detect/prefilter: speed up setup

If the global detect.prefilter.default setting is not "auto", it is
wasteful to run each prefilter setup routine. This patch tracks which
of the engines have been explicitly enabled in the rules and only
runs those.
pull/3451/head
Victor Julien 7 years ago
parent 4f1befd217
commit 7fca17639d

@ -348,11 +348,16 @@ void PrefilterSetupRuleGroup(DetectEngineCtx *de_ctx, SigGroupHead *sgh)
{ {
BUG_ON(PatternMatchPrepareGroup(de_ctx, sgh) != 0); BUG_ON(PatternMatchPrepareGroup(de_ctx, sgh) != 0);
/* set up engines if needed - independent of 'detect.prefilter.default' /* set up engines if needed - when prefilter is set to auto we run
* setting as the prefilter keyword may have enabled individual sigs */ * all engines, otherwise only those that have been forced by the
* prefilter keyword. */
const enum DetectEnginePrefilterSetting setting = de_ctx->prefilter_setting;
for (int i = 0; i < DETECT_TBLSIZE; i++) for (int i = 0; i < DETECT_TBLSIZE; i++)
{ {
if (sigmatch_table[i].SetupPrefilter != NULL) { if (sigmatch_table[i].SetupPrefilter != NULL &&
(setting == DETECT_PREFILTER_AUTO ||
de_ctx->sm_types_prefilter[i]))
{
sigmatch_table[i].SetupPrefilter(de_ctx, sgh); sigmatch_table[i].SetupPrefilter(de_ctx, sgh);
} }
} }

@ -94,6 +94,9 @@ static int DetectPrefilterSetup (DetectEngineCtx *de_ctx, Signature *s, const ch
cd->flags |= DETECT_CONTENT_FAST_PATTERN; cd->flags |= DETECT_CONTENT_FAST_PATTERN;
} else { } else {
s->flags |= SIG_FLAG_PREFILTER; s->flags |= SIG_FLAG_PREFILTER;
/* make sure setup function runs for this type. */
de_ctx->sm_types_prefilter[sm->type] = true;
} }
SCReturnInt(0); SCReturnInt(0);

@ -892,6 +892,11 @@ typedef struct DetectEngineCtx_ {
/** signatures stats */ /** signatures stats */
SigFileLoaderStat sig_stat; SigFileLoaderStat sig_stat;
/** per keyword flag indicating if a prefilter has been
* set for it. If true, the setup function will have to
* run. */
bool sm_types_prefilter[DETECT_TBLSIZE];
} DetectEngineCtx; } DetectEngineCtx;
/* Engine groups profiles (low, medium, high, custom) */ /* Engine groups profiles (low, medium, high, custom) */

Loading…
Cancel
Save