Having a class Rules

This commit is contained in:
Felipe Zimmerle
2018-11-19 13:57:47 -03:00
parent 6504f2664b
commit 57553f08e3
6 changed files with 80 additions and 30 deletions

View File

@@ -0,0 +1,48 @@
/*
* ModSecurity, http://www.modsecurity.org/
* Copyright (c) 2015 Trustwave Holdings, Inc. (http://www.trustwave.com/)
*
* You may not use this file except in compliance with
* the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* If any of the files related to licensing are missing or if you have any
* other questions related to licensing please contact Trustwave Holdings, Inc.
* directly using the email address security@modsecurity.org.
*
*/
#include <stdio.h>
#include <string.h>
#ifdef __cplusplus
#include <ctime>
#include <iostream>
#include <string>
#include <vector>
#include <list>
#endif
#ifndef HEADERS_MODSECURITY_RULES_H_
#define HEADERS_MODSECURITY_RULES_H_
#include "modsecurity/rules_set_properties.h"
#include "modsecurity/modsecurity.h"
#include "modsecurity/transaction.h"
#include "modsecurity/rule.h"
#ifdef __cplusplus
namespace modsecurity {
class Rules : public std::vector<Rule *> {
public:
};
} // namespace modsecurity
#endif
#endif // HEADERS_MODSECURITY_RULES_H_

View File

@@ -25,12 +25,14 @@
#endif #endif
#ifndef HEADERS_MODSECURITY_RULES_H_ #ifndef HEADERS_MODSECURITY_RULES_SET_H_
#define HEADERS_MODSECURITY_RULES_H_ #define HEADERS_MODSECURITY_RULES_SET_H_
#include "modsecurity/rules_set_properties.h" #include "modsecurity/rules_set_properties.h"
#include "modsecurity/modsecurity.h" #include "modsecurity/modsecurity.h"
#include "modsecurity/transaction.h" #include "modsecurity/transaction.h"
#include "modsecurity/rule.h"
#include "modsecurity/rules.h"
#ifdef __cplusplus #ifdef __cplusplus
@@ -40,17 +42,16 @@ namespace Parser {
class Driver; class Driver;
} }
class RulesSetPhases { class RulesSetPhases {
public: public:
~RulesSetPhases() { ~RulesSetPhases() {
/** Cleanup the rules */ /** Cleanup the rules */
for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) { for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) {
std::vector<Rule *> rules = m_rules[i]; Rules *rules = &m_rules[i];
while (rules.empty() == false) { while (rules->empty() == false) {
Rule *rule = rules.back(); Rule *rule = rules->back();
rules.pop_back(); rules->pop_back();
if (rule->refCountDecreaseAndCheck()) { if (rule->refCountDecreaseAndCheck()) {
rule = NULL; rule = NULL;
} }
@@ -84,8 +85,8 @@ class RulesSetPhases {
std::sort (v.begin(), v.end()); std::sort (v.begin(), v.end());
for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) { for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) {
for (size_t j = 0; j < from->at(i).size(); j++) { for (size_t j = 0; j < from->at(i)->size(); j++) {
Rule *rule = from->at(i).at(j); Rule *rule = from->at(i)->at(j);
if (std::binary_search(v.begin(), v.end(), rule->m_ruleId)) { if (std::binary_search(v.begin(), v.end(), rule->m_ruleId)) {
if (err != NULL) { if (err != NULL) {
*err << "Rule id: " << std::to_string(rule->m_ruleId) \ *err << "Rule id: " << std::to_string(rule->m_ruleId) \
@@ -115,10 +116,10 @@ class RulesSetPhases {
} }
} }
std::vector<modsecurity::Rule *> operator[](int index) { return m_rules[index]; } Rules *operator[](int index) { return &m_rules[index]; }
std::vector<modsecurity::Rule *> at(int index) { return m_rules[index]; } Rules *at(int index) { return &m_rules[index]; }
std::vector<modsecurity::Rule *> m_rules[8]; Rules m_rules[8];
}; };
@@ -192,4 +193,4 @@ int msc_rules_cleanup(RulesSet *rules);
} // namespace modsecurity } // namespace modsecurity
#endif #endif
#endif // HEADERS_MODSECURITY_RULES_H_ #endif // HEADERS_MODSECURITY_RULES_SET_H_

View File

@@ -42,6 +42,7 @@ pkginclude_HEADERS = \
../headers/modsecurity/intervention.h \ ../headers/modsecurity/intervention.h \
../headers/modsecurity/modsecurity.h \ ../headers/modsecurity/modsecurity.h \
../headers/modsecurity/rule.h \ ../headers/modsecurity/rule.h \
../headers/modsecurity/rules.h \
../headers/modsecurity/rule_message.h \ ../headers/modsecurity/rule_message.h \
../headers/modsecurity/rules_set.h \ ../headers/modsecurity/rules_set.h \
../headers/modsecurity/rules_set_properties.h \ ../headers/modsecurity/rules_set_properties.h \

View File

@@ -119,9 +119,9 @@ int Driver::addSecRule(Rule *rule) {
return false; return false;
} }
for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) { for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) {
std::vector<Rule *> rules = m_rulesSetPhases[i]; Rules *rules = m_rulesSetPhases[i];
for (int j = 0; j < rules.size(); j++) { for (int j = 0; j < rules->size(); j++) {
if (rules[j]->m_ruleId == rule->m_ruleId) { if (rules->at(j)->m_ruleId == rule->m_ruleId) {
m_parserError << "Rule id: " << std::to_string(rule->m_ruleId) \ m_parserError << "Rule id: " << std::to_string(rule->m_ruleId) \
<< " is duplicated" << std::endl; << " is duplicated" << std::endl;
return false; return false;

View File

@@ -155,10 +155,10 @@ int RulesSet::evaluate(int phase, Transaction *t) {
return 0; return 0;
} }
std::vector<Rule *> rules = m_rulesSetPhases[phase]; std::vector<Rule *> *rules = m_rulesSetPhases[phase];
ms_dbg_a(t, 9, "This phase consists of " \ ms_dbg_a(t, 9, "This phase consists of " \
+ std::to_string(rules.size()) + " rule(s)."); + std::to_string(rules->size()) + " rule(s).");
if (t->m_allowType == actions::disruptive::FromNowOnAllowType if (t->m_allowType == actions::disruptive::FromNowOnAllowType
&& phase != modsecurity::Phases::LoggingPhase) { && phase != modsecurity::Phases::LoggingPhase) {
@@ -176,8 +176,8 @@ int RulesSet::evaluate(int phase, Transaction *t) {
t->m_allowType = actions::disruptive::NoneAllowType; t->m_allowType = actions::disruptive::NoneAllowType;
} }
for (int i = 0; i < rules.size(); i++) { for (int i = 0; i < rules->size(); i++) {
Rule *rule = rules[i]; Rule *rule = rules->at(i);
if (t->m_marker.empty() == false) { if (t->m_marker.empty() == false) {
ms_dbg_a(t, 9, "Skipped rule id '" + std::to_string(rule->m_ruleId) \ ms_dbg_a(t, 9, "Skipped rule id '" + std::to_string(rule->m_ruleId) \
+ "' due to a SecMarker: " + t->m_marker); + "' due to a SecMarker: " + t->m_marker);
@@ -299,13 +299,13 @@ void RulesSet::debug(int level, const std::string &id,
void RulesSet::dump() { void RulesSet::dump() {
std::cout << "Rules: " << std::endl; std::cout << "Rules: " << std::endl;
for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) { for (int i = 0; i < modsecurity::Phases::NUMBER_OF_PHASES; i++) {
std::vector<Rule *> rules = m_rulesSetPhases[i]; std::vector<Rule *> *rules = m_rulesSetPhases[i];
std::cout << "Phase: " << std::to_string(i); std::cout << "Phase: " << std::to_string(i);
std::cout << " (" << std::to_string(rules.size()); std::cout << " (" << std::to_string(rules->size());
std::cout << " rules)" << std::endl; std::cout << " rules)" << std::endl;
for (int j = 0; j < rules.size(); j++) { for (int j = 0; j < rules->size(); j++) {
std::cout << " Rule ID: " << std::to_string(rules[j]->m_ruleId); std::cout << " Rule ID: " << std::to_string(rules->at(j)->m_ruleId);
std::cout << "--" << rules[j] << std::endl; std::cout << "--" << rules->at(j) << std::endl;
} }
} }
} }

View File

@@ -68,18 +68,18 @@ int main(int argc, char **argv) {
int nphases = modsecurity::Phases::NUMBER_OF_PHASES; int nphases = modsecurity::Phases::NUMBER_OF_PHASES;
for (int i = 0; i < nphases; i++) { for (int i = 0; i < nphases; i++) {
std::vector<Rule *> rules = modsecRules->m_rulesSetPhases[i]; std::vector<Rule *> *rules = modsecRules->m_rulesSetPhases[i];
if (rules.size() == 0) { if (rules->size() == 0) {
continue; continue;
} }
std::cout << "Phase: " << std::to_string(i); std::cout << "Phase: " << std::to_string(i);
std::cout << " (" << std::to_string(rules.size()); std::cout << " (" << std::to_string(rules->size());
std::cout << " rules)" << std::endl; std::cout << " rules)" << std::endl;
std::unordered_map<std::string, int> operators; std::unordered_map<std::string, int> operators;
std::unordered_map<std::string, int> variables; std::unordered_map<std::string, int> variables;
std::unordered_map<std::string, int> op2var; std::unordered_map<std::string, int> op2var;
for (auto &z : rules) { for (auto &z : *rules) {
std::string key; std::string key;
if (z == NULL) { if (z == NULL) {
continue; continue;
@@ -138,7 +138,7 @@ int main(int argc, char **argv) {
std::cout << std::endl; std::cout << std::endl;
} }
total += rules.size(); total += rules->size();
} }
std::cout << std::endl; std::cout << std::endl;