suricata
util-unittest-helper.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2017 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Pablo Rincon Crespo <pablo.rincon.crespo@gmail.com>
22  *
23  * This file provide a set of helper functions for reducing the complexity
24  * when constructing unittests
25  */
26 
27 #include "suricata-common.h"
28 
29 #include "decode.h"
30 
31 #include "flow-private.h"
32 #include "flow-util.h"
33 #include "flow-spare-pool.h"
34 
35 #include "detect.h"
36 #include "detect-parse.h"
37 #include "detect-engine.h"
38 #include "detect-engine-alert.h"
39 #include "detect-engine-sigorder.h"
40 #include "detect-engine-build.h"
41 
42 #include "stream-tcp.h"
43 #include "stream-tcp-private.h"
44 
45 #include "util-debug.h"
46 #include "util-error.h"
47 #include "util-unittest-helper.h"
48 
49 #if defined(UNITTESTS) || defined(FUZZ)
50 Flow *TestHelperBuildFlow(int family, const char *src, const char *dst, Port sp, Port dp)
51 {
52  struct in_addr in;
53 
54  Flow *f = SCMalloc(sizeof(Flow));
55  if (unlikely(f == NULL)) {
56  printf("FlowAlloc failed\n");
57  ;
58  return NULL;
59  }
60  memset(f, 0x00, sizeof(Flow));
61 
63 
64  if (family == AF_INET) {
65  f->flags |= FLOW_IPV4;
66  } else if (family == AF_INET6) {
67  f->flags |= FLOW_IPV6;
68  }
69 
70  if (src != NULL) {
71  if (family == AF_INET) {
72  if (inet_pton(AF_INET, src, &in) != 1) {
73  printf("invalid address %s\n", src);
74  SCFree(f);
75  return NULL;
76  }
77  f->src.addr_data32[0] = in.s_addr;
78  } else {
79  BUG_ON(1);
80  }
81  }
82  if (dst != NULL) {
83  if (family == AF_INET) {
84  if (inet_pton(AF_INET, dst, &in) != 1) {
85  printf("invalid address %s\n", dst);
86  SCFree(f);
87  return NULL;
88  }
89  f->dst.addr_data32[0] = in.s_addr;
90  } else {
91  BUG_ON(1);
92  }
93  }
94 
95  f->sp = sp;
96  f->dp = dp;
97 
98  return f;
99 }
100 /** \brief writes the contents of a buffer into a file */
101 int TestHelperBufferToFile(const char *name, const uint8_t *data, size_t size)
102 {
103  if (remove(name) != 0) {
104  if (errno != ENOENT) {
105  printf("failed remove, errno=%d\n", errno);
106  return -1;
107  }
108  }
109  FILE *fd = fopen(name, "wb");
110  if (fd == NULL) {
111  printf("failed open, errno=%d\n", errno);
112  return -2;
113  }
114  if (fwrite (data, 1, size, fd) != size) {
115  fclose(fd);
116  return -3;
117  }
118  fclose(fd);
119  return 0;
120 }
121 
122 /**
123  * \brief UTHBuildPacketReal is a function that create tcp/udp packets for unittests
124  * specifying ip and port sources and destinations
125  *
126  * \param payload pointer to the payload buffer
127  * \param payload_len pointer to the length of the payload
128  * \param ipproto Protocols allowed atm are IPPROTO_TCP and IPPROTO_UDP
129  * \param src pointer to a string containing the ip source
130  * \param dst pointer to a string containing the ip destination
131  * \param sport pointer to a string containing the port source
132  * \param dport pointer to a string containing the port destination
133  *
134  * \retval Packet pointer to the built in packet
135  */
136 Packet *UTHBuildPacketReal(uint8_t *payload, uint16_t payload_len,
137  uint8_t ipproto, const char *src, const char *dst,
138  uint16_t sport, uint16_t dport)
139 {
140  struct in_addr in;
141 
143  if (unlikely(p == NULL))
144  return NULL;
145 
146  p->ts = TimeGet();
147 
148  p->src.family = AF_INET;
149  p->dst.family = AF_INET;
150  p->payload = payload;
152  p->proto = ipproto;
153 
154  if (inet_pton(AF_INET, src, &in) != 1)
155  goto error;
156  p->src.addr_data32[0] = in.s_addr;
157  if (ipproto == IPPROTO_TCP || ipproto == IPPROTO_UDP || ipproto == IPPROTO_SCTP)
158  p->sp = sport;
159 
160  if (inet_pton(AF_INET, dst, &in) != 1)
161  goto error;
162  p->dst.addr_data32[0] = in.s_addr;
163  if (ipproto == IPPROTO_TCP || ipproto == IPPROTO_UDP || ipproto == IPPROTO_SCTP)
164  p->dp = dport;
165 
166  IPV4Hdr *ip4h = PacketSetIPV4(p, GET_PKT_DATA(p));
167  if (ip4h == NULL)
168  goto error;
169 
170  ip4h->s_ip_src.s_addr = p->src.addr_data32[0];
171  ip4h->s_ip_dst.s_addr = p->dst.addr_data32[0];
172  ip4h->ip_proto = ipproto;
173  ip4h->ip_verhl = 0x40 | (sizeof(IPV4Hdr) / 4);
174  p->proto = ipproto;
175 
176  int hdr_offset = sizeof(IPV4Hdr);
177  switch (ipproto) {
178  case IPPROTO_UDP: {
179  UDPHdr *udph = PacketSetUDP(p, (GET_PKT_DATA(p) + hdr_offset));
180  if (udph == NULL)
181  goto error;
182 
183  udph->uh_sport = htons(sport);
184  udph->uh_dport = htons(dport);
185  udph->uh_len = htons(payload_len + sizeof(UDPHdr));
186  ip4h->ip_len = htons(payload_len + sizeof(IPV4Hdr) + sizeof(UDPHdr));
187  hdr_offset += sizeof(UDPHdr);
188  break;
189  }
190  case IPPROTO_TCP: {
191  TCPHdr *tcph = PacketSetTCP(p, GET_PKT_DATA(p) + hdr_offset);
192  if (tcph == NULL)
193  goto error;
194 
195  tcph->th_sport = htons(sport);
196  tcph->th_dport = htons(dport);
197  tcph->th_offx2 = (sizeof(TCPHdr) / 4) << 4;
198  tcph->th_win = 0x4444; // non-zero window
199  tcph->th_flags = TH_ACK;
200  ip4h->ip_len = htons(payload_len + sizeof(IPV4Hdr) + sizeof(TCPHdr));
201  hdr_offset += sizeof(TCPHdr);
202  break;
203  }
204  case IPPROTO_ICMP: {
205  ICMPV4Hdr *icmpv4h = PacketSetICMPv4(p, (GET_PKT_DATA(p) + hdr_offset));
206  if (icmpv4h == NULL)
207  goto error;
208 
209  hdr_offset += sizeof(ICMPV4Hdr);
210  break;
211  }
212  default:
213  break;
214  /* TODO: Add more protocols */
215  }
216 
217  if (payload && payload_len) {
218  PacketCopyDataOffset(p, hdr_offset, payload, payload_len);
219  }
220  SET_PKT_LEN(p, hdr_offset + payload_len);
221  p->payload = GET_PKT_DATA(p)+hdr_offset;
223 
224  return p;
225 
226 error:
227  SCFree(p);
228  return NULL;
229 }
230 
231 /**
232  * \brief UTHBuildPacket is a wrapper that build packets with default ip
233  * and port fields
234  *
235  * \param payload pointer to the payload buffer
236  * \param payload_len pointer to the length of the payload
237  * \param ipproto Protocols allowed atm are IPPROTO_TCP and IPPROTO_UDP
238  *
239  * \retval Packet pointer to the built in packet
240  */
241 Packet *UTHBuildPacket(uint8_t *payload, uint16_t payload_len,
242  uint8_t ipproto)
243 {
244  return UTHBuildPacketReal(payload, payload_len, ipproto,
245  "192.168.1.5", "192.168.1.1",
246  41424, 80);
247 }
248 
249 #endif
250 #ifdef UNITTESTS
252 {
253  PacketSetIPV4(p, (uint8_t *)ip4h);
254 }
255 
257 {
258  PacketSetIPV6(p, (uint8_t *)ip6h);
259 }
260 
262 {
263  PacketSetTCP(p, (uint8_t *)tcph);
264 }
265 
266 /**
267  * \brief return the uint32_t for a ipv4 address string
268  *
269  * \param str Valid ipaddress in string form (e.g. 1.2.3.4)
270  *
271  * \retval uint the uin32_t representation
272  */
273 uint32_t UTHSetIPv4Address(const char *str)
274 {
275  struct in_addr in;
276  if (inet_pton(AF_INET, str, &in) != 1) {
277  printf("invalid IPv6 address %s\n", str);
278  exit(EXIT_FAILURE);
279  }
280  return (uint32_t)in.s_addr;
281 }
282 
283 /**
284  * \brief UTHBuildPacketReal is a function that create tcp/udp packets for unittests
285  * specifying ip and port sources and destinations (IPV6)
286  *
287  * \param payload pointer to the payload buffer
288  * \param payload_len pointer to the length of the payload
289  * \param ipproto Protocols allowed atm are IPPROTO_TCP and IPPROTO_UDP
290  * \param src pointer to a string containing the ip source
291  * \param dst pointer to a string containing the ip destination
292  * \param sport pointer to a string containing the port source
293  * \param dport pointer to a string containing the port destination
294  *
295  * \retval Packet pointer to the built in packet
296  */
297 Packet *UTHBuildPacketIPV6Real(uint8_t *payload, uint16_t payload_len, uint8_t ipproto,
298  const char *src, const char *dst, uint16_t sport, uint16_t dport)
299 {
300  uint32_t in[4];
301  TCPHdr *tcph = NULL;
302 
304  if (unlikely(p == NULL))
305  return NULL;
306 
307  p->ts = TimeGet();
308 
309  p->src.family = AF_INET6;
310  p->dst.family = AF_INET6;
311  p->payload = payload;
313  p->proto = ipproto;
314 
315  IPV6Hdr *ip6h = SCCalloc(1, sizeof(IPV6Hdr));
316  if (ip6h == NULL)
317  goto error;
318  ip6h->s_ip6_nxt = ipproto;
319  ip6h->s_ip6_plen = htons(payload_len + sizeof(TCPHdr));
320  UTHSetIPV6Hdr(p, ip6h);
321 
322  if (inet_pton(AF_INET6, src, &in) != 1)
323  goto error;
324  p->src.addr_data32[0] = in[0];
325  p->src.addr_data32[1] = in[1];
326  p->src.addr_data32[2] = in[2];
327  p->src.addr_data32[3] = in[3];
328  p->sp = sport;
329  ip6h->s_ip6_src[0] = in[0];
330  ip6h->s_ip6_src[1] = in[1];
331  ip6h->s_ip6_src[2] = in[2];
332  ip6h->s_ip6_src[3] = in[3];
333 
334  if (inet_pton(AF_INET6, dst, &in) != 1)
335  goto error;
336  p->dst.addr_data32[0] = in[0];
337  p->dst.addr_data32[1] = in[1];
338  p->dst.addr_data32[2] = in[2];
339  p->dst.addr_data32[3] = in[3];
340  p->dp = dport;
341  ip6h->s_ip6_dst[0] = in[0];
342  ip6h->s_ip6_dst[1] = in[1];
343  ip6h->s_ip6_dst[2] = in[2];
344  ip6h->s_ip6_dst[3] = in[3];
345 
346  tcph = SCMalloc(sizeof(TCPHdr));
347  if (tcph == NULL)
348  goto error;
349  memset(tcph, 0, sizeof(TCPHdr));
350  tcph->th_sport = htons(sport);
351  tcph->th_dport = htons(dport);
352  UTHSetTCPHdr(p, tcph);
353 
354  SET_PKT_LEN(p, sizeof(IPV6Hdr) + sizeof(TCPHdr) + payload_len);
355  return p;
356 
357 error:
358  if (p != NULL) {
359  if (ip6h != NULL) {
360  SCFree(ip6h);
361  }
362  if (tcph != NULL) {
363  SCFree(tcph);
364  }
365  SCFree(p);
366  }
367  return NULL;
368 }
369 
370 /**
371  * \brief UTHBuildPacketFromEth is a wrapper that build a packet for the rawbytes
372  *
373  * \param raw_eth pointer to the rawbytes containing an ethernet packet
374  * (and any other headers inside)
375  * \param pktsize pointer to the length of the payload
376  *
377  * \retval Packet pointer to the built in packet; NULL if something fail
378  */
379 Packet *UTHBuildPacketFromEth(uint8_t *raw_eth, uint16_t pktsize)
380 {
384  if (unlikely(p == NULL))
385  return NULL;
386  memset(&dtv, 0, sizeof(DecodeThreadVars));
387  memset(&th_v, 0, sizeof(th_v));
388 
389  DecodeEthernet(&th_v, &dtv, p, raw_eth, pktsize);
390  return p;
391 }
392 
393 /**
394  * \brief UTHBuildPacketSrcDst is a wrapper that build packets specifying IPs
395  * and defaulting ports
396  *
397  * \param payload pointer to the payload buffer
398  * \param payload_len pointer to the length of the payload
399  * \param ipproto Protocols allowed atm are IPPROTO_TCP and IPPROTO_UDP
400  *
401  * \retval Packet pointer to the built in packet
402  */
403 Packet *UTHBuildPacketSrcDst(uint8_t *payload, uint16_t payload_len,
404  uint8_t ipproto, const char *src, const char *dst)
405 {
406  return UTHBuildPacketReal(payload, payload_len, ipproto,
407  src, dst,
408  41424, 80);
409 }
410 
411 /**
412  * \brief UTHBuildPacketSrcDst is a wrapper that build packets specifying IPs
413  * and defaulting ports (IPV6)
414  *
415  * \param payload pointer to the payload buffer
416  * \param payload_len pointer to the length of the payload
417  * \param ipproto Protocols allowed atm are IPPROTO_TCP and IPPROTO_UDP
418  *
419  * \retval Packet pointer to the built in packet
420  */
421 Packet *UTHBuildPacketIPV6SrcDst(uint8_t *payload, uint16_t payload_len,
422  uint8_t ipproto, const char *src, const char *dst)
423 {
424  return UTHBuildPacketIPV6Real(payload, payload_len, ipproto,
425  src, dst,
426  41424, 80);
427 }
428 
429 /**
430  * \brief UTHBuildPacketSrcDstPorts is a wrapper that build packets specifying
431  * src and dst ports and defaulting IPs
432  *
433  * \param payload pointer to the payload buffer
434  * \param payload_len pointer to the length of the payload
435  * \param ipproto Protocols allowed atm are IPPROTO_TCP and IPPROTO_UDP
436  *
437  * \retval Packet pointer to the built in packet
438  */
439 Packet *UTHBuildPacketSrcDstPorts(uint8_t *payload, uint16_t payload_len,
440  uint8_t ipproto, uint16_t sport, uint16_t dport)
441 {
442  return UTHBuildPacketReal(payload, payload_len, ipproto,
443  "192.168.1.5", "192.168.1.1",
444  sport, dport);
445 }
446 
447 /**
448  * \brief UTHFreePackets: function to release the allocated data
449  * from UTHBuildPacket and the packet itself
450  *
451  * \param p pointer to the Packet
452  */
453 void UTHFreePackets(Packet **p, int numpkts)
454 {
455  if (p == NULL)
456  return;
457 
458  int i = 0;
459  for (; i < numpkts; i++) {
460  UTHFreePacket(p[i]);
461  }
462 }
463 
464 /**
465  * \brief UTHFreePacket: function to release the allocated data
466  * from UTHBuildPacket and the packet itself
467  *
468  * \param p pointer to the Packet
469  */
471 {
472  if (p == NULL)
473  return;
474  /* for IPv6 UTHBuildPacketIPV6Real allocs both IPv6 hdr and TCP hdr */
475  if (p->l3.type == PACKET_L3_IPV6) {
476  SCFree(p->l3.hdrs.ip6h);
477  p->l3.hdrs.ip6h = NULL;
478  if (p->l4.type == PACKET_L4_TCP) {
479  SCFree(p->l4.hdrs.tcph);
480  p->l4.hdrs.tcph = NULL;
481  }
482  }
483  PacketFree(p);
484 }
485 
487 {
488  if (p && f) {
489  p->flow = f;
490  p->flags |= PKT_HAS_FLOW;
491  }
492 }
493 
494 Flow *UTHBuildFlow(int family, const char *src, const char *dst, Port sp, Port dp)
495 {
496  return TestHelperBuildFlow(family, src, dst, sp, dp);
497 }
498 
499 void UTHFreeFlow(Flow *flow)
500 {
501  if (flow != NULL) {
502  FLOW_DESTROY(flow);
503  SCFree(flow);//FlowFree(flow);
504  }
505 }
506 
507 int UTHAddStreamToFlow(Flow *f, int direction,
508  uint8_t *data, uint32_t data_len)
509 {
510  FAIL_IF_NULL(f);
511  FAIL_IF_NOT(f->proto == IPPROTO_TCP);
513  TcpSession *ssn = f->protoctx;
514 
515  StreamingBufferSegment seg;
516  TcpStream *stream = direction == 0 ? &ssn->client : &ssn->server;
517  int r = StreamingBufferAppend(&stream->sb, &stream_config.sbcnf, &seg, data, data_len);
518  FAIL_IF_NOT(r == 0);
519  stream->last_ack += data_len;
520  return 1;
521 }
522 
524  uint32_t ts_isn,
525  uint32_t tc_isn)
526 {
527  FAIL_IF_NULL(f);
528 
529  TcpSession *ssn = SCCalloc(1, sizeof(*ssn));
530  FAIL_IF_NULL(ssn);
531 
533  ssn->client.sb = x;
534  ssn->server.sb = x;
535 
536  ssn->client.isn = ts_isn;
537  ssn->server.isn = tc_isn;
538 
539  f->protoctx = ssn;
540  return 1;
541 }
542 
544 {
545  FAIL_IF_NULL(f);
546  FAIL_IF_NOT(f->proto == IPPROTO_TCP);
547  TcpSession *ssn = f->protoctx;
548  FAIL_IF_NULL(ssn);
550  SCFree(ssn);
551  f->protoctx = NULL;
552  return 1;
553 }
554 
555 /**
556  * \brief UTHGenericTest: function that perform a generic check taking care of
557  * as maximum common unittest elements as possible.
558  * It will create a detection engine, append an array
559  * of signatures an check the expected results for each
560  * of them, it check matches for an array of packets
561  *
562  * \param pkt pointer to the array of packets
563  * \param numpkts number of packets to match
564  * \param sigs array of char* pointing to signatures to load
565  * \param numsigs number of signatures to load and check
566  * \param results pointer to arrays of numbers, each of them foreach packet
567  * to check if sids matches that packet as expected with
568  * that number of times or not. The size of results should be
569  * numpkts * numsigs * sizeof(uint16_t *)
570  *
571  * Example:
572  * result[1][3] would mean the number of times the pkt[1]
573  * match the sid[3]
574  *
575  * \retval int 1 if the match of all the sids is the specified has the
576  * specified results; 0 if not
577  */
578 int UTHGenericTest(Packet **pkt, int numpkts, const char *sigs[], uint32_t sids[], uint32_t *results, int numsigs)
579 {
580 
581  int result = 0;
582  if (pkt == NULL || sigs == NULL || numpkts == 0
583  || sids == NULL || results == NULL || numsigs == 0) {
584  SCLogError("Arguments invalid, that the pointer/arrays are not NULL, and the number of "
585  "signatures and packets is > 0");
586  goto end;
587  }
589  if (de_ctx == NULL) {
590  goto end;
591  }
592  de_ctx->flags |= DE_QUIET;
593 
594  if (UTHAppendSigs(de_ctx, sigs, numsigs) == 0)
595  goto cleanup;
596 
597  result = UTHMatchPacketsWithResults(de_ctx, pkt, numpkts, sids, results, numsigs);
598 
599 cleanup:
601 end:
602  return result;
603 }
604 
605 /**
606  * \brief UTHCheckPacketMatches: function to check if a packet match some sids
607  *
608  *
609  * \param p pointer to the Packet
610  * \param sigs array of char* pointing to signatures to load
611  * \param numsigs number of signatures to load from the array
612  * \param results pointer to an array of numbers to check if sids matches
613  * that number of times or not.
614  *
615  * \retval int 1 if the match of all the sids is the specified has the
616  * specified results; 0 if not
617  */
618 int UTHCheckPacketMatchResults(Packet *p, uint32_t sids[], uint32_t results[], int numsigs)
619 {
620  if (p == NULL || sids == NULL) {
621  SCLogError("Arguments invalid, check if the "
622  "packet is NULL, and if the array contain sids is set");
623  return 0;
624  }
625 
626  int i = 0;
627  int res = 1;
628  for (; i < numsigs; i++) {
629  uint32_t r = PacketAlertCheck(p, sids[i]);
630  if (r != results[i]) {
631  SCLogInfo("Sid %" PRIu32 " matched %" PRIu32 " times, and not %" PRIu32 " as expected",
632  sids[i], r, results[i]);
633  res = 0;
634  } else {
635  SCLogInfo("Sid %" PRIu32 " matched %" PRIu32 " times, as expected", sids[i], r);
636  }
637  }
638  return res;
639 }
640 
641 /**
642  * \brief UTHAppendSigs: Add sigs to the detection_engine checking for errors
643  *
644  * \param de_ctx pointer to the DetectEngineCtx used
645  * \param sigs array of char* pointing to signatures to load
646  * \param numsigs number of signatures to load from the array
647  * (size of the array)
648  *
649  * \retval int 0 if we have errors; 1 if all the signatures loaded successfully
650  */
651 int UTHAppendSigs(DetectEngineCtx *de_ctx, const char *sigs[], int numsigs)
652 {
653  BUG_ON(de_ctx == NULL);
654  BUG_ON(numsigs <= 0);
655  BUG_ON(sigs == NULL);
656 
657  for (int i = 0; i < numsigs; i++) {
658  if (sigs[i] == NULL) {
659  SCLogError("Check the signature"
660  " at position %d",
661  i);
662  return 0;
663  }
664  Signature *s = DetectEngineAppendSig(de_ctx, sigs[i]);
665  if (s == NULL) {
666  SCLogError("Check the signature at"
667  " position %d (%s)",
668  i, sigs[i]);
669  return 0;
670  }
671  }
672  return 1;
673 }
674 
675 /**
676  * \test UTHMatchPacketsWithResults Match a packet or a array of packets against sigs
677  * of a de_ctx, checking that each signature matches X times for certain packets
678  *
679  * \param de_ctx pointer with the signatures loaded
680  * \param p pointer to the array of packets
681  * \param num_packets number of packets in the array
682  *
683  * \retval return 1 if all goes well
684  * \retval return 0 if something fail
685  */
686 int UTHMatchPacketsWithResults(DetectEngineCtx *de_ctx, Packet **p, int num_packets, uint32_t sids[], uint32_t *results, int numsigs)
687 {
688  BUG_ON(de_ctx == NULL);
689  BUG_ON(p == NULL);
690 
691  int result = 0;
694  DetectEngineThreadCtx *det_ctx = NULL;
695  memset(&dtv, 0, sizeof(DecodeThreadVars));
696  memset(&th_v, 0, sizeof(th_v));
697 
700  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
701 
702  for (int i = 0; i < num_packets; i++) {
703  SigMatchSignatures(&th_v, de_ctx, det_ctx, p[i]);
704  if (UTHCheckPacketMatchResults(p[i], sids, &results[(i * numsigs)], numsigs) == 0)
705  goto cleanup;
706  }
707 
708  result = 1;
709 cleanup:
710  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
712  return result;
713 }
714 
715 /**
716  * \test UTHMatchPackets Match a packet or a array of packets against sigs
717  * of a de_ctx, but note that the return value doesn't mean that we have a
718  * match, we have to check it later with PacketAlertCheck()
719  *
720  * \param de_ctx pointer with the signatures loaded
721  * \param p pointer to the array of packets
722  * \param num_packets number of packets in the array
723  *
724  * \retval return 1 if all goes well
725  * \retval return 0 if something fail
726  */
727 int UTHMatchPackets(DetectEngineCtx *de_ctx, Packet **p, int num_packets)
728 {
729  BUG_ON(de_ctx == NULL);
730  BUG_ON(p == NULL);
731  int result = 1;
734  DetectEngineThreadCtx *det_ctx = NULL;
735  memset(&dtv, 0, sizeof(DecodeThreadVars));
736  memset(&th_v, 0, sizeof(th_v));
739  if (SCSigOrderSignatures(de_ctx) != 0) {
740  result = 0;
741  }
744  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
745 
746  for (int i = 0; i < num_packets; i++)
747  SigMatchSignatures(&th_v, de_ctx, det_ctx, p[i]);
748 
749  /* Here we don't check if the packet matched or not, because
750  * the de_ctx can have multiple signatures, and some of them may match
751  * and others may not. That check will be outside
752  */
753  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
755  return result;
756 }
757 
758 /**
759  * \test Test if a packet match a signature given as string and a mpm_type
760  * Hint: Useful for unittests with only one packet and one signature
761  *
762  * \param sig pointer to the string signature to test
763  * \param sid sid number of the signature
764  *
765  * \retval return 1 if match
766  * \retval return 0 if not
767  */
768 int UTHPacketMatchSigMpm(Packet *p, char *sig, uint16_t mpm_type)
769 {
770  SCEnter();
771 
772  int result = 0;
773 
776  DetectEngineThreadCtx *det_ctx = NULL;
777 
778  memset(&dtv, 0, sizeof(DecodeThreadVars));
779  memset(&th_v, 0, sizeof(th_v));
781 
782  if (mpm_type == MPM_AC) {
783  SCConfSet("mpm-algo", "ac");
784 #ifdef BUILD_HYPERSCAN
785  } else if (mpm_type == MPM_HS) {
786  SCConfSet("mpm-algo", "hs");
787 #endif
788  } else {
789  BUG_ON("unsupported MPM type");
790  }
791 
793  if (de_ctx == NULL) {
794  printf("de_ctx == NULL: ");
795  goto end;
796  }
797  de_ctx->flags |= DE_QUIET;
798 
800  if (s == NULL) {
801  printf("signature == NULL: ");
802  goto end;
803  }
804 
806  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
807 
808  SigMatchSignatures(&th_v, de_ctx, det_ctx, p);
809  if (PacketAlertCheck(p, s->id) != 1) {
810  printf("signature didn't alert: ");
811  goto end;
812  }
813 
814  result = 1;
815 end:
816  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
819  SCConfSet("mpm-algo", "auto");
820  SCReturnInt(result);
821 }
822 
823 /**
824  * \test Test if a packet match a signature given as string
825  * Hint: Useful for unittests with only one packet and one signature
826  *
827  * \param sig pointer to the string signature to test
828  * \param sid sid number of the signature
829  *
830  * \retval return 1 if match
831  * \retval return 0 if not
832  */
833 int UTHPacketMatchSig(Packet *p, const char *sig)
834 {
835  int result = 1;
836 
839  DetectEngineThreadCtx *det_ctx = NULL;
840 
841  memset(&dtv, 0, sizeof(DecodeThreadVars));
842  memset(&th_v, 0, sizeof(th_v));
844 
846  if (de_ctx == NULL) {
847  result=0;
848  goto end;
849  }
850 
851  de_ctx->flags |= DE_QUIET;
852 
854  if (s == NULL) {
855  result = 0;
856  goto end;
857  }
858 
860  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
861 
862  SigMatchSignatures(&th_v, de_ctx, det_ctx, p);
863  if (PacketAlertCheck(p, s->id) != 1) {
864  result = 0;
865  goto end;
866  }
867 
868 end:
869  if (det_ctx != NULL)
870  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
871  if (de_ctx != NULL)
874  return result;
875 }
876 
877 uint32_t UTHBuildPacketOfFlows(uint32_t start, uint32_t end, uint8_t dir)
878 {
879  FlowLookupStruct fls;
880  memset(&fls, 0, sizeof(fls));
881  ThreadVars tv;
882  memset(&tv, 0, sizeof(tv));
883 
884  uint32_t i = start;
885  uint8_t payload[] = "Payload";
886  for (; i < end; i++) {
887  Packet *p = UTHBuildPacket(payload, sizeof(payload), IPPROTO_TCP);
888  if (dir == 0) {
889  p->src.addr_data32[0] = i;
890  p->dst.addr_data32[0] = i + 1;
891  } else {
892  p->src.addr_data32[0] = i + 1;
893  p->dst.addr_data32[0] = i;
894  }
895  FlowHandlePacket(&tv, &fls, p);
896  if (p->flow != NULL) {
898  }
899 
900  /* Now the queues should be updated */
901  UTHFreePacket(p);
902  }
903 
904  Flow *f;
905  while ((f = FlowQueuePrivateGetFromTop(&fls.spare_queue))) {
906  FlowFree(f);
907  }
908  while ((f = FlowQueuePrivateGetFromTop(&fls.work_queue))) {
909  FlowFree(f);
910  }
911 
912  return i;
913 }
914 
915 /** \brief parser a sig and see if the expected result is correct */
916 int UTHParseSignature(const char *str, bool expect)
917 {
920  de_ctx->flags |= DE_QUIET;
921 
923  if (expect)
924  FAIL_IF_NULL(s);
925  else
926  FAIL_IF_NOT_NULL(s);
927 
929  PASS;
930 }
931 
932 /*
933  * unittests for the unittest helpers
934  */
935 
936 /**
937  * \brief CheckUTHTestPacket wrapper to check packets for unittests
938  */
939 static int CheckUTHTestPacket(Packet *p, uint8_t ipproto)
940 {
941  uint16_t sport = 41424;
942  uint16_t dport = 80;
943  uint8_t payload[] = "Payload";
944 
945  uint8_t len = sizeof(payload);
946 
947  if (p == NULL)
948  return 0;
949 
950  if (p->payload_len != len)
951  return 0;
952 
953  if (strncmp((char *)payload, (char *)p->payload, len) != 0)
954  return 0;
955 
956  if (p->src.family != AF_INET)
957  return 0;
958  if (p->dst.family != AF_INET)
959  return 0;
960  if (p->proto != ipproto)
961  return 0;
962 
963  switch(ipproto) {
964  case IPPROTO_UDP: {
965  const UDPHdr *udph = PacketGetUDP(p);
966  if (udph == NULL)
967  return 0;
968  if (SCNtohs(udph->uh_sport) != sport)
969  return 0;
970  if (SCNtohs(udph->uh_dport) != dport)
971  return 0;
972  break;
973  }
974  case IPPROTO_TCP: {
975  const TCPHdr *tcph = PacketGetTCP(p);
976  if (tcph == NULL)
977  return 0;
978  if (SCNtohs(tcph->th_sport) != sport)
979  return 0;
980  if (SCNtohs(tcph->th_dport) != dport)
981  return 0;
982  break;
983  }
984  }
985  return 1;
986 }
987 
988 #ifdef HAVE_MEMMEM
989 #include <string.h>
990 void * UTHmemsearch(const void *big, size_t big_len, const void *little, size_t little_len) {
991  return memmem(big, big_len, little, little_len);
992 }
993 #else
994 #include "util-spm-bs.h"
995 void * UTHmemsearch(const void *big, size_t big_len, const void *little, size_t little_len) {
996  return BasicSearch(big, big_len, little, little_len);
997 }
998 #endif //HAVE_MEMMEM
999 
1000 /**
1001  * \brief UTHBuildPacketRealTest01 wrapper to check packets for unittests
1002  */
1003 static int UTHBuildPacketRealTest01(void)
1004 {
1005  uint8_t payload[] = "Payload";
1006 
1007  Packet *p = UTHBuildPacketReal(payload, sizeof(payload), IPPROTO_TCP,
1008  "192.168.1.5", "192.168.1.1", 41424, 80);
1009 
1010  int ret = CheckUTHTestPacket(p, IPPROTO_TCP);
1011  UTHFreePacket(p);
1012 
1013  return ret;
1014 }
1015 
1016 /**
1017  * \brief UTHBuildPacketRealTest02 wrapper to check packets for unittests
1018  */
1019 static int UTHBuildPacketRealTest02(void)
1020 {
1021  uint8_t payload[] = "Payload";
1022 
1023  Packet *p = UTHBuildPacketReal(payload, sizeof(payload), IPPROTO_UDP,
1024  "192.168.1.5", "192.168.1.1", 41424, 80);
1025 
1026  int ret = CheckUTHTestPacket(p, IPPROTO_UDP);
1027  UTHFreePacket(p);
1028  return ret;
1029 }
1030 
1031 /**
1032  * \brief UTHBuildPacketTest01 wrapper to check packets for unittests
1033  */
1034 static int UTHBuildPacketTest01(void)
1035 {
1036  uint8_t payload[] = "Payload";
1037 
1038  Packet *p = UTHBuildPacket(payload, sizeof(payload), IPPROTO_TCP);
1039 
1040  int ret = CheckUTHTestPacket(p, IPPROTO_TCP);
1041  UTHFreePacket(p);
1042 
1043  return ret;
1044 }
1045 
1046 /**
1047  * \brief UTHBuildPacketTest02 wrapper to check packets for unittests
1048  */
1049 static int UTHBuildPacketTest02(void)
1050 {
1051  uint8_t payload[] = "Payload";
1052 
1053  Packet *p = UTHBuildPacket(payload, sizeof(payload), IPPROTO_UDP);
1054 
1055  int ret = CheckUTHTestPacket(p, IPPROTO_UDP);
1056  UTHFreePacket(p);
1057 
1058  return ret;
1059 }
1060 
1061 /**
1062  * \brief UTHBuildPacketOfFlowsTest01 wrapper to check packets for unittests
1063  */
1064 static int UTHBuildPacketOfFlowsTest01(void)
1065 {
1066  int result = 0;
1067 
1069  uint32_t flow_spare_q_len = FlowSpareGetPoolSize();
1070 
1071  UTHBuildPacketOfFlows(0, 100, 0);
1072 
1073  if (FlowSpareGetPoolSize() != flow_spare_q_len - 100)
1074  result = 0;
1075  else
1076  result = 1;
1077  FlowShutdown();
1078 
1079  return result;
1080 }
1081 
1082 
1083 /**
1084  * \brief UTHBuildPacketSrcDstTest01 wrapper to check packets for unittests
1085  */
1086 static int UTHBuildPacketSrcDstTest01(void)
1087 {
1088  uint8_t payload[] = "Payload";
1089 
1090  Packet *p = UTHBuildPacketSrcDst(payload, sizeof(payload), IPPROTO_TCP,
1091  "192.168.1.5", "192.168.1.1");
1092 
1093  int ret = CheckUTHTestPacket(p, IPPROTO_TCP);
1094  UTHFreePacket(p);
1095 
1096  return ret;
1097 }
1098 
1099 /**
1100  * \brief UTHBuildPacketSrcDstTest02 wrapper to check packets for unittests
1101  */
1102 static int UTHBuildPacketSrcDstTest02(void)
1103 {
1104  uint8_t payload[] = "Payload";
1105 
1106  Packet *p = UTHBuildPacketSrcDst(payload, sizeof(payload), IPPROTO_UDP,
1107  "192.168.1.5", "192.168.1.1");
1108 
1109  int ret = CheckUTHTestPacket(p, IPPROTO_UDP);
1110  UTHFreePacket(p);
1111 
1112  return ret;
1113 }
1114 
1115 /**
1116  * \brief UTHBuildPacketSrcDstPortsTest01 wrapper to check packets for unittests
1117  */
1118 static int UTHBuildPacketSrcDstPortsTest01(void)
1119 {
1120  uint8_t payload[] = "Payload";
1121 
1122  Packet *p = UTHBuildPacketSrcDstPorts(payload, sizeof(payload), IPPROTO_TCP,
1123  41424, 80);
1124 
1125  int ret = CheckUTHTestPacket(p, IPPROTO_TCP);
1126  UTHFreePacket(p);
1127 
1128  return ret;
1129 }
1130 
1131 /**
1132  * \brief UTHBuildPacketSrcDstPortsTest02 wrapper to check packets for unittests
1133  */
1134 static int UTHBuildPacketSrcDstPortsTest02(void)
1135 {
1136  uint8_t payload[] = "Payload";
1137 
1138  Packet *p = UTHBuildPacketSrcDstPorts(payload, sizeof(payload), IPPROTO_UDP,
1139  41424, 80);
1140 
1141  int ret = CheckUTHTestPacket(p, IPPROTO_UDP);
1142  UTHFreePacket(p);
1143 
1144  return ret;
1145 }
1146 
1147 #endif /* UNITTESTS */
1148 
1150 {
1151 #ifdef UNITTESTS
1152  UtRegisterTest("UTHBuildPacketRealTest01", UTHBuildPacketRealTest01);
1153  UtRegisterTest("UTHBuildPacketRealTest02", UTHBuildPacketRealTest02);
1154  UtRegisterTest("UTHBuildPacketTest01", UTHBuildPacketTest01);
1155  UtRegisterTest("UTHBuildPacketTest02", UTHBuildPacketTest02);
1156  UtRegisterTest("UTHBuildPacketSrcDstTest01", UTHBuildPacketSrcDstTest01);
1157  UtRegisterTest("UTHBuildPacketSrcDstTest02", UTHBuildPacketSrcDstTest02);
1158  UtRegisterTest("UTHBuildPacketSrcDstPortsTest01",
1159  UTHBuildPacketSrcDstPortsTest01);
1160  UtRegisterTest("UTHBuildPacketSrcDstPortsTest02",
1161  UTHBuildPacketSrcDstPortsTest02);
1162  UtRegisterTest("UTHBuildPacketOfFlowsTest01", UTHBuildPacketOfFlowsTest01);
1163 
1164 #endif /* UNITTESTS */
1165 }
1166 
UPDATE_DIR_BOTH
@ UPDATE_DIR_BOTH
Definition: stream-tcp-reassemble.h:58
FlowLookupStruct_::work_queue
FlowQueuePrivate work_queue
Definition: flow.h:551
Packet_::proto
uint8_t proto
Definition: decode.h:538
UTHParseSignature
int UTHParseSignature(const char *str, bool expect)
parser a sig and see if the expected result is correct
Definition: util-unittest-helper.c:916
TcpStream_
Definition: stream-tcp-private.h:106
len
uint8_t len
Definition: app-layer-dnp3.h:2
UTHmemsearch
void * UTHmemsearch(const void *big, size_t big_len, const void *little, size_t little_len)
Definition: util-unittest-helper.c:995
TCPHdr_::th_dport
uint16_t th_dport
Definition: decode-tcp.h:151
detect-engine.h
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
UDPHdr_::uh_dport
uint16_t uh_dport
Definition: decode-udp.h:44
TcpStream_::isn
uint32_t isn
Definition: stream-tcp-private.h:113
Flow_::flags
uint64_t flags
Definition: flow.h:408
PKT_HAS_FLOW
#define PKT_HAS_FLOW
Definition: decode.h:1311
UTHAddStreamToFlow
int UTHAddStreamToFlow(Flow *f, int direction, uint8_t *data, uint32_t data_len)
Definition: util-unittest-helper.c:507
FlowSpareGetPoolSize
uint32_t FlowSpareGetPoolSize(void)
Definition: flow-spare-pool.c:46
flow-util.h
stream-tcp.h
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
MPM_HS
@ MPM_HS
Definition: util-mpm.h:54
name
const char * name
Definition: detect-engine-proto.c:47
Flow_::proto
uint8_t proto
Definition: flow.h:381
Packet_::payload
uint8_t * payload
Definition: decode.h:620
PacketAlertCheck
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
Definition: detect-engine-alert.c:144
Packet_::flags
uint32_t flags
Definition: decode.h:562
ssn
TcpSession ssn
Definition: fuzz_dataset.c:31
flow-private.h
Flow_
Flow data structure.
Definition: flow.h:359
UTHBuildPacketSrcDst
Packet * UTHBuildPacketSrcDst(uint8_t *payload, uint16_t payload_len, uint8_t ipproto, const char *src, const char *dst)
UTHBuildPacketSrcDst is a wrapper that build packets specifying IPs and defaulting ports.
Definition: util-unittest-helper.c:403
UTHSetIPV4Hdr
void UTHSetIPV4Hdr(Packet *p, IPV4Hdr *ip4h)
Definition: util-unittest-helper.c:251
TCPHdr_::th_win
uint16_t th_win
Definition: decode-tcp.h:156
UTHSetIPv4Address
uint32_t UTHSetIPv4Address(const char *str)
return the uint32_t for a ipv4 address string
Definition: util-unittest-helper.c:273
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
UTHPacketMatchSigMpm
int UTHPacketMatchSigMpm(Packet *p, char *sig, uint16_t mpm_type)
Definition: util-unittest-helper.c:768
TcpStreamCnf_::sbcnf
StreamingBufferConfig sbcnf
Definition: stream-tcp.h:89
FlowLookupStruct_
Definition: flow.h:547
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
PacketCopyDataOffset
int PacketCopyDataOffset(Packet *p, uint32_t offset, const uint8_t *data, uint32_t datalen)
Copy data to Packet payload at given offset.
Definition: decode.c:340
ICMPV4Hdr
struct ICMPV4Hdr_ ICMPV4Hdr
SCSigSignatureOrderingModuleCleanup
void SCSigSignatureOrderingModuleCleanup(DetectEngineCtx *de_ctx)
De-registers all the signature ordering functions registered.
Definition: detect-engine-sigorder.c:945
PacketL3::hdrs
union PacketL3::Hdrs hdrs
UTHCheckPacketMatchResults
int UTHCheckPacketMatchResults(Packet *p, uint32_t sids[], uint32_t results[], int numsigs)
UTHCheckPacketMatches: function to check if a packet match some sids.
Definition: util-unittest-helper.c:618
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
UTHPacketMatchSig
int UTHPacketMatchSig(Packet *p, const char *sig)
Definition: util-unittest-helper.c:833
StreamingBufferAppend
int StreamingBufferAppend(StreamingBuffer *sb, const StreamingBufferConfig *cfg, StreamingBufferSegment *seg, const uint8_t *data, uint32_t data_len)
Definition: util-streaming-buffer.c:1097
FlowHandlePacket
void FlowHandlePacket(ThreadVars *tv, FlowLookupStruct *fls, Packet *p)
Entry point for packet flow handling.
Definition: flow.c:560
UTHSetTCPHdr
void UTHSetTCPHdr(Packet *p, TCPHdr *tcph)
Definition: util-unittest-helper.c:261
UTHBuildPacket
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
Definition: util-unittest-helper.c:241
SigMatchSignatures
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Definition: detect.c:3305
p
Packet * p
Definition: fuzz_dataset.c:30
SCSigOrderSignatures
int SCSigOrderSignatures(DetectEngineCtx *de_ctx)
Orders the signatures.
Definition: detect-engine-sigorder.c:801
UTHBuildPacketSrcDstPorts
Packet * UTHBuildPacketSrcDstPorts(uint8_t *payload, uint16_t payload_len, uint8_t ipproto, uint16_t sport, uint16_t dport)
UTHBuildPacketSrcDstPorts is a wrapper that build packets specifying src and dst ports and defaulting...
Definition: util-unittest-helper.c:439
Flow_::dp
Port dp
Definition: flow.h:375
UTHSetIPV6Hdr
void UTHSetIPV6Hdr(Packet *p, IPV6Hdr *ip6h)
Definition: util-unittest-helper.c:256
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
stream_config
TcpStreamCnf stream_config
Definition: stream-tcp.c:227
util-spm-bs.h
UTHBuildPacketReal
Packet * UTHBuildPacketReal(uint8_t *payload, uint16_t payload_len, uint8_t ipproto, const char *src, const char *dst, uint16_t sport, uint16_t dport)
UTHBuildPacketReal is a function that create tcp/udp packets for unittests specifying ip and port sou...
Definition: util-unittest-helper.c:136
Flow_::protoctx
void * protoctx
Definition: flow.h:438
FLOW_IPV4
#define FLOW_IPV4
Definition: flow.h:99
Packet_::payload_len
uint16_t payload_len
Definition: decode.h:621
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
FLOWLOCK_UNLOCK
#define FLOWLOCK_UNLOCK(fb)
Definition: flow.h:276
UTHBuildPacketOfFlows
uint32_t UTHBuildPacketOfFlows(uint32_t start, uint32_t end, uint8_t dir)
Definition: util-unittest-helper.c:877
IPV4Hdr
struct IPV4Hdr_ IPV4Hdr
PacketL3::Hdrs::ip6h
IPV6Hdr * ip6h
Definition: decode.h:451
UTHAssignFlow
void UTHAssignFlow(Packet *p, Flow *f)
Definition: util-unittest-helper.c:486
TcpStream_::last_ack
uint32_t last_ack
Definition: stream-tcp-private.h:115
IPV4Hdr_::ip_len
uint16_t ip_len
Definition: decode-ipv4.h:75
flow-spare-pool.h
Flow_::dst
FlowAddress dst
Definition: flow.h:362
FlowInitConfig
void FlowInitConfig(bool quiet)
initialize the configuration
Definition: flow.c:574
SET_PKT_LEN
#define SET_PKT_LEN(p, len)
Definition: decode.h:214
UTHMatchPackets
int UTHMatchPackets(DetectEngineCtx *de_ctx, Packet **p, int num_packets)
Definition: util-unittest-helper.c:727
TCPHdr_::th_sport
uint16_t th_sport
Definition: decode-tcp.h:150
UTHBuildFlow
Flow * UTHBuildFlow(int family, const char *src, const char *dst, Port sp, Port dp)
Definition: util-unittest-helper.c:494
FLOW_INITIALIZE
#define FLOW_INITIALIZE(f)
Definition: flow-util.h:38
UTHBuildPacketIPV6Real
Packet * UTHBuildPacketIPV6Real(uint8_t *payload, uint16_t payload_len, uint8_t ipproto, const char *src, const char *dst, uint16_t sport, uint16_t dport)
UTHBuildPacketReal is a function that create tcp/udp packets for unittests specifying ip and port sou...
Definition: util-unittest-helper.c:297
PACKET_L4_TCP
@ PACKET_L4_TCP
Definition: decode.h:466
TCPHdr_::th_flags
uint8_t th_flags
Definition: decode-tcp.h:155
decode.h
FAIL_IF_NOT_NULL
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
Definition: util-unittest.h:96
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
util-error.h
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
UTHMatchPacketsWithResults
int UTHMatchPacketsWithResults(DetectEngineCtx *de_ctx, Packet **p, int num_packets, uint32_t sids[], uint32_t *results, int numsigs)
Definition: util-unittest-helper.c:686
DetectEngineThreadCtx_
Definition: detect.h:1316
UDPHdr_::uh_len
uint16_t uh_len
Definition: decode-udp.h:45
Packet_::ts
SCTime_t ts
Definition: decode.h:570
TCPHdr_::th_offx2
uint8_t th_offx2
Definition: decode-tcp.h:154
UTHRegisterTests
void UTHRegisterTests(void)
Definition: util-unittest-helper.c:1149
UTHAddSessionToFlow
int UTHAddSessionToFlow(Flow *f, uint32_t ts_isn, uint32_t tc_isn)
Definition: util-unittest-helper.c:523
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
GET_PKT_DATA
#define GET_PKT_DATA(p)
Definition: decode.h:210
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
DetectEngineThreadCtxInit
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
Definition: detect-engine.c:3660
Packet_::sp
Port sp
Definition: decode.h:523
SCSigRegisterSignatureOrderingFuncs
void SCSigRegisterSignatureOrderingFuncs(DetectEngineCtx *de_ctx)
Lets you register the Signature ordering functions. The order in which the functions are registered s...
Definition: detect-engine-sigorder.c:925
PacketFree
void PacketFree(Packet *p)
Return a malloced packet.
Definition: decode.c:221
TH_ACK
#define TH_ACK
Definition: decode-tcp.h:38
TestHelperBufferToFile
int TestHelperBufferToFile(const char *name, const uint8_t *data, size_t size)
writes the contents of a buffer into a file
Definition: util-unittest-helper.c:101
FlowQueuePrivateGetFromTop
Flow * FlowQueuePrivateGetFromTop(FlowQueuePrivate *fqc)
Definition: flow-queue.c:151
BUG_ON
#define BUG_ON(x)
Definition: suricata-common.h:322
BasicSearch
uint8_t * BasicSearch(const uint8_t *haystack, uint32_t haystack_len, const uint8_t *needle, uint16_t needle_len)
Basic search improved. Limits are better handled, so it doesn't start searches that wont fit in the r...
Definition: util-spm-bs.c:49
IPV6Hdr_
Definition: decode-ipv6.h:32
Packet_
Definition: decode.h:516
detect-engine-build.h
TimeGet
SCTime_t TimeGet(void)
Definition: util-time.c:152
stream-tcp-private.h
ICMPV4Hdr_
Definition: decode-icmpv4.h:165
MPM_AC
@ MPM_AC
Definition: util-mpm.h:52
detect-engine-alert.h
Packet_::l4
struct PacketL4 l4
Definition: decode.h:616
Port
uint16_t Port
Definition: decode.h:219
STREAMING_BUFFER_INITIALIZER
#define STREAMING_BUFFER_INITIALIZER
Definition: util-streaming-buffer.h:137
SCLogInfo
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
Definition: util-debug.h:232
Flow_::src
FlowAddress src
Definition: flow.h:362
SigGroupBuild
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
Definition: detect-engine-build.c:2300
dtv
DecodeThreadVars * dtv
Definition: fuzz_decodepcapfile.c:35
StatsThreadInit
void StatsThreadInit(StatsThreadContext *stats)
Definition: counters.c:1332
UTHFreeFlow
void UTHFreeFlow(Flow *flow)
Definition: util-unittest-helper.c:499
StreamingBuffer_
Definition: util-streaming-buffer.h:108
IPV4Hdr_
Definition: decode-ipv4.h:72
FlowLookupStruct_::spare_queue
FlowQueuePrivate spare_queue
Definition: flow.h:549
PacketL3::type
enum PacketL3Types type
Definition: decode.h:445
th_v
ThreadVars * th_v
Definition: fuzz_dataset.c:29
Packet_::flow
struct Flow_ * flow
Definition: decode.h:564
PacketL4::type
enum PacketL4Types type
Definition: decode.h:477
SCNtohs
#define SCNtohs(x)
Definition: suricata-common.h:436
suricata-common.h
FlowFree
void FlowFree(Flow *f)
cleanup & free the memory of a flow
Definition: flow-util.c:85
FLOW_IPV6
#define FLOW_IPV6
Definition: flow.h:101
UTHBuildPacketIPV6SrcDst
Packet * UTHBuildPacketIPV6SrcDst(uint8_t *payload, uint16_t payload_len, uint8_t ipproto, const char *src, const char *dst)
UTHBuildPacketSrcDst is a wrapper that build packets specifying IPs and defaulting ports (IPV6)
Definition: util-unittest-helper.c:421
FlowShutdown
void FlowShutdown(void)
shutdown the flow engine
Definition: flow.c:718
TcpStream_::sb
StreamingBuffer sb
Definition: stream-tcp-private.h:135
UDPHdr
struct UDPHdr_ UDPHdr
DetectEngineThreadCtxDeinit
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Definition: detect-engine.c:3905
Packet_::app_update_direction
uint8_t app_update_direction
Definition: decode.h:550
UDPHdr_::uh_sport
uint16_t uh_sport
Definition: decode-udp.h:43
UDPHdr_
Definition: decode-udp.h:42
TcpSession_::client
TcpStream client
Definition: stream-tcp-private.h:297
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:34
UTHGenericTest
int UTHGenericTest(Packet **pkt, int numpkts, const char *sigs[], uint32_t sids[], uint32_t *results, int numsigs)
UTHGenericTest: function that perform a generic check taking care of as maximum common unittest eleme...
Definition: util-unittest-helper.c:578
PacketGetFromAlloc
Packet * PacketGetFromAlloc(void)
Get a malloced packet.
Definition: decode.c:260
detect-engine-sigorder.h
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
PacketL4::L4Hdrs::tcph
TCPHdr * tcph
Definition: decode.h:481
Packet_::l3
struct PacketL3 l3
Definition: decode.h:615
TcpSession_::server
TcpStream server
Definition: stream-tcp-private.h:296
str
#define str(s)
Definition: suricata-common.h:313
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SCFree
#define SCFree(p)
Definition: util-mem.h:61
DecodeThreadVars_
Structure to hold thread specific data for all decode modules.
Definition: decode.h:995
UTHFreePacket
void UTHFreePacket(Packet *p)
UTHFreePacket: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:470
Signature_::id
uint32_t id
Definition: detect.h:741
PACKET_L3_IPV6
@ PACKET_L3_IPV6
Definition: decode.h:440
StreamTcpSessionCleanup
void StreamTcpSessionCleanup(TcpSession *ssn)
Session cleanup function. Does not free the ssn.
Definition: stream-tcp.c:335
detect-parse.h
src
uint16_t src
Definition: app-layer-dnp3.h:5
Signature_
Signature container.
Definition: detect.h:692
payload_len
uint16_t payload_len
Definition: stream-tcp-private.h:1
PacketL4::hdrs
union PacketL4::L4Hdrs hdrs
UTHBuildPacketFromEth
Packet * UTHBuildPacketFromEth(uint8_t *raw_eth, uint16_t pktsize)
UTHBuildPacketFromEth is a wrapper that build a packet for the rawbytes.
Definition: util-unittest-helper.c:379
SCConfSet
int SCConfSet(const char *name, const char *val)
Set a configuration value.
Definition: conf.c:241
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
Address_::family
char family
Definition: decode.h:114
Packet_::dst
Address dst
Definition: decode.h:521
FLOW_QUIET
#define FLOW_QUIET
Definition: flow.h:43
TestHelperBuildFlow
Flow * TestHelperBuildFlow(int family, const char *src, const char *dst, Port sp, Port dp)
Definition: util-unittest-helper.c:50
IPPROTO_SCTP
#define IPPROTO_SCTP
Definition: decode.h:1273
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
UTHAppendSigs
int UTHAppendSigs(DetectEngineCtx *de_ctx, const char *sigs[], int numsigs)
UTHAppendSigs: Add sigs to the detection_engine checking for errors.
Definition: util-unittest-helper.c:651
TCPHdr
struct TCPHdr_ TCPHdr
Flow_::sp
Port sp
Definition: flow.h:364
dst
uint16_t dst
Definition: app-layer-dnp3.h:4
UTHRemoveSessionFromFlow
int UTHRemoveSessionFromFlow(Flow *f)
Definition: util-unittest-helper.c:543
TcpSession_
Definition: stream-tcp-private.h:283
Packet_::dp
Port dp
Definition: decode.h:531
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
IPV4Hdr_::ip_proto
uint8_t ip_proto
Definition: decode-ipv4.h:79
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
StatsThreadCleanup
void StatsThreadCleanup(StatsThreadContext *stats)
Definition: counters.c:1428
IPV4Hdr_::ip_verhl
uint8_t ip_verhl
Definition: decode-ipv4.h:73
DecodeEthernet
int DecodeEthernet(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint32_t len)
Definition: decode-ethernet.c:41
FLOW_DESTROY
#define FLOW_DESTROY(f)
Definition: flow-util.h:119
TCPHdr_
Definition: decode-tcp.h:149
Packet_::src
Address src
Definition: decode.h:520
f
Flow f
Definition: fuzz_dataset.c:32
UTHFreePackets
void UTHFreePackets(Packet **p, int numpkts)
UTHFreePackets: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:453