suricata
suricata-common.h
Go to the documentation of this file.
1 /* Copyright (C) 2007-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * Common includes, etc.
24  */
25 
26 #ifndef SURICATA_SURICATA_COMMON_H
27 #define SURICATA_SURICATA_COMMON_H
28 
29 #ifdef __cplusplus
30 extern "C"
31 {
32 #endif
33 
34 #ifdef DEBUG
35 #define DBG_PERF
36 #endif
37 
38 #ifndef _GNU_SOURCE
39 #define _GNU_SOURCE
40 #endif
41 
42 #define __USE_GNU
43 
44 #if defined(__clang_analyzer__)
45 /* clang analyzer acts as DEBUG_VALIDATION in some places, so
46  * force this so #ifdef DEBUG_VALIDATION code gets included */
47 #define DEBUG_VALIDATION 1
48 
49  /* function prototype to be used to filter taints. To be used
50  * through the DEBUG_VALIDATE_MARK_SANITIZED macro. The scan-build
51  * taint config will then consider this in the taint analysis. */
52  void ScanBuildMarkSanitized(const void *);
53 #endif
54 
55 #if CPPCHECK == 1
56 #define __has_feature(x) 0
57 #endif
58 #if defined(__has_feature)
59 #if __has_feature(address_sanitizer)
60 #define SC_ADDRESS_SANITIZER 1
61 #endif
62 #elif defined(__SANITIZE_ADDRESS__)
63 #define SC_ADDRESS_SANITIZER 1
64 #endif
65 
66 #include "autoconf.h"
67 
68 #ifndef REVISION
69 #define REVISION "undefined"
70 #endif
71 #ifndef __SCFILENAME__
72 #define __SCFILENAME__ "undefined"
73 #endif
74 
75 #ifndef CLS
76 #warning "L1 cache line size not detected during build. Assuming 64 bytes."
77 #define CLS 64
78 #endif
79 
80 #if HAVE_DIRENT_H
81 #include <dirent.h>
82 #endif
83 
84 #if HAVE_STDIO_H
85 #include <stdio.h>
86 #endif
87 
88 #if HAVE_STDDEF_H
89 #include <stddef.h>
90 #endif
91 
92 #if HAVE_STDINT_h
93 #include <stdint.h>
94 #endif
95 
96 #if HAVE_STDBOOL_H
97 #include <stdbool.h>
98 #endif
99 
100 #if HAVE_STDARG_H
101 #include <stdarg.h>
102 #endif
103 
104 #ifdef HAVE_STDLIB_H
105 #include <stdlib.h>
106 #endif
107 
108 #if HAVE_ERRNO_H
109 #include <errno.h>
110 #endif
111 
112 #if HAVE_UNISTD_H
113 #include <unistd.h>
114 #endif
115 
116 #if HAVE_INTTYPES_H
117 #include <inttypes.h>
118 #endif
119 
120 #if HAVE_LIMITS_H
121 #include <limits.h>
122 #endif
123 
124 #if HAVE_CTYPE_H
125 #include <ctype.h>
126 #endif
127 
128 #if HAVE_MEMMOVE_S
129 #ifndef __STDC_WANT_LIB_EXT1__
130 #define __STDC_WANT_LIB_EXT1__ 1
131 #endif
132 #endif
133 
134 #if HAVE_STRING_H
135 #include <string.h>
136 #endif
137 
138 #if HAVE_STRINGS_H
139 #include <strings.h>
140 #endif
141 
142 #if HAVE_FCNTL_H
143 #include <fcntl.h>
144 #endif
145 
146 #ifdef HAVE_TIME_H
147 #include <time.h>
148 #endif
149 
150 #if HAVE_SYS_SYSCALL_H
151 #include <sys/syscall.h>
152 #endif
153 
154 #if HAVE_SYSCALL_H
155 #include <syscall.h>
156 #endif
157 
158 #if HAVE_SYS_TYPES_H
159 #include <sys/types.h> /* for gettid(2) */
160 #endif
161 
162 #if HAVE_SCHED_H
163 #include <sched.h> /* for sched_setaffinity(2) */
164 #endif
165 
166 #ifdef HAVE_TYPE_U_LONG_NOT_DEFINED
167 typedef unsigned long int u_long;
168 #endif
169 #ifdef HAVE_TYPE_U_INT_NOT_DEFINED
170 typedef unsigned int u_int;
171 #endif
172 #ifdef HAVE_TYPE_U_SHORT_NOT_DEFINED
173 typedef unsigned short u_short;
174 #endif
175 #ifdef HAVE_TYPE_U_CHAR_NOT_DEFINED
176 typedef unsigned char u_char;
177 #endif
178 
179 #include <pcre2.h>
180 
181 #ifdef HAVE_SYSLOG_H
182 #include <syslog.h>
183 #else
184 #ifdef OS_WIN32
185 #include "win32-syslog.h"
186 #endif /* OS_WIN32 */
187 #endif /* HAVE_SYSLOG_H */
188 
189 #ifdef OS_WIN32
190 #include "win32-misc.h"
191 #include "win32-service.h"
192 #endif /* OS_WIN32 */
193 
194 #if HAVE_SYS_TIME_H
195 #include <sys/time.h>
196 #endif
197 
198 #if HAVE_POLL_H
199 #include <poll.h>
200 #endif
201 
202 #if HAVE_SYS_SIGNAL_H
203 #include <sys/signal.h>
204 #endif
205 
206 #if HAVE_SIGNAL_H
207 #include <signal.h>
208 #endif
209 
210 #if HAVE_SYS_SOCKET_H
211 #include <sys/socket.h>
212 #endif
213 
214 #if HAVE_SYS_STAT_H
215 #include <sys/stat.h>
216 #endif
217 
218 #if HAVE_SYS_IOCTL_H
219 #include <sys/ioctl.h>
220 #endif
221 
222 #if HAVE_SYS_MMAN_H
223 #include <sys/mman.h>
224 #endif
225 
226 #if HAVE_SYS_RANDOM_H
227 #include <sys/random.h>
228 #endif
229 
230 #if HAVE_NETINET_IN_H
231 #include <netinet/in.h>
232 #endif
233 
234 #if HAVE_ARPA_INET_H
235 #include <arpa/inet.h>
236 #endif
237 
238 #if HAVE_NETDB_H
239 #include <netdb.h>
240 #endif
241 
242 #if HAVE_MALLOC_H
243 #include <malloc.h>
244 #endif
245 
246 #if __CYGWIN__
247 #if !defined _X86_ && !defined __x86_64
248 #define _X86_
249 #endif
250 #endif
251 
252 #if !__CYGWIN__
253 #ifdef HAVE_WINSOCK2_H
254 #include <winsock2.h>
255 #endif
256 #ifdef HAVE_WS2TCPIP_H
257 #include <ws2tcpip.h>
258 #endif
259 #endif /* !__CYGWIN__ */
260 
261 #ifdef HAVE_WINDOWS_H
262 #ifndef _WIN32_WINNT
263 #define _WIN32_WINNT 0x0501
264 #endif
265 #include <windows.h>
266 #endif
267 
268 #ifdef HAVE_W32API_WINBASE_H
269 #include <w32api/winbase.h>
270 #endif
271 
272 #ifdef HAVE_W32API_WTYPES_H
273 #include <w32api/wtypes.h>
274 #endif
275 
276 #ifndef SC_PCAP_DONT_INCLUDE_PCAP_H
277 #ifdef HAVE_PCAP_H
278 #include <pcap.h>
279 #endif
280 
281 #ifdef HAVE_PCAP_PCAP_H
282 #include <pcap/pcap.h>
283 #endif
284 #endif
285 
286 #ifdef HAVE_UTIME_H
287 #include <utime.h>
288 #endif
289 
290 #ifdef HAVE_LIBGEN_H
291 #include <libgen.h>
292 #endif
293 
294 #ifdef HAVE_GRP_H
295 #include <grp.h>
296 #endif
297 
298 #ifdef HAVE_PWD_H
299 #include <pwd.h>
300 #endif
301 
302 #include <jansson.h>
303 #ifndef JSON_ESCAPE_SLASH
304 #define JSON_ESCAPE_SLASH 0
305 #endif
306 
307 #ifdef HAVE_MAGIC
308 #include <magic.h>
309 #endif
310 
311 #ifdef HAVE_MATH_H
312 #include <math.h>
313 #endif
314 
315 #ifdef HAVE_MM_MALLOC_H
316 #include <mm_malloc.h>
317 #endif
318 
319 /* we need this to stringify the defines which are supplied at compiletime see:
320  http://gcc.gnu.org/onlinedocs/gcc-3.4.1/cpp/Stringification.html#Stringification */
321 #define xstr(s) str(s)
322 #define str(s) #s
323 
324 #if CPPCHECK==1
325  #define BUG_ON(x) if (((x))) exit(1)
326 #else
327  #if defined HAVE_ASSERT_H && !defined NDEBUG
328  #include <assert.h>
329  #define BUG_ON(x) assert(!(x))
330  #else
331  #define BUG_ON(x) do { \
332  if (((x))) { \
333  fprintf(stderr, "BUG at %s:%d(%s)\n", __FILE__, __LINE__, __func__); \
334  fprintf(stderr, "Code: '%s'\n", xstr((x))); \
335  exit(EXIT_FAILURE); \
336  } \
337  } while(0)
338  #endif
339 #endif
340 
341 /** type for the internal signature id. Since it's used in the matching engine
342  * extensively keeping this as small as possible reduces the overall memory
343  * footprint of the engine. Set to uint32_t if the engine needs to support
344  * more than 64k sigs. */
345 //#define SigIntId uint16_t
346 #define SigIntId uint32_t
347 
348 /** same for pattern id's */
349 #define PatIntId uint32_t
350 
351 /** FreeBSD does not define __WORDSIZE, but it uses __LONG_BIT */
352 #ifndef __WORDSIZE
353  #ifdef __LONG_BIT
354  #define __WORDSIZE __LONG_BIT
355  #else
356  #ifdef LONG_BIT
357  #define __WORDSIZE LONG_BIT
358  #endif
359  #endif
360 #endif
361 
362 /** Windows does not define __WORDSIZE, but it uses __X86__ */
363 #ifndef __WORDSIZE
364  #if defined(__X86__) || defined(_X86_) || defined(_M_IX86)
365  #define __WORDSIZE 32
366  #else
367  #if defined(__X86_64__) || defined(_X86_64_) || \
368  defined(__x86_64) || defined(__x86_64__) || \
369  defined(__amd64) || defined(__amd64__)
370  #define __WORDSIZE 64
371  #endif
372  #endif
373 #endif
374 
375 /** if not succesful yet try the data models */
376 #ifndef __WORDSIZE
377  #if defined(_ILP32) || defined(__ILP32__)
378  #define __WORDSIZE 32
379  #endif
380  #if defined(_LP64) || defined(__LP64__)
381  #define __WORDSIZE 64
382  #endif
383 #endif
384 
385 #ifndef __WORDSIZE
386  #warning Defaulting to __WORDSIZE 32
387  #define __WORDSIZE 32
388 #endif
389 
390 /** darwin doesn't defined __BYTE_ORDER and friends, but BYTE_ORDER */
391 #ifndef __BYTE_ORDER
392  #if defined(BYTE_ORDER)
393  #define __BYTE_ORDER BYTE_ORDER
394  #elif defined(__BYTE_ORDER__)
395  #define __BYTE_ORDER __BYTE_ORDER__
396  #else
397  #error "byte order not detected"
398  #endif
399 #endif
400 
401 #ifndef __LITTLE_ENDIAN
402  #if defined(LITTLE_ENDIAN)
403  #define __LITTLE_ENDIAN LITTLE_ENDIAN
404  #elif defined(__ORDER_LITTLE_ENDIAN__)
405  #define __LITTLE_ENDIAN __ORDER_LITTLE_ENDIAN__
406  #endif
407 #endif
408 
409 #ifndef __BIG_ENDIAN
410  #if defined(BIG_ENDIAN)
411  #define __BIG_ENDIAN BIG_ENDIAN
412  #elif defined(__ORDER_BIG_ENDIAN__)
413  #define __BIG_ENDIAN __ORDER_BIG_ENDIAN__
414  #endif
415 #endif
416 
417 #if !defined(__LITTLE_ENDIAN) && !defined(__BIG_ENDIAN)
418  #error "byte order: can't figure out big or little"
419 #endif
420 
421 #ifndef MIN
422 #define MIN(x, y) (((x)<(y))?(x):(y))
423 #endif
424 
425 #ifndef MAX
426 #define MAX(x, y) (((x)<(y))?(y):(x))
427 #endif
428 
429 #define BIT_U8(n) ((uint8_t)(1 << (n)))
430 #define BIT_U16(n) ((uint16_t)(1 << (n)))
431 #define BIT_U32(n) ((uint32_t)(1UL << (n)))
432 #define BIT_U64(n) (1ULL << (n))
433 
434 #define WARN_UNUSED __attribute__((warn_unused_result))
435 
436 #if defined(__MINGW32__)
437 #define ATTR_FMT_PRINTF(x, y) __attribute__((format(__MINGW_PRINTF_FORMAT, (x), (y))))
438 #elif defined(__GNUC__)
439 #define ATTR_FMT_PRINTF(x, y) __attribute__((format(printf, (x), (y))))
440 #else
441 #define ATTR_FMT_PRINTF(x, y)
442 #endif
443 
444 #define SCNtohl(x) (uint32_t)ntohl((x))
445 #define SCNtohs(x) (uint16_t)ntohs((x))
446 
447 /* swap flags if one of them is set, otherwise do nothing. */
448 #define SWAP_FLAGS(flags, a, b) \
449  do { \
450  if (((flags) & ((a)|(b))) == (a)) { \
451  (flags) &= ~(a); \
452  (flags) |= (b); \
453  } else if (((flags) & ((a)|(b))) == (b)) { \
454  (flags) &= ~(b); \
455  (flags) |= (a); \
456  } \
457  } while(0)
458 
459 #define SWAP_VARS(type, a, b) \
460  do { \
461  type t = (a); \
462  (a) = (b); \
463  (b) = t; \
464  } while (0)
465 
466 #include <ctype.h>
467 #define u8_tolower(c) ((uint8_t)tolower((uint8_t)(c)))
468 #define u8_toupper(c) ((uint8_t)toupper((uint8_t)(c)))
469 
486 
489 
490 /** \note update PacketProfileLoggerIdToString if you change anything here */
491 typedef enum LoggerId {
493 
494  /* TX loggers first for low logger IDs */
501 
502  /** \warning Note that transaction loggers here with a value > 31
503  will not work. */
504 
505  /* non-tx loggers below */
506 
525 
526  /* An ID that can be used by loggers registered by plugins and/or
527  * library users. */
529 
530  /* Must come last. */
533 
534 /* If we don't have Lua, create a typedef for lua_State so the
535  * exported Lua functions don't fail the build. */
536 typedef struct lua_State lua_State;
537 
538 #include "tm-threads-common.h"
539 #include "util-optimize.h"
540 #include "util-time.h"
541 #include "util-mem.h"
542 #include "util-memcmp.h"
543 #include "util-atomic.h"
544 #include "util-unittest.h"
545 
546 // pseudo system headers
547 #include "queue.h"
548 #include "tree.h"
549 
550 #ifndef HAVE_STRLCAT
551 size_t strlcat(char *, const char *src, size_t siz);
552 #endif
553 #ifndef HAVE_STRLCPY
554 size_t strlcpy(char *dst, const char *src, size_t siz);
555 #endif
556 #ifndef HAVE_STRPTIME
557 char *strptime(const char * __restrict, const char * __restrict, struct tm * __restrict);
558 #endif
559 
560 #ifndef HAVE_FWRITE_UNLOCKED
561 #define SCFwriteUnlocked fwrite
562 #define SCFflushUnlocked fflush
563 #define SCClearErrUnlocked clearerr
564 #define SCFerrorUnlocked ferror
565 #else
566 #define SCFwriteUnlocked fwrite_unlocked
567 #define SCFflushUnlocked fflush_unlocked
568 #define SCClearErrUnlocked clearerr_unlocked
569 #define SCFerrorUnlocked ferror_unlocked
570 #endif
571 extern int coverage_unittests;
572 extern int g_ut_modules;
573 extern int g_ut_covered;
574 
575 #define ARRAY_SIZE(arr) (sizeof(arr) / sizeof(arr[0]))
576 
577 #ifdef __cplusplus
578 }
579 #endif
580 
581 #endif /* SURICATA_SURICATA_COMMON_H */
win32-misc.h
PROF_DETECT_GETSGH
@ PROF_DETECT_GETSGH
Definition: suricata-common.h:472
PacketProfileDetectId_
PacketProfileDetectId_
Definition: suricata-common.h:470
g_ut_modules
int g_ut_modules
Definition: suricata.c:993
LOGGER_USER
@ LOGGER_USER
Definition: suricata-common.h:528
PROF_DETECT_PF_PAYLOAD
@ PROF_DETECT_PF_PAYLOAD
Definition: suricata-common.h:477
LOGGER_ALERT_SYSLOG
@ LOGGER_ALERT_SYSLOG
Definition: suricata-common.h:509
LOGGER_FILEDATA
@ LOGGER_FILEDATA
Definition: suricata-common.h:500
LOGGER_JSON_STATS
@ LOGGER_JSON_STATS
Definition: suricata-common.h:519
LOGGER_JSON_ALERT
@ LOGGER_JSON_ALERT
Definition: suricata-common.h:510
LOGGER_JSON_ARP
@ LOGGER_JSON_ARP
Definition: suricata-common.h:524
PROF_DETECT_ALERT
@ PROF_DETECT_ALERT
Definition: suricata-common.h:483
LoggerId
LoggerId
Definition: suricata-common.h:491
PROF_DETECT_SIZE
@ PROF_DETECT_SIZE
Definition: suricata-common.h:487
g_ut_covered
int g_ut_covered
Definition: suricata.c:994
PROF_DETECT_PF_TX
@ PROF_DETECT_PF_TX
Definition: suricata-common.h:478
PROF_DETECT_CLEANUP
@ PROF_DETECT_CLEANUP
Definition: suricata-common.h:485
tm-threads-common.h
LOGGER_STATS
@ LOGGER_STATS
Definition: suricata-common.h:518
util-unittest.h
PROF_DETECT_PF_SORT2
@ PROF_DETECT_PF_SORT2
Definition: suricata-common.h:481
strlcpy
size_t strlcpy(char *dst, const char *src, size_t siz)
Definition: util-strlcpyu.c:43
PROF_DETECT_PF_SORT1
@ PROF_DETECT_PF_SORT1
Definition: suricata-common.h:480
lua_State
struct lua_State lua_State
Definition: suricata-common.h:536
util-memcmp.h
PROF_DETECT_TX_UPDATE
@ PROF_DETECT_TX_UPDATE
Definition: suricata-common.h:484
LOGGER_JSON_FLOW
@ LOGGER_JSON_FLOW
Definition: suricata-common.h:516
LOGGER_TCP_DATA
@ LOGGER_TCP_DATA
Definition: suricata-common.h:515
strptime
char * strptime(const char *__restrict, const char *__restrict, struct tm *__restrict)
Definition: util-strptime.c:97
strlcat
size_t strlcat(char *, const char *src, size_t siz)
Definition: util-strlcatu.c:45
LOGGER_JSON_FILE
@ LOGGER_JSON_FILE
Definition: suricata-common.h:514
PacketProfileDetectId
enum PacketProfileDetectId_ PacketProfileDetectId
PROF_DETECT_PF_PKT
@ PROF_DETECT_PF_PKT
Definition: suricata-common.h:476
LOGGER_UNDEFINED
@ LOGGER_UNDEFINED
Definition: suricata-common.h:492
util-atomic.h
util-time.h
LOGGER_TLS
@ LOGGER_TLS
Definition: suricata-common.h:497
LOGGER_SIZE
@ LOGGER_SIZE
Definition: suricata-common.h:531
LOGGER_JSON_NETFLOW
@ LOGGER_JSON_NETFLOW
Definition: suricata-common.h:517
PROF_DETECT_IPONLY
@ PROF_DETECT_IPONLY
Definition: suricata-common.h:473
queue.h
win32-syslog.h
tree.h
util-mem.h
LOGGER_PCAP
@ LOGGER_PCAP
Definition: suricata-common.h:520
LOGGER_JSON_METADATA
@ LOGGER_JSON_METADATA
Definition: suricata-common.h:521
PROF_DETECT_PF_RECORD
@ PROF_DETECT_PF_RECORD
Definition: suricata-common.h:479
LOGGER_JSON_DROP
@ LOGGER_JSON_DROP
Definition: suricata-common.h:512
PROF_DETECT_SETUP
@ PROF_DETECT_SETUP
Definition: suricata-common.h:471
LOGGER_ALERT_DEBUG
@ LOGGER_ALERT_DEBUG
Definition: suricata-common.h:507
util-optimize.h
win32-service.h
LOGGER_FILE
@ LOGGER_FILE
Definition: suricata-common.h:499
PROF_DETECT_RULES
@ PROF_DETECT_RULES
Definition: suricata-common.h:474
LOGGER_JSON_TX
@ LOGGER_JSON_TX
Definition: suricata-common.h:498
PROF_DETECT_NONMPMLIST
@ PROF_DETECT_NONMPMLIST
Definition: suricata-common.h:482
src
uint16_t src
Definition: app-layer-dnp3.h:5
LOGGER_FILE_STORE
@ LOGGER_FILE_STORE
Definition: suricata-common.h:513
LOGGER_TLS_STORE_CLIENT
@ LOGGER_TLS_STORE_CLIENT
Definition: suricata-common.h:496
LOGGER_JSON_FRAME
@ LOGGER_JSON_FRAME
Definition: suricata-common.h:522
PROF_DETECT_TX
@ PROF_DETECT_TX
Definition: suricata-common.h:475
LOGGER_TLS_STORE
@ LOGGER_TLS_STORE
Definition: suricata-common.h:495
coverage_unittests
int coverage_unittests
Definition: suricata.c:992
dst
uint16_t dst
Definition: app-layer-dnp3.h:4
LOGGER_JSON_STREAM
@ LOGGER_JSON_STREAM
Definition: suricata-common.h:523
LOGGER_ALERT_FAST
@ LOGGER_ALERT_FAST
Definition: suricata-common.h:508
LOGGER_JSON_ANOMALY
@ LOGGER_JSON_ANOMALY
Definition: suricata-common.h:511