suricata
suricata-plugin.h
Go to the documentation of this file.
1 /* Copyright (C) 2020-2021 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 #ifndef __SURICATA_PLUGIN_H__
19 #define __SURICATA_PLUGIN_H__
20 
21 #include <stdint.h>
22 #include <stdbool.h>
23 
24 #include "conf.h"
25 
26 /**
27  * The size of the data chunk inside each packet structure a plugin
28  * has for private data (Packet->plugin_v).
29  */
30 #define PLUGIN_VAR_SIZE 64
31 
32 /**
33  * Structure to define a Suricata plugin.
34  */
35 typedef struct SCPlugin_ {
36  const char *name;
37  const char *license;
38  const char *author;
39  void (*Init)(void);
41 
42 /**
43  * Structure used to define a file type plugin.
44  *
45  * Currently only used by the Eve output type.
46  *
47  * name -- The plugin name. This name is used to identify the plugin: eve-log.filetype and in the
48  * plugins: section
49  */
50 typedef struct SCPluginFileType_ {
51  char *name;
52  /* Init Called on first access */
53  int (*Init)(ConfNode *conf, bool threaded, void **init_data);
54  /* Write - Called on each write to the object */
55  int (*Write)(const char *buffer, int buffer_len, void *init_data, void *thread_data);
56  /* Close - Called on final close */
57  void (*Deinit)(void *init_data);
58  /* ThreadInit - Called for each thread using file object*/
59  int (*ThreadInit)(void *init_data, int thread_id, void **thread_data);
60  /* ThreadDeinit - Called for each thread using file object */
61  int (*ThreadDeinit)(void *init_data, void *thread_data);
64 
66 
67 typedef struct SCCapturePlugin_ {
68  char *name;
69  void (*Init)(const char *args, int plugin_slot, int receive_slot, int decode_slot);
70  int (*ThreadInit)(void *ctx, int thread_id, void **thread_ctx);
71  int (*ThreadDeinit)(void *ctx, void *thread_ctx);
72  const char *(*GetDefaultMode)(void);
75 
77 
78 #endif /* __SURICATA_PLUGIN_H */
SCPluginRegisterCapture
int SCPluginRegisterCapture(SCCapturePlugin *)
SCPluginFileType
struct SCPluginFileType_ SCPluginFileType
SCPluginFileType_::Deinit
void(* Deinit)(void *init_data)
Definition: suricata-plugin.h:57
SCCapturePlugin_::Init
void(* Init)(const char *args, int plugin_slot, int receive_slot, int decode_slot)
Definition: suricata-plugin.h:69
SCCapturePlugin_::ThreadInit
int(* ThreadInit)(void *ctx, int thread_id, void **thread_ctx)
Definition: suricata-plugin.h:70
SCPluginFileType_::Init
int(* Init)(ConfNode *conf, bool threaded, void **init_data)
Definition: suricata-plugin.h:53
SCCapturePlugin_::name
char * name
Definition: suricata-plugin.h:68
SCCapturePlugin_
Definition: suricata-plugin.h:67
SCPluginFileType_::ThreadDeinit
int(* ThreadDeinit)(void *init_data, void *thread_data)
Definition: suricata-plugin.h:61
SCPlugin_::license
const char * license
Definition: suricata-plugin.h:37
SCCapturePlugin_::TAILQ_ENTRY
TAILQ_ENTRY(SCCapturePlugin_) entries
SCPlugin_::author
const char * author
Definition: suricata-plugin.h:38
SCPlugin_
Definition: suricata-plugin.h:35
SCPluginFileType_::Write
int(* Write)(const char *buffer, int buffer_len, void *init_data, void *thread_data)
Definition: suricata-plugin.h:55
conf.h
SCPluginFileType_::name
char * name
Definition: suricata-plugin.h:51
SCCapturePlugin
struct SCCapturePlugin_ SCCapturePlugin
SCPlugin_::Init
void(* Init)(void)
Definition: suricata-plugin.h:39
SCPluginFileType_
Definition: suricata-plugin.h:50
ConfNode_
Definition: conf.h:32
SCPlugin
struct SCPlugin_ SCPlugin
SCPluginFileType_::TAILQ_ENTRY
TAILQ_ENTRY(SCPluginFileType_) entries
SCPluginRegisterFileType
bool SCPluginRegisterFileType(SCPluginFileType *)
SCPlugin_::name
const char * name
Definition: suricata-plugin.h:36
SCPluginFileType_::ThreadInit
int(* ThreadInit)(void *init_data, int thread_id, void **thread_data)
Definition: suricata-plugin.h:59
SCCapturePlugin_::ThreadDeinit
int(* ThreadDeinit)(void *ctx, void *thread_ctx)
Definition: suricata-plugin.h:71