Go to the documentation of this file.
34 #ifdef HAVE_SYS_RESOURCE_H
36 #include <sys/resource.h>
145 #ifdef SYSTEMD_NOTIFY
170 #define DEFAULT_MAX_PENDING_PACKETS 1024
173 #define VERBOSE_MAX (SC_LOG_DEBUG - SC_LOG_NOTICE)
198 #ifndef AFLFUZZ_NO_RANDOM
305 #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
306 static void SignalHandlerSigint(
int sig)
310 static void SignalHandlerSigterm(
int sig)
316 #define UNW_LOCAL_ONLY
317 #include <libunwind.h>
318 static void SignalHandlerUnexpected(
int sig_num, siginfo_t *info,
void *context)
323 signal(SIGABRT, SIG_DFL);
324 signal(SIGSEGV, SIG_DFL);
326 if ((r = unw_init_local(&cursor, (unw_context_t *)(context)) != 0)) {
327 SCLogError(
"unable to obtain stack trace: unw_init_local: %s", unw_strerror(r));
336 if (unw_is_signal_frame(&cursor) == 0) {
339 if (unw_get_proc_name(&cursor,
name,
sizeof(
name), &off) == UNW_ENOMEM) {
348 r = unw_step(&cursor);
358 kill(getpid(), sig_num);
360 #undef UNW_LOCAL_ONLY
370 static void SignalHandlerSigusr2(
int sig)
380 static void SignalHandlerSigHup(
int sig)
433 #ifdef HAVE_AF_PACKET
441 #ifdef BUILD_HYPERSCAN
462 static void OnNotifyRunning(
void)
464 #ifdef SYSTEMD_NOTIFY
490 static int SetBpfString(
int argc,
char *argv[])
492 char *bpf_filter = NULL;
493 uint32_t bpf_len = 0;
498 while(argv[tmpindex] != NULL) {
499 bpf_len+=strlen(argv[tmpindex]) + 1;
511 while(argv[tmpindex] != NULL) {
512 strlcat(bpf_filter, argv[tmpindex],bpf_len);
513 if(argv[tmpindex + 1] != NULL) {
514 strlcat(bpf_filter,
" ", bpf_len);
519 if(strlen(bpf_filter) > 0) {
531 static void SetBpfStringFromFile(
char *filename)
533 char *bpf_filter = NULL;
534 char *bpf_comment_tmp = NULL;
535 char *bpf_comment_start = NULL;
541 fp = fopen(filename,
"r");
543 SCLogError(
"Failed to open file %s", filename);
548 SCLogError(
"Failed to stat file %s", filename);
552 bpf_len = ((size_t)(st.st_size)) + 1;
556 SCLogError(
"Failed to allocate buffer for bpf filter in file %s", filename);
560 nm = fread(bpf_filter, 1, bpf_len - 1, fp);
561 if ((ferror(fp) != 0) || (nm != (bpf_len - 1))) {
562 SCLogError(
"Failed to read complete BPF file %s", filename);
568 bpf_filter[nm] =
'\0';
570 if(strlen(bpf_filter) > 0) {
572 bpf_comment_start = bpf_filter;
573 while((bpf_comment_tmp = strchr(bpf_comment_start,
'#')) != NULL) {
574 while((*bpf_comment_tmp !=
'\0') &&
575 (*bpf_comment_tmp !=
'\r') && (*bpf_comment_tmp !=
'\n'))
577 *bpf_comment_tmp++ =
' ';
579 bpf_comment_start = bpf_comment_tmp;
582 while((bpf_comment_tmp = strchr(bpf_filter,
'\r')) != NULL) {
583 *bpf_comment_tmp =
' ';
585 while((bpf_comment_tmp = strchr(bpf_filter,
'\n')) != NULL) {
586 *bpf_comment_tmp =
' ';
589 while (strlen(bpf_filter) > 0 &&
590 bpf_filter[strlen(bpf_filter)-1] ==
' ')
592 bpf_filter[strlen(bpf_filter)-1] =
'\0';
594 if (strlen(bpf_filter) > 0) {
604 static void PrintUsage(
const char *progname)
611 printf(
"USAGE: %s [OPTIONS] [BPF FILTER]\n\n", progname);
613 printf(
"\n General:\n");
614 printf(
"\t-v : be more verbose (use multiple times to "
615 "increase verbosity)\n");
616 printf(
"\t-c <path> : path to configuration file\n");
617 printf(
"\t-l <dir> : default log directory\n");
618 printf(
"\t--include <path> : additional configuration file\n");
619 printf(
"\t--set name=value : set a configuration value\n");
620 printf(
"\t--pidfile <file> : write pid to this file\n");
621 printf(
"\t-T : test configuration file (use with -c)\n");
622 printf(
"\t--init-errors-fatal : enable fatal failure on signature init "
625 printf(
"\t-D : run as daemon\n");
627 printf(
"\t--service-install : install as service\n");
628 printf(
"\t--service-remove : remove service\n");
629 printf(
"\t--service-change-params : change service startup parameters\n");
631 #ifdef HAVE_LIBCAP_NG
632 printf(
"\t--user <user> : run suricata as this user after init\n");
633 printf(
"\t--group <group> : run suricata as this group after init\n");
635 #ifdef BUILD_UNIX_SOCKET
636 printf(
"\t--unix-socket[=<file>] : use unix socket to control suricata work\n");
638 printf(
"\t--runmode <runmode_id> : specific runmode modification the engine should run. The argument\n"
639 "\t supplied should be the id for the runmode obtained by running\n"
640 "\t --list-runmodes\n");
642 printf(
"\n Capture and IPS:\n");
644 printf(
"\t-F <bpf filter file> : bpf filter file\n");
645 printf(
"\t-k [all|none] : force checksum check (all) or disabled it "
647 printf(
"\t-i <dev or ip> : run in pcap live mode\n");
648 printf(
"\t--pcap[=<dev>] : run in pcap mode, no value select interfaces "
649 "from suricata.yaml\n");
650 #ifdef HAVE_PCAP_SET_BUFF
651 printf(
"\t--pcap-buffer-size : size of the pcap buffer value from 0 - %i\n",INT_MAX);
654 printf(
"\t-q <qid[:qid]> : run in inline nfqueue mode (use colon to "
655 "specify a range of queues)\n");
658 printf(
"\t-d <divert port> : run in inline ipfw divert mode\n");
660 #ifdef HAVE_AF_PACKET
661 printf(
"\t--af-packet[=<dev>] : run in af-packet mode, no value select interfaces from suricata.yaml\n");
664 printf(
"\t--af-xdp[=<dev>] : run in af-xdp mode, no value select "
665 "interfaces from suricata.yaml\n");
668 printf(
"\t--netmap[=<dev>] : run in netmap mode, no value select interfaces from suricata.yaml\n");
671 printf(
"\t--pfring[=<dev>] : run in pfring mode, use interfaces from suricata.yaml\n");
672 printf(
"\t--pfring-int <dev> : run in pfring mode, use interface <dev>\n");
673 printf(
"\t--pfring-cluster-id <id> : pfring cluster id \n");
674 printf(
"\t--pfring-cluster-type <type> : pfring cluster type for PF_RING 4.1.2 and later cluster_round_robin|cluster_flow\n");
677 printf(
"\t--dpdk : run in dpdk mode, uses interfaces from "
681 printf(
"\t--dag <dagX:Y> : process ERF records from DAG interface X, stream Y\n");
684 printf(
"\t--windivert <filter> : run in inline WinDivert mode\n");
685 printf(
"\t--windivert-forward <filter> : run in inline WinDivert mode, as a gateway\n");
688 printf(
"\t--reject-dev <dev> : send reject packets from this interface\n");
691 printf(
"\n Capture Files:\n");
692 printf(
"\t-r <path> : run in pcap file/offline mode\n");
693 printf(
"\t--pcap-file-continuous : when running in pcap mode with a directory, "
694 "continue checking directory for pcaps until interrupted\n");
695 printf(
"\t--pcap-file-delete : when running in replay mode (-r with "
696 "directory or file), will delete pcap files that have been processed when done\n");
697 printf(
"\t--pcap-file-recursive : will descend into subdirectories when running "
698 "in replay mode (-r)\n");
699 printf(
"\t--pcap-file-buffer-size : set read buffer size (setvbuf)\n");
700 printf(
"\t--erf-in <path> : process an ERF file\n");
702 printf(
"\n Detection:\n");
703 printf(
"\t-s <path> : path to signature file loaded in addition to "
704 "suricata.yaml settings (optional)\n");
705 printf(
"\t-S <path> : path to signature file loaded exclusively "
707 printf(
"\t--disable-detection : disable detection engine\n");
708 printf(
"\t--engine-analysis : print reports on analysis of different "
709 "sections in the engine and exit.\n"
710 "\t Please have a look at the conf parameter "
711 "engine-analysis on what reports\n"
712 "\t can be printed\n");
714 printf(
"\n Firewall:\n");
715 printf(
"\t--firewall : enable firewall mode\n");
716 printf(
"\t--firewall-rules-exclusive=<path> : path to firewall rule file loaded "
719 printf(
"\n Info:\n");
720 printf(
"\t-V : display Suricata version\n");
721 printf(
"\t--list-keywords[=all|csv|<kword>] : list keywords implemented by the engine\n");
722 printf(
"\t--list-runmodes : list supported runmodes\n");
723 printf(
"\t--list-app-layer-protos : list supported app layer protocols\n");
724 printf(
"\t--list-rule-protos : list supported rule protocols\n");
725 printf(
"\t--list-app-layer-hooks : list supported app layer hooks for use in "
727 printf(
"\t--list-app-layer-frames : list supported app layer frames for use with "
728 "'frame' keyword\n");
729 printf(
"\t--dump-config : show the running configuration\n");
730 printf(
"\t--dump-features : display provided features\n");
731 printf(
"\t--build-info : display build information\n");
733 printf(
"\n Testing:\n");
734 printf(
"\t--simulate-ips : force engine into IPS mode. Useful for QA\n");
736 printf(
"\t-u : run the unittests and exit\n");
737 printf(
"\t-U=REGEX, --unittest-filter=REGEX : filter unittests with a pcre compatible "
739 printf(
"\t--list-unittests : list unit tests\n");
740 printf(
"\t--fatal-unittests : enable fatal failure on unittest error\n");
741 printf(
"\t--unittests-coverage : display unittest coverage report\n");
744 printf(
"\nTo run " PROG_NAME " with default configuration on "
745 "interface eth0 with signature file \"signatures.rules\", run the "
746 "command as:\n\n%s -c suricata.yaml -s signatures.rules -i eth0 \n\n",
750 static void PrintBuildInfo(
void)
754 char features[2048] =
"";
759 strlcat(features,
"DEBUG ",
sizeof(features));
761 #ifdef DEBUG_VALIDATION
762 strlcat(features,
"DEBUG_VALIDATION ",
sizeof(features));
765 strlcat(features,
"UNITTESTS ",
sizeof(features));
768 strlcat(features,
"NFQ ",
sizeof(features));
771 strlcat(features,
"IPFW ",
sizeof(features));
773 #ifdef HAVE_PCAP_SET_BUFF
774 strlcat(features,
"PCAP_SET_BUFF ",
sizeof(features));
777 strlcat(features,
"PF_RING ",
sizeof(features));
780 strlcat(features,
"NAPATECH ",
sizeof(features));
782 #ifdef HAVE_AF_PACKET
783 strlcat(features,
"AF_PACKET ",
sizeof(features));
786 strlcat(features,
"NETMAP ",
sizeof(features));
788 #ifdef HAVE_PACKET_FANOUT
789 strlcat(features,
"HAVE_PACKET_FANOUT ",
sizeof(features));
792 strlcat(features,
"DAG ",
sizeof(features));
794 #ifdef HAVE_LIBCAP_NG
795 strlcat(features,
"LIBCAP_NG ",
sizeof(features));
798 strlcat(features,
"LIBNET1.1 ",
sizeof(features));
800 strlcat(features,
"HAVE_HTP_URI_NORMALIZE_HOOK ",
sizeof(features));
801 #ifdef PCRE2_HAVE_JIT
802 strlcat(features,
"PCRE_JIT ",
sizeof(features));
805 strlcat(features,
"HAVE_NSS ",
sizeof(features));
807 strlcat(features,
"HTTP2_DECOMPRESSION ",
sizeof(features));
809 strlcat(features,
"HAVE_LUA ",
sizeof(features));
811 strlcat(features,
"HAVE_JA3 ",
sizeof(features));
814 strlcat(features,
"HAVE_JA4 ",
sizeof(features));
816 strlcat(features,
"HAVE_LIBJANSSON ",
sizeof(features));
818 strlcat(features,
"PROFILING ",
sizeof(features));
820 #ifdef PROFILE_LOCKING
821 strlcat(features,
"PROFILE_LOCKING ",
sizeof(features));
823 #ifdef BUILD_UNIX_SOCKET
824 strlcat(features,
"UNIX_SOCKET ",
sizeof(features));
826 #if defined(TLS_C11) || defined(TLS_GNU)
827 strlcat(features,
"TLS ",
sizeof(features));
830 strlcat(features,
"TLS_C11 ",
sizeof(features));
831 #elif defined(TLS_GNU)
832 strlcat(features,
"TLS_GNU ",
sizeof(features));
835 strlcat(features,
"MAGIC ",
sizeof(features));
837 strlcat(features,
"RUST ",
sizeof(features));
838 #if defined(SC_ADDRESS_SANITIZER)
839 strlcat(features,
"ASAN ",
sizeof(features));
841 #if defined(HAVE_POPCNT64)
842 strlcat(features,
"POPCNT64 ",
sizeof(features));
844 if (strlen(features) == 0) {
845 strlcat(features,
"none",
sizeof(features));
848 printf(
"Features: %s\n", features);
851 memset(features, 0x00,
sizeof(features));
852 #if defined(__SSE4_2__)
853 strlcat(features,
"SSE_4_2 ",
sizeof(features));
855 #if defined(__SSE4_1__)
856 strlcat(features,
"SSE_4_1 ",
sizeof(features));
858 #if defined(__SSE3__)
859 strlcat(features,
"SSE_3 ",
sizeof(features));
861 #if defined(__SSE2__)
862 strlcat(features,
"SSE_2 ",
sizeof(features));
864 if (strlen(features) == 0) {
865 strlcat(features,
"none",
sizeof(features));
867 printf(
"SIMD support: %s\n", features);
870 memset(features, 0x00,
sizeof(features));
871 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_1)
872 strlcat(features,
"1 ",
sizeof(features));
874 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_2)
875 strlcat(features,
"2 ",
sizeof(features));
877 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_4)
878 strlcat(features,
"4 ",
sizeof(features));
880 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_8)
881 strlcat(features,
"8 ",
sizeof(features));
883 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_16)
884 strlcat(features,
"16 ",
sizeof(features));
886 if (strlen(features) == 0) {
887 strlcat(features,
"none",
sizeof(features));
889 strlcat(features,
"byte(s)",
sizeof(features));
891 printf(
"Atomic intrinsics: %s\n", features);
895 #elif __WORDSIZE == 32
898 bits =
"<unknown>-bits";
901 #if __BYTE_ORDER == __BIG_ENDIAN
902 endian =
"Big-endian";
903 #elif __BYTE_ORDER == __LITTLE_ENDIAN
904 endian =
"Little-endian";
906 endian =
"<unknown>-endian";
909 printf(
"%s, %s architecture\n", bits, endian);
911 printf(
"GCC version %s, C version %"PRIiMAX
"\n", __VERSION__, (intmax_t)__STDC_VERSION__);
913 printf(
"C version %"PRIiMAX
"\n", (intmax_t)__STDC_VERSION__);
917 printf(
"compiled with -fstack-protector\n");
920 printf(
"compiled with -fstack-protector-all\n");
929 #if _FORTIFY_SOURCE == 2
930 printf(
"compiled with _FORTIFY_SOURCE=2\n");
931 #elif _FORTIFY_SOURCE == 1
932 printf(
"compiled with _FORTIFY_SOURCE=1\n");
933 #elif _FORTIFY_SOURCE == 0
934 printf(
"compiled with _FORTIFY_SOURCE=0\n");
937 printf(
"L1 cache line size (CLS)=%d\n",
CLS);
940 tls =
"_Thread_local";
941 #elif defined(TLS_GNU)
944 #error "Unsupported thread local"
946 printf(
"thread local storage method: %s\n", tls);
948 printf(
"compiled with %s\n", htp_get_version());
950 #include "build-info.h"
1046 static TmEcode ParseInterfacesList(
const int runmode,
char *pcap_dev)
1052 if (strlen(pcap_dev) == 0) {
1055 SCLogError(
"No interface found in config for pcap");
1062 if (strlen(pcap_dev)) {
1064 SCLogError(
"Failed to set pfring.live-interface");
1071 char iface_selector[] =
"dpdk.interfaces";
1074 SCLogError(
"No interface found in config for %s", iface_selector);
1078 #ifdef HAVE_AF_PACKET
1081 if (strlen(pcap_dev)) {
1083 SCLogError(
"Failed to set af-packet.live-interface");
1089 SCLogError(
"No interface found in config for af-packet");
1097 if (strlen(pcap_dev)) {
1099 SCLogError(
"Failed to set af-xdp.live-interface");
1105 SCLogError(
"No interface found in config for af-xdp");
1113 if (strlen(pcap_dev)) {
1115 SCLogError(
"Failed to set netmap.live-interface");
1121 SCLogError(
"No interface found in config for netmap");
1130 SCLogError(
"No group found in config for nflog");
1139 static void SCInstanceInit(
SCInstance *suri,
const char *progname)
1141 memset(suri, 0x00,
sizeof(*suri));
1168 #if HAVE_DETECT_DISABLED==1
1178 if (strstr(prog_ver,
"RELEASE") != NULL) {
1198 if (strstr(
PROG_VER,
"-dev") == NULL) {
1209 static TmEcode PrintVersion(
void)
1217 const char *mode = suri->
system ?
"SYSTEM" :
"USER";
1218 SCLogNotice(
"This is %s version %s running in %s mode",
1229 static void SCPrintElapsedTime(
struct timeval *start_time)
1231 if (start_time == NULL)
1233 struct timeval end_time;
1234 memset(&end_time, 0,
sizeof(end_time));
1235 gettimeofday(&end_time, NULL);
1236 uint64_t milliseconds = ((end_time.tv_sec - start_time->tv_sec) * 1000) +
1237 (((1000000 + end_time.tv_usec - start_time->tv_usec) / 1000) - 1000);
1238 SCLogInfo(
"time elapsed %.3fs", (
float)milliseconds/(
float)1000);
1241 static int ParseCommandLineAfpacket(
SCInstance *suri,
const char *in_arg)
1243 #ifdef HAVE_AF_PACKET
1255 SCLogInfo(
"Multiple af-packet option without interface on each is useless");
1259 "has been specified");
1265 SCLogError(
"AF_PACKET not enabled. On Linux "
1266 "host, make sure to pass --enable-af-packet to "
1267 "configure when building.");
1272 static int ParseCommandLineAfxdp(
SCInstance *suri,
const char *in_arg)
1286 SCLogInfo(
"Multiple af-xdp options without interface on each is useless");
1290 "has been specified");
1297 "host, make sure correct libraries are installed,"
1298 " see documentation for information.");
1303 static int ParseCommandLineDpdk(
SCInstance *suri,
const char *in_arg)
1309 SCLogInfo(
"Multiple dpdk options have no effect on Suricata");
1312 "has been specified");
1319 "host, make sure to pass --enable-dpdk to "
1320 "configure when building.");
1325 static int ParseCommandLinePcapLive(
SCInstance *suri,
const char *in_arg)
1327 #if defined(OS_WIN32) && !defined(HAVE_LIBWPCAP)
1329 FatalError(
"Live capture not available. To support live capture compile against Npcap.");
1333 if (in_arg != NULL) {
1336 if (strlen(in_arg) > 9 && strncmp(in_arg,
"DeviceNPF", 9) == 0) {
1337 snprintf(suri->
pcap_dev,
sizeof(suri->
pcap_dev),
"\\Device\\NPF%s", in_arg+9);
1343 if (strcmp(suri->
pcap_dev, in_arg) != 0) {
1345 }
else if (strlen(suri->
pcap_dev) > 0 && isdigit((
unsigned char)suri->
pcap_dev[0])) {
1346 SCLogError(
"failed to find a pcap device for IP %s", in_arg);
1360 "has been specified");
1370 static bool IsLogDirectoryWritable(
const char*
str)
1372 if (access(
str, W_OK) == 0)
1384 int dump_config = 0;
1385 int dump_features = 0;
1386 int list_app_layer_protocols = 0;
1387 int list_rule_protocols = 0;
1388 int list_app_layer_hooks = 0;
1389 int list_app_layer_frames = 0;
1390 int list_unittests = 0;
1391 int list_runmodes = 0;
1392 int list_keywords = 0;
1397 int is_firewall = 0;
1406 struct option long_opts[] = {
1408 {
"dump-config", 0, &dump_config, 1},
1409 {
"dump-features", 0, &dump_features, 1},
1410 {
"pfring", optional_argument, 0, 0},
1411 {
"pfring-int", required_argument, 0, 0},
1412 {
"pfring-cluster-id", required_argument, 0, 0},
1413 {
"pfring-cluster-type", required_argument, 0, 0},
1417 {
"af-packet", optional_argument, 0, 0},
1418 {
"af-xdp", optional_argument, 0, 0},
1419 {
"netmap", optional_argument, 0, 0},
1420 {
"pcap", optional_argument, 0, 0},
1421 {
"pcap-file-continuous", 0, 0, 0},
1422 {
"pcap-file-delete", 0, 0, 0},
1423 {
"pcap-file-recursive", 0, 0, 0},
1424 {
"pcap-file-buffer-size", required_argument, 0, 0},
1425 {
"simulate-ips", 0, 0 , 0},
1427 {
"strict-rule-keywords", optional_argument, 0, 0},
1429 {
"capture-plugin", required_argument, 0, 0},
1430 {
"capture-plugin-args", required_argument, 0, 0},
1432 #ifdef BUILD_UNIX_SOCKET
1433 {
"unix-socket", optional_argument, 0, 0},
1435 {
"pcap-buffer-size", required_argument, 0, 0},
1436 {
"unittest-filter", required_argument, 0,
'U'},
1437 {
"list-app-layer-protos", 0, &list_app_layer_protocols, 1},
1438 {
"list-rule-protos", 0, &list_rule_protocols, 1},
1439 {
"list-app-layer-hooks", 0, &list_app_layer_hooks, 1},
1440 {
"list-app-layer-frames", 0, &list_app_layer_frames, 1},
1441 {
"list-unittests", 0, &list_unittests, 1},
1442 {
"list-runmodes", 0, &list_runmodes, 1},
1443 {
"list-keywords", optional_argument, &list_keywords, 1},
1444 {
"runmode", required_argument, NULL, 0},
1447 {
"service-install", 0, 0, 0},
1448 {
"service-remove", 0, 0, 0},
1449 {
"service-change-params", 0, 0, 0},
1451 {
"pidfile", required_argument, 0, 0},
1452 {
"init-errors-fatal", 0, 0, 0},
1453 {
"disable-detection", 0, 0, 0},
1454 {
"disable-hashing", 0, 0, 0},
1455 {
"fatal-unittests", 0, 0, 0},
1457 {
"user", required_argument, 0, 0},
1458 {
"group", required_argument, 0, 0},
1459 {
"erf-in", required_argument, 0, 0},
1460 {
"dag", required_argument, 0, 0},
1461 {
"build-info", 0, &build_info, 1},
1462 {
"data-dir", required_argument, 0, 0},
1464 {
"windivert", required_argument, 0, 0},
1465 {
"windivert-forward", required_argument, 0, 0},
1467 #ifdef HAVE_LIBNET11
1468 {
"reject-dev", required_argument, 0, 0},
1470 {
"set", required_argument, 0, 0},
1472 {
"nflog", optional_argument, 0, 0},
1474 {
"simulate-packet-flow-memcap", required_argument, 0, 0},
1475 {
"simulate-applayer-error-at-offset-ts", required_argument, 0, 0},
1476 {
"simulate-applayer-error-at-offset-tc", required_argument, 0, 0},
1477 {
"simulate-packet-loss", required_argument, 0, 0},
1478 {
"simulate-packet-tcp-reassembly-memcap", required_argument, 0, 0},
1479 {
"simulate-packet-tcp-ssn-memcap", required_argument, 0, 0},
1480 {
"simulate-packet-defrag-memcap", required_argument, 0, 0},
1481 {
"simulate-alert-queue-realloc-failure", 0, 0, 0},
1485 {
"firewall", 0, &is_firewall, 1 },
1486 {
"firewall-rules-exclusive", required_argument, 0, 0},
1488 {
"include", required_argument, 0, 0},
1495 int option_index = 0;
1497 char short_opts[] =
"c:TDhi:l:q:d:r:us:S:U:VF:vk:";
1499 while ((opt = getopt_long(argc, argv, short_opts, long_opts, &option_index)) != -1) {
1502 if (strcmp((long_opts[option_index]).
name,
"help") == 0) {
1505 }
else if (strcmp((long_opts[option_index]).
name,
"pfring") == 0 ||
1506 strcmp((long_opts[option_index]).
name,
"pfring-int") == 0) {
1511 if (optarg != NULL) {
1514 ((strlen(optarg) <
sizeof(suri->
pcap_dev)) ?
1515 (strlen(optarg) + 1) :
sizeof(suri->
pcap_dev)));
1520 "to pass --enable-pfring to configure when building.");
1523 }
else if (strcmp((long_opts[option_index]).
name,
"pfring-cluster-id") == 0) {
1526 SCLogError(
"failed to set pfring.cluster-id");
1531 "to pass --enable-pfring to configure when building.");
1534 }
else if (strcmp((long_opts[option_index]).
name,
"pfring-cluster-type") == 0) {
1537 SCLogError(
"failed to set pfring.cluster-type");
1542 "to pass --enable-pfring to configure when building.");
1545 }
else if (strcmp((long_opts[option_index]).
name,
"capture-plugin") == 0) {
1548 }
else if (strcmp((long_opts[option_index]).
name,
"capture-plugin-args") == 0) {
1550 }
else if (strcmp((long_opts[option_index]).
name,
"dpdk") == 0) {
1551 if (ParseCommandLineDpdk(suri, optarg) !=
TM_ECODE_OK) {
1554 }
else if (strcmp((long_opts[option_index]).
name,
"af-packet") == 0) {
1555 if (ParseCommandLineAfpacket(suri, optarg) !=
TM_ECODE_OK) {
1558 }
else if (strcmp((long_opts[option_index]).
name,
"af-xdp") == 0) {
1559 if (ParseCommandLineAfxdp(suri, optarg) !=
TM_ECODE_OK) {
1562 }
else if (strcmp((long_opts[option_index]).
name,
"netmap") == 0) {
1570 ((strlen(optarg) <
sizeof(suri->
pcap_dev)) ?
1571 (strlen(optarg) + 1) :
sizeof(suri->
pcap_dev)));
1577 SCLogInfo(
"Multiple netmap option without interface on each is useless");
1582 "has been specified");
1583 PrintUsage(argv[0]);
1590 }
else if (strcmp((long_opts[option_index]).
name,
"nflog") == 0) {
1600 }
else if (strcmp((long_opts[option_index]).
name,
"pcap") == 0) {
1601 if (ParseCommandLinePcapLive(suri, optarg) !=
TM_ECODE_OK) {
1604 }
else if (strcmp((long_opts[option_index]).
name,
"simulate-ips") == 0) {
1607 }
else if (strcmp((long_opts[option_index]).
name,
"init-errors-fatal") == 0) {
1609 SCLogError(
"failed to set engine init-failure-fatal");
1612 #ifdef BUILD_UNIX_SOCKET
1613 }
else if (strcmp((long_opts[option_index]).
name ,
"unix-socket") == 0) {
1618 SCLogError(
"failed to set unix-command.filename");
1624 "has been specified");
1625 PrintUsage(argv[0]);
1630 else if(strcmp((long_opts[option_index]).
name,
"list-app-layer-protocols") == 0) {
1632 }
else if (strcmp((long_opts[option_index]).
name,
"list-app-layer-hooks") == 0) {
1634 }
else if (strcmp((long_opts[option_index]).
name,
"list-unittests") == 0) {
1638 SCLogError(
"unit tests not enabled. Make sure to pass --enable-unittests to "
1639 "configure when building");
1642 }
else if (strcmp((long_opts[option_index]).
name,
"list-runmodes") == 0) {
1645 }
else if (strcmp((long_opts[option_index]).
name,
"list-keywords") == 0) {
1647 if (strcmp(
"short", optarg) != 0) {
1651 }
else if (strcmp((long_opts[option_index]).
name,
"runmode") == 0) {
1653 }
else if (strcmp((long_opts[option_index]).
name,
"engine-analysis") == 0) {
1657 else if (strcmp((long_opts[option_index]).
name,
"service-install") == 0) {
1658 suri->
run_mode = RUNMODE_INSTALL_SERVICE;
1660 }
else if (strcmp((long_opts[option_index]).
name,
"service-remove") == 0) {
1661 suri->
run_mode = RUNMODE_REMOVE_SERVICE;
1663 }
else if (strcmp((long_opts[option_index]).
name,
"service-change-params") == 0) {
1664 suri->
run_mode = RUNMODE_CHANGE_SERVICE_PARAMS;
1668 else if (strcmp((long_opts[option_index]).
name,
"pidfile") == 0) {
1671 SCLogError(
"strdup failed: %s", strerror(errno));
1674 }
else if (strcmp((long_opts[option_index]).
name,
"disable-detection") == 0) {
1676 }
else if (strcmp((long_opts[option_index]).
name,
"disable-hashing") == 0) {
1680 }
else if (strcmp((long_opts[option_index]).
name,
"fatal-unittests") == 0) {
1684 SCLogError(
"unit tests not enabled. Make sure to pass --enable-unittests to "
1685 "configure when building");
1688 }
else if (strcmp((long_opts[option_index]).
name,
"user") == 0) {
1689 #ifndef HAVE_LIBCAP_NG
1691 " drop privileges, but it was not compiled into Suricata.");
1697 }
else if (strcmp((long_opts[option_index]).
name,
"group") == 0) {
1698 #ifndef HAVE_LIBCAP_NG
1700 " drop privileges, but it was not compiled into Suricata.");
1706 }
else if (strcmp((long_opts[option_index]).
name,
"erf-in") == 0) {
1712 }
else if (strcmp((long_opts[option_index]).
name,
"dag") == 0) {
1718 SCLogError(
"more than one run mode has been specified");
1719 PrintUsage(argv[0]);
1724 SCLogError(
"libdag and a DAG card are required"
1725 " to receive packets using --dag.");
1728 }
else if (strcmp((long_opts[option_index]).
name,
"napatech") == 0) {
1729 #ifdef HAVE_NAPATECH
1732 SCLogError(
"libntapi and a Napatech adapter are required"
1733 " to capture packets using --napatech.");
1736 }
else if (strcmp((long_opts[option_index]).
name,
"pcap-buffer-size") == 0) {
1737 #ifdef HAVE_PCAP_SET_BUFF
1739 SCLogError(
"failed to set pcap-buffer-size");
1744 " doesn't support setting buffer size.");
1746 }
else if (strcmp((long_opts[option_index]).
name,
"build-info") == 0) {
1749 }
else if (strcmp((long_opts[option_index]).
name,
"windivert-forward") == 0) {
1753 if (WinDivertRegisterQueue(
true, optarg) == -1) {
1757 if (WinDivertRegisterQueue(
true, optarg) == -1) {
1762 "has been specified");
1763 PrintUsage(argv[0]);
1767 else if(strcmp((long_opts[option_index]).
name,
"windivert") == 0) {
1770 if (WinDivertRegisterQueue(
false, optarg) == -1) {
1774 if (WinDivertRegisterQueue(
false, optarg) == -1) {
1779 "has been specified");
1780 PrintUsage(argv[0]);
1784 SCLogError(
"WinDivert not enabled. Make sure to pass --enable-windivert to "
1785 "configure when building.");
1788 }
else if(strcmp((long_opts[option_index]).
name,
"reject-dev") == 0) {
1789 #ifdef HAVE_LIBNET11
1791 extern char *g_reject_dev;
1792 extern uint16_t g_reject_dev_mtu;
1793 g_reject_dev = optarg;
1796 g_reject_dev_mtu = (uint16_t)mtu;
1799 SCLogError(
"Libnet 1.1 support not enabled. Compile Suricata with libnet support.");
1803 else if (strcmp((long_opts[option_index]).
name,
"set") == 0) {
1804 if (optarg != NULL) {
1806 char *val = strchr(optarg,
'=');
1808 FatalError(
"Invalid argument for --set, must be key=val.");
1811 FatalError(
"failed to set configuration value %s", optarg);
1815 else if (strcmp((long_opts[option_index]).
name,
"pcap-file-continuous") == 0) {
1817 SCLogError(
"Failed to set pcap-file.continuous");
1821 else if (strcmp((long_opts[option_index]).
name,
"pcap-file-delete") == 0) {
1823 SCLogError(
"Failed to set pcap-file.delete-when-done");
1827 else if (strcmp((long_opts[option_index]).
name,
"pcap-file-recursive") == 0) {
1829 SCLogError(
"failed to set pcap-file.recursive");
1832 }
else if (strcmp((long_opts[option_index]).
name,
"pcap-file-buffer-size") == 0) {
1834 SCLogError(
"failed to set pcap-file.buffer-size");
1837 }
else if (strcmp((long_opts[option_index]).
name,
"data-dir") == 0) {
1838 if (optarg == NULL) {
1839 SCLogError(
"no option argument (optarg) for -d");
1849 " supplied at the command-line (-d %s) doesn't "
1850 "exist. Shutting down the engine.",
1855 }
else if (strcmp((long_opts[option_index]).
name,
"strict-rule-keywords") == 0) {
1856 if (optarg == NULL) {
1862 FatalError(
"failed to duplicate 'strict' string");
1864 }
else if (strcmp((long_opts[option_index]).
name,
"include") == 0) {
1869 "Failed to allocate memory for additional configuration files: %s",
1874 for (
int i = 0;; i++) {
1876 const char **additional_configs =
1878 if (additional_configs == NULL) {
1879 FatalError(
"Failed to allocate memory for additional configuration "
1891 }
else if (strcmp((long_opts[option_index]).
name,
"firewall-rules-exclusive") == 0) {
1893 SCLogError(
"can't have multiple --firewall-rules-exclusive options");
1901 (long_opts[option_index]).
name, optarg);
1912 SCLogError(
"failed to set engine init-failure-fatal");
1925 if (optarg == NULL) {
1926 SCLogError(
"no option argument (optarg) for -i");
1929 #ifdef HAVE_AF_PACKET
1930 if (ParseCommandLineAfpacket(suri, optarg) !=
TM_ECODE_OK) {
1935 #if defined HAVE_NETMAP
1941 "option%s %s available:"
1943 " NETMAP (--netmap=%s)"
1945 ". Use --pcap=%s to suppress this warning",
1946 i == 1 ?
"" :
"s", i == 1 ?
"is" :
"are"
1954 if (ParseCommandLinePcapLive(suri, optarg) !=
TM_ECODE_OK) {
1960 if (optarg == NULL) {
1961 SCLogError(
"no option argument (optarg) for -l");
1971 " supplied at the command-line (-l %s) doesn't "
1972 "exist. Shutting down the engine.",
1976 if (!IsLogDirectoryWritable(optarg)) {
1978 " supplied at the command-line (-l %s) is not "
1979 "writable. Shutting down the engine.",
1998 "has been specified");
1999 PrintUsage(argv[0]);
2003 SCLogError(
"NFQUEUE not enabled. Make sure to pass --enable-nfqueue to configure when "
2020 "has been specified");
2021 PrintUsage(argv[0]);
2025 SCLogError(
"IPFW not enabled. Make sure to pass --enable-ipfw to configure when "
2036 "has been specified");
2037 PrintUsage(argv[0]);
2042 SCLogError(
"pcap file '%s': %s", optarg, strerror(errno));
2046 SCLogError(
"ERROR: Failed to set pcap-file.file\n");
2053 SCLogError(
"can't have multiple -s options or mix -s and -S.");
2060 SCLogError(
"can't have multiple -S options or mix -s and -S.");
2073 PrintUsage(argv[0]);
2077 SCLogError(
"unit tests not enabled. Make sure to pass --enable-unittests to configure "
2094 if (optarg == NULL) {
2095 SCLogError(
"no option argument (optarg) for -F");
2099 SetBpfStringFromFile(optarg);
2102 static bool ignore_extra =
false;
2105 else if (!ignore_extra) {
2106 SCLogNotice(
"extraneous verbose option(s) ignored");
2107 ignore_extra =
true;
2111 if (optarg == NULL) {
2112 SCLogError(
"no option argument (optarg) for -k");
2115 if (!strcmp(
"all", optarg))
2117 else if (!strcmp(
"none", optarg))
2120 SCLogError(
"option '%s' invalid for -k", optarg);
2125 PrintUsage(argv[0]);
2135 SCLogError(
"can't use -s/-S or --firewall-rules-exclusive when detection is disabled");
2142 if (list_app_layer_protocols)
2144 if (list_rule_protocols)
2146 if (list_app_layer_hooks)
2148 if (list_app_layer_frames)
2166 ret = SetBpfString(optind, argv);
2174 int WindowsInitService(
int argc,
char **argv)
2176 if (SCRunningAsService()) {
2177 char path[MAX_PATH];
2179 strlcpy(path, argv[0], MAX_PATH);
2180 if ((p = strrchr(path,
'\\'))) {
2183 if (!SetCurrentDirectory(path)) {
2184 SCLogError(
"Can't set current directory to: %s", path);
2187 SCLogInfo(
"Current directory is set to: %s", path);
2188 SCServiceInit(argc, argv);
2193 if (0 != WSAStartup(MAKEWORD(2, 2), &wsaData)) {
2194 SCLogError(
"Can't initialize Windows sockets: %d", WSAGetLastError());
2205 const char *pid_filename;
2207 if (
SCConfGet(
"pid-file", &pid_filename) == 1) {
2208 SCLogInfo(
"Use pid file %s from config file.", pid_filename);
2215 SCLogError(
"strdup failed: %s", strerror(errno));
2234 SCLogError(
"Unable to create PID file, concurrent run of"
2235 " Suricata can occur.");
2236 SCLogError(
"PID file creation WILL be mandatory for daemon mode"
2237 " in future version");
2252 if (
SCConfGet(
"run-as.user", &
id) == 1) {
2256 if (
SCConfGet(
"run-as.group", &
id) == 1) {
2274 static int InitSignalHandler(
SCInstance *suri)
2277 #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
2282 if (
SCConfGetBool(
"logging.stacktrace-on-signal", &enabled) == 0) {
2287 SCLogInfo(
"Preparing unexpected signal handling");
2288 struct sigaction stacktrace_action;
2289 memset(&stacktrace_action, 0,
sizeof(stacktrace_action));
2290 stacktrace_action.sa_sigaction = SignalHandlerUnexpected;
2291 stacktrace_action.sa_flags = SA_SIGINFO;
2292 sigaction(SIGSEGV, &stacktrace_action, NULL);
2293 sigaction(SIGABRT, &stacktrace_action, NULL);
2316 #ifdef PROFILE_RULES
2317 SCProfilingRulesGlobalInit();
2324 #ifdef PROFILE_RULES
2377 SCPrintElapsedTime(start_time);
2451 PrintUsage(argv[0]);
2461 case RUNMODE_INSTALL_SERVICE:
2462 if (SCServiceInstall(argc, argv)) {
2465 SCLogInfo(
"Suricata service has been successfully installed.");
2467 case RUNMODE_REMOVE_SERVICE:
2468 if (SCServiceRemove()) {
2471 SCLogInfo(
"Suricata service has been successfully removed.");
2473 case RUNMODE_CHANGE_SERVICE_PARAMS:
2474 if (SCServiceChangeParams(argc, argv)) {
2477 SCLogInfo(
"Suricata service startup parameters has been successfully changed.");
2505 static void SetupDelayedDetect(
SCInstance *suri)
2514 if (decnf != NULL) {
2516 if (strcmp(denode->
val,
"delayed-detect") == 0) {
2527 SCLogInfo(
"Packets will start being processed before signatures are active.");
2545 static int ConfigGetCaptureValue(
SCInstance *suri)
2549 intmax_t tmp_max_pending_packets;
2550 if (
SCConfGetInt(
"max-pending-packets", &tmp_max_pending_packets) != 1)
2552 if (tmp_max_pending_packets < 1 || tmp_max_pending_packets > 2147483648) {
2553 SCLogError(
"Maximum max-pending-packets setting is 2147483648 and must be greater than 0. "
2554 "Please check %s for errors",
2565 const char *temp_default_packet_size;
2566 if ((
SCConfGet(
"default-packet-size", &temp_default_packet_size)) != 1) {
2569 int strip_trailing_plus = 0;
2579 const int mtu = GetGlobalMTUWin32();
2593 strip_trailing_plus = 1;
2599 for (lthread = 0; lthread < nlive; lthread++) {
2602 (void)
strlcpy(dev, live_dev,
sizeof(dev));
2604 if (strip_trailing_plus) {
2605 size_t len = strlen(dev);
2607 (dev[
len-1] ==
'+' ||
2608 dev[
len-1] ==
'^' ||
2627 SCLogError(
"Error parsing max-pending-packets "
2628 "from conf file - %s. Killing engine",
2629 temp_default_packet_size);
2639 static void PostRunStartedDetectSetup(
const SCInstance *suri)
2653 SCLogNotice(
"Signature(s) loaded, Detect thread(s) activated.");
2665 SetupDelayedDetect(suri);
2668 int default_tenant = 0;
2670 (void)
SCConfGetBool(
"multi-detect.default", &default_tenant);
2673 "detection engine contexts failed.");
2683 FatalError(
"initializing detection engine failed.");
2699 static void PostConfLoadedSetupHostMode(
void)
2701 const char *hostmode = NULL;
2703 if (
SCConfGet(
"host-mode", &hostmode) == 1) {
2704 if (!strcmp(hostmode,
"router")) {
2706 }
else if (!strcmp(hostmode,
"sniffer-only")) {
2709 if (strcmp(hostmode,
"auto") != 0) {
2721 SCLogInfo(
"No 'host-mode': suricata is in IPS mode, using "
2722 "default setting 'router'");
2725 SCLogInfo(
"No 'host-mode': suricata is in IDS mode, using "
2726 "default setting 'sniffer-only'");
2738 FatalError(
"could not set USER mode logdir");
2744 FatalError(
"could not set USER mode datadir");
2756 int cnf_firewall_enabled = 0;
2757 if (
SCConfGetBool(
"firewall.enabled", &cnf_firewall_enabled) == 1) {
2758 if (cnf_firewall_enabled == 1) {
2762 FatalError(
"firewall mode enabled through commandline, but disabled in config");
2767 SCLogWarning(
"firewall mode is EXPERIMENTAL and subject to change");
2775 int disable_offloading;
2776 if (
SCConfGetBool(
"capture.disable-offloading", &disable_offloading) == 0)
2777 disable_offloading = 1;
2778 if (disable_offloading) {
2785 const char *cv = NULL;
2786 if (
SCConfGet(
"capture.checksum-validation", &cv) == 1) {
2787 if (strcmp(cv,
"none") == 0) {
2789 }
else if (strcmp(cv,
"all") == 0) {
2796 SCConfSet(
"stream.checksum-validation",
"0");
2799 SCConfSet(
"stream.checksum-validation",
"1");
2808 #ifdef HAVE_PACKET_EBPF
2810 EBPFRegisterExtension();
2833 SCLogInfo(
"Setting engine mode to IDS mode by default");
2854 const char *custom_umask;
2855 if (
SCConfGet(
"umask", &custom_umask) == 1) {
2857 if (
StringParseUint16(&mask, 8, (uint16_t)strlen(custom_umask), custom_umask) > 0) {
2858 umask((mode_t)mask);
2875 SCLogInfo(
"== Carrying out Engine Analysis ==");
2876 const char *temp = NULL;
2877 if (
SCConfGet(
"engine-analysis", &temp) == 0) {
2878 SCLogInfo(
"no engine-analysis parameter(s) defined in conf file. "
2879 "Please define/enable them in the conf to use this "
2898 "basic address vars test failed. Please check %s for errors", suri->
conf_filename);
2927 "supplied by %s (default-log-dir) doesn't exist. "
2928 "Shutting down the engine",
2932 if (!IsLogDirectoryWritable(suri->
log_dir)) {
2934 "supplied by %s (default-log-dir) is not writable. "
2935 "Shutting down the engine",
2953 PostConfLoadedSetupHostMode();
3020 return EXIT_FAILURE;
3041 SCInstanceInit(&
suricata, progname);
3059 if (
SCConfGetBool(
"vlan.use-for-tracking", &tracking) == 1 && !tracking) {
3063 SCLogDebug(
"vlan tracking is %s", tracking == 1 ?
"enabled" :
"disabled");
3064 if (
SCConfGetBool(
"livedev.use-for-tracking", &tracking) == 1 && !tracking) {
3068 if (
SCConfGetBool(
"decoder.recursion-level.use-for-tracking", &tracking) == 1 && !tracking) {
3084 SCLogInfo(
"Running suricata under test mode");
3118 SCLogNotice(
"Configuration provided was successfully loaded. Exiting.");
3161 int limit_nproc = 0;
3162 if (
SCConfGetBool(
"security.limit-noproc", &limit_nproc) == 0) {
3166 #if defined(SC_ADDRESS_SANITIZER)
3169 "\"security.limit-noproc\" (setrlimit()) not set when using address sanitizer");
3175 #if defined(HAVE_SYS_RESOURCE_H)
3178 SCLogWarning(
"setrlimit has no effect when running as root.");
3181 struct rlimit r = { 0, 0 };
3182 if (setrlimit(RLIMIT_NPROC, &r) != 0) {
3183 SCLogWarning(
"setrlimit failed to prevent process creation.");
3205 PostRunStartedDetectSetup(&
suricata);
@ RUNMODE_LIST_APP_LAYERS
enum SCRunModes SCRunMode
@ RUNMODE_ENGINE_ANALYSIS
void TmModuleUnixManagerRegister(void)
void StatsReleaseResources(void)
Releases the resources allotted by the Stats API.
#define DETECT_ENGINE_MPM_CACHE_OP_PRUNE
void TmModuleReceiveIPFWRegister(void)
Registration Function for RecieveIPFW.
void SuricataMainLoop(void)
int ExceptionSimulationCommandLineParser(const char *name, const char *arg)
char * firewall_rule_file
void AppLayerHtpNeedFileInspection(void)
Sets a flag that informs the HTP app layer that some module in the engine needs the http request file...
void TmThreadDisablePacketThreads(const uint16_t set, const uint16_t check, const uint8_t module_flags)
Disable all packet threads.
enum SCRunModes aux_run_mode
void IPPairInitConfig(bool quiet)
initialize the configuration
void SCLogInitLogModule(SCLogInitData *sc_lid)
Initializes the logging module.
void SCEnableDefaultSignalHandlers(void)
Enable default signal handlers.
int LiveDeviceListClean(void)
void DetectEngineDeReference(DetectEngineCtx **de_ctx)
struct timeval start_time
bool IsRunModeOffline(enum SCRunModes run_mode_to_check)
#define SC_ATOMIC_INIT(name)
wrapper for initializing an atomic variable.
SystemHugepageSnapshot * prerun_snap
void TmThreadContinueThreads(void)
Unpauses all threads present in tv_root.
@ SURI_HOST_IS_SNIFFER_ONLY
enum DetectEngineType type
int SigLoadSignatures(DetectEngineCtx *de_ctx, char *sig_file, bool sig_file_exclusive)
Load signatures.
const char * firewall_rule_file_exclusive
#define SC_ATOMIC_SET(name, val)
Set the value for the atomic variable.
@ RUNMODE_LIST_APP_LAYER_FRAMES
SCConfNode * SCConfGetRootNode(void)
Get the root configuration node.
DetectEngineCtx * DetectEngineCtxInitStubForDD(void)
void LiveDevRegisterExtension(void)
void OutputTxShutdown(void)
void AppLayerHtpPrintStats(void)
void StatsSetupPostConfigPreOutput(void)
char * runmode_custom_mode
struct HtpBodyChunk_ * next
void TmModuleReceiveNFQRegister(void)
void DetectEngineMpmCacheService(uint32_t op_flags)
int LiveBuildDeviceList(const char *runmode)
void RunModeShutDown(void)
void SCProtoNameInit(void)
void SuricataPostInit(void)
void RunModeDispatch(int runmode, const char *custom_mode, const char *capture_plugin_name, const char *capture_plugin_args)
volatile sig_atomic_t sigint_count
SC_ATOMIC_DECLARE(unsigned int, engine_stage)
void TmModuleRunDeInit(void)
void TmThreadsUnsealThreads(void)
void RegisterFlowBypassInfo(void)
#define SCSetThreadName(n)
int SCConfYamlHandleInclude(SCConfNode *parent, const char *filename)
Include a file in the configuration.
void SCLogDeInitLogModule(void)
De-Initializes the logging module.
void TmModuleDecodeErfFileRegister(void)
Register the ERF file decoder module.
main detection engine ctx
int StringParseUint16(uint16_t *res, int base, size_t len, const char *str)
void DetectEngineReloadSetIdle(void)
void DatalinkTableDeinit(void)
int SCConfGet(const char *name, const char **vptr)
Retrieve the value of a configuration node.
DetectEngineCtx * DetectEngineGetCurrent(void)
int EngineModeIsUnknown(void)
void VarNameStoreInit(void)
void TmModuleFlowRecyclerRegister(void)
int SCConfNodeChildValueIsTrue(const SCConfNode *node, const char *key)
Test if a configuration node has a true value.
void DatalinkTableInit(void)
void Daemonize(void)
Daemonize the process.
void UtilSignalHandlerSetup(int sig, void(*handler)(int))
#define TAILQ_FOREACH(var, head, field)
void TmModuleDecodeAFPRegister(void)
Registration Function for DecodeAFP.
void TmModuleDecodeWinDivertRegister(void)
int DetectEngineAddToMaster(DetectEngineCtx *de_ctx)
int SCConfGetChildValueBool(const SCConfNode *base, const char *name, int *val)
void TmModuleStatsLoggerRegister(void)
void RegisterAllModules(void)
int DetectEngineMultiTenantSetup(const bool unix_socket)
setup multi-detect / multi-tenancy
void SupportFastPatternForSigMatchTypes(void)
Registers the keywords(SMs) that should be given fp support.
TmEcode SCParseCommandLine(int argc, char **argv)
int CheckValidDaemonModes(int daemon, int mode)
Check for a valid combination daemon/mode.
void SCGetGroupID(const char *group_name, uint32_t *gid)
Function to get the group ID from the specified group name.
int SCConfGetBool(const char *name, int *val)
Retrieve a configuration value as a boolean.
void TmThreadDisableReceiveThreads(void)
Disable all threads having the specified TMs.
void StatsInit(void)
Initializes the perf counter api. Things are hard coded currently. More work to be done when we imple...
void PreRunInit(const int runmode)
void MacSetRegisterFlowStorage(void)
void EngineModeSetFirewall(void)
void SuricataShutdown(void)
const char * conf_filename
int GetIfaceMTU(const char *dev)
output the link MTU
void GlobalsInitPreConfig(void)
void TmModuleReceiveNetmapRegister(void)
void PacketPoolPostRunmodes(void)
Set the max_pending_return_packets value.
void NFQInitConfig(bool quiet)
To initialize the NFQ global configuration data.
void TmModuleReceiveWinDivertRegister(void)
bool EngineModeIsFirewall(void)
void SCProfilingDestroy(void)
Free resources used by profiling.
void AFPPeersListClean(void)
Clean the global peers list.
void RunModeInitializeOutputs(void)
int DetectPortTestConfVars(void)
void SCThresholdConfGlobalInit(void)
void DecodeUnregisterCounters(void)
const char * capture_plugin_name
int SCConfYamlLoadFile(const char *filename)
Load configuration from a YAML file.
void HostBitInitCtx(void)
bool IsRunModeSystem(enum SCRunModes run_mode_to_check)
const char * capture_plugin_args
void TmModuleLoggerRegister(void)
void PacketPoolInit(void)
int AppLayerDeSetup(void)
De initializes the app layer.
@ RUNMODE_LIST_APP_LAYER_HOOKS
size_t strlcpy(char *dst, const char *src, size_t siz)
void PcapTranslateIPToDevice(char *pcap_dev, size_t len)
void FlowDisableFlowRecyclerThread(void)
Used to disable flow recycler thread(s).
void SCRunmodeSet(SCRunMode run_mode)
Set the current run mode.
void TmModuleDecodePcapFileRegister(void)
void TmModuleBypassedFlowManagerRegister(void)
void IPPairShutdown(void)
shutdown the flow engine
void SCConfInit(void)
Initialize the configuration system.
void DetectParseFreeRegexes(void)
void SCConfDump(void)
Dump configuration to stdout.
void TmModuleDecodeNFLOGRegister(void)
int NFQParseAndRegisterQueues(const char *queues)
Parses and adds Netfilter queue(s).
void FlowInitConfig(bool quiet)
initialize the configuration
int AppLayerSetup(void)
Setup the app layer.
void FeatureTrackingRegister(void)
void TmModuleReceiveDPDKRegister(void)
void UnixManagerThreadSpawnNonRunmode(const bool unix_socket_enabled)
void RunModeInitializeThreadSettings(void)
void StreamTcpInitConfig(bool)
To initialize the stream global configuration data.
int GetIfaceMaxPacketSize(LiveDevice *ld)
output max packet size for a link
SCRunMode SCRunmodeGet(void)
Get the current run mode.
void TmModuleDecodeNetmapRegister(void)
Registration Function for DecodeNetmap.
void PreRunPostPrivsDropInit(const int runmode)
void SigTableCleanup(void)
int DetectEngineMoveToFreeList(DetectEngineCtx *de_ctx)
volatile sig_atomic_t sigterm_count
TmEcode TmThreadWaitOnThreadInit(void)
Used to check if all threads have finished their initialization. On finding an un-initialized thread,...
const char * SCLogLevel2Name(const SCLogLevel lvl)
void TmModuleVerdictNFQRegister(void)
void AppLayerRegisterGlobalCounters(void)
HACK to work around our broken unix manager (re)init loop.
void RunModeListRunmodes(void)
Lists all registered runmodes.
size_t strlcat(char *, const char *src, size_t siz)
void LiveSetOffloadDisable(void)
void StatsSetupPostConfigPostOutput(void)
void EngineModeSetIDS(void)
void TmModuleReceiveAFPRegister(void)
Registration Function for RecieveAFP.
int LiveBuildDeviceListCustom(const char *runmode, const char *itemname)
LiveDevice * LiveGetDevice(const char *name)
Get a pointer to the device at idx.
void UnixSocketKillSocketThread(void)
void TmModuleVerdictIPFWRegister(void)
Registration Function for VerdictIPFW.
int SCConfGetInt(const char *name, intmax_t *val)
Retrieve a configuration value as an integer.
bool g_stats_eps_per_app_proto_errors
void HttpRangeContainersInit(void)
struct timeval last_reload
void TmModuleVerdictWinDivertRegister(void)
void HostCleanup(void)
Cleanup the host engine.
void FlowDisableFlowManagerThread(void)
Used to disable flow manager thread(s).
int UtilSignalUnblock(int signum)
int DetectEngineEnabled(void)
Check if detection is enabled.
void TmThreadClearThreadsFamily(int family)
#define THV_REQ_FLOW_LOOP
void FlowRateRegisterFlowStorage(void)
void TmModuleRunInit(void)
void EngineModeSetIPS(void)
void HTPAtExitPrintStats(void)
Print the stats of the HTTP requests.
int UtilSignalBlock(int signum)
void SCProfilingPrefilterGlobalInit(void)
void ThresholdDestroy(void)
#define SCLogWarning(...)
Macro used to log WARNING messages.
int PostConfLoadedSetup(SCInstance *suri)
const char * GetProgramVersion(void)
get string with program version
void TmModuleReceivePcapFileRegister(void)
int32_t CoredumpLoadConfig(void)
Configures the core dump size.
int IPFWRegisterQueue(char *queue)
Add an IPFW divert.
int ListAppLayerHooks(const char *conf_filename)
int ListAppLayerProtocols(const char *conf_filename)
void DatasetsDestroy(void)
void UtilCpuPrintSummary(void)
Print a summary of CPUs detected (configured and online)
int profiling_packets_enabled
int SystemDNotifyReady(void)
void TmThreadKillThreads(void)
void OutputDeregisterAll(void)
Deregister all modules. Useful for a memory clean exit.
void PostConfLoadedDetectSetup(SCInstance *suri)
int EngineModeIsIDS(void)
TmModule tmm_modules[TMM_SIZE]
const char * SCConfigGetLogDirectory(void)
void OutputNotifyFileRotation(void)
Notifies all registered file rotation notification flags.
int StorageFinalize(void)
void VarNameStoreDestroy(void)
void TmModuleFlowWorkerRegister(void)
uint32_t max_pending_packets
const char ** additional_configs
#define DEFAULT_PID_FILENAME
volatile sig_atomic_t sighup_count
TmEcode ConfigSetDataDirectory(char *name)
void TmModuleDecodeErfDagRegister(void)
Register the ERF file decoder module.
#define SCDropMainThreadCaps(...)
void TmModuleDebugList(void)
void TmModuleDecodeNFQRegister(void)
void SCProtoNameRelease(void)
int RunmodeIsUnittests(void)
void SCPluginsLoad(const char *capture_plugin_name, const char *capture_plugin_args)
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
void TmModuleReceiveNFLOGRegister(void)
#define DEFAULT_PACKET_SIZE
#define WarnInvalidConfEntry(param_name, format, value)
Generic API that can be used by all to log an invalid conf entry.
#define TM_FLAG_RECEIVE_TM
void TmModuleReceiveErfFileRegister(void)
Register the ERF file receiver (reader) module.
int SCConfSetFromString(const char *input, int final)
Set a configuration parameter from a string.
int SCConfSetFinal(const char *name, const char *val)
Set a final configuration value.
#define SCRealloc(ptr, sz)
void TmModuleDecodeAFXDPRegister(void)
Registration Function for DecodeAFXDP.
uint32_t default_packet_size
void SigTableApplyStrictCommandLineOption(const char *str)
@ DETECT_ENGINE_TYPE_NORMAL
void TmThreadKillThreadsFamily(int family)
void FeatureTrackingRelease(void)
void TmqhCleanup(void)
Clean up registration time allocs.
void StreamTcpFreeConfig(bool quiet)
void DecodeGlobalConfig(void)
char * strict_rule_parsing_string
DetectEngineCtx * DetectEngineCtxInitStubForMT(void)
const char * LiveGetDeviceName(int number)
Get a pointer to the device name at idx.
void FlowShutdown(void)
shutdown the flow engine
void SCHInfoLoadFromConfig(void)
Load the host os policy information from the configuration.
void DetectEngineBumpVersion(void)
void TmModuleFlowManagerRegister(void)
int SCStartInternalRunMode(int argc, char **argv)
int SCPidfileTestRunning(const char *pid_filename)
Check the Suricata pid file (used at the startup)
void HostShutdown(void)
shutdown the flow engine
#define SCFstatFn(fd, statbuf)
void LiveSetOffloadWarn(void)
void ParseSizeDeinit(void)
void SCConfDeInit(void)
De-initializes the configuration system.
void RunModeRegisterRunModes(void)
Register all runmodes in the engine.
int ListRuleProtocols(const char *conf_filename)
void SCProfilingDump(void)
void TmModuleReceiveAFXDPRegister(void)
void EngineStop(void)
make sure threads can stop the engine by calling this function. Purpose: pcap file mode needs to be a...
int ParseSizeStringU32(const char *size, uint32_t *res)
void TmModuleReceiveErfDagRegister(void)
Register the ERF file receiver (reader) module.
void IPPairBitInitCtx(void)
TmEcode ConfigSetLogDirectory(const char *name)
void TmModuleDecodeIPFWRegister(void)
Registration Function for DecodeIPFW.
int ConfUnixSocketIsEnable(void)
#define TM_FLAG_PACKET_ALL
struct SCLogConfig_ SCLogConfig
Holds the config state used by the logging api.
#define DETECT_ENGINE_MPM_CACHE_OP_SAVE
volatile sig_atomic_t sigusr2_count
void SystemHugepageSnapshotDestroy(SystemHugepageSnapshot *s)
void TmModuleDecodePcapRegister(void)
Registration Function for DecodePcap.
TmEcode SCLoadYamlConfig(void)
TmEcode ConfigCheckDataDirectory(const char *data_dir)
SCConfNode * SCConfGetNode(const char *name)
Get a SCConfNode by name.
#define SCLogError(...)
Macro used to log ERROR messages.
int DetectEngineReloadStart(void)
void TopologyDestroy(void)
#define DEFAULT_CONF_FILE
#define SC_LOG_MAX_LOG_MSG_LEN
void AppLayerParserPostStreamSetup(void)
void TmModuleReceivePcapRegister(void)
Registration Function for ReceivePcap.
void SCGetUserID(const char *user_name, const char *group_name, uint32_t *uid, uint32_t *gid)
Function to get the user and group ID from the specified user name.
bool install_signal_handlers
void TmModuleRespondRejectRegister(void)
void CoredumpEnable(void)
Enable coredumps on systems where coredumps can and need to be enabled.
void RunUnittests(int list_unittests, const char *regex_arg)
TmEcode ConfigCheckLogDirectoryExists(const char *log_dir)
int SCConfSet(const char *name, const char *val)
Set a configuration value.
void PacketAlertTagInit(void)
int RunModeEngineIsIPS(int capture_mode, const char *runmode, const char *capture_plugin_name)
DetectEngineCtx * DetectEngineCtxInit(void)
void SCOnLoggingReady(void)
Invokes all registered logging ready callbacks.
void TmModuleDecodeLibRegister(void)
register a "Decode" module for suricata as a library.
int EngineModeIsIPS(void)
int ListAppLayerFrames(const char *conf_filename)
void SCProfilingKeywordsGlobalInit(void)
void EngineDone(void)
Used to indicate that the current task is done.
bool firewall_rule_file_exclusive
const char * GetDocURL(void)
void PostRunDeinit(const int runmode, struct timeval *start_time)
clean up / shutdown code for packet modes
void HostInitConfig(bool quiet)
initialize the configuration
TmEcode TmThreadWaitOnThreadRunning(void)
Waits for all threads to be in a running state.
void HttpRangeContainersDestroy(void)
void SCLogLoadConfig(int daemon, int verbose, uint32_t userid, uint32_t groupid)
int DetectEngineReload(const SCInstance *suri)
Reload the detection engine.
#define DEFAULT_MAX_PENDING_PACKETS
void DetectEngineClearMaster(void)
void SetMasterExceptionPolicy(void)
void TmThreadCheckThreadState(void)
Used to check the thread for certain conditions of failure.
void OutputFilestoreRegisterGlobalCounters(void)
int InitGlobal(void)
Global initialization common to all runmodes.
int LiveGetDeviceCount(void)
Get the number of registered devices.
SystemHugepageSnapshot * SystemHugepageSnapshotCreate(void)
The function creates a snapshot of the system's hugepage usage per NUMA node and per hugepage size....
void SCProfilingSghsGlobalInit(void)
@ RUNMODE_LIST_RULE_PROTOS
int SCPidfileCreate(const char *pidfile)
Write a pid file (used at the startup) This commonly needed by the init scripts.
int LiveRegisterDeviceName(const char *dev)
Add a device for monitoring.
#define SCStatFn(pathname, statbuf)
void LiveDeviceFinalize(void)
void TmModuleDecodeDPDKRegister(void)
Registration Function for DecodeDPDK.
void PacketPoolDestroy(void)
void HTPFreeConfig(void)
Clears the HTTP server configuration memory used by HTP library.
void LandlockSandboxing(SCInstance *suri)
int ListKeywords(const char *keyword_info)
#define SCLogNotice(...)
Macro used to log NOTICE messages.
void SuricataPreInit(const char *progname)
void DPDKCleanupEAL(void)
@ RUNMODE_PRINT_BUILDINFO
void SCPidfileRemove(const char *pid_filename)
Remove the pid file (used at the startup)
void NFQContextsClean(void)
Clean global contexts. Must be called on exit.
void SystemHugepageEvaluateHugepages(SystemHugepageSnapshot *pre_s, SystemHugepageSnapshot *post_s)
The function compares two hugepage snapshots and prints out recommendations for hugepage configuratio...
#define DEBUG_VALIDATE_BUG_ON(exp)
int SCFinalizeRunMode(void)
void SCProfilingInit(void)
Initialize profiling.
void GlobalsDestroy(void)
int DetectEngineReloadIsStart(void)
volatile uint8_t suricata_ctl_flags
#define TM_FLAG_FLOWWORKER_TM
void TagDestroyCtx(void)
Destroy tag context hash tables.
int DetectAddressTestConfVars(void)
void FlowWorkToDoCleanup(void)
Clean up all the flows that have unprocessed segments and have some work to do in the detection engin...
void MpmHSGlobalCleanup(void)
void TmqResetQueues(void)