zeek/scripts/base/frameworks
Johanna Amann db6f028003 Add config framework.
The configuration framework consists of three mostly distinct parts:

* option variables
* the config reader
* the script level framework

I will describe the three elements in the following.

Internally, this commit also performs a range of changes to the Input
manager; it marks a lot of functions as const and introduces a new
ValueToVal method (which could in theory replace the already existing
one - it is a bit more powerful).

This also changes SerialTypes to have a subtype for Values, just as
Fields already have it; I think it was mostly an oversight that this was
not introduced from the beginning. This should not necessitate any code
changes for people already using SerialTypes.

option variable
===============

The option keyword allows variables to be specified as run-tine options.
Such variables cannot be changed using normal assignments. Instead, they
can be changed using Option::set. It is possible to "subscribe" to
options and be notified when an option value changes.

Change handlers can also change values before they are applied; this
gives them the opportunity to reject changes. Priorities can be
specified if there are several handlers for one option.

Example script:

option testbool: bool = T;

function option_changed(ID: string, new_value: bool): bool
  {
  print fmt("Value of %s changed from %s to %s", ID, testbool, new_value);
  return new_value;
  }

event bro_init()
  {
  print "Old value", testbool;
  Option::set_change_handler("testbool", option_changed);
  Option::set("testbool", F);
  print "New value", testbool;
  }

config reader
=============

The config reader provides a way to read configuration files back into
Bro. Most importantly it automatically converts values to the correct
types. This is important because it is at least inconvenient (and
sometimes near impossible) to perform the necessary type conversions in
Bro scripts themselves. This is especially true for sets/vectors.

Configuration generally look like this:

[option name][tab/spaces][new variable value]

so, for example:

testaddr 2607:f8b0:4005:801::200e
testinterval 60
testtime 1507321987
test_set a	b	c	d	erdbeerschnitzel

The reader uses the option name to look up the type that variable has in
the Bro core and automatically converts the value to the correct type.

Example script use:

type Idx: record {
  option_name: string;
};

type Val: record {
  option_val: string;
};

global currconfig: table[string] of string = table();

event InputConfig::new_value(name: string, source: string, id: string, value: any)
  {
  print id, value;
  }

event bro_init()
  {
  Input::add_table([$reader=Input::READER_CONFIG, $source="../configfile", $name="configuration", $idx=Idx, $val=Val, $destination=currconfig, $want_record=F]);
  }

Script-level config framework
=============================

The script-level framework ties these two features together and makes
them a bit more convenient to use. Configuration files can simply be
specified by placing them into Config::config_files. The framework also
creates a config.log that shows all value changes that took place.

Usage example:

redef Config::config_files += {configfile};

export {
  option testbool : bool = F;
}

The file is now monitored for changes; when a change occurs the
respective option values are automatically updated and the value change
is written to config.log.
2017-11-29 13:46:59 -08:00
..
analyzer Add README files for most Bro frameworks 2013-10-11 00:19:37 -05:00
broker Fix minor typos in documentation 2016-11-14 09:50:19 -06:00
cluster Add a test for starting a cluster with a logger node 2016-07-15 15:23:49 -05:00
communication Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00
config Add config framework. 2017-11-29 13:46:59 -08:00
control Add README files for most Bro frameworks 2013-10-11 00:19:37 -05:00
dpd Add an argument to "disable_analyzer" to not do a reporter message by default. 2016-08-09 10:22:31 -04:00
files Tiny mime-type fix from Dan Caselden. 2017-02-14 07:21:00 -08:00
input Add config framework. 2017-11-29 13:46:59 -08:00
intel problem: broctl can trigger intel reporter error 2017-09-28 09:34:38 -04:00
logging Fix ascii writer to not discard a ".gz" file extension 2017-08-25 15:39:12 -05:00
netcontrol NetControl: small rule_error changes 2017-04-07 10:26:34 -07:00
notice add a max_line_length flag to ContentLine_Analyzer 2017-11-03 16:25:26 -04:00
openflow Fix various typos in the openflow framework docs 2016-11-09 14:29:03 -06:00
packet-filter Fix a number of documentation building errors 2016-06-27 12:41:40 -07:00
reporter Merge remote-tracking branch 'origin/topic/johanna/bit-1181' 2016-07-26 14:52:27 -07:00
signatures Log::write in signature framework was missing ts 2015-03-25 12:01:09 -07:00
software Several fixes and improvements for software version parsing. 2017-07-13 02:22:03 -04:00
sumstats Track outstanding_global_views updates by uid 2016-07-29 12:54:20 -04:00
tunnels Allow logging filters to inherit default path from stream. 2015-03-19 14:49:55 -05:00