Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-bpsec-defaultsc.c
Line
Count
Source
1
/* packet-bpsec-defaultsc.c
2
 * BPSec Default security contexts
3
 * References:
4
 *     RFC 9173: https://www.rfc-editor.org/rfc/rfc9173.html
5
 *
6
 * Copyright 2019-2021, Brian Sipos <brian.sipos@gmail.com>
7
 *
8
 * Wireshark - Network traffic analyzer
9
 * By Gerald Combs <gerald@wireshark.org>
10
 * Copyright 1998 Gerald Combs
11
 *
12
 * SPDX-License-Identifier: LGPL-2.1-or-later
13
 */
14
#include "config.h"
15
#include <stdint.h>
16
17
#include "packet-bpsec.h"
18
#include <epan/packet.h>
19
#include <epan/prefs.h>
20
#include <epan/proto.h>
21
#include <epan/tfs.h>
22
#include <epan/wscbor.h>
23
24
void proto_register_bpsec_defaultsc(void);
25
void proto_reg_handoff_bpsec_defaultsc(void);
26
27
/// Protocol handles
28
static int proto_bpsec_defaultsc;
29
30
static const val64_string shavar_vals[] = {
31
    {5, "HMAC 256/256"},
32
    {6, "HMAC 384/384"},
33
    {7, "HMAC 512/512"},
34
    {0, NULL},
35
};
36
37
static const val64_string aesvar_vals[] = {
38
    {1, "A128GCM"},
39
    {3, "A256GCM"},
40
    {0, NULL},
41
};
42
43
// Field definitions
44
static int hf_defaultsc_shavar;
45
static int hf_defaultsc_wrapedkey;
46
static int hf_defaultsc_scope;
47
static int hf_defaultsc_scope_pri_block;
48
static int hf_defaultsc_scope_tgt_head;
49
static int hf_defaultsc_scope_sec_head;
50
static int hf_defaultsc_hmac;
51
static int hf_defaultsc_iv;
52
static int hf_defaultsc_aesvar;
53
static int hf_defaultsc_authtag;
54
55
static int *const defaultsc_scope[] = {
56
    &hf_defaultsc_scope_pri_block,
57
    &hf_defaultsc_scope_tgt_head,
58
    &hf_defaultsc_scope_sec_head,
59
    NULL
60
};
61
62
// Tree structures
63
static int ett_defaultsc_scope;
64
65
0
static int dissect_defaultsc_param_shavar(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_) {
66
0
    int offset = 0;
67
0
    wscbor_chunk_t *chunk = wscbor_chunk_read(pinfo->pool, tvb, &offset);
68
0
    uint64_t *val = wscbor_require_uint64(pinfo->pool, chunk);
69
0
    proto_tree_add_cbor_uint64(tree, hf_defaultsc_shavar, pinfo, tvb, chunk, val);
70
0
    return offset;
71
0
}
72
73
0
static int dissect_defaultsc_param_wrappedkey(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_) {
74
0
    int offset = 0;
75
0
    wscbor_chunk_t *chunk = wscbor_chunk_read(pinfo->pool, tvb, &offset);
76
0
    wscbor_require_bstr(pinfo->pool, chunk);
77
0
    proto_tree_add_cbor_bstr(tree, hf_defaultsc_wrapedkey, pinfo, tvb, chunk);
78
0
    return offset;
79
0
}
80
81
0
static int dissect_defaultsc_param_scope(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_) {
82
0
    int offset = 0;
83
0
    wscbor_chunk_t *chunk = wscbor_chunk_read(pinfo->pool, tvb, &offset);
84
0
    uint64_t *flags = wscbor_require_uint64(pinfo->pool, chunk);
85
0
    proto_tree_add_cbor_bitmask(tree, hf_defaultsc_scope, ett_defaultsc_scope, defaultsc_scope, pinfo, tvb, chunk, flags);
86
0
    return offset;
87
0
}
88
89
0
static int dissect_defaultsc_result_hmac(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_) {
90
0
    int offset = 0;
91
0
    wscbor_chunk_t *chunk = wscbor_chunk_read(pinfo->pool, tvb, &offset);
92
0
    wscbor_require_bstr(pinfo->pool, chunk);
93
0
    proto_tree_add_cbor_bstr(tree, hf_defaultsc_hmac, pinfo, tvb, chunk);
94
0
    return offset;
95
0
}
96
97
0
static int dissect_defaultsc_param_iv(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_) {
98
0
    int offset = 0;
99
0
    wscbor_chunk_t *chunk = wscbor_chunk_read(pinfo->pool, tvb, &offset);
100
0
    wscbor_require_bstr(pinfo->pool, chunk);
101
0
    proto_tree_add_cbor_bstr(tree, hf_defaultsc_iv, pinfo, tvb, chunk);
102
0
    return offset;
103
0
}
104
105
0
static int dissect_defaultsc_param_aesvar(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_) {
106
0
    int offset = 0;
107
0
    wscbor_chunk_t *chunk = wscbor_chunk_read(pinfo->pool, tvb, &offset);
108
0
    uint64_t *val = wscbor_require_uint64(pinfo->pool, chunk);
109
0
    proto_tree_add_cbor_uint64(tree, hf_defaultsc_aesvar, pinfo, tvb, chunk, val);
110
0
    return offset;
111
0
}
112
113
0
static int dissect_defaultsc_result_authtag(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_) {
114
0
    int offset = 0;
115
0
    wscbor_chunk_t *chunk = wscbor_chunk_read(pinfo->pool, tvb, &offset);
116
0
    wscbor_require_bstr(pinfo->pool, chunk);
117
0
    proto_tree_add_cbor_bstr(tree, hf_defaultsc_authtag, pinfo, tvb, chunk);
118
0
    return offset;
119
0
}
120
121
/// Re-initialize after a configuration change
122
16
static void reinit_bpsec_defaultsc(void) {
123
16
}
124
125
/// Overall registration of the protocol
126
16
void proto_register_bpsec_defaultsc(void) {
127
16
    static hf_register_info fields[] = {
128
16
        {&hf_defaultsc_shavar, {"SHA Variant", "bpsec-defaultsc.shavar", FT_UINT64, BASE_DEC | BASE_VAL64_STRING, VALS64(shavar_vals), 0x0, NULL, HFILL}},
129
16
        {&hf_defaultsc_wrapedkey, {"Wrapped Key", "bpsec-defaultsc.wrappedkey", FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL}},
130
16
        {&hf_defaultsc_scope, {"BIB Scope", "bpsec-defaultsc.scope", FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL}},
131
16
        {&hf_defaultsc_scope_pri_block, {"Primary Block", "bpsec-defaultsc.scope.pri_block", FT_BOOLEAN, 16, TFS(&tfs_set_notset), 0x0001, NULL, HFILL}},
132
16
        {&hf_defaultsc_scope_tgt_head, {"Target Header", "bpsec-defaultsc.scope.tgt_head", FT_BOOLEAN, 16, TFS(&tfs_set_notset), 0x0002, NULL, HFILL}},
133
16
        {&hf_defaultsc_scope_sec_head, {"Security Header", "bpsec-defaultsc.scope.sec_head", FT_BOOLEAN, 16, TFS(&tfs_set_notset), 0x0004, NULL, HFILL}},
134
16
        {&hf_defaultsc_hmac, {"Expected HMAC", "bpsec-defaultsc.hmac", FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL}},
135
16
        {&hf_defaultsc_iv, {"IV", "bpsec-defaultsc.iv", FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL}},
136
16
        {&hf_defaultsc_aesvar, {"AES Variant", "bpsec-defaultsc.aesvar", FT_UINT64, BASE_DEC | BASE_VAL64_STRING, VALS64(aesvar_vals), 0x0, NULL, HFILL}},
137
16
        {&hf_defaultsc_authtag, {"Authentication Tag", "bpsec-defaultsc.authtag", FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL}},
138
16
    };
139
16
    static int *ett[] = {
140
16
        &ett_defaultsc_scope,
141
16
    };
142
143
16
    proto_bpsec_defaultsc = proto_register_protocol("BPSec Default Security Contexts", "BPSec Default SC","bpsec-defaultsc");
144
145
16
    proto_register_field_array(proto_bpsec_defaultsc, fields, array_length(fields));
146
16
    proto_register_subtree_array(ett, array_length(ett));
147
148
16
    prefs_register_protocol(proto_bpsec_defaultsc, reinit_bpsec_defaultsc);
149
16
}
150
151
16
void proto_reg_handoff_bpsec_defaultsc(void) {
152
    // Context 1: BIB-HMAC-SHA2
153
16
    {
154
16
        int64_t *key = g_new0(int64_t, 1);
155
16
        *key = 1;
156
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(NULL, proto_bpsec_defaultsc, NULL, "BIB-HMAC-SHA2");
157
16
        dissector_add_custom_table_handle("bpsec.ctx", key, hdl);
158
16
    }
159
16
    {
160
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
161
16
        key->context_id = 1;
162
16
        key->type_id = 1;
163
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_param_shavar, proto_bpsec_defaultsc, NULL, "BIB-HMAC-SHA2 SHA Variant");
164
16
        dissector_add_custom_table_handle("bpsec.param", key, hdl);
165
16
    }
166
16
    {
167
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
168
16
        key->context_id = 1;
169
16
        key->type_id = 2;
170
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_param_wrappedkey, proto_bpsec_defaultsc, NULL, "BIB-HMAC-SHA2 Wrapped Key");
171
16
        dissector_add_custom_table_handle("bpsec.param", key, hdl);
172
16
    }
173
16
    {
174
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
175
16
        key->context_id = 1;
176
16
        key->type_id = 3;
177
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_param_scope, proto_bpsec_defaultsc, NULL, "BIB-HMAC-SHA2 AAD Scope");
178
16
        dissector_add_custom_table_handle("bpsec.param", key, hdl);
179
16
    }
180
16
    {
181
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
182
16
        key->context_id = 1;
183
16
        key->type_id = 1;
184
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_result_hmac, proto_bpsec_defaultsc, NULL, "BIB-HMAC-SHA2 Tag");
185
16
        dissector_add_custom_table_handle("bpsec.result", key, hdl);
186
16
    }
187
188
    // Context 2: BCB-AES-GCM
189
16
    {
190
16
        int64_t *key = g_new0(int64_t, 1);
191
16
        *key = 2;
192
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(NULL, proto_bpsec_defaultsc, NULL, "BCB-AES-GCM");
193
16
        dissector_add_custom_table_handle("bpsec.ctx", key, hdl);
194
16
    }
195
16
    {
196
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
197
16
        key->context_id = 2;
198
16
        key->type_id = 1;
199
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_param_iv, proto_bpsec_defaultsc, NULL, "BCB-AES-GCM IV");
200
16
        dissector_add_custom_table_handle("bpsec.param", key, hdl);
201
16
    }
202
16
    {
203
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
204
16
        key->context_id = 2;
205
16
        key->type_id = 2;
206
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_param_aesvar, proto_bpsec_defaultsc, NULL, "BCB-AES-GCM AES Variant");
207
16
        dissector_add_custom_table_handle("bpsec.param", key, hdl);
208
16
    }
209
16
    {
210
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
211
16
        key->context_id = 2;
212
16
        key->type_id = 3;
213
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_param_wrappedkey, proto_bpsec_defaultsc, NULL, "BCB-AES-GCM Wrapped Key");
214
16
        dissector_add_custom_table_handle("bpsec.param", key, hdl);
215
16
    }
216
16
    {
217
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
218
16
        key->context_id = 2;
219
16
        key->type_id = 4;
220
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_param_scope, proto_bpsec_defaultsc, NULL, "BCB-AES-GCM AAD Scope");
221
16
        dissector_add_custom_table_handle("bpsec.param", key, hdl);
222
16
    }
223
16
    {
224
16
        bpsec_id_t *key = g_new(bpsec_id_t, 1);
225
16
        key->context_id = 2;
226
16
        key->type_id = 1;
227
16
        dissector_handle_t hdl = create_dissector_handle_with_name_and_description(dissect_defaultsc_result_authtag, proto_bpsec_defaultsc, NULL, "BCB-AES-GCM Tag");
228
16
        dissector_add_custom_table_handle("bpsec.result", key, hdl);
229
16
    }
230
231
16
    reinit_bpsec_defaultsc();
232
16
}