/src/suricata/src/stream-tcp.h
Line | Count | Source |
1 | | /* Copyright (C) 2007-2025 Open Information Security Foundation |
2 | | * |
3 | | * You can copy, redistribute or modify this Program under the terms of |
4 | | * the GNU General Public License version 2 as published by the Free |
5 | | * Software Foundation. |
6 | | * |
7 | | * This program is distributed in the hope that it will be useful, |
8 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
9 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
10 | | * GNU General Public License for more details. |
11 | | * |
12 | | * You should have received a copy of the GNU General Public License |
13 | | * version 2 along with this program; if not, write to the Free Software |
14 | | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA |
15 | | * 02110-1301, USA. |
16 | | */ |
17 | | |
18 | | /** |
19 | | * \file |
20 | | * |
21 | | * \author Victor Julien <victor@inliniac.net> |
22 | | * \author Gurvinder Singh <gurvindersinghdahiya@gmail.com> |
23 | | */ |
24 | | |
25 | | #ifndef SURICATA_STREAM_TCP_H |
26 | | #define SURICATA_STREAM_TCP_H |
27 | | |
28 | | #include "stream-tcp-private.h" |
29 | | |
30 | | #include "stream.h" |
31 | | #include "stream-tcp-reassemble.h" |
32 | | #include "suricata.h" |
33 | | #include "util-exception-policy-types.h" |
34 | | |
35 | 78 | #define STREAM_VERBOSE false |
36 | | /* Flag to indicate that the checksum validation for the stream engine |
37 | | has been enabled */ |
38 | 9.66M | #define STREAMTCP_INIT_FLAG_CHECKSUM_VALIDATION BIT_U8(0) |
39 | 78 | #define STREAMTCP_INIT_FLAG_DROP_INVALID BIT_U8(1) |
40 | 156k | #define STREAMTCP_INIT_FLAG_BYPASS BIT_U8(2) |
41 | 31.3M | #define STREAMTCP_INIT_FLAG_INLINE BIT_U8(3) |
42 | | /** flag to drop packets with URG flag set */ |
43 | | #define STREAMTCP_INIT_FLAG_DROP_URG BIT_U8(4) |
44 | | |
45 | | enum TcpStreamUrgentHandling { |
46 | | TCP_STREAM_URGENT_INLINE, /**< treat as inline data */ |
47 | 78 | #define TCP_STREAM_URGENT_DEFAULT TCP_STREAM_URGENT_INLINE |
48 | | TCP_STREAM_URGENT_DROP, /**< drop TCP packet with URG flag */ |
49 | | TCP_STREAM_URGENT_OOB, /**< treat 1 byte of URG data as OOB */ |
50 | | TCP_STREAM_URGENT_GAP, /**< treat 1 byte of URG data as GAP */ |
51 | | }; |
52 | | |
53 | | /*global flow data*/ |
54 | | typedef struct TcpStreamCnf_ { |
55 | | /** stream tracking |
56 | | * |
57 | | * max stream mem usage |
58 | | */ |
59 | | SC_ATOMIC_DECLARE(uint64_t, memcap); |
60 | | SC_ATOMIC_DECLARE(uint64_t, reassembly_memcap); /**< max memory usage for stream reassembly */ |
61 | | |
62 | | uint16_t stream_init_flags; /**< new stream flags will be initialized to this */ |
63 | | |
64 | | /* coccinelle: TcpStreamCnf:flags:STREAMTCP_INIT_ */ |
65 | | uint8_t flags; |
66 | | uint8_t max_synack_queued; |
67 | | |
68 | | uint32_t prealloc_sessions; /**< ssns to prealloc per stream thread */ |
69 | | uint32_t prealloc_segments; /**< segments to prealloc per stream thread */ |
70 | | bool midstream; |
71 | | bool async_oneside; |
72 | | bool streaming_log_api; |
73 | | uint8_t max_syn_queued; |
74 | | |
75 | | uint32_t reassembly_depth; /**< Depth until when we reassemble the stream */ |
76 | | |
77 | | uint16_t reassembly_toserver_chunk_size; |
78 | | uint16_t reassembly_toclient_chunk_size; |
79 | | |
80 | | enum ExceptionPolicy ssn_memcap_policy; |
81 | | enum ExceptionPolicy reassembly_memcap_policy; |
82 | | enum ExceptionPolicy midstream_policy; |
83 | | enum TcpStreamUrgentHandling urgent_policy; |
84 | | enum TcpStreamUrgentHandling urgent_oob_limit_policy; |
85 | | |
86 | | /* default to "LINUX" timestamp behavior if true*/ |
87 | | bool liberal_timestamps; |
88 | | |
89 | | StreamingBufferConfig sbcnf; |
90 | | } TcpStreamCnf; |
91 | | |
92 | | typedef struct StreamTcpThread_ { |
93 | | int ssn_pool_id; |
94 | | |
95 | | StatsCounterId counter_tcp_active_sessions; |
96 | | StatsCounterId counter_tcp_sessions; |
97 | | /** sessions not picked up because memcap was reached */ |
98 | | StatsCounterId counter_tcp_ssn_memcap; |
99 | | StatsCounterId counter_tcp_ssn_from_cache; |
100 | | StatsCounterId counter_tcp_ssn_from_pool; |
101 | | /** exception policy */ |
102 | | ExceptionPolicyCounters counter_tcp_ssn_memcap_eps; |
103 | | /** pseudo packets processed */ |
104 | | StatsCounterId counter_tcp_pseudo; |
105 | | /** packets rejected because their csum is invalid */ |
106 | | StatsCounterId counter_tcp_invalid_checksum; |
107 | | /** midstream pickups */ |
108 | | StatsCounterId counter_tcp_midstream_pickups; |
109 | | /** exception policy stats */ |
110 | | ExceptionPolicyCounters counter_tcp_midstream_eps; |
111 | | /** wrong thread */ |
112 | | StatsCounterId counter_tcp_wrong_thread; |
113 | | /** ack for unseen data */ |
114 | | StatsCounterId counter_tcp_ack_unseen_data; |
115 | | |
116 | | /** tcp reassembly thread data */ |
117 | | TcpReassemblyThreadCtx *ra_ctx; |
118 | | } StreamTcpThread; |
119 | | |
120 | | extern TcpStreamCnf stream_config; |
121 | | void StreamTcpInitConfig(bool); |
122 | | void StreamTcpFreeConfig(bool); |
123 | | void StreamTcpRegisterTests (void); |
124 | | |
125 | | void StreamTcpSessionPktFree (Packet *); |
126 | | |
127 | | void StreamTcpInitMemuse(void); |
128 | | void StreamTcpIncrMemuse(uint64_t); |
129 | | void StreamTcpDecrMemuse(uint64_t); |
130 | | int StreamTcpSetMemcap(uint64_t); |
131 | | uint64_t StreamTcpGetMemcap(void); |
132 | | int StreamTcpCheckMemcap(uint64_t); |
133 | | uint64_t StreamTcpMemuseCounter(void); |
134 | | |
135 | | int StreamTcpSegmentForEach(const Packet *p, uint8_t flag, |
136 | | StreamSegmentCallback CallbackFunc, |
137 | | void *data); |
138 | | int StreamTcpSegmentForSession( |
139 | | const Packet *p, uint8_t flag, StreamSegmentCallback CallbackFunc, void *data); |
140 | | void StreamTcpReassembleConfigEnableOverlapCheck(void); |
141 | | void TcpSessionSetReassemblyDepth(TcpSession *ssn, uint32_t size); |
142 | | |
143 | | typedef int (*StreamReassembleRawFunc)( |
144 | | void *data, const uint8_t *input, const uint32_t input_len, const uint64_t offset); |
145 | | |
146 | | int StreamReassembleForFrame(TcpSession *ssn, TcpStream *stream, StreamReassembleRawFunc Callback, |
147 | | void *cb_data, const uint64_t offset, const bool eof); |
148 | | int StreamReassembleLog(const TcpSession *ssn, const TcpStream *stream, |
149 | | StreamReassembleRawFunc Callback, void *cb_data, const uint64_t progress_in, |
150 | | uint64_t *progress_out, const bool eof); |
151 | | int StreamReassembleRaw(TcpSession *ssn, const Packet *p, |
152 | | StreamReassembleRawFunc Callback, void *cb_data, |
153 | | uint64_t *progress_out, bool respect_inspect_depth); |
154 | | void StreamReassembleRawUpdateProgress(TcpSession *ssn, Packet *p, const uint64_t progress); |
155 | | |
156 | | void StreamTcpDetectLogFlush(ThreadVars *tv, StreamTcpThread *stt, Flow *f, Packet *p, PacketQueueNoLock *pq); |
157 | | |
158 | | const char *StreamTcpStateAsString(const enum TcpState); |
159 | | |
160 | | enum ExceptionPolicy StreamTcpSsnMemcapGetExceptionPolicy(void); |
161 | | enum ExceptionPolicy StreamTcpReassemblyMemcapGetExceptionPolicy(void); |
162 | | enum ExceptionPolicy StreamMidstreamGetExceptionPolicy(void); |
163 | | |
164 | | /** ------- Inline functions: ------ */ |
165 | | |
166 | | /** |
167 | | * \brief If we are on IPS mode, and got a drop action triggered from |
168 | | * the IP only module, or from a reassembled msg and/or from an |
169 | | * applayer detection, then drop the rest of the packets of the |
170 | | * same stream and avoid inspecting it any further |
171 | | * \param p pointer to the Packet to check |
172 | | * \retval 1 if we must drop this stream |
173 | | * \retval 0 if the stream still legal |
174 | | */ |
175 | | static inline int StreamTcpCheckFlowDrops(Packet *p) |
176 | 9.85M | { |
177 | | /* If we are on IPS mode, and got a drop action triggered from |
178 | | * the IP only module, or from a reassembled msg and/or from an |
179 | | * applayer detection, then drop the rest of the packets of the |
180 | | * same stream and avoid inspecting it any further */ |
181 | 9.85M | if (EngineModeIsIPS() && (p->flow->flags & FLOW_ACTION_DROP)) |
182 | 0 | return 1; |
183 | | |
184 | 9.85M | return 0; |
185 | 9.85M | } Unexecuted instantiation: app-layer-parser.c:StreamTcpCheckFlowDrops Unexecuted instantiation: app-layer-smtp.c:StreamTcpCheckFlowDrops Unexecuted instantiation: app-layer-ssh.c:StreamTcpCheckFlowDrops Unexecuted instantiation: app-layer.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-engine-state.c:StreamTcpCheckFlowDrops Unexecuted instantiation: output.c:StreamTcpCheckFlowDrops Unexecuted instantiation: stream-tcp-reassemble.c:StreamTcpCheckFlowDrops stream-tcp.c:StreamTcpCheckFlowDrops Line | Count | Source | 176 | 9.85M | { | 177 | | /* If we are on IPS mode, and got a drop action triggered from | 178 | | * the IP only module, or from a reassembled msg and/or from an | 179 | | * applayer detection, then drop the rest of the packets of the | 180 | | * same stream and avoid inspecting it any further */ | 181 | 9.85M | if (EngineModeIsIPS() && (p->flow->flags & FLOW_ACTION_DROP)) | 182 | 0 | return 1; | 183 | | | 184 | 9.85M | return 0; | 185 | 9.85M | } |
Unexecuted instantiation: suricata.c:StreamTcpCheckFlowDrops Unexecuted instantiation: util-exception-policy.c:StreamTcpCheckFlowDrops Unexecuted instantiation: util-file.c:StreamTcpCheckFlowDrops Unexecuted instantiation: app-layer-detect-proto.c:StreamTcpCheckFlowDrops Unexecuted instantiation: app-layer-frames.c:StreamTcpCheckFlowDrops Unexecuted instantiation: app-layer-htp.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-engine-payload.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-engine-register.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-filemagic.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-filename.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-filesize.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-filestore.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-ftpbounce.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-client-body.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-cookie.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-header-names.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-host.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-method.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-protocol.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-request-line.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-response-line.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-server-body.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-start.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-stat-code.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-stat-msg.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-ua.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-uri.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-lua.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-pcre.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-reference.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-sip-method.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-sip-uri.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-ssl-state.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-ssl-version.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-stream_size.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tcp-session.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-threshold.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-alpn.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-cert-fingerprint.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-cert-issuer.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-cert-serial.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-cert-subject.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-cert-validity.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-certs.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-ja3-hash.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-ja3-string.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-ja3s-hash.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-ja3s-string.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-random.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-sni.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-subjectaltname.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls-version.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-tls.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-ttl.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-uricontent.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-urilen.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect.c:StreamTcpCheckFlowDrops Unexecuted instantiation: flow-hash.c:StreamTcpCheckFlowDrops Unexecuted instantiation: flow-manager.c:StreamTcpCheckFlowDrops Unexecuted instantiation: flow-timeout.c:StreamTcpCheckFlowDrops Unexecuted instantiation: flow-worker.c:StreamTcpCheckFlowDrops Unexecuted instantiation: output-eve-stream.c:StreamTcpCheckFlowDrops Unexecuted instantiation: output-filestore.c:StreamTcpCheckFlowDrops Unexecuted instantiation: output-json-alert.c:StreamTcpCheckFlowDrops Unexecuted instantiation: output-json-flow.c:StreamTcpCheckFlowDrops Unexecuted instantiation: output-json-frame.c:StreamTcpCheckFlowDrops Unexecuted instantiation: output-streaming.c:StreamTcpCheckFlowDrops Unexecuted instantiation: runmode-unix-socket.c:StreamTcpCheckFlowDrops Unexecuted instantiation: stream-tcp-list.c:StreamTcpCheckFlowDrops Unexecuted instantiation: stream-tcp-sack.c:StreamTcpCheckFlowDrops Unexecuted instantiation: stream.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-bypass.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-config.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-engine-event.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-engine-file.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-engine-frame.c:StreamTcpCheckFlowDrops Unexecuted instantiation: detect-http-header-common.c:StreamTcpCheckFlowDrops Unexecuted instantiation: util-unittest-helper.c:StreamTcpCheckFlowDrops |
186 | | |
187 | | enum { |
188 | | /* stream has no segments for forced reassembly, nor for detection */ |
189 | | STREAM_HAS_UNPROCESSED_SEGMENTS_NONE = 0, |
190 | | /* stream has no segments for forced reassembly, but only segments that |
191 | | * have been sent for detection, but are stuck in the detection queues */ |
192 | | STREAM_HAS_UNPROCESSED_SEGMENTS_NEED_ONLY_DETECTION = 1, |
193 | | }; |
194 | | |
195 | | TmEcode StreamTcp (ThreadVars *, Packet *, void *, PacketQueueNoLock *); |
196 | | uint8_t StreamNeedsReassembly(const TcpSession *ssn, uint8_t direction); |
197 | | TmEcode StreamTcpThreadInit(ThreadVars *, void *, void **); |
198 | | TmEcode StreamTcpThreadDeinit(ThreadVars *tv, void *data); |
199 | | |
200 | | int StreamTcpPacket (ThreadVars *tv, Packet *p, StreamTcpThread *stt, |
201 | | PacketQueueNoLock *pq); |
202 | | /* clear ssn and return to pool */ |
203 | | void StreamTcpSessionClear(void *ssnptr); |
204 | | /* cleanup ssn, but don't free ssn */ |
205 | | void StreamTcpSessionCleanup(TcpSession *ssn); |
206 | | /* cleanup stream, but don't free the stream */ |
207 | | void StreamTcpStreamCleanup(TcpStream *stream); |
208 | | /* check if bypass is enabled */ |
209 | | int StreamTcpBypassEnabled(void); |
210 | | bool StreamTcpInlineMode(void); |
211 | | |
212 | | bool TcpSessionPacketSsnReuse(const Packet *p, const Flow *f, const void *tcp_ssn); |
213 | | |
214 | | void StreamTcpUpdateAppLayerProgress(TcpSession *ssn, char direction, |
215 | | const uint32_t progress); |
216 | | |
217 | | uint64_t StreamTcpGetUsable(const TcpStream *stream, const bool eof); |
218 | | uint64_t StreamDataRightEdge(const TcpStream *stream, const bool eof); |
219 | | |
220 | | #endif /* SURICATA_STREAM_TCP_H */ |