suricata
detect-engine-address.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * Address part of the detection engine.
24  */
25 
26 #include "suricata-common.h"
27 #include "decode.h"
28 #include "detect.h"
29 #include "flow-var.h"
30 
31 #include "util-cidr.h"
32 #include "util-rule-vars.h"
33 #include "conf.h"
34 #include "conf-yaml-loader.h"
35 
36 #include "detect-engine-siggroup.h"
37 #include "detect-engine-address.h"
40 #include "detect-engine-port.h"
41 
42 #include "util-debug.h"
43 #include "util-byte.h"
44 #include "util-print.h"
45 #include "util-var.h"
46 
47 /* prototypes */
48 #ifdef DEBUG
49 static void DetectAddressPrint(DetectAddress *);
50 #else
51 #define DetectAddressPrint(...)
52 #endif
53 static int DetectAddressCutNot(DetectAddress *, DetectAddress **);
54 static int DetectAddressCut(DetectEngineCtx *, DetectAddress *, DetectAddress *,
55  DetectAddress **);
56 static int DetectAddressParse2(const DetectEngineCtx *de_ctx, DetectAddressHead *gh,
57  DetectAddressHead *ghn, const char *s, int negate, ResolvedVariablesList *var_list,
58  int recur);
59 
61 
62 /**
63  * \brief Creates and returns a new instance of a DetectAddress.
64  *
65  * \retval ag Pointer to the newly created DetectAddress on success;
66  * NULL on failure.
67  */
69 {
70  DetectAddress *ag = SCCalloc(1, sizeof(DetectAddress));
71  if (unlikely(ag == NULL))
72  return NULL;
73  return ag;
74 }
75 
76 /**
77  * \brief Frees a DetectAddress instance.
78  *
79  * \param ag Pointer to the DetectAddress instance to be freed.
80  */
82 {
83  if (ag == NULL)
84  return;
85 
86  SCFree(ag);
87 }
88 
89 /**
90  * \internal
91  * \brief Returns a new instance of DetectAddressHead.
92  *
93  * \retval gh Pointer to the new instance of DetectAddressHead.
94  */
95 static DetectAddressHead *DetectAddressHeadInit(void)
96 {
98  if (unlikely(gh == NULL))
99  return NULL;
100  return gh;
101 }
102 
103 /**
104  * \internal
105  * \brief Frees a DetectAddressHead instance.
106  *
107  * \param gh Pointer to the DetectAddressHead instance to be freed.
108  */
109 static void DetectAddressHeadFree(DetectAddressHead *gh)
110 {
111  if (gh != NULL) {
113  SCFree(gh);
114  }
115 }
116 
117 /**
118  * \brief copy a DetectAddress
119  *
120  * \param orig Pointer to the instance of DetectAddress that contains the
121  * address data to be copied to the new instance.
122  *
123  * \retval ag Pointer to the new instance of DetectAddress that contains the
124  * copied address.
125  */
127 {
129  if (ag == NULL)
130  return NULL;
131 
132  ag->flags = orig->flags;
133  COPY_ADDRESS(&orig->ip, &ag->ip);
134  COPY_ADDRESS(&orig->ip2, &ag->ip2);
135  return ag;
136 }
137 
138 /**
139  * \brief Frees a list of DetectAddress instances.
140  *
141  * \param head Pointer to a list of DetectAddress instances to be freed.
142  */
144 {
145  for (DetectAddress *cur = head; cur != NULL; ) {
146  DetectAddress *next = cur->next;
147  cur->next = NULL;
148  DetectAddressFree(cur);
149  cur = next;
150  }
151 }
152 
153 /**
154  * \internal
155  * \brief Helper function for DetectAddressInsert. Sets one of the
156  * DetectAddressHead head pointers, to the DetectAddress argument
157  * based on its address family.
158  *
159  * \param gh Pointer to the DetectAddressHead.
160  * \param newhead Pointer to the DetectAddress.
161  *
162  * \retval 0 On success.
163  * \retval -1 On failure.
164  */
165 static int SetHeadPtr(DetectAddressHead *gh, DetectAddress *newhead)
166 {
167  if (newhead->ip.family == AF_INET) {
168  gh->ipv4_head = newhead;
169  } else if (newhead->ip.family == AF_INET6) {
170  gh->ipv6_head = newhead;
171  } else {
172  SCLogDebug("newhead->family %u not supported", newhead->ip.family);
173  return -1;
174  }
175 
176  return 0;
177 }
178 
179 /**
180  * \internal
181  * \brief Returns the DetectAddress head from the DetectAddressHeads,
182  * based on the address family of the incoming DetectAddress arg.
183  *
184  * \param gh Pointer to the DetectAddressHead.
185  * \param new Pointer to the DetectAddress.
186  *
187  * \retval head Pointer to the DetectAddress(the head from
188  * DetectAddressHead).
189  */
190 static DetectAddress *GetHeadPtr(DetectAddressHead *gh, DetectAddress *new)
191 {
192  DetectAddress *head = NULL;
193 
194  if (new->ip.family == AF_INET)
195  head = gh->ipv4_head;
196  else if (new->ip.family == AF_INET6)
197  head = gh->ipv6_head;
198 
199  return head;
200 }
201 
202 /**
203  * \internal
204  * \brief insert DetectAddress into a DetectAddressHead
205  *
206  * \param de_ctx Pointer to the detection engine context.
207  * \param gh Pointer to the DetectAddressHead list to which it has to
208  * be inserted.
209  * \param new Pointer to the DetectAddress, that has to be inserted.
210  *
211  * \retval 1 On successfully inserting it.
212  * \retval -1 On error.
213  * \retval 0 Not inserted, memory of new is freed.
214  */
215 static int DetectAddressInsert(DetectEngineCtx *de_ctx, DetectAddressHead *gh,
216  DetectAddress *new)
217 {
218  DetectAddress *head = NULL;
219  DetectAddress *cur = NULL;
220  DetectAddress *c = NULL;
221  int r = 0;
222 
223  if (new == NULL)
224  return 0;
225 
226  /* get our head ptr based on the address we want to insert */
227  head = GetHeadPtr(gh, new);
228 
229  /* see if it already exists or overlaps with existing ag's */
230  if (head != NULL) {
231  cur = NULL;
232 
233  for (cur = head; cur != NULL; cur = cur->next) {
234  r = DetectAddressCmp(new, cur);
235  BUG_ON(r == ADDRESS_ER);
236 
237  /* if so, handle that */
238  if (r == ADDRESS_EQ) {
239  /* exact overlap/match */
240  if (cur != new) {
241  DetectAddressFree(new);
242  return 0;
243  }
244 
245  return 1;
246  } else if (r == ADDRESS_GT) {
247  /* only add it now if we are bigger than the last group.
248  * Otherwise we'll handle it later. */
249  if (cur->next == NULL) {
250  /* put in the list */
251  new->prev = cur;
252  cur->next = new;
253 
254  return 1;
255  }
256  } else if (r == ADDRESS_LT) {
257  /* see if we need to insert the ag anywhere put in the list */
258  if (cur->prev != NULL)
259  cur->prev->next = new;
260  new->prev = cur->prev;
261  new->next = cur;
262  cur->prev = new;
263 
264  /* update head if required */
265  if (head == cur) {
266  head = new;
267 
268  if (SetHeadPtr(gh, head) < 0)
269  goto error;
270  }
271 
272  return 1;
273  /* alright, those were the simple cases, lets handle the more
274  * complex ones now */
275  } else if (r == ADDRESS_ES) {
276  c = NULL;
277  r = DetectAddressCut(de_ctx, cur, new, &c);
278  if (r == -1)
279  goto error;
280 
281  DetectAddressInsert(de_ctx, gh, new);
282  if (c != NULL)
283  DetectAddressInsert(de_ctx, gh, c);
284 
285  return 1;
286  } else if (r == ADDRESS_EB) {
287  c = NULL;
288  r = DetectAddressCut(de_ctx, cur, new, &c);
289  if (r == -1)
290  goto error;
291 
292  DetectAddressInsert(de_ctx, gh, new);
293  if (c != NULL)
294  DetectAddressInsert(de_ctx, gh, c);
295 
296  return 1;
297  } else if (r == ADDRESS_LE) {
298  c = NULL;
299  r = DetectAddressCut(de_ctx, cur, new, &c);
300  if (r == -1)
301  goto error;
302 
303  DetectAddressInsert(de_ctx, gh, new);
304  if (c != NULL)
305  DetectAddressInsert(de_ctx, gh, c);
306 
307  return 1;
308  } else if (r == ADDRESS_GE) {
309  c = NULL;
310  r = DetectAddressCut(de_ctx, cur,new,&c);
311  if (r == -1)
312  goto error;
313 
314  DetectAddressInsert(de_ctx, gh, new);
315  if (c != NULL)
316  DetectAddressInsert(de_ctx, gh, c);
317 
318  return 1;
319  }
320  }
321 
322  /* head is NULL, so get a group and set head to it */
323  } else {
324  head = new;
325  if (SetHeadPtr(gh, head) < 0) {
326  SCLogDebug("SetHeadPtr failed");
327  goto error;
328  }
329  }
330 
331  return 1;
332 
333 error:
334  /* XXX */
335  return -1;
336 }
337 
338 /**
339  * \brief Checks if two address group lists are equal.
340  *
341  * \param list1 Pointer to the first address group list.
342  * \param list2 Pointer to the second address group list.
343  *
344  * \retval true On success.
345  * \retval false On failure.
346  */
348 {
349  DetectAddress *item = list1;
350  DetectAddress *it = list2;
351 
352  // First, compare items one by one.
353  while (item != NULL && it != NULL) {
354  if (DetectAddressCmp(item, it) != ADDRESS_EQ) {
355  return false;
356  }
357 
358  item = item->next;
359  it = it->next;
360  }
361 
362  // Are the lists of the same size?
363  return item == NULL && it == NULL;
364 }
365 
366 /**
367  * \internal
368  * \brief Parses an ipv4/ipv6 address string and updates the result into the
369  * DetectAddress instance sent as the argument.
370  *
371  * \param dd Pointer to the DetectAddress instance which should be updated with
372  * the address range details from the parsed ip string.
373  * \param str Pointer to address string that has to be parsed.
374  *
375  * \retval 0 On successfully parsing the address string.
376  * \retval -1 On failure.
377  */
378 static int DetectAddressParseString(DetectAddress *dd, const char *str)
379 {
380  char *ip = NULL;
381  char *ip2 = NULL;
382  char *mask = NULL;
383  int r = 0;
384  char ipstr[256];
385 
386  /* shouldn't see 'any' here */
387  BUG_ON(strcasecmp(str, "any") == 0);
388 
389  strlcpy(ipstr, str, sizeof(ipstr));
390  SCLogDebug("str %s", str);
391 
392  /* we work with a copy so that we can put a
393  * nul-termination in it later */
394  ip = ipstr;
395 
396  /* handle the negation case */
397  if (ip[0] == '!') {
398  dd->flags |= ADDRESS_FLAG_NOT;
399  ip++;
400  }
401 
402  /* see if the address is an ipv4 or ipv6 address */
403  if ((strchr(str, ':')) == NULL) {
404  /* IPv4 Address */
405  struct in_addr in;
406 
407  dd->ip.family = AF_INET;
408 
409  if ((mask = strchr(ip, '/')) != NULL) {
410  /* 1.2.3.4/xxx format (either dotted or cidr notation */
411  ip[mask - ip] = '\0';
412  mask++;
413  uint32_t ip4addr = 0;
414  uint32_t netmask = 0;
415 
416  if ((strchr (mask, '.')) == NULL) {
417  /* 1.2.3.4/24 format */
418 
419  for (size_t u = 0; u < strlen(mask); u++) {
420  if(!isdigit((unsigned char)mask[u]))
421  goto error;
422  }
423 
424  int cidr;
425  if (StringParseI32RangeCheck(&cidr, 10, 0, (const char *)mask, 0, 32) < 0)
426  goto error;
427  netmask = CIDRGet(cidr);
428  } else {
429  /* 1.2.3.4/255.255.255.0 format */
430  r = inet_pton(AF_INET, mask, &in);
431  if (r <= 0)
432  goto error;
433 
434  netmask = in.s_addr;
435 
436  /* validate netmask */
437  int cidr = CIDRFromMask(netmask);
438  if (cidr < 0) {
439  SCLogError(
440  "netmask \"%s\" is not usable. Only netmasks that are compatible with "
441  "CIDR notation are supported. See ticket #5168.",
442  mask);
443  goto error;
444  }
445  }
446 
447  r = inet_pton(AF_INET, ip, &in);
448  if (r <= 0)
449  goto error;
450 
451  ip4addr = in.s_addr;
452 
453  dd->ip.addr_data32[0] = dd->ip2.addr_data32[0] = ip4addr & netmask;
454  dd->ip2.addr_data32[0] |=~ netmask;
455  } else if ((ip2 = strchr(ip, '-')) != NULL) {
456  /* 1.2.3.4-1.2.3.6 range format */
457  ip[ip2 - ip] = '\0';
458  ip2++;
459 
460  r = inet_pton(AF_INET, ip, &in);
461  if (r <= 0)
462  goto error;
463  dd->ip.addr_data32[0] = in.s_addr;
464 
465  r = inet_pton(AF_INET, ip2, &in);
466  if (r <= 0)
467  goto error;
468  dd->ip2.addr_data32[0] = in.s_addr;
469 
470  /* a > b is illegal, a = b is ok */
471  if (SCNtohl(dd->ip.addr_data32[0]) > SCNtohl(dd->ip2.addr_data32[0]))
472  goto error;
473  } else {
474  /* 1.2.3.4 format */
475  r = inet_pton(AF_INET, ip, &in);
476  if (r <= 0)
477  goto error;
478  /* single host */
479  dd->ip.addr_data32[0] = in.s_addr;
480  dd->ip2.addr_data32[0] = in.s_addr;
481  }
482  } else {
483  /* IPv6 Address */
484  struct in6_addr in6, mask6;
485  uint32_t ip6addr[4], netmask[4];
486 
487  dd->ip.family = AF_INET6;
488 
489  if ((mask = strchr(ip, '/')) != NULL) {
490  ip[mask - ip] = '\0';
491  mask++;
492 
493  int cidr;
494  if (StringParseI32RangeCheck(&cidr, 10, 0, (const char *)mask, 0, 128) < 0)
495  goto error;
496 
497  r = inet_pton(AF_INET6, ip, &in6);
498  if (r <= 0)
499  goto error;
500  memcpy(&ip6addr, &in6.s6_addr, sizeof(ip6addr));
501 
502  CIDRGetIPv6(cidr, &mask6);
503  memcpy(&netmask, &mask6.s6_addr, sizeof(netmask));
504 
505  dd->ip2.addr_data32[0] = dd->ip.addr_data32[0] = ip6addr[0] & netmask[0];
506  dd->ip2.addr_data32[1] = dd->ip.addr_data32[1] = ip6addr[1] & netmask[1];
507  dd->ip2.addr_data32[2] = dd->ip.addr_data32[2] = ip6addr[2] & netmask[2];
508  dd->ip2.addr_data32[3] = dd->ip.addr_data32[3] = ip6addr[3] & netmask[3];
509 
510  dd->ip2.addr_data32[0] |=~ netmask[0];
511  dd->ip2.addr_data32[1] |=~ netmask[1];
512  dd->ip2.addr_data32[2] |=~ netmask[2];
513  dd->ip2.addr_data32[3] |=~ netmask[3];
514  } else if ((ip2 = strchr(ip, '-')) != NULL) {
515  dd->flags |= ADDRESS_FLAG_RANGE;
516  /* 2001::1-2001::4 range format */
517  ip[ip2 - ip] = '\0';
518  ip2++;
519 
520  r = inet_pton(AF_INET6, ip, &in6);
521  if (r <= 0)
522  goto error;
523  memcpy(&dd->ip.address, &in6.s6_addr, sizeof(ip6addr));
524 
525  r = inet_pton(AF_INET6, ip2, &in6);
526  if (r <= 0)
527  goto error;
528  memcpy(&dd->ip2.address, &in6.s6_addr, sizeof(ip6addr));
529 
530  /* a > b is illegal, a=b is ok */
531  if (AddressIPv6Gt(&dd->ip, &dd->ip2))
532  goto error;
533  } else {
534  r = inet_pton(AF_INET6, ip, &in6);
535  if (r <= 0)
536  goto error;
537 
538  memcpy(&dd->ip.address, &in6.s6_addr, sizeof(dd->ip.address));
539  memcpy(&dd->ip2.address, &in6.s6_addr, sizeof(dd->ip2.address));
540  }
541 
542  }
543 
544  BUG_ON(dd->ip.family == 0);
545 
546  return 0;
547 
548 error:
549  return -1;
550 }
551 
552 /**
553  * \internal
554  * \brief Simply parse an address and return a DetectAddress instance containing
555  * the address ranges of the parsed ip addressstring
556  *
557  * \param str Pointer to a character string containing the ip address
558  *
559  * \retval dd Pointer to the DetectAddress instance containing the address
560  * range details from the parsed ip string
561  */
562 static DetectAddress *DetectAddressParseSingle(const char *str)
563 {
564  SCLogDebug("str %s", str);
565 
567  if (dd == NULL)
568  return NULL;
569 
570  if (DetectAddressParseString(dd, str) < 0) {
571  SCLogDebug("AddressParse failed");
572  DetectAddressFree(dd);
573  return NULL;
574  }
575 
576  return dd;
577 }
578 
579 /**
580  * \brief Setup a single address string, parse it and add the resulting
581  * Address-Range(s) to the AddressHead(DetectAddressHead instance).
582  *
583  * \param gh Pointer to the Address-Head(DetectAddressHead) to which the
584  * resulting Address-Range(s) from the parsed ip string has to
585  * be added.
586  * \param s Pointer to the ip address string to be parsed.
587  *
588  * \retval 0 On success.
589  * \retval -1 On failure.
590  */
591 static int DetectAddressSetup(DetectAddressHead *gh, const char *s)
592 {
593  SCLogDebug("gh %p, s %s", gh, s);
594 
595  while (*s != '\0' && isspace(*s))
596  s++;
597 
598  if (strcasecmp(s, "any") == 0) {
599  SCLogDebug("adding 0.0.0.0/0 and ::/0 as we\'re handling \'any\'");
600 
601  DetectAddress *ad = DetectAddressParseSingle("0.0.0.0/0");
602  if (ad == NULL)
603  return -1;
604 
605  BUG_ON(ad->ip.family == 0);
606 
607  if (DetectAddressInsert(NULL, gh, ad) < 0) {
608  SCLogDebug("DetectAddressInsert failed");
609  DetectAddressFree(ad);
610  return -1;
611  }
612 
613  ad = DetectAddressParseSingle("::/0");
614  if (ad == NULL)
615  return -1;
616 
617  BUG_ON(ad->ip.family == 0);
618 
619  if (DetectAddressInsert(NULL, gh, ad) < 0) {
620  SCLogDebug("DetectAddressInsert failed");
621  DetectAddressFree(ad);
622  return -1;
623  }
624  return 0;
625  }
626 
627  /* parse the address */
628  DetectAddress *ad = DetectAddressParseSingle(s);
629  if (ad == NULL) {
630  SCLogError("failed to parse address \"%s\"", s);
631  return -1;
632  }
633 
634  /* handle the not case, we apply the negation then insert the part(s) */
635  if (ad->flags & ADDRESS_FLAG_NOT) {
636  DetectAddress *ad2 = NULL;
637 
638  if (DetectAddressCutNot(ad, &ad2) < 0) {
639  SCLogDebug("DetectAddressCutNot failed");
640  DetectAddressFree(ad);
641  return -1;
642  }
643 
644  /* normally a 'not' will result in two ad's unless the 'not' is on the start or end
645  * of the address space (e.g. 0.0.0.0 or 255.255.255.255). */
646  if (ad2 != NULL) {
647  if (DetectAddressInsert(NULL, gh, ad2) < 0) {
648  SCLogDebug("DetectAddressInsert failed");
649  DetectAddressFree(ad);
650  DetectAddressFree(ad2);
651  return -1;
652  }
653  }
654  }
655  if (ad->flags & ADDRESS_FLAG_RANGE) {
656  gh->contains_range = true;
657  }
658 
659  int r = DetectAddressInsert(NULL, gh, ad);
660  if (r < 0) {
661  SCLogDebug("DetectAddressInsert failed");
662  DetectAddressFree(ad);
663  return -1;
664  }
665  SCLogDebug("r %d",r);
666  return 0;
667 }
668 
669 /**
670  * \brief Parses an address string and updates the 2 address heads with the
671  * address data.
672  *
673  * Note that this function should only be called by the wrapping function
674  * DetectAddressParse2. The wrapping function provides long address handling
675  * when the address size exceeds a threshold value.
676  *
677  * \todo We don't seem to be handling negated cases, like [addr,![!addr,addr]],
678  * since we pass around negate without keeping a count of ! with depth.
679  * Can solve this by keeping a count of the negations with depth, so that
680  * an even no of negations would count as no negation and an odd no of
681  * negations would count as a negation.
682  *
683  * \param gh Pointer to the address head that should hold address ranges
684  * that are not negated.
685  * \param ghn Pointer to the address head that should hold address ranges
686  * that are negated.
687  * \param s Pointer to the character string holding the address to be
688  * parsed.
689  * \param negate Flag that indicates if the received address string is negated
690  * or not. 0 if it is not, 1 it it is.
691  *
692  * \retval 0 On successfully parsing.
693  * \retval -1 On failure.
694  */
695 static int DetectAddressParseInternal(const DetectEngineCtx *de_ctx, DetectAddressHead *gh,
696  DetectAddressHead *ghn, const char *s, int negate, ResolvedVariablesList *var_list,
697  int recur, char *address, size_t address_length)
698 {
699  size_t x = 0;
700  size_t u = 0;
701  int o_set = 0, n_set = 0, d_set = 0;
702  int depth = 0;
703  const char *rule_var_address = NULL;
704  char *temp_rule_var_address = NULL;
705 
706  if (++recur > 64) {
707  SCLogError("address block recursion "
708  "limit reached (max 64)");
709  goto error;
710  }
711 
712  SCLogDebug("s %s negate %s", s, negate ? "true" : "false");
713 
714  size_t size = strlen(s);
715  for (u = 0, x = 0; u < size && x < address_length; u++) {
716  if (x == (address_length - 1)) {
717  SCLogError("Hit the address buffer"
718  " limit for the supplied address. Invalidating sig. "
719  "Please file a bug report on this.");
720  goto error;
721  }
722  address[x] = s[u];
723  x++;
724 
725  if (!o_set && s[u] == '!') {
726  n_set = 1;
727  x--;
728  } else if (s[u] == '[') {
729  if (!o_set) {
730  o_set = 1;
731  x = 0;
732  }
733  depth++;
734  } else if (s[u] == ']') {
735  if (depth == 1) {
736  address[x - 1] = '\0';
737  x = 0;
738  SCLogDebug("address %s negate %d, n_set %d", address, negate, n_set);
739  if (((negate + n_set) % 2) == 0) {
740  /* normal block */
741  SCLogDebug("normal block");
742 
743  if (DetectAddressParse2(de_ctx, gh, ghn, address, (negate + n_set) % 2, var_list, recur) < 0)
744  goto error;
745  } else {
746  /* negated block
747  *
748  * Extra steps are necessary. First consider it as a normal
749  * (non-negated) range. Merge the + and - ranges if
750  * applicable. Then insert the result into the ghn list. */
751  SCLogDebug("negated block");
752 
753  DetectAddressHead tmp_gh = { NULL, NULL, false };
754  DetectAddressHead tmp_ghn = { NULL, NULL, false };
755 
756  if (DetectAddressParse2(de_ctx, &tmp_gh, &tmp_ghn, address, 0, var_list, recur) < 0) {
757  DetectAddressHeadCleanup(&tmp_gh);
758  DetectAddressHeadCleanup(&tmp_ghn);
759  goto error;
760  }
761 
762  DetectAddress *tmp_ad;
763  DetectAddress *tmp_ad2;
764 #ifdef DEBUG
765  SCLogDebug("tmp_gh: IPv4");
766  for (tmp_ad = tmp_gh.ipv4_head; tmp_ad; tmp_ad = tmp_ad->next) {
767  DetectAddressPrint(tmp_ad);
768  }
769  SCLogDebug("tmp_ghn: IPv4");
770  for (tmp_ad = tmp_ghn.ipv4_head; tmp_ad; tmp_ad = tmp_ad->next) {
771  DetectAddressPrint(tmp_ad);
772  }
773  SCLogDebug("tmp_gh: IPv6");
774  for (tmp_ad = tmp_gh.ipv6_head; tmp_ad; tmp_ad = tmp_ad->next) {
775  DetectAddressPrint(tmp_ad);
776  }
777  SCLogDebug("tmp_ghn: IPv6");
778  for (tmp_ad = tmp_ghn.ipv6_head; tmp_ad; tmp_ad = tmp_ad->next) {
779  DetectAddressPrint(tmp_ad);
780  }
781 #endif
782  if (DetectAddressMergeNot(&tmp_gh, &tmp_ghn) < 0) {
783  DetectAddressHeadCleanup(&tmp_ghn);
784  DetectAddressHeadCleanup(&tmp_gh);
785  goto error;
786  }
787  DetectAddressHeadCleanup(&tmp_ghn);
788 
789  SCLogDebug("merged successfully");
790 
791  /* insert the IPv4 addresses into the negated list */
792  for (tmp_ad = tmp_gh.ipv4_head; tmp_ad; tmp_ad = tmp_ad->next) {
793  /* work with a copy of the address group */
794  tmp_ad2 = DetectAddressCopy(tmp_ad);
795  if (tmp_ad2 == NULL) {
796  SCLogDebug("DetectAddressCopy failed");
797  DetectAddressHeadCleanup(&tmp_gh);
798  goto error;
799  }
800  DetectAddressPrint(tmp_ad2);
801  DetectAddressInsert(NULL, ghn, tmp_ad2);
802  }
803 
804  /* insert the IPv6 addresses into the negated list */
805  for (tmp_ad = tmp_gh.ipv6_head; tmp_ad; tmp_ad = tmp_ad->next) {
806  /* work with a copy of the address group */
807  tmp_ad2 = DetectAddressCopy(tmp_ad);
808  if (tmp_ad2 == NULL) {
809  SCLogDebug("DetectAddressCopy failed");
810  DetectAddressHeadCleanup(&tmp_gh);
811  goto error;
812  }
813  DetectAddressPrint(tmp_ad2);
814  DetectAddressInsert(NULL, ghn, tmp_ad2);
815  }
816 
817  DetectAddressHeadCleanup(&tmp_gh);
818  }
819  n_set = 0;
820  }
821  depth--;
822  } else if (depth == 0 && s[u] == ',') {
823  if (o_set == 1) {
824  o_set = 0;
825  } else if (d_set == 1) {
826  address[x - 1] = '\0';
827 
828  rule_var_address = SCRuleVarsGetConfVar(de_ctx, address,
830  if (rule_var_address == NULL)
831  goto error;
832 
833  if (strlen(rule_var_address) == 0) {
834  SCLogError("variable %s resolved "
835  "to nothing. This is likely a misconfiguration. "
836  "Note that a negated address needs to be quoted, "
837  "\"!$HOME_NET\" instead of !$HOME_NET. See issue #295.",
838  s);
839  goto error;
840  }
841 
842  SCLogDebug("rule_var_address %s", rule_var_address);
843  if ((negate + n_set) % 2) {
844  /* add +1 to safisfy gcc 15 + -Wformat-truncation=2 */
845  const size_t str_size = strlen(rule_var_address) + 3 + 1;
846  temp_rule_var_address = SCMalloc(str_size);
847  if (unlikely(temp_rule_var_address == NULL))
848  goto error;
849  snprintf(temp_rule_var_address, str_size, "[%s]", rule_var_address);
850  } else {
851  temp_rule_var_address = SCStrdup(rule_var_address);
852  if (unlikely(temp_rule_var_address == NULL))
853  goto error;
854  }
855 
856  if (DetectAddressParse2(de_ctx, gh, ghn, temp_rule_var_address,
857  (negate + n_set) % 2, var_list, recur) < 0) {
858  if (temp_rule_var_address != rule_var_address)
859  SCFree(temp_rule_var_address);
860  goto error;
861  }
862  d_set = 0;
863  n_set = 0;
864  SCFree(temp_rule_var_address);
865  } else {
866  address[x - 1] = '\0';
867 
868  if (!((negate + n_set) % 2)) {
869  SCLogDebug("DetectAddressSetup into gh, %s", address);
870  if (DetectAddressSetup(gh, address) < 0)
871  goto error;
872  } else {
873  SCLogDebug("DetectAddressSetup into ghn, %s", address);
874  if (DetectAddressSetup(ghn, address) < 0)
875  goto error;
876  }
877  n_set = 0;
878  }
879  x = 0;
880  } else if (depth == 0 && s[u] == '$') {
881  d_set = 1;
882  } else if (depth == 0 && u == size - 1) {
883  if (x == address_length) {
884  address[x - 1] = '\0';
885  } else {
886  address[x] = '\0';
887  }
888  x = 0;
889 
890  if (AddVariableToResolveList(var_list, address) == -1) {
891  SCLogError("Found a loop in a address "
892  "groups declaration. This is likely a misconfiguration.");
893  goto error;
894  }
895 
896  if (d_set == 1) {
897  rule_var_address = SCRuleVarsGetConfVar(de_ctx, address,
899  if (rule_var_address == NULL)
900  goto error;
901 
902  if (strlen(rule_var_address) == 0) {
903  SCLogError("variable %s resolved "
904  "to nothing. This is likely a misconfiguration. "
905  "Note that a negated address needs to be quoted, "
906  "\"!$HOME_NET\" instead of !$HOME_NET. See issue #295.",
907  s);
908  goto error;
909  }
910 
911  SCLogDebug("rule_var_address %s", rule_var_address);
912  if ((negate + n_set) % 2) {
913  /* add +1 to safisfy gcc 15 + -Wformat-truncation=2 */
914  const size_t str_size = strlen(rule_var_address) + 3 + 1;
915  temp_rule_var_address = SCMalloc(str_size);
916  if (unlikely(temp_rule_var_address == NULL))
917  goto error;
918  snprintf(temp_rule_var_address, str_size, "[%s]", rule_var_address);
919  } else {
920  temp_rule_var_address = SCStrdup(rule_var_address);
921  if (unlikely(temp_rule_var_address == NULL))
922  goto error;
923  }
924 
925  if (DetectAddressParse2(de_ctx, gh, ghn, temp_rule_var_address,
926  (negate + n_set) % 2, var_list, recur) < 0) {
927  SCLogDebug("DetectAddressParse2 hates us");
928  if (temp_rule_var_address != rule_var_address)
929  SCFree(temp_rule_var_address);
930  goto error;
931  }
932  d_set = 0;
933  SCFree(temp_rule_var_address);
934  } else {
935  if (!((negate + n_set) % 2)) {
936  SCLogDebug("DetectAddressSetup into gh, %s", address);
937  if (DetectAddressSetup(gh, address) < 0) {
938  SCLogDebug("DetectAddressSetup gh fail");
939  goto error;
940  }
941  } else {
942  SCLogDebug("DetectAddressSetup into ghn, %s", address);
943  if (DetectAddressSetup(ghn, address) < 0) {
944  SCLogDebug("DetectAddressSetup ghn fail");
945  goto error;
946  }
947  }
948  }
949  n_set = 0;
950  }
951  }
952  if (depth > 0) {
953  SCLogError("not every address block was "
954  "properly closed in \"%s\", %d missing closing brackets (]). "
955  "Note: problem might be in a variable.",
956  s, depth);
957  goto error;
958  } else if (depth < 0) {
959  SCLogError("not every address block was "
960  "properly opened in \"%s\", %d missing opening brackets ([). "
961  "Note: problem might be in a variable.",
962  s, depth * -1);
963  goto error;
964  }
965 
966  return 0;
967 
968 error:
969 
970  return -1;
971 }
972 
973 /**
974  * \internal
975  * \brief Wrapper function for address parsing to minimize heap allocs during address parsing.
976  *
977  * \retval Return value from DetectAddressParseInternal
978  */
979 static int DetectAddressParse2(const DetectEngineCtx *de_ctx, DetectAddressHead *gh,
980  DetectAddressHead *ghn, const char *s, int negate, ResolvedVariablesList *var_list,
981  int recur)
982 {
983  int rc;
984 #define MAX_ADDRESS_LENGTH 8192
985 
986  size_t address_length = strlen(s);
987  if (address_length > (MAX_ADDRESS_LENGTH - 1)) {
988  char *address = SCCalloc(1, address_length);
989  if (address == NULL) {
990  SCLogError("Unable to allocate"
991  " memory for address parsing.");
992  return -1;
993  }
994  rc = DetectAddressParseInternal(
995  de_ctx, gh, ghn, s, negate, var_list, recur, address, address_length);
996  SCFree(address);
997  } else {
998  char address[MAX_ADDRESS_LENGTH] = "";
999  rc = DetectAddressParseInternal(
1000  de_ctx, gh, ghn, s, negate, var_list, recur, address, MAX_ADDRESS_LENGTH);
1001  }
1002  return rc;
1003 }
1004 
1005 /**
1006  * \internal
1007  * \brief See if the addresses and ranges in an address head cover the
1008  * entire ip space.
1009  *
1010  * \param gh Pointer to the DetectAddressHead to check.
1011  *
1012  * \retval 0 No.
1013  * \retval 1 Yes.
1014  *
1015  * \todo do the same for IPv6
1016  */
1017 static int DetectAddressIsCompleteIPSpace(DetectAddressHead *gh)
1018 {
1020  if (r == 1)
1021  return 1;
1022 
1023  return 0;
1024 }
1025 
1026 /**
1027  * \brief Merge the + and the - list (+ positive match, - 'not' match)
1028  *
1029  * \param gh Pointer to the address head containing the non-NOT groups.
1030  * \param ghn Pointer to the address head containing the NOT groups.
1031  *
1032  * \retval 0 On success.
1033  * \retval -1 On failure.
1034  */
1036 {
1037  DetectAddress *ad;
1038  DetectAddress *ag, *ag2;
1039  int r = 0;
1040 
1041  SCLogDebug("gh->ipv4_head %p, ghn->ipv4_head %p", gh->ipv4_head,
1042  ghn->ipv4_head);
1043 
1044  /* check if the negated list covers the entire ip space. If so
1045  * the user screwed up the rules/vars. */
1046  if (DetectAddressIsCompleteIPSpace(ghn) == 1) {
1047  SCLogError("Complete IP space negated. "
1048  "Rule address range is NIL. Probably have a !any or "
1049  "an address range that supplies a NULL address range");
1050  goto error;
1051  }
1052 
1053  /* step 0: if the gh list is empty, but the ghn list isn't we have a pure
1054  * not thingy. In that case we add a 0.0.0.0/0 first. */
1055  if (gh->ipv4_head == NULL && ghn->ipv4_head != NULL) {
1056  r = DetectAddressSetup(gh, "0.0.0.0/0");
1057  if (r < 0) {
1058  SCLogDebug("DetectAddressSetup for 0.0.0.0/0 failed");
1059  goto error;
1060  }
1061  }
1062  /* ... or ::/0 for ipv6 */
1063  if (gh->ipv6_head == NULL && ghn->ipv6_head != NULL) {
1064  r = DetectAddressSetup(gh, "::/0");
1065  if (r < 0) {
1066  SCLogDebug("DetectAddressSetup for ::/0 failed");
1067  goto error;
1068  }
1069  }
1070 
1071  /* step 1: insert our ghn members into the gh list */
1072  for (ag = ghn->ipv4_head; ag != NULL; ag = ag->next) {
1073  /* work with a copy of the ad so we can easily clean up the ghn group
1074  * later. */
1075  ad = DetectAddressCopy(ag);
1076  if (ad == NULL) {
1077  SCLogDebug("DetectAddressCopy failed");
1078  goto error;
1079  }
1080 
1081  r = DetectAddressInsert(NULL, gh, ad);
1082  if (r < 0) {
1083  SCLogDebug("DetectAddressInsert failed");
1084  goto error;
1085  }
1086  }
1087  /* ... and the same for ipv6 */
1088  for (ag = ghn->ipv6_head; ag != NULL; ag = ag->next) {
1089  /* work with a copy of the ad so we can easily clean up the ghn group
1090  * later. */
1091  ad = DetectAddressCopy(ag);
1092  if (ad == NULL) {
1093  SCLogDebug("DetectAddressCopy failed");
1094  goto error;
1095  }
1096 
1097  r = DetectAddressInsert(NULL, gh, ad);
1098  if (r < 0) {
1099  SCLogDebug("DetectAddressInsert failed");
1100  goto error;
1101  }
1102  }
1103 #ifdef DEBUG
1104  DetectAddress *tmp_ad;
1105  for (tmp_ad = gh->ipv6_head; tmp_ad; tmp_ad = tmp_ad->next) {
1106  DetectAddressPrint(tmp_ad);
1107  }
1108 #endif
1109  int ipv4_applied = 0;
1110  int ipv6_applied = 0;
1111 
1112  /* step 2: pull the address blocks that match our 'not' blocks */
1113  for (ag = ghn->ipv4_head; ag != NULL; ag = ag->next) {
1114  SCLogDebug("ag %p", ag);
1115  DetectAddressPrint(ag);
1116 
1117  int applied = 0;
1118  for (ag2 = gh->ipv4_head; ag2 != NULL; ) {
1119  SCLogDebug("ag2 %p", ag2);
1120  DetectAddressPrint(ag2);
1121 
1122  r = DetectAddressCmp(ag, ag2);
1123  /* XXX more ??? */
1124  if (r == ADDRESS_EQ || r == ADDRESS_EB) {
1125  if (ag2->prev != NULL)
1126  ag2->prev->next = ag2->next;
1127  if (ag2->next != NULL)
1128  ag2->next->prev = ag2->prev;
1129  if (gh->ipv4_head == ag2)
1130  gh->ipv4_head = ag2->next;
1131  /* store the next ptr and remove the group */
1132  DetectAddress *next_ag2 = ag2->next;
1133  DetectAddressFree(ag2);
1134  ag2 = next_ag2;
1135  applied = 1;
1136  } else {
1137  ag2 = ag2->next;
1138  }
1139  }
1140 
1141  if (applied) {
1142  ipv4_applied++;
1143  }
1144  }
1145  /* ... and the same for ipv6 */
1146  for (ag = ghn->ipv6_head; ag != NULL; ag = ag->next) {
1147  int applied = 0;
1148  for (ag2 = gh->ipv6_head; ag2 != NULL; ) {
1149  r = DetectAddressCmp(ag, ag2);
1150  if (r == ADDRESS_EQ || r == ADDRESS_EB) { /* XXX more ??? */
1151  if (ag2->prev != NULL)
1152  ag2->prev->next = ag2->next;
1153  if (ag2->next != NULL)
1154  ag2->next->prev = ag2->prev;
1155  if (gh->ipv6_head == ag2)
1156  gh->ipv6_head = ag2->next;
1157  /* store the next ptr and remove the group */
1158  DetectAddress *next_ag2 = ag2->next;
1159  DetectAddressFree(ag2);
1160  ag2 = next_ag2;
1161 
1162  SCLogDebug("applied");
1163  applied = 1;
1164  } else {
1165  ag2 = ag2->next;
1166  }
1167  }
1168  if (applied) {
1169  ipv6_applied++;
1170  }
1171  }
1172 #ifdef DEBUG
1173  for (tmp_ad = gh->ipv6_head; tmp_ad; tmp_ad = tmp_ad->next) {
1174  DetectAddressPrint(tmp_ad);
1175  }
1176  for (tmp_ad = ghn->ipv6_head; tmp_ad; tmp_ad = tmp_ad->next) {
1177  DetectAddressPrint(tmp_ad);
1178  }
1179 #endif
1180  if (ghn->ipv4_head != NULL || ghn->ipv6_head != NULL) {
1181  int cnt = 0;
1182  for (ad = ghn->ipv4_head; ad; ad = ad->next)
1183  cnt++;
1184 
1185  if (ipv4_applied != cnt) {
1186  SCLogError("not all IPv4 negations "
1187  "could be applied: %d != %d",
1188  cnt, ipv4_applied);
1189  goto error;
1190  }
1191 
1192  cnt = 0;
1193  for (ad = ghn->ipv6_head; ad; ad = ad->next)
1194  cnt++;
1195 
1196  if (ipv6_applied != cnt) {
1197  SCLogError("not all IPv6 negations "
1198  "could be applied: %d != %d",
1199  cnt, ipv6_applied);
1200  goto error;
1201  }
1202  }
1203 
1204  /* if the result is that we have no addresses we return error */
1205  if (gh->ipv4_head == NULL && gh->ipv6_head == NULL) {
1206  SCLogError("no addresses left after "
1207  "merging addresses and negated addresses");
1208  goto error;
1209  }
1210 
1211  return 0;
1212 
1213 error:
1214  return -1;
1215 }
1216 
1218 {
1219  SCLogDebug("Testing address conf vars for any misconfigured values");
1220 
1221  ResolvedVariablesList var_list;
1222  TAILQ_INIT(&var_list);
1223 
1224  SCConfNode *address_vars_node = SCConfGetNode("vars.address-groups");
1225  if (address_vars_node == NULL) {
1226  return 0;
1227  }
1228 
1229  DetectAddressHead *gh = NULL;
1230  DetectAddressHead *ghn = NULL;
1231 
1232  SCConfNode *seq_node;
1233  TAILQ_FOREACH(seq_node, &address_vars_node->head, next) {
1234  SCLogDebug("Testing %s - %s", seq_node->name, seq_node->val);
1235 
1236  gh = DetectAddressHeadInit();
1237  if (gh == NULL) {
1238  goto error;
1239  }
1240  ghn = DetectAddressHeadInit();
1241  if (ghn == NULL) {
1242  goto error;
1243  }
1244 
1245  if (seq_node->val == NULL) {
1246  SCLogError("Address var \"%s\" probably has a sequence(something "
1247  "in brackets) value set without any quotes. Please "
1248  "quote it using \"..\".",
1249  seq_node->name);
1250  goto error;
1251  }
1252 
1253  int r = DetectAddressParse2(
1254  NULL, gh, ghn, seq_node->val, /* start with negate no */ 0, &var_list, 0);
1255 
1256  CleanVariableResolveList(&var_list);
1257 
1258  if (r < 0) {
1259  SCLogError("failed to parse address var \"%s\" with value \"%s\". "
1260  "Please check its syntax",
1261  seq_node->name, seq_node->val);
1262  goto error;
1263  }
1264 
1265  if (DetectAddressIsCompleteIPSpace(ghn)) {
1266  SCLogError("address var - \"%s\" has the complete IP space negated "
1267  "with its value \"%s\". Rule address range is NIL. "
1268  "Probably have a !any or an address range that supplies "
1269  "a NULL address range",
1270  seq_node->name, seq_node->val);
1271  goto error;
1272  }
1273 
1274  DetectAddressHeadFree(gh);
1275  DetectAddressHeadFree(ghn);
1276  ghn = NULL;
1277  }
1278 
1279  return 0;
1280  error:
1281  if (gh != NULL)
1282  DetectAddressHeadFree(gh);
1283  if (ghn != NULL)
1284  DetectAddressHeadFree(ghn);
1285  return -1;
1286 }
1287 
1288 #include "util-hash-lookup3.h"
1289 
1290 typedef struct DetectAddressMap_ {
1291  char *string;
1296 
1297 static uint32_t DetectAddressMapHashFunc(HashListTable *ht, void *data, uint16_t datalen)
1298 {
1299  const DetectAddressMap *map = (DetectAddressMap *)data;
1300  uint32_t hash = 0;
1301 
1302  hash = hashlittle_safe(map->string, strlen(map->string), 0);
1303  hash %= ht->array_size;
1304 
1305  return hash;
1306 }
1307 
1308 static char DetectAddressMapCompareFunc(void *data1, uint16_t len1, void *data2,
1309  uint16_t len2)
1310 {
1311  DetectAddressMap *map1 = (DetectAddressMap *)data1;
1312  DetectAddressMap *map2 = (DetectAddressMap *)data2;
1313 
1314  char r = (strcmp(map1->string, map2->string) == 0);
1315  return r;
1316 }
1317 
1318 static void DetectAddressMapFreeFunc(void *data)
1319 {
1320  DetectAddressMap *map = (DetectAddressMap *)data;
1321  if (map != NULL) {
1322  DetectAddressHeadFree(map->address);
1323  SCFree(map->string);
1324  }
1325  SCFree(map);
1326 }
1327 
1329 {
1330  de_ctx->address_table = HashListTableInit(4096, DetectAddressMapHashFunc,
1331  DetectAddressMapCompareFunc,
1332  DetectAddressMapFreeFunc);
1333  if (de_ctx->address_table == NULL)
1334  return -1;
1335 
1336  return 0;
1337 }
1338 
1340 {
1341  if (de_ctx->address_table == NULL)
1342  return;
1343 
1345  de_ctx->address_table = NULL;
1346 }
1347 
1348 static bool DetectAddressMapAdd(DetectEngineCtx *de_ctx, const char *string,
1349  DetectAddressHead *address, bool contains_negation, bool contains_range)
1350 {
1351  DetectAddressMap *map = SCCalloc(1, sizeof(*map));
1352  if (map == NULL)
1353  return false;
1354 
1355  map->string = SCStrdup(string);
1356  if (map->string == NULL) {
1357  SCFree(map);
1358  return false;
1359  }
1360  map->address = address;
1361  map->contains_negation = contains_negation;
1362  map->contains_range = contains_range;
1363 
1364  if (HashListTableAdd(de_ctx->address_table, map, 0) != 0) {
1365  SCFree(map->string);
1366  SCFree(map);
1367  return false;
1368  }
1369 
1370  return true;
1371 }
1372 
1373 static const DetectAddressMap *DetectAddressMapLookup(DetectEngineCtx *de_ctx,
1374  const char *string)
1375 {
1376  DetectAddressMap map = { (char *)string, NULL, false, false };
1377 
1379  &map, 0);
1380  return res;
1381 }
1382 
1383 /**
1384  * \brief Parses an address group sent as a character string and updates the
1385  * DetectAddressHead sent as the argument with the relevant address
1386  * ranges from the parsed string.
1387  *
1388  * \param de_ctx Pointer to the detection engine context
1389  * \param gh Pointer to the DetectAddressHead.
1390  * \param str Pointer to the character string containing the address group
1391  * that has to be parsed.
1392  *
1393  * \retval 1 On success. Contained negation.
1394  * \retval 0 On success. Did not contain negation.
1395  * \retval -1 On failure.
1396  */
1398  const DetectEngineCtx *de_ctx, DetectAddressHead *gh, const char *str, bool *contains_range)
1399 {
1400  SCLogDebug("gh %p, str %s", gh, str);
1401 
1402  if (str == NULL) {
1403  SCLogDebug("DetectAddressParse can not be run with NULL address");
1404  return -1;
1405  }
1406 
1407  DetectAddressHead *ghn = DetectAddressHeadInit();
1408  if (ghn == NULL) {
1409  SCLogDebug("DetectAddressHeadInit for ghn failed");
1410  return -1;
1411  }
1412 
1413  int r = DetectAddressParse2(de_ctx, gh, ghn, str, /* start with negate no */ 0, NULL, 0);
1414  if (r < 0) {
1415  SCLogDebug("DetectAddressParse2 returned %d", r);
1416  DetectAddressHeadFree(ghn);
1417  return -1;
1418  }
1419 
1420  SCLogDebug("gh->ipv4_head %p, ghn->ipv4_head %p", gh->ipv4_head,
1421  ghn->ipv4_head);
1422 
1423  bool contains_negation = (ghn->ipv4_head != NULL || ghn->ipv6_head != NULL);
1424  if (contains_range != NULL) {
1425  *contains_range = (gh->contains_range == true || ghn->contains_range == true);
1426  }
1427 
1428  /* merge the 'not' address groups */
1429  if (DetectAddressMergeNot(gh, ghn) < 0) {
1430  SCLogDebug("DetectAddressMergeNot failed");
1431  DetectAddressHeadFree(ghn);
1432  return -1;
1433  }
1434 
1435  /* free the temp negate head */
1436  DetectAddressHeadFree(ghn);
1437  return contains_negation ? 1 : 0;
1438 }
1439 
1441  DetectEngineCtx *de_ctx, const char *string, bool *contains_negation, bool *contains_range)
1442 {
1443  DEBUG_VALIDATE_BUG_ON(contains_range == NULL);
1444  if (contains_range == NULL) {
1445  SCLogError("contain_range should not be NULL");
1446  return NULL;
1447  }
1448 
1449  const DetectAddressMap *res = DetectAddressMapLookup(de_ctx, string);
1450  if (res != NULL) {
1451  SCLogDebug("found: %s :: %p", string, res);
1452  *contains_negation = res->contains_negation;
1453  *contains_range = res->contains_range;
1454  return res->address;
1455  }
1456 
1457  SCLogDebug("%s not found", string);
1458 
1459  DetectAddressHead *head = DetectAddressHeadInit();
1460  if (head == NULL)
1461  return NULL;
1462 
1463  const int r = DetectAddressParse(de_ctx, head, string, contains_range);
1464  if (r < 0) {
1465  DetectAddressHeadFree(head);
1466  return NULL;
1467  } else if (r == 1) {
1468  *contains_negation = true;
1469  } else {
1470  *contains_negation = false;
1471  }
1472 
1473  if (!DetectAddressMapAdd(
1474  (DetectEngineCtx *)de_ctx, string, head, *contains_negation, *contains_range)) {
1475  DetectAddressHeadFree(head);
1476  return NULL;
1477  }
1478 
1479  return head;
1480 }
1481 
1482 /**
1483  * \brief Cleans a DetectAddressHead. The functions frees the address
1484  * group heads(ipv4 and ipv6) inside the DetectAddressHead
1485  * instance.
1486  *
1487  * \param gh Pointer to the DetectAddressHead instance that has to be
1488  * cleaned.
1489  */
1491 {
1492  if (gh != NULL) {
1493  if (gh->ipv4_head != NULL) {
1495  gh->ipv4_head = NULL;
1496  }
1497  if (gh->ipv6_head != NULL) {
1499  gh->ipv6_head = NULL;
1500  }
1501  }
1502 }
1503 
1504 /**
1505  * \brief Dispatcher function that calls the ipv4 and ipv6 address cut functions.
1506  * Have a look at DetectAddressCutIPv4() and DetectAddressCutIPv6() for
1507  * explanations on what these functions do.
1508  *
1509  * \param de_ctx Pointer to the DetectEngineCtx.
1510  * \param a Pointer to the first address to be cut.
1511  * \param b Pointer to the second address to be cut.
1512  * \param c Pointer to a pointer to a third DetectAddressData, in case the
1513  * ranges from a and b, demand a third address range.
1514  *
1515  * \retval 0 On success.
1516  * \retval -1 On failure.
1517  */
1518 int DetectAddressCut(DetectEngineCtx *de_ctx, DetectAddress *a,
1519  DetectAddress *b, DetectAddress **c)
1520 {
1521  if (a->ip.family == AF_INET)
1522  return DetectAddressCutIPv4(de_ctx, a, b, c);
1523  else if (a->ip.family == AF_INET6)
1524  return DetectAddressCutIPv6(de_ctx, a, b, c);
1525 
1526  return -1;
1527 }
1528 
1529 /**
1530  * \brief Cuts a negated address range with respect to the entire ip range, and
1531  * supplies with the address range that doesn't belong to the negated
1532  * address range.
1533  *
1534  * There are 2 cases here -
1535  *
1536  * The first case includes the address being located at the extreme ends
1537  * of the ip space, in which we get a single range.
1538  * For example: !0.0.0.0, in which case we get 0.0.0.1 to 255.255.255.255.
1539  *
1540  * The second case includes the address not present at either of the
1541  * ip space extremes, in which case we get 2 ranges. The second range
1542  * would be supplied back with the argument "b" supplied to this function.
1543  * For example: !10.20.30.40, in which case we the 2 ranges, 0.0.0.0 -
1544  * 10.20.30.39 and 10.20.30.41 - 255.255.255.255.
1545  *
1546  * The above negation cases can similarly be extended to ranges, i.e.
1547  * ![0.0.0.0 - 10.20.30.40], ![255.255.240.240 - 255.255.255.255] and
1548  * ![10.20.30.40 - 10.20.30.50].
1549  *
1550  *
1551  * \param a Pointer to the DetectAddressData instance, that contains the negated
1552  * address range that has to be cut.
1553  * \param b Pointer to a pointer to a DetectAddressData instance, that should be
1554  * filled with the address range, if the argument "a", doesn't fall at
1555  * the extreme ends of the ip address space.
1556  *
1557  * \retval 0 On success.
1558  * \retval -1 On failure.
1559  */
1560 int DetectAddressCutNot(DetectAddress *a, DetectAddress **b)
1561 {
1562  if (a->ip.family == AF_INET)
1563  return DetectAddressCutNotIPv4(a, b);
1564  else if (a->ip.family == AF_INET6)
1565  return DetectAddressCutNotIPv6(a, b);
1566 
1567  return -1;
1568 }
1569 
1570 /**
1571  * \brief Used to compare 2 address ranges.
1572  *
1573  * \param a Pointer to the first DetectAddressData to be compared.
1574  * \param b Pointer to the second DetectAddressData to be compared.
1575  */
1577 {
1578  if (a->ip.family != b->ip.family)
1579  return ADDRESS_ER;
1580 
1581  if (a->ip.family == AF_INET)
1582  return DetectAddressCmpIPv4(a, b);
1583  else if (a->ip.family == AF_INET6)
1584  return DetectAddressCmpIPv6(a, b);
1585 
1586  return ADDRESS_ER;
1587 }
1588 
1589 /**
1590  * \brief Match a packets address against a signatures addrs array
1591  *
1592  * \param addrs array of DetectMatchAddressIPv4's
1593  * \param addrs_cnt array size in members
1594  * \param a packets address
1595  *
1596  * \retval 0 no match
1597  * \retval 1 match
1598  *
1599  * \note addresses in addrs are in host order
1600  *
1601  * \todo array should be ordered, so we can break out of the loop
1602  */
1604  uint16_t addrs_cnt, const Address *a)
1605 {
1606  SCEnter();
1607 
1608  if (addrs == NULL || addrs_cnt == 0) {
1609  SCReturnInt(0);
1610  }
1611 
1612  uint32_t match_addr = SCNtohl(a->addr_data32[0]);
1613  for (uint16_t idx = 0; idx < addrs_cnt; idx++) {
1614  if (match_addr >= addrs[idx].ip && match_addr <= addrs[idx].ip2) {
1615  SCReturnInt(1);
1616  }
1617  }
1618 
1619  SCReturnInt(0);
1620 }
1621 
1622 /**
1623  * \brief Match a packets address against a signatures addrs array
1624  *
1625  * \param addrs array of DetectMatchAddressIPv6's
1626  * \param addrs_cnt array size in members
1627  * \param a packets address
1628  *
1629  * \retval 0 no match
1630  * \retval 1 match
1631  *
1632  * \note addresses in addrs are in host order
1633  *
1634  * \todo array should be ordered, so we can break out of the loop
1635  */
1637  uint16_t addrs_cnt, const Address *a)
1638 {
1639  SCEnter();
1640 
1641  if (addrs == NULL || addrs_cnt == 0) {
1642  SCReturnInt(0);
1643  }
1644 
1645  uint32_t match_addr[4];
1646  match_addr[0] = SCNtohl(a->addr_data32[0]);
1647  match_addr[1] = SCNtohl(a->addr_data32[1]);
1648  match_addr[2] = SCNtohl(a->addr_data32[2]);
1649  match_addr[3] = SCNtohl(a->addr_data32[3]);
1650 
1651  /* See if the packet address is within the range of any entry in the
1652  * signature's address match array.
1653  */
1654  for (uint16_t idx = 0; idx < addrs_cnt; idx++) {
1655  uint16_t result1 = 0, result2 = 0;
1656 
1657  /* See if packet address equals either limit. Return 1 if true. */
1658  if (0 == memcmp(match_addr, addrs[idx].ip, sizeof(match_addr))) {
1659  SCReturnInt(1);
1660  }
1661  if (0 == memcmp(match_addr, addrs[idx].ip2, sizeof(match_addr))) {
1662  SCReturnInt(1);
1663  }
1664 
1665  /* See if packet address is greater than lower limit
1666  * of the current signature address match pair.
1667  */
1668  for (int i = 0; i < 4; i++) {
1669  if (match_addr[i] > addrs[idx].ip[i]) {
1670  result1 = 1;
1671  break;
1672  }
1673  if (match_addr[i] < addrs[idx].ip[i]) {
1674  result1 = 0;
1675  break;
1676  }
1677  }
1678 
1679  /* If not greater than lower limit, try next address match entry */
1680  if (result1 == 0)
1681  continue;
1682 
1683  /* See if packet address is less than upper limit
1684  * of the current signature address match pair.
1685  */
1686  for (int i = 0; i < 4; i++) {
1687  if (match_addr[i] < addrs[idx].ip2[i]) {
1688  result2 = 1;
1689  break;
1690  }
1691  if (match_addr[i] > addrs[idx].ip2[i]) {
1692  result2 = 0;
1693  break;
1694  }
1695  }
1696 
1697  /* Return a match if packet address is between the two
1698  * signature address match limits.
1699  */
1700  if (result1 == 1 && result2 == 1)
1701  SCReturnInt(1);
1702  }
1703 
1704  SCReturnInt(0);
1705 }
1706 
1707 /**
1708  * \brief Check if a particular address(ipv4 or ipv6) matches the address
1709  * range in the DetectAddress instance.
1710  *
1711  * We basically check that the address falls in between the address
1712  * range in DetectAddress.
1713  *
1714  * \param dd Pointer to the DetectAddress instance.
1715  * \param a Pointer to an Address instance.
1716  *
1717  * \param 1 On a match.
1718  * \param 0 On no match.
1719  */
1720 static int DetectAddressMatch(DetectAddress *dd, Address *a)
1721 {
1722  SCEnter();
1723 
1724  if (dd->ip.family != a->family) {
1725  SCReturnInt(0);
1726  }
1727 
1728  //DetectAddressPrint(dd);
1729  //AddressDebugPrint(a);
1730 
1731  switch (a->family) {
1732  case AF_INET:
1733 
1734  /* XXX figure out a way to not need to do this SCNtohl if we switch to
1735  * Address inside DetectAddressData we can do uint8_t checks */
1736  if (SCNtohl(a->addr_data32[0]) >= SCNtohl(dd->ip.addr_data32[0]) &&
1737  SCNtohl(a->addr_data32[0]) <= SCNtohl(dd->ip2.addr_data32[0]))
1738  {
1739  SCReturnInt(1);
1740  } else {
1741  SCReturnInt(0);
1742  }
1743 
1744  break;
1745  case AF_INET6:
1746  if (AddressIPv6Ge(a, &dd->ip) == 1 &&
1747  AddressIPv6Le(a, &dd->ip2) == 1)
1748  {
1749  SCReturnInt(1);
1750  } else {
1751  SCReturnInt(0);
1752  }
1753 
1754  break;
1755  default:
1756  SCLogDebug("What other address type can we have :-/");
1757  break;
1758  }
1759 
1760  SCReturnInt(0);
1761 }
1762 
1763 #ifdef DEBUG
1764 /**
1765  * \brief Prints the address data held by the DetectAddress. If the address
1766  * data family is IPv4, we print the ipv4 address and mask, and
1767  * if the address data family is IPv6, we print the ipv6 address and
1768  * mask.
1769  *
1770  * \param ad Pointer to the DetectAddress instance to be printed.
1771  */
1772 static void DetectAddressPrint(DetectAddress *gr)
1773 {
1774  if (gr == NULL)
1775  return;
1776 
1777  if (gr->ip.family == AF_INET) {
1778  struct in_addr in;
1779  char ip[16], mask[16];
1780 
1781  memcpy(&in, &gr->ip.addr_data32[0], sizeof(in));
1782  PrintInet(AF_INET, &in, ip, sizeof(ip));
1783  memcpy(&in, &gr->ip2.addr_data32[0], sizeof(in));
1784  PrintInet(AF_INET, &in, mask, sizeof(mask));
1785 
1786  SCLogDebug("%s/%s", ip, mask);
1787 // printf("%s/%s", ip, mask);
1788  } else if (gr->ip.family == AF_INET6) {
1789  struct in6_addr in6;
1790  char ip[66], mask[66];
1791 
1792  memcpy(&in6, &gr->ip.addr_data32, sizeof(in6));
1793  PrintInet(AF_INET6, &in6, ip, sizeof(ip));
1794  memcpy(&in6, &gr->ip2.addr_data32, sizeof(in6));
1795  PrintInet(AF_INET6, &in6, mask, sizeof(mask));
1796 
1797  SCLogDebug("%s/%s", ip, mask);
1798 // printf("%s/%s", ip, mask);
1799  }
1800 }
1801 #endif
1802 
1803 /**
1804  * \brief Find the group matching address in a group head.
1805  *
1806  * \param gh Pointer to the address group head(DetectAddressHead instance).
1807  * \param a Pointer to an Address instance.
1808  *
1809  * \retval g On success pointer to an DetectAddress if we find a match
1810  * for the Address "a", in the DetectAddressHead "gh".
1811  */
1813 {
1814  SCEnter();
1815 
1816  DetectAddress *g = NULL;
1817 
1818  if (gh == NULL) {
1819  SCReturnPtr(NULL, "DetectAddress");
1820  }
1821 
1822  /* XXX should we really do this check every time we run this function? */
1823  if (a->family == AF_INET) {
1824  SCLogDebug("IPv4");
1825  g = gh->ipv4_head;
1826  } else if (a->family == AF_INET6) {
1827  SCLogDebug("IPv6");
1828  g = gh->ipv6_head;
1829  }
1830 
1831  for ( ; g != NULL; g = g->next) {
1832  if (DetectAddressMatch(g,a) == 1) {
1833  SCReturnPtr(g, "DetectAddress");
1834  }
1835  }
1836 
1837  SCReturnPtr(NULL, "DetectAddress");
1838 }
1839 
1840 /********************************Unittests*************************************/
1841 
1842 #ifdef UNITTESTS
1843 
1844 static bool UTHValidateDetectAddress(DetectAddress *ad, const char *one, const char *two)
1845 {
1846  char str1[46] = "", str2[46] = "";
1847 
1848  if (ad == NULL)
1849  return false;
1850 
1851  switch(ad->ip.family) {
1852  case AF_INET:
1853  PrintInet(AF_INET, (const void *)&ad->ip.addr_data32[0], str1, sizeof(str1));
1854  SCLogDebug("%s", str1);
1855  PrintInet(AF_INET, (const void *)&ad->ip2.addr_data32[0], str2, sizeof(str2));
1856  SCLogDebug("%s", str2);
1857 
1858  if (strcmp(str1, one) != 0) {
1859  SCLogInfo("%s != %s", str1, one);
1860  return false;
1861  }
1862 
1863  if (strcmp(str2, two) != 0) {
1864  SCLogInfo("%s != %s", str2, two);
1865  return false;
1866  }
1867 
1868  return true;
1869  break;
1870 
1871  case AF_INET6:
1872  PrintInet(AF_INET6, (const void *)&ad->ip.addr_data32[0], str1, sizeof(str1));
1873  SCLogDebug("%s", str1);
1874  PrintInet(AF_INET6, (const void *)&ad->ip2.addr_data32[0], str2, sizeof(str2));
1875  SCLogDebug("%s", str2);
1876 
1877  if (strcmp(str1, one) != 0) {
1878  SCLogInfo("%s != %s", str1, one);
1879  return false;
1880  }
1881 
1882  if (strcmp(str2, two) != 0) {
1883  SCLogInfo("%s != %s", str2, two);
1884  return false;
1885  }
1886 
1887  return true;
1888  break;
1889  }
1890 
1891  return false;
1892 }
1893 
1895  const char *one;
1896  const char *two;
1898 
1899 static int UTHValidateDetectAddressHead(DetectAddressHead *gh, int nranges, UTHValidateDetectAddressHeadRange *expectations)
1900 {
1901  int expect = nranges;
1902  int have = 0;
1903 
1904  if (gh == NULL)
1905  return false;
1906 
1907  DetectAddress *ad = NULL;
1908  ad = gh->ipv4_head;
1909  if (ad == NULL)
1910  ad = gh->ipv6_head;
1911  while (have < expect) {
1912  if (ad == NULL) {
1913  printf("bad head: have %d ranges, expected %d: ", have, expect);
1914  return false;
1915  }
1916 
1917  if (!UTHValidateDetectAddress(ad, expectations[have].one, expectations[have].two))
1918  return false;
1919 
1920  ad = ad->next;
1921  have++;
1922  }
1923 
1924  return true;
1925 }
1926 
1927 static int AddressTestParse01(void)
1928 {
1929  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4");
1930 
1931  if (dd) {
1932  DetectAddressFree(dd);
1933  return 1;
1934  }
1935 
1936  return 0;
1937 }
1938 
1939 static int AddressTestParse02(void)
1940 {
1941  int result = 1;
1942  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4");
1943 
1944  if (dd) {
1945  if (dd->ip2.addr_data32[0] != SCNtohl(16909060) ||
1946  dd->ip.addr_data32[0] != SCNtohl(16909060)) {
1947  result = 0;
1948  }
1949 
1950  printf("ip %"PRIu32", ip2 %"PRIu32"\n", dd->ip.addr_data32[0], dd->ip2.addr_data32[0]);
1951  DetectAddressFree(dd);
1952  return result;
1953  }
1954 
1955  return 0;
1956 }
1957 
1958 static int AddressTestParse03(void)
1959 {
1960  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4/255.255.255.0");
1961 
1962  if (dd) {
1963  DetectAddressFree(dd);
1964  return 1;
1965  }
1966 
1967  return 0;
1968 }
1969 
1970 static int AddressTestParse04(void)
1971 {
1972  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4/255.255.255.0");
1973  FAIL_IF_NULL(dd);
1974 
1975  char left[16], right[16];
1976  PrintInet(AF_INET, (const void *)&dd->ip.addr_data32[0], left, sizeof(left));
1977  PrintInet(AF_INET, (const void *)&dd->ip2.addr_data32[0], right, sizeof(right));
1978  SCLogDebug("left %s right %s", left, right);
1979  FAIL_IF_NOT(dd->ip.addr_data32[0] == SCNtohl(16909056));
1980  FAIL_IF_NOT(dd->ip2.addr_data32[0] == SCNtohl(16909311));
1981  FAIL_IF_NOT(strcmp(left, "1.2.3.0") == 0);
1982  FAIL_IF_NOT(strcmp(right, "1.2.3.255") == 0);
1983 
1984  DetectAddressFree(dd);
1985  PASS;
1986 }
1987 
1988 /** \test that address range sets proper start address */
1989 static int AddressTestParse04bug5081(void)
1990 {
1991  DetectAddress *dd = DetectAddressParseSingle("1.2.3.64/26");
1992  FAIL_IF_NULL(dd);
1993 
1994  char left[16], right[16];
1995  PrintInet(AF_INET, (const void *)&dd->ip.addr_data32[0], left, sizeof(left));
1996  PrintInet(AF_INET, (const void *)&dd->ip2.addr_data32[0], right, sizeof(right));
1997  SCLogDebug("left %s right %s", left, right);
1998  FAIL_IF_NOT(strcmp(left, "1.2.3.64") == 0);
1999  FAIL_IF_NOT(strcmp(right, "1.2.3.127") == 0);
2000 
2001  DetectAddressFree(dd);
2002  PASS;
2003 }
2004 
2005 static int AddressTestParse05(void)
2006 {
2007  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4/24");
2008 
2009  if (dd) {
2010  DetectAddressFree(dd);
2011  return 1;
2012  }
2013 
2014  return 0;
2015 }
2016 
2017 static int AddressTestParse06(void)
2018 {
2019  int result = 1;
2020  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4/24");
2021 
2022  if (dd) {
2023  if (dd->ip2.addr_data32[0] != SCNtohl(16909311) ||
2024  dd->ip.addr_data32[0] != SCNtohl(16909056)) {
2025  result = 0;
2026  }
2027 
2028  DetectAddressFree(dd);
2029  return result;
2030  }
2031 
2032  return 0;
2033 }
2034 
2035 static int AddressTestParse07(void)
2036 {
2037  DetectAddress *dd = DetectAddressParseSingle("2001::/3");
2038 
2039  if (dd) {
2040  DetectAddressFree(dd);
2041  return 1;
2042  }
2043 
2044  return 0;
2045 }
2046 
2047 static int AddressTestParse08(void)
2048 {
2049  int result = 1;
2050  DetectAddress *dd = DetectAddressParseSingle("2001::/3");
2051 
2052  if (dd) {
2053  if (dd->ip.addr_data32[0] != SCNtohl(536870912) || dd->ip.addr_data32[1] != 0x00000000 ||
2054  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != 0x00000000 ||
2055 
2056  dd->ip2.addr_data32[0] != SCNtohl(1073741823) || dd->ip2.addr_data32[1] != 0xFFFFFFFF ||
2057  dd->ip2.addr_data32[2] != 0xFFFFFFFF || dd->ip2.addr_data32[3] != 0xFFFFFFFF) {
2058  DetectAddressPrint(dd);
2059  result = 0;
2060  }
2061 
2062  DetectAddressFree(dd);
2063  return result;
2064  }
2065 
2066  return 0;
2067 }
2068 
2069 static int AddressTestParse09(void)
2070 {
2071  DetectAddress *dd = DetectAddressParseSingle("2001::1/128");
2072 
2073  if (dd) {
2074  DetectAddressFree(dd);
2075  return 1;
2076  }
2077 
2078  return 0;
2079 }
2080 
2081 static int AddressTestParse10(void)
2082 {
2083  int result = 1;
2084  DetectAddress *dd = DetectAddressParseSingle("2001::/128");
2085 
2086  if (dd) {
2087  if (dd->ip.addr_data32[0] != SCNtohl(536936448) || dd->ip.addr_data32[1] != 0x00000000 ||
2088  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != 0x00000000 ||
2089 
2090  dd->ip2.addr_data32[0] != SCNtohl(536936448) || dd->ip2.addr_data32[1] != 0x00000000 ||
2091  dd->ip2.addr_data32[2] != 0x00000000 || dd->ip2.addr_data32[3] != 0x00000000) {
2092  DetectAddressPrint(dd);
2093  result = 0;
2094  }
2095 
2096  DetectAddressFree(dd);
2097  return result;
2098  }
2099 
2100  return 0;
2101 }
2102 
2103 static int AddressTestParse11(void)
2104 {
2105  DetectAddress *dd = DetectAddressParseSingle("2001::/48");
2106 
2107  if (dd) {
2108  DetectAddressFree(dd);
2109  return 1;
2110  }
2111 
2112  return 0;
2113 }
2114 
2115 static int AddressTestParse12(void)
2116 {
2117  int result = 1;
2118  DetectAddress *dd = DetectAddressParseSingle("2001::/48");
2119 
2120  if (dd) {
2121  if (dd->ip.addr_data32[0] != SCNtohl(536936448) || dd->ip.addr_data32[1] != 0x00000000 ||
2122  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != 0x00000000 ||
2123 
2124  dd->ip2.addr_data32[0] != SCNtohl(536936448) || dd->ip2.addr_data32[1] != SCNtohl(65535) ||
2125  dd->ip2.addr_data32[2] != 0xFFFFFFFF || dd->ip2.addr_data32[3] != 0xFFFFFFFF) {
2126  DetectAddressPrint(dd);
2127  result = 0;
2128  }
2129 
2130  DetectAddressFree(dd);
2131  return result;
2132  }
2133 
2134  return 0;
2135 }
2136 static int AddressTestParse13(void)
2137 {
2138  DetectAddress *dd = DetectAddressParseSingle("2001::/16");
2139 
2140  if (dd) {
2141  DetectAddressFree(dd);
2142  return 1;
2143  }
2144 
2145  return 0;
2146 }
2147 
2148 static int AddressTestParse14(void)
2149 {
2150  int result = 1;
2151  DetectAddress *dd = DetectAddressParseSingle("2001::/16");
2152 
2153  if (dd) {
2154  if (dd->ip.addr_data32[0] != SCNtohl(536936448) || dd->ip.addr_data32[1] != 0x00000000 ||
2155  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != 0x00000000 ||
2156 
2157  dd->ip2.addr_data32[0] != SCNtohl(537001983) || dd->ip2.addr_data32[1] != 0xFFFFFFFF ||
2158  dd->ip2.addr_data32[2] != 0xFFFFFFFF || dd->ip2.addr_data32[3] != 0xFFFFFFFF) {
2159  result = 0;
2160  }
2161 
2162  DetectAddressFree(dd);
2163  return result;
2164  }
2165 
2166  return 0;
2167 }
2168 
2169 static int AddressTestParse15(void)
2170 {
2171  DetectAddress *dd = DetectAddressParseSingle("2001::/0");
2172 
2173  if (dd) {
2174  DetectAddressFree(dd);
2175  return 1;
2176  }
2177 
2178  return 0;
2179 }
2180 
2181 static int AddressTestParse16(void)
2182 {
2183  int result = 1;
2184  DetectAddress *dd = DetectAddressParseSingle("2001::/0");
2185 
2186  if (dd) {
2187  if (dd->ip.addr_data32[0] != 0x00000000 || dd->ip.addr_data32[1] != 0x00000000 ||
2188  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != 0x00000000 ||
2189 
2190  dd->ip2.addr_data32[0] != 0xFFFFFFFF || dd->ip2.addr_data32[1] != 0xFFFFFFFF ||
2191  dd->ip2.addr_data32[2] != 0xFFFFFFFF || dd->ip2.addr_data32[3] != 0xFFFFFFFF) {
2192  result = 0;
2193  }
2194 
2195  DetectAddressFree(dd);
2196  return result;
2197  }
2198 
2199  return 0;
2200 }
2201 
2202 static int AddressTestParse17(void)
2203 {
2204  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4-1.2.3.6");
2205 
2206  if (dd) {
2207  DetectAddressFree(dd);
2208  return 1;
2209  }
2210 
2211  return 0;
2212 }
2213 
2214 static int AddressTestParse18(void)
2215 {
2216  int result = 1;
2217  DetectAddress *dd = DetectAddressParseSingle("1.2.3.4-1.2.3.6");
2218 
2219  if (dd) {
2220  if (dd->ip2.addr_data32[0] != SCNtohl(16909062) ||
2221  dd->ip.addr_data32[0] != SCNtohl(16909060)) {
2222  result = 0;
2223  }
2224 
2225  DetectAddressFree(dd);
2226  return result;
2227  }
2228 
2229  return 0;
2230 }
2231 
2232 static int AddressTestParse19(void)
2233 {
2234  DetectAddress *dd = DetectAddressParseSingle("1.2.3.6-1.2.3.4");
2235 
2236  if (dd) {
2237  DetectAddressFree(dd);
2238  return 0;
2239  }
2240 
2241  return 1;
2242 }
2243 
2244 static int AddressTestParse20(void)
2245 {
2246  DetectAddress *dd = DetectAddressParseSingle("2001::1-2001::4");
2247 
2248  if (dd) {
2249  DetectAddressFree(dd);
2250  return 1;
2251  }
2252 
2253  return 0;
2254 }
2255 
2256 static int AddressTestParse21(void)
2257 {
2258  int result = 1;
2259  DetectAddress *dd = DetectAddressParseSingle("2001::1-2001::4");
2260 
2261  if (dd) {
2262  if (dd->ip.addr_data32[0] != SCNtohl(536936448) || dd->ip.addr_data32[1] != 0x00000000 ||
2263  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != SCNtohl(1) ||
2264 
2265  dd->ip2.addr_data32[0] != SCNtohl(536936448) || dd->ip2.addr_data32[1] != 0x00000000 ||
2266  dd->ip2.addr_data32[2] != 0x00000000 || dd->ip2.addr_data32[3] != SCNtohl(4)) {
2267  result = 0;
2268  }
2269 
2270  DetectAddressFree(dd);
2271  return result;
2272  }
2273 
2274  return 0;
2275 }
2276 
2277 static int AddressTestParse22(void)
2278 {
2279  DetectAddress *dd = DetectAddressParseSingle("2001::4-2001::1");
2280 
2281  if (dd) {
2282  DetectAddressFree(dd);
2283  return 0;
2284  }
2285 
2286  return 1;
2287 }
2288 
2289 static int AddressTestParse23(void)
2290 {
2291  DetectAddressHead *gh = DetectAddressHeadInit();
2292  FAIL_IF_NULL(gh);
2293  int r = DetectAddressParse(NULL, gh, "any", NULL);
2294  FAIL_IF_NOT(r == 0);
2295  DetectAddressHeadFree(gh);
2296  PASS;
2297 }
2298 
2299 static int AddressTestParse24(void)
2300 {
2301  DetectAddressHead *gh = DetectAddressHeadInit();
2302  FAIL_IF_NULL(gh);
2303  int r = DetectAddressParse(NULL, gh, "Any", NULL);
2304  FAIL_IF_NOT(r == 0);
2305  DetectAddressHeadFree(gh);
2306  PASS;
2307 }
2308 
2309 static int AddressTestParse25(void)
2310 {
2311  DetectAddressHead *gh = DetectAddressHeadInit();
2312  FAIL_IF_NULL(gh);
2313  int r = DetectAddressParse(NULL, gh, "ANY", NULL);
2314  FAIL_IF_NOT(r == 0);
2315  DetectAddressHeadFree(gh);
2316  PASS;
2317 }
2318 
2319 /** \test recursion limit */
2320 static int AddressTestParse26(void)
2321 {
2322  DetectAddressHead *gh = DetectAddressHeadInit();
2323  FAIL_IF_NULL(gh);
2324  /* exactly 64: should pass */
2325  int r = DetectAddressParse(NULL, gh,
2326  "[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[["
2327  "1.2.3.4"
2328  "]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]",
2329  NULL);
2330  FAIL_IF_NOT(r == 0);
2331  DetectAddressHeadFree(gh);
2332  gh = DetectAddressHeadInit();
2333  FAIL_IF_NULL(gh);
2334  /* exactly 65: should fail */
2335  r = DetectAddressParse(NULL, gh,
2336  "[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[["
2337  "1.2.3.4"
2338  "]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]",
2339  NULL);
2340  FAIL_IF(r == 0);
2341  DetectAddressHeadFree(gh);
2342  PASS;
2343 }
2344 
2345 static int AddressTestParse27(void)
2346 {
2347  DetectAddress *dd = DetectAddressParseSingle("!192.168.0.1");
2348 
2349  if (dd) {
2350  DetectAddressFree(dd);
2351  return 1;
2352  }
2353 
2354  return 0;
2355 }
2356 
2357 static int AddressTestParse28(void)
2358 {
2359  int result = 0;
2360  DetectAddress *dd = DetectAddressParseSingle("!1.2.3.4");
2361 
2362  if (dd) {
2363  if (dd->flags & ADDRESS_FLAG_NOT &&
2364  dd->ip.addr_data32[0] == SCNtohl(16909060)) {
2365  result = 1;
2366  }
2367 
2368  DetectAddressFree(dd);
2369  return result;
2370  }
2371 
2372  return 0;
2373 }
2374 
2375 static int AddressTestParse29(void)
2376 {
2377  DetectAddress *dd = DetectAddressParseSingle("!1.2.3.0/24");
2378 
2379  if (dd) {
2380  DetectAddressFree(dd);
2381  return 1;
2382  }
2383 
2384  return 0;
2385 }
2386 
2387 static int AddressTestParse30(void)
2388 {
2389  int result = 0;
2390  DetectAddress *dd = DetectAddressParseSingle("!1.2.3.4/24");
2391 
2392  if (dd) {
2393  if (dd->flags & ADDRESS_FLAG_NOT &&
2394  dd->ip.addr_data32[0] == SCNtohl(16909056) &&
2395  dd->ip2.addr_data32[0] == SCNtohl(16909311)) {
2396  result = 1;
2397  }
2398 
2399  DetectAddressFree(dd);
2400  return result;
2401  }
2402 
2403  return 0;
2404 }
2405 
2406 /**
2407  * \test make sure !any is rejected
2408  */
2409 static int AddressTestParse31(void)
2410 {
2411  DetectAddress *dd = DetectAddressParseSingle("!any");
2412 
2413  if (dd) {
2414  DetectAddressFree(dd);
2415  return 0;
2416  }
2417 
2418  return 1;
2419 }
2420 
2421 static int AddressTestParse32(void)
2422 {
2423  DetectAddress *dd = DetectAddressParseSingle("!2001::1");
2424 
2425  if (dd) {
2426  DetectAddressFree(dd);
2427  return 1;
2428  }
2429 
2430  return 0;
2431 }
2432 
2433 static int AddressTestParse33(void)
2434 {
2435  int result = 0;
2436  DetectAddress *dd = DetectAddressParseSingle("!2001::1");
2437 
2438  if (dd) {
2439  if (dd->flags & ADDRESS_FLAG_NOT &&
2440  dd->ip.addr_data32[0] == SCNtohl(536936448) && dd->ip.addr_data32[1] == 0x00000000 &&
2441  dd->ip.addr_data32[2] == 0x00000000 && dd->ip.addr_data32[3] == SCNtohl(1)) {
2442  result = 1;
2443  }
2444 
2445  DetectAddressFree(dd);
2446  return result;
2447  }
2448 
2449  return 0;
2450 }
2451 
2452 static int AddressTestParse34(void)
2453 {
2454  DetectAddress *dd = DetectAddressParseSingle("!2001::/16");
2455 
2456  if (dd) {
2457  DetectAddressFree(dd);
2458  return 1;
2459  }
2460 
2461  return 0;
2462 }
2463 
2464 static int AddressTestParse35(void)
2465 {
2466  int result = 0;
2467  DetectAddress *dd = DetectAddressParseSingle("!2001::/16");
2468 
2469  if (dd) {
2470  if (dd->flags & ADDRESS_FLAG_NOT &&
2471  dd->ip.addr_data32[0] == SCNtohl(536936448) && dd->ip.addr_data32[1] == 0x00000000 &&
2472  dd->ip.addr_data32[2] == 0x00000000 && dd->ip.addr_data32[3] == 0x00000000 &&
2473 
2474  dd->ip2.addr_data32[0] == SCNtohl(537001983) && dd->ip2.addr_data32[1] == 0xFFFFFFFF &&
2475  dd->ip2.addr_data32[2] == 0xFFFFFFFF && dd->ip2.addr_data32[3] == 0xFFFFFFFF) {
2476  result = 1;
2477  }
2478 
2479  DetectAddressFree(dd);
2480  return result;
2481  }
2482 
2483  return 0;
2484 }
2485 
2486 static int AddressTestParse36(void)
2487 {
2488  int result = 1;
2489  DetectAddress *dd = DetectAddressParseSingle("ffff::/16");
2490 
2491  if (dd) {
2492  if (dd->ip.addr_data32[0] != SCNtohl(0xFFFF0000) || dd->ip.addr_data32[1] != 0x00000000 ||
2493  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != 0x00000000 ||
2494 
2495  dd->ip2.addr_data32[0] != 0xFFFFFFFF || dd->ip2.addr_data32[1] != 0xFFFFFFFF ||
2496  dd->ip2.addr_data32[2] != 0xFFFFFFFF || dd->ip2.addr_data32[3] != 0xFFFFFFFF) {
2497 
2498  DetectAddressPrint(dd);
2499  result = 0;
2500  }
2501  DetectAddressPrint(dd);
2502 
2503  DetectAddressFree(dd);
2504  return result;
2505  }
2506 
2507  return 0;
2508 }
2509 
2510 static int AddressTestParse37(void)
2511 {
2512  int result = 1;
2513  DetectAddress *dd = DetectAddressParseSingle("::/0");
2514 
2515  if (dd) {
2516  if (dd->ip.addr_data32[0] != 0x00000000 || dd->ip.addr_data32[1] != 0x00000000 ||
2517  dd->ip.addr_data32[2] != 0x00000000 || dd->ip.addr_data32[3] != 0x00000000 ||
2518 
2519  dd->ip2.addr_data32[0] != 0xFFFFFFFF || dd->ip2.addr_data32[1] != 0xFFFFFFFF ||
2520  dd->ip2.addr_data32[2] != 0xFFFFFFFF || dd->ip2.addr_data32[3] != 0xFFFFFFFF) {
2521  DetectAddressPrint(dd);
2522  result = 0;
2523  }
2524  DetectAddressPrint(dd);
2525 
2526  DetectAddressFree(dd);
2527  return result;
2528  }
2529 
2530  return 0;
2531 }
2532 
2533 static int AddressTestMatch01(void)
2534 {
2535  DetectAddress *dd = NULL;
2536  int result = 1;
2537  struct in_addr in;
2538  Address a;
2539 
2540  if (inet_pton(AF_INET, "1.2.3.4", &in) != 1)
2541  return 0;
2542  memset(&a, 0, sizeof(Address));
2543  a.family = AF_INET;
2544  a.addr_data32[0] = in.s_addr;
2545 
2546  dd = DetectAddressParseSingle("1.2.3.4/24");
2547  if (dd) {
2548  if (DetectAddressMatch(dd, &a) == 0)
2549  result = 0;
2550 
2551  DetectAddressFree(dd);
2552  return result;
2553  }
2554 
2555  return 0;
2556 }
2557 
2558 static int AddressTestMatch02(void)
2559 {
2560  DetectAddress *dd = NULL;
2561  int result = 1;
2562  struct in_addr in;
2563  Address a;
2564 
2565  if (inet_pton(AF_INET, "1.2.3.127", &in) != 1)
2566  return 0;
2567  memset(&a, 0, sizeof(Address));
2568  a.family = AF_INET;
2569  a.addr_data32[0] = in.s_addr;
2570 
2571  dd = DetectAddressParseSingle("1.2.3.4/25");
2572  if (dd) {
2573  if (DetectAddressMatch(dd, &a) == 0)
2574  result = 0;
2575 
2576  DetectAddressFree(dd);
2577  return result;
2578  }
2579 
2580  return 0;
2581 }
2582 
2583 static int AddressTestMatch03(void)
2584 {
2585  DetectAddress *dd = NULL;
2586  int result = 1;
2587  struct in_addr in;
2588  Address a;
2589 
2590  if (inet_pton(AF_INET, "1.2.3.128", &in) != 1)
2591  return 0;
2592  memset(&a, 0, sizeof(Address));
2593  a.family = AF_INET;
2594  a.addr_data32[0] = in.s_addr;
2595 
2596  dd = DetectAddressParseSingle("1.2.3.4/25");
2597  if (dd) {
2598  if (DetectAddressMatch(dd, &a) == 1)
2599  result = 0;
2600 
2601  DetectAddressFree(dd);
2602  return result;
2603  }
2604 
2605  return 0;
2606 }
2607 
2608 static int AddressTestMatch04(void)
2609 {
2610  DetectAddress *dd = NULL;
2611  int result = 1;
2612  struct in_addr in;
2613  Address a;
2614 
2615  if (inet_pton(AF_INET, "1.2.2.255", &in) != 1)
2616  return 0;
2617  memset(&a, 0, sizeof(Address));
2618  a.family = AF_INET;
2619  a.addr_data32[0] = in.s_addr;
2620 
2621  dd = DetectAddressParseSingle("1.2.3.4/25");
2622  if (dd) {
2623  if (DetectAddressMatch(dd, &a) == 1)
2624  result = 0;
2625 
2626  DetectAddressFree(dd);
2627  return result;
2628  }
2629 
2630  return 0;
2631 }
2632 
2633 static int AddressTestMatch05(void)
2634 {
2635  DetectAddress *dd = NULL;
2636  int result = 1;
2637  struct in_addr in;
2638  Address a;
2639 
2640  if (inet_pton(AF_INET, "1.2.3.4", &in) != 1)
2641  return 0;
2642  memset(&a, 0, sizeof(Address));
2643  a.family = AF_INET;
2644  a.addr_data32[0] = in.s_addr;
2645 
2646  dd = DetectAddressParseSingle("1.2.3.4/32");
2647  if (dd) {
2648  if (DetectAddressMatch(dd, &a) == 0)
2649  result = 0;
2650 
2651  DetectAddressFree(dd);
2652  return result;
2653  }
2654 
2655  return 0;
2656 }
2657 
2658 static int AddressTestMatch06(void)
2659 {
2660  DetectAddress *dd = NULL;
2661  int result = 1;
2662  struct in_addr in;
2663  Address a;
2664 
2665  if (inet_pton(AF_INET, "1.2.3.4", &in) != 1)
2666  return 0;
2667  memset(&a, 0, sizeof(Address));
2668  a.family = AF_INET;
2669  a.addr_data32[0] = in.s_addr;
2670 
2671  dd = DetectAddressParseSingle("0.0.0.0/0.0.0.0");
2672  if (dd) {
2673  if (DetectAddressMatch(dd, &a) == 0)
2674  result = 0;
2675 
2676  DetectAddressFree(dd);
2677  return result;
2678  }
2679 
2680  return 0;
2681 }
2682 
2683 static int AddressTestMatch07(void)
2684 {
2685  DetectAddress *dd = NULL;
2686  int result = 1;
2687  struct in6_addr in6;
2688  Address a;
2689 
2690  if (inet_pton(AF_INET6, "2001::1", &in6) != 1)
2691  return 0;
2692  memset(&a, 0, sizeof(Address));
2693  a.family = AF_INET6;
2694  memcpy(&a.addr_data32, &in6.s6_addr, sizeof(in6.s6_addr));
2695 
2696  dd = DetectAddressParseSingle("2001::/3");
2697  if (dd) {
2698  if (DetectAddressMatch(dd, &a) == 0)
2699  result = 0;
2700 
2701  DetectAddressFree(dd);
2702  return result;
2703  }
2704 
2705  return 0;
2706 }
2707 
2708 static int AddressTestMatch08(void)
2709 {
2710  DetectAddress *dd = NULL;
2711  int result = 1;
2712  struct in6_addr in6;
2713  Address a;
2714 
2715  if (inet_pton(AF_INET6, "1999:ffff:ffff:ffff:ffff:ffff:ffff:ffff", &in6) != 1)
2716  return 0;
2717  memset(&a, 0, sizeof(Address));
2718  a.family = AF_INET6;
2719  memcpy(&a.addr_data32, &in6.s6_addr, sizeof(in6.s6_addr));
2720 
2721  dd = DetectAddressParseSingle("2001::/3");
2722  if (dd) {
2723  if (DetectAddressMatch(dd, &a) == 1)
2724  result = 0;
2725 
2726  DetectAddressFree(dd);
2727  return result;
2728  }
2729 
2730  return 0;
2731 }
2732 
2733 static int AddressTestMatch09(void)
2734 {
2735  DetectAddress *dd = NULL;
2736  int result = 1;
2737  struct in6_addr in6;
2738  Address a;
2739 
2740  if (inet_pton(AF_INET6, "2001::2", &in6) != 1)
2741  return 0;
2742  memset(&a, 0, sizeof(Address));
2743  a.family = AF_INET6;
2744  memcpy(&a.addr_data32, &in6.s6_addr, sizeof(in6.s6_addr));
2745 
2746  dd = DetectAddressParseSingle("2001::1/128");
2747  if (dd) {
2748  if (DetectAddressMatch(dd, &a) == 1)
2749  result = 0;
2750 
2751  DetectAddressFree(dd);
2752  return result;
2753  }
2754 
2755  return 0;
2756 }
2757 
2758 static int AddressTestMatch10(void)
2759 {
2760  DetectAddress *dd = NULL;
2761  int result = 1;
2762  struct in6_addr in6;
2763  Address a;
2764 
2765  if (inet_pton(AF_INET6, "2001::2", &in6) != 1)
2766  return 0;
2767  memset(&a, 0, sizeof(Address));
2768  a.family = AF_INET6;
2769  memcpy(&a.addr_data32, &in6.s6_addr, sizeof(in6.s6_addr));
2770 
2771  dd = DetectAddressParseSingle("2001::1/126");
2772  if (dd) {
2773  if (DetectAddressMatch(dd, &a) == 0)
2774  result = 0;
2775 
2776  DetectAddressFree(dd);
2777  return result;
2778  }
2779 
2780  return 0;
2781 }
2782 
2783 static int AddressTestMatch11(void)
2784 {
2785  DetectAddress *dd = NULL;
2786  int result = 1;
2787  struct in6_addr in6;
2788  Address a;
2789 
2790  if (inet_pton(AF_INET6, "2001::3", &in6) != 1)
2791  return 0;
2792  memset(&a, 0, sizeof(Address));
2793  a.family = AF_INET6;
2794  memcpy(&a.addr_data32, &in6.s6_addr, sizeof(in6.s6_addr));
2795 
2796  dd = DetectAddressParseSingle("2001::1/127");
2797  if (dd) {
2798  if (DetectAddressMatch(dd, &a) == 1)
2799  result = 0;
2800 
2801  DetectAddressFree(dd);
2802  return result;
2803  }
2804 
2805  return 0;
2806 }
2807 
2808 static int AddressTestCmp01(void)
2809 {
2810  DetectAddress *da = NULL, *db = NULL;
2811  int result = 1;
2812 
2813  da = DetectAddressParseSingle("192.168.0.0/255.255.255.0");
2814  if (da == NULL) goto error;
2815  db = DetectAddressParseSingle("192.168.0.0/255.255.255.0");
2816  if (db == NULL) goto error;
2817 
2818  if (DetectAddressCmp(da, db) != ADDRESS_EQ)
2819  result = 0;
2820 
2821  DetectAddressFree(da);
2822  DetectAddressFree(db);
2823  return result;
2824 
2825 error:
2826  if (da) DetectAddressFree(da);
2827  if (db) DetectAddressFree(db);
2828  return 0;
2829 }
2830 
2831 static int AddressTestCmp02(void)
2832 {
2833  DetectAddress *da = NULL, *db = NULL;
2834  int result = 1;
2835 
2836  da = DetectAddressParseSingle("192.168.0.0/255.255.0.0");
2837  if (da == NULL) goto error;
2838  db = DetectAddressParseSingle("192.168.0.0/255.255.255.0");
2839  if (db == NULL) goto error;
2840 
2841  if (DetectAddressCmp(da, db) != ADDRESS_EB)
2842  result = 0;
2843 
2844  DetectAddressFree(da);
2845  DetectAddressFree(db);
2846  return result;
2847 
2848 error:
2849  if (da) DetectAddressFree(da);
2850  if (db) DetectAddressFree(db);
2851  return 0;
2852 }
2853 
2854 static int AddressTestCmp03(void)
2855 {
2856  DetectAddress *da = NULL, *db = NULL;
2857  int result = 1;
2858 
2859  da = DetectAddressParseSingle("192.168.0.0/255.255.255.0");
2860  if (da == NULL) goto error;
2861  db = DetectAddressParseSingle("192.168.0.0/255.255.0.0");
2862  if (db == NULL) goto error;
2863 
2864  if (DetectAddressCmp(da, db) != ADDRESS_ES)
2865  result = 0;
2866 
2867  DetectAddressFree(da);
2868  DetectAddressFree(db);
2869  return result;
2870 
2871 error:
2872  if (da) DetectAddressFree(da);
2873  if (db) DetectAddressFree(db);
2874  return 0;
2875 }
2876 
2877 static int AddressTestCmp04(void)
2878 {
2879  DetectAddress *da = NULL, *db = NULL;
2880  int result = 1;
2881 
2882  da = DetectAddressParseSingle("192.168.0.0/255.255.255.0");
2883  if (da == NULL) goto error;
2884  db = DetectAddressParseSingle("192.168.1.0/255.255.255.0");
2885  if (db == NULL) goto error;
2886 
2887  if (DetectAddressCmp(da, db) != ADDRESS_LT)
2888  result = 0;
2889 
2890  DetectAddressFree(da);
2891  DetectAddressFree(db);
2892  return result;
2893 
2894 error:
2895  if (da) DetectAddressFree(da);
2896  if (db) DetectAddressFree(db);
2897  return 0;
2898 }
2899 
2900 static int AddressTestCmp05(void)
2901 {
2902  DetectAddress *da = NULL, *db = NULL;
2903  int result = 1;
2904 
2905  da = DetectAddressParseSingle("192.168.1.0/255.255.255.0");
2906  if (da == NULL) goto error;
2907  db = DetectAddressParseSingle("192.168.0.0/255.255.255.0");
2908  if (db == NULL) goto error;
2909 
2910  if (DetectAddressCmp(da, db) != ADDRESS_GT)
2911  result = 0;
2912 
2913  DetectAddressFree(da);
2914  DetectAddressFree(db);
2915  return result;
2916 
2917 error:
2918  if (da) DetectAddressFree(da);
2919  if (db) DetectAddressFree(db);
2920  return 0;
2921 }
2922 
2923 static int AddressTestCmp06(void)
2924 {
2925  DetectAddress *da = NULL, *db = NULL;
2926  int result = 1;
2927 
2928  da = DetectAddressParseSingle("192.168.1.0/255.255.0.0");
2929  if (da == NULL) goto error;
2930  db = DetectAddressParseSingle("192.168.0.0/255.255.0.0");
2931  if (db == NULL) goto error;
2932 
2933  if (DetectAddressCmp(da, db) != ADDRESS_EQ)
2934  result = 0;
2935 
2936  DetectAddressFree(da);
2937  DetectAddressFree(db);
2938  return result;
2939 
2940 error:
2941  if (da) DetectAddressFree(da);
2942  if (db) DetectAddressFree(db);
2943  return 0;
2944 }
2945 
2946 static int AddressTestCmpIPv407(void)
2947 {
2948  DetectAddress *da = NULL, *db = NULL;
2949  int result = 1;
2950 
2951  da = DetectAddressParseSingle("192.168.1.0/255.255.255.0");
2952  if (da == NULL) goto error;
2953  db = DetectAddressParseSingle("192.168.1.128-192.168.2.128");
2954  if (db == NULL) goto error;
2955 
2956  if (DetectAddressCmp(da, db) != ADDRESS_LE)
2957  result = 0;
2958 
2959  DetectAddressFree(da);
2960  DetectAddressFree(db);
2961  return result;
2962 
2963 error:
2964  if (da) DetectAddressFree(da);
2965  if (db) DetectAddressFree(db);
2966  return 0;
2967 }
2968 
2969 static int AddressTestCmpIPv408(void)
2970 {
2971  DetectAddress *da = NULL, *db = NULL;
2972  int result = 1;
2973 
2974  da = DetectAddressParseSingle("192.168.1.128-192.168.2.128");
2975  if (da == NULL) goto error;
2976  db = DetectAddressParseSingle("192.168.1.0/255.255.255.0");
2977  if (db == NULL) goto error;
2978 
2979  if (DetectAddressCmp(da, db) != ADDRESS_GE)
2980  result = 0;
2981 
2982  DetectAddressFree(da);
2983  DetectAddressFree(db);
2984  return result;
2985 
2986 error:
2987  if (da) DetectAddressFree(da);
2988  if (db) DetectAddressFree(db);
2989  return 0;
2990 }
2991 
2992 static int AddressTestCmp07(void)
2993 {
2994  DetectAddress *da = NULL, *db = NULL;
2995  int result = 1;
2996 
2997  da = DetectAddressParseSingle("2001::/3");
2998  if (da == NULL) goto error;
2999  db = DetectAddressParseSingle("2001::1/3");
3000  if (db == NULL) goto error;
3001 
3002  if (DetectAddressCmp(da, db) != ADDRESS_EQ)
3003  result = 0;
3004 
3005  DetectAddressFree(da);
3006  DetectAddressFree(db);
3007  return result;
3008 
3009 error:
3010  if (da) DetectAddressFree(da);
3011  if (db) DetectAddressFree(db);
3012  return 0;
3013 }
3014 
3015 static int AddressTestCmp08(void)
3016 {
3017  DetectAddress *da = NULL, *db = NULL;
3018  int result = 1;
3019 
3020  da = DetectAddressParseSingle("2001::/3");
3021  if (da == NULL) goto error;
3022  db = DetectAddressParseSingle("2001::/8");
3023  if (db == NULL) goto error;
3024 
3025  if (DetectAddressCmp(da, db) != ADDRESS_EB)
3026  result = 0;
3027 
3028  DetectAddressFree(da);
3029  DetectAddressFree(db);
3030  return result;
3031 
3032 error:
3033  if (da) DetectAddressFree(da);
3034  if (db) DetectAddressFree(db);
3035  return 0;
3036 }
3037 
3038 static int AddressTestCmp09(void)
3039 {
3040  DetectAddress *da = NULL, *db = NULL;
3041  int result = 1;
3042 
3043  da = DetectAddressParseSingle("2001::/8");
3044  if (da == NULL) goto error;
3045  db = DetectAddressParseSingle("2001::/3");
3046  if (db == NULL) goto error;
3047 
3048  if (DetectAddressCmp(da, db) != ADDRESS_ES)
3049  result = 0;
3050 
3051  DetectAddressFree(da);
3052  DetectAddressFree(db);
3053  return result;
3054 
3055 error:
3056  if (da) DetectAddressFree(da);
3057  if (db) DetectAddressFree(db);
3058  return 0;
3059 }
3060 
3061 static int AddressTestCmp10(void)
3062 {
3063  DetectAddress *da = NULL, *db = NULL;
3064  int result = 1;
3065 
3066  da = DetectAddressParseSingle("2001:1:2:3:0:0:0:0/64");
3067  if (da == NULL) goto error;
3068  db = DetectAddressParseSingle("2001:1:2:4:0:0:0:0/64");
3069  if (db == NULL) goto error;
3070 
3071  if (DetectAddressCmp(da, db) != ADDRESS_LT)
3072  result = 0;
3073 
3074  DetectAddressFree(da);
3075  DetectAddressFree(db);
3076  return result;
3077 
3078 error:
3079  if (da) DetectAddressFree(da);
3080  if (db) DetectAddressFree(db);
3081  return 0;
3082 }
3083 
3084 static int AddressTestCmp11(void)
3085 {
3086  DetectAddress *da = NULL, *db = NULL;
3087  int result = 1;
3088 
3089  da = DetectAddressParseSingle("2001:1:2:4:0:0:0:0/64");
3090  if (da == NULL) goto error;
3091  db = DetectAddressParseSingle("2001:1:2:3:0:0:0:0/64");
3092  if (db == NULL) goto error;
3093 
3094  if (DetectAddressCmp(da, db) != ADDRESS_GT)
3095  result = 0;
3096 
3097  DetectAddressFree(da);
3098  DetectAddressFree(db);
3099  return result;
3100 
3101 error:
3102  if (da) DetectAddressFree(da);
3103  if (db) DetectAddressFree(db);
3104  return 0;
3105 }
3106 
3107 static int AddressTestCmp12(void)
3108 {
3109  DetectAddress *da = NULL, *db = NULL;
3110  int result = 1;
3111 
3112  da = DetectAddressParseSingle("2001:1:2:3:1:0:0:0/64");
3113  if (da == NULL) goto error;
3114  db = DetectAddressParseSingle("2001:1:2:3:2:0:0:0/64");
3115  if (db == NULL) goto error;
3116 
3117  if (DetectAddressCmp(da, db) != ADDRESS_EQ)
3118  result = 0;
3119 
3120  DetectAddressFree(da);
3121  DetectAddressFree(db);
3122  return result;
3123 
3124 error:
3125  if (da) DetectAddressFree(da);
3126  if (db) DetectAddressFree(db);
3127  return 0;
3128 }
3129 
3130 static int AddressTestAddressGroupSetup01(void)
3131 {
3132  int result = 0;
3133  DetectAddressHead *gh = DetectAddressHeadInit();
3134 
3135  if (gh != NULL) {
3136  int r = DetectAddressParse(NULL, gh, "1.2.3.4", NULL);
3137  if (r == 0)
3138  result = 1;
3139 
3140  DetectAddressHeadFree(gh);
3141  }
3142  return result;
3143 }
3144 
3145 static int AddressTestAddressGroupSetup02(void)
3146 {
3147  int result = 0;
3148  DetectAddressHead *gh = DetectAddressHeadInit();
3149 
3150  if (gh != NULL) {
3151  int r = DetectAddressParse(NULL, gh, "1.2.3.4", NULL);
3152  if (r == 0 && gh->ipv4_head != NULL)
3153  result = 1;
3154 
3155  DetectAddressHeadFree(gh);
3156  }
3157  return result;
3158 }
3159 
3160 static int AddressTestAddressGroupSetup03(void)
3161 {
3162  int result = 0;
3163  DetectAddressHead *gh = DetectAddressHeadInit();
3164 
3165  if (gh != NULL) {
3166  int r = DetectAddressParse(NULL, gh, "1.2.3.4", NULL);
3167  if (r == 0 && gh->ipv4_head != NULL) {
3168  DetectAddress *prev_head = gh->ipv4_head;
3169 
3170  r = DetectAddressParse(NULL, gh, "1.2.3.3", NULL);
3171  if (r == 0 && gh->ipv4_head != prev_head &&
3172  gh->ipv4_head != NULL && gh->ipv4_head->next == prev_head) {
3173  result = 1;
3174  }
3175  }
3176 
3177  DetectAddressHeadFree(gh);
3178  }
3179  return result;
3180 }
3181 
3182 static int AddressTestAddressGroupSetup04(void)
3183 {
3184  int result = 0;
3185  DetectAddressHead *gh = DetectAddressHeadInit();
3186 
3187  if (gh != NULL) {
3188  int r = DetectAddressParse(NULL, gh, "1.2.3.4", NULL);
3189  if (r == 0 && gh->ipv4_head != NULL) {
3190  DetectAddress *prev_head = gh->ipv4_head;
3191 
3192  r = DetectAddressParse(NULL, gh, "1.2.3.3", NULL);
3193  if (r == 0 && gh->ipv4_head != prev_head &&
3194  gh->ipv4_head != NULL && gh->ipv4_head->next == prev_head) {
3195  DetectAddress *ph = gh->ipv4_head;
3196 
3197  r = DetectAddressParse(NULL, gh, "1.2.3.2", NULL);
3198  if (r == 0 && gh->ipv4_head != ph &&
3199  gh->ipv4_head != NULL && gh->ipv4_head->next == ph) {
3200  result = 1;
3201  }
3202  }
3203  }
3204 
3205  DetectAddressHeadFree(gh);
3206  }
3207  return result;
3208 }
3209 
3210 static int AddressTestAddressGroupSetup05(void)
3211 {
3212  int result = 0;
3213  DetectAddressHead *gh = DetectAddressHeadInit();
3214 
3215  if (gh != NULL) {
3216  int r = DetectAddressParse(NULL, gh, "1.2.3.2", NULL);
3217  if (r == 0 && gh->ipv4_head != NULL) {
3218  DetectAddress *prev_head = gh->ipv4_head;
3219 
3220  r = DetectAddressParse(NULL, gh, "1.2.3.3", NULL);
3221  if (r == 0 && gh->ipv4_head == prev_head &&
3222  gh->ipv4_head != NULL && gh->ipv4_head->next != prev_head) {
3223  DetectAddress *ph = gh->ipv4_head;
3224 
3225  r = DetectAddressParse(NULL, gh, "1.2.3.4", NULL);
3226  if (r == 0 && gh->ipv4_head == ph &&
3227  gh->ipv4_head != NULL && gh->ipv4_head->next != ph) {
3228  result = 1;
3229  }
3230  }
3231  }
3232 
3233  DetectAddressHeadFree(gh);
3234  }
3235  return result;
3236 }
3237 
3238 static int AddressTestAddressGroupSetup06(void)
3239 {
3240  int result = 0;
3241  DetectAddressHead *gh = DetectAddressHeadInit();
3242 
3243  if (gh != NULL) {
3244  int r = DetectAddressParse(NULL, gh, "1.2.3.2", NULL);
3245  if (r == 0 && gh->ipv4_head != NULL) {
3246  DetectAddress *prev_head = gh->ipv4_head;
3247 
3248  r = DetectAddressParse(NULL, gh, "1.2.3.2", NULL);
3249  if (r == 0 && gh->ipv4_head == prev_head &&
3250  gh->ipv4_head != NULL && gh->ipv4_head->next == NULL) {
3251  result = 1;
3252  }
3253  }
3254 
3255  DetectAddressHeadFree(gh);
3256  }
3257  return result;
3258 }
3259 
3260 static int AddressTestAddressGroupSetup07(void)
3261 {
3262  int result = 0;
3263  DetectAddressHead *gh = DetectAddressHeadInit();
3264 
3265  if (gh != NULL) {
3266  int r = DetectAddressParse(NULL, gh, "10.0.0.0/8", NULL);
3267  if (r == 0 && gh->ipv4_head != NULL) {
3268  r = DetectAddressParse(NULL, gh, "10.10.10.10", NULL);
3269  if (r == 0 && gh->ipv4_head != NULL &&
3270  gh->ipv4_head->next != NULL &&
3271  gh->ipv4_head->next->next != NULL) {
3272  result = 1;
3273  }
3274  }
3275 
3276  DetectAddressHeadFree(gh);
3277  }
3278  return result;
3279 }
3280 
3281 static int AddressTestAddressGroupSetup08(void)
3282 {
3283  int result = 0;
3284  DetectAddressHead *gh = DetectAddressHeadInit();
3285 
3286  if (gh != NULL) {
3287  int r = DetectAddressParse(NULL, gh, "10.10.10.10", NULL);
3288  if (r == 0 && gh->ipv4_head != NULL) {
3289  r = DetectAddressParse(NULL, gh, "10.0.0.0/8", NULL);
3290  if (r == 0 && gh->ipv4_head != NULL &&
3291  gh->ipv4_head->next != NULL &&
3292  gh->ipv4_head->next->next != NULL) {
3293  result = 1;
3294  }
3295  }
3296 
3297  DetectAddressHeadFree(gh);
3298  }
3299  return result;
3300 }
3301 
3302 static int AddressTestAddressGroupSetup09(void)
3303 {
3304  int result = 0;
3305  DetectAddressHead *gh = DetectAddressHeadInit();
3306 
3307  if (gh != NULL) {
3308  int r = DetectAddressParse(NULL, gh, "10.10.10.0/24", NULL);
3309  if (r == 0 && gh->ipv4_head != NULL) {
3310  r = DetectAddressParse(NULL, gh, "10.10.10.10-10.10.11.1", NULL);
3311  if (r == 0 && gh->ipv4_head != NULL &&
3312  gh->ipv4_head->next != NULL &&
3313  gh->ipv4_head->next->next != NULL) {
3314  result = 1;
3315  }
3316  }
3317 
3318  DetectAddressHeadFree(gh);
3319  }
3320  return result;
3321 }
3322 
3323 static int AddressTestAddressGroupSetup10(void)
3324 {
3325  int result = 0;
3326  DetectAddressHead *gh = DetectAddressHeadInit();
3327 
3328  if (gh != NULL) {
3329  int r = DetectAddressParse(NULL, gh, "10.10.10.10-10.10.11.1", NULL);
3330  if (r == 0 && gh->ipv4_head != NULL) {
3331  r = DetectAddressParse(NULL, gh, "10.10.10.0/24", NULL);
3332  if (r == 0 && gh->ipv4_head != NULL &&
3333  gh->ipv4_head->next != NULL &&
3334  gh->ipv4_head->next->next != NULL) {
3335  result = 1;
3336  }
3337  }
3338 
3339  DetectAddressHeadFree(gh);
3340  }
3341  return result;
3342 }
3343 
3344 static int AddressTestAddressGroupSetup11(void)
3345 {
3346  int result = 0;
3347  DetectAddressHead *gh = DetectAddressHeadInit();
3348 
3349  if (gh != NULL) {
3350  int r = DetectAddressParse(NULL, gh, "10.10.10.10-10.10.11.1", NULL);
3351  if (r == 0) {
3352  r = DetectAddressParse(NULL, gh, "10.10.10.0/24", NULL);
3353  if (r == 0) {
3354  r = DetectAddressParse(NULL, gh, "0.0.0.0/0", NULL);
3355  if (r == 0) {
3356  DetectAddress *one = gh->ipv4_head, *two = one->next,
3357  *three = two->next, *four = three->next,
3358  *five = four->next;
3359 
3360  /* result should be:
3361  * 0.0.0.0/10.10.9.255
3362  * 10.10.10.0/10.10.10.9
3363  * 10.10.10.10/10.10.10.255
3364  * 10.10.11.0/10.10.11.1
3365  * 10.10.11.2/255.255.255.255
3366  */
3367  if (one->ip.addr_data32[0] == 0x00000000 && one->ip2.addr_data32[0] == SCNtohl(168430079) &&
3368  two->ip.addr_data32[0] == SCNtohl(168430080) && two->ip2.addr_data32[0] == SCNtohl(168430089) &&
3369  three->ip.addr_data32[0] == SCNtohl(168430090) && three->ip2.addr_data32[0] == SCNtohl(168430335) &&
3370  four->ip.addr_data32[0] == SCNtohl(168430336) && four->ip2.addr_data32[0] == SCNtohl(168430337) &&
3371  five->ip.addr_data32[0] == SCNtohl(168430338) && five->ip2.addr_data32[0] == 0xFFFFFFFF) {
3372  result = 1;
3373  }
3374  }
3375  }
3376  }
3377 
3378  DetectAddressHeadFree(gh);
3379  }
3380  return result;
3381 }
3382 
3383 static int AddressTestAddressGroupSetup12 (void)
3384 {
3385  int result = 0;
3386  DetectAddressHead *gh = DetectAddressHeadInit();
3387 
3388  if (gh != NULL) {
3389  int r = DetectAddressParse(NULL, gh, "10.10.10.10-10.10.11.1", NULL);
3390  if (r == 0) {
3391  r = DetectAddressParse(NULL, gh, "0.0.0.0/0", NULL);
3392  if (r == 0) {
3393  r = DetectAddressParse(NULL, gh, "10.10.10.0/24", NULL);
3394  if (r == 0) {
3395  DetectAddress *one = gh->ipv4_head, *two = one->next,
3396  *three = two->next, *four = three->next,
3397  *five = four->next;
3398 
3399  /* result should be:
3400  * 0.0.0.0/10.10.9.255
3401  * 10.10.10.0/10.10.10.9
3402  * 10.10.10.10/10.10.10.255
3403  * 10.10.11.0/10.10.11.1
3404  * 10.10.11.2/255.255.255.255
3405  */
3406  if (one->ip.addr_data32[0] == 0x00000000 && one->ip2.addr_data32[0] == SCNtohl(168430079) &&
3407  two->ip.addr_data32[0] == SCNtohl(168430080) && two->ip2.addr_data32[0] == SCNtohl(168430089) &&
3408  three->ip.addr_data32[0] == SCNtohl(168430090) && three->ip2.addr_data32[0] == SCNtohl(168430335) &&
3409  four->ip.addr_data32[0] == SCNtohl(168430336) && four->ip2.addr_data32[0] == SCNtohl(168430337) &&
3410  five->ip.addr_data32[0] == SCNtohl(168430338) && five->ip2.addr_data32[0] == 0xFFFFFFFF) {
3411  result = 1;
3412  }
3413  }
3414  }
3415  }
3416 
3417  DetectAddressHeadFree(gh);
3418  }
3419  return result;
3420 }
3421 
3422 static int AddressTestAddressGroupSetup13(void)
3423 {
3424  int result = 0;
3425  DetectAddressHead *gh = DetectAddressHeadInit();
3426 
3427  if (gh != NULL) {
3428  int r = DetectAddressParse(NULL, gh, "0.0.0.0/0", NULL);
3429  if (r == 0) {
3430  r = DetectAddressParse(NULL, gh, "10.10.10.10-10.10.11.1", NULL);
3431  if (r == 0) {
3432  r = DetectAddressParse(NULL, gh, "10.10.10.0/24", NULL);
3433  if (r == 0) {
3434  DetectAddress *one = gh->ipv4_head, *two = one->next,
3435  *three = two->next, *four = three->next,
3436  *five = four->next;
3437 
3438  /* result should be:
3439  * 0.0.0.0/10.10.9.255
3440  * 10.10.10.0/10.10.10.9
3441  * 10.10.10.10/10.10.10.255
3442  * 10.10.11.0/10.10.11.1
3443  * 10.10.11.2/255.255.255.255
3444  */
3445  if (one->ip.addr_data32[0] == 0x00000000 && one->ip2.addr_data32[0] == SCNtohl(168430079) &&
3446  two->ip.addr_data32[0] == SCNtohl(168430080) && two->ip2.addr_data32[0] == SCNtohl(168430089) &&
3447  three->ip.addr_data32[0] == SCNtohl(168430090) && three->ip2.addr_data32[0] == SCNtohl(168430335) &&
3448  four->ip.addr_data32[0] == SCNtohl(168430336) && four->ip2.addr_data32[0] == SCNtohl(168430337) &&
3449  five->ip.addr_data32[0] == SCNtohl(168430338) && five->ip2.addr_data32[0] == 0xFFFFFFFF) {
3450  result = 1;
3451  }
3452  }
3453  }
3454  }
3455 
3456  DetectAddressHeadFree(gh);
3457  }
3458  return result;
3459 }
3460 
3461 static int AddressTestAddressGroupSetupIPv414(void)
3462 {
3463  DetectAddressHead *gh = DetectAddressHeadInit();
3464  FAIL_IF_NULL(gh);
3465 
3466  int r = DetectAddressParse(NULL, gh, "!1.2.3.4", NULL);
3467  FAIL_IF_NOT(r == 1);
3468 
3469  DetectAddress *one = gh->ipv4_head;
3470  FAIL_IF_NULL(one);
3471  DetectAddress *two = one->next;
3472  FAIL_IF_NULL(two);
3473 
3474  /* result should be:
3475  * 0.0.0.0/1.2.3.3
3476  * 1.2.3.5/255.255.255.255
3477  */
3478  FAIL_IF_NOT(one->ip.addr_data32[0] == 0x00000000);
3479  FAIL_IF_NOT(one->ip2.addr_data32[0] == SCNtohl(16909059));
3480  FAIL_IF_NOT(two->ip.addr_data32[0] == SCNtohl(16909061));
3481  FAIL_IF_NOT(two->ip2.addr_data32[0] == 0xFFFFFFFF);
3482  DetectAddressHeadFree(gh);
3483 
3484  PASS;
3485 }
3486 
3487 static int AddressTestAddressGroupSetupIPv415(void)
3488 {
3489  DetectAddressHead *gh = DetectAddressHeadInit();
3490  FAIL_IF_NULL(gh);
3491 
3492  int r = DetectAddressParse(NULL, gh, "!0.0.0.0", NULL);
3493  FAIL_IF_NOT(r == 1);
3494 
3495  DetectAddress *one = gh->ipv4_head;
3496  FAIL_IF_NULL(one);
3497  FAIL_IF_NOT_NULL(one->next);
3498 
3499  /* result should be:
3500  * 0.0.0.1/255.255.255.255
3501  */
3502  FAIL_IF_NOT(one->ip.addr_data32[0] == SCNtohl(1));
3503  FAIL_IF_NOT(one->ip2.addr_data32[0] == 0xFFFFFFFF);
3504 
3505  DetectAddressHeadFree(gh);
3506  PASS;
3507 }
3508 
3509 static int AddressTestAddressGroupSetupIPv416(void)
3510 {
3511  DetectAddressHead *gh = DetectAddressHeadInit();
3512  FAIL_IF_NULL(gh);
3513 
3514  int r = DetectAddressParse(NULL, gh, "!255.255.255.255", NULL);
3515  FAIL_IF_NOT(r == 1);
3516 
3517  DetectAddress *one = gh->ipv4_head;
3518  FAIL_IF_NULL(one);
3519  FAIL_IF_NOT_NULL(one->next);
3520 
3521  /* result should be:
3522  * 0.0.0.0/255.255.255.254
3523  */
3524  FAIL_IF_NOT(one->ip.addr_data32[0] == 0x00000000);
3525  FAIL_IF_NOT(one->ip2.addr_data32[0] == SCNtohl(4294967294));
3526 
3527  DetectAddressHeadFree(gh);
3528  PASS;
3529 }
3530 
3531 static int AddressTestAddressGroupSetup14(void)
3532 {
3533  int result = 0;
3534  DetectAddressHead *gh = DetectAddressHeadInit();
3535 
3536  if (gh != NULL) {
3537  int r = DetectAddressParse(NULL, gh, "2001::1", NULL);
3538  if (r == 0)
3539  result = 1;
3540 
3541  DetectAddressHeadFree(gh);
3542  }
3543  return result;
3544 }
3545 
3546 static int AddressTestAddressGroupSetup15(void)
3547 {
3548  int result = 0;
3549  DetectAddressHead *gh = DetectAddressHeadInit();
3550 
3551  if (gh != NULL) {
3552  int r = DetectAddressParse(NULL, gh, "2001::1", NULL);
3553  if (r == 0 && gh->ipv6_head != NULL)
3554  result = 1;
3555 
3556  DetectAddressHeadFree(gh);
3557  }
3558  return result;
3559 }
3560 
3561 static int AddressTestAddressGroupSetup16(void)
3562 {
3563  int result = 0;
3564  DetectAddressHead *gh = DetectAddressHeadInit();
3565 
3566  if (gh != NULL) {
3567  int r = DetectAddressParse(NULL, gh, "2001::4", NULL);
3568  if (r == 0 && gh->ipv6_head != NULL) {
3569  DetectAddress *prev_head = gh->ipv6_head;
3570 
3571  r = DetectAddressParse(NULL, gh, "2001::3", NULL);
3572  if (r == 0 && gh->ipv6_head != prev_head &&
3573  gh->ipv6_head != NULL && gh->ipv6_head->next == prev_head) {
3574  result = 1;
3575  }
3576  }
3577 
3578  DetectAddressHeadFree(gh);
3579  }
3580  return result;
3581 }
3582 
3583 static int AddressTestAddressGroupSetup17(void)
3584 {
3585  int result = 0;
3586  DetectAddressHead *gh = DetectAddressHeadInit();
3587 
3588  if (gh != NULL) {
3589  int r = DetectAddressParse(NULL, gh, "2001::4", NULL);
3590  if (r == 0 && gh->ipv6_head != NULL) {
3591  DetectAddress *prev_head = gh->ipv6_head;
3592 
3593  r = DetectAddressParse(NULL, gh, "2001::3", NULL);
3594  if (r == 0 && gh->ipv6_head != prev_head &&
3595  gh->ipv6_head != NULL && gh->ipv6_head->next == prev_head) {
3596  DetectAddress *ph = gh->ipv6_head;
3597 
3598  r = DetectAddressParse(NULL, gh, "2001::2", NULL);
3599  if (r == 0 && gh->ipv6_head != ph &&
3600  gh->ipv6_head != NULL && gh->ipv6_head->next == ph) {
3601  result = 1;
3602  }
3603  }
3604  }
3605 
3606  DetectAddressHeadFree(gh);
3607  }
3608  return result;
3609 }
3610 
3611 static int AddressTestAddressGroupSetup18(void)
3612 {
3613  int result = 0;
3614  DetectAddressHead *gh = DetectAddressHeadInit();
3615 
3616  if (gh != NULL) {
3617  int r = DetectAddressParse(NULL, gh, "2001::2", NULL);
3618  if (r == 0 && gh->ipv6_head != NULL) {
3619  DetectAddress *prev_head = gh->ipv6_head;
3620 
3621  r = DetectAddressParse(NULL, gh, "2001::3", NULL);
3622  if (r == 0 && gh->ipv6_head == prev_head &&
3623  gh->ipv6_head != NULL && gh->ipv6_head->next != prev_head) {
3624  DetectAddress *ph = gh->ipv6_head;
3625 
3626  r = DetectAddressParse(NULL, gh, "2001::4", NULL);
3627  if (r == 0 && gh->ipv6_head == ph &&
3628  gh->ipv6_head != NULL && gh->ipv6_head->next != ph) {
3629  result = 1;
3630  }
3631  }
3632  }
3633 
3634  DetectAddressHeadFree(gh);
3635  }
3636  return result;
3637 }
3638 
3639 static int AddressTestAddressGroupSetup19(void)
3640 {
3641  int result = 0;
3642  DetectAddressHead *gh = DetectAddressHeadInit();
3643 
3644  if (gh != NULL) {
3645  int r = DetectAddressParse(NULL, gh, "2001::2", NULL);
3646  if (r == 0 && gh->ipv6_head != NULL) {
3647  DetectAddress *prev_head = gh->ipv6_head;
3648 
3649  r = DetectAddressParse(NULL, gh, "2001::2", NULL);
3650  if (r == 0 && gh->ipv6_head == prev_head &&
3651  gh->ipv6_head != NULL && gh->ipv6_head->next == NULL) {
3652  result = 1;
3653  }
3654  }
3655 
3656  DetectAddressHeadFree(gh);
3657  }
3658  return result;
3659 }
3660 
3661 static int AddressTestAddressGroupSetup20(void)
3662 {
3663  int result = 0;
3664  DetectAddressHead *gh = DetectAddressHeadInit();
3665 
3666  if (gh != NULL) {
3667  int r = DetectAddressParse(NULL, gh, "2000::/3", NULL);
3668  if (r == 0 && gh->ipv6_head != NULL) {
3669  r = DetectAddressParse(NULL, gh, "2001::4", NULL);
3670  if (r == 0 && gh->ipv6_head != NULL &&
3671  gh->ipv6_head->next != NULL &&
3672  gh->ipv6_head->next->next != NULL) {
3673  result = 1;
3674  }
3675  }
3676 
3677  DetectAddressHeadFree(gh);
3678  }
3679  return result;
3680 }
3681 
3682 static int AddressTestAddressGroupSetup21(void)
3683 {
3684  int result = 0;
3685  DetectAddressHead *gh = DetectAddressHeadInit();
3686 
3687  if (gh != NULL) {
3688  int r = DetectAddressParse(NULL, gh, "2001::4", NULL);
3689  if (r == 0 && gh->ipv6_head != NULL) {
3690  r = DetectAddressParse(NULL, gh, "2000::/3", NULL);
3691  if (r == 0 && gh->ipv6_head != NULL &&
3692  gh->ipv6_head->next != NULL &&
3693  gh->ipv6_head->next->next != NULL) {
3694  result = 1;
3695  }
3696  }
3697 
3698  DetectAddressHeadFree(gh);
3699  }
3700  return result;
3701 }
3702 
3703 static int AddressTestAddressGroupSetup22(void)
3704 {
3705  int result = 0;
3706  DetectAddressHead *gh = DetectAddressHeadInit();
3707 
3708  if (gh != NULL) {
3709  int r = DetectAddressParse(NULL, gh, "2000::/3", NULL);
3710  if (r == 0 && gh->ipv6_head != NULL) {
3711  r = DetectAddressParse(NULL, gh, "2001::4-2001::6", NULL);
3712  if (r == 0 && gh->ipv6_head != NULL &&
3713  gh->ipv6_head->next != NULL &&
3714  gh->ipv6_head->next->next != NULL) {
3715  result = 1;
3716  }
3717  }
3718 
3719  DetectAddressHeadFree(gh);
3720  }
3721  return result;
3722 }
3723 
3724 static int AddressTestAddressGroupSetup23(void)
3725 {
3726  int result = 0;
3727  DetectAddressHead *gh = DetectAddressHeadInit();
3728 
3729  if (gh != NULL) {
3730  int r = DetectAddressParse(NULL, gh, "2001::4-2001::6", NULL);
3731  if (r == 0 && gh->ipv6_head != NULL) {
3732  r = DetectAddressParse(NULL, gh, "2000::/3", NULL);
3733  if (r == 0 && gh->ipv6_head != NULL &&
3734  gh->ipv6_head->next != NULL &&
3735  gh->ipv6_head->next->next != NULL) {
3736  result = 1;
3737  }
3738  }
3739 
3740  DetectAddressHeadFree(gh);
3741  }
3742  return result;
3743 }
3744 
3745 static int AddressTestAddressGroupSetup24(void)
3746 {
3747  int result = 0;
3748  DetectAddressHead *gh = DetectAddressHeadInit();
3749 
3750  if (gh != NULL) {
3751  int r = DetectAddressParse(NULL, gh, "2001::4-2001::6", NULL);
3752  if (r == 0) {
3753  r = DetectAddressParse(NULL, gh, "2001::/3", NULL);
3754  if (r == 0) {
3755  r = DetectAddressParse(NULL, gh, "::/0", NULL);
3756  if (r == 0) {
3757  DetectAddress *one = gh->ipv6_head, *two = one->next,
3758  *three = two->next, *four = three->next,
3759  *five = four->next;
3760  if (one->ip.addr_data32[0] == 0x00000000 &&
3761  one->ip.addr_data32[1] == 0x00000000 &&
3762  one->ip.addr_data32[2] == 0x00000000 &&
3763  one->ip.addr_data32[3] == 0x00000000 &&
3764  one->ip2.addr_data32[0] == SCNtohl(536870911) &&
3765  one->ip2.addr_data32[1] == 0xFFFFFFFF &&
3766  one->ip2.addr_data32[2] == 0xFFFFFFFF &&
3767  one->ip2.addr_data32[3] == 0xFFFFFFFF &&
3768 
3769  two->ip.addr_data32[0] == SCNtohl(536870912) &&
3770  two->ip.addr_data32[1] == 0x00000000 &&
3771  two->ip.addr_data32[2] == 0x00000000 &&
3772  two->ip.addr_data32[3] == 0x00000000 &&
3773  two->ip2.addr_data32[0] == SCNtohl(536936448) &&
3774  two->ip2.addr_data32[1] == 0x00000000 &&
3775  two->ip2.addr_data32[2] == 0x00000000 &&
3776  two->ip2.addr_data32[3] == SCNtohl(3) &&
3777 
3778  three->ip.addr_data32[0] == SCNtohl(536936448) &&
3779  three->ip.addr_data32[1] == 0x00000000 &&
3780  three->ip.addr_data32[2] == 0x00000000 &&
3781  three->ip.addr_data32[3] == SCNtohl(4) &&
3782  three->ip2.addr_data32[0] == SCNtohl(536936448) &&
3783  three->ip2.addr_data32[1] == 0x00000000 &&
3784  three->ip2.addr_data32[2] == 0x00000000 &&
3785  three->ip2.addr_data32[3] == SCNtohl(6) &&
3786 
3787  four->ip.addr_data32[0] == SCNtohl(536936448) &&
3788  four->ip.addr_data32[1] == 0x00000000 &&
3789  four->ip.addr_data32[2] == 0x00000000 &&
3790  four->ip.addr_data32[3] == SCNtohl(7) &&
3791  four->ip2.addr_data32[0] == SCNtohl(1073741823) &&
3792  four->ip2.addr_data32[1] == 0xFFFFFFFF &&
3793  four->ip2.addr_data32[2] == 0xFFFFFFFF &&
3794  four->ip2.addr_data32[3] == 0xFFFFFFFF &&
3795 
3796  five->ip.addr_data32[0] == SCNtohl(1073741824) &&
3797  five->ip.addr_data32[1] == 0x00000000 &&
3798  five->ip.addr_data32[2] == 0x00000000 &&
3799  five->ip.addr_data32[3] == 0x00000000 &&
3800  five->ip2.addr_data32[0] == 0xFFFFFFFF &&
3801  five->ip2.addr_data32[1] == 0xFFFFFFFF &&
3802  five->ip2.addr_data32[2] == 0xFFFFFFFF &&
3803  five->ip2.addr_data32[3] == 0xFFFFFFFF) {
3804  result = 1;
3805  }
3806  }
3807  }
3808  }
3809 
3810  DetectAddressHeadFree(gh);
3811  }
3812  return result;
3813 }
3814 
3815 static int AddressTestAddressGroupSetup25(void)
3816 {
3817  int result = 0;
3818  DetectAddressHead *gh = DetectAddressHeadInit();
3819 
3820  if (gh != NULL) {
3821  int r = DetectAddressParse(NULL, gh, "2001::4-2001::6", NULL);
3822  if (r == 0) {
3823  r = DetectAddressParse(NULL, gh, "::/0", NULL);
3824  if (r == 0) {
3825  r = DetectAddressParse(NULL, gh, "2001::/3", NULL);
3826  if (r == 0) {
3827  DetectAddress *one = gh->ipv6_head, *two = one->next,
3828  *three = two->next, *four = three->next,
3829  *five = four->next;
3830  if (one->ip.addr_data32[0] == 0x00000000 &&
3831  one->ip.addr_data32[1] == 0x00000000 &&
3832  one->ip.addr_data32[2] == 0x00000000 &&
3833  one->ip.addr_data32[3] == 0x00000000 &&
3834  one->ip2.addr_data32[0] == SCNtohl(536870911) &&
3835  one->ip2.addr_data32[1] == 0xFFFFFFFF &&
3836  one->ip2.addr_data32[2] == 0xFFFFFFFF &&
3837  one->ip2.addr_data32[3] == 0xFFFFFFFF &&
3838 
3839  two->ip.addr_data32[0] == SCNtohl(536870912) &&
3840  two->ip.addr_data32[1] == 0x00000000 &&
3841  two->ip.addr_data32[2] == 0x00000000 &&
3842  two->ip.addr_data32[3] == 0x00000000 &&
3843  two->ip2.addr_data32[0] == SCNtohl(536936448) &&
3844  two->ip2.addr_data32[1] == 0x00000000 &&
3845  two->ip2.addr_data32[2] == 0x00000000 &&
3846  two->ip2.addr_data32[3] == SCNtohl(3) &&
3847 
3848  three->ip.addr_data32[0] == SCNtohl(536936448) &&
3849  three->ip.addr_data32[1] == 0x00000000 &&
3850  three->ip.addr_data32[2] == 0x00000000 &&
3851  three->ip.addr_data32[3] == SCNtohl(4) &&
3852  three->ip2.addr_data32[0] == SCNtohl(536936448) &&
3853  three->ip2.addr_data32[1] == 0x00000000 &&
3854  three->ip2.addr_data32[2] == 0x00000000 &&
3855  three->ip2.addr_data32[3] == SCNtohl(6) &&
3856 
3857  four->ip.addr_data32[0] == SCNtohl(536936448) &&
3858  four->ip.addr_data32[1] == 0x00000000 &&
3859  four->ip.addr_data32[2] == 0x00000000 &&
3860  four->ip.addr_data32[3] == SCNtohl(7) &&
3861  four->ip2.addr_data32[0] == SCNtohl(1073741823) &&
3862  four->ip2.addr_data32[1] == 0xFFFFFFFF &&
3863  four->ip2.addr_data32[2] == 0xFFFFFFFF &&
3864  four->ip2.addr_data32[3] == 0xFFFFFFFF &&
3865 
3866  five->ip.addr_data32[0] == SCNtohl(1073741824) &&
3867  five->ip.addr_data32[1] == 0x00000000 &&
3868  five->ip.addr_data32[2] == 0x00000000 &&
3869  five->ip.addr_data32[3] == 0x00000000 &&
3870  five->ip2.addr_data32[0] == 0xFFFFFFFF &&
3871  five->ip2.addr_data32[1] == 0xFFFFFFFF &&
3872  five->ip2.addr_data32[2] == 0xFFFFFFFF &&
3873  five->ip2.addr_data32[3] == 0xFFFFFFFF) {
3874  result = 1;
3875  }
3876  }
3877  }
3878  }
3879 
3880  DetectAddressHeadFree(gh);
3881  }
3882  return result;
3883 }
3884 
3885 static int AddressTestAddressGroupSetup26(void)
3886 {
3887  int result = 0;
3888  DetectAddressHead *gh = DetectAddressHeadInit();
3889 
3890  if (gh != NULL) {
3891  int r = DetectAddressParse(NULL, gh, "::/0", NULL);
3892  if (r == 0) {
3893  r = DetectAddressParse(NULL, gh, "2001::4-2001::6", NULL);
3894  if (r == 0) {
3895  r = DetectAddressParse(NULL, gh, "2001::/3", NULL);
3896  if (r == 0) {
3897  DetectAddress *one = gh->ipv6_head, *two = one->next,
3898  *three = two->next, *four = three->next,
3899  *five = four->next;
3900  if (one->ip.addr_data32[0] == 0x00000000 &&
3901  one->ip.addr_data32[1] == 0x00000000 &&
3902  one->ip.addr_data32[2] == 0x00000000 &&
3903  one->ip.addr_data32[3] == 0x00000000 &&
3904  one->ip2.addr_data32[0] == SCNtohl(536870911) &&
3905  one->ip2.addr_data32[1] == 0xFFFFFFFF &&
3906  one->ip2.addr_data32[2] == 0xFFFFFFFF &&
3907  one->ip2.addr_data32[3] == 0xFFFFFFFF &&
3908 
3909  two->ip.addr_data32[0] == SCNtohl(536870912) &&
3910  two->ip.addr_data32[1] == 0x00000000 &&
3911  two->ip.addr_data32[2] == 0x00000000 &&
3912  two->ip.addr_data32[3] == 0x00000000 &&
3913  two->ip2.addr_data32[0] == SCNtohl(536936448) &&
3914  two->ip2.addr_data32[1] == 0x00000000 &&
3915  two->ip2.addr_data32[2] == 0x00000000 &&
3916  two->ip2.addr_data32[3] == SCNtohl(3) &&
3917 
3918  three->ip.addr_data32[0] == SCNtohl(536936448) &&
3919  three->ip.addr_data32[1] == 0x00000000 &&
3920  three->ip.addr_data32[2] == 0x00000000 &&
3921  three->ip.addr_data32[3] == SCNtohl(4) &&
3922  three->ip2.addr_data32[0] == SCNtohl(536936448) &&
3923  three->ip2.addr_data32[1] == 0x00000000 &&
3924  three->ip2.addr_data32[2] == 0x00000000 &&
3925  three->ip2.addr_data32[3] == SCNtohl(6) &&
3926 
3927  four->ip.addr_data32[0] == SCNtohl(536936448) &&
3928  four->ip.addr_data32[1] == 0x00000000 &&
3929  four->ip.addr_data32[2] == 0x00000000 &&
3930  four->ip.addr_data32[3] == SCNtohl(7) &&
3931  four->ip2.addr_data32[0] == SCNtohl(1073741823) &&
3932  four->ip2.addr_data32[1] == 0xFFFFFFFF &&
3933  four->ip2.addr_data32[2] == 0xFFFFFFFF &&
3934  four->ip2.addr_data32[3] == 0xFFFFFFFF &&
3935 
3936  five->ip.addr_data32[0] == SCNtohl(1073741824) &&
3937  five->ip.addr_data32[1] == 0x00000000 &&
3938  five->ip.addr_data32[2] == 0x00000000 &&
3939  five->ip.addr_data32[3] == 0x00000000 &&
3940  five->ip2.addr_data32[0] == 0xFFFFFFFF &&
3941  five->ip2.addr_data32[1] == 0xFFFFFFFF &&
3942  five->ip2.addr_data32[2] == 0xFFFFFFFF &&
3943  five->ip2.addr_data32[3] == 0xFFFFFFFF) {
3944  result = 1;
3945  }
3946  }
3947  }
3948  }
3949 
3950  DetectAddressHeadFree(gh);
3951  }
3952  return result;
3953 }
3954 
3955 static int AddressTestAddressGroupSetup27(void)
3956 {
3957  int result = 0;
3958  DetectAddressHead *gh = DetectAddressHeadInit();
3959 
3960  if (gh != NULL) {
3961  int r = DetectAddressParse(NULL, gh, "[1.2.3.4]", NULL);
3962  if (r == 0)
3963  result = 1;
3964 
3965  DetectAddressHeadFree(gh);
3966  }
3967  return result;
3968 }
3969 
3970 static int AddressTestAddressGroupSetup28(void)
3971 {
3972  int result = 0;
3973  DetectAddressHead *gh = DetectAddressHeadInit();
3974 
3975  if (gh != NULL) {
3976  int r = DetectAddressParse(NULL, gh, "[1.2.3.4,4.3.2.1]", NULL);
3977  if (r == 0)
3978  result = 1;
3979 
3980  DetectAddressHeadFree(gh);
3981  }
3982  return result;
3983 }
3984 
3985 static int AddressTestAddressGroupSetup29(void)
3986 {
3987  int result = 0;
3988  DetectAddressHead *gh = DetectAddressHeadInit();
3989 
3990  if (gh != NULL) {
3991  int r = DetectAddressParse(NULL, gh, "[1.2.3.4,4.3.2.1,10.10.10.10]", NULL);
3992  if (r == 0)
3993  result = 1;
3994 
3995  DetectAddressHeadFree(gh);
3996  }
3997  return result;
3998 }
3999 
4000 static int AddressTestAddressGroupSetup30(void)
4001 {
4002  int result = 0;
4003  DetectAddressHead *gh = DetectAddressHeadInit();
4004 
4005  if (gh != NULL) {
4006  int r = DetectAddressParse(
4007  NULL, gh, "[[1.2.3.4,2.3.4.5],4.3.2.1,[10.10.10.10,11.11.11.11]]", NULL);
4008  if (r == 0)
4009  result = 1;
4010 
4011  DetectAddressHeadFree(gh);
4012  }
4013  return result;
4014 }
4015 
4016 static int AddressTestAddressGroupSetup31(void)
4017 {
4018  int result = 0;
4019  DetectAddressHead *gh = DetectAddressHeadInit();
4020 
4021  if (gh != NULL) {
4022  int r = DetectAddressParse(NULL, gh,
4023  "[[1.2.3.4,[2.3.4.5,3.4.5.6]],4.3.2.1,[10.10.10.10,[11.11.11.11,12.12.12.12]]]",
4024  NULL);
4025  if (r == 0)
4026  result = 1;
4027 
4028  DetectAddressHeadFree(gh);
4029  }
4030  return result;
4031 }
4032 
4033 static int AddressTestAddressGroupSetup32(void)
4034 {
4035  int result = 0;
4036  DetectAddressHead *gh = DetectAddressHeadInit();
4037 
4038  if (gh != NULL) {
4039  int r = DetectAddressParse(NULL, gh,
4040  "[[1.2.3.4,[2.3.4.5,[3.4.5.6,4.5.6.7]]],4.3.2.1,[10.10.10.10,[11.11.11.11,[12.12."
4041  "12.12,13.13.13.13]]]]",
4042  NULL);
4043  if (r == 0)
4044  result = 1;
4045 
4046  DetectAddressHeadFree(gh);
4047  }
4048  return result;
4049 }
4050 
4051 static int AddressTestAddressGroupSetup33(void)
4052 {
4053  int result = 0;
4054  DetectAddressHead *gh = DetectAddressHeadInit();
4055 
4056  if (gh != NULL) {
4057  int r = DetectAddressParse(NULL, gh, "![1.1.1.1,[2.2.2.2,[3.3.3.3,4.4.4.4]]]", NULL);
4058  if (r == 1)
4059  result = 1;
4060 
4061  DetectAddressHeadFree(gh);
4062  }
4063  return result;
4064 }
4065 
4066 static int AddressTestAddressGroupSetup34(void)
4067 {
4068  int result = 0;
4069  DetectAddressHead *gh = DetectAddressHeadInit();
4070 
4071  if (gh != NULL) {
4072  int r = DetectAddressParse(NULL, gh, "[1.0.0.0/8,![1.1.1.1,[1.2.1.1,1.3.1.1]]]", NULL);
4073  if (r == 1)
4074  result = 1;
4075 
4076  DetectAddressHeadFree(gh);
4077  }
4078  return result;
4079 }
4080 
4081 static int AddressTestAddressGroupSetup35(void)
4082 {
4083  int result = 0;
4084  DetectAddressHead *gh = DetectAddressHeadInit();
4085 
4086  if (gh != NULL) {
4087  int r = DetectAddressParse(NULL, gh, "[1.0.0.0/8,[2.0.0.0/8,![1.1.1.1,2.2.2.2]]]", NULL);
4088  if (r == 1)
4089  result = 1;
4090 
4091  DetectAddressHeadFree(gh);
4092  }
4093  return result;
4094 }
4095 
4096 static int AddressTestAddressGroupSetup36 (void)
4097 {
4098  int result = 0;
4099 
4100  DetectAddressHead *gh = DetectAddressHeadInit();
4101  if (gh != NULL) {
4102  int r = DetectAddressParse(NULL, gh, "[1.0.0.0/8,[2.0.0.0/8,[3.0.0.0/8,!1.1.1.1]]]", NULL);
4103  if (r == 1)
4104  result = 1;
4105 
4106  DetectAddressHeadFree(gh);
4107  }
4108  return result;
4109 }
4110 
4111 static int AddressTestAddressGroupSetup37(void)
4112 {
4113  int result = 0;
4114  DetectAddressHead *gh = DetectAddressHeadInit();
4115 
4116  if (gh != NULL) {
4117  int r = DetectAddressParse(NULL, gh, "[0.0.0.0/0,::/0]", NULL);
4118  if (r == 0)
4119  result = 1;
4120 
4121  DetectAddressHeadFree(gh);
4122  }
4123  return result;
4124 }
4125 
4126 static int AddressTestAddressGroupSetup38(void)
4127 {
4128  UTHValidateDetectAddressHeadRange expectations[3] = {
4129  { "0.0.0.0", "192.167.255.255" },
4130  { "192.168.14.0", "192.168.14.255" },
4131  { "192.169.0.0", "255.255.255.255" } };
4132  int result = 0;
4133  DetectAddressHead *gh = DetectAddressHeadInit();
4134 
4135  if (gh != NULL) {
4136  int r = DetectAddressParse(NULL, gh, "![192.168.0.0/16,!192.168.14.0/24]", NULL);
4137  if (r == 1) {
4138  if (UTHValidateDetectAddressHead(gh, 3, expectations))
4139  result = 1;
4140  }
4141 
4142  DetectAddressHeadFree(gh);
4143  }
4144  return result;
4145 }
4146 
4147 static int AddressTestAddressGroupSetup39(void)
4148 {
4149  UTHValidateDetectAddressHeadRange expectations[3] = {
4150  { "0.0.0.0", "192.167.255.255" },
4151  { "192.168.14.0", "192.168.14.255" },
4152  { "192.169.0.0", "255.255.255.255" } };
4153  int result = 0;
4154  DetectAddressHead *gh = DetectAddressHeadInit();
4155 
4156  if (gh != NULL) {
4157  int r = DetectAddressParse(NULL, gh, "[![192.168.0.0/16,!192.168.14.0/24]]", NULL);
4158  if (r == 1) {
4159  if (UTHValidateDetectAddressHead(gh, 3, expectations))
4160  result = 1;
4161  }
4162 
4163  DetectAddressHeadFree(gh);
4164  }
4165  return result;
4166 }
4167 
4168 static int AddressTestAddressGroupSetup40(void)
4169 {
4170  UTHValidateDetectAddressHeadRange expectations[3] = {
4171  { "0.0.0.0", "192.167.255.255" },
4172  { "192.168.14.0", "192.168.14.255" },
4173  { "192.169.0.0", "255.255.255.255" } };
4174  int result = 0;
4175  DetectAddressHead *gh = DetectAddressHeadInit();
4176  if (gh != NULL) {
4177  int r = DetectAddressParse(NULL, gh, "[![192.168.0.0/16,[!192.168.14.0/24]]]", NULL);
4178  if (r == 1) {
4179  if (UTHValidateDetectAddressHead(gh, 3, expectations))
4180  result = 1;
4181  }
4182 
4183  DetectAddressHeadFree(gh);
4184  }
4185  return result;
4186 }
4187 
4188 static int AddressTestAddressGroupSetup41(void)
4189 {
4190  UTHValidateDetectAddressHeadRange expectations[3] = {
4191  { "0.0.0.0", "192.167.255.255" },
4192  { "192.168.14.0", "192.168.14.255" },
4193  { "192.169.0.0", "255.255.255.255" } };
4194  int result = 0;
4195  DetectAddressHead *gh = DetectAddressHeadInit();
4196  if (gh != NULL) {
4197  int r = DetectAddressParse(NULL, gh, "[![192.168.0.0/16,![192.168.14.0/24]]]", NULL);
4198  if (r == 1) {
4199  if (UTHValidateDetectAddressHead(gh, 3, expectations))
4200  result = 1;
4201  }
4202 
4203  DetectAddressHeadFree(gh);
4204  }
4205  return result;
4206 }
4207 
4208 static int AddressTestAddressGroupSetup42(void)
4209 {
4210  UTHValidateDetectAddressHeadRange expectations[1] = {
4211  { "2000:0000:0000:0000:0000:0000:0000:0000", "3fff:ffff:ffff:ffff:ffff:ffff:ffff:ffff" } };
4212  int result = 0;
4213  DetectAddressHead *gh = DetectAddressHeadInit();
4214  if (gh != NULL) {
4215  int r = DetectAddressParse(NULL, gh, "[2001::/3]", NULL);
4216  if (r == 0) {
4217  if (UTHValidateDetectAddressHead(gh, 1, expectations))
4218  result = 1;
4219  }
4220 
4221  DetectAddressHeadFree(gh);
4222  }
4223  return result;
4224 }
4225 
4226 static int AddressTestAddressGroupSetup43(void)
4227 {
4228  UTHValidateDetectAddressHeadRange expectations[2] = {
4229  { "2000:0000:0000:0000:0000:0000:0000:0000", "2fff:ffff:ffff:ffff:ffff:ffff:ffff:ffff" },
4230  { "3800:0000:0000:0000:0000:0000:0000:0000", "3fff:ffff:ffff:ffff:ffff:ffff:ffff:ffff" } };
4231  int result = 0;
4232  DetectAddressHead *gh = DetectAddressHeadInit();
4233  if (gh != NULL) {
4234  int r = DetectAddressParse(NULL, gh, "[2001::/3,!3000::/5]", NULL);
4235  if (r == 1) {
4236  if (UTHValidateDetectAddressHead(gh, 2, expectations))
4237  result = 1;
4238  }
4239 
4240  DetectAddressHeadFree(gh);
4241  }
4242  return result;
4243 }
4244 
4245 static int AddressTestAddressGroupSetup44(void)
4246 {
4247  UTHValidateDetectAddressHeadRange expectations[2] = {
4248  { "3ffe:ffff:7654:feda:1245:ba98:0000:0000", "3ffe:ffff:7654:feda:1245:ba98:ffff:ffff" }};
4249  int result = 0;
4250  DetectAddressHead *gh = DetectAddressHeadInit();
4251  if (gh != NULL) {
4252  int r = DetectAddressParse(NULL, gh, "3ffe:ffff:7654:feda:1245:ba98:3210:4562/96", NULL);
4253  if (r == 0) {
4254  if (UTHValidateDetectAddressHead(gh, 1, expectations))
4255  result = 1;
4256  }
4257 
4258  DetectAddressHeadFree(gh);
4259  }
4260  return result;
4261 }
4262 
4263 static int AddressTestAddressGroupSetup45(void)
4264 {
4265  int result = 0;
4266  DetectAddressHead *gh = DetectAddressHeadInit();
4267  if (gh != NULL) {
4268  int r = DetectAddressParse(NULL, gh, "[192.168.1.3,!192.168.0.0/16]", NULL);
4269  if (r != 0) {
4270  result = 1;
4271  }
4272 
4273  DetectAddressHeadFree(gh);
4274  }
4275  return result;
4276 }
4277 
4278 static int AddressTestAddressGroupSetup46(void)
4279 {
4280  UTHValidateDetectAddressHeadRange expectations[4] = {
4281  { "0.0.0.0", "192.167.255.255" },
4282  { "192.168.1.0", "192.168.1.255" },
4283  { "192.168.3.0", "192.168.3.255" },
4284  { "192.169.0.0", "255.255.255.255" } };
4285  int result = 0;
4286  DetectAddressHead *gh = DetectAddressHeadInit();
4287  if (gh != NULL) {
4288  int r = DetectAddressParse(
4289  NULL, gh, "[![192.168.0.0/16,![192.168.1.0/24,192.168.3.0/24]]]", NULL);
4290  if (r == 1) {
4291  if (UTHValidateDetectAddressHead(gh, 4, expectations))
4292  result = 1;
4293  }
4294 
4295  DetectAddressHeadFree(gh);
4296  }
4297  return result;
4298 }
4299 
4300 /** \test net with some negations, then all negated */
4301 static int AddressTestAddressGroupSetup47(void)
4302 {
4303  UTHValidateDetectAddressHeadRange expectations[5] = {
4304  { "0.0.0.0", "192.167.255.255" },
4305  { "192.168.1.0", "192.168.1.255" },
4306  { "192.168.3.0", "192.168.3.255" },
4307  { "192.168.5.0", "192.168.5.255" },
4308  { "192.169.0.0", "255.255.255.255" } };
4309  int result = 0;
4310  DetectAddressHead *gh = DetectAddressHeadInit();
4311  if (gh != NULL) {
4312  int r = DetectAddressParse(NULL, gh,
4313  "[![192.168.0.0/16,![192.168.1.0/24,192.168.3.0/24],!192.168.5.0/24]]", NULL);
4314  if (r == 1) {
4315  if (UTHValidateDetectAddressHead(gh, 5, expectations))
4316  result = 1;
4317  }
4318 
4319  DetectAddressHeadFree(gh);
4320  }
4321  return result;
4322 }
4323 
4324 /** \test same as AddressTestAddressGroupSetup47, but not negated */
4325 static int AddressTestAddressGroupSetup48(void)
4326 {
4327  UTHValidateDetectAddressHeadRange expectations[4] = {
4328  { "192.168.0.0", "192.168.0.255" },
4329  { "192.168.2.0", "192.168.2.255" },
4330  { "192.168.4.0", "192.168.4.255" },
4331  { "192.168.6.0", "192.168.255.255" } };
4332  int result = 0;
4333  DetectAddressHead *gh = DetectAddressHeadInit();
4334  if (gh != NULL) {
4335  int r = DetectAddressParse(NULL, gh,
4336  "[192.168.0.0/16,![192.168.1.0/24,192.168.3.0/24],!192.168.5.0/24]", NULL);
4337  if (r == 1) {
4338  if (UTHValidateDetectAddressHead(gh, 4, expectations))
4339  result = 1;
4340  }
4341 
4342  DetectAddressHeadFree(gh);
4343  }
4344  return result;
4345 }
4346 
4347 static int AddressTestCutIPv401(void)
4348 {
4349  DetectAddress *c;
4350  DetectAddress *a = DetectAddressParseSingle("1.2.3.0/255.255.255.0");
4351  FAIL_IF_NULL(a);
4352  DetectAddress *b = DetectAddressParseSingle("1.2.2.0-1.2.3.4");
4353  FAIL_IF_NULL(b);
4354 
4355  FAIL_IF(DetectAddressCut(NULL, a, b, &c) == -1);
4356 
4357  DetectAddressFree(a);
4358  DetectAddressFree(b);
4359  DetectAddressFree(c);
4360  PASS;
4361 }
4362 
4363 static int AddressTestCutIPv402(void)
4364 {
4365  DetectAddress *a, *b, *c = NULL;
4366  a = DetectAddressParseSingle("1.2.3.0/255.255.255.0");
4367  b = DetectAddressParseSingle("1.2.2.0-1.2.3.4");
4368 
4369  if (DetectAddressCut(NULL, a, b, &c) == -1)
4370  goto error;
4371 
4372  if (c == NULL)
4373  goto error;
4374 
4375  DetectAddressFree(a);
4376  DetectAddressFree(b);
4377  DetectAddressFree(c);
4378  return 1;
4379 
4380 error:
4381  DetectAddressFree(a);
4382  DetectAddressFree(b);
4383  DetectAddressFree(c);
4384  return 0;
4385 }
4386 
4387 static int AddressTestCutIPv403(void)
4388 {
4389  DetectAddress *a, *b, *c = NULL;
4390  a = DetectAddressParseSingle("1.2.3.0/255.255.255.0");
4391  b = DetectAddressParseSingle("1.2.2.0-1.2.3.4");
4392 
4393  if (DetectAddressCut(NULL, a, b, &c) == -1)
4394  goto error;
4395 
4396  if (c == NULL)
4397  goto error;
4398 
4399  if (a->ip.addr_data32[0] != SCNtohl(16908800) || a->ip2.addr_data32[0] != SCNtohl(16909055))
4400  goto error;
4401  if (b->ip.addr_data32[0] != SCNtohl(16909056) || b->ip2.addr_data32[0] != SCNtohl(16909060))
4402  goto error;
4403  if (c->ip.addr_data32[0] != SCNtohl(16909061) || c->ip2.addr_data32[0] != SCNtohl(16909311))
4404  goto error;
4405 
4406  DetectAddressFree(a);
4407  DetectAddressFree(b);
4408  DetectAddressFree(c);
4409  return 1;
4410 
4411 error:
4412  DetectAddressFree(a);
4413  DetectAddressFree(b);
4414  DetectAddressFree(c);
4415  return 0;
4416 }
4417 
4418 static int AddressTestCutIPv404(void)
4419 {
4420  DetectAddress *a, *b, *c = NULL;
4421  a = DetectAddressParseSingle("1.2.3.3-1.2.3.6");
4422  b = DetectAddressParseSingle("1.2.3.0-1.2.3.5");
4423 
4424  if (DetectAddressCut(NULL, a, b, &c) == -1)
4425  goto error;
4426 
4427  if (c == NULL)
4428  goto error;
4429 
4430  if (a->ip.addr_data32[0] != SCNtohl(16909056) || a->ip2.addr_data32[0] != SCNtohl(16909058))
4431  goto error;
4432  if (b->ip.addr_data32[0] != SCNtohl(16909059) || b->ip2.addr_data32[0] != SCNtohl(16909061))
4433  goto error;
4434  if (c->ip.addr_data32[0] != SCNtohl(16909062) || c->ip2.addr_data32[0] != SCNtohl(16909062))
4435  goto error;
4436 
4437 
4438  DetectAddressFree(a);
4439  DetectAddressFree(b);
4440  DetectAddressFree(c);
4441  return 1;
4442 
4443 error:
4444  DetectAddressFree(a);
4445  DetectAddressFree(b);
4446  DetectAddressFree(c);
4447  return 0;
4448 }
4449 
4450 static int AddressTestCutIPv405(void)
4451 {
4452  DetectAddress *a, *b, *c = NULL;
4453  a = DetectAddressParseSingle("1.2.3.3-1.2.3.6");
4454  b = DetectAddressParseSingle("1.2.3.0-1.2.3.9");
4455 
4456  if (DetectAddressCut(NULL, a, b, &c) == -1)
4457  goto error;
4458 
4459  if (c == NULL)
4460  goto error;
4461 
4462  if (a->ip.addr_data32[0] != SCNtohl(16909056) || a->ip2.addr_data32[0] != SCNtohl(16909058))
4463  goto error;
4464  if (b->ip.addr_data32[0] != SCNtohl(16909059) || b->ip2.addr_data32[0] != SCNtohl(16909062))
4465  goto error;
4466  if (c->ip.addr_data32[0] != SCNtohl(16909063) || c->ip2.addr_data32[0] != SCNtohl(16909065))
4467  goto error;
4468 
4469  DetectAddressFree(a);
4470  DetectAddressFree(b);
4471  DetectAddressFree(c);
4472  return 1;
4473 
4474 error:
4475  DetectAddressFree(a);
4476  DetectAddressFree(b);
4477  DetectAddressFree(c);
4478  return 0;
4479 }
4480 
4481 static int AddressTestCutIPv406(void)
4482 {
4483  DetectAddress *a, *b, *c = NULL;
4484  a = DetectAddressParseSingle("1.2.3.0-1.2.3.9");
4485  b = DetectAddressParseSingle("1.2.3.3-1.2.3.6");
4486 
4487  if (DetectAddressCut(NULL, a, b, &c) == -1)
4488  goto error;
4489 
4490  if (c == NULL)
4491  goto error;
4492 
4493  if (a->ip.addr_data32[0] != SCNtohl(16909056) || a->ip2.addr_data32[0] != SCNtohl(16909058))
4494  goto error;
4495  if (b->ip.addr_data32[0] != SCNtohl(16909059) || b->ip2.addr_data32[0] != SCNtohl(16909062))
4496  goto error;
4497  if (c->ip.addr_data32[0] != SCNtohl(16909063) || c->ip2.addr_data32[0] != SCNtohl(16909065))
4498  goto error;
4499 
4500  DetectAddressFree(a);
4501  DetectAddressFree(b);
4502  DetectAddressFree(c);
4503  return 1;
4504 
4505 error:
4506  DetectAddressFree(a);
4507  DetectAddressFree(b);
4508  DetectAddressFree(c);
4509  return 0;
4510 }
4511 
4512 static int AddressTestCutIPv407(void)
4513 {
4514  DetectAddress *a, *b, *c = NULL;
4515  a = DetectAddressParseSingle("1.2.3.0-1.2.3.6");
4516  b = DetectAddressParseSingle("1.2.3.0-1.2.3.9");
4517 
4518  if (DetectAddressCut(NULL, a, b, &c) == -1)
4519  goto error;
4520 
4521  if (c != NULL)
4522  goto error;
4523 
4524  if (a->ip.addr_data32[0] != SCNtohl(16909056) || a->ip2.addr_data32[0] != SCNtohl(16909062))
4525  goto error;
4526  if (b->ip.addr_data32[0] != SCNtohl(16909063) || b->ip2.addr_data32[0] != SCNtohl(16909065))
4527  goto error;
4528 
4529  DetectAddressFree(a);
4530  DetectAddressFree(b);
4531  DetectAddressFree(c);
4532  return 1;
4533 
4534 error:
4535  DetectAddressFree(a);
4536  DetectAddressFree(b);
4537  DetectAddressFree(c);
4538  return 0;
4539 }
4540 
4541 static int AddressTestCutIPv408(void)
4542 {
4543  DetectAddress *a, *b, *c = NULL;
4544  a = DetectAddressParseSingle("1.2.3.3-1.2.3.9");
4545  b = DetectAddressParseSingle("1.2.3.0-1.2.3.9");
4546 
4547  if (DetectAddressCut(NULL, a, b, &c) == -1)
4548  goto error;
4549 
4550  if (c != NULL)
4551  goto error;
4552 
4553  if (a->ip.addr_data32[0] != SCNtohl(16909056) || a->ip2.addr_data32[0] != SCNtohl(16909058))
4554  goto error;
4555  if (b->ip.addr_data32[0] != SCNtohl(16909059) || b->ip2.addr_data32[0] != SCNtohl(16909065))
4556  goto error;
4557 
4558  DetectAddressFree(a);
4559  DetectAddressFree(b);
4560  DetectAddressFree(c);
4561  return 1;
4562 
4563 error:
4564  DetectAddressFree(a);
4565  DetectAddressFree(b);
4566  DetectAddressFree(c);
4567  return 0;
4568 }
4569 
4570 static int AddressTestCutIPv409(void)
4571 {
4572  DetectAddress *a, *b, *c = NULL;
4573  a = DetectAddressParseSingle("1.2.3.0-1.2.3.9");
4574  b = DetectAddressParseSingle("1.2.3.0-1.2.3.6");
4575 
4576  if (DetectAddressCut(NULL, a, b, &c) == -1)
4577  goto error;
4578 
4579  if (c != NULL)
4580  goto error;
4581 
4582  if (a->ip.addr_data32[0] != SCNtohl(16909056) || a->ip2.addr_data32[0] != SCNtohl(16909062))
4583  goto error;
4584  if (b->ip.addr_data32[0] != SCNtohl(16909063) || b->ip2.addr_data32[0] != SCNtohl(16909065))
4585  goto error;
4586 
4587  DetectAddressFree(a);
4588  DetectAddressFree(b);
4589  DetectAddressFree(c);
4590  return 1;
4591 
4592 error:
4593  DetectAddressFree(a);
4594  DetectAddressFree(b);
4595  DetectAddressFree(c);
4596  return 0;
4597 }
4598 
4599 static int AddressTestCutIPv410(void)
4600 {
4601  DetectAddress *a, *b, *c = NULL;
4602  a = DetectAddressParseSingle("1.2.3.0-1.2.3.9");
4603  b = DetectAddressParseSingle("1.2.3.3-1.2.3.9");
4604 
4605  if (DetectAddressCut(NULL, a, b, &c) == -1)
4606  goto error;
4607 
4608  if (c != NULL)
4609  goto error;
4610 
4611  if (a->ip.addr_data32[0] != SCNtohl(16909056) || a->ip2.addr_data32[0] != SCNtohl(16909058))
4612  goto error;
4613  if (b->ip.addr_data32[0] != SCNtohl(16909059) || b->ip2.addr_data32[0] != SCNtohl(16909065))
4614  goto error;
4615 
4616  printf("ip %u ip2 %u ", (uint32_t)htonl(a->ip.addr_data32[0]), (uint32_t)htonl(a->ip2.addr_data32[0]));
4617 
4618  DetectAddressFree(a);
4619  DetectAddressFree(b);
4620  DetectAddressFree(c);
4621  return 1;
4622 
4623 error:
4624  DetectAddressFree(a);
4625  DetectAddressFree(b);
4626  DetectAddressFree(c);
4627  return 0;
4628 }
4629 
4630 static int AddressTestParseInvalidMask01(void)
4631 {
4632  int result = 1;
4633  DetectAddress *dd = NULL;
4634 
4635  dd = DetectAddressParseSingle("192.168.2.0/33");
4636  if (dd != NULL) {
4637  DetectAddressFree(dd);
4638  result = 0;
4639  }
4640  return result;
4641 }
4642 
4643 static int AddressTestParseInvalidMask02(void)
4644 {
4645  int result = 1;
4646  DetectAddress *dd = NULL;
4647 
4648  dd = DetectAddressParseSingle("192.168.2.0/255.255.257.0");
4649  if (dd != NULL) {
4650  DetectAddressFree(dd);
4651  result = 0;
4652  }
4653  return result;
4654 }
4655 
4656 static int AddressTestParseInvalidMask03(void)
4657 {
4658  int result = 1;
4659  DetectAddress *dd = NULL;
4660 
4661  dd = DetectAddressParseSingle("192.168.2.0/blue");
4662  if (dd != NULL) {
4663  DetectAddressFree(dd);
4664  result = 0;
4665  }
4666  return result;
4667 }
4668 
4669 static int AddressConfVarsTest01(void)
4670 {
4671  static const char *dummy_conf_string =
4672  "%YAML 1.1\n"
4673  "---\n"
4674  "\n"
4675  "vars:\n"
4676  "\n"
4677  " address-groups:\n"
4678  "\n"
4679  " HOME_NET: \"any\"\n"
4680  "\n"
4681  " EXTERNAL_NET: \"!any\"\n"
4682  "\n"
4683  " port-groups:\n"
4684  "\n"
4685  " HTTP_PORTS: \"any\"\n"
4686  "\n"
4687  " SHELLCODE_PORTS: \"!any\"\n"
4688  "\n";
4689 
4690  int result = 0;
4691 
4693  SCConfInit();
4694  SCConfYamlLoadString(dummy_conf_string, strlen(dummy_conf_string));
4695 
4697  result = 1;
4698 
4699  SCConfDeInit();
4701 
4702  return result;
4703 }
4704 
4705 static int AddressConfVarsTest02(void)
4706 {
4707  static const char *dummy_conf_string =
4708  "%YAML 1.1\n"
4709  "---\n"
4710  "\n"
4711  "vars:\n"
4712  "\n"
4713  " address-groups:\n"
4714  "\n"
4715  " HOME_NET: \"any\"\n"
4716  "\n"
4717  " EXTERNAL_NET: \"any\"\n"
4718  "\n"
4719  " port-groups:\n"
4720  "\n"
4721  " HTTP_PORTS: \"any\"\n"
4722  "\n"
4723  " SHELLCODE_PORTS: \"!any\"\n"
4724  "\n";
4725 
4726  int result = 0;
4727 
4729  SCConfInit();
4730  SCConfYamlLoadString(dummy_conf_string, strlen(dummy_conf_string));
4731 
4733  result = 1;
4734 
4735  SCConfDeInit();
4737 
4738  return result;
4739 }
4740 
4741 static int AddressConfVarsTest03(void)
4742 {
4743  static const char *dummy_conf_string =
4744  "%YAML 1.1\n"
4745  "---\n"
4746  "\n"
4747  "vars:\n"
4748  "\n"
4749  " address-groups:\n"
4750  "\n"
4751  " HOME_NET: \"any\"\n"
4752  "\n"
4753  " EXTERNAL_NET: \"!$HOME_NET\"\n"
4754  "\n"
4755  " port-groups:\n"
4756  "\n"
4757  " HTTP_PORTS: \"any\"\n"
4758  "\n"
4759  " SHELLCODE_PORTS: \"!$HTTP_PORTS\"\n"
4760  "\n";
4761 
4762  int result = 0;
4763 
4765  SCConfInit();
4766  SCConfYamlLoadString(dummy_conf_string, strlen(dummy_conf_string));
4767 
4769  result = 1;
4770 
4771  SCConfDeInit();
4773 
4774  return result;
4775 }
4776 
4777 static int AddressConfVarsTest04(void)
4778 {
4779  static const char *dummy_conf_string =
4780  "%YAML 1.1\n"
4781  "---\n"
4782  "\n"
4783  "vars:\n"
4784  "\n"
4785  " address-groups:\n"
4786  "\n"
4787  " HOME_NET: \"any\"\n"
4788  "\n"
4789  " EXTERNAL_NET: \"$HOME_NET\"\n"
4790  "\n"
4791  " port-groups:\n"
4792  "\n"
4793  " HTTP_PORTS: \"any\"\n"
4794  "\n"
4795  " SHELLCODE_PORTS: \"$HTTP_PORTS\"\n"
4796  "\n";
4797 
4798  int result = 0;
4799 
4801  SCConfInit();
4802  SCConfYamlLoadString(dummy_conf_string, strlen(dummy_conf_string));
4803 
4805  result = 1;
4806 
4807  SCConfDeInit();
4809 
4810  return result;
4811 }
4812 
4813 static int AddressConfVarsTest05(void)
4814 {
4815  static const char *dummy_conf_string =
4816  "%YAML 1.1\n"
4817  "---\n"
4818  "\n"
4819  "vars:\n"
4820  "\n"
4821  " address-groups:\n"
4822  "\n"
4823  " HOME_NET: \"any\"\n"
4824  "\n"
4825  " EXTERNAL_NET: [192.168.0.1]\n"
4826  "\n"
4827  " port-groups:\n"
4828  "\n"
4829  " HTTP_PORTS: \"any\"\n"
4830  "\n"
4831  " SHELLCODE_PORTS: [80]\n"
4832  "\n";
4833 
4834  int result = 0;
4835 
4837  SCConfInit();
4838  SCConfYamlLoadString(dummy_conf_string, strlen(dummy_conf_string));
4839 
4840  if (DetectAddressTestConfVars() != -1 && DetectPortTestConfVars() != -1)
4841  goto end;
4842 
4843  result = 1;
4844 
4845  end:
4846  SCConfDeInit();
4848 
4849  return result;
4850 }
4851 
4852 static int AddressConfVarsTest06(void)
4853 {
4854  // HOME_NET value size = 10261 bytes
4855  static const char *dummy_conf_string =
4856  "%YAML 1.1\n"
4857  "---\n"
4858  "\n"
4859  "vars:\n"
4860  "\n"
4861  " address-groups:\n"
4862  "\n"
4863  " HOME_NET: "
4864  "\"[2002:0000:3238:DFE1:63:0000:0000:FEFB,2002:0000:3238:DFE1:63:0000:0000:FEFB,"
4865  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4866  "2004:0000:3238:DFE1:63:0000:0000:FEFB,2005:0000:3238:DFE1:63:0000:0000:FEFB,"
4867  "2006:0000:3238:DFE1:63:0000:0000:FEFB,2007:0000:3238:DFE1:63:0000:0000:FEFB,"
4868  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4869  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4870  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4871  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4872  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4873  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4874  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4875  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4876  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4877  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4878  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4879  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4880  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4881  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4882  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4883  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4884  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4885  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4886  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4887  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4888  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4889  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4890  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4891  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4892  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4893  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4894  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4895  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4896  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4897  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4898  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4899  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4900  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4901  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4902  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4903  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4904  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4905  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4906  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4907  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4908  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4909  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4910  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4911  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4912  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4913  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4914  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4915  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4916  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4917  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4918  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4919  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4920  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4921  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4922  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4923  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4924  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4925  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4926  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4927  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4928  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4929  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4930  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4931  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4932  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4933  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4934  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4935  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4936  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4937  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4938  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4939  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4940  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4941  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4942  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4943  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4944  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4945  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4946  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4947  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4948  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4949  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4950  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4951  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4952  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4953  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4954  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4955  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4956  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4957  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4958  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4959  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4960  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4961  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4962  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4963  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4964  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4965  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4966  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4967  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4968  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4969  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4970  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4971  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4972  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4973  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4974  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4975  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4976  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4977  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4978  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4979  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4980  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4981  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4982  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4983  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4984  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4985  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4986  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4987  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4988  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4989  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4990  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4991  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4992  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4993  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4994  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4995  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4996  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4997  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB,"
4998  "2002:0000:3238:DFE1:63:0000:0000:FEFB,2003:0000:3238:DFE1:63:0000:0000:FEFB]\"\n"
4999  "\n"
5000  " EXTERNAL_NET: \"any\"\n"
5001  "\n";
5002 
5004  SCConfInit();
5005  SCConfYamlLoadString(dummy_conf_string, strlen(dummy_conf_string));
5006 
5008 
5009  SCConfDeInit();
5011 
5012  PASS;
5013 }
5014 
5015 #endif /* UNITTESTS */
5016 
5017 void DetectAddressTests(void)
5018 {
5019 #ifdef UNITTESTS
5022 
5023  UtRegisterTest("AddressTestParse01", AddressTestParse01);
5024  UtRegisterTest("AddressTestParse02", AddressTestParse02);
5025  UtRegisterTest("AddressTestParse03", AddressTestParse03);
5026  UtRegisterTest("AddressTestParse04", AddressTestParse04);
5027  UtRegisterTest("AddressTestParse04bug5081", AddressTestParse04bug5081);
5028  UtRegisterTest("AddressTestParse05", AddressTestParse05);
5029  UtRegisterTest("AddressTestParse06", AddressTestParse06);
5030  UtRegisterTest("AddressTestParse07", AddressTestParse07);
5031  UtRegisterTest("AddressTestParse08", AddressTestParse08);
5032  UtRegisterTest("AddressTestParse09", AddressTestParse09);
5033  UtRegisterTest("AddressTestParse10", AddressTestParse10);
5034  UtRegisterTest("AddressTestParse11", AddressTestParse11);
5035  UtRegisterTest("AddressTestParse12", AddressTestParse12);
5036  UtRegisterTest("AddressTestParse13", AddressTestParse13);
5037  UtRegisterTest("AddressTestParse14", AddressTestParse14);
5038  UtRegisterTest("AddressTestParse15", AddressTestParse15);
5039  UtRegisterTest("AddressTestParse16", AddressTestParse16);
5040  UtRegisterTest("AddressTestParse17", AddressTestParse17);
5041  UtRegisterTest("AddressTestParse18", AddressTestParse18);
5042  UtRegisterTest("AddressTestParse19", AddressTestParse19);
5043  UtRegisterTest("AddressTestParse20", AddressTestParse20);
5044  UtRegisterTest("AddressTestParse21", AddressTestParse21);
5045  UtRegisterTest("AddressTestParse22", AddressTestParse22);
5046  UtRegisterTest("AddressTestParse23", AddressTestParse23);
5047  UtRegisterTest("AddressTestParse24", AddressTestParse24);
5048  UtRegisterTest("AddressTestParse25", AddressTestParse25);
5049  UtRegisterTest("AddressTestParse26", AddressTestParse26);
5050  UtRegisterTest("AddressTestParse27", AddressTestParse27);
5051  UtRegisterTest("AddressTestParse28", AddressTestParse28);
5052  UtRegisterTest("AddressTestParse29", AddressTestParse29);
5053  UtRegisterTest("AddressTestParse30", AddressTestParse30);
5054  UtRegisterTest("AddressTestParse31", AddressTestParse31);
5055  UtRegisterTest("AddressTestParse32", AddressTestParse32);
5056  UtRegisterTest("AddressTestParse33", AddressTestParse33);
5057  UtRegisterTest("AddressTestParse34", AddressTestParse34);
5058  UtRegisterTest("AddressTestParse35", AddressTestParse35);
5059  UtRegisterTest("AddressTestParse36", AddressTestParse36);
5060  UtRegisterTest("AddressTestParse37", AddressTestParse37);
5061 
5062  UtRegisterTest("AddressTestMatch01", AddressTestMatch01);
5063  UtRegisterTest("AddressTestMatch02", AddressTestMatch02);
5064  UtRegisterTest("AddressTestMatch03", AddressTestMatch03);
5065  UtRegisterTest("AddressTestMatch04", AddressTestMatch04);
5066  UtRegisterTest("AddressTestMatch05", AddressTestMatch05);
5067  UtRegisterTest("AddressTestMatch06", AddressTestMatch06);
5068  UtRegisterTest("AddressTestMatch07", AddressTestMatch07);
5069  UtRegisterTest("AddressTestMatch08", AddressTestMatch08);
5070  UtRegisterTest("AddressTestMatch09", AddressTestMatch09);
5071  UtRegisterTest("AddressTestMatch10", AddressTestMatch10);
5072  UtRegisterTest("AddressTestMatch11", AddressTestMatch11);
5073 
5074  UtRegisterTest("AddressTestCmp01", AddressTestCmp01);
5075  UtRegisterTest("AddressTestCmp02", AddressTestCmp02);
5076  UtRegisterTest("AddressTestCmp03", AddressTestCmp03);
5077  UtRegisterTest("AddressTestCmp04", AddressTestCmp04);
5078  UtRegisterTest("AddressTestCmp05", AddressTestCmp05);
5079  UtRegisterTest("AddressTestCmp06", AddressTestCmp06);
5080  UtRegisterTest("AddressTestCmpIPv407", AddressTestCmpIPv407);
5081  UtRegisterTest("AddressTestCmpIPv408", AddressTestCmpIPv408);
5082 
5083  UtRegisterTest("AddressTestCmp07", AddressTestCmp07);
5084  UtRegisterTest("AddressTestCmp08", AddressTestCmp08);
5085  UtRegisterTest("AddressTestCmp09", AddressTestCmp09);
5086  UtRegisterTest("AddressTestCmp10", AddressTestCmp10);
5087  UtRegisterTest("AddressTestCmp11", AddressTestCmp11);
5088  UtRegisterTest("AddressTestCmp12", AddressTestCmp12);
5089 
5090  UtRegisterTest("AddressTestAddressGroupSetup01",
5091  AddressTestAddressGroupSetup01);
5092  UtRegisterTest("AddressTestAddressGroupSetup02",
5093  AddressTestAddressGroupSetup02);
5094  UtRegisterTest("AddressTestAddressGroupSetup03",
5095  AddressTestAddressGroupSetup03);
5096  UtRegisterTest("AddressTestAddressGroupSetup04",
5097  AddressTestAddressGroupSetup04);
5098  UtRegisterTest("AddressTestAddressGroupSetup05",
5099  AddressTestAddressGroupSetup05);
5100  UtRegisterTest("AddressTestAddressGroupSetup06",
5101  AddressTestAddressGroupSetup06);
5102  UtRegisterTest("AddressTestAddressGroupSetup07",
5103  AddressTestAddressGroupSetup07);
5104  UtRegisterTest("AddressTestAddressGroupSetup08",
5105  AddressTestAddressGroupSetup08);
5106  UtRegisterTest("AddressTestAddressGroupSetup09",
5107  AddressTestAddressGroupSetup09);
5108  UtRegisterTest("AddressTestAddressGroupSetup10",
5109  AddressTestAddressGroupSetup10);
5110  UtRegisterTest("AddressTestAddressGroupSetup11",
5111  AddressTestAddressGroupSetup11);
5112  UtRegisterTest("AddressTestAddressGroupSetup12",
5113  AddressTestAddressGroupSetup12);
5114  UtRegisterTest("AddressTestAddressGroupSetup13",
5115  AddressTestAddressGroupSetup13);
5116  UtRegisterTest("AddressTestAddressGroupSetupIPv414",
5117  AddressTestAddressGroupSetupIPv414);
5118  UtRegisterTest("AddressTestAddressGroupSetupIPv415",
5119  AddressTestAddressGroupSetupIPv415);
5120  UtRegisterTest("AddressTestAddressGroupSetupIPv416",
5121  AddressTestAddressGroupSetupIPv416);
5122 
5123  UtRegisterTest("AddressTestAddressGroupSetup14",
5124  AddressTestAddressGroupSetup14);
5125  UtRegisterTest("AddressTestAddressGroupSetup15",
5126  AddressTestAddressGroupSetup15);
5127  UtRegisterTest("AddressTestAddressGroupSetup16",
5128  AddressTestAddressGroupSetup16);
5129  UtRegisterTest("AddressTestAddressGroupSetup17",
5130  AddressTestAddressGroupSetup17);
5131  UtRegisterTest("AddressTestAddressGroupSetup18",
5132  AddressTestAddressGroupSetup18);
5133  UtRegisterTest("AddressTestAddressGroupSetup19",
5134  AddressTestAddressGroupSetup19);
5135  UtRegisterTest("AddressTestAddressGroupSetup20",
5136  AddressTestAddressGroupSetup20);
5137  UtRegisterTest("AddressTestAddressGroupSetup21",
5138  AddressTestAddressGroupSetup21);
5139  UtRegisterTest("AddressTestAddressGroupSetup22",
5140  AddressTestAddressGroupSetup22);
5141  UtRegisterTest("AddressTestAddressGroupSetup23",
5142  AddressTestAddressGroupSetup23);
5143  UtRegisterTest("AddressTestAddressGroupSetup24",
5144  AddressTestAddressGroupSetup24);
5145  UtRegisterTest("AddressTestAddressGroupSetup25",
5146  AddressTestAddressGroupSetup25);
5147  UtRegisterTest("AddressTestAddressGroupSetup26",
5148  AddressTestAddressGroupSetup26);
5149 
5150  UtRegisterTest("AddressTestAddressGroupSetup27",
5151  AddressTestAddressGroupSetup27);
5152  UtRegisterTest("AddressTestAddressGroupSetup28",
5153  AddressTestAddressGroupSetup28);
5154  UtRegisterTest("AddressTestAddressGroupSetup29",
5155  AddressTestAddressGroupSetup29);
5156  UtRegisterTest("AddressTestAddressGroupSetup30",
5157  AddressTestAddressGroupSetup30);
5158  UtRegisterTest("AddressTestAddressGroupSetup31",
5159  AddressTestAddressGroupSetup31);
5160  UtRegisterTest("AddressTestAddressGroupSetup32",
5161  AddressTestAddressGroupSetup32);
5162  UtRegisterTest("AddressTestAddressGroupSetup33",
5163  AddressTestAddressGroupSetup33);
5164  UtRegisterTest("AddressTestAddressGroupSetup34",
5165  AddressTestAddressGroupSetup34);
5166  UtRegisterTest("AddressTestAddressGroupSetup35",
5167  AddressTestAddressGroupSetup35);
5168  UtRegisterTest("AddressTestAddressGroupSetup36",
5169  AddressTestAddressGroupSetup36);
5170  UtRegisterTest("AddressTestAddressGroupSetup37",
5171  AddressTestAddressGroupSetup37);
5172  UtRegisterTest("AddressTestAddressGroupSetup38",
5173  AddressTestAddressGroupSetup38);
5174  UtRegisterTest("AddressTestAddressGroupSetup39",
5175  AddressTestAddressGroupSetup39);
5176  UtRegisterTest("AddressTestAddressGroupSetup40",
5177  AddressTestAddressGroupSetup40);
5178  UtRegisterTest("AddressTestAddressGroupSetup41",
5179  AddressTestAddressGroupSetup41);
5180  UtRegisterTest("AddressTestAddressGroupSetup42",
5181  AddressTestAddressGroupSetup42);
5182  UtRegisterTest("AddressTestAddressGroupSetup43",
5183  AddressTestAddressGroupSetup43);
5184  UtRegisterTest("AddressTestAddressGroupSetup44",
5185  AddressTestAddressGroupSetup44);
5186  UtRegisterTest("AddressTestAddressGroupSetup45",
5187  AddressTestAddressGroupSetup45);
5188  UtRegisterTest("AddressTestAddressGroupSetup46",
5189  AddressTestAddressGroupSetup46);
5190  UtRegisterTest("AddressTestAddressGroupSetup47",
5191  AddressTestAddressGroupSetup47);
5192  UtRegisterTest("AddressTestAddressGroupSetup48",
5193  AddressTestAddressGroupSetup48);
5194 
5195  UtRegisterTest("AddressTestCutIPv401", AddressTestCutIPv401);
5196  UtRegisterTest("AddressTestCutIPv402", AddressTestCutIPv402);
5197  UtRegisterTest("AddressTestCutIPv403", AddressTestCutIPv403);
5198  UtRegisterTest("AddressTestCutIPv404", AddressTestCutIPv404);
5199  UtRegisterTest("AddressTestCutIPv405", AddressTestCutIPv405);
5200  UtRegisterTest("AddressTestCutIPv406", AddressTestCutIPv406);
5201  UtRegisterTest("AddressTestCutIPv407", AddressTestCutIPv407);
5202  UtRegisterTest("AddressTestCutIPv408", AddressTestCutIPv408);
5203  UtRegisterTest("AddressTestCutIPv409", AddressTestCutIPv409);
5204  UtRegisterTest("AddressTestCutIPv410", AddressTestCutIPv410);
5205 
5206  UtRegisterTest("AddressTestParseInvalidMask01",
5207  AddressTestParseInvalidMask01);
5208  UtRegisterTest("AddressTestParseInvalidMask02",
5209  AddressTestParseInvalidMask02);
5210  UtRegisterTest("AddressTestParseInvalidMask03",
5211  AddressTestParseInvalidMask03);
5212 
5213  UtRegisterTest("AddressConfVarsTest01 ", AddressConfVarsTest01);
5214  UtRegisterTest("AddressConfVarsTest02 ", AddressConfVarsTest02);
5215  UtRegisterTest("AddressConfVarsTest03 ", AddressConfVarsTest03);
5216  UtRegisterTest("AddressConfVarsTest04 ", AddressConfVarsTest04);
5217  UtRegisterTest("AddressConfVarsTest05 ", AddressConfVarsTest05);
5218  UtRegisterTest("AddressConfVarsTest06 ", AddressConfVarsTest06);
5219 #endif /* UNITTESTS */
5220 }
DetectAddressListsAreEqual
bool DetectAddressListsAreEqual(DetectAddress *list1, DetectAddress *list2)
Checks if two address group lists are equal.
Definition: detect-engine-address.c:347
DetectAddressCutNotIPv4
int DetectAddressCutNotIPv4(DetectAddress *a, DetectAddress **b)
Cuts and returns an address range, which is the complement of the address range that is supplied as t...
Definition: detect-engine-address-ipv4.c:367
util-byte.h
DetectAddress_::ip
Address ip
Definition: detect.h:172
SCConfYamlLoadString
int SCConfYamlLoadString(const char *string, size_t len)
Load configuration from a YAML string.
Definition: conf-yaml-loader.c:535
DetectAddressFree
void DetectAddressFree(DetectAddress *ag)
Frees a DetectAddress instance.
Definition: detect-engine-address.c:81
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
DetectAddressTests
void DetectAddressTests(void)
ADDRESS_EB
@ ADDRESS_EB
Definition: detect.h:158
ADDRESS_LE
@ ADDRESS_LE
Definition: detect.h:155
DetectAddressMap_::contains_negation
bool contains_negation
Definition: detect-engine-address.c:1293
DetectAddressCutIPv6
int DetectAddressCutIPv6(DetectEngineCtx *de_ctx, DetectAddress *a, DetectAddress *b, DetectAddress **c)
Definition: detect-engine-address-ipv6.c:352
TAILQ_INIT
#define TAILQ_INIT(head)
Definition: queue.h:262
DetectAddressHead_::contains_range
bool contains_range
Definition: detect.h:189
detect-engine-siggroup.h
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
AddressIPv6Le
int AddressIPv6Le(const Address *a, const Address *b)
Compares 2 ipv6 addresses and returns if the first address(a) is less than or equal to the second add...
Definition: detect-engine-address-ipv6.c:161
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
DetectAddressMatchIPv4
int DetectAddressMatchIPv4(const DetectMatchAddressIPv4 *addrs, uint16_t addrs_cnt, const Address *a)
Match a packets address against a signatures addrs array.
Definition: detect-engine-address.c:1603
DetectAddress_
address structure for use in the detection engine.
Definition: detect.h:170
SC_RULE_VARS_ADDRESS_GROUPS
@ SC_RULE_VARS_ADDRESS_GROUPS
Definition: util-rule-vars.h:31
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
DetectAddressHead_
Definition: detect.h:185
next
struct HtpBodyChunk_ * next
Definition: app-layer-htp.h:0
DetectAddressHeadCleanup
void DetectAddressHeadCleanup(DetectAddressHead *gh)
Cleans a DetectAddressHead. The functions frees the address group heads(ipv4 and ipv6) inside the Det...
Definition: detect-engine-address.c:1490
ADDRESS_LT
@ ADDRESS_LT
Definition: detect.h:154
DetectAddressMap
struct DetectAddressMap_ DetectAddressMap
CIDRGet
uint32_t CIDRGet(int cidr)
Definition: util-cidr.c:56
DetectAddressMapFree
void DetectAddressMapFree(DetectEngineCtx *de_ctx)
Definition: detect-engine-address.c:1339
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DetectAddressIPv4Tests
void DetectAddressIPv4Tests(void)
Definition: detect-engine-address-ipv4.c:1007
TAILQ_FOREACH
#define TAILQ_FOREACH(var, head, field)
Definition: queue.h:252
ADDRESS_EQ
@ ADDRESS_EQ
Definition: detect.h:156
Address_
Definition: decode.h:113
HashListTableLookup
void * HashListTableLookup(HashListTable *ht, void *data, uint16_t datalen)
Definition: util-hashlist.c:244
CleanVariableResolveList
void CleanVariableResolveList(ResolvedVariablesList *var_list)
Definition: util-var.c:168
DetectPortTestConfVars
int DetectPortTestConfVars(void)
Definition: detect-engine-port.c:1057
util-var.h
DetectAddressLookupInHead
DetectAddress * DetectAddressLookupInHead(const DetectAddressHead *gh, Address *a)
Find the group matching address in a group head.
Definition: detect-engine-address.c:1812
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
HashListTableAdd
int HashListTableAdd(HashListTable *ht, void *data, uint16_t datalen)
Definition: util-hashlist.c:113
DetectAddress_::prev
struct DetectAddress_ * prev
Definition: detect.h:179
strlcpy
size_t strlcpy(char *dst, const char *src, size_t siz)
Definition: util-strlcpyu.c:43
HashListTable_::array_size
uint32_t array_size
Definition: util-hashlist.h:41
DetectAddressCmpIPv4
int DetectAddressCmpIPv4(DetectAddress *a, DetectAddress *b)
Compares 2 addresses(address ranges) and returns the relationship between the 2 addresses.
Definition: detect-engine-address-ipv4.c:58
Address_::address
union Address_::@29 address
SCConfInit
void SCConfInit(void)
Initialize the configuration system.
Definition: conf.c:120
util-cidr.h
HashListTableInit
HashListTable * HashListTableInit(uint32_t size, uint32_t(*Hash)(struct HashListTable_ *, void *, uint16_t), char(*Compare)(void *, uint16_t, void *, uint16_t), void(*Free)(void *))
Definition: util-hashlist.c:34
decode.h
FAIL_IF_NOT_NULL
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
Definition: util-unittest.h:96
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectAddressIsCompleteIPSpaceIPv4
int DetectAddressIsCompleteIPSpaceIPv4(DetectAddress *ag)
Check if the address group list covers the complete IPv4 IP space.
Definition: detect-engine-address-ipv4.c:313
StringParseI32RangeCheck
int StringParseI32RangeCheck(int32_t *res, int base, size_t len, const char *str, int32_t min, int32_t max)
Definition: util-byte.c:680
DetectAddressCutIPv4
int DetectAddressCutIPv4(DetectEngineCtx *de_ctx, DetectAddress *a, DetectAddress *b, DetectAddress **c)
Cut groups and merge sigs.
Definition: detect-engine-address-ipv4.c:112
ADDRESS_GE
@ ADDRESS_GE
Definition: detect.h:159
UTHValidateDetectAddressHeadRange_::one
const char * one
Definition: detect-engine-address.c:1895
util-print.h
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
detect.h
PrintInet
const char * PrintInet(int af, const void *src, char *dst, socklen_t size)
Definition: util-print.c:238
detect-engine-port.h
DetectAddress_::ip2
Address ip2
Definition: detect.h:173
DetectAddressMergeNot
int DetectAddressMergeNot(DetectAddressHead *gh, DetectAddressHead *ghn)
Merge the + and the - list (+ positive match, - 'not' match)
Definition: detect-engine-address.c:1035
BUG_ON
#define BUG_ON(x)
Definition: suricata-common.h:322
hashlittle_safe
uint32_t hashlittle_safe(const void *key, size_t length, uint32_t initval)
Definition: util-hash-lookup3.c:482
DetectAddressCopy
DetectAddress * DetectAddressCopy(DetectAddress *orig)
copy a DetectAddress
Definition: detect-engine-address.c:126
CIDRFromMask
int CIDRFromMask(uint32_t netmask)
Turn 32 bit mask into CIDR.
Definition: util-cidr.c:34
util-rule-vars.h
conf-yaml-loader.h
conf.h
UTHValidateDetectAddressHeadRange
struct UTHValidateDetectAddressHeadRange_ UTHValidateDetectAddressHeadRange
DetectAddressCleanupList
void DetectAddressCleanupList(DetectAddress *head)
Frees a list of DetectAddress instances.
Definition: detect-engine-address.c:143
SCReturnPtr
#define SCReturnPtr(x, type)
Definition: util-debug.h:300
MAX_ADDRESS_LENGTH
#define MAX_ADDRESS_LENGTH
SCConfCreateContextBackup
void SCConfCreateContextBackup(void)
Creates a backup of the conf_hash hash_table used by the conf API.
Definition: conf.c:740
HashListTable_
Definition: util-hashlist.h:37
SCLogInfo
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
Definition: util-debug.h:232
DetectAddressMap_
Definition: detect-engine-address.c:1290
DetectAddressHead_::ipv6_head
DetectAddress * ipv6_head
Definition: detect.h:187
CIDRGetIPv6
void CIDRGetIPv6(int cidr, struct in6_addr *in6)
Creates a cidr ipv6 netblock, based on the cidr netblock value.
Definition: util-cidr.c:81
cnt
uint32_t cnt
Definition: tmqh-packetpool.h:7
DetectAddressMatchIPv6
int DetectAddressMatchIPv6(const DetectMatchAddressIPv6 *addrs, uint16_t addrs_cnt, const Address *a)
Match a packets address against a signatures addrs array.
Definition: detect-engine-address.c:1636
DetectEngineCtx_::address_table
HashListTable * address_table
Definition: detect.h:1142
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
suricata-common.h
HashListTableFree
void HashListTableFree(HashListTable *ht)
Definition: util-hashlist.c:87
ADDRESS_FLAG_RANGE
#define ADDRESS_FLAG_RANGE
Definition: detect.h:164
SCConfDeInit
void SCConfDeInit(void)
De-initializes the configuration system.
Definition: conf.c:759
SCStrdup
#define SCStrdup(s)
Definition: util-mem.h:56
util-hash-lookup3.h
detect-engine-address-ipv6.h
DetectAddressMap_::contains_range
bool contains_range
Definition: detect-engine-address.c:1294
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
DetectAddressMapInit
int DetectAddressMapInit(DetectEngineCtx *de_ctx)
Definition: detect-engine-address.c:1328
DetectAddressCmpIPv6
int DetectAddressCmpIPv6(DetectAddress *a, DetectAddress *b)
Compares 2 addresses(address ranges) and returns the relationship between the 2 addresses.
Definition: detect-engine-address-ipv6.c:231
HtpBodyChunk_::next
struct HtpBodyChunk_ * next
Definition: app-layer-htp.h:124
str
#define str(s)
Definition: suricata-common.h:313
SCConfGetNode
SCConfNode * SCConfGetNode(const char *name)
Get a SCConfNode by name.
Definition: conf.c:183
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
UTHValidateDetectAddressHeadRange_
Definition: detect-engine-address.c:1894
head
Flow * head
Definition: flow-hash.h:1
DetectAddressMap_::address
DetectAddressHead * address
Definition: detect-engine-address.c:1292
SCFree
#define SCFree(p)
Definition: util-mem.h:61
SCNtohl
#define SCNtohl(x)
Definition: suricata-common.h:435
detect-engine-address-ipv4.h
DetectParseAddress
const DetectAddressHead * DetectParseAddress(DetectEngineCtx *de_ctx, const char *string, bool *contains_negation, bool *contains_range)
Definition: detect-engine-address.c:1440
SCConfRestoreContextBackup
void SCConfRestoreContextBackup(void)
Restores the backup of the hash_table present in backup_conf_hash back to conf_hash.
Definition: conf.c:750
DetectAddressCutNotIPv6
int DetectAddressCutNotIPv6(DetectAddress *a, DetectAddress **b)
Cuts and returns an address range, which is the complement of the address range that is supplied as t...
Definition: detect-engine-address-ipv6.c:703
AddVariableToResolveList
int AddVariableToResolveList(ResolvedVariablesList *list, const char *var)
Definition: util-var.c:139
address
uint8_t address
Definition: decode-ppp.h:0
DetectAddress_::next
struct DetectAddress_ * next
Definition: detect.h:181
DetectMatchAddressIPv6_
Definition: detect.h:198
DetectMatchAddressIPv4_
Definition: detect.h:193
Address_::family
char family
Definition: decode.h:114
ADDRESS_ES
@ ADDRESS_ES
Definition: detect.h:157
SCConfNode_::name
char * name
Definition: conf.h:38
DetectAddressIPv6Tests
void DetectAddressIPv6Tests(void)
Definition: detect-engine-address-ipv6.c:1530
ADDRESS_FLAG_NOT
#define ADDRESS_FLAG_NOT
Definition: detect.h:163
UTHValidateDetectAddressHeadRange_::two
const char * two
Definition: detect-engine-address.c:1896
DetectAddressParse
int DetectAddressParse(const DetectEngineCtx *de_ctx, DetectAddressHead *gh, const char *str, bool *contains_range)
Parses an address group sent as a character string and updates the DetectAddressHead sent as the argu...
Definition: detect-engine-address.c:1397
COPY_ADDRESS
#define COPY_ADDRESS(a, b)
Definition: decode.h:128
AddressIPv6Gt
int AddressIPv6Gt(const Address *a, const Address *b)
Compares 2 ipv6 addresses and returns if the first address(a) is greater than the second address(b) o...
Definition: detect-engine-address-ipv6.c:89
SCRuleVarsGetConfVar
const char * SCRuleVarsGetConfVar(const DetectEngineCtx *de_ctx, const char *conf_var_name, SCRuleVarsType conf_vars_type)
Definition: util-rule-vars.c:64
AddressIPv6Ge
int AddressIPv6Ge(const Address *a, const Address *b)
Compares 2 ipv6 addresses and returns if the first address(a) is greater than or equal to the second ...
Definition: detect-engine-address-ipv6.c:193
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
SCConfNode_
Definition: conf.h:37
flow-var.h
SCConfNode_::val
char * val
Definition: conf.h:39
DetectAddress_::flags
uint8_t flags
Definition: detect.h:176
DetectAddressCmp
int DetectAddressCmp(DetectAddress *a, DetectAddress *b)
Used to compare 2 address ranges.
Definition: detect-engine-address.c:1576
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
DetectAddressHead_::ipv4_head
DetectAddress * ipv4_head
Definition: detect.h:186
DetectAddressPrint
#define DetectAddressPrint(...)
Definition: detect-engine-address.c:51
detect-engine-address.h
DetectAddressMap_::string
char * string
Definition: detect-engine-address.c:1291
DetectAddressInit
DetectAddress * DetectAddressInit(void)
Creates and returns a new instance of a DetectAddress.
Definition: detect-engine-address.c:68
DetectAddressTestConfVars
int DetectAddressTestConfVars(void)
Definition: detect-engine-address.c:1217
ADDRESS_ER
@ ADDRESS_ER
Definition: detect.h:153
ADDRESS_GT
@ ADDRESS_GT
Definition: detect.h:160