Skip to content
Scan many patterns at once

Scan many patterns at once

Scan many patterns at once

Ask several patterns together over one read of the input, each match reported under the pattern that made it. A set of twenty costs one lex rather than twenty (pattern sets).

In a pattern file a let NAME = PATTERN line is a member under its name and a bare pattern line a member under its line number:

$ cat rules.trex
# what a line may hold
let host = \I:addr
let mail = \E:e
\N{>=100}
$ cat notes.txt
from 10.0.0.1 at 500 to bob@x.com
x = 7 and 10.0.0.2

Every match, under its member

$ trex scan --patterns rules.trex notes.txt
[5..13] "10.0.0.1"  captures: addr="10.0.0.1"  pattern: host
[17..20] "500"  pattern: 4
[24..33] "bob@x.com"  captures: e="bob@x.com"  pattern: mail
[44..52] "10.0.0.2"  captures: addr="10.0.0.2"  pattern: host

Which patterns match a line

A set also answers which of its members match at all, without listing the matches:

let set = trex::PatternSet::new(vec![
    trex::parse(r"\E").expect("valid"),
    trex::parse(r"\I").expect("valid"),
    trex::parse(r"\U").expect("valid"),
]);
assert_eq!(set.matches(b"from 10.0.0.1 to bob@x.com"), [0, 1]);

--single-match reports each member’s first match and no more, and --all, --any and --none keep the records holding a combination of members.