/src/wireshark/epan/dissectors/packet-hdfsdata.c
Line | Count | Source |
1 | | /* packet-hdfsdata.c |
2 | | * HDFS data Protocol and dissectors |
3 | | * |
4 | | * Copyright (c) 2011 by Isilon Systems. |
5 | | * |
6 | | * Author: Allison Obourn <aobourn@isilon.com> |
7 | | * |
8 | | * Wireshark - Network traffic analyzer |
9 | | * By Gerald Combs <gerald@wireshark.org> |
10 | | * Copyright 1999 Gerald Combs |
11 | | * |
12 | | * SPDX-License-Identifier: GPL-2.0-or-later |
13 | | */ |
14 | | |
15 | | |
16 | | #include "config.h" |
17 | | |
18 | | #include <epan/packet.h> |
19 | | #include "packet-tcp.h" |
20 | | |
21 | | void proto_register_hdfsdata(void); |
22 | | void proto_reg_handoff_hdfsdata(void); |
23 | | |
24 | | #if 0 |
25 | | #define NAMENODE_PORT 8020 |
26 | | #define DATANODE_PORT 8021 |
27 | | #endif |
28 | | |
29 | 0 | #define FIRST_READ_FRAGMENT_LEN 15 |
30 | 0 | #define SECOND_READ_FRAGMENT_LEN 29 |
31 | 0 | #define LAST_READ_FRAGMENT_LEN 4 |
32 | 0 | #define WRITE_OP 80 |
33 | 0 | #define READ_OP 81 |
34 | 0 | #define MIN_WRITE_REQ 35 |
35 | 0 | #define MIN_READ_REQ 36 |
36 | | |
37 | 0 | #define STATUS_SUCCESS 6 |
38 | 0 | #define PIPELINE_LEN 1 |
39 | 0 | #define STATUS_LEN 2 |
40 | 0 | #define FINISH_REQ_LEN 4 |
41 | 0 | #define END_PACKET_LEN 8 |
42 | 0 | #define READ_RESP_HEAD_LEN 19 |
43 | 0 | #define WRITE_RESP_HEAD_LEN 21 |
44 | 0 | #define WRITE_REQ_HEAD_LEN 7 |
45 | | |
46 | 0 | #define CRC 1 |
47 | 0 | #define CRC_SIZE 8.0 |
48 | 0 | #define CHUNKSIZE_START 3 |
49 | | |
50 | | |
51 | | #if 0 |
52 | | static const int RESPONSE_HEADER = 1; |
53 | | static const int RESPONSE_METADATA = 2; |
54 | | static const int RESPONSE_DATA = 3; |
55 | | #endif |
56 | | |
57 | | static int proto_hdfsdata; |
58 | | static int hf_hdfsdata_version; |
59 | | static int hf_hdfsdata_cmd; |
60 | | static int hf_hdfsdata_blockid; |
61 | | static int hf_hdfsdata_timestamp; |
62 | | static int hf_hdfsdata_startoffset; |
63 | | static int hf_hdfsdata_blocklen; |
64 | | static int hf_hdfsdata_clientlen; |
65 | | static int hf_hdfsdata_clientid; |
66 | | static int hf_hdfsdata_tokenlen; |
67 | | static int hf_hdfsdata_tokenid; |
68 | | static int hf_hdfsdata_tokenpassword; |
69 | | static int hf_hdfsdata_tokentype; |
70 | | static int hf_hdfsdata_tokenservice; |
71 | | static int hf_hdfsdata_status; |
72 | | static int hf_hdfsdata_checksumtype; |
73 | | static int hf_hdfsdata_chunksize; |
74 | | static int hf_hdfsdata_chunkoffset; |
75 | | static int hf_hdfsdata_datalength; |
76 | | static int hf_hdfsdata_inblockoffset; |
77 | | static int hf_hdfsdata_seqnum; |
78 | | static int hf_hdfsdata_last; |
79 | | static int hf_hdfsdata_crc32; |
80 | | static int hf_hdfsdata_datalen; |
81 | | static int hf_hdfsdata_rest; |
82 | | static int hf_hdfsdata_end; |
83 | | static int hf_hdfsdata_packetsize; |
84 | | static int hf_hdfsdata_chunklength; |
85 | | static int hf_hdfsdata_crc64; |
86 | | static int hf_hdfsdata_pipelinestatus; |
87 | | |
88 | | static int hf_hdfsdata_pipelinenum; |
89 | | static int hf_hdfsdata_recovery; |
90 | | static int hf_hdfsdata_sourcenode; |
91 | | static int hf_hdfsdata_currentpipeline; |
92 | | static int hf_hdfsdata_node; |
93 | | |
94 | | static int ett_hdfsdata; |
95 | | |
96 | | static dissector_handle_t hdfsdata_handle; |
97 | | |
98 | | /* Taken from HDFS |
99 | | Parse the first byte of a vint/vlong to determine the number of bytes |
100 | | value is the first byte of the vint/vlong |
101 | | returns the total number of bytes (1 to 9) */ |
102 | | static int |
103 | 0 | decode_vint_size (int8_t value) { |
104 | 0 | if (value >= -112) { |
105 | 0 | return 1; |
106 | 0 | } else if (value < -120) { |
107 | 0 | return -119 - value; |
108 | 0 | } |
109 | 0 | return -111 - value; |
110 | 0 | } |
111 | | |
112 | | /* Taken from HDFS |
113 | | converts a variable length number into a long and discovers how many bytes it is |
114 | | returns the decoded number */ |
115 | | static unsigned |
116 | | dissect_variable_length_long (tvbuff_t *tvb, proto_tree *hdfsdata_tree, int* offset) |
117 | 0 | { |
118 | 0 | int byte_count = 1; |
119 | 0 | int idx = 0; |
120 | 0 | unsigned i = 0; |
121 | 0 | int8_t first_byte = tvb_get_uint8(tvb, *offset); |
122 | 0 | unsigned size = 0; |
123 | |
|
124 | 0 | int len = decode_vint_size(first_byte); |
125 | 0 | if (len == 1) { |
126 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_clientlen, tvb, *offset, byte_count, ENC_BIG_ENDIAN); |
127 | 0 | *offset = (*offset) + byte_count; |
128 | 0 | return first_byte; |
129 | 0 | } |
130 | | |
131 | 0 | for (idx = 0; idx < len-1; idx++) { |
132 | 0 | char b = tvb_get_uint8(tvb, *offset + byte_count); |
133 | 0 | byte_count++; |
134 | 0 | i = i << 8; |
135 | 0 | i = i | (b & 0xFF); |
136 | 0 | } |
137 | 0 | size = ((first_byte < -120 || (first_byte >= -112 && first_byte < 0)) ? (i ^ 0xFFFFFFFF) : i); |
138 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_clientlen, tvb, *offset, byte_count, ENC_BIG_ENDIAN); |
139 | 0 | *offset = (*offset) + byte_count; |
140 | |
|
141 | 0 | return size; |
142 | 0 | } |
143 | | |
144 | | /* dissects a variable length int and then using its value dissects the following string */ |
145 | | static void |
146 | | dissect_variable_int_string(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int *offset) |
147 | 0 | { |
148 | | /* Get the variable length int that represents the length of the next field */ |
149 | 0 | int len = dissect_variable_length_long (tvb, hdfsdata_tree, offset); |
150 | | |
151 | | /* client id = amount of bytes in previous */ |
152 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_clientid, tvb, *offset, len, ENC_ASCII); |
153 | 0 | *offset += len; |
154 | 0 | } |
155 | | |
156 | | /* dissects the access tokens that appear at the end of requests. |
157 | | tokens: id, password, kind, service */ |
158 | | static void |
159 | | dissect_access_tokens(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int *offset) |
160 | 0 | { |
161 | 0 | uint8_t len = 0; |
162 | |
|
163 | 0 | proto_tree_add_item_ret_uint8(hdfsdata_tree, hf_hdfsdata_tokenlen, tvb, *offset, 1, ENC_BIG_ENDIAN, &len); |
164 | 0 | *offset += 1; |
165 | | |
166 | | /* token id = amount of bytes in previous */ |
167 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_tokenid, tvb, *offset, len, ENC_ASCII); |
168 | 0 | *offset += len; |
169 | |
|
170 | 0 | proto_tree_add_item_ret_uint8(hdfsdata_tree, hf_hdfsdata_tokenlen, tvb, *offset, 1, ENC_BIG_ENDIAN, &len); |
171 | 0 | *offset += 1; |
172 | | |
173 | | /* token password = amount of bytes in previous */ |
174 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_tokenpassword, tvb, *offset, len, ENC_ASCII); |
175 | 0 | *offset += len; |
176 | |
|
177 | 0 | proto_tree_add_item_ret_uint8(hdfsdata_tree, hf_hdfsdata_tokenlen, tvb, *offset, 1, ENC_BIG_ENDIAN, &len); |
178 | 0 | *offset += 1; |
179 | | |
180 | | /* token type = amount of bytes in previous */ |
181 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_tokentype, tvb, *offset, len, ENC_ASCII); |
182 | 0 | *offset += len; |
183 | |
|
184 | 0 | proto_tree_add_item_ret_uint8(hdfsdata_tree, hf_hdfsdata_tokenlen, tvb, *offset, 1, ENC_BIG_ENDIAN, &len); |
185 | 0 | *offset += 1; |
186 | | |
187 | | /* token service = amount of bytes in previous; */ |
188 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_tokenservice, tvb, *offset, len, ENC_ASCII); |
189 | 0 | *offset += len; |
190 | 0 | } |
191 | | |
192 | | /* handles parsing read response packets */ |
193 | | static void |
194 | | dissect_read_response(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int offset) |
195 | 0 | { |
196 | 0 | int len = 0; |
197 | 0 | uint32_t chunksize; |
198 | | |
199 | | /* 4 bytes = data length */ |
200 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_datalength, tvb, offset, 4, ENC_BIG_ENDIAN); |
201 | 0 | offset += 4; |
202 | | |
203 | | /* 8 bytes = in block offset */ |
204 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_inblockoffset, tvb, offset, 8, ENC_BIG_ENDIAN); |
205 | 0 | offset += 8; |
206 | | |
207 | | /* 8 bytes = sequence number */ |
208 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_seqnum, tvb, offset, 8, ENC_BIG_ENDIAN); |
209 | 0 | offset += 8; |
210 | | |
211 | | /* 1 byte = last packet in block */ |
212 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_last, tvb, offset, 1, ENC_BIG_ENDIAN); |
213 | 0 | offset += 1; |
214 | | |
215 | | /* 4 byte = length of data */ |
216 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_datalen, tvb, offset, 4, ENC_BIG_ENDIAN); |
217 | 0 | offset += 4; |
218 | | |
219 | | /* if there is a crc checksum it is 8* the length of the data * checksum size / chunksize */ |
220 | 0 | chunksize = tvb_get_ntohl(tvb, CHUNKSIZE_START); |
221 | 0 | if (chunksize == 0) /* let's not divide by zero */ |
222 | 0 | return; |
223 | 0 | if (tvb_get_uint8(tvb, 2) == CRC) { |
224 | 0 | len = (int)(CRC_SIZE * tvb_get_ntohl(tvb, offset - 4) * |
225 | 0 | tvb_get_ntohl(tvb, offset - 8) / chunksize); |
226 | 0 | } |
227 | | |
228 | | /* the rest of bytes (usually 4) = crc32 code */ |
229 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_crc32, tvb, offset, len, ENC_BIG_ENDIAN); |
230 | | /* offset += len; */ |
231 | 0 | } |
232 | | |
233 | | /* dissects the first packet of the read response */ |
234 | | static void |
235 | 0 | dissect_read_response_start(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int offset) { |
236 | | /* 2 bytes = status code */ |
237 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_status, tvb, offset, 2, ENC_BIG_ENDIAN); |
238 | 0 | offset += 2; |
239 | | |
240 | | /* checksum type = 1 byte. 1 = crc32, 0 = null */ |
241 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_checksumtype, tvb, offset, 1, ENC_BIG_ENDIAN); |
242 | 0 | offset += 1; |
243 | | |
244 | | /* 4 bytes = chunksize */ |
245 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_chunksize, tvb, offset, 4, ENC_BIG_ENDIAN); |
246 | 0 | offset += 4; |
247 | | |
248 | | /* 8 bytes = chunk offset */ |
249 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_chunkoffset, tvb, offset, 8, ENC_BIG_ENDIAN); |
250 | | /* offset += 8; */ |
251 | 0 | } |
252 | | |
253 | | /* dissects the fields specific to a read request */ |
254 | | static void |
255 | | dissect_read_request(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int *offset) |
256 | 0 | { |
257 | | |
258 | | /* 8 bytes = start offset */ |
259 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_startoffset, tvb, *offset, 8, ENC_BIG_ENDIAN); |
260 | 0 | *offset += 8; |
261 | | |
262 | | /* 8 bytes = block length */ |
263 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_blocklen, tvb, *offset, 8, ENC_BIG_ENDIAN); |
264 | 0 | *offset += 8; |
265 | |
|
266 | 0 | } |
267 | | |
268 | | /* dissects the fields specific to a write request */ |
269 | | static void |
270 | | dissect_write_request(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int *offset) |
271 | 0 | { |
272 | | /* 4 bytes = number of nodes in pipeline */ |
273 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_pipelinenum, tvb, *offset, 4, ENC_BIG_ENDIAN); |
274 | 0 | *offset += 4; |
275 | | |
276 | | /* 1 bytes = recovery boolean */ |
277 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_recovery, tvb, *offset, 1, ENC_BIG_ENDIAN); |
278 | 0 | *offset += 1; |
279 | 0 | } |
280 | | |
281 | | /* dissects the fields specific to a write request */ |
282 | | static void |
283 | | dissect_write_request_end(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int *offset) |
284 | 0 | { |
285 | 0 | int i = 0; |
286 | 0 | int len = 0; |
287 | | |
288 | | /* 1 bytes = source node */ |
289 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_sourcenode, tvb, *offset, 1, ENC_BIG_ENDIAN); |
290 | 0 | *offset += 1; |
291 | | |
292 | | /* 4 bytes = number of nodes currently in the pipeline (usually just -1 of before) */ |
293 | 0 | len = tvb_get_ntohl(tvb, *offset); |
294 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_currentpipeline, tvb, *offset, 4, ENC_BIG_ENDIAN); |
295 | 0 | *offset += 4; |
296 | | |
297 | | /* variable length sequence of node objects */ |
298 | 0 | for (i = 0; i < len; i++) { |
299 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_node, tvb, *offset, 4, ENC_BIG_ENDIAN); |
300 | 0 | *offset += 4; |
301 | 0 | } |
302 | 0 | } |
303 | | |
304 | | /* dissects the beginning of the read and write request messages */ |
305 | | static int |
306 | 0 | dissect_header(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int* offset){ |
307 | |
|
308 | 0 | int command = 0; |
309 | | |
310 | | /* 2 bytes = protocol version */ |
311 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_version, tvb, *offset, 2, ENC_BIG_ENDIAN); |
312 | 0 | *offset += 2; |
313 | | |
314 | | /* 1 byte = command */ |
315 | 0 | command = tvb_get_uint8(tvb, *offset); |
316 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_cmd, tvb, *offset, 1, ENC_BIG_ENDIAN); |
317 | 0 | *offset += 1; |
318 | | |
319 | | /* 8 bytes = block id */ |
320 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_blockid, tvb, *offset, 8, ENC_BIG_ENDIAN); |
321 | 0 | *offset += 8; |
322 | | |
323 | | /* 8 bytes = timestamp */ |
324 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_timestamp, tvb, *offset, 8, ENC_BIG_ENDIAN); |
325 | 0 | *offset += 8; |
326 | |
|
327 | 0 | return command; |
328 | 0 | } |
329 | | |
330 | | /* decodes the write response messages */ |
331 | | static void |
332 | | dissect_write_response(tvbuff_t *tvb, proto_tree *hdfsdata_tree, int offset) |
333 | 0 | { |
334 | | /* 4 bytes = packetsize */ |
335 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_packetsize, tvb, offset, 4, ENC_BIG_ENDIAN); |
336 | 0 | offset += 4; |
337 | | |
338 | | /* 8 bytes = offset in block */ |
339 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_startoffset, tvb, offset, 8, ENC_BIG_ENDIAN); |
340 | 0 | offset += 8; |
341 | | |
342 | | /* 8 bytes = sequence number */ |
343 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_seqnum, tvb, offset, 8, ENC_BIG_ENDIAN); |
344 | 0 | offset += 8; |
345 | | |
346 | | /* 1 bytes = last packet */ |
347 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_last, tvb, offset, 1, ENC_BIG_ENDIAN); |
348 | 0 | offset += 1; |
349 | | |
350 | | /* 4 bytes = chunk length */ |
351 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_chunklength, tvb, offset, 4, ENC_BIG_ENDIAN); |
352 | 0 | offset += 4; |
353 | | |
354 | | /* 8 bytes = crc code */ |
355 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_crc64, tvb, offset, 8, ENC_BIG_ENDIAN); |
356 | 0 | offset += 8; |
357 | | |
358 | | /* add the rest -> RESPONSE_DATA */ |
359 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_rest, tvb, offset, (tvb_reported_length(tvb)) - offset, ENC_ASCII); |
360 | | /* offset += (tvb_reported_length(tvb)); */ |
361 | 0 | } |
362 | | |
363 | | /* determine PDU length of protocol */ |
364 | | static unsigned |
365 | | get_hdfsdata_message_len(packet_info *pinfo _U_, tvbuff_t *tvb, int offset, void *data _U_) |
366 | 0 | { |
367 | | /* get data packet len, add FIRST_READ_FRAGMENT_LEN for first fragment (before len), |
368 | | SECOND_READ_FRAGMENT_LEN for second fragment (incl len), subtract 4 for length itself. */ |
369 | |
|
370 | 0 | if (tvb_reported_length(tvb) <= 4 || tvb_reported_length(tvb) == END_PACKET_LEN |
371 | 0 | || tvb_get_ntohl(tvb, 0) == tvb_reported_length(tvb) - WRITE_RESP_HEAD_LEN |
372 | 0 | || (tvb_reported_length(tvb) >= MIN_READ_REQ && tvb_get_uint8(tvb, 2) == READ_OP) |
373 | 0 | || (tvb_reported_length(tvb) >= MIN_WRITE_REQ && tvb_get_uint8(tvb, 2) == WRITE_OP)) { |
374 | |
|
375 | 0 | return tvb_reported_length(tvb); |
376 | 0 | } |
377 | 0 | return tvb_get_ntohl(tvb, offset + FIRST_READ_FRAGMENT_LEN) + |
378 | 0 | FIRST_READ_FRAGMENT_LEN + SECOND_READ_FRAGMENT_LEN - LAST_READ_FRAGMENT_LEN; |
379 | 0 | } |
380 | | |
381 | | /* This method dissects fully reassembled messages */ |
382 | | static int |
383 | | dissect_hdfsdata_message(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_) |
384 | 0 | { |
385 | 0 | int offset = 0; |
386 | |
|
387 | 0 | col_set_str(pinfo->cinfo, COL_PROTOCOL, "HDFSDATA"); |
388 | | /* Clear out stuff in the info column */ |
389 | 0 | col_set_str(pinfo->cinfo, COL_INFO, "HDFS Data"); |
390 | | |
391 | |
|
392 | 0 | if (tree) { |
393 | 0 | proto_item *ti = NULL; |
394 | 0 | proto_tree *hdfsdata_tree = NULL; |
395 | |
|
396 | 0 | ti = proto_tree_add_item(tree, proto_hdfsdata, tvb, offset, -1, ENC_NA); |
397 | 0 | hdfsdata_tree = proto_item_add_subtree(ti, ett_hdfsdata); |
398 | | |
399 | | /* if only 1 bytes packet must just contain just the pipeline status */ |
400 | 0 | if ((tvb_reported_length(tvb)) == PIPELINE_LEN) { |
401 | | |
402 | | /* 1 bytes = pipeline status */ |
403 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_pipelinestatus, tvb, offset, PIPELINE_LEN, ENC_BIG_ENDIAN); |
404 | | |
405 | | /* if only 2 bytes packet must just contain just a status code */ |
406 | 0 | } else if ((tvb_reported_length(tvb)) == STATUS_LEN) { |
407 | | /* 2 bytes = status code */ |
408 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_status, tvb, offset, STATUS_LEN, ENC_BIG_ENDIAN); |
409 | | |
410 | | /* if it is 4 bytes long it must be a finish request packet */ |
411 | 0 | } else if ((tvb_reported_length(tvb)) == FINISH_REQ_LEN) { |
412 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_end, tvb, offset, 4, ENC_BIG_ENDIAN); |
413 | | |
414 | | /* read response packet */ |
415 | 0 | } else if (tvb_reported_length(tvb) >= READ_RESP_HEAD_LEN && tvb_reported_length(tvb) == |
416 | 0 | tvb_get_ntohl(tvb, FIRST_READ_FRAGMENT_LEN) + |
417 | 0 | FIRST_READ_FRAGMENT_LEN + SECOND_READ_FRAGMENT_LEN - LAST_READ_FRAGMENT_LEN){ |
418 | |
|
419 | 0 | dissect_read_response_start(tvb, hdfsdata_tree, offset); |
420 | 0 | offset += FIRST_READ_FRAGMENT_LEN; |
421 | |
|
422 | 0 | dissect_read_response(tvb, hdfsdata_tree, offset); |
423 | 0 | offset+= SECOND_READ_FRAGMENT_LEN; |
424 | | |
425 | | /* This message just contains data so we can display it all as one block */ |
426 | |
|
427 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_rest, tvb, offset, (tvb_reported_length(tvb)) - offset, ENC_ASCII); |
428 | |
|
429 | 0 | } else { |
430 | |
|
431 | 0 | uint8_t op = tvb_get_uint8(tvb, 2); |
432 | | |
433 | | /* READ request */ |
434 | 0 | if ((tvb_reported_length(tvb)) >= MIN_READ_REQ && op == READ_OP) { |
435 | 0 | dissect_header(tvb, hdfsdata_tree, &offset); |
436 | 0 | dissect_read_request(tvb, hdfsdata_tree, &offset); |
437 | 0 | dissect_variable_int_string(tvb, hdfsdata_tree, &offset); |
438 | 0 | dissect_access_tokens(tvb, hdfsdata_tree, &offset); |
439 | | |
440 | | /* WRITE request */ |
441 | 0 | } else if ((tvb_reported_length(tvb)) >= MIN_WRITE_REQ && op == WRITE_OP) { |
442 | 0 | dissect_header(tvb, hdfsdata_tree, &offset); |
443 | 0 | dissect_write_request(tvb, hdfsdata_tree, &offset); |
444 | 0 | dissect_variable_int_string(tvb, hdfsdata_tree, &offset); |
445 | 0 | dissect_write_request_end(tvb, hdfsdata_tree, &offset); |
446 | 0 | dissect_access_tokens(tvb, hdfsdata_tree, &offset); |
447 | | |
448 | | /* checksum type = 1 byte. 1 = crc32, 0 = null */ |
449 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_checksumtype, tvb, offset, 1, ENC_BIG_ENDIAN); |
450 | 0 | offset += 1; |
451 | | |
452 | | /* 4 bytes = chunksize */ |
453 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_chunksize, tvb, offset, 4, ENC_BIG_ENDIAN); |
454 | | |
455 | | /* write responses store the data length in the first 4 bytes. This length does not |
456 | | include 21 bits of header */ |
457 | 0 | } else if (tvb_reported_length(tvb) >= 4 && tvb_get_ntohl(tvb, 0) == |
458 | 0 | tvb_reported_length(tvb) - WRITE_RESP_HEAD_LEN) { |
459 | |
|
460 | 0 | dissect_write_response(tvb, hdfsdata_tree, offset); |
461 | |
|
462 | 0 | } else { |
463 | | /* This message contains some form of data that we have not successfully been able to |
464 | | pattern match and catagorize. Display all of it as data. */ |
465 | 0 | proto_tree_add_item(hdfsdata_tree, hf_hdfsdata_rest, tvb, offset, (tvb_reported_length(tvb)), ENC_ASCII); |
466 | 0 | } |
467 | 0 | } |
468 | 0 | } |
469 | |
|
470 | 0 | return tvb_captured_length(tvb); |
471 | 0 | } |
472 | | |
473 | | static int |
474 | | dissect_hdfsdata(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data) |
475 | 0 | { |
476 | 0 | int frame_header_len = 0; |
477 | |
|
478 | 0 | bool need_reassemble = false; |
479 | 0 | uint8_t op = 0; |
480 | 0 | bool only_packet = tvb_reported_length(tvb) == 1 || (tvb_reported_length(tvb) == 2 && |
481 | 0 | tvb_get_ntohs(tvb, 0) == STATUS_SUCCESS); |
482 | |
|
483 | 0 | if (tvb_reported_length(tvb) >= 3) |
484 | 0 | op = tvb_get_uint8(tvb, 2); |
485 | |
|
486 | 0 | if (!only_packet && tvb_reported_length(tvb) != 4 && !(tvb_reported_length(tvb) >= MIN_READ_REQ && op == READ_OP) && |
487 | 0 | !(tvb_reported_length(tvb) >= MIN_WRITE_REQ && op == WRITE_OP) && !(tvb_reported_length(tvb) == END_PACKET_LEN && |
488 | 0 | !tvb_get_ntohl(tvb, 0) && !tvb_get_ntohl(tvb, 4))) { |
489 | |
|
490 | 0 | need_reassemble = true; |
491 | 0 | } |
492 | | |
493 | | /* setting the header size for the different types of packets */ |
494 | 0 | if (only_packet || tvb_reported_length(tvb) == END_PACKET_LEN) { |
495 | 0 | frame_header_len = tvb_reported_length(tvb); |
496 | |
|
497 | 0 | } else if (tvb_reported_length(tvb) == FIRST_READ_FRAGMENT_LEN ||(tvb_reported_length(tvb) >= MIN_READ_REQ && |
498 | 0 | op == READ_OP && !((tvb_reported_length(tvb)) == 2 && !tvb_get_ntohs(tvb, 0)))) { |
499 | |
|
500 | 0 | frame_header_len = READ_RESP_HEAD_LEN; |
501 | |
|
502 | 0 | } else if (tvb_reported_length(tvb) >= MIN_WRITE_REQ && op == WRITE_OP) { |
503 | 0 | frame_header_len = WRITE_REQ_HEAD_LEN; |
504 | 0 | } |
505 | |
|
506 | 0 | tcp_dissect_pdus(tvb, pinfo, tree, need_reassemble, frame_header_len, get_hdfsdata_message_len, dissect_hdfsdata_message, data); |
507 | 0 | return tvb_captured_length(tvb); |
508 | 0 | } |
509 | | |
510 | | /* registers the protocol with the given names */ |
511 | | void |
512 | | proto_register_hdfsdata(void) |
513 | 16 | { |
514 | 16 | static hf_register_info hf[] = { |
515 | | |
516 | | /* list of all options for dissecting the protocol */ |
517 | | |
518 | | /************************************************* |
519 | | Read request |
520 | | **************************************************/ |
521 | 16 | { &hf_hdfsdata_version, |
522 | 16 | { "HDFSDATA protocol version", "hdfsdata.version", |
523 | 16 | FT_UINT16, BASE_DEC, |
524 | 16 | NULL, 0x0, |
525 | 16 | NULL, HFILL } |
526 | 16 | }, |
527 | 16 | { &hf_hdfsdata_cmd, |
528 | 16 | { "HDFSDATA command", "hdfsdata.cmd", |
529 | 16 | FT_UINT8, BASE_DEC, |
530 | 16 | NULL, 0x0, |
531 | 16 | NULL, HFILL } |
532 | 16 | }, |
533 | 16 | { &hf_hdfsdata_blockid, |
534 | 16 | { "HDFSDATA block id", "hdfsdata.blockid", |
535 | 16 | FT_UINT64, BASE_DEC, |
536 | 16 | NULL, 0x0, |
537 | 16 | NULL, HFILL } |
538 | 16 | }, |
539 | 16 | { &hf_hdfsdata_timestamp, |
540 | 16 | { "HDFSDATA timestamp", "hdfsdata.timestamp", |
541 | 16 | FT_UINT64, BASE_DEC, |
542 | 16 | NULL, 0x0, |
543 | 16 | NULL, HFILL } |
544 | 16 | }, |
545 | | /*** |
546 | | Read specific |
547 | | ***/ |
548 | 16 | { &hf_hdfsdata_startoffset, |
549 | 16 | { "HDFSDATA start offset", "hdfsdata.startoffset", |
550 | 16 | FT_UINT64, BASE_DEC, |
551 | 16 | NULL, 0x0, |
552 | 16 | NULL, HFILL } |
553 | 16 | }, |
554 | 16 | { &hf_hdfsdata_blocklen, |
555 | 16 | { "HDFSDATA block length", "hdfsdata.blocklen", |
556 | 16 | FT_UINT64, BASE_DEC, |
557 | 16 | NULL, 0x0, |
558 | 16 | NULL, HFILL } |
559 | 16 | }, |
560 | | /*** |
561 | | Write specific |
562 | | ***/ |
563 | 16 | { &hf_hdfsdata_pipelinenum, |
564 | 16 | { "HDFSDATA number in pipeline", "hdfsdata.pipelinenum", |
565 | 16 | FT_UINT32, BASE_DEC, |
566 | 16 | NULL, 0x0, |
567 | 16 | NULL, HFILL } |
568 | 16 | }, |
569 | 16 | { &hf_hdfsdata_recovery, |
570 | 16 | { "HDFSDATA recovery boolean", "hdfsdata.recovery", |
571 | 16 | FT_UINT8, BASE_DEC, |
572 | 16 | NULL, 0x0, |
573 | 16 | NULL, HFILL } |
574 | 16 | }, |
575 | 16 | { &hf_hdfsdata_sourcenode, |
576 | 16 | { "HDFSDATA source node", "hdfsdata.sourcenode", |
577 | 16 | FT_UINT8, BASE_DEC, |
578 | 16 | NULL, 0x0, |
579 | 16 | NULL, HFILL } |
580 | 16 | }, |
581 | 16 | { &hf_hdfsdata_currentpipeline, |
582 | 16 | { "HDFSDATA current number of nodes in the pipeline", "hdfsdata.currentpipeline", |
583 | 16 | FT_UINT32, BASE_DEC, |
584 | 16 | NULL, 0x0, |
585 | 16 | NULL, HFILL } |
586 | 16 | }, |
587 | 16 | { &hf_hdfsdata_node, |
588 | 16 | { "HDFSDATA node object", "hdfsdata.node", |
589 | 16 | FT_UINT32, BASE_DEC, |
590 | 16 | NULL, 0x0, |
591 | 16 | NULL, HFILL } |
592 | 16 | }, |
593 | | /*** |
594 | | Var length |
595 | | **/ |
596 | 16 | { &hf_hdfsdata_clientlen, |
597 | 16 | { "HDFSDATA client id length", "hdfsdata.clientlen", |
598 | 16 | FT_UINT8, BASE_DEC, |
599 | 16 | NULL, 0x0, |
600 | 16 | NULL, HFILL } |
601 | 16 | }, |
602 | 16 | { &hf_hdfsdata_clientid, |
603 | 16 | { "HDFSDATA client id", "hdfsdata.clientid", |
604 | 16 | FT_STRING, BASE_NONE, |
605 | 16 | NULL, 0x0, |
606 | 16 | NULL, HFILL } |
607 | 16 | }, |
608 | 16 | { &hf_hdfsdata_end, |
609 | 16 | { "HDFSDATA end data request", "hdfsdata.end", |
610 | 16 | FT_UINT32, BASE_DEC, |
611 | 16 | NULL, 0x0, |
612 | 16 | NULL, HFILL } |
613 | 16 | }, |
614 | | /************************************************* |
615 | | Access tokens |
616 | | **************************************************/ |
617 | 16 | { &hf_hdfsdata_tokenlen, |
618 | 16 | { "HDFSDATA access token length", "hdfsdata.tokenlen", |
619 | 16 | FT_UINT8, BASE_DEC, |
620 | 16 | NULL, 0x0, |
621 | 16 | NULL, HFILL } |
622 | 16 | }, |
623 | 16 | { &hf_hdfsdata_tokenid, |
624 | 16 | { "HDFSDATA access token ID", "hdfsdata.tokenid", |
625 | 16 | FT_STRING, BASE_NONE, |
626 | 16 | NULL, 0x0, |
627 | 16 | NULL, HFILL } |
628 | 16 | }, |
629 | 16 | { &hf_hdfsdata_tokenpassword, |
630 | 16 | { "HDFSDATA access token password", "hdfsdata.tokenpassword", |
631 | 16 | FT_STRING, BASE_NONE, |
632 | 16 | NULL, 0x0, |
633 | 16 | NULL, HFILL } |
634 | 16 | }, |
635 | 16 | { &hf_hdfsdata_tokentype, |
636 | 16 | { "HDFSDATA access token type", "hdfsdata.tokentype", |
637 | 16 | FT_STRING, BASE_NONE, |
638 | 16 | NULL, 0x0, |
639 | 16 | NULL, HFILL } |
640 | 16 | }, |
641 | 16 | { &hf_hdfsdata_tokenservice, |
642 | 16 | { "HDFSDATA access token service", "hdfsdata.tokenservice", |
643 | 16 | FT_STRING, BASE_NONE, |
644 | 16 | NULL, 0x0, |
645 | 16 | NULL, HFILL } |
646 | 16 | }, |
647 | | /*********************************************** |
648 | | Responses 1 |
649 | | ***********************************************/ |
650 | 16 | { &hf_hdfsdata_status, |
651 | 16 | { "HDFSDATA status code", "hdfsdata.status", |
652 | 16 | FT_UINT16, BASE_DEC, |
653 | 16 | NULL, 0x0, |
654 | 16 | NULL, HFILL } |
655 | 16 | }, |
656 | 16 | { &hf_hdfsdata_checksumtype, |
657 | 16 | { "HDFSDATA checksum type", "hdfsdata.checksumtype", |
658 | 16 | FT_UINT8, BASE_DEC, |
659 | 16 | NULL, 0x0, |
660 | 16 | NULL, HFILL } |
661 | 16 | }, |
662 | 16 | { &hf_hdfsdata_chunksize, |
663 | 16 | { "HDFSDATA chunk size", "hdfsdata.chunksize", |
664 | 16 | FT_UINT32, BASE_DEC, |
665 | 16 | NULL, 0x0, |
666 | 16 | NULL, HFILL } |
667 | 16 | }, |
668 | 16 | { &hf_hdfsdata_chunkoffset, |
669 | 16 | { "HDFSDATA chunk offset", "hdfsdata.chunkoffset", |
670 | 16 | FT_UINT64, BASE_DEC, |
671 | 16 | NULL, 0x0, |
672 | 16 | NULL, HFILL } |
673 | 16 | }, |
674 | | /*********************************************** |
675 | | Responses 2 |
676 | | ***********************************************/ |
677 | 16 | { &hf_hdfsdata_datalength, |
678 | 16 | { "HDFSDATA length of data", "hdfsdata.datalength", |
679 | 16 | FT_UINT32, BASE_DEC, |
680 | 16 | NULL, 0x0, |
681 | 16 | NULL, HFILL } |
682 | 16 | }, |
683 | 16 | { &hf_hdfsdata_inblockoffset, |
684 | 16 | { "HDFSDATA in block offset", "hdfsdata.inblockoffset", |
685 | 16 | FT_UINT64, BASE_DEC, |
686 | 16 | NULL, 0x0, |
687 | 16 | NULL, HFILL } |
688 | 16 | }, |
689 | 16 | { &hf_hdfsdata_seqnum, |
690 | 16 | { "HDFSDATA sequence number", "hdfsdata.seqnum", |
691 | 16 | FT_UINT64, BASE_DEC, |
692 | 16 | NULL, 0x0, |
693 | 16 | NULL, HFILL } |
694 | 16 | }, |
695 | 16 | { &hf_hdfsdata_last, |
696 | 16 | { "HDFSDATA last packet in block", "hdfsdata.last", |
697 | 16 | FT_INT8, BASE_DEC, |
698 | 16 | NULL, 0x0, |
699 | 16 | NULL, HFILL } |
700 | 16 | }, |
701 | 16 | { &hf_hdfsdata_datalen, |
702 | 16 | { "HDFSDATA length of data", "hdfsdata.datalen", |
703 | 16 | FT_INT32, BASE_DEC, |
704 | 16 | NULL, 0x0, |
705 | 16 | NULL, HFILL } |
706 | 16 | }, |
707 | 16 | { &hf_hdfsdata_crc32, |
708 | 16 | { "HDFSDATA crc32 checksum", "hdfsdata.crc32", |
709 | 16 | FT_INT32, BASE_DEC, |
710 | 16 | NULL, 0x0, |
711 | 16 | NULL, HFILL } |
712 | 16 | }, |
713 | | /*********************************************** |
714 | | Responses 3 |
715 | | ***********************************************/ |
716 | 16 | { &hf_hdfsdata_rest, |
717 | 16 | { "HDFSDATA data", "hdfsdata.rest", |
718 | 16 | FT_STRING, BASE_NONE, |
719 | 16 | NULL, 0x0, |
720 | 16 | NULL, HFILL } |
721 | 16 | }, |
722 | | /*********************************************** |
723 | | Write Response 1 |
724 | | ***********************************************/ |
725 | 16 | { &hf_hdfsdata_packetsize, |
726 | 16 | { "HDFSDATA packet size", "hdfsdata.packetsize", |
727 | 16 | FT_UINT32, BASE_DEC, |
728 | 16 | NULL, 0x0, |
729 | 16 | NULL, HFILL } |
730 | 16 | }, |
731 | 16 | { &hf_hdfsdata_chunklength, |
732 | 16 | { "HDFSDATA chunk length", "hdfsdata.chunklength", |
733 | 16 | FT_UINT32, BASE_DEC, |
734 | 16 | NULL, 0x0, |
735 | 16 | NULL, HFILL } |
736 | 16 | }, |
737 | 16 | { &hf_hdfsdata_crc64, |
738 | 16 | { "HDFSDATA crc64 checksum", "hdfsdata.crc64", |
739 | 16 | FT_INT64, BASE_DEC, |
740 | 16 | NULL, 0x0, |
741 | 16 | NULL, HFILL } |
742 | 16 | }, |
743 | 16 | { &hf_hdfsdata_pipelinestatus, |
744 | 16 | { "HDFSDATA pipeline status", "hdfsdata.pipelinestatus", |
745 | 16 | FT_INT8, BASE_DEC, |
746 | 16 | NULL, 0x0, |
747 | 16 | NULL, HFILL } |
748 | 16 | }, |
749 | 16 | }; |
750 | | |
751 | | /* Setup protocol subtree array */ |
752 | 16 | static int *ett[] = { |
753 | 16 | &ett_hdfsdata |
754 | 16 | }; |
755 | | |
756 | 16 | proto_hdfsdata = proto_register_protocol ("HDFSDATA Protocol", "HDFSDATA", "hdfsdata"); |
757 | | |
758 | 16 | proto_register_field_array(proto_hdfsdata, hf, array_length(hf)); |
759 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
760 | | |
761 | 16 | hdfsdata_handle = register_dissector("hdfsdata", dissect_hdfsdata, proto_hdfsdata); |
762 | 16 | } |
763 | | |
764 | | /* registers handoff */ |
765 | | void |
766 | | proto_reg_handoff_hdfsdata(void) |
767 | 16 | { |
768 | 16 | dissector_add_for_decode_as_with_preference("tcp.port", hdfsdata_handle); |
769 | 16 | } |
770 | | /* |
771 | | * Editor modelines |
772 | | * |
773 | | * Local Variables: |
774 | | * c-basic-offset: 2 |
775 | | * tab-width: 8 |
776 | | * indent-tabs-mode: nil |
777 | | * End: |
778 | | * |
779 | | * ex: set shiftwidth=2 tabstop=8 expandtab: |
780 | | * :indentSize=2:tabSize=8:noTabs=true: |
781 | | */ |