suricata
util-lua-sandbox.c File Reference
#include "suricata-common.h"
#include "lua.h"
#include "lauxlib.h"
#include "lualib.h"
#include "util-debug.h"
#include "util-lua-sandbox.h"
#include "util-lua-builtins.h"
#include "util-validate.h"
Include dependency graph for util-lua-sandbox.c:

Go to the source code of this file.

Macros

#define SANDBOX_CTX   "SANDBOX_CTX"
 

Functions

void SCLuaSbLoadLibs (lua_State *L)
 
lua_State * SCLuaSbStateNew (uint64_t alloclimit, uint64_t instructionlimit)
 Allocate a new Lua sandbox. More...
 
SCLuaSbState * SCLuaSbGetContext (lua_State *L)
 
void SCLuaSbStateClose (lua_State *L)
 
uint64_t SCLuaSbResetBytesLimit (lua_State *L)
 
void SCLuaSbUpdateBytesLimit (lua_State *L)
 
void SCLuaSbRestoreBytesLimit (lua_State *L, const uint64_t cfg_limit)
 
void SCLuaSbResetInstructionCounter (lua_State *L)
 

Detailed Description

Macro Definition Documentation

◆ SANDBOX_CTX

#define SANDBOX_CTX   "SANDBOX_CTX"

Definition at line 37 of file util-lua-sandbox.c.

Function Documentation

◆ SCLuaSbGetContext()

SCLuaSbState* SCLuaSbGetContext ( lua_State *  L)

Get the Suricata Lua sandbox context from the lua_State.

Note: May return null if this Lua state was not allocated from the sandbox.

Definition at line 359 of file util-lua-sandbox.c.

References ctx, and SANDBOX_CTX.

Referenced by SCLuaSbResetBytesLimit(), SCLuaSbResetInstructionCounter(), SCLuaSbRestoreBytesLimit(), SCLuaSbStateClose(), and SCLuaSbUpdateBytesLimit().

Here is the caller graph for this function:

◆ SCLuaSbLoadLibs()

void SCLuaSbLoadLibs ( lua_State *  L)

Load allowed Lua libraries into the state.

Functions from each library that are not in the allowed list are replaced with LuaBlockedFunction.

Definition at line 287 of file util-lua-sandbox.c.

◆ SCLuaSbResetBytesLimit()

uint64_t SCLuaSbResetBytesLimit ( lua_State *  L)

Definition at line 392 of file util-lua-sandbox.c.

References SCLuaSbState::alloc_limit, and SCLuaSbGetContext().

Referenced by DetectLuaMatchBuffer().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ SCLuaSbResetInstructionCounter()

void SCLuaSbResetInstructionCounter ( lua_State *  L)

Reset the instruction counter for the provided state.

Definition at line 422 of file util-lua-sandbox.c.

References SCLuaSbState::blocked_function_error, SCLuaSbState::instruction_count, SCLuaSbState::instruction_count_error, and SCLuaSbGetContext().

Here is the call graph for this function:

◆ SCLuaSbRestoreBytesLimit()

void SCLuaSbRestoreBytesLimit ( lua_State *  L,
const uint64_t  cfg_limit 
)

Definition at line 411 of file util-lua-sandbox.c.

References SCLuaSbState::alloc_limit, and SCLuaSbGetContext().

Referenced by DetectLuaMatchBuffer().

Here is the call graph for this function:
Here is the caller graph for this function:

◆ SCLuaSbStateClose()

void SCLuaSbStateClose ( lua_State *  L)

Definition at line 368 of file util-lua-sandbox.c.

References SCLuaSbState::alloc_bytes, BUG_ON, SCLuaSbState::L, SCFree, and SCLuaSbGetContext().

Here is the call graph for this function:

◆ SCLuaSbStateNew()

lua_State* SCLuaSbStateNew ( uint64_t  alloclimit,
uint64_t  instructionlimit 
)

Allocate a new Lua sandbox.

Returns
An allocated sandbox state or NULL if memory allocation fails.

Definition at line 327 of file util-lua-sandbox.c.

References SCLuaSbState::alloc_bytes, SCLuaSbState::alloc_limit, SCLuaSbState::hook_instruction_count, SCLuaSbState::instruction_limit, SCLuaSbState::L, and SCCalloc.

◆ SCLuaSbUpdateBytesLimit()

void SCLuaSbUpdateBytesLimit ( lua_State *  L)

Definition at line 403 of file util-lua-sandbox.c.

References SCLuaSbState::alloc_bytes, SCLuaSbState::alloc_limit, and SCLuaSbGetContext().

Referenced by DetectLuaMatchBuffer().

Here is the call graph for this function:
Here is the caller graph for this function: