Go to the documentation of this file.
34 #ifdef HAVE_SYS_RESOURCE_H
36 #include <sys/resource.h>
145 #ifdef SYSTEMD_NOTIFY
170 #define DEFAULT_MAX_PENDING_PACKETS 1024
173 #define VERBOSE_MAX (SC_LOG_DEBUG - SC_LOG_NOTICE)
198 #ifndef AFLFUZZ_NO_RANDOM
323 #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
324 static void SignalHandlerSigint(
int sig)
328 static void SignalHandlerSigterm(
int sig)
334 #define UNW_LOCAL_ONLY
335 #include <libunwind.h>
336 static void SignalHandlerUnexpected(
int sig_num, siginfo_t *info,
void *context)
341 signal(SIGABRT, SIG_DFL);
342 signal(SIGSEGV, SIG_DFL);
344 if ((r = unw_init_local(&cursor, (unw_context_t *)(context)) != 0)) {
345 SCLogError(
"unable to obtain stack trace: unw_init_local: %s", unw_strerror(r));
349 int cw = snprintf(msg,
sizeof(msg),
"stacktrace:sig %d:", sig_num);
352 size_t offset =
MIN((
size_t)cw,
sizeof(msg) - 1);
355 while (r > 0 &&
offset <
sizeof(msg) - 1) {
356 if (unw_is_signal_frame(&cursor) == 0) {
358 char name[256] =
"?";
359 int ret = unw_get_proc_name(&cursor,
name,
sizeof(
name), &off);
361 if (ret != 0 && ret != -UNW_ENOMEM) {
362 cw = snprintf(msg +
offset,
sizeof(msg) -
offset,
"[unknown]:");
364 cw = snprintf(msg +
offset,
sizeof(msg) -
offset,
"%s+0x%08" PRIx64,
name, off);
371 r = unw_step(&cursor);
372 if (r > 0 &&
offset <
sizeof(msg) - 1) {
379 if (
offset >=
sizeof(msg) - 1)
380 memcpy(msg +
sizeof(msg) - 4,
"...", 4);
385 kill(getpid(), sig_num);
387 #undef UNW_LOCAL_ONLY
397 static void SignalHandlerSigusr2(
int sig)
407 static void SignalHandlerSigHup(
int sig)
460 #ifdef HAVE_AF_PACKET
468 #ifdef BUILD_HYPERSCAN
489 static void OnNotifyRunning(
void)
491 #ifdef SYSTEMD_NOTIFY
517 static int SetBpfString(
int argc,
char *argv[])
519 char *bpf_filter = NULL;
520 uint32_t bpf_len = 0;
525 while(argv[tmpindex] != NULL) {
526 bpf_len+=strlen(argv[tmpindex]) + 1;
538 while(argv[tmpindex] != NULL) {
539 strlcat(bpf_filter, argv[tmpindex],bpf_len);
540 if(argv[tmpindex + 1] != NULL) {
541 strlcat(bpf_filter,
" ", bpf_len);
546 if(strlen(bpf_filter) > 0) {
558 static void SetBpfStringFromFile(
char *filename)
560 char *bpf_filter = NULL;
561 char *bpf_comment_tmp = NULL;
562 char *bpf_comment_start = NULL;
568 fp = fopen(filename,
"r");
570 SCLogError(
"Failed to open file %s", filename);
575 SCLogError(
"Failed to stat file %s", filename);
579 bpf_len = ((size_t)(st.st_size)) + 1;
583 SCLogError(
"Failed to allocate buffer for bpf filter in file %s", filename);
587 nm = fread(bpf_filter, 1, bpf_len - 1, fp);
588 if ((ferror(fp) != 0) || (nm != (bpf_len - 1))) {
589 SCLogError(
"Failed to read complete BPF file %s", filename);
596 bpf_filter[nm] =
'\0';
598 if(strlen(bpf_filter) > 0) {
600 bpf_comment_start = bpf_filter;
601 while((bpf_comment_tmp = strchr(bpf_comment_start,
'#')) != NULL) {
602 while((*bpf_comment_tmp !=
'\0') &&
603 (*bpf_comment_tmp !=
'\r') && (*bpf_comment_tmp !=
'\n'))
605 *bpf_comment_tmp++ =
' ';
607 bpf_comment_start = bpf_comment_tmp;
610 while((bpf_comment_tmp = strchr(bpf_filter,
'\r')) != NULL) {
611 *bpf_comment_tmp =
' ';
613 while((bpf_comment_tmp = strchr(bpf_filter,
'\n')) != NULL) {
614 *bpf_comment_tmp =
' ';
617 while (strlen(bpf_filter) > 0 &&
618 bpf_filter[strlen(bpf_filter)-1] ==
' ')
620 bpf_filter[strlen(bpf_filter)-1] =
'\0';
622 if (strlen(bpf_filter) > 0) {
632 static void PrintUsage(
const char *progname)
639 printf(
"USAGE: %s [OPTIONS] [BPF FILTER]\n\n", progname);
641 printf(
"\n General:\n");
642 printf(
"\t-v : be more verbose (use multiple times to "
643 "increase verbosity)\n");
644 printf(
"\t-c <path> : path to configuration file\n");
645 printf(
"\t-l <dir> : default log directory\n");
646 printf(
"\t--include <path> : additional configuration file\n");
647 printf(
"\t--set name=value : set a configuration value\n");
648 printf(
"\t--pidfile <file> : write pid to this file\n");
649 printf(
"\t-T : test configuration file (use with -c)\n");
650 printf(
"\t--init-errors-fatal : enable fatal failure on signature init "
653 printf(
"\t-D : run as daemon\n");
655 printf(
"\t--service-install : install as service\n");
656 printf(
"\t--service-remove : remove service\n");
657 printf(
"\t--service-change-params : change service startup parameters\n");
659 #ifdef HAVE_LIBCAP_NG
660 printf(
"\t--user <user> : run suricata as this user after init\n");
661 printf(
"\t--group <group> : run suricata as this group after init\n");
663 #ifdef BUILD_UNIX_SOCKET
664 printf(
"\t--unix-socket[=<file>] : use unix socket to control suricata work\n");
666 printf(
"\t--runmode <runmode_id> : specific runmode modification the engine should run. The argument\n"
667 "\t supplied should be the id for the runmode obtained by running\n"
668 "\t --list-runmodes\n");
669 printf(
"\t--plugin <path> : load plugin in addition to config\n");
671 printf(
"\n Capture and IPS:\n");
673 printf(
"\t-F <bpf filter file> : bpf filter file\n");
674 printf(
"\t-k [all|none] : force checksum check (all) or disabled it "
676 printf(
"\t-i <dev or ip> : run in pcap live mode\n");
677 printf(
"\t--pcap[=<dev>] : run in pcap mode, no value select interfaces "
678 "from suricata.yaml\n");
679 #ifdef HAVE_PCAP_SET_BUFF
680 printf(
"\t--pcap-buffer-size : size of the pcap buffer value from 0 - %i\n",INT_MAX);
683 printf(
"\t-q <qid[:qid]> : run in inline nfqueue mode (use colon to "
684 "specify a range of queues)\n");
687 printf(
"\t-d <divert port> : run in inline ipfw divert mode\n");
689 #ifdef HAVE_AF_PACKET
690 printf(
"\t--af-packet[=<dev>] : run in af-packet mode, no value select interfaces from suricata.yaml\n");
693 printf(
"\t--af-xdp[=<dev>] : run in af-xdp mode, no value select "
694 "interfaces from suricata.yaml\n");
697 printf(
"\t--netmap[=<dev>] : run in netmap mode, no value select interfaces from suricata.yaml\n");
700 printf(
"\t--pfring[=<dev>] : run in pfring mode, use interfaces from suricata.yaml\n");
701 printf(
"\t--pfring-int <dev> : run in pfring mode, use interface <dev>\n");
702 printf(
"\t--pfring-cluster-id <id> : pfring cluster id \n");
703 printf(
"\t--pfring-cluster-type <type> : pfring cluster type for PF_RING 4.1.2 and later cluster_round_robin|cluster_flow\n");
706 printf(
"\t--dpdk : run in dpdk mode, uses interfaces from "
710 printf(
"\t--dag <dagX:Y> : process ERF records from DAG interface X, stream Y\n");
713 printf(
"\t--windivert <filter> : run in inline WinDivert mode\n");
714 printf(
"\t--windivert-forward <filter> : run in inline WinDivert mode, as a gateway\n");
717 printf(
"\t--reject-dev <dev> : send reject packets from this interface\n");
720 printf(
"\n Capture Files:\n");
721 printf(
"\t-r <path> : run in pcap file/offline mode\n");
722 printf(
"\t--pcap-file-continuous : when running in pcap mode with a directory, "
723 "continue checking directory for pcaps until interrupted\n");
724 printf(
"\t--pcap-file-delete : when running in replay mode (-r with "
725 "directory or file), will delete pcap files that have been processed when done\n");
726 printf(
"\t--pcap-file-recursive : will descend into subdirectories when running "
727 "in replay mode (-r)\n");
728 printf(
"\t--pcap-file-buffer-size : set read buffer size (setvbuf)\n");
729 printf(
"\t--erf-in <path> : process an ERF file\n");
731 printf(
"\n Detection:\n");
732 printf(
"\t-s <path> : path to signature file loaded in addition to "
733 "suricata.yaml settings (optional)\n");
734 printf(
"\t-S <path> : path to signature file loaded exclusively "
736 printf(
"\t--disable-detection : disable detection engine\n");
737 printf(
"\t--engine-analysis : print reports on analysis of different "
738 "sections in the engine and exit.\n"
739 "\t Please have a look at the conf parameter "
740 "engine-analysis on what reports\n"
741 "\t can be printed\n");
743 printf(
"\n Firewall:\n");
744 printf(
"\t--firewall : enable firewall mode\n");
745 printf(
"\t--firewall-rules-exclusive=<path> : path to firewall rule file loaded "
748 printf(
"\n Info:\n");
749 printf(
"\t-V : display Suricata version\n");
750 printf(
"\t--list-keywords[=all|csv|<kword>] : list keywords implemented by the engine\n");
751 printf(
"\t--list-runmodes : list supported runmodes\n");
752 printf(
"\t--list-app-layer-protos : list supported app layer protocols\n");
753 printf(
"\t--list-rule-protos : list supported rule protocols\n");
754 printf(
"\t--list-app-layer-hooks : list supported app layer hooks for use in "
756 printf(
"\t--list-app-layer-frames : list supported app layer frames for use with "
757 "'frame' keyword\n");
758 printf(
"\t--dump-config : show the running configuration\n");
759 printf(
"\t--dump-features : display provided features\n");
760 printf(
"\t--build-info : display build information\n");
762 printf(
"\n Testing:\n");
763 printf(
"\t--simulate-ips : force engine into IPS mode. Useful for QA\n");
765 printf(
"\t-u : run the unittests and exit\n");
766 printf(
"\t-U=REGEX, --unittest-filter=REGEX : filter unittests with a pcre compatible "
768 printf(
"\t--list-unittests : list unit tests\n");
769 printf(
"\t--fatal-unittests : enable fatal failure on unittest error\n");
770 printf(
"\t--unittests-coverage : display unittest coverage report\n");
773 printf(
"\nTo run " PROG_NAME " with default configuration on "
774 "interface eth0 with signature file \"signatures.rules\", run the "
775 "command as:\n\n%s -c suricata.yaml -s signatures.rules -i eth0 \n\n",
779 static void PrintBuildInfo(
void)
784 char features[2048] =
"";
789 strlcat(features,
"DEBUG ",
sizeof(features));
791 #ifdef DEBUG_VALIDATION
792 strlcat(features,
"DEBUG_VALIDATION ",
sizeof(features));
795 strlcat(features,
"QA_SIMULATION ",
sizeof(features));
798 strlcat(features,
"UNITTESTS ",
sizeof(features));
801 strlcat(features,
"NFQ ",
sizeof(features));
804 strlcat(features,
"IPFW ",
sizeof(features));
806 #ifdef HAVE_PCAP_SET_BUFF
807 strlcat(features,
"PCAP_SET_BUFF ",
sizeof(features));
810 strlcat(features,
"PF_RING ",
sizeof(features));
813 strlcat(features,
"NAPATECH ",
sizeof(features));
815 #ifdef HAVE_AF_PACKET
816 strlcat(features,
"AF_PACKET ",
sizeof(features));
819 strlcat(features,
"NETMAP ",
sizeof(features));
821 #ifdef HAVE_PACKET_FANOUT
822 strlcat(features,
"HAVE_PACKET_FANOUT ",
sizeof(features));
825 strlcat(features,
"DAG ",
sizeof(features));
827 #ifdef HAVE_LIBCAP_NG
828 strlcat(features,
"LIBCAP_NG ",
sizeof(features));
831 strlcat(features,
"LIBNET1.1 ",
sizeof(features));
833 strlcat(features,
"HAVE_HTP_URI_NORMALIZE_HOOK ",
sizeof(features));
834 #ifdef PCRE2_HAVE_JIT
835 strlcat(features,
"PCRE_JIT ",
sizeof(features));
838 strlcat(features,
"HAVE_NSS ",
sizeof(features));
840 strlcat(features,
"HTTP2_DECOMPRESSION ",
sizeof(features));
842 strlcat(features,
"HAVE_LUA ",
sizeof(features));
844 strlcat(features,
"HAVE_JA3 ",
sizeof(features));
847 strlcat(features,
"HAVE_JA4 ",
sizeof(features));
849 strlcat(features,
"HAVE_LIBJANSSON ",
sizeof(features));
851 strlcat(features,
"PROFILING ",
sizeof(features));
853 #ifdef HAVE_PACKET_EBPF
854 strlcat(features,
"EBPF ",
sizeof(features));
856 #ifdef PROFILE_LOCKING
857 strlcat(features,
"PROFILE_LOCKING ",
sizeof(features));
859 #ifdef BUILD_UNIX_SOCKET
860 strlcat(features,
"UNIX_SOCKET ",
sizeof(features));
862 #if defined(TLS_C11) || defined(TLS_GNU)
863 strlcat(features,
"TLS ",
sizeof(features));
866 strlcat(features,
"TLS_C11 ",
sizeof(features));
867 #elif defined(TLS_GNU)
868 strlcat(features,
"TLS_GNU ",
sizeof(features));
871 strlcat(features,
"MAGIC ",
sizeof(features));
873 strlcat(features,
"RUST ",
sizeof(features));
874 #if defined(SC_ADDRESS_SANITIZER)
875 strlcat(features,
"ASAN ",
sizeof(features));
877 #if defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
878 strlcat(features,
"FUZZ ",
sizeof(features));
880 #if defined(HAVE_POPCNT64)
881 strlcat(features,
"POPCNT64 ",
sizeof(features));
883 if (strlen(features) == 0) {
884 strlcat(features,
"none",
sizeof(features));
887 printf(
"Features: %s\n", features);
890 memset(features, 0x00,
sizeof(features));
891 #if defined(__SSE4_2__)
892 strlcat(features,
"SSE_4_2 ",
sizeof(features));
894 #if defined(__SSE4_1__)
895 strlcat(features,
"SSE_4_1 ",
sizeof(features));
897 #if defined(__SSE3__)
898 strlcat(features,
"SSE_3 ",
sizeof(features));
900 #if defined(__SSE2__)
901 strlcat(features,
"SSE_2 ",
sizeof(features));
903 if (strlen(features) == 0) {
904 strlcat(features,
"none",
sizeof(features));
906 printf(
"SIMD support: %s\n", features);
909 memset(features, 0x00,
sizeof(features));
910 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_1)
911 strlcat(features,
"1 ",
sizeof(features));
913 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_2)
914 strlcat(features,
"2 ",
sizeof(features));
916 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_4)
917 strlcat(features,
"4 ",
sizeof(features));
919 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_8)
920 strlcat(features,
"8 ",
sizeof(features));
922 #if defined(__GCC_HAVE_SYNC_COMPARE_AND_SWAP_16)
923 strlcat(features,
"16 ",
sizeof(features));
925 if (strlen(features) == 0) {
926 strlcat(features,
"none",
sizeof(features));
928 strlcat(features,
"byte(s)",
sizeof(features));
930 printf(
"Atomic intrinsics: %s\n", features);
934 #elif __WORDSIZE == 32
937 bits =
"<unknown>-bits";
940 #if __BYTE_ORDER == __BIG_ENDIAN
941 endian =
"Big-endian";
942 #elif __BYTE_ORDER == __LITTLE_ENDIAN
943 endian =
"Little-endian";
945 endian =
"<unknown>-endian";
948 printf(
"%s, %s architecture\n", bits, endian);
950 printf(
"GCC version %s, C version %"PRIiMAX
"\n", __VERSION__, (intmax_t)__STDC_VERSION__);
952 printf(
"C version %"PRIiMAX
"\n", (intmax_t)__STDC_VERSION__);
956 printf(
"compiled with -fstack-protector\n");
959 printf(
"compiled with -fstack-protector-all\n");
968 #if _FORTIFY_SOURCE == 2
969 printf(
"compiled with _FORTIFY_SOURCE=2\n");
970 #elif _FORTIFY_SOURCE == 1
971 printf(
"compiled with _FORTIFY_SOURCE=1\n");
972 #elif _FORTIFY_SOURCE == 0
973 printf(
"compiled with _FORTIFY_SOURCE=0\n");
976 printf(
"L1 cache line size (CLS)=%d\n",
CLS);
979 tls =
"_Thread_local";
980 #elif defined(TLS_GNU)
983 #error "Unsupported thread local"
985 printf(
"thread local storage method: %s\n", tls);
987 printf(
"compiled with %s\n", htp_get_version());
989 #include "build-info.h"
1085 static TmEcode ParseInterfacesList(
const int runmode,
char *pcap_dev)
1091 if (strlen(pcap_dev) == 0) {
1094 SCLogError(
"No interface found in config for pcap");
1101 if (strlen(pcap_dev)) {
1103 SCLogError(
"Failed to set pfring.live-interface");
1110 char iface_selector[] =
"dpdk.interfaces";
1113 SCLogError(
"No interface found in config for %s", iface_selector);
1117 #ifdef HAVE_AF_PACKET
1120 if (strlen(pcap_dev)) {
1122 SCLogError(
"Failed to set af-packet.live-interface");
1128 SCLogError(
"No interface found in config for af-packet");
1136 if (strlen(pcap_dev)) {
1138 SCLogError(
"Failed to set af-xdp.live-interface");
1144 SCLogError(
"No interface found in config for af-xdp");
1152 if (strlen(pcap_dev)) {
1154 SCLogError(
"Failed to set netmap.live-interface");
1160 SCLogError(
"No interface found in config for netmap");
1169 SCLogError(
"No group found in config for nflog");
1178 static void SCInstanceInit(
SCInstance *suri,
const char *progname)
1180 memset(suri, 0x00,
sizeof(*suri));
1207 #if HAVE_DETECT_DISABLED==1
1217 if (strstr(prog_ver,
"RELEASE") != NULL) {
1237 if (strstr(
PROG_VER,
"-dev") == NULL) {
1248 static TmEcode PrintVersion(
void)
1256 const char *mode = suri->
system ?
"SYSTEM" :
"USER";
1257 SCLogNotice(
"This is %s version %s running in %s mode",
1268 static void SCPrintElapsedTime(
struct timeval *start_time)
1270 if (start_time == NULL)
1272 struct timeval end_time;
1273 memset(&end_time, 0,
sizeof(end_time));
1274 gettimeofday(&end_time, NULL);
1275 uint64_t milliseconds = ((end_time.tv_sec - start_time->tv_sec) * 1000) +
1276 (((1000000 + end_time.tv_usec - start_time->tv_usec) / 1000) - 1000);
1277 SCLogInfo(
"time elapsed %.3fs", (
float)milliseconds/(
float)1000);
1280 static int ParseCommandLineAfpacket(
SCInstance *suri,
const char *in_arg)
1282 #ifdef HAVE_AF_PACKET
1294 SCLogInfo(
"Multiple af-packet option without interface on each is useless");
1298 "has been specified");
1304 SCLogError(
"AF_PACKET not enabled. On Linux "
1305 "host, make sure to pass --enable-af-packet to "
1306 "configure when building.");
1311 static int ParseCommandLineAfxdp(
SCInstance *suri,
const char *in_arg)
1325 SCLogInfo(
"Multiple af-xdp options without interface on each is useless");
1329 "has been specified");
1336 "host, make sure correct libraries are installed,"
1337 " see documentation for information.");
1342 static int ParseCommandLineDpdk(
SCInstance *suri,
const char *in_arg)
1348 SCLogInfo(
"Multiple dpdk options have no effect on Suricata");
1351 "has been specified");
1358 "host, make sure to pass --enable-dpdk to "
1359 "configure when building.");
1364 static int ParseCommandLinePcapLive(
SCInstance *suri,
const char *in_arg)
1366 #if defined(OS_WIN32) && !defined(HAVE_LIBWPCAP)
1368 FatalError(
"Live capture not available. To support live capture compile against Npcap.");
1372 if (in_arg != NULL) {
1375 if (strlen(in_arg) > 9 && strncmp(in_arg,
"DeviceNPF", 9) == 0) {
1376 snprintf(suri->
pcap_dev,
sizeof(suri->
pcap_dev),
"\\Device\\NPF%s", in_arg+9);
1382 if (strcmp(suri->
pcap_dev, in_arg) != 0) {
1384 }
else if (strlen(suri->
pcap_dev) > 0 && isdigit((
unsigned char)suri->
pcap_dev[0])) {
1385 SCLogError(
"failed to find a pcap device for IP %s", in_arg);
1399 "has been specified");
1409 static bool IsLogDirectoryWritable(
const char*
str)
1411 return access(
str, W_OK) == 0;
1420 static void AddCommandLineOptionValue(
1421 const char ***values,
const char *value,
const char *description)
1423 if (*values == NULL) {
1424 *values =
SCCalloc(2,
sizeof(
char *));
1425 if (*values == NULL) {
1426 FatalError(
"Failed to allocate memory for %s: %s", description, strerror(errno));
1428 (*values)[0] = value;
1430 for (
int i = 0;; i++) {
1431 if ((*values)[i] == NULL) {
1432 const char **new_values =
SCRealloc(*values, (i + 2) *
sizeof(
char *));
1433 if (new_values == NULL) {
1435 "Failed to allocate memory for %s: %s", description, strerror(errno));
1437 *values = new_values;
1438 (*values)[i] = value;
1439 (*values)[i + 1] = NULL;
1453 int dump_config = 0;
1454 int dump_features = 0;
1455 int list_app_layer_protocols = 0;
1456 int list_rule_protocols = 0;
1457 int list_app_layer_hooks = 0;
1458 int list_app_layer_frames = 0;
1459 int list_unittests = 0;
1460 int list_runmodes = 0;
1461 int list_keywords = 0;
1466 int is_firewall = 0;
1475 struct option long_opts[] = {
1477 {
"dump-config", 0, &dump_config, 1},
1478 {
"dump-features", 0, &dump_features, 1},
1479 {
"pfring", optional_argument, 0, 0},
1480 {
"pfring-int", required_argument, 0, 0},
1481 {
"pfring-cluster-id", required_argument, 0, 0},
1482 {
"pfring-cluster-type", required_argument, 0, 0},
1486 {
"af-packet", optional_argument, 0, 0},
1487 {
"af-xdp", optional_argument, 0, 0},
1488 {
"netmap", optional_argument, 0, 0},
1489 {
"pcap", optional_argument, 0, 0},
1490 {
"pcap-file-continuous", 0, 0, 0},
1491 {
"pcap-file-delete", 0, 0, 0},
1492 {
"pcap-file-recursive", 0, 0, 0},
1493 {
"pcap-file-buffer-size", required_argument, 0, 0},
1494 {
"simulate-ips", 0, 0 , 0},
1496 {
"strict-rule-keywords", optional_argument, 0, 0},
1498 {
"plugin", required_argument, 0, 0},
1499 {
"capture-plugin", required_argument, 0, 0},
1500 {
"capture-plugin-args", required_argument, 0, 0},
1502 #ifdef BUILD_UNIX_SOCKET
1503 {
"unix-socket", optional_argument, 0, 0},
1505 {
"pcap-buffer-size", required_argument, 0, 0},
1506 {
"unittest-filter", required_argument, 0,
'U'},
1507 {
"list-app-layer-protos", 0, &list_app_layer_protocols, 1},
1508 {
"list-rule-protos", 0, &list_rule_protocols, 1},
1509 {
"list-app-layer-hooks", 0, &list_app_layer_hooks, 1},
1510 {
"list-app-layer-frames", 0, &list_app_layer_frames, 1},
1511 {
"list-unittests", 0, &list_unittests, 1},
1512 {
"list-runmodes", 0, &list_runmodes, 1},
1513 {
"list-keywords", optional_argument, &list_keywords, 1},
1514 {
"runmode", required_argument, NULL, 0},
1517 {
"service-install", 0, 0, 0},
1518 {
"service-remove", 0, 0, 0},
1519 {
"service-change-params", 0, 0, 0},
1521 {
"pidfile", required_argument, 0, 0},
1522 {
"init-errors-fatal", 0, 0, 0},
1523 {
"disable-detection", 0, 0, 0},
1524 {
"disable-hashing", 0, 0, 0},
1525 {
"fatal-unittests", 0, 0, 0},
1527 {
"user", required_argument, 0, 0},
1528 {
"group", required_argument, 0, 0},
1529 {
"erf-in", required_argument, 0, 0},
1530 {
"dag", required_argument, 0, 0},
1531 {
"build-info", 0, &build_info, 1},
1532 {
"data-dir", required_argument, 0, 0},
1534 {
"windivert", required_argument, 0, 0},
1535 {
"windivert-forward", required_argument, 0, 0},
1537 #ifdef HAVE_LIBNET11
1538 {
"reject-dev", required_argument, 0, 0},
1540 {
"set", required_argument, 0, 0},
1542 {
"nflog", optional_argument, 0, 0},
1544 {
"simulate-packet-flow-memcap", required_argument, 0, 0},
1545 {
"simulate-applayer-error-at-offset-ts", required_argument, 0, 0},
1546 {
"simulate-applayer-error-at-offset-tc", required_argument, 0, 0},
1547 {
"simulate-packet-loss", required_argument, 0, 0},
1548 {
"simulate-packet-tcp-reassembly-memcap", required_argument, 0, 0},
1549 {
"simulate-packet-tcp-ssn-memcap", required_argument, 0, 0},
1550 {
"simulate-packet-defrag-memcap", required_argument, 0, 0},
1551 {
"simulate-alert-queue-realloc-failure", 0, 0, 0},
1555 {
"firewall", 0, &is_firewall, 1 },
1556 {
"firewall-rules-exclusive", required_argument, 0, 0},
1558 {
"include", required_argument, 0, 0},
1565 int option_index = 0;
1567 char short_opts[] =
"c:TDhi:l:q:d:r:us:S:U:VF:vk:";
1569 while ((opt = getopt_long(argc, argv, short_opts, long_opts, &option_index)) != -1) {
1572 if (strcmp((long_opts[option_index]).
name,
"help") == 0) {
1575 }
else if (strcmp((long_opts[option_index]).
name,
"pfring") == 0 ||
1576 strcmp((long_opts[option_index]).
name,
"pfring-int") == 0) {
1581 if (optarg != NULL) {
1584 ((strlen(optarg) <
sizeof(suri->
pcap_dev)) ?
1585 (strlen(optarg) + 1) :
sizeof(suri->
pcap_dev)));
1590 "to pass --enable-pfring to configure when building.");
1593 }
else if (strcmp((long_opts[option_index]).
name,
"pfring-cluster-id") == 0) {
1596 SCLogError(
"failed to set pfring.cluster-id");
1601 "to pass --enable-pfring to configure when building.");
1604 }
else if (strcmp((long_opts[option_index]).
name,
"pfring-cluster-type") == 0) {
1607 SCLogError(
"failed to set pfring.cluster-type");
1612 "to pass --enable-pfring to configure when building.");
1615 }
else if (strcmp((long_opts[option_index]).
name,
"plugin") == 0) {
1617 }
else if (strcmp((long_opts[option_index]).
name,
"capture-plugin") == 0) {
1620 }
else if (strcmp((long_opts[option_index]).
name,
"capture-plugin-args") == 0) {
1622 }
else if (strcmp((long_opts[option_index]).
name,
"dpdk") == 0) {
1623 if (ParseCommandLineDpdk(suri, optarg) !=
TM_ECODE_OK) {
1626 }
else if (strcmp((long_opts[option_index]).
name,
"af-packet") == 0) {
1627 if (ParseCommandLineAfpacket(suri, optarg) !=
TM_ECODE_OK) {
1630 }
else if (strcmp((long_opts[option_index]).
name,
"af-xdp") == 0) {
1631 if (ParseCommandLineAfxdp(suri, optarg) !=
TM_ECODE_OK) {
1634 }
else if (strcmp((long_opts[option_index]).
name,
"netmap") == 0) {
1642 ((strlen(optarg) <
sizeof(suri->
pcap_dev)) ?
1643 (strlen(optarg) + 1) :
sizeof(suri->
pcap_dev)));
1649 SCLogInfo(
"Multiple netmap option without interface on each is useless");
1654 "has been specified");
1655 PrintUsage(argv[0]);
1662 }
else if (strcmp((long_opts[option_index]).
name,
"nflog") == 0) {
1672 }
else if (strcmp((long_opts[option_index]).
name,
"pcap") == 0) {
1673 if (ParseCommandLinePcapLive(suri, optarg) !=
TM_ECODE_OK) {
1676 }
else if (strcmp((long_opts[option_index]).
name,
"simulate-ips") == 0) {
1679 }
else if (strcmp((long_opts[option_index]).
name,
"init-errors-fatal") == 0) {
1681 SCLogError(
"failed to set engine init-failure-fatal");
1684 #ifdef BUILD_UNIX_SOCKET
1685 }
else if (strcmp((long_opts[option_index]).
name ,
"unix-socket") == 0) {
1690 SCLogError(
"failed to set unix-command.filename");
1696 "has been specified");
1697 PrintUsage(argv[0]);
1702 else if(strcmp((long_opts[option_index]).
name,
"list-app-layer-protocols") == 0) {
1704 }
else if (strcmp((long_opts[option_index]).
name,
"list-app-layer-hooks") == 0) {
1706 }
else if (strcmp((long_opts[option_index]).
name,
"list-unittests") == 0) {
1710 SCLogError(
"unit tests not enabled. Make sure to pass --enable-unittests to "
1711 "configure when building");
1714 }
else if (strcmp((long_opts[option_index]).
name,
"list-runmodes") == 0) {
1717 }
else if (strcmp((long_opts[option_index]).
name,
"list-keywords") == 0) {
1719 if (strcmp(
"short", optarg) != 0) {
1723 }
else if (strcmp((long_opts[option_index]).
name,
"runmode") == 0) {
1725 }
else if (strcmp((long_opts[option_index]).
name,
"engine-analysis") == 0) {
1729 else if (strcmp((long_opts[option_index]).
name,
"service-install") == 0) {
1730 suri->
run_mode = RUNMODE_INSTALL_SERVICE;
1732 }
else if (strcmp((long_opts[option_index]).
name,
"service-remove") == 0) {
1733 suri->
run_mode = RUNMODE_REMOVE_SERVICE;
1735 }
else if (strcmp((long_opts[option_index]).
name,
"service-change-params") == 0) {
1736 suri->
run_mode = RUNMODE_CHANGE_SERVICE_PARAMS;
1740 else if (strcmp((long_opts[option_index]).
name,
"pidfile") == 0) {
1743 SCLogError(
"strdup failed: %s", strerror(errno));
1746 }
else if (strcmp((long_opts[option_index]).
name,
"disable-detection") == 0) {
1748 }
else if (strcmp((long_opts[option_index]).
name,
"disable-hashing") == 0) {
1752 }
else if (strcmp((long_opts[option_index]).
name,
"fatal-unittests") == 0) {
1756 SCLogError(
"unit tests not enabled. Make sure to pass --enable-unittests to "
1757 "configure when building");
1760 }
else if (strcmp((long_opts[option_index]).
name,
"user") == 0) {
1761 #ifndef HAVE_LIBCAP_NG
1763 " drop privileges, but it was not compiled into Suricata.");
1769 }
else if (strcmp((long_opts[option_index]).
name,
"group") == 0) {
1770 #ifndef HAVE_LIBCAP_NG
1772 " drop privileges, but it was not compiled into Suricata.");
1778 }
else if (strcmp((long_opts[option_index]).
name,
"erf-in") == 0) {
1784 }
else if (strcmp((long_opts[option_index]).
name,
"dag") == 0) {
1790 SCLogError(
"more than one run mode has been specified");
1791 PrintUsage(argv[0]);
1796 SCLogError(
"libdag and a DAG card are required"
1797 " to receive packets using --dag.");
1800 }
else if (strcmp((long_opts[option_index]).
name,
"napatech") == 0) {
1801 #ifdef HAVE_NAPATECH
1804 SCLogError(
"libntapi and a Napatech adapter are required"
1805 " to capture packets using --napatech.");
1808 }
else if (strcmp((long_opts[option_index]).
name,
"pcap-buffer-size") == 0) {
1809 #ifdef HAVE_PCAP_SET_BUFF
1811 SCLogError(
"failed to set pcap-buffer-size");
1816 " doesn't support setting buffer size.");
1818 }
else if (strcmp((long_opts[option_index]).
name,
"build-info") == 0) {
1821 }
else if (strcmp((long_opts[option_index]).
name,
"windivert-forward") == 0) {
1825 if (WinDivertRegisterQueue(
true, optarg) == -1) {
1829 if (WinDivertRegisterQueue(
true, optarg) == -1) {
1834 "has been specified");
1835 PrintUsage(argv[0]);
1839 else if(strcmp((long_opts[option_index]).
name,
"windivert") == 0) {
1842 if (WinDivertRegisterQueue(
false, optarg) == -1) {
1846 if (WinDivertRegisterQueue(
false, optarg) == -1) {
1851 "has been specified");
1852 PrintUsage(argv[0]);
1856 SCLogError(
"WinDivert not enabled. Make sure to pass --enable-windivert to "
1857 "configure when building.");
1860 }
else if(strcmp((long_opts[option_index]).
name,
"reject-dev") == 0) {
1861 #ifdef HAVE_LIBNET11
1863 extern char *g_reject_dev;
1864 extern uint16_t g_reject_dev_mtu;
1865 g_reject_dev = optarg;
1868 g_reject_dev_mtu = (uint16_t)mtu;
1871 SCLogError(
"Libnet 1.1 support not enabled. Compile Suricata with libnet support.");
1875 else if (strcmp((long_opts[option_index]).
name,
"set") == 0) {
1876 if (optarg != NULL) {
1878 char *val = strchr(optarg,
'=');
1880 FatalError(
"Invalid argument for --set, must be key=val.");
1883 FatalError(
"failed to set configuration value %s", optarg);
1887 else if (strcmp((long_opts[option_index]).
name,
"pcap-file-continuous") == 0) {
1889 SCLogError(
"Failed to set pcap-file.continuous");
1893 else if (strcmp((long_opts[option_index]).
name,
"pcap-file-delete") == 0) {
1895 SCLogError(
"Failed to set pcap-file.delete-when-done");
1899 else if (strcmp((long_opts[option_index]).
name,
"pcap-file-recursive") == 0) {
1901 SCLogError(
"failed to set pcap-file.recursive");
1904 }
else if (strcmp((long_opts[option_index]).
name,
"pcap-file-buffer-size") == 0) {
1906 SCLogError(
"failed to set pcap-file.buffer-size");
1909 }
else if (strcmp((long_opts[option_index]).
name,
"data-dir") == 0) {
1910 if (optarg == NULL) {
1911 SCLogError(
"no option argument (optarg) for -d");
1921 " supplied at the command-line (-d %s) doesn't "
1922 "exist. Shutting down the engine.",
1927 }
else if (strcmp((long_opts[option_index]).
name,
"strict-rule-keywords") == 0) {
1928 if (optarg == NULL) {
1934 FatalError(
"failed to duplicate 'strict' string");
1936 }
else if (strcmp((long_opts[option_index]).
name,
"include") == 0) {
1937 AddCommandLineOptionValue(
1939 }
else if (strcmp((long_opts[option_index]).
name,
"firewall-rules-exclusive") == 0) {
1941 SCLogError(
"can't have multiple --firewall-rules-exclusive options");
1949 (long_opts[option_index]).
name, optarg);
1960 SCLogError(
"failed to set engine init-failure-fatal");
1973 if (optarg == NULL) {
1974 SCLogError(
"no option argument (optarg) for -i");
1977 #ifdef HAVE_AF_PACKET
1978 if (ParseCommandLineAfpacket(suri, optarg) !=
TM_ECODE_OK) {
1983 #if defined HAVE_NETMAP
1989 "option%s %s available:"
1991 " NETMAP (--netmap=%s)"
1993 ". Use --pcap=%s to suppress this warning",
1994 i == 1 ?
"" :
"s", i == 1 ?
"is" :
"are"
2002 if (ParseCommandLinePcapLive(suri, optarg) !=
TM_ECODE_OK) {
2008 if (optarg == NULL) {
2009 SCLogError(
"no option argument (optarg) for -l");
2019 " supplied at the command-line (-l %s) doesn't "
2020 "exist. Shutting down the engine.",
2024 if (!IsLogDirectoryWritable(optarg)) {
2026 " supplied at the command-line (-l %s) is not "
2027 "writable. Shutting down the engine.",
2046 "has been specified");
2047 PrintUsage(argv[0]);
2051 SCLogError(
"NFQUEUE not enabled. Make sure to pass --enable-nfqueue to configure when "
2068 "has been specified");
2069 PrintUsage(argv[0]);
2073 SCLogError(
"IPFW not enabled. Make sure to pass --enable-ipfw to configure when "
2084 "has been specified");
2085 PrintUsage(argv[0]);
2090 SCLogError(
"pcap file '%s': %s", optarg, strerror(errno));
2094 SCLogError(
"ERROR: Failed to set pcap-file.file\n");
2101 SCLogError(
"can't have multiple -s options or mix -s and -S.");
2108 SCLogError(
"can't have multiple -S options or mix -s and -S.");
2121 PrintUsage(argv[0]);
2125 SCLogError(
"unit tests not enabled. Make sure to pass --enable-unittests to configure "
2142 if (optarg == NULL) {
2143 SCLogError(
"no option argument (optarg) for -F");
2147 SetBpfStringFromFile(optarg);
2150 static bool ignore_extra =
false;
2153 else if (!ignore_extra) {
2154 SCLogNotice(
"extraneous verbose option(s) ignored");
2155 ignore_extra =
true;
2159 if (optarg == NULL) {
2160 SCLogError(
"no option argument (optarg) for -k");
2163 if (!strcmp(
"all", optarg))
2165 else if (!strcmp(
"none", optarg))
2168 SCLogError(
"option '%s' invalid for -k", optarg);
2173 PrintUsage(argv[0]);
2183 SCLogError(
"can't use -s/-S or --firewall-rules-exclusive when detection is disabled");
2190 if (list_app_layer_protocols)
2192 if (list_rule_protocols)
2194 if (list_app_layer_hooks)
2196 if (list_app_layer_frames)
2214 ret = SetBpfString(optind, argv);
2222 int WindowsInitService(
int argc,
char **argv)
2224 if (SCRunningAsService()) {
2225 char path[MAX_PATH];
2227 strlcpy(path, argv[0], MAX_PATH);
2228 if ((
p = strrchr(path,
'\\'))) {
2231 if (!SetCurrentDirectory(path)) {
2232 SCLogError(
"Can't set current directory to: %s", path);
2235 SCLogInfo(
"Current directory is set to: %s", path);
2236 SCServiceInit(argc, argv);
2241 if (0 != WSAStartup(MAKEWORD(2, 2), &wsaData)) {
2242 SCLogError(
"Can't initialize Windows sockets: %d", WSAGetLastError());
2253 const char *pid_filename;
2256 SCLogInfo(
"Use pid file %s from config file.", pid_filename);
2263 SCLogError(
"strdup failed: %s", strerror(errno));
2282 SCLogError(
"Unable to create PID file, concurrent run of"
2283 " Suricata can occur.");
2284 SCLogError(
"PID file creation WILL be mandatory for daemon mode"
2285 " in future version");
2300 if (
SCConfGet(
"run-as.user", &
id) == 1) {
2304 if (
SCConfGet(
"run-as.group", &
id) == 1) {
2322 static int InitSignalHandler(
SCInstance *suri)
2325 #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
2330 if (
SCConfGetBool(
"logging.stacktrace-on-signal", &enabled) == 0) {
2335 SCLogInfo(
"Preparing unexpected signal handling");
2336 struct sigaction stacktrace_action;
2337 memset(&stacktrace_action, 0,
sizeof(stacktrace_action));
2338 stacktrace_action.sa_sigaction = SignalHandlerUnexpected;
2339 stacktrace_action.sa_flags = SA_SIGINFO;
2340 sigaction(SIGSEGV, &stacktrace_action, NULL);
2341 sigaction(SIGABRT, &stacktrace_action, NULL);
2364 #ifdef PROFILE_RULES
2365 SCProfilingRulesGlobalInit();
2372 #ifdef PROFILE_RULES
2426 SCPrintElapsedTime(start_time);
2500 PrintUsage(argv[0]);
2510 case RUNMODE_INSTALL_SERVICE:
2511 if (SCServiceInstall(argc, argv)) {
2514 SCLogInfo(
"Suricata service has been successfully installed.");
2516 case RUNMODE_REMOVE_SERVICE:
2517 if (SCServiceRemove()) {
2520 SCLogInfo(
"Suricata service has been successfully removed.");
2522 case RUNMODE_CHANGE_SERVICE_PARAMS:
2523 if (SCServiceChangeParams(argc, argv)) {
2526 SCLogInfo(
"Suricata service startup parameters has been successfully changed.");
2543 SCLogError(
"Please specify a runmode or capture option. "
2544 "Use --list-runmodes to see available runmodes.");
2559 static void SetupDelayedDetect(
SCInstance *suri)
2568 if (decnf != NULL) {
2570 if (strcmp(denode->
val,
"delayed-detect") == 0) {
2581 SCLogInfo(
"Packets will start being processed before signatures are active.");
2599 static int ConfigGetCaptureValue(
SCInstance *suri)
2603 intmax_t tmp_max_pending_packets;
2604 if (
SCConfGetInt(
"max-pending-packets", &tmp_max_pending_packets) != 1)
2606 if (tmp_max_pending_packets < 1 || tmp_max_pending_packets > 2147483648) {
2607 SCLogError(
"Maximum max-pending-packets setting is 2147483648 and must be greater than 0. "
2608 "Please check %s for errors",
2619 const char *temp_default_packet_size;
2620 if ((
SCConfGetNonNull(
"default-packet-size", &temp_default_packet_size)) != 1) {
2623 int strip_trailing_plus = 0;
2633 const int mtu = GetGlobalMTUWin32();
2647 strip_trailing_plus = 1;
2653 for (lthread = 0; lthread < nlive; lthread++) {
2656 (void)
strlcpy(dev, live_dev,
sizeof(dev));
2658 if (strip_trailing_plus) {
2659 size_t len = strlen(dev);
2661 (dev[
len-1] ==
'+' ||
2662 dev[
len-1] ==
'^' ||
2681 SCLogError(
"Error parsing max-pending-packets "
2682 "from conf file - %s. Killing engine",
2683 temp_default_packet_size);
2693 static void PostRunStartedDetectSetup(
const SCInstance *suri)
2707 SCLogNotice(
"Signature(s) loaded, Detect thread(s) activated.");
2719 SetupDelayedDetect(suri);
2722 int default_tenant = 0;
2724 (void)
SCConfGetBool(
"multi-detect.default", &default_tenant);
2727 "detection engine contexts failed.");
2737 FatalError(
"initializing detection engine failed.");
2753 static void PostConfLoadedSetupHostMode(
void)
2755 const char *hostmode = NULL;
2758 if (!strcmp(hostmode,
"router")) {
2760 }
else if (!strcmp(hostmode,
"bridge")) {
2762 }
else if (!strcmp(hostmode,
"sniffer-only")) {
2765 if (strcmp(hostmode,
"auto") != 0) {
2786 SCLogInfo(
"No 'host-mode': suricata is in IPS mode, using "
2787 "default setting 'router'");
2791 SCLogInfo(
"No 'host-mode': suricata is in IDS mode, using "
2792 "default setting 'sniffer-only'");
2804 FatalError(
"could not set USER mode logdir");
2810 FatalError(
"could not set USER mode datadir");
2822 int cnf_firewall_enabled = 0;
2823 if (
SCConfGetBool(
"firewall.enabled", &cnf_firewall_enabled) == 1) {
2824 if (cnf_firewall_enabled == 1) {
2828 FatalError(
"firewall mode enabled through commandline, but disabled in config");
2833 SCLogWarning(
"firewall mode is EXPERIMENTAL and subject to change");
2841 int disable_offloading;
2842 if (
SCConfGetBool(
"capture.disable-offloading", &disable_offloading) == 0)
2843 disable_offloading = 1;
2844 if (disable_offloading) {
2851 const char *cv = NULL;
2853 if (strcmp(cv,
"none") == 0) {
2855 }
else if (strcmp(cv,
"all") == 0) {
2862 SCConfSet(
"stream.checksum-validation",
"0");
2865 SCConfSet(
"stream.checksum-validation",
"1");
2874 #ifdef HAVE_PACKET_EBPF
2876 EBPFRegisterExtension();
2899 SCLogInfo(
"Setting engine mode to IDS mode by default");
2920 const char *custom_umask;
2923 if (
StringParseUint16(&mask, 8, (uint16_t)strlen(custom_umask), custom_umask) > 0) {
2924 umask((mode_t)mask);
2941 SCLogInfo(
"== Carrying out Engine Analysis ==");
2942 const char *temp = NULL;
2943 if (
SCConfGet(
"engine-analysis", &temp) == 0) {
2944 SCLogInfo(
"no engine-analysis parameter(s) defined in conf file. "
2945 "Please define/enable them in the conf to use this "
2964 "basic address vars test failed. Please check %s for errors", suri->
conf_filename);
2993 "supplied by %s (default-log-dir) doesn't exist. "
2994 "Shutting down the engine",
2998 if (!IsLogDirectoryWritable(suri->
log_dir)) {
3000 "supplied by %s (default-log-dir) is not writable. "
3001 "Shutting down the engine",
3019 PostConfLoadedSetupHostMode();
3086 return EXIT_FAILURE;
3109 SCInstanceInit(&
suricata, progname);
3127 if (
SCConfGetBool(
"vlan.use-for-tracking", &tracking) == 1 && !tracking) {
3131 SCLogDebug(
"vlan tracking is %s", tracking == 1 ?
"enabled" :
"disabled");
3132 if (
SCConfGetBool(
"livedev.use-for-tracking", &tracking) == 1 && !tracking) {
3136 if (
SCConfGetBool(
"decoder.recursion-level.use-for-tracking", &tracking) == 1 && !tracking) {
3152 SCLogInfo(
"Running suricata under test mode");
3186 SCLogNotice(
"Configuration provided was successfully loaded. Exiting.");
3229 int limit_nproc = 0;
3230 if (
SCConfGetBool(
"security.limit-noproc", &limit_nproc) == 0) {
3234 #if defined(SC_ADDRESS_SANITIZER)
3237 "\"security.limit-noproc\" (setrlimit()) not set when using address sanitizer");
3243 #if defined(HAVE_SYS_RESOURCE_H) && defined(RLIMIT_NPROC)
3246 SCLogWarning(
"setrlimit has no effect when running as root.");
3249 struct rlimit r = { 0, 0 };
3250 if (setrlimit(RLIMIT_NPROC, &r) != 0) {
3251 SCLogWarning(
"setrlimit failed to prevent process creation.");
3277 PostRunStartedDetectSetup(&
suricata);
@ RUNMODE_LIST_APP_LAYERS
enum SCRunModes SCRunMode
@ RUNMODE_ENGINE_ANALYSIS
void TmModuleUnixManagerRegister(void)
void StatsReleaseResources(void)
Releases the resources allotted by the Stats API.
#define DETECT_ENGINE_MPM_CACHE_OP_PRUNE
void TmModuleReceiveIPFWRegister(void)
Registration Function for RecieveIPFW.
void SuricataMainLoop(void)
int ExceptionSimulationCommandLineParser(const char *name, const char *arg)
char * firewall_rule_file
void AppLayerHtpNeedFileInspection(void)
Sets a flag that informs the HTP app layer that some module in the engine needs the http request file...
void TmThreadDisablePacketThreads(const uint16_t set, const uint16_t check, const uint8_t module_flags)
Disable all packet threads.
enum SCRunModes aux_run_mode
void IPPairInitConfig(bool quiet)
initialize the configuration
void SCLogInitLogModule(SCLogInitData *sc_lid)
Initializes the logging module.
void EngineModeSetIPS(const enum EngineHostMode mode)
void SCEnableDefaultSignalHandlers(void)
Enable default signal handlers.
int LiveDeviceListClean(void)
void DetectEngineDeReference(DetectEngineCtx **de_ctx)
struct timeval start_time
bool IsRunModeOffline(enum SCRunModes run_mode_to_check)
#define SC_ATOMIC_INIT(name)
wrapper for initializing an atomic variable.
SystemHugepageSnapshot * prerun_snap
void TmThreadContinueThreads(void)
Unpauses all threads present in tv_root.
enum DetectEngineType type
int SigLoadSignatures(DetectEngineCtx *de_ctx, char *sig_file, bool sig_file_exclusive)
Load signatures.
const char * firewall_rule_file_exclusive
#define SC_ATOMIC_SET(name, val)
Set the value for the atomic variable.
@ RUNMODE_LIST_APP_LAYER_FRAMES
SCConfNode * SCConfGetRootNode(void)
Get the root configuration node.
DetectEngineCtx * DetectEngineCtxInitStubForDD(void)
void LiveDevRegisterExtension(void)
void OutputTxShutdown(void)
void AppLayerHtpPrintStats(void)
void StatsSetupPostConfigPreOutput(void)
char * runmode_custom_mode
struct HtpBodyChunk_ * next
void TmModuleReceiveNFQRegister(void)
void DetectEngineMpmCacheService(uint32_t op_flags)
int LiveBuildDeviceList(const char *runmode)
void RunModeShutDown(void)
void SCProtoNameInit(void)
void SuricataPostInit(void)
void RunModeDispatch(int runmode, const char *custom_mode, const char *capture_plugin_name, const char *capture_plugin_args)
volatile sig_atomic_t sigint_count
SC_ATOMIC_DECLARE(unsigned int, engine_stage)
void TmModuleRunDeInit(void)
void TmThreadsUnsealThreads(void)
void RegisterFlowBypassInfo(void)
#define SCSetThreadName(n)
int SCConfYamlHandleInclude(SCConfNode *parent, const char *filename)
Include a file in the configuration.
void SCLogDeInitLogModule(void)
De-Initializes the logging module.
void TmModuleDecodeErfFileRegister(void)
Register the ERF file decoder module.
main detection engine ctx
int StringParseUint16(uint16_t *res, int base, size_t len, const char *str)
void DetectEngineReloadSetIdle(void)
void DatalinkTableDeinit(void)
int SCConfGet(const char *name, const char **vptr)
Retrieve the value of a configuration node.
DetectEngineCtx * DetectEngineGetCurrent(void)
int EngineModeIsUnknown(void)
void VarNameStoreInit(void)
void TmModuleFlowRecyclerRegister(void)
int SCConfNodeChildValueIsTrue(const SCConfNode *node, const char *key)
Test if a configuration node has a true value.
void DatalinkTableInit(void)
void Daemonize(void)
Daemonize the process.
void UtilSignalHandlerSetup(int sig, void(*handler)(int))
#define TAILQ_FOREACH(var, head, field)
void EngineModeSetFirewall(const enum EngineHostMode mode)
void TmModuleDecodeAFPRegister(void)
Registration Function for DecodeAFP.
void TmModuleDecodeWinDivertRegister(void)
void UtilCpuEnableSparcMisalignEmulation(void)
Handle memory access miss align on SPARC processors.
int DetectEngineAddToMaster(DetectEngineCtx *de_ctx)
int SCConfGetChildValueBool(const SCConfNode *base, const char *name, int *val)
void TmModuleStatsLoggerRegister(void)
void RegisterAllModules(void)
int DetectEngineMultiTenantSetup(const bool unix_socket)
setup multi-detect / multi-tenancy
void SupportFastPatternForSigMatchTypes(void)
Registers the keywords(SMs) that should be given fp support.
bool EngineHostModeIsSniffer(void)
TmEcode SCParseCommandLine(int argc, char **argv)
int CheckValidDaemonModes(int daemon, int mode)
Check for a valid combination daemon/mode.
void SCGetGroupID(const char *group_name, uint32_t *gid)
Function to get the group ID from the specified group name.
int SCConfGetBool(const char *name, int *val)
Retrieve a configuration value as a boolean.
enum EngineHostMode g_engine_host_mode
void TmThreadDisableReceiveThreads(void)
Disable all threads having the specified TMs.
void StatsInit(void)
Initializes the perf counter api. Things are hard coded currently. More work to be done when we imple...
void PreRunInit(const int runmode)
void MacSetRegisterFlowStorage(void)
void SuricataShutdown(void)
const char * conf_filename
int GetIfaceMTU(const char *dev)
output the link MTU
void GlobalsInitPreConfig(void)
void TmModuleReceiveNetmapRegister(void)
void PacketPoolPostRunmodes(void)
Set the max_pending_return_packets value.
void NFQInitConfig(bool quiet)
To initialize the NFQ global configuration data.
void TmModuleReceiveWinDivertRegister(void)
bool EngineModeIsFirewall(void)
void SCProfilingDestroy(void)
Free resources used by profiling.
void AFPPeersListClean(void)
Clean the global peers list.
void RunModeInitializeOutputs(void)
int DetectPortTestConfVars(void)
void SCThresholdConfGlobalInit(void)
void DecodeUnregisterCounters(void)
const char * capture_plugin_name
int SCConfYamlLoadFile(const char *filename)
Load configuration from a YAML file.
void HostBitInitCtx(void)
bool IsRunModeSystem(enum SCRunModes run_mode_to_check)
const char * capture_plugin_args
void ThresholdRegisterGlobalCounters(void)
void TmModuleLoggerRegister(void)
void PacketPoolInit(void)
int AppLayerDeSetup(void)
De initializes the app layer.
@ RUNMODE_LIST_APP_LAYER_HOOKS
size_t strlcpy(char *dst, const char *src, size_t siz)
void PcapTranslateIPToDevice(char *pcap_dev, size_t len)
void FlowDisableFlowRecyclerThread(void)
Used to disable flow recycler thread(s).
void SCRunmodeSet(SCRunMode run_mode)
Set the current run mode.
void TmModuleDecodePcapFileRegister(void)
void TmModuleBypassedFlowManagerRegister(void)
void IPPairShutdown(void)
shutdown the flow engine
void SCConfInit(void)
Initialize the configuration system.
void DetectParseFreeRegexes(void)
void SCConfDump(void)
Dump configuration to stdout.
void TmModuleDecodeNFLOGRegister(void)
int NFQParseAndRegisterQueues(const char *queues)
Parses and adds Netfilter queue(s).
void FlowInitConfig(bool quiet)
initialize the configuration
int AppLayerSetup(void)
Setup the app layer.
void FeatureTrackingRegister(void)
void TmModuleReceiveDPDKRegister(void)
void UnixManagerThreadSpawnNonRunmode(const bool unix_socket_enabled)
void RunModeInitializeThreadSettings(void)
void StreamTcpInitConfig(bool)
To initialize the stream global configuration data.
int GetIfaceMaxPacketSize(LiveDevice *ld)
output max packet size for a link
SCRunMode SCRunmodeGet(void)
Get the current run mode.
void TmModuleDecodeNetmapRegister(void)
Registration Function for DecodeNetmap.
void PreRunPostPrivsDropInit(const int runmode)
void SigTableCleanup(void)
int DetectEngineMoveToFreeList(DetectEngineCtx *de_ctx)
volatile sig_atomic_t sigterm_count
TmEcode TmThreadWaitOnThreadInit(void)
Used to check if all threads have finished their initialization. On finding an un-initialized thread,...
const char * SCLogLevel2Name(const SCLogLevel lvl)
void TmModuleVerdictNFQRegister(void)
void AppLayerRegisterGlobalCounters(void)
HACK to work around our broken unix manager (re)init loop.
int SCFinalizeRunMode(int argc)
void RunModeListRunmodes(void)
Lists all registered runmodes.
size_t strlcat(char *, const char *src, size_t siz)
void LiveSetOffloadDisable(void)
void StatsSetupPostConfigPostOutput(void)
void EngineModeSetIDS(void)
void TmModuleReceiveAFPRegister(void)
Registration Function for RecieveAFP.
int LiveBuildDeviceListCustom(const char *runmode, const char *itemname)
LiveDevice * LiveGetDevice(const char *name)
Get a pointer to the device at idx.
void UnixSocketKillSocketThread(void)
void TmModuleVerdictIPFWRegister(void)
Registration Function for VerdictIPFW.
int SCConfGetInt(const char *name, intmax_t *val)
Retrieve a configuration value as an integer.
bool g_stats_eps_per_app_proto_errors
void HttpRangeContainersInit(void)
struct timeval last_reload
void TmModuleVerdictWinDivertRegister(void)
void HostCleanup(void)
Cleanup the host engine.
void FlowDisableFlowManagerThread(void)
Used to disable flow manager thread(s).
int SCConfGetNonNull(const char *name, const char **vptr)
Retrieve the non-null value of a configuration node.
int UtilSignalUnblock(int signum)
int DetectEngineEnabled(void)
Check if detection is enabled.
void TmThreadClearThreadsFamily(int family)
#define THV_REQ_FLOW_LOOP
void FlowRateRegisterFlowStorage(void)
void TmModuleRunInit(void)
void HTPAtExitPrintStats(void)
Print the stats of the HTTP requests.
int UtilSignalBlock(int signum)
void SCProfilingPrefilterGlobalInit(void)
void ThresholdDestroy(void)
#define SCLogWarning(...)
Macro used to log WARNING messages.
int PostConfLoadedSetup(SCInstance *suri)
const char * GetProgramVersion(void)
get string with program version
void TmModuleReceivePcapFileRegister(void)
int32_t CoredumpLoadConfig(void)
Configures the core dump size.
int IPFWRegisterQueue(char *queue)
Add an IPFW divert.
int ListAppLayerHooks(const char *conf_filename)
int ListAppLayerProtocols(const char *conf_filename)
void DatasetsDestroy(void)
void UtilCpuPrintSummary(void)
Print a summary of CPUs detected (configured and online)
int profiling_packets_enabled
int SystemDNotifyReady(void)
void TmThreadKillThreads(void)
void OutputDeregisterAll(void)
Deregister all modules. Useful for a memory clean exit.
void PostConfLoadedDetectSetup(SCInstance *suri)
int EngineModeIsIDS(void)
TmModule tmm_modules[TMM_SIZE]
const char * SCConfigGetLogDirectory(void)
void OutputNotifyFileRotation(void)
Notifies all registered file rotation notification flags.
void VarNameStoreDestroy(void)
void TmModuleFlowWorkerRegister(void)
uint32_t max_pending_packets
const char ** additional_configs
#define DEFAULT_PID_FILENAME
volatile sig_atomic_t sighup_count
TmEcode ConfigSetDataDirectory(char *name)
void TmModuleDecodeErfDagRegister(void)
Register the ERF file decoder module.
#define SCDropMainThreadCaps(...)
void TmModuleDebugList(void)
void TmModuleDecodeNFQRegister(void)
void SCProtoNameRelease(void)
int RunmodeIsUnittests(void)
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
void TmModuleReceiveNFLOGRegister(void)
#define DEFAULT_PACKET_SIZE
#define WarnInvalidConfEntry(param_name, format, value)
Generic API that can be used by all to log an invalid conf entry.
#define TM_FLAG_RECEIVE_TM
void TmModuleReceiveErfFileRegister(void)
Register the ERF file receiver (reader) module.
int SCConfSetFromString(const char *input, int final)
Set a configuration parameter from a string.
int SCConfSetFinal(const char *name, const char *val)
Set a final configuration value.
#define SCRealloc(ptr, sz)
void TmModuleDecodeAFXDPRegister(void)
Registration Function for DecodeAFXDP.
uint32_t default_packet_size
void SigTableApplyStrictCommandLineOption(const char *str)
@ DETECT_ENGINE_TYPE_NORMAL
void TmThreadKillThreadsFamily(int family)
void FeatureTrackingRelease(void)
void TmqhCleanup(void)
Clean up registration time allocs.
void StreamTcpFreeConfig(bool quiet)
void DecodeGlobalConfig(void)
char * strict_rule_parsing_string
DetectEngineCtx * DetectEngineCtxInitStubForMT(void)
const char * LiveGetDeviceName(int number)
Get a pointer to the device name at idx.
void FlowShutdown(void)
shutdown the flow engine
void SCHInfoLoadFromConfig(void)
Load the host os policy information from the configuration.
void DetectEngineBumpVersion(void)
void TmModuleFlowManagerRegister(void)
int SCStartInternalRunMode(int argc, char **argv)
int SCPidfileTestRunning(const char *pid_filename)
Check the Suricata pid file (used at the startup)
void HostShutdown(void)
shutdown the flow engine
#define SCFstatFn(fd, statbuf)
void LiveSetOffloadWarn(void)
void ParseSizeDeinit(void)
void SCConfDeInit(void)
De-initializes the configuration system.
void RunModeRegisterRunModes(void)
Register all runmodes in the engine.
int ListRuleProtocols(const char *conf_filename)
void SCProfilingDump(void)
void TmModuleReceiveAFXDPRegister(void)
void EngineStop(void)
make sure threads can stop the engine by calling this function. Purpose: pcap file mode needs to be a...
int ParseSizeStringU32(const char *size, uint32_t *res)
bool EngineHostModeIsBridge(void)
void TmModuleReceiveErfDagRegister(void)
Register the ERF file receiver (reader) module.
void IPPairBitInitCtx(void)
TmEcode ConfigSetLogDirectory(const char *name)
void TmModuleDecodeIPFWRegister(void)
Registration Function for DecodeIPFW.
int ConfUnixSocketIsEnable(void)
#define TM_FLAG_PACKET_ALL
struct SCLogConfig_ SCLogConfig
Holds the config state used by the logging api.
#define DETECT_ENGINE_MPM_CACHE_OP_SAVE
volatile sig_atomic_t sigusr2_count
void SystemHugepageSnapshotDestroy(SystemHugepageSnapshot *s)
void TmModuleDecodePcapRegister(void)
Registration Function for DecodePcap.
TmEcode SCLoadYamlConfig(void)
TmEcode ConfigCheckDataDirectory(const char *data_dir)
SCConfNode * SCConfGetNode(const char *name)
Get a SCConfNode by name.
#define SCLogError(...)
Macro used to log ERROR messages.
int DetectEngineReloadStart(void)
void TopologyDestroy(void)
#define DEFAULT_CONF_FILE
#define SC_LOG_MAX_LOG_MSG_LEN
void AppLayerParserPostStreamSetup(void)
void TmModuleReceivePcapRegister(void)
Registration Function for ReceivePcap.
void SCGetUserID(const char *user_name, const char *group_name, uint32_t *uid, uint32_t *gid)
Function to get the user and group ID from the specified user name.
bool install_signal_handlers
void TmModuleRespondRejectRegister(void)
void CoredumpEnable(void)
Enable coredumps on systems where coredumps can and need to be enabled.
void RunUnittests(int list_unittests, const char *regex_arg)
TmEcode ConfigCheckLogDirectoryExists(const char *log_dir)
int SCConfSet(const char *name, const char *val)
Set a configuration value.
void PacketAlertTagInit(void)
int RunModeEngineIsIPS(int capture_mode, const char *runmode, const char *capture_plugin_name)
DetectEngineCtx * DetectEngineCtxInit(void)
void SCOnLoggingReady(void)
Invokes all registered logging ready callbacks.
void TmModuleDecodeLibRegister(void)
register a "Decode" module for suricata as a library.
int EngineModeIsIPS(void)
int ListAppLayerFrames(const char *conf_filename)
void SCProfilingKeywordsGlobalInit(void)
void EngineDone(void)
Used to indicate that the current task is done.
bool firewall_rule_file_exclusive
const char * GetDocURL(void)
void PostRunDeinit(const int runmode, struct timeval *start_time)
clean up / shutdown code for packet modes
void HostInitConfig(bool quiet)
initialize the configuration
TmEcode TmThreadWaitOnThreadRunning(void)
Waits for all threads to be in a running state.
void HttpRangeContainersDestroy(void)
void SCLogLoadConfig(int daemon, int verbose, uint32_t userid, uint32_t groupid)
int DetectEngineReload(const SCInstance *suri)
Reload the detection engine.
#define DEFAULT_MAX_PENDING_PACKETS
void DetectEngineClearMaster(void)
void SetMasterExceptionPolicy(void)
void TmThreadCheckThreadState(void)
Used to check the thread for certain conditions of failure.
void OutputFilestoreRegisterGlobalCounters(void)
int InitGlobal(void)
Global initialization common to all runmodes.
int LiveGetDeviceCount(void)
Get the number of registered devices.
SystemHugepageSnapshot * SystemHugepageSnapshotCreate(void)
The function creates a snapshot of the system's hugepage usage per NUMA node and per hugepage size....
void SCProfilingSghsGlobalInit(void)
@ RUNMODE_LIST_RULE_PROTOS
int SCPidfileCreate(const char *pidfile)
Write a pid file (used at the startup) This commonly needed by the init scripts.
int LiveRegisterDeviceName(const char *dev)
Add a device for monitoring.
#define SCStatFn(pathname, statbuf)
void LiveDeviceFinalize(void)
void TmModuleDecodeDPDKRegister(void)
Registration Function for DecodeDPDK.
void PacketPoolDestroy(void)
void HTPFreeConfig(void)
Clears the HTTP server configuration memory used by HTP library.
void LandlockSandboxing(SCInstance *suri)
int ListKeywords(const char *keyword_info)
#define SCLogNotice(...)
Macro used to log NOTICE messages.
void SuricataPreInit(const char *progname)
const char ** additional_plugins
void DPDKCleanupEAL(void)
@ RUNMODE_PRINT_BUILDINFO
void SCPidfileRemove(const char *pid_filename)
Remove the pid file (used at the startup)
void NFQContextsClean(void)
Clean global contexts. Must be called on exit.
void SystemHugepageEvaluateHugepages(SystemHugepageSnapshot *pre_s, SystemHugepageSnapshot *post_s)
The function compares two hugepage snapshots and prints out recommendations for hugepage configuratio...
#define DEBUG_VALIDATE_BUG_ON(exp)
void SCProfilingInit(void)
Initialize profiling.
void GlobalsDestroy(void)
@ ENGINE_HOST_IS_SNIFFER_ONLY
int DetectEngineReloadIsStart(void)
int SCStorageFinalize(void)
volatile uint8_t suricata_ctl_flags
#define TM_FLAG_FLOWWORKER_TM
void TagDestroyCtx(void)
Destroy tag context hash tables.
int DetectAddressTestConfVars(void)
void FlowWorkToDoCleanup(void)
Clean up all the flows that have unprocessed segments and have some work to do in the detection engin...
void MpmHSGlobalCleanup(void)
void SCPluginsLoad(const char *capture_plugin_name, const char *capture_plugin_args, const char **additional_plugins)
void TmqResetQueues(void)