suricata
suricata-plugin.h
Go to the documentation of this file.
1 /* Copyright (C) 2020-2021 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 #ifndef __SURICATA_PLUGIN_H__
19 #define __SURICATA_PLUGIN_H__
20 
21 #include "autoconf.h"
22 
23 #include <stdint.h>
24 #include <stdbool.h>
25 
26 #include "conf.h"
27 
28 /**
29  * The size of the data chunk inside each packet structure a plugin
30  * has for private data (Packet->plugin_v).
31  */
32 #define PLUGIN_VAR_SIZE 64
33 
34 /**
35  * Structure to define a Suricata plugin.
36  */
37 typedef struct SCPlugin_ {
38  const char *name;
39  const char *license;
40  const char *author;
41  void (*Init)(void);
43 
44 /**
45  * Structure used to define a file type plugin.
46  *
47  * Currently only used by the Eve output type.
48  *
49  * name -- The plugin name. This name is used to identify the plugin: eve-log.filetype and in the
50  * plugins: section
51  */
52 typedef struct SCPluginFileType_ {
53  char *name;
54  /* Init Called on first access */
55  int (*Init)(ConfNode *conf, bool threaded, void **init_data);
56  /* Write - Called on each write to the object */
57  int (*Write)(const char *buffer, int buffer_len, void *init_data, void *thread_data);
58  /* Close - Called on final close */
59  void (*Deinit)(void *init_data);
60  /* ThreadInit - Called for each thread using file object*/
61  int (*ThreadInit)(void *init_data, int thread_id, void **thread_data);
62  /* ThreadDeinit - Called for each thread using file object */
63  int (*ThreadDeinit)(void *init_data, void *thread_data);
66 
68 
69 typedef struct SCCapturePlugin_ {
70  char *name;
71  void (*Init)(const char *args, int plugin_slot, int receive_slot, int decode_slot);
72  int (*ThreadInit)(void *ctx, int thread_id, void **thread_ctx);
73  int (*ThreadDeinit)(void *ctx, void *thread_ctx);
74  const char *(*GetDefaultMode)(void);
77 
79 
80 #endif /* __SURICATA_PLUGIN_H */
SCPluginRegisterCapture
int SCPluginRegisterCapture(SCCapturePlugin *)
SCPluginFileType
struct SCPluginFileType_ SCPluginFileType
SCPluginFileType_::Deinit
void(* Deinit)(void *init_data)
Definition: suricata-plugin.h:59
SCCapturePlugin_::Init
void(* Init)(const char *args, int plugin_slot, int receive_slot, int decode_slot)
Definition: suricata-plugin.h:71
SCCapturePlugin_::ThreadInit
int(* ThreadInit)(void *ctx, int thread_id, void **thread_ctx)
Definition: suricata-plugin.h:72
SCPluginFileType_::Init
int(* Init)(ConfNode *conf, bool threaded, void **init_data)
Definition: suricata-plugin.h:55
SCCapturePlugin_::name
char * name
Definition: suricata-plugin.h:70
SCCapturePlugin_
Definition: suricata-plugin.h:69
SCPluginFileType_::ThreadDeinit
int(* ThreadDeinit)(void *init_data, void *thread_data)
Definition: suricata-plugin.h:63
SCPlugin_::license
const char * license
Definition: suricata-plugin.h:39
SCCapturePlugin_::TAILQ_ENTRY
TAILQ_ENTRY(SCCapturePlugin_) entries
SCPlugin_::author
const char * author
Definition: suricata-plugin.h:40
SCPlugin_
Definition: suricata-plugin.h:37
SCPluginFileType_::Write
int(* Write)(const char *buffer, int buffer_len, void *init_data, void *thread_data)
Definition: suricata-plugin.h:57
conf.h
SCPluginFileType_::name
char * name
Definition: suricata-plugin.h:53
SCCapturePlugin
struct SCCapturePlugin_ SCCapturePlugin
SCPlugin_::Init
void(* Init)(void)
Definition: suricata-plugin.h:41
SCPluginFileType_
Definition: suricata-plugin.h:52
ConfNode_
Definition: conf.h:32
SCPlugin
struct SCPlugin_ SCPlugin
SCPluginFileType_::TAILQ_ENTRY
TAILQ_ENTRY(SCPluginFileType_) entries
SCPluginRegisterFileType
bool SCPluginRegisterFileType(SCPluginFileType *)
SCPlugin_::name
const char * name
Definition: suricata-plugin.h:38
SCPluginFileType_::ThreadInit
int(* ThreadInit)(void *init_data, int thread_id, void **thread_data)
Definition: suricata-plugin.h:61
SCCapturePlugin_::ThreadDeinit
int(* ThreadDeinit)(void *ctx, void *thread_ctx)
Definition: suricata-plugin.h:73