Go to the documentation of this file.
69 void *state,
void *txv,
const Signature *s,
73 static void DetectLuaRegisterTests(
void);
76 static int g_lua_ja3_list_id = 0;
77 static int g_lua_ja3s_list_id = 0;
111 #define FLAG_DATATYPE_PACKET BIT_U32(0)
112 #define FLAG_DATATYPE_PAYLOAD BIT_U32(1)
113 #define FLAG_LIST_JA3 BIT_U32(3)
114 #define FLAG_LIST_JA3S BIT_U32(4)
115 #define FLAG_ERROR_LOGGED BIT_U32(23)
116 #define FLAG_BLOCKED_FUNCTION_LOGGED BIT_U32(24)
117 #define FLAG_INSTRUCTION_LIMIT_LOGGED BIT_U32(25)
118 #define FLAG_MEMORY_LIMIT_LOGGED BIT_U32(26)
120 #define DEFAULT_LUA_ALLOC_LIMIT 500000
121 #define DEFAULT_LUA_INSTRUCTION_LIMIT 500000
126 int size = lua_gettop(state);
127 printf(
"%s: size %d\n", prefix, size);
129 for (
int i = 1; i <= size; i++) {
130 int type = lua_type(state, i);
131 printf(
"- %s: Stack size=%d, level=%d, type=%d, ", prefix, size, i,
type);
135 printf(
"function %s", lua_tostring(state, i));
138 printf(
"bool %s", lua_toboolean(state, i) ?
"true" :
"false");
141 printf(
"number %g", lua_tonumber(state, i));
144 printf(
"string `%s'", lua_tostring(state, i));
147 printf(
"table `%s'", lua_tostring(state, i));
150 printf(
"other %s", lua_typename(state,
type));
161 lua_pushlightuserdata(state, (
void *)data);
162 lua_settable(state, LUA_REGISTRYINDEX);
169 static int DetectLuaRunMatch(
175 if (lua_pcall(tlua->
luastate, 1, 1, 0) != 0) {
176 const char *reason = lua_tostring(tlua->
luastate, -1);
187 reason =
"memory limit exceeded";
195 if (!(tlua->
flags & flag)) {
196 SCLogWarning(
"Lua script failed to run successfully: %s", reason);
201 while (lua_gettop(tlua->
luastate) > 0) {
210 if (lua_gettop(tlua->
luastate) > 0) {
212 if (lua_type(tlua->
luastate, 1) == LUA_TNUMBER) {
213 lua_Integer script_ret = lua_tointeger(tlua->
luastate, 1);
219 SCLogDebug(
"Unsupported datatype returned from Lua script");
230 while (lua_gettop(tlua->
luastate) > 0) {
243 if (buffer == NULL || buffer_len == 0)
262 lua_getglobal(tlua->
luastate,
"match");
265 lua_pushliteral(tlua->
luastate,
"offset");
276 int r = DetectLuaRunMatch(det_ctx, lua, tlua);
309 flags = STREAM_TOSERVER;
311 flags = STREAM_TOCLIENT;
328 lua_getglobal(tlua->
luastate,
"match");
334 int r = DetectLuaRunMatch(det_ctx, lua, tlua);
360 lua_getglobal(tlua->
luastate,
"match");
366 int r = DetectLuaRunMatch(det_ctx, lua, tlua);
385 void *state,
void *txv,
const Signature *s,
388 return DetectLuaAppMatchCommon(det_ctx,
f,
flags, state, s,
ctx);
394 static const char *ut_script = NULL;
397 static void *DetectLuaThreadInit(
void *data,
bool allow_restricted_functions)
417 if (allow_restricted_functions) {
424 LuaStateSetDetectLuaData(t->
luastate, lua);
428 if (ut_script != NULL) {
429 status = luaL_loadbuffer(t->
luastate, ut_script, strlen(ut_script),
"unittest");
446 if (lua_pcall(t->
luastate, 0, 0, 0) != 0) {
452 lua_getglobal(t->
luastate,
"thread_init");
453 if (lua_isfunction(t->
luastate, -1)) {
454 if (lua_pcall(t->
luastate, 0, 0, 0) != 0) {
455 SCLogError(
"couldn't run script 'thread_init' function: %s",
472 static void *DetectLuaThreadRestrictedInit(
void *data)
474 return DetectLuaThreadInit(data,
false);
477 static void *DetectLuaThreadAllowInit(
void *data)
479 return DetectLuaThreadInit(data,
true);
482 static void DetectLuaThreadFree(
void *
ctx)
510 if (strlen(
str) &&
str[0] ==
'!') {
524 DetectLuaFree(
de_ctx, lua);
529 int allow_restricted_functions)
534 if (luastate == NULL)
536 if (allow_restricted_functions) {
537 luaL_openlibs(luastate);
542 LuaStateSetDetectLuaData(luastate, ld);
546 if (ut_script != NULL) {
547 status = luaL_loadbuffer(luastate, ut_script, strlen(ut_script),
"unittest");
549 SCLogError(
"couldn't load file: %s", lua_tostring(luastate, -1));
554 status = luaL_loadfile(luastate, ld->
filename);
556 SCLogError(
"couldn't load file: %s", lua_tostring(luastate, -1));
564 if (lua_pcall(luastate, 0, 0, 0) != 0) {
565 SCLogError(
"couldn't prime file: %s", lua_tostring(luastate, -1));
569 lua_getglobal(luastate,
"init");
570 if (lua_type(luastate, -1) != LUA_TFUNCTION) {
577 lua_pushlightuserdata(luastate, (
void *)s);
579 if (lua_pcall(luastate, 1, 1, 0) != 0) {
580 SCLogError(
"couldn't run script 'init' function: %s", lua_tostring(luastate, -1));
585 if (lua_gettop(luastate) == 0) {
586 SCLogError(
"init function in script should return table, nothing returned");
589 if (lua_type(luastate, 1) != LUA_TTABLE) {
590 SCLogError(
"init function in script should return table, returned is not table");
594 lua_pushnil(luastate);
596 while (lua_next(luastate, -2)) {
597 k = lua_tostring(luastate, -2);
602 if (strcmp(k,
"flowvar") == 0) {
603 if (lua_istable(luastate, -1)) {
604 lua_pushnil(luastate);
605 while (lua_next(luastate, -2) != 0) {
607 const char *value = lua_tostring(luastate, -1);
610 lua_pop(luastate, 1);
624 lua_pop(luastate, 1);
626 }
else if (strcmp(k,
"flowint") == 0) {
627 if (lua_istable(luastate, -1)) {
628 lua_pushnil(luastate);
629 while (lua_next(luastate, -2) != 0) {
631 const char *value = lua_tostring(luastate, -1);
634 lua_pop(luastate, 1);
648 lua_pop(luastate, 1);
652 bool required = lua_toboolean(luastate, -1);
653 lua_pop(luastate, 1);
658 if (strcmp(k,
"ja3") == 0) {
660 }
else if (strcmp(k,
"ja3s") == 0) {
662 }
else if (strcmp(k,
"packet") == 0) {
664 }
else if (strcmp(k,
"payload") == 0) {
666 }
else if (strcmp(k,
"buffer") == 0) {
672 }
else if (strcmp(k,
"stream") == 0) {
679 }
else if (strncmp(k,
"http", 4) == 0 || strncmp(k,
"dns", 3) == 0 ||
680 strncmp(k,
"tls", 3) == 0 || strncmp(k,
"ssh", 3) == 0 ||
681 strncmp(k,
"smtp", 4) == 0 || strncmp(k,
"dnp3", 4) == 0) {
682 SCLogError(
"data type %s no longer supported, use rule hooks", k);
692 lua_pop(luastate, 1);
716 if (
SCConfGetBool(
"security.lua.allow-rules", &enabled) == 1 && !enabled) {
717 SCLogError(
"Lua rules disabled by security configuration: security.lua.allow-rules");
728 (void)
SCConfGetInt(
"security.lua.max-bytes", &lua_alloc_limit);
729 (void)
SCConfGetInt(
"security.lua.max-instructions", &lua_instruction_limit);
733 int allow_restricted_functions = 0;
734 (void)
SCConfGetBool(
"security.lua.allow-restricted-functions", &allow_restricted_functions);
736 if (DetectLuaSetupPrime(
de_ctx, lua, s, allow_restricted_functions) == -1) {
740 void *cb = DetectLuaThreadRestrictedInit;
741 if (allow_restricted_functions) {
742 cb = DetectLuaThreadAllowInit;
752 if (list == -1 || (list == 0 && s->
init_data->
list == INT_MAX)) {
770 list = g_lua_ja3_list_id;
772 list = g_lua_ja3s_list_id;
784 DetectLuaFree(
de_ctx, lua);
803 for (uint16_t i = 0; i < lua->
flowints; i++) {
806 for (uint16_t i = 0; i < lua->
flowvars; i++) {
809 for (uint16_t i = 0; i < lua->
bytevars; i++) {
823 static int LuaMatchTest01(
void)
827 const char script[] =
"local flowvarlib = require(\"suricata.flowvar\")\n"
828 "function init (args)\n"
829 " flowvarlib.register(\"cnt\")\n"
832 "function thread_init (args)\n"
833 " cnt = flowvarlib.get(\"cnt\")\n"
836 "function match(args)\n"
839 " a = tostring(tonumber(a)+1)\n"
848 " print (\"pre check: \" .. (a))\n"
849 " if tonumber(a) == 2 then\n"
856 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
859 "POST / HTTP/1.1\r\n"
860 "Host: www.emergingthreats.net\r\n\r\n";
862 "POST / HTTP/1.1\r\n"
863 "Host: www.openinfosecfoundation.org\r\n\r\n";
864 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
865 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
877 memset(&
f, 0,
sizeof(
f));
878 memset(&
ssn, 0,
sizeof(
ssn));
949 static int LuaMatchTest01a(
void)
951 const char script[] =
"local flowvarlib = require(\"suricata.flowvar\")\n"
952 "function init (args)\n"
953 " flowvarlib.register(\"cnt\")\n"
956 "function thread_init (args)\n"
957 " cnt = flowvarlib.get(\"cnt\")\n"
960 "function match(args)\n"
961 " a = cnt:value(0)\n"
963 " a = tostring(tonumber(a)+1)\n"
972 " print (\"pre check: \" .. (a))\n"
973 " if tonumber(a) == 2 then\n"
980 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
982 uint8_t httpbuf1[] =
"POST / HTTP/1.1\r\n"
983 "Host: www.emergingthreats.net\r\n\r\n";
984 uint8_t httpbuf2[] =
"POST / HTTP/1.1\r\n"
985 "Host: www.openinfosecfoundation.org\r\n\r\n";
986 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
987 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
999 memset(&
f, 0,
sizeof(
f));
1000 memset(&
ssn, 0,
sizeof(
ssn));
1072 static int LuaMatchTest02(
void)
1074 const char script[] =
"local flowvarlib = require(\"suricata.flowvar\")\n"
1075 "function init (args)\n"
1076 " flowvarlib.register(\"cnt\")\n"
1077 " local needs = {}\n"
1078 " needs[\"payload\"] = tostring(true)\n"
1081 "function thread_init (args)\n"
1082 " cnt = flowvarlib.get(\"cnt\")\n"
1085 "function match(args)\n"
1086 " a = cnt:value()\n"
1088 " a = tostring(tonumber(a)+1)\n"
1092 " a = tostring(1)\n"
1097 " print (\"pre check: \" .. (a))\n"
1098 " if tonumber(a) == 2 then\n"
1099 " print \"match\"\n"
1105 char sig[] =
"alert tcp any any -> any any (flow:to_server; lua:unittest; sid:1;)";
1106 uint8_t httpbuf1[] =
"POST / HTTP/1.1\r\n"
1107 "Host: www.emergingthreats.net\r\n\r\n";
1108 uint8_t httpbuf2[] =
"POST / HTTP/1.1\r\n"
1109 "Host: www.openinfosecfoundation.org\r\n\r\n";
1110 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1111 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1121 memset(&
f, 0,
sizeof(
f));
1122 memset(&
ssn, 0,
sizeof(
ssn));
1184 static int LuaMatchTest02a(
void)
1186 const char script[] =
"local flowvarlib = require(\"suricata.flowvar\")\n"
1187 "function init (args)\n"
1188 " flowvarlib.register(\"cnt\")"
1189 " local needs = {}\n"
1190 " needs[\"payload\"] = tostring(true)\n"
1193 "function thread_init (args)\n"
1194 " cnt = flowvarlib.get(\"cnt\")"
1197 "function match(args)\n"
1198 " a = cnt:value()\n"
1200 " a = tostring(tonumber(a)+1)\n"
1204 " a = tostring(1)\n"
1209 " print (\"pre check: \" .. (a))\n"
1210 " if tonumber(a) == 2 then\n"
1211 " print \"match\"\n"
1217 char sig[] =
"alert tcp any any -> any any (flow:to_server; lua:unittest; sid:1;)";
1218 uint8_t httpbuf1[] =
"POST / HTTP/1.1\r\n"
1219 "Host: www.emergingthreats.net\r\n\r\n";
1220 uint8_t httpbuf2[] =
"POST / HTTP/1.1\r\n"
1221 "Host: www.openinfosecfoundation.org\r\n\r\n";
1222 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1223 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1233 memset(&
f, 0,
sizeof(
f));
1234 memset(&
ssn, 0,
sizeof(
ssn));
1294 static int LuaMatchTest03(
void)
1296 const char script[] =
"local flowvarlib = require(\"suricata.flowvar\")\n"
1297 "function init (args)\n"
1298 " flowvarlib.register(\"cnt\")\n"
1299 " local needs = {}\n"
1300 " needs[\"packet\"] = tostring(true)\n"
1304 "function thread_init (args)\n"
1305 " cnt = flowvarlib.get(\"cnt\")\n"
1308 "function match(args)\n"
1309 " a = cnt:value()\n"
1311 " a = tostring(tonumber(a)+1)\n"
1315 " a = tostring(1)\n"
1320 " print (\"pre check: \" .. (a))\n"
1321 " if tonumber(a) == 2 then\n"
1322 " print \"match\"\n"
1328 char sig[] =
"alert tcp any any -> any any (flow:to_server; lua:unittest; sid:1;)";
1329 uint8_t httpbuf1[] =
"POST / HTTP/1.1\r\n"
1330 "Host: www.emergingthreats.net\r\n\r\n";
1331 uint8_t httpbuf2[] =
"POST / HTTP/1.1\r\n"
1332 "Host: www.openinfosecfoundation.org\r\n\r\n";
1333 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1334 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1344 memset(&
f, 0,
sizeof(
f));
1345 memset(&
ssn, 0,
sizeof(
ssn));
1404 static int LuaMatchTest03a(
void)
1406 const char script[] =
"local flowvarlib = require(\"suricata.flowvar\")\n"
1407 "function init (args)\n"
1408 " flowvarlib.register(\"cnt\")\n"
1409 " local needs = {}\n"
1410 " needs[\"packet\"] = tostring(true)\n"
1414 "function thread_init (args)\n"
1415 " cnt = flowvarlib.get(\"cnt\")\n"
1418 "function match(args)\n"
1419 " a = cnt:value()\n"
1421 " a = tostring(tonumber(a)+1)\n"
1425 " a = tostring(1)\n"
1430 " print (\"pre check: \" .. (a))\n"
1431 " if tonumber(a) == 2 then\n"
1432 " print \"match\"\n"
1438 char sig[] =
"alert tcp any any -> any any (flow:to_server; lua:unittest; sid:1;)";
1439 uint8_t httpbuf1[] =
"POST / HTTP/1.1\r\n"
1440 "Host: www.emergingthreats.net\r\n\r\n";
1441 uint8_t httpbuf2[] =
"POST / HTTP/1.1\r\n"
1442 "Host: www.openinfosecfoundation.org\r\n\r\n";
1443 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1444 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1454 memset(&
f, 0,
sizeof(
f));
1455 memset(&
ssn, 0,
sizeof(
ssn));
1514 static int LuaMatchTest04(
void)
1516 const char script[] =
"local flowintlib = require(\"suricata.flowint\")\n"
1517 "function init (args)\n"
1518 " flowintlib.register(\"cnt\")\n"
1522 "function thread_init (args)\n"
1523 " cnt = flowintlib.get(\"cnt\")\n"
1526 "function match(args)\n"
1527 " print \"inspecting\""
1528 " a = cnt:value()\n"
1535 " a = cnt:value()\n"
1537 " print \"match\"\n"
1543 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
1545 uint8_t httpbuf1[] =
"POST / HTTP/1.1\r\n"
1546 "Host: www.emergingthreats.net\r\n\r\n";
1547 uint8_t httpbuf2[] =
"POST / HTTP/1.1\r\n"
1548 "Host: www.openinfosecfoundation.org\r\n\r\n";
1549 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1550 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1562 memset(&
f, 0,
sizeof(
f));
1563 memset(&
ssn, 0,
sizeof(
ssn));
1632 static int LuaMatchTest04a(
void)
1634 const char script[] =
"local flowintlib = require(\"suricata.flowint\")\n"
1635 "function init (args)\n"
1636 " flowintlib.register(\"cnt\")\n"
1640 "function thread_init (args)\n"
1641 " cnt = flowintlib.get(\"cnt\")\n"
1644 "function match(args)\n"
1645 " print \"inspecting\""
1646 " a = cnt:value()\n"
1653 " a = cnt:value()\n"
1655 " print \"match\"\n"
1661 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
1663 uint8_t httpbuf1[] =
1664 "POST / HTTP/1.1\r\n"
1665 "Host: www.emergingthreats.net\r\n\r\n";
1666 uint8_t httpbuf2[] =
1667 "POST / HTTP/1.1\r\n"
1668 "Host: www.openinfosecfoundation.org\r\n\r\n";
1669 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1670 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1682 memset(&
f, 0,
sizeof(
f));
1683 memset(&
ssn, 0,
sizeof(
ssn));
1752 static int LuaMatchTest05(
void)
1754 const char script[] =
"local flowintlib = require(\"suricata.flowint\")\n"
1755 "function init (args)\n"
1756 " flowintlib.register(\"cnt\")\n"
1760 "function thread_init (args)\n"
1761 " cnt = flowintlib.get(\"cnt\")\n"
1764 "function match(args)\n"
1765 " print \"inspecting\""
1768 " print \"match\"\n"
1774 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
1776 uint8_t httpbuf1[] =
1777 "POST / HTTP/1.1\r\n"
1778 "Host: www.emergingthreats.net\r\n\r\n";
1779 uint8_t httpbuf2[] =
1780 "POST / HTTP/1.1\r\n"
1781 "Host: www.openinfosecfoundation.org\r\n\r\n";
1782 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1783 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1795 memset(&
f, 0,
sizeof(
f));
1796 memset(&
ssn, 0,
sizeof(
ssn));
1865 static int LuaMatchTest05a(
void)
1867 const char script[] =
"local flowintlib = require(\"suricata.flowint\")\n"
1868 "function init (args)\n"
1869 " flowintlib.register(\"cnt\")\n"
1873 "function thread_init (args)\n"
1874 " cnt = flowintlib.get(\"cnt\")\n"
1877 "function match(args)\n"
1878 " print \"inspecting\""
1881 " print \"match\"\n"
1887 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
1889 uint8_t httpbuf1[] =
1890 "POST / HTTP/1.1\r\n"
1891 "Host: www.emergingthreats.net\r\n\r\n";
1892 uint8_t httpbuf2[] =
1893 "POST / HTTP/1.1\r\n"
1894 "Host: www.openinfosecfoundation.org\r\n\r\n";
1895 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
1896 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
1908 memset(&
f, 0,
sizeof(
f));
1909 memset(&
ssn, 0,
sizeof(
ssn));
1980 static int LuaMatchTest06(
void)
1982 const char script[] =
"local flowintlib = require(\"suricata.flowint\")\n"
1983 "function init (args)\n"
1984 " flowintlib.register(\"cnt\")\n"
1988 "function thread_init (args)\n"
1989 " cnt = flowintlib.get(\"cnt\")\n"
1992 "function match(args)\n"
1993 " print \"inspecting\""
1994 " a = cnt:value()\n"
1995 " if a == nil then\n"
1996 " print \"new var set to 2\""
2001 " print \"match\"\n"
2007 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
2009 uint8_t httpbuf1[] =
2010 "POST / HTTP/1.1\r\n"
2011 "Host: www.emergingthreats.net\r\n\r\n";
2012 uint8_t httpbuf2[] =
2013 "POST / HTTP/1.1\r\n"
2014 "Host: www.openinfosecfoundation.org\r\n\r\n";
2015 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
2016 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
2028 memset(&
f, 0,
sizeof(
f));
2029 memset(&
ssn, 0,
sizeof(
ssn));
2098 static int LuaMatchTest06a(
void)
2100 const char script[] =
"local flowintlib = require(\"suricata.flowint\")\n"
2101 "function init (args)\n"
2102 " flowintlib.register(\"cnt\")\n"
2106 "function thread_init (args)\n"
2107 " cnt = flowintlib.get(\"cnt\")\n"
2110 "function match(args)\n"
2111 " print \"inspecting\""
2112 " a = cnt:value()\n"
2113 " if a == nil then\n"
2114 " print \"new var set to 2\""
2119 " print \"match\"\n"
2125 char sig[] =
"alert http1:request_complete any any -> any any (flow:to_server; lua:unittest; "
2127 uint8_t httpbuf1[] =
2128 "POST / HTTP/1.1\r\n"
2129 "Host: www.emergingthreats.net\r\n\r\n";
2130 uint8_t httpbuf2[] =
2131 "POST / HTTP/1.1\r\n"
2132 "Host: www.openinfosecfoundation.org\r\n\r\n";
2133 uint32_t httplen1 =
sizeof(httpbuf1) - 1;
2134 uint32_t httplen2 =
sizeof(httpbuf2) - 1;
2146 memset(&
f, 0,
sizeof(
f));
2147 memset(&
ssn, 0,
sizeof(
ssn));
2215 void DetectLuaRegisterTests(
void)
#define FLAG_MEMORY_LIMIT_LOGGED
void LuaStateSetThreadVars(lua_State *luastate, ThreadVars *tv)
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
SigTableElmt * sigmatch_table
void SCLuaSbUpdateBytesLimit(lua_State *L)
void(* Free)(DetectEngineCtx *, void *)
#define FLAG_BLOCKED_FUNCTION_LOGGED
uint64_t SCLuaSbResetBytesLimit(lua_State *L)
void * DetectThreadCtxGetKeywordThreadCtx(DetectEngineThreadCtx *det_ctx, int id)
Retrieve thread local keyword ctx by id.
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
SCLuaSbState * SCLuaSbGetContext(lua_State *L)
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
#define FLAG_INSTRUCTION_LIMIT_LOGGED
main detection engine ctx
#define DEFAULT_LUA_INSTRUCTION_LIMIT
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
int(* AppLayerTxMatch)(DetectEngineThreadCtx *, Flow *, uint8_t flags, void *alstate, void *txv, const Signature *, const SigMatchCtx *)
#define DETECT_LUA_MAX_FLOWVARS
void AppLayerParserThreadCtxFree(AppLayerParserThreadCtx *tctx)
Destroys the app layer parser thread context obtained using AppLayerParserThreadCtxAlloc().
#define FLOW_PKT_TOSERVER
int SCConfGetBool(const char *name, int *val)
Retrieve a configuration value as a boolean.
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
uint32_t flowvar[DETECT_LUA_MAX_FLOWVARS]
uint32_t VarNameStoreRegister(const char *name, const enum VarTypes type)
StatsCounterId lua_instruction_limit_errors
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
#define SIG_FLAG_TOCLIENT
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
#define FLAG_DATATYPE_PACKET
void DetectAppLayerInspectEngineRegister(const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
Registers an app inspection engine.
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
struct lua_State lua_State
void StreamTcpInitConfig(bool)
To initialize the stream global configuration data.
#define FLOW_INITIALIZE(f)
#define SIG_FLAG_TOSERVER
uint32_t VarNameStoreLookupByName(const char *name, const enum VarTypes type)
find name for id+type at packet time. As the active store won't be modified, we don't need locks.
#define PASS
Pass the test.
void SCLuaSbRestoreBytesLimit(lua_State *L, const uint64_t cfg_limit)
StatsCounterId lua_memory_limit_errors
uint64_t instruction_limit
int SCConfGetInt(const char *name, intmax_t *val)
Retrieve a configuration value as an integer.
AppLayerParserThreadCtx * alp_tctx
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Per thread variable structure.
void DetectLuaRegister(void)
Registration function for keyword: lua.
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
void VarNameStoreUnregister(const uint32_t id, const enum VarTypes type)
void StatsCounterIncr(StatsThreadContext *stats, StatsCounterId id)
Increments the local counter.
#define DETECT_LUA_MAX_FLOWINTS
#define FLAG_DATATYPE_PAYLOAD
#define SCLogWarning(...)
Macro used to log WARNING messages.
int DetectLuaMatchBuffer(DetectEngineThreadCtx *det_ctx, const Signature *s, const SigMatchData *smd, const uint8_t *buffer, uint32_t buffer_len, uint32_t offset, Flow *f)
@ SIGNATURE_HOOK_TYPE_NOT_SET
StatsCounterId lua_rule_errors
DetectLuaDataBytevarEntry bytevar[DETECT_LUA_MAX_BYTEVARS]
void SCLuaSbStateClose(lua_State *L)
uint32_t flowint[DETECT_LUA_MAX_FLOWINTS]
#define FLAG_ERROR_LOGGED
SignatureInitData * init_data
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
void SCLuaRequirefBuiltIns(lua_State *L)
Register Suricata built-in modules for loading in a non-sandboxed environment.
bool blocked_function_error
#define FLOW_PKT_TOCLIENT
void LuaExtensionsMatchSetup(lua_State *lua_state, DetectLuaData *ld, DetectEngineThreadCtx *det_ctx, Flow *f, Packet *p, const Signature *s, uint8_t flags)
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
void LuaDumpStack(lua_State *state, const char *prefix)
dump stack from lua state to screen
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
int SCConfSetFinal(const char *name, const char *val)
Set a final configuration value.
void StatsThreadInit(StatsThreadContext *stats)
AppLayerParserThreadCtx * AppLayerParserThreadCtxAlloc(void)
Gets a new app layer protocol's parser thread context.
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
void SCLuaSbLoadLibs(lua_State *L)
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
int DetectBufferTypeRegister(const char *name)
void StreamTcpFreeConfig(bool quiet)
int DetectRegisterThreadCtxFuncs(DetectEngineCtx *de_ctx, const char *name, void *(*InitFunc)(void *), void *data, void(*FreeFunc)(void *), int mode)
Register Thread keyword context Funcs.
int AppLayerParserParse(ThreadVars *tv, AppLayerParserThreadCtx *alp_tctx, Flow *f, AppProto alproto, uint8_t flags, const uint8_t *input, uint32_t input_len)
union FlowVar_::@121 data
#define DEFAULT_LUA_ALLOC_LIMIT
enum SignatureHookType type
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
void SCLuaSbResetInstructionCounter(lua_State *L)
uint8_t DetectEngineInspectGenericList(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
const char luaext_key_ld[]
#define SCLogError(...)
Macro used to log ERROR messages.
#define FLOW_PKT_ESTABLISHED
DetectEngineCtx * DetectEngineCtxInit(void)
bool instruction_count_error
char * DetectLoadCompleteSigPath(const DetectEngineCtx *de_ctx, const char *sig_file)
Create the path if default-rule-path was specified.
lua_State * SCLuaSbStateNew(uint64_t alloclimit, uint64_t instructionlimit)
Allocate a new Lua sandbox.
FlowVar * FlowVarGet(Flow *f, uint32_t idx)
get the flowvar with index 'idx' from the flow
int DetectUnregisterThreadCtxFuncs(DetectEngineCtx *de_ctx, void *data, const char *name)
Remove Thread keyword context registration.
AppProto alproto
application level protocol
int DetectBufferGetActiveList(DetectEngineCtx *de_ctx, Signature *s)
void StatsThreadCleanup(StatsThreadContext *stats)
StatsCounterId lua_blocked_function_errors
void(* RegisterTests)(void)
int LuaPushStringBuffer(lua_State *luastate, const uint8_t *input, size_t input_len)
void UTHFreePackets(Packet **p, int numpkts)
UTHFreePackets: function to release the allocated data from UTHBuildPacket and the packet itself.