rust/detect: convert uint nom 8

And users of uint directly impacted by this change.

Ticket: #8051
pull/14332/head
Jason Ish 10 months ago committed by Victor Julien
parent cf604751de
commit efc32dea41

@ -16,10 +16,10 @@
*/ */
use super::uint::{detect_parse_uint, DetectUintData}; use super::uint::{detect_parse_uint, DetectUintData};
use nom7::branch::alt; use nom8::branch::alt;
use nom7::bytes::complete::{is_a, tag}; use nom8::bytes::complete::{is_a, tag};
use nom7::combinator::{opt, value}; use nom8::combinator::{opt, value};
use nom7::IResult; use nom8::{IResult, Parser};
use std::ffi::CStr; use std::ffi::CStr;
#[allow(non_camel_case_types)] #[allow(non_camel_case_types)]
@ -53,16 +53,16 @@ fn detect_parse_flow_direction(i: &str) -> IResult<&str, DetectFlowDir> {
value(DetectFlowDir::DETECT_FLOW_TOSERVER, tag("toserver")), value(DetectFlowDir::DETECT_FLOW_TOSERVER, tag("toserver")),
value(DetectFlowDir::DETECT_FLOW_TOCLIENT, tag("toclient")), value(DetectFlowDir::DETECT_FLOW_TOCLIENT, tag("toclient")),
value(DetectFlowDir::DETECT_FLOW_TOEITHER, tag("either")), value(DetectFlowDir::DETECT_FLOW_TOEITHER, tag("either")),
))(i)?; )).parse(i)?;
return Ok((i, fd)); return Ok((i, fd));
} }
fn detect_parse_flow_pkts(i: &str) -> IResult<&str, DetectFlowPkts> { fn detect_parse_flow_pkts(i: &str) -> IResult<&str, DetectFlowPkts> {
let (i, _) = opt(is_a(" \t"))(i)?; let (i, _) = opt(is_a(" \t")).parse(i)?;
let (i, fd) = detect_parse_flow_direction(i)?; let (i, fd) = detect_parse_flow_direction(i)?;
let (i, _) = opt(is_a(" \t"))(i)?; let (i, _) = opt(is_a(" \t")).parse(i)?;
let (i, _) = tag(",")(i)?; let (i, _) = tag(",").parse(i)?;
let (i, _) = opt(is_a(" \t"))(i)?; let (i, _) = opt(is_a(" \t")).parse(i)?;
return detect_parse_flow_pkts_dir(i, fd); return detect_parse_flow_pkts_dir(i, fd);
} }
@ -111,11 +111,11 @@ pub unsafe extern "C" fn SCDetectFlowPktsFree(ctx: &mut DetectFlowPkts) {
} }
fn detect_parse_flow_bytes(i: &str) -> IResult<&str, DetectFlowBytes> { fn detect_parse_flow_bytes(i: &str) -> IResult<&str, DetectFlowBytes> {
let (i, _) = opt(is_a(" \t"))(i)?; let (i, _) = opt(is_a(" \t")).parse(i)?;
let (i, fd) = detect_parse_flow_direction(i)?; let (i, fd) = detect_parse_flow_direction(i)?;
let (i, _) = opt(is_a(" \t"))(i)?; let (i, _) = opt(is_a(" \t")).parse(i)?;
let (i, _) = tag(",")(i)?; let (i, _) = tag(",").parse(i)?;
let (i, _) = opt(is_a(" \t"))(i)?; let (i, _) = opt(is_a(" \t")).parse(i)?;
return detect_parse_flow_bytes_dir(i, fd); return detect_parse_flow_bytes_dir(i, fd);
} }

@ -16,10 +16,10 @@
*/ */
use super::uint::*; use super::uint::*;
use nom7::bytes::complete::{is_a, take_while}; use nom8::bytes::complete::{is_a, take_while};
use nom7::character::complete::{alpha0, char, digit1}; use nom8::character::complete::{alpha0, char, digit1};
use nom7::combinator::{all_consuming, map_opt, map_res, opt}; use nom8::combinator::{all_consuming, map_opt, map_res, opt};
use nom7::IResult; use nom8::{IResult, Parser};
use std::ffi::CStr; use std::ffi::CStr;
use std::str::FromStr; use std::str::FromStr;
@ -58,17 +58,17 @@ pub struct DetectStreamSizeData {
} }
pub fn detect_parse_stream_size(i: &str) -> IResult<&str, DetectStreamSizeData> { pub fn detect_parse_stream_size(i: &str) -> IResult<&str, DetectStreamSizeData> {
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, flags) = map_res(alpha0, DetectStreamSizeDataFlags::from_str)(i)?; let (i, flags) = map_res(alpha0, DetectStreamSizeDataFlags::from_str).parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, _) = char(',')(i)?; let (i, _) = char(',').parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, mode) = detect_parse_uint_mode(i)?; let (i, mode) = detect_parse_uint_mode(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, _) = char(',')(i)?; let (i, _) = char(',').parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, arg1) = map_opt(digit1, |s: &str| s.parse::<u32>().ok())(i)?; let (i, arg1) = map_opt(digit1, |s: &str| s.parse::<u32>().ok()).parse(i)?;
let (i, _) = all_consuming(take_while(|c| c == ' '))(i)?; let (i, _) = all_consuming(take_while(|c| c == ' ')).parse(i)?;
let du32 = DetectUintData::<u32> { let du32 = DetectUintData::<u32> {
arg1, arg1,
arg2: 0, arg2: 0,

@ -15,13 +15,13 @@
* 02110-1301, USA. * 02110-1301, USA.
*/ */
use nom7::branch::alt; use nom8::branch::alt;
use nom7::bytes::complete::{is_a, tag, tag_no_case, take, take_till, take_while}; use nom8::bytes::complete::{is_a, tag, tag_no_case, take, take_till, take_while};
use nom7::character::complete::{anychar, char, digit1, hex_digit1, i32 as nom_i32}; use nom8::character::complete::{anychar, char, digit1, hex_digit1, i32 as nom_i32};
use nom7::combinator::{all_consuming, map_opt, opt, value, verify}; use nom8::combinator::{all_consuming, map_opt, opt, value, verify};
use nom7::error::{make_error, Error, ErrorKind}; use nom8::error::{make_error, Error, ErrorKind};
use nom7::Err; use nom8::Err;
use nom7::IResult; use nom8::{IResult, Parser};
use super::EnumString; use super::EnumString;
@ -71,28 +71,28 @@ pub struct DetectUintArrayData<T> {
} }
fn parse_uint_index_precise(s: &str) -> IResult<&str, DetectUintIndex> { fn parse_uint_index_precise(s: &str) -> IResult<&str, DetectUintIndex> {
let (s, oob) = opt(tag("oob_or"))(s)?; let (s, oob) = opt(tag("oob_or")).parse(s)?;
let (s, _) = opt(is_a(" "))(s)?; let (s, _) = opt(is_a(" ")).parse(s)?;
let (s, i32_index) = nom_i32(s)?; let (s, i32_index) = nom_i32.parse(s)?;
Ok((s, DetectUintIndex::Index((oob.is_some(), i32_index)))) Ok((s, DetectUintIndex::Index((oob.is_some(), i32_index))))
} }
fn parse_uint_index_nb(s: &str) -> IResult<&str, DetectUintIndex> { fn parse_uint_index_nb(s: &str) -> IResult<&str, DetectUintIndex> {
let (s, _) = tag("nb")(s)?; let (s, _) = tag("nb").parse(s)?;
let (s, _) = opt(is_a(" "))(s)?; let (s, _) = opt(is_a(" ")).parse(s)?;
let (s, du32) = detect_parse_uint::<u32>(s)?; let (s, du32) = detect_parse_uint::<u32>(s)?;
Ok((s, DetectUintIndex::NumberMatches(du32))) Ok((s, DetectUintIndex::NumberMatches(du32)))
} }
fn parse_uint_index_val(s: &str) -> Option<DetectUintIndex> { fn parse_uint_index_val(s: &str) -> Option<DetectUintIndex> {
let (_s, arg1) = alt((parse_uint_index_precise, parse_uint_index_nb))(s).ok()?; let (_s, arg1) = alt((parse_uint_index_precise, parse_uint_index_nb)).parse(s).ok()?;
Some(arg1) Some(arg1)
} }
fn parse_uint_subslice_aux(s: &str) -> IResult<&str, (i32, i32)> { fn parse_uint_subslice_aux(s: &str) -> IResult<&str, (i32, i32)> {
let (s, start) = nom_i32(s)?; let (s, start) = nom_i32.parse(s)?;
let (s, _) = char(':')(s)?; let (s, _) = char(':').parse(s)?;
let (s, end) = nom_i32(s)?; let (s, end) = nom_i32.parse(s)?;
return Ok((s, (start, end))); return Ok((s, (start, end)));
} }
@ -113,8 +113,8 @@ fn parse_uint_subslice(parts: &[&str]) -> Option<(i32, i32)> {
} }
fn parse_uint_count(s: &str) -> IResult<&str, DetectUintData<u32>> { fn parse_uint_count(s: &str) -> IResult<&str, DetectUintData<u32>> {
let (s, _) = tag("count")(s)?; let (s, _) = tag("count").parse(s)?;
let (s, _) = opt(is_a(" "))(s)?; let (s, _) = opt(is_a(" ")).parse(s)?;
let (s, du32) = detect_parse_uint::<u32>(s)?; let (s, du32) = detect_parse_uint::<u32>(s)?;
Ok((s, du32)) Ok((s, du32))
} }
@ -353,13 +353,13 @@ fn parse_flag_list<T1: DetectIntType, T2: EnumString<T1>>(
let mut r = Vec::new(); let mut r = Vec::new();
let mut s2 = s; let mut s2 = s;
while !s2.is_empty() { while !s2.is_empty() {
let (s, _) = opt(is_a(" "))(s2)?; let (s, _) = opt(is_a(" ")).parse(s2)?;
let (s, neg) = opt(tag("!"))(s)?; let (s, neg) = opt(tag("!")).parse(s)?;
let neg = neg.is_some(); let neg = neg.is_some();
let (s, vals) = if singlechar { let (s, vals) = if singlechar {
take(1usize)(s) take(1usize).parse(s)
} else { } else {
take_while(|c| c != ' ' && c != ',')(s) take_while(|c| c != ' ' && c != ',').parse(s)
}?; }?;
let value = T2::from_str(vals); let value = T2::from_str(vals);
if value.is_none() { if value.is_none() {
@ -370,7 +370,7 @@ fn parse_flag_list<T1: DetectIntType, T2: EnumString<T1>>(
let (s, _) = if singlechar { let (s, _) = if singlechar {
Ok((s, None)) Ok((s, None))
} else { } else {
opt(is_a(" ,"))(s) opt(is_a(" ,")).parse(s)
}?; }?;
r.push(FlagItem { neg, value }); r.push(FlagItem { neg, value });
s2 = s; s2 = s;
@ -386,7 +386,7 @@ pub fn detect_parse_uint_bitflags<T1: DetectIntType, T2: EnumString<T1>>(
} }
// otherwise, try strings for bitmask // otherwise, try strings for bitmask
let (s, modifier) = parse_bitchars_modifier(s, defmod).ok()?; let (s, modifier) = parse_bitchars_modifier(s, defmod).ok()?;
let (s, _) = take_while::<_, &str, Error<_>>(|c| c == ' ' || c == '\t')(s).ok()?; let (s, _) = take_while::<_, &str, Error<_>>(|c| c == ' ' || c == '\t').parse(s).ok()?;
if let Ok((rem, l)) = parse_flag_list::<T1, T2>(s, singlechar) { if let Ok((rem, l)) = parse_flag_list::<T1, T2>(s, singlechar) {
if !rem.is_empty() { if !rem.is_empty() {
SCLogError!("junk at the end of bitflags"); SCLogError!("junk at the end of bitflags");
@ -481,7 +481,7 @@ pub fn detect_parse_uint_enum<T1: DetectIntType, T2: EnumString<T1>>(
} }
// we need to precise the Error type, we get error[E0283]: type annotations needed // we need to precise the Error type, we get error[E0283]: type annotations needed
let (s, neg) = opt(char::<_, Error<_>>('!'))(s).ok()?; let (s, neg) = opt(char::<_, Error<_>>('!')).parse(s).ok()?;
let mode = if neg.is_some() { let mode = if neg.is_some() {
DetectUintMode::DetectUintModeNe DetectUintMode::DetectUintModeNe
} else { } else {
@ -528,13 +528,13 @@ pub fn detect_parse_uint_unit(i: &str) -> IResult<&str, u64> {
value(1024 * 1024, tag_no_case("mb")), value(1024 * 1024, tag_no_case("mb")),
value(1024 * 1024 * 1024, tag_no_case("gib")), value(1024 * 1024 * 1024, tag_no_case("gib")),
value(1024 * 1024 * 1024, tag_no_case("gb")), value(1024 * 1024 * 1024, tag_no_case("gb")),
))(i)?; )).parse(i)?;
return Ok((i, unit)); return Ok((i, unit));
} }
pub fn detect_parse_uint_value_hex<T: DetectIntType>(i: &str) -> IResult<&str, T> { pub fn detect_parse_uint_value_hex<T: DetectIntType>(i: &str) -> IResult<&str, T> {
let (i, _) = tag("0x")(i)?; let (i, _) = tag("0x").parse(i)?;
let (i, arg1s) = hex_digit1(i)?; let (i, arg1s) = hex_digit1.parse(i)?;
match T::from_str_radix(arg1s, 16) { match T::from_str_radix(arg1s, 16) {
Ok(arg1) => Ok((i, arg1)), Ok(arg1) => Ok((i, arg1)),
_ => Err(Err::Error(make_error(i, ErrorKind::Verify))), _ => Err(Err::Error(make_error(i, ErrorKind::Verify))),
@ -542,13 +542,13 @@ pub fn detect_parse_uint_value_hex<T: DetectIntType>(i: &str) -> IResult<&str, T
} }
pub fn detect_parse_uint_value<T: DetectIntType>(i: &str) -> IResult<&str, T> { pub fn detect_parse_uint_value<T: DetectIntType>(i: &str) -> IResult<&str, T> {
let (i, arg1) = alt((detect_parse_uint_value_hex, detect_parse_uint_with_unit))(i)?; let (i, arg1) = alt((detect_parse_uint_value_hex, detect_parse_uint_with_unit)).parse(i)?;
Ok((i, arg1)) Ok((i, arg1))
} }
pub fn detect_parse_uint_with_unit<T: DetectIntType>(i: &str) -> IResult<&str, T> { pub fn detect_parse_uint_with_unit<T: DetectIntType>(i: &str) -> IResult<&str, T> {
let (i, arg1) = map_opt(digit1, |s: &str| s.parse::<T>().ok())(i)?; let (i, arg1) = map_opt(digit1, |s: &str| s.parse::<T>().ok()).parse(i)?;
let (i, unit) = opt(detect_parse_uint_unit)(i)?; let (i, unit) = opt(detect_parse_uint_unit).parse(i)?;
if arg1 >= T::one() { if arg1 >= T::one() {
if let Some(u) = unit { if let Some(u) = unit {
if T::max_value().to_u64().unwrap() / u < arg1.to_u64().unwrap() { if T::max_value().to_u64().unwrap() / u < arg1.to_u64().unwrap() {
@ -564,8 +564,8 @@ pub fn detect_parse_uint_with_unit<T: DetectIntType>(i: &str) -> IResult<&str, T
pub fn detect_parse_uint_start_equal<T: DetectIntType>( pub fn detect_parse_uint_start_equal<T: DetectIntType>(
i: &str, i: &str,
) -> IResult<&str, DetectUintData<T>> { ) -> IResult<&str, DetectUintData<T>> {
let (i, _) = opt(tag("="))(i)?; let (i, _) = opt(tag("=")).parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, arg1) = detect_parse_uint_value(i)?; let (i, arg1) = detect_parse_uint_value(i)?;
Ok(( Ok((
i, i,
@ -580,14 +580,14 @@ pub fn detect_parse_uint_start_equal<T: DetectIntType>(
pub fn detect_parse_uint_start_interval<T: DetectIntType>( pub fn detect_parse_uint_start_interval<T: DetectIntType>(
i: &str, i: &str,
) -> IResult<&str, DetectUintData<T>> { ) -> IResult<&str, DetectUintData<T>> {
let (i, neg) = opt(char('!'))(i)?; let (i, neg) = opt(char('!')).parse(i)?;
let (i, arg1) = detect_parse_uint_value(i)?; let (i, arg1) = detect_parse_uint_value(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, _) = alt((tag("-"), tag("<>")))(i)?; let (i, _) = alt((tag("-"), tag("<>"))).parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, arg2) = verify(detect_parse_uint_value, |x| { let (i, arg2) = verify(detect_parse_uint_value, |x| {
x > &arg1 && *x - arg1 > T::one() x > &arg1 && *x - arg1 > T::one()
})(i)?; }).parse(i)?;
let mode = if neg.is_some() { let mode = if neg.is_some() {
DetectUintMode::DetectUintModeNegRg DetectUintMode::DetectUintModeNegRg
} else { } else {
@ -597,14 +597,14 @@ pub fn detect_parse_uint_start_interval<T: DetectIntType>(
} }
pub fn detect_parse_uint_bitmask<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> { pub fn detect_parse_uint_bitmask<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> {
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, _) = tag("&")(i)?; let (i, _) = tag("&").parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, arg1) = detect_parse_uint_value(i)?; let (i, arg1) = detect_parse_uint_value(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, neg) = opt(tag("!"))(i)?; let (i, neg) = opt(tag("!")).parse(i)?;
let (i, _) = tag("=")(i)?; let (i, _) = tag("=").parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, arg2) = detect_parse_uint_value(i)?; let (i, arg2) = detect_parse_uint_value(i)?;
if arg2 & arg1 != arg2 { if arg2 & arg1 != arg2 {
// could never match // could never match
@ -621,14 +621,14 @@ pub fn detect_parse_uint_bitmask<T: DetectIntType>(i: &str) -> IResult<&str, Det
fn detect_parse_uint_start_interval_inclusive<T: DetectIntType>( fn detect_parse_uint_start_interval_inclusive<T: DetectIntType>(
i: &str, i: &str,
) -> IResult<&str, DetectUintData<T>> { ) -> IResult<&str, DetectUintData<T>> {
let (i, neg) = opt(char('!'))(i)?; let (i, neg) = opt(char('!')).parse(i)?;
let (i, arg1) = verify(detect_parse_uint_value::<T>, |x| *x > T::min_value())(i)?; let (i, arg1) = verify(detect_parse_uint_value::<T>, |x| *x > T::min_value()).parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, _) = alt((tag("-"), tag("<>")))(i)?; let (i, _) = alt((tag("-"), tag("<>"))).parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, arg2) = verify(detect_parse_uint_value::<T>, |x| { let (i, arg2) = verify(detect_parse_uint_value::<T>, |x| {
*x > arg1 && *x < T::max_value() *x > arg1 && *x < T::max_value()
})(i)?; }).parse(i)?;
let mode = if neg.is_some() { let mode = if neg.is_some() {
DetectUintMode::DetectUintModeNegRg DetectUintMode::DetectUintModeNegRg
} else { } else {
@ -653,13 +653,13 @@ pub fn detect_parse_uint_mode(i: &str) -> IResult<&str, DetectUintMode> {
value(DetectUintMode::DetectUintModeNe, tag("!=")), value(DetectUintMode::DetectUintModeNe, tag("!=")),
value(DetectUintMode::DetectUintModeNe, tag("!")), value(DetectUintMode::DetectUintModeNe, tag("!")),
value(DetectUintMode::DetectUintModeEqual, tag("=")), value(DetectUintMode::DetectUintModeEqual, tag("=")),
))(i)?; )).parse(i)?;
return Ok((i, mode)); return Ok((i, mode));
} }
fn detect_parse_uint_start_symbol<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> { fn detect_parse_uint_start_symbol<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> {
let (i, mode) = detect_parse_uint_mode(i)?; let (i, mode) = detect_parse_uint_mode(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, arg1) = detect_parse_uint_value(i)?; let (i, arg1) = detect_parse_uint_value(i)?;
match mode { match mode {
@ -764,30 +764,30 @@ pub fn detect_match_uint<T: DetectIntType>(x: &DetectUintData<T>, val: T) -> boo
pub(crate) fn detect_parse_uint_notending<T: DetectIntType>( pub(crate) fn detect_parse_uint_notending<T: DetectIntType>(
i: &str, i: &str,
) -> IResult<&str, DetectUintData<T>> { ) -> IResult<&str, DetectUintData<T>> {
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, uint) = alt(( let (i, uint) = alt((
detect_parse_uint_bitmask, detect_parse_uint_bitmask,
detect_parse_uint_start_interval, detect_parse_uint_start_interval,
detect_parse_uint_start_equal, detect_parse_uint_start_equal,
detect_parse_uint_start_symbol, detect_parse_uint_start_symbol,
))(i)?; )).parse(i)?;
Ok((i, uint)) Ok((i, uint))
} }
pub fn detect_parse_uint<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> { pub fn detect_parse_uint<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> {
let (i, uint) = detect_parse_uint_notending(i)?; let (i, uint) = detect_parse_uint_notending(i)?;
let (i, _) = all_consuming(take_while(|c| c == ' '))(i)?; let (i, _) = all_consuming(take_while(|c| c == ' ')).parse(i)?;
Ok((i, uint)) Ok((i, uint))
} }
pub fn detect_parse_uint_inclusive<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> { pub fn detect_parse_uint_inclusive<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> {
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, uint) = alt(( let (i, uint) = alt((
detect_parse_uint_start_interval_inclusive, detect_parse_uint_start_interval_inclusive,
detect_parse_uint_start_equal, detect_parse_uint_start_equal,
detect_parse_uint_start_symbol, detect_parse_uint_start_symbol,
))(i)?; )).parse(i)?;
let (i, _) = all_consuming(take_while(|c| c == ' '))(i)?; let (i, _) = all_consuming(take_while(|c| c == ' ')).parse(i)?;
Ok((i, uint)) Ok((i, uint))
} }
@ -944,10 +944,10 @@ pub unsafe extern "C" fn SCDetectU16Parse(
} }
pub fn detect_parse_unquote_uint<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> { pub fn detect_parse_unquote_uint<T: DetectIntType>(i: &str) -> IResult<&str, DetectUintData<T>> {
let (i, _) = take_while(|c| c == ' ')(i)?; let (i, _) = take_while(|c| c == ' ').parse(i)?;
let (i, quote) = opt(tag("\""))(i)?; let (i, quote) = opt(tag("\"")).parse(i)?;
if quote.is_some() { if quote.is_some() {
let (i, unquote) = take_till(|c| c == '"')(i)?; let (i, unquote) = take_till(|c| c == '"').parse(i)?;
if i.is_empty() { if i.is_empty() {
return Err(Err::Error(make_error(i, ErrorKind::Tag))); return Err(Err::Error(make_error(i, ErrorKind::Tag)));
} }

@ -16,11 +16,11 @@
*/ */
use super::uint::*; use super::uint::*;
use nom7::branch::alt; use nom8::branch::alt;
use nom7::bytes::complete::{is_a, tag, take_while}; use nom8::bytes::complete::{is_a, tag, take_while};
use nom7::character::complete::char; use nom8::character::complete::char;
use nom7::combinator::{all_consuming, opt, value}; use nom8::combinator::{all_consuming, opt, value};
use nom7::IResult; use nom8::{IResult, Parser};
use std::ffi::CStr; use std::ffi::CStr;
@ -32,17 +32,17 @@ pub struct DetectUrilenData {
} }
pub fn detect_parse_urilen_raw(i: &str) -> IResult<&str, bool> { pub fn detect_parse_urilen_raw(i: &str) -> IResult<&str, bool> {
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, _) = char(',')(i)?; let (i, _) = char(',').parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
let (i, v) = alt((value(true, tag("raw")), value(false, tag("norm"))))(i)?; let (i, v) = alt((value(true, tag("raw")), value(false, tag("norm")))).parse(i)?;
let (i, _) = opt(is_a(" "))(i)?; let (i, _) = opt(is_a(" ")).parse(i)?;
Ok((i, v)) Ok((i, v))
} }
pub fn detect_parse_urilen(i: &str) -> IResult<&str, DetectUrilenData> { pub fn detect_parse_urilen(i: &str) -> IResult<&str, DetectUrilenData> {
let (i, du16) = detect_parse_uint_notending::<u16>(i)?; let (i, du16) = detect_parse_uint_notending::<u16>(i)?;
let (i, _) = take_while(|c| c == ' ')(i)?; let (i, _) = take_while(|c| c == ' ').parse(i)?;
if i.is_empty() { if i.is_empty() {
return Ok(( return Ok((
i, i,
@ -52,7 +52,7 @@ pub fn detect_parse_urilen(i: &str) -> IResult<&str, DetectUrilenData> {
}, },
)); ));
} }
let (i, raw_buffer) = all_consuming(detect_parse_urilen_raw)(i)?; let (i, raw_buffer) = all_consuming(detect_parse_urilen_raw).parse(i)?;
return Ok((i, DetectUrilenData { du16, raw_buffer })); return Ok((i, DetectUrilenData { du16, raw_buffer }));
} }

@ -20,10 +20,9 @@ use crate::common::nom7::bits;
use crate::detect::uint::{detect_parse_uint, DetectUintData}; use crate::detect::uint::{detect_parse_uint, DetectUintData};
use crate::http2::http2::{HTTP2DynTable, HTTP2_MAX_TABLESIZE}; use crate::http2::http2::{HTTP2DynTable, HTTP2_MAX_TABLESIZE};
use nom7::bits::streaming::take as take_bits; use nom7::bits::streaming::take as take_bits;
use nom7::branch::alt;
use nom7::bytes::complete::tag; use nom7::bytes::complete::tag;
use nom7::bytes::streaming::{is_a, is_not, take, take_while}; use nom7::bytes::streaming::{take, take_while};
use nom7::combinator::{complete, cond, map_opt, opt, rest, verify}; use nom7::combinator::{complete, cond, map_opt, verify};
use nom7::error::{make_error, ErrorKind}; use nom7::error::{make_error, ErrorKind};
use nom7::multi::many0; use nom7::multi::many0;
use nom7::number::streaming::{be_u16, be_u24, be_u32, be_u8}; use nom7::number::streaming::{be_u16, be_u24, be_u32, be_u8};
@ -683,12 +682,17 @@ pub struct DetectHTTP2settingsSigCtx {
pub value: Option<DetectUintData<u32>>, //optional value pub value: Option<DetectUintData<u32>>, //optional value
} }
pub fn http2_parse_settingsctx(i: &str) -> IResult<&str, DetectHTTP2settingsSigCtx> { pub fn http2_parse_settingsctx(i: &str) -> nom8::IResult<&str, DetectHTTP2settingsSigCtx> {
let (i, _) = opt(is_a(" "))(i)?; use nom8::Parser;
let (i, id) = map_opt(alt((complete(is_not(" <>=")), rest)), |s: &str| { use nom8::bytes::complete::{is_a as is_a8, is_not as is_not8};
use nom8::combinator::{complete as complete8, map_opt as map_opt8, opt as opt8, rest as rest8};
use nom8::branch::alt as alt8;
let (i, _) = opt8(is_a8(" ")).parse(i)?;
let (i, id) = map_opt8(alt8((complete8(is_not8(" <>=")), rest8)), |s: &str| {
HTTP2SettingsId::from_str(s).ok() HTTP2SettingsId::from_str(s).ok()
})(i)?; }).parse(i)?;
let (i, value) = opt(complete(detect_parse_uint))(i)?; let (i, value) = opt8(complete8(detect_parse_uint)).parse(i)?;
Ok((i, DetectHTTP2settingsSigCtx { id, value })) Ok((i, DetectHTTP2settingsSigCtx { id, value }))
} }

Loading…
Cancel
Save