# Undefined symbol while writing an analyzer

**URL:** <https://community.zeek.org/t/undefined-symbol-while-writing-an-analyzer/4121>\
**Category:** Zeek\
**Created:** [April 21, 2016, 3:46pm UTC](https://community.zeek.org/t/undefined-symbol-while-writing-an-analyzer/4121 "2016-04-21T15:46:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luis\_Martin](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@Luis\_Martin](https://community.zeek.org/u/Luis_Martin)\
**Post date:** [April 21, 2016, 3:46pm UTC](https://community.zeek.org/t/undefined-symbol-while-writing-an-analyzer/4121/1 "2016-04-21T15:46:43Z")

</div>

Hey guys,

I would really appreciate some help on this.

I think I can reduce the source of the problem to two points:

- A namespace problem. I have revised my code and does not find anything wrong. I’ll keep checking
- A linkage problem:

To compile the plugin I followed the instructions of the “Writing Bro Plugins” documentation guide. In the Plugins.cc file instantiated of the Analyzer and included “Myprotocol.h”, which had been previously created with binpac\_Quickstart’s start.py

However the Makefile and configure files were created with the “init-plugin” script. Do you know if I have to modify anything in the Makefile to build a protocol analyzer plugin?

Unfortunately in the “Writing Bro plugins” documentation page, the “Protocol Analyzers” section is empty…

Hope you can help me.

Best reagards!

---

<div class="post-metadata">

**Author:** ![Vlad\_Grigorescu3](https://avatars.discourse-cdn.com/v4/letter/v/dec6dc/32.png) [@Vlad\_Grigorescu3](https://community.zeek.org/u/Vlad_Grigorescu3)\
**Post date:** [April 22, 2016, 4:33pm UTC](https://community.zeek.org/t/undefined-symbol-while-writing-an-analyzer/4121/2 "2016-04-22T16:33:25Z")

</div>

Hi Luis,

binpac\_quickstart has a --plugin option which should set up the skeleton  
in much the same way init-plugin does. Try that, and please let me know  
if you encounter issues with it.

&nbsp;&nbsp;--Vlad

Luis Martin Liras \<[martin.liras@gmail.com](mailto:martin.liras@gmail.com)\> writes:

---

<div class="post-metadata">

**Author:** ![Luis\_Martin](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@Luis\_Martin](https://community.zeek.org/u/Luis_Martin)\
**Post date:** [April 25, 2016, 7:04am UTC](https://community.zeek.org/t/undefined-symbol-while-writing-an-analyzer/4121/3 "2016-04-25T07:04:54Z")

</div>

Thank you for your reply Vlad.

Unfortunately that was not the problem as I've been using this option from the beginning.

The problem was related with the linkage options. I was using the configure and Makefile files that the init-plugin --plugin script was giving me. BUT these 'configure' and 'Makefile' files are prepared for a simple plugin with simple functions. If you need to write an analyzer with thi --plugin option you need to modify the resulting CMakeLists.txt.

This is how it comes:

cmake\_minimum\_required(VERSION 2.8)  
project(Plugin)  
include(BroPlugin)  
bro\_plugin\_begin(MyProt MyProt)  
bro\_plugin\_cc(src/Plugin.cc)  
bro\_plugin\_bif(src/events.bif)  
bro\_plugin\_dist\_files(README CHANGES COPYING VERSION)  
bro\_plugin\_end()

and this is how it must be:

cmake\_minimum\_required(VERSION 2.8)  
project(Plugin)  
include(BroPlugin)  
bro\_plugin\_begin(MyProt MyProt)  
bro\_plugin\_bif(src/types.bif src/events.bif) \<---  
bro\_plugin\_cc(src/Plugin.cc src/MyProt.cc src/MyProt\_pac.cc) \<---  
bro\_plugin\_dist\_files(README CHANGES COPYING VERSION)  
bro\_plugin\_end()

Apart from that, I had to add the different records in the init-bare.bro file and, weird enough, I had to modify the build/src/types.bif.netvar\_h file to add the records I was using, maybe someone can explain me that.

Ah!, and do not reuse a type name that other analyzer is already using... it will give you a segmentation fault.

Now it works fine.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/undefined-symbol-while-writing-an-analyzer/4121/4 "2022-05-06T15:43:37Z")

</div>


