transform-sha256: use Rust sha256 bindings

Use new Rust sha256 bindings insead of libnss.
pull/5722/head
Jason Ish 4 years ago committed by Victor Julien
parent 0f714be9f3
commit 9e14c00298

@ -34,17 +34,13 @@
#include "util-unittest.h"
#include "util-print.h"
#ifdef HAVE_NSS
#include <sechash.h>
#endif
#include "rust.h"
static int DetectTransformToSha256Setup (DetectEngineCtx *, Signature *, const char *);
#ifdef HAVE_NSS
#ifdef UNITTESTS
static void DetectTransformToSha256RegisterTests(void);
#endif
static void TransformToSha256(InspectionBuffer *buffer, void *options);
#endif
void DetectTransformSha256Register(void)
{
@ -55,25 +51,15 @@ void DetectTransformSha256Register(void)
"/rules/transforms.html#to-sha256";
sigmatch_table[DETECT_TRANSFORM_SHA256].Setup =
DetectTransformToSha256Setup;
#ifdef HAVE_NSS
sigmatch_table[DETECT_TRANSFORM_SHA256].Transform =
TransformToSha256;
#ifdef UNITTESTS
sigmatch_table[DETECT_TRANSFORM_SHA256].RegisterTests =
DetectTransformToSha256RegisterTests;
#endif
#endif
sigmatch_table[DETECT_TRANSFORM_SHA256].flags |= SIGMATCH_NOOPT;
}
#ifndef HAVE_NSS
static int DetectTransformToSha256Setup (DetectEngineCtx *de_ctx, Signature *s, const char *nullstr)
{
SCLogError(SC_ERR_NO_SHA256_SUPPORT, "no SHA-256 calculation support built in, "
"needed for to_sha256 keyword");
return -1;
}
#else
/**
* \internal
* \brief Apply the nocase keyword to the last pattern match, either content or uricontent
@ -86,6 +72,11 @@ static int DetectTransformToSha256Setup (DetectEngineCtx *de_ctx, Signature *s,
static int DetectTransformToSha256Setup (DetectEngineCtx *de_ctx, Signature *s, const char *nullstr)
{
SCEnter();
if (g_disable_hashing) {
SCLogError(SC_ERR_HASHING_DISABLED, "SHA256 hashing has been disabled, "
"needed for to_sha256 keyword");
SCReturnInt(-1);
}
int r = DetectSignatureAddTransform(s, DETECT_TRANSFORM_SHA256, NULL);
SCReturnInt(r);
}
@ -94,21 +85,12 @@ static void TransformToSha256(InspectionBuffer *buffer, void *options)
{
const uint8_t *input = buffer->inspect;
const uint32_t input_len = buffer->inspect_len;
uint8_t output[SHA256_LENGTH];
uint8_t output[SC_SHA256_LEN];
//PrintRawDataFp(stdout, input, input_len);
HASHContext *sha256_ctx = HASH_Create(HASH_AlgSHA256);
if (sha256_ctx) {
HASH_Begin(sha256_ctx);
HASH_Update(sha256_ctx, input, input_len);
unsigned int len = 0;
HASH_End(sha256_ctx, output, &len, sizeof(output));
HASH_Destroy(sha256_ctx);
SCSha256HashBuffer(input, input_len, output, sizeof(output));
InspectionBufferCopy(buffer, output, sizeof(output));
}
}
#ifdef UNITTESTS
static int DetectTransformToSha256Test01(void)
@ -132,4 +114,3 @@ static void DetectTransformToSha256RegisterTests(void)
DetectTransformToSha256Test01);
}
#endif
#endif

@ -25,6 +25,7 @@
* cbindgen. */
#define SC_MD5_LEN 16
#define SC_SHA1_LEN 20
#define SC_SHA256_LEN 32
#define JB_SET_STRING(jb, key, val) jb_set_formatted((jb), "\"" key "\":\"" val "\"")
#define JB_SET_TRUE(jb, key) jb_set_formatted((jb), "\"" key "\":true")

Loading…
Cancel
Save