Coverage Report

Created: 2026-09-28 07:39

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/suricata8/rust/src/sip/detect.rs
Line
Count
Source
1
/* Copyright (C) 2019-2024 Open Information Security Foundation
2
 *
3
 * You can copy, redistribute or modify this Program under the terms of
4
 * the GNU General Public License version 2 as published by the Free
5
 * Software Foundation.
6
 *
7
 * This program is distributed in the hope that it will be useful,
8
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
10
 * GNU General Public License for more details.
11
 *
12
 * You should have received a copy of the GNU General Public License
13
 * version 2 along with this program; if not, write to the Free Software
14
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15
 * 02110-1301, USA.
16
 */
17
18
// written by Giuseppe Longo <giuseppe@glongo.it>
19
20
use crate::core::{STREAM_TOCLIENT, STREAM_TOSERVER};
21
use crate::detect::{helper_keyword_register_sticky_buffer, SigTableElmtStickyBuffer};
22
use crate::direction::Direction;
23
use crate::sip::sip::{SIPTransaction, ALPROTO_SIP};
24
use std::os::raw::{c_int, c_void};
25
use std::ptr;
26
use suricata_sys::sys::{
27
    DetectEngineCtx, DetectEngineThreadCtx, SCDetectBufferSetActiveList,
28
    SCDetectHelperBufferMpmRegister, SCDetectHelperMultiBufferMpmRegister,
29
    SCDetectSignatureSetAppProto, Signature,
30
};
31
32
static mut G_SIP_PROTOCOL_BUFFER_ID: c_int = 0;
33
static mut G_SIP_STAT_CODE_BUFFER_ID: c_int = 0;
34
static mut G_SIP_STAT_MSG_BUFFER_ID: c_int = 0;
35
static mut G_SIP_REQUEST_LINE_BUFFER_ID: c_int = 0;
36
static mut G_SIP_RESPONSE_LINE_BUFFER_ID: c_int = 0;
37
static mut G_SIP_FROM_HDR_BUFFER_ID: c_int = 0;
38
static mut G_SIP_TO_HDR_BUFFER_ID: c_int = 0;
39
static mut G_SIP_VIA_HDR_BUFFER_ID: c_int = 0;
40
static mut G_SIP_UA_HDR_BUFFER_ID: c_int = 0;
41
static mut G_SIP_CONTENT_TYPE_HDR_BUFFER_ID: c_int = 0;
42
static mut G_SIP_CONTENT_LENGTH_HDR_BUFFER_ID: c_int = 0;
43
44
#[no_mangle]
45
pub unsafe extern "C" fn SCSipTxGetMethod(
46
    tx: &SIPTransaction, buffer: *mut *const u8, buffer_len: *mut u32,
47
) -> u8 {
48
    if let Some(ref r) = tx.request {
49
        let m = &r.method;
50
        if !m.is_empty() {
51
            *buffer = m.as_ptr();
52
            *buffer_len = m.len() as u32;
53
            return 1;
54
        }
55
    }
56
57
    *buffer = ptr::null();
58
    *buffer_len = 0;
59
60
    return 0;
61
}
62
63
#[no_mangle]
64
0
pub unsafe extern "C" fn SCSipTxGetUri(
65
0
    tx: &SIPTransaction, buffer: *mut *const u8, buffer_len: *mut u32,
66
0
) -> u8 {
67
0
    if let Some(ref r) = tx.request {
68
0
        let p = &r.path;
69
0
        if !p.is_empty() {
70
0
            *buffer = p.as_ptr();
71
0
            *buffer_len = p.len() as u32;
72
0
            return 1;
73
0
        }
74
0
    }
75
76
0
    *buffer = ptr::null();
77
0
    *buffer_len = 0;
78
79
0
    return 0;
80
0
}
81
82
2
unsafe extern "C" fn sip_protocol_setup(
83
2
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
84
2
) -> c_int {
85
2
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
86
1
        return -1;
87
1
    }
88
1
    if SCDetectBufferSetActiveList(de, s, G_SIP_PROTOCOL_BUFFER_ID) < 0 {
89
0
        return -1;
90
1
    }
91
1
    return 0;
92
2
}
93
94
0
unsafe extern "C" fn sip_protocol_get(
95
0
    tx: *const c_void, direction: u8, buffer: *mut *const u8, buffer_len: *mut u32,
96
0
) -> bool {
97
0
    let tx = cast_pointer!(tx, SIPTransaction);
98
0
    match direction.into() {
99
        Direction::ToServer => {
100
0
            if let Some(ref r) = tx.request {
101
0
                let v = &r.version;
102
0
                if !v.is_empty() {
103
0
                    *buffer = v.as_ptr();
104
0
                    *buffer_len = v.len() as u32;
105
0
                    return true;
106
0
                }
107
0
            }
108
        }
109
        Direction::ToClient => {
110
0
            if let Some(ref r) = tx.response {
111
0
                let v = &r.version;
112
0
                if !v.is_empty() {
113
0
                    *buffer = v.as_ptr();
114
0
                    *buffer_len = v.len() as u32;
115
0
                    return true;
116
0
                }
117
0
            }
118
        }
119
    }
120
0
    *buffer = ptr::null();
121
0
    *buffer_len = 0;
122
0
    return false;
123
0
}
124
125
400
unsafe extern "C" fn sip_stat_code_setup(
126
400
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
127
400
) -> c_int {
128
400
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
129
5
        return -1;
130
395
    }
131
395
    if SCDetectBufferSetActiveList(de, s, G_SIP_STAT_CODE_BUFFER_ID) < 0 {
132
0
        return -1;
133
395
    }
134
395
    return 0;
135
400
}
136
137
0
unsafe extern "C" fn sip_stat_code_get(
138
0
    tx: *const c_void, _flags: u8, buffer: *mut *const u8, buffer_len: *mut u32,
139
0
) -> bool {
140
0
    let tx = cast_pointer!(tx, SIPTransaction);
141
0
    if let Some(ref r) = tx.response {
142
0
        let c = &r.code;
143
0
        if !c.is_empty() {
144
0
            *buffer = c.as_ptr();
145
0
            *buffer_len = c.len() as u32;
146
0
            return true;
147
0
        }
148
0
    }
149
0
    *buffer = ptr::null();
150
0
    *buffer_len = 0;
151
0
    return false;
152
0
}
153
154
391
unsafe extern "C" fn sip_stat_msg_setup(
155
391
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
156
391
) -> c_int {
157
391
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
158
264
        return -1;
159
127
    }
160
127
    if SCDetectBufferSetActiveList(de, s, G_SIP_STAT_MSG_BUFFER_ID) < 0 {
161
0
        return -1;
162
127
    }
163
127
    return 0;
164
391
}
165
166
0
unsafe extern "C" fn sip_stat_msg_get(
167
0
    tx: *const c_void, _flags: u8, buffer: *mut *const u8, buffer_len: *mut u32,
168
0
) -> bool {
169
0
    let tx = cast_pointer!(tx, SIPTransaction);
170
0
    if let Some(ref r) = tx.response {
171
0
        let re = &r.reason;
172
0
        if !re.is_empty() {
173
0
            *buffer = re.as_ptr();
174
0
            *buffer_len = re.len() as u32;
175
0
            return true;
176
0
        }
177
0
    }
178
0
    *buffer = ptr::null();
179
0
    *buffer_len = 0;
180
0
    return false;
181
0
}
182
183
5
unsafe extern "C" fn sip_request_line_setup(
184
5
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
185
5
) -> c_int {
186
5
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
187
3
        return -1;
188
2
    }
189
2
    if SCDetectBufferSetActiveList(de, s, G_SIP_REQUEST_LINE_BUFFER_ID) < 0 {
190
0
        return -1;
191
2
    }
192
2
    return 0;
193
5
}
194
195
0
unsafe extern "C" fn sip_request_line_get(
196
0
    tx: *const c_void, _flags: u8, buffer: *mut *const u8, buffer_len: *mut u32,
197
0
) -> bool {
198
0
    let tx = cast_pointer!(tx, SIPTransaction);
199
0
    if let Some(ref r) = tx.request_line {
200
0
        if !r.is_empty() {
201
0
            *buffer = r.as_ptr();
202
0
            *buffer_len = r.len() as u32;
203
0
            return true;
204
0
        }
205
0
    }
206
0
    *buffer = ptr::null();
207
0
    *buffer_len = 0;
208
0
    return false;
209
0
}
210
211
2
unsafe extern "C" fn sip_response_line_setup(
212
2
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
213
2
) -> c_int {
214
2
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
215
1
        return -1;
216
1
    }
217
1
    if SCDetectBufferSetActiveList(de, s, G_SIP_RESPONSE_LINE_BUFFER_ID) < 0 {
218
0
        return -1;
219
1
    }
220
1
    return 0;
221
2
}
222
223
0
unsafe extern "C" fn sip_response_line_get(
224
0
    tx: *const c_void, _flags: u8, buffer: *mut *const u8, buffer_len: *mut u32,
225
0
) -> bool {
226
0
    let tx = cast_pointer!(tx, SIPTransaction);
227
0
    if let Some(ref r) = tx.response_line {
228
0
        if !r.is_empty() {
229
0
            *buffer = r.as_ptr();
230
0
            *buffer_len = r.len() as u32;
231
0
            return true;
232
0
        }
233
0
    }
234
0
    *buffer = ptr::null();
235
0
    *buffer_len = 0;
236
0
    return false;
237
0
}
238
239
0
fn sip_get_header_value<'a>(
240
0
    tx: &'a SIPTransaction, i: u32, direction: Direction, s: &str,
241
0
) -> Option<&'a str> {
242
0
    let headers = match direction {
243
0
        Direction::ToServer => tx.request.as_ref().map(|r| &r.headers),
244
0
        Direction::ToClient => tx.response.as_ref().map(|r| &r.headers),
245
    };
246
0
    if let Some(headers) = headers {
247
0
        if let Some(header_vals) = headers.get(s) {
248
0
            if (i as usize) < header_vals.len() {
249
0
                let value = &header_vals[i as usize];
250
0
                return Some(value);
251
0
            }
252
0
        }
253
0
    }
254
0
    return None;
255
0
}
256
257
4
unsafe extern "C" fn sip_from_hdr_setup(
258
4
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
259
4
) -> c_int {
260
4
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
261
1
        return -1;
262
3
    }
263
3
    if SCDetectBufferSetActiveList(de, s, G_SIP_FROM_HDR_BUFFER_ID) < 0 {
264
0
        return -1;
265
3
    }
266
3
    return 0;
267
4
}
268
269
0
unsafe extern "C" fn sip_from_hdr_get_data(
270
0
    _de: *mut DetectEngineThreadCtx, tx: *const c_void, flow_flags: u8, local_id: u32,
271
0
    buffer: *mut *const u8, buffer_len: *mut u32,
272
0
) -> bool {
273
0
    let tx = cast_pointer!(tx, SIPTransaction);
274
0
    if let Some(value) = sip_get_header_value(tx, local_id, flow_flags.into(), "From") {
275
0
        *buffer = value.as_ptr();
276
0
        *buffer_len = value.len() as u32;
277
0
        return true;
278
0
    }
279
0
    *buffer = ptr::null();
280
0
    *buffer_len = 0;
281
0
    return false;
282
0
}
283
284
8
unsafe extern "C" fn sip_to_hdr_setup(
285
8
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
286
8
) -> c_int {
287
8
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
288
1
        return -1;
289
7
    }
290
7
    if SCDetectBufferSetActiveList(de, s, G_SIP_TO_HDR_BUFFER_ID) < 0 {
291
0
        return -1;
292
7
    }
293
7
    return 0;
294
8
}
295
296
0
unsafe extern "C" fn sip_to_hdr_get_data(
297
0
    _de: *mut DetectEngineThreadCtx, tx: *const c_void, flow_flags: u8, local_id: u32,
298
0
    buffer: *mut *const u8, buffer_len: *mut u32,
299
0
) -> bool {
300
0
    let tx = cast_pointer!(tx, SIPTransaction);
301
0
    if let Some(value) = sip_get_header_value(tx, local_id, flow_flags.into(), "To") {
302
0
        *buffer = value.as_ptr();
303
0
        *buffer_len = value.len() as u32;
304
0
        return true;
305
0
    }
306
0
    *buffer = ptr::null();
307
0
    *buffer_len = 0;
308
0
    return false;
309
0
}
310
311
3
unsafe extern "C" fn sip_via_hdr_setup(
312
3
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
313
3
) -> c_int {
314
3
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
315
1
        return -1;
316
2
    }
317
2
    if SCDetectBufferSetActiveList(de, s, G_SIP_VIA_HDR_BUFFER_ID) < 0 {
318
0
        return -1;
319
2
    }
320
2
    return 0;
321
3
}
322
323
0
unsafe extern "C" fn sip_via_hdr_get_data(
324
0
    _de: *mut DetectEngineThreadCtx, tx: *const c_void, flow_flags: u8, local_id: u32,
325
0
    buffer: *mut *const u8, buffer_len: *mut u32,
326
0
) -> bool {
327
0
    let tx = cast_pointer!(tx, SIPTransaction);
328
0
    if let Some(value) = sip_get_header_value(tx, local_id, flow_flags.into(), "Via") {
329
0
        *buffer = value.as_ptr();
330
0
        *buffer_len = value.len() as u32;
331
0
        return true;
332
0
    }
333
0
    *buffer = ptr::null();
334
0
    *buffer_len = 0;
335
0
    return false;
336
0
}
337
338
1
unsafe extern "C" fn sip_ua_hdr_setup(
339
1
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
340
1
) -> c_int {
341
1
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
342
0
        return -1;
343
1
    }
344
1
    if SCDetectBufferSetActiveList(de, s, G_SIP_UA_HDR_BUFFER_ID) < 0 {
345
0
        return -1;
346
1
    }
347
1
    return 0;
348
1
}
349
350
0
unsafe extern "C" fn sip_ua_hdr_get_data(
351
0
    _de: *mut DetectEngineThreadCtx, tx: *const c_void, flow_flags: u8, local_id: u32,
352
0
    buffer: *mut *const u8, buffer_len: *mut u32,
353
0
) -> bool {
354
0
    let tx = cast_pointer!(tx, SIPTransaction);
355
0
    if let Some(value) = sip_get_header_value(tx, local_id, flow_flags.into(), "User-Agent") {
356
0
        *buffer = value.as_ptr();
357
0
        *buffer_len = value.len() as u32;
358
0
        return true;
359
0
    }
360
0
    *buffer = ptr::null();
361
0
    *buffer_len = 0;
362
0
    return false;
363
0
}
364
365
3
unsafe extern "C" fn sip_content_type_hdr_setup(
366
3
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
367
3
) -> c_int {
368
3
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
369
1
        return -1;
370
2
    }
371
2
    if SCDetectBufferSetActiveList(de, s, G_SIP_CONTENT_TYPE_HDR_BUFFER_ID) < 0 {
372
0
        return -1;
373
2
    }
374
2
    return 0;
375
3
}
376
377
0
unsafe extern "C" fn sip_content_type_hdr_get_data(
378
0
    _de: *mut DetectEngineThreadCtx, tx: *const c_void, flow_flags: u8, local_id: u32,
379
0
    buffer: *mut *const u8, buffer_len: *mut u32,
380
0
) -> bool {
381
0
    let tx = cast_pointer!(tx, SIPTransaction);
382
0
    if let Some(value) = sip_get_header_value(tx, local_id, flow_flags.into(), "Content-Type") {
383
0
        *buffer = value.as_ptr();
384
0
        *buffer_len = value.len() as u32;
385
0
        return true;
386
0
    }
387
0
    *buffer = ptr::null();
388
0
    *buffer_len = 0;
389
0
    return false;
390
0
}
391
392
5
unsafe extern "C" fn sip_content_length_hdr_setup(
393
5
    de: *mut DetectEngineCtx, s: *mut Signature, _raw: *const std::os::raw::c_char,
394
5
) -> c_int {
395
5
    if SCDetectSignatureSetAppProto(s, ALPROTO_SIP) != 0 {
396
1
        return -1;
397
4
    }
398
4
    if SCDetectBufferSetActiveList(de, s, G_SIP_CONTENT_LENGTH_HDR_BUFFER_ID) < 0 {
399
0
        return -1;
400
4
    }
401
4
    return 0;
402
5
}
403
404
0
unsafe extern "C" fn sip_content_length_hdr_get_data(
405
0
    _de: *mut DetectEngineThreadCtx, tx: *const c_void, flow_flags: u8, local_id: u32,
406
0
    buffer: *mut *const u8, buffer_len: *mut u32,
407
0
) -> bool {
408
0
    let tx = cast_pointer!(tx, SIPTransaction);
409
0
    if let Some(value) = sip_get_header_value(tx, local_id, flow_flags.into(), "Content-Length") {
410
0
        *buffer = value.as_ptr();
411
0
        *buffer_len = value.len() as u32;
412
0
        return true;
413
0
    }
414
0
    *buffer = ptr::null();
415
0
    *buffer_len = 0;
416
0
    return false;
417
0
}
418
#[no_mangle]
419
39
pub unsafe extern "C" fn SCDetectSipRegister() {
420
39
    let kw = SigTableElmtStickyBuffer {
421
39
        name: String::from("sip.protocol"),
422
39
        desc: String::from("sticky buffer to match on the SIP protocol"),
423
39
        url: String::from("/rules/sip-keywords.html#sip-protocol"),
424
39
        setup: sip_protocol_setup,
425
39
    };
426
39
    let _g_sip_protocol_kw_id = helper_keyword_register_sticky_buffer(&kw);
427
39
    G_SIP_PROTOCOL_BUFFER_ID = SCDetectHelperBufferMpmRegister(
428
39
        b"sip.protocol\0".as_ptr() as *const libc::c_char,
429
39
        b"sip.protocol\0".as_ptr() as *const libc::c_char,
430
39
        ALPROTO_SIP,
431
39
        STREAM_TOSERVER | STREAM_TOCLIENT,
432
39
        Some(sip_protocol_get),
433
39
    );
434
39
    let kw = SigTableElmtStickyBuffer {
435
39
        name: String::from("sip.stat_code"),
436
39
        desc: String::from("sticky buffer to match on the SIP status code"),
437
39
        url: String::from("/rules/sip-keywords.html#sip-stat-code"),
438
39
        setup: sip_stat_code_setup,
439
39
    };
440
39
    let _g_sip_stat_code_kw_id = helper_keyword_register_sticky_buffer(&kw);
441
39
    G_SIP_STAT_CODE_BUFFER_ID = SCDetectHelperBufferMpmRegister(
442
39
        b"sip.stat_code\0".as_ptr() as *const libc::c_char,
443
39
        b"sip.stat_code\0".as_ptr() as *const libc::c_char,
444
39
        ALPROTO_SIP,
445
39
        STREAM_TOCLIENT,
446
39
        Some(sip_stat_code_get),
447
39
    );
448
39
    let kw = SigTableElmtStickyBuffer {
449
39
        name: String::from("sip.stat_msg"),
450
39
        desc: String::from("sticky buffer to match on the SIP status message"),
451
39
        url: String::from("/rules/sip-keywords.html#sip-stat-msg"),
452
39
        setup: sip_stat_msg_setup,
453
39
    };
454
39
    let _g_sip_stat_msg_kw_id = helper_keyword_register_sticky_buffer(&kw);
455
39
    G_SIP_STAT_MSG_BUFFER_ID = SCDetectHelperBufferMpmRegister(
456
39
        b"sip.stat_msg\0".as_ptr() as *const libc::c_char,
457
39
        b"sip.stat_msg\0".as_ptr() as *const libc::c_char,
458
39
        ALPROTO_SIP,
459
39
        STREAM_TOCLIENT,
460
39
        Some(sip_stat_msg_get),
461
39
    );
462
39
    let kw = SigTableElmtStickyBuffer {
463
39
        name: String::from("sip.request_line"),
464
39
        desc: String::from("sticky buffer to match on the SIP request line"),
465
39
        url: String::from("/rules/sip-keywords.html#sip-request-line"),
466
39
        setup: sip_request_line_setup,
467
39
    };
468
39
    let _g_sip_request_line_kw_id = helper_keyword_register_sticky_buffer(&kw);
469
39
    G_SIP_REQUEST_LINE_BUFFER_ID = SCDetectHelperBufferMpmRegister(
470
39
        b"sip.request_line\0".as_ptr() as *const libc::c_char,
471
39
        b"sip.request_line\0".as_ptr() as *const libc::c_char,
472
39
        ALPROTO_SIP,
473
39
        STREAM_TOSERVER,
474
39
        Some(sip_request_line_get),
475
39
    );
476
39
    let kw = SigTableElmtStickyBuffer {
477
39
        name: String::from("sip.response_line"),
478
39
        desc: String::from("sticky buffer to match on the SIP response line"),
479
39
        url: String::from("/rules/sip-keywords.html#sip-response-line"),
480
39
        setup: sip_response_line_setup,
481
39
    };
482
39
    let _g_sip_response_line_kw_id = helper_keyword_register_sticky_buffer(&kw);
483
39
    G_SIP_RESPONSE_LINE_BUFFER_ID = SCDetectHelperBufferMpmRegister(
484
39
        b"sip.response_line\0".as_ptr() as *const libc::c_char,
485
39
        b"sip.response_line\0".as_ptr() as *const libc::c_char,
486
39
        ALPROTO_SIP,
487
39
        STREAM_TOCLIENT,
488
39
        Some(sip_response_line_get),
489
39
    );
490
39
    let kw = SigTableElmtStickyBuffer {
491
39
        name: String::from("sip.from"),
492
39
        desc: String::from("sticky buffer to match on the SIP From header"),
493
39
        url: String::from("/rules/sip-keywords.html#sip-from"),
494
39
        setup: sip_from_hdr_setup,
495
39
    };
496
39
    let _g_sip_from_hdr_kw_id = helper_keyword_register_sticky_buffer(&kw);
497
39
    G_SIP_FROM_HDR_BUFFER_ID = SCDetectHelperMultiBufferMpmRegister(
498
39
        b"sip.from\0".as_ptr() as *const libc::c_char,
499
39
        b"sip.from\0".as_ptr() as *const libc::c_char,
500
39
        ALPROTO_SIP,
501
39
        STREAM_TOSERVER | STREAM_TOCLIENT,
502
39
        Some(sip_from_hdr_get_data),
503
39
    );
504
39
    let kw = SigTableElmtStickyBuffer {
505
39
        name: String::from("sip.to"),
506
39
        desc: String::from("sticky buffer to match on the SIP To header"),
507
39
        url: String::from("/rules/sip-keywords.html#sip-to"),
508
39
        setup: sip_to_hdr_setup,
509
39
    };
510
39
    let _g_sip_to_hdr_kw_id = helper_keyword_register_sticky_buffer(&kw);
511
39
    G_SIP_TO_HDR_BUFFER_ID = SCDetectHelperMultiBufferMpmRegister(
512
39
        b"sip.to\0".as_ptr() as *const libc::c_char,
513
39
        b"sip.to\0".as_ptr() as *const libc::c_char,
514
39
        ALPROTO_SIP,
515
39
        STREAM_TOSERVER | STREAM_TOCLIENT,
516
39
        Some(sip_to_hdr_get_data),
517
39
    );
518
39
    let kw = SigTableElmtStickyBuffer {
519
39
        name: String::from("sip.via"),
520
39
        desc: String::from("sticky buffer to match on the SIP Via header"),
521
39
        url: String::from("/rules/sip-keywords.html#sip-via"),
522
39
        setup: sip_via_hdr_setup,
523
39
    };
524
39
    let _g_sip_via_hdr_kw_id = helper_keyword_register_sticky_buffer(&kw);
525
39
    G_SIP_VIA_HDR_BUFFER_ID = SCDetectHelperMultiBufferMpmRegister(
526
39
        b"sip.via\0".as_ptr() as *const libc::c_char,
527
39
        b"sip.via\0".as_ptr() as *const libc::c_char,
528
39
        ALPROTO_SIP,
529
39
        STREAM_TOSERVER | STREAM_TOCLIENT,
530
39
        Some(sip_via_hdr_get_data),
531
39
    );
532
39
    let kw = SigTableElmtStickyBuffer {
533
39
        name: String::from("sip.user_agent"),
534
39
        desc: String::from("sticky buffer to match on the SIP User-Agent header"),
535
39
        url: String::from("/rules/sip-keywords.html#sip-user-agent"),
536
39
        setup: sip_ua_hdr_setup,
537
39
    };
538
39
    let _g_sip_ua_hdr_kw_id = helper_keyword_register_sticky_buffer(&kw);
539
39
    G_SIP_UA_HDR_BUFFER_ID = SCDetectHelperMultiBufferMpmRegister(
540
39
        b"sip.ua\0".as_ptr() as *const libc::c_char,
541
39
        b"sip.ua\0".as_ptr() as *const libc::c_char,
542
39
        ALPROTO_SIP,
543
39
        STREAM_TOSERVER | STREAM_TOCLIENT,
544
39
        Some(sip_ua_hdr_get_data),
545
39
    );
546
39
    let kw = SigTableElmtStickyBuffer {
547
39
        name: String::from("sip.content_type"),
548
39
        desc: String::from("sticky buffer to match on the SIP Content-Type header"),
549
39
        url: String::from("/rules/sip-keywords.html#sip-content-type"),
550
39
        setup: sip_content_type_hdr_setup,
551
39
    };
552
39
    let _g_sip_content_type_hdr_kw_id = helper_keyword_register_sticky_buffer(&kw);
553
39
    G_SIP_CONTENT_TYPE_HDR_BUFFER_ID = SCDetectHelperMultiBufferMpmRegister(
554
39
        b"sip.content_type\0".as_ptr() as *const libc::c_char,
555
39
        b"sip.content_type\0".as_ptr() as *const libc::c_char,
556
39
        ALPROTO_SIP,
557
39
        STREAM_TOSERVER | STREAM_TOCLIENT,
558
39
        Some(sip_content_type_hdr_get_data),
559
39
    );
560
39
    let kw = SigTableElmtStickyBuffer {
561
39
        name: String::from("sip.content_length"),
562
39
        desc: String::from("sticky buffer to match on the SIP Content-Length header"),
563
39
        url: String::from("/rules/sip-keywords.html#sip-content-length"),
564
39
        setup: sip_content_length_hdr_setup,
565
39
    };
566
39
    let _g_sip_content_length_hdr_kw_id = helper_keyword_register_sticky_buffer(&kw);
567
39
    G_SIP_CONTENT_LENGTH_HDR_BUFFER_ID = SCDetectHelperMultiBufferMpmRegister(
568
39
        b"sip.content_length\0".as_ptr() as *const libc::c_char,
569
39
        b"sip.content_length\0".as_ptr() as *const libc::c_char,
570
39
        ALPROTO_SIP,
571
39
        STREAM_TOSERVER | STREAM_TOCLIENT,
572
39
        Some(sip_content_length_hdr_get_data),
573
39
    );
574
39
}