• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

OISF / suricata / 22771398406

06 Mar 2026 04:05PM UTC coverage: 60.821% (-18.5%) from 79.291%
22771398406

Pull #14969

github

web-flow
Merge 4bff826f9 into 6ec9e5c95
Pull Request #14969: suricata.yaml: add missing modbus logger v2

132766 of 218288 relevant lines covered (60.82%)

2431625.5 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

88.08
/src/app-layer-parser.c
1
/* Copyright (C) 2007-2026 Open Information Security Foundation
2
 *
3
 * You can copy, redistribute or modify this Program under the terms of
4
 * the GNU General Public License version 2 as published by the Free
5
 * Software Foundation.
6
 *
7
 * This program is distributed in the hope that it will be useful,
8
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
10
 * GNU General Public License for more details.
11
 *
12
 * You should have received a copy of the GNU General Public License
13
 * version 2 along with this program; if not, write to the Free Software
14
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15
 * 02110-1301, USA.
16
 */
17

18
/**
19
 * \file
20
 *
21
 * \author Victor Julien <victor@inliniac.net>
22
 *
23
 * Generic App-layer parsing functions.
24
 */
25

26
#include "suricata-common.h"
27
#include "app-layer-parser.h"
28

29
#include "flow.h"
30
#include "flow-private.h"
31
#include "flow-util.h"
32

33
#include "app-layer-frames.h"
34
#include "app-layer-events.h"
35

36
#include "stream-tcp.h"
37

38
#include "util-validate.h"
39
#include "util-config.h"
40

41
#include "app-layer.h"
42
#include "app-layer-detect-proto.h"
43

44
#include "app-layer-ftp.h"
45
#include "app-layer-smtp.h"
46

47
#include "app-layer-smb.h"
48
#include "app-layer-htp.h"
49
#include "app-layer-ssl.h"
50
#include "app-layer-ssh.h"
51
#include "app-layer-modbus.h"
52
#include "app-layer-dnp3.h"
53
#include "app-layer-nfs-tcp.h"
54
#include "app-layer-nfs-udp.h"
55
#include "app-layer-tftp.h"
56
#include "app-layer-ike.h"
57
#include "app-layer-http2.h"
58
#include "app-layer-imap.h"
59

60
struct AppLayerParserThreadCtx_ {
61
    void *(*alproto_local_storage)[FLOW_PROTO_MAX];
62
};
63

64

65
/**
66
 * \brief App layer protocol parser context.
67
 */
68
typedef struct AppLayerParserProtoCtx_
69
{
70
    /* 0 - to_server, 1 - to_client. */
71
    AppLayerParserFPtr Parser[2];
72

73
    bool logger;
74

75
    /* Indicates the direction the parser is ready to see the data
76
     * the first time for a flow.  Values accepted -
77
     * STREAM_TOSERVER, STREAM_TOCLIENT */
78
    uint8_t first_data_dir;
79

80
    uint32_t logger_bits;   /**< registered loggers for this proto */
81

82
    void *(*StateAlloc)(void *, AppProto);
83
    void (*StateFree)(void *);
84
    void (*StateTransactionFree)(void *, uint64_t);
85
    void *(*LocalStorageAlloc)(void);
86
    void (*LocalStorageFree)(void *);
87

88
    /** get FileContainer reference from the TX. MUST return a non-NULL reference if the TX
89
     *  has or may have files in the requested direction at some point. */
90
    AppLayerGetFileState (*GetTxFiles)(void *, uint8_t);
91

92
    int (*StateGetProgress)(void *alstate, uint8_t direction);
93
    uint64_t (*StateGetTxCnt)(void *alstate);
94
    void *(*StateGetTx)(void *alstate, uint64_t tx_id);
95
    AppLayerGetTxIteratorFunc StateGetTxIterator;
96
    int complete_ts;
97
    int complete_tc;
98
    int (*StateGetEventInfoById)(
99
            uint8_t event_id, const char **event_name, AppLayerEventType *event_type);
100
    int (*StateGetEventInfo)(
101
            const char *event_name, uint8_t *event_id, AppLayerEventType *event_type);
102

103
    AppLayerStateData *(*GetStateData)(void *state);
104
    AppLayerTxData *(*GetTxData)(void *tx);
105
    void (*ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig);
106

107
    void (*SetStreamDepthFlag)(void *tx, uint8_t flags);
108

109
    AppLayerParserGetFrameIdByNameFn GetFrameIdByName;
110
    AppLayerParserGetFrameNameByIdFn GetFrameNameById;
111

112
    AppLayerParserGetStateIdByNameFn GetStateIdByName;
113
    AppLayerParserGetStateNameByIdFn GetStateNameById;
114

115
    /* each app-layer has its own value */
116
    uint32_t stream_depth;
117

118
    /* Option flags such as supporting gaps or not. */
119
    uint32_t option_flags;
120
    /* coccinelle: AppLayerParserProtoCtx:option_flags:APP_LAYER_PARSER_OPT_ */
121

122
    uint32_t internal_flags;
123
    /* coccinelle: AppLayerParserProtoCtx:internal_flags:APP_LAYER_PARSER_INT_ */
124

125
#ifdef UNITTESTS
126
    void (*RegisterUnittests)(void);
127
#endif
128
} AppLayerParserProtoCtx;
129

130
typedef struct AppLayerParserCtx_ {
131
    AppLayerParserProtoCtx (*ctxs)[FLOW_PROTO_MAX];
132
    size_t ctxs_len;
133
} AppLayerParserCtx;
134

135
struct AppLayerParserState_ {
136
    /* coccinelle: AppLayerParserState:flags:APP_LAYER_PARSER_ */
137
    uint16_t flags;
138

139
    /* Indicates the current transaction that is being inspected.
140
     * We have a var per direction. */
141
    uint64_t inspect_id[2];
142
    /* Indicates the current transaction being logged.  Unlike inspect_id,
143
     * we don't need a var per direction since we don't log a transaction
144
     * unless we have the entire transaction. */
145
    uint64_t log_id;
146

147
    uint64_t min_id;
148

149
    /* Used to store decoder events. */
150
    AppLayerDecoderEvents *decoder_events;
151

152
    FramesContainer *frames;
153
};
154

155
enum ExceptionPolicy g_applayerparser_error_policy = EXCEPTION_POLICY_NOT_SET;
156

157
static void AppLayerConfig(void)
158
{
37✔
159
    g_applayerparser_error_policy = ExceptionPolicyParse("app-layer.error-policy", true);
37✔
160
}
37✔
161

162
enum ExceptionPolicy AppLayerErrorGetExceptionPolicy(void)
163
{
340✔
164
    return g_applayerparser_error_policy;
340✔
165
}
340✔
166

167
static void AppLayerParserFramesFreeContainer(FramesContainer *frames)
168
{
35,670✔
169
    if (frames != NULL) {
35,670✔
170
        FramesFree(&frames->toserver);
27,525✔
171
        FramesFree(&frames->toclient);
27,525✔
172
        SCFree(frames);
27,525✔
173
    }
27,525✔
174
}
35,670✔
175

176
void AppLayerFramesFreeContainer(Flow *f)
177
{
1,803✔
178
    if (f == NULL || f->alparser == NULL || f->alparser->frames == NULL)
1,803✔
179
        return;
×
180
    AppLayerParserFramesFreeContainer(f->alparser->frames);
1,803✔
181
    f->alparser->frames = NULL;
1,803✔
182
}
1,803✔
183

184
FramesContainer *AppLayerFramesGetContainer(const Flow *f)
185
{
2,705,694✔
186
    if (f == NULL || f->alparser == NULL)
2,705,694✔
187
        return NULL;
153,726✔
188
    return f->alparser->frames;
2,551,968✔
189
}
2,705,694✔
190

191
FramesContainer *AppLayerFramesSetupContainer(Flow *f)
192
{
1,242,041✔
193
#ifdef UNITTESTS
194
    if (f == NULL || f->alparser == NULL || (f->proto == IPPROTO_TCP && f->protoctx == NULL))
195
        return NULL;
196
#endif
197
    DEBUG_VALIDATE_BUG_ON(f == NULL || f->alparser == NULL);
1,242,041✔
198
    if (f->alparser->frames == NULL) {
1,242,041✔
199
        f->alparser->frames = SCCalloc(1, sizeof(FramesContainer));
27,525✔
200
        if (f->alparser->frames == NULL) {
27,525✔
201
            return NULL;
×
202
        }
×
203
#ifdef DEBUG
204
        f->alparser->frames->toserver.ipproto = f->proto;
205
        f->alparser->frames->toserver.alproto = f->alproto;
206
        f->alparser->frames->toclient.ipproto = f->proto;
207
        f->alparser->frames->toclient.alproto = f->alproto;
208
#endif
209
    }
27,525✔
210
    return f->alparser->frames;
1,242,041✔
211
}
1,242,041✔
212

213
#ifdef UNITTESTS
214
void UTHAppLayerParserStateGetIds(void *ptr, uint64_t *i1, uint64_t *i2, uint64_t *log, uint64_t *min)
215
{
216
    struct AppLayerParserState_ *s = ptr;
217
    *i1 = s->inspect_id[0];
218
    *i2 = s->inspect_id[1];
219
    *log = s->log_id;
220
    *min = s->min_id;
221
}
222
#endif
223

224
/* Static global version of the parser context.
225
 * Post 2.0 let's look at changing this to move it out to app-layer.c. */
226
static AppLayerParserCtx alp_ctx;
227

228
int AppLayerParserProtoIsRegistered(uint8_t ipproto, AppProto alproto)
229
{
4,962✔
230
    uint8_t ipproto_map = FlowGetProtoMapping(ipproto);
4,962✔
231

232
    return (alp_ctx.ctxs[alproto][ipproto_map].StateAlloc != NULL) ? 1 : 0;
4,962✔
233
}
4,962✔
234

235
AppLayerParserState *AppLayerParserStateAlloc(void)
236
{
33,867✔
237
    SCEnter();
33,867✔
238

239
    AppLayerParserState *pstate = (AppLayerParserState *)SCCalloc(1, sizeof(*pstate));
33,867✔
240
    if (pstate == NULL)
33,867✔
241
        goto end;
×
242

243
 end:
33,867✔
244
    SCReturnPtr(pstate, "AppLayerParserState");
33,867✔
245
}
33,867✔
246

247
void AppLayerParserStateFree(AppLayerParserState *pstate)
248
{
33,867✔
249
    SCEnter();
33,867✔
250

251
    if (pstate->decoder_events != NULL)
33,867✔
252
        SCAppLayerDecoderEventsFreeEvents(&pstate->decoder_events);
×
253
    AppLayerParserFramesFreeContainer(pstate->frames);
33,867✔
254
    SCFree(pstate);
33,867✔
255

256
    SCReturn;
33,867✔
257
}
33,867✔
258

259
int AppLayerParserSetup(void)
260
{
37✔
261
    SCEnter();
37✔
262
    // initial allocation that will later be grown using realloc,
263
    // when new protocols register themselves and make g_alproto_max grow
264
    alp_ctx.ctxs = SCCalloc(g_alproto_max, sizeof(AppLayerParserProtoCtx[FLOW_PROTO_MAX]));
37✔
265
    if (unlikely(alp_ctx.ctxs == NULL)) {
37✔
266
        FatalError("Unable to alloc alp_ctx.ctxs.");
×
267
    }
×
268
    alp_ctx.ctxs_len = g_alproto_max;
37✔
269
    SCReturnInt(0);
37✔
270
}
37✔
271

272
void AppLayerParserPostStreamSetup(void)
273
{
35✔
274
    /* lets set a default value for stream_depth */
275
    for (int flow_proto = 0; flow_proto < FLOW_PROTO_DEFAULT; flow_proto++) {
140✔
276
        for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
4,305✔
277
            if (!(alp_ctx.ctxs[alproto][flow_proto].internal_flags &
4,200✔
278
                        APP_LAYER_PARSER_INT_STREAM_DEPTH_SET)) {
4,200✔
279
                alp_ctx.ctxs[alproto][flow_proto].stream_depth = stream_config.reassembly_depth;
4,158✔
280
            }
4,158✔
281
        }
4,200✔
282
    }
105✔
283
}
35✔
284

285
int AppLayerParserDeSetup(void)
286
{
28✔
287
    SCEnter();
28✔
288

289
    SCFree(alp_ctx.ctxs);
28✔
290

291
    FTPParserCleanup();
28✔
292
    SMTPParserCleanup();
28✔
293

294
    SCReturnInt(0);
28✔
295
}
28✔
296

297
AppLayerParserThreadCtx *AppLayerParserThreadCtxAlloc(void)
298
{
229✔
299
    SCEnter();
229✔
300

301
    AppLayerParserThreadCtx *tctx = SCCalloc(1, sizeof(*tctx));
229✔
302
    if (tctx == NULL)
229✔
303
        goto end;
×
304

305
    tctx->alproto_local_storage = SCCalloc(g_alproto_max, sizeof(void *[FLOW_PROTO_MAX]));
229✔
306
    if (unlikely(tctx->alproto_local_storage == NULL)) {
229✔
307
        SCFree(tctx);
×
308
        tctx = NULL;
×
309
        goto end;
×
310
    }
×
311
    for (uint8_t flow_proto = 0; flow_proto < FLOW_PROTO_DEFAULT; flow_proto++) {
916✔
312
        for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
28,167✔
313
            uint8_t ipproto = FlowGetReverseProtoMapping(flow_proto);
27,480✔
314

315
            tctx->alproto_local_storage[alproto][flow_proto] =
27,480✔
316
                    AppLayerParserGetProtocolParserLocalStorage(ipproto, alproto);
27,480✔
317
        }
27,480✔
318
    }
687✔
319

320
 end:
229✔
321
    SCReturnPtr(tctx, "void *");
229✔
322
}
229✔
323

324
void AppLayerParserThreadCtxFree(AppLayerParserThreadCtx *tctx)
325
{
225✔
326
    SCEnter();
225✔
327

328
    for (uint8_t flow_proto = 0; flow_proto < FLOW_PROTO_DEFAULT; flow_proto++) {
900✔
329
        for (AppProto alproto = 0; alproto < g_alproto_max; alproto++) {
27,675✔
330
            uint8_t ipproto = FlowGetReverseProtoMapping(flow_proto);
27,000✔
331

332
            AppLayerParserDestroyProtocolParserLocalStorage(
27,000✔
333
                    ipproto, alproto, tctx->alproto_local_storage[alproto][flow_proto]);
27,000✔
334
        }
27,000✔
335
    }
675✔
336

337
    SCFree(tctx->alproto_local_storage);
225✔
338
    SCFree(tctx);
225✔
339
    SCReturn;
225✔
340
}
225✔
341

342
/** \brief check if a parser is enabled in the config
343
 *  Returns enabled always if: were running unittests
344
 */
345
int SCAppLayerParserConfParserEnabled(const char *ipproto, const char *alproto_name)
346
{
1,421✔
347
    SCEnter();
1,421✔
348

349
    char param[100];
1,421✔
350
    SCConfNode *g_proto, *i_proto;
1,421✔
351
    bool g_enabled = false;
1,421✔
352
    bool i_enabled = false;
1,421✔
353
    int r;
1,421✔
354

355
    if (RunmodeIsUnittests())
1,421✔
356
        SCReturnInt(1);
×
357

358
    r = snprintf(param, sizeof(param), "%s%s%s%s%s", "app-layer.protocols.", alproto_name, ".",
1,421✔
359
            ipproto, ".enabled");
1,421✔
360
    if (r < 0) {
1,421✔
361
        FatalError("snprintf failure.");
×
362
    } else if (r > (int)sizeof(param)) {
1,421✔
363
        FatalError("buffer not big enough to write param.");
×
364
    }
×
365
    SCLogDebug("Looking for %s", param);
1,421✔
366

367
    i_proto = SCConfGetNode(param);
1,421✔
368
    if (i_proto && i_proto->val) {
1,421✔
369
        if (SCConfValIsTrue(i_proto->val)) {
28✔
370
            i_enabled = true;
28✔
371
        } else if (SCConfValIsFalse(i_proto->val)) {
28✔
372
            i_enabled = false;
×
373
        } else if (strcasecmp(i_proto->val, "detection-only") == 0) {
×
374
            i_enabled = false;
×
375
        } else {
×
376
            FatalError("Invalid value found for %s.", param);
×
377
        }
×
378
    }
28✔
379

380
    r = snprintf(param, sizeof(param), "%s%s%s", "app-layer.protocols.", alproto_name, ".enabled");
1,421✔
381
    if (r < 0) {
1,421✔
382
        FatalError("snprintf failure.");
×
383
    } else if (r > (int)sizeof(param)) {
1,421✔
384
        FatalError("buffer not big enough to write param.");
×
385
    }
×
386

387
    SCLogDebug("Looking for %s", param);
1,421✔
388
    g_proto = SCConfGetNode(param);
1,421✔
389
    if (g_proto && g_proto->val) {
1,421✔
390
        if (SCConfValIsTrue(g_proto->val)) {
224✔
391
            g_enabled = true;
224✔
392
        } else if (SCConfValIsFalse(g_proto->val)) {
224✔
393
            g_enabled = false;
×
394
        } else if (strcasecmp(g_proto->val, "detection-only") == 0) {
×
395
            g_enabled = false;
×
396
        } else {
×
397
            FatalError("Invalid value found for %s", param);
×
398
        }
×
399
    }
224✔
400

401
    if ((i_proto && g_proto) && (i_enabled ^ g_enabled)) {
1,421✔
402
        /* these checks are also performed for detection-only, no need to issue double warning */
403
        SCLogDebug("Inconsistent global (%s) and respective ipproto (%s) settings found for "
×
404
                   "alproto %s and ipproto %s",
×
405
                g_enabled ? "TRUE" : "FALSE", i_enabled ? "TRUE" : "FALSE", alproto_name, ipproto);
×
406
    }
×
407

408
    if (i_proto) {
1,421✔
409
        SCReturnInt(i_enabled);
28✔
410
    }
28✔
411
    if (g_proto) {
1,393✔
412
        SCReturnInt(g_enabled);
224✔
413
    }
224✔
414

415
    SCReturnInt(1);
1,393✔
416
}
1,393✔
417

418
/***** Parser related registration *****/
419

420
int AppLayerParserRegisterParser(uint8_t ipproto, AppProto alproto,
421
                      uint8_t direction,
422
                      AppLayerParserFPtr Parser)
423
{
2,860✔
424
    SCEnter();
2,860✔
425

426
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)]
2,860✔
427
            .Parser[(direction & STREAM_TOSERVER) ? 0 : 1] = Parser;
2,860✔
428

429
    SCReturnInt(0);
2,860✔
430
}
2,860✔
431

432
void SCAppLayerParserRegisterParserAcceptableDataDirection(
433
        uint8_t ipproto, AppProto alproto, uint8_t direction)
434
{
208✔
435
    SCEnter();
208✔
436

437
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].first_data_dir |=
208✔
438
            (direction & (STREAM_TOSERVER | STREAM_TOCLIENT));
208✔
439

440
    SCReturn;
208✔
441
}
208✔
442

443
void AppLayerParserRegisterOptionFlags(uint8_t ipproto, AppProto alproto,
444
        uint32_t flags)
445
{
358✔
446
    SCEnter();
358✔
447

448
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].option_flags |= flags;
358✔
449

450
    SCReturn;
358✔
451
}
358✔
452

453
void AppLayerParserRegisterStateFuncs(uint8_t ipproto, AppProto alproto,
454
        void *(*StateAlloc)(void *, AppProto), void (*StateFree)(void *))
455
{
1,430✔
456
    SCEnter();
1,430✔
457

458
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateAlloc = StateAlloc;
1,430✔
459
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateFree = StateFree;
1,430✔
460

461
    SCReturn;
1,430✔
462
}
1,430✔
463

464
void AppLayerParserRegisterLocalStorageFunc(uint8_t ipproto, AppProto alproto,
465
                                 void *(*LocalStorageAlloc)(void),
466
                                 void (*LocalStorageFree)(void *))
467
{
74✔
468
    SCEnter();
74✔
469

470
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageAlloc = LocalStorageAlloc;
74✔
471
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageFree = LocalStorageFree;
74✔
472

473
    SCReturn;
74✔
474
}
74✔
475

476
void AppLayerParserRegisterGetTxFilesFunc(
477
        uint8_t ipproto, AppProto alproto, AppLayerGetFileState (*GetTxFiles)(void *, uint8_t))
478
{
296✔
479
    SCEnter();
296✔
480

481
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxFiles = GetTxFiles;
296✔
482

483
    SCReturn;
296✔
484
}
296✔
485

486
void AppLayerParserRegisterLoggerBits(uint8_t ipproto, AppProto alproto, LoggerId bits)
487
{
556✔
488
    SCEnter();
556✔
489

490
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].logger_bits = bits;
556✔
491

492
    SCReturn;
556✔
493
}
556✔
494

495
void SCAppLayerParserRegisterLogger(uint8_t ipproto, AppProto alproto)
496
{
927✔
497
    SCEnter();
927✔
498

499
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].logger = true;
927✔
500

501
    SCReturn;
927✔
502
}
927✔
503

504
void AppLayerParserRegisterGetStateProgressFunc(uint8_t ipproto, AppProto alproto,
505
    int (*StateGetProgress)(void *alstate, uint8_t direction))
506
{
1,430✔
507
    SCEnter();
1,430✔
508

509
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetProgress = StateGetProgress;
1,430✔
510

511
    SCReturn;
1,430✔
512
}
1,430✔
513

514
void AppLayerParserRegisterTxFreeFunc(uint8_t ipproto, AppProto alproto,
515
                           void (*StateTransactionFree)(void *, uint64_t))
516
{
1,430✔
517
    SCEnter();
1,430✔
518

519
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateTransactionFree = StateTransactionFree;
1,430✔
520

521
    SCReturn;
1,430✔
522
}
1,430✔
523

524
void AppLayerParserRegisterGetTxCnt(uint8_t ipproto, AppProto alproto,
525
                         uint64_t (*StateGetTxCnt)(void *alstate))
526
{
1,430✔
527
    SCEnter();
1,430✔
528

529
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTxCnt = StateGetTxCnt;
1,430✔
530

531
    SCReturn;
1,430✔
532
}
1,430✔
533

534
void AppLayerParserRegisterGetTx(uint8_t ipproto, AppProto alproto,
535
                      void *(StateGetTx)(void *alstate, uint64_t tx_id))
536
{
1,430✔
537
    SCEnter();
1,430✔
538

539
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTx = StateGetTx;
1,430✔
540

541
    SCReturn;
1,430✔
542
}
1,430✔
543

544
void AppLayerParserRegisterGetTxIterator(uint8_t ipproto, AppProto alproto,
545
                      AppLayerGetTxIteratorFunc Func)
546
{
1,282✔
547
    SCEnter();
1,282✔
548
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTxIterator = Func;
1,282✔
549
    SCReturn;
1,282✔
550
}
1,282✔
551

552
void AppLayerParserRegisterStateProgressCompletionStatus(
553
        AppProto alproto, const int ts, const int tc)
554
{
1,430✔
555
    BUG_ON(ts == 0);
1,430✔
556
    BUG_ON(tc == 0);
1,430✔
557
    BUG_ON(!AppProtoIsValid(alproto));
1,430✔
558
    BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts != 0 &&
1,430✔
559
            alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts != ts);
1,430✔
560
    BUG_ON(alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc != 0 &&
1,430✔
561
            alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc != tc);
1,430✔
562

563
    alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts = ts;
1,430✔
564
    alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc = tc;
1,430✔
565
}
1,430✔
566

567
void AppLayerParserRegisterGetEventInfoById(uint8_t ipproto, AppProto alproto,
568
        int (*StateGetEventInfoById)(
569
                uint8_t event_id, const char **event_name, AppLayerEventType *event_type))
570
{
1,245✔
571
    SCEnter();
1,245✔
572

573
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetEventInfoById =
1,245✔
574
            StateGetEventInfoById;
1,245✔
575

576
    SCReturn;
1,245✔
577
}
1,245✔
578

579
void AppLayerParserRegisterGetStateFuncs(uint8_t ipproto, AppProto alproto,
580
        AppLayerParserGetStateIdByNameFn GetIdByNameFunc,
581
        AppLayerParserGetStateNameByIdFn GetNameByIdFunc)
582
{
111✔
583
    SCEnter();
111✔
584
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateIdByName = GetIdByNameFunc;
111✔
585
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateNameById = GetNameByIdFunc;
111✔
586
    SCReturn;
111✔
587
}
111✔
588

589
void AppLayerParserRegisterGetFrameFuncs(uint8_t ipproto, AppProto alproto,
590
        AppLayerParserGetFrameIdByNameFn GetIdByNameFunc,
591
        AppLayerParserGetFrameNameByIdFn GetNameByIdFunc)
592
{
837✔
593
    SCEnter();
837✔
594
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameIdByName = GetIdByNameFunc;
837✔
595
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameNameById = GetNameByIdFunc;
837✔
596
    SCReturn;
837✔
597
}
837✔
598

599
void AppLayerParserRegisterGetEventInfo(uint8_t ipproto, AppProto alproto,
600
        int (*StateGetEventInfo)(
601
                const char *event_name, uint8_t *event_id, AppLayerEventType *event_type))
602
{
1,282✔
603
    SCEnter();
1,282✔
604

605
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetEventInfo = StateGetEventInfo;
1,282✔
606

607
    SCReturn;
1,282✔
608
}
1,282✔
609

610
void AppLayerParserRegisterTxDataFunc(uint8_t ipproto, AppProto alproto,
611
        AppLayerTxData *(*GetTxData)(void *tx))
612
{
1,430✔
613
    SCEnter();
1,430✔
614

615
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxData = GetTxData;
1,430✔
616

617
    SCReturn;
1,430✔
618
}
1,430✔
619

620
void AppLayerParserRegisterStateDataFunc(
621
        uint8_t ipproto, AppProto alproto, AppLayerStateData *(*GetStateData)(void *state))
622
{
1,430✔
623
    SCEnter();
1,430✔
624

625
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateData = GetStateData;
1,430✔
626

627
    SCReturn;
1,430✔
628
}
1,430✔
629

630
void AppLayerParserRegisterApplyTxConfigFunc(uint8_t ipproto, AppProto alproto,
631
        void (*ApplyTxConfig)(void *state, void *tx, int mode, AppLayerTxConfig))
632
{
74✔
633
    SCEnter();
74✔
634

635
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].ApplyTxConfig = ApplyTxConfig;
74✔
636

637
    SCReturn;
74✔
638
}
74✔
639

640
void AppLayerParserRegisterSetStreamDepthFlag(uint8_t ipproto, AppProto alproto,
641
        void (*SetStreamDepthFlag)(void *tx, uint8_t flags))
642
{
37✔
643
    SCEnter();
37✔
644

645
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].SetStreamDepthFlag = SetStreamDepthFlag;
37✔
646

647
    SCReturn;
37✔
648
}
37✔
649

650
/***** Get and transaction functions *****/
651

652
void *AppLayerParserGetProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto)
653
{
27,480✔
654
    SCEnter();
27,480✔
655
    void * r = NULL;
27,480✔
656

657
    if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageAlloc != NULL) {
27,480✔
658
        r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageAlloc();
458✔
659
    }
458✔
660

661
    SCReturnPtr(r, "void *");
27,480✔
662
}
27,480✔
663

664
void AppLayerParserDestroyProtocolParserLocalStorage(uint8_t ipproto, AppProto alproto,
665
                                          void *local_data)
666
{
27,000✔
667
    SCEnter();
27,000✔
668

669
    if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageFree != NULL) {
27,000✔
670
        alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].LocalStorageFree(local_data);
450✔
671
    }
450✔
672

673
    SCReturn;
27,000✔
674
}
27,000✔
675

676
/** \brief default tx iterator
677
 *
678
 *  Used if the app layer parser doesn't register its own iterator.
679
 *  Simply walks the tx_id space until it finds a tx. Uses 'state' to
680
 *  keep track of where it left off.
681
 *
682
 *  \retval txptr or NULL if no more txs in list
683
 */
684
static AppLayerGetTxIterTuple AppLayerDefaultGetTxIterator(
685
        const uint8_t ipproto, const AppProto alproto,
686
        void *alstate, uint64_t min_tx_id, uint64_t max_tx_id,
687
        AppLayerGetTxIterState *state)
688
{
132,171✔
689
    uint64_t ustate = *(uint64_t *)state;
132,171✔
690
    uint64_t tx_id = MAX(min_tx_id, ustate);
132,171✔
691
    for ( ; tx_id < max_tx_id; tx_id++) {
132,171✔
692
        void *tx_ptr = AppLayerParserGetTx(ipproto, alproto, alstate, tx_id);
124,080✔
693
        if (tx_ptr != NULL) {
124,080✔
694
            ustate = tx_id + 1;
124,080✔
695
            *state = *(AppLayerGetTxIterState *)&ustate;
124,080✔
696
            AppLayerGetTxIterTuple tuple = {
124,080✔
697
                .tx_ptr = tx_ptr,
124,080✔
698
                .tx_id = tx_id,
124,080✔
699
                .has_next = (tx_id + 1 < max_tx_id),
124,080✔
700
            };
124,080✔
701
            SCLogDebug("tuple: %p/%"PRIu64"/%s", tuple.tx_ptr, tuple.tx_id,
124,080✔
702
                    tuple.has_next ? "true" : "false");
124,080✔
703
            return tuple;
124,080✔
704
        }
124,080✔
705
    }
124,080✔
706

707
    AppLayerGetTxIterTuple no_tuple = { NULL, 0, false };
8,091✔
708
    return no_tuple;
8,091✔
709
}
132,171✔
710

711
AppLayerGetTxIteratorFunc AppLayerGetTxIterator(const uint8_t ipproto,
712
        const AppProto alproto)
713
{
2,449,626✔
714
    AppLayerGetTxIteratorFunc Func =
2,449,626✔
715
            alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTxIterator;
2,449,626✔
716
    return Func ? Func : AppLayerDefaultGetTxIterator;
2,449,626✔
717
}
2,449,626✔
718

719
uint64_t AppLayerParserGetTransactionLogId(AppLayerParserState *pstate)
720
{
729,579✔
721
    SCEnter();
729,579✔
722

723
    SCReturnCT((pstate == NULL) ? 0 : pstate->log_id, "uint64_t");
729,579✔
724
}
729,579✔
725

726
uint64_t AppLayerParserGetMinId(AppLayerParserState *pstate)
727
{
8,942✔
728
    SCEnter();
8,942✔
729

730
    SCReturnCT((pstate == NULL) ? 0 : pstate->min_id, "uint64_t");
8,942✔
731
}
8,942✔
732

733
void AppLayerParserSetTransactionLogId(AppLayerParserState *pstate, uint64_t tx_id)
734
{
75,519✔
735
    SCEnter();
75,519✔
736

737
    if (pstate != NULL)
75,519✔
738
        pstate->log_id = tx_id;
75,519✔
739

740
    SCReturn;
75,519✔
741
}
75,519✔
742

743
uint64_t AppLayerParserGetTransactionInspectId(AppLayerParserState *pstate, uint8_t direction)
744
{
1,020,441✔
745
    SCEnter();
1,020,441✔
746

747
    if (pstate != NULL)
1,020,441✔
748
        SCReturnCT(pstate->inspect_id[(direction & STREAM_TOSERVER) ? 0 : 1], "uint64_t");
1,020,441✔
749

750
    DEBUG_VALIDATE_BUG_ON(1);
×
751
    SCReturnCT(0ULL, "uint64_t");
×
752
}
1,020,441✔
753

754
inline uint8_t AppLayerParserGetTxDetectProgress(AppLayerTxData *txd, const uint8_t dir)
755
{
×
756
    uint8_t p = (dir & STREAM_TOSERVER) ? txd->detect_progress_ts : txd->detect_progress_tc;
×
757
    return p;
×
758
}
×
759

760
static inline uint32_t GetTxLogged(AppLayerTxData *txd)
761
{
173,180✔
762
    return txd->logged;
173,180✔
763
}
173,180✔
764

765
void SCAppLayerTxDataCleanup(AppLayerTxData *txd)
766
{
278,064✔
767
    if (txd->de_state) {
278,064✔
768
        SCDetectEngineStateFree(txd->de_state);
16,871✔
769
    }
16,871✔
770
    if (txd->events) {
278,064✔
771
        SCAppLayerDecoderEventsFreeEvents(&txd->events);
15,501✔
772
    }
15,501✔
773
    if (txd->txbits) {
278,064✔
774
        SCGenericVarFree(txd->txbits);
×
775
    }
×
776
}
278,064✔
777

778
void AppLayerParserSetTransactionInspectId(const Flow *f, AppLayerParserState *pstate,
779
                                           void *alstate, const uint8_t flags,
780
                                           bool tag_txs_as_inspected)
781
{
493,165✔
782
    SCEnter();
493,165✔
783

784
    const int direction = (flags & STREAM_TOSERVER) ? 0 : 1;
493,165✔
785
    const uint64_t total_txs = AppLayerParserGetTxCnt(f, alstate);
493,165✔
786
    uint64_t idx = AppLayerParserGetTransactionInspectId(pstate, flags);
493,165✔
787
    const int state_done_progress = AppLayerParserGetStateProgressCompletionStatus(f->alproto, flags);
493,165✔
788
    const uint8_t ipproto = f->proto;
493,165✔
789
    const AppProto alproto = f->alproto;
493,165✔
790

791
    AppLayerGetTxIteratorFunc IterFunc = AppLayerGetTxIterator(ipproto, alproto);
493,165✔
792
    AppLayerGetTxIterState state = { 0 };
493,165✔
793

794
    SCLogDebug("called: %s, tag_txs_as_inspected %s",direction==0?"toserver":"toclient",
493,165✔
795
            tag_txs_as_inspected?"true":"false");
493,165✔
796

797
    /* mark all txs as inspected if the applayer progress is
798
     * at the 'end state'. */
799
    while (1) {
537,566✔
800
        AppLayerGetTxIterTuple ires = IterFunc(ipproto, alproto, alstate, idx, total_txs, &state);
537,566✔
801
        if (ires.tx_ptr == NULL)
537,566✔
802
            break;
80,400✔
803

804
        void *tx = ires.tx_ptr;
457,166✔
805
        idx = ires.tx_id;
457,166✔
806

807
        int state_progress = AppLayerParserGetStateProgress(ipproto, alproto, tx, flags);
457,166✔
808
        if (state_progress < state_done_progress)
457,166✔
809
            break;
343,322✔
810

811
        AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
113,844✔
812
        if (tag_txs_as_inspected) {
113,844✔
813
            const uint8_t inspected_flag = (flags & STREAM_TOSERVER) ? APP_LAYER_TX_INSPECTED_TS
2,421✔
814
                                                                     : APP_LAYER_TX_INSPECTED_TC;
2,421✔
815
            if (txd->flags & inspected_flag) {
2,421✔
816
                txd->flags |= inspected_flag;
×
817
                SCLogDebug("%p/%" PRIu64 " in-order tx is done for direction %s. Flags %02x", tx,
×
818
                        idx, flags & STREAM_TOSERVER ? "toserver" : "toclient", txd->flags);
×
819
            }
×
820
        }
2,421✔
821
        idx++;
113,844✔
822
        if (!ires.has_next)
113,844✔
823
            break;
69,443✔
824
    }
113,844✔
825
    pstate->inspect_id[direction] = idx;
493,165✔
826
    SCLogDebug("inspect_id now %"PRIu64, pstate->inspect_id[direction]);
493,165✔
827

828
    /* if necessary we flag all txs that are complete as 'inspected'
829
     * also move inspect_id forward. */
830
    if (tag_txs_as_inspected) {
493,165✔
831
        /* continue at idx */
832
        while (1) {
8,654✔
833
            AppLayerGetTxIterTuple ires = IterFunc(ipproto, alproto, alstate, idx, total_txs, &state);
8,654✔
834
            if (ires.tx_ptr == NULL)
8,654✔
835
                break;
5,800✔
836

837
            void *tx = ires.tx_ptr;
2,854✔
838
            /* if we got a higher id than the minimum we requested, we
839
             * skipped a bunch of 'null-txs'. Lets see if we can up the
840
             * inspect tracker */
841
            if (ires.tx_id > idx && pstate->inspect_id[direction] == idx) {
2,854✔
842
                pstate->inspect_id[direction] = ires.tx_id;
3✔
843
            }
3✔
844
            idx = ires.tx_id;
2,854✔
845

846
            const int state_progress = AppLayerParserGetStateProgress(ipproto, alproto, tx, flags);
2,854✔
847
            if (state_progress < state_done_progress)
2,854✔
848
                break;
2,850✔
849

850
            /* txd can be NULL for HTTP sessions where the user data alloc failed */
851
            AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
4✔
852
            const uint8_t inspected_flag = (flags & STREAM_TOSERVER) ? APP_LAYER_TX_INSPECTED_TS
4✔
853
                                                                     : APP_LAYER_TX_INSPECTED_TC;
4✔
854
            if (txd->flags & inspected_flag) {
4✔
855
                txd->flags |= inspected_flag;
×
856
                SCLogDebug("%p/%" PRIu64 " out of order tx is done for direction %s. Flag %02x", tx,
×
857
                        idx, flags & STREAM_TOSERVER ? "toserver" : "toclient", txd->flags);
×
858

859
                SCLogDebug("%p/%" PRIu64 " out of order tx. Update inspect_id? %" PRIu64, tx, idx,
×
860
                        pstate->inspect_id[direction]);
×
861
                if (pstate->inspect_id[direction] + 1 == idx)
×
862
                    pstate->inspect_id[direction] = idx;
×
863
            }
×
864
            if (!ires.has_next)
4✔
865
                break;
2✔
866
            idx++;
2✔
867
        }
2✔
868
    }
8,652✔
869

870
    SCReturn;
493,165✔
871
}
493,165✔
872

873
AppLayerDecoderEvents *AppLayerParserGetDecoderEvents(AppLayerParserState *pstate)
874
{
1,958,461✔
875
    SCEnter();
1,958,461✔
876

877
    SCReturnPtr(pstate->decoder_events,
1,958,461✔
878
                "AppLayerDecoderEvents *");
1,958,461✔
879
}
1,958,461✔
880

881
AppLayerDecoderEvents *AppLayerParserGetEventsByTx(uint8_t ipproto, AppProto alproto,
882
                                        void *tx)
883
{
2,100,739✔
884
    SCEnter();
2,100,739✔
885

886
    AppLayerDecoderEvents *ptr = NULL;
2,100,739✔
887

888
    /* Access events via the tx_data. */
889
    AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
2,100,739✔
890
    if (txd->events != NULL) {
2,100,739✔
891
        ptr = txd->events;
99,862✔
892
    }
99,862✔
893

894
    SCReturnPtr(ptr, "AppLayerDecoderEvents *");
2,100,739✔
895
}
2,100,739✔
896

897
AppLayerGetFileState AppLayerParserGetTxFiles(const Flow *f, void *tx, const uint8_t direction)
898
{
909,305✔
899
    SCEnter();
909,305✔
900

901
    if (alp_ctx.ctxs[f->alproto][f->protomap].GetTxFiles != NULL) {
909,305✔
902
        return alp_ctx.ctxs[f->alproto][f->protomap].GetTxFiles(tx, direction);
892,971✔
903
    }
892,971✔
904

905
    AppLayerGetFileState files = { .fc = NULL, .cfg = NULL };
16,334✔
906
    return files;
16,334✔
907
}
909,305✔
908

909
static void AppLayerParserFileTxHousekeeping(
910
        const Flow *f, void *tx, const uint8_t pkt_dir, const bool trunc)
911
{
135,056✔
912
    AppLayerGetFileState files = AppLayerParserGetTxFiles(f, tx, pkt_dir);
135,056✔
913
    if (files.fc) {
135,056✔
914
        FilesPrune(files.fc, files.cfg, trunc);
135,056✔
915
    }
135,056✔
916
}
135,056✔
917

918
#define IS_DISRUPTED(flags) ((flags) & (STREAM_DEPTH | STREAM_GAP))
6,736,097✔
919

920
extern int g_detect_disabled;
921
extern bool g_file_logger_enabled;
922
extern bool g_filedata_logger_enabled;
923

924
/**
925
 * \brief remove obsolete (inspected and logged) transactions
926
 */
927
void AppLayerParserTransactionsCleanup(Flow *f, const uint8_t pkt_dir)
928
{
747,998✔
929
    SCEnter();
747,998✔
930
    DEBUG_ASSERT_FLOW_LOCKED(f);
747,998✔
931

932
    AppLayerParserProtoCtx *p = &alp_ctx.ctxs[f->alproto][f->protomap];
747,998✔
933
    if (unlikely(p->StateTransactionFree == NULL))
747,998✔
934
        SCReturn;
14,567✔
935

936
    const bool has_tx_detect_flags = !g_detect_disabled;
733,431✔
937
    const uint8_t ipproto = f->proto;
733,431✔
938
    const AppProto alproto = f->alproto;
733,431✔
939
    void * const alstate = f->alstate;
733,431✔
940
    AppLayerParserState * const alparser = f->alparser;
733,431✔
941

942
    if (alstate == NULL || alparser == NULL)
733,431✔
943
        SCReturn;
4✔
944

945
    const uint64_t min = alparser->min_id;
733,427✔
946
    const uint64_t total_txs = AppLayerParserGetTxCnt(f, alstate);
733,427✔
947
    const LoggerId logger_expectation = AppLayerParserProtocolGetLoggerBits(ipproto, alproto);
733,427✔
948
    const int tx_end_state_ts = AppLayerParserGetStateProgressCompletionStatus(alproto, STREAM_TOSERVER);
733,427✔
949
    const int tx_end_state_tc = AppLayerParserGetStateProgressCompletionStatus(alproto, STREAM_TOCLIENT);
733,427✔
950
    const uint8_t ts_disrupt_flags = FlowGetDisruptionFlags(f, STREAM_TOSERVER);
733,427✔
951
    const uint8_t tc_disrupt_flags = FlowGetDisruptionFlags(f, STREAM_TOCLIENT);
733,427✔
952

953
    int pkt_dir_trunc = -1;
733,427✔
954

955
    AppLayerGetTxIteratorFunc IterFunc = AppLayerGetTxIterator(ipproto, alproto);
733,427✔
956
    AppLayerGetTxIterState state;
733,427✔
957
    memset(&state, 0, sizeof(state));
733,427✔
958
    uint64_t i = min;
733,427✔
959
    uint64_t new_min = min;
733,427✔
960
    SCLogDebug("start min %"PRIu64, min);
733,427✔
961
    bool skipped = false;
733,427✔
962
    // const bool support_files = AppLayerParserSupportsFiles(f->proto, f->alproto);
963

964
    while (1) {
4,635,904✔
965
        AppLayerGetTxIterTuple ires = IterFunc(ipproto, alproto, alstate, i, total_txs, &state);
4,635,904✔
966
        if (ires.tx_ptr == NULL)
4,635,904✔
967
            break;
236,409✔
968

969
        bool tx_skipped = false;
4,635,904✔
970
        void *tx = ires.tx_ptr;
4,399,495✔
971
        i = ires.tx_id; // actual tx id for the tx the IterFunc returned
4,399,495✔
972

973
        SCLogDebug("%p/%"PRIu64" checking", tx, i);
4,399,495✔
974
        AppLayerTxData *txd = AppLayerParserGetTxData(ipproto, alproto, tx);
4,399,495✔
975
        if (AppLayerParserHasFilesInDir(txd, pkt_dir)) {
4,399,495✔
976
            if (pkt_dir_trunc == -1)
135,056✔
977
                pkt_dir_trunc = IS_DISRUPTED(
114,565✔
978
                        (pkt_dir == STREAM_TOSERVER) ? ts_disrupt_flags : tc_disrupt_flags);
135,056✔
979
            AppLayerParserFileTxHousekeeping(f, tx, pkt_dir, (bool)pkt_dir_trunc);
135,056✔
980
        }
135,056✔
981
        // should be reset by parser next time it updates the tx
982
        if (pkt_dir & STREAM_TOSERVER) {
4,399,495✔
983
            txd->updated_ts = false;
2,803,989✔
984
        } else {
2,803,989✔
985
            txd->updated_tc = false;
1,595,506✔
986
        }
1,595,506✔
987
        const int tx_progress_tc =
4,399,495✔
988
                AppLayerParserGetStateProgress(ipproto, alproto, tx, tc_disrupt_flags);
4,399,495✔
989
        if (tx_progress_tc < tx_end_state_tc) {
4,399,495✔
990
            SCLogDebug("%p/%"PRIu64" skipping: tc parser not done", tx, i);
2,201,506✔
991
            skipped = true;
2,201,506✔
992
            goto next;
2,201,506✔
993
        }
2,201,506✔
994
        const int tx_progress_ts =
2,197,989✔
995
                AppLayerParserGetStateProgress(ipproto, alproto, tx, ts_disrupt_flags);
2,197,989✔
996
        if (tx_progress_ts < tx_end_state_ts) {
2,197,989✔
997
            SCLogDebug("%p/%"PRIu64" skipping: ts parser not done", tx, i);
542,606✔
998
            skipped = true;
542,606✔
999
            goto next;
542,606✔
1000
        }
542,606✔
1001

1002
        if (has_tx_detect_flags) {
1,655,383✔
1003
            if (!IS_DISRUPTED(ts_disrupt_flags) &&
1,655,383✔
1004
                    (f->sgh_toserver != NULL || (f->flags & FLOW_SGH_TOSERVER) == 0)) {
1,655,383✔
1005
                if ((txd->flags & (APP_LAYER_TX_INSPECTED_TS | APP_LAYER_TX_SKIP_INSPECT_TS)) ==
1,561,743✔
1006
                        0) {
1,561,743✔
1007
                    SCLogDebug("%p/%" PRIu64 " skipping: TS inspect not done: ts:%02x", tx, i,
80,413✔
1008
                            txd->flags);
80,413✔
1009
                    tx_skipped = true;
80,413✔
1010
                }
80,413✔
1011
            }
1,561,743✔
1012
            if (!IS_DISRUPTED(tc_disrupt_flags) &&
1,655,383✔
1013
                    (f->sgh_toclient != NULL || (f->flags & FLOW_SGH_TOCLIENT) == 0)) {
1,655,383✔
1014
                if ((txd->flags & (APP_LAYER_TX_INSPECTED_TC | APP_LAYER_TX_SKIP_INSPECT_TC)) ==
1,572,683✔
1015
                        0) {
1,572,683✔
1016
                    SCLogDebug("%p/%" PRIu64 " skipping: TC inspect not done: ts:%02x", tx, i,
1,453,598✔
1017
                            txd->flags);
1,453,598✔
1018
                    tx_skipped = true;
1,453,598✔
1019
                }
1,453,598✔
1020
            }
1,572,683✔
1021
        }
1,655,383✔
1022

1023
        if (tx_skipped) {
1,655,383✔
1024
            SCLogDebug("%p/%" PRIu64 " tx_skipped", tx, i);
1,464,858✔
1025
            skipped = true;
1,464,858✔
1026
            goto next;
1,464,858✔
1027
        }
1,464,858✔
1028

1029
        if (logger_expectation != 0) {
190,525✔
1030
            LoggerId tx_logged = GetTxLogged(txd);
173,180✔
1031
            if (tx_logged != logger_expectation) {
173,180✔
1032
                SCLogDebug("%p/%"PRIu64" skipping: logging not done: want:%"PRIx32", have:%"PRIx32,
4,189✔
1033
                        tx, i, logger_expectation, tx_logged);
4,189✔
1034
                skipped = true;
4,189✔
1035
                goto next;
4,189✔
1036
            }
4,189✔
1037
        }
173,180✔
1038

1039
        /* if file logging is enabled, we keep a tx active while some of the files aren't
1040
         * logged yet. */
1041
        SCLogDebug("files_opened %u files_logged %u files_stored %u", txd->files_opened,
186,336✔
1042
                txd->files_logged, txd->files_stored);
186,336✔
1043

1044
        if (txd->files_opened) {
186,336✔
1045
            if (g_file_logger_enabled && txd->files_opened != txd->files_logged) {
11,391✔
1046
                skipped = true;
142✔
1047
                goto next;
142✔
1048
            }
142✔
1049
            if (g_filedata_logger_enabled && txd->files_opened != txd->files_stored) {
11,249✔
1050
                skipped = true;
×
1051
                goto next;
×
1052
            }
×
1053
        }
11,249✔
1054

1055
        /* if we are here, the tx can be freed. */
1056
        p->StateTransactionFree(alstate, i);
186,194✔
1057
        SCLogDebug("%p/%"PRIu64" freed", tx, i);
186,194✔
1058

1059
        /* if we didn't skip any tx so far, up the minimum */
1060
        SCLogDebug("skipped? %s i %"PRIu64", new_min %"PRIu64, skipped ? "true" : "false", i, new_min);
186,194✔
1061
        if (!skipped)
186,194✔
1062
            new_min = i + 1;
88,298✔
1063
        SCLogDebug("final i %"PRIu64", new_min %"PRIu64, i, new_min);
186,194✔
1064

1065
next:
4,399,495✔
1066
        if (!ires.has_next) {
4,399,495✔
1067
            /* this was the last tx. See if we skipped any. If not
1068
             * we removed all and can update the minimum to the max
1069
             * id. */
1070
            SCLogDebug("no next: cur tx i %"PRIu64", total %"PRIu64, i, total_txs);
497,018✔
1071
            if (!skipped) {
497,018✔
1072
                new_min = total_txs;
55,273✔
1073
                SCLogDebug("no next: cur tx i %"PRIu64", total %"PRIu64": "
55,273✔
1074
                        "new_min updated to %"PRIu64, i, total_txs, new_min);
55,273✔
1075
            }
55,273✔
1076
            break;
497,018✔
1077
        }
497,018✔
1078
        i++;
3,902,477✔
1079
    }
3,902,477✔
1080

1081
    /* see if we need to bring all trackers up to date. */
1082
    SCLogDebug("update f->alparser->min_id? %"PRIu64" vs %"PRIu64, new_min, alparser->min_id);
733,427✔
1083
    if (new_min > alparser->min_id) {
733,427✔
1084
        const uint64_t next_id = new_min;
80,984✔
1085
        alparser->min_id = next_id;
80,984✔
1086
        alparser->inspect_id[0] = MAX(alparser->inspect_id[0], next_id);
80,984✔
1087
        alparser->inspect_id[1] = MAX(alparser->inspect_id[1], next_id);
80,984✔
1088
        alparser->log_id = MAX(alparser->log_id, next_id);
80,984✔
1089
        SCLogDebug("updated f->alparser->min_id %"PRIu64, alparser->min_id);
80,984✔
1090
    }
80,984✔
1091
    SCReturn;
733,427✔
1092
}
733,427✔
1093

1094
static inline int StateGetProgressCompletionStatus(const AppProto alproto, const uint8_t flags)
1095
{
3,921,210✔
1096
    if (flags & STREAM_TOSERVER) {
3,921,210✔
1097
        return alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_ts;
1,980,673✔
1098
    } else if (flags & STREAM_TOCLIENT) {
1,980,673✔
1099
        return alp_ctx.ctxs[alproto][FLOW_PROTO_DEFAULT].complete_tc;
1,940,537✔
1100
    } else {
1,940,537✔
1101
        DEBUG_VALIDATE_BUG_ON(1);
×
1102
        return 0;
×
1103
    }
×
1104
}
3,921,210✔
1105

1106
/**
1107
 *  \brief get the progress value for a tx/protocol
1108
 *
1109
 *  If the stream is disrupted, we return the 'completion' value.
1110
 */
1111
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto,
1112
                        void *alstate, uint8_t flags)
1113
{
20,654,244✔
1114
    SCEnter();
20,654,244✔
1115
    int r;
20,654,244✔
1116
    if (unlikely(IS_DISRUPTED(flags))) {
20,654,244✔
1117
        r = StateGetProgressCompletionStatus(alproto, flags);
389✔
1118
    } else {
20,653,855✔
1119
        uint8_t direction = flags & (STREAM_TOCLIENT | STREAM_TOSERVER);
20,653,855✔
1120
        r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetProgress(
20,653,855✔
1121
                alstate, direction);
20,653,855✔
1122
    }
20,653,855✔
1123
    SCReturnInt(r);
20,654,244✔
1124
}
20,654,244✔
1125

1126
uint64_t AppLayerParserGetTxCnt(const Flow *f, void *alstate)
1127
{
3,557,480✔
1128
    SCEnter();
3,557,480✔
1129
    uint64_t r = alp_ctx.ctxs[f->alproto][f->protomap].StateGetTxCnt(alstate);
3,557,480✔
1130
    SCReturnCT(r, "uint64_t");
3,557,480✔
1131
}
3,557,480✔
1132

1133
void *AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id)
1134
{
250,987✔
1135
    SCEnter();
250,987✔
1136
    void *r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].StateGetTx(alstate, tx_id);
250,987✔
1137
    SCReturnPtr(r, "void *");
250,987✔
1138
}
250,987✔
1139

1140
int AppLayerParserGetStateProgressCompletionStatus(AppProto alproto,
1141
                                                   uint8_t direction)
1142
{
3,920,821✔
1143
    SCEnter();
3,920,821✔
1144
    int r = StateGetProgressCompletionStatus(alproto, direction);
3,920,821✔
1145
    SCReturnInt(r);
3,920,821✔
1146
}
3,920,821✔
1147

1148
int AppLayerParserGetEventInfo(uint8_t ipproto, AppProto alproto, const char *event_name,
1149
        uint8_t *event_id, AppLayerEventType *event_type)
1150
{
89,370✔
1151
    SCEnter();
89,370✔
1152
    const int ipproto_map = FlowGetProtoMapping(ipproto);
89,370✔
1153
    int r = (alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfo == NULL)
89,370✔
1154
                    ? -1
89,370✔
1155
                    : alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfo(
89,370✔
1156
                              event_name, event_id, event_type);
88,420✔
1157
    SCReturnInt(r);
89,370✔
1158
}
89,370✔
1159

1160
int AppLayerParserGetEventInfoById(uint8_t ipproto, AppProto alproto, uint8_t event_id,
1161
        const char **event_name, AppLayerEventType *event_type)
1162
{
31,925✔
1163
    SCEnter();
31,925✔
1164
    const int ipproto_map = FlowGetProtoMapping(ipproto);
31,925✔
1165
    *event_name = (const char *)NULL;
31,925✔
1166
    int r = (alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfoById == NULL)
31,925✔
1167
                    ? -1
31,925✔
1168
                    : alp_ctx.ctxs[alproto][ipproto_map].StateGetEventInfoById(
31,925✔
1169
                              event_id, event_name, event_type);
31,925✔
1170
    SCReturnInt(r);
31,925✔
1171
}
31,925✔
1172

1173
uint8_t AppLayerParserGetFirstDataDir(uint8_t ipproto, AppProto alproto)
1174
{
27,422✔
1175
    SCEnter();
27,422✔
1176
    uint8_t r = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].first_data_dir;
27,422✔
1177
    SCReturnCT(r, "uint8_t");
27,422✔
1178
}
27,422✔
1179

1180
uint64_t AppLayerParserGetTransactionActive(const Flow *f,
1181
        AppLayerParserState *pstate, uint8_t direction)
1182
{
6,486✔
1183
    SCEnter();
6,486✔
1184

1185
    uint64_t active_id;
6,486✔
1186
    uint64_t log_id = pstate->log_id;
6,486✔
1187
    uint64_t inspect_id = pstate->inspect_id[(direction & STREAM_TOSERVER) ? 0 : 1];
6,486✔
1188
    if (alp_ctx.ctxs[f->alproto][f->protomap].logger) {
6,486✔
1189
        active_id = MIN(log_id, inspect_id);
6,300✔
1190
    } else {
6,300✔
1191
        active_id = inspect_id;
186✔
1192
    }
186✔
1193

1194
    SCReturnCT(active_id, "uint64_t");
6,486✔
1195
}
6,486✔
1196

1197
bool AppLayerParserSupportsFiles(uint8_t ipproto, AppProto alproto)
1198
{
770,633✔
1199
    // Custom case for only signature-only protocol so far
1200
    if (alproto == ALPROTO_HTTP) {
770,633✔
1201
        return AppLayerParserSupportsFiles(ipproto, ALPROTO_HTTP1) ||
13,974✔
1202
               AppLayerParserSupportsFiles(ipproto, ALPROTO_HTTP2);
13,974✔
1203
    }
13,974✔
1204
    return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxFiles != NULL;
756,659✔
1205
}
770,633✔
1206

1207
AppLayerTxData *AppLayerParserGetTxData(uint8_t ipproto, AppProto alproto, void *tx)
1208
{
17,799,287✔
1209
    SCEnter();
17,799,287✔
1210
    AppLayerTxData *d = alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetTxData(tx);
17,799,287✔
1211
    SCReturnPtr(d, "AppLayerTxData");
17,799,287✔
1212
}
17,799,287✔
1213

1214
AppLayerStateData *AppLayerParserGetStateData(uint8_t ipproto, AppProto alproto, void *state)
1215
{
43,850✔
1216
    SCEnter();
43,850✔
1217
    if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateData) {
43,850✔
1218
        AppLayerStateData *d =
43,850✔
1219
                alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateData(state);
43,850✔
1220
        SCReturnPtr(d, "AppLayerStateData");
43,850✔
1221
    }
43,850✔
1222
    SCReturnPtr(NULL, "AppLayerStateData");
43,850✔
1223
}
43,850✔
1224

1225
void AppLayerParserApplyTxConfig(uint8_t ipproto, AppProto alproto,
1226
        void *state, void *tx, enum ConfigAction mode, AppLayerTxConfig config)
1227
{
4✔
1228
    SCEnter();
4✔
1229
    const int ipproto_map = FlowGetProtoMapping(ipproto);
4✔
1230
    if (alp_ctx.ctxs[alproto][ipproto_map].ApplyTxConfig) {
4✔
1231
        alp_ctx.ctxs[alproto][ipproto_map].ApplyTxConfig(state, tx, mode, config);
4✔
1232
    }
4✔
1233
    SCReturn;
4✔
1234
}
4✔
1235

1236
/***** General *****/
1237

1238
static inline void SetEOFFlags(AppLayerParserState *pstate, const uint8_t flags)
1239
{
537,642✔
1240
    if ((flags & (STREAM_EOF|STREAM_TOSERVER)) == (STREAM_EOF|STREAM_TOSERVER)) {
537,642✔
1241
        SCLogDebug("setting APP_LAYER_PARSER_EOF_TS");
7,489✔
1242
        SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_EOF_TS);
7,489✔
1243
    } else if ((flags & (STREAM_EOF|STREAM_TOCLIENT)) == (STREAM_EOF|STREAM_TOCLIENT)) {
530,153✔
1244
        SCLogDebug("setting APP_LAYER_PARSER_EOF_TC");
7,212✔
1245
        SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_EOF_TC);
7,212✔
1246
    }
7,212✔
1247
}
537,642✔
1248

1249
/** \internal
1250
 *  \brief create/close stream frames
1251
 *  On first invocation of TCP parser in a direction, create a <alproto>.stream frame.
1252
 *  On STREAM_EOF, set the final length. */
1253
static void HandleStreamFrames(Flow *f, StreamSlice stream_slice, const uint8_t *input,
1254
        const uint32_t input_len, const uint8_t flags)
1255
{
537,631✔
1256
    const uint8_t direction = (flags & STREAM_TOSERVER) ? 0 : 1;
537,631✔
1257
    AppLayerParserState *pstate = f->alparser;
537,631✔
1258

1259
    /* setup the generic stream frame */
1260
    if (((direction == 0 && (pstate->flags & APP_LAYER_PARSER_SFRAME_TS) == 0) ||
537,631✔
1261
                (direction == 1 && (pstate->flags & APP_LAYER_PARSER_SFRAME_TC) == 0)) &&
537,631✔
1262
            input != NULL && f->proto == IPPROTO_TCP) {
537,631✔
1263
        Frame *frame = AppLayerFrameGetLastOpenByType(f, direction, FRAME_STREAM_TYPE);
42,734✔
1264
        if (frame == NULL) {
42,734✔
1265
            int64_t frame_len = -1;
42,734✔
1266
            if (flags & STREAM_EOF)
42,734✔
1267
                frame_len = input_len;
1,328✔
1268

1269
            frame = AppLayerFrameNewByAbsoluteOffset(
42,734✔
1270
                    f, &stream_slice, stream_slice.offset, frame_len, direction, FRAME_STREAM_TYPE);
42,734✔
1271
            if (frame) {
42,734✔
1272
                SCLogDebug("opened: frame %p id %" PRIi64, frame, frame->id);
20,114✔
1273
                frame->flags = FRAME_FLAG_ENDS_AT_EOF; // TODO logic is not yet implemented
20,114✔
1274
                DEBUG_VALIDATE_BUG_ON(
20,114✔
1275
                        frame->id != 1); // should always be the first frame that is created
20,114✔
1276
            }
20,114✔
1277
            if (direction == 0) {
42,734✔
1278
                pstate->flags |= APP_LAYER_PARSER_SFRAME_TS;
22,684✔
1279
            } else {
22,684✔
1280
                pstate->flags |= APP_LAYER_PARSER_SFRAME_TC;
20,050✔
1281
            }
20,050✔
1282
        }
42,734✔
1283
    } else if (flags & STREAM_EOF) {
494,897✔
1284
        Frame *frame = AppLayerFrameGetLastOpenByType(f, direction, FRAME_STREAM_TYPE);
13,373✔
1285
        SCLogDebug("EOF closing: frame %p", frame);
13,373✔
1286
        if (frame) {
13,373✔
1287
            /* calculate final frame length */
1288
            int64_t slice_o = (int64_t)stream_slice.offset - (int64_t)frame->offset;
7,369✔
1289
            int64_t frame_len = slice_o + (int64_t)input_len;
7,369✔
1290
            SCLogDebug("%s: EOF frame->offset %" PRIu64 " -> %" PRIi64 ": o %" PRIi64,
7,369✔
1291
                    AppProtoToString(f->alproto), frame->offset, frame_len, slice_o);
7,369✔
1292
            frame->len = frame_len;
7,369✔
1293
        }
7,369✔
1294
    }
13,373✔
1295
}
537,631✔
1296

1297
static void Setup(Flow *f, const uint8_t direction, const uint8_t *input, uint32_t input_len,
1298
        const uint8_t flags, StreamSlice *as)
1299
{
537,631✔
1300
    memset(as, 0, sizeof(*as));
537,631✔
1301
    as->input = input;
537,631✔
1302
    as->input_len = input_len;
537,631✔
1303
    as->flags = flags;
537,631✔
1304

1305
    if (f->proto == IPPROTO_TCP && f->protoctx != NULL) {
537,631✔
1306
        TcpSession *ssn = f->protoctx;
491,529✔
1307
        TcpStream *stream = (direction & STREAM_TOSERVER) ? &ssn->client : &ssn->server;
491,529✔
1308
        as->offset = STREAM_APP_PROGRESS(stream);
491,529✔
1309
    }
491,529✔
1310
}
537,631✔
1311

1312
/** \retval int -1 in case of unrecoverable error. App-layer tracking stops for this flow.
1313
 *  \retval int 0 ok: we did not update app_progress
1314
 *  \retval int 1 ok: we updated app_progress */
1315
int AppLayerParserParse(ThreadVars *tv, AppLayerParserThreadCtx *alp_tctx, Flow *f, AppProto alproto,
1316
                        uint8_t flags, const uint8_t *input, uint32_t input_len)
1317
{
549,606✔
1318
    SCEnter();
549,606✔
1319
#ifdef DEBUG_VALIDATION
1320
    BUG_ON(f->protomap != FlowGetProtoMapping(f->proto));
1321
#endif
1322
    AppLayerParserState *pstate = f->alparser;
549,606✔
1323
    AppLayerParserProtoCtx *p = &alp_ctx.ctxs[alproto][f->protomap];
549,606✔
1324
    StreamSlice stream_slice;
549,606✔
1325
    void *alstate = NULL;
549,606✔
1326
    uint64_t p_tx_cnt = 0;
549,606✔
1327
    uint32_t consumed = input_len;
549,606✔
1328
    const uint8_t direction = (flags & STREAM_TOSERVER) ? 0 : 1;
549,606✔
1329

1330
    /* we don't have the parser registered for this protocol */
1331
    if (p->StateAlloc == NULL) {
549,606✔
1332
        if (f->proto == IPPROTO_TCP) {
11,168✔
1333
            StreamTcpDisableAppLayer(f);
4✔
1334
        }
4✔
1335
        goto end;
11,168✔
1336
    }
11,168✔
1337

1338
    if (flags & STREAM_GAP) {
538,438✔
1339
        if (!(p->option_flags & APP_LAYER_PARSER_OPT_ACCEPT_GAPS)) {
9,193✔
1340
            SCLogDebug("app-layer parser does not accept gaps");
796✔
1341
            if (f->alstate != NULL && !FlowChangeProto(f)) {
796✔
1342
                SCAppLayerParserTriggerRawStreamInspection(f, direction);
789✔
1343
            }
789✔
1344
            AppLayerIncGapErrorCounter(tv, f);
796✔
1345
            goto error;
796✔
1346
        }
796✔
1347
    }
9,193✔
1348

1349
    /* Get the parser state (if any) */
1350
    if (pstate == NULL) {
537,642✔
1351
        f->alparser = pstate = AppLayerParserStateAlloc();
33,867✔
1352
        if (pstate == NULL) {
33,867✔
1353
            AppLayerIncAllocErrorCounter(tv, f);
×
1354
            goto error;
×
1355
        }
×
1356
    }
33,867✔
1357

1358
    SetEOFFlags(pstate, flags);
537,642✔
1359

1360
    alstate = f->alstate;
537,642✔
1361
    if (alstate == NULL || FlowChangeProto(f)) {
537,642✔
1362
        f->alstate = alstate = p->StateAlloc(alstate, f->alproto_orig);
33,867✔
1363
        if (alstate == NULL) {
33,867✔
1364
            AppLayerIncAllocErrorCounter(tv, f);
×
1365
            goto error;
×
1366
        }
×
1367
        SCLogDebug("alloced new app layer state %p (name %s)",
33,867✔
1368
                   alstate, AppLayerGetProtoName(f->alproto));
33,867✔
1369

1370
        /* set flow flags to state */
1371
        if (f->file_flags != 0) {
33,867✔
1372
            AppLayerStateData *sd = AppLayerParserGetStateData(f->proto, f->alproto, f->alstate);
24,274✔
1373
            if (sd != NULL) {
24,274✔
1374
                if ((sd->file_flags & f->file_flags) != f->file_flags) {
24,274✔
1375
                    SCLogDebug("state data: updating file_flags %04x with flow file_flags %04x",
24,274✔
1376
                            sd->file_flags, f->file_flags);
24,274✔
1377
                    sd->file_flags |= f->file_flags;
24,274✔
1378
                }
24,274✔
1379
            }
24,274✔
1380
        }
24,274✔
1381
    } else {
503,775✔
1382
        SCLogDebug("using existing app layer state %p (name %s))",
503,775✔
1383
                   alstate, AppLayerGetProtoName(f->alproto));
503,775✔
1384
    }
503,775✔
1385

1386
    p_tx_cnt = AppLayerParserGetTxCnt(f, f->alstate);
537,642✔
1387

1388
    /* invoke the recursive parser, but only on data. We may get empty msgs on EOF */
1389
    if (input_len > 0 || (flags & STREAM_EOF)) {
537,642✔
1390
        Setup(f, flags & (STREAM_TOSERVER | STREAM_TOCLIENT), input, input_len, flags,
537,631✔
1391
                &stream_slice);
537,631✔
1392
        HandleStreamFrames(f, stream_slice, input, input_len, flags);
537,631✔
1393

1394
#ifdef QA_SIMULATION
1395
        if (((stream_slice.flags & STREAM_TOSERVER) &&
1396
                    stream_slice.offset >= g_eps_applayer_error_offset_ts)) {
1397
            SCLogNotice("putting parser %s into an error state from toserver offset %" PRIu64,
1398
                    AppProtoToString(alproto), g_eps_applayer_error_offset_ts);
1399
            AppLayerIncParserErrorCounter(tv, f);
1400
            goto error;
1401
        }
1402
        if (((stream_slice.flags & STREAM_TOCLIENT) &&
1403
                    stream_slice.offset >= g_eps_applayer_error_offset_tc)) {
1404
            SCLogNotice("putting parser %s into an error state from toclient offset %" PRIu64,
1405
                    AppProtoToString(alproto), g_eps_applayer_error_offset_tc);
1406
            AppLayerIncParserErrorCounter(tv, f);
1407
            goto error;
1408
        }
1409
#endif
1410
        /* invoke the parser */
1411
        AppLayerResult res = p->Parser[direction](f, alstate, pstate, stream_slice,
537,631✔
1412
                alp_tctx->alproto_local_storage[alproto][f->protomap]);
537,631✔
1413
        if (res.status < 0) {
537,631✔
1414
            AppLayerIncParserErrorCounter(tv, f);
4,185✔
1415
            goto error;
4,185✔
1416
        } else if (res.status > 0) {
533,446✔
1417
            DEBUG_VALIDATE_BUG_ON(res.consumed > input_len);
8,983✔
1418
            DEBUG_VALIDATE_BUG_ON(res.needed + res.consumed < input_len);
8,983✔
1419
            DEBUG_VALIDATE_BUG_ON(res.needed == 0);
8,983✔
1420
            /* incomplete is only supported for TCP */
1421
            DEBUG_VALIDATE_BUG_ON(f->proto != IPPROTO_TCP);
8,983✔
1422

1423
            /* put protocol in error state on improper use of the
1424
             * return codes. */
1425
            if (res.consumed > input_len || res.needed + res.consumed < input_len) {
8,983✔
1426
                AppLayerIncInternalErrorCounter(tv, f);
×
1427
                goto error;
×
1428
            }
×
1429

1430
            if (f->proto == IPPROTO_TCP && f->protoctx != NULL) {
8,983✔
1431
                TcpSession *ssn = f->protoctx;
8,983✔
1432
                SCLogDebug("direction %d/%s", direction,
8,983✔
1433
                        (flags & STREAM_TOSERVER) ? "toserver" : "toclient");
8,983✔
1434
                if (direction == 0) {
8,983✔
1435
                    /* parser told us how much data it needs on top of what it
1436
                     * consumed. So we need tell stream engine how much we need
1437
                     * before the next call */
1438
                    ssn->client.data_required = res.needed;
3,714✔
1439
                    SCLogDebug("setting data_required %u", ssn->client.data_required);
3,714✔
1440
                } else {
5,269✔
1441
                    /* parser told us how much data it needs on top of what it
1442
                     * consumed. So we need tell stream engine how much we need
1443
                     * before the next call */
1444
                    ssn->server.data_required = res.needed;
5,269✔
1445
                    SCLogDebug("setting data_required %u", ssn->server.data_required);
5,269✔
1446
                }
5,269✔
1447
            }
8,983✔
1448
            consumed = res.consumed;
8,983✔
1449
        }
8,983✔
1450
    }
537,631✔
1451

1452
    /* set the packets to no inspection and reassembly if required */
1453
    if (pstate->flags & APP_LAYER_PARSER_NO_INSPECTION) {
533,457✔
1454
        AppLayerParserSetEOF(pstate);
634✔
1455

1456
        if (f->proto == IPPROTO_TCP) {
634✔
1457
            StreamTcpDisableAppLayer(f);
33✔
1458

1459
            /* Set the no reassembly flag for both the stream in this TcpSession */
1460
            if (pstate->flags & APP_LAYER_PARSER_NO_REASSEMBLY) {
33✔
1461
                /* Used only if it's TCP */
1462
                TcpSession *ssn = f->protoctx;
×
1463
                if (ssn != NULL) {
×
1464
                    StreamTcpSetSessionNoReassemblyFlag(ssn, 0);
×
1465
                    StreamTcpSetSessionNoReassemblyFlag(ssn, 1);
×
1466
                }
×
1467
            }
×
1468
            /* Set the bypass flag for both the stream in this TcpSession */
1469
            if (pstate->flags & APP_LAYER_PARSER_BYPASS_READY) {
33✔
1470
                /* Used only if it's TCP */
1471
                TcpSession *ssn = f->protoctx;
×
1472
                if (ssn != NULL) {
×
1473
                    StreamTcpSetSessionBypassFlag(ssn);
×
1474
                }
×
1475
            }
×
1476
        } else {
601✔
1477
            // for TCP, this is set after flushing
1478
            FlowSetNoPayloadInspectionFlag(f);
601✔
1479
        }
601✔
1480
    }
634✔
1481

1482
    /* In cases like HeartBleed for TLS we need to inspect AppLayer but not Payload */
1483
    if (!(f->flags & FLOW_NOPAYLOAD_INSPECTION) && pstate->flags & APP_LAYER_PARSER_NO_INSPECTION_PAYLOAD) {
533,457✔
1484
        FlowSetNoPayloadInspectionFlag(f);
1,494✔
1485
        /* Set the no reassembly flag for both the stream in this TcpSession */
1486
        if (f->proto == IPPROTO_TCP) {
1,494✔
1487
            /* Used only if it's TCP */
1488
            TcpSession *ssn = f->protoctx;
1,494✔
1489
            if (ssn != NULL) {
1,494✔
1490
                StreamTcpSetDisableRawReassemblyFlag(ssn, 0);
1,494✔
1491
                StreamTcpSetDisableRawReassemblyFlag(ssn, 1);
1,494✔
1492
            }
1,494✔
1493
        }
1,494✔
1494
    }
1,494✔
1495

1496
    /* get the diff in tx cnt for stats keeping */
1497
    uint64_t cur_tx_cnt = AppLayerParserGetTxCnt(f, f->alstate);
533,457✔
1498
    if (cur_tx_cnt > p_tx_cnt && tv) {
533,457✔
1499
        AppLayerIncTxCounter(tv, f, cur_tx_cnt - p_tx_cnt);
187,258✔
1500
    }
187,258✔
1501

1502
 end:
544,625✔
1503
    /* update app progress */
1504
    if (consumed != input_len && f->proto == IPPROTO_TCP && f->protoctx != NULL) {
544,625✔
1505
        TcpSession *ssn = f->protoctx;
8,973✔
1506
        StreamTcpUpdateAppLayerProgress(ssn, direction, consumed);
8,973✔
1507
        SCReturnInt(1);
8,973✔
1508
    }
8,973✔
1509

1510
    SCReturnInt(0);
544,625✔
1511
 error:
4,981✔
1512
    /* Set the no app layer inspection flag for both
1513
     * the stream in this Flow */
1514
    if (f->proto == IPPROTO_TCP) {
4,981✔
1515
        StreamTcpDisableAppLayer(f);
2,424✔
1516
    }
2,424✔
1517
    AppLayerParserSetEOF(pstate);
4,981✔
1518
    SCReturnInt(-1);
4,981✔
1519
}
544,625✔
1520

1521
void AppLayerParserSetEOF(AppLayerParserState *pstate)
1522
{
5,615✔
1523
    SCEnter();
5,615✔
1524

1525
    if (pstate == NULL)
5,615✔
1526
        goto end;
7✔
1527

1528
    SCLogDebug("setting APP_LAYER_PARSER_EOF_TC and APP_LAYER_PARSER_EOF_TS");
5,608✔
1529
    SCAppLayerParserStateSetFlag(pstate, (APP_LAYER_PARSER_EOF_TS | APP_LAYER_PARSER_EOF_TC));
5,608✔
1530

1531
 end:
5,615✔
1532
    SCReturn;
5,615✔
1533
}
5,608✔
1534

1535
/* return true if there are app parser decoder events. These are
1536
 * only the ones that are set during protocol detection. */
1537
bool AppLayerParserHasDecoderEvents(AppLayerParserState *pstate)
1538
{
2,246,736✔
1539
    SCEnter();
2,246,736✔
1540

1541
    if (pstate == NULL)
2,246,736✔
1542
        return false;
288,275✔
1543

1544
    const AppLayerDecoderEvents *decoder_events = AppLayerParserGetDecoderEvents(pstate);
1,958,461✔
1545
    if (decoder_events && decoder_events->cnt)
1,958,461✔
1546
        return true;
×
1547

1548
    /* if we have reached here, we don't have events */
1549
    return false;
1,958,461✔
1550
}
1,958,461✔
1551

1552
/** \brief simple way to globally test if a alproto is registered
1553
 *         and fully enabled in the configuration.
1554
 */
1555
int AppLayerParserIsEnabled(AppProto alproto)
1556
{
228✔
1557
    for (int i = 0; i < FLOW_PROTO_APPLAYER_MAX; i++) {
281✔
1558
        if (alp_ctx.ctxs[alproto][i].StateGetProgress != NULL) {
281✔
1559
            return 1;
228✔
1560
        }
228✔
1561
    }
281✔
1562
    return 0;
×
1563
}
228✔
1564

1565
int AppLayerParserProtocolHasLogger(uint8_t ipproto, AppProto alproto)
1566
{
556✔
1567
    SCEnter();
556✔
1568
    int ipproto_map = FlowGetProtoMapping(ipproto);
556✔
1569
    int r = (!alp_ctx.ctxs[alproto][ipproto_map].logger) ? 0 : 1;
556✔
1570
    SCReturnInt(r);
556✔
1571
}
556✔
1572

1573
LoggerId AppLayerParserProtocolGetLoggerBits(uint8_t ipproto, AppProto alproto)
1574
{
1,508,729✔
1575
    SCEnter();
1,508,729✔
1576
    const int ipproto_map = FlowGetProtoMapping(ipproto);
1,508,729✔
1577
    LoggerId r = alp_ctx.ctxs[alproto][ipproto_map].logger_bits;
1,508,729✔
1578
    SCReturnUInt(r);
1,508,729✔
1579
}
1,508,729✔
1580

1581
void SCAppLayerParserTriggerRawStreamInspection(Flow *f, int direction)
1582
{
156,614✔
1583
    SCEnter();
156,614✔
1584

1585
    SCLogDebug("f %p tcp %p direction %d", f, f ? f->protoctx : NULL, direction);
156,614✔
1586
    if (f != NULL && f->protoctx != NULL)
156,614✔
1587
        StreamTcpReassembleTriggerRawInspection(f->protoctx, direction);
152,766✔
1588

1589
    SCReturn;
156,614✔
1590
}
156,614✔
1591

1592
void SCAppLayerParserSetStreamDepth(uint8_t ipproto, AppProto alproto, uint32_t stream_depth)
1593
{
44✔
1594
    SCEnter();
44✔
1595

1596
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].stream_depth = stream_depth;
44✔
1597
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].internal_flags |=
44✔
1598
            APP_LAYER_PARSER_INT_STREAM_DEPTH_SET;
44✔
1599

1600
    SCReturn;
44✔
1601
}
44✔
1602

1603
uint32_t AppLayerParserGetStreamDepth(const Flow *f)
1604
{
41,671✔
1605
    SCReturnInt(alp_ctx.ctxs[f->alproto][f->protomap].stream_depth);
41,671✔
1606
}
41,671✔
1607

1608
void AppLayerParserSetStreamDepthFlag(uint8_t ipproto, AppProto alproto, void *state, uint64_t tx_id, uint8_t flags)
1609
{
711✔
1610
    SCEnter();
711✔
1611
    void *tx = NULL;
711✔
1612
    if (state != NULL) {
711✔
1613
        if ((tx = AppLayerParserGetTx(ipproto, alproto, state, tx_id)) != NULL) {
711✔
1614
            if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].SetStreamDepthFlag != NULL) {
711✔
1615
                alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].SetStreamDepthFlag(tx, flags);
153✔
1616
            }
153✔
1617
        }
711✔
1618
    }
711✔
1619
    SCReturn;
711✔
1620
}
711✔
1621

1622
/**
1623
 *  \param id progress value id to get the name for
1624
 *  \param direction STREAM_TOSERVER/STREAM_TOCLIENT
1625
 */
1626
int AppLayerParserGetStateIdByName(
1627
        uint8_t ipproto, AppProto alproto, const char *name, const uint8_t direction)
1628
{
471✔
1629
    if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateIdByName != NULL) {
471✔
1630
        return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateIdByName(
379✔
1631
                name, direction);
379✔
1632
    } else {
379✔
1633
        return -1;
92✔
1634
    }
92✔
1635
}
471✔
1636

1637
/**
1638
 *  \param id progress value id to get the name for
1639
 *  \param direction STREAM_TOSERVER/STREAM_TOCLIENT
1640
 */
1641
const char *AppLayerParserGetStateNameById(
1642
        uint8_t ipproto, AppProto alproto, const int id, const uint8_t direction)
1643
{
68,407✔
1644
    if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateNameById != NULL) {
68,407✔
1645
        return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetStateNameById(id, direction);
6,693✔
1646
    } else {
61,714✔
1647
        return NULL;
61,714✔
1648
    }
61,714✔
1649
}
68,407✔
1650

1651
int AppLayerParserGetFrameIdByName(uint8_t ipproto, AppProto alproto, const char *name)
1652
{
42,722✔
1653
    if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameIdByName != NULL) {
42,722✔
1654
        return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameIdByName(name);
42,100✔
1655
    } else {
42,100✔
1656
        return -1;
622✔
1657
    }
622✔
1658
}
42,722✔
1659

1660
const char *AppLayerParserGetFrameNameById(uint8_t ipproto, AppProto alproto, const uint8_t id)
1661
{
1,747✔
1662
    if (alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameNameById != NULL) {
1,747✔
1663
        return alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].GetFrameNameById(id);
1,747✔
1664
    } else {
1,747✔
1665
        return NULL;
×
1666
    }
×
1667
}
1,747✔
1668

1669
/***** Cleanup *****/
1670

1671
void AppLayerParserStateProtoCleanup(
1672
        uint8_t protomap, AppProto alproto, void *alstate, AppLayerParserState *pstate)
1673
{
76,409✔
1674
    SCEnter();
76,409✔
1675

1676
    AppLayerParserProtoCtx *ctx = &alp_ctx.ctxs[alproto][protomap];
76,409✔
1677

1678
    if (ctx->StateFree != NULL && alstate != NULL)
76,409✔
1679
        ctx->StateFree(alstate);
33,867✔
1680

1681
    /* free the app layer parser api state */
1682
    if (pstate != NULL)
76,409✔
1683
        AppLayerParserStateFree(pstate);
33,867✔
1684

1685
    SCReturn;
76,409✔
1686
}
76,409✔
1687

1688
void AppLayerParserStateCleanup(const Flow *f, void *alstate, AppLayerParserState *pstate)
1689
{
75,381✔
1690
    AppLayerParserStateProtoCleanup(f->protomap, f->alproto, alstate, pstate);
75,381✔
1691
}
75,381✔
1692

1693
static void ValidateParserProtoDump(AppProto alproto, uint8_t ipproto)
1694
{
×
1695
    uint8_t map = FlowGetProtoMapping(ipproto);
×
1696
    const AppLayerParserProtoCtx *ctx = &alp_ctx.ctxs[alproto][map];
×
1697
    printf("ERROR: incomplete app-layer registration\n");
×
1698
    printf("AppLayer protocol %s ipproto %u\n", AppProtoToString(alproto), ipproto);
×
1699
    printf("- option flags %"PRIx32"\n", ctx->option_flags);
×
1700
    printf("- first_data_dir %"PRIx8"\n", ctx->first_data_dir);
×
1701
    printf("Mandatory:\n");
×
1702
    printf("- Parser[0] %p Parser[1] %p\n", ctx->Parser[0], ctx->Parser[1]);
×
1703
    printf("- StateAlloc %p StateFree %p\n", ctx->StateAlloc, ctx->StateFree);
×
1704
    printf("- StateGetTx %p StateGetTxCnt %p StateTransactionFree %p\n",
×
1705
            ctx->StateGetTx, ctx->StateGetTxCnt, ctx->StateTransactionFree);
×
1706
    printf("- GetTxData %p\n", ctx->GetTxData);
×
1707
    printf("- GetStateData %p\n", ctx->GetStateData);
×
1708
    printf("- StateGetProgress %p\n", ctx->StateGetProgress);
×
1709
    printf("Optional:\n");
×
1710
    printf("- LocalStorageAlloc %p LocalStorageFree %p\n", ctx->LocalStorageAlloc, ctx->LocalStorageFree);
×
1711
    printf("- StateGetEventInfo %p StateGetEventInfoById %p\n", ctx->StateGetEventInfo,
×
1712
            ctx->StateGetEventInfoById);
×
1713
}
×
1714

1715
#define BOTH_SET(a, b) ((a) != NULL && (b) != NULL)
2,786✔
1716
#define BOTH_SET_OR_BOTH_UNSET(a, b) (((a) == NULL && (b) == NULL) || ((a) != NULL && (b) != NULL))
1,393✔
1717
#define THREE_SET(a, b, c) ((a) != NULL && (b) != NULL && (c) != NULL)
1,393✔
1718

1719
static void ValidateParserProto(AppProto alproto, uint8_t ipproto)
1720
{
2,960✔
1721
    uint8_t map = FlowGetProtoMapping(ipproto);
2,960✔
1722
    const AppLayerParserProtoCtx *ctx = &alp_ctx.ctxs[alproto][map];
2,960✔
1723

1724
    if (ctx->Parser[0] == NULL && ctx->Parser[1] == NULL)
2,960✔
1725
        return;
1,567✔
1726

1727
    if (!(BOTH_SET(ctx->Parser[0], ctx->Parser[1]))) {
1,393✔
1728
        goto bad;
×
1729
    }
×
1730
    if (!(BOTH_SET(ctx->StateFree, ctx->StateAlloc))) {
1,393✔
1731
        goto bad;
×
1732
    }
×
1733
    if (!(THREE_SET(ctx->StateGetTx, ctx->StateGetTxCnt, ctx->StateTransactionFree))) {
1,393✔
1734
        goto bad;
×
1735
    }
×
1736
    if (ctx->StateGetProgress == NULL) {
1,393✔
1737
        goto bad;
×
1738
    }
×
1739
    /* local storage is optional, but needs both set if used */
1740
    if (!(BOTH_SET_OR_BOTH_UNSET(ctx->LocalStorageAlloc, ctx->LocalStorageFree))) {
1,393✔
1741
        goto bad;
×
1742
    }
×
1743
    if (ctx->GetTxData == NULL) {
1,393✔
1744
        goto bad;
×
1745
    }
×
1746
    if (ctx->GetStateData == NULL) {
1,393✔
1747
        goto bad;
×
1748
    }
×
1749
    return;
1,393✔
1750
bad:
1,393✔
1751
    ValidateParserProtoDump(alproto, ipproto);
×
1752
    exit(EXIT_FAILURE);
×
1753
}
1,393✔
1754
#undef BOTH_SET
1755
#undef BOTH_SET_OR_BOTH_UNSET
1756
#undef THREE_SET
1757

1758
static void ValidateParser(AppProto alproto)
1759
{
1,480✔
1760
    ValidateParserProto(alproto, IPPROTO_TCP);
1,480✔
1761
    ValidateParserProto(alproto, IPPROTO_UDP);
1,480✔
1762
}
1,480✔
1763

1764
static void ValidateParsers(void)
1765
{
37✔
1766
    AppProto p = 0;
37✔
1767
    for (; p < g_alproto_max; p++) {
1,517✔
1768
        ValidateParser(p);
1,480✔
1769
    }
1,480✔
1770
}
37✔
1771

1772
#define ARRAY_CAP_STEP 16
74✔
1773
static void (**PreRegisteredCallbacks)(void) = NULL;
1774
static size_t preregistered_callbacks_nb = 0;
1775
static size_t preregistered_callbacks_cap = 0;
1776

1777
int SCAppLayerParserReallocCtx(AppProto alproto)
1778
{
37✔
1779
    if (alp_ctx.ctxs_len <= alproto && alproto < g_alproto_max) {
37✔
1780
        /* Realloc alp_ctx.ctxs, so that dynamic alproto can be treated as real/normal ones.
1781
         * In case we need to turn off dynamic alproto. */
1782
        void *tmp = SCRealloc(alp_ctx.ctxs, sizeof(AppLayerParserProtoCtx[FLOW_PROTO_MAX]) *
37✔
1783
                                                    (alp_ctx.ctxs_len + ARRAY_CAP_STEP));
37✔
1784
        if (unlikely(tmp == NULL)) {
37✔
1785
            FatalError("Unable to realloc alp_ctx.ctxs.");
×
1786
        }
×
1787
        alp_ctx.ctxs = tmp;
37✔
1788
        memset(&alp_ctx.ctxs[alp_ctx.ctxs_len], 0,
37✔
1789
                sizeof(AppLayerParserProtoCtx[FLOW_PROTO_MAX]) * ARRAY_CAP_STEP);
37✔
1790
        alp_ctx.ctxs_len += ARRAY_CAP_STEP;
37✔
1791
    }
37✔
1792
    return 0;
37✔
1793
}
37✔
1794

1795
int AppLayerParserPreRegister(void (*Register)(void))
1796
{
×
1797
    if (preregistered_callbacks_nb == preregistered_callbacks_cap) {
×
1798
        void *tmp = SCRealloc(PreRegisteredCallbacks,
×
1799
                sizeof(void *) * (preregistered_callbacks_cap + ARRAY_CAP_STEP));
×
1800
        if (tmp == NULL) {
×
1801
            return 1;
×
1802
        }
×
1803
        preregistered_callbacks_cap += ARRAY_CAP_STEP;
×
1804
        PreRegisteredCallbacks = tmp;
×
1805
    }
×
1806
    PreRegisteredCallbacks[preregistered_callbacks_nb] = Register;
×
1807
    preregistered_callbacks_nb++;
×
1808
    return 0;
×
1809
}
×
1810

1811
void AppLayerParserRegisterProtocolParsers(void)
1812
{
37✔
1813
    SCEnter();
37✔
1814

1815
    AppLayerConfig();
37✔
1816

1817
    RegisterHTPParsers();
37✔
1818
    RegisterSSLParsers();
37✔
1819
    SCRegisterDcerpcParser();
37✔
1820
    SCRegisterDcerpcUdpParser();
37✔
1821
    RegisterSMBParsers();
37✔
1822
    RegisterFTPParsers();
37✔
1823
    RegisterSSHParsers();
37✔
1824
    RegisterSMTPParsers();
37✔
1825
    SCRegisterDnsUdpParser();
37✔
1826
    SCRegisterDnsTcpParser();
37✔
1827
    SCRegisterBittorrentDhtUdpParser();
37✔
1828
    RegisterModbusParsers();
37✔
1829
    SCEnipRegisterParsers();
37✔
1830
    RegisterDNP3Parsers();
37✔
1831
    RegisterNFSTCPParsers();
37✔
1832
    RegisterNFSUDPParsers();
37✔
1833
    SCRegisterNtpParser();
37✔
1834
    RegisterTFTPParsers();
37✔
1835
    RegisterIKEParsers();
37✔
1836
    SCRegisterKrb5Parser();
37✔
1837
    SCRegisterDhcpParser();
37✔
1838
    SCRegisterSnmpParser();
37✔
1839
    SCRegisterSipParser();
37✔
1840
    SCRegisterQuicParser();
37✔
1841
    SCRegisterWebSocketParser();
37✔
1842
    SCRegisterLdapTcpParser();
37✔
1843
    SCRegisterLdapUdpParser();
37✔
1844
    SCRegisterMdnsParser();
37✔
1845
    SCRegisterTemplateParser();
37✔
1846
    SCRfbRegisterParser();
37✔
1847
    SCMqttRegisterParser();
37✔
1848
    SCRegisterPgsqlParser();
37✔
1849
    SCRegisterPop3Parser();
37✔
1850
    SCRegisterRdpParser();
37✔
1851
    RegisterHTTP2Parsers();
37✔
1852
    SCRegisterTelnetParser();
37✔
1853
    RegisterIMAPParsers();
37✔
1854

1855
    for (size_t i = 0; i < preregistered_callbacks_nb; i++) {
37✔
1856
        PreRegisteredCallbacks[i]();
×
1857
    }
×
1858

1859
    ValidateParsers();
37✔
1860
}
37✔
1861

1862
/* coccinelle: SCAppLayerParserStateSetFlag():2,2:APP_LAYER_PARSER_ */
1863
void SCAppLayerParserStateSetFlag(AppLayerParserState *pstate, uint16_t flag)
1864
{
52,541✔
1865
    SCEnter();
52,541✔
1866
    pstate->flags |= flag;
52,541✔
1867
    SCReturn;
52,541✔
1868
}
52,541✔
1869

1870
/* coccinelle: SCAppLayerParserStateIssetFlag():2,2:APP_LAYER_PARSER_ */
1871
uint16_t SCAppLayerParserStateIssetFlag(AppLayerParserState *pstate, uint16_t flag)
1872
{
3,128,408✔
1873
    SCEnter();
3,128,408✔
1874
    SCReturnUInt(pstate->flags & flag);
3,128,408✔
1875
}
3,128,408✔
1876

1877
/***** Unittests *****/
1878

1879
#ifdef UNITTESTS
1880
#include "util-unittest-helper.h"
1881

1882
void AppLayerParserRegisterProtocolUnittests(uint8_t ipproto, AppProto alproto,
1883
                                  void (*RegisterUnittests)(void))
1884
{
1885
    SCEnter();
1886
    alp_ctx.ctxs[alproto][FlowGetProtoMapping(ipproto)].RegisterUnittests = RegisterUnittests;
1887
    SCReturn;
1888
}
1889

1890
void AppLayerParserRegisterUnittests(void)
1891
{
1892
    SCEnter();
1893

1894
    int ip;
1895
    AppProto alproto;
1896
    AppLayerParserProtoCtx *ctx;
1897

1898
    for (ip = 0; ip < FLOW_PROTO_DEFAULT; ip++) {
1899
        for (alproto = 0; alproto < g_alproto_max; alproto++) {
1900
            ctx = &alp_ctx.ctxs[alproto][ip];
1901
            if (ctx->RegisterUnittests == NULL)
1902
                continue;
1903
            ctx->RegisterUnittests();
1904
        }
1905
    }
1906

1907
    SCReturn;
1908
}
1909

1910
#endif
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc