/src/suricata8/rust/src/detect/transforms/dotprefix.rs
Line | Count | Source |
1 | | /* Copyright (C) 2024 Open Information Security Foundation |
2 | | * |
3 | | * You can copy, redistribute or modify this Program under the terms of |
4 | | * the GNU General Public License version 2 as published by the Free |
5 | | * Software Foundation. |
6 | | * |
7 | | * This program is distributed in the hope that it will be useful, |
8 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
9 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
10 | | * GNU General Public License for more details. |
11 | | * |
12 | | * You should have received a copy of the GNU General Public License |
13 | | * version 2 along with this program; if not, write to the Free Software |
14 | | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA |
15 | | * 02110-1301, USA. |
16 | | */ |
17 | | |
18 | | use crate::detect::SIGMATCH_NOOPT; |
19 | | use suricata_sys::sys::{ |
20 | | DetectEngineCtx, DetectEngineThreadCtx, InspectionBuffer, SCDetectHelperTransformRegister, |
21 | | SCDetectSignatureAddTransform, SCInspectionBufferCheckAndExpand, SCInspectionBufferInPlace, |
22 | | SCInspectionBufferTruncate, SCTransformTableElmt, Signature, |
23 | | }; |
24 | | |
25 | | use std::os::raw::{c_int, c_void}; |
26 | | use std::ptr; |
27 | | |
28 | | static mut G_TRANSFORM_DOT_PREFIX_ID: c_int = 0; |
29 | | |
30 | 783 | unsafe extern "C" fn dot_prefix_setup( |
31 | 783 | _de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char, |
32 | 783 | ) -> c_int { |
33 | 783 | return SCDetectSignatureAddTransform(s, G_TRANSFORM_DOT_PREFIX_ID, ptr::null_mut()); |
34 | 783 | } |
35 | | |
36 | 0 | fn dot_prefix_transform_do(input: &[u8], output: &mut [u8]) { |
37 | 0 | if std::ptr::eq(output.as_ptr(), input.as_ptr()) { |
38 | 0 | output.copy_within(0..input.len(), 1); |
39 | 0 | } else { |
40 | 0 | output[1..].copy_from_slice(input); |
41 | 0 | } |
42 | 0 | output[0] = b'.'; |
43 | 0 | } |
44 | | |
45 | 0 | unsafe extern "C" fn dot_prefix_transform( |
46 | 0 | _det: *mut DetectEngineThreadCtx, buffer: *mut InspectionBuffer, _ctx: *mut c_void, |
47 | 0 | ) { |
48 | 0 | let input_len = (*buffer).inspect_len; |
49 | 0 | if input_len == 0 { |
50 | 0 | return; |
51 | 0 | } |
52 | 0 | let inplace = SCInspectionBufferInPlace(buffer); |
53 | | |
54 | 0 | let output = SCInspectionBufferCheckAndExpand(buffer, input_len + 1); |
55 | 0 | if output.is_null() { |
56 | | // allocation failure |
57 | 0 | return; |
58 | 0 | } |
59 | 0 | let input = if inplace { |
60 | 0 | // may have been reallocated |
61 | 0 | (*buffer).buf |
62 | 0 | } else { |
63 | 0 | (*buffer).inspect |
64 | | }; |
65 | 0 | let input = build_slice!(input, input_len as usize); |
66 | 0 | let output = std::slice::from_raw_parts_mut(output, (input_len + 1) as usize); |
67 | | |
68 | 0 | dot_prefix_transform_do(input, output); |
69 | | |
70 | 0 | SCInspectionBufferTruncate(buffer, input_len + 1); |
71 | 0 | } |
72 | | |
73 | | #[no_mangle] |
74 | 39 | pub unsafe extern "C" fn DetectTransformDotPrefixRegister() { |
75 | 39 | let kw = SCTransformTableElmt { |
76 | 39 | name: b"dotprefix\0".as_ptr() as *const libc::c_char, |
77 | 39 | desc: b"modify buffer to extract the dotprefix\0".as_ptr() as *const libc::c_char, |
78 | 39 | url: b"/rules/transforms.html#dotprefix\0".as_ptr() as *const libc::c_char, |
79 | 39 | Setup: Some(dot_prefix_setup), |
80 | 39 | flags: SIGMATCH_NOOPT, |
81 | 39 | Transform: Some(dot_prefix_transform), |
82 | 39 | Free: None, |
83 | 39 | TransformValidate: None, |
84 | 39 | TransformId: None, |
85 | 39 | }; |
86 | | unsafe { |
87 | 39 | G_TRANSFORM_DOT_PREFIX_ID = SCDetectHelperTransformRegister(&kw); |
88 | 39 | if G_TRANSFORM_DOT_PREFIX_ID < 0 { |
89 | 0 | SCLogWarning!("Failed registering transform dot_prefix"); |
90 | 39 | } |
91 | | } |
92 | 39 | } |
93 | | |
94 | | #[cfg(test)] |
95 | | mod tests { |
96 | | use super::*; |
97 | | |
98 | | #[test] |
99 | | fn test_dot_prefix_transform() { |
100 | | let buf = b"example.com"; |
101 | | let mut out = vec![0; b"example.com".len() + 1]; |
102 | | dot_prefix_transform_do(buf, &mut out); |
103 | | assert_eq!(out, b".example.com"); |
104 | | let mut buf = Vec::with_capacity(b"hello.example.com".len() + 1); |
105 | | buf.extend_from_slice(b"hello.example.com"); |
106 | | let mut out = vec![0; b"hello.example.com".len() + 1]; |
107 | | dot_prefix_transform_do(&buf, &mut out); |
108 | | assert_eq!(out, b".hello.example.com"); |
109 | | // test in place |
110 | | let still_buf = unsafe { std::slice::from_raw_parts(buf.as_ptr(), buf.len()) }; |
111 | | buf.push(b'.'); |
112 | | dot_prefix_transform_do(still_buf, &mut buf); |
113 | | assert_eq!(&buf, b".hello.example.com"); |
114 | | } |
115 | | } |