diff --git a/src/detect-engine.c b/src/detect-engine.c index e3319d79aa..b176fedc86 100644 --- a/src/detect-engine.c +++ b/src/detect-engine.c @@ -1986,6 +1986,7 @@ static DetectEngineCtx *DetectEngineCtxInitReal(enum DetectEngineType type, cons TAILQ_INIT(&de_ctx->sig_stat.failed_sigs); de_ctx->sigerror = NULL; de_ctx->type = type; + de_ctx->filemagic_thread_ctx_id = -1; if (type == DETECT_ENGINE_TYPE_DD_STUB || type == DETECT_ENGINE_TYPE_MT_STUB) { de_ctx->version = DetectEngineGetVersion(); diff --git a/src/detect-filemagic.c b/src/detect-filemagic.c index 607f650cd8..7ca7cb2a9c 100644 --- a/src/detect-filemagic.c +++ b/src/detect-filemagic.c @@ -92,8 +92,6 @@ static int DetectEngineInspectFilemagic( const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id); -static int g_magic_thread_ctx_id = -1; - /** * \brief Registration function for keyword: filemagic */ @@ -251,10 +249,10 @@ static int DetectFilemagicSetup (DetectEngineCtx *de_ctx, Signature *s, const ch de_ctx, s, NULL, DETECT_FILE_MAGIC, g_file_magic_buffer_id, s->alproto) < 0) return -1; - if (g_magic_thread_ctx_id == -1) { - g_magic_thread_ctx_id = DetectRegisterThreadCtxFuncs( + if (de_ctx->filemagic_thread_ctx_id == -1) { + de_ctx->filemagic_thread_ctx_id = DetectRegisterThreadCtxFuncs( de_ctx, "filemagic", DetectFilemagicThreadInit, NULL, DetectFilemagicThreadFree, 1); - if (g_magic_thread_ctx_id == -1) + if (de_ctx->filemagic_thread_ctx_id == -1) return -1; } return 0; @@ -276,11 +274,10 @@ static int DetectFilemagicSetupSticky(DetectEngineCtx *de_ctx, Signature *s, con if (DetectBufferSetActiveList(s, g_file_magic_buffer_id) < 0) return -1; - if (g_magic_thread_ctx_id == -1) { - g_magic_thread_ctx_id = DetectRegisterThreadCtxFuncs(de_ctx, "filemagic", - DetectFilemagicThreadInit, NULL, - DetectFilemagicThreadFree, 1); - if (g_magic_thread_ctx_id == -1) + if (de_ctx->filemagic_thread_ctx_id == -1) { + de_ctx->filemagic_thread_ctx_id = DetectRegisterThreadCtxFuncs( + de_ctx, "filemagic", DetectFilemagicThreadInit, NULL, DetectFilemagicThreadFree, 1); + if (de_ctx->filemagic_thread_ctx_id == -1) return -1; } return 0; @@ -301,7 +298,8 @@ static InspectionBuffer *FilemagicGetDataCallback(DetectEngineThreadCtx *det_ctx if (cur_file->magic == NULL) { DetectFilemagicThreadData *tfilemagic = - (DetectFilemagicThreadData *)DetectThreadCtxGetKeywordThreadCtx(det_ctx, g_magic_thread_ctx_id); + (DetectFilemagicThreadData *)DetectThreadCtxGetKeywordThreadCtx( + det_ctx, det_ctx->de_ctx->filemagic_thread_ctx_id); if (tfilemagic == NULL) { return NULL; } diff --git a/src/detect.h b/src/detect.h index 2aadd7fbf6..86d32939fe 100644 --- a/src/detect.h +++ b/src/detect.h @@ -807,6 +807,9 @@ typedef struct DetectEngineCtx_ { uint16_t mpm_matcher; /**< mpm matcher this ctx uses */ uint16_t spm_matcher; /**< spm matcher this ctx uses */ + /* registration id for per thread ctx for the filemagic/file.magic keywords */ + int filemagic_thread_ctx_id; + /* spm thread context prototype, built as spm matchers are constructed and * later used to construct thread context for each thread. */ SpmGlobalThreadCtx *spm_global_thread_ctx;