF_NULL(sm->ctx); \
983  FAIL_IF_NOT(((DetectCsumData *)sm->ctx)->valid == 0); \
984  DetectEngineCtxFree(de_ctx); \
985  }
986 
987 static int DetectCsumValidArgsTestParse03(void)
988 {
989  TEST3(ipv4, DETECT_IPV4_CSUM);
990  TEST3(tcpv4, DETECT_TCPV4_CSUM);
991  TEST3(tcpv6, DETECT_TCPV6_CSUM);
992  TEST3(udpv4, DETECT_UDPV4_CSUM);
993  TEST3(udpv6, DETECT_UDPV6_CSUM);
994  TEST3(icmpv4, DETECT_ICMPV4_CSUM);
995  TEST3(icmpv6, DETECT_ICMPV6_CSUM);
996  PASS;
997 }
998 #undef TEST3
999 #undef mystr
1000 
1001 #include "stream-tcp.h"
1002 
1003 static int DetectCsumICMPV6Test01(void)
1004 {
1005  ThreadVars tv;
1006  DetectEngineThreadCtx *det_ctx = NULL;
1008 
1010  FAIL_IF_NULL(p);
1011 
1012  uint8_t pkt[] = {
1013  0x00, 0x30, 0x18, 0xa8, 0x7c, 0x23, 0x2c, 0x41,
1014  0x38, 0xa7, 0xea, 0xeb, 0x86, 0xdd, 0x60, 0x00,
1015  0x00, 0x00, 0x00, 0x40, 0x3c, 0x40, 0xad, 0xa1,
1016  0x09, 0x80, 0x00, 0x01, 0xd6, 0xf3, 0x20, 0x01,
1017  0xf4, 0xbe, 0xea, 0x3c, 0x00, 0x01, 0x00, 0x00,
1018  0x00, 0x00, 0x32, 0xb2, 0x00, 0x01, 0x32, 0xb2,
1019  0x09, 0x80, 0x20, 0x01, 0x00, 0x00, 0x3c, 0x00,
1020  0x01, 0x04, 0x00, 0x00, 0x00, 0x00, 0x3c, 0x00,
1021  0x01, 0x04, 0x00, 0x00, 0x00, 0x00, 0x2c, 0x00,
1022  0x01, 0x04, 0x00, 0x00, 0x00, 0x00, 0x2c, 0x00,
1023  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3c, 0x00,
1024  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x2c, 0x00,
1025  0x01, 0x04, 0x00, 0x00, 0x00, 0x00, 0x3a, 0x00,
1026  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x80, 0x00,
1027  0x63, 0xc2, 0x00, 0x00, 0x00, 0x00 };
1028 
1029  PacketCopyData(p, pkt, sizeof(pkt));
1030 
1031  memset(&tv, 0, sizeof(tv));
1033  memset(&dtv, 0, sizeof(dtv));
1034 
1035  StreamTcpInitConfig(true);
1037 
1041  de_ctx->flags |= DE_QUIET;
1042 
1043  Signature *s = DetectEngineAppendSig(de_ctx, "alert ip any any -> any any "
1044  "(icmpv6-csum:valid; sid:1;)");
1045  FAIL_IF_NULL(s);
1047 
1049 
1050  DetectEngineThreadCtxInit(&tv, (void *)de_ctx, (void *)&det_ctx);
1051 
1052  SigMatchSignatures(&tv, de_ctx, det_ctx, p);
1053  FAIL_IF(!PacketAlertCheck(p, 1));
1054 
1055  PacketFree(p);
1056  FlowShutdown();
1057  DetectEngineThreadCtxDeinit(&tv, det_ctx);
1059  StreamTcpFreeConfig(true);
1061  PASS;
1062 }
1063 
1064 static void DetectCsumRegisterTests(void)
1065 {
1066  UtRegisterTest("DetectCsumValidArgsTestParse01",
1067  DetectCsumValidArgsTestParse01);
1068  UtRegisterTest("DetectCsumInvalidArgsTestParse02",
1069  DetectCsumInvalidArgsTestParse02);
1070  UtRegisterTest("DetectCsumValidArgsTestParse03",
1071  DetectCsumValidArgsTestParse03);
1072 
1073  UtRegisterTest("DetectCsumICMPV6Test01",
1074  DetectCsumICMPV6Test01);
1075 }
1076 #endif /* UNITTESTS */
PacketL4::csum_set
bool csum_set
Definition: decode.h:478
host.h
Packet_::proto
uint8_t proto
Definition: decode.h:538
len
uint8_t len
Definition: app-layer-dnp3.h:2
detect-engine.h
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
IPV6_GET_RAW_PLEN
#define IPV6_GET_RAW_PLEN(ip6h)
Definition: decode-ipv6.h:66
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
DETECT_CSUM_VALID
#define DETECT_CSUM_VALID
Definition: detect-csum.c:41
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
DETECT_IGMP_CSUM
@ DETECT_IGMP_CSUM
Definition: detect-engine-register.h:128
PacketCopyData
int PacketCopyData(Packet *p, const uint8_t *pktdata, uint32_t pktlen)
Copy data to Packet payload and set packet length.
Definition: decode.c:386
SigTableElmt_::name
const char * name
Definition: detect.h:1542
stream-tcp.h
DETECT_ICMPV4_CSUM
@ DETECT_ICMPV4_CSUM
Definition: detect-engine-register.h:126
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
PacketL4::csum
uint16_t csum
Definition: decode.h:479
ICMPV6Hdr_::csum
uint16_t csum
Definition: decode-icmpv6.h:132
PacketAlertCheck
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
Definition: detect-engine-alert.c:144
Packet_::flags
uint32_t flags
Definition: decode.h:562
DETECT_UDPV6_CSUM
@ DETECT_UDPV6_CSUM
Definition: detect-engine-register.h:125
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
TCP_GET_RAW_HLEN
#define TCP_GET_RAW_HLEN(tcph)
Definition: decode-tcp.h:72
DetectCsumData
struct DetectCsumData_ DetectCsumData
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
mpm_default_matcher
uint8_t mpm_default_matcher
Definition: util-mpm.c:47
SigMatchSignatures
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Definition: detect.c:3305
p
Packet * p
Definition: fuzz_dataset.c:30
DETECT_CSUM_INVALID
#define DETECT_CSUM_INVALID
Definition: detect-csum.c:42
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
Packet_::payload_len
uint16_t payload_len
Definition: decode.h:621
util-unittest-helper.h
DETECT_TCPV4_CSUM
@ DETECT_TCPV4_CSUM
Definition: detect-engine-register.h:122
FlowInitConfig
void FlowInitConfig(bool quiet)
initialize the configuration
Definition: flow.c:574
StreamTcpInitConfig
void StreamTcpInitConfig(bool)
To initialize the stream global configuration data.
Definition: stream-tcp.c:496
decode.h
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
GET_PKT_DATA
#define GET_PKT_DATA(p)
Definition: decode.h:210
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
pkt-var.h
DetectEngineThreadCtxInit
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
Definition: detect-engine.c:3660
IPV4_GET_RAW_HLEN
#define IPV4_GET_RAW_HLEN(ip4h)
Definition: decode-ipv4.h:96
DetectEngineCtx_::mpm_matcher
uint8_t mpm_matcher
Definition: detect.h:998
PacketFree
void PacketFree(Packet *p)
Return a malloced packet.
Definition: decode.c:221
DETECT_SM_LIST_MATCH
@ DETECT_SM_LIST_MATCH
Definition: detect.h:118
util-profiling.h
IPV6Hdr_
Definition: decode-ipv6.h:32
Packet_
Definition: decode.h:516
detect-engine-build.h
GET_PKT_LEN
#define GET_PKT_LEN(p)
Definition: decode.h:209
ICMPV4Hdr_
Definition: decode-icmpv4.h:165
detect-engine-alert.h
Packet_::l4
struct PacketL4 l4
Definition: decode.h:616
PKT_IGNORE_CHECKSUM
#define PKT_IGNORE_CHECKSUM
Definition: decode.h:1327
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
DETECT_IPV4_CSUM
@ DETECT_IPV4_CSUM
Definition: detect-engine-register.h:121
DetectCsumData_::valid
int16_t valid
Definition: detect-csum.c:47
SigGroupBuild
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
Definition: detect-engine-build.c:2300
dtv
DecodeThreadVars * dtv
Definition: fuzz_decodepcapfile.c:35
StatsThreadInit
void StatsThreadInit(StatsThreadContext *stats)
Definition: counters.c:1332
PacketL3::csum_set
bool csum_set
Definition: decode.h:447
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
IPV4Hdr_
Definition: decode-ipv4.h:72
ICMPV6Hdr_
Definition: decode-icmpv6.h:129
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
StreamTcpFreeConfig
void StreamTcpFreeConfig(bool quiet)
Definition: stream-tcp.c:864
suricata-common.h
FlowShutdown
void FlowShutdown(void)
shutdown the flow engine
Definition: flow.c:718
packet.h
DetectEngineThreadCtxDeinit
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Definition: detect-engine.c:3905
IGMPHdr_
Definition: decode-igmp.h:25
DetectCsumRegister
void DetectCsumRegister(void)
Registers handlers for all the checksum keywords. The checksum keywords that are registered are ipv4-...
Definition: detect-csum.c:144
SCStrdup
#define SCStrdup(s)
Definition: util-mem.h:56
UDPHdr_
Definition: decode-udp.h:42
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:34
PacketGetFromAlloc
Packet * PacketGetFromAlloc(void)
Get a malloced packet.
Definition: decode.c:260
DetectCsumData_
Definition: detect-csum.c:44
Packet_::l3
struct PacketL3 l3
Definition: decode.h:615
str
#define str(s)
Definition: suricata-common.h:313
SCFree
#define SCFree(p)
Definition: util-mem.h:61
DecodeThreadVars_
Structure to hold thread specific data for all decode modules.
Definition: decode.h:995
DETECT_ICMPV6_CSUM
@ DETECT_ICMPV6_CSUM
Definition: detect-engine-register.h:127
TEST1
#define TEST1(kwstr)
Definition: detect-csum.c:899
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
TEST3
#define TEST3(kwstr, kwtype)
Definition: detect-csum.c:966
PacketL3::csum
uint16_t csum
Definition: decode.h:448
UDP_HEADER_LEN
#define UDP_HEADER_LEN
Definition: decode-udp.h:27
FLOW_QUIET
#define FLOW_QUIET
Definition: flow.h:43
TEST2
#define TEST2(kwstr)
Definition: detect-csum.c:931
IPV6_HEADER_LEN
#define IPV6_HEADER_LEN
Definition: decode-ipv6.h:27
IPV4_GET_RAW_IPLEN
#define IPV4_GET_RAW_IPLEN(ip4h)
Definition: decode-ipv4.h:98
detect-csum.h
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
DETECT_TCPV6_CSUM
@ DETECT_TCPV6_CSUM
Definition: detect-engine-register.h:123
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
StatsThreadCleanup
void StatsThreadCleanup(StatsThreadContext *stats)
Definition: counters.c:1428
DecodeEthernet
int DecodeEthernet(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint32_t len)
Definition: decode-ethernet.c:41
TCPHdr_
Definition: decode-tcp.h:149
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
DETECT_UDPV4_CSUM
@ DETECT_UDPV4_CSUM
Definition: detect-engine-register.h:124
UDPHdr_::uh_sum
uint16_t uh_sum
Definition: decode-udp.h:46