|
suricata
|
#include "suricata-common.h"#include "detect.h"#include "detect-engine.h"#include "detect-engine-address.h"#include "detect-engine-port.h"#include "detect-engine-mpm.h"#include "detect-engine-state.h"#include "detect-engine-build.h"#include "detect-content.h"#include "detect-bsize.h"#include "detect-isdataat.h"#include "detect-pcre.h"#include "detect-uricontent.h"#include "detect-reference.h"#include "detect-ipproto.h"#include "detect-flow.h"#include "detect-app-layer-protocol.h"#include "detect-lua.h"#include "detect-app-layer-event.h"#include "detect-http-method.h"#include "pkt-var.h"#include "host.h"#include "util-profiling.h"#include "decode.h"#include "flow.h"#include "util-rule-vars.h"#include "conf.h"#include "conf-yaml-loader.h"#include "app-layer.h"#include "app-layer-protos.h"#include "app-layer-parser.h"#include "app-layer-htp.h"#include "util-classification-config.h"#include "util-unittest.h"#include "util-unittest-helper.h"#include "util-debug.h"#include "string.h"#include "detect-parse.h"#include "detect-engine-iponly.h"#include "detect-engine-file.h"#include "app-layer-detect-proto.h"#include "action-globals.h"#include "util-validate.h"#include "detect-engine-alert.h"#include "packet.h"#include "tests/detect-parse.c"
Go to the source code of this file.
Data Structures | |
| struct | SigDuplWrapper_ |
| Registration table for file handlers. More... | |
| struct | SignatureParser_ |
| struct | FirewallPolicyChain |
| Ordered, most-specific-first list of config paths a single policy can be configured at. More... | |
Macros | |
| #define | FW_POLICY_YAML_PATH_MAX 320 |
| max length of a firewall.policies YAML config path More... | |
| #define | FW_POLICY_YAML_PATH_NAME_MAX 64 |
| max length of a single YAML path leaf segment (a hook or sub state name) More... | |
| #define | FW_POLICY_CHAIN_MAX 6 |
| max number of config paths consulted to resolve one policy More... | |
| #define | CASE_CODE_STRING(E, S) case E: return S; break |
| #define | CASE_CODE(E) case E: return #E |
| #define | URL "https://suricata.io/our-story/deprecation-policy/" |
Typedefs | |
| typedef struct SigDuplWrapper_ | SigDuplWrapper |
| Registration table for file handlers. More... | |
| typedef struct SignatureParser_ | SignatureParser |
| typedef struct FirewallPolicyChain | FirewallPolicyChain |
| Ordered, most-specific-first list of config paths a single policy can be configured at. More... | |
Enumerations | |
| enum | DetectFirewallPolicyClass { DETECT_FIREWALL_POLICY_CLASS_PACKET, DETECT_FIREWALL_POLICY_CLASS_APP } |
Functions | |
| const char * | DetectListToHumanString (int list) |
| const char * | DetectListToString (int list) |
| int | DetectEngineContentModifierBufferSetup (DetectEngineCtx *de_ctx, Signature *s, const char *arg, int sm_type, int sm_list, AppProto alproto) |
| SigMatch * | SigMatchAlloc (void) |
| void | SigMatchFree (DetectEngineCtx *de_ctx, SigMatch *sm) |
| free a SigMatch More... | |
| bool | SCSigMatchSilentErrorEnabled (const DetectEngineCtx *de_ctx, uint16_t id) |
| bool | SigMatchStrictEnabled (const enum DetectKeywordId id) |
| void | SigTableApplyStrictCommandLineOption (const char *str) |
| SigMatch * | SCSigMatchAppendSMToList (DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list) |
| Append a SigMatch to the list type. More... | |
| void | SigMatchRemoveSMFromList (Signature *s, SigMatch *sm, int sm_list) |
| SigMatch * | DetectGetLastSMFromMpmLists (const DetectEngineCtx *de_ctx, const Signature *s) |
| get the last SigMatch from lists that support MPM. More... | |
| SigMatch * | SCDetectGetLastSMFromLists (const Signature *s,...) |
| Returns the sm with the largest index (added latest) from the lists passed to us. More... | |
| SigMatch * | DetectGetLastSMByListPtr (const Signature *s, SigMatch *sm_list,...) |
| Returns the sm with the largest index (added last) from the list passed to us as a pointer. More... | |
| SigMatch * | DetectGetLastSMByListId (const Signature *s, int list_id,...) |
| Returns the sm with the largest index (added last) from the list passed to us as an id. More... | |
| SigMatch * | DetectGetLastSM (const Signature *s) |
| Returns the sm with the largest index (added latest) from this sig. More... | |
| int | SigMatchListSMBelongsTo (const Signature *s, const SigMatch *key_sm) |
| const char * | DetectFirewallAppGenericHookName (const uint8_t state, const uint8_t complete_state, const int direction) |
| Generic start/complete hook alias for an app progress state, in config form (hyphens), or NULL for intermediate states. More... | |
| void | DetectRegisterAppLayerHookLists (void) |
| register app hooks as generic lists More... | |
| void | DetectListSupportedProtocols (void) |
| int | SignatureInitDataBufferCheckExpand (Signature *s) |
| check if buffers array still has space left, expand if not More... | |
| Signature * | SigAlloc (void) |
| void | SigFree (DetectEngineCtx *de_ctx, Signature *s) |
| int | DetectSignatureSetMultiAppProto (Signature *s, const AppProto *alprotos) |
| this function is used to set multiple possible app-layer protos More... | |
| int | SCDetectSignatureSetAppProto (Signature *s, AppProto alproto) |
| SigMatchData * | SigMatchList2DataArray (SigMatch *head) |
| convert SigMatch list to SigMatchData array More... | |
| Signature * | SigInit (DetectEngineCtx *de_ctx, const char *sigstr) |
| Parses a signature and adds it to the Detection Engine Context. More... | |
| int | DetectParseDupSigHashInit (DetectEngineCtx *de_ctx) |
| Initializes the hash table that is used to cull duplicate sigs. More... | |
| void | DetectParseDupSigHashFree (DetectEngineCtx *de_ctx) |
| Frees the hash table that is used to cull duplicate sigs. More... | |
| Signature * | DetectFirewallRuleAppendNew (DetectEngineCtx *de_ctx, const char *sigstr) |
| Parse and append a Signature into the Detection Engine Context signature list. More... | |
| Signature * | DetectEngineAppendSig (DetectEngineCtx *de_ctx, const char *sigstr) |
| Parse and append a Signature into the Detection Engine Context signature list. More... | |
| int | DetectParsePcreExec (DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options) |
| void | DetectParseFreeRegex (DetectParseRegex *r) |
| void | DetectParseFreeRegexes (void) |
| void | DetectParseRegexAddToFreeList (DetectParseRegex *detect_parse) |
| add regex and/or study to at exit free list More... | |
| bool | DetectSetupParseRegexesOpts (const char *parse_str, DetectParseRegex *detect_parse, int opts) |
| DetectParseRegex * | DetectSetupPCRE2 (const char *parse_str, int opts) |
| int | SC_Pcre2SubstringCopy (pcre2_match_data *match_data, uint32_t number, PCRE2_UCHAR *buffer, PCRE2_SIZE *bufflen) |
| int | SC_Pcre2SubstringGet (pcre2_match_data *match_data, uint32_t number, PCRE2_UCHAR **bufferptr, PCRE2_SIZE *bufflen) |
| void | DetectSetupParseRegexes (const char *parse_str, DetectParseRegex *detect_parse) |
| const char * | ActionScopeToString (enum ActionScope s) |
| void | DetectFirewallPolicyToString (const struct DetectFirewallPolicy *p, char *out, size_t out_size) |
| int | DetectFirewallInitDefaultPolicies (DetectEngineCtx *de_ctx) |
| allocate and initialize to default values the policies table More... | |
| int | DetectFirewallLoadDefaultPolicies (DetectEngineCtx *de_ctx) |
| void | DetectParseRegisterTests (void) |
| this function registers unit tests for DetectParse More... | |
| void | SigParseRegisterTests (void) |
Variables | |
| SigTableElmt * | sigmatch_table = NULL |
| bool | sc_set_caps |
| int | g_skip_prefilter |
signature parser
Definition in file detect-parse.c.
| #define CASE_CODE | ( | E | ) | case E: return #E |
Definition at line 163 of file detect-parse.c.
| #define CASE_CODE_STRING | ( | E, | |
| S | |||
| ) | case E: return S; break |
| #define FW_POLICY_CHAIN_MAX 6 |
max number of config paths consulted to resolve one policy
Definition at line 135 of file detect-parse.c.
| #define FW_POLICY_YAML_PATH_MAX 320 |
max length of a firewall.policies YAML config path
Definition at line 131 of file detect-parse.c.
| #define FW_POLICY_YAML_PATH_NAME_MAX 64 |
max length of a single YAML path leaf segment (a hook or sub state name)
Definition at line 133 of file detect-parse.c.
| #define URL "https://suricata.io/our-story/deprecation-policy/" |
| typedef struct FirewallPolicyChain FirewallPolicyChain |
Ordered, most-specific-first list of config paths a single policy can be configured at.
| typedef struct SigDuplWrapper_ SigDuplWrapper |
Registration table for file handlers.
We use this as data to the hash table DetectEngineCtx->dup_sig_hash_table.
| typedef struct SignatureParser_ SignatureParser |
helper structure for sig parsing
Valid action scopes per firewall hook class.
| Enumerator | |
|---|---|
| DETECT_FIREWALL_POLICY_CLASS_PACKET | |
| DETECT_FIREWALL_POLICY_CLASS_APP | |
Definition at line 113 of file detect-parse.c.
| const char* ActionScopeToString | ( | enum ActionScope | s | ) |
Definition at line 4067 of file detect-parse.c.
References ACTION_SCOPE_AUTO, ACTION_SCOPE_FLOW, ACTION_SCOPE_HOOK, ACTION_SCOPE_PACKET, ACTION_SCOPE_TX, and DEBUG_VALIDATE_BUG_ON.
Referenced by DetectFirewallPolicyToString().

| Signature* DetectEngineAppendSig | ( | DetectEngineCtx * | de_ctx, |
| const char * | sigstr | ||
| ) |
Parse and append a Signature into the Detection Engine Context signature list.
If the signature is bidirectional it should append two signatures (with the addresses switched) into the list. Also handle duplicate signatures. In case of duplicate sigs, use the ones that have the latest revision. We use the sid and the msg to identify duplicate sigs. If 2 sigs have the same sid and gid, they are duplicates.
| de_ctx | Pointer to the Detection Engine Context. |
| sigstr | Pointer to a character string containing the signature to be parsed. |
| sig_file | Pointer to a character string containing the filename from which signature is read |
| lineno | Line number from where signature is read |
| Pointer | to the head Signature in the detection engine ctx sig_list on success; NULL on failure. |
In DetectEngineAppendSig(), the signatures are prepended and we always return the first one so if the signature is bidirectional, the returned sig will point through "next" ptr to the cloned signatures with the switched addresses
Definition at line 3847 of file detect-parse.c.
References de_ctx, and SigInit().
Referenced by UTHAppendSigs(), UTHPacketMatchSig(), UTHPacketMatchSigMpm(), and UTHParseSignature().


| int DetectEngineContentModifierBufferSetup | ( | DetectEngineCtx * | de_ctx, |
| Signature * | s, | ||
| const char * | arg, | ||
| int | sm_type, | ||
| int | sm_list, | ||
| AppProto | alproto | ||
| ) |
| arg | NULL or empty string |
Definition at line 179 of file detect-parse.c.
References Signature_::alproto, ALPROTO_UNKNOWN, DETECT_SM_LIST_NOTSET, Signature_::init_data, SignatureInitData_::list, name, SCLogError, and sigmatch_table.
Referenced by DetectHttpUriSetup().

| const char* DetectFirewallAppGenericHookName | ( | const uint8_t | state, |
| const uint8_t | complete_state, | ||
| const int | direction | ||
| ) |
Generic start/complete hook alias for an app progress state, in config form (hyphens), or NULL for intermediate states.
Definition at line 1185 of file detect-parse.c.
| int DetectFirewallInitDefaultPolicies | ( | DetectEngineCtx * | de_ctx | ) |
allocate and initialize to default values the policies table
Definition at line 4423 of file detect-parse.c.
References DetectFirewallPolicies::app_policies, HashTableInit(), and SCCalloc.

| int DetectFirewallLoadDefaultPolicies | ( | DetectEngineCtx * | de_ctx | ) |
Definition at line 4492 of file detect-parse.c.
References DetectEngineCtx_::config_prefix, de_ctx, and DetectEngineCtx_::fw_policies.
| void DetectFirewallPolicyToString | ( | const struct DetectFirewallPolicy * | p, |
| char * | out, | ||
| size_t | out_size | ||
| ) |
Definition at line 4085 of file detect-parse.c.
References Packet_::action, ACTION_ACCEPT, ACTION_ALERT, ACTION_DROP, ACTION_PASS, ACTION_REJECT_ANY, ACTION_REJECT_BOTH, ACTION_REJECT_DST, ACTION_SCOPE_FLOW, ActionScopeToString(), DEBUG_VALIDATE_BUG_ON, p, and strlcat().

| Signature* DetectFirewallRuleAppendNew | ( | DetectEngineCtx * | de_ctx, |
| const char * | sigstr | ||
| ) |
Parse and append a Signature into the Detection Engine Context signature list.
If the signature is bidirectional it should append two signatures (with the addresses switched) into the list. Also handle duplicate signatures. In case of duplicate sigs, use the ones that have the latest revision. We use the sid and the msg to identify duplicate sigs. If 2 sigs have the same sid and gid, they are duplicates.
| de_ctx | Pointer to the Detection Engine Context. |
| sigstr | Pointer to a character string containing the signature to be parsed. |
| sig_file | Pointer to a character string containing the filename from which signature is read |
| lineno | Line number from where signature is read |
| Pointer | to the head Signature in the detection engine ctx sig_list on success; NULL on failure. |
In DetectEngineAppendSig(), the signatures are prepended and we always return the first one so if the signature is bidirectional, the returned sig will point through "next" ptr to the cloned signatures with the switched addresses
Definition at line 3775 of file detect-parse.c.
Returns the sm with the largest index (added latest) from this sig.
| sm_last | Pointer to last sm |
Definition at line 741 of file detect-parse.c.
References SignatureInitData_::buffer_index, SignatureInitData_::buffers, DETECT_SM_LIST_MAX, SigMatch_::idx, Signature_::init_data, SignatureInitData_::smlists_tail, and SignatureInitDataBuffer_::tail.
Returns the sm with the largest index (added last) from the list passed to us as an id.
| list_id | id of the list to be searched |
| va_args | list of keyword types terminated by -1 |
| sm_last | to last sm. |
Definition at line 690 of file detect-parse.c.
References SignatureInitData_::buffer_index, SignatureInitData_::buffers, DETECT_SM_LIST_MAX, Signature_::init_data, and SignatureInitDataBuffer_::tail.
Returns the sm with the largest index (added last) from the list passed to us as a pointer.
| sm_list | pointer to the SigMatch we should look before |
| va_args | list of keyword types terminated by -1 |
| sm_last | to last sm. |
Definition at line 658 of file detect-parse.c.
Referenced by DetectGetLastSMFromMpmLists().

| SigMatch* DetectGetLastSMFromMpmLists | ( | const DetectEngineCtx * | de_ctx, |
| const Signature * | s | ||
| ) |
get the last SigMatch from lists that support MPM.
Definition at line 559 of file detect-parse.c.
References SignatureInitData_::buffer_index, SignatureInitData_::buffers, de_ctx, DETECT_CONTENT, DETECT_SM_LIST_MAX, DetectEngineBufferTypeSupportsMpmGetById(), DetectGetLastSMByListPtr(), SignatureInitDataBuffer_::id, SigMatch_::idx, Signature_::init_data, SignatureInitData_::smlists_tail, and SignatureInitDataBuffer_::tail.

| void DetectListSupportedProtocols | ( | void | ) |
Definition at line 1581 of file detect-parse.c.
References AppProtoDetectListNames(), and DetectEngineProtoList().
Referenced by ListRuleProtocols().


| const char* DetectListToHumanString | ( | int | list | ) |
Definition at line 145 of file detect-parse.c.
Referenced by DumpPatterns().

| const char* DetectListToString | ( | int | list | ) |
Definition at line 163 of file detect-parse.c.
| void DetectParseDupSigHashFree | ( | DetectEngineCtx * | de_ctx | ) |
Frees the hash table that is used to cull duplicate sigs.
| de_ctx | Pointer to the detection engine context that holds this table. |
Definition at line 3592 of file detect-parse.c.
References de_ctx, DetectEngineCtx_::dup_sig_hash_table, and HashListTableFree().
Referenced by DetectEngineCtxFree().


| int DetectParseDupSigHashInit | ( | DetectEngineCtx * | de_ctx | ) |
Initializes the hash table that is used to cull duplicate sigs.
| de_ctx | Pointer to the detection engine context. |
| 0 | On success. |
| -1 | On failure. |
Definition at line 3575 of file detect-parse.c.
References de_ctx, DetectEngineCtx_::dup_sig_hash_table, and HashListTableInit().

| void DetectParseFreeRegex | ( | DetectParseRegex * | r | ) |
Definition at line 3911 of file detect-parse.c.
References DetectParseRegex::context, and DetectParseRegex::regex.
| void DetectParseFreeRegexes | ( | void | ) |
Definition at line 3921 of file detect-parse.c.
Referenced by GlobalsDestroy().

| int DetectParsePcreExec | ( | DetectParseRegex * | parse_regex, |
| pcre2_match_data ** | match, | ||
| const char * | str, | ||
| int | start_offset, | ||
| int | options | ||
| ) |
Definition at line 3901 of file detect-parse.c.
| void DetectParseRegexAddToFreeList | ( | DetectParseRegex * | detect_parse | ) |
add regex and/or study to at exit free list
Definition at line 3937 of file detect-parse.c.
References FatalError, DetectParseRegex::next, DetectParseRegex::regex, and SCCalloc.
Referenced by DetectSetupParseRegexesOpts().

| void DetectParseRegisterTests | ( | void | ) |
this function registers unit tests for DetectParse
Definition at line 146 of file detect-parse.c.
References UtRegisterTest().
Referenced by SigParseRegisterTests().


| void DetectRegisterAppLayerHookLists | ( | void | ) |
register app hooks as generic lists
Register each hook in each app protocol as: <alproto>:<hook name>:generic These lists can be used by lua scripts to hook into.
Definition at line 1203 of file detect-parse.c.
References ALPROTO_FAILED, AppLayerParserGetMaxSubState(), AppLayerParserGetSubStateCompletion(), AppLayerParserGetSubStateName(), AppLayerParserGetSubStateProgressName(), AppLayerParserSupportsSubStates(), AppProtoToStringRaw(), BUG_ON, DetectAppLayerInspectEngineRegisterSubState(), DetectEngineInspectGenericList(), g_alproto_max, SCLogDebug, SIG_FLAG_TOCLIENT, and SIG_FLAG_TOSERVER.
Referenced by SigTableSetup().


| void DetectSetupParseRegexes | ( | const char * | parse_str, |
| DetectParseRegex * | detect_parse | ||
| ) |
Definition at line 4027 of file detect-parse.c.
References DetectSetupParseRegexesOpts(), and FatalError.

| bool DetectSetupParseRegexesOpts | ( | const char * | parse_str, |
| DetectParseRegex * | detect_parse, | ||
| int | opts | ||
| ) |
Definition at line 3948 of file detect-parse.c.
References DetectParseRegex::context, DetectParseRegexAddToFreeList(), DetectParseRegex::regex, SC_MATCH_LIMIT_DEFAULT, SC_MATCH_LIMIT_RECURSION_DEFAULT, and SCLogError.
Referenced by DetectSetupParseRegexes().


| DetectParseRegex* DetectSetupPCRE2 | ( | const char * | parse_str, |
| int | opts | ||
| ) |
Definition at line 3977 of file detect-parse.c.
References DetectParseRegex::next, DetectParseRegex::regex, SCCalloc, SCFree, and SCLogError.
this function is used to set multiple possible app-layer protos
into the current signature (for example ja4 for both tls and quic)
| s | pointer to the Current Signature |
| alprotos | an array terminated by ALPROTO_UNKNOWN |
| 0 | on Success |
| -1 | on Failure |
Definition at line 2428 of file detect-parse.c.
References Signature_::alproto, ALPROTO_UNKNOWN, SignatureInitData_::alprotos, Signature_::init_data, SCDetectSignatureSetAppProto(), and SIG_ALPROTO_MAX.

| int SC_Pcre2SubstringCopy | ( | pcre2_match_data * | match_data, |
| uint32_t | number, | ||
| PCRE2_UCHAR * | buffer, | ||
| PCRE2_SIZE * | bufflen | ||
| ) |
Definition at line 4003 of file detect-parse.c.
| int SC_Pcre2SubstringGet | ( | pcre2_match_data * | match_data, |
| uint32_t | number, | ||
| PCRE2_UCHAR ** | bufferptr, | ||
| PCRE2_SIZE * | bufflen | ||
| ) |
Definition at line 4015 of file detect-parse.c.
Returns the sm with the largest index (added latest) from the lists passed to us.
| Pointer | to Last sm. |
Definition at line 596 of file detect-parse.c.
References SignatureInitData_::buffer_index, SignatureInitData_::buffers, DETECT_SM_LIST_NOTSET, SignatureInitDataBuffer_::id, Signature_::init_data, SignatureInitData_::list, and SCLogDebug.
Definition at line 2506 of file detect-parse.c.
Referenced by DetectSignatureSetMultiAppProto().

| SigMatch* SCSigMatchAppendSMToList | ( | DetectEngineCtx * | de_ctx, |
| Signature * | s, | ||
| uint16_t | type, | ||
| SigMatchCtx * | ctx, | ||
| const int | list | ||
| ) |
Append a SigMatch to the list type.
| s | Signature. |
| new | The sig match to append. |
| list | The list to append to. |
Definition at line 420 of file detect-parse.c.
Referenced by DetectContentSetup(), and DetectFlowvarPostMatchSetup().

| bool SCSigMatchSilentErrorEnabled | ( | const DetectEngineCtx * | de_ctx, |
| uint16_t | id | ||
| ) |
Definition at line 363 of file detect-parse.c.
References de_ctx, and DetectEngineCtx_::sm_types_silent_error.
| Signature* SigAlloc | ( | void | ) |
Definition at line 2211 of file detect-parse.c.
References SignatureInitData_::buffers, SignatureInitData_::buffers_size, DETECT_SM_LIST_NOTSET, Signature_::init_data, SignatureInitData_::is_rule_state_dependant, SignatureInitData_::list, SignatureInitData_::mpm_sm_list, Signature_::prio, SignatureInitData_::rule_state_dependant_sids_idx, SCCalloc, SCFree, and unlikely.
| void SigFree | ( | DetectEngineCtx * | de_ctx, |
| Signature * | s | ||
| ) |
Definition at line 2331 of file detect-parse.c.
References SignatureInitData_::buffer_index, SignatureInitData_::buffers, SignatureInitData_::cidr_dst, SignatureInitData_::cidr_src, DetectEngineTransforms::cnt, de_ctx, DETECT_SM_LIST_MAX, SigTableElmt_::Free, SignatureInitDataBuffer_::head, Signature_::init_data, IPOnlyCIDRListFree(), SigMatch_::next, TransformData_::options, SCFree, sigmatch_table, SigMatchFree(), SignatureInitData_::smlists, TransformData_::transform, DetectEngineTransforms::transforms, and SignatureInitData_::transforms.
Referenced by SigCleanSignatures().


| Signature* SigInit | ( | DetectEngineCtx * | de_ctx, |
| const char * | sigstr | ||
| ) |
Parses a signature and adds it to the Detection Engine Context.
| de_ctx | Pointer to the Detection Engine Context. |
| sigstr | Pointer to a character string containing the signature to be parsed. |
| Pointer | to the Signature instance on success; NULL on failure. |
Definition at line 3500 of file detect-parse.c.
Referenced by DetectEngineAppendSig().

| SigMatch* SigMatchAlloc | ( | void | ) |
Definition at line 307 of file detect-parse.c.
References SigMatch_::next, SigMatch_::prev, SCCalloc, and unlikely.
| void SigMatchFree | ( | DetectEngineCtx * | de_ctx, |
| SigMatch * | sm | ||
| ) |
free a SigMatch
| sm | SigMatch to free. |
free the ctx, for that we call the Free func
Definition at line 321 of file detect-parse.c.
References SigMatch_::ctx, de_ctx, SigTableElmt_::Free, SCFree, sigmatch_table, and SigMatch_::type.
Referenced by DetectIPProtoRemoveAllSMs(), and SigFree().

| SigMatchData* SigMatchList2DataArray | ( | SigMatch * | head | ) |
convert SigMatch list to SigMatchData array
Definition at line 2642 of file detect-parse.c.
References len.
Definition at line 795 of file detect-parse.c.
References SignatureInitData_::buffer_index, SignatureInitData_::buffers, SignatureInitDataBuffer_::head, SignatureInitDataBuffer_::id, Signature_::init_data, and SigMatch_::next.
Definition at line 519 of file detect-parse.c.
References Signature_::init_data, SigMatch_::next, SigMatch_::prev, SignatureInitData_::smlists, and SignatureInitData_::smlists_tail.
Referenced by DetectIPProtoRemoveAllSMs().

| bool SigMatchStrictEnabled | ( | const enum DetectKeywordId | id | ) |
Definition at line 368 of file detect-parse.c.
References DETECT_TBLSIZE, flags, SIGMATCH_STRICT_PARSING, and sigmatch_table.
| int SignatureInitDataBufferCheckExpand | ( | Signature * | s | ) |
check if buffers array still has space left, expand if not
Definition at line 2191 of file detect-parse.c.
References SignatureInitData_::buffer_index, SignatureInitData_::buffers, SignatureInitData_::buffers_size, Signature_::init_data, and SCRealloc.
Referenced by DetectBufferGetActiveList().

| void SigParseRegisterTests | ( | void | ) |
Definition at line 6342 of file detect-parse.c.
References DetectParseRegisterTests(), and UtRegisterTest().
Referenced by SigRegisterTests().


| void SigTableApplyStrictCommandLineOption | ( | const char * | str | ) |
Definition at line 376 of file detect-parse.c.
References DETECT_TBLSIZE, FatalError, SigTableElmt_::flags, SCStrdup, SIGMATCH_STRICT_PARSING, sigmatch_table, and str.
| int g_skip_prefilter |
Definition at line 1159 of file detect-engine-mpm.c.
| bool sc_set_caps |
set caps or not
Definition at line 193 of file suricata.c.
| SigTableElmt* sigmatch_table = NULL |
Definition at line 79 of file detect-parse.c.
Referenced by DetectAckRegister(), DetectAppLayerEventRegister(), DetectAppLayerProtocolRegister(), DetectAppLayerStateRegister(), DetectAsn1Register(), DetectBase64DataRegister(), DetectBase64DecodeRegister(), DetectBsizeRegister(), DetectBypassRegister(), DetectByteExtractRegister(), DetectBytejumpRegister(), DetectBytemathRegister(), DetectBytetestRegister(), DetectClasstypeRegister(), DetectConfigRegister(), DetectContentRegister(), DetectCsumRegister(), DetectDatarepRegister(), DetectDatasetRegister(), DetectDepthRegister(), DetectDetectionFilterRegister(), DetectDistanceRegister(), DetectDnsResponseRegister(), DetectDsizeRegister(), DetectEngineAppInspectionEngineSignatureFree(), DetectEngineBufferTypeValidateTransform(), DetectEngineContentModifierBufferSetup(), DetectEngineEventRegister(), DetectEngineInspectGenericList(), DetectEntropyRegister(), DetectEtherhdrRegister(), DetectFastPatternRegister(), DetectFiledataRegister(), DetectFilemagicRegister(), DetectFileMd5Register(), DetectFilenameRegister(), DetectFileSha1Register(), DetectFileSha256Register(), DetectFilesizeRegister(), DetectFilestoreRegister(), DetectFlagsRegister(), DetectFlowAgeRegister(), DetectFlowbitsRegister(), DetectFlowBytesRegister(), DetectFlowBytesToClientRegister(), DetectFlowBytesToServerRegister(), DetectFlowElephantRegister(), DetectFlowintRegister(), DetectFlowPktsRegister(), DetectFlowPktsToClientRegister(), DetectFlowPktsToServerRegister(), DetectFlowRegister(), DetectFlowvarRegister(), DetectFragBitsRegister(), DetectFragOffsetRegister(), DetectFrameRegister(), DetectFtpbounceRegister(), DetectFtpCommandDataRegister(), DetectFtpCommandRegister(), DetectFtpCompletionCodeRegister(), DetectFtpdataRegister(), DetectFtpDynamicPortRegister(), DetectFtpModeRegister(), DetectFtpReplyReceivedRegister(), DetectFtpReplyRegister(), DetectGeoipRegister(), DetectGidRegister(), DetectHostbitsRegister(), DetectHttp2Register(), DetectHttpClientBodyRegister(), DetectHttpCookieRegister(), DetectHttpHeaderNamesRegister(), DetectHttpHeaderRegister(), DetectHttpHHRegister(), DetectHttpMethodRegister(), DetectHttpProtocolRegister(), DetectHttpRawHeaderRegister(), DetectHttpRequestHeaderRegister(), DetectHttpRequestLineRegister(), DetectHttpResponseHeaderRegister(), DetectHttpResponseLineRegister(), DetectHttpServerBodyRegister(), DetectHttpStartRegister(), DetectHttpStatCodeRegister(), DetectHttpStatMsgRegister(), DetectHttpUARegister(), DetectHttpUriRegister(), DetectIcmpIdRegister(), DetectIcmpSeqRegister(), DetectIcmpv4HdrRegister(), DetectICMPv6hdrRegister(), DetectICMPv6mtuRegister(), DetectICodeRegister(), DetectIdRegister(), DetectIGMPHdrRegister(), DetectIGMPTypeRegister(), DetectIPAddrBufferRegister(), DetectIpOptsRegister(), DetectIPProtoRegister(), DetectIPRepRegister(), DetectIpv4hdrRegister(), DetectIpv6hdrRegister(), DetectIsdataatRegister(), DetectITypeRegister(), DetectJa4HashRegister(), DetectL3ProtoRegister(), DetectLuaRegister(), DetectMarkRegister(), DetectMetadataRegister(), DetectMsgRegister(), DetectNoalertRegister(), DetectNocaseRegister(), DetectOffsetRegister(), DetectPcreRegister(), DetectPktDataRegister(), DetectPktvarRegister(), DetectPrefilterRegister(), DetectPriorityRegister(), DetectRawbytesRegister(), DetectReferenceRegister(), DetectReplaceRegister(), DetectRequiresRegister(), DetectRevRegister(), DetectRpcRegister(), DetectSameipRegister(), DetectSCTPChunkCntRegister(), DetectSCTPChunkDataRegister(), DetectSCTPChunkTypeRegister(), DetectSCTPHdrRegister(), DetectSCTPVtagRegister(), DetectSeqRegister(), DetectSidRegister(), DetectSipMethodRegister(), DetectSipUriRegister(), DetectSslStateRegister(), DetectSslVersionRegister(), DetectStreamSizeRegister(), DetectTagRegister(), DetectTargetRegister(), DetectTcphdrRegister(), DetectTcpmssRegister(), DetectTcpSessionRegister(), DetectTcpWscaleRegister(), DetectTemplateRegister(), DetectThresholdRegister(), DetectTlsAlpnRegister(), DetectTlsCertChainLenRegister(), DetectTlsCertsRegister(), DetectTlsFingerprintRegister(), DetectTlsIssuerRegister(), DetectTlsJa3HashRegister(), DetectTlsJa3SHashRegister(), DetectTlsJa3SStringRegister(), DetectTlsJa3StringRegister(), DetectTlsRandomBytesRegister(), DetectTlsRandomRegister(), DetectTlsRandomTimeRegister(), DetectTlsRegister(), DetectTlsSerialRegister(), DetectTlsSniRegister(), DetectTlsSubjectAltNameRegister(), DetectTlsSubjectRegister(), DetectTlsValidityRegister(), DetectTlsVersionRegister(), DetectTosRegister(), DetectTransformLuaxformRegister(), DetectTransformPcrexformRegister(), DetectTtlRegister(), DetectUdphdrRegister(), DetectUricontentRegister(), DetectUrilenRegister(), DetectVlanIdRegister(), DetectVlanLayersRegister(), DetectWindowRegister(), DetectWithinRegister(), DetectXbitsRegister(), EngineAnalysisFP(), EngineAnalysisRules2(), PrefilterSetupRuleGroup(), SCDetectHelperKeywordAliasRegister(), SCDetectHelperKeywordRegister(), SCDetectHelperKeywordSetCleanCString(), SCDetectHelperNewKeywordId(), SCDetectHelperTransformRegister(), SCSigTableHasKeyword(), SigFree(), SigMatchFree(), SigMatchStrictEnabled(), SigTableApplyStrictCommandLineOption(), SigTableCleanup(), SigTableInit(), SigTableList(), and SigTableRegisterTests().