suricata
util-mpm.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2021 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * Pattern matcher utility Functions
24  */
25 
26 #include "suricata-common.h"
27 #include "util-mpm.h"
28 #include "util-debug.h"
29 
30 /* include pattern matchers */
31 #include "util-mpm-ac.h"
32 #include "util-mpm-ac-ks.h"
33 #include "util-mpm-hs.h"
34 #include "util-hashlist.h"
35 
36 #include "detect-engine.h"
37 #include "util-misc.h"
38 #include "conf.h"
39 #include "conf-yaml-loader.h"
40 #include "queue.h"
41 #include "util-memcpy.h"
42 #ifdef BUILD_HYPERSCAN
43 #include "hs.h"
44 #endif
45 
48 
49 /**
50  * \brief Register a new Mpm Context.
51  *
52  * \param name A new profile to be registered to store this MpmCtx.
53  * \param sm_list sm_list for this name (might be variable with xforms)
54  * \param alproto app proto or ALPROTO_UNKNOWN if not for app-layer
55  *
56  * \retval id Return the id created for the new MpmCtx profile.
57  */
59  DetectEngineCtx *de_ctx, const char *name, const int sm_list, const AppProto alproto)
60 {
61  /* the very first entry */
62  if (de_ctx->mpm_ctx_factory_container == NULL) {
64  if (de_ctx->mpm_ctx_factory_container == NULL) {
65  FatalError("Error allocating memory");
66  }
68  }
69 
71  MpmCtxFactoryItem *pitem = NULL;
72  while (item) {
73  if (item->sm_list == sm_list && item->alproto == alproto && item->name != NULL &&
74  strcmp(item->name, name) == 0) {
75  return item->id;
76  }
77  pitem = item;
78  item = item->next;
79  }
80 
81  MpmCtxFactoryItem *nitem = SCCalloc(1, sizeof(MpmCtxFactoryItem));
82  if (unlikely(nitem == NULL)) {
83  FatalError("Error allocating memory");
84  }
85  nitem->name = name;
86  nitem->sm_list = sm_list;
88  nitem->alproto = alproto;
89 
90  /* toserver */
91  nitem->mpm_ctx_ts = SCCalloc(1, sizeof(MpmCtx));
92  if (nitem->mpm_ctx_ts == NULL) {
93  FatalError("Error allocating memory");
94  }
96 
97  /* toclient */
98  nitem->mpm_ctx_tc = SCCalloc(1, sizeof(MpmCtx));
99  if (nitem->mpm_ctx_tc == NULL) {
100  FatalError("Error allocating memory");
101  }
103 
104  /* store the newly created item */
105  if (pitem == NULL)
107  else
108  pitem->next = nitem;
109 
110  return nitem->id;
111 }
112 
114 {
115  if (mpm_ctx == NULL)
116  return 0;
117 
118  if (de_ctx->mpm_ctx_factory_container == NULL) {
119  return 0;
120  }
121 
122  for (MpmCtxFactoryItem *i = de_ctx->mpm_ctx_factory_container->items; i != NULL; i = i->next) {
123  if (mpm_ctx == i->mpm_ctx_ts || mpm_ctx == i->mpm_ctx_tc) {
124  return 1;
125  }
126  }
127  return 0;
128 }
129 
130 MpmCtx *MpmFactoryGetMpmCtxForProfile(const DetectEngineCtx *de_ctx, int32_t id, int direction)
131 {
132  if (id == MPM_CTX_FACTORY_UNIQUE_CONTEXT) {
133  MpmCtx *mpm_ctx = SCCalloc(1, sizeof(MpmCtx));
134  if (unlikely(mpm_ctx == NULL)) {
135  FatalError("Error allocating memory");
136  }
137  return mpm_ctx;
138  } else if (id < -1) {
139  SCLogError("Invalid argument - %d\n", id);
140  return NULL;
141  } else if (id >= de_ctx->mpm_ctx_factory_container->max_id) {
142  /* this id does not exist */
143  return NULL;
144  } else {
146  i = i->next) {
147  if (id == i->id) {
148  return (direction == 0) ? i->mpm_ctx_ts : i->mpm_ctx_tc;
149  }
150  }
151  return NULL;
152  }
153 }
154 
156 {
157  if (mpm_ctx == NULL)
158  return;
159 
160  if (!MpmFactoryIsMpmCtxAvailable(de_ctx, mpm_ctx)) {
161  if (mpm_ctx->mpm_type != MPM_NOTSET)
162  mpm_table[mpm_ctx->mpm_type].DestroyCtx(mpm_ctx);
163  SCFree(mpm_ctx);
164  }
165 }
166 
168 {
169  if (de_ctx->mpm_ctx_factory_container == NULL)
170  return;
171 
173  while (item) {
174  if (item->mpm_ctx_ts != NULL) {
175  if (item->mpm_ctx_ts->mpm_type != MPM_NOTSET)
177  SCFree(item->mpm_ctx_ts);
178  }
179  if (item->mpm_ctx_tc != NULL) {
180  if (item->mpm_ctx_tc->mpm_type != MPM_NOTSET)
182  SCFree(item->mpm_ctx_tc);
183  }
184 
185  MpmCtxFactoryItem *next = item->next;
186  SCFree(item);
187  item = next;
188  }
189 
192 }
193 
194 void MpmInitThreadCtx(MpmThreadCtx *mpm_thread_ctx, MpmCtx *mpm_ctx, uint16_t matcher)
195 {
196  if (mpm_table[matcher].InitThreadCtx != NULL) {
197  mpm_table[matcher].InitThreadCtx(mpm_ctx, mpm_thread_ctx);
198  }
199 }
200 
201 void MpmDestroyThreadCtx(MpmThreadCtx *mpm_thread_ctx, const uint16_t matcher)
202 {
203  if (mpm_table[matcher].DestroyThreadCtx != NULL) {
204  mpm_table[matcher].DestroyThreadCtx(NULL, mpm_thread_ctx);
205  }
206 }
207 
208 void MpmInitCtx(MpmCtx *mpm_ctx, uint8_t matcher)
209 {
210  mpm_ctx->mpm_type = matcher;
211  mpm_table[matcher].InitCtx(mpm_ctx);
212 }
213 
214 /* MPM matcher to use by default, i.e. when "mpm-algo" is set to "auto".
215  * If Hyperscan is available, use it. Otherwise, use AC. */
216 #ifdef BUILD_HYPERSCAN
217 # define DEFAULT_MPM MPM_HS
218 # define DEFAULT_MPM_AC MPM_AC
219 #else
220 # define DEFAULT_MPM MPM_AC
221 #endif
222 
223 void MpmTableSetup(void)
224 {
225  memset(mpm_table, 0, sizeof(mpm_table));
227 
228  MpmACRegister();
230 #ifdef BUILD_HYPERSCAN
231  #ifdef HAVE_HS_VALID_PLATFORM
232  /* Enable runtime check for SSSE3. Do not use Hyperscan MPM matcher if
233  * check is not successful. */
234  if (hs_valid_platform() != HS_SUCCESS) {
235  SCLogInfo("SSSE3 support not detected, disabling Hyperscan for "
236  "MPM");
237  /* Fall back to best Aho-Corasick variant. */
238  mpm_default_matcher = DEFAULT_MPM_AC;
239  } else {
240  MpmHSRegister();
241  }
242  #else
243  MpmHSRegister();
244  #endif /* HAVE_HS_VALID_PLATFORM */
245 #endif /* BUILD_HYPERSCAN */
246 }
247 
248 int MpmAddPatternCS(struct MpmCtx_ *mpm_ctx, uint8_t *pat, uint16_t patlen,
249  uint16_t offset, uint16_t depth,
250  uint32_t pid, SigIntId sid, uint8_t flags)
251 {
252  return mpm_table[mpm_ctx->mpm_type].AddPattern(mpm_ctx, pat, patlen,
253  offset, depth,
254  pid, sid, flags);
255 }
256 
257 int SCMpmAddPatternCI(MpmCtx *mpm_ctx, const uint8_t *pat, uint16_t patlen, uint16_t offset,
258  uint16_t depth, uint32_t pid, SigIntId sid, uint8_t flags)
259 {
260  return mpm_table[mpm_ctx->mpm_type].AddPatternNocase(mpm_ctx, pat, patlen,
261  offset, depth,
262  pid, sid, flags);
263 }
264 
265 
266 /**
267  * \internal
268  * \brief Creates a hash of the pattern. We use it for the hashing process
269  * during the initial pattern insertion time, to cull duplicate sigs.
270  *
271  * \param pat Pointer to the pattern.
272  * \param patlen Pattern length.
273  *
274  * \retval hash A 32 bit unsigned hash.
275  */
276 static inline uint32_t MpmInitHashRaw(const uint8_t *pat, uint16_t patlen)
277 {
278  uint32_t hash = patlen * pat[0];
279  if (patlen > 1)
280  hash += pat[1];
281 
282  return (hash % MPM_INIT_HASH_SIZE);
283 }
284 
285 /**
286  * \internal
287  * \brief Looks up a pattern. We use it for the hashing process during the
288  * the initial pattern insertion time, to cull duplicate sigs.
289  *
290  * \param ctx Pointer to the AC ctx.
291  * \param pat Pointer to the pattern.
292  * \param patlen Pattern length.
293  * \param flags Flags. We don't need this.
294  *
295  * \retval hash A 32 bit unsigned hash.
296  */
297 static inline MpmPattern *MpmInitHashLookup(MpmCtx *ctx, const uint8_t *pat, uint16_t patlen,
298  uint16_t offset, uint16_t depth, uint8_t flags, uint32_t pid)
299 {
300  uint32_t hash = MpmInitHashRaw(pat, patlen);
301 
302  if (ctx->init_hash == NULL) {
303  return NULL;
304  }
305 
306  MpmPattern *t = ctx->init_hash[hash];
307  for ( ; t != NULL; t = t->next) {
308  if (!(flags & MPM_PATTERN_CTX_OWNS_ID)) {
309  if (t->id == pid)
310  return t;
311  } else {
312  if (t->len == patlen && t->offset == offset && t->depth == depth &&
313  memcmp(pat, t->original_pat, patlen) == 0 &&
314  t->flags == flags)
315  {
316  return t;
317  }
318  }
319  }
320 
321  return NULL;
322 }
323 
324 /**
325  * \internal
326  * \brief Allocs a new pattern instance.
327  *
328  * \param mpm_ctx Pointer to the mpm context.
329  *
330  * \retval p Pointer to the newly created pattern.
331  */
332 static inline MpmPattern *MpmAllocPattern(MpmCtx *mpm_ctx)
333 {
334  MpmPattern *p = SCCalloc(1, sizeof(MpmPattern));
335  if (unlikely(p == NULL)) {
336  exit(EXIT_FAILURE);
337  }
338 
339  mpm_ctx->memory_cnt++;
340  mpm_ctx->memory_size += sizeof(MpmPattern);
341 
342  return p;
343 }
344 
345 /**
346  * \internal
347  * \brief Used to free MpmPattern instances.
348  *
349  * \param mpm_ctx Pointer to the mpm context.
350  * \param p Pointer to the MpmPattern instance to be freed.
351  */
353 {
354  if (p == NULL)
355  return;
356 
357  if (p->cs != NULL && p->cs != p->ci) {
358  SCFree(p->cs);
359  mpm_ctx->memory_cnt--;
360  mpm_ctx->memory_size -= p->len;
361  }
362 
363  if (p->ci != NULL) {
364  SCFree(p->ci);
365  mpm_ctx->memory_cnt--;
366  mpm_ctx->memory_size -= p->len;
367  }
368 
369  if (p->original_pat != NULL) {
370  SCFree(p->original_pat);
371  mpm_ctx->memory_cnt--;
372  mpm_ctx->memory_size -= p->len;
373  }
374 
375  if (p->sids != NULL) {
376  SCFree(p->sids);
377  }
378 
379  SCFree(p);
380  mpm_ctx->memory_cnt--;
381  mpm_ctx->memory_size -= sizeof(MpmPattern);
382 }
383 
384 static inline uint32_t MpmInitHash(MpmPattern *p)
385 {
386  uint32_t hash = p->len * p->original_pat[0];
387  if (p->len > 1)
388  hash += p->original_pat[1];
389 
390  return (hash % MPM_INIT_HASH_SIZE);
391 }
392 
393 static inline int MpmInitHashAdd(MpmCtx *ctx, MpmPattern *p)
394 {
395  uint32_t hash = MpmInitHash(p);
396 
397  if (ctx->init_hash == NULL) {
398  return -1;
399  }
400 
401  if (ctx->init_hash[hash] == NULL) {
402  ctx->init_hash[hash] = p;
403  return 0;
404  }
405 
406  MpmPattern *tt = NULL;
407  MpmPattern *t = ctx->init_hash[hash];
408 
409  /* get the list tail */
410  do {
411  tt = t;
412  t = t->next;
413  } while (t != NULL);
414 
415  tt->next = p;
416 
417  return 0;
418 }
419 
420 /**
421  * \internal
422  * \brief Add a pattern to the mpm-ac context.
423  *
424  * \param mpm_ctx Mpm context.
425  * \param pat Pointer to the pattern.
426  * \param patlen Length of the pattern.
427  * \param pid Pattern id
428  * \param sid Signature id (internal id).
429  * \param flags Pattern's MPM_PATTERN_* flags.
430  *
431  * \retval 0 On success.
432  * \retval -1 On failure.
433  */
434 int MpmAddPattern(MpmCtx *mpm_ctx, const uint8_t *pat, uint16_t patlen, uint16_t offset,
435  uint16_t depth, uint32_t pid, SigIntId sid, uint8_t flags)
436 {
437  SCLogDebug("Adding pattern for ctx %p, patlen %"PRIu16" and pid %" PRIu32,
438  mpm_ctx, patlen, pid);
439 
440  if (patlen == 0) {
441  SCLogWarning("pattern length 0");
442  return 0;
443  }
444 
446  pid = UINT_MAX;
447 
448  /* check if we have already inserted this pattern */
449  MpmPattern *p = MpmInitHashLookup(mpm_ctx, pat, patlen,
450  offset, depth, flags, pid);
451  if (p == NULL) {
452  SCLogDebug("Allocing new pattern");
453 
454  /* p will never be NULL */
455  p = MpmAllocPattern(mpm_ctx);
456 
457  p->len = patlen;
458  p->flags = flags;
459  p->offset = offset;
460  p->depth = depth;
462  p->id = mpm_ctx->max_pat_id++;
463  else
464  p->id = pid;
465 
466  p->original_pat = SCMalloc(patlen);
467  if (p->original_pat == NULL)
468  goto error;
469  mpm_ctx->memory_cnt++;
470  mpm_ctx->memory_size += patlen;
471  memcpy(p->original_pat, pat, patlen);
472 
473  p->ci = SCMalloc(patlen);
474  if (p->ci == NULL)
475  goto error;
476  mpm_ctx->memory_cnt++;
477  mpm_ctx->memory_size += patlen;
478  MemcpyToLower(p->ci, pat, patlen);
479 
480  /* setup the case sensitive part of the pattern */
482  /* nocase means no difference between cs and ci */
483  p->cs = p->ci;
484  } else {
485  if (memcmp(p->ci, pat, p->len) == 0) {
486  /* no diff between cs and ci: pat is lowercase */
487  p->cs = p->ci;
488  } else {
489  p->cs = SCMalloc(patlen);
490  if (p->cs == NULL)
491  goto error;
492  mpm_ctx->memory_cnt++;
493  mpm_ctx->memory_size += patlen;
494  memcpy(p->cs, pat, patlen);
495  }
496  }
497 
498  /* put in the pattern hash */
499  if (MpmInitHashAdd(mpm_ctx, p) != 0)
500  goto error;
501 
502  mpm_ctx->pattern_cnt++;
503 
504  if (!(mpm_ctx->flags & MPMCTX_FLAGS_NODEPTH)) {
505  if (depth) {
506  mpm_ctx->maxdepth = MAX(mpm_ctx->maxdepth, depth);
507  SCLogDebug("%p: depth %u max %u", mpm_ctx, depth, mpm_ctx->maxdepth);
508  } else {
509  mpm_ctx->flags |= MPMCTX_FLAGS_NODEPTH;
510  mpm_ctx->maxdepth = 0;
511  SCLogDebug("%p: alas, no depth for us", mpm_ctx);
512  }
513  }
514 
515  if (mpm_ctx->maxlen < patlen)
516  mpm_ctx->maxlen = patlen;
517 
518  if (mpm_ctx->minlen == 0) {
519  mpm_ctx->minlen = patlen;
520  } else {
521  if (mpm_ctx->minlen > patlen)
522  mpm_ctx->minlen = patlen;
523  }
524 
525  /* we need the max pat id */
526  if (p->id > mpm_ctx->max_pat_id)
527  mpm_ctx->max_pat_id = p->id;
528 
529  p->sids_size = 1;
530  p->sids = SCMalloc(p->sids_size * sizeof(SigIntId));
531  BUG_ON(p->sids == NULL);
532  p->sids[0] = sid;
533  } else {
534  /* we can be called multiple times for the same sid in the case
535  * of the 'single' modus. Here multiple rule groups share the
536  * same mpm ctx and might be adding the same pattern to the
537  * mpm_ctx */
538  int found = 0;
539  uint32_t x = 0;
540  for (x = 0; x < p->sids_size; x++) {
541  if (p->sids[x] == sid) {
542  found = 1;
543  break;
544  }
545  }
546 
547  if (!found) {
548  SigIntId *sids = SCRealloc(p->sids, (sizeof(SigIntId) * (p->sids_size + 1)));
549  BUG_ON(sids == NULL);
550  p->sids = sids;
551  p->sids[p->sids_size] = sid;
552  p->sids_size++;
553  }
554  }
555 
556  return 0;
557 
558 error:
559  MpmFreePattern(mpm_ctx, p);
560  return -1;
561 }
562 
563 
564 /************************************Unittests*********************************/
565 
566 #ifdef UNITTESTS
567 #endif /* UNITTESTS */
568 
570 {
571 #ifdef UNITTESTS
572  uint16_t i;
573 
574  for (i = 0; i < MPM_TABLE_SIZE; i++) {
575  if (i == MPM_NOTSET)
576  continue;
577 
578  g_ut_modules++;
579 
580  if (mpm_table[i].RegisterUnittests != NULL) {
581  g_ut_covered++;
583  } else {
584  if (coverage_unittests)
585  SCLogWarning("mpm module %s has no "
586  "unittest registration function.",
587  mpm_table[i].name);
588  }
589  }
590 
591 #endif
592 }
MpmCtx_::mpm_type
uint8_t mpm_type
Definition: util-mpm.h:113
detect-engine.h
offset
uint64_t offset
Definition: util-streaming-buffer.h:0
MpmTableElmt_::InitThreadCtx
void(* InitThreadCtx)(struct MpmCtx_ *, struct MpmThreadCtx_ *)
Definition: util-mpm.h:171
util-hashlist.h
MpmFactoryDeRegisterAllMpmCtxProfiles
void MpmFactoryDeRegisterAllMpmCtxProfiles(DetectEngineCtx *de_ctx)
Definition: util-mpm.c:167
g_ut_modules
int g_ut_modules
Definition: suricata.c:995
MpmThreadCtx_
Definition: util-mpm.h:62
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
MpmFreePattern
void MpmFreePattern(MpmCtx *mpm_ctx, MpmPattern *p)
Definition: util-mpm.c:352
MpmFactoryReClaimMpmCtx
void MpmFactoryReClaimMpmCtx(const DetectEngineCtx *de_ctx, MpmCtx *mpm_ctx)
Definition: util-mpm.c:155
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
util-mpm-ac-ks.h
next
struct HtpBodyChunk_ * next
Definition: app-layer-htp.h:0
name
const char * name
Definition: detect-engine-proto.c:47
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
Packet_::flags
uint32_t flags
Definition: decode.h:562
MpmRegisterTests
void MpmRegisterTests(void)
Definition: util-mpm.c:569
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
util-memcpy.h
MpmCtx_::memory_size
uint32_t memory_size
Definition: util-mpm.h:126
g_ut_covered
int g_ut_covered
Definition: suricata.c:996
MpmCtxFactoryItem::mpm_ctx_ts
MpmCtx * mpm_ctx_ts
Definition: util-mpm.h:140
MpmCtx_::maxlen
uint16_t maxlen
Definition: util-mpm.h:123
MpmTableElmt_::AddPattern
int(* AddPattern)(struct MpmCtx_ *, uint8_t *, uint16_t, uint16_t, uint16_t, uint32_t, SigIntId, uint8_t)
Definition: util-mpm.h:190
mpm_default_matcher
uint8_t mpm_default_matcher
Definition: util-mpm.c:47
p
Packet * p
Definition: fuzz_dataset.c:30
DetectEngineCtx_::mpm_ctx_factory_container
MpmCtxFactoryContainer * mpm_ctx_factory_container
Definition: detect.h:1063
MpmPattern_::original_pat
uint8_t * original_pat
Definition: util-mpm.h:83
MpmCtx_::maxdepth
uint16_t maxdepth
Definition: util-mpm.h:117
MAX
#define MAX(x, y)
Definition: suricata-common.h:417
MpmTableElmt_::InitCtx
void(* InitCtx)(struct MpmCtx_ *)
Definition: util-mpm.h:170
MpmPattern_::flags
uint8_t flags
Definition: util-mpm.h:74
MpmInitCtx
void MpmInitCtx(MpmCtx *mpm_ctx, uint8_t matcher)
Definition: util-mpm.c:208
DEFAULT_MPM
#define DEFAULT_MPM
Definition: util-mpm.c:220
MpmCtx_::max_pat_id
uint32_t max_pat_id
Definition: util-mpm.h:128
MpmPattern
struct MpmPattern_ MpmPattern
MpmCtxFactoryItem::name
const char * name
Definition: util-mpm.h:139
MpmDestroyThreadCtx
void MpmDestroyThreadCtx(MpmThreadCtx *mpm_thread_ctx, const uint16_t matcher)
Definition: util-mpm.c:201
MpmFactoryIsMpmCtxAvailable
int32_t MpmFactoryIsMpmCtxAvailable(const DetectEngineCtx *de_ctx, const MpmCtx *mpm_ctx)
Definition: util-mpm.c:113
util-debug.h
MpmPattern_::next
struct MpmPattern_ * next
Definition: util-mpm.h:95
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
MpmFactoryGetMpmCtxForProfile
MpmCtx * MpmFactoryGetMpmCtxForProfile(const DetectEngineCtx *de_ctx, int32_t id, int direction)
Definition: util-mpm.c:130
MPM_NOTSET
@ MPM_NOTSET
Definition: util-mpm.h:49
MPM_PATTERN_CTX_OWNS_ID
#define MPM_PATTERN_CTX_OWNS_ID
Definition: util-mpm.h:161
MpmPattern_::id
uint32_t id
Definition: util-mpm.h:89
MpmAddPattern
int MpmAddPattern(MpmCtx *mpm_ctx, const uint8_t *pat, uint16_t patlen, uint16_t offset, uint16_t depth, uint32_t pid, SigIntId sid, uint8_t flags)
Definition: util-mpm.c:434
SCMpmAddPatternCI
int SCMpmAddPatternCI(MpmCtx *mpm_ctx, const uint8_t *pat, uint16_t patlen, uint16_t offset, uint16_t depth, uint32_t pid, SigIntId sid, uint8_t flags)
Definition: util-mpm.c:257
SCLogWarning
#define SCLogWarning(...)
Macro used to log WARNING messages.
Definition: util-debug.h:262
MpmCtxFactoryContainer_::items
MpmCtxFactoryItem * items
Definition: util-mpm.h:149
MpmCtx_::minlen
uint16_t minlen
Definition: util-mpm.h:122
BUG_ON
#define BUG_ON(x)
Definition: suricata-common.h:322
MPMCTX_FLAGS_GLOBAL
#define MPMCTX_FLAGS_GLOBAL
Definition: util-mpm.h:101
SigIntId
#define SigIntId
Definition: detect-engine-state.h:38
MpmFactoryRegisterMpmCtxProfile
int32_t MpmFactoryRegisterMpmCtxProfile(DetectEngineCtx *de_ctx, const char *name, const int sm_list, const AppProto alproto)
Register a new Mpm Context.
Definition: util-mpm.c:58
conf-yaml-loader.h
conf.h
MPM_INIT_HASH_SIZE
#define MPM_INIT_HASH_SIZE
Definition: util-mpm.h:32
queue.h
util-mpm-ac.h
MpmPattern_
Definition: util-mpm.h:70
MpmCtxFactoryItem::sm_list
int32_t sm_list
Definition: util-mpm.h:143
MpmTableSetup
void MpmTableSetup(void)
Definition: util-mpm.c:223
MpmAddPatternCS
int MpmAddPatternCS(struct MpmCtx_ *mpm_ctx, uint8_t *pat, uint16_t patlen, uint16_t offset, uint16_t depth, uint32_t pid, SigIntId sid, uint8_t flags)
Definition: util-mpm.c:248
MPMCTX_FLAGS_NODEPTH
#define MPMCTX_FLAGS_NODEPTH
Definition: util-mpm.h:102
SCLogInfo
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
Definition: util-debug.h:232
MpmACTileRegister
void MpmACTileRegister(void)
Register the aho-corasick mpm 'ks' originally developed by Ken Steele for Tilera Tile-Gx processor.
Definition: util-mpm-ac-ks.c:1389
ENGINE_SGH_MPM_FACTORY_CONTEXT_START_ID_RANGE
#define ENGINE_SGH_MPM_FACTORY_CONTEXT_START_ID_RANGE
Definition: detect.h:1256
MpmCtxFactoryItem::next
struct MpmCtxFactoryItem * next
Definition: util-mpm.h:145
SCRealloc
#define SCRealloc(ptr, sz)
Definition: util-mem.h:50
MPM_PATTERN_FLAG_NOCASE
#define MPM_PATTERN_FLAG_NOCASE
Definition: util-mpm.h:154
MPM_TABLE_SIZE
@ MPM_TABLE_SIZE
Definition: util-mpm.h:56
util-mpm.h
flags
uint8_t flags
Definition: decode-gre.h:0
suricata-common.h
MpmCtx_::pattern_cnt
uint32_t pattern_cnt
Definition: util-mpm.h:120
MpmTableElmt_::AddPatternNocase
int(* AddPatternNocase)(struct MpmCtx_ *, const uint8_t *, uint16_t, uint16_t, uint16_t, uint32_t, SigIntId, uint8_t)
Definition: util-mpm.h:191
MpmPattern_::offset
uint16_t offset
Definition: util-mpm.h:77
FatalError
#define FatalError(...)
Definition: util-debug.h:517
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
MpmPattern_::depth
uint16_t depth
Definition: util-mpm.h:80
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
MpmTableElmt_::DestroyCtx
void(* DestroyCtx)(struct MpmCtx_ *)
Definition: util-mpm.h:172
MpmCtxFactoryItem
Definition: util-mpm.h:138
SCFree
#define SCFree(p)
Definition: util-mem.h:61
MPM_CTX_FACTORY_UNIQUE_CONTEXT
#define MPM_CTX_FACTORY_UNIQUE_CONTEXT
Definition: util-mpm.h:136
MpmACRegister
void MpmACRegister(void)
Register the aho-corasick mpm.
Definition: util-mpm-ac.c:1062
MpmCtxFactoryItem::alproto
AppProto alproto
Definition: util-mpm.h:144
MpmCtxFactoryItem::id
int32_t id
Definition: util-mpm.h:142
MpmInitThreadCtx
void MpmInitThreadCtx(MpmThreadCtx *mpm_thread_ctx, MpmCtx *mpm_ctx, uint16_t matcher)
Definition: util-mpm.c:194
MpmCtx_::memory_cnt
uint32_t memory_cnt
Definition: util-mpm.h:125
MpmPattern_::len
uint16_t len
Definition: util-mpm.h:72
mpm_table
MpmTableElmt mpm_table[MPM_TABLE_SIZE]
Definition: util-mpm.c:46
MpmCtxFactoryItem::mpm_ctx_tc
MpmCtx * mpm_ctx_tc
Definition: util-mpm.h:141
util-mpm-hs.h
MpmTableElmt_::DestroyThreadCtx
void(* DestroyThreadCtx)(struct MpmCtx_ *, struct MpmThreadCtx_ *)
Definition: util-mpm.h:173
MpmCtxFactoryContainer_::max_id
int32_t max_id
Definition: util-mpm.h:150
coverage_unittests
int coverage_unittests
Definition: suricata.c:994
MpmCtx_
Definition: util-mpm.h:111
util-misc.h
MpmCtx_::flags
uint8_t flags
Definition: util-mpm.h:115
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
MpmTableElmt_
Definition: util-mpm.h:168
MpmHSRegister
void MpmHSRegister(void)
MpmTableElmt_::RegisterUnittests
void(* RegisterUnittests)(void)
Definition: util-mpm.h:204
MpmCtxFactoryContainer_
Definition: util-mpm.h:148