• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

OISF / suricata / 22801236550

07 Mar 2026 02:55PM UTC coverage: 76.656% (-2.6%) from 79.291%
22801236550

Pull #14983

github

web-flow
Merge 04a32b920 into 6ec9e5c95
Pull Request #14983: transform/subslice: Add subslice transform

610 of 681 new or added lines in 2 files covered. (89.57%)

12689 existing lines in 284 files now uncovered.

245462 of 320212 relevant lines covered (76.66%)

3038231.79 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

96.25
/src/app-layer-frames.c
1
/* Copyright (C) 2007-2024 Open Information Security Foundation
2
 *
3
 * You can copy, redistribute or modify this Program under the terms of
4
 * the GNU General Public License version 2 as published by the Free
5
 * Software Foundation.
6
 *
7
 * This program is distributed in the hope that it will be useful,
8
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
10
 * GNU General Public License for more details.
11
 *
12
 * You should have received a copy of the GNU General Public License
13
 * version 2 along with this program; if not, write to the Free Software
14
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15
 * 02110-1301, USA.
16
 */
17

18
/**
19
 * \file
20
 *
21
 * \author Victor Julien <victor@inliniac.net>
22
 *
23
 */
24

25
#include "suricata-common.h"
26
#include "util-print.h"
27

28
#include "flow.h"
29
#include "stream-tcp.h"
30
#include "rust.h"
31
#include "app-layer-frames.h"
32
#include "app-layer-parser.h"
33

34
struct FrameConfig {
35
    SC_ATOMIC_DECLARE(uint64_t, types);
36
};
37
/* This array should be allocated to contain g_alproto_max protocols. */
38
static struct FrameConfig *frame_config;
39

40
void FrameConfigInit(void)
41
{
44✔
42
    frame_config = SCCalloc(g_alproto_max, sizeof(struct FrameConfig));
44✔
43
    if (unlikely(frame_config == NULL)) {
44✔
44
        FatalError("Unable to alloc frame_config.");
×
45
    }
×
46
    for (AppProto p = 0; p < g_alproto_max; p++) {
1,804✔
47
        SC_ATOMIC_INIT(frame_config[p].types);
1,760✔
48
    }
1,760✔
49
}
44✔
50

51
void FrameConfigDeInit(void)
52
{
30✔
53
    SCFree(frame_config);
30✔
54
}
30✔
55

56
void FrameConfigEnableAll(void)
UNCOV
57
{
×
UNCOV
58
    const uint64_t bits = UINT64_MAX;
×
UNCOV
59
    for (AppProto p = 0; p < g_alproto_max; p++) {
×
UNCOV
60
        struct FrameConfig *fc = &frame_config[p];
×
UNCOV
61
        SC_ATOMIC_OR(fc->types, bits);
×
UNCOV
62
    }
×
UNCOV
63
}
×
64

65
void FrameConfigEnable(const AppProto p, const uint8_t type)
66
{
36,492✔
67
    const uint64_t bits = BIT_U64(type);
36,492✔
68
    struct FrameConfig *fc = &frame_config[p];
36,492✔
69
    SC_ATOMIC_OR(fc->types, bits);
36,492✔
70
}
36,492✔
71

72
static inline bool FrameConfigTypeIsEnabled(const AppProto p, const uint8_t type)
73
{
3,016,098✔
74
    struct FrameConfig *fc = &frame_config[p];
3,016,098✔
75
    const uint64_t bits = BIT_U64(type);
3,016,098✔
76
    const bool enabled = (SC_ATOMIC_GET(fc->types) & bits) != 0;
3,016,098✔
77
    return enabled;
3,016,098✔
78
}
3,016,098✔
79

80
#ifdef DEBUG
81
static void FrameDebug(const char *prefix, const Frames *frames, const Frame *frame)
82
{
83
    const char *type_name = "unknown";
84
    if (frame->type == FRAME_STREAM_TYPE) {
85
        type_name = "stream";
86
    } else if (frames != NULL) {
87
        type_name = AppLayerParserGetFrameNameById(frames->ipproto, frames->alproto, frame->type);
88
    }
89
    SCLogDebug("[%s] %p: frame:%p type:%u/%s id:%" PRIi64 " flags:%02x offset:%" PRIu64
90
               ", len:%" PRIi64 ", inspect_progress:%" PRIu64 ", events:%u %u/%u/%u/%u",
91
            prefix, frames, frame, frame->type, type_name, frame->id, frame->flags, frame->offset,
92
            frame->len, frame->inspect_progress, frame->event_cnt, frame->events[0],
93
            frame->events[1], frame->events[2], frame->events[3]);
94
}
95
#else
96
#define FrameDebug(prefix, frames, frame)
97
#endif
98

99
/**
100
 * \note "open" means a frame that has no length set (len == -1)
101
 * \todo perhaps we can search backwards */
102
Frame *FrameGetLastOpenByType(Frames *frames, const uint8_t frame_type)
103
{
311,250✔
104
    Frame *candidate = NULL;
311,250✔
105

106
    SCLogDebug(
311,250✔
107
            "frames %p cnt %u, looking for last of type %" PRIu8, frames, frames->cnt, frame_type);
311,250✔
108
    for (uint16_t i = 0; i < frames->cnt; i++) {
1,551,951✔
109
        if (i < FRAMES_STATIC_CNT) {
1,240,701✔
110
            Frame *frame = &frames->sframes[i];
606,092✔
111
            FrameDebug("get_by_id(static)", frames, frame);
606,092✔
112
            if (frame->type == frame_type && frame->len == -1)
606,092✔
113
                candidate = frame;
8,140✔
114
        } else {
634,609✔
115
            const uint16_t o = i - FRAMES_STATIC_CNT;
634,609✔
116
            Frame *frame = &frames->dframes[o];
634,609✔
117
            FrameDebug("get_by_id(dynamic)", frames, frame);
634,609✔
118
            if (frame->type == frame_type && frame->len == -1)
634,609✔
119
                candidate = frame;
15✔
120
        }
634,609✔
121
    }
1,240,701✔
122
    return candidate;
311,250✔
123
}
311,250✔
124

125
Frame *FrameGetById(Frames *frames, const int64_t id)
126
{
148,830✔
127
    SCLogDebug("frames %p cnt %u, looking for %" PRIi64, frames, frames->cnt, id);
148,830✔
128
    for (uint16_t i = 0; i < frames->cnt; i++) {
1,971,020✔
129
        if (i < FRAMES_STATIC_CNT) {
1,970,910✔
130
            Frame *frame = &frames->sframes[i];
367,218✔
131
            FrameDebug("get_by_id(static)", frames, frame);
367,218✔
132
            if (frame->id == id)
367,218✔
133
                return frame;
67,983✔
134
        } else {
1,603,692✔
135
            const uint16_t o = i - FRAMES_STATIC_CNT;
1,603,692✔
136
            Frame *frame = &frames->dframes[o];
1,603,692✔
137
            FrameDebug("get_by_id(dynamic)", frames, frame);
1,603,692✔
138
            if (frame->id == id)
1,603,692✔
139
                return frame;
80,737✔
140
        }
1,603,692✔
141
    }
1,970,910✔
142
    return NULL;
110✔
143
}
148,830✔
144

145
Frame *FrameGetByIndex(Frames *frames, const uint32_t idx)
146
{
11,153,054✔
147
    if (idx >= frames->cnt)
11,153,054✔
148
        return NULL;
×
149

150
    if (idx < FRAMES_STATIC_CNT) {
11,153,054✔
151
        Frame *frame = &frames->sframes[idx];
795,653✔
152
        FrameDebug("get_by_idx(s)", frames, frame);
795,653✔
153
        return frame;
795,653✔
154
    } else {
10,357,401✔
155
        const uint32_t o = idx - FRAMES_STATIC_CNT;
10,357,401✔
156
        Frame *frame = &frames->dframes[o];
10,357,401✔
157
        FrameDebug("get_by_idx(d)", frames, frame);
10,357,401✔
158
        return frame;
10,357,401✔
159
    }
10,357,401✔
160
}
11,153,054✔
161

162
static Frame *FrameNew(Frames *frames, uint64_t offset, int64_t len)
163
{
1,242,318✔
164
    DEBUG_VALIDATE_BUG_ON(frames == NULL);
1,242,318✔
165

166
    if (frames->cnt < FRAMES_STATIC_CNT) {
1,242,318✔
167
        Frame *frame = &frames->sframes[frames->cnt];
720,969✔
168
        frames->sframes[frames->cnt].offset = offset;
720,969✔
169
        frames->sframes[frames->cnt].len = len;
720,969✔
170
        frames->sframes[frames->cnt].id = ++frames->base_id;
720,969✔
171
        frames->cnt++;
720,969✔
172
        return frame;
720,969✔
173
    } else if (frames->dframes == NULL) {
720,969✔
174
        DEBUG_VALIDATE_BUG_ON(frames->dyn_size != 0);
8,819✔
175
        DEBUG_VALIDATE_BUG_ON(frames->cnt != FRAMES_STATIC_CNT);
8,819✔
176

177
        frames->dframes = SCCalloc(8, sizeof(Frame));
8,819✔
178
        if (frames->dframes == NULL) {
8,819✔
179
            return NULL;
×
180
        }
×
181
        frames->cnt++;
8,819✔
182
        DEBUG_VALIDATE_BUG_ON(frames->cnt != FRAMES_STATIC_CNT + 1);
8,819✔
183

184
        frames->dyn_size = 8;
8,819✔
185
        frames->dframes[0].offset = offset;
8,819✔
186
        frames->dframes[0].len = len;
8,819✔
187
        frames->dframes[0].id = ++frames->base_id;
8,819✔
188
        return &frames->dframes[0];
8,819✔
189
    } else {
512,530✔
190
        DEBUG_VALIDATE_BUG_ON(frames->cnt < FRAMES_STATIC_CNT);
512,530✔
191

192
        /* need to handle dynamic storage of frames now */
193
        const uint16_t dyn_cnt = frames->cnt - FRAMES_STATIC_CNT;
512,530✔
194
        if (dyn_cnt < frames->dyn_size) {
512,530✔
195
            DEBUG_VALIDATE_BUG_ON(frames->dframes == NULL);
402,966✔
196

197
            // fall through
198
        } else {
402,966✔
199
            if (frames->dyn_size == 256) {
109,564✔
200
                SCLogDebug("limit reached! 256 dynamic frames already");
102,097✔
201
                // limit reached
202
                // TODO figure out if this should lead to an event of sorts
203
                return NULL;
102,097✔
204
            }
102,097✔
205

206
            /* realloc time */
207
            uint16_t new_dyn_size = frames->dyn_size * 2;
7,467✔
208
            uint32_t new_alloc_size = new_dyn_size * sizeof(Frame);
7,467✔
209

210
            void *ptr = SCRealloc(frames->dframes, new_alloc_size);
7,467✔
211
            if (ptr == NULL) {
7,467✔
212
                return NULL;
×
213
            }
×
214

215
            memset((uint8_t *)ptr + (frames->dyn_size * sizeof(Frame)), 0x00,
7,467✔
216
                    (frames->dyn_size * sizeof(Frame)));
7,467✔
217
            frames->dframes = ptr;
7,467✔
218
            frames->dyn_size = new_dyn_size;
7,467✔
219
        }
7,467✔
220

221
        frames->cnt++;
410,433✔
222
        frames->dframes[dyn_cnt].offset = offset;
410,433✔
223
        frames->dframes[dyn_cnt].len = len;
410,433✔
224
        frames->dframes[dyn_cnt].id = ++frames->base_id;
410,433✔
225
        return &frames->dframes[dyn_cnt];
410,433✔
226
    }
512,530✔
227
}
1,242,318✔
228

229
static void FrameClean(Frame *frame)
230
{
1,158,272✔
231
    memset(frame, 0, sizeof(*frame));
1,158,272✔
232
}
1,158,272✔
233

234
static void FrameCopy(Frame *dst, Frame *src)
235
{
13,970,209✔
236
    memcpy(dst, src, sizeof(*dst));
13,970,209✔
237
}
13,970,209✔
238

239
#ifdef DEBUG
240
static void AppLayerFrameDumpForFrames(const char *prefix, const Frames *frames)
241
{
242
    SCLogDebug("prefix: %s", prefix);
243
    for (uint16_t i = 0; i < frames->cnt; i++) {
244
        if (i < FRAMES_STATIC_CNT) {
245
            const Frame *frame = &frames->sframes[i];
246
            FrameDebug(prefix, frames, frame);
247
        } else {
248
            const uint16_t o = i - FRAMES_STATIC_CNT;
249
            const Frame *frame = &frames->dframes[o];
250
            FrameDebug(prefix, frames, frame);
251
        }
252
    }
253
    SCLogDebug("prefix: %s", prefix);
254
}
255
#endif
256

257
static inline uint64_t FrameLeftEdge(const TcpStream *stream, const Frame *frame)
258
{
14,400,890✔
259
    const int64_t app_progress = STREAM_APP_PROGRESS(stream);
14,400,890✔
260

261
    const int64_t frame_offset = frame->offset;
14,400,890✔
262
    const int64_t frame_data = app_progress - frame_offset;
14,400,890✔
263

264
    SCLogDebug("frame_offset %" PRIi64 ", frame_data %" PRIi64 ", frame->len %" PRIi64,
14,400,890✔
265
            frame_offset, frame_data, frame->len);
14,400,890✔
266
    DEBUG_VALIDATE_BUG_ON(frame_offset > app_progress);
14,400,890✔
267

268
    /* length unknown, make sure to have at least 2500 */
269
    if (frame->len < 0) {
14,400,890✔
270
        if (frame_data <= 2500) {
203,317✔
271
            SCLogDebug("got <= 2500 bytes (%" PRIu64 "), returning offset %" PRIu64, frame_data,
125,921✔
272
                    frame_offset);
125,921✔
273
            return frame_offset;
125,921✔
274
        } else {
125,921✔
275
            SCLogDebug("got > 2500 bytes (%" PRIu64 "), returning offset %" PRIu64, frame_data,
77,396✔
276
                    (frame_offset + (frame_data - 2500)));
77,396✔
277
            return frame_offset + (frame_data - 2500);
77,396✔
278
        }
77,396✔
279

280
        /* length specified */
281
    } else {
14,197,573✔
282
        /* have all data for the frame, we can skip it */
283
        if (frame->len <= frame_data) {
14,197,573✔
284
            uint64_t x = frame_offset + frame_data;
14,172,429✔
285
            SCLogDebug("x %" PRIu64, x);
14,172,429✔
286
            return x;
14,172,429✔
287
            /*
288

289
                [ stream      <frame_data> ]
290
                             [ frame        .......]
291

292
             */
293
        } else if (frame_data < 2500) {
14,172,429✔
294
            uint64_t x = frame_offset;
13,996✔
295
            SCLogDebug("x %" PRIu64, x);
13,996✔
296
            return x;
13,996✔
297
        } else {
13,996✔
298
            uint64_t x = frame_offset + (frame_data - 2500);
11,148✔
299
            SCLogDebug("x %" PRIu64, x);
11,148✔
300
            return x;
11,148✔
301
        }
11,148✔
302
    }
14,197,573✔
303
}
14,400,890✔
304

305
/** Stream buffer slides forward, we need to update and age out
306
 *  frame offsets/frames. Aging out means we move existing frames
307
 *  into the slots we'd free up.
308
 *
309
 *  Start:
310
 *
311
 *  [ stream ]
312
 *    [ frame   ...........]
313
 *      offset: 2
314
 *      len: 19
315
 *
316
 *  Slide:
317
 *         [ stream ]
318
 *    [ frame ....          .]
319
 *      offset: 2
320
 *       len: 19
321
 *
322
 *  Slide:
323
 *                [ stream ]
324
 *    [ frame ...........    ]
325
 *      offset: 2
326
 *      len: 19
327
 */
328
static int FrameSlide(const char *ds, Frames *frames, const TcpStream *stream, const uint32_t slide)
329
{
15,585✔
330
    SCLogDebug("start: left edge %" PRIu64 ", left_edge_rel %u, stream base %" PRIu64
15,585✔
331
               ", next %" PRIu64,
15,585✔
332
            (uint64_t)frames->left_edge_rel + STREAM_BASE_OFFSET(stream), frames->left_edge_rel,
15,585✔
333
            STREAM_BASE_OFFSET(stream), STREAM_BASE_OFFSET(stream) + slide);
15,585✔
334
    DEBUG_VALIDATE_BUG_ON(frames == NULL);
15,585✔
335
    SCLogDebug("%s frames %p: sliding %u bytes", ds, frames, slide);
15,585✔
336
    uint64_t le = STREAM_APP_PROGRESS(stream);
15,585✔
337
    const uint64_t next_base = STREAM_BASE_OFFSET(stream) + slide;
15,585✔
338
#if defined(DEBUG) || defined(DEBUG_VALIDATION)
339
    const uint16_t start = frames->cnt;
340
    uint16_t removed = 0;
341
#endif
342
    uint16_t x = 0;
15,585✔
343
    for (uint16_t i = 0; i < frames->cnt; i++) {
452,444✔
344
        if (i < FRAMES_STATIC_CNT) {
436,859✔
345
            Frame *frame = &frames->sframes[i];
11,239✔
346
            FrameDebug("slide(s)", frames, frame);
11,239✔
347
            if (frame->len >= 0 && frame->offset + frame->len <= next_base) {
11,239✔
348
                // remove by not incrementing 'x'
349
                SCLogDebug("removing %p id %" PRIi64, frame, frame->id);
186✔
350
                FrameClean(frame);
186✔
351
#if defined(DEBUG) || defined(DEBUG_VALIDATION)
352
                removed++;
353
#endif
354
            } else {
11,053✔
355
                Frame *nframe = &frames->sframes[x];
11,053✔
356
                FrameCopy(nframe, frame);
11,053✔
357
                if (frame != nframe) {
11,053✔
358
                    FrameClean(frame);
10✔
359
                }
10✔
360
                le = MIN(le, FrameLeftEdge(stream, nframe));
11,053✔
361
                x++;
11,053✔
362
            }
11,053✔
363
        } else {
425,620✔
364
            const uint16_t o = i - FRAMES_STATIC_CNT;
425,620✔
365
            Frame *frame = &frames->dframes[o];
425,620✔
366
            FrameDebug("slide(d)", frames, frame);
425,620✔
367
            if (frame->len >= 0 && frame->offset + frame->len <= next_base) {
425,620✔
368
                // remove by not incrementing 'x'
369
                SCLogDebug("removing %p id %" PRIi64, frame, frame->id);
5,804✔
370
                FrameClean(frame);
5,804✔
371
#if defined(DEBUG) || defined(DEBUG_VALIDATION)
372
                removed++;
373
#endif
374
            } else {
419,816✔
375
                Frame *nframe;
419,816✔
376
                if (x >= FRAMES_STATIC_CNT) {
419,816✔
377
                    nframe = &frames->dframes[x - FRAMES_STATIC_CNT];
419,658✔
378
                } else {
419,658✔
379
                    nframe = &frames->sframes[x];
158✔
380
                }
158✔
381
                FrameCopy(nframe, frame);
419,816✔
382
                if (frame != nframe) {
419,816✔
383
                    FrameClean(frame);
6,105✔
384
                }
6,105✔
385
                le = MIN(le, FrameLeftEdge(stream, nframe));
419,816✔
386
                x++;
419,816✔
387
            }
419,816✔
388
        }
425,620✔
389
    }
436,859✔
390
    frames->cnt = x;
15,585✔
391
    uint64_t o = STREAM_BASE_OFFSET(stream) + slide;
15,585✔
392
    DEBUG_VALIDATE_BUG_ON(o > le);
15,585✔
393
    DEBUG_VALIDATE_BUG_ON(le - o > UINT32_MAX);
15,585✔
394
    frames->left_edge_rel = (uint32_t)(le - o);
15,585✔
395

396
#ifdef DEBUG
397
    SCLogDebug("end: left edge %" PRIu64 ", left_edge_rel %u, stream base %" PRIu64
398
               " (+slide), cnt %u, removed %u, start %u",
399
            (uint64_t)frames->left_edge_rel + STREAM_BASE_OFFSET(stream) + slide,
400
            frames->left_edge_rel, STREAM_BASE_OFFSET(stream) + slide, frames->cnt, removed, start);
401
    char pf[32] = "";
402
    snprintf(pf, sizeof(pf), "%s:post_slide", ds);
403
    AppLayerFrameDumpForFrames(pf, frames);
404
#endif
405
    DEBUG_VALIDATE_BUG_ON(x != start - removed);
15,585✔
406
    return 0;
15,585✔
407
}
15,585✔
408

409
void AppLayerFramesSlide(Flow *f, const uint32_t slide, const uint8_t direction)
410
{
35,057✔
411
    FramesContainer *frames_container = AppLayerFramesGetContainer(f);
35,057✔
412
    if (frames_container == NULL)
35,057✔
413
        return;
19,467✔
414
    Frames *frames;
15,590✔
415
    TcpSession *ssn = f->protoctx;
15,590✔
416
    TcpStream *stream;
15,590✔
417
    if (direction == STREAM_TOSERVER) {
15,590✔
418
        stream = &ssn->client;
6,988✔
419
        frames = &frames_container->toserver;
6,988✔
420
        FrameSlide("toserver", frames, stream, slide);
6,988✔
421
    } else {
8,602✔
422
        stream = &ssn->server;
8,602✔
423
        frames = &frames_container->toclient;
8,602✔
424
        FrameSlide("toclient", frames, stream, slide);
8,602✔
425
    }
8,602✔
426
}
15,590✔
427

428
static void FrameFreeSingleFrame(Frames *frames, Frame *r)
429
{
180,510✔
430
    FrameDebug("free", frames, r);
180,510✔
431
    FrameClean(r);
180,510✔
432
}
180,510✔
433

434
static void FramesClear(Frames *frames)
435
{
81,491✔
436
    DEBUG_VALIDATE_BUG_ON(frames == NULL);
81,491✔
437

438
    SCLogDebug("frames %u", frames->cnt);
81,491✔
439
    for (uint16_t i = 0; i < frames->cnt; i++) {
262,001✔
440
        if (i < FRAMES_STATIC_CNT) {
180,510✔
441
            Frame *r = &frames->sframes[i];
65,840✔
442
            SCLogDebug("removing frame %p", r);
65,840✔
443
            FrameFreeSingleFrame(frames, r);
65,840✔
444
        } else {
114,670✔
445
            const uint16_t o = i - FRAMES_STATIC_CNT;
114,670✔
446
            Frame *r = &frames->dframes[o];
114,670✔
447
            SCLogDebug("removing frame %p", r);
114,670✔
448
            FrameFreeSingleFrame(frames, r);
114,670✔
449
        }
114,670✔
450
    }
180,510✔
451
    frames->cnt = 0;
81,491✔
452
}
81,491✔
453

454
void FramesFree(Frames *frames)
455
{
55,206✔
456
    DEBUG_VALIDATE_BUG_ON(frames == NULL);
55,206✔
457
    FramesClear(frames);
55,206✔
458
    SCFree(frames->dframes);
55,206✔
459
    frames->dframes = NULL;
55,206✔
460
}
55,206✔
461

462
/** \brief create new frame using a pointer to start of the frame
463
 */
464
Frame *AppLayerFrameNewByPointer(Flow *f, const StreamSlice *stream_slice,
465
        const uint8_t *frame_start, const int64_t len, int dir, uint8_t frame_type)
466
{
165,974✔
467
    SCLogDebug("frame_start:%p stream_slice->input:%p stream_slice->offset:%" PRIu64, frame_start,
165,974✔
468
            stream_slice->input, stream_slice->offset);
165,974✔
469

470
    if (!(FrameConfigTypeIsEnabled(f->alproto, frame_type)))
165,974✔
471
        return NULL;
112,915✔
472

473
        /* workarounds for many (unit|fuzz)tests not handling TCP data properly */
474
#if defined(UNITTESTS) || defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
53,067✔
475
    if (f->proto == IPPROTO_TCP && f->protoctx == NULL)
53,067✔
476
        return NULL;
24✔
477
    if (frame_start < stream_slice->input ||
53,043✔
478
            frame_start > stream_slice->input + stream_slice->input_len)
53,043✔
479
        return NULL;
480
#endif
53,043✔
481
    DEBUG_VALIDATE_BUG_ON(frame_start < stream_slice->input);
2,147,536,690✔
482
    DEBUG_VALIDATE_BUG_ON(stream_slice->input == NULL);
2,147,536,690✔
483
    DEBUG_VALIDATE_BUG_ON(f->proto == IPPROTO_TCP && f->protoctx == NULL);
2,147,536,690✔
484

485
    ptrdiff_t ptr_offset = frame_start - stream_slice->input;
2,147,536,690✔
486
#ifdef DEBUG
487
    uint64_t offset = ptr_offset + stream_slice->offset;
488
    SCLogDebug("flow %p direction %s frame %p starting at %" PRIu64 " len %" PRIi64
489
               " (offset %" PRIu64 ")",
490
            f, dir == 0 ? "toserver" : "toclient", frame_start, offset, len, stream_slice->offset);
491
#endif
492
    DEBUG_VALIDATE_BUG_ON(f->alparser == NULL);
2,147,536,690✔
493

494
    FramesContainer *frames_container = AppLayerFramesSetupContainer(f);
2,147,536,690✔
495
    if (frames_container == NULL)
2,147,536,690✔
496
        return NULL;
×
497

498
    Frames *frames;
2,147,536,690✔
499
    if (dir == 0) {
2,147,536,690✔
500
        frames = &frames_container->toserver;
24,699✔
501
    } else {
2,147,511,991✔
502
        frames = &frames_container->toclient;
2,147,511,991✔
503
    }
2,147,511,991✔
504

505
    uint64_t abs_frame_offset = stream_slice->offset + ptr_offset;
2,147,536,690✔
506

507
    Frame *r = FrameNew(frames, abs_frame_offset, len);
2,147,536,690✔
508
    if (r != NULL) {
2,147,536,690✔
509
        r->type = frame_type;
52,037✔
510
        FrameDebug("new_by_ptr", frames, r);
52,037✔
511
    }
52,037✔
512
    return r;
2,147,536,690✔
513
}
2,147,536,690✔
514

515
static Frame *AppLayerFrameUdp(
516
        Flow *f, const uint32_t frame_start_rel, const int64_t len, int dir, uint8_t frame_type)
517
{
31,759✔
518
    DEBUG_VALIDATE_BUG_ON(f->proto != IPPROTO_UDP);
31,759✔
519

520
    if (!(FrameConfigTypeIsEnabled(f->alproto, frame_type)))
31,759✔
521
        return NULL;
×
522

523
    FramesContainer *frames_container = AppLayerFramesSetupContainer(f);
31,759✔
524
    if (frames_container == NULL)
31,759✔
525
        return NULL;
×
526

527
    Frames *frames;
31,759✔
528
    if (dir == 0) {
31,759✔
529
        frames = &frames_container->toserver;
25,290✔
530
    } else {
25,290✔
531
        frames = &frames_container->toclient;
6,469✔
532
    }
6,469✔
533

534
    Frame *r = FrameNew(frames, frame_start_rel, len);
31,759✔
535
    if (r != NULL) {
31,759✔
536
        r->type = frame_type;
31,759✔
537
    }
31,759✔
538
    return r;
31,759✔
539
}
31,759✔
540

541
/** \brief create new frame using a relative offset from the start of the stream slice
542
 */
543
Frame *SCAppLayerFrameNewByRelativeOffset(Flow *f, const void *ss, const uint32_t frame_start_rel,
544
        const int64_t len, int dir, uint8_t frame_type)
545
{
2,316,488✔
546
    // need to hide StreamSlice argument
547
    // as we cannot bindgen a C function with an argument whose type
548
    // is defined in rust (at least before a suricata_core crate)
549
    const StreamSlice *stream_slice = (const StreamSlice *)ss;
2,316,488✔
550
    if (!(FrameConfigTypeIsEnabled(f->alproto, frame_type)))
2,316,488✔
551
        return NULL;
1,170,265✔
552

553
        /* workarounds for many (unit|fuzz)tests not handling TCP data properly */
554
#if defined(UNITTESTS) || defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
1,146,225✔
555
    if (f->proto == IPPROTO_TCP && f->protoctx == NULL)
1,146,225✔
556
        return NULL;
557
    if (stream_slice->input == NULL)
1,146,225✔
558
        return NULL;
559
#else
560
    DEBUG_VALIDATE_BUG_ON(stream_slice->input == NULL);
2,147,483,647✔
561
#endif
2,147,483,647✔
562
    DEBUG_VALIDATE_BUG_ON(f->proto == IPPROTO_TCP && f->protoctx == NULL);
2,148,629,872✔
563
    DEBUG_VALIDATE_BUG_ON(f->alparser == NULL);
2,148,629,872✔
564

565
    if (f->proto == IPPROTO_UDP) {
2,148,629,872✔
566
        return AppLayerFrameUdp(f, frame_start_rel, len, dir, frame_type);
31,759✔
567
    }
31,759✔
568

569
    FramesContainer *frames_container = AppLayerFramesSetupContainer(f);
2,148,598,113✔
570
    if (frames_container == NULL)
2,148,598,113✔
571
        return NULL;
×
572

573
    Frames *frames;
2,148,598,113✔
574
    if (dir == 0) {
2,148,598,113✔
575
        frames = &frames_container->toserver;
554,815✔
576
    } else {
2,148,043,298✔
577
        frames = &frames_container->toclient;
2,148,043,298✔
578
    }
2,148,043,298✔
579

580
    const uint64_t frame_abs_offset = (uint64_t)frame_start_rel + stream_slice->offset;
2,148,598,113✔
581
#ifdef DEBUG_VALIDATION
582
    const TcpSession *ssn = f->protoctx;
583
    const TcpStream *stream = dir == 0 ? &ssn->client : &ssn->server;
584
    BUG_ON(stream_slice->offset != STREAM_APP_PROGRESS(stream));
585
    BUG_ON(frame_abs_offset > STREAM_APP_PROGRESS(stream) + stream_slice->input_len);
586
#endif
587
    Frame *r = FrameNew(frames, frame_abs_offset, len);
2,148,598,113✔
588
    if (r != NULL) {
2,148,598,113✔
589
        r->type = frame_type;
1,013,375✔
590
    }
1,013,375✔
591
    return r;
2,148,598,113✔
592
}
2,148,598,113✔
593

594
void AppLayerFrameDump(Flow *f)
595
{
540,531✔
596
#ifdef DEBUG
597
    if (f->proto == IPPROTO_TCP && f->protoctx && f->alparser) {
598
        FramesContainer *frames_container = AppLayerFramesGetContainer(f);
599
        if (frames_container != NULL) {
600
            AppLayerFrameDumpForFrames("toserver::dump", &frames_container->toserver);
601
            AppLayerFrameDumpForFrames("toclient::dump", &frames_container->toclient);
602
        }
603
    }
604
#endif
605
}
540,531✔
606

607
/** \brief create new frame using the absolute offset from the start of the stream
608
 */
609
Frame *AppLayerFrameNewByAbsoluteOffset(Flow *f, const StreamSlice *stream_slice,
610
        const uint64_t frame_start, const int64_t len, int dir, uint8_t frame_type)
611
{
76,343✔
612
    if (!(FrameConfigTypeIsEnabled(f->alproto, frame_type)))
76,343✔
613
        return NULL;
33,297✔
614

615
        /* workarounds for many (unit|fuzz)tests not handling TCP data properly */
616
#if defined(UNITTESTS) || defined(FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION)
43,051✔
617
    if (f->proto == IPPROTO_TCP && f->protoctx == NULL)
43,051✔
618
        return NULL;
619
    if (stream_slice->input == NULL)
43,051✔
620
        return NULL;
1✔
621
#else
622
    DEBUG_VALIDATE_BUG_ON(stream_slice->input == NULL);
2,147,483,647✔
623
#endif
2,147,483,647✔
624
    DEBUG_VALIDATE_BUG_ON(f->proto == IPPROTO_TCP && f->protoctx == NULL);
2,147,526,697✔
625
    DEBUG_VALIDATE_BUG_ON(f->alparser == NULL);
2,147,526,697✔
626
    DEBUG_VALIDATE_BUG_ON(frame_start < stream_slice->offset);
2,147,526,697✔
627
    DEBUG_VALIDATE_BUG_ON(frame_start - stream_slice->offset >= (uint64_t)INT_MAX);
2,147,526,697✔
628

629
    FramesContainer *frames_container = AppLayerFramesSetupContainer(f);
2,147,526,697✔
630
    if (frames_container == NULL)
2,147,526,697✔
631
        return NULL;
×
632

633
    Frames *frames;
2,147,526,697✔
634
    if (dir == 0) {
2,147,526,697✔
635
        frames = &frames_container->toserver;
22,851✔
636
    } else {
2,147,506,498✔
637
        frames = &frames_container->toclient;
2,147,503,846✔
638
    }
2,147,503,846✔
639

640
    SCLogDebug("flow %p direction %s frame type %u offset %" PRIu64 " len %" PRIi64
2,147,526,697✔
641
               " (slice offset %" PRIu64 ")",
2,147,526,697✔
642
            f, dir == 0 ? "toserver" : "toclient", frame_type, frame_start, len,
2,147,526,697✔
643
            stream_slice->offset);
2,147,526,697✔
644
    Frame *r = FrameNew(frames, frame_start, len);
2,147,526,697✔
645
    if (r != NULL) {
2,147,526,697✔
646
        r->type = frame_type;
43,050✔
647
    }
43,050✔
648
    return r;
2,147,526,697✔
649
}
2,147,526,697✔
650

651
void AppLayerFrameAddEvent(Frame *r, uint8_t e)
652
{
143✔
653
    if (r != NULL) {
143✔
654
        if (r->event_cnt < 4) { // TODO
143✔
655
            r->events[r->event_cnt++] = e;
143✔
656
        }
143✔
657
        FrameDebug("add_event", NULL, r);
143✔
658
    }
143✔
659
}
143✔
660

661
void SCAppLayerFrameAddEventById(const Flow *f, const int dir, const FrameId id, uint8_t e)
662
{
143✔
663
    Frame *frame = AppLayerFrameGetById(f, dir, id);
143✔
664
    AppLayerFrameAddEvent(frame, e);
143✔
665
}
143✔
666

667
void AppLayerFrameSetLength(Frame *frame, int64_t len)
668
{
43✔
669
    if (frame != NULL) {
43✔
670
        frame->len = len;
43✔
671
        FrameDebug("set_length", NULL, frame);
43✔
672
    }
43✔
673
}
43✔
674

675
void SCAppLayerFrameSetLengthById(const Flow *f, const int dir, const FrameId id, int64_t len)
676
{
43✔
677
    Frame *frame = AppLayerFrameGetById(f, dir, id);
43✔
678
    AppLayerFrameSetLength(frame, len);
43✔
679
}
43✔
680

681
void AppLayerFrameSetTxId(Frame *r, uint64_t tx_id)
682
{
162,263✔
683
    if (r != NULL) {
162,263✔
684
        r->flags |= FRAME_FLAG_TX_ID_SET;
162,263✔
685
        r->tx_id = tx_id;
162,263✔
686
        FrameDebug("set_txid", NULL, r);
162,263✔
687
    }
162,263✔
688
}
162,263✔
689

690
void SCAppLayerFrameSetTxIdById(const Flow *f, const int dir, const FrameId id, uint64_t tx_id)
691
{
126,659✔
692
    Frame *frame = AppLayerFrameGetById(f, dir, id);
126,659✔
693
    AppLayerFrameSetTxId(frame, tx_id);
126,659✔
694
}
126,659✔
695

696
Frame *AppLayerFrameGetById(const Flow *f, const int dir, const FrameId frame_id)
697
{
147,069✔
698
    FramesContainer *frames_container = AppLayerFramesGetContainer(f);
147,069✔
699
    SCLogDebug("get frame_id %" PRIi64 " direction %u/%s frames_container %p", frame_id, dir,
147,069✔
700
            dir == 0 ? "toserver" : "toclient", frames_container);
147,069✔
701
    if (frames_container == NULL)
147,069✔
702
        return NULL;
×
703

704
    Frames *frames;
147,069✔
705
    if (dir == 0) {
147,069✔
706
        frames = &frames_container->toserver;
87,185✔
707
    } else {
87,185✔
708
        frames = &frames_container->toclient;
59,884✔
709
    }
59,884✔
710
    SCLogDebug("frames %p", frames);
147,069✔
711
    return FrameGetById(frames, frame_id);
147,069✔
712
}
147,069✔
713

714
Frame *AppLayerFrameGetLastOpenByType(Flow *f, const int dir, const uint8_t frame_type)
715
{
425,562✔
716
    if (!(FrameConfigTypeIsEnabled(f->alproto, frame_type)))
425,562✔
717
        return NULL;
103,002✔
718

719
    FramesContainer *frames_container = AppLayerFramesGetContainer(f);
322,560✔
720
    SCLogDebug("get frame_type %" PRIu8 " direction %u/%s frames_container %p", frame_type, dir,
322,560✔
721
            dir == 0 ? "toserver" : "toclient", frames_container);
322,560✔
722
    if (frames_container == NULL)
322,560✔
723
        return NULL;
11,302✔
724

725
    Frames *frames;
311,258✔
726
    if (dir == 0) {
311,258✔
727
        frames = &frames_container->toserver;
291,768✔
728
    } else {
291,776✔
729
        frames = &frames_container->toclient;
19,490✔
730
    }
19,490✔
731
    SCLogDebug("frames %p", frames);
311,258✔
732
    return FrameGetLastOpenByType(frames, frame_type);
311,258✔
733
}
322,560✔
734

735
static inline bool FrameIsDone(const Frame *frame, const uint64_t abs_right_edge)
736
{
14,439,214✔
737
    /* frame with negative length means we don't know the size yet. */
738
    if (frame->len < 0)
14,439,214✔
739
        return false;
197,112✔
740

741
    const int64_t frame_abs_offset = frame->offset;
14,242,102✔
742
    const int64_t frame_right_edge = frame_abs_offset + frame->len;
14,242,102✔
743
    if ((uint64_t)frame_right_edge <= abs_right_edge) {
14,242,102✔
744
        SCLogDebug("frame %p id %" PRIi64 " is done", frame, frame->id);
899,874✔
745
        return true;
899,874✔
746
    }
899,874✔
747
    return false;
13,342,228✔
748
}
14,242,102✔
749

750
static void FramePrune(Frames *frames, const TcpStream *stream, const bool eof)
751
{
637,329✔
752
#ifdef DEBUG_VALIDATION
753
    const uint64_t frames_le_start = (uint64_t)frames->left_edge_rel + STREAM_BASE_OFFSET(stream);
754
#endif
755
    SCLogDebug("start: left edge %" PRIu64 ", left_edge_rel %u, stream base %" PRIu64,
637,329✔
756
            (uint64_t)frames->left_edge_rel + STREAM_BASE_OFFSET(stream), frames->left_edge_rel,
637,329✔
757
            STREAM_BASE_OFFSET(stream));
637,329✔
758
    const uint64_t acked = StreamTcpGetUsable(stream, eof);
637,329✔
759
    uint64_t le = STREAM_APP_PROGRESS(stream);
637,329✔
760

761
#if defined(DEBUG) || defined(DEBUG_VALIDATION)
762
    const uint16_t start = frames->cnt;
763
    uint16_t removed = 0;
764
#endif
765
    uint16_t x = 0;
637,329✔
766
    for (uint16_t i = 0; i < frames->cnt; i++) {
15,130,390✔
767
        if (i < FRAMES_STATIC_CNT) {
14,493,061✔
768
            Frame *frame = &frames->sframes[i];
1,133,195✔
769
            FrameDebug("prune(s)", frames, frame);
1,133,195✔
770
            if (eof || FrameIsDone(frame, acked)) {
1,133,195✔
771
                // remove by not incrementing 'x'
772
                SCLogDebug("removing %p id %" PRIi64, frame, frame->id);
661,980✔
773
                FrameDebug("remove(s)", frames, frame);
661,980✔
774
                FrameClean(frame);
661,980✔
775
#if defined(DEBUG) || defined(DEBUG_VALIDATION)
776
                removed++;
777
#endif
778
            } else {
661,980✔
779
                const uint64_t fle = FrameLeftEdge(stream, frame);
471,215✔
780
                le = MIN(le, fle);
471,215✔
781
                SCLogDebug("le %" PRIu64 ", frame fle %" PRIu64, le, fle);
471,215✔
782
                Frame *nframe = &frames->sframes[x];
471,215✔
783
                FrameCopy(nframe, frame);
471,215✔
784
                if (frame != nframe) {
471,215✔
785
                    FrameClean(frame);
3,167✔
786
                }
3,167✔
787
                x++;
471,215✔
788
            }
471,215✔
789
        } else {
13,359,866✔
790
            const uint16_t o = i - FRAMES_STATIC_CNT;
13,359,866✔
791
            Frame *frame = &frames->dframes[o];
13,359,866✔
792
            FrameDebug("prune(d)", frames, frame);
13,359,866✔
793
            if (eof || FrameIsDone(frame, acked)) {
13,359,866✔
794
                // remove by not incrementing 'x'
795
                SCLogDebug("removing %p id %" PRIi64, frame, frame->id);
291,741✔
796
                FrameDebug("remove(d)", frames, frame);
291,741✔
797
                FrameClean(frame);
291,741✔
798
#if defined(DEBUG) || defined(DEBUG_VALIDATION)
799
                removed++;
800
#endif
801
            } else {
13,068,125✔
802
                const uint64_t fle = FrameLeftEdge(stream, frame);
13,068,125✔
803
                le = MIN(le, fle);
13,068,125✔
804
                SCLogDebug("le %" PRIu64 ", frame fle %" PRIu64, le, fle);
13,068,125✔
805
                Frame *nframe;
13,068,125✔
806
                if (x >= FRAMES_STATIC_CNT) {
13,068,125✔
807
                    nframe = &frames->dframes[x - FRAMES_STATIC_CNT];
13,061,246✔
808
                } else {
13,061,246✔
809
                    nframe = &frames->sframes[x];
6,879✔
810
                }
6,879✔
811
                FrameCopy(nframe, frame);
13,068,125✔
812
                if (frame != nframe) {
13,068,125✔
813
                    FrameClean(frame);
8,769✔
814
                }
8,769✔
815
                x++;
13,068,125✔
816
            }
13,068,125✔
817
        }
13,359,866✔
818
    }
14,493,061✔
819
    frames->cnt = x;
637,329✔
820
    DEBUG_VALIDATE_BUG_ON(le < STREAM_BASE_OFFSET(stream));
637,329✔
821
    DEBUG_VALIDATE_BUG_ON(le - STREAM_BASE_OFFSET(stream) > UINT32_MAX);
637,329✔
822
    frames->left_edge_rel = (uint32_t)(le - STREAM_BASE_OFFSET(stream));
637,329✔
823
#ifdef DEBUG
824
    SCLogDebug("end: left edge %" PRIu64 ", left_edge_rel %u, stream base %" PRIu64
825
               ", cnt %u, removed %u, start %u",
826
            (uint64_t)frames->left_edge_rel + STREAM_BASE_OFFSET(stream), frames->left_edge_rel,
827
            STREAM_BASE_OFFSET(stream), frames->cnt, removed, start);
828
    AppLayerFrameDumpForFrames("post_slide", frames);
829
#endif
830
    if (frames->cnt > 0) { // if we removed all this can fail
637,329✔
831
        DEBUG_VALIDATE_BUG_ON(frames_le_start > le);
226,396✔
832
    }
226,396✔
833
    DEBUG_VALIDATE_BUG_ON(x != start - removed);
637,329✔
834
}
637,329✔
835

836
void FramesPrune(Flow *f, Packet *p)
837
{
854,545✔
838
    if (f->proto == IPPROTO_TCP && f->protoctx == NULL)
854,545✔
839
        return;
×
840
    FramesContainer *frames_container = AppLayerFramesGetContainer(f);
854,545✔
841
    if (frames_container == NULL)
854,545✔
842
        return;
189,069✔
843

844
    Frames *frames;
665,476✔
845

846
    if (p->proto == IPPROTO_UDP) {
665,476✔
847
        SCLogDebug("clearing all UDP frames");
26,285✔
848
        if (PKT_IS_TOSERVER(p)) {
26,285✔
849
            frames = &frames_container->toserver;
20,956✔
850
        } else {
20,956✔
851
            frames = &frames_container->toclient;
5,329✔
852
        }
5,329✔
853
        FramesClear(frames);
26,285✔
854
        return;
26,285✔
855
    }
26,285✔
856

857
    TcpSession *ssn = f->protoctx;
639,191✔
858

859
    if (ssn->flags & STREAMTCP_FLAG_APP_LAYER_DISABLED) {
639,191✔
860
        AppLayerFramesFreeContainer(f);
1,854✔
861
        return;
1,854✔
862
    }
1,854✔
863

864
    TcpStream *stream;
637,337✔
865
    if (PKT_IS_TOSERVER(p)) {
637,337✔
866
        stream = &ssn->client;
321,345✔
867
        frames = &frames_container->toserver;
321,345✔
868
    } else {
321,353✔
869
        stream = &ssn->server;
315,992✔
870
        frames = &frames_container->toclient;
315,992✔
871
    }
315,992✔
872

873
    const bool eof = ssn->state == TCP_CLOSED || PKT_IS_PSEUDOPKT(p);
637,337✔
874
    SCLogDebug("eof %s", eof ? "TRUE" : "false");
637,337✔
875
    FramePrune(frames, stream, eof);
637,337✔
876
}
637,337✔
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc