# Compile Errors in Linux

**URL:** <https://community.zeek.org/t/compile-errors-in-linux/15>\
**Category:** Zeek\
**Created:** [September 14, 1998, 8:12pm UTC](https://community.zeek.org/t/compile-errors-in-linux/15 "1998-09-14T20:12:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Don\_Miller](https://avatars.discourse-cdn.com/v4/letter/d/53a042/32.png) [@Don\_Miller](https://community.zeek.org/u/Don_Miller)\
**Post date:** [September 14, 1998, 8:12pm UTC](https://community.zeek.org/t/compile-errors-in-linux/15/1 "1998-09-14T20:12:48Z")

</div>

Group,

I am using linux version 5.2 to compile the bro software. I am having  
problems with the DNS.cc source code. The error has to do with the  
"void DNS\_Mgr::AddResult function.

There is a message that says there is a syntax error before the ( on  
line 688. Has anyone seen this?

Don Miller

---

<div class="post-metadata">

**Author:** ![Zach\_Brown](https://avatars.discourse-cdn.com/v4/letter/z/91b2a8/32.png) [@Zach\_Brown](https://community.zeek.org/u/Zach_Brown)\
**Post date:** [September 14, 1998, 8:47pm UTC](https://community.zeek.org/t/compile-errors-in-linux/15/2 "1998-09-14T20:47:21Z")

</div>

It helps if you give us the output of whatever is giving you the error,  
and linux 5.2? whats that? 🙂

it seems there is a collision between a member of nb\_dns\_result and  
\<netdb.h\>.. the attached patch is an ugly nasty hack that gets it to  
compile.. then you get to run into collisions in TCP.h..

I don't have time now, but maybe later I'll try to get this to compile  
under glibc and linux.

-- zach

--- DNS.cc.old Mon Sep 14 13:41:33 1998  
+++ DNS.cc Mon Sep 14 13:42:10 1998  
@@ -22,6 +22,7 @@  
#include \<stdlib.h\>  
#include \<errno.h\>  
#include \<netdb.h\>  
+#undef h\_errno /\* collides w/ member in struct in nb\_dns.h \*/  
#include \<sys/types.h\>  
#include \<sys/time.h\>  
#include \<sys/socket.h\>  
--- nb\_dns.c.old Mon Sep 14 13:41:40 1998  
+++ nb\_dns.c Mon Sep 14 13:42:01 1998  
@@ -43,6 +43,7 @@  
#include \<errno.h\>  
#include \<memory.h\>  
#include \<netdb.h\>  
+#undef h\_errno /\* collides w/ member in struct in nb\_dns.h \*/  
#include \<resolv.h\>  
#include \<stdio.h\>  
#include \<stdlib.h\>

---

<div class="post-metadata">

**Author:** ![Olav\_Kolbu](https://avatars.discourse-cdn.com/v4/letter/o/ad7895/32.png) [@Olav\_Kolbu](https://community.zeek.org/u/Olav_Kolbu)\
**Post date:** [September 14, 1998, 10:31pm UTC](https://community.zeek.org/t/compile-errors-in-linux/15/3 "1998-09-14T22:31:46Z")

</div>

Just gave it a try on my RedHat 5.1 box, and there are a whole number of  
things you have to fix to get it to compile properly. Not for the faint of  
heart here... Here is a quick list for the impatient, not sure what  
approach the maintainer wants to take regarding Linux support so I'm  
leaving out the actual diffs (these are too nasty for production anyway  
;-).

0. The h\_errno has to be #undef'ed sometime after including 'netdb.h' in  
DNS.cc. This is because netdb.h re-#defines it to something unsuitable.  
Defining '\_LIBC', e.g. adding -D\_LIBC to your CFLAGS line in Makefile  
gives the same effect.

1. Some values in the enumeration 'EndpointState' (various source files)  
conflicts with already enumerated types in /usr/include/linux/tcp.h Rename  
the enumerated values that conflict (and do the same in the source files),  
or comment out the whole typedef from TCP.h. Commenting out will force you  
to change 'EndpointState' to say 'unsigned char' in the relevant places in  
the source, and you also need to explicitly #define TCP\_INACTIVE,  
TCP\_PARTIAL, TCP\_CLOSED and TCP\_RESET to some unique values above 11  
(thats where the relevant system ones stop on my box).

2. \_All\_ the members of the tcphdr and udphdr structs have different names  
under Linux compared to what's expected in the source. Which basically  
means you have to edit a lot of files to fix this. The relevant system  
definitions are in /usr/include/linux/{tcp,udp}.h and look like this  
(these dumps primarily for the maintainer so he can have a look at doing  
linux support):

struct tcphdr {  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u16 source;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u16 dest;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u32 seq;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u32 ack\_seq;  
#if defined(\_\_LITTLE\_ENDIAN\_BITFIELD)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u16 res1:4,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;doff:4,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;fin:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;syn:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rst:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;psh:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ack:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;urg:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;res2:2;  
#elif defined(\_\_BIG\_ENDIAN\_BITFIELD)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u16 doff:4,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;res1:4,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;res2:2,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;urg:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ack:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;psh:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rst:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;syn:1,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;fin:1;  
#else  
#error "Adjust your \<asm/byteorder.h\> defines"  
#endif  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u16 window;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u16 check;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\_\_u16 urg\_ptr;  
};

struct udphdr {  
&nbsp;&nbsp;unsigned short source;  
&nbsp;&nbsp;unsigned short dest;  
&nbsp;&nbsp;unsigned short len;  
&nbsp;&nbsp;unsigned short check;  
};

Compare this to what say Solaris:

struct tcphdr {  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short th\_sport; /\* source port \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short th\_dport; /\* destination port \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;tcp\_seq th\_seq; /\* sequence number \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;tcp\_seq th\_ack; /\* acknowledgement number \*/  
#ifdef \_BIT\_FIELDS\_LTOH  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_int th\_x2:4, /\* (unused) \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;th\_off:4; /\* data offset \*/  
#else  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_int th\_off:4, /\* data offset \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;th\_x2:4; /\* (unused) \*/  
#endif  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_char th\_flags;  
#define TH\_FIN 0x01  
#define TH\_SYN 0x02  
#define TH\_RST 0x04  
#define TH\_PUSH 0x08  
#define TH\_ACK 0x10  
#define TH\_URG 0x20  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short th\_win; /\* window \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short th\_sum; /\* checksum \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short th\_urp; /\* urgent pointer \*/  
};

struct udphdr {  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short uh\_sport; /\* source port \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short uh\_dport; /\* destination port \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;short uh\_ulen; /\* udp length \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u\_short uh\_sum; /\* udp checksum \*/  
};

Note specifically the change from a single flags member that you typically  
'tp-\>flags & TH\_URG' to 'tp-\>urg'.

The quick list of changes:

TCP:

th\_off -\> doff  
th\_sport -\> source  
th\_dport -\> dest

th\_flags & TH\_SYN -\> syn  
th\_flags & TH\_ACK -\> ack  
etc etc just lowercase the #define and remove 'th\_' on the various flags.

th\_seq -\> seq  
th\_ack -\> ack\_seq

UDP:

uh\_sum -\> check  
uh\_ulen -\> len  
uh\_sport -\> source  
uh\_dport -\> dest

That should be it. I haven't done any tests at all, so the fixes above may  
or may not give you a bro that actually works. But at least it runs and it  
does produce what appears to be useful output.

Note that I also had to change line 89 in policy/hot.bro from

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[external\_routers, external\_routers, bgp],  
to  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[external\_routers, external\_routers, 179/tcp],

This is because (I presume, haven't read the source for the parser) bgp  
isn't defined in your average Linux /etc/services file.

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;OK

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/compile-errors-in-linux/15/4 "2022-05-06T15:36:02Z")

</div>


