Snort mailing list archives

Re: Snort183 -A unsock -- part deux


From: "Dr. Richard W. Tibbs" <ccamp () oakcitysolutions com>
Date: Sun, 17 Mar 2002 13:28:24 -0500

On this issue, I am now inclined to see how a complete snort source distrib compiles on Win2k. I suspect there is some majic that the configure script (win version) performs to get the right defines and includes done for snprintf. What I have tried up to this point is just adding the snprintf source (the sendmail version from snort) with my socket prog files, and evidently that is not enough, even with everything from the /snort/win32 directories downloaded and added to my MS vis. studio project. The bottom line is that I can get snprintf to compile cleanly with no errors or warnings *ONLY* by defining __STDC__, at the expense of all other modules failing due to includes of snort.h. Is snort not a "standard" C program under win32?
I attached the config.h and snprintf.h and .c to this email.
Keep in mind config.h was not generated from a configure script, just came straight from the snort site via CVS. Also: all other modules compile successfully, with perhaps a few warnings except for snprintf.c The errors I am getting from the "most vanilla" situation (just commenting out #define HAVE_SNPRINTF) are here (but see my analysis below): --------------------Configuration: snort - Win32 MSSQL Debug--------------------
Compiling...
snprintf.c
c:\cpp_project\oak_snortprj\snprintf.c(83) : error C2061: syntax error : identifier 'va_dcl' c:\cpp_project\oak_snortprj\snprintf.c(112) : error C2065: 'u_char' : undeclared identifier c:\cpp_project\oak_snortprj\snprintf.c(112) : error C2143: syntax error : missing ')' before 'constant' c:\cpp_project\oak_snortprj\snprintf.c(189) : warning C4013: 'va_arg' undefined; assuming extern returning int c:\cpp_project\oak_snortprj\snprintf.c(189) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(191) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(200) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(204) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(212) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(216) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(223) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(227) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(233) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(237) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(243) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(247) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(251) : error C2059: syntax error : 'type' c:\cpp_project\oak_snortprj\snprintf.c(260) : error C2059: syntax error : 'type'
Error executing cl.exe.

snprintf.obj - 17 error(s), 1 warning(s)

My Analysis: If I look at the logic in the snprintf.h file, it looks for "not" HAVE_SNPRINTF then for __STDC__ to include stdarg.h This file has everything except va_dcl, which seems only to be defined in varargs.h The config.h from the win32 subdirectories does not define __STDC__, but if I insert a line to define it then the errors are merely:

--------------------Configuration: snort - Win32 MSSQL Debug--------------------
Compiling...
snprintf.c
C:\CPP_project\Oak_snortprj\snprintf.c(112) : error C2065: 'u_char' : undeclared identifier C:\CPP_project\Oak_snortprj\snprintf.c(112) : error C2143: syntax error : missing ')' before 'constant'
Error executing cl.exe.

snprintf.obj - 2 error(s), 0 warning(s)

Now, upon a search through the MS vis studio include directory for text "u_char" I find only winsock.h and a few others reference and/or define it.

If I include
#include <winsock.h> at the very top of snprintf.h, I get a clean compile with no errors or warnings!! So adding a define for __STDC__ and including winsock seems to solve the problem for snprintf. BUT!!! all other modules fail to compile due to syntax errors in places like xdr.h gnuc.h etc when __STC__ is defined !!. AAAaaaarrrrg!

My conclusion is that snort under win32 is not standard C?
I still have a dilemma here.

>>>RWT

Fyodor wrote:

Dr. Richard W. Tibbs <ccamp () oakcitysolutions com> spoke:


Kind people:  Thanks for all the help up to this point.
I have a decent compile of the socket code now.
I am now having a problem with snprintf.
There seems to be no definition of the function on Win2K.
If I comment out the
#define HAVE_SNPRINTF = 1



line in config.h,
then compiling snprintf.c results in all kinds of errors concerning some
kind of defines or typedefs named va_dcl, va_alist and such.

Any ideas?



we ship an implementation of snprintf() which is based on the one
shipped with sendmail. If your platform doesn't have snprintf() within
libc configure should figure that out and enable it...

as for building errors, guess there could be some portability problems,
can we see the errors, maybe we could give you hints as what has to be
changed...


/* $Id: snprintf.c,v 1.9 2001/02/07 12:37:12 fygrave Exp $ */
/*
** Copyright (C) 1998,1999,2000,2001 Martin Roesch <roesch () clark net>
**
** This program is free software; you can redistribute it and/or modify
** it under the terms of the GNU General Public License as published by
** the Free Software Foundation; either version 2 of the License, or
** (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU General Public License for more details.
**
** You should have received a copy of the GNU General Public License
** along with this program; if not, write to the Free Software
** Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
*/

/*
** This file contains various routines which we shamelessly steal from other
** opensource products :-P (I love code reuseability idea) 
**                      fygrave () tigerteam net
*/

#include "config.h"
#ifndef HAVE_SNPRINTF
    #include "snprintf.h"

/* snprintf() and all supporting routines were taken from sendmail, hence the 
 * copyleft message 
 */

/*
 * Copyright (c) 1998 Sendmail, Inc.  All rights reserved.
 * Copyright (c) 1997 Eric P. Allman.  All rights reserved.
 * Copyright (c) 1988, 1993
 *      The Regents of the University of California.  All rights reserved.
 *
 * By using this file, you agree to the terms and conditions set
 * forth in the LICENSE file which can be found at the top level of
 * the sendmail distribution.
 *
 */

/*
**  SNPRINTF, VSNPRINT -- counted versions of printf
**
**      These versions have been grabbed off the net.  They have been
**      cleaned up to compile properly and support for .precision and
**      %lx has been added.
*/

/**************************************************************
 * Original:
 * Patrick Powell Tue Apr 11 09:48:21 PDT 1995
 * A bombproof version of doprnt (sm_dopr) included.
 * Sigh.  This sort of thing is always nasty do deal with.  Note that
 * the version here does not include floating point...
 *
 * snprintf() is used instead of sprintf() as it does limit checks
 * for string length.  This covers a nasty loophole.
 *
 * The other functions are there to prevent NULL pointers from
 * causing nast effects.
 **************************************************************/

void    sm_dopr();
char    *DoprEnd;
int SnprfOverflow;

    #ifndef HAVE_SNPRINTF

/* VARARGS3 */
int
        #ifdef __STDC__
snprintf(char *str, size_t count, const char *fmt, ...)
        #else
snprintf(str, count, fmt, va_alist)
char *str;
size_t count;
const char *fmt;
va_dcl
        #endif
{
    int len;
    VA_LOCAL_DECL

    VA_START(fmt);
    len = vsnprintf(str, count, fmt, ap);
    VA_END;
    return len;
}


        #ifndef luna2
#ifndef HAVE_VSNPRINTF
                
int
vsnprintf(str, count, fmt, args)
char *str;
size_t count;
const char *fmt;
va_list args;
{
    str[0] = 0;
    DoprEnd = str + count - 1;
    SnprfOverflow = 0;
    sm_dopr( str, fmt, args );
    if(count > 0)
        DoprEnd[0] = 0;
    if(SnprfOverflow && tTd(57, 2))
        printf("\nvsnprintf overflow, len = %ld, str = %s",
               (long) count, shortenstring(str, MAXSHORTSTR));
    return strlen((const char *)str);
}

#endif /* !HAVE_VSNPRINTF */
        
        #endif /* !luna2 */
    #endif /* !HASSNPRINTF */

/*
 * sm_dopr(): poor man's version of doprintf
 */

void fmtstr __P((char *value, int ljust, int len, int zpad, int maxwidth));
void fmtnum __P((long value, int base, int dosign, int ljust, int len, int zpad));
void dostr __P(( char * , int ));
char *output;
void dopr_outch __P(( int c ));
int SyslogErrno;

void
sm_dopr( buffer, format, args )
char *buffer;
const char *format;
va_list args;
{
    int ch;
    long value;
    int longflag  = 0;
    int pointflag = 0;
    int maxwidth  = 0;
    char *strvalue;
    int ljust;
    int len;
    int zpad;
#if !HAVE_STRERROR && !defined(ERRLIST_PREDEFINED)
    extern char *sys_errlist[];
    extern int sys_nerr;
#endif


    output = buffer;
    while((ch = *format++) != '\0')
    {
        switch(ch)
        {
            case '%':
                ljust = len = zpad = maxwidth = 0;
                longflag = pointflag = 0;
                nextch:
                ch = *format++;
                switch(ch)
                {
                    case 0:
                        dostr( "**end of format**" , 0);
                        return;
                    case '-': ljust = 1; goto nextch;
                    case '0': /* set zero padding if len not set */
                        if(len==0 && !pointflag) zpad = '0';
                    case '1':
                    case '2':
                    case '3':
                    case '4':
                    case '5':
                    case '6':
                    case '7':
                    case '8':
                    case '9':
                        if(pointflag)
                            maxwidth = maxwidth*10 + ch - '0';
                        else
                            len = len*10 + ch - '0';
                        goto nextch;
                    case '*': 
                        if(pointflag)
                            maxwidth = va_arg( args, int );
                        else
                            len = va_arg( args, int );
                        goto nextch;
                    case '.': pointflag = 1; goto nextch;
                    case 'l': longflag = 1; goto nextch;
                    case 'u':
                    case 'U':
                        /*fmtnum(value,base,dosign,ljust,len,zpad) */
                        if(longflag)
                        {
                            value = va_arg( args, long );
                        }
                        else
                        {
                            value = va_arg( args, int );
                        }
                        fmtnum( value, 10,0, ljust, len, zpad ); break;
                    case 'o':
                    case 'O':
                        /*fmtnum(value,base,dosign,ljust,len,zpad) */
                        if(longflag)
                        {
                            value = va_arg( args, long );
                        }
                        else
                        {
                            value = va_arg( args, int );
                        }
                        fmtnum( value, 8,0, ljust, len, zpad ); break;
                    case 'd':
                    case 'D':
                        if(longflag)
                        {
                            value = va_arg( args, long );
                        }
                        else
                        {
                            value = va_arg( args, int );
                        }
                        fmtnum( value, 10,1, ljust, len, zpad ); break;
                    case 'x':
                        if(longflag)
                        {
                            value = va_arg( args, long );
                        }
                        else
                        {
                            value = va_arg( args, int );
                        }
                        fmtnum( value, 16,0, ljust, len, zpad ); break;
                    case 'X':
                        if(longflag)
                        {
                            value = va_arg( args, long );
                        }
                        else
                        {
                            value = va_arg( args, int );
                        }
                        fmtnum( value,-16,0, ljust, len, zpad ); break;
                    case 's':
                        strvalue = va_arg( args, char *);
                        if(maxwidth > 0 || !pointflag)
                        {
                            if(pointflag && len > maxwidth)
                                len = maxwidth; /* Adjust padding */
                            fmtstr( strvalue,ljust,len,zpad, maxwidth);
                        }
                        break;
                    case 'c':
                        ch = va_arg( args, int );
                        dopr_outch( ch ); break;
                    case 'm':
#if HAVE_STRERROR 
                        dostr(strerror(SyslogErrno), 0);
#else
                        if(SyslogErrno < 0 || SyslogErrno >= sys_nerr)
                        {
                            dostr("Error ", 0);
                            fmtnum(SyslogErrno, 10, 0, 0, 0, 0);
                        }
                        else
                            dostr((char *)sys_errlist[SyslogErrno], 0);
#endif
                        break;

                    case '%': dopr_outch( ch ); continue;
                    default:
                        dostr(  "???????" , 0);
                }
                break;
            default:
                dopr_outch( ch );
                break;
        }
    }
    *output = 0;
}

void
fmtstr(  value, ljust, len, zpad, maxwidth )
char *value;
int ljust, len, zpad, maxwidth;
{
    int padlen, strlen;     /* amount to pad */

    if(value == 0)
    {
        value = "<NULL>";
    }
    for(strlen = 0; value[strlen]; ++ strlen); /* strlen */
    if(strlen > maxwidth && maxwidth)
        strlen = maxwidth;
    padlen = len - strlen;
    if(padlen < 0) padlen = 0;
    if(ljust) padlen = -padlen;
    while(padlen > 0)
    {
        dopr_outch( ' ' );
        --padlen;
    }
    dostr( value, maxwidth );
    while(padlen < 0)
    {
        dopr_outch( ' ' );
        ++padlen;
    }
}

void
fmtnum(  value, base, dosign, ljust, len, zpad )
long value;
int base, dosign, ljust, len, zpad;
{
    int signvalue = 0;
    unsigned long uvalue;
    char convert[20];
    int place = 0;
    int padlen = 0; /* amount to pad */
    int caps = 0;

    /* DEBUGP(("value 0x%x, base %d, dosign %d, ljust %d, len %d, zpad %d\n",
        value, base, dosign, ljust, len, zpad )); */
    uvalue = value;
    if(dosign)
    {
        if(value < 0)
        {
            signvalue = '-';
            uvalue = -value;
        }
    }
    if(base < 0)
    {
        caps = 1;
        base = -base;
    }
    do
    {
        convert[place++] =
        (caps? "0123456789ABCDEF":"0123456789abcdef")
        [uvalue % (unsigned)base  ];
        uvalue = (uvalue / (unsigned)base );
    }while(uvalue);
    convert[place] = 0;
    padlen = len - place;
    if(padlen < 0) padlen = 0;
    if(ljust) padlen = -padlen;
    /* DEBUGP(( "str '%s', place %d, sign %c, padlen %d\n",
        convert,place,signvalue,padlen)); */
    if(zpad && padlen > 0)
    {
        if(signvalue)
        {
            dopr_outch( signvalue );
            --padlen;
            signvalue = 0;
        }
        while(padlen > 0)
        {
            dopr_outch( zpad );
            --padlen;
        }
    }
    while(padlen > 0)
    {
        dopr_outch( ' ' );
        --padlen;
    }
    if(signvalue) dopr_outch( signvalue );
    while(place > 0) dopr_outch( convert[--place] );
    while(padlen < 0)
    {
        dopr_outch( ' ' );
        ++padlen;
    }
}

void
dostr( str , cut)
char *str;
int cut;
{
    if(cut)
    {
        while(*str && cut-- > 0) dopr_outch(*str++);
    }
    else
    {
        while(*str) dopr_outch(*str++);
    }
}

void
dopr_outch( c )
int c;
{
#if 0
    if(iscntrl(c) && c != '\n' && c != '\t')
    {
        c = '@' + (c & 0x1F);
        if(DoprEnd == 0 || output < DoprEnd)
            *output++ = '^';
    }
#endif
    if(DoprEnd == 0 || output < DoprEnd)
        *output++ = c;
    else
        SnprfOverflow++;
}

/*
**  QUAD_TO_STRING -- Convert a quad type to a string.
**
**      Convert a quad type to a string.  This must be done
**      separately as %lld/%qd are not supported by snprint()
**      and adding support would slow down systems which only
**      emulate the data type.
**
**      Parameters:
**              value -- number to convert to a string.
**
**      Returns:
**              pointer to a string.
*/

char *
quad_to_string(value)
QUAD_T value;
{
    char *fmtstr;
    static char buf[64];

    /*
    **  Use sprintf() instead of snprintf() since snprintf()
    **  does not support %qu or %llu.  The buffer is large enough
    **  to hold the string so there is no danger of buffer
    **  overflow.
    */

#if NEED_PERCENTQ
    fmtstr = "%qu";
#else
    fmtstr = "%llu";
#endif
    sprintf(buf, fmtstr, value);
    return buf;
}
/*
**  SHORTENSTRING -- return short version of a string
**
**      If the string is already short, just return it.  If it is too
**      long, return the head and tail of the string.
**
**      Parameters:
**              s -- the string to shorten.
**              m -- the max length of the string.
**
**      Returns:
**              Either s or a short version of s.
*/

char *
shortenstring(s, m)
register const char *s;
int m;
{
    int l;
    static char buf[MAXSHORTSTR + 1];

    l = strlen(s);
    if(l < m)
        return(char *) s;
    if(m > MAXSHORTSTR)
        m = MAXSHORTSTR;
    else if(m < 10)
    {
        if(m < 5)
        {
            strncpy(buf, s, m);
            buf[m] = '\0';
            return buf;
        }
        strncpy(buf, s, m - 3);
        strcpy(buf + m - 3, "...");
        return buf;
    }
    m = (m - 3) / 2;
    strncpy(buf, s, m);
    strcpy(buf + m, "...");
    strcpy(buf + m + 3, s + l - m);
    return buf;
}

#endif
#ifndef __SNPRINTF_H__
#define __SNPRINTF_H__

#ifndef HAVE_SNPRINTF

#include <stdio.h>
#include "config.h"
#include <sys/types.h>
#include <string.h>
//#include <varargs.h>
#include <winsock.h>

#ifdef __STDC__

#include <stdarg.h>

# define VA_LOCAL_DECL  va_list ap;
# define VA_START(f)    va_start(ap, f)
# define VA_END         va_end(ap)

#else /* __STDC__ */

#ifndef WIN32
#include <varargs.h>
#endif  /* WIN32 */

# define VA_LOCAL_DECL  va_list ap;
# define VA_START(f)    va_start(ap)
# define VA_END         va_end(ap)

#endif /* __STDC__ */

#ifndef __P
#include "cdefs.h"
#endif /* ! __P */

#ifndef QUAD_T
# define QUAD_T unsigned long
#endif /* ! QUAD_T */



#define tTd(flag, level)        (tTdvect[flag] >= (u_char)level)
#define MAXSHORTSTR  203             /* max short string length */

unsigned char   tTdvect[100];   /* trace vector YADDA */

int snprintf(char *, size_t , const char *, ...);
#ifndef HAVE_VSNPRINTF
int vsnprintf(char *, size_t, const char *, va_list);
#endif /* HAVE_VSNPRINTF */
char *shortenstring(register const char *, int);


#endif /* HAVE_SNPRINTF */
#endif /* __SNPRINTF_H__ */
/* config.h.  Generated automatically by configure.  */

/* config.h.in.  Generated automatically from configure.in by autoheader.  */



/* Define if on AIX 3.

   System headers sometimes define this.

   We just want to avoid a redefinition error message.  */

#ifndef _ALL_SOURCE

/* #undef _ALL_SOURCE */

#endif



/* Define if you have the ANSI C header files.  */

/* #undef STDC_HEADERS */



/* Define if your processor stores words with the most significant

   byte first (like Motorola and SPARC, unlike Intel and VAX).  */

#define WORDS_LITTLEENDIAN 1



/* $Id: config.h,v 1.1 2001/08/07 13:15:12 fygrave Exp $ */

#define PACKAGE "snort"

/* #undef BSDI */

/* #undef FREEBSD */

/* #undef IRIX */

/* #undef AIX */

/* #undef LINUX */

/* #undef OPENBSD */

#define WIN32 1

/* #undef PCAP_TIMEOUT_IGNORED */

/* #undef SOLARIS */

/* #undef STUPID_SOLARIS_CHECKSUM_BUG */

/* #undef SUNOS */

/* #undef HPUX */

/* #undef OSF1 */

/* #undef WORDS_MUSTALIGN */

/* #undef ENABLE_POSTGRESQL */

/* #undef u_int8_t */

/* #undef u_int16_t */

/* #undef u_int32_t */

/* #undef NEED_DECL_PRINTF */

/* #undef NEED_DECL_FPRINTF */

/* #undef NEED_DECL_SYSLOG */

/* #undef NEED_DECL_PUTS */

/* #undef NEED_DECL_PUTC */

/* #undef NEED_DECL_FPUTS */

/* #undef NEED_DECL_FPUTC */

/* #undef NEED_DECL_FOPEN */

/* #undef NEED_DECL_FCLOSE */

/* #undef NEED_DECL_FWRITE */

/* #undef NEED_DECL_FFLUSH */

/* #undef NEED_DECL_GETOPT */

/* #undef NEED_DECL_BZERO */

/* #undef NEED_DECL_BCOPY */

/* #undef NEED_DECL_MEMSET */

/* #undef NEED_DECL_STRTOL */

/* #undef NEED_DECL_STRCASECMP */

/* #undef NEED_DECL_STRNCASECMP */

/* #undef NEED_DECL_STRERROR */

/* #undef NEED_DECL_PERROR */

/* #undef NEED_DECL_SOCKET */

/* #undef NEED_DECL_SENDTO */

/* #undef NEED_DECL_VSNPRINTF */

/* #undef NEED_DECL_STRTOUL */

#define ERRLIST_PREDEFINED 1



/* Define if you have the snprintf function.  */

// #define HAVE_SNPRINTF 1 //YADDA
//#define snprintf _snprintf
//#define vsnprintf _vsnprintf


/* Define if you have the strerror function.  */

#define HAVE_STRERROR 1



/* Define if you have the strlcat function.  */

/* #undef HAVE_STRLCAT */



/* Define if you have the strlcpy function.  */

/* #undef HAVE_STRLCPY */
//#define HAVE_STRLCPY 1



/* Define if you have the strtoul function.  */

/* #undef HAVE_STRTOUL */



/* Define if you have the vsnprintf function.  */

/* #undef HAVE_VSNPRINTF */



/* Define if you have the <paths.h> header file.  */

/* #undef HAVE_PATHS_H */



/* Define if you have the <stdlib.h> header file.  */

#define HAVE_STDLIB_H 1



/* Define if you have the <string.h> header file.  */

#define HAVE_STRING_H 1



/* Define if you have the <strings.h> header file.  */

/* #undef HAVE_STRINGS_H */



/* Define if you have the <sys/sockio.h> header file.  */

/* #undef HAVE_SYS_SOCKIO_H */



/* Define if you have the <unistd.h> header file.  */

#define HAVE_UNISTD_H 1



/* Define if you have the m library (-lm).  */

/* #undef HAVE_LIBM */



/* Define if you have the nsl library (-lnsl).  */

/* #undef HAVE_LIBNSL */



/* Define if you have the pcap library (-lpcap).  */

#define HAVE_LIBPCAP 1



/* Define if you have the socket library (-lsocket).  */

/* #undef HAVE_LIBSOCKET */



/* Define if you have the z library (-lz).  */

/* #undef HAVE_LIBZ */



/* Name of package */

#define PACKAGE "snort"



/* Version number of package */

#ifdef ENABLE_MYSQL

        #define VERSION "1.8-MySQL-WIN32"

#else

    #ifdef ENABLE_MSSQL

            #define VERSION "1.8-MSSQL-WIN32"

    #else

            #ifdef ENABLE_RESPONSE

                    #define VERSION "1.8-FlexRESP-WIN32"

            #else

                    #define VERSION "1.8-WIN32"

            #endif

    #endif

#endif



/* you have this cuz autoheader is dumb */

/* #undef NEED_DECL_ */


Current thread: