suricata
detect-engine.c File Reference
#include "suricata-common.h"
#include "suricata.h"
#include "detect.h"
#include "flow.h"
#include "flow-private.h"
#include "flow-util.h"
#include "flow-worker.h"
#include "conf.h"
#include "conf-yaml-loader.h"
#include "datasets.h"
#include "app-layer-parser.h"
#include "app-layer-events.h"
#include "app-layer-htp.h"
#include "detect-parse.h"
#include "detect-engine-sigorder.h"
#include "detect-engine-build.h"
#include "detect-engine-buffer.h"
#include "detect-engine-siggroup.h"
#include "detect-engine-address.h"
#include "detect-engine-port.h"
#include "detect-engine-prefilter.h"
#include "detect-engine-mpm.h"
#include "detect-engine-iponly.h"
#include "detect-engine-tag.h"
#include "detect-engine-frame.h"
#include "detect-engine-file.h"
#include "detect-engine.h"
#include "detect-engine-state.h"
#include "detect-engine-payload.h"
#include "detect-fast-pattern.h"
#include "detect-byte-extract.h"
#include "detect-content.h"
#include "detect-uricontent.h"
#include "detect-tcphdr.h"
#include "detect-engine-threshold.h"
#include "detect-engine-content-inspection.h"
#include "detect-engine-loader.h"
#include "detect-engine-alert.h"
#include "util-classification-config.h"
#include "util-reference-config.h"
#include "util-threshold-config.h"
#include "util-error.h"
#include "util-hash.h"
#include "util-byte.h"
#include "util-debug.h"
#include "util-action.h"
#include "util-magic.h"
#include "util-signal.h"
#include "util-spm.h"
#include "util-device-private.h"
#include "util-var-name.h"
#include "util-path.h"
#include "util-profiling.h"
#include "util-validate.h"
#include "util-hash-string.h"
#include "util-enum.h"
#include "util-conf.h"
#include "tm-threads.h"
#include "runmodes.h"
#include "reputation.h"
#include "util-hash-lookup3.h"

Go to the source code of this file.

Data Structures

struct  DetectEngineSyncer_
 
struct  TenantLoaderCtx_
 

Macros

#define DETECT_ENGINE_DEFAULT_INSPECTION_RECURSION_LIMIT   3000
 
#define DEFAULT_MAX_FLOWBITS_PER_SIGNATURE   8
 

Typedefs

typedef struct DetectEngineSyncer_ DetectEngineSyncer
 
typedef struct TenantLoaderCtx_ TenantLoaderCtx
 

Enumerations

enum  DetectEngineSyncState { IDLE, RELOAD }
 

Functions

const char * DetectTableToString (enum DetectTable table)
 
void DetectPktInspectEngineRegister (const char *name, InspectionBufferGetPktDataPtr GetPktData, InspectionBufferPktInspectFunc Callback)
 register inspect engine at start up time More...
 
void DetectAppLayerInspectEngineRegister (const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
 Registers an app inspection engine. More...
 
void DetectAppLayerInspectEngineRegisterSubState (const char *name, AppProto alproto, uint32_t dir, uint8_t sub_state, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
 register an app inspection engine for a tx type More...
 
void DetectAppLayerInspectEngineRegisterSingle (const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionSingleBufferGetDataPtr GetData)
 
void DetectEngineFrameInspectEngineRegister (DetectEngineCtx *de_ctx, const char *name, int dir, InspectionBufferFrameInspectFunc Callback, AppProto alproto, uint8_t type)
 register inspect engine at start up time More...
 
const char * DetectEngineAppHookToName (const AppProto p, const uint8_t sub_state, const uint8_t state, const uint8_t direction)
 
int DetectEngineAppHookToSmlist (const AppProto p, const uint8_t sub_state, const uint8_t state, const uint8_t direction)
 get the sm_list for a app hook More...
 
int DetectEngineAppInspectionEngine2Signature (DetectEngineCtx *de_ctx, Signature *s)
 
void DetectEngineAppInspectionEngineSignatureFree (DetectEngineCtx *de_ctx, Signature *s)
 free app inspect engines for a signature More...
 
int DetectBufferTypeMaxId (void)
 
int DetectBufferTypeRegister (const char *name)
 
void DetectBufferTypeSupportsMultiInstance (const char *name)
 
void DetectBufferTypeSupportsFrames (const char *name)
 
void DetectBufferTypeSupportsPacket (const char *name)
 
void DetectBufferTypeSupportsMpm (const char *name)
 
void DetectBufferTypeSupportsTransformations (const char *name)
 
int DetectBufferTypeGetByName (const char *name)
 
const DetectBufferType * DetectEngineBufferTypeGetById (const DetectEngineCtx *de_ctx, const int id)
 
const char * DetectEngineBufferTypeGetNameById (const DetectEngineCtx *de_ctx, const int id)
 
int DetectEngineBufferTypeRegisterWithFrameEngines (DetectEngineCtx *de_ctx, const char *name, const int direction, const AppProto alproto, const uint8_t frame_type)
 
int DetectEngineBufferTypeRegister (DetectEngineCtx *de_ctx, const char *name)
 
void DetectBufferTypeSetDescriptionByName (const char *name, const char *desc)
 
void DetectBufferTypeSetRunAlways (const char *name)
 
void DetectEngineBufferTypeSetRunAlways (DetectEngineCtx *de_ctx, const int id)
 
const char * DetectEngineBufferTypeGetDescriptionById (const DetectEngineCtx *de_ctx, const int id)
 
void DetectEngineBufferTypeSupportsFrames (DetectEngineCtx *de_ctx, const char *name)
 
void DetectEngineBufferTypeSupportsPacket (DetectEngineCtx *de_ctx, const char *name)
 
void DetectEngineBufferTypeSupportsMpm (DetectEngineCtx *de_ctx, const char *name)
 
void DetectEngineBufferTypeSupportsTransformations (DetectEngineCtx *de_ctx, const char *name)
 
bool DetectEngineBufferTypeSupportsMultiInstanceGetById (const DetectEngineCtx *de_ctx, const int id)
 
bool DetectEngineBufferTypeSupportsPacketGetById (const DetectEngineCtx *de_ctx, const int id)
 
bool DetectEngineBufferTypeSupportsMpmGetById (const DetectEngineCtx *de_ctx, const int id)
 
bool DetectEngineBufferTypeSupportsFramesGetById (const DetectEngineCtx *de_ctx, const int id)
 
void DetectBufferTypeRegisterSetupCallback (const char *name, void(*SetupCallback)(const DetectEngineCtx *, Signature *, const DetectBufferType *))
 
void DetectEngineBufferRunSetupCallback (const DetectEngineCtx *de_ctx, const int id, Signature *s)
 
void DetectBufferTypeRegisterValidateCallback (const char *name, bool(*ValidateCallback)(const Signature *, const char **sigerror, const DetectBufferType *))
 
bool DetectEngineBufferRunValidateCallback (const DetectEngineCtx *de_ctx, const int id, const Signature *s, const char **sigerror)
 
bool DetectBufferIsPresent (const Signature *s, const uint32_t buf_id)
 
bool DetectEngineBufferTypeValidateTransform (DetectEngineCtx *de_ctx, int sm_list, const uint8_t *content, uint16_t content_len, const char **namestr)
 Check content byte array compatibility with transforms. More...
 
void DetectBufferTypeCloseRegistration (void)
 
int DetectEngineBufferTypeGetByIdTransforms (DetectEngineCtx *de_ctx, const int id, TransformData *transforms, uint8_t transform_cnt)
 
bool DetectEnginePktInspectionRun (ThreadVars *tv, DetectEngineThreadCtx *det_ctx, const Signature *s, Flow *f, Packet *p, uint8_t *alert_flags)
 
int DetectEnginePktInspectionSetup (Signature *s)
 
int DetectEngineReloadStart (void)
 
int DetectEngineReloadIsStart (void)
 
void DetectEngineReloadSetIdle (void)
 
int DetectEngineReloadIsIdle (void)
 
uint8_t DetectEngineInspectGenericList (DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
 
uint8_t DetectEngineInspectBufferSingle (DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
 Do the content inspection & validation for a signature. More...
 
uint8_t DetectEngineInspectBufferGeneric (DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
 Do the content inspection & validation for a signature. More...
 
void DetectAppLayerMultiRegisterSubState (const char *name, AppProto alproto, uint32_t dir, uint8_t sub_state, uint8_t progress, InspectionMultiBufferGetDataPtr GetData, int priority)
 
void DetectAppLayerMultiRegister (const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectionMultiBufferGetDataPtr GetData, int priority)
 
InspectionBuffer * DetectGetSingleData (struct DetectEngineThreadCtx_ *det_ctx, const DetectEngineTransforms *transforms, Flow *f, const uint8_t flow_flags, void *txv, const int list_id, InspectionSingleBufferGetDataPtr GetBuf)
 
InspectionBuffer * DetectGetMultiData (struct DetectEngineThreadCtx_ *det_ctx, const DetectEngineTransforms *transforms, Flow *f, const uint8_t flow_flags, void *txv, const int list_id, uint32_t index, InspectionMultiBufferGetDataPtr GetBuf)
 
uint8_t DetectEngineInspectMultiBufferGeneric (DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
 
int DetectEngineInspectPktBufferGeneric (DetectEngineThreadCtx *det_ctx, const DetectEnginePktInspectionEngine *engine, const Signature *s, Packet *p, uint8_t *_alert_flags)
 Do the content inspection & validation for a signature. More...
 
bool DetectEngineMpmCachingEnabled (void)
 
const char * DetectEngineMpmCachingGetPath (void)
 
void DetectEngineMpmCacheService (uint32_t op_flags)
 
DetectEngineCtx * DetectEngineCtxInitStubForMT (void)
 
DetectEngineCtx * DetectEngineCtxInitStubForDD (void)
 
DetectEngineCtx * DetectEngineCtxInit (void)
 
DetectEngineCtx * DetectEngineCtxInitWithPrefix (const char *prefix, uint32_t tenant_id)
 
void DetectEngineCtxFree (DetectEngineCtx *de_ctx)
 Free a DetectEngineCtx:: More...
 
void DetectEngineResetMaxSigId (DetectEngineCtx *de_ctx)
 
TmEcode DetectEngineThreadCtxInit (ThreadVars *tv, void *initdata, void **data)
 initialize thread specific detection engine context More...
 
DetectEngineThreadCtx * DetectEngineThreadCtxInitForReload (ThreadVars *tv, DetectEngineCtx *new_de_ctx, int mt)
 
TmEcode DetectEngineThreadCtxDeinit (ThreadVars *tv, void *data)
 
int DetectRegisterThreadCtxFuncs (DetectEngineCtx *de_ctx, const char *name, void *(*InitFunc)(void *), void *data, void(*FreeFunc)(void *), int mode)
 Register Thread keyword context Funcs. More...
 
int DetectUnregisterThreadCtxFuncs (DetectEngineCtx *de_ctx, void *data, const char *name)
 Remove Thread keyword context registration. More...
 
void * DetectThreadCtxGetKeywordThreadCtx (DetectEngineThreadCtx *det_ctx, int id)
 Retrieve thread local keyword ctx by id. More...
 
int SCDetectRegisterThreadCtxGlobalFuncs (const char *name, void *(*InitFunc)(void *), void *data, void(*FreeFunc)(void *))
 Register Thread keyword context Funcs (Global) More...
 
void * SCDetectThreadCtxGetGlobalKeywordThreadCtx (DetectEngineThreadCtx *det_ctx, int id)
 Retrieve thread local keyword ctx by id. More...
 
int DetectEngineEnabled (void)
 Check if detection is enabled. More...
 
uint32_t DetectEngineGetVersion (void)
 
void DetectEngineBumpVersion (void)
 
DetectEngineCtx * DetectEngineGetCurrent (void)
 
DetectEngineCtx * DetectEngineReference (DetectEngineCtx *de_ctx)
 
bool DetectEngineMultiTenantEnabled (void)
 
int DetectEngineLoadTenantBlocking (uint32_t tenant_id, const char *yaml)
 Load a tenant and wait for loading to complete. More...
 
int DetectEngineReloadTenantBlocking (uint32_t tenant_id, const char *yaml, int reload_cnt)
 Reload a tenant and wait for loading to complete. More...
 
int DetectEngineReloadTenantsBlocking (const int reload_cnt)
 Reload all tenants and wait for loading to complete. More...
 
int DetectEngineMultiTenantSetup (const bool unix_socket)
 setup multi-detect / multi-tenancy More...
 
int DetectEngineTenantRegisterLivedev (uint32_t tenant_id, int device_id)
 
int DetectEngineTenantRegisterVlanId (uint32_t tenant_id, uint16_t vlan_id)
 
int DetectEngineTenantUnregisterVlanId (uint32_t tenant_id, uint16_t vlan_id)
 
int DetectEngineTenantRegisterPcapFile (uint32_t tenant_id)
 
int DetectEngineTenantUnregisterPcapFile (uint32_t tenant_id)
 
DetectEngineCtx * DetectEngineGetByTenantId (uint32_t tenant_id)
 
void DetectEngineDeReference (DetectEngineCtx **de_ctx)
 
int DetectEngineAddToMaster (DetectEngineCtx *de_ctx)
 
int DetectEngineMoveToFreeList (DetectEngineCtx *de_ctx)
 
void DetectEnginePruneFreeList (void)
 
void DetectEngineClearMaster (void)
 
int DetectEngineReload (const SCInstance *suri)
 Reload the detection engine. More...
 
int DetectEngineMTApply (void)
 
void DetectEngineSetParseMetadata (void)
 
void DetectEngineUnsetParseMetadata (void)
 
int DetectEngineMustParseMetadata (void)
 
const char * DetectSigmatchListEnumToString (enum DetectSigmatchListEnum type)
 
void DetectEngineSetEvent (DetectEngineThreadCtx *det_ctx, uint8_t e)
 
bool DetectMd5ValidateCallback (const Signature *s, const char **sigerror, const DetectBufferType *map)
 
void DetectLowerSetupCallback (const DetectEngineCtx *de_ctx, Signature *s, const DetectBufferType *map)
 
bool SCDetectEngineRegisterRateFilterCallback (SCDetectRateFilterFunc fn, void *arg)
 Register a callback when a rate_filter has been applied to an alert. More...
 
int DetectEngineThreadCtxGetJsonContext (DetectEngineThreadCtx *det_ctx)
 
void DetectEngineRegisterTests (void)
 

Variables

const struct SignatureProperties signature_properties [SIG_TYPE_MAX]
 

Detailed Description

Macro Definition Documentation

◆ DEFAULT_MAX_FLOWBITS_PER_SIGNATURE

#define DEFAULT_MAX_FLOWBITS_PER_SIGNATURE   8

Definition at line 98 of file detect-engine.c.

◆ DETECT_ENGINE_DEFAULT_INSPECTION_RECURSION_LIMIT

#define DETECT_ENGINE_DEFAULT_INSPECTION_RECURSION_LIMIT   3000

Definition at line 96 of file detect-engine.c.

Typedef Documentation

◆ DetectEngineSyncer

◆ TenantLoaderCtx

Enumeration Type Documentation

◆ DetectEngineSyncState

Enumerator
IDLE 

ready to start a reload

RELOAD 

command main thread to do the reload

Definition at line 2068 of file detect-engine.c.

Function Documentation

◆ DetectAppLayerInspectEngineRegister()

void DetectAppLayerInspectEngineRegister ( const char *  name,
AppProto  alproto,
uint32_t  dir,
uint8_t  progress,
InspectEngineFuncPtr  Callback2,
InspectionBufferGetDataPtr  GetData 
)

Registers an app inspection engine.

Parameters
nameName of the detection list
alprotoApp layer protocol for which we will register the engine.
directionThe direction for the engine: SIG_FLAG_TOSERVER or SIG_FLAG_TOCLIENT
progressMinimal progress value for inspect engine to run
CallbackThe engine callback.

Definition at line 275 of file detect-engine.c.

Referenced by SCDetectHelperBufferProgressRegister().

Here is the caller graph for this function:

◆ DetectAppLayerInspectEngineRegisterSingle()

void DetectAppLayerInspectEngineRegisterSingle ( const char *  name,
AppProto  alproto,
uint32_t  dir,
uint8_t  progress,
InspectEngineFuncPtr  Callback,
InspectionSingleBufferGetDataPtr  GetData 
)

Definition at line 321 of file detect-engine.c.

◆ DetectAppLayerInspectEngineRegisterSubState()

void DetectAppLayerInspectEngineRegisterSubState ( const char *  name,
AppProto  alproto,
uint32_t  dir,
uint8_t  type,
uint8_t  progress,
InspectEngineFuncPtr  Callback2,
InspectionBufferGetDataPtr  GetData 
)

register an app inspection engine for a tx type

Parameters
typethe tx type

Definition at line 298 of file detect-engine.c.

Referenced by DetectFileRegisterFileProtocols(), DetectRegisterAppLayerHookLists(), and SCDetectHelperBufferProgressRegisterSubState().

Here is the caller graph for this function:

◆ DetectAppLayerMultiRegister()

void DetectAppLayerMultiRegister ( const char *  name,
AppProto  alproto,
uint32_t  dir,
uint8_t  progress,
InspectionMultiBufferGetDataPtr  GetData,
int  priority 
)

Definition at line 2329 of file detect-engine.c.

◆ DetectAppLayerMultiRegisterSubState()

void DetectAppLayerMultiRegisterSubState ( const char *  name,
AppProto  alproto,
uint32_t  dir,
uint8_t  sub_state,
uint8_t  progress,
InspectionMultiBufferGetDataPtr  GetData,
int  priority 
)

Definition at line 2317 of file detect-engine.c.

◆ DetectBufferIsPresent()

bool DetectBufferIsPresent ( const Signature *  s,
const uint32_t  buf_id 
)

◆ DetectBufferTypeCloseRegistration()

void DetectBufferTypeCloseRegistration ( void  )

Definition at line 1841 of file detect-engine.c.

References BUG_ON.

◆ DetectBufferTypeGetByName()

int DetectBufferTypeGetByName ( const char *  name)

Definition at line 1452 of file detect-engine.c.

Referenced by DetectEngineAppInspectionEngine2Signature(), DetectFrameMpmRegister(), and DetectPktInspectEngineRegister().

Here is the caller graph for this function:

◆ DetectBufferTypeMaxId()

int DetectBufferTypeMaxId ( void  )

Definition at line 1209 of file detect-engine.c.

◆ DetectBufferTypeRegister()

int DetectBufferTypeRegister ( const char *  name)

Definition at line 1388 of file detect-engine.c.

References BUG_ON.

Referenced by DetectPktInspectEngineRegister(), SCDetectHelperBufferProgressRegister(), and SCDetectHelperBufferProgressRegisterSubState().

Here is the caller graph for this function:

◆ DetectBufferTypeRegisterSetupCallback()

void DetectBufferTypeRegisterSetupCallback ( const char *  name,
void(*)(const DetectEngineCtx *, Signature *, const DetectBufferType *)  SetupCallback 
)

Definition at line 1657 of file detect-engine.c.

References BUG_ON.

Referenced by SCDetectRegisterBufferLowerMd5Callbacks().

Here is the caller graph for this function:

◆ DetectBufferTypeRegisterValidateCallback()

void DetectBufferTypeRegisterValidateCallback ( const char *  name,
bool(*)(const Signature *, const char **sigerror, const DetectBufferType *)  ValidateCallback 
)

Definition at line 1675 of file detect-engine.c.

References BUG_ON.

Referenced by SCDetectRegisterBufferLowerMd5Callbacks().

Here is the caller graph for this function:

◆ DetectBufferTypeSetDescriptionByName()

void DetectBufferTypeSetDescriptionByName ( const char *  name,
const char *  desc 
)

Definition at line 1549 of file detect-engine.c.

References BUG_ON.

◆ DetectBufferTypeSetRunAlways()

void DetectBufferTypeSetRunAlways ( const char *  name)

Definition at line 1560 of file detect-engine.c.

◆ DetectBufferTypeSupportsFrames()

void DetectBufferTypeSupportsFrames ( const char *  name)

Definition at line 1412 of file detect-engine.c.

References BUG_ON.

Referenced by DetectFrameMpmRegister().

Here is the caller graph for this function:

◆ DetectBufferTypeSupportsMpm()

void DetectBufferTypeSupportsMpm ( const char *  name)

Definition at line 1432 of file detect-engine.c.

References BUG_ON.

Referenced by DetectFrameMpmRegister().

Here is the caller graph for this function:

◆ DetectBufferTypeSupportsMultiInstance()

void DetectBufferTypeSupportsMultiInstance ( const char *  name)

Definition at line 1402 of file detect-engine.c.

References BUG_ON.

◆ DetectBufferTypeSupportsPacket()

void DetectBufferTypeSupportsPacket ( const char *  name)

Definition at line 1422 of file detect-engine.c.

References BUG_ON.

◆ DetectBufferTypeSupportsTransformations()

void DetectBufferTypeSupportsTransformations ( const char *  name)

Definition at line 1442 of file detect-engine.c.

References BUG_ON.

Referenced by DetectFrameMpmRegister().

Here is the caller graph for this function:

◆ DetectEngineAddToMaster()

int DetectEngineAddToMaster ( DetectEngineCtx *  de_ctx)

Definition at line 4967 of file detect-engine.c.

References de_ctx, and SCLogDebug.

◆ DetectEngineAppHookToName()

const char* DetectEngineAppHookToName ( const AppProto  p,
const uint8_t  sub_state,
const uint8_t  state,
const uint8_t  direction 
)
Parameters
directionSTREAM_TOSERVER or STREAM_TOCLIENT

Definition at line 845 of file detect-engine.c.

References AppLayerParserGetStateNameById(), AppLayerParserGetStateProgressCompletionStatus(), AppLayerParserGetSubStateProgressName(), AppLayerParserSupportsSubStates(), BUG_ON, name, and p.

Referenced by DetectEngineAppHookToSmlist().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineAppHookToSmlist()

int DetectEngineAppHookToSmlist ( const AppProto  p,
const uint8_t  sub_state,
const uint8_t  state,
const uint8_t  direction 
)

get the sm_list for a app hook

Parameters
sub_statesub_state to use or 0 if not in use

Definition at line 884 of file detect-engine.c.

References AppProtoToStringRaw(), DetectEngineAppHookToName(), name, p, and SCLogError.

Referenced by DetectEngineAppInspectionEngine2Signature().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineAppInspectionEngine2Signature()

◆ DetectEngineAppInspectionEngineSignatureFree()

void DetectEngineAppInspectionEngineSignatureFree ( DetectEngineCtx *  de_ctx,
Signature *  s 
)

free app inspect engines for a signature

For lists that are registered multiple times, like http_header and http_cookie, making the engines owner of the lists is complicated. Multiple engines in a sig may be pointing to the same list. To address this the 'free' code needs to be extra careful about not double freeing, so it takes an approach to first fill an array of the to-free pointers before freeing them.

Definition at line 1103 of file detect-engine.c.

References Signature_::app_inspect, BUG_ON, SigMatchData_::ctx, de_ctx, Signature_::frame_inspect, SigTableElmt_::Free, SigMatchData_::is_last, next, DetectEngineAppInspectionEngine_::next, DetectEnginePktInspectionEngine::next, DetectEngineFrameInspectionEngine::next, Signature_::pkt_inspect, SCFree, sigmatch_table, DetectEngineAppInspectionEngine_::smd, DetectEnginePktInspectionEngine::smd, DetectEngineFrameInspectionEngine::smd, and SigMatchData_::type.

◆ DetectEngineBufferRunSetupCallback()

void DetectEngineBufferRunSetupCallback ( const DetectEngineCtx *  de_ctx,
const int  id,
Signature *  s 
)

Definition at line 1667 of file detect-engine.c.

References de_ctx, DetectEngineBufferTypeGetById(), and DetectBufferType_::SetupCallback.

Here is the call graph for this function:

◆ DetectEngineBufferRunValidateCallback()

bool DetectEngineBufferRunValidateCallback ( const DetectEngineCtx *  de_ctx,
const int  id,
const Signature *  s,
const char **  sigerror 
)

Definition at line 1686 of file detect-engine.c.

References DetectEngineTransforms::cnt, de_ctx, DetectEngineBufferTypeGetById(), DetectBufferType_::transforms, and DetectBufferType_::ValidateCallback.

Here is the call graph for this function:

◆ DetectEngineBufferTypeGetById()

◆ DetectEngineBufferTypeGetByIdTransforms()

int DetectEngineBufferTypeGetByIdTransforms ( DetectEngineCtx *  de_ctx,
const int  id,
TransformData *  transforms,
uint8_t  transform_cnt 
)

◆ DetectEngineBufferTypeGetDescriptionById()

const char* DetectEngineBufferTypeGetDescriptionById ( const DetectEngineCtx *  de_ctx,
const int  id 
)

Definition at line 1580 of file detect-engine.c.

References de_ctx, DetectBufferType_::description, and DetectEngineBufferTypeGetById().

Referenced by EngineAnalysisFP().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineBufferTypeGetNameById()

const char* DetectEngineBufferTypeGetNameById ( const DetectEngineCtx *  de_ctx,
const int  id 
)

Definition at line 1482 of file detect-engine.c.

References de_ctx, DetectEngineBufferTypeGetById(), and DetectBufferType_::name.

Referenced by DetectEngineBufferTypeSetRunAlways(), DumpPatterns(), EngineAnalysisFP(), and EngineAnalysisRules2().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineBufferTypeRegister()

int DetectEngineBufferTypeRegister ( DetectEngineCtx *  de_ctx,
const char *  name 
)

Definition at line 1539 of file detect-engine.c.

Referenced by DetectEngineFrameInspectEngineRegister(), and DetectEngineFrameMpmRegister().

Here is the caller graph for this function:

◆ DetectEngineBufferTypeRegisterWithFrameEngines()

int DetectEngineBufferTypeRegisterWithFrameEngines ( DetectEngineCtx *  de_ctx,
const char *  name,
const int  direction,
const AppProto  alproto,
const uint8_t  frame_type 
)

Definition at line 1505 of file detect-engine.c.

◆ DetectEngineBufferTypeSetRunAlways()

void DetectEngineBufferTypeSetRunAlways ( DetectEngineCtx *  de_ctx,
const int  id 
)

Definition at line 1569 of file detect-engine.c.

References de_ctx, DetectEngineBufferTypeGetNameById(), and name.

Here is the call graph for this function:

◆ DetectEngineBufferTypeSupportsFrames()

void DetectEngineBufferTypeSupportsFrames ( DetectEngineCtx *  de_ctx,
const char *  name 
)

Definition at line 1589 of file detect-engine.c.

Referenced by DetectEngineFrameMpmRegister().

Here is the caller graph for this function:

◆ DetectEngineBufferTypeSupportsFramesGetById()

bool DetectEngineBufferTypeSupportsFramesGetById ( const DetectEngineCtx *  de_ctx,
const int  id 
)

Definition at line 1648 of file detect-engine.c.

References de_ctx, DetectEngineBufferTypeGetById(), DetectBufferType_::frame, and SCLogDebug.

Here is the call graph for this function:

◆ DetectEngineBufferTypeSupportsMpm()

void DetectEngineBufferTypeSupportsMpm ( DetectEngineCtx *  de_ctx,
const char *  name 
)

Definition at line 1605 of file detect-engine.c.

Referenced by DetectEngineFrameMpmRegister().

Here is the caller graph for this function:

◆ DetectEngineBufferTypeSupportsMpmGetById()

bool DetectEngineBufferTypeSupportsMpmGetById ( const DetectEngineCtx *  de_ctx,
const int  id 
)

Definition at line 1639 of file detect-engine.c.

References de_ctx, DetectEngineBufferTypeGetById(), DetectBufferType_::mpm, and SCLogDebug.

Referenced by DetectGetLastSMFromMpmLists(), and FastPatternSupportEnabledForSigMatchList().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineBufferTypeSupportsMultiInstanceGetById()

bool DetectEngineBufferTypeSupportsMultiInstanceGetById ( const DetectEngineCtx *  de_ctx,
const int  id 
)

Definition at line 1621 of file detect-engine.c.

References BOOL2STR, de_ctx, DetectEngineBufferTypeGetById(), DetectBufferType_::multi_instance, and SCLogDebug.

Referenced by DetectBufferGetActiveList().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineBufferTypeSupportsPacket()

void DetectEngineBufferTypeSupportsPacket ( DetectEngineCtx *  de_ctx,
const char *  name 
)

Definition at line 1597 of file detect-engine.c.

◆ DetectEngineBufferTypeSupportsPacketGetById()

bool DetectEngineBufferTypeSupportsPacketGetById ( const DetectEngineCtx *  de_ctx,
const int  id 
)

Definition at line 1630 of file detect-engine.c.

References de_ctx, DetectEngineBufferTypeGetById(), DetectBufferType_::packet, and SCLogDebug.

Here is the call graph for this function:

◆ DetectEngineBufferTypeSupportsTransformations()

void DetectEngineBufferTypeSupportsTransformations ( DetectEngineCtx *  de_ctx,
const char *  name 
)

Definition at line 1613 of file detect-engine.c.

Referenced by DetectEngineFrameMpmRegister().

Here is the caller graph for this function:

◆ DetectEngineBufferTypeValidateTransform()

bool DetectEngineBufferTypeValidateTransform ( DetectEngineCtx *  de_ctx,
int  sm_list,
const uint8_t *  content,
uint16_t  content_len,
const char **  namestr 
)

Check content byte array compatibility with transforms.

The "content" array is presented to the transforms so that each transform may validate that it's compatible with the transform.

When a transform indicates the byte array is incompatible, none of the subsequent transforms, if any, are invoked. This means the first validation failure terminates the loop.

Parameters
de_ctxDetection engine context.
sm_listThe SM list id.
contentThe byte array being validated
namestrreturns the name of the transform that is incompatible with content.
Return values
true(false) If any of the transforms indicate the byte array is (is not) compatible.

Definition at line 1725 of file detect-engine.c.

References BUG_ON, DetectEngineTransforms::cnt, de_ctx, DetectEngineBufferTypeGetById(), SigTableElmt_::name, TransformData_::options, sigmatch_table, TransformData_::transform, DetectEngineTransforms::transforms, DetectBufferType_::transforms, and SigTableElmt_::TransformValidate.

Referenced by DetectContentSetup().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineBumpVersion()

void DetectEngineBumpVersion ( void  )

Definition at line 4133 of file detect-engine.c.

◆ DetectEngineClearMaster()

void DetectEngineClearMaster ( void  )

Definition at line 5067 of file detect-engine.c.

Referenced by GlobalsDestroy().

Here is the caller graph for this function:

◆ DetectEngineCtxFree()

◆ DetectEngineCtxInit()

DetectEngineCtx* DetectEngineCtxInit ( void  )

Definition at line 2873 of file detect-engine.c.

Referenced by DetectEngineCtxInitWithPrefix(), UTHGenericTest(), UTHPacketMatchSig(), UTHPacketMatchSigMpm(), and UTHParseSignature().

Here is the caller graph for this function:

◆ DetectEngineCtxInitStubForDD()

DetectEngineCtx* DetectEngineCtxInitStubForDD ( void  )

Definition at line 2868 of file detect-engine.c.

◆ DetectEngineCtxInitStubForMT()

DetectEngineCtx* DetectEngineCtxInitStubForMT ( void  )

Definition at line 2863 of file detect-engine.c.

◆ DetectEngineCtxInitWithPrefix()

DetectEngineCtx* DetectEngineCtxInitWithPrefix ( const char *  prefix,
uint32_t  tenant_id 
)

Definition at line 2878 of file detect-engine.c.

References DetectEngineCtxInit().

Here is the call graph for this function:

◆ DetectEngineDeReference()

void DetectEngineDeReference ( DetectEngineCtx **  de_ctx)

Definition at line 4943 of file detect-engine.c.

References de_ctx, and DEBUG_VALIDATE_BUG_ON.

Referenced by DetectEngineMpmCacheService(), GlobalsDestroy(), and SCDetectEngineRegisterRateFilterCallback().

Here is the caller graph for this function:

◆ DetectEngineEnabled()

int DetectEngineEnabled ( void  )

Check if detection is enabled.

Return values
booltrue or false

Definition at line 4109 of file detect-engine.c.

◆ DetectEngineFrameInspectEngineRegister()

◆ DetectEngineGetByTenantId()

DetectEngineCtx* DetectEngineGetByTenantId ( uint32_t  tenant_id)

Definition at line 4917 of file detect-engine.c.

◆ DetectEngineGetCurrent()

DetectEngineCtx* DetectEngineGetCurrent ( void  )

Definition at line 4142 of file detect-engine.c.

Referenced by DetectEngineMpmCacheService(), DetectEngineThreadCtxInit(), GlobalsDestroy(), and SCDetectEngineRegisterRateFilterCallback().

Here is the caller graph for this function:

◆ DetectEngineGetVersion()

uint32_t DetectEngineGetVersion ( void  )

Definition at line 4123 of file detect-engine.c.

References version.

◆ DetectEngineInspectBufferGeneric()

uint8_t DetectEngineInspectBufferGeneric ( DetectEngineCtx *  de_ctx,
DetectEngineThreadCtx *  det_ctx,
const DetectEngineAppInspectionEngine *  engine,
const Signature *  s,
Flow *  f,
uint8_t  flags,
void *  alstate,
void *  txv,
uint64_t  tx_id 
)

Do the content inspection & validation for a signature.

Parameters
de_ctxDetection engine context
det_ctxDetection engine thread context
sSignature to inspect
fFlow
flagsapp layer flags
stateApp layer state
Return values
0no match.
1match.
2Sig can't match.

Definition at line 2267 of file detect-engine.c.

References SCLogDebug, and DetectEngineAppInspectionEngine_::sm_list.

◆ DetectEngineInspectBufferSingle()

uint8_t DetectEngineInspectBufferSingle ( DetectEngineCtx *  de_ctx,
DetectEngineThreadCtx *  det_ctx,
const DetectEngineAppInspectionEngine *  engine,
const Signature *  s,
Flow *  f,
uint8_t  flags,
void *  alstate,
void *  txv,
uint64_t  tx_id 
)

Do the content inspection & validation for a signature.

Parameters
de_ctxDetection engine context
det_ctxDetection engine thread context
sSignature to inspect
fFlow
flagsapp layer flags
stateApp layer state
Return values
0no match.
1match.
2Sig can't match.

Definition at line 2207 of file detect-engine.c.

References SCLogDebug, and DetectEngineAppInspectionEngine_::sm_list.

◆ DetectEngineInspectGenericList()

uint8_t DetectEngineInspectGenericList ( DetectEngineCtx *  de_ctx,
DetectEngineThreadCtx *  det_ctx,
const struct DetectEngineAppInspectionEngine_ *  engine,
const Signature *  s,
Flow *  f,
uint8_t  flags,
void *  alstate,
void *  txv,
uint64_t  tx_id 
)

◆ DetectEngineInspectMultiBufferGeneric()

◆ DetectEngineInspectPktBufferGeneric()

int DetectEngineInspectPktBufferGeneric ( DetectEngineThreadCtx *  det_ctx,
const DetectEnginePktInspectionEngine *  engine,
const Signature *  s,
Packet *  p,
uint8_t *  _alert_flags 
)

◆ DetectEngineLoadTenantBlocking()

int DetectEngineLoadTenantBlocking ( uint32_t  tenant_id,
const char *  yaml 
)

Load a tenant and wait for loading to complete.

Definition at line 4438 of file detect-engine.c.

◆ DetectEngineMoveToFreeList()

int DetectEngineMoveToFreeList ( DetectEngineCtx *  de_ctx)

Definition at line 5027 of file detect-engine.c.

Referenced by GlobalsDestroy().

Here is the caller graph for this function:

◆ DetectEngineMpmCacheService()

◆ DetectEngineMpmCachingEnabled()

bool DetectEngineMpmCachingEnabled ( void  )

Definition at line 2683 of file detect-engine.c.

References SCConfGetBool().

Referenced by DetectEngineMpmCachingGetPath().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineMpmCachingGetPath()

const char* DetectEngineMpmCachingGetPath ( void  )

Definition at line 2692 of file detect-engine.c.

References DetectEngineMpmCachingEnabled(), SCConfGet(), and SCLogInfo.

Here is the call graph for this function:

◆ DetectEngineMTApply()

int DetectEngineMTApply ( void  )

Definition at line 5226 of file detect-engine.c.

◆ DetectEngineMultiTenantEnabled()

bool DetectEngineMultiTenantEnabled ( void  )

Definition at line 4179 of file detect-engine.c.

◆ DetectEngineMultiTenantSetup()

int DetectEngineMultiTenantSetup ( const bool  unix_socket)

setup multi-detect / multi-tenancy

See if MT is enabled. If so, setup the selector, tenants and mappings. Tenants and mappings are optional, and can also dynamically be added and removed from the unix socket.

Definition at line 4601 of file detect-engine.c.

References TENANT_SELECTOR_UNKNOWN.

◆ DetectEngineMustParseMetadata()

int DetectEngineMustParseMetadata ( void  )

Definition at line 5293 of file detect-engine.c.

Referenced by DetectMetadataHashInit().

Here is the caller graph for this function:

◆ DetectEnginePktInspectionRun()

bool DetectEnginePktInspectionRun ( ThreadVars *  tv,
DetectEngineThreadCtx *  det_ctx,
const Signature *  s,
Flow *  f,
Packet *  p,
uint8_t *  alert_flags 
)

◆ DetectEnginePktInspectionSetup()

int DetectEnginePktInspectionSetup ( Signature *  s)

◆ DetectEnginePruneFreeList()

void DetectEnginePruneFreeList ( void  )

Definition at line 5037 of file detect-engine.c.

◆ DetectEngineReference()

DetectEngineCtx* DetectEngineReference ( DetectEngineCtx *  de_ctx)

Definition at line 4165 of file detect-engine.c.

References de_ctx, and DetectEngineCtx_::ref_cnt.

Referenced by DetectEngineThreadCtxInitForReload().

Here is the caller graph for this function:

◆ DetectEngineRegisterTests()

void DetectEngineRegisterTests ( void  )

Definition at line 5705 of file detect-engine.c.

References UtRegisterTest().

Here is the call graph for this function:

◆ DetectEngineReload()

int DetectEngineReload ( const SCInstance *  suri)

Reload the detection engine.

Parameters
filenameYAML file to load for the detect config
Return values
-1error
0ok

Definition at line 5094 of file detect-engine.c.

References SCInstance_::conf_filename, and SCLogNotice.

Referenced by SuricataMainLoop().

Here is the caller graph for this function:

◆ DetectEngineReloadIsIdle()

int DetectEngineReloadIsIdle ( void  )

Definition at line 2116 of file detect-engine.c.

References SCMutexLock.

◆ DetectEngineReloadIsStart()

int DetectEngineReloadIsStart ( void  )

Definition at line 2096 of file detect-engine.c.

References SCMutexLock.

Referenced by SuricataMainLoop().

Here is the caller graph for this function:

◆ DetectEngineReloadSetIdle()

void DetectEngineReloadSetIdle ( void  )

Definition at line 2108 of file detect-engine.c.

References SCMutexLock.

Referenced by SuricataMainLoop().

Here is the caller graph for this function:

◆ DetectEngineReloadStart()

int DetectEngineReloadStart ( void  )

Definition at line 2082 of file detect-engine.c.

References SCMutexLock.

Referenced by SuricataMainLoop().

Here is the caller graph for this function:

◆ DetectEngineReloadTenantBlocking()

int DetectEngineReloadTenantBlocking ( uint32_t  tenant_id,
const char *  yaml,
int  reload_cnt 
)

Reload a tenant and wait for loading to complete.

Definition at line 4452 of file detect-engine.c.

◆ DetectEngineReloadTenantsBlocking()

int DetectEngineReloadTenantsBlocking ( const int  reload_cnt)

Reload all tenants and wait for loading to complete.

Definition at line 4466 of file detect-engine.c.

◆ DetectEngineResetMaxSigId()

void DetectEngineResetMaxSigId ( DetectEngineCtx *  de_ctx)

Definition at line 3336 of file detect-engine.c.

References de_ctx, and DetectEngineCtx_::signum.

Referenced by SigCleanSignatures().

Here is the caller graph for this function:

◆ DetectEngineSetEvent()

void DetectEngineSetEvent ( DetectEngineThreadCtx *  det_ctx,
uint8_t  e 
)

Definition at line 5327 of file detect-engine.c.

References DetectEngineThreadCtx_::decoder_events, DetectEngineThreadCtx_::events, and SCAppLayerDecoderEventsSetEventRaw().

Referenced by FileSwfDecompression(), FileSwfZlibDecompression(), InspectionBufferMultipleForListGet(), and PostRuleMatchWorkQueueAppend().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineSetParseMetadata()

void DetectEngineSetParseMetadata ( void  )

Definition at line 5283 of file detect-engine.c.

◆ DetectEngineTenantRegisterLivedev()

int DetectEngineTenantRegisterLivedev ( uint32_t  tenant_id,
int  device_id 
)

Definition at line 4884 of file detect-engine.c.

◆ DetectEngineTenantRegisterPcapFile()

int DetectEngineTenantRegisterPcapFile ( uint32_t  tenant_id)

Definition at line 4900 of file detect-engine.c.

References SCLogInfo, and TENANT_SELECTOR_DIRECT.

◆ DetectEngineTenantRegisterVlanId()

int DetectEngineTenantRegisterVlanId ( uint32_t  tenant_id,
uint16_t  vlan_id 
)

Definition at line 4890 of file detect-engine.c.

◆ DetectEngineTenantUnregisterPcapFile()

int DetectEngineTenantUnregisterPcapFile ( uint32_t  tenant_id)

Definition at line 4906 of file detect-engine.c.

References SCLogInfo, and TENANT_SELECTOR_DIRECT.

◆ DetectEngineTenantUnregisterVlanId()

int DetectEngineTenantUnregisterVlanId ( uint32_t  tenant_id,
uint16_t  vlan_id 
)

Definition at line 4895 of file detect-engine.c.

◆ DetectEngineThreadCtxDeinit()

TmEcode DetectEngineThreadCtxDeinit ( ThreadVars *  tv,
void *  data 
)

Definition at line 3905 of file detect-engine.c.

References HashTableFree(), DetectEngineThreadCtx_::mt_det_ctxs_hash, SCLogWarning, and TM_ECODE_OK.

Referenced by DetectEngineThreadCtxInit(), UTHMatchPackets(), UTHMatchPacketsWithResults(), UTHPacketMatchSig(), and UTHPacketMatchSigMpm().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineThreadCtxGetJsonContext()

◆ DetectEngineThreadCtxInit()

TmEcode DetectEngineThreadCtxInit ( ThreadVars *  tv,
void *  initdata,
void **  data 
)

initialize thread specific detection engine context

Note
there is a special case when using delayed detect. In this case the function is called twice per thread. The first time the rules are not yet loaded. de_ctx->delayed_detect_initialized will be 0. The 2nd time they will be loaded. de_ctx->delayed_detect_initialized will be 1. This is needed to do the per thread counter registration before the packet runtime starts. In delayed detect mode, the first call will return a NULL ptr through the data ptr.
Parameters
tvThreadVars for this thread
initdatapointer to de_ctx
data[out]pointer to store our thread detection ctx
Return values
TM_ECODE_OKif all went well
TM_ECODE_FAILEDon serious errors

alert counter setup

Definition at line 3660 of file detect-engine.c.

References DetectEngineThreadCtx_::de_ctx, DETECT_ENGINE_TYPE_NORMAL, DETECT_ENGINE_TYPE_TENANT, DetectEngineGetCurrent(), DetectEngineThreadCtxDeinit(), RunmodeIsUnittests(), SCCalloc, TM_ECODE_FAILED, tv, DetectEngineThreadCtx_::tv, DetectEngineCtx_::type, and unlikely.

Referenced by UTHMatchPackets(), UTHMatchPacketsWithResults(), UTHPacketMatchSig(), and UTHPacketMatchSigMpm().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectEngineThreadCtxInitForReload()

DetectEngineThreadCtx* DetectEngineThreadCtxInitForReload ( ThreadVars *  tv,
DetectEngineCtx *  new_de_ctx,
int  mt 
)

◆ DetectEngineUnsetParseMetadata()

void DetectEngineUnsetParseMetadata ( void  )

Definition at line 5288 of file detect-engine.c.

◆ DetectGetMultiData()

InspectionBuffer* DetectGetMultiData ( struct DetectEngineThreadCtx_ *  det_ctx,
const DetectEngineTransforms *  transforms,
Flow *  f,
const uint8_t  flow_flags,
void *  txv,
const int  list_id,
uint32_t  index,
InspectionMultiBufferGetDataPtr  GetBuf 
)

Definition at line 2356 of file detect-engine.c.

References DETECT_CI_FLAGS_SINGLE, InspectionBuffer::flags, InspectionBuffer::initialized, InspectionBufferMultipleForListGet(), InspectionBufferSetupMulti(), and InspectionBufferSetupMultiEmpty().

Referenced by DetectEngineInspectMultiBufferGeneric().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ DetectGetSingleData()

InspectionBuffer* DetectGetSingleData ( struct DetectEngineThreadCtx_ *  det_ctx,
const DetectEngineTransforms *  transforms,
Flow *  f,
const uint8_t  flow_flags,
void *  txv,
const int  list_id,
InspectionSingleBufferGetDataPtr  GetBuf 
)

Definition at line 2339 of file detect-engine.c.

References InspectionBuffer::inspect, SCInspectionBufferGet(), and SCInspectionBufferSetupAndApplyTransforms().

Here is the call graph for this function:

◆ DetectLowerSetupCallback()

◆ DetectMd5ValidateCallback()

◆ DetectPktInspectEngineRegister()

void DetectPktInspectEngineRegister ( const char *  name,
InspectionBufferGetPktDataPtr  GetPktData,
InspectionBufferPktInspectFunc  Callback 
)

◆ DetectRegisterThreadCtxFuncs()

int DetectRegisterThreadCtxFuncs ( DetectEngineCtx *  de_ctx,
const char *  name,
void *(*)(void *)  InitFunc,
void *  data,
void(*)(void *)  FreeFunc,
int  mode 
)

Register Thread keyword context Funcs.

Parameters
de_ctxdetection engine to register in
namekeyword name for error printing
InitFuncfunction ptr
datakeyword init data to pass to Func. Can be NULL.
FreeFuncfunction ptr
mode0 normal (ctx per keyword instance) 1 shared (one ctx per det_ct)
Return values
idfor retrieval of ctx at runtime
-1on error
Note
make sure "data" remains valid and it free'd elsewhere. It's recommended to store it in the keywords global ctx so that it's freed when the de_ctx is freed.

Definition at line 3963 of file detect-engine.c.

References BUG_ON, de_ctx, HashListTableInit(), and DetectEngineCtx_::keyword_hash.

Here is the call graph for this function:

◆ DetectSigmatchListEnumToString()

◆ DetectTableToString()

◆ DetectThreadCtxGetKeywordThreadCtx()

void* DetectThreadCtxGetKeywordThreadCtx ( DetectEngineThreadCtx *  det_ctx,
int  id 
)

Retrieve thread local keyword ctx by id.

Parameters
det_ctxdetection engine thread ctx to retrieve the ctx from
idid of the ctx returned by DetectRegisterThreadCtxInitFunc at keyword init.
Return values
ctxor NULL on error

Definition at line 4033 of file detect-engine.c.

References DetectEngineThreadCtx_::keyword_ctxs_array, and DetectEngineThreadCtx_::keyword_ctxs_size.

Referenced by DetectLuaMatchBuffer(), and DetectPcrePayloadMatch().

Here is the caller graph for this function:

◆ DetectUnregisterThreadCtxFuncs()

int DetectUnregisterThreadCtxFuncs ( DetectEngineCtx *  de_ctx,
void *  data,
const char *  name 
)

Remove Thread keyword context registration.

Parameters
de_ctxdetection engine to deregister from
det_ctxdetection engine thread context to deregister from
datakeyword init data to pass to Func. Can be NULL.
namekeyword name for error printing
Return values
1Item unregistered
0otherwise
Note
make sure "data" remains valid and it free'd elsewhere. It's recommended to store it in the keywords global ctx so that it's freed when the de_ctx is freed.

Definition at line 4015 of file detect-engine.c.

References DetectEngineThreadKeywordCtxItem_::data, de_ctx, HashListTableRemove(), DetectEngineCtx_::keyword_hash, and name.

Here is the call graph for this function:

◆ SCDetectEngineRegisterRateFilterCallback()

bool SCDetectEngineRegisterRateFilterCallback ( SCDetectRateFilterFunc  cb,
void *  arg 
)

Register a callback when a rate_filter has been applied to an alert.

This callback is added to the current detection engine and will be copied to all future detection engines over rule reloads.

Definition at line 5405 of file detect-engine.c.

References de_ctx, DetectEngineDeReference(), DetectEngineGetCurrent(), DetectEngineCtx_::rate_filter_callback_arg, DetectEngineCtx_::RateFilterCallback, and SCLogError.

Here is the call graph for this function:

◆ SCDetectRegisterThreadCtxGlobalFuncs()

int SCDetectRegisterThreadCtxGlobalFuncs ( const char *  name,
void *(*)(void *)  InitFunc,
void *  data,
void(*)(void *)  FreeFunc 
)

Register Thread keyword context Funcs (Global)

IDs stay static over reloads and between tenants

Parameters
namekeyword name for error printing
InitFuncfunction ptr
FreeFuncfunction ptr
Return values
idfor retrieval of ctx at runtime
-1on error

Definition at line 4053 of file detect-engine.c.

References BUG_ON.

◆ SCDetectThreadCtxGetGlobalKeywordThreadCtx()

void* SCDetectThreadCtxGetGlobalKeywordThreadCtx ( DetectEngineThreadCtx *  det_ctx,
int  id 
)

Retrieve thread local keyword ctx by id.

Parameters
det_ctxdetection engine thread ctx to retrieve the ctx from
idid of the ctx returned by DetectRegisterThreadCtxInitFunc at keyword init.
Return values
ctxor NULL on error

Definition at line 4097 of file detect-engine.c.

References DetectEngineThreadCtx_::global_keyword_ctxs_array, and DetectEngineThreadCtx_::global_keyword_ctxs_size.

Referenced by HttpHeaderGetBufferSpace().

Here is the caller graph for this function:

Variable Documentation

◆ signature_properties

SIG_PROP_FLOW_ACTION_PACKET
@ SIG_PROP_FLOW_ACTION_PACKET
Definition: detect.h:85
SIG_PROP_FLOW_ACTION_FLOW_IF_STATEFUL
@ SIG_PROP_FLOW_ACTION_FLOW_IF_STATEFUL
Definition: detect.h:87
SIG_PROP_FLOW_ACTION_FLOW
@ SIG_PROP_FLOW_ACTION_FLOW
Definition: detect.h:86