# Hui Lin\_Where is Binpac warning for Bro 2.0

**URL:** <https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150>\
**Category:** Development\
**Tags:** development\
**Created:** [December 9, 2011, 10:40pm UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150 "2011-12-09T22:40:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hui\_Lin](https://avatars.discourse-cdn.com/v4/letter/h/13edae/32.png) [@Hui\_Lin](https://community.zeek.org/u/Hui_Lin)\
**Post date:** [December 9, 2011, 10:40pm UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/1 "2011-12-09T22:40:10Z")

</div>

I try another thing.

I just type this in my binpac code

&check(abcdefg)

right after a variable, and my binpac code is successfully compiled and linked. So &check is ignored in current Bro package, is it?

That is a really bad news for me. Then I have to spend much much more time to rewrite &check condition into Bro’s script which is sometimes hard to do.

Is there any future plan to activate &check statement again?

Best,

Hui

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [December 10, 2011, 1:06am UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/2 "2011-12-10T01:06:39Z")

</div>

Are you sure that this was working previously? I don't think that the &check attribute has ever actually been implemented in binpac (at least the functionality of the &check statement.

.Seth

---

<div class="post-metadata">

**Author:** ![Hui\_Lin](https://avatars.discourse-cdn.com/v4/letter/h/13edae/32.png) [@Hui\_Lin](https://community.zeek.org/u/Hui_Lin)\
**Post date:** [December 10, 2011, 1:15am UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/3 "2011-12-10T01:15:38Z")

</div>

That is cruel!

I remember that at the very beginning, I saw some exception generated by binpac which is related to some value range.

In this afternoon, I check some cc code generated by binpac code, it seems that Binpac will generate some exception such as out-of-bound, string length and so on. I probably regard them as the exception throwed by &check.

Anyway, the news is cruel to me and I have to put those checks into Bro script.

Does binpac++ will do something like this?

Best,

Hui

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [December 10, 2011, 2:37am UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/4 "2011-12-10T02:37:08Z")

</div>

> Anyway, the news is cruel to me and I have to put those checks into Bro script.

What sort of checks are they? I wouldn't think you'd want to have too many &check conditions within your parser, but I don't know the protocols you're working on.

> Does binpac++ will do something like this?

I don't recall. You'll have to wait for Robin to answer. 🙂

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [December 12, 2011, 9:53am UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/5 "2011-12-12T09:53:26Z")

</div>

Yes, it will eventually. Can you give a few more details on the kind  
of checks you want to do?

Robin

---

<div class="post-metadata">

**Author:** ![Hui\_Lin](https://avatars.discourse-cdn.com/v4/letter/h/13edae/32.png) [@Hui\_Lin](https://community.zeek.org/u/Hui_Lin)\
**Post date:** [December 15, 2011, 10:54pm UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/6 "2011-12-15T22:54:25Z")

</div>

On the current work, I am doing some basic checking. Such as value range. I sometimes add thing like check(0) to some obsolete case.

There is something that is coming to my mind which is not related to my work. Is that possible to have some simple state management in binpac too? Like make it possible for us to define global variable as parsing goes on.

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [December 16, 2011, 1:11am UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/7 "2011-12-16T01:11:41Z")

</div>

Yes, you can do it but it's a bit of a mess since you have to use the c/c++ integration techniques (there are examples of this in many of the existing binpac analyzers like in ssl-protocol.pac). Binpac++ supports this much better since it's a turing complete programming language in itself.

The rule of thumb I've tried to stick to is only store things in the analyzer that are needed to continue parsing the protocol and pass everything else to script land through events.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/hui-lin-where-is-binpac-warning-for-bro-2-0/2150/8 "2022-05-06T15:40:03Z")

</div>


