88 static inline uint8_t DetectRulePacketRules(
ThreadVars *
const tv,
123 DetectRunInspectIPOnly(
th_v,
de_ctx, det_ctx, pflow,
p);
126 DetectRunGetRuleGroup(
de_ctx,
p, pflow, &scratch);
129 if (scratch.
sgh == NULL) {
131 SCLogDebug(
"no sgh for this packet, nothing to match against");
135 "packet %" PRIu64
": no sgh, need to apply default policies",
PcapPacketCntGet(
p));
138 DetectRunPrefilterPkt(
th_v,
de_ctx, det_ctx,
p, &scratch);
142 const uint8_t pkt_policy = DetectRulePacketRules(
th_v,
de_ctx, det_ctx,
p, pflow, &scratch);
160 if (
p->
proto == IPPROTO_TCP) {
164 SCLogDebug(
"default accept: no PKT_STREAM_EST");
165 DetectRunAppendDefaultAccept(det_ctx,
p);
178 DetectRunFrames(
th_v,
de_ctx, det_ctx,
p, pflow, &scratch);
188 DetectRunAppendDefaultAccept(det_ctx,
p);
192 }
else if (
p->
proto == IPPROTO_UDP) {
193 DetectRunFrames(
th_v,
de_ctx, det_ctx,
p, pflow, &scratch);
197 DetectRunTx(
th_v,
de_ctx, det_ctx,
p, pflow, &scratch);
208 DetectRunAppendDefaultAccept(det_ctx,
p);
213 DetectRunPostRules(
th_v,
de_ctx, det_ctx,
p, pflow, &scratch);
215 DetectRunCleanup(det_ctx,
p, pflow);
240 if (scratch.
sgh == NULL) {
241 SCLogDebug(
"no sgh for this packet, nothing to match against");
246 DetectRunPrefilterPkt(
th_v,
de_ctx, det_ctx,
p, &scratch);
250 const uint8_t pkt_policy = DetectRulePacketRules(
th_v,
de_ctx, det_ctx,
p, pflow, &scratch);
257 DetectRunPostRules(
th_v,
de_ctx, det_ctx,
p, pflow, &scratch);
259 DetectRunCleanup(det_ctx,
p, pflow);
272 SCLogDebug(
"running match functions, sm %p", smd);
309 }
else if (
p->
proto == 0) {
310 if (!(PacketIsIPv4(
p) || PacketIsIPv6(
p))) {
319 int proto = PacketGetIPProto(
p);
320 if (
proto == IPPROTO_TCP) {
324 const uint16_t port = dir ?
p->
dp :
p->
sp;
329 SCLogDebug(
"TCP list %p, port %u, direction %s, sghport %p, sgh %p", list, port,
330 dir ?
"toserver" :
"toclient", sghport, sgh);
331 }
else if (
proto == IPPROTO_UDP) {
333 uint16_t port = dir ?
p->
dp :
p->
sp;
337 SCLogDebug(
"UDP list %p, port %u, direction %s, sghport %p, sgh %p", list, port,
338 dir ?
"toserver" :
"toclient", sghport, sgh);
346 static inline void DetectPrefilterCopyDeDup(
354 while (final_cnt-- > 0) {
359 if (
likely(
id != previous_id)) {
376 DetectPostInspectFileFlagsUpdate(
Flow *
f,
const SigGroupHead *sgh, uint8_t direction)
381 SCLogDebug(
"requesting disabling all file features for flow");
385 SCLogDebug(
"requesting disabling filestore for flow");
386 flow_file_flags |= (FLOWFILE_NO_STORE_TS|FLOWFILE_NO_STORE_TC);
389 if (!(sgh->
flags & SIG_GROUP_HEAD_HAVEFILEMAGIC)) {
390 SCLogDebug(
"requesting disabling magic for flow");
395 SCLogDebug(
"requesting disabling md5 for flow");
399 SCLogDebug(
"requesting disabling sha1 for flow");
403 SCLogDebug(
"requesting disabling sha256 for flow");
407 if (flow_file_flags != 0) {
423 SCLogDebug(
"STREAMTCP_STREAM_FLAG_DISABLE_RAW ssn.client");
428 DetectPostInspectFileFlagsUpdate(pflow,
438 SCLogDebug(
"STREAMTCP_STREAM_FLAG_DISABLE_RAW ssn.server");
443 DetectPostInspectFileFlagsUpdate(pflow,
448 static inline void DetectRunGetRuleGroup(
456 bool use_flow_sgh =
false;
459 if (PacketGetIPProto(
p) == pflow->
proto) {
463 SCLogDebug(
"sgh = pflow->sgh_toserver; => %p", sgh);
467 SCLogDebug(
"sgh = pflow->sgh_toclient; => %p", sgh);
473 if (!(use_flow_sgh)) {
486 DetectRunPostGetFirstRuleGroup(
p, pflow, sgh);
506 SCLogDebug(
"testing against \"ip-only\" signatures");
525 static inline bool DetectRunInspectRuleHeader(
537 SCLogDebug(
"skipping sig as the flow has no flowvars and sig "
538 "has SIG_FLAG_REQUIRE_FLOWVAR flag set.");
543 if (!(s->
proto == NULL)) {
544 const uint8_t s_proto_flags = s->
proto->
flags;
556 if (PacketIsEthernet(
p) &&
590 SCLogDebug(
"port-less protocol and sig needs ports");
596 if (PacketIsIPv4(
p)) {
599 }
else if (PacketIsIPv6(
p)) {
606 if (PacketIsIPv4(
p)) {
609 }
else if (PacketIsIPv6(
p)) {
637 DetectPrefilterCopyDeDup(
de_ctx, det_ctx);
652 static bool IsOnlyTxInDirection(
Flow *
f, uint64_t txid, uint8_t dir)
655 if (tx_cnt == txid + 1) {
659 if (tx_cnt == txid + 2) {
665 if ((dir == STREAM_TOSERVER && (txd->
flags & APP_LAYER_TX_SKIP_INSPECT_TS)) ||
666 (dir == STREAM_TOCLIENT && (txd->
flags & APP_LAYER_TX_SKIP_INSPECT_TC))) {
674 static int SortHelper(
const void *a,
const void *b)
680 return sa->
iid > sb->
iid ? 1 : -1;
683 static inline bool SkipFwRules(
const Packet *
p)
685 if (
p->
flow != NULL) {
710 SCLogDebug(
"packet %" PRIu64
": drop PKT_DROP_REASON_FW_DEFAULT_PACKET_POLICY",
722 SCLogDebug(
"packet %" PRIu64
": accept scope hook upgraded to packet",
752 const uint8_t alert_flags_in)
768 uint8_t alert_flags = alert_flags_in;
769 if (
f->
proto != IPPROTO_UDP) {
781 static inline uint8_t DetectRulePacketRules(
ThreadVars *
const tv,
786 bool fw_verdict =
false;
806 bool skip_fw = SkipFwRules(
p);
807 uint32_t sflags, next_sflags = 0;
809 next_s = *match_array++;
810 next_sflags = next_s->
flags;
812 while (match_cnt--) {
814 bool break_out_of_packet_filter =
false;
815 uint8_t alert_flags = 0;
820 sflags = next_sflags;
822 next_s = *match_array++;
823 next_sflags = next_s->
flags;
835 }
else if (have_fw_rules) {
842 break_out_of_packet_filter =
true;
865 if (SigDsizePrefilter(
p, s, sflags))
876 if (DetectRunInspectRuleHeader(
p, pflow, s, sflags) ==
false) {
887 DetectRunPostMatch(
tv, det_ctx,
p, s);
889 DetectRulePacketAppendAlert(
de_ctx, det_ctx, s,
p, pflow, alert_flags);
898 SCLogDebug(
"sig_array_len %u det_ctx->pmq.rule_id_array_cnt %u",
901 for (uint32_t x = 0; x < match_cnt; x++) {
902 *r++ = match_array[x];
903 SCLogDebug(
"appended %u", match_array[x]->
id);
910 if (
ts->app_inspect == NULL) {
922 uint32_t skipped = 0;
923 for (uint32_t x = 0; x < match_cnt; x++) {
925 if (last_sig == *
m) {
932 match_cnt -= skipped;
934 next_s = *match_array++;
935 next_sflags = next_s->
flags;
982 break_out_of_packet_filter =
true;
986 DetectVarProcessList(det_ctx, pflow,
p);
987 DetectReplaceFree(det_ctx);
991 if (break_out_of_packet_filter)
1000 if (have_fw_rules) {
1001 if (skip_fw || fw_verdict) {
1021 uint8_t flow_flags = 0;
1022 bool app_decoder_events =
false;
1045 det_ctx->pkt_stream_add_cnt++;
1054 flow_flags = STREAM_TOSERVER;
1057 flow_flags = STREAM_TOCLIENT;
1063 flow_flags |= STREAM_EOF;
1094 (
p->
proto == IPPROTO_UDP) ||
1106 SCLogDebug(
"packet doesn't have established flag set (proto %d)",
p->
proto);
1112 DetectRunScratchpad pad = { alproto, flow_flags, app_decoder_events, fw_pkt_policy, NULL };
1149 SCLogDebug(
"packet %" PRIu64
": default action as no verdict set %02x (pkt %s)",
1162 if (pflow != NULL) {
1185 FatalError(
"failed to allocate %" PRIu64
" bytes",
1189 SCLogDebug(
"array initialized to %u elements (%"PRIu64
" bytes)",
1201 const uint32_t need)
1212 uint32_t new_size = needed;
1215 FatalError(
"failed to expand to %" PRIu64
" bytes",
1221 SCLogDebug(
"array expanded from %u to %u elements (%"PRIu64
" bytes -> %"PRIu64
" bytes)",
1234 DetectRunTxSortHelper(
const void *a,
const void *b)
1238 if (s1->
id == s0->
id) {
1245 return s0->
id > s1->
id ? 1 : -1;
1249 #define TRACE_SID_TXS(sid,txs,...) \
1251 char _trace_buf[2048]; \
1252 snprintf(_trace_buf, sizeof(_trace_buf), __VA_ARGS__); \
1253 SCLogNotice("%p/%"PRIu64"/%u: %s", txs->tx_ptr, txs->tx_id, sid, _trace_buf); \
1256 #define TRACE_SID_TXS(sid,txs,...)
1268 SCLogDebug(
"pre: tx_ptr %p flow::alproto %s engine::alproto %s", tx_ptr,
1271 switch (engine_alproto) {
1274 tx_ptr = SCDoH2GetDnsTx(tx_ptr, flow_flags);
1285 }
else if (engine_alproto != alproto && engine_alproto !=
ALPROTO_UNKNOWN) {
1312 const uint8_t in_flow_flags,
1316 const uint8_t flow_flags = in_flow_flags;
1317 const int direction = (flow_flags & STREAM_TOSERVER) ? 0 : 1;
1318 uint32_t inspect_flags = stored_flags ? *stored_flags : 0;
1319 int total_matches = 0;
1320 uint16_t file_no_match = 0;
1321 bool mpm_before_progress =
false;
1322 bool mpm_in_progress =
false;
1324 TRACE_SID_TXS(s->
id, tx,
"starting %s", direction ?
"toclient" :
"toserver");
1327 if (
likely(stored_flags == NULL)) {
1345 TRACE_SID_TXS(s->
id, tx,
"continue, inspect_flags %x", inspect_flags);
1350 TRACE_SID_TXS(s->
id, tx,
"engine %p inspect_flags %x", engine, inspect_flags);
1354 if (!(inspect_flags &
BIT_U32(engine->
id)) &&
1366 "skip because engine alproto %s sub_state %u != tx_type %u (engine "
1370 engine = engine->
next;
1374 "inspecting engine alproto %s sub_state %u == tx_type %u (engine progress %u)",
1379 if (tx_ptr == NULL) {
1385 engine = engine->
next;
1396 SCLogDebug(
"tx progress %d < engine progress %d",
1403 "engine->mpm: t->tx_progress %u > engine->progress %u, so set "
1404 "mpm_before_progress",
1406 mpm_before_progress =
true;
1409 "engine->mpm: t->tx_progress %u == engine->progress %u, so set "
1413 mpm_in_progress =
true;
1418 uint8_t engine_flags = flow_flags;
1419 if (direction != engine->
dir) {
1420 engine_flags = flow_flags ^ (STREAM_TOCLIENT | STREAM_TOSERVER);
1426 TRACE_SID_TXS(s->
id, tx,
"stream skipped, stored result %d used instead", match);
1431 mpm_before_progress =
true;
1446 de_ctx, det_ctx, engine, s,
f, engine_flags, alstate, tx_ptr, tx->
tx_id);
1451 TRACE_SID_TXS(s->
id, tx,
"stream ran, store result %d for next tx (if any)", match);
1456 engine = engine->
next;
1463 engine = engine->
next;
1475 if (engine->
mpm && mpm_before_progress) {
1481 direction != engine->
dir) {
1487 if (direction == 0 && engine->
next == NULL) {
1491 engine = engine->
next;
1495 engine = engine->
next;
1496 }
while (engine != NULL);
1497 TRACE_SID_TXS(s->
id, tx,
"inspect_flags %x, total_matches %u, engine %p",
1498 inspect_flags, total_matches, engine);
1500 bool full_match =
false;
1501 if (engine == NULL && total_matches) {
1508 *stored_flags = inspect_flags;
1509 TRACE_SID_TXS(s->
id, tx,
"continue inspect flags %08x", inspect_flags);
1516 if (file_no_match) {
1527 inspect_flags, flow_flags, file_no_match);
1531 "mpm won't trigger for it anymore");
1535 "we may have to revisit anyway");
1537 inspect_flags, flow_flags, file_no_match);
1541 "mpm will revisit it");
1543 }
else if (inspect_flags != 0 || file_no_match != 0) {
1546 inspect_flags, flow_flags, file_no_match);
1548 if (inspect_flags == 0) {
1549 TRACE_SID_TXS(s->
id, tx,
"no match: inspect_flags %08x", inspect_flags);
1567 NULL, 0, NULL, NULL, 0, 0, 0, 0, false, 0, \
1575 const uint64_t tx_id,
void *tx_ptr,
const uint8_t flow_flags)
1578 const uint8_t tx_progress =
1582 const uint8_t e_tx_end_state =
1587 if (!updated && tx_progress < e_tx_end_state && ((flow_flags & STREAM_EOF) == 0)) {
1591 const uint8_t inspected_flag =
1594 SCLogDebug(
"%" PRIu64
" tx already fully inspected for %s. Flags %02x", tx_id,
1595 flow_flags & STREAM_TOSERVER ?
"toserver" :
"toclient", txd->
flags);
1599 const uint8_t skip_flag = (flow_flags & STREAM_TOSERVER) ? APP_LAYER_TX_SKIP_INSPECT_TS
1600 : APP_LAYER_TX_SKIP_INSPECT_TC;
1602 SCLogDebug(
"%" PRIu64
" tx should not be inspected in direction %s. Flags %02x", tx_id,
1603 flow_flags & STREAM_TOSERVER ?
"toserver" :
"toclient", txd->
flags);
1612 const uint8_t detect_progress =
1615 const int dir_int = (flow_flags & STREAM_TOSERVER) ? 0 : 1;
1618 tx_de_state ? &tx_de_state->
dir_state[dir_int] : NULL;
1624 .detect_progress = detect_progress,
1625 .detect_progress_orig = detect_progress,
1626 .tx_progress = (uint8_t)tx_progress,
1627 .tx_end_state = e_tx_end_state,
1634 static inline void StoreDetectProgress(
1638 if (flow_flags & STREAM_TOSERVER) {
1647 static inline void RuleMatchCandidateMergeStateRules(
1665 uint32_t j = *array_idx;
1677 uint32_t k = *array_idx;
1699 if (s->
iid <= s0->
id) {
1748 static inline void DetectFwEnsureLteCoverage(
1767 DetectFwEnsureLteCoverage(det_ctx, fw_state);
1768 for (uint32_t i = 0; i < array_idx; i++) {
1778 if (
flags == NULL) {
1779 if (!DetectRunInspectRuleHeader(
p,
f, s, s->
flags)) {
1787 if (
flags != NULL &&
1831 return covered > (counted ? 1 : 0);
1847 !DetectRunInspectRuleHeader(
p,
f, s, s->
flags)) {
1850 for (uint32_t k = 0; k < can_idx; k++) {
1855 DetectFwEnsureLteCoverage(det_ctx, fw_state);
1909 const uint8_t progress)
1911 const uint8_t dir_flags = direction & (STREAM_TOSERVER | STREAM_TOCLIENT);
1926 if (
likely(ap != NULL)) {
1932 SCLogDebug(
"dropping packet PKT_DROP_REASON_FW_DEFAULT_APP_POLICY");
1939 DetectRunAppendDefaultAppPolicyAlert(det_ctx,
p,
true, tx, ap);
1947 const bool last_hook =
progress == tx->tx_progress;
1948 bool apply_to_packet =
false;
1953 apply_to_packet =
true;
1957 apply_to_packet = tx->is_last;
1960 apply_to_packet = tx->is_last && last_hook;
1967 SCLogDebug(
"packet %" PRIu64
" hook %u default policy ACCEPT, apply_to_packet:%s",
1972 DetectRunAppendDefaultAppPolicyAlert(det_ctx,
p, apply_to_packet, tx, ap);
1973 }
else if (apply_to_packet) {
1975 DetectRunAppendDefaultAccept(det_ctx,
p);
1999 const uint8_t start_hook,
const uint8_t end_hook)
2003 const bool need_verdict =
2005 SCLogDebug(
"need_verdict:%s is_last:%s end_hook:%u tx->tx_end_state:%u tx->progress: %u",
2009 for (uint8_t hook = start_hook; hook <= end_hook; hook++) {
2010 const bool apply_to_packet =
2013 SCLogDebug(
"%" PRIu64
": %s default policy for hook %u, apply_to_packet %s",
2018 det_ctx, policies, tx,
p, alproto, direction, hook);
2019 SCLogDebug(
"fw: hook:%u policy:%02x apply_to_packet:%s", hook, policy.
action,
2039 if (apply_to_packet) {
2054 SCLogDebug(
"default accept: last tx and progress at end_hook %u", end_hook);
2055 DetectRunAppendDefaultAccept(det_ctx,
p);
2077 const Signature *s,
const uint32_t can_idx,
const bool lte_counted,
2095 SCLogDebug(
"default accept due to flow accept");
2096 DetectRunAppendDefaultAccept(det_ctx,
p);
2107 const bool accept_tx_applies_to_packet = tx->
is_last;
2108 if (accept_tx_applies_to_packet) {
2109 SCLogDebug(
"accept:tx: should be applied to the packet");
2110 DetectRunAppendDefaultAccept(det_ctx,
p);
2114 SCLogDebug(
"APP_LAYER_TX_ACCEPT, so skip rule");
2129 SCLogDebug(
"check if prior hooks are satisfied: s->app_progress_hook %u, "
2130 "tx->detect_progress_orig %u",
2133 if (DetectFwOtherLteCoversHook(det_ctx, fw_state, s, lte_counted)) {
2134 SCLogDebug(
"later LTE in-progress rule brought us here: us:%u covered:%u",
2142 SCLogDebug(
"missing fw rules at list start: sid %u, progress %u (%u:%u)", s->
id,
2182 if (can_idx + 1 < can_size) {
2188 if (DetectFwOtherLteCoversHook(det_ctx, fw_state, s, lte_counted)) {
2189 SCLogDebug(
"we have another LTE in-progress. Us:%u covered:%u",
2192 SCLogDebug(
"peek: next sid progress %u != current progress %u, so current "
2193 "is last for progress",
2198 SCLogDebug(
"peek: missing progress, so we'll drop that unless we get a "
2199 "sweeping accept first");
2205 SCLogDebug(
"peek: next sid not a fw rule, so current is last for progress");
2210 SCLogDebug(
"peek: no peek beyond last rule");
2211 if (!DetectFwOtherLteCoversHook(det_ctx, fw_state, s, lte_counted)) {
2213 SCLogDebug(
"peek: there are no rules to allow the state after this rule");
2305 SCLogDebug(
"fw fw_skip_app_filter:%s skip_fw_hook:%s "
2306 "skip_before_progress:%u fw_last_for_progress:%s fw_next_progress_missing:%s",
2333 SCLogDebug(
"accept:tx applied, skip_fw_hook, skip_before_progress %u",
2338 SCLogDebug(
"sid %u: ACTION_ACCEPT with ACTION_SCOPE_FLOW", s->
id);
2359 if (rule_cnt == 0) {
2362 DetectRunAppendDefaultAccept(det_ctx,
p);
2369 DetectRunAppendDefaultAccept(det_ctx,
p);
2386 alproto, flow_flags & (STREAM_TOSERVER | STREAM_TOCLIENT),
2410 const uint8_t flow_flags)
2419 const bool fw_accept_to_packet = ApplyAcceptToPacket(tx, s);
2420 if (fw_accept_to_packet) {
2422 SCLogDebug(
"accept:(tx|hook): should be applied to the packet");
2428 DetectRunTxFirewallApplyAccept(det_ctx,
p, flow_flags, s, tx, fw_state);
2430 SCLogDebug(
"drop packet because of rule with drop action");
2433 SCLogDebug(
"drop flow because of rule with drop action");
2455 static int DetectRunTxFirewallRulePartialMatch(
2462 SCLogDebug(
"need to apply accept to packet");
2463 DetectRunAppendDefaultAccept(det_ctx,
p);
2466 SCLogDebug(
"only applying accept:flow on full match, downgrading to "
2487 const uint8_t flow_flags)
2540 Packet *
p,
const uint8_t flow_flags)
2546 const bool fw_accept_to_packet = ApplyAcceptToPacket(tx, s);
2547 DetectRunTxFirewallApplyAccept(det_ctx,
p, flow_flags, s, tx, fw_state);
2548 if (fw_accept_to_packet) {
2550 DetectRunAppendDefaultAccept(det_ctx,
p);
2562 const uint8_t flow_flags = scratch->
flow_flags;
2565 const uint8_t ipproto =
f->
proto;
2573 uint32_t tx_inspected = 0;
2577 bool last_tx_skipped =
false;
2584 if (ires.
tx_ptr == NULL) {
2585 SCLogDebug(
"%p/%" PRIu64
" no transaction to inspect", ires.
tx_ptr, tx_id_min);
2591 SCLogDebug(
"%p/%"PRIu64
" no transaction to inspect",
2598 tx_id_min = tx.
tx_id + 1;
2608 bool do_sort =
false;
2609 bool fw_lte_candidates =
false;
2610 uint32_t array_idx = 0;
2620 SCLogDebug(
"%p/%"PRIu64
" rules added from prefilter: %u candidates",
2624 if (!(RuleMatchCandidateTxArrayHasSpace(det_ctx, total_rules))) {
2625 RuleMatchCandidateTxArrayExpand(det_ctx, total_rules);
2638 fw_lte_candidates =
true;
2644 if (!(RuleMatchCandidateTxArrayHasSpace(det_ctx, total_rules))) {
2645 RuleMatchCandidateTxArrayExpand(det_ctx, total_rules);
2651 uint32_t x = array_idx;
2653 RuleMatchCandidateMergeStateRules(det_ctx, &array_idx, &fw_lte_candidates);
2657 const uint32_t old = array_idx;
2662 if (have_new_file) {
2663 SCLogDebug(
"%p/%"PRIu64
" destate: need to consider new file",
2670 for (; tx_store != NULL; tx_store = tx_store->
next) {
2676 store_cnt++, state_cnt++)
2695 fw_lte_candidates =
true;
2700 do_sort |= (array_idx > old);
2706 DetectRunTxSortHelper);
2715 for (uint32_t i = 0; i < array_idx; i++) {
2726 if (have_fw_rules && fw_lte_candidates) {
2727 DetectFwBuildLteCoverage(det_ctx,
p,
f, &fw_state, array_idx);
2730 SCLogDebug(
"%s: tx_progress %u tx %p have_fw_rules %s array_idx %u detect_progress_orig %u "
2731 "cur detect_progress %u",
2732 flow_flags & STREAM_TOSERVER ?
"toserver" :
"toclient", tx.
tx_progress,
2736 if (have_fw_rules) {
2739 const int r = DetectTxFirewallNoRulesApplyPolicies(
2740 det_ctx,
p,
f, &tx, alproto, flow_flags, array_idx);
2744 }
else if (r == 2) {
2750 for (uint32_t i = 0; i < array_idx; i++) {
2756 flow_flags & STREAM_TOSERVER ?
"toserver" :
"toclient", tx.
tx_progress,
2759 if (have_fw_rules) {
2761 det_ctx,
p, &tx, flow_flags & (STREAM_TOSERVER | STREAM_TOCLIENT), s, i,
2763 SCLogDebug(
"fw fw_skip_app_filter:%s skip_fw_hook:%s "
2764 "skip_before_progress:%u fw_last_for_progress:%s "
2765 "fw_next_progress_missing:%s",
2784 while ((i + 1) < array_idx &&
2786 SCLogDebug(
"%p/%" PRIu64
" inspecting SKIP NEXT: sid %u (%u), flags %08x",
2792 s->
id, s->
iid, inspect_flags ? *inspect_flags : 0);
2794 if (inspect_flags) {
2797 " inspecting: sid %u (%u), flags %08x DE_STATE_FLAG_FULL_INSPECT",
2802 if (have_fw_rules) {
2803 DetectRunTxFirewallRuleStatefulReApplyMatch(
2804 det_ctx, s, &tx, &fw_state,
p, flow_flags);
2810 " inspecting: sid %u (%u), flags %08x DE_STATE_FLAG_SIG_CANT_MATCH",
2822 if (have_fw_rules) {
2826 SCLogDebug(
"fw fw_skip_app_filter:%s skip_fw_hook:%s "
2827 "skip_before_progress:%u fw_last_for_progress:%s "
2828 "fw_next_progress_missing:%s",
2840 const int r = DetectRunTxInspectRule(
tv,
de_ctx, det_ctx,
p,
f, flow_flags,
2841 alstate, &tx, s, inspect_flags, can, scratch);
2845 DetectFwRetireLteRule(det_ctx, can);
2849 DetectRunPostMatch(
tv, det_ctx,
p, s);
2857 DetectRunTxFirewallRuleFullMatch(det_ctx, s, &tx, &fw_state,
f,
p, flow_flags);
2859 }
else if (r == 0) {
2861 if (DetectRunTxFirewallRulePartialMatch(det_ctx, s, &tx,
p) == 1) {
2864 }
else if (r == -1) {
2866 DetectRunTxFirewallRuleNoMatch(det_ctx, s, &tx, &fw_state,
p, flow_flags) ==
2872 DetectVarProcessList(det_ctx,
p->
flow,
p);
2881 uint32_t prev_array_idx = array_idx;
2885 if (!(RuleMatchCandidateTxArrayHasSpace(det_ctx, needed))) {
2886 RuleMatchCandidateTxArrayExpand(det_ctx, needed);
2891 if (
ts->app_inspect != NULL) {
2902 if (have_fw_rules) {
2903 DetectFwCountAppendedLteRule(det_ctx,
p,
f, &fw_state,
ts, array_idx);
2907 SCLogDebug(
"%p/%" PRIu64
" rule %u (%u) added from 'post match' prefilter",
2911 SCLogDebug(
"%p/%" PRIu64
" rules added from 'post match' prefilter: %u", tx.
tx_ptr,
2912 tx.
tx_id, array_idx - prev_array_idx);
2913 if (prev_array_idx != array_idx) {
2916 DetectRunTxSortHelper);
2932 flow_flags & STREAM_TOSERVER ?
"toserver" :
"toclient");
2933 const uint8_t inspected_flag = (flow_flags & STREAM_TOSERVER)
2937 SCLogDebug(
"%p/%" PRIu64
" tx is done for direction %s. Progress %02x", tx.
tx_ptr,
2938 tx.
tx_id, flow_flags & STREAM_TOSERVER ?
"toserver" :
"toclient",
2960 if (have_fw_rules) {
2961 if (tx_inspected == 0) {
2963 SCLogDebug(
"default accept: no app inspect performed");
2964 DetectRunAppendDefaultAccept(det_ctx,
p);
2965 }
else if (last_tx_skipped) {
2969 SCLogDebug(
"default accept: last tx skipped");
2970 DetectRunAppendDefaultAccept(det_ctx,
p);
2986 SCLogDebug(
"pcap_cnt %" PRIu64
": %s: skip frame inspection for TCP w/o APP UPDATE",
2991 if (frames_container == NULL) {
2996 frames = &frames_container->
toserver;
2998 frames = &frames_container->
toclient;
3001 for (uint32_t idx = 0; idx < frames->
cnt; idx++) {
3004 if (frame == NULL) {
3009 uint32_t array_idx = 0;
3017 SCLogDebug(
"%p/%" PRIi64
" rules added from prefilter: %u candidates", frame, frame->
id,
3022 if (!(RuleMatchCandidateTxArrayHasSpace(
3023 det_ctx, total_rules))) {
3024 RuleMatchCandidateTxArrayExpand(det_ctx, total_rules);
3041 uint32_t x = array_idx;
3054 SCLogDebug(
"%p/%" PRIi64
" rule %u (%u) added from 'match' list", frame, frame->
id,
3058 SCLogDebug(
"%p/%" PRIi64
" rules added from 'match' list: %u", frame, frame->
id,
3063 for (uint32_t i = 0; i < array_idx; i++) {
3070 while ((i + 1) < array_idx &&
3074 SCLogDebug(
"%p/%" PRIi64
" inspecting: sid %u (%u)", frame, frame->
id, s->
id, s->
iid);
3077 SCLogDebug(
"%p/%" PRIi64
" Start sid %u", frame, frame->
id, s->
id);
3081 bool r = DetectRunInspectRuleHeader(
p,
f, s, s->
flags);
3086 DetectRunPostMatch(
tv, det_ctx,
p, s);
3089 "%p/%" PRIi64
" sig %u (%u) matched", frame, frame->
id, s->
id, s->
iid);
3090 const uint8_t alert_flags =
3093 const uint8_t ipproto =
p->
proto;
3094 uint8_t sub_state = 0;
3107 DetectVarProcessList(det_ctx,
p->
flow,
p);
3118 "frame->inspect_progress: %" PRIu64
" -> not updated", frame->
inspect_progress);
3121 SCLogDebug(
"%p/%" PRIi64
" rules inspected, running cleanup", frame, frame->
id);
3169 SCLogDebug(
"p->pcap %" PRIu64
": no detection on packet, "
3170 "PKT_NOPACKET_INSPECTION is set",
3228 if (det_ctx == NULL) {
3229 printf(
"ERROR: Detect has no thread ctx\n");
3235 SCLogDebug(
"Detect Engine using new det_ctx - %p",
3246 if (tenant_id > 0 && tenant_id < det_ctx->mt_det_ctxs_cnt) {
3249 if (det_ctx == NULL)
3257 SCLogDebug(
"MT de_ctx %p det_ctx %p (tenant %u)",
de_ctx, det_ctx, tenant_id);
3273 #ifdef PROFILE_RULES
3276 gettimeofday(&
ts, NULL);
3277 if (
ts.tv_sec != det_ctx->rule_perf_last_sync) {
3278 SCProfilingRuleThreatAggregate(det_ctx);
3279 det_ctx->rule_perf_last_sync =
ts.tv_sec;
3293 DetectPostInspectFileFlagsUpdate(
f, NULL , STREAM_TOSERVER);
3294 DetectPostInspectFileFlagsUpdate(
f, NULL , STREAM_TOCLIENT);
3297 #if defined(UNITTESTS) || defined(FUZZ)