suricata
detect-rpc.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2020 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Pablo Rincon <pablo.rincon.crespo@gmail.com>
22  *
23  * Implements RPC keyword
24  */
25 
26 #include "suricata-common.h"
27 #include "decode.h"
28 
29 #include "detect.h"
30 #include "detect-rpc.h"
31 #include "detect-parse.h"
32 #include "detect-engine.h"
33 #include "detect-engine-mpm.h"
34 #include "detect-engine-siggroup.h"
35 #include "detect-engine-address.h"
36 #include "detect-engine-build.h"
37 
38 #include "util-unittest-helper.h"
39 #include "util-debug.h"
40 #include "util-byte.h"
41 
42 /**
43  * \brief Regex for parsing our rpc options
44  */
45 #define PARSE_REGEX "^\\s*([0-9]{0,10})\\s*(?:,\\s*([0-9]{0,10}|[*])\\s*(?:,\\s*([0-9]{0,10}|[*]))?)?\\s*$"
46 
47 static DetectParseRegex parse_regex;
48 
49 static int DetectRpcMatch (DetectEngineThreadCtx *, Packet *,
50  const Signature *, const SigMatchCtx *);
51 static int DetectRpcSetup (DetectEngineCtx *, Signature *, const char *);
52 #ifdef UNITTESTS
53 static void DetectRpcRegisterTests(void);
54 #endif
55 void DetectRpcFree(DetectEngineCtx *, void *);
56 
57 /**
58  * \brief Registration function for rpc keyword
59  */
60 void DetectRpcRegister (void)
61 {
63  sigmatch_table[DETECT_RPC].desc = "match RPC procedure numbers and RPC version";
64  sigmatch_table[DETECT_RPC].url = "/rules/payload-keywords.html#rpc";
65  sigmatch_table[DETECT_RPC].Match = DetectRpcMatch;
66  sigmatch_table[DETECT_RPC].Setup = DetectRpcSetup;
68 #ifdef UNITTESTS
69  sigmatch_table[DETECT_RPC].RegisterTests = DetectRpcRegisterTests;
70 #endif
71  DetectSetupParseRegexes(PARSE_REGEX, &parse_regex);
72 }
73 
74 /*
75  * returns 0: no match
76  * 1: match
77  * -1: error
78  */
79 
80 /**
81  * \brief This function is used to match rpc request set on a packet with those passed via rpc
82  *
83  * \param t pointer to thread vars
84  * \param det_ctx pointer to the pattern matcher thread
85  * \param p pointer to the current packet
86  * \param m pointer to the sigmatch that we will cast into DetectRpcData
87  *
88  * \retval 0 no match
89  * \retval 1 match
90  */
91 static int DetectRpcMatch (DetectEngineThreadCtx *det_ctx, Packet *p,
92  const Signature *s, const SigMatchCtx *ctx)
93 {
94  /* PrintRawDataFp(stdout, p->payload, p->payload_len); */
95  const DetectRpcData *rd = (const DetectRpcData *)ctx;
96  char *rpcmsg = (char *)p->payload;
97 
98  if (PacketIsTCP(p)) {
99  /* if Rpc msg too small */
100  if (p->payload_len < 28) {
101  SCLogDebug("TCP packet to small for the rpc msg (%u)", p->payload_len);
102  return 0;
103  }
104  rpcmsg += 4;
105  } else if (PacketIsUDP(p)) {
106  /* if Rpc msg too small */
107  if (p->payload_len < 24) {
108  SCLogDebug("UDP packet to small for the rpc msg (%u)", p->payload_len);
109  return 0;
110  }
111  } else {
112  SCLogDebug("No valid proto for the rpc message");
113  return 0;
114  }
115 
116  /* Point through the rpc msg structure. Use SCNtohl() to compare values */
117  RpcMsg *msg = (RpcMsg *)rpcmsg;
118 
119  /* If its not a call, no match */
120  if (SCNtohl(msg->type) != 0) {
121  SCLogDebug("RPC message type is not a call");
122  return 0;
123  }
124 
125  if (SCNtohl(msg->prog) != rd->program)
126  return 0;
127 
128  if ((rd->flags & DETECT_RPC_CHECK_VERSION) && SCNtohl(msg->vers) != rd->program_version)
129  return 0;
130 
131  if ((rd->flags & DETECT_RPC_CHECK_PROCEDURE) && SCNtohl(msg->proc) != rd->procedure)
132  return 0;
133 
134  SCLogDebug("prog:%u pver:%u proc:%u matched", SCNtohl(msg->prog), SCNtohl(msg->vers), SCNtohl(msg->proc));
135  return 1;
136 }
137 
138 /**
139  * \brief This function is used to parse rpc options passed via rpc keyword
140  *
141  * \param de_ctx Pointer to the detection engine context
142  * \param rpcstr Pointer to the user provided rpc options
143  *
144  * \retval rd pointer to DetectRpcData on success
145  * \retval NULL on failure
146  */
147 static DetectRpcData *DetectRpcParse (DetectEngineCtx *de_ctx, const char *rpcstr)
148 {
149  DetectRpcData *rd = NULL;
150  char *args[3] = {NULL,NULL,NULL};
151  int res = 0;
152  size_t pcre2_len;
153 
154  pcre2_match_data *match = NULL;
155  int ret = DetectParsePcreExec(&parse_regex, &match, rpcstr, 0, 0);
156  if (ret < 1 || ret > 4) {
157  SCLogError("parse error, ret %" PRId32 ", string %s", ret, rpcstr);
158  goto error;
159  }
160 
161  if (ret > 1) {
162  const char *str_ptr;
163  res = pcre2_substring_get_bynumber(match, 1, (PCRE2_UCHAR8 **)&str_ptr, &pcre2_len);
164  if (res < 0) {
165  SCLogError("pcre2_substring_get_bynumber failed");
166  goto error;
167  }
168  args[0] = (char *)str_ptr;
169 
170  if (ret > 2) {
171  res = pcre2_substring_get_bynumber(match, 2, (PCRE2_UCHAR8 **)&str_ptr, &pcre2_len);
172  if (res < 0) {
173  SCLogError("pcre2_substring_get_bynumber failed");
174  goto error;
175  }
176  args[1] = (char *)str_ptr;
177  }
178  if (ret > 3) {
179  res = pcre2_substring_get_bynumber(match, 3, (PCRE2_UCHAR8 **)&str_ptr, &pcre2_len);
180  if (res < 0) {
181  SCLogError("pcre2_substring_get_bynumber failed");
182  goto error;
183  }
184  args[2] = (char *)str_ptr;
185  }
186  }
187 
188  rd = SCMalloc(sizeof(DetectRpcData));
189  if (unlikely(rd == NULL))
190  goto error;
191  rd->flags = 0;
192  rd->program = 0;
193  rd->program_version = 0;
194  rd->procedure = 0;
195 
196  int i;
197  for (i = 0; i < (ret - 1); i++) {
198  if (args[i]) {
199  switch (i) {
200  case 0:
201  if (StringParseUint32(&rd->program, 10, strlen(args[i]), args[i]) <= 0) {
202  SCLogError("Invalid size specified for the rpc program:\"%s\"", args[i]);
203  goto error;
204  }
206  break;
207  case 1:
208  if (args[i][0] != '*') {
209  if (StringParseUint32(&rd->program_version, 10, strlen(args[i]), args[i]) <= 0) {
210  SCLogError(
211  "Invalid size specified for the rpc version:\"%s\"", args[i]);
212  goto error;
213  }
215  }
216  break;
217  case 2:
218  if (args[i][0] != '*') {
219  if (StringParseUint32(&rd->procedure, 10, strlen(args[i]), args[i]) <= 0) {
220  SCLogError(
221  "Invalid size specified for the rpc procedure:\"%s\"", args[i]);
222  goto error;
223  }
225  }
226  break;
227  }
228  } else {
229  SCLogError("invalid rpc option %s", rpcstr);
230  goto error;
231  }
232  }
233  for (i = 0; i < (ret -1); i++){
234  if (args[i] != NULL)
235  pcre2_substring_free((PCRE2_UCHAR8 *)args[i]);
236  }
237  pcre2_match_data_free(match);
238  return rd;
239 
240 error:
241  if (match) {
242  pcre2_match_data_free(match);
243  }
244  for (i = 0; i < (ret -1) && i < 3; i++){
245  if (args[i] != NULL)
246  pcre2_substring_free((PCRE2_UCHAR8 *)args[i]);
247  }
248  if (rd != NULL)
249  DetectRpcFree(de_ctx, rd);
250  return NULL;
251 
252 }
253 
254 /**
255  * \brief this function is used to add the parsed rpcdata into the current signature
256  *
257  * \param de_ctx pointer to the Detection Engine Context
258  * \param s pointer to the Current Signature
259  * \param m pointer to the Current SigMatch
260  * \param rpcstr pointer to the user provided rpc options
261  *
262  * \retval 0 on Success
263  * \retval -1 on Failure
264  */
265 int DetectRpcSetup (DetectEngineCtx *de_ctx, Signature *s, const char *rpcstr)
266 {
267  DetectRpcData *rd = NULL;
268 
269  rd = DetectRpcParse(de_ctx, rpcstr);
270  if (rd == NULL) goto error;
271 
273  NULL) {
274  goto error;
275  }
277 
278  return 0;
279 
280 error:
281  if (rd != NULL)
282  DetectRpcFree(de_ctx, rd);
283  return -1;
284 
285 }
286 
287 /**
288  * \brief this function will free memory associated with DetectRpcData
289  *
290  * \param rd pointer to DetectRpcData
291  */
293 {
294  SCEnter();
295 
296  if (ptr == NULL) {
297  SCReturn;
298  }
299 
300  DetectRpcData *rd = (DetectRpcData *)ptr;
301  SCFree(rd);
302 
303  SCReturn;
304 }
305 
306 #ifdef UNITTESTS
307 #include "detect-engine-alert.h"
308 /**
309  * \test DetectRpcTestParse01 is a test to make sure that we return "something"
310  * when given valid rpc opt
311  */
312 static int DetectRpcTestParse01 (void)
313 {
314  DetectRpcData *rd = DetectRpcParse(NULL, "123,444,555");
315  FAIL_IF_NULL(rd);
316 
317  DetectRpcFree(NULL, rd);
318  PASS;
319 }
320 
321 /**
322  * \test DetectRpcTestParse02 is a test for setting the established rpc opt
323  */
324 static int DetectRpcTestParse02 (void)
325 {
326  DetectRpcData *rd = NULL;
327  rd = DetectRpcParse(NULL, "111,222,333");
328  FAIL_IF_NULL(rd);
332  FAIL_IF_NOT(rd->program == 111);
333  FAIL_IF_NOT(rd->program_version == 222);
334  FAIL_IF_NOT(rd->procedure == 333);
335 
336  DetectRpcFree(NULL, rd);
337 
338  PASS;
339 }
340 
341 /**
342  * \test DetectRpcTestParse03 is a test for checking the wildcards
343  * and not specified fields
344  */
345 static int DetectRpcTestParse03 (void)
346 {
347  DetectRpcData *rd = NULL;
348 
349  rd = DetectRpcParse(NULL, "111,*,333");
350  FAIL_IF_NULL(rd);
351 
355  FAIL_IF_NOT(rd->program == 111);
356  FAIL_IF_NOT(rd->program_version == 0);
357  FAIL_IF_NOT(rd->procedure == 333);
358 
359  DetectRpcFree(NULL, rd);
360 
361  rd = DetectRpcParse(NULL, "111,222,*");
362  FAIL_IF_NULL(rd);
363 
367  FAIL_IF_NOT(rd->program == 111);
368  FAIL_IF_NOT(rd->program_version == 222);
369  FAIL_IF_NOT(rd->procedure == 0);
370 
371  DetectRpcFree(NULL, rd);
372 
373  rd = DetectRpcParse(NULL, "111,*,*");
374  FAIL_IF_NULL(rd);
375 
379  FAIL_IF_NOT(rd->program == 111);
380  FAIL_IF_NOT(rd->program_version == 0);
381  FAIL_IF_NOT(rd->procedure == 0);
382 
383  DetectRpcFree(NULL, rd);
384 
385  rd = DetectRpcParse(NULL, "111,222");
386  FAIL_IF_NULL(rd);
387 
391  FAIL_IF_NOT(rd->program == 111);
392  FAIL_IF_NOT(rd->program_version == 222);
393  FAIL_IF_NOT(rd->procedure == 0);
394 
395  DetectRpcFree(NULL, rd);
396 
397  rd = DetectRpcParse(NULL, "111");
398  FAIL_IF_NULL(rd);
399 
403  FAIL_IF_NOT(rd->program == 111);
404  FAIL_IF_NOT(rd->program_version == 0);
405  FAIL_IF_NOT(rd->procedure == 0);
406 
407  DetectRpcFree(NULL, rd);
408  PASS;
409 }
410 
411 /**
412  * \test DetectRpcTestParse04 is a test for check the discarding of empty options
413  */
414 static int DetectRpcTestParse04 (void)
415 {
416  DetectRpcData *rd = NULL;
417  rd = DetectRpcParse(NULL, "");
418 
419  FAIL_IF_NOT_NULL(rd);
420  DetectRpcFree(NULL, rd);
421 
422  PASS;
423 }
424 
425 /**
426  * \test DetectRpcTestParse05 is a test for check invalid values
427  */
428 static int DetectRpcTestParse05 (void)
429 {
430  DetectRpcData *rd = NULL;
431  rd = DetectRpcParse(NULL, "111,aaa,*");
432 
433  FAIL_IF_NOT_NULL(rd);
434  DetectRpcFree(NULL, rd);
435 
436  PASS;
437 }
438 
439 /**
440  * \test DetectRpcTestParse05 is a test to check the match function
441  */
442 static int DetectRpcTestSig01(void)
443 {
444  /* RPC Call */
445  uint8_t buf[] = {
446  /* XID */
447  0x64,0xb2,0xb3,0x75,
448  /* Message type: Call (0) */
449  0x00,0x00,0x00,0x00,
450  /* RPC Version (2) */
451  0x00,0x00,0x00,0x02,
452  /* Program portmap (100000) */
453  0x00,0x01,0x86,0xa0,
454  /* Program version (2) */
455  0x00,0x00,0x00,0x02,
456  /* Program procedure (3) = GETPORT */
457  0x00,0x00,0x00,0x03,
458  /* AUTH_NULL */
459  0x00,0x00,0x00,0x00,
460  /* Length 0 */
461  0x00,0x00,0x00,0x00,
462  /* VERIFIER NULL */
463  0x00,0x00,0x00,0x00,
464  /* Length 0 */
465  0x00,0x00,0x00,0x00,
466  /* Program portmap */
467  0x00,0x01,0x86,0xa2,
468  /* Version 2 */
469  0x00,0x00,0x00,0x02,
470  /* Proto UDP */
471  0x00,0x00,0x00,0x11,
472  /* Port 0 */
473  0x00,0x00,0x00,0x00 };
474  uint16_t buflen = sizeof(buf);
475  Packet *p = NULL;
476  Signature *s = NULL;
478  DetectEngineThreadCtx *det_ctx;
479 
480  memset(&th_v, 0, sizeof(th_v));
482 
483  p = UTHBuildPacket(buf, buflen, IPPROTO_UDP);
484 
487 
488  de_ctx->flags |= DE_QUIET;
489 
491  "alert udp any any -> any any (msg:\"RPC Get Port Call\"; rpc:100000, 2, 3; sid:1;)");
492  FAIL_IF_NULL(s);
493 
495  "alert udp any any -> any any (msg:\"RPC Get Port Call\"; rpc:100000, 2, *; sid:2;)");
496  FAIL_IF_NULL(s);
497 
499  "alert udp any any -> any any (msg:\"RPC Get Port Call\"; rpc:100000, *, 3; sid:3;)");
500  FAIL_IF_NULL(s);
501 
503  "alert udp any any -> any any (msg:\"RPC Get Port Call\"; rpc:100000, *, *; sid:4;)");
504  FAIL_IF_NULL(s);
505 
506  s = DetectEngineAppendSig(de_ctx, "alert udp any any -> any any (msg:\"RPC Get XXX Call.. no "
507  "match\"; rpc:123456, *, 3; sid:5;)");
508  FAIL_IF_NULL(s);
509 
511  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
512 
513  SigMatchSignatures(&th_v, de_ctx, det_ctx, p);
514  FAIL_IF(PacketAlertCheck(p, 1) == 0);
515  FAIL_IF(PacketAlertCheck(p, 2) == 0);
516  FAIL_IF(PacketAlertCheck(p, 3) == 0);
517  FAIL_IF(PacketAlertCheck(p, 4) == 0);
518  FAIL_IF(PacketAlertCheck(p, 5) > 0);
519 
520  UTHFreePackets(&p, 1);
521 
522  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
525  PASS;
526 }
527 
528 /**
529  * \brief this function registers unit tests for DetectRpc
530  */
531 static void DetectRpcRegisterTests(void)
532 {
533  UtRegisterTest("DetectRpcTestParse01", DetectRpcTestParse01);
534  UtRegisterTest("DetectRpcTestParse02", DetectRpcTestParse02);
535  UtRegisterTest("DetectRpcTestParse03", DetectRpcTestParse03);
536  UtRegisterTest("DetectRpcTestParse04", DetectRpcTestParse04);
537  UtRegisterTest("DetectRpcTestParse05", DetectRpcTestParse05);
538  UtRegisterTest("DetectRpcTestSig01", DetectRpcTestSig01);
539 }
540 #endif /* UNITTESTS */
util-byte.h
SigTableElmt_::url
const char * url
Definition: detect.h:1545
detect-engine.h
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
RpcMsg_::type
uint32_t type
Definition: detect-rpc.h:37
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
detect-engine-siggroup.h
DetectParseRegex
Definition: detect-parse.h:94
SigTableElmt_::name
const char * name
Definition: detect.h:1542
PARSE_REGEX
#define PARSE_REGEX
Regex for parsing our rpc options.
Definition: detect-rpc.c:45
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
DetectRpcData_
Definition: detect-rpc.h:44
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
DetectRpcData_::flags
uint8_t flags
Definition: detect-rpc.h:48
DetectRpcData_::procedure
uint32_t procedure
Definition: detect-rpc.h:47
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
RpcMsg_
Definition: detect-rpc.h:35
Packet_::payload
uint8_t * payload
Definition: decode.h:620
PacketAlertCheck
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
Definition: detect-engine-alert.c:144
DetectRpcRegister
void DetectRpcRegister(void)
Registration function for rpc keyword.
Definition: detect-rpc.c:60
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DetectRpcData_::program_version
uint32_t program_version
Definition: detect-rpc.h:46
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
DETECT_RPC_CHECK_PROCEDURE
#define DETECT_RPC_CHECK_PROCEDURE
Definition: detect-rpc.h:32
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
UTHBuildPacket
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
Definition: util-unittest-helper.c:241
SigMatchSignatures
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Definition: detect.c:3305
p
Packet * p
Definition: fuzz_dataset.c:30
DetectParsePcreExec
int DetectParsePcreExec(DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options)
Definition: detect-parse.c:4019
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
Packet_::payload_len
uint16_t payload_len
Definition: decode.h:621
DETECT_RPC
@ DETECT_RPC
Definition: detect-engine-register.h:118
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
detect-rpc.h
decode.h
FAIL_IF_NOT_NULL
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
Definition: util-unittest.h:96
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
DetectRpcData_::program
uint32_t program
Definition: detect-rpc.h:45
DetectSetupParseRegexes
void DetectSetupParseRegexes(const char *parse_str, DetectParseRegex *detect_parse)
Definition: detect-parse.c:4145
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
detect-engine-mpm.h
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
DetectEngineThreadCtxInit
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
Definition: detect-engine.c:3660
RpcMsg_::prog
uint32_t prog
Definition: detect-rpc.h:39
StringParseUint32
int StringParseUint32(uint32_t *res, int base, size_t len, const char *str)
Definition: util-byte.c:268
DETECT_SM_LIST_MATCH
@ DETECT_SM_LIST_MATCH
Definition: detect.h:118
RpcMsg_::proc
uint32_t proc
Definition: detect-rpc.h:41
SCReturn
#define SCReturn
Definition: util-debug.h:286
Signature_::flags
uint32_t flags
Definition: detect.h:693
Packet_
Definition: decode.h:516
detect-engine-build.h
detect-engine-alert.h
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
SigGroupBuild
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
Definition: detect-engine-build.c:2300
StatsThreadInit
void StatsThreadInit(StatsThreadContext *stats)
Definition: counters.c:1332
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
th_v
ThreadVars * th_v
Definition: fuzz_dataset.c:29
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
suricata-common.h
DetectEngineThreadCtxDeinit
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Definition: detect-engine.c:3905
DetectRpcFree
void DetectRpcFree(DetectEngineCtx *, void *)
this function will free memory associated with DetectRpcData
Definition: detect-rpc.c:292
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SCFree
#define SCFree(p)
Definition: util-mem.h:61
SCNtohl
#define SCNtohl(x)
Definition: suricata-common.h:435
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
RpcMsg_::vers
uint32_t vers
Definition: detect-rpc.h:40
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
DETECT_RPC_CHECK_PROGRAM
#define DETECT_RPC_CHECK_PROGRAM
Definition: detect-rpc.h:30
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
DETECT_RPC_CHECK_VERSION
#define DETECT_RPC_CHECK_VERSION
Definition: detect-rpc.h:31
StatsThreadCleanup
void StatsThreadCleanup(StatsThreadContext *stats)
Definition: counters.c:1428
detect-engine-address.h
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
SIG_FLAG_REQUIRE_PACKET
#define SIG_FLAG_REQUIRE_PACKET
Definition: detect.h:257
UTHFreePackets
void UTHFreePackets(Packet **p, int numpkts)
UTHFreePackets: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:453