# Hui Lin\_Merging DNP3 analyzer

**URL:** <https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377>\
**Category:** Development\
**Tags:** development\
**Created:** [July 30, 2012, 4:46pm UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377 "2012-07-30T16:46:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hui\_Lin](https://avatars.discourse-cdn.com/v4/letter/h/13edae/32.png) [@Hui\_Lin](https://community.zeek.org/u/Hui_Lin)\
**Post date:** [July 30, 2012, 4:46pm UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/1 "2012-07-30T16:46:33Z")

</div>

Hi, Robin,

I think the DNP3 analyzer is ready to be merged. The only concern now is that I still left very little Debug codes. Do u want me to remove them all?

I don’t have a tracker account. Can you create a ticket for me and give me a basic idea how to do the merging?

Best,

Hui

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [July 31, 2012, 4:51am UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/2 "2012-07-31T04:51:54Z")

</div>

> I think the DNP3 analyzer is ready to be merged. The only concern now is  
> that I still left very little Debug codes. Do u want me to remove them all?

Yes, generally, that should probably be removed. Take a look at the  
DBG\_LOG macro though (if you aren't already using it), it it's a good  
way to keep some debugging information in.

> I don't have a tracker account. Can you create a ticket for me and give me  
> a basic idea how to do the merging?

I'll do the merging; once you're ready just create a ticket and set it  
to merge request. I'll create you an account on the tracker tomorrow.

However, as this is something for Bro 2.2, it'll take a bit until I'll  
do the merge; we're in feature freeze mode right now. 🙂

Robin

---

<div class="post-metadata">

**Author:** ![Hui\_Lin](https://avatars.discourse-cdn.com/v4/letter/h/13edae/32.png) [@Hui\_Lin](https://community.zeek.org/u/Hui_Lin)\
**Post date:** [August 1, 2012, 3:50pm UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/3 "2012-08-01T15:50:38Z")

</div>

Hi, Robin,

Another two questions:

1. I have some customization codes in DNP3.cc. I simply printf the error message in this file (such as memory allocation failed). For those error messages, do I have to include them in log files ?

2. where should I put several sample policy files?

Best,

Hui

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [August 1, 2012, 10:49pm UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/4 "2012-08-01T22:49:52Z")

</div>

Hui, what's the branch your most recent code is in?

> 1. I have some customization codes in DNP3.cc. I simply printf the error  
> message in this file (such as memory allocation failed). For those error  
> messages, do I have to include them in log files ?

Yes, you should use the reporter for errors. For memory in particular,  
you don't need to check if you use "new" (because a handler for that  
is installed), and there's safe\_malloc etc. for the C-style functions  
(see util.h)

> 2. where should I put several sample policy files?

Put them under scripts/policy/protocols/ for now, we can later see if  
that's something we want to ship.

Robin

---

<div class="post-metadata">

**Author:** ![Hui\_Lin](https://avatars.discourse-cdn.com/v4/letter/h/13edae/32.png) [@Hui\_Lin](https://community.zeek.org/u/Hui_Lin)\
**Post date:** [August 2, 2012, 12:21am UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/5 "2012-08-02T00:21:08Z")

</div>

> Hui, what’s the branch your most recent code is in?

I am working on the branch topic/hui/powergrid3  
But I have not pushed my recent modifications.

> > 1. I have some customization codes in DNP3.cc. I simply printf the error  
> > message in this file (such as memory allocation failed). For those error  
> > messages, do I have to include them in log files ?
> 
> Yes, you should use the reporter for errors. For memory in particular,  
> you don’t need to check if you use “new” (because a handler for that  
> is installed), and there’s safe\_malloc etc. for the C-style functions  
> (see util.h)

Do we have any macro for reporting errors? There are some other errors in addition to memory allocation.

I may need some time to replace that old malloc functiions with the safe ones.

> > 1. where should I put several sample policy files?
> 
> Put them under scripts/policy/protocols/ for now, we can later see if  
> that’s something we want to ship.

OK.  
I also plan to add little explanations on those policies.

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [August 2, 2012, 3:47pm UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/6 "2012-08-02T15:47:12Z")

</div>

You can use the reporter, see reporter.h; in particular its Weird  
methods if it's protocol weirdness.

Robin

---

<div class="post-metadata">

**Author:** ![Hui\_Lin](https://avatars.discourse-cdn.com/v4/letter/h/13edae/32.png) [@Hui\_Lin](https://community.zeek.org/u/Hui_Lin)\
**Post date:** [August 2, 2012, 3:49pm UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/7 "2012-08-02T15:49:34Z")

</div>

Just found out by taking look at FTP analyzer. 🙂

I am using reporter-\>Warnings though.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/hui-lin-merging-dnp3-analyzer/2377/8 "2022-05-06T15:40:27Z")

</div>


