Go to the documentation of this file.
74 static inline int FlowHashRawAddressIPv6GtU32(
const uint32_t *a,
const uint32_t *b)
76 for (uint8_t i = 0; i < 4; i++) {
97 const uint32_t
u32[6];
119 if (PacketIsIPv4(p)) {
124 int ai = (p->
src.addr_data32[0] > p->
dst.addr_data32[0]);
125 fhk.
addrs[1 - ai] = p->
src.addr_data32[0];
126 fhk.
addrs[ai] = p->
dst.addr_data32[0];
128 fhk.
ports[0] = 0xfedc;
129 fhk.
ports[1] = 0xba98;
140 }
else if (PacketIsIPv6(p)) {
144 if (FlowHashRawAddressIPv6GtU32(p->
src.addr_data32, p->
dst.addr_data32)) {
145 fhk.
src[0] = p->
src.addr_data32[0];
146 fhk.
src[1] = p->
src.addr_data32[1];
147 fhk.
src[2] = p->
src.addr_data32[2];
148 fhk.
src[3] = p->
src.addr_data32[3];
149 fhk.
dst[0] = p->
dst.addr_data32[0];
150 fhk.
dst[1] = p->
dst.addr_data32[1];
151 fhk.
dst[2] = p->
dst.addr_data32[2];
152 fhk.
dst[3] = p->
dst.addr_data32[3];
154 fhk.
src[0] = p->
dst.addr_data32[0];
155 fhk.
src[1] = p->
dst.addr_data32[1];
156 fhk.
src[2] = p->
dst.addr_data32[2];
157 fhk.
src[3] = p->
dst.addr_data32[3];
158 fhk.
dst[0] = p->
src.addr_data32[0];
159 fhk.
dst[1] = p->
src.addr_data32[1];
160 fhk.
dst[2] = p->
src.addr_data32[2];
161 fhk.
dst[3] = p->
src.addr_data32[3];
164 fhk.
ports[0] = 0xfedc;
165 fhk.
ports[1] = 0xba98;
190 static inline uint32_t FlowGetHash(
const Packet *p)
194 if (PacketIsIPv4(p)) {
195 if (PacketIsTCP(p) || PacketIsUDP(p)) {
198 int ai = (p->
src.addr_data32[0] > p->
dst.addr_data32[0]);
199 fhk.
addrs[1-ai] = p->
src.addr_data32[0];
200 fhk.
addrs[ai] = p->
dst.addr_data32[0];
202 const int pi = (p->
sp > p->
dp);
225 const int ai = (psrc > pdst);
226 fhk.
addrs[1-ai] = psrc;
227 fhk.
addrs[ai] = pdst;
245 const int ai = (p->
src.addr_data32[0] > p->
dst.addr_data32[0]);
246 fhk.
addrs[1-ai] = p->
src.addr_data32[0];
247 fhk.
addrs[ai] = p->
dst.addr_data32[0];
248 fhk.
ports[0] = 0xfeed;
249 fhk.
ports[1] = 0xbeef;
260 }
else if (PacketIsIPv6(p)) {
262 if (FlowHashRawAddressIPv6GtU32(p->
src.addr_data32, p->
dst.addr_data32)) {
263 fhk.
src[0] = p->
src.addr_data32[0];
264 fhk.
src[1] = p->
src.addr_data32[1];
265 fhk.
src[2] = p->
src.addr_data32[2];
266 fhk.
src[3] = p->
src.addr_data32[3];
267 fhk.
dst[0] = p->
dst.addr_data32[0];
268 fhk.
dst[1] = p->
dst.addr_data32[1];
269 fhk.
dst[2] = p->
dst.addr_data32[2];
270 fhk.
dst[3] = p->
dst.addr_data32[3];
272 fhk.
src[0] = p->
dst.addr_data32[0];
273 fhk.
src[1] = p->
dst.addr_data32[1];
274 fhk.
src[2] = p->
dst.addr_data32[2];
275 fhk.
src[3] = p->
dst.addr_data32[3];
276 fhk.
dst[0] = p->
src.addr_data32[0];
277 fhk.
dst[1] = p->
src.addr_data32[1];
278 fhk.
dst[2] = p->
src.addr_data32[2];
279 fhk.
dst[3] = p->
src.addr_data32[3];
282 const int pi = (p->
sp > p->
dp);
319 const int pi = (fk->
sp > fk->
dp);
356 const int pi = (fk->
sp > fk->
dp);
371 static inline bool CmpAddrs(
const uint32_t addr1[4],
const uint32_t addr2[4])
373 return addr1[0] == addr2[0] && addr1[1] == addr2[1] &&
374 addr1[2] == addr2[2] && addr1[3] == addr2[3];
377 static inline bool CmpAddrsAndPorts(
const uint32_t src1[4],
378 const uint32_t dst1[4],
Port src_port1,
Port dst_port1,
379 const uint32_t src2[4],
const uint32_t dst2[4],
Port src_port2,
385 return (CmpAddrs(src1, src2) && CmpAddrs(dst1, dst2) &&
386 src_port1 == src_port2 && dst_port1 == dst_port2) ||
387 (CmpAddrs(src1, dst2) && CmpAddrs(dst1, src2) &&
388 src_port1 == dst_port2 && dst_port1 == src_port2);
391 static inline bool CmpVlanIds(
394 return ((vlan_id1[0] ^ vlan_id2[0]) &
g_vlan_mask) == 0 &&
395 ((vlan_id1[1] ^ vlan_id2[1]) &
g_vlan_mask) == 0 &&
399 static inline bool CmpLiveDevIds(
const LiveDevice *livedev,
const uint16_t
id)
401 uint16_t devid = livedev ? livedev->
id : 0;
407 static inline bool CmpFlowPacket(
const Flow *f,
const Packet *p)
413 return CmpAddrsAndPorts(f_src, f_dst, f->
sp, f->
dp, p_src, p_dst, p->
sp, p->
dp) &&
418 static inline bool CmpFlowKey(
const Flow *f,
const FlowKey *k)
424 return CmpAddrsAndPorts(f_src, f_dst, f->
sp, f->
dp, k_src, k_dst, k->
sp, k->
dp) &&
429 static inline bool CmpAddrsAndICMPTypes(
const uint32_t src1[4],
430 const uint32_t dst1[4], uint8_t icmp_s_type1, uint8_t icmp_d_type1,
431 const uint32_t src2[4],
const uint32_t dst2[4], uint8_t icmp_s_type2,
432 uint8_t icmp_d_type2)
437 return (CmpAddrs(src1, src2) && CmpAddrs(dst1, dst2) &&
438 icmp_s_type1 == icmp_s_type2 && icmp_d_type1 == icmp_d_type2) ||
439 (CmpAddrs(src1, dst2) && CmpAddrs(dst1, src2) &&
440 icmp_s_type1 == icmp_d_type2 && icmp_d_type1 == icmp_s_type2);
443 static inline bool CmpFlowICMPPacket(
const Flow *f,
const Packet *p)
449 return CmpAddrsAndICMPTypes(f_src, f_dst, f->
icmp_s.type, f->
icmp_d.type, p_src, p_dst,
465 static inline int FlowCompareICMPv4(
Flow *f,
const Packet *p)
493 return CmpFlowICMPPacket(f, p);
508 static inline int FlowCompareESP(
Flow *f,
const Packet *p)
515 return CmpAddrs(f_src, p_src) && CmpAddrs(f_dst, p_dst) && f->
proto == p->
proto &&
527 static inline int FlowCompare(
Flow *f,
const Packet *p)
529 if (p->
proto == IPPROTO_ICMP) {
530 return FlowCompareICMPv4(f, p);
531 }
else if (PacketIsESP(p)) {
532 return FlowCompareESP(f, p);
534 return CmpFlowPacket(f, p);
548 static inline bool FlowCreateCheck(
const Packet *p,
const bool emerg)
553 if (PacketIsTCP(p)) {
554 const TCPHdr *tcph = PacketGetTCP(p);
564 if (PacketIsICMPv4(p)) {
606 const Packet *p,
const bool emerg)
609 bool spare_sync =
false;
626 if (
tv && fls->
dtv) {
645 static void FlowExceptionPolicyStatsIncr(
681 if (g_eps_flow_memcap != UINT64_MAX && g_eps_flow_memcap == p->
pcap_cnt) {
682 NoFlowHandleIPS(
tv, fls, p);
687 if (!FlowCreateCheck(p, emerg)) {
694 f = FlowSpareSync(
tv, fls, p, emerg);
706 f = FlowGetUsedFlow(
tv, fls->
dtv, p->
ts);
708 NoFlowHandleIPS(
tv, fls, p);
710 if (
tv != NULL && fls->
dtv != NULL) {
719 if (
tv != NULL && fls->
dtv != NULL) {
734 if (
tv != NULL && fls->
dtv != NULL) {
740 NoFlowHandleIPS(
tv, fls, p);
757 const uint32_t hash,
Packet *p)
760 if (
tv != NULL && fls->
dtv != NULL) {
774 Flow *f = FlowGetNew(
tv, fls, p);
807 FlowBucket *fb,
Flow *f,
Flow *prev_f)
819 if (f->
proto != IPPROTO_TCP || FlowBelongsToUs(
tv, f)) {
826 f->
next = fb->evicted;
834 static inline bool FlowIsTimedOut(
const Flow *f,
const uint32_t sec,
const bool emerg)
843 if ((int64_t)sec >= timeout_at)
875 SCLogDebug(
"fb %p fb->head %p", fb, fb->head);
878 if (fb->head == NULL) {
879 f = FlowGetNew(
tv, fls, p);
894 FlowReference(dest, f);
901 const uint32_t fb_nextts = !emerg ?
SC_ATOMIC_GET(fb->next_ts) : 0;
907 const bool timedout = (fb_nextts < (uint32_t)
SCTIME_SECS(p->
ts) &&
912 MoveToWorkQueue(
tv, fls, fb, f, prev_f);
915 }
else if (FlowCompare(f, p) != 0) {
919 Flow *new_f = TcpReuseReplace(
tv, fls, fb, f, hash, p);
922 MoveToWorkQueue(
tv, fls, fb, f, prev_f);
931 FlowReference(dest, f);
941 if (next_f == NULL) {
942 f = FlowGetNew(
tv, fls, p);
958 FlowReference(dest, f);
975 static inline bool FlowCompareKey(
Flow *f,
FlowKey *key)
977 if ((f->
proto != IPPROTO_TCP) && (f->
proto != IPPROTO_UDP))
979 return CmpFlowKey(f, key);
993 uint32_t hash = flow_id & 0x0000FFFF;
996 SCLogDebug(
"fb %p fb->head %p", fb, fb->head);
998 for (
Flow *f = fb->head; f != NULL; f = f->
next) {
999 if (FlowGetId(f) == flow_id) {
1020 static Flow *FlowGetExistingFlowFromHash(
FlowKey *key,
const uint32_t hash)
1025 SCLogDebug(
"fb %p fb->head %p", fb, fb->head);
1027 for (
Flow *f = fb->head; f != NULL; f = f->
next) {
1029 if (FlowCompareKey(f, key)) {
1057 Flow *f = FlowGetExistingFlowFromHash(key, hash);
1066 SCLogDebug(
"Can't get a spare flow at start");
1072 f->
src.addr_data32[0] = key->
src.addr_data32[0];
1073 f->
src.addr_data32[1] = key->
src.addr_data32[1];
1074 f->
src.addr_data32[2] = key->
src.addr_data32[2];
1075 f->
src.addr_data32[3] = key->
src.addr_data32[3];
1076 f->
dst.addr_data32[0] = key->
dst.addr_data32[0];
1077 f->
dst.addr_data32[1] = key->
dst.addr_data32[1];
1078 f->
dst.addr_data32[2] = key->
dst.addr_data32[2];
1079 f->
dst.addr_data32[3] = key->
dst.addr_data32[3];
1087 }
else if (key->
src.
family == AF_INET6) {
1106 #define FLOW_GET_NEW_TRIES 5
1110 static inline int GetUsedTryLockBucket(FlowBucket *fb)
1115 static inline int GetUsedTryLockFlow(
Flow *f)
1120 static inline uint32_t GetUsedAtomicUpdate(
const uint32_t val)
1157 #define STATSADDUI64(cnt, value) \
1159 StatsAddUI64(tv, dtv->cnt, (value)); \
1162 #define STATSADDUI64(cnt, value) \
1163 StatsAddUI64(tv, dtv->cnt, (value));
1199 if (GetUsedTryLockBucket(fb) != 0) {
1210 if (GetUsedTryLockFlow(f) != 0) {
1216 if (StillAlive(f,
ts)) {
#define ESP_GET_SPI(esph)
Get the spi field off a packet.
FlowQueuePrivate work_queue
TmEcode OutputFlowLog(ThreadVars *tv, void *thread_data, Flow *f)
Run flow logger(s)
uint16_t counter_flow_udp
void ExceptionPolicyApply(Packet *p, enum ExceptionPolicy policy, enum PacketDropReason drop_reason)
uint16_t counter_flow_active
#define ICMPV4_GET_EMB_PROTO(p)
void StatsIncr(ThreadVars *tv, uint16_t id)
Increments the local counter.
#define IPV4_GET_RAW_IPDST_U32(ip4h)
uint32_t hashword(const uint32_t *k, size_t length, uint32_t initval)
uint16_t counter_flow_icmp4
bool TcpSessionPacketSsnReuse(const Packet *p, const Flow *f, const void *tcp_ssn)
#define SC_ATOMIC_SET(name, val)
Set the value for the atomic variable.
@ PKT_DROP_REASON_FLOW_MEMCAP
uint32_t address_un_data32[4]
FlowQueuePrivate FlowSpareGetFromPool(void)
uint16_t counter_flow_spare_sync_avg
uint32_t FlowKeyGetHash(FlowKey *fk)
#define ICMPV4_DEST_UNREACH_IS_VALID(p)
uint16_t vlan_id[VLAN_MAX_LAYERS]
union Address_::@26 address
#define SC_ATOMIC_ADD(name, val)
add a value to our atomic variable
#define FLOWLOCK_TRYWRLOCK(fb)
struct FlowHashKey4_ FlowHashKey4
#define FBLOCK_TRYLOCK(fb)
struct Flow_::@116::@122 icmp_d
uint16_t counter_flow_tcp
struct Packet_::@29::@36 icmp_s
uint32_t address_un_data32[4]
struct Packet_::@31::@37 icmp_d
TcpStreamCnf stream_config
struct Flow_::@114::@120 icmp_s
uint16_t counter_flow_get_used
#define FLOWLOCK_UNLOCK(fb)
uint16_t counter_flow_spare_sync_empty
uint16_t counter_flow_tcp_reuse
uint16_t counter_flow_total
void FlowWakeupFlowManagerThread(void)
#define FLOW_CHECK_MEMCAP(size)
check if a memory alloc would fit in the memcap
uint32_t emerg_spare_sync_stamp
uint16_t counter_flow_spare_sync
struct Flow_::@114::@121 esp
#define STREAM_PKT_FLAG_TCP_PORT_REUSE
#define FLOW_GET_NEW_TRIES
#define STATSADDUI64(cnt, value)
#define SCTIME_FROM_TIMESPEC(ts)
#define FLOWLOCK_WRLOCK(fb)
SC_ATOMIC_EXTERN(unsigned int, flow_prune_idx)
uint16_t eps_id[EXCEPTION_POLICY_MAX]
Per thread variable structure.
unsigned int FlowStorageSize(void)
struct FlowHashKey6_ FlowHashKey6
Flow * FlowQueuePrivateGetFromTop(FlowQueuePrivate *fqc)
void FlowTimeoutsEmergency(void)
uint8_t FlowGetProtoMapping(uint8_t proto)
Function to map the protocol to the defined FLOW_PROTO_* enumeration.
Flow * FlowGetExistingFlowFromFlowId(int64_t flow_id)
Look for existing Flow using a flow id value.
#define FLOW_END_FLAG_EMERGENCY
#define FBLOCK_UNLOCK(fb)
struct LiveDevice_ * livedev
int FlowClearMemory(Flow *f, uint8_t proto_map)
Function clear the flow memory before queueing it to spare flow queue.
FlowProtoTimeout flow_timeouts_delta[FLOW_PROTO_MAX]
Data structures and function prototypes for keeping state for the detection engine.
int RunmodeIsUnittests(void)
void FlowUpdateState(Flow *f, const enum FlowState s)
FlowQueuePrivate spare_queue
uint32_t FlowGetIpPairProtoHash(const Packet *p)
uint16_t counter_flow_spare_sync_incomplete
#define IPV4_GET_RAW_IPSRC_U32(ip4h)
uint16_t counter_flow_icmp6
ExceptionPolicyCounters counter_flow_memcap_eps
Flow * FlowGetFlowFromHash(ThreadVars *tv, FlowLookupStruct *fls, Packet *p, Flow **dest)
Get Flow for packet.
struct LiveDevice_ * livedev
enum ExceptionPolicy memcap_policy
void StatsAddUI64(ThreadVars *tv, uint16_t id, uint64_t x)
Adds a value of type uint64_t to the local counter.
Structure to hold thread specific data for all decode modules.
Flow * FlowGetFromFlowKey(FlowKey *key, struct timespec *ttime, const uint32_t hash)
Get or create a Flow using a FlowKey.
void * output_flow_thread_data
uint16_t vlan_id[VLAN_MAX_LAYERS]
#define STREAM_PKT_FLAG_SET(p, f)
uint16_t vlan_id[VLAN_MAX_LAYERS]
uint16_t counter_flow_memcap
#define FLOW_END_FLAG_TIMEOUT
uint16_t vlan_id[VLAN_MAX_LAYERS]
#define SC_ATOMIC_GET(name)
Get the value from the atomic variable.
uint16_t vlan_id[VLAN_MAX_LAYERS]
void FlowQueuePrivateAppendFlow(FlowQueuePrivate *fqc, Flow *f)
Flow * FlowAlloc(void)
allocate a flow
#define FLOW_END_FLAG_FORCED
#define ICMPV4_IS_ERROR_MSG(type)
void FlowInit(Flow *f, const Packet *p)
void FlowSetupPacket(Packet *p)
prepare packet for a life with flow Set PKT_WANTS_FLOW flag to indicate workers should do a flow look...
union FlowAddress_::@113 address
union PacketL4::L4Vars vars
FlowThreadId thread_id[2]
#define SC_ATOMIC_OR(name, val)
Bitwise OR a value to our atomic variable.